PL_InitArenaPool:
   32|   564k|                 PRUint32 align) {
   33|       |  /*
   34|       |   * Look-up table of PR_BITMASK(PR_CeilingLog2(align)) values for
   35|       |   * align = 1 to 32.
   36|       |   */
   37|   564k|  static const PRUint8 pmasks[33] = {
   38|   564k|      0, /*  not used */
   39|   564k|      0,  1,  3,  3,  7,  7,  7,  7,
   40|   564k|      15, 15, 15, 15, 15, 15, 15, 15, /*  1 ... 16 */
   41|   564k|      31, 31, 31, 31, 31, 31, 31, 31,
   42|   564k|      31, 31, 31, 31, 31, 31, 31, 31 /* 17 ... 32 */
   43|   564k|  };
   44|       |
   45|   564k|  if (align == 0) {
  ------------------
  |  Branch (45:7): [True: 0, False: 564k]
  ------------------
   46|      0|    align = PL_ARENA_DEFAULT_ALIGN;
  ------------------
  |  |   28|      0|#define PL_ARENA_DEFAULT_ALIGN sizeof(double)
  ------------------
   47|      0|  }
   48|       |
   49|   564k|  if (align < sizeof(pmasks) / sizeof(pmasks[0])) {
  ------------------
  |  Branch (49:7): [True: 564k, False: 0]
  ------------------
   50|   564k|    pool->mask = pmasks[align];
   51|   564k|  } else {
   52|      0|    pool->mask = PR_BITMASK(PR_CeilingLog2(align));
  ------------------
  |  |  147|      0|#define PR_BITMASK(n)   (PR_BIT(n) - 1)
  |  |  ------------------
  |  |  |  |  146|      0|#define PR_BIT(n)       ((PRUint32)1 << (n))
  |  |  ------------------
  ------------------
   53|      0|  }
   54|       |
   55|   564k|  pool->first.next = NULL;
   56|       |  /* Set all three addresses in pool->first to the same dummy value.
   57|       |   * These addresses are only compared with each other, but never
   58|       |   * dereferenced. */
   59|   564k|  pool->first.base = pool->first.avail = pool->first.limit =
   60|   564k|      (PRUword)PL_ARENA_ALIGN(pool, &pool->first + 1);
  ------------------
  |  |  146|   564k|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  ------------------
   61|   564k|  pool->current = &pool->first;
   62|       |  /*
   63|       |   * Compute the net size so that each arena's gross size is |size|.
   64|       |   * sizeof(PLArena) + pool->mask is the header and alignment slop
   65|       |   * that PL_ArenaAllocate adds to the net size.
   66|       |   */
   67|   564k|  if (size > sizeof(PLArena) + pool->mask) {
  ------------------
  |  Branch (67:7): [True: 564k, False: 0]
  ------------------
   68|   564k|    pool->arenasize = size - (sizeof(PLArena) + pool->mask);
   69|   564k|  } else {
   70|      0|    pool->arenasize = size;
   71|      0|  }
   72|       |#ifdef PL_ARENAMETER
   73|       |  memset(&pool->stats, 0, sizeof pool->stats);
   74|       |  pool->stats.name = strdup(name);
   75|       |  pool->stats.next = arena_stats_list;
   76|       |  arena_stats_list = &pool->stats;
   77|       |#endif
   78|   564k|}
PL_ArenaAllocate:
   99|   493k|PR_IMPLEMENT(void*) PL_ArenaAllocate(PLArenaPool* pool, PRUint32 nb) {
  100|   493k|  PLArena* a;
  101|   493k|  char* rp; /* returned pointer */
  102|   493k|  PRUint32 nbOld;
  103|       |
  104|   493k|  PR_ASSERT((nb & pool->mask) == 0);
  ------------------
  |  |  208|   493k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 493k, False: 0]
  |  |  ------------------
  ------------------
  105|       |
  106|   493k|  nbOld = nb;
  107|   493k|  nb = (PRUword)PL_ARENA_ALIGN(pool, nb); /* force alignment */
  ------------------
  |  |  146|   493k|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  ------------------
  108|   493k|  if (nb < nbOld) {
  ------------------
  |  Branch (108:7): [True: 0, False: 493k]
  ------------------
  109|      0|    return NULL;
  110|      0|  }
  111|       |
  112|       |  /* attempt to allocate from arenas at pool->current */
  113|   493k|  {
  114|   493k|    a = pool->current;
  115|   493k|    do {
  116|   493k|      if (nb <= a->limit - a->avail) {
  ------------------
  |  Branch (116:11): [True: 0, False: 493k]
  ------------------
  117|      0|        pool->current = a;
  118|      0|        rp = (char*)a->avail;
  119|      0|        a->avail += nb;
  120|      0|        return rp;
  121|      0|      }
  122|   493k|    } while (NULL != (a = a->next));
  ------------------
  |  Branch (122:14): [True: 0, False: 493k]
  ------------------
  123|   493k|  }
  124|       |
  125|       |  /* attempt to allocate from the heap */
  126|   493k|  {
  127|   493k|    PRUint32 sz = PR_MAX(pool->arenasize, nb);
  ------------------
  |  |  159|   493k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 493k, False: 15]
  |  |  ------------------
  ------------------
  128|   493k|    if (PR_UINT32_MAX - sz < sizeof *a + pool->mask) {
  ------------------
  |  |  302|   493k|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  ------------------
  |  |  |  |  282|   493k|#define PR_UINT32(x) x ## U
  |  |  ------------------
  ------------------
  |  Branch (128:9): [True: 0, False: 493k]
  ------------------
  129|      0|      a = NULL;
  130|   493k|    } else {
  131|   493k|      sz += sizeof *a + pool->mask; /* header and alignment slop */
  132|   493k|      a = (PLArena*)PR_MALLOC(sz);
  ------------------
  |  |   55|   493k|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  ------------------
  133|   493k|    }
  134|   493k|    if (NULL != a) {
  ------------------
  |  Branch (134:9): [True: 493k, False: 0]
  ------------------
  135|   493k|      a->limit = (PRUword)a + sz;
  136|   493k|      a->base = a->avail = (PRUword)PL_ARENA_ALIGN(pool, a + 1);
  ------------------
  |  |  146|   493k|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  ------------------
  137|   493k|      PL_MAKE_MEM_NOACCESS((void*)a->avail, a->limit - a->avail);
  138|   493k|      rp = (char*)a->avail;
  139|   493k|      a->avail += nb;
  140|   493k|      PR_ASSERT(a->avail <= a->limit);
  ------------------
  |  |  208|   493k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 493k, False: 0]
  |  |  ------------------
  ------------------
  141|       |      /* the newly allocated arena is linked after pool->current
  142|       |       *  and becomes pool->current */
  143|   493k|      a->next = pool->current->next;
  144|   493k|      pool->current->next = a;
  145|   493k|      pool->current = a;
  146|   493k|      if (NULL == pool->first.next) {
  ------------------
  |  Branch (146:11): [True: 0, False: 493k]
  ------------------
  147|      0|        pool->first.next = a;
  148|      0|      }
  149|   493k|      PL_COUNT_ARENA(pool, ++);
  150|   493k|      COUNT(pool, nmallocs);
  151|   493k|      return (rp);
  152|   493k|    }
  153|   493k|  }
  154|       |
  155|       |  /* we got to here, and there's no memory to allocate */
  156|      0|  return (NULL);
  157|   493k|} /* --- end PL_ArenaAllocate() --- */
PL_ClearArenaPool:
  173|   238k|PR_IMPLEMENT(void) PL_ClearArenaPool(PLArenaPool* pool, PRInt32 pattern) {
  174|   238k|  PLArena* a;
  175|       |
  176|   479k|  for (a = pool->first.next; a; a = a->next) {
  ------------------
  |  Branch (176:30): [True: 240k, False: 238k]
  ------------------
  177|   240k|    PR_ASSERT(a->base <= a->avail && a->avail <= a->limit);
  ------------------
  |  |  208|   481k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 240k, False: 0]
  |  |  |  Branch (208:7): [True: 240k, False: 0]
  |  |  ------------------
  ------------------
  178|   240k|    a->avail = a->base;
  179|   240k|    PL_CLEAR_UNUSED_PATTERN(a, pattern);
  ------------------
  |  |  191|   240k|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|   240k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  192|   240k|        PR_ASSERT((a)->avail <= (a)->limit); \
  |  |  ------------------
  |  |  |  |  208|   240k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 240k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  193|   240k|        PL_MAKE_MEM_UNDEFINED((void*)(a)->avail, (a)->limit - (a)->avail); \
  |  |  194|   240k|        memset((void*)(a)->avail, (pattern), (a)->limit - (a)->avail); \
  |  |  195|   240k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|   240k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  180|   240k|    PL_MAKE_MEM_NOACCESS((void*)a->avail, a->limit - a->avail);
  181|   240k|  }
  182|   238k|}
PL_ArenaRelease:
  207|     73|PR_IMPLEMENT(void) PL_ArenaRelease(PLArenaPool* pool, char* mark) {
  208|     73|  PLArena* a;
  209|       |
  210|    146|  for (a = &pool->first; a; a = a->next) {
  ------------------
  |  Branch (210:26): [True: 146, False: 0]
  ------------------
  211|    146|    if (PR_UPTRDIFF(mark, a->base) <= PR_UPTRDIFF(a->avail, a->base)) {
  ------------------
  |  |  188|    146|#define PR_UPTRDIFF(p,q) ((PRUword)(p) - (PRUword)(q))
  ------------------
                  if (PR_UPTRDIFF(mark, a->base) <= PR_UPTRDIFF(a->avail, a->base)) {
  ------------------
  |  |  188|    146|#define PR_UPTRDIFF(p,q) ((PRUword)(p) - (PRUword)(q))
  ------------------
  |  Branch (211:9): [True: 73, False: 73]
  ------------------
  212|     73|      a->avail = (PRUword)PL_ARENA_ALIGN(pool, mark);
  ------------------
  |  |  146|     73|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  ------------------
  213|     73|      FreeArenaList(pool, a);
  214|     73|      return;
  215|     73|    }
  216|    146|  }
  217|     73|}
PL_FreeArenaPool:
  219|   556k|PR_IMPLEMENT(void) PL_FreeArenaPool(PLArenaPool* pool) {
  220|   556k|  FreeArenaList(pool, &pool->first);
  221|   556k|  COUNT(pool, ndeallocs);
  222|   556k|}
PL_FinishArenaPool:
  224|  7.74k|PR_IMPLEMENT(void) PL_FinishArenaPool(PLArenaPool* pool) {
  225|  7.74k|  FreeArenaList(pool, &pool->first);
  226|       |#ifdef PL_ARENAMETER
  227|       |  {
  228|       |    PLArenaStats *stats, **statsp;
  229|       |
  230|       |    if (pool->stats.name) {
  231|       |      PR_DELETE(pool->stats.name);
  232|       |    }
  233|       |    for (statsp = &arena_stats_list; (stats = *statsp) != 0;
  234|       |         statsp = &stats->next) {
  235|       |      if (stats == &pool->stats) {
  236|       |        *statsp = stats->next;
  237|       |        return;
  238|       |      }
  239|       |    }
  240|       |  }
  241|       |#endif
  242|  7.74k|}
plarena.c:FreeArenaList:
  188|   564k|static void FreeArenaList(PLArenaPool* pool, PLArena* head) {
  189|   564k|  PLArena* a = head->next;
  190|   564k|  if (!a) {
  ------------------
  |  Branch (190:7): [True: 77.3k, False: 487k]
  ------------------
  191|  77.3k|    return;
  192|  77.3k|  }
  193|       |
  194|   487k|  head->next = NULL;
  195|       |
  196|   493k|  do {
  197|   493k|    PLArena* tmp = a;
  198|   493k|    a = a->next;
  199|   493k|    PL_CLEAR_ARENA(tmp);
  ------------------
  |  |  200|   493k|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|   493k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  201|   493k|        PL_MAKE_MEM_UNDEFINED((void*)(a), (a)->limit - (PRUword)(a)); \
  |  |  202|   493k|        memset((void*)(a), PL_FREE_PATTERN, (a)->limit - (PRUword)(a)); \
  |  |  ------------------
  |  |  |  |  197|   493k|#define PL_FREE_PATTERN 0xDA
  |  |  ------------------
  |  |  203|   493k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|   493k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  200|   493k|    PL_COUNT_ARENA(pool, --);
  201|   493k|    PR_DELETE(tmp);
  ------------------
  |  |  110|   493k|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  202|   493k|  } while (a);
  ------------------
  |  Branch (202:12): [True: 5.93k, False: 487k]
  ------------------
  203|       |
  204|   487k|  pool->current = head;
  205|   487k|}

PL_NewHashTable:
   58|     17|                void* allocPriv) {
   59|     17|  PLHashTable* ht;
   60|     17|  PRSize nb;
   61|       |
   62|     17|  if (n <= MINBUCKETS) {
  ------------------
  |  |   22|     17|#define MINBUCKETS (1 << MINBUCKETSLOG2)
  |  |  ------------------
  |  |  |  |   21|     17|#define MINBUCKETSLOG2 4
  |  |  ------------------
  ------------------
  |  Branch (62:7): [True: 10, False: 7]
  ------------------
   63|     10|    n = MINBUCKETSLOG2;
  ------------------
  |  |   21|     10|#define MINBUCKETSLOG2 4
  ------------------
   64|     10|  } else {
   65|      7|    n = PR_CeilingLog2(n);
   66|      7|    if ((PRInt32)n < 0) {
  ------------------
  |  Branch (66:9): [True: 0, False: 7]
  ------------------
   67|      0|      return 0;
   68|      0|    }
   69|      7|  }
   70|       |
   71|     17|  if (!allocOps) {
  ------------------
  |  Branch (71:7): [True: 9, False: 8]
  ------------------
   72|      9|    allocOps = &defaultHashAllocOps;
   73|      9|  }
   74|       |
   75|     17|  ht = (PLHashTable*)((*allocOps->allocTable)(allocPriv, sizeof *ht));
   76|     17|  if (!ht) {
  ------------------
  |  Branch (76:7): [True: 0, False: 17]
  ------------------
   77|      0|    return 0;
   78|      0|  }
   79|     17|  memset(ht, 0, sizeof *ht);
   80|     17|  ht->shift = PL_HASH_BITS - n;
  ------------------
  |  |   19|     17|#define PL_HASH_BITS 32  /* Number of bits in PLHashNumber */
  ------------------
   81|     17|  n = 1 << n;
   82|     17|  nb = n * sizeof(PLHashEntry*);
   83|     17|  ht->buckets = (PLHashEntry**)((*allocOps->allocTable)(allocPriv, nb));
   84|     17|  if (!ht->buckets) {
  ------------------
  |  Branch (84:7): [True: 0, False: 17]
  ------------------
   85|      0|    (*allocOps->freeTable)(allocPriv, ht);
   86|      0|    return 0;
   87|      0|  }
   88|     17|  memset(ht->buckets, 0, nb);
   89|       |
   90|     17|  ht->keyHash = keyHash;
   91|     17|  ht->keyCompare = keyCompare;
   92|     17|  ht->valueCompare = valueCompare;
   93|     17|  ht->allocOps = allocOps;
   94|     17|  ht->allocPriv = allocPriv;
   95|     17|  return ht;
   96|     17|}
PL_HashTableDestroy:
   99|     17|PL_HashTableDestroy(PLHashTable* ht) {
  100|     17|  PRUint32 i, n;
  101|     17|  PLHashEntry *he, *next;
  102|     17|  const PLHashAllocOps* allocOps = ht->allocOps;
  103|     17|  void* allocPriv = ht->allocPriv;
  104|       |
  105|     17|  n = NBUCKETS(ht);
  ------------------
  |  |   18|     17|#define NBUCKETS(ht) (1 << (PL_HASH_BITS - (ht)->shift))
  |  |  ------------------
  |  |  |  |   19|     17|#define PL_HASH_BITS 32  /* Number of bits in PLHashNumber */
  |  |  ------------------
  ------------------
  106|  1.05k|  for (i = 0; i < n; i++) {
  ------------------
  |  Branch (106:15): [True: 1.04k, False: 17]
  ------------------
  107|  1.46k|    for (he = ht->buckets[i]; he; he = next) {
  ------------------
  |  Branch (107:31): [True: 428, False: 1.04k]
  ------------------
  108|    428|      next = he->next;
  109|    428|      (*allocOps->freeEntry)(allocPriv, he, HT_FREE_ENTRY);
  ------------------
  |  |   39|    428|#define HT_FREE_ENTRY   1               /* free value and entire entry */
  ------------------
  110|    428|    }
  111|  1.04k|  }
  112|     17|#ifdef DEBUG
  113|     17|  memset(ht->buckets, 0xDB, n * sizeof ht->buckets[0]);
  114|     17|#endif
  115|     17|  (*allocOps->freeTable)(allocPriv, ht->buckets);
  116|     17|#ifdef DEBUG
  117|     17|  memset(ht, 0xDB, sizeof *ht);
  118|     17|#endif
  119|     17|  (*allocOps->freeTable)(allocPriv, ht);
  120|     17|}
PL_HashTableRawLookup:
  128|  90.4k|PL_HashTableRawLookup(PLHashTable* ht, PLHashNumber keyHash, const void* key) {
  129|  90.4k|  PLHashEntry *he, **hep, **hep0;
  130|  90.4k|  PLHashNumber h;
  131|       |
  132|       |#ifdef HASHMETER
  133|       |  ht->nlookups++;
  134|       |#endif
  135|  90.4k|  h = keyHash * GOLDEN_RATIO;
  ------------------
  |  |  125|  90.4k|#define GOLDEN_RATIO 0x9E3779B9U /* 2/(1+sqrt(5))*(2^32) */
  ------------------
  136|  90.4k|  h >>= ht->shift;
  137|  90.4k|  hep = hep0 = &ht->buckets[h];
  138|   111k|  while ((he = *hep) != 0) {
  ------------------
  |  Branch (138:10): [True: 67.8k, False: 43.5k]
  ------------------
  139|  67.8k|    if (he->keyHash == keyHash && (*ht->keyCompare)(key, he->key)) {
  ------------------
  |  Branch (139:9): [True: 46.9k, False: 20.8k]
  |  Branch (139:35): [True: 46.9k, False: 13]
  ------------------
  140|       |      /* Move to front of chain if not already there */
  141|  46.9k|      if (hep != hep0) {
  ------------------
  |  Branch (141:11): [True: 5.67k, False: 41.2k]
  ------------------
  142|  5.67k|        *hep = he->next;
  143|  5.67k|        he->next = *hep0;
  144|  5.67k|        *hep0 = he;
  145|  5.67k|      }
  146|  46.9k|      return hep0;
  147|  46.9k|    }
  148|  20.9k|    hep = &he->next;
  149|       |#ifdef HASHMETER
  150|       |    ht->nsteps++;
  151|       |#endif
  152|  20.9k|  }
  153|  43.5k|  return hep;
  154|  90.4k|}
PL_HashTableRawLookupConst:
  161|  13.2M|                           const void* key) {
  162|  13.2M|  PLHashEntry *he, **hep;
  163|  13.2M|  PLHashNumber h;
  164|       |
  165|       |#ifdef HASHMETER
  166|       |  ht->nlookups++;
  167|       |#endif
  168|  13.2M|  h = keyHash * GOLDEN_RATIO;
  ------------------
  |  |  125|  13.2M|#define GOLDEN_RATIO 0x9E3779B9U /* 2/(1+sqrt(5))*(2^32) */
  ------------------
  169|  13.2M|  h >>= ht->shift;
  170|  13.2M|  hep = &ht->buckets[h];
  171|  13.2M|  while ((he = *hep) != 0) {
  ------------------
  |  Branch (171:10): [True: 13.2M, False: 8.98k]
  ------------------
  172|  13.2M|    if (he->keyHash == keyHash && (*ht->keyCompare)(key, he->key)) {
  ------------------
  |  Branch (172:9): [True: 13.2M, False: 56.7k]
  |  Branch (172:35): [True: 13.2M, False: 151]
  ------------------
  173|  13.2M|      break;
  174|  13.2M|    }
  175|  56.9k|    hep = &he->next;
  176|       |#ifdef HASHMETER
  177|       |    ht->nsteps++;
  178|       |#endif
  179|  56.9k|  }
  180|  13.2M|  return hep;
  181|  13.2M|}
PL_HashTableRawAdd:
  185|  15.9k|                   const void* key, void* value) {
  186|  15.9k|  PRUint32 i, n;
  187|  15.9k|  PLHashEntry *he, *next, **oldbuckets;
  188|  15.9k|  PRSize nb;
  189|       |
  190|       |  /* Grow the table if it is overloaded */
  191|  15.9k|  n = NBUCKETS(ht);
  ------------------
  |  |   18|  15.9k|#define NBUCKETS(ht) (1 << (PL_HASH_BITS - (ht)->shift))
  |  |  ------------------
  |  |  |  |   19|  15.9k|#define PL_HASH_BITS 32  /* Number of bits in PLHashNumber */
  |  |  ------------------
  ------------------
  192|  15.9k|  if (ht->nentries >= OVERLOADED(n)) {
  ------------------
  |  |   25|  15.9k|#define OVERLOADED(n) ((n) - ((n) >> 3))
  ------------------
  |  Branch (192:7): [True: 8, False: 15.9k]
  ------------------
  193|      8|    oldbuckets = ht->buckets;
  194|      8|    nb = 2 * n * sizeof(PLHashEntry*);
  195|      8|    ht->buckets =
  196|      8|        (PLHashEntry**)((*ht->allocOps->allocTable)(ht->allocPriv, nb));
  197|      8|    if (!ht->buckets) {
  ------------------
  |  Branch (197:9): [True: 0, False: 8]
  ------------------
  198|      0|      ht->buckets = oldbuckets;
  199|      0|      return 0;
  200|      0|    }
  201|      8|    memset(ht->buckets, 0, nb);
  202|       |#ifdef HASHMETER
  203|       |    ht->ngrows++;
  204|       |#endif
  205|      8|    ht->shift--;
  206|       |
  207|    616|    for (i = 0; i < n; i++) {
  ------------------
  |  Branch (207:17): [True: 608, False: 8]
  ------------------
  208|  1.14k|      for (he = oldbuckets[i]; he; he = next) {
  ------------------
  |  Branch (208:32): [True: 532, False: 608]
  ------------------
  209|    532|        next = he->next;
  210|    532|        hep = PL_HashTableRawLookup(ht, he->keyHash, he->key);
  211|    532|        PR_ASSERT(*hep == 0);
  ------------------
  |  |  208|    532|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 532, False: 0]
  |  |  ------------------
  ------------------
  212|    532|        he->next = 0;
  213|    532|        *hep = he;
  214|    532|      }
  215|    608|    }
  216|      8|#ifdef DEBUG
  217|      8|    memset(oldbuckets, 0xDB, n * sizeof oldbuckets[0]);
  218|      8|#endif
  219|      8|    (*ht->allocOps->freeTable)(ht->allocPriv, oldbuckets);
  220|      8|    hep = PL_HashTableRawLookup(ht, keyHash, key);
  221|      8|  }
  222|       |
  223|       |  /* Make a new key value entry */
  224|  15.9k|  he = (*ht->allocOps->allocEntry)(ht->allocPriv, key);
  225|  15.9k|  if (!he) {
  ------------------
  |  Branch (225:7): [True: 0, False: 15.9k]
  ------------------
  226|      0|    return 0;
  227|      0|  }
  228|  15.9k|  he->keyHash = keyHash;
  229|  15.9k|  he->key = key;
  230|  15.9k|  he->value = value;
  231|  15.9k|  he->next = *hep;
  232|  15.9k|  *hep = he;
  233|  15.9k|  ht->nentries++;
  234|  15.9k|  return he;
  235|  15.9k|}
PL_HashTableAdd:
  238|  16.0k|PL_HashTableAdd(PLHashTable* ht, const void* key, void* value) {
  239|  16.0k|  PLHashNumber keyHash;
  240|  16.0k|  PLHashEntry *he, **hep;
  241|       |
  242|  16.0k|  keyHash = (*ht->keyHash)(key);
  243|  16.0k|  hep = PL_HashTableRawLookup(ht, keyHash, key);
  244|  16.0k|  if ((he = *hep) != 0) {
  ------------------
  |  Branch (244:7): [True: 71, False: 15.9k]
  ------------------
  245|       |    /* Hit; see if values match */
  246|     71|    if ((*ht->valueCompare)(he->value, value)) {
  ------------------
  |  Branch (246:9): [True: 0, False: 71]
  ------------------
  247|       |      /* key,value pair is already present in table */
  248|      0|      return he;
  249|      0|    }
  250|     71|    if (he->value) {
  ------------------
  |  Branch (250:9): [True: 71, False: 0]
  ------------------
  251|     71|      (*ht->allocOps->freeEntry)(ht->allocPriv, he, HT_FREE_VALUE);
  ------------------
  |  |   38|     71|#define HT_FREE_VALUE   0               /* just free the entry's value */
  ------------------
  252|     71|    }
  253|     71|    he->value = value;
  254|     71|    return he;
  255|     71|  }
  256|  15.9k|  return PL_HashTableRawAdd(ht, hep, keyHash, key, value);
  257|  16.0k|}
PL_HashTableRawRemove:
  260|  15.5k|PL_HashTableRawRemove(PLHashTable* ht, PLHashEntry** hep, PLHashEntry* he) {
  261|  15.5k|  PRUint32 i, n;
  262|  15.5k|  PLHashEntry *next, **oldbuckets;
  263|  15.5k|  PRSize nb;
  264|       |
  265|  15.5k|  *hep = he->next;
  266|  15.5k|  (*ht->allocOps->freeEntry)(ht->allocPriv, he, HT_FREE_ENTRY);
  ------------------
  |  |   39|  15.5k|#define HT_FREE_ENTRY   1               /* free value and entire entry */
  ------------------
  267|       |
  268|       |  /* Shrink table if it's underloaded */
  269|  15.5k|  n = NBUCKETS(ht);
  ------------------
  |  |   18|  15.5k|#define NBUCKETS(ht) (1 << (PL_HASH_BITS - (ht)->shift))
  |  |  ------------------
  |  |  |  |   19|  15.5k|#define PL_HASH_BITS 32  /* Number of bits in PLHashNumber */
  |  |  ------------------
  ------------------
  270|  15.5k|  if (--ht->nentries < UNDERLOADED(n)) {
  ------------------
  |  |   28|  15.5k|#define UNDERLOADED(n) (((n) > MINBUCKETS) ? ((n) >> 2) : 0)
  |  |  ------------------
  |  |  |  |   22|  15.5k|#define MINBUCKETS (1 << MINBUCKETSLOG2)
  |  |  |  |  ------------------
  |  |  |  |  |  |   21|  15.5k|#define MINBUCKETSLOG2 4
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (28:25): [True: 2, False: 15.5k]
  |  |  ------------------
  ------------------
  |  Branch (270:7): [True: 2, False: 15.5k]
  ------------------
  271|      2|    oldbuckets = ht->buckets;
  272|      2|    nb = n * sizeof(PLHashEntry*) / 2;
  273|      2|    ht->buckets =
  274|      2|        (PLHashEntry**)((*ht->allocOps->allocTable)(ht->allocPriv, nb));
  275|      2|    if (!ht->buckets) {
  ------------------
  |  Branch (275:9): [True: 0, False: 2]
  ------------------
  276|      0|      ht->buckets = oldbuckets;
  277|      0|      return;
  278|      0|    }
  279|      2|    memset(ht->buckets, 0, nb);
  280|       |#ifdef HASHMETER
  281|       |    ht->nshrinks++;
  282|       |#endif
  283|      2|    ht->shift++;
  284|       |
  285|     98|    for (i = 0; i < n; i++) {
  ------------------
  |  Branch (285:17): [True: 96, False: 2]
  ------------------
  286|     97|      for (he = oldbuckets[i]; he; he = next) {
  ------------------
  |  Branch (286:32): [True: 1, False: 96]
  ------------------
  287|      1|        next = he->next;
  288|      1|        hep = PL_HashTableRawLookup(ht, he->keyHash, he->key);
  289|      1|        PR_ASSERT(*hep == 0);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  290|      1|        he->next = 0;
  291|      1|        *hep = he;
  292|      1|      }
  293|     96|    }
  294|      2|#ifdef DEBUG
  295|      2|    memset(oldbuckets, 0xDB, n * sizeof oldbuckets[0]);
  296|      2|#endif
  297|      2|    (*ht->allocOps->freeTable)(ht->allocPriv, oldbuckets);
  298|      2|  }
  299|  15.5k|}
PL_HashTableRemove:
  302|  15.5k|PL_HashTableRemove(PLHashTable* ht, const void* key) {
  303|  15.5k|  PLHashNumber keyHash;
  304|  15.5k|  PLHashEntry *he, **hep;
  305|       |
  306|  15.5k|  keyHash = (*ht->keyHash)(key);
  307|  15.5k|  hep = PL_HashTableRawLookup(ht, keyHash, key);
  308|  15.5k|  if ((he = *hep) == 0) {
  ------------------
  |  Branch (308:7): [True: 0, False: 15.5k]
  ------------------
  309|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  310|      0|  }
  311|       |
  312|       |  /* Hit; remove element */
  313|  15.5k|  PL_HashTableRawRemove(ht, hep, he);
  314|  15.5k|  return PR_TRUE;
  ------------------
  |  |  437|  15.5k|#define PR_TRUE 1
  ------------------
  315|  15.5k|}
PL_HashTableLookup:
  318|  58.3k|PL_HashTableLookup(PLHashTable* ht, const void* key) {
  319|  58.3k|  PLHashNumber keyHash;
  320|  58.3k|  PLHashEntry *he, **hep;
  321|       |
  322|  58.3k|  keyHash = (*ht->keyHash)(key);
  323|  58.3k|  hep = PL_HashTableRawLookup(ht, keyHash, key);
  324|  58.3k|  if ((he = *hep) != 0) {
  ------------------
  |  Branch (324:7): [True: 31.3k, False: 27.0k]
  ------------------
  325|  31.3k|    return he->value;
  326|  31.3k|  }
  327|  27.0k|  return 0;
  328|  58.3k|}
PL_HashTableLookupConst:
  334|  13.2M|PL_HashTableLookupConst(PLHashTable* ht, const void* key) {
  335|  13.2M|  PLHashNumber keyHash;
  336|  13.2M|  PLHashEntry *he, **hep;
  337|       |
  338|  13.2M|  keyHash = (*ht->keyHash)(key);
  339|  13.2M|  hep = PL_HashTableRawLookupConst(ht, keyHash, key);
  340|  13.2M|  if ((he = *hep) != 0) {
  ------------------
  |  Branch (340:7): [True: 13.2M, False: 8.98k]
  ------------------
  341|  13.2M|    return he->value;
  342|  13.2M|  }
  343|  8.98k|  return 0;
  344|  13.2M|}
PL_HashTableEnumerateEntries:
  352|      5|PL_HashTableEnumerateEntries(PLHashTable* ht, PLHashEnumerator f, void* arg) {
  353|      5|  PLHashEntry *he, **hep;
  354|      5|  PRUint32 i, nbuckets;
  355|      5|  int rv, n = 0;
  356|      5|  PLHashEntry* todo = 0;
  357|       |
  358|      5|  nbuckets = NBUCKETS(ht);
  ------------------
  |  |   18|      5|#define NBUCKETS(ht) (1 << (PL_HASH_BITS - (ht)->shift))
  |  |  ------------------
  |  |  |  |   19|      5|#define PL_HASH_BITS 32  /* Number of bits in PLHashNumber */
  |  |  ------------------
  ------------------
  359|    197|  for (i = 0; i < nbuckets; i++) {
  ------------------
  |  Branch (359:15): [True: 192, False: 5]
  ------------------
  360|    192|    hep = &ht->buckets[i];
  361|    192|    while ((he = *hep) != 0) {
  ------------------
  |  Branch (361:12): [True: 0, False: 192]
  ------------------
  362|      0|      rv = (*f)(he, n, arg);
  363|      0|      n++;
  364|      0|      if (rv & (HT_ENUMERATE_REMOVE | HT_ENUMERATE_UNHASH)) {
  ------------------
  |  |   28|      0|#define HT_ENUMERATE_REMOVE     2       /* remove and free the current entry */
  ------------------
                    if (rv & (HT_ENUMERATE_REMOVE | HT_ENUMERATE_UNHASH)) {
  ------------------
  |  |   29|      0|#define HT_ENUMERATE_UNHASH     4       /* just unhash the current entry */
  ------------------
  |  Branch (364:11): [True: 0, False: 0]
  ------------------
  365|      0|        *hep = he->next;
  366|      0|        if (rv & HT_ENUMERATE_REMOVE) {
  ------------------
  |  |   28|      0|#define HT_ENUMERATE_REMOVE     2       /* remove and free the current entry */
  ------------------
  |  Branch (366:13): [True: 0, False: 0]
  ------------------
  367|      0|          he->next = todo;
  368|      0|          todo = he;
  369|      0|        }
  370|      0|      } else {
  371|      0|        hep = &he->next;
  372|      0|      }
  373|      0|      if (rv & HT_ENUMERATE_STOP) {
  ------------------
  |  |   27|      0|#define HT_ENUMERATE_STOP       1       /* stop enumerating entries */
  ------------------
  |  Branch (373:11): [True: 0, False: 0]
  ------------------
  374|      0|        goto out;
  375|      0|      }
  376|      0|    }
  377|    192|  }
  378|       |
  379|      5|out:
  380|      5|  hep = &todo;
  381|      5|  while ((he = *hep) != 0) {
  ------------------
  |  Branch (381:10): [True: 0, False: 5]
  ------------------
  382|      0|    PL_HashTableRawRemove(ht, hep, he);
  383|      0|  }
  384|      5|  return n;
  385|      5|}
PL_CompareValues:
  468|  13.0M|PL_CompareValues(const void* v1, const void* v2) { return v1 == v2; }
plhash.c:DefaultAllocTable:
   33|     28|static void* PR_CALLBACK DefaultAllocTable(void* pool, PRSize size) {
   34|     28|  return PR_MALLOC(size);
  ------------------
  |  |   55|     28|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  ------------------
   35|     28|}
plhash.c:DefaultFreeTable:
   37|     28|static void PR_CALLBACK DefaultFreeTable(void* pool, void* item) {
   38|     28|  PR_Free(item);
   39|     28|}
plhash.c:DefaultAllocEntry:
   41|  8.17k|static PLHashEntry* PR_CALLBACK DefaultAllocEntry(void* pool, const void* key) {
   42|  8.17k|  return PR_NEW(PLHashEntry);
  ------------------
  |  |   65|  8.17k|#define PR_NEW(_struct) ((_struct *) PR_MALLOC(sizeof(_struct)))
  |  |  ------------------
  |  |  |  |   55|  8.17k|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  |  |  ------------------
  ------------------
   43|  8.17k|}
plhash.c:DefaultFreeEntry:
   46|  8.24k|                                         PRUintn flag) {
   47|  8.24k|  if (flag == HT_FREE_ENTRY) {
  ------------------
  |  |   39|  8.24k|#define HT_FREE_ENTRY   1               /* free value and entire entry */
  ------------------
  |  Branch (47:7): [True: 8.17k, False: 71]
  ------------------
   48|  8.17k|    PR_Free(he);
   49|  8.17k|  }
   50|  8.24k|}

PL_strcasecmp:
   41|      3|PL_strcasecmp(const char* a, const char* b) {
   42|      3|  const unsigned char* ua = (const unsigned char*)a;
   43|      3|  const unsigned char* ub = (const unsigned char*)b;
   44|       |
   45|      3|  if ((const char*)0 == a) {
  ------------------
  |  Branch (45:7): [True: 0, False: 3]
  ------------------
   46|      0|    return ((const char*)0 == b) ? 0 : -1;
  ------------------
  |  Branch (46:12): [True: 0, False: 0]
  ------------------
   47|      0|  }
   48|      3|  if ((const char*)0 == b) {
  ------------------
  |  Branch (48:7): [True: 0, False: 3]
  ------------------
   49|      0|    return 1;
   50|      0|  }
   51|       |
   52|      3|  while ((uc[*ua] == uc[*ub]) && ('\0' != *a)) {
  ------------------
  |  Branch (52:10): [True: 0, False: 3]
  |  Branch (52:34): [True: 0, False: 0]
  ------------------
   53|      0|    a++;
   54|      0|    ua++;
   55|      0|    ub++;
   56|      0|  }
   57|       |
   58|      3|  return (PRIntn)(uc[*ua] - uc[*ub]);
   59|      3|}
PL_strncasecmp:
   62|    798|PL_strncasecmp(const char* a, const char* b, PRUint32 max) {
   63|    798|  const unsigned char* ua = (const unsigned char*)a;
   64|    798|  const unsigned char* ub = (const unsigned char*)b;
   65|       |
   66|    798|  if ((const char*)0 == a) {
  ------------------
  |  Branch (66:7): [True: 0, False: 798]
  ------------------
   67|      0|    return ((const char*)0 == b) ? 0 : -1;
  ------------------
  |  Branch (67:12): [True: 0, False: 0]
  ------------------
   68|      0|  }
   69|    798|  if ((const char*)0 == b) {
  ------------------
  |  Branch (69:7): [True: 0, False: 798]
  ------------------
   70|      0|    return 1;
   71|      0|  }
   72|       |
   73|  1.65k|  while (max && (uc[*ua] == uc[*ub]) && ('\0' != *a)) {
  ------------------
  |  Branch (73:10): [True: 1.55k, False: 99]
  |  Branch (73:17): [True: 855, False: 699]
  |  Branch (73:41): [True: 855, False: 0]
  ------------------
   74|    855|    a++;
   75|    855|    ua++;
   76|    855|    ub++;
   77|    855|    max--;
   78|    855|  }
   79|       |
   80|    798|  if (0 == max) {
  ------------------
  |  Branch (80:7): [True: 99, False: 699]
  ------------------
   81|     99|    return (PRIntn)0;
   82|     99|  }
   83|       |
   84|    699|  return (PRIntn)(uc[*ua] - uc[*ub]);
   85|    798|}

PL_strlen:
   12|     51|PL_strlen(const char* str) {
   13|     51|  size_t l;
   14|       |
   15|     51|  if ((const char*)0 == str) {
  ------------------
  |  Branch (15:7): [True: 0, False: 51]
  ------------------
   16|      0|    return 0;
   17|      0|  }
   18|       |
   19|     51|  l = strlen(str);
   20|       |
   21|       |  /* error checking in case we have a 64-bit platform -- make sure
   22|       |   * we don't have ultra long strings that overflow an int32
   23|       |   */
   24|     51|  if (sizeof(PRUint32) < sizeof(size_t)) {
  ------------------
  |  Branch (24:7): [Folded - Ignored]
  ------------------
   25|     51|    if (l > PR_INT32_MAX) {
  ------------------
  |  |  300|     51|#define PR_INT32_MAX PR_INT32(2147483647)
  |  |  ------------------
  |  |  |  |  281|     51|#define PR_INT32(x)  x
  |  |  ------------------
  ------------------
  |  Branch (25:9): [True: 0, False: 51]
  ------------------
   26|      0|      PR_Assert("l <= PR_INT32_MAX", __FILE__, __LINE__);
   27|      0|    }
   28|     51|  }
   29|       |
   30|     51|  return (PRUint32)l;
   31|     51|}

_PR_Getfd:
   43|      4|PRFileDesc* _PR_Getfd(void) {
   44|      4|  PRFileDesc* fd;
   45|       |  /*
   46|       |  ** $$$
   47|       |  ** This may look a little wasteful. We'll see. Right now I want to
   48|       |  ** be able to toggle between caching and not at runtime to measure
   49|       |  ** the differences. If it isn't too annoying, I'll leave it in.
   50|       |  ** $$$$
   51|       |  **
   52|       |  ** The test is against _pr_fd_cache.limit_high. If that's zero,
   53|       |  ** we're not doing the extended cache but going for performance.
   54|       |  */
   55|      4|  if (0 == _pr_fd_cache.limit_high) {
  ------------------
  |  Branch (55:7): [True: 0, False: 4]
  ------------------
   56|      0|    goto allocate;
   57|      4|  } else {
   58|      4|    do {
   59|      4|      if (NULL == _pr_fd_cache.head) {
  ------------------
  |  Branch (59:11): [True: 4, False: 0]
  ------------------
   60|      4|        goto allocate; /* nothing there */
   61|      4|      }
   62|      0|      if (_pr_fd_cache.count < _pr_fd_cache.limit_low) {
  ------------------
  |  Branch (62:11): [True: 0, False: 0]
  ------------------
   63|      0|        goto allocate;
   64|      0|      }
   65|       |
   66|       |      /* we "should" be able to extract an fd from the cache */
   67|      0|      PR_Lock(_pr_fd_cache.ml); /* need the lock to do this safely */
   68|      0|      fd = _pr_fd_cache.head;   /* protected extraction */
   69|      0|      if (NULL == fd)           /* unexpected, but not fatal */
  ------------------
  |  Branch (69:11): [True: 0, False: 0]
  ------------------
   70|      0|      {
   71|      0|        PR_ASSERT(0 == _pr_fd_cache.count);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   72|      0|        PR_ASSERT(NULL == _pr_fd_cache.tail);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   73|      0|      } else {
   74|      0|        _pr_fd_cache.count -= 1;
   75|      0|        _pr_fd_cache.head = fd->higher;
   76|      0|        if (NULL == _pr_fd_cache.head) {
  ------------------
  |  Branch (76:13): [True: 0, False: 0]
  ------------------
   77|      0|          PR_ASSERT(0 == _pr_fd_cache.count);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   78|      0|          _pr_fd_cache.tail = NULL;
   79|      0|        }
   80|      0|        PR_ASSERT(&_pr_faulty_methods == fd->methods);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   81|      0|        PR_ASSERT(PR_INVALID_IO_LAYER == fd->identity);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   82|      0|        PR_ASSERT(_PR_FILEDESC_FREED == fd->secret->state);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   83|      0|      }
   84|      0|      PR_Unlock(_pr_fd_cache.ml);
   85|       |
   86|      0|    } while (NULL == fd); /* then go around and allocate a new one */
  ------------------
  |  Branch (86:14): [True: 0, False: 0]
  ------------------
   87|      4|  }
   88|       |
   89|      4|finished:
   90|      4|  fd->dtor = NULL;
   91|      4|  fd->lower = fd->higher = NULL;
   92|      4|  fd->identity = PR_NSPR_IO_LAYER;
  ------------------
  |  |  454|      4|#define PR_NSPR_IO_LAYER (PRDescIdentity)0
  ------------------
   93|      4|  memset(fd->secret, 0, sizeof(PRFilePrivate));
   94|      4|  return fd;
   95|       |
   96|      4|allocate:
   97|      4|  fd = PR_NEW(PRFileDesc);
  ------------------
  |  |   65|      4|#define PR_NEW(_struct) ((_struct *) PR_MALLOC(sizeof(_struct)))
  |  |  ------------------
  |  |  |  |   55|      4|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  |  |  ------------------
  ------------------
   98|      4|  if (NULL != fd) {
  ------------------
  |  Branch (98:7): [True: 4, False: 0]
  ------------------
   99|      4|    fd->secret = PR_NEW(PRFilePrivate);
  ------------------
  |  |   65|      4|#define PR_NEW(_struct) ((_struct *) PR_MALLOC(sizeof(_struct)))
  |  |  ------------------
  |  |  |  |   55|      4|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  |  |  ------------------
  ------------------
  100|      4|    if (NULL == fd->secret) {
  ------------------
  |  Branch (100:9): [True: 0, False: 4]
  ------------------
  101|      0|      PR_DELETE(fd);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  102|      0|    }
  103|      4|  }
  104|      4|  if (NULL != fd) {
  ------------------
  |  Branch (104:7): [True: 4, False: 0]
  ------------------
  105|      4|    goto finished;
  106|      4|  } else {
  107|      0|    return NULL;
  108|      0|  }
  109|       |
  110|      4|} /* _PR_Getfd */
_PR_Putfd:
  116|      1|void _PR_Putfd(PRFileDesc* fd) {
  117|      1|  PR_ASSERT(PR_NSPR_IO_LAYER == fd->identity);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  118|      1|  fd->methods = &_pr_faulty_methods;
  119|      1|  fd->identity = PR_INVALID_IO_LAYER;
  ------------------
  |  |  452|      1|#define PR_INVALID_IO_LAYER (PRDescIdentity)-1
  ------------------
  120|      1|  fd->secret->state = _PR_FILEDESC_FREED;
  ------------------
  |  | 1704|      1|#define _PR_FILEDESC_FREED      0x11111111
  ------------------
  121|       |
  122|      1|  if (0 != _pr_fd_cache.limit_high) {
  ------------------
  |  Branch (122:7): [True: 1, False: 0]
  ------------------
  123|      1|    if (_pr_fd_cache.count < _pr_fd_cache.limit_high) {
  ------------------
  |  Branch (123:9): [True: 1, False: 0]
  ------------------
  124|      1|      PR_Lock(_pr_fd_cache.ml);
  125|      1|      if (NULL == _pr_fd_cache.tail) {
  ------------------
  |  Branch (125:11): [True: 1, False: 0]
  ------------------
  126|      1|        PR_ASSERT(0 == _pr_fd_cache.count);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  127|      1|        PR_ASSERT(NULL == _pr_fd_cache.head);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  128|      1|        _pr_fd_cache.head = _pr_fd_cache.tail = fd;
  129|      1|      } else {
  130|      0|        PR_ASSERT(NULL == _pr_fd_cache.tail->higher);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  131|      0|        _pr_fd_cache.tail->higher = fd;
  132|      0|        _pr_fd_cache.tail = fd; /* new value */
  133|      0|      }
  134|      1|      fd->higher = NULL;       /* always so */
  135|      1|      _pr_fd_cache.count += 1; /* count the new entry */
  136|      1|      PR_Unlock(_pr_fd_cache.ml);
  137|      1|      return;
  138|      1|    }
  139|      1|  }
  140|       |
  141|      0|  PR_Free(fd->secret);
  142|      0|  PR_Free(fd);
  143|      0|} /* _PR_Putfd */
_PR_InitFdCache:
  166|      1|void _PR_InitFdCache(void) {
  167|       |  /*
  168|       |  ** The fd caching is enabled by default for DEBUG builds,
  169|       |  ** disabled by default for OPT builds. That default can
  170|       |  ** be overridden at runtime using environment variables
  171|       |  ** or a super-wiz-bang API.
  172|       |  */
  173|      1|  const char* low = PR_GetEnv("NSPR_FD_CACHE_SIZE_LOW");
  174|      1|  const char* high = PR_GetEnv("NSPR_FD_CACHE_SIZE_HIGH");
  175|       |
  176|       |  /*
  177|       |  ** _low is allowed to be zero, _high is not.
  178|       |  ** If _high is zero, we're not doing the caching.
  179|       |  */
  180|       |
  181|      1|  _pr_fd_cache.limit_low = 0;
  182|      1|#if defined(DEBUG)
  183|      1|  _pr_fd_cache.limit_high = FD_SETSIZE;
  184|       |#else
  185|       |  _pr_fd_cache.limit_high = 0;
  186|       |#endif /* defined(DEBUG) */
  187|       |
  188|      1|  if (NULL != low) {
  ------------------
  |  Branch (188:7): [True: 0, False: 1]
  ------------------
  189|      0|    _pr_fd_cache.limit_low = atoi(low);
  190|      0|  }
  191|      1|  if (NULL != high) {
  ------------------
  |  Branch (191:7): [True: 0, False: 1]
  ------------------
  192|      0|    _pr_fd_cache.limit_high = atoi(high);
  193|      0|  }
  194|       |
  195|      1|  if (_pr_fd_cache.limit_low < 0) {
  ------------------
  |  Branch (195:7): [True: 0, False: 1]
  ------------------
  196|      0|    _pr_fd_cache.limit_low = 0;
  197|      0|  }
  198|      1|  if (_pr_fd_cache.limit_low > FD_SETSIZE) {
  ------------------
  |  Branch (198:7): [True: 0, False: 1]
  ------------------
  199|      0|    _pr_fd_cache.limit_low = FD_SETSIZE;
  200|      0|  }
  201|       |
  202|      1|  if (_pr_fd_cache.limit_high > FD_SETSIZE) {
  ------------------
  |  Branch (202:7): [True: 0, False: 1]
  ------------------
  203|      0|    _pr_fd_cache.limit_high = FD_SETSIZE;
  204|      0|  }
  205|       |
  206|      1|  if (_pr_fd_cache.limit_high < _pr_fd_cache.limit_low) {
  ------------------
  |  Branch (206:7): [True: 0, False: 1]
  ------------------
  207|      0|    _pr_fd_cache.limit_high = _pr_fd_cache.limit_low;
  208|      0|  }
  209|       |
  210|      1|  _pr_fd_cache.ml = PR_NewLock();
  211|      1|  PR_ASSERT(NULL != _pr_fd_cache.ml);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  212|       |
  213|      1|} /* _PR_InitFdCache */

PR_Close:
   94|  9.71k|PR_IMPLEMENT(PRStatus) PR_Close(PRFileDesc* fd) {
   95|  9.71k|  return (fd->methods->close)(fd);
   96|  9.71k|}
PR_Read:
   98|   159k|PR_IMPLEMENT(PRInt32) PR_Read(PRFileDesc* fd, void* buf, PRInt32 amount) {
   99|   159k|  return ((fd->methods->read)(fd, buf, amount));
  100|   159k|}
PR_Write:
  103|   156k|PR_Write(PRFileDesc* fd, const void* buf, PRInt32 amount) {
  104|   156k|  return ((fd->methods->write)(fd, buf, amount));
  105|   156k|}
PR_GetSocketOption:
  219|   169k|PR_GetSocketOption(PRFileDesc* fd, PRSocketOptionData* data) {
  220|   169k|  return ((fd->methods->getsocketoption)(fd, data));
  221|   169k|}

pl_FDDestructor:
   21|  19.4k|void PR_CALLBACK pl_FDDestructor(PRFileDesc* fd) {
   22|  19.4k|  PR_ASSERT(fd != NULL);
  ------------------
  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 19.4k, False: 0]
  |  |  ------------------
  ------------------
   23|  19.4k|  if (NULL != fd->lower) {
  ------------------
  |  Branch (23:7): [True: 0, False: 19.4k]
  ------------------
   24|      0|    fd->lower->higher = fd->higher;
   25|      0|  }
   26|  19.4k|  if (NULL != fd->higher) {
  ------------------
  |  Branch (26:7): [True: 0, False: 19.4k]
  ------------------
   27|      0|    fd->higher->lower = fd->lower;
   28|      0|  }
   29|  19.4k|  PR_DELETE(fd);
  ------------------
  |  |  110|  19.4k|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
   30|  19.4k|}
PR_GetDefaultIOMethods:
  403|      1|PR_IMPLEMENT(const PRIOMethods*) PR_GetDefaultIOMethods(void) {
  404|      1|  return &pl_methods;
  405|      1|} /* PR_GetDefaultIOMethods */
PR_CreateIOLayerStub:
  408|  19.4k|PR_CreateIOLayerStub(PRDescIdentity ident, const PRIOMethods* methods) {
  409|  19.4k|  PRFileDesc* fd = NULL;
  410|  19.4k|  PR_ASSERT((PR_NSPR_IO_LAYER != ident) && (PR_TOP_IO_LAYER != ident));
  ------------------
  |  |  208|  38.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 19.4k, False: 0]
  |  |  |  Branch (208:7): [True: 19.4k, False: 0]
  |  |  ------------------
  ------------------
  411|  19.4k|  if ((PR_NSPR_IO_LAYER == ident) || (PR_TOP_IO_LAYER == ident)) {
  ------------------
  |  |  454|  19.4k|#define PR_NSPR_IO_LAYER (PRDescIdentity)0
  ------------------
                if ((PR_NSPR_IO_LAYER == ident) || (PR_TOP_IO_LAYER == ident)) {
  ------------------
  |  |  453|  19.4k|#define PR_TOP_IO_LAYER (PRDescIdentity)-2
  ------------------
  |  Branch (411:7): [True: 0, False: 19.4k]
  |  Branch (411:38): [True: 0, False: 19.4k]
  ------------------
  412|      0|    PR_SetError(PR_INVALID_ARGUMENT_ERROR, 0);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  413|  19.4k|  } else {
  414|  19.4k|    fd = PR_NEWZAP(PRFileDesc);
  ------------------
  |  |   99|  19.4k|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  415|  19.4k|    if (NULL == fd) {
  ------------------
  |  Branch (415:9): [True: 0, False: 19.4k]
  ------------------
  416|      0|      PR_SetError(PR_OUT_OF_MEMORY_ERROR, 0);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  417|  19.4k|    } else {
  418|  19.4k|      fd->methods = methods;
  419|  19.4k|      fd->dtor = pl_FDDestructor;
  420|  19.4k|      fd->identity = ident;
  421|  19.4k|    }
  422|  19.4k|  }
  423|  19.4k|  return fd;
  424|  19.4k|} /* PR_CreateIOLayerStub */
PR_PushIOLayer:
  467|  9.71k|PR_PushIOLayer(PRFileDesc* stack, PRDescIdentity id, PRFileDesc* fd) {
  468|  9.71k|  PRFileDesc* insert = PR_GetIdentitiesLayer(stack, id);
  469|       |
  470|  9.71k|  PR_ASSERT(fd != NULL);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  471|  9.71k|  PR_ASSERT(stack != NULL);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  472|  9.71k|  PR_ASSERT(insert != NULL);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  473|  9.71k|  PR_ASSERT(PR_IO_LAYER_HEAD != id);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  474|  9.71k|  if ((NULL == stack) || (NULL == fd) || (NULL == insert)) {
  ------------------
  |  Branch (474:7): [True: 0, False: 9.71k]
  |  Branch (474:26): [True: 0, False: 9.71k]
  |  Branch (474:42): [True: 0, False: 9.71k]
  ------------------
  475|      0|    PR_SetError(PR_INVALID_ARGUMENT_ERROR, 0);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  476|      0|    return PR_FAILURE;
  477|      0|  }
  478|       |
  479|  9.71k|  if (stack == insert) {
  ------------------
  |  Branch (479:7): [True: 9.71k, False: 0]
  ------------------
  480|       |    /* going on top of the stack */
  481|       |    /* old-style stack */
  482|  9.71k|    PRFileDesc copy = *stack;
  483|  9.71k|    *stack = *fd;
  484|  9.71k|    *fd = copy;
  485|  9.71k|    fd->higher = stack;
  486|  9.71k|    if (fd->lower) {
  ------------------
  |  Branch (486:9): [True: 0, False: 9.71k]
  ------------------
  487|      0|      PR_ASSERT(fd->lower->higher == stack);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  488|      0|      fd->lower->higher = fd;
  489|      0|    }
  490|  9.71k|    stack->lower = fd;
  491|  9.71k|    stack->higher = NULL;
  492|  9.71k|  } else {
  493|       |    /*
  494|       |     * going somewhere in the middle of the stack for both old and new
  495|       |     * style stacks, or going on top of stack for new style stack
  496|       |     */
  497|      0|    fd->lower = insert;
  498|      0|    fd->higher = insert->higher;
  499|       |
  500|      0|    insert->higher->lower = fd;
  501|      0|    insert->higher = fd;
  502|      0|  }
  503|       |
  504|  9.71k|  return PR_SUCCESS;
  505|  9.71k|}
PR_PopIOLayer:
  507|  9.71k|PR_IMPLEMENT(PRFileDesc*) PR_PopIOLayer(PRFileDesc* stack, PRDescIdentity id) {
  508|  9.71k|  PRFileDesc* extract = PR_GetIdentitiesLayer(stack, id);
  509|       |
  510|  9.71k|  PR_ASSERT(0 != id);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  511|  9.71k|  PR_ASSERT(NULL != stack);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  512|  9.71k|  PR_ASSERT(NULL != extract);
  ------------------
  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
  513|  9.71k|  if ((NULL == stack) || (0 == id) || (NULL == extract)) {
  ------------------
  |  Branch (513:7): [True: 0, False: 9.71k]
  |  Branch (513:26): [True: 0, False: 9.71k]
  |  Branch (513:39): [True: 0, False: 9.71k]
  ------------------
  514|      0|    PR_SetError(PR_INVALID_ARGUMENT_ERROR, 0);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  515|      0|    return NULL;
  516|      0|  }
  517|       |
  518|  9.71k|  if (extract == stack) {
  ------------------
  |  Branch (518:7): [True: 9.71k, False: 0]
  ------------------
  519|       |    /* popping top layer of the stack */
  520|       |    /* old style stack */
  521|  9.71k|    PRFileDesc copy = *stack;
  522|  9.71k|    extract = stack->lower;
  523|  9.71k|    *stack = *extract;
  524|  9.71k|    *extract = copy;
  525|  9.71k|    stack->higher = NULL;
  526|  9.71k|    if (stack->lower) {
  ------------------
  |  Branch (526:9): [True: 0, False: 9.71k]
  ------------------
  527|      0|      PR_ASSERT(stack->lower->higher == extract);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  528|      0|      stack->lower->higher = stack;
  529|      0|    }
  530|  9.71k|  } else if ((PR_IO_LAYER_HEAD == stack->identity) &&
  ------------------
  |  |  451|      0|#define PR_IO_LAYER_HEAD (PRDescIdentity)-3
  ------------------
  |  Branch (530:14): [True: 0, False: 0]
  ------------------
  531|      0|             (extract == stack->lower) && (extract->lower == NULL)) {
  ------------------
  |  Branch (531:14): [True: 0, False: 0]
  |  Branch (531:43): [True: 0, False: 0]
  ------------------
  532|       |    /*
  533|       |     * new style stack
  534|       |     * popping the only layer in the stack; delete the stack too
  535|       |     */
  536|      0|    stack->lower = NULL;
  537|      0|    _PR_DestroyIOLayer(stack);
  538|      0|  } else {
  539|       |    /* for both kinds of stacks */
  540|      0|    extract->lower->higher = extract->higher;
  541|      0|    extract->higher->lower = extract->lower;
  542|      0|  }
  543|  9.71k|  extract->higher = extract->lower = NULL;
  544|  9.71k|  return extract;
  545|  9.71k|} /* PR_PopIOLayer */
PR_GetUniqueIdentity:
  557|      2|PR_IMPLEMENT(PRDescIdentity) PR_GetUniqueIdentity(const char* layer_name) {
  558|      2|  PRDescIdentity identity, length;
  559|      2|  char **names = NULL, *name = NULL, **old = NULL;
  560|       |
  561|      2|  if (!_pr_initialized) {
  ------------------
  |  Branch (561:7): [True: 0, False: 2]
  ------------------
  562|      0|    _PR_ImplicitInitialization();
  563|      0|  }
  564|       |
  565|      2|  PR_ASSERT((PRDescIdentity)((1UL << ((sizeof(PRDescIdentity) * 8) - 1)) - 1)
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  566|      2|            > identity_cache.ident);
  567|       |
  568|      2|  if (NULL != layer_name) {
  ------------------
  |  Branch (568:7): [True: 2, False: 0]
  ------------------
  569|      2|    name = (char*)PR_Malloc(strlen(layer_name) + 1);
  570|      2|    if (NULL == name) {
  ------------------
  |  Branch (570:9): [True: 0, False: 2]
  ------------------
  571|      0|      PR_SetError(PR_OUT_OF_MEMORY_ERROR, 0);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  572|      0|      return PR_INVALID_IO_LAYER;
  ------------------
  |  |  452|      0|#define PR_INVALID_IO_LAYER (PRDescIdentity)-1
  ------------------
  573|      0|    }
  574|      2|    strcpy(name, layer_name);
  575|      2|  }
  576|       |
  577|       |  /* this initial code runs unsafe */
  578|      2|retry:
  579|      2|  PR_ASSERT(NULL == names);
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  580|       |  /*
  581|       |   * In the initial round, both identity_cache.ident and
  582|       |   * identity_cache.length are 0, so (identity_cache.ident + 1) is greater
  583|       |   * than length.  In later rounds, identity_cache.ident is always less
  584|       |   * than length, so (identity_cache.ident + 1) can be equal to but cannot
  585|       |   * be greater than length.
  586|       |   */
  587|      2|  length = identity_cache.length;
  588|      2|  if ((identity_cache.ident + 1) >= length) {
  ------------------
  |  Branch (588:7): [True: 1, False: 1]
  ------------------
  589|      1|    length += ID_CACHE_INCREMENT;
  ------------------
  |  |  547|      1|#define ID_CACHE_INCREMENT 16
  ------------------
  590|      1|    names = (char**)PR_CALLOC(length * sizeof(char*));
  ------------------
  |  |   88|      1|#define PR_CALLOC(_size) (PR_Calloc(1, (_size)))
  ------------------
  591|      1|    if (NULL == names) {
  ------------------
  |  Branch (591:9): [True: 0, False: 1]
  ------------------
  592|      0|      if (NULL != name) {
  ------------------
  |  Branch (592:11): [True: 0, False: 0]
  ------------------
  593|      0|        PR_DELETE(name);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  594|      0|      }
  595|      0|      PR_SetError(PR_OUT_OF_MEMORY_ERROR, 0);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  596|      0|      return PR_INVALID_IO_LAYER;
  ------------------
  |  |  452|      0|#define PR_INVALID_IO_LAYER (PRDescIdentity)-1
  ------------------
  597|      0|    }
  598|      1|  }
  599|       |
  600|       |  /* now we get serious about thread safety */
  601|      2|  PR_Lock(identity_cache.ml);
  602|      2|  PR_ASSERT(identity_cache.length == 0 ||
  ------------------
  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 1, False: 1]
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  603|      2|            identity_cache.ident < identity_cache.length);
  604|      2|  identity = identity_cache.ident + 1;
  605|      2|  if (identity >= identity_cache.length) /* there's no room */
  ------------------
  |  Branch (605:7): [True: 1, False: 1]
  ------------------
  606|      1|  {
  607|       |    /* we have to do something - hopefully it's already done */
  608|      1|    if ((NULL != names) && (identity < length)) {
  ------------------
  |  Branch (608:9): [True: 1, False: 0]
  |  Branch (608:28): [True: 1, False: 0]
  ------------------
  609|       |      /* what we did is still okay */
  610|      1|      if (identity_cache.length != 0) {
  ------------------
  |  Branch (610:11): [True: 0, False: 1]
  ------------------
  611|      0|        memcpy(names, identity_cache.name,
  612|      0|               identity_cache.length * sizeof(char*));
  613|      0|      }
  614|      1|      old = identity_cache.name;
  615|      1|      identity_cache.name = names;
  616|      1|      identity_cache.length = length;
  617|      1|      names = NULL;
  618|      1|    } else {
  619|      0|      PR_Unlock(identity_cache.ml);
  620|      0|      if (NULL != names) {
  ------------------
  |  Branch (620:11): [True: 0, False: 0]
  ------------------
  621|      0|        PR_DELETE(names);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  622|      0|      }
  623|      0|      goto retry;
  624|      0|    }
  625|      1|  }
  626|      2|  if (NULL != name) /* there's a name to be stored */
  ------------------
  |  Branch (626:7): [True: 2, False: 0]
  ------------------
  627|      2|  {
  628|      2|    identity_cache.name[identity] = name;
  629|      2|  }
  630|      2|  identity_cache.ident = identity;
  631|      2|  PR_ASSERT(identity_cache.ident < identity_cache.length);
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  632|      2|  PR_Unlock(identity_cache.ml);
  633|       |
  634|      2|  if (NULL != old) {
  ------------------
  |  Branch (634:7): [True: 0, False: 2]
  ------------------
  635|      0|    PR_DELETE(old);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  636|      0|  }
  637|      2|  if (NULL != names) {
  ------------------
  |  Branch (637:7): [True: 0, False: 2]
  ------------------
  638|      0|    PR_DELETE(names);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  639|      0|  }
  640|       |
  641|      2|  return identity;
  642|      2|} /* PR_GetUniqueIdentity */
PR_GetIdentitiesLayer:
  670|   966k|PR_GetIdentitiesLayer(PRFileDesc* fd, PRDescIdentity id) {
  671|   966k|  PRFileDesc* layer = fd;
  672|       |
  673|   966k|  if (PR_TOP_IO_LAYER == id) {
  ------------------
  |  |  453|   966k|#define PR_TOP_IO_LAYER (PRDescIdentity)-2
  ------------------
  |  Branch (673:7): [True: 19.4k, False: 946k]
  ------------------
  674|  19.4k|    if (PR_IO_LAYER_HEAD == fd->identity) {
  ------------------
  |  |  451|  19.4k|#define PR_IO_LAYER_HEAD (PRDescIdentity)-3
  ------------------
  |  Branch (674:9): [True: 0, False: 19.4k]
  ------------------
  675|      0|      return fd->lower;
  676|      0|    }
  677|  19.4k|    return fd;
  678|  19.4k|  }
  679|       |
  680|   946k|  for (layer = fd; layer != NULL; layer = layer->lower) {
  ------------------
  |  Branch (680:20): [True: 946k, False: 0]
  ------------------
  681|   946k|    if (id == layer->identity) {
  ------------------
  |  Branch (681:9): [True: 946k, False: 0]
  ------------------
  682|   946k|      return layer;
  683|   946k|    }
  684|   946k|  }
  685|      0|  for (layer = fd; layer != NULL; layer = layer->higher) {
  ------------------
  |  Branch (685:20): [True: 0, False: 0]
  ------------------
  686|      0|    if (id == layer->identity) {
  ------------------
  |  Branch (686:9): [True: 0, False: 0]
  ------------------
  687|      0|      return layer;
  688|      0|    }
  689|      0|  }
  690|      0|  return NULL;
  691|      0|} /* PR_GetIdentitiesLayer */
_PR_InitLayerCache:
  693|      1|void _PR_InitLayerCache(void) {
  694|      1|  memset(&identity_cache, 0, sizeof(identity_cache));
  695|      1|  identity_cache.ml = PR_NewLock();
  696|      1|  PR_ASSERT(NULL != identity_cache.ml);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  697|      1|} /* _PR_InitLayerCache */
prlayer.c:pl_DefGetsocketoption:
  341|   169k|                                                  PRSocketOptionData* data) {
  342|   169k|  PR_ASSERT(fd != NULL);
  ------------------
  |  |  208|   169k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 169k, False: 0]
  |  |  ------------------
  ------------------
  343|   169k|  PR_ASSERT(fd->lower != NULL);
  ------------------
  |  |  208|   169k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 169k, False: 0]
  |  |  ------------------
  ------------------
  344|       |
  345|   169k|  return (fd->lower->methods->getsocketoption)(fd->lower, data);
  346|   169k|}

_PR_InitLog:
  186|      1|void _PR_InitLog(void) {
  187|      1|  char* ev;
  188|       |
  189|      1|  _pr_logLock = PR_NewLock();
  190|       |
  191|      1|  ev = PR_GetEnv("NSPR_LOG_MODULES");
  192|      1|  if (ev && ev[0]) {
  ------------------
  |  Branch (192:7): [True: 0, False: 1]
  |  Branch (192:13): [True: 0, False: 0]
  ------------------
  193|      0|    char module[64]; /* Security-Critical: If you change this
  194|       |                      * size, you must also change the sscanf
  195|       |                      * format string to be size-1.
  196|       |                      */
  197|      0|    PRBool isSync = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  198|      0|    PRIntn evlen = strlen(ev), pos = 0;
  199|      0|    PRInt32 bufSize = DEFAULT_BUF_SIZE;
  ------------------
  |  |  139|      0|#define DEFAULT_BUF_SIZE 16384
  ------------------
  200|      0|    while (pos < evlen) {
  ------------------
  |  Branch (200:12): [True: 0, False: 0]
  ------------------
  201|      0|      PRIntn level = 1, count = 0, delta = 0;
  202|      0|      count = sscanf(
  203|      0|          &ev[pos],
  204|      0|          "%63[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789_-"
  205|      0|          "]%n:%d%n",
  206|      0|          module, &delta, &level, &delta);
  207|      0|      pos += delta;
  208|      0|      if (count == 0) {
  ------------------
  |  Branch (208:11): [True: 0, False: 0]
  ------------------
  209|      0|        break;
  210|      0|      }
  211|       |
  212|       |      /*
  213|       |      ** If count == 2, then we got module and level. If count
  214|       |      ** == 1, then level defaults to 1 (module enabled).
  215|       |      */
  216|      0|      if (strcasecmp(module, "sync") == 0) {
  ------------------
  |  Branch (216:11): [True: 0, False: 0]
  ------------------
  217|      0|        isSync = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  218|      0|      } else if (strcasecmp(module, "bufsize") == 0) {
  ------------------
  |  Branch (218:18): [True: 0, False: 0]
  ------------------
  219|      0|        if (level >= LINE_BUF_SIZE) {
  ------------------
  |  |  138|      0|#define LINE_BUF_SIZE 512
  ------------------
  |  Branch (219:13): [True: 0, False: 0]
  ------------------
  220|      0|          bufSize = level;
  221|      0|        }
  222|      0|      } else if (strcasecmp(module, "timestamp") == 0) {
  ------------------
  |  Branch (222:18): [True: 0, False: 0]
  ------------------
  223|      0|        outputTimeStamp = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  224|      0|      } else if (strcasecmp(module, "append") == 0) {
  ------------------
  |  Branch (224:18): [True: 0, False: 0]
  ------------------
  225|      0|        appendToLog = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  226|      0|      } else {
  227|      0|        PRLogModuleInfo* lm = logModules;
  228|      0|        PRBool skip_modcheck =
  229|      0|            (0 == strcasecmp(module, "all")) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                          (0 == strcasecmp(module, "all")) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (229:13): [True: 0, False: 0]
  ------------------
  230|       |
  231|      0|        while (lm != NULL) {
  ------------------
  |  Branch (231:16): [True: 0, False: 0]
  ------------------
  232|      0|          if (skip_modcheck) {
  ------------------
  |  Branch (232:15): [True: 0, False: 0]
  ------------------
  233|      0|            lm->level = (PRLogModuleLevel)level;
  234|      0|          } else if (strcasecmp(module, lm->name) == 0) {
  ------------------
  |  Branch (234:22): [True: 0, False: 0]
  ------------------
  235|      0|            lm->level = (PRLogModuleLevel)level;
  236|      0|            break;
  237|      0|          }
  238|      0|          lm = lm->next;
  239|      0|        }
  240|      0|      }
  241|       |      /*found:*/
  242|      0|      count = sscanf(&ev[pos], " , %n", &delta);
  243|      0|      pos += delta;
  244|      0|      if (count == EOF) {
  ------------------
  |  Branch (244:11): [True: 0, False: 0]
  ------------------
  245|      0|        break;
  246|      0|      }
  247|      0|    }
  248|      0|    PR_SetLogBuffering(isSync ? 0 : bufSize);
  ------------------
  |  Branch (248:24): [True: 0, False: 0]
  ------------------
  249|       |
  250|      0|    ev = PR_GetEnvSecure("NSPR_LOG_FILE");
  251|      0|    if (ev && ev[0]) {
  ------------------
  |  Branch (251:9): [True: 0, False: 0]
  |  Branch (251:15): [True: 0, False: 0]
  ------------------
  252|      0|      if (!PR_SetLogFile(ev)) {
  ------------------
  |  Branch (252:11): [True: 0, False: 0]
  ------------------
  253|       |#ifdef XP_PC
  254|       |        char* str = PR_smprintf("Unable to create nspr log file '%s'\n", ev);
  255|       |        if (str) {
  256|       |          OutputDebugStringA(str);
  257|       |          PR_smprintf_free(str);
  258|       |        }
  259|       |#else
  260|      0|        fprintf(stderr, "Unable to create nspr log file '%s'\n", ev);
  261|      0|#endif
  262|      0|      }
  263|      0|    } else {
  264|       |#ifdef _PR_USE_STDIO_FOR_LOGGING
  265|       |      logFile = stderr;
  266|       |#else
  267|      0|      logFile = _pr_stderr;
  268|      0|#endif
  269|      0|    }
  270|      0|  }
  271|      1|}
PR_NewLogModule:
  353|     11|PR_IMPLEMENT(PRLogModuleInfo*) PR_NewLogModule(const char* name) {
  354|     11|  PRLogModuleInfo* lm;
  355|       |
  356|     11|  if (!_pr_initialized) {
  ------------------
  |  Branch (356:7): [True: 0, False: 11]
  ------------------
  357|      0|    _PR_ImplicitInitialization();
  358|      0|  }
  359|       |
  360|     11|  lm = PR_NEWZAP(PRLogModuleInfo);
  ------------------
  |  |   99|     11|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  361|     11|  if (lm) {
  ------------------
  |  Branch (361:7): [True: 11, False: 0]
  ------------------
  362|     11|    lm->name = strdup(name);
  363|     11|    lm->level = PR_LOG_NONE;
  364|     11|    lm->next = logModules;
  365|     11|    logModules = lm;
  366|     11|    _PR_SetLogModuleLevel(lm);
  367|     11|  }
  368|     11|  return lm;
  369|     11|}
prlog.c:_PR_SetLogModuleLevel:
  311|     11|static void _PR_SetLogModuleLevel(PRLogModuleInfo* lm) {
  312|     11|  char* ev;
  313|       |
  314|     11|  ev = PR_GetEnv("NSPR_LOG_MODULES");
  315|     11|  if (ev && ev[0]) {
  ------------------
  |  Branch (315:7): [True: 0, False: 11]
  |  Branch (315:13): [True: 0, False: 0]
  ------------------
  316|      0|    char module[64]; /* Security-Critical: If you change this
  317|       |                      * size, you must also change the sscanf
  318|       |                      * format string to be size-1.
  319|       |                      */
  320|      0|    PRIntn evlen = strlen(ev), pos = 0;
  321|      0|    while (pos < evlen) {
  ------------------
  |  Branch (321:12): [True: 0, False: 0]
  ------------------
  322|      0|      PRIntn level = 1, count = 0, delta = 0;
  323|       |
  324|      0|      count = sscanf(
  325|      0|          &ev[pos],
  326|      0|          "%63[ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789_-"
  327|      0|          "]%n:%d%n",
  328|      0|          module, &delta, &level, &delta);
  329|      0|      pos += delta;
  330|      0|      if (count == 0) {
  ------------------
  |  Branch (330:11): [True: 0, False: 0]
  ------------------
  331|      0|        break;
  332|      0|      }
  333|       |
  334|       |      /*
  335|       |      ** If count == 2, then we got module and level. If count
  336|       |      ** == 1, then level defaults to 1 (module enabled).
  337|       |      */
  338|      0|      if (lm != NULL) {
  ------------------
  |  Branch (338:11): [True: 0, False: 0]
  ------------------
  339|      0|        if ((strcasecmp(module, "all") == 0) ||
  ------------------
  |  Branch (339:13): [True: 0, False: 0]
  ------------------
  340|      0|            (strcasecmp(module, lm->name) == 0)) {
  ------------------
  |  Branch (340:13): [True: 0, False: 0]
  ------------------
  341|      0|          lm->level = (PRLogModuleLevel)level;
  342|      0|        }
  343|      0|      }
  344|      0|      count = sscanf(&ev[pos], " , %n", &delta);
  345|      0|      pos += delta;
  346|      0|      if (count == EOF) {
  ------------------
  |  Branch (346:11): [True: 0, False: 0]
  ------------------
  347|      0|        break;
  348|      0|      }
  349|      0|    }
  350|      0|  }
  351|     11|} /* end _PR_SetLogModuleLevel() */

_PR_InitMW:
  171|      1|void _PR_InitMW(void) {
  172|       |#ifdef WINNT
  173|       |  /*
  174|       |   * We use NT 4's InterlockedCompareExchange() to operate
  175|       |   * on PRMWStatus variables.
  176|       |   */
  177|       |  PR_ASSERT(sizeof(LONG) == sizeof(PRMWStatus));
  178|       |  TimerInit();
  179|       |#endif
  180|      1|  mw_lock = PR_NewLock();
  181|      1|  PR_ASSERT(NULL != mw_lock);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  182|      1|  mw_state = PR_NEWZAP(_PRGlobalState);
  ------------------
  |  |   99|      1|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  183|      1|  PR_ASSERT(NULL != mw_state);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  184|      1|  PR_INIT_CLIST(&mw_state->group_list);
  ------------------
  |  |  100|      1|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      1|    (_l)->next = (_l); \
  |  |  102|      1|    (_l)->prev = (_l); \
  |  |  103|      1|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  185|      1|  max_polling_interval = PR_MillisecondsToInterval(MAX_POLLING_INTERVAL);
  ------------------
  |  |   15|      1|#define MAX_POLLING_INTERVAL 100
  ------------------
  186|      1|} /* _PR_InitMW */

PR_smprintf:
 1166|  13.2k|PR_IMPLEMENT(char*) PR_smprintf(const char* fmt, ...) {
 1167|  13.2k|  va_list ap;
 1168|  13.2k|  char* rv;
 1169|       |
 1170|  13.2k|  va_start(ap, fmt);
 1171|  13.2k|  rv = PR_vsmprintf(fmt, ap);
 1172|  13.2k|  va_end(ap);
 1173|  13.2k|  return rv;
 1174|  13.2k|}
PR_smprintf_free:
 1179|  13.2k|PR_IMPLEMENT(void) PR_smprintf_free(char* mem) { PR_DELETE(mem); }
  ------------------
  |  |  110|  13.2k|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
PR_vsmprintf:
 1181|  13.2k|PR_IMPLEMENT(char*) PR_vsmprintf(const char* fmt, va_list ap) {
 1182|  13.2k|  SprintfState ss;
 1183|  13.2k|  int rv;
 1184|       |
 1185|  13.2k|  ss.stuff = GrowStuff;
 1186|  13.2k|  ss.base = 0;
 1187|  13.2k|  ss.cur = 0;
 1188|  13.2k|  ss.maxlen = 0;
 1189|  13.2k|  rv = dosprintf(&ss, fmt, ap);
 1190|  13.2k|  if (rv < 0) {
  ------------------
  |  Branch (1190:7): [True: 0, False: 13.2k]
  ------------------
 1191|      0|    if (ss.base) {
  ------------------
  |  Branch (1191:9): [True: 0, False: 0]
  ------------------
 1192|      0|      PR_DELETE(ss.base);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
 1193|      0|    }
 1194|      0|    return 0;
 1195|      0|  }
 1196|  13.2k|  return ss.base;
 1197|  13.2k|}
PR_snprintf:
 1220|  4.85k|PR_snprintf(char* out, PRUint32 outlen, const char* fmt, ...) {
 1221|  4.85k|  va_list ap;
 1222|  4.85k|  PRUint32 rv;
 1223|       |
 1224|  4.85k|  va_start(ap, fmt);
 1225|  4.85k|  rv = PR_vsnprintf(out, outlen, fmt, ap);
 1226|  4.85k|  va_end(ap);
 1227|  4.85k|  return rv;
 1228|  4.85k|}
PR_vsnprintf:
 1231|  4.85k|PR_vsnprintf(char* out, PRUint32 outlen, const char* fmt, va_list ap) {
 1232|  4.85k|  SprintfState ss;
 1233|  4.85k|  PRUint32 n;
 1234|       |
 1235|  4.85k|  PR_ASSERT(outlen != 0 && outlen <= PR_INT32_MAX);
  ------------------
  |  |  208|  9.70k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 4.85k, False: 0]
  |  |  |  Branch (208:7): [True: 4.85k, False: 0]
  |  |  ------------------
  ------------------
 1236|  4.85k|  if (outlen == 0 || outlen > PR_INT32_MAX) {
  ------------------
  |  |  300|  4.85k|#define PR_INT32_MAX PR_INT32(2147483647)
  |  |  ------------------
  |  |  |  |  281|  4.85k|#define PR_INT32(x)  x
  |  |  ------------------
  ------------------
  |  Branch (1236:7): [True: 0, False: 4.85k]
  |  Branch (1236:22): [True: 0, False: 4.85k]
  ------------------
 1237|      0|    return 0;
 1238|      0|  }
 1239|       |
 1240|  4.85k|  ss.stuff = LimitStuff;
 1241|  4.85k|  ss.base = out;
 1242|  4.85k|  ss.cur = out;
 1243|  4.85k|  ss.maxlen = outlen;
 1244|  4.85k|  (void)dosprintf(&ss, fmt, ap);
 1245|       |
 1246|       |  /* If we added chars, and we didn't append a null, do it now. */
 1247|  4.85k|  if ((ss.cur != ss.base) && (*(ss.cur - 1) != '\0')) {
  ------------------
  |  Branch (1247:7): [True: 4.85k, False: 0]
  |  Branch (1247:30): [True: 0, False: 4.85k]
  ------------------
 1248|      0|    *(ss.cur - 1) = '\0';
 1249|      0|  }
 1250|       |
 1251|  4.85k|  n = ss.cur - ss.base;
 1252|  4.85k|  return n ? n - 1 : n;
  ------------------
  |  Branch (1252:10): [True: 4.85k, False: 0]
  ------------------
 1253|  4.85k|}
prprf.c:dosprintf:
  677|  18.1k|static int dosprintf(SprintfState* ss, const char* fmt, va_list ap) {
  678|  18.1k|  char c;
  679|  18.1k|  int flags, width, prec, radix, type;
  680|  18.1k|  union {
  681|  18.1k|    char ch;
  682|  18.1k|    int i;
  683|  18.1k|    long l;
  684|  18.1k|    PRInt64 ll;
  685|  18.1k|    double d;
  686|  18.1k|    const char* s;
  687|  18.1k|    int* ip;
  688|       |#ifdef WIN32
  689|       |    const WCHAR* ws;
  690|       |#endif
  691|  18.1k|  } u;
  692|  18.1k|  const char* fmt0;
  693|  18.1k|  static char* hex = "0123456789abcdef";
  694|  18.1k|  static char* HEX = "0123456789ABCDEF";
  695|  18.1k|  char* hexp;
  696|  18.1k|  int rv, i;
  697|  18.1k|  struct NumArg* nas = NULL;
  698|  18.1k|  struct NumArg* nap = NULL;
  699|  18.1k|  struct NumArg nasArray[NAS_DEFAULT_NUM];
  700|  18.1k|  char pattern[20];
  701|  18.1k|  const char* dolPt = NULL; /* in "%4$.2f", dolPt will point to . */
  702|       |#ifdef WIN32
  703|       |  char* pBuf = NULL;
  704|       |#endif
  705|       |
  706|       |  /*
  707|       |  ** build an argument array, IF the fmt is numbered argument
  708|       |  ** list style, to contain the Numbered Argument list pointers
  709|       |  */
  710|       |
  711|  18.1k|  nas = BuildArgArray(fmt, ap, &rv, nasArray);
  712|  18.1k|  if (rv < 0) {
  ------------------
  |  Branch (712:7): [True: 0, False: 18.1k]
  ------------------
  713|       |    /* the fmt contains error Numbered Argument format, jliu@netscape.com */
  714|      0|    PR_ASSERT(0);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  715|      0|    return rv;
  716|      0|  }
  717|       |
  718|  95.2k|  while ((c = *fmt++) != 0) {
  ------------------
  |  Branch (718:10): [True: 77.0k, False: 18.1k]
  ------------------
  719|  77.0k|    if (c != '%') {
  ------------------
  |  Branch (719:9): [True: 41.5k, False: 35.5k]
  ------------------
  720|  41.5k|      rv = (*ss->stuff)(ss, fmt - 1, 1);
  721|  41.5k|      if (rv < 0) {
  ------------------
  |  Branch (721:11): [True: 0, False: 41.5k]
  ------------------
  722|      0|        return rv;
  723|      0|      }
  724|  41.5k|      continue;
  725|  41.5k|    }
  726|  35.5k|    fmt0 = fmt - 1;
  727|       |
  728|       |    /*
  729|       |    ** Gobble up the % format string. Hopefully we have handled all
  730|       |    ** of the strange cases!
  731|       |    */
  732|  35.5k|    flags = 0;
  733|  35.5k|    c = *fmt++;
  734|  35.5k|    if (c == '%') {
  ------------------
  |  Branch (734:9): [True: 0, False: 35.5k]
  ------------------
  735|       |      /* quoting a % with %% */
  736|      0|      rv = (*ss->stuff)(ss, fmt - 1, 1);
  737|      0|      if (rv < 0) {
  ------------------
  |  Branch (737:11): [True: 0, False: 0]
  ------------------
  738|      0|        return rv;
  739|      0|      }
  740|      0|      continue;
  741|      0|    }
  742|       |
  743|  35.5k|    if (nas != NULL) {
  ------------------
  |  Branch (743:9): [True: 0, False: 35.5k]
  ------------------
  744|       |      /* the fmt contains the Numbered Arguments feature */
  745|      0|      i = 0;
  746|      0|      while (c && c != '$') { /* should improve error check later */
  ------------------
  |  Branch (746:14): [True: 0, False: 0]
  |  Branch (746:19): [True: 0, False: 0]
  ------------------
  747|      0|        i = (i * 10) + (c - '0');
  748|      0|        c = *fmt++;
  749|      0|      }
  750|       |
  751|      0|      if (nas[i - 1].type == TYPE_UNKNOWN) {
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  |  Branch (751:11): [True: 0, False: 0]
  ------------------
  752|      0|        if (nas && (nas != nasArray)) {
  ------------------
  |  Branch (752:13): [True: 0, False: 0]
  |  Branch (752:20): [True: 0, False: 0]
  ------------------
  753|      0|          PR_DELETE(nas);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  754|      0|        }
  755|      0|        return -1;
  756|      0|      }
  757|       |
  758|      0|      nap = &nas[i - 1];
  759|      0|      dolPt = fmt;
  760|      0|      c = *fmt++;
  761|      0|    }
  762|       |
  763|       |    /*
  764|       |     * Examine optional flags.  Note that we do not implement the
  765|       |     * '#' flag of sprintf().  The ANSI C spec. of the '#' flag is
  766|       |     * somewhat ambiguous and not ideal, which is perhaps why
  767|       |     * the various sprintf() implementations are inconsistent
  768|       |     * on this feature.
  769|       |     */
  770|  35.5k|    while ((c == '-') || (c == '+') || (c == ' ') || (c == '0')) {
  ------------------
  |  Branch (770:12): [True: 0, False: 35.5k]
  |  Branch (770:26): [True: 0, False: 35.5k]
  |  Branch (770:40): [True: 0, False: 35.5k]
  |  Branch (770:54): [True: 0, False: 35.5k]
  ------------------
  771|      0|      if (c == '-') {
  ------------------
  |  Branch (771:11): [True: 0, False: 0]
  ------------------
  772|      0|        flags |= FLAG_LEFT;
  ------------------
  |  |   90|      0|#define FLAG_LEFT 0x1
  ------------------
  773|      0|      }
  774|      0|      if (c == '+') {
  ------------------
  |  Branch (774:11): [True: 0, False: 0]
  ------------------
  775|      0|        flags |= FLAG_SIGNED;
  ------------------
  |  |   91|      0|#define FLAG_SIGNED 0x2
  ------------------
  776|      0|      }
  777|      0|      if (c == ' ') {
  ------------------
  |  Branch (777:11): [True: 0, False: 0]
  ------------------
  778|      0|        flags |= FLAG_SPACED;
  ------------------
  |  |   92|      0|#define FLAG_SPACED 0x4
  ------------------
  779|      0|      }
  780|      0|      if (c == '0') {
  ------------------
  |  Branch (780:11): [True: 0, False: 0]
  ------------------
  781|      0|        flags |= FLAG_ZEROS;
  ------------------
  |  |   93|      0|#define FLAG_ZEROS 0x8
  ------------------
  782|      0|      }
  783|      0|      c = *fmt++;
  784|      0|    }
  785|  35.5k|    if (flags & FLAG_SIGNED) {
  ------------------
  |  |   91|  35.5k|#define FLAG_SIGNED 0x2
  ------------------
  |  Branch (785:9): [True: 0, False: 35.5k]
  ------------------
  786|      0|      flags &= ~FLAG_SPACED;
  ------------------
  |  |   92|      0|#define FLAG_SPACED 0x4
  ------------------
  787|      0|    }
  788|  35.5k|    if (flags & FLAG_LEFT) {
  ------------------
  |  |   90|  35.5k|#define FLAG_LEFT 0x1
  ------------------
  |  Branch (788:9): [True: 0, False: 35.5k]
  ------------------
  789|      0|      flags &= ~FLAG_ZEROS;
  ------------------
  |  |   93|      0|#define FLAG_ZEROS 0x8
  ------------------
  790|      0|    }
  791|       |
  792|       |    /* width */
  793|  35.5k|    if (c == '*') {
  ------------------
  |  Branch (793:9): [True: 0, False: 35.5k]
  ------------------
  794|      0|      c = *fmt++;
  795|      0|      width = va_arg(ap, int);
  796|  35.5k|    } else {
  797|  35.5k|      width = 0;
  798|  35.5k|      while ((c >= '0') && (c <= '9')) {
  ------------------
  |  Branch (798:14): [True: 35.5k, False: 0]
  |  Branch (798:28): [True: 0, False: 35.5k]
  ------------------
  799|      0|        width = (width * 10) + (c - '0');
  800|      0|        c = *fmt++;
  801|      0|      }
  802|  35.5k|    }
  803|       |
  804|       |    /* precision */
  805|  35.5k|    prec = -1;
  806|  35.5k|    if (c == '.') {
  ------------------
  |  Branch (806:9): [True: 0, False: 35.5k]
  ------------------
  807|      0|      c = *fmt++;
  808|      0|      if (c == '*') {
  ------------------
  |  Branch (808:11): [True: 0, False: 0]
  ------------------
  809|      0|        c = *fmt++;
  810|      0|        prec = va_arg(ap, int);
  811|      0|      } else {
  812|      0|        prec = 0;
  813|      0|        while ((c >= '0') && (c <= '9')) {
  ------------------
  |  Branch (813:16): [True: 0, False: 0]
  |  Branch (813:30): [True: 0, False: 0]
  ------------------
  814|      0|          prec = (prec * 10) + (c - '0');
  815|      0|          c = *fmt++;
  816|      0|        }
  817|      0|      }
  818|      0|    }
  819|       |
  820|       |    /* size */
  821|  35.5k|    type = TYPE_INTN;
  ------------------
  |  |   76|  35.5k|#define TYPE_INTN 2
  ------------------
  822|  35.5k|    if (c == 'h') {
  ------------------
  |  Branch (822:9): [True: 0, False: 35.5k]
  ------------------
  823|      0|      type = TYPE_INT16;
  ------------------
  |  |   74|      0|#define TYPE_INT16 0
  ------------------
  824|      0|      c = *fmt++;
  825|  35.5k|    } else if (c == 'L') {
  ------------------
  |  Branch (825:16): [True: 0, False: 35.5k]
  ------------------
  826|       |      /* XXX not quite sure here */
  827|      0|      type = TYPE_INT64;
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  828|      0|      c = *fmt++;
  829|  35.5k|    } else if (c == 'l') {
  ------------------
  |  Branch (829:16): [True: 16.6k, False: 18.8k]
  ------------------
  830|  16.6k|      type = TYPE_INT32;
  ------------------
  |  |   78|  16.6k|#define TYPE_INT32 4
  ------------------
  831|  16.6k|      c = *fmt++;
  832|  16.6k|      if (c == 'l') {
  ------------------
  |  Branch (832:11): [True: 298, False: 16.3k]
  ------------------
  833|    298|        type = TYPE_INT64;
  ------------------
  |  |   80|    298|#define TYPE_INT64 6
  ------------------
  834|    298|        c = *fmt++;
  835|    298|      }
  836|  18.8k|    } else if (c == 'z') {
  ------------------
  |  Branch (836:16): [True: 0, False: 18.8k]
  ------------------
  837|      0|      if (sizeof(size_t) == sizeof(PRInt32)) {
  ------------------
  |  Branch (837:11): [Folded - Ignored]
  ------------------
  838|      0|        type = TYPE_INT32;
  ------------------
  |  |   78|      0|#define TYPE_INT32 4
  ------------------
  839|      0|      } else if (sizeof(size_t) == sizeof(PRInt64)) {
  ------------------
  |  Branch (839:18): [Folded - Ignored]
  ------------------
  840|      0|        type = TYPE_INT64;
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  841|      0|      }
  842|      0|      c = *fmt++;
  843|      0|    }
  844|       |
  845|       |    /* format */
  846|  35.5k|    hexp = hex;
  847|  35.5k|    switch (c) {
  848|      0|      case 'd':
  ------------------
  |  Branch (848:7): [True: 0, False: 35.5k]
  ------------------
  849|      0|      case 'i': /* decimal/integer */
  ------------------
  |  Branch (849:7): [True: 0, False: 35.5k]
  ------------------
  850|      0|        radix = 10;
  851|      0|        goto fetch_and_convert;
  852|       |
  853|      0|      case 'o': /* octal */
  ------------------
  |  Branch (853:7): [True: 0, False: 35.5k]
  ------------------
  854|      0|        radix = 8;
  855|      0|        type |= 1;
  856|      0|        goto fetch_and_convert;
  857|       |
  858|  16.6k|      case 'u': /* unsigned decimal */
  ------------------
  |  Branch (858:7): [True: 16.6k, False: 18.8k]
  ------------------
  859|  16.6k|        radix = 10;
  860|  16.6k|        type |= 1;
  861|  16.6k|        goto fetch_and_convert;
  862|       |
  863|      0|      case 'x': /* unsigned hex */
  ------------------
  |  Branch (863:7): [True: 0, False: 35.5k]
  ------------------
  864|      0|        radix = 16;
  865|      0|        type |= 1;
  866|      0|        goto fetch_and_convert;
  867|       |
  868|      0|      case 'X': /* unsigned HEX */
  ------------------
  |  Branch (868:7): [True: 0, False: 35.5k]
  ------------------
  869|      0|        radix = 16;
  870|      0|        hexp = HEX;
  871|      0|        type |= 1;
  872|      0|        goto fetch_and_convert;
  873|       |
  874|  16.6k|      fetch_and_convert:
  875|  16.6k|        switch (type) {
  ------------------
  |  Branch (875:17): [True: 0, False: 16.6k]
  ------------------
  876|      0|          case TYPE_INT16:
  ------------------
  |  |   74|      0|#define TYPE_INT16 0
  ------------------
  |  Branch (876:11): [True: 0, False: 16.6k]
  ------------------
  877|      0|            u.l = nas ? nap->u.i : va_arg(ap, int);
  ------------------
  |  Branch (877:19): [True: 0, False: 0]
  ------------------
  878|      0|            if (u.l < 0) {
  ------------------
  |  Branch (878:17): [True: 0, False: 0]
  ------------------
  879|      0|              u.l = -u.l;
  880|      0|              flags |= FLAG_NEG;
  ------------------
  |  |   94|      0|#define FLAG_NEG 0x10
  ------------------
  881|      0|            }
  882|      0|            goto do_long;
  883|      0|          case TYPE_UINT16:
  ------------------
  |  |   75|      0|#define TYPE_UINT16 1
  ------------------
  |  Branch (883:11): [True: 0, False: 16.6k]
  ------------------
  884|      0|            u.l = (nas ? nap->u.i : va_arg(ap, int)) & 0xffff;
  ------------------
  |  Branch (884:20): [True: 0, False: 0]
  ------------------
  885|      0|            goto do_long;
  886|      0|          case TYPE_INTN:
  ------------------
  |  |   76|      0|#define TYPE_INTN 2
  ------------------
  |  Branch (886:11): [True: 0, False: 16.6k]
  ------------------
  887|      0|            u.l = nas ? nap->u.i : va_arg(ap, int);
  ------------------
  |  Branch (887:19): [True: 0, False: 0]
  ------------------
  888|      0|            if (u.l < 0) {
  ------------------
  |  Branch (888:17): [True: 0, False: 0]
  ------------------
  889|      0|              u.l = -u.l;
  890|      0|              flags |= FLAG_NEG;
  ------------------
  |  |   94|      0|#define FLAG_NEG 0x10
  ------------------
  891|      0|            }
  892|      0|            goto do_long;
  893|      0|          case TYPE_UINTN:
  ------------------
  |  |   77|      0|#define TYPE_UINTN 3
  ------------------
  |  Branch (893:11): [True: 0, False: 16.6k]
  ------------------
  894|      0|            u.l = (long)(nas ? nap->u.ui : va_arg(ap, unsigned int));
  ------------------
  |  Branch (894:26): [True: 0, False: 0]
  ------------------
  895|      0|            goto do_long;
  896|       |
  897|      0|          case TYPE_INT32:
  ------------------
  |  |   78|      0|#define TYPE_INT32 4
  ------------------
  |  Branch (897:11): [True: 0, False: 16.6k]
  ------------------
  898|      0|            u.l = nas ? nap->u.i32 : va_arg(ap, PRInt32);
  ------------------
  |  Branch (898:19): [True: 0, False: 0]
  ------------------
  899|      0|            if (u.l < 0) {
  ------------------
  |  Branch (899:17): [True: 0, False: 0]
  ------------------
  900|      0|              u.l = -u.l;
  901|      0|              flags |= FLAG_NEG;
  ------------------
  |  |   94|      0|#define FLAG_NEG 0x10
  ------------------
  902|      0|            }
  903|      0|            goto do_long;
  904|  16.3k|          case TYPE_UINT32:
  ------------------
  |  |   79|  16.3k|#define TYPE_UINT32 5
  ------------------
  |  Branch (904:11): [True: 16.3k, False: 298]
  ------------------
  905|  16.3k|            u.l = (long)(nas ? nap->u.ui32 : va_arg(ap, PRUint32));
  ------------------
  |  Branch (905:26): [True: 0, False: 16.3k]
  ------------------
  906|  16.3k|          do_long:
  907|  16.3k|            rv = cvt_l(ss, u.l, width, prec, radix, type, flags, hexp);
  908|  16.3k|            if (rv < 0) {
  ------------------
  |  Branch (908:17): [True: 0, False: 16.3k]
  ------------------
  909|      0|              return rv;
  910|      0|            }
  911|  16.3k|            break;
  912|       |
  913|  16.3k|          case TYPE_INT64:
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  |  Branch (913:11): [True: 0, False: 16.6k]
  ------------------
  914|      0|            u.ll = nas ? nap->u.ll : va_arg(ap, PRInt64);
  ------------------
  |  Branch (914:20): [True: 0, False: 0]
  ------------------
  915|      0|            if (!LL_GE_ZERO(u.ll)) {
  ------------------
  |  |   78|      0|#define LL_GE_ZERO(a)       ((a) >= 0)
  ------------------
  |  Branch (915:17): [True: 0, False: 0]
  ------------------
  916|      0|              LL_NEG(u.ll, u.ll);
  ------------------
  |  |  104|      0|#define LL_NEG(r, a)        ((r) = -(a))
  ------------------
  917|      0|              flags |= FLAG_NEG;
  ------------------
  |  |   94|      0|#define FLAG_NEG 0x10
  ------------------
  918|      0|            }
  919|      0|            goto do_longlong;
  920|    298|          case TYPE_UINT64:
  ------------------
  |  |   81|    298|#define TYPE_UINT64 7
  ------------------
  |  Branch (920:11): [True: 298, False: 16.3k]
  ------------------
  921|    298|            u.ll = nas ? nap->u.ull : va_arg(ap, PRUint64);
  ------------------
  |  Branch (921:20): [True: 0, False: 298]
  ------------------
  922|    298|          do_longlong:
  923|    298|            rv = cvt_ll(ss, u.ll, width, prec, radix, type, flags, hexp);
  924|    298|            if (rv < 0) {
  ------------------
  |  Branch (924:17): [True: 0, False: 298]
  ------------------
  925|      0|              return rv;
  926|      0|            }
  927|    298|            break;
  928|  16.6k|        }
  929|  16.6k|        break;
  930|       |
  931|  16.6k|      case 'e':
  ------------------
  |  Branch (931:7): [True: 0, False: 35.5k]
  ------------------
  932|      0|      case 'E':
  ------------------
  |  Branch (932:7): [True: 0, False: 35.5k]
  ------------------
  933|      0|      case 'f':
  ------------------
  |  Branch (933:7): [True: 0, False: 35.5k]
  ------------------
  934|      0|      case 'g':
  ------------------
  |  Branch (934:7): [True: 0, False: 35.5k]
  ------------------
  935|      0|        u.d = nas ? nap->u.d : va_arg(ap, double);
  ------------------
  |  Branch (935:15): [True: 0, False: 0]
  ------------------
  936|      0|        if (nas != NULL) {
  ------------------
  |  Branch (936:13): [True: 0, False: 0]
  ------------------
  937|      0|          i = fmt - dolPt;
  938|      0|          if (i < sizeof(pattern)) {
  ------------------
  |  Branch (938:15): [True: 0, False: 0]
  ------------------
  939|      0|            pattern[0] = '%';
  940|      0|            memcpy(&pattern[1], dolPt, i);
  941|      0|            rv = cvt_f(ss, u.d, pattern, &pattern[i + 1]);
  942|      0|          }
  943|      0|        } else {
  944|      0|          rv = cvt_f(ss, u.d, fmt0, fmt);
  945|      0|        }
  946|       |
  947|      0|        if (rv < 0) {
  ------------------
  |  Branch (947:13): [True: 0, False: 0]
  ------------------
  948|      0|          return rv;
  949|      0|        }
  950|      0|        break;
  951|       |
  952|      0|      case 'c':
  ------------------
  |  Branch (952:7): [True: 0, False: 35.5k]
  ------------------
  953|      0|        u.ch = nas ? nap->u.i : va_arg(ap, int);
  ------------------
  |  Branch (953:16): [True: 0, False: 0]
  ------------------
  954|      0|        if ((flags & FLAG_LEFT) == 0) {
  ------------------
  |  |   90|      0|#define FLAG_LEFT 0x1
  ------------------
  |  Branch (954:13): [True: 0, False: 0]
  ------------------
  955|      0|          while (width-- > 1) {
  ------------------
  |  Branch (955:18): [True: 0, False: 0]
  ------------------
  956|      0|            rv = (*ss->stuff)(ss, " ", 1);
  957|      0|            if (rv < 0) {
  ------------------
  |  Branch (957:17): [True: 0, False: 0]
  ------------------
  958|      0|              return rv;
  959|      0|            }
  960|      0|          }
  961|      0|        }
  962|      0|        rv = (*ss->stuff)(ss, &u.ch, 1);
  963|      0|        if (rv < 0) {
  ------------------
  |  Branch (963:13): [True: 0, False: 0]
  ------------------
  964|      0|          return rv;
  965|      0|        }
  966|      0|        if (flags & FLAG_LEFT) {
  ------------------
  |  |   90|      0|#define FLAG_LEFT 0x1
  ------------------
  |  Branch (966:13): [True: 0, False: 0]
  ------------------
  967|      0|          while (width-- > 1) {
  ------------------
  |  Branch (967:18): [True: 0, False: 0]
  ------------------
  968|      0|            rv = (*ss->stuff)(ss, " ", 1);
  969|      0|            if (rv < 0) {
  ------------------
  |  Branch (969:17): [True: 0, False: 0]
  ------------------
  970|      0|              return rv;
  971|      0|            }
  972|      0|          }
  973|      0|        }
  974|      0|        break;
  975|       |
  976|      0|      case 'p':
  ------------------
  |  Branch (976:7): [True: 0, False: 35.5k]
  ------------------
  977|      0|        if (sizeof(void*) == sizeof(PRInt32)) {
  ------------------
  |  Branch (977:13): [Folded - Ignored]
  ------------------
  978|      0|          type = TYPE_UINT32;
  ------------------
  |  |   79|      0|#define TYPE_UINT32 5
  ------------------
  979|      0|        } else if (sizeof(void*) == sizeof(PRInt64)) {
  ------------------
  |  Branch (979:20): [Folded - Ignored]
  ------------------
  980|      0|          type = TYPE_UINT64;
  ------------------
  |  |   81|      0|#define TYPE_UINT64 7
  ------------------
  981|      0|        } else if (sizeof(void*) == sizeof(int)) {
  ------------------
  |  Branch (981:20): [Folded - Ignored]
  ------------------
  982|      0|          type = TYPE_UINTN;
  ------------------
  |  |   77|      0|#define TYPE_UINTN 3
  ------------------
  983|      0|        } else {
  984|      0|          PR_ASSERT(0);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  985|      0|          break;
  986|      0|        }
  987|      0|        radix = 16;
  988|      0|        goto fetch_and_convert;
  989|       |
  990|      0|#ifndef WIN32
  991|      0|      case 'S':
  ------------------
  |  Branch (991:7): [True: 0, False: 35.5k]
  ------------------
  992|       |        /* XXX not supported I suppose */
  993|      0|        PR_ASSERT(0);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  994|      0|        break;
  995|      0|#endif
  996|       |
  997|       |#if 0
  998|       |            case 'C':
  999|       |            case 'E':
 1000|       |            case 'G':
 1001|       |                /* XXX not supported I suppose */
 1002|       |                PR_ASSERT(0);
 1003|       |                break;
 1004|       |#endif
 1005|       |
 1006|       |#ifdef WIN32
 1007|       |      case 'S':
 1008|       |        u.ws = nas ? nap->u.ws : va_arg(ap, const WCHAR*);
 1009|       |
 1010|       |        /* Get the required size in rv */
 1011|       |        rv = WideCharToMultiByte(CP_ACP, 0, u.ws, -1, NULL, 0, NULL, NULL);
 1012|       |        if (rv == 0) {
 1013|       |          rv = 1;
 1014|       |        }
 1015|       |        pBuf = PR_MALLOC(rv);
 1016|       |        WideCharToMultiByte(CP_ACP, 0, u.ws, -1, pBuf, (int)rv, NULL, NULL);
 1017|       |        pBuf[rv - 1] = '\0';
 1018|       |
 1019|       |        rv = cvt_s(ss, pBuf, width, prec, flags);
 1020|       |
 1021|       |        /* We don't need the allocated buffer anymore */
 1022|       |        PR_Free(pBuf);
 1023|       |        if (rv < 0) {
 1024|       |          return rv;
 1025|       |        }
 1026|       |        break;
 1027|       |
 1028|       |#endif
 1029|       |
 1030|  18.8k|      case 's':
  ------------------
  |  Branch (1030:7): [True: 18.8k, False: 16.6k]
  ------------------
 1031|  18.8k|        u.s = nas ? nap->u.s : va_arg(ap, const char*);
  ------------------
  |  Branch (1031:15): [True: 0, False: 18.8k]
  ------------------
 1032|  18.8k|        rv = cvt_s(ss, u.s, width, prec, flags);
 1033|  18.8k|        if (rv < 0) {
  ------------------
  |  Branch (1033:13): [True: 0, False: 18.8k]
  ------------------
 1034|      0|          return rv;
 1035|      0|        }
 1036|  18.8k|        break;
 1037|       |
 1038|  18.8k|      case 'n':
  ------------------
  |  Branch (1038:7): [True: 0, False: 35.5k]
  ------------------
 1039|      0|        u.ip = nas ? nap->u.ip : va_arg(ap, int*);
  ------------------
  |  Branch (1039:16): [True: 0, False: 0]
  ------------------
 1040|      0|        if (u.ip) {
  ------------------
  |  Branch (1040:13): [True: 0, False: 0]
  ------------------
 1041|      0|          *u.ip = ss->cur - ss->base;
 1042|      0|        }
 1043|      0|        break;
 1044|       |
 1045|      0|      default:
  ------------------
  |  Branch (1045:7): [True: 0, False: 35.5k]
  ------------------
 1046|       |        /* Not a % token after all... skip it */
 1047|       |#if 0
 1048|       |                PR_ASSERT(0);
 1049|       |#endif
 1050|      0|        rv = (*ss->stuff)(ss, "%", 1);
 1051|      0|        if (rv < 0) {
  ------------------
  |  Branch (1051:13): [True: 0, False: 0]
  ------------------
 1052|      0|          return rv;
 1053|      0|        }
 1054|      0|        rv = (*ss->stuff)(ss, fmt - 1, 1);
 1055|      0|        if (rv < 0) {
  ------------------
  |  Branch (1055:13): [True: 0, False: 0]
  ------------------
 1056|      0|          return rv;
 1057|      0|        }
 1058|  35.5k|    }
 1059|  35.5k|  }
 1060|       |
 1061|       |  /* Stuff trailing NUL */
 1062|  18.1k|  rv = (*ss->stuff)(ss, "\0", 1);
 1063|       |
 1064|  18.1k|  if (nas && (nas != nasArray)) {
  ------------------
  |  Branch (1064:7): [True: 0, False: 18.1k]
  |  Branch (1064:14): [True: 0, False: 0]
  ------------------
 1065|      0|    PR_DELETE(nas);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
 1066|      0|  }
 1067|       |
 1068|  18.1k|  return rv;
 1069|  18.1k|}
prprf.c:BuildArgArray:
  384|  18.1k|                                    struct NumArg* nasArray) {
  385|  18.1k|  int number = 0, cn = 0, i;
  386|  18.1k|  const char* p;
  387|  18.1k|  char c;
  388|  18.1k|  struct NumArg* nas;
  389|       |
  390|       |  /*
  391|       |  **  first pass:
  392|       |  **  determine how many legal % I have got, then allocate space
  393|       |  */
  394|       |
  395|  18.1k|  p = fmt;
  396|  18.1k|  *rv = 0;
  397|  18.1k|  i = 0;
  398|   112k|  while ((c = *p++) != 0) {
  ------------------
  |  Branch (398:10): [True: 94.0k, False: 18.1k]
  ------------------
  399|  94.0k|    if (c != '%') {
  ------------------
  |  Branch (399:9): [True: 58.5k, False: 35.5k]
  ------------------
  400|  58.5k|      continue;
  401|  58.5k|    }
  402|  35.5k|    if ((c = *p++) == '%') { /* skip %% case */
  ------------------
  |  Branch (402:9): [True: 0, False: 35.5k]
  ------------------
  403|      0|      continue;
  404|      0|    }
  405|       |
  406|  35.5k|    while (c != 0) {
  ------------------
  |  Branch (406:12): [True: 35.5k, False: 0]
  ------------------
  407|  35.5k|      if (c > '9' || c < '0') {
  ------------------
  |  Branch (407:11): [True: 35.5k, False: 0]
  |  Branch (407:22): [True: 0, False: 0]
  ------------------
  408|  35.5k|        if (c == '$') { /* numbered argument case */
  ------------------
  |  Branch (408:13): [True: 0, False: 35.5k]
  ------------------
  409|      0|          if (i > 0) {
  ------------------
  |  Branch (409:15): [True: 0, False: 0]
  ------------------
  410|      0|            *rv = -1;
  411|      0|            return NULL;
  412|      0|          }
  413|      0|          number++;
  414|  35.5k|        } else { /* non-numbered argument case */
  415|  35.5k|          if (number > 0) {
  ------------------
  |  Branch (415:15): [True: 0, False: 35.5k]
  ------------------
  416|      0|            *rv = -1;
  417|      0|            return NULL;
  418|      0|          }
  419|  35.5k|          i = 1;
  420|  35.5k|        }
  421|  35.5k|        break;
  422|  35.5k|      }
  423|       |
  424|      0|      c = *p++;
  425|      0|    }
  426|  35.5k|  }
  427|       |
  428|  18.1k|  if (number == 0) {
  ------------------
  |  Branch (428:7): [True: 18.1k, False: 0]
  ------------------
  429|  18.1k|    return NULL;
  430|  18.1k|  }
  431|       |
  432|      0|  if (number > NAS_DEFAULT_NUM) {
  ------------------
  |  |   67|      0|#define NAS_DEFAULT_NUM 20 /* default number of NumberedArgument array */
  ------------------
  |  Branch (432:7): [True: 0, False: 0]
  ------------------
  433|      0|    nas = (struct NumArg*)PR_MALLOC(number * sizeof(struct NumArg));
  ------------------
  |  |   55|      0|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  ------------------
  434|      0|    if (!nas) {
  ------------------
  |  Branch (434:9): [True: 0, False: 0]
  ------------------
  435|      0|      *rv = -1;
  436|      0|      return NULL;
  437|      0|    }
  438|      0|  } else {
  439|      0|    nas = nasArray;
  440|      0|  }
  441|       |
  442|      0|  for (i = 0; i < number; i++) {
  ------------------
  |  Branch (442:15): [True: 0, False: 0]
  ------------------
  443|      0|    nas[i].type = TYPE_UNKNOWN;
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  444|      0|  }
  445|       |
  446|       |  /*
  447|       |  ** second pass:
  448|       |  ** set nas[].type
  449|       |  */
  450|       |
  451|      0|  p = fmt;
  452|      0|  while ((c = *p++) != 0) {
  ------------------
  |  Branch (452:10): [True: 0, False: 0]
  ------------------
  453|      0|    if (c != '%') {
  ------------------
  |  Branch (453:9): [True: 0, False: 0]
  ------------------
  454|      0|      continue;
  455|      0|    }
  456|      0|    c = *p++;
  457|      0|    if (c == '%') {
  ------------------
  |  Branch (457:9): [True: 0, False: 0]
  ------------------
  458|      0|      continue;
  459|      0|    }
  460|       |
  461|      0|    cn = 0;
  462|      0|    while (c && c != '$') { /* should improve error check later */
  ------------------
  |  Branch (462:12): [True: 0, False: 0]
  |  Branch (462:17): [True: 0, False: 0]
  ------------------
  463|      0|      cn = cn * 10 + c - '0';
  464|      0|      c = *p++;
  465|      0|    }
  466|       |
  467|      0|    if (!c || cn < 1 || cn > number) {
  ------------------
  |  Branch (467:9): [True: 0, False: 0]
  |  Branch (467:15): [True: 0, False: 0]
  |  Branch (467:25): [True: 0, False: 0]
  ------------------
  468|      0|      *rv = -1;
  469|      0|      break;
  470|      0|    }
  471|       |
  472|       |    /* nas[cn] starts from 0, and make sure nas[cn].type is not assigned */
  473|      0|    cn--;
  474|      0|    if (nas[cn].type != TYPE_UNKNOWN) {
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  |  Branch (474:9): [True: 0, False: 0]
  ------------------
  475|      0|      continue;
  476|      0|    }
  477|       |
  478|      0|    c = *p++;
  479|       |
  480|       |    /* width */
  481|      0|    if (c == '*') {
  ------------------
  |  Branch (481:9): [True: 0, False: 0]
  ------------------
  482|       |      /* not supported feature, for the argument is not numbered */
  483|      0|      *rv = -1;
  484|      0|      break;
  485|      0|    }
  486|       |
  487|      0|    while ((c >= '0') && (c <= '9')) {
  ------------------
  |  Branch (487:12): [True: 0, False: 0]
  |  Branch (487:26): [True: 0, False: 0]
  ------------------
  488|      0|      c = *p++;
  489|      0|    }
  490|       |
  491|       |    /* precision */
  492|      0|    if (c == '.') {
  ------------------
  |  Branch (492:9): [True: 0, False: 0]
  ------------------
  493|      0|      c = *p++;
  494|      0|      if (c == '*') {
  ------------------
  |  Branch (494:11): [True: 0, False: 0]
  ------------------
  495|       |        /* not supported feature, for the argument is not numbered */
  496|      0|        *rv = -1;
  497|      0|        break;
  498|      0|      }
  499|       |
  500|      0|      while ((c >= '0') && (c <= '9')) {
  ------------------
  |  Branch (500:14): [True: 0, False: 0]
  |  Branch (500:28): [True: 0, False: 0]
  ------------------
  501|      0|        c = *p++;
  502|      0|      }
  503|      0|    }
  504|       |
  505|       |    /* size */
  506|      0|    nas[cn].type = TYPE_INTN;
  ------------------
  |  |   76|      0|#define TYPE_INTN 2
  ------------------
  507|      0|    if (c == 'h') {
  ------------------
  |  Branch (507:9): [True: 0, False: 0]
  ------------------
  508|      0|      nas[cn].type = TYPE_INT16;
  ------------------
  |  |   74|      0|#define TYPE_INT16 0
  ------------------
  509|      0|      c = *p++;
  510|      0|    } else if (c == 'L') {
  ------------------
  |  Branch (510:16): [True: 0, False: 0]
  ------------------
  511|       |      /* XXX not quite sure here */
  512|      0|      nas[cn].type = TYPE_INT64;
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  513|      0|      c = *p++;
  514|      0|    } else if (c == 'l') {
  ------------------
  |  Branch (514:16): [True: 0, False: 0]
  ------------------
  515|      0|      nas[cn].type = TYPE_INT32;
  ------------------
  |  |   78|      0|#define TYPE_INT32 4
  ------------------
  516|      0|      c = *p++;
  517|      0|      if (c == 'l') {
  ------------------
  |  Branch (517:11): [True: 0, False: 0]
  ------------------
  518|      0|        nas[cn].type = TYPE_INT64;
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  519|      0|        c = *p++;
  520|      0|      }
  521|      0|    } else if (c == 'z') {
  ------------------
  |  Branch (521:16): [True: 0, False: 0]
  ------------------
  522|      0|      if (sizeof(size_t) == sizeof(PRInt32)) {
  ------------------
  |  Branch (522:11): [Folded - Ignored]
  ------------------
  523|      0|        nas[cn].type = TYPE_INT32;
  ------------------
  |  |   78|      0|#define TYPE_INT32 4
  ------------------
  524|      0|      } else if (sizeof(size_t) == sizeof(PRInt64)) {
  ------------------
  |  Branch (524:18): [Folded - Ignored]
  ------------------
  525|      0|        nas[cn].type = TYPE_INT64;
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  526|      0|      } else {
  527|      0|        nas[cn].type = TYPE_UNKNOWN;
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  528|      0|      }
  529|      0|      c = *p++;
  530|      0|    }
  531|       |
  532|       |    /* format */
  533|      0|    switch (c) {
  534|      0|      case 'd':
  ------------------
  |  Branch (534:7): [True: 0, False: 0]
  ------------------
  535|      0|      case 'c':
  ------------------
  |  Branch (535:7): [True: 0, False: 0]
  ------------------
  536|      0|      case 'i':
  ------------------
  |  Branch (536:7): [True: 0, False: 0]
  ------------------
  537|      0|      case 'o':
  ------------------
  |  Branch (537:7): [True: 0, False: 0]
  ------------------
  538|      0|      case 'u':
  ------------------
  |  Branch (538:7): [True: 0, False: 0]
  ------------------
  539|      0|      case 'x':
  ------------------
  |  Branch (539:7): [True: 0, False: 0]
  ------------------
  540|      0|      case 'X':
  ------------------
  |  Branch (540:7): [True: 0, False: 0]
  ------------------
  541|      0|        break;
  542|       |
  543|      0|      case 'e':
  ------------------
  |  Branch (543:7): [True: 0, False: 0]
  ------------------
  544|      0|      case 'f':
  ------------------
  |  Branch (544:7): [True: 0, False: 0]
  ------------------
  545|      0|      case 'g':
  ------------------
  |  Branch (545:7): [True: 0, False: 0]
  ------------------
  546|      0|        nas[cn].type = TYPE_DOUBLE;
  ------------------
  |  |   83|      0|#define TYPE_DOUBLE 9
  ------------------
  547|      0|        break;
  548|       |
  549|      0|      case 'p':
  ------------------
  |  Branch (549:7): [True: 0, False: 0]
  ------------------
  550|       |        /* XXX should use cpp */
  551|      0|        if (sizeof(void*) == sizeof(PRInt32)) {
  ------------------
  |  Branch (551:13): [Folded - Ignored]
  ------------------
  552|      0|          nas[cn].type = TYPE_UINT32;
  ------------------
  |  |   79|      0|#define TYPE_UINT32 5
  ------------------
  553|      0|        } else if (sizeof(void*) == sizeof(PRInt64)) {
  ------------------
  |  Branch (553:20): [Folded - Ignored]
  ------------------
  554|      0|          nas[cn].type = TYPE_UINT64;
  ------------------
  |  |   81|      0|#define TYPE_UINT64 7
  ------------------
  555|      0|        } else if (sizeof(void*) == sizeof(PRIntn)) {
  ------------------
  |  Branch (555:20): [Folded - Ignored]
  ------------------
  556|      0|          nas[cn].type = TYPE_UINTN;
  ------------------
  |  |   77|      0|#define TYPE_UINTN 3
  ------------------
  557|      0|        } else {
  558|      0|          nas[cn].type = TYPE_UNKNOWN;
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  559|      0|        }
  560|      0|        break;
  561|       |
  562|      0|      case 'S':
  ------------------
  |  Branch (562:7): [True: 0, False: 0]
  ------------------
  563|       |#ifdef WIN32
  564|       |        nas[cn].type = TYPE_WSTRING;
  565|       |        break;
  566|       |#endif
  567|      0|      case 'C':
  ------------------
  |  Branch (567:7): [True: 0, False: 0]
  ------------------
  568|      0|      case 'E':
  ------------------
  |  Branch (568:7): [True: 0, False: 0]
  ------------------
  569|      0|      case 'G':
  ------------------
  |  Branch (569:7): [True: 0, False: 0]
  ------------------
  570|       |        /* XXX not supported I suppose */
  571|      0|        PR_ASSERT(0);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  572|      0|        nas[cn].type = TYPE_UNKNOWN;
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  573|      0|        break;
  574|       |
  575|      0|      case 's':
  ------------------
  |  Branch (575:7): [True: 0, False: 0]
  ------------------
  576|      0|        nas[cn].type = TYPE_STRING;
  ------------------
  |  |   82|      0|#define TYPE_STRING 8
  ------------------
  577|      0|        break;
  578|       |
  579|      0|      case 'n':
  ------------------
  |  Branch (579:7): [True: 0, False: 0]
  ------------------
  580|      0|        nas[cn].type = TYPE_INTSTR;
  ------------------
  |  |   84|      0|#define TYPE_INTSTR 10
  ------------------
  581|      0|        break;
  582|       |
  583|      0|      default:
  ------------------
  |  Branch (583:7): [True: 0, False: 0]
  ------------------
  584|      0|        PR_ASSERT(0);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  585|      0|        nas[cn].type = TYPE_UNKNOWN;
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  586|      0|        break;
  587|      0|    }
  588|       |
  589|       |    /* get a legal para. */
  590|      0|    if (nas[cn].type == TYPE_UNKNOWN) {
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  |  Branch (590:9): [True: 0, False: 0]
  ------------------
  591|      0|      *rv = -1;
  592|      0|      break;
  593|      0|    }
  594|      0|  }
  595|       |
  596|       |  /*
  597|       |  ** third pass
  598|       |  ** fill the nas[cn].ap
  599|       |  */
  600|       |
  601|      0|  if (*rv < 0) {
  ------------------
  |  Branch (601:7): [True: 0, False: 0]
  ------------------
  602|      0|    if (nas != nasArray) {
  ------------------
  |  Branch (602:9): [True: 0, False: 0]
  ------------------
  603|      0|      PR_DELETE(nas);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  604|      0|    }
  605|      0|    return NULL;
  606|      0|  }
  607|       |
  608|      0|  cn = 0;
  609|      0|  while (cn < number) {
  ------------------
  |  Branch (609:10): [True: 0, False: 0]
  ------------------
  610|      0|    if (nas[cn].type == TYPE_UNKNOWN) {
  ------------------
  |  |   88|      0|#define TYPE_UNKNOWN 20
  ------------------
  |  Branch (610:9): [True: 0, False: 0]
  ------------------
  611|      0|      cn++;
  612|      0|      continue;
  613|      0|    }
  614|       |
  615|      0|    switch (nas[cn].type) {
  616|      0|      case TYPE_INT16:
  ------------------
  |  |   74|      0|#define TYPE_INT16 0
  ------------------
  |  Branch (616:7): [True: 0, False: 0]
  ------------------
  617|      0|      case TYPE_UINT16:
  ------------------
  |  |   75|      0|#define TYPE_UINT16 1
  ------------------
  |  Branch (617:7): [True: 0, False: 0]
  ------------------
  618|      0|      case TYPE_INTN:
  ------------------
  |  |   76|      0|#define TYPE_INTN 2
  ------------------
  |  Branch (618:7): [True: 0, False: 0]
  ------------------
  619|      0|        nas[cn].u.i = va_arg(ap, int);
  620|      0|        break;
  621|       |
  622|      0|      case TYPE_UINTN:
  ------------------
  |  |   77|      0|#define TYPE_UINTN 3
  ------------------
  |  Branch (622:7): [True: 0, False: 0]
  ------------------
  623|      0|        nas[cn].u.ui = va_arg(ap, unsigned int);
  624|      0|        break;
  625|       |
  626|      0|      case TYPE_INT32:
  ------------------
  |  |   78|      0|#define TYPE_INT32 4
  ------------------
  |  Branch (626:7): [True: 0, False: 0]
  ------------------
  627|      0|        nas[cn].u.i32 = va_arg(ap, PRInt32);
  628|      0|        break;
  629|       |
  630|      0|      case TYPE_UINT32:
  ------------------
  |  |   79|      0|#define TYPE_UINT32 5
  ------------------
  |  Branch (630:7): [True: 0, False: 0]
  ------------------
  631|      0|        nas[cn].u.ui32 = va_arg(ap, PRUint32);
  632|      0|        break;
  633|       |
  634|      0|      case TYPE_INT64:
  ------------------
  |  |   80|      0|#define TYPE_INT64 6
  ------------------
  |  Branch (634:7): [True: 0, False: 0]
  ------------------
  635|      0|        nas[cn].u.ll = va_arg(ap, PRInt64);
  636|      0|        break;
  637|       |
  638|      0|      case TYPE_UINT64:
  ------------------
  |  |   81|      0|#define TYPE_UINT64 7
  ------------------
  |  Branch (638:7): [True: 0, False: 0]
  ------------------
  639|      0|        nas[cn].u.ull = va_arg(ap, PRUint64);
  640|      0|        break;
  641|       |
  642|      0|      case TYPE_STRING:
  ------------------
  |  |   82|      0|#define TYPE_STRING 8
  ------------------
  |  Branch (642:7): [True: 0, False: 0]
  ------------------
  643|      0|        nas[cn].u.s = va_arg(ap, char*);
  644|      0|        break;
  645|       |
  646|       |#ifdef WIN32
  647|       |      case TYPE_WSTRING:
  648|       |        nas[cn].u.ws = va_arg(ap, WCHAR*);
  649|       |        break;
  650|       |#endif
  651|       |
  652|      0|      case TYPE_INTSTR:
  ------------------
  |  |   84|      0|#define TYPE_INTSTR 10
  ------------------
  |  Branch (652:7): [True: 0, False: 0]
  ------------------
  653|      0|        nas[cn].u.ip = va_arg(ap, int*);
  654|      0|        break;
  655|       |
  656|      0|      case TYPE_DOUBLE:
  ------------------
  |  |   83|      0|#define TYPE_DOUBLE 9
  ------------------
  |  Branch (656:7): [True: 0, False: 0]
  ------------------
  657|      0|        nas[cn].u.d = va_arg(ap, double);
  658|      0|        break;
  659|       |
  660|      0|      default:
  ------------------
  |  Branch (660:7): [True: 0, False: 0]
  ------------------
  661|      0|        if (nas != nasArray) {
  ------------------
  |  Branch (661:13): [True: 0, False: 0]
  ------------------
  662|      0|          PR_DELETE(nas);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  663|      0|        }
  664|      0|        *rv = -1;
  665|      0|        return NULL;
  666|      0|    }
  667|       |
  668|      0|    cn++;
  669|      0|  }
  670|       |
  671|      0|  return nas;
  672|      0|}
prprf.c:cvt_l:
  228|  16.3k|                 int type, int flags, const char* hexp) {
  229|  16.3k|  char cvtbuf[100];
  230|  16.3k|  char* cvt;
  231|  16.3k|  int digits;
  232|       |
  233|       |  /* according to the man page this needs to happen */
  234|  16.3k|  if ((prec == 0) && (num == 0)) {
  ------------------
  |  Branch (234:7): [True: 0, False: 16.3k]
  |  Branch (234:22): [True: 0, False: 0]
  ------------------
  235|      0|    return 0;
  236|      0|  }
  237|       |
  238|       |  /*
  239|       |  ** Converting decimal is a little tricky. In the unsigned case we
  240|       |  ** need to stop when we hit 10 digits. In the signed case, we can
  241|       |  ** stop when the number is zero.
  242|       |  */
  243|  16.3k|  cvt = cvtbuf + sizeof(cvtbuf);
  244|  16.3k|  digits = 0;
  245|  37.1k|  while (num) {
  ------------------
  |  Branch (245:10): [True: 20.7k, False: 16.3k]
  ------------------
  246|  20.7k|    int digit = (((unsigned long)num) % radix) & 0xF;
  247|  20.7k|    *--cvt = hexp[digit];
  248|  20.7k|    digits++;
  249|  20.7k|    num = (long)(((unsigned long)num) / radix);
  250|  20.7k|  }
  251|  16.3k|  if (digits == 0) {
  ------------------
  |  Branch (251:7): [True: 999, False: 15.3k]
  ------------------
  252|    999|    *--cvt = '0';
  253|    999|    digits++;
  254|    999|  }
  255|       |
  256|       |  /*
  257|       |  ** Now that we have the number converted without its sign, deal with
  258|       |  ** the sign and zero padding.
  259|       |  */
  260|  16.3k|  return fill_n(ss, cvt, digits, width, prec, type, flags);
  261|  16.3k|}
prprf.c:fill_n:
  138|  16.6k|                  int prec, int type, int flags) {
  139|  16.6k|  int zerowidth = 0;
  140|  16.6k|  int precwidth = 0;
  141|  16.6k|  int signwidth = 0;
  142|  16.6k|  int leftspaces = 0;
  143|  16.6k|  int rightspaces = 0;
  144|  16.6k|  int cvtwidth;
  145|  16.6k|  int rv;
  146|  16.6k|  char sign;
  147|       |
  148|  16.6k|  if ((type & 1) == 0) {
  ------------------
  |  Branch (148:7): [True: 0, False: 16.6k]
  ------------------
  149|      0|    if (flags & FLAG_NEG) {
  ------------------
  |  |   94|      0|#define FLAG_NEG 0x10
  ------------------
  |  Branch (149:9): [True: 0, False: 0]
  ------------------
  150|      0|      sign = '-';
  151|      0|      signwidth = 1;
  152|      0|    } else if (flags & FLAG_SIGNED) {
  ------------------
  |  |   91|      0|#define FLAG_SIGNED 0x2
  ------------------
  |  Branch (152:16): [True: 0, False: 0]
  ------------------
  153|      0|      sign = '+';
  154|      0|      signwidth = 1;
  155|      0|    } else if (flags & FLAG_SPACED) {
  ------------------
  |  |   92|      0|#define FLAG_SPACED 0x4
  ------------------
  |  Branch (155:16): [True: 0, False: 0]
  ------------------
  156|      0|      sign = ' ';
  157|      0|      signwidth = 1;
  158|      0|    }
  159|      0|  }
  160|  16.6k|  cvtwidth = signwidth + srclen;
  161|       |
  162|  16.6k|  if (prec > 0) {
  ------------------
  |  Branch (162:7): [True: 0, False: 16.6k]
  ------------------
  163|      0|    if (prec > srclen) {
  ------------------
  |  Branch (163:9): [True: 0, False: 0]
  ------------------
  164|      0|      precwidth = prec - srclen; /* Need zero filling */
  165|      0|      cvtwidth += precwidth;
  166|      0|    }
  167|      0|  }
  168|       |
  169|  16.6k|  if ((flags & FLAG_ZEROS) && (prec < 0)) {
  ------------------
  |  |   93|  16.6k|#define FLAG_ZEROS 0x8
  ------------------
  |  Branch (169:7): [True: 0, False: 16.6k]
  |  Branch (169:31): [True: 0, False: 0]
  ------------------
  170|      0|    if (width > cvtwidth) {
  ------------------
  |  Branch (170:9): [True: 0, False: 0]
  ------------------
  171|      0|      zerowidth = width - cvtwidth; /* Zero filling */
  172|      0|      cvtwidth += zerowidth;
  173|      0|    }
  174|      0|  }
  175|       |
  176|  16.6k|  if (flags & FLAG_LEFT) {
  ------------------
  |  |   90|  16.6k|#define FLAG_LEFT 0x1
  ------------------
  |  Branch (176:7): [True: 0, False: 16.6k]
  ------------------
  177|      0|    if (width > cvtwidth) {
  ------------------
  |  Branch (177:9): [True: 0, False: 0]
  ------------------
  178|       |      /* Space filling on the right (i.e. left adjusting) */
  179|      0|      rightspaces = width - cvtwidth;
  180|      0|    }
  181|  16.6k|  } else {
  182|  16.6k|    if (width > cvtwidth) {
  ------------------
  |  Branch (182:9): [True: 0, False: 16.6k]
  ------------------
  183|       |      /* Space filling on the left (i.e. right adjusting) */
  184|      0|      leftspaces = width - cvtwidth;
  185|      0|    }
  186|  16.6k|  }
  187|  16.6k|  while (--leftspaces >= 0) {
  ------------------
  |  Branch (187:10): [True: 0, False: 16.6k]
  ------------------
  188|      0|    rv = (*ss->stuff)(ss, " ", 1);
  189|      0|    if (rv < 0) {
  ------------------
  |  Branch (189:9): [True: 0, False: 0]
  ------------------
  190|      0|      return rv;
  191|      0|    }
  192|      0|  }
  193|  16.6k|  if (signwidth) {
  ------------------
  |  Branch (193:7): [True: 0, False: 16.6k]
  ------------------
  194|      0|    rv = (*ss->stuff)(ss, &sign, 1);
  195|      0|    if (rv < 0) {
  ------------------
  |  Branch (195:9): [True: 0, False: 0]
  ------------------
  196|      0|      return rv;
  197|      0|    }
  198|      0|  }
  199|  16.6k|  while (--precwidth >= 0) {
  ------------------
  |  Branch (199:10): [True: 0, False: 16.6k]
  ------------------
  200|      0|    rv = (*ss->stuff)(ss, "0", 1);
  201|      0|    if (rv < 0) {
  ------------------
  |  Branch (201:9): [True: 0, False: 0]
  ------------------
  202|      0|      return rv;
  203|      0|    }
  204|      0|  }
  205|  16.6k|  while (--zerowidth >= 0) {
  ------------------
  |  Branch (205:10): [True: 0, False: 16.6k]
  ------------------
  206|      0|    rv = (*ss->stuff)(ss, "0", 1);
  207|      0|    if (rv < 0) {
  ------------------
  |  Branch (207:9): [True: 0, False: 0]
  ------------------
  208|      0|      return rv;
  209|      0|    }
  210|      0|  }
  211|  16.6k|  rv = (*ss->stuff)(ss, src, srclen);
  212|  16.6k|  if (rv < 0) {
  ------------------
  |  Branch (212:7): [True: 0, False: 16.6k]
  ------------------
  213|      0|    return rv;
  214|      0|  }
  215|  16.6k|  while (--rightspaces >= 0) {
  ------------------
  |  Branch (215:10): [True: 0, False: 16.6k]
  ------------------
  216|      0|    rv = (*ss->stuff)(ss, " ", 1);
  217|      0|    if (rv < 0) {
  ------------------
  |  Branch (217:9): [True: 0, False: 0]
  ------------------
  218|      0|      return rv;
  219|      0|    }
  220|      0|  }
  221|  16.6k|  return 0;
  222|  16.6k|}
prprf.c:cvt_ll:
  267|    298|                  int type, int flags, const char* hexp) {
  268|    298|  char cvtbuf[100];
  269|    298|  char* cvt;
  270|    298|  int digits;
  271|    298|  PRInt64 rad;
  272|       |
  273|       |  /* according to the man page this needs to happen */
  274|    298|  if ((prec == 0) && (LL_IS_ZERO(num))) {
  ------------------
  |  |   75|      0|#define LL_IS_ZERO(a)       ((a) == 0)
  ------------------
  |  Branch (274:7): [True: 0, False: 298]
  |  Branch (274:22): [True: 0, False: 0]
  ------------------
  275|      0|    return 0;
  276|      0|  }
  277|       |
  278|       |  /*
  279|       |  ** Converting decimal is a little tricky. In the unsigned case we
  280|       |  ** need to stop when we hit 10 digits. In the signed case, we can
  281|       |  ** stop when the number is zero.
  282|       |  */
  283|    298|  LL_I2L(rad, radix);
  ------------------
  |  |  149|    298|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  284|    298|  cvt = cvtbuf + sizeof(cvtbuf);
  285|    298|  digits = 0;
  286|  3.63k|  while (!LL_IS_ZERO(num)) {
  ------------------
  |  |   75|  3.63k|#define LL_IS_ZERO(a)       ((a) == 0)
  ------------------
  |  Branch (286:10): [True: 3.33k, False: 298]
  ------------------
  287|  3.33k|    PRInt32 digit;
  288|  3.33k|    PRInt64 quot, rem;
  289|  3.33k|    LL_UDIVMOD(&quot, &rem, num, rad);
  ------------------
  |  |  164|  3.33k|    (*(qp) = ((PRUint64)(a) / (b)), \
  |  |  165|  3.33k|     *(rp) = ((PRUint64)(a) % (b)))
  ------------------
  290|  3.33k|    LL_L2I(digit, rem);
  ------------------
  |  |  144|  3.33k|#define LL_L2I(i, l)        ((i) = (PRInt32)(l))
  ------------------
  291|  3.33k|    *--cvt = hexp[digit & 0xf];
  292|  3.33k|    digits++;
  293|  3.33k|    num = quot;
  294|  3.33k|  }
  295|    298|  if (digits == 0) {
  ------------------
  |  Branch (295:7): [True: 0, False: 298]
  ------------------
  296|      0|    *--cvt = '0';
  297|      0|    digits++;
  298|      0|  }
  299|       |
  300|       |  /*
  301|       |  ** Now that we have the number converted without its sign, deal with
  302|       |  ** the sign and zero padding.
  303|       |  */
  304|    298|  return fill_n(ss, cvt, digits, width, prec, type, flags);
  305|    298|}
prprf.c:cvt_s:
  351|  18.8k|                 int flags) {
  352|  18.8k|  int slen;
  353|       |
  354|  18.8k|  if (prec == 0) {
  ------------------
  |  Branch (354:7): [True: 0, False: 18.8k]
  ------------------
  355|      0|    return 0;
  356|      0|  }
  357|       |
  358|       |  /* Limit string length by precision value */
  359|  18.8k|  if (!str) {
  ------------------
  |  Branch (359:7): [True: 0, False: 18.8k]
  ------------------
  360|      0|    str = "(null)";
  361|      0|  }
  362|  18.8k|  if (prec > 0) {
  ------------------
  |  Branch (362:7): [True: 0, False: 18.8k]
  ------------------
  363|       |    /* this is:  slen = strnlen(str, prec); */
  364|      0|    register const char* s;
  365|       |
  366|      0|    for (s = str; prec && *s; s++, prec--);
  ------------------
  |  Branch (366:19): [True: 0, False: 0]
  |  Branch (366:27): [True: 0, False: 0]
  ------------------
  367|      0|    slen = s - str;
  368|  18.8k|  } else {
  369|  18.8k|    slen = strlen(str);
  370|  18.8k|  }
  371|       |
  372|       |  /* and away we go */
  373|  18.8k|  return fill2(ss, str, slen, width, flags);
  374|  18.8k|}
prprf.c:fill2:
  100|  18.8k|                 int flags) {
  101|  18.8k|  char space = ' ';
  102|  18.8k|  int rv;
  103|       |
  104|  18.8k|  width -= srclen;
  105|  18.8k|  if ((width > 0) && ((flags & FLAG_LEFT) == 0)) { /* Right adjusting */
  ------------------
  |  |   90|      0|#define FLAG_LEFT 0x1
  ------------------
  |  Branch (105:7): [True: 0, False: 18.8k]
  |  Branch (105:22): [True: 0, False: 0]
  ------------------
  106|      0|    if (flags & FLAG_ZEROS) {
  ------------------
  |  |   93|      0|#define FLAG_ZEROS 0x8
  ------------------
  |  Branch (106:9): [True: 0, False: 0]
  ------------------
  107|      0|      space = '0';
  108|      0|    }
  109|      0|    while (--width >= 0) {
  ------------------
  |  Branch (109:12): [True: 0, False: 0]
  ------------------
  110|      0|      rv = (*ss->stuff)(ss, &space, 1);
  111|      0|      if (rv < 0) {
  ------------------
  |  Branch (111:11): [True: 0, False: 0]
  ------------------
  112|      0|        return rv;
  113|      0|      }
  114|      0|    }
  115|      0|  }
  116|       |
  117|       |  /* Copy out the source data */
  118|  18.8k|  rv = (*ss->stuff)(ss, src, srclen);
  119|  18.8k|  if (rv < 0) {
  ------------------
  |  Branch (119:7): [True: 0, False: 18.8k]
  ------------------
  120|      0|    return rv;
  121|      0|  }
  122|       |
  123|  18.8k|  if ((width > 0) && ((flags & FLAG_LEFT) != 0)) { /* Left adjusting */
  ------------------
  |  |   90|      0|#define FLAG_LEFT 0x1
  ------------------
  |  Branch (123:7): [True: 0, False: 18.8k]
  |  Branch (123:22): [True: 0, False: 0]
  ------------------
  124|      0|    while (--width >= 0) {
  ------------------
  |  Branch (124:12): [True: 0, False: 0]
  ------------------
  125|      0|      rv = (*ss->stuff)(ss, &space, 1);
  126|      0|      if (rv < 0) {
  ------------------
  |  Branch (126:11): [True: 0, False: 0]
  ------------------
  127|      0|        return rv;
  128|      0|      }
  129|      0|    }
  130|      0|  }
  131|  18.8k|  return 0;
  132|  18.8k|}
prprf.c:GrowStuff:
 1119|  75.8k|static int GrowStuff(SprintfState* ss, const char* sp, PRUint32 len) {
 1120|  75.8k|  ptrdiff_t off;
 1121|  75.8k|  char* newbase;
 1122|  75.8k|  PRUint32 newlen;
 1123|       |
 1124|  75.8k|  off = ss->cur - ss->base;
 1125|  75.8k|  if (PR_UINT32_MAX - len < off) {
  ------------------
  |  |  302|  75.8k|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  ------------------
  |  |  |  |  282|  75.8k|#define PR_UINT32(x) x ## U
  |  |  ------------------
  ------------------
  |  Branch (1125:7): [True: 0, False: 75.8k]
  ------------------
 1126|       |    /* off + len would be too big. */
 1127|      0|    return -1;
 1128|      0|  }
 1129|  75.8k|  if (off + len >= ss->maxlen) {
  ------------------
  |  Branch (1129:7): [True: 14.4k, False: 61.3k]
  ------------------
 1130|       |    /* Grow the buffer */
 1131|  14.4k|    PRUint32 increment = (len > 32) ? len : 32;
  ------------------
  |  Branch (1131:26): [True: 791, False: 13.6k]
  ------------------
 1132|  14.4k|    if (PR_UINT32_MAX - ss->maxlen < increment) {
  ------------------
  |  |  302|  14.4k|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  ------------------
  |  |  |  |  282|  14.4k|#define PR_UINT32(x) x ## U
  |  |  ------------------
  ------------------
  |  Branch (1132:9): [True: 0, False: 14.4k]
  ------------------
 1133|       |      /* ss->maxlen + increment would overflow. */
 1134|      0|      return -1;
 1135|      0|    }
 1136|  14.4k|    newlen = ss->maxlen + increment;
 1137|  14.4k|    if (newlen > PR_INT32_MAX) {
  ------------------
  |  |  300|  14.4k|#define PR_INT32_MAX PR_INT32(2147483647)
  |  |  ------------------
  |  |  |  |  281|  14.4k|#define PR_INT32(x)  x
  |  |  ------------------
  ------------------
  |  Branch (1137:9): [True: 0, False: 14.4k]
  ------------------
 1138|      0|      return -1;
 1139|      0|    }
 1140|  14.4k|    if (ss->base) {
  ------------------
  |  Branch (1140:9): [True: 1.12k, False: 13.2k]
  ------------------
 1141|  1.12k|      newbase = (char*)PR_REALLOC(ss->base, newlen);
  ------------------
  |  |   77|  1.12k|#define PR_REALLOC(_ptr, _size) (PR_Realloc((_ptr), (_size)))
  ------------------
 1142|  13.2k|    } else {
 1143|  13.2k|      newbase = (char*)PR_MALLOC(newlen);
  ------------------
  |  |   55|  13.2k|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  ------------------
 1144|  13.2k|    }
 1145|  14.4k|    if (!newbase) {
  ------------------
  |  Branch (1145:9): [True: 0, False: 14.4k]
  ------------------
 1146|       |      /* Ran out of memory */
 1147|      0|      return -1;
 1148|      0|    }
 1149|  14.4k|    ss->base = newbase;
 1150|  14.4k|    ss->maxlen = newlen;
 1151|  14.4k|    ss->cur = ss->base + off;
 1152|  14.4k|  }
 1153|       |
 1154|       |  /* Copy data */
 1155|   275k|  while (len) {
  ------------------
  |  Branch (1155:10): [True: 199k, False: 75.8k]
  ------------------
 1156|   199k|    --len;
 1157|   199k|    *ss->cur++ = *sp++;
 1158|   199k|  }
 1159|  75.8k|  PR_ASSERT((PRUint32)(ss->cur - ss->base) <= ss->maxlen);
  ------------------
  |  |  208|  75.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 75.8k, False: 0]
  |  |  ------------------
  ------------------
 1160|  75.8k|  return 0;
 1161|  75.8k|}
prprf.c:LimitStuff:
 1202|  19.4k|static int LimitStuff(SprintfState* ss, const char* sp, PRUint32 len) {
 1203|  19.4k|  PRUint32 limit = ss->maxlen - (ss->cur - ss->base);
 1204|       |
 1205|  19.4k|  if (len > limit) {
  ------------------
  |  Branch (1205:7): [True: 0, False: 19.4k]
  ------------------
 1206|      0|    len = limit;
 1207|      0|  }
 1208|  82.4k|  while (len) {
  ------------------
  |  Branch (1208:10): [True: 63.0k, False: 19.4k]
  ------------------
 1209|  63.0k|    --len;
 1210|  63.0k|    *ss->cur++ = *sp++;
 1211|  63.0k|  }
 1212|  19.4k|  return 0;
 1213|  19.4k|}

_PR_InitLinker:
  104|      1|void _PR_InitLinker(void) {
  105|      1|  PRLibrary* lm = NULL;
  106|      1|#if defined(XP_UNIX)
  107|      1|  void* h;
  108|      1|#endif
  109|       |
  110|      1|  if (!pr_linker_lock) {
  ------------------
  |  Branch (110:7): [True: 1, False: 0]
  ------------------
  111|      1|    pr_linker_lock = PR_NewNamedMonitor("linker-lock");
  112|      1|  }
  113|      1|  PR_EnterMonitor(pr_linker_lock);
  114|       |
  115|       |#if defined(XP_PC)
  116|       |  lm = PR_NEWZAP(PRLibrary);
  117|       |  lm->name = strdup("Executable");
  118|       |  /* A module handle for the executable. */
  119|       |  lm->dlh = GetModuleHandle(NULL);
  120|       |
  121|       |  lm->refCount = 1;
  122|       |  lm->staticTable = NULL;
  123|       |  pr_exe_loadmap = lm;
  124|       |  pr_loadmap = lm;
  125|       |
  126|       |#elif defined(XP_UNIX)
  127|       |#  ifdef HAVE_DLL
  128|      1|#    if defined(USE_DLFCN) && !defined(NO_DLOPEN_NULL)
  129|      1|  h = dlopen(0, RTLD_LAZY);
  130|      1|  if (!h) {
  ------------------
  |  Branch (130:7): [True: 0, False: 1]
  ------------------
  131|      0|    char* error;
  132|       |
  133|      0|    DLLErrorInternal(_MD_ERRNO());
  ------------------
  |  |  314|      0|#define _MD_ERRNO()                 (errno)
  ------------------
  134|      0|    error = (char*)PR_MALLOC(PR_GetErrorTextLength());
  ------------------
  |  |   55|      0|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  ------------------
  135|      0|    (void)PR_GetErrorText(error);
  136|      0|    fprintf(stderr, "failed to initialize shared libraries [%s]\n", error);
  137|      0|    PR_DELETE(error);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  138|      0|    abort(); /* XXX */
  139|      0|  }
  140|       |#    elif defined(USE_HPSHL)
  141|       |  h = NULL;
  142|       |  /* don't abort with this NULL */
  143|       |#    elif defined(NO_DLOPEN_NULL)
  144|       |  h = NULL; /* XXXX  toshok */ /* XXXX  vlad */
  145|       |#    else
  146|       |#      error no dll strategy
  147|       |#    endif /* USE_DLFCN */
  148|       |
  149|      1|  lm = PR_NEWZAP(PRLibrary);
  ------------------
  |  |   99|      1|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  150|      1|  if (lm) {
  ------------------
  |  Branch (150:7): [True: 1, False: 0]
  ------------------
  151|      1|    lm->name = strdup("a.out");
  152|      1|    lm->refCount = 1;
  153|      1|    lm->dlh = h;
  154|      1|    lm->staticTable = NULL;
  155|      1|  }
  156|      1|  pr_exe_loadmap = lm;
  157|      1|  pr_loadmap = lm;
  158|      1|#  endif   /* HAVE_DLL */
  159|      1|#endif     /* XP_UNIX */
  160|       |
  161|      1|  if (lm) {
  ------------------
  |  Branch (161:7): [True: 1, False: 0]
  ------------------
  162|      1|    PR_LOG(_pr_linker_lm, PR_LOG_MIN, ("Loaded library %s (init)", lm->name));
  ------------------
  |  |  177|      1|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  178|      1|      if (PR_LOG_TEST(_module,_level)) { \
  |  |  ------------------
  |  |  |  |  167|      1|    ((_module)->level >= (_level))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (167:5): [True: 0, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  179|      0|      PR_LogPrint _args;         \
  |  |  180|      0|      }                     \
  |  |  181|      1|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  163|      1|  }
  164|       |
  165|      1|  PR_ExitMonitor(pr_linker_lock);
  166|      1|}

_PR_InitZones:
  140|      1|void _PR_InitZones(void) {
  141|      1|  int i, j;
  142|      1|  char* envp;
  143|      1|  PRBool* sym;
  144|       |
  145|      1|  if ((sym = (PRBool*)pr_FindSymbolInProg("nspr_use_zone_allocator")) != NULL) {
  ------------------
  |  Branch (145:7): [True: 0, False: 1]
  ------------------
  146|      0|    use_zone_allocator = *sym;
  147|      1|  } else if ((envp = getenv("NSPR_USE_ZONE_ALLOCATOR")) != NULL) {
  ------------------
  |  Branch (147:14): [True: 0, False: 1]
  ------------------
  148|      0|    use_zone_allocator = (atoi(envp) == 1);
  149|      0|  }
  150|       |
  151|      1|  if (!use_zone_allocator) {
  ------------------
  |  Branch (151:7): [True: 1, False: 0]
  ------------------
  152|      1|    return;
  153|      1|  }
  154|       |
  155|      0|  for (j = 0; j < THREAD_POOLS; j++) {
  ------------------
  |  |   47|      0|#  define THREAD_POOLS 11 /* prime number for modulus */
  ------------------
  |  Branch (155:15): [True: 0, False: 0]
  ------------------
  156|      0|    for (i = 0; i < MEM_ZONES; i++) {
  ------------------
  |  |   46|      0|#  define MEM_ZONES 7
  ------------------
  |  Branch (156:17): [True: 0, False: 0]
  ------------------
  157|      0|      MemoryZone* mz = &zones[i][j];
  158|      0|      int rv = pthread_mutex_init(&mz->lock, NULL);
  159|      0|      PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  160|      0|      if (rv != 0) {
  ------------------
  |  Branch (160:11): [True: 0, False: 0]
  ------------------
  161|      0|        goto loser;
  162|      0|      }
  163|      0|      mz->blockSize = 16 << (2 * i);
  164|      0|    }
  165|      0|  }
  166|      0|  return;
  167|       |
  168|      0|loser:
  169|      0|  _PR_DestroyZones();
  170|      0|  return;
  171|      0|}
PR_Malloc:
  420|  8.19M|PR_IMPLEMENT(void*) PR_Malloc(PRUint32 size) {
  421|  8.19M|  if (!_pr_initialized) {
  ------------------
  |  Branch (421:7): [True: 0, False: 8.19M]
  ------------------
  422|      0|    _PR_ImplicitInitialization();
  423|      0|  }
  424|       |
  425|  8.19M|  return use_zone_allocator ? pr_ZoneMalloc(size) : malloc(size);
  ------------------
  |  Branch (425:10): [True: 0, False: 8.19M]
  ------------------
  426|  8.19M|}
PR_Calloc:
  428|  10.3M|PR_IMPLEMENT(void*) PR_Calloc(PRUint32 nelem, PRUint32 elsize) {
  429|  10.3M|  if (!_pr_initialized) {
  ------------------
  |  Branch (429:7): [True: 0, False: 10.3M]
  ------------------
  430|      0|    _PR_ImplicitInitialization();
  431|      0|  }
  432|       |
  433|  10.3M|  return use_zone_allocator ? pr_ZoneCalloc(nelem, elsize)
  ------------------
  |  Branch (433:10): [True: 0, False: 10.3M]
  ------------------
  434|  10.3M|                            : calloc(nelem, elsize);
  435|  10.3M|}
PR_Realloc:
  437|  3.81k|PR_IMPLEMENT(void*) PR_Realloc(void* ptr, PRUint32 size) {
  438|  3.81k|  if (!_pr_initialized) {
  ------------------
  |  Branch (438:7): [True: 0, False: 3.81k]
  ------------------
  439|      0|    _PR_ImplicitInitialization();
  440|      0|  }
  441|       |
  442|  3.81k|  return use_zone_allocator ? pr_ZoneRealloc(ptr, size) : realloc(ptr, size);
  ------------------
  |  Branch (442:10): [True: 0, False: 3.81k]
  ------------------
  443|  3.81k|}
PR_Free:
  445|  18.5M|PR_IMPLEMENT(void) PR_Free(void* ptr) {
  446|  18.5M|  if (use_zone_allocator) {
  ------------------
  |  Branch (446:7): [True: 0, False: 18.5M]
  ------------------
  447|      0|    pr_ZoneFree(ptr);
  448|  18.5M|  } else {
  449|  18.5M|    free(ptr);
  450|  18.5M|  }
  451|  18.5M|}
prmem.c:pr_FindSymbolInProg:
   91|      1|static void* pr_FindSymbolInProg(const char* name) {
   92|      1|  void* h;
   93|      1|  void* sym;
   94|       |
   95|      1|  h = dlopen(0, RTLD_LAZY);
   96|      1|  if (h == NULL) {
  ------------------
  |  Branch (96:7): [True: 0, False: 1]
  ------------------
   97|      0|    return NULL;
   98|      0|  }
   99|      1|  sym = dlsym(h, name);
  100|      1|  (void)dlclose(h);
  101|      1|  return sym;
  102|      1|}

PR_GetPageSize:
   59|      1|PR_IMPLEMENT(PRInt32) PR_GetPageSize(void) {
   60|      1|  if (!_pr_pageSize) {
  ------------------
  |  Branch (60:7): [True: 1, False: 0]
  ------------------
   61|      1|    GetPageSize();
   62|      1|  }
   63|      1|  return _pr_pageSize;
   64|      1|}
prosdep.c:GetPageSize:
   22|      1|static void GetPageSize(void) {
   23|      1|  PRInt32 pageSize;
   24|       |
   25|       |  /* Get page size */
   26|      1|#ifdef XP_UNIX
   27|      1|#  if defined AIX || defined LINUX || defined __GNU__ || defined __GLIBC__ || \
   28|      1|      defined FREEBSD || defined NETBSD || defined OPENBSD || defined DARWIN
   29|      1|  _pr_pageSize = getpagesize();
   30|       |#  elif defined(HPUX)
   31|       |  /* I have no idea. Don't get me started. --Rob */
   32|       |  _pr_pageSize = sysconf(_SC_PAGE_SIZE);
   33|       |#  else
   34|       |  _pr_pageSize = sysconf(_SC_PAGESIZE);
   35|       |#  endif
   36|      1|#endif /* XP_UNIX */
   37|       |
   38|       |#ifdef XP_PC
   39|       |#  ifdef _WIN32
   40|       |  SYSTEM_INFO info;
   41|       |  GetSystemInfo(&info);
   42|       |  _pr_pageSize = info.dwPageSize;
   43|       |#  else
   44|       |  _pr_pageSize = 4096;
   45|       |#  endif
   46|       |#endif /* XP_PC */
   47|       |
   48|      1|  pageSize = _pr_pageSize;
   49|      1|  PR_CEILING_LOG2(_pr_pageShift, pageSize);
  ------------------
  |  |   72|      1|  PR_BEGIN_MACRO                       \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      1|    PRUint32 j_ = (PRUint32)(_n);      \
  |  |   74|      1|    (_log2) = (j_ <= 1 ? 0 : 32 - pr_bitscan_clz32(j_ - 1)); \
  |  |  ------------------
  |  |  |  |   40|      1|# define pr_bitscan_clz32(val)  __builtin_clz(val)
  |  |  ------------------
  |  |  |  Branch (74:16): [True: 0, False: 1]
  |  |  ------------------
  |  |   75|      1|  PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   50|      1|}

_MD_EarlyInit:
    8|      1|void _MD_EarlyInit(void) {}

_PR_UnixInit:
 2585|      1|void _PR_UnixInit(void) {
 2586|      1|  struct sigaction sigact;
 2587|      1|  int rv;
 2588|       |
 2589|      1|  sigemptyset(&timer_set);
 2590|       |
 2591|       |#if !defined(_PR_PTHREADS)
 2592|       |
 2593|       |  sigaddset(&timer_set, SIGALRM);
 2594|       |  sigemptyset(&empty_set);
 2595|       |  intr_timeout_ticks = PR_SecondsToInterval(_PR_INTERRUPT_CHECK_INTERVAL_SECS);
 2596|       |
 2597|       |#  if defined(SOLARIS)
 2598|       |
 2599|       |  if (getenv("NSPR_SIGSEGV_HANDLE")) {
 2600|       |    sigact.sa_handler = sigsegvhandler;
 2601|       |    sigact.sa_flags = 0;
 2602|       |    sigact.sa_mask = timer_set;
 2603|       |    sigaction(SIGSEGV, &sigact, 0);
 2604|       |  }
 2605|       |
 2606|       |  if (getenv("NSPR_SIGABRT_HANDLE")) {
 2607|       |    sigact.sa_handler = sigaborthandler;
 2608|       |    sigact.sa_flags = 0;
 2609|       |    sigact.sa_mask = timer_set;
 2610|       |    sigaction(SIGABRT, &sigact, 0);
 2611|       |  }
 2612|       |
 2613|       |  if (getenv("NSPR_SIGBUS_HANDLE")) {
 2614|       |    sigact.sa_handler = sigbushandler;
 2615|       |    sigact.sa_flags = 0;
 2616|       |    sigact.sa_mask = timer_set;
 2617|       |    sigaction(SIGBUS, &sigact, 0);
 2618|       |  }
 2619|       |
 2620|       |#  endif
 2621|       |#endif /* !defined(_PR_PTHREADS) */
 2622|       |
 2623|      1|  sigact.sa_handler = SIG_IGN;
 2624|      1|  sigemptyset(&sigact.sa_mask);
 2625|      1|  sigact.sa_flags = 0;
 2626|      1|  rv = sigaction(SIGPIPE, &sigact, 0);
 2627|      1|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 2628|       |
 2629|      1|  _pr_unix_rename_lock = PR_NewLock();
 2630|      1|  PR_ASSERT(NULL != _pr_unix_rename_lock);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 2631|      1|  _pr_Xfe_mon = PR_NewMonitor();
 2632|      1|  PR_ASSERT(NULL != _pr_Xfe_mon);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 2633|       |
 2634|      1|  _PR_InitIOV(); /* one last hack */
 2635|      1|}
PR_Now:
 2749|  32.8k|PR_Now(void) {
 2750|  32.8k|  struct timeval tv;
 2751|  32.8k|  PRInt64 s, us, s2us;
 2752|       |
 2753|  32.8k|  GETTIMEOFDAY(&tv);
  ------------------
  |  |  506|  32.8k|#define GETTIMEOFDAY(tp) gettimeofday((tp), NULL)
  ------------------
 2754|  32.8k|  LL_I2L(s2us, PR_USEC_PER_SEC);
  ------------------
  |  |  149|  32.8k|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
 2755|  32.8k|  LL_I2L(s, tv.tv_sec);
  ------------------
  |  |  149|  32.8k|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
 2756|  32.8k|  LL_I2L(us, tv.tv_usec);
  ------------------
  |  |  149|  32.8k|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
 2757|  32.8k|  LL_MUL(s, s, s2us);
  ------------------
  |  |  115|  32.8k|#define LL_MUL(r, a, b)        ((r) = (a) * (b))
  ------------------
 2758|  32.8k|  LL_ADD(s, s, us);
  ------------------
  |  |  105|  32.8k|#define LL_ADD(r, a, b)     ((r) = (a) + (b))
  ------------------
 2759|  32.8k|  return s;
 2760|  32.8k|}
_PR_UNIX_TicksPerSecond2:
 2799|      2|PRIntervalTime _PR_UNIX_TicksPerSecond2() { return 1000; }
unix.c:_PR_InitIOV:
 2526|      1|static void _PR_InitIOV(void) {
 2527|       |#if defined(SOLARIS2_5)
 2528|       |  PRLibrary* lib;
 2529|       |  void* open64_func;
 2530|       |
 2531|       |  open64_func = PR_FindSymbolAndLibrary("open64", &lib);
 2532|       |  if (NULL != open64_func) {
 2533|       |    PR_ASSERT(NULL != lib);
 2534|       |    _md_iovector._open64 = (_MD_Open64)open64_func;
 2535|       |    _md_iovector._mmap64 = (_MD_Mmap64)PR_FindSymbol(lib, "mmap64");
 2536|       |    _md_iovector._fstat64 = (_MD_Fstat64)PR_FindSymbol(lib, "fstat64");
 2537|       |    _md_iovector._stat64 = (_MD_Stat64)PR_FindSymbol(lib, "stat64");
 2538|       |    _md_iovector._lseek64 = (_MD_Lseek64)PR_FindSymbol(lib, "lseek64");
 2539|       |    (void)PR_UnloadLibrary(lib);
 2540|       |  } else {
 2541|       |    _md_iovector._open64 = open;
 2542|       |    _md_iovector._mmap64 = _MD_Unix_mmap64;
 2543|       |    _md_iovector._fstat64 = _MD_solaris25_fstat64;
 2544|       |    _md_iovector._stat64 = _MD_solaris25_stat64;
 2545|       |    _md_iovector._lseek64 = _MD_Unix_lseek64;
 2546|       |  }
 2547|       |#elif defined(_PR_NO_LARGE_FILES)
 2548|       |  _md_iovector._open64 = open;
 2549|       |  _md_iovector._mmap64 = _MD_Unix_mmap64;
 2550|       |  _md_iovector._fstat64 = fstat;
 2551|       |  _md_iovector._stat64 = stat;
 2552|       |  _md_iovector._lseek64 = _MD_Unix_lseek64;
 2553|       |#elif defined(_PR_HAVE_OFF64_T)
 2554|       |#  if (defined(ANDROID) && __ANDROID_API__ < 21)
 2555|       |  /*
 2556|       |   * Android < 21 doesn't have open64.  We pass the O_LARGEFILE flag to open
 2557|       |   * in _MD_open.
 2558|       |   */
 2559|       |  _md_iovector._open64 = open;
 2560|       |#  else
 2561|      1|  _md_iovector._open64 = open64;
 2562|      1|#  endif
 2563|      1|  _md_iovector._mmap64 = mmap64;
 2564|       |#  if (defined(ANDROID) && __ANDROID_API__ < 21)
 2565|       |  /* Same as the open64 case for Android. */
 2566|       |  _md_iovector._fstat64 = (_MD_Fstat64)fstat;
 2567|       |  _md_iovector._stat64 = (_MD_Stat64)stat;
 2568|       |#  else
 2569|      1|  _md_iovector._fstat64 = fstat64;
 2570|      1|  _md_iovector._stat64 = stat64;
 2571|      1|#  endif
 2572|      1|  _md_iovector._lseek64 = lseek64;
 2573|       |#elif defined(_PR_HAVE_LARGE_OFF_T)
 2574|       |  _md_iovector._open64 = open;
 2575|       |  _md_iovector._mmap64 = mmap;
 2576|       |  _md_iovector._fstat64 = fstat;
 2577|       |  _md_iovector._stat64 = stat;
 2578|       |  _md_iovector._lseek64 = lseek;
 2579|       |#else
 2580|       |#  error "I don't know yet"
 2581|       |#endif
 2582|      1|  LL_I2L(minus_one, -1);
  ------------------
  |  |  149|      1|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
 2583|      1|} /* _PR_InitIOV */

_MD_unix_map_default_error:
   12|      1|void _MD_unix_map_default_error(int err) {
   13|      1|  PRErrorCode prError;
   14|       |
   15|      1|  switch (err) {
   16|      0|    case EACCES:
  ------------------
  |  Branch (16:5): [True: 0, False: 1]
  ------------------
   17|      0|      prError = PR_NO_ACCESS_RIGHTS_ERROR;
  ------------------
  |  |  118|      0|#define PR_NO_ACCESS_RIGHTS_ERROR                (-5966L)
  ------------------
   18|      0|      break;
   19|      0|    case EADDRINUSE:
  ------------------
  |  Branch (19:5): [True: 0, False: 1]
  ------------------
   20|      0|      prError = PR_ADDRESS_IN_USE_ERROR;
  ------------------
  |  |   70|      0|#define PR_ADDRESS_IN_USE_ERROR                  (-5982L)
  ------------------
   21|      0|      break;
   22|      0|    case EADDRNOTAVAIL:
  ------------------
  |  Branch (22:5): [True: 0, False: 1]
  ------------------
   23|      0|      prError = PR_ADDRESS_NOT_AVAILABLE_ERROR;
  ------------------
  |  |   58|      0|#define PR_ADDRESS_NOT_AVAILABLE_ERROR           (-5986L)
  ------------------
   24|      0|      break;
   25|      0|    case EAFNOSUPPORT:
  ------------------
  |  Branch (25:5): [True: 0, False: 1]
  ------------------
   26|      0|      prError = PR_ADDRESS_NOT_SUPPORTED_ERROR;
  ------------------
  |  |   61|      0|#define PR_ADDRESS_NOT_SUPPORTED_ERROR           (-5985L)
  ------------------
   27|      0|      break;
   28|      0|    case EAGAIN:
  ------------------
  |  Branch (28:5): [True: 0, False: 1]
  ------------------
   29|      0|      prError = PR_WOULD_BLOCK_ERROR;
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
   30|      0|      break;
   31|       |      /*
   32|       |       * On QNX and Neutrino, EALREADY is defined as EBUSY.
   33|       |       */
   34|      0|#if EALREADY != EBUSY
   35|      0|    case EALREADY:
  ------------------
  |  Branch (35:5): [True: 0, False: 1]
  ------------------
   36|      0|      prError = PR_ALREADY_INITIATED_ERROR;
  ------------------
  |  |  217|      0|#define PR_ALREADY_INITIATED_ERROR               (-5933L)
  ------------------
   37|      0|      break;
   38|      0|#endif
   39|      0|    case EBADF:
  ------------------
  |  Branch (39:5): [True: 0, False: 1]
  ------------------
   40|      0|      prError = PR_BAD_DESCRIPTOR_ERROR;
  ------------------
  |  |   19|      0|#define PR_BAD_DESCRIPTOR_ERROR                  (-5999L)
  ------------------
   41|      0|      break;
   42|      0|#ifdef EBADMSG
   43|      0|    case EBADMSG:
  ------------------
  |  Branch (43:5): [True: 0, False: 1]
  ------------------
   44|      0|      prError = PR_IO_ERROR;
  ------------------
  |  |   43|      0|#define PR_IO_ERROR                              (-5991L)
  ------------------
   45|      0|      break;
   46|      0|#endif
   47|      0|    case EBUSY:
  ------------------
  |  Branch (47:5): [True: 0, False: 1]
  ------------------
   48|      0|      prError = PR_FILESYSTEM_MOUNTED_ERROR;
  ------------------
  |  |  178|      0|#define PR_FILESYSTEM_MOUNTED_ERROR              (-5946L)
  ------------------
   49|      0|      break;
   50|      0|    case ECONNABORTED:
  ------------------
  |  Branch (50:5): [True: 0, False: 1]
  ------------------
   51|      0|      prError = PR_CONNECT_ABORTED_ERROR;
  ------------------
  |  |  232|      0|#define PR_CONNECT_ABORTED_ERROR                 (-5928L)
  ------------------
   52|      0|      break;
   53|      0|    case ECONNREFUSED:
  ------------------
  |  Branch (53:5): [True: 0, False: 1]
  ------------------
   54|      0|      prError = PR_CONNECT_REFUSED_ERROR;
  ------------------
  |  |   73|      0|#define PR_CONNECT_REFUSED_ERROR                 (-5981L)
  ------------------
   55|      0|      break;
   56|      0|    case ECONNRESET:
  ------------------
  |  Branch (56:5): [True: 0, False: 1]
  ------------------
   57|      0|      prError = PR_CONNECT_RESET_ERROR;
  ------------------
  |  |  133|      0|#define PR_CONNECT_RESET_ERROR                   (-5961L)
  ------------------
   58|      0|      break;
   59|      0|    case EDEADLK:
  ------------------
  |  Branch (59:5): [True: 0, False: 1]
  ------------------
   60|      0|      prError = PR_DEADLOCK_ERROR;
  ------------------
  |  |  139|      0|#define PR_DEADLOCK_ERROR                        (-5959L)
  ------------------
   61|      0|      break;
   62|       |#ifdef EDIRCORRUPTED
   63|       |    case EDIRCORRUPTED:
   64|       |      prError = PR_DIRECTORY_CORRUPTED_ERROR;
   65|       |      break;
   66|       |#endif
   67|      0|#ifdef EDQUOT
   68|      0|    case EDQUOT:
  ------------------
  |  Branch (68:5): [True: 0, False: 1]
  ------------------
   69|      0|      prError = PR_NO_DEVICE_SPACE_ERROR;
  ------------------
  |  |  148|      0|#define PR_NO_DEVICE_SPACE_ERROR                 (-5956L)
  ------------------
   70|      0|      break;
   71|      0|#endif
   72|      0|    case EEXIST:
  ------------------
  |  Branch (72:5): [True: 0, False: 1]
  ------------------
   73|      0|      prError = PR_FILE_EXISTS_ERROR;
  ------------------
  |  |  187|      0|#define PR_FILE_EXISTS_ERROR                     (-5943L)
  ------------------
   74|      0|      break;
   75|      0|    case EFAULT:
  ------------------
  |  Branch (75:5): [True: 0, False: 1]
  ------------------
   76|      0|      prError = PR_ACCESS_FAULT_ERROR;
  ------------------
  |  |   25|      0|#define PR_ACCESS_FAULT_ERROR                    (-5997L)
  ------------------
   77|      0|      break;
   78|      0|    case EFBIG:
  ------------------
  |  Branch (78:5): [True: 0, False: 1]
  ------------------
   79|      0|      prError = PR_FILE_TOO_BIG_ERROR;
  ------------------
  |  |  145|      0|#define PR_FILE_TOO_BIG_ERROR                    (-5957L)
  ------------------
   80|      0|      break;
   81|      0|    case EHOSTUNREACH:
  ------------------
  |  Branch (81:5): [True: 0, False: 1]
  ------------------
   82|      0|    case EHOSTDOWN:
  ------------------
  |  Branch (82:5): [True: 0, False: 1]
  ------------------
   83|      0|      prError = PR_HOST_UNREACHABLE_ERROR;
  ------------------
  |  |  235|      0|#define PR_HOST_UNREACHABLE_ERROR                (-5927L)
  ------------------
   84|      0|      break;
   85|      0|    case EINPROGRESS:
  ------------------
  |  Branch (85:5): [True: 0, False: 1]
  ------------------
   86|      0|      prError = PR_IN_PROGRESS_ERROR;
  ------------------
  |  |  214|      0|#define PR_IN_PROGRESS_ERROR                     (-5934L)
  ------------------
   87|      0|      break;
   88|      0|    case EINTR:
  ------------------
  |  Branch (88:5): [True: 0, False: 1]
  ------------------
   89|      0|      prError = PR_PENDING_INTERRUPT_ERROR;
  ------------------
  |  |   37|      0|#define PR_PENDING_INTERRUPT_ERROR               (-5993L)
  ------------------
   90|      0|      break;
   91|      0|    case EINVAL:
  ------------------
  |  Branch (91:5): [True: 0, False: 1]
  ------------------
   92|      0|      prError = PR_INVALID_ARGUMENT_ERROR;
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
   93|      0|      break;
   94|      0|    case EIO:
  ------------------
  |  Branch (94:5): [True: 0, False: 1]
  ------------------
   95|      0|      prError = PR_IO_ERROR;
  ------------------
  |  |   43|      0|#define PR_IO_ERROR                              (-5991L)
  ------------------
   96|      0|      break;
   97|      0|    case EISCONN:
  ------------------
  |  Branch (97:5): [True: 0, False: 1]
  ------------------
   98|      0|      prError = PR_IS_CONNECTED_ERROR;
  ------------------
  |  |   64|      0|#define PR_IS_CONNECTED_ERROR                    (-5984L)
  ------------------
   99|      0|      break;
  100|      0|    case EISDIR:
  ------------------
  |  Branch (100:5): [True: 0, False: 1]
  ------------------
  101|      0|      prError = PR_IS_DIRECTORY_ERROR;
  ------------------
  |  |  157|      0|#define PR_IS_DIRECTORY_ERROR                    (-5953L)
  ------------------
  102|      0|      break;
  103|      0|    case ELOOP:
  ------------------
  |  Branch (103:5): [True: 0, False: 1]
  ------------------
  104|      0|      prError = PR_LOOP_ERROR;
  ------------------
  |  |  160|      0|#define PR_LOOP_ERROR                            (-5952L)
  ------------------
  105|      0|      break;
  106|      0|    case EMFILE:
  ------------------
  |  Branch (106:5): [True: 0, False: 1]
  ------------------
  107|      0|      prError = PR_PROC_DESC_TABLE_FULL_ERROR;
  ------------------
  |  |  103|      0|#define PR_PROC_DESC_TABLE_FULL_ERROR            (-5971L)
  ------------------
  108|      0|      break;
  109|      0|    case EMLINK:
  ------------------
  |  Branch (109:5): [True: 0, False: 1]
  ------------------
  110|      0|      prError = PR_MAX_DIRECTORY_ENTRIES_ERROR;
  ------------------
  |  |  190|      0|#define PR_MAX_DIRECTORY_ENTRIES_ERROR           (-5942L)
  ------------------
  111|      0|      break;
  112|      0|    case EMSGSIZE:
  ------------------
  |  Branch (112:5): [True: 0, False: 1]
  ------------------
  113|      0|      prError = PR_INVALID_ARGUMENT_ERROR;
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  114|      0|      break;
  115|      0|#ifdef EMULTIHOP
  116|      0|    case EMULTIHOP:
  ------------------
  |  Branch (116:5): [True: 0, False: 1]
  ------------------
  117|      0|      prError = PR_REMOTE_FILE_ERROR;
  ------------------
  |  |  127|      0|#define PR_REMOTE_FILE_ERROR                     (-5963L)
  ------------------
  118|      0|      break;
  119|      0|#endif
  120|      0|    case ENAMETOOLONG:
  ------------------
  |  Branch (120:5): [True: 0, False: 1]
  ------------------
  121|      0|      prError = PR_NAME_TOO_LONG_ERROR;
  ------------------
  |  |  163|      0|#define PR_NAME_TOO_LONG_ERROR                   (-5951L)
  ------------------
  122|      0|      break;
  123|      0|    case ENETUNREACH:
  ------------------
  |  Branch (123:5): [True: 0, False: 1]
  ------------------
  124|      0|      prError = PR_NETWORK_UNREACHABLE_ERROR;
  ------------------
  |  |   76|      0|#define PR_NETWORK_UNREACHABLE_ERROR             (-5980L)
  ------------------
  125|      0|      break;
  126|      0|    case ENFILE:
  ------------------
  |  Branch (126:5): [True: 0, False: 1]
  ------------------
  127|      0|      prError = PR_SYS_DESC_TABLE_FULL_ERROR;
  ------------------
  |  |  106|      0|#define PR_SYS_DESC_TABLE_FULL_ERROR             (-5970L)
  ------------------
  128|      0|      break;
  129|       |      /*
  130|       |       * On SCO OpenServer 5, ENOBUFS is defined as ENOSR.
  131|       |       */
  132|      0|#if defined(ENOBUFS) && (ENOBUFS != ENOSR)
  133|      0|    case ENOBUFS:
  ------------------
  |  Branch (133:5): [True: 0, False: 1]
  ------------------
  134|      0|      prError = PR_INSUFFICIENT_RESOURCES_ERROR;
  ------------------
  |  |   94|      0|#define PR_INSUFFICIENT_RESOURCES_ERROR          (-5974L)
  ------------------
  135|      0|      break;
  136|      0|#endif
  137|      0|    case ENODEV:
  ------------------
  |  Branch (137:5): [True: 0, False: 1]
  ------------------
  138|      0|      prError = PR_FILE_NOT_FOUND_ERROR;
  ------------------
  |  |  166|      0|#define PR_FILE_NOT_FOUND_ERROR                  (-5950L)
  ------------------
  139|      0|      break;
  140|      0|    case ENOENT:
  ------------------
  |  Branch (140:5): [True: 0, False: 1]
  ------------------
  141|      0|      prError = PR_FILE_NOT_FOUND_ERROR;
  ------------------
  |  |  166|      0|#define PR_FILE_NOT_FOUND_ERROR                  (-5950L)
  ------------------
  142|      0|      break;
  143|      0|    case ENOLCK:
  ------------------
  |  Branch (143:5): [True: 0, False: 1]
  ------------------
  144|      0|      prError = PR_FILE_IS_LOCKED_ERROR;
  ------------------
  |  |  142|      0|#define PR_FILE_IS_LOCKED_ERROR                  (-5958L)
  ------------------
  145|      0|      break;
  146|      0|#ifdef ENOLINK
  147|      0|    case ENOLINK:
  ------------------
  |  Branch (147:5): [True: 0, False: 1]
  ------------------
  148|      0|      prError = PR_REMOTE_FILE_ERROR;
  ------------------
  |  |  127|      0|#define PR_REMOTE_FILE_ERROR                     (-5963L)
  ------------------
  149|      0|      break;
  150|      0|#endif
  151|      0|    case ENOMEM:
  ------------------
  |  Branch (151:5): [True: 0, False: 1]
  ------------------
  152|      0|      prError = PR_OUT_OF_MEMORY_ERROR;
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  153|      0|      break;
  154|      0|    case ENOPROTOOPT:
  ------------------
  |  Branch (154:5): [True: 0, False: 1]
  ------------------
  155|      0|      prError = PR_INVALID_ARGUMENT_ERROR;
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  156|      0|      break;
  157|      0|    case ENOSPC:
  ------------------
  |  Branch (157:5): [True: 0, False: 1]
  ------------------
  158|      0|      prError = PR_NO_DEVICE_SPACE_ERROR;
  ------------------
  |  |  148|      0|#define PR_NO_DEVICE_SPACE_ERROR                 (-5956L)
  ------------------
  159|      0|      break;
  160|      0|#ifdef ENOSR
  161|      0|    case ENOSR:
  ------------------
  |  Branch (161:5): [True: 0, False: 1]
  ------------------
  162|      0|      prError = PR_INSUFFICIENT_RESOURCES_ERROR;
  ------------------
  |  |   94|      0|#define PR_INSUFFICIENT_RESOURCES_ERROR          (-5974L)
  ------------------
  163|      0|      break;
  164|      0|#endif
  165|      0|    case ENOSYS:
  ------------------
  |  Branch (165:5): [True: 0, False: 1]
  ------------------
  166|      0|      prError = PR_NOT_IMPLEMENTED_ERROR;
  ------------------
  |  |   40|      0|#define PR_NOT_IMPLEMENTED_ERROR                 (-5992L)
  ------------------
  167|      0|      break;
  168|      1|    case ENOTCONN:
  ------------------
  |  Branch (168:5): [True: 1, False: 0]
  ------------------
  169|      1|      prError = PR_NOT_CONNECTED_ERROR;
  ------------------
  |  |   82|      1|#define PR_NOT_CONNECTED_ERROR                   (-5978L)
  ------------------
  170|      1|      break;
  171|      0|    case ENOTDIR:
  ------------------
  |  Branch (171:5): [True: 0, False: 1]
  ------------------
  172|      0|      prError = PR_NOT_DIRECTORY_ERROR;
  ------------------
  |  |  169|      0|#define PR_NOT_DIRECTORY_ERROR                   (-5949L)
  ------------------
  173|      0|      break;
  174|      0|    case ENOTSOCK:
  ------------------
  |  Branch (174:5): [True: 0, False: 1]
  ------------------
  175|      0|      prError = PR_NOT_SOCKET_ERROR;
  ------------------
  |  |  109|      0|#define PR_NOT_SOCKET_ERROR                      (-5969L)
  ------------------
  176|      0|      break;
  177|      0|    case ENXIO:
  ------------------
  |  Branch (177:5): [True: 0, False: 1]
  ------------------
  178|      0|      prError = PR_FILE_NOT_FOUND_ERROR;
  ------------------
  |  |  166|      0|#define PR_FILE_NOT_FOUND_ERROR                  (-5950L)
  ------------------
  179|      0|      break;
  180|      0|    case EOPNOTSUPP:
  ------------------
  |  Branch (180:5): [True: 0, False: 1]
  ------------------
  181|      0|      prError = PR_NOT_TCP_SOCKET_ERROR;
  ------------------
  |  |  112|      0|#define PR_NOT_TCP_SOCKET_ERROR                  (-5968L)
  ------------------
  182|      0|      break;
  183|      0|#ifdef EOVERFLOW
  184|      0|    case EOVERFLOW:
  ------------------
  |  Branch (184:5): [True: 0, False: 1]
  ------------------
  185|      0|      prError = PR_BUFFER_OVERFLOW_ERROR;
  ------------------
  |  |  130|      0|#define PR_BUFFER_OVERFLOW_ERROR                 (-5962L)
  ------------------
  186|      0|      break;
  187|      0|#endif
  188|      0|    case EPERM:
  ------------------
  |  Branch (188:5): [True: 0, False: 1]
  ------------------
  189|      0|      prError = PR_NO_ACCESS_RIGHTS_ERROR;
  ------------------
  |  |  118|      0|#define PR_NO_ACCESS_RIGHTS_ERROR                (-5966L)
  ------------------
  190|      0|      break;
  191|      0|    case EPIPE:
  ------------------
  |  Branch (191:5): [True: 0, False: 1]
  ------------------
  192|      0|      prError = PR_CONNECT_RESET_ERROR;
  ------------------
  |  |  133|      0|#define PR_CONNECT_RESET_ERROR                   (-5961L)
  ------------------
  193|      0|      break;
  194|      0|#ifdef EPROTO
  195|      0|    case EPROTO:
  ------------------
  |  Branch (195:5): [True: 0, False: 1]
  ------------------
  196|      0|      prError = PR_IO_ERROR;
  ------------------
  |  |   43|      0|#define PR_IO_ERROR                              (-5991L)
  ------------------
  197|      0|      break;
  198|      0|#endif
  199|      0|    case EPROTONOSUPPORT:
  ------------------
  |  Branch (199:5): [True: 0, False: 1]
  ------------------
  200|      0|      prError = PR_PROTOCOL_NOT_SUPPORTED_ERROR;
  ------------------
  |  |  124|      0|#define PR_PROTOCOL_NOT_SUPPORTED_ERROR          (-5964L)
  ------------------
  201|      0|      break;
  202|      0|    case EPROTOTYPE:
  ------------------
  |  Branch (202:5): [True: 0, False: 1]
  ------------------
  203|      0|      prError = PR_ADDRESS_NOT_SUPPORTED_ERROR;
  ------------------
  |  |   61|      0|#define PR_ADDRESS_NOT_SUPPORTED_ERROR           (-5985L)
  ------------------
  204|      0|      break;
  205|      0|    case ERANGE:
  ------------------
  |  Branch (205:5): [True: 0, False: 1]
  ------------------
  206|      0|      prError = PR_INVALID_METHOD_ERROR;
  ------------------
  |  |   28|      0|#define PR_INVALID_METHOD_ERROR                  (-5996L)
  ------------------
  207|      0|      break;
  208|      0|    case EROFS:
  ------------------
  |  Branch (208:5): [True: 0, False: 1]
  ------------------
  209|      0|      prError = PR_READ_ONLY_FILESYSTEM_ERROR;
  ------------------
  |  |  172|      0|#define PR_READ_ONLY_FILESYSTEM_ERROR            (-5948L)
  ------------------
  210|      0|      break;
  211|      0|    case ESPIPE:
  ------------------
  |  Branch (211:5): [True: 0, False: 1]
  ------------------
  212|      0|      prError = PR_INVALID_METHOD_ERROR;
  ------------------
  |  |   28|      0|#define PR_INVALID_METHOD_ERROR                  (-5996L)
  ------------------
  213|      0|      break;
  214|      0|    case ETIMEDOUT:
  ------------------
  |  Branch (214:5): [True: 0, False: 1]
  ------------------
  215|      0|      prError = PR_IO_TIMEOUT_ERROR;
  ------------------
  |  |   46|      0|#define PR_IO_TIMEOUT_ERROR                      (-5990L)
  ------------------
  216|      0|      break;
  217|       |#if EWOULDBLOCK != EAGAIN
  218|       |    case EWOULDBLOCK:
  219|       |      prError = PR_WOULD_BLOCK_ERROR;
  220|       |      break;
  221|       |#endif
  222|      0|    case EXDEV:
  ------------------
  |  Branch (222:5): [True: 0, False: 1]
  ------------------
  223|      0|      prError = PR_NOT_SAME_DEVICE_ERROR;
  ------------------
  |  |  181|      0|#define PR_NOT_SAME_DEVICE_ERROR                 (-5945L)
  ------------------
  224|      0|      break;
  225|      0|    default:
  ------------------
  |  Branch (225:5): [True: 0, False: 1]
  ------------------
  226|      0|      prError = PR_UNKNOWN_ERROR;
  ------------------
  |  |   34|      0|#define PR_UNKNOWN_ERROR                         (-5994L)
  ------------------
  227|      0|      break;
  228|      1|  }
  229|      1|  PR_SetError(prError, err);
  230|      1|}
_MD_unix_map_getpeername_error:
  546|      1|void _MD_unix_map_getpeername_error(int err) {
  547|      1|  PRErrorCode prError;
  548|       |
  549|      1|  switch (err) {
  550|      0|    case ENOMEM:
  ------------------
  |  Branch (550:5): [True: 0, False: 1]
  ------------------
  551|      0|      prError = PR_INSUFFICIENT_RESOURCES_ERROR;
  ------------------
  |  |   94|      0|#define PR_INSUFFICIENT_RESOURCES_ERROR          (-5974L)
  ------------------
  552|      0|      break;
  553|      1|    default:
  ------------------
  |  Branch (553:5): [True: 1, False: 0]
  ------------------
  554|      1|      _MD_unix_map_default_error(err);
  555|      1|      return;
  556|      1|  }
  557|      0|  PR_SetError(prError, err);
  558|      0|}

_PR_InitSegs:
   13|      1|void _PR_InitSegs(void) {}

_PR_InitAtomic:
  243|      1|void _PR_InitAtomic(void) { _PR_MD_INIT_ATOMIC(); }

_PR_InitDtoa:
   25|      1|void _PR_InitDtoa(void) {
   26|      1|  dtoa_lock[0] = PR_NewLock();
   27|      1|  dtoa_lock[1] = PR_NewLock();
   28|      1|}

_PR_InitEnv:
   65|      1|void _PR_InitEnv(void) { _PR_NEW_LOCK_ENV(); }
  ------------------
  |  |   45|      1|    { _pr_envLock = PR_NewLock(); }
  ------------------
PR_GetEnv:
   69|     14|PR_IMPLEMENT(char*) PR_GetEnv(const char* var) {
   70|     14|  char* ev;
   71|       |
   72|     14|  if (!_pr_initialized) {
  ------------------
  |  Branch (72:7): [True: 0, False: 14]
  ------------------
   73|      0|    _PR_ImplicitInitialization();
   74|      0|  }
   75|       |
   76|     14|  _PR_LOCK_ENV();
  ------------------
  |  |   54|     14|    {                                        \
  |  |   55|     14|      if (_pr_envLock) PR_Lock(_pr_envLock); \
  |  |  ------------------
  |  |  |  Branch (55:11): [True: 3, False: 11]
  |  |  ------------------
  |  |   56|     14|    }
  ------------------
   77|     14|  ev = _PR_MD_GET_ENV(var);
  ------------------
  |  | 1923|     14|#define    _PR_MD_GET_ENV _MD_GET_ENV
  |  |  ------------------
  |  |  |  |  266|     14|#define _MD_GET_ENV             getenv
  |  |  ------------------
  ------------------
   78|     14|  _PR_UNLOCK_ENV();
  ------------------
  |  |   58|     14|    {                                          \
  |  |   59|     14|      if (_pr_envLock) PR_Unlock(_pr_envLock); \
  |  |  ------------------
  |  |  |  Branch (59:11): [True: 3, False: 11]
  |  |  ------------------
  |  |   60|     14|    }
  ------------------
   79|     14|  return ev;
   80|     14|}
PR_GetEnvSecure:
   82|  18.2k|PR_IMPLEMENT(char*) PR_GetEnvSecure(const char* var) {
   83|  18.2k|#ifdef HAVE_SECURE_GETENV
   84|  18.2k|  char* ev;
   85|       |
   86|  18.2k|  if (!_pr_initialized) {
  ------------------
  |  Branch (86:7): [True: 0, False: 18.2k]
  ------------------
   87|      0|    _PR_ImplicitInitialization();
   88|      0|  }
   89|       |
   90|  18.2k|  _PR_LOCK_ENV();
  ------------------
  |  |   54|  18.2k|    {                                        \
  |  |   55|  18.2k|      if (_pr_envLock) PR_Lock(_pr_envLock); \
  |  |  ------------------
  |  |  |  Branch (55:11): [True: 18.2k, False: 0]
  |  |  ------------------
  |  |   56|  18.2k|    }
  ------------------
   91|  18.2k|  ev = secure_getenv(var);
   92|  18.2k|  _PR_UNLOCK_ENV();
  ------------------
  |  |   58|  18.2k|    {                                          \
  |  |   59|  18.2k|      if (_pr_envLock) PR_Unlock(_pr_envLock); \
  |  |  ------------------
  |  |  |  Branch (59:11): [True: 18.2k, False: 0]
  |  |  ------------------
  |  |   60|  18.2k|    }
  ------------------
   93|       |
   94|  18.2k|  return ev;
   95|       |#else
   96|       |#  ifdef XP_UNIX
   97|       |  /*
   98|       |  ** Fall back to checking uids and gids.  This won't detect any other
   99|       |  ** privilege-granting mechanisms the platform may have.  This also
  100|       |  ** can't detect the case where the process already called
  101|       |  ** setuid(geteuid()) and/or setgid(getegid()).
  102|       |  */
  103|       |  if (getuid() != geteuid() || getgid() != getegid()) {
  104|       |    return NULL;
  105|       |  }
  106|       |#  endif /* XP_UNIX */
  107|       |  return PR_GetEnv(var);
  108|       |#endif   /* HAVE_SECURE_GETENV */
  109|  18.2k|}

nspr_InitializePRErrorTable:
  120|      1|void nspr_InitializePRErrorTable(void) { PR_ErrorInstallTable(&et); }

PR_GetError:
   11|  71.5k|PR_IMPLEMENT(PRErrorCode) PR_GetError(void) {
   12|  71.5k|  PRThread* thread = PR_GetCurrentThread();
   13|  71.5k|  return thread->errorCode;
   14|  71.5k|}
PR_SetError:
   21|   821k|PR_IMPLEMENT(void) PR_SetError(PRErrorCode code, PRInt32 osErr) {
   22|   821k|  PRThread* thread = PR_GetCurrentThread();
   23|   821k|  thread->errorCode = code;
   24|   821k|  thread->osErrorCode = osErr;
   25|   821k|  thread->errorStringLength = 0;
   26|   821k|}

PR_ErrorInstallTable:
  154|      3|PR_ErrorInstallTable(const struct PRErrorTable* table) {
  155|      3|  struct PRErrorTableList* new_et;
  156|       |
  157|      3|  new_et = (struct PRErrorTableList*)PR_Malloc(sizeof(struct PRErrorTableList));
  158|      3|  if (!new_et) {
  ------------------
  |  Branch (158:7): [True: 0, False: 3]
  ------------------
  159|      0|    return errno; /* oops */
  160|      0|  }
  161|      3|  new_et->table = table;
  162|      3|  if (callback_newtable) {
  ------------------
  |  Branch (162:7): [True: 0, False: 3]
  ------------------
  163|      0|    new_et->table_private = callback_newtable(table, callback_private);
  164|      3|  } else {
  165|      3|    new_et->table_private = 0;
  166|      3|  }
  167|      3|  new_et->next = Table_List;
  168|      3|  Table_List = new_et;
  169|      3|  return 0;
  170|      3|}

_PR_ImplicitInitialization:
  200|      1|void _PR_ImplicitInitialization(void) {
  201|      1|  _PR_InitStuff();
  202|       |
  203|       |  /* Enable interrupts */
  204|       |#if !defined(_PR_PTHREADS) && !defined(_PR_GLOBAL_THREADS_ONLY)
  205|       |  _PR_MD_START_INTERRUPTS();
  206|       |#endif
  207|      1|}
PR_CallOnce:
  706|   636k|PR_IMPLEMENT(PRStatus) PR_CallOnce(PRCallOnceType* once, PRCallOnceFN func) {
  707|   636k|  if (!_pr_initialized) {
  ------------------
  |  Branch (707:7): [True: 1, False: 636k]
  ------------------
  708|      1|    _PR_ImplicitInitialization();
  709|      1|  }
  710|       |
  711|   636k|  PR_Lock(mod_init.ml);
  712|   636k|  PRIntn initialized = once->initialized;
  713|   636k|  PRStatus status = once->status;
  714|   636k|  PR_Unlock(mod_init.ml);
  715|   636k|  if (!initialized) {
  ------------------
  |  Branch (715:7): [True: 12, False: 636k]
  ------------------
  716|     12|    if (PR_ATOMIC_SET(&once->inProgress, 1) == 0) {
  ------------------
  |  |  124|     12|#define PR_ATOMIC_SET(val, newval) __sync_lock_test_and_set(val, newval)
  ------------------
  |  Branch (716:9): [True: 12, False: 0]
  ------------------
  717|     12|      status = (*func)();
  718|     12|      PR_Lock(mod_init.ml);
  719|     12|      once->status = status;
  720|     12|      once->initialized = 1;
  721|     12|      PR_NotifyAllCondVar(mod_init.cv);
  722|     12|      PR_Unlock(mod_init.ml);
  723|     12|    } else {
  724|      0|      PR_Lock(mod_init.ml);
  725|      0|      while (!once->initialized) {
  ------------------
  |  Branch (725:14): [True: 0, False: 0]
  ------------------
  726|      0|        PR_WaitCondVar(mod_init.cv, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |   54|      0|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
  727|      0|      }
  728|      0|      status = once->status;
  729|      0|      PR_Unlock(mod_init.ml);
  730|      0|      if (PR_SUCCESS != status) {
  ------------------
  |  Branch (730:11): [True: 0, False: 0]
  ------------------
  731|      0|        PR_SetError(PR_CALL_ONCE_ERROR, 0);
  ------------------
  |  |  241|      0|#define PR_CALL_ONCE_ERROR                       (-5925L)
  ------------------
  732|      0|      }
  733|      0|    }
  734|     12|    return status;
  735|     12|  }
  736|   636k|  if (PR_SUCCESS != status) {
  ------------------
  |  Branch (736:7): [True: 0, False: 636k]
  ------------------
  737|      0|    PR_SetError(PR_CALL_ONCE_ERROR, 0);
  ------------------
  |  |  241|      0|#define PR_CALL_ONCE_ERROR                       (-5925L)
  ------------------
  738|      0|  }
  739|   636k|  return status;
  740|   636k|}
PR_CallOnceWithArg:
  743|   179k|PR_CallOnceWithArg(PRCallOnceType* once, PRCallOnceWithArgFN func, void* arg) {
  744|   179k|  if (!_pr_initialized) {
  ------------------
  |  Branch (744:7): [True: 0, False: 179k]
  ------------------
  745|      0|    _PR_ImplicitInitialization();
  746|      0|  }
  747|       |
  748|   179k|  PR_Lock(mod_init.ml);
  749|   179k|  PRIntn initialized = once->initialized;
  750|   179k|  PRStatus status = once->status;
  751|   179k|  PR_Unlock(mod_init.ml);
  752|   179k|  if (!initialized) {
  ------------------
  |  Branch (752:7): [True: 27, False: 179k]
  ------------------
  753|     27|    if (PR_ATOMIC_SET(&once->inProgress, 1) == 0) {
  ------------------
  |  |  124|     27|#define PR_ATOMIC_SET(val, newval) __sync_lock_test_and_set(val, newval)
  ------------------
  |  Branch (753:9): [True: 27, False: 0]
  ------------------
  754|     27|      status = (*func)(arg);
  755|     27|      PR_Lock(mod_init.ml);
  756|     27|      once->status = status;
  757|     27|      once->initialized = 1;
  758|     27|      PR_NotifyAllCondVar(mod_init.cv);
  759|     27|      PR_Unlock(mod_init.ml);
  760|     27|    } else {
  761|      0|      PR_Lock(mod_init.ml);
  762|      0|      while (!once->initialized) {
  ------------------
  |  Branch (762:14): [True: 0, False: 0]
  ------------------
  763|      0|        PR_WaitCondVar(mod_init.cv, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |   54|      0|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
  764|      0|      }
  765|      0|      status = once->status;
  766|      0|      PR_Unlock(mod_init.ml);
  767|      0|      if (PR_SUCCESS != status) {
  ------------------
  |  Branch (767:11): [True: 0, False: 0]
  ------------------
  768|      0|        PR_SetError(PR_CALL_ONCE_ERROR, 0);
  ------------------
  |  |  241|      0|#define PR_CALL_ONCE_ERROR                       (-5925L)
  ------------------
  769|      0|      }
  770|      0|    }
  771|     27|    return status;
  772|     27|  }
  773|   179k|  if (PR_SUCCESS != status) {
  ------------------
  |  Branch (773:7): [True: 0, False: 179k]
  ------------------
  774|      0|    PR_SetError(PR_CALL_ONCE_ERROR, 0);
  ------------------
  |  |  241|      0|#define PR_CALL_ONCE_ERROR                       (-5925L)
  ------------------
  775|      0|  }
  776|   179k|  return status;
  777|   179k|}
prinit.c:_PR_InitStuff:
  129|      1|static void _PR_InitStuff(void) {
  130|      1|  if (_pr_initialized) {
  ------------------
  |  Branch (130:7): [True: 0, False: 1]
  ------------------
  131|      0|    return;
  132|      0|  }
  133|      1|  _pr_initialized = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  134|      1|#ifdef _PR_ZONE_ALLOCATOR
  135|      1|  _PR_InitZones();
  136|      1|#endif
  137|       |#ifdef WINNT
  138|       |  _pr_SetNativeThreadsOnlyMode();
  139|       |#endif
  140|       |
  141|      1|  (void)PR_GetPageSize();
  142|       |
  143|      1|  _pr_clock_lm = PR_NewLogModule("clock");
  144|      1|  _pr_cmon_lm = PR_NewLogModule("cmon");
  145|      1|  _pr_io_lm = PR_NewLogModule("io");
  146|      1|  _pr_mon_lm = PR_NewLogModule("mon");
  147|      1|  _pr_linker_lm = PR_NewLogModule("linker");
  148|      1|  _pr_cvar_lm = PR_NewLogModule("cvar");
  149|      1|  _pr_sched_lm = PR_NewLogModule("sched");
  150|      1|  _pr_thread_lm = PR_NewLogModule("thread");
  151|      1|  _pr_gc_lm = PR_NewLogModule("gc");
  152|      1|  _pr_shm_lm = PR_NewLogModule("shm");
  153|      1|  _pr_shma_lm = PR_NewLogModule("shma");
  154|       |
  155|       |  /* NOTE: These init's cannot depend on _PR_MD_CURRENT_THREAD() */
  156|      1|  _PR_MD_EARLY_INIT();
  ------------------
  |  | 1888|      1|#define    _PR_MD_EARLY_INIT _MD_EARLY_INIT
  |  |  ------------------
  |  |  |  |  712|      1|#define _MD_EARLY_INIT                  _MD_EarlyInit
  |  |  ------------------
  ------------------
  157|       |
  158|      1|  _PR_InitLocks();
  159|      1|  _PR_InitAtomic();
  160|      1|  _PR_InitSegs();
  161|      1|  _PR_InitStacks();
  162|      1|  _PR_InitTPD();
  163|      1|  _PR_InitEnv();
  164|      1|  _PR_InitLayerCache();
  165|      1|  _PR_InitClock();
  166|       |
  167|      1|  _pr_sleeplock = PR_NewLock();
  168|      1|  PR_ASSERT(NULL != _pr_sleeplock);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  169|       |
  170|      1|  _PR_InitThreads(PR_USER_THREAD, PR_PRIORITY_NORMAL, 0);
  171|       |
  172|      1|#ifndef _PR_GLOBAL_THREADS_ONLY
  173|      1|  _PR_InitCPUs();
  174|      1|#endif
  175|       |
  176|       |  /*
  177|       |   * XXX: call _PR_InitMem only on those platforms for which nspr implements
  178|       |   *  malloc, for now.
  179|       |   */
  180|       |#ifdef _PR_OVERRIDE_MALLOC
  181|       |  _PR_InitMem();
  182|       |#endif
  183|       |
  184|      1|  _PR_InitCMon();
  185|      1|  _PR_InitIO();
  186|      1|  _PR_InitNet();
  187|      1|  _PR_InitTime();
  188|      1|  _PR_InitLog();
  189|      1|  _PR_InitLinker();
  190|      1|  _PR_InitCallOnce();
  191|      1|  _PR_InitDtoa();
  192|      1|  _PR_InitMW();
  193|      1|  _PR_InitRWLocks();
  194|       |
  195|      1|  nspr_InitializePRErrorTable();
  196|       |
  197|      1|  _PR_MD_FINAL_INIT();
  ------------------
  |  | 1894|      1|#define    _PR_MD_FINAL_INIT _MD_FINAL_INIT
  |  |  ------------------
  |  |  |  |  713|      1|#define _MD_FINAL_INIT                  _PR_UnixInit
  |  |  ------------------
  ------------------
  198|      1|}
prinit.c:_PR_InitCallOnce:
  692|      1|static void _PR_InitCallOnce(void) {
  693|      1|  mod_init.ml = PR_NewLock();
  694|      1|  PR_ASSERT(NULL != mod_init.ml);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  695|      1|  mod_init.cv = PR_NewCondVar(mod_init.ml);
  696|      1|  PR_ASSERT(NULL != mod_init.cv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  697|      1|}

_PR_InitClock:
   22|      1|void _PR_InitClock(void) {
   23|      1|  _PR_MD_INTERVAL_INIT();
   24|      1|#ifdef DEBUG
   25|      1|  {
   26|      1|    PRIntervalTime ticksPerSec = PR_TicksPerSecond();
   27|       |
   28|      1|    PR_ASSERT(ticksPerSec >= PR_INTERVAL_MIN);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
   29|      1|    PR_ASSERT(ticksPerSec <= PR_INTERVAL_MAX);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
   30|      1|  }
   31|      1|#endif /* DEBUG */
   32|      1|}
PR_TicksPerSecond:
   41|      2|PR_EXTERN(PRUint32) PR_TicksPerSecond(void) {
   42|      2|  if (!_pr_initialized) {
  ------------------
  |  Branch (42:7): [True: 0, False: 2]
  ------------------
   43|      0|    _PR_ImplicitInitialization();
   44|      0|  }
   45|      2|  return _PR_MD_INTERVAL_PER_SEC();
  ------------------
  |  | 1966|      2|#define _PR_MD_INTERVAL_PER_SEC _MD_INTERVAL_PER_SEC
  |  |  ------------------
  |  |  |  |  306|      2|#define _MD_INTERVAL_PER_SEC        _PR_UNIX_TicksPerSecond2
  |  |  ------------------
  ------------------
   46|      2|} /* PR_TicksPerSecond */
PR_MillisecondsToInterval:
   52|      1|PR_IMPLEMENT(PRIntervalTime) PR_MillisecondsToInterval(PRUint32 milli) {
   53|      1|  PRIntervalTime ticks;
   54|      1|  PRUint64 tock, tps, msecPerSec, rounding;
   55|      1|  LL_UI2L(tock, milli);
  ------------------
  |  |  150|      1|#define LL_UI2L(l, ui)        ((l) = (PRInt64)(ui))
  ------------------
   56|      1|  LL_I2L(msecPerSec, PR_MSEC_PER_SEC);
  ------------------
  |  |  149|      1|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
   57|      1|  LL_I2L(rounding, (PR_MSEC_PER_SEC >> 1));
  ------------------
  |  |  149|      1|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
   58|      1|  LL_I2L(tps, PR_TicksPerSecond());
  ------------------
  |  |  149|      1|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
   59|      1|  LL_MUL(tock, tock, tps);
  ------------------
  |  |  115|      1|#define LL_MUL(r, a, b)        ((r) = (a) * (b))
  ------------------
   60|      1|  LL_ADD(tock, tock, rounding);
  ------------------
  |  |  105|      1|#define LL_ADD(r, a, b)     ((r) = (a) + (b))
  ------------------
   61|      1|  LL_DIV(tock, tock, msecPerSec);
  ------------------
  |  |  116|      1|#define LL_DIV(r, a, b)        ((r) = (a) / (b))
  ------------------
   62|      1|  LL_L2UI(ticks, tock);
  ------------------
  |  |  145|      1|#define LL_L2UI(ui, l)        ((ui) = (PRUint32)(l))
  ------------------
   63|      1|  return ticks;
   64|      1|} /* PR_MillisecondsToInterval */

PR_CeilingLog2:
   11|      7|PR_IMPLEMENT(PRIntn) PR_CeilingLog2(PRUint32 n) {
   12|      7|  PRIntn log2;
   13|      7|  PR_CEILING_LOG2(log2, n);
  ------------------
  |  |   72|      7|  PR_BEGIN_MACRO                       \
  |  |  ------------------
  |  |  |  |  123|      7|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      7|    PRUint32 j_ = (PRUint32)(_n);      \
  |  |   74|      7|    (_log2) = (j_ <= 1 ? 0 : 32 - pr_bitscan_clz32(j_ - 1)); \
  |  |  ------------------
  |  |  |  |   40|      7|# define pr_bitscan_clz32(val)  __builtin_clz(val)
  |  |  ------------------
  |  |  |  Branch (74:16): [True: 0, False: 7]
  |  |  ------------------
  |  |   75|      7|  PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      7|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   14|      7|  return log2;
   15|      7|}

_PR_InitNet:
  358|      1|void _PR_InitNet(void) {
  359|      1|#if defined(XP_UNIX)
  360|       |#  ifdef HAVE_NETCONFIG
  361|       |  /*
  362|       |   * This one-liner prevents the endless re-open's and re-read's of
  363|       |   * /etc/netconfig on EACH and EVERY call to accept(), connect(), etc.
  364|       |   */
  365|       |  (void)setnetconfig();
  366|       |#  endif
  367|      1|#endif
  368|       |#if !defined(_PR_NO_DNS_LOCK)
  369|       |  _pr_dnsLock = PR_NewLock();
  370|       |#endif
  371|       |#if !defined(_PR_HAVE_GETPROTO_R)
  372|       |  _getproto_lock = PR_NewLock();
  373|       |#endif
  374|      1|#if defined(_PR_INET6) && defined(_PR_HAVE_GETHOSTBYNAME2)
  375|      1|  _pr_query_ifs_lock = PR_NewLock();
  376|      1|#endif
  377|      1|}
PR_ConvertIPv4AddrToIPv6:
 1754|  61.2k|PR_ConvertIPv4AddrToIPv6(PRUint32 v4addr, PRIPv6Addr* v6addr) {
 1755|  61.2k|  PRUint8* dstp;
 1756|  61.2k|  dstp = v6addr->pr_s6_addr;
  ------------------
  |  |  138|  61.2k|#define pr_s6_addr      _S6_un._S6_u8
  ------------------
 1757|  61.2k|  memset(dstp, 0, 10);
 1758|  61.2k|  memset(dstp + 10, 0xff, 2);
 1759|  61.2k|  memcpy(dstp + 12, (char*)&v4addr, 4);
 1760|  61.2k|}
PR_ntohl:
 1763|     93|PR_IMPLEMENT(PRUint32) PR_ntohl(PRUint32 n) { return ntohl(n); }
PR_htonll:
 1779|  5.82M|PR_IMPLEMENT(PRUint64) PR_htonll(PRUint64 n) {
 1780|       |#ifdef IS_BIG_ENDIAN
 1781|       |  return n;
 1782|       |#else
 1783|  5.82M|  PRUint32 hi, lo;
 1784|  5.82M|  lo = (PRUint32)n;
 1785|  5.82M|  hi = (PRUint32)(n >> 32);
 1786|  5.82M|  hi = htonl(hi);
 1787|  5.82M|  lo = htonl(lo);
 1788|  5.82M|  return ((PRUint64)lo << 32) + (PRUint64)hi;
 1789|  5.82M|#endif
 1790|  5.82M|} /* htonll */

PR_ImplodeTime:
  219|    486|PR_ImplodeTime(const PRExplodedTime* exploded) {
  220|    486|  PRExplodedTime copy;
  221|    486|  PRTime retVal;
  222|    486|  PRInt64 secPerDay, usecPerSec;
  223|    486|  PRInt64 temp;
  224|    486|  PRInt64 numSecs64;
  225|    486|  PRInt32 numDays;
  226|    486|  PRInt32 numSecs;
  227|       |
  228|       |  /* Normalize first.  Do this on our copy */
  229|    486|  copy = *exploded;
  230|    486|  PR_NormalizeTime(&copy, PR_GMTParameters);
  231|       |
  232|    486|  numDays = DAYS_BETWEEN_YEARS(1970, copy.tm_year);
  ------------------
  |  |   41|    486|#define DAYS_BETWEEN_YEARS(A, B) (COUNT_DAYS(B) - COUNT_DAYS(A))
  |  |  ------------------
  |  |  |  |   40|    486|#define COUNT_DAYS(Y) (((Y) - 1) * 365 + COUNT_LEAPS(Y))
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|    486|#define COUNT_LEAPS(Y) (((Y) - 1) / 4 - ((Y) - 1) / 100 + ((Y) - 1) / 400)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define DAYS_BETWEEN_YEARS(A, B) (COUNT_DAYS(B) - COUNT_DAYS(A))
  |  |  ------------------
  |  |  |  |   40|    486|#define COUNT_DAYS(Y) (((Y) - 1) * 365 + COUNT_LEAPS(Y))
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|    486|#define COUNT_LEAPS(Y) (((Y) - 1) / 4 - ((Y) - 1) / 100 + ((Y) - 1) / 400)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  233|       |
  234|    486|  numSecs = copy.tm_yday * 86400 + copy.tm_hour * 3600 + copy.tm_min * 60 +
  235|    486|            copy.tm_sec;
  236|       |
  237|    486|  LL_I2L(temp, numDays);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  238|    486|  LL_I2L(secPerDay, 86400);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  239|    486|  LL_MUL(temp, temp, secPerDay);
  ------------------
  |  |  115|    486|#define LL_MUL(r, a, b)        ((r) = (a) * (b))
  ------------------
  240|    486|  LL_I2L(numSecs64, numSecs);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  241|    486|  LL_ADD(numSecs64, numSecs64, temp);
  ------------------
  |  |  105|    486|#define LL_ADD(r, a, b)     ((r) = (a) + (b))
  ------------------
  242|       |
  243|       |  /* apply the GMT and DST offsets */
  244|    486|  LL_I2L(temp, copy.tm_params.tp_gmt_offset);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  245|    486|  LL_SUB(numSecs64, numSecs64, temp);
  ------------------
  |  |  106|    486|#define LL_SUB(r, a, b)     ((r) = (a) - (b))
  ------------------
  246|    486|  LL_I2L(temp, copy.tm_params.tp_dst_offset);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  247|    486|  LL_SUB(numSecs64, numSecs64, temp);
  ------------------
  |  |  106|    486|#define LL_SUB(r, a, b)     ((r) = (a) - (b))
  ------------------
  248|       |
  249|    486|  LL_I2L(usecPerSec, 1000000L);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  250|    486|  LL_MUL(temp, numSecs64, usecPerSec);
  ------------------
  |  |  115|    486|#define LL_MUL(r, a, b)        ((r) = (a) * (b))
  ------------------
  251|    486|  LL_I2L(retVal, copy.tm_usec);
  ------------------
  |  |  149|    486|#define LL_I2L(l, i)        ((l) = (PRInt64)(i))
  ------------------
  252|    486|  LL_ADD(retVal, retVal, temp);
  ------------------
  |  |  105|    486|#define LL_ADD(r, a, b)     ((r) = (a) + (b))
  ------------------
  253|       |
  254|    486|  return retVal;
  255|    486|}
PR_NormalizeTime:
  345|    486|PR_NormalizeTime(PRExplodedTime* time, PRTimeParamFn params) {
  346|    486|  int daysInMonth;
  347|    486|  PRInt32 numDays;
  348|       |
  349|       |  /* Get back to GMT */
  350|    486|  time->tm_sec -= time->tm_params.tp_gmt_offset + time->tm_params.tp_dst_offset;
  351|    486|  time->tm_params.tp_gmt_offset = 0;
  352|    486|  time->tm_params.tp_dst_offset = 0;
  353|       |
  354|       |  /* Now normalize GMT */
  355|       |
  356|    486|  if (time->tm_usec < 0 || time->tm_usec >= 1000000) {
  ------------------
  |  Branch (356:7): [True: 0, False: 486]
  |  Branch (356:28): [True: 0, False: 486]
  ------------------
  357|      0|    time->tm_sec += time->tm_usec / 1000000;
  358|      0|    time->tm_usec %= 1000000;
  359|      0|    if (time->tm_usec < 0) {
  ------------------
  |  Branch (359:9): [True: 0, False: 0]
  ------------------
  360|      0|      time->tm_usec += 1000000;
  361|      0|      time->tm_sec--;
  362|      0|    }
  363|      0|  }
  364|       |
  365|       |  /* Note that we do not count leap seconds in this implementation */
  366|    486|  if (time->tm_sec < 0 || time->tm_sec >= 60) {
  ------------------
  |  Branch (366:7): [True: 0, False: 486]
  |  Branch (366:27): [True: 0, False: 486]
  ------------------
  367|      0|    time->tm_min += time->tm_sec / 60;
  368|      0|    time->tm_sec %= 60;
  369|      0|    if (time->tm_sec < 0) {
  ------------------
  |  Branch (369:9): [True: 0, False: 0]
  ------------------
  370|      0|      time->tm_sec += 60;
  371|      0|      time->tm_min--;
  372|      0|    }
  373|      0|  }
  374|       |
  375|    486|  if (time->tm_min < 0 || time->tm_min >= 60) {
  ------------------
  |  Branch (375:7): [True: 0, False: 486]
  |  Branch (375:27): [True: 0, False: 486]
  ------------------
  376|      0|    time->tm_hour += time->tm_min / 60;
  377|      0|    time->tm_min %= 60;
  378|      0|    if (time->tm_min < 0) {
  ------------------
  |  Branch (378:9): [True: 0, False: 0]
  ------------------
  379|      0|      time->tm_min += 60;
  380|      0|      time->tm_hour--;
  381|      0|    }
  382|      0|  }
  383|       |
  384|    486|  if (time->tm_hour < 0 || time->tm_hour >= 24) {
  ------------------
  |  Branch (384:7): [True: 0, False: 486]
  |  Branch (384:28): [True: 0, False: 486]
  ------------------
  385|      0|    time->tm_mday += time->tm_hour / 24;
  386|      0|    time->tm_hour %= 24;
  387|      0|    if (time->tm_hour < 0) {
  ------------------
  |  Branch (387:9): [True: 0, False: 0]
  ------------------
  388|      0|      time->tm_hour += 24;
  389|      0|      time->tm_mday--;
  390|      0|    }
  391|      0|  }
  392|       |
  393|       |  /* Normalize month and year before mday */
  394|    486|  if (time->tm_month < 0 || time->tm_month >= 12) {
  ------------------
  |  Branch (394:7): [True: 0, False: 486]
  |  Branch (394:29): [True: 0, False: 486]
  ------------------
  395|      0|    time->tm_year += time->tm_month / 12;
  396|      0|    time->tm_month %= 12;
  397|      0|    if (time->tm_month < 0) {
  ------------------
  |  Branch (397:9): [True: 0, False: 0]
  ------------------
  398|      0|      time->tm_month += 12;
  399|      0|      time->tm_year--;
  400|      0|    }
  401|      0|  }
  402|       |
  403|       |  /* Now that month and year are in proper range, normalize mday */
  404|       |
  405|    486|  if (time->tm_mday < 1) {
  ------------------
  |  Branch (405:7): [True: 0, False: 486]
  ------------------
  406|       |    /* mday too small */
  407|      0|    do {
  408|       |      /* the previous month */
  409|      0|      time->tm_month--;
  410|      0|      if (time->tm_month < 0) {
  ------------------
  |  Branch (410:11): [True: 0, False: 0]
  ------------------
  411|      0|        time->tm_month = 11;
  412|      0|        time->tm_year--;
  413|      0|      }
  414|      0|      time->tm_mday += nDays[IsLeapYear(time->tm_year)][time->tm_month];
  415|      0|    } while (time->tm_mday < 1);
  ------------------
  |  Branch (415:14): [True: 0, False: 0]
  ------------------
  416|    486|  } else {
  417|    486|    daysInMonth = nDays[IsLeapYear(time->tm_year)][time->tm_month];
  418|    502|    while (time->tm_mday > daysInMonth) {
  ------------------
  |  Branch (418:12): [True: 16, False: 486]
  ------------------
  419|       |      /* mday too large */
  420|     16|      time->tm_mday -= daysInMonth;
  421|     16|      time->tm_month++;
  422|     16|      if (time->tm_month > 11) {
  ------------------
  |  Branch (422:11): [True: 0, False: 16]
  ------------------
  423|      0|        time->tm_month = 0;
  424|      0|        time->tm_year++;
  425|      0|      }
  426|     16|      daysInMonth = nDays[IsLeapYear(time->tm_year)][time->tm_month];
  427|     16|    }
  428|    486|  }
  429|       |
  430|       |  /* Recompute yday and wday */
  431|    486|  time->tm_yday =
  432|    486|      time->tm_mday + lastDayOfMonth[IsLeapYear(time->tm_year)][time->tm_month];
  433|       |
  434|    486|  numDays = DAYS_BETWEEN_YEARS(1970, time->tm_year) + time->tm_yday;
  ------------------
  |  |   41|    486|#define DAYS_BETWEEN_YEARS(A, B) (COUNT_DAYS(B) - COUNT_DAYS(A))
  |  |  ------------------
  |  |  |  |   40|    486|#define COUNT_DAYS(Y) (((Y) - 1) * 365 + COUNT_LEAPS(Y))
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|    486|#define COUNT_LEAPS(Y) (((Y) - 1) / 4 - ((Y) - 1) / 100 + ((Y) - 1) / 400)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define DAYS_BETWEEN_YEARS(A, B) (COUNT_DAYS(B) - COUNT_DAYS(A))
  |  |  ------------------
  |  |  |  |   40|    486|#define COUNT_DAYS(Y) (((Y) - 1) * 365 + COUNT_LEAPS(Y))
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|    486|#define COUNT_LEAPS(Y) (((Y) - 1) / 4 - ((Y) - 1) / 100 + ((Y) - 1) / 400)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  435|    486|  time->tm_wday = (numDays + 4) % 7;
  436|    486|  if (time->tm_wday < 0) {
  ------------------
  |  Branch (436:7): [True: 68, False: 418]
  ------------------
  437|     68|    time->tm_wday += 7;
  438|     68|  }
  439|       |
  440|       |  /* Recompute time parameters */
  441|       |
  442|    486|  time->tm_params = params(time);
  443|       |
  444|    486|  ApplySecOffset(time,
  445|    486|                 time->tm_params.tp_gmt_offset + time->tm_params.tp_dst_offset);
  446|    486|}
_PR_InitTime:
  538|      1|void _PR_InitTime(void) {
  539|       |#ifdef HAVE_LOCALTIME_MONITOR
  540|       |  monitor = PR_NewLock();
  541|       |#endif
  542|       |#ifdef WINCE
  543|       |  _MD_InitTime();
  544|       |#endif
  545|      1|}
PR_GMTParameters:
  854|    486|PR_GMTParameters(const PRExplodedTime* gmt) {
  855|    486|  PRTimeParameters retVal = {0, 0};
  856|    486|  return retVal;
  857|    486|}
prtime.c:ApplySecOffset:
  279|    486|static void ApplySecOffset(PRExplodedTime* time, PRInt32 secOffset) {
  280|    486|  time->tm_sec += secOffset;
  281|       |
  282|       |  /* Note that in this implementation we do not count leap seconds */
  283|    486|  if (time->tm_sec < 0 || time->tm_sec >= 60) {
  ------------------
  |  Branch (283:7): [True: 0, False: 486]
  |  Branch (283:27): [True: 0, False: 486]
  ------------------
  284|      0|    time->tm_min += time->tm_sec / 60;
  285|      0|    time->tm_sec %= 60;
  286|      0|    if (time->tm_sec < 0) {
  ------------------
  |  Branch (286:9): [True: 0, False: 0]
  ------------------
  287|      0|      time->tm_sec += 60;
  288|      0|      time->tm_min--;
  289|      0|    }
  290|      0|  }
  291|       |
  292|    486|  if (time->tm_min < 0 || time->tm_min >= 60) {
  ------------------
  |  Branch (292:7): [True: 0, False: 486]
  |  Branch (292:27): [True: 0, False: 486]
  ------------------
  293|      0|    time->tm_hour += time->tm_min / 60;
  294|      0|    time->tm_min %= 60;
  295|      0|    if (time->tm_min < 0) {
  ------------------
  |  Branch (295:9): [True: 0, False: 0]
  ------------------
  296|      0|      time->tm_min += 60;
  297|      0|      time->tm_hour--;
  298|      0|    }
  299|      0|  }
  300|       |
  301|    486|  if (time->tm_hour < 0) {
  ------------------
  |  Branch (301:7): [True: 0, False: 486]
  ------------------
  302|       |    /* Decrement mday, yday, and wday */
  303|      0|    time->tm_hour += 24;
  304|      0|    time->tm_mday--;
  305|      0|    time->tm_yday--;
  306|      0|    if (time->tm_mday < 1) {
  ------------------
  |  Branch (306:9): [True: 0, False: 0]
  ------------------
  307|      0|      time->tm_month--;
  308|      0|      if (time->tm_month < 0) {
  ------------------
  |  Branch (308:11): [True: 0, False: 0]
  ------------------
  309|      0|        time->tm_month = 11;
  310|      0|        time->tm_year--;
  311|      0|        if (IsLeapYear(time->tm_year)) {
  ------------------
  |  Branch (311:13): [True: 0, False: 0]
  ------------------
  312|      0|          time->tm_yday = 365;
  313|      0|        } else {
  314|      0|          time->tm_yday = 364;
  315|      0|        }
  316|      0|      }
  317|      0|      time->tm_mday = nDays[IsLeapYear(time->tm_year)][time->tm_month];
  318|      0|    }
  319|      0|    time->tm_wday--;
  320|      0|    if (time->tm_wday < 0) {
  ------------------
  |  Branch (320:9): [True: 0, False: 0]
  ------------------
  321|      0|      time->tm_wday = 6;
  322|      0|    }
  323|    486|  } else if (time->tm_hour > 23) {
  ------------------
  |  Branch (323:14): [True: 0, False: 486]
  ------------------
  324|       |    /* Increment mday, yday, and wday */
  325|      0|    time->tm_hour -= 24;
  326|      0|    time->tm_mday++;
  327|      0|    time->tm_yday++;
  328|      0|    if (time->tm_mday > nDays[IsLeapYear(time->tm_year)][time->tm_month]) {
  ------------------
  |  Branch (328:9): [True: 0, False: 0]
  ------------------
  329|      0|      time->tm_mday = 1;
  330|      0|      time->tm_month++;
  331|      0|      if (time->tm_month > 11) {
  ------------------
  |  Branch (331:11): [True: 0, False: 0]
  ------------------
  332|      0|        time->tm_month = 0;
  333|      0|        time->tm_year++;
  334|      0|        time->tm_yday = 0;
  335|      0|      }
  336|      0|    }
  337|      0|    time->tm_wday++;
  338|      0|    if (time->tm_wday > 6) {
  ------------------
  |  Branch (338:9): [True: 0, False: 0]
  ------------------
  339|      0|      time->tm_wday = 0;
  340|      0|    }
  341|      0|  }
  342|    486|}
prtime.c:IsLeapYear:
  267|    988|static int IsLeapYear(PRInt16 year) {
  268|    988|  if ((year % 4 == 0 && year % 100 != 0) || year % 400 == 0) {
  ------------------
  |  Branch (268:8): [True: 142, False: 846]
  |  Branch (268:25): [True: 132, False: 10]
  |  Branch (268:45): [True: 4, False: 852]
  ------------------
  269|    136|    return 1;
  270|    136|  }
  271|    852|  return 0;
  272|    988|}

_PR_InitIO:
 1117|      1|void _PR_InitIO(void) {
 1118|      1|#  if defined(DEBUG)
 1119|      1|  memset(&pt_debug, 0, sizeof(PTDebug));
 1120|      1|  pt_debug.timeStarted = PR_Now();
 1121|      1|#  endif
 1122|       |
 1123|      1|  _pr_flock_lock = PR_NewLock();
 1124|      1|  PR_ASSERT(NULL != _pr_flock_lock);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 1125|      1|  _pr_flock_cv = PR_NewCondVar(_pr_flock_lock);
 1126|      1|  PR_ASSERT(NULL != _pr_flock_cv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 1127|      1|  _pr_rename_lock = PR_NewLock();
 1128|      1|  PR_ASSERT(NULL != _pr_rename_lock);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 1129|       |
 1130|      1|  _PR_InitFdCache(); /* do that */
 1131|       |
 1132|      1|  _pr_stdin = pt_SetMethods(0, PR_DESC_FILE, PR_FALSE, PR_TRUE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                _pr_stdin = pt_SetMethods(0, PR_DESC_FILE, PR_FALSE, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1133|      1|  _pr_stdout = pt_SetMethods(1, PR_DESC_FILE, PR_FALSE, PR_TRUE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                _pr_stdout = pt_SetMethods(1, PR_DESC_FILE, PR_FALSE, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1134|      1|  _pr_stderr = pt_SetMethods(2, PR_DESC_FILE, PR_FALSE, PR_TRUE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                _pr_stderr = pt_SetMethods(2, PR_DESC_FILE, PR_FALSE, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1135|      1|  PR_ASSERT(_pr_stdin && _pr_stdout && _pr_stderr);
  ------------------
  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 1136|       |
 1137|       |#  ifdef _PR_IPV6_V6ONLY_PROBE
 1138|       |  /* In Mac OS X v10.3 Panther Beta the IPV6_V6ONLY socket option
 1139|       |   * is turned on by default, contrary to what RFC 3493, Section
 1140|       |   * 5.3 says.  So we have to turn it off.  Find out whether we
 1141|       |   * are running on such a system.
 1142|       |   */
 1143|       |  {
 1144|       |    int osfd;
 1145|       |    osfd = socket(AF_INET6, SOCK_STREAM, 0);
 1146|       |    if (osfd != -1) {
 1147|       |      int on;
 1148|       |      socklen_t optlen = sizeof(on);
 1149|       |      if (getsockopt(osfd, IPPROTO_IPV6, IPV6_V6ONLY, &on, &optlen) == 0) {
 1150|       |        _pr_ipv6_v6only_on_by_default = on;
 1151|       |      }
 1152|       |      close(osfd);
 1153|       |    }
 1154|       |  }
 1155|       |#  endif
 1156|      1|} /* _PR_InitIO */
PR_GetFileMethods:
 3367|      3|PR_IMPLEMENT(const PRIOMethods*) PR_GetFileMethods(void) {
 3368|      3|  return &_pr_file_methods;
 3369|      3|} /* PR_GetFileMethods */
PR_GetTCPMethods:
 3375|      1|PR_IMPLEMENT(const PRIOMethods*) PR_GetTCPMethods(void) {
 3376|      1|  return &_pr_tcp_methods;
 3377|      1|} /* PR_GetTCPMethods */
PR_Socket:
 3452|      1|PR_Socket(PRInt32 domain, PRInt32 type, PRInt32 proto) {
 3453|      1|  PRIntn osfd;
 3454|      1|  PRDescType ftype;
 3455|      1|  PRFileDesc* fd = NULL;
 3456|      1|#  if defined(_PR_INET6_PROBE) || !defined(_PR_INET6)
 3457|      1|  PRInt32 tmp_domain = domain;
 3458|      1|#  endif
 3459|       |
 3460|      1|  if (!_pr_initialized) {
  ------------------
  |  Branch (3460:7): [True: 0, False: 1]
  ------------------
 3461|      0|    _PR_ImplicitInitialization();
 3462|      0|  }
 3463|       |
 3464|      1|  if (pt_TestAbort()) {
  ------------------
  |  Branch (3464:7): [True: 0, False: 1]
  ------------------
 3465|      0|    return NULL;
 3466|      0|  }
 3467|       |
 3468|      1|  if (PF_INET != domain && PR_AF_INET6 != domain
  ------------------
  |  |   27|      0|#define PR_AF_INET6 10  /* same as AF_INET6 */
  ------------------
  |  Branch (3468:7): [True: 0, False: 1]
  |  Branch (3468:28): [True: 0, False: 0]
  ------------------
 3469|      1|#  if defined(_PR_HAVE_SDP)
 3470|      1|      && PR_AF_INET_SDP != domain
  ------------------
  |  |  113|      0|#define PR_AF_INET_SDP 101
  ------------------
  |  Branch (3470:10): [True: 0, False: 0]
  ------------------
 3471|       |#    if defined(SOLARIS)
 3472|       |      && PR_AF_INET6_SDP != domain
 3473|       |#    endif /* SOLARIS */
 3474|      1|#  endif   /* _PR_HAVE_SDP */
 3475|      1|      && PF_UNIX != domain) {
  ------------------
  |  Branch (3475:10): [True: 0, False: 0]
  ------------------
 3476|      0|    PR_SetError(PR_ADDRESS_NOT_SUPPORTED_ERROR, 0);
  ------------------
  |  |   61|      0|#define PR_ADDRESS_NOT_SUPPORTED_ERROR           (-5985L)
  ------------------
 3477|      0|    return fd;
 3478|      0|  }
 3479|      1|  if (type == SOCK_STREAM) {
  ------------------
  |  Branch (3479:7): [True: 1, False: 0]
  ------------------
 3480|      1|    ftype = PR_DESC_SOCKET_TCP;
 3481|      1|  } else if (type == SOCK_DGRAM) {
  ------------------
  |  Branch (3481:14): [True: 0, False: 0]
  ------------------
 3482|      0|    ftype = PR_DESC_SOCKET_UDP;
 3483|      0|  } else {
 3484|      0|    (void)PR_SetError(PR_ADDRESS_NOT_SUPPORTED_ERROR, 0);
  ------------------
  |  |   61|      0|#define PR_ADDRESS_NOT_SUPPORTED_ERROR           (-5985L)
  ------------------
 3485|      0|    return fd;
 3486|      0|  }
 3487|      1|#  if defined(_PR_HAVE_SDP)
 3488|      1|#    if defined(LINUX)
 3489|      1|  if (PR_AF_INET_SDP == domain) {
  ------------------
  |  |  113|      1|#define PR_AF_INET_SDP 101
  ------------------
  |  Branch (3489:7): [True: 0, False: 1]
  ------------------
 3490|      0|    domain = AF_INET_SDP;
  ------------------
  |  |  208|      0|#      define AF_INET_SDP 27
  ------------------
 3491|      0|  }
 3492|       |#    elif defined(SOLARIS)
 3493|       |  if (PR_AF_INET_SDP == domain) {
 3494|       |    domain = AF_INET;
 3495|       |    proto = PROTO_SDP;
 3496|       |  } else if (PR_AF_INET6_SDP == domain) {
 3497|       |    domain = AF_INET6;
 3498|       |    proto = PROTO_SDP;
 3499|       |  }
 3500|       |#    endif /* SOLARIS */
 3501|      1|#  endif   /* _PR_HAVE_SDP */
 3502|      1|#  if defined(_PR_INET6_PROBE)
 3503|      1|  if (PR_AF_INET6 == domain) {
  ------------------
  |  |   27|      1|#define PR_AF_INET6 10  /* same as AF_INET6 */
  ------------------
  |  Branch (3503:7): [True: 0, False: 1]
  ------------------
 3504|      0|    domain = _pr_ipv6_is_present() ? AF_INET6 : AF_INET;
  ------------------
  |  Branch (3504:14): [True: 0, False: 0]
  ------------------
 3505|      0|  }
 3506|       |#  elif defined(_PR_INET6)
 3507|       |  if (PR_AF_INET6 == domain) {
 3508|       |    domain = AF_INET6;
 3509|       |  }
 3510|       |#  else
 3511|       |  if (PR_AF_INET6 == domain) {
 3512|       |    domain = AF_INET;
 3513|       |  }
 3514|       |#  endif
 3515|       |
 3516|      1|  osfd = socket(domain, type, proto);
 3517|      1|  if (osfd == -1) {
  ------------------
  |  Branch (3517:7): [True: 0, False: 1]
  ------------------
 3518|      0|    pt_MapError(_PR_MD_MAP_SOCKET_ERROR, errno);
  ------------------
  |  |   63|      0|#define _PR_MD_MAP_SOCKET_ERROR _MD_unix_map_socket_error
  ------------------
 3519|      1|  } else {
 3520|       |#  ifdef _PR_IPV6_V6ONLY_PROBE
 3521|       |    if ((domain == AF_INET6) && _pr_ipv6_v6only_on_by_default) {
 3522|       |      int on = 0;
 3523|       |      (void)setsockopt(osfd, IPPROTO_IPV6, IPV6_V6ONLY, &on, sizeof(on));
 3524|       |    }
 3525|       |#  endif
 3526|      1|    fd = pt_SetMethods(osfd, ftype, PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                  fd = pt_SetMethods(osfd, ftype, PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3527|      1|    if (fd == NULL) {
  ------------------
  |  Branch (3527:9): [True: 0, False: 1]
  ------------------
 3528|      0|      close(osfd);
 3529|      0|    }
 3530|      1|  }
 3531|       |#  ifdef _PR_NEED_SECRET_AF
 3532|       |  if (fd != NULL) {
 3533|       |    fd->secret->af = domain;
 3534|       |  }
 3535|       |#  endif
 3536|      1|#  if defined(_PR_INET6_PROBE) || !defined(_PR_INET6)
 3537|      1|  if (fd != NULL) {
  ------------------
  |  Branch (3537:7): [True: 1, False: 0]
  ------------------
 3538|       |    /*
 3539|       |     * For platforms with no support for IPv6
 3540|       |     * create layered socket for IPv4-mapped IPv6 addresses
 3541|       |     */
 3542|      1|    if (PR_AF_INET6 == tmp_domain && PR_AF_INET == domain) {
  ------------------
  |  |   27|      1|#define PR_AF_INET6 10  /* same as AF_INET6 */
  ------------------
                  if (PR_AF_INET6 == tmp_domain && PR_AF_INET == domain) {
  ------------------
  |  |   96|      0|#define PR_AF_INET AF_INET
  ------------------
  |  Branch (3542:9): [True: 0, False: 1]
  |  Branch (3542:38): [True: 0, False: 0]
  ------------------
 3543|      0|      if (PR_FAILURE == _pr_push_ipv6toipv4_layer(fd)) {
  ------------------
  |  Branch (3543:11): [True: 0, False: 0]
  ------------------
 3544|      0|        PR_Close(fd);
 3545|      0|        fd = NULL;
 3546|      0|      }
 3547|      0|    }
 3548|      1|  }
 3549|      1|#  endif
 3550|      1|  return fd;
 3551|      1|} /* PR_Socket */
PR_NewTCPSocket:
 4306|      1|PR_IMPLEMENT(PRFileDesc*) PR_NewTCPSocket(void) {
 4307|      1|  PRIntn domain = PF_INET;
 4308|       |
 4309|      1|  return PR_Socket(domain, SOCK_STREAM, 0);
 4310|      1|} /* PR_NewTCPSocket */
ptio.c:pt_SetMethods:
 3319|      4|                                 PRBool isAcceptedSocket, PRBool imported) {
 3320|      4|  PRFileDesc* fd = _PR_Getfd();
 3321|       |
 3322|      4|  if (fd == NULL) {
  ------------------
  |  Branch (3322:7): [True: 0, False: 4]
  ------------------
 3323|      0|    PR_SetError(PR_OUT_OF_MEMORY_ERROR, 0);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
 3324|      4|  } else {
 3325|      4|    fd->secret->md.osfd = osfd;
 3326|      4|    fd->secret->state = _PR_FILEDESC_OPEN;
  ------------------
  |  | 1702|      4|#define _PR_FILEDESC_OPEN       0xaaaaaaaa    /* 1010101... */
  ------------------
 3327|      4|    if (imported) {
  ------------------
  |  Branch (3327:9): [True: 3, False: 1]
  ------------------
 3328|      3|      fd->secret->inheritable = _PR_TRI_UNKNOWN;
 3329|      3|    } else {
 3330|       |      /* By default, a Unix fd is not closed on exec. */
 3331|      1|#  ifdef DEBUG
 3332|      1|      PRIntn flags;
 3333|      1|      flags = fcntl(osfd, F_GETFD, 0);
 3334|      1|      PR_ASSERT(0 == flags);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 3335|      1|#  endif
 3336|      1|      fd->secret->inheritable = _PR_TRI_TRUE;
 3337|      1|    }
 3338|      4|    switch (type) {
 3339|      3|      case PR_DESC_FILE:
  ------------------
  |  Branch (3339:7): [True: 3, False: 1]
  ------------------
 3340|      3|        fd->methods = PR_GetFileMethods();
 3341|      3|        break;
 3342|      1|      case PR_DESC_SOCKET_TCP:
  ------------------
  |  Branch (3342:7): [True: 1, False: 3]
  ------------------
 3343|      1|        fd->methods = PR_GetTCPMethods();
 3344|       |#  ifdef _PR_ACCEPT_INHERIT_NONBLOCK
 3345|       |        if (!isAcceptedSocket) {
 3346|       |          pt_MakeSocketNonblock(osfd);
 3347|       |        }
 3348|       |#  else
 3349|      1|        pt_MakeSocketNonblock(osfd);
  ------------------
  |  | 3315|      1|#    define pt_MakeSocketNonblock pt_MakeFdNonblock
  ------------------
 3350|      1|#  endif
 3351|      1|        break;
 3352|      0|      case PR_DESC_SOCKET_UDP:
  ------------------
  |  Branch (3352:7): [True: 0, False: 4]
  ------------------
 3353|      0|        fd->methods = PR_GetUDPMethods();
 3354|      0|        pt_MakeFdNonblock(osfd);
 3355|      0|        break;
 3356|      0|      case PR_DESC_PIPE:
  ------------------
  |  Branch (3356:7): [True: 0, False: 4]
  ------------------
 3357|      0|        fd->methods = PR_GetPipeMethods();
 3358|      0|        pt_MakeFdNonblock(osfd);
 3359|      0|        break;
 3360|      0|      default:
  ------------------
  |  Branch (3360:7): [True: 0, False: 4]
  ------------------
 3361|      0|        break;
 3362|      4|    }
 3363|      4|  }
 3364|      4|  return fd;
 3365|      4|} /* pt_SetMethods */
ptio.c:pt_Close:
 1233|      1|static PRStatus pt_Close(PRFileDesc* fd) {
 1234|      1|  if ((NULL == fd) || (NULL == fd->secret) ||
  ------------------
  |  Branch (1234:7): [True: 0, False: 1]
  |  Branch (1234:23): [True: 0, False: 1]
  ------------------
 1235|      1|      ((_PR_FILEDESC_OPEN != fd->secret->state) &&
  ------------------
  |  | 1702|      1|#define _PR_FILEDESC_OPEN       0xaaaaaaaa    /* 1010101... */
  ------------------
  |  Branch (1235:8): [True: 0, False: 1]
  ------------------
 1236|      1|       (_PR_FILEDESC_CLOSED != fd->secret->state))) {
  ------------------
  |  | 1703|      0|#define _PR_FILEDESC_CLOSED     0x55555555    /* 0101010... */
  ------------------
  |  Branch (1236:8): [True: 0, False: 0]
  ------------------
 1237|      0|    PR_SetError(PR_BAD_DESCRIPTOR_ERROR, 0);
  ------------------
  |  |   19|      0|#define PR_BAD_DESCRIPTOR_ERROR                  (-5999L)
  ------------------
 1238|      0|    return PR_FAILURE;
 1239|      0|  }
 1240|      1|  if (pt_TestAbort()) {
  ------------------
  |  Branch (1240:7): [True: 0, False: 1]
  ------------------
 1241|      0|    return PR_FAILURE;
 1242|      0|  }
 1243|       |
 1244|      1|  if (_PR_FILEDESC_OPEN == fd->secret->state) {
  ------------------
  |  | 1702|      1|#define _PR_FILEDESC_OPEN       0xaaaaaaaa    /* 1010101... */
  ------------------
  |  Branch (1244:7): [True: 1, False: 0]
  ------------------
 1245|      1|    if (-1 == close(fd->secret->md.osfd)) {
  ------------------
  |  Branch (1245:9): [True: 0, False: 1]
  ------------------
 1246|      0|      pt_MapError(_PR_MD_MAP_CLOSE_ERROR, errno);
  ------------------
  |  |   60|      0|#define _PR_MD_MAP_CLOSE_ERROR  _MD_unix_map_close_error
  ------------------
 1247|      0|      return PR_FAILURE;
 1248|      0|    }
 1249|      1|    fd->secret->state = _PR_FILEDESC_CLOSED;
  ------------------
  |  | 1703|      1|#define _PR_FILEDESC_CLOSED     0x55555555    /* 0101010... */
  ------------------
 1250|      1|  }
 1251|      1|  _PR_Putfd(fd);
 1252|      1|  return PR_SUCCESS;
 1253|      1|} /* pt_Close */
ptio.c:pt_GetPeerName:
 2818|      1|static PRStatus pt_GetPeerName(PRFileDesc* fd, PRNetAddr* addr) {
 2819|      1|  PRIntn rv = -1;
 2820|      1|  pt_SockLen addr_len = sizeof(PRNetAddr);
 2821|       |
 2822|      1|  if (pt_TestAbort()) {
  ------------------
  |  Branch (2822:7): [True: 0, False: 1]
  ------------------
 2823|      0|    return PR_FAILURE;
 2824|      0|  }
 2825|       |
 2826|      1|  rv = getpeername(fd->secret->md.osfd, (struct sockaddr*)addr, &addr_len);
 2827|       |
 2828|      1|  if (rv == -1) {
  ------------------
  |  Branch (2828:7): [True: 1, False: 0]
  ------------------
 2829|      1|    pt_MapError(_PR_MD_MAP_GETPEERNAME_ERROR, errno);
  ------------------
  |  |  105|      1|#define _PR_MD_MAP_GETPEERNAME_ERROR    _MD_unix_map_getpeername_error
  ------------------
 2830|      1|    return PR_FAILURE;
 2831|      1|  }
 2832|       |#  ifdef _PR_HAVE_SOCKADDR_LEN
 2833|       |  /* ignore the sa_len field of struct sockaddr */
 2834|       |  if (addr) {
 2835|       |    addr->raw.family = ((struct sockaddr*)addr)->sa_family;
 2836|       |  }
 2837|       |#  endif /* _PR_HAVE_SOCKADDR_LEN */
 2838|      0|#  ifdef _PR_INET6
 2839|      0|  if (AF_INET6 == addr->raw.family) {
  ------------------
  |  Branch (2839:7): [True: 0, False: 0]
  ------------------
 2840|      0|    addr->raw.family = PR_AF_INET6;
  ------------------
  |  |   27|      0|#define PR_AF_INET6 10  /* same as AF_INET6 */
  ------------------
 2841|      0|  }
 2842|      0|#  endif
 2843|      0|  PR_ASSERT(IsValidNetAddr(addr) == PR_TRUE);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2844|      0|  PR_ASSERT(IsValidNetAddrLen(addr, addr_len) == PR_TRUE);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2845|      0|  return PR_SUCCESS;
 2846|      1|} /* pt_GetPeerName */
ptio.c:pt_MakeFdNonblock:
 3288|      1|static void pt_MakeFdNonblock(PRIntn osfd) {
 3289|      1|  PRIntn flags;
 3290|      1|  flags = fcntl(osfd, F_GETFL, 0);
 3291|      1|  flags |= _PR_FCNTL_FLAGS;
  ------------------
  |  | 3280|      1|#    define _PR_FCNTL_FLAGS O_NONBLOCK
  ------------------
 3292|      1|  (void)fcntl(osfd, F_SETFL, flags);
 3293|      1|}
ptio.c:pt_TestAbort:
 1210|      3|static PRBool pt_TestAbort(void) {
 1211|      3|  PRThread* me = PR_GetCurrentThread();
 1212|      3|  if (_PT_THREAD_INTERRUPTED(me)) {
  ------------------
  |  |  149|      3|        (!(thr->interrupt_blocked) && (thr->state & PT_THREAD_ABORTED))
  |  |  ------------------
  |  |  |  |  142|      3|#define PT_THREAD_ABORTED   0x10    /* thread has been interrupted */
  |  |  ------------------
  |  |  |  Branch (149:10): [True: 3, False: 0]
  |  |  |  Branch (149:39): [True: 0, False: 3]
  |  |  ------------------
  ------------------
 1213|      0|    PR_SetError(PR_PENDING_INTERRUPT_ERROR, 0);
  ------------------
  |  |   37|      0|#define PR_PENDING_INTERRUPT_ERROR               (-5993L)
  ------------------
 1214|      0|    me->state &= ~PT_THREAD_ABORTED;
  ------------------
  |  |  142|      0|#define PT_THREAD_ABORTED   0x10    /* thread has been interrupted */
  ------------------
 1215|      0|    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1216|      0|  }
 1217|      3|  return PR_FALSE;
  ------------------
  |  |  438|      3|#define PR_FALSE 0
  ------------------
 1218|      3|} /* pt_TestAbort */
ptio.c:pt_MapError:
 1220|      1|static void pt_MapError(void (*mapper)(PRIntn), PRIntn syserrno) {
 1221|      1|  switch (syserrno) {
 1222|      0|    case EINTR:
  ------------------
  |  Branch (1222:5): [True: 0, False: 1]
  ------------------
 1223|      0|      PR_SetError(PR_PENDING_INTERRUPT_ERROR, 0);
  ------------------
  |  |   37|      0|#define PR_PENDING_INTERRUPT_ERROR               (-5993L)
  ------------------
 1224|      0|      break;
 1225|      0|    case ETIMEDOUT:
  ------------------
  |  Branch (1225:5): [True: 0, False: 1]
  ------------------
 1226|      0|      PR_SetError(PR_IO_TIMEOUT_ERROR, 0);
  ------------------
  |  |   46|      0|#define PR_IO_TIMEOUT_ERROR                      (-5990L)
  ------------------
 1227|      0|      break;
 1228|      1|    default:
  ------------------
  |  Branch (1228:5): [True: 1, False: 0]
  ------------------
 1229|      1|      mapper(syserrno);
 1230|      1|  }
 1231|      1|} /* pt_MapError */

_PR_InitCPUs:
   22|      1|void _PR_InitCPUs(void) { PT_LOG("_PR_InitCPUs") }
_PR_InitStacks:
   23|      1|void _PR_InitStacks(void){PT_LOG("_PR_InitStacks")}

_PR_InitLocks:
   45|      1|void _PR_InitLocks(void) {
   46|      1|  int rv;
   47|      1|  rv = _PT_PTHREAD_MUTEXATTR_INIT(&_pt_mattr);
  ------------------
  |  |   17|      1|#define _PT_PTHREAD_MUTEXATTR_INIT        pthread_mutexattr_init
  ------------------
   48|      1|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
   49|       |
   50|      1|#  if (defined(LINUX) &&                                               \
   51|      1|       (__GLIBC__ > 2 || (__GLIBC__ == 2 && __GLIBC_MINOR__ >= 2))) || \
   52|      1|      (defined(FREEBSD) && __FreeBSD_version > 700055)
   53|      1|  rv = pthread_mutexattr_settype(&_pt_mattr, PTHREAD_MUTEX_ADAPTIVE_NP);
   54|      1|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
   55|      1|#  endif
   56|       |
   57|      1|  rv = _PT_PTHREAD_CONDATTR_INIT(&_pt_cvar_attr);
  ------------------
  |  |   30|      1|#define _PT_PTHREAD_CONDATTR_INIT         pthread_condattr_init
  ------------------
   58|      1|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
   59|      1|}
PR_NewLock:
  121|  4.90M|PR_IMPLEMENT(PRLock*) PR_NewLock(void) {
  122|  4.90M|  PRIntn rv;
  123|  4.90M|  PRLock* lock;
  124|       |
  125|  4.90M|  if (!_pr_initialized) {
  ------------------
  |  Branch (125:7): [True: 0, False: 4.90M]
  ------------------
  126|      0|    _PR_ImplicitInitialization();
  127|      0|  }
  128|       |
  129|  4.90M|  lock = PR_NEWZAP(PRLock);
  ------------------
  |  |   99|  4.90M|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  130|  4.90M|  if (lock != NULL) {
  ------------------
  |  Branch (130:7): [True: 4.90M, False: 0]
  ------------------
  131|  4.90M|    rv = _PT_PTHREAD_MUTEX_INIT(lock->mutex, _pt_mattr);
  ------------------
  |  |   19|  4.90M|#define _PT_PTHREAD_MUTEX_INIT(m, a)      pthread_mutex_init(&(m), &(a))
  ------------------
  132|  4.90M|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  4.90M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.90M, False: 0]
  |  |  ------------------
  ------------------
  133|  4.90M|  }
  134|  4.90M|#  if defined(DEBUG)
  135|  4.90M|  pt_debug.locks_created += 1;
  136|  4.90M|#  endif
  137|  4.90M|  return lock;
  138|  4.90M|} /* PR_NewLock */
PR_DestroyLock:
  140|  4.90M|PR_IMPLEMENT(void) PR_DestroyLock(PRLock* lock) {
  141|  4.90M|  PRIntn rv;
  142|  4.90M|  PR_ASSERT(NULL != lock);
  ------------------
  |  |  208|  4.90M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.90M, False: 0]
  |  |  ------------------
  ------------------
  143|  4.90M|  PR_ASSERT(PR_FALSE == lock->locked);
  ------------------
  |  |  208|  4.90M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.90M, False: 0]
  |  |  ------------------
  ------------------
  144|  4.90M|  PR_ASSERT(0 == lock->notified.length);
  ------------------
  |  |  208|  4.90M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.90M, False: 0]
  |  |  ------------------
  ------------------
  145|  4.90M|  PR_ASSERT(NULL == lock->notified.link);
  ------------------
  |  |  208|  4.90M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.90M, False: 0]
  |  |  ------------------
  ------------------
  146|  4.90M|  rv = pthread_mutex_destroy(&lock->mutex);
  147|  4.90M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  4.90M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.90M, False: 0]
  |  |  ------------------
  ------------------
  148|  4.90M|#  if defined(DEBUG)
  149|  4.90M|  memset(lock, 0xaf, sizeof(PRLock));
  150|  4.90M|  pt_debug.locks_destroyed += 1;
  151|  4.90M|#  endif
  152|  4.90M|  PR_Free(lock);
  153|  4.90M|} /* PR_DestroyLock */
PR_Lock:
  155|   152M|PR_IMPLEMENT(void) PR_Lock(PRLock* lock) {
  156|       |  /* Nb: PR_Lock must not call PR_GetCurrentThread to access the |id| or
  157|       |   * |tid| field of the current thread's PRThread structure because
  158|       |   * _pt_root calls PR_Lock before setting thred->id and thred->tid. */
  159|   152M|  PRIntn rv;
  160|   152M|  PR_ASSERT(lock != NULL);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  161|   152M|  rv = pthread_mutex_lock(&lock->mutex);
  162|   152M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  163|   152M|  PR_ASSERT(0 == lock->notified.length);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  164|   152M|  PR_ASSERT(NULL == lock->notified.link);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  165|   152M|  PR_ASSERT(PR_FALSE == lock->locked);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  166|       |  /* Nb: the order of the next two statements is not critical to
  167|       |   * the correctness of PR_AssertCurrentThreadOwnsLock(), but
  168|       |   * this particular order makes the assertion more likely to
  169|       |   * catch errors. */
  170|   152M|  lock->owner = pthread_self();
  171|   152M|  lock->locked = PR_TRUE;
  ------------------
  |  |  437|   152M|#define PR_TRUE 1
  ------------------
  172|   152M|#  if defined(DEBUG)
  173|   152M|  pt_debug.locks_acquired += 1;
  174|   152M|#  endif
  175|   152M|} /* PR_Lock */
PR_Unlock:
  177|   152M|PR_IMPLEMENT(PRStatus) PR_Unlock(PRLock* lock) {
  178|   152M|  pthread_t self = pthread_self();
  179|   152M|  PRIntn rv;
  180|       |
  181|   152M|  PR_ASSERT(lock != NULL);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  182|   152M|  PR_ASSERT(_PT_PTHREAD_MUTEX_IS_LOCKED(lock->mutex));
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  183|   152M|  PR_ASSERT(PR_TRUE == lock->locked);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  184|   152M|  PR_ASSERT(pthread_equal(lock->owner, self));
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  185|       |
  186|   152M|  if (!lock->locked || !pthread_equal(lock->owner, self)) {
  ------------------
  |  Branch (186:7): [True: 0, False: 152M]
  |  Branch (186:24): [True: 0, False: 152M]
  ------------------
  187|      0|    return PR_FAILURE;
  188|      0|  }
  189|       |
  190|   152M|  lock->locked = PR_FALSE;
  ------------------
  |  |  438|   152M|#define PR_FALSE 0
  ------------------
  191|   152M|  if (0 == lock->notified.length) /* shortcut */
  ------------------
  |  Branch (191:7): [True: 152M, False: 40]
  ------------------
  192|   152M|  {
  193|   152M|    rv = pthread_mutex_unlock(&lock->mutex);
  194|   152M|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|   152M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 152M, False: 0]
  |  |  ------------------
  ------------------
  195|   152M|  } else {
  196|     40|    pt_PostNotifies(lock, PR_TRUE);
  ------------------
  |  |  437|     40|#define PR_TRUE 1
  ------------------
  197|     40|  }
  198|       |
  199|   152M|#  if defined(DEBUG)
  200|   152M|  pt_debug.locks_released += 1;
  201|   152M|#  endif
  202|   152M|  return PR_SUCCESS;
  203|   152M|} /* PR_Unlock */
PR_NewCondVar:
  296|  19.4k|PR_IMPLEMENT(PRCondVar*) PR_NewCondVar(PRLock* lock) {
  297|  19.4k|  PRCondVar* cv = PR_NEW(PRCondVar);
  ------------------
  |  |   65|  19.4k|#define PR_NEW(_struct) ((_struct *) PR_MALLOC(sizeof(_struct)))
  |  |  ------------------
  |  |  |  |   55|  19.4k|#define PR_MALLOC(_bytes) (PR_Malloc((_bytes)))
  |  |  ------------------
  ------------------
  298|  19.4k|  PR_ASSERT(lock != NULL);
  ------------------
  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 19.4k, False: 0]
  |  |  ------------------
  ------------------
  299|  19.4k|  if (cv != NULL) {
  ------------------
  |  Branch (299:7): [True: 19.4k, False: 0]
  ------------------
  300|  19.4k|    int rv = _PT_PTHREAD_COND_INIT(cv->cv, _pt_cvar_attr);
  ------------------
  |  |   33|  19.4k|#define _PT_PTHREAD_COND_INIT(m, a)       pthread_cond_init(&(m), &(a))
  ------------------
  301|  19.4k|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 19.4k, False: 0]
  |  |  ------------------
  ------------------
  302|  19.4k|    if (0 == rv) {
  ------------------
  |  Branch (302:9): [True: 19.4k, False: 0]
  ------------------
  303|  19.4k|      cv->lock = lock;
  304|  19.4k|      cv->notify_pending = 0;
  305|  19.4k|#  if defined(DEBUG)
  306|  19.4k|      pt_debug.cvars_created += 1;
  307|  19.4k|#  endif
  308|  19.4k|    } else {
  309|      0|      PR_DELETE(cv);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  310|      0|      cv = NULL;
  311|      0|    }
  312|  19.4k|  }
  313|  19.4k|  return cv;
  314|  19.4k|} /* PR_NewCondVar */
PR_DestroyCondVar:
  316|  19.4k|PR_IMPLEMENT(void) PR_DestroyCondVar(PRCondVar* cvar) {
  317|  19.4k|  if (0 > PR_ATOMIC_DECREMENT(&cvar->notify_pending)) {
  ------------------
  |  |  123|  19.4k|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (317:7): [True: 19.4k, False: 0]
  ------------------
  318|  19.4k|    PRIntn rv = pthread_cond_destroy(&cvar->cv);
  319|  19.4k|#  if defined(DEBUG)
  320|  19.4k|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 19.4k, False: 0]
  |  |  ------------------
  ------------------
  321|  19.4k|    memset(cvar, 0xaf, sizeof(PRCondVar));
  322|  19.4k|    pt_debug.cvars_destroyed += 1;
  323|       |#  else
  324|       |    (void)rv;
  325|       |#  endif
  326|  19.4k|    PR_Free(cvar);
  327|  19.4k|  }
  328|  19.4k|} /* PR_DestroyCondVar */
PR_NotifyAllCondVar:
  401|     40|PR_IMPLEMENT(PRStatus) PR_NotifyAllCondVar(PRCondVar* cvar) {
  402|     40|  PR_ASSERT(cvar != NULL);
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
  403|     40|  pt_PostNotifyToCvar(cvar, PR_TRUE);
  ------------------
  |  |  437|     40|#define PR_TRUE 1
  ------------------
  404|     40|  return PR_SUCCESS;
  405|     40|} /* PR_NotifyAllCondVar */
PR_NewMonitor:
  452|  42.9k|PR_IMPLEMENT(PRMonitor*) PR_NewMonitor(void) {
  453|  42.9k|  PRMonitor* mon;
  454|  42.9k|  int rv;
  455|       |
  456|  42.9k|  if (!_pr_initialized) {
  ------------------
  |  Branch (456:7): [True: 0, False: 42.9k]
  ------------------
  457|      0|    _PR_ImplicitInitialization();
  458|      0|  }
  459|       |
  460|  42.9k|  mon = PR_NEWZAP(PRMonitor);
  ------------------
  |  |   99|  42.9k|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  461|  42.9k|  if (mon == NULL) {
  ------------------
  |  Branch (461:7): [True: 0, False: 42.9k]
  ------------------
  462|      0|    PR_SetError(PR_OUT_OF_MEMORY_ERROR, 0);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  463|      0|    return NULL;
  464|      0|  }
  465|       |
  466|  42.9k|  rv = _PT_PTHREAD_MUTEX_INIT(mon->lock, _pt_mattr);
  ------------------
  |  |   19|  42.9k|#define _PT_PTHREAD_MUTEX_INIT(m, a)      pthread_mutex_init(&(m), &(a))
  ------------------
  467|  42.9k|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  42.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 42.9k, False: 0]
  |  |  ------------------
  ------------------
  468|  42.9k|  if (0 != rv) {
  ------------------
  |  Branch (468:7): [True: 0, False: 42.9k]
  ------------------
  469|      0|    goto error1;
  470|      0|  }
  471|       |
  472|  42.9k|  _PT_PTHREAD_INVALIDATE_THR_HANDLE(mon->owner);
  ------------------
  |  |   70|  42.9k|#define _PT_PTHREAD_INVALIDATE_THR_HANDLE(t)  (t) = 0
  ------------------
  473|       |
  474|  42.9k|  rv = _PT_PTHREAD_COND_INIT(mon->entryCV, _pt_cvar_attr);
  ------------------
  |  |   33|  42.9k|#define _PT_PTHREAD_COND_INIT(m, a)       pthread_cond_init(&(m), &(a))
  ------------------
  475|  42.9k|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  42.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 42.9k, False: 0]
  |  |  ------------------
  ------------------
  476|  42.9k|  if (0 != rv) {
  ------------------
  |  Branch (476:7): [True: 0, False: 42.9k]
  ------------------
  477|      0|    goto error2;
  478|      0|  }
  479|       |
  480|  42.9k|  rv = _PT_PTHREAD_COND_INIT(mon->waitCV, _pt_cvar_attr);
  ------------------
  |  |   33|  42.9k|#define _PT_PTHREAD_COND_INIT(m, a)       pthread_cond_init(&(m), &(a))
  ------------------
  481|  42.9k|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  42.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 42.9k, False: 0]
  |  |  ------------------
  ------------------
  482|  42.9k|  if (0 != rv) {
  ------------------
  |  Branch (482:7): [True: 0, False: 42.9k]
  ------------------
  483|      0|    goto error3;
  484|      0|  }
  485|       |
  486|  42.9k|  mon->notifyTimes = 0;
  487|  42.9k|  mon->entryCount = 0;
  488|  42.9k|  mon->refCount = 1;
  489|  42.9k|  mon->name = NULL;
  490|  42.9k|  return mon;
  491|       |
  492|      0|error3:
  493|      0|  pthread_cond_destroy(&mon->entryCV);
  494|      0|error2:
  495|      0|  pthread_mutex_destroy(&mon->lock);
  496|      0|error1:
  497|      0|  PR_Free(mon);
  498|      0|  _PR_MD_MAP_DEFAULT_ERROR(rv);
  ------------------
  |  |   15|      0|#define _PR_MD_MAP_DEFAULT_ERROR    _MD_unix_map_default_error
  ------------------
  499|      0|  return NULL;
  500|      0|} /* PR_NewMonitor */
PR_NewNamedMonitor:
  502|      1|PR_IMPLEMENT(PRMonitor*) PR_NewNamedMonitor(const char* name) {
  503|      1|  PRMonitor* mon = PR_NewMonitor();
  504|      1|  if (mon) {
  ------------------
  |  Branch (504:7): [True: 1, False: 0]
  ------------------
  505|      1|    mon->name = name;
  506|      1|  }
  507|      1|  return mon;
  508|      1|}
PR_DestroyMonitor:
  510|  2.17M|PR_IMPLEMENT(void) PR_DestroyMonitor(PRMonitor* mon) {
  511|  2.17M|  int rv;
  512|       |
  513|  2.17M|  PR_ASSERT(mon != NULL);
  ------------------
  |  |  208|  2.17M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.17M, False: 0]
  |  |  ------------------
  ------------------
  514|  2.17M|  if (PR_ATOMIC_DECREMENT(&mon->refCount) == 0) {
  ------------------
  |  |  123|  2.17M|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (514:7): [True: 42.9k, False: 2.13M]
  ------------------
  515|  42.9k|    rv = pthread_cond_destroy(&mon->waitCV);
  516|  42.9k|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  42.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 42.9k, False: 0]
  |  |  ------------------
  ------------------
  517|  42.9k|    rv = pthread_cond_destroy(&mon->entryCV);
  518|  42.9k|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  42.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 42.9k, False: 0]
  |  |  ------------------
  ------------------
  519|  42.9k|    rv = pthread_mutex_destroy(&mon->lock);
  520|  42.9k|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  42.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 42.9k, False: 0]
  |  |  ------------------
  ------------------
  521|  42.9k|#  if defined(DEBUG)
  522|  42.9k|    memset(mon, 0xaf, sizeof(PRMonitor));
  523|  42.9k|#  endif
  524|  42.9k|    PR_Free(mon);
  525|  42.9k|  }
  526|  2.17M|} /* PR_DestroyMonitor */
PR_GetMonitorEntryCount:
  531|  9.10M|PR_IMPLEMENT(PRIntn) PR_GetMonitorEntryCount(PRMonitor* mon) {
  532|  9.10M|  pthread_t self = pthread_self();
  533|  9.10M|  PRIntn rv;
  534|  9.10M|  PRIntn count = 0;
  535|       |
  536|  9.10M|  rv = pthread_mutex_lock(&mon->lock);
  537|  9.10M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  9.10M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.10M, False: 0]
  |  |  ------------------
  ------------------
  538|  9.10M|  if (pthread_equal(mon->owner, self)) {
  ------------------
  |  Branch (538:7): [True: 7.08M, False: 2.01M]
  ------------------
  539|  7.08M|    count = mon->entryCount;
  540|  7.08M|  }
  541|  9.10M|  rv = pthread_mutex_unlock(&mon->lock);
  542|  9.10M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  9.10M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.10M, False: 0]
  |  |  ------------------
  ------------------
  543|  9.10M|  return count;
  544|  9.10M|}
PR_EnterMonitor:
  558|  2.14M|PR_IMPLEMENT(void) PR_EnterMonitor(PRMonitor* mon) {
  559|  2.14M|  pthread_t self = pthread_self();
  560|  2.14M|  PRIntn rv;
  561|       |
  562|  2.14M|  PR_ASSERT(mon != NULL);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  563|  2.14M|  rv = pthread_mutex_lock(&mon->lock);
  564|  2.14M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  565|  2.14M|  if (mon->entryCount != 0) {
  ------------------
  |  Branch (565:7): [True: 10.8k, False: 2.13M]
  ------------------
  566|  10.8k|    if (pthread_equal(mon->owner, self)) {
  ------------------
  |  Branch (566:9): [True: 10.8k, False: 0]
  ------------------
  567|  10.8k|      goto done;
  568|  10.8k|    }
  569|      0|    while (mon->entryCount != 0) {
  ------------------
  |  Branch (569:12): [True: 0, False: 0]
  ------------------
  570|      0|      rv = pthread_cond_wait(&mon->entryCV, &mon->lock);
  571|      0|      PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  572|      0|    }
  573|      0|  }
  574|       |  /* and now I have the monitor */
  575|  2.13M|  PR_ASSERT(0 == mon->notifyTimes);
  ------------------
  |  |  208|  2.13M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.13M, False: 0]
  |  |  ------------------
  ------------------
  576|  2.13M|  PR_ASSERT(_PT_PTHREAD_THR_HANDLE_IS_INVALID(mon->owner));
  ------------------
  |  |  208|  2.13M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.13M, False: 0]
  |  |  ------------------
  ------------------
  577|  2.13M|  _PT_PTHREAD_COPY_THR_HANDLE(self, mon->owner);
  ------------------
  |  |   72|  2.13M|#define _PT_PTHREAD_COPY_THR_HANDLE(st, dt)   (dt) = (st)
  ------------------
  578|       |
  579|  2.14M|done:
  580|  2.14M|  mon->entryCount += 1;
  581|  2.14M|  rv = pthread_mutex_unlock(&mon->lock);
  582|  2.14M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  583|  2.14M|} /* PR_EnterMonitor */
PR_ExitMonitor:
  585|  2.14M|PR_IMPLEMENT(PRStatus) PR_ExitMonitor(PRMonitor* mon) {
  586|  2.14M|  pthread_t self = pthread_self();
  587|  2.14M|  PRIntn rv;
  588|  2.14M|  PRBool notifyEntryWaiter = PR_FALSE;
  ------------------
  |  |  438|  2.14M|#define PR_FALSE 0
  ------------------
  589|  2.14M|  PRIntn notifyTimes = 0;
  590|       |
  591|  2.14M|  PR_ASSERT(mon != NULL);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  592|  2.14M|  rv = pthread_mutex_lock(&mon->lock);
  593|  2.14M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  594|       |  /* the entries should be > 0 and we'd better be the owner */
  595|  2.14M|  PR_ASSERT(mon->entryCount > 0);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  596|  2.14M|  PR_ASSERT(pthread_equal(mon->owner, self));
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  597|  2.14M|  if (mon->entryCount == 0 || !pthread_equal(mon->owner, self)) {
  ------------------
  |  Branch (597:7): [True: 0, False: 2.14M]
  |  Branch (597:31): [True: 0, False: 2.14M]
  ------------------
  598|      0|    rv = pthread_mutex_unlock(&mon->lock);
  599|      0|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  600|      0|    return PR_FAILURE;
  601|      0|  }
  602|       |
  603|  2.14M|  mon->entryCount -= 1; /* reduce by one */
  604|  2.14M|  if (mon->entryCount == 0) {
  ------------------
  |  Branch (604:7): [True: 2.13M, False: 10.8k]
  ------------------
  605|       |    /* and if it transitioned to zero - notify an entry waiter */
  606|       |    /* make the owner unknown */
  607|  2.13M|    _PT_PTHREAD_INVALIDATE_THR_HANDLE(mon->owner);
  ------------------
  |  |   70|  2.13M|#define _PT_PTHREAD_INVALIDATE_THR_HANDLE(t)  (t) = 0
  ------------------
  608|  2.13M|    notifyEntryWaiter = PR_TRUE;
  ------------------
  |  |  437|  2.13M|#define PR_TRUE 1
  ------------------
  609|  2.13M|    notifyTimes = mon->notifyTimes;
  610|  2.13M|    mon->notifyTimes = 0;
  611|       |    /* We will access the members of 'mon' after unlocking mon->lock.
  612|       |     * Add a reference. */
  613|  2.13M|    PR_ATOMIC_INCREMENT(&mon->refCount);
  ------------------
  |  |  122|  2.13M|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  614|  2.13M|  }
  615|  2.14M|  rv = pthread_mutex_unlock(&mon->lock);
  616|  2.14M|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  2.14M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.14M, False: 0]
  |  |  ------------------
  ------------------
  617|  2.14M|  if (notifyEntryWaiter) {
  ------------------
  |  Branch (617:7): [True: 2.13M, False: 10.8k]
  ------------------
  618|  2.13M|    if (notifyTimes) {
  ------------------
  |  Branch (618:9): [True: 0, False: 2.13M]
  ------------------
  619|      0|      pt_PostNotifiesFromMonitor(&mon->waitCV, notifyTimes);
  620|      0|    }
  621|  2.13M|    rv = pthread_cond_signal(&mon->entryCV);
  622|  2.13M|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|  2.13M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2.13M, False: 0]
  |  |  ------------------
  ------------------
  623|       |    /* We are done accessing the members of 'mon'. Release the
  624|       |     * reference. */
  625|  2.13M|    PR_DestroyMonitor(mon);
  626|  2.13M|  }
  627|  2.14M|  return PR_SUCCESS;
  628|  2.14M|} /* PR_ExitMonitor */
ptsynch.c:pt_PostNotifies:
   61|     40|static void pt_PostNotifies(PRLock* lock, PRBool unlock) {
   62|     40|  PRIntn index, rv;
   63|     40|  _PT_Notified post;
   64|     40|  _PT_Notified *notified, *prev = NULL;
   65|       |  /*
   66|       |   * Time to actually notify any conditions that were affected
   67|       |   * while the lock was held. Get a copy of the list that's in
   68|       |   * the lock structure and then zero the original. If it's
   69|       |   * linked to other such structures, we own that storage.
   70|       |   */
   71|     40|  post = lock->notified; /* a safe copy; we own the lock */
   72|       |
   73|     40|#  if defined(DEBUG)
   74|     40|  memset(&lock->notified, 0, sizeof(_PT_Notified)); /* reset */
   75|       |#  else
   76|       |  lock->notified.length = 0; /* these are really sufficient */
   77|       |  lock->notified.link = NULL;
   78|       |#  endif
   79|       |
   80|       |  /* should (may) we release lock before notifying? */
   81|     40|  if (unlock) {
  ------------------
  |  Branch (81:7): [True: 40, False: 0]
  ------------------
   82|     40|    rv = pthread_mutex_unlock(&lock->mutex);
   83|     40|    PR_ASSERT(0 == rv);
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
   84|     40|  }
   85|       |
   86|     40|  notified = &post; /* this is where we start */
   87|     40|  do {
   88|     80|    for (index = 0; index < notified->length; ++index) {
  ------------------
  |  Branch (88:21): [True: 40, False: 40]
  ------------------
   89|     40|      PRCondVar* cv = notified->cv[index].cv;
   90|     40|      PR_ASSERT(NULL != cv);
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
   91|     40|      PR_ASSERT(0 != notified->cv[index].times);
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
   92|     40|      if (-1 == notified->cv[index].times) {
  ------------------
  |  Branch (92:11): [True: 40, False: 0]
  ------------------
   93|     40|        rv = pthread_cond_broadcast(&cv->cv);
   94|     40|        PR_ASSERT(0 == rv);
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
   95|     40|      } else {
   96|      0|        while (notified->cv[index].times-- > 0) {
  ------------------
  |  Branch (96:16): [True: 0, False: 0]
  ------------------
   97|      0|          rv = pthread_cond_signal(&cv->cv);
   98|      0|          PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   99|      0|        }
  100|      0|      }
  101|     40|#  if defined(DEBUG)
  102|     40|      pt_debug.cvars_notified += 1;
  103|     40|      if (0 > PR_ATOMIC_DECREMENT(&cv->notify_pending)) {
  ------------------
  |  |  123|     40|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (103:11): [True: 0, False: 40]
  ------------------
  104|      0|        pt_debug.delayed_cv_deletes += 1;
  105|      0|        PR_DestroyCondVar(cv);
  106|      0|      }
  107|       |#  else  /* defined(DEBUG) */
  108|       |      if (0 > PR_ATOMIC_DECREMENT(&cv->notify_pending)) {
  109|       |        PR_DestroyCondVar(cv);
  110|       |      }
  111|       |#  endif /* defined(DEBUG) */
  112|     40|    }
  113|     40|    prev = notified;
  114|     40|    notified = notified->link;
  115|     40|    if (&post != prev) {
  ------------------
  |  Branch (115:9): [True: 0, False: 40]
  ------------------
  116|      0|      PR_DELETE(prev);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  117|      0|    }
  118|     40|  } while (NULL != notified);
  ------------------
  |  Branch (118:12): [True: 0, False: 40]
  ------------------
  119|     40|} /* pt_PostNotifies */
ptsynch.c:pt_PostNotifyToCvar:
  258|     40|static void pt_PostNotifyToCvar(PRCondVar* cvar, PRBool broadcast) {
  259|     40|  PRIntn index = 0;
  260|     40|  _PT_Notified* notified = &cvar->lock->notified;
  261|       |
  262|     40|  PR_ASSERT(PR_TRUE == cvar->lock->locked);
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
  263|     40|  PR_ASSERT(pthread_equal(cvar->lock->owner, pthread_self()));
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
  264|     40|  PR_ASSERT(_PT_PTHREAD_MUTEX_IS_LOCKED(cvar->lock->mutex));
  ------------------
  |  |  208|     40|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 40, False: 0]
  |  |  ------------------
  ------------------
  265|       |
  266|     40|  while (1) {
  ------------------
  |  Branch (266:10): [Folded - Ignored]
  ------------------
  267|     40|    for (index = 0; index < notified->length; ++index) {
  ------------------
  |  Branch (267:21): [True: 0, False: 40]
  ------------------
  268|      0|      if (notified->cv[index].cv == cvar) {
  ------------------
  |  Branch (268:11): [True: 0, False: 0]
  ------------------
  269|      0|        if (broadcast) {
  ------------------
  |  Branch (269:13): [True: 0, False: 0]
  ------------------
  270|      0|          notified->cv[index].times = -1;
  271|      0|        } else if (-1 != notified->cv[index].times) {
  ------------------
  |  Branch (271:20): [True: 0, False: 0]
  ------------------
  272|      0|          notified->cv[index].times += 1;
  273|      0|        }
  274|      0|        return; /* we're finished */
  275|      0|      }
  276|      0|    }
  277|       |    /* if not full, enter new CV in this array */
  278|     40|    if (notified->length < PT_CV_NOTIFIED_LENGTH) {
  ------------------
  |  |  122|     40|#define PT_CV_NOTIFIED_LENGTH 6
  ------------------
  |  Branch (278:9): [True: 40, False: 0]
  ------------------
  279|     40|      break;
  280|     40|    }
  281|       |
  282|       |    /* if there's no link, create an empty array and link it */
  283|      0|    if (NULL == notified->link) {
  ------------------
  |  Branch (283:9): [True: 0, False: 0]
  ------------------
  284|      0|      notified->link = PR_NEWZAP(_PT_Notified);
  ------------------
  |  |   99|      0|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  285|      0|    }
  286|      0|    notified = notified->link;
  287|      0|  }
  288|       |
  289|       |  /* A brand new entry in the array */
  290|     40|  (void)PR_ATOMIC_INCREMENT(&cvar->notify_pending);
  ------------------
  |  |  122|     40|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  291|     40|  notified->cv[index].times = (broadcast) ? -1 : 1;
  ------------------
  |  Branch (291:31): [True: 40, False: 0]
  ------------------
  292|     40|  notified->cv[index].cv = cvar;
  293|     40|  notified->length += 1;
  294|     40|} /* pt_PostNotifyToCvar */

PR_GetCurrentThread:
  581|  4.39M|PR_IMPLEMENT(PRThread*) PR_GetCurrentThread(void) {
  582|  4.39M|  void* thred;
  583|       |
  584|  4.39M|  if (!_pr_initialized) {
  ------------------
  |  Branch (584:7): [True: 0, False: 4.39M]
  ------------------
  585|      0|    _PR_ImplicitInitialization();
  586|      0|  }
  587|       |
  588|  4.39M|  _PT_PTHREAD_GETSPECIFIC(pt_book.key, thred);
  ------------------
  |  |   84|  4.39M|#define _PT_PTHREAD_GETSPECIFIC(k, r)    (r) = pthread_getspecific(k)
  ------------------
  589|  4.39M|  if (NULL == thred) {
  ------------------
  |  Branch (589:7): [True: 0, False: 4.39M]
  ------------------
  590|      0|    thred = pt_AttachThread();
  591|      0|  }
  592|  4.39M|  PR_ASSERT(NULL != thred);
  ------------------
  |  |  208|  4.39M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 4.39M, False: 0]
  |  |  ------------------
  ------------------
  593|  4.39M|  return (PRThread*)thred;
  594|  4.39M|} /* PR_GetCurrentThread */
PR_Sleep:
  738|    633|PR_IMPLEMENT(PRStatus) PR_Sleep(PRIntervalTime ticks) {
  739|    633|  PRStatus rv = PR_SUCCESS;
  740|       |
  741|    633|  if (!_pr_initialized) {
  ------------------
  |  Branch (741:7): [True: 0, False: 633]
  ------------------
  742|      0|    _PR_ImplicitInitialization();
  743|      0|  }
  744|       |
  745|    633|  if (PR_INTERVAL_NO_WAIT == ticks) {
  ------------------
  |  |   53|    633|#define PR_INTERVAL_NO_WAIT 0UL
  ------------------
  |  Branch (745:7): [True: 633, False: 0]
  ------------------
  746|    633|    _PT_PTHREAD_YIELD();
  ------------------
  |  |  157|    633|#define _PT_PTHREAD_YIELD()             sched_yield()
  ------------------
  747|    633|  } else {
  748|      0|    PRCondVar* cv;
  749|      0|    PRIntervalTime timein;
  750|       |
  751|      0|    timein = PR_IntervalNow();
  752|      0|    cv = PR_NewCondVar(_pr_sleeplock);
  753|      0|    PR_ASSERT(cv != NULL);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  754|      0|    PR_Lock(_pr_sleeplock);
  755|      0|    do {
  756|      0|      PRIntervalTime now = PR_IntervalNow();
  757|      0|      PRIntervalTime delta = now - timein;
  758|      0|      if (delta > ticks) {
  ------------------
  |  Branch (758:11): [True: 0, False: 0]
  ------------------
  759|      0|        break;
  760|      0|      }
  761|      0|      rv = PR_WaitCondVar(cv, ticks - delta);
  762|      0|    } while (PR_SUCCESS == rv);
  ------------------
  |  Branch (762:14): [True: 0, False: 0]
  ------------------
  763|      0|    PR_Unlock(_pr_sleeplock);
  764|      0|    PR_DestroyCondVar(cv);
  765|      0|  }
  766|      0|  return rv;
  767|    633|} /* PR_Sleep */
_PR_InitThreads:
  835|      1|                     PRUintn maxPTDs) {
  836|      1|  int rv;
  837|      1|  PRThread* thred;
  838|       |
  839|      1|  PR_ASSERT(priority == PR_PRIORITY_NORMAL);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  840|       |
  841|       |#  ifdef _PR_NEED_PTHREAD_INIT
  842|       |  /*
  843|       |   * On BSD/OS (3.1 and 4.0), the pthread subsystem is lazily
  844|       |   * initialized, but pthread_self() fails to initialize
  845|       |   * pthreads and hence returns a null thread ID if invoked
  846|       |   * by the primordial thread before any other pthread call.
  847|       |   * So we explicitly initialize pthreads here.
  848|       |   */
  849|       |  pthread_init();
  850|       |#  endif
  851|       |
  852|       |#  if _POSIX_THREAD_PRIORITY_SCHEDULING > 0
  853|       |#    if defined(FREEBSD)
  854|       |  {
  855|       |    pthread_attr_t attr;
  856|       |    int policy;
  857|       |    /* get the min and max priorities of the default policy */
  858|       |    pthread_attr_init(&attr);
  859|       |    pthread_attr_setinheritsched(&attr, PTHREAD_EXPLICIT_SCHED);
  860|       |    pthread_attr_getschedpolicy(&attr, &policy);
  861|       |    pt_book.minPrio = sched_get_priority_min(policy);
  862|       |    PR_ASSERT(-1 != pt_book.minPrio);
  863|       |    pt_book.maxPrio = sched_get_priority_max(policy);
  864|       |    PR_ASSERT(-1 != pt_book.maxPrio);
  865|       |    pthread_attr_destroy(&attr);
  866|       |  }
  867|       |#    else
  868|       |  /*
  869|       |  ** These might be function evaluations
  870|       |  */
  871|       |  pt_book.minPrio = PT_PRIO_MIN;
  872|       |  pt_book.maxPrio = PT_PRIO_MAX;
  873|       |#    endif
  874|       |#  endif
  875|       |
  876|      1|  PR_ASSERT(NULL == pt_book.ml);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  877|      1|  pt_book.ml = PR_NewLock();
  878|      1|  PR_ASSERT(NULL != pt_book.ml);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  879|      1|  pt_book.cv = PR_NewCondVar(pt_book.ml);
  880|      1|  PR_ASSERT(NULL != pt_book.cv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  881|      1|  thred = PR_NEWZAP(PRThread);
  ------------------
  |  |   99|      1|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  882|      1|  PR_ASSERT(NULL != thred);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  883|      1|  thred->arg = NULL;
  884|      1|  thred->startFunc = NULL;
  885|      1|  thred->priority = priority;
  886|      1|  thred->id = pthread_self();
  887|      1|  thred->idSet = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  888|      1|#  ifdef _PR_NICE_PRIORITY_SCHEDULING
  889|      1|  thred->tid = gettid();
  890|      1|#  endif
  891|       |
  892|      1|  thred->state = (PT_THREAD_DETACHED | PT_THREAD_PRIMORD);
  ------------------
  |  |  138|      1|#define PT_THREAD_DETACHED  0x01    /* thread can't be joined */
  ------------------
                thred->state = (PT_THREAD_DETACHED | PT_THREAD_PRIMORD);
  ------------------
  |  |  141|      1|#define PT_THREAD_PRIMORD   0x08    /* this is the primordial thread */
  ------------------
  893|      1|  if (PR_SYSTEM_THREAD == type) {
  ------------------
  |  Branch (893:7): [True: 0, False: 1]
  ------------------
  894|      0|    thred->state |= PT_THREAD_SYSTEM;
  ------------------
  |  |  140|      0|#define PT_THREAD_SYSTEM    0x04    /* system (not user) thread */
  ------------------
  895|      0|    pt_book.system += 1;
  896|      0|    pt_book.this_many = 0;
  897|      1|  } else {
  898|      1|    pt_book.user += 1;
  899|      1|    pt_book.this_many = 1;
  900|      1|  }
  901|      1|  thred->next = thred->prev = NULL;
  902|      1|  pt_book.first = pt_book.last = thred;
  903|       |
  904|      1|  thred->stack = PR_NEWZAP(PRThreadStack);
  ------------------
  |  |   99|      1|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  905|      1|  PR_ASSERT(thred->stack != NULL);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  906|      1|  thred->stack->stackSize = 0;
  907|      1|  thred->stack->thr = thred;
  908|      1|  _PR_InitializeStack(thred->stack);
  909|       |
  910|       |  /*
  911|       |   * Create a key for our use to store a backpointer in the pthread
  912|       |   * to our PRThread object. This object gets deleted when the thread
  913|       |   * returns from its root in the case of a detached thread. Other
  914|       |   * threads delete the objects in Join.
  915|       |   *
  916|       |   * NB: The destructor logic seems to have a bug so it isn't used.
  917|       |   * NBB: Oh really? I'm going to give it a spin - AOF 19 June 1998.
  918|       |   * More info - the problem is that pthreads calls the destructor
  919|       |   * eagerly as the thread returns from its root, rather than lazily
  920|       |   * after the thread is joined. Therefore, threads that are joining
  921|       |   * and holding PRThread references are actually holding pointers to
  922|       |   * nothing.
  923|       |   */
  924|      1|  rv = _PT_PTHREAD_KEY_CREATE(&pt_book.key, _pt_thread_death);
  ------------------
  |  |   81|      1|#define _PT_PTHREAD_KEY_CREATE           pthread_key_create
  ------------------
  925|      1|  if (0 != rv) {
  ------------------
  |  Branch (925:7): [True: 0, False: 1]
  ------------------
  926|      0|    PR_Assert("0 == rv", __FILE__, __LINE__);
  927|      0|  }
  928|      1|  pt_book.keyCreated = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  929|      1|  rv = pthread_setspecific(pt_book.key, thred);
  930|      1|  PR_ASSERT(0 == rv);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  931|      1|} /* _PR_InitThreads */
ptthread.c:_PR_InitializeStack:
   99|      1|static void _PR_InitializeStack(PRThreadStack* ts) {
  100|      1|  if (ts && (ts->stackTop == 0)) {
  ------------------
  |  Branch (100:7): [True: 1, False: 0]
  |  Branch (100:13): [True: 1, False: 0]
  ------------------
  101|      1|    ts->allocBase = (char*)&ts;
  102|      1|    ts->allocSize = ts->stackSize;
  103|       |
  104|       |    /*
  105|       |    ** Setup stackTop and stackBottom values.
  106|       |    */
  107|       |#  ifdef HAVE_STACK_GROWING_UP
  108|       |    ts->stackBottom = ts->allocBase + ts->stackSize;
  109|       |    ts->stackTop = ts->allocBase;
  110|       |#  else
  111|      1|    ts->stackTop = ts->allocBase;
  112|      1|    ts->stackBottom = ts->allocBase - ts->stackSize;
  113|      1|#  endif
  114|      1|  }
  115|      1|}

_PR_InitCMon:
  308|      1|void _PR_InitCMon(void) {
  309|      1|  _PR_NEW_LOCK_MCACHE();
  ------------------
  |  |   30|      1|#    define _PR_NEW_LOCK_MCACHE() (_pr_mcacheLock = PR_NewLock())
  ------------------
  310|      1|  ExpandMonitorCache(3);
  311|      1|}
prcmon.c:ExpandMonitorCache:
   94|      1|static PRStatus ExpandMonitorCache(PRUintn new_size_log2) {
   95|      1|  MonitorCacheEntry **old_hash_buckets, *p;
   96|      1|  PRUintn i, entries, old_num_hash_buckets, added;
   97|      1|  MonitorCacheEntry** new_hash_buckets;
   98|      1|  MonitorCacheEntryBlock* new_block;
   99|       |
  100|      1|  entries = 1L << new_size_log2;
  101|       |
  102|       |  /*
  103|       |  ** Expand the monitor-cache-entry free list
  104|       |  */
  105|      1|  new_block = (MonitorCacheEntryBlock*)PR_CALLOC(
  ------------------
  |  |   88|      1|#define PR_CALLOC(_size) (PR_Calloc(1, (_size)))
  ------------------
  106|      1|      sizeof(MonitorCacheEntryBlock) +
  107|      1|      (entries - 1) * sizeof(MonitorCacheEntry));
  108|      1|  if (NULL == new_block) {
  ------------------
  |  Branch (108:7): [True: 0, False: 1]
  ------------------
  109|      0|    return PR_FAILURE;
  110|      0|  }
  111|       |
  112|       |  /*
  113|       |  ** Allocate system monitors for the new monitor cache entries. If we
  114|       |  ** run out of system monitors, break out of the loop.
  115|       |  */
  116|      9|  for (i = 0, p = new_block->entries; i < entries; i++, p++) {
  ------------------
  |  Branch (116:39): [True: 8, False: 1]
  ------------------
  117|      8|    p->mon = PR_NewMonitor();
  118|      8|    if (!p->mon) {
  ------------------
  |  Branch (118:9): [True: 0, False: 8]
  ------------------
  119|      0|      break;
  120|      0|    }
  121|      8|  }
  122|      1|  added = i;
  123|      1|  if (added != entries) {
  ------------------
  |  Branch (123:7): [True: 0, False: 1]
  ------------------
  124|      0|    MonitorCacheEntryBlock* realloc_block;
  125|       |
  126|      0|    if (added == 0) {
  ------------------
  |  Branch (126:9): [True: 0, False: 0]
  ------------------
  127|       |      /* Totally out of system monitors. Lossage abounds */
  128|      0|      PR_DELETE(new_block);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  129|      0|      return PR_FAILURE;
  130|      0|    }
  131|       |
  132|       |    /*
  133|       |    ** We were able to allocate some of the system monitors. Use
  134|       |    ** realloc to shrink down the new_block memory. If that fails,
  135|       |    ** carry on with the too-large new_block.
  136|       |    */
  137|      0|    realloc_block = (MonitorCacheEntryBlock*)PR_REALLOC(
  ------------------
  |  |   77|      0|#define PR_REALLOC(_ptr, _size) (PR_Realloc((_ptr), (_size)))
  ------------------
  138|      0|        new_block, sizeof(MonitorCacheEntryBlock) +
  139|      0|                       (added - 1) * sizeof(MonitorCacheEntry));
  140|      0|    if (realloc_block) {
  ------------------
  |  Branch (140:9): [True: 0, False: 0]
  ------------------
  141|      0|      new_block = realloc_block;
  142|      0|    }
  143|      0|  }
  144|       |
  145|       |  /*
  146|       |  ** Now that we have allocated all of the system monitors, build up
  147|       |  ** the new free list. We can just update the free_list because we own
  148|       |  ** the mcache-lock and we aren't calling anyone who might want to use
  149|       |  ** it.
  150|       |  */
  151|      8|  for (i = 0, p = new_block->entries; i < added - 1; i++, p++) {
  ------------------
  |  Branch (151:39): [True: 7, False: 1]
  ------------------
  152|      7|    p->next = p + 1;
  153|      7|  }
  154|      1|  p->next = free_entries;
  155|      1|  free_entries = new_block->entries;
  156|      1|  num_free_entries += added;
  157|      1|  new_block->next = mcache_blocks;
  158|      1|  mcache_blocks = new_block;
  159|       |
  160|       |  /* Try to expand the hash table */
  161|      1|  new_hash_buckets =
  162|      1|      (MonitorCacheEntry**)PR_CALLOC(entries * sizeof(MonitorCacheEntry*));
  ------------------
  |  |   88|      1|#define PR_CALLOC(_size) (PR_Calloc(1, (_size)))
  ------------------
  163|      1|  if (NULL == new_hash_buckets) {
  ------------------
  |  Branch (163:7): [True: 0, False: 1]
  ------------------
  164|       |    /*
  165|       |    ** Partial lossage. In this situation we don't get any more hash
  166|       |    ** buckets, which just means that the table lookups will take
  167|       |    ** longer. This is bad, but not fatal
  168|       |    */
  169|      0|    PR_LOG(_pr_cmon_lm, PR_LOG_WARNING,
  ------------------
  |  |  177|      0|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  178|      0|      if (PR_LOG_TEST(_module,_level)) { \
  |  |  ------------------
  |  |  |  |  167|      0|    ((_module)->level >= (_level))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (167:5): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  179|      0|      PR_LogPrint _args;         \
  |  |  180|      0|      }                     \
  |  |  181|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  170|      0|           ("unable to grow monitor cache hash buckets"));
  171|      0|    return PR_SUCCESS;
  172|      0|  }
  173|       |
  174|       |  /*
  175|       |  ** Compute new hash mask value. This value is used to mask an address
  176|       |  ** until it's bits are in the right spot for indexing into the hash
  177|       |  ** table.
  178|       |  */
  179|      1|  hash_mask = entries - 1;
  180|       |
  181|       |  /*
  182|       |  ** Expand the hash table. We have to rehash everything in the old
  183|       |  ** table into the new table.
  184|       |  */
  185|      1|  old_hash_buckets = hash_buckets;
  186|      1|  old_num_hash_buckets = num_hash_buckets;
  187|      1|  for (i = 0; i < old_num_hash_buckets; i++) {
  ------------------
  |  Branch (187:15): [True: 0, False: 1]
  ------------------
  188|      0|    p = old_hash_buckets[i];
  189|      0|    while (p) {
  ------------------
  |  Branch (189:12): [True: 0, False: 0]
  ------------------
  190|      0|      MonitorCacheEntry* next = p->next;
  191|       |
  192|       |      /* Hash based on new table size, and then put p in the new table */
  193|      0|      PRUintn hash = HASH(p->address);
  ------------------
  |  |   78|      0|  ((PRUint32)(((PRUptrdiff)(address) >> 2) ^ ((PRUptrdiff)(address) >> 10)) & \
  |  |   79|      0|   hash_mask)
  ------------------
  194|      0|      p->next = new_hash_buckets[hash];
  195|      0|      new_hash_buckets[hash] = p;
  196|       |
  197|      0|      p = next;
  198|      0|    }
  199|      0|  }
  200|       |
  201|       |  /*
  202|       |  ** Switch over to new hash table and THEN call free of the old
  203|       |  ** table. Since free might re-enter _pr_mcache_lock, things would
  204|       |  ** break terribly if it used the old hash table.
  205|       |  */
  206|      1|  hash_buckets = new_hash_buckets;
  207|      1|  num_hash_buckets = entries;
  208|      1|  num_hash_buckets_log2 = new_size_log2;
  209|      1|  PR_DELETE(old_hash_buckets);
  ------------------
  |  |  110|      1|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  210|       |
  211|      1|  PR_LOG(
  ------------------
  |  |  177|      1|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  178|      1|      if (PR_LOG_TEST(_module,_level)) { \
  |  |  ------------------
  |  |  |  |  167|      1|    ((_module)->level >= (_level))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (167:5): [True: 0, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  179|      0|      PR_LogPrint _args;         \
  |  |  180|      0|      }                     \
  |  |  181|      1|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  212|      1|      _pr_cmon_lm, PR_LOG_NOTICE,
  213|      1|      ("expanded monitor cache to %d (buckets %d)", num_free_entries, entries));
  214|       |
  215|      1|  return PR_SUCCESS;
  216|      1|} /* ExpandMonitorCache */

PR_NewRWLock:
   97|      1|PR_NewRWLock(PRUint32 lock_rank, const char* lock_name) {
   98|      1|  PRRWLock* rwlock;
   99|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  100|       |  int err;
  101|       |#endif
  102|       |
  103|      1|  if (!_pr_initialized) {
  ------------------
  |  Branch (103:7): [True: 0, False: 1]
  ------------------
  104|      0|    _PR_ImplicitInitialization();
  105|      0|  }
  106|       |
  107|      1|  rwlock = PR_NEWZAP(PRRWLock);
  ------------------
  |  |   99|      1|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
  108|      1|  if (rwlock == NULL) {
  ------------------
  |  Branch (108:7): [True: 0, False: 1]
  ------------------
  109|      0|    return NULL;
  110|      0|  }
  111|       |
  112|      1|  rwlock->rw_rank = lock_rank;
  113|      1|  if (lock_name != NULL) {
  ------------------
  |  Branch (113:7): [True: 0, False: 1]
  ------------------
  114|      0|    rwlock->rw_name = (char*)PR_Malloc(strlen(lock_name) + 1);
  115|      0|    if (rwlock->rw_name == NULL) {
  ------------------
  |  Branch (115:9): [True: 0, False: 0]
  ------------------
  116|      0|      PR_DELETE(rwlock);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  117|      0|      return (NULL);
  118|      0|    }
  119|      0|    strcpy(rwlock->rw_name, lock_name);
  120|      1|  } else {
  121|      1|    rwlock->rw_name = NULL;
  122|      1|  }
  123|       |
  124|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  125|       |  err = RWLOCK_INIT(&rwlock->rw_lock);
  126|       |  if (err != 0) {
  127|       |    PR_SetError(PR_UNKNOWN_ERROR, err);
  128|       |    PR_Free(rwlock->rw_name);
  129|       |    PR_DELETE(rwlock);
  130|       |    return NULL;
  131|       |  }
  132|       |  return rwlock;
  133|       |#else
  134|      1|  rwlock->rw_lock = PR_NewLock();
  135|      1|  if (rwlock->rw_lock == NULL) {
  ------------------
  |  Branch (135:7): [True: 0, False: 1]
  ------------------
  136|      0|    goto failed;
  137|      0|  }
  138|      1|  rwlock->rw_reader_waitq = PR_NewCondVar(rwlock->rw_lock);
  139|      1|  if (rwlock->rw_reader_waitq == NULL) {
  ------------------
  |  Branch (139:7): [True: 0, False: 1]
  ------------------
  140|      0|    goto failed;
  141|      0|  }
  142|      1|  rwlock->rw_writer_waitq = PR_NewCondVar(rwlock->rw_lock);
  143|      1|  if (rwlock->rw_writer_waitq == NULL) {
  ------------------
  |  Branch (143:7): [True: 0, False: 1]
  ------------------
  144|      0|    goto failed;
  145|      0|  }
  146|      1|  rwlock->rw_reader_cnt = 0;
  147|      1|  rwlock->rw_writer_cnt = 0;
  148|      1|  rwlock->rw_lock_cnt = 0;
  149|      1|  return rwlock;
  150|       |
  151|      0|failed:
  152|      0|  if (rwlock->rw_reader_waitq != NULL) {
  ------------------
  |  Branch (152:7): [True: 0, False: 0]
  ------------------
  153|      0|    PR_DestroyCondVar(rwlock->rw_reader_waitq);
  154|      0|  }
  155|      0|  if (rwlock->rw_lock != NULL) {
  ------------------
  |  Branch (155:7): [True: 0, False: 0]
  ------------------
  156|      0|    PR_DestroyLock(rwlock->rw_lock);
  157|      0|  }
  158|      0|  PR_Free(rwlock->rw_name);
  159|      0|  PR_DELETE(rwlock);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  160|      0|  return NULL;
  161|      1|#endif
  162|      1|}
PR_DestroyRWLock:
  168|      1|PR_DestroyRWLock(PRRWLock* rwlock) {
  169|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  170|       |  int err;
  171|       |  err = RWLOCK_DESTROY(&rwlock->rw_lock);
  172|       |  PR_ASSERT(err == 0);
  173|       |#else
  174|      1|  PR_ASSERT(rwlock->rw_reader_cnt == 0);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  175|      1|  PR_DestroyCondVar(rwlock->rw_reader_waitq);
  176|      1|  PR_DestroyCondVar(rwlock->rw_writer_waitq);
  177|      1|  PR_DestroyLock(rwlock->rw_lock);
  178|      1|#endif
  179|      1|  if (rwlock->rw_name != NULL) {
  ------------------
  |  Branch (179:7): [True: 0, False: 1]
  ------------------
  180|      0|    PR_Free(rwlock->rw_name);
  181|      0|  }
  182|      1|  PR_DELETE(rwlock);
  ------------------
  |  |  110|      1|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  183|      1|}
PR_RWLock_Rlock:
  189|      2|PR_RWLock_Rlock(PRRWLock* rwlock) {
  190|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  191|       |  int err;
  192|       |#endif
  193|       |
  194|      2|#ifdef _PR_RWLOCK_RANK_ORDER_DEBUG
  195|       |  /*
  196|       |   * assert that rank ordering is not violated; the rank of 'rwlock' should
  197|       |   * be equal to or greater than the highest rank of all the locks held by
  198|       |   * the thread.
  199|       |   */
  200|      2|  PR_ASSERT((rwlock->rw_rank == PR_RWLOCK_RANK_NONE) ||
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  201|      2|            (rwlock->rw_rank >= _PR_GET_THREAD_RWLOCK_RANK()));
  202|      2|#endif
  203|       |
  204|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  205|       |  err = RWLOCK_RDLOCK(&rwlock->rw_lock);
  206|       |  PR_ASSERT(err == 0);
  207|       |#else
  208|      2|  PR_Lock(rwlock->rw_lock);
  209|       |  /*
  210|       |   * wait if write-locked or if a writer is waiting; preference for writers
  211|       |   */
  212|      2|  while ((rwlock->rw_lock_cnt < 0) || (rwlock->rw_writer_cnt > 0)) {
  ------------------
  |  Branch (212:10): [True: 0, False: 2]
  |  Branch (212:39): [True: 0, False: 2]
  ------------------
  213|      0|    rwlock->rw_reader_cnt++;
  214|      0|    PR_WaitCondVar(rwlock->rw_reader_waitq, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |   54|      0|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
  215|      0|    rwlock->rw_reader_cnt--;
  216|      0|  }
  217|       |  /*
  218|       |   * Increment read-lock count
  219|       |   */
  220|      2|  rwlock->rw_lock_cnt++;
  221|       |
  222|      2|  PR_Unlock(rwlock->rw_lock);
  223|      2|#endif
  224|       |
  225|      2|#ifdef _PR_RWLOCK_RANK_ORDER_DEBUG
  226|       |  /*
  227|       |   * update thread's lock rank
  228|       |   */
  229|      2|  if (rwlock->rw_rank != PR_RWLOCK_RANK_NONE) {
  ------------------
  |  |   29|      2|#define PR_RWLOCK_RANK_NONE 0
  ------------------
  |  Branch (229:7): [True: 0, False: 2]
  ------------------
  230|      0|    _PR_SET_THREAD_RWLOCK_RANK(rwlock);
  231|      0|  }
  232|      2|#endif
  233|      2|}
PR_RWLock_Wlock:
  239|      1|PR_RWLock_Wlock(PRRWLock* rwlock) {
  240|      1|#if defined(DEBUG)
  241|      1|  PRThread* me = PR_GetCurrentThread();
  242|      1|#endif
  243|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  244|       |  int err;
  245|       |#endif
  246|       |
  247|      1|#ifdef _PR_RWLOCK_RANK_ORDER_DEBUG
  248|       |  /*
  249|       |   * assert that rank ordering is not violated; the rank of 'rwlock' should
  250|       |   * be equal to or greater than the highest rank of all the locks held by
  251|       |   * the thread.
  252|       |   */
  253|      1|  PR_ASSERT((rwlock->rw_rank == PR_RWLOCK_RANK_NONE) ||
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  254|      1|            (rwlock->rw_rank >= _PR_GET_THREAD_RWLOCK_RANK()));
  255|      1|#endif
  256|       |
  257|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  258|       |  err = RWLOCK_WRLOCK(&rwlock->rw_lock);
  259|       |  PR_ASSERT(err == 0);
  260|       |#else
  261|      1|  PR_Lock(rwlock->rw_lock);
  262|       |  /*
  263|       |   * wait if read locked
  264|       |   */
  265|      1|  while (rwlock->rw_lock_cnt != 0) {
  ------------------
  |  Branch (265:10): [True: 0, False: 1]
  ------------------
  266|      0|    rwlock->rw_writer_cnt++;
  267|      0|    PR_WaitCondVar(rwlock->rw_writer_waitq, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |   54|      0|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
  268|      0|    rwlock->rw_writer_cnt--;
  269|      0|  }
  270|       |  /*
  271|       |   * apply write lock
  272|       |   */
  273|      1|  rwlock->rw_lock_cnt--;
  274|      1|  PR_ASSERT(rwlock->rw_lock_cnt == -1);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  275|      1|#  ifdef DEBUG
  276|      1|  PR_ASSERT(me != NULL);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  277|      1|  rwlock->rw_owner = me;
  278|      1|#  endif
  279|      1|  PR_Unlock(rwlock->rw_lock);
  280|      1|#endif
  281|       |
  282|      1|#ifdef _PR_RWLOCK_RANK_ORDER_DEBUG
  283|       |  /*
  284|       |   * update thread's lock rank
  285|       |   */
  286|      1|  if (rwlock->rw_rank != PR_RWLOCK_RANK_NONE) {
  ------------------
  |  |   29|      1|#define PR_RWLOCK_RANK_NONE 0
  ------------------
  |  Branch (286:7): [True: 0, False: 1]
  ------------------
  287|      0|    _PR_SET_THREAD_RWLOCK_RANK(rwlock);
  288|      0|  }
  289|      1|#endif
  290|      1|}
PR_RWLock_Unlock:
  296|      3|PR_RWLock_Unlock(PRRWLock* rwlock) {
  297|      3|#if defined(DEBUG)
  298|      3|  PRThread* me = PR_GetCurrentThread();
  299|      3|#endif
  300|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  301|       |  int err;
  302|       |#endif
  303|       |
  304|       |#if defined(HAVE_UNIX98_RWLOCK) || defined(HAVE_UI_RWLOCK)
  305|       |  err = RWLOCK_UNLOCK(&rwlock->rw_lock);
  306|       |  PR_ASSERT(err == 0);
  307|       |#else
  308|      3|  PR_Lock(rwlock->rw_lock);
  309|       |  /*
  310|       |   * lock must be read or write-locked
  311|       |   */
  312|      3|  PR_ASSERT(rwlock->rw_lock_cnt != 0);
  ------------------
  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  ------------------
  ------------------
  313|      3|  if (rwlock->rw_lock_cnt > 0) {
  ------------------
  |  Branch (313:7): [True: 2, False: 1]
  ------------------
  314|       |    /*
  315|       |     * decrement read-lock count
  316|       |     */
  317|      2|    rwlock->rw_lock_cnt--;
  318|      2|    if (rwlock->rw_lock_cnt == 0) {
  ------------------
  |  Branch (318:9): [True: 2, False: 0]
  ------------------
  319|       |      /*
  320|       |       * lock is not read-locked anymore; wakeup a waiting writer
  321|       |       */
  322|      2|      if (rwlock->rw_writer_cnt > 0) {
  ------------------
  |  Branch (322:11): [True: 0, False: 2]
  ------------------
  323|      0|        PR_NotifyCondVar(rwlock->rw_writer_waitq);
  324|      0|      }
  325|      2|    }
  326|      2|  } else {
  327|      1|    PR_ASSERT(rwlock->rw_lock_cnt == -1);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  328|       |
  329|      1|    rwlock->rw_lock_cnt = 0;
  330|      1|#  ifdef DEBUG
  331|      1|    PR_ASSERT(rwlock->rw_owner == me);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  332|      1|    rwlock->rw_owner = NULL;
  333|      1|#  endif
  334|       |    /*
  335|       |     * wakeup a writer, if present; preference for writers
  336|       |     */
  337|      1|    if (rwlock->rw_writer_cnt > 0) {
  ------------------
  |  Branch (337:9): [True: 0, False: 1]
  ------------------
  338|      0|      PR_NotifyCondVar(rwlock->rw_writer_waitq);
  339|      0|    }
  340|       |    /*
  341|       |     * else, wakeup all readers, if any
  342|       |     */
  343|      1|    else if (rwlock->rw_reader_cnt > 0) {
  ------------------
  |  Branch (343:14): [True: 0, False: 1]
  ------------------
  344|      0|      PR_NotifyAllCondVar(rwlock->rw_reader_waitq);
  345|      0|    }
  346|      1|  }
  347|      3|  PR_Unlock(rwlock->rw_lock);
  348|      3|#endif
  349|       |
  350|      3|#ifdef _PR_RWLOCK_RANK_ORDER_DEBUG
  351|       |  /*
  352|       |   * update thread's lock rank
  353|       |   */
  354|      3|  if (rwlock->rw_rank != PR_RWLOCK_RANK_NONE) {
  ------------------
  |  |   29|      3|#define PR_RWLOCK_RANK_NONE 0
  ------------------
  |  Branch (354:7): [True: 0, False: 3]
  ------------------
  355|      0|    _PR_UNSET_THREAD_RWLOCK_RANK(rwlock);
  356|      0|  }
  357|      3|#endif
  358|      3|  return;
  359|      3|}
_PR_InitRWLocks:
  367|      1|void _PR_InitRWLocks(void) {
  368|       |  /*
  369|       |   * allocated thread-private-data index for rwlock list
  370|       |   */
  371|      1|  if (PR_NewThreadPrivateIndex(&pr_thread_rwlock_key, _PR_RELEASE_LOCK_STACK) ==
  ------------------
  |  Branch (371:7): [True: 0, False: 1]
  ------------------
  372|      1|      PR_FAILURE) {
  373|      0|    pr_thread_rwlock_alloc_failed = 1;
  374|      0|    return;
  375|      0|  }
  376|      1|}

_PR_InitTPD:
   60|      1|void _PR_InitTPD(void) {
   61|      1|  _pr_tpd_destructors = (PRThreadPrivateDTOR*)PR_CALLOC(
  ------------------
  |  |   88|      1|#define PR_CALLOC(_size) (PR_Calloc(1, (_size)))
  ------------------
   62|      1|      _PR_TPD_LIMIT * sizeof(PRThreadPrivateDTOR*));
   63|      1|  PR_ASSERT(NULL != _pr_tpd_destructors);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
   64|      1|  _pr_tpd_length = _PR_TPD_LIMIT;
  ------------------
  |  |   49|      1|#define _PR_TPD_LIMIT 128             /* arbitary limit on the TPD slots */
  ------------------
   65|      1|}
PR_NewThreadPrivateIndex:
   93|      2|PR_NewThreadPrivateIndex(PRUintn* newIndex, PRThreadPrivateDTOR dtor) {
   94|      2|  PRStatus rv;
   95|      2|  PRInt32 index;
   96|       |
   97|      2|  if (!_pr_initialized) {
  ------------------
  |  Branch (97:7): [True: 0, False: 2]
  ------------------
   98|      0|    _PR_ImplicitInitialization();
   99|      0|  }
  100|       |
  101|      2|  PR_ASSERT(NULL != newIndex);
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  102|      2|  PR_ASSERT(NULL != _pr_tpd_destructors);
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  103|       |
  104|      2|  index = PR_ATOMIC_INCREMENT(&_pr_tpd_highwater) - 1; /* allocate index */
  ------------------
  |  |  122|      2|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  105|      2|  if (_PR_TPD_LIMIT <= index) {
  ------------------
  |  |   49|      2|#define _PR_TPD_LIMIT 128             /* arbitary limit on the TPD slots */
  ------------------
  |  Branch (105:7): [True: 0, False: 2]
  ------------------
  106|      0|    PR_SetError(PR_TPD_RANGE_ERROR, 0);
  ------------------
  |  |  100|      0|#define PR_TPD_RANGE_ERROR                       (-5972L)
  ------------------
  107|      0|    rv = PR_FAILURE; /* that's just wrong */
  108|      2|  } else {
  109|      2|    _pr_tpd_destructors[index] = dtor; /* record destructor @index */
  110|      2|    *newIndex = (PRUintn)index;        /* copy into client's location */
  111|      2|    rv = PR_SUCCESS;                   /* that's okay */
  112|      2|  }
  113|       |
  114|      2|  return rv;
  115|      2|}
PR_SetThreadPrivate:
  131|      2|PR_IMPLEMENT(PRStatus) PR_SetThreadPrivate(PRUintn index, void* priv) {
  132|      2|  PRThread* self = PR_GetCurrentThread();
  133|       |
  134|       |  /*
  135|       |  ** To improve performance, we don't check if the index has been
  136|       |  ** allocated.
  137|       |  */
  138|      2|  if (index >= _PR_TPD_LIMIT) {
  ------------------
  |  |   49|      2|#define _PR_TPD_LIMIT 128             /* arbitary limit on the TPD slots */
  ------------------
  |  Branch (138:7): [True: 0, False: 2]
  ------------------
  139|      0|    PR_SetError(PR_TPD_RANGE_ERROR, 0);
  ------------------
  |  |  100|      0|#define PR_TPD_RANGE_ERROR                       (-5972L)
  ------------------
  140|      0|    return PR_FAILURE;
  141|      0|  }
  142|       |
  143|      2|  PR_ASSERT(((NULL == self->privateData) && (0 == self->tpdLength)) ||
  ------------------
  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 1, False: 1]
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  144|      2|            ((NULL != self->privateData) && (0 != self->tpdLength)));
  145|       |
  146|       |  /*
  147|       |  ** If this thread does not have a sufficient vector for the index
  148|       |  ** being set, go ahead and extend this vector now.
  149|       |  */
  150|      2|  if ((NULL == self->privateData) || (self->tpdLength <= index)) {
  ------------------
  |  Branch (150:7): [True: 1, False: 1]
  |  Branch (150:38): [True: 0, False: 1]
  ------------------
  151|      1|    void* extension = PR_CALLOC(_pr_tpd_length * sizeof(void*));
  ------------------
  |  |   88|      1|#define PR_CALLOC(_size) (PR_Calloc(1, (_size)))
  ------------------
  152|      1|    if (NULL == extension) {
  ------------------
  |  Branch (152:9): [True: 0, False: 1]
  ------------------
  153|      0|      PR_SetError(PR_OUT_OF_MEMORY_ERROR, 0);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  154|      0|      return PR_FAILURE;
  155|      0|    }
  156|      1|    if (self->privateData) {
  ------------------
  |  Branch (156:9): [True: 0, False: 1]
  ------------------
  157|      0|      (void)memcpy(extension, self->privateData,
  158|      0|                   self->tpdLength * sizeof(void*));
  159|      0|      PR_DELETE(self->privateData);
  ------------------
  |  |  110|      0|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  160|      0|    }
  161|      1|    self->tpdLength = _pr_tpd_length;
  162|      1|    self->privateData = (void**)extension;
  163|      1|  }
  164|       |  /*
  165|       |  ** There wasn't much chance of having to call the destructor
  166|       |  ** unless the slot already existed.
  167|       |  */
  168|      1|  else if (self->privateData[index] && _pr_tpd_destructors[index]) {
  ------------------
  |  Branch (168:12): [True: 1, False: 0]
  |  Branch (168:40): [True: 1, False: 0]
  ------------------
  169|      1|    void* data = self->privateData[index];
  170|      1|    self->privateData[index] = NULL;
  171|      1|    (*_pr_tpd_destructors[index])(data);
  172|      1|  }
  173|       |
  174|      2|  PR_ASSERT(index < self->tpdLength);
  ------------------
  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  ------------------
  ------------------
  175|      2|  self->privateData[index] = priv;
  176|       |
  177|      2|  return PR_SUCCESS;
  178|      2|}
PR_GetThreadPrivate:
  189|  27.2k|PR_IMPLEMENT(void*) PR_GetThreadPrivate(PRUintn index) {
  190|  27.2k|  PRThread* self = PR_GetCurrentThread();
  191|  27.2k|  void* tpd = ((NULL == self->privateData) || (index >= self->tpdLength))
  ------------------
  |  Branch (191:16): [True: 1, False: 27.2k]
  |  Branch (191:47): [True: 0, False: 27.2k]
  ------------------
  192|  27.2k|                  ? NULL
  193|  27.2k|                  : self->privateData[index];
  194|       |
  195|  27.2k|  return tpd;
  196|  27.2k|}

server_certs.cc:_ZL10toUcharPtrPKh:
    8|      4|static unsigned char* toUcharPtr(const uint8_t* v) {
    9|      4|  return const_cast<unsigned char*>(static_cast<const unsigned char*>(v));
   10|      4|}

_ZN19DummyIOLayerMethods8CreateFDEiPS_:
   20|  9.71k|                                               DummyIOLayerMethods *methods) {
   21|  9.71k|  ScopedPRFileDesc fd(PR_CreateIOLayerStub(id, &DummyMethodsForward));
   22|  9.71k|  assert(fd);
   23|  9.71k|  if (!fd) {
  ------------------
  |  Branch (23:7): [True: 0, False: 9.71k]
  ------------------
   24|      0|    return nullptr;
   25|      0|  }
   26|  9.71k|  fd->secret = reinterpret_cast<PRFilePrivate *>(methods);
   27|  9.71k|  return fd;
   28|  9.71k|}
_ZN19DummyIOLayerMethods5CloseEP10PRFileDesc:
   30|  9.71k|PRStatus DummyIOLayerMethods::Close(PRFileDesc *f) {
   31|  9.71k|  f->secret = nullptr;
   32|  9.71k|  f->dtor(f);
   33|  9.71k|  return PR_SUCCESS;
   34|  9.71k|}
_ZN19DummyIOLayerMethods8ShutdownEP10PRFileDesci:
  112|      7|PRStatus DummyIOLayerMethods::Shutdown(PRFileDesc *f, int32_t how) {
  113|      7|  return PR_SUCCESS;
  114|      7|}
_ZN19DummyIOLayerMethods4SendEP10PRFileDescPKviij:
  125|   410k|                                  PRIntervalTime to) {
  126|   410k|  return Write(f, buf, amount);
  127|   410k|}
_ZN19DummyIOLayerMethods11GetpeernameEP10PRFileDescP9PRNetAddr:
  168|  70.9k|PRStatus DummyIOLayerMethods::Getpeername(PRFileDesc *f, PRNetAddr *addr) {
  169|  70.9k|  addr->inet.family = PR_AF_INET;
  ------------------
  |  |   96|  70.9k|#define PR_AF_INET AF_INET
  ------------------
  170|  70.9k|  addr->inet.port = 0;
  171|  70.9k|  addr->inet.ip = 0;
  172|       |
  173|  70.9k|  return PR_SUCCESS;
  174|  70.9k|}
_ZN19DummyIOLayerMethods13GetsockoptionEP10PRFileDescP18PRSocketOptionData:
  182|   169k|                                            PRSocketOptionData *opt) {
  183|   169k|  switch (opt->option) {
  184|   169k|    case PR_SockOpt_Nonblocking:
  ------------------
  |  Branch (184:5): [True: 169k, False: 0]
  ------------------
  185|   169k|      opt->value.non_blocking = PR_TRUE;
  ------------------
  |  |  437|   169k|#define PR_TRUE 1
  ------------------
  186|   169k|      return PR_SUCCESS;
  187|      0|    default:
  ------------------
  |  Branch (187:5): [True: 0, False: 169k]
  ------------------
  188|      0|      UNIMPLEMENTED();
  ------------------
  |  |   14|      0|  std::cerr << "Unimplemented: " << __FUNCTION__ << std::endl; \
  |  |   15|      0|  assert(false);
  ------------------
  189|      0|      break;
  190|   169k|  }
  191|       |
  192|      0|  return PR_FAILURE;
  193|   169k|}
_ZN19DummyIOLayerMethods13SetsockoptionEP10PRFileDescPK18PRSocketOptionData:
  196|  2.62k|                                            const PRSocketOptionData *opt) {
  197|  2.62k|  switch (opt->option) {
  198|      0|    case PR_SockOpt_Nonblocking:
  ------------------
  |  Branch (198:5): [True: 0, False: 2.62k]
  ------------------
  199|      0|      return PR_SUCCESS;
  200|  2.62k|    case PR_SockOpt_NoDelay:
  ------------------
  |  Branch (200:5): [True: 2.62k, False: 0]
  ------------------
  201|  2.62k|      return PR_SUCCESS;
  202|      0|    default:
  ------------------
  |  Branch (202:5): [True: 0, False: 2.62k]
  ------------------
  203|      0|      UNIMPLEMENTED();
  ------------------
  |  |   14|      0|  std::cerr << "Unimplemented: " << __FUNCTION__ << std::endl; \
  |  |   15|      0|  assert(false);
  ------------------
  204|      0|      break;
  205|  2.62k|  }
  206|       |
  207|      0|  return PR_FAILURE;
  208|  2.62k|}

dummy_io_fwd.cc:_ZL10DummyCloseP10PRFileDesc:
   13|  9.71k|static PRStatus DummyClose(PRFileDesc *f) { return ToMethods(f)->Close(f); }
dummy_io_fwd.cc:_ZL9ToMethodsP10PRFileDesc:
    9|  1.82M|static DummyIOLayerMethods *ToMethods(PRFileDesc *f) {
   10|  1.82M|  return reinterpret_cast<DummyIOLayerMethods *>(f->secret);
   11|  1.82M|}
dummy_io_fwd.cc:_ZL13DummyShutdownP10PRFileDesci:
   72|      7|static PRStatus DummyShutdown(PRFileDesc *f, int32_t how) {
   73|      7|  return ToMethods(f)->Shutdown(f, how);
   74|      7|}
dummy_io_fwd.cc:_ZL9DummyRecvP10PRFileDescPviij:
   77|  1.16M|                         int32_t flags, PRIntervalTime to) {
   78|  1.16M|  return ToMethods(f)->Recv(f, buf, buflen, flags, to);
   79|  1.16M|}
dummy_io_fwd.cc:_ZL9DummySendP10PRFileDescPKviij:
   82|   410k|                         int32_t flags, PRIntervalTime to) {
   83|   410k|  return ToMethods(f)->Send(f, buf, amount, flags, to);
   84|   410k|}
dummy_io_fwd.cc:_ZL16DummyGetpeernameP10PRFileDescP9PRNetAddr:
  114|  70.9k|static PRStatus DummyGetpeername(PRFileDesc *f, PRNetAddr *addr) {
  115|  70.9k|  return ToMethods(f)->Getpeername(f, addr);
  116|  70.9k|}
dummy_io_fwd.cc:_ZL18DummyGetsockoptionP10PRFileDescP18PRSocketOptionData:
  122|   169k|static PRStatus DummyGetsockoption(PRFileDesc *f, PRSocketOptionData *opt) {
  123|   169k|  return ToMethods(f)->Getsockoption(f, opt);
  124|   169k|}
dummy_io_fwd.cc:_ZL18DummySetsockoptionP10PRFileDescPK18PRSocketOptionData:
  127|  2.62k|                                   const PRSocketOptionData *opt) {
  128|  2.62k|  return ToMethods(f)->Setsockoption(f, opt);
  129|  2.62k|}

_ZN17ScopedMaybeDeleteI10PRFileDescEclEPS0_:
   64|  9.71k|  void operator()(T* ptr) {
   65|  9.71k|    if (ptr) {
  ------------------
  |  Branch (65:9): [True: 9.71k, False: 0]
  ------------------
   66|  9.71k|      ScopedDelete del;
   67|  9.71k|      del(ptr);
   68|  9.71k|    }
   69|  9.71k|  }
_ZN12ScopedDeleteclEP10PRFileDesc:
   44|  9.71k|  void operator()(PRFileDesc* fd) { PR_Close(fd); }
_ZN12ScopedDeleteclEP18CERTCertificateStr:
   23|      2|  void operator()(CERTCertificate* cert) { CERT_DestroyCertificate(cert); }
_ZN12ScopedDeleteclEP15PK11SlotInfoStr:
   38|  4.72k|  void operator()(PK11SlotInfo* slot) { PK11_FreeSlot(slot); }
_ZN12ScopedDeleteclEP13PK11SymKeyStr:
   40|  4.72k|  void operator()(PK11SymKey* key) { PK11_FreeSymKey(key); }
_ZN12ScopedDeleteclEP19SECKEYPrivateKeyStr:
   51|      2|  void operator()(SECKEYPrivateKey* key) { SECKEY_DestroyPrivateKey(key); }
_ZN17ScopedMaybeDeleteI19SECKEYPrivateKeyStrEclEPS0_:
   64|      2|  void operator()(T* ptr) {
   65|      2|    if (ptr) {
  ------------------
  |  Branch (65:9): [True: 2, False: 0]
  ------------------
   66|      2|      ScopedDelete del;
   67|      2|      del(ptr);
   68|      2|    }
   69|      2|  }
_ZN17ScopedMaybeDeleteI18CERTCertificateStrEclEPS0_:
   64|      2|  void operator()(T* ptr) {
   65|      2|    if (ptr) {
  ------------------
  |  Branch (65:9): [True: 2, False: 0]
  ------------------
   66|      2|      ScopedDelete del;
   67|      2|      del(ptr);
   68|      2|    }
   69|      2|  }
_ZN17ScopedMaybeDeleteI15PK11SlotInfoStrEclEPS0_:
   64|  4.72k|  void operator()(T* ptr) {
   65|  4.72k|    if (ptr) {
  ------------------
  |  Branch (65:9): [True: 4.72k, False: 0]
  ------------------
   66|  4.72k|      ScopedDelete del;
   67|  4.72k|      del(ptr);
   68|  4.72k|    }
   69|  4.72k|  }
_ZN17ScopedMaybeDeleteI13PK11SymKeyStrEclEPS0_:
   64|  4.72k|  void operator()(T* ptr) {
   65|  4.72k|    if (ptr) {
  ------------------
  |  Branch (65:9): [True: 4.72k, False: 0]
  ------------------
   66|  4.72k|      ScopedDelete del;
   67|  4.72k|      del(ptr);
   68|  4.72k|    }
   69|  4.72k|  }

_ZN11NSSDatabaseC2Ev:
   15|      1|  NSSDatabase() { assert(NSS_NoDB_Init(nullptr) == SECSuccess); }
_ZN11NSSDatabaseD2Ev:
   16|      1|  ~NSSDatabase() { assert(NSS_Shutdown() == SECSuccess); }

_ZN9TlsCommon7FixTimeEP10PRFileDesc:
   21|  9.71k|void FixTime(PRFileDesc* fd) {
   22|  9.71k|  SECStatus rv = SSL_SetTimeFunc(fd, FixedTime, nullptr);
  ------------------
  |  |  892|  9.71k|    SSL_EXPERIMENTAL_API("SSL_SetTimeFunc",                              \
  |  |  ------------------
  |  |  |  |   22|  9.71k|    (SSL_GetExperimentalAPI(name)                                   \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (22:6): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   23|  9.71k|         ? ((SECStatus(*) arglist)SSL_GetExperimentalAPI(name))args \
  |  |  |  |   24|  9.71k|         : SECFailure)
  |  |  ------------------
  |  |  893|  9.71k|                         (PRFileDesc * _fd, SSLTimeFunc _f, void *_arg), \
  |  |  894|  9.71k|                         (fd, f, arg))
  ------------------
   23|  9.71k|  assert(rv == SECSuccess);
   24|  9.71k|}
_ZN9TlsCommon25EnableAllProtocolVersionsEv:
   26|  9.71k|void EnableAllProtocolVersions() {
   27|  9.71k|  SSLVersionRange supported;
   28|  9.71k|  SECStatus rv;
   29|       |
   30|       |  // Enable all supported versions for TCP.
   31|  9.71k|  rv = SSL_VersionRangeGetSupported(ssl_variant_stream, &supported);
   32|  9.71k|  assert(rv == SECSuccess);
   33|       |
   34|  9.71k|  rv = SSL_VersionRangeSetDefault(ssl_variant_stream, &supported);
   35|  9.71k|  assert(rv == SECSuccess);
   36|       |
   37|       |  // Enable all supported versions for UDP.
   38|  9.71k|  rv = SSL_VersionRangeGetSupported(ssl_variant_datagram, &supported);
   39|  9.71k|  assert(rv == SECSuccess);
   40|       |
   41|  9.71k|  rv = SSL_VersionRangeSetDefault(ssl_variant_datagram, &supported);
   42|  9.71k|  assert(rv == SECSuccess);
   43|  9.71k|}
_ZN9TlsCommon21EnableAllCipherSuitesEP10PRFileDesc:
   45|  9.71k|void EnableAllCipherSuites(PRFileDesc* fd) {
   46|   699k|  for (uint16_t i = 0; i < SSL_NumImplementedCiphers; ++i) {
  ------------------
  |  Branch (46:24): [True: 690k, False: 9.71k]
  ------------------
   47|   690k|    SECStatus rv = SSL_CipherPrefSet(fd, SSL_ImplementedCiphers[i], true);
   48|   690k|    assert(rv == SECSuccess);
   49|   690k|  }
   50|  9.71k|}
_ZN9TlsCommon11DoHandshakeEP10PRFileDescb:
   52|  9.71k|void DoHandshake(PRFileDesc* fd, bool isServer) {
   53|  9.71k|  SECStatus rv = SSL_ResetHandshake(fd, isServer);
   54|  9.71k|  assert(rv == SECSuccess);
   55|       |
   56|  9.71k|  do {
   57|  9.71k|    rv = SSL_ForceHandshake(fd);
   58|  9.71k|  } while (rv != SECSuccess && PR_GetError() == PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|  7.09k|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (58:12): [True: 7.09k, False: 2.62k]
  |  Branch (58:32): [True: 0, False: 7.09k]
  ------------------
   59|       |
   60|       |  // If the handshake succeeds, let's read some data from the server, if any.
   61|  9.71k|  if (rv == SECSuccess) {
  ------------------
  |  Branch (61:7): [True: 2.62k, False: 7.09k]
  ------------------
   62|  2.62k|    uint8_t block[1024];
   63|  2.62k|    int32_t nb;
   64|       |
   65|       |    // Read application data and echo it back.
   66|   159k|    while ((nb = PR_Read(fd, block, sizeof(block))) > 0) {
  ------------------
  |  Branch (66:12): [True: 156k, False: 2.62k]
  ------------------
   67|   156k|      PR_Write(fd, block, nb);
   68|   156k|    }
   69|  2.62k|  }
   70|  9.71k|}
common.cc:_ZL9FixedTimePv:
   16|  67.2k|static PRTime FixedTime(void*) { return 1234; }

_ZN9TlsServer25InstallServerCertificatesEP10PRFileDesc:
  290|      1|void InstallServerCertificates(PRFileDesc* fd) {
  291|       |  // ECDSA P-256 certificate.
  292|      1|  InstallServerCertificate(fd, kP256ServerCert, sizeof(kP256ServerCert),
  293|      1|                           kP256ServerKey, sizeof(kP256ServerKey));
  294|       |
  295|       |  // RSA-2048 certificate.
  296|      1|  InstallServerCertificate(fd, kRsaServerCert, sizeof(kRsaServerCert),
  297|      1|                           kRsaServerKey, sizeof(kRsaServerKey));
  298|       |
  299|       |  // TODO(mdauer): Install more different cerificate types.
  300|      1|}
server_certs.cc:_ZL24InstallServerCertificateP10PRFileDescPKhmS2_m:
  258|      2|                                     size_t keyLen) {
  259|      2|  ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
  260|      2|  assert(slot);
  261|       |
  262|      2|  SECItem certItem = {siBuffer, toUcharPtr(certData),
  263|      2|                      static_cast<unsigned int>(certLen)};
  264|      2|  SECItem pkcs8Item = {siBuffer, toUcharPtr(keyData),
  265|      2|                       static_cast<unsigned int>(keyLen)};
  266|       |
  267|       |  // Import the certificate.
  268|      2|  static CERTCertDBHandle* certDB = CERT_GetDefaultCertDB();
  269|      2|  ScopedCERTCertificate cert(
  270|      2|      CERT_NewTempCertificate(certDB, &certItem, nullptr, false, true));
  271|      2|  assert(cert);
  272|       |
  273|       |  // Import the private key.
  274|      2|  SECKEYPrivateKey* key = nullptr;
  275|      2|  SECStatus rv = PK11_ImportDERPrivateKeyInfoAndReturnKey(
  276|      2|      slot.get(), &pkcs8Item, nullptr, nullptr, false, false, KU_ALL, &key,
  ------------------
  |  |  571|      2|    (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  562|      2|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  |  |  ------------------
  |  |                   (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  563|      2|#define KU_NON_REPUDIATION (0x40)   /* bit 1 */
  |  |  ------------------
  |  |                   (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  564|      2|#define KU_KEY_ENCIPHERMENT (0x20)  /* bit 2 */
  |  |  ------------------
  |  |  572|      2|     KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  565|      2|#define KU_DATA_ENCIPHERMENT (0x10) /* bit 3 */
  |  |  ------------------
  |  |                    KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  566|      2|#define KU_KEY_AGREEMENT (0x08)     /* bit 4 */
  |  |  ------------------
  |  |                    KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  567|      2|#define KU_KEY_CERT_SIGN (0x04)     /* bit 5 */
  |  |  ------------------
  |  |  573|      2|     KU_CRL_SIGN | KU_ENCIPHER_ONLY)
  |  |  ------------------
  |  |  |  |  568|      2|#define KU_CRL_SIGN (0x02)          /* bit 6 */
  |  |  ------------------
  |  |                    KU_CRL_SIGN | KU_ENCIPHER_ONLY)
  |  |  ------------------
  |  |  |  |  569|      2|#define KU_ENCIPHER_ONLY (0x01)     /* bit 7 */
  |  |  ------------------
  ------------------
  277|      2|      nullptr);
  278|      2|  assert(rv == SECSuccess);
  279|       |
  280|       |  // Adopt the private key to ensure it's freed.
  281|      2|  ScopedSECKEYPrivateKey privKey(key);
  282|       |
  283|       |  // Configure server with the imported key and certificate.
  284|      2|  rv = SSL_ConfigServerCert(fd, cert.get(), privKey.get(), nullptr, 0);
  285|      2|  assert(rv == SECSuccess);
  286|      2|}

_ZN9TlsServer6ConfigC2EPKhm:
   46|  9.71k|Config::Config(const uint8_t* data, size_t len) {
   47|  9.71k|  union {
   48|  9.71k|    uint64_t bitmap;
   49|  9.71k|    struct {
   50|  9.71k|      uint32_t config;
   51|  9.71k|      uint16_t ssl_version_range_min;
   52|  9.71k|      uint16_t ssl_version_range_max;
   53|  9.71k|    };
   54|  9.71k|  };
   55|       |
   56|  31.3M|  for (size_t i = 0; i < len; i++) {
  ------------------
  |  Branch (56:22): [True: 31.3M, False: 9.71k]
  ------------------
   57|  31.3M|    bitmap ^= static_cast<uint64_t>(data[i]) << (8 * (i % 8));
   58|  31.3M|  }
   59|       |
   60|       |  // Map SSL version values to a valid range.
   61|  9.71k|  ssl_version_range_min =
   62|  9.71k|      SSL_VERSION_RANGE_MIN_VALID +
  ------------------
  |  |   18|  9.71k|#define SSL_VERSION_RANGE_MIN_VALID 0x0301
  ------------------
   63|  9.71k|      (ssl_version_range_min %
   64|  9.71k|       (1 + SSL_VERSION_RANGE_MAX_VALID - SSL_VERSION_RANGE_MIN_VALID));
  ------------------
  |  |   20|  9.71k|#define SSL_VERSION_RANGE_MAX_VALID 0x0304
  ------------------
                     (1 + SSL_VERSION_RANGE_MAX_VALID - SSL_VERSION_RANGE_MIN_VALID));
  ------------------
  |  |   18|  9.71k|#define SSL_VERSION_RANGE_MIN_VALID 0x0301
  ------------------
   65|  9.71k|  ssl_version_range_max =
   66|  9.71k|      ssl_version_range_min +
   67|  9.71k|      (ssl_version_range_max %
   68|  9.71k|       (1 + SSL_VERSION_RANGE_MAX_VALID - ssl_version_range_min));
  ------------------
  |  |   20|  9.71k|#define SSL_VERSION_RANGE_MAX_VALID 0x0304
  ------------------
   69|       |
   70|  9.71k|  config_ = config;
   71|  9.71k|  ssl_version_range_ = {
   72|  9.71k|      .min = ssl_version_range_min,
   73|  9.71k|      .max = ssl_version_range_max,
   74|  9.71k|  };
   75|  9.71k|}
_ZN9TlsServer6Config12SetCallbacksEP10PRFileDesc:
   77|  9.71k|void Config::SetCallbacks(PRFileDesc* fd) {
   78|  9.71k|  SECStatus rv = SSL_AuthCertificateHook(fd, AuthCertificateHook, this);
   79|  9.71k|  assert(rv == SECSuccess);
   80|       |
   81|  9.71k|  rv = SSL_SetCanFalseStartCallback(fd, CanFalseStartCallback, nullptr);
   82|  9.71k|  assert(rv == SECSuccess);
   83|  9.71k|}
_ZN9TlsServer6Config16SetSocketOptionsEP10PRFileDesc:
   85|  9.71k|void Config::SetSocketOptions(PRFileDesc* fd) {
   86|  9.71k|  SECStatus rv = SSL_OptionSet(fd, SSL_ENABLE_EXTENDED_MASTER_SECRET,
  ------------------
  |  |  195|  9.71k|#define SSL_ENABLE_EXTENDED_MASTER_SECRET 30
  ------------------
   87|  9.71k|                               this->EnableExtendedMasterSecret());
   88|  9.71k|  assert(rv == SECSuccess);
   89|       |
   90|  9.71k|  rv = SSL_OptionSet(fd, SSL_REQUEST_CERTIFICATE, this->RequestCertificate());
  ------------------
  |  |   71|  9.71k|#define SSL_REQUEST_CERTIFICATE 3 /* (off by default) */
  ------------------
   91|  9.71k|  assert(rv == SECSuccess);
   92|       |
   93|  9.71k|  rv = SSL_OptionSet(fd, SSL_REQUIRE_CERTIFICATE, this->RequireCertificate());
  ------------------
  |  |   87|  9.71k|#define SSL_REQUIRE_CERTIFICATE 10 /* (SSL_REQUIRE_FIRST_HANDSHAKE */
  ------------------
   94|  9.71k|  assert(rv == SECSuccess);
   95|       |
   96|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_DEFLATE, this->EnableDeflate());
  ------------------
  |  |  110|  9.71k|#define SSL_ENABLE_DEFLATE 19           /* (unsupported, deprecated, off) */
  ------------------
   97|  9.71k|  assert(rv == SECSuccess);
   98|       |
   99|  9.71k|  rv = SSL_OptionSet(fd, SSL_CBC_RANDOM_IV, this->EnableCbcRandomIv());
  ------------------
  |  |  158|  9.71k|#define SSL_CBC_RANDOM_IV 23
  ------------------
  100|  9.71k|  assert(rv == SECSuccess);
  101|       |
  102|  9.71k|  rv = SSL_OptionSet(fd, SSL_REQUIRE_SAFE_NEGOTIATION,
  ------------------
  |  |  112|  9.71k|#define SSL_REQUIRE_SAFE_NEGOTIATION 21 /* Peer must send Signaling       */
  ------------------
  103|  9.71k|                     this->RequireSafeNegotiation());
  104|  9.71k|  assert(rv == SECSuccess);
  105|       |
  106|  9.71k|  rv = SSL_OptionSet(fd, SSL_NO_CACHE, this->NoCache());
  ------------------
  |  |   85|  9.71k|#define SSL_NO_CACHE 9             /* don't use the session cache */
  ------------------
  107|  9.71k|  assert(rv == SECSuccess);
  108|       |
  109|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_GREASE, this->EnableGrease());
  ------------------
  |  |  374|  9.71k|#define SSL_ENABLE_GREASE 42
  ------------------
  110|  9.71k|  assert(rv == SECSuccess);
  111|       |
  112|  9.71k|  if (this->SetCertificateCompressionAlgorithm()) {
  ------------------
  |  Branch (112:7): [True: 4.93k, False: 4.78k]
  ------------------
  113|  4.93k|    rv = SSL_SetCertificateCompressionAlgorithm(fd, kCompressionAlg);
  ------------------
  |  | 1083|  4.93k|    SSL_EXPERIMENTAL_API("SSL_SetCertificateCompressionAlgorithm", \
  |  |  ------------------
  |  |  |  |   22|  4.93k|    (SSL_GetExperimentalAPI(name)                                   \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (22:6): [True: 4.93k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   23|  4.93k|         ? ((SECStatus(*) arglist)SSL_GetExperimentalAPI(name))args \
  |  |  |  |   24|  4.93k|         : SECFailure)
  |  |  ------------------
  |  | 1084|  4.93k|                         (PRFileDesc * _fd,                        \
  |  | 1085|  4.93k|                          SSLCertificateCompressionAlgorithm t),   \
  |  | 1086|  4.93k|                         (fd, t))
  ------------------
  114|  4.93k|    assert(rv == SECSuccess);
  115|  4.93k|  }
  116|       |
  117|  9.71k|  if (this->SetVersionRange()) {
  ------------------
  |  Branch (117:7): [True: 3.96k, False: 5.74k]
  ------------------
  118|  3.96k|    rv = SSL_VersionRangeSet(fd, &ssl_version_range_);
  119|  3.96k|    assert(rv == SECSuccess);
  120|  3.96k|  }
  121|       |
  122|  9.71k|  if (this->AddExternalPsk()) {
  ------------------
  |  Branch (122:7): [True: 4.72k, False: 4.99k]
  ------------------
  123|  4.72k|    ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
  124|  4.72k|    assert(slot);
  125|       |
  126|  4.72k|    ScopedPK11SymKey key(PK11_KeyGen(slot.get(), CKM_NSS_CHACHA20_POLY1305,
  ------------------
  |  |  243|  4.72k|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|  4.72k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  4.72k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  127|  4.72k|                                     nullptr, 32, nullptr));
  128|  4.72k|    assert(key);
  129|       |
  130|  4.72k|    rv = SSL_AddExternalPsk(fd, key.get(), kPskIdentity,
  ------------------
  |  | 1051|  4.72k|    SSL_EXPERIMENTAL_API("SSL_AddExternalPsk",                                 \
  |  |  ------------------
  |  |  |  |   22|  4.72k|    (SSL_GetExperimentalAPI(name)                                   \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (22:6): [True: 4.72k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   23|  4.72k|         ? ((SECStatus(*) arglist)SSL_GetExperimentalAPI(name))args \
  |  |  |  |   24|  4.72k|         : SECFailure)
  |  |  ------------------
  |  | 1052|  4.72k|                         (PRFileDesc * _fd, PK11SymKey * _psk,                 \
  |  | 1053|  4.72k|                          const PRUint8 *_identity, unsigned int _identityLen, \
  |  | 1054|  4.72k|                          SSLHashType _hash),                                  \
  |  | 1055|  4.72k|                         (fd, psk, identity, identityLen, hash))
  ------------------
  131|  4.72k|                            sizeof(kPskIdentity) - 1, this->PskHashType());
  132|  4.72k|    assert(rv == SECSuccess);
  133|  4.72k|  }
  134|       |
  135|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_0RTT_DATA, this->EnableZeroRtt());
  ------------------
  |  |  244|  9.71k|#define SSL_ENABLE_0RTT_DATA 33
  ------------------
  136|  9.71k|  assert(rv == SECSuccess);
  137|       |
  138|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_ALPN, this->EnableAlpn());
  ------------------
  |  |  174|  9.71k|#define SSL_ENABLE_ALPN 26
  ------------------
  139|  9.71k|  assert(rv == SECSuccess);
  140|       |
  141|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_FALLBACK_SCSV, this->EnableFallbackScsv());
  ------------------
  |  |  183|  9.71k|#define SSL_ENABLE_FALLBACK_SCSV 28 /* Send fallback SCSV in \
  ------------------
  142|  9.71k|  assert(rv == SECSuccess);
  143|       |
  144|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_SESSION_TICKETS,
  ------------------
  |  |  108|  9.71k|#define SSL_ENABLE_SESSION_TICKETS 18   /* Enable TLS SessionTicket       */
  ------------------
  145|  9.71k|                     this->EnableSessionTickets());
  146|  9.71k|  assert(rv == SECSuccess);
  147|       |
  148|  9.71k|  rv = SSL_OptionSet(fd, SSL_NO_LOCKS, this->NoLocks());
  ------------------
  |  |  107|  9.71k|#define SSL_NO_LOCKS 17                 /* Don't use locks for protection */
  ------------------
  149|  9.71k|  assert(rv == SECSuccess);
  150|       |
  151|  9.71k|  rv = SSL_EnableTls13BackendEch(fd, this->EnableTls13BackendEch());
  ------------------
  |  |  538|  9.71k|    SSL_EXPERIMENTAL_API("SSL_EnableTls13BackendEch", \
  |  |  ------------------
  |  |  |  |   22|  9.71k|    (SSL_GetExperimentalAPI(name)                                   \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (22:6): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   23|  9.71k|         ? ((SECStatus(*) arglist)SSL_GetExperimentalAPI(name))args \
  |  |  |  |   24|  9.71k|         : SECFailure)
  |  |  ------------------
  |  |  539|  9.71k|                         (PRFileDesc * _fd, PRBool _enabled), (fd, enabled))
  ------------------
  152|  9.71k|  assert(rv == SECSuccess);
  153|       |
  154|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_DELEGATED_CREDENTIALS,
  ------------------
  |  |  328|  9.71k|#define SSL_ENABLE_DELEGATED_CREDENTIALS 40
  ------------------
  155|  9.71k|                     this->EnableDelegatedCredentials());
  156|  9.71k|  assert(rv == SECSuccess);
  157|       |
  158|  9.71k|  rv = SSL_OptionSet(fd, SSL_ENABLE_DTLS_SHORT_HEADER,
  ------------------
  |  |  283|  9.71k|#define SSL_ENABLE_DTLS_SHORT_HEADER 36
  ------------------
  159|  9.71k|                     this->EnableDtlsShortHeader());
  160|  9.71k|  assert(rv == SECSuccess);
  161|       |
  162|  9.71k|#ifndef IS_DTLS_FUZZ
  163|  9.71k|  rv =
  164|  9.71k|      SSL_OptionSet(fd, SSL_ENABLE_RENEGOTIATION, SSL_RENEGOTIATE_UNRESTRICTED);
  ------------------
  |  |  111|  9.71k|#define SSL_ENABLE_RENEGOTIATION 20     /* Values below (default: never)  */
  ------------------
                    SSL_OptionSet(fd, SSL_ENABLE_RENEGOTIATION, SSL_RENEGOTIATE_UNRESTRICTED);
  ------------------
  |  |  714|  9.71k|#define SSL_RENEGOTIATE_UNRESTRICTED ((PRBool)1)
  ------------------
  165|  9.71k|  assert(rv == SECSuccess);
  166|  9.71k|#endif
  167|  9.71k|}
server_config.cc:_ZL19AuthCertificateHookPvP10PRFileDescii:
   27|  3.83k|                                     PRBool isServer) {
   28|  3.83k|  assert(isServer);
   29|  3.83k|  auto config = reinterpret_cast<TlsServer::Config*>(arg);
   30|  3.83k|  if (config->FailCertificateAuthentication()) return SECFailure;
  ------------------
  |  Branch (30:7): [True: 354, False: 3.47k]
  ------------------
   31|       |
   32|  3.47k|  return SECSuccess;
   33|  3.83k|}

_ZN9TlsServer6Config11PskHashTypeEv:
   31|  4.72k|  SSLHashType PskHashType() {
   32|  4.72k|    if (config_ % 2) return ssl_hash_sha256;
  ------------------
  |  Branch (32:9): [True: 2.44k, False: 2.27k]
  ------------------
   33|       |
   34|  2.27k|    return ssl_hash_sha384;
   35|  4.72k|  };
_ZN9TlsServer6Config26EnableExtendedMasterSecretEv:
   40|  9.71k|  bool EnableExtendedMasterSecret() { return config_ & (1 << 0); };
_ZN9TlsServer6Config18RequestCertificateEv:
   41|  9.71k|  bool RequestCertificate() { return config_ & (1 << 1); };
_ZN9TlsServer6Config18RequireCertificateEv:
   42|  9.71k|  bool RequireCertificate() { return config_ & (1 << 2); };
_ZN9TlsServer6Config13EnableDeflateEv:
   43|  9.71k|  bool EnableDeflate() { return config_ & (1 << 3); };
_ZN9TlsServer6Config17EnableCbcRandomIvEv:
   44|  9.71k|  bool EnableCbcRandomIv() { return config_ & (1 << 4); };
_ZN9TlsServer6Config22RequireSafeNegotiationEv:
   45|  9.71k|  bool RequireSafeNegotiation() { return config_ & (1 << 5); };
_ZN9TlsServer6Config7NoCacheEv:
   46|  9.71k|  bool NoCache() { return config_ & (1 << 6); };
_ZN9TlsServer6Config12EnableGreaseEv:
   47|  9.71k|  bool EnableGrease() { return config_ & (1 << 7); };
_ZN9TlsServer6Config34SetCertificateCompressionAlgorithmEv:
   48|  9.71k|  bool SetCertificateCompressionAlgorithm() { return config_ & (1 << 8); };
_ZN9TlsServer6Config15SetVersionRangeEv:
   49|  9.71k|  bool SetVersionRange() { return config_ & (1 << 9); };
_ZN9TlsServer6Config14AddExternalPskEv:
   50|  9.71k|  bool AddExternalPsk() { return config_ & (1 << 10); };
_ZN9TlsServer6Config13EnableZeroRttEv:
   51|  9.71k|  bool EnableZeroRtt() { return config_ & (1 << 11); };
_ZN9TlsServer6Config10EnableAlpnEv:
   52|  9.71k|  bool EnableAlpn() { return config_ & (1 << 12); };
_ZN9TlsServer6Config18EnableFallbackScsvEv:
   53|  9.71k|  bool EnableFallbackScsv() { return config_ & (1 << 13); };
_ZN9TlsServer6Config20EnableSessionTicketsEv:
   54|  9.71k|  bool EnableSessionTickets() { return config_ & (1 << 14); };
_ZN9TlsServer6Config7NoLocksEv:
   55|  9.71k|  bool NoLocks() { return config_ & (1 << 15); };
_ZN9TlsServer6Config29FailCertificateAuthenticationEv:
   56|  3.83k|  bool FailCertificateAuthentication() { return config_ & (1 << 16); }
_ZN9TlsServer6Config21EnableTls13BackendEchEv:
   57|  9.71k|  bool EnableTls13BackendEch() { return config_ & (1 << 17); }
_ZN9TlsServer6Config26EnableDelegatedCredentialsEv:
   58|  9.71k|  bool EnableDelegatedCredentials() { return config_ & (1 << 18); };
_ZN9TlsServer6Config21EnableDtlsShortHeaderEv:
   59|  9.71k|  bool EnableDtlsShortHeader() { return config_ & (1 << 19); };

_ZN9TlsSocket13DummyPrSocket4ReadEP10PRFileDescPvi:
   17|  1.16M|int32_t DummyPrSocket::Read(PRFileDesc *fd, void *data, int32_t len) {
   18|  1.16M|  assert(data && len > 0);
   19|       |
   20|  1.16M|  int32_t amount = std::min(len, static_cast<int32_t>(len_));
   21|  1.16M|  memcpy(data, buf_, amount);
   22|       |
   23|  1.16M|  buf_ += amount;
   24|  1.16M|  len_ -= amount;
   25|       |
   26|  1.16M|  return amount;
   27|  1.16M|}
_ZN9TlsSocket13DummyPrSocket5WriteEP10PRFileDescPKvi:
   29|   410k|int32_t DummyPrSocket::Write(PRFileDesc *fd, const void *buf, int32_t length) {
   30|   410k|  return length;
   31|   410k|}
_ZN9TlsSocket13DummyPrSocket4RecvEP10PRFileDescPviij:
   34|  1.16M|                            int32_t flags, PRIntervalTime to) {
   35|  1.16M|  assert(flags == 0);
   36|  1.16M|  return Read(fd, buf, buflen);
   37|  1.16M|}

_ZN9TlsSocket13DummyPrSocketC2EPKhm:
   18|  9.71k|  DummyPrSocket(const uint8_t *buf, size_t len) : buf_(buf), len_(len) {}

LLVMFuzzerTestOneInput:
   48|  9.71k|extern "C" int LLVMFuzzerTestOneInput(const uint8_t* data, size_t size) {
   49|  9.71k|  static NSSDatabase db = NSSDatabase();
   50|  9.71k|  static SSLServerSessionCache cache = SSLServerSessionCache();
   51|  9.71k|  static PRDescIdentity id = PR_GetUniqueIdentity("fuzz-server");
   52|       |
   53|       |  // Create model socket.
   54|  9.71k|  static ScopedPRFileDesc model(ImportFD(nullptr, PR_NewTCPSocket()));
  ------------------
  |  |   25|  9.71k|#define ImportFD SSL_ImportFD
  ------------------
   55|  9.71k|  assert(model);
   56|       |
   57|       |  // Initialize the model socket once.
   58|  9.71k|  static PRCallOnceType initModelOnce;
   59|  9.71k|  PR_CallOnceWithArg(&initModelOnce, InitModelSocket, model.get());
   60|       |
   61|       |  // Create and import dummy socket.
   62|  9.71k|  TlsSocket::DummyPrSocket socket = TlsSocket::DummyPrSocket(data, size);
   63|  9.71k|  ScopedPRFileDesc prFd(DummyIOLayerMethods::CreateFD(id, &socket));
   64|  9.71k|  PRFileDesc* sslFd = ImportFD(model.get(), prFd.get());
  ------------------
  |  |   25|  9.71k|#define ImportFD SSL_ImportFD
  ------------------
   65|  9.71k|  assert(sslFd == prFd.get());
   66|       |
   67|       |  // Derive server config from input data.
   68|  9.71k|  TlsServer::Config config = TlsServer::Config(data, size);
   69|       |
   70|  9.71k|  if (ssl_trace >= 90) {
  ------------------
  |  Branch (70:7): [True: 0, False: 9.71k]
  ------------------
   71|      0|    std::cerr << config << "\n";
   72|      0|  }
   73|       |
   74|       |  // Keeping things determinstic.
   75|  9.71k|  assert(RNG_RandomUpdate(NULL, 0) == SECSuccess);
   76|  9.71k|  assert(SSL_SetURL(sslFd, "fuzz.server") == SECSuccess);
   77|       |
   78|  9.71k|  TlsCommon::EnableAllProtocolVersions();
   79|  9.71k|  TlsCommon::EnableAllCipherSuites(sslFd);
   80|  9.71k|  TlsCommon::FixTime(sslFd);
   81|       |
   82|       |  // Set socket options from server config.
   83|  9.71k|  config.SetCallbacks(sslFd);
   84|  9.71k|  config.SetSocketOptions(sslFd);
   85|       |
   86|       |  // Perform the acutal handshake.
   87|  9.71k|  TlsCommon::DoHandshake(sslFd, true);
   88|       |
   89|       |  // Clear the cache. We never want to resume as we couldn't reproduce that.
   90|  9.71k|  SSL_ClearSessionCache();
   91|       |
   92|  9.71k|  return 0;
   93|  9.71k|}
_ZN21SSLServerSessionCacheC2Ev:
   30|      1|  SSLServerSessionCache() {
   31|      1|    assert(SSL_ConfigServerSessionIDCache(1024, 0, 0, ".") == SECSuccess);
   32|      1|  }
_ZN21SSLServerSessionCacheD2Ev:
   34|      1|  ~SSLServerSessionCache() {
   35|      1|    assert(SSL_ShutdownServerSessionIDCache() == SECSuccess);
   36|      1|  }
tls_server.cc:_ZL15InitModelSocketPv:
   39|      1|static PRStatus InitModelSocket(void* arg) {
   40|      1|  PRFileDesc* fd = reinterpret_cast<PRFileDesc*>(arg);
   41|       |
   42|      1|  TlsCommon::EnableAllCipherSuites(fd);
   43|      1|  TlsServer::InstallServerCertificates(fd);
   44|       |
   45|      1|  return PR_SUCCESS;
   46|      1|}

nssArena_verifyPointer:
  153|  19.4k|{
  154|  19.4k|    PRStatus rv;
  155|       |
  156|  19.4k|    rv = nssPointerTracker_initialize(&arena_pointer_tracker);
  157|  19.4k|    if (PR_SUCCESS != rv) {
  ------------------
  |  Branch (157:9): [True: 0, False: 19.4k]
  ------------------
  158|       |        /*
  159|       |         * This is a little disingenious.  We have to initialize the
  160|       |         * tracker, because someone could "legitimately" try to verify
  161|       |         * an arena pointer before one is ever created.  And this step
  162|       |         * might fail, due to lack of memory.  But the only way that
  163|       |         * this step can fail is if it's doing the call_once stuff,
  164|       |         * (later calls just no-op).  And if it didn't no-op, there
  165|       |         * aren't any valid arenas.. so the argument certainly isn't one.
  166|       |         */
  167|      0|        nss_SetError(NSS_ERROR_INVALID_ARENA);
  168|      0|        return PR_FAILURE;
  169|      0|    }
  170|       |
  171|  19.4k|    rv = nssPointerTracker_verify(&arena_pointer_tracker, arena);
  172|  19.4k|    if (PR_SUCCESS != rv) {
  ------------------
  |  Branch (172:9): [True: 0, False: 19.4k]
  ------------------
  173|      0|        nss_SetError(NSS_ERROR_INVALID_ARENA);
  174|      0|        return PR_FAILURE;
  175|      0|    }
  176|       |
  177|  19.4k|    return PR_SUCCESS;
  178|  19.4k|}
NSSArena_Create:
  328|      2|{
  329|      2|    nss_ClearErrorStack();
  330|      2|    return nssArena_Create();
  331|      2|}
nssArena_Create:
  350|  7.74k|{
  351|  7.74k|    NSSArena *rv = (NSSArena *)NULL;
  352|       |
  353|  7.74k|    rv = nss_ZNEW((NSSArena *)NULL, NSSArena);
  ------------------
  |  |  348|  7.74k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  354|  7.74k|    if ((NSSArena *)NULL == rv) {
  ------------------
  |  Branch (354:9): [True: 0, False: 7.74k]
  ------------------
  355|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
  356|      0|        return (NSSArena *)NULL;
  357|      0|    }
  358|       |
  359|  7.74k|    rv->lock = PR_NewLock();
  360|  7.74k|    if ((PRLock *)NULL == rv->lock) {
  ------------------
  |  Branch (360:9): [True: 0, False: 7.74k]
  ------------------
  361|      0|        (void)nss_ZFreeIf(rv);
  362|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
  363|      0|        return (NSSArena *)NULL;
  364|      0|    }
  365|       |
  366|       |    /*
  367|       |     * Arena sizes.  The current security code has 229 occurrences of
  368|       |     * PORT_NewArena.  The default chunksizes specified break down as
  369|       |     *
  370|       |     *  Size    Mult.   Specified as
  371|       |     *   512       1    512
  372|       |     *  1024       7    1024
  373|       |     *  2048       5    2048
  374|       |     *  2048       5    CRMF_DEFAULT_ARENA_SIZE
  375|       |     *  2048     190    DER_DEFAULT_CHUNKSIZE
  376|       |     *  2048      20    SEC_ASN1_DEFAULT_ARENA_SIZE
  377|       |     *  4096       1    4096
  378|       |     *
  379|       |     * Obviously this "default chunksize" flexibility isn't very
  380|       |     * useful to us, so I'll just pick 2048.
  381|       |     */
  382|       |
  383|  7.74k|    PL_InitArenaPool(&rv->pool, "NSS", 2048, sizeof(double));
  384|       |
  385|  7.74k|#ifdef DEBUG
  386|  7.74k|    {
  387|  7.74k|        PRStatus st;
  388|  7.74k|        st = arena_add_pointer(rv);
  389|  7.74k|        if (PR_SUCCESS != st) {
  ------------------
  |  Branch (389:13): [True: 0, False: 7.74k]
  ------------------
  390|      0|            PL_FinishArenaPool(&rv->pool);
  391|      0|            PR_DestroyLock(rv->lock);
  392|      0|            (void)nss_ZFreeIf(rv);
  393|      0|            return (NSSArena *)NULL;
  394|      0|        }
  395|  7.74k|    }
  396|  7.74k|#endif /* DEBUG */
  397|       |
  398|  7.74k|    return rv;
  399|  7.74k|}
NSSArena_Destroy:
  419|  3.66k|{
  420|  3.66k|    nss_ClearErrorStack();
  421|       |
  422|  3.66k|#ifdef DEBUG
  423|  3.66k|    if (PR_SUCCESS != nssArena_verifyPointer(arena)) {
  ------------------
  |  Branch (423:9): [True: 0, False: 3.66k]
  ------------------
  424|      0|        return PR_FAILURE;
  425|      0|    }
  426|  3.66k|#endif /* DEBUG */
  427|       |
  428|  3.66k|    return nssArena_Destroy(arena);
  429|  3.66k|}
nssArena_Destroy:
  449|  7.74k|{
  450|  7.74k|    PRLock *lock;
  451|       |
  452|       |#ifdef NSSDEBUG
  453|       |    if (PR_SUCCESS != nssArena_verifyPointer(arena)) {
  454|       |        return PR_FAILURE;
  455|       |    }
  456|       |#endif /* NSSDEBUG */
  457|       |
  458|  7.74k|    if ((PRLock *)NULL == arena->lock) {
  ------------------
  |  Branch (458:9): [True: 0, False: 7.74k]
  ------------------
  459|       |        /* Just got destroyed */
  460|      0|        nss_SetError(NSS_ERROR_INVALID_ARENA);
  461|      0|        return PR_FAILURE;
  462|      0|    }
  463|  7.74k|    PR_Lock(arena->lock);
  464|       |
  465|  7.74k|#ifdef DEBUG
  466|  7.74k|    if (PR_SUCCESS != arena_remove_pointer(arena)) {
  ------------------
  |  Branch (466:9): [True: 0, False: 7.74k]
  ------------------
  467|      0|        PR_Unlock(arena->lock);
  468|      0|        return PR_FAILURE;
  469|      0|    }
  470|  7.74k|#endif /* DEBUG */
  471|       |
  472|  7.74k|#ifdef ARENA_DESTRUCTOR_LIST
  473|       |    /* Note that the arena is locked at this time */
  474|  7.74k|    nss_arena_call_destructor_chain(arena->first_destructor);
  475|  7.74k|#endif /* ARENA_DESTRUCTOR_LIST */
  476|       |
  477|  7.74k|    PL_FinishArenaPool(&arena->pool);
  478|  7.74k|    lock = arena->lock;
  479|  7.74k|    arena->lock = (PRLock *)NULL;
  480|  7.74k|    PR_Unlock(lock);
  481|  7.74k|    PR_DestroyLock(lock);
  482|  7.74k|    (void)nss_ZFreeIf(arena);
  483|  7.74k|    return PR_SUCCESS;
  484|  7.74k|}
nss_ZAlloc:
  823|  78.2k|{
  824|  78.2k|    struct pointer_header *h;
  825|  78.2k|    PRUint32 my_size = size + sizeof(struct pointer_header);
  826|       |
  827|  78.2k|    if (my_size < sizeof(struct pointer_header)) {
  ------------------
  |  Branch (827:9): [True: 0, False: 78.2k]
  ------------------
  828|       |        /* Wrapped */
  829|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
  830|      0|        return (void *)NULL;
  831|      0|    }
  832|       |
  833|  78.2k|    if ((NSSArena *)NULL == arenaOpt) {
  ------------------
  |  Branch (833:9): [True: 42.8k, False: 35.4k]
  ------------------
  834|       |        /* Heap allocation, no locking required. */
  835|  42.8k|        h = (struct pointer_header *)PR_Calloc(1, my_size);
  836|  42.8k|        if ((struct pointer_header *)NULL == h) {
  ------------------
  |  Branch (836:13): [True: 0, False: 42.8k]
  ------------------
  837|      0|            nss_SetError(NSS_ERROR_NO_MEMORY);
  838|      0|            return (void *)NULL;
  839|      0|        }
  840|       |
  841|  42.8k|        h->arena = (NSSArena *)NULL;
  842|  42.8k|        h->size = size;
  843|       |        /* We used calloc: it's already zeroed */
  844|       |
  845|  42.8k|        return (void *)((char *)h + sizeof(struct pointer_header));
  846|  42.8k|    } else {
  847|  35.4k|        void *rv;
  848|       |/* Arena allocation */
  849|       |#ifdef NSSDEBUG
  850|       |        if (PR_SUCCESS != nssArena_verifyPointer(arenaOpt)) {
  851|       |            return (void *)NULL;
  852|       |        }
  853|       |#endif /* NSSDEBUG */
  854|       |
  855|  35.4k|        if ((PRLock *)NULL == arenaOpt->lock) {
  ------------------
  |  Branch (855:13): [True: 0, False: 35.4k]
  ------------------
  856|       |            /* Just got destroyed */
  857|      0|            nss_SetError(NSS_ERROR_INVALID_ARENA);
  858|      0|            return (void *)NULL;
  859|      0|        }
  860|  35.4k|        PR_Lock(arenaOpt->lock);
  861|       |
  862|  35.4k|#ifdef ARENA_THREADMARK
  863|  35.4k|        if ((PRThread *)NULL != arenaOpt->marking_thread) {
  ------------------
  |  Branch (863:13): [True: 0, False: 35.4k]
  ------------------
  864|      0|            if (PR_GetCurrentThread() != arenaOpt->marking_thread) {
  ------------------
  |  Branch (864:17): [True: 0, False: 0]
  ------------------
  865|      0|                nss_SetError(NSS_ERROR_ARENA_MARKED_BY_ANOTHER_THREAD);
  866|      0|                PR_Unlock(arenaOpt->lock);
  867|      0|                return (void *)NULL;
  868|      0|            }
  869|      0|        }
  870|  35.4k|#endif /* ARENA_THREADMARK */
  871|       |
  872|  35.4k|        rv = nss_zalloc_arena_locked(arenaOpt, size);
  873|       |
  874|  35.4k|        PR_Unlock(arenaOpt->lock);
  875|  35.4k|        return rv;
  876|  35.4k|    }
  877|       |    /*NOTREACHED*/
  878|  78.2k|}
nss_ZFreeIf:
  923|  54.3k|{
  924|  54.3k|    struct pointer_header *h;
  925|       |
  926|  54.3k|    if ((void *)NULL == pointer) {
  ------------------
  |  Branch (926:9): [True: 3.66k, False: 50.6k]
  ------------------
  927|  3.66k|        return PR_SUCCESS;
  928|  3.66k|    }
  929|       |
  930|  50.6k|    h = (struct pointer_header *)((char *)pointer -
  931|  50.6k|                                  sizeof(struct pointer_header));
  932|       |
  933|       |    /* Check any magic here */
  934|       |
  935|  50.6k|    if ((NSSArena *)NULL == h->arena) {
  ------------------
  |  Branch (935:9): [True: 42.8k, False: 7.79k]
  ------------------
  936|       |        /* Heap */
  937|  42.8k|        (void)nsslibc_memset(pointer, 0, h->size);
  938|  42.8k|        PR_Free(h);
  939|  42.8k|        return PR_SUCCESS;
  940|  42.8k|    } else {
  941|       |/* Arena */
  942|       |#ifdef NSSDEBUG
  943|       |        if (PR_SUCCESS != nssArena_verifyPointer(h->arena)) {
  944|       |            return PR_FAILURE;
  945|       |        }
  946|       |#endif /* NSSDEBUG */
  947|       |
  948|  7.79k|        if ((PRLock *)NULL == h->arena->lock) {
  ------------------
  |  Branch (948:13): [True: 0, False: 7.79k]
  ------------------
  949|       |            /* Just got destroyed.. so this pointer is invalid */
  950|      0|            nss_SetError(NSS_ERROR_INVALID_POINTER);
  951|      0|            return PR_FAILURE;
  952|      0|        }
  953|  7.79k|        PR_Lock(h->arena->lock);
  954|       |
  955|  7.79k|        (void)nsslibc_memset(pointer, 0, h->size);
  956|       |
  957|       |        /* No way to "free" it within an NSPR arena. */
  958|       |
  959|  7.79k|        PR_Unlock(h->arena->lock);
  960|  7.79k|        return PR_SUCCESS;
  961|  7.79k|    }
  962|       |    /*NOTREACHED*/
  963|  50.6k|}
nssArena_Shutdown:
 1137|      1|{
 1138|      1|    PRStatus rv = PR_SUCCESS;
 1139|      1|#ifdef DEBUG
 1140|      1|    rv = nssPointerTracker_finalize(&arena_pointer_tracker);
 1141|      1|#endif
 1142|      1|    return rv;
 1143|      1|}
arena.c:arena_add_pointer:
  100|  7.74k|{
  101|  7.74k|    PRStatus rv;
  102|       |
  103|  7.74k|    rv = nssPointerTracker_initialize(&arena_pointer_tracker);
  104|  7.74k|    if (PR_SUCCESS != rv) {
  ------------------
  |  Branch (104:9): [True: 0, False: 7.74k]
  ------------------
  105|      0|        return rv;
  106|      0|    }
  107|       |
  108|  7.74k|    rv = nssPointerTracker_add(&arena_pointer_tracker, arena);
  109|  7.74k|    if (PR_SUCCESS != rv) {
  ------------------
  |  Branch (109:9): [True: 0, False: 7.74k]
  ------------------
  110|      0|        NSSError e = NSS_GetError();
  111|      0|        if (NSS_ERROR_NO_MEMORY != e) {
  ------------------
  |  Branch (111:13): [True: 0, False: 0]
  ------------------
  112|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR);
  113|      0|        }
  114|       |
  115|      0|        return rv;
  116|      0|    }
  117|       |
  118|  7.74k|    return PR_SUCCESS;
  119|  7.74k|}
arena.c:arena_remove_pointer:
  123|  7.74k|{
  124|  7.74k|    PRStatus rv;
  125|       |
  126|  7.74k|    rv = nssPointerTracker_remove(&arena_pointer_tracker, arena);
  127|  7.74k|    if (PR_SUCCESS != rv) {
  ------------------
  |  Branch (127:9): [True: 0, False: 7.74k]
  ------------------
  128|      0|        nss_SetError(NSS_ERROR_INTERNAL_ERROR);
  129|      0|    }
  130|       |
  131|  7.74k|    return rv;
  132|  7.74k|}
arena.c:nss_arena_call_destructor_chain:
  304|  7.74k|{
  305|  7.74k|    for (; it; it = it->next) {
  ------------------
  |  Branch (305:12): [True: 0, False: 7.74k]
  ------------------
  306|      0|        (*(it->destructor))(it->arg);
  307|      0|    }
  308|  7.74k|}
arena.c:nss_zalloc_arena_locked:
  746|  35.4k|{
  747|  35.4k|    void *p;
  748|  35.4k|    void *rv;
  749|  35.4k|    struct pointer_header *h;
  750|  35.4k|    PRUint32 my_size = size + sizeof(struct pointer_header);
  751|  35.4k|    PL_ARENA_ALLOCATE(p, &arena->pool, my_size);
  ------------------
  |  |  150|  35.4k|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|  35.4k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  151|  35.4k|        PLArena *_a = (pool)->current; \
  |  |  152|  35.4k|        PRUint32 _nb = PL_ARENA_ALIGN(pool, (PRUint32)nb); \
  |  |  ------------------
  |  |  |  |  146|  35.4k|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  |  |  ------------------
  |  |  153|  35.4k|        PRUword _p = _a->avail; \
  |  |  154|  35.4k|        if (_nb < (PRUint32)nb) { \
  |  |  ------------------
  |  |  |  Branch (154:13): [True: 0, False: 35.4k]
  |  |  ------------------
  |  |  155|      0|            _p = 0; \
  |  |  156|  35.4k|        } else if (_nb > (_a->limit - _a->avail)) { \
  |  |  ------------------
  |  |  |  Branch (156:20): [True: 7.77k, False: 27.6k]
  |  |  ------------------
  |  |  157|  7.77k|            _p = (PRUword)PL_ArenaAllocate(pool, _nb); \
  |  |  158|  27.6k|        } else { \
  |  |  159|  27.6k|            _a->avail += _nb; \
  |  |  160|  27.6k|        } \
  |  |  161|  35.4k|        p = (void *)_p; \
  |  |  162|  35.4k|        if (p) { \
  |  |  ------------------
  |  |  |  Branch (162:13): [True: 35.4k, False: 0]
  |  |  ------------------
  |  |  163|  35.4k|            PL_MAKE_MEM_UNDEFINED(p, (PRUint32)nb); \
  |  |  164|  35.4k|            PL_ArenaCountAllocation(pool, (PRUint32)nb); \
  |  |  165|  35.4k|        } \
  |  |  166|  35.4k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  35.4k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  752|  35.4k|    if ((void *)NULL == p) {
  ------------------
  |  Branch (752:9): [True: 0, False: 35.4k]
  ------------------
  753|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
  754|      0|        return (void *)NULL;
  755|      0|    }
  756|       |    /*
  757|       |     * Do this before we unlock.  This way if the user is using
  758|       |     * an arena in one thread while destroying it in another, he'll
  759|       |     * fault/FMR in his code, not ours.
  760|       |     */
  761|  35.4k|    h = (struct pointer_header *)p;
  762|  35.4k|    h->arena = arena;
  763|  35.4k|    h->size = size;
  764|  35.4k|    rv = (void *)((char *)h + sizeof(struct pointer_header));
  765|  35.4k|    (void)nsslibc_memset(rv, 0, size);
  766|  35.4k|    return rv;
  767|  35.4k|}

NSS_GetErrorStack:
  219|    174|{
  220|    174|    error_stack *es = error_get_my_stack();
  221|       |
  222|    174|    if ((error_stack *)NULL == es) {
  ------------------
  |  Branch (222:9): [True: 0, False: 174]
  ------------------
  223|      0|        return (PRInt32 *)NULL;
  224|      0|    }
  225|       |
  226|       |    /* Make sure it's terminated */
  227|    174|    es->stack[es->header.count] = 0;
  228|       |
  229|    174|    return es->stack;
  230|    174|}
nss_SetError:
  242|  23.4k|{
  243|  23.4k|    error_stack *es;
  244|       |
  245|  23.4k|    if (0 == error) {
  ------------------
  |  Branch (245:9): [True: 0, False: 23.4k]
  ------------------
  246|      0|        nss_ClearErrorStack();
  247|      0|        return;
  248|      0|    }
  249|       |
  250|  23.4k|    es = error_get_my_stack();
  251|  23.4k|    if ((error_stack *)NULL == es) {
  ------------------
  |  Branch (251:9): [True: 0, False: 23.4k]
  ------------------
  252|       |        /* Oh, well. */
  253|      0|        return;
  254|      0|    }
  255|       |
  256|  23.4k|    if (es->header.count < es->header.space) {
  ------------------
  |  Branch (256:9): [True: 23.0k, False: 364]
  ------------------
  257|  23.0k|        es->stack[es->header.count++] = error;
  258|  23.0k|    } else {
  259|    364|        memmove(es->stack, es->stack + 1,
  260|    364|                (es->header.space - 1) * (sizeof es->stack[0]));
  261|    364|        es->stack[es->header.space - 1] = error;
  262|    364|    }
  263|  23.4k|    return;
  264|  23.4k|}
nss_ClearErrorStack:
  274|  3.66k|{
  275|  3.66k|    error_stack *es = error_get_my_stack();
  276|  3.66k|    if ((error_stack *)NULL == es) {
  ------------------
  |  Branch (276:9): [True: 0, False: 3.66k]
  ------------------
  277|       |        /* Oh, well. */
  278|      0|        return;
  279|      0|    }
  280|       |
  281|  3.66k|    es->header.count = 0;
  282|  3.66k|    es->stack[0] = 0;
  283|  3.66k|    return;
  284|  3.66k|}
nss_DestroyErrorStack:
  294|      1|{
  295|      1|    if (INVALID_TPD_INDEX != error_stack_index) {
  ------------------
  |  |   51|      1|#define INVALID_TPD_INDEX UINT_MAX
  ------------------
  |  Branch (295:9): [True: 1, False: 0]
  ------------------
  296|      1|        PR_SetThreadPrivate(error_stack_index, NULL);
  297|      1|        error_stack_index = INVALID_TPD_INDEX;
  ------------------
  |  |   51|      1|#define INVALID_TPD_INDEX UINT_MAX
  ------------------
  298|      1|        error_call_once = error_call_again; /* allow to init again */
  299|      1|    }
  300|      1|    return;
  301|      1|}
error.c:error_get_my_stack:
  110|  27.2k|{
  111|  27.2k|    PRStatus st;
  112|  27.2k|    error_stack *rv;
  113|  27.2k|    PRUintn new_size;
  114|  27.2k|    PRUint32 new_bytes;
  115|  27.2k|    error_stack *new_stack;
  116|       |
  117|  27.2k|    if (INVALID_TPD_INDEX == error_stack_index) {
  ------------------
  |  |   51|  27.2k|#define INVALID_TPD_INDEX UINT_MAX
  ------------------
  |  Branch (117:9): [True: 1, False: 27.2k]
  ------------------
  118|      1|        st = PR_CallOnce(&error_call_once, error_once_function);
  119|      1|        if (PR_SUCCESS != st) {
  ------------------
  |  Branch (119:13): [True: 0, False: 1]
  ------------------
  120|      0|            return (error_stack *)NULL;
  121|      0|        }
  122|      1|    }
  123|       |
  124|  27.2k|    rv = (error_stack *)PR_GetThreadPrivate(error_stack_index);
  125|  27.2k|    if ((error_stack *)NULL == rv) {
  ------------------
  |  Branch (125:9): [True: 1, False: 27.2k]
  ------------------
  126|       |        /* Doesn't exist; create one */
  127|      1|        new_size = 16;
  128|  27.2k|    } else if (rv->header.count == rv->header.space &&
  ------------------
  |  Branch (128:16): [True: 429, False: 26.8k]
  ------------------
  129|  27.2k|               rv->header.count < NSS_MAX_ERROR_STACK_COUNT) {
  ------------------
  |  |   22|    429|#define NSS_MAX_ERROR_STACK_COUNT 16 /* error codes */
  ------------------
  |  Branch (129:16): [True: 0, False: 429]
  ------------------
  130|       |        /* Too small, expand it */
  131|      0|        new_size = PR_MIN(rv->header.space * 2, NSS_MAX_ERROR_STACK_COUNT);
  ------------------
  |  |  158|      0|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  132|  27.2k|    } else {
  133|       |        /* Okay, return it */
  134|  27.2k|        return rv;
  135|  27.2k|    }
  136|       |
  137|      1|    new_bytes = (new_size * sizeof(PRInt32)) + sizeof(error_stack);
  138|       |    /* Use NSPR's calloc/realloc, not NSS's, to avoid loops! */
  139|      1|    new_stack = PR_Calloc(1, new_bytes);
  140|       |
  141|      1|    if ((error_stack *)NULL != new_stack) {
  ------------------
  |  Branch (141:9): [True: 1, False: 0]
  ------------------
  142|      1|        if ((error_stack *)NULL != rv) {
  ------------------
  |  Branch (142:13): [True: 0, False: 1]
  ------------------
  143|      0|            (void)nsslibc_memcpy(new_stack, rv, rv->header.space);
  144|      0|        }
  145|      1|        new_stack->header.space = new_size;
  146|      1|    }
  147|       |
  148|       |    /* Set the value, whether or not the allocation worked */
  149|      1|    PR_SetThreadPrivate(error_stack_index, new_stack);
  150|      1|    return new_stack;
  151|  27.2k|}
error.c:error_once_function:
   71|      1|{
   72|       |
   73|       |/*
   74|       | * This #ifdef function is redundant. It performs the same thing as the
   75|       | * else case.
   76|       | *
   77|       | * However, the MinGW version looks up the function from nss3's export
   78|       | * table, and on MinGW _that_ behaves differently than passing a
   79|       | * function pointer in a different module because MinGW has
   80|       | * -mnop-fun-dllimport specified, which generates function thunks for
   81|       | * cross-module calls. And when a module (like nssckbi) gets unloaded,
   82|       | * and you try to call into that thunk (which is now missing) you'll
   83|       | * crash. So we do this bit of ugly to avoid that crash. Fortunately
   84|       | * this is the only place we've had to do this.
   85|       | */
   86|       |#if defined(__MINGW32__)
   87|       |    HMODULE nss3 = GetModuleHandleW(L"nss3");
   88|       |    if (nss3) {
   89|       |        PRThreadPrivateDTOR freePtr = (PRThreadPrivateDTOR)GetProcAddress(nss3, "PR_Free");
   90|       |        if (freePtr) {
   91|       |            return PR_NewThreadPrivateIndex(&error_stack_index, freePtr);
   92|       |        }
   93|       |    }
   94|       |    return PR_NewThreadPrivateIndex(&error_stack_index, PR_Free);
   95|       |#else
   96|      1|    return PR_NewThreadPrivateIndex(&error_stack_index, PR_Free);
   97|      1|#endif
   98|      1|}

nssHash_Create:
   80|      6|{
   81|      6|    nssHash *rv;
   82|      6|    NSSArena *arena;
   83|      6|    PRBool i_alloced;
   84|       |
   85|       |#ifdef NSSDEBUG
   86|       |    if (arenaOpt && PR_SUCCESS != nssArena_verifyPointer(arenaOpt)) {
   87|       |        nss_SetError(NSS_ERROR_INVALID_POINTER);
   88|       |        return (nssHash *)NULL;
   89|       |    }
   90|       |#endif /* NSSDEBUG */
   91|       |
   92|      6|    if (arenaOpt) {
  ------------------
  |  Branch (92:9): [True: 6, False: 0]
  ------------------
   93|      6|        arena = arenaOpt;
   94|      6|        i_alloced = PR_FALSE;
  ------------------
  |  |  438|      6|#define PR_FALSE 0
  ------------------
   95|      6|    } else {
   96|      0|        arena = nssArena_Create();
   97|      0|        i_alloced = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
   98|      0|    }
   99|       |
  100|      6|    rv = nss_ZNEW(arena, nssHash);
  ------------------
  |  |  348|      6|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  101|      6|    if ((nssHash *)NULL == rv) {
  ------------------
  |  Branch (101:9): [True: 0, False: 6]
  ------------------
  102|      0|        goto loser;
  103|      0|    }
  104|       |
  105|      6|    rv->mutex = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      6|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  106|      6|    if ((PZLock *)NULL == rv->mutex) {
  ------------------
  |  Branch (106:9): [True: 0, False: 6]
  ------------------
  107|      0|        goto loser;
  108|      0|    }
  109|       |
  110|      6|    rv->plHashTable =
  111|      6|        PL_NewHashTable(numBuckets, keyHash, keyCompare, valueCompare,
  112|      6|                        &nssArenaHashAllocOps, arena);
  113|      6|    if ((PLHashTable *)NULL == rv->plHashTable) {
  ------------------
  |  Branch (113:9): [True: 0, False: 6]
  ------------------
  114|      0|        (void)PZ_DestroyLock(rv->mutex);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  115|      0|        goto loser;
  116|      0|    }
  117|       |
  118|      6|    rv->count = 0;
  119|      6|    rv->arena = arena;
  120|      6|    rv->i_alloced_arena = i_alloced;
  121|       |
  122|      6|    return rv;
  123|      0|loser:
  124|      0|    (void)nss_ZFreeIf(rv);
  125|      0|    return (nssHash *)NULL;
  126|      6|}
nssHash_CreateString:
  145|      2|{
  146|      2|    return nssHash_Create(arenaOpt, numBuckets, PL_HashString,
  147|      2|                          PL_CompareStrings, PL_CompareStrings);
  148|      2|}
nssHash_CreateItem:
  156|      2|{
  157|      2|    return nssHash_Create(arenaOpt, numBuckets, nss_item_hash,
  158|      2|                          nss_compare_items, PL_CompareValues);
  159|      2|}
nssHash_Destroy:
  167|      6|{
  168|      6|    (void)PZ_DestroyLock(hash->mutex);
  ------------------
  |  |  244|      6|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  169|      6|    PL_HashTableDestroy(hash->plHashTable);
  170|      6|    if (hash->i_alloced_arena) {
  ------------------
  |  Branch (170:9): [True: 0, False: 6]
  ------------------
  171|      0|        nssArena_Destroy(hash->arena);
  172|      6|    } else {
  173|      6|        nss_ZFreeIf(hash);
  174|      6|    }
  175|      6|}
nssHash_Add:
  183|  7.78k|{
  184|  7.78k|    PRStatus error = PR_FAILURE;
  185|  7.78k|    PLHashEntry *he;
  186|       |
  187|  7.78k|    PZ_Lock(hash->mutex);
  ------------------
  |  |  245|  7.78k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  188|       |
  189|  7.78k|    he = PL_HashTableAdd(hash->plHashTable, key, (void *)value);
  190|  7.78k|    if ((PLHashEntry *)NULL == he) {
  ------------------
  |  Branch (190:9): [True: 0, False: 7.78k]
  ------------------
  191|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
  192|  7.78k|    } else if (he->value != value) {
  ------------------
  |  Branch (192:16): [True: 0, False: 7.78k]
  ------------------
  193|      0|        nss_SetError(NSS_ERROR_HASH_COLLISION);
  194|  7.78k|    } else {
  195|  7.78k|        hash->count++;
  196|  7.78k|        error = PR_SUCCESS;
  197|  7.78k|    }
  198|       |
  199|  7.78k|    (void)PZ_Unlock(hash->mutex);
  ------------------
  |  |  246|  7.78k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  200|       |
  201|  7.78k|    return error;
  202|  7.78k|}
nssHash_Remove:
  210|  7.78k|{
  211|  7.78k|    PRBool found;
  212|       |
  213|  7.78k|    PZ_Lock(hash->mutex);
  ------------------
  |  |  245|  7.78k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  214|       |
  215|  7.78k|    found = PL_HashTableRemove(hash->plHashTable, it);
  216|  7.78k|    if (found) {
  ------------------
  |  Branch (216:9): [True: 7.78k, False: 0]
  ------------------
  217|  7.78k|        hash->count--;
  218|  7.78k|    }
  219|       |
  220|  7.78k|    (void)PZ_Unlock(hash->mutex);
  ------------------
  |  |  246|  7.78k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  221|  7.78k|    return;
  222|  7.78k|}
nssHash_Count:
  230|      2|{
  231|      2|    PRUint32 count;
  232|       |
  233|      2|    PZ_Lock(hash->mutex);
  ------------------
  |  |  245|      2|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  234|       |
  235|      2|    count = hash->count;
  236|       |
  237|      2|    (void)PZ_Unlock(hash->mutex);
  ------------------
  |  |  246|      2|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  238|       |
  239|      2|    return count;
  240|      2|}
nssHash_Lookup:
  270|  31.2k|{
  271|  31.2k|    void *rv;
  272|       |
  273|  31.2k|    PZ_Lock(hash->mutex);
  ------------------
  |  |  245|  31.2k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  274|       |
  275|  31.2k|    rv = PL_HashTableLookup(hash->plHashTable, it);
  276|       |
  277|  31.2k|    (void)PZ_Unlock(hash->mutex);
  ------------------
  |  |  246|  31.2k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  278|       |
  279|  31.2k|    return rv;
  280|  31.2k|}
nssHash_Iterate:
  302|      1|{
  303|      1|    struct arg_str as;
  304|      1|    as.fcn = fcn;
  305|      1|    as.closure = closure;
  306|       |
  307|      1|    PZ_Lock(hash->mutex);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  308|       |
  309|      1|    PL_HashTableEnumerateEntries(hash->plHashTable, nss_hash_enumerator, &as);
  310|       |
  311|      1|    (void)PZ_Unlock(hash->mutex);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  312|       |
  313|      1|    return;
  314|      1|}
hash.c:nss_item_hash:
   56|  15.5k|{
   57|  15.5k|    unsigned int i;
   58|  15.5k|    PLHashNumber h;
   59|  15.5k|    NSSItem *it = (NSSItem *)key;
   60|  15.5k|    h = 0;
   61|   432k|    for (i = 0; i < it->size; i++)
  ------------------
  |  Branch (61:17): [True: 417k, False: 15.5k]
  ------------------
   62|   417k|        h = PR_ROTATE_LEFT32(h, 4) ^ ((unsigned char *)it->data)[i];
  ------------------
  |  |  147|   417k|#define PR_ROTATE_LEFT32(a, bits) (((a) << (bits)) | ((a) >> (32 - (bits))))
  ------------------
   63|  15.5k|    return h;
   64|  15.5k|}
hash.c:nss_compare_items:
   68|  8.01k|{
   69|  8.01k|    PRStatus ignore;
   70|  8.01k|    return (int)nssItem_Equal((NSSItem *)v1, (NSSItem *)v2, &ignore);
   71|  8.01k|}

hashops.c:nss_arena_hash_alloc_table:
   17|     12|{
   18|     12|    NSSArena *arena = (NSSArena *)NULL;
   19|       |
   20|       |#ifdef NSSDEBUG
   21|       |    if ((void *)NULL != arena) {
   22|       |        if (PR_SUCCESS != nssArena_verifyPointer(arena)) {
   23|       |            return (void *)NULL;
   24|       |        }
   25|       |    }
   26|       |#endif /* NSSDEBUG */
   27|       |
   28|     12|    return nss_ZAlloc(arena, size);
   29|     12|}
hashops.c:nss_arena_hash_free_table:
   33|     12|{
   34|     12|    (void)nss_ZFreeIf(item);
   35|     12|}
hashops.c:nss_arena_hash_alloc_entry:
   39|  7.78k|{
   40|  7.78k|    NSSArena *arena = NULL;
   41|       |
   42|       |#ifdef NSSDEBUG
   43|       |    if ((void *)NULL != arena) {
   44|       |        if (PR_SUCCESS != nssArena_verifyPointer(arena)) {
   45|       |            return (void *)NULL;
   46|       |        }
   47|       |    }
   48|       |#endif /* NSSDEBUG */
   49|       |
   50|  7.78k|    return nss_ZNEW(arena, PLHashEntry);
  ------------------
  |  |  348|  7.78k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   51|  7.78k|}
hashops.c:nss_arena_hash_free_entry:
   55|  7.78k|{
   56|  7.78k|    if (HT_FREE_ENTRY == flag) {
  ------------------
  |  |   39|  7.78k|#define HT_FREE_ENTRY   1               /* free value and entire entry */
  ------------------
  |  Branch (56:9): [True: 7.78k, False: 0]
  ------------------
   57|  7.78k|        (void)nss_ZFreeIf(he);
   58|  7.78k|    }
   59|  7.78k|}

nssItem_Create:
   34|  15.7k|{
   35|  15.7k|    NSSItem *rv = (NSSItem *)NULL;
   36|       |
   37|  15.7k|#ifdef DEBUG
   38|  15.7k|    if ((NSSArena *)NULL != arenaOpt) {
  ------------------
  |  Branch (38:9): [True: 15.7k, False: 0]
  ------------------
   39|  15.7k|        if (PR_SUCCESS != nssArena_verifyPointer(arenaOpt)) {
  ------------------
  |  Branch (39:13): [True: 0, False: 15.7k]
  ------------------
   40|      0|            return (NSSItem *)NULL;
   41|      0|        }
   42|  15.7k|    }
   43|       |
   44|  15.7k|    if ((const void *)NULL == data) {
  ------------------
  |  Branch (44:9): [True: 4, False: 15.7k]
  ------------------
   45|      4|        if (length > 0) {
  ------------------
  |  Branch (45:13): [True: 0, False: 4]
  ------------------
   46|      0|            nss_SetError(NSS_ERROR_INVALID_POINTER);
   47|      0|            return (NSSItem *)NULL;
   48|      0|        }
   49|      4|    }
   50|  15.7k|#endif /* DEBUG */
   51|       |
   52|  15.7k|    if ((NSSItem *)NULL == rvOpt) {
  ------------------
  |  Branch (52:9): [True: 0, False: 15.7k]
  ------------------
   53|      0|        rv = (NSSItem *)nss_ZNEW(arenaOpt, NSSItem);
  ------------------
  |  |  348|      0|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   54|      0|        if ((NSSItem *)NULL == rv) {
  ------------------
  |  Branch (54:13): [True: 0, False: 0]
  ------------------
   55|      0|            goto loser;
   56|      0|        }
   57|  15.7k|    } else {
   58|  15.7k|        rv = rvOpt;
   59|  15.7k|    }
   60|       |
   61|  15.7k|    rv->size = length;
   62|  15.7k|    rv->data = nss_ZAlloc(arenaOpt, length);
   63|  15.7k|    if ((void *)NULL == rv->data) {
  ------------------
  |  Branch (63:9): [True: 0, False: 15.7k]
  ------------------
   64|      0|        goto loser;
   65|      0|    }
   66|       |
   67|  15.7k|    if (length > 0) {
  ------------------
  |  Branch (67:9): [True: 15.7k, False: 4]
  ------------------
   68|  15.7k|        (void)nsslibc_memcpy(rv->data, data, length);
   69|  15.7k|    }
   70|       |
   71|  15.7k|    return rv;
   72|       |
   73|      0|loser:
   74|      0|    if (rv != rvOpt) {
  ------------------
  |  Branch (74:9): [True: 0, False: 0]
  ------------------
   75|      0|        nss_ZFreeIf(rv);
   76|      0|    }
   77|       |
   78|      0|    return (NSSItem *)NULL;
   79|  15.7k|}
nssItem_Equal:
  168|  31.3k|{
  169|  31.3k|    if ((PRStatus *)NULL != statusOpt) {
  ------------------
  |  Branch (169:9): [True: 31.3k, False: 5]
  ------------------
  170|  31.3k|        *statusOpt = PR_SUCCESS;
  171|  31.3k|    }
  172|       |
  173|  31.3k|    if (((const NSSItem *)NULL == one) && ((const NSSItem *)NULL == two)) {
  ------------------
  |  Branch (173:9): [True: 0, False: 31.3k]
  |  Branch (173:43): [True: 0, False: 0]
  ------------------
  174|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  175|      0|    }
  176|       |
  177|  31.3k|    if (((const NSSItem *)NULL == one) || ((const NSSItem *)NULL == two)) {
  ------------------
  |  Branch (177:9): [True: 0, False: 31.3k]
  |  Branch (177:43): [True: 0, False: 31.3k]
  ------------------
  178|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  179|      0|    }
  180|       |
  181|  31.3k|    if (one->size != two->size) {
  ------------------
  |  Branch (181:9): [True: 0, False: 31.3k]
  ------------------
  182|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  183|      0|    }
  184|       |
  185|  31.3k|    return nsslibc_memequal(one->data, two->data, one->size, statusOpt);
  186|  31.3k|}

nsslibc_memcpy:
   42|  15.8k|{
   43|       |#ifdef NSSDEBUG
   44|       |    if (((void *)NULL == dest) || ((const void *)NULL == source)) {
   45|       |        nss_SetError(NSS_ERROR_INVALID_POINTER);
   46|       |        return (void *)NULL;
   47|       |    }
   48|       |#endif /* NSSDEBUG */
   49|       |
   50|  15.8k|    return memcpy(dest, source, (size_t)n);
   51|  15.8k|}
nsslibc_memset:
   66|  86.0k|{
   67|       |#ifdef NSSDEBUG
   68|       |    if (((void *)NULL == dest)) {
   69|       |        nss_SetError(NSS_ERROR_INVALID_POINTER);
   70|       |        return (void *)NULL;
   71|       |    }
   72|       |#endif /* NSSDEBUG */
   73|       |
   74|  86.0k|    return memset(dest, (int)byte, (size_t)n);
   75|  86.0k|}
nsslibc_memequal:
   92|  31.3k|{
   93|       |#ifdef NSSDEBUG
   94|       |    if ((((void *)NULL == a) || ((void *)NULL == b))) {
   95|       |        nss_SetError(NSS_ERROR_INVALID_POINTER);
   96|       |        if ((PRStatus *)NULL != statusOpt) {
   97|       |            *statusOpt = PR_FAILURE;
   98|       |        }
   99|       |        return PR_FALSE;
  100|       |    }
  101|       |#endif /* NSSDEBUG */
  102|       |
  103|  31.3k|    if ((PRStatus *)NULL != statusOpt) {
  ------------------
  |  Branch (103:9): [True: 31.3k, False: 5]
  ------------------
  104|  31.3k|        *statusOpt = PR_SUCCESS;
  105|  31.3k|    }
  106|       |
  107|  31.3k|    if (0 == memcmp(a, b, len)) {
  ------------------
  |  Branch (107:9): [True: 31.3k, False: 16]
  ------------------
  108|  31.3k|        return PR_TRUE;
  ------------------
  |  |  437|  31.3k|#define PR_TRUE 1
  ------------------
  109|  31.3k|    } else {
  110|     16|        return PR_FALSE;
  ------------------
  |  |  438|     16|#define PR_FALSE 0
  ------------------
  111|     16|    }
  112|  31.3k|}

nssList_Create:
   76|  3.66k|{
   77|  3.66k|    NSSArena *arena;
   78|  3.66k|    nssList *list;
   79|  3.66k|    PRBool i_alloced;
   80|  3.66k|    if (arenaOpt) {
  ------------------
  |  Branch (80:9): [True: 1, False: 3.66k]
  ------------------
   81|      1|        arena = arenaOpt;
   82|      1|        i_alloced = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   83|  3.66k|    } else {
   84|  3.66k|        arena = nssArena_Create();
   85|  3.66k|        i_alloced = PR_TRUE;
  ------------------
  |  |  437|  3.66k|#define PR_TRUE 1
  ------------------
   86|  3.66k|    }
   87|  3.66k|    if (!arena) {
  ------------------
  |  Branch (87:9): [True: 0, False: 3.66k]
  ------------------
   88|      0|        return (nssList *)NULL;
   89|      0|    }
   90|  3.66k|    list = nss_ZNEW(arena, nssList);
  ------------------
  |  |  348|  3.66k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   91|  3.66k|    if (!list) {
  ------------------
  |  Branch (91:9): [True: 0, False: 3.66k]
  ------------------
   92|      0|        if (!arenaOpt) {
  ------------------
  |  Branch (92:13): [True: 0, False: 0]
  ------------------
   93|      0|            NSSArena_Destroy(arena);
   94|      0|        }
   95|      0|        return (nssList *)NULL;
   96|      0|    }
   97|  3.66k|    if (threadSafe) {
  ------------------
  |  Branch (97:9): [True: 2, False: 3.66k]
  ------------------
   98|      2|        list->lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   99|      2|        if (!list->lock) {
  ------------------
  |  Branch (99:13): [True: 0, False: 2]
  ------------------
  100|      0|            if (arenaOpt) {
  ------------------
  |  Branch (100:17): [True: 0, False: 0]
  ------------------
  101|      0|                nss_ZFreeIf(list);
  102|      0|            } else {
  103|      0|                NSSArena_Destroy(arena);
  104|      0|            }
  105|      0|            return (nssList *)NULL;
  106|      0|        }
  107|      2|    }
  108|  3.66k|    list->arena = arena;
  109|  3.66k|    list->i_alloced_arena = i_alloced;
  110|  3.66k|    list->compareFunc = pointer_compare;
  111|  3.66k|    return list;
  112|  3.66k|}
nssList_Destroy:
  116|  3.66k|{
  117|  3.66k|    if (!list) {
  ------------------
  |  Branch (117:9): [True: 0, False: 3.66k]
  ------------------
  118|      0|        return PR_SUCCESS;
  119|      0|    }
  120|  3.66k|    if (!list->i_alloced_arena) {
  ------------------
  |  Branch (120:9): [True: 1, False: 3.66k]
  ------------------
  121|      1|        nssList_Clear(list, NULL);
  122|      1|    }
  123|  3.66k|    if (list->lock) {
  ------------------
  |  Branch (123:9): [True: 2, False: 3.66k]
  ------------------
  124|      2|        (void)PZ_DestroyLock(list->lock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  125|      2|    }
  126|  3.66k|    if (list->i_alloced_arena) {
  ------------------
  |  Branch (126:9): [True: 3.66k, False: 1]
  ------------------
  127|  3.66k|        NSSArena_Destroy(list->arena);
  128|  3.66k|        list = NULL;
  129|  3.66k|    }
  130|  3.66k|    nss_ZFreeIf(list);
  131|  3.66k|    return PR_SUCCESS;
  132|  3.66k|}
nssList_SetSortFunction:
  142|  3.66k|{
  143|       |    /* XXX if list already has elements, sort them */
  144|  3.66k|    list->sortFunc = sortFunc;
  145|  3.66k|}
nssList_Clear:
  155|      2|{
  156|      2|    PRCList *link;
  157|      2|    nssListElement *node, *tmp;
  158|      2|    if (!list) {
  ------------------
  |  Branch (158:9): [True: 0, False: 2]
  ------------------
  159|      0|        return;
  160|      0|    }
  161|      2|    NSSLIST_LOCK_IF(list);
  ------------------
  |  |   39|      2|    if ((list)->lock)         \
  |  |  ------------------
  |  |  |  Branch (39:9): [True: 2, False: 0]
  |  |  ------------------
  |  |   40|      2|    PZ_Lock((list)->lock)
  |  |  ------------------
  |  |  |  |  245|      2|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  162|      2|    node = list->head;
  163|      2|    list->head = NULL;
  164|      4|    while (node && list->count > 0) {
  ------------------
  |  Branch (164:12): [True: 3, False: 1]
  |  Branch (164:20): [True: 2, False: 1]
  ------------------
  165|      2|        if (destructor)
  ------------------
  |  Branch (165:13): [True: 2, False: 0]
  ------------------
  166|      2|            (*destructor)(node->data);
  167|      2|        link = &node->link;
  168|      2|        tmp = (nssListElement *)PR_NEXT_LINK(link);
  ------------------
  |  |   47|      2|        ((_e)->next)
  ------------------
  169|      2|        PR_REMOVE_LINK(link);
  ------------------
  |  |   72|      2|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      2|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      2|    (_e)->prev->next = (_e)->next; \
  |  |   74|      2|    (_e)->next->prev = (_e)->prev; \
  |  |   75|      2|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      2|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  170|      2|        nss_ZFreeIf(node);
  171|      2|        node = tmp;
  172|      2|        --list->count;
  173|      2|    }
  174|      2|    NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|      2|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 2, False: 0]
  |  |  ------------------
  |  |   44|      2|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|      2|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  175|      2|}
nssList_Add:
  222|  3.66k|{
  223|  3.66k|    NSSLIST_LOCK_IF(list);
  ------------------
  |  |   39|  3.66k|    if ((list)->lock)         \
  |  |  ------------------
  |  |  |  Branch (39:9): [True: 4, False: 3.66k]
  |  |  ------------------
  |  |   40|  3.66k|    PZ_Lock((list)->lock)
  |  |  ------------------
  |  |  |  |  245|      4|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  224|  3.66k|    (void)nsslist_add_element(list, data);
  225|  3.66k|    NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|  3.66k|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 4, False: 3.66k]
  |  |  ------------------
  |  |   44|  3.66k|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|      4|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  226|  3.66k|    return PR_SUCCESS;
  227|  3.66k|}
nssList_AddUnique:
  231|    230|{
  232|    230|    PRStatus nssrv;
  233|    230|    nssListElement *node;
  234|    230|    NSSLIST_LOCK_IF(list);
  ------------------
  |  |   39|    230|    if ((list)->lock)         \
  |  |  ------------------
  |  |  |  Branch (39:9): [True: 0, False: 230]
  |  |  ------------------
  |  |   40|    230|    PZ_Lock((list)->lock)
  |  |  ------------------
  |  |  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  235|    230|    node = nsslist_get_matching_element(list, data);
  236|    230|    if (node) {
  ------------------
  |  Branch (236:9): [True: 0, False: 230]
  ------------------
  237|       |        /* already in, finish */
  238|      0|        NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|      0|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   44|      0|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  239|      0|        return PR_SUCCESS;
  240|      0|    }
  241|    230|    nssrv = nsslist_add_element(list, data);
  242|    230|    NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|    230|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 0, False: 230]
  |  |  ------------------
  |  |   44|    230|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  243|    230|    return nssrv;
  244|    230|}
nssList_Remove:
  248|  3.89k|{
  249|  3.89k|    nssListElement *node;
  250|  3.89k|    NSSLIST_LOCK_IF(list);
  ------------------
  |  |   39|  3.89k|    if ((list)->lock)         \
  |  |  ------------------
  |  |  |  Branch (39:9): [True: 0, False: 3.89k]
  |  |  ------------------
  |  |   40|  3.89k|    PZ_Lock((list)->lock)
  |  |  ------------------
  |  |  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  251|  3.89k|    node = nsslist_get_matching_element(list, data);
  252|  3.89k|    if (node) {
  ------------------
  |  Branch (252:9): [True: 3.89k, False: 0]
  ------------------
  253|  3.89k|        if (node == list->head) {
  ------------------
  |  Branch (253:13): [True: 3.71k, False: 181]
  ------------------
  254|  3.71k|            list->head = (nssListElement *)PR_NEXT_LINK(&node->link);
  ------------------
  |  |   47|  3.71k|        ((_e)->next)
  ------------------
  255|  3.71k|        }
  256|  3.89k|        PR_REMOVE_LINK(&node->link);
  ------------------
  |  |   72|  3.89k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|  3.89k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|  3.89k|    (_e)->prev->next = (_e)->next; \
  |  |   74|  3.89k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|  3.89k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  3.89k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  257|  3.89k|        nss_ZFreeIf(node);
  258|  3.89k|        if (--list->count == 0) {
  ------------------
  |  Branch (258:13): [True: 3.66k, False: 230]
  ------------------
  259|  3.66k|            list->head = NULL;
  260|  3.66k|        }
  261|  3.89k|    }
  262|  3.89k|    NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|  3.89k|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 0, False: 3.89k]
  |  |  ------------------
  |  |   44|  3.89k|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  263|  3.89k|    return PR_SUCCESS;
  264|  3.89k|}
nssList_Count:
  278|  15.6k|{
  279|  15.6k|    return list->count;
  280|  15.6k|}
nssList_GetArray:
  284|  11.9k|{
  285|  11.9k|    nssListElement *node;
  286|  11.9k|    PRUint32 i = 0;
  287|  11.9k|    PR_ASSERT(maxElements > 0);
  ------------------
  |  |  208|  11.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 11.9k, False: 0]
  |  |  ------------------
  ------------------
  288|  11.9k|    node = list->head;
  289|  11.9k|    if (!node) {
  ------------------
  |  Branch (289:9): [True: 0, False: 11.9k]
  ------------------
  290|      0|        return PR_SUCCESS;
  291|      0|    }
  292|  11.9k|    NSSLIST_LOCK_IF(list);
  ------------------
  |  |   39|  11.9k|    if ((list)->lock)         \
  |  |  ------------------
  |  |  |  Branch (39:9): [True: 11.7k, False: 230]
  |  |  ------------------
  |  |   40|  11.9k|    PZ_Lock((list)->lock)
  |  |  ------------------
  |  |  |  |  245|  11.7k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  293|  23.6k|    while (node) {
  ------------------
  |  Branch (293:12): [True: 23.6k, False: 0]
  ------------------
  294|  23.6k|        rvArray[i++] = node->data;
  295|  23.6k|        if (i == maxElements)
  ------------------
  |  Branch (295:13): [True: 11.9k, False: 11.7k]
  ------------------
  296|  11.9k|            break;
  297|  11.7k|        node = (nssListElement *)PR_NEXT_LINK(&node->link);
  ------------------
  |  |   47|  11.7k|        ((_e)->next)
  ------------------
  298|  11.7k|        if (node == list->head) {
  ------------------
  |  Branch (298:13): [True: 0, False: 11.7k]
  ------------------
  299|      0|            break;
  300|      0|        }
  301|  11.7k|    }
  302|  11.9k|    NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|  11.9k|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 11.7k, False: 230]
  |  |  ------------------
  |  |   44|  11.9k|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|  11.7k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  303|  11.9k|    return PR_SUCCESS;
  304|  11.9k|}
nssList_Clone:
  308|      1|{
  309|      1|    nssList *rvList;
  310|      1|    nssListElement *node;
  311|      1|    rvList = nssList_Create(NULL, (list->lock != NULL));
  312|      1|    if (!rvList) {
  ------------------
  |  Branch (312:9): [True: 0, False: 1]
  ------------------
  313|      0|        return NULL;
  314|      0|    }
  315|      1|    NSSLIST_LOCK_IF(list);
  ------------------
  |  |   39|      1|    if ((list)->lock)         \
  |  |  ------------------
  |  |  |  Branch (39:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   40|      1|    PZ_Lock((list)->lock)
  |  |  ------------------
  |  |  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  316|      1|    if (list->count > 0) {
  ------------------
  |  Branch (316:9): [True: 1, False: 0]
  ------------------
  317|      1|        node = list->head;
  318|      2|        while (PR_TRUE) {
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  |  |  ------------------
  |  |  |  Branch (437:17): [Folded - Ignored]
  |  |  ------------------
  ------------------
  319|      2|            nssList_Add(rvList, node->data);
  320|      2|            node = (nssListElement *)PR_NEXT_LINK(&node->link);
  ------------------
  |  |   47|      2|        ((_e)->next)
  ------------------
  321|      2|            if (node == list->head) {
  ------------------
  |  Branch (321:17): [True: 1, False: 1]
  ------------------
  322|      1|                break;
  323|      1|            }
  324|      2|        }
  325|      1|    }
  326|      1|    NSSLIST_UNLOCK_IF(list);
  ------------------
  |  |   43|      1|    if ((list)->lock)           \
  |  |  ------------------
  |  |  |  Branch (43:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   44|      1|    PZ_Unlock((list)->lock)
  |  |  ------------------
  |  |  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  327|      1|    return rvList;
  328|      1|}
nssList_CreateIterator:
  332|      1|{
  333|      1|    nssListIterator *rvIterator;
  334|      1|    rvIterator = nss_ZNEW(NULL, nssListIterator);
  ------------------
  |  |  348|      1|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  335|      1|    if (!rvIterator) {
  ------------------
  |  Branch (335:9): [True: 0, False: 1]
  ------------------
  336|      0|        return NULL;
  337|      0|    }
  338|      1|    rvIterator->list = nssList_Clone(list);
  339|      1|    if (!rvIterator->list) {
  ------------------
  |  Branch (339:9): [True: 0, False: 1]
  ------------------
  340|      0|        nss_ZFreeIf(rvIterator);
  341|      0|        return NULL;
  342|      0|    }
  343|      1|    rvIterator->current = rvIterator->list->head;
  344|      1|    if (list->lock) {
  ------------------
  |  Branch (344:9): [True: 1, False: 0]
  ------------------
  345|      1|        rvIterator->lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  346|      1|        if (!rvIterator->lock) {
  ------------------
  |  Branch (346:13): [True: 0, False: 1]
  ------------------
  347|      0|            nssList_Destroy(rvIterator->list);
  348|      0|            nss_ZFreeIf(rvIterator);
  349|      0|            rvIterator = NULL;
  350|      0|        }
  351|      1|    }
  352|      1|    return rvIterator;
  353|      1|}
nssListIterator_Destroy:
  357|      1|{
  358|      1|    if (iter->lock) {
  ------------------
  |  Branch (358:9): [True: 1, False: 0]
  ------------------
  359|      1|        (void)PZ_DestroyLock(iter->lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  360|      1|    }
  361|      1|    if (iter->list) {
  ------------------
  |  Branch (361:9): [True: 1, False: 0]
  ------------------
  362|      1|        nssList_Destroy(iter->list);
  363|      1|    }
  364|      1|    nss_ZFreeIf(iter);
  365|      1|}
list.c:pointer_compare:
   48|  4.30k|{
   49|  4.30k|    return (PRBool)(a == b);
   50|  4.30k|}
list.c:nsslist_add_element:
  179|  3.89k|{
  180|  3.89k|    nssListElement *node = nss_ZNEW(list->arena, nssListElement);
  ------------------
  |  |  348|  3.89k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  181|  3.89k|    if (!node) {
  ------------------
  |  Branch (181:9): [True: 0, False: 3.89k]
  ------------------
  182|      0|        return PR_FAILURE;
  183|      0|    }
  184|  3.89k|    PR_INIT_CLIST(&node->link);
  ------------------
  |  |  100|  7.79k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  3.89k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  7.79k|    (_l)->next = (_l); \
  |  |  102|  7.79k|    (_l)->prev = (_l); \
  |  |  103|  7.79k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  3.89k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  185|  3.89k|    node->data = data;
  186|  3.89k|    if (list->head) {
  ------------------
  |  Branch (186:9): [True: 232, False: 3.66k]
  ------------------
  187|    232|        if (list->sortFunc) {
  ------------------
  |  Branch (187:13): [True: 230, False: 2]
  ------------------
  188|    230|            PRCList *link;
  189|    230|            nssListElement *currNode;
  190|    230|            currNode = list->head;
  191|       |            /* insert in ordered list */
  192|    230|            while (currNode) {
  ------------------
  |  Branch (192:20): [True: 230, False: 0]
  ------------------
  193|    230|                link = &currNode->link;
  194|    230|                if (list->sortFunc(data, currNode->data) <= 0) {
  ------------------
  |  Branch (194:21): [True: 49, False: 181]
  ------------------
  195|       |                    /* new element goes before current node */
  196|     49|                    PR_INSERT_BEFORE(&node->link, link);
  ------------------
  |  |   25|     49|    PR_BEGIN_MACRO       \
  |  |  ------------------
  |  |  |  |  123|     49|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   26|     49|    (_e)->next = (_l);   \
  |  |   27|     49|    (_e)->prev = (_l)->prev; \
  |  |   28|     49|    (_l)->prev->next = (_e); \
  |  |   29|     49|    (_l)->prev = (_e);   \
  |  |   30|     49|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|     49|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  197|       |                    /* reset head if this is first */
  198|     49|                    if (currNode == list->head)
  ------------------
  |  Branch (198:25): [True: 49, False: 0]
  ------------------
  199|     49|                        list->head = node;
  200|     49|                    break;
  201|     49|                }
  202|    181|                if (link == PR_LIST_TAIL(&list->head->link)) {
  ------------------
  |  |   66|    181|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
  |  Branch (202:21): [True: 181, False: 0]
  ------------------
  203|       |                    /* reached end of list, append */
  204|    181|                    PR_INSERT_AFTER(&node->link, link);
  ------------------
  |  |   36|    181|    PR_BEGIN_MACRO       \
  |  |  ------------------
  |  |  |  |  123|    181|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   37|    181|    (_e)->next = (_l)->next; \
  |  |   38|    181|    (_e)->prev = (_l);   \
  |  |   39|    181|    (_l)->next->prev = (_e); \
  |  |   40|    181|    (_l)->next = (_e);   \
  |  |   41|    181|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|    181|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  205|    181|                    break;
  206|    181|                }
  207|      0|                currNode = (nssListElement *)PR_NEXT_LINK(&currNode->link);
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  208|      0|            }
  209|    230|        } else {
  210|       |            /* not sorting */
  211|      2|            PR_APPEND_LINK(&node->link, &list->head->link);
  ------------------
  |  |   57|      2|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|      2|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|      2|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|      2|    (_e)->next = (_l);   \
  |  |  |  |   27|      2|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|      2|    (_l)->prev->next = (_e); \
  |  |  |  |   29|      2|    (_l)->prev = (_e);   \
  |  |  |  |   30|      2|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|      2|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  212|      2|        }
  213|  3.66k|    } else {
  214|  3.66k|        list->head = node;
  215|  3.66k|    }
  216|  3.89k|    ++list->count;
  217|  3.89k|    return PR_SUCCESS;
  218|  3.89k|}
list.c:nsslist_get_matching_element:
   54|  4.12k|{
   55|  4.12k|    nssListElement *node;
   56|  4.12k|    node = list->head;
   57|  4.12k|    if (!node) {
  ------------------
  |  Branch (57:9): [True: 0, False: 4.12k]
  ------------------
   58|      0|        return NULL;
   59|      0|    }
   60|  4.30k|    while (node) {
  ------------------
  |  Branch (60:12): [True: 4.30k, False: 0]
  ------------------
   61|       |        /* using a callback slows things down when it's just compare ... */
   62|  4.30k|        if (list->compareFunc(node->data, data)) {
  ------------------
  |  Branch (62:13): [True: 3.89k, False: 411]
  ------------------
   63|  3.89k|            break;
   64|  3.89k|        }
   65|    411|        if (&node->link == PR_LIST_TAIL(&list->head->link)) {
  ------------------
  |  |   66|    411|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
  |  Branch (65:13): [True: 230, False: 181]
  ------------------
   66|    230|            node = NULL;
   67|    230|            break;
   68|    230|        }
   69|    181|        node = (nssListElement *)PR_NEXT_LINK(&node->link);
  ------------------
  |  |   47|    181|        ((_e)->next)
  ------------------
   70|    181|    }
   71|  4.12k|    return node;
   72|  4.12k|}

nssPointerTracker_initialize:
   85|  27.1k|{
   86|  27.1k|    PRStatus rv = PR_CallOnceWithArg(&tracker->once, trackerOnceFunc, tracker);
   87|  27.1k|    if (PR_SUCCESS != rv) {
  ------------------
  |  Branch (87:9): [True: 0, False: 27.1k]
  ------------------
   88|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
   89|      0|    }
   90|       |
   91|  27.1k|    return rv;
   92|  27.1k|}
nssPointerTracker_finalize:
  147|      1|{
  148|      1|    PZLock *lock;
  ------------------
  |  |  185|      1|#define PZLock PRLock
  ------------------
  149|       |
  150|      1|    if ((nssPointerTracker *)NULL == tracker) {
  ------------------
  |  Branch (150:9): [True: 0, False: 1]
  ------------------
  151|      0|        nss_SetError(NSS_ERROR_INVALID_POINTER);
  152|      0|        return PR_FAILURE;
  153|      0|    }
  154|       |
  155|      1|    if ((PZLock *)NULL == tracker->lock) {
  ------------------
  |  Branch (155:9): [True: 0, False: 1]
  ------------------
  156|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  157|      0|        return PR_FAILURE;
  158|      0|    }
  159|       |
  160|      1|    lock = tracker->lock;
  161|      1|    PZ_Lock(lock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  162|       |
  163|      1|    if ((PLHashTable *)NULL == tracker->table) {
  ------------------
  |  Branch (163:9): [True: 0, False: 1]
  ------------------
  164|      0|        PZ_Unlock(lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  165|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  166|      0|        return PR_FAILURE;
  167|      0|    }
  168|       |
  169|       |#ifdef DONT_DESTROY_EMPTY_TABLES
  170|       |    /*
  171|       |     * I changed my mind; I think we don't want this after all.
  172|       |     * Comments?
  173|       |     */
  174|       |    count = PL_HashTableEnumerateEntries(tracker->table, count_entries,
  175|       |                                         (void *)NULL);
  176|       |
  177|       |    if (0 != count) {
  178|       |        PZ_Unlock(lock);
  179|       |        nss_SetError(NSS_ERROR_TRACKER_NOT_EMPTY);
  180|       |        return PR_FAILURE;
  181|       |    }
  182|       |#endif /* DONT_DESTROY_EMPTY_TABLES */
  183|       |
  184|      1|    PL_HashTableDestroy(tracker->table);
  185|       |    /* memset(tracker, 0, sizeof(nssPointerTracker)); */
  186|      1|    tracker->once = zero_once;
  187|      1|    tracker->lock = (PZLock *)NULL;
  188|      1|    tracker->table = (PLHashTable *)NULL;
  189|       |
  190|      1|    PZ_Unlock(lock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  191|      1|    PZ_DestroyLock(lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  192|       |
  193|      1|    return PR_SUCCESS;
  194|      1|}
nssPointerTracker_add:
  221|  7.74k|{
  222|  7.74k|    void *check;
  223|  7.74k|    PLHashEntry *entry;
  224|       |
  225|  7.74k|    if ((nssPointerTracker *)NULL == tracker) {
  ------------------
  |  Branch (225:9): [True: 0, False: 7.74k]
  ------------------
  226|      0|        nss_SetError(NSS_ERROR_INVALID_POINTER);
  227|      0|        return PR_FAILURE;
  228|      0|    }
  229|       |
  230|  7.74k|    if ((PZLock *)NULL == tracker->lock) {
  ------------------
  |  Branch (230:9): [True: 0, False: 7.74k]
  ------------------
  231|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  232|      0|        return PR_FAILURE;
  233|      0|    }
  234|       |
  235|  7.74k|    PZ_Lock(tracker->lock);
  ------------------
  |  |  245|  7.74k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  236|       |
  237|  7.74k|    if ((PLHashTable *)NULL == tracker->table) {
  ------------------
  |  Branch (237:9): [True: 0, False: 7.74k]
  ------------------
  238|      0|        PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  239|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  240|      0|        return PR_FAILURE;
  241|      0|    }
  242|       |
  243|  7.74k|    check = PL_HashTableLookup(tracker->table, pointer);
  244|  7.74k|    if ((void *)NULL != check) {
  ------------------
  |  Branch (244:9): [True: 0, False: 7.74k]
  ------------------
  245|      0|        PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  246|      0|        nss_SetError(NSS_ERROR_DUPLICATE_POINTER);
  247|      0|        return PR_FAILURE;
  248|      0|    }
  249|       |
  250|  7.74k|    entry = PL_HashTableAdd(tracker->table, pointer, (void *)pointer);
  251|       |
  252|  7.74k|    PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|  7.74k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  253|       |
  254|  7.74k|    if ((PLHashEntry *)NULL == entry) {
  ------------------
  |  Branch (254:9): [True: 0, False: 7.74k]
  ------------------
  255|      0|        nss_SetError(NSS_ERROR_NO_MEMORY);
  256|      0|        return PR_FAILURE;
  257|      0|    }
  258|       |
  259|  7.74k|    return PR_SUCCESS;
  260|  7.74k|}
nssPointerTracker_remove:
  287|  7.74k|{
  288|  7.74k|    PRBool registered;
  289|       |
  290|  7.74k|    if ((nssPointerTracker *)NULL == tracker) {
  ------------------
  |  Branch (290:9): [True: 0, False: 7.74k]
  ------------------
  291|      0|        nss_SetError(NSS_ERROR_INVALID_POINTER);
  292|      0|        return PR_FAILURE;
  293|      0|    }
  294|       |
  295|  7.74k|    if ((PZLock *)NULL == tracker->lock) {
  ------------------
  |  Branch (295:9): [True: 0, False: 7.74k]
  ------------------
  296|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  297|      0|        return PR_FAILURE;
  298|      0|    }
  299|       |
  300|  7.74k|    PZ_Lock(tracker->lock);
  ------------------
  |  |  245|  7.74k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  301|       |
  302|  7.74k|    if ((PLHashTable *)NULL == tracker->table) {
  ------------------
  |  Branch (302:9): [True: 0, False: 7.74k]
  ------------------
  303|      0|        PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  304|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  305|      0|        return PR_FAILURE;
  306|      0|    }
  307|       |
  308|  7.74k|    registered = PL_HashTableRemove(tracker->table, pointer);
  309|  7.74k|    PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|  7.74k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  310|       |
  311|  7.74k|    if (!registered) {
  ------------------
  |  Branch (311:9): [True: 0, False: 7.74k]
  ------------------
  312|      0|        nss_SetError(NSS_ERROR_POINTER_NOT_REGISTERED);
  313|      0|        return PR_FAILURE;
  314|      0|    }
  315|       |
  316|  7.74k|    return PR_SUCCESS;
  317|  7.74k|}
nssPointerTracker_verify:
  346|  19.4k|{
  347|  19.4k|    void *check;
  348|       |
  349|  19.4k|    if ((nssPointerTracker *)NULL == tracker) {
  ------------------
  |  Branch (349:9): [True: 0, False: 19.4k]
  ------------------
  350|      0|        nss_SetError(NSS_ERROR_INVALID_POINTER);
  351|      0|        return PR_FAILURE;
  352|      0|    }
  353|       |
  354|  19.4k|    if ((PZLock *)NULL == tracker->lock) {
  ------------------
  |  Branch (354:9): [True: 0, False: 19.4k]
  ------------------
  355|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  356|      0|        return PR_FAILURE;
  357|      0|    }
  358|       |
  359|  19.4k|    PZ_Lock(tracker->lock);
  ------------------
  |  |  245|  19.4k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  360|       |
  361|  19.4k|    if ((PLHashTable *)NULL == tracker->table) {
  ------------------
  |  Branch (361:9): [True: 0, False: 19.4k]
  ------------------
  362|      0|        PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  363|      0|        nss_SetError(NSS_ERROR_TRACKER_NOT_INITIALIZED);
  364|      0|        return PR_FAILURE;
  365|      0|    }
  366|       |
  367|  19.4k|    check = PL_HashTableLookup(tracker->table, pointer);
  368|  19.4k|    PZ_Unlock(tracker->lock);
  ------------------
  |  |  246|  19.4k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  369|       |
  370|  19.4k|    if ((void *)NULL == check) {
  ------------------
  |  Branch (370:9): [True: 0, False: 19.4k]
  ------------------
  371|      0|        nss_SetError(NSS_ERROR_POINTER_NOT_REGISTERED);
  372|      0|        return PR_FAILURE;
  373|      0|    }
  374|       |
  375|  19.4k|    return PR_SUCCESS;
  376|  19.4k|}
tracker.c:trackerOnceFunc:
   42|      1|{
   43|      1|    nssPointerTracker *tracker = (nssPointerTracker *)arg;
   44|       |
   45|      1|    tracker->lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   46|      1|    if ((PZLock *)NULL == tracker->lock) {
  ------------------
  |  Branch (46:9): [True: 0, False: 1]
  ------------------
   47|      0|        return PR_FAILURE;
   48|      0|    }
   49|       |
   50|      1|    tracker->table =
   51|      1|        PL_NewHashTable(0, identity_hash, PL_CompareValues, PL_CompareValues,
   52|      1|                        (PLHashAllocOps *)NULL, (void *)NULL);
   53|      1|    if ((PLHashTable *)NULL == tracker->table) {
  ------------------
  |  Branch (53:9): [True: 0, False: 1]
  ------------------
   54|      0|        PZ_DestroyLock(tracker->lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   55|      0|        tracker->lock = (PZLock *)NULL;
   56|      0|        return PR_FAILURE;
   57|      0|    }
   58|       |
   59|      1|    return PR_SUCCESS;
   60|      1|}
tracker.c:identity_hash:
   28|  42.6k|{
   29|  42.6k|    return (PLHashNumber)((char *)key - (char *)NULL);
   30|  42.6k|}

nssUTF8_Duplicate:
  193|      4|{
  194|      4|    NSSUTF8 *rv;
  195|      4|    PRUint32 len;
  196|       |
  197|       |#ifdef NSSDEBUG
  198|       |    if ((const NSSUTF8 *)NULL == s) {
  199|       |        nss_SetError(NSS_ERROR_INVALID_POINTER);
  200|       |        return (NSSUTF8 *)NULL;
  201|       |    }
  202|       |
  203|       |    if ((NSSArena *)NULL != arenaOpt) {
  204|       |        if (PR_SUCCESS != nssArena_verifyPointer(arenaOpt)) {
  205|       |            return (NSSUTF8 *)NULL;
  206|       |        }
  207|       |    }
  208|       |#endif /* NSSDEBUG */
  209|       |
  210|      4|    len = PL_strlen((const char *)s);
  211|       |#ifdef PEDANTIC
  212|       |    if ('\0' != ((const char *)s)[len]) {
  213|       |        /* must have wrapped, e.g., too big for PRUint32 */
  214|       |        nss_SetError(NSS_ERROR_NO_MEMORY);
  215|       |        return (NSSUTF8 *)NULL;
  216|       |    }
  217|       |#endif     /* PEDANTIC */
  218|      4|    len++; /* zero termination */
  219|       |
  220|      4|    rv = nss_ZAlloc(arenaOpt, len);
  221|      4|    if ((void *)NULL == rv) {
  ------------------
  |  Branch (221:9): [True: 0, False: 4]
  ------------------
  222|      0|        return (NSSUTF8 *)NULL;
  223|      0|    }
  224|       |
  225|      4|    (void)nsslibc_memcpy(rv, s, len);
  226|      4|    return rv;
  227|      4|}
nssUTF8_Create:
  429|     68|{
  430|     68|    NSSUTF8 *rv = NULL;
  431|       |
  432|       |#ifdef NSSDEBUG
  433|       |    if ((NSSArena *)NULL != arenaOpt) {
  434|       |        if (PR_SUCCESS != nssArena_verifyPointer(arenaOpt)) {
  435|       |            return (NSSUTF8 *)NULL;
  436|       |        }
  437|       |    }
  438|       |
  439|       |    if ((const void *)NULL == inputString) {
  440|       |        nss_SetError(NSS_ERROR_INVALID_POINTER);
  441|       |        return (NSSUTF8 *)NULL;
  442|       |    }
  443|       |#endif /* NSSDEBUG */
  444|       |
  445|     68|    switch (type) {
  446|      0|        case nssStringType_DirectoryString:
  ------------------
  |  Branch (446:9): [True: 0, False: 68]
  ------------------
  447|       |            /* This is a composite type requiring BER */
  448|      0|            nss_SetError(NSS_ERROR_UNSUPPORTED_TYPE);
  449|      0|            break;
  450|      0|        case nssStringType_TeletexString:
  ------------------
  |  Branch (450:9): [True: 0, False: 68]
  ------------------
  451|       |            /*
  452|       |             * draft-ietf-pkix-ipki-part1-11 says in part:
  453|       |             *
  454|       |             * In addition, many legacy implementations support names encoded
  455|       |             * in the ISO 8859-1 character set (Latin1String) but tag them as
  456|       |             * TeletexString.  The Latin1String includes characters used in
  457|       |             * Western European countries which are not part of the
  458|       |             * TeletexString charcter set.  Implementations that process
  459|       |             * TeletexString SHOULD be prepared to handle the entire ISO
  460|       |             * 8859-1 character set.[ISO 8859-1].
  461|       |             */
  462|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR); /* unimplemented */
  463|      0|            break;
  464|     68|        case nssStringType_PrintableString:
  ------------------
  |  Branch (464:9): [True: 68, False: 0]
  ------------------
  465|       |            /*
  466|       |             * PrintableString consists of A-Za-z0-9 ,()+,-./:=?
  467|       |             * This is a subset of ASCII, which is a subset of UTF8.
  468|       |             * So we can just duplicate the string over.
  469|       |             */
  470|       |
  471|     68|            if (0 == size) {
  ------------------
  |  Branch (471:17): [True: 0, False: 68]
  ------------------
  472|      0|                rv = nssUTF8_Duplicate((const NSSUTF8 *)inputString, arenaOpt);
  473|     68|            } else {
  474|     68|                rv = nss_ZAlloc(arenaOpt, size + 1);
  475|     68|                if ((NSSUTF8 *)NULL == rv) {
  ------------------
  |  Branch (475:21): [True: 0, False: 68]
  ------------------
  476|      0|                    return (NSSUTF8 *)NULL;
  477|      0|                }
  478|       |
  479|     68|                (void)nsslibc_memcpy(rv, inputString, size);
  480|     68|            }
  481|       |
  482|     68|            break;
  483|     68|        case nssStringType_UniversalString:
  ------------------
  |  Branch (483:9): [True: 0, False: 68]
  ------------------
  484|       |            /* 4-byte unicode */
  485|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR); /* unimplemented */
  486|      0|            break;
  487|      0|        case nssStringType_BMPString:
  ------------------
  |  Branch (487:9): [True: 0, False: 68]
  ------------------
  488|       |            /* Base Multilingual Plane of Unicode */
  489|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR); /* unimplemented */
  490|      0|            break;
  491|      0|        case nssStringType_UTF8String:
  ------------------
  |  Branch (491:9): [True: 0, False: 68]
  ------------------
  492|      0|            if (0 == size) {
  ------------------
  |  Branch (492:17): [True: 0, False: 0]
  ------------------
  493|      0|                rv = nssUTF8_Duplicate((const NSSUTF8 *)inputString, arenaOpt);
  494|      0|            } else {
  495|      0|                rv = nss_ZAlloc(arenaOpt, size + 1);
  496|      0|                if ((NSSUTF8 *)NULL == rv) {
  ------------------
  |  Branch (496:21): [True: 0, False: 0]
  ------------------
  497|      0|                    return (NSSUTF8 *)NULL;
  498|      0|                }
  499|       |
  500|      0|                (void)nsslibc_memcpy(rv, inputString, size);
  501|      0|            }
  502|       |
  503|      0|            break;
  504|      0|        case nssStringType_PHGString:
  ------------------
  |  Branch (504:9): [True: 0, False: 68]
  ------------------
  505|       |            /*
  506|       |             * PHGString is an IA5String (with case-insensitive comparisons).
  507|       |             * IA5 is ~almost~ ascii; ascii has dollar-sign where IA5 has
  508|       |             * currency symbol.
  509|       |             */
  510|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR); /* unimplemented */
  511|      0|            break;
  512|      0|        case nssStringType_GeneralString:
  ------------------
  |  Branch (512:9): [True: 0, False: 68]
  ------------------
  513|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR); /* unimplemented */
  514|      0|            break;
  515|      0|        default:
  ------------------
  |  Branch (515:9): [True: 0, False: 68]
  ------------------
  516|      0|            nss_SetError(NSS_ERROR_UNSUPPORTED_TYPE);
  517|      0|            break;
  518|     68|    }
  519|       |
  520|     68|    return rv;
  521|     68|}

CERT_GetOidString:
  701|  4.21k|{
  702|  4.21k|    PRUint8* stop;  /* points to first byte after OID string */
  703|  4.21k|    PRUint8* first; /* byte of an OID component integer      */
  704|  4.21k|    PRUint8* last;  /* byte of an OID component integer      */
  705|  4.21k|    char* rvString = NULL;
  706|  4.21k|    char* prefix = NULL;
  707|       |
  708|  4.21k|#define MAX_OID_LEN 1024 /* bytes */
  709|       |
  710|  4.21k|    if (oid->len > MAX_OID_LEN) {
  ------------------
  |  |  708|  4.21k|#define MAX_OID_LEN 1024 /* bytes */
  ------------------
  |  Branch (710:9): [True: 0, False: 4.21k]
  ------------------
  711|      0|        PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  712|      0|        return NULL;
  713|      0|    }
  714|       |
  715|       |    /* If the OID has length 1, we bail. */
  716|  4.21k|    if (oid->len < 2) {
  ------------------
  |  Branch (716:9): [True: 35, False: 4.17k]
  ------------------
  717|     35|        return NULL;
  718|     35|    }
  719|       |
  720|       |    /* first will point to the next sequence of bytes to decode */
  721|  4.17k|    first = (PRUint8*)oid->data;
  722|       |    /* stop points to one past the legitimate data */
  723|  4.17k|    stop = &first[oid->len];
  724|       |
  725|       |    /*
  726|       |     * Check for our pseudo-encoded single-digit OIDs
  727|       |     */
  728|  4.17k|    if ((*first == 0x80) && (2 == oid->len)) {
  ------------------
  |  Branch (728:9): [True: 126, False: 4.04k]
  |  Branch (728:29): [True: 3, False: 123]
  ------------------
  729|       |        /* Funky encoding.  The second byte is the number */
  730|      3|        rvString = PR_smprintf("%lu", (PRUint32)first[1]);
  731|      3|        if (!rvString) {
  ------------------
  |  Branch (731:13): [True: 0, False: 3]
  ------------------
  732|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  733|      0|        }
  734|      3|        return rvString;
  735|      3|    }
  736|       |
  737|  17.4k|    for (; first < stop; first = last + 1) {
  ------------------
  |  Branch (737:12): [True: 13.2k, False: 4.17k]
  ------------------
  738|  13.2k|        unsigned int bytesBeforeLast;
  739|       |
  740|  17.3k|        for (last = first; last < stop; last++) {
  ------------------
  |  Branch (740:28): [True: 16.9k, False: 345]
  ------------------
  741|  16.9k|            if (0 == (*last & 0x80)) {
  ------------------
  |  Branch (741:17): [True: 12.9k, False: 4.02k]
  ------------------
  742|  12.9k|                break;
  743|  12.9k|            }
  744|  16.9k|        }
  745|       |        /* There's no first bit set, so this isn't valid. Bail.*/
  746|  13.2k|        if (last == stop) {
  ------------------
  |  Branch (746:13): [True: 345, False: 12.9k]
  ------------------
  747|    345|            goto unsupported;
  748|    345|        }
  749|  12.9k|        bytesBeforeLast = (unsigned int)(last - first);
  750|  12.9k|        if (bytesBeforeLast <= 3U) { /* 0-28 bit number */
  ------------------
  |  Branch (750:13): [True: 12.6k, False: 311]
  ------------------
  751|  12.6k|            PRUint32 n = 0;
  752|  12.6k|            PRUint32 c;
  753|       |
  754|  12.6k|#define CGET(i, m)    \
  755|  12.6k|    c = last[-i] & m; \
  756|  12.6k|    n |= c << (7 * i)
  757|       |
  758|  12.6k|#define CASE(i, m)  \
  759|  12.6k|    case i:         \
  760|  12.6k|        CGET(i, m); \
  761|  12.6k|        if (!n)     \
  762|  12.6k|        goto unsupported /* fall-through */
  763|       |
  764|  12.6k|            switch (bytesBeforeLast) {
  ------------------
  |  Branch (764:21): [True: 0, False: 12.6k]
  ------------------
  765|    121|                CASE(3, 0x7f);
  ------------------
  |  |  759|    121|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 121, False: 12.5k]
  |  |  ------------------
  |  |  760|    121|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    121|    c = last[-i] & m; \
  |  |  |  |  756|    121|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    121|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 26, False: 95]
  |  |  ------------------
  |  |  762|    121|        goto unsupported /* fall-through */
  ------------------
  766|    319|                CASE(2, 0x7f);
  ------------------
  |  |  759|    319|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 224, False: 12.4k]
  |  |  ------------------
  |  |  760|    319|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    319|    c = last[-i] & m; \
  |  |  |  |  756|    319|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    319|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 37, False: 282]
  |  |  ------------------
  |  |  762|    319|        goto unsupported /* fall-through */
  ------------------
  767|    898|                CASE(1, 0x7f);
  ------------------
  |  |  759|    898|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 616, False: 12.0k]
  |  |  ------------------
  |  |  760|    898|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    898|    c = last[-i] & m; \
  |  |  |  |  756|    898|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    898|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 98, False: 800]
  |  |  ------------------
  |  |  762|    898|        goto unsupported /* fall-through */
  ------------------
  768|  12.4k|                case 0:
  ------------------
  |  Branch (768:17): [True: 11.6k, False: 961]
  ------------------
  769|  12.4k|                    n |= last[0] & 0x7f;
  770|  12.4k|                    break;
  771|  12.6k|            }
  772|  12.4k|            if (last[0] & 0x80) {
  ------------------
  |  Branch (772:17): [True: 0, False: 12.4k]
  ------------------
  773|      0|                goto unsupported;
  774|      0|            }
  775|       |
  776|  12.4k|            if (!rvString) {
  ------------------
  |  Branch (776:17): [True: 3.89k, False: 8.58k]
  ------------------
  777|       |                /* This is the first number.. decompose it */
  778|  3.89k|                PRUint32 one = PR_MIN(n / 40, 2); /* never > 2 */
  ------------------
  |  |  158|  3.89k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 475, False: 3.41k]
  |  |  ------------------
  ------------------
  779|  3.89k|                PRUint32 two = n - (one * 40);
  780|       |
  781|  3.89k|                rvString = PR_smprintf("OID.%lu.%lu", one, two);
  782|  8.58k|            } else {
  783|  8.58k|                prefix = rvString;
  784|  8.58k|                rvString = PR_smprintf("%s.%lu", prefix, n);
  785|  8.58k|            }
  786|  12.4k|        } else if (bytesBeforeLast <= 9U) { /* 29-64 bit number */
  ------------------
  |  Branch (786:20): [True: 299, False: 12]
  ------------------
  787|    299|            PRUint64 n = 0;
  788|    299|            PRUint64 c;
  789|       |
  790|    299|            switch (bytesBeforeLast) {
  ------------------
  |  Branch (790:21): [True: 0, False: 299]
  ------------------
  791|     67|                CASE(9, 0x01);
  ------------------
  |  |  759|     67|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 67, False: 232]
  |  |  ------------------
  |  |  760|     67|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|     67|    c = last[-i] & m; \
  |  |  |  |  756|     67|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|     67|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 9, False: 58]
  |  |  ------------------
  |  |  762|     67|        goto unsupported /* fall-through */
  ------------------
  792|     87|                CASE(8, 0x7f);
  ------------------
  |  |  759|     87|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 29, False: 270]
  |  |  ------------------
  |  |  760|     87|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|     87|    c = last[-i] & m; \
  |  |  |  |  756|     87|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|     87|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 3, False: 84]
  |  |  ------------------
  |  |  762|     87|        goto unsupported /* fall-through */
  ------------------
  793|    122|                CASE(7, 0x7f);
  ------------------
  |  |  759|    122|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 38, False: 261]
  |  |  ------------------
  |  |  760|    122|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    122|    c = last[-i] & m; \
  |  |  |  |  756|    122|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    122|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 20, False: 102]
  |  |  ------------------
  |  |  762|    122|        goto unsupported /* fall-through */
  ------------------
  794|    138|                CASE(6, 0x7f);
  ------------------
  |  |  759|    138|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 36, False: 263]
  |  |  ------------------
  |  |  760|    138|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    138|    c = last[-i] & m; \
  |  |  |  |  756|    138|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    138|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 13, False: 125]
  |  |  ------------------
  |  |  762|    138|        goto unsupported /* fall-through */
  ------------------
  795|    175|                CASE(5, 0x7f);
  ------------------
  |  |  759|    175|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 50, False: 249]
  |  |  ------------------
  |  |  760|    175|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    175|    c = last[-i] & m; \
  |  |  |  |  756|    175|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    175|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 22, False: 153]
  |  |  ------------------
  |  |  762|    175|        goto unsupported /* fall-through */
  ------------------
  796|    232|                CASE(4, 0x7f);
  ------------------
  |  |  759|    232|    case i:         \
  |  |  ------------------
  |  |  |  Branch (759:5): [True: 79, False: 220]
  |  |  ------------------
  |  |  760|    232|        CGET(i, m); \
  |  |  ------------------
  |  |  |  |  755|    232|    c = last[-i] & m; \
  |  |  |  |  756|    232|    n |= c << (7 * i)
  |  |  ------------------
  |  |  761|    232|        if (!n)     \
  |  |  ------------------
  |  |  |  Branch (761:13): [True: 25, False: 207]
  |  |  ------------------
  |  |  762|    232|        goto unsupported /* fall-through */
  ------------------
  797|    207|                CGET(3, 0x7f);
  ------------------
  |  |  755|    207|    c = last[-i] & m; \
  |  |  756|    207|    n |= c << (7 * i)
  ------------------
  798|    207|                CGET(2, 0x7f);
  ------------------
  |  |  755|    207|    c = last[-i] & m; \
  |  |  756|    207|    n |= c << (7 * i)
  ------------------
  799|    207|                CGET(1, 0x7f);
  ------------------
  |  |  755|    207|    c = last[-i] & m; \
  |  |  756|    207|    n |= c << (7 * i)
  ------------------
  800|    207|                CGET(0, 0x7f);
  ------------------
  |  |  755|    207|    c = last[-i] & m; \
  |  |  756|    207|    n |= c << (7 * i)
  ------------------
  801|    207|                break;
  802|    299|            }
  803|    207|            if (last[0] & 0x80)
  ------------------
  |  Branch (803:17): [True: 0, False: 207]
  ------------------
  804|      0|                goto unsupported;
  805|       |
  806|    207|            if (!rvString) {
  ------------------
  |  Branch (806:17): [True: 91, False: 116]
  ------------------
  807|       |                /* This is the first number.. decompose it */
  808|     91|                PRUint64 one = PR_MIN(n / 40, 2); /* never > 2 */
  ------------------
  |  |  158|     91|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 91]
  |  |  ------------------
  ------------------
  809|     91|                PRUint64 two = n - (one * 40);
  810|       |
  811|     91|                rvString = PR_smprintf("OID.%llu.%llu", one, two);
  812|    116|            } else {
  813|    116|                prefix = rvString;
  814|    116|                rvString = PR_smprintf("%s.%llu", prefix, n);
  815|    116|            }
  816|    207|        } else {
  817|       |        /* More than a 64-bit number, or not minimal encoding. */
  818|    610|        unsupported:
  819|    610|            if (!rvString)
  ------------------
  |  Branch (819:17): [True: 188, False: 422]
  ------------------
  820|    188|                rvString = PR_smprintf("OID.UNSUPPORTED");
  821|    422|            else {
  822|    422|                prefix = rvString;
  823|    422|                rvString = PR_smprintf("%s.UNSUPPORTED", prefix);
  824|    422|            }
  825|    610|        }
  826|       |
  827|  13.2k|        if (prefix) {
  ------------------
  |  Branch (827:13): [True: 9.11k, False: 4.17k]
  ------------------
  828|  9.11k|            PR_smprintf_free(prefix);
  829|  9.11k|            prefix = NULL;
  830|  9.11k|        }
  831|  13.2k|        if (!rvString) {
  ------------------
  |  Branch (831:13): [True: 0, False: 13.2k]
  ------------------
  832|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  833|      0|            break;
  834|      0|        }
  835|  13.2k|    }
  836|  4.17k|    return rvString;
  837|  4.17k|}
CERT_NameToAsciiInvertible:
 1117|  7.78k|{
 1118|  7.78k|    CERTRDN** rdns;
 1119|  7.78k|    CERTRDN** lastRdn;
 1120|  7.78k|    CERTRDN** rdn;
 1121|  7.78k|    PRBool first = PR_TRUE;
  ------------------
  |  |  437|  7.78k|#define PR_TRUE 1
  ------------------
 1122|  7.78k|    stringBuf strBuf = { NULL, 0, 0 };
 1123|       |
 1124|  7.78k|    rdns = name->rdns;
 1125|  7.78k|    if (rdns == NULL) {
  ------------------
  |  Branch (1125:9): [True: 0, False: 7.78k]
  ------------------
 1126|      0|        return NULL;
 1127|      0|    }
 1128|       |
 1129|       |    /* find last RDN */
 1130|  7.78k|    lastRdn = rdns;
 1131|  17.7k|    while (*lastRdn)
  ------------------
  |  Branch (1131:12): [True: 9.98k, False: 7.78k]
  ------------------
 1132|  9.98k|        lastRdn++;
 1133|  7.78k|    lastRdn--;
 1134|       |
 1135|       |    /*
 1136|       |     * Loop over name contents in _reverse_ RDN order appending to string
 1137|       |     */
 1138|  17.6k|    for (rdn = lastRdn; rdn >= rdns; rdn--) {
  ------------------
  |  Branch (1138:25): [True: 9.93k, False: 7.74k]
  ------------------
 1139|  9.93k|        CERTAVA** avas = (*rdn)->avas;
 1140|  9.93k|        CERTAVA* ava;
 1141|  9.93k|        PRBool newRDN = PR_TRUE;
  ------------------
  |  |  437|  9.93k|#define PR_TRUE 1
  ------------------
 1142|       |
 1143|       |        /*
 1144|       |         * XXX Do we need to traverse the AVAs in reverse order, too?
 1145|       |         */
 1146|  19.8k|        while (avas && (ava = *avas++) != NULL) {
  ------------------
  |  Branch (1146:16): [True: 19.8k, False: 0]
  |  Branch (1146:24): [True: 9.93k, False: 9.90k]
  ------------------
 1147|  9.93k|            SECStatus rv;
 1148|       |            /* Put in comma or plus separator */
 1149|  9.93k|            if (!first) {
  ------------------
  |  Branch (1149:17): [True: 2.15k, False: 7.78k]
  ------------------
 1150|       |                /* Use of spaces is deprecated in RFC 2253. */
 1151|  2.15k|                rv = AppendStr(&strBuf, newRDN ? "," : "+");
  ------------------
  |  Branch (1151:41): [True: 2.15k, False: 0]
  ------------------
 1152|  2.15k|                if (rv)
  ------------------
  |  Branch (1152:21): [True: 0, False: 2.15k]
  ------------------
 1153|      0|                    goto loser;
 1154|  7.78k|            } else {
 1155|  7.78k|                first = PR_FALSE;
  ------------------
  |  |  438|  7.78k|#define PR_FALSE 0
  ------------------
 1156|  7.78k|            }
 1157|       |
 1158|       |            /* Add in tag type plus value into strBuf */
 1159|  9.93k|            rv = AppendAVA(&strBuf, ava, strict);
 1160|  9.93k|            if (rv)
  ------------------
  |  Branch (1160:17): [True: 35, False: 9.90k]
  ------------------
 1161|     35|                goto loser;
 1162|  9.90k|            newRDN = PR_FALSE;
  ------------------
  |  |  438|  9.90k|#define PR_FALSE 0
  ------------------
 1163|  9.90k|        }
 1164|  9.93k|    }
 1165|  7.74k|    return strBuf.buffer;
 1166|     35|loser:
 1167|     35|    if (strBuf.buffer) {
  ------------------
  |  Branch (1167:9): [True: 11, False: 24]
  ------------------
 1168|     11|        PORT_Free(strBuf.buffer);
  ------------------
  |  |   60|     11|#define PORT_Free PORT_Free_Util
  ------------------
 1169|     11|    }
 1170|     35|    return NULL;
 1171|  7.78k|}
CERT_NameToAscii:
 1175|  7.78k|{
 1176|  7.78k|    return CERT_NameToAsciiInvertible(name, CERT_N2A_READABLE);
 1177|  7.78k|}
cert_GetCertificateEmailAddresses:
 1437|  3.89k|{
 1438|  3.89k|    char* rawEmailAddr = NULL;
 1439|  3.89k|    char* addrBuf = NULL;
 1440|  3.89k|    char* pBuf = NULL;
 1441|  3.89k|    PORTCheapArenaPool tmpArena;
 1442|  3.89k|    PRUint32 maxLen = 0;
 1443|  3.89k|    PRInt32 finalLen = 0;
 1444|  3.89k|    SECStatus rv;
 1445|  3.89k|    SECItem subAltName;
 1446|       |
 1447|  3.89k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  3.89k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 1448|       |
 1449|  3.89k|    subAltName.data = NULL;
 1450|  3.89k|    maxLen = cert->derCert.len;
 1451|  3.89k|    PORT_Assert(maxLen);
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.89k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.89k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1452|  3.89k|    if (!maxLen)
  ------------------
  |  Branch (1452:9): [True: 0, False: 3.89k]
  ------------------
 1453|      0|        maxLen = 2000; /* a guess, should never happen */
 1454|       |
 1455|  3.89k|    pBuf = addrBuf = (char*)PORT_ArenaZAlloc(&tmpArena.arena, maxLen + 1);
  ------------------
  |  |   59|  3.89k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 1456|  3.89k|    if (!addrBuf)
  ------------------
  |  Branch (1456:9): [True: 0, False: 3.89k]
  ------------------
 1457|      0|        goto loser;
 1458|       |
 1459|  3.89k|    rawEmailAddr = CERT_GetNameElement(&tmpArena.arena, &cert->subject,
 1460|  3.89k|                                       SEC_OID_PKCS9_EMAIL_ADDRESS);
 1461|  3.89k|    pBuf = appendStringToBuf(pBuf, rawEmailAddr, &maxLen);
 1462|       |
 1463|  3.89k|    rawEmailAddr = CERT_GetNameElement(&tmpArena.arena, &cert->subject,
 1464|  3.89k|                                       SEC_OID_RFC1274_MAIL);
 1465|  3.89k|    pBuf = appendStringToBuf(pBuf, rawEmailAddr, &maxLen);
 1466|       |
 1467|  3.89k|    rv = CERT_FindCertExtension(cert, SEC_OID_X509_SUBJECT_ALT_NAME, &subAltName);
 1468|  3.89k|    if (rv == SECSuccess && subAltName.data) {
  ------------------
  |  Branch (1468:9): [True: 70, False: 3.82k]
  |  Branch (1468:29): [True: 70, False: 0]
  ------------------
 1469|     70|        CERTGeneralName* nameList = NULL;
 1470|       |
 1471|     70|        if (!!(nameList = CERT_DecodeAltNameExtension(&tmpArena.arena, &subAltName))) {
  ------------------
  |  Branch (1471:13): [True: 30, False: 40]
  ------------------
 1472|     30|            CERTGeneralName* current = nameList;
 1473|     57|            do {
 1474|     57|                if (current->type == certDirectoryName) {
  ------------------
  |  Branch (1474:21): [True: 0, False: 57]
  ------------------
 1475|      0|                    rawEmailAddr =
 1476|      0|                        CERT_GetNameElement(&tmpArena.arena,
 1477|      0|                                            &current->name.directoryName,
 1478|      0|                                            SEC_OID_PKCS9_EMAIL_ADDRESS);
 1479|      0|                    pBuf =
 1480|      0|                        appendStringToBuf(pBuf, rawEmailAddr, &maxLen);
 1481|       |
 1482|      0|                    rawEmailAddr =
 1483|      0|                        CERT_GetNameElement(&tmpArena.arena,
 1484|      0|                                            &current->name.directoryName,
 1485|      0|                                            SEC_OID_RFC1274_MAIL);
 1486|      0|                    pBuf =
 1487|      0|                        appendStringToBuf(pBuf, rawEmailAddr, &maxLen);
 1488|     57|                } else if (current->type == certRFC822Name) {
  ------------------
  |  Branch (1488:28): [True: 32, False: 25]
  ------------------
 1489|     32|                    pBuf =
 1490|     32|                        appendItemToBuf(pBuf, &current->name.other, &maxLen);
 1491|     32|                }
 1492|     57|                current = CERT_GetNextGeneralName(current);
 1493|     57|            } while (current != nameList);
  ------------------
  |  Branch (1493:22): [True: 27, False: 30]
  ------------------
 1494|     30|        }
 1495|     70|        SECITEM_FreeItem(&subAltName, PR_FALSE);
  ------------------
  |  |  108|     70|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&subAltName, PR_FALSE);
  ------------------
  |  |  438|     70|#define PR_FALSE 0
  ------------------
 1496|       |        /* Don't free nameList, it's part of the tmpArena. */
 1497|     70|    }
 1498|       |    /* now copy superstring to cert's arena */
 1499|  3.89k|    finalLen = (pBuf - addrBuf) + 1;
 1500|  3.89k|    pBuf = NULL;
 1501|  3.89k|    if (finalLen > 1) {
  ------------------
  |  Branch (1501:9): [True: 68, False: 3.82k]
  ------------------
 1502|     68|        pBuf = PORT_ArenaAlloc(cert->arena, finalLen);
  ------------------
  |  |   53|     68|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1503|     68|        if (pBuf) {
  ------------------
  |  Branch (1503:13): [True: 68, False: 0]
  ------------------
 1504|     68|            PORT_Memcpy(pBuf, addrBuf, finalLen);
  ------------------
  |  |  180|     68|#define PORT_Memcpy memcpy
  ------------------
 1505|     68|        }
 1506|     68|    }
 1507|  3.89k|loser:
 1508|  3.89k|    PORT_DestroyCheapArena(&tmpArena);
 1509|       |
 1510|  3.89k|    return pBuf;
 1511|  3.89k|}
alg1485.c:escapeAndQuote:
  655|  4.74k|{
  656|  4.74k|    int i, reqLen = 0;
  657|  4.74k|    EQMode mode = pEQMode ? *pEQMode : minimalEscape;
  ------------------
  |  Branch (657:19): [True: 4.69k, False: 47]
  ------------------
  658|       |
  659|  4.74k|    reqLen = cert_RFC1485_GetRequiredLen(src, srclen, &mode);
  660|       |    /* reqLen is max 16384*3 + 2 */
  661|       |    /* space for terminal null */
  662|  4.74k|    if (reqLen < 0 || reqLen + 1 > dstlen) {
  ------------------
  |  Branch (662:9): [True: 0, False: 4.74k]
  |  Branch (662:23): [True: 0, False: 4.74k]
  ------------------
  663|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  664|      0|        return SECFailure;
  665|      0|    }
  666|       |
  667|  4.74k|    if (mode == minimalEscapeAndQuote)
  ------------------
  |  Branch (667:9): [True: 440, False: 4.30k]
  ------------------
  668|    440|        *dst++ = C_DOUBLE_QUOTE;
  ------------------
  |  |  117|    440|#define C_DOUBLE_QUOTE '\042'
  ------------------
  669|  50.2k|    for (i = 0; i < srclen; i++) {
  ------------------
  |  Branch (669:17): [True: 45.5k, False: 4.74k]
  ------------------
  670|  45.5k|        char c = src[i];
  671|  45.5k|        if (NEEDS_HEX_ESCAPE(c)) {
  ------------------
  |  |  155|  45.5k|#define NEEDS_HEX_ESCAPE(c) ((PRUint8)c < 0x20 || c == 0x7f)
  |  |  ------------------
  |  |  |  Branch (155:30): [True: 2.01k, False: 43.5k]
  |  |  |  Branch (155:51): [True: 89, False: 43.4k]
  |  |  ------------------
  ------------------
  672|  2.10k|            *dst++ = C_BACKSLASH;
  ------------------
  |  |  119|  2.10k|#define C_BACKSLASH '\134'
  ------------------
  673|  2.10k|            *dst++ = hexChars[(c >> 4) & 0x0f];
  674|  2.10k|            *dst++ = hexChars[c & 0x0f];
  675|  43.4k|        } else {
  676|  43.4k|            if (NEEDS_ESCAPE(c) || (SPECIAL_CHAR(c) && mode == fullEscape)) {
  ------------------
  |  |  153|  86.8k|#define NEEDS_ESCAPE(c) (c == C_DOUBLE_QUOTE || c == C_BACKSLASH)
  |  |  ------------------
  |  |  |  |  117|  86.8k|#define C_DOUBLE_QUOTE '\042'
  |  |  ------------------
  |  |               #define NEEDS_ESCAPE(c) (c == C_DOUBLE_QUOTE || c == C_BACKSLASH)
  |  |  ------------------
  |  |  |  |  119|  86.6k|#define C_BACKSLASH '\134'
  |  |  ------------------
  |  |  |  Branch (153:26): [True: 162, False: 43.2k]
  |  |  |  Branch (153:49): [True: 194, False: 43.0k]
  |  |  ------------------
  ------------------
                          if (NEEDS_ESCAPE(c) || (SPECIAL_CHAR(c) && mode == fullEscape)) {
  ------------------
  |  |  127|  86.1k|    (((c) == ',') || ((c) == '=') || ((c) == C_DOUBLE_QUOTE) ||                \
  |  |  ------------------
  |  |  |  |  117|  42.7k|#define C_DOUBLE_QUOTE '\042'
  |  |  ------------------
  |  |  |  Branch (127:6): [True: 123, False: 42.9k]
  |  |  |  Branch (127:22): [True: 218, False: 42.7k]
  |  |  |  Branch (127:38): [True: 0, False: 42.7k]
  |  |  ------------------
  |  |  128|  43.0k|     ((c) == '\r') || ((c) == '\n') || ((c) == '+') ||                         \
  |  |  ------------------
  |  |  |  Branch (128:6): [True: 0, False: 42.7k]
  |  |  |  Branch (128:23): [True: 0, False: 42.7k]
  |  |  |  Branch (128:40): [True: 131, False: 42.5k]
  |  |  ------------------
  |  |  129|  43.0k|     ((c) == '<') || ((c) == '>') || ((c) == '#') ||                           \
  |  |  ------------------
  |  |  |  Branch (129:6): [True: 267, False: 42.3k]
  |  |  |  Branch (129:22): [True: 75, False: 42.2k]
  |  |  |  Branch (129:38): [True: 292, False: 41.9k]
  |  |  ------------------
  |  |  130|  43.0k|     ((c) == ';') || ((c) == C_BACKSLASH))
  |  |  ------------------
  |  |  |  |  119|  41.7k|#define C_BACKSLASH '\134'
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 183, False: 41.7k]
  |  |  |  Branch (130:22): [True: 0, False: 41.7k]
  |  |  ------------------
  ------------------
  |  Branch (676:56): [True: 0, False: 1.28k]
  ------------------
  677|    356|                *dst++ = C_BACKSLASH;
  ------------------
  |  |  119|    356|#define C_BACKSLASH '\134'
  ------------------
  678|    356|            }
  679|  43.4k|            *dst++ = c;
  680|  43.4k|        }
  681|  45.5k|    }
  682|  4.74k|    if (mode == minimalEscapeAndQuote)
  ------------------
  |  Branch (682:9): [True: 440, False: 4.30k]
  ------------------
  683|    440|        *dst++ = C_DOUBLE_QUOTE;
  ------------------
  |  |  117|    440|#define C_DOUBLE_QUOTE '\042'
  ------------------
  684|  4.74k|    *dst++ = 0;
  685|  4.74k|    if (pEQMode)
  ------------------
  |  Branch (685:9): [True: 4.69k, False: 47]
  ------------------
  686|  4.69k|        *pEQMode = mode;
  687|  4.74k|    return SECSuccess;
  688|  4.74k|}
alg1485.c:cert_RFC1485_GetRequiredLen:
  608|  9.48k|{
  609|  9.48k|    int i, reqLen = 0;
  610|  9.48k|    EQMode mode = pEQMode ? *pEQMode : minimalEscape;
  ------------------
  |  Branch (610:19): [True: 9.43k, False: 47]
  ------------------
  611|  9.48k|    PRBool needsQuoting = PR_FALSE;
  ------------------
  |  |  438|  9.48k|#define PR_FALSE 0
  ------------------
  612|  9.48k|    char lastC = 0;
  613|       |
  614|       |    /* avoids needing to check for overflow */
  615|  9.48k|    if (srclen > 16384) {
  ------------------
  |  Branch (615:9): [True: 0, False: 9.48k]
  ------------------
  616|      0|        return -1;
  617|      0|    }
  618|       |    /* need to make an initial pass to determine if quoting is needed */
  619|   101k|    for (i = 0; i < srclen; i++) {
  ------------------
  |  Branch (619:17): [True: 91.8k, False: 9.48k]
  ------------------
  620|  91.8k|        char c = src[i];
  621|  91.8k|        reqLen++;
  622|  91.8k|        if (NEEDS_HEX_ESCAPE(c)) { /* c -> \xx  */
  ------------------
  |  |  155|  91.8k|#define NEEDS_HEX_ESCAPE(c) ((PRUint8)c < 0x20 || c == 0x7f)
  |  |  ------------------
  |  |  |  Branch (155:30): [True: 4.11k, False: 87.7k]
  |  |  |  Branch (155:51): [True: 180, False: 87.6k]
  |  |  ------------------
  ------------------
  623|  4.29k|            reqLen += 2;
  624|  87.6k|        } else if (NEEDS_ESCAPE(c)) { /* c -> \c   */
  ------------------
  |  |  153|  87.6k|#define NEEDS_ESCAPE(c) (c == C_DOUBLE_QUOTE || c == C_BACKSLASH)
  |  |  ------------------
  |  |  |  |  117|   175k|#define C_DOUBLE_QUOTE '\042'
  |  |  ------------------
  |  |               #define NEEDS_ESCAPE(c) (c == C_DOUBLE_QUOTE || c == C_BACKSLASH)
  |  |  ------------------
  |  |  |  |  119|   174k|#define C_BACKSLASH '\134'
  |  |  ------------------
  |  |  |  Branch (153:26): [True: 328, False: 87.2k]
  |  |  |  Branch (153:49): [True: 389, False: 86.8k]
  |  |  ------------------
  ------------------
  625|    717|            reqLen++;
  626|  86.8k|        } else if (SPECIAL_CHAR(c)) {
  ------------------
  |  |  127|  86.8k|    (((c) == ',') || ((c) == '=') || ((c) == C_DOUBLE_QUOTE) ||                \
  |  |  ------------------
  |  |  |  |  117|  86.1k|#define C_DOUBLE_QUOTE '\042'
  |  |  ------------------
  |  |  |  Branch (127:6): [True: 256, False: 86.6k]
  |  |  |  Branch (127:22): [True: 437, False: 86.1k]
  |  |  |  Branch (127:38): [True: 0, False: 86.1k]
  |  |  ------------------
  |  |  128|  86.8k|     ((c) == '\r') || ((c) == '\n') || ((c) == '+') ||                         \
  |  |  ------------------
  |  |  |  Branch (128:6): [True: 0, False: 86.1k]
  |  |  |  Branch (128:23): [True: 0, False: 86.1k]
  |  |  |  Branch (128:40): [True: 265, False: 85.9k]
  |  |  ------------------
  |  |  129|  86.8k|     ((c) == '<') || ((c) == '>') || ((c) == '#') ||                           \
  |  |  ------------------
  |  |  |  Branch (129:6): [True: 536, False: 85.3k]
  |  |  |  Branch (129:22): [True: 151, False: 85.2k]
  |  |  |  Branch (129:38): [True: 588, False: 84.6k]
  |  |  ------------------
  |  |  130|  86.8k|     ((c) == ';') || ((c) == C_BACKSLASH))
  |  |  ------------------
  |  |  |  |  119|  84.2k|#define C_BACKSLASH '\134'
  |  |  ------------------
  |  |  |  Branch (130:6): [True: 370, False: 84.2k]
  |  |  |  Branch (130:22): [True: 0, False: 84.2k]
  |  |  ------------------
  ------------------
  627|  2.60k|            if (mode == minimalEscapeAndQuote) /* quoting is allowed */
  ------------------
  |  Branch (627:17): [True: 2.22k, False: 376]
  ------------------
  628|  2.22k|                needsQuoting = PR_TRUE;        /* entirety will need quoting */
  ------------------
  |  |  437|  2.22k|#define PR_TRUE 1
  ------------------
  629|    376|            else if (mode == fullEscape)
  ------------------
  |  Branch (629:22): [True: 0, False: 376]
  ------------------
  630|      0|                reqLen++; /* MAY escape this character */
  631|  84.2k|        } else if (OPTIONAL_SPACE(c) && OPTIONAL_SPACE(lastC)) {
  ------------------
  |  |  124|   168k|    (((c) == ' ') || ((c) == '\r') || ((c) == '\n'))
  |  |  ------------------
  |  |  |  Branch (124:6): [True: 4.22k, False: 80.0k]
  |  |  |  Branch (124:22): [True: 0, False: 80.0k]
  |  |  |  Branch (124:39): [True: 0, False: 80.0k]
  |  |  ------------------
  ------------------
                      } else if (OPTIONAL_SPACE(c) && OPTIONAL_SPACE(lastC)) {
  ------------------
  |  |  124|  4.22k|    (((c) == ' ') || ((c) == '\r') || ((c) == '\n'))
  |  |  ------------------
  |  |  |  Branch (124:6): [True: 481, False: 3.74k]
  |  |  |  Branch (124:22): [True: 70, False: 3.67k]
  |  |  |  Branch (124:39): [True: 40, False: 3.63k]
  |  |  ------------------
  ------------------
  632|    591|            if (mode == minimalEscapeAndQuote) /* quoting is allowed */
  ------------------
  |  Branch (632:17): [True: 381, False: 210]
  ------------------
  633|    381|                needsQuoting = PR_TRUE;        /* entirety will need quoting */
  ------------------
  |  |  437|    381|#define PR_TRUE 1
  ------------------
  634|    591|        }
  635|  91.8k|        lastC = c;
  636|  91.8k|    }
  637|       |    /* if it begins or ends in optional space it needs quoting */
  638|  9.48k|    if (!needsQuoting && srclen > 0 && mode == minimalEscapeAndQuote &&
  ------------------
  |  Branch (638:9): [True: 8.68k, False: 800]
  |  Branch (638:26): [True: 8.60k, False: 78]
  |  Branch (638:40): [True: 4.31k, False: 4.28k]
  ------------------
  639|  9.48k|        (OPTIONAL_SPACE(src[srclen - 1]) || OPTIONAL_SPACE(src[0]))) {
  ------------------
  |  |  124|  8.63k|    (((c) == ' ') || ((c) == '\r') || ((c) == '\n'))
  |  |  ------------------
  |  |  |  Branch (124:6): [True: 53, False: 4.26k]
  |  |  |  Branch (124:22): [True: 22, False: 4.24k]
  |  |  |  Branch (124:39): [True: 6, False: 4.23k]
  |  |  ------------------
  ------------------
                      (OPTIONAL_SPACE(src[srclen - 1]) || OPTIONAL_SPACE(src[0]))) {
  ------------------
  |  |  124|  4.23k|    (((c) == ' ') || ((c) == '\r') || ((c) == '\n'))
  |  |  ------------------
  |  |  |  Branch (124:6): [True: 7, False: 4.22k]
  |  |  |  Branch (124:22): [True: 7, False: 4.22k]
  |  |  |  Branch (124:39): [True: 6, False: 4.21k]
  |  |  ------------------
  ------------------
  640|    101|        needsQuoting = PR_TRUE;
  ------------------
  |  |  437|    101|#define PR_TRUE 1
  ------------------
  641|    101|    }
  642|       |
  643|  9.48k|    if (needsQuoting)
  ------------------
  |  Branch (643:9): [True: 901, False: 8.58k]
  ------------------
  644|    901|        reqLen += 2;
  645|  9.48k|    if (pEQMode && mode == minimalEscapeAndQuote && !needsQuoting)
  ------------------
  |  Branch (645:9): [True: 9.43k, False: 47]
  |  Branch (645:20): [True: 5.15k, False: 4.28k]
  |  Branch (645:53): [True: 4.25k, False: 901]
  ------------------
  646|  4.25k|        *pEQMode = minimalEscape;
  647|       |    /* Maximum output size would be 3*srclen+2 */
  648|  9.48k|    return reqLen;
  649|  9.48k|}
alg1485.c:AppendStr:
  554|  12.0k|{
  555|  12.0k|    char* buf;
  556|  12.0k|    unsigned bufLen, bufSize, len;
  557|  12.0k|    int size = 0;
  558|       |
  559|       |    /* Figure out how much to grow buf by (add in the '\0') */
  560|  12.0k|    buf = bufp->buffer;
  561|  12.0k|    bufLen = bufp->offset;
  562|  12.0k|    len = PORT_Strlen(str);
  ------------------
  |  |  190|  12.0k|#define PORT_Strlen(s) strlen(s)
  ------------------
  563|  12.0k|    bufSize = bufLen + len;
  564|  12.0k|    if (!buf) {
  ------------------
  |  Branch (564:9): [True: 7.75k, False: 4.29k]
  ------------------
  565|  7.75k|        bufSize++;
  566|  7.75k|        size = PR_MAX(DEFAULT_BUFFER_SIZE, bufSize * 2);
  ------------------
  |  |  159|  7.75k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 7.75k, False: 6]
  |  |  ------------------
  ------------------
  567|  7.75k|        buf = (char*)PORT_Alloc(size);
  ------------------
  |  |   52|  7.75k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  568|  7.75k|        bufp->size = size;
  569|  7.75k|    } else if (bufp->size < bufSize) {
  ------------------
  |  Branch (569:16): [True: 0, False: 4.29k]
  ------------------
  570|      0|        size = bufSize * 2;
  571|      0|        buf = (char*)PORT_Realloc(buf, size);
  ------------------
  |  |   64|      0|#define PORT_Realloc PORT_Realloc_Util
  ------------------
  572|      0|        bufp->size = size;
  573|      0|    }
  574|  12.0k|    if (!buf) {
  ------------------
  |  Branch (574:9): [True: 0, False: 12.0k]
  ------------------
  575|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  576|      0|        return SECFailure;
  577|      0|    }
  578|  12.0k|    bufp->buffer = buf;
  579|  12.0k|    bufp->offset = bufSize;
  580|       |
  581|       |    /* Concatenate str onto buf */
  582|  12.0k|    buf = buf + bufLen;
  583|  12.0k|    if (bufLen)
  ------------------
  |  Branch (583:9): [True: 4.29k, False: 7.75k]
  ------------------
  584|  4.29k|        buf--;                      /* stomp on old '\0' */
  585|  12.0k|    PORT_Memcpy(buf, str, len + 1); /* put in new null */
  ------------------
  |  |  180|  12.0k|#define PORT_Memcpy memcpy
  ------------------
  586|  12.0k|    return SECSuccess;
  587|  12.0k|}
alg1485.c:AppendAVA:
  921|  9.93k|{
  922|  9.93k|#define TMPBUF_LEN 2048
  923|  9.93k|    const NameToKind* pn2k = name2kinds;
  924|  9.93k|    SECItem* avaValue = NULL;
  925|  9.93k|    char* unknownTag = NULL;
  926|  9.93k|    char* encodedAVA = NULL;
  927|  9.93k|    PRBool useHex = PR_FALSE; /* use =#hexXXXX form */
  ------------------
  |  |  438|  9.93k|#define PR_FALSE 0
  ------------------
  928|  9.93k|    PRBool truncateName = PR_FALSE;
  ------------------
  |  |  438|  9.93k|#define PR_FALSE 0
  ------------------
  929|  9.93k|    PRBool truncateValue = PR_FALSE;
  ------------------
  |  |  438|  9.93k|#define PR_FALSE 0
  ------------------
  930|  9.93k|    SECOidTag endKind;
  931|  9.93k|    SECStatus rv;
  932|  9.93k|    unsigned int len;
  933|  9.93k|    unsigned int nameLen, valueLen;
  934|  9.93k|    unsigned int maxName, maxValue;
  935|  9.93k|    EQMode mode = minimalEscapeAndQuote;
  936|  9.93k|    NameToKind n2k = { NULL, 32767, SEC_OID_UNKNOWN, SEC_ASN1_DS };
  ------------------
  |  |   24|  9.93k|#define SEC_ASN1_DS SEC_ASN1_HIGH_TAG_NUMBER
  |  |  ------------------
  |  |  |  |  107|  9.93k|#define SEC_ASN1_HIGH_TAG_NUMBER 0x1f
  |  |  ------------------
  ------------------
  937|  9.93k|    char tmpBuf[TMPBUF_LEN];
  938|       |
  939|  9.93k|#define tagName n2k.name /* non-NULL means use NAME= form */
  940|  9.93k|#define maxBytes n2k.maxLen
  941|  9.93k|#define tag n2k.kind
  942|  9.93k|#define vt n2k.valueType
  943|       |
  944|       |    /* READABLE mode recognizes more names from the name2kinds table
  945|       |     * than do STRICT or INVERTIBLE modes.  This assignment chooses the
  946|       |     * point in the table where the attribute type name scanning stops.
  947|       |     */
  948|  9.93k|    endKind = (strict == CERT_N2A_READABLE) ? SEC_OID_UNKNOWN
  ------------------
  |  Branch (948:15): [True: 9.93k, False: 0]
  ------------------
  949|  9.93k|                                            : SEC_OID_AVA_POSTAL_ADDRESS;
  950|  9.93k|    tag = CERT_GetAVATag(ava);
  ------------------
  |  |  941|  9.93k|#define tag n2k.kind
  ------------------
  951|   135k|    while (pn2k->kind != tag && pn2k->kind != endKind) {
  ------------------
  |  |  941|   271k|#define tag n2k.kind
  ------------------
  |  Branch (951:12): [True: 130k, False: 5.72k]
  |  Branch (951:33): [True: 125k, False: 4.21k]
  ------------------
  952|   125k|        ++pn2k;
  953|   125k|    }
  954|       |
  955|  9.93k|    if (pn2k->kind != endKind) {
  ------------------
  |  Branch (955:9): [True: 5.72k, False: 4.21k]
  ------------------
  956|  5.72k|        n2k = *pn2k;
  957|  5.72k|    } else if (strict != CERT_N2A_READABLE) {
  ------------------
  |  Branch (957:16): [True: 0, False: 4.21k]
  ------------------
  958|      0|        useHex = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  959|      0|    }
  960|       |    /* For invertable form, force Directory Strings to use hex form. */
  961|  9.93k|    if (strict == CERT_N2A_INVERTIBLE && vt == SEC_ASN1_DS) {
  ------------------
  |  |  942|      0|#define vt n2k.valueType
  ------------------
                  if (strict == CERT_N2A_INVERTIBLE && vt == SEC_ASN1_DS) {
  ------------------
  |  |   24|      0|#define SEC_ASN1_DS SEC_ASN1_HIGH_TAG_NUMBER
  |  |  ------------------
  |  |  |  |  107|      0|#define SEC_ASN1_HIGH_TAG_NUMBER 0x1f
  |  |  ------------------
  ------------------
  |  Branch (961:9): [True: 0, False: 9.93k]
  |  Branch (961:42): [True: 0, False: 0]
  ------------------
  962|      0|        tagName = NULL;   /* must use OID.N form */
  ------------------
  |  |  939|      0|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
  963|      0|        useHex = PR_TRUE; /* must use hex string */
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  964|      0|    }
  965|  9.93k|    if (!useHex) {
  ------------------
  |  Branch (965:9): [True: 9.93k, False: 0]
  ------------------
  966|  9.93k|        avaValue = CERT_DecodeAVAValue(&ava->value);
  967|  9.93k|        if (!avaValue) {
  ------------------
  |  Branch (967:13): [True: 5.21k, False: 4.71k]
  ------------------
  968|  5.21k|            useHex = PR_TRUE;
  ------------------
  |  |  437|  5.21k|#define PR_TRUE 1
  ------------------
  969|  5.21k|            if (strict != CERT_N2A_READABLE) {
  ------------------
  |  Branch (969:17): [True: 0, False: 5.21k]
  ------------------
  970|      0|                tagName = NULL; /* must use OID.N form */
  ------------------
  |  |  939|      0|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
  971|      0|            }
  972|  5.21k|        }
  973|  9.93k|    }
  974|  9.93k|    if (!tagName) {
  ------------------
  |  |  939|  9.93k|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
  |  Branch (974:9): [True: 4.21k, False: 5.72k]
  ------------------
  975|       |        /* handle unknown attribute types per RFC 2253 */
  976|  4.21k|        tagName = unknownTag = CERT_GetOidString(&ava->type);
  ------------------
  |  |  939|  4.21k|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
  977|  4.21k|        if (!tagName) {
  ------------------
  |  |  939|  4.21k|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
  |  Branch (977:13): [True: 35, False: 4.17k]
  ------------------
  978|     35|            if (avaValue)
  ------------------
  |  Branch (978:17): [True: 23, False: 12]
  ------------------
  979|     23|                SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  108|     23|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  437|     23|#define PR_TRUE 1
  ------------------
  980|     35|            return SECFailure;
  981|     35|        }
  982|  4.21k|    }
  983|  9.90k|    if (useHex) {
  ------------------
  |  Branch (983:9): [True: 5.20k, False: 4.69k]
  ------------------
  984|  5.20k|        avaValue = get_hex_string(&ava->value);
  985|  5.20k|        if (!avaValue) {
  ------------------
  |  Branch (985:13): [True: 0, False: 5.20k]
  ------------------
  986|      0|            if (unknownTag)
  ------------------
  |  Branch (986:17): [True: 0, False: 0]
  ------------------
  987|      0|                PR_smprintf_free(unknownTag);
  988|      0|            return SECFailure;
  989|      0|        }
  990|  5.20k|    }
  991|       |
  992|  9.90k|    nameLen = strlen(tagName);
  ------------------
  |  |  939|  9.90k|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
  993|       |
  994|  9.90k|    if (useHex) {
  ------------------
  |  Branch (994:9): [True: 5.20k, False: 4.69k]
  ------------------
  995|  5.20k|        valueLen = avaValue->len;
  996|  5.20k|    } else {
  997|  4.69k|        int reqLen = cert_RFC1485_GetRequiredLen((char*)avaValue->data, avaValue->len, &mode);
  998|  4.69k|        if (reqLen < 0) {
  ------------------
  |  Branch (998:13): [True: 0, False: 4.69k]
  ------------------
  999|      0|            SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1000|      0|            return SECFailure;
 1001|      0|        }
 1002|  4.69k|        valueLen = reqLen;
 1003|  4.69k|    }
 1004|  9.90k|    if (UINT_MAX - nameLen < 2 ||
  ------------------
  |  Branch (1004:9): [True: 0, False: 9.90k]
  ------------------
 1005|  9.90k|        valueLen > UINT_MAX - nameLen - 2) {
  ------------------
  |  Branch (1005:9): [True: 0, False: 9.90k]
  ------------------
 1006|      0|        SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1007|      0|        return SECFailure;
 1008|      0|    }
 1009|  9.90k|    len = nameLen + valueLen + 2; /* Add 2 for '=' and trailing NUL */
 1010|       |
 1011|  9.90k|    maxName = nameLen;
 1012|  9.90k|    maxValue = valueLen;
 1013|  9.90k|    if (len <= sizeof(tmpBuf)) {
  ------------------
  |  Branch (1013:9): [True: 9.90k, False: 0]
  ------------------
 1014|  9.90k|        encodedAVA = tmpBuf;
 1015|  9.90k|    } else if (strict != CERT_N2A_READABLE) {
  ------------------
  |  Branch (1015:16): [True: 0, False: 0]
  ------------------
 1016|      0|        encodedAVA = PORT_Alloc(len);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1017|      0|        if (!encodedAVA) {
  ------------------
  |  Branch (1017:13): [True: 0, False: 0]
  ------------------
 1018|      0|            SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1019|      0|            if (unknownTag)
  ------------------
  |  Branch (1019:17): [True: 0, False: 0]
  ------------------
 1020|      0|                PR_smprintf_free(unknownTag);
 1021|      0|            return SECFailure;
 1022|      0|        }
 1023|      0|    } else {
 1024|       |        /* Must make output fit in tmpbuf */
 1025|      0|        unsigned int fair = (sizeof tmpBuf) / 2 - 1; /* for = and \0 */
 1026|       |
 1027|      0|        if (nameLen < fair) {
  ------------------
  |  Branch (1027:13): [True: 0, False: 0]
  ------------------
 1028|       |            /* just truncate the value */
 1029|      0|            maxValue = (sizeof tmpBuf) - (nameLen + 6); /* for "=...\0",
 1030|       |                                                     and possibly '"' */
 1031|      0|        } else if (valueLen < fair) {
  ------------------
  |  Branch (1031:20): [True: 0, False: 0]
  ------------------
 1032|       |            /* just truncate the name */
 1033|      0|            maxName = (sizeof tmpBuf) - (valueLen + 5); /* for "=...\0" */
 1034|      0|        } else {
 1035|       |            /* truncate both */
 1036|      0|            maxName = maxValue = fair - 3; /* for "..." */
 1037|      0|        }
 1038|      0|        if (nameLen > maxName) {
  ------------------
  |  Branch (1038:13): [True: 0, False: 0]
  ------------------
 1039|      0|            PORT_Assert(unknownTag && unknownTag == tagName);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1040|      0|            truncateName = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1041|      0|            nameLen = maxName;
 1042|      0|        }
 1043|      0|        encodedAVA = tmpBuf;
 1044|      0|    }
 1045|       |
 1046|  9.90k|    memcpy(encodedAVA, tagName, nameLen);
  ------------------
  |  |  939|  9.90k|#define tagName n2k.name /* non-NULL means use NAME= form */
  ------------------
 1047|  9.90k|    if (truncateName) {
  ------------------
  |  Branch (1047:9): [True: 0, False: 9.90k]
  ------------------
 1048|       |        /* If tag name is too long, we know it is an OID form that was
 1049|       |         * allocated from the heap, so we can modify it in place
 1050|       |         */
 1051|      0|        encodedAVA[nameLen - 1] = '.';
 1052|      0|        encodedAVA[nameLen - 2] = '.';
 1053|      0|        encodedAVA[nameLen - 3] = '.';
 1054|      0|    }
 1055|  9.90k|    encodedAVA[nameLen++] = '=';
 1056|  9.90k|    if (unknownTag)
  ------------------
  |  Branch (1056:9): [True: 4.17k, False: 5.72k]
  ------------------
 1057|  4.17k|        PR_smprintf_free(unknownTag);
 1058|       |
 1059|  9.90k|    if (strict == CERT_N2A_READABLE && maxValue > maxBytes)
  ------------------
  |  |  940|  9.90k|#define maxBytes n2k.maxLen
  ------------------
  |  Branch (1059:9): [True: 9.90k, False: 0]
  |  Branch (1059:40): [True: 173, False: 9.72k]
  ------------------
 1060|    173|        maxValue = maxBytes;
  ------------------
  |  |  940|    173|#define maxBytes n2k.maxLen
  ------------------
 1061|  9.90k|    if (valueLen > maxValue) {
  ------------------
  |  Branch (1061:9): [True: 173, False: 9.72k]
  ------------------
 1062|    173|        valueLen = maxValue;
 1063|    173|        truncateValue = PR_TRUE;
  ------------------
  |  |  437|    173|#define PR_TRUE 1
  ------------------
 1064|    173|    }
 1065|       |    /* escape and quote as necessary - don't quote hex strings */
 1066|  9.90k|    if (useHex) {
  ------------------
  |  Branch (1066:9): [True: 5.20k, False: 4.69k]
  ------------------
 1067|  5.20k|        char* end = encodedAVA + nameLen + valueLen;
 1068|  5.20k|        memcpy(encodedAVA + nameLen, (char*)avaValue->data, valueLen);
 1069|  5.20k|        end[0] = '\0';
 1070|  5.20k|        if (truncateValue) {
  ------------------
  |  Branch (1070:13): [True: 48, False: 5.15k]
  ------------------
 1071|     48|            end[-1] = '.';
 1072|     48|            end[-2] = '.';
 1073|     48|            end[-3] = '.';
 1074|     48|        }
 1075|  5.20k|        rv = SECSuccess;
 1076|  5.20k|    } else if (!truncateValue) {
  ------------------
  |  Branch (1076:16): [True: 4.57k, False: 125]
  ------------------
 1077|  4.57k|        rv = escapeAndQuote(encodedAVA + nameLen, len - nameLen,
 1078|  4.57k|                            (char*)avaValue->data, avaValue->len, &mode);
 1079|  4.57k|    } else {
 1080|       |        /* must truncate the escaped and quoted value */
 1081|    125|        char bigTmpBuf[TMPBUF_LEN * 3 + 3];
 1082|    125|        PORT_Assert(valueLen < sizeof tmpBuf);
  ------------------
  |  |  120|    125|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    125|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 125, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1083|    125|        rv = escapeAndQuote(bigTmpBuf, sizeof bigTmpBuf, (char*)avaValue->data,
 1084|    125|                            PR_MIN(avaValue->len, valueLen), &mode);
  ------------------
  |  |  158|    125|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 12, False: 113]
  |  |  ------------------
  ------------------
 1085|       |
 1086|    125|        bigTmpBuf[valueLen--] = '\0'; /* hard stop here */
 1087|       |        /* See if we're in the middle of a multi-byte UTF8 character */
 1088|    206|        while (((bigTmpBuf[valueLen] & 0xc0) == 0x80) && valueLen > 0) {
  ------------------
  |  Branch (1088:16): [True: 81, False: 125]
  |  Branch (1088:58): [True: 81, False: 0]
  ------------------
 1089|     81|            bigTmpBuf[valueLen--] = '\0';
 1090|     81|        }
 1091|       |        /* add ellipsis to signify truncation. */
 1092|    125|        bigTmpBuf[++valueLen] = '.';
 1093|    125|        bigTmpBuf[++valueLen] = '.';
 1094|    125|        bigTmpBuf[++valueLen] = '.';
 1095|    125|        if (bigTmpBuf[0] == '"')
  ------------------
  |  Branch (1095:13): [True: 43, False: 82]
  ------------------
 1096|     43|            bigTmpBuf[++valueLen] = '"';
 1097|    125|        bigTmpBuf[++valueLen] = '\0';
 1098|    125|        PORT_Assert(nameLen + valueLen <= (sizeof tmpBuf) - 1);
  ------------------
  |  |  120|    125|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    125|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 125, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1099|    125|        memcpy(encodedAVA + nameLen, bigTmpBuf, valueLen + 1);
 1100|    125|    }
 1101|       |
 1102|  9.90k|    SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  108|  9.90k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  437|  9.90k|#define PR_TRUE 1
  ------------------
 1103|  9.90k|    if (rv == SECSuccess)
  ------------------
  |  Branch (1103:9): [True: 9.90k, False: 0]
  ------------------
 1104|  9.90k|        rv = AppendStr(bufp, encodedAVA);
 1105|  9.90k|    if (encodedAVA != tmpBuf)
  ------------------
  |  Branch (1105:9): [True: 0, False: 9.90k]
  ------------------
 1106|      0|        PORT_Free(encodedAVA);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1107|  9.90k|    return rv;
 1108|  9.90k|}
alg1485.c:get_hex_string:
  842|  5.20k|{
  843|  5.20k|    SECItem* rv;
  844|  5.20k|    unsigned int i, j;
  845|  5.20k|    static const char hex[] = { "0123456789ABCDEF" };
  846|       |
  847|       |    /* '#' + 2 chars per octet + terminator */
  848|  5.20k|    rv = SECITEM_AllocItem(NULL, NULL, data->len * 2 + 2);
  ------------------
  |  |  103|  5.20k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  849|  5.20k|    if (!rv) {
  ------------------
  |  Branch (849:9): [True: 0, False: 5.20k]
  ------------------
  850|      0|        return NULL;
  851|      0|    }
  852|  5.20k|    rv->data[0] = '#';
  853|  5.20k|    rv->len = 1 + 2 * data->len;
  854|  48.3k|    for (i = 0; i < data->len; i++) {
  ------------------
  |  Branch (854:17): [True: 43.1k, False: 5.20k]
  ------------------
  855|  43.1k|        j = data->data[i];
  856|  43.1k|        rv->data[2 * i + 1] = hex[j >> 4];
  857|  43.1k|        rv->data[2 * i + 2] = hex[j & 15];
  858|  43.1k|    }
  859|  5.20k|    rv->data[rv->len] = 0;
  860|  5.20k|    return rv;
  861|  5.20k|}
alg1485.c:CERT_GetNameElement:
 1252|  7.78k|{
 1253|  7.78k|    CERTRDN** rdns = name->rdns;
 1254|  7.78k|    CERTRDN* rdn;
 1255|  7.78k|    CERTAVA* ava = NULL;
 1256|       |
 1257|  17.7k|    while (rdns && (rdn = *rdns++) != 0) {
  ------------------
  |  Branch (1257:12): [True: 17.6k, False: 49]
  |  Branch (1257:20): [True: 9.95k, False: 7.73k]
  ------------------
 1258|  9.95k|        CERTAVA** avas = rdn->avas;
 1259|  19.9k|        while (avas && (ava = *avas++) != 0) {
  ------------------
  |  Branch (1259:16): [True: 19.8k, False: 49]
  |  Branch (1259:24): [True: 9.95k, False: 9.91k]
  ------------------
 1260|  9.95k|            int tag = CERT_GetAVATag(ava);
 1261|  9.95k|            if (tag == wantedTag) {
  ------------------
  |  Branch (1261:17): [True: 49, False: 9.91k]
  ------------------
 1262|     49|                avas = NULL;
 1263|     49|                rdns = NULL; /* break out of all loops */
 1264|     49|            }
 1265|  9.95k|        }
 1266|  9.95k|    }
 1267|  7.78k|    return ava ? avaToString(arena, ava) : NULL;
  ------------------
  |  Branch (1267:12): [True: 49, False: 7.73k]
  ------------------
 1268|  7.78k|}
alg1485.c:avaToString:
 1215|     49|{
 1216|     49|    char* buf = NULL;
 1217|     49|    SECItem* avaValue;
 1218|     49|    int valueLen;
 1219|       |
 1220|     49|    avaValue = CERT_DecodeAVAValue(&ava->value);
 1221|     49|    if (!avaValue) {
  ------------------
  |  Branch (1221:9): [True: 2, False: 47]
  ------------------
 1222|      2|        return buf;
 1223|      2|    }
 1224|     47|    int reqLen = cert_RFC1485_GetRequiredLen((char*)avaValue->data, avaValue->len, NULL);
 1225|       |    /* reqLen is max 16384*3 + 2 */
 1226|     47|    if (reqLen >= 0) {
  ------------------
  |  Branch (1226:9): [True: 47, False: 0]
  ------------------
 1227|     47|        valueLen = reqLen + 1;
 1228|     47|        if (arena) {
  ------------------
  |  Branch (1228:13): [True: 47, False: 0]
  ------------------
 1229|     47|            buf = (char*)PORT_ArenaZAlloc(arena, valueLen);
  ------------------
  |  |   59|     47|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 1230|     47|        } else {
 1231|      0|            buf = (char*)PORT_ZAlloc(valueLen);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 1232|      0|        }
 1233|     47|        if (buf) {
  ------------------
  |  Branch (1233:13): [True: 47, False: 0]
  ------------------
 1234|     47|            SECStatus rv =
 1235|     47|                escapeAndQuote(buf, valueLen, (char*)avaValue->data, avaValue->len, NULL);
 1236|     47|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1236:17): [True: 0, False: 47]
  ------------------
 1237|      0|                if (!arena)
  ------------------
  |  Branch (1237:21): [True: 0, False: 0]
  ------------------
 1238|      0|                    PORT_Free(buf);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1239|      0|                buf = NULL;
 1240|      0|            }
 1241|     47|        }
 1242|     47|    }
 1243|     47|    SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  108|     47|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(avaValue, PR_TRUE);
  ------------------
  |  |  437|     47|#define PR_TRUE 1
  ------------------
 1244|     47|    return buf;
 1245|     49|}
alg1485.c:appendStringToBuf:
 1381|  7.78k|{
 1382|  7.78k|    PRUint32 len;
 1383|  7.78k|    if (dest && src && src[0] && *pRemaining > (len = PL_strlen(src))) {
  ------------------
  |  Branch (1383:9): [True: 7.78k, False: 0]
  |  Branch (1383:17): [True: 47, False: 7.73k]
  |  Branch (1383:24): [True: 47, False: 0]
  |  Branch (1383:34): [True: 47, False: 0]
  ------------------
 1384|     47|        PRUint32 i;
 1385|  2.27k|        for (i = 0; i < len; ++i)
  ------------------
  |  Branch (1385:21): [True: 2.23k, False: 47]
  ------------------
 1386|  2.23k|            dest[i] = tolower((unsigned char)src[i]);
 1387|     47|        dest[len] = 0;
 1388|     47|        dest += len + 1;
 1389|     47|        *pRemaining -= len + 1;
 1390|     47|    }
 1391|  7.78k|    return dest;
 1392|  7.78k|}
alg1485.c:appendItemToBuf:
 1399|     32|{
 1400|     32|    if (dest && src && src->data && src->len && src->data[0]) {
  ------------------
  |  Branch (1400:9): [True: 32, False: 0]
  |  Branch (1400:17): [True: 32, False: 0]
  |  Branch (1400:24): [True: 32, False: 0]
  |  Branch (1400:37): [True: 32, False: 0]
  |  Branch (1400:49): [True: 25, False: 7]
  ------------------
 1401|     25|        PRUint32 len = src->len;
 1402|     25|        PRUint32 i;
 1403|     25|        PRUint32 reqLen = len + 1;
 1404|       |        /* are there any embedded control characters ? */
 1405|    560|        for (i = 0; i < len; i++) {
  ------------------
  |  Branch (1405:21): [True: 535, False: 25]
  ------------------
 1406|    535|            if (NEEDS_HEX_ESCAPE(src->data[i]))
  ------------------
  |  | 1395|    535|#define NEEDS_HEX_ESCAPE(c) (c < 0x20)
  |  |  ------------------
  |  |  |  Branch (1395:29): [True: 200, False: 335]
  |  |  ------------------
  ------------------
 1407|    200|                reqLen += 2;
 1408|    535|        }
 1409|     25|        if (*pRemaining > reqLen) {
  ------------------
  |  Branch (1409:13): [True: 25, False: 0]
  ------------------
 1410|    560|            for (i = 0; i < len; ++i) {
  ------------------
  |  Branch (1410:25): [True: 535, False: 25]
  ------------------
 1411|    535|                PRUint8 c = src->data[i];
 1412|    535|                if (NEEDS_HEX_ESCAPE(c)) {
  ------------------
  |  | 1395|    535|#define NEEDS_HEX_ESCAPE(c) (c < 0x20)
  |  |  ------------------
  |  |  |  Branch (1395:29): [True: 200, False: 335]
  |  |  ------------------
  ------------------
 1413|    200|                    *dest++ =
 1414|    200|                        C_BACKSLASH;
  ------------------
  |  |  119|    200|#define C_BACKSLASH '\134'
  ------------------
 1415|    200|                    *dest++ =
 1416|    200|                        hexChars[(c >> 4) & 0x0f];
 1417|    200|                    *dest++ =
 1418|    200|                        hexChars[c & 0x0f];
 1419|    335|                } else {
 1420|    335|                    *dest++ =
 1421|    335|                        tolower(c);
 1422|    335|                }
 1423|    535|            }
 1424|     25|            *dest++ = '\0';
 1425|     25|            *pRemaining -= reqLen;
 1426|     25|        }
 1427|     25|    }
 1428|     32|    return dest;
 1429|     32|}

CERT_KeyFromIssuerAndSN:
  184|  3.89k|{
  185|  3.89k|    key->len = sn->len + issuer->len;
  186|       |
  187|  3.89k|    if ((sn->data == NULL) || (issuer->data == NULL)) {
  ------------------
  |  Branch (187:9): [True: 0, False: 3.89k]
  |  Branch (187:31): [True: 0, False: 3.89k]
  ------------------
  188|      0|        goto loser;
  189|      0|    }
  190|       |
  191|  3.89k|    key->data = (unsigned char *)PORT_ArenaAlloc(arena, key->len);
  ------------------
  |  |   53|  3.89k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  192|  3.89k|    if (!key->data) {
  ------------------
  |  Branch (192:9): [True: 0, False: 3.89k]
  ------------------
  193|      0|        goto loser;
  194|      0|    }
  195|       |
  196|       |    /* copy the serialNumber */
  197|  3.89k|    PORT_Memcpy(key->data, sn->data, sn->len);
  ------------------
  |  |  180|  3.89k|#define PORT_Memcpy memcpy
  ------------------
  198|       |
  199|       |    /* copy the issuer */
  200|  3.89k|    PORT_Memcpy(&key->data[sn->len], issuer->data, issuer->len);
  ------------------
  |  |  180|  3.89k|#define PORT_Memcpy memcpy
  ------------------
  201|       |
  202|  3.89k|    return (SECSuccess);
  203|       |
  204|      0|loser:
  205|      0|    return (SECFailure);
  206|  3.89k|}
CERT_IssuerNameFromDERCert:
  258|  8.13k|{
  259|  8.13k|    int rv;
  260|  8.13k|    PORTCheapArenaPool tmpArena;
  261|  8.13k|    CERTSignedData sd;
  262|  8.13k|    void *tmpptr;
  263|       |
  264|  8.13k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  8.13k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  265|       |
  266|  8.13k|    PORT_Memset(&sd, 0, sizeof(CERTSignedData));
  ------------------
  |  |  182|  8.13k|#define PORT_Memset memset
  ------------------
  267|  8.13k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &sd, CERT_SignedDataTemplate,
  ------------------
  |  |  102|  8.13k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  268|  8.13k|                                derCert);
  269|  8.13k|    if (rv) {
  ------------------
  |  Branch (269:9): [True: 244, False: 7.89k]
  ------------------
  270|    244|        goto loser;
  271|    244|    }
  272|       |
  273|  7.89k|    PORT_Memset(derName, 0, sizeof(SECItem));
  ------------------
  |  |  182|  7.89k|#define PORT_Memset memset
  ------------------
  274|  7.89k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, derName,
  ------------------
  |  |  102|  7.89k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  275|  7.89k|                                SEC_CertIssuerTemplate, &sd.data);
  276|  7.89k|    if (rv) {
  ------------------
  |  Branch (276:9): [True: 16, False: 7.87k]
  ------------------
  277|     16|        goto loser;
  278|     16|    }
  279|       |
  280|  7.87k|    tmpptr = derName->data;
  281|  7.87k|    derName->data = (unsigned char *)PORT_Alloc(derName->len);
  ------------------
  |  |   52|  7.87k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  282|  7.87k|    if (derName->data == NULL) {
  ------------------
  |  Branch (282:9): [True: 0, False: 7.87k]
  ------------------
  283|      0|        goto loser;
  284|      0|    }
  285|       |
  286|  7.87k|    PORT_Memcpy(derName->data, tmpptr, derName->len);
  ------------------
  |  |  180|  7.87k|#define PORT_Memcpy memcpy
  ------------------
  287|       |
  288|  7.87k|    PORT_DestroyCheapArena(&tmpArena);
  289|  7.87k|    return (SECSuccess);
  290|       |
  291|    260|loser:
  292|    260|    PORT_DestroyCheapArena(&tmpArena);
  293|    260|    return (SECFailure);
  294|  7.87k|}
CERT_SerialNumberFromDERCert:
  298|  11.7k|{
  299|  11.7k|    int rv;
  300|  11.7k|    PORTCheapArenaPool tmpArena;
  301|  11.7k|    CERTSignedData sd;
  302|  11.7k|    void *tmpptr;
  303|       |
  304|  11.7k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  11.7k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  305|       |
  306|  11.7k|    PORT_Memset(&sd, 0, sizeof(CERTSignedData));
  ------------------
  |  |  182|  11.7k|#define PORT_Memset memset
  ------------------
  307|  11.7k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &sd, CERT_SignedDataTemplate,
  ------------------
  |  |  102|  11.7k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  308|  11.7k|                                derCert);
  309|  11.7k|    if (rv) {
  ------------------
  |  Branch (309:9): [True: 0, False: 11.7k]
  ------------------
  310|      0|        goto loser;
  311|      0|    }
  312|       |
  313|  11.7k|    PORT_Memset(derName, 0, sizeof(SECItem));
  ------------------
  |  |  182|  11.7k|#define PORT_Memset memset
  ------------------
  314|  11.7k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, derName,
  ------------------
  |  |  102|  11.7k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  315|  11.7k|                                SEC_CertSerialNumberTemplate, &sd.data);
  316|  11.7k|    if (rv) {
  ------------------
  |  Branch (316:9): [True: 0, False: 11.7k]
  ------------------
  317|      0|        goto loser;
  318|      0|    }
  319|       |
  320|  11.7k|    tmpptr = derName->data;
  321|  11.7k|    derName->data = (unsigned char *)PORT_Alloc(derName->len);
  ------------------
  |  |   52|  11.7k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  322|  11.7k|    if (derName->data == NULL) {
  ------------------
  |  Branch (322:9): [True: 0, False: 11.7k]
  ------------------
  323|      0|        goto loser;
  324|      0|    }
  325|       |
  326|  11.7k|    PORT_Memcpy(derName->data, tmpptr, derName->len);
  ------------------
  |  |  180|  11.7k|#define PORT_Memcpy memcpy
  ------------------
  327|       |
  328|  11.7k|    PORT_DestroyCheapArena(&tmpArena);
  329|  11.7k|    return (SECSuccess);
  330|       |
  331|      0|loser:
  332|      0|    PORT_DestroyCheapArena(&tmpArena);
  333|      0|    return (SECFailure);
  334|  11.7k|}
cert_GetCertType:
  434|  3.89k|{
  435|  3.89k|    PRUint32 nsCertType;
  436|       |
  437|  3.89k|    if (cert->nsCertType) {
  ------------------
  |  Branch (437:9): [True: 0, False: 3.89k]
  ------------------
  438|       |        /* once set, no need to recalculate */
  439|      0|        return SECSuccess;
  440|      0|    }
  441|  3.89k|    nsCertType = cert_ComputeCertType(cert);
  442|       |
  443|       |    /* Assert that it is safe to cast &cert->nsCertType to "PRInt32 *" */
  444|  3.89k|    PORT_Assert(sizeof(cert->nsCertType) == sizeof(PRInt32));
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.89k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  445|  3.89k|    PR_ATOMIC_SET((PRInt32 *)&cert->nsCertType, nsCertType);
  ------------------
  |  |  124|  3.89k|#define PR_ATOMIC_SET(val, newval) __sync_lock_test_and_set(val, newval)
  ------------------
  446|  3.89k|    return SECSuccess;
  447|  3.89k|}
cert_IsIPsecOID:
  451|     52|{
  452|     52|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (452:9): [True: 1, False: 51]
  ------------------
  453|     52|            extKeyUsage, SEC_OID_EXT_KEY_USAGE_IPSEC_IKE) == SECSuccess) {
  454|      1|        return PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  455|      1|    }
  456|     51|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (456:9): [True: 0, False: 51]
  ------------------
  457|     51|            extKeyUsage, SEC_OID_IPSEC_IKE_END) == SECSuccess) {
  458|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  459|      0|    }
  460|     51|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (460:9): [True: 0, False: 51]
  ------------------
  461|     51|            extKeyUsage, SEC_OID_IPSEC_IKE_INTERMEDIATE) == SECSuccess) {
  462|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  463|      0|    }
  464|       |    /* these are now deprecated, but may show up. Treat them the same as IKE */
  465|     51|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (465:9): [True: 1, False: 50]
  ------------------
  466|     51|            extKeyUsage, SEC_OID_EXT_KEY_USAGE_IPSEC_END) == SECSuccess) {
  467|      1|        return PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  468|      1|    }
  469|     50|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (469:9): [True: 1, False: 49]
  ------------------
  470|     50|            extKeyUsage, SEC_OID_EXT_KEY_USAGE_IPSEC_TUNNEL) == SECSuccess) {
  471|      1|        return PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  472|      1|    }
  473|     49|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (473:9): [True: 3, False: 46]
  ------------------
  474|     49|            extKeyUsage, SEC_OID_EXT_KEY_USAGE_IPSEC_USER) == SECSuccess) {
  475|      3|        return PR_TRUE;
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
  476|      3|    }
  477|       |    /* this one should probably be in cert_ComputeCertType and set all usages? */
  478|     46|    if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (478:9): [True: 0, False: 46]
  ------------------
  479|     46|            extKeyUsage, SEC_OID_X509_ANY_EXT_KEY_USAGE) == SECSuccess) {
  480|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  481|      0|    }
  482|     46|    return PR_FALSE;
  ------------------
  |  |  438|     46|#define PR_FALSE 0
  ------------------
  483|     46|}
cert_ComputeCertType:
  487|  3.89k|{
  488|  3.89k|    SECStatus rv;
  489|  3.89k|    SECItem tmpitem;
  490|  3.89k|    SECItem encodedExtKeyUsage;
  491|  3.89k|    CERTOidSequence *extKeyUsage = NULL;
  492|  3.89k|    CERTBasicConstraints basicConstraint;
  493|  3.89k|    PRUint32 nsCertType = 0;
  494|  3.89k|    PRBool isCA = PR_FALSE;
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  495|       |
  496|  3.89k|    tmpitem.data = NULL;
  497|  3.89k|    CERT_FindNSCertTypeExtension(cert, &tmpitem);
  498|  3.89k|    encodedExtKeyUsage.data = NULL;
  499|  3.89k|    rv = CERT_FindCertExtension(cert, SEC_OID_X509_EXT_KEY_USAGE,
  500|  3.89k|                                &encodedExtKeyUsage);
  501|  3.89k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (501:9): [True: 80, False: 3.81k]
  ------------------
  502|     80|        extKeyUsage = CERT_DecodeOidSequence(&encodedExtKeyUsage);
  503|     80|    }
  504|  3.89k|    rv = CERT_FindBasicConstraintExten(cert, &basicConstraint);
  505|  3.89k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (505:9): [True: 1.05k, False: 2.83k]
  ------------------
  506|  1.05k|        isCA = basicConstraint.isCA;
  507|  1.05k|    }
  508|  3.89k|    if (tmpitem.data != NULL || extKeyUsage != NULL) {
  ------------------
  |  Branch (508:9): [True: 0, False: 3.89k]
  |  Branch (508:33): [True: 52, False: 3.83k]
  ------------------
  509|     52|        if (tmpitem.data == NULL || tmpitem.len == 0) {
  ------------------
  |  Branch (509:13): [True: 52, False: 0]
  |  Branch (509:37): [True: 0, False: 0]
  ------------------
  510|     52|            nsCertType = 0;
  511|     52|        } else {
  512|      0|            nsCertType = tmpitem.data[0];
  513|      0|        }
  514|       |
  515|       |        /* free tmpitem data pointer to avoid memory leak */
  516|     52|        PORT_Free(tmpitem.data);
  ------------------
  |  |   60|     52|#define PORT_Free PORT_Free_Util
  ------------------
  517|     52|        tmpitem.data = NULL;
  518|       |
  519|       |        /*
  520|       |         * for this release, we will allow SSL certs with an email address
  521|       |         * to be used for email
  522|       |         */
  523|     52|        if ((nsCertType & NS_CERT_TYPE_SSL_CLIENT) && cert->emailAddr &&
  ------------------
  |  |  447|     52|#define NS_CERT_TYPE_SSL_CLIENT (0x80)        /* bit 0 */
  ------------------
  |  Branch (523:13): [True: 0, False: 52]
  |  Branch (523:55): [True: 0, False: 0]
  ------------------
  524|     52|            cert->emailAddr[0]) {
  ------------------
  |  Branch (524:13): [True: 0, False: 0]
  ------------------
  525|      0|            nsCertType |= NS_CERT_TYPE_EMAIL;
  ------------------
  |  |  449|      0|#define NS_CERT_TYPE_EMAIL (0x20)             /* bit 2 */
  ------------------
  526|      0|        }
  527|       |        /*
  528|       |         * for this release, we will allow SSL intermediate CAs to be
  529|       |         * email intermediate CAs too.
  530|       |         */
  531|     52|        if (nsCertType & NS_CERT_TYPE_SSL_CA) {
  ------------------
  |  |  452|     52|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
  |  Branch (531:13): [True: 0, False: 52]
  ------------------
  532|      0|            nsCertType |= NS_CERT_TYPE_EMAIL_CA;
  ------------------
  |  |  453|      0|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
  533|      0|        }
  534|       |        /*
  535|       |         * allow a cert with the extended key usage of EMail Protect
  536|       |         * to be used for email or as an email CA, if basic constraints
  537|       |         * indicates that it is a CA.
  538|       |         */
  539|     52|        if (findOIDinOIDSeqByTagNum(extKeyUsage,
  ------------------
  |  Branch (539:13): [True: 4, False: 48]
  ------------------
  540|     52|                                    SEC_OID_EXT_KEY_USAGE_EMAIL_PROTECT) ==
  541|     52|            SECSuccess) {
  542|      4|            nsCertType |= isCA ? NS_CERT_TYPE_EMAIL_CA : NS_CERT_TYPE_EMAIL;
  ------------------
  |  |  453|      1|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
                          nsCertType |= isCA ? NS_CERT_TYPE_EMAIL_CA : NS_CERT_TYPE_EMAIL;
  ------------------
  |  |  449|      7|#define NS_CERT_TYPE_EMAIL (0x20)             /* bit 2 */
  ------------------
  |  Branch (542:27): [True: 1, False: 3]
  ------------------
  543|      4|        }
  544|     52|        if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (544:13): [True: 6, False: 46]
  ------------------
  545|     52|                extKeyUsage, SEC_OID_EXT_KEY_USAGE_SERVER_AUTH) == SECSuccess) {
  546|      6|            nsCertType |= isCA ? NS_CERT_TYPE_SSL_CA : NS_CERT_TYPE_SSL_SERVER;
  ------------------
  |  |  452|      1|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                          nsCertType |= isCA ? NS_CERT_TYPE_SSL_CA : NS_CERT_TYPE_SSL_SERVER;
  ------------------
  |  |  448|     11|#define NS_CERT_TYPE_SSL_SERVER (0x40)        /* bit 1 */
  ------------------
  |  Branch (546:27): [True: 1, False: 5]
  ------------------
  547|      6|        }
  548|       |        /*
  549|       |         * Treat certs with step-up OID as also having SSL server type.
  550|       |         * COMODO needs this behaviour until June 2020.  See Bug 737802.
  551|       |         */
  552|     52|        if (findOIDinOIDSeqByTagNum(extKeyUsage,
  ------------------
  |  Branch (552:13): [True: 0, False: 52]
  ------------------
  553|     52|                                    SEC_OID_NS_KEY_USAGE_GOVT_APPROVED) ==
  554|     52|            SECSuccess) {
  555|      0|            nsCertType |= isCA ? NS_CERT_TYPE_SSL_CA : NS_CERT_TYPE_SSL_SERVER;
  ------------------
  |  |  452|      0|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                          nsCertType |= isCA ? NS_CERT_TYPE_SSL_CA : NS_CERT_TYPE_SSL_SERVER;
  ------------------
  |  |  448|      0|#define NS_CERT_TYPE_SSL_SERVER (0x40)        /* bit 1 */
  ------------------
  |  Branch (555:27): [True: 0, False: 0]
  ------------------
  556|      0|        }
  557|     52|        if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (557:13): [True: 2, False: 50]
  ------------------
  558|     52|                extKeyUsage, SEC_OID_EXT_KEY_USAGE_CLIENT_AUTH) == SECSuccess) {
  559|      2|            nsCertType |= isCA ? NS_CERT_TYPE_SSL_CA : NS_CERT_TYPE_SSL_CLIENT;
  ------------------
  |  |  452|      1|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                          nsCertType |= isCA ? NS_CERT_TYPE_SSL_CA : NS_CERT_TYPE_SSL_CLIENT;
  ------------------
  |  |  447|      3|#define NS_CERT_TYPE_SSL_CLIENT (0x80)        /* bit 0 */
  ------------------
  |  Branch (559:27): [True: 1, False: 1]
  ------------------
  560|      2|        }
  561|     52|        if (cert_IsIPsecOID(extKeyUsage)) {
  ------------------
  |  Branch (561:13): [True: 6, False: 46]
  ------------------
  562|      6|            nsCertType |= isCA ? NS_CERT_TYPE_IPSEC_CA : NS_CERT_TYPE_IPSEC;
  ------------------
  |  |  445|      4|#define NS_CERT_TYPE_IPSEC_CA (0x200)         /* outside the NS Cert Type Extenstion */
  ------------------
                          nsCertType |= isCA ? NS_CERT_TYPE_IPSEC_CA : NS_CERT_TYPE_IPSEC;
  ------------------
  |  |  446|      8|#define NS_CERT_TYPE_IPSEC (0x100)            /* outside the NS Cert Type Extenstion */
  ------------------
  |  Branch (562:27): [True: 4, False: 2]
  ------------------
  563|      6|        }
  564|     52|        if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (564:13): [True: 3, False: 49]
  ------------------
  565|     52|                extKeyUsage, SEC_OID_EXT_KEY_USAGE_CODE_SIGN) == SECSuccess) {
  566|      3|            nsCertType |= isCA ? NS_CERT_TYPE_OBJECT_SIGNING_CA : NS_CERT_TYPE_OBJECT_SIGNING;
  ------------------
  |  |  454|      1|#define NS_CERT_TYPE_OBJECT_SIGNING_CA (0x01) /* bit 7 */
  ------------------
                          nsCertType |= isCA ? NS_CERT_TYPE_OBJECT_SIGNING_CA : NS_CERT_TYPE_OBJECT_SIGNING;
  ------------------
  |  |  450|      5|#define NS_CERT_TYPE_OBJECT_SIGNING (0x10)    /* bit 3 */
  ------------------
  |  Branch (566:27): [True: 1, False: 2]
  ------------------
  567|      3|        }
  568|     52|        if (findOIDinOIDSeqByTagNum(
  ------------------
  |  Branch (568:13): [True: 1, False: 51]
  ------------------
  569|     52|                extKeyUsage, SEC_OID_EXT_KEY_USAGE_TIME_STAMP) == SECSuccess) {
  570|      1|            nsCertType |= EXT_KEY_USAGE_TIME_STAMP;
  ------------------
  |  |  456|      1|#define EXT_KEY_USAGE_TIME_STAMP (0x8000)
  ------------------
  571|      1|        }
  572|     52|        if (findOIDinOIDSeqByTagNum(extKeyUsage, SEC_OID_OCSP_RESPONDER) ==
  ------------------
  |  Branch (572:13): [True: 1, False: 51]
  ------------------
  573|     52|            SECSuccess) {
  574|      1|            nsCertType |= EXT_KEY_USAGE_STATUS_RESPONDER;
  ------------------
  |  |  457|      1|#define EXT_KEY_USAGE_STATUS_RESPONDER (0x4000)
  ------------------
  575|      1|        }
  576|  3.83k|    } else {
  577|       |        /* If no NS Cert Type extension and no EKU extension, then */
  578|  3.83k|        nsCertType = 0;
  579|  3.83k|        if (CERT_IsCACert(cert, &nsCertType))
  ------------------
  |  Branch (579:13): [True: 128, False: 3.71k]
  ------------------
  580|    128|            nsCertType |= EXT_KEY_USAGE_STATUS_RESPONDER;
  ------------------
  |  |  457|    128|#define EXT_KEY_USAGE_STATUS_RESPONDER (0x4000)
  ------------------
  581|       |        /* if the basic constraint extension says the cert is a CA, then
  582|       |           allow SSL CA and EMAIL CA and Status Responder */
  583|  3.83k|        if (isCA) {
  ------------------
  |  Branch (583:13): [True: 71, False: 3.76k]
  ------------------
  584|     71|            nsCertType |= (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA |
  ------------------
  |  |  452|     71|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                          nsCertType |= (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA |
  ------------------
  |  |  453|     71|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
  585|     71|                           EXT_KEY_USAGE_STATUS_RESPONDER);
  ------------------
  |  |  457|     71|#define EXT_KEY_USAGE_STATUS_RESPONDER (0x4000)
  ------------------
  586|     71|        }
  587|       |        /* allow any ssl or email (no ca or object signing. */
  588|  3.83k|        nsCertType |= NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER |
  ------------------
  |  |  447|  3.83k|#define NS_CERT_TYPE_SSL_CLIENT (0x80)        /* bit 0 */
  ------------------
                      nsCertType |= NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER |
  ------------------
  |  |  448|  3.83k|#define NS_CERT_TYPE_SSL_SERVER (0x40)        /* bit 1 */
  ------------------
  589|  3.83k|                      NS_CERT_TYPE_EMAIL;
  ------------------
  |  |  449|  3.83k|#define NS_CERT_TYPE_EMAIL (0x20)             /* bit 2 */
  ------------------
  590|  3.83k|    }
  591|       |
  592|       |    /* IPSEC is allowed to use SSL client and server certs as well as email certs */
  593|  3.89k|    if (nsCertType & (NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_EMAIL)) {
  ------------------
  |  |  447|  3.89k|#define NS_CERT_TYPE_SSL_CLIENT (0x80)        /* bit 0 */
  ------------------
                  if (nsCertType & (NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_EMAIL)) {
  ------------------
  |  |  448|  3.89k|#define NS_CERT_TYPE_SSL_SERVER (0x40)        /* bit 1 */
  ------------------
                  if (nsCertType & (NS_CERT_TYPE_SSL_CLIENT | NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_EMAIL)) {
  ------------------
  |  |  449|  3.89k|#define NS_CERT_TYPE_EMAIL (0x20)             /* bit 2 */
  ------------------
  |  Branch (593:9): [True: 3.84k, False: 45]
  ------------------
  594|  3.84k|        nsCertType |= NS_CERT_TYPE_IPSEC;
  ------------------
  |  |  446|  3.84k|#define NS_CERT_TYPE_IPSEC (0x100)            /* outside the NS Cert Type Extenstion */
  ------------------
  595|  3.84k|    }
  596|  3.89k|    if (nsCertType & (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA)) {
  ------------------
  |  |  452|  3.89k|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                  if (nsCertType & (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA)) {
  ------------------
  |  |  453|  3.89k|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
  |  Branch (596:9): [True: 130, False: 3.76k]
  ------------------
  597|    130|        nsCertType |= NS_CERT_TYPE_IPSEC_CA;
  ------------------
  |  |  445|    130|#define NS_CERT_TYPE_IPSEC_CA (0x200)         /* outside the NS Cert Type Extenstion */
  ------------------
  598|    130|    }
  599|       |
  600|  3.89k|    if (encodedExtKeyUsage.data != NULL) {
  ------------------
  |  Branch (600:9): [True: 79, False: 3.81k]
  ------------------
  601|     79|        PORT_Free(encodedExtKeyUsage.data);
  ------------------
  |  |   60|     79|#define PORT_Free PORT_Free_Util
  ------------------
  602|     79|    }
  603|  3.89k|    if (extKeyUsage != NULL) {
  ------------------
  |  Branch (603:9): [True: 52, False: 3.83k]
  ------------------
  604|     52|        CERT_DestroyOidSequence(extKeyUsage);
  605|     52|    }
  606|  3.89k|    return nsCertType;
  607|  3.89k|}
cert_GetKeyID:
  614|  3.89k|{
  615|  3.89k|    SECItem tmpitem;
  616|  3.89k|    SECStatus rv;
  617|       |
  618|  3.89k|    cert->subjectKeyID.len = 0;
  619|       |
  620|       |    /* see of the cert has a key identifier extension */
  621|  3.89k|    rv = CERT_FindSubjectKeyIDExtension(cert, &tmpitem);
  622|  3.89k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (622:9): [True: 83, False: 3.80k]
  ------------------
  623|     83|        cert->subjectKeyID.data =
  624|     83|            (unsigned char *)PORT_ArenaAlloc(cert->arena, tmpitem.len);
  ------------------
  |  |   53|     83|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  625|     83|        if (cert->subjectKeyID.data != NULL) {
  ------------------
  |  Branch (625:13): [True: 83, False: 0]
  ------------------
  626|     83|            PORT_Memcpy(cert->subjectKeyID.data, tmpitem.data, tmpitem.len);
  ------------------
  |  |  180|     83|#define PORT_Memcpy memcpy
  ------------------
  627|     83|            cert->subjectKeyID.len = tmpitem.len;
  628|     83|            cert->keyIDGenerated = PR_FALSE;
  ------------------
  |  |  438|     83|#define PR_FALSE 0
  ------------------
  629|     83|        }
  630|       |
  631|     83|        PORT_Free(tmpitem.data);
  ------------------
  |  |   60|     83|#define PORT_Free PORT_Free_Util
  ------------------
  632|     83|    }
  633|       |
  634|       |    /* if the cert doesn't have a key identifier extension, then generate one*/
  635|  3.89k|    if (cert->subjectKeyID.len == 0) {
  ------------------
  |  Branch (635:9): [True: 3.80k, False: 83]
  ------------------
  636|       |        /*
  637|       |         * pkix says that if the subjectKeyID is not present, then we should
  638|       |         * use the SHA-1 hash of the DER-encoded publicKeyInfo from the cert
  639|       |         */
  640|  3.80k|        cert->subjectKeyID.data =
  641|  3.80k|            (unsigned char *)PORT_ArenaAlloc(cert->arena, SHA1_LENGTH);
  ------------------
  |  |   53|  3.80k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
                          (unsigned char *)PORT_ArenaAlloc(cert->arena, SHA1_LENGTH);
  ------------------
  |  |  101|  3.80k|#define SHA1_LENGTH 20       /* Bytes */
  ------------------
  642|  3.80k|        if (cert->subjectKeyID.data != NULL) {
  ------------------
  |  Branch (642:13): [True: 3.80k, False: 0]
  ------------------
  643|  3.80k|            rv = PK11_HashBuf(SEC_OID_SHA1, cert->subjectKeyID.data,
  644|  3.80k|                              cert->derPublicKey.data, cert->derPublicKey.len);
  645|  3.80k|            if (rv == SECSuccess) {
  ------------------
  |  Branch (645:17): [True: 3.80k, False: 0]
  ------------------
  646|  3.80k|                cert->subjectKeyID.len = SHA1_LENGTH;
  ------------------
  |  |  101|  3.80k|#define SHA1_LENGTH 20       /* Bytes */
  ------------------
  647|  3.80k|            }
  648|  3.80k|        }
  649|  3.80k|    }
  650|       |
  651|  3.89k|    if (cert->subjectKeyID.len == 0) {
  ------------------
  |  Branch (651:9): [True: 0, False: 3.89k]
  ------------------
  652|      0|        return (SECFailure);
  653|      0|    }
  654|  3.89k|    return (SECSuccess);
  655|  3.89k|}
CERT_DecodeDERCertificate:
  721|  4.06k|{
  722|  4.06k|    CERTCertificate *cert;
  723|  4.06k|    PLArenaPool *arena;
  724|  4.06k|    void *data;
  725|  4.06k|    int rv;
  726|  4.06k|    int len;
  727|  4.06k|    char *tmpname;
  728|       |
  729|       |    /* make a new arena */
  730|  4.06k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  4.06k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  4.06k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  731|       |
  732|  4.06k|    if (!arena) {
  ------------------
  |  Branch (732:9): [True: 0, False: 4.06k]
  ------------------
  733|      0|        return 0;
  734|      0|    }
  735|       |
  736|       |    /* allocate the certificate structure */
  737|  4.06k|    cert = (CERTCertificate *)PORT_ArenaZAlloc(arena, sizeof(CERTCertificate));
  ------------------
  |  |   59|  4.06k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  738|       |
  739|  4.06k|    if (!cert) {
  ------------------
  |  Branch (739:9): [True: 0, False: 4.06k]
  ------------------
  740|      0|        goto loser;
  741|      0|    }
  742|       |
  743|  4.06k|    cert->arena = arena;
  744|       |
  745|  4.06k|    if (copyDER) {
  ------------------
  |  Branch (745:9): [True: 4.06k, False: 0]
  ------------------
  746|       |        /* copy the DER data for the cert into this arena */
  747|  4.06k|        data = (void *)PORT_ArenaAlloc(arena, derSignedCert->len);
  ------------------
  |  |   53|  4.06k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  748|  4.06k|        if (!data) {
  ------------------
  |  Branch (748:13): [True: 0, False: 4.06k]
  ------------------
  749|      0|            goto loser;
  750|      0|        }
  751|  4.06k|        cert->derCert.data = (unsigned char *)data;
  752|  4.06k|        cert->derCert.len = derSignedCert->len;
  753|  4.06k|        PORT_Memcpy(data, derSignedCert->data, derSignedCert->len);
  ------------------
  |  |  180|  4.06k|#define PORT_Memcpy memcpy
  ------------------
  754|  4.06k|    } else {
  755|       |        /* point to passed in DER data */
  756|      0|        cert->derCert = *derSignedCert;
  757|      0|    }
  758|       |
  759|       |    /* decode the certificate info */
  760|  4.06k|    rv = SEC_QuickDERDecodeItem(arena, cert, SEC_SignedCertificateTemplate,
  ------------------
  |  |  102|  4.06k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  761|  4.06k|                                &cert->derCert);
  762|       |
  763|  4.06k|    if (rv) {
  ------------------
  |  Branch (763:9): [True: 174, False: 3.89k]
  ------------------
  764|    174|        goto loser;
  765|    174|    }
  766|       |
  767|  3.89k|    if (cert_HasUnknownCriticalExten(cert->extensions) == PR_TRUE) {
  ------------------
  |  |  437|  3.89k|#define PR_TRUE 1
  ------------------
  |  Branch (767:9): [True: 6, False: 3.88k]
  ------------------
  768|      6|        cert->options.bits.hasUnsupportedCriticalExt = PR_TRUE;
  ------------------
  |  |  437|      6|#define PR_TRUE 1
  ------------------
  769|      6|    }
  770|       |
  771|       |    /* generate and save the database key for the cert */
  772|  3.89k|    rv = CERT_KeyFromIssuerAndSN(arena, &cert->derIssuer, &cert->serialNumber,
  773|  3.89k|                                 &cert->certKey);
  774|  3.89k|    if (rv) {
  ------------------
  |  Branch (774:9): [True: 0, False: 3.89k]
  ------------------
  775|      0|        goto loser;
  776|      0|    }
  777|       |
  778|       |    /* set the nickname */
  779|  3.89k|    if (nickname == NULL) {
  ------------------
  |  Branch (779:9): [True: 3.89k, False: 0]
  ------------------
  780|  3.89k|        cert->nickname = NULL;
  781|  3.89k|    } else {
  782|       |        /* copy and install the nickname */
  783|      0|        len = PORT_Strlen(nickname) + 1;
  ------------------
  |  |  190|      0|#define PORT_Strlen(s) strlen(s)
  ------------------
  784|      0|        cert->nickname = (char *)PORT_ArenaAlloc(arena, len);
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  785|      0|        if (cert->nickname == NULL) {
  ------------------
  |  Branch (785:13): [True: 0, False: 0]
  ------------------
  786|      0|            goto loser;
  787|      0|        }
  788|       |
  789|      0|        PORT_Memcpy(cert->nickname, nickname, len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  790|      0|    }
  791|       |
  792|       |    /* set the email address */
  793|  3.89k|    cert->emailAddr = cert_GetCertificateEmailAddresses(cert);
  794|       |
  795|       |    /* initialize the subjectKeyID */
  796|  3.89k|    rv = cert_GetKeyID(cert);
  797|  3.89k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (797:9): [True: 0, False: 3.89k]
  ------------------
  798|      0|        goto loser;
  799|      0|    }
  800|       |
  801|       |    /* initialize keyUsage */
  802|  3.89k|    rv = GetKeyUsage(cert);
  803|  3.89k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (803:9): [True: 0, False: 3.89k]
  ------------------
  804|      0|        goto loser;
  805|      0|    }
  806|       |
  807|       |    /* determine if this is a root cert */
  808|  3.89k|    cert->isRoot = cert_IsRootCert(cert);
  809|       |
  810|       |    /* initialize the certType */
  811|  3.89k|    rv = cert_GetCertType(cert);
  812|  3.89k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (812:9): [True: 0, False: 3.89k]
  ------------------
  813|      0|        goto loser;
  814|      0|    }
  815|       |
  816|  3.89k|    tmpname = CERT_NameToAscii(&cert->subject);
  817|  3.89k|    if (tmpname != NULL) {
  ------------------
  |  Branch (817:9): [True: 3.87k, False: 18]
  ------------------
  818|  3.87k|        cert->subjectName = PORT_ArenaStrdup(cert->arena, tmpname);
  ------------------
  |  |   57|  3.87k|#define PORT_ArenaStrdup PORT_ArenaStrdup_Util
  ------------------
  819|  3.87k|        PORT_Free(tmpname);
  ------------------
  |  |   60|  3.87k|#define PORT_Free PORT_Free_Util
  ------------------
  820|  3.87k|    }
  821|       |
  822|  3.89k|    tmpname = CERT_NameToAscii(&cert->issuer);
  823|  3.89k|    if (tmpname != NULL) {
  ------------------
  |  Branch (823:9): [True: 3.87k, False: 17]
  ------------------
  824|  3.87k|        cert->issuerName = PORT_ArenaStrdup(cert->arena, tmpname);
  ------------------
  |  |   57|  3.87k|#define PORT_ArenaStrdup PORT_ArenaStrdup_Util
  ------------------
  825|  3.87k|        PORT_Free(tmpname);
  ------------------
  |  |   60|  3.87k|#define PORT_Free PORT_Free_Util
  ------------------
  826|  3.87k|    }
  827|       |
  828|  3.89k|    cert->referenceCount = 1;
  829|  3.89k|    cert->slot = NULL;
  830|  3.89k|    cert->pkcs11ID = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  3.89k|#define CK_INVALID_HANDLE 0
  ------------------
  831|  3.89k|    cert->dbnickname = NULL;
  832|       |
  833|  3.89k|    return (cert);
  834|       |
  835|    174|loser:
  836|       |
  837|    174|    if (arena) {
  ------------------
  |  Branch (837:9): [True: 174, False: 0]
  ------------------
  838|    174|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|    174|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|    174|#define PR_FALSE 0
  ------------------
  839|    174|    }
  840|       |
  841|    174|    return (0);
  842|  3.89k|}
CERT_GetCertTimes:
  935|    340|{
  936|    340|    SECStatus rv;
  937|       |
  938|    340|    if (!c || !notBefore || !notAfter) {
  ------------------
  |  Branch (938:9): [True: 0, False: 340]
  |  Branch (938:15): [True: 0, False: 340]
  |  Branch (938:29): [True: 0, False: 340]
  ------------------
  939|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  940|      0|        return SECFailure;
  941|      0|    }
  942|       |
  943|       |    /* convert DER not-before time */
  944|    340|    rv = DER_DecodeTimeChoice(notBefore, &c->validity.notBefore);
  ------------------
  |  |   22|    340|#define DER_DecodeTimeChoice DER_DecodeTimeChoice_Util
  ------------------
  945|    340|    if (rv) {
  ------------------
  |  Branch (945:9): [True: 76, False: 264]
  ------------------
  946|     76|        return (SECFailure);
  947|     76|    }
  948|       |
  949|       |    /* convert DER not-after time */
  950|    264|    rv = DER_DecodeTimeChoice(notAfter, &c->validity.notAfter);
  ------------------
  |  |   22|    264|#define DER_DecodeTimeChoice DER_DecodeTimeChoice_Util
  ------------------
  951|    264|    if (rv) {
  ------------------
  |  Branch (951:9): [True: 44, False: 220]
  ------------------
  952|     44|        return (SECFailure);
  953|     44|    }
  954|       |
  955|    220|    return (SECSuccess);
  956|    264|}
CERT_DupCertificate:
 1269|   122k|{
 1270|   122k|    if (c) {
  ------------------
  |  Branch (1270:9): [True: 113k, False: 9.71k]
  ------------------
 1271|   113k|        NSSCertificate *tmp = STAN_GetNSSCertificate(c);
 1272|   113k|        nssCertificate_AddRef(tmp);
 1273|   113k|    }
 1274|   122k|    return c;
 1275|   122k|}
CERT_SetDefaultCertDB:
 1296|      1|{
 1297|      1|    default_cert_db_handle = handle;
 1298|       |
 1299|      1|    return;
 1300|      1|}
CERT_GetDefaultCertDB:
 1304|  9.72k|{
 1305|  9.72k|    return (default_cert_db_handle);
 1306|  9.72k|}
CERT_IsCACert:
 2113|  3.83k|{
 2114|  3.83k|    unsigned int cType = cert->nsCertType;
 2115|  3.83k|    PRBool ret = PR_FALSE;
  ------------------
  |  |  438|  3.83k|#define PR_FALSE 0
  ------------------
 2116|       |
 2117|       |    /*
 2118|       |     * Check if the constraints are available and it's a CA, OR if it's
 2119|       |     * a X.509 v1 Root CA.
 2120|       |     */
 2121|  3.83k|    CERTBasicConstraints constraints;
 2122|  3.83k|    if ((CERT_FindBasicConstraintExten(cert, &constraints) == SECSuccess &&
  ------------------
  |  Branch (2122:10): [True: 1.04k, False: 2.79k]
  ------------------
 2123|  3.83k|         constraints.isCA) ||
  ------------------
  |  Branch (2123:10): [True: 71, False: 970]
  ------------------
 2124|  3.83k|        (cert->isRoot && cert_Version(cert) < SEC_CERTIFICATE_VERSION_3))
  ------------------
  |  |  300|     98|#define SEC_CERTIFICATE_VERSION_3 2 /* v3 extensions */
  ------------------
  |  Branch (2124:10): [True: 98, False: 3.67k]
  |  Branch (2124:26): [True: 57, False: 41]
  ------------------
 2125|    128|        cType |= (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA);
  ------------------
  |  |  452|    128|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                      cType |= (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA);
  ------------------
  |  |  453|    128|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
 2126|       |
 2127|       |    /*
 2128|       |     * Apply trust overrides, if any.
 2129|       |     */
 2130|  3.83k|    cType = cert_ComputeTrustOverrides(cert, cType);
 2131|  3.83k|    ret = (cType & (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA |
  ------------------
  |  |  452|  3.83k|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
                  ret = (cType & (NS_CERT_TYPE_SSL_CA | NS_CERT_TYPE_EMAIL_CA |
  ------------------
  |  |  453|  3.83k|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
  |  Branch (2131:11): [True: 128, False: 3.71k]
  ------------------
 2132|  3.83k|                    NS_CERT_TYPE_OBJECT_SIGNING_CA))
  ------------------
  |  |  454|  3.83k|#define NS_CERT_TYPE_OBJECT_SIGNING_CA (0x01) /* bit 7 */
  ------------------
 2133|  3.83k|              ? PR_TRUE
  ------------------
  |  |  437|    128|#define PR_TRUE 1
  ------------------
 2134|  3.83k|              : PR_FALSE;
  ------------------
  |  |  438|  7.55k|#define PR_FALSE 0
  ------------------
 2135|       |
 2136|  3.83k|    if (rettype) {
  ------------------
  |  Branch (2136:9): [True: 3.83k, False: 0]
  ------------------
 2137|  3.83k|        *rettype = cType;
 2138|  3.83k|    }
 2139|       |
 2140|  3.83k|    return ret;
 2141|  3.83k|}
CERT_IsNewer:
 2219|    230|{
 2220|    230|    PRTime notBeforeA, notAfterA, notBeforeB, notAfterB, now;
 2221|    230|    SECStatus rv;
 2222|    230|    PRBool newerbefore, newerafter;
 2223|       |
 2224|    230|    rv = CERT_GetCertTimes(certa, &notBeforeA, &notAfterA);
 2225|    230|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2225:9): [True: 120, False: 110]
  ------------------
 2226|    120|        return (PR_FALSE);
  ------------------
  |  |  438|    120|#define PR_FALSE 0
  ------------------
 2227|    120|    }
 2228|       |
 2229|    110|    rv = CERT_GetCertTimes(certb, &notBeforeB, &notAfterB);
 2230|    110|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2230:9): [True: 0, False: 110]
  ------------------
 2231|      0|        return (PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2232|      0|    }
 2233|       |
 2234|    110|    newerbefore = PR_FALSE;
  ------------------
  |  |  438|    110|#define PR_FALSE 0
  ------------------
 2235|    110|    if (LL_CMP(notBeforeA, >, notBeforeB)) {
  ------------------
  |  |   79|    110|#define LL_CMP(a, op, b)    ((PRInt64)(a) op (PRInt64)(b))
  |  |  ------------------
  |  |  |  Branch (79:29): [True: 55, False: 55]
  |  |  ------------------
  ------------------
 2236|     55|        newerbefore = PR_TRUE;
  ------------------
  |  |  437|     55|#define PR_TRUE 1
  ------------------
 2237|     55|    }
 2238|       |
 2239|    110|    newerafter = PR_FALSE;
  ------------------
  |  |  438|    110|#define PR_FALSE 0
  ------------------
 2240|    110|    if (LL_CMP(notAfterA, >, notAfterB)) {
  ------------------
  |  |   79|    110|#define LL_CMP(a, op, b)    ((PRInt64)(a) op (PRInt64)(b))
  |  |  ------------------
  |  |  |  Branch (79:29): [True: 49, False: 61]
  |  |  ------------------
  ------------------
 2241|     49|        newerafter = PR_TRUE;
  ------------------
  |  |  437|     49|#define PR_TRUE 1
  ------------------
 2242|     49|    }
 2243|       |
 2244|    110|    if (newerbefore && newerafter) {
  ------------------
  |  Branch (2244:9): [True: 55, False: 55]
  |  Branch (2244:24): [True: 7, False: 48]
  ------------------
 2245|      7|        return (PR_TRUE);
  ------------------
  |  |  437|      7|#define PR_TRUE 1
  ------------------
 2246|      7|    }
 2247|       |
 2248|    103|    if ((!newerbefore) && (!newerafter)) {
  ------------------
  |  Branch (2248:9): [True: 55, False: 48]
  |  Branch (2248:27): [True: 13, False: 42]
  ------------------
 2249|     13|        return (PR_FALSE);
  ------------------
  |  |  438|     13|#define PR_FALSE 0
  ------------------
 2250|     13|    }
 2251|       |
 2252|       |    /* get current time */
 2253|     90|    now = PR_Now();
 2254|       |
 2255|     90|    if (newerbefore) {
  ------------------
  |  Branch (2255:9): [True: 48, False: 42]
  ------------------
 2256|       |        /* cert A was issued after cert B, but expires sooner */
 2257|       |        /* if A is expired, then pick B */
 2258|     48|        if (LL_CMP(notAfterA, <, now)) {
  ------------------
  |  |   79|     48|#define LL_CMP(a, op, b)    ((PRInt64)(a) op (PRInt64)(b))
  |  |  ------------------
  |  |  |  Branch (79:29): [True: 48, False: 0]
  |  |  ------------------
  ------------------
 2259|     48|            return (PR_FALSE);
  ------------------
  |  |  438|     48|#define PR_FALSE 0
  ------------------
 2260|     48|        }
 2261|      0|        return (PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2262|     48|    } else {
 2263|       |        /* cert B was issued after cert A, but expires sooner */
 2264|       |        /* if B is expired, then pick A */
 2265|     42|        if (LL_CMP(notAfterB, <, now)) {
  ------------------
  |  |   79|     42|#define LL_CMP(a, op, b)    ((PRInt64)(a) op (PRInt64)(b))
  |  |  ------------------
  |  |  |  Branch (79:29): [True: 42, False: 0]
  |  |  ------------------
  ------------------
 2266|     42|            return (PR_TRUE);
  ------------------
  |  |  437|     42|#define PR_TRUE 1
  ------------------
 2267|     42|        }
 2268|      0|        return (PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2269|     42|    }
 2270|     90|}
CERT_LockCertTrust:
 2991|  7.73k|{
 2992|  7.73k|    PORT_Assert(certTrustLock != NULL);
  ------------------
  |  |  120|  7.73k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.73k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.73k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2993|  7.73k|    PZ_Lock(certTrustLock);
  ------------------
  |  |  245|  7.73k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 2994|  7.73k|}
CERT_LockCertTempPerm:
 3003|   128k|{
 3004|   128k|    PORT_Assert(certTempPermCertLock != NULL);
  ------------------
  |  |  120|   128k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   128k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 128k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3005|   128k|    PZ_Lock(certTempPermCertLock);
  ------------------
  |  |  245|   128k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 3006|   128k|}
CERT_MaybeLockCertTempPerm:
 3013|   117k|{
 3014|   117k|    if (certTempPermCertLock) {
  ------------------
  |  Branch (3014:9): [True: 117k, False: 0]
  ------------------
 3015|   117k|        PZ_Lock(certTempPermCertLock);
  ------------------
  |  |  245|   117k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 3016|   117k|    }
 3017|   117k|}
cert_InitLocks:
 3021|      1|{
 3022|      1|    if (certRefCountLock == NULL) {
  ------------------
  |  Branch (3022:9): [True: 1, False: 0]
  ------------------
 3023|      1|        certRefCountLock = PZ_NewLock(nssILockRefLock);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 3024|      1|        PORT_Assert(certRefCountLock != NULL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3025|      1|        if (!certRefCountLock) {
  ------------------
  |  Branch (3025:13): [True: 0, False: 1]
  ------------------
 3026|      0|            return SECFailure;
 3027|      0|        }
 3028|      1|    }
 3029|       |
 3030|      1|    if (certTrustLock == NULL) {
  ------------------
  |  Branch (3030:9): [True: 1, False: 0]
  ------------------
 3031|      1|        certTrustLock = PZ_NewLock(nssILockCertDB);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 3032|      1|        PORT_Assert(certTrustLock != NULL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3033|      1|        if (!certTrustLock) {
  ------------------
  |  Branch (3033:13): [True: 0, False: 1]
  ------------------
 3034|      0|            PZ_DestroyLock(certRefCountLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 3035|      0|            certRefCountLock = NULL;
 3036|      0|            return SECFailure;
 3037|      0|        }
 3038|      1|    }
 3039|       |
 3040|      1|    if (certTempPermCertLock == NULL) {
  ------------------
  |  Branch (3040:9): [True: 1, False: 0]
  ------------------
 3041|      1|        certTempPermCertLock = PZ_NewLock(nssILockCertDB);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 3042|      1|        PORT_Assert(certTempPermCertLock != NULL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3043|      1|        if (!certTempPermCertLock) {
  ------------------
  |  Branch (3043:13): [True: 0, False: 1]
  ------------------
 3044|      0|            PZ_DestroyLock(certTrustLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 3045|      0|            PZ_DestroyLock(certRefCountLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 3046|      0|            certRefCountLock = NULL;
 3047|      0|            certTrustLock = NULL;
 3048|      0|            return SECFailure;
 3049|      0|        }
 3050|      1|    }
 3051|       |
 3052|      1|    return SECSuccess;
 3053|      1|}
cert_DestroyLocks:
 3057|      1|{
 3058|      1|    SECStatus rv = SECSuccess;
 3059|       |
 3060|      1|    PORT_Assert(certRefCountLock != NULL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3061|      1|    if (certRefCountLock) {
  ------------------
  |  Branch (3061:9): [True: 1, False: 0]
  ------------------
 3062|      1|        PZ_DestroyLock(certRefCountLock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 3063|      1|        certRefCountLock = NULL;
 3064|      1|    } else {
 3065|      0|        rv = SECFailure;
 3066|      0|    }
 3067|       |
 3068|      1|    PORT_Assert(certTrustLock != NULL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3069|      1|    if (certTrustLock) {
  ------------------
  |  Branch (3069:9): [True: 1, False: 0]
  ------------------
 3070|      1|        PZ_DestroyLock(certTrustLock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 3071|      1|        certTrustLock = NULL;
 3072|      1|    } else {
 3073|      0|        rv = SECFailure;
 3074|      0|    }
 3075|       |
 3076|      1|    PORT_Assert(certTempPermCertLock != NULL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3077|      1|    if (certTempPermCertLock) {
  ------------------
  |  Branch (3077:9): [True: 1, False: 0]
  ------------------
 3078|      1|        PZ_DestroyLock(certTempPermCertLock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 3079|      1|        certTempPermCertLock = NULL;
 3080|      1|    } else {
 3081|      0|        rv = SECFailure;
 3082|      0|    }
 3083|      1|    return rv;
 3084|      1|}
CERT_UnlockCertTrust:
 3091|  7.73k|{
 3092|  7.73k|    PORT_Assert(certTrustLock != NULL);
  ------------------
  |  |  120|  7.73k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.73k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.73k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3093|  7.73k|    PRStatus prstat = PZ_Unlock(certTrustLock);
  ------------------
  |  |  246|  7.73k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 3094|  7.73k|    PORT_AssertArg(prstat == PR_SUCCESS);
  ------------------
  |  |  124|  7.73k|#define PORT_AssertArg PR_ASSERT_ARG
  |  |  ------------------
  |  |  |  |  210|  7.73k|#define PR_ASSERT_ARG(_expr) PR_ASSERT(_expr)
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  7.73k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 7.73k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3095|  7.73k|}
CERT_UnlockCertTempPerm:
 3102|   128k|{
 3103|   128k|    PORT_Assert(certTempPermCertLock != NULL);
  ------------------
  |  |  120|   128k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   128k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 128k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3104|   128k|    PRStatus prstat = PZ_Unlock(certTempPermCertLock);
  ------------------
  |  |  246|   128k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 3105|   128k|    PORT_AssertArg(prstat == PR_SUCCESS);
  ------------------
  |  |  124|   128k|#define PORT_AssertArg PR_ASSERT_ARG
  |  |  ------------------
  |  |  |  |  210|   128k|#define PR_ASSERT_ARG(_expr) PR_ASSERT(_expr)
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   128k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 128k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3106|   128k|}
CERT_MaybeUnlockCertTempPerm:
 3110|   117k|{
 3111|   117k|    if (certTempPermCertLock) {
  ------------------
  |  Branch (3111:9): [True: 117k, False: 0]
  ------------------
 3112|   117k|        PZ_Unlock(certTempPermCertLock);
  ------------------
  |  |  246|   117k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 3113|   117k|    }
 3114|   117k|}
cert_CreateSubjectKeyIDSlotCheckHash:
 3178|      1|{
 3179|       |    /*
 3180|       |     * This hash is used to remember the series of a slot
 3181|       |     * when we last checked for user certs
 3182|       |     */
 3183|      1|    gSubjKeyIDSlotCheckHash =
 3184|      1|        PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
 3185|      1|                        SECITEM_HashCompare, &cert_AllocOps, NULL);
 3186|      1|    if (!gSubjKeyIDSlotCheckHash) {
  ------------------
  |  Branch (3186:9): [True: 0, False: 1]
  ------------------
 3187|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3188|      0|        return SECFailure;
 3189|      0|    }
 3190|      1|    gSubjKeyIDSlotCheckLock = PR_NewLock();
 3191|      1|    if (!gSubjKeyIDSlotCheckLock) {
  ------------------
  |  Branch (3191:9): [True: 0, False: 1]
  ------------------
 3192|      0|        PL_HashTableDestroy(gSubjKeyIDSlotCheckHash);
 3193|      0|        gSubjKeyIDSlotCheckHash = NULL;
 3194|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3195|      0|        return SECFailure;
 3196|      0|    }
 3197|      1|    return SECSuccess;
 3198|      1|}
cert_CreateSubjectKeyIDHashTable:
 3202|      1|{
 3203|      1|    gSubjKeyIDHash = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
 3204|      1|                                     SECITEM_HashCompare, &cert_AllocOps, NULL);
 3205|      1|    if (!gSubjKeyIDHash) {
  ------------------
  |  Branch (3205:9): [True: 0, False: 1]
  ------------------
 3206|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3207|      0|        return SECFailure;
 3208|      0|    }
 3209|      1|    gSubjKeyIDLock = PR_NewLock();
 3210|      1|    if (!gSubjKeyIDLock) {
  ------------------
  |  Branch (3210:9): [True: 0, False: 1]
  ------------------
 3211|      0|        PL_HashTableDestroy(gSubjKeyIDHash);
 3212|      0|        gSubjKeyIDHash = NULL;
 3213|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3214|      0|        return SECFailure;
 3215|      0|    }
 3216|       |    /* initialize the companion hash (for remembering slot series) */
 3217|      1|    if (cert_CreateSubjectKeyIDSlotCheckHash() != SECSuccess) {
  ------------------
  |  Branch (3217:9): [True: 0, False: 1]
  ------------------
 3218|      0|        cert_DestroySubjectKeyIDHashTable();
 3219|      0|        return SECFailure;
 3220|      0|    }
 3221|      1|    return SECSuccess;
 3222|      1|}
cert_DestroySubjectKeyIDSlotCheckHash:
 3355|      1|{
 3356|      1|    if (gSubjKeyIDSlotCheckHash) {
  ------------------
  |  Branch (3356:9): [True: 1, False: 0]
  ------------------
 3357|      1|        PR_Lock(gSubjKeyIDSlotCheckLock);
 3358|      1|        PL_HashTableDestroy(gSubjKeyIDSlotCheckHash);
 3359|      1|        gSubjKeyIDSlotCheckHash = NULL;
 3360|      1|        PR_Unlock(gSubjKeyIDSlotCheckLock);
 3361|      1|        PR_DestroyLock(gSubjKeyIDSlotCheckLock);
 3362|      1|        gSubjKeyIDSlotCheckLock = NULL;
 3363|      1|    }
 3364|      1|    return SECSuccess;
 3365|      1|}
cert_DestroySubjectKeyIDHashTable:
 3369|      1|{
 3370|      1|    if (gSubjKeyIDHash) {
  ------------------
  |  Branch (3370:9): [True: 1, False: 0]
  ------------------
 3371|      1|        PR_Lock(gSubjKeyIDLock);
 3372|      1|        PL_HashTableDestroy(gSubjKeyIDHash);
 3373|      1|        gSubjKeyIDHash = NULL;
 3374|      1|        PR_Unlock(gSubjKeyIDLock);
 3375|      1|        PR_DestroyLock(gSubjKeyIDLock);
 3376|      1|        gSubjKeyIDLock = NULL;
 3377|      1|    }
 3378|      1|    cert_DestroySubjectKeyIDSlotCheckHash();
 3379|      1|    return SECSuccess;
 3380|      1|}
certdb.c:findOIDinOIDSeqByTagNum:
  410|    714|{
  411|    714|    SECItem **oids;
  412|    714|    SECItem *oid;
  413|    714|    SECStatus rv = SECFailure;
  414|       |
  415|    714|    if (seq != NULL) {
  ------------------
  |  Branch (415:9): [True: 714, False: 0]
  ------------------
  416|    714|        oids = seq->oids;
  417|  1.20k|        while (oids != NULL && *oids != NULL) {
  ------------------
  |  Branch (417:16): [True: 1.20k, False: 0]
  |  Branch (417:32): [True: 516, False: 691]
  ------------------
  418|    516|            oid = *oids;
  419|    516|            if (SECOID_FindOIDTag(oid) == tagnum) {
  ------------------
  |  |  117|    516|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
  |  Branch (419:17): [True: 23, False: 493]
  ------------------
  420|     23|                rv = SECSuccess;
  421|     23|                break;
  422|     23|            }
  423|    493|            oids++;
  424|    493|        }
  425|    714|    }
  426|    714|    return rv;
  427|    714|}
certdb.c:GetKeyUsage:
  380|  3.89k|{
  381|  3.89k|    SECStatus rv;
  382|  3.89k|    SECItem tmpitem;
  383|       |
  384|  3.89k|    rv = CERT_FindKeyUsageExtension(cert, &tmpitem);
  385|  3.89k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (385:9): [True: 54, False: 3.83k]
  ------------------
  386|       |        /* remember the actual value of the extension */
  387|     54|        cert->rawKeyUsage = tmpitem.len ? tmpitem.data[0] : 0;
  ------------------
  |  Branch (387:29): [True: 54, False: 0]
  ------------------
  388|     54|        cert->keyUsagePresent = PR_TRUE;
  ------------------
  |  |  437|     54|#define PR_TRUE 1
  ------------------
  389|     54|        cert->keyUsage = cert->rawKeyUsage;
  390|       |
  391|     54|        PORT_Free(tmpitem.data);
  ------------------
  |  |   60|     54|#define PORT_Free PORT_Free_Util
  ------------------
  392|     54|        tmpitem.data = NULL;
  393|  3.83k|    } else {
  394|       |        /* if the extension is not present, then we allow all uses */
  395|  3.83k|        cert->keyUsage = KU_ALL;
  ------------------
  |  |  571|  3.83k|    (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  562|  3.83k|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  |  |  ------------------
  |  |                   (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  563|  3.83k|#define KU_NON_REPUDIATION (0x40)   /* bit 1 */
  |  |  ------------------
  |  |                   (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  564|  3.83k|#define KU_KEY_ENCIPHERMENT (0x20)  /* bit 2 */
  |  |  ------------------
  |  |  572|  3.83k|     KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  565|  3.83k|#define KU_DATA_ENCIPHERMENT (0x10) /* bit 3 */
  |  |  ------------------
  |  |                    KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  566|  3.83k|#define KU_KEY_AGREEMENT (0x08)     /* bit 4 */
  |  |  ------------------
  |  |                    KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  567|  3.83k|#define KU_KEY_CERT_SIGN (0x04)     /* bit 5 */
  |  |  ------------------
  |  |  573|  3.83k|     KU_CRL_SIGN | KU_ENCIPHER_ONLY)
  |  |  ------------------
  |  |  |  |  568|  3.83k|#define KU_CRL_SIGN (0x02)          /* bit 6 */
  |  |  ------------------
  |  |                    KU_CRL_SIGN | KU_ENCIPHER_ONLY)
  |  |  ------------------
  |  |  |  |  569|  3.83k|#define KU_ENCIPHER_ONLY (0x01)     /* bit 7 */
  |  |  ------------------
  ------------------
  396|  3.83k|        cert->rawKeyUsage = KU_ALL;
  ------------------
  |  |  571|  3.83k|    (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  562|  3.83k|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  |  |  ------------------
  |  |                   (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  563|  3.83k|#define KU_NON_REPUDIATION (0x40)   /* bit 1 */
  |  |  ------------------
  |  |                   (KU_DIGITAL_SIGNATURE | KU_NON_REPUDIATION | KU_KEY_ENCIPHERMENT | \
  |  |  ------------------
  |  |  |  |  564|  3.83k|#define KU_KEY_ENCIPHERMENT (0x20)  /* bit 2 */
  |  |  ------------------
  |  |  572|  3.83k|     KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  565|  3.83k|#define KU_DATA_ENCIPHERMENT (0x10) /* bit 3 */
  |  |  ------------------
  |  |                    KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  566|  3.83k|#define KU_KEY_AGREEMENT (0x08)     /* bit 4 */
  |  |  ------------------
  |  |                    KU_DATA_ENCIPHERMENT | KU_KEY_AGREEMENT | KU_KEY_CERT_SIGN |      \
  |  |  ------------------
  |  |  |  |  567|  3.83k|#define KU_KEY_CERT_SIGN (0x04)     /* bit 5 */
  |  |  ------------------
  |  |  573|  3.83k|     KU_CRL_SIGN | KU_ENCIPHER_ONLY)
  |  |  ------------------
  |  |  |  |  568|  3.83k|#define KU_CRL_SIGN (0x02)          /* bit 6 */
  |  |  ------------------
  |  |                    KU_CRL_SIGN | KU_ENCIPHER_ONLY)
  |  |  ------------------
  |  |  |  |  569|  3.83k|#define KU_ENCIPHER_ONLY (0x01)     /* bit 7 */
  |  |  ------------------
  ------------------
  397|  3.83k|        cert->keyUsagePresent = PR_FALSE;
  ------------------
  |  |  438|  3.83k|#define PR_FALSE 0
  ------------------
  398|  3.83k|    }
  399|       |
  400|  3.89k|    if (CERT_GovtApprovedBitSet(cert)) {
  ------------------
  |  Branch (400:9): [True: 0, False: 3.89k]
  ------------------
  401|      0|        cert->keyUsage |= KU_NS_GOVT_APPROVED;
  ------------------
  |  |  589|      0|#define KU_NS_GOVT_APPROVED (0x8000) /*don't make part of KU_ALL!*/
  ------------------
  402|      0|        cert->rawKeyUsage |= KU_NS_GOVT_APPROVED;
  ------------------
  |  |  589|      0|#define KU_NS_GOVT_APPROVED (0x8000) /*don't make part of KU_ALL!*/
  ------------------
  403|      0|    }
  404|       |
  405|  3.89k|    return (SECSuccess);
  406|  3.89k|}
certdb.c:cert_IsRootCert:
  659|  3.89k|{
  660|  3.89k|    SECStatus rv;
  661|  3.89k|    SECItem tmpitem;
  662|       |
  663|       |    /* cache the authKeyID extension, if present */
  664|  3.89k|    cert->authKeyID = CERT_FindAuthKeyIDExten(cert->arena, cert);
  665|       |
  666|       |    /* it MUST be self-issued to be a root */
  667|  3.89k|    if (cert->derIssuer.len == 0 ||
  ------------------
  |  Branch (667:9): [True: 0, False: 3.89k]
  ------------------
  668|  3.89k|        !SECITEM_ItemsAreEqual(&cert->derIssuer, &cert->derSubject)) {
  ------------------
  |  |  109|  3.89k|#define SECITEM_ItemsAreEqual SECITEM_ItemsAreEqual_Util
  ------------------
  |  Branch (668:9): [True: 3.76k, False: 124]
  ------------------
  669|  3.76k|        return PR_FALSE;
  ------------------
  |  |  438|  3.76k|#define PR_FALSE 0
  ------------------
  670|  3.76k|    }
  671|       |
  672|       |    /* check the authKeyID extension */
  673|    124|    if (cert->authKeyID) {
  ------------------
  |  Branch (673:9): [True: 24, False: 100]
  ------------------
  674|       |        /* authority key identifier is present */
  675|     24|        if (cert->authKeyID->keyID.len > 0) {
  ------------------
  |  Branch (675:13): [True: 17, False: 7]
  ------------------
  676|       |            /* the keyIdentifier field is set, look for subjectKeyID */
  677|     17|            rv = CERT_FindSubjectKeyIDExtension(cert, &tmpitem);
  678|     17|            if (rv == SECSuccess) {
  ------------------
  |  Branch (678:17): [True: 8, False: 9]
  ------------------
  679|      8|                PRBool match;
  680|       |                /* also present, they MUST match for it to be a root */
  681|      8|                match =
  682|      8|                    SECITEM_ItemsAreEqual(&cert->authKeyID->keyID, &tmpitem);
  ------------------
  |  |  109|      8|#define SECITEM_ItemsAreEqual SECITEM_ItemsAreEqual_Util
  ------------------
  683|      8|                PORT_Free(tmpitem.data);
  ------------------
  |  |   60|      8|#define PORT_Free PORT_Free_Util
  ------------------
  684|      8|                if (!match)
  ------------------
  |  Branch (684:21): [True: 2, False: 6]
  ------------------
  685|      2|                    return PR_FALSE; /* else fall through */
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  686|      9|            } else {
  687|       |                /* the subject key ID is required when AKI is present */
  688|      9|                return PR_FALSE;
  ------------------
  |  |  438|      9|#define PR_FALSE 0
  ------------------
  689|      9|            }
  690|     17|        }
  691|     13|        if (cert->authKeyID->authCertIssuer) {
  ------------------
  |  Branch (691:13): [True: 3, False: 10]
  ------------------
  692|      3|            SECItem *caName;
  693|      3|            caName = (SECItem *)CERT_GetGeneralNameByType(
  694|      3|                cert->authKeyID->authCertIssuer, certDirectoryName, PR_TRUE);
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
  695|      3|            if (caName) {
  ------------------
  |  Branch (695:17): [True: 2, False: 1]
  ------------------
  696|      2|                if (!SECITEM_ItemsAreEqual(&cert->derIssuer, caName)) {
  ------------------
  |  |  109|      2|#define SECITEM_ItemsAreEqual SECITEM_ItemsAreEqual_Util
  ------------------
  |  Branch (696:21): [True: 1, False: 1]
  ------------------
  697|      1|                    return PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  698|      1|                } /* else fall through */
  699|      2|            }     /* else ??? could not get general name as directory name? */
  700|      3|        }
  701|     12|        if (cert->authKeyID->authCertSerialNumber.len > 0) {
  ------------------
  |  Branch (701:13): [True: 9, False: 3]
  ------------------
  702|      9|            if (!SECITEM_ItemsAreEqual(
  ------------------
  |  |  109|      9|#define SECITEM_ItemsAreEqual SECITEM_ItemsAreEqual_Util
  ------------------
  |  Branch (702:17): [True: 8, False: 1]
  ------------------
  703|      9|                    &cert->serialNumber,
  704|      9|                    &cert->authKeyID->authCertSerialNumber)) {
  705|      8|                return PR_FALSE;
  ------------------
  |  |  438|      8|#define PR_FALSE 0
  ------------------
  706|      8|            } /* else fall through */
  707|      9|        }
  708|       |        /* all of the AKI fields that were present passed the test */
  709|      4|        return PR_TRUE;
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
  710|     12|    }
  711|       |    /* else the AKI was not present, so this is a root */
  712|    100|    return PR_TRUE;
  ------------------
  |  |  437|    100|#define PR_TRUE 1
  ------------------
  713|    124|}
certdb.c:cert_Version:
 2055|     98|{
 2056|     98|    int version = 0;
 2057|     98|    if (cert && cert->version.data && cert->version.len) {
  ------------------
  |  Branch (2057:9): [True: 98, False: 0]
  |  Branch (2057:17): [True: 97, False: 1]
  |  Branch (2057:39): [True: 97, False: 0]
  ------------------
 2058|     97|        version = DER_GetInteger(&cert->version);
  ------------------
  |  |   27|     97|#define DER_GetInteger DER_GetInteger_Util
  ------------------
 2059|     97|        if (version < 0)
  ------------------
  |  Branch (2059:13): [True: 37, False: 60]
  ------------------
 2060|     37|            version = 0;
 2061|     97|    }
 2062|     98|    return version;
 2063|     98|}
certdb.c:cert_ComputeTrustOverrides:
 2067|  3.83k|{
 2068|  3.83k|    CERTCertTrust trust;
 2069|  3.83k|    SECStatus rv = SECFailure;
 2070|       |
 2071|  3.83k|    rv = CERT_GetCertTrust(cert, &trust);
 2072|       |
 2073|  3.83k|    if (rv == SECSuccess &&
  ------------------
  |  Branch (2073:9): [True: 0, False: 3.83k]
  ------------------
 2074|  3.83k|        (trust.sslFlags | trust.emailFlags | trust.objectSigningFlags)) {
  ------------------
  |  Branch (2074:9): [True: 0, False: 0]
  ------------------
 2075|       |
 2076|      0|        if (trust.sslFlags & (CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED))
  ------------------
  |  |    9|      0|#define CERTDB_TERMINAL_RECORD (1u << 0)
  ------------------
                      if (trust.sslFlags & (CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED))
  ------------------
  |  |   10|      0|#define CERTDB_TRUSTED (1u << 1)
  ------------------
  |  Branch (2076:13): [True: 0, False: 0]
  ------------------
 2077|      0|            cType |= NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_SSL_CLIENT;
  ------------------
  |  |  448|      0|#define NS_CERT_TYPE_SSL_SERVER (0x40)        /* bit 1 */
  ------------------
                          cType |= NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_SSL_CLIENT;
  ------------------
  |  |  447|      0|#define NS_CERT_TYPE_SSL_CLIENT (0x80)        /* bit 0 */
  ------------------
 2078|      0|        if (trust.sslFlags & (CERTDB_VALID_CA | CERTDB_TRUSTED_CA))
  ------------------
  |  |   12|      0|#define CERTDB_VALID_CA (1u << 3)
  ------------------
                      if (trust.sslFlags & (CERTDB_VALID_CA | CERTDB_TRUSTED_CA))
  ------------------
  |  |   13|      0|#define CERTDB_TRUSTED_CA (1u << 4) /* trusted for issuing server certs */
  ------------------
  |  Branch (2078:13): [True: 0, False: 0]
  ------------------
 2079|      0|            cType |= NS_CERT_TYPE_SSL_CA;
  ------------------
  |  |  452|      0|#define NS_CERT_TYPE_SSL_CA (0x04)            /* bit 5 */
  ------------------
 2080|       |#if defined(CERTDB_NOT_TRUSTED)
 2081|       |        if (trust.sslFlags & CERTDB_NOT_TRUSTED)
 2082|       |            cType &= ~(NS_CERT_TYPE_SSL_SERVER | NS_CERT_TYPE_SSL_CLIENT |
 2083|       |                       NS_CERT_TYPE_SSL_CA);
 2084|       |#endif
 2085|      0|        if (trust.emailFlags & (CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED))
  ------------------
  |  |    9|      0|#define CERTDB_TERMINAL_RECORD (1u << 0)
  ------------------
                      if (trust.emailFlags & (CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED))
  ------------------
  |  |   10|      0|#define CERTDB_TRUSTED (1u << 1)
  ------------------
  |  Branch (2085:13): [True: 0, False: 0]
  ------------------
 2086|      0|            cType |= NS_CERT_TYPE_EMAIL;
  ------------------
  |  |  449|      0|#define NS_CERT_TYPE_EMAIL (0x20)             /* bit 2 */
  ------------------
 2087|      0|        if (trust.emailFlags & (CERTDB_VALID_CA | CERTDB_TRUSTED_CA))
  ------------------
  |  |   12|      0|#define CERTDB_VALID_CA (1u << 3)
  ------------------
                      if (trust.emailFlags & (CERTDB_VALID_CA | CERTDB_TRUSTED_CA))
  ------------------
  |  |   13|      0|#define CERTDB_TRUSTED_CA (1u << 4) /* trusted for issuing server certs */
  ------------------
  |  Branch (2087:13): [True: 0, False: 0]
  ------------------
 2088|      0|            cType |= NS_CERT_TYPE_EMAIL_CA;
  ------------------
  |  |  453|      0|#define NS_CERT_TYPE_EMAIL_CA (0x02)          /* bit 6 */
  ------------------
 2089|       |#if defined(CERTDB_NOT_TRUSTED)
 2090|       |        if (trust.emailFlags & CERTDB_NOT_TRUSTED)
 2091|       |            cType &= ~(NS_CERT_TYPE_EMAIL | NS_CERT_TYPE_EMAIL_CA);
 2092|       |#endif
 2093|      0|        if (trust.objectSigningFlags &
  ------------------
  |  Branch (2093:13): [True: 0, False: 0]
  ------------------
 2094|      0|            (CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED))
  ------------------
  |  |    9|      0|#define CERTDB_TERMINAL_RECORD (1u << 0)
  ------------------
                          (CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED))
  ------------------
  |  |   10|      0|#define CERTDB_TRUSTED (1u << 1)
  ------------------
 2095|      0|            cType |= NS_CERT_TYPE_OBJECT_SIGNING;
  ------------------
  |  |  450|      0|#define NS_CERT_TYPE_OBJECT_SIGNING (0x10)    /* bit 3 */
  ------------------
 2096|      0|        if (trust.objectSigningFlags & (CERTDB_VALID_CA | CERTDB_TRUSTED_CA))
  ------------------
  |  |   12|      0|#define CERTDB_VALID_CA (1u << 3)
  ------------------
                      if (trust.objectSigningFlags & (CERTDB_VALID_CA | CERTDB_TRUSTED_CA))
  ------------------
  |  |   13|      0|#define CERTDB_TRUSTED_CA (1u << 4) /* trusted for issuing server certs */
  ------------------
  |  Branch (2096:13): [True: 0, False: 0]
  ------------------
 2097|      0|            cType |= NS_CERT_TYPE_OBJECT_SIGNING_CA;
  ------------------
  |  |  454|      0|#define NS_CERT_TYPE_OBJECT_SIGNING_CA (0x01) /* bit 7 */
  ------------------
 2098|       |#if defined(CERTDB_NOT_TRUSTED)
 2099|       |        if (trust.objectSigningFlags & CERTDB_NOT_TRUSTED)
 2100|       |            cType &=
 2101|       |                ~(NS_CERT_TYPE_OBJECT_SIGNING | NS_CERT_TYPE_OBJECT_SIGNING_CA);
 2102|       |#endif
 2103|      0|    }
 2104|  3.83k|    return cType;
 2105|  3.83k|}
certdb.c:cert_AllocTable:
 3147|      4|{
 3148|      4|    return PORT_Alloc(size);
  ------------------
  |  |   52|      4|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 3149|      4|}
certdb.c:cert_FreeTable:
 3153|      4|{
 3154|      4|    PORT_Free(item);
  ------------------
  |  |   60|      4|#define PORT_Free PORT_Free_Util
  ------------------
 3155|      4|}

CERT_FindCertExtension:
   25|  11.6k|{
   26|  11.6k|    return (cert_FindExtension(cert->extensions, tag, value));
   27|  11.6k|}
CERT_FindNSCertTypeExtension:
   49|  3.89k|{
   50|       |
   51|  3.89k|    return (CERT_FindBitStringExtension(
   52|  3.89k|        cert->extensions, SEC_OID_NS_CERT_EXT_CERT_TYPE, retItem));
   53|  3.89k|}
CERT_FindKeyUsageExtension:
  112|  3.89k|{
  113|       |
  114|  3.89k|    return (CERT_FindBitStringExtension(cert->extensions,
  115|  3.89k|                                        SEC_OID_X509_KEY_USAGE, retItem));
  116|  3.89k|}
CERT_FindSubjectKeyIDExtension:
  123|  3.90k|{
  124|       |
  125|  3.90k|    SECStatus rv;
  126|  3.90k|    SECItem encodedValue = { siBuffer, NULL, 0 };
  127|  3.90k|    SECItem decodedValue = { siBuffer, NULL, 0 };
  128|       |
  129|  3.90k|    rv = cert_FindExtension(cert->extensions, SEC_OID_X509_SUBJECT_KEY_ID,
  130|  3.90k|                            &encodedValue);
  131|  3.90k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (131:9): [True: 221, False: 3.68k]
  ------------------
  132|    221|        PORTCheapArenaPool tmpArena;
  133|    221|        PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|    221|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  134|    221|        rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &decodedValue,
  ------------------
  |  |  102|    221|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  135|    221|                                    SEC_ASN1_GET(SEC_OctetStringTemplate),
  ------------------
  |  |  188|    221|#define SEC_ASN1_GET(x) x
  ------------------
  136|    221|                                    &encodedValue);
  137|    221|        if (rv == SECSuccess) {
  ------------------
  |  Branch (137:13): [True: 91, False: 130]
  ------------------
  138|     91|            rv = SECITEM_CopyItem(NULL, retItem, &decodedValue);
  ------------------
  |  |  106|     91|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  139|     91|        }
  140|    221|        PORT_DestroyCheapArena(&tmpArena);
  141|    221|    }
  142|  3.90k|    SECITEM_FreeItem(&encodedValue, PR_FALSE);
  ------------------
  |  |  108|  3.90k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&encodedValue, PR_FALSE);
  ------------------
  |  |  438|  3.90k|#define PR_FALSE 0
  ------------------
  143|  3.90k|    return rv;
  144|  3.90k|}
CERT_FindBasicConstraintExten:
  149|  7.73k|{
  150|  7.73k|    SECItem encodedExtenValue;
  151|  7.73k|    SECStatus rv;
  152|       |
  153|  7.73k|    encodedExtenValue.data = NULL;
  154|  7.73k|    encodedExtenValue.len = 0;
  155|       |
  156|  7.73k|    rv = cert_FindExtension(cert->extensions, SEC_OID_X509_BASIC_CONSTRAINTS,
  157|  7.73k|                            &encodedExtenValue);
  158|  7.73k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (158:9): [True: 4.18k, False: 3.54k]
  ------------------
  159|  4.18k|        return (rv);
  160|  4.18k|    }
  161|       |
  162|  3.54k|    rv = CERT_DecodeBasicConstraintValue(value, &encodedExtenValue);
  163|       |
  164|       |    /* free the raw extension data */
  165|  3.54k|    PORT_Free(encodedExtenValue.data);
  ------------------
  |  |   60|  3.54k|#define PORT_Free PORT_Free_Util
  ------------------
  166|  3.54k|    encodedExtenValue.data = NULL;
  167|       |
  168|  3.54k|    return (rv);
  169|  7.73k|}
CERT_FindAuthKeyIDExten:
  173|  3.89k|{
  174|  3.89k|    SECItem encodedExtenValue;
  175|  3.89k|    SECStatus rv;
  176|  3.89k|    CERTAuthKeyID *ret;
  177|       |
  178|  3.89k|    encodedExtenValue.data = NULL;
  179|  3.89k|    encodedExtenValue.len = 0;
  180|       |
  181|  3.89k|    rv = cert_FindExtension(cert->extensions, SEC_OID_X509_AUTH_KEY_ID,
  182|  3.89k|                            &encodedExtenValue);
  183|  3.89k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (183:9): [True: 3.62k, False: 266]
  ------------------
  184|  3.62k|        return (NULL);
  185|  3.62k|    }
  186|       |
  187|    266|    ret = CERT_DecodeAuthKeyID(arena, &encodedExtenValue);
  188|       |
  189|    266|    PORT_Free(encodedExtenValue.data);
  ------------------
  |  |   60|    266|#define PORT_Free PORT_Free_Util
  ------------------
  190|    266|    encodedExtenValue.data = NULL;
  191|       |
  192|    266|    return (ret);
  193|  3.89k|}

cert_FindExtensionByOID:
   49|  34.9k|{
   50|  34.9k|    CERTCertExtension *ext;
   51|  34.9k|    SECStatus rv = SECSuccess;
   52|       |
   53|  34.9k|    ext = GetExtension(extensions, oid);
   54|  34.9k|    if (ext == NULL) {
  ------------------
  |  Branch (54:9): [True: 27.6k, False: 7.34k]
  ------------------
   55|  27.6k|        PORT_SetError(SEC_ERROR_EXTENSION_NOT_FOUND);
  ------------------
  |  |   65|  27.6k|#define PORT_SetError PORT_SetError_Util
  ------------------
   56|  27.6k|        return (SECFailure);
   57|  27.6k|    }
   58|  7.34k|    if (value)
  ------------------
  |  Branch (58:9): [True: 7.34k, False: 0]
  ------------------
   59|  7.34k|        rv = SECITEM_CopyItem(NULL, value, &ext->value);
  ------------------
  |  |  106|  7.34k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
   60|  7.34k|    return (rv);
   61|  34.9k|}
cert_FindExtension:
   95|  34.9k|{
   96|  34.9k|    SECOidData *oid;
   97|       |
   98|  34.9k|    oid = SECOID_FindOIDByTag((SECOidTag)tag);
  ------------------
  |  |  116|  34.9k|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
   99|  34.9k|    if (!oid) {
  ------------------
  |  Branch (99:9): [True: 0, False: 34.9k]
  ------------------
  100|      0|        return (SECFailure);
  101|      0|    }
  102|       |
  103|  34.9k|    return (cert_FindExtensionByOID(extensions, &oid->oid, value));
  104|  34.9k|}
CERT_FindBitStringExtension:
  397|  7.78k|{
  398|  7.78k|    SECItem wrapperItem, tmpItem = { siBuffer, 0 };
  399|  7.78k|    SECStatus rv;
  400|  7.78k|    PORTCheapArenaPool tmpArena;
  401|       |
  402|  7.78k|    wrapperItem.data = NULL;
  403|  7.78k|    tmpItem.data = NULL;
  404|       |
  405|  7.78k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  7.78k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  406|       |
  407|  7.78k|    rv = cert_FindExtension(extensions, tag, &wrapperItem);
  408|  7.78k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (408:9): [True: 4.70k, False: 3.07k]
  ------------------
  409|  4.70k|        goto loser;
  410|  4.70k|    }
  411|       |
  412|  3.07k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &tmpItem,
  ------------------
  |  |  102|  3.07k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  413|  3.07k|                                SEC_ASN1_GET(SEC_BitStringTemplate),
  ------------------
  |  |  188|  3.07k|#define SEC_ASN1_GET(x) x
  ------------------
  414|  3.07k|                                &wrapperItem);
  415|       |
  416|  3.07k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (416:9): [True: 3.02k, False: 54]
  ------------------
  417|  3.02k|        goto loser;
  418|  3.02k|    }
  419|       |
  420|     54|    retItem->data = (unsigned char *)PORT_ZAlloc((tmpItem.len + 7) >> 3);
  ------------------
  |  |   72|     54|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  421|     54|    if (retItem->data == NULL) {
  ------------------
  |  Branch (421:9): [True: 0, False: 54]
  ------------------
  422|      0|        goto loser;
  423|      0|    }
  424|       |
  425|     54|    if (tmpItem.len > 0) {
  ------------------
  |  Branch (425:9): [True: 54, False: 0]
  ------------------
  426|     54|        PORT_Memcpy(retItem->data, tmpItem.data, (tmpItem.len + 7) >> 3);
  ------------------
  |  |  180|     54|#define PORT_Memcpy memcpy
  ------------------
  427|     54|    }
  428|       |
  429|     54|    retItem->len = tmpItem.len;
  430|       |
  431|     54|    rv = SECSuccess;
  432|     54|    goto done;
  433|       |
  434|  7.72k|loser:
  435|  7.72k|    rv = SECFailure;
  436|       |
  437|  7.78k|done:
  438|  7.78k|    PORT_DestroyCheapArena(&tmpArena);
  439|       |
  440|  7.78k|    if (wrapperItem.data) {
  ------------------
  |  Branch (440:9): [True: 3.07k, False: 4.70k]
  ------------------
  441|  3.07k|        PORT_Free(wrapperItem.data);
  ------------------
  |  |   60|  3.07k|#define PORT_Free PORT_Free_Util
  ------------------
  442|  3.07k|    }
  443|       |
  444|  7.78k|    return (rv);
  445|  7.72k|}
cert_HasUnknownCriticalExten:
  472|  3.89k|{
  473|  3.89k|    CERTCertExtension **exts;
  474|  3.89k|    CERTCertExtension *ext = NULL;
  475|  3.89k|    PRBool hasUnknownCriticalExten = PR_FALSE;
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  476|       |
  477|  3.89k|    exts = extensions;
  478|       |
  479|  3.89k|    if (exts) {
  ------------------
  |  Branch (479:9): [True: 3.79k, False: 94]
  ------------------
  480|  11.5k|        while (*exts) {
  ------------------
  |  Branch (480:16): [True: 7.74k, False: 3.79k]
  ------------------
  481|  7.74k|            ext = *exts;
  482|       |            /* If the criticality is omitted, it's non-critical.
  483|       |               If an extension is critical, make sure that we know
  484|       |               how to process the extension.
  485|       |             */
  486|  7.74k|            if (ext->critical.data && ext->critical.data[0] == 0xff) {
  ------------------
  |  Branch (486:17): [True: 55, False: 7.68k]
  |  Branch (486:39): [True: 39, False: 16]
  ------------------
  487|     39|                if (SECOID_KnownCertExtenOID(&ext->id) == PR_FALSE) {
  ------------------
  |  |  438|     39|#define PR_FALSE 0
  ------------------
  |  Branch (487:21): [True: 6, False: 33]
  ------------------
  488|      6|                    hasUnknownCriticalExten = PR_TRUE;
  ------------------
  |  |  437|      6|#define PR_TRUE 1
  ------------------
  489|      6|                    break;
  490|      6|                }
  491|     39|            }
  492|  7.73k|            exts++;
  493|  7.73k|        }
  494|  3.79k|    }
  495|  3.89k|    return (hasUnknownCriticalExten);
  496|  3.89k|}
certxutl.c:GetExtension:
   25|  34.9k|{
   26|  34.9k|    CERTCertExtension **exts;
   27|  34.9k|    CERTCertExtension *ext = NULL;
   28|  34.9k|    SECComparison comp;
   29|       |
   30|  34.9k|    exts = extensions;
   31|       |
   32|  34.9k|    if (exts) {
  ------------------
  |  Branch (32:9): [True: 34.1k, False: 846]
  ------------------
   33|  90.4k|        while (*exts) {
  ------------------
  |  Branch (33:16): [True: 63.6k, False: 26.7k]
  ------------------
   34|  63.6k|            ext = *exts;
   35|  63.6k|            comp = SECITEM_CompareItem(oid, &ext->id);
  ------------------
  |  |  105|  63.6k|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
   36|  63.6k|            if (comp == SECEqual)
  ------------------
  |  Branch (36:17): [True: 7.34k, False: 56.2k]
  ------------------
   37|  7.34k|                break;
   38|       |
   39|  56.2k|            exts++;
   40|  56.2k|        }
   41|  34.1k|        return (*exts ? ext : NULL);
  ------------------
  |  Branch (41:17): [True: 7.34k, False: 26.7k]
  ------------------
   42|  34.1k|    }
   43|    846|    return (NULL);
   44|  34.9k|}

InitCRLCache:
  962|      1|{
  963|      1|    if (PR_FALSE == crlcache_initialized) {
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  |  Branch (963:9): [True: 1, False: 0]
  ------------------
  964|      1|        PORT_Assert(NULL == crlcache.lock);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  965|      1|        PORT_Assert(NULL == crlcache.issuers);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  966|      1|        PORT_Assert(NULL == namedCRLCache.lock);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  967|      1|        PORT_Assert(NULL == namedCRLCache.entries);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  968|      1|        if (crlcache.lock || crlcache.issuers || namedCRLCache.lock ||
  ------------------
  |  Branch (968:13): [True: 0, False: 1]
  |  Branch (968:30): [True: 0, False: 1]
  |  Branch (968:50): [True: 0, False: 1]
  ------------------
  969|      1|            namedCRLCache.entries) {
  ------------------
  |  Branch (969:13): [True: 0, False: 1]
  ------------------
  970|       |            /* CRL cache already partially initialized */
  971|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  972|      0|            return SECFailure;
  973|      0|        }
  974|       |#ifdef GLOBAL_RWLOCK
  975|       |        crlcache.lock = NSSRWLock_New(NSS_RWLOCK_RANK_NONE, NULL);
  976|       |#else
  977|      1|        crlcache.lock = PR_NewLock();
  978|      1|#endif
  979|      1|        namedCRLCache.lock = PR_NewLock();
  980|      1|        crlcache.issuers = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
  981|      1|                                           PL_CompareValues, NULL, NULL);
  982|      1|        namedCRLCache.entries = PL_NewHashTable(
  983|      1|            0, SECITEM_Hash, SECITEM_HashCompare, PL_CompareValues, NULL, NULL);
  984|      1|        if (!crlcache.lock || !namedCRLCache.lock || !crlcache.issuers ||
  ------------------
  |  Branch (984:13): [True: 0, False: 1]
  |  Branch (984:31): [True: 0, False: 1]
  |  Branch (984:54): [True: 0, False: 1]
  ------------------
  985|      1|            !namedCRLCache.entries) {
  ------------------
  |  Branch (985:13): [True: 0, False: 1]
  ------------------
  986|      0|            if (crlcache.lock) {
  ------------------
  |  Branch (986:17): [True: 0, False: 0]
  ------------------
  987|       |#ifdef GLOBAL_RWLOCK
  988|       |                NSSRWLock_Destroy(crlcache.lock);
  989|       |#else
  990|      0|                PR_DestroyLock(crlcache.lock);
  991|      0|#endif
  992|      0|                crlcache.lock = NULL;
  993|      0|            }
  994|      0|            if (namedCRLCache.lock) {
  ------------------
  |  Branch (994:17): [True: 0, False: 0]
  ------------------
  995|      0|                PR_DestroyLock(namedCRLCache.lock);
  996|      0|                namedCRLCache.lock = NULL;
  997|      0|            }
  998|      0|            if (crlcache.issuers) {
  ------------------
  |  Branch (998:17): [True: 0, False: 0]
  ------------------
  999|      0|                PL_HashTableDestroy(crlcache.issuers);
 1000|      0|                crlcache.issuers = NULL;
 1001|      0|            }
 1002|      0|            if (namedCRLCache.entries) {
  ------------------
  |  Branch (1002:17): [True: 0, False: 0]
  ------------------
 1003|      0|                PL_HashTableDestroy(namedCRLCache.entries);
 1004|      0|                namedCRLCache.entries = NULL;
 1005|      0|            }
 1006|       |
 1007|      0|            return SECFailure;
 1008|      0|        }
 1009|      1|        crlcache_initialized = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1010|      1|        return SECSuccess;
 1011|      1|    } else {
 1012|      0|        PORT_Assert(crlcache.lock);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1013|      0|        PORT_Assert(crlcache.issuers);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1014|      0|        if ((NULL == crlcache.lock) || (NULL == crlcache.issuers)) {
  ------------------
  |  Branch (1014:13): [True: 0, False: 0]
  |  Branch (1014:40): [True: 0, False: 0]
  ------------------
 1015|       |            /* CRL cache not fully initialized */
 1016|      0|            return SECFailure;
 1017|      0|        } else {
 1018|       |            /* CRL cache already initialized */
 1019|      0|            return SECSuccess;
 1020|      0|        }
 1021|      0|    }
 1022|      1|}
ShutdownCRLCache:
 1202|      1|{
 1203|      1|    SECStatus rv = SECSuccess;
 1204|      1|    if (PR_FALSE == crlcache_initialized && !crlcache.lock &&
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  |  Branch (1204:9): [True: 0, False: 1]
  |  Branch (1204:45): [True: 0, False: 0]
  ------------------
 1205|      1|        !crlcache.issuers) {
  ------------------
  |  Branch (1205:9): [True: 0, False: 0]
  ------------------
 1206|       |        /* CRL cache has already been shut down */
 1207|      0|        return SECSuccess;
 1208|      0|    }
 1209|      1|    if (PR_TRUE == crlcache_initialized &&
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  |  Branch (1209:9): [True: 1, False: 0]
  ------------------
 1210|      1|        (!crlcache.lock || !crlcache.issuers || !namedCRLCache.lock ||
  ------------------
  |  Branch (1210:10): [True: 0, False: 1]
  |  Branch (1210:28): [True: 0, False: 1]
  |  Branch (1210:49): [True: 0, False: 1]
  ------------------
 1211|      1|         !namedCRLCache.entries)) {
  ------------------
  |  Branch (1211:10): [True: 0, False: 1]
  ------------------
 1212|       |        /* CRL cache has partially been shut down */
 1213|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1214|      0|        return SECFailure;
 1215|      0|    }
 1216|       |    /* empty the CRL cache */
 1217|       |    /* free the issuers */
 1218|      1|    PL_HashTableEnumerateEntries(crlcache.issuers, &FreeIssuer, &rv);
 1219|       |    /* free the hash table of issuers */
 1220|      1|    PL_HashTableDestroy(crlcache.issuers);
 1221|      1|    crlcache.issuers = NULL;
 1222|       |/* free the global lock */
 1223|       |#ifdef GLOBAL_RWLOCK
 1224|       |    NSSRWLock_Destroy(crlcache.lock);
 1225|       |#else
 1226|      1|    PR_DestroyLock(crlcache.lock);
 1227|      1|#endif
 1228|      1|    crlcache.lock = NULL;
 1229|       |
 1230|       |    /* empty the named CRL cache. This must be done after freeing the CRL
 1231|       |     * cache, since some CRLs in this cache are in the memory for the other  */
 1232|       |    /* free the entries */
 1233|      1|    PL_HashTableEnumerateEntries(namedCRLCache.entries, &FreeNamedEntries, &rv);
 1234|       |    /* free the hash table of issuers */
 1235|      1|    PL_HashTableDestroy(namedCRLCache.entries);
 1236|      1|    namedCRLCache.entries = NULL;
 1237|       |    /* free the global lock */
 1238|      1|    PR_DestroyLock(namedCRLCache.lock);
 1239|      1|    namedCRLCache.lock = NULL;
 1240|       |
 1241|      1|    crlcache_initialized = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1242|      1|    return rv;
 1243|      1|}

CERT_NewGeneralName:
  153|     95|{
  154|     95|    CERTGeneralName *name = arena ? PORT_ArenaZNew(arena, CERTGeneralName)
  ------------------
  |  |  155|     95|    (type *)PORT_ArenaZAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   59|     95|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  |  |  ------------------
  ------------------
  |  Branch (154:29): [True: 95, False: 0]
  ------------------
  155|     95|                                  : PORT_ZNew(CERTGeneralName);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  156|     95|    if (name) {
  ------------------
  |  Branch (156:9): [True: 95, False: 0]
  ------------------
  157|     95|        name->type = type;
  158|     95|        name->l.prev = name->l.next = &name->l;
  159|     95|    }
  160|     95|    return name;
  161|     95|}
CERT_GetNextGeneralName:
  264|     94|{
  265|     94|    PRCList *next;
  266|       |
  267|     94|    next = current->l.next;
  268|     94|    return (CERTGeneralName *)(((char *)next) - offsetof(CERTGeneralName, l));
  269|     94|}
CERT_DecodeGeneralName:
  418|     95|{
  419|     95|    const SEC_ASN1Template *template;
  420|     95|    CERTGeneralNameType genNameType;
  421|     95|    SECStatus rv = SECSuccess;
  422|     95|    SECItem *newEncodedName;
  423|       |
  424|     95|    if (!reqArena) {
  ------------------
  |  Branch (424:9): [True: 0, False: 95]
  ------------------
  425|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  426|      0|        return NULL;
  427|      0|    }
  428|       |    /* make a copy for decoding so the data decoded with QuickDER doesn't
  429|       |       point to temporary memory */
  430|     95|    newEncodedName = SECITEM_ArenaDupItem(reqArena, encodedName);
  ------------------
  |  |  104|     95|#define SECITEM_ArenaDupItem SECITEM_ArenaDupItem_Util
  ------------------
  431|     95|    if (!newEncodedName) {
  ------------------
  |  Branch (431:9): [True: 0, False: 95]
  ------------------
  432|      0|        return NULL;
  433|      0|    }
  434|       |    /* TODO: mark arena */
  435|     95|    genNameType = (CERTGeneralNameType)((*(newEncodedName->data) & 0x0f) + 1);
  436|     95|    if (genName == NULL) {
  ------------------
  |  Branch (436:9): [True: 95, False: 0]
  ------------------
  437|     95|        genName = CERT_NewGeneralName(reqArena, genNameType);
  438|     95|        if (!genName)
  ------------------
  |  Branch (438:13): [True: 0, False: 95]
  ------------------
  439|      0|            goto loser;
  440|     95|    } else {
  441|      0|        genName->type = genNameType;
  442|      0|        genName->l.prev = genName->l.next = &genName->l;
  443|      0|    }
  444|       |
  445|     95|    switch (genNameType) {
  446|      4|        case certURI:
  ------------------
  |  Branch (446:9): [True: 4, False: 91]
  ------------------
  447|      4|            template = CERT_URITemplate;
  448|      4|            break;
  449|     37|        case certRFC822Name:
  ------------------
  |  Branch (449:9): [True: 37, False: 58]
  ------------------
  450|     37|            template = CERT_RFC822NameTemplate;
  451|     37|            break;
  452|     17|        case certDNSName:
  ------------------
  |  Branch (452:9): [True: 17, False: 78]
  ------------------
  453|     17|            template = CERT_DNSNameTemplate;
  454|     17|            break;
  455|      3|        case certIPAddress:
  ------------------
  |  Branch (455:9): [True: 3, False: 92]
  ------------------
  456|      3|            template = CERT_IPAddressTemplate;
  457|      3|            break;
  458|      5|        case certOtherName:
  ------------------
  |  Branch (458:9): [True: 5, False: 90]
  ------------------
  459|      5|            template = CERTOtherNameTemplate;
  460|      5|            break;
  461|      4|        case certRegisterID:
  ------------------
  |  Branch (461:9): [True: 4, False: 91]
  ------------------
  462|      4|            template = CERT_RegisteredIDTemplate;
  463|      4|            break;
  464|      2|        case certEDIPartyName:
  ------------------
  |  Branch (464:9): [True: 2, False: 93]
  ------------------
  465|      2|            template = CERT_EDIPartyNameTemplate;
  466|      2|            break;
  467|      7|        case certX400Address:
  ------------------
  |  Branch (467:9): [True: 7, False: 88]
  ------------------
  468|      7|            template = CERT_X400AddressTemplate;
  469|      7|            break;
  470|     12|        case certDirectoryName:
  ------------------
  |  Branch (470:9): [True: 12, False: 83]
  ------------------
  471|     12|            template = CERT_DirectoryNameTemplate;
  472|     12|            break;
  473|      4|        default:
  ------------------
  |  Branch (473:9): [True: 4, False: 91]
  ------------------
  474|      4|            goto loser;
  475|     95|    }
  476|     91|    rv = SEC_QuickDERDecodeItem(reqArena, genName, template, newEncodedName);
  ------------------
  |  |  102|     91|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  477|     91|    if (rv != SECSuccess)
  ------------------
  |  Branch (477:9): [True: 15, False: 76]
  ------------------
  478|     15|        goto loser;
  479|     76|    if (genNameType == certDirectoryName) {
  ------------------
  |  Branch (479:9): [True: 9, False: 67]
  ------------------
  480|      9|        rv = SEC_QuickDERDecodeItem(reqArena, &(genName->name.directoryName),
  ------------------
  |  |  102|      9|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  481|      9|                                    CERT_NameTemplate,
  482|      9|                                    &(genName->derDirectoryName));
  483|      9|        if (rv != SECSuccess)
  ------------------
  |  Branch (483:13): [True: 6, False: 3]
  ------------------
  484|      6|            goto loser;
  485|      9|    }
  486|       |
  487|       |    /* TODO: unmark arena */
  488|     70|    return genName;
  489|     25|loser:
  490|       |    /* TODO: release arena to mark */
  491|     25|    return NULL;
  492|     76|}
cert_DecodeGeneralNames:
  496|    181|{
  497|    181|    PRCList *head = NULL;
  498|    181|    PRCList *tail = NULL;
  499|    181|    CERTGeneralName *currentName = NULL;
  500|       |
  501|    181|    PORT_Assert(arena);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  502|    181|    if (!encodedGenName || !arena) {
  ------------------
  |  Branch (502:9): [True: 121, False: 60]
  |  Branch (502:28): [True: 0, False: 60]
  ------------------
  503|    121|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|    121|#define PORT_SetError PORT_SetError_Util
  ------------------
  504|    121|        return NULL;
  505|    121|    }
  506|       |    /* TODO: mark arena */
  507|    130|    while (*encodedGenName != NULL) {
  ------------------
  |  Branch (507:12): [True: 95, False: 35]
  ------------------
  508|     95|        currentName = CERT_DecodeGeneralName(arena, *encodedGenName, NULL);
  509|     95|        if (currentName == NULL)
  ------------------
  |  Branch (509:13): [True: 25, False: 70]
  ------------------
  510|     25|            break;
  511|     70|        if (head == NULL) {
  ------------------
  |  Branch (511:13): [True: 38, False: 32]
  ------------------
  512|     38|            head = &(currentName->l);
  513|     38|            tail = head;
  514|     38|        }
  515|     70|        currentName->l.next = head;
  516|     70|        currentName->l.prev = tail;
  517|     70|        tail = head->prev = tail->next = &(currentName->l);
  518|     70|        encodedGenName++;
  519|     70|    }
  520|     60|    if (currentName) {
  ------------------
  |  Branch (520:9): [True: 35, False: 25]
  ------------------
  521|       |        /* TODO: unmark arena */
  522|     35|        return CERT_GetNextGeneralName(currentName);
  523|     35|    }
  524|       |    /* TODO: release arena to mark */
  525|     25|    return NULL;
  526|     60|}
CERT_GetGeneralNameByType:
  979|      3|{
  980|      3|    CERTGeneralName *current;
  981|       |
  982|      3|    if (!genNames)
  ------------------
  |  Branch (982:9): [True: 0, False: 3]
  ------------------
  983|      0|        return NULL;
  984|      3|    current = genNames;
  985|       |
  986|      4|    do {
  987|      4|        if (current->type == type) {
  ------------------
  |  Branch (987:13): [True: 2, False: 2]
  ------------------
  988|      2|            switch (type) {
  ------------------
  |  Branch (988:21): [True: 0, False: 2]
  ------------------
  989|      0|                case certDNSName:
  ------------------
  |  Branch (989:17): [True: 0, False: 2]
  ------------------
  990|      0|                case certEDIPartyName:
  ------------------
  |  Branch (990:17): [True: 0, False: 2]
  ------------------
  991|      0|                case certIPAddress:
  ------------------
  |  Branch (991:17): [True: 0, False: 2]
  ------------------
  992|      0|                case certRegisterID:
  ------------------
  |  Branch (992:17): [True: 0, False: 2]
  ------------------
  993|      0|                case certRFC822Name:
  ------------------
  |  Branch (993:17): [True: 0, False: 2]
  ------------------
  994|      0|                case certX400Address:
  ------------------
  |  Branch (994:17): [True: 0, False: 2]
  ------------------
  995|      0|                case certURI:
  ------------------
  |  Branch (995:17): [True: 0, False: 2]
  ------------------
  996|      0|                    return (void *)&current->name.other; /* SECItem * */
  997|       |
  998|      0|                case certOtherName:
  ------------------
  |  Branch (998:17): [True: 0, False: 2]
  ------------------
  999|      0|                    return (void *)&current->name.OthName; /* OthName * */
 1000|       |
 1001|      2|                case certDirectoryName:
  ------------------
  |  Branch (1001:17): [True: 2, False: 0]
  ------------------
 1002|      2|                    return derFormat
  ------------------
  |  Branch (1002:28): [True: 2, False: 0]
  ------------------
 1003|      2|                               ? (void *)&current
 1004|      2|                                     ->derDirectoryName /* SECItem * */
 1005|      2|                               : (void *)&current->name
 1006|      0|                                     .directoryName; /* CERTName * */
 1007|      2|            }
 1008|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1009|      0|            return NULL;
 1010|      2|        }
 1011|      2|        current = CERT_GetNextGeneralName(current);
 1012|      2|    } while (current != genNames);
  ------------------
  |  Branch (1012:14): [True: 1, False: 1]
  ------------------
 1013|      1|    return NULL;
 1014|      3|}

CERT_DecodeOidSequence:
  590|    160|{
  591|    160|    PLArenaPool *arena = NULL;
  592|    160|    SECStatus rv;
  593|    160|    CERTOidSequence *oidSeq;
  594|    160|    SECItem newSeqItem;
  595|       |
  596|       |    /* make a new arena */
  597|    160|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|    160|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|    160|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  598|       |
  599|    160|    if (!arena) {
  ------------------
  |  Branch (599:9): [True: 0, False: 160]
  ------------------
  600|      0|        goto loser;
  601|      0|    }
  602|       |
  603|       |    /* allocate the userNotice structure */
  604|    160|    oidSeq =
  605|    160|        (CERTOidSequence *)PORT_ArenaZAlloc(arena, sizeof(CERTOidSequence));
  ------------------
  |  |   59|    160|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  606|       |
  607|    160|    if (oidSeq == NULL) {
  ------------------
  |  Branch (607:9): [True: 0, False: 160]
  ------------------
  608|      0|        goto loser;
  609|      0|    }
  610|       |
  611|    160|    oidSeq->arena = arena;
  612|       |
  613|       |    /* copy the DER into the arena, since Quick DER returns data that points
  614|       |       into the DER input, which may get freed by the caller */
  615|    160|    rv = SECITEM_CopyItem(arena, &newSeqItem, seqItem);
  ------------------
  |  |  106|    160|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  616|    160|    if (rv != SECSuccess) {
  ------------------
  |  Branch (616:9): [True: 0, False: 160]
  ------------------
  617|      0|        goto loser;
  618|      0|    }
  619|       |
  620|       |    /* decode the user notice */
  621|    160|    rv =
  622|    160|        SEC_QuickDERDecodeItem(arena, oidSeq, CERT_OidSeqTemplate, &newSeqItem);
  ------------------
  |  |  102|    160|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  623|       |
  624|    160|    if (rv != SECSuccess) {
  ------------------
  |  Branch (624:9): [True: 56, False: 104]
  ------------------
  625|     56|        goto loser;
  626|     56|    }
  627|       |
  628|    104|    return (oidSeq);
  629|       |
  630|     56|loser:
  631|     56|    if (arena) {
  ------------------
  |  Branch (631:9): [True: 56, False: 0]
  ------------------
  632|     56|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|     56|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|     56|#define PR_FALSE 0
  ------------------
  633|     56|    }
  634|     56|    return (NULL);
  635|    160|}
CERT_DestroyOidSequence:
  639|    104|{
  640|    104|    if (oidSeq != NULL) {
  ------------------
  |  Branch (640:9): [True: 104, False: 0]
  ------------------
  641|    104|        PORT_FreeArena(oidSeq->arena, PR_FALSE);
  ------------------
  |  |   61|    104|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(oidSeq->arena, PR_FALSE);
  ------------------
  |  |  438|    104|#define PR_FALSE 0
  ------------------
  642|    104|    }
  643|    104|    return;
  644|    104|}
CERT_GovtApprovedBitSet:
  648|  3.89k|{
  649|  3.89k|    SECStatus rv;
  650|  3.89k|    SECItem extItem;
  651|  3.89k|    CERTOidSequence *oidSeq = NULL;
  652|  3.89k|    PRBool ret;
  653|  3.89k|    SECItem **oids;
  654|  3.89k|    SECItem *oid;
  655|  3.89k|    SECOidTag oidTag;
  656|       |
  657|  3.89k|    extItem.data = NULL;
  658|  3.89k|    rv = CERT_FindCertExtension(cert, SEC_OID_X509_EXT_KEY_USAGE, &extItem);
  659|  3.89k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (659:9): [True: 3.81k, False: 80]
  ------------------
  660|  3.81k|        goto loser;
  661|  3.81k|    }
  662|       |
  663|     80|    oidSeq = CERT_DecodeOidSequence(&extItem);
  664|     80|    if (oidSeq == NULL) {
  ------------------
  |  Branch (664:9): [True: 28, False: 52]
  ------------------
  665|     28|        goto loser;
  666|     28|    }
  667|       |
  668|     52|    oids = oidSeq->oids;
  669|     92|    while (oids != NULL && *oids != NULL) {
  ------------------
  |  Branch (669:12): [True: 92, False: 0]
  |  Branch (669:28): [True: 40, False: 52]
  ------------------
  670|     40|        oid = *oids;
  671|       |
  672|     40|        oidTag = SECOID_FindOIDTag(oid);
  ------------------
  |  |  117|     40|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
  673|       |
  674|     40|        if (oidTag == SEC_OID_NS_KEY_USAGE_GOVT_APPROVED) {
  ------------------
  |  Branch (674:13): [True: 0, False: 40]
  ------------------
  675|      0|            goto success;
  676|      0|        }
  677|       |
  678|     40|        oids++;
  679|     40|    }
  680|       |
  681|  3.89k|loser:
  682|  3.89k|    ret = PR_FALSE;
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  683|  3.89k|    goto done;
  684|      0|success:
  685|      0|    ret = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  686|  3.89k|done:
  687|  3.89k|    if (oidSeq != NULL) {
  ------------------
  |  Branch (687:9): [True: 52, False: 3.83k]
  ------------------
  688|     52|        CERT_DestroyOidSequence(oidSeq);
  689|     52|    }
  690|  3.89k|    if (extItem.data != NULL) {
  ------------------
  |  Branch (690:9): [True: 79, False: 3.81k]
  ------------------
  691|     79|        PORT_Free(extItem.data);
  ------------------
  |  |   60|     79|#define PORT_Free PORT_Free_Util
  ------------------
  692|     79|    }
  693|  3.89k|    return (ret);
  694|      0|}

CERT_GetAVATag:
   69|  19.8k|{
   70|  19.8k|    SECOidData *oid;
   71|  19.8k|    if (!ava->type.data)
  ------------------
  |  Branch (71:9): [True: 0, False: 19.8k]
  ------------------
   72|      0|        return (SECOidTag)-1;
   73|       |
   74|  19.8k|    oid = SECOID_FindOID(&ava->type);
  ------------------
  |  |  115|  19.8k|#define SECOID_FindOID SECOID_FindOID_Util
  ------------------
   75|       |
   76|  19.8k|    if (oid) {
  ------------------
  |  Branch (76:9): [True: 11.5k, False: 8.31k]
  ------------------
   77|  11.5k|        return (oid->offset);
   78|  11.5k|    }
   79|  8.31k|    return (SECOidTag)-1;
   80|  19.8k|}
CERT_DecodeAVAValue:
  599|  9.98k|{
  600|  9.98k|    SECItem *retItem;
  601|  9.98k|    const SEC_ASN1Template *theTemplate = NULL;
  602|  9.98k|    enum { conv_none,
  603|  9.98k|           conv_ucs4,
  604|  9.98k|           conv_ucs2,
  605|  9.98k|           conv_iso88591 } convert = conv_none;
  606|  9.98k|    SECItem avaValue = { siBuffer, 0 };
  607|  9.98k|    PORTCheapArenaPool tmpArena;
  608|       |
  609|  9.98k|    if (!derAVAValue || !derAVAValue->len || !derAVAValue->data) {
  ------------------
  |  Branch (609:9): [True: 0, False: 9.98k]
  |  Branch (609:25): [True: 0, False: 9.98k]
  |  Branch (609:46): [True: 0, False: 9.98k]
  ------------------
  610|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  611|      0|        return NULL;
  612|      0|    }
  613|       |
  614|  9.98k|    switch (derAVAValue->data[0]) {
  615|    124|        case SEC_ASN1_UNIVERSAL_STRING:
  ------------------
  |  |  104|    124|#define SEC_ASN1_UNIVERSAL_STRING 0x1c
  ------------------
  |  Branch (615:9): [True: 124, False: 9.86k]
  ------------------
  616|    124|            convert = conv_ucs4;
  617|    124|            theTemplate = SEC_ASN1_GET(SEC_UniversalStringTemplate);
  ------------------
  |  |  188|    124|#define SEC_ASN1_GET(x) x
  ------------------
  618|    124|            break;
  619|    173|        case SEC_ASN1_IA5_STRING:
  ------------------
  |  |   98|    173|#define SEC_ASN1_IA5_STRING 0x16
  ------------------
  |  Branch (619:9): [True: 173, False: 9.81k]
  ------------------
  620|    173|            theTemplate = SEC_ASN1_GET(SEC_IA5StringTemplate);
  ------------------
  |  |  188|    173|#define SEC_ASN1_GET(x) x
  ------------------
  621|    173|            break;
  622|  2.92k|        case SEC_ASN1_PRINTABLE_STRING:
  ------------------
  |  |   95|  2.92k|#define SEC_ASN1_PRINTABLE_STRING 0x13
  ------------------
  |  Branch (622:9): [True: 2.92k, False: 7.06k]
  ------------------
  623|  2.92k|            theTemplate = SEC_ASN1_GET(SEC_PrintableStringTemplate);
  ------------------
  |  |  188|  2.92k|#define SEC_ASN1_GET(x) x
  ------------------
  624|  2.92k|            break;
  625|    149|        case SEC_ASN1_T61_STRING:
  ------------------
  |  |   96|    149|#define SEC_ASN1_T61_STRING 0x14
  ------------------
  |  Branch (625:9): [True: 149, False: 9.83k]
  ------------------
  626|       |            /*
  627|       |             * Per common practice, we're not decoding actual T.61, but instead
  628|       |             * treating T61-labeled strings as containing ISO-8859-1.
  629|       |             */
  630|    149|            convert = conv_iso88591;
  631|    149|            theTemplate = SEC_ASN1_GET(SEC_T61StringTemplate);
  ------------------
  |  |  188|    149|#define SEC_ASN1_GET(x) x
  ------------------
  632|    149|            break;
  633|    278|        case SEC_ASN1_BMP_STRING:
  ------------------
  |  |  106|    278|#define SEC_ASN1_BMP_STRING 0x1e
  ------------------
  |  Branch (633:9): [True: 278, False: 9.70k]
  ------------------
  634|    278|            convert = conv_ucs2;
  635|    278|            theTemplate = SEC_ASN1_GET(SEC_BMPStringTemplate);
  ------------------
  |  |  188|    278|#define SEC_ASN1_GET(x) x
  ------------------
  636|    278|            break;
  637|  1.22k|        case SEC_ASN1_UTF8_STRING:
  ------------------
  |  |   88|  1.22k|#define SEC_ASN1_UTF8_STRING 0x0c
  ------------------
  |  Branch (637:9): [True: 1.22k, False: 8.75k]
  ------------------
  638|       |            /* No conversion needed ! */
  639|  1.22k|            theTemplate = SEC_ASN1_GET(SEC_UTF8StringTemplate);
  ------------------
  |  |  188|  1.22k|#define SEC_ASN1_GET(x) x
  ------------------
  640|  1.22k|            break;
  641|  5.11k|        default:
  ------------------
  |  Branch (641:9): [True: 5.11k, False: 4.87k]
  ------------------
  642|  5.11k|            PORT_SetError(SEC_ERROR_INVALID_AVA);
  ------------------
  |  |   65|  5.11k|#define PORT_SetError PORT_SetError_Util
  ------------------
  643|  5.11k|            return NULL;
  644|  9.98k|    }
  645|       |
  646|  4.87k|    PORT_Memset(&avaValue, 0, sizeof(SECItem));
  ------------------
  |  |  182|  4.87k|#define PORT_Memset memset
  ------------------
  647|  4.87k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  4.87k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  648|  4.87k|    if (SEC_QuickDERDecodeItem(&tmpArena.arena, &avaValue, theTemplate,
  ------------------
  |  |  102|  4.87k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  |  Branch (648:9): [True: 0, False: 4.87k]
  ------------------
  649|  4.87k|                               derAVAValue) != SECSuccess) {
  650|      0|        PORT_DestroyCheapArena(&tmpArena);
  651|      0|        return NULL;
  652|      0|    }
  653|       |
  654|  4.87k|    if (convert != conv_none) {
  ------------------
  |  Branch (654:9): [True: 551, False: 4.32k]
  ------------------
  655|    551|        unsigned int utf8ValLen = avaValue.len * 3;
  656|    551|        unsigned char *utf8Val =
  657|    551|            (unsigned char *)PORT_ArenaZAlloc(&tmpArena.arena, utf8ValLen);
  ------------------
  |  |   59|    551|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  658|       |
  659|    551|        switch (convert) {
  ------------------
  |  Branch (659:17): [True: 0, False: 551]
  ------------------
  660|    124|            case conv_ucs4:
  ------------------
  |  Branch (660:13): [True: 124, False: 427]
  ------------------
  661|    124|                if (avaValue.len % 4 != 0 ||
  ------------------
  |  Branch (661:21): [True: 36, False: 88]
  ------------------
  662|    124|                    !PORT_UCS4_UTF8Conversion(PR_FALSE, avaValue.data,
  ------------------
  |  |  438|     88|#define PR_FALSE 0
  ------------------
  |  Branch (662:21): [True: 39, False: 49]
  ------------------
  663|     88|                                              avaValue.len, utf8Val, utf8ValLen,
  664|     88|                                              &utf8ValLen)) {
  665|     75|                    PORT_DestroyCheapArena(&tmpArena);
  666|     75|                    PORT_SetError(SEC_ERROR_INVALID_AVA);
  ------------------
  |  |   65|     75|#define PORT_SetError PORT_SetError_Util
  ------------------
  667|     75|                    return NULL;
  668|     75|                }
  669|     49|                break;
  670|    278|            case conv_ucs2:
  ------------------
  |  Branch (670:13): [True: 278, False: 273]
  ------------------
  671|    278|                if (avaValue.len % 2 != 0 ||
  ------------------
  |  Branch (671:21): [True: 5, False: 273]
  ------------------
  672|    278|                    !PORT_UCS2_UTF8Conversion(PR_FALSE, avaValue.data,
  ------------------
  |  |   71|    273|#define PORT_UCS2_UTF8Conversion PORT_UCS2_UTF8Conversion_Util
  ------------------
                                  !PORT_UCS2_UTF8Conversion(PR_FALSE, avaValue.data,
  ------------------
  |  |  438|    273|#define PR_FALSE 0
  ------------------
  |  Branch (672:21): [True: 31, False: 242]
  ------------------
  673|    273|                                              avaValue.len, utf8Val, utf8ValLen,
  674|    273|                                              &utf8ValLen)) {
  675|     36|                    PORT_DestroyCheapArena(&tmpArena);
  676|     36|                    PORT_SetError(SEC_ERROR_INVALID_AVA);
  ------------------
  |  |   65|     36|#define PORT_SetError PORT_SetError_Util
  ------------------
  677|     36|                    return NULL;
  678|     36|                }
  679|    242|                break;
  680|    242|            case conv_iso88591:
  ------------------
  |  Branch (680:13): [True: 149, False: 402]
  ------------------
  681|    149|                if (!PORT_ISO88591_UTF8Conversion(avaValue.data, avaValue.len,
  ------------------
  |  Branch (681:21): [True: 0, False: 149]
  ------------------
  682|    149|                                                  utf8Val, utf8ValLen,
  683|    149|                                                  &utf8ValLen)) {
  684|      0|                    PORT_DestroyCheapArena(&tmpArena);
  685|      0|                    PORT_SetError(SEC_ERROR_INVALID_AVA);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  686|      0|                    return NULL;
  687|      0|                }
  688|    149|                break;
  689|    149|            case conv_none:
  ------------------
  |  Branch (689:13): [True: 0, False: 551]
  ------------------
  690|      0|                PORT_Assert(0); /* not reached */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  691|      0|                break;
  692|    551|        }
  693|       |
  694|    440|        avaValue.data = utf8Val;
  695|    440|        avaValue.len = utf8ValLen;
  696|    440|    }
  697|       |
  698|  4.76k|    retItem = SECITEM_DupItem(&avaValue);
  ------------------
  |  |  107|  4.76k|#define SECITEM_DupItem SECITEM_DupItem_Util
  ------------------
  699|  4.76k|    PORT_DestroyCheapArena(&tmpArena);
  700|  4.76k|    return retItem;
  701|  4.87k|}

CERT_GetCertTrust:
   95|  7.73k|{
   96|  7.73k|    SECStatus rv;
   97|  7.73k|    CERT_LockCertTrust(cert);
   98|  7.73k|    if (!cert || cert->trust == NULL) {
  ------------------
  |  Branch (98:9): [True: 0, False: 7.73k]
  |  Branch (98:18): [True: 7.73k, False: 0]
  ------------------
   99|  7.73k|        rv = SECFailure;
  100|  7.73k|    } else {
  101|      0|        *trust = *cert->trust;
  102|      0|        rv = SECSuccess;
  103|      0|    }
  104|  7.73k|    CERT_UnlockCertTrust(cert);
  105|  7.73k|    return (rv);
  106|  7.73k|}
CERT_MapStanError:
  159|    174|{
  160|    174|    PRInt32 *errorStack;
  161|    174|    NSSError error, prevError;
  162|    174|    int secError;
  163|    174|    int i;
  164|       |
  165|    174|    errorStack = NSS_GetErrorStack();
  166|    174|    if (errorStack == 0) {
  ------------------
  |  Branch (166:9): [True: 0, False: 174]
  ------------------
  167|      0|        PORT_SetError(0);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  168|      0|        return;
  169|      0|    }
  170|    174|    error = prevError = CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|    174|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
  171|       |    /* get the 'top 2' error codes from the stack */
  172|    402|    for (i = 0; errorStack[i]; i++) {
  ------------------
  |  Branch (172:17): [True: 228, False: 174]
  ------------------
  173|    228|        prevError = error;
  174|    228|        error = errorStack[i];
  175|    228|    }
  176|    174|    if (error == NSS_ERROR_PKCS11) {
  ------------------
  |  Branch (176:9): [True: 0, False: 174]
  ------------------
  177|       |        /* map it */
  178|      0|        secError = PK11_MapError(prevError);
  179|      0|    }
  180|    174|    STAN_MAP_ERROR(NSS_ERROR_NO_ERROR, 0)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  181|    174|    STAN_MAP_ERROR(NSS_ERROR_NO_MEMORY, SEC_ERROR_NO_MEMORY)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  182|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_BASE64, SEC_ERROR_BAD_DATA)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  183|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_BER, SEC_ERROR_BAD_DER)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  184|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ATAV, SEC_ERROR_INVALID_AVA)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  185|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_PASSWORD, SEC_ERROR_BAD_PASSWORD)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  186|    174|    STAN_MAP_ERROR(NSS_ERROR_BUSY, SEC_ERROR_BUSY)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  187|    174|    STAN_MAP_ERROR(NSS_ERROR_DEVICE_ERROR, SEC_ERROR_IO)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  188|    174|    STAN_MAP_ERROR(NSS_ERROR_CERTIFICATE_ISSUER_NOT_FOUND,
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  189|    174|                   SEC_ERROR_UNKNOWN_ISSUER)
  190|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_CERTIFICATE, SEC_ERROR_CERT_NOT_VALID)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  191|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_UTF8, SEC_ERROR_BAD_DATA)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  192|    174|    STAN_MAP_ERROR(NSS_ERROR_INVALID_NSSOID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 174]
  |  |  ------------------
  ------------------
  193|       |
  194|       |    /* these are library failure for lack of a better error code */
  195|    174|    STAN_MAP_ERROR(NSS_ERROR_NOT_FOUND, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 60, False: 114]
  |  |  ------------------
  ------------------
  196|    174|    STAN_MAP_ERROR(NSS_ERROR_CERTIFICATE_IN_CACHE, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    174|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  197|    114|    STAN_MAP_ERROR(NSS_ERROR_MAXIMUM_FOUND, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  198|    114|    STAN_MAP_ERROR(NSS_ERROR_USER_CANCELED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  199|    114|    STAN_MAP_ERROR(NSS_ERROR_TRACKER_NOT_INITIALIZED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  200|    114|    STAN_MAP_ERROR(NSS_ERROR_ALREADY_INITIALIZED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  201|    114|    STAN_MAP_ERROR(NSS_ERROR_ARENA_MARKED_BY_ANOTHER_THREAD,
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  202|    114|                   SEC_ERROR_LIBRARY_FAILURE)
  203|    114|    STAN_MAP_ERROR(NSS_ERROR_HASH_COLLISION, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  204|       |
  205|    114|    STAN_MAP_ERROR(NSS_ERROR_INTERNAL_ERROR, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  206|       |
  207|       |    /* these are all invalid arguments */
  208|    114|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ARGUMENT, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  209|    114|    STAN_MAP_ERROR(NSS_ERROR_INVALID_POINTER, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  210|    114|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ARENA, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 114]
  |  |  ------------------
  ------------------
  211|    114|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ARENA_MARK, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 114, False: 0]
  |  |  ------------------
  ------------------
  212|    114|    STAN_MAP_ERROR(NSS_ERROR_DUPLICATE_POINTER, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|    114|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  213|      0|    STAN_MAP_ERROR(NSS_ERROR_POINTER_NOT_REGISTERED, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  214|      0|    STAN_MAP_ERROR(NSS_ERROR_TRACKER_NOT_EMPTY, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  215|      0|    STAN_MAP_ERROR(NSS_ERROR_VALUE_TOO_LARGE, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  216|      0|    STAN_MAP_ERROR(NSS_ERROR_UNSUPPORTED_TYPE, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  217|      0|    STAN_MAP_ERROR(NSS_ERROR_BUFFER_TOO_SHORT, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  218|      0|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ATOB_CONTEXT, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  219|      0|    STAN_MAP_ERROR(NSS_ERROR_INVALID_BTOA_CONTEXT, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  220|      0|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ITEM, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  221|      0|    STAN_MAP_ERROR(NSS_ERROR_INVALID_STRING, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  222|      0|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ASN1ENCODER, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  223|      0|    STAN_MAP_ERROR(NSS_ERROR_INVALID_ASN1DECODER, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  224|      0|    STAN_MAP_ERROR(NSS_ERROR_UNKNOWN_ATTRIBUTE, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |  150|      0|    else if (error == (x)) { secError = y; }
  |  |  ------------------
  |  |  |  Branch (150:14): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  225|      0|    else { secError = SEC_ERROR_LIBRARY_FAILURE; }
  226|    174|    PORT_SetError(secError);
  ------------------
  |  |   65|    174|#define PORT_SetError PORT_SetError_Util
  ------------------
  227|    174|}
CERT_NewTempCertificate:
  357|  4.07k|{
  358|  4.07k|    NSSCertificate *c;
  359|  4.07k|    CERTCertificate *cc;
  360|  4.07k|    NSSCertificate *tempCert = NULL;
  361|  4.07k|    nssPKIObject *pkio;
  362|  4.07k|    NSSCryptoContext *gCC = STAN_GetDefaultCryptoContext();
  363|  4.07k|    NSSTrustDomain *gTD = STAN_GetDefaultTrustDomain();
  364|  4.07k|    if (!isperm) {
  ------------------
  |  Branch (364:9): [True: 4.07k, False: 0]
  ------------------
  365|  4.07k|        NSSDER encoding;
  366|  4.07k|        NSSITEM_FROM_SECITEM(&encoding, derCert);
  ------------------
  |  |   27|  4.07k|    (nssit)->data = (void *)(secit)->data; \
  |  |   28|  4.07k|    (nssit)->size = (PRUint32)(secit)->len;
  ------------------
  367|       |        /* First, see if it is already a temp cert */
  368|  4.07k|        c = NSSCryptoContext_FindCertificateByEncodedCertificate(gCC,
  369|  4.07k|                                                                 &encoding);
  370|  4.07k|        if (!c && handle) {
  ------------------
  |  Branch (370:13): [True: 4.06k, False: 5]
  |  Branch (370:19): [True: 4.06k, False: 0]
  ------------------
  371|       |            /* Then, see if it is already a perm cert */
  372|  4.06k|            c = NSSTrustDomain_FindCertificateByEncodedCertificate(handle,
  373|  4.06k|                                                                   &encoding);
  374|  4.06k|        }
  375|  4.07k|        if (c) {
  ------------------
  |  Branch (375:13): [True: 5, False: 4.06k]
  ------------------
  376|       |            /* actually, that search ends up going by issuer/serial,
  377|       |             * so it is still possible to return a cert with the same
  378|       |             * issuer/serial but a different encoding, and we're
  379|       |             * going to reject that
  380|       |             */
  381|      5|            if (!nssItem_Equal(&c->encoding, &encoding, NULL)) {
  ------------------
  |  Branch (381:17): [True: 5, False: 0]
  ------------------
  382|      5|                nssCertificate_Destroy(c);
  383|      5|                PORT_SetError(SEC_ERROR_REUSED_ISSUER_AND_SERIAL);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
  384|      5|                cc = NULL;
  385|      5|            } else {
  386|      0|                cc = STAN_GetCERTCertificateOrRelease(c);
  387|      0|                if (cc == NULL) {
  ------------------
  |  Branch (387:21): [True: 0, False: 0]
  ------------------
  388|      0|                    CERT_MapStanError();
  389|      0|                }
  390|      0|            }
  391|      5|            return cc;
  392|      5|        }
  393|  4.07k|    }
  394|  4.06k|    pkio = nssPKIObject_Create(NULL, NULL, gTD, gCC, nssPKIMonitor);
  395|  4.06k|    if (!pkio) {
  ------------------
  |  Branch (395:9): [True: 0, False: 4.06k]
  ------------------
  396|      0|        CERT_MapStanError();
  397|      0|        return NULL;
  398|      0|    }
  399|  4.06k|    c = nss_ZNEW(pkio->arena, NSSCertificate);
  ------------------
  |  |  348|  4.06k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  400|  4.06k|    if (!c) {
  ------------------
  |  Branch (400:9): [True: 0, False: 4.06k]
  ------------------
  401|      0|        CERT_MapStanError();
  402|      0|        nssPKIObject_Destroy(pkio);
  403|      0|        return NULL;
  404|      0|    }
  405|  4.06k|    c->object = *pkio;
  406|  4.06k|    if (copyDER) {
  ------------------
  |  Branch (406:9): [True: 4.06k, False: 0]
  ------------------
  407|  4.06k|        nssItem_Create(c->object.arena, &c->encoding, derCert->len,
  408|  4.06k|                       derCert->data);
  409|  4.06k|    } else {
  410|      0|        NSSITEM_FROM_SECITEM(&c->encoding, derCert);
  ------------------
  |  |   27|      0|    (nssit)->data = (void *)(secit)->data; \
  |  |   28|      0|    (nssit)->size = (PRUint32)(secit)->len;
  ------------------
  411|      0|    }
  412|       |    /* Forces a decoding of the cert in order to obtain the parts used
  413|       |     * below
  414|       |     */
  415|       |    /* 'c' is not adopted here, if we fail loser frees what has been
  416|       |     * allocated so far for 'c' */
  417|  4.06k|    cc = STAN_GetCERTCertificate(c);
  418|  4.06k|    if (!cc) {
  ------------------
  |  Branch (418:9): [True: 174, False: 3.89k]
  ------------------
  419|    174|        CERT_MapStanError();
  420|    174|        goto loser;
  421|    174|    }
  422|  3.89k|    nssItem_Create(c->object.arena, &c->issuer, cc->derIssuer.len,
  423|  3.89k|                   cc->derIssuer.data);
  424|  3.89k|    nssItem_Create(c->object.arena, &c->subject, cc->derSubject.len,
  425|  3.89k|                   cc->derSubject.data);
  426|       |    /* CERTCertificate stores serial numbers decoded.  I need the DER
  427|       |     * here.  sigh.
  428|       |     */
  429|  3.89k|    SECItem derSerial = { 0 };
  430|  3.89k|    CERT_SerialNumberFromDERCert(&cc->derCert, &derSerial);
  431|  3.89k|    if (!derSerial.data)
  ------------------
  |  Branch (431:9): [True: 0, False: 3.89k]
  ------------------
  432|      0|        goto loser;
  433|  3.89k|    nssItem_Create(c->object.arena, &c->serial, derSerial.len,
  434|  3.89k|                   derSerial.data);
  435|  3.89k|    PORT_Free(derSerial.data);
  ------------------
  |  |   60|  3.89k|#define PORT_Free PORT_Free_Util
  ------------------
  436|       |
  437|  3.89k|    if (nickname) {
  ------------------
  |  Branch (437:9): [True: 0, False: 3.89k]
  ------------------
  438|      0|        c->object.tempName =
  439|      0|            nssUTF8_Create(c->object.arena, nssStringType_UTF8String,
  440|      0|                           (NSSUTF8 *)nickname, PORT_Strlen(nickname));
  ------------------
  |  |  190|      0|#define PORT_Strlen(s) strlen(s)
  ------------------
  441|      0|    }
  442|  3.89k|    if (cc->emailAddr && cc->emailAddr[0]) {
  ------------------
  |  Branch (442:9): [True: 68, False: 3.82k]
  |  Branch (442:26): [True: 68, False: 0]
  ------------------
  443|     68|        c->email = nssUTF8_Create(
  444|     68|            c->object.arena, nssStringType_PrintableString,
  445|     68|            (NSSUTF8 *)cc->emailAddr, PORT_Strlen(cc->emailAddr));
  ------------------
  |  |  190|     68|#define PORT_Strlen(s) strlen(s)
  ------------------
  446|     68|    }
  447|       |
  448|  3.89k|    tempCert = NSSCryptoContext_FindOrImportCertificate(gCC, c);
  449|  3.89k|    if (!tempCert) {
  ------------------
  |  Branch (449:9): [True: 0, False: 3.89k]
  ------------------
  450|      0|        CERT_MapStanError();
  451|      0|        goto loser;
  452|      0|    }
  453|       |    /* destroy our copy */
  454|  3.89k|    NSSCertificate_Destroy(c);
  455|       |    /* and use the stored entry */
  456|  3.89k|    c = tempCert;
  457|  3.89k|    cc = STAN_GetCERTCertificateOrRelease(c);
  458|  3.89k|    if (!cc) {
  ------------------
  |  Branch (458:9): [True: 0, False: 3.89k]
  ------------------
  459|       |        /* STAN_GetCERTCertificateOrRelease destroys c on failure. */
  460|      0|        CERT_MapStanError();
  461|      0|        return NULL;
  462|      0|    }
  463|       |
  464|  3.89k|    CERT_LockCertTempPerm(cc);
  465|  3.89k|    cc->istemp = PR_TRUE;
  ------------------
  |  |  437|  3.89k|#define PR_TRUE 1
  ------------------
  466|  3.89k|    cc->isperm = PR_FALSE;
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  467|  3.89k|    CERT_UnlockCertTempPerm(cc);
  468|  3.89k|    return cc;
  469|    174|loser:
  470|       |    /* Perhaps this should be nssCertificate_Destroy(c) */
  471|    174|    nssPKIObject_Destroy(&c->object);
  472|    174|    return NULL;
  473|  3.89k|}
CERT_DestroyCertificate:
  817|   117k|{
  818|   117k|    if (cert) {
  ------------------
  |  Branch (818:9): [True: 117k, False: 0]
  ------------------
  819|       |        /* don't use STAN_GetNSSCertificate because we don't want to
  820|       |         * go to the trouble of translating the CERTCertificate into
  821|       |         * an NSSCertificate just to destroy it.  If it hasn't been done
  822|       |         * yet, don't do it at all
  823|       |         *
  824|       |         * cert->nssCertificate contains its own locks and refcount, but as it
  825|       |         * may be NULL, the pointer itself must be guarded by some other lock.
  826|       |         * Rather than creating a new global lock for only this purpose, share
  827|       |         * an existing global lock that happens to be taken near the write in
  828|       |         * fill_CERTCertificateFields(). The longer-term goal is to refactor
  829|       |         * all these global locks to be certificate-scoped. */
  830|   117k|        CERT_MaybeLockCertTempPerm(cert);
  831|   117k|        NSSCertificate *tmp = cert->nssCertificate;
  832|   117k|        CERT_MaybeUnlockCertTempPerm(cert);
  833|   117k|        if (tmp) {
  ------------------
  |  Branch (833:13): [True: 117k, False: 0]
  ------------------
  834|       |            /* delete the NSSCertificate */
  835|   117k|            NSSCertificate_Destroy(tmp);
  836|   117k|        } else if (cert->arena) {
  ------------------
  |  Branch (836:20): [True: 0, False: 0]
  ------------------
  837|      0|            PORT_FreeArena(cert->arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(cert->arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  838|      0|        }
  839|   117k|    }
  840|   117k|    return;
  841|   117k|}

CERT_DecodeAuthKeyID:
   81|    266|{
   82|    266|    CERTAuthKeyID *value = NULL;
   83|    266|    SECStatus rv = SECFailure;
   84|    266|    void *mark;
   85|    266|    SECItem newEncodedValue;
   86|       |
   87|    266|    PORT_Assert(arena);
  ------------------
  |  |  120|    266|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    266|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 266, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   88|       |
   89|    266|    do {
   90|    266|        mark = PORT_ArenaMark(arena);
  ------------------
  |  |   55|    266|#define PORT_ArenaMark PORT_ArenaMark_Util
  ------------------
   91|    266|        value = (CERTAuthKeyID *)PORT_ArenaZAlloc(arena, sizeof(*value));
  ------------------
  |  |   59|    266|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
   92|    266|        if (value == NULL)
  ------------------
  |  Branch (92:13): [True: 0, False: 266]
  ------------------
   93|      0|            break;
   94|    266|        value->DERAuthCertIssuer = NULL;
   95|       |        /* copy the DER into the arena, since Quick DER returns data that points
   96|       |           into the DER input, which may get freed by the caller */
   97|    266|        rv = SECITEM_CopyItem(arena, &newEncodedValue, encodedValue);
  ------------------
  |  |  106|    266|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
   98|    266|        if (rv != SECSuccess) {
  ------------------
  |  Branch (98:13): [True: 0, False: 266]
  ------------------
   99|      0|            break;
  100|      0|        }
  101|       |
  102|    266|        rv = SEC_QuickDERDecodeItem(arena, value, CERTAuthKeyIDTemplate,
  ------------------
  |  |  102|    266|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  103|    266|                                    &newEncodedValue);
  104|    266|        if (rv != SECSuccess)
  ------------------
  |  Branch (104:13): [True: 128, False: 138]
  ------------------
  105|    128|            break;
  106|       |
  107|    138|        value->authCertIssuer =
  108|    138|            cert_DecodeGeneralNames(arena, value->DERAuthCertIssuer);
  109|    138|        if (value->authCertIssuer == NULL)
  ------------------
  |  Branch (109:13): [True: 133, False: 5]
  ------------------
  110|    133|            break;
  111|       |
  112|       |        /* what if the general name contains other format but not URI ?
  113|       |           hl
  114|       |         */
  115|      5|        if ((value->authCertSerialNumber.data && !value->authCertIssuer) ||
  ------------------
  |  Branch (115:14): [True: 3, False: 2]
  |  Branch (115:50): [True: 0, False: 3]
  ------------------
  116|      5|            (!value->authCertSerialNumber.data && value->authCertIssuer)) {
  ------------------
  |  Branch (116:14): [True: 2, False: 3]
  |  Branch (116:51): [True: 2, False: 0]
  ------------------
  117|      2|            PORT_SetError(SEC_ERROR_EXTENSION_VALUE_INVALID);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  118|      2|            break;
  119|      2|        }
  120|      5|    } while (0);
  ------------------
  |  Branch (120:14): [Folded - Ignored]
  ------------------
  121|       |
  122|    266|    if (rv != SECSuccess) {
  ------------------
  |  Branch (122:9): [True: 128, False: 138]
  ------------------
  123|    128|        PORT_ArenaRelease(arena, mark);
  ------------------
  |  |   56|    128|#define PORT_ArenaRelease PORT_ArenaRelease_Util
  ------------------
  124|    128|        return ((CERTAuthKeyID *)NULL);
  125|    128|    }
  126|    138|    PORT_ArenaUnmark(arena, mark);
  ------------------
  |  |   58|    138|#define PORT_ArenaUnmark PORT_ArenaUnmark_Util
  ------------------
  127|    138|    return (value);
  128|    266|}

CERT_DecodeBasicConstraintValue:
   94|  3.54k|{
   95|  3.54k|    EncodedContext decodeContext;
   96|  3.54k|    PORTCheapArenaPool tmpArena;
   97|  3.54k|    SECStatus rv = SECSuccess;
   98|       |
   99|  3.54k|    do {
  100|  3.54k|        PORT_Memset(&decodeContext, 0, sizeof(decodeContext));
  ------------------
  |  |  182|  3.54k|#define PORT_Memset memset
  ------------------
  101|       |        /* initialize the value just in case we got "0x30 00", or when the
  102|       |           pathLenConstraint is omitted.
  103|       |         */
  104|  3.54k|        decodeContext.isCA.data = &hexFalse;
  105|  3.54k|        decodeContext.isCA.len = 1;
  106|       |
  107|  3.54k|        PORT_InitCheapArena(&tmpArena, SEC_ASN1_DEFAULT_ARENA_SIZE);
  ------------------
  |  |   60|  3.54k|#define SEC_ASN1_DEFAULT_ARENA_SIZE (2048)
  ------------------
  108|       |
  109|  3.54k|        rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &decodeContext,
  ------------------
  |  |  102|  3.54k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  110|  3.54k|                                    CERTBasicConstraintsTemplate, encodedValue);
  111|  3.54k|        if (rv == SECFailure)
  ------------------
  |  Branch (111:13): [True: 1.44k, False: 2.10k]
  ------------------
  112|  1.44k|            break;
  113|       |
  114|  2.10k|        value->isCA = decodeContext.isCA.data
  ------------------
  |  Branch (114:23): [True: 2.10k, False: 0]
  ------------------
  115|  2.10k|                          ? (PRBool)(decodeContext.isCA.data[0] != 0)
  116|  2.10k|                          : PR_FALSE;
  ------------------
  |  |  438|  2.10k|#define PR_FALSE 0
  ------------------
  117|  2.10k|        if (decodeContext.pathLenConstraint.data == NULL) {
  ------------------
  |  Branch (117:13): [True: 2.09k, False: 3]
  ------------------
  118|       |            /* if the pathLenConstraint is not encoded, and the current setting
  119|       |              is CA, then the pathLenConstraint should be set to a negative
  120|       |              number
  121|       |              for unlimited certificate path.
  122|       |             */
  123|  2.09k|            if (value->isCA) {
  ------------------
  |  Branch (123:17): [True: 148, False: 1.94k]
  ------------------
  124|    148|                value->pathLenConstraint = CERT_UNLIMITED_PATH_CONSTRAINT;
  ------------------
  |  |  599|    148|#define CERT_UNLIMITED_PATH_CONSTRAINT -2
  ------------------
  125|  1.94k|            } else {
  126|  1.94k|                value->pathLenConstraint = 0;
  127|  1.94k|            }
  128|  2.09k|        } else if (value->isCA) {
  ------------------
  |  Branch (128:20): [True: 0, False: 3]
  ------------------
  129|      0|            long len = DER_GetInteger(&decodeContext.pathLenConstraint);
  ------------------
  |  |   27|      0|#define DER_GetInteger DER_GetInteger_Util
  ------------------
  130|      0|            if (len < 0 || len == LONG_MAX) {
  ------------------
  |  Branch (130:17): [True: 0, False: 0]
  |  Branch (130:28): [True: 0, False: 0]
  ------------------
  131|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  132|      0|                GEN_BREAK(SECFailure);
  ------------------
  |  |   41|      0|    rv = status;          \
  |  |   42|      0|    break;
  ------------------
  133|      0|            }
  134|      0|            value->pathLenConstraint = len;
  135|      3|        } else {
  136|       |            /* here we get an error where the subject is not a CA, but
  137|       |               the pathLenConstraint is set */
  138|      3|            PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
  139|      3|            GEN_BREAK(SECFailure);
  ------------------
  |  |   41|      3|    rv = status;          \
  |  |   42|      3|    break;
  ------------------
  140|      0|            break;
  141|      3|        }
  142|  2.10k|    } while (0);
  ------------------
  |  Branch (142:14): [Folded - Ignored]
  ------------------
  143|       |
  144|      0|    PORT_DestroyCheapArena(&tmpArena);
  145|  3.54k|    return (rv);
  146|  3.54k|}

CERT_DecodeAltNameExtension:
  164|     70|{
  165|     70|    SECStatus rv = SECSuccess;
  166|     70|    CERTAltNameEncodedContext encodedContext;
  167|     70|    SECItem *newEncodedAltName;
  168|       |
  169|     70|    if (!reqArena) {
  ------------------
  |  Branch (169:9): [True: 0, False: 70]
  ------------------
  170|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  171|      0|        return NULL;
  172|      0|    }
  173|       |
  174|     70|    newEncodedAltName = SECITEM_ArenaDupItem(reqArena, EncodedAltName);
  ------------------
  |  |  104|     70|#define SECITEM_ArenaDupItem SECITEM_ArenaDupItem_Util
  ------------------
  175|     70|    if (!newEncodedAltName) {
  ------------------
  |  Branch (175:9): [True: 0, False: 70]
  ------------------
  176|      0|        return NULL;
  177|      0|    }
  178|       |
  179|     70|    encodedContext.encodedGenName = NULL;
  180|     70|    PORT_Memset(&encodedContext, 0, sizeof(CERTAltNameEncodedContext));
  ------------------
  |  |  182|     70|#define PORT_Memset memset
  ------------------
  181|     70|    rv = SEC_QuickDERDecodeItem(reqArena, &encodedContext,
  ------------------
  |  |  102|     70|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  182|     70|                                CERT_GeneralNamesTemplate, newEncodedAltName);
  183|     70|    if (rv == SECFailure) {
  ------------------
  |  Branch (183:9): [True: 19, False: 51]
  ------------------
  184|     19|        goto loser;
  185|     19|    }
  186|     51|    if (encodedContext.encodedGenName && encodedContext.encodedGenName[0])
  ------------------
  |  Branch (186:9): [True: 51, False: 0]
  |  Branch (186:42): [True: 43, False: 8]
  ------------------
  187|     43|        return cert_DecodeGeneralNames(reqArena, encodedContext.encodedGenName);
  188|       |    /* Extension contained an empty GeneralNames sequence */
  189|       |    /* Treat as extension not found */
  190|      8|    PORT_SetError(SEC_ERROR_EXTENSION_NOT_FOUND);
  ------------------
  |  |   65|      8|#define PORT_SetError PORT_SetError_Util
  ------------------
  191|     27|loser:
  192|     27|    return NULL;
  193|      8|}

CERT_FreeDistNames:
  533|      1|{
  534|      1|    PORT_FreeArena(names->arena, PR_FALSE);
  ------------------
  |  |   61|      1|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(names->arena, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  535|       |
  536|      1|    return;
  537|      1|}
CERT_GetSSLCACerts:
  637|      1|{
  638|      1|    PLArenaPool *arena;
  639|      1|    CERTDistNames *names;
  640|      1|    int i;
  641|      1|    SECStatus rv;
  642|      1|    dnameNode *node;
  643|       |
  644|       |    /* allocate an arena to use */
  645|      1|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|      1|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|      1|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  646|      1|    if (arena == NULL) {
  ------------------
  |  Branch (646:9): [True: 0, False: 1]
  ------------------
  647|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  648|      0|        return (NULL);
  649|      0|    }
  650|       |
  651|       |    /* allocate the header structure */
  652|      1|    names = (CERTDistNames *)PORT_ArenaAlloc(arena, sizeof(CERTDistNames));
  ------------------
  |  |   53|      1|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  653|      1|    if (names == NULL) {
  ------------------
  |  Branch (653:9): [True: 0, False: 1]
  ------------------
  654|      0|        goto loser;
  655|      0|    }
  656|       |
  657|       |    /* initialize the header struct */
  658|      1|    names->arena = arena;
  659|      1|    names->head = NULL;
  660|      1|    names->nnames = 0;
  661|      1|    names->names = NULL;
  662|       |
  663|       |    /* collect the names from the database */
  664|      1|    rv = PK11_TraverseSlotCerts(CollectDistNames, (void *)names, NULL);
  665|      1|    if (rv) {
  ------------------
  |  Branch (665:9): [True: 0, False: 1]
  ------------------
  666|      0|        goto loser;
  667|      0|    }
  668|       |
  669|       |    /* construct the array from the list */
  670|      1|    if (names->nnames) {
  ------------------
  |  Branch (670:9): [True: 0, False: 1]
  ------------------
  671|      0|        names->names = (SECItem *)PORT_ArenaAlloc(arena, names->nnames * sizeof(SECItem));
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  672|       |
  673|      0|        if (names->names == NULL) {
  ------------------
  |  Branch (673:13): [True: 0, False: 0]
  ------------------
  674|      0|            goto loser;
  675|      0|        }
  676|       |
  677|      0|        node = (dnameNode *)names->head;
  678|       |
  679|      0|        for (i = 0; i < names->nnames; i++) {
  ------------------
  |  Branch (679:21): [True: 0, False: 0]
  ------------------
  680|      0|            PORT_Assert(node != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  681|       |
  682|      0|            names->names[i] = node->name;
  683|      0|            node = node->next;
  684|      0|        }
  685|       |
  686|      0|        PORT_Assert(node == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  687|      0|    }
  688|       |
  689|      1|    return (names);
  690|       |
  691|      0|loser:
  692|      0|    PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  693|      0|    return (NULL);
  694|      1|}
CERT_CertChainFromCert:
 1032|      2|{
 1033|      2|    CERTCertificateList *chain = NULL;
 1034|      2|    NSSCertificate **stanChain;
 1035|      2|    NSSCertificate *stanCert;
 1036|      2|    PLArenaPool *arena;
 1037|      2|    NSSUsage nssUsage;
 1038|      2|    int i, len;
 1039|      2|    NSSTrustDomain *td = STAN_GetDefaultTrustDomain();
 1040|      2|    NSSCryptoContext *cc = STAN_GetDefaultCryptoContext();
 1041|       |
 1042|      2|    stanCert = STAN_GetNSSCertificate(cert);
 1043|      2|    if (!stanCert) {
  ------------------
  |  Branch (1043:9): [True: 0, False: 2]
  ------------------
 1044|       |        /* error code is set */
 1045|      0|        return NULL;
 1046|      0|    }
 1047|      2|    nssUsage.anyUsage = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1048|      2|    nssUsage.nss3usage = usage;
 1049|      2|    nssUsage.nss3lookingForCA = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1050|      2|    stanChain = NSSCertificate_BuildChain(stanCert, NULL, &nssUsage, NULL, NULL,
 1051|      2|                                          CERT_MAX_CERT_CHAIN, NULL, NULL, td, cc);
  ------------------
  |  |  610|      2|#define CERT_MAX_CERT_CHAIN 20
  ------------------
 1052|      2|    if (!stanChain) {
  ------------------
  |  Branch (1052:9): [True: 0, False: 2]
  ------------------
 1053|      0|        PORT_SetError(SEC_ERROR_UNKNOWN_ISSUER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1054|      0|        return NULL;
 1055|      0|    }
 1056|       |
 1057|      2|    len = 0;
 1058|      2|    stanCert = stanChain[0];
 1059|      4|    while (stanCert) {
  ------------------
  |  Branch (1059:12): [True: 2, False: 2]
  ------------------
 1060|      2|        stanCert = stanChain[++len];
 1061|      2|    }
 1062|       |
 1063|      2|    arena = PORT_NewArena(4096);
  ------------------
  |  |   63|      2|#define PORT_NewArena PORT_NewArena_Util
  ------------------
 1064|      2|    if (arena == NULL) {
  ------------------
  |  Branch (1064:9): [True: 0, False: 2]
  ------------------
 1065|      0|        goto loser;
 1066|      0|    }
 1067|       |
 1068|      2|    chain = (CERTCertificateList *)PORT_ArenaAlloc(arena,
  ------------------
  |  |   53|      2|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1069|      2|                                                   sizeof(CERTCertificateList));
 1070|      2|    if (!chain)
  ------------------
  |  Branch (1070:9): [True: 0, False: 2]
  ------------------
 1071|      0|        goto loser;
 1072|      2|    chain->certs = (SECItem *)PORT_ArenaAlloc(arena, len * sizeof(SECItem));
  ------------------
  |  |   53|      2|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1073|      2|    if (!chain->certs)
  ------------------
  |  Branch (1073:9): [True: 0, False: 2]
  ------------------
 1074|      0|        goto loser;
 1075|      2|    i = 0;
 1076|      2|    stanCert = stanChain[i];
 1077|      4|    while (stanCert) {
  ------------------
  |  Branch (1077:12): [True: 2, False: 2]
  ------------------
 1078|      2|        SECItem derCert;
 1079|      2|        CERTCertificate *cCert = STAN_GetCERTCertificate(stanCert);
 1080|      2|        if (!cCert) {
  ------------------
  |  Branch (1080:13): [True: 0, False: 2]
  ------------------
 1081|      0|            goto loser;
 1082|      0|        }
 1083|      2|        derCert.len = (unsigned int)stanCert->encoding.size;
 1084|      2|        derCert.data = (unsigned char *)stanCert->encoding.data;
 1085|      2|        derCert.type = siBuffer;
 1086|      2|        if (SECITEM_CopyItem(arena, &chain->certs[i], &derCert) != SECSuccess) {
  ------------------
  |  |  106|      2|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (1086:13): [True: 0, False: 2]
  ------------------
 1087|      0|            CERT_DestroyCertificate(cCert);
 1088|      0|            goto loser;
 1089|      0|        }
 1090|      2|        stanCert = stanChain[++i];
 1091|      2|        if (!stanCert && !cCert->isRoot) {
  ------------------
  |  Branch (1091:13): [True: 2, False: 0]
  |  Branch (1091:26): [True: 0, False: 2]
  ------------------
 1092|       |            /* reached the end of the chain, but the final cert is
 1093|       |             * not a root.  Don't discard it.
 1094|       |             */
 1095|      0|            includeRoot = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1096|      0|        }
 1097|      2|        CERT_DestroyCertificate(cCert);
 1098|      2|    }
 1099|      2|    if (!includeRoot && len > 1) {
  ------------------
  |  Branch (1099:9): [True: 0, False: 2]
  |  Branch (1099:25): [True: 0, False: 0]
  ------------------
 1100|      0|        chain->len = len - 1;
 1101|      2|    } else {
 1102|      2|        chain->len = len;
 1103|      2|    }
 1104|       |
 1105|      2|    chain->arena = arena;
 1106|      2|    nss_ZFreeIf(stanChain);
 1107|      2|    return chain;
 1108|      0|loser:
 1109|      0|    i = 0;
 1110|      0|    stanCert = stanChain[i];
 1111|      0|    while (stanCert) {
  ------------------
  |  Branch (1111:12): [True: 0, False: 0]
  ------------------
 1112|      0|        CERTCertificate *cCert = STAN_GetCERTCertificate(stanCert);
 1113|      0|        if (cCert) {
  ------------------
  |  Branch (1113:13): [True: 0, False: 0]
  ------------------
 1114|      0|            CERT_DestroyCertificate(cCert);
 1115|      0|        }
 1116|      0|        stanCert = stanChain[++i];
 1117|      0|    }
 1118|      0|    nss_ZFreeIf(stanChain);
 1119|      0|    if (arena) {
  ------------------
  |  Branch (1119:9): [True: 0, False: 0]
  ------------------
 1120|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1121|      0|    }
 1122|      0|    return NULL;
 1123|      2|}
CERT_DupCertList:
 1166|  19.4k|{
 1167|  19.4k|    CERTCertificateList *newList = NULL;
 1168|  19.4k|    PLArenaPool *arena = NULL;
 1169|  19.4k|    SECItem *newItem;
 1170|  19.4k|    SECItem *oldItem;
 1171|  19.4k|    int len = oldList->len;
 1172|  19.4k|    int rv;
 1173|       |
 1174|       |    /* arena for SecCertificateList */
 1175|  19.4k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  19.4k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  19.4k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 1176|  19.4k|    if (arena == NULL)
  ------------------
  |  Branch (1176:9): [True: 0, False: 19.4k]
  ------------------
 1177|      0|        goto no_memory;
 1178|       |
 1179|       |    /* now build the CERTCertificateList */
 1180|  19.4k|    newList = PORT_ArenaNew(arena, CERTCertificateList);
  ------------------
  |  |  153|  19.4k|    (type *)PORT_ArenaAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   53|  19.4k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  |  |  ------------------
  ------------------
 1181|  19.4k|    if (newList == NULL)
  ------------------
  |  Branch (1181:9): [True: 0, False: 19.4k]
  ------------------
 1182|      0|        goto no_memory;
 1183|  19.4k|    newList->arena = arena;
 1184|  19.4k|    newItem = (SECItem *)PORT_ArenaAlloc(arena, len * sizeof(SECItem));
  ------------------
  |  |   53|  19.4k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1185|  19.4k|    if (newItem == NULL)
  ------------------
  |  Branch (1185:9): [True: 0, False: 19.4k]
  ------------------
 1186|      0|        goto no_memory;
 1187|  19.4k|    newList->certs = newItem;
 1188|  19.4k|    newList->len = len;
 1189|       |
 1190|  38.8k|    for (oldItem = oldList->certs; len > 0; --len, ++newItem, ++oldItem) {
  ------------------
  |  Branch (1190:36): [True: 19.4k, False: 19.4k]
  ------------------
 1191|  19.4k|        rv = SECITEM_CopyItem(arena, newItem, oldItem);
  ------------------
  |  |  106|  19.4k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1192|  19.4k|        if (rv < 0)
  ------------------
  |  Branch (1192:13): [True: 0, False: 19.4k]
  ------------------
 1193|      0|            goto loser;
 1194|  19.4k|    }
 1195|  19.4k|    return newList;
 1196|       |
 1197|      0|no_memory:
 1198|      0|    PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1199|      0|loser:
 1200|      0|    if (arena != NULL) {
  ------------------
  |  Branch (1200:9): [True: 0, False: 0]
  ------------------
 1201|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1202|      0|    }
 1203|      0|    return NULL;
 1204|      0|}
CERT_DestroyCertificateList:
 1208|  19.4k|{
 1209|  19.4k|    PORT_FreeArena(list->arena, PR_FALSE);
  ------------------
  |  |   61|  19.4k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(list->arena, PR_FALSE);
  ------------------
  |  |  438|  19.4k|#define PR_FALSE 0
  ------------------
 1210|  19.4k|}

CERT_ClearOCSPCache:
  595|      1|{
  596|      1|    OCSP_TRACE(("OCSP CERT_ClearOCSPCache\n"));
  ------------------
  |  |  144|      1|#define OCSP_TRACE(msg) ocsp_Trace msg
  ------------------
  597|      1|    PR_EnterMonitor(OCSP_Global.monitor);
  598|      1|    while (OCSP_Global.cache.numberOfEntries > 0) {
  ------------------
  |  Branch (598:12): [True: 0, False: 1]
  ------------------
  599|      0|        ocsp_RemoveCacheItem(&OCSP_Global.cache,
  600|      0|                             OCSP_Global.cache.LRUitem);
  601|      0|    }
  602|      1|    PR_ExitMonitor(OCSP_Global.monitor);
  603|      1|    return SECSuccess;
  604|      1|}
OCSP_InitGlobal:
  933|      1|{
  934|      1|    SECStatus rv = SECFailure;
  935|       |
  936|      1|    if (OCSP_Global.monitor == NULL) {
  ------------------
  |  Branch (936:9): [True: 1, False: 0]
  ------------------
  937|      1|        OCSP_Global.monitor = PR_NewMonitor();
  938|      1|    }
  939|      1|    if (!OCSP_Global.monitor)
  ------------------
  |  Branch (939:9): [True: 0, False: 1]
  ------------------
  940|      0|        return SECFailure;
  941|       |
  942|      1|    PR_EnterMonitor(OCSP_Global.monitor);
  943|      1|    if (!OCSP_Global.cache.entries) {
  ------------------
  |  Branch (943:9): [True: 1, False: 0]
  ------------------
  944|      1|        OCSP_Global.cache.entries =
  945|      1|            PL_NewHashTable(0,
  946|      1|                            ocsp_CacheKeyHashFunction,
  947|      1|                            ocsp_CacheKeyCompareFunction,
  948|      1|                            PL_CompareValues,
  949|      1|                            NULL,
  950|      1|                            NULL);
  951|      1|        OCSP_Global.ocspFailureMode = ocspMode_FailureIsVerificationFailure;
  952|      1|        OCSP_Global.cache.numberOfEntries = 0;
  953|      1|        OCSP_Global.cache.MRUitem = NULL;
  954|      1|        OCSP_Global.cache.LRUitem = NULL;
  955|      1|    } else {
  956|       |        /*
  957|       |         * NSS might call this function twice while attempting to init.
  958|       |         * But it's not allowed to call this again after any activity.
  959|       |         */
  960|      0|        PORT_Assert(OCSP_Global.cache.numberOfEntries == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  961|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  962|      0|    }
  963|      1|    if (OCSP_Global.cache.entries)
  ------------------
  |  Branch (963:9): [True: 1, False: 0]
  ------------------
  964|      1|        rv = SECSuccess;
  965|      1|    PR_ExitMonitor(OCSP_Global.monitor);
  966|      1|    return rv;
  967|      1|}
OCSP_ShutdownGlobal:
  971|      1|{
  972|      1|    if (!OCSP_Global.monitor)
  ------------------
  |  Branch (972:9): [True: 0, False: 1]
  ------------------
  973|      0|        return SECSuccess;
  974|       |
  975|      1|    PR_EnterMonitor(OCSP_Global.monitor);
  976|      1|    if (OCSP_Global.cache.entries) {
  ------------------
  |  Branch (976:9): [True: 1, False: 0]
  ------------------
  977|      1|        CERT_ClearOCSPCache();
  978|      1|        PL_HashTableDestroy(OCSP_Global.cache.entries);
  979|      1|        OCSP_Global.cache.entries = NULL;
  980|      1|    }
  981|      1|    PORT_Assert(OCSP_Global.cache.numberOfEntries == 0);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  982|      1|    OCSP_Global.cache.MRUitem = NULL;
  983|      1|    OCSP_Global.cache.LRUitem = NULL;
  984|       |
  985|      1|    OCSP_Global.defaultHttpClientFcn = NULL;
  986|      1|    OCSP_Global.maxCacheEntries = DEFAULT_OCSP_CACHE_SIZE;
  ------------------
  |  |   40|      1|#define DEFAULT_OCSP_CACHE_SIZE 1000
  ------------------
  987|      1|    OCSP_Global.minimumSecondsToNextFetchAttempt =
  988|      1|        DEFAULT_MINIMUM_SECONDS_TO_NEXT_OCSP_FETCH_ATTEMPT;
  ------------------
  |  |   41|      1|#define DEFAULT_MINIMUM_SECONDS_TO_NEXT_OCSP_FETCH_ATTEMPT 1 * 60 * 60L
  ------------------
  989|      1|    OCSP_Global.maximumSecondsToNextFetchAttempt =
  990|      1|        DEFAULT_MAXIMUM_SECONDS_TO_NEXT_OCSP_FETCH_ATTEMPT;
  ------------------
  |  |   42|      1|#define DEFAULT_MAXIMUM_SECONDS_TO_NEXT_OCSP_FETCH_ATTEMPT 24 * 60 * 60L
  ------------------
  991|      1|    OCSP_Global.ocspFailureMode =
  992|      1|        ocspMode_FailureIsVerificationFailure;
  993|      1|    PR_ExitMonitor(OCSP_Global.monitor);
  994|       |
  995|      1|    PR_DestroyMonitor(OCSP_Global.monitor);
  996|      1|    OCSP_Global.monitor = NULL;
  997|      1|    return SECSuccess;
  998|      1|}
ocsp.c:ocsp_Trace:
  173|      1|{
  174|      1|    char buf[2000];
  175|      1|    va_list args;
  176|       |
  177|      1|    if (!wantOcspTrace())
  ------------------
  |  Branch (177:9): [True: 1, False: 0]
  ------------------
  178|      1|        return;
  179|      0|    va_start(args, format);
  180|      0|    PR_vsnprintf(buf, sizeof(buf), format, args);
  181|      0|    va_end(args);
  182|      0|    PR_LogPrint("%s", buf);
  183|      0|}
ocsp.c:wantOcspTrace:
  155|      1|{
  156|      1|    static PRBool firstTime = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  157|      1|    static PRBool wantTrace = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  158|       |
  159|      1|#ifdef NSS_HAVE_GETENV
  160|      1|    if (firstTime) {
  ------------------
  |  Branch (160:9): [True: 1, False: 0]
  ------------------
  161|      1|        char *ev = PR_GetEnvSecure("NSS_TRACE_OCSP");
  162|      1|        if (ev && ev[0]) {
  ------------------
  |  Branch (162:13): [True: 0, False: 1]
  |  Branch (162:19): [True: 0, False: 0]
  ------------------
  163|      0|            wantTrace = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  164|      0|        }
  165|      1|        firstTime = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  166|      1|    }
  167|      1|#endif
  168|      1|    return wantTrace;
  169|      1|}

DSAU_ConvertUnsignedToSigned:
   36|  23.4k|{
   37|  23.4k|    unsigned char *pSrc = src->data;
   38|  23.4k|    unsigned char *pDst = dest->data;
   39|  23.4k|    unsigned int cntSrc = src->len;
   40|       |
   41|       |    /* skip any leading zeros. */
   42|  23.5k|    while (cntSrc && !(*pSrc)) {
  ------------------
  |  Branch (42:12): [True: 23.5k, False: 0]
  |  Branch (42:22): [True: 105, False: 23.4k]
  ------------------
   43|    105|        pSrc++;
   44|    105|        cntSrc--;
   45|    105|    }
   46|  23.4k|    if (!cntSrc) {
  ------------------
  |  Branch (46:9): [True: 0, False: 23.4k]
  ------------------
   47|      0|        *pDst = 0;
   48|      0|        dest->len = 1;
   49|      0|        return;
   50|      0|    }
   51|       |
   52|  23.4k|    if (*pSrc & 0x80)
  ------------------
  |  Branch (52:9): [True: 11.6k, False: 11.7k]
  ------------------
   53|  11.6k|        *pDst++ = 0;
   54|       |
   55|  23.4k|    PORT_Memcpy(pDst, pSrc, cntSrc);
  ------------------
  |  |  180|  23.4k|#define PORT_Memcpy memcpy
  ------------------
   56|  23.4k|    dest->len = (pDst - dest->data) + cntSrc;
   57|  23.4k|}
DSAU_EncodeDerSigWithLen:
  240|  11.7k|{
  241|       |
  242|  11.7k|    PORT_Assert((src->len == len) && (len % 2 == 0));
  ------------------
  |  |  120|  11.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  23.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 11.7k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 11.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  243|  11.7k|    if ((src->len != len) || (src->len % 2 != 0)) {
  ------------------
  |  Branch (243:9): [True: 0, False: 11.7k]
  |  Branch (243:30): [True: 0, False: 11.7k]
  ------------------
  244|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  245|      0|        return SECFailure;
  246|      0|    }
  247|       |
  248|  11.7k|    return common_EncodeDerSig(dest, src);
  249|  11.7k|}
dsautil.c:common_EncodeDerSig:
  102|  11.7k|{
  103|  11.7k|    SECItem *item;
  104|  11.7k|    SECItem srcItem;
  105|  11.7k|    DSA_ASN1Signature sig;
  106|  11.7k|    unsigned char *signedR;
  107|  11.7k|    unsigned char *signedS;
  108|  11.7k|    unsigned int len;
  109|       |
  110|       |    /* Allocate memory with room for an extra byte that
  111|       |     * may be required if the top bit in the first byte
  112|       |     * is already set.
  113|       |     */
  114|  11.7k|    len = src->len / 2;
  115|  11.7k|    signedR = (unsigned char *)PORT_Alloc(len + 1);
  ------------------
  |  |   52|  11.7k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  116|  11.7k|    if (!signedR)
  ------------------
  |  Branch (116:9): [True: 0, False: 11.7k]
  ------------------
  117|      0|        return SECFailure;
  118|  11.7k|    signedS = (unsigned char *)PORT_ZAlloc(len + 1);
  ------------------
  |  |   72|  11.7k|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  119|  11.7k|    if (!signedS) {
  ------------------
  |  Branch (119:9): [True: 0, False: 11.7k]
  ------------------
  120|      0|        if (signedR)
  ------------------
  |  Branch (120:13): [True: 0, False: 0]
  ------------------
  121|      0|            PORT_Free(signedR);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  122|      0|        return SECFailure;
  123|      0|    }
  124|       |
  125|  11.7k|    PORT_Memset(&sig, 0, sizeof(sig));
  ------------------
  |  |  182|  11.7k|#define PORT_Memset memset
  ------------------
  126|       |
  127|       |    /* Must convert r and s from "unsigned" integers to "signed" integers.
  128|       |    ** If the high order bit of the first byte (MSB) is 1, then must
  129|       |    ** prepend with leading zero.
  130|       |    ** Must remove all but one leading zero byte from numbers.
  131|       |    */
  132|  11.7k|    sig.r.type = siUnsignedInteger;
  133|  11.7k|    sig.r.data = signedR;
  134|  11.7k|    sig.r.len = sizeof signedR;
  135|  11.7k|    sig.s.type = siUnsignedInteger;
  136|  11.7k|    sig.s.data = signedS;
  137|  11.7k|    sig.s.len = sizeof signedR;
  138|       |
  139|  11.7k|    srcItem.data = src->data;
  140|  11.7k|    srcItem.len = len;
  141|       |
  142|  11.7k|    DSAU_ConvertUnsignedToSigned(&sig.r, &srcItem);
  143|  11.7k|    srcItem.data += len;
  144|  11.7k|    DSAU_ConvertUnsignedToSigned(&sig.s, &srcItem);
  145|       |
  146|  11.7k|    item = SEC_ASN1EncodeItem(NULL, dest, &sig, DSA_SignatureTemplate);
  ------------------
  |  |   89|  11.7k|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
  147|  11.7k|    if (signedR)
  ------------------
  |  Branch (147:9): [True: 11.7k, False: 0]
  ------------------
  148|  11.7k|        PORT_Free(signedR);
  ------------------
  |  |   60|  11.7k|#define PORT_Free PORT_Free_Util
  ------------------
  149|  11.7k|    if (signedS)
  ------------------
  |  Branch (149:9): [True: 11.7k, False: 0]
  ------------------
  150|  11.7k|        PORT_Free(signedS);
  ------------------
  |  |   60|  11.7k|#define PORT_Free PORT_Free_Util
  ------------------
  151|  11.7k|    if (item == NULL)
  ------------------
  |  Branch (151:9): [True: 0, False: 11.7k]
  ------------------
  152|      0|        return SECFailure;
  153|       |
  154|       |    /* XXX leak item? */
  155|  11.7k|    return SECSuccess;
  156|  11.7k|}

HASH_GetHashObjectByOidTag:
  273|  98.4k|{
  274|  98.4k|    HASH_HashType ht = HASH_GetHashTypeByOidTag(hashOid);
  ------------------
  |  |  125|  98.4k|#define HASH_GetHashTypeByOidTag HASH_GetHashTypeByOidTag_Util
  ------------------
  275|       |
  276|  98.4k|    return (ht == HASH_AlgNULL) ? NULL : &SECHashObjects[ht];
  ------------------
  |  Branch (276:12): [True: 0, False: 98.4k]
  ------------------
  277|  98.4k|}
HASH_ResultLenByOidTag:
  282|  98.4k|{
  283|  98.4k|    const SECHashObject *hashObject = HASH_GetHashObjectByOidTag(hashOid);
  284|  98.4k|    unsigned int resultLen = 0;
  285|       |
  286|  98.4k|    if (hashObject)
  ------------------
  |  Branch (286:9): [True: 98.4k, False: 0]
  ------------------
  287|  98.4k|        resultLen = hashObject->length;
  288|  98.4k|    return resultLen;
  289|  98.4k|}

SECKEY_CreateDHPrivateKey:
  175|  29.0k|{
  176|  29.0k|    SECKEYPrivateKey *privk;
  177|  29.0k|    PK11SlotInfo *slot;
  178|       |
  179|  29.0k|    if (!param || !param->base.data || !param->prime.data ||
  ------------------
  |  Branch (179:9): [True: 0, False: 29.0k]
  |  Branch (179:19): [True: 0, False: 29.0k]
  |  Branch (179:40): [True: 0, False: 29.0k]
  ------------------
  180|  29.0k|        SECKEY_BigIntegerBitLength(&param->prime) < DH_MIN_P_BITS ||
  ------------------
  |  |  154|  58.1k|#define DH_MIN_P_BITS 128
  ------------------
  |  Branch (180:9): [True: 0, False: 29.0k]
  ------------------
  181|  29.0k|        param->base.len == 0 || param->base.len > param->prime.len + 1 ||
  ------------------
  |  Branch (181:9): [True: 0, False: 29.0k]
  |  Branch (181:33): [True: 0, False: 29.0k]
  ------------------
  182|  29.0k|        (param->base.len == 1 && param->base.data[0] == 0)) {
  ------------------
  |  Branch (182:10): [True: 29.0k, False: 0]
  |  Branch (182:34): [True: 0, False: 29.0k]
  ------------------
  183|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  184|      0|        return NULL;
  185|      0|    }
  186|       |
  187|  29.0k|    slot = PK11_GetBestSlot(CKM_DH_PKCS_KEY_PAIR_GEN, cx);
  ------------------
  |  |  758|  29.0k|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  188|  29.0k|    if (!slot) {
  ------------------
  |  Branch (188:9): [True: 0, False: 29.0k]
  ------------------
  189|      0|        return NULL;
  190|      0|    }
  191|       |
  192|  29.0k|    privk = PK11_GenerateKeyPair(slot, CKM_DH_PKCS_KEY_PAIR_GEN, param,
  ------------------
  |  |  758|  29.0k|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  193|  29.0k|                                 pubk, PR_FALSE, PR_FALSE, cx);
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
                                               pubk, PR_FALSE, PR_FALSE, cx);
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
  194|  29.0k|    if (!privk)
  ------------------
  |  Branch (194:9): [True: 0, False: 29.0k]
  ------------------
  195|      0|        privk = PK11_GenerateKeyPair(slot, CKM_DH_PKCS_KEY_PAIR_GEN, param,
  ------------------
  |  |  758|      0|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  196|      0|                                     pubk, PR_FALSE, PR_TRUE, cx);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
                                                   pubk, PR_FALSE, PR_TRUE, cx);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  197|       |
  198|  29.0k|    PK11_FreeSlot(slot);
  199|  29.0k|    return (privk);
  200|  29.0k|}
SECKEY_CreateECPrivateKey:
  211|      1|{
  212|      1|    SECKEYPrivateKey *privk;
  213|      1|    PK11SlotInfo *slot = PK11_GetBestSlot(CKM_EC_KEY_PAIR_GEN, cx);
  ------------------
  |  | 1072|      1|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  214|      1|    if (!slot) {
  ------------------
  |  Branch (214:9): [True: 0, False: 1]
  ------------------
  215|      0|        return NULL;
  216|      0|    }
  217|       |
  218|      1|    privk = PK11_GenerateKeyPairWithOpFlags(slot, CKM_EC_KEY_PAIR_GEN,
  ------------------
  |  | 1072|      1|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  219|      1|                                            param, pubk,
  220|      1|                                            PK11_ATTR_SESSION |
  ------------------
  |  |  195|      1|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
  221|      1|                                                PK11_ATTR_INSENSITIVE |
  ------------------
  |  |  261|      1|#define PK11_ATTR_INSENSITIVE 0x00000080L
  ------------------
  222|      1|                                                PK11_ATTR_PUBLIC,
  ------------------
  |  |  217|      1|#define PK11_ATTR_PUBLIC 0x00000008L
  ------------------
  223|      1|                                            CKF_DERIVE, CKF_DERIVE | CKF_SIGN,
  ------------------
  |  | 1364|      1|#define CKF_DERIVE 0x00080000UL
  ------------------
                                                          CKF_DERIVE, CKF_DERIVE | CKF_SIGN,
  ------------------
  |  | 1364|      1|#define CKF_DERIVE 0x00080000UL
  ------------------
                                                          CKF_DERIVE, CKF_DERIVE | CKF_SIGN,
  ------------------
  |  | 1356|      1|#define CKF_SIGN 0x00000800UL
  ------------------
  224|      1|                                            cx);
  225|      1|    if (!privk)
  ------------------
  |  Branch (225:9): [True: 0, False: 1]
  ------------------
  226|      0|        privk = PK11_GenerateKeyPairWithOpFlags(slot, CKM_EC_KEY_PAIR_GEN,
  ------------------
  |  | 1072|      0|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  227|      0|                                                param, pubk,
  228|      0|                                                PK11_ATTR_SESSION |
  ------------------
  |  |  195|      0|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
  229|      0|                                                    PK11_ATTR_SENSITIVE |
  ------------------
  |  |  260|      0|#define PK11_ATTR_SENSITIVE 0x00000040L
  ------------------
  230|      0|                                                    PK11_ATTR_PRIVATE,
  ------------------
  |  |  216|      0|#define PK11_ATTR_PRIVATE 0x00000004L
  ------------------
  231|      0|                                                CKF_DERIVE, CKF_DERIVE | CKF_SIGN,
  ------------------
  |  | 1364|      0|#define CKF_DERIVE 0x00080000UL
  ------------------
                                                              CKF_DERIVE, CKF_DERIVE | CKF_SIGN,
  ------------------
  |  | 1364|      0|#define CKF_DERIVE 0x00080000UL
  ------------------
                                                              CKF_DERIVE, CKF_DERIVE | CKF_SIGN,
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
  232|      0|                                                cx);
  233|       |
  234|      1|    PK11_FreeSlot(slot);
  235|      1|    return (privk);
  236|      1|}
SECKEY_DestroyPrivateKey:
  267|  57.0k|{
  268|  57.0k|    if (privk) {
  ------------------
  |  Branch (268:9): [True: 47.3k, False: 9.71k]
  ------------------
  269|  47.3k|        if (privk->pkcs11Slot) {
  ------------------
  |  Branch (269:13): [True: 47.3k, False: 0]
  ------------------
  270|  47.3k|            if (privk->pkcs11IsTemp) {
  ------------------
  |  Branch (270:17): [True: 47.3k, False: 0]
  ------------------
  271|  47.3k|                PK11_DestroyObject(privk->pkcs11Slot, privk->pkcs11ID);
  272|  47.3k|            }
  273|  47.3k|            PK11_FreeSlot(privk->pkcs11Slot);
  274|  47.3k|        }
  275|  47.3k|        if (privk->arena) {
  ------------------
  |  Branch (275:13): [True: 47.3k, False: 0]
  ------------------
  276|  47.3k|            PORT_FreeArena(privk->arena, PR_TRUE);
  ------------------
  |  |   61|  47.3k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(privk->arena, PR_TRUE);
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
  277|  47.3k|        }
  278|  47.3k|    }
  279|  57.0k|}
SECKEY_DestroyPublicKey:
  283|  64.2k|{
  284|  64.2k|    if (pubk) {
  ------------------
  |  Branch (284:9): [True: 54.5k, False: 9.71k]
  ------------------
  285|  54.5k|        if (pubk->pkcs11Slot) {
  ------------------
  |  Branch (285:13): [True: 50.3k, False: 4.21k]
  ------------------
  286|  50.3k|            if (!PK11_IsPermObject(pubk->pkcs11Slot, pubk->pkcs11ID)) {
  ------------------
  |  Branch (286:17): [True: 50.3k, False: 0]
  ------------------
  287|  50.3k|                PK11_DestroyObject(pubk->pkcs11Slot, pubk->pkcs11ID);
  288|  50.3k|            }
  289|  50.3k|            PK11_FreeSlot(pubk->pkcs11Slot);
  290|  50.3k|        }
  291|  54.5k|        if (pubk->arena) {
  ------------------
  |  Branch (291:13): [True: 54.5k, False: 0]
  ------------------
  292|  54.5k|            PORT_FreeArena(pubk->arena, PR_FALSE);
  ------------------
  |  |   61|  54.5k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(pubk->arena, PR_FALSE);
  ------------------
  |  |  438|  54.5k|#define PR_FALSE 0
  ------------------
  293|  54.5k|        }
  294|  54.5k|    }
  295|  64.2k|}
SECKEY_UpdateCertPQG:
  459|  3.83k|{
  460|  3.83k|    if (!subjectCert) {
  ------------------
  |  Branch (460:9): [True: 0, False: 3.83k]
  ------------------
  461|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  462|      0|        return SECFailure;
  463|      0|    }
  464|  3.83k|    return seckey_UpdateCertPQGChain(subjectCert, 0);
  465|  3.83k|}
seckey_GetKeyType:
  520|  2.95k|{
  521|  2.95k|    KeyType keyType;
  522|       |
  523|  2.95k|    switch (tag) {
  524|      0|        case SEC_OID_X500_RSA_ENCRYPTION:
  ------------------
  |  Branch (524:9): [True: 0, False: 2.95k]
  ------------------
  525|  2.95k|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (525:9): [True: 2.95k, False: 0]
  ------------------
  526|  2.95k|            keyType = rsaKey;
  527|  2.95k|            break;
  528|      0|        case SEC_OID_PKCS1_RSA_PSS_SIGNATURE:
  ------------------
  |  Branch (528:9): [True: 0, False: 2.95k]
  ------------------
  529|      0|            keyType = rsaPssKey;
  530|      0|            break;
  531|      0|        case SEC_OID_PKCS1_RSA_OAEP_ENCRYPTION:
  ------------------
  |  Branch (531:9): [True: 0, False: 2.95k]
  ------------------
  532|      0|            keyType = rsaOaepKey;
  533|      0|            break;
  534|      0|        case SEC_OID_ANSIX9_DSA_SIGNATURE:
  ------------------
  |  Branch (534:9): [True: 0, False: 2.95k]
  ------------------
  535|      0|            keyType = dsaKey;
  536|      0|            break;
  537|      0|        case SEC_OID_MISSI_KEA_DSS_OLD:
  ------------------
  |  Branch (537:9): [True: 0, False: 2.95k]
  ------------------
  538|      0|        case SEC_OID_MISSI_KEA_DSS:
  ------------------
  |  Branch (538:9): [True: 0, False: 2.95k]
  ------------------
  539|      0|        case SEC_OID_MISSI_DSS_OLD:
  ------------------
  |  Branch (539:9): [True: 0, False: 2.95k]
  ------------------
  540|      0|        case SEC_OID_MISSI_DSS:
  ------------------
  |  Branch (540:9): [True: 0, False: 2.95k]
  ------------------
  541|      0|            keyType = fortezzaKey;
  542|      0|            break;
  543|      0|        case SEC_OID_MISSI_KEA:
  ------------------
  |  Branch (543:9): [True: 0, False: 2.95k]
  ------------------
  544|      0|        case SEC_OID_MISSI_ALT_KEA:
  ------------------
  |  Branch (544:9): [True: 0, False: 2.95k]
  ------------------
  545|      0|            keyType = keaKey;
  546|      0|            break;
  547|      0|        case SEC_OID_X942_DIFFIE_HELMAN_KEY:
  ------------------
  |  Branch (547:9): [True: 0, False: 2.95k]
  ------------------
  548|      0|            keyType = dhKey;
  549|      0|            break;
  550|      0|        case SEC_OID_ANSIX962_EC_PUBLIC_KEY:
  ------------------
  |  Branch (550:9): [True: 0, False: 2.95k]
  ------------------
  551|      0|            keyType = ecKey;
  552|      0|            break;
  553|      0|        case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (553:9): [True: 0, False: 2.95k]
  ------------------
  554|      0|            keyType = edKey;
  555|      0|            break;
  556|       |        /* accommodate applications that hand us a signature type when they
  557|       |         * should be handing us a cipher type */
  558|      0|        case SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (558:9): [True: 0, False: 2.95k]
  ------------------
  559|      0|        case SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (559:9): [True: 0, False: 2.95k]
  ------------------
  560|      0|        case SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (560:9): [True: 0, False: 2.95k]
  ------------------
  561|      0|        case SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (561:9): [True: 0, False: 2.95k]
  ------------------
  562|      0|        case SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (562:9): [True: 0, False: 2.95k]
  ------------------
  563|      0|        case SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (563:9): [True: 0, False: 2.95k]
  ------------------
  564|      0|            keyType = rsaKey;
  565|      0|            break;
  566|      0|        default:
  ------------------
  |  Branch (566:9): [True: 0, False: 2.95k]
  ------------------
  567|      0|            keyType = nullKey;
  568|  2.95k|    }
  569|  2.95k|    return keyType;
  570|  2.95k|}
SECKEY_ExtractPublicKey:
  755|  4.27k|{
  756|  4.27k|    return seckey_ExtractPublicKey(spki);
  757|  4.27k|}
CERT_ExtractPublicKey:
  761|      2|{
  762|      2|    return seckey_ExtractPublicKey(&cert->subjectPublicKeyInfo);
  763|      2|}
SECKEY_ECParamsToKeySize:
  767|  29.3k|{
  768|  29.3k|    SECOidTag tag;
  769|  29.3k|    SECItem oid = { siBuffer, NULL, 0 };
  770|       |
  771|       |    /* The encodedParams data contains 0x06 (SEC_ASN1_OBJECT_ID),
  772|       |     * followed by the length of the curve oid and the curve oid.
  773|       |     */
  774|  29.3k|    oid.len = encodedParams->data[1];
  775|  29.3k|    oid.data = encodedParams->data + 2;
  776|  29.3k|    if ((tag = SECOID_FindOIDTag(&oid)) == SEC_OID_UNKNOWN)
  ------------------
  |  |  117|  29.3k|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
  |  Branch (776:9): [True: 0, False: 29.3k]
  ------------------
  777|      0|        return 0;
  778|       |
  779|  29.3k|    switch (tag) {
  780|      0|        case SEC_OID_SECG_EC_SECP112R1:
  ------------------
  |  Branch (780:9): [True: 0, False: 29.3k]
  ------------------
  781|      0|        case SEC_OID_SECG_EC_SECP112R2:
  ------------------
  |  Branch (781:9): [True: 0, False: 29.3k]
  ------------------
  782|      0|            return 112;
  783|       |
  784|      0|        case SEC_OID_SECG_EC_SECT113R1:
  ------------------
  |  Branch (784:9): [True: 0, False: 29.3k]
  ------------------
  785|      0|        case SEC_OID_SECG_EC_SECT113R2:
  ------------------
  |  Branch (785:9): [True: 0, False: 29.3k]
  ------------------
  786|      0|            return 113;
  787|       |
  788|      0|        case SEC_OID_SECG_EC_SECP128R1:
  ------------------
  |  Branch (788:9): [True: 0, False: 29.3k]
  ------------------
  789|      0|        case SEC_OID_SECG_EC_SECP128R2:
  ------------------
  |  Branch (789:9): [True: 0, False: 29.3k]
  ------------------
  790|      0|            return 128;
  791|       |
  792|      0|        case SEC_OID_SECG_EC_SECT131R1:
  ------------------
  |  Branch (792:9): [True: 0, False: 29.3k]
  ------------------
  793|      0|        case SEC_OID_SECG_EC_SECT131R2:
  ------------------
  |  Branch (793:9): [True: 0, False: 29.3k]
  ------------------
  794|      0|            return 131;
  795|       |
  796|      0|        case SEC_OID_SECG_EC_SECP160K1:
  ------------------
  |  Branch (796:9): [True: 0, False: 29.3k]
  ------------------
  797|      0|        case SEC_OID_SECG_EC_SECP160R1:
  ------------------
  |  Branch (797:9): [True: 0, False: 29.3k]
  ------------------
  798|      0|        case SEC_OID_SECG_EC_SECP160R2:
  ------------------
  |  Branch (798:9): [True: 0, False: 29.3k]
  ------------------
  799|      0|            return 160;
  800|       |
  801|      0|        case SEC_OID_SECG_EC_SECT163K1:
  ------------------
  |  Branch (801:9): [True: 0, False: 29.3k]
  ------------------
  802|      0|        case SEC_OID_SECG_EC_SECT163R1:
  ------------------
  |  Branch (802:9): [True: 0, False: 29.3k]
  ------------------
  803|      0|        case SEC_OID_SECG_EC_SECT163R2:
  ------------------
  |  Branch (803:9): [True: 0, False: 29.3k]
  ------------------
  804|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V1:
  ------------------
  |  Branch (804:9): [True: 0, False: 29.3k]
  ------------------
  805|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V2:
  ------------------
  |  Branch (805:9): [True: 0, False: 29.3k]
  ------------------
  806|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V3:
  ------------------
  |  Branch (806:9): [True: 0, False: 29.3k]
  ------------------
  807|      0|            return 163;
  808|       |
  809|      0|        case SEC_OID_ANSIX962_EC_C2PNB176V1:
  ------------------
  |  Branch (809:9): [True: 0, False: 29.3k]
  ------------------
  810|      0|            return 176;
  811|       |
  812|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V1:
  ------------------
  |  Branch (812:9): [True: 0, False: 29.3k]
  ------------------
  813|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V2:
  ------------------
  |  Branch (813:9): [True: 0, False: 29.3k]
  ------------------
  814|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V3:
  ------------------
  |  Branch (814:9): [True: 0, False: 29.3k]
  ------------------
  815|      0|        case SEC_OID_ANSIX962_EC_C2ONB191V4:
  ------------------
  |  Branch (815:9): [True: 0, False: 29.3k]
  ------------------
  816|      0|        case SEC_OID_ANSIX962_EC_C2ONB191V5:
  ------------------
  |  Branch (816:9): [True: 0, False: 29.3k]
  ------------------
  817|      0|            return 191;
  818|       |
  819|      0|        case SEC_OID_SECG_EC_SECP192K1:
  ------------------
  |  Branch (819:9): [True: 0, False: 29.3k]
  ------------------
  820|      0|        case SEC_OID_ANSIX962_EC_PRIME192V1:
  ------------------
  |  Branch (820:9): [True: 0, False: 29.3k]
  ------------------
  821|      0|        case SEC_OID_ANSIX962_EC_PRIME192V2:
  ------------------
  |  Branch (821:9): [True: 0, False: 29.3k]
  ------------------
  822|      0|        case SEC_OID_ANSIX962_EC_PRIME192V3:
  ------------------
  |  Branch (822:9): [True: 0, False: 29.3k]
  ------------------
  823|      0|            return 192;
  824|       |
  825|      0|        case SEC_OID_SECG_EC_SECT193R1:
  ------------------
  |  Branch (825:9): [True: 0, False: 29.3k]
  ------------------
  826|      0|        case SEC_OID_SECG_EC_SECT193R2:
  ------------------
  |  Branch (826:9): [True: 0, False: 29.3k]
  ------------------
  827|      0|            return 193;
  828|       |
  829|      0|        case SEC_OID_ANSIX962_EC_C2PNB208W1:
  ------------------
  |  Branch (829:9): [True: 0, False: 29.3k]
  ------------------
  830|      0|            return 208;
  831|       |
  832|      0|        case SEC_OID_SECG_EC_SECP224K1:
  ------------------
  |  Branch (832:9): [True: 0, False: 29.3k]
  ------------------
  833|      0|        case SEC_OID_SECG_EC_SECP224R1:
  ------------------
  |  Branch (833:9): [True: 0, False: 29.3k]
  ------------------
  834|      0|            return 224;
  835|       |
  836|      0|        case SEC_OID_SECG_EC_SECT233K1:
  ------------------
  |  Branch (836:9): [True: 0, False: 29.3k]
  ------------------
  837|      0|        case SEC_OID_SECG_EC_SECT233R1:
  ------------------
  |  Branch (837:9): [True: 0, False: 29.3k]
  ------------------
  838|      0|            return 233;
  839|       |
  840|      0|        case SEC_OID_SECG_EC_SECT239K1:
  ------------------
  |  Branch (840:9): [True: 0, False: 29.3k]
  ------------------
  841|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V1:
  ------------------
  |  Branch (841:9): [True: 0, False: 29.3k]
  ------------------
  842|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V2:
  ------------------
  |  Branch (842:9): [True: 0, False: 29.3k]
  ------------------
  843|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V3:
  ------------------
  |  Branch (843:9): [True: 0, False: 29.3k]
  ------------------
  844|      0|        case SEC_OID_ANSIX962_EC_C2ONB239V4:
  ------------------
  |  Branch (844:9): [True: 0, False: 29.3k]
  ------------------
  845|      0|        case SEC_OID_ANSIX962_EC_C2ONB239V5:
  ------------------
  |  Branch (845:9): [True: 0, False: 29.3k]
  ------------------
  846|      0|        case SEC_OID_ANSIX962_EC_PRIME239V1:
  ------------------
  |  Branch (846:9): [True: 0, False: 29.3k]
  ------------------
  847|      0|        case SEC_OID_ANSIX962_EC_PRIME239V2:
  ------------------
  |  Branch (847:9): [True: 0, False: 29.3k]
  ------------------
  848|      0|        case SEC_OID_ANSIX962_EC_PRIME239V3:
  ------------------
  |  Branch (848:9): [True: 0, False: 29.3k]
  ------------------
  849|      0|            return 239;
  850|       |
  851|      0|        case SEC_OID_SECG_EC_SECP256K1:
  ------------------
  |  Branch (851:9): [True: 0, False: 29.3k]
  ------------------
  852|  20.0k|        case SEC_OID_ANSIX962_EC_PRIME256V1:
  ------------------
  |  Branch (852:9): [True: 20.0k, False: 9.25k]
  ------------------
  853|  20.0k|            return 256;
  854|       |
  855|      0|        case SEC_OID_ANSIX962_EC_C2PNB272W1:
  ------------------
  |  Branch (855:9): [True: 0, False: 29.3k]
  ------------------
  856|      0|            return 272;
  857|       |
  858|      0|        case SEC_OID_SECG_EC_SECT283K1:
  ------------------
  |  Branch (858:9): [True: 0, False: 29.3k]
  ------------------
  859|      0|        case SEC_OID_SECG_EC_SECT283R1:
  ------------------
  |  Branch (859:9): [True: 0, False: 29.3k]
  ------------------
  860|      0|            return 283;
  861|       |
  862|      0|        case SEC_OID_ANSIX962_EC_C2PNB304W1:
  ------------------
  |  Branch (862:9): [True: 0, False: 29.3k]
  ------------------
  863|      0|            return 304;
  864|       |
  865|      0|        case SEC_OID_ANSIX962_EC_C2TNB359V1:
  ------------------
  |  Branch (865:9): [True: 0, False: 29.3k]
  ------------------
  866|      0|            return 359;
  867|       |
  868|      0|        case SEC_OID_ANSIX962_EC_C2PNB368W1:
  ------------------
  |  Branch (868:9): [True: 0, False: 29.3k]
  ------------------
  869|      0|            return 368;
  870|       |
  871|  2.00k|        case SEC_OID_SECG_EC_SECP384R1:
  ------------------
  |  Branch (871:9): [True: 2.00k, False: 27.3k]
  ------------------
  872|  2.00k|            return 384;
  873|       |
  874|      0|        case SEC_OID_SECG_EC_SECT409K1:
  ------------------
  |  Branch (874:9): [True: 0, False: 29.3k]
  ------------------
  875|      0|        case SEC_OID_SECG_EC_SECT409R1:
  ------------------
  |  Branch (875:9): [True: 0, False: 29.3k]
  ------------------
  876|      0|            return 409;
  877|       |
  878|      0|        case SEC_OID_ANSIX962_EC_C2TNB431R1:
  ------------------
  |  Branch (878:9): [True: 0, False: 29.3k]
  ------------------
  879|      0|            return 431;
  880|       |
  881|     40|        case SEC_OID_SECG_EC_SECP521R1:
  ------------------
  |  Branch (881:9): [True: 40, False: 29.2k]
  ------------------
  882|     40|            return 521;
  883|       |
  884|      0|        case SEC_OID_SECG_EC_SECT571K1:
  ------------------
  |  Branch (884:9): [True: 0, False: 29.3k]
  ------------------
  885|      0|        case SEC_OID_SECG_EC_SECT571R1:
  ------------------
  |  Branch (885:9): [True: 0, False: 29.3k]
  ------------------
  886|      0|            return 571;
  887|       |
  888|      0|        case SEC_OID_X25519:
  ------------------
  |  Branch (888:9): [True: 0, False: 29.3k]
  ------------------
  889|  7.21k|        case SEC_OID_CURVE25519:
  ------------------
  |  Branch (889:9): [True: 7.21k, False: 22.1k]
  ------------------
  890|  7.21k|        case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (890:9): [True: 0, False: 29.3k]
  ------------------
  891|  7.21k|            return 255;
  892|       |
  893|      0|        default:
  ------------------
  |  Branch (893:9): [True: 0, False: 29.3k]
  ------------------
  894|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  895|      0|            return 0;
  896|  29.3k|    }
  897|  29.3k|}
SECKEY_ECParamsToBasePointOrderLen:
  901|  11.7k|{
  902|  11.7k|    SECOidTag tag;
  903|  11.7k|    SECItem oid = { siBuffer, NULL, 0 };
  904|       |
  905|       |    /* The encodedParams data contains 0x06 (SEC_ASN1_OBJECT_ID),
  906|       |     * followed by the length of the curve oid and the curve oid.
  907|       |     */
  908|  11.7k|    oid.len = encodedParams->data[1];
  909|  11.7k|    oid.data = encodedParams->data + 2;
  910|  11.7k|    if ((tag = SECOID_FindOIDTag(&oid)) == SEC_OID_UNKNOWN)
  ------------------
  |  |  117|  11.7k|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
  |  Branch (910:9): [True: 0, False: 11.7k]
  ------------------
  911|      0|        return 0;
  912|       |
  913|  11.7k|    switch (tag) {
  914|      0|        case SEC_OID_SECG_EC_SECP112R1:
  ------------------
  |  Branch (914:9): [True: 0, False: 11.7k]
  ------------------
  915|      0|            return 112;
  916|      0|        case SEC_OID_SECG_EC_SECP112R2:
  ------------------
  |  Branch (916:9): [True: 0, False: 11.7k]
  ------------------
  917|      0|            return 110;
  918|       |
  919|      0|        case SEC_OID_SECG_EC_SECT113R1:
  ------------------
  |  Branch (919:9): [True: 0, False: 11.7k]
  ------------------
  920|      0|        case SEC_OID_SECG_EC_SECT113R2:
  ------------------
  |  Branch (920:9): [True: 0, False: 11.7k]
  ------------------
  921|      0|            return 113;
  922|       |
  923|      0|        case SEC_OID_SECG_EC_SECP128R1:
  ------------------
  |  Branch (923:9): [True: 0, False: 11.7k]
  ------------------
  924|      0|            return 128;
  925|      0|        case SEC_OID_SECG_EC_SECP128R2:
  ------------------
  |  Branch (925:9): [True: 0, False: 11.7k]
  ------------------
  926|      0|            return 126;
  927|       |
  928|      0|        case SEC_OID_SECG_EC_SECT131R1:
  ------------------
  |  Branch (928:9): [True: 0, False: 11.7k]
  ------------------
  929|      0|        case SEC_OID_SECG_EC_SECT131R2:
  ------------------
  |  Branch (929:9): [True: 0, False: 11.7k]
  ------------------
  930|      0|            return 131;
  931|       |
  932|      0|        case SEC_OID_SECG_EC_SECP160K1:
  ------------------
  |  Branch (932:9): [True: 0, False: 11.7k]
  ------------------
  933|      0|        case SEC_OID_SECG_EC_SECP160R1:
  ------------------
  |  Branch (933:9): [True: 0, False: 11.7k]
  ------------------
  934|      0|        case SEC_OID_SECG_EC_SECP160R2:
  ------------------
  |  Branch (934:9): [True: 0, False: 11.7k]
  ------------------
  935|      0|            return 161;
  936|       |
  937|      0|        case SEC_OID_SECG_EC_SECT163K1:
  ------------------
  |  Branch (937:9): [True: 0, False: 11.7k]
  ------------------
  938|      0|            return 163;
  939|      0|        case SEC_OID_SECG_EC_SECT163R1:
  ------------------
  |  Branch (939:9): [True: 0, False: 11.7k]
  ------------------
  940|      0|            return 162;
  941|      0|        case SEC_OID_SECG_EC_SECT163R2:
  ------------------
  |  Branch (941:9): [True: 0, False: 11.7k]
  ------------------
  942|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V1:
  ------------------
  |  Branch (942:9): [True: 0, False: 11.7k]
  ------------------
  943|      0|            return 163;
  944|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V2:
  ------------------
  |  Branch (944:9): [True: 0, False: 11.7k]
  ------------------
  945|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V3:
  ------------------
  |  Branch (945:9): [True: 0, False: 11.7k]
  ------------------
  946|      0|            return 162;
  947|       |
  948|      0|        case SEC_OID_ANSIX962_EC_C2PNB176V1:
  ------------------
  |  Branch (948:9): [True: 0, False: 11.7k]
  ------------------
  949|      0|            return 161;
  950|       |
  951|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V1:
  ------------------
  |  Branch (951:9): [True: 0, False: 11.7k]
  ------------------
  952|      0|            return 191;
  953|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V2:
  ------------------
  |  Branch (953:9): [True: 0, False: 11.7k]
  ------------------
  954|      0|            return 190;
  955|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V3:
  ------------------
  |  Branch (955:9): [True: 0, False: 11.7k]
  ------------------
  956|      0|            return 189;
  957|      0|        case SEC_OID_ANSIX962_EC_C2ONB191V4:
  ------------------
  |  Branch (957:9): [True: 0, False: 11.7k]
  ------------------
  958|      0|            return 191;
  959|      0|        case SEC_OID_ANSIX962_EC_C2ONB191V5:
  ------------------
  |  Branch (959:9): [True: 0, False: 11.7k]
  ------------------
  960|      0|            return 188;
  961|       |
  962|      0|        case SEC_OID_SECG_EC_SECP192K1:
  ------------------
  |  Branch (962:9): [True: 0, False: 11.7k]
  ------------------
  963|      0|        case SEC_OID_ANSIX962_EC_PRIME192V1:
  ------------------
  |  Branch (963:9): [True: 0, False: 11.7k]
  ------------------
  964|      0|        case SEC_OID_ANSIX962_EC_PRIME192V2:
  ------------------
  |  Branch (964:9): [True: 0, False: 11.7k]
  ------------------
  965|      0|        case SEC_OID_ANSIX962_EC_PRIME192V3:
  ------------------
  |  Branch (965:9): [True: 0, False: 11.7k]
  ------------------
  966|      0|            return 192;
  967|       |
  968|      0|        case SEC_OID_SECG_EC_SECT193R1:
  ------------------
  |  Branch (968:9): [True: 0, False: 11.7k]
  ------------------
  969|      0|        case SEC_OID_SECG_EC_SECT193R2:
  ------------------
  |  Branch (969:9): [True: 0, False: 11.7k]
  ------------------
  970|      0|            return 193;
  971|       |
  972|      0|        case SEC_OID_ANSIX962_EC_C2PNB208W1:
  ------------------
  |  Branch (972:9): [True: 0, False: 11.7k]
  ------------------
  973|      0|            return 193;
  974|       |
  975|      0|        case SEC_OID_SECG_EC_SECP224K1:
  ------------------
  |  Branch (975:9): [True: 0, False: 11.7k]
  ------------------
  976|      0|            return 225;
  977|      0|        case SEC_OID_SECG_EC_SECP224R1:
  ------------------
  |  Branch (977:9): [True: 0, False: 11.7k]
  ------------------
  978|      0|            return 224;
  979|       |
  980|      0|        case SEC_OID_SECG_EC_SECT233K1:
  ------------------
  |  Branch (980:9): [True: 0, False: 11.7k]
  ------------------
  981|      0|            return 232;
  982|      0|        case SEC_OID_SECG_EC_SECT233R1:
  ------------------
  |  Branch (982:9): [True: 0, False: 11.7k]
  ------------------
  983|      0|            return 233;
  984|       |
  985|      0|        case SEC_OID_SECG_EC_SECT239K1:
  ------------------
  |  Branch (985:9): [True: 0, False: 11.7k]
  ------------------
  986|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V1:
  ------------------
  |  Branch (986:9): [True: 0, False: 11.7k]
  ------------------
  987|      0|            return 238;
  988|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V2:
  ------------------
  |  Branch (988:9): [True: 0, False: 11.7k]
  ------------------
  989|      0|            return 237;
  990|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V3:
  ------------------
  |  Branch (990:9): [True: 0, False: 11.7k]
  ------------------
  991|      0|            return 236;
  992|      0|        case SEC_OID_ANSIX962_EC_C2ONB239V4:
  ------------------
  |  Branch (992:9): [True: 0, False: 11.7k]
  ------------------
  993|      0|            return 238;
  994|      0|        case SEC_OID_ANSIX962_EC_C2ONB239V5:
  ------------------
  |  Branch (994:9): [True: 0, False: 11.7k]
  ------------------
  995|      0|            return 237;
  996|      0|        case SEC_OID_ANSIX962_EC_PRIME239V1:
  ------------------
  |  Branch (996:9): [True: 0, False: 11.7k]
  ------------------
  997|      0|        case SEC_OID_ANSIX962_EC_PRIME239V2:
  ------------------
  |  Branch (997:9): [True: 0, False: 11.7k]
  ------------------
  998|      0|        case SEC_OID_ANSIX962_EC_PRIME239V3:
  ------------------
  |  Branch (998:9): [True: 0, False: 11.7k]
  ------------------
  999|      0|            return 239;
 1000|       |
 1001|      0|        case SEC_OID_SECG_EC_SECP256K1:
  ------------------
  |  Branch (1001:9): [True: 0, False: 11.7k]
  ------------------
 1002|  11.7k|        case SEC_OID_ANSIX962_EC_PRIME256V1:
  ------------------
  |  Branch (1002:9): [True: 11.7k, False: 0]
  ------------------
 1003|  11.7k|            return 256;
 1004|       |
 1005|      0|        case SEC_OID_ANSIX962_EC_C2PNB272W1:
  ------------------
  |  Branch (1005:9): [True: 0, False: 11.7k]
  ------------------
 1006|      0|            return 257;
 1007|       |
 1008|      0|        case SEC_OID_SECG_EC_SECT283K1:
  ------------------
  |  Branch (1008:9): [True: 0, False: 11.7k]
  ------------------
 1009|      0|            return 281;
 1010|      0|        case SEC_OID_SECG_EC_SECT283R1:
  ------------------
  |  Branch (1010:9): [True: 0, False: 11.7k]
  ------------------
 1011|      0|            return 282;
 1012|       |
 1013|      0|        case SEC_OID_ANSIX962_EC_C2PNB304W1:
  ------------------
  |  Branch (1013:9): [True: 0, False: 11.7k]
  ------------------
 1014|      0|            return 289;
 1015|       |
 1016|      0|        case SEC_OID_ANSIX962_EC_C2TNB359V1:
  ------------------
  |  Branch (1016:9): [True: 0, False: 11.7k]
  ------------------
 1017|      0|            return 353;
 1018|       |
 1019|      0|        case SEC_OID_ANSIX962_EC_C2PNB368W1:
  ------------------
  |  Branch (1019:9): [True: 0, False: 11.7k]
  ------------------
 1020|      0|            return 353;
 1021|       |
 1022|      0|        case SEC_OID_SECG_EC_SECP384R1:
  ------------------
  |  Branch (1022:9): [True: 0, False: 11.7k]
  ------------------
 1023|      0|            return 384;
 1024|       |
 1025|      0|        case SEC_OID_SECG_EC_SECT409K1:
  ------------------
  |  Branch (1025:9): [True: 0, False: 11.7k]
  ------------------
 1026|      0|            return 407;
 1027|      0|        case SEC_OID_SECG_EC_SECT409R1:
  ------------------
  |  Branch (1027:9): [True: 0, False: 11.7k]
  ------------------
 1028|      0|            return 409;
 1029|       |
 1030|      0|        case SEC_OID_ANSIX962_EC_C2TNB431R1:
  ------------------
  |  Branch (1030:9): [True: 0, False: 11.7k]
  ------------------
 1031|      0|            return 418;
 1032|       |
 1033|      0|        case SEC_OID_SECG_EC_SECP521R1:
  ------------------
  |  Branch (1033:9): [True: 0, False: 11.7k]
  ------------------
 1034|      0|            return 521;
 1035|       |
 1036|      0|        case SEC_OID_SECG_EC_SECT571K1:
  ------------------
  |  Branch (1036:9): [True: 0, False: 11.7k]
  ------------------
 1037|      0|        case SEC_OID_SECG_EC_SECT571R1:
  ------------------
  |  Branch (1037:9): [True: 0, False: 11.7k]
  ------------------
 1038|      0|            return 570;
 1039|       |
 1040|      0|        case SEC_OID_X25519:
  ------------------
  |  Branch (1040:9): [True: 0, False: 11.7k]
  ------------------
 1041|      0|        case SEC_OID_CURVE25519:
  ------------------
  |  Branch (1041:9): [True: 0, False: 11.7k]
  ------------------
 1042|      0|        case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (1042:9): [True: 0, False: 11.7k]
  ------------------
 1043|      0|            return 255;
 1044|       |
 1045|      0|        default:
  ------------------
  |  Branch (1045:9): [True: 0, False: 11.7k]
  ------------------
 1046|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1047|      0|            return 0;
 1048|  11.7k|    }
 1049|  11.7k|}
SECKEY_BigIntegerBitLength:
 1054|   159k|{
 1055|   159k|    const unsigned char *p;
 1056|   159k|    unsigned octets;
 1057|   159k|    unsigned bits;
 1058|       |
 1059|   159k|    if (!number || !number->data) {
  ------------------
  |  Branch (1059:9): [True: 0, False: 159k]
  |  Branch (1059:20): [True: 3, False: 159k]
  ------------------
 1060|      3|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
 1061|      3|        return 0;
 1062|      3|    }
 1063|       |
 1064|   159k|    p = number->data;
 1065|   159k|    octets = number->len;
 1066|   166k|    while (octets > 0 && !*p) {
  ------------------
  |  Branch (1066:12): [True: 166k, False: 6]
  |  Branch (1066:26): [True: 6.74k, False: 159k]
  ------------------
 1067|  6.74k|        ++p;
 1068|  6.74k|        --octets;
 1069|  6.74k|    }
 1070|   159k|    if (octets == 0) {
  ------------------
  |  Branch (1070:9): [True: 6, False: 159k]
  ------------------
 1071|      6|        return 0;
 1072|      6|    }
 1073|       |    /* bits = 7..1 because we know at least one bit is set already */
 1074|       |    /* Note: This could do a binary search, but this is faster for keys if we
 1075|       |     * assume that good keys will have the MSB set. */
 1076|   243k|    for (bits = 7; bits > 0; --bits) {
  ------------------
  |  Branch (1076:20): [True: 242k, False: 676]
  ------------------
 1077|   242k|        if (*p & (1 << bits)) {
  ------------------
  |  Branch (1077:13): [True: 159k, False: 83.7k]
  ------------------
 1078|   159k|            break;
 1079|   159k|        }
 1080|   242k|    }
 1081|   159k|    return octets * 8 + bits - 7;
 1082|   159k|}
SECKEY_PublicKeyStrength:
 1087|  2.95k|{
 1088|  2.95k|    return (SECKEY_PublicKeyStrengthInBits(pubk) + 7) / 8;
 1089|  2.95k|}
SECKEY_PublicKeyStrengthInBits:
 1094|  57.2k|{
 1095|  57.2k|    unsigned bitSize = 0;
 1096|       |
 1097|  57.2k|    if (!pubk) {
  ------------------
  |  Branch (1097:9): [True: 0, False: 57.2k]
  ------------------
 1098|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1099|      0|        return 0;
 1100|      0|    }
 1101|       |
 1102|       |    /* interpret modulus length as key strength */
 1103|  57.2k|    switch (pubk->keyType) {
 1104|  11.8k|        case rsaKey:
  ------------------
  |  Branch (1104:9): [True: 11.8k, False: 45.4k]
  ------------------
 1105|  11.8k|            bitSize = SECKEY_BigIntegerBitLength(&pubk->u.rsa.modulus);
 1106|  11.8k|            break;
 1107|      0|        case dsaKey:
  ------------------
  |  Branch (1107:9): [True: 0, False: 57.2k]
  ------------------
 1108|      0|            bitSize = SECKEY_BigIntegerBitLength(&pubk->u.dsa.params.prime);
 1109|      0|            break;
 1110|  27.8k|        case dhKey:
  ------------------
  |  Branch (1110:9): [True: 27.8k, False: 29.4k]
  ------------------
 1111|  27.8k|            bitSize = SECKEY_BigIntegerBitLength(&pubk->u.dh.prime);
 1112|  27.8k|            break;
 1113|  17.5k|        case ecKey:
  ------------------
  |  Branch (1113:9): [True: 17.5k, False: 39.6k]
  ------------------
 1114|  17.5k|        case edKey:
  ------------------
  |  Branch (1114:9): [True: 0, False: 57.2k]
  ------------------
 1115|  17.5k|        case ecMontKey:
  ------------------
  |  Branch (1115:9): [True: 0, False: 57.2k]
  ------------------
 1116|  17.5k|            bitSize = SECKEY_ECParamsToKeySize(&pubk->u.ec.DEREncodedParams);
 1117|  17.5k|            break;
 1118|      0|        default:
  ------------------
  |  Branch (1118:9): [True: 0, False: 57.2k]
  ------------------
 1119|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1120|      0|            break;
 1121|  57.2k|    }
 1122|  57.2k|    return bitSize;
 1123|  57.2k|}
SECKEY_PrivateKeyStrengthInBits:
 1127|  47.3k|{
 1128|  47.3k|    unsigned bitSize = 0;
 1129|  47.3k|    SECItem params = { siBuffer, NULL, 0 };
 1130|  47.3k|    SECStatus rv;
 1131|       |
 1132|  47.3k|    if (!privk) {
  ------------------
  |  Branch (1132:9): [True: 0, False: 47.3k]
  ------------------
 1133|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1134|      0|        return 0;
 1135|      0|    }
 1136|       |
 1137|       |    /* interpret modulus length as key strength */
 1138|  47.3k|    switch (privk->keyType) {
 1139|  35.5k|        case rsaKey:
  ------------------
  |  Branch (1139:9): [True: 35.5k, False: 11.7k]
  ------------------
 1140|  35.5k|        case rsaPssKey:
  ------------------
  |  Branch (1140:9): [True: 0, False: 47.3k]
  ------------------
 1141|  35.5k|        case rsaOaepKey:
  ------------------
  |  Branch (1141:9): [True: 0, False: 47.3k]
  ------------------
 1142|  35.5k|            rv = PK11_ReadAttribute(privk->pkcs11Slot, privk->pkcs11ID,
 1143|  35.5k|                                    CKA_MODULUS, NULL, &params);
  ------------------
  |  |  558|  35.5k|#define CKA_MODULUS 0x00000120UL
  ------------------
 1144|  35.5k|            if ((rv != SECSuccess) || (params.data == NULL)) {
  ------------------
  |  Branch (1144:17): [True: 0, False: 35.5k]
  |  Branch (1144:39): [True: 0, False: 35.5k]
  ------------------
 1145|       |                /* some tokens don't export CKA_MODULUS on the private key,
 1146|       |                 * PK11_SignatureLen works around this if necessary. This
 1147|       |                 * method is less percise because it returns bytes instead
 1148|       |                 * of bits, so we only do it if we can't get the modulus */
 1149|      0|                bitSize = PK11_SignatureLen((SECKEYPrivateKey *)privk) * PR_BITS_PER_BYTE;
  ------------------
  |  |  286|      0|#define PR_BITS_PER_BYTE    8
  ------------------
 1150|      0|                if (bitSize == -1) {
  ------------------
  |  Branch (1150:21): [True: 0, False: 0]
  ------------------
 1151|      0|                    return 0;
 1152|      0|                }
 1153|      0|                return bitSize;
 1154|      0|            }
 1155|  35.5k|            bitSize = SECKEY_BigIntegerBitLength(&params);
 1156|  35.5k|            PORT_Free(params.data);
  ------------------
  |  |   60|  35.5k|#define PORT_Free PORT_Free_Util
  ------------------
 1157|  35.5k|            return bitSize;
 1158|      0|        case dsaKey:
  ------------------
  |  Branch (1158:9): [True: 0, False: 47.3k]
  ------------------
 1159|      0|        case fortezzaKey:
  ------------------
  |  Branch (1159:9): [True: 0, False: 47.3k]
  ------------------
 1160|      0|        case dhKey:
  ------------------
  |  Branch (1160:9): [True: 0, False: 47.3k]
  ------------------
 1161|      0|        case keaKey:
  ------------------
  |  Branch (1161:9): [True: 0, False: 47.3k]
  ------------------
 1162|      0|            rv = PK11_ReadAttribute(privk->pkcs11Slot, privk->pkcs11ID,
 1163|      0|                                    CKA_PRIME, NULL, &params);
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 1164|      0|            if ((rv != SECSuccess) || (params.data == NULL)) {
  ------------------
  |  Branch (1164:17): [True: 0, False: 0]
  |  Branch (1164:39): [True: 0, False: 0]
  ------------------
 1165|      0|                PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1166|      0|                return 0;
 1167|      0|            }
 1168|      0|            bitSize = SECKEY_BigIntegerBitLength(&params);
 1169|      0|            PORT_Free(params.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1170|      0|            return bitSize;
 1171|  11.7k|        case ecKey:
  ------------------
  |  Branch (1171:9): [True: 11.7k, False: 35.5k]
  ------------------
 1172|  11.7k|            rv = PK11_ReadAttribute(privk->pkcs11Slot, privk->pkcs11ID,
 1173|  11.7k|                                    CKA_EC_PARAMS, NULL, &params);
  ------------------
  |  |  602|  11.7k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 1174|  11.7k|            if ((rv != SECSuccess) || (params.data == NULL)) {
  ------------------
  |  Branch (1174:17): [True: 0, False: 11.7k]
  |  Branch (1174:39): [True: 0, False: 11.7k]
  ------------------
 1175|      0|                return 0;
 1176|      0|            }
 1177|  11.7k|            bitSize = SECKEY_ECParamsToKeySize(&params);
 1178|  11.7k|            PORT_Free(params.data);
  ------------------
  |  |   60|  11.7k|#define PORT_Free PORT_Free_Util
  ------------------
 1179|  11.7k|            return bitSize;
 1180|      0|        default:
  ------------------
  |  Branch (1180:9): [True: 0, False: 47.3k]
  ------------------
 1181|      0|            break;
 1182|  47.3k|    }
 1183|      0|    PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1184|      0|    return 0;
 1185|  47.3k|}
SECKEY_CopyPrivateKey:
 1221|      2|{
 1222|      2|    SECKEYPrivateKey *copyk;
 1223|      2|    PLArenaPool *arena;
 1224|       |
 1225|      2|    if (!privk || !privk->pkcs11Slot) {
  ------------------
  |  Branch (1225:9): [True: 0, False: 2]
  |  Branch (1225:19): [True: 0, False: 2]
  ------------------
 1226|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1227|      0|        return NULL;
 1228|      0|    }
 1229|       |
 1230|      2|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|      2|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|      2|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 1231|      2|    if (arena == NULL) {
  ------------------
  |  Branch (1231:9): [True: 0, False: 2]
  ------------------
 1232|      0|        return NULL;
 1233|      0|    }
 1234|       |
 1235|      2|    copyk = (SECKEYPrivateKey *)PORT_ArenaZAlloc(arena, sizeof(SECKEYPrivateKey));
  ------------------
  |  |   59|      2|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 1236|      2|    if (copyk) {
  ------------------
  |  Branch (1236:9): [True: 2, False: 0]
  ------------------
 1237|      2|        copyk->arena = arena;
 1238|      2|        copyk->keyType = privk->keyType;
 1239|       |
 1240|       |        /* copy the PKCS #11 parameters */
 1241|      2|        copyk->pkcs11Slot = PK11_ReferenceSlot(privk->pkcs11Slot);
 1242|       |        /* if the key we're referencing was a temparary key we have just
 1243|       |         * created, that we want to go away when we're through, we need
 1244|       |         * to make a copy of it */
 1245|      2|        if (privk->pkcs11IsTemp) {
  ------------------
  |  Branch (1245:13): [True: 2, False: 0]
  ------------------
 1246|      2|            copyk->pkcs11ID =
 1247|      2|                PK11_CopyKey(privk->pkcs11Slot, privk->pkcs11ID);
 1248|      2|            if (copyk->pkcs11ID == CK_INVALID_HANDLE)
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1248:17): [True: 0, False: 2]
  ------------------
 1249|      0|                goto fail;
 1250|      2|        } else {
 1251|      0|            copyk->pkcs11ID = privk->pkcs11ID;
 1252|      0|        }
 1253|      2|        copyk->pkcs11IsTemp = privk->pkcs11IsTemp;
 1254|      2|        copyk->wincx = privk->wincx;
 1255|      2|        copyk->staticflags = privk->staticflags;
 1256|      2|        return copyk;
 1257|      2|    } else {
 1258|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1259|      0|    }
 1260|       |
 1261|      0|fail:
 1262|      0|    PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1263|      0|    return NULL;
 1264|      2|}
SECKEY_CopyPublicKey:
 1268|  2.95k|{
 1269|  2.95k|    SECKEYPublicKey *copyk;
 1270|  2.95k|    PLArenaPool *arena;
 1271|  2.95k|    SECStatus rv = SECSuccess;
 1272|       |
 1273|  2.95k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  2.95k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  2.95k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 1274|  2.95k|    if (arena == NULL) {
  ------------------
  |  Branch (1274:9): [True: 0, False: 2.95k]
  ------------------
 1275|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1276|      0|        return NULL;
 1277|      0|    }
 1278|       |
 1279|  2.95k|    copyk = (SECKEYPublicKey *)PORT_ArenaZAlloc(arena, sizeof(SECKEYPublicKey));
  ------------------
  |  |   59|  2.95k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 1280|  2.95k|    if (!copyk) {
  ------------------
  |  Branch (1280:9): [True: 0, False: 2.95k]
  ------------------
 1281|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1282|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1283|      0|        return NULL;
 1284|      0|    }
 1285|       |
 1286|  2.95k|    copyk->arena = arena;
 1287|  2.95k|    copyk->keyType = pubk->keyType;
 1288|  2.95k|    if (pubk->pkcs11Slot &&
  ------------------
  |  Branch (1288:9): [True: 0, False: 2.95k]
  ------------------
 1289|  2.95k|        PK11_IsPermObject(pubk->pkcs11Slot, pubk->pkcs11ID)) {
  ------------------
  |  Branch (1289:9): [True: 0, False: 0]
  ------------------
 1290|      0|        copyk->pkcs11Slot = PK11_ReferenceSlot(pubk->pkcs11Slot);
 1291|      0|        copyk->pkcs11ID = pubk->pkcs11ID;
 1292|  2.95k|    } else {
 1293|  2.95k|        copyk->pkcs11Slot = NULL; /* go get own reference */
 1294|  2.95k|        copyk->pkcs11ID = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  2.95k|#define CK_INVALID_HANDLE 0
  ------------------
 1295|  2.95k|    }
 1296|  2.95k|    switch (pubk->keyType) {
 1297|  2.95k|        case rsaKey:
  ------------------
  |  Branch (1297:9): [True: 2.95k, False: 0]
  ------------------
 1298|  2.95k|            rv = SECITEM_CopyItem(arena, &copyk->u.rsa.modulus,
  ------------------
  |  |  106|  2.95k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1299|  2.95k|                                  &pubk->u.rsa.modulus);
 1300|  2.95k|            if (rv == SECSuccess) {
  ------------------
  |  Branch (1300:17): [True: 2.95k, False: 0]
  ------------------
 1301|  2.95k|                rv = SECITEM_CopyItem(arena, &copyk->u.rsa.publicExponent,
  ------------------
  |  |  106|  2.95k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1302|  2.95k|                                      &pubk->u.rsa.publicExponent);
 1303|  2.95k|                if (rv == SECSuccess)
  ------------------
  |  Branch (1303:21): [True: 2.95k, False: 0]
  ------------------
 1304|  2.95k|                    return copyk;
 1305|  2.95k|            }
 1306|      0|            break;
 1307|      0|        case dsaKey:
  ------------------
  |  Branch (1307:9): [True: 0, False: 2.95k]
  ------------------
 1308|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dsa.publicValue,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1309|      0|                                  &pubk->u.dsa.publicValue);
 1310|      0|            if (rv != SECSuccess)
  ------------------
  |  Branch (1310:17): [True: 0, False: 0]
  ------------------
 1311|      0|                break;
 1312|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dsa.params.prime,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1313|      0|                                  &pubk->u.dsa.params.prime);
 1314|      0|            if (rv != SECSuccess)
  ------------------
  |  Branch (1314:17): [True: 0, False: 0]
  ------------------
 1315|      0|                break;
 1316|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dsa.params.subPrime,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1317|      0|                                  &pubk->u.dsa.params.subPrime);
 1318|      0|            if (rv != SECSuccess)
  ------------------
  |  Branch (1318:17): [True: 0, False: 0]
  ------------------
 1319|      0|                break;
 1320|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dsa.params.base,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1321|      0|                                  &pubk->u.dsa.params.base);
 1322|      0|            break;
 1323|      0|        case dhKey:
  ------------------
  |  Branch (1323:9): [True: 0, False: 2.95k]
  ------------------
 1324|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dh.prime, &pubk->u.dh.prime);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1325|      0|            if (rv != SECSuccess)
  ------------------
  |  Branch (1325:17): [True: 0, False: 0]
  ------------------
 1326|      0|                break;
 1327|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dh.base, &pubk->u.dh.base);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1328|      0|            if (rv != SECSuccess)
  ------------------
  |  Branch (1328:17): [True: 0, False: 0]
  ------------------
 1329|      0|                break;
 1330|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.dh.publicValue,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1331|      0|                                  &pubk->u.dh.publicValue);
 1332|      0|            break;
 1333|      0|        case ecKey:
  ------------------
  |  Branch (1333:9): [True: 0, False: 2.95k]
  ------------------
 1334|      0|        case edKey:
  ------------------
  |  Branch (1334:9): [True: 0, False: 2.95k]
  ------------------
 1335|      0|        case ecMontKey:
  ------------------
  |  Branch (1335:9): [True: 0, False: 2.95k]
  ------------------
 1336|      0|            copyk->u.ec.size = pubk->u.ec.size;
 1337|      0|            rv = seckey_HasCurveOID(pubk);
 1338|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1338:17): [True: 0, False: 0]
  ------------------
 1339|      0|                break;
 1340|      0|            }
 1341|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.ec.DEREncodedParams,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1342|      0|                                  &pubk->u.ec.DEREncodedParams);
 1343|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1343:17): [True: 0, False: 0]
  ------------------
 1344|      0|                break;
 1345|      0|            }
 1346|      0|            copyk->u.ec.encoding = ECPoint_Undefined;
 1347|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.ec.publicValue,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1348|      0|                                  &pubk->u.ec.publicValue);
 1349|      0|            break;
 1350|      0|        case nullKey:
  ------------------
  |  Branch (1350:9): [True: 0, False: 2.95k]
  ------------------
 1351|      0|            return copyk;
 1352|      0|        case kyberKey:
  ------------------
  |  Branch (1352:9): [True: 0, False: 2.95k]
  ------------------
 1353|      0|            copyk->u.kyber.params = pubk->u.kyber.params;
 1354|      0|            rv = SECITEM_CopyItem(arena, &copyk->u.kyber.publicValue,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1355|      0|                                  &pubk->u.kyber.publicValue);
 1356|      0|            break;
 1357|      0|        default:
  ------------------
  |  Branch (1357:9): [True: 0, False: 2.95k]
  ------------------
 1358|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1359|      0|            rv = SECFailure;
 1360|      0|            break;
 1361|  2.95k|    }
 1362|      0|    if (rv == SECSuccess)
  ------------------
  |  Branch (1362:9): [True: 0, False: 0]
  ------------------
 1363|      0|        return copyk;
 1364|       |
 1365|      0|    SECKEY_DestroyPublicKey(copyk);
 1366|      0|    return NULL;
 1367|      0|}
SECKEY_EnforceKeySize:
 1375|  50.2k|{
 1376|  50.2k|    PRInt32 opt = -1;
 1377|  50.2k|    PRInt32 optVal;
 1378|  50.2k|    SECStatus rv;
 1379|       |
 1380|  50.2k|    switch (keyType) {
 1381|  38.5k|        case rsaKey:
  ------------------
  |  Branch (1381:9): [True: 38.5k, False: 11.7k]
  ------------------
 1382|  38.5k|        case rsaPssKey:
  ------------------
  |  Branch (1382:9): [True: 0, False: 50.2k]
  ------------------
 1383|  38.5k|        case rsaOaepKey:
  ------------------
  |  Branch (1383:9): [True: 0, False: 50.2k]
  ------------------
 1384|  38.5k|            opt = NSS_RSA_MIN_KEY_SIZE;
  ------------------
  |  |  286|  38.5k|#define NSS_RSA_MIN_KEY_SIZE 0x001
  ------------------
 1385|  38.5k|            break;
 1386|      0|        case dsaKey:
  ------------------
  |  Branch (1386:9): [True: 0, False: 50.2k]
  ------------------
 1387|      0|        case fortezzaKey:
  ------------------
  |  Branch (1387:9): [True: 0, False: 50.2k]
  ------------------
 1388|      0|            opt = NSS_DSA_MIN_KEY_SIZE;
  ------------------
  |  |  288|      0|#define NSS_DSA_MIN_KEY_SIZE 0x004
  ------------------
 1389|      0|            break;
 1390|      0|        case dhKey:
  ------------------
  |  Branch (1390:9): [True: 0, False: 50.2k]
  ------------------
 1391|      0|        case keaKey:
  ------------------
  |  Branch (1391:9): [True: 0, False: 50.2k]
  ------------------
 1392|      0|            opt = NSS_DH_MIN_KEY_SIZE;
  ------------------
  |  |  287|      0|#define NSS_DH_MIN_KEY_SIZE 0x002
  ------------------
 1393|      0|            break;
 1394|  11.7k|        case ecKey:
  ------------------
  |  Branch (1394:9): [True: 11.7k, False: 38.5k]
  ------------------
 1395|  11.7k|            opt = NSS_ECC_MIN_KEY_SIZE;
  ------------------
  |  |  327|  11.7k|#define NSS_ECC_MIN_KEY_SIZE 0x011
  ------------------
 1396|  11.7k|            break;
 1397|      0|        case nullKey:
  ------------------
  |  Branch (1397:9): [True: 0, False: 50.2k]
  ------------------
 1398|      0|        default:
  ------------------
  |  Branch (1398:9): [True: 0, False: 50.2k]
  ------------------
 1399|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1400|      0|            return SECFailure;
 1401|  50.2k|    }
 1402|  50.2k|    PORT_Assert(opt != -1);
  ------------------
  |  |  120|  50.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  50.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 50.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1403|  50.2k|    rv = NSS_OptionGet(opt, &optVal);
 1404|  50.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1404:9): [True: 0, False: 50.2k]
  ------------------
 1405|      0|        return rv;
 1406|      0|    }
 1407|  50.2k|    if (optVal > keyLength) {
  ------------------
  |  Branch (1407:9): [True: 6, False: 50.2k]
  ------------------
 1408|      6|        PORT_SetError(error);
  ------------------
  |  |   65|      6|#define PORT_SetError PORT_SetError_Util
  ------------------
 1409|      6|        return SECFailure;
 1410|      6|    }
 1411|  50.2k|    return SECSuccess;
 1412|  50.2k|}
SECKEY_DestroyPrivateKeyInfo:
 1955|      2|{
 1956|      2|    PLArenaPool *poolp;
 1957|       |
 1958|      2|    if (pvk != NULL) {
  ------------------
  |  Branch (1958:9): [True: 2, False: 0]
  ------------------
 1959|      2|        if (pvk->arena) {
  ------------------
  |  Branch (1959:13): [True: 2, False: 0]
  ------------------
 1960|      2|            poolp = pvk->arena;
 1961|       |            /* zero structure since PORT_FreeArena does not support
 1962|       |             * this yet.
 1963|       |             */
 1964|      2|            PORT_Memset(pvk->privateKey.data, 0, pvk->privateKey.len);
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 1965|      2|            PORT_Memset(pvk, 0, sizeof(*pvk));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 1966|      2|            if (freeit == PR_TRUE) {
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  |  Branch (1966:17): [True: 2, False: 0]
  ------------------
 1967|      2|                PORT_FreeArena(poolp, PR_TRUE);
  ------------------
  |  |   61|      2|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(poolp, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1968|      2|            } else {
 1969|      0|                pvk->arena = poolp;
 1970|      0|            }
 1971|      2|        } else {
 1972|      0|            SECITEM_ZfreeItem(&pvk->version, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&pvk->version, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1973|      0|            SECITEM_ZfreeItem(&pvk->privateKey, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&pvk->privateKey, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1974|      0|            SECOID_DestroyAlgorithmID(&pvk->algorithm, PR_FALSE);
  ------------------
  |  |  114|      0|#define SECOID_DestroyAlgorithmID SECOID_DestroyAlgorithmID_Util
  ------------------
                          SECOID_DestroyAlgorithmID(&pvk->algorithm, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1975|      0|            PORT_Memset(pvk, 0, sizeof(*pvk));
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 1976|      0|            if (freeit == PR_TRUE) {
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  |  Branch (1976:17): [True: 0, False: 0]
  ------------------
 1977|      0|                PORT_Free(pvk);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1978|      0|            }
 1979|      0|        }
 1980|      2|    }
 1981|      2|}
SECKEY_GetPrivateKeyType:
 2059|  47.3k|{
 2060|  47.3k|    return privKey->keyType;
 2061|  47.3k|}
SECKEY_GetPublicKeyType:
 2065|  44.9k|{
 2066|  44.9k|    return pubKey->keyType;
 2067|  44.9k|}
SECKEY_CacheStaticFlags:
 2289|      2|{
 2290|      2|    SECStatus rv = SECFailure;
 2291|      2|    if (key && key->pkcs11Slot && key->pkcs11ID) {
  ------------------
  |  Branch (2291:9): [True: 2, False: 0]
  |  Branch (2291:16): [True: 2, False: 0]
  |  Branch (2291:35): [True: 2, False: 0]
  ------------------
 2292|      2|        key->staticflags |= SECKEY_Attributes_Cached;
  ------------------
  |  |  212|      2|#define SECKEY_Attributes_Cached 0x1 /* bit 0 states \
  ------------------
 2293|      2|        SECKEY_CacheAttribute(key, CKA_PRIVATE);
  ------------------
  |  | 2281|      2|    if (CK_TRUE == PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)) { \
  |  |  ------------------
  |  |  |  |   22|      2|#define CK_TRUE 1
  |  |  ------------------
  |  |                   if (CK_TRUE == PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)) { \
  |  |  ------------------
  |  |  |  |  438|      2|#define PR_FALSE 0
  |  |  ------------------
  |  |  |  Branch (2281:9): [True: 0, False: 2]
  |  |  ------------------
  |  | 2282|      0|        key->staticflags |= SECKEY_##attribute;                                                 \
  |  | 2283|      2|    } else {                                                                                    \
  |  | 2284|      2|        key->staticflags &= (~SECKEY_##attribute);                                              \
  |  | 2285|      2|    }
  ------------------
 2294|      2|        SECKEY_CacheAttribute(key, CKA_ALWAYS_AUTHENTICATE);
  ------------------
  |  | 2281|      2|    if (CK_TRUE == PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)) { \
  |  |  ------------------
  |  |  |  |   22|      2|#define CK_TRUE 1
  |  |  ------------------
  |  |                   if (CK_TRUE == PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)) { \
  |  |  ------------------
  |  |  |  |  438|      2|#define PR_FALSE 0
  |  |  ------------------
  |  |  |  Branch (2281:9): [True: 0, False: 2]
  |  |  ------------------
  |  | 2282|      0|        key->staticflags |= SECKEY_##attribute;                                                 \
  |  | 2283|      2|    } else {                                                                                    \
  |  | 2284|      2|        key->staticflags &= (~SECKEY_##attribute);                                              \
  |  | 2285|      2|    }
  ------------------
 2295|      2|        rv = SECSuccess;
 2296|      2|    }
 2297|      2|    return rv;
 2298|      2|}
seckey.c:seckey_UpdateCertPQGChain:
  334|  3.83k|{
  335|  3.83k|    SECStatus rv;
  336|  3.83k|    SECOidData *oid = NULL;
  337|  3.83k|    int tag;
  338|  3.83k|    CERTSubjectPublicKeyInfo *subjectSpki = NULL;
  339|  3.83k|    CERTSubjectPublicKeyInfo *issuerSpki = NULL;
  340|  3.83k|    CERTCertificate *issuerCert = NULL;
  341|       |
  342|       |    /* increment cert chain length counter*/
  343|  3.83k|    count++;
  344|       |
  345|       |    /* check if cert chain length exceeds the maximum length*/
  346|  3.83k|    if (count > CERT_MAX_CERT_CHAIN) {
  ------------------
  |  |  610|  3.83k|#define CERT_MAX_CERT_CHAIN 20
  ------------------
  |  Branch (346:9): [True: 0, False: 3.83k]
  ------------------
  347|      0|        return SECFailure;
  348|      0|    }
  349|       |
  350|  3.83k|    oid = SECOID_FindOID(&subjectCert->subjectPublicKeyInfo.algorithm.algorithm);
  ------------------
  |  |  115|  3.83k|#define SECOID_FindOID SECOID_FindOID_Util
  ------------------
  351|  3.83k|    if (oid != NULL) {
  ------------------
  |  Branch (351:9): [True: 3.41k, False: 416]
  ------------------
  352|  3.41k|        tag = oid->offset;
  353|       |
  354|       |        /* Check if cert has a DSA or EC public key. If not, return
  355|       |         * success since no PQG params need to be updated.
  356|       |         *
  357|       |         * Question: do we really need to do this for EC keys. They don't have
  358|       |         * PQG parameters, but they do have parameters. The question is does
  359|       |         * the child cert inherit those parameters for EC from the parent, or
  360|       |         * do we always include those parameters in each cert.
  361|       |         */
  362|       |
  363|  3.41k|        if ((tag != SEC_OID_ANSIX9_DSA_SIGNATURE) &&
  ------------------
  |  Branch (363:13): [True: 3.41k, False: 1]
  ------------------
  364|  3.41k|            (tag != SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST) &&
  ------------------
  |  Branch (364:13): [True: 3.41k, False: 1]
  ------------------
  365|  3.41k|            (tag != SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA224_DIGEST) &&
  ------------------
  |  Branch (365:13): [True: 3.41k, False: 0]
  ------------------
  366|  3.41k|            (tag != SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA256_DIGEST) &&
  ------------------
  |  Branch (366:13): [True: 3.41k, False: 0]
  ------------------
  367|  3.41k|            (tag != SEC_OID_BOGUS_DSA_SIGNATURE_WITH_SHA1_DIGEST) &&
  ------------------
  |  Branch (367:13): [True: 3.41k, False: 0]
  ------------------
  368|  3.41k|            (tag != SEC_OID_SDN702_DSA_SIGNATURE) &&
  ------------------
  |  Branch (368:13): [True: 3.41k, False: 0]
  ------------------
  369|  3.41k|            (tag != SEC_OID_ED25519_PUBLIC_KEY) &&
  ------------------
  |  Branch (369:13): [True: 3.41k, False: 0]
  ------------------
  370|  3.41k|            (tag != SEC_OID_ANSIX962_EC_PUBLIC_KEY)) {
  ------------------
  |  Branch (370:13): [True: 3.22k, False: 186]
  ------------------
  371|       |
  372|  3.22k|            return SECSuccess;
  373|  3.22k|        }
  374|  3.41k|    } else {
  375|    416|        return SECFailure; /* return failure if oid is NULL */
  376|    416|    }
  377|       |
  378|       |    /* if cert has PQG parameters, return success */
  379|       |
  380|    188|    subjectSpki = &subjectCert->subjectPublicKeyInfo;
  381|       |
  382|    188|    if (subjectSpki->algorithm.parameters.len != 0) {
  ------------------
  |  Branch (382:9): [True: 188, False: 0]
  ------------------
  383|    188|        return SECSuccess;
  384|    188|    }
  385|       |
  386|       |    /* check if the cert is self-signed */
  387|      0|    if (subjectCert->isRoot) {
  ------------------
  |  Branch (387:9): [True: 0, False: 0]
  ------------------
  388|       |        /* fail since cert is self-signed and has no pqg params. */
  389|      0|        return SECFailure;
  390|      0|    }
  391|       |
  392|       |    /* get issuer cert */
  393|      0|    issuerCert = CERT_FindCertIssuer(subjectCert, PR_Now(), certUsageAnyCA);
  394|      0|    if (!issuerCert) {
  ------------------
  |  Branch (394:9): [True: 0, False: 0]
  ------------------
  395|      0|        return SECFailure;
  396|      0|    }
  397|       |
  398|       |    /* if parent is not DSA, return failure since
  399|       |       we don't allow this case. */
  400|       |
  401|      0|    oid = SECOID_FindOID(&issuerCert->subjectPublicKeyInfo.algorithm.algorithm);
  ------------------
  |  |  115|      0|#define SECOID_FindOID SECOID_FindOID_Util
  ------------------
  402|      0|    if (oid != NULL) {
  ------------------
  |  Branch (402:9): [True: 0, False: 0]
  ------------------
  403|      0|        tag = oid->offset;
  404|       |
  405|       |        /* Check if issuer cert has a DSA public key. If not,
  406|       |         * return failure.   */
  407|       |
  408|      0|        if ((tag != SEC_OID_ANSIX9_DSA_SIGNATURE) &&
  ------------------
  |  Branch (408:13): [True: 0, False: 0]
  ------------------
  409|      0|            (tag != SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST) &&
  ------------------
  |  Branch (409:13): [True: 0, False: 0]
  ------------------
  410|      0|            (tag != SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA224_DIGEST) &&
  ------------------
  |  Branch (410:13): [True: 0, False: 0]
  ------------------
  411|      0|            (tag != SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA256_DIGEST) &&
  ------------------
  |  Branch (411:13): [True: 0, False: 0]
  ------------------
  412|      0|            (tag != SEC_OID_BOGUS_DSA_SIGNATURE_WITH_SHA1_DIGEST) &&
  ------------------
  |  Branch (412:13): [True: 0, False: 0]
  ------------------
  413|      0|            (tag != SEC_OID_SDN702_DSA_SIGNATURE) &&
  ------------------
  |  Branch (413:13): [True: 0, False: 0]
  ------------------
  414|      0|            (tag != SEC_OID_ED25519_PUBLIC_KEY) &&
  ------------------
  |  Branch (414:13): [True: 0, False: 0]
  ------------------
  415|      0|            (tag != SEC_OID_ANSIX962_EC_PUBLIC_KEY)) {
  ------------------
  |  Branch (415:13): [True: 0, False: 0]
  ------------------
  416|      0|            rv = SECFailure;
  417|      0|            goto loser;
  418|      0|        }
  419|      0|    } else {
  420|      0|        rv = SECFailure; /* return failure if oid is NULL */
  421|      0|        goto loser;
  422|      0|    }
  423|       |
  424|       |    /* at this point the subject cert has no pqg parameters and the
  425|       |     * issuer cert has a DSA public key.  Update the issuer's
  426|       |     * pqg parameters with a recursive call to this same function. */
  427|       |
  428|      0|    rv = seckey_UpdateCertPQGChain(issuerCert, count);
  429|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (429:9): [True: 0, False: 0]
  ------------------
  430|      0|        rv = SECFailure;
  431|      0|        goto loser;
  432|      0|    }
  433|       |
  434|       |    /* ensure issuer has pqg parameters */
  435|       |
  436|      0|    issuerSpki = &issuerCert->subjectPublicKeyInfo;
  437|      0|    if (issuerSpki->algorithm.parameters.len == 0) {
  ------------------
  |  Branch (437:9): [True: 0, False: 0]
  ------------------
  438|      0|        rv = SECFailure;
  439|      0|    }
  440|       |
  441|       |    /* if update was successful and pqg params present, then copy the
  442|       |     * parameters to the subject cert's key. */
  443|       |
  444|      0|    if (rv == SECSuccess) {
  ------------------
  |  Branch (444:9): [True: 0, False: 0]
  ------------------
  445|      0|        rv = SECITEM_CopyItem(subjectCert->arena,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  446|      0|                              &subjectSpki->algorithm.parameters,
  447|      0|                              &issuerSpki->algorithm.parameters);
  448|      0|    }
  449|       |
  450|      0|loser:
  451|      0|    if (issuerCert) {
  ------------------
  |  Branch (451:9): [True: 0, False: 0]
  ------------------
  452|      0|        CERT_DestroyCertificate(issuerCert);
  453|      0|    }
  454|      0|    return rv;
  455|      0|}
seckey.c:seckey_ExtractPublicKey:
  598|  4.27k|{
  599|  4.27k|    SECKEYPublicKey *pubk;
  600|  4.27k|    SECItem os, newOs, newParms;
  601|  4.27k|    SECStatus rv;
  602|  4.27k|    PLArenaPool *arena;
  603|  4.27k|    SECOidTag tag;
  604|       |
  605|  4.27k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  4.27k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  4.27k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  606|  4.27k|    if (arena == NULL)
  ------------------
  |  Branch (606:9): [True: 0, False: 4.27k]
  ------------------
  607|      0|        return NULL;
  608|       |
  609|  4.27k|    pubk = (SECKEYPublicKey *)PORT_ArenaZAlloc(arena, sizeof(SECKEYPublicKey));
  ------------------
  |  |   59|  4.27k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  610|  4.27k|    if (pubk == NULL) {
  ------------------
  |  Branch (610:9): [True: 0, False: 4.27k]
  ------------------
  611|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  612|      0|        return NULL;
  613|      0|    }
  614|       |
  615|  4.27k|    pubk->arena = arena;
  616|  4.27k|    pubk->pkcs11Slot = 0;
  617|  4.27k|    pubk->pkcs11ID = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  4.27k|#define CK_INVALID_HANDLE 0
  ------------------
  618|       |
  619|       |    /* Convert bit string length from bits to bytes */
  620|  4.27k|    os = spki->subjectPublicKey;
  621|  4.27k|    DER_ConvertBitString(&os);
  ------------------
  |  |  125|  4.27k|    {                                         \
  |  |  126|  4.27k|        (item)->len = ((item)->len + 7) >> 3; \
  |  |  127|  4.27k|    }
  ------------------
  622|       |
  623|  4.27k|    tag = SECOID_GetAlgorithmTag(&spki->algorithm);
  ------------------
  |  |  119|  4.27k|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
  624|       |
  625|       |    /* copy the DER into the arena, since Quick DER returns data that points
  626|       |       into the DER input, which may get freed by the caller */
  627|  4.27k|    rv = SECITEM_CopyItem(arena, &newOs, &os);
  ------------------
  |  |  106|  4.27k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  628|  4.27k|    if (rv == SECSuccess)
  ------------------
  |  Branch (628:9): [True: 4.27k, False: 0]
  ------------------
  629|  4.27k|        switch (tag) {
  630|      0|            case SEC_OID_X500_RSA_ENCRYPTION:
  ------------------
  |  Branch (630:13): [True: 0, False: 4.27k]
  ------------------
  631|  3.02k|            case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (631:13): [True: 3.02k, False: 1.25k]
  ------------------
  632|  3.02k|            case SEC_OID_PKCS1_RSA_PSS_SIGNATURE:
  ------------------
  |  Branch (632:13): [True: 1, False: 4.27k]
  ------------------
  633|  3.02k|                pubk->keyType = rsaKey;
  634|  3.02k|                prepare_rsa_pub_key_for_asn1(pubk);
  635|  3.02k|                rv = SEC_QuickDERDecodeItem(arena, pubk, SECKEY_RSAPublicKeyTemplate, &newOs);
  ------------------
  |  |  102|  3.02k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  636|  3.02k|                if (rv == SECSuccess)
  ------------------
  |  Branch (636:21): [True: 3.01k, False: 2]
  ------------------
  637|  3.01k|                    return pubk;
  638|      2|                break;
  639|      2|            case SEC_OID_ANSIX9_DSA_SIGNATURE:
  ------------------
  |  Branch (639:13): [True: 0, False: 4.27k]
  ------------------
  640|      0|            case SEC_OID_SDN702_DSA_SIGNATURE:
  ------------------
  |  Branch (640:13): [True: 0, False: 4.27k]
  ------------------
  641|      0|                pubk->keyType = dsaKey;
  642|      0|                prepare_dsa_pub_key_for_asn1(pubk);
  643|      0|                rv = SEC_QuickDERDecodeItem(arena, pubk, SECKEY_DSAPublicKeyTemplate, &newOs);
  ------------------
  |  |  102|      0|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  644|      0|                if (rv != SECSuccess)
  ------------------
  |  Branch (644:21): [True: 0, False: 0]
  ------------------
  645|      0|                    break;
  646|       |
  647|      0|                rv = seckey_DSADecodePQG(arena, pubk,
  648|      0|                                         &spki->algorithm.parameters);
  649|       |
  650|      0|                if (rv == SECSuccess)
  ------------------
  |  Branch (650:21): [True: 0, False: 0]
  ------------------
  651|      0|                    return pubk;
  652|      0|                break;
  653|      0|            case SEC_OID_X942_DIFFIE_HELMAN_KEY:
  ------------------
  |  Branch (653:13): [True: 0, False: 4.27k]
  ------------------
  654|      0|                pubk->keyType = dhKey;
  655|      0|                prepare_dh_pub_key_for_asn1(pubk);
  656|      0|                rv = SEC_QuickDERDecodeItem(arena, pubk, SECKEY_DHPublicKeyTemplate, &newOs);
  ------------------
  |  |  102|      0|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  657|      0|                if (rv != SECSuccess)
  ------------------
  |  Branch (657:21): [True: 0, False: 0]
  ------------------
  658|      0|                    break;
  659|       |
  660|       |                /* copy the DER into the arena, since Quick DER returns data that points
  661|       |                   into the DER input, which may get freed by the caller */
  662|      0|                rv = SECITEM_CopyItem(arena, &newParms, &spki->algorithm.parameters);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  663|      0|                if (rv != SECSuccess)
  ------------------
  |  Branch (663:21): [True: 0, False: 0]
  ------------------
  664|      0|                    break;
  665|       |
  666|      0|                rv = SEC_QuickDERDecodeItem(arena, pubk, SECKEY_DHParamKeyTemplate,
  ------------------
  |  |  102|      0|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  667|      0|                                            &newParms);
  668|       |
  669|      0|                if (rv == SECSuccess)
  ------------------
  |  Branch (669:21): [True: 0, False: 0]
  ------------------
  670|      0|                    return pubk;
  671|      0|                break;
  672|      0|            case SEC_OID_X25519:
  ------------------
  |  Branch (672:13): [True: 0, False: 4.27k]
  ------------------
  673|      0|            case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (673:13): [True: 0, False: 4.27k]
  ------------------
  674|       |                /* A basic consistency check on inputs. */
  675|      0|                if (newOs.len == 0) {
  ------------------
  |  Branch (675:21): [True: 0, False: 0]
  ------------------
  676|      0|                    PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  677|      0|                    break;
  678|      0|                }
  679|       |
  680|       |                /* Currently supporting only (Pure)Ed25519 .*/
  681|      0|                if (spki->algorithm.parameters.len != 0) {
  ------------------
  |  Branch (681:21): [True: 0, False: 0]
  ------------------
  682|      0|                    PORT_SetError(SEC_ERROR_UNSUPPORTED_KEYALG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  683|      0|                    break;
  684|      0|                }
  685|       |
  686|       |                /* edKey corresponds to Ed25519 mechanism.
  687|       |                 * ecMontKey corresponds to X25519 mechanism.
  688|       |                 * The other options are not supported. */
  689|      0|                if (tag == SEC_OID_X25519) {
  ------------------
  |  Branch (689:21): [True: 0, False: 0]
  ------------------
  690|      0|                    pubk->keyType = ecMontKey;
  691|      0|                } else {
  692|       |                    /* tag == SEC_OID_ED25519_PUBLIC_KEY */
  693|      0|                    pubk->keyType = edKey;
  694|      0|                }
  695|       |
  696|      0|                pubk->u.ec.size = 0;
  697|       |
  698|      0|                SECOidData *oid25519 = SECOID_FindOIDByTag(tag);
  ------------------
  |  |  116|      0|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
  699|      0|                if (!oid25519) {
  ------------------
  |  Branch (699:21): [True: 0, False: 0]
  ------------------
  700|      0|                    break;
  701|      0|                }
  702|       |
  703|      0|                if (!SECITEM_AllocItem(arena, &pubk->u.ec.DEREncodedParams, oid25519->oid.len + 2)) {
  ------------------
  |  |  103|      0|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (703:21): [True: 0, False: 0]
  ------------------
  704|      0|                    break;
  705|      0|                }
  706|      0|                pubk->u.ec.DEREncodedParams.data[0] = SEC_ASN1_OBJECT_ID;
  ------------------
  |  |   82|      0|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
  707|      0|                pubk->u.ec.DEREncodedParams.data[1] = oid25519->oid.len;
  708|      0|                PORT_Memcpy(pubk->u.ec.DEREncodedParams.data + 2, oid25519->oid.data, oid25519->oid.len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  709|       |
  710|      0|                rv = SECITEM_CopyItem(arena, &pubk->u.ec.publicValue, &newOs);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  711|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (711:21): [True: 0, False: 0]
  ------------------
  712|      0|                    break;
  713|      0|                }
  714|      0|                return pubk;
  715|  1.24k|            case SEC_OID_ANSIX962_EC_PUBLIC_KEY:
  ------------------
  |  Branch (715:13): [True: 1.24k, False: 3.02k]
  ------------------
  716|       |                /* A basic sanity check on inputs. */
  717|  1.24k|                if (spki->algorithm.parameters.len == 0 || newOs.len == 0) {
  ------------------
  |  Branch (717:21): [True: 0, False: 1.24k]
  |  Branch (717:60): [True: 0, False: 1.24k]
  ------------------
  718|      0|                    PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  719|      0|                    break;
  720|      0|                }
  721|  1.24k|                pubk->keyType = ecKey;
  722|  1.24k|                pubk->u.ec.size = 0;
  723|       |
  724|       |                /* Since PKCS#11 directly takes the DER encoding of EC params
  725|       |                 * and public value, we don't need any decoding here.
  726|       |                 */
  727|  1.24k|                rv = SECITEM_CopyItem(arena, &pubk->u.ec.DEREncodedParams,
  ------------------
  |  |  106|  1.24k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  728|  1.24k|                                      &spki->algorithm.parameters);
  729|  1.24k|                if (rv != SECSuccess) {
  ------------------
  |  Branch (729:21): [True: 0, False: 1.24k]
  ------------------
  730|      0|                    break;
  731|      0|                }
  732|  1.24k|                rv = SECITEM_CopyItem(arena, &pubk->u.ec.publicValue, &newOs);
  ------------------
  |  |  106|  1.24k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  733|  1.24k|                if (rv != SECSuccess) {
  ------------------
  |  Branch (733:21): [True: 0, False: 1.24k]
  ------------------
  734|      0|                    break;
  735|      0|                }
  736|  1.24k|                pubk->u.ec.encoding = ECPoint_Undefined;
  737|  1.24k|                rv = seckey_HasCurveOID(pubk);
  738|  1.24k|                if (rv == SECSuccess) {
  ------------------
  |  Branch (738:21): [True: 1.24k, False: 0]
  ------------------
  739|  1.24k|                    return pubk;
  740|  1.24k|                }
  741|      0|                break;
  742|       |
  743|      2|            default:
  ------------------
  |  Branch (743:13): [True: 2, False: 4.27k]
  ------------------
  744|      2|                PORT_SetError(SEC_ERROR_UNSUPPORTED_KEYALG);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  745|      2|                break;
  746|  4.27k|        }
  747|       |
  748|      4|    SECKEY_DestroyPublicKey(pubk);
  749|      4|    return NULL;
  750|  4.27k|}
seckey.c:seckey_HasCurveOID:
  582|  1.24k|{
  583|  1.24k|    SECItem oid;
  584|  1.24k|    SECStatus rv;
  585|  1.24k|    PORTCheapArenaPool tmpArena;
  586|       |
  587|  1.24k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  1.24k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  588|       |    /* If we can decode it, an OID is available. */
  589|  1.24k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &oid,
  ------------------
  |  |  102|  1.24k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  590|  1.24k|                                SEC_ASN1_GET(SEC_ObjectIDTemplate),
  ------------------
  |  |  188|  1.24k|#define SEC_ASN1_GET(x) x
  ------------------
  591|  1.24k|                                &pubKey->u.ec.DEREncodedParams);
  592|  1.24k|    PORT_DestroyCheapArena(&tmpArena);
  593|  1.24k|    return rv;
  594|  1.24k|}
seckey.c:prepare_rsa_pub_key_for_asn1:
  116|  3.02k|{
  117|  3.02k|    pubk->u.rsa.modulus.type = siUnsignedInteger;
  118|  3.02k|    pubk->u.rsa.publicExponent.type = siUnsignedInteger;
  119|  3.02k|}

SGN_Digest:
  575|  38.3k|{
  576|  38.3k|    int modulusLen;
  577|  38.3k|    SECStatus rv;
  578|  38.3k|    SECItem digder;
  579|  38.3k|    PLArenaPool *arena = 0;
  580|  38.3k|    SGNDigestInfo *di = 0;
  581|  38.3k|    SECOidTag enctag;
  582|  38.3k|    PRUint32 policyFlags;
  583|  38.3k|    PRInt32 optFlags;
  584|       |
  585|  38.3k|    result->data = 0;
  586|       |
  587|  38.3k|    if (NSS_OptionGet(NSS_KEY_SIZE_POLICY_FLAGS, &optFlags) != SECFailure) {
  ------------------
  |  |  317|  38.3k|#define NSS_KEY_SIZE_POLICY_FLAGS 0x00e
  ------------------
  |  Branch (587:9): [True: 38.3k, False: 0]
  ------------------
  588|  38.3k|        if (optFlags & NSS_KEY_SIZE_POLICY_SIGN_FLAG) {
  ------------------
  |  |  323|  38.3k|#define NSS_KEY_SIZE_POLICY_SIGN_FLAG 4
  ------------------
  |  Branch (588:13): [True: 38.3k, False: 0]
  ------------------
  589|  38.3k|            rv = SECKEY_EnforceKeySize(privKey->keyType,
  590|  38.3k|                                       SECKEY_PrivateKeyStrengthInBits(privKey),
  591|  38.3k|                                       SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
  592|  38.3k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (592:17): [True: 0, False: 38.3k]
  ------------------
  593|      0|                return SECFailure;
  594|      0|            }
  595|  38.3k|        }
  596|  38.3k|    }
  597|       |    /* check the policy on the hash algorithm */
  598|  38.3k|    if ((NSS_GetAlgorithmPolicy(algtag, &policyFlags) == SECFailure) ||
  ------------------
  |  Branch (598:9): [True: 0, False: 38.3k]
  ------------------
  599|  38.3k|        !(policyFlags & NSS_USE_ALG_IN_ANY_SIGNATURE)) {
  ------------------
  |  |  575|  38.3k|#define NSS_USE_ALG_IN_ANY_SIGNATURE 0x00000020    /* used in any signature */
  ------------------
  |  Branch (599:9): [True: 0, False: 38.3k]
  ------------------
  600|      0|        PORT_SetError(SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  601|      0|        return SECFailure;
  602|      0|    }
  603|       |    /* check the policy on the encryption algorithm */
  604|  38.3k|    enctag = sec_GetEncAlgFromSigAlg(
  605|  38.3k|        SEC_GetSignatureAlgorithmOidTag(privKey->keyType, algtag));
  606|  38.3k|    if ((enctag == SEC_OID_UNKNOWN) ||
  ------------------
  |  Branch (606:9): [True: 0, False: 38.3k]
  ------------------
  607|  38.3k|        (NSS_GetAlgorithmPolicy(enctag, &policyFlags) == SECFailure) ||
  ------------------
  |  Branch (607:9): [True: 0, False: 38.3k]
  ------------------
  608|  38.3k|        !(policyFlags & NSS_USE_ALG_IN_ANY_SIGNATURE)) {
  ------------------
  |  |  575|  38.3k|#define NSS_USE_ALG_IN_ANY_SIGNATURE 0x00000020    /* used in any signature */
  ------------------
  |  Branch (608:9): [True: 0, False: 38.3k]
  ------------------
  609|      0|        PORT_SetError(SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  610|      0|        return SECFailure;
  611|      0|    }
  612|       |
  613|  38.3k|    if (privKey->keyType == rsaKey) {
  ------------------
  |  Branch (613:9): [True: 27.4k, False: 10.8k]
  ------------------
  614|       |
  615|  27.4k|        arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  27.4k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                      arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  27.4k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  616|  27.4k|        if (!arena) {
  ------------------
  |  Branch (616:13): [True: 0, False: 27.4k]
  ------------------
  617|      0|            rv = SECFailure;
  618|      0|            goto loser;
  619|      0|        }
  620|       |
  621|       |        /* Construct digest info */
  622|  27.4k|        di = SGN_CreateDigestInfo(algtag, digest->data, digest->len);
  ------------------
  |  |  123|  27.4k|#define SGN_CreateDigestInfo SGN_CreateDigestInfo_Util
  ------------------
  623|  27.4k|        if (!di) {
  ------------------
  |  Branch (623:13): [True: 0, False: 27.4k]
  ------------------
  624|      0|            rv = SECFailure;
  625|      0|            goto loser;
  626|      0|        }
  627|       |
  628|       |        /* Der encode the digest as a DigestInfo */
  629|  27.4k|        rv = DER_Encode(arena, &digder, SGNDigestInfoTemplate,
  ------------------
  |  |   23|  27.4k|#define DER_Encode DER_Encode_Util
  ------------------
  630|  27.4k|                        di);
  631|  27.4k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (631:13): [True: 0, False: 27.4k]
  ------------------
  632|      0|            goto loser;
  633|      0|        }
  634|  27.4k|    } else {
  635|  10.8k|        digder.data = digest->data;
  636|  10.8k|        digder.len = digest->len;
  637|  10.8k|    }
  638|       |
  639|       |    /*
  640|       |    ** Encrypt signature after constructing appropriate PKCS#1 signature
  641|       |    ** block
  642|       |    */
  643|  38.3k|    modulusLen = PK11_SignatureLen(privKey);
  644|  38.3k|    if (modulusLen <= 0) {
  ------------------
  |  Branch (644:9): [True: 0, False: 38.3k]
  ------------------
  645|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  646|      0|        rv = SECFailure;
  647|      0|        goto loser;
  648|      0|    }
  649|  38.3k|    result->len = modulusLen;
  650|  38.3k|    result->data = (unsigned char *)PORT_Alloc(modulusLen);
  ------------------
  |  |   52|  38.3k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  651|  38.3k|    result->type = siBuffer;
  652|       |
  653|  38.3k|    if (result->data == NULL) {
  ------------------
  |  Branch (653:9): [True: 0, False: 38.3k]
  ------------------
  654|      0|        rv = SECFailure;
  655|      0|        goto loser;
  656|      0|    }
  657|       |
  658|  38.3k|    rv = PK11_Sign(privKey, result, &digder);
  659|  38.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (659:9): [True: 0, False: 38.3k]
  ------------------
  660|      0|        PORT_Free(result->data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  661|      0|        result->data = NULL;
  662|      0|    }
  663|       |
  664|  38.3k|loser:
  665|  38.3k|    SGN_DestroyDigestInfo(di);
  ------------------
  |  |  124|  38.3k|#define SGN_DestroyDigestInfo SGN_DestroyDigestInfo_Util
  ------------------
  666|  38.3k|    if (arena != NULL) {
  ------------------
  |  Branch (666:9): [True: 27.4k, False: 10.8k]
  ------------------
  667|  27.4k|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|  27.4k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|  27.4k|#define PR_FALSE 0
  ------------------
  668|  27.4k|    }
  669|  38.3k|    return rv;
  670|  38.3k|}
SEC_GetSignatureAlgorithmOidTag:
  674|  38.3k|{
  675|  38.3k|    SECOidTag sigTag = SEC_OID_UNKNOWN;
  676|       |
  677|  38.3k|    switch (keyType) {
  678|  27.4k|        case rsaKey:
  ------------------
  |  Branch (678:9): [True: 27.4k, False: 10.8k]
  ------------------
  679|  27.4k|            switch (hashAlgTag) {
  680|      0|                case SEC_OID_MD2:
  ------------------
  |  Branch (680:17): [True: 0, False: 27.4k]
  ------------------
  681|      0|                    sigTag = SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION;
  682|      0|                    break;
  683|      0|                case SEC_OID_MD5:
  ------------------
  |  Branch (683:17): [True: 0, False: 27.4k]
  ------------------
  684|      0|                    sigTag = SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION;
  685|      0|                    break;
  686|  26.5k|                case SEC_OID_SHA1:
  ------------------
  |  Branch (686:17): [True: 26.5k, False: 900]
  ------------------
  687|  26.5k|                    sigTag = SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION;
  688|  26.5k|                    break;
  689|      0|                case SEC_OID_SHA224:
  ------------------
  |  Branch (689:17): [True: 0, False: 27.4k]
  ------------------
  690|      0|                    sigTag = SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION;
  691|      0|                    break;
  692|      0|                case SEC_OID_UNKNOWN: /* default for RSA if not specified */
  ------------------
  |  Branch (692:17): [True: 0, False: 27.4k]
  ------------------
  693|    595|                case SEC_OID_SHA256:
  ------------------
  |  Branch (693:17): [True: 595, False: 26.8k]
  ------------------
  694|    595|                    sigTag = SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION;
  695|    595|                    break;
  696|    266|                case SEC_OID_SHA384:
  ------------------
  |  Branch (696:17): [True: 266, False: 27.2k]
  ------------------
  697|    266|                    sigTag = SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION;
  698|    266|                    break;
  699|     39|                case SEC_OID_SHA512:
  ------------------
  |  Branch (699:17): [True: 39, False: 27.4k]
  ------------------
  700|     39|                    sigTag = SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION;
  701|     39|                    break;
  702|      0|                default:
  ------------------
  |  Branch (702:17): [True: 0, False: 27.4k]
  ------------------
  703|      0|                    break;
  704|  27.4k|            }
  705|  27.4k|            break;
  706|  27.4k|        case dsaKey:
  ------------------
  |  Branch (706:9): [True: 0, False: 38.3k]
  ------------------
  707|      0|            switch (hashAlgTag) {
  708|      0|                case SEC_OID_SHA1:
  ------------------
  |  Branch (708:17): [True: 0, False: 0]
  ------------------
  709|      0|                    sigTag = SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST;
  710|      0|                    break;
  711|      0|                case SEC_OID_SHA224:
  ------------------
  |  Branch (711:17): [True: 0, False: 0]
  ------------------
  712|      0|                    sigTag = SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA224_DIGEST;
  713|      0|                    break;
  714|      0|                case SEC_OID_UNKNOWN: /* default for DSA if not specified */
  ------------------
  |  Branch (714:17): [True: 0, False: 0]
  ------------------
  715|      0|                case SEC_OID_SHA256:
  ------------------
  |  Branch (715:17): [True: 0, False: 0]
  ------------------
  716|      0|                    sigTag = SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA256_DIGEST;
  717|      0|                    break;
  718|      0|                default:
  ------------------
  |  Branch (718:17): [True: 0, False: 0]
  ------------------
  719|      0|                    break;
  720|      0|            }
  721|      0|            break;
  722|  10.8k|        case ecKey:
  ------------------
  |  Branch (722:9): [True: 10.8k, False: 27.4k]
  ------------------
  723|  10.8k|            switch (hashAlgTag) {
  724|  8.53k|                case SEC_OID_SHA1:
  ------------------
  |  Branch (724:17): [True: 8.53k, False: 2.32k]
  ------------------
  725|  8.53k|                    sigTag = SEC_OID_ANSIX962_ECDSA_SHA1_SIGNATURE;
  726|  8.53k|                    break;
  727|      0|                case SEC_OID_SHA224:
  ------------------
  |  Branch (727:17): [True: 0, False: 10.8k]
  ------------------
  728|      0|                    sigTag = SEC_OID_ANSIX962_ECDSA_SHA224_SIGNATURE;
  729|      0|                    break;
  730|      0|                case SEC_OID_UNKNOWN: /* default for ECDSA if not specified */
  ------------------
  |  Branch (730:17): [True: 0, False: 10.8k]
  ------------------
  731|    178|                case SEC_OID_SHA256:
  ------------------
  |  Branch (731:17): [True: 178, False: 10.6k]
  ------------------
  732|    178|                    sigTag = SEC_OID_ANSIX962_ECDSA_SHA256_SIGNATURE;
  733|    178|                    break;
  734|    157|                case SEC_OID_SHA384:
  ------------------
  |  Branch (734:17): [True: 157, False: 10.7k]
  ------------------
  735|    157|                    sigTag = SEC_OID_ANSIX962_ECDSA_SHA384_SIGNATURE;
  736|    157|                    break;
  737|  1.99k|                case SEC_OID_SHA512:
  ------------------
  |  Branch (737:17): [True: 1.99k, False: 8.87k]
  ------------------
  738|  1.99k|                    sigTag = SEC_OID_ANSIX962_ECDSA_SHA512_SIGNATURE;
  739|  1.99k|                    break;
  740|      0|                default:
  ------------------
  |  Branch (740:17): [True: 0, False: 10.8k]
  ------------------
  741|      0|                    break;
  742|  10.8k|            }
  743|  10.8k|        default:
  ------------------
  |  Branch (743:9): [True: 0, False: 38.3k]
  ------------------
  744|  10.8k|            break;
  745|  38.3k|    }
  746|  38.3k|    return sigTag;
  747|  38.3k|}

sec_GetEncAlgFromSigAlg:
  261|  38.3k|{
  262|       |    /* get the "encryption" algorithm */
  263|  38.3k|    switch (sigAlg) {
  264|      0|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (264:9): [True: 0, False: 38.3k]
  ------------------
  265|      0|        case SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (265:9): [True: 0, False: 38.3k]
  ------------------
  266|      0|        case SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (266:9): [True: 0, False: 38.3k]
  ------------------
  267|  26.5k|        case SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (267:9): [True: 26.5k, False: 11.7k]
  ------------------
  268|  26.5k|        case SEC_OID_ISO_SHA_WITH_RSA_SIGNATURE:
  ------------------
  |  Branch (268:9): [True: 0, False: 38.3k]
  ------------------
  269|  26.5k|        case SEC_OID_ISO_SHA1_WITH_RSA_SIGNATURE:
  ------------------
  |  Branch (269:9): [True: 0, False: 38.3k]
  ------------------
  270|  26.5k|        case SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (270:9): [True: 0, False: 38.3k]
  ------------------
  271|  27.1k|        case SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (271:9): [True: 595, False: 37.7k]
  ------------------
  272|  27.4k|        case SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (272:9): [True: 266, False: 38.0k]
  ------------------
  273|  27.4k|        case SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (273:9): [True: 39, False: 38.2k]
  ------------------
  274|  27.4k|            return SEC_OID_PKCS1_RSA_ENCRYPTION;
  275|      0|        case SEC_OID_PKCS1_RSA_PSS_SIGNATURE:
  ------------------
  |  Branch (275:9): [True: 0, False: 38.3k]
  ------------------
  276|      0|            return SEC_OID_PKCS1_RSA_PSS_SIGNATURE;
  277|       |
  278|       |        /* what about normal DSA? */
  279|      0|        case SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST:
  ------------------
  |  Branch (279:9): [True: 0, False: 38.3k]
  ------------------
  280|      0|        case SEC_OID_BOGUS_DSA_SIGNATURE_WITH_SHA1_DIGEST:
  ------------------
  |  Branch (280:9): [True: 0, False: 38.3k]
  ------------------
  281|      0|        case SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA224_DIGEST:
  ------------------
  |  Branch (281:9): [True: 0, False: 38.3k]
  ------------------
  282|      0|        case SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA256_DIGEST:
  ------------------
  |  Branch (282:9): [True: 0, False: 38.3k]
  ------------------
  283|      0|            return SEC_OID_ANSIX9_DSA_SIGNATURE;
  284|      0|        case SEC_OID_MISSI_DSS:
  ------------------
  |  Branch (284:9): [True: 0, False: 38.3k]
  ------------------
  285|      0|        case SEC_OID_MISSI_KEA_DSS:
  ------------------
  |  Branch (285:9): [True: 0, False: 38.3k]
  ------------------
  286|      0|        case SEC_OID_MISSI_KEA_DSS_OLD:
  ------------------
  |  Branch (286:9): [True: 0, False: 38.3k]
  ------------------
  287|      0|        case SEC_OID_MISSI_DSS_OLD:
  ------------------
  |  Branch (287:9): [True: 0, False: 38.3k]
  ------------------
  288|      0|            return SEC_OID_MISSI_DSS;
  289|  8.53k|        case SEC_OID_ANSIX962_ECDSA_SHA1_SIGNATURE:
  ------------------
  |  Branch (289:9): [True: 8.53k, False: 29.7k]
  ------------------
  290|  8.53k|        case SEC_OID_ANSIX962_ECDSA_SHA224_SIGNATURE:
  ------------------
  |  Branch (290:9): [True: 0, False: 38.3k]
  ------------------
  291|  8.71k|        case SEC_OID_ANSIX962_ECDSA_SHA256_SIGNATURE:
  ------------------
  |  Branch (291:9): [True: 178, False: 38.1k]
  ------------------
  292|  8.87k|        case SEC_OID_ANSIX962_ECDSA_SHA384_SIGNATURE:
  ------------------
  |  Branch (292:9): [True: 157, False: 38.1k]
  ------------------
  293|  10.8k|        case SEC_OID_ANSIX962_ECDSA_SHA512_SIGNATURE:
  ------------------
  |  Branch (293:9): [True: 1.99k, False: 36.3k]
  ------------------
  294|  10.8k|        case SEC_OID_ANSIX962_ECDSA_SIGNATURE_RECOMMENDED_DIGEST:
  ------------------
  |  Branch (294:9): [True: 0, False: 38.3k]
  ------------------
  295|  10.8k|        case SEC_OID_ANSIX962_ECDSA_SIGNATURE_SPECIFIED_DIGEST:
  ------------------
  |  Branch (295:9): [True: 0, False: 38.3k]
  ------------------
  296|  10.8k|            return SEC_OID_ANSIX962_EC_PUBLIC_KEY;
  297|       |        /* we don't implement MD4 hashes */
  298|      0|        case SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (298:9): [True: 0, False: 38.3k]
  ------------------
  299|      0|        default:
  ------------------
  |  Branch (299:9): [True: 0, False: 38.3k]
  ------------------
  300|      0|            PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  301|      0|            break;
  302|  38.3k|    }
  303|      0|    return SEC_OID_UNKNOWN;
  304|  38.3k|}
vfy_ImportPublicKey:
  630|  2.95k|{
  631|  2.95k|    PK11SlotInfo *slot;
  632|  2.95k|    CK_OBJECT_HANDLE objID;
  633|       |
  634|  2.95k|    if (cx->key->pkcs11Slot &&
  ------------------
  |  Branch (634:9): [True: 0, False: 2.95k]
  ------------------
  635|  2.95k|        PK11_DoesMechanismFlag(cx->key->pkcs11Slot,
  ------------------
  |  Branch (635:9): [True: 0, False: 0]
  ------------------
  636|      0|                               cx->mech, CKF_VERIFY)) {
  ------------------
  |  | 1358|      0|#define CKF_VERIFY 0x00002000
  ------------------
  637|      0|        return SECSuccess;
  638|      0|    }
  639|  2.95k|    slot = PK11_GetBestSlotWithAttributes(cx->mech, CKF_VERIFY, 0, cx->wincx);
  ------------------
  |  | 1358|  2.95k|#define CKF_VERIFY 0x00002000
  ------------------
  640|  2.95k|    if (slot == NULL) {
  ------------------
  |  Branch (640:9): [True: 0, False: 2.95k]
  ------------------
  641|      0|        return SECFailure; /* can't find a slot, fall back to
  642|       |                            * normal processing */
  643|      0|    }
  644|  2.95k|    objID = PK11_ImportPublicKey(slot, cx->key, PR_FALSE);
  ------------------
  |  |  438|  2.95k|#define PR_FALSE 0
  ------------------
  645|  2.95k|    PK11_FreeSlot(slot);
  646|  2.95k|    return objID == CK_INVALID_HANDLE ? SECFailure : SECSuccess;
  ------------------
  |  |   78|  2.95k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (646:12): [True: 0, False: 2.95k]
  ------------------
  647|  2.95k|}
VFY_DestroyContext:
  885|  2.95k|{
  886|  2.95k|    if (cx) {
  ------------------
  |  Branch (886:9): [True: 2.95k, False: 0]
  ------------------
  887|  2.95k|        if (cx->hashcx != NULL) {
  ------------------
  |  Branch (887:13): [True: 0, False: 2.95k]
  ------------------
  888|      0|            (*cx->hashobj->destroy)(cx->hashcx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  889|      0|            cx->hashcx = NULL;
  890|      0|        }
  891|  2.95k|        if (cx->vfycx != NULL) {
  ------------------
  |  Branch (891:13): [True: 0, False: 2.95k]
  ------------------
  892|      0|            (void)PK11_DestroyContext(cx->vfycx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  893|      0|            cx->vfycx = NULL;
  894|      0|        }
  895|  2.95k|        if (cx->key) {
  ------------------
  |  Branch (895:13): [True: 2.95k, False: 0]
  ------------------
  896|  2.95k|            SECKEY_DestroyPublicKey(cx->key);
  897|  2.95k|        }
  898|  2.95k|        if (cx->pkcs1RSADigestInfo) {
  ------------------
  |  Branch (898:13): [True: 4, False: 2.94k]
  ------------------
  899|      4|            PORT_Free(cx->pkcs1RSADigestInfo);
  ------------------
  |  |   60|      4|#define PORT_Free PORT_Free_Util
  ------------------
  900|      4|        }
  901|  2.95k|        SECITEM_FreeItem(&cx->mechparams, PR_FALSE);
  ------------------
  |  |  108|  2.95k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&cx->mechparams, PR_FALSE);
  ------------------
  |  |  438|  2.95k|#define PR_FALSE 0
  ------------------
  902|  2.95k|        if (freeit) {
  ------------------
  |  Branch (902:13): [True: 2.95k, False: 0]
  ------------------
  903|  2.95k|            PORT_ZFree(cx, sizeof(VFYContext));
  ------------------
  |  |   75|  2.95k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  904|  2.95k|        }
  905|  2.95k|    }
  906|  2.95k|}
VFY_VerifyDigestDirect:
 1107|  2.95k|{
 1108|  2.95k|    CK_MECHANISM_TYPE mech = sec_GetCombinedMech(encAlg, hashAlg);
 1109|  2.95k|    return vfy_VerifyDigest(digest, key, sig, encAlg, hashAlg, mech,
 1110|  2.95k|                            NULL, wincx);
 1111|  2.95k|}
secvfy.c:vfy_CreateContext:
  721|  2.95k|{
  722|  2.95k|    VFYContext *cx;
  723|  2.95k|    SECStatus rv;
  724|  2.95k|    KeyType type;
  725|  2.95k|    PRUint32 policyFlags;
  726|  2.95k|    PRInt32 optFlags;
  727|       |
  728|       |    /* make sure the encryption algorithm matches the key type */
  729|       |    /* RSA-PSS algorithm can be used with both rsaKey and rsaPssKey */
  730|  2.95k|    type = seckey_GetKeyType(encAlg);
  731|  2.95k|    if ((key->keyType != type) &&
  ------------------
  |  Branch (731:9): [True: 0, False: 2.95k]
  ------------------
  732|  2.95k|        ((key->keyType != rsaKey) || (type != rsaPssKey))) {
  ------------------
  |  Branch (732:10): [True: 0, False: 0]
  |  Branch (732:38): [True: 0, False: 0]
  ------------------
  733|      0|        SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  734|      0|        PORT_SetError(SEC_ERROR_PKCS7_KEYALG_MISMATCH);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  735|      0|        return NULL;
  736|      0|    }
  737|  2.95k|    if (NSS_OptionGet(NSS_KEY_SIZE_POLICY_FLAGS, &optFlags) != SECFailure) {
  ------------------
  |  |  317|  2.95k|#define NSS_KEY_SIZE_POLICY_FLAGS 0x00e
  ------------------
  |  Branch (737:9): [True: 2.95k, False: 0]
  ------------------
  738|  2.95k|        if (optFlags & NSS_KEY_SIZE_POLICY_VERIFY_FLAG) {
  ------------------
  |  |  322|  2.95k|#define NSS_KEY_SIZE_POLICY_VERIFY_FLAG 2
  ------------------
  |  Branch (738:13): [True: 2.95k, False: 0]
  ------------------
  739|  2.95k|            rv = SECKEY_EnforceKeySize(key->keyType,
  740|  2.95k|                                       SECKEY_PublicKeyStrengthInBits(key),
  741|  2.95k|                                       SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
  742|  2.95k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (742:17): [True: 6, False: 2.95k]
  ------------------
  743|      6|                SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  108|      6|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  438|      6|#define PR_FALSE 0
  ------------------
  744|      6|                return NULL;
  745|      6|            }
  746|  2.95k|        }
  747|  2.95k|    }
  748|       |    /* check the policy on the encryption algorithm */
  749|  2.95k|    if ((NSS_GetAlgorithmPolicy(encAlg, &policyFlags) == SECFailure) ||
  ------------------
  |  Branch (749:9): [True: 0, False: 2.95k]
  ------------------
  750|  2.95k|        !(policyFlags & NSS_USE_ALG_IN_ANY_SIGNATURE)) {
  ------------------
  |  |  575|  2.95k|#define NSS_USE_ALG_IN_ANY_SIGNATURE 0x00000020    /* used in any signature */
  ------------------
  |  Branch (750:9): [True: 0, False: 2.95k]
  ------------------
  751|      0|        SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  752|      0|        PORT_SetError(SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  753|      0|        return NULL;
  754|      0|    }
  755|       |
  756|  2.95k|    cx = (VFYContext *)PORT_ZAlloc(sizeof(VFYContext));
  ------------------
  |  |   72|  2.95k|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  757|  2.95k|    if (cx == NULL) {
  ------------------
  |  Branch (757:9): [True: 0, False: 2.95k]
  ------------------
  758|       |        /* after this point mechparamsp is 'owned' by the context and will be
  759|       |         * freed by Destroy context for any other failures here */
  760|      0|        SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(mechparamsp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  761|      0|        goto loser;
  762|      0|    }
  763|       |
  764|  2.95k|    cx->wincx = wincx;
  765|  2.95k|    cx->hasSignature = (sig != NULL);
  766|  2.95k|    cx->encAlg = encAlg;
  767|  2.95k|    cx->hashAlg = hashAlg;
  768|  2.95k|    cx->mech = mech;
  769|  2.95k|    if (mechparamsp) {
  ------------------
  |  Branch (769:9): [True: 0, False: 2.95k]
  ------------------
  770|      0|        cx->mechparams = *mechparamsp;
  771|  2.95k|    } else {
  772|       |        /* probably needs to have a call to set the default
  773|       |         * paramseters based on hashAlg and encAlg */
  774|  2.95k|        cx->mechparams.data = NULL;
  775|  2.95k|        cx->mechparams.len = 0;
  776|  2.95k|    }
  777|  2.95k|    cx->key = SECKEY_CopyPublicKey(key);
  778|  2.95k|    cx->pkcs1RSADigestInfo = NULL;
  779|  2.95k|    if (mech != CKM_INVALID_MECHANISM) {
  ------------------
  |  |  155|  2.95k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  |  Branch (779:9): [True: 2.95k, False: 0]
  ------------------
  780|  2.95k|        rv = vfy_ImportPublicKey(cx);
  781|       |        /* if we can't import the key, then we probably can't
  782|       |         * support the requested combined mechanism, fallback
  783|       |         * to the non-combined method */
  784|  2.95k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (784:13): [True: 0, False: 2.95k]
  ------------------
  785|      0|            cx->mech = mech = CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  786|      0|        }
  787|  2.95k|    }
  788|  2.95k|    if (sig) {
  ------------------
  |  Branch (788:9): [True: 2.95k, False: 0]
  ------------------
  789|       |        /* sigh, if we are prehashing, we still need to do verifyRecover
  790|       |         * recover for RSA PKCS #1 */
  791|  2.95k|        if ((mech == CKM_INVALID_MECHANISM || prehash) && (type == rsaKey)) {
  ------------------
  |  |  155|  5.90k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  |  Branch (791:14): [True: 0, False: 2.95k]
  |  Branch (791:47): [True: 2.95k, False: 0]
  |  Branch (791:59): [True: 2.95k, False: 0]
  ------------------
  792|       |            /* in traditional rsa PKCS #1, we use verify recover to get
  793|       |             * the encoded RSADigestInfo. In all other cases we just
  794|       |             * stash the signature encoded in PKCS#11 in our context */
  795|  2.95k|            rv = recoverPKCS1DigestInfo(hashAlg, &cx->hashAlg,
  796|  2.95k|                                        &cx->pkcs1RSADigestInfo,
  797|  2.95k|                                        &cx->pkcs1RSADigestInfoLen,
  798|  2.95k|                                        cx->key,
  799|  2.95k|                                        sig, wincx);
  800|  2.95k|        } else {
  801|       |            /* at this point hashAlg should be known. Only the RSA case
  802|       |             * enters here with hashAlg unknown, and it's found out
  803|       |             * above */
  804|      0|            PORT_Assert(hashAlg != SEC_OID_UNKNOWN);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  805|      0|            rv = vfy_SetPKCS11SigFromX509Sig(cx, sig);
  806|      0|        }
  807|  2.95k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (807:13): [True: 2.94k, False: 4]
  ------------------
  808|  2.94k|            goto loser;
  809|  2.94k|        }
  810|  2.95k|    }
  811|       |
  812|       |    /* check hash alg again, RSA may have changed it.*/
  813|      4|    if (HASH_GetHashTypeByOidTag(cx->hashAlg) == HASH_AlgNULL) {
  ------------------
  |  |  125|      4|#define HASH_GetHashTypeByOidTag HASH_GetHashTypeByOidTag_Util
  ------------------
  |  Branch (813:9): [True: 0, False: 4]
  ------------------
  814|       |        /* error set by HASH_GetHashTypeByOidTag */
  815|      0|        goto loser;
  816|      0|    }
  817|       |    /* check the policy on the hash algorithm. Do this after
  818|       |     * the rsa decode because some uses of this function get hash implicitly
  819|       |     * from the RSA signature itself. */
  820|      4|    if ((NSS_GetAlgorithmPolicy(cx->hashAlg, &policyFlags) == SECFailure) ||
  ------------------
  |  Branch (820:9): [True: 0, False: 4]
  ------------------
  821|      4|        !(policyFlags & NSS_USE_ALG_IN_ANY_SIGNATURE)) {
  ------------------
  |  |  575|      4|#define NSS_USE_ALG_IN_ANY_SIGNATURE 0x00000020    /* used in any signature */
  ------------------
  |  Branch (821:9): [True: 0, False: 4]
  ------------------
  822|      0|        PORT_SetError(SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  823|      0|        goto loser;
  824|      0|    }
  825|       |
  826|      4|    if (hash) {
  ------------------
  |  Branch (826:9): [True: 0, False: 4]
  ------------------
  827|      0|        *hash = cx->hashAlg;
  828|      0|    }
  829|      4|    return cx;
  830|       |
  831|  2.94k|loser:
  832|  2.94k|    if (cx) {
  ------------------
  |  Branch (832:9): [True: 2.94k, False: 0]
  ------------------
  833|  2.94k|        VFY_DestroyContext(cx, PR_TRUE);
  ------------------
  |  |  437|  2.94k|#define PR_TRUE 1
  ------------------
  834|  2.94k|    }
  835|  2.94k|    return 0;
  836|      4|}
secvfy.c:sec_GetCombinedMech:
  390|  2.95k|{
  391|  2.95k|    switch (encalg) {
  392|  2.95k|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (392:9): [True: 2.95k, False: 0]
  ------------------
  393|  2.95k|            return sec_RSAPKCS1GetCombinedMech(hashalg);
  394|      0|        case SEC_OID_PKCS1_RSA_PSS_SIGNATURE:
  ------------------
  |  Branch (394:9): [True: 0, False: 2.95k]
  ------------------
  395|      0|            return sec_RSAPSSGetCombinedMech(hashalg);
  396|      0|        case SEC_OID_ANSIX962_EC_PUBLIC_KEY:
  ------------------
  |  Branch (396:9): [True: 0, False: 2.95k]
  ------------------
  397|      0|            return sec_ECDSAGetCombinedMech(hashalg);
  398|      0|        case SEC_OID_ANSIX9_DSA_SIGNATURE:
  ------------------
  |  Branch (398:9): [True: 0, False: 2.95k]
  ------------------
  399|      0|            return sec_DSAGetCombinedMech(hashalg);
  400|      0|        default:
  ------------------
  |  Branch (400:9): [True: 0, False: 2.95k]
  ------------------
  401|      0|            break;
  402|  2.95k|    }
  403|      0|    return CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  404|  2.95k|}
secvfy.c:sec_RSAPKCS1GetCombinedMech:
  307|  2.95k|{
  308|  2.95k|    switch (hashalg) {
  309|      0|        case SEC_OID_MD5:
  ------------------
  |  Branch (309:9): [True: 0, False: 2.95k]
  ------------------
  310|      0|            return CKM_MD5_RSA_PKCS;
  ------------------
  |  |  727|      0|#define CKM_MD5_RSA_PKCS 0x00000005UL
  ------------------
  311|      0|        case SEC_OID_MD2:
  ------------------
  |  Branch (311:9): [True: 0, False: 2.95k]
  ------------------
  312|      0|            return CKM_MD2_RSA_PKCS;
  ------------------
  |  |  726|      0|#define CKM_MD2_RSA_PKCS 0x00000004UL
  ------------------
  313|  1.66k|        case SEC_OID_SHA1:
  ------------------
  |  Branch (313:9): [True: 1.66k, False: 1.29k]
  ------------------
  314|  1.66k|            return CKM_SHA1_RSA_PKCS;
  ------------------
  |  |  728|  1.66k|#define CKM_SHA1_RSA_PKCS 0x00000006UL
  ------------------
  315|      0|        case SEC_OID_SHA224:
  ------------------
  |  Branch (315:9): [True: 0, False: 2.95k]
  ------------------
  316|      0|            return CKM_SHA224_RSA_PKCS;
  ------------------
  |  |  778|      0|#define CKM_SHA224_RSA_PKCS 0x00000046UL
  ------------------
  317|  1.00k|        case SEC_OID_SHA256:
  ------------------
  |  Branch (317:9): [True: 1.00k, False: 1.95k]
  ------------------
  318|  1.00k|            return CKM_SHA256_RSA_PKCS;
  ------------------
  |  |  770|  1.00k|#define CKM_SHA256_RSA_PKCS 0x00000040UL
  ------------------
  319|      6|        case SEC_OID_SHA384:
  ------------------
  |  Branch (319:9): [True: 6, False: 2.95k]
  ------------------
  320|      6|            return CKM_SHA384_RSA_PKCS;
  ------------------
  |  |  771|      6|#define CKM_SHA384_RSA_PKCS 0x00000041UL
  ------------------
  321|    285|        case SEC_OID_SHA512:
  ------------------
  |  Branch (321:9): [True: 285, False: 2.67k]
  ------------------
  322|    285|            return CKM_SHA512_RSA_PKCS;
  ------------------
  |  |  772|    285|#define CKM_SHA512_RSA_PKCS 0x00000042UL
  ------------------
  323|      0|        default:
  ------------------
  |  Branch (323:9): [True: 0, False: 2.95k]
  ------------------
  324|      0|            break;
  325|  2.95k|    }
  326|      0|    return CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  327|  2.95k|}
secvfy.c:recoverPKCS1DigestInfo:
   45|  2.95k|{
   46|  2.95k|    SGNDigestInfo *di = NULL;
   47|  2.95k|    SECItem it;
   48|  2.95k|    PRBool rv = SECSuccess;
   49|       |
   50|  2.95k|    PORT_Assert(digestAlgOut);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   51|  2.95k|    PORT_Assert(digestInfo);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   52|  2.95k|    PORT_Assert(digestInfoLen);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   53|  2.95k|    PORT_Assert(key);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   54|  2.95k|    PORT_Assert(key->keyType == rsaKey);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   55|  2.95k|    PORT_Assert(sig);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   56|       |
   57|  2.95k|    it.data = NULL;
   58|  2.95k|    it.len = SECKEY_PublicKeyStrength(key);
   59|  2.95k|    if (it.len != 0) {
  ------------------
  |  Branch (59:9): [True: 2.95k, False: 0]
  ------------------
   60|  2.95k|        it.data = (unsigned char *)PORT_Alloc(it.len);
  ------------------
  |  |   52|  2.95k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
   61|  2.95k|    }
   62|  2.95k|    if (it.len == 0 || it.data == NULL) {
  ------------------
  |  Branch (62:9): [True: 0, False: 2.95k]
  |  Branch (62:24): [True: 0, False: 2.95k]
  ------------------
   63|      0|        rv = SECFailure;
   64|      0|    }
   65|       |
   66|  2.95k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (66:9): [True: 2.95k, False: 0]
  ------------------
   67|       |        /* decrypt the block */
   68|  2.95k|        rv = PK11_VerifyRecover(key, sig, &it, wincx);
   69|  2.95k|    }
   70|       |
   71|  2.95k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (71:9): [True: 4, False: 2.94k]
  ------------------
   72|      4|        if (givenDigestAlg != SEC_OID_UNKNOWN) {
  ------------------
  |  Branch (72:13): [True: 4, False: 0]
  ------------------
   73|       |            /* We don't need to parse the DigestInfo if the caller gave us the
   74|       |             * digest algorithm to use. Later verifyPKCS1DigestInfo will verify
   75|       |             * that the DigestInfo identifies the given digest algorithm and
   76|       |             * that the DigestInfo is encoded absolutely correctly.
   77|       |             */
   78|      4|            *digestInfoLen = it.len;
   79|      4|            *digestInfo = (unsigned char *)it.data;
   80|      4|            *digestAlgOut = givenDigestAlg;
   81|      4|            return SECSuccess;
   82|      4|        }
   83|      4|    }
   84|       |
   85|  2.94k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (85:9): [True: 0, False: 2.94k]
  ------------------
   86|       |        /* The caller didn't specify a digest algorithm to use, so choose the
   87|       |         * digest algorithm by parsing the AlgorithmIdentifier within the
   88|       |         * DigestInfo.
   89|       |         */
   90|      0|        di = SGN_DecodeDigestInfo(&it);
   91|      0|        if (!di) {
  ------------------
  |  Branch (91:13): [True: 0, False: 0]
  ------------------
   92|      0|            rv = SECFailure;
   93|      0|        }
   94|      0|    }
   95|       |
   96|  2.94k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (96:9): [True: 0, False: 2.94k]
  ------------------
   97|      0|        *digestAlgOut = SECOID_GetAlgorithmTag(&di->digestAlgorithm);
  ------------------
  |  |  119|      0|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
   98|      0|        if (*digestAlgOut == SEC_OID_UNKNOWN) {
  ------------------
  |  Branch (98:13): [True: 0, False: 0]
  ------------------
   99|      0|            rv = SECFailure;
  100|      0|        }
  101|      0|    }
  102|       |
  103|  2.94k|    if (di) {
  ------------------
  |  Branch (103:9): [True: 0, False: 2.94k]
  ------------------
  104|      0|        SGN_DestroyDigestInfo(di);
  ------------------
  |  |  124|      0|#define SGN_DestroyDigestInfo SGN_DestroyDigestInfo_Util
  ------------------
  105|      0|    }
  106|       |
  107|  2.94k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (107:9): [True: 0, False: 2.94k]
  ------------------
  108|      0|        *digestInfoLen = it.len;
  109|      0|        *digestInfo = (unsigned char *)it.data;
  110|  2.94k|    } else {
  111|  2.94k|        if (it.data) {
  ------------------
  |  Branch (111:13): [True: 2.94k, False: 0]
  ------------------
  112|  2.94k|            PORT_Free(it.data);
  ------------------
  |  |   60|  2.94k|#define PORT_Free PORT_Free_Util
  ------------------
  113|  2.94k|        }
  114|  2.94k|        *digestInfo = NULL;
  115|  2.94k|        *digestInfoLen = 0;
  116|  2.94k|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|  2.94k|#define PORT_SetError PORT_SetError_Util
  ------------------
  117|  2.94k|    }
  118|       |
  119|  2.94k|    return rv;
  120|  2.95k|}
secvfy.c:verifyPKCS1DigestInfo:
  164|      4|{
  165|      4|    SECItem pkcs1DigestInfo;
  166|      4|    pkcs1DigestInfo.data = cx->pkcs1RSADigestInfo;
  167|      4|    pkcs1DigestInfo.len = cx->pkcs1RSADigestInfoLen;
  168|      4|    return _SGN_VerifyPKCS1DigestInfo(
  169|      4|        cx->hashAlg, digest, &pkcs1DigestInfo,
  170|      4|        PR_FALSE /*XXX: unsafeAllowMissingParameters*/);
  ------------------
  |  |  438|      4|#define PR_FALSE 0
  ------------------
  171|      4|}
secvfy.c:vfy_VerifyDigest:
 1060|  2.95k|{
 1061|  2.95k|    SECStatus rv;
 1062|  2.95k|    VFYContext *cx;
 1063|  2.95k|    SECItem dsasig; /* also used for ECDSA */
 1064|  2.95k|    rv = SECFailure;
 1065|       |
 1066|  2.95k|    cx = vfy_CreateContext(key, sig, encAlg, hashAlg, mech, mechparamsp,
 1067|  2.95k|                           NULL, PR_TRUE, wincx);
  ------------------
  |  |  437|  2.95k|#define PR_TRUE 1
  ------------------
 1068|  2.95k|    if (cx != NULL) {
  ------------------
  |  Branch (1068:9): [True: 4, False: 2.95k]
  ------------------
 1069|      4|        switch (key->keyType) {
 1070|      4|            case rsaKey:
  ------------------
  |  Branch (1070:13): [True: 4, False: 0]
  ------------------
 1071|       |                /* PSS isn't handled here for VerifyDigest. SSL
 1072|       |                 * calls PK11_Verify directly */
 1073|      4|                rv = verifyPKCS1DigestInfo(cx, digest);
 1074|       |                /* Error (if any) set by verifyPKCS1DigestInfo */
 1075|      4|                break;
 1076|      0|            case ecKey:
  ------------------
  |  Branch (1076:13): [True: 0, False: 4]
  ------------------
 1077|      0|            case dsaKey:
  ------------------
  |  Branch (1077:13): [True: 0, False: 4]
  ------------------
 1078|      0|                dsasig.data = cx->u.buffer;
 1079|      0|                dsasig.len = checkedSignatureLen(cx->key);
 1080|      0|                if (dsasig.len == 0) {
  ------------------
  |  Branch (1080:21): [True: 0, False: 0]
  ------------------
 1081|       |                    /* Error set by checkedSignatureLen */
 1082|      0|                    rv = SECFailure;
 1083|      0|                    break;
 1084|      0|                }
 1085|      0|                if (dsasig.len > sizeof(cx->u)) {
  ------------------
  |  Branch (1085:21): [True: 0, False: 0]
  ------------------
 1086|      0|                    PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1087|      0|                    rv = SECFailure;
 1088|      0|                    break;
 1089|      0|                }
 1090|      0|                rv = PK11_Verify(cx->key, &dsasig, (SECItem *)digest, cx->wincx);
 1091|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (1091:21): [True: 0, False: 0]
  ------------------
 1092|      0|                    PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1093|      0|                }
 1094|      0|                break;
 1095|      0|            default:
  ------------------
  |  Branch (1095:13): [True: 0, False: 4]
  ------------------
 1096|      0|                break;
 1097|      4|        }
 1098|      4|        VFY_DestroyContext(cx, PR_TRUE);
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
 1099|      4|    }
 1100|  2.95k|    return rv;
 1101|  2.95k|}

nssSlot_Destroy:
   33|  23.4k|{
   34|  23.4k|    if (slot) {
  ------------------
  |  Branch (34:9): [True: 23.4k, False: 0]
  ------------------
   35|  23.4k|        if (PR_ATOMIC_DECREMENT(&slot->base.refCount) == 0) {
  ------------------
  |  |  123|  23.4k|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (35:13): [True: 2, False: 23.4k]
  ------------------
   36|      2|            PK11_FreeSlot(slot->pk11slot);
   37|      2|            PZ_DestroyLock(slot->base.lock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   38|      2|            PZ_DestroyCondVar(slot->isPresentCondition);
  ------------------
  |  |  249|      2|#define PZ_DestroyCondVar(v) PR_DestroyCondVar((v))
  ------------------
   39|      2|            PZ_DestroyLock(slot->isPresentLock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   40|      2|            return nssArena_Destroy(slot->base.arena);
   41|      2|        }
   42|  23.4k|    }
   43|  23.4k|    return PR_SUCCESS;
   44|  23.4k|}
nssSlot_AddRef:
   72|  23.4k|{
   73|  23.4k|    PR_ATOMIC_INCREMENT(&slot->base.refCount);
  ------------------
  |  |  122|  23.4k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
   74|  23.4k|    return slot;
   75|  23.4k|}
nssSlot_IsTokenPresent:
  118|  23.4k|{
  119|  23.4k|    CK_RV ckrv;
  120|  23.4k|    PRStatus nssrv;
  121|  23.4k|    NSSToken *nssToken = NULL;
  122|       |    /* XXX */
  123|  23.4k|    nssSession *session;
  124|  23.4k|    CK_SLOT_INFO slotInfo;
  125|  23.4k|    void *epv;
  126|  23.4k|    PRBool isPresent = PR_FALSE;
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
  127|  23.4k|    PRBool doUpdateCachedCerts = PR_FALSE;
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
  128|       |
  129|       |    /* permanent slots are always present unless they're disabled */
  130|  23.4k|    if (nssSlot_IsPermanent(slot)) {
  ------------------
  |  Branch (130:9): [True: 23.4k, False: 0]
  ------------------
  131|  23.4k|        return !PK11_IsDisabled(slot->pk11slot);
  132|  23.4k|    }
  133|       |
  134|       |    /* avoid repeated calls to check token status within set interval */
  135|      0|    PZ_Lock(slot->isPresentLock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  136|      0|    if (token_status_checked(slot)) {
  ------------------
  |  Branch (136:9): [True: 0, False: 0]
  ------------------
  137|      0|        CK_FLAGS ckFlags = slot->ckFlags;
  138|      0|        PZ_Unlock(slot->isPresentLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  139|      0|        return ((ckFlags & CKF_TOKEN_PRESENT) != 0);
  ------------------
  |  |  131|      0|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  140|      0|    }
  141|      0|    PZ_Unlock(slot->isPresentLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  142|       |
  143|       |    /* First obtain the slot epv before we set up the condition
  144|       |     * variable, so we can just return if we couldn't get it. */
  145|      0|    epv = slot->epv;
  146|      0|    if (!epv) {
  ------------------
  |  Branch (146:9): [True: 0, False: 0]
  ------------------
  147|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  148|      0|    }
  149|       |
  150|       |    /* set up condition so only one thread is active in this part of the code at a time */
  151|      0|    PZ_Lock(slot->isPresentLock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  152|      0|    while (slot->isPresentThread) {
  ------------------
  |  Branch (152:12): [True: 0, False: 0]
  ------------------
  153|      0|        PR_WaitCondVar(slot->isPresentCondition, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |   54|      0|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
  154|      0|    }
  155|       |    /* if we were one of multiple threads here, the first thread will have
  156|       |     * given us the answer, no need to make more queries of the token. */
  157|      0|    if (token_status_checked(slot)) {
  ------------------
  |  Branch (157:9): [True: 0, False: 0]
  ------------------
  158|      0|        CK_FLAGS ckFlags = slot->ckFlags;
  159|      0|        PZ_Unlock(slot->isPresentLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  160|      0|        return ((ckFlags & CKF_TOKEN_PRESENT) != 0);
  ------------------
  |  |  131|      0|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  161|      0|    }
  162|       |    /* this is the winning thread, block all others until we've determined
  163|       |     * if the token is present and that it needs initialization. */
  164|      0|    slot->lastTokenPingState = nssSlotLastPingState_Update;
  165|      0|    slot->isPresentThread = PR_GetCurrentThread();
  166|       |
  167|      0|    PZ_Unlock(slot->isPresentLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  168|       |
  169|      0|    nssToken = PK11Slot_GetNSSToken(slot->pk11slot);
  170|      0|    if (!nssToken) {
  ------------------
  |  Branch (170:9): [True: 0, False: 0]
  ------------------
  171|      0|        isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  172|      0|        goto done;
  173|      0|    }
  174|       |
  175|      0|    if (PK11_GetSlotInfo(slot->pk11slot, &slotInfo) != SECSuccess) {
  ------------------
  |  Branch (175:9): [True: 0, False: 0]
  ------------------
  176|      0|        nssToken->base.name[0] = 0; /* XXX */
  177|      0|        isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  178|      0|        goto done;
  179|      0|    }
  180|      0|    slot->ckFlags = slotInfo.flags;
  181|       |    /* check for the presence of the token */
  182|      0|    if ((slot->ckFlags & CKF_TOKEN_PRESENT) == 0) {
  ------------------
  |  |  131|      0|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  |  Branch (182:9): [True: 0, False: 0]
  ------------------
  183|      0|        session = nssToken_GetDefaultSession(nssToken);
  184|      0|        if (session) {
  ------------------
  |  Branch (184:13): [True: 0, False: 0]
  ------------------
  185|      0|            nssSession_EnterMonitor(session);
  186|       |            /* token is not present */
  187|      0|            if (session->handle != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (187:17): [True: 0, False: 0]
  ------------------
  188|       |                /* session is valid, close and invalidate it */
  189|      0|                CKAPI(epv)
  ------------------
  |  |   24|      0|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
  190|      0|                    ->C_CloseSession(session->handle);
  191|      0|                session->handle = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  192|      0|            }
  193|      0|            nssSession_ExitMonitor(session);
  194|      0|        }
  195|      0|        if (nssToken->base.name[0] != 0) {
  ------------------
  |  Branch (195:13): [True: 0, False: 0]
  ------------------
  196|       |            /* notify the high-level cache that the token is removed */
  197|      0|            nssToken->base.name[0] = 0; /* XXX */
  198|      0|            nssToken_NotifyCertsNotVisible(nssToken);
  199|      0|        }
  200|      0|        nssToken->base.name[0] = 0; /* XXX */
  201|       |        /* clear the token cache */
  202|      0|        nssToken_Remove(nssToken);
  203|      0|        isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  204|      0|        goto done;
  205|      0|    }
  206|       |    /* token is present, use the session info to determine if the card
  207|       |     * has been removed and reinserted.
  208|       |     */
  209|      0|    session = nssToken_GetDefaultSession(nssToken);
  210|      0|    if (session) {
  ------------------
  |  Branch (210:9): [True: 0, False: 0]
  ------------------
  211|      0|        PRBool tokenRemoved;
  212|      0|        nssSession_EnterMonitor(session);
  213|      0|        if (session->handle != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (213:13): [True: 0, False: 0]
  ------------------
  214|      0|            CK_SESSION_INFO sessionInfo;
  215|      0|            ckrv = CKAPI(epv)->C_GetSessionInfo(session->handle, &sessionInfo);
  ------------------
  |  |   24|      0|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
  216|      0|            if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (216:17): [True: 0, False: 0]
  ------------------
  217|       |                /* session is screwy, close and invalidate it */
  218|      0|                CKAPI(epv)
  ------------------
  |  |   24|      0|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
  219|      0|                    ->C_CloseSession(session->handle);
  220|      0|                session->handle = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  221|      0|            }
  222|      0|        }
  223|      0|        tokenRemoved = (session->handle == CK_INVALID_HANDLE);
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  224|      0|        nssSession_ExitMonitor(session);
  225|       |        /* token not removed, finished */
  226|      0|        if (!tokenRemoved) {
  ------------------
  |  Branch (226:13): [True: 0, False: 0]
  ------------------
  227|      0|            isPresent = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  228|      0|            goto done;
  229|      0|        }
  230|      0|    }
  231|       |    /* the token has been removed, and reinserted, or the slot contains
  232|       |     * a token it doesn't recognize. invalidate all the old
  233|       |     * information we had on this token, if we can't refresh, clear
  234|       |     * the present flag */
  235|      0|    nssToken_NotifyCertsNotVisible(nssToken);
  236|      0|    nssToken_Remove(nssToken);
  237|      0|    if (nssToken->base.name[0] == 0) {
  ------------------
  |  Branch (237:9): [True: 0, False: 0]
  ------------------
  238|      0|        doUpdateCachedCerts = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  239|      0|    }
  240|      0|    if (PK11_InitToken(slot->pk11slot, PR_FALSE) != SECSuccess) {
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (240:9): [True: 0, False: 0]
  ------------------
  241|      0|        isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  242|      0|        goto done;
  243|      0|    }
  244|      0|    if (doUpdateCachedCerts) {
  ------------------
  |  Branch (244:9): [True: 0, False: 0]
  ------------------
  245|      0|        nssTrustDomain_UpdateCachedTokenCerts(nssToken->trustDomain,
  246|      0|                                              nssToken);
  247|      0|    }
  248|      0|    nssrv = nssToken_Refresh(nssToken);
  249|      0|    if (nssrv != PR_SUCCESS) {
  ------------------
  |  Branch (249:9): [True: 0, False: 0]
  ------------------
  250|      0|        nssToken->base.name[0] = 0; /* XXX */
  251|      0|        slot->ckFlags &= ~CKF_TOKEN_PRESENT;
  ------------------
  |  |  131|      0|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  252|      0|        isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  253|      0|        goto done;
  254|      0|    }
  255|      0|    isPresent = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  256|      0|done:
  257|      0|    if (nssToken) {
  ------------------
  |  Branch (257:9): [True: 0, False: 0]
  ------------------
  258|      0|        (void)nssToken_Destroy(nssToken);
  259|      0|    }
  260|       |    /* Once we've set up the condition variable,
  261|       |     * Before returning, it's necessary to:
  262|       |     *  1) Set the lastTokenPingTime so that any other threads waiting on this
  263|       |     *     initialization and any future calls within the initialization window
  264|       |     *     return the just-computed status.
  265|       |     *  2) Indicate we're complete, waking up all other threads that may still
  266|       |     *     be waiting on initialization can progress.
  267|       |     */
  268|      0|    PZ_Lock(slot->isPresentLock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  269|       |    /* don't update the time if we were reset while we were
  270|       |     * getting the token state */
  271|      0|    if (slot->lastTokenPingState == nssSlotLastPingState_Update) {
  ------------------
  |  Branch (271:9): [True: 0, False: 0]
  ------------------
  272|      0|        slot->lastTokenPingTime = PR_IntervalNow();
  273|      0|        slot->lastTokenPingState = nssSlotLastPingState_Valid;
  274|      0|    }
  275|      0|    slot->isPresentThread = NULL;
  276|      0|    PR_NotifyAllCondVar(slot->isPresentCondition);
  277|      0|    PZ_Unlock(slot->isPresentLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  278|      0|    return isPresent;
  279|      0|}
nssSlot_GetCryptokiEPV:
  284|  23.4k|{
  285|  23.4k|    return slot->epv;
  286|  23.4k|}
nssSlot_GetToken:
  291|  23.4k|{
  292|  23.4k|    NSSToken *rvToken = NULL;
  293|       |
  294|  23.4k|    if (nssSlot_IsTokenPresent(slot)) {
  ------------------
  |  Branch (294:9): [True: 23.4k, False: 0]
  ------------------
  295|  23.4k|        rvToken = PK11Slot_GetNSSToken(slot->pk11slot);
  296|  23.4k|    }
  297|       |
  298|  23.4k|    return rvToken;
  299|  23.4k|}
nssSession_EnterMonitor:
  304|  23.4k|{
  305|  23.4k|    if (s->lock)
  ------------------
  |  Branch (305:9): [True: 23.4k, False: 0]
  ------------------
  306|  23.4k|        PZ_Lock(s->lock);
  ------------------
  |  |  245|  23.4k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  307|  23.4k|    return PR_SUCCESS;
  308|  23.4k|}
nssSession_ExitMonitor:
  313|  23.4k|{
  314|  23.4k|    return (s->lock) ? PZ_Unlock(s->lock) : PR_SUCCESS;
  ------------------
  |  |  246|  23.4k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  |  Branch (314:12): [True: 23.4k, False: 0]
  ------------------
  315|  23.4k|}

nssToken_Destroy:
   29|  23.4k|{
   30|  23.4k|    if (tok) {
  ------------------
  |  Branch (30:9): [True: 23.4k, False: 4]
  ------------------
   31|  23.4k|        if (PR_ATOMIC_DECREMENT(&tok->base.refCount) == 0) {
  ------------------
  |  |  123|  23.4k|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (31:13): [True: 2, False: 23.4k]
  ------------------
   32|      2|            PK11_FreeSlot(tok->pk11slot);
   33|      2|            PZ_DestroyLock(tok->base.lock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   34|      2|            nssTokenObjectCache_Destroy(tok->cache);
   35|      2|            (void)nssSlot_Destroy(tok->slot);
   36|      2|            return nssArena_Destroy(tok->base.arena);
   37|      2|        }
   38|  23.4k|    }
   39|  23.4k|    return PR_SUCCESS;
   40|  23.4k|}
nssToken_AddRef:
   52|  23.4k|{
   53|  23.4k|    PR_ATOMIC_INCREMENT(&tok->base.refCount);
  ------------------
  |  |  122|  23.4k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
   54|  23.4k|    return tok;
   55|  23.4k|}
nssToken_GetSlot:
   60|  23.4k|{
   61|  23.4k|    return nssSlot_AddRef(tok->slot);
   62|  23.4k|}
nssToken_GetCryptokiEPV:
   67|  23.4k|{
   68|  23.4k|    return nssSlot_GetCryptokiEPV(token->slot);
   69|  23.4k|}
nssToken_GetDefaultSession:
   74|  7.87k|{
   75|  7.87k|    return token->defaultSession;
   76|  7.87k|}
nssToken_FindObjectsByTemplate:
  372|  23.4k|{
  373|  23.4k|    CK_OBJECT_CLASS objclass = (CK_OBJECT_CLASS)-1;
  374|  23.4k|    nssCryptokiObject **objects = NULL;
  375|  23.4k|    PRUint32 i;
  376|       |
  377|  23.4k|    if (!token) {
  ------------------
  |  Branch (377:9): [True: 0, False: 23.4k]
  ------------------
  378|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  379|      0|        if (statusOpt)
  ------------------
  |  Branch (379:13): [True: 0, False: 0]
  ------------------
  380|      0|            *statusOpt = PR_FAILURE;
  381|      0|        return NULL;
  382|      0|    }
  383|  46.8k|    for (i = 0; i < otsize; i++) {
  ------------------
  |  Branch (383:17): [True: 46.8k, False: 0]
  ------------------
  384|  46.8k|        if (obj_template[i].type == CKA_CLASS) {
  ------------------
  |  |  511|  46.8k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (384:13): [True: 23.4k, False: 23.4k]
  ------------------
  385|  23.4k|            objclass = *(CK_OBJECT_CLASS *)obj_template[i].pValue;
  386|  23.4k|            break;
  387|  23.4k|        }
  388|  46.8k|    }
  389|  23.4k|    PR_ASSERT(i < otsize);
  ------------------
  |  |  208|  23.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 23.4k, False: 0]
  |  |  ------------------
  ------------------
  390|  23.4k|    if (i == otsize) {
  ------------------
  |  Branch (390:9): [True: 0, False: 23.4k]
  ------------------
  391|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  392|      0|        if (statusOpt)
  ------------------
  |  Branch (392:13): [True: 0, False: 0]
  ------------------
  393|      0|            *statusOpt = PR_FAILURE;
  394|      0|        return NULL;
  395|      0|    }
  396|       |    /* If these objects are being cached, try looking there first */
  397|  23.4k|    if (token->cache &&
  ------------------
  |  Branch (397:9): [True: 0, False: 23.4k]
  ------------------
  398|  23.4k|        nssTokenObjectCache_HaveObjectClass(token->cache, objclass)) {
  ------------------
  |  Branch (398:9): [True: 0, False: 0]
  ------------------
  399|      0|        PRStatus status;
  400|      0|        objects = nssTokenObjectCache_FindObjectsByTemplate(token->cache,
  401|      0|                                                            objclass,
  402|      0|                                                            obj_template,
  403|      0|                                                            otsize,
  404|      0|                                                            maximumOpt,
  405|      0|                                                            &status);
  406|      0|        if (status == PR_SUCCESS) {
  ------------------
  |  Branch (406:13): [True: 0, False: 0]
  ------------------
  407|      0|            if (statusOpt)
  ------------------
  |  Branch (407:17): [True: 0, False: 0]
  ------------------
  408|      0|                *statusOpt = status;
  409|      0|            return objects;
  410|      0|        }
  411|      0|    }
  412|       |    /* Either they are not cached, or cache failed; look on token. */
  413|  23.4k|    objects = find_objects(token, sessionOpt,
  414|  23.4k|                           obj_template, otsize,
  415|  23.4k|                           maximumOpt, statusOpt);
  416|  23.4k|    return objects;
  417|  23.4k|}
nssToken_FindCertificateByIssuerAndSerialNumber:
  744|  7.87k|{
  745|  7.87k|    CK_ATTRIBUTE_PTR attr;
  746|  7.87k|    CK_ATTRIBUTE cert_template[4];
  747|  7.87k|    CK_ULONG ctsize;
  748|  7.87k|    nssCryptokiObject **objects;
  749|  7.87k|    nssCryptokiObject *rvObject = NULL;
  750|  7.87k|    NSS_CK_TEMPLATE_START(cert_template, attr, ctsize);
  ------------------
  |  |   30|  7.87k|    attr = _template;                                \
  |  |   31|  7.87k|    size = 0;
  ------------------
  751|       |
  752|  7.87k|    if (!token) {
  ------------------
  |  Branch (752:9): [True: 0, False: 7.87k]
  ------------------
  753|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  754|      0|        if (statusOpt)
  ------------------
  |  Branch (754:13): [True: 0, False: 0]
  ------------------
  755|      0|            *statusOpt = PR_FAILURE;
  756|      0|        return NULL;
  757|      0|    }
  758|       |    /* Set the search to token/session only if provided */
  759|  7.87k|    if (searchType == nssTokenSearchType_SessionOnly) {
  ------------------
  |  Branch (759:9): [True: 0, False: 7.87k]
  ------------------
  760|      0|        NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_TOKEN, &g_ck_false);
  ------------------
  |  |   34|      0|    (pattr)->type = kind;                            \
  |  |   35|      0|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|      0|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|      0|    (pattr)++;
  ------------------
  761|  7.87k|    } else if ((searchType == nssTokenSearchType_TokenOnly) ||
  ------------------
  |  Branch (761:16): [True: 7.87k, False: 0]
  ------------------
  762|  7.87k|               (searchType == nssTokenSearchType_TokenForced)) {
  ------------------
  |  Branch (762:16): [True: 0, False: 0]
  ------------------
  763|  7.87k|        NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_TOKEN, &g_ck_true);
  ------------------
  |  |   34|  7.87k|    (pattr)->type = kind;                            \
  |  |   35|  7.87k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  7.87k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  7.87k|    (pattr)++;
  ------------------
  764|  7.87k|    }
  765|       |    /* Set the unique id */
  766|  7.87k|    NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_CLASS, &g_ck_class_cert);
  ------------------
  |  |   34|  7.87k|    (pattr)->type = kind;                            \
  |  |   35|  7.87k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  7.87k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  7.87k|    (pattr)++;
  ------------------
  767|  7.87k|    NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_ISSUER, issuer);
  ------------------
  |  |   34|  7.87k|    (pattr)->type = kind;                            \
  |  |   35|  7.87k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  7.87k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  7.87k|    (pattr)++;
  ------------------
  768|  7.87k|    NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_SERIAL_NUMBER, serial);
  ------------------
  |  |   34|  7.87k|    (pattr)->type = kind;                            \
  |  |   35|  7.87k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  7.87k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  7.87k|    (pattr)++;
  ------------------
  769|  7.87k|    NSS_CK_TEMPLATE_FINISH(cert_template, attr, ctsize);
  ------------------
  |  |   60|  7.87k|    size = (attr) - (_template);                      \
  |  |   61|  7.87k|    PR_ASSERT(size <= sizeof(_template) / sizeof(_template[0]));
  |  |  ------------------
  |  |  |  |  208|  7.87k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.87k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  770|       |    /* get the object handle */
  771|  7.87k|    if (searchType == nssTokenSearchType_TokenForced) {
  ------------------
  |  Branch (771:9): [True: 0, False: 7.87k]
  ------------------
  772|      0|        objects = find_objects(token, sessionOpt,
  773|      0|                               cert_template, ctsize,
  774|      0|                               1, statusOpt);
  775|  7.87k|    } else {
  776|  7.87k|        objects = nssToken_FindObjectsByTemplate(token, sessionOpt,
  777|  7.87k|                                                 cert_template, ctsize,
  778|  7.87k|                                                 1, statusOpt);
  779|  7.87k|    }
  780|  7.87k|    if (objects) {
  ------------------
  |  Branch (780:9): [True: 0, False: 7.87k]
  ------------------
  781|      0|        rvObject = objects[0];
  782|      0|        nss_ZFreeIf(objects);
  783|      0|    }
  784|       |
  785|  7.87k|    return rvObject;
  786|  7.87k|}
nssToken_FindTrustForCertificate:
 1037|  15.5k|{
 1038|  15.5k|    CK_OBJECT_CLASS tobjc = CKO_NSS_TRUST;
  ------------------
  |  |   37|  15.5k|#define CKO_NSS_TRUST (CKO_NSS + 3)
  |  |  ------------------
  |  |  |  |   33|  15.5k|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|  15.5k|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  15.5k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1039|  15.5k|    CK_ATTRIBUTE_PTR attr;
 1040|  15.5k|    CK_ATTRIBUTE tobj_template[5];
 1041|  15.5k|    CK_ULONG tobj_size;
 1042|  15.5k|    nssSession *session = sessionOpt ? sessionOpt : token->defaultSession;
  ------------------
  |  Branch (1042:27): [True: 0, False: 15.5k]
  ------------------
 1043|  15.5k|    nssCryptokiObject *object = NULL, **objects;
 1044|       |
 1045|       |    /* Don't ask the module to use an invalid session handle. */
 1046|  15.5k|    if (!session || session->handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  15.5k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1046:9): [True: 0, False: 15.5k]
  |  Branch (1046:21): [True: 0, False: 15.5k]
  ------------------
 1047|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1048|      0|        return object;
 1049|      0|    }
 1050|       |
 1051|  15.5k|    NSS_CK_TEMPLATE_START(tobj_template, attr, tobj_size);
  ------------------
  |  |   30|  15.5k|    attr = _template;                                \
  |  |   31|  15.5k|    size = 0;
  ------------------
 1052|  15.5k|    if (searchType == nssTokenSearchType_TokenOnly) {
  ------------------
  |  Branch (1052:9): [True: 15.5k, False: 0]
  ------------------
 1053|  15.5k|        NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_TOKEN, &g_ck_true);
  ------------------
  |  |   34|  15.5k|    (pattr)->type = kind;                            \
  |  |   35|  15.5k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  15.5k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  15.5k|    (pattr)++;
  ------------------
 1054|  15.5k|    }
 1055|  15.5k|    NSS_CK_SET_ATTRIBUTE_VAR(attr, CKA_CLASS, tobjc);
  ------------------
  |  |   48|  15.5k|    (pattr)->type = kind;                          \
  |  |   49|  15.5k|    (pattr)->pValue = (CK_VOID_PTR)&var;           \
  |  |   50|  15.5k|    (pattr)->ulValueLen = (CK_ULONG)sizeof(var);   \
  |  |   51|  15.5k|    (pattr)++;
  ------------------
 1056|  15.5k|    NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_ISSUER, certIssuer);
  ------------------
  |  |   34|  15.5k|    (pattr)->type = kind;                            \
  |  |   35|  15.5k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  15.5k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  15.5k|    (pattr)++;
  ------------------
 1057|  15.5k|    NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_SERIAL_NUMBER, certSerial);
  ------------------
  |  |   34|  15.5k|    (pattr)->type = kind;                            \
  |  |   35|  15.5k|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|  15.5k|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|  15.5k|    (pattr)++;
  ------------------
 1058|  15.5k|    NSS_CK_TEMPLATE_FINISH(tobj_template, attr, tobj_size);
  ------------------
  |  |   60|  15.5k|    size = (attr) - (_template);                      \
  |  |   61|  15.5k|    PR_ASSERT(size <= sizeof(_template) / sizeof(_template[0]));
  |  |  ------------------
  |  |  |  |  208|  15.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 15.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1059|  15.5k|    objects = nssToken_FindObjectsByTemplate(token, session,
 1060|  15.5k|                                             tobj_template, tobj_size,
 1061|  15.5k|                                             1, NULL);
 1062|  15.5k|    if (objects) {
  ------------------
  |  Branch (1062:9): [True: 0, False: 15.5k]
  ------------------
 1063|      0|        object = objects[0];
 1064|      0|        nss_ZFreeIf(objects);
 1065|      0|    }
 1066|  15.5k|    return object;
 1067|  15.5k|}
nssToken_TraverseCertificates:
 1365|      2|{
 1366|      2|    CK_RV ckrv;
 1367|      2|    CK_ULONG count;
 1368|      2|    CK_OBJECT_HANDLE *objectHandles;
 1369|      2|    CK_ATTRIBUTE_PTR attr;
 1370|      2|    CK_ATTRIBUTE cert_template[2];
 1371|      2|    CK_ULONG ctsize;
 1372|      2|    NSSArena *arena;
 1373|      2|    PRUint32 arraySize, numHandles;
 1374|      2|    nssCryptokiObject **objects;
 1375|      2|    void *epv = nssToken_GetCryptokiEPV(token);
 1376|      2|    nssSession *session = (sessionOpt) ? sessionOpt : token->defaultSession;
  ------------------
  |  Branch (1376:27): [True: 2, False: 0]
  ------------------
 1377|       |
 1378|       |    /* Don't ask the module to use an invalid session handle. */
 1379|      2|    if (!session || session->handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1379:9): [True: 0, False: 2]
  |  Branch (1379:21): [True: 0, False: 2]
  ------------------
 1380|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1381|      0|        return PR_FAILURE;
 1382|      0|    }
 1383|       |
 1384|       |    /* template for all certs */
 1385|      2|    NSS_CK_TEMPLATE_START(cert_template, attr, ctsize);
  ------------------
  |  |   30|      2|    attr = _template;                                \
  |  |   31|      2|    size = 0;
  ------------------
 1386|      2|    if (searchType == nssTokenSearchType_SessionOnly) {
  ------------------
  |  Branch (1386:9): [True: 0, False: 2]
  ------------------
 1387|      0|        NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_TOKEN, &g_ck_false);
  ------------------
  |  |   34|      0|    (pattr)->type = kind;                            \
  |  |   35|      0|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|      0|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|      0|    (pattr)++;
  ------------------
 1388|      2|    } else if (searchType == nssTokenSearchType_TokenOnly ||
  ------------------
  |  Branch (1388:16): [True: 2, False: 0]
  ------------------
 1389|      2|               searchType == nssTokenSearchType_TokenForced) {
  ------------------
  |  Branch (1389:16): [True: 0, False: 0]
  ------------------
 1390|      2|        NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_TOKEN, &g_ck_true);
  ------------------
  |  |   34|      2|    (pattr)->type = kind;                            \
  |  |   35|      2|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|      2|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|      2|    (pattr)++;
  ------------------
 1391|      2|    }
 1392|      2|    NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_CLASS, &g_ck_class_cert);
  ------------------
  |  |   34|      2|    (pattr)->type = kind;                            \
  |  |   35|      2|    (pattr)->pValue = (CK_VOID_PTR)(item)->data;     \
  |  |   36|      2|    (pattr)->ulValueLen = (CK_ULONG)(item)->size;    \
  |  |   37|      2|    (pattr)++;
  ------------------
 1393|      2|    NSS_CK_TEMPLATE_FINISH(cert_template, attr, ctsize);
  ------------------
  |  |   60|      2|    size = (attr) - (_template);                      \
  |  |   61|      2|    PR_ASSERT(size <= sizeof(_template) / sizeof(_template[0]));
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1394|       |
 1395|       |    /* the arena is only for the array of object handles */
 1396|      2|    arena = nssArena_Create();
 1397|      2|    if (!arena) {
  ------------------
  |  Branch (1397:9): [True: 0, False: 2]
  ------------------
 1398|      0|        return PR_FAILURE;
 1399|      0|    }
 1400|      2|    arraySize = OBJECT_STACK_SIZE;
  ------------------
  |  |   24|      2|#define OBJECT_STACK_SIZE 16
  ------------------
 1401|      2|    numHandles = 0;
 1402|      2|    objectHandles = nss_ZNEWARRAY(arena, CK_OBJECT_HANDLE, arraySize);
  ------------------
  |  |  371|      2|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
 1403|      2|    if (!objectHandles) {
  ------------------
  |  Branch (1403:9): [True: 0, False: 2]
  ------------------
 1404|      0|        goto loser;
 1405|      0|    }
 1406|      2|    nssSession_EnterMonitor(session); /* ==== session lock === */
 1407|       |    /* Initialize the find with the template */
 1408|      2|    ckrv = CKAPI(epv)->C_FindObjectsInit(session->handle,
  ------------------
  |  |   24|      2|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
 1409|      2|                                         cert_template, ctsize);
 1410|      2|    if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1410:9): [True: 0, False: 2]
  ------------------
 1411|      0|        nssSession_ExitMonitor(session);
 1412|      0|        goto loser;
 1413|      0|    }
 1414|      2|    while (PR_TRUE) {
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  |  |  ------------------
  |  |  |  Branch (437:17): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1415|       |        /* Issue the find for up to arraySize - numHandles objects */
 1416|      2|        ckrv = CKAPI(epv)->C_FindObjects(session->handle,
  ------------------
  |  |   24|      2|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
 1417|      2|                                         objectHandles + numHandles,
 1418|      2|                                         arraySize - numHandles,
 1419|      2|                                         &count);
 1420|      2|        if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1420:13): [True: 0, False: 2]
  ------------------
 1421|      0|            nssSession_ExitMonitor(session);
 1422|      0|            goto loser;
 1423|      0|        }
 1424|       |        /* bump the number of found objects */
 1425|      2|        numHandles += count;
 1426|      2|        if (numHandles < arraySize) {
  ------------------
  |  Branch (1426:13): [True: 2, False: 0]
  ------------------
 1427|      2|            break;
 1428|      2|        }
 1429|       |        /* the array is filled, double it and continue */
 1430|      0|        arraySize *= 2;
 1431|      0|        objectHandles = nss_ZREALLOCARRAY(objectHandles,
  ------------------
  |  |  391|      0|    ((type *)nss_ZRealloc((p), sizeof(type) * (quantity)))
  ------------------
 1432|      0|                                          CK_OBJECT_HANDLE,
 1433|      0|                                          arraySize);
 1434|      0|        if (!objectHandles) {
  ------------------
  |  Branch (1434:13): [True: 0, False: 0]
  ------------------
 1435|      0|            nssSession_ExitMonitor(session);
 1436|      0|            goto loser;
 1437|      0|        }
 1438|      0|    }
 1439|      2|    ckrv = CKAPI(epv)->C_FindObjectsFinal(session->handle);
  ------------------
  |  |   24|      2|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
 1440|      2|    nssSession_ExitMonitor(session); /* ==== end session lock === */
 1441|      2|    if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1441:9): [True: 0, False: 2]
  ------------------
 1442|      0|        goto loser;
 1443|      0|    }
 1444|      2|    if (numHandles > 0) {
  ------------------
  |  Branch (1444:9): [True: 0, False: 2]
  ------------------
 1445|      0|        objects = create_objects_from_handles(token, session,
 1446|      0|                                              objectHandles, numHandles);
 1447|      0|        if (objects) {
  ------------------
  |  Branch (1447:13): [True: 0, False: 0]
  ------------------
 1448|      0|            nssCryptokiObject **op;
 1449|      0|            for (op = objects; *op; op++) {
  ------------------
  |  Branch (1449:32): [True: 0, False: 0]
  ------------------
 1450|      0|                (void)(*callback)(*op, arg);
 1451|      0|            }
 1452|      0|            nss_ZFreeIf(objects);
 1453|      0|        }
 1454|      0|    }
 1455|      2|    nssArena_Destroy(arena);
 1456|      2|    return PR_SUCCESS;
 1457|      0|loser:
 1458|      0|    nssArena_Destroy(arena);
 1459|      0|    return PR_FAILURE;
 1460|      2|}
devtoken.c:find_objects:
  240|  23.4k|{
  241|  23.4k|    CK_RV ckrv = CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  242|  23.4k|    CK_ULONG count;
  243|  23.4k|    CK_OBJECT_HANDLE *objectHandles = NULL;
  244|  23.4k|    CK_OBJECT_HANDLE staticObjects[OBJECT_STACK_SIZE];
  245|  23.4k|    PRUint32 arraySize, numHandles;
  246|  23.4k|    void *epv = nssToken_GetCryptokiEPV(tok);
  247|  23.4k|    nssCryptokiObject **objects;
  248|  23.4k|    nssSession *session = (sessionOpt) ? sessionOpt : tok->defaultSession;
  ------------------
  |  Branch (248:27): [True: 23.4k, False: 0]
  ------------------
  249|       |
  250|       |    /* Don't ask the module to use an invalid session handle. */
  251|  23.4k|    if (!session || session->handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  23.4k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (251:9): [True: 0, False: 23.4k]
  |  Branch (251:21): [True: 0, False: 23.4k]
  ------------------
  252|      0|        ckrv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  253|      0|        goto loser;
  254|      0|    }
  255|       |
  256|       |    /* the arena is only for the array of object handles */
  257|  23.4k|    if (maximumOpt > 0) {
  ------------------
  |  Branch (257:9): [True: 23.4k, False: 0]
  ------------------
  258|  23.4k|        arraySize = maximumOpt;
  259|  23.4k|    } else {
  260|      0|        arraySize = OBJECT_STACK_SIZE;
  ------------------
  |  |   24|      0|#define OBJECT_STACK_SIZE 16
  ------------------
  261|      0|    }
  262|  23.4k|    numHandles = 0;
  263|  23.4k|    if (arraySize <= OBJECT_STACK_SIZE) {
  ------------------
  |  |   24|  23.4k|#define OBJECT_STACK_SIZE 16
  ------------------
  |  Branch (263:9): [True: 23.4k, False: 0]
  ------------------
  264|  23.4k|        objectHandles = staticObjects;
  265|  23.4k|    } else {
  266|      0|        objectHandles = nss_ZNEWARRAY(NULL, CK_OBJECT_HANDLE, arraySize);
  ------------------
  |  |  371|      0|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
  267|      0|    }
  268|  23.4k|    if (!objectHandles) {
  ------------------
  |  Branch (268:9): [True: 0, False: 23.4k]
  ------------------
  269|      0|        ckrv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  270|      0|        goto loser;
  271|      0|    }
  272|  23.4k|    nssSession_EnterMonitor(session); /* ==== session lock === */
  273|       |    /* Initialize the find with the template */
  274|  23.4k|    ckrv = CKAPI(epv)->C_FindObjectsInit(session->handle,
  ------------------
  |  |   24|  23.4k|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
  275|  23.4k|                                         obj_template, otsize);
  276|  23.4k|    if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (276:9): [True: 0, False: 23.4k]
  ------------------
  277|      0|        nssSession_ExitMonitor(session);
  278|      0|        goto loser;
  279|      0|    }
  280|  23.4k|    while (PR_TRUE) {
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  |  |  ------------------
  |  |  |  Branch (437:17): [Folded - Ignored]
  |  |  ------------------
  ------------------
  281|       |        /* Issue the find for up to arraySize - numHandles objects */
  282|  23.4k|        ckrv = CKAPI(epv)->C_FindObjects(session->handle,
  ------------------
  |  |   24|  23.4k|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
  283|  23.4k|                                         objectHandles + numHandles,
  284|  23.4k|                                         arraySize - numHandles,
  285|  23.4k|                                         &count);
  286|  23.4k|        if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (286:13): [True: 0, False: 23.4k]
  ------------------
  287|      0|            nssSession_ExitMonitor(session);
  288|      0|            goto loser;
  289|      0|        }
  290|       |        /* bump the number of found objects */
  291|  23.4k|        numHandles += count;
  292|  23.4k|        if (maximumOpt > 0 || numHandles < arraySize) {
  ------------------
  |  Branch (292:13): [True: 23.4k, False: 0]
  |  Branch (292:31): [True: 0, False: 0]
  ------------------
  293|       |            /* When a maximum is provided, the search is done all at once,
  294|       |             * so the search is finished.  If the number returned was less
  295|       |             * than the number sought, the search is finished.
  296|       |             */
  297|  23.4k|            break;
  298|  23.4k|        }
  299|       |        /* the array is filled, double it and continue */
  300|      0|        arraySize *= 2;
  301|      0|        if (objectHandles == staticObjects) {
  ------------------
  |  Branch (301:13): [True: 0, False: 0]
  ------------------
  302|      0|            objectHandles = nss_ZNEWARRAY(NULL, CK_OBJECT_HANDLE, arraySize);
  ------------------
  |  |  371|      0|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
  303|      0|            if (objectHandles) {
  ------------------
  |  Branch (303:17): [True: 0, False: 0]
  ------------------
  304|      0|                PORT_Memcpy(objectHandles, staticObjects,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  305|      0|                            OBJECT_STACK_SIZE * sizeof(objectHandles[1]));
  ------------------
  |  |   24|      0|#define OBJECT_STACK_SIZE 16
  ------------------
  306|      0|            }
  307|      0|        } else {
  308|      0|            objectHandles = nss_ZREALLOCARRAY(objectHandles,
  ------------------
  |  |  391|      0|    ((type *)nss_ZRealloc((p), sizeof(type) * (quantity)))
  ------------------
  309|      0|                                              CK_OBJECT_HANDLE,
  310|      0|                                              arraySize);
  311|      0|        }
  312|      0|        if (!objectHandles) {
  ------------------
  |  Branch (312:13): [True: 0, False: 0]
  ------------------
  313|      0|            nssSession_ExitMonitor(session);
  314|      0|            ckrv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  315|      0|            goto loser;
  316|      0|        }
  317|      0|    }
  318|  23.4k|    ckrv = CKAPI(epv)->C_FindObjectsFinal(session->handle);
  ------------------
  |  |   24|  23.4k|    ((CK_FUNCTION_LIST_PTR)(epv))
  ------------------
  319|  23.4k|    nssSession_ExitMonitor(session); /* ==== end session lock === */
  320|  23.4k|    if (ckrv != CKR_OK) {
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (320:9): [True: 0, False: 23.4k]
  ------------------
  321|      0|        goto loser;
  322|      0|    }
  323|  23.4k|    if (numHandles > 0) {
  ------------------
  |  Branch (323:9): [True: 0, False: 23.4k]
  ------------------
  324|      0|        objects = create_objects_from_handles(tok, session,
  325|      0|                                              objectHandles, numHandles);
  326|  23.4k|    } else {
  327|  23.4k|        nss_SetError(NSS_ERROR_NOT_FOUND);
  328|  23.4k|        objects = NULL;
  329|  23.4k|    }
  330|  23.4k|    if (objectHandles && objectHandles != staticObjects) {
  ------------------
  |  Branch (330:9): [True: 23.4k, False: 0]
  |  Branch (330:26): [True: 0, False: 23.4k]
  ------------------
  331|      0|        nss_ZFreeIf(objectHandles);
  332|      0|    }
  333|  23.4k|    if (statusOpt)
  ------------------
  |  Branch (333:9): [True: 7.87k, False: 15.5k]
  ------------------
  334|  7.87k|        *statusOpt = PR_SUCCESS;
  335|  23.4k|    return objects;
  336|      0|loser:
  337|      0|    if (objectHandles && objectHandles != staticObjects) {
  ------------------
  |  Branch (337:9): [True: 0, False: 0]
  |  Branch (337:26): [True: 0, False: 0]
  ------------------
  338|      0|        nss_ZFreeIf(objectHandles);
  339|      0|    }
  340|       |    /*
  341|       |     * These errors should be treated the same as if the objects just weren't
  342|       |     * found..
  343|       |     */
  344|      0|    if ((ckrv == CKR_ATTRIBUTE_TYPE_INVALID) ||
  ------------------
  |  | 1408|      0|#define CKR_ATTRIBUTE_TYPE_INVALID 0x00000012UL
  ------------------
  |  Branch (344:9): [True: 0, False: 0]
  ------------------
  345|      0|        (ckrv == CKR_ATTRIBUTE_VALUE_INVALID) ||
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  |  Branch (345:9): [True: 0, False: 0]
  ------------------
  346|      0|        (ckrv == CKR_DATA_INVALID) ||
  ------------------
  |  | 1414|      0|#define CKR_DATA_INVALID 0x00000020UL
  ------------------
  |  Branch (346:9): [True: 0, False: 0]
  ------------------
  347|      0|        (ckrv == CKR_DATA_LEN_RANGE) ||
  ------------------
  |  | 1415|      0|#define CKR_DATA_LEN_RANGE 0x00000021UL
  ------------------
  |  Branch (347:9): [True: 0, False: 0]
  ------------------
  348|      0|        (ckrv == CKR_FUNCTION_NOT_SUPPORTED) ||
  ------------------
  |  | 1426|      0|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
  |  Branch (348:9): [True: 0, False: 0]
  ------------------
  349|      0|        (ckrv == CKR_TEMPLATE_INCOMPLETE) ||
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
  |  Branch (349:9): [True: 0, False: 0]
  ------------------
  350|      0|        (ckrv == CKR_TEMPLATE_INCONSISTENT)) {
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
  |  Branch (350:9): [True: 0, False: 0]
  ------------------
  351|       |
  352|      0|        nss_SetError(NSS_ERROR_NOT_FOUND);
  353|      0|        if (statusOpt)
  ------------------
  |  Branch (353:13): [True: 0, False: 0]
  ------------------
  354|      0|            *statusOpt = PR_SUCCESS;
  355|      0|    } else {
  356|      0|        nss_SetError(ckrv);
  357|      0|        nss_SetError(NSS_ERROR_PKCS11);
  358|      0|        if (statusOpt)
  ------------------
  |  Branch (358:13): [True: 0, False: 0]
  ------------------
  359|      0|            *statusOpt = PR_FAILURE;
  360|      0|    }
  361|      0|    return (nssCryptokiObject **)NULL;
  362|  23.4k|}

nssSlotArray_Destroy:
  129|  11.7k|{
  130|  11.7k|    if (slots) {
  ------------------
  |  Branch (130:9): [True: 11.7k, False: 0]
  ------------------
  131|  11.7k|        NSSSlot **slotp;
  132|  35.1k|        for (slotp = slots; *slotp; slotp++) {
  ------------------
  |  Branch (132:29): [True: 23.4k, False: 11.7k]
  ------------------
  133|  23.4k|            nssSlot_Destroy(*slotp);
  134|  23.4k|        }
  135|  11.7k|        nss_ZFreeIf(slots);
  136|  11.7k|    }
  137|  11.7k|}
nssTokenObjectCache_Destroy:
  259|      2|{
  260|      2|    if (cache) {
  ------------------
  |  Branch (260:9): [True: 0, False: 2]
  ------------------
  261|      0|        clear_cache(cache);
  262|      0|        if (cache->lock) {
  ------------------
  |  Branch (262:13): [True: 0, False: 0]
  ------------------
  263|      0|            PZ_DestroyLock(cache->lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  264|      0|        }
  265|      0|        nss_ZFreeIf(cache);
  266|      0|    }
  267|      2|}

rijndael_native_key_expansion:
  127|   326k|{
  128|   326k|    switch (Nk) {
  129|  11.9k|        case 4:
  ------------------
  |  Branch (129:9): [True: 11.9k, False: 314k]
  ------------------
  130|  11.9k|            native_key_expansion128(cx, key);
  131|  11.9k|            return;
  132|      0|        case 6:
  ------------------
  |  Branch (132:9): [True: 0, False: 326k]
  ------------------
  133|      0|            native_key_expansion192(cx, key);
  134|      0|            return;
  135|   314k|        case 8:
  ------------------
  |  Branch (135:9): [True: 314k, False: 11.9k]
  ------------------
  136|   314k|            native_key_expansion256(cx, key);
  137|   314k|            return;
  138|      0|        default:
  ------------------
  |  Branch (138:9): [True: 0, False: 326k]
  ------------------
  139|       |            /* This shouldn't happen (checked by the caller). */
  140|      0|            return;
  141|   326k|    }
  142|   326k|}
rijndael_native_encryptBlock:
  148|   326k|{
  149|   326k|    unsigned int i;
  150|   326k|    pre_align __m128i m post_align = _mm_loadu_si128((__m128i *)input);
  151|   326k|    m = _mm_xor_si128(m, cx->k.keySchedule[0]);
  152|  4.52M|    for (i = 1; i < cx->Nr; ++i) {
  ------------------
  |  Branch (152:17): [True: 4.19M, False: 326k]
  ------------------
  153|  4.19M|        m = _mm_aesenc_si128(m, cx->k.keySchedule[i]);
  154|  4.19M|    }
  155|   326k|    m = _mm_aesenclast_si128(m, cx->k.keySchedule[cx->Nr]);
  156|   326k|    _mm_storeu_si128((__m128i *)output, m);
  157|   326k|}
aes-x86.c:native_key_expansion128:
   23|  11.9k|{
   24|  11.9k|    __m128i *keySchedule = cx->k.keySchedule;
   25|  11.9k|    pre_align __m128i tmp_key post_align;
   26|  11.9k|    pre_align __m128i tmp post_align;
   27|  11.9k|    keySchedule[0] = _mm_loadu_si128((__m128i *)key);
   28|  11.9k|    EXPAND_KEY128(keySchedule[0], 0x01, keySchedule[1]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   29|  11.9k|    EXPAND_KEY128(keySchedule[1], 0x02, keySchedule[2]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   30|  11.9k|    EXPAND_KEY128(keySchedule[2], 0x04, keySchedule[3]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   31|  11.9k|    EXPAND_KEY128(keySchedule[3], 0x08, keySchedule[4]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   32|  11.9k|    EXPAND_KEY128(keySchedule[4], 0x10, keySchedule[5]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   33|  11.9k|    EXPAND_KEY128(keySchedule[5], 0x20, keySchedule[6]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   34|  11.9k|    EXPAND_KEY128(keySchedule[6], 0x40, keySchedule[7]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   35|  11.9k|    EXPAND_KEY128(keySchedule[7], 0x80, keySchedule[8]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   36|  11.9k|    EXPAND_KEY128(keySchedule[8], 0x1B, keySchedule[9]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   37|  11.9k|    EXPAND_KEY128(keySchedule[9], 0x36, keySchedule[10]);
  ------------------
  |  |   14|  11.9k|    tmp_key = _mm_aeskeygenassist_si128(k, rcon);     \
  |  |   15|  11.9k|    tmp_key = _mm_shuffle_epi32(tmp_key, 0xFF);       \
  |  |   16|  11.9k|    tmp = _mm_xor_si128(k, _mm_slli_si128(k, 4));     \
  |  |   17|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   18|  11.9k|    tmp = _mm_xor_si128(tmp, _mm_slli_si128(tmp, 4)); \
  |  |   19|  11.9k|    res = _mm_xor_si128(tmp, tmp_key)
  ------------------
   38|  11.9k|}
aes-x86.c:native_key_expansion256:
   98|   314k|{
   99|   314k|    __m128i *keySchedule = cx->k.keySchedule;
  100|   314k|    pre_align __m128i tmp_key post_align;
  101|   314k|    pre_align __m128i tmp1 post_align;
  102|   314k|    pre_align __m128i tmp2 post_align;
  103|   314k|    keySchedule[0] = _mm_loadu_si128((__m128i *)key);
  104|   314k|    keySchedule[1] = _mm_loadu_si128((__m128i *)(key + 16));
  105|   314k|    EXPAND_KEY256(keySchedule[2], keySchedule[3], keySchedule[0],
  ------------------
  |  |   93|   314k|    EXPAND_KEY256_PART(res1, rcon, k1, k2, 0xFF); \
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  |  |   94|   314k|    EXPAND_KEY256_PART(res2, 0x00, k2, res1, 0xAA)
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  ------------------
  106|   314k|                  keySchedule[1], 0x01);
  107|   314k|    EXPAND_KEY256(keySchedule[4], keySchedule[5], keySchedule[2],
  ------------------
  |  |   93|   314k|    EXPAND_KEY256_PART(res1, rcon, k1, k2, 0xFF); \
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  |  |   94|   314k|    EXPAND_KEY256_PART(res2, 0x00, k2, res1, 0xAA)
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  ------------------
  108|   314k|                  keySchedule[3], 0x02);
  109|   314k|    EXPAND_KEY256(keySchedule[6], keySchedule[7], keySchedule[4],
  ------------------
  |  |   93|   314k|    EXPAND_KEY256_PART(res1, rcon, k1, k2, 0xFF); \
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  |  |   94|   314k|    EXPAND_KEY256_PART(res2, 0x00, k2, res1, 0xAA)
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  ------------------
  110|   314k|                  keySchedule[5], 0x04);
  111|   314k|    EXPAND_KEY256(keySchedule[8], keySchedule[9], keySchedule[6],
  ------------------
  |  |   93|   314k|    EXPAND_KEY256_PART(res1, rcon, k1, k2, 0xFF); \
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  |  |   94|   314k|    EXPAND_KEY256_PART(res2, 0x00, k2, res1, 0xAA)
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  ------------------
  112|   314k|                  keySchedule[7], 0x08);
  113|   314k|    EXPAND_KEY256(keySchedule[10], keySchedule[11], keySchedule[8],
  ------------------
  |  |   93|   314k|    EXPAND_KEY256_PART(res1, rcon, k1, k2, 0xFF); \
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  |  |   94|   314k|    EXPAND_KEY256_PART(res2, 0x00, k2, res1, 0xAA)
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  ------------------
  114|   314k|                  keySchedule[9], 0x10);
  115|   314k|    EXPAND_KEY256(keySchedule[12], keySchedule[13], keySchedule[10],
  ------------------
  |  |   93|   314k|    EXPAND_KEY256_PART(res1, rcon, k1, k2, 0xFF); \
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  |  |   94|   314k|    EXPAND_KEY256_PART(res2, 0x00, k2, res1, 0xAA)
  |  |  ------------------
  |  |  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  |  |  ------------------
  ------------------
  116|   314k|                  keySchedule[11], 0x20);
  117|   314k|    EXPAND_KEY256_PART(keySchedule[14], 0x40, keySchedule[12],
  ------------------
  |  |   85|   314k|    tmp_key = _mm_shuffle_epi32(_mm_aeskeygenassist_si128(k2x, rconx), X);    \
  |  |   86|   314k|    tmp2 = _mm_slli_si128(k1x, 4);                                            \
  |  |   87|   314k|    tmp1 = _mm_xor_si128(k1x, tmp2);                                          \
  |  |   88|   314k|    tmp2 = _mm_slli_si128(tmp2, 4);                                           \
  |  |   89|   314k|    tmp1 = _mm_xor_si128(_mm_xor_si128(tmp1, tmp2), _mm_slli_si128(tmp2, 4)); \
  |  |   90|   314k|    res = _mm_xor_si128(tmp1, tmp_key);
  ------------------
  118|   314k|                       keySchedule[13], 0xFF);
  119|   314k|}

HMAC_Destroy:
   27|  1.16M|{
   28|  1.16M|    if (cx == NULL)
  ------------------
  |  Branch (28:9): [True: 0, False: 1.16M]
  ------------------
   29|      0|        return;
   30|       |
   31|  1.16M|    PORT_Assert(!freeit == !cx->wasAllocated);
  ------------------
  |  |  120|  1.16M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.16M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.16M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   32|  1.16M|    if (cx->hash != NULL) {
  ------------------
  |  Branch (32:9): [True: 1.16M, False: 0]
  ------------------
   33|  1.16M|        cx->hashobj->destroy(cx->hash, PR_TRUE);
  ------------------
  |  |  437|  1.16M|#define PR_TRUE 1
  ------------------
   34|  1.16M|        PORT_Memset(cx, 0, sizeof *cx);
  ------------------
  |  |  182|  1.16M|#define PORT_Memset memset
  ------------------
   35|  1.16M|    }
   36|  1.16M|    if (freeit)
  ------------------
  |  Branch (36:9): [True: 1.16M, False: 0]
  ------------------
   37|  1.16M|        PORT_Free(cx);
  ------------------
  |  |   60|  1.16M|#define PORT_Free PORT_Free_Util
  ------------------
   38|  1.16M|}
HMAC_Init:
   85|  1.16M|{
   86|  1.16M|    SECStatus rv;
   87|       |
   88|  1.16M|    if (cx == NULL) {
  ------------------
  |  Branch (88:9): [True: 0, False: 1.16M]
  ------------------
   89|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   90|      0|        return SECFailure;
   91|      0|    }
   92|  1.16M|    cx->wasAllocated = PR_FALSE;
  ------------------
  |  |  438|  1.16M|#define PR_FALSE 0
  ------------------
   93|  1.16M|    cx->hashobj = hash_obj;
   94|  1.16M|    cx->hash = cx->hashobj->create();
   95|  1.16M|    if (cx->hash == NULL)
  ------------------
  |  Branch (95:9): [True: 0, False: 1.16M]
  ------------------
   96|      0|        goto loser;
   97|       |
   98|  1.16M|    rv = hmac_initKey(cx, secret, secret_len, isFIPS);
   99|  1.16M|    if (rv != SECSuccess)
  ------------------
  |  Branch (99:9): [True: 0, False: 1.16M]
  ------------------
  100|      0|        goto loser;
  101|       |
  102|  1.16M|    return rv;
  103|      0|loser:
  104|      0|    if (cx->hash != NULL)
  ------------------
  |  Branch (104:9): [True: 0, False: 0]
  ------------------
  105|      0|        cx->hashobj->destroy(cx->hash, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  106|      0|    return SECFailure;
  107|  1.16M|}
HMAC_Create:
  112|  1.16M|{
  113|  1.16M|    SECStatus rv;
  114|  1.16M|    HMACContext *cx = PORT_ZNew(HMACContext);
  ------------------
  |  |  148|  1.16M|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  1.16M|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  115|  1.16M|    if (cx == NULL)
  ------------------
  |  Branch (115:9): [True: 0, False: 1.16M]
  ------------------
  116|      0|        return NULL;
  117|  1.16M|    rv = HMAC_Init(cx, hash_obj, secret, secret_len, isFIPS);
  118|  1.16M|    cx->wasAllocated = PR_TRUE;
  ------------------
  |  |  437|  1.16M|#define PR_TRUE 1
  ------------------
  119|  1.16M|    if (rv != SECSuccess) {
  ------------------
  |  Branch (119:9): [True: 0, False: 1.16M]
  ------------------
  120|      0|        PORT_Free(cx); /* contains no secret info */
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  121|      0|        cx = NULL;
  122|      0|    }
  123|  1.16M|    return cx;
  124|  1.16M|}
HMAC_ReInit:
  131|    772|{
  132|    772|    PRBool wasAllocated;
  133|    772|    SECStatus rv;
  134|       |
  135|       |    /* if we are using the same hash, keep the hash contexts and only
  136|       |     * init the key */
  137|    772|    if ((cx->hashobj == hash_obj) && (cx->hash != NULL)) {
  ------------------
  |  Branch (137:9): [True: 772, False: 0]
  |  Branch (137:38): [True: 772, False: 0]
  ------------------
  138|    772|        return hmac_initKey(cx, secret, secret_len, isFIPS);
  139|    772|    }
  140|       |    /* otherwise we destroy the contents of the context and
  141|       |     * initalize it from scratch. We need to preseve the current state
  142|       |     * of wasAllocated to the final destroy works correctly */
  143|      0|    wasAllocated = cx->wasAllocated;
  144|      0|    cx->wasAllocated = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  145|      0|    HMAC_Destroy(cx, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  146|      0|    rv = HMAC_Init(cx, hash_obj, secret, secret_len, isFIPS);
  147|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (147:9): [True: 0, False: 0]
  ------------------
  148|      0|        return rv;
  149|      0|    }
  150|      0|    cx->wasAllocated = wasAllocated;
  151|      0|    return SECSuccess;
  152|      0|}
HMAC_Begin:
  156|  2.08M|{
  157|       |    /* start inner hash */
  158|  2.08M|    cx->hashobj->begin(cx->hash);
  159|  2.08M|    cx->hashobj->update(cx->hash, cx->ipad, cx->hashobj->blocklength);
  160|  2.08M|}
HMAC_Update:
  164|  3.94M|{
  165|  3.94M|    cx->hashobj->update(cx->hash, data, data_len);
  166|  3.94M|}
HMAC_Finish:
  171|  2.02M|{
  172|  2.02M|    if (max_result_len < cx->hashobj->length) {
  ------------------
  |  Branch (172:9): [True: 0, False: 2.02M]
  ------------------
  173|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  174|      0|        return SECFailure;
  175|      0|    }
  176|       |
  177|  2.02M|    cx->hashobj->end(cx->hash, result, result_len, max_result_len);
  178|  2.02M|    if (*result_len != cx->hashobj->length)
  ------------------
  |  Branch (178:9): [True: 0, False: 2.02M]
  ------------------
  179|      0|        return SECFailure;
  180|       |
  181|  2.02M|    cx->hashobj->begin(cx->hash);
  182|  2.02M|    cx->hashobj->update(cx->hash, cx->opad, cx->hashobj->blocklength);
  183|  2.02M|    cx->hashobj->update(cx->hash, result, *result_len);
  184|  2.02M|    cx->hashobj->end(cx->hash, result, result_len, max_result_len);
  185|  2.02M|    return SECSuccess;
  186|  2.02M|}
alghmac.c:hmac_initKey:
   43|  1.16M|{
   44|  1.16M|    unsigned int i;
   45|  1.16M|    unsigned char hashed_secret[HASH_LENGTH_MAX];
   46|       |
   47|       |    /* required by FIPS 198 Section 3 */
   48|  1.16M|    if (isFIPS && secret_len < cx->hashobj->length / 2) {
  ------------------
  |  Branch (48:9): [True: 1.54k, False: 1.16M]
  |  Branch (48:19): [True: 0, False: 1.54k]
  ------------------
   49|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   50|      0|        return SECFailure;
   51|      0|    }
   52|       |
   53|  1.16M|    if (secret_len > cx->hashobj->blocklength) {
  ------------------
  |  Branch (53:9): [True: 29.5k, False: 1.13M]
  ------------------
   54|  29.5k|        cx->hashobj->begin(cx->hash);
   55|  29.5k|        cx->hashobj->update(cx->hash, secret, secret_len);
   56|  29.5k|        PORT_Assert(cx->hashobj->length <= sizeof hashed_secret);
  ------------------
  |  |  120|  29.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 29.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   57|  29.5k|        cx->hashobj->end(cx->hash, hashed_secret, &secret_len,
   58|  29.5k|                         sizeof hashed_secret);
   59|  29.5k|        if (secret_len != cx->hashobj->length) {
  ------------------
  |  Branch (59:13): [True: 0, False: 29.5k]
  ------------------
   60|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   61|      0|            goto loser;
   62|      0|        }
   63|  29.5k|        secret = (const unsigned char *)&hashed_secret[0];
   64|  29.5k|    }
   65|       |
   66|  1.16M|    PORT_Memset(cx->ipad, 0x36, cx->hashobj->blocklength);
  ------------------
  |  |  182|  1.16M|#define PORT_Memset memset
  ------------------
   67|  1.16M|    PORT_Memset(cx->opad, 0x5c, cx->hashobj->blocklength);
  ------------------
  |  |  182|  1.16M|#define PORT_Memset memset
  ------------------
   68|       |
   69|       |    /* fold secret into padding */
   70|  53.1M|    for (i = 0; i < secret_len; i++) {
  ------------------
  |  Branch (70:17): [True: 52.0M, False: 1.16M]
  ------------------
   71|  52.0M|        cx->ipad[i] ^= secret[i];
   72|  52.0M|        cx->opad[i] ^= secret[i];
   73|  52.0M|    }
   74|  1.16M|    PORT_Memset(hashed_secret, 0, sizeof hashed_secret);
  ------------------
  |  |  182|  1.16M|#define PORT_Memset memset
  ------------------
   75|  1.16M|    return SECSuccess;
   76|       |
   77|      0|loser:
   78|      0|    PORT_Memset(hashed_secret, 0, sizeof hashed_secret);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
   79|      0|    return SECFailure;
   80|  1.16M|}

RC4_AllocateContext:
  110|  1.18k|{
  111|  1.18k|    return PORT_ZNew(RC4Context);
  ------------------
  |  |  148|  1.18k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  1.18k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  112|  1.18k|}
RC4_InitContext:
  118|  1.18k|{
  119|  1.18k|    unsigned int i;
  120|  1.18k|    PRUint8 j, tmp;
  121|  1.18k|    PRUint8 K[256];
  122|  1.18k|    PRUint8 *L;
  123|       |
  124|       |    /* verify the key length. */
  125|  1.18k|    PORT_Assert(len > 0 && len < ARCFOUR_STATE_SIZE);
  ------------------
  |  |  120|  1.18k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.37k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.18k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1.18k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  126|  1.18k|    if (len == 0 || len >= ARCFOUR_STATE_SIZE) {
  ------------------
  |  |   46|  1.18k|#define ARCFOUR_STATE_SIZE 256
  ------------------
  |  Branch (126:9): [True: 0, False: 1.18k]
  |  Branch (126:21): [True: 0, False: 1.18k]
  ------------------
  127|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  128|      0|        return SECFailure;
  129|      0|    }
  130|  1.18k|    if (cx == NULL) {
  ------------------
  |  Branch (130:9): [True: 0, False: 1.18k]
  ------------------
  131|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  132|      0|        return SECFailure;
  133|      0|    }
  134|       |    /* Initialize the state using array indices. */
  135|  1.18k|    memcpy(cx->S, Kinit, sizeof cx->S);
  136|       |    /* Fill in K repeatedly with values from key. */
  137|  1.18k|    L = K;
  138|  18.9k|    for (i = sizeof K; i > len; i -= len) {
  ------------------
  |  Branch (138:24): [True: 17.7k, False: 1.18k]
  ------------------
  139|  17.7k|        memcpy(L, key, len);
  140|  17.7k|        L += len;
  141|  17.7k|    }
  142|  1.18k|    memcpy(L, key, i);
  143|       |    /* Stir the state of the generator.  At this point it is assumed
  144|       |     * that the key is the size of the state buffer.  If this is not
  145|       |     * the case, the key bytes are repeated to fill the buffer.
  146|       |     */
  147|  1.18k|    j = 0;
  148|  1.18k|#define ARCFOUR_STATE_STIR(ii) \
  149|  1.18k|    j = j + cx->S[ii] + K[ii]; \
  150|  1.18k|    SWAP(cx->S[ii], cx->S[j]);
  151|   304k|    for (i = 0; i < ARCFOUR_STATE_SIZE; i++) {
  ------------------
  |  |   46|   304k|#define ARCFOUR_STATE_SIZE 256
  ------------------
  |  Branch (151:17): [True: 303k, False: 1.18k]
  ------------------
  152|   303k|        ARCFOUR_STATE_STIR(i);
  ------------------
  |  |  149|   303k|    j = j + cx->S[ii] + K[ii]; \
  |  |  150|   303k|    SWAP(cx->S[ii], cx->S[j]);
  |  |  ------------------
  |  |  |  |   51|   303k|    tmp = a;       \
  |  |  |  |   52|   303k|    a = b;         \
  |  |  |  |   53|   303k|    b = tmp;
  |  |  ------------------
  ------------------
  153|   303k|    }
  154|  1.18k|    cx->i = 0;
  155|  1.18k|    cx->j = 0;
  156|  1.18k|    return SECSuccess;
  157|  1.18k|}
RC4_CreateContext:
  164|  1.18k|{
  165|  1.18k|    RC4Context *cx = RC4_AllocateContext();
  166|  1.18k|    if (cx) {
  ------------------
  |  Branch (166:9): [True: 1.18k, False: 0]
  ------------------
  167|  1.18k|        SECStatus rv = RC4_InitContext(cx, key, len, NULL, 0, 0, 0);
  168|  1.18k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (168:13): [True: 0, False: 1.18k]
  ------------------
  169|      0|            PORT_ZFree(cx, sizeof(*cx));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  170|      0|            cx = NULL;
  171|      0|        }
  172|  1.18k|    }
  173|  1.18k|    return cx;
  174|  1.18k|}
RC4_DestroyContext:
  178|  1.18k|{
  179|  1.18k|    if (freeit)
  ------------------
  |  Branch (179:9): [True: 1.18k, False: 0]
  ------------------
  180|  1.18k|        PORT_ZFree(cx, sizeof(*cx));
  ------------------
  |  |   75|  1.18k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  181|  1.18k|}

CheckX86CPUSupport:
  102|      1|{
  103|      1|    unsigned long eax, ebx, ecx, edx;
  104|      1|    unsigned long eax7, ebx7, ecx7, edx7;
  105|      1|    char *disable_hw_aes = PR_GetEnvSecure("NSS_DISABLE_HW_AES");
  106|      1|    char *disable_pclmul = PR_GetEnvSecure("NSS_DISABLE_PCLMUL");
  107|      1|    char *disable_hw_sha = PR_GetEnvSecure("NSS_DISABLE_HW_SHA");
  108|      1|    char *disable_avx = PR_GetEnvSecure("NSS_DISABLE_AVX");
  109|      1|    char *disable_avx2 = PR_GetEnvSecure("NSS_DISABLE_AVX2");
  110|      1|    char *disable_adx = PR_GetEnvSecure("NSS_DISABLE_ADX");
  111|      1|    char *disable_ssse3 = PR_GetEnvSecure("NSS_DISABLE_SSSE3");
  112|      1|    char *disable_sse4_1 = PR_GetEnvSecure("NSS_DISABLE_SSE4_1");
  113|      1|    char *disable_sse4_2 = PR_GetEnvSecure("NSS_DISABLE_SSE4_2");
  114|      1|    freebl_cpuid(1, &eax, &ebx, &ecx, &edx);
  115|      1|    freebl_cpuid(7, &eax7, &ebx7, &ecx7, &edx7);
  116|      1|    aesni_support_ = (PRBool)((ecx & ECX_AESNI) != 0 && disable_hw_aes == NULL);
  ------------------
  |  |   81|      1|#define ECX_AESNI (1 << 25)
  ------------------
  |  Branch (116:31): [True: 1, False: 0]
  |  Branch (116:57): [True: 1, False: 0]
  ------------------
  117|      1|    clmul_support_ = (PRBool)((ecx & ECX_CLMUL) != 0 && disable_pclmul == NULL);
  ------------------
  |  |   82|      1|#define ECX_CLMUL (1 << 1)
  ------------------
  |  Branch (117:31): [True: 1, False: 0]
  |  Branch (117:57): [True: 1, False: 0]
  ------------------
  118|      1|    sha_support_ = (PRBool)((ebx7 & EBX_SHA) != 0 && disable_hw_sha == NULL);
  ------------------
  |  |   90|      1|#define EBX_SHA (1 << 29)
  ------------------
  |  Branch (118:29): [True: 1, False: 0]
  |  Branch (118:54): [True: 1, False: 0]
  ------------------
  119|       |    /* For AVX we ensure that:
  120|       |     *  - The AVX, OSXSAVE, and XSAVE bits of ECX from CPUID(EAX=1) are set, and
  121|       |     *  - the SSE and AVX state bits of XCR0 are set (check_xcr0_ymm).
  122|       |     */
  123|      1|    avx_support_ = (PRBool)((ecx & AVX_BITS) == AVX_BITS) && check_xcr0_ymm() &&
  ------------------
  |  |   96|      1|#define AVX_BITS (ECX_XSAVE | ECX_OSXSAVE | ECX_AVX)
  |  |  ------------------
  |  |  |  |   83|      1|#define ECX_XSAVE (1 << 26)
  |  |  ------------------
  |  |               #define AVX_BITS (ECX_XSAVE | ECX_OSXSAVE | ECX_AVX)
  |  |  ------------------
  |  |  |  |   84|      1|#define ECX_OSXSAVE (1 << 27)
  |  |  ------------------
  |  |               #define AVX_BITS (ECX_XSAVE | ECX_OSXSAVE | ECX_AVX)
  |  |  ------------------
  |  |  |  |   85|      1|#define ECX_AVX (1 << 28)
  |  |  ------------------
  ------------------
                  avx_support_ = (PRBool)((ecx & AVX_BITS) == AVX_BITS) && check_xcr0_ymm() &&
  ------------------
  |  |   96|      1|#define AVX_BITS (ECX_XSAVE | ECX_OSXSAVE | ECX_AVX)
  |  |  ------------------
  |  |  |  |   83|      1|#define ECX_XSAVE (1 << 26)
  |  |  ------------------
  |  |               #define AVX_BITS (ECX_XSAVE | ECX_OSXSAVE | ECX_AVX)
  |  |  ------------------
  |  |  |  |   84|      1|#define ECX_OSXSAVE (1 << 27)
  |  |  ------------------
  |  |               #define AVX_BITS (ECX_XSAVE | ECX_OSXSAVE | ECX_AVX)
  |  |  ------------------
  |  |  |  |   85|      1|#define ECX_AVX (1 << 28)
  |  |  ------------------
  ------------------
  |  Branch (123:20): [True: 1, False: 0]
  |  Branch (123:62): [True: 1, False: 0]
  ------------------
  124|      1|                   disable_avx == NULL;
  ------------------
  |  Branch (124:20): [True: 1, False: 0]
  ------------------
  125|       |    /* For AVX2 we ensure that:
  126|       |     *  - AVX is supported,
  127|       |     *  - the AVX2, BMI1, and BMI2 bits of EBX from CPUID(EAX=7) are set, and
  128|       |     *  - the FMA, and MOVBE bits of ECX from CPUID(EAX=1) are set.
  129|       |     * We do not check for LZCNT support.
  130|       |     */
  131|      1|    avx2_support_ = (PRBool)(avx_support_ == PR_TRUE &&
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  |  Branch (131:30): [True: 1, False: 0]
  ------------------
  132|      1|                             (ebx7 & AVX2_EBX_BITS) == AVX2_EBX_BITS &&
  ------------------
  |  |   97|      1|#define AVX2_EBX_BITS (EBX_AVX2 | EBX_BMI1 | EBX_BMI2)
  |  |  ------------------
  |  |  |  |   86|      1|#define EBX_AVX2 (1 << 5)
  |  |  ------------------
  |  |               #define AVX2_EBX_BITS (EBX_AVX2 | EBX_BMI1 | EBX_BMI2)
  |  |  ------------------
  |  |  |  |   88|      1|#define EBX_BMI1 (1 << 3)
  |  |  ------------------
  |  |               #define AVX2_EBX_BITS (EBX_AVX2 | EBX_BMI1 | EBX_BMI2)
  |  |  ------------------
  |  |  |  |   89|      1|#define EBX_BMI2 (1 << 8)
  |  |  ------------------
  ------------------
                                           (ebx7 & AVX2_EBX_BITS) == AVX2_EBX_BITS &&
  ------------------
  |  |   97|      2|#define AVX2_EBX_BITS (EBX_AVX2 | EBX_BMI1 | EBX_BMI2)
  |  |  ------------------
  |  |  |  |   86|      1|#define EBX_AVX2 (1 << 5)
  |  |  ------------------
  |  |               #define AVX2_EBX_BITS (EBX_AVX2 | EBX_BMI1 | EBX_BMI2)
  |  |  ------------------
  |  |  |  |   88|      1|#define EBX_BMI1 (1 << 3)
  |  |  ------------------
  |  |               #define AVX2_EBX_BITS (EBX_AVX2 | EBX_BMI1 | EBX_BMI2)
  |  |  ------------------
  |  |  |  |   89|      1|#define EBX_BMI2 (1 << 8)
  |  |  ------------------
  ------------------
  |  Branch (132:30): [True: 1, False: 0]
  ------------------
  133|      1|                             (ecx & AVX2_ECX_BITS) == AVX2_ECX_BITS &&
  ------------------
  |  |   98|      1|#define AVX2_ECX_BITS (ECX_FMA | ECX_MOVBE)
  |  |  ------------------
  |  |  |  |   91|      1|#define ECX_FMA (1 << 12)
  |  |  ------------------
  |  |               #define AVX2_ECX_BITS (ECX_FMA | ECX_MOVBE)
  |  |  ------------------
  |  |  |  |   92|      1|#define ECX_MOVBE (1 << 22)
  |  |  ------------------
  ------------------
                                           (ecx & AVX2_ECX_BITS) == AVX2_ECX_BITS &&
  ------------------
  |  |   98|      2|#define AVX2_ECX_BITS (ECX_FMA | ECX_MOVBE)
  |  |  ------------------
  |  |  |  |   91|      1|#define ECX_FMA (1 << 12)
  |  |  ------------------
  |  |               #define AVX2_ECX_BITS (ECX_FMA | ECX_MOVBE)
  |  |  ------------------
  |  |  |  |   92|      1|#define ECX_MOVBE (1 << 22)
  |  |  ------------------
  ------------------
  |  Branch (133:30): [True: 1, False: 0]
  ------------------
  134|      1|                             disable_avx2 == NULL);
  ------------------
  |  Branch (134:30): [True: 1, False: 0]
  ------------------
  135|       |    /* CPUID.(EAX=07H, ECX=0H):EBX.ADX[bit 19]=1 indicates
  136|       |    the processor supports ADCX and ADOX instructions.*/
  137|      1|    adx_support_ = (PRBool)((ebx7 & EBX_ADX) != 0 && disable_adx == NULL);
  ------------------
  |  |   87|      1|#define EBX_ADX (1 << 19)
  ------------------
  |  Branch (137:29): [True: 1, False: 0]
  |  Branch (137:54): [True: 1, False: 0]
  ------------------
  138|      1|    ssse3_support_ = (PRBool)((ecx & ECX_SSSE3) != 0 &&
  ------------------
  |  |   93|      1|#define ECX_SSSE3 (1 << 9)
  ------------------
  |  Branch (138:31): [True: 1, False: 0]
  ------------------
  139|      1|                              disable_ssse3 == NULL);
  ------------------
  |  Branch (139:31): [True: 1, False: 0]
  ------------------
  140|      1|    sse4_1_support_ = (PRBool)((ecx & ECX_SSE4_1) != 0 &&
  ------------------
  |  |   94|      1|#define ECX_SSE4_1 (1 << 19)
  ------------------
  |  Branch (140:32): [True: 1, False: 0]
  ------------------
  141|      1|                               disable_sse4_1 == NULL);
  ------------------
  |  Branch (141:32): [True: 1, False: 0]
  ------------------
  142|      1|    sse4_2_support_ = (PRBool)((ecx & ECX_SSE4_2) != 0 &&
  ------------------
  |  |   95|      1|#define ECX_SSE4_2 (1 << 20)
  ------------------
  |  Branch (142:32): [True: 1, False: 0]
  ------------------
  143|      1|                               disable_sse4_2 == NULL);
  ------------------
  |  Branch (143:32): [True: 1, False: 0]
  ------------------
  144|      1|}
aesni_support:
  440|   669k|{
  441|   669k|    return aesni_support_;
  442|   669k|}
clmul_support:
  445|   326k|{
  446|   326k|    return clmul_support_;
  447|   326k|}
sha_support:
  450|  1.23M|{
  451|  1.23M|    return sha_support_;
  452|  1.23M|}
ssse3_support:
  470|  1.23M|{
  471|  1.23M|    return ssse3_support_;
  472|  1.23M|}
sse4_1_support:
  475|  1.23M|{
  476|  1.23M|    return sse4_1_support_;
  477|  1.23M|}
arm_sha2_support:
  505|  1.23M|{
  506|  1.23M|    return arm_sha2_support_;
  507|  1.23M|}
BL_Init:
  576|      1|{
  577|      1|    if (PR_CallOnce(&coFreeblInit, FreeblInit) != PR_SUCCESS) {
  ------------------
  |  Branch (577:9): [True: 0, False: 1]
  ------------------
  578|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  579|      0|        return SECFailure;
  580|      0|    }
  581|      1|    RSA_Init();
  582|       |
  583|      1|    return SECSuccess;
  584|      1|}
blinit.c:check_xcr0_ymm:
   58|      1|{
   59|      1|    PRUint32 xcr0;
   60|       |#if defined(_MSC_VER)
   61|       |#if defined(_M_IX86)
   62|       |    __asm {
   63|       |        mov ecx, 0
   64|       |        xgetbv
   65|       |        mov xcr0, eax
   66|       |    }
   67|       |#else
   68|       |    xcr0 = (PRUint32)_xgetbv(0); /* Requires VS2010 SP1 or later. */
   69|       |#endif /* _M_IX86 */
   70|       |#else  /* _MSC_VER */
   71|       |    /* Old OSX compilers don't support xgetbv. Use byte form. */
   72|      1|    __asm__(".byte 0x0F, 0x01, 0xd0"
   73|      1|            : "=a"(xcr0)
   74|      1|            : "c"(0)
   75|      1|            : "%edx");
   76|      1|#endif /* _MSC_VER */
   77|       |    /* Check if xmm and ymm state are enabled in XCR0. */
   78|      1|    return (xcr0 & 6) == 6;
   79|      1|}
blinit.c:FreeblInit:
  563|      1|{
  564|      1|#ifdef NSS_X86_OR_X64
  565|      1|    CheckX86CPUSupport();
  566|       |#elif (defined(__aarch64__) || defined(__arm__))
  567|       |    CheckARMSupport();
  568|       |#elif (defined(__powerpc__))
  569|       |    CheckPPCSupport();
  570|       |#endif
  571|      1|    return PR_SUCCESS;
  572|      1|}

camellia_setup128:
  435|    738|{
  436|    738|    PRUint32 kll, klr, krl, krr;
  437|    738|    PRUint32 il, ir, t0, t1, w0, w1;
  438|    738|    PRUint32 kw4l, kw4r, dw, tl, tr;
  439|    738|    PRUint32 subL[26];
  440|    738|    PRUint32 subR[26];
  441|       |#if defined(CAMELLIA_NEED_TMP_VARIABLE)
  442|       |    PRUint32 tmp;
  443|       |#endif
  444|       |
  445|       |    /**
  446|       |     *  k == kll || klr || krl || krr (|| is concatination)
  447|       |     */
  448|    738|    kll = GETU32(key);
  ------------------
  |  |   45|    738|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|    738|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  449|    738|    klr = GETU32(key + 4);
  ------------------
  |  |   45|    738|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|    738|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  450|    738|    krl = GETU32(key + 8);
  ------------------
  |  |   45|    738|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|    738|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  451|    738|    krr = GETU32(key + 12);
  ------------------
  |  |   45|    738|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|    738|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  452|       |    /**
  453|       |     * generate KL dependent subkeys
  454|       |     */
  455|    738|    subl(0) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  456|    738|    subr(0) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  457|    738|    subl(1) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  458|    738|    subr(1) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  459|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  460|    738|    subl(4) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  461|    738|    subr(4) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  462|    738|    subl(5) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  463|    738|    subr(5) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  464|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 30);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  465|    738|    subl(10) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  466|    738|    subr(10) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  467|    738|    subl(11) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  468|    738|    subr(11) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  469|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  470|    738|    subl(13) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  471|    738|    subr(13) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  472|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  473|    738|    subl(16) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  474|    738|    subr(16) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  475|    738|    subl(17) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  476|    738|    subr(17) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  477|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  478|    738|    subl(18) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  479|    738|    subr(18) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  480|    738|    subl(19) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  481|    738|    subr(19) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  482|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  483|    738|    subl(22) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  484|    738|    subr(22) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  485|    738|    subl(23) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  486|    738|    subr(23) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  487|       |
  488|       |    /* generate KA */
  489|    738|    kll = subl(0);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  490|    738|    klr = subr(0);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  491|    738|    krl = subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  492|    738|    krr = subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  493|    738|    CAMELLIA_F(kll, klr,
  ------------------
  |  |  101|    738|    do {                                                   \
  |  |  102|    738|        il = xl ^ kl;                                      \
  |  |  103|    738|        ir = xr ^ kr;                                      \
  |  |  104|    738|        t0 = il >> 16;                                     \
  |  |  105|    738|        t1 = ir >> 16;                                     \
  |  |  106|    738|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|    738|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|    738|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|    738|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|    738|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|    738|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|    738|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|    738|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|    738|        yl ^= yr;                                          \
  |  |  115|    738|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|    738|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|    738|        yr ^= yl;                                          \
  |  |  117|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  494|    738|               CAMELLIA_SIGMA1L, CAMELLIA_SIGMA1R,
  495|    738|               w0, w1, il, ir, t0, t1);
  496|    738|    krl ^= w0;
  497|    738|    krr ^= w1;
  498|    738|    CAMELLIA_F(krl, krr,
  ------------------
  |  |  101|    738|    do {                                                   \
  |  |  102|    738|        il = xl ^ kl;                                      \
  |  |  103|    738|        ir = xr ^ kr;                                      \
  |  |  104|    738|        t0 = il >> 16;                                     \
  |  |  105|    738|        t1 = ir >> 16;                                     \
  |  |  106|    738|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|    738|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|    738|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|    738|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|    738|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|    738|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|    738|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|    738|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|    738|        yl ^= yr;                                          \
  |  |  115|    738|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|    738|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|    738|        yr ^= yl;                                          \
  |  |  117|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  499|    738|               CAMELLIA_SIGMA2L, CAMELLIA_SIGMA2R,
  500|    738|               kll, klr, il, ir, t0, t1);
  501|    738|    CAMELLIA_F(kll, klr,
  ------------------
  |  |  101|    738|    do {                                                   \
  |  |  102|    738|        il = xl ^ kl;                                      \
  |  |  103|    738|        ir = xr ^ kr;                                      \
  |  |  104|    738|        t0 = il >> 16;                                     \
  |  |  105|    738|        t1 = ir >> 16;                                     \
  |  |  106|    738|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|    738|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|    738|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|    738|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|    738|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|    738|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|    738|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|    738|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|    738|        yl ^= yr;                                          \
  |  |  115|    738|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|    738|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|    738|        yr ^= yl;                                          \
  |  |  117|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  502|    738|               CAMELLIA_SIGMA3L, CAMELLIA_SIGMA3R,
  503|    738|               krl, krr, il, ir, t0, t1);
  504|    738|    krl ^= w0;
  505|    738|    krr ^= w1;
  506|    738|    CAMELLIA_F(krl, krr,
  ------------------
  |  |  101|    738|    do {                                                   \
  |  |  102|    738|        il = xl ^ kl;                                      \
  |  |  103|    738|        ir = xr ^ kr;                                      \
  |  |  104|    738|        t0 = il >> 16;                                     \
  |  |  105|    738|        t1 = ir >> 16;                                     \
  |  |  106|    738|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|    738|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|    738|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|    738|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|    738|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|    738|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|    738|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|    738|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|    738|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|    738|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|    738|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|    738|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|    738|        yl ^= yr;                                          \
  |  |  115|    738|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|    738|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|    738|        yr ^= yl;                                          \
  |  |  117|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  507|    738|               CAMELLIA_SIGMA4L, CAMELLIA_SIGMA4R,
  508|    738|               w0, w1, il, ir, t0, t1);
  509|    738|    kll ^= w0;
  510|    738|    klr ^= w1;
  511|       |
  512|       |    /* generate KA dependent subkeys */
  513|    738|    subl(2) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  514|    738|    subr(2) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  515|    738|    subl(3) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  516|    738|    subr(3) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  517|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  518|    738|    subl(6) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  519|    738|    subr(6) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  520|    738|    subl(7) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  521|    738|    subr(7) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  522|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  523|    738|    subl(8) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  524|    738|    subr(8) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  525|    738|    subl(9) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  526|    738|    subr(9) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  527|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  528|    738|    subl(12) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  529|    738|    subr(12) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  530|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  531|    738|    subl(14) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  532|    738|    subr(14) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  533|    738|    subl(15) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  534|    738|    subr(15) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  535|    738|    CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 34);
  ------------------
  |  |   86|    738|    do {                                                \
  |  |   87|    738|        w0 = ll;                                        \
  |  |   88|    738|        w1 = lr;                                        \
  |  |   89|    738|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|    738|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|    738|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|    738|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  536|    738|    subl(20) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  537|    738|    subr(20) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  538|    738|    subl(21) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  539|    738|    subr(21) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  540|    738|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17);
  ------------------
  |  |   77|    738|    do {                                             \
  |  |   78|    738|        w0 = ll;                                     \
  |  |   79|    738|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|    738|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|    738|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|    738|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|    738|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  541|    738|    subl(24) = kll;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  542|    738|    subr(24) = klr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  543|    738|    subl(25) = krl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  544|    738|    subr(25) = krr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  545|       |
  546|       |    /* absorb kw2 to other subkeys */
  547|    738|    subl(3) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(3) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  548|    738|    subr(3) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(3) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  549|    738|    subl(5) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(5) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  550|    738|    subr(5) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(5) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  551|    738|    subl(7) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(7) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  552|    738|    subr(7) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(7) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  553|    738|    subl(1) ^= subr(1) & ~subr(9);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(9);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(9);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  554|    738|    dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  555|    738|    subl(11) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(11) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  556|    738|    subr(11) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(11) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  557|    738|    subl(13) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(13) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  558|    738|    subr(13) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(13) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  559|    738|    subl(15) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(15) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  560|    738|    subr(15) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(15) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  561|    738|    subl(1) ^= subr(1) & ~subr(17);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(17);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(17);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  562|    738|    dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  563|    738|    subl(19) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(19) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  564|    738|    subr(19) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(19) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  565|    738|    subl(21) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(21) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  566|    738|    subr(21) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(21) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  567|    738|    subl(23) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(23) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  568|    738|    subr(23) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(23) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  569|    738|    subl(24) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  subl(24) ^= subl(1);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  570|    738|    subr(24) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  subr(24) ^= subr(1);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  571|       |
  572|       |    /* absorb kw4 to other subkeys */
  573|    738|    kw4l = subl(25);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  574|    738|    kw4r = subr(25);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  575|    738|    subl(22) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  576|    738|    subr(22) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  577|    738|    subl(20) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  578|    738|    subr(20) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  579|    738|    subl(18) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  580|    738|    subr(18) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  581|    738|    kw4l ^= kw4r & ~subr(16);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  582|    738|    dw = kw4l & subl(16), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = kw4l & subl(16), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  583|    738|    subl(14) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  584|    738|    subr(14) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  585|    738|    subl(12) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  586|    738|    subr(12) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  587|    738|    subl(10) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  588|    738|    subr(10) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  589|    738|    kw4l ^= kw4r & ~subr(8);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  590|    738|    dw = kw4l & subl(8), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = kw4l & subl(8), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  591|    738|    subl(6) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  592|    738|    subr(6) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  593|    738|    subl(4) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  594|    738|    subr(4) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  595|    738|    subl(2) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  596|    738|    subr(2) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  597|    738|    subl(0) ^= kw4l;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  598|    738|    subr(0) ^= kw4r;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  599|       |
  600|       |    /* key XOR is end of F-function */
  601|    738|    CamelliaSubkeyL(0) = subl(0) ^ subl(2);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(0) = subl(0) ^ subl(2);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(0) = subl(0) ^ subl(2);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  602|    738|    CamelliaSubkeyR(0) = subr(0) ^ subr(2);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(0) = subr(0) ^ subr(2);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(0) = subr(0) ^ subr(2);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  603|    738|    CamelliaSubkeyL(2) = subl(3);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(2) = subl(3);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  604|    738|    CamelliaSubkeyR(2) = subr(3);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(2) = subr(3);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  605|    738|    CamelliaSubkeyL(3) = subl(2) ^ subl(4);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(3) = subl(2) ^ subl(4);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(3) = subl(2) ^ subl(4);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  606|    738|    CamelliaSubkeyR(3) = subr(2) ^ subr(4);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(3) = subr(2) ^ subr(4);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(3) = subr(2) ^ subr(4);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  607|    738|    CamelliaSubkeyL(4) = subl(3) ^ subl(5);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(4) = subl(3) ^ subl(5);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(4) = subl(3) ^ subl(5);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  608|    738|    CamelliaSubkeyR(4) = subr(3) ^ subr(5);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(4) = subr(3) ^ subr(5);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(4) = subr(3) ^ subr(5);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  609|    738|    CamelliaSubkeyL(5) = subl(4) ^ subl(6);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(5) = subl(4) ^ subl(6);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(5) = subl(4) ^ subl(6);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  610|    738|    CamelliaSubkeyR(5) = subr(4) ^ subr(6);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(5) = subr(4) ^ subr(6);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(5) = subr(4) ^ subr(6);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  611|    738|    CamelliaSubkeyL(6) = subl(5) ^ subl(7);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(6) = subl(5) ^ subl(7);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(6) = subl(5) ^ subl(7);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  612|    738|    CamelliaSubkeyR(6) = subr(5) ^ subr(7);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(6) = subr(5) ^ subr(7);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(6) = subr(5) ^ subr(7);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  613|    738|    tl = subl(10) ^ (subr(10) & ~subr(8));
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(10) ^ (subr(10) & ~subr(8));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(10) ^ (subr(10) & ~subr(8));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  614|    738|    dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  615|    738|    CamelliaSubkeyL(7) = subl(6) ^ tl;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(7) = subl(6) ^ tl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  616|    738|    CamelliaSubkeyR(7) = subr(6) ^ tr;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(7) = subr(6) ^ tr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  617|    738|    CamelliaSubkeyL(8) = subl(8);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(8) = subl(8);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  618|    738|    CamelliaSubkeyR(8) = subr(8);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(8) = subr(8);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  619|    738|    CamelliaSubkeyL(9) = subl(9);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(9) = subl(9);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  620|    738|    CamelliaSubkeyR(9) = subr(9);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(9) = subr(9);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  621|    738|    tl = subl(7) ^ (subr(7) & ~subr(9));
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(7) ^ (subr(7) & ~subr(9));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(7) ^ (subr(7) & ~subr(9));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  622|    738|    dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  623|    738|    CamelliaSubkeyL(10) = tl ^ subl(11);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(10) = tl ^ subl(11);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  624|    738|    CamelliaSubkeyR(10) = tr ^ subr(11);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(10) = tr ^ subr(11);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  625|    738|    CamelliaSubkeyL(11) = subl(10) ^ subl(12);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(11) = subl(10) ^ subl(12);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(11) = subl(10) ^ subl(12);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  626|    738|    CamelliaSubkeyR(11) = subr(10) ^ subr(12);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(11) = subr(10) ^ subr(12);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(11) = subr(10) ^ subr(12);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  627|    738|    CamelliaSubkeyL(12) = subl(11) ^ subl(13);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(12) = subl(11) ^ subl(13);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(12) = subl(11) ^ subl(13);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  628|    738|    CamelliaSubkeyR(12) = subr(11) ^ subr(13);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(12) = subr(11) ^ subr(13);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(12) = subr(11) ^ subr(13);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  629|    738|    CamelliaSubkeyL(13) = subl(12) ^ subl(14);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(13) = subl(12) ^ subl(14);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(13) = subl(12) ^ subl(14);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  630|    738|    CamelliaSubkeyR(13) = subr(12) ^ subr(14);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(13) = subr(12) ^ subr(14);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(13) = subr(12) ^ subr(14);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  631|    738|    CamelliaSubkeyL(14) = subl(13) ^ subl(15);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(14) = subl(13) ^ subl(15);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(14) = subl(13) ^ subl(15);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  632|    738|    CamelliaSubkeyR(14) = subr(13) ^ subr(15);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(14) = subr(13) ^ subr(15);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(14) = subr(13) ^ subr(15);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  633|    738|    tl = subl(18) ^ (subr(18) & ~subr(16));
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(18) ^ (subr(18) & ~subr(16));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(18) ^ (subr(18) & ~subr(16));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  634|    738|    dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  635|    738|    CamelliaSubkeyL(15) = subl(14) ^ tl;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(15) = subl(14) ^ tl;
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  636|    738|    CamelliaSubkeyR(15) = subr(14) ^ tr;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(15) = subr(14) ^ tr;
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  637|    738|    CamelliaSubkeyL(16) = subl(16);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(16) = subl(16);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  638|    738|    CamelliaSubkeyR(16) = subr(16);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(16) = subr(16);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  639|    738|    CamelliaSubkeyL(17) = subl(17);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(17) = subl(17);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  640|    738|    CamelliaSubkeyR(17) = subr(17);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(17) = subr(17);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  641|    738|    tl = subl(15) ^ (subr(15) & ~subr(17));
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(15) ^ (subr(15) & ~subr(17));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(15) ^ (subr(15) & ~subr(17));
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  642|    738|    dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|    738|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  643|    738|    CamelliaSubkeyL(18) = tl ^ subl(19);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(18) = tl ^ subl(19);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  644|    738|    CamelliaSubkeyR(18) = tr ^ subr(19);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(18) = tr ^ subr(19);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  645|    738|    CamelliaSubkeyL(19) = subl(18) ^ subl(20);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(19) = subl(18) ^ subl(20);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(19) = subl(18) ^ subl(20);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  646|    738|    CamelliaSubkeyR(19) = subr(18) ^ subr(20);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(19) = subr(18) ^ subr(20);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(19) = subr(18) ^ subr(20);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  647|    738|    CamelliaSubkeyL(20) = subl(19) ^ subl(21);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(20) = subl(19) ^ subl(21);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(20) = subl(19) ^ subl(21);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  648|    738|    CamelliaSubkeyR(20) = subr(19) ^ subr(21);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(20) = subr(19) ^ subr(21);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(20) = subr(19) ^ subr(21);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  649|    738|    CamelliaSubkeyL(21) = subl(20) ^ subl(22);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(21) = subl(20) ^ subl(22);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(21) = subl(20) ^ subl(22);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  650|    738|    CamelliaSubkeyR(21) = subr(20) ^ subr(22);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(21) = subr(20) ^ subr(22);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(21) = subr(20) ^ subr(22);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  651|    738|    CamelliaSubkeyL(22) = subl(21) ^ subl(23);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(22) = subl(21) ^ subl(23);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(22) = subl(21) ^ subl(23);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  652|    738|    CamelliaSubkeyR(22) = subr(21) ^ subr(23);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(22) = subr(21) ^ subr(23);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(22) = subr(21) ^ subr(23);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  653|    738|    CamelliaSubkeyL(23) = subl(22);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(23) = subl(22);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  654|    738|    CamelliaSubkeyR(23) = subr(22);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(23) = subr(22);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  655|    738|    CamelliaSubkeyL(24) = subl(24) ^ subl(23);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(24) = subl(24) ^ subl(23);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(24) = subl(24) ^ subl(23);
  ------------------
  |  |  430|    738|#define subl(x) subL[(x)]
  ------------------
  656|    738|    CamelliaSubkeyR(24) = subr(24) ^ subr(23);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(24) = subr(24) ^ subr(23);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(24) = subr(24) ^ subr(23);
  ------------------
  |  |  431|    738|#define subr(x) subR[(x)]
  ------------------
  657|       |
  658|       |    /* apply the inverse of the last half of P-function */
  659|    738|    dw = CamelliaSubkeyL(2) ^ CamelliaSubkeyR(2), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(2) ^ CamelliaSubkeyR(2), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(2) ^ CamelliaSubkeyR(2), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  660|    738|    CamelliaSubkeyR(2) = CamelliaSubkeyL(2) ^ dw, CamelliaSubkeyL(2) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(2) = CamelliaSubkeyL(2) ^ dw, CamelliaSubkeyL(2) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(2) = CamelliaSubkeyL(2) ^ dw, CamelliaSubkeyL(2) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  661|    738|    dw = CamelliaSubkeyL(3) ^ CamelliaSubkeyR(3), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(3) ^ CamelliaSubkeyR(3), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(3) ^ CamelliaSubkeyR(3), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  662|    738|    CamelliaSubkeyR(3) = CamelliaSubkeyL(3) ^ dw, CamelliaSubkeyL(3) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(3) = CamelliaSubkeyL(3) ^ dw, CamelliaSubkeyL(3) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(3) = CamelliaSubkeyL(3) ^ dw, CamelliaSubkeyL(3) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  663|    738|    dw = CamelliaSubkeyL(4) ^ CamelliaSubkeyR(4), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(4) ^ CamelliaSubkeyR(4), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(4) ^ CamelliaSubkeyR(4), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  664|    738|    CamelliaSubkeyR(4) = CamelliaSubkeyL(4) ^ dw, CamelliaSubkeyL(4) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(4) = CamelliaSubkeyL(4) ^ dw, CamelliaSubkeyL(4) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(4) = CamelliaSubkeyL(4) ^ dw, CamelliaSubkeyL(4) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  665|    738|    dw = CamelliaSubkeyL(5) ^ CamelliaSubkeyR(5), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(5) ^ CamelliaSubkeyR(5), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(5) ^ CamelliaSubkeyR(5), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  666|    738|    CamelliaSubkeyR(5) = CamelliaSubkeyL(5) ^ dw, CamelliaSubkeyL(5) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(5) = CamelliaSubkeyL(5) ^ dw, CamelliaSubkeyL(5) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(5) = CamelliaSubkeyL(5) ^ dw, CamelliaSubkeyL(5) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  667|    738|    dw = CamelliaSubkeyL(6) ^ CamelliaSubkeyR(6), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(6) ^ CamelliaSubkeyR(6), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(6) ^ CamelliaSubkeyR(6), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  668|    738|    CamelliaSubkeyR(6) = CamelliaSubkeyL(6) ^ dw, CamelliaSubkeyL(6) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(6) = CamelliaSubkeyL(6) ^ dw, CamelliaSubkeyL(6) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(6) = CamelliaSubkeyL(6) ^ dw, CamelliaSubkeyL(6) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  669|    738|    dw = CamelliaSubkeyL(7) ^ CamelliaSubkeyR(7), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(7) ^ CamelliaSubkeyR(7), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(7) ^ CamelliaSubkeyR(7), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  670|    738|    CamelliaSubkeyR(7) = CamelliaSubkeyL(7) ^ dw, CamelliaSubkeyL(7) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(7) = CamelliaSubkeyL(7) ^ dw, CamelliaSubkeyL(7) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(7) = CamelliaSubkeyL(7) ^ dw, CamelliaSubkeyL(7) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  671|    738|    dw = CamelliaSubkeyL(10) ^ CamelliaSubkeyR(10), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(10) ^ CamelliaSubkeyR(10), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(10) ^ CamelliaSubkeyR(10), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  672|    738|    CamelliaSubkeyR(10) = CamelliaSubkeyL(10) ^ dw, CamelliaSubkeyL(10) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(10) = CamelliaSubkeyL(10) ^ dw, CamelliaSubkeyL(10) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(10) = CamelliaSubkeyL(10) ^ dw, CamelliaSubkeyL(10) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  673|    738|    dw = CamelliaSubkeyL(11) ^ CamelliaSubkeyR(11), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(11) ^ CamelliaSubkeyR(11), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(11) ^ CamelliaSubkeyR(11), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  674|    738|    CamelliaSubkeyR(11) = CamelliaSubkeyL(11) ^ dw, CamelliaSubkeyL(11) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(11) = CamelliaSubkeyL(11) ^ dw, CamelliaSubkeyL(11) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(11) = CamelliaSubkeyL(11) ^ dw, CamelliaSubkeyL(11) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  675|    738|    dw = CamelliaSubkeyL(12) ^ CamelliaSubkeyR(12), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(12) ^ CamelliaSubkeyR(12), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(12) ^ CamelliaSubkeyR(12), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  676|    738|    CamelliaSubkeyR(12) = CamelliaSubkeyL(12) ^ dw, CamelliaSubkeyL(12) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(12) = CamelliaSubkeyL(12) ^ dw, CamelliaSubkeyL(12) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(12) = CamelliaSubkeyL(12) ^ dw, CamelliaSubkeyL(12) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  677|    738|    dw = CamelliaSubkeyL(13) ^ CamelliaSubkeyR(13), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(13) ^ CamelliaSubkeyR(13), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(13) ^ CamelliaSubkeyR(13), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  678|    738|    CamelliaSubkeyR(13) = CamelliaSubkeyL(13) ^ dw, CamelliaSubkeyL(13) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(13) = CamelliaSubkeyL(13) ^ dw, CamelliaSubkeyL(13) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(13) = CamelliaSubkeyL(13) ^ dw, CamelliaSubkeyL(13) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  679|    738|    dw = CamelliaSubkeyL(14) ^ CamelliaSubkeyR(14), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(14) ^ CamelliaSubkeyR(14), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(14) ^ CamelliaSubkeyR(14), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  680|    738|    CamelliaSubkeyR(14) = CamelliaSubkeyL(14) ^ dw, CamelliaSubkeyL(14) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(14) = CamelliaSubkeyL(14) ^ dw, CamelliaSubkeyL(14) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(14) = CamelliaSubkeyL(14) ^ dw, CamelliaSubkeyL(14) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  681|    738|    dw = CamelliaSubkeyL(15) ^ CamelliaSubkeyR(15), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(15) ^ CamelliaSubkeyR(15), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(15) ^ CamelliaSubkeyR(15), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  682|    738|    CamelliaSubkeyR(15) = CamelliaSubkeyL(15) ^ dw, CamelliaSubkeyL(15) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(15) = CamelliaSubkeyL(15) ^ dw, CamelliaSubkeyL(15) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(15) = CamelliaSubkeyL(15) ^ dw, CamelliaSubkeyL(15) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  683|    738|    dw = CamelliaSubkeyL(18) ^ CamelliaSubkeyR(18), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(18) ^ CamelliaSubkeyR(18), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(18) ^ CamelliaSubkeyR(18), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  684|    738|    CamelliaSubkeyR(18) = CamelliaSubkeyL(18) ^ dw, CamelliaSubkeyL(18) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(18) = CamelliaSubkeyL(18) ^ dw, CamelliaSubkeyL(18) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(18) = CamelliaSubkeyL(18) ^ dw, CamelliaSubkeyL(18) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  685|    738|    dw = CamelliaSubkeyL(19) ^ CamelliaSubkeyR(19), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(19) ^ CamelliaSubkeyR(19), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(19) ^ CamelliaSubkeyR(19), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  686|    738|    CamelliaSubkeyR(19) = CamelliaSubkeyL(19) ^ dw, CamelliaSubkeyL(19) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(19) = CamelliaSubkeyL(19) ^ dw, CamelliaSubkeyL(19) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(19) = CamelliaSubkeyL(19) ^ dw, CamelliaSubkeyL(19) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  687|    738|    dw = CamelliaSubkeyL(20) ^ CamelliaSubkeyR(20), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(20) ^ CamelliaSubkeyR(20), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(20) ^ CamelliaSubkeyR(20), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  688|    738|    CamelliaSubkeyR(20) = CamelliaSubkeyL(20) ^ dw, CamelliaSubkeyL(20) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(20) = CamelliaSubkeyL(20) ^ dw, CamelliaSubkeyL(20) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(20) = CamelliaSubkeyL(20) ^ dw, CamelliaSubkeyL(20) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  689|    738|    dw = CamelliaSubkeyL(21) ^ CamelliaSubkeyR(21), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(21) ^ CamelliaSubkeyR(21), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(21) ^ CamelliaSubkeyR(21), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  690|    738|    CamelliaSubkeyR(21) = CamelliaSubkeyL(21) ^ dw, CamelliaSubkeyL(21) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(21) = CamelliaSubkeyL(21) ^ dw, CamelliaSubkeyL(21) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(21) = CamelliaSubkeyL(21) ^ dw, CamelliaSubkeyL(21) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  691|    738|    dw = CamelliaSubkeyL(22) ^ CamelliaSubkeyR(22), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(22) ^ CamelliaSubkeyR(22), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(22) ^ CamelliaSubkeyR(22), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  692|    738|    CamelliaSubkeyR(22) = CamelliaSubkeyL(22) ^ dw, CamelliaSubkeyL(22) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(22) = CamelliaSubkeyL(22) ^ dw, CamelliaSubkeyL(22) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(22) = CamelliaSubkeyL(22) ^ dw, CamelliaSubkeyL(22) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  693|    738|    dw = CamelliaSubkeyL(23) ^ CamelliaSubkeyR(23), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(23) ^ CamelliaSubkeyR(23), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(23) ^ CamelliaSubkeyR(23), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|    738|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
  694|    738|    CamelliaSubkeyR(23) = CamelliaSubkeyL(23) ^ dw, CamelliaSubkeyL(23) = dw;
  ------------------
  |  |   67|    738|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(23) = CamelliaSubkeyL(23) ^ dw, CamelliaSubkeyL(23) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(23) = CamelliaSubkeyL(23) ^ dw, CamelliaSubkeyL(23) = dw;
  ------------------
  |  |   66|    738|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
  695|       |
  696|    738|    return;
  697|    738|}
camellia_setup256:
  701|  1.29k|{
  702|  1.29k|    PRUint32 kll, klr, krl, krr;     /* left half of key */
  703|  1.29k|    PRUint32 krll, krlr, krrl, krrr; /* right half of key */
  704|  1.29k|    PRUint32 il, ir, t0, t1, w0, w1; /* temporary variables */
  705|  1.29k|    PRUint32 kw4l, kw4r, dw, tl, tr;
  706|  1.29k|    PRUint32 subL[34];
  707|  1.29k|    PRUint32 subR[34];
  708|       |#if defined(CAMELLIA_NEED_TMP_VARIABLE)
  709|       |    PRUint32 tmp;
  710|       |#endif
  711|       |
  712|       |    /**
  713|       |     *  key = (kll || klr || krl || krr || krll || krlr || krrl || krrr)
  714|       |     *  (|| is concatination)
  715|       |     */
  716|       |
  717|  1.29k|    kll = GETU32(key);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  718|  1.29k|    klr = GETU32(key + 4);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  719|  1.29k|    krl = GETU32(key + 8);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  720|  1.29k|    krr = GETU32(key + 12);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  721|  1.29k|    krll = GETU32(key + 16);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  722|  1.29k|    krlr = GETU32(key + 20);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  723|  1.29k|    krrl = GETU32(key + 24);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  724|  1.29k|    krrr = GETU32(key + 28);
  ------------------
  |  |   45|  1.29k|#define GETU32(p) SHA_HTONL(*((PRUint32 *)(p)))
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  725|       |
  726|       |    /* generate KL dependent subkeys */
  727|  1.29k|    subl(0) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  728|  1.29k|    subr(0) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  729|  1.29k|    subl(1) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  730|  1.29k|    subr(1) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  731|  1.29k|    CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 45);
  ------------------
  |  |   86|  1.29k|    do {                                                \
  |  |   87|  1.29k|        w0 = ll;                                        \
  |  |   88|  1.29k|        w1 = lr;                                        \
  |  |   89|  1.29k|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|  1.29k|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|  1.29k|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|  1.29k|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  732|  1.29k|    subl(12) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  733|  1.29k|    subr(12) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  734|  1.29k|    subl(13) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  735|  1.29k|    subr(13) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  736|  1.29k|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  737|  1.29k|    subl(16) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  738|  1.29k|    subr(16) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  739|  1.29k|    subl(17) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  740|  1.29k|    subr(17) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  741|  1.29k|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 17);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  742|  1.29k|    subl(22) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  743|  1.29k|    subr(22) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  744|  1.29k|    subl(23) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  745|  1.29k|    subr(23) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  746|  1.29k|    CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 34);
  ------------------
  |  |   86|  1.29k|    do {                                                \
  |  |   87|  1.29k|        w0 = ll;                                        \
  |  |   88|  1.29k|        w1 = lr;                                        \
  |  |   89|  1.29k|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|  1.29k|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|  1.29k|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|  1.29k|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  747|  1.29k|    subl(30) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  748|  1.29k|    subr(30) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  749|  1.29k|    subl(31) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  750|  1.29k|    subr(31) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  751|       |
  752|       |    /* generate KR dependent subkeys */
  753|  1.29k|    CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 15);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  754|  1.29k|    subl(4) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  755|  1.29k|    subr(4) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  756|  1.29k|    subl(5) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  757|  1.29k|    subr(5) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  758|  1.29k|    CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 15);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  759|  1.29k|    subl(8) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  760|  1.29k|    subr(8) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  761|  1.29k|    subl(9) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  762|  1.29k|    subr(9) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  763|  1.29k|    CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 30);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  764|  1.29k|    subl(18) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  765|  1.29k|    subr(18) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  766|  1.29k|    subl(19) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  767|  1.29k|    subr(19) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  768|  1.29k|    CAMELLIA_ROLDQo32(krll, krlr, krrl, krrr, w0, w1, 34);
  ------------------
  |  |   86|  1.29k|    do {                                                \
  |  |   87|  1.29k|        w0 = ll;                                        \
  |  |   88|  1.29k|        w1 = lr;                                        \
  |  |   89|  1.29k|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|  1.29k|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|  1.29k|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|  1.29k|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  769|  1.29k|    subl(26) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  770|  1.29k|    subr(26) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  771|  1.29k|    subl(27) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  772|  1.29k|    subr(27) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  773|  1.29k|    CAMELLIA_ROLDQo32(krll, krlr, krrl, krrr, w0, w1, 34);
  ------------------
  |  |   86|  1.29k|    do {                                                \
  |  |   87|  1.29k|        w0 = ll;                                        \
  |  |   88|  1.29k|        w1 = lr;                                        \
  |  |   89|  1.29k|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|  1.29k|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|  1.29k|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|  1.29k|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  774|       |
  775|       |    /* generate KA */
  776|  1.29k|    kll = subl(0) ^ krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  777|  1.29k|    klr = subr(0) ^ krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  778|  1.29k|    krl = subl(1) ^ krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  779|  1.29k|    krr = subr(1) ^ krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  780|  1.29k|    CAMELLIA_F(kll, klr,
  ------------------
  |  |  101|  1.29k|    do {                                                   \
  |  |  102|  1.29k|        il = xl ^ kl;                                      \
  |  |  103|  1.29k|        ir = xr ^ kr;                                      \
  |  |  104|  1.29k|        t0 = il >> 16;                                     \
  |  |  105|  1.29k|        t1 = ir >> 16;                                     \
  |  |  106|  1.29k|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|  1.29k|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|  1.29k|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|  1.29k|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|  1.29k|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|  1.29k|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|  1.29k|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|  1.29k|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|  1.29k|        yl ^= yr;                                          \
  |  |  115|  1.29k|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|  1.29k|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|  1.29k|        yr ^= yl;                                          \
  |  |  117|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  781|  1.29k|               CAMELLIA_SIGMA1L, CAMELLIA_SIGMA1R,
  782|  1.29k|               w0, w1, il, ir, t0, t1);
  783|  1.29k|    krl ^= w0;
  784|  1.29k|    krr ^= w1;
  785|  1.29k|    CAMELLIA_F(krl, krr,
  ------------------
  |  |  101|  1.29k|    do {                                                   \
  |  |  102|  1.29k|        il = xl ^ kl;                                      \
  |  |  103|  1.29k|        ir = xr ^ kr;                                      \
  |  |  104|  1.29k|        t0 = il >> 16;                                     \
  |  |  105|  1.29k|        t1 = ir >> 16;                                     \
  |  |  106|  1.29k|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|  1.29k|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|  1.29k|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|  1.29k|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|  1.29k|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|  1.29k|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|  1.29k|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|  1.29k|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|  1.29k|        yl ^= yr;                                          \
  |  |  115|  1.29k|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|  1.29k|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|  1.29k|        yr ^= yl;                                          \
  |  |  117|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  786|  1.29k|               CAMELLIA_SIGMA2L, CAMELLIA_SIGMA2R,
  787|  1.29k|               kll, klr, il, ir, t0, t1);
  788|  1.29k|    kll ^= krll;
  789|  1.29k|    klr ^= krlr;
  790|  1.29k|    CAMELLIA_F(kll, klr,
  ------------------
  |  |  101|  1.29k|    do {                                                   \
  |  |  102|  1.29k|        il = xl ^ kl;                                      \
  |  |  103|  1.29k|        ir = xr ^ kr;                                      \
  |  |  104|  1.29k|        t0 = il >> 16;                                     \
  |  |  105|  1.29k|        t1 = ir >> 16;                                     \
  |  |  106|  1.29k|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|  1.29k|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|  1.29k|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|  1.29k|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|  1.29k|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|  1.29k|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|  1.29k|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|  1.29k|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|  1.29k|        yl ^= yr;                                          \
  |  |  115|  1.29k|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|  1.29k|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|  1.29k|        yr ^= yl;                                          \
  |  |  117|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  791|  1.29k|               CAMELLIA_SIGMA3L, CAMELLIA_SIGMA3R,
  792|  1.29k|               krl, krr, il, ir, t0, t1);
  793|  1.29k|    krl ^= w0 ^ krrl;
  794|  1.29k|    krr ^= w1 ^ krrr;
  795|  1.29k|    CAMELLIA_F(krl, krr,
  ------------------
  |  |  101|  1.29k|    do {                                                   \
  |  |  102|  1.29k|        il = xl ^ kl;                                      \
  |  |  103|  1.29k|        ir = xr ^ kr;                                      \
  |  |  104|  1.29k|        t0 = il >> 16;                                     \
  |  |  105|  1.29k|        t1 = ir >> 16;                                     \
  |  |  106|  1.29k|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|  1.29k|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|  1.29k|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|  1.29k|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|  1.29k|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|  1.29k|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|  1.29k|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|  1.29k|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|  1.29k|        yl ^= yr;                                          \
  |  |  115|  1.29k|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|  1.29k|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|  1.29k|        yr ^= yl;                                          \
  |  |  117|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  796|  1.29k|               CAMELLIA_SIGMA4L, CAMELLIA_SIGMA4R,
  797|  1.29k|               w0, w1, il, ir, t0, t1);
  798|  1.29k|    kll ^= w0;
  799|  1.29k|    klr ^= w1;
  800|       |
  801|       |    /* generate KB */
  802|  1.29k|    krll ^= kll;
  803|  1.29k|    krlr ^= klr;
  804|  1.29k|    krrl ^= krl;
  805|  1.29k|    krrr ^= krr;
  806|  1.29k|    CAMELLIA_F(krll, krlr,
  ------------------
  |  |  101|  1.29k|    do {                                                   \
  |  |  102|  1.29k|        il = xl ^ kl;                                      \
  |  |  103|  1.29k|        ir = xr ^ kr;                                      \
  |  |  104|  1.29k|        t0 = il >> 16;                                     \
  |  |  105|  1.29k|        t1 = ir >> 16;                                     \
  |  |  106|  1.29k|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|  1.29k|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|  1.29k|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|  1.29k|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|  1.29k|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|  1.29k|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|  1.29k|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|  1.29k|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|  1.29k|        yl ^= yr;                                          \
  |  |  115|  1.29k|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|  1.29k|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|  1.29k|        yr ^= yl;                                          \
  |  |  117|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  807|  1.29k|               CAMELLIA_SIGMA5L, CAMELLIA_SIGMA5R,
  808|  1.29k|               w0, w1, il, ir, t0, t1);
  809|  1.29k|    krrl ^= w0;
  810|  1.29k|    krrr ^= w1;
  811|  1.29k|    CAMELLIA_F(krrl, krrr,
  ------------------
  |  |  101|  1.29k|    do {                                                   \
  |  |  102|  1.29k|        il = xl ^ kl;                                      \
  |  |  103|  1.29k|        ir = xr ^ kr;                                      \
  |  |  104|  1.29k|        t0 = il >> 16;                                     \
  |  |  105|  1.29k|        t1 = ir >> 16;                                     \
  |  |  106|  1.29k|        yl = CAMELLIA_SP1110(ir & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  107|  1.29k|             CAMELLIA_SP0222((t1 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  108|  1.29k|             CAMELLIA_SP3033(t1 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  109|  1.29k|             CAMELLIA_SP4404((ir >> 8) & 0xff);            \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  110|  1.29k|        yr = CAMELLIA_SP1110((t0 >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   95|  1.29k|#define CAMELLIA_SP1110(INDEX) (camellia_sp1110[(INDEX)])
  |  |  ------------------
  |  |  111|  1.29k|             CAMELLIA_SP0222(t0 & 0xff) ^                  \
  |  |  ------------------
  |  |  |  |   96|  1.29k|#define CAMELLIA_SP0222(INDEX) (camellia_sp0222[(INDEX)])
  |  |  ------------------
  |  |  112|  1.29k|             CAMELLIA_SP3033((il >> 8) & 0xff) ^           \
  |  |  ------------------
  |  |  |  |   97|  1.29k|#define CAMELLIA_SP3033(INDEX) (camellia_sp3033[(INDEX)])
  |  |  ------------------
  |  |  113|  1.29k|             CAMELLIA_SP4404(il & 0xff);                   \
  |  |  ------------------
  |  |  |  |   98|  1.29k|#define CAMELLIA_SP4404(INDEX) (camellia_sp4404[(INDEX)])
  |  |  ------------------
  |  |  114|  1.29k|        yl ^= yr;                                          \
  |  |  115|  1.29k|        yr = CAMELLIA_RR8(yr);                             \
  |  |  ------------------
  |  |  |  |   70|  1.29k|#define CAMELLIA_RR8(x) (((x) >> 8) + ((x) << 24))
  |  |  ------------------
  |  |  116|  1.29k|        yr ^= yl;                                          \
  |  |  117|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (117:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  812|  1.29k|               CAMELLIA_SIGMA6L, CAMELLIA_SIGMA6R,
  813|  1.29k|               w0, w1, il, ir, t0, t1);
  814|  1.29k|    krll ^= w0;
  815|  1.29k|    krlr ^= w1;
  816|       |
  817|       |    /* generate KA dependent subkeys */
  818|  1.29k|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 15);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  819|  1.29k|    subl(6) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  820|  1.29k|    subr(6) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  821|  1.29k|    subl(7) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  822|  1.29k|    subr(7) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  823|  1.29k|    CAMELLIA_ROLDQ(kll, klr, krl, krr, w0, w1, 30);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  824|  1.29k|    subl(14) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  825|  1.29k|    subr(14) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  826|  1.29k|    subl(15) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  827|  1.29k|    subr(15) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  828|  1.29k|    subl(24) = klr;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  829|  1.29k|    subr(24) = krl;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  830|  1.29k|    subl(25) = krr;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  831|  1.29k|    subr(25) = kll;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  832|  1.29k|    CAMELLIA_ROLDQo32(kll, klr, krl, krr, w0, w1, 49);
  ------------------
  |  |   86|  1.29k|    do {                                                \
  |  |   87|  1.29k|        w0 = ll;                                        \
  |  |   88|  1.29k|        w1 = lr;                                        \
  |  |   89|  1.29k|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|  1.29k|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|  1.29k|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|  1.29k|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  833|  1.29k|    subl(28) = kll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  834|  1.29k|    subr(28) = klr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  835|  1.29k|    subl(29) = krl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  836|  1.29k|    subr(29) = krr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  837|       |
  838|       |    /* generate KB dependent subkeys */
  839|  1.29k|    subl(2) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  840|  1.29k|    subr(2) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  841|  1.29k|    subl(3) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  842|  1.29k|    subr(3) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  843|  1.29k|    CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 30);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  844|  1.29k|    subl(10) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  845|  1.29k|    subr(10) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  846|  1.29k|    subl(11) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  847|  1.29k|    subr(11) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  848|  1.29k|    CAMELLIA_ROLDQ(krll, krlr, krrl, krrr, w0, w1, 30);
  ------------------
  |  |   77|  1.29k|    do {                                             \
  |  |   78|  1.29k|        w0 = ll;                                     \
  |  |   79|  1.29k|        ll = (ll << bits) + (lr >> (32 - bits));     \
  |  |   80|  1.29k|        lr = (lr << bits) + (rl >> (32 - bits));     \
  |  |   81|  1.29k|        rl = (rl << bits) + (rr >> (32 - bits));     \
  |  |   82|  1.29k|        rr = (rr << bits) + (w0 >> (32 - bits));     \
  |  |   83|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (83:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  849|  1.29k|    subl(20) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  850|  1.29k|    subr(20) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  851|  1.29k|    subl(21) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  852|  1.29k|    subr(21) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  853|  1.29k|    CAMELLIA_ROLDQo32(krll, krlr, krrl, krrr, w0, w1, 51);
  ------------------
  |  |   86|  1.29k|    do {                                                \
  |  |   87|  1.29k|        w0 = ll;                                        \
  |  |   88|  1.29k|        w1 = lr;                                        \
  |  |   89|  1.29k|        ll = (lr << (bits - 32)) + (rl >> (64 - bits)); \
  |  |   90|  1.29k|        lr = (rl << (bits - 32)) + (rr >> (64 - bits)); \
  |  |   91|  1.29k|        rl = (rr << (bits - 32)) + (w0 >> (64 - bits)); \
  |  |   92|  1.29k|        rr = (w0 << (bits - 32)) + (w1 >> (64 - bits)); \
  |  |   93|  1.29k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (93:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  854|  1.29k|    subl(32) = krll;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  855|  1.29k|    subr(32) = krlr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  856|  1.29k|    subl(33) = krrl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  857|  1.29k|    subr(33) = krrr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  858|       |
  859|       |    /* absorb kw2 to other subkeys */
  860|  1.29k|    subl(3) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(3) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  861|  1.29k|    subr(3) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(3) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  862|  1.29k|    subl(5) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(5) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  863|  1.29k|    subr(5) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(5) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  864|  1.29k|    subl(7) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(7) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  865|  1.29k|    subr(7) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(7) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  866|  1.29k|    subl(1) ^= subr(1) & ~subr(9);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(9);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(9);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  867|  1.29k|    dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = subl(1) & subl(9), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  868|  1.29k|    subl(11) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(11) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  869|  1.29k|    subr(11) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(11) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  870|  1.29k|    subl(13) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(13) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  871|  1.29k|    subr(13) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(13) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  872|  1.29k|    subl(15) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(15) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  873|  1.29k|    subr(15) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(15) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  874|  1.29k|    subl(1) ^= subr(1) & ~subr(17);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(17);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(17);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  875|  1.29k|    dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = subl(1) & subl(17), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  876|  1.29k|    subl(19) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(19) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  877|  1.29k|    subr(19) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(19) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  878|  1.29k|    subl(21) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(21) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  879|  1.29k|    subr(21) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(21) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  880|  1.29k|    subl(23) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(23) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  881|  1.29k|    subr(23) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(23) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  882|  1.29k|    subl(1) ^= subr(1) & ~subr(25);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(25);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subl(1) ^= subr(1) & ~subr(25);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  883|  1.29k|    dw = subl(1) & subl(25), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(25), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = subl(1) & subl(25), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = subl(1) & subl(25), subr(1) ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  884|  1.29k|    subl(27) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(27) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  885|  1.29k|    subr(27) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(27) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  886|  1.29k|    subl(29) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(29) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  887|  1.29k|    subr(29) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(29) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  888|  1.29k|    subl(31) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(31) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  889|  1.29k|    subr(31) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(31) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  890|  1.29k|    subl(32) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  subl(32) ^= subl(1);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  891|  1.29k|    subr(32) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  subr(32) ^= subr(1);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  892|       |
  893|       |    /* absorb kw4 to other subkeys */
  894|  1.29k|    kw4l = subl(33);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  895|  1.29k|    kw4r = subr(33);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  896|  1.29k|    subl(30) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  897|  1.29k|    subr(30) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  898|  1.29k|    subl(28) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  899|  1.29k|    subr(28) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  900|  1.29k|    subl(26) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  901|  1.29k|    subr(26) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  902|  1.29k|    kw4l ^= kw4r & ~subr(24);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  903|  1.29k|    dw = kw4l & subl(24), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = kw4l & subl(24), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  904|  1.29k|    subl(22) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  905|  1.29k|    subr(22) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  906|  1.29k|    subl(20) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  907|  1.29k|    subr(20) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  908|  1.29k|    subl(18) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  909|  1.29k|    subr(18) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  910|  1.29k|    kw4l ^= kw4r & ~subr(16);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  911|  1.29k|    dw = kw4l & subl(16), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = kw4l & subl(16), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  912|  1.29k|    subl(14) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  913|  1.29k|    subr(14) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  914|  1.29k|    subl(12) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  915|  1.29k|    subr(12) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  916|  1.29k|    subl(10) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  917|  1.29k|    subr(10) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  918|  1.29k|    kw4l ^= kw4r & ~subr(8);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  919|  1.29k|    dw = kw4l & subl(8), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = kw4l & subl(8), kw4r ^= CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  920|  1.29k|    subl(6) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  921|  1.29k|    subr(6) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  922|  1.29k|    subl(4) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  923|  1.29k|    subr(4) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  924|  1.29k|    subl(2) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  925|  1.29k|    subr(2) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  926|  1.29k|    subl(0) ^= kw4l;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  927|  1.29k|    subr(0) ^= kw4r;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  928|       |
  929|       |    /* key XOR is end of F-function */
  930|  1.29k|    CamelliaSubkeyL(0) = subl(0) ^ subl(2);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(0) = subl(0) ^ subl(2);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(0) = subl(0) ^ subl(2);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  931|  1.29k|    CamelliaSubkeyR(0) = subr(0) ^ subr(2);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(0) = subr(0) ^ subr(2);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(0) = subr(0) ^ subr(2);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  932|  1.29k|    CamelliaSubkeyL(2) = subl(3);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(2) = subl(3);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  933|  1.29k|    CamelliaSubkeyR(2) = subr(3);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(2) = subr(3);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  934|  1.29k|    CamelliaSubkeyL(3) = subl(2) ^ subl(4);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(3) = subl(2) ^ subl(4);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(3) = subl(2) ^ subl(4);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  935|  1.29k|    CamelliaSubkeyR(3) = subr(2) ^ subr(4);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(3) = subr(2) ^ subr(4);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(3) = subr(2) ^ subr(4);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  936|  1.29k|    CamelliaSubkeyL(4) = subl(3) ^ subl(5);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(4) = subl(3) ^ subl(5);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(4) = subl(3) ^ subl(5);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  937|  1.29k|    CamelliaSubkeyR(4) = subr(3) ^ subr(5);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(4) = subr(3) ^ subr(5);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(4) = subr(3) ^ subr(5);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  938|  1.29k|    CamelliaSubkeyL(5) = subl(4) ^ subl(6);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(5) = subl(4) ^ subl(6);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(5) = subl(4) ^ subl(6);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  939|  1.29k|    CamelliaSubkeyR(5) = subr(4) ^ subr(6);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(5) = subr(4) ^ subr(6);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(5) = subr(4) ^ subr(6);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  940|  1.29k|    CamelliaSubkeyL(6) = subl(5) ^ subl(7);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(6) = subl(5) ^ subl(7);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(6) = subl(5) ^ subl(7);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  941|  1.29k|    CamelliaSubkeyR(6) = subr(5) ^ subr(7);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(6) = subr(5) ^ subr(7);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(6) = subr(5) ^ subr(7);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  942|  1.29k|    tl = subl(10) ^ (subr(10) & ~subr(8));
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(10) ^ (subr(10) & ~subr(8));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(10) ^ (subr(10) & ~subr(8));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  943|  1.29k|    dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(8), tr = subr(10) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  944|  1.29k|    CamelliaSubkeyL(7) = subl(6) ^ tl;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(7) = subl(6) ^ tl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  945|  1.29k|    CamelliaSubkeyR(7) = subr(6) ^ tr;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(7) = subr(6) ^ tr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  946|  1.29k|    CamelliaSubkeyL(8) = subl(8);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(8) = subl(8);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  947|  1.29k|    CamelliaSubkeyR(8) = subr(8);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(8) = subr(8);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  948|  1.29k|    CamelliaSubkeyL(9) = subl(9);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(9) = subl(9);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  949|  1.29k|    CamelliaSubkeyR(9) = subr(9);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(9) = subr(9);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  950|  1.29k|    tl = subl(7) ^ (subr(7) & ~subr(9));
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(7) ^ (subr(7) & ~subr(9));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(7) ^ (subr(7) & ~subr(9));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  951|  1.29k|    dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(9), tr = subr(7) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  952|  1.29k|    CamelliaSubkeyL(10) = tl ^ subl(11);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(10) = tl ^ subl(11);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  953|  1.29k|    CamelliaSubkeyR(10) = tr ^ subr(11);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(10) = tr ^ subr(11);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  954|  1.29k|    CamelliaSubkeyL(11) = subl(10) ^ subl(12);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(11) = subl(10) ^ subl(12);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(11) = subl(10) ^ subl(12);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  955|  1.29k|    CamelliaSubkeyR(11) = subr(10) ^ subr(12);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(11) = subr(10) ^ subr(12);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(11) = subr(10) ^ subr(12);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  956|  1.29k|    CamelliaSubkeyL(12) = subl(11) ^ subl(13);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(12) = subl(11) ^ subl(13);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(12) = subl(11) ^ subl(13);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  957|  1.29k|    CamelliaSubkeyR(12) = subr(11) ^ subr(13);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(12) = subr(11) ^ subr(13);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(12) = subr(11) ^ subr(13);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  958|  1.29k|    CamelliaSubkeyL(13) = subl(12) ^ subl(14);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(13) = subl(12) ^ subl(14);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(13) = subl(12) ^ subl(14);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  959|  1.29k|    CamelliaSubkeyR(13) = subr(12) ^ subr(14);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(13) = subr(12) ^ subr(14);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(13) = subr(12) ^ subr(14);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  960|  1.29k|    CamelliaSubkeyL(14) = subl(13) ^ subl(15);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(14) = subl(13) ^ subl(15);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(14) = subl(13) ^ subl(15);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  961|  1.29k|    CamelliaSubkeyR(14) = subr(13) ^ subr(15);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(14) = subr(13) ^ subr(15);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(14) = subr(13) ^ subr(15);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  962|  1.29k|    tl = subl(18) ^ (subr(18) & ~subr(16));
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(18) ^ (subr(18) & ~subr(16));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(18) ^ (subr(18) & ~subr(16));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  963|  1.29k|    dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(16), tr = subr(18) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  964|  1.29k|    CamelliaSubkeyL(15) = subl(14) ^ tl;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(15) = subl(14) ^ tl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  965|  1.29k|    CamelliaSubkeyR(15) = subr(14) ^ tr;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(15) = subr(14) ^ tr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  966|  1.29k|    CamelliaSubkeyL(16) = subl(16);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(16) = subl(16);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  967|  1.29k|    CamelliaSubkeyR(16) = subr(16);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(16) = subr(16);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  968|  1.29k|    CamelliaSubkeyL(17) = subl(17);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(17) = subl(17);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  969|  1.29k|    CamelliaSubkeyR(17) = subr(17);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(17) = subr(17);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  970|  1.29k|    tl = subl(15) ^ (subr(15) & ~subr(17));
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(15) ^ (subr(15) & ~subr(17));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(15) ^ (subr(15) & ~subr(17));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  971|  1.29k|    dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(17), tr = subr(15) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  972|  1.29k|    CamelliaSubkeyL(18) = tl ^ subl(19);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(18) = tl ^ subl(19);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  973|  1.29k|    CamelliaSubkeyR(18) = tr ^ subr(19);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(18) = tr ^ subr(19);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  974|  1.29k|    CamelliaSubkeyL(19) = subl(18) ^ subl(20);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(19) = subl(18) ^ subl(20);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(19) = subl(18) ^ subl(20);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  975|  1.29k|    CamelliaSubkeyR(19) = subr(18) ^ subr(20);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(19) = subr(18) ^ subr(20);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(19) = subr(18) ^ subr(20);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  976|  1.29k|    CamelliaSubkeyL(20) = subl(19) ^ subl(21);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(20) = subl(19) ^ subl(21);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(20) = subl(19) ^ subl(21);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  977|  1.29k|    CamelliaSubkeyR(20) = subr(19) ^ subr(21);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(20) = subr(19) ^ subr(21);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(20) = subr(19) ^ subr(21);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  978|  1.29k|    CamelliaSubkeyL(21) = subl(20) ^ subl(22);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(21) = subl(20) ^ subl(22);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(21) = subl(20) ^ subl(22);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  979|  1.29k|    CamelliaSubkeyR(21) = subr(20) ^ subr(22);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(21) = subr(20) ^ subr(22);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(21) = subr(20) ^ subr(22);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  980|  1.29k|    CamelliaSubkeyL(22) = subl(21) ^ subl(23);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(22) = subl(21) ^ subl(23);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(22) = subl(21) ^ subl(23);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  981|  1.29k|    CamelliaSubkeyR(22) = subr(21) ^ subr(23);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(22) = subr(21) ^ subr(23);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(22) = subr(21) ^ subr(23);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  982|  1.29k|    tl = subl(26) ^ (subr(26) & ~subr(24));
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(26) ^ (subr(26) & ~subr(24));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(26) ^ (subr(26) & ~subr(24));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  983|  1.29k|    dw = tl & subl(24), tr = subr(26) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(24), tr = subr(26) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(24), tr = subr(26) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  984|  1.29k|    CamelliaSubkeyL(23) = subl(22) ^ tl;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(23) = subl(22) ^ tl;
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  985|  1.29k|    CamelliaSubkeyR(23) = subr(22) ^ tr;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(23) = subr(22) ^ tr;
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  986|  1.29k|    CamelliaSubkeyL(24) = subl(24);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(24) = subl(24);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  987|  1.29k|    CamelliaSubkeyR(24) = subr(24);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(24) = subr(24);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  988|  1.29k|    CamelliaSubkeyL(25) = subl(25);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(25) = subl(25);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  989|  1.29k|    CamelliaSubkeyR(25) = subr(25);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(25) = subr(25);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  990|  1.29k|    tl = subl(23) ^ (subr(23) & ~subr(25));
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  tl = subl(23) ^ (subr(23) & ~subr(25));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  tl = subl(23) ^ (subr(23) & ~subr(25));
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  991|  1.29k|    dw = tl & subl(25), tr = subr(23) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  dw = tl & subl(25), tr = subr(23) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  dw = tl & subl(25), tr = subr(23) ^ CAMELLIA_RL1(dw);
  ------------------
  |  |   72|  1.29k|#define CAMELLIA_RL1(x) (((x) << 1) + ((x) >> 31))
  ------------------
  992|  1.29k|    CamelliaSubkeyL(26) = tl ^ subl(27);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(26) = tl ^ subl(27);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  993|  1.29k|    CamelliaSubkeyR(26) = tr ^ subr(27);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(26) = tr ^ subr(27);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  994|  1.29k|    CamelliaSubkeyL(27) = subl(26) ^ subl(28);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(27) = subl(26) ^ subl(28);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(27) = subl(26) ^ subl(28);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  995|  1.29k|    CamelliaSubkeyR(27) = subr(26) ^ subr(28);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(27) = subr(26) ^ subr(28);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(27) = subr(26) ^ subr(28);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  996|  1.29k|    CamelliaSubkeyL(28) = subl(27) ^ subl(29);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(28) = subl(27) ^ subl(29);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(28) = subl(27) ^ subl(29);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  997|  1.29k|    CamelliaSubkeyR(28) = subr(27) ^ subr(29);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(28) = subr(27) ^ subr(29);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(28) = subr(27) ^ subr(29);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
  998|  1.29k|    CamelliaSubkeyL(29) = subl(28) ^ subl(30);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(29) = subl(28) ^ subl(30);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(29) = subl(28) ^ subl(30);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
  999|  1.29k|    CamelliaSubkeyR(29) = subr(28) ^ subr(30);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(29) = subr(28) ^ subr(30);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(29) = subr(28) ^ subr(30);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
 1000|  1.29k|    CamelliaSubkeyL(30) = subl(29) ^ subl(31);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(30) = subl(29) ^ subl(31);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(30) = subl(29) ^ subl(31);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
 1001|  1.29k|    CamelliaSubkeyR(30) = subr(29) ^ subr(31);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(30) = subr(29) ^ subr(31);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(30) = subr(29) ^ subr(31);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
 1002|  1.29k|    CamelliaSubkeyL(31) = subl(30);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(31) = subl(30);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
 1003|  1.29k|    CamelliaSubkeyR(31) = subr(30);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(31) = subr(30);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
 1004|  1.29k|    CamelliaSubkeyL(32) = subl(32) ^ subl(31);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyL(32) = subl(32) ^ subl(31);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
                  CamelliaSubkeyL(32) = subl(32) ^ subl(31);
  ------------------
  |  |  430|  1.29k|#define subl(x) subL[(x)]
  ------------------
 1005|  1.29k|    CamelliaSubkeyR(32) = subr(32) ^ subr(31);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(32) = subr(32) ^ subr(31);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
                  CamelliaSubkeyR(32) = subr(32) ^ subr(31);
  ------------------
  |  |  431|  1.29k|#define subr(x) subR[(x)]
  ------------------
 1006|       |
 1007|       |    /* apply the inverse of the last half of P-function */
 1008|  1.29k|    dw = CamelliaSubkeyL(2) ^ CamelliaSubkeyR(2), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(2) ^ CamelliaSubkeyR(2), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(2) ^ CamelliaSubkeyR(2), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1009|  1.29k|    CamelliaSubkeyR(2) = CamelliaSubkeyL(2) ^ dw, CamelliaSubkeyL(2) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(2) = CamelliaSubkeyL(2) ^ dw, CamelliaSubkeyL(2) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(2) = CamelliaSubkeyL(2) ^ dw, CamelliaSubkeyL(2) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1010|  1.29k|    dw = CamelliaSubkeyL(3) ^ CamelliaSubkeyR(3), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(3) ^ CamelliaSubkeyR(3), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(3) ^ CamelliaSubkeyR(3), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1011|  1.29k|    CamelliaSubkeyR(3) = CamelliaSubkeyL(3) ^ dw, CamelliaSubkeyL(3) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(3) = CamelliaSubkeyL(3) ^ dw, CamelliaSubkeyL(3) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(3) = CamelliaSubkeyL(3) ^ dw, CamelliaSubkeyL(3) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1012|  1.29k|    dw = CamelliaSubkeyL(4) ^ CamelliaSubkeyR(4), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(4) ^ CamelliaSubkeyR(4), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(4) ^ CamelliaSubkeyR(4), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1013|  1.29k|    CamelliaSubkeyR(4) = CamelliaSubkeyL(4) ^ dw, CamelliaSubkeyL(4) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(4) = CamelliaSubkeyL(4) ^ dw, CamelliaSubkeyL(4) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(4) = CamelliaSubkeyL(4) ^ dw, CamelliaSubkeyL(4) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1014|  1.29k|    dw = CamelliaSubkeyL(5) ^ CamelliaSubkeyR(5), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(5) ^ CamelliaSubkeyR(5), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(5) ^ CamelliaSubkeyR(5), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1015|  1.29k|    CamelliaSubkeyR(5) = CamelliaSubkeyL(5) ^ dw, CamelliaSubkeyL(5) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(5) = CamelliaSubkeyL(5) ^ dw, CamelliaSubkeyL(5) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(5) = CamelliaSubkeyL(5) ^ dw, CamelliaSubkeyL(5) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1016|  1.29k|    dw = CamelliaSubkeyL(6) ^ CamelliaSubkeyR(6), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(6) ^ CamelliaSubkeyR(6), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(6) ^ CamelliaSubkeyR(6), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1017|  1.29k|    CamelliaSubkeyR(6) = CamelliaSubkeyL(6) ^ dw, CamelliaSubkeyL(6) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(6) = CamelliaSubkeyL(6) ^ dw, CamelliaSubkeyL(6) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(6) = CamelliaSubkeyL(6) ^ dw, CamelliaSubkeyL(6) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1018|  1.29k|    dw = CamelliaSubkeyL(7) ^ CamelliaSubkeyR(7), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(7) ^ CamelliaSubkeyR(7), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(7) ^ CamelliaSubkeyR(7), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1019|  1.29k|    CamelliaSubkeyR(7) = CamelliaSubkeyL(7) ^ dw, CamelliaSubkeyL(7) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(7) = CamelliaSubkeyL(7) ^ dw, CamelliaSubkeyL(7) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(7) = CamelliaSubkeyL(7) ^ dw, CamelliaSubkeyL(7) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1020|  1.29k|    dw = CamelliaSubkeyL(10) ^ CamelliaSubkeyR(10), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(10) ^ CamelliaSubkeyR(10), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(10) ^ CamelliaSubkeyR(10), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1021|  1.29k|    CamelliaSubkeyR(10) = CamelliaSubkeyL(10) ^ dw, CamelliaSubkeyL(10) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(10) = CamelliaSubkeyL(10) ^ dw, CamelliaSubkeyL(10) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(10) = CamelliaSubkeyL(10) ^ dw, CamelliaSubkeyL(10) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1022|  1.29k|    dw = CamelliaSubkeyL(11) ^ CamelliaSubkeyR(11), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(11) ^ CamelliaSubkeyR(11), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(11) ^ CamelliaSubkeyR(11), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1023|  1.29k|    CamelliaSubkeyR(11) = CamelliaSubkeyL(11) ^ dw, CamelliaSubkeyL(11) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(11) = CamelliaSubkeyL(11) ^ dw, CamelliaSubkeyL(11) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(11) = CamelliaSubkeyL(11) ^ dw, CamelliaSubkeyL(11) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1024|  1.29k|    dw = CamelliaSubkeyL(12) ^ CamelliaSubkeyR(12), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(12) ^ CamelliaSubkeyR(12), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(12) ^ CamelliaSubkeyR(12), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1025|  1.29k|    CamelliaSubkeyR(12) = CamelliaSubkeyL(12) ^ dw, CamelliaSubkeyL(12) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(12) = CamelliaSubkeyL(12) ^ dw, CamelliaSubkeyL(12) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(12) = CamelliaSubkeyL(12) ^ dw, CamelliaSubkeyL(12) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1026|  1.29k|    dw = CamelliaSubkeyL(13) ^ CamelliaSubkeyR(13), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(13) ^ CamelliaSubkeyR(13), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(13) ^ CamelliaSubkeyR(13), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1027|  1.29k|    CamelliaSubkeyR(13) = CamelliaSubkeyL(13) ^ dw, CamelliaSubkeyL(13) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(13) = CamelliaSubkeyL(13) ^ dw, CamelliaSubkeyL(13) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(13) = CamelliaSubkeyL(13) ^ dw, CamelliaSubkeyL(13) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1028|  1.29k|    dw = CamelliaSubkeyL(14) ^ CamelliaSubkeyR(14), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(14) ^ CamelliaSubkeyR(14), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(14) ^ CamelliaSubkeyR(14), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1029|  1.29k|    CamelliaSubkeyR(14) = CamelliaSubkeyL(14) ^ dw, CamelliaSubkeyL(14) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(14) = CamelliaSubkeyL(14) ^ dw, CamelliaSubkeyL(14) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(14) = CamelliaSubkeyL(14) ^ dw, CamelliaSubkeyL(14) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1030|  1.29k|    dw = CamelliaSubkeyL(15) ^ CamelliaSubkeyR(15), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(15) ^ CamelliaSubkeyR(15), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(15) ^ CamelliaSubkeyR(15), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1031|  1.29k|    CamelliaSubkeyR(15) = CamelliaSubkeyL(15) ^ dw, CamelliaSubkeyL(15) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(15) = CamelliaSubkeyL(15) ^ dw, CamelliaSubkeyL(15) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(15) = CamelliaSubkeyL(15) ^ dw, CamelliaSubkeyL(15) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1032|  1.29k|    dw = CamelliaSubkeyL(18) ^ CamelliaSubkeyR(18), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(18) ^ CamelliaSubkeyR(18), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(18) ^ CamelliaSubkeyR(18), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1033|  1.29k|    CamelliaSubkeyR(18) = CamelliaSubkeyL(18) ^ dw, CamelliaSubkeyL(18) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(18) = CamelliaSubkeyL(18) ^ dw, CamelliaSubkeyL(18) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(18) = CamelliaSubkeyL(18) ^ dw, CamelliaSubkeyL(18) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1034|  1.29k|    dw = CamelliaSubkeyL(19) ^ CamelliaSubkeyR(19), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(19) ^ CamelliaSubkeyR(19), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(19) ^ CamelliaSubkeyR(19), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1035|  1.29k|    CamelliaSubkeyR(19) = CamelliaSubkeyL(19) ^ dw, CamelliaSubkeyL(19) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(19) = CamelliaSubkeyL(19) ^ dw, CamelliaSubkeyL(19) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(19) = CamelliaSubkeyL(19) ^ dw, CamelliaSubkeyL(19) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1036|  1.29k|    dw = CamelliaSubkeyL(20) ^ CamelliaSubkeyR(20), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(20) ^ CamelliaSubkeyR(20), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(20) ^ CamelliaSubkeyR(20), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1037|  1.29k|    CamelliaSubkeyR(20) = CamelliaSubkeyL(20) ^ dw, CamelliaSubkeyL(20) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(20) = CamelliaSubkeyL(20) ^ dw, CamelliaSubkeyL(20) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(20) = CamelliaSubkeyL(20) ^ dw, CamelliaSubkeyL(20) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1038|  1.29k|    dw = CamelliaSubkeyL(21) ^ CamelliaSubkeyR(21), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(21) ^ CamelliaSubkeyR(21), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(21) ^ CamelliaSubkeyR(21), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1039|  1.29k|    CamelliaSubkeyR(21) = CamelliaSubkeyL(21) ^ dw, CamelliaSubkeyL(21) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(21) = CamelliaSubkeyL(21) ^ dw, CamelliaSubkeyL(21) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(21) = CamelliaSubkeyL(21) ^ dw, CamelliaSubkeyL(21) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1040|  1.29k|    dw = CamelliaSubkeyL(22) ^ CamelliaSubkeyR(22), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(22) ^ CamelliaSubkeyR(22), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(22) ^ CamelliaSubkeyR(22), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1041|  1.29k|    CamelliaSubkeyR(22) = CamelliaSubkeyL(22) ^ dw, CamelliaSubkeyL(22) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(22) = CamelliaSubkeyL(22) ^ dw, CamelliaSubkeyL(22) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(22) = CamelliaSubkeyL(22) ^ dw, CamelliaSubkeyL(22) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1042|  1.29k|    dw = CamelliaSubkeyL(23) ^ CamelliaSubkeyR(23), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(23) ^ CamelliaSubkeyR(23), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(23) ^ CamelliaSubkeyR(23), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1043|  1.29k|    CamelliaSubkeyR(23) = CamelliaSubkeyL(23) ^ dw, CamelliaSubkeyL(23) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(23) = CamelliaSubkeyL(23) ^ dw, CamelliaSubkeyL(23) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(23) = CamelliaSubkeyL(23) ^ dw, CamelliaSubkeyL(23) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1044|  1.29k|    dw = CamelliaSubkeyL(26) ^ CamelliaSubkeyR(26), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(26) ^ CamelliaSubkeyR(26), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(26) ^ CamelliaSubkeyR(26), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1045|  1.29k|    CamelliaSubkeyR(26) = CamelliaSubkeyL(26) ^ dw, CamelliaSubkeyL(26) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(26) = CamelliaSubkeyL(26) ^ dw, CamelliaSubkeyL(26) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(26) = CamelliaSubkeyL(26) ^ dw, CamelliaSubkeyL(26) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1046|  1.29k|    dw = CamelliaSubkeyL(27) ^ CamelliaSubkeyR(27), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(27) ^ CamelliaSubkeyR(27), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(27) ^ CamelliaSubkeyR(27), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1047|  1.29k|    CamelliaSubkeyR(27) = CamelliaSubkeyL(27) ^ dw, CamelliaSubkeyL(27) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(27) = CamelliaSubkeyL(27) ^ dw, CamelliaSubkeyL(27) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(27) = CamelliaSubkeyL(27) ^ dw, CamelliaSubkeyL(27) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1048|  1.29k|    dw = CamelliaSubkeyL(28) ^ CamelliaSubkeyR(28), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(28) ^ CamelliaSubkeyR(28), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(28) ^ CamelliaSubkeyR(28), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1049|  1.29k|    CamelliaSubkeyR(28) = CamelliaSubkeyL(28) ^ dw, CamelliaSubkeyL(28) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(28) = CamelliaSubkeyL(28) ^ dw, CamelliaSubkeyL(28) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(28) = CamelliaSubkeyL(28) ^ dw, CamelliaSubkeyL(28) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1050|  1.29k|    dw = CamelliaSubkeyL(29) ^ CamelliaSubkeyR(29), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(29) ^ CamelliaSubkeyR(29), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(29) ^ CamelliaSubkeyR(29), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1051|  1.29k|    CamelliaSubkeyR(29) = CamelliaSubkeyL(29) ^ dw, CamelliaSubkeyL(29) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(29) = CamelliaSubkeyL(29) ^ dw, CamelliaSubkeyL(29) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(29) = CamelliaSubkeyL(29) ^ dw, CamelliaSubkeyL(29) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1052|  1.29k|    dw = CamelliaSubkeyL(30) ^ CamelliaSubkeyR(30), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(30) ^ CamelliaSubkeyR(30), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(30) ^ CamelliaSubkeyR(30), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1053|  1.29k|    CamelliaSubkeyR(30) = CamelliaSubkeyL(30) ^ dw, CamelliaSubkeyL(30) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(30) = CamelliaSubkeyL(30) ^ dw, CamelliaSubkeyL(30) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(30) = CamelliaSubkeyL(30) ^ dw, CamelliaSubkeyL(30) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1054|  1.29k|    dw = CamelliaSubkeyL(31) ^ CamelliaSubkeyR(31), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  dw = CamelliaSubkeyL(31) ^ CamelliaSubkeyR(31), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  dw = CamelliaSubkeyL(31) ^ CamelliaSubkeyR(31), dw = CAMELLIA_RL8(dw);
  ------------------
  |  |   74|  1.29k|#define CAMELLIA_RL8(x) (((x) << 8) + ((x) >> 24))
  ------------------
 1055|  1.29k|    CamelliaSubkeyR(31) = CamelliaSubkeyL(31) ^ dw, CamelliaSubkeyL(31) = dw;
  ------------------
  |  |   67|  1.29k|#define CamelliaSubkeyR(INDEX) (subkey[(INDEX)*2 + 1])
  ------------------
                  CamelliaSubkeyR(31) = CamelliaSubkeyL(31) ^ dw, CamelliaSubkeyL(31) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
                  CamelliaSubkeyR(31) = CamelliaSubkeyL(31) ^ dw, CamelliaSubkeyL(31) = dw;
  ------------------
  |  |   66|  1.29k|#define CamelliaSubkeyL(INDEX) (subkey[(INDEX)*2])
  ------------------
 1056|       |
 1057|  1.29k|    return;
 1058|  1.29k|}
camellia_key_expansion:
 1570|  2.03k|{
 1571|  2.03k|    cx->keysize = keysize;
 1572|       |
 1573|  2.03k|    switch (keysize) {
 1574|    738|        case 16:
  ------------------
  |  Branch (1574:9): [True: 738, False: 1.29k]
  ------------------
 1575|    738|            camellia_setup128(key, cx->expandedKey);
 1576|    738|            break;
 1577|      0|        case 24:
  ------------------
  |  Branch (1577:9): [True: 0, False: 2.03k]
  ------------------
 1578|      0|            camellia_setup192(key, cx->expandedKey);
 1579|      0|            break;
 1580|  1.29k|        case 32:
  ------------------
  |  Branch (1580:9): [True: 1.29k, False: 738]
  ------------------
 1581|  1.29k|            camellia_setup256(key, cx->expandedKey);
 1582|  1.29k|            break;
 1583|      0|        default:
  ------------------
  |  Branch (1583:9): [True: 0, False: 2.03k]
  ------------------
 1584|      0|            break;
 1585|  2.03k|    }
 1586|  2.03k|    return SECSuccess;
 1587|  2.03k|}
Camellia_CreateContext:
 1777|  2.03k|{
 1778|  2.03k|    CamelliaContext *cx;
 1779|       |
 1780|  2.03k|    if (key == NULL ||
  ------------------
  |  Branch (1780:9): [True: 0, False: 2.03k]
  ------------------
 1781|  2.03k|        (keysize != 16 && keysize != 24 && keysize != 32)) {
  ------------------
  |  Branch (1781:10): [True: 1.29k, False: 738]
  |  Branch (1781:27): [True: 1.29k, False: 0]
  |  Branch (1781:44): [True: 0, False: 1.29k]
  ------------------
 1782|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1783|      0|        return NULL;
 1784|      0|    }
 1785|  2.03k|    if (mode != NSS_CAMELLIA && mode != NSS_CAMELLIA_CBC) {
  ------------------
  |  |   42|  4.06k|#define NSS_CAMELLIA 0
  ------------------
                  if (mode != NSS_CAMELLIA && mode != NSS_CAMELLIA_CBC) {
  ------------------
  |  |   43|  2.03k|#define NSS_CAMELLIA_CBC 1
  ------------------
  |  Branch (1785:9): [True: 2.03k, False: 0]
  |  Branch (1785:33): [True: 0, False: 2.03k]
  ------------------
 1786|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1787|      0|        return NULL;
 1788|      0|    }
 1789|  2.03k|    if (mode == NSS_CAMELLIA_CBC && iv == NULL) {
  ------------------
  |  |   43|  4.06k|#define NSS_CAMELLIA_CBC 1
  ------------------
  |  Branch (1789:9): [True: 2.03k, False: 0]
  |  Branch (1789:37): [True: 0, False: 2.03k]
  ------------------
 1790|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1791|      0|        return NULL;
 1792|      0|    }
 1793|  2.03k|    cx = PORT_ZNew(CamelliaContext);
  ------------------
  |  |  148|  2.03k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  2.03k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1794|  2.03k|    if (!cx) {
  ------------------
  |  Branch (1794:9): [True: 0, False: 2.03k]
  ------------------
 1795|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1796|      0|        return NULL;
 1797|      0|    }
 1798|       |
 1799|       |    /* copy in the iv, if neccessary */
 1800|  2.03k|    if (mode == NSS_CAMELLIA_CBC) {
  ------------------
  |  |   43|  2.03k|#define NSS_CAMELLIA_CBC 1
  ------------------
  |  Branch (1800:9): [True: 2.03k, False: 0]
  ------------------
 1801|  2.03k|        memcpy(cx->iv, iv, CAMELLIA_BLOCK_SIZE);
  ------------------
  |  |    8|  2.03k|#define CAMELLIA_BLOCK_SIZE 16  /* bytes */
  ------------------
 1802|  2.03k|        cx->worker = (encrypt) ? &camellia_encryptCBC : &camellia_decryptCBC;
  ------------------
  |  Branch (1802:22): [True: 1.01k, False: 1.01k]
  ------------------
 1803|  2.03k|    } else {
 1804|      0|        cx->worker = (encrypt) ? &camellia_encryptECB : &camellia_decryptECB;
  ------------------
  |  Branch (1804:22): [True: 0, False: 0]
  ------------------
 1805|      0|    }
 1806|       |    /* copy keysize */
 1807|  2.03k|    cx->keysize = keysize;
 1808|       |
 1809|       |    /* Generate expanded key */
 1810|  2.03k|    if (camellia_key_expansion(cx, key, keysize) != SECSuccess)
  ------------------
  |  Branch (1810:9): [True: 0, False: 2.03k]
  ------------------
 1811|      0|        goto cleanup;
 1812|       |
 1813|  2.03k|    return cx;
 1814|      0|cleanup:
 1815|      0|    PORT_ZFree(cx, sizeof *cx);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 1816|      0|    return NULL;
 1817|  2.03k|}
Camellia_DestroyContext:
 1827|  2.03k|{
 1828|  2.03k|    if (cx)
  ------------------
  |  Branch (1828:9): [True: 2.03k, False: 0]
  ------------------
 1829|  2.03k|        memset(cx, 0, sizeof *cx);
 1830|  2.03k|    if (freeit)
  ------------------
  |  Branch (1830:9): [True: 2.03k, False: 0]
  ------------------
 1831|  2.03k|        PORT_Free(cx);
  ------------------
  |  |   60|  2.03k|#define PORT_Free PORT_Free_Util
  ------------------
 1832|  2.03k|}

ChaCha20Poly1305_InitContext:
  153|   278k|{
  154|       |#ifdef NSS_DISABLE_CHACHAPOLY
  155|       |    return SECFailure;
  156|       |#else
  157|   278k|    if (keyLen != 32) {
  ------------------
  |  Branch (157:9): [True: 0, False: 278k]
  ------------------
  158|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  159|      0|        return SECFailure;
  160|      0|    }
  161|   278k|    if (tagLen != 16) {
  ------------------
  |  Branch (161:9): [True: 0, False: 278k]
  ------------------
  162|      0|        PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  163|      0|        return SECFailure;
  164|      0|    }
  165|       |
  166|   278k|    PORT_Memcpy(ctx->key, key, sizeof(ctx->key));
  ------------------
  |  |  180|   278k|#define PORT_Memcpy memcpy
  ------------------
  167|   278k|    ctx->tagLen = tagLen;
  168|       |
  169|   278k|    NSS_CLASSIFY(ctx->key, sizeof(ctx->key));
  170|       |
  171|   278k|    return SECSuccess;
  172|   278k|#endif
  173|   278k|}
ChaCha20Poly1305_CreateContext:
  178|   278k|{
  179|       |#ifdef NSS_DISABLE_CHACHAPOLY
  180|       |    return NULL;
  181|       |#else
  182|   278k|    ChaCha20Poly1305Context *ctx;
  183|       |
  184|   278k|    ctx = PORT_New(ChaCha20Poly1305Context);
  ------------------
  |  |  151|   278k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|   278k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  185|   278k|    if (ctx == NULL) {
  ------------------
  |  Branch (185:9): [True: 0, False: 278k]
  ------------------
  186|      0|        return NULL;
  187|      0|    }
  188|       |
  189|   278k|    if (ChaCha20Poly1305_InitContext(ctx, key, keyLen, tagLen) != SECSuccess) {
  ------------------
  |  Branch (189:9): [True: 0, False: 278k]
  ------------------
  190|      0|        PORT_Free(ctx);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  191|      0|        ctx = NULL;
  192|      0|    }
  193|       |
  194|   278k|    return ctx;
  195|   278k|#endif
  196|   278k|}
ChaCha20Poly1305_DestroyContext:
  200|   278k|{
  201|   278k|#ifndef NSS_DISABLE_CHACHAPOLY
  202|   278k|    PORT_Memset(ctx, 0, sizeof(*ctx));
  ------------------
  |  |  182|   278k|#define PORT_Memset memset
  ------------------
  203|   278k|    if (freeit) {
  ------------------
  |  Branch (203:9): [True: 278k, False: 0]
  ------------------
  204|   278k|        PORT_Free(ctx);
  ------------------
  |  |   60|   278k|#define PORT_Free PORT_Free_Util
  ------------------
  205|   278k|    }
  206|   278k|#endif
  207|   278k|}

SEED_set_key:
  300|  1.48k|{
  301|  1.48k|    seed_word K0, K1, K2, K3;
  302|  1.48k|    seed_word t0, t1;
  303|       |
  304|  1.48k|    char2word(rawkey, K0);
  ------------------
  |  |   24|  1.48k|    (i) = ((((seed_word)((c)[0])) << 24) | \
  |  |   25|  1.48k|           (((seed_word)((c)[1])) << 16) | \
  |  |   26|  1.48k|           (((seed_word)((c)[2])) << 8) |  \
  |  |   27|  1.48k|           ((seed_word)((c)[3])))
  ------------------
  305|  1.48k|    char2word(rawkey + 4, K1);
  ------------------
  |  |   24|  1.48k|    (i) = ((((seed_word)((c)[0])) << 24) | \
  |  |   25|  1.48k|           (((seed_word)((c)[1])) << 16) | \
  |  |   26|  1.48k|           (((seed_word)((c)[2])) << 8) |  \
  |  |   27|  1.48k|           ((seed_word)((c)[3])))
  ------------------
  306|  1.48k|    char2word(rawkey + 8, K2);
  ------------------
  |  |   24|  1.48k|    (i) = ((((seed_word)((c)[0])) << 24) | \
  |  |   25|  1.48k|           (((seed_word)((c)[1])) << 16) | \
  |  |   26|  1.48k|           (((seed_word)((c)[2])) << 8) |  \
  |  |   27|  1.48k|           ((seed_word)((c)[3])))
  ------------------
  307|  1.48k|    char2word(rawkey + 12, K3);
  ------------------
  |  |   24|  1.48k|    (i) = ((((seed_word)((c)[0])) << 24) | \
  |  |   25|  1.48k|           (((seed_word)((c)[1])) << 16) | \
  |  |   26|  1.48k|           (((seed_word)((c)[2])) << 8) |  \
  |  |   27|  1.48k|           ((seed_word)((c)[3])))
  ------------------
  308|       |
  309|  1.48k|    t0 = (K0 + K2 - KC0);
  ------------------
  |  |  280|  1.48k|#define KC0 0x9e3779b9
  ------------------
  310|  1.48k|    t1 = (K1 - K3 + KC0);
  ------------------
  |  |  280|  1.48k|#define KC0 0x9e3779b9
  ------------------
  311|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[0]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  312|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC1);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  313|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[2]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  314|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC2);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  315|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[4]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  316|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC3);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  317|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[6]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  318|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC4);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  319|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[8]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  320|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC5);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  321|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[10]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  322|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC6);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  323|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[12]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  324|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC7);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  325|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[14]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  326|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC8);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  327|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[16]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  328|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC9);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  329|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[18]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  330|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC10);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  331|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[20]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  332|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC11);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  333|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[22]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  334|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC12);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  335|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[24]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  336|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC13);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  337|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[26]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  338|  1.48k|    KEYSCHEDULE_UPDATE0(t0, t1, K0, K1, K2, K3, KC14);
  ------------------
  |  |   36|  1.48k|    (T0) = (K2);                                        \
  |  |   37|  1.48k|    (K2) = (((K2) << 8) ^ ((K3) >> 24));                \
  |  |   38|  1.48k|    (K3) = (((K3) << 8) ^ ((T0) >> 24));                \
  |  |   39|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   40|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  339|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[28]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  340|  1.48k|    KEYSCHEDULE_UPDATE1(t0, t1, K0, K1, K2, K3, KC15);
  ------------------
  |  |   43|  1.48k|    (T0) = (K0);                                        \
  |  |   44|  1.48k|    (K0) = (((K0) >> 8) ^ ((K1) << 24));                \
  |  |   45|  1.48k|    (K1) = (((K1) >> 8) ^ ((T0) << 24));                \
  |  |   46|  1.48k|    (T0) = ((K0) + (K2) - (KC));                        \
  |  |   47|  1.48k|    (T1) = ((K1) + (KC) - (K3))
  ------------------
  341|  1.48k|    KEYUPDATE_TEMP(t0, t1, &ks->data[30]);
  ------------------
  |  |   50|  1.48k|    (K)[0] = G_FUNC((T0));        \
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  |  |   51|  1.48k|    (K)[1] = G_FUNC((T1))
  |  |  ------------------
  |  |  |  |   18|  1.48k|    SS[0][((v)&0xff)] ^             \
  |  |  |  |   19|  1.48k|        SS[1][((v) >> 8 & 0xff)] ^  \
  |  |  |  |   20|  1.48k|        SS[2][((v) >> 16 & 0xff)] ^ \
  |  |  |  |   21|  1.48k|        SS[3][((v) >> 24 & 0xff)]
  |  |  ------------------
  ------------------
  342|  1.48k|}
SEED_InitContext:
  538|  1.48k|{
  539|  1.48k|    if (!cx) {
  ------------------
  |  Branch (539:9): [True: 0, False: 1.48k]
  ------------------
  540|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  541|      0|        return SECFailure;
  542|      0|    }
  543|       |
  544|  1.48k|    switch (mode) {
  545|      0|        case NSS_SEED:
  ------------------
  |  |   46|      0|#define NSS_SEED 0
  ------------------
  |  Branch (545:9): [True: 0, False: 1.48k]
  ------------------
  546|      0|            SEED_set_key(key, &cx->ks);
  547|      0|            cx->mode = NSS_SEED;
  ------------------
  |  |   46|      0|#define NSS_SEED 0
  ------------------
  548|      0|            cx->encrypt = encrypt;
  549|      0|            break;
  550|       |
  551|  1.48k|        case NSS_SEED_CBC:
  ------------------
  |  |   47|  1.48k|#define NSS_SEED_CBC 1
  ------------------
  |  Branch (551:9): [True: 1.48k, False: 0]
  ------------------
  552|  1.48k|            memcpy(cx->iv, iv, 16);
  553|  1.48k|            SEED_set_key(key, &cx->ks);
  554|  1.48k|            cx->mode = NSS_SEED_CBC;
  ------------------
  |  |   47|  1.48k|#define NSS_SEED_CBC 1
  ------------------
  555|  1.48k|            cx->encrypt = encrypt;
  556|  1.48k|            break;
  557|       |
  558|      0|        default:
  ------------------
  |  Branch (558:9): [True: 0, False: 1.48k]
  ------------------
  559|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  560|      0|            return SECFailure;
  561|  1.48k|    }
  562|       |
  563|  1.48k|    return SECSuccess;
  564|  1.48k|}
SEED_CreateContext:
  569|  1.48k|{
  570|  1.48k|    SEEDContext *cx = PORT_ZNew(SEEDContext);
  ------------------
  |  |  148|  1.48k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  1.48k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  571|  1.48k|    SECStatus rv = SEED_InitContext(cx, key, SEED_KEY_LENGTH, iv, mode,
  ------------------
  |  |  141|  1.48k|#define SEED_KEY_LENGTH 16 /* bytes */
  ------------------
  572|  1.48k|                                    encrypt, 0);
  573|       |
  574|  1.48k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (574:9): [True: 0, False: 1.48k]
  ------------------
  575|      0|        PORT_ZFree(cx, sizeof *cx);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  576|      0|        cx = NULL;
  577|      0|    }
  578|       |
  579|  1.48k|    return cx;
  580|  1.48k|}
SEED_DestroyContext:
  584|  1.48k|{
  585|  1.48k|    if (cx) {
  ------------------
  |  Branch (585:9): [True: 1.48k, False: 0]
  ------------------
  586|  1.48k|        memset(cx, 0, sizeof *cx);
  587|       |
  588|  1.48k|        if (freeit)
  ------------------
  |  Branch (588:13): [True: 1.48k, False: 0]
  ------------------
  589|  1.48k|            PORT_Free(cx);
  ------------------
  |  |   60|  1.48k|#define PORT_Free PORT_Free_Util
  ------------------
  590|  1.48k|    }
  591|  1.48k|}

DES_MakeSchedule:
  404|   147k|{
  405|   147k|    register HALF left, right;
  406|   147k|    register HALF c0, d0;
  407|   147k|    register HALF temp;
  408|   147k|    int delta;
  409|   147k|    unsigned int ls;
  410|       |
  411|   147k|#if defined(HAVE_UNALIGNED_ACCESS)
  412|   147k|    left = HALFPTR(key)[0];
  ------------------
  |  |   18|   147k|#define HALFPTR(x) ((HALF *)(x))
  ------------------
  413|   147k|    right = HALFPTR(key)[1];
  ------------------
  |  |   18|   147k|#define HALFPTR(x) ((HALF *)(x))
  ------------------
  414|   147k|#if defined(IS_LITTLE_ENDIAN)
  415|   147k|    BYTESWAP(left, temp);
  ------------------
  |  |  358|   147k|    __asm("bswap  %0"        \
  |  |  359|   147k|          : "+r"(word));
  ------------------
  416|   147k|    BYTESWAP(right, temp);
  ------------------
  |  |  358|   147k|    __asm("bswap  %0"        \
  |  |  359|   147k|          : "+r"(word));
  ------------------
  417|   147k|#endif
  418|       |#else
  419|       |    if (((ptrdiff_t)key & 0x03) == 0) {
  420|       |        left = HALFPTR(key)[0];
  421|       |        right = HALFPTR(key)[1];
  422|       |#if defined(IS_LITTLE_ENDIAN)
  423|       |        BYTESWAP(left, temp);
  424|       |        BYTESWAP(right, temp);
  425|       |#endif
  426|       |    } else {
  427|       |        left = ((HALF)key[0] << 24) | ((HALF)key[1] << 16) |
  428|       |               ((HALF)key[2] << 8) | key[3];
  429|       |        right = ((HALF)key[4] << 24) | ((HALF)key[5] << 16) |
  430|       |                ((HALF)key[6] << 8) | key[7];
  431|       |    }
  432|       |#endif
  433|       |
  434|   147k|    PC1(left, right, c0, d0, temp);
  ------------------
  |  |  387|   147k|    right ^= temp = ((left >> 4) ^ right) & 0x0f0f0f0f; \
  |  |  388|   147k|    left ^= temp << 4;                                  \
  |  |  389|   147k|    FLIP_RIGHT_DIAGONAL(left, temp);                    \
  |  |  ------------------
  |  |  |  |  351|   147k|    temp = (word ^ (word >> 18)) & 0x00003333; \
  |  |  |  |  352|   147k|    word ^= temp | (temp << 18);               \
  |  |  |  |  353|   147k|    temp = (word ^ (word >> 9)) & 0x00550055;  \
  |  |  |  |  354|   147k|    word ^= temp | (temp << 9);
  |  |  ------------------
  |  |  390|   147k|    FLIP_RIGHT_DIAGONAL(right, temp);                   \
  |  |  ------------------
  |  |  |  |  351|   147k|    temp = (word ^ (word >> 18)) & 0x00003333; \
  |  |  |  |  352|   147k|    word ^= temp | (temp << 18);               \
  |  |  |  |  353|   147k|    temp = (word ^ (word >> 9)) & 0x00550055;  \
  |  |  |  |  354|   147k|    word ^= temp | (temp << 9);
  |  |  ------------------
  |  |  391|   147k|    BYTESWAP(right, temp);                              \
  |  |  ------------------
  |  |  |  |  358|   147k|    __asm("bswap  %0"        \
  |  |  |  |  359|   147k|          : "+r"(word));
  |  |  ------------------
  |  |  392|   147k|    c0 = right >> 4;                                    \
  |  |  393|   147k|    d0 = ((left & 0x00ffffff) << 4) | (right & 0xf);
  ------------------
  435|       |
  436|   147k|    if (direction == DES_ENCRYPT) {
  ------------------
  |  Branch (436:9): [True: 90.5k, False: 56.5k]
  ------------------
  437|  90.5k|        delta = 2 * (int)sizeof(HALF);
  438|  90.5k|    } else {
  439|  56.5k|        ks += 30;
  440|  56.5k|        delta = (-2) * (int)sizeof(HALF);
  441|  56.5k|    }
  442|       |
  443|  2.50M|    for (ls = 0x8103; ls; ls >>= 1) {
  ------------------
  |  Branch (443:23): [True: 2.35M, False: 147k]
  ------------------
  444|  2.35M|        if (ls & 1) {
  ------------------
  |  Branch (444:13): [True: 588k, False: 1.76M]
  ------------------
  445|   588k|            c0 = LEFT_SHIFT_1(c0);
  ------------------
  |  |  395|   588k|#define LEFT_SHIFT_1(reg) (((reg << 1) | (reg >> 27)) & 0x0FFFFFFF)
  ------------------
  446|   588k|            d0 = LEFT_SHIFT_1(d0);
  ------------------
  |  |  395|   588k|#define LEFT_SHIFT_1(reg) (((reg << 1) | (reg >> 27)) & 0x0FFFFFFF)
  ------------------
  447|  1.76M|        } else {
  448|  1.76M|            c0 = LEFT_SHIFT_2(c0);
  ------------------
  |  |  396|  1.76M|#define LEFT_SHIFT_2(reg) (((reg << 2) | (reg >> 26)) & 0x0FFFFFFF)
  ------------------
  449|  1.76M|            d0 = LEFT_SHIFT_2(d0);
  ------------------
  |  |  396|  1.76M|#define LEFT_SHIFT_2(reg) (((reg << 2) | (reg >> 26)) & 0x0FFFFFFF)
  ------------------
  450|  1.76M|        }
  451|       |
  452|       |#ifdef USE_INDEXING
  453|       |#define PC2LOOKUP(b, c) PC2[b][c]
  454|       |
  455|       |        left = PC2LOOKUP(0, ((c0 >> 22) & 0x3F));
  456|       |        left |= PC2LOOKUP(1, ((c0 >> 13) & 0x3F));
  457|       |        left |= PC2LOOKUP(2, ((c0 >> 4) & 0x38) | (c0 & 0x7));
  458|       |        left |= PC2LOOKUP(3, ((c0 >> 18) & 0xC) | ((c0 >> 11) & 0x3) | (c0 & 0x30));
  459|       |
  460|       |        right = PC2LOOKUP(4, ((d0 >> 22) & 0x3F));
  461|       |        right |= PC2LOOKUP(5, ((d0 >> 15) & 0x30) | ((d0 >> 14) & 0xf));
  462|       |        right |= PC2LOOKUP(6, ((d0 >> 7) & 0x3F));
  463|       |        right |= PC2LOOKUP(7, ((d0 >> 1) & 0x3C) | (d0 & 0x3));
  464|       |#else
  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  466|       |
  467|  2.35M|        left = PC2LOOKUP(0, ((c0 >> 20) & 0xFC));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  468|  2.35M|        left |= PC2LOOKUP(1, ((c0 >> 11) & 0xFC));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  469|  2.35M|        left |= PC2LOOKUP(2, ((c0 >> 2) & 0xE0) | ((c0 << 2) & 0x1C));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  470|  2.35M|        left |= PC2LOOKUP(3, ((c0 >> 16) & 0x30) | ((c0 >> 9) & 0xC) | ((c0 << 2) & 0xC0));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  471|       |
  472|  2.35M|        right = PC2LOOKUP(4, ((d0 >> 20) & 0xFC));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  473|  2.35M|        right |= PC2LOOKUP(5, ((d0 >> 13) & 0xC0) | ((d0 >> 12) & 0x3C));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  474|  2.35M|        right |= PC2LOOKUP(6, ((d0 >> 5) & 0xFC));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  475|  2.35M|        right |= PC2LOOKUP(7, ((d0 << 1) & 0xF0) | ((d0 << 2) & 0x0C));
  ------------------
  |  |  465|  2.35M|#define PC2LOOKUP(b, c) *(HALF *)((BYTE *)&PC2[b][0] + (c))
  ------------------
  476|  2.35M|#endif
  477|       |        /* left  contains key bits for S1 S3 S2 S4 */
  478|       |        /* right contains key bits for S6 S8 S5 S7 */
  479|  2.35M|        temp = (left << 16)     /* S2 S4 XX XX */
  480|  2.35M|               | (right >> 16); /* XX XX S6 S8 */
  481|  2.35M|        ks[0] = temp;
  482|       |
  483|  2.35M|        temp = (left & 0xffff0000)     /* S1 S3 XX XX */
  484|  2.35M|               | (right & 0x0000ffff); /* XX XX S5 S7 */
  485|  2.35M|        ks[1] = temp;
  486|       |
  487|  2.35M|        ks = (HALF *)((BYTE *)ks + delta);
  488|  2.35M|    }
  489|   147k|}
DES_Do1Block:
  560|   611k|{
  561|   611k|    register HALF left, right;
  562|   611k|    register HALF temp;
  563|       |
  564|   611k|#if defined(HAVE_UNALIGNED_ACCESS)
  565|   611k|    left = HALFPTR(inbuf)[0];
  ------------------
  |  |   18|   611k|#define HALFPTR(x) ((HALF *)(x))
  ------------------
  566|   611k|    right = HALFPTR(inbuf)[1];
  ------------------
  |  |   18|   611k|#define HALFPTR(x) ((HALF *)(x))
  ------------------
  567|   611k|#if defined(IS_LITTLE_ENDIAN)
  568|   611k|    BYTESWAP(left, temp);
  ------------------
  |  |  358|   611k|    __asm("bswap  %0"        \
  |  |  359|   611k|          : "+r"(word));
  ------------------
  569|   611k|    BYTESWAP(right, temp);
  ------------------
  |  |  358|   611k|    __asm("bswap  %0"        \
  |  |  359|   611k|          : "+r"(word));
  ------------------
  570|   611k|#endif
  571|       |#else
  572|       |    if (((ptrdiff_t)inbuf & 0x03) == 0) {
  573|       |        left = HALFPTR(inbuf)[0];
  574|       |        right = HALFPTR(inbuf)[1];
  575|       |#if defined(IS_LITTLE_ENDIAN)
  576|       |        BYTESWAP(left, temp);
  577|       |        BYTESWAP(right, temp);
  578|       |#endif
  579|       |    } else {
  580|       |        left = ((HALF)inbuf[0] << 24) | ((HALF)inbuf[1] << 16) |
  581|       |               ((HALF)inbuf[2] << 8) | inbuf[3];
  582|       |        right = ((HALF)inbuf[4] << 24) | ((HALF)inbuf[5] << 16) |
  583|       |                ((HALF)inbuf[6] << 8) | inbuf[7];
  584|       |    }
  585|       |#endif
  586|       |
  587|   611k|    IP(left, right, temp);
  ------------------
  |  |  531|   611k|    right ^= temp = ((left >> 4) ^ right) & 0x0f0f0f0f;  \
  |  |  532|   611k|    left ^= temp << 4;                                   \
  |  |  533|   611k|    right ^= temp = ((left >> 16) ^ right) & 0x0000ffff; \
  |  |  534|   611k|    left ^= temp << 16;                                  \
  |  |  535|   611k|    right ^= temp = ((left << 2) ^ right) & 0xcccccccc;  \
  |  |  536|   611k|    left ^= temp >> 2;                                   \
  |  |  537|   611k|    right ^= temp = ((left << 8) ^ right) & 0xff00ff00;  \
  |  |  538|   611k|    left ^= temp >> 8;                                   \
  |  |  539|   611k|    right ^= temp = ((left >> 1) ^ right) & 0x55555555;  \
  |  |  540|   611k|    left ^= temp << 1;
  ------------------
  588|       |
  589|       |    /* shift the values left circularly 3 bits. */
  590|   611k|    left = (left << 3) | (left >> 29);
  591|   611k|    right = (right << 3) | (right >> 29);
  592|       |
  593|       |#ifdef USE_INDEXING
  594|       |#define KSLOOKUP(s, b) SP[s][((temp >> (b + 2)) & 0x3f)]
  595|       |#else
  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  597|   611k|#endif
  598|   611k|#define ROUND(out, in, r)                            \
  599|   611k|    temp = in ^ ks[2 * r];                           \
  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  608|   611k|    out ^= KSLOOKUP(6, 0);
  609|       |
  610|       |    /* Do the 16 Feistel rounds */
  611|   611k|    ROUND(left, right, 0)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  612|   611k|    ROUND(right, left, 1)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  613|   611k|    ROUND(left, right, 2)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  614|   611k|    ROUND(right, left, 3)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  615|   611k|    ROUND(left, right, 4)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  616|   611k|    ROUND(right, left, 5)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  617|   611k|    ROUND(left, right, 6)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  618|   611k|    ROUND(right, left, 7)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  619|   611k|    ROUND(left, right, 8)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  620|   611k|    ROUND(right, left, 9)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  621|   611k|    ROUND(left, right, 10)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  622|   611k|    ROUND(right, left, 11)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  623|   611k|    ROUND(left, right, 12)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  624|   611k|    ROUND(right, left, 13)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  625|   611k|    ROUND(left, right, 14)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  626|   611k|    ROUND(right, left, 15)
  ------------------
  |  |  599|   611k|    temp = in ^ ks[2 * r];                           \
  |  |  600|   611k|    out ^= KSLOOKUP(1, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  601|   611k|    out ^= KSLOOKUP(3, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  602|   611k|    out ^= KSLOOKUP(5, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  603|   611k|    out ^= KSLOOKUP(7, 0);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  604|   611k|    temp = ((in >> 4) | (in << 28)) ^ ks[2 * r + 1]; \
  |  |  605|   611k|    out ^= KSLOOKUP(0, 24);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  606|   611k|    out ^= KSLOOKUP(2, 16);                          \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  607|   611k|    out ^= KSLOOKUP(4, 8);                           \
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  |  |  608|   611k|    out ^= KSLOOKUP(6, 0);
  |  |  ------------------
  |  |  |  |  596|   611k|#define KSLOOKUP(s, b) *(HALF *)((BYTE *)&SP[s][0] + ((temp >> b) & 0xFC))
  |  |  ------------------
  ------------------
  627|       |
  628|       |    /* now shift circularly right 3 bits to undo the shifting done
  629|       |    ** above.  switch left and right here.
  630|       |    */
  631|   611k|    temp = (left >> 3) | (left << 29);
  632|   611k|    left = (right >> 3) | (right << 29);
  633|   611k|    right = temp;
  634|       |
  635|   611k|    FP(left, right, temp);
  ------------------
  |  |  547|   611k|    right ^= temp = ((left >> 1) ^ right) & 0x55555555;  \
  |  |  548|   611k|    left ^= temp << 1;                                   \
  |  |  549|   611k|    right ^= temp = ((left << 8) ^ right) & 0xff00ff00;  \
  |  |  550|   611k|    left ^= temp >> 8;                                   \
  |  |  551|   611k|    right ^= temp = ((left << 2) ^ right) & 0xcccccccc;  \
  |  |  552|   611k|    left ^= temp >> 2;                                   \
  |  |  553|   611k|    right ^= temp = ((left >> 16) ^ right) & 0x0000ffff; \
  |  |  554|   611k|    left ^= temp << 16;                                  \
  |  |  555|   611k|    right ^= temp = ((left >> 4) ^ right) & 0x0f0f0f0f;  \
  |  |  556|   611k|    left ^= temp << 4;
  ------------------
  636|       |
  637|   611k|#if defined(HAVE_UNALIGNED_ACCESS)
  638|   611k|#if defined(IS_LITTLE_ENDIAN)
  639|   611k|    BYTESWAP(left, temp);
  ------------------
  |  |  358|   611k|    __asm("bswap  %0"        \
  |  |  359|   611k|          : "+r"(word));
  ------------------
  640|   611k|    BYTESWAP(right, temp);
  ------------------
  |  |  358|   611k|    __asm("bswap  %0"        \
  |  |  359|   611k|          : "+r"(word));
  ------------------
  641|   611k|#endif
  642|   611k|    HALFPTR(outbuf)
  ------------------
  |  |   18|   611k|#define HALFPTR(x) ((HALF *)(x))
  ------------------
  643|   611k|    [0] = left;
  644|   611k|    HALFPTR(outbuf)
  ------------------
  |  |   18|   611k|#define HALFPTR(x) ((HALF *)(x))
  ------------------
  645|   611k|    [1] = right;
  646|       |#else
  647|       |    if (((ptrdiff_t)outbuf & 0x03) == 0) {
  648|       |#if defined(IS_LITTLE_ENDIAN)
  649|       |        BYTESWAP(left, temp);
  650|       |        BYTESWAP(right, temp);
  651|       |#endif
  652|       |        HALFPTR(outbuf)
  653|       |        [0] = left;
  654|       |        HALFPTR(outbuf)
  655|       |        [1] = right;
  656|       |    } else {
  657|       |        outbuf[0] = (BYTE)(left >> 24);
  658|       |        outbuf[1] = (BYTE)(left >> 16);
  659|       |        outbuf[2] = (BYTE)(left >> 8);
  660|       |        outbuf[3] = (BYTE)(left);
  661|       |
  662|       |        outbuf[4] = (BYTE)(right >> 24);
  663|       |        outbuf[5] = (BYTE)(right >> 16);
  664|       |        outbuf[6] = (BYTE)(right >> 8);
  665|       |        outbuf[7] = (BYTE)(right);
  666|       |    }
  667|       |#endif
  668|   611k|}

DES_InitContext:
  146|  58.9k|{
  147|  58.9k|    DESDirection opposite;
  148|  58.9k|    if (!cx) {
  ------------------
  |  Branch (148:9): [True: 0, False: 58.9k]
  ------------------
  149|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  150|      0|        return SECFailure;
  151|      0|    }
  152|  58.9k|    cx->direction = encrypt ? DES_ENCRYPT : DES_DECRYPT;
  ------------------
  |  Branch (152:21): [True: 46.4k, False: 12.4k]
  ------------------
  153|  58.9k|    opposite = encrypt ? DES_DECRYPT : DES_ENCRYPT;
  ------------------
  |  Branch (153:16): [True: 46.4k, False: 12.4k]
  ------------------
  154|  58.9k|    switch (mode) {
  155|      0|        case NSS_DES: /* DES ECB */
  ------------------
  |  |   25|      0|#define NSS_DES 0
  ------------------
  |  Branch (155:9): [True: 0, False: 58.9k]
  ------------------
  156|      0|            DES_MakeSchedule(cx->ks0, key, cx->direction);
  157|      0|            cx->worker = &DES_ECB;
  158|      0|            break;
  159|       |
  160|  33.9k|        case NSS_DES_EDE3: /* DES EDE ECB */
  ------------------
  |  |   27|  33.9k|#define NSS_DES_EDE3 2
  ------------------
  |  Branch (160:9): [True: 33.9k, False: 24.9k]
  ------------------
  161|  33.9k|            cx->worker = &DES_EDE3_ECB;
  162|  33.9k|            if (encrypt) {
  ------------------
  |  Branch (162:17): [True: 33.9k, False: 0]
  ------------------
  163|  33.9k|                DES_MakeSchedule(cx->ks0, key, cx->direction);
  164|  33.9k|                DES_MakeSchedule(cx->ks1, key + 8, opposite);
  165|  33.9k|                DES_MakeSchedule(cx->ks2, key + 16, cx->direction);
  166|  33.9k|            } else {
  167|      0|                DES_MakeSchedule(cx->ks2, key, cx->direction);
  168|      0|                DES_MakeSchedule(cx->ks1, key + 8, opposite);
  169|      0|                DES_MakeSchedule(cx->ks0, key + 16, cx->direction);
  170|      0|            }
  171|  33.9k|            break;
  172|       |
  173|  14.8k|        case NSS_DES_CBC: /* DES CBC */
  ------------------
  |  |   26|  14.8k|#define NSS_DES_CBC 1
  ------------------
  |  Branch (173:9): [True: 14.8k, False: 44.0k]
  ------------------
  174|  14.8k|            COPY8BTOHALF(cx->iv, iv);
  ------------------
  |  |   31|  14.8k|#define COPY8BTOHALF(to, from) COPY8B(to, from, from)
  |  |  ------------------
  |  |  |  |   24|  14.8k|    HALFPTR(to)               \
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  14.8k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  |  |   25|  14.8k|    [0] = HALFPTR(from)[0];   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  14.8k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  |  |   26|  14.8k|    HALFPTR(to)               \
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  14.8k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  |  |   27|  14.8k|    [1] = HALFPTR(from)[1];
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  14.8k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  175|  14.8k|            cx->worker = encrypt ? &DES_CBCEn : &DES_CBCDe;
  ------------------
  |  Branch (175:26): [True: 7.40k, False: 7.40k]
  ------------------
  176|  14.8k|            DES_MakeSchedule(cx->ks0, key, cx->direction);
  177|  14.8k|            break;
  178|       |
  179|  10.1k|        case NSS_DES_EDE3_CBC: /* DES EDE CBC */
  ------------------
  |  |   28|  10.1k|#define NSS_DES_EDE3_CBC 3
  ------------------
  |  Branch (179:9): [True: 10.1k, False: 48.7k]
  ------------------
  180|  10.1k|            COPY8BTOHALF(cx->iv, iv);
  ------------------
  |  |   31|  10.1k|#define COPY8BTOHALF(to, from) COPY8B(to, from, from)
  |  |  ------------------
  |  |  |  |   24|  10.1k|    HALFPTR(to)               \
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  10.1k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  |  |   25|  10.1k|    [0] = HALFPTR(from)[0];   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  10.1k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  |  |   26|  10.1k|    HALFPTR(to)               \
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  10.1k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  |  |   27|  10.1k|    [1] = HALFPTR(from)[1];
  |  |  |  |  ------------------
  |  |  |  |  |  |   18|  10.1k|#define HALFPTR(x) ((HALF *)(x))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  181|  10.1k|            if (encrypt) {
  ------------------
  |  Branch (181:17): [True: 5.05k, False: 5.05k]
  ------------------
  182|  5.05k|                cx->worker = &DES_EDE3CBCEn;
  183|  5.05k|                DES_MakeSchedule(cx->ks0, key, cx->direction);
  184|  5.05k|                DES_MakeSchedule(cx->ks1, key + 8, opposite);
  185|  5.05k|                DES_MakeSchedule(cx->ks2, key + 16, cx->direction);
  186|  5.05k|            } else {
  187|  5.05k|                cx->worker = &DES_EDE3CBCDe;
  188|  5.05k|                DES_MakeSchedule(cx->ks2, key, cx->direction);
  189|  5.05k|                DES_MakeSchedule(cx->ks1, key + 8, opposite);
  190|  5.05k|                DES_MakeSchedule(cx->ks0, key + 16, cx->direction);
  191|  5.05k|            }
  192|  10.1k|            break;
  193|       |
  194|      0|        default:
  ------------------
  |  Branch (194:9): [True: 0, False: 58.9k]
  ------------------
  195|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  196|      0|            return SECFailure;
  197|  58.9k|    }
  198|  58.9k|    return SECSuccess;
  199|  58.9k|}
DES_CreateContext:
  203|  58.9k|{
  204|  58.9k|    DESContext *cx = PORT_ZNew(DESContext);
  ------------------
  |  |  148|  58.9k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  58.9k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  205|  58.9k|    SECStatus rv = DES_InitContext(cx, key, 0, iv, mode, encrypt, 0);
  206|       |
  207|  58.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (207:9): [True: 0, False: 58.9k]
  ------------------
  208|      0|        PORT_ZFree(cx, sizeof *cx);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  209|      0|        cx = NULL;
  210|      0|    }
  211|  58.9k|    return cx;
  212|  58.9k|}
DES_DestroyContext:
  216|  58.9k|{
  217|  58.9k|    if (cx) {
  ------------------
  |  Branch (217:9): [True: 58.9k, False: 0]
  ------------------
  218|  58.9k|        memset(cx, 0, sizeof *cx);
  219|  58.9k|        if (freeit)
  ------------------
  |  Branch (219:13): [True: 58.9k, False: 0]
  ------------------
  220|  58.9k|            PORT_Free(cx);
  ------------------
  |  |   60|  58.9k|#define PORT_Free PORT_Free_Util
  ------------------
  221|  58.9k|    }
  222|  58.9k|}
DES_Encrypt:
  227|  33.9k|{
  228|       |
  229|  33.9k|    if ((inLen % 8) != 0 || maxOutLen < inLen || !cx ||
  ------------------
  |  Branch (229:9): [True: 0, False: 33.9k]
  |  Branch (229:29): [True: 0, False: 33.9k]
  |  Branch (229:50): [True: 0, False: 33.9k]
  ------------------
  230|  33.9k|        cx->direction != DES_ENCRYPT) {
  ------------------
  |  Branch (230:9): [True: 0, False: 33.9k]
  ------------------
  231|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  232|      0|        return SECFailure;
  233|      0|    }
  234|       |
  235|  33.9k|    cx->worker(cx, out, in, inLen);
  236|  33.9k|    if (outLen)
  ------------------
  |  Branch (236:9): [True: 33.9k, False: 0]
  ------------------
  237|  33.9k|        *outLen = inLen;
  238|  33.9k|    return SECSuccess;
  239|  33.9k|}
desblapi.c:DES_EDE3_ECB:
   47|  33.9k|{
   48|   237k|    while (len) {
  ------------------
  |  Branch (48:12): [True: 203k, False: 33.9k]
  ------------------
   49|   203k|        DES_Do1Block(cx->ks0, in, out);
   50|   203k|        len -= 8;
   51|   203k|        in += 8;
   52|   203k|        DES_Do1Block(cx->ks1, out, out);
   53|   203k|        DES_Do1Block(cx->ks2, out, out);
   54|   203k|        out += 8;
   55|   203k|    }
   56|  33.9k|}

RNG_RNGInit:
   39|      1|{
   40|       |    /* Allow only one call to initialize the context */
   41|      1|    if (PR_CallOnce(&coRNGInit, rng_init) != PR_SUCCESS) {
  ------------------
  |  Branch (41:9): [True: 0, False: 1]
  ------------------
   42|      0|        return SECFailure;
   43|      0|    }
   44|       |
   45|      1|    return SECSuccess;
   46|      1|}
RNG_RandomUpdate:
   52|  9.71k|{
   53|       |    /* Check for a valid RNG lock. */
   54|  9.71k|    PORT_Assert(rng_lock != NULL);
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   55|  9.71k|    if (rng_lock == NULL) {
  ------------------
  |  Branch (55:9): [True: 0, False: 9.71k]
  ------------------
   56|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   57|      0|        return SECFailure;
   58|      0|    }
   59|       |
   60|       |    /* --- LOCKED --- */
   61|  9.71k|    PZ_Lock(rng_lock);
  ------------------
  |  |  245|  9.71k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
   62|  9.71k|    memset(globalBytes, 0, GLOBAL_BYTES_SIZE);
  ------------------
  |  |   13|  9.71k|#define GLOBAL_BYTES_SIZE 100
  ------------------
   63|  9.71k|    globalNumCalls = 0;
   64|  9.71k|    if (data) {
  ------------------
  |  Branch (64:9): [True: 0, False: 9.71k]
  ------------------
   65|      0|        memcpy(globalBytes, (PRUint8 *)data, PR_MIN(bytes, GLOBAL_BYTES_SIZE));
  ------------------
  |  |  158|      0|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
   66|      0|    }
   67|  9.71k|    PZ_Unlock(rng_lock);
  ------------------
  |  |  246|  9.71k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
   68|       |    /* --- UNLOCKED --- */
   69|       |
   70|  9.71k|    return SECSuccess;
   71|  9.71k|}
RNG_GenerateGlobalRandomBytes:
   75|   274k|{
   76|   274k|    static const uint8_t key[32] = { 0 };
   77|   274k|    uint8_t nonce[12] = { 0 };
   78|       |
   79|       |    /* Check for a valid RNG lock. */
   80|   274k|    PORT_Assert(rng_lock != NULL);
  ------------------
  |  |  120|   274k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   274k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 274k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   81|   274k|    if (rng_lock == NULL) {
  ------------------
  |  Branch (81:9): [True: 0, False: 274k]
  ------------------
   82|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   83|      0|        return SECFailure;
   84|      0|    }
   85|       |
   86|       |    /* --- LOCKED --- */
   87|   274k|    PZ_Lock(rng_lock);
  ------------------
  |  |  245|   274k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
   88|       |
   89|   274k|    memcpy(nonce, &globalNumCalls, sizeof(globalNumCalls));
   90|   274k|    globalNumCalls++;
   91|       |
   92|   274k|    ChaCha20Poly1305Context *cx =
   93|   274k|        ChaCha20Poly1305_CreateContext(key, sizeof(key), 16);
   94|   274k|    if (!cx) {
  ------------------
  |  Branch (94:9): [True: 0, False: 274k]
  ------------------
   95|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   96|      0|        PZ_Unlock(rng_lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
   97|      0|        return SECFailure;
   98|      0|    }
   99|       |
  100|   274k|    memset(dest, 0, len);
  101|   274k|    memcpy(dest, globalBytes, PR_MIN(len, GLOBAL_BYTES_SIZE));
  ------------------
  |  |  158|   274k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 274k, False: 4]
  |  |  ------------------
  ------------------
  102|   274k|    Hacl_Chacha20_chacha20_encrypt(len, (uint8_t *)dest, (uint8_t *)dest,
  103|   274k|                                   (uint8_t *)key, nonce, 0);
  104|   274k|    ChaCha20Poly1305_DestroyContext(cx, PR_TRUE);
  ------------------
  |  |  437|   274k|#define PR_TRUE 1
  ------------------
  105|       |
  106|   274k|    PZ_Unlock(rng_lock);
  ------------------
  |  |  246|   274k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  107|       |    /* --- UNLOCKED --- */
  108|       |
  109|   274k|    return SECSuccess;
  110|   274k|}
RNG_RNGShutdown:
  114|      1|{
  115|      1|    if (rng_lock) {
  ------------------
  |  Branch (115:9): [True: 1, False: 0]
  ------------------
  116|      1|        PZ_DestroyLock(rng_lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  117|      1|        rng_lock = NULL;
  118|      1|    }
  119|      1|    coRNGInit = pristineCallOnce;
  120|      1|}
det_rng.c:rng_init:
   22|      1|{
   23|      1|    rng_lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   24|      1|    if (!rng_lock) {
  ------------------
  |  Branch (24:9): [True: 0, False: 1]
  ------------------
   25|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   26|      0|        return PR_FAILURE;
   27|      0|    }
   28|       |    /* --- LOCKED --- */
   29|      1|    PZ_Lock(rng_lock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
   30|      1|    memset(globalBytes, 0, GLOBAL_BYTES_SIZE);
  ------------------
  |  |   13|      1|#define GLOBAL_BYTES_SIZE 100
  ------------------
   31|      1|    PZ_Unlock(rng_lock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
   32|       |    /* --- UNLOCKED --- */
   33|       |
   34|      1|    return PR_SUCCESS;
   35|      1|}

DH_NewKey:
  137|  29.0k|{
  138|  29.0k|    PLArenaPool *arena;
  139|  29.0k|    DHPrivateKey *key;
  140|  29.0k|    mp_int g, xa, p, Ya;
  141|  29.0k|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  142|  29.0k|    SECStatus rv = SECSuccess;
  143|  29.0k|    if (!params || !privKey) {
  ------------------
  |  Branch (143:9): [True: 0, False: 29.0k]
  |  Branch (143:20): [True: 0, False: 29.0k]
  ------------------
  144|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  145|      0|        return SECFailure;
  146|      0|    }
  147|  29.0k|    arena = PORT_NewArena(NSS_FREEBL_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  29.0k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(NSS_FREEBL_DEFAULT_CHUNKSIZE);
  ------------------
  |  |  143|  29.0k|#define NSS_FREEBL_DEFAULT_CHUNKSIZE 2048
  ------------------
  148|  29.0k|    if (!arena) {
  ------------------
  |  Branch (148:9): [True: 0, False: 29.0k]
  ------------------
  149|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  150|      0|        return SECFailure;
  151|      0|    }
  152|  29.0k|    key = (DHPrivateKey *)PORT_ArenaZAlloc(arena, sizeof(DHPrivateKey));
  ------------------
  |  |   59|  29.0k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  153|  29.0k|    if (!key) {
  ------------------
  |  Branch (153:9): [True: 0, False: 29.0k]
  ------------------
  154|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  155|      0|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  156|      0|        return SECFailure;
  157|      0|    }
  158|  29.0k|    key->arena = arena;
  159|  29.0k|    MP_DIGITS(&g) = 0;
  ------------------
  |  |  152|  29.0k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  160|  29.0k|    MP_DIGITS(&xa) = 0;
  ------------------
  |  |  152|  29.0k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  161|  29.0k|    MP_DIGITS(&p) = 0;
  ------------------
  |  |  152|  29.0k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  162|  29.0k|    MP_DIGITS(&Ya) = 0;
  ------------------
  |  |  152|  29.0k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  163|  29.0k|    CHECK_MPI_OK(mp_init(&g));
  ------------------
  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   13|  29.0k|    goto cleanup
  ------------------
  164|  29.0k|    CHECK_MPI_OK(mp_init(&xa));
  ------------------
  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   13|  29.0k|    goto cleanup
  ------------------
  165|  29.0k|    CHECK_MPI_OK(mp_init(&p));
  ------------------
  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   13|  29.0k|    goto cleanup
  ------------------
  166|  29.0k|    CHECK_MPI_OK(mp_init(&Ya));
  ------------------
  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   13|  29.0k|    goto cleanup
  ------------------
  167|       |    /* Set private key's p */
  168|  29.0k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->prime, &params->prime));
  ------------------
  |  |    8|  29.0k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |    9|  29.0k|    goto cleanup
  ------------------
  169|  29.0k|    SECITEM_TO_MPINT(key->prime, &p);
  ------------------
  |  |   19|  29.0k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  |  |  ------------------
  |  |  |  |   13|  29.0k|    goto cleanup
  |  |  ------------------
  ------------------
  170|       |    /* Set private key's g */
  171|  29.0k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->base, &params->base));
  ------------------
  |  |    8|  29.0k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |    9|  29.0k|    goto cleanup
  ------------------
  172|  29.0k|    SECITEM_TO_MPINT(key->base, &g);
  ------------------
  |  |   19|  29.0k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  |  |  ------------------
  |  |  |  |   13|  29.0k|    goto cleanup
  |  |  ------------------
  ------------------
  173|       |    /* Generate private key xa */
  174|  29.0k|    SECITEM_AllocItem(arena, &key->privateValue,
  ------------------
  |  |  103|  29.0k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  175|  29.0k|                      dh_GetSecretKeyLen(params->prime.len));
  176|  29.0k|    CHECK_SEC_OK(RNG_GenerateGlobalRandomBytes(key->privateValue.data,
  ------------------
  |  |    8|  29.0k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |    9|  29.0k|    goto cleanup
  ------------------
  177|  29.0k|                                               key->privateValue.len));
  178|  29.0k|    SECITEM_TO_MPINT(key->privateValue, &xa);
  ------------------
  |  |   19|  29.0k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  |  |  ------------------
  |  |  |  |   13|  29.0k|    goto cleanup
  |  |  ------------------
  ------------------
  179|       |    /* xa < p */
  180|  29.0k|    CHECK_MPI_OK(mp_mod(&xa, &p, &xa));
  ------------------
  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   13|  29.0k|    goto cleanup
  ------------------
  181|       |    /* Compute public key Ya = g ** xa mod p */
  182|  29.0k|    CHECK_MPI_OK(mp_exptmod(&g, &xa, &p, &Ya));
  ------------------
  |  |   12|  29.0k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   13|  29.0k|    goto cleanup
  ------------------
  183|  29.0k|    MPINT_TO_SECITEM(&Ya, &key->publicValue, key->arena);
  ------------------
  |  |   22|  29.0k|    do {                                                        \
  |  |   23|  29.0k|        int mpintLen = mp_unsigned_octet_size(mp);              \
  |  |   24|  29.0k|        if (mpintLen <= 0) {                                    \
  |  |  ------------------
  |  |  |  Branch (24:13): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   25|      0|            err = MP_RANGE;                                     \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |   26|      0|            goto cleanup;                                       \
  |  |   27|      0|        }                                                       \
  |  |   28|  29.0k|        SECITEM_AllocItem(arena, (it), mpintLen);               \
  |  |  ------------------
  |  |  |  |  103|  29.0k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  |  |  ------------------
  |  |   29|  29.0k|        if ((it)->data == NULL) {                               \
  |  |  ------------------
  |  |  |  Branch (29:13): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   30|      0|            err = MP_MEM;                                       \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |   31|      0|            goto cleanup;                                       \
  |  |   32|      0|        }                                                       \
  |  |   33|  29.0k|        err = mp_to_unsigned_octets(mp, (it)->data, (it)->len); \
  |  |   34|  29.0k|        if (err < 0)                                            \
  |  |  ------------------
  |  |  |  Branch (34:13): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   35|  29.0k|            goto cleanup;                                       \
  |  |   36|  29.0k|        else                                                    \
  |  |   37|  29.0k|            err = MP_OKAY;                                      \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |   38|  29.0k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (38:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  184|  29.0k|    *privKey = key;
  185|  29.0k|cleanup:
  186|  29.0k|    mp_clear(&g);
  187|  29.0k|    mp_clear(&xa);
  188|  29.0k|    mp_clear(&p);
  189|  29.0k|    mp_clear(&Ya);
  190|  29.0k|    if (err) {
  ------------------
  |  Branch (190:9): [True: 0, False: 29.0k]
  ------------------
  191|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
  192|      0|        rv = SECFailure;
  193|      0|    }
  194|  29.0k|    if (rv) {
  ------------------
  |  Branch (194:9): [True: 0, False: 29.0k]
  ------------------
  195|      0|        *privKey = NULL;
  196|      0|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  197|      0|    }
  198|  29.0k|    return rv;
  199|  29.0k|}
DH_Derive:
  207|  56.8k|{
  208|  56.8k|    mp_int p, Xa, Yb, ZZ, psub1;
  209|  56.8k|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  210|  56.8k|    unsigned int len = 0;
  211|  56.8k|    unsigned int nb;
  212|  56.8k|    unsigned char *secret = NULL;
  213|  56.8k|    if (!publicValue || !publicValue->len || !prime || !prime->len ||
  ------------------
  |  Branch (213:9): [True: 0, False: 56.8k]
  |  Branch (213:25): [True: 0, False: 56.8k]
  |  Branch (213:46): [True: 0, False: 56.8k]
  |  Branch (213:56): [True: 0, False: 56.8k]
  ------------------
  214|  56.8k|        !privateValue || !privateValue->len || !derivedSecret) {
  ------------------
  |  Branch (214:9): [True: 0, False: 56.8k]
  |  Branch (214:26): [True: 0, False: 56.8k]
  |  Branch (214:48): [True: 0, False: 56.8k]
  ------------------
  215|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  216|      0|        return SECFailure;
  217|      0|    }
  218|  56.8k|    memset(derivedSecret, 0, sizeof *derivedSecret);
  219|  56.8k|    MP_DIGITS(&p) = 0;
  ------------------
  |  |  152|  56.8k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  220|  56.8k|    MP_DIGITS(&Xa) = 0;
  ------------------
  |  |  152|  56.8k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  221|  56.8k|    MP_DIGITS(&Yb) = 0;
  ------------------
  |  |  152|  56.8k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  222|  56.8k|    MP_DIGITS(&ZZ) = 0;
  ------------------
  |  |  152|  56.8k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  223|  56.8k|    MP_DIGITS(&psub1) = 0;
  ------------------
  |  |  152|  56.8k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  224|  56.8k|    CHECK_MPI_OK(mp_init(&p));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  225|  56.8k|    CHECK_MPI_OK(mp_init(&Xa));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  226|  56.8k|    CHECK_MPI_OK(mp_init(&Yb));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  227|  56.8k|    CHECK_MPI_OK(mp_init(&ZZ));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  228|  56.8k|    CHECK_MPI_OK(mp_init(&psub1));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  229|  56.8k|    SECITEM_TO_MPINT(*publicValue, &Yb);
  ------------------
  |  |   19|  56.8k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  |  |  ------------------
  |  |  |  |   13|  56.8k|    goto cleanup
  |  |  ------------------
  ------------------
  230|  56.8k|    SECITEM_TO_MPINT(*privateValue, &Xa);
  ------------------
  |  |   19|  56.8k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  |  |  ------------------
  |  |  |  |   13|  56.8k|    goto cleanup
  |  |  ------------------
  ------------------
  231|  56.8k|    SECITEM_TO_MPINT(*prime, &p);
  ------------------
  |  |   19|  56.8k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  |  |  ------------------
  |  |  |  |   13|  56.8k|    goto cleanup
  |  |  ------------------
  ------------------
  232|  56.8k|    CHECK_MPI_OK(mp_sub_d(&p, 1, &psub1));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  233|       |
  234|       |    /* We assume that the modulus, p, is a safe prime. That is, p = 2q+1 where
  235|       |     * q is also a prime. Thus the orders of the subgroups are factors of 2q:
  236|       |     * namely 1, 2, q and 2q.
  237|       |     *
  238|       |     * We check that the peer's public value isn't zero (which isn't in the
  239|       |     * group), one (subgroup of order one) or p-1 (subgroup of order 2). We
  240|       |     * also check that the public value is less than p, to avoid being fooled
  241|       |     * by values like p+1 or 2*p-1.
  242|       |     *
  243|       |     * Thus we must be operating in the subgroup of size q or 2q. */
  244|  56.8k|    if (mp_cmp_d(&Yb, 1) <= 0 ||
  ------------------
  |  Branch (244:9): [True: 0, False: 56.8k]
  ------------------
  245|  56.8k|        mp_cmp(&Yb, &psub1) >= 0) {
  ------------------
  |  Branch (245:9): [True: 0, False: 56.8k]
  ------------------
  246|      0|        err = MP_BADARG;
  ------------------
  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  ------------------
  247|      0|        goto cleanup;
  248|      0|    }
  249|       |
  250|       |    /* ZZ = (Yb)**Xa mod p */
  251|  56.8k|    CHECK_MPI_OK(mp_exptmod(&Yb, &Xa, &p, &ZZ));
  ------------------
  |  |   12|  56.8k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 56.8k]
  |  |  ------------------
  |  |   13|  56.8k|    goto cleanup
  ------------------
  252|       |    /* number of bytes in the derived secret */
  253|  56.8k|    len = mp_unsigned_octet_size(&ZZ);
  254|  56.8k|    if (len <= 0) {
  ------------------
  |  Branch (254:9): [True: 0, False: 56.8k]
  ------------------
  255|      0|        err = MP_BADARG;
  ------------------
  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  ------------------
  256|      0|        goto cleanup;
  257|      0|    }
  258|       |
  259|       |    /*
  260|       |     * We check to make sure that ZZ is not equal to 0, 1 or -1 mod p.
  261|       |     * This helps guard against small subgroup attacks, since an attacker
  262|       |     * using a subgroup of size N will produce 0, 1 or -1 with probability 1/N.
  263|       |     * When the protocol is executed within a properly large subgroup, the
  264|       |     * probability of this result will be negligibly small.  For example,
  265|       |     * with a safe prime of the form 2q+1, the probability will be 1/q.
  266|       |     *
  267|       |     * We return MP_BADARG because this is probably the result of a bad
  268|       |     * public value or a bad prime having been provided.
  269|       |     */
  270|  56.8k|    if (mp_cmp_d(&ZZ, 0) == 0 || mp_cmp_d(&ZZ, 1) == 0 ||
  ------------------
  |  Branch (270:9): [True: 0, False: 56.8k]
  |  Branch (270:34): [True: 0, False: 56.8k]
  ------------------
  271|  56.8k|        mp_cmp(&ZZ, &psub1) == 0) {
  ------------------
  |  Branch (271:9): [True: 0, False: 56.8k]
  ------------------
  272|      0|        err = MP_BADARG;
  ------------------
  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  ------------------
  273|      0|        goto cleanup;
  274|      0|    }
  275|       |
  276|       |    /* allocate a buffer which can hold the entire derived secret. */
  277|  56.8k|    secret = PORT_Alloc(len);
  ------------------
  |  |   52|  56.8k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  278|  56.8k|    if (secret == NULL) {
  ------------------
  |  Branch (278:9): [True: 0, False: 56.8k]
  ------------------
  279|      0|        err = MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
  280|      0|        goto cleanup;
  281|      0|    }
  282|       |    /* grab the derived secret */
  283|  56.8k|    err = mp_to_unsigned_octets(&ZZ, secret, len);
  284|  56.8k|    if (err >= 0)
  ------------------
  |  Branch (284:9): [True: 56.8k, False: 0]
  ------------------
  285|  56.8k|        err = MP_OKAY;
  ------------------
  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  286|       |    /*
  287|       |    ** if outBytes is 0 take all of the bytes from the derived secret.
  288|       |    ** if outBytes is not 0 take exactly outBytes from the derived secret, zero
  289|       |    ** pad at the beginning if necessary, and truncate beginning bytes
  290|       |    ** if necessary.
  291|       |    */
  292|  56.8k|    if (outBytes > 0)
  ------------------
  |  Branch (292:9): [True: 545, False: 56.2k]
  ------------------
  293|    545|        nb = outBytes;
  294|  56.2k|    else
  295|  56.2k|        nb = len;
  296|  56.8k|    if (SECITEM_AllocItem(NULL, derivedSecret, nb) == NULL) {
  ------------------
  |  |  103|  56.8k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (296:9): [True: 0, False: 56.8k]
  ------------------
  297|      0|        err = MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
  298|      0|        goto cleanup;
  299|      0|    }
  300|  56.8k|    if (len < nb) {
  ------------------
  |  Branch (300:9): [True: 2, False: 56.8k]
  ------------------
  301|      2|        unsigned int offset = nb - len;
  302|      2|        memset(derivedSecret->data, 0, offset);
  303|      2|        memcpy(derivedSecret->data + offset, secret, len);
  304|  56.8k|    } else {
  305|  56.8k|        memcpy(derivedSecret->data, secret + len - nb, nb);
  306|  56.8k|    }
  307|  56.8k|cleanup:
  308|  56.8k|    mp_clear(&p);
  309|  56.8k|    mp_clear(&Xa);
  310|  56.8k|    mp_clear(&Yb);
  311|  56.8k|    mp_clear(&ZZ);
  312|  56.8k|    mp_clear(&psub1);
  313|  56.8k|    if (secret) {
  ------------------
  |  Branch (313:9): [True: 56.8k, False: 0]
  ------------------
  314|       |        /* free the buffer allocated for the full secret. */
  315|  56.8k|        PORT_ZFree(secret, len);
  ------------------
  |  |   75|  56.8k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  316|  56.8k|    }
  317|  56.8k|    if (err) {
  ------------------
  |  Branch (317:9): [True: 0, False: 56.8k]
  ------------------
  318|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
  319|      0|        if (derivedSecret->data)
  ------------------
  |  Branch (319:13): [True: 0, False: 0]
  ------------------
  320|      0|            PORT_ZFree(derivedSecret->data, derivedSecret->len);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  321|      0|        return SECFailure;
  322|      0|    }
  323|  56.8k|    return SECSuccess;
  324|  56.8k|}
dh.c:dh_GetSecretKeyLen:
   27|  29.0k|{
   28|       |    /* Based on Table 2 in NIST SP 800-57. */
   29|  29.0k|    if (primeLen >= 1920) { /* 15360 bits */
  ------------------
  |  Branch (29:9): [True: 0, False: 29.0k]
  ------------------
   30|      0|        return 64;          /* 512 bits */
   31|      0|    }
   32|  29.0k|    if (primeLen >= 960) { /* 7680 bits */
  ------------------
  |  Branch (32:9): [True: 1.33k, False: 27.7k]
  ------------------
   33|  1.33k|        return 48;         /* 384 bits */
   34|  1.33k|    }
   35|  27.7k|    if (primeLen >= 384) { /* 3072 bits */
  ------------------
  |  Branch (35:9): [True: 5.97k, False: 21.7k]
  ------------------
   36|  5.97k|        return 32;         /* 256 bits */
   37|  5.97k|    }
   38|  21.7k|    if (primeLen >= 256) { /* 2048 bits */
  ------------------
  |  Branch (38:9): [True: 21.7k, False: 0]
  ------------------
   39|  21.7k|        return 28;         /* 224 bits */
   40|  21.7k|    }
   41|      0|    return 20; /* 160 bits */
   42|  21.7k|}

ec_NewKey:
  104|  18.2k|{
  105|  18.2k|    SECStatus rv = SECFailure;
  106|  18.2k|    PLArenaPool *arena;
  107|  18.2k|    ECPrivateKey *key;
  108|  18.2k|    int len;
  109|       |
  110|  18.2k|    if (!ecParams || ecParams->name == ECCurve_noName ||
  ------------------
  |  Branch (110:9): [True: 0, False: 18.2k]
  |  Branch (110:22): [True: 0, False: 18.2k]
  ------------------
  111|  18.2k|        !privKey || !privKeyBytes || privKeyLen <= 0) {
  ------------------
  |  Branch (111:9): [True: 0, False: 18.2k]
  |  Branch (111:21): [True: 0, False: 18.2k]
  |  Branch (111:38): [True: 0, False: 18.2k]
  ------------------
  112|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  113|      0|        return SECFailure;
  114|      0|    }
  115|       |
  116|  18.2k|    if (ecParams->fieldID.type != ec_field_plain) {
  ------------------
  |  Branch (116:9): [True: 0, False: 18.2k]
  ------------------
  117|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  118|      0|        return SECFailure;
  119|      0|    }
  120|       |
  121|       |    /* Initialize an arena for the EC key. */
  122|  18.2k|    if (!(arena = PORT_NewArena(NSS_FREEBL_DEFAULT_CHUNKSIZE)))
  ------------------
  |  |   63|  18.2k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  if (!(arena = PORT_NewArena(NSS_FREEBL_DEFAULT_CHUNKSIZE)))
  ------------------
  |  |  143|  18.2k|#define NSS_FREEBL_DEFAULT_CHUNKSIZE 2048
  ------------------
  |  Branch (122:9): [True: 0, False: 18.2k]
  ------------------
  123|      0|        return SECFailure;
  124|       |
  125|  18.2k|    key = (ECPrivateKey *)PORT_ArenaZAlloc(arena, sizeof(ECPrivateKey));
  ------------------
  |  |   59|  18.2k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  126|  18.2k|    if (!key) {
  ------------------
  |  Branch (126:9): [True: 0, False: 18.2k]
  ------------------
  127|      0|        goto cleanup;
  128|      0|    }
  129|       |
  130|       |    /* Set the version number (SEC 1 section C.4 says it should be 1) */
  131|  18.2k|    SECITEM_AllocItem(arena, &key->version, 1);
  ------------------
  |  |  103|  18.2k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  132|  18.2k|    key->version.data[0] = 1;
  133|       |
  134|       |    /* Copy all of the fields from the ECParams argument to the
  135|       |     * ECParams structure within the private key.
  136|       |     */
  137|  18.2k|    key->ecParams.arena = arena;
  138|  18.2k|    key->ecParams.type = ecParams->type;
  139|  18.2k|    key->ecParams.fieldID.size = ecParams->fieldID.size;
  140|  18.2k|    key->ecParams.fieldID.type = ecParams->fieldID.type;
  141|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.fieldID.u.prime,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  142|  18.2k|                                  &ecParams->fieldID.u.prime));
  143|  18.2k|    key->ecParams.fieldID.k1 = ecParams->fieldID.k1;
  144|  18.2k|    key->ecParams.fieldID.k2 = ecParams->fieldID.k2;
  145|  18.2k|    key->ecParams.fieldID.k3 = ecParams->fieldID.k3;
  146|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.curve.a,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  147|  18.2k|                                  &ecParams->curve.a));
  148|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.curve.b,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  149|  18.2k|                                  &ecParams->curve.b));
  150|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.curve.seed,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  151|  18.2k|                                  &ecParams->curve.seed));
  152|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.base,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  153|  18.2k|                                  &ecParams->base));
  154|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.order,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  155|  18.2k|                                  &ecParams->order));
  156|  18.2k|    key->ecParams.cofactor = ecParams->cofactor;
  157|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.DEREncoding,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  158|  18.2k|                                  &ecParams->DEREncoding));
  159|  18.2k|    key->ecParams.name = ecParams->name;
  160|  18.2k|    CHECK_SEC_OK(SECITEM_CopyItem(arena, &key->ecParams.curveOID,
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  161|  18.2k|                                  &ecParams->curveOID));
  162|       |
  163|  18.2k|    SECITEM_AllocItem(arena, &key->publicValue, EC_GetPointSize(ecParams));
  ------------------
  |  |  103|  18.2k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  164|  18.2k|    len = ecParams->order.len;
  165|  18.2k|    SECITEM_AllocItem(arena, &key->privateValue, len);
  ------------------
  |  |  103|  18.2k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  166|       |
  167|       |    /* Copy private key */
  168|  18.2k|    if (privKeyLen >= len) {
  ------------------
  |  Branch (168:9): [True: 18.2k, False: 0]
  ------------------
  169|  18.2k|        memcpy(key->privateValue.data, privKeyBytes, len);
  170|  18.2k|    } else {
  171|      0|        memset(key->privateValue.data, 0, (len - privKeyLen));
  172|      0|        memcpy(key->privateValue.data + (len - privKeyLen), privKeyBytes, privKeyLen);
  173|      0|    }
  174|       |
  175|       |    /* Compute corresponding public key */
  176|       |
  177|       |    /* Use curve specific code for point multiplication */
  178|  18.2k|    if (ecParams->name == ECCurve_Ed25519) {
  ------------------
  |  Branch (178:9): [True: 0, False: 18.2k]
  ------------------
  179|      0|        CHECK_SEC_OK(ED_DerivePublicKey(&key->privateValue, &key->publicValue));
  ------------------
  |  |    8|      0|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 0]
  |  |  ------------------
  |  |    9|      0|    goto cleanup
  ------------------
  180|  18.2k|    } else {
  181|  18.2k|        const ECMethod *method = ec_get_method_from_name(ecParams->name);
  182|  18.2k|        if (method == NULL || method->pt_mul == NULL) {
  ------------------
  |  Branch (182:13): [True: 0, False: 18.2k]
  |  Branch (182:31): [True: 0, False: 18.2k]
  ------------------
  183|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  184|      0|            rv = SECFailure;
  185|      0|            goto cleanup;
  186|      0|        }
  187|  18.2k|        CHECK_SEC_OK(method->pt_mul(&key->publicValue, &key->privateValue, NULL));
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  188|  18.2k|    }
  189|       |
  190|  18.2k|    NSS_DECLASSIFY(key->publicValue.data, key->publicValue.len); /* Declassifying public key to avoid false positive */
  191|  18.2k|    *privKey = key;
  192|  18.2k|    return SECSuccess;
  193|       |
  194|      0|cleanup:
  195|      0|    PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  196|      0|    return rv;
  197|  18.2k|}
EC_NewKeyFromSeed:
  207|      1|{
  208|      1|    return ec_NewKey(ecParams, privKey, seed, seedlen);
  209|      1|}
ec_GenerateRandomPrivateKey:
  218|  29.9k|{
  219|  29.9k|    SECStatus rv = SECFailure;
  220|       |
  221|  29.9k|    unsigned int len = EC_GetScalarSize(ecParams);
  222|       |
  223|  29.9k|    if (privKey->len != len || privKey->data == NULL) {
  ------------------
  |  Branch (223:9): [True: 0, False: 29.9k]
  |  Branch (223:32): [True: 0, False: 29.9k]
  ------------------
  224|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  225|      0|        return SECFailure;
  226|      0|    }
  227|       |
  228|  29.9k|    const ECMethod *method = ec_get_method_from_name(ecParams->name);
  229|  29.9k|    if (method == NULL || method->scalar_validate == NULL) {
  ------------------
  |  Branch (229:9): [True: 0, False: 29.9k]
  |  Branch (229:27): [True: 0, False: 29.9k]
  ------------------
  230|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  231|      0|        return SECFailure;
  232|      0|    }
  233|       |
  234|  29.9k|    uint8_t leading_coeff_mask;
  235|  29.9k|    switch (ecParams->name) {
  236|      0|        case ECCurve_Ed25519:
  ------------------
  |  Branch (236:9): [True: 0, False: 29.9k]
  ------------------
  237|  7.42k|        case ECCurve25519:
  ------------------
  |  Branch (237:9): [True: 7.42k, False: 22.5k]
  ------------------
  238|  27.8k|        case ECCurve_NIST_P256:
  ------------------
  |  Branch (238:9): [True: 20.4k, False: 9.52k]
  ------------------
  239|  29.9k|        case ECCurve_NIST_P384:
  ------------------
  |  Branch (239:9): [True: 2.04k, False: 27.9k]
  ------------------
  240|  29.9k|            leading_coeff_mask = 0xff;
  241|  29.9k|            break;
  242|     52|        case ECCurve_NIST_P521:
  ------------------
  |  Branch (242:9): [True: 52, False: 29.9k]
  ------------------
  243|     52|            leading_coeff_mask = 0x01;
  244|     52|            break;
  245|      0|        default:
  ------------------
  |  Branch (245:9): [True: 0, False: 29.9k]
  ------------------
  246|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  247|      0|            return SECFailure;
  248|  29.9k|    }
  249|       |
  250|       |    /* The rejection sampling method from FIPS 186-5 A.4.2 */
  251|  29.9k|    int count = 100;
  252|  29.9k|    do {
  253|  29.9k|        rv = RNG_GenerateGlobalRandomBytes(privKey->data, len);
  254|  29.9k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (254:13): [True: 0, False: 29.9k]
  ------------------
  255|      0|            PORT_SetError(SEC_ERROR_NEED_RANDOM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  256|      0|            return SECFailure;
  257|      0|        }
  258|  29.9k|        privKey->data[0] &= leading_coeff_mask;
  259|  29.9k|        NSS_CLASSIFY(privKey->data, privKey->len);
  260|  29.9k|        rv = method->scalar_validate(privKey);
  261|  29.9k|    } while (rv != SECSuccess && --count > 0);
  ------------------
  |  Branch (261:14): [True: 0, False: 29.9k]
  |  Branch (261:34): [True: 0, False: 0]
  ------------------
  262|       |
  263|  29.9k|    if (rv != SECSuccess) { // implies count == 0
  ------------------
  |  Branch (263:9): [True: 0, False: 29.9k]
  ------------------
  264|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  265|      0|    }
  266|       |
  267|  29.9k|    return rv;
  268|  29.9k|}
EC_NewKey:
  276|  18.2k|{
  277|  18.2k|    SECStatus rv = SECFailure;
  278|  18.2k|    SECItem privKeyRand = { siBuffer, NULL, 0 };
  279|       |
  280|  18.2k|    if (!ecParams || ecParams->name == ECCurve_noName || !privKey) {
  ------------------
  |  Branch (280:9): [True: 0, False: 18.2k]
  |  Branch (280:22): [True: 0, False: 18.2k]
  |  Branch (280:58): [True: 0, False: 18.2k]
  ------------------
  281|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  282|      0|        return SECFailure;
  283|      0|    }
  284|       |
  285|  18.2k|    SECITEM_AllocItem(NULL, &privKeyRand, EC_GetScalarSize(ecParams));
  ------------------
  |  |  103|  18.2k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  286|  18.2k|    if (privKeyRand.data == NULL) {
  ------------------
  |  Branch (286:9): [True: 0, False: 18.2k]
  ------------------
  287|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  288|      0|        rv = SECFailure;
  289|      0|        goto cleanup;
  290|      0|    }
  291|  18.2k|    rv = ec_GenerateRandomPrivateKey(ecParams, &privKeyRand);
  292|  18.2k|    if (rv != SECSuccess || privKeyRand.data == NULL) {
  ------------------
  |  Branch (292:9): [True: 0, False: 18.2k]
  |  Branch (292:29): [True: 0, False: 18.2k]
  ------------------
  293|      0|        goto cleanup;
  294|      0|    }
  295|       |    /* generate public key */
  296|  18.2k|    CHECK_SEC_OK(ec_NewKey(ecParams, privKey, privKeyRand.data, privKeyRand.len));
  ------------------
  |  |    8|  18.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |    9|  18.2k|    goto cleanup
  ------------------
  297|       |
  298|  18.2k|cleanup:
  299|  18.2k|    if (privKeyRand.data) {
  ------------------
  |  Branch (299:9): [True: 18.2k, False: 0]
  ------------------
  300|  18.2k|        SECITEM_ZfreeItem(&privKeyRand, PR_FALSE);
  ------------------
  |  |  110|  18.2k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(&privKeyRand, PR_FALSE);
  ------------------
  |  |  438|  18.2k|#define PR_FALSE 0
  ------------------
  301|  18.2k|    }
  302|       |#if EC_DEBUG
  303|       |    printf("EC_NewKey returning %s\n",
  304|       |           (rv == SECSuccess) ? "success" : "failure");
  305|       |#endif
  306|       |
  307|  18.2k|    return rv;
  308|  18.2k|}
EC_ValidatePublicKey:
  318|  35.9k|{
  319|  35.9k|    if (!ecParams || ecParams->name == ECCurve_noName ||
  ------------------
  |  Branch (319:9): [True: 0, False: 35.9k]
  |  Branch (319:22): [True: 0, False: 35.9k]
  ------------------
  320|  35.9k|        !publicValue || !publicValue->len) {
  ------------------
  |  Branch (320:9): [True: 0, False: 35.9k]
  |  Branch (320:25): [True: 0, False: 35.9k]
  ------------------
  321|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  322|      0|        return SECFailure;
  323|      0|    }
  324|       |
  325|       |    /* Uses curve specific code for point validation. */
  326|  35.9k|    if (ecParams->fieldID.type != ec_field_plain) {
  ------------------
  |  Branch (326:9): [True: 0, False: 35.9k]
  ------------------
  327|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  328|      0|        return SECFailure;
  329|      0|    }
  330|       |
  331|  35.9k|    const ECMethod *method = ec_get_method_from_name(ecParams->name);
  332|  35.9k|    if (method == NULL || method->pt_validate == NULL) {
  ------------------
  |  Branch (332:9): [True: 0, False: 35.9k]
  |  Branch (332:27): [True: 0, False: 35.9k]
  ------------------
  333|       |        /* unknown curve */
  334|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  335|      0|        return SECFailure;
  336|      0|    }
  337|       |
  338|  35.9k|    SECStatus rv = method->pt_validate(publicValue);
  339|  35.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (339:9): [True: 374, False: 35.6k]
  ------------------
  340|    374|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|    374|#define PORT_SetError PORT_SetError_Util
  ------------------
  341|    374|    }
  342|  35.9k|    return rv;
  343|  35.9k|}
ECDH_Derive:
  361|  17.7k|{
  362|  17.7k|    if (!publicValue || !publicValue->len ||
  ------------------
  |  Branch (362:9): [True: 0, False: 17.7k]
  |  Branch (362:25): [True: 0, False: 17.7k]
  ------------------
  363|  17.7k|        !ecParams || ecParams->name == ECCurve_noName ||
  ------------------
  |  Branch (363:9): [True: 0, False: 17.7k]
  |  Branch (363:22): [True: 0, False: 17.7k]
  ------------------
  364|  17.7k|        !privateValue || !privateValue->len || !derivedSecret) {
  ------------------
  |  Branch (364:9): [True: 0, False: 17.7k]
  |  Branch (364:26): [True: 0, False: 17.7k]
  |  Branch (364:48): [True: 0, False: 17.7k]
  ------------------
  365|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  366|      0|        return SECFailure;
  367|      0|    }
  368|       |
  369|       |    /*
  370|       |     * Make sure the point is on the requested curve to avoid
  371|       |     * certain small subgroup attacks.
  372|       |     */
  373|  17.7k|    if (EC_ValidatePublicKey(ecParams, publicValue) != SECSuccess) {
  ------------------
  |  Branch (373:9): [True: 374, False: 17.3k]
  ------------------
  374|    374|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|    374|#define PORT_SetError PORT_SetError_Util
  ------------------
  375|    374|        return SECFailure;
  376|    374|    }
  377|       |
  378|       |    /* Perform curve specific multiplication using ECMethod */
  379|  17.3k|    if (ecParams->fieldID.type != ec_field_plain) {
  ------------------
  |  Branch (379:9): [True: 0, False: 17.3k]
  ------------------
  380|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  381|      0|        return SECFailure;
  382|      0|    }
  383|       |
  384|  17.3k|    const ECMethod *method = ec_get_method_from_name(ecParams->name);
  385|  17.3k|    if (method == NULL || method->pt_validate == NULL ||
  ------------------
  |  Branch (385:9): [True: 0, False: 17.3k]
  |  Branch (385:27): [True: 0, False: 17.3k]
  ------------------
  386|  17.3k|        method->pt_mul == NULL) {
  ------------------
  |  Branch (386:9): [True: 0, False: 17.3k]
  ------------------
  387|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  388|      0|        return SECFailure;
  389|      0|    }
  390|       |
  391|  17.3k|    memset(derivedSecret, 0, sizeof(*derivedSecret));
  392|  17.3k|    derivedSecret = SECITEM_AllocItem(NULL, derivedSecret, EC_GetScalarSize(ecParams));
  ------------------
  |  |  103|  17.3k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  393|  17.3k|    if (derivedSecret == NULL) {
  ------------------
  |  Branch (393:9): [True: 0, False: 17.3k]
  ------------------
  394|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  395|      0|        return SECFailure;
  396|      0|    }
  397|       |
  398|  17.3k|    SECStatus rv = method->pt_mul(derivedSecret, privateValue, publicValue);
  399|  17.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (399:9): [True: 1, False: 17.3k]
  ------------------
  400|      1|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  401|      1|        SECITEM_ZfreeItem(derivedSecret, PR_FALSE);
  ------------------
  |  |  110|      1|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(derivedSecret, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  402|      1|    }
  403|  17.3k|    return rv;
  404|  17.3k|}
ECDSA_SignDigestWithSeed:
  463|  11.7k|{
  464|       |#if EC_DEBUG || EC_DOUBLECHECK
  465|       |    SECItem *signature2 = SECITEM_AllocItem(NULL, NULL, signature->len);
  466|       |    SECStatus signSuccess = ec_SignDigestWithSeed(key, signature, digest, kb, kblen);
  467|       |    SECStatus signSuccessDouble = ec_SignDigestWithSeed(key, signature2, digest, kb, kblen);
  468|       |    int signaturesEqual = NSS_SecureMemcmp(signature->data, signature2->data, signature->len);
  469|       |    SECStatus rv;
  470|       |
  471|       |    if ((signaturesEqual == 0) && (signSuccess == SECSuccess) && (signSuccessDouble == SECSuccess)) {
  472|       |        rv = SECSuccess;
  473|       |    } else {
  474|       |        rv = SECFailure;
  475|       |    }
  476|       |
  477|       |#if EC_DEBUG
  478|       |    printf("ECDSA signing with seed %s after signing twice\n", (rv == SECSuccess) ? "succeeded" : "failed");
  479|       |#endif
  480|       |
  481|       |    SECITEM_FreeItem(signature2, PR_TRUE);
  482|       |    return rv;
  483|       |#else
  484|  11.7k|    return ec_SignDigestWithSeed(key, signature, digest, kb, kblen);
  485|  11.7k|#endif
  486|  11.7k|}
ECDSA_SignDigest:
  494|  11.7k|{
  495|  11.7k|    SECItem nonceRand = { siBuffer, NULL, 0 };
  496|       |
  497|  11.7k|    if (!key) {
  ------------------
  |  Branch (497:9): [True: 0, False: 11.7k]
  ------------------
  498|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  499|      0|        return SECFailure;
  500|      0|    }
  501|       |
  502|       |    /* Generate random value k */
  503|  11.7k|    SECITEM_AllocItem(NULL, &nonceRand, EC_GetScalarSize(&key->ecParams));
  ------------------
  |  |  103|  11.7k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  504|  11.7k|    if (nonceRand.data == NULL) {
  ------------------
  |  Branch (504:9): [True: 0, False: 11.7k]
  ------------------
  505|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  506|      0|        return SECFailure;
  507|      0|    }
  508|       |
  509|  11.7k|    SECStatus rv = ec_GenerateRandomPrivateKey(&key->ecParams, &nonceRand);
  510|  11.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (510:9): [True: 0, False: 11.7k]
  ------------------
  511|      0|        goto cleanup;
  512|      0|    }
  513|       |
  514|       |    /* Generate ECDSA signature with the specified k value */
  515|  11.7k|    rv = ECDSA_SignDigestWithSeed(key, signature, digest, nonceRand.data, nonceRand.len);
  516|  11.7k|    NSS_DECLASSIFY(signature->data, signature->len);
  517|       |
  518|  11.7k|cleanup:
  519|  11.7k|    SECITEM_ZfreeItem(&nonceRand, PR_FALSE);
  ------------------
  |  |  110|  11.7k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                  SECITEM_ZfreeItem(&nonceRand, PR_FALSE);
  ------------------
  |  |  438|  11.7k|#define PR_FALSE 0
  ------------------
  520|       |
  521|       |#if EC_DEBUG
  522|       |    printf("ECDSA signing %s\n",
  523|       |           (rv == SECSuccess) ? "succeeded" : "failed");
  524|       |#endif
  525|       |
  526|  11.7k|    return rv;
  527|  11.7k|}
ec.c:ec_get_method_from_name:
   87|   113k|{
   88|   113k|    unsigned long i;
   89|   200k|    for (i = 0; i < sizeof(kMethods) / sizeof(kMethods[0]); ++i) {
  ------------------
  |  Branch (89:17): [True: 200k, False: 0]
  ------------------
   90|   200k|        if (kMethods[i].name == name) {
  ------------------
  |  Branch (90:13): [True: 113k, False: 87.2k]
  ------------------
   91|   113k|            return &kMethods[i];
   92|   113k|        }
   93|   200k|    }
   94|      0|    return NULL;
   95|   113k|}
ec.c:ec_SignDigestWithSeed:
  414|  11.7k|{
  415|  11.7k|    ECParams *ecParams = NULL;
  416|  11.7k|    unsigned olen; /* length in bytes of the base point order */
  417|       |
  418|       |    /* Check args */
  419|  11.7k|    if (!key || !signature || !digest || !kb || (kblen <= 0)) {
  ------------------
  |  Branch (419:9): [True: 0, False: 11.7k]
  |  Branch (419:17): [True: 0, False: 11.7k]
  |  Branch (419:31): [True: 0, False: 11.7k]
  |  Branch (419:42): [True: 0, False: 11.7k]
  |  Branch (419:49): [True: 0, False: 11.7k]
  ------------------
  420|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  421|      0|        return SECFailure;
  422|      0|    }
  423|       |
  424|  11.7k|    ecParams = &(key->ecParams);
  425|  11.7k|    olen = ecParams->order.len;
  426|  11.7k|    if (signature->data == NULL) {
  ------------------
  |  Branch (426:9): [True: 0, False: 11.7k]
  ------------------
  427|       |        /* a call to get the signature length only */
  428|      0|        signature->len = 2 * olen;
  429|      0|        return SECSuccess;
  430|      0|    }
  431|  11.7k|    if (signature->len < 2 * olen) {
  ------------------
  |  Branch (431:9): [True: 0, False: 11.7k]
  ------------------
  432|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  433|      0|        return SECFailure;
  434|      0|    }
  435|       |
  436|       |    /* Perform curve specific signature using ECMethod */
  437|  11.7k|    if (ecParams->fieldID.type != ec_field_plain) {
  ------------------
  |  Branch (437:9): [True: 0, False: 11.7k]
  ------------------
  438|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  439|      0|        return SECFailure;
  440|      0|    }
  441|       |
  442|  11.7k|    const ECMethod *method = ec_get_method_from_name(ecParams->name);
  443|  11.7k|    if (method == NULL || method->sign_digest == NULL) {
  ------------------
  |  Branch (443:9): [True: 0, False: 11.7k]
  |  Branch (443:27): [True: 0, False: 11.7k]
  ------------------
  444|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  445|      0|        return SECFailure;
  446|      0|    }
  447|       |
  448|  11.7k|    SECStatus rv = method->sign_digest(key, signature, digest, kb, kblen);
  449|  11.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (449:9): [True: 0, False: 11.7k]
  ------------------
  450|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  451|      0|    }
  452|       |
  453|       |#if EC_DEBUG
  454|       |    printf("ECDSA signing with seed %s\n",
  455|       |           (rv == SECSuccess) ? "succeeded" : "failed");
  456|       |#endif
  457|  11.7k|    return rv;
  458|  11.7k|}

EC_FillParams:
  100|  54.8k|{
  101|  54.8k|    SECStatus rv = SECFailure;
  102|  54.8k|    SECOidTag tag;
  103|  54.8k|    SECItem oid = { siBuffer, NULL, 0 };
  104|       |
  105|       |#if EC_DEBUG
  106|       |    int i;
  107|       |
  108|       |    printf("Encoded params in EC_DecodeParams: ");
  109|       |    for (i = 0; i < encodedParams->len; i++) {
  110|       |        printf("%02x:", encodedParams->data[i]);
  111|       |    }
  112|       |    printf("\n");
  113|       |#endif
  114|       |
  115|  54.8k|    if ((encodedParams->len != ANSI_X962_CURVE_OID_TOTAL_LEN) &&
  ------------------
  |  |   10|  54.8k|#define ANSI_X962_CURVE_OID_TOTAL_LEN 10
  ------------------
  |  Branch (115:9): [True: 28.6k, False: 26.2k]
  ------------------
  116|  54.8k|        (encodedParams->len != SECG_CURVE_OID_TOTAL_LEN) &&
  ------------------
  |  |   11|  28.6k|#define SECG_CURVE_OID_TOTAL_LEN 7
  ------------------
  |  Branch (116:9): [True: 22.2k, False: 6.33k]
  ------------------
  117|  54.8k|        (encodedParams->len != PKIX_NEWCURVES_OID_TOTAL_LEN) &&
  ------------------
  |  |   12|  22.2k|#define PKIX_NEWCURVES_OID_TOTAL_LEN 11
  ------------------
  |  Branch (117:9): [True: 0, False: 22.2k]
  ------------------
  118|  54.8k|        (encodedParams->len != ED25519_OID_TOTAL_LEN)) {
  ------------------
  |  |   13|      0|#define ED25519_OID_TOTAL_LEN 5
  ------------------
  |  Branch (118:9): [True: 0, False: 0]
  ------------------
  119|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  120|      0|        return SECFailure;
  121|  54.8k|    };
  122|       |
  123|  54.8k|    oid.len = encodedParams->len - 2;
  124|  54.8k|    oid.data = encodedParams->data + 2;
  125|  54.8k|    if ((encodedParams->data[0] != SEC_ASN1_OBJECT_ID) ||
  ------------------
  |  |   82|  54.8k|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
  |  Branch (125:9): [True: 0, False: 54.8k]
  ------------------
  126|  54.8k|        ((tag = SECOID_FindOIDTag(&oid)) == SEC_OID_UNKNOWN)) {
  ------------------
  |  |  117|  54.8k|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
  |  Branch (126:9): [True: 0, False: 54.8k]
  ------------------
  127|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  128|      0|        return SECFailure;
  129|      0|    }
  130|       |
  131|  54.8k|    params->arena = arena;
  132|  54.8k|    params->cofactor = 0;
  133|  54.8k|    params->type = ec_params_named;
  134|  54.8k|    params->name = ECCurve_noName;
  135|       |
  136|       |    /* Fill out curveOID */
  137|  54.8k|    params->curveOID.len = oid.len;
  138|  54.8k|    params->curveOID.data = (unsigned char *)PORT_ArenaAlloc(arena, oid.len);
  ------------------
  |  |   53|  54.8k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  139|  54.8k|    if (params->curveOID.data == NULL)
  ------------------
  |  Branch (139:9): [True: 0, False: 54.8k]
  ------------------
  140|      0|        goto cleanup;
  141|  54.8k|    memcpy(params->curveOID.data, oid.data, oid.len);
  142|       |
  143|       |#if EC_DEBUG
  144|       |    printf("Curve: %s\n", SECOID_FindOIDTagDescription(tag));
  145|       |#endif
  146|       |
  147|  54.8k|    switch (tag) {
  148|  26.2k|        case SEC_OID_ANSIX962_EC_PRIME256V1:
  ------------------
  |  Branch (148:9): [True: 26.2k, False: 28.6k]
  ------------------
  149|       |            /* Populate params for prime256v1 aka secp256r1
  150|       |             * (the NIST P-256 curve)
  151|       |             */
  152|  26.2k|            CHECK_SEC_OK(gf_populate_params_bytes(ECCurve_X9_62_PRIME_256V1,
  ------------------
  |  |   20|  26.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (20:9): [True: 0, False: 26.2k]
  |  |  ------------------
  |  |   21|  26.2k|    goto cleanup
  ------------------
  153|  26.2k|                                                  ec_field_plain, params));
  154|  26.2k|            break;
  155|       |
  156|  26.2k|        case SEC_OID_SECG_EC_SECP384R1:
  ------------------
  |  Branch (156:9): [True: 6.13k, False: 48.6k]
  ------------------
  157|       |            /* Populate params for secp384r1
  158|       |             * (the NIST P-384 curve)
  159|       |             */
  160|  6.13k|            CHECK_SEC_OK(gf_populate_params_bytes(ECCurve_SECG_PRIME_384R1,
  ------------------
  |  |   20|  6.13k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (20:9): [True: 0, False: 6.13k]
  |  |  ------------------
  |  |   21|  6.13k|    goto cleanup
  ------------------
  161|  6.13k|                                                  ec_field_plain, params));
  162|  6.13k|            break;
  163|       |
  164|  6.13k|        case SEC_OID_SECG_EC_SECP521R1:
  ------------------
  |  Branch (164:9): [True: 156, False: 54.6k]
  ------------------
  165|       |            /* Populate params for secp521r1
  166|       |             * (the NIST P-521 curve)
  167|       |             */
  168|    156|            CHECK_SEC_OK(gf_populate_params_bytes(ECCurve_SECG_PRIME_521R1,
  ------------------
  |  |   20|    156|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (20:9): [True: 0, False: 156]
  |  |  ------------------
  |  |   21|    156|    goto cleanup
  ------------------
  169|    156|                                                  ec_field_plain, params));
  170|    156|            break;
  171|       |
  172|    156|        case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (172:9): [True: 0, False: 54.8k]
  ------------------
  173|      0|            params->type = ec_params_edwards_named;
  174|      0|            CHECK_SEC_OK(gf_populate_params_bytes(ECCurve_Ed25519,
  ------------------
  |  |   20|      0|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (20:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   21|      0|    goto cleanup
  ------------------
  175|      0|                                                  ec_field_plain, params));
  176|       |
  177|      0|            break;
  178|       |
  179|      0|        case SEC_OID_X25519:
  ------------------
  |  Branch (179:9): [True: 0, False: 54.8k]
  ------------------
  180|  22.2k|        case SEC_OID_CURVE25519:
  ------------------
  |  Branch (180:9): [True: 22.2k, False: 32.5k]
  ------------------
  181|       |            /* Populate params for Curve25519 */
  182|  22.2k|            params->type = ec_params_montgomery_named;
  183|  22.2k|            CHECK_SEC_OK(gf_populate_params_bytes(ECCurve25519,
  ------------------
  |  |   20|  22.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (20:9): [True: 0, False: 22.2k]
  |  |  ------------------
  |  |   21|  22.2k|    goto cleanup
  ------------------
  184|  22.2k|                                                  ec_field_plain,
  185|  22.2k|                                                  params));
  186|  22.2k|            break;
  187|       |
  188|  22.2k|        default:
  ------------------
  |  Branch (188:9): [True: 44, False: 54.7k]
  ------------------
  189|     44|            break;
  190|  54.8k|    };
  191|       |
  192|  54.8k|cleanup:
  193|  54.8k|    if (!params->cofactor) {
  ------------------
  |  Branch (193:9): [True: 44, False: 54.7k]
  ------------------
  194|     44|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|     44|#define PORT_SetError PORT_SetError_Util
  ------------------
  195|       |#if EC_DEBUG
  196|       |        printf("Unrecognized curve, returning NULL params\n");
  197|       |#endif
  198|     44|    }
  199|       |
  200|  54.8k|    return rv;
  201|  54.8k|}
EC_DecodeParams:
  205|  18.2k|{
  206|  18.2k|    PLArenaPool *arena;
  207|  18.2k|    ECParams *params;
  208|  18.2k|    SECStatus rv = SECFailure;
  209|       |
  210|       |    /* Initialize an arena for the ECParams structure */
  211|  18.2k|    if (!(arena = PORT_NewArena(NSS_FREEBL_DEFAULT_CHUNKSIZE)))
  ------------------
  |  |   63|  18.2k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  if (!(arena = PORT_NewArena(NSS_FREEBL_DEFAULT_CHUNKSIZE)))
  ------------------
  |  |  143|  18.2k|#define NSS_FREEBL_DEFAULT_CHUNKSIZE 2048
  ------------------
  |  Branch (211:9): [True: 0, False: 18.2k]
  ------------------
  212|      0|        return SECFailure;
  213|       |
  214|  18.2k|    params = (ECParams *)PORT_ArenaZAlloc(arena, sizeof(ECParams));
  ------------------
  |  |   59|  18.2k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  215|  18.2k|    if (!params) {
  ------------------
  |  Branch (215:9): [True: 0, False: 18.2k]
  ------------------
  216|      0|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  217|      0|        return SECFailure;
  218|      0|    }
  219|       |
  220|       |    /* Copy the encoded params */
  221|  18.2k|    SECITEM_AllocItem(arena, &(params->DEREncoding),
  ------------------
  |  |  103|  18.2k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  222|  18.2k|                      encodedParams->len);
  223|  18.2k|    memcpy(params->DEREncoding.data, encodedParams->data, encodedParams->len);
  224|       |
  225|       |    /* Fill out the rest of the ECParams structure based on
  226|       |     * the encoded params
  227|       |     */
  228|  18.2k|    rv = EC_FillParams(arena, encodedParams, params);
  229|  18.2k|    if (rv == SECFailure) {
  ------------------
  |  Branch (229:9): [True: 44, False: 18.2k]
  ------------------
  230|     44|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|     44|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|     44|#define PR_TRUE 1
  ------------------
  231|     44|        return SECFailure;
  232|  18.2k|    } else {
  233|  18.2k|        *ecparams = params;
  234|  18.2k|        ;
  235|  18.2k|        return SECSuccess;
  236|  18.2k|    }
  237|  18.2k|}
EC_GetPointSize:
  241|  54.3k|{
  242|  54.3k|    ECCurveName name = params->name;
  243|  54.3k|    const ECCurveBytes *curveParams;
  244|       |
  245|  54.3k|    if ((name < ECCurve_noName) || (name > ECCurve_pastLastCurve) ||
  ------------------
  |  Branch (245:9): [True: 0, False: 54.3k]
  |  Branch (245:36): [True: 0, False: 54.3k]
  ------------------
  246|  54.3k|        ((curveParams = ecCurve_map[name]) == NULL)) {
  ------------------
  |  Branch (246:9): [True: 0, False: 54.3k]
  ------------------
  247|       |        /* unknown curve, calculate point size from params. assume standard curves with 2 points
  248|       |         * and a point compression indicator byte */
  249|      0|        int sizeInBytes = (params->fieldID.size + 7) / 8;
  250|      0|        return sizeInBytes * 2 + 1;
  251|      0|    }
  252|       |
  253|  54.3k|    if (params->type == ec_params_edwards_named || params->type == ec_params_montgomery_named) {
  ------------------
  |  Branch (253:9): [True: 0, False: 54.3k]
  |  Branch (253:52): [True: 22.0k, False: 32.2k]
  ------------------
  254|  22.0k|        return curveParams->scalarSize;
  255|  22.0k|    }
  256|       |
  257|  32.2k|    return curveParams->pointSize - 1;
  258|  54.3k|}
EC_GetScalarSize:
  262|  77.3k|{
  263|  77.3k|    ECCurveName name = params->name;
  264|  77.3k|    const ECCurveBytes *curveParams;
  265|       |
  266|  77.3k|    if ((name < ECCurve_noName) || (name > ECCurve_pastLastCurve) ||
  ------------------
  |  Branch (266:9): [True: 0, False: 77.3k]
  |  Branch (266:36): [True: 0, False: 77.3k]
  ------------------
  267|  77.3k|        ((curveParams = ecCurve_map[name]) == NULL)) {
  ------------------
  |  Branch (267:9): [True: 0, False: 77.3k]
  ------------------
  268|       |        /* unknown curve, calculate scalar size from field size in params */
  269|      0|        int sizeInBytes = (params->fieldID.size + 7) / 8;
  270|      0|        return sizeInBytes;
  271|      0|    }
  272|  77.3k|    return curveParams->scalarSize;
  273|  77.3k|}
ecdecode.c:gf_populate_params_bytes:
   65|  54.7k|{
   66|  54.7k|    SECStatus rv = SECFailure;
   67|  54.7k|    const ECCurveBytes *curveParams;
   68|       |
   69|  54.7k|    if ((name < ECCurve_noName) || (name > ECCurve_pastLastCurve))
  ------------------
  |  Branch (69:9): [True: 0, False: 54.7k]
  |  Branch (69:36): [True: 0, False: 54.7k]
  ------------------
   70|      0|        goto cleanup;
   71|  54.7k|    params->name = name;
   72|  54.7k|    curveParams = ecCurve_map[params->name];
   73|  54.7k|    CHECK_OK(curveParams);
  ------------------
  |  |   17|  54.7k|    if (func == NULL)  \
  |  |  ------------------
  |  |  |  Branch (17:9): [True: 0, False: 54.7k]
  |  |  ------------------
  |  |   18|  54.7k|    goto cleanup
  ------------------
   74|  54.7k|    params->fieldID.size = curveParams->size;
   75|  54.7k|    params->fieldID.type = field_type;
   76|  54.7k|    if (field_type != ec_field_plain) {
  ------------------
  |  Branch (76:9): [True: 0, False: 54.7k]
  ------------------
   77|      0|        return SECFailure;
   78|      0|    }
   79|  54.7k|    params->fieldID.u.prime.len = curveParams->scalarSize;
   80|  54.7k|    params->fieldID.u.prime.data = (unsigned char *)curveParams->irr;
   81|  54.7k|    params->curve.a.len = curveParams->scalarSize;
   82|  54.7k|    params->curve.a.data = (unsigned char *)curveParams->curvea;
   83|  54.7k|    params->curve.b.len = curveParams->scalarSize;
   84|  54.7k|    params->curve.b.data = (unsigned char *)curveParams->curveb;
   85|  54.7k|    params->base.len = curveParams->pointSize;
   86|  54.7k|    params->base.data = (unsigned char *)curveParams->base;
   87|  54.7k|    params->order.len = curveParams->scalarSize;
   88|  54.7k|    params->order.data = (unsigned char *)curveParams->order;
   89|  54.7k|    params->cofactor = curveParams->cofactor;
   90|       |
   91|  54.7k|    rv = SECSuccess;
   92|       |
   93|  54.7k|cleanup:
   94|  54.7k|    return rv;
   95|  54.7k|}

ec_Curve25519_mul:
   15|  14.6k|{
   16|       |// Note: this cast is safe because HaCl* state has a post-condition that only "mypublic" changed.
   17|       |#if defined HACL_CAN_COMPILE_INLINE_ASM
   18|       |    Hacl_Curve25519_64_ecdh(mypublic, (uint8_t *)secret, (uint8_t *)basepoint);
   19|       |#else
   20|  14.6k|    Hacl_Curve25519_51_ecdh(mypublic, (uint8_t *)secret, (uint8_t *)basepoint);
   21|  14.6k|#endif
   22|       |
   23|  14.6k|    return 0;
   24|  14.6k|}

ec_Curve25519_pt_validate:
   24|  14.6k|{
   25|  14.6k|    PRUint8 *p;
   26|  14.6k|    PRUint64 i;
   27|  14.6k|    PRUint8 forbiddenValues[12][32] = {
   28|  14.6k|        { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
   29|  14.6k|          0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
   30|  14.6k|          0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
   31|  14.6k|          0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 },
   32|  14.6k|        { 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
   33|  14.6k|          0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
   34|  14.6k|          0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
   35|  14.6k|          0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 },
   36|  14.6k|        { 0xe0, 0xeb, 0x7a, 0x7c, 0x3b, 0x41, 0xb8, 0xae,
   37|  14.6k|          0x16, 0x56, 0xe3, 0xfa, 0xf1, 0x9f, 0xc4, 0x6a,
   38|  14.6k|          0xda, 0x09, 0x8d, 0xeb, 0x9c, 0x32, 0xb1, 0xfd,
   39|  14.6k|          0x86, 0x62, 0x05, 0x16, 0x5f, 0x49, 0xb8, 0x00 },
   40|  14.6k|        { 0x5f, 0x9c, 0x95, 0xbc, 0xa3, 0x50, 0x8c, 0x24,
   41|  14.6k|          0xb1, 0xd0, 0xb1, 0x55, 0x9c, 0x83, 0xef, 0x5b,
   42|  14.6k|          0x04, 0x44, 0x5c, 0xc4, 0x58, 0x1c, 0x8e, 0x86,
   43|  14.6k|          0xd8, 0x22, 0x4e, 0xdd, 0xd0, 0x9f, 0x11, 0x57 },
   44|  14.6k|        { 0xec, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   45|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   46|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   47|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f },
   48|  14.6k|        { 0xed, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   49|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   50|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   51|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f },
   52|  14.6k|        { 0xee, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   53|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   54|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   55|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x7f },
   56|  14.6k|        { 0xcd, 0xeb, 0x7a, 0x7c, 0x3b, 0x41, 0xb8, 0xae,
   57|  14.6k|          0x16, 0x56, 0xe3, 0xfa, 0xf1, 0x9f, 0xc4, 0x6a,
   58|  14.6k|          0xda, 0x09, 0x8d, 0xeb, 0x9c, 0x32, 0xb1, 0xfd,
   59|  14.6k|          0x86, 0x62, 0x05, 0x16, 0x5f, 0x49, 0xb8, 0x80 },
   60|  14.6k|        { 0x4c, 0x9c, 0x95, 0xbc, 0xa3, 0x50, 0x8c, 0x24,
   61|  14.6k|          0xb1, 0xd0, 0xb1, 0x55, 0x9c, 0x83, 0xef, 0x5b,
   62|  14.6k|          0x04, 0x44, 0x5c, 0xc4, 0x58, 0x1c, 0x8e, 0x86,
   63|  14.6k|          0xd8, 0x22, 0x4e, 0xdd, 0xd0, 0x9f, 0x11, 0xd7 },
   64|  14.6k|        { 0xd9, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   65|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   66|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   67|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff },
   68|  14.6k|        { 0xda, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   69|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   70|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   71|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff },
   72|  14.6k|        { 0xdb, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   73|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   74|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
   75|  14.6k|          0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff },
   76|  14.6k|    };
   77|       |
   78|  14.6k|    if (px->len == 32) {
  ------------------
  |  Branch (78:9): [True: 14.6k, False: 6]
  ------------------
   79|  14.6k|        p = px->data;
   80|  14.6k|    } else {
   81|      6|        return SECFailure;
   82|      6|    }
   83|       |
   84|   190k|    for (i = 0; i < PR_ARRAY_SIZE(forbiddenValues); ++i) {
  ------------------
  |  |  167|   190k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (84:17): [True: 175k, False: 14.6k]
  ------------------
   85|   175k|        if (NSS_SecureMemcmp(p, forbiddenValues[i], px->len) == 0) {
  ------------------
  |  Branch (85:13): [True: 2, False: 175k]
  ------------------
   86|      2|            return SECFailure;
   87|      2|        }
   88|   175k|    }
   89|       |
   90|  14.6k|    return SECSuccess;
   91|  14.6k|}
ec_Curve25519_scalar_validate:
   98|  7.42k|{
   99|  7.42k|    if (!scalar || !scalar->data) {
  ------------------
  |  Branch (99:9): [True: 0, False: 7.42k]
  |  Branch (99:20): [True: 0, False: 7.42k]
  ------------------
  100|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  101|      0|        return SECFailure;
  102|      0|    }
  103|       |
  104|  7.42k|    if (scalar->len != 32) {
  ------------------
  |  Branch (104:9): [True: 0, False: 7.42k]
  ------------------
  105|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  106|      0|        return SECFailure;
  107|      0|    }
  108|  7.42k|    return SECSuccess;
  109|  7.42k|}
ec_Curve25519_pt_mul:
  118|  14.6k|{
  119|  14.6k|    PRUint8 *px;
  120|  14.6k|    PRUint8 basePoint[32] = { 9 };
  121|       |
  122|  14.6k|    if (!P) {
  ------------------
  |  Branch (122:9): [True: 7.42k, False: 7.20k]
  ------------------
  123|  7.42k|        px = basePoint;
  124|  7.42k|    } else {
  125|  7.20k|        PORT_Assert(P->len == 32);
  ------------------
  |  |  120|  7.20k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.20k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.20k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  126|  7.20k|        if (P->len != 32) {
  ------------------
  |  Branch (126:13): [True: 0, False: 7.20k]
  ------------------
  127|      0|            return SECFailure;
  128|      0|        }
  129|  7.20k|        px = P->data;
  130|  7.20k|    }
  131|  14.6k|    if (k->len != 32) {
  ------------------
  |  Branch (131:9): [True: 0, False: 14.6k]
  ------------------
  132|      0|        return SECFailure;
  133|      0|    }
  134|       |
  135|  14.6k|    SECStatus rv = ec_Curve25519_mul(X->data, k->data, px);
  136|  14.6k|    if (NSS_SecureMemcmpZero(X->data, X->len) == 0) {
  ------------------
  |  Branch (136:9): [True: 1, False: 14.6k]
  ------------------
  137|      1|        return SECFailure;
  138|      1|    }
  139|  14.6k|    return rv;
  140|  14.6k|}

ec_secp256r1_pt_validate:
   19|  17.1k|{
   20|  17.1k|    SECStatus res = SECSuccess;
   21|  17.1k|    if (!pt || !pt->data) {
  ------------------
  |  Branch (21:9): [True: 0, False: 17.1k]
  |  Branch (21:16): [True: 0, False: 17.1k]
  ------------------
   22|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   23|      0|        res = SECFailure;
   24|      0|        return res;
   25|      0|    }
   26|       |
   27|  17.1k|    if (pt->len != 65) {
  ------------------
  |  Branch (27:9): [True: 92, False: 17.0k]
  ------------------
   28|     92|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|     92|#define PORT_SetError PORT_SetError_Util
  ------------------
   29|     92|        res = SECFailure;
   30|     92|        return res;
   31|     92|    }
   32|       |
   33|  17.0k|    if (pt->data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|  17.0k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (33:9): [True: 20, False: 17.0k]
  ------------------
   34|     20|        PORT_SetError(SEC_ERROR_UNSUPPORTED_EC_POINT_FORM);
  ------------------
  |  |   65|     20|#define PORT_SetError PORT_SetError_Util
  ------------------
   35|     20|        res = SECFailure;
   36|     20|        return res;
   37|     20|    }
   38|       |
   39|  17.0k|    bool b = Hacl_P256_validate_public_key(pt->data + 1);
   40|       |
   41|  17.0k|    if (!b) {
  ------------------
  |  Branch (41:9): [True: 78, False: 16.9k]
  ------------------
   42|     78|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|     78|#define PORT_SetError PORT_SetError_Util
  ------------------
   43|     78|        res = SECFailure;
   44|     78|    }
   45|  17.0k|    return res;
   46|  17.0k|}
ec_secp256r1_scalar_validate:
   54|  20.4k|{
   55|  20.4k|    SECStatus res = SECSuccess;
   56|  20.4k|    if (!scalar || !scalar->data) {
  ------------------
  |  Branch (56:9): [True: 0, False: 20.4k]
  |  Branch (56:20): [True: 0, False: 20.4k]
  ------------------
   57|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   58|      0|        res = SECFailure;
   59|      0|        return res;
   60|      0|    }
   61|       |
   62|  20.4k|    if (scalar->len != 32) {
  ------------------
  |  Branch (62:9): [True: 0, False: 20.4k]
  ------------------
   63|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   64|      0|        res = SECFailure;
   65|      0|        return res;
   66|      0|    }
   67|       |
   68|  20.4k|    bool b = Hacl_P256_validate_private_key(scalar->data);
   69|       |
   70|  20.4k|    if (!b) {
  ------------------
  |  Branch (70:9): [True: 0, False: 20.4k]
  ------------------
   71|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   72|      0|        res = SECFailure;
   73|      0|    }
   74|  20.4k|    return res;
   75|  20.4k|}
ec_secp256r1_pt_mul:
   85|  16.9k|{
   86|  16.9k|    SECStatus res = SECSuccess;
   87|  16.9k|    if (!P) {
  ------------------
  |  Branch (87:9): [True: 8.73k, False: 8.21k]
  ------------------
   88|  8.73k|        uint8_t derived[64] = { 0 };
   89|       |
   90|  8.73k|        if (!X || !k || !X->data || !k->data ||
  ------------------
  |  Branch (90:13): [True: 0, False: 8.73k]
  |  Branch (90:19): [True: 0, False: 8.73k]
  |  Branch (90:25): [True: 0, False: 8.73k]
  |  Branch (90:37): [True: 0, False: 8.73k]
  ------------------
   91|  8.73k|            X->len < 65 || k->len != 32) {
  ------------------
  |  Branch (91:13): [True: 0, False: 8.73k]
  |  Branch (91:28): [True: 0, False: 8.73k]
  ------------------
   92|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   93|      0|            res = SECFailure;
   94|      0|            return res;
   95|      0|        }
   96|       |
   97|  8.73k|        bool b = Hacl_P256_dh_initiator(derived, k->data);
   98|       |
   99|  8.73k|        if (!b) {
  ------------------
  |  Branch (99:13): [True: 0, False: 8.73k]
  ------------------
  100|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  101|      0|            res = SECFailure;
  102|      0|            return res;
  103|      0|        }
  104|       |
  105|  8.73k|        X->len = 65;
  106|  8.73k|        X->data[0] = EC_POINT_FORM_UNCOMPRESSED;
  ------------------
  |  |   92|  8.73k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  107|  8.73k|        memcpy(X->data + 1, derived, 64);
  108|       |
  109|  8.73k|    } else {
  110|  8.21k|        uint8_t full_key[32] = { 0 };
  111|  8.21k|        uint8_t *key;
  112|  8.21k|        uint8_t derived[64] = { 0 };
  113|       |
  114|  8.21k|        if (!X || !k || !P || !X->data || !k->data || !P->data ||
  ------------------
  |  Branch (114:13): [True: 0, False: 8.21k]
  |  Branch (114:19): [True: 0, False: 8.21k]
  |  Branch (114:25): [True: 0, False: 8.21k]
  |  Branch (114:31): [True: 0, False: 8.21k]
  |  Branch (114:43): [True: 0, False: 8.21k]
  |  Branch (114:55): [True: 0, False: 8.21k]
  ------------------
  115|  8.21k|            X->len < 32 || P->len != 65 ||
  ------------------
  |  Branch (115:13): [True: 0, False: 8.21k]
  |  Branch (115:28): [True: 0, False: 8.21k]
  ------------------
  116|  8.21k|            P->data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|  8.21k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (116:13): [True: 0, False: 8.21k]
  ------------------
  117|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  118|      0|            res = SECFailure;
  119|      0|            return res;
  120|      0|        }
  121|       |
  122|       |        /* We consider keys of up to size 32, or of size 33 with a single leading 0 */
  123|  8.21k|        if (k->len < 32) {
  ------------------
  |  Branch (123:13): [True: 0, False: 8.21k]
  ------------------
  124|      0|            memcpy(full_key + 32 - k->len, k->data, k->len);
  125|      0|            key = full_key;
  126|  8.21k|        } else if (k->len == 32) {
  ------------------
  |  Branch (126:20): [True: 8.21k, False: 0]
  ------------------
  127|  8.21k|            key = k->data;
  128|  8.21k|        } else if (k->len == 33 && k->data[0] == 0) {
  ------------------
  |  Branch (128:20): [True: 0, False: 0]
  |  Branch (128:36): [True: 0, False: 0]
  ------------------
  129|      0|            key = k->data + 1;
  130|      0|        } else {
  131|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  132|      0|            res = SECFailure;
  133|      0|            return res;
  134|      0|        }
  135|       |
  136|  8.21k|        bool b = Hacl_P256_dh_responder(derived, P->data + 1, key);
  137|       |
  138|  8.21k|        if (!b) {
  ------------------
  |  Branch (138:13): [True: 0, False: 8.21k]
  ------------------
  139|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  140|      0|            res = SECFailure;
  141|      0|            return res;
  142|      0|        }
  143|       |
  144|  8.21k|        X->len = 32;
  145|  8.21k|        memcpy(X->data, derived, 32);
  146|  8.21k|    }
  147|       |
  148|  16.9k|    return res;
  149|  16.9k|}
ec_secp256r1_sign_digest:
  159|  11.7k|{
  160|  11.7k|    SECStatus res = SECSuccess;
  161|       |
  162|  11.7k|    if (!ecPrivKey || !signature || !digest || !kb ||
  ------------------
  |  Branch (162:9): [True: 0, False: 11.7k]
  |  Branch (162:23): [True: 0, False: 11.7k]
  |  Branch (162:37): [True: 0, False: 11.7k]
  |  Branch (162:48): [True: 0, False: 11.7k]
  ------------------
  163|  11.7k|        !ecPrivKey->privateValue.data ||
  ------------------
  |  Branch (163:9): [True: 0, False: 11.7k]
  ------------------
  164|  11.7k|        !signature->data || !digest->data ||
  ------------------
  |  Branch (164:9): [True: 0, False: 11.7k]
  |  Branch (164:29): [True: 0, False: 11.7k]
  ------------------
  165|  11.7k|        ecPrivKey->ecParams.name != ECCurve_NIST_P256) {
  ------------------
  |  Branch (165:9): [True: 0, False: 11.7k]
  ------------------
  166|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  167|      0|        res = SECFailure;
  168|      0|        return res;
  169|      0|    }
  170|       |
  171|  11.7k|    if (kblen == 0 || digest->len == 0 || signature->len < 64) {
  ------------------
  |  Branch (171:9): [True: 0, False: 11.7k]
  |  Branch (171:23): [True: 0, False: 11.7k]
  |  Branch (171:43): [True: 0, False: 11.7k]
  ------------------
  172|      0|        PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  173|      0|        res = SECFailure;
  174|      0|        return res;
  175|      0|    }
  176|       |
  177|       |    // Private keys should be 32 bytes, but some software trims leading zeros,
  178|       |    // and some software produces 33 byte keys with a leading zero. We'll
  179|       |    // accept these variants.
  180|  11.7k|    uint8_t padded_key_data[32] = { 0 };
  181|  11.7k|    uint8_t *key;
  182|  11.7k|    SECItem *privKey = &ecPrivKey->privateValue;
  183|  11.7k|    if (privKey->len == 32) {
  ------------------
  |  Branch (183:9): [True: 11.7k, False: 0]
  ------------------
  184|  11.7k|        key = privKey->data;
  185|  11.7k|    } else if (privKey->len == 33 && privKey->data[0] == 0) {
  ------------------
  |  Branch (185:16): [True: 0, False: 0]
  |  Branch (185:38): [True: 0, False: 0]
  ------------------
  186|      0|        key = privKey->data + 1;
  187|      0|    } else if (privKey->len < 32) {
  ------------------
  |  Branch (187:16): [True: 0, False: 0]
  ------------------
  188|      0|        memcpy(padded_key_data + 32 - privKey->len, privKey->data, privKey->len);
  189|      0|        key = padded_key_data;
  190|      0|    } else {
  191|      0|        PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  192|      0|        return SECFailure;
  193|      0|    }
  194|       |
  195|  11.7k|    uint8_t hash[32] = { 0 };
  196|  11.7k|    if (digest->len < 32) {
  ------------------
  |  Branch (196:9): [True: 9.39k, False: 2.32k]
  ------------------
  197|  9.39k|        memcpy(hash + 32 - digest->len, digest->data, digest->len);
  198|  9.39k|    } else {
  199|  2.32k|        memcpy(hash, digest->data, 32);
  200|  2.32k|    }
  201|       |
  202|  11.7k|    uint8_t nonce[32] = { 0 };
  203|  11.7k|    if (kblen < 32) {
  ------------------
  |  Branch (203:9): [True: 0, False: 11.7k]
  ------------------
  204|      0|        memcpy(nonce + 32 - kblen, kb, kblen);
  205|  11.7k|    } else {
  206|  11.7k|        memcpy(nonce, kb, 32);
  207|  11.7k|    }
  208|       |
  209|  11.7k|    bool b = Hacl_P256_ecdsa_sign_p256_without_hash(
  210|  11.7k|        signature->data, 32, hash, key, nonce);
  211|  11.7k|    if (!b) {
  ------------------
  |  Branch (211:9): [True: 0, False: 11.7k]
  ------------------
  212|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  213|      0|        res = SECFailure;
  214|      0|        return res;
  215|      0|    }
  216|       |
  217|  11.7k|    signature->len = 64;
  218|  11.7k|    return res;
  219|  11.7k|}

ec_secp384r1_pt_validate:
   21|  4.09k|{
   22|  4.09k|    SECStatus res = SECSuccess;
   23|  4.09k|    if (!pt || !pt->data) {
  ------------------
  |  Branch (23:9): [True: 0, False: 4.09k]
  |  Branch (23:16): [True: 0, False: 4.09k]
  ------------------
   24|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   25|      0|        res = SECFailure;
   26|      0|        return res;
   27|      0|    }
   28|       |
   29|  4.09k|    if (pt->len != 97) {
  ------------------
  |  Branch (29:9): [True: 27, False: 4.07k]
  ------------------
   30|     27|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|     27|#define PORT_SetError PORT_SetError_Util
  ------------------
   31|     27|        res = SECFailure;
   32|     27|        return res;
   33|     27|    }
   34|       |
   35|  4.07k|    if (pt->data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|  4.07k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (35:9): [True: 12, False: 4.05k]
  ------------------
   36|     12|        PORT_SetError(SEC_ERROR_UNSUPPORTED_EC_POINT_FORM);
  ------------------
  |  |   65|     12|#define PORT_SetError PORT_SetError_Util
  ------------------
   37|     12|        res = SECFailure;
   38|     12|        return res;
   39|     12|    }
   40|       |
   41|  4.05k|    bool b = Hacl_P384_validate_public_key(pt->data + 1);
   42|       |
   43|  4.05k|    if (!b) {
  ------------------
  |  Branch (43:9): [True: 64, False: 3.99k]
  ------------------
   44|     64|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|     64|#define PORT_SetError PORT_SetError_Util
  ------------------
   45|     64|        res = SECFailure;
   46|     64|    }
   47|  4.05k|    return res;
   48|  4.07k|}
ec_secp384r1_scalar_validate:
   56|  2.04k|{
   57|  2.04k|    SECStatus res = SECSuccess;
   58|  2.04k|    if (!scalar || !scalar->data) {
  ------------------
  |  Branch (58:9): [True: 0, False: 2.04k]
  |  Branch (58:20): [True: 0, False: 2.04k]
  ------------------
   59|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   60|      0|        res = SECFailure;
   61|      0|        return res;
   62|      0|    }
   63|       |
   64|  2.04k|    if (scalar->len != 48) {
  ------------------
  |  Branch (64:9): [True: 0, False: 2.04k]
  ------------------
   65|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   66|      0|        res = SECFailure;
   67|      0|        return res;
   68|      0|    }
   69|       |
   70|  2.04k|    bool b = Hacl_P384_validate_private_key(scalar->data);
   71|       |
   72|  2.04k|    if (!b) {
  ------------------
  |  Branch (72:9): [True: 0, False: 2.04k]
  ------------------
   73|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   74|      0|        res = SECFailure;
   75|      0|    }
   76|  2.04k|    return res;
   77|  2.04k|}
ec_secp384r1_pt_mul:
   87|  3.99k|{
   88|  3.99k|    SECStatus res = SECSuccess;
   89|  3.99k|    if (!P) {
  ------------------
  |  Branch (89:9): [True: 2.04k, False: 1.94k]
  ------------------
   90|  2.04k|        uint8_t derived[96] = { 0 };
   91|       |
   92|  2.04k|        if (!X || !k || !X->data || !k->data ||
  ------------------
  |  Branch (92:13): [True: 0, False: 2.04k]
  |  Branch (92:19): [True: 0, False: 2.04k]
  |  Branch (92:25): [True: 0, False: 2.04k]
  |  Branch (92:37): [True: 0, False: 2.04k]
  ------------------
   93|  2.04k|            X->len < 97 || k->len != 48) {
  ------------------
  |  Branch (93:13): [True: 0, False: 2.04k]
  |  Branch (93:28): [True: 0, False: 2.04k]
  ------------------
   94|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   95|      0|            res = SECFailure;
   96|      0|            return res;
   97|      0|        }
   98|       |
   99|  2.04k|        bool b = Hacl_P384_dh_initiator(derived, k->data);
  100|       |
  101|  2.04k|        if (!b) {
  ------------------
  |  Branch (101:13): [True: 0, False: 2.04k]
  ------------------
  102|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  103|      0|            res = SECFailure;
  104|      0|            return res;
  105|      0|        }
  106|       |
  107|  2.04k|        X->len = 97;
  108|  2.04k|        X->data[0] = EC_POINT_FORM_UNCOMPRESSED;
  ------------------
  |  |   92|  2.04k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  109|  2.04k|        memcpy(X->data + 1, derived, 96);
  110|       |
  111|  2.04k|    } else {
  112|  1.94k|        uint8_t full_key[48] = { 0 };
  113|  1.94k|        uint8_t *key;
  114|  1.94k|        uint8_t derived[96] = { 0 };
  115|       |
  116|  1.94k|        if (!X || !k || !P || !X->data || !k->data || !P->data ||
  ------------------
  |  Branch (116:13): [True: 0, False: 1.94k]
  |  Branch (116:19): [True: 0, False: 1.94k]
  |  Branch (116:25): [True: 0, False: 1.94k]
  |  Branch (116:31): [True: 0, False: 1.94k]
  |  Branch (116:43): [True: 0, False: 1.94k]
  |  Branch (116:55): [True: 0, False: 1.94k]
  ------------------
  117|  1.94k|            X->len < 48 || P->len != 97 ||
  ------------------
  |  Branch (117:13): [True: 0, False: 1.94k]
  |  Branch (117:28): [True: 0, False: 1.94k]
  ------------------
  118|  1.94k|            P->data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|  1.94k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (118:13): [True: 0, False: 1.94k]
  ------------------
  119|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  120|      0|            res = SECFailure;
  121|      0|            return res;
  122|      0|        }
  123|       |
  124|       |        /* We consider keys of up to size 48, or of size 49 with a single leading 0 */
  125|  1.94k|        if (k->len < 48) {
  ------------------
  |  Branch (125:13): [True: 0, False: 1.94k]
  ------------------
  126|      0|            memcpy(full_key + 48 - k->len, k->data, k->len);
  127|      0|            key = full_key;
  128|  1.94k|        } else if (k->len == 48) {
  ------------------
  |  Branch (128:20): [True: 1.94k, False: 0]
  ------------------
  129|  1.94k|            key = k->data;
  130|  1.94k|        } else if (k->len == 49 && k->data[0] == 0) {
  ------------------
  |  Branch (130:20): [True: 0, False: 0]
  |  Branch (130:36): [True: 0, False: 0]
  ------------------
  131|      0|            key = k->data + 1;
  132|      0|        } else {
  133|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  134|      0|            res = SECFailure;
  135|      0|            return res;
  136|      0|        }
  137|       |
  138|  1.94k|        bool b = Hacl_P384_dh_responder(derived, P->data + 1, key);
  139|       |
  140|  1.94k|        if (!b) {
  ------------------
  |  Branch (140:13): [True: 0, False: 1.94k]
  ------------------
  141|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  142|      0|            res = SECFailure;
  143|      0|            return res;
  144|      0|        }
  145|       |
  146|  1.94k|        X->len = 48;
  147|  1.94k|        memcpy(X->data, derived, 48);
  148|  1.94k|    }
  149|       |
  150|  3.99k|    return res;
  151|  3.99k|}

ec_secp521r1_pt_validate:
   21|    125|{
   22|    125|    SECStatus res = SECSuccess;
   23|    125|    if (!pt || !pt->data) {
  ------------------
  |  Branch (23:9): [True: 0, False: 125]
  |  Branch (23:16): [True: 0, False: 125]
  ------------------
   24|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   25|      0|        res = SECFailure;
   26|      0|        return res;
   27|      0|    }
   28|       |
   29|    125|    if (pt->len != 133) {
  ------------------
  |  Branch (29:9): [True: 20, False: 105]
  ------------------
   30|     20|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|     20|#define PORT_SetError PORT_SetError_Util
  ------------------
   31|     20|        res = SECFailure;
   32|     20|        return res;
   33|     20|    }
   34|       |
   35|    105|    if (pt->data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|    105|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (35:9): [True: 2, False: 103]
  ------------------
   36|      2|        PORT_SetError(SEC_ERROR_UNSUPPORTED_EC_POINT_FORM);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
   37|      2|        res = SECFailure;
   38|      2|        return res;
   39|      2|    }
   40|       |
   41|    103|    bool b = Hacl_P521_validate_public_key(pt->data + 1);
   42|       |
   43|    103|    if (!b) {
  ------------------
  |  Branch (43:9): [True: 51, False: 52]
  ------------------
   44|     51|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|     51|#define PORT_SetError PORT_SetError_Util
  ------------------
   45|     51|        res = SECFailure;
   46|     51|    }
   47|    103|    return res;
   48|    105|}
ec_secp521r1_scalar_validate:
   56|     52|{
   57|     52|    SECStatus res = SECSuccess;
   58|     52|    if (!scalar || !scalar->data) {
  ------------------
  |  Branch (58:9): [True: 0, False: 52]
  |  Branch (58:20): [True: 0, False: 52]
  ------------------
   59|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   60|      0|        res = SECFailure;
   61|      0|        return res;
   62|      0|    }
   63|       |
   64|     52|    if (scalar->len != 66) {
  ------------------
  |  Branch (64:9): [True: 0, False: 52]
  ------------------
   65|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   66|      0|        res = SECFailure;
   67|      0|        return res;
   68|      0|    }
   69|       |
   70|     52|    bool b = Hacl_P521_validate_private_key(scalar->data);
   71|       |
   72|     52|    if (!b) {
  ------------------
  |  Branch (72:9): [True: 0, False: 52]
  ------------------
   73|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   74|      0|        res = SECFailure;
   75|      0|    }
   76|     52|    return res;
   77|     52|}
ec_secp521r1_pt_mul:
   87|     52|{
   88|     52|    SECStatus res = SECSuccess;
   89|     52|    if (!P) {
  ------------------
  |  Branch (89:9): [True: 52, False: 0]
  ------------------
   90|     52|        uint8_t derived[132] = { 0 };
   91|       |
   92|     52|        if (!X || !k || !X->data || !k->data ||
  ------------------
  |  Branch (92:13): [True: 0, False: 52]
  |  Branch (92:19): [True: 0, False: 52]
  |  Branch (92:25): [True: 0, False: 52]
  |  Branch (92:37): [True: 0, False: 52]
  ------------------
   93|     52|            X->len < 133 || k->len != 66) {
  ------------------
  |  Branch (93:13): [True: 0, False: 52]
  |  Branch (93:29): [True: 0, False: 52]
  ------------------
   94|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   95|      0|            res = SECFailure;
   96|      0|            return res;
   97|      0|        }
   98|       |
   99|     52|        bool b = Hacl_P521_dh_initiator(derived, k->data);
  100|       |
  101|     52|        if (!b) {
  ------------------
  |  Branch (101:13): [True: 0, False: 52]
  ------------------
  102|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  103|      0|            res = SECFailure;
  104|      0|            return res;
  105|      0|        }
  106|       |
  107|     52|        X->len = 133;
  108|     52|        X->data[0] = EC_POINT_FORM_UNCOMPRESSED;
  ------------------
  |  |   92|     52|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  109|     52|        memcpy(X->data + 1, derived, 132);
  110|       |
  111|     52|    } else {
  112|      0|        uint8_t full_key[66] = { 0 };
  113|      0|        uint8_t *key;
  114|      0|        uint8_t derived[132] = { 0 };
  115|       |
  116|      0|        if (!X || !k || !P || !X->data || !k->data || !P->data ||
  ------------------
  |  Branch (116:13): [True: 0, False: 0]
  |  Branch (116:19): [True: 0, False: 0]
  |  Branch (116:25): [True: 0, False: 0]
  |  Branch (116:31): [True: 0, False: 0]
  |  Branch (116:43): [True: 0, False: 0]
  |  Branch (116:55): [True: 0, False: 0]
  ------------------
  117|      0|            X->len < 66 || P->len != 133 ||
  ------------------
  |  Branch (117:13): [True: 0, False: 0]
  |  Branch (117:28): [True: 0, False: 0]
  ------------------
  118|      0|            P->data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|      0|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (118:13): [True: 0, False: 0]
  ------------------
  119|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  120|      0|            res = SECFailure;
  121|      0|            return res;
  122|      0|        }
  123|       |
  124|       |        /* We consider keys of up to size 66, or of size 67 with a single leading 0 */
  125|      0|        if (k->len < 66) {
  ------------------
  |  Branch (125:13): [True: 0, False: 0]
  ------------------
  126|      0|            memcpy(full_key + 66 - k->len, k->data, k->len);
  127|      0|            key = full_key;
  128|      0|        } else if (k->len == 66) {
  ------------------
  |  Branch (128:20): [True: 0, False: 0]
  ------------------
  129|      0|            key = k->data;
  130|      0|        } else if (k->len == 67 && k->data[0] == 0) {
  ------------------
  |  Branch (130:20): [True: 0, False: 0]
  |  Branch (130:36): [True: 0, False: 0]
  ------------------
  131|      0|            key = k->data + 1;
  132|      0|        } else {
  133|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  134|      0|            res = SECFailure;
  135|      0|            return res;
  136|      0|        }
  137|       |
  138|      0|        bool b = Hacl_P521_dh_responder(derived, P->data + 1, key);
  139|       |
  140|      0|        if (!b) {
  ------------------
  |  Branch (140:13): [True: 0, False: 0]
  ------------------
  141|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  142|      0|            res = SECFailure;
  143|      0|            return res;
  144|      0|        }
  145|       |
  146|      0|        X->len = 66;
  147|      0|        memcpy(X->data, derived, 66);
  148|      0|    }
  149|       |
  150|     52|    return res;
  151|     52|}

gcm_HashInit_hw:
  112|   326k|{
  113|   326k|    ghash->ghash_mul = gcm_HashMult_hw;
  114|   326k|    ghash->x = _mm_setzero_si128();
  115|       |    /* MSVC requires __m64 to load epi64. */
  116|   326k|    ghash->h = _mm_set_epi32(ghash->h_high >> 32, (uint32_t)ghash->h_high,
  117|   326k|                             ghash->h_low >> 32, (uint32_t)ghash->h_low);
  118|   326k|    ghash->hw = PR_TRUE;
  ------------------
  |  |  437|   326k|#define PR_TRUE 1
  ------------------
  119|   326k|    return SECSuccess;
  120|   326k|}

get64:
   81|   653k|{
   82|   653k|    return ((uint64_t)bytes[0]) << 56 |
   83|   653k|           ((uint64_t)bytes[1]) << 48 |
   84|   653k|           ((uint64_t)bytes[2]) << 40 |
   85|   653k|           ((uint64_t)bytes[3]) << 32 |
   86|   653k|           ((uint64_t)bytes[4]) << 24 |
   87|   653k|           ((uint64_t)bytes[5]) << 16 |
   88|   653k|           ((uint64_t)bytes[6]) << 8 |
   89|   653k|           ((uint64_t)bytes[7]);
   90|   653k|}
gcmHash_InitContext:
   95|   326k|{
   96|   326k|    SECStatus rv = SECSuccess;
   97|       |
   98|   326k|    ghash->cLen = 0;
   99|   326k|    ghash->bufLen = 0;
  100|   326k|    PORT_Memset(ghash->counterBuf, 0, sizeof(ghash->counterBuf));
  ------------------
  |  |  182|   326k|#define PORT_Memset memset
  ------------------
  101|       |
  102|   326k|    ghash->h_low = get64(H + 8);
  103|   326k|    ghash->h_high = get64(H);
  104|       |#ifdef USE_ARM_GCM
  105|       |#if defined(__aarch64__)
  106|       |    if (arm_pmull_support() && !sw) {
  107|       |#else
  108|       |    if (arm_neon_support() && !sw) {
  109|       |#endif
  110|       |#elif defined(USE_PPC_CRYPTO)
  111|       |    if (ppc_crypto_support() && !sw) {
  112|       |#else
  113|   326k|    if (clmul_support() && !sw) {
  ------------------
  |  Branch (113:9): [True: 326k, False: 0]
  |  Branch (113:28): [True: 326k, False: 0]
  ------------------
  114|   326k|#endif
  115|   326k|        rv = gcm_HashInit_hw(ghash);
  116|   326k|    } else {
  117|       |/* We fall back to the software implementation if we can't use / don't
  118|       | * want to use pclmul. */
  119|      0|#ifdef HAVE_INT128_SUPPORT
  120|      0|        ghash->ghash_mul = gcm_HashMult_sftw;
  121|       |#else
  122|       |        ghash->ghash_mul = gcm_HashMult_sftw32;
  123|       |#endif
  124|      0|        ghash->x_high = ghash->x_low = 0;
  125|      0|        ghash->hw = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  126|      0|    }
  127|   326k|    return rv;
  128|   326k|}
GCM_CreateContext:
  551|   326k|{
  552|   326k|    GCMContext *gcm = NULL;
  553|   326k|    gcmHashContext *ghash = NULL;
  554|   326k|    unsigned char H[MAX_BLOCK_SIZE];
  555|   326k|    unsigned int tmp;
  556|   326k|    const CK_NSS_GCM_PARAMS *gcmParams = (const CK_NSS_GCM_PARAMS *)params;
  557|   326k|    SECStatus rv;
  558|       |#ifdef DISABLE_HW_GCM
  559|       |    const PRBool sw = PR_TRUE;
  560|       |#else
  561|   326k|    const PRBool sw = PR_FALSE;
  ------------------
  |  |  438|   326k|#define PR_FALSE 0
  ------------------
  562|   326k|#endif
  563|       |
  564|   326k|    gcm = PORT_ZNew(GCMContext);
  ------------------
  |  |  148|   326k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|   326k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  565|   326k|    if (gcm == NULL) {
  ------------------
  |  Branch (565:9): [True: 0, False: 326k]
  ------------------
  566|      0|        return NULL;
  567|      0|    }
  568|   326k|    gcm->cipher = cipher;
  569|   326k|    gcm->cipher_context = context;
  570|   326k|    ghash = PORT_ZNewAligned(gcmHashContext, 16, mem);
  ------------------
  |  |  150|   326k|    (type *)PORT_ZAllocAlignedOffset(sizeof(type), alignment, offsetof(type, mem))
  |  |  ------------------
  |  |  |  |   74|   326k|#define PORT_ZAllocAlignedOffset PORT_ZAllocAlignedOffset_Util
  |  |  ------------------
  ------------------
  571|       |
  572|       |    /* first plug in the ghash context */
  573|   326k|    gcm->ghash_context = ghash;
  574|   326k|    PORT_Memset(H, 0, AES_BLOCK_SIZE);
  ------------------
  |  |  182|   326k|#define PORT_Memset memset
  ------------------
                  PORT_Memset(H, 0, AES_BLOCK_SIZE);
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  575|   326k|    rv = (*cipher)(context, H, &tmp, AES_BLOCK_SIZE, H, AES_BLOCK_SIZE, AES_BLOCK_SIZE);
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
                  rv = (*cipher)(context, H, &tmp, AES_BLOCK_SIZE, H, AES_BLOCK_SIZE, AES_BLOCK_SIZE);
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
                  rv = (*cipher)(context, H, &tmp, AES_BLOCK_SIZE, H, AES_BLOCK_SIZE, AES_BLOCK_SIZE);
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  576|   326k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (576:9): [True: 0, False: 326k]
  ------------------
  577|      0|        goto loser;
  578|      0|    }
  579|   326k|    rv = gcmHash_InitContext(ghash, H, sw);
  580|   326k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (580:9): [True: 0, False: 326k]
  ------------------
  581|      0|        goto loser;
  582|      0|    }
  583|       |
  584|   326k|    gcm_InitIVContext(&gcm->gcm_iv);
  585|   326k|    gcm->ctr_context_init = PR_FALSE;
  ------------------
  |  |  438|   326k|#define PR_FALSE 0
  ------------------
  586|       |
  587|       |    /* if gcmPara/ms is NULL, then we are creating an PKCS #11 MESSAGE
  588|       |     * style context, in which we initialize the key once, then do separate
  589|       |     * iv/aad's for each message. In that case we only initialize the key
  590|       |     * and ghash. We initialize the counter in each separate message */
  591|   326k|    if (gcmParams == NULL) {
  ------------------
  |  Branch (591:9): [True: 326k, False: 0]
  ------------------
  592|       |        /* OK we are finished with init, if we are doing MESSAGE interface,
  593|       |         * return from here */
  594|   326k|        return gcm;
  595|   326k|    }
  596|       |
  597|      0|    rv = gcm_InitCounter(gcm, gcmParams->pIv, gcmParams->ulIvLen,
  598|      0|                         gcmParams->ulTagBits, gcmParams->pAAD,
  599|      0|                         gcmParams->ulAADLen);
  600|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (600:9): [True: 0, False: 0]
  ------------------
  601|      0|        goto loser;
  602|      0|    }
  603|      0|    PORT_SafeZero(H, AES_BLOCK_SIZE);
  ------------------
  |  |  130|      0|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  604|      0|    gcm->ctr_context_init = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  605|      0|    return gcm;
  606|       |
  607|      0|loser:
  608|      0|    PORT_SafeZero(H, AES_BLOCK_SIZE);
  ------------------
  |  |  130|      0|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  609|      0|    if (ghash && ghash->mem) {
  ------------------
  |  Branch (609:9): [True: 0, False: 0]
  |  Branch (609:18): [True: 0, False: 0]
  ------------------
  610|      0|        void *mem = ghash->mem;
  611|      0|        PORT_SafeZero(ghash, sizeof(gcmHashContext));
  612|      0|        PORT_Free(mem);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  613|      0|    }
  614|      0|    if (gcm) {
  ------------------
  |  Branch (614:9): [True: 0, False: 0]
  ------------------
  615|      0|        PORT_ZFree(gcm, sizeof(GCMContext));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  616|      0|    }
  617|      0|    return NULL;
  618|      0|}
GCM_DestroyContext:
  816|   326k|{
  817|   326k|    void *mem = gcm->ghash_context->mem;
  818|       |    /* ctr_context is statically allocated and will be freed when we free
  819|       |     * gcm. call their destroy functions to free up any locally
  820|       |     * allocated data (like mp_int's) */
  821|   326k|    if (gcm->ctr_context_init) {
  ------------------
  |  Branch (821:9): [True: 0, False: 326k]
  ------------------
  822|      0|        CTR_DestroyContext(&gcm->ctr_context, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  823|      0|    }
  824|   326k|    PORT_Memset(gcm->ghash_context, 0, sizeof(gcmHashContext));
  ------------------
  |  |  182|   326k|#define PORT_Memset memset
  ------------------
  825|   326k|    PORT_Free(mem);
  ------------------
  |  |   60|   326k|#define PORT_Free PORT_Free_Util
  ------------------
  826|   326k|    PORT_Memset(&gcm->tagBits, 0, sizeof(gcm->tagBits));
  ------------------
  |  |  182|   326k|#define PORT_Memset memset
  ------------------
  827|   326k|    PORT_Memset(gcm->tagKey, 0, sizeof(gcm->tagKey));
  ------------------
  |  |  182|   326k|#define PORT_Memset memset
  ------------------
  828|   326k|    if (freeit) {
  ------------------
  |  Branch (828:9): [True: 326k, False: 0]
  ------------------
  829|   326k|        PORT_Free(gcm);
  ------------------
  |  |   60|   326k|#define PORT_Free PORT_Free_Util
  ------------------
  830|   326k|    }
  831|   326k|}
gcm_InitIVContext:
  998|   326k|{
  999|   326k|    gcmIv->counter = 0;
 1000|   326k|    gcmIv->max_count = 0;
 1001|   326k|    gcmIv->ivGen = CKG_GENERATE;
  ------------------
  |  | 1992|   326k|#define CKG_GENERATE 0x00000001UL
  ------------------
 1002|   326k|    gcmIv->ivLen = 0;
 1003|   326k|    gcmIv->fixedBits = 0;
 1004|   326k|}

Kyber_Encapsulate:
  178|     99|{
  179|     99|    if (!valid_params(params)) {
  ------------------
  |  Branch (179:9): [True: 0, False: 99]
  ------------------
  180|      0|        PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  181|      0|        return SECFailure;
  182|      0|    }
  183|       |
  184|     99|    if (!(valid_enc_seed(params, enc_seed) && valid_pubkey(params, pubkey) && valid_ciphertext(params, ciphertext) && valid_secret(params, secret))) {
  ------------------
  |  Branch (184:11): [True: 99, False: 0]
  |  Branch (184:47): [True: 99, False: 0]
  |  Branch (184:79): [True: 99, False: 0]
  |  Branch (184:119): [True: 99, False: 0]
  ------------------
  185|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  186|      0|        return SECFailure;
  187|      0|    }
  188|       |
  189|     99|    uint8_t randbuf[KYBER_ENC_COIN_BYTES];
  190|     99|    uint8_t *coins;
  191|     99|    if (enc_seed) {
  ------------------
  |  Branch (191:9): [True: 0, False: 99]
  ------------------
  192|      0|        coins = enc_seed->data;
  193|     99|    } else {
  194|     99|        if (RNG_GenerateGlobalRandomBytes(randbuf, sizeof randbuf) != SECSuccess) {
  ------------------
  |  Branch (194:13): [True: 0, False: 99]
  ------------------
  195|      0|            PORT_SetError(SEC_ERROR_NEED_RANDOM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  196|      0|            return SECFailure;
  197|      0|        }
  198|     99|        coins = randbuf;
  199|     99|    }
  200|     99|    NSS_CLASSIFY(coins, KYBER_ENC_COIN_BYTES);
  201|     99|    if (params == params_kyber768_round3 || params == params_kyber768_round3_test_mode) {
  ------------------
  |  Branch (201:9): [True: 0, False: 99]
  |  Branch (201:45): [True: 0, False: 99]
  ------------------
  202|      0|        pqcrystals_kyber768_ref_enc_derand(ciphertext->data, secret->data, pubkey->data, coins);
  203|     99|    } else if (params == params_ml_kem768 || params == params_ml_kem768_test_mode) {
  ------------------
  |  Branch (203:16): [True: 99, False: 0]
  |  Branch (203:46): [True: 0, False: 0]
  ------------------
  204|     99|        libcrux_ml_kem_types_MlKemPublicKey_15 pk_value;
  205|     99|        memcpy(pk_value.value, pubkey->data, KYBER768_PUBLIC_KEY_BYTES);
  ------------------
  |  |    8|     99|#define KYBER768_PUBLIC_KEY_BYTES 1184U
  ------------------
  206|       |
  207|     99|        bool valid_pk = libcrux_ml_kem_mlkem768_portable_validate_public_key(&pk_value);
  208|     99|        if (!valid_pk) {
  ------------------
  |  Branch (208:13): [True: 16, False: 83]
  ------------------
  209|     16|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|     16|#define PORT_SetError PORT_SetError_Util
  ------------------
  210|     16|            return SECFailure;
  211|     16|        }
  212|       |
  213|     83|        tuple_3c encap = libcrux_ml_kem_mlkem768_portable_encapsulate(&pk_value, coins);
  214|     83|        memcpy(ciphertext->data, encap.fst.value, KYBER768_CIPHERTEXT_BYTES);
  ------------------
  |  |   10|     83|#define KYBER768_CIPHERTEXT_BYTES 1088U
  ------------------
  215|     83|        memcpy(secret->data, encap.snd, KYBER_SHARED_SECRET_BYTES);
  ------------------
  |  |   12|     83|#define KYBER_SHARED_SECRET_BYTES 32U
  ------------------
  216|     83|    } else {
  217|       |        /* unreachable */
  218|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  219|      0|        return SECFailure;
  220|      0|    }
  221|       |
  222|     83|    return SECSuccess;
  223|     99|}
kyber.c:valid_params:
   39|     99|{
   40|     99|    switch (params) {
   41|      0|        case params_kyber768_round3:
  ------------------
  |  Branch (41:9): [True: 0, False: 99]
  ------------------
   42|      0|        case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (42:9): [True: 0, False: 99]
  ------------------
   43|     99|        case params_ml_kem768:
  ------------------
  |  Branch (43:9): [True: 99, False: 0]
  ------------------
   44|     99|        case params_ml_kem768_test_mode:
  ------------------
  |  Branch (44:9): [True: 0, False: 99]
  ------------------
   45|     99|            return true;
   46|      0|        default:
  ------------------
  |  Branch (46:9): [True: 0, False: 99]
  ------------------
   47|      0|            return false;
   48|     99|    }
   49|     99|}
kyber.c:valid_pubkey:
   53|     99|{
   54|     99|    switch (params) {
   55|      0|        case params_kyber768_round3:
  ------------------
  |  Branch (55:9): [True: 0, False: 99]
  ------------------
   56|      0|        case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (56:9): [True: 0, False: 99]
  ------------------
   57|     99|        case params_ml_kem768:
  ------------------
  |  Branch (57:9): [True: 99, False: 0]
  ------------------
   58|     99|        case params_ml_kem768_test_mode:
  ------------------
  |  Branch (58:9): [True: 0, False: 99]
  ------------------
   59|     99|            return pubkey && pubkey->len == KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|    198|#define KYBER768_PUBLIC_KEY_BYTES 1184U
  ------------------
  |  Branch (59:20): [True: 99, False: 0]
  |  Branch (59:30): [True: 99, False: 0]
  ------------------
   60|      0|        default:
  ------------------
  |  Branch (60:9): [True: 0, False: 99]
  ------------------
   61|      0|            return false;
   62|     99|    }
   63|     99|}
kyber.c:valid_enc_seed:
  123|     99|{
  124|     99|    switch (params) {
  125|      0|        case params_kyber768_round3:
  ------------------
  |  Branch (125:9): [True: 0, False: 99]
  ------------------
  126|     99|        case params_ml_kem768:
  ------------------
  |  Branch (126:9): [True: 99, False: 0]
  ------------------
  127|     99|            return !seed;
  128|      0|        case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (128:9): [True: 0, False: 99]
  ------------------
  129|      0|        case params_ml_kem768_test_mode:
  ------------------
  |  Branch (129:9): [True: 0, False: 99]
  ------------------
  130|      0|            return !seed || seed->len == KYBER_SHARED_SECRET_BYTES;
  ------------------
  |  |   12|      0|#define KYBER_SHARED_SECRET_BYTES 32U
  ------------------
  |  Branch (130:20): [True: 0, False: 0]
  |  Branch (130:29): [True: 0, False: 0]
  ------------------
  131|      0|        default:
  ------------------
  |  Branch (131:9): [True: 0, False: 99]
  ------------------
  132|      0|            return false;
  133|     99|    }
  134|     99|}
kyber.c:valid_ciphertext:
   81|     99|{
   82|     99|    switch (params) {
   83|      0|        case params_kyber768_round3:
  ------------------
  |  Branch (83:9): [True: 0, False: 99]
  ------------------
   84|      0|        case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (84:9): [True: 0, False: 99]
  ------------------
   85|     99|        case params_ml_kem768:
  ------------------
  |  Branch (85:9): [True: 99, False: 0]
  ------------------
   86|     99|        case params_ml_kem768_test_mode:
  ------------------
  |  Branch (86:9): [True: 0, False: 99]
  ------------------
   87|     99|            return ciphertext && ciphertext->len == KYBER768_CIPHERTEXT_BYTES;
  ------------------
  |  |   10|    198|#define KYBER768_CIPHERTEXT_BYTES 1088U
  ------------------
  |  Branch (87:20): [True: 99, False: 0]
  |  Branch (87:34): [True: 99, False: 0]
  ------------------
   88|      0|        default:
  ------------------
  |  Branch (88:9): [True: 0, False: 99]
  ------------------
   89|      0|            return false;
   90|     99|    }
   91|     99|}
kyber.c:valid_secret:
   95|     99|{
   96|     99|    switch (params) {
   97|      0|        case params_kyber768_round3:
  ------------------
  |  Branch (97:9): [True: 0, False: 99]
  ------------------
   98|      0|        case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (98:9): [True: 0, False: 99]
  ------------------
   99|     99|        case params_ml_kem768:
  ------------------
  |  Branch (99:9): [True: 99, False: 0]
  ------------------
  100|     99|        case params_ml_kem768_test_mode:
  ------------------
  |  Branch (100:9): [True: 0, False: 99]
  ------------------
  101|     99|            return secret && secret->len == KYBER_SHARED_SECRET_BYTES;
  ------------------
  |  |   12|    198|#define KYBER_SHARED_SECRET_BYTES 32U
  ------------------
  |  Branch (101:20): [True: 99, False: 0]
  |  Branch (101:30): [True: 99, False: 0]
  ------------------
  102|      0|        default:
  ------------------
  |  Branch (102:9): [True: 0, False: 99]
  ------------------
  103|      0|            return false;
  104|     99|    }
  105|     99|}

MD5_NewContext:
  216|   111k|{
  217|       |    /* no need to ZAlloc, MD5_Begin will init the context */
  218|   111k|    MD5Context *cx = (MD5Context *)PORT_Alloc(sizeof(MD5Context));
  ------------------
  |  |   52|   111k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  219|   111k|    if (cx == NULL) {
  ------------------
  |  Branch (219:9): [True: 0, False: 111k]
  ------------------
  220|      0|        PORT_SetError(PR_OUT_OF_MEMORY_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_OUT_OF_MEMORY_ERROR);
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  221|      0|        return NULL;
  222|      0|    }
  223|   111k|    return cx;
  224|   111k|}
MD5_DestroyContext:
  228|   111k|{
  229|   111k|    memset(cx, 0, sizeof *cx);
  230|   111k|    if (freeit) {
  ------------------
  |  Branch (230:9): [True: 111k, False: 0]
  ------------------
  231|   111k|        PORT_Free(cx);
  ------------------
  |  |   60|   111k|#define PORT_Free PORT_Free_Util
  ------------------
  232|   111k|    }
  233|   111k|}
MD5_Begin:
  237|   374k|{
  238|   374k|    cx->lsbInput = 0;
  239|   374k|    cx->msbInput = 0;
  240|       |    /*  memset(cx->inBuf, 0, sizeof(cx->inBuf)); */
  241|   374k|    cx->cv[0] = CV0_1;
  ------------------
  |  |   22|   374k|#define CV0_1 0x67452301
  ------------------
  242|   374k|    cx->cv[1] = CV0_2;
  ------------------
  |  |   23|   374k|#define CV0_2 0xefcdab89
  ------------------
  243|   374k|    cx->cv[2] = CV0_3;
  ------------------
  |  |   24|   374k|#define CV0_3 0x98badcfe
  ------------------
  244|   374k|    cx->cv[3] = CV0_4;
  ------------------
  |  |   25|   374k|#define CV0_4 0x10325476
  ------------------
  245|   374k|}
MD5_Update:
  423|  1.36M|{
  424|  1.36M|    PRUint32 bytesToConsume;
  425|  1.36M|    PRUint32 inBufIndex = cx->lsbInput & 63;
  426|  1.36M|    const PRUint32 *wBuf;
  427|       |
  428|       |    /* Add the number of input bytes to the 64-bit input counter. */
  429|  1.36M|    addto64(cx->msbInput, cx->lsbInput, inputLen);
  ------------------
  |  |  255|  1.36M|    sumlow += addend;                    \
  |  |  256|  1.36M|    if (sumlow < addend)                 \
  |  |  ------------------
  |  |  |  Branch (256:9): [True: 0, False: 1.36M]
  |  |  ------------------
  |  |  257|  1.36M|        ++sumhigh;
  ------------------
  430|  1.36M|    if (inBufIndex) {
  ------------------
  |  Branch (430:9): [True: 643k, False: 724k]
  ------------------
  431|       |        /* There is already data in the buffer.  Fill with input. */
  432|   643k|        bytesToConsume = PR_MIN(inputLen, MD5_BUFFER_SIZE - inBufIndex);
  ------------------
  |  |  158|   643k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 524k, False: 118k]
  |  |  ------------------
  ------------------
  433|   643k|        memcpy(&cx->inBuf[inBufIndex], input, bytesToConsume);
  ------------------
  |  |  193|   643k|#define inBuf u.b
  ------------------
  434|   643k|        if (inBufIndex + bytesToConsume >= MD5_BUFFER_SIZE) {
  ------------------
  |  |   19|   643k|#define MD5_BUFFER_SIZE 64
  ------------------
  |  Branch (434:13): [True: 118k, False: 524k]
  ------------------
  435|       |/* The buffer is filled.  Run the compression function. */
  436|       |#ifndef IS_LITTLE_ENDIAN
  437|       |            md5_prep_state_le(cx);
  438|       |#endif
  439|   118k|            md5_compress(cx, cx->u.w);
  440|   118k|        }
  441|       |        /* Remaining input. */
  442|   643k|        inputLen -= bytesToConsume;
  443|   643k|        input += bytesToConsume;
  444|   643k|    }
  445|       |
  446|       |    /* Iterate over 64-byte chunks of the message. */
  447|  1.88M|    while (inputLen >= MD5_BUFFER_SIZE) {
  ------------------
  |  |   19|  1.88M|#define MD5_BUFFER_SIZE 64
  ------------------
  |  Branch (447:12): [True: 520k, False: 1.36M]
  ------------------
  448|   520k|#ifdef IS_LITTLE_ENDIAN
  449|   520k|#ifdef HAVE_UNALIGNED_ACCESS
  450|       |        /* x86 can handle arithmetic on non-word-aligned buffers */
  451|   520k|        wBuf = (PRUint32 *)input;
  452|       |#else
  453|       |        if ((ptrdiff_t)input & 0x3) {
  454|       |            /* buffer not aligned, copy it to force alignment */
  455|       |            memcpy(cx->inBuf, input, MD5_BUFFER_SIZE);
  456|       |            wBuf = cx->u.w;
  457|       |        } else {
  458|       |            /* buffer is aligned */
  459|       |            wBuf = (PRUint32 *)input;
  460|       |        }
  461|       |#endif
  462|       |#else
  463|       |        md5_prep_buffer_le(cx, input);
  464|       |        wBuf = cx->u.w;
  465|       |#endif
  466|   520k|        md5_compress(cx, wBuf);
  467|   520k|        inputLen -= MD5_BUFFER_SIZE;
  ------------------
  |  |   19|   520k|#define MD5_BUFFER_SIZE 64
  ------------------
  468|   520k|        input += MD5_BUFFER_SIZE;
  ------------------
  |  |   19|   520k|#define MD5_BUFFER_SIZE 64
  ------------------
  469|   520k|    }
  470|       |
  471|       |    /* Tail of message (message bytes mod 64). */
  472|  1.36M|    if (inputLen)
  ------------------
  |  Branch (472:9): [True: 475k, False: 892k]
  ------------------
  473|   475k|        memcpy(cx->inBuf, input, inputLen);
  ------------------
  |  |  193|   475k|#define inBuf u.b
  ------------------
  474|  1.36M|}
MD5_End:
  494|   362k|{
  495|       |#ifndef IS_LITTLE_ENDIAN
  496|       |    PRUint32 tmp;
  497|       |#endif
  498|   362k|    PRUint32 lowInput, highInput;
  499|   362k|    PRUint32 inBufIndex = cx->lsbInput & 63;
  500|       |
  501|   362k|    if (maxDigestLen < MD5_HASH_LEN) {
  ------------------
  |  |   18|   362k|#define MD5_HASH_LEN 16
  ------------------
  |  Branch (501:9): [True: 0, False: 362k]
  ------------------
  502|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  503|      0|        return;
  504|      0|    }
  505|       |
  506|       |    /* Copy out the length of bits input before padding. */
  507|   362k|    lowInput = cx->lsbInput;
  508|   362k|    highInput = (cx->msbInput << 3) | (lowInput >> 29);
  509|   362k|    lowInput <<= 3;
  510|       |
  511|   362k|    if (inBufIndex < MD5_END_BUFFER) {
  ------------------
  |  |   20|   362k|#define MD5_END_BUFFER (MD5_BUFFER_SIZE - 8)
  |  |  ------------------
  |  |  |  |   19|   362k|#define MD5_BUFFER_SIZE 64
  |  |  ------------------
  ------------------
  |  Branch (511:9): [True: 361k, False: 920]
  ------------------
  512|   361k|        MD5_Update(cx, padbytes, MD5_END_BUFFER - inBufIndex);
  ------------------
  |  |   20|   361k|#define MD5_END_BUFFER (MD5_BUFFER_SIZE - 8)
  |  |  ------------------
  |  |  |  |   19|   361k|#define MD5_BUFFER_SIZE 64
  |  |  ------------------
  ------------------
  513|   361k|    } else {
  514|    920|        MD5_Update(cx, padbytes,
  515|    920|                   MD5_END_BUFFER + MD5_BUFFER_SIZE - inBufIndex);
  ------------------
  |  |   20|    920|#define MD5_END_BUFFER (MD5_BUFFER_SIZE - 8)
  |  |  ------------------
  |  |  |  |   19|    920|#define MD5_BUFFER_SIZE 64
  |  |  ------------------
  ------------------
                                 MD5_END_BUFFER + MD5_BUFFER_SIZE - inBufIndex);
  ------------------
  |  |   19|    920|#define MD5_BUFFER_SIZE 64
  ------------------
  516|    920|    }
  517|       |
  518|       |    /* Store the number of bytes input (before padding) in final 64 bits. */
  519|   362k|    cx->u.w[14] = lendian(lowInput);
  ------------------
  |  |  263|   362k|    (i32)
  ------------------
  520|   362k|    cx->u.w[15] = lendian(highInput);
  ------------------
  |  |  263|   362k|    (i32)
  ------------------
  521|       |
  522|       |/* Final call to compress. */
  523|       |#ifndef IS_LITTLE_ENDIAN
  524|       |    md5_prep_state_le(cx);
  525|       |#endif
  526|   362k|    md5_compress(cx, cx->u.w);
  527|       |
  528|       |    /* Copy the resulting values out of the chain variables into return buf. */
  529|   362k|    if (digestLen)
  ------------------
  |  Branch (529:9): [True: 362k, False: 0]
  ------------------
  530|   362k|        *digestLen = MD5_HASH_LEN;
  ------------------
  |  |   18|   362k|#define MD5_HASH_LEN 16
  ------------------
  531|       |#ifndef IS_LITTLE_ENDIAN
  532|       |    cx->cv[0] = lendian(cx->cv[0]);
  533|       |    cx->cv[1] = lendian(cx->cv[1]);
  534|       |    cx->cv[2] = lendian(cx->cv[2]);
  535|       |    cx->cv[3] = lendian(cx->cv[3]);
  536|       |#endif
  537|   362k|    memcpy(digest, cx->cv, MD5_HASH_LEN);
  ------------------
  |  |   18|   362k|#define MD5_HASH_LEN 16
  ------------------
  538|   362k|}
MD5_FlattenSize:
  568|  23.5k|{
  569|  23.5k|    return sizeof(*cx);
  570|  23.5k|}
md5.c:md5_compress:
  344|  1.00M|{
  345|  1.00M|    PRUint32 a, b, c, d;
  346|  1.00M|    PRUint32 tmp;
  347|  1.00M|    a = cx->cv[0];
  348|  1.00M|    b = cx->cv[1];
  349|  1.00M|    c = cx->cv[2];
  350|  1.00M|    d = cx->cv[3];
  351|  1.00M|    FF(a, b, c, d, wBuf[R1B0], S1_0, T1_0);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  352|  1.00M|    FF(d, a, b, c, wBuf[R1B1], S1_1, T1_1);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  353|  1.00M|    FF(c, d, a, b, wBuf[R1B2], S1_2, T1_2);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  354|  1.00M|    FF(b, c, d, a, wBuf[R1B3], S1_3, T1_3);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  355|  1.00M|    FF(a, b, c, d, wBuf[R1B4], S1_0, T1_4);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  356|  1.00M|    FF(d, a, b, c, wBuf[R1B5], S1_1, T1_5);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  357|  1.00M|    FF(c, d, a, b, wBuf[R1B6], S1_2, T1_6);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  358|  1.00M|    FF(b, c, d, a, wBuf[R1B7], S1_3, T1_7);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  359|  1.00M|    FF(a, b, c, d, wBuf[R1B8], S1_0, T1_8);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  360|  1.00M|    FF(d, a, b, c, wBuf[R1B9], S1_1, T1_9);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  361|  1.00M|    FF(c, d, a, b, wBuf[R1B10], S1_2, T1_10);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  362|  1.00M|    FF(b, c, d, a, wBuf[R1B11], S1_3, T1_11);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  363|  1.00M|    FF(a, b, c, d, wBuf[R1B12], S1_0, T1_12);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  364|  1.00M|    FF(d, a, b, c, wBuf[R1B13], S1_1, T1_13);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  365|  1.00M|    FF(c, d, a, b, wBuf[R1B14], S1_2, T1_14);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  366|  1.00M|    FF(b, c, d, a, wBuf[R1B15], S1_3, T1_15);
  ------------------
  |  |  331|  1.00M|    a = b + cls(a + F(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  367|  1.00M|    GG(a, b, c, d, wBuf[R2B0], S2_0, T2_0);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  368|  1.00M|    GG(d, a, b, c, wBuf[R2B1], S2_1, T2_1);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  369|  1.00M|    GG(c, d, a, b, wBuf[R2B2], S2_2, T2_2);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  370|  1.00M|    GG(b, c, d, a, wBuf[R2B3], S2_3, T2_3);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  371|  1.00M|    GG(a, b, c, d, wBuf[R2B4], S2_0, T2_4);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  372|  1.00M|    GG(d, a, b, c, wBuf[R2B5], S2_1, T2_5);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  373|  1.00M|    GG(c, d, a, b, wBuf[R2B6], S2_2, T2_6);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  374|  1.00M|    GG(b, c, d, a, wBuf[R2B7], S2_3, T2_7);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  375|  1.00M|    GG(a, b, c, d, wBuf[R2B8], S2_0, T2_8);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  376|  1.00M|    GG(d, a, b, c, wBuf[R2B9], S2_1, T2_9);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  377|  1.00M|    GG(c, d, a, b, wBuf[R2B10], S2_2, T2_10);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  378|  1.00M|    GG(b, c, d, a, wBuf[R2B11], S2_3, T2_11);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  379|  1.00M|    GG(a, b, c, d, wBuf[R2B12], S2_0, T2_12);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  380|  1.00M|    GG(d, a, b, c, wBuf[R2B13], S2_1, T2_13);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  381|  1.00M|    GG(c, d, a, b, wBuf[R2B14], S2_2, T2_14);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  382|  1.00M|    GG(b, c, d, a, wBuf[R2B15], S2_3, T2_15);
  ------------------
  |  |  334|  1.00M|    a = b + cls(a + G(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  383|  1.00M|    HH(a, b, c, d, wBuf[R3B0], S3_0, T3_0);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  384|  1.00M|    HH(d, a, b, c, wBuf[R3B1], S3_1, T3_1);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  385|  1.00M|    HH(c, d, a, b, wBuf[R3B2], S3_2, T3_2);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  386|  1.00M|    HH(b, c, d, a, wBuf[R3B3], S3_3, T3_3);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  387|  1.00M|    HH(a, b, c, d, wBuf[R3B4], S3_0, T3_4);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  388|  1.00M|    HH(d, a, b, c, wBuf[R3B5], S3_1, T3_5);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  389|  1.00M|    HH(c, d, a, b, wBuf[R3B6], S3_2, T3_6);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  390|  1.00M|    HH(b, c, d, a, wBuf[R3B7], S3_3, T3_7);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  391|  1.00M|    HH(a, b, c, d, wBuf[R3B8], S3_0, T3_8);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  392|  1.00M|    HH(d, a, b, c, wBuf[R3B9], S3_1, T3_9);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  393|  1.00M|    HH(c, d, a, b, wBuf[R3B10], S3_2, T3_10);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  394|  1.00M|    HH(b, c, d, a, wBuf[R3B11], S3_3, T3_11);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  395|  1.00M|    HH(a, b, c, d, wBuf[R3B12], S3_0, T3_12);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  396|  1.00M|    HH(d, a, b, c, wBuf[R3B13], S3_1, T3_13);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  397|  1.00M|    HH(c, d, a, b, wBuf[R3B14], S3_2, T3_14);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  398|  1.00M|    HH(b, c, d, a, wBuf[R3B15], S3_3, T3_15);
  ------------------
  |  |  337|  1.00M|    a = b + cls(a + H(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  399|  1.00M|    II(a, b, c, d, wBuf[R4B0], S4_0, T4_0);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  400|  1.00M|    II(d, a, b, c, wBuf[R4B1], S4_1, T4_1);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  401|  1.00M|    II(c, d, a, b, wBuf[R4B2], S4_2, T4_2);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  402|  1.00M|    II(b, c, d, a, wBuf[R4B3], S4_3, T4_3);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  403|  1.00M|    II(a, b, c, d, wBuf[R4B4], S4_0, T4_4);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  404|  1.00M|    II(d, a, b, c, wBuf[R4B5], S4_1, T4_5);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  405|  1.00M|    II(c, d, a, b, wBuf[R4B6], S4_2, T4_6);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  406|  1.00M|    II(b, c, d, a, wBuf[R4B7], S4_3, T4_7);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  407|  1.00M|    II(a, b, c, d, wBuf[R4B8], S4_0, T4_8);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  408|  1.00M|    II(d, a, b, c, wBuf[R4B9], S4_1, T4_9);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  409|  1.00M|    II(c, d, a, b, wBuf[R4B10], S4_2, T4_10);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  410|  1.00M|    II(b, c, d, a, wBuf[R4B11], S4_3, T4_11);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  411|  1.00M|    II(a, b, c, d, wBuf[R4B12], S4_0, T4_12);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  412|  1.00M|    II(d, a, b, c, wBuf[R4B13], S4_1, T4_13);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  413|  1.00M|    II(c, d, a, b, wBuf[R4B14], S4_2, T4_14);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  414|  1.00M|    II(b, c, d, a, wBuf[R4B15], S4_3, T4_15);
  ------------------
  |  |  340|  1.00M|    a = b + cls(a + I(b, c, d) + bufint + ti, s)
  |  |  ------------------
  |  |  |  |  247|  1.00M|#define cls(i32, s) (tmp = i32, tmp << s | tmp >> (32 - s))
  |  |  ------------------
  ------------------
  415|  1.00M|    cx->cv[0] += a;
  416|  1.00M|    cx->cv[1] += b;
  417|  1.00M|    cx->cv[2] += c;
  418|  1.00M|    cx->cv[3] += d;
  419|  1.00M|}

s_mp_mul_comba_4:
  142|     49|{
  143|     49|    mp_digit c0, c1, c2, at[8];
  144|       |
  145|     49|    memcpy(at, A->dp, 4 * sizeof(mp_digit));
  146|     49|    memcpy(at + 4, B->dp, 4 * sizeof(mp_digit));
  147|     49|    COMBA_START;
  148|       |
  149|     49|    COMBA_CLEAR;
  ------------------
  |  |   37|     49|    c0 = c1 = c2 = 0;
  ------------------
  150|       |    /* 0 */
  151|     49|    MULADD(at[0], at[4]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  152|     49|    COMBA_STORE(C->dp[0]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  153|       |    /* 1 */
  154|     49|    COMBA_FORWARD;
  ------------------
  |  |   41|     49|    do {              \
  |  |   42|     49|        c0 = c1;      \
  |  |   43|     49|        c1 = c2;      \
  |  |   44|     49|        c2 = 0;       \
  |  |   45|     49|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  155|     49|    MULADD(at[0], at[5]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  156|     49|    MULADD(at[1], at[4]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  157|     49|    COMBA_STORE(C->dp[1]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  158|       |    /* 2 */
  159|     49|    COMBA_FORWARD;
  ------------------
  |  |   41|     49|    do {              \
  |  |   42|     49|        c0 = c1;      \
  |  |   43|     49|        c1 = c2;      \
  |  |   44|     49|        c2 = 0;       \
  |  |   45|     49|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  160|     49|    MULADD(at[0], at[6]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  161|     49|    MULADD(at[1], at[5]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  162|     49|    MULADD(at[2], at[4]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  163|     49|    COMBA_STORE(C->dp[2]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  164|       |    /* 3 */
  165|     49|    COMBA_FORWARD;
  ------------------
  |  |   41|     49|    do {              \
  |  |   42|     49|        c0 = c1;      \
  |  |   43|     49|        c1 = c2;      \
  |  |   44|     49|        c2 = 0;       \
  |  |   45|     49|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  166|     49|    MULADD(at[0], at[7]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  167|     49|    MULADD(at[1], at[6]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  168|     49|    MULADD(at[2], at[5]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  169|     49|    MULADD(at[3], at[4]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  170|     49|    COMBA_STORE(C->dp[3]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  171|       |    /* 4 */
  172|     49|    COMBA_FORWARD;
  ------------------
  |  |   41|     49|    do {              \
  |  |   42|     49|        c0 = c1;      \
  |  |   43|     49|        c1 = c2;      \
  |  |   44|     49|        c2 = 0;       \
  |  |   45|     49|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  173|     49|    MULADD(at[1], at[7]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  174|     49|    MULADD(at[2], at[6]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  175|     49|    MULADD(at[3], at[5]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  176|     49|    COMBA_STORE(C->dp[4]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  177|       |    /* 5 */
  178|     49|    COMBA_FORWARD;
  ------------------
  |  |   41|     49|    do {              \
  |  |   42|     49|        c0 = c1;      \
  |  |   43|     49|        c1 = c2;      \
  |  |   44|     49|        c2 = 0;       \
  |  |   45|     49|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  179|     49|    MULADD(at[2], at[7]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  180|     49|    MULADD(at[3], at[6]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  181|     49|    COMBA_STORE(C->dp[5]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  182|       |    /* 6 */
  183|     49|    COMBA_FORWARD;
  ------------------
  |  |   41|     49|    do {              \
  |  |   42|     49|        c0 = c1;      \
  |  |   43|     49|        c1 = c2;      \
  |  |   44|     49|        c2 = 0;       \
  |  |   45|     49|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  184|     49|    MULADD(at[3], at[7]);
  ------------------
  |  |   52|     49|    __asm__(                                        \
  |  |   53|     49|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     49|        "mulq  %7           \n\t"                   \
  |  |   55|     49|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     49|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     49|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     49|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     49|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     49|        : "%rax", "%rdx", "cc");
  ------------------
  185|     49|    COMBA_STORE(C->dp[6]);
  ------------------
  |  |   67|     49|    x = c0;
  ------------------
  186|     49|    COMBA_STORE2(C->dp[7]);
  ------------------
  |  |   70|     49|    x = c1;
  ------------------
  187|     49|    C->used = 8;
  188|     49|    C->sign = A->sign ^ B->sign;
  189|     49|    mp_clamp(C);
  ------------------
  |  |   26|     49|    {                                                    \
  |  |   27|     52|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 52, False: 0]
  |  |  |  Branch (27:29): [True: 3, False: 49]
  |  |  ------------------
  |  |   28|     49|            --((a)->used);                               \
  |  |   29|     49|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|     49|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 49, False: 0]
  |  |  ------------------
  |  |   30|     49|    }
  ------------------
  190|     49|    COMBA_FINI;
  191|     49|}
s_mp_mul_comba_8:
  195|     46|{
  196|     46|    mp_digit c0, c1, c2, at[16];
  197|       |
  198|     46|    memcpy(at, A->dp, 8 * sizeof(mp_digit));
  199|     46|    memcpy(at + 8, B->dp, 8 * sizeof(mp_digit));
  200|     46|    COMBA_START;
  201|       |
  202|     46|    COMBA_CLEAR;
  ------------------
  |  |   37|     46|    c0 = c1 = c2 = 0;
  ------------------
  203|       |    /* 0 */
  204|     46|    MULADD(at[0], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  205|     46|    COMBA_STORE(C->dp[0]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  206|       |    /* 1 */
  207|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  208|     46|    MULADD(at[0], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  209|     46|    MULADD(at[1], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  210|     46|    COMBA_STORE(C->dp[1]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  211|       |    /* 2 */
  212|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  213|     46|    MULADD(at[0], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  214|     46|    MULADD(at[1], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  215|     46|    MULADD(at[2], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  216|     46|    COMBA_STORE(C->dp[2]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  217|       |    /* 3 */
  218|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  219|     46|    MULADD(at[0], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  220|     46|    MULADD(at[1], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  221|     46|    MULADD(at[2], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  222|     46|    MULADD(at[3], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  223|     46|    COMBA_STORE(C->dp[3]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  224|       |    /* 4 */
  225|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  226|     46|    MULADD(at[0], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  227|     46|    MULADD(at[1], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  228|     46|    MULADD(at[2], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  229|     46|    MULADD(at[3], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  230|     46|    MULADD(at[4], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  231|     46|    COMBA_STORE(C->dp[4]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  232|       |    /* 5 */
  233|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  234|     46|    MULADD(at[0], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  235|     46|    MULADD(at[1], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  236|     46|    MULADD(at[2], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  237|     46|    MULADD(at[3], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  238|     46|    MULADD(at[4], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  239|     46|    MULADD(at[5], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  240|     46|    COMBA_STORE(C->dp[5]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  241|       |    /* 6 */
  242|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  243|     46|    MULADD(at[0], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  244|     46|    MULADD(at[1], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  245|     46|    MULADD(at[2], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  246|     46|    MULADD(at[3], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  247|     46|    MULADD(at[4], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  248|     46|    MULADD(at[5], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  249|     46|    MULADD(at[6], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  250|     46|    COMBA_STORE(C->dp[6]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  251|       |    /* 7 */
  252|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  253|     46|    MULADD(at[0], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  254|     46|    MULADD(at[1], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  255|     46|    MULADD(at[2], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  256|     46|    MULADD(at[3], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  257|     46|    MULADD(at[4], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  258|     46|    MULADD(at[5], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  259|     46|    MULADD(at[6], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  260|     46|    MULADD(at[7], at[8]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  261|     46|    COMBA_STORE(C->dp[7]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  262|       |    /* 8 */
  263|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  264|     46|    MULADD(at[1], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  265|     46|    MULADD(at[2], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  266|     46|    MULADD(at[3], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  267|     46|    MULADD(at[4], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  268|     46|    MULADD(at[5], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  269|     46|    MULADD(at[6], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  270|     46|    MULADD(at[7], at[9]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  271|     46|    COMBA_STORE(C->dp[8]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  272|       |    /* 9 */
  273|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  274|     46|    MULADD(at[2], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  275|     46|    MULADD(at[3], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  276|     46|    MULADD(at[4], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  277|     46|    MULADD(at[5], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  278|     46|    MULADD(at[6], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  279|     46|    MULADD(at[7], at[10]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  280|     46|    COMBA_STORE(C->dp[9]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  281|       |    /* 10 */
  282|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  283|     46|    MULADD(at[3], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  284|     46|    MULADD(at[4], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  285|     46|    MULADD(at[5], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  286|     46|    MULADD(at[6], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  287|     46|    MULADD(at[7], at[11]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  288|     46|    COMBA_STORE(C->dp[10]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  289|       |    /* 11 */
  290|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  291|     46|    MULADD(at[4], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  292|     46|    MULADD(at[5], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  293|     46|    MULADD(at[6], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  294|     46|    MULADD(at[7], at[12]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  295|     46|    COMBA_STORE(C->dp[11]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  296|       |    /* 12 */
  297|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  298|     46|    MULADD(at[5], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  299|     46|    MULADD(at[6], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  300|     46|    MULADD(at[7], at[13]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  301|     46|    COMBA_STORE(C->dp[12]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  302|       |    /* 13 */
  303|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  304|     46|    MULADD(at[6], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  305|     46|    MULADD(at[7], at[14]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  306|     46|    COMBA_STORE(C->dp[13]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  307|       |    /* 14 */
  308|     46|    COMBA_FORWARD;
  ------------------
  |  |   41|     46|    do {              \
  |  |   42|     46|        c0 = c1;      \
  |  |   43|     46|        c1 = c2;      \
  |  |   44|     46|        c2 = 0;       \
  |  |   45|     46|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  309|     46|    MULADD(at[7], at[15]);
  ------------------
  |  |   52|     46|    __asm__(                                        \
  |  |   53|     46|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|     46|        "mulq  %7           \n\t"                   \
  |  |   55|     46|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|     46|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|     46|        "adcq  $0,%2        \n\t"                   \
  |  |   58|     46|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|     46|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|     46|        : "%rax", "%rdx", "cc");
  ------------------
  310|     46|    COMBA_STORE(C->dp[14]);
  ------------------
  |  |   67|     46|    x = c0;
  ------------------
  311|     46|    COMBA_STORE2(C->dp[15]);
  ------------------
  |  |   70|     46|    x = c1;
  ------------------
  312|     46|    C->used = 16;
  313|     46|    C->sign = A->sign ^ B->sign;
  314|     46|    mp_clamp(C);
  ------------------
  |  |   26|     46|    {                                                    \
  |  |   27|     66|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 66, False: 0]
  |  |  |  Branch (27:29): [True: 20, False: 46]
  |  |  ------------------
  |  |   28|     46|            --((a)->used);                               \
  |  |   29|     46|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|     46|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 46, False: 0]
  |  |  ------------------
  |  |   30|     46|    }
  ------------------
  315|     46|    COMBA_FINI;
  316|     46|}
s_mp_mul_comba_16:
  320|   135k|{
  321|   135k|    mp_digit c0, c1, c2, at[32];
  322|       |
  323|   135k|    memcpy(at, A->dp, 16 * sizeof(mp_digit));
  324|   135k|    memcpy(at + 16, B->dp, 16 * sizeof(mp_digit));
  325|   135k|    COMBA_START;
  326|       |
  327|   135k|    COMBA_CLEAR;
  ------------------
  |  |   37|   135k|    c0 = c1 = c2 = 0;
  ------------------
  328|       |    /* 0 */
  329|   135k|    MULADD(at[0], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  330|   135k|    COMBA_STORE(C->dp[0]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  331|       |    /* 1 */
  332|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  333|   135k|    MULADD(at[0], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  334|   135k|    MULADD(at[1], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  335|   135k|    COMBA_STORE(C->dp[1]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  336|       |    /* 2 */
  337|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  338|   135k|    MULADD(at[0], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  339|   135k|    MULADD(at[1], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  340|   135k|    MULADD(at[2], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  341|   135k|    COMBA_STORE(C->dp[2]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  342|       |    /* 3 */
  343|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  344|   135k|    MULADD(at[0], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  345|   135k|    MULADD(at[1], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  346|   135k|    MULADD(at[2], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  347|   135k|    MULADD(at[3], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  348|   135k|    COMBA_STORE(C->dp[3]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  349|       |    /* 4 */
  350|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  351|   135k|    MULADD(at[0], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  352|   135k|    MULADD(at[1], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  353|   135k|    MULADD(at[2], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  354|   135k|    MULADD(at[3], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  355|   135k|    MULADD(at[4], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  356|   135k|    COMBA_STORE(C->dp[4]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  357|       |    /* 5 */
  358|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  359|   135k|    MULADD(at[0], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  360|   135k|    MULADD(at[1], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  361|   135k|    MULADD(at[2], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  362|   135k|    MULADD(at[3], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  363|   135k|    MULADD(at[4], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  364|   135k|    MULADD(at[5], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  365|   135k|    COMBA_STORE(C->dp[5]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  366|       |    /* 6 */
  367|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  368|   135k|    MULADD(at[0], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  369|   135k|    MULADD(at[1], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  370|   135k|    MULADD(at[2], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  371|   135k|    MULADD(at[3], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  372|   135k|    MULADD(at[4], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  373|   135k|    MULADD(at[5], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  374|   135k|    MULADD(at[6], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  375|   135k|    COMBA_STORE(C->dp[6]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  376|       |    /* 7 */
  377|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  378|   135k|    MULADD(at[0], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  379|   135k|    MULADD(at[1], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  380|   135k|    MULADD(at[2], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  381|   135k|    MULADD(at[3], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  382|   135k|    MULADD(at[4], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  383|   135k|    MULADD(at[5], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  384|   135k|    MULADD(at[6], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  385|   135k|    MULADD(at[7], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  386|   135k|    COMBA_STORE(C->dp[7]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  387|       |    /* 8 */
  388|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  389|   135k|    MULADD(at[0], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  390|   135k|    MULADD(at[1], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  391|   135k|    MULADD(at[2], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  392|   135k|    MULADD(at[3], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  393|   135k|    MULADD(at[4], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  394|   135k|    MULADD(at[5], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  395|   135k|    MULADD(at[6], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  396|   135k|    MULADD(at[7], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  397|   135k|    MULADD(at[8], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  398|   135k|    COMBA_STORE(C->dp[8]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  399|       |    /* 9 */
  400|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  401|   135k|    MULADD(at[0], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  402|   135k|    MULADD(at[1], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  403|   135k|    MULADD(at[2], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  404|   135k|    MULADD(at[3], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  405|   135k|    MULADD(at[4], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  406|   135k|    MULADD(at[5], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  407|   135k|    MULADD(at[6], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  408|   135k|    MULADD(at[7], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  409|   135k|    MULADD(at[8], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  410|   135k|    MULADD(at[9], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  411|   135k|    COMBA_STORE(C->dp[9]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  412|       |    /* 10 */
  413|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  414|   135k|    MULADD(at[0], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  415|   135k|    MULADD(at[1], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  416|   135k|    MULADD(at[2], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  417|   135k|    MULADD(at[3], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  418|   135k|    MULADD(at[4], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  419|   135k|    MULADD(at[5], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  420|   135k|    MULADD(at[6], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  421|   135k|    MULADD(at[7], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  422|   135k|    MULADD(at[8], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  423|   135k|    MULADD(at[9], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  424|   135k|    MULADD(at[10], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  425|   135k|    COMBA_STORE(C->dp[10]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  426|       |    /* 11 */
  427|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  428|   135k|    MULADD(at[0], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  429|   135k|    MULADD(at[1], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  430|   135k|    MULADD(at[2], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  431|   135k|    MULADD(at[3], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  432|   135k|    MULADD(at[4], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  433|   135k|    MULADD(at[5], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  434|   135k|    MULADD(at[6], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  435|   135k|    MULADD(at[7], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  436|   135k|    MULADD(at[8], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  437|   135k|    MULADD(at[9], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  438|   135k|    MULADD(at[10], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  439|   135k|    MULADD(at[11], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  440|   135k|    COMBA_STORE(C->dp[11]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  441|       |    /* 12 */
  442|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  443|   135k|    MULADD(at[0], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  444|   135k|    MULADD(at[1], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  445|   135k|    MULADD(at[2], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  446|   135k|    MULADD(at[3], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  447|   135k|    MULADD(at[4], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  448|   135k|    MULADD(at[5], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  449|   135k|    MULADD(at[6], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  450|   135k|    MULADD(at[7], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  451|   135k|    MULADD(at[8], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  452|   135k|    MULADD(at[9], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  453|   135k|    MULADD(at[10], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  454|   135k|    MULADD(at[11], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  455|   135k|    MULADD(at[12], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  456|   135k|    COMBA_STORE(C->dp[12]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  457|       |    /* 13 */
  458|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  459|   135k|    MULADD(at[0], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  460|   135k|    MULADD(at[1], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  461|   135k|    MULADD(at[2], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  462|   135k|    MULADD(at[3], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  463|   135k|    MULADD(at[4], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  464|   135k|    MULADD(at[5], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  465|   135k|    MULADD(at[6], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  466|   135k|    MULADD(at[7], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  467|   135k|    MULADD(at[8], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  468|   135k|    MULADD(at[9], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  469|   135k|    MULADD(at[10], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  470|   135k|    MULADD(at[11], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  471|   135k|    MULADD(at[12], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  472|   135k|    MULADD(at[13], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  473|   135k|    COMBA_STORE(C->dp[13]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  474|       |    /* 14 */
  475|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  476|   135k|    MULADD(at[0], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  477|   135k|    MULADD(at[1], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  478|   135k|    MULADD(at[2], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  479|   135k|    MULADD(at[3], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  480|   135k|    MULADD(at[4], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  481|   135k|    MULADD(at[5], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  482|   135k|    MULADD(at[6], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  483|   135k|    MULADD(at[7], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  484|   135k|    MULADD(at[8], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  485|   135k|    MULADD(at[9], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  486|   135k|    MULADD(at[10], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  487|   135k|    MULADD(at[11], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  488|   135k|    MULADD(at[12], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  489|   135k|    MULADD(at[13], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  490|   135k|    MULADD(at[14], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  491|   135k|    COMBA_STORE(C->dp[14]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  492|       |    /* 15 */
  493|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  494|   135k|    MULADD(at[0], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  495|   135k|    MULADD(at[1], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  496|   135k|    MULADD(at[2], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  497|   135k|    MULADD(at[3], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  498|   135k|    MULADD(at[4], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  499|   135k|    MULADD(at[5], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  500|   135k|    MULADD(at[6], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  501|   135k|    MULADD(at[7], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  502|   135k|    MULADD(at[8], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  503|   135k|    MULADD(at[9], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  504|   135k|    MULADD(at[10], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  505|   135k|    MULADD(at[11], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  506|   135k|    MULADD(at[12], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  507|   135k|    MULADD(at[13], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  508|   135k|    MULADD(at[14], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  509|   135k|    MULADD(at[15], at[16]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  510|   135k|    COMBA_STORE(C->dp[15]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  511|       |    /* 16 */
  512|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  513|   135k|    MULADD(at[1], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  514|   135k|    MULADD(at[2], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  515|   135k|    MULADD(at[3], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  516|   135k|    MULADD(at[4], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  517|   135k|    MULADD(at[5], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  518|   135k|    MULADD(at[6], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  519|   135k|    MULADD(at[7], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  520|   135k|    MULADD(at[8], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  521|   135k|    MULADD(at[9], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  522|   135k|    MULADD(at[10], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  523|   135k|    MULADD(at[11], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  524|   135k|    MULADD(at[12], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  525|   135k|    MULADD(at[13], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  526|   135k|    MULADD(at[14], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  527|   135k|    MULADD(at[15], at[17]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  528|   135k|    COMBA_STORE(C->dp[16]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  529|       |    /* 17 */
  530|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  531|   135k|    MULADD(at[2], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  532|   135k|    MULADD(at[3], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  533|   135k|    MULADD(at[4], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  534|   135k|    MULADD(at[5], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  535|   135k|    MULADD(at[6], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  536|   135k|    MULADD(at[7], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  537|   135k|    MULADD(at[8], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  538|   135k|    MULADD(at[9], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  539|   135k|    MULADD(at[10], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  540|   135k|    MULADD(at[11], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  541|   135k|    MULADD(at[12], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  542|   135k|    MULADD(at[13], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  543|   135k|    MULADD(at[14], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  544|   135k|    MULADD(at[15], at[18]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  545|   135k|    COMBA_STORE(C->dp[17]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  546|       |    /* 18 */
  547|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  548|   135k|    MULADD(at[3], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  549|   135k|    MULADD(at[4], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  550|   135k|    MULADD(at[5], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  551|   135k|    MULADD(at[6], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  552|   135k|    MULADD(at[7], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  553|   135k|    MULADD(at[8], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  554|   135k|    MULADD(at[9], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  555|   135k|    MULADD(at[10], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  556|   135k|    MULADD(at[11], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  557|   135k|    MULADD(at[12], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  558|   135k|    MULADD(at[13], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  559|   135k|    MULADD(at[14], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  560|   135k|    MULADD(at[15], at[19]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  561|   135k|    COMBA_STORE(C->dp[18]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  562|       |    /* 19 */
  563|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  564|   135k|    MULADD(at[4], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  565|   135k|    MULADD(at[5], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  566|   135k|    MULADD(at[6], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  567|   135k|    MULADD(at[7], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  568|   135k|    MULADD(at[8], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  569|   135k|    MULADD(at[9], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  570|   135k|    MULADD(at[10], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  571|   135k|    MULADD(at[11], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  572|   135k|    MULADD(at[12], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  573|   135k|    MULADD(at[13], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  574|   135k|    MULADD(at[14], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  575|   135k|    MULADD(at[15], at[20]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  576|   135k|    COMBA_STORE(C->dp[19]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  577|       |    /* 20 */
  578|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  579|   135k|    MULADD(at[5], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  580|   135k|    MULADD(at[6], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  581|   135k|    MULADD(at[7], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  582|   135k|    MULADD(at[8], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  583|   135k|    MULADD(at[9], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  584|   135k|    MULADD(at[10], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  585|   135k|    MULADD(at[11], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  586|   135k|    MULADD(at[12], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  587|   135k|    MULADD(at[13], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  588|   135k|    MULADD(at[14], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  589|   135k|    MULADD(at[15], at[21]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  590|   135k|    COMBA_STORE(C->dp[20]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  591|       |    /* 21 */
  592|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  593|   135k|    MULADD(at[6], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  594|   135k|    MULADD(at[7], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  595|   135k|    MULADD(at[8], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  596|   135k|    MULADD(at[9], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  597|   135k|    MULADD(at[10], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  598|   135k|    MULADD(at[11], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  599|   135k|    MULADD(at[12], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  600|   135k|    MULADD(at[13], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  601|   135k|    MULADD(at[14], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  602|   135k|    MULADD(at[15], at[22]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  603|   135k|    COMBA_STORE(C->dp[21]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  604|       |    /* 22 */
  605|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  606|   135k|    MULADD(at[7], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  607|   135k|    MULADD(at[8], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  608|   135k|    MULADD(at[9], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  609|   135k|    MULADD(at[10], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  610|   135k|    MULADD(at[11], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  611|   135k|    MULADD(at[12], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  612|   135k|    MULADD(at[13], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  613|   135k|    MULADD(at[14], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  614|   135k|    MULADD(at[15], at[23]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  615|   135k|    COMBA_STORE(C->dp[22]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  616|       |    /* 23 */
  617|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  618|   135k|    MULADD(at[8], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  619|   135k|    MULADD(at[9], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  620|   135k|    MULADD(at[10], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  621|   135k|    MULADD(at[11], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  622|   135k|    MULADD(at[12], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  623|   135k|    MULADD(at[13], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  624|   135k|    MULADD(at[14], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  625|   135k|    MULADD(at[15], at[24]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  626|   135k|    COMBA_STORE(C->dp[23]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  627|       |    /* 24 */
  628|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  629|   135k|    MULADD(at[9], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  630|   135k|    MULADD(at[10], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  631|   135k|    MULADD(at[11], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  632|   135k|    MULADD(at[12], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  633|   135k|    MULADD(at[13], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  634|   135k|    MULADD(at[14], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  635|   135k|    MULADD(at[15], at[25]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  636|   135k|    COMBA_STORE(C->dp[24]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  637|       |    /* 25 */
  638|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  639|   135k|    MULADD(at[10], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  640|   135k|    MULADD(at[11], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  641|   135k|    MULADD(at[12], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  642|   135k|    MULADD(at[13], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  643|   135k|    MULADD(at[14], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  644|   135k|    MULADD(at[15], at[26]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  645|   135k|    COMBA_STORE(C->dp[25]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  646|       |    /* 26 */
  647|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  648|   135k|    MULADD(at[11], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  649|   135k|    MULADD(at[12], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  650|   135k|    MULADD(at[13], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  651|   135k|    MULADD(at[14], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  652|   135k|    MULADD(at[15], at[27]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  653|   135k|    COMBA_STORE(C->dp[26]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  654|       |    /* 27 */
  655|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  656|   135k|    MULADD(at[12], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  657|   135k|    MULADD(at[13], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  658|   135k|    MULADD(at[14], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  659|   135k|    MULADD(at[15], at[28]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  660|   135k|    COMBA_STORE(C->dp[27]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  661|       |    /* 28 */
  662|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  663|   135k|    MULADD(at[13], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  664|   135k|    MULADD(at[14], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  665|   135k|    MULADD(at[15], at[29]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  666|   135k|    COMBA_STORE(C->dp[28]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  667|       |    /* 29 */
  668|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  669|   135k|    MULADD(at[14], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  670|   135k|    MULADD(at[15], at[30]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  671|   135k|    COMBA_STORE(C->dp[29]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  672|       |    /* 30 */
  673|   135k|    COMBA_FORWARD;
  ------------------
  |  |   41|   135k|    do {              \
  |  |   42|   135k|        c0 = c1;      \
  |  |   43|   135k|        c1 = c2;      \
  |  |   44|   135k|        c2 = 0;       \
  |  |   45|   135k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  674|   135k|    MULADD(at[15], at[31]);
  ------------------
  |  |   52|   135k|    __asm__(                                        \
  |  |   53|   135k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|   135k|        "mulq  %7           \n\t"                   \
  |  |   55|   135k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|   135k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|   135k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|   135k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|   135k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|   135k|        : "%rax", "%rdx", "cc");
  ------------------
  675|   135k|    COMBA_STORE(C->dp[30]);
  ------------------
  |  |   67|   135k|    x = c0;
  ------------------
  676|   135k|    COMBA_STORE2(C->dp[31]);
  ------------------
  |  |   70|   135k|    x = c1;
  ------------------
  677|   135k|    C->used = 32;
  678|   135k|    C->sign = A->sign ^ B->sign;
  679|   135k|    mp_clamp(C);
  ------------------
  |  |   26|   135k|    {                                                    \
  |  |   27|   135k|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 135k, False: 0]
  |  |  |  Branch (27:29): [True: 55, False: 135k]
  |  |  ------------------
  |  |   28|   135k|            --((a)->used);                               \
  |  |   29|   135k|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|   135k|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 135k, False: 0]
  |  |  ------------------
  |  |   30|   135k|    }
  ------------------
  680|   135k|    COMBA_FINI;
  681|   135k|}
s_mp_mul_comba_32:
  685|  36.2k|{
  686|  36.2k|    mp_digit c0, c1, c2, at[64];
  687|       |
  688|  36.2k|    memcpy(at, A->dp, 32 * sizeof(mp_digit));
  689|  36.2k|    memcpy(at + 32, B->dp, 32 * sizeof(mp_digit));
  690|  36.2k|    COMBA_START;
  691|       |
  692|  36.2k|    COMBA_CLEAR;
  ------------------
  |  |   37|  36.2k|    c0 = c1 = c2 = 0;
  ------------------
  693|       |    /* 0 */
  694|  36.2k|    MULADD(at[0], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  695|  36.2k|    COMBA_STORE(C->dp[0]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  696|       |    /* 1 */
  697|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  698|  36.2k|    MULADD(at[0], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  699|  36.2k|    MULADD(at[1], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  700|  36.2k|    COMBA_STORE(C->dp[1]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  701|       |    /* 2 */
  702|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  703|  36.2k|    MULADD(at[0], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  704|  36.2k|    MULADD(at[1], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  705|  36.2k|    MULADD(at[2], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  706|  36.2k|    COMBA_STORE(C->dp[2]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  707|       |    /* 3 */
  708|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  709|  36.2k|    MULADD(at[0], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  710|  36.2k|    MULADD(at[1], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  711|  36.2k|    MULADD(at[2], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  712|  36.2k|    MULADD(at[3], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  713|  36.2k|    COMBA_STORE(C->dp[3]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  714|       |    /* 4 */
  715|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  716|  36.2k|    MULADD(at[0], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  717|  36.2k|    MULADD(at[1], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  718|  36.2k|    MULADD(at[2], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  719|  36.2k|    MULADD(at[3], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  720|  36.2k|    MULADD(at[4], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  721|  36.2k|    COMBA_STORE(C->dp[4]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  722|       |    /* 5 */
  723|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  724|  36.2k|    MULADD(at[0], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  725|  36.2k|    MULADD(at[1], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  726|  36.2k|    MULADD(at[2], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  727|  36.2k|    MULADD(at[3], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  728|  36.2k|    MULADD(at[4], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  729|  36.2k|    MULADD(at[5], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  730|  36.2k|    COMBA_STORE(C->dp[5]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  731|       |    /* 6 */
  732|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  733|  36.2k|    MULADD(at[0], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  734|  36.2k|    MULADD(at[1], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  735|  36.2k|    MULADD(at[2], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  736|  36.2k|    MULADD(at[3], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  737|  36.2k|    MULADD(at[4], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  738|  36.2k|    MULADD(at[5], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  739|  36.2k|    MULADD(at[6], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  740|  36.2k|    COMBA_STORE(C->dp[6]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  741|       |    /* 7 */
  742|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  743|  36.2k|    MULADD(at[0], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  744|  36.2k|    MULADD(at[1], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  745|  36.2k|    MULADD(at[2], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  746|  36.2k|    MULADD(at[3], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  747|  36.2k|    MULADD(at[4], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  748|  36.2k|    MULADD(at[5], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  749|  36.2k|    MULADD(at[6], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  750|  36.2k|    MULADD(at[7], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  751|  36.2k|    COMBA_STORE(C->dp[7]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  752|       |    /* 8 */
  753|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  754|  36.2k|    MULADD(at[0], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  755|  36.2k|    MULADD(at[1], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  756|  36.2k|    MULADD(at[2], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  757|  36.2k|    MULADD(at[3], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  758|  36.2k|    MULADD(at[4], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  759|  36.2k|    MULADD(at[5], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  760|  36.2k|    MULADD(at[6], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  761|  36.2k|    MULADD(at[7], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  762|  36.2k|    MULADD(at[8], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  763|  36.2k|    COMBA_STORE(C->dp[8]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  764|       |    /* 9 */
  765|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  766|  36.2k|    MULADD(at[0], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  767|  36.2k|    MULADD(at[1], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  768|  36.2k|    MULADD(at[2], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  769|  36.2k|    MULADD(at[3], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  770|  36.2k|    MULADD(at[4], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  771|  36.2k|    MULADD(at[5], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  772|  36.2k|    MULADD(at[6], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  773|  36.2k|    MULADD(at[7], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  774|  36.2k|    MULADD(at[8], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  775|  36.2k|    MULADD(at[9], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  776|  36.2k|    COMBA_STORE(C->dp[9]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  777|       |    /* 10 */
  778|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  779|  36.2k|    MULADD(at[0], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  780|  36.2k|    MULADD(at[1], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  781|  36.2k|    MULADD(at[2], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  782|  36.2k|    MULADD(at[3], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  783|  36.2k|    MULADD(at[4], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  784|  36.2k|    MULADD(at[5], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  785|  36.2k|    MULADD(at[6], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  786|  36.2k|    MULADD(at[7], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  787|  36.2k|    MULADD(at[8], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  788|  36.2k|    MULADD(at[9], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  789|  36.2k|    MULADD(at[10], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  790|  36.2k|    COMBA_STORE(C->dp[10]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  791|       |    /* 11 */
  792|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  793|  36.2k|    MULADD(at[0], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  794|  36.2k|    MULADD(at[1], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  795|  36.2k|    MULADD(at[2], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  796|  36.2k|    MULADD(at[3], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  797|  36.2k|    MULADD(at[4], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  798|  36.2k|    MULADD(at[5], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  799|  36.2k|    MULADD(at[6], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  800|  36.2k|    MULADD(at[7], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  801|  36.2k|    MULADD(at[8], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  802|  36.2k|    MULADD(at[9], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  803|  36.2k|    MULADD(at[10], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  804|  36.2k|    MULADD(at[11], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  805|  36.2k|    COMBA_STORE(C->dp[11]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  806|       |    /* 12 */
  807|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  808|  36.2k|    MULADD(at[0], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  809|  36.2k|    MULADD(at[1], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  810|  36.2k|    MULADD(at[2], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  811|  36.2k|    MULADD(at[3], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  812|  36.2k|    MULADD(at[4], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  813|  36.2k|    MULADD(at[5], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  814|  36.2k|    MULADD(at[6], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  815|  36.2k|    MULADD(at[7], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  816|  36.2k|    MULADD(at[8], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  817|  36.2k|    MULADD(at[9], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  818|  36.2k|    MULADD(at[10], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  819|  36.2k|    MULADD(at[11], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  820|  36.2k|    MULADD(at[12], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  821|  36.2k|    COMBA_STORE(C->dp[12]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  822|       |    /* 13 */
  823|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  824|  36.2k|    MULADD(at[0], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  825|  36.2k|    MULADD(at[1], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  826|  36.2k|    MULADD(at[2], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  827|  36.2k|    MULADD(at[3], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  828|  36.2k|    MULADD(at[4], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  829|  36.2k|    MULADD(at[5], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  830|  36.2k|    MULADD(at[6], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  831|  36.2k|    MULADD(at[7], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  832|  36.2k|    MULADD(at[8], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  833|  36.2k|    MULADD(at[9], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  834|  36.2k|    MULADD(at[10], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  835|  36.2k|    MULADD(at[11], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  836|  36.2k|    MULADD(at[12], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  837|  36.2k|    MULADD(at[13], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  838|  36.2k|    COMBA_STORE(C->dp[13]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  839|       |    /* 14 */
  840|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  841|  36.2k|    MULADD(at[0], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  842|  36.2k|    MULADD(at[1], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  843|  36.2k|    MULADD(at[2], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  844|  36.2k|    MULADD(at[3], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  845|  36.2k|    MULADD(at[4], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  846|  36.2k|    MULADD(at[5], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  847|  36.2k|    MULADD(at[6], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  848|  36.2k|    MULADD(at[7], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  849|  36.2k|    MULADD(at[8], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  850|  36.2k|    MULADD(at[9], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  851|  36.2k|    MULADD(at[10], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  852|  36.2k|    MULADD(at[11], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  853|  36.2k|    MULADD(at[12], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  854|  36.2k|    MULADD(at[13], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  855|  36.2k|    MULADD(at[14], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  856|  36.2k|    COMBA_STORE(C->dp[14]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  857|       |    /* 15 */
  858|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  859|  36.2k|    MULADD(at[0], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  860|  36.2k|    MULADD(at[1], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  861|  36.2k|    MULADD(at[2], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  862|  36.2k|    MULADD(at[3], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  863|  36.2k|    MULADD(at[4], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  864|  36.2k|    MULADD(at[5], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  865|  36.2k|    MULADD(at[6], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  866|  36.2k|    MULADD(at[7], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  867|  36.2k|    MULADD(at[8], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  868|  36.2k|    MULADD(at[9], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  869|  36.2k|    MULADD(at[10], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  870|  36.2k|    MULADD(at[11], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  871|  36.2k|    MULADD(at[12], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  872|  36.2k|    MULADD(at[13], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  873|  36.2k|    MULADD(at[14], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  874|  36.2k|    MULADD(at[15], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  875|  36.2k|    COMBA_STORE(C->dp[15]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  876|       |    /* 16 */
  877|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  878|  36.2k|    MULADD(at[0], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  879|  36.2k|    MULADD(at[1], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  880|  36.2k|    MULADD(at[2], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  881|  36.2k|    MULADD(at[3], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  882|  36.2k|    MULADD(at[4], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  883|  36.2k|    MULADD(at[5], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  884|  36.2k|    MULADD(at[6], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  885|  36.2k|    MULADD(at[7], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  886|  36.2k|    MULADD(at[8], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  887|  36.2k|    MULADD(at[9], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  888|  36.2k|    MULADD(at[10], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  889|  36.2k|    MULADD(at[11], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  890|  36.2k|    MULADD(at[12], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  891|  36.2k|    MULADD(at[13], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  892|  36.2k|    MULADD(at[14], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  893|  36.2k|    MULADD(at[15], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  894|  36.2k|    MULADD(at[16], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  895|  36.2k|    COMBA_STORE(C->dp[16]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  896|       |    /* 17 */
  897|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  898|  36.2k|    MULADD(at[0], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  899|  36.2k|    MULADD(at[1], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  900|  36.2k|    MULADD(at[2], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  901|  36.2k|    MULADD(at[3], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  902|  36.2k|    MULADD(at[4], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  903|  36.2k|    MULADD(at[5], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  904|  36.2k|    MULADD(at[6], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  905|  36.2k|    MULADD(at[7], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  906|  36.2k|    MULADD(at[8], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  907|  36.2k|    MULADD(at[9], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  908|  36.2k|    MULADD(at[10], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  909|  36.2k|    MULADD(at[11], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  910|  36.2k|    MULADD(at[12], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  911|  36.2k|    MULADD(at[13], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  912|  36.2k|    MULADD(at[14], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  913|  36.2k|    MULADD(at[15], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  914|  36.2k|    MULADD(at[16], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  915|  36.2k|    MULADD(at[17], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  916|  36.2k|    COMBA_STORE(C->dp[17]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  917|       |    /* 18 */
  918|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  919|  36.2k|    MULADD(at[0], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  920|  36.2k|    MULADD(at[1], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  921|  36.2k|    MULADD(at[2], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  922|  36.2k|    MULADD(at[3], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  923|  36.2k|    MULADD(at[4], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  924|  36.2k|    MULADD(at[5], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  925|  36.2k|    MULADD(at[6], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  926|  36.2k|    MULADD(at[7], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  927|  36.2k|    MULADD(at[8], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  928|  36.2k|    MULADD(at[9], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  929|  36.2k|    MULADD(at[10], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  930|  36.2k|    MULADD(at[11], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  931|  36.2k|    MULADD(at[12], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  932|  36.2k|    MULADD(at[13], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  933|  36.2k|    MULADD(at[14], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  934|  36.2k|    MULADD(at[15], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  935|  36.2k|    MULADD(at[16], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  936|  36.2k|    MULADD(at[17], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  937|  36.2k|    MULADD(at[18], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  938|  36.2k|    COMBA_STORE(C->dp[18]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  939|       |    /* 19 */
  940|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  941|  36.2k|    MULADD(at[0], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  942|  36.2k|    MULADD(at[1], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  943|  36.2k|    MULADD(at[2], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  944|  36.2k|    MULADD(at[3], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  945|  36.2k|    MULADD(at[4], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  946|  36.2k|    MULADD(at[5], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  947|  36.2k|    MULADD(at[6], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  948|  36.2k|    MULADD(at[7], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  949|  36.2k|    MULADD(at[8], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  950|  36.2k|    MULADD(at[9], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  951|  36.2k|    MULADD(at[10], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  952|  36.2k|    MULADD(at[11], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  953|  36.2k|    MULADD(at[12], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  954|  36.2k|    MULADD(at[13], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  955|  36.2k|    MULADD(at[14], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  956|  36.2k|    MULADD(at[15], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  957|  36.2k|    MULADD(at[16], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  958|  36.2k|    MULADD(at[17], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  959|  36.2k|    MULADD(at[18], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  960|  36.2k|    MULADD(at[19], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  961|  36.2k|    COMBA_STORE(C->dp[19]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  962|       |    /* 20 */
  963|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  964|  36.2k|    MULADD(at[0], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  965|  36.2k|    MULADD(at[1], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  966|  36.2k|    MULADD(at[2], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  967|  36.2k|    MULADD(at[3], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  968|  36.2k|    MULADD(at[4], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  969|  36.2k|    MULADD(at[5], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  970|  36.2k|    MULADD(at[6], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  971|  36.2k|    MULADD(at[7], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  972|  36.2k|    MULADD(at[8], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  973|  36.2k|    MULADD(at[9], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  974|  36.2k|    MULADD(at[10], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  975|  36.2k|    MULADD(at[11], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  976|  36.2k|    MULADD(at[12], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  977|  36.2k|    MULADD(at[13], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  978|  36.2k|    MULADD(at[14], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  979|  36.2k|    MULADD(at[15], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  980|  36.2k|    MULADD(at[16], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  981|  36.2k|    MULADD(at[17], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  982|  36.2k|    MULADD(at[18], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  983|  36.2k|    MULADD(at[19], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  984|  36.2k|    MULADD(at[20], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  985|  36.2k|    COMBA_STORE(C->dp[20]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
  986|       |    /* 21 */
  987|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  988|  36.2k|    MULADD(at[0], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  989|  36.2k|    MULADD(at[1], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  990|  36.2k|    MULADD(at[2], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  991|  36.2k|    MULADD(at[3], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  992|  36.2k|    MULADD(at[4], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  993|  36.2k|    MULADD(at[5], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  994|  36.2k|    MULADD(at[6], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  995|  36.2k|    MULADD(at[7], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  996|  36.2k|    MULADD(at[8], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  997|  36.2k|    MULADD(at[9], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  998|  36.2k|    MULADD(at[10], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
  999|  36.2k|    MULADD(at[11], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1000|  36.2k|    MULADD(at[12], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1001|  36.2k|    MULADD(at[13], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1002|  36.2k|    MULADD(at[14], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1003|  36.2k|    MULADD(at[15], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1004|  36.2k|    MULADD(at[16], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1005|  36.2k|    MULADD(at[17], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1006|  36.2k|    MULADD(at[18], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1007|  36.2k|    MULADD(at[19], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1008|  36.2k|    MULADD(at[20], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1009|  36.2k|    MULADD(at[21], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1010|  36.2k|    COMBA_STORE(C->dp[21]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1011|       |    /* 22 */
 1012|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1013|  36.2k|    MULADD(at[0], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1014|  36.2k|    MULADD(at[1], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1015|  36.2k|    MULADD(at[2], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1016|  36.2k|    MULADD(at[3], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1017|  36.2k|    MULADD(at[4], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1018|  36.2k|    MULADD(at[5], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1019|  36.2k|    MULADD(at[6], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1020|  36.2k|    MULADD(at[7], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1021|  36.2k|    MULADD(at[8], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1022|  36.2k|    MULADD(at[9], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1023|  36.2k|    MULADD(at[10], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1024|  36.2k|    MULADD(at[11], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1025|  36.2k|    MULADD(at[12], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1026|  36.2k|    MULADD(at[13], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1027|  36.2k|    MULADD(at[14], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1028|  36.2k|    MULADD(at[15], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1029|  36.2k|    MULADD(at[16], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1030|  36.2k|    MULADD(at[17], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1031|  36.2k|    MULADD(at[18], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1032|  36.2k|    MULADD(at[19], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1033|  36.2k|    MULADD(at[20], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1034|  36.2k|    MULADD(at[21], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1035|  36.2k|    MULADD(at[22], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1036|  36.2k|    COMBA_STORE(C->dp[22]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1037|       |    /* 23 */
 1038|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1039|  36.2k|    MULADD(at[0], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1040|  36.2k|    MULADD(at[1], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1041|  36.2k|    MULADD(at[2], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1042|  36.2k|    MULADD(at[3], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1043|  36.2k|    MULADD(at[4], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1044|  36.2k|    MULADD(at[5], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1045|  36.2k|    MULADD(at[6], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1046|  36.2k|    MULADD(at[7], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1047|  36.2k|    MULADD(at[8], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1048|  36.2k|    MULADD(at[9], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1049|  36.2k|    MULADD(at[10], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1050|  36.2k|    MULADD(at[11], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1051|  36.2k|    MULADD(at[12], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1052|  36.2k|    MULADD(at[13], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1053|  36.2k|    MULADD(at[14], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1054|  36.2k|    MULADD(at[15], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1055|  36.2k|    MULADD(at[16], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1056|  36.2k|    MULADD(at[17], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1057|  36.2k|    MULADD(at[18], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1058|  36.2k|    MULADD(at[19], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1059|  36.2k|    MULADD(at[20], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1060|  36.2k|    MULADD(at[21], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1061|  36.2k|    MULADD(at[22], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1062|  36.2k|    MULADD(at[23], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1063|  36.2k|    COMBA_STORE(C->dp[23]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1064|       |    /* 24 */
 1065|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1066|  36.2k|    MULADD(at[0], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1067|  36.2k|    MULADD(at[1], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1068|  36.2k|    MULADD(at[2], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1069|  36.2k|    MULADD(at[3], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1070|  36.2k|    MULADD(at[4], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1071|  36.2k|    MULADD(at[5], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1072|  36.2k|    MULADD(at[6], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1073|  36.2k|    MULADD(at[7], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1074|  36.2k|    MULADD(at[8], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1075|  36.2k|    MULADD(at[9], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1076|  36.2k|    MULADD(at[10], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1077|  36.2k|    MULADD(at[11], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1078|  36.2k|    MULADD(at[12], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1079|  36.2k|    MULADD(at[13], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1080|  36.2k|    MULADD(at[14], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1081|  36.2k|    MULADD(at[15], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1082|  36.2k|    MULADD(at[16], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1083|  36.2k|    MULADD(at[17], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1084|  36.2k|    MULADD(at[18], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1085|  36.2k|    MULADD(at[19], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1086|  36.2k|    MULADD(at[20], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1087|  36.2k|    MULADD(at[21], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1088|  36.2k|    MULADD(at[22], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1089|  36.2k|    MULADD(at[23], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1090|  36.2k|    MULADD(at[24], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1091|  36.2k|    COMBA_STORE(C->dp[24]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1092|       |    /* 25 */
 1093|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1094|  36.2k|    MULADD(at[0], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1095|  36.2k|    MULADD(at[1], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1096|  36.2k|    MULADD(at[2], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1097|  36.2k|    MULADD(at[3], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1098|  36.2k|    MULADD(at[4], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1099|  36.2k|    MULADD(at[5], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1100|  36.2k|    MULADD(at[6], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1101|  36.2k|    MULADD(at[7], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1102|  36.2k|    MULADD(at[8], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1103|  36.2k|    MULADD(at[9], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1104|  36.2k|    MULADD(at[10], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1105|  36.2k|    MULADD(at[11], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1106|  36.2k|    MULADD(at[12], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1107|  36.2k|    MULADD(at[13], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1108|  36.2k|    MULADD(at[14], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1109|  36.2k|    MULADD(at[15], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1110|  36.2k|    MULADD(at[16], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1111|  36.2k|    MULADD(at[17], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1112|  36.2k|    MULADD(at[18], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1113|  36.2k|    MULADD(at[19], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1114|  36.2k|    MULADD(at[20], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1115|  36.2k|    MULADD(at[21], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1116|  36.2k|    MULADD(at[22], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1117|  36.2k|    MULADD(at[23], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1118|  36.2k|    MULADD(at[24], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1119|  36.2k|    MULADD(at[25], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1120|  36.2k|    COMBA_STORE(C->dp[25]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1121|       |    /* 26 */
 1122|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1123|  36.2k|    MULADD(at[0], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1124|  36.2k|    MULADD(at[1], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1125|  36.2k|    MULADD(at[2], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1126|  36.2k|    MULADD(at[3], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1127|  36.2k|    MULADD(at[4], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1128|  36.2k|    MULADD(at[5], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1129|  36.2k|    MULADD(at[6], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1130|  36.2k|    MULADD(at[7], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1131|  36.2k|    MULADD(at[8], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1132|  36.2k|    MULADD(at[9], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1133|  36.2k|    MULADD(at[10], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1134|  36.2k|    MULADD(at[11], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1135|  36.2k|    MULADD(at[12], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1136|  36.2k|    MULADD(at[13], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1137|  36.2k|    MULADD(at[14], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1138|  36.2k|    MULADD(at[15], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1139|  36.2k|    MULADD(at[16], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1140|  36.2k|    MULADD(at[17], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1141|  36.2k|    MULADD(at[18], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1142|  36.2k|    MULADD(at[19], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1143|  36.2k|    MULADD(at[20], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1144|  36.2k|    MULADD(at[21], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1145|  36.2k|    MULADD(at[22], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1146|  36.2k|    MULADD(at[23], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1147|  36.2k|    MULADD(at[24], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1148|  36.2k|    MULADD(at[25], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1149|  36.2k|    MULADD(at[26], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1150|  36.2k|    COMBA_STORE(C->dp[26]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1151|       |    /* 27 */
 1152|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1153|  36.2k|    MULADD(at[0], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1154|  36.2k|    MULADD(at[1], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1155|  36.2k|    MULADD(at[2], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1156|  36.2k|    MULADD(at[3], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1157|  36.2k|    MULADD(at[4], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1158|  36.2k|    MULADD(at[5], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1159|  36.2k|    MULADD(at[6], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1160|  36.2k|    MULADD(at[7], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1161|  36.2k|    MULADD(at[8], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1162|  36.2k|    MULADD(at[9], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1163|  36.2k|    MULADD(at[10], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1164|  36.2k|    MULADD(at[11], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1165|  36.2k|    MULADD(at[12], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1166|  36.2k|    MULADD(at[13], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1167|  36.2k|    MULADD(at[14], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1168|  36.2k|    MULADD(at[15], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1169|  36.2k|    MULADD(at[16], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1170|  36.2k|    MULADD(at[17], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1171|  36.2k|    MULADD(at[18], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1172|  36.2k|    MULADD(at[19], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1173|  36.2k|    MULADD(at[20], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1174|  36.2k|    MULADD(at[21], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1175|  36.2k|    MULADD(at[22], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1176|  36.2k|    MULADD(at[23], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1177|  36.2k|    MULADD(at[24], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1178|  36.2k|    MULADD(at[25], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1179|  36.2k|    MULADD(at[26], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1180|  36.2k|    MULADD(at[27], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1181|  36.2k|    COMBA_STORE(C->dp[27]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1182|       |    /* 28 */
 1183|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1184|  36.2k|    MULADD(at[0], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1185|  36.2k|    MULADD(at[1], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1186|  36.2k|    MULADD(at[2], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1187|  36.2k|    MULADD(at[3], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1188|  36.2k|    MULADD(at[4], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1189|  36.2k|    MULADD(at[5], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1190|  36.2k|    MULADD(at[6], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1191|  36.2k|    MULADD(at[7], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1192|  36.2k|    MULADD(at[8], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1193|  36.2k|    MULADD(at[9], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1194|  36.2k|    MULADD(at[10], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1195|  36.2k|    MULADD(at[11], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1196|  36.2k|    MULADD(at[12], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1197|  36.2k|    MULADD(at[13], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1198|  36.2k|    MULADD(at[14], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1199|  36.2k|    MULADD(at[15], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1200|  36.2k|    MULADD(at[16], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1201|  36.2k|    MULADD(at[17], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1202|  36.2k|    MULADD(at[18], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1203|  36.2k|    MULADD(at[19], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1204|  36.2k|    MULADD(at[20], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1205|  36.2k|    MULADD(at[21], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1206|  36.2k|    MULADD(at[22], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1207|  36.2k|    MULADD(at[23], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1208|  36.2k|    MULADD(at[24], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1209|  36.2k|    MULADD(at[25], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1210|  36.2k|    MULADD(at[26], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1211|  36.2k|    MULADD(at[27], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1212|  36.2k|    MULADD(at[28], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1213|  36.2k|    COMBA_STORE(C->dp[28]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1214|       |    /* 29 */
 1215|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1216|  36.2k|    MULADD(at[0], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1217|  36.2k|    MULADD(at[1], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1218|  36.2k|    MULADD(at[2], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1219|  36.2k|    MULADD(at[3], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1220|  36.2k|    MULADD(at[4], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1221|  36.2k|    MULADD(at[5], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1222|  36.2k|    MULADD(at[6], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1223|  36.2k|    MULADD(at[7], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1224|  36.2k|    MULADD(at[8], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1225|  36.2k|    MULADD(at[9], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1226|  36.2k|    MULADD(at[10], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1227|  36.2k|    MULADD(at[11], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1228|  36.2k|    MULADD(at[12], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1229|  36.2k|    MULADD(at[13], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1230|  36.2k|    MULADD(at[14], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1231|  36.2k|    MULADD(at[15], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1232|  36.2k|    MULADD(at[16], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1233|  36.2k|    MULADD(at[17], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1234|  36.2k|    MULADD(at[18], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1235|  36.2k|    MULADD(at[19], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1236|  36.2k|    MULADD(at[20], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1237|  36.2k|    MULADD(at[21], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1238|  36.2k|    MULADD(at[22], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1239|  36.2k|    MULADD(at[23], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1240|  36.2k|    MULADD(at[24], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1241|  36.2k|    MULADD(at[25], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1242|  36.2k|    MULADD(at[26], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1243|  36.2k|    MULADD(at[27], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1244|  36.2k|    MULADD(at[28], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1245|  36.2k|    MULADD(at[29], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1246|  36.2k|    COMBA_STORE(C->dp[29]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1247|       |    /* 30 */
 1248|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1249|  36.2k|    MULADD(at[0], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1250|  36.2k|    MULADD(at[1], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1251|  36.2k|    MULADD(at[2], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1252|  36.2k|    MULADD(at[3], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1253|  36.2k|    MULADD(at[4], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1254|  36.2k|    MULADD(at[5], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1255|  36.2k|    MULADD(at[6], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1256|  36.2k|    MULADD(at[7], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1257|  36.2k|    MULADD(at[8], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1258|  36.2k|    MULADD(at[9], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1259|  36.2k|    MULADD(at[10], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1260|  36.2k|    MULADD(at[11], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1261|  36.2k|    MULADD(at[12], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1262|  36.2k|    MULADD(at[13], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1263|  36.2k|    MULADD(at[14], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1264|  36.2k|    MULADD(at[15], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1265|  36.2k|    MULADD(at[16], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1266|  36.2k|    MULADD(at[17], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1267|  36.2k|    MULADD(at[18], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1268|  36.2k|    MULADD(at[19], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1269|  36.2k|    MULADD(at[20], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1270|  36.2k|    MULADD(at[21], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1271|  36.2k|    MULADD(at[22], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1272|  36.2k|    MULADD(at[23], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1273|  36.2k|    MULADD(at[24], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1274|  36.2k|    MULADD(at[25], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1275|  36.2k|    MULADD(at[26], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1276|  36.2k|    MULADD(at[27], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1277|  36.2k|    MULADD(at[28], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1278|  36.2k|    MULADD(at[29], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1279|  36.2k|    MULADD(at[30], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1280|  36.2k|    COMBA_STORE(C->dp[30]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1281|       |    /* 31 */
 1282|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1283|  36.2k|    MULADD(at[0], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1284|  36.2k|    MULADD(at[1], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1285|  36.2k|    MULADD(at[2], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1286|  36.2k|    MULADD(at[3], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1287|  36.2k|    MULADD(at[4], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1288|  36.2k|    MULADD(at[5], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1289|  36.2k|    MULADD(at[6], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1290|  36.2k|    MULADD(at[7], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1291|  36.2k|    MULADD(at[8], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1292|  36.2k|    MULADD(at[9], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1293|  36.2k|    MULADD(at[10], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1294|  36.2k|    MULADD(at[11], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1295|  36.2k|    MULADD(at[12], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1296|  36.2k|    MULADD(at[13], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1297|  36.2k|    MULADD(at[14], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1298|  36.2k|    MULADD(at[15], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1299|  36.2k|    MULADD(at[16], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1300|  36.2k|    MULADD(at[17], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1301|  36.2k|    MULADD(at[18], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1302|  36.2k|    MULADD(at[19], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1303|  36.2k|    MULADD(at[20], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1304|  36.2k|    MULADD(at[21], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1305|  36.2k|    MULADD(at[22], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1306|  36.2k|    MULADD(at[23], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1307|  36.2k|    MULADD(at[24], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1308|  36.2k|    MULADD(at[25], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1309|  36.2k|    MULADD(at[26], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1310|  36.2k|    MULADD(at[27], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1311|  36.2k|    MULADD(at[28], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1312|  36.2k|    MULADD(at[29], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1313|  36.2k|    MULADD(at[30], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1314|  36.2k|    MULADD(at[31], at[32]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1315|  36.2k|    COMBA_STORE(C->dp[31]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1316|       |    /* 32 */
 1317|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1318|  36.2k|    MULADD(at[1], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1319|  36.2k|    MULADD(at[2], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1320|  36.2k|    MULADD(at[3], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1321|  36.2k|    MULADD(at[4], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1322|  36.2k|    MULADD(at[5], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1323|  36.2k|    MULADD(at[6], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1324|  36.2k|    MULADD(at[7], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1325|  36.2k|    MULADD(at[8], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1326|  36.2k|    MULADD(at[9], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1327|  36.2k|    MULADD(at[10], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1328|  36.2k|    MULADD(at[11], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1329|  36.2k|    MULADD(at[12], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1330|  36.2k|    MULADD(at[13], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1331|  36.2k|    MULADD(at[14], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1332|  36.2k|    MULADD(at[15], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1333|  36.2k|    MULADD(at[16], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1334|  36.2k|    MULADD(at[17], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1335|  36.2k|    MULADD(at[18], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1336|  36.2k|    MULADD(at[19], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1337|  36.2k|    MULADD(at[20], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1338|  36.2k|    MULADD(at[21], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1339|  36.2k|    MULADD(at[22], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1340|  36.2k|    MULADD(at[23], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1341|  36.2k|    MULADD(at[24], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1342|  36.2k|    MULADD(at[25], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1343|  36.2k|    MULADD(at[26], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1344|  36.2k|    MULADD(at[27], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1345|  36.2k|    MULADD(at[28], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1346|  36.2k|    MULADD(at[29], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1347|  36.2k|    MULADD(at[30], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1348|  36.2k|    MULADD(at[31], at[33]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1349|  36.2k|    COMBA_STORE(C->dp[32]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1350|       |    /* 33 */
 1351|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1352|  36.2k|    MULADD(at[2], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1353|  36.2k|    MULADD(at[3], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1354|  36.2k|    MULADD(at[4], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1355|  36.2k|    MULADD(at[5], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1356|  36.2k|    MULADD(at[6], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1357|  36.2k|    MULADD(at[7], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1358|  36.2k|    MULADD(at[8], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1359|  36.2k|    MULADD(at[9], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1360|  36.2k|    MULADD(at[10], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1361|  36.2k|    MULADD(at[11], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1362|  36.2k|    MULADD(at[12], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1363|  36.2k|    MULADD(at[13], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1364|  36.2k|    MULADD(at[14], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1365|  36.2k|    MULADD(at[15], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1366|  36.2k|    MULADD(at[16], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1367|  36.2k|    MULADD(at[17], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1368|  36.2k|    MULADD(at[18], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1369|  36.2k|    MULADD(at[19], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1370|  36.2k|    MULADD(at[20], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1371|  36.2k|    MULADD(at[21], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1372|  36.2k|    MULADD(at[22], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1373|  36.2k|    MULADD(at[23], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1374|  36.2k|    MULADD(at[24], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1375|  36.2k|    MULADD(at[25], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1376|  36.2k|    MULADD(at[26], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1377|  36.2k|    MULADD(at[27], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1378|  36.2k|    MULADD(at[28], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1379|  36.2k|    MULADD(at[29], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1380|  36.2k|    MULADD(at[30], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1381|  36.2k|    MULADD(at[31], at[34]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1382|  36.2k|    COMBA_STORE(C->dp[33]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1383|       |    /* 34 */
 1384|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1385|  36.2k|    MULADD(at[3], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1386|  36.2k|    MULADD(at[4], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1387|  36.2k|    MULADD(at[5], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1388|  36.2k|    MULADD(at[6], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1389|  36.2k|    MULADD(at[7], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1390|  36.2k|    MULADD(at[8], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1391|  36.2k|    MULADD(at[9], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1392|  36.2k|    MULADD(at[10], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1393|  36.2k|    MULADD(at[11], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1394|  36.2k|    MULADD(at[12], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1395|  36.2k|    MULADD(at[13], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1396|  36.2k|    MULADD(at[14], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1397|  36.2k|    MULADD(at[15], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1398|  36.2k|    MULADD(at[16], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1399|  36.2k|    MULADD(at[17], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1400|  36.2k|    MULADD(at[18], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1401|  36.2k|    MULADD(at[19], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1402|  36.2k|    MULADD(at[20], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1403|  36.2k|    MULADD(at[21], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1404|  36.2k|    MULADD(at[22], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1405|  36.2k|    MULADD(at[23], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1406|  36.2k|    MULADD(at[24], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1407|  36.2k|    MULADD(at[25], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1408|  36.2k|    MULADD(at[26], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1409|  36.2k|    MULADD(at[27], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1410|  36.2k|    MULADD(at[28], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1411|  36.2k|    MULADD(at[29], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1412|  36.2k|    MULADD(at[30], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1413|  36.2k|    MULADD(at[31], at[35]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1414|  36.2k|    COMBA_STORE(C->dp[34]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1415|       |    /* 35 */
 1416|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1417|  36.2k|    MULADD(at[4], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1418|  36.2k|    MULADD(at[5], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1419|  36.2k|    MULADD(at[6], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1420|  36.2k|    MULADD(at[7], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1421|  36.2k|    MULADD(at[8], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1422|  36.2k|    MULADD(at[9], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1423|  36.2k|    MULADD(at[10], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1424|  36.2k|    MULADD(at[11], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1425|  36.2k|    MULADD(at[12], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1426|  36.2k|    MULADD(at[13], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1427|  36.2k|    MULADD(at[14], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1428|  36.2k|    MULADD(at[15], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1429|  36.2k|    MULADD(at[16], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1430|  36.2k|    MULADD(at[17], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1431|  36.2k|    MULADD(at[18], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1432|  36.2k|    MULADD(at[19], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1433|  36.2k|    MULADD(at[20], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1434|  36.2k|    MULADD(at[21], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1435|  36.2k|    MULADD(at[22], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1436|  36.2k|    MULADD(at[23], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1437|  36.2k|    MULADD(at[24], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1438|  36.2k|    MULADD(at[25], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1439|  36.2k|    MULADD(at[26], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1440|  36.2k|    MULADD(at[27], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1441|  36.2k|    MULADD(at[28], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1442|  36.2k|    MULADD(at[29], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1443|  36.2k|    MULADD(at[30], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1444|  36.2k|    MULADD(at[31], at[36]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1445|  36.2k|    COMBA_STORE(C->dp[35]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1446|       |    /* 36 */
 1447|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1448|  36.2k|    MULADD(at[5], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1449|  36.2k|    MULADD(at[6], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1450|  36.2k|    MULADD(at[7], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1451|  36.2k|    MULADD(at[8], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1452|  36.2k|    MULADD(at[9], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1453|  36.2k|    MULADD(at[10], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1454|  36.2k|    MULADD(at[11], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1455|  36.2k|    MULADD(at[12], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1456|  36.2k|    MULADD(at[13], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1457|  36.2k|    MULADD(at[14], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1458|  36.2k|    MULADD(at[15], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1459|  36.2k|    MULADD(at[16], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1460|  36.2k|    MULADD(at[17], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1461|  36.2k|    MULADD(at[18], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1462|  36.2k|    MULADD(at[19], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1463|  36.2k|    MULADD(at[20], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1464|  36.2k|    MULADD(at[21], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1465|  36.2k|    MULADD(at[22], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1466|  36.2k|    MULADD(at[23], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1467|  36.2k|    MULADD(at[24], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1468|  36.2k|    MULADD(at[25], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1469|  36.2k|    MULADD(at[26], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1470|  36.2k|    MULADD(at[27], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1471|  36.2k|    MULADD(at[28], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1472|  36.2k|    MULADD(at[29], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1473|  36.2k|    MULADD(at[30], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1474|  36.2k|    MULADD(at[31], at[37]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1475|  36.2k|    COMBA_STORE(C->dp[36]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1476|       |    /* 37 */
 1477|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1478|  36.2k|    MULADD(at[6], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1479|  36.2k|    MULADD(at[7], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1480|  36.2k|    MULADD(at[8], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1481|  36.2k|    MULADD(at[9], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1482|  36.2k|    MULADD(at[10], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1483|  36.2k|    MULADD(at[11], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1484|  36.2k|    MULADD(at[12], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1485|  36.2k|    MULADD(at[13], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1486|  36.2k|    MULADD(at[14], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1487|  36.2k|    MULADD(at[15], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1488|  36.2k|    MULADD(at[16], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1489|  36.2k|    MULADD(at[17], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1490|  36.2k|    MULADD(at[18], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1491|  36.2k|    MULADD(at[19], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1492|  36.2k|    MULADD(at[20], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1493|  36.2k|    MULADD(at[21], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1494|  36.2k|    MULADD(at[22], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1495|  36.2k|    MULADD(at[23], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1496|  36.2k|    MULADD(at[24], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1497|  36.2k|    MULADD(at[25], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1498|  36.2k|    MULADD(at[26], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1499|  36.2k|    MULADD(at[27], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1500|  36.2k|    MULADD(at[28], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1501|  36.2k|    MULADD(at[29], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1502|  36.2k|    MULADD(at[30], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1503|  36.2k|    MULADD(at[31], at[38]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1504|  36.2k|    COMBA_STORE(C->dp[37]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1505|       |    /* 38 */
 1506|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1507|  36.2k|    MULADD(at[7], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1508|  36.2k|    MULADD(at[8], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1509|  36.2k|    MULADD(at[9], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1510|  36.2k|    MULADD(at[10], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1511|  36.2k|    MULADD(at[11], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1512|  36.2k|    MULADD(at[12], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1513|  36.2k|    MULADD(at[13], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1514|  36.2k|    MULADD(at[14], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1515|  36.2k|    MULADD(at[15], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1516|  36.2k|    MULADD(at[16], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1517|  36.2k|    MULADD(at[17], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1518|  36.2k|    MULADD(at[18], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1519|  36.2k|    MULADD(at[19], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1520|  36.2k|    MULADD(at[20], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1521|  36.2k|    MULADD(at[21], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1522|  36.2k|    MULADD(at[22], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1523|  36.2k|    MULADD(at[23], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1524|  36.2k|    MULADD(at[24], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1525|  36.2k|    MULADD(at[25], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1526|  36.2k|    MULADD(at[26], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1527|  36.2k|    MULADD(at[27], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1528|  36.2k|    MULADD(at[28], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1529|  36.2k|    MULADD(at[29], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1530|  36.2k|    MULADD(at[30], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1531|  36.2k|    MULADD(at[31], at[39]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1532|  36.2k|    COMBA_STORE(C->dp[38]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1533|       |    /* 39 */
 1534|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1535|  36.2k|    MULADD(at[8], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1536|  36.2k|    MULADD(at[9], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1537|  36.2k|    MULADD(at[10], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1538|  36.2k|    MULADD(at[11], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1539|  36.2k|    MULADD(at[12], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1540|  36.2k|    MULADD(at[13], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1541|  36.2k|    MULADD(at[14], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1542|  36.2k|    MULADD(at[15], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1543|  36.2k|    MULADD(at[16], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1544|  36.2k|    MULADD(at[17], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1545|  36.2k|    MULADD(at[18], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1546|  36.2k|    MULADD(at[19], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1547|  36.2k|    MULADD(at[20], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1548|  36.2k|    MULADD(at[21], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1549|  36.2k|    MULADD(at[22], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1550|  36.2k|    MULADD(at[23], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1551|  36.2k|    MULADD(at[24], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1552|  36.2k|    MULADD(at[25], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1553|  36.2k|    MULADD(at[26], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1554|  36.2k|    MULADD(at[27], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1555|  36.2k|    MULADD(at[28], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1556|  36.2k|    MULADD(at[29], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1557|  36.2k|    MULADD(at[30], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1558|  36.2k|    MULADD(at[31], at[40]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1559|  36.2k|    COMBA_STORE(C->dp[39]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1560|       |    /* 40 */
 1561|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1562|  36.2k|    MULADD(at[9], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1563|  36.2k|    MULADD(at[10], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1564|  36.2k|    MULADD(at[11], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1565|  36.2k|    MULADD(at[12], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1566|  36.2k|    MULADD(at[13], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1567|  36.2k|    MULADD(at[14], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1568|  36.2k|    MULADD(at[15], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1569|  36.2k|    MULADD(at[16], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1570|  36.2k|    MULADD(at[17], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1571|  36.2k|    MULADD(at[18], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1572|  36.2k|    MULADD(at[19], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1573|  36.2k|    MULADD(at[20], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1574|  36.2k|    MULADD(at[21], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1575|  36.2k|    MULADD(at[22], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1576|  36.2k|    MULADD(at[23], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1577|  36.2k|    MULADD(at[24], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1578|  36.2k|    MULADD(at[25], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1579|  36.2k|    MULADD(at[26], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1580|  36.2k|    MULADD(at[27], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1581|  36.2k|    MULADD(at[28], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1582|  36.2k|    MULADD(at[29], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1583|  36.2k|    MULADD(at[30], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1584|  36.2k|    MULADD(at[31], at[41]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1585|  36.2k|    COMBA_STORE(C->dp[40]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1586|       |    /* 41 */
 1587|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1588|  36.2k|    MULADD(at[10], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1589|  36.2k|    MULADD(at[11], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1590|  36.2k|    MULADD(at[12], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1591|  36.2k|    MULADD(at[13], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1592|  36.2k|    MULADD(at[14], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1593|  36.2k|    MULADD(at[15], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1594|  36.2k|    MULADD(at[16], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1595|  36.2k|    MULADD(at[17], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1596|  36.2k|    MULADD(at[18], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1597|  36.2k|    MULADD(at[19], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1598|  36.2k|    MULADD(at[20], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1599|  36.2k|    MULADD(at[21], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1600|  36.2k|    MULADD(at[22], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1601|  36.2k|    MULADD(at[23], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1602|  36.2k|    MULADD(at[24], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1603|  36.2k|    MULADD(at[25], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1604|  36.2k|    MULADD(at[26], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1605|  36.2k|    MULADD(at[27], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1606|  36.2k|    MULADD(at[28], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1607|  36.2k|    MULADD(at[29], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1608|  36.2k|    MULADD(at[30], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1609|  36.2k|    MULADD(at[31], at[42]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1610|  36.2k|    COMBA_STORE(C->dp[41]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1611|       |    /* 42 */
 1612|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1613|  36.2k|    MULADD(at[11], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1614|  36.2k|    MULADD(at[12], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1615|  36.2k|    MULADD(at[13], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1616|  36.2k|    MULADD(at[14], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1617|  36.2k|    MULADD(at[15], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1618|  36.2k|    MULADD(at[16], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1619|  36.2k|    MULADD(at[17], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1620|  36.2k|    MULADD(at[18], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1621|  36.2k|    MULADD(at[19], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1622|  36.2k|    MULADD(at[20], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1623|  36.2k|    MULADD(at[21], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1624|  36.2k|    MULADD(at[22], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1625|  36.2k|    MULADD(at[23], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1626|  36.2k|    MULADD(at[24], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1627|  36.2k|    MULADD(at[25], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1628|  36.2k|    MULADD(at[26], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1629|  36.2k|    MULADD(at[27], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1630|  36.2k|    MULADD(at[28], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1631|  36.2k|    MULADD(at[29], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1632|  36.2k|    MULADD(at[30], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1633|  36.2k|    MULADD(at[31], at[43]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1634|  36.2k|    COMBA_STORE(C->dp[42]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1635|       |    /* 43 */
 1636|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1637|  36.2k|    MULADD(at[12], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1638|  36.2k|    MULADD(at[13], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1639|  36.2k|    MULADD(at[14], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1640|  36.2k|    MULADD(at[15], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1641|  36.2k|    MULADD(at[16], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1642|  36.2k|    MULADD(at[17], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1643|  36.2k|    MULADD(at[18], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1644|  36.2k|    MULADD(at[19], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1645|  36.2k|    MULADD(at[20], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1646|  36.2k|    MULADD(at[21], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1647|  36.2k|    MULADD(at[22], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1648|  36.2k|    MULADD(at[23], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1649|  36.2k|    MULADD(at[24], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1650|  36.2k|    MULADD(at[25], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1651|  36.2k|    MULADD(at[26], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1652|  36.2k|    MULADD(at[27], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1653|  36.2k|    MULADD(at[28], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1654|  36.2k|    MULADD(at[29], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1655|  36.2k|    MULADD(at[30], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1656|  36.2k|    MULADD(at[31], at[44]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1657|  36.2k|    COMBA_STORE(C->dp[43]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1658|       |    /* 44 */
 1659|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1660|  36.2k|    MULADD(at[13], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1661|  36.2k|    MULADD(at[14], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1662|  36.2k|    MULADD(at[15], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1663|  36.2k|    MULADD(at[16], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1664|  36.2k|    MULADD(at[17], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1665|  36.2k|    MULADD(at[18], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1666|  36.2k|    MULADD(at[19], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1667|  36.2k|    MULADD(at[20], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1668|  36.2k|    MULADD(at[21], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1669|  36.2k|    MULADD(at[22], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1670|  36.2k|    MULADD(at[23], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1671|  36.2k|    MULADD(at[24], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1672|  36.2k|    MULADD(at[25], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1673|  36.2k|    MULADD(at[26], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1674|  36.2k|    MULADD(at[27], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1675|  36.2k|    MULADD(at[28], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1676|  36.2k|    MULADD(at[29], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1677|  36.2k|    MULADD(at[30], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1678|  36.2k|    MULADD(at[31], at[45]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1679|  36.2k|    COMBA_STORE(C->dp[44]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1680|       |    /* 45 */
 1681|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1682|  36.2k|    MULADD(at[14], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1683|  36.2k|    MULADD(at[15], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1684|  36.2k|    MULADD(at[16], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1685|  36.2k|    MULADD(at[17], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1686|  36.2k|    MULADD(at[18], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1687|  36.2k|    MULADD(at[19], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1688|  36.2k|    MULADD(at[20], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1689|  36.2k|    MULADD(at[21], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1690|  36.2k|    MULADD(at[22], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1691|  36.2k|    MULADD(at[23], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1692|  36.2k|    MULADD(at[24], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1693|  36.2k|    MULADD(at[25], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1694|  36.2k|    MULADD(at[26], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1695|  36.2k|    MULADD(at[27], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1696|  36.2k|    MULADD(at[28], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1697|  36.2k|    MULADD(at[29], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1698|  36.2k|    MULADD(at[30], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1699|  36.2k|    MULADD(at[31], at[46]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1700|  36.2k|    COMBA_STORE(C->dp[45]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1701|       |    /* 46 */
 1702|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1703|  36.2k|    MULADD(at[15], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1704|  36.2k|    MULADD(at[16], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1705|  36.2k|    MULADD(at[17], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1706|  36.2k|    MULADD(at[18], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1707|  36.2k|    MULADD(at[19], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1708|  36.2k|    MULADD(at[20], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1709|  36.2k|    MULADD(at[21], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1710|  36.2k|    MULADD(at[22], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1711|  36.2k|    MULADD(at[23], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1712|  36.2k|    MULADD(at[24], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1713|  36.2k|    MULADD(at[25], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1714|  36.2k|    MULADD(at[26], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1715|  36.2k|    MULADD(at[27], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1716|  36.2k|    MULADD(at[28], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1717|  36.2k|    MULADD(at[29], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1718|  36.2k|    MULADD(at[30], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1719|  36.2k|    MULADD(at[31], at[47]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1720|  36.2k|    COMBA_STORE(C->dp[46]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1721|       |    /* 47 */
 1722|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1723|  36.2k|    MULADD(at[16], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1724|  36.2k|    MULADD(at[17], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1725|  36.2k|    MULADD(at[18], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1726|  36.2k|    MULADD(at[19], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1727|  36.2k|    MULADD(at[20], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1728|  36.2k|    MULADD(at[21], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1729|  36.2k|    MULADD(at[22], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1730|  36.2k|    MULADD(at[23], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1731|  36.2k|    MULADD(at[24], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1732|  36.2k|    MULADD(at[25], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1733|  36.2k|    MULADD(at[26], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1734|  36.2k|    MULADD(at[27], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1735|  36.2k|    MULADD(at[28], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1736|  36.2k|    MULADD(at[29], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1737|  36.2k|    MULADD(at[30], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1738|  36.2k|    MULADD(at[31], at[48]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1739|  36.2k|    COMBA_STORE(C->dp[47]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1740|       |    /* 48 */
 1741|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1742|  36.2k|    MULADD(at[17], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1743|  36.2k|    MULADD(at[18], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1744|  36.2k|    MULADD(at[19], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1745|  36.2k|    MULADD(at[20], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1746|  36.2k|    MULADD(at[21], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1747|  36.2k|    MULADD(at[22], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1748|  36.2k|    MULADD(at[23], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1749|  36.2k|    MULADD(at[24], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1750|  36.2k|    MULADD(at[25], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1751|  36.2k|    MULADD(at[26], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1752|  36.2k|    MULADD(at[27], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1753|  36.2k|    MULADD(at[28], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1754|  36.2k|    MULADD(at[29], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1755|  36.2k|    MULADD(at[30], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1756|  36.2k|    MULADD(at[31], at[49]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1757|  36.2k|    COMBA_STORE(C->dp[48]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1758|       |    /* 49 */
 1759|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1760|  36.2k|    MULADD(at[18], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1761|  36.2k|    MULADD(at[19], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1762|  36.2k|    MULADD(at[20], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1763|  36.2k|    MULADD(at[21], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1764|  36.2k|    MULADD(at[22], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1765|  36.2k|    MULADD(at[23], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1766|  36.2k|    MULADD(at[24], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1767|  36.2k|    MULADD(at[25], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1768|  36.2k|    MULADD(at[26], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1769|  36.2k|    MULADD(at[27], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1770|  36.2k|    MULADD(at[28], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1771|  36.2k|    MULADD(at[29], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1772|  36.2k|    MULADD(at[30], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1773|  36.2k|    MULADD(at[31], at[50]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1774|  36.2k|    COMBA_STORE(C->dp[49]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1775|       |    /* 50 */
 1776|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1777|  36.2k|    MULADD(at[19], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1778|  36.2k|    MULADD(at[20], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1779|  36.2k|    MULADD(at[21], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1780|  36.2k|    MULADD(at[22], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1781|  36.2k|    MULADD(at[23], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1782|  36.2k|    MULADD(at[24], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1783|  36.2k|    MULADD(at[25], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1784|  36.2k|    MULADD(at[26], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1785|  36.2k|    MULADD(at[27], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1786|  36.2k|    MULADD(at[28], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1787|  36.2k|    MULADD(at[29], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1788|  36.2k|    MULADD(at[30], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1789|  36.2k|    MULADD(at[31], at[51]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1790|  36.2k|    COMBA_STORE(C->dp[50]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1791|       |    /* 51 */
 1792|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1793|  36.2k|    MULADD(at[20], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1794|  36.2k|    MULADD(at[21], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1795|  36.2k|    MULADD(at[22], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1796|  36.2k|    MULADD(at[23], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1797|  36.2k|    MULADD(at[24], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1798|  36.2k|    MULADD(at[25], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1799|  36.2k|    MULADD(at[26], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1800|  36.2k|    MULADD(at[27], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1801|  36.2k|    MULADD(at[28], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1802|  36.2k|    MULADD(at[29], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1803|  36.2k|    MULADD(at[30], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1804|  36.2k|    MULADD(at[31], at[52]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1805|  36.2k|    COMBA_STORE(C->dp[51]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1806|       |    /* 52 */
 1807|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1808|  36.2k|    MULADD(at[21], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1809|  36.2k|    MULADD(at[22], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1810|  36.2k|    MULADD(at[23], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1811|  36.2k|    MULADD(at[24], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1812|  36.2k|    MULADD(at[25], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1813|  36.2k|    MULADD(at[26], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1814|  36.2k|    MULADD(at[27], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1815|  36.2k|    MULADD(at[28], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1816|  36.2k|    MULADD(at[29], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1817|  36.2k|    MULADD(at[30], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1818|  36.2k|    MULADD(at[31], at[53]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1819|  36.2k|    COMBA_STORE(C->dp[52]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1820|       |    /* 53 */
 1821|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1822|  36.2k|    MULADD(at[22], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1823|  36.2k|    MULADD(at[23], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1824|  36.2k|    MULADD(at[24], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1825|  36.2k|    MULADD(at[25], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1826|  36.2k|    MULADD(at[26], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1827|  36.2k|    MULADD(at[27], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1828|  36.2k|    MULADD(at[28], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1829|  36.2k|    MULADD(at[29], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1830|  36.2k|    MULADD(at[30], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1831|  36.2k|    MULADD(at[31], at[54]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1832|  36.2k|    COMBA_STORE(C->dp[53]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1833|       |    /* 54 */
 1834|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1835|  36.2k|    MULADD(at[23], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1836|  36.2k|    MULADD(at[24], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1837|  36.2k|    MULADD(at[25], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1838|  36.2k|    MULADD(at[26], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1839|  36.2k|    MULADD(at[27], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1840|  36.2k|    MULADD(at[28], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1841|  36.2k|    MULADD(at[29], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1842|  36.2k|    MULADD(at[30], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1843|  36.2k|    MULADD(at[31], at[55]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1844|  36.2k|    COMBA_STORE(C->dp[54]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1845|       |    /* 55 */
 1846|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1847|  36.2k|    MULADD(at[24], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1848|  36.2k|    MULADD(at[25], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1849|  36.2k|    MULADD(at[26], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1850|  36.2k|    MULADD(at[27], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1851|  36.2k|    MULADD(at[28], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1852|  36.2k|    MULADD(at[29], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1853|  36.2k|    MULADD(at[30], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1854|  36.2k|    MULADD(at[31], at[56]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1855|  36.2k|    COMBA_STORE(C->dp[55]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1856|       |    /* 56 */
 1857|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1858|  36.2k|    MULADD(at[25], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1859|  36.2k|    MULADD(at[26], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1860|  36.2k|    MULADD(at[27], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1861|  36.2k|    MULADD(at[28], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1862|  36.2k|    MULADD(at[29], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1863|  36.2k|    MULADD(at[30], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1864|  36.2k|    MULADD(at[31], at[57]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1865|  36.2k|    COMBA_STORE(C->dp[56]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1866|       |    /* 57 */
 1867|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1868|  36.2k|    MULADD(at[26], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1869|  36.2k|    MULADD(at[27], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1870|  36.2k|    MULADD(at[28], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1871|  36.2k|    MULADD(at[29], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1872|  36.2k|    MULADD(at[30], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1873|  36.2k|    MULADD(at[31], at[58]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1874|  36.2k|    COMBA_STORE(C->dp[57]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1875|       |    /* 58 */
 1876|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1877|  36.2k|    MULADD(at[27], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1878|  36.2k|    MULADD(at[28], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1879|  36.2k|    MULADD(at[29], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1880|  36.2k|    MULADD(at[30], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1881|  36.2k|    MULADD(at[31], at[59]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1882|  36.2k|    COMBA_STORE(C->dp[58]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1883|       |    /* 59 */
 1884|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1885|  36.2k|    MULADD(at[28], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1886|  36.2k|    MULADD(at[29], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1887|  36.2k|    MULADD(at[30], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1888|  36.2k|    MULADD(at[31], at[60]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1889|  36.2k|    COMBA_STORE(C->dp[59]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1890|       |    /* 60 */
 1891|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1892|  36.2k|    MULADD(at[29], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1893|  36.2k|    MULADD(at[30], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1894|  36.2k|    MULADD(at[31], at[61]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1895|  36.2k|    COMBA_STORE(C->dp[60]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1896|       |    /* 61 */
 1897|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1898|  36.2k|    MULADD(at[30], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1899|  36.2k|    MULADD(at[31], at[62]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1900|  36.2k|    COMBA_STORE(C->dp[61]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1901|       |    /* 62 */
 1902|  36.2k|    COMBA_FORWARD;
  ------------------
  |  |   41|  36.2k|    do {              \
  |  |   42|  36.2k|        c0 = c1;      \
  |  |   43|  36.2k|        c1 = c2;      \
  |  |   44|  36.2k|        c2 = 0;       \
  |  |   45|  36.2k|    } while (0);
  |  |  ------------------
  |  |  |  Branch (45:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1903|  36.2k|    MULADD(at[31], at[63]);
  ------------------
  |  |   52|  36.2k|    __asm__(                                        \
  |  |   53|  36.2k|        "movq  %6,%%rax     \n\t"                   \
  |  |   54|  36.2k|        "mulq  %7           \n\t"                   \
  |  |   55|  36.2k|        "addq  %%rax,%0     \n\t"                   \
  |  |   56|  36.2k|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   57|  36.2k|        "adcq  $0,%2        \n\t"                   \
  |  |   58|  36.2k|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |   59|  36.2k|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |   60|  36.2k|        : "%rax", "%rdx", "cc");
  ------------------
 1904|  36.2k|    COMBA_STORE(C->dp[62]);
  ------------------
  |  |   67|  36.2k|    x = c0;
  ------------------
 1905|  36.2k|    COMBA_STORE2(C->dp[63]);
  ------------------
  |  |   70|  36.2k|    x = c1;
  ------------------
 1906|  36.2k|    C->used = 64;
 1907|  36.2k|    C->sign = A->sign ^ B->sign;
 1908|  36.2k|    mp_clamp(C);
  ------------------
  |  |   26|  36.2k|    {                                                    \
  |  |   27|  36.2k|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 36.2k, False: 0]
  |  |  |  Branch (27:29): [True: 16, False: 36.2k]
  |  |  ------------------
  |  |   28|  36.2k|            --((a)->used);                               \
  |  |   29|  36.2k|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  36.2k|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 36.2k, False: 0]
  |  |  ------------------
  |  |   30|  36.2k|    }
  ------------------
 1909|  36.2k|    COMBA_FINI;
 1910|  36.2k|}
s_mp_sqr_comba_4:
 1914|    187|{
 1915|    187|    mp_digit *a, b[8], c0, c1, c2;
 1916|       |
 1917|    187|    a = A->dp;
 1918|    187|    COMBA_START;
 1919|       |
 1920|       |    /* clear carries */
 1921|    187|    CLEAR_CARRY;
  ------------------
  |  |   64|    187|    c0 = c1 = c2 = 0;
  ------------------
 1922|       |
 1923|       |    /* output 0 */
 1924|    187|    SQRADD(a[0], a[0]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1925|    187|    COMBA_STORE(b[0]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1926|       |
 1927|       |    /* output 1 */
 1928|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1929|    187|    SQRADD2(a[0], a[1]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1930|    187|    COMBA_STORE(b[1]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1931|       |
 1932|       |    /* output 2 */
 1933|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1934|    187|    SQRADD2(a[0], a[2]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1935|    187|    SQRADD(a[1], a[1]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1936|    187|    COMBA_STORE(b[2]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1937|       |
 1938|       |    /* output 3 */
 1939|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1940|    187|    SQRADD2(a[0], a[3]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1941|    187|    SQRADD2(a[1], a[2]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1942|    187|    COMBA_STORE(b[3]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1943|       |
 1944|       |    /* output 4 */
 1945|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1946|    187|    SQRADD2(a[1], a[3]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1947|    187|    SQRADD(a[2], a[2]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1948|    187|    COMBA_STORE(b[4]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1949|       |
 1950|       |    /* output 5 */
 1951|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1952|    187|    SQRADD2(a[2], a[3]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1953|    187|    COMBA_STORE(b[5]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1954|       |
 1955|       |    /* output 6 */
 1956|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1957|    187|    SQRADD(a[3], a[3]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1958|    187|    COMBA_STORE(b[6]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1959|    187|    COMBA_STORE2(b[7]);
  ------------------
  |  |   70|    187|    x = c1;
  ------------------
 1960|    187|    COMBA_FINI;
 1961|       |
 1962|    187|    B->used = 8;
 1963|    187|    B->sign = ZPOS;
  ------------------
  |  |  326|    187|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|    187|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 1964|    187|    memcpy(B->dp, b, 8 * sizeof(mp_digit));
 1965|    187|    mp_clamp(B);
  ------------------
  |  |   26|    187|    {                                                    \
  |  |   27|    215|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 215, False: 0]
  |  |  |  Branch (27:29): [True: 28, False: 187]
  |  |  ------------------
  |  |   28|    187|            --((a)->used);                               \
  |  |   29|    187|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|    187|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 187, False: 0]
  |  |  ------------------
  |  |   30|    187|    }
  ------------------
 1966|    187|}
s_mp_sqr_comba_8:
 1970|    187|{
 1971|    187|    mp_digit *a, b[16], c0, c1, c2, sc0, sc1, sc2;
 1972|       |
 1973|    187|    a = A->dp;
 1974|    187|    COMBA_START;
 1975|       |
 1976|       |    /* clear carries */
 1977|    187|    CLEAR_CARRY;
  ------------------
  |  |   64|    187|    c0 = c1 = c2 = 0;
  ------------------
 1978|       |
 1979|       |    /* output 0 */
 1980|    187|    SQRADD(a[0], a[0]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1981|    187|    COMBA_STORE(b[0]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1982|       |
 1983|       |    /* output 1 */
 1984|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1985|    187|    SQRADD2(a[0], a[1]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1986|    187|    COMBA_STORE(b[1]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1987|       |
 1988|       |    /* output 2 */
 1989|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1990|    187|    SQRADD2(a[0], a[2]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1991|    187|    SQRADD(a[1], a[1]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1992|    187|    COMBA_STORE(b[2]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1993|       |
 1994|       |    /* output 3 */
 1995|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1996|    187|    SQRADD2(a[0], a[3]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1997|    187|    SQRADD2(a[1], a[2]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 1998|    187|    COMBA_STORE(b[3]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 1999|       |
 2000|       |    /* output 4 */
 2001|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2002|    187|    SQRADD2(a[0], a[4]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2003|    187|    SQRADD2(a[1], a[3]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2004|    187|    SQRADD(a[2], a[2]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2005|    187|    COMBA_STORE(b[4]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2006|       |
 2007|       |    /* output 5 */
 2008|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2009|    187|    SQRADDSC(a[0], a[5]);
  ------------------
  |  |  107|    187|    __asm__(                              \
  |  |  108|    187|        "movq  %3,%%rax     \n\t"         \
  |  |  109|    187|        "mulq  %4           \n\t"         \
  |  |  110|    187|        "movq  %%rax,%0     \n\t"         \
  |  |  111|    187|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|    187|        "xorq  %2,%2        \n\t"         \
  |  |  113|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|    187|        : "g"(i), "g"(j)                  \
  |  |  115|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2010|    187|    SQRADDAC(a[1], a[4]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2011|    187|    SQRADDAC(a[2], a[3]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2012|    187|    SQRADDDB;
  ------------------
  |  |  129|    187|    __asm__(                                                      \
  |  |  130|    187|        "addq %6,%0         \n\t"                                 \
  |  |  131|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  132|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  133|    187|        "addq %6,%0         \n\t"                                 \
  |  |  134|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  135|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  136|    187|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|    187|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|    187|        : "cc");
  ------------------
 2013|    187|    COMBA_STORE(b[5]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2014|       |
 2015|       |    /* output 6 */
 2016|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2017|    187|    SQRADDSC(a[0], a[6]);
  ------------------
  |  |  107|    187|    __asm__(                              \
  |  |  108|    187|        "movq  %3,%%rax     \n\t"         \
  |  |  109|    187|        "mulq  %4           \n\t"         \
  |  |  110|    187|        "movq  %%rax,%0     \n\t"         \
  |  |  111|    187|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|    187|        "xorq  %2,%2        \n\t"         \
  |  |  113|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|    187|        : "g"(i), "g"(j)                  \
  |  |  115|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2018|    187|    SQRADDAC(a[1], a[5]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2019|    187|    SQRADDAC(a[2], a[4]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2020|    187|    SQRADDDB;
  ------------------
  |  |  129|    187|    __asm__(                                                      \
  |  |  130|    187|        "addq %6,%0         \n\t"                                 \
  |  |  131|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  132|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  133|    187|        "addq %6,%0         \n\t"                                 \
  |  |  134|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  135|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  136|    187|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|    187|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|    187|        : "cc");
  ------------------
 2021|    187|    SQRADD(a[3], a[3]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2022|    187|    COMBA_STORE(b[6]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2023|       |
 2024|       |    /* output 7 */
 2025|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2026|    187|    SQRADDSC(a[0], a[7]);
  ------------------
  |  |  107|    187|    __asm__(                              \
  |  |  108|    187|        "movq  %3,%%rax     \n\t"         \
  |  |  109|    187|        "mulq  %4           \n\t"         \
  |  |  110|    187|        "movq  %%rax,%0     \n\t"         \
  |  |  111|    187|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|    187|        "xorq  %2,%2        \n\t"         \
  |  |  113|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|    187|        : "g"(i), "g"(j)                  \
  |  |  115|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2027|    187|    SQRADDAC(a[1], a[6]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2028|    187|    SQRADDAC(a[2], a[5]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2029|    187|    SQRADDAC(a[3], a[4]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2030|    187|    SQRADDDB;
  ------------------
  |  |  129|    187|    __asm__(                                                      \
  |  |  130|    187|        "addq %6,%0         \n\t"                                 \
  |  |  131|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  132|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  133|    187|        "addq %6,%0         \n\t"                                 \
  |  |  134|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  135|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  136|    187|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|    187|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|    187|        : "cc");
  ------------------
 2031|    187|    COMBA_STORE(b[7]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2032|       |
 2033|       |    /* output 8 */
 2034|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2035|    187|    SQRADDSC(a[1], a[7]);
  ------------------
  |  |  107|    187|    __asm__(                              \
  |  |  108|    187|        "movq  %3,%%rax     \n\t"         \
  |  |  109|    187|        "mulq  %4           \n\t"         \
  |  |  110|    187|        "movq  %%rax,%0     \n\t"         \
  |  |  111|    187|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|    187|        "xorq  %2,%2        \n\t"         \
  |  |  113|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|    187|        : "g"(i), "g"(j)                  \
  |  |  115|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2036|    187|    SQRADDAC(a[2], a[6]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2037|    187|    SQRADDAC(a[3], a[5]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2038|    187|    SQRADDDB;
  ------------------
  |  |  129|    187|    __asm__(                                                      \
  |  |  130|    187|        "addq %6,%0         \n\t"                                 \
  |  |  131|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  132|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  133|    187|        "addq %6,%0         \n\t"                                 \
  |  |  134|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  135|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  136|    187|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|    187|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|    187|        : "cc");
  ------------------
 2039|    187|    SQRADD(a[4], a[4]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2040|    187|    COMBA_STORE(b[8]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2041|       |
 2042|       |    /* output 9 */
 2043|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2044|    187|    SQRADDSC(a[2], a[7]);
  ------------------
  |  |  107|    187|    __asm__(                              \
  |  |  108|    187|        "movq  %3,%%rax     \n\t"         \
  |  |  109|    187|        "mulq  %4           \n\t"         \
  |  |  110|    187|        "movq  %%rax,%0     \n\t"         \
  |  |  111|    187|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|    187|        "xorq  %2,%2        \n\t"         \
  |  |  113|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|    187|        : "g"(i), "g"(j)                  \
  |  |  115|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2045|    187|    SQRADDAC(a[3], a[6]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2046|    187|    SQRADDAC(a[4], a[5]);
  ------------------
  |  |  118|    187|    __asm__(                                           \
  |  |  119|    187|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|    187|        "mulq  %7           \n\t"                      \
  |  |  121|    187|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|    187|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|    187|        "adcq  $0,%2        \n\t"                      \
  |  |  124|    187|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|    187|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2047|    187|    SQRADDDB;
  ------------------
  |  |  129|    187|    __asm__(                                                      \
  |  |  130|    187|        "addq %6,%0         \n\t"                                 \
  |  |  131|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  132|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  133|    187|        "addq %6,%0         \n\t"                                 \
  |  |  134|    187|        "adcq %7,%1         \n\t"                                 \
  |  |  135|    187|        "adcq %8,%2         \n\t"                                 \
  |  |  136|    187|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|    187|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|    187|        : "cc");
  ------------------
 2048|    187|    COMBA_STORE(b[9]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2049|       |
 2050|       |    /* output 10 */
 2051|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2052|    187|    SQRADD2(a[3], a[7]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2053|    187|    SQRADD2(a[4], a[6]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2054|    187|    SQRADD(a[5], a[5]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2055|    187|    COMBA_STORE(b[10]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2056|       |
 2057|       |    /* output 11 */
 2058|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2059|    187|    SQRADD2(a[4], a[7]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2060|    187|    SQRADD2(a[5], a[6]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2061|    187|    COMBA_STORE(b[11]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2062|       |
 2063|       |    /* output 12 */
 2064|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2065|    187|    SQRADD2(a[5], a[7]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2066|    187|    SQRADD(a[6], a[6]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2067|    187|    COMBA_STORE(b[12]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2068|       |
 2069|       |    /* output 13 */
 2070|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2071|    187|    SQRADD2(a[6], a[7]);
  ------------------
  |  |   93|    187|    __asm__(                                        \
  |  |   94|    187|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|    187|        "mulq  %7           \n\t"                   \
  |  |   96|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|    187|        "adcq  $0,%2        \n\t"                   \
  |  |   99|    187|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|    187|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|    187|        "adcq  $0,%2        \n\t"                   \
  |  |  102|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2072|    187|    COMBA_STORE(b[13]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2073|       |
 2074|       |    /* output 14 */
 2075|    187|    CARRY_FORWARD;
  ------------------
  |  |   73|    187|    do {              \
  |  |   74|    187|        c0 = c1;      \
  |  |   75|    187|        c1 = c2;      \
  |  |   76|    187|        c2 = 0;       \
  |  |   77|    187|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2076|    187|    SQRADD(a[7], a[7]);
  ------------------
  |  |   82|    187|    __asm__(                                \
  |  |   83|    187|        "movq  %6,%%rax     \n\t"           \
  |  |   84|    187|        "mulq  %%rax        \n\t"           \
  |  |   85|    187|        "addq  %%rax,%0     \n\t"           \
  |  |   86|    187|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|    187|        "adcq  $0,%2        \n\t"           \
  |  |   88|    187|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|    187|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|    187|        : "%rax", "%rdx", "cc");
  ------------------
 2077|    187|    COMBA_STORE(b[14]);
  ------------------
  |  |   67|    187|    x = c0;
  ------------------
 2078|    187|    COMBA_STORE2(b[15]);
  ------------------
  |  |   70|    187|    x = c1;
  ------------------
 2079|    187|    COMBA_FINI;
 2080|       |
 2081|    187|    B->used = 16;
 2082|    187|    B->sign = ZPOS;
  ------------------
  |  |  326|    187|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|    187|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 2083|    187|    memcpy(B->dp, b, 16 * sizeof(mp_digit));
 2084|    187|    mp_clamp(B);
  ------------------
  |  |   26|    187|    {                                                    \
  |  |   27|    223|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 223, False: 0]
  |  |  |  Branch (27:29): [True: 36, False: 187]
  |  |  ------------------
  |  |   28|    187|            --((a)->used);                               \
  |  |   29|    187|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|    187|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 187, False: 0]
  |  |  ------------------
  |  |   30|    187|    }
  ------------------
 2085|    187|}
s_mp_sqr_comba_16:
 2089|  85.1M|{
 2090|  85.1M|    mp_digit *a, b[32], c0, c1, c2, sc0, sc1, sc2;
 2091|       |
 2092|  85.1M|    a = A->dp;
 2093|  85.1M|    COMBA_START;
 2094|       |
 2095|       |    /* clear carries */
 2096|  85.1M|    CLEAR_CARRY;
  ------------------
  |  |   64|  85.1M|    c0 = c1 = c2 = 0;
  ------------------
 2097|       |
 2098|       |    /* output 0 */
 2099|  85.1M|    SQRADD(a[0], a[0]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2100|  85.1M|    COMBA_STORE(b[0]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2101|       |
 2102|       |    /* output 1 */
 2103|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2104|  85.1M|    SQRADD2(a[0], a[1]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2105|  85.1M|    COMBA_STORE(b[1]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2106|       |
 2107|       |    /* output 2 */
 2108|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2109|  85.1M|    SQRADD2(a[0], a[2]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2110|  85.1M|    SQRADD(a[1], a[1]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2111|  85.1M|    COMBA_STORE(b[2]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2112|       |
 2113|       |    /* output 3 */
 2114|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2115|  85.1M|    SQRADD2(a[0], a[3]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2116|  85.1M|    SQRADD2(a[1], a[2]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2117|  85.1M|    COMBA_STORE(b[3]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2118|       |
 2119|       |    /* output 4 */
 2120|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2121|  85.1M|    SQRADD2(a[0], a[4]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2122|  85.1M|    SQRADD2(a[1], a[3]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2123|  85.1M|    SQRADD(a[2], a[2]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2124|  85.1M|    COMBA_STORE(b[4]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2125|       |
 2126|       |    /* output 5 */
 2127|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2128|  85.1M|    SQRADDSC(a[0], a[5]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2129|  85.1M|    SQRADDAC(a[1], a[4]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2130|  85.1M|    SQRADDAC(a[2], a[3]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2131|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2132|  85.1M|    COMBA_STORE(b[5]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2133|       |
 2134|       |    /* output 6 */
 2135|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2136|  85.1M|    SQRADDSC(a[0], a[6]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2137|  85.1M|    SQRADDAC(a[1], a[5]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2138|  85.1M|    SQRADDAC(a[2], a[4]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2139|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2140|  85.1M|    SQRADD(a[3], a[3]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2141|  85.1M|    COMBA_STORE(b[6]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2142|       |
 2143|       |    /* output 7 */
 2144|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2145|  85.1M|    SQRADDSC(a[0], a[7]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2146|  85.1M|    SQRADDAC(a[1], a[6]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2147|  85.1M|    SQRADDAC(a[2], a[5]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2148|  85.1M|    SQRADDAC(a[3], a[4]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2149|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2150|  85.1M|    COMBA_STORE(b[7]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2151|       |
 2152|       |    /* output 8 */
 2153|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2154|  85.1M|    SQRADDSC(a[0], a[8]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2155|  85.1M|    SQRADDAC(a[1], a[7]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2156|  85.1M|    SQRADDAC(a[2], a[6]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2157|  85.1M|    SQRADDAC(a[3], a[5]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2158|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2159|  85.1M|    SQRADD(a[4], a[4]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2160|  85.1M|    COMBA_STORE(b[8]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2161|       |
 2162|       |    /* output 9 */
 2163|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2164|  85.1M|    SQRADDSC(a[0], a[9]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2165|  85.1M|    SQRADDAC(a[1], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2166|  85.1M|    SQRADDAC(a[2], a[7]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2167|  85.1M|    SQRADDAC(a[3], a[6]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2168|  85.1M|    SQRADDAC(a[4], a[5]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2169|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2170|  85.1M|    COMBA_STORE(b[9]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2171|       |
 2172|       |    /* output 10 */
 2173|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2174|  85.1M|    SQRADDSC(a[0], a[10]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2175|  85.1M|    SQRADDAC(a[1], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2176|  85.1M|    SQRADDAC(a[2], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2177|  85.1M|    SQRADDAC(a[3], a[7]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2178|  85.1M|    SQRADDAC(a[4], a[6]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2179|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2180|  85.1M|    SQRADD(a[5], a[5]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2181|  85.1M|    COMBA_STORE(b[10]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2182|       |
 2183|       |    /* output 11 */
 2184|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2185|  85.1M|    SQRADDSC(a[0], a[11]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2186|  85.1M|    SQRADDAC(a[1], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2187|  85.1M|    SQRADDAC(a[2], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2188|  85.1M|    SQRADDAC(a[3], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2189|  85.1M|    SQRADDAC(a[4], a[7]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2190|  85.1M|    SQRADDAC(a[5], a[6]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2191|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2192|  85.1M|    COMBA_STORE(b[11]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2193|       |
 2194|       |    /* output 12 */
 2195|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2196|  85.1M|    SQRADDSC(a[0], a[12]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2197|  85.1M|    SQRADDAC(a[1], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2198|  85.1M|    SQRADDAC(a[2], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2199|  85.1M|    SQRADDAC(a[3], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2200|  85.1M|    SQRADDAC(a[4], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2201|  85.1M|    SQRADDAC(a[5], a[7]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2202|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2203|  85.1M|    SQRADD(a[6], a[6]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2204|  85.1M|    COMBA_STORE(b[12]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2205|       |
 2206|       |    /* output 13 */
 2207|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2208|  85.1M|    SQRADDSC(a[0], a[13]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2209|  85.1M|    SQRADDAC(a[1], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2210|  85.1M|    SQRADDAC(a[2], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2211|  85.1M|    SQRADDAC(a[3], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2212|  85.1M|    SQRADDAC(a[4], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2213|  85.1M|    SQRADDAC(a[5], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2214|  85.1M|    SQRADDAC(a[6], a[7]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2215|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2216|  85.1M|    COMBA_STORE(b[13]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2217|       |
 2218|       |    /* output 14 */
 2219|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2220|  85.1M|    SQRADDSC(a[0], a[14]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2221|  85.1M|    SQRADDAC(a[1], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2222|  85.1M|    SQRADDAC(a[2], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2223|  85.1M|    SQRADDAC(a[3], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2224|  85.1M|    SQRADDAC(a[4], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2225|  85.1M|    SQRADDAC(a[5], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2226|  85.1M|    SQRADDAC(a[6], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2227|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2228|  85.1M|    SQRADD(a[7], a[7]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2229|  85.1M|    COMBA_STORE(b[14]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2230|       |
 2231|       |    /* output 15 */
 2232|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2233|  85.1M|    SQRADDSC(a[0], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2234|  85.1M|    SQRADDAC(a[1], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2235|  85.1M|    SQRADDAC(a[2], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2236|  85.1M|    SQRADDAC(a[3], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2237|  85.1M|    SQRADDAC(a[4], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2238|  85.1M|    SQRADDAC(a[5], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2239|  85.1M|    SQRADDAC(a[6], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2240|  85.1M|    SQRADDAC(a[7], a[8]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2241|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2242|  85.1M|    COMBA_STORE(b[15]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2243|       |
 2244|       |    /* output 16 */
 2245|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2246|  85.1M|    SQRADDSC(a[1], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2247|  85.1M|    SQRADDAC(a[2], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2248|  85.1M|    SQRADDAC(a[3], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2249|  85.1M|    SQRADDAC(a[4], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2250|  85.1M|    SQRADDAC(a[5], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2251|  85.1M|    SQRADDAC(a[6], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2252|  85.1M|    SQRADDAC(a[7], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2253|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2254|  85.1M|    SQRADD(a[8], a[8]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2255|  85.1M|    COMBA_STORE(b[16]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2256|       |
 2257|       |    /* output 17 */
 2258|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2259|  85.1M|    SQRADDSC(a[2], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2260|  85.1M|    SQRADDAC(a[3], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2261|  85.1M|    SQRADDAC(a[4], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2262|  85.1M|    SQRADDAC(a[5], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2263|  85.1M|    SQRADDAC(a[6], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2264|  85.1M|    SQRADDAC(a[7], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2265|  85.1M|    SQRADDAC(a[8], a[9]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2266|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2267|  85.1M|    COMBA_STORE(b[17]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2268|       |
 2269|       |    /* output 18 */
 2270|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2271|  85.1M|    SQRADDSC(a[3], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2272|  85.1M|    SQRADDAC(a[4], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2273|  85.1M|    SQRADDAC(a[5], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2274|  85.1M|    SQRADDAC(a[6], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2275|  85.1M|    SQRADDAC(a[7], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2276|  85.1M|    SQRADDAC(a[8], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2277|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2278|  85.1M|    SQRADD(a[9], a[9]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2279|  85.1M|    COMBA_STORE(b[18]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2280|       |
 2281|       |    /* output 19 */
 2282|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2283|  85.1M|    SQRADDSC(a[4], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2284|  85.1M|    SQRADDAC(a[5], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2285|  85.1M|    SQRADDAC(a[6], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2286|  85.1M|    SQRADDAC(a[7], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2287|  85.1M|    SQRADDAC(a[8], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2288|  85.1M|    SQRADDAC(a[9], a[10]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2289|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2290|  85.1M|    COMBA_STORE(b[19]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2291|       |
 2292|       |    /* output 20 */
 2293|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2294|  85.1M|    SQRADDSC(a[5], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2295|  85.1M|    SQRADDAC(a[6], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2296|  85.1M|    SQRADDAC(a[7], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2297|  85.1M|    SQRADDAC(a[8], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2298|  85.1M|    SQRADDAC(a[9], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2299|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2300|  85.1M|    SQRADD(a[10], a[10]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2301|  85.1M|    COMBA_STORE(b[20]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2302|       |
 2303|       |    /* output 21 */
 2304|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2305|  85.1M|    SQRADDSC(a[6], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2306|  85.1M|    SQRADDAC(a[7], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2307|  85.1M|    SQRADDAC(a[8], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2308|  85.1M|    SQRADDAC(a[9], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2309|  85.1M|    SQRADDAC(a[10], a[11]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2310|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2311|  85.1M|    COMBA_STORE(b[21]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2312|       |
 2313|       |    /* output 22 */
 2314|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2315|  85.1M|    SQRADDSC(a[7], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2316|  85.1M|    SQRADDAC(a[8], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2317|  85.1M|    SQRADDAC(a[9], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2318|  85.1M|    SQRADDAC(a[10], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2319|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2320|  85.1M|    SQRADD(a[11], a[11]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2321|  85.1M|    COMBA_STORE(b[22]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2322|       |
 2323|       |    /* output 23 */
 2324|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2325|  85.1M|    SQRADDSC(a[8], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2326|  85.1M|    SQRADDAC(a[9], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2327|  85.1M|    SQRADDAC(a[10], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2328|  85.1M|    SQRADDAC(a[11], a[12]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2329|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2330|  85.1M|    COMBA_STORE(b[23]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2331|       |
 2332|       |    /* output 24 */
 2333|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2334|  85.1M|    SQRADDSC(a[9], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2335|  85.1M|    SQRADDAC(a[10], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2336|  85.1M|    SQRADDAC(a[11], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2337|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2338|  85.1M|    SQRADD(a[12], a[12]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2339|  85.1M|    COMBA_STORE(b[24]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2340|       |
 2341|       |    /* output 25 */
 2342|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2343|  85.1M|    SQRADDSC(a[10], a[15]);
  ------------------
  |  |  107|  85.1M|    __asm__(                              \
  |  |  108|  85.1M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  85.1M|        "mulq  %4           \n\t"         \
  |  |  110|  85.1M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  85.1M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  85.1M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  85.1M|        : "g"(i), "g"(j)                  \
  |  |  115|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2344|  85.1M|    SQRADDAC(a[11], a[14]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2345|  85.1M|    SQRADDAC(a[12], a[13]);
  ------------------
  |  |  118|  85.1M|    __asm__(                                           \
  |  |  119|  85.1M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  85.1M|        "mulq  %7           \n\t"                      \
  |  |  121|  85.1M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  85.1M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  85.1M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  85.1M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  85.1M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2346|  85.1M|    SQRADDDB;
  ------------------
  |  |  129|  85.1M|    __asm__(                                                      \
  |  |  130|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  85.1M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  85.1M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  85.1M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  85.1M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  85.1M|        : "cc");
  ------------------
 2347|  85.1M|    COMBA_STORE(b[25]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2348|       |
 2349|       |    /* output 26 */
 2350|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2351|  85.1M|    SQRADD2(a[11], a[15]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2352|  85.1M|    SQRADD2(a[12], a[14]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2353|  85.1M|    SQRADD(a[13], a[13]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2354|  85.1M|    COMBA_STORE(b[26]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2355|       |
 2356|       |    /* output 27 */
 2357|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2358|  85.1M|    SQRADD2(a[12], a[15]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2359|  85.1M|    SQRADD2(a[13], a[14]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2360|  85.1M|    COMBA_STORE(b[27]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2361|       |
 2362|       |    /* output 28 */
 2363|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2364|  85.1M|    SQRADD2(a[13], a[15]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2365|  85.1M|    SQRADD(a[14], a[14]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2366|  85.1M|    COMBA_STORE(b[28]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2367|       |
 2368|       |    /* output 29 */
 2369|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2370|  85.1M|    SQRADD2(a[14], a[15]);
  ------------------
  |  |   93|  85.1M|    __asm__(                                        \
  |  |   94|  85.1M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  85.1M|        "mulq  %7           \n\t"                   \
  |  |   96|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  85.1M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  85.1M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  85.1M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2371|  85.1M|    COMBA_STORE(b[29]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2372|       |
 2373|       |    /* output 30 */
 2374|  85.1M|    CARRY_FORWARD;
  ------------------
  |  |   73|  85.1M|    do {              \
  |  |   74|  85.1M|        c0 = c1;      \
  |  |   75|  85.1M|        c1 = c2;      \
  |  |   76|  85.1M|        c2 = 0;       \
  |  |   77|  85.1M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2375|  85.1M|    SQRADD(a[15], a[15]);
  ------------------
  |  |   82|  85.1M|    __asm__(                                \
  |  |   83|  85.1M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  85.1M|        "mulq  %%rax        \n\t"           \
  |  |   85|  85.1M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  85.1M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  85.1M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  85.1M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  85.1M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  85.1M|        : "%rax", "%rdx", "cc");
  ------------------
 2376|  85.1M|    COMBA_STORE(b[30]);
  ------------------
  |  |   67|  85.1M|    x = c0;
  ------------------
 2377|  85.1M|    COMBA_STORE2(b[31]);
  ------------------
  |  |   70|  85.1M|    x = c1;
  ------------------
 2378|  85.1M|    COMBA_FINI;
 2379|       |
 2380|  85.1M|    B->used = 32;
 2381|  85.1M|    B->sign = ZPOS;
  ------------------
  |  |  326|  85.1M|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|  85.1M|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 2382|  85.1M|    memcpy(B->dp, b, 32 * sizeof(mp_digit));
 2383|  85.1M|    mp_clamp(B);
  ------------------
  |  |   26|  85.1M|    {                                                    \
  |  |   27|  85.1M|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 85.1M, False: 0]
  |  |  |  Branch (27:29): [True: 431, False: 85.1M]
  |  |  ------------------
  |  |   28|  85.1M|            --((a)->used);                               \
  |  |   29|  85.1M|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  85.1M|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 85.1M, False: 0]
  |  |  ------------------
  |  |   30|  85.1M|    }
  ------------------
 2384|  85.1M|}
s_mp_sqr_comba_32:
 2388|  15.0M|{
 2389|  15.0M|    mp_digit *a, b[64], c0, c1, c2, sc0, sc1, sc2;
 2390|       |
 2391|  15.0M|    a = A->dp;
 2392|  15.0M|    COMBA_START;
 2393|       |
 2394|       |    /* clear carries */
 2395|  15.0M|    CLEAR_CARRY;
  ------------------
  |  |   64|  15.0M|    c0 = c1 = c2 = 0;
  ------------------
 2396|       |
 2397|       |    /* output 0 */
 2398|  15.0M|    SQRADD(a[0], a[0]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2399|  15.0M|    COMBA_STORE(b[0]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2400|       |
 2401|       |    /* output 1 */
 2402|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2403|  15.0M|    SQRADD2(a[0], a[1]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2404|  15.0M|    COMBA_STORE(b[1]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2405|       |
 2406|       |    /* output 2 */
 2407|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2408|  15.0M|    SQRADD2(a[0], a[2]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2409|  15.0M|    SQRADD(a[1], a[1]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2410|  15.0M|    COMBA_STORE(b[2]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2411|       |
 2412|       |    /* output 3 */
 2413|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2414|  15.0M|    SQRADD2(a[0], a[3]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2415|  15.0M|    SQRADD2(a[1], a[2]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2416|  15.0M|    COMBA_STORE(b[3]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2417|       |
 2418|       |    /* output 4 */
 2419|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2420|  15.0M|    SQRADD2(a[0], a[4]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2421|  15.0M|    SQRADD2(a[1], a[3]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2422|  15.0M|    SQRADD(a[2], a[2]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2423|  15.0M|    COMBA_STORE(b[4]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2424|       |
 2425|       |    /* output 5 */
 2426|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2427|  15.0M|    SQRADDSC(a[0], a[5]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2428|  15.0M|    SQRADDAC(a[1], a[4]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2429|  15.0M|    SQRADDAC(a[2], a[3]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2430|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2431|  15.0M|    COMBA_STORE(b[5]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2432|       |
 2433|       |    /* output 6 */
 2434|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2435|  15.0M|    SQRADDSC(a[0], a[6]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2436|  15.0M|    SQRADDAC(a[1], a[5]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2437|  15.0M|    SQRADDAC(a[2], a[4]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2438|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2439|  15.0M|    SQRADD(a[3], a[3]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2440|  15.0M|    COMBA_STORE(b[6]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2441|       |
 2442|       |    /* output 7 */
 2443|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2444|  15.0M|    SQRADDSC(a[0], a[7]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2445|  15.0M|    SQRADDAC(a[1], a[6]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2446|  15.0M|    SQRADDAC(a[2], a[5]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2447|  15.0M|    SQRADDAC(a[3], a[4]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2448|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2449|  15.0M|    COMBA_STORE(b[7]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2450|       |
 2451|       |    /* output 8 */
 2452|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2453|  15.0M|    SQRADDSC(a[0], a[8]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2454|  15.0M|    SQRADDAC(a[1], a[7]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2455|  15.0M|    SQRADDAC(a[2], a[6]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2456|  15.0M|    SQRADDAC(a[3], a[5]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2457|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2458|  15.0M|    SQRADD(a[4], a[4]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2459|  15.0M|    COMBA_STORE(b[8]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2460|       |
 2461|       |    /* output 9 */
 2462|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2463|  15.0M|    SQRADDSC(a[0], a[9]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2464|  15.0M|    SQRADDAC(a[1], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2465|  15.0M|    SQRADDAC(a[2], a[7]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2466|  15.0M|    SQRADDAC(a[3], a[6]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2467|  15.0M|    SQRADDAC(a[4], a[5]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2468|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2469|  15.0M|    COMBA_STORE(b[9]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2470|       |
 2471|       |    /* output 10 */
 2472|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2473|  15.0M|    SQRADDSC(a[0], a[10]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2474|  15.0M|    SQRADDAC(a[1], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2475|  15.0M|    SQRADDAC(a[2], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2476|  15.0M|    SQRADDAC(a[3], a[7]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2477|  15.0M|    SQRADDAC(a[4], a[6]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2478|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2479|  15.0M|    SQRADD(a[5], a[5]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2480|  15.0M|    COMBA_STORE(b[10]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2481|       |
 2482|       |    /* output 11 */
 2483|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2484|  15.0M|    SQRADDSC(a[0], a[11]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2485|  15.0M|    SQRADDAC(a[1], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2486|  15.0M|    SQRADDAC(a[2], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2487|  15.0M|    SQRADDAC(a[3], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2488|  15.0M|    SQRADDAC(a[4], a[7]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2489|  15.0M|    SQRADDAC(a[5], a[6]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2490|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2491|  15.0M|    COMBA_STORE(b[11]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2492|       |
 2493|       |    /* output 12 */
 2494|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2495|  15.0M|    SQRADDSC(a[0], a[12]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2496|  15.0M|    SQRADDAC(a[1], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2497|  15.0M|    SQRADDAC(a[2], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2498|  15.0M|    SQRADDAC(a[3], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2499|  15.0M|    SQRADDAC(a[4], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2500|  15.0M|    SQRADDAC(a[5], a[7]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2501|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2502|  15.0M|    SQRADD(a[6], a[6]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2503|  15.0M|    COMBA_STORE(b[12]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2504|       |
 2505|       |    /* output 13 */
 2506|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2507|  15.0M|    SQRADDSC(a[0], a[13]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2508|  15.0M|    SQRADDAC(a[1], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2509|  15.0M|    SQRADDAC(a[2], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2510|  15.0M|    SQRADDAC(a[3], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2511|  15.0M|    SQRADDAC(a[4], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2512|  15.0M|    SQRADDAC(a[5], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2513|  15.0M|    SQRADDAC(a[6], a[7]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2514|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2515|  15.0M|    COMBA_STORE(b[13]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2516|       |
 2517|       |    /* output 14 */
 2518|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2519|  15.0M|    SQRADDSC(a[0], a[14]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2520|  15.0M|    SQRADDAC(a[1], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2521|  15.0M|    SQRADDAC(a[2], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2522|  15.0M|    SQRADDAC(a[3], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2523|  15.0M|    SQRADDAC(a[4], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2524|  15.0M|    SQRADDAC(a[5], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2525|  15.0M|    SQRADDAC(a[6], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2526|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2527|  15.0M|    SQRADD(a[7], a[7]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2528|  15.0M|    COMBA_STORE(b[14]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2529|       |
 2530|       |    /* output 15 */
 2531|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2532|  15.0M|    SQRADDSC(a[0], a[15]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2533|  15.0M|    SQRADDAC(a[1], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2534|  15.0M|    SQRADDAC(a[2], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2535|  15.0M|    SQRADDAC(a[3], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2536|  15.0M|    SQRADDAC(a[4], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2537|  15.0M|    SQRADDAC(a[5], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2538|  15.0M|    SQRADDAC(a[6], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2539|  15.0M|    SQRADDAC(a[7], a[8]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2540|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2541|  15.0M|    COMBA_STORE(b[15]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2542|       |
 2543|       |    /* output 16 */
 2544|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2545|  15.0M|    SQRADDSC(a[0], a[16]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2546|  15.0M|    SQRADDAC(a[1], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2547|  15.0M|    SQRADDAC(a[2], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2548|  15.0M|    SQRADDAC(a[3], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2549|  15.0M|    SQRADDAC(a[4], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2550|  15.0M|    SQRADDAC(a[5], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2551|  15.0M|    SQRADDAC(a[6], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2552|  15.0M|    SQRADDAC(a[7], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2553|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2554|  15.0M|    SQRADD(a[8], a[8]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2555|  15.0M|    COMBA_STORE(b[16]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2556|       |
 2557|       |    /* output 17 */
 2558|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2559|  15.0M|    SQRADDSC(a[0], a[17]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2560|  15.0M|    SQRADDAC(a[1], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2561|  15.0M|    SQRADDAC(a[2], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2562|  15.0M|    SQRADDAC(a[3], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2563|  15.0M|    SQRADDAC(a[4], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2564|  15.0M|    SQRADDAC(a[5], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2565|  15.0M|    SQRADDAC(a[6], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2566|  15.0M|    SQRADDAC(a[7], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2567|  15.0M|    SQRADDAC(a[8], a[9]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2568|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2569|  15.0M|    COMBA_STORE(b[17]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2570|       |
 2571|       |    /* output 18 */
 2572|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2573|  15.0M|    SQRADDSC(a[0], a[18]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2574|  15.0M|    SQRADDAC(a[1], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2575|  15.0M|    SQRADDAC(a[2], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2576|  15.0M|    SQRADDAC(a[3], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2577|  15.0M|    SQRADDAC(a[4], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2578|  15.0M|    SQRADDAC(a[5], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2579|  15.0M|    SQRADDAC(a[6], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2580|  15.0M|    SQRADDAC(a[7], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2581|  15.0M|    SQRADDAC(a[8], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2582|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2583|  15.0M|    SQRADD(a[9], a[9]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2584|  15.0M|    COMBA_STORE(b[18]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2585|       |
 2586|       |    /* output 19 */
 2587|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2588|  15.0M|    SQRADDSC(a[0], a[19]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2589|  15.0M|    SQRADDAC(a[1], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2590|  15.0M|    SQRADDAC(a[2], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2591|  15.0M|    SQRADDAC(a[3], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2592|  15.0M|    SQRADDAC(a[4], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2593|  15.0M|    SQRADDAC(a[5], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2594|  15.0M|    SQRADDAC(a[6], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2595|  15.0M|    SQRADDAC(a[7], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2596|  15.0M|    SQRADDAC(a[8], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2597|  15.0M|    SQRADDAC(a[9], a[10]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2598|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2599|  15.0M|    COMBA_STORE(b[19]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2600|       |
 2601|       |    /* output 20 */
 2602|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2603|  15.0M|    SQRADDSC(a[0], a[20]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2604|  15.0M|    SQRADDAC(a[1], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2605|  15.0M|    SQRADDAC(a[2], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2606|  15.0M|    SQRADDAC(a[3], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2607|  15.0M|    SQRADDAC(a[4], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2608|  15.0M|    SQRADDAC(a[5], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2609|  15.0M|    SQRADDAC(a[6], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2610|  15.0M|    SQRADDAC(a[7], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2611|  15.0M|    SQRADDAC(a[8], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2612|  15.0M|    SQRADDAC(a[9], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2613|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2614|  15.0M|    SQRADD(a[10], a[10]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2615|  15.0M|    COMBA_STORE(b[20]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2616|       |
 2617|       |    /* output 21 */
 2618|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2619|  15.0M|    SQRADDSC(a[0], a[21]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2620|  15.0M|    SQRADDAC(a[1], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2621|  15.0M|    SQRADDAC(a[2], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2622|  15.0M|    SQRADDAC(a[3], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2623|  15.0M|    SQRADDAC(a[4], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2624|  15.0M|    SQRADDAC(a[5], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2625|  15.0M|    SQRADDAC(a[6], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2626|  15.0M|    SQRADDAC(a[7], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2627|  15.0M|    SQRADDAC(a[8], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2628|  15.0M|    SQRADDAC(a[9], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2629|  15.0M|    SQRADDAC(a[10], a[11]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2630|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2631|  15.0M|    COMBA_STORE(b[21]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2632|       |
 2633|       |    /* output 22 */
 2634|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2635|  15.0M|    SQRADDSC(a[0], a[22]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2636|  15.0M|    SQRADDAC(a[1], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2637|  15.0M|    SQRADDAC(a[2], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2638|  15.0M|    SQRADDAC(a[3], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2639|  15.0M|    SQRADDAC(a[4], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2640|  15.0M|    SQRADDAC(a[5], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2641|  15.0M|    SQRADDAC(a[6], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2642|  15.0M|    SQRADDAC(a[7], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2643|  15.0M|    SQRADDAC(a[8], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2644|  15.0M|    SQRADDAC(a[9], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2645|  15.0M|    SQRADDAC(a[10], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2646|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2647|  15.0M|    SQRADD(a[11], a[11]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2648|  15.0M|    COMBA_STORE(b[22]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2649|       |
 2650|       |    /* output 23 */
 2651|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2652|  15.0M|    SQRADDSC(a[0], a[23]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2653|  15.0M|    SQRADDAC(a[1], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2654|  15.0M|    SQRADDAC(a[2], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2655|  15.0M|    SQRADDAC(a[3], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2656|  15.0M|    SQRADDAC(a[4], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2657|  15.0M|    SQRADDAC(a[5], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2658|  15.0M|    SQRADDAC(a[6], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2659|  15.0M|    SQRADDAC(a[7], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2660|  15.0M|    SQRADDAC(a[8], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2661|  15.0M|    SQRADDAC(a[9], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2662|  15.0M|    SQRADDAC(a[10], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2663|  15.0M|    SQRADDAC(a[11], a[12]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2664|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2665|  15.0M|    COMBA_STORE(b[23]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2666|       |
 2667|       |    /* output 24 */
 2668|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2669|  15.0M|    SQRADDSC(a[0], a[24]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2670|  15.0M|    SQRADDAC(a[1], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2671|  15.0M|    SQRADDAC(a[2], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2672|  15.0M|    SQRADDAC(a[3], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2673|  15.0M|    SQRADDAC(a[4], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2674|  15.0M|    SQRADDAC(a[5], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2675|  15.0M|    SQRADDAC(a[6], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2676|  15.0M|    SQRADDAC(a[7], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2677|  15.0M|    SQRADDAC(a[8], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2678|  15.0M|    SQRADDAC(a[9], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2679|  15.0M|    SQRADDAC(a[10], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2680|  15.0M|    SQRADDAC(a[11], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2681|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2682|  15.0M|    SQRADD(a[12], a[12]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2683|  15.0M|    COMBA_STORE(b[24]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2684|       |
 2685|       |    /* output 25 */
 2686|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2687|  15.0M|    SQRADDSC(a[0], a[25]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2688|  15.0M|    SQRADDAC(a[1], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2689|  15.0M|    SQRADDAC(a[2], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2690|  15.0M|    SQRADDAC(a[3], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2691|  15.0M|    SQRADDAC(a[4], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2692|  15.0M|    SQRADDAC(a[5], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2693|  15.0M|    SQRADDAC(a[6], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2694|  15.0M|    SQRADDAC(a[7], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2695|  15.0M|    SQRADDAC(a[8], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2696|  15.0M|    SQRADDAC(a[9], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2697|  15.0M|    SQRADDAC(a[10], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2698|  15.0M|    SQRADDAC(a[11], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2699|  15.0M|    SQRADDAC(a[12], a[13]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2700|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2701|  15.0M|    COMBA_STORE(b[25]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2702|       |
 2703|       |    /* output 26 */
 2704|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2705|  15.0M|    SQRADDSC(a[0], a[26]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2706|  15.0M|    SQRADDAC(a[1], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2707|  15.0M|    SQRADDAC(a[2], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2708|  15.0M|    SQRADDAC(a[3], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2709|  15.0M|    SQRADDAC(a[4], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2710|  15.0M|    SQRADDAC(a[5], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2711|  15.0M|    SQRADDAC(a[6], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2712|  15.0M|    SQRADDAC(a[7], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2713|  15.0M|    SQRADDAC(a[8], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2714|  15.0M|    SQRADDAC(a[9], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2715|  15.0M|    SQRADDAC(a[10], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2716|  15.0M|    SQRADDAC(a[11], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2717|  15.0M|    SQRADDAC(a[12], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2718|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2719|  15.0M|    SQRADD(a[13], a[13]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2720|  15.0M|    COMBA_STORE(b[26]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2721|       |
 2722|       |    /* output 27 */
 2723|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2724|  15.0M|    SQRADDSC(a[0], a[27]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2725|  15.0M|    SQRADDAC(a[1], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2726|  15.0M|    SQRADDAC(a[2], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2727|  15.0M|    SQRADDAC(a[3], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2728|  15.0M|    SQRADDAC(a[4], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2729|  15.0M|    SQRADDAC(a[5], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2730|  15.0M|    SQRADDAC(a[6], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2731|  15.0M|    SQRADDAC(a[7], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2732|  15.0M|    SQRADDAC(a[8], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2733|  15.0M|    SQRADDAC(a[9], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2734|  15.0M|    SQRADDAC(a[10], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2735|  15.0M|    SQRADDAC(a[11], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2736|  15.0M|    SQRADDAC(a[12], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2737|  15.0M|    SQRADDAC(a[13], a[14]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2738|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2739|  15.0M|    COMBA_STORE(b[27]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2740|       |
 2741|       |    /* output 28 */
 2742|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2743|  15.0M|    SQRADDSC(a[0], a[28]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2744|  15.0M|    SQRADDAC(a[1], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2745|  15.0M|    SQRADDAC(a[2], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2746|  15.0M|    SQRADDAC(a[3], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2747|  15.0M|    SQRADDAC(a[4], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2748|  15.0M|    SQRADDAC(a[5], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2749|  15.0M|    SQRADDAC(a[6], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2750|  15.0M|    SQRADDAC(a[7], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2751|  15.0M|    SQRADDAC(a[8], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2752|  15.0M|    SQRADDAC(a[9], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2753|  15.0M|    SQRADDAC(a[10], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2754|  15.0M|    SQRADDAC(a[11], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2755|  15.0M|    SQRADDAC(a[12], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2756|  15.0M|    SQRADDAC(a[13], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2757|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2758|  15.0M|    SQRADD(a[14], a[14]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2759|  15.0M|    COMBA_STORE(b[28]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2760|       |
 2761|       |    /* output 29 */
 2762|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2763|  15.0M|    SQRADDSC(a[0], a[29]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2764|  15.0M|    SQRADDAC(a[1], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2765|  15.0M|    SQRADDAC(a[2], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2766|  15.0M|    SQRADDAC(a[3], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2767|  15.0M|    SQRADDAC(a[4], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2768|  15.0M|    SQRADDAC(a[5], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2769|  15.0M|    SQRADDAC(a[6], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2770|  15.0M|    SQRADDAC(a[7], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2771|  15.0M|    SQRADDAC(a[8], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2772|  15.0M|    SQRADDAC(a[9], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2773|  15.0M|    SQRADDAC(a[10], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2774|  15.0M|    SQRADDAC(a[11], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2775|  15.0M|    SQRADDAC(a[12], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2776|  15.0M|    SQRADDAC(a[13], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2777|  15.0M|    SQRADDAC(a[14], a[15]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2778|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2779|  15.0M|    COMBA_STORE(b[29]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2780|       |
 2781|       |    /* output 30 */
 2782|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2783|  15.0M|    SQRADDSC(a[0], a[30]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2784|  15.0M|    SQRADDAC(a[1], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2785|  15.0M|    SQRADDAC(a[2], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2786|  15.0M|    SQRADDAC(a[3], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2787|  15.0M|    SQRADDAC(a[4], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2788|  15.0M|    SQRADDAC(a[5], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2789|  15.0M|    SQRADDAC(a[6], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2790|  15.0M|    SQRADDAC(a[7], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2791|  15.0M|    SQRADDAC(a[8], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2792|  15.0M|    SQRADDAC(a[9], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2793|  15.0M|    SQRADDAC(a[10], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2794|  15.0M|    SQRADDAC(a[11], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2795|  15.0M|    SQRADDAC(a[12], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2796|  15.0M|    SQRADDAC(a[13], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2797|  15.0M|    SQRADDAC(a[14], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2798|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2799|  15.0M|    SQRADD(a[15], a[15]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2800|  15.0M|    COMBA_STORE(b[30]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2801|       |
 2802|       |    /* output 31 */
 2803|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2804|  15.0M|    SQRADDSC(a[0], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2805|  15.0M|    SQRADDAC(a[1], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2806|  15.0M|    SQRADDAC(a[2], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2807|  15.0M|    SQRADDAC(a[3], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2808|  15.0M|    SQRADDAC(a[4], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2809|  15.0M|    SQRADDAC(a[5], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2810|  15.0M|    SQRADDAC(a[6], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2811|  15.0M|    SQRADDAC(a[7], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2812|  15.0M|    SQRADDAC(a[8], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2813|  15.0M|    SQRADDAC(a[9], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2814|  15.0M|    SQRADDAC(a[10], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2815|  15.0M|    SQRADDAC(a[11], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2816|  15.0M|    SQRADDAC(a[12], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2817|  15.0M|    SQRADDAC(a[13], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2818|  15.0M|    SQRADDAC(a[14], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2819|  15.0M|    SQRADDAC(a[15], a[16]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2820|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2821|  15.0M|    COMBA_STORE(b[31]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2822|       |
 2823|       |    /* output 32 */
 2824|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2825|  15.0M|    SQRADDSC(a[1], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2826|  15.0M|    SQRADDAC(a[2], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2827|  15.0M|    SQRADDAC(a[3], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2828|  15.0M|    SQRADDAC(a[4], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2829|  15.0M|    SQRADDAC(a[5], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2830|  15.0M|    SQRADDAC(a[6], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2831|  15.0M|    SQRADDAC(a[7], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2832|  15.0M|    SQRADDAC(a[8], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2833|  15.0M|    SQRADDAC(a[9], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2834|  15.0M|    SQRADDAC(a[10], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2835|  15.0M|    SQRADDAC(a[11], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2836|  15.0M|    SQRADDAC(a[12], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2837|  15.0M|    SQRADDAC(a[13], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2838|  15.0M|    SQRADDAC(a[14], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2839|  15.0M|    SQRADDAC(a[15], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2840|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2841|  15.0M|    SQRADD(a[16], a[16]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2842|  15.0M|    COMBA_STORE(b[32]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2843|       |
 2844|       |    /* output 33 */
 2845|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2846|  15.0M|    SQRADDSC(a[2], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2847|  15.0M|    SQRADDAC(a[3], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2848|  15.0M|    SQRADDAC(a[4], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2849|  15.0M|    SQRADDAC(a[5], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2850|  15.0M|    SQRADDAC(a[6], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2851|  15.0M|    SQRADDAC(a[7], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2852|  15.0M|    SQRADDAC(a[8], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2853|  15.0M|    SQRADDAC(a[9], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2854|  15.0M|    SQRADDAC(a[10], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2855|  15.0M|    SQRADDAC(a[11], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2856|  15.0M|    SQRADDAC(a[12], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2857|  15.0M|    SQRADDAC(a[13], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2858|  15.0M|    SQRADDAC(a[14], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2859|  15.0M|    SQRADDAC(a[15], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2860|  15.0M|    SQRADDAC(a[16], a[17]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2861|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2862|  15.0M|    COMBA_STORE(b[33]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2863|       |
 2864|       |    /* output 34 */
 2865|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2866|  15.0M|    SQRADDSC(a[3], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2867|  15.0M|    SQRADDAC(a[4], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2868|  15.0M|    SQRADDAC(a[5], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2869|  15.0M|    SQRADDAC(a[6], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2870|  15.0M|    SQRADDAC(a[7], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2871|  15.0M|    SQRADDAC(a[8], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2872|  15.0M|    SQRADDAC(a[9], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2873|  15.0M|    SQRADDAC(a[10], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2874|  15.0M|    SQRADDAC(a[11], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2875|  15.0M|    SQRADDAC(a[12], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2876|  15.0M|    SQRADDAC(a[13], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2877|  15.0M|    SQRADDAC(a[14], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2878|  15.0M|    SQRADDAC(a[15], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2879|  15.0M|    SQRADDAC(a[16], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2880|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2881|  15.0M|    SQRADD(a[17], a[17]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2882|  15.0M|    COMBA_STORE(b[34]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2883|       |
 2884|       |    /* output 35 */
 2885|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2886|  15.0M|    SQRADDSC(a[4], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2887|  15.0M|    SQRADDAC(a[5], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2888|  15.0M|    SQRADDAC(a[6], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2889|  15.0M|    SQRADDAC(a[7], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2890|  15.0M|    SQRADDAC(a[8], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2891|  15.0M|    SQRADDAC(a[9], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2892|  15.0M|    SQRADDAC(a[10], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2893|  15.0M|    SQRADDAC(a[11], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2894|  15.0M|    SQRADDAC(a[12], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2895|  15.0M|    SQRADDAC(a[13], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2896|  15.0M|    SQRADDAC(a[14], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2897|  15.0M|    SQRADDAC(a[15], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2898|  15.0M|    SQRADDAC(a[16], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2899|  15.0M|    SQRADDAC(a[17], a[18]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2900|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2901|  15.0M|    COMBA_STORE(b[35]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2902|       |
 2903|       |    /* output 36 */
 2904|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2905|  15.0M|    SQRADDSC(a[5], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2906|  15.0M|    SQRADDAC(a[6], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2907|  15.0M|    SQRADDAC(a[7], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2908|  15.0M|    SQRADDAC(a[8], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2909|  15.0M|    SQRADDAC(a[9], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2910|  15.0M|    SQRADDAC(a[10], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2911|  15.0M|    SQRADDAC(a[11], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2912|  15.0M|    SQRADDAC(a[12], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2913|  15.0M|    SQRADDAC(a[13], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2914|  15.0M|    SQRADDAC(a[14], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2915|  15.0M|    SQRADDAC(a[15], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2916|  15.0M|    SQRADDAC(a[16], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2917|  15.0M|    SQRADDAC(a[17], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2918|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2919|  15.0M|    SQRADD(a[18], a[18]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2920|  15.0M|    COMBA_STORE(b[36]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2921|       |
 2922|       |    /* output 37 */
 2923|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2924|  15.0M|    SQRADDSC(a[6], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2925|  15.0M|    SQRADDAC(a[7], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2926|  15.0M|    SQRADDAC(a[8], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2927|  15.0M|    SQRADDAC(a[9], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2928|  15.0M|    SQRADDAC(a[10], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2929|  15.0M|    SQRADDAC(a[11], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2930|  15.0M|    SQRADDAC(a[12], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2931|  15.0M|    SQRADDAC(a[13], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2932|  15.0M|    SQRADDAC(a[14], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2933|  15.0M|    SQRADDAC(a[15], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2934|  15.0M|    SQRADDAC(a[16], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2935|  15.0M|    SQRADDAC(a[17], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2936|  15.0M|    SQRADDAC(a[18], a[19]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2937|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2938|  15.0M|    COMBA_STORE(b[37]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2939|       |
 2940|       |    /* output 38 */
 2941|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2942|  15.0M|    SQRADDSC(a[7], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2943|  15.0M|    SQRADDAC(a[8], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2944|  15.0M|    SQRADDAC(a[9], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2945|  15.0M|    SQRADDAC(a[10], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2946|  15.0M|    SQRADDAC(a[11], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2947|  15.0M|    SQRADDAC(a[12], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2948|  15.0M|    SQRADDAC(a[13], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2949|  15.0M|    SQRADDAC(a[14], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2950|  15.0M|    SQRADDAC(a[15], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2951|  15.0M|    SQRADDAC(a[16], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2952|  15.0M|    SQRADDAC(a[17], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2953|  15.0M|    SQRADDAC(a[18], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2954|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2955|  15.0M|    SQRADD(a[19], a[19]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2956|  15.0M|    COMBA_STORE(b[38]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2957|       |
 2958|       |    /* output 39 */
 2959|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2960|  15.0M|    SQRADDSC(a[8], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2961|  15.0M|    SQRADDAC(a[9], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2962|  15.0M|    SQRADDAC(a[10], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2963|  15.0M|    SQRADDAC(a[11], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2964|  15.0M|    SQRADDAC(a[12], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2965|  15.0M|    SQRADDAC(a[13], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2966|  15.0M|    SQRADDAC(a[14], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2967|  15.0M|    SQRADDAC(a[15], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2968|  15.0M|    SQRADDAC(a[16], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2969|  15.0M|    SQRADDAC(a[17], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2970|  15.0M|    SQRADDAC(a[18], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2971|  15.0M|    SQRADDAC(a[19], a[20]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2972|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2973|  15.0M|    COMBA_STORE(b[39]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2974|       |
 2975|       |    /* output 40 */
 2976|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2977|  15.0M|    SQRADDSC(a[9], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2978|  15.0M|    SQRADDAC(a[10], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2979|  15.0M|    SQRADDAC(a[11], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2980|  15.0M|    SQRADDAC(a[12], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2981|  15.0M|    SQRADDAC(a[13], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2982|  15.0M|    SQRADDAC(a[14], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2983|  15.0M|    SQRADDAC(a[15], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2984|  15.0M|    SQRADDAC(a[16], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2985|  15.0M|    SQRADDAC(a[17], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2986|  15.0M|    SQRADDAC(a[18], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2987|  15.0M|    SQRADDAC(a[19], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2988|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 2989|  15.0M|    SQRADD(a[20], a[20]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2990|  15.0M|    COMBA_STORE(b[40]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 2991|       |
 2992|       |    /* output 41 */
 2993|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2994|  15.0M|    SQRADDSC(a[10], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2995|  15.0M|    SQRADDAC(a[11], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2996|  15.0M|    SQRADDAC(a[12], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2997|  15.0M|    SQRADDAC(a[13], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2998|  15.0M|    SQRADDAC(a[14], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 2999|  15.0M|    SQRADDAC(a[15], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3000|  15.0M|    SQRADDAC(a[16], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3001|  15.0M|    SQRADDAC(a[17], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3002|  15.0M|    SQRADDAC(a[18], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3003|  15.0M|    SQRADDAC(a[19], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3004|  15.0M|    SQRADDAC(a[20], a[21]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3005|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3006|  15.0M|    COMBA_STORE(b[41]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3007|       |
 3008|       |    /* output 42 */
 3009|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3010|  15.0M|    SQRADDSC(a[11], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3011|  15.0M|    SQRADDAC(a[12], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3012|  15.0M|    SQRADDAC(a[13], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3013|  15.0M|    SQRADDAC(a[14], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3014|  15.0M|    SQRADDAC(a[15], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3015|  15.0M|    SQRADDAC(a[16], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3016|  15.0M|    SQRADDAC(a[17], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3017|  15.0M|    SQRADDAC(a[18], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3018|  15.0M|    SQRADDAC(a[19], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3019|  15.0M|    SQRADDAC(a[20], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3020|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3021|  15.0M|    SQRADD(a[21], a[21]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3022|  15.0M|    COMBA_STORE(b[42]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3023|       |
 3024|       |    /* output 43 */
 3025|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3026|  15.0M|    SQRADDSC(a[12], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3027|  15.0M|    SQRADDAC(a[13], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3028|  15.0M|    SQRADDAC(a[14], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3029|  15.0M|    SQRADDAC(a[15], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3030|  15.0M|    SQRADDAC(a[16], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3031|  15.0M|    SQRADDAC(a[17], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3032|  15.0M|    SQRADDAC(a[18], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3033|  15.0M|    SQRADDAC(a[19], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3034|  15.0M|    SQRADDAC(a[20], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3035|  15.0M|    SQRADDAC(a[21], a[22]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3036|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3037|  15.0M|    COMBA_STORE(b[43]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3038|       |
 3039|       |    /* output 44 */
 3040|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3041|  15.0M|    SQRADDSC(a[13], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3042|  15.0M|    SQRADDAC(a[14], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3043|  15.0M|    SQRADDAC(a[15], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3044|  15.0M|    SQRADDAC(a[16], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3045|  15.0M|    SQRADDAC(a[17], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3046|  15.0M|    SQRADDAC(a[18], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3047|  15.0M|    SQRADDAC(a[19], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3048|  15.0M|    SQRADDAC(a[20], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3049|  15.0M|    SQRADDAC(a[21], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3050|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3051|  15.0M|    SQRADD(a[22], a[22]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3052|  15.0M|    COMBA_STORE(b[44]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3053|       |
 3054|       |    /* output 45 */
 3055|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3056|  15.0M|    SQRADDSC(a[14], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3057|  15.0M|    SQRADDAC(a[15], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3058|  15.0M|    SQRADDAC(a[16], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3059|  15.0M|    SQRADDAC(a[17], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3060|  15.0M|    SQRADDAC(a[18], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3061|  15.0M|    SQRADDAC(a[19], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3062|  15.0M|    SQRADDAC(a[20], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3063|  15.0M|    SQRADDAC(a[21], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3064|  15.0M|    SQRADDAC(a[22], a[23]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3065|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3066|  15.0M|    COMBA_STORE(b[45]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3067|       |
 3068|       |    /* output 46 */
 3069|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3070|  15.0M|    SQRADDSC(a[15], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3071|  15.0M|    SQRADDAC(a[16], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3072|  15.0M|    SQRADDAC(a[17], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3073|  15.0M|    SQRADDAC(a[18], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3074|  15.0M|    SQRADDAC(a[19], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3075|  15.0M|    SQRADDAC(a[20], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3076|  15.0M|    SQRADDAC(a[21], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3077|  15.0M|    SQRADDAC(a[22], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3078|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3079|  15.0M|    SQRADD(a[23], a[23]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3080|  15.0M|    COMBA_STORE(b[46]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3081|       |
 3082|       |    /* output 47 */
 3083|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3084|  15.0M|    SQRADDSC(a[16], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3085|  15.0M|    SQRADDAC(a[17], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3086|  15.0M|    SQRADDAC(a[18], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3087|  15.0M|    SQRADDAC(a[19], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3088|  15.0M|    SQRADDAC(a[20], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3089|  15.0M|    SQRADDAC(a[21], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3090|  15.0M|    SQRADDAC(a[22], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3091|  15.0M|    SQRADDAC(a[23], a[24]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3092|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3093|  15.0M|    COMBA_STORE(b[47]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3094|       |
 3095|       |    /* output 48 */
 3096|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3097|  15.0M|    SQRADDSC(a[17], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3098|  15.0M|    SQRADDAC(a[18], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3099|  15.0M|    SQRADDAC(a[19], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3100|  15.0M|    SQRADDAC(a[20], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3101|  15.0M|    SQRADDAC(a[21], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3102|  15.0M|    SQRADDAC(a[22], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3103|  15.0M|    SQRADDAC(a[23], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3104|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3105|  15.0M|    SQRADD(a[24], a[24]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3106|  15.0M|    COMBA_STORE(b[48]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3107|       |
 3108|       |    /* output 49 */
 3109|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3110|  15.0M|    SQRADDSC(a[18], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3111|  15.0M|    SQRADDAC(a[19], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3112|  15.0M|    SQRADDAC(a[20], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3113|  15.0M|    SQRADDAC(a[21], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3114|  15.0M|    SQRADDAC(a[22], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3115|  15.0M|    SQRADDAC(a[23], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3116|  15.0M|    SQRADDAC(a[24], a[25]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3117|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3118|  15.0M|    COMBA_STORE(b[49]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3119|       |
 3120|       |    /* output 50 */
 3121|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3122|  15.0M|    SQRADDSC(a[19], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3123|  15.0M|    SQRADDAC(a[20], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3124|  15.0M|    SQRADDAC(a[21], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3125|  15.0M|    SQRADDAC(a[22], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3126|  15.0M|    SQRADDAC(a[23], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3127|  15.0M|    SQRADDAC(a[24], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3128|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3129|  15.0M|    SQRADD(a[25], a[25]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3130|  15.0M|    COMBA_STORE(b[50]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3131|       |
 3132|       |    /* output 51 */
 3133|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3134|  15.0M|    SQRADDSC(a[20], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3135|  15.0M|    SQRADDAC(a[21], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3136|  15.0M|    SQRADDAC(a[22], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3137|  15.0M|    SQRADDAC(a[23], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3138|  15.0M|    SQRADDAC(a[24], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3139|  15.0M|    SQRADDAC(a[25], a[26]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3140|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3141|  15.0M|    COMBA_STORE(b[51]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3142|       |
 3143|       |    /* output 52 */
 3144|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3145|  15.0M|    SQRADDSC(a[21], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3146|  15.0M|    SQRADDAC(a[22], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3147|  15.0M|    SQRADDAC(a[23], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3148|  15.0M|    SQRADDAC(a[24], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3149|  15.0M|    SQRADDAC(a[25], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3150|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3151|  15.0M|    SQRADD(a[26], a[26]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3152|  15.0M|    COMBA_STORE(b[52]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3153|       |
 3154|       |    /* output 53 */
 3155|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3156|  15.0M|    SQRADDSC(a[22], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3157|  15.0M|    SQRADDAC(a[23], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3158|  15.0M|    SQRADDAC(a[24], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3159|  15.0M|    SQRADDAC(a[25], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3160|  15.0M|    SQRADDAC(a[26], a[27]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3161|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3162|  15.0M|    COMBA_STORE(b[53]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3163|       |
 3164|       |    /* output 54 */
 3165|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3166|  15.0M|    SQRADDSC(a[23], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3167|  15.0M|    SQRADDAC(a[24], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3168|  15.0M|    SQRADDAC(a[25], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3169|  15.0M|    SQRADDAC(a[26], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3170|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3171|  15.0M|    SQRADD(a[27], a[27]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3172|  15.0M|    COMBA_STORE(b[54]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3173|       |
 3174|       |    /* output 55 */
 3175|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3176|  15.0M|    SQRADDSC(a[24], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3177|  15.0M|    SQRADDAC(a[25], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3178|  15.0M|    SQRADDAC(a[26], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3179|  15.0M|    SQRADDAC(a[27], a[28]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3180|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3181|  15.0M|    COMBA_STORE(b[55]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3182|       |
 3183|       |    /* output 56 */
 3184|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3185|  15.0M|    SQRADDSC(a[25], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3186|  15.0M|    SQRADDAC(a[26], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3187|  15.0M|    SQRADDAC(a[27], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3188|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3189|  15.0M|    SQRADD(a[28], a[28]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3190|  15.0M|    COMBA_STORE(b[56]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3191|       |
 3192|       |    /* output 57 */
 3193|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3194|  15.0M|    SQRADDSC(a[26], a[31]);
  ------------------
  |  |  107|  15.0M|    __asm__(                              \
  |  |  108|  15.0M|        "movq  %3,%%rax     \n\t"         \
  |  |  109|  15.0M|        "mulq  %4           \n\t"         \
  |  |  110|  15.0M|        "movq  %%rax,%0     \n\t"         \
  |  |  111|  15.0M|        "movq  %%rdx,%1     \n\t"         \
  |  |  112|  15.0M|        "xorq  %2,%2        \n\t"         \
  |  |  113|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2) \
  |  |  114|  15.0M|        : "g"(i), "g"(j)                  \
  |  |  115|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3195|  15.0M|    SQRADDAC(a[27], a[30]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3196|  15.0M|    SQRADDAC(a[28], a[29]);
  ------------------
  |  |  118|  15.0M|    __asm__(                                           \
  |  |  119|  15.0M|        "movq  %6,%%rax     \n\t"                      \
  |  |  120|  15.0M|        "mulq  %7           \n\t"                      \
  |  |  121|  15.0M|        "addq  %%rax,%0     \n\t"                      \
  |  |  122|  15.0M|        "adcq  %%rdx,%1     \n\t"                      \
  |  |  123|  15.0M|        "adcq  $0,%2        \n\t"                      \
  |  |  124|  15.0M|        : "=r"(sc0), "=r"(sc1), "=r"(sc2)              \
  |  |  125|  15.0M|        : "0"(sc0), "1"(sc1), "2"(sc2), "g"(i), "g"(j) \
  |  |  126|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3197|  15.0M|    SQRADDDB;
  ------------------
  |  |  129|  15.0M|    __asm__(                                                      \
  |  |  130|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  131|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  132|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  133|  15.0M|        "addq %6,%0         \n\t"                                 \
  |  |  134|  15.0M|        "adcq %7,%1         \n\t"                                 \
  |  |  135|  15.0M|        "adcq %8,%2         \n\t"                                 \
  |  |  136|  15.0M|        : "=&r"(c0), "=&r"(c1), "=&r"(c2)                         \
  |  |  137|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "r"(sc0), "r"(sc1), "r"(sc2) \
  |  |  138|  15.0M|        : "cc");
  ------------------
 3198|  15.0M|    COMBA_STORE(b[57]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3199|       |
 3200|       |    /* output 58 */
 3201|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3202|  15.0M|    SQRADD2(a[27], a[31]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3203|  15.0M|    SQRADD2(a[28], a[30]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3204|  15.0M|    SQRADD(a[29], a[29]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3205|  15.0M|    COMBA_STORE(b[58]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3206|       |
 3207|       |    /* output 59 */
 3208|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3209|  15.0M|    SQRADD2(a[28], a[31]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3210|  15.0M|    SQRADD2(a[29], a[30]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3211|  15.0M|    COMBA_STORE(b[59]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3212|       |
 3213|       |    /* output 60 */
 3214|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3215|  15.0M|    SQRADD2(a[29], a[31]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3216|  15.0M|    SQRADD(a[30], a[30]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3217|  15.0M|    COMBA_STORE(b[60]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3218|       |
 3219|       |    /* output 61 */
 3220|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3221|  15.0M|    SQRADD2(a[30], a[31]);
  ------------------
  |  |   93|  15.0M|    __asm__(                                        \
  |  |   94|  15.0M|        "movq  %6,%%rax     \n\t"                   \
  |  |   95|  15.0M|        "mulq  %7           \n\t"                   \
  |  |   96|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |   97|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |   98|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |   99|  15.0M|        "addq  %%rax,%0     \n\t"                   \
  |  |  100|  15.0M|        "adcq  %%rdx,%1     \n\t"                   \
  |  |  101|  15.0M|        "adcq  $0,%2        \n\t"                   \
  |  |  102|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)              \
  |  |  103|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i), "g"(j) \
  |  |  104|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3222|  15.0M|    COMBA_STORE(b[61]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3223|       |
 3224|       |    /* output 62 */
 3225|  15.0M|    CARRY_FORWARD;
  ------------------
  |  |   73|  15.0M|    do {              \
  |  |   74|  15.0M|        c0 = c1;      \
  |  |   75|  15.0M|        c1 = c2;      \
  |  |   76|  15.0M|        c2 = 0;       \
  |  |   77|  15.0M|    } while (0);
  |  |  ------------------
  |  |  |  Branch (77:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3226|  15.0M|    SQRADD(a[31], a[31]);
  ------------------
  |  |   82|  15.0M|    __asm__(                                \
  |  |   83|  15.0M|        "movq  %6,%%rax     \n\t"           \
  |  |   84|  15.0M|        "mulq  %%rax        \n\t"           \
  |  |   85|  15.0M|        "addq  %%rax,%0     \n\t"           \
  |  |   86|  15.0M|        "adcq  %%rdx,%1     \n\t"           \
  |  |   87|  15.0M|        "adcq  $0,%2        \n\t"           \
  |  |   88|  15.0M|        : "=r"(c0), "=r"(c1), "=r"(c2)      \
  |  |   89|  15.0M|        : "0"(c0), "1"(c1), "2"(c2), "g"(i) \
  |  |   90|  15.0M|        : "%rax", "%rdx", "cc");
  ------------------
 3227|  15.0M|    COMBA_STORE(b[62]);
  ------------------
  |  |   67|  15.0M|    x = c0;
  ------------------
 3228|  15.0M|    COMBA_STORE2(b[63]);
  ------------------
  |  |   70|  15.0M|    x = c1;
  ------------------
 3229|  15.0M|    COMBA_FINI;
 3230|       |
 3231|  15.0M|    B->used = 64;
 3232|  15.0M|    B->sign = ZPOS;
  ------------------
  |  |  326|  15.0M|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|  15.0M|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 3233|  15.0M|    memcpy(B->dp, b, 64 * sizeof(mp_digit));
 3234|  15.0M|    mp_clamp(B);
  ------------------
  |  |   26|  15.0M|    {                                                    \
  |  |   27|  15.5M|        while ((a)->used && (a)->dp[(a)->used - 1] == 0) \
  |  |  ------------------
  |  |  |  Branch (27:16): [True: 15.5M, False: 0]
  |  |  |  Branch (27:29): [True: 517k, False: 15.0M]
  |  |  ------------------
  |  |   28|  15.0M|            --((a)->used);                               \
  |  |   29|  15.0M|        (a)->sign = (a)->used ? (a)->sign : ZPOS;        \
  |  |  ------------------
  |  |  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  |  |  ------------------
  |  |  |  |  |  |   37|  15.0M|#define MP_ZPOS 0
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (29:21): [True: 15.0M, False: 0]
  |  |  ------------------
  |  |   30|  15.0M|    }
  ------------------
 3235|  15.0M|}

freebl_cpuid:
   41|      5|{
   42|      5|    __asm__("xor %%ecx, %%ecx\n\t"
   43|      5|            "cpuid\n\t"
   44|      5|            : "=a"(*eax),
   45|      5|              "=b"(*ebx),
   46|      5|              "=c"(*ecx),
   47|      5|              "=d"(*edx)
   48|      5|            : "0"(op));
   49|      5|}
s_mpi_getProcessorLineSize:
  653|      1|{
  654|      1|    unsigned long eax, ebx, ecx, edx;
  655|      1|    PRUint32 cpuid[3];
  656|      1|    unsigned long cpuidLevel;
  657|      1|    unsigned long cacheLineSize = 0;
  658|      1|    int manufacturer = MAN_UNKNOWN;
  ------------------
  |  |  627|      1|#define MAN_UNKNOWN 9
  ------------------
  659|      1|    int i;
  660|      1|    char string[13];
  661|       |
  662|       |#if !defined(AMD_64)
  663|       |    if (is386()) {
  664|       |        return 0; /* 386 had no cache */
  665|       |    }
  666|       |    if (is486()) {
  667|       |        return 32; /* really? need more info */
  668|       |    }
  669|       |#endif
  670|       |
  671|       |    /* Pentium, cpuid command is available */
  672|      1|    freebl_cpuid(0, &eax, &ebx, &ecx, &edx);
  673|      1|    cpuidLevel = eax;
  674|       |    /* string holds the CPU's manufacturer ID string - a twelve
  675|       |     * character ASCII string stored in ebx, edx, ecx, and
  676|       |     * the 32-bit extended feature flags are in edx, ecx.
  677|       |     */
  678|      1|    cpuid[0] = ebx;
  679|      1|    cpuid[1] = ecx;
  680|      1|    cpuid[2] = edx;
  681|      1|    memcpy(string, cpuid, sizeof(cpuid));
  682|      1|    string[12] = 0;
  683|       |
  684|      1|    manufacturer = MAN_UNKNOWN;
  ------------------
  |  |  627|      1|#define MAN_UNKNOWN 9
  ------------------
  685|     11|    for (i = 0; i < n_manufacturers; i++) {
  ------------------
  |  Branch (685:17): [True: 10, False: 1]
  ------------------
  686|     10|        if (strcmp(manMap[i], string) == 0) {
  ------------------
  |  Branch (686:13): [True: 0, False: 10]
  ------------------
  687|      0|            manufacturer = i;
  688|      0|        }
  689|     10|    }
  690|       |
  691|      1|    if (manufacturer == INTEL) {
  ------------------
  |  |  603|      1|#define INTEL 0
  ------------------
  |  Branch (691:9): [True: 0, False: 1]
  ------------------
  692|      0|        cacheLineSize = getIntelCacheLineSize(cpuidLevel);
  693|      1|    } else {
  694|      1|        cacheLineSize = getOtherCacheLineSize(cpuidLevel);
  695|      1|    }
  696|       |    /* doesn't support cache info based on cpuid. This means
  697|       |     * an old pentium class processor, which have cache lines of
  698|       |     * 32. If we learn differently, we can use a switch based on
  699|       |     * the Manufacturer id  */
  700|      1|    if (cacheLineSize == 0) {
  ------------------
  |  Branch (700:9): [True: 0, False: 1]
  ------------------
  701|      0|        cacheLineSize = 32;
  702|      0|    }
  703|      1|    return cacheLineSize;
  704|      1|}
mpcpucache.c:getOtherCacheLineSize:
  587|      1|{
  588|      1|    unsigned long lineSize = 0;
  589|      1|    unsigned long eax, ebx, ecx, edx;
  590|       |
  591|       |    /* get the Extended CPUID level */
  592|      1|    freebl_cpuid(0x80000000, &eax, &ebx, &ecx, &edx);
  593|      1|    cpuidLevel = eax;
  594|       |
  595|      1|    if (cpuidLevel >= 0x80000005) {
  ------------------
  |  Branch (595:9): [True: 1, False: 0]
  ------------------
  596|      1|        freebl_cpuid(0x80000005, &eax, &ebx, &ecx, &edx);
  597|      1|        lineSize = ecx & 0xff; /* line Size, L1 Data Cache */
  598|      1|    }
  599|      1|    return lineSize;
  600|      1|}

mp_init:
  121|  1.10M|{
  122|  1.10M|    return mp_init_size(mp, s_mp_defprec);
  123|       |
  124|  1.10M|} /* end mp_init() */
mp_init_size:
  140|  3.63M|{
  141|  3.63M|    ARGCHK(mp != NULL && prec > 0, MP_BADARG);
  ------------------
  |  |  355|  3.63M|#define ARGCHK(X, Y) assert(X)
  ------------------
  142|       |
  143|  3.63M|    prec = MP_ROUNDUP(prec, s_mp_defprec);
  ------------------
  |  |   89|  3.63M|#define MP_ROUNDUP(a, b) (MP_HOWMANY(a, b) * (b))
  |  |  ------------------
  |  |  |  |   88|  3.63M|#define MP_HOWMANY(a, b) (((a) + (b)-1) / (b))
  |  |  ------------------
  ------------------
  144|  3.63M|    if ((DIGITS(mp) = s_mp_alloc(prec, sizeof(mp_digit))) == NULL)
  ------------------
  |  |  335|  3.63M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  3.63M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  |  Branch (144:9): [True: 0, False: 3.63M]
  ------------------
  145|      0|        return MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
  146|       |
  147|  3.63M|    SIGN(mp) = ZPOS;
  ------------------
  |  |  332|  3.63M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  3.63M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(mp) = ZPOS;
  ------------------
  |  |  326|  3.63M|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|  3.63M|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  148|  3.63M|    USED(mp) = 1;
  ------------------
  |  |  333|  3.63M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  3.63M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  149|  3.63M|    ALLOC(mp) = prec;
  ------------------
  |  |  334|  3.63M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  3.63M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  150|       |
  151|  3.63M|    return MP_OKAY;
  ------------------
  |  |   39|  3.63M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  152|       |
  153|  3.63M|} /* end mp_init_size() */
mp_init_copy:
  169|  1.35M|{
  170|  1.35M|    ARGCHK(mp != NULL && from != NULL, MP_BADARG);
  ------------------
  |  |  355|  1.35M|#define ARGCHK(X, Y) assert(X)
  ------------------
  171|       |
  172|  1.35M|    if (mp == from)
  ------------------
  |  Branch (172:9): [True: 0, False: 1.35M]
  ------------------
  173|      0|        return MP_OKAY;
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  174|       |
  175|  1.35M|    if ((DIGITS(mp) = s_mp_alloc(ALLOC(from), sizeof(mp_digit))) == NULL)
  ------------------
  |  |  335|  1.35M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  1.35M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                  if ((DIGITS(mp) = s_mp_alloc(ALLOC(from), sizeof(mp_digit))) == NULL)
  ------------------
  |  |  334|  1.35M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  1.35M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  |  Branch (175:9): [True: 0, False: 1.35M]
  ------------------
  176|      0|        return MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
  177|       |
  178|  1.35M|    s_mp_copy(DIGITS(from), DIGITS(mp), USED(from));
  ------------------
  |  |  335|  1.35M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  1.35M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                  s_mp_copy(DIGITS(from), DIGITS(mp), USED(from));
  ------------------
  |  |  335|  1.35M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  1.35M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                  s_mp_copy(DIGITS(from), DIGITS(mp), USED(from));
  ------------------
  |  |  333|  1.35M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  1.35M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  179|  1.35M|    USED(mp) = USED(from);
  ------------------
  |  |  333|  1.35M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  1.35M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  USED(mp) = USED(from);
  ------------------
  |  |  333|  1.35M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  1.35M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  180|  1.35M|    ALLOC(mp) = ALLOC(from);
  ------------------
  |  |  334|  1.35M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  1.35M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
                  ALLOC(mp) = ALLOC(from);
  ------------------
  |  |  334|  1.35M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  1.35M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  181|  1.35M|    SIGN(mp) = SIGN(from);
  ------------------
  |  |  332|  1.35M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  1.35M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(mp) = SIGN(from);
  ------------------
  |  |  332|  1.35M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  1.35M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
  182|       |
  183|  1.35M|    return MP_OKAY;
  ------------------
  |  |   39|  1.35M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  184|       |
  185|  1.35M|} /* end mp_init_copy() */
mp_copy:
  201|  6.40M|{
  202|  6.40M|    ARGCHK(from != NULL && to != NULL, MP_BADARG);
  ------------------
  |  |  355|  6.40M|#define ARGCHK(X, Y) assert(X)
  ------------------
  203|       |
  204|  6.40M|    if (from == to)
  ------------------
  |  Branch (204:9): [True: 67.8k, False: 6.34M]
  ------------------
  205|  67.8k|        return MP_OKAY;
  ------------------
  |  |   39|  67.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  206|       |
  207|  6.34M|    { /* copy */
  208|  6.34M|        mp_digit *tmp;
  209|       |
  210|       |        /*
  211|       |          If the allocated buffer in 'to' already has enough space to hold
  212|       |          all the used digits of 'from', we'll re-use it to avoid hitting
  213|       |          the memory allocater more than necessary; otherwise, we'd have
  214|       |          to grow anyway, so we just allocate a hunk and make the copy as
  215|       |          usual
  216|       |         */
  217|  6.34M|        if (ALLOC(to) >= USED(from)) {
  ------------------
  |  |  334|  6.34M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  6.34M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
                      if (ALLOC(to) >= USED(from)) {
  ------------------
  |  |  333|  6.34M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  6.34M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (217:13): [True: 6.34M, False: 0]
  ------------------
  218|  6.34M|            s_mp_setz(DIGITS(to) + USED(from), ALLOC(to) - USED(from));
  ------------------
  |  |  335|  6.34M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  6.34M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                          s_mp_setz(DIGITS(to) + USED(from), ALLOC(to) - USED(from));
  ------------------
  |  |  333|  6.34M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  6.34M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                          s_mp_setz(DIGITS(to) + USED(from), ALLOC(to) - USED(from));
  ------------------
  |  |  334|  6.34M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  6.34M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
                          s_mp_setz(DIGITS(to) + USED(from), ALLOC(to) - USED(from));
  ------------------
  |  |  333|  6.34M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  6.34M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  219|  6.34M|            s_mp_copy(DIGITS(from), DIGITS(to), USED(from));
  ------------------
  |  |  335|  6.34M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  6.34M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                          s_mp_copy(DIGITS(from), DIGITS(to), USED(from));
  ------------------
  |  |  335|  6.34M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  6.34M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                          s_mp_copy(DIGITS(from), DIGITS(to), USED(from));
  ------------------
  |  |  333|  6.34M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  6.34M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  220|       |
  221|  6.34M|        } else {
  222|      0|            if ((tmp = s_mp_alloc(ALLOC(from), sizeof(mp_digit))) == NULL)
  ------------------
  |  |  334|      0|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|      0|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  |  Branch (222:17): [True: 0, False: 0]
  ------------------
  223|      0|                return MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
  224|       |
  225|      0|            s_mp_copy(DIGITS(from), tmp, USED(from));
  ------------------
  |  |  335|      0|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|      0|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                          s_mp_copy(DIGITS(from), tmp, USED(from));
  ------------------
  |  |  333|      0|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      0|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  226|       |
  227|      0|            if (DIGITS(to) != NULL) {
  ------------------
  |  |  335|      0|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|      0|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  |  Branch (227:17): [True: 0, False: 0]
  ------------------
  228|      0|                s_mp_setz(DIGITS(to), ALLOC(to));
  ------------------
  |  |  335|      0|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|      0|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                              s_mp_setz(DIGITS(to), ALLOC(to));
  ------------------
  |  |  334|      0|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|      0|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  229|      0|                s_mp_free(DIGITS(to));
  ------------------
  |  |  335|      0|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|      0|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  230|      0|            }
  231|       |
  232|      0|            DIGITS(to) = tmp;
  ------------------
  |  |  335|      0|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|      0|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  233|      0|            ALLOC(to) = ALLOC(from);
  ------------------
  |  |  334|      0|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|      0|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
                          ALLOC(to) = ALLOC(from);
  ------------------
  |  |  334|      0|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|      0|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  234|      0|        }
  235|       |
  236|       |        /* Copy the precision and sign from the original */
  237|  6.34M|        USED(to) = USED(from);
  ------------------
  |  |  333|  6.34M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  6.34M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                      USED(to) = USED(from);
  ------------------
  |  |  333|  6.34M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  6.34M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  238|  6.34M|        SIGN(to) = SIGN(from);
  ------------------
  |  |  332|  6.34M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  6.34M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(to) = SIGN(from);
  ------------------
  |  |  332|  6.34M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  6.34M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
  239|  6.34M|    } /* end copy */
  240|       |
  241|  6.34M|    return MP_OKAY;
  ------------------
  |  |   39|  6.34M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  242|       |
  243|  6.34M|} /* end mp_copy() */
mp_exch:
  259|   194k|{
  260|   194k|#if MP_ARGCHK == 2
  261|   194k|    assert(mp1 != NULL && mp2 != NULL);
  262|       |#else
  263|       |    if (mp1 == NULL || mp2 == NULL)
  264|       |        return;
  265|       |#endif
  266|       |
  267|   194k|    s_mp_exch(mp1, mp2);
  268|       |
  269|   194k|} /* end mp_exch() */
mp_clear:
  285|   112M|{
  286|   112M|    if (mp == NULL)
  ------------------
  |  Branch (286:9): [True: 0, False: 112M]
  ------------------
  287|      0|        return;
  288|       |
  289|   112M|    if (DIGITS(mp) != NULL) {
  ------------------
  |  |  335|   112M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   112M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  |  Branch (289:9): [True: 4.98M, False: 107M]
  ------------------
  290|  4.98M|        s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  335|  4.98M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  4.98M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                      s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  334|  4.98M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  4.98M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  291|  4.98M|        s_mp_free(DIGITS(mp));
  ------------------
  |  |  335|  4.98M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  4.98M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  292|  4.98M|        DIGITS(mp) = NULL;
  ------------------
  |  |  335|  4.98M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  4.98M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  293|  4.98M|    }
  294|       |
  295|   112M|    USED(mp) = 0;
  ------------------
  |  |  333|   112M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   112M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  296|   112M|    ALLOC(mp) = 0;
  ------------------
  |  |  334|   112M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|   112M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  297|       |
  298|   112M|} /* end mp_clear() */
mp_zero:
  312|   826k|{
  313|   826k|    if (mp == NULL)
  ------------------
  |  Branch (313:9): [True: 0, False: 826k]
  ------------------
  314|      0|        return;
  315|       |
  316|   826k|    s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  335|   826k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   826k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                  s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  334|   826k|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|   826k|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  317|   826k|    USED(mp) = 1;
  ------------------
  |  |  333|   826k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   826k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  318|   826k|    SIGN(mp) = ZPOS;
  ------------------
  |  |  332|   826k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   826k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(mp) = ZPOS;
  ------------------
  |  |  326|   826k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   826k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  319|       |
  320|   826k|} /* end mp_zero() */
mp_set:
  328|   161k|{
  329|   161k|    if (mp == NULL)
  ------------------
  |  Branch (329:9): [True: 0, False: 161k]
  ------------------
  330|      0|        return;
  331|       |
  332|   161k|    mp_zero(mp);
  333|   161k|    DIGIT(mp, 0) = d;
  ------------------
  |  |  336|   161k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   161k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  334|       |
  335|   161k|} /* end mp_set() */
mp_set_int:
  343|  72.4k|{
  344|  72.4k|    unsigned long v = labs(z);
  345|  72.4k|    mp_err res;
  346|       |
  347|  72.4k|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|  72.4k|#define ARGCHK(X, Y) assert(X)
  ------------------
  348|       |
  349|       |    /* https://bugzilla.mozilla.org/show_bug.cgi?id=1509432 */
  350|  72.4k|    if ((res = mp_set_ulong(mp, v)) != MP_OKAY) { /* avoids duplicated code */
  ------------------
  |  |   39|  72.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (350:9): [True: 0, False: 72.4k]
  ------------------
  351|      0|        return res;
  352|      0|    }
  353|       |
  354|  72.4k|    if (z < 0) {
  ------------------
  |  Branch (354:9): [True: 0, False: 72.4k]
  ------------------
  355|      0|        SIGN(mp) = NEG;
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(mp) = NEG;
  ------------------
  |  |  325|      0|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|      0|#define MP_NEG 1
  |  |  ------------------
  ------------------
  356|      0|    }
  357|       |
  358|  72.4k|    return MP_OKAY;
  ------------------
  |  |   39|  72.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  359|  72.4k|} /* end mp_set_int() */
mp_set_ulong:
  367|  72.4k|{
  368|  72.4k|    int ix;
  369|  72.4k|    mp_err res;
  370|       |
  371|  72.4k|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|  72.4k|#define ARGCHK(X, Y) assert(X)
  ------------------
  372|       |
  373|  72.4k|    mp_zero(mp);
  374|  72.4k|    if (z == 0)
  ------------------
  |  Branch (374:9): [True: 0, False: 72.4k]
  ------------------
  375|      0|        return MP_OKAY; /* shortcut for zero */
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  376|       |
  377|  72.4k|    if (sizeof z <= sizeof(mp_digit)) {
  ------------------
  |  Branch (377:9): [Folded - Ignored]
  ------------------
  378|  72.4k|        DIGIT(mp, 0) = z;
  ------------------
  |  |  336|  72.4k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  72.4k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  379|  72.4k|    } else {
  380|      0|        for (ix = sizeof(long) - 1; ix >= 0; ix--) {
  ------------------
  |  Branch (380:37): [True: 0, False: 0]
  ------------------
  381|      0|            if ((res = s_mp_mul_d(mp, (UCHAR_MAX + 1))) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (381:17): [True: 0, False: 0]
  ------------------
  382|      0|                return res;
  383|       |
  384|      0|            res = s_mp_add_d(mp, (mp_digit)((z >> (ix * CHAR_BIT)) & UCHAR_MAX));
  385|      0|            if (res != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (385:17): [True: 0, False: 0]
  ------------------
  386|      0|                return res;
  387|      0|        }
  388|      0|    }
  389|  72.4k|    return MP_OKAY;
  ------------------
  |  |   39|  72.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  390|  72.4k|} /* end mp_set_ulong() */
mp_sub_d:
  453|  56.8k|{
  454|  56.8k|    mp_int tmp;
  455|  56.8k|    mp_err res;
  456|       |
  457|  56.8k|    ARGCHK(a != NULL && b != NULL, MP_BADARG);
  ------------------
  |  |  355|  56.8k|#define ARGCHK(X, Y) assert(X)
  ------------------
  458|       |
  459|  56.8k|    if ((res = mp_init_copy(&tmp, a)) != MP_OKAY)
  ------------------
  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (459:9): [True: 0, False: 56.8k]
  ------------------
  460|      0|        return res;
  461|       |
  462|  56.8k|    if (SIGN(&tmp) == NEG) {
  ------------------
  |  |  332|  56.8k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  56.8k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(&tmp) == NEG) {
  ------------------
  |  |  325|  56.8k|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|  56.8k|#define MP_NEG 1
  |  |  ------------------
  ------------------
  |  Branch (462:9): [True: 0, False: 56.8k]
  ------------------
  463|      0|        if ((res = s_mp_add_d(&tmp, d)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (463:13): [True: 0, False: 0]
  ------------------
  464|      0|            goto CLEANUP;
  465|  56.8k|    } else if (s_mp_cmp_d(&tmp, d) >= 0) {
  ------------------
  |  Branch (465:16): [True: 56.8k, False: 0]
  ------------------
  466|  56.8k|        if ((res = s_mp_sub_d(&tmp, d)) != MP_OKAY)
  ------------------
  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (466:13): [True: 0, False: 56.8k]
  ------------------
  467|      0|            goto CLEANUP;
  468|  56.8k|    } else {
  469|      0|        mp_neg(&tmp, &tmp);
  470|       |
  471|      0|        DIGIT(&tmp, 0) = d - DIGIT(&tmp, 0);
  ------------------
  |  |  336|      0|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      0|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
                      DIGIT(&tmp, 0) = d - DIGIT(&tmp, 0);
  ------------------
  |  |  336|      0|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      0|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  472|      0|        SIGN(&tmp) = NEG;
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(&tmp) = NEG;
  ------------------
  |  |  325|      0|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|      0|#define MP_NEG 1
  |  |  ------------------
  ------------------
  473|      0|    }
  474|       |
  475|  56.8k|    if (s_mp_cmp_d(&tmp, 0) == 0)
  ------------------
  |  Branch (475:9): [True: 0, False: 56.8k]
  ------------------
  476|      0|        SIGN(&tmp) = ZPOS;
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(&tmp) = ZPOS;
  ------------------
  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|      0|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  477|       |
  478|  56.8k|    s_mp_exch(&tmp, b);
  479|       |
  480|  56.8k|CLEANUP:
  481|  56.8k|    mp_clear(&tmp);
  482|  56.8k|    return res;
  483|       |
  484|  56.8k|} /* end mp_sub_d() */
mp_add:
  741|   167k|{
  742|   167k|    mp_err res;
  743|       |
  744|   167k|    ARGCHK(a != NULL && b != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|   167k|#define ARGCHK(X, Y) assert(X)
  ------------------
  745|       |
  746|   167k|    if (SIGN(a) == SIGN(b)) { /* same sign:  add values, keep sign */
  ------------------
  |  |  332|   167k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   167k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(a) == SIGN(b)) { /* same sign:  add values, keep sign */
  ------------------
  |  |  332|   167k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   167k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
  |  Branch (746:9): [True: 130k, False: 36.4k]
  ------------------
  747|   130k|        MP_CHECKOK(s_mp_add_3arg(a, b, c));
  ------------------
  |  |  319|   130k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   130k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 130k]
  |  |  ------------------
  |  |  320|   130k|    goto CLEANUP
  ------------------
  748|   130k|    } else if (s_mp_cmp(a, b) >= 0) { /* different sign: |a| >= |b|   */
  ------------------
  |  Branch (748:16): [True: 7.37k, False: 29.0k]
  ------------------
  749|  7.37k|        MP_CHECKOK(s_mp_sub_3arg(a, b, c));
  ------------------
  |  |  319|  7.37k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  7.37k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 7.37k]
  |  |  ------------------
  |  |  320|  7.37k|    goto CLEANUP
  ------------------
  750|  29.0k|    } else { /* different sign: |a|  < |b|   */
  751|  29.0k|        MP_CHECKOK(s_mp_sub_3arg(b, a, c));
  ------------------
  |  |  319|  29.0k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |  320|  29.0k|    goto CLEANUP
  ------------------
  752|  29.0k|    }
  753|       |
  754|   167k|    if (s_mp_cmp_d(c, 0) == MP_EQ)
  ------------------
  |  |   50|   167k|#define MP_EQ 0
  ------------------
  |  Branch (754:9): [True: 80, False: 167k]
  ------------------
  755|     80|        SIGN(c) = ZPOS;
  ------------------
  |  |  332|     80|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|     80|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(c) = ZPOS;
  ------------------
  |  |  326|     80|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|     80|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  756|       |
  757|   167k|CLEANUP:
  758|   167k|    return res;
  759|       |
  760|   167k|} /* end mp_add() */
mp_sub:
  774|   166k|{
  775|   166k|    mp_err res;
  776|   166k|    int magDiff;
  777|       |
  778|   166k|    ARGCHK(a != NULL && b != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|   166k|#define ARGCHK(X, Y) assert(X)
  ------------------
  779|       |
  780|   166k|    if (a == b) {
  ------------------
  |  Branch (780:9): [True: 0, False: 166k]
  ------------------
  781|      0|        mp_zero(c);
  782|      0|        return MP_OKAY;
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  783|      0|    }
  784|       |
  785|   166k|    if (MP_SIGN(a) != MP_SIGN(b)) {
  ------------------
  |  |  149|   166k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  if (MP_SIGN(a) != MP_SIGN(b)) {
  ------------------
  |  |  149|   166k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
  |  Branch (785:9): [True: 0, False: 166k]
  ------------------
  786|      0|        MP_CHECKOK(s_mp_add_3arg(a, b, c));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
  787|   166k|    } else if (!(magDiff = s_mp_cmp(a, b))) {
  ------------------
  |  Branch (787:16): [True: 460, False: 165k]
  ------------------
  788|    460|        mp_zero(c);
  789|    460|        res = MP_OKAY;
  ------------------
  |  |   39|    460|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  790|   165k|    } else if (magDiff > 0) {
  ------------------
  |  Branch (790:16): [True: 150k, False: 15.5k]
  ------------------
  791|   150k|        MP_CHECKOK(s_mp_sub_3arg(a, b, c));
  ------------------
  |  |  319|   150k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   150k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 150k]
  |  |  ------------------
  |  |  320|   150k|    goto CLEANUP
  ------------------
  792|   150k|    } else {
  793|  15.5k|        MP_CHECKOK(s_mp_sub_3arg(b, a, c));
  ------------------
  |  |  319|  15.5k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  15.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 15.5k]
  |  |  ------------------
  |  |  320|  15.5k|    goto CLEANUP
  ------------------
  794|  15.5k|        MP_SIGN(c) = !MP_SIGN(a);
  ------------------
  |  |  149|  15.5k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                      MP_SIGN(c) = !MP_SIGN(a);
  ------------------
  |  |  149|  15.5k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
  795|  15.5k|    }
  796|       |
  797|   166k|    if (s_mp_cmp_d(c, 0) == MP_EQ)
  ------------------
  |  |   50|   166k|#define MP_EQ 0
  ------------------
  |  Branch (797:9): [True: 460, False: 165k]
  ------------------
  798|    460|        MP_SIGN(c) = MP_ZPOS;
  ------------------
  |  |  149|    460|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                      MP_SIGN(c) = MP_ZPOS;
  ------------------
  |  |   37|    460|#define MP_ZPOS 0
  ------------------
  799|       |
  800|   166k|CLEANUP:
  801|   166k|    return res;
  802|       |
  803|   166k|} /* end mp_sub() */
s_mp_mulg:
  819|   349k|{
  820|   349k|    mp_digit *pb;
  821|   349k|    mp_int tmp;
  822|   349k|    mp_err res;
  823|   349k|    mp_size ib;
  824|   349k|    mp_size useda, usedb;
  825|       |
  826|   349k|    ARGCHK(a != NULL && b != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|   349k|#define ARGCHK(X, Y) assert(X)
  ------------------
  827|       |
  828|   349k|    if (a == c) {
  ------------------
  |  Branch (828:9): [True: 312k, False: 36.2k]
  ------------------
  829|   312k|        if ((res = mp_init_copy(&tmp, a)) != MP_OKAY)
  ------------------
  |  |   39|   312k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (829:13): [True: 0, False: 312k]
  ------------------
  830|      0|            return res;
  831|   312k|        if (a == b)
  ------------------
  |  Branch (831:13): [True: 0, False: 312k]
  ------------------
  832|      0|            b = &tmp;
  833|   312k|        a = &tmp;
  834|   312k|    } else if (b == c) {
  ------------------
  |  Branch (834:16): [True: 0, False: 36.2k]
  ------------------
  835|      0|        if ((res = mp_init_copy(&tmp, b)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (835:13): [True: 0, False: 0]
  ------------------
  836|      0|            return res;
  837|      0|        b = &tmp;
  838|  36.2k|    } else {
  839|  36.2k|        MP_DIGITS(&tmp) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  840|  36.2k|    }
  841|       |
  842|   349k|    if (MP_USED(a) < MP_USED(b)) {
  ------------------
  |  |  150|   349k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if (MP_USED(a) < MP_USED(b)) {
  ------------------
  |  |  150|   349k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (842:9): [True: 17.2k, False: 331k]
  ------------------
  843|  17.2k|        const mp_int *xch = b; /* switch a and b, to do fewer outer loops */
  844|  17.2k|        b = a;
  845|  17.2k|        a = xch;
  846|  17.2k|    }
  847|       |
  848|   349k|    MP_USED(c) = 1;
  ------------------
  |  |  150|   349k|#define MP_USED(MP) ((MP)->used)
  ------------------
  849|   349k|    MP_DIGIT(c, 0) = 0;
  ------------------
  |  |  153|   349k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  850|   349k|    if ((res = s_mp_pad(c, USED(a) + USED(b))) != MP_OKAY)
  ------------------
  |  |  333|   349k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   349k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  if ((res = s_mp_pad(c, USED(a) + USED(b))) != MP_OKAY)
  ------------------
  |  |  333|   349k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   349k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  if ((res = s_mp_pad(c, USED(a) + USED(b))) != MP_OKAY)
  ------------------
  |  |   39|   349k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (850:9): [True: 0, False: 349k]
  ------------------
  851|      0|        goto CLEANUP;
  852|       |
  853|   349k|#ifdef NSS_USE_COMBA
  854|       |    /* comba isn't constant time because it clamps! If we cared
  855|       |     * (we needed a constant time version of multiply that was 'faster'
  856|       |     * we could easily pass constantTime down to the comba code and
  857|       |     * get it to skip the clamp... but here are assembler versions
  858|       |     * which add comba to platforms that can't compile the normal
  859|       |     * comba's imbedded assembler which would also need to change, so
  860|       |     * for now we just skip comba when we are running constant time. */
  861|   349k|    if (!constantTime && (MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
  ------------------
  |  |  150|   312k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if (!constantTime && (MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
  ------------------
  |  |  150|   312k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if (!constantTime && (MP_USED(a) == MP_USED(b)) && IS_POWER_OF_2(MP_USED(b))) {
  ------------------
  |  |  153|   222k|#define IS_POWER_OF_2(a) ((a) && !((a) & ((a)-1)))
  |  |  ------------------
  |  |  |  Branch (153:27): [True: 222k, False: 0]
  |  |  |  Branch (153:34): [True: 172k, False: 50.9k]
  |  |  ------------------
  ------------------
  |  Branch (861:9): [True: 312k, False: 36.2k]
  |  Branch (861:26): [True: 222k, False: 90.0k]
  ------------------
  862|   172k|        if (MP_USED(a) == 4) {
  ------------------
  |  |  150|   172k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (862:13): [True: 49, False: 171k]
  ------------------
  863|     49|            s_mp_mul_comba_4(a, b, c);
  864|     49|            goto CLEANUP;
  865|     49|        }
  866|   171k|        if (MP_USED(a) == 8) {
  ------------------
  |  |  150|   171k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (866:13): [True: 46, False: 171k]
  ------------------
  867|     46|            s_mp_mul_comba_8(a, b, c);
  868|     46|            goto CLEANUP;
  869|     46|        }
  870|   171k|        if (MP_USED(a) == 16) {
  ------------------
  |  |  150|   171k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (870:13): [True: 135k, False: 36.6k]
  ------------------
  871|   135k|            s_mp_mul_comba_16(a, b, c);
  872|   135k|            goto CLEANUP;
  873|   135k|        }
  874|  36.6k|        if (MP_USED(a) == 32) {
  ------------------
  |  |  150|  36.6k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (874:13): [True: 36.2k, False: 374]
  ------------------
  875|  36.2k|            s_mp_mul_comba_32(a, b, c);
  876|  36.2k|            goto CLEANUP;
  877|  36.2k|        }
  878|  36.6k|    }
  879|   177k|#endif
  880|       |
  881|   177k|    pb = MP_DIGITS(b);
  ------------------
  |  |  152|   177k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  882|   177k|    s_mpv_mul_d(MP_DIGITS(a), MP_USED(a), *pb++, MP_DIGITS(c));
  ------------------
  |  |  181|   177k|    ((mp_digit *)c)[a_len] = s_mpv_mul_set_vec64(c, a, a_len, b)
  ------------------
  883|       |
  884|       |    /* Outer loop:  Digits of b */
  885|   177k|    useda = MP_USED(a);
  ------------------
  |  |  150|   177k|#define MP_USED(MP) ((MP)->used)
  ------------------
  886|   177k|    usedb = MP_USED(b);
  ------------------
  |  |  150|   177k|#define MP_USED(MP) ((MP)->used)
  ------------------
  887|  2.26M|    for (ib = 1; ib < usedb; ib++) {
  ------------------
  |  Branch (887:18): [True: 2.08M, False: 177k]
  ------------------
  888|  2.08M|        mp_digit b_i = *pb++;
  889|       |
  890|       |        /* Inner product:  Digits of a */
  891|  2.08M|        if (constantTime || b_i)
  ------------------
  |  Branch (891:13): [True: 1.12M, False: 965k]
  |  Branch (891:29): [True: 918k, False: 46.9k]
  ------------------
  892|  2.04M|            s_mpv_mul_d_add(MP_DIGITS(a), useda, b_i, MP_DIGITS(c) + ib);
  ------------------
  |  |  185|  2.04M|    ((mp_digit *)c)[a_len] = s_mpv_mul_add_vec64(c, a, a_len, b)
  ------------------
  893|  46.9k|        else
  894|  46.9k|            MP_DIGIT(c, ib + useda) = b_i;
  ------------------
  |  |  153|  46.9k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  895|  2.08M|    }
  896|       |
  897|   177k|    if (!constantTime) {
  ------------------
  |  Branch (897:9): [True: 141k, False: 36.2k]
  ------------------
  898|   141k|        s_mp_clamp(c);
  899|   141k|    }
  900|       |
  901|   177k|    if (SIGN(a) == SIGN(b) || s_mp_cmp_d(c, 0) == MP_EQ)
  ------------------
  |  |  332|   177k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   177k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(a) == SIGN(b) || s_mp_cmp_d(c, 0) == MP_EQ)
  ------------------
  |  |  332|   177k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   355k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(a) == SIGN(b) || s_mp_cmp_d(c, 0) == MP_EQ)
  ------------------
  |  |   50|      0|#define MP_EQ 0
  ------------------
  |  Branch (901:9): [True: 177k, False: 0]
  |  Branch (901:31): [True: 0, False: 0]
  ------------------
  902|   177k|        SIGN(c) = ZPOS;
  ------------------
  |  |  332|   177k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   177k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(c) = ZPOS;
  ------------------
  |  |  326|   177k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   177k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  903|      0|    else
  904|      0|        SIGN(c) = NEG;
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(c) = NEG;
  ------------------
  |  |  325|      0|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|      0|#define MP_NEG 1
  |  |  ------------------
  ------------------
  905|       |
  906|   349k|CLEANUP:
  907|   349k|    mp_clear(&tmp);
  908|   349k|    return res;
  909|   177k|} /* end smp_mulg() */
mp_mul:
  923|   312k|{
  924|   312k|    return s_mp_mulg(a, b, c, 0);
  925|   312k|} /* end mp_mul() */
mp_mulCT:
  940|  36.2k|{
  941|  36.2k|    mp_err res;
  942|       |
  943|       |    /* make the multiply values fixed length so multiply
  944|       |     * doesn't leak the length. at this point all the
  945|       |     * values are blinded, but once we finish we want the
  946|       |     * output size to be hidden (so no clamping the out put) */
  947|  36.2k|    MP_CHECKOK(s_mp_pad(a, setSize));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
  948|  36.2k|    MP_CHECKOK(s_mp_pad(b, setSize));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
  949|  36.2k|    MP_CHECKOK(s_mp_pad(c, 2 * setSize));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
  950|  36.2k|    MP_CHECKOK(s_mp_mulg(a, b, c, 1));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
  951|  36.2k|CLEANUP:
  952|  36.2k|    return res;
  953|  36.2k|} /* end mp_mulCT() */
mp_sqr:
  971|   106M|{
  972|   106M|    mp_digit *pa;
  973|   106M|    mp_digit d;
  974|   106M|    mp_err res;
  975|   106M|    mp_size ix;
  976|   106M|    mp_int tmp;
  977|   106M|    int count;
  978|       |
  979|   106M|    ARGCHK(a != NULL && sqr != NULL, MP_BADARG);
  ------------------
  |  |  355|   106M|#define ARGCHK(X, Y) assert(X)
  ------------------
  980|       |
  981|   106M|    if (a == sqr) {
  ------------------
  |  Branch (981:9): [True: 0, False: 106M]
  ------------------
  982|      0|        if ((res = mp_init_copy(&tmp, a)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (982:13): [True: 0, False: 0]
  ------------------
  983|      0|            return res;
  984|      0|        a = &tmp;
  985|   106M|    } else {
  986|   106M|        DIGITS(&tmp) = 0;
  ------------------
  |  |  335|   106M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   106M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  987|   106M|        res = MP_OKAY;
  ------------------
  |  |   39|   106M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  988|   106M|    }
  989|       |
  990|   106M|    ix = 2 * MP_USED(a);
  ------------------
  |  |  150|   106M|#define MP_USED(MP) ((MP)->used)
  ------------------
  991|   106M|    if (ix > MP_ALLOC(sqr)) {
  ------------------
  |  |  151|   106M|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
  |  Branch (991:9): [True: 0, False: 106M]
  ------------------
  992|      0|        MP_USED(sqr) = 1;
  ------------------
  |  |  150|      0|#define MP_USED(MP) ((MP)->used)
  ------------------
  993|      0|        MP_CHECKOK(s_mp_grow(sqr, ix));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
  994|      0|    }
  995|   106M|    MP_USED(sqr) = ix;
  ------------------
  |  |  150|   106M|#define MP_USED(MP) ((MP)->used)
  ------------------
  996|   106M|    MP_DIGIT(sqr, 0) = 0;
  ------------------
  |  |  153|   106M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  997|       |
  998|   106M|#ifdef NSS_USE_COMBA
  999|   106M|    if (IS_POWER_OF_2(MP_USED(a))) {
  ------------------
  |  |  153|   106M|#define IS_POWER_OF_2(a) ((a) && !((a) & ((a)-1)))
  |  |  ------------------
  |  |  |  Branch (153:27): [True: 106M, False: 0]
  |  |  |  Branch (153:34): [True: 102M, False: 4.37M]
  |  |  ------------------
  ------------------
 1000|   102M|        if (MP_USED(a) == 4) {
  ------------------
  |  |  150|   102M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (1000:13): [True: 187, False: 102M]
  ------------------
 1001|    187|            s_mp_sqr_comba_4(a, sqr);
 1002|    187|            goto CLEANUP;
 1003|    187|        }
 1004|   102M|        if (MP_USED(a) == 8) {
  ------------------
  |  |  150|   102M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (1004:13): [True: 187, False: 102M]
  ------------------
 1005|    187|            s_mp_sqr_comba_8(a, sqr);
 1006|    187|            goto CLEANUP;
 1007|    187|        }
 1008|   102M|        if (MP_USED(a) == 16) {
  ------------------
  |  |  150|   102M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (1008:13): [True: 85.1M, False: 17.0M]
  ------------------
 1009|  85.1M|            s_mp_sqr_comba_16(a, sqr);
 1010|  85.1M|            goto CLEANUP;
 1011|  85.1M|        }
 1012|  17.0M|        if (MP_USED(a) == 32) {
  ------------------
  |  |  150|  17.0M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (1012:13): [True: 15.0M, False: 1.99M]
  ------------------
 1013|  15.0M|            s_mp_sqr_comba_32(a, sqr);
 1014|  15.0M|            goto CLEANUP;
 1015|  15.0M|        }
 1016|  17.0M|    }
 1017|  6.37M|#endif
 1018|       |
 1019|  6.37M|    pa = MP_DIGITS(a);
  ------------------
  |  |  152|  6.37M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1020|  6.37M|    count = MP_USED(a) - 1;
  ------------------
  |  |  150|  6.37M|#define MP_USED(MP) ((MP)->used)
  ------------------
 1021|  6.37M|    if (count > 0) {
  ------------------
  |  Branch (1021:9): [True: 6.21M, False: 167k]
  ------------------
 1022|  6.21M|        d = *pa++;
 1023|  6.21M|        s_mpv_mul_d(pa, count, d, MP_DIGITS(sqr) + 1);
  ------------------
  |  |  181|  6.21M|    ((mp_digit *)c)[a_len] = s_mpv_mul_set_vec64(c, a, a_len, b)
  ------------------
 1024|   507M|        for (ix = 3; --count > 0; ix += 2) {
  ------------------
  |  Branch (1024:22): [True: 501M, False: 6.21M]
  ------------------
 1025|   501M|            d = *pa++;
 1026|   501M|            s_mpv_mul_d_add(pa, count, d, MP_DIGITS(sqr) + ix);
  ------------------
  |  |  185|   501M|    ((mp_digit *)c)[a_len] = s_mpv_mul_add_vec64(c, a, a_len, b)
  ------------------
 1027|   501M|        }                                    /* for(ix ...) */
 1028|  6.21M|        MP_DIGIT(sqr, MP_USED(sqr) - 1) = 0; /* above loop stopped short of this. */
  ------------------
  |  |  153|  6.21M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1029|       |
 1030|       |        /* now sqr *= 2 */
 1031|  6.21M|        s_mp_mul_2(sqr);
 1032|  6.21M|    } else {
 1033|   167k|        MP_DIGIT(sqr, 1) = 0;
  ------------------
  |  |  153|   167k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1034|   167k|    }
 1035|       |
 1036|       |    /* now add the squares of the digits of a to sqr. */
 1037|  6.37M|    s_mpv_sqr_add_prop(MP_DIGITS(a), MP_USED(a), MP_DIGITS(sqr));
  ------------------
  |  |  152|  6.37M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
                  s_mpv_sqr_add_prop(MP_DIGITS(a), MP_USED(a), MP_DIGITS(sqr));
  ------------------
  |  |  150|  6.37M|#define MP_USED(MP) ((MP)->used)
  ------------------
                  s_mpv_sqr_add_prop(MP_DIGITS(a), MP_USED(a), MP_DIGITS(sqr));
  ------------------
  |  |  152|  6.37M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1038|       |
 1039|  6.37M|    SIGN(sqr) = ZPOS;
  ------------------
  |  |  332|  6.37M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  6.37M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(sqr) = ZPOS;
  ------------------
  |  |  326|  6.37M|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|  6.37M|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 1040|  6.37M|    s_mp_clamp(sqr);
 1041|       |
 1042|   106M|CLEANUP:
 1043|   106M|    mp_clear(&tmp);
 1044|   106M|    return res;
 1045|       |
 1046|  6.37M|} /* end mp_sqr() */
mp_div:
 1062|   500k|{
 1063|   500k|    mp_err res;
 1064|   500k|    mp_int *pQ, *pR;
 1065|   500k|    mp_int qtmp, rtmp, btmp;
 1066|   500k|    int cmp;
 1067|   500k|    mp_sign signA;
 1068|   500k|    mp_sign signB;
 1069|       |
 1070|   500k|    ARGCHK(a != NULL && b != NULL, MP_BADARG);
  ------------------
  |  |  355|   500k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1071|       |
 1072|   500k|    signA = MP_SIGN(a);
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
 1073|   500k|    signB = MP_SIGN(b);
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
 1074|       |
 1075|   500k|    if (mp_cmp_z(b) == MP_EQ)
  ------------------
  |  |   50|   500k|#define MP_EQ 0
  ------------------
  |  Branch (1075:9): [True: 0, False: 500k]
  ------------------
 1076|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 1077|       |
 1078|   500k|    DIGITS(&qtmp) = 0;
  ------------------
  |  |  335|   500k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   500k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
 1079|   500k|    DIGITS(&rtmp) = 0;
  ------------------
  |  |  335|   500k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   500k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
 1080|   500k|    DIGITS(&btmp) = 0;
  ------------------
  |  |  335|   500k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   500k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
 1081|       |
 1082|       |    /* Set up some temporaries... */
 1083|   500k|    if (!r || r == a || r == b) {
  ------------------
  |  Branch (1083:9): [True: 2.39k, False: 497k]
  |  Branch (1083:15): [True: 425k, False: 72.3k]
  |  Branch (1083:25): [True: 0, False: 72.3k]
  ------------------
 1084|   427k|        MP_CHECKOK(mp_init_copy(&rtmp, a));
  ------------------
  |  |  319|   427k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   427k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 427k]
  |  |  ------------------
  |  |  320|   427k|    goto CLEANUP
  ------------------
 1085|   427k|        pR = &rtmp;
 1086|   427k|    } else {
 1087|  72.3k|        MP_CHECKOK(mp_copy(a, r));
  ------------------
  |  |  319|  72.3k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  72.3k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 72.3k]
  |  |  ------------------
  |  |  320|  72.3k|    goto CLEANUP
  ------------------
 1088|  72.3k|        pR = r;
 1089|  72.3k|    }
 1090|       |
 1091|   500k|    if (!q || q == a || q == b) {
  ------------------
  |  Branch (1091:9): [True: 497k, False: 2.39k]
  |  Branch (1091:15): [True: 2.39k, False: 0]
  |  Branch (1091:25): [True: 0, False: 0]
  ------------------
 1092|   500k|        MP_CHECKOK(mp_init_size(&qtmp, MP_USED(a)));
  ------------------
  |  |  319|   500k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   500k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 500k]
  |  |  ------------------
  |  |  320|   500k|    goto CLEANUP
  ------------------
 1093|   500k|        pQ = &qtmp;
 1094|   500k|    } else {
 1095|      0|        MP_CHECKOK(s_mp_pad(q, MP_USED(a)));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 1096|      0|        pQ = q;
 1097|      0|        mp_zero(pQ);
 1098|      0|    }
 1099|       |
 1100|       |    /*
 1101|       |      If |a| <= |b|, we can compute the solution without division;
 1102|       |      otherwise, we actually do the work required.
 1103|       |     */
 1104|   500k|    if ((cmp = s_mp_cmp(a, b)) <= 0) {
  ------------------
  |  Branch (1104:9): [True: 146, False: 500k]
  ------------------
 1105|    146|        if (cmp) {
  ------------------
  |  Branch (1105:13): [True: 146, False: 0]
  ------------------
 1106|       |            /* r was set to a above. */
 1107|    146|            mp_zero(pQ);
 1108|    146|        } else {
 1109|      0|            mp_set(pQ, 1);
 1110|      0|            mp_zero(pR);
 1111|      0|        }
 1112|   500k|    } else {
 1113|   500k|        MP_CHECKOK(mp_init_copy(&btmp, b));
  ------------------
  |  |  319|   500k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   500k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 500k]
  |  |  ------------------
  |  |  320|   500k|    goto CLEANUP
  ------------------
 1114|   500k|        MP_CHECKOK(s_mp_div(pR, &btmp, pQ));
  ------------------
  |  |  319|   500k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   500k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 500k]
  |  |  ------------------
  |  |  320|   500k|    goto CLEANUP
  ------------------
 1115|   500k|    }
 1116|       |
 1117|       |    /* Compute the signs for the output  */
 1118|   500k|    MP_SIGN(pR) = signA;        /* Sr = Sa              */
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
 1119|       |    /* Sq = ZPOS if Sa == Sb */ /* Sq = NEG if Sa != Sb */
 1120|   500k|    MP_SIGN(pQ) = (signA == signB) ? ZPOS : NEG;
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(pQ) = (signA == signB) ? ZPOS : NEG;
  ------------------
  |  |  326|   500k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   500k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
                  MP_SIGN(pQ) = (signA == signB) ? ZPOS : NEG;
  ------------------
  |  |  325|      0|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|   500k|#define MP_NEG 1
  |  |  ------------------
  ------------------
  |  Branch (1120:19): [True: 500k, False: 0]
  ------------------
 1121|       |
 1122|   500k|    if (s_mp_cmp_d(pQ, 0) == MP_EQ)
  ------------------
  |  |   50|   500k|#define MP_EQ 0
  ------------------
  |  Branch (1122:9): [True: 146, False: 500k]
  ------------------
 1123|    146|        SIGN(pQ) = ZPOS;
  ------------------
  |  |  332|    146|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|    146|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(pQ) = ZPOS;
  ------------------
  |  |  326|    146|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|    146|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 1124|   500k|    if (s_mp_cmp_d(pR, 0) == MP_EQ)
  ------------------
  |  |   50|   500k|#define MP_EQ 0
  ------------------
  |  Branch (1124:9): [True: 241, False: 500k]
  ------------------
 1125|    241|        SIGN(pR) = ZPOS;
  ------------------
  |  |  332|    241|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|    241|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(pR) = ZPOS;
  ------------------
  |  |  326|    241|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|    241|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 1126|       |
 1127|       |    /* Copy output, if it is needed      */
 1128|   500k|    if (q && q != pQ)
  ------------------
  |  Branch (1128:9): [True: 2.39k, False: 497k]
  |  Branch (1128:14): [True: 2.39k, False: 0]
  ------------------
 1129|  2.39k|        s_mp_exch(pQ, q);
 1130|       |
 1131|   500k|    if (r && r != pR)
  ------------------
  |  Branch (1131:9): [True: 497k, False: 2.39k]
  |  Branch (1131:14): [True: 425k, False: 72.3k]
  ------------------
 1132|   425k|        s_mp_exch(pR, r);
 1133|       |
 1134|   500k|CLEANUP:
 1135|   500k|    mp_clear(&btmp);
 1136|   500k|    mp_clear(&rtmp);
 1137|   500k|    mp_clear(&qtmp);
 1138|       |
 1139|   500k|    return res;
 1140|       |
 1141|   500k|} /* end mp_div() */
mp_mod:
 1279|   212k|{
 1280|   212k|    mp_err res;
 1281|   212k|    int mag;
 1282|       |
 1283|   212k|    ARGCHK(a != NULL && m != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|   212k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1284|       |
 1285|   212k|    if (SIGN(m) == NEG)
  ------------------
  |  |  332|   212k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   212k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(m) == NEG)
  ------------------
  |  |  325|   212k|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|   212k|#define MP_NEG 1
  |  |  ------------------
  ------------------
  |  Branch (1285:9): [True: 0, False: 212k]
  ------------------
 1286|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 1287|       |
 1288|       |    /*
 1289|       |     If |a| > m, we need to divide to get the remainder and take the
 1290|       |     absolute value.
 1291|       |
 1292|       |     If |a| < m, we don't need to do any division, just copy and adjust
 1293|       |     the sign (if a is negative).
 1294|       |
 1295|       |     If |a| == m, we can simply set the result to zero.
 1296|       |
 1297|       |     This order is intended to minimize the average path length of the
 1298|       |     comparison chain on common workloads -- the most frequent cases are
 1299|       |     that |a| != m, so we do those first.
 1300|       |     */
 1301|   212k|    if ((mag = s_mp_cmp(a, m)) > 0) {
  ------------------
  |  Branch (1301:9): [True: 144k, False: 68.0k]
  ------------------
 1302|   144k|        if ((res = mp_div(a, m, NULL, c)) != MP_OKAY)
  ------------------
  |  |   39|   144k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1302:13): [True: 0, False: 144k]
  ------------------
 1303|      0|            return res;
 1304|       |
 1305|   144k|        if (SIGN(c) == NEG) {
  ------------------
  |  |  332|   144k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   144k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      if (SIGN(c) == NEG) {
  ------------------
  |  |  325|   144k|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|   144k|#define MP_NEG 1
  |  |  ------------------
  ------------------
  |  Branch (1305:13): [True: 0, False: 144k]
  ------------------
 1306|      0|            if ((res = mp_add(c, m, c)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1306:17): [True: 0, False: 0]
  ------------------
 1307|      0|                return res;
 1308|      0|        }
 1309|       |
 1310|   144k|    } else if (mag < 0) {
  ------------------
  |  Branch (1310:16): [True: 68.0k, False: 0]
  ------------------
 1311|  68.0k|        if ((res = mp_copy(a, c)) != MP_OKAY)
  ------------------
  |  |   39|  68.0k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1311:13): [True: 0, False: 68.0k]
  ------------------
 1312|      0|            return res;
 1313|       |
 1314|  68.0k|        if (mp_cmp_z(a) < 0) {
  ------------------
  |  Branch (1314:13): [True: 14.8k, False: 53.1k]
  ------------------
 1315|  14.8k|            if ((res = mp_add(c, m, c)) != MP_OKAY)
  ------------------
  |  |   39|  14.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1315:17): [True: 0, False: 14.8k]
  ------------------
 1316|      0|                return res;
 1317|  14.8k|        }
 1318|       |
 1319|  68.0k|    } else {
 1320|      0|        mp_zero(c);
 1321|      0|    }
 1322|       |
 1323|   212k|    return MP_OKAY;
  ------------------
  |  |   39|   212k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1324|       |
 1325|   212k|} /* end mp_mod() */
s_mp_subCT_d:
 1338|  1.15M|{
 1339|  1.15M|    *ret = a - b - borrow;
 1340|  1.15M|    return MP_CT_LTU(a, *ret) | (MP_CT_EQ(a, *ret) & borrow);
  ------------------
  |  |  188|  1.15M|#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
  |  |  ------------------
  |  |  |  |  186|  1.15M|    MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
  |  |  |  |  ------------------
  |  |  |  |  |  |  181|  1.15M|#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r)      /* mask, l and r are booleans */
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  180|  1.15M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |  187|  1.15M|               (MP_CT_HIGH_TO_LOW(d)), c)
  |  |  ------------------
  ------------------
                  return MP_CT_LTU(a, *ret) | (MP_CT_EQ(a, *ret) & borrow);
  ------------------
  |  |  171|  1.15M|#define MP_CT_EQ(a, b) MP_CT_ZERO(((a) ^ (b)))
  |  |  ------------------
  |  |  |  |  165|  1.15M|#define MP_CT_ZERO(x) (MP_CT_TRUE ^ MP_CT_HIGH_TO_LOW(((x) | (((mp_digit)0) - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  160|  1.15M|#define MP_CT_TRUE ((mp_digit)1)
  |  |  |  |  ------------------
  |  |  |  |               #define MP_CT_ZERO(x) (MP_CT_TRUE ^ MP_CT_HIGH_TO_LOW(((x) | (((mp_digit)0) - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  159|  1.15M|#define MP_CT_HIGH_TO_LOW(x) ((mp_digit)((mp_digit)(x) >> (MP_DIGIT_BIT - 1)))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  137|  1.15M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  |  136|  1.15M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1341|  1.15M|} /*  s_mp_subCT_d() */
mp_subCT:
 1352|  36.2k|{
 1353|  36.2k|    mp_size used_a = MP_USED(a);
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
 1354|  36.2k|    mp_size i;
 1355|  36.2k|    mp_err res;
 1356|       |
 1357|  36.2k|    MP_CHECKOK(s_mp_pad(b, used_a));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1358|  36.2k|    MP_CHECKOK(s_mp_pad(ret, used_a));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1359|  36.2k|    *borrow = 0;
 1360|  1.19M|    for (i = 0; i < used_a; i++) {
  ------------------
  |  Branch (1360:17): [True: 1.15M, False: 36.2k]
  ------------------
 1361|  1.15M|        *borrow = s_mp_subCT_d(MP_DIGIT(a, i), MP_DIGIT(b, i), *borrow,
  ------------------
  |  |  153|  1.15M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
                      *borrow = s_mp_subCT_d(MP_DIGIT(a, i), MP_DIGIT(b, i), *borrow,
  ------------------
  |  |  153|  1.15M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1362|  1.15M|                               &MP_DIGIT(ret, i));
  ------------------
  |  |  153|  1.15M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1363|  1.15M|    }
 1364|       |
 1365|  36.2k|    res = MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1366|  36.2k|CLEANUP:
 1367|  36.2k|    return res;
 1368|  36.2k|} /*  end mp_subCT() */
mp_selectCT:
 1379|  36.2k|{
 1380|  36.2k|    mp_size used_a = MP_USED(a);
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
 1381|  36.2k|    mp_err res;
 1382|  36.2k|    mp_size i;
 1383|       |
 1384|  36.2k|    cond *= MP_DIGIT_MAX;
  ------------------
  |  |   79|  36.2k|#define MP_DIGIT_MAX ULONG_MAX
  ------------------
 1385|       |
 1386|       |    /* we currently require these to be equal on input,
 1387|       |     * we could use pad to extend one of them, but that might
 1388|       |     * leak data as it wouldn't be constant time */
 1389|  36.2k|    if (used_a != MP_USED(b)) {
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (1389:9): [True: 0, False: 36.2k]
  ------------------
 1390|      0|        return MP_BADARG;
  ------------------
  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  ------------------
 1391|      0|    }
 1392|       |
 1393|  36.2k|    MP_CHECKOK(s_mp_pad(ret, used_a));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1394|  1.19M|    for (i = 0; i < used_a; i++) {
  ------------------
  |  Branch (1394:17): [True: 1.15M, False: 36.2k]
  ------------------
 1395|  1.15M|        MP_DIGIT(ret, i) = MP_CT_SEL_DIGIT(cond, MP_DIGIT(a, i), MP_DIGIT(b, i));
  ------------------
  |  |  153|  1.15M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
                      MP_DIGIT(ret, i) = MP_CT_SEL_DIGIT(cond, MP_DIGIT(a, i), MP_DIGIT(b, i));
  ------------------
  |  |  182|  1.15M|#define MP_CT_SEL_DIGIT(m, l, r) MP_CT_SEL(m, l, r) /*mask, l, and r are mp_digit */
  |  |  ------------------
  |  |  |  |  180|  1.15M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  ------------------
  ------------------
 1396|  1.15M|    }
 1397|  36.2k|    res = MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1398|  36.2k|CLEANUP:
 1399|  36.2k|    return res;
 1400|  36.2k|} /* end mp_selectCT() */
mp_reduceCT:
 1417|  36.2k|{
 1418|  36.2k|    mp_size used_m = MP_USED(m);
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
 1419|  36.2k|    mp_size used_c = used_m * 2 + 1;
 1420|  36.2k|    mp_digit *m_digits, *c_digits;
 1421|  36.2k|    mp_size i;
 1422|  36.2k|    mp_digit borrow, carry;
 1423|  36.2k|    mp_err res;
 1424|  36.2k|    mp_int sub;
 1425|       |
 1426|  36.2k|    MP_DIGITS(&sub) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1427|  36.2k|    MP_CHECKOK(mp_init_size(&sub, used_m));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1428|       |
 1429|  36.2k|    if (a != c) {
  ------------------
  |  Branch (1429:9): [True: 0, False: 36.2k]
  ------------------
 1430|      0|        MP_CHECKOK(mp_copy(a, c));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 1431|      0|    }
 1432|  36.2k|    MP_CHECKOK(s_mp_pad(c, used_c));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1433|  36.2k|    m_digits = MP_DIGITS(m);
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1434|  36.2k|    c_digits = MP_DIGITS(c);
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1435|  1.19M|    for (i = 0; i < used_m; i++) {
  ------------------
  |  Branch (1435:17): [True: 1.15M, False: 36.2k]
  ------------------
 1436|  1.15M|        mp_digit m_i = MP_DIGIT(c, i) * n0i;
  ------------------
  |  |  153|  1.15M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1437|  1.15M|        s_mpv_mul_d_add_propCT(m_digits, used_m, m_i, c_digits++, used_c--);
 1438|  1.15M|    }
 1439|  36.2k|    s_mp_rshd(c, used_m);
 1440|       |    /* MP_USED(c) should be used_m+1 with the high word being any carry
 1441|       |     * from the previous multiply, save that carry and drop the high
 1442|       |     * word for the substraction below */
 1443|  36.2k|    carry = MP_DIGIT(c, used_m);
  ------------------
  |  |  153|  36.2k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1444|  36.2k|    MP_DIGIT(c, used_m) = 0;
  ------------------
  |  |  153|  36.2k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 1445|  36.2k|    MP_USED(c) = used_m;
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
 1446|       |    /* mp_subCT wants c and m to be the same size, we've already
 1447|       |     * guarrenteed that in the previous statement, so mp_subCT won't actually
 1448|       |     * modify m, so it's safe to recast */
 1449|  36.2k|    MP_CHECKOK(mp_subCT(c, (mp_int *)m, &sub, &borrow));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1450|       |
 1451|       |    /* we return c-m if c >= m no borrow or there was a borrow and a carry */
 1452|  36.2k|    MP_CHECKOK(mp_selectCT(borrow ^ carry, c, &sub, c));
  ------------------
  |  |  319|  36.2k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |  320|  36.2k|    goto CLEANUP
  ------------------
 1453|  36.2k|    res = MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1454|  36.2k|CLEANUP:
 1455|  36.2k|    mp_clear(&sub);
 1456|  36.2k|    return res;
 1457|  36.2k|} /* end mp_reduceCT() */
mp_submod:
 1537|  36.2k|{
 1538|  36.2k|    mp_err res;
 1539|       |
 1540|  36.2k|    ARGCHK(a != NULL && b != NULL && m != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|  36.2k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1541|       |
 1542|  36.2k|    if ((res = mp_sub(a, b, c)) != MP_OKAY)
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1542:9): [True: 0, False: 36.2k]
  ------------------
 1543|      0|        return res;
 1544|  36.2k|    if ((res = mp_mod(c, m, c)) != MP_OKAY)
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1544:9): [True: 0, False: 36.2k]
  ------------------
 1545|      0|        return res;
 1546|       |
 1547|  36.2k|    return MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1548|  36.2k|}
mp_mulmod:
 1562|  72.5k|{
 1563|  72.5k|    mp_err res;
 1564|       |
 1565|  72.5k|    ARGCHK(a != NULL && b != NULL && m != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|  72.5k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1566|       |
 1567|  72.5k|    if ((res = mp_mul(a, b, c)) != MP_OKAY)
  ------------------
  |  |   39|  72.5k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1567:9): [True: 0, False: 72.5k]
  ------------------
 1568|      0|        return res;
 1569|  72.5k|    if ((res = mp_mod(c, m, c)) != MP_OKAY)
  ------------------
  |  |   39|  72.5k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1569:9): [True: 0, False: 72.5k]
  ------------------
 1570|      0|        return res;
 1571|       |
 1572|  72.5k|    return MP_OKAY;
  ------------------
  |  |   39|  72.5k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1573|  72.5k|}
mp_mulmontmodCT:
 1592|  36.2k|{
 1593|  36.2k|    mp_err res;
 1594|       |
 1595|  36.2k|    ARGCHK(a != NULL && b != NULL && m != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|  36.2k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1596|       |
 1597|  36.2k|    if ((res = mp_mulCT(a, b, c, MP_USED(m))) != MP_OKAY)
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if ((res = mp_mulCT(a, b, c, MP_USED(m))) != MP_OKAY)
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1597:9): [True: 0, False: 36.2k]
  ------------------
 1598|      0|        return res;
 1599|       |
 1600|  36.2k|    if ((res = mp_reduceCT(c, m, n0i, c)) != MP_OKAY)
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1600:9): [True: 0, False: 36.2k]
  ------------------
 1601|      0|        return res;
 1602|       |
 1603|  36.2k|    return MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1604|  36.2k|}
s_mp_exptmod:
 1645|  2.39k|{
 1646|  2.39k|    mp_int s, x, mu;
 1647|  2.39k|    mp_err res;
 1648|  2.39k|    mp_digit d;
 1649|  2.39k|    unsigned int dig, bit;
 1650|       |
 1651|  2.39k|    ARGCHK(a != NULL && b != NULL && c != NULL && m != NULL, MP_BADARG);
  ------------------
  |  |  355|  2.39k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1652|       |
 1653|  2.39k|    if (mp_cmp_z(b) < 0 || mp_cmp_z(m) <= 0)
  ------------------
  |  Branch (1653:9): [True: 0, False: 2.39k]
  |  Branch (1653:28): [True: 0, False: 2.39k]
  ------------------
 1654|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 1655|       |
 1656|  2.39k|    if ((res = mp_init(&s)) != MP_OKAY)
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1656:9): [True: 0, False: 2.39k]
  ------------------
 1657|      0|        return res;
 1658|  2.39k|    if ((res = mp_init_copy(&x, a)) != MP_OKAY ||
  ------------------
  |  |   39|  4.79k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1658:9): [True: 0, False: 2.39k]
  ------------------
 1659|  2.39k|        (res = mp_mod(&x, m, &x)) != MP_OKAY)
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1659:9): [True: 0, False: 2.39k]
  ------------------
 1660|      0|        goto X;
 1661|  2.39k|    if ((res = mp_init(&mu)) != MP_OKAY)
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1661:9): [True: 0, False: 2.39k]
  ------------------
 1662|      0|        goto MU;
 1663|       |
 1664|  2.39k|    mp_set(&s, 1);
 1665|       |
 1666|       |    /* mu = b^2k / m */
 1667|  2.39k|    if ((res = s_mp_add_d(&mu, 1)) != MP_OKAY)
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1667:9): [True: 0, False: 2.39k]
  ------------------
 1668|      0|        goto CLEANUP;
 1669|  2.39k|    if ((res = s_mp_lshd(&mu, 2 * USED(m))) != MP_OKAY)
  ------------------
  |  |  333|  2.39k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  2.39k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  if ((res = s_mp_lshd(&mu, 2 * USED(m))) != MP_OKAY)
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1669:9): [True: 0, False: 2.39k]
  ------------------
 1670|      0|        goto CLEANUP;
 1671|  2.39k|    if ((res = mp_div(&mu, m, &mu, NULL)) != MP_OKAY)
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1671:9): [True: 0, False: 2.39k]
  ------------------
 1672|      0|        goto CLEANUP;
 1673|       |
 1674|       |    /* Loop over digits of b in ascending order, except highest order */
 1675|  2.39k|    for (dig = 0; dig < (USED(b) - 1); dig++) {
  ------------------
  |  |  333|  2.39k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  2.39k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (1675:19): [True: 0, False: 2.39k]
  ------------------
 1676|      0|        d = DIGIT(b, dig);
  ------------------
  |  |  336|      0|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      0|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 1677|       |
 1678|       |        /* Loop over the bits of the lower-order digits */
 1679|      0|        for (bit = 0; bit < DIGIT_BIT; bit++) {
  ------------------
  |  |  328|      0|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|      0|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|      0|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1679:23): [True: 0, False: 0]
  ------------------
 1680|      0|            if (d & 1) {
  ------------------
  |  Branch (1680:17): [True: 0, False: 0]
  ------------------
 1681|      0|                if ((res = s_mp_mul(&s, &x)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1681:21): [True: 0, False: 0]
  ------------------
 1682|      0|                    goto CLEANUP;
 1683|      0|                if ((res = s_mp_reduce(&s, m, &mu)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1683:21): [True: 0, False: 0]
  ------------------
 1684|      0|                    goto CLEANUP;
 1685|      0|            }
 1686|       |
 1687|      0|            d >>= 1;
 1688|       |
 1689|      0|            if ((res = s_mp_sqr(&x)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1689:17): [True: 0, False: 0]
  ------------------
 1690|      0|                goto CLEANUP;
 1691|      0|            if ((res = s_mp_reduce(&x, m, &mu)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1691:17): [True: 0, False: 0]
  ------------------
 1692|      0|                goto CLEANUP;
 1693|      0|        }
 1694|      0|    }
 1695|       |
 1696|       |    /* Now do the last digit... */
 1697|  2.39k|    d = DIGIT(b, dig);
  ------------------
  |  |  336|  2.39k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  2.39k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 1698|       |
 1699|  43.8k|    while (d) {
  ------------------
  |  Branch (1699:12): [True: 41.4k, False: 2.39k]
  ------------------
 1700|  41.4k|        if (d & 1) {
  ------------------
  |  Branch (1700:13): [True: 16.2k, False: 25.1k]
  ------------------
 1701|  16.2k|            if ((res = s_mp_mul(&s, &x)) != MP_OKAY)
  ------------------
  |  |   39|  16.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1701:17): [True: 0, False: 16.2k]
  ------------------
 1702|      0|                goto CLEANUP;
 1703|  16.2k|            if ((res = s_mp_reduce(&s, m, &mu)) != MP_OKAY)
  ------------------
  |  |   39|  16.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1703:17): [True: 0, False: 16.2k]
  ------------------
 1704|      0|                goto CLEANUP;
 1705|  16.2k|        }
 1706|       |
 1707|  41.4k|        d >>= 1;
 1708|       |
 1709|  41.4k|        if ((res = s_mp_sqr(&x)) != MP_OKAY)
  ------------------
  |  |   39|  41.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1709:13): [True: 0, False: 41.4k]
  ------------------
 1710|      0|            goto CLEANUP;
 1711|  41.4k|        if ((res = s_mp_reduce(&x, m, &mu)) != MP_OKAY)
  ------------------
  |  |   39|  41.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (1711:13): [True: 0, False: 41.4k]
  ------------------
 1712|      0|            goto CLEANUP;
 1713|  41.4k|    }
 1714|       |
 1715|  2.39k|    s_mp_exch(&s, c);
 1716|       |
 1717|  2.39k|CLEANUP:
 1718|  2.39k|    mp_clear(&mu);
 1719|  2.39k|MU:
 1720|  2.39k|    mp_clear(&x);
 1721|  2.39k|X:
 1722|  2.39k|    mp_clear(&s);
 1723|       |
 1724|  2.39k|    return res;
 1725|       |
 1726|  2.39k|} /* end s_mp_exptmod() */
mp_cmp_z:
 1790|  11.8M|{
 1791|  11.8M|    ARGMPCHK(a != NULL);
  ------------------
  |  |  354|  11.8M|#define ARGMPCHK(X) assert(X)
  ------------------
 1792|       |
 1793|  11.8M|    if (SIGN(a) == NEG)
  ------------------
  |  |  332|  11.8M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  11.8M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(a) == NEG)
  ------------------
  |  |  325|  11.8M|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|  11.8M|#define MP_NEG 1
  |  |  ------------------
  ------------------
  |  Branch (1793:9): [True: 15.5k, False: 11.8M]
  ------------------
 1794|  15.5k|        return MP_LT;
  ------------------
  |  |   49|  15.5k|#define MP_LT -1
  ------------------
 1795|  11.8M|    else if (USED(a) == 1 && DIGIT(a, 0) == 0)
  ------------------
  |  |  333|  11.8M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  11.8M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  else if (USED(a) == 1 && DIGIT(a, 0) == 0)
  ------------------
  |  |  336|   970k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   970k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  |  Branch (1795:14): [True: 970k, False: 10.8M]
  |  Branch (1795:30): [True: 414k, False: 555k]
  ------------------
 1796|   414k|        return MP_EQ;
  ------------------
  |  |   50|   414k|#define MP_EQ 0
  ------------------
 1797|  11.4M|    else
 1798|  11.4M|        return MP_GT;
  ------------------
  |  |   51|  11.4M|#define MP_GT 1
  ------------------
 1799|       |
 1800|  11.8M|} /* end mp_cmp_z() */
mp_cmp_d:
 1814|   170k|{
 1815|   170k|    ARGCHK(a != NULL, MP_EQ);
  ------------------
  |  |  355|   170k|#define ARGCHK(X, Y) assert(X)
  ------------------
 1816|       |
 1817|   170k|    if (SIGN(a) == NEG)
  ------------------
  |  |  332|   170k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   170k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(a) == NEG)
  ------------------
  |  |  325|   170k|#define NEG MP_NEG
  |  |  ------------------
  |  |  |  |   36|   170k|#define MP_NEG 1
  |  |  ------------------
  ------------------
  |  Branch (1817:9): [True: 0, False: 170k]
  ------------------
 1818|      0|        return MP_LT;
  ------------------
  |  |   49|      0|#define MP_LT -1
  ------------------
 1819|       |
 1820|   170k|    return s_mp_cmp_d(a, d);
 1821|       |
 1822|   170k|} /* end mp_cmp_d() */
mp_cmp:
 1830|  31.4M|{
 1831|  31.4M|    ARGCHK(a != NULL && b != NULL, MP_EQ);
  ------------------
  |  |  355|  31.4M|#define ARGCHK(X, Y) assert(X)
  ------------------
 1832|       |
 1833|  31.4M|    if (SIGN(a) == SIGN(b)) {
  ------------------
  |  |  332|  31.4M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  31.4M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  if (SIGN(a) == SIGN(b)) {
  ------------------
  |  |  332|  31.4M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  31.4M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
  |  Branch (1833:9): [True: 31.4M, False: 0]
  ------------------
 1834|  31.4M|        int mag;
 1835|       |
 1836|  31.4M|        if ((mag = s_mp_cmp(a, b)) == MP_EQ)
  ------------------
  |  |   50|  31.4M|#define MP_EQ 0
  ------------------
  |  Branch (1836:13): [True: 35.5k, False: 31.4M]
  ------------------
 1837|  35.5k|            return MP_EQ;
  ------------------
  |  |   50|  35.5k|#define MP_EQ 0
  ------------------
 1838|       |
 1839|  31.4M|        if (SIGN(a) == ZPOS)
  ------------------
  |  |  332|  31.4M|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  31.4M|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      if (SIGN(a) == ZPOS)
  ------------------
  |  |  326|  31.4M|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|  31.4M|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  |  Branch (1839:13): [True: 31.4M, False: 0]
  ------------------
 1840|  31.4M|            return mag;
 1841|      0|        else
 1842|      0|            return -mag;
 1843|       |
 1844|  31.4M|    } else if (SIGN(a) == ZPOS) {
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  } else if (SIGN(a) == ZPOS) {
  ------------------
  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|      0|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
  |  Branch (1844:16): [True: 0, False: 0]
  ------------------
 1845|      0|        return MP_GT;
  ------------------
  |  |   51|      0|#define MP_GT 1
  ------------------
 1846|      0|    } else {
 1847|      0|        return MP_LT;
  ------------------
  |  |   49|      0|#define MP_LT -1
  ------------------
 1848|      0|    }
 1849|       |
 1850|  31.4M|} /* end mp_cmp() */
mp_isodd:
 1882|   196k|{
 1883|   196k|    ARGMPCHK(a != NULL);
  ------------------
  |  |  354|   196k|#define ARGMPCHK(X) assert(X)
  ------------------
 1884|       |
 1885|   196k|    return (int)(DIGIT(a, 0) & 1);
  ------------------
  |  |  336|   196k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   196k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 1886|       |
 1887|   196k|} /* end mp_isodd() */
mp_iseven:
 1895|      1|{
 1896|      1|    return !mp_isodd(a);
 1897|       |
 1898|      1|} /* end mp_iseven() */
mp_gcd:
 1916|      8|{
 1917|      8|    mp_err res;
 1918|      8|    mp_digit cond = 0, mask = 0;
 1919|      8|    mp_int g, temp, f;
 1920|      8|    int i, j, m, bit = 1, delta = 1, shifts = 0, last = -1;
 1921|      8|    mp_size top, flen, glen;
 1922|      8|    mp_int *clear[3];
 1923|       |
 1924|      8|    ARGCHK(a != NULL && b != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|      8|#define ARGCHK(X, Y) assert(X)
  ------------------
 1925|       |    /*
 1926|       |    Early exit if either of the inputs is zero.
 1927|       |    Caller is responsible for the proper handling of inputs.
 1928|       |    */
 1929|      8|    if (mp_cmp_z(a) == MP_EQ) {
  ------------------
  |  |   50|      8|#define MP_EQ 0
  ------------------
  |  Branch (1929:9): [True: 0, False: 8]
  ------------------
 1930|      0|        res = mp_copy(b, c);
 1931|      0|        SIGN(c) = ZPOS;
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(c) = ZPOS;
  ------------------
  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|      0|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 1932|      0|        return res;
 1933|      8|    } else if (mp_cmp_z(b) == MP_EQ) {
  ------------------
  |  |   50|      8|#define MP_EQ 0
  ------------------
  |  Branch (1933:16): [True: 0, False: 8]
  ------------------
 1934|      0|        res = mp_copy(a, c);
 1935|      0|        SIGN(c) = ZPOS;
  ------------------
  |  |  332|      0|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      0|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(c) = ZPOS;
  ------------------
  |  |  326|      0|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|      0|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 1936|      0|        return res;
 1937|      0|    }
 1938|       |
 1939|      8|    MP_CHECKOK(mp_init(&temp));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1940|      8|    clear[++last] = &temp;
 1941|      8|    MP_CHECKOK(mp_init_copy(&g, a));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1942|      8|    clear[++last] = &g;
 1943|      8|    MP_CHECKOK(mp_init_copy(&f, b));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1944|      8|    clear[++last] = &f;
 1945|       |
 1946|       |    /*
 1947|       |    For even case compute the number of
 1948|       |    shared powers of 2 in f and g.
 1949|       |    */
 1950|     16|    for (i = 0; i < USED(&f) && i < USED(&g); i++) {
  ------------------
  |  |  333|     16|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|     32|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  for (i = 0; i < USED(&f) && i < USED(&g); i++) {
  ------------------
  |  |  333|     16|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|     16|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (1950:17): [True: 16, False: 0]
  |  Branch (1950:33): [True: 8, False: 8]
  ------------------
 1951|      8|        mask = ~(DIGIT(&f, i) | DIGIT(&g, i));
  ------------------
  |  |  336|      8|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      8|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
                      mask = ~(DIGIT(&f, i) | DIGIT(&g, i));
  ------------------
  |  |  336|      8|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      8|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 1952|    520|        for (j = 0; j < MP_DIGIT_BIT; j++) {
  ------------------
  |  |  137|    520|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|    520|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
  |  Branch (1952:21): [True: 512, False: 8]
  ------------------
 1953|    512|            bit &= mask;
 1954|    512|            shifts += bit;
 1955|    512|            mask >>= 1;
 1956|    512|        }
 1957|      8|    }
 1958|       |    /* Reduce to the odd case by removing the powers of 2. */
 1959|      8|    s_mp_div_2d(&f, shifts);
 1960|      8|    s_mp_div_2d(&g, shifts);
 1961|       |
 1962|       |    /* Allocate to the size of largest mp_int. */
 1963|      8|    top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      8|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      8|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      8|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      8|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      8|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      8|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      0|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      0|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (1963:25): [True: 8, False: 0]
  ------------------
 1964|      8|    MP_CHECKOK(s_mp_grow(&f, top));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1965|      8|    MP_CHECKOK(s_mp_grow(&g, top));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1966|      8|    MP_CHECKOK(s_mp_grow(&temp, top));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1967|       |
 1968|       |    /* Make sure f contains the odd value. */
 1969|      8|    MP_CHECKOK(mp_cswap((~DIGIT(&f, 0) & 1), &f, &g, top));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 1970|       |
 1971|       |    /* Upper bound for the total iterations. */
 1972|      8|    flen = mpl_significant_bits(&f);
 1973|      8|    glen = mpl_significant_bits(&g);
 1974|      8|    m = 4 + 3 * ((flen >= glen) ? flen : glen);
  ------------------
  |  Branch (1974:18): [True: 0, False: 8]
  ------------------
 1975|       |
 1976|       |#if defined(_MSC_VER)
 1977|       |#pragma warning(push)
 1978|       |#pragma warning(disable : 4146) // Thanks MSVC, we know what we're negating an unsigned mp_digit
 1979|       |#endif
 1980|       |
 1981|  24.6k|    for (i = 0; i < m; i++) {
  ------------------
  |  Branch (1981:17): [True: 24.6k, False: 8]
  ------------------
 1982|       |        /* Step 1: conditional swap. */
 1983|       |        /* Set cond if delta > 0 and g is odd. */
 1984|  24.6k|        cond = (-delta >> (8 * sizeof(delta) - 1)) & DIGIT(&g, 0) & 1;
  ------------------
  |  |  336|  24.6k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  24.6k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 1985|       |        /* If cond is set replace (delta,f) with (-delta,-f). */
 1986|  24.6k|        delta = (-cond & -delta) | ((cond - 1) & delta);
 1987|  24.6k|        SIGN(&f) ^= cond;
  ------------------
  |  |  332|  24.6k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  24.6k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 1988|       |        /* If cond is set swap f with g. */
 1989|  24.6k|        MP_CHECKOK(mp_cswap(cond, &f, &g, top));
  ------------------
  |  |  319|  24.6k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  24.6k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 24.6k]
  |  |  ------------------
  |  |  320|  24.6k|    goto CLEANUP
  ------------------
 1990|       |
 1991|       |        /* Step 2: elemination. */
 1992|       |        /* Update delta. */
 1993|  24.6k|        delta++;
 1994|       |        /* If g is odd, right shift (g+f) else right shift g. */
 1995|  24.6k|        MP_CHECKOK(mp_add(&g, &f, &temp));
  ------------------
  |  |  319|  24.6k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  24.6k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 24.6k]
  |  |  ------------------
  |  |  320|  24.6k|    goto CLEANUP
  ------------------
 1996|  24.6k|        MP_CHECKOK(mp_cswap((DIGIT(&g, 0) & 1), &g, &temp, top));
  ------------------
  |  |  319|  24.6k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  24.6k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 24.6k]
  |  |  ------------------
  |  |  320|  24.6k|    goto CLEANUP
  ------------------
 1997|  24.6k|        s_mp_div_2(&g);
 1998|  24.6k|    }
 1999|       |
 2000|       |#if defined(_MSC_VER)
 2001|       |#pragma warning(pop)
 2002|       |#endif
 2003|       |
 2004|       |    /* GCD is in f, take the absolute value. */
 2005|      8|    SIGN(&f) = ZPOS;
  ------------------
  |  |  332|      8|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      8|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(&f) = ZPOS;
  ------------------
  |  |  326|      8|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|      8|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 2006|       |
 2007|       |    /* Add back the removed powers of 2. */
 2008|      8|    MP_CHECKOK(s_mp_mul_2d(&f, shifts));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 2009|       |
 2010|      8|    MP_CHECKOK(mp_copy(&f, c));
  ------------------
  |  |  319|      8|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      8|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 8]
  |  |  ------------------
  |  |  320|      8|    goto CLEANUP
  ------------------
 2011|       |
 2012|      8|CLEANUP:
 2013|     32|    while (last >= 0)
  ------------------
  |  Branch (2013:12): [True: 24, False: 8]
  ------------------
 2014|     24|        mp_clear(clear[last--]);
 2015|      8|    return res;
 2016|      8|} /* end mp_gcd() */
s_mp_invmod_radix:
 2311|   194k|{
 2312|   194k|    mp_digit T = P;
 2313|   194k|    T *= 2 - (P * T);
 2314|   194k|    T *= 2 - (P * T);
 2315|   194k|    T *= 2 - (P * T);
 2316|   194k|    T *= 2 - (P * T);
 2317|   194k|#if !defined(MP_USE_UINT_DIGIT)
 2318|   194k|    T *= 2 - (P * T);
 2319|   194k|    T *= 2 - (P * T);
 2320|   194k|#endif
 2321|   194k|    return T;
 2322|   194k|}
s_mp_invmod_odd_m:
 2374|      1|{
 2375|      1|    mp_err res;
 2376|      1|    mp_digit cond = 0;
 2377|      1|    mp_int g, f, v, r, temp;
 2378|      1|    int i, its, delta = 1, last = -1;
 2379|      1|    mp_size top, flen, glen;
 2380|      1|    mp_int *clear[6];
 2381|       |
 2382|      1|    ARGCHK(a != NULL && m != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|      1|#define ARGCHK(X, Y) assert(X)
  ------------------
 2383|       |    /* Check for invalid inputs. */
 2384|      1|    if (mp_cmp_z(a) == MP_EQ || mp_cmp_d(m, 2) == MP_LT)
  ------------------
  |  |   50|      2|#define MP_EQ 0
  ------------------
                  if (mp_cmp_z(a) == MP_EQ || mp_cmp_d(m, 2) == MP_LT)
  ------------------
  |  |   49|      1|#define MP_LT -1
  ------------------
  |  Branch (2384:9): [True: 0, False: 1]
  |  Branch (2384:33): [True: 0, False: 1]
  ------------------
 2385|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 2386|       |
 2387|      1|    if (a == m || mp_iseven(m))
  ------------------
  |  Branch (2387:9): [True: 0, False: 1]
  |  Branch (2387:19): [True: 0, False: 1]
  ------------------
 2388|      0|        return MP_UNDEF;
  ------------------
  |  |   45|      0|#define MP_UNDEF -5  /* answer is undefined   */
  ------------------
 2389|       |
 2390|      1|    MP_CHECKOK(mp_init(&temp));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2391|      1|    clear[++last] = &temp;
 2392|      1|    MP_CHECKOK(mp_init(&v));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2393|      1|    clear[++last] = &v;
 2394|      1|    MP_CHECKOK(mp_init(&r));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2395|      1|    clear[++last] = &r;
 2396|      1|    MP_CHECKOK(mp_init_copy(&g, a));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2397|      1|    clear[++last] = &g;
 2398|      1|    MP_CHECKOK(mp_init_copy(&f, m));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2399|      1|    clear[++last] = &f;
 2400|       |
 2401|      1|    mp_set(&v, 0);
 2402|      1|    mp_set(&r, 1);
 2403|       |
 2404|       |    /* Allocate to the size of largest mp_int. */
 2405|      1|    top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      1|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      1|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      1|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      1|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      1|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      1|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  top = (mp_size)1 + ((USED(&f) >= USED(&g)) ? USED(&f) : USED(&g));
  ------------------
  |  |  333|      0|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      0|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (2405:25): [True: 1, False: 0]
  ------------------
 2406|      1|    MP_CHECKOK(s_mp_grow(&f, top));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2407|      1|    MP_CHECKOK(s_mp_grow(&g, top));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2408|      1|    MP_CHECKOK(s_mp_grow(&temp, top));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2409|      1|    MP_CHECKOK(s_mp_grow(&v, top));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2410|      1|    MP_CHECKOK(s_mp_grow(&r, top));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2411|       |
 2412|       |    /* Upper bound for the total iterations. */
 2413|      1|    flen = mpl_significant_bits(&f);
 2414|      1|    glen = mpl_significant_bits(&g);
 2415|      1|    its = 4 + 3 * ((flen >= glen) ? flen : glen);
  ------------------
  |  Branch (2415:20): [True: 1, False: 0]
  ------------------
 2416|       |
 2417|       |#if defined(_MSC_VER)
 2418|       |#pragma warning(push)
 2419|       |#pragma warning(disable : 4146) // Thanks MSVC, we know what we're negating an unsigned mp_digit
 2420|       |#endif
 2421|       |
 2422|  6.14k|    for (i = 0; i < its; i++) {
  ------------------
  |  Branch (2422:17): [True: 6.14k, False: 1]
  ------------------
 2423|       |        /* Step 1: conditional swap. */
 2424|       |        /* Set cond if delta > 0 and g is odd. */
 2425|  6.14k|        cond = (-delta >> (8 * sizeof(delta) - 1)) & DIGIT(&g, 0) & 1;
  ------------------
  |  |  336|  6.14k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  6.14k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 2426|       |        /* If cond is set replace (delta,f,v) with (-delta,-f,-v). */
 2427|  6.14k|        delta = (-cond & -delta) | ((cond - 1) & delta);
 2428|  6.14k|        SIGN(&f) ^= cond;
  ------------------
  |  |  332|  6.14k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  6.14k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 2429|  6.14k|        SIGN(&v) ^= cond;
  ------------------
  |  |  332|  6.14k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  6.14k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 2430|       |        /* If cond is set swap (f,v) with (g,r). */
 2431|  6.14k|        MP_CHECKOK(mp_cswap(cond, &f, &g, top));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2432|  6.14k|        MP_CHECKOK(mp_cswap(cond, &v, &r, top));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2433|       |
 2434|       |        /* Step 2: elemination. */
 2435|       |        /* Update delta */
 2436|  6.14k|        delta++;
 2437|       |        /* If g is odd replace r with (r+v). */
 2438|  6.14k|        MP_CHECKOK(mp_add(&r, &v, &temp));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2439|  6.14k|        MP_CHECKOK(mp_cswap((DIGIT(&g, 0) & 1), &r, &temp, top));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2440|       |        /* If g is odd, right shift (g+f) else right shift g. */
 2441|  6.14k|        MP_CHECKOK(mp_add(&g, &f, &temp));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2442|  6.14k|        MP_CHECKOK(mp_cswap((DIGIT(&g, 0) & 1), &g, &temp, top));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2443|  6.14k|        s_mp_div_2(&g);
 2444|       |        /*
 2445|       |        If r is even, right shift it.
 2446|       |        If r is odd, right shift (r+m) which is even because m is odd.
 2447|       |        We want the result modulo m so adding in multiples of m here vanish.
 2448|       |        */
 2449|  6.14k|        MP_CHECKOK(mp_add(&r, m, &temp));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2450|  6.14k|        MP_CHECKOK(mp_cswap((DIGIT(&r, 0) & 1), &r, &temp, top));
  ------------------
  |  |  319|  6.14k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  6.14k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 6.14k]
  |  |  ------------------
  |  |  320|  6.14k|    goto CLEANUP
  ------------------
 2451|  6.14k|        s_mp_div_2(&r);
 2452|  6.14k|    }
 2453|       |
 2454|       |#if defined(_MSC_VER)
 2455|       |#pragma warning(pop)
 2456|       |#endif
 2457|       |
 2458|       |    /* We have the inverse in v, propagate sign from f. */
 2459|      1|    SIGN(&v) ^= SIGN(&f);
  ------------------
  |  |  332|      1|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      1|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(&v) ^= SIGN(&f);
  ------------------
  |  |  332|      1|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      1|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 2460|       |    /* GCD is in f, take the absolute value. */
 2461|      1|    SIGN(&f) = ZPOS;
  ------------------
  |  |  332|      1|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|      1|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  SIGN(&f) = ZPOS;
  ------------------
  |  |  326|      1|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|      1|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 2462|       |
 2463|       |    /* If gcd != 1, not invertible. */
 2464|      1|    if (mp_cmp_d(&f, 1) != MP_EQ) {
  ------------------
  |  |   50|      1|#define MP_EQ 0
  ------------------
  |  Branch (2464:9): [True: 0, False: 1]
  ------------------
 2465|      0|        res = MP_UNDEF;
  ------------------
  |  |   45|      0|#define MP_UNDEF -5  /* answer is undefined   */
  ------------------
 2466|      0|        goto CLEANUP;
 2467|      0|    }
 2468|       |
 2469|       |    /* Return inverse modulo m. */
 2470|      1|    MP_CHECKOK(mp_mod(&v, m, c));
  ------------------
  |  |  319|      1|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1]
  |  |  ------------------
  |  |  320|      1|    goto CLEANUP
  ------------------
 2471|       |
 2472|      1|CLEANUP:
 2473|      6|    while (last >= 0)
  ------------------
  |  Branch (2473:12): [True: 5, False: 1]
  ------------------
 2474|      5|        mp_clear(clear[last--]);
 2475|      1|    return res;
 2476|      1|}
mp_invmod:
 2671|      1|{
 2672|      1|    ARGCHK(a != NULL && m != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|      1|#define ARGCHK(X, Y) assert(X)
  ------------------
 2673|       |
 2674|      1|    if (mp_cmp_z(a) == 0 || mp_cmp_z(m) == 0)
  ------------------
  |  Branch (2674:9): [True: 0, False: 1]
  |  Branch (2674:29): [True: 0, False: 1]
  ------------------
 2675|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 2676|       |
 2677|      1|    if (mp_isodd(m)) {
  ------------------
  |  Branch (2677:9): [True: 1, False: 0]
  ------------------
 2678|      1|        return s_mp_invmod_odd_m(a, m, c);
 2679|      1|    }
 2680|      0|    if (mp_iseven(a))
  ------------------
  |  Branch (2680:9): [True: 0, False: 0]
  ------------------
 2681|      0|        return MP_UNDEF; /* not invertable */
  ------------------
  |  |   45|      0|#define MP_UNDEF -5  /* answer is undefined   */
  ------------------
 2682|       |
 2683|      0|    return s_mp_invmod_even_m(a, m, c);
 2684|       |
 2685|      0|} /* end mp_invmod() */
s_mp_grow:
 3038|  47.4k|{
 3039|  47.4k|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|  47.4k|#define ARGCHK(X, Y) assert(X)
  ------------------
 3040|       |
 3041|  47.4k|    if (min > ALLOC(mp)) {
  ------------------
  |  |  334|  47.4k|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  47.4k|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  |  Branch (3041:9): [True: 47.4k, False: 29]
  ------------------
 3042|  47.4k|        mp_digit *tmp;
 3043|       |
 3044|       |        /* Set min to next nearest default precision block size */
 3045|  47.4k|        min = MP_ROUNDUP(min, s_mp_defprec);
  ------------------
  |  |   89|  47.4k|#define MP_ROUNDUP(a, b) (MP_HOWMANY(a, b) * (b))
  |  |  ------------------
  |  |  |  |   88|  47.4k|#define MP_HOWMANY(a, b) (((a) + (b)-1) / (b))
  |  |  ------------------
  ------------------
 3046|       |
 3047|  47.4k|        if ((tmp = s_mp_alloc(min, sizeof(mp_digit))) == NULL)
  ------------------
  |  Branch (3047:13): [True: 0, False: 47.4k]
  ------------------
 3048|      0|            return MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
 3049|       |
 3050|  47.4k|        s_mp_copy(DIGITS(mp), tmp, USED(mp));
  ------------------
  |  |  335|  47.4k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  47.4k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                      s_mp_copy(DIGITS(mp), tmp, USED(mp));
  ------------------
  |  |  333|  47.4k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  47.4k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 3051|       |
 3052|  47.4k|        s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  335|  47.4k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  47.4k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                      s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  334|  47.4k|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  47.4k|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
 3053|  47.4k|        s_mp_free(DIGITS(mp));
  ------------------
  |  |  335|  47.4k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  47.4k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
 3054|  47.4k|        DIGITS(mp) = tmp;
  ------------------
  |  |  335|  47.4k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|  47.4k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
 3055|  47.4k|        ALLOC(mp) = min;
  ------------------
  |  |  334|  47.4k|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|  47.4k|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
 3056|  47.4k|    }
 3057|       |
 3058|  47.4k|    return MP_OKAY;
  ------------------
  |  |   39|  47.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3059|       |
 3060|  47.4k|} /* end s_mp_grow() */
s_mp_pad:
 3069|   145M|{
 3070|   145M|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|   145M|#define ARGCHK(X, Y) assert(X)
  ------------------
 3071|       |
 3072|   145M|    if (min > USED(mp)) {
  ------------------
  |  |  333|   145M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   145M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3072:9): [True: 144M, False: 326k]
  ------------------
 3073|   144M|        mp_err res;
 3074|       |
 3075|       |        /* Make sure there is room to increase precision  */
 3076|   144M|        if (min > ALLOC(mp)) {
  ------------------
  |  |  334|   144M|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|   144M|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  |  Branch (3076:13): [True: 47.4k, False: 144M]
  ------------------
 3077|  47.4k|            if ((res = s_mp_grow(mp, min)) != MP_OKAY)
  ------------------
  |  |   39|  47.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (3077:17): [True: 0, False: 47.4k]
  ------------------
 3078|      0|                return res;
 3079|   144M|        } else {
 3080|   144M|            s_mp_setz(DIGITS(mp) + USED(mp), min - USED(mp));
  ------------------
  |  |  335|   144M|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   144M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                          s_mp_setz(DIGITS(mp) + USED(mp), min - USED(mp));
  ------------------
  |  |  333|   144M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   144M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                          s_mp_setz(DIGITS(mp) + USED(mp), min - USED(mp));
  ------------------
  |  |  333|   144M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   144M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 3081|   144M|        }
 3082|       |
 3083|       |        /* Increase precision; should already be 0-filled */
 3084|   144M|        USED(mp) = min;
  ------------------
  |  |  333|   144M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   144M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 3085|   144M|    }
 3086|       |
 3087|   145M|    return MP_OKAY;
  ------------------
  |  |   39|   145M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3088|       |
 3089|   145M|} /* end s_mp_pad() */
s_mp_setz:
 3098|   178M|{
 3099|   178M|    memset(dp, 0, count * sizeof(mp_digit));
 3100|   178M|} /* end s_mp_setz() */
s_mp_copy:
 3109|  7.74M|{
 3110|  7.74M|    memcpy(dp, sp, count * sizeof(mp_digit));
 3111|  7.74M|} /* end s_mp_copy() */
s_mp_alloc:
 3120|  5.03M|{
 3121|  5.03M|    return calloc(nb, ni);
 3122|       |
 3123|  5.03M|} /* end s_mp_alloc() */
s_mp_free:
 3132|  5.03M|{
 3133|  5.03M|    if (ptr) {
  ------------------
  |  Branch (3133:9): [True: 5.03M, False: 0]
  ------------------
 3134|  5.03M|        free(ptr);
 3135|  5.03M|    }
 3136|  5.03M|} /* end s_mp_free() */
s_mp_clamp:
 3145|   208M|{
 3146|   208M|    mp_size used = MP_USED(mp);
  ------------------
  |  |  150|   208M|#define MP_USED(MP) ((MP)->used)
  ------------------
 3147|   386M|    while (used > 1 && DIGIT(mp, used - 1) == 0)
  ------------------
  |  |  336|   385M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   385M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  |  Branch (3147:12): [True: 385M, False: 666k]
  |  Branch (3147:24): [True: 177M, False: 208M]
  ------------------
 3148|   177M|        --used;
 3149|   208M|    MP_USED(mp) = used;
  ------------------
  |  |  150|   208M|#define MP_USED(MP) ((MP)->used)
  ------------------
 3150|   208M|    if (used == 1 && DIGIT(mp, 0) == 0)
  ------------------
  |  |  336|   666k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   666k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  |  Branch (3150:9): [True: 666k, False: 208M]
  |  Branch (3150:22): [True: 413k, False: 253k]
  ------------------
 3151|   413k|        MP_SIGN(mp) = ZPOS;
  ------------------
  |  |  149|   413k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                      MP_SIGN(mp) = ZPOS;
  ------------------
  |  |  326|   413k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   413k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 3152|   208M|} /* end s_mp_clamp() */
s_mp_exch:
 3161|   723k|{
 3162|   723k|    mp_int tmp;
 3163|   723k|    if (!a || !b) {
  ------------------
  |  Branch (3163:9): [True: 0, False: 723k]
  |  Branch (3163:15): [True: 0, False: 723k]
  ------------------
 3164|      0|        return;
 3165|      0|    }
 3166|       |
 3167|   723k|    tmp = *a;
 3168|   723k|    *a = *b;
 3169|   723k|    *b = tmp;
 3170|       |
 3171|   723k|} /* end s_mp_exch() */
s_mp_lshd:
 3189|  10.4M|{
 3190|  10.4M|    mp_err res;
 3191|  10.4M|    unsigned int ix;
 3192|       |
 3193|  10.4M|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|  10.4M|#define ARGCHK(X, Y) assert(X)
  ------------------
 3194|       |
 3195|  10.4M|    if (p == 0)
  ------------------
  |  Branch (3195:9): [True: 0, False: 10.4M]
  ------------------
 3196|      0|        return MP_OKAY;
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3197|       |
 3198|  10.4M|    if (MP_USED(mp) == 1 && MP_DIGIT(mp, 0) == 0)
  ------------------
  |  |  150|  10.4M|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if (MP_USED(mp) == 1 && MP_DIGIT(mp, 0) == 0)
  ------------------
  |  |  153|   714k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  |  Branch (3198:9): [True: 714k, False: 9.74M]
  |  Branch (3198:29): [True: 146, False: 714k]
  ------------------
 3199|    146|        return MP_OKAY;
  ------------------
  |  |   39|    146|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3200|       |
 3201|  10.4M|    if ((res = s_mp_pad(mp, USED(mp) + p)) != MP_OKAY)
  ------------------
  |  |  333|  10.4M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  10.4M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  if ((res = s_mp_pad(mp, USED(mp) + p)) != MP_OKAY)
  ------------------
  |  |   39|  10.4M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (3201:9): [True: 0, False: 10.4M]
  ------------------
 3202|      0|        return res;
 3203|       |
 3204|       |    /* Shift all the significant figures over as needed */
 3205|   198M|    for (ix = USED(mp) - p; ix-- > 0;) {
  ------------------
  |  |  333|  10.4M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  10.4M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3205:29): [True: 188M, False: 10.4M]
  ------------------
 3206|   188M|        DIGIT(mp, ix + p) = DIGIT(mp, ix);
  ------------------
  |  |  336|   188M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   188M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
                      DIGIT(mp, ix + p) = DIGIT(mp, ix);
  ------------------
  |  |  336|   188M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   188M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3207|   188M|    }
 3208|       |
 3209|       |    /* Fill the bottom digits with zeroes */
 3210|  31.6M|    for (ix = 0; (mp_size)ix < p; ix++)
  ------------------
  |  Branch (3210:18): [True: 21.1M, False: 10.4M]
  ------------------
 3211|  21.1M|        DIGIT(mp, ix) = 0;
  ------------------
  |  |  336|  21.1M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  21.1M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3212|       |
 3213|  10.4M|    return MP_OKAY;
  ------------------
  |  |   39|  10.4M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3214|       |
 3215|  10.4M|} /* end s_mp_lshd() */
s_mp_mul_2d:
 3227|  59.5k|{
 3228|  59.5k|    mp_err res;
 3229|  59.5k|    mp_digit dshift, rshift, mask, x, prev = 0;
 3230|  59.5k|    mp_digit *pa = NULL;
 3231|  59.5k|    int i;
 3232|       |
 3233|  59.5k|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|  59.5k|#define ARGCHK(X, Y) assert(X)
  ------------------
 3234|       |
 3235|  59.5k|    dshift = d / MP_DIGIT_BIT;
  ------------------
  |  |  137|  59.5k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  59.5k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
 3236|  59.5k|    d %= MP_DIGIT_BIT;
  ------------------
  |  |  137|  59.5k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  59.5k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
 3237|       |    /* mp_digit >> rshift is undefined behavior for rshift >= MP_DIGIT_BIT */
 3238|       |    /* mod and corresponding mask logic avoid that when d = 0 */
 3239|  59.5k|    rshift = MP_DIGIT_BIT - d;
  ------------------
  |  |  137|  59.5k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  59.5k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
 3240|  59.5k|    rshift %= MP_DIGIT_BIT;
  ------------------
  |  |  137|  59.5k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  59.5k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
 3241|       |    /* mask = (2**d - 1) * 2**(w-d) mod 2**w */
 3242|  59.5k|    mask = (DIGIT_MAX << rshift) + 1;
  ------------------
  |  |  327|  59.5k|#define DIGIT_MAX MP_DIGIT_MAX
  |  |  ------------------
  |  |  |  |   79|  59.5k|#define MP_DIGIT_MAX ULONG_MAX
  |  |  ------------------
  ------------------
 3243|  59.5k|    mask &= DIGIT_MAX - 1;
  ------------------
  |  |  327|  59.5k|#define DIGIT_MAX MP_DIGIT_MAX
  |  |  ------------------
  |  |  |  |   79|  59.5k|#define MP_DIGIT_MAX ULONG_MAX
  |  |  ------------------
  ------------------
 3244|       |    /* bits to be shifted out of the top word */
 3245|  59.5k|    x = MP_DIGIT(mp, MP_USED(mp) - 1) & mask;
  ------------------
  |  |  153|  59.5k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 3246|       |
 3247|  59.5k|    if (MP_OKAY != (res = s_mp_pad(mp, MP_USED(mp) + dshift + (x != 0))))
  ------------------
  |  |   39|  59.5k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
                  if (MP_OKAY != (res = s_mp_pad(mp, MP_USED(mp) + dshift + (x != 0))))
  ------------------
  |  |  150|  59.5k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (3247:9): [True: 0, False: 59.5k]
  ------------------
 3248|      0|        return res;
 3249|       |
 3250|  59.5k|    if (dshift && MP_OKAY != (res = s_mp_lshd(mp, dshift)))
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (3250:9): [True: 0, False: 59.5k]
  |  Branch (3250:19): [True: 0, False: 0]
  ------------------
 3251|      0|        return res;
 3252|       |
 3253|  59.5k|    pa = MP_DIGITS(mp) + dshift;
  ------------------
  |  |  152|  59.5k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3254|       |
 3255|  2.70M|    for (i = MP_USED(mp) - dshift; i > 0; i--) {
  ------------------
  |  |  150|  59.5k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (3255:36): [True: 2.64M, False: 59.5k]
  ------------------
 3256|  2.64M|        x = *pa;
 3257|  2.64M|        *pa++ = (x << d) | prev;
 3258|  2.64M|        prev = (x & mask) >> rshift;
 3259|  2.64M|    }
 3260|       |
 3261|  59.5k|    s_mp_clamp(mp);
 3262|  59.5k|    return MP_OKAY;
  ------------------
  |  |   39|  59.5k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3263|  59.5k|} /* end s_mp_mul_2d() */
s_mp_rshd:
 3275|   128M|{
 3276|   128M|    mp_size ix;
 3277|   128M|    mp_digit *src, *dst;
 3278|       |
 3279|   128M|    if (p == 0)
  ------------------
  |  Branch (3279:9): [True: 36.9k, False: 128M]
  ------------------
 3280|  36.9k|        return;
 3281|       |
 3282|       |    /* Shortcut when all digits are to be shifted off */
 3283|   128M|    if (p >= USED(mp)) {
  ------------------
  |  |  333|   128M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   128M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3283:9): [True: 205k, False: 128M]
  ------------------
 3284|   205k|        s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  335|   205k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   205k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
                      s_mp_setz(DIGITS(mp), ALLOC(mp));
  ------------------
  |  |  334|   205k|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|   205k|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
 3285|   205k|        USED(mp) = 1;
  ------------------
  |  |  333|   205k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   205k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 3286|   205k|        SIGN(mp) = ZPOS;
  ------------------
  |  |  332|   205k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|   205k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                      SIGN(mp) = ZPOS;
  ------------------
  |  |  326|   205k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   205k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 3287|   205k|        return;
 3288|   205k|    }
 3289|       |
 3290|       |    /* Shift all the significant figures over as needed */
 3291|   128M|    dst = MP_DIGITS(mp);
  ------------------
  |  |  152|   128M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3292|   128M|    src = dst + p;
 3293|  3.03G|    for (ix = USED(mp) - p; ix > 0; ix--)
  ------------------
  |  |  333|   128M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   128M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3293:29): [True: 2.90G, False: 128M]
  ------------------
 3294|  2.90G|        *dst++ = *src++;
 3295|       |
 3296|   128M|    MP_USED(mp) -= p;
  ------------------
  |  |  150|   128M|#define MP_USED(MP) ((MP)->used)
  ------------------
 3297|       |    /* Fill the top digits with zeroes */
 3298|  3.01G|    while (p-- > 0)
  ------------------
  |  Branch (3298:12): [True: 2.88G, False: 128M]
  ------------------
 3299|  2.88G|        *dst++ = 0;
 3300|       |
 3301|   128M|} /* end s_mp_rshd() */
s_mp_div_2:
 3310|  36.9k|{
 3311|  36.9k|    s_mp_div_2d(mp, 1);
 3312|       |
 3313|  36.9k|} /* end s_mp_div_2() */
s_mp_mul_2:
 3321|  6.21M|{
 3322|  6.21M|    mp_digit *pd;
 3323|  6.21M|    unsigned int ix, used;
 3324|  6.21M|    mp_digit kin = 0;
 3325|       |
 3326|  6.21M|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|  6.21M|#define ARGCHK(X, Y) assert(X)
  ------------------
 3327|       |
 3328|       |    /* Shift digits leftward by 1 bit */
 3329|  6.21M|    used = MP_USED(mp);
  ------------------
  |  |  150|  6.21M|#define MP_USED(MP) ((MP)->used)
  ------------------
 3330|  6.21M|    pd = MP_DIGITS(mp);
  ------------------
  |  |  152|  6.21M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3331|  1.03G|    for (ix = 0; ix < used; ix++) {
  ------------------
  |  Branch (3331:18): [True: 1.02G, False: 6.21M]
  ------------------
 3332|  1.02G|        mp_digit d = *pd;
 3333|  1.02G|        *pd++ = (d << 1) | kin;
 3334|  1.02G|        kin = (d >> (DIGIT_BIT - 1));
  ------------------
  |  |  328|  1.02G|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  1.02G|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  1.02G|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3335|  1.02G|    }
 3336|       |
 3337|       |    /* Deal with rollover from last digit */
 3338|  6.21M|    if (kin) {
  ------------------
  |  Branch (3338:9): [True: 0, False: 6.21M]
  ------------------
 3339|      0|        if (ix >= ALLOC(mp)) {
  ------------------
  |  |  334|      0|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|      0|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
  |  Branch (3339:13): [True: 0, False: 0]
  ------------------
 3340|      0|            mp_err res;
 3341|      0|            if ((res = s_mp_grow(mp, ALLOC(mp) + 1)) != MP_OKAY)
  ------------------
  |  |  334|      0|#define ALLOC(MP) MP_ALLOC(MP)
  |  |  ------------------
  |  |  |  |  151|      0|#define MP_ALLOC(MP) ((MP)->alloc)
  |  |  ------------------
  ------------------
                          if ((res = s_mp_grow(mp, ALLOC(mp) + 1)) != MP_OKAY)
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (3341:17): [True: 0, False: 0]
  ------------------
 3342|      0|                return res;
 3343|      0|        }
 3344|       |
 3345|      0|        DIGIT(mp, ix) = kin;
  ------------------
  |  |  336|      0|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      0|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3346|      0|        USED(mp) += 1;
  ------------------
  |  |  333|      0|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|      0|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 3347|      0|    }
 3348|       |
 3349|  6.21M|    return MP_OKAY;
  ------------------
  |  |   39|  6.21M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3350|       |
 3351|  6.21M|} /* end s_mp_mul_2() */
s_mp_mod_2d:
 3364|   115k|{
 3365|   115k|    mp_size ndig = (d / DIGIT_BIT), nbit = (d % DIGIT_BIT);
  ------------------
  |  |  328|   115k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|   115k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   115k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  mp_size ndig = (d / DIGIT_BIT), nbit = (d % DIGIT_BIT);
  ------------------
  |  |  328|   115k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|   115k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   115k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3366|   115k|    mp_size ix;
 3367|   115k|    mp_digit dmask;
 3368|       |
 3369|   115k|    if (ndig >= USED(mp))
  ------------------
  |  |  333|   115k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   115k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3369:9): [True: 8.46k, False: 107k]
  ------------------
 3370|  8.46k|        return;
 3371|       |
 3372|       |    /* Flush all the bits above 2^d in its digit */
 3373|   107k|    dmask = ((mp_digit)1 << nbit) - 1;
 3374|   107k|    DIGIT(mp, ndig) &= dmask;
  ------------------
  |  |  336|   107k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   107k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3375|       |
 3376|       |    /* Flush all digits above the one with 2^d in it */
 3377|  1.59M|    for (ix = ndig + 1; ix < USED(mp); ix++)
  ------------------
  |  |  333|  1.59M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  1.59M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3377:25): [True: 1.48M, False: 107k]
  ------------------
 3378|  1.48M|        DIGIT(mp, ix) = 0;
  ------------------
  |  |  336|  1.48M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  1.48M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3379|       |
 3380|   107k|    s_mp_clamp(mp);
 3381|       |
 3382|   107k|} /* end s_mp_mod_2d() */
s_mp_div_2d:
 3395|  37.0k|{
 3396|  37.0k|    int ix;
 3397|  37.0k|    mp_digit save, next, mask, lshift;
 3398|       |
 3399|  37.0k|    s_mp_rshd(mp, d / DIGIT_BIT);
  ------------------
  |  |  328|  37.0k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  37.0k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  37.0k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3400|  37.0k|    d %= DIGIT_BIT;
  ------------------
  |  |  328|  37.0k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  37.0k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  37.0k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3401|       |    /* mp_digit << lshift is undefined behavior for lshift >= MP_DIGIT_BIT */
 3402|       |    /* mod and corresponding mask logic avoid that when d = 0 */
 3403|  37.0k|    lshift = DIGIT_BIT - d;
  ------------------
  |  |  328|  37.0k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  37.0k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  37.0k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3404|  37.0k|    lshift %= DIGIT_BIT;
  ------------------
  |  |  328|  37.0k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  37.0k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  37.0k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3405|  37.0k|    mask = ((mp_digit)1 << d) - 1;
 3406|  37.0k|    save = 0;
 3407|   462k|    for (ix = USED(mp) - 1; ix >= 0; ix--) {
  ------------------
  |  |  333|  37.0k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  37.0k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (3407:29): [True: 425k, False: 37.0k]
  ------------------
 3408|   425k|        next = DIGIT(mp, ix) & mask;
  ------------------
  |  |  336|   425k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   425k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3409|   425k|        DIGIT(mp, ix) = (save << lshift) | (DIGIT(mp, ix) >> d);
  ------------------
  |  |  336|   425k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   425k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
                      DIGIT(mp, ix) = (save << lshift) | (DIGIT(mp, ix) >> d);
  ------------------
  |  |  336|   425k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   425k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3410|   425k|        save = next;
 3411|   425k|    }
 3412|  37.0k|    s_mp_clamp(mp);
 3413|       |
 3414|  37.0k|} /* end s_mp_div_2d() */
s_mp_norm:
 3433|   500k|{
 3434|   500k|    mp_digit d;
 3435|   500k|    mp_digit mask;
 3436|   500k|    mp_digit b_msd;
 3437|   500k|    mp_err res = MP_OKAY;
  ------------------
  |  |   39|   500k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3438|       |
 3439|   500k|    ARGCHK(a != NULL && b != NULL && pd != NULL, MP_BADARG);
  ------------------
  |  |  355|   500k|#define ARGCHK(X, Y) assert(X)
  ------------------
 3440|       |
 3441|   500k|    d = 0;
 3442|   500k|    mask = DIGIT_MAX & ~(DIGIT_MAX >> 1); /* mask is msb of digit */
  ------------------
  |  |  327|   500k|#define DIGIT_MAX MP_DIGIT_MAX
  |  |  ------------------
  |  |  |  |   79|   500k|#define MP_DIGIT_MAX ULONG_MAX
  |  |  ------------------
  ------------------
                  mask = DIGIT_MAX & ~(DIGIT_MAX >> 1); /* mask is msb of digit */
  ------------------
  |  |  327|   500k|#define DIGIT_MAX MP_DIGIT_MAX
  |  |  ------------------
  |  |  |  |   79|   500k|#define MP_DIGIT_MAX ULONG_MAX
  |  |  ------------------
  ------------------
 3443|   500k|    b_msd = DIGIT(b, USED(b) - 1);
  ------------------
  |  |  336|   500k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   500k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3444|   502k|    while (!(b_msd & mask)) {
  ------------------
  |  Branch (3444:12): [True: 1.93k, False: 500k]
  ------------------
 3445|  1.93k|        b_msd <<= 1;
 3446|  1.93k|        ++d;
 3447|  1.93k|    }
 3448|       |
 3449|   500k|    if (d) {
  ------------------
  |  Branch (3449:9): [True: 31, False: 500k]
  ------------------
 3450|     31|        MP_CHECKOK(s_mp_mul_2d(a, d));
  ------------------
  |  |  319|     31|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|     31|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 31]
  |  |  ------------------
  |  |  320|     31|    goto CLEANUP
  ------------------
 3451|     31|        MP_CHECKOK(s_mp_mul_2d(b, d));
  ------------------
  |  |  319|     31|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|     31|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 31]
  |  |  ------------------
  |  |  320|     31|    goto CLEANUP
  ------------------
 3452|     31|    }
 3453|       |
 3454|   500k|    *pd = d;
 3455|   500k|CLEANUP:
 3456|   500k|    return res;
 3457|       |
 3458|   500k|} /* end s_mp_norm() */
s_mp_add_d:
 3471|  2.39k|{
 3472|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
 3473|       |    mp_word w, k = 0;
 3474|       |    mp_size ix = 1;
 3475|       |
 3476|       |    w = (mp_word)DIGIT(mp, 0) + d;
 3477|       |    DIGIT(mp, 0) = ACCUM(w);
 3478|       |    k = CARRYOUT(w);
 3479|       |
 3480|       |    while (ix < USED(mp) && k) {
 3481|       |        w = (mp_word)DIGIT(mp, ix) + k;
 3482|       |        DIGIT(mp, ix) = ACCUM(w);
 3483|       |        k = CARRYOUT(w);
 3484|       |        ++ix;
 3485|       |    }
 3486|       |
 3487|       |    if (k != 0) {
 3488|       |        mp_err res;
 3489|       |
 3490|       |        if ((res = s_mp_pad(mp, USED(mp) + 1)) != MP_OKAY)
 3491|       |            return res;
 3492|       |
 3493|       |        DIGIT(mp, ix) = (mp_digit)k;
 3494|       |    }
 3495|       |
 3496|       |    return MP_OKAY;
 3497|       |#else
 3498|  2.39k|    mp_digit *pmp = MP_DIGITS(mp);
  ------------------
  |  |  152|  2.39k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3499|  2.39k|    mp_digit sum, mp_i, carry = 0;
 3500|  2.39k|    mp_err res = MP_OKAY;
  ------------------
  |  |   39|  2.39k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3501|  2.39k|    int used = (int)MP_USED(mp);
  ------------------
  |  |  150|  2.39k|#define MP_USED(MP) ((MP)->used)
  ------------------
 3502|       |
 3503|  2.39k|    mp_i = *pmp;
 3504|  2.39k|    *pmp++ = sum = d + mp_i;
 3505|  2.39k|    carry = (sum < d);
 3506|  2.39k|    while (carry && --used > 0) {
  ------------------
  |  Branch (3506:12): [True: 0, False: 2.39k]
  |  Branch (3506:21): [True: 0, False: 0]
  ------------------
 3507|      0|        mp_i = *pmp;
 3508|      0|        *pmp++ = sum = carry + mp_i;
 3509|      0|        carry = !sum;
 3510|      0|    }
 3511|  2.39k|    if (carry && !used) {
  ------------------
  |  Branch (3511:9): [True: 0, False: 2.39k]
  |  Branch (3511:18): [True: 0, False: 0]
  ------------------
 3512|       |        /* mp is growing */
 3513|      0|        used = MP_USED(mp);
  ------------------
  |  |  150|      0|#define MP_USED(MP) ((MP)->used)
  ------------------
 3514|      0|        MP_CHECKOK(s_mp_pad(mp, used + 1));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 3515|      0|        MP_DIGIT(mp, used) = carry;
  ------------------
  |  |  153|      0|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 3516|      0|    }
 3517|  2.39k|CLEANUP:
 3518|  2.39k|    return res;
 3519|  2.39k|#endif
 3520|  2.39k|} /* end s_mp_add_d() */
s_mp_sub_d:
 3529|  56.8k|{
 3530|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 3531|       |    mp_word w, b = 0;
 3532|       |    mp_size ix = 1;
 3533|       |
 3534|       |    /* Compute initial subtraction    */
 3535|       |    w = (RADIX + (mp_word)DIGIT(mp, 0)) - d;
 3536|       |    b = CARRYOUT(w) ? 0 : 1;
 3537|       |    DIGIT(mp, 0) = ACCUM(w);
 3538|       |
 3539|       |    /* Propagate borrows leftward     */
 3540|       |    while (b && ix < USED(mp)) {
 3541|       |        w = (RADIX + (mp_word)DIGIT(mp, ix)) - b;
 3542|       |        b = CARRYOUT(w) ? 0 : 1;
 3543|       |        DIGIT(mp, ix) = ACCUM(w);
 3544|       |        ++ix;
 3545|       |    }
 3546|       |
 3547|       |    /* Remove leading zeroes          */
 3548|       |    s_mp_clamp(mp);
 3549|       |
 3550|       |    /* If we have a borrow out, it's a violation of the input invariant */
 3551|       |    if (b)
 3552|       |        return MP_RANGE;
 3553|       |    else
 3554|       |        return MP_OKAY;
 3555|       |#else
 3556|  56.8k|    mp_digit *pmp = MP_DIGITS(mp);
  ------------------
  |  |  152|  56.8k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3557|  56.8k|    mp_digit mp_i, diff, borrow;
 3558|  56.8k|    mp_size used = MP_USED(mp);
  ------------------
  |  |  150|  56.8k|#define MP_USED(MP) ((MP)->used)
  ------------------
 3559|       |
 3560|  56.8k|    mp_i = *pmp;
 3561|  56.8k|    *pmp++ = diff = mp_i - d;
 3562|  56.8k|    borrow = (diff > mp_i);
 3563|  56.8k|    while (borrow && --used) {
  ------------------
  |  Branch (3563:12): [True: 0, False: 56.8k]
  |  Branch (3563:22): [True: 0, False: 0]
  ------------------
 3564|      0|        mp_i = *pmp;
 3565|      0|        *pmp++ = diff = mp_i - borrow;
 3566|      0|        borrow = (diff > mp_i);
 3567|      0|    }
 3568|  56.8k|    s_mp_clamp(mp);
 3569|  56.8k|    return (borrow && !used) ? MP_RANGE : MP_OKAY;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
                  return (borrow && !used) ? MP_RANGE : MP_OKAY;
  ------------------
  |  |   39|  56.8k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (3569:13): [True: 0, False: 56.8k]
  |  Branch (3569:23): [True: 0, False: 0]
  ------------------
 3570|  56.8k|#endif
 3571|  56.8k|} /* end s_mp_sub_d() */
s_mp_mul_d:
 3580|  5.48M|{
 3581|  5.48M|    mp_err res;
 3582|  5.48M|    mp_size used;
 3583|  5.48M|    int pow;
 3584|       |
 3585|  5.48M|    if (!d) {
  ------------------
  |  Branch (3585:9): [True: 0, False: 5.48M]
  ------------------
 3586|      0|        mp_zero(a);
 3587|      0|        return MP_OKAY;
  ------------------
  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3588|      0|    }
 3589|  5.48M|    if (d == 1)
  ------------------
  |  Branch (3589:9): [True: 160k, False: 5.32M]
  ------------------
 3590|   160k|        return MP_OKAY;
  ------------------
  |  |   39|   160k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3591|  5.32M|    if (0 <= (pow = s_mp_ispow2d(d))) {
  ------------------
  |  Branch (3591:9): [True: 59.4k, False: 5.26M]
  ------------------
 3592|  59.4k|        return s_mp_mul_2d(a, (mp_digit)pow);
 3593|  59.4k|    }
 3594|       |
 3595|  5.26M|    used = MP_USED(a);
  ------------------
  |  |  150|  5.26M|#define MP_USED(MP) ((MP)->used)
  ------------------
 3596|  5.26M|    MP_CHECKOK(s_mp_pad(a, used + 1));
  ------------------
  |  |  319|  5.26M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  5.26M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 5.26M]
  |  |  ------------------
  |  |  320|  5.26M|    goto CLEANUP
  ------------------
 3597|       |
 3598|  5.26M|    s_mpv_mul_d(MP_DIGITS(a), used, d, MP_DIGITS(a));
  ------------------
  |  |  181|  5.26M|    ((mp_digit *)c)[a_len] = s_mpv_mul_set_vec64(c, a, a_len, b)
  ------------------
 3599|       |
 3600|  5.26M|    s_mp_clamp(a);
 3601|       |
 3602|  5.26M|CLEANUP:
 3603|  5.26M|    return res;
 3604|       |
 3605|  5.26M|} /* end s_mp_mul_d() */
s_mp_add_3arg:
 3824|   130k|{
 3825|   130k|    mp_digit *pa, *pb, *pc;
 3826|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
 3827|       |    mp_word w = 0;
 3828|       |#else
 3829|   130k|    mp_digit sum, carry = 0, d;
 3830|   130k|#endif
 3831|   130k|    mp_size ix;
 3832|   130k|    mp_size used;
 3833|   130k|    mp_err res;
 3834|       |
 3835|   130k|    MP_SIGN(c) = MP_SIGN(a);
  ------------------
  |  |  149|   130k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(c) = MP_SIGN(a);
  ------------------
  |  |  149|   130k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
 3836|   130k|    if (MP_USED(a) < MP_USED(b)) {
  ------------------
  |  |  150|   130k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if (MP_USED(a) < MP_USED(b)) {
  ------------------
  |  |  150|   130k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (3836:9): [True: 72.6k, False: 58.2k]
  ------------------
 3837|  72.6k|        const mp_int *xch = a;
 3838|  72.6k|        a = b;
 3839|  72.6k|        b = xch;
 3840|  72.6k|    }
 3841|       |
 3842|       |    /* Make sure a has enough precision for the output value */
 3843|   130k|    if (MP_OKAY != (res = s_mp_pad(c, MP_USED(a))))
  ------------------
  |  |   39|   130k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
                  if (MP_OKAY != (res = s_mp_pad(c, MP_USED(a))))
  ------------------
  |  |  150|   130k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (3843:9): [True: 0, False: 130k]
  ------------------
 3844|      0|        return res;
 3845|       |
 3846|       |    /*
 3847|       |     Add up all digits up to the precision of b.  If b had initially
 3848|       |     the same precision as a, or greater, we took care of it by the
 3849|       |     exchange step above, so there is no problem.  If b had initially
 3850|       |     less precision, we'll have to make sure the carry out is duly
 3851|       |     propagated upward among the higher-order digits of the sum.
 3852|       |    */
 3853|   130k|    pa = MP_DIGITS(a);
  ------------------
  |  |  152|   130k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3854|   130k|    pb = MP_DIGITS(b);
  ------------------
  |  |  152|   130k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3855|   130k|    pc = MP_DIGITS(c);
  ------------------
  |  |  152|   130k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 3856|   130k|    used = MP_USED(b);
  ------------------
  |  |  150|   130k|#define MP_USED(MP) ((MP)->used)
  ------------------
 3857|  2.44M|    for (ix = 0; ix < used; ix++) {
  ------------------
  |  Branch (3857:18): [True: 2.31M, False: 130k]
  ------------------
 3858|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
 3859|       |        w = w + *pa++ + *pb++;
 3860|       |        *pc++ = ACCUM(w);
 3861|       |        w = CARRYOUT(w);
 3862|       |#else
 3863|  2.31M|        d = *pa++;
 3864|  2.31M|        sum = d + *pb++;
 3865|  2.31M|        d = (sum < d); /* detect overflow */
 3866|  2.31M|        *pc++ = sum += carry;
 3867|  2.31M|        carry = d + (sum < carry); /* detect overflow */
 3868|  2.31M|#endif
 3869|  2.31M|    }
 3870|       |
 3871|       |    /* If we run out of 'b' digits before we're actually done, make
 3872|       |     sure the carries get propagated upward...
 3873|       |   */
 3874|   710k|    for (used = MP_USED(a); ix < used; ++ix) {
  ------------------
  |  |  150|   130k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (3874:29): [True: 579k, False: 130k]
  ------------------
 3875|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
 3876|       |        w = w + *pa++;
 3877|       |        *pc++ = ACCUM(w);
 3878|       |        w = CARRYOUT(w);
 3879|       |#else
 3880|   579k|        *pc++ = sum = carry + *pa++;
 3881|   579k|        carry = (sum < carry);
 3882|   579k|#endif
 3883|   579k|    }
 3884|       |
 3885|       |/* If there's an overall carry out, increase precision and include
 3886|       |     it.  We could have done this initially, but why touch the memory
 3887|       |     allocator unless we're sure we have to?
 3888|       |   */
 3889|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_ADD_WORD)
 3890|       |    if (w) {
 3891|       |        if ((res = s_mp_pad(c, used + 1)) != MP_OKAY)
 3892|       |            return res;
 3893|       |
 3894|       |        DIGIT(c, used) = (mp_digit)w;
 3895|       |        ++used;
 3896|       |    }
 3897|       |#else
 3898|   130k|    if (carry) {
  ------------------
  |  Branch (3898:9): [True: 6.68k, False: 124k]
  ------------------
 3899|  6.68k|        if ((res = s_mp_pad(c, used + 1)) != MP_OKAY)
  ------------------
  |  |   39|  6.68k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (3899:13): [True: 0, False: 6.68k]
  ------------------
 3900|      0|            return res;
 3901|       |
 3902|  6.68k|        DIGIT(c, used) = carry;
  ------------------
  |  |  336|  6.68k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  6.68k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 3903|  6.68k|        ++used;
 3904|  6.68k|    }
 3905|   130k|#endif
 3906|   130k|    MP_USED(c) = used;
  ------------------
  |  |  150|   130k|#define MP_USED(MP) ((MP)->used)
  ------------------
 3907|   130k|    return MP_OKAY;
  ------------------
  |  |   39|   130k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 3908|   130k|}
s_mp_sub:
 4001|  41.1M|{
 4002|  41.1M|    mp_digit *pa, *pb, *limit;
 4003|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4004|       |    mp_sword w = 0;
 4005|       |#else
 4006|  41.1M|    mp_digit d, diff, borrow = 0;
 4007|  41.1M|#endif
 4008|       |
 4009|       |    /*
 4010|       |    Subtract and propagate borrow.  Up to the precision of b, this
 4011|       |    accounts for the digits of b; after that, we just make sure the
 4012|       |    carries get to the right place.  This saves having to pad b out to
 4013|       |    the precision of a just to make the loops work right...
 4014|       |   */
 4015|  41.1M|    pa = MP_DIGITS(a);
  ------------------
  |  |  152|  41.1M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4016|  41.1M|    pb = MP_DIGITS(b);
  ------------------
  |  |  152|  41.1M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4017|  41.1M|    limit = pb + MP_USED(b);
  ------------------
  |  |  150|  41.1M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4018|   972M|    while (pb < limit) {
  ------------------
  |  Branch (4018:12): [True: 931M, False: 41.1M]
  ------------------
 4019|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4020|       |        w = w + *pa - *pb++;
 4021|       |        *pa++ = ACCUM(w);
 4022|       |        w >>= MP_DIGIT_BIT;
 4023|       |#else
 4024|   931M|        d = *pa;
 4025|   931M|        diff = d - *pb++;
 4026|   931M|        d = (diff > d); /* detect borrow */
 4027|   931M|        if (borrow && --diff == MP_DIGIT_MAX)
  ------------------
  |  |   79|   472M|#define MP_DIGIT_MAX ULONG_MAX
  ------------------
  |  Branch (4027:13): [True: 472M, False: 458M]
  |  Branch (4027:23): [True: 27.4k, False: 472M]
  ------------------
 4028|  27.4k|            ++d;
 4029|   931M|        *pa++ = diff;
 4030|   931M|        borrow = d;
 4031|   931M|#endif
 4032|   931M|    }
 4033|  41.1M|    limit = MP_DIGITS(a) + MP_USED(a);
  ------------------
  |  |  152|  41.1M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
                  limit = MP_DIGITS(a) + MP_USED(a);
  ------------------
  |  |  150|  41.1M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4034|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4035|       |    while (w && pa < limit) {
 4036|       |        w = w + *pa;
 4037|       |        *pa++ = ACCUM(w);
 4038|       |        w >>= MP_DIGIT_BIT;
 4039|       |    }
 4040|       |#else
 4041|  65.3M|    while (borrow && pa < limit) {
  ------------------
  |  Branch (4041:12): [True: 24.2M, False: 41.1M]
  |  Branch (4041:22): [True: 24.2M, False: 0]
  ------------------
 4042|  24.2M|        d = *pa;
 4043|  24.2M|        *pa++ = diff = d - borrow;
 4044|  24.2M|        borrow = (diff > d);
 4045|  24.2M|    }
 4046|  41.1M|#endif
 4047|       |
 4048|       |    /* Clobber any leading zeroes we created    */
 4049|  41.1M|    s_mp_clamp(a);
 4050|       |
 4051|       |/*
 4052|       |     If there was a borrow out, then |b| > |a| in violation
 4053|       |     of our input invariant.  We've already done the work,
 4054|       |     but we'll at least complain about it...
 4055|       |   */
 4056|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4057|       |    return w ? MP_RANGE : MP_OKAY;
 4058|       |#else
 4059|  41.1M|    return borrow ? MP_RANGE : MP_OKAY;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
                  return borrow ? MP_RANGE : MP_OKAY;
  ------------------
  |  |   39|  41.1M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4059:12): [True: 0, False: 41.1M]
  ------------------
 4060|  41.1M|#endif
 4061|  41.1M|} /* end s_mp_sub() */
s_mp_sub_3arg:
 4068|   202k|{
 4069|   202k|    mp_digit *pa, *pb, *pc;
 4070|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4071|       |    mp_sword w = 0;
 4072|       |#else
 4073|   202k|    mp_digit d, diff, borrow = 0;
 4074|   202k|#endif
 4075|   202k|    int ix, limit;
 4076|   202k|    mp_err res;
 4077|       |
 4078|   202k|    MP_SIGN(c) = MP_SIGN(a);
  ------------------
  |  |  149|   202k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(c) = MP_SIGN(a);
  ------------------
  |  |  149|   202k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
 4079|       |
 4080|       |    /* Make sure a has enough precision for the output value */
 4081|   202k|    if (MP_OKAY != (res = s_mp_pad(c, MP_USED(a))))
  ------------------
  |  |   39|   202k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
                  if (MP_OKAY != (res = s_mp_pad(c, MP_USED(a))))
  ------------------
  |  |  150|   202k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (4081:9): [True: 0, False: 202k]
  ------------------
 4082|      0|        return res;
 4083|       |
 4084|       |    /*
 4085|       |    Subtract and propagate borrow.  Up to the precision of b, this
 4086|       |    accounts for the digits of b; after that, we just make sure the
 4087|       |    carries get to the right place.  This saves having to pad b out to
 4088|       |    the precision of a just to make the loops work right...
 4089|       |   */
 4090|   202k|    pa = MP_DIGITS(a);
  ------------------
  |  |  152|   202k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4091|   202k|    pb = MP_DIGITS(b);
  ------------------
  |  |  152|   202k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4092|   202k|    pc = MP_DIGITS(c);
  ------------------
  |  |  152|   202k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4093|   202k|    limit = MP_USED(b);
  ------------------
  |  |  150|   202k|#define MP_USED(MP) ((MP)->used)
  ------------------
 4094|  3.29M|    for (ix = 0; ix < limit; ++ix) {
  ------------------
  |  Branch (4094:18): [True: 3.09M, False: 202k]
  ------------------
 4095|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4096|       |        w = w + *pa++ - *pb++;
 4097|       |        *pc++ = ACCUM(w);
 4098|       |        w >>= MP_DIGIT_BIT;
 4099|       |#else
 4100|  3.09M|        d = *pa++;
 4101|  3.09M|        diff = d - *pb++;
 4102|  3.09M|        d = (diff > d);
 4103|  3.09M|        if (borrow && --diff == MP_DIGIT_MAX)
  ------------------
  |  |   79|   879k|#define MP_DIGIT_MAX ULONG_MAX
  ------------------
  |  Branch (4103:13): [True: 879k, False: 2.21M]
  |  Branch (4103:23): [True: 3.31k, False: 876k]
  ------------------
 4104|  3.31k|            ++d;
 4105|  3.09M|        *pc++ = diff;
 4106|  3.09M|        borrow = d;
 4107|  3.09M|#endif
 4108|  3.09M|    }
 4109|   245k|    for (limit = MP_USED(a); ix < limit; ++ix) {
  ------------------
  |  |  150|   202k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (4109:30): [True: 43.3k, False: 202k]
  ------------------
 4110|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4111|       |        w = w + *pa++;
 4112|       |        *pc++ = ACCUM(w);
 4113|       |        w >>= MP_DIGIT_BIT;
 4114|       |#else
 4115|  43.3k|        d = *pa++;
 4116|  43.3k|        *pc++ = diff = d - borrow;
 4117|  43.3k|        borrow = (diff > d);
 4118|  43.3k|#endif
 4119|  43.3k|    }
 4120|       |
 4121|       |    /* Clobber any leading zeroes we created    */
 4122|   202k|    MP_USED(c) = ix;
  ------------------
  |  |  150|   202k|#define MP_USED(MP) ((MP)->used)
  ------------------
 4123|   202k|    s_mp_clamp(c);
 4124|       |
 4125|       |/*
 4126|       |     If there was a borrow out, then |b| > |a| in violation
 4127|       |     of our input invariant.  We've already done the work,
 4128|       |     but we'll at least complain about it...
 4129|       |   */
 4130|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_SUB_WORD)
 4131|       |    return w ? MP_RANGE : MP_OKAY;
 4132|       |#else
 4133|   202k|    return borrow ? MP_RANGE : MP_OKAY;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
                  return borrow ? MP_RANGE : MP_OKAY;
  ------------------
  |  |   39|   202k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4133:12): [True: 0, False: 202k]
  ------------------
 4134|   202k|#endif
 4135|   202k|}
s_mp_mul:
 4141|   131k|{
 4142|   131k|    return mp_mul(a, b, a);
 4143|   131k|} /* end s_mp_mul() */
s_mpv_mul_d_add_propCT:
 4178|  1.15M|{
 4179|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_MUL_WORD)
 4180|       |    mp_digit d = 0;
 4181|       |
 4182|       |    c_len -= a_len;
 4183|       |    /* Inner product:  Digits of a */
 4184|       |    while (a_len--) {
 4185|       |        mp_word w = ((mp_word)b * *a++) + *c + d;
 4186|       |        *c++ = ACCUM(w);
 4187|       |        d = CARRYOUT(w);
 4188|       |    }
 4189|       |
 4190|       |    /* propagate the carry to the end, even if carry is zero */
 4191|       |    while (c_len--) {
 4192|       |        mp_word w = (mp_word)*c + d;
 4193|       |        *c++ = ACCUM(w);
 4194|       |        d = CARRYOUT(w);
 4195|       |    }
 4196|       |#else
 4197|  1.15M|    mp_digit carry = 0;
 4198|  1.15M|    c_len -= a_len;
 4199|  38.2M|    while (a_len--) {
  ------------------
  |  Branch (4199:12): [True: 37.1M, False: 1.15M]
  ------------------
 4200|  37.1M|        mp_digit a_i = *a++;
 4201|  37.1M|        mp_digit a0b0, a1b1;
 4202|  37.1M|        MP_MUL_DxD(a_i, b, a1b1, a0b0);
  ------------------
  |  | 4157|  37.1M|    {                                                              \
  |  | 4158|  37.1M|        mp_digit a0b1, a1b0;                                       \
  |  | 4159|  37.1M|        Plo = (a & MP_HALF_DIGIT_MAX) * (b & MP_HALF_DIGIT_MAX);   \
  |  |  ------------------
  |  |  |  |   81|  37.1M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  |                       Plo = (a & MP_HALF_DIGIT_MAX) * (b & MP_HALF_DIGIT_MAX);   \
  |  |  ------------------
  |  |  |  |   81|  37.1M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  | 4160|  37.1M|        Phi = (a >> MP_HALF_DIGIT_BIT) * (b >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       Phi = (a >> MP_HALF_DIGIT_BIT) * (b >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4161|  37.1M|        a0b1 = (a & MP_HALF_DIGIT_MAX) * (b >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |   81|  37.1M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  |                       a0b1 = (a & MP_HALF_DIGIT_MAX) * (b >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4162|  37.1M|        a1b0 = (a >> MP_HALF_DIGIT_BIT) * (b & MP_HALF_DIGIT_MAX); \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       a1b0 = (a >> MP_HALF_DIGIT_BIT) * (b & MP_HALF_DIGIT_MAX); \
  |  |  ------------------
  |  |  |  |   81|  37.1M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  | 4163|  37.1M|        a1b0 += a0b1;                                              \
  |  | 4164|  37.1M|        Phi += a1b0 >> MP_HALF_DIGIT_BIT;                          \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4165|  37.1M|        Phi += (MP_CT_LTU(a1b0, a0b1)) << MP_HALF_DIGIT_BIT;       \
  |  |  ------------------
  |  |  |  |  188|  37.1M|#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
  |  |  |  |  ------------------
  |  |  |  |  |  |  186|  37.1M|    MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  181|  37.1M|#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r)      /* mask, l and r are booleans */
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  |  180|  37.1M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  187|  37.1M|               (MP_CT_HIGH_TO_LOW(d)), c)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       Phi += (MP_CT_LTU(a1b0, a0b1)) << MP_HALF_DIGIT_BIT;       \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4166|  37.1M|        a1b0 <<= MP_HALF_DIGIT_BIT;                                \
  |  |  ------------------
  |  |  |  |  141|  37.1M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  37.1M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  37.1M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4167|  37.1M|        Plo += a1b0;                                               \
  |  | 4168|  37.1M|        Phi += MP_CT_LTU(Plo, a1b0);                               \
  |  |  ------------------
  |  |  |  |  188|  37.1M|#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
  |  |  |  |  ------------------
  |  |  |  |  |  |  186|  37.1M|    MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  181|  37.1M|#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r)      /* mask, l and r are booleans */
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  |  180|  37.1M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  187|  37.1M|               (MP_CT_HIGH_TO_LOW(d)), c)
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4169|  37.1M|    }
  ------------------
 4203|       |
 4204|  37.1M|        a0b0 += carry;
 4205|  37.1M|        a1b1 += MP_CT_LTU(a0b0, carry);
  ------------------
  |  |  188|  37.1M|#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
  |  |  ------------------
  |  |  |  |  186|  37.1M|    MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
  |  |  |  |  ------------------
  |  |  |  |  |  |  181|  37.1M|#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r)      /* mask, l and r are booleans */
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  180|  37.1M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |  187|  37.1M|               (MP_CT_HIGH_TO_LOW(d)), c)
  |  |  ------------------
  ------------------
 4206|  37.1M|        a0b0 += a_i = *c;
 4207|  37.1M|        a1b1 += MP_CT_LTU(a0b0, a_i);
  ------------------
  |  |  188|  37.1M|#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
  |  |  ------------------
  |  |  |  |  186|  37.1M|    MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
  |  |  |  |  ------------------
  |  |  |  |  |  |  181|  37.1M|#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r)      /* mask, l and r are booleans */
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  180|  37.1M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |  187|  37.1M|               (MP_CT_HIGH_TO_LOW(d)), c)
  |  |  ------------------
  ------------------
 4208|       |
 4209|  37.1M|        *c++ = a0b0;
 4210|  37.1M|        carry = a1b1;
 4211|  37.1M|    }
 4212|       |    /* propagate the carry to the end, even if carry is zero */
 4213|  21.4M|    while (c_len--) {
  ------------------
  |  Branch (4213:12): [True: 20.2M, False: 1.15M]
  ------------------
 4214|  20.2M|        mp_digit c_i = *c;
 4215|  20.2M|        carry += c_i;
 4216|  20.2M|        *c++ = carry;
 4217|  20.2M|        carry = MP_CT_LTU(carry, c_i);
  ------------------
  |  |  188|  20.2M|#define MP_CT_LTU(a, b) MP_CT_OVERFLOW(a, b, MP_CT_LT(a, b), b)
  |  |  ------------------
  |  |  |  |  186|  20.2M|    MP_CT_SELB(MP_CT_HIGH_TO_LOW((a) ^ (b)), \
  |  |  |  |  ------------------
  |  |  |  |  |  |  181|  20.2M|#define MP_CT_SELB(m, l, r) MP_CT_SEL(m, l, r)      /* mask, l and r are booleans */
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  180|  20.2M|#define MP_CT_SEL(m, l, r) ((r) ^ ((m) & ((r) ^ (l))))
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |  187|  20.2M|               (MP_CT_HIGH_TO_LOW(d)), c)
  |  |  ------------------
  ------------------
 4218|  20.2M|    }
 4219|  1.15M|#endif
 4220|  1.15M|}
s_mpv_sqr_add_prop:
 4364|  6.37M|{
 4365|       |#if !defined(MP_NO_MP_WORD) && !defined(MP_NO_MUL_WORD)
 4366|       |    mp_word w;
 4367|       |    mp_digit d;
 4368|       |    mp_size ix;
 4369|       |
 4370|       |    w = 0;
 4371|       |#define ADD_SQUARE(n)                     \
 4372|       |    d = pa[n];                            \
 4373|       |    w += (d * (mp_word)d) + ps[2 * n];    \
 4374|       |    ps[2 * n] = ACCUM(w);                 \
 4375|       |    w = (w >> DIGIT_BIT) + ps[2 * n + 1]; \
 4376|       |    ps[2 * n + 1] = ACCUM(w);             \
 4377|       |    w = (w >> DIGIT_BIT)
 4378|       |
 4379|       |    for (ix = a_len; ix >= 4; ix -= 4) {
 4380|       |        ADD_SQUARE(0);
 4381|       |        ADD_SQUARE(1);
 4382|       |        ADD_SQUARE(2);
 4383|       |        ADD_SQUARE(3);
 4384|       |        pa += 4;
 4385|       |        ps += 8;
 4386|       |    }
 4387|       |    if (ix) {
 4388|       |        ps += 2 * ix;
 4389|       |        pa += ix;
 4390|       |        switch (ix) {
 4391|       |            case 3:
 4392|       |                ADD_SQUARE(-3); /* FALLTHRU */
 4393|       |            case 2:
 4394|       |                ADD_SQUARE(-2); /* FALLTHRU */
 4395|       |            case 1:
 4396|       |                ADD_SQUARE(-1); /* FALLTHRU */
 4397|       |            case 0:
 4398|       |                break;
 4399|       |        }
 4400|       |    }
 4401|       |    while (w) {
 4402|       |        w += *ps;
 4403|       |        *ps++ = ACCUM(w);
 4404|       |        w = (w >> DIGIT_BIT);
 4405|       |    }
 4406|       |#else
 4407|  6.37M|    mp_digit carry = 0;
 4408|   520M|    while (a_len--) {
  ------------------
  |  Branch (4408:12): [True: 513M, False: 6.37M]
  ------------------
 4409|   513M|        mp_digit a_i = *pa++;
 4410|   513M|        mp_digit a0a0, a1a1;
 4411|       |
 4412|   513M|        MP_SQR_D(a_i, a1a1, a0a0);
  ------------------
  |  | 4347|   513M|    {                                                              \
  |  | 4348|   513M|        mp_digit Pmid;                                             \
  |  | 4349|   513M|        Plo = (a & MP_HALF_DIGIT_MAX) * (a & MP_HALF_DIGIT_MAX);   \
  |  |  ------------------
  |  |  |  |   81|   513M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  |                       Plo = (a & MP_HALF_DIGIT_MAX) * (a & MP_HALF_DIGIT_MAX);   \
  |  |  ------------------
  |  |  |  |   81|   513M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  | 4350|   513M|        Phi = (a >> MP_HALF_DIGIT_BIT) * (a >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |  141|   513M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|   513M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|   513M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       Phi = (a >> MP_HALF_DIGIT_BIT) * (a >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |  141|   513M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|   513M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|   513M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4351|   513M|        Pmid = (a & MP_HALF_DIGIT_MAX) * (a >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |   81|   513M|#define MP_HALF_DIGIT_MAX UINT_MAX
  |  |  ------------------
  |  |                       Pmid = (a & MP_HALF_DIGIT_MAX) * (a >> MP_HALF_DIGIT_BIT); \
  |  |  ------------------
  |  |  |  |  141|   513M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|   513M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|   513M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4352|   513M|        Phi += Pmid >> (MP_HALF_DIGIT_BIT - 1);                    \
  |  |  ------------------
  |  |  |  |  141|   513M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|   513M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|   513M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4353|   513M|        Pmid <<= (MP_HALF_DIGIT_BIT + 1);                          \
  |  |  ------------------
  |  |  |  |  141|   513M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|   513M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|   513M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 4354|   513M|        Plo += Pmid;                                               \
  |  | 4355|   513M|        if (Plo < Pmid)                                            \
  |  |  ------------------
  |  |  |  Branch (4355:13): [True: 170M, False: 343M]
  |  |  ------------------
  |  | 4356|   513M|            ++Phi;                                                 \
  |  | 4357|   513M|    }
  ------------------
 4413|       |
 4414|       |        /* here a1a1 and a0a0 constitute a_i ** 2 */
 4415|   513M|        a0a0 += carry;
 4416|   513M|        if (a0a0 < carry)
  ------------------
  |  Branch (4416:13): [True: 0, False: 513M]
  ------------------
 4417|      0|            ++a1a1;
 4418|       |
 4419|       |        /* now add to ps */
 4420|   513M|        a0a0 += a_i = *ps;
 4421|   513M|        if (a0a0 < a_i)
  ------------------
  |  Branch (4421:13): [True: 252M, False: 261M]
  ------------------
 4422|   252M|            ++a1a1;
 4423|   513M|        *ps++ = a0a0;
 4424|   513M|        a1a1 += a_i = *ps;
 4425|   513M|        carry = (a1a1 < a_i);
 4426|   513M|        *ps++ = a1a1;
 4427|   513M|    }
 4428|  6.37M|    while (carry) {
  ------------------
  |  Branch (4428:12): [True: 0, False: 6.37M]
  ------------------
 4429|      0|        mp_digit s_i = *ps;
 4430|      0|        carry += s_i;
 4431|      0|        *ps++ = carry;
 4432|      0|        carry = carry < s_i;
 4433|      0|    }
 4434|  6.37M|#endif
 4435|  6.37M|}
s_mpv_div_2dx1d:
 4446|  5.48M|{
 4447|  5.48M|    mp_digit d1, d0, q1, q0;
 4448|  5.48M|    mp_digit r1, r0, m;
 4449|       |
 4450|  5.48M|    d1 = divisor >> MP_HALF_DIGIT_BIT;
  ------------------
  |  |  141|  5.48M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  ------------------
  |  |  |  |  137|  5.48M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  5.48M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4451|  5.48M|    d0 = divisor & MP_HALF_DIGIT_MAX;
  ------------------
  |  |   81|  5.48M|#define MP_HALF_DIGIT_MAX UINT_MAX
  ------------------
 4452|  5.48M|    r1 = Nhi % d1;
 4453|  5.48M|    q1 = Nhi / d1;
 4454|  5.48M|    m = q1 * d0;
 4455|  5.48M|    r1 = (r1 << MP_HALF_DIGIT_BIT) | (Nlo >> MP_HALF_DIGIT_BIT);
  ------------------
  |  |  141|  5.48M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  ------------------
  |  |  |  |  137|  5.48M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  5.48M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  r1 = (r1 << MP_HALF_DIGIT_BIT) | (Nlo >> MP_HALF_DIGIT_BIT);
  ------------------
  |  |  141|  5.48M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  ------------------
  |  |  |  |  137|  5.48M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  5.48M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4456|  5.48M|    if (r1 < m) {
  ------------------
  |  Branch (4456:9): [True: 1.53M, False: 3.94M]
  ------------------
 4457|  1.53M|        q1--, r1 += divisor;
 4458|  1.53M|        if (r1 >= divisor && r1 < m) {
  ------------------
  |  Branch (4458:13): [True: 577k, False: 960k]
  |  Branch (4458:30): [True: 241, False: 577k]
  ------------------
 4459|    241|            q1--, r1 += divisor;
 4460|    241|        }
 4461|  1.53M|    }
 4462|  5.48M|    r1 -= m;
 4463|  5.48M|    r0 = r1 % d1;
 4464|  5.48M|    q0 = r1 / d1;
 4465|  5.48M|    m = q0 * d0;
 4466|  5.48M|    r0 = (r0 << MP_HALF_DIGIT_BIT) | (Nlo & MP_HALF_DIGIT_MAX);
  ------------------
  |  |  141|  5.48M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  ------------------
  |  |  |  |  137|  5.48M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  5.48M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  r0 = (r0 << MP_HALF_DIGIT_BIT) | (Nlo & MP_HALF_DIGIT_MAX);
  ------------------
  |  |   81|  5.48M|#define MP_HALF_DIGIT_MAX UINT_MAX
  ------------------
 4467|  5.48M|    if (r0 < m) {
  ------------------
  |  Branch (4467:9): [True: 1.52M, False: 3.96M]
  ------------------
 4468|  1.52M|        q0--, r0 += divisor;
 4469|  1.52M|        if (r0 >= divisor && r0 < m) {
  ------------------
  |  Branch (4469:13): [True: 543k, False: 979k]
  |  Branch (4469:30): [True: 256, False: 543k]
  ------------------
 4470|    256|            q0--, r0 += divisor;
 4471|    256|        }
 4472|  1.52M|    }
 4473|  5.48M|    if (qp)
  ------------------
  |  Branch (4473:9): [True: 5.48M, False: 0]
  ------------------
 4474|  5.48M|        *qp = (q1 << MP_HALF_DIGIT_BIT) | q0;
  ------------------
  |  |  141|  5.48M|#define MP_HALF_DIGIT_BIT (MP_DIGIT_BIT / 2)
  |  |  ------------------
  |  |  |  |  137|  5.48M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  5.48M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4475|  5.48M|    if (rp)
  ------------------
  |  Branch (4475:9): [True: 5.48M, False: 0]
  ------------------
 4476|  5.48M|        *rp = r0 - m;
 4477|  5.48M|    return MP_OKAY;
  ------------------
  |  |   39|  5.48M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 4478|  5.48M|}
s_mp_sqr:
 4486|  41.4k|{
 4487|  41.4k|    mp_err res;
 4488|  41.4k|    mp_int tmp;
 4489|       |
 4490|  41.4k|    if ((res = mp_init_size(&tmp, 2 * USED(a))) != MP_OKAY)
  ------------------
  |  |  333|  41.4k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  41.4k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  if ((res = mp_init_size(&tmp, 2 * USED(a))) != MP_OKAY)
  ------------------
  |  |   39|  41.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4490:9): [True: 0, False: 41.4k]
  ------------------
 4491|      0|        return res;
 4492|  41.4k|    res = mp_sqr(a, &tmp);
 4493|  41.4k|    if (res == MP_OKAY) {
  ------------------
  |  |   39|  41.4k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4493:9): [True: 41.4k, False: 0]
  ------------------
 4494|  41.4k|        s_mp_exch(&tmp, a);
 4495|  41.4k|    }
 4496|  41.4k|    mp_clear(&tmp);
 4497|  41.4k|    return res;
 4498|  41.4k|}
s_mp_div:
 4515|   500k|{
 4516|   500k|    mp_int part, t;
 4517|   500k|    mp_digit q_msd;
 4518|   500k|    mp_err res;
 4519|   500k|    mp_digit d;
 4520|   500k|    mp_digit div_msd;
 4521|   500k|    int ix;
 4522|       |
 4523|   500k|    if (mp_cmp_z(div) == 0)
  ------------------
  |  Branch (4523:9): [True: 0, False: 500k]
  ------------------
 4524|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 4525|       |
 4526|   500k|    DIGITS(&t) = 0;
  ------------------
  |  |  335|   500k|#define DIGITS(MP) MP_DIGITS(MP)
  |  |  ------------------
  |  |  |  |  152|   500k|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
 4527|       |    /* Shortcut if divisor is power of two */
 4528|   500k|    if ((ix = s_mp_ispow2(div)) >= 0) {
  ------------------
  |  Branch (4528:9): [True: 95, False: 500k]
  ------------------
 4529|     95|        MP_CHECKOK(mp_copy(rem, quot));
  ------------------
  |  |  319|     95|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|     95|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 95]
  |  |  ------------------
  |  |  320|     95|    goto CLEANUP
  ------------------
 4530|     95|        s_mp_div_2d(quot, (mp_digit)ix);
 4531|     95|        s_mp_mod_2d(rem, (mp_digit)ix);
 4532|       |
 4533|     95|        return MP_OKAY;
  ------------------
  |  |   39|     95|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 4534|     95|    }
 4535|       |
 4536|   500k|    MP_SIGN(rem) = ZPOS;
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(rem) = ZPOS;
  ------------------
  |  |  326|   500k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   500k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 4537|   500k|    MP_SIGN(div) = ZPOS;
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(div) = ZPOS;
  ------------------
  |  |  326|   500k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   500k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 4538|   500k|    MP_SIGN(&part) = ZPOS;
  ------------------
  |  |  149|   500k|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(&part) = ZPOS;
  ------------------
  |  |  326|   500k|#define ZPOS MP_ZPOS
  |  |  ------------------
  |  |  |  |   37|   500k|#define MP_ZPOS 0
  |  |  ------------------
  ------------------
 4539|       |
 4540|       |    /* A working temporary for division     */
 4541|   500k|    MP_CHECKOK(mp_init_size(&t, MP_ALLOC(rem)));
  ------------------
  |  |  319|   500k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   500k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 500k]
  |  |  ------------------
  |  |  320|   500k|    goto CLEANUP
  ------------------
 4542|       |
 4543|       |    /* Normalize to optimize guessing       */
 4544|   500k|    MP_CHECKOK(s_mp_norm(rem, div, &d));
  ------------------
  |  |  319|   500k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   500k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 500k]
  |  |  ------------------
  |  |  320|   500k|    goto CLEANUP
  ------------------
 4545|       |
 4546|       |    /* Perform the division itself...woo!   */
 4547|   500k|    MP_USED(quot) = MP_ALLOC(quot);
  ------------------
  |  |  150|   500k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  MP_USED(quot) = MP_ALLOC(quot);
  ------------------
  |  |  151|   500k|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
 4548|       |
 4549|       |    /* Find a partial substring of rem which is at least div */
 4550|       |    /* If we didn't find one, we're finished dividing    */
 4551|  5.98M|    while (MP_USED(rem) > MP_USED(div) || s_mp_cmp(rem, div) >= 0) {
  ------------------
  |  |  150|  5.98M|#define MP_USED(MP) ((MP)->used)
  ------------------
                  while (MP_USED(rem) > MP_USED(div) || s_mp_cmp(rem, div) >= 0) {
  ------------------
  |  |  150|  11.9M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (4551:12): [True: 5.48M, False: 500k]
  |  Branch (4551:43): [True: 1, False: 500k]
  ------------------
 4552|  5.48M|        int i;
 4553|  5.48M|        int unusedRem;
 4554|  5.48M|        int partExtended = 0; /* set to true if we need to extend part */
 4555|       |
 4556|  5.48M|        unusedRem = MP_USED(rem) - MP_USED(div);
  ------------------
  |  |  150|  5.48M|#define MP_USED(MP) ((MP)->used)
  ------------------
                      unusedRem = MP_USED(rem) - MP_USED(div);
  ------------------
  |  |  150|  5.48M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4557|  5.48M|        MP_DIGITS(&part) = MP_DIGITS(rem) + unusedRem;
  ------------------
  |  |  152|  5.48M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
                      MP_DIGITS(&part) = MP_DIGITS(rem) + unusedRem;
  ------------------
  |  |  152|  5.48M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4558|  5.48M|        MP_ALLOC(&part) = MP_ALLOC(rem) - unusedRem;
  ------------------
  |  |  151|  5.48M|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
                      MP_ALLOC(&part) = MP_ALLOC(rem) - unusedRem;
  ------------------
  |  |  151|  5.48M|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
 4559|  5.48M|        MP_USED(&part) = MP_USED(div);
  ------------------
  |  |  150|  5.48M|#define MP_USED(MP) ((MP)->used)
  ------------------
                      MP_USED(&part) = MP_USED(div);
  ------------------
  |  |  150|  5.48M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4560|       |
 4561|       |        /* We have now truncated the part of the remainder to the same length as
 4562|       |         * the divisor. If part is smaller than div, extend part by one digit. */
 4563|  5.48M|        if (s_mp_cmp(&part, div) < 0) {
  ------------------
  |  Branch (4563:13): [True: 5.48M, False: 175]
  ------------------
 4564|  5.48M|            --unusedRem;
 4565|  5.48M|#if MP_ARGCHK == 2
 4566|  5.48M|            assert(unusedRem >= 0);
 4567|  5.48M|#endif
 4568|  5.48M|            --MP_DIGITS(&part);
  ------------------
  |  |  152|  5.48M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4569|  5.48M|            ++MP_USED(&part);
  ------------------
  |  |  150|  5.48M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4570|  5.48M|            ++MP_ALLOC(&part);
  ------------------
  |  |  151|  5.48M|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
 4571|  5.48M|            partExtended = 1;
 4572|  5.48M|        }
 4573|       |
 4574|       |        /* Compute a guess for the next quotient digit       */
 4575|  5.48M|        q_msd = MP_DIGIT(&part, MP_USED(&part) - 1);
  ------------------
  |  |  153|  5.48M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 4576|  5.48M|        div_msd = MP_DIGIT(div, MP_USED(div) - 1);
  ------------------
  |  |  153|  5.48M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 4577|  5.48M|        if (!partExtended) {
  ------------------
  |  Branch (4577:13): [True: 175, False: 5.48M]
  ------------------
 4578|       |            /* In this case, q_msd /= div_msd is always 1. First, since div_msd is
 4579|       |             * normalized to have the high bit set, 2*div_msd > MP_DIGIT_MAX. Since
 4580|       |             * we didn't extend part, q_msd >= div_msd. Therefore we know that
 4581|       |             * div_msd <= q_msd <= MP_DIGIT_MAX < 2*div_msd. Dividing by div_msd we
 4582|       |             * get 1 <= q_msd/div_msd < 2. So q_msd /= div_msd must be 1. */
 4583|    175|            q_msd = 1;
 4584|  5.48M|        } else {
 4585|  5.48M|            if (q_msd == div_msd) {
  ------------------
  |  Branch (4585:17): [True: 1.64k, False: 5.48M]
  ------------------
 4586|  1.64k|                q_msd = MP_DIGIT_MAX;
  ------------------
  |  |   79|  1.64k|#define MP_DIGIT_MAX ULONG_MAX
  ------------------
 4587|  5.48M|            } else {
 4588|  5.48M|                mp_digit r;
 4589|  5.48M|                MP_CHECKOK(s_mpv_div_2dx1d(q_msd, MP_DIGIT(&part, MP_USED(&part) - 2),
  ------------------
  |  |  319|  5.48M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  5.48M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 5.48M]
  |  |  ------------------
  |  |  320|  5.48M|    goto CLEANUP
  ------------------
 4590|  5.48M|                                           div_msd, &q_msd, &r));
 4591|  5.48M|            }
 4592|  5.48M|        }
 4593|  5.48M|#if MP_ARGCHK == 2
 4594|  5.48M|        assert(q_msd > 0); /* This case should never occur any more. */
 4595|  5.48M|#endif
 4596|  5.48M|        if (q_msd <= 0)
  ------------------
  |  Branch (4596:13): [True: 0, False: 5.48M]
  ------------------
 4597|      0|            break;
 4598|       |
 4599|       |        /* See what that multiplies out to                   */
 4600|  5.48M|        mp_copy(div, &t);
 4601|  5.48M|        MP_CHECKOK(s_mp_mul_d(&t, q_msd));
  ------------------
  |  |  319|  5.48M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  5.48M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 5.48M]
  |  |  ------------------
  |  |  320|  5.48M|    goto CLEANUP
  ------------------
 4602|       |
 4603|       |        /*
 4604|       |           If it's too big, back it off.  We should not have to do this
 4605|       |           more than once, or, in rare cases, twice.  Knuth describes a
 4606|       |           method by which this could be reduced to a maximum of once, but
 4607|       |           I didn't implement that here.
 4608|       |           When using s_mpv_div_2dx1d, we may have to do this 3 times.
 4609|       |         */
 4610|  6.56M|        for (i = 4; s_mp_cmp(&t, &part) > 0 && i > 0; --i) {
  ------------------
  |  Branch (4610:21): [True: 1.07M, False: 5.48M]
  |  Branch (4610:48): [True: 1.07M, False: 0]
  ------------------
 4611|  1.07M|            --q_msd;
 4612|  1.07M|            MP_CHECKOK(s_mp_sub(&t, div)); /* t -= div */
  ------------------
  |  |  319|  1.07M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  1.07M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1.07M]
  |  |  ------------------
  |  |  320|  1.07M|    goto CLEANUP
  ------------------
 4613|  1.07M|        }
 4614|  5.48M|        if (i < 0) {
  ------------------
  |  Branch (4614:13): [True: 0, False: 5.48M]
  ------------------
 4615|      0|            res = MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 4616|      0|            goto CLEANUP;
 4617|      0|        }
 4618|       |
 4619|       |        /* At this point, q_msd should be the right next digit   */
 4620|  5.48M|        MP_CHECKOK(s_mp_sub(&part, &t)); /* part -= t */
  ------------------
  |  |  319|  5.48M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  5.48M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 5.48M]
  |  |  ------------------
  |  |  320|  5.48M|    goto CLEANUP
  ------------------
 4621|  5.48M|        s_mp_clamp(rem);
 4622|       |
 4623|       |        /*
 4624|       |          Include the digit in the quotient.  We allocated enough memory
 4625|       |          for any quotient we could ever possibly get, so we should not
 4626|       |          have to check for failures here
 4627|       |         */
 4628|  5.48M|        MP_DIGIT(quot, unusedRem) = q_msd;
  ------------------
  |  |  153|  5.48M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 4629|  5.48M|    }
 4630|       |
 4631|       |    /* Denormalize remainder                */
 4632|   500k|    if (d) {
  ------------------
  |  Branch (4632:9): [True: 31, False: 500k]
  ------------------
 4633|     31|        s_mp_div_2d(rem, d);
 4634|     31|    }
 4635|       |
 4636|   500k|    s_mp_clamp(quot);
 4637|       |
 4638|   500k|CLEANUP:
 4639|   500k|    mp_clear(&t);
 4640|       |
 4641|   500k|    return res;
 4642|       |
 4643|   500k|} /* end s_mp_div() */
s_mp_reduce:
 4687|  57.7k|{
 4688|  57.7k|    mp_int q;
 4689|  57.7k|    mp_err res;
 4690|       |
 4691|  57.7k|    if ((res = mp_init_copy(&q, x)) != MP_OKAY)
  ------------------
  |  |   39|  57.7k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4691:9): [True: 0, False: 57.7k]
  ------------------
 4692|      0|        return res;
 4693|       |
 4694|  57.7k|    s_mp_rshd(&q, USED(m) - 1); /* q1 = x / b^(k-1)  */
  ------------------
  |  |  333|  57.7k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  57.7k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 4695|  57.7k|    s_mp_mul(&q, mu);           /* q2 = q1 * mu      */
 4696|  57.7k|    s_mp_rshd(&q, USED(m) + 1); /* q3 = q2 / b^(k+1) */
  ------------------
  |  |  333|  57.7k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  57.7k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 4697|       |
 4698|       |    /* x = x mod b^(k+1), quick (no division) */
 4699|  57.7k|    s_mp_mod_2d(x, DIGIT_BIT * (USED(m) + 1));
  ------------------
  |  |  328|  57.7k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  57.7k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  57.7k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  s_mp_mod_2d(x, DIGIT_BIT * (USED(m) + 1));
  ------------------
  |  |  333|  57.7k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  57.7k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 4700|       |
 4701|       |    /* q = q * m mod b^(k+1), quick (no division) */
 4702|  57.7k|    s_mp_mul(&q, m);
 4703|  57.7k|    s_mp_mod_2d(&q, DIGIT_BIT * (USED(m) + 1));
  ------------------
  |  |  328|  57.7k|#define DIGIT_BIT MP_DIGIT_BIT
  |  |  ------------------
  |  |  |  |  137|  57.7k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  57.7k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  s_mp_mod_2d(&q, DIGIT_BIT * (USED(m) + 1));
  ------------------
  |  |  333|  57.7k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  57.7k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 4704|       |
 4705|       |    /* x = x - q */
 4706|  57.7k|    if ((res = mp_sub(x, &q, x)) != MP_OKAY)
  ------------------
  |  |   39|  57.7k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4706:9): [True: 0, False: 57.7k]
  ------------------
 4707|      0|        goto CLEANUP;
 4708|       |
 4709|       |    /* If x < 0, add b^(k+1) to it */
 4710|  57.7k|    if (mp_cmp_z(x) < 0) {
  ------------------
  |  Branch (4710:9): [True: 683, False: 57.0k]
  ------------------
 4711|    683|        mp_set(&q, 1);
 4712|    683|        if ((res = s_mp_lshd(&q, USED(m) + 1)) != MP_OKAY)
  ------------------
  |  |  333|    683|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|    683|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                      if ((res = s_mp_lshd(&q, USED(m) + 1)) != MP_OKAY)
  ------------------
  |  |   39|    683|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4712:13): [True: 0, False: 683]
  ------------------
 4713|      0|            goto CLEANUP;
 4714|    683|        if ((res = mp_add(x, &q, x)) != MP_OKAY)
  ------------------
  |  |   39|    683|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4714:13): [True: 0, False: 683]
  ------------------
 4715|      0|            goto CLEANUP;
 4716|    683|    }
 4717|       |
 4718|       |    /* Back off if it's too big */
 4719|  63.0k|    while (mp_cmp(x, m) >= 0) {
  ------------------
  |  Branch (4719:12): [True: 5.28k, False: 57.7k]
  ------------------
 4720|  5.28k|        if ((res = s_mp_sub(x, m)) != MP_OKAY)
  ------------------
  |  |   39|  5.28k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (4720:13): [True: 0, False: 5.28k]
  ------------------
 4721|      0|            break;
 4722|  5.28k|    }
 4723|       |
 4724|  57.7k|CLEANUP:
 4725|  57.7k|    mp_clear(&q);
 4726|       |
 4727|  57.7k|    return res;
 4728|       |
 4729|  57.7k|} /* end s_mp_reduce() */
s_mp_cmp:
 4742|   173M|{
 4743|   173M|    ARGMPCHK(a != NULL && b != NULL);
  ------------------
  |  |  354|   173M|#define ARGMPCHK(X) assert(X)
  ------------------
 4744|       |
 4745|   173M|    mp_size used_a = MP_USED(a);
  ------------------
  |  |  150|   173M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4746|   173M|    {
 4747|   173M|        mp_size used_b = MP_USED(b);
  ------------------
  |  |  150|   173M|#define MP_USED(MP) ((MP)->used)
  ------------------
 4748|       |
 4749|   173M|        if (used_a > used_b)
  ------------------
  |  Branch (4749:13): [True: 23.9M, False: 149M]
  ------------------
 4750|  23.9M|            goto IS_GT;
 4751|   149M|        if (used_a < used_b)
  ------------------
  |  Branch (4751:13): [True: 683k, False: 148M]
  ------------------
 4752|   683k|            goto IS_LT;
 4753|   149M|    }
 4754|   148M|    {
 4755|   148M|        mp_digit *pa, *pb;
 4756|   148M|        mp_digit da = 0, db = 0;
 4757|       |
 4758|   148M|#define CMP_AB(n)                     \
 4759|   148M|    if ((da = pa[n]) != (db = pb[n])) \
 4760|   148M|    goto done
 4761|       |
 4762|   148M|        pa = MP_DIGITS(a) + used_a;
  ------------------
  |  |  152|   148M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4763|   148M|        pb = MP_DIGITS(b) + used_a;
  ------------------
  |  |  152|   148M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 4764|   149M|        while (used_a >= 4) {
  ------------------
  |  Branch (4764:16): [True: 149M, False: 46.1k]
  ------------------
 4765|   149M|            pa -= 4;
 4766|   149M|            pb -= 4;
 4767|   149M|            used_a -= 4;
 4768|   149M|            CMP_AB(3);
  ------------------
  |  | 4759|   149M|    if ((da = pa[n]) != (db = pb[n])) \
  |  |  ------------------
  |  |  |  Branch (4759:9): [True: 144M, False: 4.21M]
  |  |  ------------------
  |  | 4760|   149M|    goto done
  ------------------
 4769|  4.21M|            CMP_AB(2);
  ------------------
  |  | 4759|  4.21M|    if ((da = pa[n]) != (db = pb[n])) \
  |  |  ------------------
  |  |  |  Branch (4759:9): [True: 3.92M, False: 292k]
  |  |  ------------------
  |  | 4760|  4.21M|    goto done
  ------------------
 4770|   292k|            CMP_AB(1);
  ------------------
  |  | 4759|   292k|    if ((da = pa[n]) != (db = pb[n])) \
  |  |  ------------------
  |  |  |  Branch (4759:9): [True: 2.27k, False: 290k]
  |  |  ------------------
  |  | 4760|   292k|    goto done
  ------------------
 4771|   290k|            CMP_AB(0);
  ------------------
  |  | 4759|   290k|    if ((da = pa[n]) != (db = pb[n])) \
  |  |  ------------------
  |  |  |  Branch (4759:9): [True: 1.75k, False: 288k]
  |  |  ------------------
  |  | 4760|   290k|    goto done
  ------------------
 4772|   290k|        }
 4773|  46.5k|        while (used_a-- > 0 && ((da = *--pa) == (db = *--pb)))
  ------------------
  |  Branch (4773:16): [True: 10.5k, False: 36.0k]
  |  Branch (4773:32): [True: 474, False: 10.0k]
  ------------------
 4774|    474|            /* do nothing */;
 4775|   148M|    done:
 4776|   148M|        if (da > db)
  ------------------
  |  Branch (4776:13): [True: 12.4M, False: 136M]
  ------------------
 4777|  12.4M|            goto IS_GT;
 4778|   136M|        if (da < db)
  ------------------
  |  Branch (4778:13): [True: 136M, False: 36.0k]
  ------------------
 4779|   136M|            goto IS_LT;
 4780|   136M|    }
 4781|  36.0k|    return MP_EQ;
  ------------------
  |  |   50|  36.0k|#define MP_EQ 0
  ------------------
 4782|   136M|IS_LT:
 4783|   136M|    return MP_LT;
  ------------------
  |  |   49|   136M|#define MP_LT -1
  ------------------
 4784|  36.4M|IS_GT:
 4785|  36.4M|    return MP_GT;
  ------------------
  |  |   51|  36.4M|#define MP_GT 1
  ------------------
 4786|   136M|} /* end s_mp_cmp() */
s_mp_cmp_d:
 4795|  1.61M|{
 4796|  1.61M|    ARGMPCHK(a != NULL);
  ------------------
  |  |  354|  1.61M|#define ARGMPCHK(X) assert(X)
  ------------------
 4797|       |
 4798|  1.61M|    if (USED(a) > 1)
  ------------------
  |  |  333|  1.61M|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  1.61M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (4798:9): [True: 1.30M, False: 310k]
  ------------------
 4799|  1.30M|        return MP_GT;
  ------------------
  |  |   51|  1.30M|#define MP_GT 1
  ------------------
 4800|       |
 4801|   310k|    if (DIGIT(a, 0) < d)
  ------------------
  |  |  336|   310k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   310k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  |  Branch (4801:9): [True: 0, False: 310k]
  ------------------
 4802|      0|        return MP_LT;
  ------------------
  |  |   49|      0|#define MP_LT -1
  ------------------
 4803|   310k|    else if (DIGIT(a, 0) > d)
  ------------------
  |  |  336|   310k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   310k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  |  Branch (4803:14): [True: 309k, False: 948]
  ------------------
 4804|   309k|        return MP_GT;
  ------------------
  |  |   51|   309k|#define MP_GT 1
  ------------------
 4805|    948|    else
 4806|    948|        return MP_EQ;
  ------------------
  |  |   50|    948|#define MP_EQ 0
  ------------------
 4807|       |
 4808|   310k|} /* end s_mp_cmp_d() */
s_mp_ispow2:
 4820|   500k|{
 4821|   500k|    mp_digit d;
 4822|   500k|    int extra = 0, ix;
 4823|       |
 4824|   500k|    ARGMPCHK(v != NULL);
  ------------------
  |  |  354|   500k|#define ARGMPCHK(X) assert(X)
  ------------------
 4825|       |
 4826|   500k|    ix = MP_USED(v) - 1;
  ------------------
  |  |  150|   500k|#define MP_USED(MP) ((MP)->used)
  ------------------
 4827|   500k|    d = MP_DIGIT(v, ix); /* most significant digit of v */
  ------------------
  |  |  153|   500k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 4828|       |
 4829|   500k|    extra = s_mp_ispow2d(d);
 4830|   500k|    if (extra < 0 || ix == 0)
  ------------------
  |  Branch (4830:9): [True: 499k, False: 910]
  |  Branch (4830:22): [True: 0, False: 910]
  ------------------
 4831|   499k|        return extra;
 4832|       |
 4833|  9.43k|    while (--ix >= 0) {
  ------------------
  |  Branch (4833:12): [True: 9.34k, False: 95]
  ------------------
 4834|  9.34k|        if (DIGIT(v, ix) != 0)
  ------------------
  |  |  336|  9.34k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  9.34k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
  |  Branch (4834:13): [True: 815, False: 8.52k]
  ------------------
 4835|    815|            return -1; /* not a power of two */
 4836|  8.52k|        extra += MP_DIGIT_BIT;
  ------------------
  |  |  137|  8.52k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  8.52k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
 4837|  8.52k|    }
 4838|       |
 4839|     95|    return extra;
 4840|       |
 4841|    910|} /* end s_mp_ispow2() */
s_mp_ispow2d:
 4849|  5.82M|{
 4850|  5.82M|    if ((d != 0) && ((d & (d - 1)) == 0)) { /* d is a power of 2 */
  ------------------
  |  Branch (4850:9): [True: 5.82M, False: 0]
  |  Branch (4850:21): [True: 60.3k, False: 5.76M]
  ------------------
 4851|  60.3k|        int pow = 0;
 4852|       |#if defined(MP_USE_UINT_DIGIT)
 4853|       |        if (d & 0xffff0000U)
 4854|       |            pow += 16;
 4855|       |        if (d & 0xff00ff00U)
 4856|       |            pow += 8;
 4857|       |        if (d & 0xf0f0f0f0U)
 4858|       |            pow += 4;
 4859|       |        if (d & 0xccccccccU)
 4860|       |            pow += 2;
 4861|       |        if (d & 0xaaaaaaaaU)
 4862|       |            pow += 1;
 4863|       |#elif defined(MP_USE_LONG_LONG_DIGIT)
 4864|       |        if (d & 0xffffffff00000000ULL)
 4865|       |            pow += 32;
 4866|       |        if (d & 0xffff0000ffff0000ULL)
 4867|       |            pow += 16;
 4868|       |        if (d & 0xff00ff00ff00ff00ULL)
 4869|       |            pow += 8;
 4870|       |        if (d & 0xf0f0f0f0f0f0f0f0ULL)
 4871|       |            pow += 4;
 4872|       |        if (d & 0xccccccccccccccccULL)
 4873|       |            pow += 2;
 4874|       |        if (d & 0xaaaaaaaaaaaaaaaaULL)
 4875|       |            pow += 1;
 4876|       |#elif defined(MP_USE_LONG_DIGIT)
 4877|  60.3k|        if (d & 0xffffffff00000000UL)
  ------------------
  |  Branch (4877:13): [True: 1.29k, False: 59.0k]
  ------------------
 4878|  1.29k|            pow += 32;
 4879|  60.3k|        if (d & 0xffff0000ffff0000UL)
  ------------------
  |  Branch (4879:13): [True: 1.26k, False: 59.1k]
  ------------------
 4880|  1.26k|            pow += 16;
 4881|  60.3k|        if (d & 0xff00ff00ff00ff00UL)
  ------------------
  |  Branch (4881:13): [True: 1.21k, False: 59.1k]
  ------------------
 4882|  1.21k|            pow += 8;
 4883|  60.3k|        if (d & 0xf0f0f0f0f0f0f0f0UL)
  ------------------
  |  Branch (4883:13): [True: 1.12k, False: 59.2k]
  ------------------
 4884|  1.12k|            pow += 4;
 4885|  60.3k|        if (d & 0xccccccccccccccccUL)
  ------------------
  |  Branch (4885:13): [True: 1.08k, False: 59.2k]
  ------------------
 4886|  1.08k|            pow += 2;
 4887|  60.3k|        if (d & 0xaaaaaaaaaaaaaaaaUL)
  ------------------
  |  Branch (4887:13): [True: 59.9k, False: 462]
  ------------------
 4888|  59.9k|            pow += 1;
 4889|       |#else
 4890|       |#error "unknown type for mp_digit"
 4891|       |#endif
 4892|  60.3k|        return pow;
 4893|  60.3k|    }
 4894|  5.76M|    return -1;
 4895|       |
 4896|  5.82M|} /* end s_mp_ispow2d() */
mp_read_unsigned_octets:
 5002|   591k|{
 5003|   591k|    int count;
 5004|   591k|    mp_err res;
 5005|   591k|    mp_digit d;
 5006|       |
 5007|   591k|    ARGCHK(mp != NULL && str != NULL && len > 0, MP_BADARG);
  ------------------
  |  |  355|   591k|#define ARGCHK(X, Y) assert(X)
  ------------------
 5008|       |
 5009|   591k|    mp_zero(mp);
 5010|       |
 5011|   591k|    count = len % sizeof(mp_digit);
 5012|   591k|    if (count) {
  ------------------
  |  Branch (5012:9): [True: 187k, False: 403k]
  ------------------
 5013|   648k|        for (d = 0; count-- > 0; --len) {
  ------------------
  |  Branch (5013:21): [True: 461k, False: 187k]
  ------------------
 5014|   461k|            d = (d << 8) | *str++;
 5015|   461k|        }
 5016|   187k|        MP_DIGIT(mp, 0) = d;
  ------------------
  |  |  153|   187k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 5017|   187k|    }
 5018|       |
 5019|       |    /* Read the rest of the digits */
 5020|  11.1M|    for (; len > 0; len -= sizeof(mp_digit)) {
  ------------------
  |  Branch (5020:12): [True: 10.5M, False: 591k]
  ------------------
 5021|  94.6M|        for (d = 0, count = sizeof(mp_digit); count > 0; --count) {
  ------------------
  |  Branch (5021:47): [True: 84.1M, False: 10.5M]
  ------------------
 5022|  84.1M|            d = (d << 8) | *str++;
 5023|  84.1M|        }
 5024|  10.5M|        if (MP_EQ == mp_cmp_z(mp)) {
  ------------------
  |  |   50|  10.5M|#define MP_EQ 0
  ------------------
  |  Branch (5024:13): [True: 413k, False: 10.1M]
  ------------------
 5025|   413k|            if (!d)
  ------------------
  |  Branch (5025:17): [True: 9.09k, False: 404k]
  ------------------
 5026|  9.09k|                continue;
 5027|  10.1M|        } else {
 5028|  10.1M|            if ((res = s_mp_lshd(mp, 1)) != MP_OKAY)
  ------------------
  |  |   39|  10.1M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (5028:17): [True: 0, False: 10.1M]
  ------------------
 5029|      0|                return res;
 5030|  10.1M|        }
 5031|  10.5M|        MP_DIGIT(mp, 0) = d;
  ------------------
  |  |  153|  10.5M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
 5032|  10.5M|    }
 5033|   591k|    return MP_OKAY;
  ------------------
  |  |   39|   591k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 5034|   591k|} /* end mp_read_unsigned_octets() */
mp_unsigned_octet_size:
 5040|   171k|{
 5041|   171k|    unsigned int bytes;
 5042|   171k|    int ix;
 5043|   171k|    mp_digit d = 0;
 5044|       |
 5045|   171k|    ARGCHK(mp != NULL, MP_BADARG);
  ------------------
  |  |  355|   171k|#define ARGCHK(X, Y) assert(X)
  ------------------
 5046|   171k|    ARGCHK(MP_ZPOS == SIGN(mp), MP_BADARG);
  ------------------
  |  |  355|   171k|#define ARGCHK(X, Y) assert(X)
  ------------------
 5047|       |
 5048|   171k|    bytes = (USED(mp) * sizeof(mp_digit));
  ------------------
  |  |  333|   171k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   171k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 5049|       |
 5050|       |    /* subtract leading zeros. */
 5051|       |    /* Iterate over each digit... */
 5052|   171k|    for (ix = USED(mp) - 1; ix >= 0; ix--) {
  ------------------
  |  |  333|   171k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|   171k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (5052:29): [True: 171k, False: 0]
  ------------------
 5053|   171k|        d = DIGIT(mp, ix);
  ------------------
  |  |  336|   171k|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|   171k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5054|   171k|        if (d)
  ------------------
  |  Branch (5054:13): [True: 171k, False: 0]
  ------------------
 5055|   171k|            break;
 5056|      0|        bytes -= sizeof(d);
 5057|      0|    }
 5058|   171k|    if (!bytes)
  ------------------
  |  Branch (5058:9): [True: 0, False: 171k]
  ------------------
 5059|      0|        return 1;
 5060|       |
 5061|       |    /* Have MSD, check digit bytes, high order first */
 5062|   173k|    for (ix = sizeof(mp_digit) - 1; ix >= 0; ix--) {
  ------------------
  |  Branch (5062:37): [True: 173k, False: 0]
  ------------------
 5063|   173k|        unsigned char x = (unsigned char)(d >> (ix * CHAR_BIT));
 5064|   173k|        if (x)
  ------------------
  |  Branch (5064:13): [True: 171k, False: 1.54k]
  ------------------
 5065|   171k|            break;
 5066|  1.54k|        --bytes;
 5067|  1.54k|    }
 5068|   171k|    return bytes;
 5069|   171k|} /* end mp_unsigned_octet_size() */
mp_to_unsigned_octets:
 5076|  85.8k|{
 5077|  85.8k|    int ix, pos = 0;
 5078|  85.8k|    unsigned int bytes;
 5079|       |
 5080|  85.8k|    ARGCHK(mp != NULL && str != NULL && !SIGN(mp), MP_BADARG);
  ------------------
  |  |  355|  85.8k|#define ARGCHK(X, Y) assert(X)
  ------------------
 5081|       |
 5082|  85.8k|    bytes = mp_unsigned_octet_size(mp);
 5083|  85.8k|    ARGCHK(bytes <= maxlen, MP_BADARG);
  ------------------
  |  |  355|  85.8k|#define ARGCHK(X, Y) assert(X)
  ------------------
 5084|       |
 5085|       |    /* Iterate over each digit... */
 5086|  3.85M|    for (ix = USED(mp) - 1; ix >= 0; ix--) {
  ------------------
  |  |  333|  85.8k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  85.8k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
  |  Branch (5086:29): [True: 3.76M, False: 85.8k]
  ------------------
 5087|  3.76M|        mp_digit d = DIGIT(mp, ix);
  ------------------
  |  |  336|  3.76M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  3.76M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5088|  3.76M|        int jx;
 5089|       |
 5090|       |        /* Unpack digit bytes, high order first */
 5091|  33.8M|        for (jx = sizeof(mp_digit) - 1; jx >= 0; jx--) {
  ------------------
  |  Branch (5091:41): [True: 30.1M, False: 3.76M]
  ------------------
 5092|  30.1M|            unsigned char x = (unsigned char)(d >> (jx * CHAR_BIT));
 5093|  30.1M|            if (!pos && !x) /* suppress leading zeros */
  ------------------
  |  Branch (5093:17): [True: 86.6k, False: 30.0M]
  |  Branch (5093:25): [True: 770, False: 85.8k]
  ------------------
 5094|    770|                continue;
 5095|  30.1M|            str[pos++] = x;
 5096|  30.1M|        }
 5097|  3.76M|    }
 5098|  85.8k|    if (!pos)
  ------------------
  |  Branch (5098:9): [True: 0, False: 85.8k]
  ------------------
 5099|      0|        str[pos++] = 0;
 5100|  85.8k|    return pos;
 5101|  85.8k|} /* end mp_to_unsigned_octets() */
mp_to_fixlen_octets:
 5149|  39.1k|{
 5150|  39.1k|    int ix, jx;
 5151|  39.1k|    unsigned int bytes;
 5152|       |
 5153|  39.1k|    ARGCHK(mp != NULL && str != NULL && !SIGN(mp) && length > 0, MP_BADARG);
  ------------------
  |  |  355|  39.1k|#define ARGCHK(X, Y) assert(X)
  ------------------
 5154|       |
 5155|       |    /* Constant time on the value of mp.  Don't use mp_unsigned_octet_size. */
 5156|  39.1k|    bytes = USED(mp) * MP_DIGIT_SIZE;
  ------------------
  |  |  333|  39.1k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  39.1k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  bytes = USED(mp) * MP_DIGIT_SIZE;
  ------------------
  |  |  136|  39.1k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  ------------------
 5157|       |
 5158|       |    /* If the output is shorter than the native size of mp, then check that any
 5159|       |     * bytes not written have zero values.  This check isn't constant time on
 5160|       |     * the assumption that timing-sensitive callers can guarantee that mp fits
 5161|       |     * in the allocated space. */
 5162|  39.1k|    ix = USED(mp) - 1;
  ------------------
  |  |  333|  39.1k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  39.1k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 5163|  39.1k|    if (bytes > length) {
  ------------------
  |  Branch (5163:9): [True: 9, False: 39.1k]
  ------------------
 5164|      9|        unsigned int zeros = bytes - length;
 5165|       |
 5166|      9|        while (zeros >= MP_DIGIT_SIZE) {
  ------------------
  |  |  136|      9|#define MP_DIGIT_SIZE sizeof(mp_digit)
  ------------------
  |  Branch (5166:16): [True: 0, False: 9]
  ------------------
 5167|      0|            ARGCHK(DIGIT(mp, ix) == 0, MP_BADARG);
  ------------------
  |  |  355|      0|#define ARGCHK(X, Y) assert(X)
  ------------------
 5168|      0|            zeros -= MP_DIGIT_SIZE;
  ------------------
  |  |  136|      0|#define MP_DIGIT_SIZE sizeof(mp_digit)
  ------------------
 5169|      0|            ix--;
 5170|      0|        }
 5171|       |
 5172|      9|        if (zeros > 0) {
  ------------------
  |  Branch (5172:13): [True: 9, False: 0]
  ------------------
 5173|      9|            mp_digit d = DIGIT(mp, ix);
  ------------------
  |  |  336|      9|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|      9|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5174|      9|            mp_digit m = ~0ULL << ((MP_DIGIT_SIZE - zeros) * CHAR_BIT);
  ------------------
  |  |  136|      9|#define MP_DIGIT_SIZE sizeof(mp_digit)
  ------------------
 5175|      9|            ARGCHK((d & m) == 0, MP_BADARG);
  ------------------
  |  |  355|      9|#define ARGCHK(X, Y) assert(X)
  ------------------
 5176|     18|            for (jx = MP_DIGIT_SIZE - zeros - 1; jx >= 0; jx--) {
  ------------------
  |  |  136|      9|#define MP_DIGIT_SIZE sizeof(mp_digit)
  ------------------
  |  Branch (5176:50): [True: 9, False: 9]
  ------------------
 5177|      9|                *str++ = d >> (jx * CHAR_BIT);
 5178|      9|            }
 5179|      9|            ix--;
 5180|      9|        }
 5181|  39.1k|    } else if (bytes < length) {
  ------------------
  |  Branch (5181:16): [True: 60, False: 39.0k]
  ------------------
 5182|       |        /* Place any needed leading zeros. */
 5183|     60|        unsigned int zeros = length - bytes;
 5184|     60|        memset(str, 0, zeros);
 5185|     60|        str += zeros;
 5186|     60|    }
 5187|       |
 5188|       |    /* Iterate over each whole digit... */
 5189|  1.24M|    for (; ix >= 0; ix--) {
  ------------------
  |  Branch (5189:12): [True: 1.20M, False: 39.1k]
  ------------------
 5190|  1.20M|        mp_digit d = DIGIT(mp, ix);
  ------------------
  |  |  336|  1.20M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  1.20M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5191|       |
 5192|       |        /* Unpack digit bytes, high order first */
 5193|  10.8M|        for (jx = MP_DIGIT_SIZE - 1; jx >= 0; jx--) {
  ------------------
  |  |  136|  1.20M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  ------------------
  |  Branch (5193:38): [True: 9.65M, False: 1.20M]
  ------------------
 5194|  9.65M|            *str++ = d >> (jx * CHAR_BIT);
 5195|  9.65M|        }
 5196|  1.20M|    }
 5197|  39.1k|    return MP_OKAY;
  ------------------
  |  |   39|  39.1k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 5198|  39.1k|} /* end mp_to_fixlen_octets() */
mp_cswap:
 5205|  79.9k|{
 5206|  79.9k|    mp_digit x;
 5207|  79.9k|    unsigned int i;
 5208|  79.9k|    mp_err res = 0;
 5209|       |
 5210|       |    /* if pointers are equal return */
 5211|  79.9k|    if (a == b)
  ------------------
  |  Branch (5211:9): [True: 0, False: 79.9k]
  ------------------
 5212|      0|        return res;
 5213|       |
 5214|  79.9k|    if (MP_ALLOC(a) < numdigits || MP_ALLOC(b) < numdigits) {
  ------------------
  |  |  151|  79.9k|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
                  if (MP_ALLOC(a) < numdigits || MP_ALLOC(b) < numdigits) {
  ------------------
  |  |  151|  79.9k|#define MP_ALLOC(MP) ((MP)->alloc)
  ------------------
  |  Branch (5214:9): [True: 0, False: 79.9k]
  |  Branch (5214:36): [True: 0, False: 79.9k]
  ------------------
 5215|      0|        MP_CHECKOK(s_mp_grow(a, numdigits));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 5216|      0|        MP_CHECKOK(s_mp_grow(b, numdigits));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 5217|      0|    }
 5218|       |
 5219|  79.9k|    condition = ((~condition & ((condition - 1))) >> (MP_DIGIT_BIT - 1)) - 1;
  ------------------
  |  |  137|  79.9k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  79.9k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
 5220|       |
 5221|  79.9k|    x = (USED(a) ^ USED(b)) & condition;
  ------------------
  |  |  333|  79.9k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  79.9k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
                  x = (USED(a) ^ USED(b)) & condition;
  ------------------
  |  |  333|  79.9k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  79.9k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 5222|  79.9k|    USED(a) ^= x;
  ------------------
  |  |  333|  79.9k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  79.9k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 5223|  79.9k|    USED(b) ^= x;
  ------------------
  |  |  333|  79.9k|#define USED(MP) MP_USED(MP)
  |  |  ------------------
  |  |  |  |  150|  79.9k|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  ------------------
 5224|       |
 5225|  79.9k|    x = (SIGN(a) ^ SIGN(b)) & condition;
  ------------------
  |  |  332|  79.9k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  79.9k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
                  x = (SIGN(a) ^ SIGN(b)) & condition;
  ------------------
  |  |  332|  79.9k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  79.9k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 5226|  79.9k|    SIGN(a) ^= x;
  ------------------
  |  |  332|  79.9k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  79.9k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 5227|  79.9k|    SIGN(b) ^= x;
  ------------------
  |  |  332|  79.9k|#define SIGN(MP) MP_SIGN(MP)
  |  |  ------------------
  |  |  |  |  149|  79.9k|#define MP_SIGN(MP) ((MP)->sign)
  |  |  ------------------
  ------------------
 5228|       |
 5229|  1.93M|    for (i = 0; i < numdigits; i++) {
  ------------------
  |  Branch (5229:17): [True: 1.85M, False: 79.9k]
  ------------------
 5230|  1.85M|        x = (DIGIT(a, i) ^ DIGIT(b, i)) & condition;
  ------------------
  |  |  336|  1.85M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  1.85M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
                      x = (DIGIT(a, i) ^ DIGIT(b, i)) & condition;
  ------------------
  |  |  336|  1.85M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  1.85M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5231|  1.85M|        DIGIT(a, i) ^= x;
  ------------------
  |  |  336|  1.85M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  1.85M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5232|  1.85M|        DIGIT(b, i) ^= x;
  ------------------
  |  |  336|  1.85M|#define DIGIT(MP, N) MP_DIGIT(MP, N)
  |  |  ------------------
  |  |  |  |  153|  1.85M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  |  |  ------------------
  ------------------
 5233|  1.85M|    }
 5234|       |
 5235|  79.9k|CLEANUP:
 5236|  79.9k|    return res;
 5237|  79.9k|} /* end mp_cswap() */

s_mpv_mul_d_add_prop:
   21|  3.37G|{
   22|  3.37G|    mp_digit w;
   23|  3.37G|    mp_digit d;
   24|       |
   25|  3.37G|    d = s_mpv_mul_add_vec64(c, a, a_len, b);
   26|  3.37G|    c += a_len;
   27|  7.88G|    while (d) {
  ------------------
  |  Branch (27:12): [True: 4.51G, False: 3.37G]
  ------------------
   28|  4.51G|        w = c[0] + d;
   29|  4.51G|        d = (w < c[0] || w < d);
  ------------------
  |  Branch (29:14): [True: 1.14G, False: 3.37G]
  |  Branch (29:26): [True: 0, False: 3.37G]
  ------------------
   30|  4.51G|        *c++ = w;
   31|  4.51G|    }
   32|  3.37G|}

mpl_get_bits:
  392|  19.5M|{
  393|  19.5M|    mp_size rshift = (lsbNum % MP_DIGIT_BIT);
  ------------------
  |  |  137|  19.5M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  19.5M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
  394|  19.5M|    mp_size lsWndx = (lsbNum / MP_DIGIT_BIT);
  ------------------
  |  |  137|  19.5M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  19.5M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
  395|  19.5M|    mp_digit *digit = MP_DIGITS(a) + lsWndx;
  ------------------
  |  |  152|  19.5M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  396|  19.5M|    mp_digit mask = ((1 << numBits) - 1);
  397|       |
  398|  19.5M|    ARGCHK(numBits < CHAR_BIT * sizeof mask, MP_BADARG);
  ------------------
  |  |  355|  19.5M|#define ARGCHK(X, Y) assert(X)
  ------------------
  399|  19.5M|    ARGCHK(MP_HOWMANY(lsbNum, MP_DIGIT_BIT) <= MP_USED(a), MP_RANGE);
  ------------------
  |  |  355|  19.5M|#define ARGCHK(X, Y) assert(X)
  ------------------
  400|       |
  401|  19.5M|    if ((numBits + lsbNum % MP_DIGIT_BIT <= MP_DIGIT_BIT) ||
  ------------------
  |  |  137|  19.5M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  19.5M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
                  if ((numBits + lsbNum % MP_DIGIT_BIT <= MP_DIGIT_BIT) ||
  ------------------
  |  |  137|  19.5M|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|  19.5M|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
  |  Branch (401:9): [True: 18.6M, False: 889k]
  ------------------
  402|  19.5M|        (lsWndx + 1 >= MP_USED(a))) {
  ------------------
  |  |  150|   889k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (402:9): [True: 3.87k, False: 885k]
  ------------------
  403|  18.6M|        mask &= (digit[0] >> rshift);
  404|  18.6M|    } else {
  405|   885k|        mask &= ((digit[0] >> rshift) | (digit[1] << (MP_DIGIT_BIT - rshift)));
  ------------------
  |  |  137|   885k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|   885k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
  406|   885k|    }
  407|  19.5M|    return (mp_err)mask;
  408|  19.5M|}
mpl_significant_bits:
  427|   194k|{
  428|       |    /*
  429|       |      start bits at 1.
  430|       |      lg(0) = 0 => bits = 1 by function semantics.
  431|       |      below does a binary search for the _position_ of the top bit set,
  432|       |      which is floor(lg(abs(a))) for a != 0.
  433|       |     */
  434|   194k|    mp_size bits = 1;
  435|   194k|    int ix;
  436|       |
  437|   194k|    ARGCHK(a != NULL, MP_BADARG);
  ------------------
  |  |  355|   194k|#define ARGCHK(X, Y) assert(X)
  ------------------
  438|       |
  439|   194k|    for (ix = MP_USED(a); ix > 0;) {
  ------------------
  |  |  150|   194k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (439:27): [True: 194k, False: 0]
  ------------------
  440|   194k|        mp_digit d, x, mask;
  441|   194k|        if ((d = MP_DIGIT(a, --ix)) == 0)
  ------------------
  |  |  153|   194k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  |  Branch (441:13): [True: 0, False: 194k]
  ------------------
  442|      0|            continue;
  443|   194k|#if !defined(MP_USE_UINT_DIGIT)
  444|   194k|        LZCNTLOOP(32);
  ------------------
  |  |  411|   194k|    do {                                           \
  |  |  412|   194k|        x = d >> (i);                              \
  |  |  413|   194k|        mask = (0 - x);                            \
  |  |  414|   194k|        mask = (0 - (mask >> (MP_DIGIT_BIT - 1))); \
  |  |  ------------------
  |  |  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  415|   194k|        bits += (i)&mask;                          \
  |  |  416|   194k|        d ^= (x ^ d) & mask;                       \
  |  |  417|   194k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (417:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  445|   194k|#endif
  446|   194k|        LZCNTLOOP(16);
  ------------------
  |  |  411|   194k|    do {                                           \
  |  |  412|   194k|        x = d >> (i);                              \
  |  |  413|   194k|        mask = (0 - x);                            \
  |  |  414|   194k|        mask = (0 - (mask >> (MP_DIGIT_BIT - 1))); \
  |  |  ------------------
  |  |  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  415|   194k|        bits += (i)&mask;                          \
  |  |  416|   194k|        d ^= (x ^ d) & mask;                       \
  |  |  417|   194k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (417:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  447|   194k|        LZCNTLOOP(8);
  ------------------
  |  |  411|   194k|    do {                                           \
  |  |  412|   194k|        x = d >> (i);                              \
  |  |  413|   194k|        mask = (0 - x);                            \
  |  |  414|   194k|        mask = (0 - (mask >> (MP_DIGIT_BIT - 1))); \
  |  |  ------------------
  |  |  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  415|   194k|        bits += (i)&mask;                          \
  |  |  416|   194k|        d ^= (x ^ d) & mask;                       \
  |  |  417|   194k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (417:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  448|   194k|        LZCNTLOOP(4);
  ------------------
  |  |  411|   194k|    do {                                           \
  |  |  412|   194k|        x = d >> (i);                              \
  |  |  413|   194k|        mask = (0 - x);                            \
  |  |  414|   194k|        mask = (0 - (mask >> (MP_DIGIT_BIT - 1))); \
  |  |  ------------------
  |  |  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  415|   194k|        bits += (i)&mask;                          \
  |  |  416|   194k|        d ^= (x ^ d) & mask;                       \
  |  |  417|   194k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (417:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  449|   194k|        LZCNTLOOP(2);
  ------------------
  |  |  411|   194k|    do {                                           \
  |  |  412|   194k|        x = d >> (i);                              \
  |  |  413|   194k|        mask = (0 - x);                            \
  |  |  414|   194k|        mask = (0 - (mask >> (MP_DIGIT_BIT - 1))); \
  |  |  ------------------
  |  |  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  415|   194k|        bits += (i)&mask;                          \
  |  |  416|   194k|        d ^= (x ^ d) & mask;                       \
  |  |  417|   194k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (417:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  450|   194k|        LZCNTLOOP(1);
  ------------------
  |  |  411|   194k|    do {                                           \
  |  |  412|   194k|        x = d >> (i);                              \
  |  |  413|   194k|        mask = (0 - x);                            \
  |  |  414|   194k|        mask = (0 - (mask >> (MP_DIGIT_BIT - 1))); \
  |  |  ------------------
  |  |  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  415|   194k|        bits += (i)&mask;                          \
  |  |  416|   194k|        d ^= (x ^ d) & mask;                       \
  |  |  417|   194k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (417:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  451|   194k|        break;
  452|   194k|    }
  453|   194k|    bits += ix * MP_DIGIT_BIT;
  ------------------
  |  |  137|   194k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  ------------------
  |  |  |  |  136|   194k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  ------------------
  ------------------
  454|   194k|    return bits;
  455|   194k|}

s_mp_redc:
   34|   106M|{
   35|   106M|    mp_err res;
   36|   106M|    mp_size i;
   37|       |
   38|   106M|    i = (MP_USED(&mmm->N) << 1) + 1;
  ------------------
  |  |  150|   106M|#define MP_USED(MP) ((MP)->used)
  ------------------
   39|   106M|    MP_CHECKOK(s_mp_pad(T, i));
  ------------------
  |  |  319|   106M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   106M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 106M]
  |  |  ------------------
  |  |  320|   106M|    goto CLEANUP
  ------------------
   40|  2.47G|    for (i = 0; i < MP_USED(&mmm->N); ++i) {
  ------------------
  |  |  150|  2.47G|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (40:17): [True: 2.36G, False: 106M]
  ------------------
   41|  2.36G|        mp_digit m_i = MP_DIGIT(T, i) * mmm->n0prime;
  ------------------
  |  |  153|  2.36G|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
   42|       |        /* T += N * m_i * (MP_RADIX ** i); */
   43|  2.36G|        s_mp_mul_d_add_offset(&mmm->N, m_i, T, i);
  ------------------
  |  |  213|  2.36G|    s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|  2.36G|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  150|  2.36G|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|  2.36G|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
   44|  2.36G|    }
   45|   106M|    s_mp_clamp(T);
   46|       |
   47|       |    /* T /= R */
   48|   106M|    s_mp_rshd(T, MP_USED(&mmm->N));
  ------------------
  |  |  150|   106M|#define MP_USED(MP) ((MP)->used)
  ------------------
   49|       |
   50|   106M|    if (s_mp_cmp(T, &mmm->N) >= 0) {
  ------------------
  |  Branch (50:9): [True: 31.0M, False: 75.7M]
  ------------------
   51|       |        /* T = T - N */
   52|  31.0M|        MP_CHECKOK(s_mp_sub(T, &mmm->N));
  ------------------
  |  |  319|  31.0M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  31.0M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 31.0M]
  |  |  ------------------
  |  |  320|  31.0M|    goto CLEANUP
  ------------------
   53|  31.0M|#ifdef DEBUG
   54|  31.0M|        if (mp_cmp(T, &mmm->N) >= 0) {
  ------------------
  |  Branch (54:13): [True: 0, False: 31.0M]
  ------------------
   55|      0|            res = MP_UNDEF;
  ------------------
  |  |   45|      0|#define MP_UNDEF -5  /* answer is undefined   */
  ------------------
   56|      0|            goto CLEANUP;
   57|      0|        }
   58|  31.0M|#endif
   59|  31.0M|    }
   60|   106M|    res = MP_OKAY;
  ------------------
  |  |   39|   106M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
   61|   106M|CLEANUP:
   62|   106M|    return res;
   63|   106M|}
s_mp_mul_mont:
   75|  21.7M|{
   76|  21.7M|    mp_digit *pb;
   77|  21.7M|    mp_digit m_i;
   78|  21.7M|    mp_err res;
   79|  21.7M|    mp_size ib; /* "index b": index of current digit of B */
   80|  21.7M|    mp_size useda, usedb;
   81|       |
   82|  21.7M|    ARGCHK(a != NULL && b != NULL && c != NULL, MP_BADARG);
  ------------------
  |  |  355|  21.7M|#define ARGCHK(X, Y) assert(X)
  ------------------
   83|       |
   84|  21.7M|    if (MP_USED(a) < MP_USED(b)) {
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
                  if (MP_USED(a) < MP_USED(b)) {
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (84:9): [True: 744, False: 21.7M]
  ------------------
   85|    744|        const mp_int *xch = b; /* switch a and b, to do fewer outer loops */
   86|    744|        b = a;
   87|    744|        a = xch;
   88|    744|    }
   89|       |
   90|  21.7M|    MP_USED(c) = 1;
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
   91|  21.7M|    MP_DIGIT(c, 0) = 0;
  ------------------
  |  |  153|  21.7M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
   92|  21.7M|    ib = (MP_USED(&mmm->N) << 1) + 1;
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
   93|  21.7M|    if ((res = s_mp_pad(c, ib)) != MP_OKAY)
  ------------------
  |  |   39|  21.7M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  |  Branch (93:9): [True: 0, False: 21.7M]
  ------------------
   94|      0|        goto CLEANUP;
   95|       |
   96|  21.7M|    useda = MP_USED(a);
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
   97|  21.7M|    pb = MP_DIGITS(b);
  ------------------
  |  |  152|  21.7M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
   98|  21.7M|    s_mpv_mul_d(MP_DIGITS(a), useda, *pb++, MP_DIGITS(c));
  ------------------
  |  |  181|  21.7M|    ((mp_digit *)c)[a_len] = s_mpv_mul_set_vec64(c, a, a_len, b)
  ------------------
   99|  21.7M|    s_mp_setz(MP_DIGITS(c) + useda + 1, ib - (useda + 1));
  ------------------
  |  |  152|  21.7M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  100|  21.7M|    m_i = MP_DIGIT(c, 0) * mmm->n0prime;
  ------------------
  |  |  153|  21.7M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  101|  21.7M|    s_mp_mul_d_add_offset(&mmm->N, m_i, c, 0);
  ------------------
  |  |  213|  21.7M|    s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|  21.7M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|  21.7M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  102|       |
  103|       |    /* Outer loop:  Digits of b */
  104|  21.7M|    usedb = MP_USED(b);
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
  105|   514M|    for (ib = 1; ib < usedb; ib++) {
  ------------------
  |  Branch (105:18): [True: 493M, False: 21.7M]
  ------------------
  106|   493M|        mp_digit b_i = *pb++;
  107|       |
  108|       |        /* Inner product:  Digits of a */
  109|   493M|        if (b_i)
  ------------------
  |  Branch (109:13): [True: 493M, False: 9.76k]
  ------------------
  110|   493M|            s_mpv_mul_d_add_prop(MP_DIGITS(a), useda, b_i, MP_DIGITS(c) + ib);
  ------------------
  |  |  152|   493M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
                          s_mpv_mul_d_add_prop(MP_DIGITS(a), useda, b_i, MP_DIGITS(c) + ib);
  ------------------
  |  |  152|   493M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  111|   493M|        m_i = MP_DIGIT(c, ib) * mmm->n0prime;
  ------------------
  |  |  153|   493M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  112|   493M|        s_mp_mul_d_add_offset(&mmm->N, m_i, c, ib);
  ------------------
  |  |  213|   493M|    s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|   493M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  150|   493M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|   493M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  113|   493M|    }
  114|  21.7M|    if (usedb < MP_USED(&mmm->N)) {
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (114:9): [True: 971k, False: 20.7M]
  ------------------
  115|  2.38M|        for (usedb = MP_USED(&mmm->N); ib < usedb; ++ib) {
  ------------------
  |  |  150|   971k|#define MP_USED(MP) ((MP)->used)
  ------------------
  |  Branch (115:40): [True: 1.41M, False: 971k]
  ------------------
  116|  1.41M|            m_i = MP_DIGIT(c, ib) * mmm->n0prime;
  ------------------
  |  |  153|  1.41M|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  117|  1.41M|            s_mp_mul_d_add_offset(&mmm->N, m_i, c, ib);
  ------------------
  |  |  213|  1.41M|    s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|  1.41M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  150|  1.41M|#define MP_USED(MP) ((MP)->used)
  |  |  ------------------
  |  |                   s_mpv_mul_d_add_prop(MP_DIGITS(a), MP_USED(a), b, MP_DIGITS(c) + off)
  |  |  ------------------
  |  |  |  |  152|  1.41M|#define MP_DIGITS(MP) ((MP)->dp)
  |  |  ------------------
  ------------------
  118|  1.41M|        }
  119|   971k|    }
  120|  21.7M|    s_mp_clamp(c);
  121|  21.7M|    s_mp_rshd(c, MP_USED(&mmm->N)); /* c /= R */
  ------------------
  |  |  150|  21.7M|#define MP_USED(MP) ((MP)->used)
  ------------------
  122|  21.7M|    if (s_mp_cmp(c, &mmm->N) >= 0) {
  ------------------
  |  Branch (122:9): [True: 3.49M, False: 18.2M]
  ------------------
  123|  3.49M|        MP_CHECKOK(s_mp_sub(c, &mmm->N));
  ------------------
  |  |  319|  3.49M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  3.49M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 3.49M]
  |  |  ------------------
  |  |  320|  3.49M|    goto CLEANUP
  ------------------
  124|  3.49M|    }
  125|  21.7M|    res = MP_OKAY;
  ------------------
  |  |   39|  21.7M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  126|       |
  127|  21.7M|CLEANUP:
  128|  21.7M|    return res;
  129|  21.7M|}
mp_to_mont:
  134|   353k|{
  135|   353k|    mp_err res;
  136|       |
  137|       |    /* xMont = x * R mod N   where  N is modulus */
  138|   353k|    if (x != xMont) {
  ------------------
  |  Branch (138:9): [True: 194k, False: 158k]
  ------------------
  139|   194k|        MP_CHECKOK(mp_copy(x, xMont));
  ------------------
  |  |  319|   194k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   194k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 194k]
  |  |  ------------------
  |  |  320|   194k|    goto CLEANUP
  ------------------
  140|   194k|    }
  141|   353k|    MP_CHECKOK(s_mp_lshd(xMont, MP_USED(N))); /* xMont = x << b */
  ------------------
  |  |  319|   353k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   353k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 353k]
  |  |  ------------------
  |  |  320|   353k|    goto CLEANUP
  ------------------
  142|   353k|    MP_CHECKOK(mp_div(xMont, N, 0, xMont));   /*         mod N */
  ------------------
  |  |  319|   353k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   353k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 353k]
  |  |  ------------------
  |  |  320|   353k|    goto CLEANUP
  ------------------
  143|   353k|CLEANUP:
  144|   353k|    return res;
  145|   353k|}
mp_calculate_mont_n0i:
  149|   194k|{
  150|   194k|    return 0 - s_mp_invmod_radix(MP_DIGIT(N, 0));
  ------------------
  |  |  153|   194k|#define MP_DIGIT(MP, N) (MP)->dp[(N)]
  ------------------
  151|   194k|}
mpi_to_weave:
  738|  1.52M|{
  739|  1.52M|    mp_size i;
  740|  1.52M|    mp_digit *endDest = weaved + (nDigits * nBignums);
  741|       |
  742|  7.60M|    for (i = 0; i < WEAVE_WORD_SIZE; i++) {
  ------------------
  |  |  694|  7.60M|#define WEAVE_WORD_SIZE 4
  ------------------
  |  Branch (742:17): [True: 6.08M, False: 1.52M]
  ------------------
  743|  6.08M|        mp_size used = MP_USED(&bignums[i]);
  ------------------
  |  |  150|  6.08M|#define MP_USED(MP) ((MP)->used)
  ------------------
  744|  6.08M|        mp_digit *pSrc = MP_DIGITS(&bignums[i]);
  ------------------
  |  |  152|  6.08M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  745|  6.08M|        mp_digit *endSrc = pSrc + used;
  746|  6.08M|        mp_digit *pDest = weaved + i;
  747|       |
  748|  6.08M|        ARGCHK(MP_SIGN(&bignums[i]) == MP_ZPOS, MP_BADARG);
  ------------------
  |  |  355|  6.08M|#define ARGCHK(X, Y) assert(X)
  ------------------
  749|  6.08M|        ARGCHK(used <= nDigits, MP_BADARG);
  ------------------
  |  |  355|  6.08M|#define ARGCHK(X, Y) assert(X)
  ------------------
  750|       |
  751|   148M|        for (; pSrc < endSrc; pSrc++) {
  ------------------
  |  Branch (751:16): [True: 142M, False: 6.08M]
  ------------------
  752|   142M|            *pDest = *pSrc;
  753|   142M|            pDest += nBignums;
  754|   142M|        }
  755|  6.36M|        while (pDest < endDest) {
  ------------------
  |  Branch (755:16): [True: 281k, False: 6.08M]
  ------------------
  756|   281k|            *pDest = 0;
  757|   281k|            pDest += nBignums;
  758|   281k|        }
  759|  6.08M|    }
  760|       |
  761|  1.52M|    return MP_OKAY;
  ------------------
  |  |   39|  1.52M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  762|  1.52M|}
weave_to_mpi:
  782|  21.0M|{
  783|       |    /* these are indices, but need to be the same size as mp_digit
  784|       |     * because of the CONST_TIME operations */
  785|  21.0M|    mp_digit i, j;
  786|  21.0M|    mp_digit d;
  787|  21.0M|    mp_digit *pDest = MP_DIGITS(a);
  ------------------
  |  |  152|  21.0M|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  788|       |
  789|  21.0M|    MP_SIGN(a) = MP_ZPOS;
  ------------------
  |  |  149|  21.0M|#define MP_SIGN(MP) ((MP)->sign)
  ------------------
                  MP_SIGN(a) = MP_ZPOS;
  ------------------
  |  |   37|  21.0M|#define MP_ZPOS 0
  ------------------
  790|  21.0M|    MP_USED(a) = nDigits;
  ------------------
  |  |  150|  21.0M|#define MP_USED(MP) ((MP)->used)
  ------------------
  791|       |
  792|  21.0M|    assert(weaved != NULL);
  793|       |
  794|       |    /* Fetch the proper column in constant time, indexing over the whole array */
  795|   516M|    for (i = 0; i < nDigits; ++i) {
  ------------------
  |  Branch (795:17): [True: 495M, False: 21.0M]
  ------------------
  796|   495M|        d = 0;
  797|  21.2G|        for (j = 0; j < nBignums; ++j) {
  ------------------
  |  Branch (797:21): [True: 20.7G, False: 495M]
  ------------------
  798|  20.7G|            d |= weaved[i * nBignums + j] & CONST_TIME_EQ(j, index);
  ------------------
  |  |  769|  20.7G|#define CONST_TIME_EQ(a, b) CONST_TIME_EQ_Z((a) ^ (b))
  |  |  ------------------
  |  |  |  |  768|  20.7G|#define CONST_TIME_EQ_Z(x) CONST_TIME_MSB(~(x) & ((x)-1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  767|  20.7G|#define CONST_TIME_MSB(x) (0L - ((x) >> (8 * sizeof(x) - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  799|  20.7G|        }
  800|   495M|        pDest[i] = d;
  801|   495M|    }
  802|       |
  803|  21.0M|    s_mp_clamp(a);
  804|  21.0M|    return MP_OKAY;
  ------------------
  |  |   39|  21.0M|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  805|  21.0M|}
mp_exptmod_safe_i:
  841|   194k|{
  842|   194k|    mp_int *pa1, *pa2, *ptmp;
  843|   194k|    mp_size i;
  844|   194k|    mp_size first_window;
  845|   194k|    mp_err res;
  846|   194k|    int expOff;
  847|   194k|    mp_int accum1, accum2, accum[WEAVE_WORD_SIZE];
  848|   194k|    mp_int tmp;
  849|   194k|    mp_digit *powersArray = NULL;
  850|   194k|    mp_digit *powers = NULL;
  851|       |
  852|   194k|    MP_DIGITS(&accum1) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  853|   194k|    MP_DIGITS(&accum2) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  854|   194k|    MP_DIGITS(&accum[0]) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  855|   194k|    MP_DIGITS(&accum[1]) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  856|   194k|    MP_DIGITS(&accum[2]) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  857|   194k|    MP_DIGITS(&accum[3]) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  858|   194k|    MP_DIGITS(&tmp) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  859|       |
  860|       |    /* grab the first window value. This allows us to preload accumulator1
  861|       |     * and save a conversion, some squares and a multiple*/
  862|   194k|    MP_CHECKOK(mpl_get_bits(exponent,
  ------------------
  |  |  319|   194k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   194k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 194k]
  |  |  ------------------
  |  |  320|   194k|    goto CLEANUP
  ------------------
  863|   194k|                            bits_in_exponent - window_bits, window_bits));
  864|   194k|    first_window = (mp_size)res;
  865|       |
  866|   194k|    MP_CHECKOK(mp_init_size(&accum1, 3 * nLen + 2));
  ------------------
  |  |  319|   194k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   194k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 194k]
  |  |  ------------------
  |  |  320|   194k|    goto CLEANUP
  ------------------
  867|   194k|    MP_CHECKOK(mp_init_size(&accum2, 3 * nLen + 2));
  ------------------
  |  |  319|   194k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   194k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 194k]
  |  |  ------------------
  |  |  320|   194k|    goto CLEANUP
  ------------------
  868|       |
  869|       |    /* build the first WEAVE_WORD powers inline */
  870|       |    /* if WEAVE_WORD_SIZE is not 4, this code will have to change */
  871|   194k|    if (num_powers > 2) {
  ------------------
  |  Branch (871:9): [True: 158k, False: 35.7k]
  ------------------
  872|   158k|        MP_CHECKOK(mp_init_size(&accum[0], 3 * nLen + 2));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  873|   158k|        MP_CHECKOK(mp_init_size(&accum[1], 3 * nLen + 2));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  874|   158k|        MP_CHECKOK(mp_init_size(&accum[2], 3 * nLen + 2));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  875|   158k|        MP_CHECKOK(mp_init_size(&accum[3], 3 * nLen + 2));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  876|   158k|        mp_set(&accum[0], 1);
  877|   158k|        MP_CHECKOK(mp_to_mont(&accum[0], &(mmm->N), &accum[0]));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  878|   158k|        MP_CHECKOK(mp_copy(montBase, &accum[1]));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  879|   317k|        SQR(montBase, &accum[2]);
  ------------------
  |  |  808|   158k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  |  |  ------------------
  |  |  |  |  320|   158k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   158k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  |  |  ------------------
  |  |  |  |  320|   158k|    goto CLEANUP
  |  |  ------------------
  ------------------
  880|   158k|        MUL_NOWEAVE(montBase, &accum[2], &accum[3]);
  ------------------
  |  |  817|   158k|    MP_CHECKOK(s_mp_mul_mont(a, x, b, mmm))
  |  |  ------------------
  |  |  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  |  |  ------------------
  |  |  |  |  320|   158k|    goto CLEANUP
  |  |  ------------------
  ------------------
  881|   158k|        powersArray = (mp_digit *)malloc(num_powers * (nLen * sizeof(mp_digit) + 1));
  882|   158k|        if (!powersArray) {
  ------------------
  |  Branch (882:13): [True: 0, False: 158k]
  ------------------
  883|      0|            res = MP_MEM;
  ------------------
  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  ------------------
  884|      0|            goto CLEANUP;
  885|      0|        }
  886|       |        /* powers[i] = base ** (i); */
  887|   158k|        powers = (mp_digit *)MP_ALIGN(powersArray, num_powers);
  ------------------
  |  |  828|   158k|#define MP_ALIGN(x, y) ((((ptrdiff_t)(x)) + ((y)-1)) & (((ptrdiff_t)0) - (y)))
  ------------------
  888|   158k|        MP_CHECKOK(mpi_to_weave(accum, powers, nLen, num_powers));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  889|   158k|        if (first_window < 4) {
  ------------------
  |  Branch (889:13): [True: 23.8k, False: 134k]
  ------------------
  890|  23.8k|            MP_CHECKOK(mp_copy(&accum[first_window], &accum1));
  ------------------
  |  |  319|  23.8k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  23.8k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 23.8k]
  |  |  ------------------
  |  |  320|  23.8k|    goto CLEANUP
  ------------------
  891|  23.8k|            first_window = num_powers;
  892|  23.8k|        }
  893|   158k|    } else {
  894|  35.7k|        if (first_window == 0) {
  ------------------
  |  Branch (894:13): [True: 0, False: 35.7k]
  ------------------
  895|      0|            mp_set(&accum1, 1);
  896|      0|            MP_CHECKOK(mp_to_mont(&accum1, &(mmm->N), &accum1));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
  897|  35.7k|        } else {
  898|       |            /* assert first_window == 1? */
  899|  35.7k|            MP_CHECKOK(mp_copy(montBase, &accum1));
  ------------------
  |  |  319|  35.7k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  35.7k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 35.7k]
  |  |  ------------------
  |  |  320|  35.7k|    goto CLEANUP
  ------------------
  900|  35.7k|        }
  901|  35.7k|    }
  902|       |
  903|       |    /*
  904|       |     * calculate all the powers in the powers array.
  905|       |     * this adds 2**(k-1)-2 square operations over just calculating the
  906|       |     * odd powers where k is the window size in the two other mp_modexpt
  907|       |     * implementations in this file. We will get some of that
  908|       |     * back by not needing the first 'k' squares and one multiply for the
  909|       |     * first window.
  910|       |     * Given the value of 4 for WEAVE_WORD_SIZE, this loop will only execute if
  911|       |     * num_powers > 2, in which case powers will have been allocated.
  912|       |     */
  913|  5.64M|    for (i = WEAVE_WORD_SIZE; i < num_powers; i++) {
  ------------------
  |  |  694|   194k|#define WEAVE_WORD_SIZE 4
  ------------------
  |  Branch (913:31): [True: 5.44M, False: 194k]
  ------------------
  914|  5.44M|        int acc_index = i & (WEAVE_WORD_SIZE - 1); /* i % WEAVE_WORD_SIZE */
  ------------------
  |  |  694|  5.44M|#define WEAVE_WORD_SIZE 4
  ------------------
  915|  5.44M|        if (i & 1) {
  ------------------
  |  Branch (915:13): [True: 2.72M, False: 2.72M]
  ------------------
  916|  2.72M|            MUL_NOWEAVE(montBase, &accum[acc_index - 1], &accum[acc_index]);
  ------------------
  |  |  817|  2.72M|    MP_CHECKOK(s_mp_mul_mont(a, x, b, mmm))
  |  |  ------------------
  |  |  |  |  319|  2.72M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  2.72M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 2.72M]
  |  |  |  |  ------------------
  |  |  |  |  320|  2.72M|    goto CLEANUP
  |  |  ------------------
  ------------------
  917|       |            /* we've filled the array do our 'per array' processing */
  918|  2.72M|            if (acc_index == (WEAVE_WORD_SIZE - 1)) {
  ------------------
  |  |  694|  2.72M|#define WEAVE_WORD_SIZE 4
  ------------------
  |  Branch (918:17): [True: 1.36M, False: 1.36M]
  ------------------
  919|  1.36M|                MP_CHECKOK(mpi_to_weave(accum, powers + i - (WEAVE_WORD_SIZE - 1),
  ------------------
  |  |  319|  1.36M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  1.36M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 1.36M]
  |  |  ------------------
  |  |  320|  1.36M|    goto CLEANUP
  ------------------
  920|  1.36M|                                        nLen, num_powers));
  921|       |
  922|  1.36M|                if (first_window <= i) {
  ------------------
  |  Branch (922:21): [True: 134k, False: 1.22M]
  ------------------
  923|   134k|                    MP_CHECKOK(mp_copy(&accum[first_window & (WEAVE_WORD_SIZE - 1)],
  ------------------
  |  |  319|   134k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   134k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 134k]
  |  |  ------------------
  |  |  320|   134k|    goto CLEANUP
  ------------------
  924|   134k|                                       &accum1));
  925|   134k|                    first_window = num_powers;
  926|   134k|                }
  927|  1.36M|            }
  928|  2.72M|        } else {
  929|       |            /* up to 8 we can find 2^i-1 in the accum array, but at 8 we our source
  930|       |             * and target are the same so we need to copy.. After that, the
  931|       |             * value is overwritten, so we need to fetch it from the stored
  932|       |             * weave array */
  933|  2.72M|            if (i > 2 * WEAVE_WORD_SIZE) {
  ------------------
  |  |  694|  2.72M|#define WEAVE_WORD_SIZE 4
  ------------------
  |  Branch (933:17): [True: 2.24M, False: 476k]
  ------------------
  934|  2.24M|                MP_CHECKOK(weave_to_mpi(&accum2, powers, i / 2, nLen, num_powers));
  ------------------
  |  |  319|  2.24M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  2.24M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 2.24M]
  |  |  ------------------
  |  |  320|  2.24M|    goto CLEANUP
  ------------------
  935|  4.49M|                SQR(&accum2, &accum[acc_index]);
  ------------------
  |  |  808|  2.24M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  2.24M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  2.24M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 2.24M]
  |  |  |  |  ------------------
  |  |  |  |  320|  2.24M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  2.24M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  2.24M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  2.24M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 2.24M]
  |  |  |  |  ------------------
  |  |  |  |  320|  2.24M|    goto CLEANUP
  |  |  ------------------
  ------------------
  936|  4.49M|            } else {
  937|   476k|                int half_power_index = (i / 2) & (WEAVE_WORD_SIZE - 1);
  ------------------
  |  |  694|   476k|#define WEAVE_WORD_SIZE 4
  ------------------
  938|   476k|                if (half_power_index == acc_index) {
  ------------------
  |  Branch (938:21): [True: 158k, False: 317k]
  ------------------
  939|       |                    /* copy is cheaper than weave_to_mpi */
  940|   158k|                    MP_CHECKOK(mp_copy(&accum[half_power_index], &accum2));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  941|   317k|                    SQR(&accum2, &accum[acc_index]);
  ------------------
  |  |  808|   158k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  |  |  ------------------
  |  |  |  |  320|   158k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   158k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  |  |  ------------------
  |  |  |  |  320|   158k|    goto CLEANUP
  |  |  ------------------
  ------------------
  942|   317k|                } else {
  943|   317k|                    SQR(&accum[half_power_index], &accum[acc_index]);
  ------------------
  |  |  808|   317k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   317k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   317k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 317k]
  |  |  |  |  ------------------
  |  |  |  |  320|   317k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   317k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   317k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   317k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 317k]
  |  |  |  |  ------------------
  |  |  |  |  320|   317k|    goto CLEANUP
  |  |  ------------------
  ------------------
  944|   317k|                }
  945|   476k|            }
  946|  2.72M|        }
  947|  5.44M|    }
  948|       |/* if the accum1 isn't set, Then there is something wrong with our logic
  949|       | * above and is an internal programming error.
  950|       | */
  951|   194k|#if MP_ARGCHK == 2
  952|   194k|    assert(MP_USED(&accum1) != 0);
  953|   194k|#endif
  954|       |
  955|       |    /* set accumulator to montgomery residue of 1 */
  956|   194k|    pa1 = &accum1;
  957|   194k|    pa2 = &accum2;
  958|       |
  959|       |    /* tmp is not used if window_bits == 1. */
  960|   194k|    if (window_bits != 1) {
  ------------------
  |  Branch (960:9): [True: 158k, False: 35.7k]
  ------------------
  961|   158k|        MP_CHECKOK(mp_init_size(&tmp, 3 * nLen + 2));
  ------------------
  |  |  319|   158k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   158k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 158k]
  |  |  ------------------
  |  |  320|   158k|    goto CLEANUP
  ------------------
  962|   158k|    }
  963|       |
  964|  19.5M|    for (expOff = bits_in_exponent - window_bits * 2; expOff >= 0; expOff -= window_bits) {
  ------------------
  |  Branch (964:55): [True: 19.3M, False: 194k]
  ------------------
  965|  19.3M|        mp_size smallExp;
  966|  19.3M|        MP_CHECKOK(mpl_get_bits(exponent, expOff, window_bits));
  ------------------
  |  |  319|  19.3M|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|  19.3M|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 19.3M]
  |  |  ------------------
  |  |  320|  19.3M|    goto CLEANUP
  ------------------
  967|  19.3M|        smallExp = (mp_size)res;
  968|       |
  969|       |        /* handle unroll the loops */
  970|  19.3M|        switch (window_bits) {
  971|   571k|            case 1:
  ------------------
  |  Branch (971:13): [True: 571k, False: 18.7M]
  ------------------
  972|   571k|                if (!smallExp) {
  ------------------
  |  Branch (972:21): [True: 535k, False: 36.0k]
  ------------------
  973|   535k|                    SQR(pa1, pa2);
  ------------------
  |  |  808|   535k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   535k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   535k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 535k]
  |  |  |  |  ------------------
  |  |  |  |  320|   535k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   535k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   535k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   535k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 535k]
  |  |  |  |  ------------------
  |  |  |  |  320|   535k|    goto CLEANUP
  |  |  ------------------
  ------------------
  974|   535k|                    SWAPPA;
  ------------------
  |  |  825|   535k|    ptmp = pa1; \
  |  |  826|   535k|    pa1 = pa2;  \
  |  |  827|   535k|    pa2 = ptmp
  ------------------
  975|   535k|                } else if (smallExp & 1) {
  ------------------
  |  Branch (975:28): [True: 36.0k, False: 0]
  ------------------
  976|  36.0k|                    SQR(pa1, pa2);
  ------------------
  |  |  808|  36.0k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  36.0k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 36.0k]
  |  |  |  |  ------------------
  |  |  |  |  320|  36.0k|    goto CLEANUP
  |  |  ------------------
  |  |  809|  36.0k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  36.0k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 36.0k]
  |  |  |  |  ------------------
  |  |  |  |  320|  36.0k|    goto CLEANUP
  |  |  ------------------
  ------------------
  977|  36.0k|                    MUL_NOWEAVE(montBase, pa2, pa1);
  ------------------
  |  |  817|  36.0k|    MP_CHECKOK(s_mp_mul_mont(a, x, b, mmm))
  |  |  ------------------
  |  |  |  |  319|  36.0k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.0k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 36.0k]
  |  |  |  |  ------------------
  |  |  |  |  320|  36.0k|    goto CLEANUP
  |  |  ------------------
  ------------------
  978|  36.0k|                } else {
  979|      0|                    abort();
  980|      0|                }
  981|   571k|                break;
  982|  13.8M|            case 6:
  ------------------
  |  Branch (982:13): [True: 13.8M, False: 5.51M]
  ------------------
  983|  13.8M|                SQR(pa1, pa2);
  ------------------
  |  |  808|  13.8M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  13.8M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  13.8M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 13.8M]
  |  |  |  |  ------------------
  |  |  |  |  320|  13.8M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  13.8M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  13.8M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  13.8M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 13.8M]
  |  |  |  |  ------------------
  |  |  |  |  320|  13.8M|    goto CLEANUP
  |  |  ------------------
  ------------------
  984|  27.6M|                SQR(pa2, pa1);
  ------------------
  |  |  808|  13.8M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  13.8M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  13.8M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 13.8M]
  |  |  |  |  ------------------
  |  |  |  |  320|  13.8M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  13.8M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  13.8M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  13.8M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 13.8M]
  |  |  |  |  ------------------
  |  |  |  |  320|  13.8M|    goto CLEANUP
  |  |  ------------------
  ------------------
  985|       |            /* fall through */
  986|  18.4M|            case 4:
  ------------------
  |  Branch (986:13): [True: 4.64M, False: 14.7M]
  ------------------
  987|  18.4M|                SQR(pa1, pa2);
  ------------------
  |  |  808|  18.4M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  18.4M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  ------------------
  988|  36.9M|                SQR(pa2, pa1);
  ------------------
  |  |  808|  18.4M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  18.4M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  ------------------
  989|  36.9M|                SQR(pa1, pa2);
  ------------------
  |  |  808|  18.4M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  18.4M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  ------------------
  990|  36.9M|                SQR(pa2, pa1);
  ------------------
  |  |  808|  18.4M|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  |  |  809|  18.4M|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  ------------------
  991|  36.9M|                MUL(smallExp, pa1, pa2);
  ------------------
  |  |  821|  18.4M|    MP_CHECKOK(weave_to_mpi(&tmp, powers, (x), nLen, num_powers)); \
  |  |  ------------------
  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  ------------------
  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  ------------------
  |  |  822|  18.4M|    MUL_NOWEAVE(&tmp, a, b)
  |  |  ------------------
  |  |  |  |  817|  18.4M|    MP_CHECKOK(s_mp_mul_mont(a, x, b, mmm))
  |  |  |  |  ------------------
  |  |  |  |  |  |  319|  18.4M|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   39|  18.4M|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (319:9): [True: 0, False: 18.4M]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  320|  18.4M|    goto CLEANUP
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  992|  18.4M|                SWAPPA;
  ------------------
  |  |  825|  18.4M|    ptmp = pa1; \
  |  |  826|  18.4M|    pa1 = pa2;  \
  |  |  827|  18.4M|    pa2 = ptmp
  ------------------
  993|  18.4M|                break;
  994|   299k|            case 5:
  ------------------
  |  Branch (994:13): [True: 299k, False: 19.0M]
  ------------------
  995|   299k|                SQR(pa1, pa2);
  ------------------
  |  |  808|   299k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   299k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  ------------------
  996|   599k|                SQR(pa2, pa1);
  ------------------
  |  |  808|   299k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   299k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  ------------------
  997|   599k|                SQR(pa1, pa2);
  ------------------
  |  |  808|   299k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   299k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  ------------------
  998|   599k|                SQR(pa2, pa1);
  ------------------
  |  |  808|   299k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   299k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  ------------------
  999|   599k|                SQR(pa1, pa2);
  ------------------
  |  |  808|   299k|    MP_CHECKOK(mp_sqr(a, b)); \
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  |  |  809|   299k|    MP_CHECKOK(s_mp_redc(b, mmm))
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  ------------------
 1000|   599k|                MUL(smallExp, pa2, pa1);
  ------------------
  |  |  821|   299k|    MP_CHECKOK(weave_to_mpi(&tmp, powers, (x), nLen, num_powers)); \
  |  |  ------------------
  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  ------------------
  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  ------------------
  |  |  822|   299k|    MUL_NOWEAVE(&tmp, a, b)
  |  |  ------------------
  |  |  |  |  817|   299k|    MP_CHECKOK(s_mp_mul_mont(a, x, b, mmm))
  |  |  |  |  ------------------
  |  |  |  |  |  |  319|   299k|    if (MP_OKAY > (res = (x))) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |   39|   299k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (319:9): [True: 0, False: 299k]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  320|   299k|    goto CLEANUP
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1001|   299k|                break;
 1002|   299k|            default:
  ------------------
  |  Branch (1002:13): [True: 0, False: 19.3M]
  ------------------
 1003|      0|                abort(); /* could do a loop? */
 1004|  19.3M|        }
 1005|  19.3M|    }
 1006|       |
 1007|   194k|    res = s_mp_redc(pa1, mmm);
 1008|   194k|    mp_exch(pa1, result);
 1009|       |
 1010|   194k|CLEANUP:
 1011|   194k|    mp_clear(&accum1);
 1012|   194k|    mp_clear(&accum2);
 1013|   194k|    mp_clear(&accum[0]);
 1014|   194k|    mp_clear(&accum[1]);
 1015|   194k|    mp_clear(&accum[2]);
 1016|   194k|    mp_clear(&accum[3]);
 1017|   194k|    mp_clear(&tmp);
 1018|       |    /* zero required by FIPS here, can't use PORT_ZFree
 1019|       |     * because mpi doesn't link with util */
 1020|   194k|    if (powers) {
  ------------------
  |  Branch (1020:9): [True: 158k, False: 35.7k]
  ------------------
 1021|   158k|        PORT_Memset(powers, 0, num_powers * sizeof(mp_digit));
  ------------------
  |  |  182|   158k|#define PORT_Memset memset
  ------------------
 1022|   158k|    }
 1023|   194k|    free(powersArray);
 1024|   194k|    return res;
 1025|   194k|}
mp_exptmod:
 1033|   196k|{
 1034|   196k|    const mp_int *base;
 1035|   196k|    mp_size bits_in_exponent, i, window_bits, odd_ints;
 1036|   196k|    mp_err res;
 1037|   196k|    int nLen;
 1038|   196k|    mp_int montBase, goodBase;
 1039|   196k|    mp_mont_modulus mmm;
 1040|   196k|#ifdef MP_USING_CACHE_SAFE_MOD_EXP
 1041|   196k|    static unsigned int max_window_bits;
 1042|   196k|#endif
 1043|       |
 1044|       |    /* function for computing n0prime only works if n0 is odd */
 1045|   196k|    if (!mp_isodd(modulus))
  ------------------
  |  Branch (1045:9): [True: 2.39k, False: 194k]
  ------------------
 1046|  2.39k|        return s_mp_exptmod(inBase, exponent, modulus, result);
 1047|       |
 1048|   194k|    if (mp_cmp_z(inBase) == MP_LT)
  ------------------
  |  |   49|   194k|#define MP_LT -1
  ------------------
  |  Branch (1048:9): [True: 0, False: 194k]
  ------------------
 1049|      0|        return MP_RANGE;
  ------------------
  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  ------------------
 1050|   194k|    MP_DIGITS(&montBase) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1051|   194k|    MP_DIGITS(&goodBase) = 0;
  ------------------
  |  |  152|   194k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1052|       |
 1053|   194k|    if (mp_cmp(inBase, modulus) < 0) {
  ------------------
  |  Branch (1053:9): [True: 194k, False: 0]
  ------------------
 1054|   194k|        base = inBase;
 1055|   194k|    } else {
 1056|      0|        MP_CHECKOK(mp_init(&goodBase));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 1057|      0|        base = &goodBase;
 1058|      0|        MP_CHECKOK(mp_mod(inBase, modulus, &goodBase));
  ------------------
  |  |  319|      0|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|      0|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 0]
  |  |  ------------------
  |  |  320|      0|    goto CLEANUP
  ------------------
 1059|      0|    }
 1060|       |
 1061|   194k|    nLen = MP_USED(modulus);
  ------------------
  |  |  150|   194k|#define MP_USED(MP) ((MP)->used)
  ------------------
 1062|   194k|    MP_CHECKOK(mp_init_size(&montBase, 2 * nLen + 2));
  ------------------
  |  |  319|   194k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   194k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 194k]
  |  |  ------------------
  |  |  320|   194k|    goto CLEANUP
  ------------------
 1063|       |
 1064|   194k|    mmm.N = *modulus; /* a copy of the mp_int struct */
 1065|       |
 1066|       |    /* compute n0', given n0, n0' = -(n0 ** -1) mod MP_RADIX
 1067|       |    **        where n0 = least significant mp_digit of N, the modulus.
 1068|       |    */
 1069|   194k|    mmm.n0prime = mp_calculate_mont_n0i(modulus);
 1070|       |
 1071|   194k|    MP_CHECKOK(mp_to_mont(base, modulus, &montBase));
  ------------------
  |  |  319|   194k|    if (MP_OKAY > (res = (x))) \
  |  |  ------------------
  |  |  |  |   39|   194k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (319:9): [True: 0, False: 194k]
  |  |  ------------------
  |  |  320|   194k|    goto CLEANUP
  ------------------
 1072|       |
 1073|   194k|    bits_in_exponent = mpl_significant_bits(exponent);
 1074|   194k|#ifdef MP_USING_CACHE_SAFE_MOD_EXP
 1075|   194k|    if (mp_using_cache_safe_exp) {
  ------------------
  |  Branch (1075:9): [True: 194k, False: 0]
  ------------------
 1076|   194k|        if (bits_in_exponent > 780)
  ------------------
  |  Branch (1076:13): [True: 72.4k, False: 121k]
  ------------------
 1077|  72.4k|            window_bits = 6;
 1078|   121k|        else if (bits_in_exponent > 256)
  ------------------
  |  Branch (1078:18): [True: 3.94k, False: 118k]
  ------------------
 1079|  3.94k|            window_bits = 5;
 1080|   118k|        else if (bits_in_exponent > 20)
  ------------------
  |  Branch (1080:18): [True: 82.3k, False: 35.7k]
  ------------------
 1081|  82.3k|            window_bits = 4;
 1082|       |        /* RSA public key exponents are typically under 20 bits (common values
 1083|       |         * are: 3, 17, 65537) and a 4-bit window is inefficient
 1084|       |         */
 1085|  35.7k|        else
 1086|  35.7k|            window_bits = 1;
 1087|   194k|    } else
 1088|      0|#endif
 1089|      0|        if (bits_in_exponent > 480)
  ------------------
  |  Branch (1089:13): [True: 0, False: 0]
  ------------------
 1090|      0|        window_bits = 6;
 1091|      0|    else if (bits_in_exponent > 160)
  ------------------
  |  Branch (1091:14): [True: 0, False: 0]
  ------------------
 1092|      0|        window_bits = 5;
 1093|      0|    else if (bits_in_exponent > 20)
  ------------------
  |  Branch (1093:14): [True: 0, False: 0]
  ------------------
 1094|      0|        window_bits = 4;
 1095|       |    /* RSA public key exponents are typically under 20 bits (common values
 1096|       |     * are: 3, 17, 65537) and a 4-bit window is inefficient
 1097|       |     */
 1098|      0|    else
 1099|      0|        window_bits = 1;
 1100|       |
 1101|   194k|#ifdef MP_USING_CACHE_SAFE_MOD_EXP
 1102|       |    /*
 1103|       |     * clamp the window size based on
 1104|       |     * the cache line size.
 1105|       |     */
 1106|   194k|    if (!max_window_bits) {
  ------------------
  |  Branch (1106:9): [True: 1, False: 194k]
  ------------------
 1107|      1|        unsigned long cache_size = s_mpi_getProcessorLineSize();
 1108|       |        /* processor has no cache, use 'fast' code always */
 1109|      1|        if (cache_size == 0) {
  ------------------
  |  Branch (1109:13): [True: 0, False: 1]
  ------------------
 1110|      0|            mp_using_cache_safe_exp = 0;
 1111|      0|        }
 1112|      1|        if ((cache_size == 0) || (cache_size >= 64)) {
  ------------------
  |  Branch (1112:13): [True: 0, False: 1]
  |  Branch (1112:34): [True: 1, False: 0]
  ------------------
 1113|      1|            max_window_bits = 6;
 1114|      1|        } else if (cache_size >= 32) {
  ------------------
  |  Branch (1114:20): [True: 0, False: 0]
  ------------------
 1115|      0|            max_window_bits = 5;
 1116|      0|        } else if (cache_size >= 16) {
  ------------------
  |  Branch (1116:20): [True: 0, False: 0]
  ------------------
 1117|      0|            max_window_bits = 4;
 1118|      0|        } else
 1119|      0|            max_window_bits = 1; /* should this be an assert? */
 1120|      1|    }
 1121|       |
 1122|       |    /* clamp the window size down before we caclulate bits_in_exponent */
 1123|   194k|    if (mp_using_cache_safe_exp) {
  ------------------
  |  Branch (1123:9): [True: 194k, False: 0]
  ------------------
 1124|   194k|        if (window_bits > max_window_bits) {
  ------------------
  |  Branch (1124:13): [True: 0, False: 194k]
  ------------------
 1125|      0|            window_bits = max_window_bits;
 1126|      0|        }
 1127|   194k|    }
 1128|   194k|#endif
 1129|       |
 1130|   194k|    odd_ints = 1 << (window_bits - 1);
 1131|   194k|    i = bits_in_exponent % window_bits;
 1132|   194k|    if (i != 0) {
  ------------------
  |  Branch (1132:9): [True: 92.4k, False: 102k]
  ------------------
 1133|  92.4k|        bits_in_exponent += window_bits - i;
 1134|  92.4k|    }
 1135|       |
 1136|       |#ifdef MP_USING_MONT_MULF
 1137|       |    if (mp_using_mont_mulf) {
 1138|       |        MP_CHECKOK(s_mp_pad(&montBase, nLen));
 1139|       |        res = mp_exptmod_f(&montBase, exponent, modulus, result, &mmm, nLen,
 1140|       |                           bits_in_exponent, window_bits, odd_ints);
 1141|       |    } else
 1142|       |#endif
 1143|   194k|#ifdef MP_USING_CACHE_SAFE_MOD_EXP
 1144|   194k|        if (mp_using_cache_safe_exp) {
  ------------------
  |  Branch (1144:13): [True: 194k, False: 0]
  ------------------
 1145|   194k|        res = mp_exptmod_safe_i(&montBase, exponent, modulus, result, &mmm, nLen,
 1146|   194k|                                bits_in_exponent, window_bits, 1 << window_bits);
 1147|   194k|    } else
 1148|      0|#endif
 1149|      0|        res = mp_exptmod_i(&montBase, exponent, modulus, result, &mmm, nLen,
 1150|      0|                           bits_in_exponent, window_bits, odd_ints);
 1151|       |
 1152|   194k|CLEANUP:
 1153|   194k|    mp_clear(&montBase);
 1154|   194k|    mp_clear(&goodBase);
 1155|       |    /* Don't mp_clear mmm.N because it is merely a copy of modulus.
 1156|       |    ** Just zap it.
 1157|       |    */
 1158|   194k|    memset(&mmm, 0, sizeof mmm);
 1159|   194k|    return res;
 1160|   194k|}

HASH_GetRawHashObject:
  238|  1.17M|{
  239|  1.17M|    if (hashType <= HASH_AlgNULL || hashType >= HASH_AlgTOTAL) {
  ------------------
  |  Branch (239:9): [True: 0, False: 1.17M]
  |  Branch (239:37): [True: 0, False: 1.17M]
  ------------------
  240|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  241|      0|        return NULL;
  242|      0|    }
  243|  1.17M|    return &SECRawHashObjects[hashType];
  244|  1.17M|}
rawhash.c:RawHash_MD5_NewContext:
   17|  31.7k|    {                                                                                    \
   18|  31.7k|        ctxtype *ctx = mmm##_NewContext();                                               \
   19|  31.7k|        return ctx;                                                                      \
   20|  31.7k|    }                                                                                    \
rawhash.c:RawHash_MD5_DestroyContext:
   42|  31.7k|    {                                                                                    \
   43|  31.7k|        ctxtype *ctx = vctx;                                                             \
   44|  31.7k|        mmm##_DestroyContext(ctx, freeit);                                               \
   45|  31.7k|    }
rawhash.c:RawHash_MD5_Begin:
   23|   350k|    {                                                                                    \
   24|   350k|        ctxtype *ctx = vctx;                                                             \
   25|   350k|        mmm##_Begin(ctx);                                                                \
   26|   350k|    }                                                                                    \
rawhash.c:RawHash_MD5_Update:
   29|   853k|    {                                                                                    \
   30|   853k|        ctxtype *ctx = vctx;                                                             \
   31|   853k|        mmm##_Update(ctx, input, len);                                                   \
   32|   853k|    }                                                                                    \
rawhash.c:RawHash_MD5_End:
   36|   345k|    {                                                                                    \
   37|   345k|        ctxtype *ctx = vctx;                                                             \
   38|   345k|        mmm##_End(ctx, digest, len, maxLen);                                             \
   39|   345k|    }                                                                                    \
rawhash.c:RawHash_SHA1_NewContext:
   17|  78.6k|    {                                                                                    \
   18|  78.6k|        ctxtype *ctx = mmm##_NewContext();                                               \
   19|  78.6k|        return ctx;                                                                      \
   20|  78.6k|    }                                                                                    \
rawhash.c:RawHash_SHA1_DestroyContext:
   42|  78.6k|    {                                                                                    \
   43|  78.6k|        ctxtype *ctx = vctx;                                                             \
   44|  78.6k|        mmm##_DestroyContext(ctx, freeit);                                               \
   45|  78.6k|    }
rawhash.c:RawHash_SHA1_Begin:
   23|   372k|    {                                                                                    \
   24|   372k|        ctxtype *ctx = vctx;                                                             \
   25|   372k|        mmm##_Begin(ctx);                                                                \
   26|   372k|    }                                                                                    \
rawhash.c:RawHash_SHA1_Update:
   29|   837k|    {                                                                                    \
   30|   837k|        ctxtype *ctx = vctx;                                                             \
   31|   837k|        mmm##_Update(ctx, input, len);                                                   \
   32|   837k|    }                                                                                    \
rawhash.c:RawHash_SHA1_End:
   36|   320k|    {                                                                                    \
   37|   320k|        ctxtype *ctx = vctx;                                                             \
   38|   320k|        mmm##_End(ctx, digest, len, maxLen);                                             \
   39|   320k|    }                                                                                    \
rawhash.c:RawHash_SHA256_NewContext:
   17|   145k|    {                                                                                    \
   18|   145k|        ctxtype *ctx = mmm##_NewContext();                                               \
   19|   145k|        return ctx;                                                                      \
   20|   145k|    }                                                                                    \
rawhash.c:RawHash_SHA256_DestroyContext:
   42|   145k|    {                                                                                    \
   43|   145k|        ctxtype *ctx = vctx;                                                             \
   44|   145k|        mmm##_DestroyContext(ctx, freeit);                                               \
   45|   145k|    }
rawhash.c:RawHash_SHA256_Begin:
   23|  1.16M|    {                                                                                    \
   24|  1.16M|        ctxtype *ctx = vctx;                                                             \
   25|  1.16M|        mmm##_Begin(ctx);                                                                \
   26|  1.16M|    }                                                                                    \
rawhash.c:RawHash_SHA256_Update:
   29|  2.83M|    {                                                                                    \
   30|  2.83M|        ctxtype *ctx = vctx;                                                             \
   31|  2.83M|        mmm##_Update(ctx, input, len);                                                   \
   32|  2.83M|    }                                                                                    \
rawhash.c:RawHash_SHA256_End:
   36|  1.16M|    {                                                                                    \
   37|  1.16M|        ctxtype *ctx = vctx;                                                             \
   38|  1.16M|        mmm##_End(ctx, digest, len, maxLen);                                             \
   39|  1.16M|    }                                                                                    \
rawhash.c:RawHash_SHA384_NewContext:
   17|   909k|    {                                                                                    \
   18|   909k|        ctxtype *ctx = mmm##_NewContext();                                               \
   19|   909k|        return ctx;                                                                      \
   20|   909k|    }                                                                                    \
rawhash.c:RawHash_SHA384_DestroyContext:
   42|   909k|    {                                                                                    \
   43|   909k|        ctxtype *ctx = vctx;                                                             \
   44|   909k|        mmm##_DestroyContext(ctx, freeit);                                               \
   45|   909k|    }
rawhash.c:RawHash_SHA384_Begin:
   23|  2.27M|    {                                                                                    \
   24|  2.27M|        ctxtype *ctx = vctx;                                                             \
   25|  2.27M|        mmm##_Begin(ctx);                                                                \
   26|  2.27M|    }                                                                                    \
rawhash.c:RawHash_SHA384_Update:
   29|  5.61M|    {                                                                                    \
   30|  5.61M|        ctxtype *ctx = vctx;                                                             \
   31|  5.61M|        mmm##_Update(ctx, input, len);                                                   \
   32|  5.61M|    }                                                                                    \
rawhash.c:RawHash_SHA384_End:
   36|  2.27M|    {                                                                                    \
   37|  2.27M|        ctxtype *ctx = vctx;                                                             \
   38|  2.27M|        mmm##_End(ctx, digest, len, maxLen);                                             \
   39|  2.27M|    }                                                                                    \
rawhash.c:RawHash_SHA512_NewContext:
   17|  7.05k|    {                                                                                    \
   18|  7.05k|        ctxtype *ctx = mmm##_NewContext();                                               \
   19|  7.05k|        return ctx;                                                                      \
   20|  7.05k|    }                                                                                    \
rawhash.c:RawHash_SHA512_DestroyContext:
   42|  7.05k|    {                                                                                    \
   43|  7.05k|        ctxtype *ctx = vctx;                                                             \
   44|  7.05k|        mmm##_DestroyContext(ctx, freeit);                                               \
   45|  7.05k|    }
rawhash.c:RawHash_SHA512_Begin:
   23|  14.1k|    {                                                                                    \
   24|  14.1k|        ctxtype *ctx = vctx;                                                             \
   25|  14.1k|        mmm##_Begin(ctx);                                                                \
   26|  14.1k|    }                                                                                    \
rawhash.c:RawHash_SHA512_Update:
   29|  31.7k|    {                                                                                    \
   30|  31.7k|        ctxtype *ctx = vctx;                                                             \
   31|  31.7k|        mmm##_Update(ctx, input, len);                                                   \
   32|  31.7k|    }                                                                                    \
rawhash.c:RawHash_SHA512_End:
   36|  14.1k|    {                                                                                    \
   37|  14.1k|        ctxtype *ctx = vctx;                                                             \
   38|  14.1k|        mmm##_End(ctx, digest, len, maxLen);                                             \
   39|  14.1k|    }                                                                                    \

AES_AllocateContext:
 1009|   343k|{
 1010|   343k|    return PORT_ZNewAligned(AESContext, 16, mem);
  ------------------
  |  |  150|   343k|    (type *)PORT_ZAllocAlignedOffset(sizeof(type), alignment, offsetof(type, mem))
  |  |  ------------------
  |  |  |  |   74|   343k|#define PORT_ZAllocAlignedOffset PORT_ZAllocAlignedOffset_Util
  |  |  ------------------
  ------------------
 1011|   343k|}
AES_InitContext:
 1116|   343k|{
 1117|   343k|    int basemode = mode;
 1118|   343k|    PRBool baseencrypt = encrypt;
 1119|   343k|    SECStatus rv;
 1120|       |
 1121|   343k|    if (blocksize != AES_BLOCK_SIZE) {
  ------------------
  |  |  130|   343k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  |  Branch (1121:9): [True: 0, False: 343k]
  ------------------
 1122|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1123|      0|        return SECFailure;
 1124|      0|    }
 1125|       |
 1126|   343k|    switch (mode) {
  ------------------
  |  Branch (1126:13): [True: 16.4k, False: 326k]
  ------------------
 1127|      0|        case NSS_AES_CTS:
  ------------------
  |  |   37|      0|#define NSS_AES_CTS 2
  ------------------
  |  Branch (1127:9): [True: 0, False: 343k]
  ------------------
 1128|      0|            basemode = NSS_AES_CBC;
  ------------------
  |  |   36|      0|#define NSS_AES_CBC 1
  ------------------
 1129|      0|            break;
 1130|   326k|        case NSS_AES_GCM:
  ------------------
  |  |   39|   326k|#define NSS_AES_GCM 4
  ------------------
  |  Branch (1130:9): [True: 326k, False: 16.4k]
  ------------------
 1131|   326k|        case NSS_AES_CTR:
  ------------------
  |  |   38|   326k|#define NSS_AES_CTR 3
  ------------------
  |  Branch (1131:9): [True: 0, False: 343k]
  ------------------
 1132|   326k|            basemode = NSS_AES;
  ------------------
  |  |   35|   326k|#define NSS_AES 0
  ------------------
 1133|   326k|            baseencrypt = PR_TRUE;
  ------------------
  |  |  437|   326k|#define PR_TRUE 1
  ------------------
 1134|   326k|            break;
 1135|   343k|    }
 1136|       |    /* Make sure enough is initialized so we can safely call Destroy. */
 1137|   343k|    cx->worker_cx = NULL;
 1138|   343k|    cx->destroy = NULL;
 1139|   343k|    cx->mode = mode;
 1140|   343k|    rv = aes_InitContext(cx, key, keysize, iv, basemode, baseencrypt);
 1141|   343k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1141:9): [True: 0, False: 343k]
  ------------------
 1142|      0|        AES_DestroyContext(cx, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1143|      0|        return rv;
 1144|      0|    }
 1145|       |
 1146|       |    /* finally, set up any mode specific contexts */
 1147|   343k|    cx->worker_aead = 0;
 1148|   343k|    switch (mode) {
 1149|      0|        case NSS_AES_CTS:
  ------------------
  |  |   37|      0|#define NSS_AES_CTS 2
  ------------------
  |  Branch (1149:9): [True: 0, False: 343k]
  ------------------
 1150|      0|            cx->worker_cx = CTS_CreateContext(cx, cx->worker, iv);
 1151|      0|            cx->worker = encrypt ? freeblCipher_CTS_EncryptUpdate : freeblCipher_CTS_DecryptUpdate;
  ------------------
  |  Branch (1151:26): [True: 0, False: 0]
  ------------------
 1152|      0|            cx->destroy = freeblDestroy_CTS_DestroyContext;
 1153|      0|            cx->isBlock = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1154|      0|            break;
 1155|   326k|        case NSS_AES_GCM:
  ------------------
  |  |   39|   326k|#define NSS_AES_GCM 4
  ------------------
  |  Branch (1155:9): [True: 326k, False: 16.4k]
  ------------------
 1156|       |#if defined(INTEL_GCM) && defined(USE_HW_AES)
 1157|       |            if (aesni_support() && (keysize % 8) == 0 && avx_support() &&
 1158|       |                clmul_support()) {
 1159|       |                cx->worker_cx = intel_AES_GCM_CreateContext(cx, cx->worker, iv);
 1160|       |                cx->worker = encrypt ? freeblCipher_intel_AES_GCM_EncryptUpdate
 1161|       |                                     : freeblCipher_intel_AES_GCM_DecryptUpdate;
 1162|       |                cx->worker_aead = encrypt ? freeblAead_intel_AES_GCM_EncryptAEAD
 1163|       |                                          : freeblAead_intel_AES_GCM_DecryptAEAD;
 1164|       |                cx->destroy = freeblDestroy_intel_AES_GCM_DestroyContext;
 1165|       |                cx->isBlock = PR_FALSE;
 1166|       |            } else
 1167|       |#elif defined(USE_PPC_CRYPTO) && defined(PPC_GCM)
 1168|       |            if (ppc_crypto_support() && (keysize % 8) == 0) {
 1169|       |                cx->worker_cx = ppc_AES_GCM_CreateContext(cx, cx->worker, iv);
 1170|       |                cx->worker = encrypt ? freeblCipher_ppc_AES_GCM_EncryptUpdate
 1171|       |                                     : freeblCipher_ppc_AES_GCM_DecryptUpdate;
 1172|       |                cx->worker_aead = encrypt ? freeblAead_ppc_AES_GCM_EncryptAEAD
 1173|       |                                          : freeblAead_ppc_AES_GCM_DecryptAEAD;
 1174|       |                cx->destroy = freeblDestroy_ppc_AES_GCM_DestroyContext;
 1175|       |                cx->isBlock = PR_FALSE;
 1176|       |            } else
 1177|       |#endif
 1178|   326k|            {
 1179|   326k|                cx->worker_cx = GCM_CreateContext(cx, cx->worker, iv);
 1180|   326k|                cx->worker = encrypt ? freeblCipher_GCM_EncryptUpdate
  ------------------
  |  Branch (1180:30): [True: 159k, False: 167k]
  ------------------
 1181|   326k|                                     : freeblCipher_GCM_DecryptUpdate;
 1182|   326k|                cx->worker_aead = encrypt ? freeblAead_GCM_EncryptAEAD
  ------------------
  |  Branch (1182:35): [True: 159k, False: 167k]
  ------------------
 1183|   326k|                                          : freeblAead_GCM_DecryptAEAD;
 1184|       |
 1185|   326k|                cx->destroy = freeblDestroy_GCM_DestroyContext;
 1186|   326k|                cx->isBlock = PR_FALSE;
  ------------------
  |  |  438|   326k|#define PR_FALSE 0
  ------------------
 1187|   326k|            }
 1188|   326k|            break;
 1189|      0|        case NSS_AES_CTR:
  ------------------
  |  |   38|      0|#define NSS_AES_CTR 3
  ------------------
  |  Branch (1189:9): [True: 0, False: 343k]
  ------------------
 1190|      0|            cx->worker_cx = CTR_CreateContext(cx, cx->worker, iv);
 1191|       |#if defined(USE_HW_AES) && defined(_MSC_VER) && defined(NSS_X86_OR_X64)
 1192|       |            if (aesni_support() && (keysize % 8) == 0) {
 1193|       |                cx->worker = freeblCipher_CTR_Update_HW_AES;
 1194|       |            } else
 1195|       |#endif
 1196|      0|            {
 1197|      0|                cx->worker = freeblCipher_CTR_Update;
 1198|      0|            }
 1199|      0|            cx->destroy = freeblDestroy_CTR_DestroyContext;
 1200|      0|            cx->isBlock = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1201|      0|            break;
 1202|  16.4k|        default:
  ------------------
  |  Branch (1202:9): [True: 16.4k, False: 326k]
  ------------------
 1203|       |            /* everything has already been set up by aes_InitContext, just
 1204|       |             * return */
 1205|  16.4k|            return SECSuccess;
 1206|   343k|    }
 1207|       |    /* check to see if we succeeded in getting the worker context */
 1208|   326k|    if (cx->worker_cx == NULL) {
  ------------------
  |  Branch (1208:9): [True: 0, False: 326k]
  ------------------
 1209|       |        /* no, just destroy the existing context */
 1210|      0|        cx->destroy = NULL; /* paranoia, though you can see a dozen lines */
 1211|       |                            /* below that this isn't necessary */
 1212|      0|        AES_DestroyContext(cx, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1213|      0|        return SECFailure;
 1214|      0|    }
 1215|   326k|    return SECSuccess;
 1216|   326k|}
AES_CreateContext:
 1226|   343k|{
 1227|   343k|    AESContext *cx = AES_AllocateContext();
 1228|   343k|    if (cx) {
  ------------------
  |  Branch (1228:9): [True: 343k, False: 0]
  ------------------
 1229|   343k|        SECStatus rv = AES_InitContext(cx, key, keysize, iv, mode, encrypt,
 1230|   343k|                                       blocksize);
 1231|   343k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1231:13): [True: 0, False: 343k]
  ------------------
 1232|      0|            AES_DestroyContext(cx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1233|      0|            cx = NULL;
 1234|      0|        }
 1235|   343k|    }
 1236|   343k|    return cx;
 1237|   343k|}
AES_DestroyContext:
 1247|   343k|{
 1248|   343k|    void *mem = cx->mem;
 1249|   343k|    if (cx->worker_cx && cx->destroy) {
  ------------------
  |  Branch (1249:9): [True: 343k, False: 0]
  |  Branch (1249:26): [True: 326k, False: 16.4k]
  ------------------
 1250|   326k|        (*cx->destroy)(cx->worker_cx, PR_TRUE);
  ------------------
  |  |  437|   326k|#define PR_TRUE 1
  ------------------
 1251|   326k|        cx->worker_cx = NULL;
 1252|   326k|        cx->destroy = NULL;
 1253|   326k|    }
 1254|   343k|    PORT_SafeZero(cx, sizeof(AESContext));
 1255|   343k|    if (freeit) {
  ------------------
  |  Branch (1255:9): [True: 343k, False: 0]
  ------------------
 1256|   343k|        PORT_Free(mem);
  ------------------
  |  |   60|   343k|#define PORT_Free PORT_Free_Util
  ------------------
 1257|   343k|    } else {
 1258|       |        /* if we are not freeing the context, restore mem, We may get called
 1259|       |         * again to actually free the context */
 1260|      0|        cx->mem = mem;
 1261|      0|    }
 1262|   343k|}
rijndael.c:aes_InitContext:
 1021|   343k|{
 1022|   343k|    unsigned int Nk;
 1023|   343k|    PRBool use_hw_aes;
 1024|       |    /* According to AES, block lengths are 128 and key lengths are 128, 192, or
 1025|       |     * 256 bits. We support other key sizes as well [128, 256] as long as the
 1026|       |     * length in bytes is divisible by 4.
 1027|       |     */
 1028|       |
 1029|   343k|    if (key == NULL ||
  ------------------
  |  Branch (1029:9): [True: 0, False: 343k]
  ------------------
 1030|   343k|        keysize < AES_BLOCK_SIZE ||
  ------------------
  |  |  130|   686k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  |  Branch (1030:9): [True: 0, False: 343k]
  ------------------
 1031|   343k|        keysize > 32 ||
  ------------------
  |  Branch (1031:9): [True: 0, False: 343k]
  ------------------
 1032|   343k|        keysize % 4 != 0) {
  ------------------
  |  Branch (1032:9): [True: 0, False: 343k]
  ------------------
 1033|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1034|      0|        return SECFailure;
 1035|      0|    }
 1036|   343k|    if (mode != NSS_AES && mode != NSS_AES_CBC) {
  ------------------
  |  |   35|   686k|#define NSS_AES 0
  ------------------
                  if (mode != NSS_AES && mode != NSS_AES_CBC) {
  ------------------
  |  |   36|  16.4k|#define NSS_AES_CBC 1
  ------------------
  |  Branch (1036:9): [True: 16.4k, False: 326k]
  |  Branch (1036:28): [True: 0, False: 16.4k]
  ------------------
 1037|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1038|      0|        return SECFailure;
 1039|      0|    }
 1040|   343k|    if (mode == NSS_AES_CBC && iv == NULL) {
  ------------------
  |  |   36|   686k|#define NSS_AES_CBC 1
  ------------------
  |  Branch (1040:9): [True: 16.4k, False: 326k]
  |  Branch (1040:32): [True: 0, False: 16.4k]
  ------------------
 1041|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1042|      0|        return SECFailure;
 1043|      0|    }
 1044|   343k|    if (!cx) {
  ------------------
  |  Branch (1044:9): [True: 0, False: 343k]
  ------------------
 1045|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1046|      0|        return SECFailure;
 1047|      0|    }
 1048|   343k|#if defined(NSS_X86_OR_X64) || defined(USE_HW_AES)
 1049|   343k|    use_hw_aes = (aesni_support() || arm_aes_support()) && (keysize % 8) == 0;
  ------------------
  |  Branch (1049:19): [True: 343k, False: 0]
  |  Branch (1049:38): [True: 0, False: 0]
  |  Branch (1049:60): [True: 343k, False: 0]
  ------------------
 1050|       |#else
 1051|       |    use_hw_aes = PR_FALSE;
 1052|       |#endif
 1053|       |    /* Nb = (block size in bits) / 32 */
 1054|   343k|    cx->Nb = AES_BLOCK_SIZE / 4;
  ------------------
  |  |  130|   343k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
 1055|       |    /* Nk = (key size in bits) / 32 */
 1056|   343k|    Nk = keysize / 4;
 1057|       |    /* Obtain number of rounds from "table" */
 1058|   343k|    cx->Nr = RIJNDAEL_NUM_ROUNDS(Nk, cx->Nb);
  ------------------
  |  |   36|   343k|    (PR_MAX(Nk, Nb) + 6)
  |  |  ------------------
  |  |  |  |  159|   343k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (159:26): [True: 320k, False: 22.7k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1059|       |    /* copy in the iv, if neccessary */
 1060|   343k|    if (mode == NSS_AES_CBC) {
  ------------------
  |  |   36|   343k|#define NSS_AES_CBC 1
  ------------------
  |  Branch (1060:9): [True: 16.4k, False: 326k]
  ------------------
 1061|  16.4k|        memcpy(cx->iv, iv, AES_BLOCK_SIZE);
  ------------------
  |  |  130|  16.4k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
 1062|       |#ifdef USE_HW_AES
 1063|       |        if (use_hw_aes) {
 1064|       |            cx->worker = freeblCipher_native_aes_cbc_worker(encrypt, keysize);
 1065|       |        } else
 1066|       |#endif
 1067|  16.4k|        {
 1068|  16.4k|            cx->worker = encrypt ? freeblCipher_rijndael_encryptCBC : freeblCipher_rijndael_decryptCBC;
  ------------------
  |  Branch (1068:26): [True: 8.20k, False: 8.20k]
  ------------------
 1069|  16.4k|        }
 1070|   326k|    } else {
 1071|       |#ifdef USE_HW_AES
 1072|       |        if (use_hw_aes) {
 1073|       |            cx->worker = freeblCipher_native_aes_ecb_worker(encrypt, keysize);
 1074|       |        } else
 1075|       |#endif
 1076|   326k|        {
 1077|   326k|            cx->worker = encrypt ? freeblCipher_rijndael_encryptECB : freeblCipher_rijndael_decryptECB;
  ------------------
  |  Branch (1077:26): [True: 326k, False: 0]
  ------------------
 1078|   326k|        }
 1079|   326k|    }
 1080|   343k|    PORT_Assert((cx->Nb * (cx->Nr + 1)) <= RIJNDAEL_MAX_EXP_KEY_SIZE);
  ------------------
  |  |  120|   343k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   343k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 343k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1081|   343k|    if ((cx->Nb * (cx->Nr + 1)) > RIJNDAEL_MAX_EXP_KEY_SIZE) {
  ------------------
  |  |   43|   343k|#define RIJNDAEL_MAX_EXP_KEY_SIZE (4 * 15)
  ------------------
  |  Branch (1081:9): [True: 0, False: 343k]
  ------------------
 1082|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1083|      0|        return SECFailure;
 1084|      0|    }
 1085|       |#ifdef USE_HW_AES
 1086|       |    if (use_hw_aes) {
 1087|       |        native_aes_init(encrypt, keysize);
 1088|       |    } else
 1089|       |#endif
 1090|   343k|    {
 1091|       |        /* Generate expanded key */
 1092|   343k|        if (encrypt) {
  ------------------
  |  Branch (1092:13): [True: 334k, False: 8.20k]
  ------------------
 1093|   334k|            if (use_hw_aes && (cx->mode == NSS_AES_GCM || cx->mode == NSS_AES ||
  ------------------
  |  |   39|   669k|#define NSS_AES_GCM 4
  ------------------
                          if (use_hw_aes && (cx->mode == NSS_AES_GCM || cx->mode == NSS_AES ||
  ------------------
  |  |   35|   343k|#define NSS_AES 0
  ------------------
  |  Branch (1093:17): [True: 334k, False: 0]
  |  Branch (1093:32): [True: 326k, False: 8.20k]
  |  Branch (1093:59): [True: 0, False: 8.20k]
  ------------------
 1094|   334k|                               cx->mode == NSS_AES_CTR)) {
  ------------------
  |  |   38|  8.20k|#define NSS_AES_CTR 3
  ------------------
  |  Branch (1094:32): [True: 0, False: 8.20k]
  ------------------
 1095|   326k|                PORT_Assert(keysize == 16 || keysize == 24 || keysize == 32);
  ------------------
  |  |  120|   326k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.28M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 11.9k, False: 314k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 314k]
  |  |  |  |  |  Branch (208:7): [True: 314k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1096|       |                /* Prepare hardware key for normal AES parameters. */
 1097|   326k|                rijndael_native_key_expansion(cx, key, Nk);
 1098|   326k|            } else {
 1099|  8.20k|                rijndael_key_expansion(cx, key, Nk);
 1100|  8.20k|            }
 1101|   334k|        } else {
 1102|  8.20k|            rijndael_invkey_expansion(cx, key, Nk);
 1103|  8.20k|        }
 1104|   343k|        BLAPI_CLEAR_STACK(256)
 1105|   343k|    }
 1106|   343k|    cx->worker_cx = cx;
 1107|   343k|    cx->destroy = NULL;
 1108|   343k|    cx->isBlock = PR_TRUE;
  ------------------
  |  |  437|   343k|#define PR_TRUE 1
  ------------------
 1109|   343k|    return SECSuccess;
 1110|   343k|}
rijndael.c:freeblCipher_rijndael_encryptECB:
  865|   326k|    {                                                                                       \
  866|   326k|        ctxtype *ctx = vctx;                                                                \
  867|   326k|        return mmm(ctx, output, outputLen, maxOutputLen, input, inputLen, blocksize);       \
  868|   326k|    }
rijndael.c:rijndael_encryptECB:
  748|   326k|{
  749|   326k|    PORT_Assert(blocksize == AES_BLOCK_SIZE);
  ------------------
  |  |  120|   326k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   326k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 326k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  750|   326k|    PRBool aesni = aesni_support();
  751|   653k|    while (inputLen > 0) {
  ------------------
  |  Branch (751:12): [True: 326k, False: 326k]
  ------------------
  752|   326k|        if (aesni) {
  ------------------
  |  Branch (752:13): [True: 326k, False: 0]
  ------------------
  753|   326k|            rijndael_native_encryptBlock(cx, output, input);
  754|   326k|        } else {
  755|      0|            rijndael_encryptBlock128(cx, output, input);
  756|      0|        }
  757|   326k|        output += AES_BLOCK_SIZE;
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  758|   326k|        input += AES_BLOCK_SIZE;
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  759|   326k|        inputLen -= AES_BLOCK_SIZE;
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  760|   326k|    }
  761|   326k|    return SECSuccess;
  762|   326k|}
rijndael.c:rijndael_key_expansion:
  386|  16.4k|{
  387|  16.4k|    unsigned int i;
  388|  16.4k|    PRUint32 *W;
  389|  16.4k|    PRUint32 *pW;
  390|  16.4k|    PRUint32 tmp;
  391|  16.4k|    unsigned int round_key_words = cx->Nb * (cx->Nr + 1);
  392|  16.4k|    if (Nk == 7) {
  ------------------
  |  Branch (392:9): [True: 0, False: 16.4k]
  ------------------
  393|      0|        rijndael_key_expansion7(cx, key, Nk);
  394|      0|        return;
  395|      0|    }
  396|  16.4k|    W = cx->k.expandedKey;
  397|       |    /* The first Nk words contain the input cipher key */
  398|  16.4k|    memcpy(W, key, Nk * 4);
  399|  16.4k|    i = Nk;
  400|  16.4k|    pW = W + i - 1;
  401|       |    /* Loop over all sets of Nk words, except the last */
  402|   147k|    while (i < round_key_words - Nk) {
  ------------------
  |  Branch (402:12): [True: 130k, False: 16.4k]
  ------------------
  403|   130k|        tmp = *pW++;
  404|   130k|        tmp = SUBBYTE(ROTBYTE(tmp)) ^ Rcon[i / Nk - 1];
  ------------------
  |  |  334|   130k|    ((((PRUint32)SBOX((w >> 24) & 0xff)) << 24) | \
  |  |  ------------------
  |  |  |  |  135|   130k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  335|   130k|     (((PRUint32)SBOX((w >> 16) & 0xff)) << 16) | \
  |  |  ------------------
  |  |  |  |  135|   130k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  336|   130k|     (((PRUint32)SBOX((w >> 8) & 0xff)) << 8) |   \
  |  |  ------------------
  |  |  |  |  135|   130k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  337|   130k|     (((PRUint32)SBOX((w)&0xff))))
  |  |  ------------------
  |  |  |  |  135|   130k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  ------------------
  405|   130k|        *pW = W[i++ - Nk] ^ tmp;
  406|   130k|        tmp = *pW++;
  407|   130k|        *pW = W[i++ - Nk] ^ tmp;
  408|   130k|        tmp = *pW++;
  409|   130k|        *pW = W[i++ - Nk] ^ tmp;
  410|   130k|        tmp = *pW++;
  411|   130k|        *pW = W[i++ - Nk] ^ tmp;
  412|   130k|        if (Nk == 4)
  ------------------
  |  Branch (412:13): [True: 97.4k, False: 33.4k]
  ------------------
  413|  97.4k|            continue;
  414|  33.4k|        switch (Nk) {
  ------------------
  |  Branch (414:17): [True: 0, False: 33.4k]
  ------------------
  415|  33.4k|            case 8:
  ------------------
  |  Branch (415:13): [True: 33.4k, False: 0]
  ------------------
  416|  33.4k|                tmp = *pW++;
  417|  33.4k|                tmp = SUBBYTE(tmp);
  ------------------
  |  |  334|  33.4k|    ((((PRUint32)SBOX((w >> 24) & 0xff)) << 24) | \
  |  |  ------------------
  |  |  |  |  135|  33.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  335|  33.4k|     (((PRUint32)SBOX((w >> 16) & 0xff)) << 16) | \
  |  |  ------------------
  |  |  |  |  135|  33.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  336|  33.4k|     (((PRUint32)SBOX((w >> 8) & 0xff)) << 8) |   \
  |  |  ------------------
  |  |  |  |  135|  33.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  337|  33.4k|     (((PRUint32)SBOX((w)&0xff))))
  |  |  ------------------
  |  |  |  |  135|  33.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  ------------------
  418|  33.4k|                *pW = W[i++ - Nk] ^ tmp;
  419|  33.4k|            case 7:
  ------------------
  |  Branch (419:13): [True: 0, False: 33.4k]
  ------------------
  420|  33.4k|                tmp = *pW++;
  421|  33.4k|                *pW = W[i++ - Nk] ^ tmp;
  422|  33.4k|            case 6:
  ------------------
  |  Branch (422:13): [True: 0, False: 33.4k]
  ------------------
  423|  33.4k|                tmp = *pW++;
  424|  33.4k|                *pW = W[i++ - Nk] ^ tmp;
  425|  33.4k|            case 5:
  ------------------
  |  Branch (425:13): [True: 0, False: 33.4k]
  ------------------
  426|  33.4k|                tmp = *pW++;
  427|  33.4k|                *pW = W[i++ - Nk] ^ tmp;
  428|  33.4k|        }
  429|  33.4k|    }
  430|       |    /* Generate the last word */
  431|  16.4k|    tmp = *pW++;
  432|  16.4k|    tmp = SUBBYTE(ROTBYTE(tmp)) ^ Rcon[i / Nk - 1];
  ------------------
  |  |  334|  16.4k|    ((((PRUint32)SBOX((w >> 24) & 0xff)) << 24) | \
  |  |  ------------------
  |  |  |  |  135|  16.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  335|  16.4k|     (((PRUint32)SBOX((w >> 16) & 0xff)) << 16) | \
  |  |  ------------------
  |  |  |  |  135|  16.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  336|  16.4k|     (((PRUint32)SBOX((w >> 8) & 0xff)) << 8) |   \
  |  |  ------------------
  |  |  |  |  135|  16.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  337|  16.4k|     (((PRUint32)SBOX((w)&0xff))))
  |  |  ------------------
  |  |  |  |  135|  16.4k|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  ------------------
  433|  16.4k|    *pW = W[i++ - Nk] ^ tmp;
  434|       |    /* There may be overflow here, if Nk % (Nb * (Nr + 1)) > 0.  However,
  435|       |     * since the above loop generated all but the last Nk key words, there
  436|       |     * is no more need for the SubByte transformation.
  437|       |     */
  438|  16.4k|    if (Nk < 8) {
  ------------------
  |  Branch (438:9): [True: 10.8k, False: 5.58k]
  ------------------
  439|  43.3k|        for (; i < round_key_words; ++i) {
  ------------------
  |  Branch (439:16): [True: 32.4k, False: 10.8k]
  ------------------
  440|  32.4k|            tmp = *pW++;
  441|  32.4k|            *pW = W[i - Nk] ^ tmp;
  442|  32.4k|        }
  443|  10.8k|    } else {
  444|       |        /* except in the case when Nk == 8.  Then one more SubByte may have
  445|       |         * to be performed, at i % Nk == 4.
  446|       |         */
  447|  22.3k|        for (; i < round_key_words; ++i) {
  ------------------
  |  Branch (447:16): [True: 16.7k, False: 5.58k]
  ------------------
  448|  16.7k|            tmp = *pW++;
  449|  16.7k|            if (i % Nk == 4)
  ------------------
  |  Branch (449:17): [True: 0, False: 16.7k]
  ------------------
  450|      0|                tmp = SUBBYTE(tmp);
  ------------------
  |  |  334|      0|    ((((PRUint32)SBOX((w >> 24) & 0xff)) << 24) | \
  |  |  ------------------
  |  |  |  |  135|      0|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  335|      0|     (((PRUint32)SBOX((w >> 16) & 0xff)) << 16) | \
  |  |  ------------------
  |  |  |  |  135|      0|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  336|      0|     (((PRUint32)SBOX((w >> 8) & 0xff)) << 8) |   \
  |  |  ------------------
  |  |  |  |  135|      0|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  |  |  337|      0|     (((PRUint32)SBOX((w)&0xff))))
  |  |  ------------------
  |  |  |  |  135|      0|#define SBOX(b) ((PRUint8)_T3[b])
  |  |  ------------------
  ------------------
  451|  16.7k|            *pW = W[i - Nk] ^ tmp;
  452|  16.7k|        }
  453|  5.58k|    }
  454|  16.4k|}
rijndael.c:rijndael_invkey_expansion:
  463|  8.20k|{
  464|  8.20k|    unsigned int r;
  465|  8.20k|    PRUint32 *roundkeyw;
  466|  8.20k|    PRUint8 *b;
  467|  8.20k|    int Nb = cx->Nb;
  468|       |    /* begins like usual key expansion ... */
  469|  8.20k|    rijndael_key_expansion(cx, key, Nk);
  470|       |    /* ... but has the additional step of InvMixColumn,
  471|       |     * excepting the first and last round keys.
  472|       |     */
  473|  8.20k|    roundkeyw = cx->k.expandedKey + cx->Nb;
  474|  93.2k|    for (r = 1; r < cx->Nr; ++r) {
  ------------------
  |  Branch (474:17): [True: 85.0k, False: 8.20k]
  ------------------
  475|       |        /* each key word, roundkeyw, represents a column in the key
  476|       |         * matrix.  Each column is multiplied by the InvMixColumn matrix.
  477|       |         *   [ 0E 0B 0D 09 ]   [ b0 ]
  478|       |         *   [ 09 0E 0B 0D ] * [ b1 ]
  479|       |         *   [ 0D 09 0E 0B ]   [ b2 ]
  480|       |         *   [ 0B 0D 09 0E ]   [ b3 ]
  481|       |         */
  482|  85.0k|        b = (PRUint8 *)roundkeyw;
  483|  85.0k|        *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  129|  85.0k|#define IMXC0(b) _IMXC0[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  130|  85.0k|#define IMXC1(b) _IMXC1[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|  85.0k|#define IMXC2(b) _IMXC2[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|  85.0k|#define IMXC3(b) _IMXC3[b]
  ------------------
  484|  85.0k|        b = (PRUint8 *)roundkeyw;
  485|  85.0k|        *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  129|  85.0k|#define IMXC0(b) _IMXC0[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  130|  85.0k|#define IMXC1(b) _IMXC1[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|  85.0k|#define IMXC2(b) _IMXC2[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|  85.0k|#define IMXC3(b) _IMXC3[b]
  ------------------
  486|  85.0k|        b = (PRUint8 *)roundkeyw;
  487|  85.0k|        *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  129|  85.0k|#define IMXC0(b) _IMXC0[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  130|  85.0k|#define IMXC1(b) _IMXC1[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|  85.0k|#define IMXC2(b) _IMXC2[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|  85.0k|#define IMXC3(b) _IMXC3[b]
  ------------------
  488|  85.0k|        b = (PRUint8 *)roundkeyw;
  489|  85.0k|        *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  129|  85.0k|#define IMXC0(b) _IMXC0[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  130|  85.0k|#define IMXC1(b) _IMXC1[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|  85.0k|#define IMXC2(b) _IMXC2[b]
  ------------------
                      *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^ IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|  85.0k|#define IMXC3(b) _IMXC3[b]
  ------------------
  490|  85.0k|        if (Nb <= 4)
  ------------------
  |  Branch (490:13): [True: 85.0k, False: 0]
  ------------------
  491|  85.0k|            continue;
  492|      0|        switch (Nb) {
  ------------------
  |  Branch (492:17): [True: 0, False: 0]
  ------------------
  493|      0|            case 8:
  ------------------
  |  Branch (493:13): [True: 0, False: 0]
  ------------------
  494|      0|                b = (PRUint8 *)roundkeyw;
  495|      0|                *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  129|      0|#define IMXC0(b) _IMXC0[b]
  ------------------
                              *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  130|      0|#define IMXC1(b) _IMXC1[b]
  ------------------
  496|      0|                               IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|      0|#define IMXC2(b) _IMXC2[b]
  ------------------
                                             IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|      0|#define IMXC3(b) _IMXC3[b]
  ------------------
  497|      0|            case 7:
  ------------------
  |  Branch (497:13): [True: 0, False: 0]
  ------------------
  498|      0|                b = (PRUint8 *)roundkeyw;
  499|      0|                *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  129|      0|#define IMXC0(b) _IMXC0[b]
  ------------------
                              *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  130|      0|#define IMXC1(b) _IMXC1[b]
  ------------------
  500|      0|                               IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|      0|#define IMXC2(b) _IMXC2[b]
  ------------------
                                             IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|      0|#define IMXC3(b) _IMXC3[b]
  ------------------
  501|      0|            case 6:
  ------------------
  |  Branch (501:13): [True: 0, False: 0]
  ------------------
  502|      0|                b = (PRUint8 *)roundkeyw;
  503|      0|                *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  129|      0|#define IMXC0(b) _IMXC0[b]
  ------------------
                              *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  130|      0|#define IMXC1(b) _IMXC1[b]
  ------------------
  504|      0|                               IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|      0|#define IMXC2(b) _IMXC2[b]
  ------------------
                                             IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|      0|#define IMXC3(b) _IMXC3[b]
  ------------------
  505|      0|            case 5:
  ------------------
  |  Branch (505:13): [True: 0, False: 0]
  ------------------
  506|      0|                b = (PRUint8 *)roundkeyw;
  507|      0|                *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  129|      0|#define IMXC0(b) _IMXC0[b]
  ------------------
                              *roundkeyw++ = IMXC0(b[0]) ^ IMXC1(b[1]) ^
  ------------------
  |  |  130|      0|#define IMXC1(b) _IMXC1[b]
  ------------------
  508|      0|                               IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  131|      0|#define IMXC2(b) _IMXC2[b]
  ------------------
                                             IMXC2(b[2]) ^ IMXC3(b[3]);
  ------------------
  |  |  132|      0|#define IMXC3(b) _IMXC3[b]
  ------------------
  509|      0|        }
  510|      0|    }
  511|  8.20k|}
rijndael.c:freeblDestroy_GCM_DestroyContext:
  983|   326k|    {                                                          \
  984|   326k|        ctxtype *ctx = vctx;                                   \
  985|   326k|        mmm(ctx, freeit);                                      \
  986|   326k|    }

RSA_PublicKeyOp:
  934|  2.94k|{
  935|  2.94k|    unsigned int modLen, expLen, offset;
  936|  2.94k|    mp_int n, e, m, c;
  937|  2.94k|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  938|  2.94k|    SECStatus rv = SECSuccess;
  939|  2.94k|    if (!key || !output || !input) {
  ------------------
  |  Branch (939:9): [True: 0, False: 2.94k]
  |  Branch (939:17): [True: 0, False: 2.94k]
  |  Branch (939:28): [True: 0, False: 2.94k]
  ------------------
  940|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  941|      0|        return SECFailure;
  942|      0|    }
  943|  2.94k|    MP_DIGITS(&n) = 0;
  ------------------
  |  |  152|  2.94k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  944|  2.94k|    MP_DIGITS(&e) = 0;
  ------------------
  |  |  152|  2.94k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  945|  2.94k|    MP_DIGITS(&m) = 0;
  ------------------
  |  |  152|  2.94k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  946|  2.94k|    MP_DIGITS(&c) = 0;
  ------------------
  |  |  152|  2.94k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
  947|  2.94k|    CHECK_MPI_OK(mp_init(&n));
  ------------------
  |  |   12|  2.94k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 2.94k]
  |  |  ------------------
  |  |   13|  2.94k|    goto cleanup
  ------------------
  948|  2.94k|    CHECK_MPI_OK(mp_init(&e));
  ------------------
  |  |   12|  2.94k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 2.94k]
  |  |  ------------------
  |  |   13|  2.94k|    goto cleanup
  ------------------
  949|  2.94k|    CHECK_MPI_OK(mp_init(&m));
  ------------------
  |  |   12|  2.94k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 2.94k]
  |  |  ------------------
  |  |   13|  2.94k|    goto cleanup
  ------------------
  950|  2.94k|    CHECK_MPI_OK(mp_init(&c));
  ------------------
  |  |   12|  2.94k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 2.94k]
  |  |  ------------------
  |  |   13|  2.94k|    goto cleanup
  ------------------
  951|  2.94k|    modLen = rsa_modulusLen(&key->modulus);
  952|  2.94k|    expLen = rsa_modulusLen(&key->publicExponent);
  953|       |
  954|  2.94k|    if (modLen == 0) {
  ------------------
  |  Branch (954:9): [True: 0, False: 2.94k]
  ------------------
  955|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  956|      0|        rv = SECFailure;
  957|      0|        goto cleanup;
  958|      0|    }
  959|       |
  960|       |    /* 1.  Obtain public key (n, e) */
  961|  2.94k|    if (BAD_RSA_KEY_SIZE(modLen, expLen)) {
  ------------------
  |  |   47|  2.94k|    ((expLen) > (modLen) || (modLen) > RSA_MAX_MODULUS_BITS / 8 || \
  |  |  ------------------
  |  |  |  |  152|  2.94k|#define RSA_MAX_MODULUS_BITS 16384
  |  |  ------------------
  |  |  |  Branch (47:6): [True: 0, False: 2.94k]
  |  |  |  Branch (47:29): [True: 0, False: 2.94k]
  |  |  ------------------
  |  |   48|  2.94k|     (expLen) > RSA_MAX_EXPONENT_BITS / 8)
  |  |  ------------------
  |  |  |  |  153|  2.94k|#define RSA_MAX_EXPONENT_BITS 64
  |  |  ------------------
  |  |  |  Branch (48:6): [True: 0, False: 2.94k]
  |  |  ------------------
  ------------------
  962|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  963|      0|        rv = SECFailure;
  964|      0|        goto cleanup;
  965|      0|    }
  966|  2.94k|    SECITEM_TO_MPINT(key->modulus, &n);
  ------------------
  |  |   19|  2.94k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  2.94k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 2.94k]
  |  |  |  |  ------------------
  |  |  |  |   13|  2.94k|    goto cleanup
  |  |  ------------------
  ------------------
  967|  2.94k|    SECITEM_TO_MPINT(key->publicExponent, &e);
  ------------------
  |  |   19|  2.94k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  2.94k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  2.94k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 2.94k]
  |  |  |  |  ------------------
  |  |  |  |   13|  2.94k|    goto cleanup
  |  |  ------------------
  ------------------
  968|  2.94k|    if (e.used > n.used) {
  ------------------
  |  Branch (968:9): [True: 0, False: 2.94k]
  ------------------
  969|       |        /* exponent should not be greater than modulus */
  970|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  971|      0|        rv = SECFailure;
  972|      0|        goto cleanup;
  973|      0|    }
  974|       |    /* 2. check input out of range (needs to be in range [0..n-1]) */
  975|  2.94k|    offset = (key->modulus.data[0] == 0) ? 1 : 0; /* may be leading 0 */
  ------------------
  |  Branch (975:14): [True: 0, False: 2.94k]
  ------------------
  976|  2.94k|    if (memcmp(input, key->modulus.data + offset, modLen) >= 0) {
  ------------------
  |  Branch (976:9): [True: 26, False: 2.91k]
  ------------------
  977|     26|        PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|     26|#define PORT_SetError PORT_SetError_Util
  ------------------
  978|     26|        rv = SECFailure;
  979|     26|        goto cleanup;
  980|     26|    }
  981|       |    /* 2 bis.  Represent message as integer in range [0..n-1] */
  982|  2.91k|    CHECK_MPI_OK(mp_read_unsigned_octets(&m, input, modLen));
  ------------------
  |  |   12|  2.91k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  2.91k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 2.91k]
  |  |  ------------------
  |  |   13|  2.91k|    goto cleanup
  ------------------
  983|       |/* 3.  Compute c = m**e mod n */
  984|       |#ifdef USE_MPI_EXPT_D
  985|       |    /* XXX see which is faster */
  986|       |    if (MP_USED(&e) == 1) {
  987|       |        CHECK_MPI_OK(mp_exptmod_d(&m, MP_DIGIT(&e, 0), &n, &c));
  988|       |    } else
  989|       |#endif
  990|  2.91k|        CHECK_MPI_OK(mp_exptmod(&m, &e, &n, &c));
  ------------------
  |  |   12|  2.91k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  2.91k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 2.91k]
  |  |  ------------------
  |  |   13|  2.91k|    goto cleanup
  ------------------
  991|       |    /* 4.  result c is ciphertext */
  992|  2.91k|    err = mp_to_fixlen_octets(&c, output, modLen);
  993|  2.91k|    if (err >= 0)
  ------------------
  |  Branch (993:9): [True: 2.91k, False: 0]
  ------------------
  994|  2.91k|        err = MP_OKAY;
  ------------------
  |  |   39|  2.91k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
  995|  2.94k|cleanup:
  996|  2.94k|    mp_clear(&n);
  997|  2.94k|    mp_clear(&e);
  998|  2.94k|    mp_clear(&m);
  999|  2.94k|    mp_clear(&c);
 1000|  2.94k|    if (err) {
  ------------------
  |  Branch (1000:9): [True: 0, False: 2.94k]
  ------------------
 1001|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1002|      0|        rv = SECFailure;
 1003|      0|    }
 1004|  2.94k|    return rv;
 1005|  2.94k|}
RSA_PrivateKeyOp:
 1548|    772|{
 1549|    772|    return rsa_PrivateKeyOp(key, output, input, PR_FALSE);
  ------------------
  |  |  438|    772|#define PR_FALSE 0
  ------------------
 1550|    772|}
RSA_PrivateKeyOpDoubleChecked:
 1556|  35.5k|{
 1557|  35.5k|    return rsa_PrivateKeyOp(key, output, input, PR_TRUE);
  ------------------
  |  |  437|  35.5k|#define PR_TRUE 1
  ------------------
 1558|  35.5k|}
RSA_PrivateKeyCheck:
 1562|      4|{
 1563|      4|    mp_int p, q, n, psub1, qsub1, e, d, d_p, d_q, qInv, res;
 1564|      4|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1565|      4|    SECStatus rv = SECSuccess;
 1566|      4|    MP_DIGITS(&p) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1567|      4|    MP_DIGITS(&q) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1568|      4|    MP_DIGITS(&n) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1569|      4|    MP_DIGITS(&psub1) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1570|      4|    MP_DIGITS(&qsub1) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1571|      4|    MP_DIGITS(&e) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1572|      4|    MP_DIGITS(&d) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1573|      4|    MP_DIGITS(&d_p) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1574|      4|    MP_DIGITS(&d_q) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1575|      4|    MP_DIGITS(&qInv) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1576|      4|    MP_DIGITS(&res) = 0;
  ------------------
  |  |  152|      4|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1577|      4|    CHECK_MPI_OK(mp_init(&p));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1578|      4|    CHECK_MPI_OK(mp_init(&q));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1579|      4|    CHECK_MPI_OK(mp_init(&n));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1580|      4|    CHECK_MPI_OK(mp_init(&psub1));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1581|      4|    CHECK_MPI_OK(mp_init(&qsub1));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1582|      4|    CHECK_MPI_OK(mp_init(&e));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1583|      4|    CHECK_MPI_OK(mp_init(&d));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1584|      4|    CHECK_MPI_OK(mp_init(&d_p));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1585|      4|    CHECK_MPI_OK(mp_init(&d_q));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1586|      4|    CHECK_MPI_OK(mp_init(&qInv));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1587|      4|    CHECK_MPI_OK(mp_init(&res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1588|       |
 1589|      4|    if (!key->modulus.data || !key->prime1.data || !key->prime2.data ||
  ------------------
  |  Branch (1589:9): [True: 0, False: 4]
  |  Branch (1589:31): [True: 0, False: 4]
  |  Branch (1589:52): [True: 0, False: 4]
  ------------------
 1590|      4|        !key->publicExponent.data || !key->privateExponent.data ||
  ------------------
  |  Branch (1590:9): [True: 0, False: 4]
  |  Branch (1590:38): [True: 0, False: 4]
  ------------------
 1591|      4|        !key->exponent1.data || !key->exponent2.data ||
  ------------------
  |  Branch (1591:9): [True: 0, False: 4]
  |  Branch (1591:33): [True: 0, False: 4]
  ------------------
 1592|      4|        !key->coefficient.data) {
  ------------------
  |  Branch (1592:9): [True: 0, False: 4]
  ------------------
 1593|       |        /* call RSA_PopulatePrivateKey first, if the application wishes to
 1594|       |         * recover these parameters */
 1595|      0|        err = MP_BADARG;
  ------------------
  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  ------------------
 1596|      0|        goto cleanup;
 1597|      0|    }
 1598|       |
 1599|      4|    SECITEM_TO_MPINT(key->modulus, &n);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1600|      4|    SECITEM_TO_MPINT(key->prime1, &p);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1601|      4|    SECITEM_TO_MPINT(key->prime2, &q);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1602|      4|    SECITEM_TO_MPINT(key->publicExponent, &e);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1603|      4|    SECITEM_TO_MPINT(key->privateExponent, &d);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1604|      4|    SECITEM_TO_MPINT(key->exponent1, &d_p);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1605|      4|    SECITEM_TO_MPINT(key->exponent2, &d_q);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1606|      4|    SECITEM_TO_MPINT(key->coefficient, &qInv);
  ------------------
  |  |   19|      4|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  |  |  ------------------
  |  |  |  |   13|      4|    goto cleanup
  |  |  ------------------
  ------------------
 1607|       |    /* p and q must be distinct. */
 1608|      4|    if (mp_cmp(&p, &q) == 0) {
  ------------------
  |  Branch (1608:9): [True: 0, False: 4]
  ------------------
 1609|      0|        rv = SECFailure;
 1610|      0|        goto cleanup;
 1611|      0|    }
 1612|      4|#define VERIFY_MPI_EQUAL(m1, m2) \
 1613|      4|    if (mp_cmp(m1, m2) != 0) {   \
 1614|      4|        rv = SECFailure;         \
 1615|      4|        goto cleanup;            \
 1616|      4|    }
 1617|      4|#define VERIFY_MPI_EQUAL_1(m)  \
 1618|      4|    if (mp_cmp_d(m, 1) != 0) { \
 1619|      4|        rv = SECFailure;       \
 1620|      4|        goto cleanup;          \
 1621|      4|    }
 1622|       |    /* n == p * q */
 1623|      4|    CHECK_MPI_OK(mp_mul(&p, &q, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1624|      4|    VERIFY_MPI_EQUAL(&res, &n);
  ------------------
  |  | 1613|      4|    if (mp_cmp(m1, m2) != 0) {   \
  |  |  ------------------
  |  |  |  Branch (1613:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1614|      0|        rv = SECFailure;         \
  |  | 1615|      0|        goto cleanup;            \
  |  | 1616|      0|    }
  ------------------
 1625|       |    /* gcd(e, p-1) == 1 */
 1626|      4|    CHECK_MPI_OK(mp_sub_d(&p, 1, &psub1));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1627|      4|    CHECK_MPI_OK(mp_gcd(&e, &psub1, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1628|      4|    VERIFY_MPI_EQUAL_1(&res);
  ------------------
  |  | 1618|      4|    if (mp_cmp_d(m, 1) != 0) { \
  |  |  ------------------
  |  |  |  Branch (1618:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1619|      0|        rv = SECFailure;       \
  |  | 1620|      0|        goto cleanup;          \
  |  | 1621|      0|    }
  ------------------
 1629|       |    /* gcd(e, q-1) == 1 */
 1630|      4|    CHECK_MPI_OK(mp_sub_d(&q, 1, &qsub1));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1631|      4|    CHECK_MPI_OK(mp_gcd(&e, &qsub1, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1632|      4|    VERIFY_MPI_EQUAL_1(&res);
  ------------------
  |  | 1618|      4|    if (mp_cmp_d(m, 1) != 0) { \
  |  |  ------------------
  |  |  |  Branch (1618:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1619|      0|        rv = SECFailure;       \
  |  | 1620|      0|        goto cleanup;          \
  |  | 1621|      0|    }
  ------------------
 1633|       |    /* d*e == 1 mod p-1 */
 1634|      4|    CHECK_MPI_OK(mp_mulmod(&d, &e, &psub1, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1635|      4|    VERIFY_MPI_EQUAL_1(&res);
  ------------------
  |  | 1618|      4|    if (mp_cmp_d(m, 1) != 0) { \
  |  |  ------------------
  |  |  |  Branch (1618:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1619|      0|        rv = SECFailure;       \
  |  | 1620|      0|        goto cleanup;          \
  |  | 1621|      0|    }
  ------------------
 1636|       |    /* d*e == 1 mod q-1 */
 1637|      4|    CHECK_MPI_OK(mp_mulmod(&d, &e, &qsub1, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1638|      4|    VERIFY_MPI_EQUAL_1(&res);
  ------------------
  |  | 1618|      4|    if (mp_cmp_d(m, 1) != 0) { \
  |  |  ------------------
  |  |  |  Branch (1618:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1619|      0|        rv = SECFailure;       \
  |  | 1620|      0|        goto cleanup;          \
  |  | 1621|      0|    }
  ------------------
 1639|       |    /* d_p == d mod p-1 */
 1640|      4|    CHECK_MPI_OK(mp_mod(&d, &psub1, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1641|      4|    VERIFY_MPI_EQUAL(&res, &d_p);
  ------------------
  |  | 1613|      4|    if (mp_cmp(m1, m2) != 0) {   \
  |  |  ------------------
  |  |  |  Branch (1613:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1614|      0|        rv = SECFailure;         \
  |  | 1615|      0|        goto cleanup;            \
  |  | 1616|      0|    }
  ------------------
 1642|       |    /* d_q == d mod q-1 */
 1643|      4|    CHECK_MPI_OK(mp_mod(&d, &qsub1, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1644|      4|    VERIFY_MPI_EQUAL(&res, &d_q);
  ------------------
  |  | 1613|      4|    if (mp_cmp(m1, m2) != 0) {   \
  |  |  ------------------
  |  |  |  Branch (1613:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1614|      0|        rv = SECFailure;         \
  |  | 1615|      0|        goto cleanup;            \
  |  | 1616|      0|    }
  ------------------
 1645|       |    /* q * q**-1 == 1 mod p */
 1646|      4|    CHECK_MPI_OK(mp_mulmod(&q, &qInv, &p, &res));
  ------------------
  |  |   12|      4|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      4|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   13|      4|    goto cleanup
  ------------------
 1647|      4|    VERIFY_MPI_EQUAL_1(&res);
  ------------------
  |  | 1618|      4|    if (mp_cmp_d(m, 1) != 0) { \
  |  |  ------------------
  |  |  |  Branch (1618:9): [True: 0, False: 4]
  |  |  ------------------
  |  | 1619|      0|        rv = SECFailure;       \
  |  | 1620|      0|        goto cleanup;          \
  |  | 1621|      0|    }
  ------------------
 1648|       |
 1649|      4|cleanup:
 1650|      4|    mp_clear(&n);
 1651|      4|    mp_clear(&p);
 1652|      4|    mp_clear(&q);
 1653|      4|    mp_clear(&psub1);
 1654|      4|    mp_clear(&qsub1);
 1655|      4|    mp_clear(&e);
 1656|      4|    mp_clear(&d);
 1657|      4|    mp_clear(&d_p);
 1658|      4|    mp_clear(&d_q);
 1659|      4|    mp_clear(&qInv);
 1660|      4|    mp_clear(&res);
 1661|      4|    if (err) {
  ------------------
  |  Branch (1661:9): [True: 0, False: 4]
  ------------------
 1662|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1663|      0|        rv = SECFailure;
 1664|      0|    }
 1665|      4|    return rv;
 1666|      4|}
RSA_Init:
 1670|      1|{
 1671|      1|    if (PR_CallOnce(&coBPInit, init_blinding_params_list) != PR_SUCCESS) {
  ------------------
  |  Branch (1671:9): [True: 0, False: 1]
  ------------------
 1672|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1673|      0|        return SECFailure;
 1674|      0|    }
 1675|      1|    return SECSuccess;
 1676|      1|}
RSA_Cleanup:
 1681|      1|{
 1682|      1|    blindingParams *bp = NULL;
 1683|      1|    if (!coBPInit.initialized)
  ------------------
  |  Branch (1683:9): [True: 0, False: 1]
  ------------------
 1684|      0|        return;
 1685|       |
 1686|      2|    while (!PR_CLIST_IS_EMPTY(&blindingParamsList.head)) {
  ------------------
  |  |   94|      2|    ((_l)->next == (_l))
  ------------------
  |  Branch (1686:12): [True: 1, False: 1]
  ------------------
 1687|      1|        RSABlindingParams *rsabp =
 1688|      1|            (RSABlindingParams *)PR_LIST_HEAD(&blindingParamsList.head);
  ------------------
  |  |   65|      1|#define PR_LIST_HEAD(_l) (_l)->next
  ------------------
 1689|      1|        PR_REMOVE_LINK(&rsabp->link);
  ------------------
  |  |   72|      1|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      1|    (_e)->prev->next = (_e)->next; \
  |  |   74|      1|    (_e)->next->prev = (_e)->prev; \
  |  |   75|      1|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1690|       |        /* clear parameters cache */
 1691|      2|        while (rsabp->bp != NULL) {
  ------------------
  |  Branch (1691:16): [True: 1, False: 1]
  ------------------
 1692|      1|            bp = rsabp->bp;
 1693|      1|            rsabp->bp = rsabp->bp->next;
 1694|      1|            mp_clear(&bp->f);
 1695|      1|            mp_clear(&bp->g);
 1696|      1|        }
 1697|      1|        SECITEM_ZfreeItem(&rsabp->modulus, PR_FALSE);
  ------------------
  |  |  110|      1|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(&rsabp->modulus, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1698|      1|        PORT_Free(rsabp);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
 1699|      1|    }
 1700|       |
 1701|      1|    if (blindingParamsList.cVar) {
  ------------------
  |  Branch (1701:9): [True: 1, False: 0]
  ------------------
 1702|      1|        PR_DestroyCondVar(blindingParamsList.cVar);
 1703|      1|        blindingParamsList.cVar = NULL;
 1704|      1|    }
 1705|       |
 1706|      1|    if (blindingParamsList.lock) {
  ------------------
  |  Branch (1706:9): [True: 1, False: 0]
  ------------------
 1707|      1|        SKIP_AFTER_FORK(PZ_DestroyLock(blindingParamsList.lock));
  ------------------
  |  |   42|      1|    if (!bl_parentForkedAfterC_Initialize) \
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   43|      1|    x
  ------------------
 1708|      1|        blindingParamsList.lock = NULL;
 1709|      1|    }
 1710|       |
 1711|      1|    coBPInit.initialized = 0;
 1712|      1|    coBPInit.inProgress = 0;
 1713|      1|    coBPInit.status = 0;
 1714|      1|}
BL_Cleanup:
 1723|      1|{
 1724|      1|    RSA_Cleanup();
 1725|      1|}
BL_SetForkState:
 1734|      2|{
 1735|      2|    bl_parentForkedAfterC_Initialize = forked;
 1736|      2|}
rsa.c:rsa_modulusLen:
  917|  42.2k|{
  918|  42.2k|    if (modulus->len == 0) {
  ------------------
  |  Branch (918:9): [True: 0, False: 42.2k]
  ------------------
  919|      0|        return 0;
  920|  42.2k|    };
  921|  42.2k|    unsigned char byteZero = modulus->data[0];
  922|  42.2k|    unsigned int modLen = modulus->len - !byteZero;
  923|  42.2k|    return modLen;
  924|  42.2k|}
rsa.c:rsa_PrivateKeyOp:
 1466|  36.3k|{
 1467|  36.3k|    unsigned int modLen;
 1468|  36.3k|    unsigned int offset;
 1469|  36.3k|    SECStatus rv = SECSuccess;
 1470|  36.3k|    mp_err err;
 1471|  36.3k|    mp_int n, c, m;
 1472|  36.3k|    mp_int f, g;
 1473|  36.3k|    mp_digit n0i;
 1474|  36.3k|    if (!key || !output || !input) {
  ------------------
  |  Branch (1474:9): [True: 0, False: 36.3k]
  |  Branch (1474:17): [True: 0, False: 36.3k]
  |  Branch (1474:28): [True: 0, False: 36.3k]
  ------------------
 1475|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1476|      0|        return SECFailure;
 1477|      0|    }
 1478|       |    /* check input out of range (needs to be in range [0..n-1]) */
 1479|  36.3k|    modLen = rsa_modulusLen(&key->modulus);
 1480|  36.3k|    if (modLen == 0) {
  ------------------
  |  Branch (1480:9): [True: 0, False: 36.3k]
  ------------------
 1481|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1482|      0|        return SECFailure;
 1483|      0|    }
 1484|  36.3k|    offset = (key->modulus.data[0] == 0) ? 1 : 0; /* may be leading 0 */
  ------------------
  |  Branch (1484:14): [True: 0, False: 36.3k]
  ------------------
 1485|  36.3k|    if (memcmp(input, key->modulus.data + offset, modLen) >= 0) {
  ------------------
  |  Branch (1485:9): [True: 109, False: 36.2k]
  ------------------
 1486|    109|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|    109|#define PORT_SetError PORT_SetError_Util
  ------------------
 1487|    109|        return SECFailure;
 1488|    109|    }
 1489|  36.2k|    MP_DIGITS(&n) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1490|  36.2k|    MP_DIGITS(&c) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1491|  36.2k|    MP_DIGITS(&m) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1492|  36.2k|    MP_DIGITS(&f) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1493|  36.2k|    MP_DIGITS(&g) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1494|  36.2k|    CHECK_MPI_OK(mp_init(&n));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1495|  36.2k|    CHECK_MPI_OK(mp_init(&c));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1496|  36.2k|    CHECK_MPI_OK(mp_init(&m));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1497|  36.2k|    CHECK_MPI_OK(mp_init(&f));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1498|  36.2k|    CHECK_MPI_OK(mp_init(&g));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1499|  36.2k|    SECITEM_TO_MPINT(key->modulus, &n);
  ------------------
  |  |   19|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1500|  36.2k|    OCTETS_TO_MPINT(input, &c, modLen);
  ------------------
  |  |   16|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), oc, len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1501|       |    /* If blinding, compute pre-image of ciphertext by multiplying by
 1502|       |    ** blinding factor
 1503|       |    */
 1504|  36.2k|    if (nssRSAUseBlinding) {
  ------------------
  |  Branch (1504:9): [Folded - Ignored]
  ------------------
 1505|  36.2k|        CHECK_SEC_OK(get_blinding_params(key, &n, modLen, &f, &g, &n0i));
  ------------------
  |  |    8|  36.2k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |    9|  36.2k|    goto cleanup
  ------------------
 1506|       |        /* c' = c*f mod n */
 1507|  36.2k|        CHECK_MPI_OK(mp_mulmod(&c, &f, &n, &c));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1508|  36.2k|    }
 1509|       |    /* Do the private key operation m = c**d mod n */
 1510|  36.2k|    if (key->prime1.len == 0 ||
  ------------------
  |  Branch (1510:9): [True: 0, False: 36.2k]
  ------------------
 1511|  36.2k|        key->prime2.len == 0 ||
  ------------------
  |  Branch (1511:9): [True: 0, False: 36.2k]
  ------------------
 1512|  36.2k|        key->exponent1.len == 0 ||
  ------------------
  |  Branch (1512:9): [True: 0, False: 36.2k]
  ------------------
 1513|  36.2k|        key->exponent2.len == 0 ||
  ------------------
  |  Branch (1513:9): [True: 0, False: 36.2k]
  ------------------
 1514|  36.2k|        key->coefficient.len == 0) {
  ------------------
  |  Branch (1514:9): [True: 0, False: 36.2k]
  ------------------
 1515|      0|        CHECK_SEC_OK(rsa_PrivateKeyOpNoCRT(key, &m, &c, &n, modLen));
  ------------------
  |  |    8|      0|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 0]
  |  |  ------------------
  |  |    9|      0|    goto cleanup
  ------------------
 1516|  36.2k|    } else if (check) {
  ------------------
  |  Branch (1516:16): [True: 35.5k, False: 663]
  ------------------
 1517|  35.5k|        CHECK_SEC_OK(rsa_PrivateKeyOpCRTCheckedPubKey(key, &m, &c));
  ------------------
  |  |    8|  35.5k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 35.5k]
  |  |  ------------------
  |  |    9|  35.5k|    goto cleanup
  ------------------
 1518|  35.5k|    } else {
 1519|    663|        CHECK_SEC_OK(rsa_PrivateKeyOpCRTNoCheck(key, &m, &c));
  ------------------
  |  |    8|    663|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 663]
  |  |  ------------------
  |  |    9|    663|    goto cleanup
  ------------------
 1520|    663|    }
 1521|       |    /* If blinding, compute post-image of plaintext by multiplying by
 1522|       |    ** blinding factor
 1523|       |    */
 1524|  36.2k|    if (nssRSAUseBlinding) {
  ------------------
  |  Branch (1524:9): [Folded - Ignored]
  ------------------
 1525|       |        /* m = m'*g mod n */
 1526|  36.2k|        CHECK_MPI_OK(mp_mulmontmodCT(&m, &g, &n, n0i, &m));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1527|  36.2k|    }
 1528|  36.2k|    err = mp_to_fixlen_octets(&m, output, modLen);
 1529|  36.2k|    if (err >= 0)
  ------------------
  |  Branch (1529:9): [True: 36.2k, False: 0]
  ------------------
 1530|  36.2k|        err = MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1531|  36.2k|cleanup:
 1532|  36.2k|    mp_clear(&n);
 1533|  36.2k|    mp_clear(&c);
 1534|  36.2k|    mp_clear(&m);
 1535|  36.2k|    mp_clear(&f);
 1536|  36.2k|    mp_clear(&g);
 1537|  36.2k|    if (err) {
  ------------------
  |  Branch (1537:9): [True: 0, False: 36.2k]
  ------------------
 1538|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1539|      0|        rv = SECFailure;
 1540|      0|    }
 1541|  36.2k|    return rv;
 1542|  36.2k|}
rsa.c:get_blinding_params:
 1279|  36.2k|{
 1280|  36.2k|    RSABlindingParams *rsabp = NULL;
 1281|  36.2k|    blindingParams *bpUnlinked = NULL;
 1282|  36.2k|    blindingParams *bp;
 1283|  36.2k|    PRCList *el;
 1284|  36.2k|    SECStatus rv = SECSuccess;
 1285|  36.2k|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1286|  36.2k|    int cmp = -1;
 1287|  36.2k|    PRBool holdingLock = PR_FALSE;
  ------------------
  |  |  438|  36.2k|#define PR_FALSE 0
  ------------------
 1288|       |
 1289|  36.2k|    do {
 1290|  36.2k|        if (blindingParamsList.lock == NULL) {
  ------------------
  |  Branch (1290:13): [True: 0, False: 36.2k]
  ------------------
 1291|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1292|      0|            return SECFailure;
 1293|      0|        }
 1294|       |        /* Acquire the list lock */
 1295|  36.2k|        PZ_Lock(blindingParamsList.lock);
  ------------------
  |  |  245|  36.2k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1296|  36.2k|        holdingLock = PR_TRUE;
  ------------------
  |  |  437|  36.2k|#define PR_TRUE 1
  ------------------
 1297|       |
 1298|       |        /* Walk the list looking for the private key */
 1299|  36.2k|        for (el = PR_NEXT_LINK(&blindingParamsList.head);
  ------------------
  |  |   47|  36.2k|        ((_e)->next)
  ------------------
 1300|  36.2k|             el != &blindingParamsList.head;
  ------------------
  |  Branch (1300:14): [True: 36.2k, False: 1]
  ------------------
 1301|  36.2k|             el = PR_NEXT_LINK(el)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
 1302|  36.2k|            rsabp = (RSABlindingParams *)el;
 1303|  36.2k|            cmp = SECITEM_CompareItem(&rsabp->modulus, &key->modulus);
  ------------------
  |  |  105|  36.2k|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
 1304|  36.2k|            if (cmp >= 0) {
  ------------------
  |  Branch (1304:17): [True: 36.2k, False: 0]
  ------------------
 1305|       |                /* The key is found or not in the list. */
 1306|  36.2k|                break;
 1307|  36.2k|            }
 1308|  36.2k|        }
 1309|       |
 1310|  36.2k|        if (cmp) {
  ------------------
  |  Branch (1310:13): [True: 1, False: 36.2k]
  ------------------
 1311|       |            /* At this point, the key is not in the list.  el should point to
 1312|       |            ** the list element before which this key should be inserted.
 1313|       |            */
 1314|      1|            rsabp = PORT_ZNew(RSABlindingParams);
  ------------------
  |  |  148|      1|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      1|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1315|      1|            if (!rsabp) {
  ------------------
  |  Branch (1315:17): [True: 0, False: 1]
  ------------------
 1316|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1317|      0|                goto cleanup;
 1318|      0|            }
 1319|       |
 1320|      1|            rv = init_blinding_params(rsabp, key, n, modLen);
 1321|      1|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1321:17): [True: 0, False: 1]
  ------------------
 1322|      0|                PORT_ZFree(rsabp, sizeof(RSABlindingParams));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 1323|      0|                goto cleanup;
 1324|      0|            }
 1325|       |
 1326|       |            /* Insert the new element into the list
 1327|       |            ** If inserting in the middle of the list, el points to the link
 1328|       |            ** to insert before.  Otherwise, the link needs to be appended to
 1329|       |            ** the end of the list, which is the same as inserting before the
 1330|       |            ** head (since el would have looped back to the head).
 1331|       |            */
 1332|      1|            PR_INSERT_BEFORE(&rsabp->link, el);
  ------------------
  |  |   25|      2|    PR_BEGIN_MACRO       \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   26|      2|    (_e)->next = (_l);   \
  |  |   27|      2|    (_e)->prev = (_l)->prev; \
  |  |   28|      2|    (_l)->prev->next = (_e); \
  |  |   29|      2|    (_l)->prev = (_e);   \
  |  |   30|      2|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1333|      1|        }
 1334|       |
 1335|       |        /* We've found (or created) the RSAblindingParams struct for this key.
 1336|       |         * Now, search its list of ready blinding params for a usable one.
 1337|       |         */
 1338|  36.2k|        *n0i = rsabp->n0i;
 1339|  36.2k|        while (0 != (bp = rsabp->bp)) {
  ------------------
  |  Branch (1339:16): [True: 36.2k, False: 1]
  ------------------
 1340|  36.2k|#ifdef UNSAFE_FUZZER_MODE
 1341|       |            /* Found a match and there are still remaining uses left */
 1342|       |            /* Return the parameters */
 1343|  36.2k|            CHECK_MPI_OK(mp_copy(&bp->f, f));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1344|  36.2k|            CHECK_MPI_OK(mp_copy(&bp->g, g));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1345|       |
 1346|  36.2k|            PZ_Unlock(blindingParamsList.lock);
  ------------------
  |  |  246|  36.2k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1347|  36.2k|            return SECSuccess;
 1348|       |#else
 1349|       |            if (--(bp->counter) > 0) {
 1350|       |                /* Found a match and there are still remaining uses left */
 1351|       |                /* Return the parameters */
 1352|       |                CHECK_MPI_OK(mp_copy(&bp->f, f));
 1353|       |                CHECK_MPI_OK(mp_copy(&bp->g, g));
 1354|       |
 1355|       |                PZ_Unlock(blindingParamsList.lock);
 1356|       |                return SECSuccess;
 1357|       |            }
 1358|       |            /* exhausted this one, give its values to caller, and
 1359|       |             * then retire it.
 1360|       |             */
 1361|       |            mp_exch(&bp->f, f);
 1362|       |            mp_exch(&bp->g, g);
 1363|       |            mp_clear(&bp->f);
 1364|       |            mp_clear(&bp->g);
 1365|       |            bp->counter = 0;
 1366|       |            /* Move to free list */
 1367|       |            rsabp->bp = bp->next;
 1368|       |            bp->next = rsabp->free;
 1369|       |            rsabp->free = bp;
 1370|       |            /* In case there're threads waiting for new blinding
 1371|       |             * value - notify 1 thread the value is ready
 1372|       |             */
 1373|       |            if (blindingParamsList.waitCount > 0) {
 1374|       |                PR_NotifyCondVar(blindingParamsList.cVar);
 1375|       |                blindingParamsList.waitCount--;
 1376|       |            }
 1377|       |            PZ_Unlock(blindingParamsList.lock);
 1378|       |            return SECSuccess;
 1379|       |#endif
 1380|  36.2k|        }
 1381|       |        /* We did not find a usable set of blinding params.  Can we make one? */
 1382|       |        /* Find a free bp struct. */
 1383|      1|        if ((bp = rsabp->free) != NULL) {
  ------------------
  |  Branch (1383:13): [True: 1, False: 0]
  ------------------
 1384|       |            /* unlink this bp */
 1385|      1|            rsabp->free = bp->next;
 1386|      1|            bp->next = NULL;
 1387|      1|            bpUnlinked = bp; /* In case we fail */
 1388|       |
 1389|      1|            PZ_Unlock(blindingParamsList.lock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1390|      1|            holdingLock = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1391|       |            /* generate blinding parameter values for the current thread */
 1392|      1|            CHECK_SEC_OK(generate_blinding_params(key, f, g, n, modLen));
  ------------------
  |  |    8|      1|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 1]
  |  |  ------------------
  |  |    9|      1|    goto cleanup
  ------------------
 1393|       |
 1394|       |            /* put the blinding parameter values into cache */
 1395|      1|            CHECK_MPI_OK(mp_init(&bp->f));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1396|      1|            CHECK_MPI_OK(mp_init(&bp->g));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1397|      1|            CHECK_MPI_OK(mp_copy(f, &bp->f));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1398|      1|            CHECK_MPI_OK(mp_copy(g, &bp->g));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1399|       |
 1400|       |            /* Put this at head of queue of usable params. */
 1401|      1|            PZ_Lock(blindingParamsList.lock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1402|      1|            holdingLock = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1403|      1|            (void)holdingLock;
 1404|       |            /* initialize RSABlindingParamsStr */
 1405|      1|            bp->counter = RSA_BLINDING_PARAMS_MAX_REUSE;
  ------------------
  |  |   99|      1|#define RSA_BLINDING_PARAMS_MAX_REUSE 50
  ------------------
 1406|      1|            bp->next = rsabp->bp;
 1407|      1|            rsabp->bp = bp;
 1408|      1|            bpUnlinked = NULL;
 1409|       |            /* In case there're threads waiting for new blinding value
 1410|       |             * just notify them the value is ready
 1411|       |             */
 1412|      1|            if (blindingParamsList.waitCount > 0) {
  ------------------
  |  Branch (1412:17): [True: 0, False: 1]
  ------------------
 1413|      0|                PR_NotifyAllCondVar(blindingParamsList.cVar);
 1414|      0|                blindingParamsList.waitCount = 0;
 1415|      0|            }
 1416|      1|            PZ_Unlock(blindingParamsList.lock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1417|      1|            return SECSuccess;
 1418|      1|        }
 1419|       |        /* Here, there are no usable blinding parameters available,
 1420|       |         * and no free bp blocks, presumably because they're all
 1421|       |         * actively having parameters generated for them.
 1422|       |         * So, we need to wait here and not eat up CPU until some
 1423|       |         * change happens.
 1424|       |         */
 1425|      0|        blindingParamsList.waitCount++;
 1426|      0|        PR_WaitCondVar(blindingParamsList.cVar, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |   54|      0|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 1427|      0|        PZ_Unlock(blindingParamsList.lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1428|      0|        holdingLock = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1429|      0|        (void)holdingLock;
 1430|      0|    } while (1);
  ------------------
  |  Branch (1430:14): [Folded - Ignored]
  ------------------
 1431|       |
 1432|      0|cleanup:
 1433|       |    /* It is possible to reach this after the lock is already released.  */
 1434|      0|    if (bpUnlinked) {
  ------------------
  |  Branch (1434:9): [True: 0, False: 0]
  ------------------
 1435|      0|        if (!holdingLock) {
  ------------------
  |  Branch (1435:13): [True: 0, False: 0]
  ------------------
 1436|      0|            PZ_Lock(blindingParamsList.lock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1437|      0|            holdingLock = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1438|      0|        }
 1439|      0|        bp = bpUnlinked;
 1440|      0|        mp_clear(&bp->f);
 1441|      0|        mp_clear(&bp->g);
 1442|      0|        bp->counter = 0;
 1443|       |        /* Must put the unlinked bp back on the free list */
 1444|      0|        bp->next = rsabp->free;
 1445|      0|        rsabp->free = bp;
 1446|      0|    }
 1447|      0|    if (holdingLock) {
  ------------------
  |  Branch (1447:9): [True: 0, False: 0]
  ------------------
 1448|      0|        PZ_Unlock(blindingParamsList.lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1449|      0|    }
 1450|      0|    if (err) {
  ------------------
  |  Branch (1450:9): [True: 0, False: 0]
  ------------------
 1451|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1452|      0|    }
 1453|      0|    *n0i = 0;
 1454|      0|    return SECFailure;
 1455|      0|}
rsa.c:init_blinding_params:
 1248|      1|{
 1249|      1|    blindingParams *bp = rsabp->array;
 1250|      1|    int i = 0;
 1251|       |
 1252|       |    /* Initialize the list pointer for the element */
 1253|      1|    PR_INIT_CLIST(&rsabp->link);
  ------------------
  |  |  100|      1|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      1|    (_l)->next = (_l); \
  |  |  102|      1|    (_l)->prev = (_l); \
  |  |  103|      1|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1254|     21|    for (i = 0; i < RSA_BLINDING_PARAMS_MAX_CACHE_SIZE; ++i, ++bp) {
  ------------------
  |  |   43|     21|#define RSA_BLINDING_PARAMS_MAX_CACHE_SIZE 20
  ------------------
  |  Branch (1254:17): [True: 20, False: 1]
  ------------------
 1255|     20|        bp->next = bp + 1;
 1256|     20|        MP_DIGITS(&bp->f) = 0;
  ------------------
  |  |  152|     20|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1257|     20|        MP_DIGITS(&bp->g) = 0;
  ------------------
  |  |  152|     20|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1258|     20|        bp->counter = 0;
 1259|     20|    }
 1260|       |    /* The last bp->next value was initialized with out
 1261|       |     * of rsabp->array pointer and must be set to NULL
 1262|       |     */
 1263|      1|    rsabp->array[RSA_BLINDING_PARAMS_MAX_CACHE_SIZE - 1].next = NULL;
  ------------------
  |  |   43|      1|#define RSA_BLINDING_PARAMS_MAX_CACHE_SIZE 20
  ------------------
 1264|       |
 1265|      1|    bp = rsabp->array;
 1266|      1|    rsabp->bp = NULL;
 1267|      1|    rsabp->free = bp;
 1268|       |
 1269|       |    /* precalculate montgomery reduction parameter */
 1270|      1|    rsabp->n0i = mp_calculate_mont_n0i(n);
 1271|       |
 1272|       |    /* List elements are keyed using the modulus */
 1273|      1|    return SECITEM_CopyItem(NULL, &rsabp->modulus, &key->modulus);
  ------------------
  |  |  106|      1|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1274|      1|}
rsa.c:generate_blinding_params:
 1206|      1|{
 1207|      1|    SECStatus rv = SECSuccess;
 1208|      1|    mp_int e, k;
 1209|      1|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1210|      1|    unsigned char *kb = NULL;
 1211|       |
 1212|      1|    MP_DIGITS(&e) = 0;
  ------------------
  |  |  152|      1|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1213|      1|    MP_DIGITS(&k) = 0;
  ------------------
  |  |  152|      1|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1214|      1|    CHECK_MPI_OK(mp_init(&e));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1215|      1|    CHECK_MPI_OK(mp_init(&k));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1216|      1|    SECITEM_TO_MPINT(key->publicExponent, &e);
  ------------------
  |  |   19|      1|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  |  |  ------------------
  |  |  |  |   13|      1|    goto cleanup
  |  |  ------------------
  ------------------
 1217|       |    /* generate random k < n */
 1218|      1|    kb = PORT_Alloc(modLen);
  ------------------
  |  |   52|      1|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1219|      1|    if (!kb) {
  ------------------
  |  Branch (1219:9): [True: 0, False: 1]
  ------------------
 1220|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1221|      0|        goto cleanup;
 1222|      0|    }
 1223|      1|    CHECK_SEC_OK(RNG_GenerateGlobalRandomBytes(kb, modLen));
  ------------------
  |  |    8|      1|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 1]
  |  |  ------------------
  |  |    9|      1|    goto cleanup
  ------------------
 1224|      1|    CHECK_MPI_OK(mp_read_unsigned_octets(&k, kb, modLen));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1225|       |    /* k < n */
 1226|      1|    CHECK_MPI_OK(mp_mod(&k, n, &k));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1227|       |    /* f = k**e mod n */
 1228|      1|    CHECK_MPI_OK(mp_exptmod(&k, &e, n, f));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1229|       |    /* g = k**-1 mod n */
 1230|      1|    CHECK_MPI_OK(mp_invmod(&k, n, g));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1231|       |    /* g in montgomery form.. */
 1232|      1|    CHECK_MPI_OK(mp_to_mont(g, n, g));
  ------------------
  |  |   12|      1|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|      1|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   13|      1|    goto cleanup
  ------------------
 1233|      1|cleanup:
 1234|      1|    if (kb)
  ------------------
  |  Branch (1234:9): [True: 1, False: 0]
  ------------------
 1235|      1|        PORT_ZFree(kb, modLen);
  ------------------
  |  |   75|      1|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 1236|      1|    mp_clear(&k);
 1237|      1|    mp_clear(&e);
 1238|      1|    if (err) {
  ------------------
  |  Branch (1238:9): [True: 0, False: 1]
  ------------------
 1239|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1240|      0|        rv = SECFailure;
 1241|      0|    }
 1242|      1|    return rv;
 1243|      1|}
rsa.c:rsa_PrivateKeyOpCRTCheckedPubKey:
 1153|  35.5k|{
 1154|  35.5k|    mp_int n, e, v;
 1155|  35.5k|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1156|  35.5k|    SECStatus rv = SECSuccess;
 1157|  35.5k|    MP_DIGITS(&n) = 0;
  ------------------
  |  |  152|  35.5k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1158|  35.5k|    MP_DIGITS(&e) = 0;
  ------------------
  |  |  152|  35.5k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1159|  35.5k|    MP_DIGITS(&v) = 0;
  ------------------
  |  |  152|  35.5k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1160|  35.5k|    CHECK_MPI_OK(mp_init(&n));
  ------------------
  |  |   12|  35.5k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 35.5k]
  |  |  ------------------
  |  |   13|  35.5k|    goto cleanup
  ------------------
 1161|  35.5k|    CHECK_MPI_OK(mp_init(&e));
  ------------------
  |  |   12|  35.5k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 35.5k]
  |  |  ------------------
  |  |   13|  35.5k|    goto cleanup
  ------------------
 1162|  35.5k|    CHECK_MPI_OK(mp_init(&v));
  ------------------
  |  |   12|  35.5k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 35.5k]
  |  |  ------------------
  |  |   13|  35.5k|    goto cleanup
  ------------------
 1163|  35.5k|    CHECK_SEC_OK(rsa_PrivateKeyOpCRTNoCheck(key, m, c));
  ------------------
  |  |    8|  35.5k|    if (SECSuccess != (rv = func)) \
  |  |  ------------------
  |  |  |  Branch (8:9): [True: 0, False: 35.5k]
  |  |  ------------------
  |  |    9|  35.5k|    goto cleanup
  ------------------
 1164|  35.5k|    SECITEM_TO_MPINT(key->modulus, &n);
  ------------------
  |  |   19|  35.5k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  35.5k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 35.5k]
  |  |  |  |  ------------------
  |  |  |  |   13|  35.5k|    goto cleanup
  |  |  ------------------
  ------------------
 1165|  35.5k|    SECITEM_TO_MPINT(key->publicExponent, &e);
  ------------------
  |  |   19|  35.5k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  35.5k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 35.5k]
  |  |  |  |  ------------------
  |  |  |  |   13|  35.5k|    goto cleanup
  |  |  ------------------
  ------------------
 1166|       |    /* Perform a public key operation v = m ** e mod n */
 1167|  35.5k|    CHECK_MPI_OK(mp_exptmod(m, &e, &n, &v));
  ------------------
  |  |   12|  35.5k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  35.5k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 35.5k]
  |  |  ------------------
  |  |   13|  35.5k|    goto cleanup
  ------------------
 1168|  35.5k|    if (mp_cmp(&v, c) != 0) {
  ------------------
  |  Branch (1168:9): [True: 0, False: 35.5k]
  ------------------
 1169|       |        /* this error triggers a fips fatal error lock */
 1170|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1171|      0|        rv = SECFailure;
 1172|      0|    }
 1173|  35.5k|cleanup:
 1174|  35.5k|    mp_clear(&n);
 1175|  35.5k|    mp_clear(&e);
 1176|  35.5k|    mp_clear(&v);
 1177|  35.5k|    if (err) {
  ------------------
  |  Branch (1177:9): [True: 0, False: 35.5k]
  ------------------
 1178|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1179|      0|        rv = SECFailure;
 1180|      0|    }
 1181|  35.5k|    return rv;
 1182|  35.5k|}
rsa.c:rsa_PrivateKeyOpCRTNoCheck:
 1036|  36.2k|{
 1037|  36.2k|    mp_int p, q, d_p, d_q, qInv;
 1038|       |    /*
 1039|       |            The length of the randomness comes from the papers:
 1040|       |            https://link.springer.com/chapter/10.1007/978-3-642-29912-4_7
 1041|       |            https://link.springer.com/chapter/10.1007/978-3-642-21554-4_5.
 1042|       |        */
 1043|  36.2k|    mp_int blinding_dp, blinding_dq, r1, r2;
 1044|  36.2k|    unsigned char random_block[EXP_BLINDING_RANDOMNESS_LEN_BYTES];
 1045|  36.2k|    mp_int m1, m2, h, ctmp;
 1046|  36.2k|    mp_err err = MP_OKAY;
  ------------------
  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  ------------------
 1047|  36.2k|    SECStatus rv = SECSuccess;
 1048|  36.2k|    MP_DIGITS(&p) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1049|  36.2k|    MP_DIGITS(&q) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1050|  36.2k|    MP_DIGITS(&d_p) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1051|  36.2k|    MP_DIGITS(&d_q) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1052|  36.2k|    MP_DIGITS(&qInv) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1053|  36.2k|    MP_DIGITS(&m1) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1054|  36.2k|    MP_DIGITS(&m2) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1055|  36.2k|    MP_DIGITS(&h) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1056|  36.2k|    MP_DIGITS(&ctmp) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1057|  36.2k|    MP_DIGITS(&blinding_dp) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1058|  36.2k|    MP_DIGITS(&blinding_dq) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1059|  36.2k|    MP_DIGITS(&r1) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1060|  36.2k|    MP_DIGITS(&r2) = 0;
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1061|       |
 1062|  36.2k|    CHECK_MPI_OK(mp_init(&p));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1063|  36.2k|    CHECK_MPI_OK(mp_init(&q));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1064|  36.2k|    CHECK_MPI_OK(mp_init(&d_p));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1065|  36.2k|    CHECK_MPI_OK(mp_init(&d_q));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1066|  36.2k|    CHECK_MPI_OK(mp_init(&qInv));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1067|  36.2k|    CHECK_MPI_OK(mp_init(&m1));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1068|  36.2k|    CHECK_MPI_OK(mp_init(&m2));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1069|  36.2k|    CHECK_MPI_OK(mp_init(&h));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1070|  36.2k|    CHECK_MPI_OK(mp_init(&ctmp));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1071|  36.2k|    CHECK_MPI_OK(mp_init(&blinding_dp));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1072|  36.2k|    CHECK_MPI_OK(mp_init(&blinding_dq));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1073|  36.2k|    CHECK_MPI_OK(mp_init_size(&r1, EXP_BLINDING_RANDOMNESS_LEN));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1074|  36.2k|    CHECK_MPI_OK(mp_init_size(&r2, EXP_BLINDING_RANDOMNESS_LEN));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1075|       |
 1076|       |    /* copy private key parameters into mp integers */
 1077|  36.2k|    SECITEM_TO_MPINT(key->prime1, &p);         /* p */
  ------------------
  |  |   19|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1078|  36.2k|    SECITEM_TO_MPINT(key->prime2, &q);         /* q */
  ------------------
  |  |   19|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1079|  36.2k|    SECITEM_TO_MPINT(key->exponent1, &d_p);    /* d_p  = d mod (p-1) */
  ------------------
  |  |   19|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1080|  36.2k|    SECITEM_TO_MPINT(key->exponent2, &d_q);    /* d_q  = d mod (q-1) */
  ------------------
  |  |   19|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1081|  36.2k|    SECITEM_TO_MPINT(key->coefficient, &qInv); /* qInv = q**-1 mod p */
  ------------------
  |  |   19|  36.2k|    CHECK_MPI_OK(mp_read_unsigned_octets((mp), (it).data, (it).len))
  |  |  ------------------
  |  |  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  |  |  ------------------
  |  |  |  |   13|  36.2k|    goto cleanup
  |  |  ------------------
  ------------------
 1082|       |
 1083|       |    // blinding_dp = 1
 1084|  36.2k|    CHECK_MPI_OK(mp_set_int(&blinding_dp, 1));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1085|       |    // blinding_dp = p - 1
 1086|  36.2k|    CHECK_MPI_OK(mp_sub(&p, &blinding_dp, &blinding_dp));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1087|       |    // generating a random value
 1088|  36.2k|    RNG_GenerateGlobalRandomBytes(random_block, EXP_BLINDING_RANDOMNESS_LEN_BYTES);
  ------------------
  |  |   29|  36.2k|#define EXP_BLINDING_RANDOMNESS_LEN_BYTES (EXP_BLINDING_RANDOMNESS_LEN * sizeof(mp_digit))
  |  |  ------------------
  |  |  |  |   28|  36.2k|#define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |               #define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1089|  36.2k|    MP_USED(&r1) = EXP_BLINDING_RANDOMNESS_LEN;
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  MP_USED(&r1) = EXP_BLINDING_RANDOMNESS_LEN;
  ------------------
  |  |   28|  36.2k|#define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  ------------------
  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  ------------------
  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1090|  36.2k|    memcpy(MP_DIGITS(&r1), random_block, sizeof(random_block));
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1091|       |    // blinding_dp = random * (p - 1)
 1092|  36.2k|    CHECK_MPI_OK(mp_mul(&blinding_dp, &r1, &blinding_dp));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1093|       |    // d_p = d_p + random * (p - 1)
 1094|  36.2k|    CHECK_MPI_OK(mp_add(&d_p, &blinding_dp, &d_p));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1095|       |
 1096|       |    // blinding_dq = 1
 1097|  36.2k|    CHECK_MPI_OK(mp_set_int(&blinding_dq, 1));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1098|       |    // blinding_dq = q - 1
 1099|  36.2k|    CHECK_MPI_OK(mp_sub(&q, &blinding_dq, &blinding_dq));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1100|       |    // generating a random value
 1101|  36.2k|    RNG_GenerateGlobalRandomBytes(random_block, EXP_BLINDING_RANDOMNESS_LEN_BYTES);
  ------------------
  |  |   29|  36.2k|#define EXP_BLINDING_RANDOMNESS_LEN_BYTES (EXP_BLINDING_RANDOMNESS_LEN * sizeof(mp_digit))
  |  |  ------------------
  |  |  |  |   28|  36.2k|#define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  |  |               #define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  |  |  ------------------
  |  |  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1102|  36.2k|    memcpy(MP_DIGITS(&r2), random_block, sizeof(random_block));
  ------------------
  |  |  152|  36.2k|#define MP_DIGITS(MP) ((MP)->dp)
  ------------------
 1103|  36.2k|    MP_USED(&r2) = EXP_BLINDING_RANDOMNESS_LEN;
  ------------------
  |  |  150|  36.2k|#define MP_USED(MP) ((MP)->used)
  ------------------
                  MP_USED(&r2) = EXP_BLINDING_RANDOMNESS_LEN;
  ------------------
  |  |   28|  36.2k|#define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  ------------------
  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define EXP_BLINDING_RANDOMNESS_LEN ((128 + MP_DIGIT_BIT - 1) / MP_DIGIT_BIT)
  |  |  ------------------
  |  |  |  |  137|  36.2k|#define MP_DIGIT_BIT (CHAR_BIT * MP_DIGIT_SIZE)
  |  |  |  |  ------------------
  |  |  |  |  |  |  136|  36.2k|#define MP_DIGIT_SIZE sizeof(mp_digit)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1104|       |    // blinding_dq = random * (q - 1)
 1105|  36.2k|    CHECK_MPI_OK(mp_mul(&blinding_dq, &r2, &blinding_dq));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1106|       |    // d_q = d_q + random * (q-1)
 1107|  36.2k|    CHECK_MPI_OK(mp_add(&d_q, &blinding_dq, &d_q));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1108|       |
 1109|       |    /* 1. m1 = c**d_p mod p */
 1110|  36.2k|    CHECK_MPI_OK(mp_mod(c, &p, &ctmp));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1111|  36.2k|    CHECK_MPI_OK(mp_exptmod(&ctmp, &d_p, &p, &m1));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1112|       |    /* 2. m2 = c**d_q mod q */
 1113|  36.2k|    CHECK_MPI_OK(mp_mod(c, &q, &ctmp));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1114|  36.2k|    CHECK_MPI_OK(mp_exptmod(&ctmp, &d_q, &q, &m2));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1115|       |    /* 3.  h = (m1 - m2) * qInv mod p */
 1116|  36.2k|    CHECK_MPI_OK(mp_submod(&m1, &m2, &p, &h));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1117|  36.2k|    CHECK_MPI_OK(mp_mulmod(&h, &qInv, &p, &h));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1118|       |    /* 4.  m = m2 + h * q */
 1119|  36.2k|    CHECK_MPI_OK(mp_mul(&h, &q, m));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1120|  36.2k|    CHECK_MPI_OK(mp_add(m, &m2, m));
  ------------------
  |  |   12|  36.2k|    if (MP_OKAY > (err = func)) \
  |  |  ------------------
  |  |  |  |   39|  36.2k|#define MP_OKAY 0    /* no error, all is well */
  |  |  ------------------
  |  |  |  Branch (12:9): [True: 0, False: 36.2k]
  |  |  ------------------
  |  |   13|  36.2k|    goto cleanup
  ------------------
 1121|  36.2k|cleanup:
 1122|  36.2k|    mp_clear(&p);
 1123|  36.2k|    mp_clear(&q);
 1124|  36.2k|    mp_clear(&d_p);
 1125|  36.2k|    mp_clear(&d_q);
 1126|  36.2k|    mp_clear(&qInv);
 1127|  36.2k|    mp_clear(&m1);
 1128|  36.2k|    mp_clear(&m2);
 1129|  36.2k|    mp_clear(&h);
 1130|  36.2k|    mp_clear(&ctmp);
 1131|  36.2k|    mp_clear(&blinding_dp);
 1132|  36.2k|    mp_clear(&blinding_dq);
 1133|  36.2k|    mp_clear(&r1);
 1134|  36.2k|    mp_clear(&r2);
 1135|  36.2k|    if (err) {
  ------------------
  |  Branch (1135:9): [True: 0, False: 36.2k]
  ------------------
 1136|      0|        MP_TO_SEC_ERROR(err);
  ------------------
  |  |   41|      0|    switch (err) {                                    \
  |  |   42|      0|        case MP_MEM:                                  \
  |  |  ------------------
  |  |  |  |   42|      0|#define MP_MEM -2    /* out of memory         */
  |  |  ------------------
  |  |  |  Branch (42:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   43|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);       \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   44|      0|            break;                                    \
  |  |   45|      0|        case MP_RANGE:                                \
  |  |  ------------------
  |  |  |  |   43|      0|#define MP_RANGE -3  /* argument out of range */
  |  |  ------------------
  |  |  |  Branch (45:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   46|      0|            PORT_SetError(SEC_ERROR_BAD_DATA);        \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   47|      0|            break;                                    \
  |  |   48|      0|        case MP_BADARG:                               \
  |  |  ------------------
  |  |  |  |   44|      0|#define MP_BADARG -4 /* invalid parameter     */
  |  |  ------------------
  |  |  |  Branch (48:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   49|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   50|      0|            break;                                    \
  |  |   51|      0|        default:                                      \
  |  |  ------------------
  |  |  |  Branch (51:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   52|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE); \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   53|      0|            break;                                    \
  |  |   54|      0|    }
  ------------------
 1137|      0|        rv = SECFailure;
 1138|      0|    }
 1139|  36.2k|    return rv;
 1140|  36.2k|}
rsa.c:init_blinding_params_list:
 1187|      1|{
 1188|      1|    blindingParamsList.lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 1189|      1|    if (!blindingParamsList.lock) {
  ------------------
  |  Branch (1189:9): [True: 0, False: 1]
  ------------------
 1190|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1191|      0|        return PR_FAILURE;
 1192|      0|    }
 1193|      1|    blindingParamsList.cVar = PR_NewCondVar(blindingParamsList.lock);
 1194|      1|    if (!blindingParamsList.cVar) {
  ------------------
  |  Branch (1194:9): [True: 0, False: 1]
  ------------------
 1195|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1196|      0|        return PR_FAILURE;
 1197|      0|    }
 1198|      1|    blindingParamsList.waitCount = 0;
 1199|      1|    PR_INIT_CLIST(&blindingParamsList.head);
  ------------------
  |  |  100|      1|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      1|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      1|    (_l)->next = (_l); \
  |  |  102|      1|    (_l)->prev = (_l); \
  |  |  103|      1|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      1|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1200|      1|    return PR_SUCCESS;
 1201|      1|}

RSA_EncryptBlock:
  916|      3|{
  917|      3|    SECStatus rv;
  918|      3|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
  919|      3|    SECItem formatted;
  920|      3|    SECItem unformatted;
  921|       |
  922|      3|    formatted.data = NULL;
  923|      3|    if (maxOutputLen < modulusLen)
  ------------------
  |  Branch (923:9): [True: 0, False: 3]
  ------------------
  924|      0|        goto failure;
  925|       |
  926|      3|    unformatted.len = inputLen;
  927|      3|    unformatted.data = (unsigned char *)input;
  928|      3|    formatted.data = NULL;
  929|      3|    rv = rsa_FormatBlock(&formatted, modulusLen, RSA_BlockPublic,
  930|      3|                         &unformatted);
  931|      3|    if (rv != SECSuccess)
  ------------------
  |  Branch (931:9): [True: 0, False: 3]
  ------------------
  932|      0|        goto failure;
  933|       |
  934|      3|    rv = RSA_PublicKeyOp(key, output, formatted.data);
  935|      3|    if (rv != SECSuccess)
  ------------------
  |  Branch (935:9): [True: 0, False: 3]
  ------------------
  936|      0|        goto failure;
  937|       |
  938|      3|    PORT_ZFree(formatted.data, modulusLen);
  ------------------
  |  |   75|      3|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  939|      3|    *outputLen = modulusLen;
  940|      3|    return SECSuccess;
  941|       |
  942|      0|failure:
  943|      0|    if (formatted.data != NULL)
  ------------------
  |  Branch (943:9): [True: 0, False: 0]
  ------------------
  944|      0|        PORT_ZFree(formatted.data, modulusLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  945|      0|    return SECFailure;
  946|      3|}
RSA_DecryptBlock:
 1111|  23.1k|{
 1112|  23.1k|    SECStatus rv;
 1113|  23.1k|    PRUint32 fail;
 1114|  23.1k|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
 1115|  23.1k|    unsigned int i;
 1116|  23.1k|    unsigned char *buffer = NULL;
 1117|  23.1k|    unsigned char *errorBuffer = NULL;
 1118|  23.1k|    unsigned char *bp = NULL;
 1119|  23.1k|    unsigned char *ep = NULL;
 1120|  23.1k|    unsigned int outLen = modulusLen;
 1121|  23.1k|    unsigned int maxLegalLen = modulusLen - 10;
 1122|  23.1k|    unsigned int errorLength;
 1123|  23.1k|    const SECHashObject *hashObj;
 1124|  23.1k|    HMACContext *hmac = NULL;
 1125|       |
 1126|       |    /* failures in the top section indicate failures in the environment
 1127|       |     * (memory) or the library. OK to return errors in these cases because
 1128|       |     * it doesn't provide any oracle information to attackers. */
 1129|  23.1k|    if (inputLen != modulusLen || modulusLen < 10) {
  ------------------
  |  Branch (1129:9): [True: 22.4k, False: 772]
  |  Branch (1129:35): [True: 0, False: 772]
  ------------------
 1130|  22.4k|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|  22.4k|#define PORT_SetError PORT_SetError_Util
  ------------------
 1131|  22.4k|        return SECFailure;
 1132|  22.4k|    }
 1133|       |
 1134|       |    /* Allocate enough space to decrypt */
 1135|    772|    buffer = PORT_ZAlloc(modulusLen);
  ------------------
  |  |   72|    772|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 1136|    772|    if (!buffer) {
  ------------------
  |  Branch (1136:9): [True: 0, False: 772]
  ------------------
 1137|      0|        goto loser;
 1138|      0|    }
 1139|    772|    errorBuffer = PORT_ZAlloc(modulusLen);
  ------------------
  |  |   72|    772|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 1140|    772|    if (!errorBuffer) {
  ------------------
  |  Branch (1140:9): [True: 0, False: 772]
  ------------------
 1141|      0|        goto loser;
 1142|      0|    }
 1143|    772|    hashObj = HASH_GetRawHashObject(HASH_AlgSHA256);
 1144|    772|    if (hashObj == NULL) {
  ------------------
  |  Branch (1144:9): [True: 0, False: 772]
  ------------------
 1145|      0|        goto loser;
 1146|      0|    }
 1147|       |
 1148|       |    /* calculate the values to return in the error case rather than
 1149|       |     * the actual returned values. This data is the same for the
 1150|       |     * same input and private key. */
 1151|    772|    hmac = rsa_GetHMACContext(hashObj, key, input, inputLen);
 1152|    772|    if (hmac == NULL) {
  ------------------
  |  Branch (1152:9): [True: 0, False: 772]
  ------------------
 1153|      0|        goto loser;
 1154|      0|    }
 1155|    772|    errorLength = rsa_GetErrorLength(hmac, hashObj->length, maxLegalLen);
 1156|    772|    if (((int)errorLength) < 0) {
  ------------------
  |  Branch (1156:9): [True: 0, False: 772]
  ------------------
 1157|      0|        goto loser;
 1158|      0|    }
 1159|       |    /* we always have to generate a full moduluslen error string. Otherwise
 1160|       |     * we create a timing dependency on errorLength, which could be used to
 1161|       |     * determine the difference between errorLength and outputLen and tell
 1162|       |     * us that there was a pkcs1 decryption failure */
 1163|    772|    rv = rsa_HMACPrf(hmac, STRING_AND_LENGTH("message"),
  ------------------
  |  | 1069|    772|#define STRING_AND_LENGTH(s) s, sizeof(s) - 1
  ------------------
 1164|    772|                     hashObj->length, errorBuffer, modulusLen);
 1165|    772|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1165:9): [True: 0, False: 772]
  ------------------
 1166|      0|        goto loser;
 1167|      0|    }
 1168|       |
 1169|    772|    HMAC_Destroy(hmac, PR_TRUE);
  ------------------
  |  |  437|    772|#define PR_TRUE 1
  ------------------
 1170|    772|    hmac = NULL;
 1171|       |
 1172|       |    /* From here on out, we will always return success. If there is
 1173|       |     * an error, we will return deterministic output based on the key
 1174|       |     * and the input data. */
 1175|    772|    rv = RSA_PrivateKeyOp(key, buffer, input);
 1176|       |
 1177|    772|    fail = PORT_CT_NE(rv, SECSuccess);
  ------------------
  |  |  361|    772|#define PORT_CT_NE(a, b) PORT_CT_NOT_ZERO(((a) - (b)))
  |  |  ------------------
  |  |  |  |  352|    772|#define PORT_CT_NOT_ZERO(x) (PORT_CT_DUPLICATE_MSB_TO_ALL(((x) | (0 - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|    772|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1178|    772|    fail |= PORT_CT_NE(buffer[0], RSA_BLOCK_FIRST_OCTET) | PORT_CT_NE(buffer[1], RSA_BlockPublic);
  ------------------
  |  |  361|    772|#define PORT_CT_NE(a, b) PORT_CT_NOT_ZERO(((a) - (b)))
  |  |  ------------------
  |  |  |  |  352|    772|#define PORT_CT_NOT_ZERO(x) (PORT_CT_DUPLICATE_MSB_TO_ALL(((x) | (0 - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|    772|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  fail |= PORT_CT_NE(buffer[0], RSA_BLOCK_FIRST_OCTET) | PORT_CT_NE(buffer[1], RSA_BlockPublic);
  ------------------
  |  |  361|    772|#define PORT_CT_NE(a, b) PORT_CT_NOT_ZERO(((a) - (b)))
  |  |  ------------------
  |  |  |  |  352|    772|#define PORT_CT_NOT_ZERO(x) (PORT_CT_DUPLICATE_MSB_TO_ALL(((x) | (0 - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|    772|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1179|       |
 1180|       |    /* There have to be at least 8 bytes of padding. */
 1181|  6.94k|    for (i = 2; i < 10; i++) {
  ------------------
  |  Branch (1181:17): [True: 6.17k, False: 772]
  ------------------
 1182|  6.17k|        fail |= PORT_CT_EQ(buffer[i], RSA_BLOCK_AFTER_PAD_OCTET);
  ------------------
  |  |  360|  6.17k|#define PORT_CT_EQ(a, b) PORT_CT_ZERO(((a) - (b)))
  |  |  ------------------
  |  |  |  |  356|  6.17k|#define PORT_CT_ZERO(x) (~PORT_CT_DUPLICATE_MSB_TO_ALL(((x) | (0 - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|  6.17k|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1183|  6.17k|    }
 1184|       |
 1185|   190k|    for (i = 10; i < modulusLen; i++) {
  ------------------
  |  Branch (1185:18): [True: 189k, False: 772]
  ------------------
 1186|   189k|        unsigned int newLen = modulusLen - i - 1;
 1187|   189k|        PRUint32 condition = PORT_CT_EQ(buffer[i], RSA_BLOCK_AFTER_PAD_OCTET) & PORT_CT_EQ(outLen, modulusLen);
  ------------------
  |  |  360|   189k|#define PORT_CT_EQ(a, b) PORT_CT_ZERO(((a) - (b)))
  |  |  ------------------
  |  |  |  |  356|   189k|#define PORT_CT_ZERO(x) (~PORT_CT_DUPLICATE_MSB_TO_ALL(((x) | (0 - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|   189k|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                      PRUint32 condition = PORT_CT_EQ(buffer[i], RSA_BLOCK_AFTER_PAD_OCTET) & PORT_CT_EQ(outLen, modulusLen);
  ------------------
  |  |  360|   189k|#define PORT_CT_EQ(a, b) PORT_CT_ZERO(((a) - (b)))
  |  |  ------------------
  |  |  |  |  356|   189k|#define PORT_CT_ZERO(x) (~PORT_CT_DUPLICATE_MSB_TO_ALL(((x) | (0 - (x)))))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|   189k|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1188|   189k|        outLen = PORT_CT_SEL(condition, newLen, outLen);
  ------------------
  |  |  348|   189k|#define PORT_CT_SEL(m, l, r) (((m) & (l)) | (~(m) & (r)))
  ------------------
 1189|   189k|    }
 1190|       |    // this can only happen if a zero wasn't found above
 1191|    772|    fail |= PORT_CT_GE(outLen, modulusLen);
  ------------------
  |  |  364|    772|#define PORT_CT_GE(a, b) (~PORT_CT_LT(a, b))
  |  |  ------------------
  |  |  |  |  363|    772|#define PORT_CT_LT(a, b) PORT_CT_DUPLICATE_MSB_TO_ALL((a) - (b))
  |  |  |  |  ------------------
  |  |  |  |  |  |  344|    772|#define PORT_CT_DUPLICATE_MSB_TO_ALL(x) ((PRUint32)((PRInt32)(x) >> (sizeof(PRInt32) * 8 - 1)))
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1192|       |
 1193|    772|    outLen = PORT_CT_SEL(fail, errorLength, outLen);
  ------------------
  |  |  348|    772|#define PORT_CT_SEL(m, l, r) (((m) & (l)) | (~(m) & (r)))
  ------------------
 1194|       |
 1195|       |    /* index into the correct buffer. Do it before we truncate outLen if the
 1196|       |     * application was asking for less data than we can return */
 1197|    772|    bp = buffer + modulusLen - outLen;
 1198|    772|    ep = errorBuffer + modulusLen - outLen;
 1199|       |
 1200|       |    /* at this point, outLen returns no information about decryption failures,
 1201|       |     * no need to hide its value. maxOutputLen is how much data the
 1202|       |     * application is expecting, which is also not sensitive. */
 1203|    772|    if (outLen > maxOutputLen) {
  ------------------
  |  Branch (1203:9): [True: 0, False: 772]
  ------------------
 1204|      0|        outLen = maxOutputLen;
 1205|      0|    }
 1206|       |
 1207|       |    /* we can't use PORT_Memcpy because caching could create a time dependency
 1208|       |     * on the status of fail. */
 1209|  92.7k|    for (i = 0; i < outLen; i++) {
  ------------------
  |  Branch (1209:17): [True: 91.9k, False: 772]
  ------------------
 1210|  91.9k|        output[i] = PORT_CT_SEL(fail, ep[i], bp[i]);
  ------------------
  |  |  348|  91.9k|#define PORT_CT_SEL(m, l, r) (((m) & (l)) | (~(m) & (r)))
  ------------------
 1211|  91.9k|    }
 1212|       |
 1213|    772|    *outputLen = outLen;
 1214|       |
 1215|    772|    PORT_Free(buffer);
  ------------------
  |  |   60|    772|#define PORT_Free PORT_Free_Util
  ------------------
 1216|    772|    PORT_Free(errorBuffer);
  ------------------
  |  |   60|    772|#define PORT_Free PORT_Free_Util
  ------------------
 1217|       |
 1218|    772|    return SECSuccess;
 1219|       |
 1220|      0|loser:
 1221|      0|    if (hmac) {
  ------------------
  |  Branch (1221:9): [True: 0, False: 0]
  ------------------
 1222|      0|        HMAC_Destroy(hmac, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1223|      0|    }
 1224|      0|    PORT_Free(buffer);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1225|      0|    PORT_Free(errorBuffer);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1226|       |
 1227|      0|    return SECFailure;
 1228|    772|}
RSA_EMSAEncodePSS:
 1246|  4.81k|{
 1247|  4.81k|    const SECHashObject *hash;
 1248|  4.81k|    void *hash_context;
 1249|  4.81k|    unsigned char *dbMask;
 1250|  4.81k|    unsigned int dbMaskLen;
 1251|  4.81k|    unsigned int i;
 1252|  4.81k|    SECStatus rv;
 1253|       |
 1254|  4.81k|    hash = HASH_GetRawHashObject(hashAlg);
 1255|  4.81k|    dbMaskLen = emLen - hash->length - 1;
 1256|       |
 1257|       |    /* Step 3 */
 1258|  4.81k|    if (emLen < hash->length + saltLen + 2) {
  ------------------
  |  Branch (1258:9): [True: 0, False: 4.81k]
  ------------------
 1259|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1260|      0|        return SECFailure;
 1261|      0|    }
 1262|       |
 1263|       |    /* Step 4 */
 1264|  4.81k|    if (salt == NULL) {
  ------------------
  |  Branch (1264:9): [True: 4.81k, False: 0]
  ------------------
 1265|  4.81k|        rv = RNG_GenerateGlobalRandomBytes(&em[dbMaskLen - saltLen], saltLen);
 1266|  4.81k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1266:13): [True: 0, False: 4.81k]
  ------------------
 1267|      0|            return rv;
 1268|      0|        }
 1269|  4.81k|    } else {
 1270|      0|        PORT_Memcpy(&em[dbMaskLen - saltLen], salt, saltLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 1271|      0|    }
 1272|       |
 1273|       |    /* Step 5 + 6 */
 1274|       |    /* Compute H and store it at its final location &em[dbMaskLen]. */
 1275|  4.81k|    hash_context = (*hash->create)();
 1276|  4.81k|    if (hash_context == NULL) {
  ------------------
  |  Branch (1276:9): [True: 0, False: 4.81k]
  ------------------
 1277|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1278|      0|        return SECFailure;
 1279|      0|    }
 1280|  4.81k|    (*hash->begin)(hash_context);
 1281|  4.81k|    (*hash->update)(hash_context, eightZeros, 8);
 1282|  4.81k|    (*hash->update)(hash_context, mHash, hash->length);
 1283|  4.81k|    (*hash->update)(hash_context, &em[dbMaskLen - saltLen], saltLen);
 1284|  4.81k|    (*hash->end)(hash_context, &em[dbMaskLen], &i, hash->length);
 1285|  4.81k|    (*hash->destroy)(hash_context, PR_TRUE);
  ------------------
  |  |  437|  4.81k|#define PR_TRUE 1
  ------------------
 1286|       |
 1287|       |    /* Step 7 + 8 */
 1288|  4.81k|    PORT_Memset(em, 0, dbMaskLen - saltLen - 1);
  ------------------
  |  |  182|  4.81k|#define PORT_Memset memset
  ------------------
 1289|  4.81k|    em[dbMaskLen - saltLen - 1] = 0x01;
 1290|       |
 1291|       |    /* Step 9 */
 1292|  4.81k|    dbMask = (unsigned char *)PORT_Alloc(dbMaskLen);
  ------------------
  |  |   52|  4.81k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1293|  4.81k|    if (dbMask == NULL) {
  ------------------
  |  Branch (1293:9): [True: 0, False: 4.81k]
  ------------------
 1294|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1295|      0|        return SECFailure;
 1296|      0|    }
 1297|  4.81k|    MGF1(maskHashAlg, dbMask, dbMaskLen, &em[dbMaskLen], hash->length);
 1298|       |
 1299|       |    /* Step 10 */
 1300|   962k|    for (i = 0; i < dbMaskLen; i++)
  ------------------
  |  Branch (1300:17): [True: 957k, False: 4.81k]
  ------------------
 1301|   957k|        em[i] ^= dbMask[i];
 1302|  4.81k|    PORT_Free(dbMask);
  ------------------
  |  |   60|  4.81k|#define PORT_Free PORT_Free_Util
  ------------------
 1303|       |
 1304|       |    /* Step 11 */
 1305|  4.81k|    em[0] &= 0xff >> (8 * emLen - emBits);
 1306|       |
 1307|       |    /* Step 12 */
 1308|  4.81k|    em[emLen - 1] = 0xbc;
 1309|       |
 1310|  4.81k|    return SECSuccess;
 1311|  4.81k|}
RSA_SignPSS:
 1432|  4.81k|{
 1433|  4.81k|    SECStatus rv = SECSuccess;
 1434|  4.81k|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
 1435|  4.81k|    unsigned int modulusBits = rsa_modulusBits(&key->modulus);
 1436|  4.81k|    unsigned int emLen = modulusLen;
 1437|  4.81k|    unsigned char *pssEncoded, *em;
 1438|       |
 1439|  4.81k|    if (maxOutputLen < modulusLen) {
  ------------------
  |  Branch (1439:9): [True: 0, False: 4.81k]
  ------------------
 1440|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1441|      0|        return SECFailure;
 1442|      0|    }
 1443|       |
 1444|  4.81k|    if ((hashAlg == HASH_AlgNULL) || (maskHashAlg == HASH_AlgNULL)) {
  ------------------
  |  Branch (1444:9): [True: 0, False: 4.81k]
  |  Branch (1444:38): [True: 0, False: 4.81k]
  ------------------
 1445|      0|        PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1446|      0|        return SECFailure;
 1447|      0|    }
 1448|       |
 1449|  4.81k|    pssEncoded = em = (unsigned char *)PORT_Alloc(modulusLen);
  ------------------
  |  |   52|  4.81k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1450|  4.81k|    if (pssEncoded == NULL) {
  ------------------
  |  Branch (1450:9): [True: 0, False: 4.81k]
  ------------------
 1451|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1452|      0|        return SECFailure;
 1453|      0|    }
 1454|       |
 1455|       |    /* len(em) == ceil((modulusBits - 1) / 8). */
 1456|  4.81k|    if (modulusBits % 8 == 1) {
  ------------------
  |  Branch (1456:9): [True: 0, False: 4.81k]
  ------------------
 1457|      0|        em[0] = 0;
 1458|      0|        emLen--;
 1459|      0|        em++;
 1460|      0|    }
 1461|  4.81k|    rv = RSA_EMSAEncodePSS(em, emLen, modulusBits - 1, input, hashAlg,
 1462|  4.81k|                           maskHashAlg, salt, saltLength);
 1463|  4.81k|    if (rv != SECSuccess)
  ------------------
  |  Branch (1463:9): [True: 0, False: 4.81k]
  ------------------
 1464|      0|        goto done;
 1465|       |
 1466|       |    // This sets error codes upon failure.
 1467|  4.81k|    rv = RSA_PrivateKeyOpDoubleChecked(key, output, pssEncoded);
 1468|  4.81k|    *outputLen = modulusLen;
 1469|       |
 1470|  4.81k|done:
 1471|  4.81k|    PORT_Free(pssEncoded);
  ------------------
  |  |   60|  4.81k|#define PORT_Free PORT_Free_Util
  ------------------
 1472|  4.81k|    return rv;
 1473|  4.81k|}
RSA_CheckSignPSS:
 1484|     38|{
 1485|     38|    SECStatus rv;
 1486|     38|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
 1487|     38|    unsigned int modulusBits = rsa_modulusBits(&key->modulus);
 1488|     38|    unsigned int emLen = modulusLen;
 1489|     38|    unsigned char *buffer, *em;
 1490|       |
 1491|     38|    if (sigLen != modulusLen) {
  ------------------
  |  Branch (1491:9): [True: 5, False: 33]
  ------------------
 1492|      5|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
 1493|      5|        return SECFailure;
 1494|      5|    }
 1495|       |
 1496|     33|    if ((hashAlg == HASH_AlgNULL) || (maskHashAlg == HASH_AlgNULL)) {
  ------------------
  |  Branch (1496:9): [True: 0, False: 33]
  |  Branch (1496:38): [True: 0, False: 33]
  ------------------
 1497|      0|        PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1498|      0|        return SECFailure;
 1499|      0|    }
 1500|       |
 1501|     33|    buffer = em = (unsigned char *)PORT_Alloc(modulusLen);
  ------------------
  |  |   52|     33|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1502|     33|    if (!buffer) {
  ------------------
  |  Branch (1502:9): [True: 0, False: 33]
  ------------------
 1503|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1504|      0|        return SECFailure;
 1505|      0|    }
 1506|       |
 1507|     33|    rv = RSA_PublicKeyOp(key, buffer, sig);
 1508|     33|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1508:9): [True: 1, False: 32]
  ------------------
 1509|      1|        PORT_Free(buffer);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
 1510|      1|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1511|      1|        return SECFailure;
 1512|      1|    }
 1513|       |
 1514|       |    /* len(em) == ceil((modulusBits - 1) / 8). */
 1515|     32|    if (modulusBits % 8 == 1) {
  ------------------
  |  Branch (1515:9): [True: 0, False: 32]
  ------------------
 1516|      0|        emLen--;
 1517|      0|        em++;
 1518|      0|    }
 1519|     32|    rv = emsa_pss_verify(hash, em, emLen, modulusBits - 1, hashAlg,
 1520|     32|                         maskHashAlg, saltLength);
 1521|       |
 1522|     32|    PORT_Free(buffer);
  ------------------
  |  |   60|     32|#define PORT_Free PORT_Free_Util
  ------------------
 1523|     32|    return rv;
 1524|     33|}
RSA_Sign:
 1533|  30.7k|{
 1534|  30.7k|    SECStatus rv = SECFailure;
 1535|  30.7k|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
 1536|  30.7k|    SECItem formatted = { siBuffer, NULL, 0 };
 1537|  30.7k|    SECItem unformatted = { siBuffer, (unsigned char *)input, inputLen };
 1538|       |
 1539|  30.7k|    if (maxOutputLen < modulusLen) {
  ------------------
  |  Branch (1539:9): [True: 0, False: 30.7k]
  ------------------
 1540|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1541|      0|        goto done;
 1542|      0|    }
 1543|       |
 1544|  30.7k|    rv = rsa_FormatBlock(&formatted, modulusLen, RSA_BlockPrivate,
 1545|  30.7k|                         &unformatted);
 1546|  30.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1546:9): [True: 0, False: 30.7k]
  ------------------
 1547|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1548|      0|        goto done;
 1549|      0|    }
 1550|       |
 1551|       |    // This sets error codes upon failure.
 1552|  30.7k|    rv = RSA_PrivateKeyOpDoubleChecked(key, output, formatted.data);
 1553|  30.7k|    *outputLen = modulusLen;
 1554|       |
 1555|  30.7k|done:
 1556|  30.7k|    if (formatted.data != NULL) {
  ------------------
  |  Branch (1556:9): [True: 30.7k, False: 0]
  ------------------
 1557|  30.7k|        PORT_ZFree(formatted.data, modulusLen);
  ------------------
  |  |   75|  30.7k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 1558|  30.7k|    }
 1559|  30.7k|    return rv;
 1560|  30.7k|}
RSA_CheckSign:
 1568|     22|{
 1569|     22|    SECStatus rv = SECFailure;
 1570|     22|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
 1571|     22|    unsigned int i;
 1572|     22|    unsigned char *buffer = NULL;
 1573|       |
 1574|     22|    if (sigLen != modulusLen) {
  ------------------
  |  Branch (1574:9): [True: 1, False: 21]
  ------------------
 1575|      1|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1576|      1|        goto done;
 1577|      1|    }
 1578|       |
 1579|       |    /*
 1580|       |     * 0x00 || BT || Pad || 0x00 || ActualData
 1581|       |     *
 1582|       |     * The "3" below is the first octet + the second octet + the 0x00
 1583|       |     * octet that always comes just before the ActualData.
 1584|       |     */
 1585|     21|    if (dataLen > modulusLen - (3 + RSA_BLOCK_MIN_PAD_LEN)) {
  ------------------
  |  |   19|     21|#define RSA_BLOCK_MIN_PAD_LEN 8
  ------------------
  |  Branch (1585:9): [True: 0, False: 21]
  ------------------
 1586|      0|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1587|      0|        goto done;
 1588|      0|    }
 1589|       |
 1590|     21|    buffer = (unsigned char *)PORT_Alloc(modulusLen + 1);
  ------------------
  |  |   52|     21|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1591|     21|    if (!buffer) {
  ------------------
  |  Branch (1591:9): [True: 0, False: 21]
  ------------------
 1592|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1593|      0|        goto done;
 1594|      0|    }
 1595|       |
 1596|     21|    if (RSA_PublicKeyOp(key, buffer, sig) != SECSuccess) {
  ------------------
  |  Branch (1596:9): [True: 1, False: 20]
  ------------------
 1597|      1|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1598|      1|        goto done;
 1599|      1|    }
 1600|       |
 1601|       |    /*
 1602|       |     * check the padding that was used
 1603|       |     */
 1604|     20|    if (buffer[0] != RSA_BLOCK_FIRST_OCTET ||
  ------------------
  |  |   20|     40|#define RSA_BLOCK_FIRST_OCTET 0x00
  ------------------
  |  Branch (1604:9): [True: 10, False: 10]
  ------------------
 1605|     20|        buffer[1] != (unsigned char)RSA_BlockPrivate) {
  ------------------
  |  Branch (1605:9): [True: 6, False: 4]
  ------------------
 1606|     16|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|     16|#define PORT_SetError PORT_SetError_Util
  ------------------
 1607|     16|        goto done;
 1608|     16|    }
 1609|      5|    for (i = 2; i < modulusLen - dataLen - 1; i++) {
  ------------------
  |  Branch (1609:17): [True: 5, False: 0]
  ------------------
 1610|      5|        if (buffer[i] != RSA_BLOCK_PRIVATE_PAD_OCTET) {
  ------------------
  |  |   21|      5|#define RSA_BLOCK_PRIVATE_PAD_OCTET 0xff
  ------------------
  |  Branch (1610:13): [True: 4, False: 1]
  ------------------
 1611|      4|            PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
 1612|      4|            goto done;
 1613|      4|        }
 1614|      5|    }
 1615|      0|    if (buffer[i] != RSA_BLOCK_AFTER_PAD_OCTET) {
  ------------------
  |  |   22|      0|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  |  Branch (1615:9): [True: 0, False: 0]
  ------------------
 1616|      0|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1617|      0|        goto done;
 1618|      0|    }
 1619|       |
 1620|       |    /*
 1621|       |     * make sure we get the same results
 1622|       |     */
 1623|      0|    if (PORT_Memcmp(buffer + modulusLen - dataLen, data, dataLen) == 0) {
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (1623:9): [True: 0, False: 0]
  ------------------
 1624|      0|        rv = SECSuccess;
 1625|      0|    }
 1626|       |
 1627|     22|done:
 1628|     22|    if (buffer) {
  ------------------
  |  Branch (1628:9): [True: 21, False: 1]
  ------------------
 1629|     21|        PORT_Free(buffer);
  ------------------
  |  |   60|     21|#define PORT_Free PORT_Free_Util
  ------------------
 1630|     21|    }
 1631|     22|    return rv;
 1632|      0|}
RSA_CheckSignRecover:
 1641|  2.95k|{
 1642|  2.95k|    SECStatus rv = SECFailure;
 1643|  2.95k|    unsigned int modulusLen = rsa_modulusLen(&key->modulus);
 1644|  2.95k|    unsigned int i;
 1645|  2.95k|    unsigned char *buffer = NULL;
 1646|  2.95k|    unsigned int padLen;
 1647|       |
 1648|  2.95k|    if (sigLen != modulusLen) {
  ------------------
  |  Branch (1648:9): [True: 69, False: 2.88k]
  ------------------
 1649|     69|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|     69|#define PORT_SetError PORT_SetError_Util
  ------------------
 1650|     69|        goto done;
 1651|     69|    }
 1652|       |
 1653|  2.88k|    buffer = (unsigned char *)PORT_Alloc(modulusLen + 1);
  ------------------
  |  |   52|  2.88k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1654|  2.88k|    if (!buffer) {
  ------------------
  |  Branch (1654:9): [True: 0, False: 2.88k]
  ------------------
 1655|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1656|      0|        goto done;
 1657|      0|    }
 1658|       |
 1659|  2.88k|    if (RSA_PublicKeyOp(key, buffer, sig) != SECSuccess) {
  ------------------
  |  Branch (1659:9): [True: 24, False: 2.85k]
  ------------------
 1660|     24|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|     24|#define PORT_SetError PORT_SetError_Util
  ------------------
 1661|     24|        goto done;
 1662|     24|    }
 1663|       |
 1664|  2.85k|    *outputLen = 0;
 1665|       |
 1666|       |    /*
 1667|       |     * check the padding that was used
 1668|       |     */
 1669|  2.85k|    if (buffer[0] != RSA_BLOCK_FIRST_OCTET ||
  ------------------
  |  |   20|  5.71k|#define RSA_BLOCK_FIRST_OCTET 0x00
  ------------------
  |  Branch (1669:9): [True: 2.77k, False: 85]
  ------------------
 1670|  2.85k|        buffer[1] != (unsigned char)RSA_BlockPrivate) {
  ------------------
  |  Branch (1670:9): [True: 72, False: 13]
  ------------------
 1671|  2.84k|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|  2.84k|#define PORT_SetError PORT_SetError_Util
  ------------------
 1672|  2.84k|        goto done;
 1673|  2.84k|    }
 1674|    379|    for (i = 2; i < modulusLen; i++) {
  ------------------
  |  Branch (1674:17): [True: 379, False: 0]
  ------------------
 1675|    379|        if (buffer[i] == RSA_BLOCK_AFTER_PAD_OCTET) {
  ------------------
  |  |   22|    379|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  |  Branch (1675:13): [True: 5, False: 374]
  ------------------
 1676|      5|            *outputLen = modulusLen - i - 1;
 1677|      5|            break;
 1678|      5|        }
 1679|    374|        if (buffer[i] != RSA_BLOCK_PRIVATE_PAD_OCTET) {
  ------------------
  |  |   21|    374|#define RSA_BLOCK_PRIVATE_PAD_OCTET 0xff
  ------------------
  |  Branch (1679:13): [True: 8, False: 366]
  ------------------
 1680|      8|            PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      8|#define PORT_SetError PORT_SetError_Util
  ------------------
 1681|      8|            goto done;
 1682|      8|        }
 1683|    374|    }
 1684|      5|    padLen = i - 2;
 1685|      5|    if (padLen < RSA_BLOCK_MIN_PAD_LEN) {
  ------------------
  |  |   19|      5|#define RSA_BLOCK_MIN_PAD_LEN 8
  ------------------
  |  Branch (1685:9): [True: 1, False: 4]
  ------------------
 1686|      1|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1687|      1|        goto done;
 1688|      1|    }
 1689|      4|    if (*outputLen == 0) {
  ------------------
  |  Branch (1689:9): [True: 0, False: 4]
  ------------------
 1690|      0|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1691|      0|        goto done;
 1692|      0|    }
 1693|      4|    if (*outputLen > maxOutputLen) {
  ------------------
  |  Branch (1693:9): [True: 0, False: 4]
  ------------------
 1694|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1695|      0|        goto done;
 1696|      0|    }
 1697|       |
 1698|      4|    PORT_Memcpy(output, buffer + modulusLen - *outputLen, *outputLen);
  ------------------
  |  |  180|      4|#define PORT_Memcpy memcpy
  ------------------
 1699|      4|    rv = SECSuccess;
 1700|       |
 1701|  2.95k|done:
 1702|  2.95k|    if (buffer) {
  ------------------
  |  Branch (1702:9): [True: 2.88k, False: 69]
  ------------------
 1703|  2.88k|        PORT_Free(buffer);
  ------------------
  |  |   60|  2.88k|#define PORT_Free PORT_Free_Util
  ------------------
 1704|  2.88k|    }
 1705|  2.95k|    return rv;
 1706|      4|}
rsapkcs.c:rsa_modulusLen:
   82|  61.7k|{
   83|  61.7k|    if (modulus->len == 0) {
  ------------------
  |  Branch (83:9): [True: 0, False: 61.7k]
  ------------------
   84|      0|        return 0;
   85|      0|    }
   86|       |
   87|  61.7k|    unsigned char byteZero = modulus->data[0];
   88|  61.7k|    unsigned int modLen = modulus->len - !byteZero;
   89|  61.7k|    return modLen;
   90|  61.7k|}
rsapkcs.c:rsa_FormatBlock:
  244|  30.7k|{
  245|  30.7k|    switch (blockType) {
  246|  30.7k|        case RSA_BlockPrivate:
  ------------------
  |  Branch (246:9): [True: 30.7k, False: 3]
  ------------------
  247|  30.7k|        case RSA_BlockPublic:
  ------------------
  |  Branch (247:9): [True: 3, False: 30.7k]
  ------------------
  248|       |            /*
  249|       |             * 0x00 || BT || Pad || 0x00 || ActualData
  250|       |             *
  251|       |             * The "3" below is the first octet + the second octet + the 0x00
  252|       |             * octet that always comes just before the ActualData.
  253|       |             */
  254|  30.7k|            if (modulusLen < (3 + RSA_BLOCK_MIN_PAD_LEN) || data->len > (modulusLen - (3 + RSA_BLOCK_MIN_PAD_LEN))) {
  ------------------
  |  |   19|  30.7k|#define RSA_BLOCK_MIN_PAD_LEN 8
  ------------------
                          if (modulusLen < (3 + RSA_BLOCK_MIN_PAD_LEN) || data->len > (modulusLen - (3 + RSA_BLOCK_MIN_PAD_LEN))) {
  ------------------
  |  |   19|  30.7k|#define RSA_BLOCK_MIN_PAD_LEN 8
  ------------------
  |  Branch (254:17): [True: 0, False: 30.7k]
  |  Branch (254:61): [True: 0, False: 30.7k]
  ------------------
  255|      0|                return SECFailure;
  256|      0|            }
  257|  30.7k|            result->data = rsa_FormatOneBlock(modulusLen, blockType, data);
  258|  30.7k|            if (result->data == NULL) {
  ------------------
  |  Branch (258:17): [True: 0, False: 30.7k]
  ------------------
  259|      0|                result->len = 0;
  260|      0|                return SECFailure;
  261|      0|            }
  262|  30.7k|            result->len = modulusLen;
  263|       |
  264|  30.7k|            break;
  265|       |
  266|      0|        case RSA_BlockRaw:
  ------------------
  |  Branch (266:9): [True: 0, False: 30.7k]
  ------------------
  267|       |            /*
  268|       |             * Pad || ActualData
  269|       |             * Pad is zeros. The application is responsible for recovering
  270|       |             * the actual data.
  271|       |             */
  272|      0|            if (data->len > modulusLen) {
  ------------------
  |  Branch (272:17): [True: 0, False: 0]
  ------------------
  273|      0|                return SECFailure;
  274|      0|            }
  275|      0|            result->data = (unsigned char *)PORT_ZAlloc(modulusLen);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  276|      0|            result->len = modulusLen;
  277|      0|            PORT_Memcpy(result->data + (modulusLen - data->len),
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  278|      0|                        data->data, data->len);
  279|      0|            break;
  280|       |
  281|      0|        default:
  ------------------
  |  Branch (281:9): [True: 0, False: 30.7k]
  ------------------
  282|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  283|      0|            result->data = NULL;
  284|      0|            result->len = 0;
  285|      0|            return SECFailure;
  286|  30.7k|    }
  287|       |
  288|  30.7k|    return SECSuccess;
  289|  30.7k|}
rsapkcs.c:rsa_FormatOneBlock:
  127|  30.7k|{
  128|  30.7k|    unsigned char *block;
  129|  30.7k|    unsigned char *bp;
  130|  30.7k|    unsigned int padLen;
  131|  30.7k|    unsigned int i, j;
  132|  30.7k|    SECStatus rv;
  133|       |
  134|  30.7k|    block = (unsigned char *)PORT_Alloc(modulusLen);
  ------------------
  |  |   52|  30.7k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  135|  30.7k|    if (block == NULL)
  ------------------
  |  Branch (135:9): [True: 0, False: 30.7k]
  ------------------
  136|      0|        return NULL;
  137|       |
  138|  30.7k|    bp = block;
  139|       |
  140|       |    /*
  141|       |     * All RSA blocks start with two octets:
  142|       |     *  0x00 || BlockType
  143|       |     */
  144|  30.7k|    *bp++ = RSA_BLOCK_FIRST_OCTET;
  ------------------
  |  |   20|  30.7k|#define RSA_BLOCK_FIRST_OCTET 0x00
  ------------------
  145|  30.7k|    *bp++ = (unsigned char)blockType;
  146|       |
  147|  30.7k|    switch (blockType) {
  148|       |
  149|       |        /*
  150|       |         * Blocks intended for private-key operation.
  151|       |         */
  152|  30.7k|        case RSA_BlockPrivate: /* preferred method */
  ------------------
  |  Branch (152:9): [True: 30.7k, False: 3]
  ------------------
  153|       |            /*
  154|       |             * 0x00 || BT || Pad || 0x00 || ActualData
  155|       |             *   1      1   padLen    1      data->len
  156|       |             * padLen must be at least RSA_BLOCK_MIN_PAD_LEN (8) bytes.
  157|       |             * Pad is either all 0x00 or all 0xff bytes, depending on blockType.
  158|       |             */
  159|  30.7k|            padLen = modulusLen - data->len - 3;
  160|  30.7k|            PORT_Assert(padLen >= RSA_BLOCK_MIN_PAD_LEN);
  ------------------
  |  |  120|  30.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  161|  30.7k|            if (padLen < RSA_BLOCK_MIN_PAD_LEN) {
  ------------------
  |  |   19|  30.7k|#define RSA_BLOCK_MIN_PAD_LEN 8
  ------------------
  |  Branch (161:17): [True: 0, False: 30.7k]
  ------------------
  162|      0|                PORT_ZFree(block, modulusLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  163|      0|                return NULL;
  164|      0|            }
  165|  30.7k|            PORT_Memset(bp, RSA_BLOCK_PRIVATE_PAD_OCTET, padLen);
  ------------------
  |  |  182|  30.7k|#define PORT_Memset memset
  ------------------
                          PORT_Memset(bp, RSA_BLOCK_PRIVATE_PAD_OCTET, padLen);
  ------------------
  |  |   21|  30.7k|#define RSA_BLOCK_PRIVATE_PAD_OCTET 0xff
  ------------------
  166|  30.7k|            bp += padLen;
  167|  30.7k|            *bp++ = RSA_BLOCK_AFTER_PAD_OCTET;
  ------------------
  |  |   22|  30.7k|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  168|  30.7k|            PORT_Memcpy(bp, data->data, data->len);
  ------------------
  |  |  180|  30.7k|#define PORT_Memcpy memcpy
  ------------------
  169|  30.7k|            break;
  170|       |
  171|       |        /*
  172|       |         * Blocks intended for public-key operation.
  173|       |         */
  174|      3|        case RSA_BlockPublic:
  ------------------
  |  Branch (174:9): [True: 3, False: 30.7k]
  ------------------
  175|       |            /*
  176|       |             * 0x00 || BT || Pad || 0x00 || ActualData
  177|       |             *   1      1   padLen    1      data->len
  178|       |             * Pad is 8 or more non-zero random bytes.
  179|       |             *
  180|       |             * Build the block left to right.
  181|       |             * Fill the entire block from Pad to the end with random bytes.
  182|       |             * Use the bytes after Pad as a supply of extra random bytes from
  183|       |             * which to find replacements for the zero bytes in Pad.
  184|       |             * If we need more than that, refill the bytes after Pad with
  185|       |             * new random bytes as necessary.
  186|       |             */
  187|       |
  188|      3|            padLen = modulusLen - (data->len + 3);
  189|      3|            PORT_Assert(padLen >= RSA_BLOCK_MIN_PAD_LEN);
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  190|      3|            if (padLen < RSA_BLOCK_MIN_PAD_LEN) {
  ------------------
  |  |   19|      3|#define RSA_BLOCK_MIN_PAD_LEN 8
  ------------------
  |  Branch (190:17): [True: 0, False: 3]
  ------------------
  191|      0|                PORT_ZFree(block, modulusLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  192|      0|                return NULL;
  193|      0|            }
  194|      3|            j = modulusLen - 2;
  195|      3|            rv = RNG_GenerateGlobalRandomBytes(bp, j);
  196|      3|            if (rv == SECSuccess) {
  ------------------
  |  Branch (196:17): [True: 3, False: 0]
  ------------------
  197|    674|                for (i = 0; i < padLen;) {
  ------------------
  |  Branch (197:29): [True: 671, False: 3]
  ------------------
  198|    671|                    unsigned char repl;
  199|       |                    /* Pad with non-zero random data. */
  200|    671|                    if (bp[i] != RSA_BLOCK_AFTER_PAD_OCTET) {
  ------------------
  |  |   22|    671|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  |  Branch (200:25): [True: 670, False: 1]
  ------------------
  201|    670|                        ++i;
  202|    670|                        continue;
  203|    670|                    }
  204|      1|                    if (j <= padLen) {
  ------------------
  |  Branch (204:25): [True: 0, False: 1]
  ------------------
  205|      0|                        rv = RNG_GenerateGlobalRandomBytes(bp + padLen,
  206|      0|                                                           modulusLen - (2 + padLen));
  207|      0|                        if (rv != SECSuccess)
  ------------------
  |  Branch (207:29): [True: 0, False: 0]
  ------------------
  208|      0|                            break;
  209|      0|                        j = modulusLen - 2;
  210|      0|                    }
  211|      1|                    do {
  212|      1|                        repl = bp[--j];
  213|      1|                    } while (repl == RSA_BLOCK_AFTER_PAD_OCTET && j > padLen);
  ------------------
  |  |   22|      2|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  |  Branch (213:30): [True: 0, False: 1]
  |  Branch (213:67): [True: 0, False: 0]
  ------------------
  214|      1|                    if (repl != RSA_BLOCK_AFTER_PAD_OCTET) {
  ------------------
  |  |   22|      1|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  |  Branch (214:25): [True: 1, False: 0]
  ------------------
  215|      1|                        bp[i++] = repl;
  216|      1|                    }
  217|      1|                }
  218|      3|            }
  219|      3|            if (rv != SECSuccess) {
  ------------------
  |  Branch (219:17): [True: 0, False: 3]
  ------------------
  220|      0|                PORT_ZFree(block, modulusLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  221|      0|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  222|      0|                return NULL;
  223|      0|            }
  224|      3|            bp += padLen;
  225|      3|            *bp++ = RSA_BLOCK_AFTER_PAD_OCTET;
  ------------------
  |  |   22|      3|#define RSA_BLOCK_AFTER_PAD_OCTET 0x00
  ------------------
  226|      3|            PORT_Memcpy(bp, data->data, data->len);
  ------------------
  |  |  180|      3|#define PORT_Memcpy memcpy
  ------------------
  227|      3|            break;
  228|       |
  229|      0|        default:
  ------------------
  |  Branch (229:9): [True: 0, False: 30.7k]
  ------------------
  230|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  231|      0|            PORT_ZFree(block, modulusLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  232|      0|            return NULL;
  233|  30.7k|    }
  234|       |
  235|  30.7k|    return block;
  236|  30.7k|}
rsapkcs.c:rsa_GetHMACContext:
  951|    772|{
  952|    772|    unsigned char keyHash[HASH_LENGTH_MAX];
  953|    772|    void *hashContext;
  954|    772|    HMACContext *hmac = NULL;
  955|    772|    unsigned int privKeyLen = key->privateExponent.len;
  956|    772|    unsigned int keyLen;
  957|    772|    SECStatus rv;
  958|       |
  959|       |    /* first get the key hash (should store in the key structure) */
  960|    772|    PORT_Memset(keyHash, 0, sizeof(keyHash));
  ------------------
  |  |  182|    772|#define PORT_Memset memset
  ------------------
  961|    772|    hashContext = (*hash->create)();
  962|    772|    if (hashContext == NULL) {
  ------------------
  |  Branch (962:9): [True: 0, False: 772]
  ------------------
  963|      0|        return NULL;
  964|      0|    }
  965|    772|    (*hash->begin)(hashContext);
  966|    772|    if (privKeyLen < inputLen) {
  ------------------
  |  Branch (966:9): [True: 0, False: 772]
  ------------------
  967|      0|        int padLen = inputLen - privKeyLen;
  968|      0|        while (padLen > sizeof(keyHash)) {
  ------------------
  |  Branch (968:16): [True: 0, False: 0]
  ------------------
  969|      0|            (*hash->update)(hashContext, keyHash, sizeof(keyHash));
  970|      0|            padLen -= sizeof(keyHash);
  971|      0|        }
  972|      0|        (*hash->update)(hashContext, keyHash, padLen);
  973|      0|    }
  974|    772|    (*hash->update)(hashContext, key->privateExponent.data, privKeyLen);
  975|    772|    (*hash->end)(hashContext, keyHash, &keyLen, sizeof(keyHash));
  976|    772|    (*hash->destroy)(hashContext, PR_TRUE);
  ------------------
  |  |  437|    772|#define PR_TRUE 1
  ------------------
  977|       |
  978|       |    /* now create the hmac key */
  979|    772|    hmac = HMAC_Create(hash, keyHash, keyLen, PR_TRUE);
  ------------------
  |  |  437|    772|#define PR_TRUE 1
  ------------------
  980|    772|    if (hmac == NULL) {
  ------------------
  |  Branch (980:9): [True: 0, False: 772]
  ------------------
  981|      0|        PORT_SafeZero(keyHash, sizeof(keyHash));
  982|      0|        return NULL;
  983|      0|    }
  984|    772|    HMAC_Begin(hmac);
  985|    772|    HMAC_Update(hmac, input, inputLen);
  986|    772|    rv = HMAC_Finish(hmac, keyHash, &keyLen, sizeof(keyHash));
  987|    772|    if (rv != SECSuccess) {
  ------------------
  |  Branch (987:9): [True: 0, False: 772]
  ------------------
  988|      0|        PORT_SafeZero(keyHash, sizeof(keyHash));
  989|      0|        HMAC_Destroy(hmac, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  990|      0|        return NULL;
  991|      0|    }
  992|       |    /* Finally set the new key into the hash context. We
  993|       |     * reuse the original context allocated above so we don't
  994|       |     * need to allocate and free another one */
  995|    772|    rv = HMAC_ReInit(hmac, hash, keyHash, keyLen, PR_TRUE);
  ------------------
  |  |  437|    772|#define PR_TRUE 1
  ------------------
  996|    772|    PORT_SafeZero(keyHash, sizeof(keyHash));
  997|    772|    if (rv != SECSuccess) {
  ------------------
  |  Branch (997:9): [True: 0, False: 772]
  ------------------
  998|      0|        HMAC_Destroy(hmac, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  999|      0|        return NULL;
 1000|      0|    }
 1001|       |
 1002|    772|    return hmac;
 1003|    772|}
rsapkcs.c:rsa_GetErrorLength:
 1072|    772|{
 1073|    772|    unsigned char out[128 * 2];
 1074|    772|    unsigned char *outp;
 1075|    772|    int outLength = 0;
 1076|    772|    int lengthMask;
 1077|    772|    SECStatus rv;
 1078|       |
 1079|    772|    lengthMask = makeMask16(maxLegalLen);
 1080|    772|    rv = rsa_HMACPrf(hmac, STRING_AND_LENGTH("length"), hashLen,
  ------------------
  |  | 1069|    772|#define STRING_AND_LENGTH(s) s, sizeof(s) - 1
  ------------------
 1081|    772|                     out, sizeof(out));
 1082|    772|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1082:9): [True: 0, False: 772]
  ------------------
 1083|      0|        return -1;
 1084|      0|    }
 1085|  99.5k|    for (outp = out; outp < out + sizeof(out); outp += 2) {
  ------------------
  |  Branch (1085:22): [True: 98.8k, False: 772]
  ------------------
 1086|  98.8k|        int candidate = outp[0] << 8 | outp[1];
 1087|  98.8k|        candidate = candidate & lengthMask;
 1088|  98.8k|        outLength = PORT_CT_SEL(PORT_CT_LT(candidate, maxLegalLen),
  ------------------
  |  |  348|  98.8k|#define PORT_CT_SEL(m, l, r) (((m) & (l)) | (~(m) & (r)))
  ------------------
 1089|  98.8k|                                candidate, outLength);
 1090|  98.8k|    }
 1091|    772|    PORT_SafeZero(out, sizeof(out));
 1092|    772|    return outLength;
 1093|    772|}
rsapkcs.c:makeMask16:
 1060|    772|{
 1061|       |    // or the high bit in each bit location
 1062|    772|    len |= (len >> 1);
 1063|    772|    len |= (len >> 2);
 1064|    772|    len |= (len >> 4);
 1065|    772|    len |= (len >> 8);
 1066|    772|    return len;
 1067|    772|}
rsapkcs.c:rsa_HMACPrf:
 1008|  1.54k|{
 1009|  1.54k|    unsigned char iterator[2] = { 0, 0 };
 1010|  1.54k|    unsigned char encodedLen[2] = { 0, 0 };
 1011|  1.54k|    unsigned char hmacLast[HASH_LENGTH_MAX];
 1012|  1.54k|    unsigned int left = length;
 1013|  1.54k|    unsigned int hashReturn;
 1014|  1.54k|    SECStatus rv = SECSuccess;
 1015|       |
 1016|       |    /* encodedLen is in bits, length is in bytes, thus the shifts
 1017|       |     * do an implied multiply by 8 */
 1018|  1.54k|    encodedLen[0] = (length >> 5) & 0xff;
 1019|  1.54k|    encodedLen[1] = (length << 3) & 0xff;
 1020|       |
 1021|  12.3k|    while (left > hashLength) {
  ------------------
  |  Branch (1021:12): [True: 10.8k, False: 1.54k]
  ------------------
 1022|  10.8k|        HMAC_Begin(hmac);
 1023|  10.8k|        HMAC_Update(hmac, iterator, 2);
 1024|  10.8k|        HMAC_Update(hmac, (const unsigned char *)label, labelLen);
 1025|  10.8k|        HMAC_Update(hmac, encodedLen, 2);
 1026|  10.8k|        rv = HMAC_Finish(hmac, output, &hashReturn, hashLength);
 1027|  10.8k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1027:13): [True: 0, False: 10.8k]
  ------------------
 1028|      0|            return rv;
 1029|      0|        }
 1030|  10.8k|        iterator[1]++;
 1031|  10.8k|        if (iterator[1] == 0)
  ------------------
  |  Branch (1031:13): [True: 0, False: 10.8k]
  ------------------
 1032|      0|            iterator[0]++;
 1033|  10.8k|        left -= hashLength;
 1034|  10.8k|        output += hashLength;
 1035|  10.8k|    }
 1036|  1.54k|    if (left) {
  ------------------
  |  Branch (1036:9): [True: 1.54k, False: 0]
  ------------------
 1037|  1.54k|        HMAC_Begin(hmac);
 1038|  1.54k|        HMAC_Update(hmac, iterator, 2);
 1039|  1.54k|        HMAC_Update(hmac, (const unsigned char *)label, labelLen);
 1040|  1.54k|        HMAC_Update(hmac, encodedLen, 2);
 1041|  1.54k|        rv = HMAC_Finish(hmac, hmacLast, &hashReturn, sizeof(hmacLast));
 1042|  1.54k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1042:13): [True: 0, False: 1.54k]
  ------------------
 1043|      0|            return rv;
 1044|      0|        }
 1045|  1.54k|        PORT_Memcpy(output, hmacLast, left);
  ------------------
  |  |  180|  1.54k|#define PORT_Memcpy memcpy
  ------------------
 1046|  1.54k|        PORT_SafeZero(hmacLast, sizeof(hmacLast));
 1047|  1.54k|    }
 1048|  1.54k|    return rv;
 1049|  1.54k|}
rsapkcs.c:MGF1:
  300|  4.82k|{
  301|  4.82k|    unsigned int digestLen;
  302|  4.82k|    PRUint32 counter;
  303|  4.82k|    PRUint32 rounds;
  304|  4.82k|    unsigned char *tempHash;
  305|  4.82k|    unsigned char *temp;
  306|  4.82k|    const SECHashObject *hash;
  307|  4.82k|    void *hashContext;
  308|  4.82k|    unsigned char C[4];
  309|  4.82k|    SECStatus rv = SECSuccess;
  310|       |
  311|  4.82k|    hash = HASH_GetRawHashObject(hashAlg);
  312|  4.82k|    if (hash == NULL) {
  ------------------
  |  Branch (312:9): [True: 0, False: 4.82k]
  ------------------
  313|      0|        return SECFailure;
  314|      0|    }
  315|       |
  316|  4.82k|    hashContext = (*hash->create)();
  317|  4.82k|    rounds = (maskLen + hash->length - 1) / hash->length;
  318|  24.0k|    for (counter = 0; counter < rounds; counter++) {
  ------------------
  |  Branch (318:23): [True: 19.2k, False: 4.82k]
  ------------------
  319|  19.2k|        C[0] = (unsigned char)((counter >> 24) & 0xff);
  320|  19.2k|        C[1] = (unsigned char)((counter >> 16) & 0xff);
  321|  19.2k|        C[2] = (unsigned char)((counter >> 8) & 0xff);
  322|  19.2k|        C[3] = (unsigned char)(counter & 0xff);
  323|       |
  324|       |        /* This could be optimized when the clone functions in
  325|       |         * rawhash.c are implemented. */
  326|  19.2k|        (*hash->begin)(hashContext);
  327|  19.2k|        (*hash->update)(hashContext, mgfSeed, mgfSeedLen);
  328|  19.2k|        (*hash->update)(hashContext, C, sizeof C);
  329|       |
  330|  19.2k|        tempHash = mask + counter * hash->length;
  331|  19.2k|        if (counter != (rounds - 1)) {
  ------------------
  |  Branch (331:13): [True: 14.4k, False: 4.82k]
  ------------------
  332|  14.4k|            (*hash->end)(hashContext, tempHash, &digestLen, hash->length);
  333|  14.4k|        } else { /* we're in the last round and need to cut the hash */
  334|  4.82k|            temp = (unsigned char *)PORT_Alloc(hash->length);
  ------------------
  |  |   52|  4.82k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  335|  4.82k|            if (!temp) {
  ------------------
  |  Branch (335:17): [True: 0, False: 4.82k]
  ------------------
  336|      0|                rv = SECFailure;
  337|      0|                goto done;
  338|      0|            }
  339|  4.82k|            (*hash->end)(hashContext, temp, &digestLen, hash->length);
  340|  4.82k|            PORT_Memcpy(tempHash, temp, maskLen - counter * hash->length);
  ------------------
  |  |  180|  4.82k|#define PORT_Memcpy memcpy
  ------------------
  341|  4.82k|            PORT_Free(temp);
  ------------------
  |  |   60|  4.82k|#define PORT_Free PORT_Free_Util
  ------------------
  342|  4.82k|        }
  343|  19.2k|    }
  344|       |
  345|  4.82k|done:
  346|  4.82k|    (*hash->destroy)(hashContext, PR_TRUE);
  ------------------
  |  |  437|  4.82k|#define PR_TRUE 1
  ------------------
  347|  4.82k|    return rv;
  348|  4.82k|}
rsapkcs.c:rsa_modulusBits:
   94|  4.85k|{
   95|  4.85k|    if (modulus->len == 0) {
  ------------------
  |  Branch (95:9): [True: 0, False: 4.85k]
  ------------------
   96|      0|        return 0;
   97|      0|    }
   98|       |
   99|  4.85k|    unsigned char byteZero = modulus->data[0];
  100|  4.85k|    unsigned int numBits = (modulus->len - 1) * 8;
  101|       |
  102|  4.85k|    if (byteZero == 0 && modulus->len == 1) {
  ------------------
  |  Branch (102:9): [True: 0, False: 4.85k]
  |  Branch (102:26): [True: 0, False: 0]
  ------------------
  103|      0|        return 0;
  104|      0|    }
  105|       |
  106|  4.85k|    if (byteZero == 0) {
  ------------------
  |  Branch (106:9): [True: 0, False: 4.85k]
  ------------------
  107|      0|        numBits -= 8;
  108|      0|        byteZero = modulus->data[1];
  109|      0|    }
  110|       |
  111|  43.6k|    while (byteZero > 0) {
  ------------------
  |  Branch (111:12): [True: 38.8k, False: 4.85k]
  ------------------
  112|  38.8k|        numBits++;
  113|  38.8k|        byteZero >>= 1;
  114|  38.8k|    }
  115|       |
  116|  4.85k|    return numBits;
  117|  4.85k|}
rsapkcs.c:emsa_pss_verify:
 1328|     32|{
 1329|     32|    const SECHashObject *hash;
 1330|     32|    void *hash_context;
 1331|     32|    unsigned char *db;
 1332|     32|    unsigned char *H_; /* H' from the RFC */
 1333|     32|    unsigned int i;
 1334|     32|    unsigned int dbMaskLen;
 1335|     32|    unsigned int zeroBits;
 1336|     32|    SECStatus rv;
 1337|       |
 1338|     32|    hash = HASH_GetRawHashObject(hashAlg);
 1339|     32|    dbMaskLen = emLen - hash->length - 1;
 1340|       |
 1341|       |    /* Step 3 + 4 */
 1342|     32|    if ((emLen < (hash->length + saltLen + 2)) ||
  ------------------
  |  Branch (1342:9): [True: 0, False: 32]
  ------------------
 1343|     32|        (em[emLen - 1] != 0xbc)) {
  ------------------
  |  Branch (1343:9): [True: 21, False: 11]
  ------------------
 1344|     21|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|     21|#define PORT_SetError PORT_SetError_Util
  ------------------
 1345|     21|        return SECFailure;
 1346|     21|    }
 1347|       |
 1348|       |    /* Step 6 */
 1349|     11|    zeroBits = 8 * emLen - emBits;
 1350|     11|    if (em[0] >> (8 - zeroBits)) {
  ------------------
  |  Branch (1350:9): [True: 4, False: 7]
  ------------------
 1351|      4|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
 1352|      4|        return SECFailure;
 1353|      4|    }
 1354|       |
 1355|       |    /* Step 7 */
 1356|      7|    db = (unsigned char *)PORT_Alloc(dbMaskLen);
  ------------------
  |  |   52|      7|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1357|      7|    if (db == NULL) {
  ------------------
  |  Branch (1357:9): [True: 0, False: 7]
  ------------------
 1358|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1359|      0|        return SECFailure;
 1360|      0|    }
 1361|       |    /* &em[dbMaskLen] points to H, used as mgfSeed */
 1362|      7|    MGF1(maskHashAlg, db, dbMaskLen, &em[dbMaskLen], hash->length);
 1363|       |
 1364|       |    /* Step 8 */
 1365|  1.53k|    for (i = 0; i < dbMaskLen; i++) {
  ------------------
  |  Branch (1365:17): [True: 1.52k, False: 7]
  ------------------
 1366|  1.52k|        db[i] ^= em[i];
 1367|  1.52k|    }
 1368|       |
 1369|       |    /* Step 9 */
 1370|      7|    db[0] &= 0xff >> zeroBits;
 1371|       |
 1372|       |    /* Step 10 */
 1373|    958|    for (i = 0; i < (dbMaskLen - saltLen - 1); i++) {
  ------------------
  |  Branch (1373:17): [True: 953, False: 5]
  ------------------
 1374|    953|        if (db[i] != 0) {
  ------------------
  |  Branch (1374:13): [True: 2, False: 951]
  ------------------
 1375|      2|            PORT_Free(db);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 1376|      2|            PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1377|      2|            return SECFailure;
 1378|      2|        }
 1379|    953|    }
 1380|      5|    if (db[dbMaskLen - saltLen - 1] != 0x01) {
  ------------------
  |  Branch (1380:9): [True: 0, False: 5]
  ------------------
 1381|      0|        PORT_Free(db);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1382|      0|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1383|      0|        return SECFailure;
 1384|      0|    }
 1385|       |
 1386|       |    /* Step 12 + 13 */
 1387|      5|    H_ = (unsigned char *)PORT_Alloc(hash->length);
  ------------------
  |  |   52|      5|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1388|      5|    if (H_ == NULL) {
  ------------------
  |  Branch (1388:9): [True: 0, False: 5]
  ------------------
 1389|      0|        PORT_Free(db);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1390|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1391|      0|        return SECFailure;
 1392|      0|    }
 1393|      5|    hash_context = (*hash->create)();
 1394|      5|    if (hash_context == NULL) {
  ------------------
  |  Branch (1394:9): [True: 0, False: 5]
  ------------------
 1395|      0|        PORT_Free(db);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1396|      0|        PORT_Free(H_);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1397|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1398|      0|        return SECFailure;
 1399|      0|    }
 1400|      5|    (*hash->begin)(hash_context);
 1401|      5|    (*hash->update)(hash_context, eightZeros, 8);
 1402|      5|    (*hash->update)(hash_context, mHash, hash->length);
 1403|      5|    (*hash->update)(hash_context, &db[dbMaskLen - saltLen], saltLen);
 1404|      5|    (*hash->end)(hash_context, H_, &i, hash->length);
 1405|      5|    (*hash->destroy)(hash_context, PR_TRUE);
  ------------------
  |  |  437|      5|#define PR_TRUE 1
  ------------------
 1406|       |
 1407|      5|    PORT_Free(db);
  ------------------
  |  |   60|      5|#define PORT_Free PORT_Free_Util
  ------------------
 1408|       |
 1409|       |    /* Step 14 */
 1410|      5|    if (PORT_Memcmp(H_, &em[dbMaskLen], hash->length) != 0) {
  ------------------
  |  |  179|      5|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (1410:9): [True: 5, False: 0]
  ------------------
 1411|      5|        PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
 1412|      5|        rv = SECFailure;
 1413|      5|    } else {
 1414|      0|        rv = SECSuccess;
 1415|      0|    }
 1416|       |
 1417|      5|    PORT_Free(H_);
  ------------------
  |  |   60|      5|#define PORT_Free PORT_Free_Util
  ------------------
 1418|      5|    return rv;
 1419|      5|}

SHA256_Compress_Native:
   55|  1.49M|{
   56|  1.49M|    __m128i h0, h1, th;
   57|  1.49M|    __m128i a, b, c, d;
   58|  1.49M|    __m128i w0, w1;
   59|  1.49M|    const __m128i shuffle = _mm_set_epi8(12, 13, 14, 15, 8, 9, 10, 11, 4, 5, 6, 7, 0, 1, 2, 3);
   60|       |
   61|  1.49M|    const __m128i *K = (__m128i *)K256;
   62|  1.49M|    const __m128i k0 = _mm_load_si128(K);
   63|  1.49M|    const __m128i k1 = _mm_load_si128(K + 1);
   64|  1.49M|    const __m128i k2 = _mm_load_si128(K + 2);
   65|  1.49M|    const __m128i k3 = _mm_load_si128(K + 3);
   66|  1.49M|    const __m128i k4 = _mm_load_si128(K + 4);
   67|  1.49M|    const __m128i k5 = _mm_load_si128(K + 5);
   68|  1.49M|    const __m128i k6 = _mm_load_si128(K + 6);
   69|  1.49M|    const __m128i k7 = _mm_load_si128(K + 7);
   70|  1.49M|    const __m128i k8 = _mm_load_si128(K + 8);
   71|  1.49M|    const __m128i k9 = _mm_load_si128(K + 9);
   72|  1.49M|    const __m128i k10 = _mm_load_si128(K + 10);
   73|  1.49M|    const __m128i k11 = _mm_load_si128(K + 11);
   74|  1.49M|    const __m128i k12 = _mm_load_si128(K + 12);
   75|  1.49M|    const __m128i k13 = _mm_load_si128(K + 13);
   76|  1.49M|    const __m128i k14 = _mm_load_si128(K + 14);
   77|  1.49M|    const __m128i k15 = _mm_load_si128(K + 15);
   78|       |
   79|  1.49M|    const __m128i *input = (__m128i *)ctx->u.b;
   80|       |
   81|  1.49M|    h0 = _mm_loadu_si128((__m128i *)(ctx->h));
   82|  1.49M|    h1 = _mm_loadu_si128((__m128i *)(ctx->h + 4));
   83|       |
   84|       |    /* H0123:4567 -> H01256:H2367 */
   85|  1.49M|    th = _mm_shuffle_epi32(h0, 0xb1);
   86|  1.49M|    h1 = _mm_shuffle_epi32(h1, 0x1b);
   87|  1.49M|    h0 = _mm_alignr_epi8(th, h1, 8);
   88|  1.49M|    h1 = _mm_blend_epi16(h1, th, 0xf0);
   89|       |
   90|  1.49M|    a = _mm_shuffle_epi8(_mm_loadu_si128(input), shuffle);
   91|  1.49M|    b = _mm_shuffle_epi8(_mm_loadu_si128(input + 1), shuffle);
   92|  1.49M|    c = _mm_shuffle_epi8(_mm_loadu_si128(input + 2), shuffle);
   93|  1.49M|    d = _mm_shuffle_epi8(_mm_loadu_si128(input + 3), shuffle);
   94|       |
   95|  1.49M|    w0 = h0;
   96|  1.49M|    w1 = h1;
   97|       |
   98|  1.49M|    ROUND(0, a, b, c, d)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
   99|  1.49M|    ROUND(1, b, c, d, a)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  100|  1.49M|    ROUND(2, c, d, a, b)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  101|  1.49M|    ROUND(3, d, a, b, c)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  102|  1.49M|    ROUND(4, a, b, c, d)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  103|  1.49M|    ROUND(5, b, c, d, a)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  104|  1.49M|    ROUND(6, c, d, a, b)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  105|  1.49M|    ROUND(7, d, a, b, c)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  106|  1.49M|    ROUND(8, a, b, c, d)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  107|  1.49M|    ROUND(9, b, c, d, a)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  108|  1.49M|    ROUND(10, c, d, a, b)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  109|  1.49M|    ROUND(11, d, a, b, c)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  1.49M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  1.49M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  1.49M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  1.49M|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  110|  1.49M|    ROUND(12, a, b, c, d)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  111|  1.49M|    ROUND(13, b, c, d, a)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  112|  1.49M|    ROUND(14, c, d, a, b)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  113|  1.49M|    ROUND(15, d, a, b, c)
  ------------------
  |  |   41|  1.49M|    {                                                       \
  |  |   42|  1.49M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  1.49M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  1.49M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  1.49M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  1.49M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  1.49M|    }
  ------------------
  114|       |
  115|  1.49M|    h0 = _mm_add_epi32(h0, w0);
  116|  1.49M|    h1 = _mm_add_epi32(h1, w1);
  117|       |
  118|       |    /* H0145:2367 -> H0123:4567 */
  119|  1.49M|    th = _mm_shuffle_epi32(h0, 0x1b);
  120|  1.49M|    h1 = _mm_shuffle_epi32(h1, 0xb1);
  121|  1.49M|    h0 = _mm_blend_epi16(th, h1, 0xf0);
  122|  1.49M|    h1 = _mm_alignr_epi8(h1, th, 8);
  123|       |
  124|  1.49M|    _mm_storeu_si128((__m128i *)ctx->h, h0);
  125|  1.49M|    _mm_storeu_si128((__m128i *)(ctx->h + 4), h1);
  126|  1.49M|}
SHA256_Update_Native:
  131|  4.13M|{
  132|  4.13M|    __m128i h0, h1, th;
  133|  4.13M|    const __m128i shuffle = _mm_set_epi8(12, 13, 14, 15, 8, 9, 10, 11, 4, 5, 6, 7, 0, 1, 2, 3);
  134|       |
  135|  4.13M|    const __m128i *K = (__m128i *)K256;
  136|  4.13M|    const __m128i k0 = _mm_load_si128(K);
  137|  4.13M|    const __m128i k1 = _mm_load_si128(K + 1);
  138|  4.13M|    const __m128i k2 = _mm_load_si128(K + 2);
  139|  4.13M|    const __m128i k3 = _mm_load_si128(K + 3);
  140|  4.13M|    const __m128i k4 = _mm_load_si128(K + 4);
  141|  4.13M|    const __m128i k5 = _mm_load_si128(K + 5);
  142|  4.13M|    const __m128i k6 = _mm_load_si128(K + 6);
  143|  4.13M|    const __m128i k7 = _mm_load_si128(K + 7);
  144|  4.13M|    const __m128i k8 = _mm_load_si128(K + 8);
  145|  4.13M|    const __m128i k9 = _mm_load_si128(K + 9);
  146|  4.13M|    const __m128i k10 = _mm_load_si128(K + 10);
  147|  4.13M|    const __m128i k11 = _mm_load_si128(K + 11);
  148|  4.13M|    const __m128i k12 = _mm_load_si128(K + 12);
  149|  4.13M|    const __m128i k13 = _mm_load_si128(K + 13);
  150|  4.13M|    const __m128i k14 = _mm_load_si128(K + 14);
  151|  4.13M|    const __m128i k15 = _mm_load_si128(K + 15);
  152|       |
  153|  4.13M|    unsigned int inBuf = ctx->sizeLo & 0x3f;
  154|  4.13M|    if (!inputLen) {
  ------------------
  |  Branch (154:9): [True: 49.5k, False: 4.08M]
  ------------------
  155|  49.5k|        return;
  156|  49.5k|    }
  157|       |
  158|       |    /* Add inputLen into the count of bytes processed, before processing */
  159|  4.08M|    if ((ctx->sizeLo += inputLen) < inputLen) {
  ------------------
  |  Branch (159:9): [True: 0, False: 4.08M]
  ------------------
  160|      0|        ctx->sizeHi++;
  161|      0|    }
  162|       |
  163|       |    /* if data already in buffer, attempt to fill rest of buffer */
  164|  4.08M|    if (inBuf) {
  ------------------
  |  Branch (164:9): [True: 1.71M, False: 2.37M]
  ------------------
  165|  1.71M|        unsigned int todo = SHA256_BLOCK_LENGTH - inBuf;
  ------------------
  |  |  120|  1.71M|#define SHA256_BLOCK_LENGTH 64    /* bytes */
  ------------------
  166|  1.71M|        if (inputLen < todo) {
  ------------------
  |  Branch (166:13): [True: 1.43M, False: 272k]
  ------------------
  167|  1.43M|            todo = inputLen;
  168|  1.43M|        }
  169|  1.71M|        memcpy(ctx->u.b + inBuf, input, todo);
  170|  1.71M|        input += todo;
  171|  1.71M|        inputLen -= todo;
  172|  1.71M|        if (inBuf + todo == SHA256_BLOCK_LENGTH) {
  ------------------
  |  |  120|  1.71M|#define SHA256_BLOCK_LENGTH 64    /* bytes */
  ------------------
  |  Branch (172:13): [True: 272k, False: 1.43M]
  ------------------
  173|   272k|            SHA256_Compress_Native(ctx);
  174|   272k|        }
  175|  1.71M|    }
  176|       |
  177|  4.08M|    h0 = _mm_loadu_si128((__m128i *)(ctx->h));
  178|  4.08M|    h1 = _mm_loadu_si128((__m128i *)(ctx->h + 4));
  179|       |
  180|       |    /* H0123:4567 -> H01256:H2367 */
  181|  4.08M|    th = _mm_shuffle_epi32(h0, 0xb1);
  182|  4.08M|    h1 = _mm_shuffle_epi32(h1, 0x1b);
  183|  4.08M|    h0 = _mm_alignr_epi8(th, h1, 8);
  184|  4.08M|    h1 = _mm_blend_epi16(h1, th, 0xf0);
  185|       |
  186|       |    /* if enough data to fill one or more whole buffers, process them. */
  187|  6.83M|    while (inputLen >= SHA256_BLOCK_LENGTH) {
  ------------------
  |  |  120|  6.83M|#define SHA256_BLOCK_LENGTH 64    /* bytes */
  ------------------
  |  Branch (187:12): [True: 2.75M, False: 4.08M]
  ------------------
  188|  2.75M|        __m128i a, b, c, d;
  189|  2.75M|        __m128i w0, w1;
  190|  2.75M|        a = _mm_shuffle_epi8(_mm_loadu_si128((__m128i *)input), shuffle);
  191|  2.75M|        b = _mm_shuffle_epi8(_mm_loadu_si128((__m128i *)(input + 16)), shuffle);
  192|  2.75M|        c = _mm_shuffle_epi8(_mm_loadu_si128((__m128i *)(input + 32)), shuffle);
  193|  2.75M|        d = _mm_shuffle_epi8(_mm_loadu_si128((__m128i *)(input + 48)), shuffle);
  194|  2.75M|        input += SHA256_BLOCK_LENGTH;
  ------------------
  |  |  120|  2.75M|#define SHA256_BLOCK_LENGTH 64    /* bytes */
  ------------------
  195|  2.75M|        inputLen -= SHA256_BLOCK_LENGTH;
  ------------------
  |  |  120|  2.75M|#define SHA256_BLOCK_LENGTH 64    /* bytes */
  ------------------
  196|       |
  197|  2.75M|        w0 = h0;
  198|  2.75M|        w1 = h1;
  199|       |
  200|  2.75M|        ROUND(0, a, b, c, d)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  201|  2.75M|        ROUND(1, b, c, d, a)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  202|  2.75M|        ROUND(2, c, d, a, b)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  203|  2.75M|        ROUND(3, d, a, b, c)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  204|  2.75M|        ROUND(4, a, b, c, d)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  205|  2.75M|        ROUND(5, b, c, d, a)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  206|  2.75M|        ROUND(6, c, d, a, b)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  207|  2.75M|        ROUND(7, d, a, b, c)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  208|  2.75M|        ROUND(8, a, b, c, d)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  209|  2.75M|        ROUND(9, b, c, d, a)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  210|  2.75M|        ROUND(10, c, d, a, b)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  211|  2.75M|        ROUND(11, d, a, b, c)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|  2.75M|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|  2.75M|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|  2.75M|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|  2.75M|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  212|  2.75M|        ROUND(12, a, b, c, d)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  213|  2.75M|        ROUND(13, b, c, d, a)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  214|  2.75M|        ROUND(14, c, d, a, b)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  215|  2.75M|        ROUND(15, d, a, b, c)
  ------------------
  |  |   41|  2.75M|    {                                                       \
  |  |   42|  2.75M|        __m128i t = _mm_add_epi32(a, k##n);                 \
  |  |   43|  2.75M|        w1 = _mm_sha256rnds2_epu32(w1, w0, t);              \
  |  |   44|  2.75M|        t = _mm_shuffle_epi32(t, 0x0e);                     \
  |  |   45|  2.75M|        w0 = _mm_sha256rnds2_epu32(w0, w1, t);              \
  |  |   46|  2.75M|        if (n < 12) {                                       \
  |  |  ------------------
  |  |  |  Branch (46:13): [Folded - Ignored]
  |  |  ------------------
  |  |   47|      0|            a = _mm_sha256msg1_epu32(a, b);                 \
  |  |   48|      0|            a = _mm_add_epi32(a, _mm_alignr_epi8(d, c, 4)); \
  |  |   49|      0|            a = _mm_sha256msg2_epu32(a, d);                 \
  |  |   50|      0|        }                                                   \
  |  |   51|  2.75M|    }
  ------------------
  216|       |
  217|  2.75M|        h0 = _mm_add_epi32(h0, w0);
  218|  2.75M|        h1 = _mm_add_epi32(h1, w1);
  219|  2.75M|    }
  220|       |
  221|       |    // H01234567 -> H01256 and H2367
  222|  4.08M|    th = _mm_shuffle_epi32(h0, 0x1b);
  223|  4.08M|    h1 = _mm_shuffle_epi32(h1, 0xb1);
  224|  4.08M|    h0 = _mm_blend_epi16(th, h1, 0xf0);
  225|  4.08M|    h1 = _mm_alignr_epi8(h1, th, 8);
  226|       |
  227|  4.08M|    _mm_storeu_si128((__m128i *)ctx->h, h0);
  228|  4.08M|    _mm_storeu_si128((__m128i *)(ctx->h + 4), h1);
  229|       |
  230|       |    /* if data left over, fill it into buffer */
  231|  4.08M|    if (inputLen) {
  ------------------
  |  Branch (231:9): [True: 1.49M, False: 2.59M]
  ------------------
  232|  1.49M|        memcpy(ctx->u.b, input, inputLen);
  233|  1.49M|    }
  234|  4.08M|}

SHA256_NewContext:
  186|   215k|{
  187|   215k|    SHA256Context *ctx = PORT_New(SHA256Context);
  ------------------
  |  |  151|   215k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|   215k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  188|   215k|    return ctx;
  189|   215k|}
SHA256_DestroyContext:
  193|   215k|{
  194|   215k|    memset(ctx, 0, sizeof *ctx);
  195|   215k|    if (freeit) {
  ------------------
  |  Branch (195:9): [True: 215k, False: 0]
  ------------------
  196|   215k|        PORT_Free(ctx);
  ------------------
  |  |   60|   215k|#define PORT_Free PORT_Free_Util
  ------------------
  197|   215k|    }
  198|   215k|}
SHA256_Begin:
  202|  1.23M|{
  203|  1.23M|    PRBool use_hw_sha2 = PR_FALSE;
  ------------------
  |  |  438|  1.23M|#define PR_FALSE 0
  ------------------
  204|       |
  205|  1.23M|    memset(ctx, 0, sizeof *ctx);
  206|  1.23M|    memcpy(H, H256, sizeof H256);
  ------------------
  |  |   31|  1.23M|#define H ctx->h
  ------------------
  207|       |
  208|  1.23M|#if defined(USE_HW_SHA2) && defined(IS_LITTLE_ENDIAN)
  209|       |    /* arm's implementation is tested on little endian only */
  210|  1.23M|    use_hw_sha2 = arm_sha2_support() || (sha_support() && ssse3_support() && sse4_1_support());
  ------------------
  |  Branch (210:19): [True: 0, False: 1.23M]
  |  Branch (210:42): [True: 1.23M, False: 0]
  |  Branch (210:59): [True: 1.23M, False: 0]
  |  Branch (210:78): [True: 1.23M, False: 0]
  ------------------
  211|  1.23M|#endif
  212|       |
  213|  1.23M|    if (use_hw_sha2) {
  ------------------
  |  Branch (213:9): [True: 1.23M, False: 0]
  ------------------
  214|  1.23M|        ctx->compress = SHA256_Compress_Native;
  215|  1.23M|        ctx->update = SHA256_Update_Native;
  216|  1.23M|    } else {
  217|      0|        ctx->compress = SHA256_Compress_Generic;
  218|      0|        ctx->update = SHA256_Update_Generic;
  219|      0|    }
  220|  1.23M|}
SHA256_Update:
  517|  2.91M|{
  518|  2.91M|    ctx->update(ctx, input, inputLen);
  519|  2.91M|}
SHA256_End:
  560|  1.22M|{
  561|  1.22M|    unsigned int inBuf = ctx->sizeLo & 0x3f;
  562|  1.22M|    unsigned int padLen = (inBuf < 56) ? (56 - inBuf) : (56 + 64 - inBuf);
  ------------------
  |  Branch (562:27): [True: 1.22M, False: 2.33k]
  ------------------
  563|  1.22M|    PRUint32 hi, lo;
  564|       |
  565|  1.22M|    hi = (ctx->sizeHi << 3) | (ctx->sizeLo >> 29);
  566|  1.22M|    lo = (ctx->sizeLo << 3);
  567|       |
  568|  1.22M|    ctx->update(ctx, pad, padLen);
  569|       |
  570|  1.22M|#if defined(IS_LITTLE_ENDIAN)
  571|  1.22M|    W[14] = SHA_HTONL(hi);
  ------------------
  |  |   29|  1.22M|#define W ctx->u.w
  ------------------
                  W[14] = SHA_HTONL(hi);
  ------------------
  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  ------------------
  572|  1.22M|    W[15] = SHA_HTONL(lo);
  ------------------
  |  |   29|  1.22M|#define W ctx->u.w
  ------------------
                  W[15] = SHA_HTONL(lo);
  ------------------
  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  ------------------
  573|       |#else
  574|       |    W[14] = hi;
  575|       |    W[15] = lo;
  576|       |#endif
  577|  1.22M|    ctx->compress(ctx);
  578|       |
  579|       |/* now output the answer */
  580|  1.22M|#if defined(IS_LITTLE_ENDIAN)
  581|  1.22M|    BYTESWAP4(H[0]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  582|  1.22M|    BYTESWAP4(H[1]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  583|  1.22M|    BYTESWAP4(H[2]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  584|  1.22M|    BYTESWAP4(H[3]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  585|  1.22M|    BYTESWAP4(H[4]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  586|  1.22M|    BYTESWAP4(H[5]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  587|  1.22M|    BYTESWAP4(H[6]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  588|  1.22M|    BYTESWAP4(H[7]);
  ------------------
  |  |  142|  1.22M|#define BYTESWAP4(x) x = SHA_HTONL(x)
  |  |  ------------------
  |  |  |  |  108|  1.22M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  589|  1.22M|#endif
  590|  1.22M|    padLen = PR_MIN(SHA256_LENGTH, maxDigestLen);
  ------------------
  |  |  158|  1.22M|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 1.14M, False: 81.3k]
  |  |  ------------------
  ------------------
  591|  1.22M|    memcpy(digest, H, padLen);
  ------------------
  |  |   31|  1.22M|#define H ctx->h
  ------------------
  592|  1.22M|    if (digestLen)
  ------------------
  |  Branch (592:9): [True: 1.22M, False: 0]
  ------------------
  593|  1.22M|        *digestLen = padLen;
  594|  1.22M|}
SHA256_FlattenSize:
  650|  69.6k|{
  651|  69.6k|    return sizeof *ctx;
  652|  69.6k|}
SHA512_NewContext:
  962|   977k|{
  963|   977k|    SHA512Context *ctx = PORT_New(SHA512Context);
  ------------------
  |  |  151|   977k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|   977k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  964|   977k|    return ctx;
  965|   977k|}
SHA512_DestroyContext:
  969|   977k|{
  970|   977k|    memset(ctx, 0, sizeof *ctx);
  971|   977k|    if (freeit) {
  ------------------
  |  Branch (971:9): [True: 977k, False: 0]
  ------------------
  972|   977k|        PORT_Free(ctx);
  ------------------
  |  |   60|   977k|#define PORT_Free PORT_Free_Util
  ------------------
  973|   977k|    }
  974|   977k|}
SHA512_Begin:
  978|  19.9k|{
  979|  19.9k|    memset(ctx, 0, sizeof *ctx);
  980|  19.9k|    memcpy(H, H512, sizeof H512);
  ------------------
  |  |   31|  19.9k|#define H ctx->h
  ------------------
  981|  19.9k|}
SHA512_Update:
 1340|  8.05M|{
 1341|  8.05M|    unsigned int inBuf;
 1342|  8.05M|    if (!inputLen)
  ------------------
  |  Branch (1342:9): [True: 43.5k, False: 8.00M]
  ------------------
 1343|  43.5k|        return;
 1344|       |
 1345|  8.00M|#if defined(HAVE_LONG_LONG)
 1346|  8.00M|    inBuf = (unsigned int)ctx->sizeLo & 0x7f;
 1347|       |    /* Add inputLen into the count of bytes processed, before processing */
 1348|  8.00M|    ctx->sizeLo += inputLen;
 1349|       |#else
 1350|       |    inBuf = (unsigned int)ctx->sizeLo.lo & 0x7f;
 1351|       |    ctx->sizeLo.lo += inputLen;
 1352|       |    if (ctx->sizeLo.lo < inputLen)
 1353|       |        ctx->sizeLo.hi++;
 1354|       |#endif
 1355|       |
 1356|       |    /* if data already in buffer, attemp to fill rest of buffer */
 1357|  8.00M|    if (inBuf) {
  ------------------
  |  Branch (1357:9): [True: 3.39M, False: 4.61M]
  ------------------
 1358|  3.39M|        unsigned int todo = SHA512_BLOCK_LENGTH - inBuf;
  ------------------
  |  |  122|  3.39M|#define SHA512_BLOCK_LENGTH 128   /* bytes */
  ------------------
 1359|  3.39M|        if (inputLen < todo)
  ------------------
  |  Branch (1359:13): [True: 3.32M, False: 73.3k]
  ------------------
 1360|  3.32M|            todo = inputLen;
 1361|  3.39M|        memcpy(B + inBuf, input, todo);
  ------------------
  |  |   30|  3.39M|#define B ctx->u.b
  ------------------
 1362|  3.39M|        input += todo;
 1363|  3.39M|        inputLen -= todo;
 1364|  3.39M|        if (inBuf + todo == SHA512_BLOCK_LENGTH)
  ------------------
  |  |  122|  3.39M|#define SHA512_BLOCK_LENGTH 128   /* bytes */
  ------------------
  |  Branch (1364:13): [True: 73.3k, False: 3.32M]
  ------------------
 1365|  73.3k|            SHA512_Compress(ctx);
 1366|  3.39M|    }
 1367|       |
 1368|       |    /* if enough data to fill one or more whole buffers, process them. */
 1369|  10.8M|    while (inputLen >= SHA512_BLOCK_LENGTH) {
  ------------------
  |  |  122|  10.8M|#define SHA512_BLOCK_LENGTH 128   /* bytes */
  ------------------
  |  Branch (1369:12): [True: 2.83M, False: 8.00M]
  ------------------
 1370|  2.83M|        memcpy(B, input, SHA512_BLOCK_LENGTH);
  ------------------
  |  |   30|  2.83M|#define B ctx->u.b
  ------------------
                      memcpy(B, input, SHA512_BLOCK_LENGTH);
  ------------------
  |  |  122|  2.83M|#define SHA512_BLOCK_LENGTH 128   /* bytes */
  ------------------
 1371|  2.83M|        input += SHA512_BLOCK_LENGTH;
  ------------------
  |  |  122|  2.83M|#define SHA512_BLOCK_LENGTH 128   /* bytes */
  ------------------
 1372|  2.83M|        inputLen -= SHA512_BLOCK_LENGTH;
  ------------------
  |  |  122|  2.83M|#define SHA512_BLOCK_LENGTH 128   /* bytes */
  ------------------
 1373|  2.83M|        SHA512_Compress(ctx);
 1374|  2.83M|    }
 1375|       |    /* if data left over, fill it into buffer */
 1376|  8.00M|    if (inputLen)
  ------------------
  |  Branch (1376:9): [True: 2.41M, False: 5.59M]
  ------------------
 1377|  2.41M|        memcpy(B, input, inputLen);
  ------------------
  |  |   30|  2.41M|#define B ctx->u.b
  ------------------
 1378|  8.00M|}
SHA512_End:
 1383|  2.34M|{
 1384|  2.34M|#if defined(HAVE_LONG_LONG)
 1385|  2.34M|    unsigned int inBuf = (unsigned int)ctx->sizeLo & 0x7f;
 1386|       |#else
 1387|       |    unsigned int inBuf = (unsigned int)ctx->sizeLo.lo & 0x7f;
 1388|       |#endif
 1389|  2.34M|    unsigned int padLen = (inBuf < 112) ? (112 - inBuf) : (112 + 128 - inBuf);
  ------------------
  |  Branch (1389:27): [True: 2.27M, False: 67.1k]
  ------------------
 1390|  2.34M|    PRUint64 lo;
 1391|  2.34M|    LL_SHL(lo, ctx->sizeLo, 3);
  ------------------
  |  |  127|  2.34M|#define LL_SHL(r, a, b)     ((r) = (PRInt64)(a) << (b))
  ------------------
 1392|       |
 1393|  2.34M|    SHA512_Update(ctx, pad, padLen);
 1394|       |
 1395|  2.34M|#if defined(HAVE_LONG_LONG)
 1396|  2.34M|    W[14] = 0;
  ------------------
  |  |   29|  2.34M|#define W ctx->u.w
  ------------------
 1397|       |#else
 1398|       |    W[14].lo = 0;
 1399|       |    W[14].hi = 0;
 1400|       |#endif
 1401|       |
 1402|  2.34M|    W[15] = lo;
  ------------------
  |  |   29|  2.34M|#define W ctx->u.w
  ------------------
 1403|  2.34M|#if defined(IS_LITTLE_ENDIAN)
 1404|  2.34M|    BYTESWAP8(W[15]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1405|  2.34M|#endif
 1406|  2.34M|    SHA512_Compress(ctx);
 1407|       |
 1408|       |/* now output the answer */
 1409|  2.34M|#if defined(IS_LITTLE_ENDIAN)
 1410|  2.34M|    BYTESWAP8(H[0]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1411|  2.34M|    BYTESWAP8(H[1]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1412|  2.34M|    BYTESWAP8(H[2]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1413|  2.34M|    BYTESWAP8(H[3]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1414|  2.34M|    BYTESWAP8(H[4]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1415|  2.34M|    BYTESWAP8(H[5]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1416|  2.34M|    BYTESWAP8(H[6]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1417|  2.34M|    BYTESWAP8(H[7]);
  ------------------
  |  |  810|  2.34M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  2.34M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1418|  2.34M|#endif
 1419|  2.34M|    padLen = PR_MIN(SHA512_LENGTH, maxDigestLen);
  ------------------
  |  |  158|  2.34M|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 2.34M]
  |  |  ------------------
  ------------------
 1420|  2.34M|    memcpy(digest, H, padLen);
  ------------------
  |  |   31|  2.34M|#define H ctx->h
  ------------------
 1421|  2.34M|    if (digestLen)
  ------------------
  |  Branch (1421:9): [True: 2.34M, False: 0]
  ------------------
 1422|  2.34M|        *digestLen = padLen;
 1423|  2.34M|}
SHA512_FlattenSize:
 1478|  5.85k|{
 1479|  5.85k|    return sizeof *ctx;
 1480|  5.85k|}
SHA384_NewContext:
 1528|   965k|{
 1529|   965k|    return SHA512_NewContext();
 1530|   965k|}
SHA384_DestroyContext:
 1534|   965k|{
 1535|   965k|    SHA512_DestroyContext(ctx, freeit);
 1536|   965k|}
SHA384_Begin:
 1540|  2.32M|{
 1541|  2.32M|    memset(ctx, 0, sizeof *ctx);
 1542|  2.32M|    memcpy(H, H384, sizeof H384);
  ------------------
  |  |   31|  2.32M|#define H ctx->h
  ------------------
 1543|  2.32M|}
SHA384_Update:
 1548|  5.67M|{
 1549|  5.67M|    SHA512_Update(ctx, input, inputLen);
 1550|  5.67M|}
SHA384_End:
 1555|  2.32M|{
 1556|  2.32M|    unsigned int maxLen = SHA_MIN(maxDigestLen, SHA384_LENGTH);
  ------------------
  |  |   37|  2.32M|#define SHA_MIN(a, b) (a < b ? a : b)
  |  |  ------------------
  |  |  |  Branch (37:24): [True: 0, False: 2.32M]
  |  |  ------------------
  ------------------
 1557|  2.32M|    SHA512_End(ctx, digest, digestLen, maxLen);
 1558|  2.32M|}
SHA384_FlattenSize:
 1596|  55.4k|{
 1597|  55.4k|    return sizeof(SHA384Context);
 1598|  55.4k|}
sha512.c:swap4b:
  103|  12.2M|{
  104|  12.2M|    __asm__("bswap %0"
  105|  12.2M|            : "+r"(value));
  106|  12.2M|    return (value);
  107|  12.2M|}
sha512.c:SHA512_Compress:
 1086|  5.24M|{
 1087|       |#if defined(USE_PPC_CRYPTO)
 1088|       |    sha512_block_p8(&H[0], &W[0], 1);
 1089|       |#else /* USE_PPC_CRYPTO */
 1090|       |
 1091|  5.24M|#if defined(IS_LITTLE_ENDIAN)
 1092|  5.24M|    {
 1093|  5.24M|        BYTESWAP8(W[0]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1094|  5.24M|        BYTESWAP8(W[1]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1095|  5.24M|        BYTESWAP8(W[2]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1096|  5.24M|        BYTESWAP8(W[3]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1097|  5.24M|        BYTESWAP8(W[4]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1098|  5.24M|        BYTESWAP8(W[5]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1099|  5.24M|        BYTESWAP8(W[6]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1100|  5.24M|        BYTESWAP8(W[7]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1101|  5.24M|        BYTESWAP8(W[8]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1102|  5.24M|        BYTESWAP8(W[9]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1103|  5.24M|        BYTESWAP8(W[10]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1104|  5.24M|        BYTESWAP8(W[11]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1105|  5.24M|        BYTESWAP8(W[12]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1106|  5.24M|        BYTESWAP8(W[13]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1107|  5.24M|        BYTESWAP8(W[14]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1108|  5.24M|        BYTESWAP8(W[15]);
  ------------------
  |  |  810|  5.24M|#define BYTESWAP8(x) x = FREEBL_HTONLL(x)
  |  |  ------------------
  |  |  |  |   46|  5.24M|#define FREEBL_HTONLL(x) __builtin_bswap64(x)
  |  |  ------------------
  ------------------
 1109|  5.24M|    }
 1110|  5.24M|#endif
 1111|       |
 1112|  5.24M|    {
 1113|       |#ifdef NOUNROLL512
 1114|       |        {
 1115|       |            /* prepare the "message schedule"   */
 1116|       |            int t;
 1117|       |            for (t = 16; t < 80; ++t) {
 1118|       |                INITW(t);
 1119|       |            }
 1120|       |        }
 1121|       |#else
 1122|  5.24M|        INITW(16);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1123|  5.24M|        INITW(17);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1124|  5.24M|        INITW(18);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1125|  5.24M|        INITW(19);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1126|       |
 1127|  5.24M|        INITW(20);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1128|  5.24M|        INITW(21);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1129|  5.24M|        INITW(22);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1130|  5.24M|        INITW(23);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1131|  5.24M|        INITW(24);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1132|  5.24M|        INITW(25);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1133|  5.24M|        INITW(26);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1134|  5.24M|        INITW(27);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1135|  5.24M|        INITW(28);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1136|  5.24M|        INITW(29);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1137|       |
 1138|  5.24M|        INITW(30);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1139|  5.24M|        INITW(31);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1140|  5.24M|        INITW(32);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1141|  5.24M|        INITW(33);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1142|  5.24M|        INITW(34);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1143|  5.24M|        INITW(35);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1144|  5.24M|        INITW(36);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1145|  5.24M|        INITW(37);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1146|  5.24M|        INITW(38);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1147|  5.24M|        INITW(39);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1148|       |
 1149|  5.24M|        INITW(40);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1150|  5.24M|        INITW(41);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1151|  5.24M|        INITW(42);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1152|  5.24M|        INITW(43);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1153|  5.24M|        INITW(44);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1154|  5.24M|        INITW(45);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1155|  5.24M|        INITW(46);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1156|  5.24M|        INITW(47);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1157|  5.24M|        INITW(48);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1158|  5.24M|        INITW(49);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1159|       |
 1160|  5.24M|        INITW(50);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1161|  5.24M|        INITW(51);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1162|  5.24M|        INITW(52);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1163|  5.24M|        INITW(53);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1164|  5.24M|        INITW(54);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1165|  5.24M|        INITW(55);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1166|  5.24M|        INITW(56);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1167|  5.24M|        INITW(57);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1168|  5.24M|        INITW(58);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1169|  5.24M|        INITW(59);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1170|       |
 1171|  5.24M|        INITW(60);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1172|  5.24M|        INITW(61);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1173|  5.24M|        INITW(62);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1174|  5.24M|        INITW(63);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1175|  5.24M|        INITW(64);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1176|  5.24M|        INITW(65);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1177|  5.24M|        INITW(66);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1178|  5.24M|        INITW(67);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1179|  5.24M|        INITW(68);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1180|  5.24M|        INITW(69);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1181|       |
 1182|  5.24M|        INITW(70);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1183|  5.24M|        INITW(71);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1184|  5.24M|        INITW(72);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1185|  5.24M|        INITW(73);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1186|  5.24M|        INITW(74);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1187|  5.24M|        INITW(75);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1188|  5.24M|        INITW(76);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1189|  5.24M|        INITW(77);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1190|  5.24M|        INITW(78);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1191|  5.24M|        INITW(79);
  ------------------
  |  |  999|  5.24M|#define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  800|  5.24M|#define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s1(x) (ROTR64(x, 19) ^ ROTR64(x, 61) ^ SHR(x, 6))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |  799|  5.24M|#define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define s0(x) (ROTR64(x, 1) ^ ROTR64(x, 8) ^ SHR(x, 7))
  |  |  |  |  ------------------
  |  |  |  |  |  |   33|  5.24M|#define SHR(x, n) (x >> n)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define INITW(t) W[t] = (s1(W[t - 2]) + W[t - 7] + s0(W[t - 15]) + W[t - 16])
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  ------------------
 1192|  5.24M|#endif
 1193|  5.24M|    }
 1194|       |#ifdef SHA512_TRACE
 1195|       |    {
 1196|       |        int i;
 1197|       |        for (i = 0; i < 80; ++i) {
 1198|       |#ifdef HAVE_LONG_LONG
 1199|       |            printf("W[%2d] = %016lx\n", i, W[i]);
 1200|       |#else
 1201|       |            printf("W[%2d] = %08x%08x\n", i, W[i].hi, W[i].lo);
 1202|       |#endif
 1203|       |        }
 1204|       |    }
 1205|       |#endif
 1206|  5.24M|    {
 1207|  5.24M|        PRUint64 a, b, c, d, e, f, g, h;
 1208|       |
 1209|  5.24M|        a = H[0];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1210|  5.24M|        b = H[1];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1211|  5.24M|        c = H[2];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1212|  5.24M|        d = H[3];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1213|  5.24M|        e = H[4];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1214|  5.24M|        f = H[5];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1215|  5.24M|        g = H[6];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1216|  5.24M|        h = H[7];
  ------------------
  |  |   31|  5.24M|#define H ctx->h
  ------------------
 1217|       |
 1218|       |#ifdef NOUNROLL512
 1219|       |        {
 1220|       |            int t;
 1221|       |            for (t = 0; t < 80; t += 8) {
 1222|       |                ROUND(t + 0, a, b, c, d, e, f, g, h)
 1223|       |                ROUND(t + 1, h, a, b, c, d, e, f, g)
 1224|       |                ROUND(t + 2, g, h, a, b, c, d, e, f)
 1225|       |                ROUND(t + 3, f, g, h, a, b, c, d, e)
 1226|       |                ROUND(t + 4, e, f, g, h, a, b, c, d)
 1227|       |                ROUND(t + 5, d, e, f, g, h, a, b, c)
 1228|       |                ROUND(t + 6, c, d, e, f, g, h, a, b)
 1229|       |                ROUND(t + 7, b, c, d, e, f, g, h, a)
 1230|       |            }
 1231|       |        }
 1232|       |#else
 1233|  5.24M|        ROUND(0, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1234|  5.24M|        ROUND(1, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1235|  5.24M|        ROUND(2, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1236|  5.24M|        ROUND(3, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1237|  5.24M|        ROUND(4, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1238|  5.24M|        ROUND(5, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1239|  5.24M|        ROUND(6, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1240|  5.24M|        ROUND(7, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1241|       |
 1242|  5.24M|        ROUND(8, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1243|  5.24M|        ROUND(9, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1244|  5.24M|        ROUND(10, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1245|  5.24M|        ROUND(11, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1246|  5.24M|        ROUND(12, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1247|  5.24M|        ROUND(13, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1248|  5.24M|        ROUND(14, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1249|  5.24M|        ROUND(15, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1250|       |
 1251|  5.24M|        ROUND(16, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1252|  5.24M|        ROUND(17, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1253|  5.24M|        ROUND(18, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1254|  5.24M|        ROUND(19, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1255|  5.24M|        ROUND(20, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1256|  5.24M|        ROUND(21, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1257|  5.24M|        ROUND(22, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1258|  5.24M|        ROUND(23, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1259|       |
 1260|  5.24M|        ROUND(24, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1261|  5.24M|        ROUND(25, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1262|  5.24M|        ROUND(26, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1263|  5.24M|        ROUND(27, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1264|  5.24M|        ROUND(28, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1265|  5.24M|        ROUND(29, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1266|  5.24M|        ROUND(30, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1267|  5.24M|        ROUND(31, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1268|       |
 1269|  5.24M|        ROUND(32, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1270|  5.24M|        ROUND(33, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1271|  5.24M|        ROUND(34, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1272|  5.24M|        ROUND(35, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1273|  5.24M|        ROUND(36, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1274|  5.24M|        ROUND(37, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1275|  5.24M|        ROUND(38, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1276|  5.24M|        ROUND(39, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1277|       |
 1278|  5.24M|        ROUND(40, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1279|  5.24M|        ROUND(41, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1280|  5.24M|        ROUND(42, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1281|  5.24M|        ROUND(43, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1282|  5.24M|        ROUND(44, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1283|  5.24M|        ROUND(45, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1284|  5.24M|        ROUND(46, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1285|  5.24M|        ROUND(47, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1286|       |
 1287|  5.24M|        ROUND(48, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1288|  5.24M|        ROUND(49, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1289|  5.24M|        ROUND(50, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1290|  5.24M|        ROUND(51, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1291|  5.24M|        ROUND(52, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1292|  5.24M|        ROUND(53, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1293|  5.24M|        ROUND(54, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1294|  5.24M|        ROUND(55, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1295|       |
 1296|  5.24M|        ROUND(56, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1297|  5.24M|        ROUND(57, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1298|  5.24M|        ROUND(58, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1299|  5.24M|        ROUND(59, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1300|  5.24M|        ROUND(60, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1301|  5.24M|        ROUND(61, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1302|  5.24M|        ROUND(62, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1303|  5.24M|        ROUND(63, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1304|       |
 1305|  5.24M|        ROUND(64, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1306|  5.24M|        ROUND(65, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1307|  5.24M|        ROUND(66, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1308|  5.24M|        ROUND(67, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1309|  5.24M|        ROUND(68, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1310|  5.24M|        ROUND(69, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1311|  5.24M|        ROUND(70, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1312|  5.24M|        ROUND(71, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1313|       |
 1314|  5.24M|        ROUND(72, a, b, c, d, e, f, g, h)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1315|  5.24M|        ROUND(73, h, a, b, c, d, e, f, g)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1316|  5.24M|        ROUND(74, g, h, a, b, c, d, e, f)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1317|  5.24M|        ROUND(75, f, g, h, a, b, c, d, e)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1318|  5.24M|        ROUND(76, e, f, g, h, a, b, c, d)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1319|  5.24M|        ROUND(77, d, e, f, g, h, a, b, c)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1320|  5.24M|        ROUND(78, c, d, e, f, g, h, a, b)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1321|  5.24M|        ROUND(79, b, c, d, e, f, g, h, a)
  ------------------
  |  | 1002|  5.24M|    h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |  798|  5.24M|#define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S1(x) (ROTR64(x, 14) ^ ROTR64(x, 18) ^ ROTR64(x, 41))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   35|  5.24M|#define Ch(x, y, z) ((x & y) ^ (~x & z))
  |  |  ------------------
  |  |                   h += S1(e) + Ch(e, f, g) + K512[n] + W[n]; \
  |  |  ------------------
  |  |  |  |   29|  5.24M|#define W ctx->u.w
  |  |  ------------------
  |  | 1003|  5.24M|    d += h;                                    \
  |  | 1004|  5.24M|    h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |  797|  5.24M|#define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  |  |               #define S0(x) (ROTR64(x, 28) ^ ROTR64(x, 34) ^ ROTR64(x, 39))
  |  |  |  |  ------------------
  |  |  |  |  |  |   30|  5.24M|#define ROTR64(x, n) (((x) >> (n)) | ((x) << (64 - (n))))
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   h += S0(a) + Maj(a, b, c);                 \
  |  |  ------------------
  |  |  |  |   36|  5.24M|#define Maj(x, y, z) ((x & y) ^ (x & z) ^ (y & z))
  |  |  ------------------
  |  | 1005|  5.24M|    DUMP(n, a, d, e, h)
  ------------------
 1322|  5.24M|#endif
 1323|       |
 1324|  5.24M|        ADDTO(a, H[0]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1325|  5.24M|        ADDTO(b, H[1]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1326|  5.24M|        ADDTO(c, H[2]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1327|  5.24M|        ADDTO(d, H[3]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1328|  5.24M|        ADDTO(e, H[4]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1329|  5.24M|        ADDTO(f, H[5]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1330|  5.24M|        ADDTO(g, H[6]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1331|  5.24M|        ADDTO(h, H[7]);
  ------------------
  |  |  997|  5.24M|#define ADDTO(x, y) y += x
  ------------------
 1332|  5.24M|    }
 1333|       |
 1334|  5.24M|#endif /* !USE_PPC_CRYPTO */
 1335|  5.24M|}

SHA1_Begin:
   59|   483k|{
   60|   483k|    ctx->size = 0;
   61|       |    /*
   62|       |     *  Initialize H with constants from FIPS180-1.
   63|       |     */
   64|   483k|    ctx->H[0] = 0x67452301L;
   65|   483k|    ctx->H[1] = 0xefcdab89L;
   66|   483k|    ctx->H[2] = 0x98badcfeL;
   67|   483k|    ctx->H[3] = 0x10325476L;
   68|   483k|    ctx->H[4] = 0xc3d2e1f0L;
   69|       |
   70|       |#if defined(USE_HW_SHA1) && defined(IS_LITTLE_ENDIAN)
   71|       |    /* arm's implementation is tested on little endian only */
   72|       |    if (arm_sha1_support()) {
   73|       |        ctx->compress = SHA1_Compress_Native;
   74|       |        ctx->update = SHA1_Update_Native;
   75|       |    } else
   76|       |#endif
   77|   483k|    {
   78|   483k|        ctx->compress = SHA1_Compress_Generic;
   79|   483k|        ctx->update = SHA1_Update_Generic;
   80|   483k|    }
   81|   483k|}
SHA1_Update:
  126|  1.50M|{
  127|  1.50M|    ctx->update(ctx, dataIn, len);
  128|  1.50M|}
SHA1_End:
  187|   425k|{
  188|   425k|    register PRUint64 size;
  189|   425k|    register PRUint32 lenB;
  190|       |
  191|   425k|    static const unsigned char bulk_pad[64] = { 0x80, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  192|   425k|                                                0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
  193|   425k|                                                0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 };
  194|   425k|#define tmp lenB
  195|       |
  196|   425k|    PORT_Assert(maxDigestLen >= SHA1_LENGTH);
  ------------------
  |  |  120|   425k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   425k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 425k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  197|       |
  198|       |    /*
  199|       |     *  Pad with a binary 1 (e.g. 0x80), then zeroes, then length in bits
  200|       |     */
  201|   425k|    size = ctx->size;
  202|       |
  203|   425k|    lenB = (PRUint32)size & 63;
  204|   425k|    SHA1_Update(ctx, bulk_pad, (((55 + 64) - lenB) & 63) + 1);
  205|   425k|    PORT_Assert(((PRUint32)ctx->size & 63) == 56);
  ------------------
  |  |  120|   425k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   425k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 425k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  206|       |    /* Convert size from bytes to bits. */
  207|   425k|    size <<= 3;
  208|   425k|    ctx->W[14] = SHA_HTONL((PRUint32)(size >> 32));
  ------------------
  |  |   22|   425k|#define W u.w
  ------------------
                  ctx->W[14] = SHA_HTONL((PRUint32)(size >> 32));
  ------------------
  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  ------------------
  209|   425k|    ctx->W[15] = SHA_HTONL((PRUint32)size);
  ------------------
  |  |   22|   425k|#define W u.w
  ------------------
                  ctx->W[15] = SHA_HTONL((PRUint32)size);
  ------------------
  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  ------------------
  210|   425k|    ctx->compress(ctx);
  211|       |
  212|       |    /*
  213|       |     *  Output hash
  214|       |     */
  215|   425k|    SHA_STORE_RESULT;
  ------------------
  |  |  149|   425k|    SHA_STORE(0);        \
  |  |  ------------------
  |  |  |  |  146|   425k|#define SHA_STORE(n) ((PRUint32 *)hashout)[n] = SHA_HTONL(ctx->H[n])
  |  |  |  |  ------------------
  |  |  |  |  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  150|   425k|    SHA_STORE(1);        \
  |  |  ------------------
  |  |  |  |  146|   425k|#define SHA_STORE(n) ((PRUint32 *)hashout)[n] = SHA_HTONL(ctx->H[n])
  |  |  |  |  ------------------
  |  |  |  |  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  151|   425k|    SHA_STORE(2);        \
  |  |  ------------------
  |  |  |  |  146|   425k|#define SHA_STORE(n) ((PRUint32 *)hashout)[n] = SHA_HTONL(ctx->H[n])
  |  |  |  |  ------------------
  |  |  |  |  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  152|   425k|    SHA_STORE(3);        \
  |  |  ------------------
  |  |  |  |  146|   425k|#define SHA_STORE(n) ((PRUint32 *)hashout)[n] = SHA_HTONL(ctx->H[n])
  |  |  |  |  ------------------
  |  |  |  |  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  153|   425k|    SHA_STORE(4);
  |  |  ------------------
  |  |  |  |  146|   425k|#define SHA_STORE(n) ((PRUint32 *)hashout)[n] = SHA_HTONL(ctx->H[n])
  |  |  |  |  ------------------
  |  |  |  |  |  |   97|   425k|#define SHA_HTONL(x) swap4b(x)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  216|   425k|    if (pDigestLen) {
  ------------------
  |  Branch (216:9): [True: 425k, False: 0]
  ------------------
  217|   425k|        *pDigestLen = SHA1_LENGTH;
  ------------------
  |  |   39|   425k|#define SHA1_LENGTH 20
  ------------------
  218|   425k|    }
  219|   425k|#undef tmp
  220|   425k|}
SHA1_NewContext:
  516|   245k|{
  517|   245k|    SHA1Context *cx;
  518|       |
  519|       |    /* no need to ZNew, SHA1_Begin will init the context */
  520|   245k|    cx = PORT_New(SHA1Context);
  ------------------
  |  |  151|   245k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|   245k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  521|   245k|    return cx;
  522|   245k|}
SHA1_DestroyContext:
  527|   245k|{
  528|   245k|    memset(cx, 0, sizeof *cx);
  529|   245k|    if (freeit) {
  ------------------
  |  Branch (529:9): [True: 245k, False: 0]
  ------------------
  530|   245k|        PORT_Free(cx);
  ------------------
  |  |   60|   245k|#define PORT_Free PORT_Free_Util
  ------------------
  531|   245k|    }
  532|   245k|}
SHA1_FlattenSize:
  560|   111k|{
  561|   111k|    return sizeof(SHA1Context);
  562|   111k|}
sha_fast.c:SHA1_Update_Generic:
  132|  1.50M|{
  133|  1.50M|    register unsigned int lenB;
  134|  1.50M|    register unsigned int togo;
  135|       |
  136|  1.50M|    if (!len)
  ------------------
  |  Branch (136:9): [True: 12.0k, False: 1.49M]
  ------------------
  137|  12.0k|        return;
  138|       |
  139|       |    /* accumulate the byte count. */
  140|  1.49M|    lenB = (unsigned int)(ctx->size) & 63U;
  141|       |
  142|  1.49M|    ctx->size += len;
  143|       |
  144|       |    /*
  145|       |     *  Read the data into W and process blocks as they get full
  146|       |     */
  147|  1.49M|    if (lenB > 0) {
  ------------------
  |  Branch (147:9): [True: 665k, False: 825k]
  ------------------
  148|   665k|        togo = 64U - lenB;
  149|   665k|        if (len < togo)
  ------------------
  |  Branch (149:13): [True: 552k, False: 112k]
  ------------------
  150|   552k|            togo = len;
  151|   665k|        memcpy(ctx->B + lenB, dataIn, togo);
  ------------------
  |  |   23|   665k|#define B u.b
  ------------------
  152|   665k|        len -= togo;
  153|   665k|        dataIn += togo;
  154|   665k|        lenB = (lenB + togo) & 63U;
  155|   665k|        if (!lenB) {
  ------------------
  |  Branch (155:13): [True: 112k, False: 552k]
  ------------------
  156|   112k|            shaCompress(&ctx->H[H2X], ctx->W);
  ------------------
  |  |  115|   112k|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  ------------------
                          shaCompress(&ctx->H[H2X], ctx->W);
  ------------------
  |  |   22|   112k|#define W u.w
  ------------------
  157|   112k|        }
  158|   665k|    }
  159|       |#if !defined(HAVE_UNALIGNED_ACCESS)
  160|       |    if ((ptrdiff_t)dataIn % sizeof(PRUint32)) {
  161|       |        while (len >= 64U) {
  162|       |            memcpy(ctx->B, dataIn, 64);
  163|       |            len -= 64U;
  164|       |            shaCompress(&ctx->H[H2X], ctx->W);
  165|       |            dataIn += 64U;
  166|       |        }
  167|       |    } else
  168|       |#endif
  169|  1.49M|    {
  170|  2.53M|        while (len >= 64U) {
  ------------------
  |  Branch (170:16): [True: 1.04M, False: 1.49M]
  ------------------
  171|  1.04M|            len -= 64U;
  172|  1.04M|            shaCompress(&ctx->H[H2X], (PRUint32 *)dataIn);
  ------------------
  |  |  115|  1.04M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  ------------------
  173|  1.04M|            dataIn += 64U;
  174|  1.04M|        }
  175|  1.49M|    }
  176|  1.49M|    if (len) {
  ------------------
  |  Branch (176:9): [True: 532k, False: 958k]
  ------------------
  177|   532k|        memcpy(ctx->B, dataIn, len);
  ------------------
  |  |   23|   532k|#define B u.b
  ------------------
  178|   532k|    }
  179|  1.49M|}
sha_fast.c:shaCompress:
  286|  1.57M|{
  287|  1.57M|    register SHA_HW_t A, B, C, D, E;
  288|       |
  289|       |#if defined(SHA_NEED_TMP_VARIABLE)
  290|       |    register PRUint32 tmp;
  291|       |#endif
  292|       |
  293|  1.57M|#if !defined(SHA_PUT_W_IN_STACK)
  294|  1.57M|#define XH(n) X[n - H2X]
  295|  1.57M|#define XW(n) X[n - W2X]
  296|       |#else
  297|       |    SHA_HW_t w_0, w_1, w_2, w_3, w_4, w_5, w_6, w_7,
  298|       |        w_8, w_9, w_10, w_11, w_12, w_13, w_14, w_15;
  299|       |#define XW(n) w_##n
  300|       |#define XH(n) X[n]
  301|       |#endif
  302|       |
  303|  1.57M|#define K0 0x5a827999L
  304|  1.57M|#define K1 0x6ed9eba1L
  305|  1.57M|#define K2 0x8f1bbcdcL
  306|  1.57M|#define K3 0xca62c1d6L
  307|       |
  308|  1.57M|#define SHA_RND1(a, b, c, d, e, n)                         \
  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  310|  1.57M|    c = SHA_ROTL(c, 30)
  311|  1.57M|#define SHA_RND2(a, b, c, d, e, n)                         \
  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  313|  1.57M|    c = SHA_ROTL(c, 30)
  314|  1.57M|#define SHA_RND3(a, b, c, d, e, n)                         \
  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  316|  1.57M|    c = SHA_ROTL(c, 30)
  317|  1.57M|#define SHA_RND4(a, b, c, d, e, n)                         \
  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  319|  1.57M|    c = SHA_ROTL(c, 30)
  320|       |
  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  322|       |
  323|  1.57M|    A = XH(0);
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  324|  1.57M|    B = XH(1);
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  325|  1.57M|    C = XH(2);
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  326|  1.57M|    D = XH(3);
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  327|  1.57M|    E = XH(4);
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  328|       |
  329|  1.57M|    LOAD(0);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  330|  1.57M|    SHA_RND1(E, A, B, C, D, 0);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  331|  1.57M|    LOAD(1);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  332|  1.57M|    SHA_RND1(D, E, A, B, C, 1);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  333|  1.57M|    LOAD(2);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  334|  1.57M|    SHA_RND1(C, D, E, A, B, 2);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  335|  1.57M|    LOAD(3);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  336|  1.57M|    SHA_RND1(B, C, D, E, A, 3);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  337|  1.57M|    LOAD(4);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  338|  1.57M|    SHA_RND1(A, B, C, D, E, 4);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  339|  1.57M|    LOAD(5);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  340|  1.57M|    SHA_RND1(E, A, B, C, D, 5);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  341|  1.57M|    LOAD(6);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  342|  1.57M|    SHA_RND1(D, E, A, B, C, 6);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  343|  1.57M|    LOAD(7);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  344|  1.57M|    SHA_RND1(C, D, E, A, B, 7);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  345|  1.57M|    LOAD(8);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  346|  1.57M|    SHA_RND1(B, C, D, E, A, 8);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  347|  1.57M|    LOAD(9);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  348|  1.57M|    SHA_RND1(A, B, C, D, E, 9);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  349|  1.57M|    LOAD(10);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  350|  1.57M|    SHA_RND1(E, A, B, C, D, 10);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  351|  1.57M|    LOAD(11);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  352|  1.57M|    SHA_RND1(D, E, A, B, C, 11);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  353|  1.57M|    LOAD(12);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  354|  1.57M|    SHA_RND1(C, D, E, A, B, 12);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  355|  1.57M|    LOAD(13);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  356|  1.57M|    SHA_RND1(B, C, D, E, A, 13);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  357|  1.57M|    LOAD(14);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  358|  1.57M|    SHA_RND1(A, B, C, D, E, 14);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  359|  1.57M|    LOAD(15);
  ------------------
  |  |  321|  1.57M|#define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define LOAD(n) XW(n) = SHA_HTONL(inbuf[n])
  |  |  ------------------
  |  |  |  |   97|  1.57M|#define SHA_HTONL(x) swap4b(x)
  |  |  ------------------
  ------------------
  360|  1.57M|    SHA_RND1(E, A, B, C, D, 15);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  361|       |
  362|  1.57M|    SHA_MIX(0, 13, 8, 2);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  363|  1.57M|    SHA_RND1(D, E, A, B, C, 0);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  364|  1.57M|    SHA_MIX(1, 14, 9, 3);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  365|  1.57M|    SHA_RND1(C, D, E, A, B, 1);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  366|  1.57M|    SHA_MIX(2, 15, 10, 4);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  367|  1.57M|    SHA_RND1(B, C, D, E, A, 2);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  368|  1.57M|    SHA_MIX(3, 0, 11, 5);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  369|  1.57M|    SHA_RND1(A, B, C, D, E, 3);
  ------------------
  |  |  309|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |   25|  1.57M|#define SHA_F1(X, Y, Z) ((((Y) ^ (Z)) & (X)) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F1(c, d, e) + a + XW(n) + K0; \
  |  |  ------------------
  |  |  |  |  303|  1.57M|#define K0 0x5a827999L
  |  |  ------------------
  |  |  310|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  370|       |
  371|  1.57M|    SHA_MIX(4, 1, 12, 6);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  372|  1.57M|    SHA_RND2(E, A, B, C, D, 4);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  373|  1.57M|    SHA_MIX(5, 2, 13, 7);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  374|  1.57M|    SHA_RND2(D, E, A, B, C, 5);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  375|  1.57M|    SHA_MIX(6, 3, 14, 8);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  376|  1.57M|    SHA_RND2(C, D, E, A, B, 6);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  377|  1.57M|    SHA_MIX(7, 4, 15, 9);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  378|  1.57M|    SHA_RND2(B, C, D, E, A, 7);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  379|  1.57M|    SHA_MIX(8, 5, 0, 10);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  380|  1.57M|    SHA_RND2(A, B, C, D, E, 8);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  381|  1.57M|    SHA_MIX(9, 6, 1, 11);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  382|  1.57M|    SHA_RND2(E, A, B, C, D, 9);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  383|  1.57M|    SHA_MIX(10, 7, 2, 12);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  384|  1.57M|    SHA_RND2(D, E, A, B, C, 10);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  385|  1.57M|    SHA_MIX(11, 8, 3, 13);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  386|  1.57M|    SHA_RND2(C, D, E, A, B, 11);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  387|  1.57M|    SHA_MIX(12, 9, 4, 14);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  388|  1.57M|    SHA_RND2(B, C, D, E, A, 12);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  389|  1.57M|    SHA_MIX(13, 10, 5, 15);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  390|  1.57M|    SHA_RND2(A, B, C, D, E, 13);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  391|  1.57M|    SHA_MIX(14, 11, 6, 0);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  392|  1.57M|    SHA_RND2(E, A, B, C, D, 14);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  393|  1.57M|    SHA_MIX(15, 12, 7, 1);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  394|  1.57M|    SHA_RND2(D, E, A, B, C, 15);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  395|       |
  396|  1.57M|    SHA_MIX(0, 13, 8, 2);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  397|  1.57M|    SHA_RND2(C, D, E, A, B, 0);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  398|  1.57M|    SHA_MIX(1, 14, 9, 3);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  399|  1.57M|    SHA_RND2(B, C, D, E, A, 1);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  400|  1.57M|    SHA_MIX(2, 15, 10, 4);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  401|  1.57M|    SHA_RND2(A, B, C, D, E, 2);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  402|  1.57M|    SHA_MIX(3, 0, 11, 5);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  403|  1.57M|    SHA_RND2(E, A, B, C, D, 3);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  404|  1.57M|    SHA_MIX(4, 1, 12, 6);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  405|  1.57M|    SHA_RND2(D, E, A, B, C, 4);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  406|  1.57M|    SHA_MIX(5, 2, 13, 7);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  407|  1.57M|    SHA_RND2(C, D, E, A, B, 5);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  408|  1.57M|    SHA_MIX(6, 3, 14, 8);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  409|  1.57M|    SHA_RND2(B, C, D, E, A, 6);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  410|  1.57M|    SHA_MIX(7, 4, 15, 9);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  411|  1.57M|    SHA_RND2(A, B, C, D, E, 7);
  ------------------
  |  |  312|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |   26|  1.57M|#define SHA_F2(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F2(c, d, e) + a + XW(n) + K1; \
  |  |  ------------------
  |  |  |  |  304|  1.57M|#define K1 0x6ed9eba1L
  |  |  ------------------
  |  |  313|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  412|       |
  413|  1.57M|    SHA_MIX(8, 5, 0, 10);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  414|  1.57M|    SHA_RND3(E, A, B, C, D, 8);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  415|  1.57M|    SHA_MIX(9, 6, 1, 11);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  416|  1.57M|    SHA_RND3(D, E, A, B, C, 9);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  417|  1.57M|    SHA_MIX(10, 7, 2, 12);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  418|  1.57M|    SHA_RND3(C, D, E, A, B, 10);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  419|  1.57M|    SHA_MIX(11, 8, 3, 13);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  420|  1.57M|    SHA_RND3(B, C, D, E, A, 11);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  421|  1.57M|    SHA_MIX(12, 9, 4, 14);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  422|  1.57M|    SHA_RND3(A, B, C, D, E, 12);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  423|  1.57M|    SHA_MIX(13, 10, 5, 15);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  424|  1.57M|    SHA_RND3(E, A, B, C, D, 13);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  425|  1.57M|    SHA_MIX(14, 11, 6, 0);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  426|  1.57M|    SHA_RND3(D, E, A, B, C, 14);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  427|  1.57M|    SHA_MIX(15, 12, 7, 1);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  428|  1.57M|    SHA_RND3(C, D, E, A, B, 15);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  429|       |
  430|  1.57M|    SHA_MIX(0, 13, 8, 2);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  431|  1.57M|    SHA_RND3(B, C, D, E, A, 0);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  432|  1.57M|    SHA_MIX(1, 14, 9, 3);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  433|  1.57M|    SHA_RND3(A, B, C, D, E, 1);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  434|  1.57M|    SHA_MIX(2, 15, 10, 4);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  435|  1.57M|    SHA_RND3(E, A, B, C, D, 2);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  436|  1.57M|    SHA_MIX(3, 0, 11, 5);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  437|  1.57M|    SHA_RND3(D, E, A, B, C, 3);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  438|  1.57M|    SHA_MIX(4, 1, 12, 6);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  439|  1.57M|    SHA_RND3(C, D, E, A, B, 4);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  440|  1.57M|    SHA_MIX(5, 2, 13, 7);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  441|  1.57M|    SHA_RND3(B, C, D, E, A, 5);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  442|  1.57M|    SHA_MIX(6, 3, 14, 8);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  443|  1.57M|    SHA_RND3(A, B, C, D, E, 6);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  444|  1.57M|    SHA_MIX(7, 4, 15, 9);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  445|  1.57M|    SHA_RND3(E, A, B, C, D, 7);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  446|  1.57M|    SHA_MIX(8, 5, 0, 10);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  447|  1.57M|    SHA_RND3(D, E, A, B, C, 8);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  448|  1.57M|    SHA_MIX(9, 6, 1, 11);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  449|  1.57M|    SHA_RND3(C, D, E, A, B, 9);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  450|  1.57M|    SHA_MIX(10, 7, 2, 12);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  451|  1.57M|    SHA_RND3(B, C, D, E, A, 10);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  452|  1.57M|    SHA_MIX(11, 8, 3, 13);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  453|  1.57M|    SHA_RND3(A, B, C, D, E, 11);
  ------------------
  |  |  315|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |   27|  1.57M|#define SHA_F3(X, Y, Z) (((X) & (Y)) | ((Z) & ((X) | (Y))))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F3(c, d, e) + a + XW(n) + K2; \
  |  |  ------------------
  |  |  |  |  305|  1.57M|#define K2 0x8f1bbcdcL
  |  |  ------------------
  |  |  316|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  454|       |
  455|  1.57M|    SHA_MIX(12, 9, 4, 14);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  456|  1.57M|    SHA_RND4(E, A, B, C, D, 12);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  457|  1.57M|    SHA_MIX(13, 10, 5, 15);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  458|  1.57M|    SHA_RND4(D, E, A, B, C, 13);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  459|  1.57M|    SHA_MIX(14, 11, 6, 0);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  460|  1.57M|    SHA_RND4(C, D, E, A, B, 14);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  461|  1.57M|    SHA_MIX(15, 12, 7, 1);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  462|  1.57M|    SHA_RND4(B, C, D, E, A, 15);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  463|       |
  464|  1.57M|    SHA_MIX(0, 13, 8, 2);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  465|  1.57M|    SHA_RND4(A, B, C, D, E, 0);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  466|  1.57M|    SHA_MIX(1, 14, 9, 3);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  467|  1.57M|    SHA_RND4(E, A, B, C, D, 1);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  468|  1.57M|    SHA_MIX(2, 15, 10, 4);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  469|  1.57M|    SHA_RND4(D, E, A, B, C, 2);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  470|  1.57M|    SHA_MIX(3, 0, 11, 5);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  471|  1.57M|    SHA_RND4(C, D, E, A, B, 3);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  472|  1.57M|    SHA_MIX(4, 1, 12, 6);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  473|  1.57M|    SHA_RND4(B, C, D, E, A, 4);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  474|  1.57M|    SHA_MIX(5, 2, 13, 7);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  475|  1.57M|    SHA_RND4(A, B, C, D, E, 5);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  476|  1.57M|    SHA_MIX(6, 3, 14, 8);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  477|  1.57M|    SHA_RND4(E, A, B, C, D, 6);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  478|  1.57M|    SHA_MIX(7, 4, 15, 9);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  479|  1.57M|    SHA_RND4(D, E, A, B, C, 7);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  480|  1.57M|    SHA_MIX(8, 5, 0, 10);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  481|  1.57M|    SHA_RND4(C, D, E, A, B, 8);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  482|  1.57M|    SHA_MIX(9, 6, 1, 11);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  483|  1.57M|    SHA_RND4(B, C, D, E, A, 9);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  484|  1.57M|    SHA_MIX(10, 7, 2, 12);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  485|  1.57M|    SHA_RND4(A, B, C, D, E, 10);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  486|  1.57M|    SHA_MIX(11, 8, 3, 13);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  487|  1.57M|    SHA_RND4(E, A, B, C, D, 11);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  488|  1.57M|    SHA_MIX(12, 9, 4, 14);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  489|  1.57M|    SHA_RND4(D, E, A, B, C, 12);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  490|  1.57M|    SHA_MIX(13, 10, 5, 15);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  491|  1.57M|    SHA_RND4(C, D, E, A, B, 13);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  492|  1.57M|    SHA_MIX(14, 11, 6, 0);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  493|  1.57M|    SHA_RND4(B, C, D, E, A, 14);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  494|  1.57M|    SHA_MIX(15, 12, 7, 1);
  ------------------
  |  |   30|  1.57M|#define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define SHA_MIX(n, a, b, c) XW(n) = SHA_ROTL(XW(a) ^ XW(b) ^ XW(c) ^ XW(n), 1)
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  495|  1.57M|    SHA_RND4(A, B, C, D, E, 15);
  ------------------
  |  |  318|  1.57M|    a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |   28|  1.57M|#define SHA_F4(X, Y, Z) ((X) ^ (Y) ^ (Z))
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  295|  1.57M|#define XW(n) X[n - W2X]
  |  |  |  |  ------------------
  |  |  |  |  |  |  116|  1.57M|#define W2X 6  /* X[0] is W[6],  and W[0] is X[-6]  */
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                   a = SHA_ROTL(b, 5) + SHA_F4(c, d, e) + a + XW(n) + K3; \
  |  |  ------------------
  |  |  |  |  306|  1.57M|#define K3 0xca62c1d6L
  |  |  ------------------
  |  |  319|  1.57M|    c = SHA_ROTL(c, 30)
  ------------------
  496|       |
  497|  1.57M|    XH(0) += A;
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  498|  1.57M|    XH(1) += B;
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  499|  1.57M|    XH(2) += C;
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  500|  1.57M|    XH(3) += D;
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  501|  1.57M|    XH(4) += E;
  ------------------
  |  |  294|  1.57M|#define XH(n) X[n - H2X]
  |  |  ------------------
  |  |  |  |  115|  1.57M|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  |  |  ------------------
  ------------------
  502|  1.57M|}
sha_fast.c:SHA1_Compress_Generic:
  506|   425k|{
  507|   425k|    shaCompress(&ctx->H[H2X], ctx->u.w);
  ------------------
  |  |  115|   425k|#define H2X 11 /* X[0] is H[11], and H[0] is X[-11] */
  ------------------
  508|   425k|}

camellia.c:swap4b:
   92|  13.2k|{
   93|  13.2k|    __asm__("bswap %0"
   94|  13.2k|            : "+r"(value));
   95|  13.2k|    return (value);
   96|  13.2k|}
sha_fast.c:SHA_ROTL:
   76|   353M|{
   77|   353M|    PRUint32 t = (PRUint32)x;
   78|   353M|    return ((t << n) | (t >> (32 - n)));
   79|   353M|}
sha_fast.c:swap4b:
   92|  28.2M|{
   93|  28.2M|    __asm__("bswap %0"
   94|  28.2M|            : "+r"(value));
   95|  28.2M|    return (value);
   96|  28.2M|}

TLS_P_hash:
   21|   254k|{
   22|   254k|    unsigned char state[PHASH_STATE_MAX_LEN];
   23|   254k|    unsigned char outbuf[PHASH_STATE_MAX_LEN];
   24|   254k|    unsigned int state_len = 0, label_len = 0, outbuf_len = 0, chunk_size;
   25|   254k|    unsigned int remaining;
   26|   254k|    unsigned char *res;
   27|   254k|    SECStatus status;
   28|   254k|    HMACContext *cx;
   29|   254k|    SECStatus rv = SECFailure;
   30|   254k|    const SECHashObject *hashObj = HASH_GetRawHashObject(hashType);
   31|       |
   32|   254k|    PORT_Assert((secret != NULL) && (secret->data != NULL || !secret->len));
  ------------------
  |  |  120|   254k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   764k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 254k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 254k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   33|   254k|    PORT_Assert((seed != NULL) && (seed->data != NULL));
  ------------------
  |  |  120|   254k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   509k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 254k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 254k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   34|   254k|    PORT_Assert((result != NULL) && (result->data != NULL));
  ------------------
  |  |  120|   254k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   509k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 254k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 254k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   35|       |
   36|   254k|    remaining = result->len;
   37|   254k|    res = result->data;
   38|       |
   39|   254k|    if (label != NULL)
  ------------------
  |  Branch (39:9): [True: 137k, False: 117k]
  ------------------
   40|   137k|        label_len = PORT_Strlen(label);
  ------------------
  |  |  190|   137k|#define PORT_Strlen(s) strlen(s)
  ------------------
   41|       |
   42|   254k|    cx = HMAC_Create(hashObj, secret->data, secret->len, isFIPS);
   43|   254k|    if (cx == NULL)
  ------------------
  |  Branch (43:9): [True: 0, False: 254k]
  ------------------
   44|      0|        goto loser;
   45|       |
   46|       |    /* initialize the state = A(1) = HMAC_hash(secret, seed) */
   47|   254k|    HMAC_Begin(cx);
   48|   254k|    HMAC_Update(cx, (unsigned char *)label, label_len);
   49|   254k|    HMAC_Update(cx, seed->data, seed->len);
   50|   254k|    status = HMAC_Finish(cx, state, &state_len, sizeof(state));
   51|   254k|    if (status != SECSuccess)
  ------------------
  |  Branch (51:9): [True: 0, False: 254k]
  ------------------
   52|      0|        goto loser;
   53|       |
   54|       |    /* generate a block at a time until we're done */
   55|   711k|    while (remaining > 0) {
  ------------------
  |  Branch (55:12): [True: 456k, False: 254k]
  ------------------
   56|       |
   57|   456k|        HMAC_Begin(cx);
   58|   456k|        HMAC_Update(cx, state, state_len);
   59|   456k|        if (label_len)
  ------------------
  |  Branch (59:13): [True: 339k, False: 117k]
  ------------------
   60|   339k|            HMAC_Update(cx, (unsigned char *)label, label_len);
   61|   456k|        HMAC_Update(cx, seed->data, seed->len);
   62|   456k|        status = HMAC_Finish(cx, outbuf, &outbuf_len, sizeof(outbuf));
   63|   456k|        if (status != SECSuccess)
  ------------------
  |  Branch (63:13): [True: 0, False: 456k]
  ------------------
   64|      0|            goto loser;
   65|       |
   66|       |        /* Update the state = A(i) = HMAC_hash(secret, A(i-1)) */
   67|   456k|        HMAC_Begin(cx);
   68|   456k|        HMAC_Update(cx, state, state_len);
   69|   456k|        status = HMAC_Finish(cx, state, &state_len, sizeof(state));
   70|   456k|        if (status != SECSuccess)
  ------------------
  |  Branch (70:13): [True: 0, False: 456k]
  ------------------
   71|      0|            goto loser;
   72|       |
   73|   456k|        chunk_size = PR_MIN(outbuf_len, remaining);
  ------------------
  |  |  158|   456k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 201k, False: 254k]
  |  |  ------------------
  ------------------
   74|   456k|        PORT_Memcpy(res, &outbuf, chunk_size);
  ------------------
  |  |  180|   456k|#define PORT_Memcpy memcpy
  ------------------
   75|   456k|        res += chunk_size;
   76|   456k|        remaining -= chunk_size;
   77|   456k|    }
   78|       |
   79|   254k|    rv = SECSuccess;
   80|       |
   81|   254k|loser:
   82|       |    /* clear out state so it's not left on the stack */
   83|   254k|    if (cx)
  ------------------
  |  Branch (83:9): [True: 254k, False: 0]
  ------------------
   84|   254k|        HMAC_Destroy(cx, PR_TRUE);
  ------------------
  |  |  437|   254k|#define PR_TRUE 1
  ------------------
   85|   254k|    PORT_SafeZero(state, sizeof(state));
   86|   254k|    PORT_SafeZero(outbuf, sizeof(outbuf));
   87|   254k|    return rv;
   88|   254k|}
TLS_PRF:
   93|  26.8k|{
   94|  26.8k|    SECStatus rv = SECFailure, status;
   95|  26.8k|    unsigned int i;
   96|  26.8k|    SECItem tmp = { siBuffer, NULL, 0 };
   97|  26.8k|    SECItem S1;
   98|  26.8k|    SECItem S2;
   99|       |
  100|  26.8k|    PORT_Assert((secret != NULL) && (secret->data != NULL || !secret->len));
  ------------------
  |  |  120|  26.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  80.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 26.8k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 26.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  101|  26.8k|    PORT_Assert((seed != NULL) && (seed->data != NULL));
  ------------------
  |  |  120|  26.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  53.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 26.8k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 26.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  102|  26.8k|    PORT_Assert((result != NULL) && (result->data != NULL));
  ------------------
  |  |  120|  26.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  53.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 26.8k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 26.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  103|       |
  104|  26.8k|    S1.type = siBuffer;
  105|  26.8k|    S1.len = (secret->len / 2) + (secret->len & 1);
  106|  26.8k|    S1.data = secret->data;
  107|       |
  108|  26.8k|    S2.type = siBuffer;
  109|  26.8k|    S2.len = S1.len;
  110|  26.8k|    S2.data = secret->data + (secret->len - S2.len);
  111|       |
  112|  26.8k|    tmp.data = (unsigned char *)PORT_Alloc(result->len);
  ------------------
  |  |   52|  26.8k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  113|  26.8k|    if (tmp.data == NULL)
  ------------------
  |  Branch (113:9): [True: 0, False: 26.8k]
  ------------------
  114|      0|        goto loser;
  115|  26.8k|    tmp.len = result->len;
  116|       |
  117|  26.8k|    status = TLS_P_hash(HASH_AlgMD5, &S1, label, seed, result, isFIPS);
  118|  26.8k|    if (status != SECSuccess)
  ------------------
  |  Branch (118:9): [True: 0, False: 26.8k]
  ------------------
  119|      0|        goto loser;
  120|       |
  121|  26.8k|    status = TLS_P_hash(HASH_AlgSHA1, &S2, label, seed, &tmp, isFIPS);
  122|  26.8k|    if (status != SECSuccess)
  ------------------
  |  Branch (122:9): [True: 0, False: 26.8k]
  ------------------
  123|      0|        goto loser;
  124|       |
  125|  1.08M|    for (i = 0; i < result->len; i++)
  ------------------
  |  Branch (125:17): [True: 1.06M, False: 26.8k]
  ------------------
  126|  1.06M|        result->data[i] ^= tmp.data[i];
  127|       |
  128|  26.8k|    rv = SECSuccess;
  129|       |
  130|  26.8k|loser:
  131|  26.8k|    if (tmp.data != NULL)
  ------------------
  |  Branch (131:9): [True: 26.8k, False: 0]
  ------------------
  132|  26.8k|        PORT_ZFree(tmp.data, tmp.len);
  ------------------
  |  |   75|  26.8k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  133|  26.8k|    return rv;
  134|  26.8k|}

Hacl_Impl_Chacha20_chacha20_init:
  117|   274k|{
  118|   274k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|   274k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  119|   274k|                    (uint32_t)0U,
  120|   274k|                    (uint32_t)4U,
  121|   274k|                    (uint32_t)1U,
  122|   274k|                    uint32_t *os = ctx;
  123|   274k|                    uint32_t x = chacha20_constants[i];
  124|   274k|                    os[i] = x;);
  125|   274k|    KRML_MAYBE_FOR8(i,
  ------------------
  |  |  354|   274k|#define KRML_MAYBE_FOR8(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 8, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  126|   274k|                    (uint32_t)0U,
  127|   274k|                    (uint32_t)8U,
  128|   274k|                    (uint32_t)1U,
  129|   274k|                    uint32_t *os = ctx + (uint32_t)4U;
  130|   274k|                    uint8_t *bj = k + i * (uint32_t)4U;
  131|   274k|                    uint32_t u = load32_le(bj);
  132|   274k|                    uint32_t r = u;
  133|   274k|                    uint32_t x = r;
  134|   274k|                    os[i] = x;);
  135|   274k|    ctx[12U] = ctr;
  136|   274k|    KRML_MAYBE_FOR3(i,
  ------------------
  |  |  324|   274k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  137|   274k|                    (uint32_t)0U,
  138|   274k|                    (uint32_t)3U,
  139|   274k|                    (uint32_t)1U,
  140|   274k|                    uint32_t *os = ctx + (uint32_t)13U;
  141|   274k|                    uint8_t *bj = n + i * (uint32_t)4U;
  142|   274k|                    uint32_t u = load32_le(bj);
  143|   274k|                    uint32_t r = u;
  144|   274k|                    uint32_t x = r;
  145|   274k|                    os[i] = x;);
  146|   274k|}
Hacl_Impl_Chacha20_chacha20_update:
  189|   274k|{
  190|   274k|    uint32_t rem = len % (uint32_t)64U;
  191|   274k|    uint32_t nb = len / (uint32_t)64U;
  192|   274k|    uint32_t rem1 = len % (uint32_t)64U;
  193|   277k|    for (uint32_t i = (uint32_t)0U; i < nb; i++) {
  ------------------
  |  Branch (193:37): [True: 3.59k, False: 274k]
  ------------------
  194|  3.59k|        chacha20_encrypt_block(ctx, out + i * (uint32_t)64U, i, text + i * (uint32_t)64U);
  195|  3.59k|    }
  196|   274k|    if (rem1 > (uint32_t)0U) {
  ------------------
  |  Branch (196:9): [True: 270k, False: 3.53k]
  ------------------
  197|   270k|        chacha20_encrypt_last(ctx, rem, out + nb * (uint32_t)64U, nb, text + nb * (uint32_t)64U);
  198|   270k|    }
  199|   274k|}
Hacl_Chacha20_chacha20_encrypt:
  209|   274k|{
  210|   274k|    uint32_t ctx[16U] = { 0U };
  211|   274k|    Hacl_Impl_Chacha20_chacha20_init(ctx, key, n, ctr);
  212|   274k|    Hacl_Impl_Chacha20_chacha20_update(ctx, len, out, text);
  213|   274k|}
Hacl_Chacha20.c:chacha20_encrypt_block:
  150|   274k|{
  151|   274k|    uint32_t k[16U] = { 0U };
  152|   274k|    chacha20_core(k, ctx, incr);
  153|   274k|    uint32_t bl[16U] = { 0U };
  154|   274k|    KRML_MAYBE_FOR16(i,
  ------------------
  |  |  402|   274k|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  155|   274k|                     (uint32_t)0U,
  156|   274k|                     (uint32_t)16U,
  157|   274k|                     (uint32_t)1U,
  158|   274k|                     uint32_t *os = bl;
  159|   274k|                     uint8_t *bj = text + i * (uint32_t)4U;
  160|   274k|                     uint32_t u = load32_le(bj);
  161|   274k|                     uint32_t r = u;
  162|   274k|                     uint32_t x = r;
  163|   274k|                     os[i] = x;);
  164|   274k|    KRML_MAYBE_FOR16(i,
  ------------------
  |  |  402|   274k|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  165|   274k|                     (uint32_t)0U,
  166|   274k|                     (uint32_t)16U,
  167|   274k|                     (uint32_t)1U,
  168|   274k|                     uint32_t *os = bl;
  169|   274k|                     uint32_t x = bl[i] ^ k[i];
  170|   274k|                     os[i] = x;);
  171|   274k|    KRML_MAYBE_FOR16(i,
  ------------------
  |  |  402|   274k|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  172|   274k|                     (uint32_t)0U,
  173|   274k|                     (uint32_t)16U,
  174|   274k|                     (uint32_t)1U,
  175|   274k|                     store32_le(out + i * (uint32_t)4U, bl[i]););
  176|   274k|}
Hacl_Chacha20.c:chacha20_core:
   97|   274k|{
   98|   274k|    memcpy(k, ctx, (uint32_t)16U * sizeof(uint32_t));
   99|   274k|    uint32_t ctr_u32 = ctr;
  100|   274k|    k[12U] = k[12U] + ctr_u32;
  101|   274k|    rounds(k);
  102|   274k|    KRML_MAYBE_FOR16(i,
  ------------------
  |  |  402|   274k|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|   274k|    do {                               \
  |  |  |  |  289|   274k|        uint32_t i = z;                \
  |  |  |  |  290|   274k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   274k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  103|   274k|                     (uint32_t)0U,
  104|   274k|                     (uint32_t)16U,
  105|   274k|                     (uint32_t)1U,
  106|   274k|                     uint32_t *os = k;
  107|   274k|                     uint32_t x = k[i] + ctx[i];
  108|   274k|                     os[i] = x;);
  109|   274k|    k[12U] = k[12U] + ctr_u32;
  110|   274k|}
Hacl_Chacha20.c:rounds:
   82|   274k|{
   83|   274k|    double_round(st);
   84|   274k|    double_round(st);
   85|   274k|    double_round(st);
   86|   274k|    double_round(st);
   87|   274k|    double_round(st);
   88|   274k|    double_round(st);
   89|   274k|    double_round(st);
   90|   274k|    double_round(st);
   91|   274k|    double_round(st);
   92|   274k|    double_round(st);
   93|   274k|}
Hacl_Chacha20.c:double_round:
   69|  2.74M|{
   70|  2.74M|    quarter_round(st, (uint32_t)0U, (uint32_t)4U, (uint32_t)8U, (uint32_t)12U);
   71|  2.74M|    quarter_round(st, (uint32_t)1U, (uint32_t)5U, (uint32_t)9U, (uint32_t)13U);
   72|  2.74M|    quarter_round(st, (uint32_t)2U, (uint32_t)6U, (uint32_t)10U, (uint32_t)14U);
   73|  2.74M|    quarter_round(st, (uint32_t)3U, (uint32_t)7U, (uint32_t)11U, (uint32_t)15U);
   74|  2.74M|    quarter_round(st, (uint32_t)0U, (uint32_t)5U, (uint32_t)10U, (uint32_t)15U);
   75|  2.74M|    quarter_round(st, (uint32_t)1U, (uint32_t)6U, (uint32_t)11U, (uint32_t)12U);
   76|  2.74M|    quarter_round(st, (uint32_t)2U, (uint32_t)7U, (uint32_t)8U, (uint32_t)13U);
   77|  2.74M|    quarter_round(st, (uint32_t)3U, (uint32_t)4U, (uint32_t)9U, (uint32_t)14U);
   78|  2.74M|}
Hacl_Chacha20.c:quarter_round:
   32|  21.9M|{
   33|  21.9M|    uint32_t sta = st[a];
   34|  21.9M|    uint32_t stb0 = st[b];
   35|  21.9M|    uint32_t std0 = st[d];
   36|  21.9M|    uint32_t sta10 = sta + stb0;
   37|  21.9M|    uint32_t std10 = std0 ^ sta10;
   38|  21.9M|    uint32_t std2 = std10 << (uint32_t)16U | std10 >> (uint32_t)16U;
   39|  21.9M|    st[a] = sta10;
   40|  21.9M|    st[d] = std2;
   41|  21.9M|    uint32_t sta0 = st[c];
   42|  21.9M|    uint32_t stb1 = st[d];
   43|  21.9M|    uint32_t std3 = st[b];
   44|  21.9M|    uint32_t sta11 = sta0 + stb1;
   45|  21.9M|    uint32_t std11 = std3 ^ sta11;
   46|  21.9M|    uint32_t std20 = std11 << (uint32_t)12U | std11 >> (uint32_t)20U;
   47|  21.9M|    st[c] = sta11;
   48|  21.9M|    st[b] = std20;
   49|  21.9M|    uint32_t sta2 = st[a];
   50|  21.9M|    uint32_t stb2 = st[b];
   51|  21.9M|    uint32_t std4 = st[d];
   52|  21.9M|    uint32_t sta12 = sta2 + stb2;
   53|  21.9M|    uint32_t std12 = std4 ^ sta12;
   54|  21.9M|    uint32_t std21 = std12 << (uint32_t)8U | std12 >> (uint32_t)24U;
   55|  21.9M|    st[a] = sta12;
   56|  21.9M|    st[d] = std21;
   57|  21.9M|    uint32_t sta3 = st[c];
   58|  21.9M|    uint32_t stb = st[d];
   59|  21.9M|    uint32_t std = st[b];
   60|  21.9M|    uint32_t sta1 = sta3 + stb;
   61|  21.9M|    uint32_t std1 = std ^ sta1;
   62|  21.9M|    uint32_t std22 = std1 << (uint32_t)7U | std1 >> (uint32_t)25U;
   63|  21.9M|    st[c] = sta1;
   64|  21.9M|    st[b] = std22;
   65|  21.9M|}
Hacl_Chacha20.c:chacha20_encrypt_last:
  180|   270k|{
  181|   270k|    uint8_t plain[64U] = { 0U };
  182|   270k|    memcpy(plain, text, len * sizeof(uint8_t));
  183|   270k|    chacha20_encrypt_block(ctx, plain, incr, plain);
  184|   270k|    memcpy(out, plain, len * sizeof(uint8_t));
  185|   270k|}

Hacl_Curve25519_51_fsquare_times:
  163|   160k|{
  164|   160k|    Hacl_Impl_Curve25519_Field51_fsqr(o, inp, tmp);
  165|  3.71M|    for (uint32_t i = (uint32_t)0U; i < n - (uint32_t)1U; i++) {
  ------------------
  |  Branch (165:37): [True: 3.55M, False: 160k]
  ------------------
  166|  3.55M|        Hacl_Impl_Curve25519_Field51_fsqr(o, o, tmp);
  167|  3.55M|    }
  168|   160k|}
Hacl_Curve25519_51_finv:
  172|  14.6k|{
  173|  14.6k|    uint64_t t1[20U] = { 0U };
  174|  14.6k|    uint64_t *a1 = t1;
  175|  14.6k|    uint64_t *b1 = t1 + (uint32_t)5U;
  176|  14.6k|    uint64_t *t010 = t1 + (uint32_t)15U;
  177|  14.6k|    FStar_UInt128_uint128 *tmp10 = tmp;
  178|  14.6k|    Hacl_Curve25519_51_fsquare_times(a1, i, tmp10, (uint32_t)1U);
  179|  14.6k|    Hacl_Curve25519_51_fsquare_times(t010, a1, tmp10, (uint32_t)2U);
  180|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(b1, t010, i, tmp);
  181|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(a1, b1, a1, tmp);
  182|  14.6k|    Hacl_Curve25519_51_fsquare_times(t010, a1, tmp10, (uint32_t)1U);
  183|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(b1, t010, b1, tmp);
  184|  14.6k|    Hacl_Curve25519_51_fsquare_times(t010, b1, tmp10, (uint32_t)5U);
  185|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(b1, t010, b1, tmp);
  186|  14.6k|    uint64_t *b10 = t1 + (uint32_t)5U;
  187|  14.6k|    uint64_t *c10 = t1 + (uint32_t)10U;
  188|  14.6k|    uint64_t *t011 = t1 + (uint32_t)15U;
  189|  14.6k|    FStar_UInt128_uint128 *tmp11 = tmp;
  190|  14.6k|    Hacl_Curve25519_51_fsquare_times(t011, b10, tmp11, (uint32_t)10U);
  191|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(c10, t011, b10, tmp);
  192|  14.6k|    Hacl_Curve25519_51_fsquare_times(t011, c10, tmp11, (uint32_t)20U);
  193|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(t011, t011, c10, tmp);
  194|  14.6k|    Hacl_Curve25519_51_fsquare_times(t011, t011, tmp11, (uint32_t)10U);
  195|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(b10, t011, b10, tmp);
  196|  14.6k|    Hacl_Curve25519_51_fsquare_times(t011, b10, tmp11, (uint32_t)50U);
  197|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(c10, t011, b10, tmp);
  198|  14.6k|    uint64_t *b11 = t1 + (uint32_t)5U;
  199|  14.6k|    uint64_t *c1 = t1 + (uint32_t)10U;
  200|  14.6k|    uint64_t *t01 = t1 + (uint32_t)15U;
  201|  14.6k|    FStar_UInt128_uint128 *tmp1 = tmp;
  202|  14.6k|    Hacl_Curve25519_51_fsquare_times(t01, c1, tmp1, (uint32_t)100U);
  203|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(t01, t01, c1, tmp);
  204|  14.6k|    Hacl_Curve25519_51_fsquare_times(t01, t01, tmp1, (uint32_t)50U);
  205|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(t01, t01, b11, tmp);
  206|  14.6k|    Hacl_Curve25519_51_fsquare_times(t01, t01, tmp1, (uint32_t)5U);
  207|  14.6k|    uint64_t *a = t1;
  208|  14.6k|    uint64_t *t0 = t1 + (uint32_t)15U;
  209|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(o, t0, a, tmp);
  210|  14.6k|}
Hacl_Curve25519_51_scalarmult:
  241|  14.6k|{
  242|  14.6k|    uint64_t init[10U] = { 0U };
  243|  14.6k|    uint64_t tmp[4U] = { 0U };
  244|  14.6k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  14.6k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  14.6k|    do {                               \
  |  |  |  |  289|  14.6k|        uint32_t i = z;                \
  |  |  |  |  290|  14.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  14.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  245|  14.6k|                    (uint32_t)0U,
  246|  14.6k|                    (uint32_t)4U,
  247|  14.6k|                    (uint32_t)1U,
  248|  14.6k|                    uint64_t *os = tmp;
  249|  14.6k|                    uint8_t *bj = pub + i * (uint32_t)8U;
  250|  14.6k|                    uint64_t u = load64_le(bj);
  251|  14.6k|                    uint64_t r = u;
  252|  14.6k|                    uint64_t x = r;
  253|  14.6k|                    os[i] = x;);
  254|  14.6k|    uint64_t tmp3 = tmp[3U];
  255|  14.6k|    tmp[3U] = tmp3 & (uint64_t)0x7fffffffffffffffU;
  256|  14.6k|    uint64_t *x = init;
  257|  14.6k|    uint64_t *z = init + (uint32_t)5U;
  258|  14.6k|    z[0U] = (uint64_t)1U;
  259|  14.6k|    z[1U] = (uint64_t)0U;
  260|  14.6k|    z[2U] = (uint64_t)0U;
  261|  14.6k|    z[3U] = (uint64_t)0U;
  262|  14.6k|    z[4U] = (uint64_t)0U;
  263|  14.6k|    uint64_t f0l = tmp[0U] & (uint64_t)0x7ffffffffffffU;
  264|  14.6k|    uint64_t f0h = tmp[0U] >> (uint32_t)51U;
  265|  14.6k|    uint64_t f1l = (tmp[1U] & (uint64_t)0x3fffffffffU) << (uint32_t)13U;
  266|  14.6k|    uint64_t f1h = tmp[1U] >> (uint32_t)38U;
  267|  14.6k|    uint64_t f2l = (tmp[2U] & (uint64_t)0x1ffffffU) << (uint32_t)26U;
  268|  14.6k|    uint64_t f2h = tmp[2U] >> (uint32_t)25U;
  269|  14.6k|    uint64_t f3l = (tmp[3U] & (uint64_t)0xfffU) << (uint32_t)39U;
  270|  14.6k|    uint64_t f3h = tmp[3U] >> (uint32_t)12U;
  271|  14.6k|    x[0U] = f0l;
  272|  14.6k|    x[1U] = f0h | f1l;
  273|  14.6k|    x[2U] = f1h | f2l;
  274|  14.6k|    x[3U] = f2h | f3l;
  275|  14.6k|    x[4U] = f3h;
  276|  14.6k|    montgomery_ladder(init, priv, init);
  277|  14.6k|    encode_point(out, init);
  278|  14.6k|}
Hacl_Curve25519_51_ecdh:
  309|  14.6k|{
  310|  14.6k|    uint8_t zeros[32U] = { 0U };
  311|  14.6k|    Hacl_Curve25519_51_scalarmult(out, priv, pub);
  312|  14.6k|    uint8_t res = (uint8_t)255U;
  313|   482k|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)32U; i++) {
  ------------------
  |  Branch (313:37): [True: 467k, False: 14.6k]
  ------------------
  314|   467k|        uint8_t uu____0 = FStar_UInt8_eq_mask(out[i], zeros[i]);
  315|   467k|        res = uu____0 & res;
  316|   467k|    }
  317|  14.6k|    uint8_t z = res;
  318|  14.6k|    bool r = z == (uint8_t)255U;
  319|  14.6k|    return !r;
  320|  14.6k|}
Hacl_Curve25519_51.c:montgomery_ladder:
  104|  14.6k|{
  105|  14.6k|    FStar_UInt128_uint128 tmp2[10U];
  106|   160k|    for (uint32_t _i = 0U; _i < (uint32_t)10U; ++_i)
  ------------------
  |  Branch (106:28): [True: 146k, False: 14.6k]
  ------------------
  107|   146k|        tmp2[_i] = FStar_UInt128_uint64_to_uint128((uint64_t)0U);
  108|  14.6k|    uint64_t p01_tmp1_swap[41U] = { 0U };
  109|  14.6k|    uint64_t *p0 = p01_tmp1_swap;
  110|  14.6k|    uint64_t *p01 = p01_tmp1_swap;
  111|  14.6k|    uint64_t *p03 = p01;
  112|  14.6k|    uint64_t *p11 = p01 + (uint32_t)10U;
  113|  14.6k|    memcpy(p11, init, (uint32_t)10U * sizeof(uint64_t));
  114|  14.6k|    uint64_t *x0 = p03;
  115|  14.6k|    uint64_t *z0 = p03 + (uint32_t)5U;
  116|  14.6k|    x0[0U] = (uint64_t)1U;
  117|  14.6k|    x0[1U] = (uint64_t)0U;
  118|  14.6k|    x0[2U] = (uint64_t)0U;
  119|  14.6k|    x0[3U] = (uint64_t)0U;
  120|  14.6k|    x0[4U] = (uint64_t)0U;
  121|  14.6k|    z0[0U] = (uint64_t)0U;
  122|  14.6k|    z0[1U] = (uint64_t)0U;
  123|  14.6k|    z0[2U] = (uint64_t)0U;
  124|  14.6k|    z0[3U] = (uint64_t)0U;
  125|  14.6k|    z0[4U] = (uint64_t)0U;
  126|  14.6k|    uint64_t *p01_tmp1 = p01_tmp1_swap;
  127|  14.6k|    uint64_t *p01_tmp11 = p01_tmp1_swap;
  128|  14.6k|    uint64_t *nq1 = p01_tmp1_swap;
  129|  14.6k|    uint64_t *nq_p11 = p01_tmp1_swap + (uint32_t)10U;
  130|  14.6k|    uint64_t *swap = p01_tmp1_swap + (uint32_t)40U;
  131|  14.6k|    Hacl_Impl_Curve25519_Field51_cswap2((uint64_t)1U, nq1, nq_p11);
  132|  14.6k|    point_add_and_double(init, p01_tmp11, tmp2);
  133|  14.6k|    swap[0U] = (uint64_t)1U;
  134|  3.68M|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)251U; i++) {
  ------------------
  |  Branch (134:37): [True: 3.67M, False: 14.6k]
  ------------------
  135|  3.67M|        uint64_t *p01_tmp12 = p01_tmp1_swap;
  136|  3.67M|        uint64_t *swap1 = p01_tmp1_swap + (uint32_t)40U;
  137|  3.67M|        uint64_t *nq2 = p01_tmp12;
  138|  3.67M|        uint64_t *nq_p12 = p01_tmp12 + (uint32_t)10U;
  139|  3.67M|        uint64_t
  140|  3.67M|            bit =
  141|  3.67M|                (uint64_t)(key[((uint32_t)253U - i) / (uint32_t)8U] >> ((uint32_t)253U - i) % (uint32_t)8U & (uint8_t)1U);
  142|  3.67M|        uint64_t sw = swap1[0U] ^ bit;
  143|  3.67M|        Hacl_Impl_Curve25519_Field51_cswap2(sw, nq2, nq_p12);
  144|  3.67M|        point_add_and_double(init, p01_tmp12, tmp2);
  145|  3.67M|        swap1[0U] = bit;
  146|  3.67M|    }
  147|  14.6k|    uint64_t sw = swap[0U];
  148|  14.6k|    Hacl_Impl_Curve25519_Field51_cswap2(sw, nq1, nq_p11);
  149|  14.6k|    uint64_t *nq10 = p01_tmp1;
  150|  14.6k|    uint64_t *tmp1 = p01_tmp1 + (uint32_t)20U;
  151|  14.6k|    point_double(nq10, tmp1, tmp2);
  152|  14.6k|    point_double(nq10, tmp1, tmp2);
  153|  14.6k|    point_double(nq10, tmp1, tmp2);
  154|  14.6k|    memcpy(out, p0, (uint32_t)10U * sizeof(uint64_t));
  155|  14.6k|}
Hacl_Curve25519_51.c:point_add_and_double:
   34|  3.68M|{
   35|  3.68M|    uint64_t *nq = p01_tmp1;
   36|  3.68M|    uint64_t *nq_p1 = p01_tmp1 + (uint32_t)10U;
   37|  3.68M|    uint64_t *tmp1 = p01_tmp1 + (uint32_t)20U;
   38|  3.68M|    uint64_t *x1 = q;
   39|  3.68M|    uint64_t *x2 = nq;
   40|  3.68M|    uint64_t *z2 = nq + (uint32_t)5U;
   41|  3.68M|    uint64_t *z3 = nq_p1 + (uint32_t)5U;
   42|  3.68M|    uint64_t *a = tmp1;
   43|  3.68M|    uint64_t *b = tmp1 + (uint32_t)5U;
   44|  3.68M|    uint64_t *ab = tmp1;
   45|  3.68M|    uint64_t *dc = tmp1 + (uint32_t)10U;
   46|  3.68M|    Hacl_Impl_Curve25519_Field51_fadd(a, x2, z2);
   47|  3.68M|    Hacl_Impl_Curve25519_Field51_fsub(b, x2, z2);
   48|  3.68M|    uint64_t *x3 = nq_p1;
   49|  3.68M|    uint64_t *z31 = nq_p1 + (uint32_t)5U;
   50|  3.68M|    uint64_t *d0 = dc;
   51|  3.68M|    uint64_t *c0 = dc + (uint32_t)5U;
   52|  3.68M|    Hacl_Impl_Curve25519_Field51_fadd(c0, x3, z31);
   53|  3.68M|    Hacl_Impl_Curve25519_Field51_fsub(d0, x3, z31);
   54|  3.68M|    Hacl_Impl_Curve25519_Field51_fmul2(dc, dc, ab, tmp2);
   55|  3.68M|    Hacl_Impl_Curve25519_Field51_fadd(x3, d0, c0);
   56|  3.68M|    Hacl_Impl_Curve25519_Field51_fsub(z31, d0, c0);
   57|  3.68M|    uint64_t *a1 = tmp1;
   58|  3.68M|    uint64_t *b1 = tmp1 + (uint32_t)5U;
   59|  3.68M|    uint64_t *d = tmp1 + (uint32_t)10U;
   60|  3.68M|    uint64_t *c = tmp1 + (uint32_t)15U;
   61|  3.68M|    uint64_t *ab1 = tmp1;
   62|  3.68M|    uint64_t *dc1 = tmp1 + (uint32_t)10U;
   63|  3.68M|    Hacl_Impl_Curve25519_Field51_fsqr2(dc1, ab1, tmp2);
   64|  3.68M|    Hacl_Impl_Curve25519_Field51_fsqr2(nq_p1, nq_p1, tmp2);
   65|  3.68M|    a1[0U] = c[0U];
   66|  3.68M|    a1[1U] = c[1U];
   67|  3.68M|    a1[2U] = c[2U];
   68|  3.68M|    a1[3U] = c[3U];
   69|  3.68M|    a1[4U] = c[4U];
   70|  3.68M|    Hacl_Impl_Curve25519_Field51_fsub(c, d, c);
   71|  3.68M|    Hacl_Impl_Curve25519_Field51_fmul1(b1, c, (uint64_t)121665U);
   72|  3.68M|    Hacl_Impl_Curve25519_Field51_fadd(b1, b1, d);
   73|  3.68M|    Hacl_Impl_Curve25519_Field51_fmul2(nq, dc1, ab1, tmp2);
   74|  3.68M|    Hacl_Impl_Curve25519_Field51_fmul(z3, z3, x1, tmp2);
   75|  3.68M|}
Hacl_Curve25519_51.c:point_double:
   79|  43.8k|{
   80|  43.8k|    uint64_t *x2 = nq;
   81|  43.8k|    uint64_t *z2 = nq + (uint32_t)5U;
   82|  43.8k|    uint64_t *a = tmp1;
   83|  43.8k|    uint64_t *b = tmp1 + (uint32_t)5U;
   84|  43.8k|    uint64_t *d = tmp1 + (uint32_t)10U;
   85|  43.8k|    uint64_t *c = tmp1 + (uint32_t)15U;
   86|  43.8k|    uint64_t *ab = tmp1;
   87|  43.8k|    uint64_t *dc = tmp1 + (uint32_t)10U;
   88|  43.8k|    Hacl_Impl_Curve25519_Field51_fadd(a, x2, z2);
   89|  43.8k|    Hacl_Impl_Curve25519_Field51_fsub(b, x2, z2);
   90|  43.8k|    Hacl_Impl_Curve25519_Field51_fsqr2(dc, ab, tmp2);
   91|  43.8k|    a[0U] = c[0U];
   92|  43.8k|    a[1U] = c[1U];
   93|  43.8k|    a[2U] = c[2U];
   94|  43.8k|    a[3U] = c[3U];
   95|  43.8k|    a[4U] = c[4U];
   96|  43.8k|    Hacl_Impl_Curve25519_Field51_fsub(c, d, c);
   97|  43.8k|    Hacl_Impl_Curve25519_Field51_fmul1(b, c, (uint64_t)121665U);
   98|  43.8k|    Hacl_Impl_Curve25519_Field51_fadd(b, b, d);
   99|  43.8k|    Hacl_Impl_Curve25519_Field51_fmul2(nq, dc, ab, tmp2);
  100|  43.8k|}
Hacl_Curve25519_51.c:encode_point:
  214|  14.6k|{
  215|  14.6k|    uint64_t *x = i;
  216|  14.6k|    uint64_t *z = i + (uint32_t)5U;
  217|  14.6k|    uint64_t tmp[5U] = { 0U };
  218|  14.6k|    uint64_t u64s[4U] = { 0U };
  219|  14.6k|    FStar_UInt128_uint128 tmp_w[10U];
  220|   160k|    for (uint32_t _i = 0U; _i < (uint32_t)10U; ++_i)
  ------------------
  |  Branch (220:28): [True: 146k, False: 14.6k]
  ------------------
  221|   146k|        tmp_w[_i] = FStar_UInt128_uint64_to_uint128((uint64_t)0U);
  222|  14.6k|    Hacl_Curve25519_51_finv(tmp, z, tmp_w);
  223|  14.6k|    Hacl_Impl_Curve25519_Field51_fmul(tmp, tmp, x, tmp_w);
  224|  14.6k|    Hacl_Impl_Curve25519_Field51_store_felem(u64s, tmp);
  225|  14.6k|    KRML_MAYBE_FOR4(i0,
  ------------------
  |  |  330|  14.6k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  14.6k|    do {                               \
  |  |  |  |  289|  14.6k|        uint32_t i = z;                \
  |  |  |  |  290|  14.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  14.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  226|  14.6k|                    (uint32_t)0U,
  227|  14.6k|                    (uint32_t)4U,
  228|  14.6k|                    (uint32_t)1U,
  229|  14.6k|                    store64_le(o + i0 * (uint32_t)8U, u64s[i0]););
  230|  14.6k|}

Hacl_Impl_P256_DH_ecp256dh_i:
 1284|  8.73k|{
 1285|  8.73k|    uint64_t tmp[16U] = { 0U };
 1286|  8.73k|    uint64_t *sk = tmp;
 1287|  8.73k|    uint64_t *pk = tmp + (uint32_t)4U;
 1288|  8.73k|    bn_from_bytes_be4(sk, private_key);
 1289|  8.73k|    uint64_t is_b_valid = bn_is_lt_order_and_gt_zero_mask4(sk);
 1290|  8.73k|    uint64_t oneq[4U] = { 0U };
 1291|  8.73k|    oneq[0U] = (uint64_t)1U;
 1292|  8.73k|    oneq[1U] = (uint64_t)0U;
 1293|  8.73k|    oneq[2U] = (uint64_t)0U;
 1294|  8.73k|    oneq[3U] = (uint64_t)0U;
 1295|  8.73k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  8.73k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  8.73k|    do {                               \
  |  |  |  |  289|  8.73k|        uint32_t i = z;                \
  |  |  |  |  290|  8.73k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  8.73k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1296|  8.73k|                    (uint32_t)0U,
 1297|  8.73k|                    (uint32_t)4U,
 1298|  8.73k|                    (uint32_t)1U,
 1299|  8.73k|                    uint64_t *os = sk;
 1300|  8.73k|                    uint64_t uu____0 = oneq[i];
 1301|  8.73k|                    uint64_t x = uu____0 ^ (is_b_valid & (sk[i] ^ uu____0));
 1302|  8.73k|                    os[i] = x;);
 1303|  8.73k|    uint64_t is_sk_valid = is_b_valid;
 1304|  8.73k|    point_mul_g(pk, sk);
 1305|  8.73k|    point_store(public_key, pk);
 1306|  8.73k|    return is_sk_valid == (uint64_t)0xFFFFFFFFFFFFFFFFU;
 1307|  8.73k|}
Hacl_Impl_P256_DH_ecp256dh_r:
 1314|  8.21k|{
 1315|  8.21k|    uint64_t tmp[16U] = { 0U };
 1316|  8.21k|    uint64_t *sk = tmp;
 1317|  8.21k|    uint64_t *pk = tmp + (uint32_t)4U;
 1318|  8.21k|    bool is_pk_valid = load_point_vartime(pk, their_pubkey);
 1319|  8.21k|    bn_from_bytes_be4(sk, private_key);
 1320|  8.21k|    uint64_t is_b_valid = bn_is_lt_order_and_gt_zero_mask4(sk);
 1321|  8.21k|    uint64_t oneq[4U] = { 0U };
 1322|  8.21k|    oneq[0U] = (uint64_t)1U;
 1323|  8.21k|    oneq[1U] = (uint64_t)0U;
 1324|  8.21k|    oneq[2U] = (uint64_t)0U;
 1325|  8.21k|    oneq[3U] = (uint64_t)0U;
 1326|  8.21k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  8.21k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  8.21k|    do {                               \
  |  |  |  |  289|  8.21k|        uint32_t i = z;                \
  |  |  |  |  290|  8.21k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  8.21k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1327|  8.21k|                    (uint32_t)0U,
 1328|  8.21k|                    (uint32_t)4U,
 1329|  8.21k|                    (uint32_t)1U,
 1330|  8.21k|                    uint64_t *os = sk;
 1331|  8.21k|                    uint64_t uu____0 = oneq[i];
 1332|  8.21k|                    uint64_t x = uu____0 ^ (is_b_valid & (sk[i] ^ uu____0));
 1333|  8.21k|                    os[i] = x;);
 1334|  8.21k|    uint64_t is_sk_valid = is_b_valid;
 1335|  8.21k|    uint64_t ss_proj[12U] = { 0U };
 1336|  8.21k|    if (is_pk_valid) {
  ------------------
  |  Branch (1336:9): [True: 8.21k, False: 0]
  ------------------
 1337|  8.21k|        point_mul(ss_proj, sk, pk);
 1338|  8.21k|        point_store(shared_secret, ss_proj);
 1339|  8.21k|    }
 1340|  8.21k|    return is_sk_valid == (uint64_t)0xFFFFFFFFFFFFFFFFU && is_pk_valid;
  ------------------
  |  Branch (1340:12): [True: 8.21k, False: 0]
  |  Branch (1340:60): [True: 8.21k, False: 0]
  ------------------
 1341|  8.21k|}
Hacl_P256_ecdsa_sign_p256_without_hash:
 1604|  11.7k|{
 1605|  11.7k|    uint64_t m_q[4U] = { 0U };
 1606|  11.7k|    uint8_t mHash[32U] = { 0U };
 1607|  11.7k|    memcpy(mHash, msg, (uint32_t)32U * sizeof(uint8_t));
 1608|  11.7k|    KRML_HOST_IGNORE(msg_len);
  ------------------
  |  |   56|  11.7k|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
 1609|  11.7k|    uint8_t *mHash32 = mHash;
 1610|  11.7k|    bn_from_bytes_be4(m_q, mHash32);
 1611|  11.7k|    qmod_short(m_q, m_q);
 1612|  11.7k|    bool res = ecdsa_sign_msg_as_qelem(signature, m_q, private_key, nonce);
 1613|  11.7k|    return res;
 1614|  11.7k|}
Hacl_P256_validate_public_key:
 1675|  17.0k|{
 1676|  17.0k|    uint64_t point_jac[12U] = { 0U };
 1677|  17.0k|    bool res = load_point_vartime(point_jac, public_key);
 1678|  17.0k|    return res;
 1679|  17.0k|}
Hacl_P256_validate_private_key:
 1693|  20.4k|{
 1694|  20.4k|    uint64_t bn_sk[4U] = { 0U };
 1695|  20.4k|    bn_from_bytes_be4(bn_sk, private_key);
 1696|  20.4k|    uint64_t res = bn_is_lt_order_and_gt_zero_mask4(bn_sk);
 1697|  20.4k|    return res == (uint64_t)0xFFFFFFFFFFFFFFFFU;
 1698|  20.4k|}
Hacl_P256_dh_initiator:
 1809|  8.73k|{
 1810|  8.73k|    return Hacl_Impl_P256_DH_ecp256dh_i(public_key, private_key);
 1811|  8.73k|}
Hacl_P256_dh_responder:
 1827|  8.21k|{
 1828|  8.21k|    return Hacl_Impl_P256_DH_ecp256dh_r(shared_secret, their_pubkey, private_key);
 1829|  8.21k|}
Hacl_P256.c:bn_from_bytes_be4:
  316|   123k|{
  317|   123k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|   123k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|   123k|    do {                               \
  |  |  |  |  289|   123k|        uint32_t i = z;                \
  |  |  |  |  290|   123k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   123k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  318|   123k|                    (uint32_t)0U,
  319|   123k|                    (uint32_t)4U,
  320|   123k|                    (uint32_t)1U,
  321|   123k|                    uint64_t *os = res;
  322|   123k|                    uint64_t u = load64_be(b + ((uint32_t)4U - i - (uint32_t)1U) * (uint32_t)8U);
  323|   123k|                    uint64_t x = u;
  324|   123k|                    os[i] = x;);
  325|   123k|}
Hacl_P256.c:bn_is_lt_order_and_gt_zero_mask4:
 1170|  60.8k|{
 1171|  60.8k|    uint64_t is_lt_order = bn_is_lt_order_mask4(f);
 1172|  60.8k|    uint64_t is_eq_zero = bn_is_zero_mask4(f);
 1173|  60.8k|    return is_lt_order & ~is_eq_zero;
 1174|  60.8k|}
Hacl_P256.c:bn_is_lt_order_mask4:
 1161|  60.8k|{
 1162|  60.8k|    uint64_t tmp[4U] = { 0U };
 1163|  60.8k|    make_order(tmp);
 1164|  60.8k|    uint64_t c = bn_sub4(tmp, f, tmp);
 1165|  60.8k|    return (uint64_t)0U - c;
 1166|  60.8k|}
Hacl_P256.c:make_order:
  345|  3.55M|{
  346|  3.55M|    n[0U] = (uint64_t)0xf3b9cac2fc632551U;
  347|  3.55M|    n[1U] = (uint64_t)0xbce6faada7179e84U;
  348|  3.55M|    n[2U] = (uint64_t)0xffffffffffffffffU;
  349|  3.55M|    n[3U] = (uint64_t)0xffffffff00000000U;
  350|  3.55M|}
Hacl_P256.c:bn_sub4:
  146|   134k|{
  147|   134k|    uint64_t c = (uint64_t)0U;
  148|   134k|    {
  149|   134k|        uint64_t t1 = x[(uint32_t)4U * (uint32_t)0U];
  150|   134k|        uint64_t t20 = y[(uint32_t)4U * (uint32_t)0U];
  151|   134k|        uint64_t *res_i0 = res + (uint32_t)4U * (uint32_t)0U;
  152|   134k|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t20, res_i0);
  ------------------
  |  |   89|   134k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  153|   134k|        uint64_t t10 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  154|   134k|        uint64_t t21 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  155|   134k|        uint64_t *res_i1 = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  156|   134k|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t10, t21, res_i1);
  ------------------
  |  |   89|   134k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  157|   134k|        uint64_t t11 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  158|   134k|        uint64_t t22 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  159|   134k|        uint64_t *res_i2 = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  160|   134k|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t11, t22, res_i2);
  ------------------
  |  |   89|   134k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  161|   134k|        uint64_t t12 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  162|   134k|        uint64_t t2 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  163|   134k|        uint64_t *res_i = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  164|   134k|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t12, t2, res_i);
  ------------------
  |  |   89|   134k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  165|   134k|    }
  166|   134k|    uint64_t c0 = c;
  167|   134k|    return c0;
  168|   134k|}
Hacl_P256.c:bn_is_zero_mask4:
   34|  84.2k|{
   35|  84.2k|    uint64_t bn_zero[4U] = { 0U };
   36|  84.2k|    uint64_t mask = (uint64_t)0xFFFFFFFFFFFFFFFFU;
   37|  84.2k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  84.2k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  84.2k|    do {                               \
  |  |  |  |  289|  84.2k|        uint32_t i = z;                \
  |  |  |  |  290|  84.2k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  84.2k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   38|  84.2k|                    (uint32_t)0U,
   39|  84.2k|                    (uint32_t)4U,
   40|  84.2k|                    (uint32_t)1U,
   41|  84.2k|                    uint64_t uu____0 = FStar_UInt64_eq_mask(f[i], bn_zero[i]);
   42|  84.2k|                    mask = uu____0 & mask;);
   43|  84.2k|    uint64_t mask1 = mask;
   44|  84.2k|    uint64_t res = mask1;
   45|  84.2k|    return res;
   46|  84.2k|}
Hacl_P256.c:point_mul_g:
 1039|  20.4k|{
 1040|  20.4k|    uint64_t q1[12U] = { 0U };
 1041|  20.4k|    make_base_point(q1);
 1042|  20.4k|    uint64_t
 1043|  20.4k|        q2[12U] = {
 1044|  20.4k|            (uint64_t)1499621593102562565U, (uint64_t)16692369783039433128U,
 1045|  20.4k|            (uint64_t)15337520135922861848U, (uint64_t)5455737214495366228U,
 1046|  20.4k|            (uint64_t)17827017231032529600U, (uint64_t)12413621606240782649U,
 1047|  20.4k|            (uint64_t)2290483008028286132U, (uint64_t)15752017553340844820U,
 1048|  20.4k|            (uint64_t)4846430910634234874U, (uint64_t)10861682798464583253U,
 1049|  20.4k|            (uint64_t)15404737222404363049U, (uint64_t)363586619281562022U
 1050|  20.4k|        };
 1051|  20.4k|    uint64_t
 1052|  20.4k|        q3[12U] = {
 1053|  20.4k|            (uint64_t)14619254753077084366U, (uint64_t)13913835116514008593U,
 1054|  20.4k|            (uint64_t)15060744674088488145U, (uint64_t)17668414598203068685U,
 1055|  20.4k|            (uint64_t)10761169236902342334U, (uint64_t)15467027479157446221U,
 1056|  20.4k|            (uint64_t)14989185522423469618U, (uint64_t)14354539272510107003U,
 1057|  20.4k|            (uint64_t)14298211796392133693U, (uint64_t)13270323784253711450U,
 1058|  20.4k|            (uint64_t)13380964971965046957U, (uint64_t)8686204248456909699U
 1059|  20.4k|        };
 1060|  20.4k|    uint64_t
 1061|  20.4k|        q4[12U] = {
 1062|  20.4k|            (uint64_t)7870395003430845958U, (uint64_t)18001862936410067720U,
 1063|  20.4k|            (uint64_t)8006461232116967215U, (uint64_t)5921313779532424762U,
 1064|  20.4k|            (uint64_t)10702113371959864307U, (uint64_t)8070517410642379879U,
 1065|  20.4k|            (uint64_t)7139806720777708306U, (uint64_t)8253938546650739833U,
 1066|  20.4k|            (uint64_t)17490482834545705718U, (uint64_t)1065249776797037500U,
 1067|  20.4k|            (uint64_t)5018258455937968775U, (uint64_t)14100621120178668337U
 1068|  20.4k|        };
 1069|  20.4k|    uint64_t *r1 = scalar;
 1070|  20.4k|    uint64_t *r2 = scalar + (uint32_t)1U;
 1071|  20.4k|    uint64_t *r3 = scalar + (uint32_t)2U;
 1072|  20.4k|    uint64_t *r4 = scalar + (uint32_t)3U;
 1073|  20.4k|    make_point_at_inf(res);
 1074|  20.4k|    uint64_t tmp[12U] = { 0U };
 1075|  20.4k|    KRML_MAYBE_FOR16(i,
  ------------------
  |  |  402|  20.4k|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|  20.4k|    do {                               \
  |  |  |  |  289|  20.4k|        uint32_t i = z;                \
  |  |  |  |  290|  20.4k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  20.4k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1076|  20.4k|                     (uint32_t)0U,
 1077|  20.4k|                     (uint32_t)16U,
 1078|  20.4k|                     (uint32_t)1U,
 1079|  20.4k|                     KRML_MAYBE_FOR4(i0, (uint32_t)0U, (uint32_t)4U, (uint32_t)1U, point_double(res, res););
 1080|  20.4k|                     uint32_t k = (uint32_t)64U - (uint32_t)4U * i - (uint32_t)4U;
 1081|  20.4k|                     uint64_t bits_l = Hacl_Bignum_Lib_bn_get_bits_u64((uint32_t)1U, r4, k, (uint32_t)4U);
 1082|  20.4k|                     precomp_get_consttime(Hacl_P256_PrecompTable_precomp_g_pow2_192_table_w4, bits_l, tmp);
 1083|  20.4k|                     point_add(res, res, tmp);
 1084|  20.4k|                     uint32_t k0 = (uint32_t)64U - (uint32_t)4U * i - (uint32_t)4U;
 1085|  20.4k|                     uint64_t bits_l0 = Hacl_Bignum_Lib_bn_get_bits_u64((uint32_t)1U, r3, k0, (uint32_t)4U);
 1086|  20.4k|                     precomp_get_consttime(Hacl_P256_PrecompTable_precomp_g_pow2_128_table_w4, bits_l0, tmp);
 1087|  20.4k|                     point_add(res, res, tmp);
 1088|  20.4k|                     uint32_t k1 = (uint32_t)64U - (uint32_t)4U * i - (uint32_t)4U;
 1089|  20.4k|                     uint64_t bits_l1 = Hacl_Bignum_Lib_bn_get_bits_u64((uint32_t)1U, r2, k1, (uint32_t)4U);
 1090|  20.4k|                     precomp_get_consttime(Hacl_P256_PrecompTable_precomp_g_pow2_64_table_w4, bits_l1, tmp);
 1091|  20.4k|                     point_add(res, res, tmp);
 1092|  20.4k|                     uint32_t k2 = (uint32_t)64U - (uint32_t)4U * i - (uint32_t)4U;
 1093|  20.4k|                     uint64_t bits_l2 = Hacl_Bignum_Lib_bn_get_bits_u64((uint32_t)1U, r1, k2, (uint32_t)4U);
 1094|  20.4k|                     precomp_get_consttime(Hacl_P256_PrecompTable_precomp_basepoint_table_w4, bits_l2, tmp);
 1095|  20.4k|                     point_add(res, res, tmp););
 1096|  20.4k|    KRML_HOST_IGNORE(q1);
  ------------------
  |  |   56|  20.4k|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
 1097|  20.4k|    KRML_HOST_IGNORE(q2);
  ------------------
  |  |   56|  20.4k|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
 1098|  20.4k|    KRML_HOST_IGNORE(q3);
  ------------------
  |  |   56|  20.4k|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
 1099|  20.4k|    KRML_HOST_IGNORE(q4);
  ------------------
  |  |   56|  20.4k|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
 1100|  20.4k|}
Hacl_P256.c:make_base_point:
  663|  20.4k|{
  664|  20.4k|    uint64_t *x = p;
  665|  20.4k|    uint64_t *y = p + (uint32_t)4U;
  666|  20.4k|    uint64_t *z = p + (uint32_t)8U;
  667|  20.4k|    make_g_x(x);
  668|  20.4k|    make_g_y(y);
  669|  20.4k|    make_fone(z);
  670|  20.4k|}
Hacl_P256.c:make_g_x:
  372|  20.4k|{
  373|  20.4k|    n[0U] = (uint64_t)0x79e730d418a9143cU;
  374|  20.4k|    n[1U] = (uint64_t)0x75ba95fc5fedb601U;
  375|  20.4k|    n[2U] = (uint64_t)0x79fb732b77622510U;
  376|  20.4k|    n[3U] = (uint64_t)0x18905f76a53755c6U;
  377|  20.4k|}
Hacl_P256.c:make_g_y:
  381|  20.4k|{
  382|  20.4k|    n[0U] = (uint64_t)0xddf25357ce95560aU;
  383|  20.4k|    n[1U] = (uint64_t)0x8b4ab8e4ba19e45cU;
  384|  20.4k|    n[2U] = (uint64_t)0xd2e88688dd21f325U;
  385|  20.4k|    n[3U] = (uint64_t)0x8571ff1825885d85U;
  386|  20.4k|}
Hacl_P256.c:make_fone:
  408|  82.4k|{
  409|  82.4k|    n[0U] = (uint64_t)0x1U;
  410|  82.4k|    n[1U] = (uint64_t)0xffffffff00000000U;
  411|  82.4k|    n[2U] = (uint64_t)0xffffffffffffffffU;
  412|  82.4k|    n[3U] = (uint64_t)0xfffffffeU;
  413|  82.4k|}
Hacl_P256.c:make_point_at_inf:
  674|  36.8k|{
  675|  36.8k|    uint64_t *x = p;
  676|  36.8k|    uint64_t *y = p + (uint32_t)4U;
  677|  36.8k|    uint64_t *z = p + (uint32_t)8U;
  678|  36.8k|    make_fzero(x);
  679|  36.8k|    make_fone(y);
  680|  36.8k|    make_fzero(z);
  681|  36.8k|}
Hacl_P256.c:make_fzero:
  399|  73.7k|{
  400|  73.7k|    n[0U] = (uint64_t)0U;
  401|  73.7k|    n[1U] = (uint64_t)0U;
  402|  73.7k|    n[2U] = (uint64_t)0U;
  403|  73.7k|    n[3U] = (uint64_t)0U;
  404|  73.7k|}
Hacl_P256.c:point_double:
  845|  3.46M|{
  846|  3.46M|    uint64_t tmp[20U] = { 0U };
  847|  3.46M|    uint64_t *x = p;
  848|  3.46M|    uint64_t *z = p + (uint32_t)8U;
  849|  3.46M|    uint64_t *x3 = res;
  850|  3.46M|    uint64_t *y3 = res + (uint32_t)4U;
  851|  3.46M|    uint64_t *z3 = res + (uint32_t)8U;
  852|  3.46M|    uint64_t *t0 = tmp;
  853|  3.46M|    uint64_t *t1 = tmp + (uint32_t)4U;
  854|  3.46M|    uint64_t *t2 = tmp + (uint32_t)8U;
  855|  3.46M|    uint64_t *t3 = tmp + (uint32_t)12U;
  856|  3.46M|    uint64_t *t4 = tmp + (uint32_t)16U;
  857|  3.46M|    uint64_t *x1 = p;
  858|  3.46M|    uint64_t *y = p + (uint32_t)4U;
  859|  3.46M|    uint64_t *z1 = p + (uint32_t)8U;
  860|  3.46M|    fsqr0(t0, x1);
  861|  3.46M|    fsqr0(t1, y);
  862|  3.46M|    fsqr0(t2, z1);
  863|  3.46M|    fmul0(t3, x1, y);
  864|  3.46M|    fadd0(t3, t3, t3);
  865|  3.46M|    fmul0(t4, y, z1);
  866|  3.46M|    fmul0(z3, x, z);
  867|  3.46M|    fadd0(z3, z3, z3);
  868|  3.46M|    fmul_by_b_coeff(y3, t2);
  869|  3.46M|    fsub0(y3, y3, z3);
  870|  3.46M|    fadd0(x3, y3, y3);
  871|  3.46M|    fadd0(y3, x3, y3);
  872|  3.46M|    fsub0(x3, t1, y3);
  873|  3.46M|    fadd0(y3, t1, y3);
  874|  3.46M|    fmul0(y3, x3, y3);
  875|  3.46M|    fmul0(x3, x3, t3);
  876|  3.46M|    fadd0(t3, t2, t2);
  877|  3.46M|    fadd0(t2, t2, t3);
  878|  3.46M|    fmul_by_b_coeff(z3, z3);
  879|  3.46M|    fsub0(z3, z3, t2);
  880|  3.46M|    fsub0(z3, z3, t0);
  881|  3.46M|    fadd0(t3, z3, z3);
  882|  3.46M|    fadd0(z3, z3, t3);
  883|  3.46M|    fadd0(t3, t0, t0);
  884|  3.46M|    fadd0(t0, t3, t0);
  885|  3.46M|    fsub0(t0, t0, t2);
  886|  3.46M|    fmul0(t0, t0, z3);
  887|  3.46M|    fadd0(y3, y3, t0);
  888|  3.46M|    fadd0(t0, t4, t4);
  889|  3.46M|    fmul0(z3, t0, z3);
  890|  3.46M|    fsub0(x3, x3, z3);
  891|  3.46M|    fmul0(z3, t0, t1);
  892|  3.46M|    fadd0(z3, z3, z3);
  893|  3.46M|    fadd0(z3, z3, z3);
  894|  3.46M|}
Hacl_P256.c:fsqr0:
  531|  17.7M|{
  532|  17.7M|    uint64_t tmp[8U] = { 0U };
  533|  17.7M|    bn_sqr4(tmp, x);
  534|  17.7M|    mont_reduction(res, tmp);
  535|  17.7M|}
Hacl_P256.c:bn_sqr4:
  256|  20.7M|{
  257|  20.7M|    memset(res, 0U, (uint32_t)8U * sizeof(uint64_t));
  258|  20.7M|    KRML_MAYBE_FOR4(
  ------------------
  |  |  330|  20.7M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  20.7M|    do {                               \
  |  |  |  |  289|  20.7M|        uint32_t i = z;                \
  |  |  |  |  290|  20.7M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  20.7M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  259|  20.7M|        i0,
  260|  20.7M|        (uint32_t)0U,
  261|  20.7M|        (uint32_t)4U,
  262|  20.7M|        (uint32_t)1U,
  263|  20.7M|        uint64_t *ab = x;
  264|  20.7M|        uint64_t a_j = x[i0];
  265|  20.7M|        uint64_t *res_j = res + i0;
  266|  20.7M|        uint64_t c = (uint64_t)0U;
  267|  20.7M|        for (uint32_t i = (uint32_t)0U; i < i0 / (uint32_t)4U; i++) {
  268|  20.7M|            uint64_t a_i = ab[(uint32_t)4U * i];
  269|  20.7M|            uint64_t *res_i0 = res_j + (uint32_t)4U * i;
  270|  20.7M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, a_j, c, res_i0);
  271|  20.7M|            uint64_t a_i0 = ab[(uint32_t)4U * i + (uint32_t)1U];
  272|  20.7M|            uint64_t *res_i1 = res_j + (uint32_t)4U * i + (uint32_t)1U;
  273|  20.7M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, a_j, c, res_i1);
  274|  20.7M|            uint64_t a_i1 = ab[(uint32_t)4U * i + (uint32_t)2U];
  275|  20.7M|            uint64_t *res_i2 = res_j + (uint32_t)4U * i + (uint32_t)2U;
  276|  20.7M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, a_j, c, res_i2);
  277|  20.7M|            uint64_t a_i2 = ab[(uint32_t)4U * i + (uint32_t)3U];
  278|  20.7M|            uint64_t *res_i = res_j + (uint32_t)4U * i + (uint32_t)3U;
  279|  20.7M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, a_j, c, res_i);
  280|  20.7M|        } for (uint32_t i = i0 / (uint32_t)4U * (uint32_t)4U; i < i0; i++) {
  281|  20.7M|            uint64_t a_i = ab[i];
  282|  20.7M|            uint64_t *res_i = res_j + i;
  283|  20.7M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, a_j, c, res_i);
  284|  20.7M|        } uint64_t r = c;
  285|  20.7M|        res[i0 + i0] = r;);
  286|  20.7M|    uint64_t c0 = Hacl_Bignum_Addition_bn_add_eq_len_u64((uint32_t)8U, res, res, res);
  287|  20.7M|    KRML_HOST_IGNORE(c0);
  ------------------
  |  |   56|  20.7M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  288|  20.7M|    uint64_t tmp[8U] = { 0U };
  289|  20.7M|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  20.7M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  20.7M|    do {                               \
  |  |  |  |  289|  20.7M|        uint32_t i = z;                \
  |  |  |  |  290|  20.7M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  20.7M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  290|  20.7M|                    (uint32_t)0U,
  291|  20.7M|                    (uint32_t)4U,
  292|  20.7M|                    (uint32_t)1U,
  293|  20.7M|                    FStar_UInt128_uint128 res1 = FStar_UInt128_mul_wide(x[i], x[i]);
  294|  20.7M|                    uint64_t hi = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(res1, (uint32_t)64U));
  295|  20.7M|                    uint64_t lo = FStar_UInt128_uint128_to_uint64(res1);
  296|  20.7M|                    tmp[(uint32_t)2U * i] = lo;
  297|  20.7M|                    tmp[(uint32_t)2U * i + (uint32_t)1U] = hi;);
  298|  20.7M|    uint64_t c1 = Hacl_Bignum_Addition_bn_add_eq_len_u64((uint32_t)8U, res, tmp, res);
  299|  20.7M|    KRML_HOST_IGNORE(c1);
  ------------------
  |  |   56|  20.7M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  300|  20.7M|}
Hacl_P256.c:mont_reduction:
  458|  79.5M|{
  459|  79.5M|    uint64_t n[4U] = { 0U };
  460|  79.5M|    make_prime(n);
  461|  79.5M|    uint64_t c0 = (uint64_t)0U;
  462|  79.5M|    KRML_MAYBE_FOR4(
  ------------------
  |  |  330|  79.5M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  79.5M|    do {                               \
  |  |  |  |  289|  79.5M|        uint32_t i = z;                \
  |  |  |  |  290|  79.5M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  79.5M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  463|  79.5M|        i0,
  464|  79.5M|        (uint32_t)0U,
  465|  79.5M|        (uint32_t)4U,
  466|  79.5M|        (uint32_t)1U,
  467|  79.5M|        uint64_t qj = (uint64_t)1U * x[i0];
  468|  79.5M|        uint64_t *res_j0 = x + i0;
  469|  79.5M|        uint64_t c = (uint64_t)0U;
  470|  79.5M|        {
  471|  79.5M|            uint64_t a_i = n[(uint32_t)4U * (uint32_t)0U];
  472|  79.5M|            uint64_t *res_i0 = res_j0 + (uint32_t)4U * (uint32_t)0U;
  473|  79.5M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, qj, c, res_i0);
  474|  79.5M|            uint64_t a_i0 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  475|  79.5M|            uint64_t *res_i1 = res_j0 + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  476|  79.5M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, qj, c, res_i1);
  477|  79.5M|            uint64_t a_i1 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  478|  79.5M|            uint64_t *res_i2 = res_j0 + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  479|  79.5M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, qj, c, res_i2);
  480|  79.5M|            uint64_t a_i2 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  481|  79.5M|            uint64_t *res_i = res_j0 + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  482|  79.5M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, qj, c, res_i);
  483|  79.5M|        } uint64_t r = c;
  484|  79.5M|        uint64_t c1 = r;
  485|  79.5M|        uint64_t *resb = x + (uint32_t)4U + i0;
  486|  79.5M|        uint64_t res_j = x[(uint32_t)4U + i0];
  487|  79.5M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, c1, res_j, resb););
  488|  79.5M|    memcpy(res, x + (uint32_t)4U, (uint32_t)4U * sizeof(uint64_t));
  489|  79.5M|    uint64_t c00 = c0;
  490|  79.5M|    uint64_t tmp[4U] = { 0U };
  491|  79.5M|    uint64_t c = (uint64_t)0U;
  492|  79.5M|    {
  493|  79.5M|        uint64_t t1 = res[(uint32_t)4U * (uint32_t)0U];
  494|  79.5M|        uint64_t t20 = n[(uint32_t)4U * (uint32_t)0U];
  495|  79.5M|        uint64_t *res_i0 = tmp + (uint32_t)4U * (uint32_t)0U;
  496|  79.5M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t20, res_i0);
  ------------------
  |  |   89|  79.5M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  497|  79.5M|        uint64_t t10 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  498|  79.5M|        uint64_t t21 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  499|  79.5M|        uint64_t *res_i1 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  500|  79.5M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t10, t21, res_i1);
  ------------------
  |  |   89|  79.5M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  501|  79.5M|        uint64_t t11 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  502|  79.5M|        uint64_t t22 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  503|  79.5M|        uint64_t *res_i2 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  504|  79.5M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t11, t22, res_i2);
  ------------------
  |  |   89|  79.5M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  505|  79.5M|        uint64_t t12 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  506|  79.5M|        uint64_t t2 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  507|  79.5M|        uint64_t *res_i = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  508|  79.5M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t12, t2, res_i);
  ------------------
  |  |   89|  79.5M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  509|  79.5M|    }
  510|  79.5M|    uint64_t c1 = c;
  511|  79.5M|    uint64_t c2 = c00 - c1;
  512|  79.5M|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  79.5M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  79.5M|    do {                               \
  |  |  |  |  289|  79.5M|        uint32_t i = z;                \
  |  |  |  |  290|  79.5M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  79.5M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  513|  79.5M|                    (uint32_t)0U,
  514|  79.5M|                    (uint32_t)4U,
  515|  79.5M|                    (uint32_t)1U,
  516|  79.5M|                    uint64_t *os = res;
  517|  79.5M|                    uint64_t x1 = (c2 & res[i]) | (~c2 & tmp[i]);
  518|  79.5M|                    os[i] = x1;);
  519|  79.5M|}
Hacl_P256.c:make_prime:
  336|   207M|{
  337|   207M|    n[0U] = (uint64_t)0xffffffffffffffffU;
  338|   207M|    n[1U] = (uint64_t)0xffffffffU;
  339|   207M|    n[2U] = (uint64_t)0x0U;
  340|   207M|    n[3U] = (uint64_t)0xffffffff00000001U;
  341|   207M|}
Hacl_P256.c:fmul0:
  523|  61.7M|{
  524|  61.7M|    uint64_t tmp[8U] = { 0U };
  525|  61.7M|    bn_mul4(tmp, x, y);
  526|  61.7M|    mont_reduction(res, tmp);
  527|  61.7M|}
Hacl_P256.c:bn_mul4:
  227|  62.1M|{
  228|  62.1M|    memset(res, 0U, (uint32_t)8U * sizeof(uint64_t));
  229|  62.1M|    KRML_MAYBE_FOR4(
  ------------------
  |  |  330|  62.1M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  62.1M|    do {                               \
  |  |  |  |  289|  62.1M|        uint32_t i = z;                \
  |  |  |  |  290|  62.1M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  62.1M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  230|  62.1M|        i0,
  231|  62.1M|        (uint32_t)0U,
  232|  62.1M|        (uint32_t)4U,
  233|  62.1M|        (uint32_t)1U,
  234|  62.1M|        uint64_t bj = y[i0];
  235|  62.1M|        uint64_t *res_j = res + i0;
  236|  62.1M|        uint64_t c = (uint64_t)0U;
  237|  62.1M|        {
  238|  62.1M|            uint64_t a_i = x[(uint32_t)4U * (uint32_t)0U];
  239|  62.1M|            uint64_t *res_i0 = res_j + (uint32_t)4U * (uint32_t)0U;
  240|  62.1M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, bj, c, res_i0);
  241|  62.1M|            uint64_t a_i0 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  242|  62.1M|            uint64_t *res_i1 = res_j + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  243|  62.1M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, bj, c, res_i1);
  244|  62.1M|            uint64_t a_i1 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  245|  62.1M|            uint64_t *res_i2 = res_j + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  246|  62.1M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, bj, c, res_i2);
  247|  62.1M|            uint64_t a_i2 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  248|  62.1M|            uint64_t *res_i = res_j + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  249|  62.1M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, bj, c, res_i);
  250|  62.1M|        } uint64_t r = c;
  251|  62.1M|        res[(uint32_t)4U + i0] = r;);
  252|  62.1M|}
Hacl_P256.c:fadd0:
  433|  89.9M|{
  434|  89.9M|    uint64_t n[4U] = { 0U };
  435|  89.9M|    make_prime(n);
  436|  89.9M|    bn_add_mod4(res, n, x, y);
  437|  89.9M|}
Hacl_P256.c:bn_add_mod4:
   92|  89.9M|{
   93|  89.9M|    uint64_t c0 = (uint64_t)0U;
   94|  89.9M|    {
   95|  89.9M|        uint64_t t1 = x[(uint32_t)4U * (uint32_t)0U];
   96|  89.9M|        uint64_t t20 = y[(uint32_t)4U * (uint32_t)0U];
   97|  89.9M|        uint64_t *res_i0 = res + (uint32_t)4U * (uint32_t)0U;
   98|  89.9M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, t1, t20, res_i0);
  ------------------
  |  |   66|  89.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   99|  89.9M|        uint64_t t10 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  100|  89.9M|        uint64_t t21 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  101|  89.9M|        uint64_t *res_i1 = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  102|  89.9M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, t10, t21, res_i1);
  ------------------
  |  |   66|  89.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  103|  89.9M|        uint64_t t11 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  104|  89.9M|        uint64_t t22 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  105|  89.9M|        uint64_t *res_i2 = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  106|  89.9M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, t11, t22, res_i2);
  ------------------
  |  |   66|  89.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  107|  89.9M|        uint64_t t12 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  108|  89.9M|        uint64_t t2 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  109|  89.9M|        uint64_t *res_i = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  110|  89.9M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, t12, t2, res_i);
  ------------------
  |  |   66|  89.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  111|  89.9M|    }
  112|  89.9M|    uint64_t c00 = c0;
  113|  89.9M|    uint64_t tmp[4U] = { 0U };
  114|  89.9M|    uint64_t c = (uint64_t)0U;
  115|  89.9M|    {
  116|  89.9M|        uint64_t t1 = res[(uint32_t)4U * (uint32_t)0U];
  117|  89.9M|        uint64_t t20 = n[(uint32_t)4U * (uint32_t)0U];
  118|  89.9M|        uint64_t *res_i0 = tmp + (uint32_t)4U * (uint32_t)0U;
  119|  89.9M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t20, res_i0);
  ------------------
  |  |   89|  89.9M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  120|  89.9M|        uint64_t t10 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  121|  89.9M|        uint64_t t21 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  122|  89.9M|        uint64_t *res_i1 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  123|  89.9M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t10, t21, res_i1);
  ------------------
  |  |   89|  89.9M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  124|  89.9M|        uint64_t t11 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  125|  89.9M|        uint64_t t22 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  126|  89.9M|        uint64_t *res_i2 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  127|  89.9M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t11, t22, res_i2);
  ------------------
  |  |   89|  89.9M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  128|  89.9M|        uint64_t t12 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  129|  89.9M|        uint64_t t2 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  130|  89.9M|        uint64_t *res_i = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  131|  89.9M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t12, t2, res_i);
  ------------------
  |  |   89|  89.9M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  132|  89.9M|    }
  133|  89.9M|    uint64_t c1 = c;
  134|  89.9M|    uint64_t c2 = c00 - c1;
  135|  89.9M|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  89.9M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  89.9M|    do {                               \
  |  |  |  |  289|  89.9M|        uint32_t i = z;                \
  |  |  |  |  290|  89.9M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  89.9M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  136|  89.9M|                    (uint32_t)0U,
  137|  89.9M|                    (uint32_t)4U,
  138|  89.9M|                    (uint32_t)1U,
  139|  89.9M|                    uint64_t *os = res;
  140|  89.9M|                    uint64_t x1 = (c2 & res[i]) | (~c2 & tmp[i]);
  141|  89.9M|                    os[i] = x1;);
  142|  89.9M|}
Hacl_P256.c:fmul_by_b_coeff:
  555|  10.7M|{
  556|  10.7M|    uint64_t b_coeff[4U] = { 0U };
  557|  10.7M|    make_b_coeff(b_coeff);
  558|  10.7M|    fmul0(res, b_coeff, x);
  559|  10.7M|}
Hacl_P256.c:make_b_coeff:
  363|  10.7M|{
  364|  10.7M|    b[0U] = (uint64_t)0xd89cdf6229c4bddfU;
  365|  10.7M|    b[1U] = (uint64_t)0xacf005cd78843090U;
  366|  10.7M|    b[2U] = (uint64_t)0xe5a220abf7212ed6U;
  367|  10.7M|    b[3U] = (uint64_t)0xdc30061d04874834U;
  368|  10.7M|}
Hacl_P256.c:fsub0:
  441|  37.8M|{
  442|  37.8M|    uint64_t n[4U] = { 0U };
  443|  37.8M|    make_prime(n);
  444|  37.8M|    bn_sub_mod4(res, n, x, y);
  445|  37.8M|}
Hacl_P256.c:bn_sub_mod4:
  172|  37.8M|{
  173|  37.8M|    uint64_t c0 = (uint64_t)0U;
  174|  37.8M|    {
  175|  37.8M|        uint64_t t1 = x[(uint32_t)4U * (uint32_t)0U];
  176|  37.8M|        uint64_t t20 = y[(uint32_t)4U * (uint32_t)0U];
  177|  37.8M|        uint64_t *res_i0 = res + (uint32_t)4U * (uint32_t)0U;
  178|  37.8M|        c0 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c0, t1, t20, res_i0);
  ------------------
  |  |   89|  37.8M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  179|  37.8M|        uint64_t t10 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  180|  37.8M|        uint64_t t21 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  181|  37.8M|        uint64_t *res_i1 = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  182|  37.8M|        c0 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c0, t10, t21, res_i1);
  ------------------
  |  |   89|  37.8M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  183|  37.8M|        uint64_t t11 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  184|  37.8M|        uint64_t t22 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  185|  37.8M|        uint64_t *res_i2 = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  186|  37.8M|        c0 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c0, t11, t22, res_i2);
  ------------------
  |  |   89|  37.8M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  187|  37.8M|        uint64_t t12 = x[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  188|  37.8M|        uint64_t t2 = y[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  189|  37.8M|        uint64_t *res_i = res + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  190|  37.8M|        c0 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c0, t12, t2, res_i);
  ------------------
  |  |   89|  37.8M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  191|  37.8M|    }
  192|  37.8M|    uint64_t c00 = c0;
  193|  37.8M|    uint64_t tmp[4U] = { 0U };
  194|  37.8M|    uint64_t c = (uint64_t)0U;
  195|  37.8M|    {
  196|  37.8M|        uint64_t t1 = res[(uint32_t)4U * (uint32_t)0U];
  197|  37.8M|        uint64_t t20 = n[(uint32_t)4U * (uint32_t)0U];
  198|  37.8M|        uint64_t *res_i0 = tmp + (uint32_t)4U * (uint32_t)0U;
  199|  37.8M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t20, res_i0);
  ------------------
  |  |   66|  37.8M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  200|  37.8M|        uint64_t t10 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  201|  37.8M|        uint64_t t21 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
  202|  37.8M|        uint64_t *res_i1 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
  203|  37.8M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t10, t21, res_i1);
  ------------------
  |  |   66|  37.8M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  204|  37.8M|        uint64_t t11 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  205|  37.8M|        uint64_t t22 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
  206|  37.8M|        uint64_t *res_i2 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
  207|  37.8M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t11, t22, res_i2);
  ------------------
  |  |   66|  37.8M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  208|  37.8M|        uint64_t t12 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  209|  37.8M|        uint64_t t2 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
  210|  37.8M|        uint64_t *res_i = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
  211|  37.8M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t12, t2, res_i);
  ------------------
  |  |   66|  37.8M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  212|  37.8M|    }
  213|  37.8M|    uint64_t c1 = c;
  214|  37.8M|    KRML_HOST_IGNORE(c1);
  ------------------
  |  |   56|  37.8M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  215|  37.8M|    uint64_t c2 = (uint64_t)0U - c00;
  216|  37.8M|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  37.8M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  37.8M|    do {                               \
  |  |  |  |  289|  37.8M|        uint32_t i = z;                \
  |  |  |  |  290|  37.8M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  37.8M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  217|  37.8M|                    (uint32_t)0U,
  218|  37.8M|                    (uint32_t)4U,
  219|  37.8M|                    (uint32_t)1U,
  220|  37.8M|                    uint64_t *os = res;
  221|  37.8M|                    uint64_t x1 = (c2 & tmp[i]) | (~c2 & res[i]);
  222|  37.8M|                    os[i] = x1;);
  223|  37.8M|}
Hacl_P256.c:precomp_get_consttime:
 1020|  1.30M|{
 1021|  1.30M|    memcpy(tmp, (uint64_t *)table, (uint32_t)12U * sizeof(uint64_t));
 1022|  1.30M|    KRML_MAYBE_FOR15(i0,
  ------------------
  |  |  396|  1.30M|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|  1.30M|    do {                               \
  |  |  |  |  289|  1.30M|        uint32_t i = z;                \
  |  |  |  |  290|  1.30M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  1.30M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1023|  1.30M|                     (uint32_t)0U,
 1024|  1.30M|                     (uint32_t)15U,
 1025|  1.30M|                     (uint32_t)1U,
 1026|  1.30M|                     uint64_t c = FStar_UInt64_eq_mask(bits_l, (uint64_t)(i0 + (uint32_t)1U));
 1027|  1.30M|                     const uint64_t *res_j = table + (i0 + (uint32_t)1U) * (uint32_t)12U;
 1028|  1.30M|                     KRML_MAYBE_FOR12(i,
 1029|  1.30M|                                      (uint32_t)0U,
 1030|  1.30M|                                      (uint32_t)12U,
 1031|  1.30M|                                      (uint32_t)1U,
 1032|  1.30M|                                      uint64_t *os = tmp;
 1033|  1.30M|                                      uint64_t x = (c & res_j[i]) | (~c & tmp[i]);
 1034|  1.30M|                                      os[i] = x;););
 1035|  1.30M|}
Hacl_P256.c:point_add:
  898|  1.89M|{
  899|  1.89M|    uint64_t tmp[36U] = { 0U };
  900|  1.89M|    uint64_t *t0 = tmp;
  901|  1.89M|    uint64_t *t1 = tmp + (uint32_t)24U;
  902|  1.89M|    uint64_t *x3 = t1;
  903|  1.89M|    uint64_t *y3 = t1 + (uint32_t)4U;
  904|  1.89M|    uint64_t *z3 = t1 + (uint32_t)8U;
  905|  1.89M|    uint64_t *t01 = t0;
  906|  1.89M|    uint64_t *t11 = t0 + (uint32_t)4U;
  907|  1.89M|    uint64_t *t2 = t0 + (uint32_t)8U;
  908|  1.89M|    uint64_t *t3 = t0 + (uint32_t)12U;
  909|  1.89M|    uint64_t *t4 = t0 + (uint32_t)16U;
  910|  1.89M|    uint64_t *t5 = t0 + (uint32_t)20U;
  911|  1.89M|    uint64_t *x1 = p;
  912|  1.89M|    uint64_t *y1 = p + (uint32_t)4U;
  913|  1.89M|    uint64_t *z10 = p + (uint32_t)8U;
  914|  1.89M|    uint64_t *x20 = q;
  915|  1.89M|    uint64_t *y20 = q + (uint32_t)4U;
  916|  1.89M|    uint64_t *z20 = q + (uint32_t)8U;
  917|  1.89M|    fmul0(t01, x1, x20);
  918|  1.89M|    fmul0(t11, y1, y20);
  919|  1.89M|    fmul0(t2, z10, z20);
  920|  1.89M|    fadd0(t3, x1, y1);
  921|  1.89M|    fadd0(t4, x20, y20);
  922|  1.89M|    fmul0(t3, t3, t4);
  923|  1.89M|    fadd0(t4, t01, t11);
  924|  1.89M|    uint64_t *y10 = p + (uint32_t)4U;
  925|  1.89M|    uint64_t *z11 = p + (uint32_t)8U;
  926|  1.89M|    uint64_t *y2 = q + (uint32_t)4U;
  927|  1.89M|    uint64_t *z21 = q + (uint32_t)8U;
  928|  1.89M|    fsub0(t3, t3, t4);
  929|  1.89M|    fadd0(t4, y10, z11);
  930|  1.89M|    fadd0(t5, y2, z21);
  931|  1.89M|    fmul0(t4, t4, t5);
  932|  1.89M|    fadd0(t5, t11, t2);
  933|  1.89M|    fsub0(t4, t4, t5);
  934|  1.89M|    uint64_t *x10 = p;
  935|  1.89M|    uint64_t *z1 = p + (uint32_t)8U;
  936|  1.89M|    uint64_t *x2 = q;
  937|  1.89M|    uint64_t *z2 = q + (uint32_t)8U;
  938|  1.89M|    fadd0(x3, x10, z1);
  939|  1.89M|    fadd0(y3, x2, z2);
  940|  1.89M|    fmul0(x3, x3, y3);
  941|  1.89M|    fadd0(y3, t01, t2);
  942|  1.89M|    fsub0(y3, x3, y3);
  943|  1.89M|    fmul_by_b_coeff(z3, t2);
  944|  1.89M|    fsub0(x3, y3, z3);
  945|  1.89M|    fadd0(z3, x3, x3);
  946|  1.89M|    fadd0(x3, x3, z3);
  947|  1.89M|    fsub0(z3, t11, x3);
  948|  1.89M|    fadd0(x3, t11, x3);
  949|  1.89M|    fmul_by_b_coeff(y3, y3);
  950|  1.89M|    fadd0(t11, t2, t2);
  951|  1.89M|    fadd0(t2, t11, t2);
  952|  1.89M|    fsub0(y3, y3, t2);
  953|  1.89M|    fsub0(y3, y3, t01);
  954|  1.89M|    fadd0(t11, y3, y3);
  955|  1.89M|    fadd0(y3, t11, y3);
  956|  1.89M|    fadd0(t11, t01, t01);
  957|  1.89M|    fadd0(t01, t11, t01);
  958|  1.89M|    fsub0(t01, t01, t2);
  959|  1.89M|    fmul0(t11, t4, y3);
  960|  1.89M|    fmul0(t2, t01, y3);
  961|  1.89M|    fmul0(y3, x3, z3);
  962|  1.89M|    fadd0(y3, y3, t2);
  963|  1.89M|    fmul0(x3, t3, x3);
  964|  1.89M|    fsub0(x3, x3, t11);
  965|  1.89M|    fmul0(z3, t4, z3);
  966|  1.89M|    fmul0(t11, t3, t01);
  967|  1.89M|    fadd0(z3, z3, t11);
  968|  1.89M|    memcpy(res, t1, (uint32_t)12U * sizeof(uint64_t));
  969|  1.89M|}
Hacl_P256.c:point_store:
  763|  16.9k|{
  764|  16.9k|    uint64_t aff_p[8U] = { 0U };
  765|  16.9k|    to_aff_point(aff_p, p);
  766|  16.9k|    aff_point_store(res, aff_p);
  767|  16.9k|}
Hacl_P256.c:to_aff_point:
  692|  16.9k|{
  693|  16.9k|    uint64_t zinv[4U] = { 0U };
  694|  16.9k|    uint64_t *px = p;
  695|  16.9k|    uint64_t *py = p + (uint32_t)4U;
  696|  16.9k|    uint64_t *pz = p + (uint32_t)8U;
  697|  16.9k|    uint64_t *x = res;
  698|  16.9k|    uint64_t *y = res + (uint32_t)4U;
  699|  16.9k|    finv(zinv, pz);
  700|  16.9k|    fmul0(x, px, zinv);
  701|  16.9k|    fmul0(y, py, zinv);
  702|  16.9k|    from_mont(x, x);
  703|  16.9k|    from_mont(y, y);
  704|  16.9k|}
Hacl_P256.c:finv:
  570|  28.6k|{
  571|  28.6k|    uint64_t tmp[16U] = { 0U };
  572|  28.6k|    uint64_t *x30 = tmp;
  573|  28.6k|    uint64_t *x2 = tmp + (uint32_t)4U;
  574|  28.6k|    uint64_t *tmp1 = tmp + (uint32_t)8U;
  575|  28.6k|    uint64_t *tmp2 = tmp + (uint32_t)12U;
  576|  28.6k|    memcpy(x2, a, (uint32_t)4U * sizeof(uint64_t));
  577|  28.6k|    {
  578|  28.6k|        fsqr0(x2, x2);
  579|  28.6k|    }
  580|  28.6k|    fmul0(x2, x2, a);
  581|  28.6k|    memcpy(x30, x2, (uint32_t)4U * sizeof(uint64_t));
  582|  28.6k|    {
  583|  28.6k|        fsqr0(x30, x30);
  584|  28.6k|    }
  585|  28.6k|    fmul0(x30, x30, a);
  586|  28.6k|    memcpy(tmp1, x30, (uint32_t)4U * sizeof(uint64_t));
  587|  28.6k|    KRML_MAYBE_FOR3(i, (uint32_t)0U, (uint32_t)3U, (uint32_t)1U, fsqr0(tmp1, tmp1););
  ------------------
  |  |  324|  28.6k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.6k|    do {                               \
  |  |  |  |  289|  28.6k|        uint32_t i = z;                \
  |  |  |  |  290|  28.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  588|  28.6k|    fmul0(tmp1, tmp1, x30);
  589|  28.6k|    memcpy(tmp2, tmp1, (uint32_t)4U * sizeof(uint64_t));
  590|  28.6k|    KRML_MAYBE_FOR6(i, (uint32_t)0U, (uint32_t)6U, (uint32_t)1U, fsqr0(tmp2, tmp2););
  ------------------
  |  |  342|  28.6k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.6k|    do {                               \
  |  |  |  |  289|  28.6k|        uint32_t i = z;                \
  |  |  |  |  290|  28.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  591|  28.6k|    fmul0(tmp2, tmp2, tmp1);
  592|  28.6k|    memcpy(tmp1, tmp2, (uint32_t)4U * sizeof(uint64_t));
  593|  28.6k|    KRML_MAYBE_FOR3(i, (uint32_t)0U, (uint32_t)3U, (uint32_t)1U, fsqr0(tmp1, tmp1););
  ------------------
  |  |  324|  28.6k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.6k|    do {                               \
  |  |  |  |  289|  28.6k|        uint32_t i = z;                \
  |  |  |  |  290|  28.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  594|  28.6k|    fmul0(tmp1, tmp1, x30);
  595|  28.6k|    memcpy(x30, tmp1, (uint32_t)4U * sizeof(uint64_t));
  596|  28.6k|    KRML_MAYBE_FOR15(i, (uint32_t)0U, (uint32_t)15U, (uint32_t)1U, fsqr0(x30, x30););
  ------------------
  |  |  396|  28.6k|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.6k|    do {                               \
  |  |  |  |  289|  28.6k|        uint32_t i = z;                \
  |  |  |  |  290|  28.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  597|  28.6k|    fmul0(x30, x30, tmp1);
  598|  28.6k|    memcpy(tmp1, x30, (uint32_t)4U * sizeof(uint64_t));
  599|  28.6k|    KRML_MAYBE_FOR2(i, (uint32_t)0U, (uint32_t)2U, (uint32_t)1U, fsqr0(tmp1, tmp1););
  ------------------
  |  |  318|  28.6k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.6k|    do {                               \
  |  |  |  |  289|  28.6k|        uint32_t i = z;                \
  |  |  |  |  290|  28.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  600|  28.6k|    fmul0(tmp1, tmp1, x2);
  601|  28.6k|    memcpy(x2, tmp1, (uint32_t)4U * sizeof(uint64_t));
  602|   946k|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)32U; i++) {
  ------------------
  |  Branch (602:37): [True: 917k, False: 28.6k]
  ------------------
  603|   917k|        fsqr0(x2, x2);
  604|   917k|    }
  605|  28.6k|    fmul0(x2, x2, a);
  606|  3.69M|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)128U; i++) {
  ------------------
  |  Branch (606:37): [True: 3.66M, False: 28.6k]
  ------------------
  607|  3.66M|        fsqr0(x2, x2);
  608|  3.66M|    }
  609|  28.6k|    fmul0(x2, x2, tmp1);
  610|   946k|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)32U; i++) {
  ------------------
  |  Branch (610:37): [True: 917k, False: 28.6k]
  ------------------
  611|   917k|        fsqr0(x2, x2);
  612|   917k|    }
  613|  28.6k|    fmul0(x2, x2, tmp1);
  614|   888k|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)30U; i++) {
  ------------------
  |  Branch (614:37): [True: 860k, False: 28.6k]
  ------------------
  615|   860k|        fsqr0(x2, x2);
  616|   860k|    }
  617|  28.6k|    fmul0(x2, x2, x30);
  618|  28.6k|    KRML_MAYBE_FOR2(i, (uint32_t)0U, (uint32_t)2U, (uint32_t)1U, fsqr0(x2, x2););
  ------------------
  |  |  318|  28.6k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.6k|    do {                               \
  |  |  |  |  289|  28.6k|        uint32_t i = z;                \
  |  |  |  |  290|  28.6k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.6k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  619|  28.6k|    fmul0(tmp1, x2, a);
  620|  28.6k|    memcpy(res, tmp1, (uint32_t)4U * sizeof(uint64_t));
  621|  28.6k|}
Hacl_P256.c:from_mont:
  539|  45.6k|{
  540|  45.6k|    uint64_t tmp[8U] = { 0U };
  541|  45.6k|    memcpy(tmp, a, (uint32_t)4U * sizeof(uint64_t));
  542|  45.6k|    mont_reduction(res, tmp);
  543|  45.6k|}
Hacl_P256.c:aff_point_store:
  755|  16.9k|{
  756|  16.9k|    uint64_t *px = p;
  757|  16.9k|    uint64_t *py = p + (uint32_t)4U;
  758|  16.9k|    bn2_to_bytes_be4(res, px, py);
  759|  16.9k|}
Hacl_P256.c:bn2_to_bytes_be4:
  329|  28.6k|{
  330|  28.6k|    bn_to_bytes_be4(res, x);
  331|  28.6k|    bn_to_bytes_be4(res + (uint32_t)32U, y);
  332|  28.6k|}
Hacl_P256.c:load_point_vartime:
  792|  25.2k|{
  793|  25.2k|    uint64_t p_aff[8U] = { 0U };
  794|  25.2k|    bool res = aff_point_load_vartime(p_aff, b);
  795|  25.2k|    if (res) {
  ------------------
  |  Branch (795:9): [True: 25.1k, False: 78]
  ------------------
  796|  25.1k|        to_proj_point(p, p_aff);
  797|  25.1k|    }
  798|  25.2k|    return res;
  799|  25.2k|}
Hacl_P256.c:aff_point_load_vartime:
  771|  25.2k|{
  772|  25.2k|    uint8_t *p_x = b;
  773|  25.2k|    uint8_t *p_y = b + (uint32_t)32U;
  774|  25.2k|    uint64_t *bn_p_x = p;
  775|  25.2k|    uint64_t *bn_p_y = p + (uint32_t)4U;
  776|  25.2k|    bn_from_bytes_be4(bn_p_x, p_x);
  777|  25.2k|    bn_from_bytes_be4(bn_p_y, p_y);
  778|  25.2k|    uint64_t *px = p;
  779|  25.2k|    uint64_t *py = p + (uint32_t)4U;
  780|  25.2k|    uint64_t lessX = bn_is_lt_prime_mask4(px);
  781|  25.2k|    uint64_t lessY = bn_is_lt_prime_mask4(py);
  782|  25.2k|    uint64_t res = lessX & lessY;
  783|  25.2k|    bool is_xy_valid = res == (uint64_t)0xFFFFFFFFFFFFFFFFU;
  784|  25.2k|    if (!is_xy_valid) {
  ------------------
  |  Branch (784:9): [True: 5, False: 25.2k]
  ------------------
  785|      5|        return false;
  786|      5|    }
  787|  25.2k|    return is_on_curve_vartime(p);
  788|  25.2k|}
Hacl_P256.c:bn_is_lt_prime_mask4:
  417|  50.4k|{
  418|  50.4k|    uint64_t tmp[4U] = { 0U };
  419|  50.4k|    make_prime(tmp);
  420|  50.4k|    uint64_t c = bn_sub4(tmp, f, tmp);
  421|  50.4k|    return (uint64_t)0U - c;
  422|  50.4k|}
Hacl_P256.c:is_on_curve_vartime:
  732|  25.2k|{
  733|  25.2k|    uint64_t rp[4U] = { 0U };
  734|  25.2k|    uint64_t tx[4U] = { 0U };
  735|  25.2k|    uint64_t ty[4U] = { 0U };
  736|  25.2k|    uint64_t *px = p;
  737|  25.2k|    uint64_t *py = p + (uint32_t)4U;
  738|  25.2k|    to_mont(tx, px);
  739|  25.2k|    to_mont(ty, py);
  740|  25.2k|    uint64_t tmp[4U] = { 0U };
  741|  25.2k|    fcube(rp, tx);
  742|  25.2k|    make_a_coeff(tmp);
  743|  25.2k|    fmul0(tmp, tmp, tx);
  744|  25.2k|    fadd0(rp, tmp, rp);
  745|  25.2k|    make_b_coeff(tmp);
  746|  25.2k|    fadd0(rp, tmp, rp);
  747|  25.2k|    fsqr0(ty, ty);
  748|  25.2k|    uint64_t r = feq_mask(ty, rp);
  749|  25.2k|    bool r0 = r == (uint64_t)0xFFFFFFFFFFFFFFFFU;
  750|  25.2k|    return r0;
  751|  25.2k|}
Hacl_P256.c:to_mont:
  547|   100k|{
  548|   100k|    uint64_t r2modn[4U] = { 0U };
  549|   100k|    make_fmont_R2(r2modn);
  550|   100k|    fmul0(res, a, r2modn);
  551|   100k|}
Hacl_P256.c:make_fmont_R2:
  390|   100k|{
  391|   100k|    n[0U] = (uint64_t)0x3U;
  392|   100k|    n[1U] = (uint64_t)0xfffffffbffffffffU;
  393|   100k|    n[2U] = (uint64_t)0xfffffffffffffffeU;
  394|   100k|    n[3U] = (uint64_t)0x4fffffffdU;
  395|   100k|}
Hacl_P256.c:fcube:
  563|  25.2k|{
  564|  25.2k|    fsqr0(res, x);
  565|  25.2k|    fmul0(res, res, x);
  566|  25.2k|}
Hacl_P256.c:make_a_coeff:
  354|  25.2k|{
  355|  25.2k|    a[0U] = (uint64_t)0xfffffffffffffffcU;
  356|  25.2k|    a[1U] = (uint64_t)0x3ffffffffU;
  357|  25.2k|    a[2U] = (uint64_t)0x0U;
  358|  25.2k|    a[3U] = (uint64_t)0xfffffffc00000004U;
  359|  25.2k|}
Hacl_P256.c:feq_mask:
  426|  25.2k|{
  427|  25.2k|    uint64_t r = bn_is_eq_mask4(a, b);
  428|  25.2k|    return r;
  429|  25.2k|}
Hacl_P256.c:bn_is_eq_mask4:
   57|  25.2k|{
   58|  25.2k|    uint64_t mask = (uint64_t)0xFFFFFFFFFFFFFFFFU;
   59|  25.2k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  25.2k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  25.2k|    do {                               \
  |  |  |  |  289|  25.2k|        uint32_t i = z;                \
  |  |  |  |  290|  25.2k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  25.2k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   60|  25.2k|                    (uint32_t)0U,
   61|  25.2k|                    (uint32_t)4U,
   62|  25.2k|                    (uint32_t)1U,
   63|  25.2k|                    uint64_t uu____0 = FStar_UInt64_eq_mask(a[i], b[i]);
   64|  25.2k|                    mask = uu____0 & mask;);
   65|  25.2k|    uint64_t mask1 = mask;
   66|  25.2k|    return mask1;
   67|  25.2k|}
Hacl_P256.c:to_proj_point:
  719|  25.1k|{
  720|  25.1k|    uint64_t *px = p;
  721|  25.1k|    uint64_t *py = p + (uint32_t)4U;
  722|  25.1k|    uint64_t *rx = res;
  723|  25.1k|    uint64_t *ry = res + (uint32_t)4U;
  724|  25.1k|    uint64_t *rz = res + (uint32_t)8U;
  725|  25.1k|    to_mont(rx, px);
  726|  25.1k|    to_mont(ry, py);
  727|  25.1k|    make_fone(rz);
  728|  25.1k|}
Hacl_P256.c:point_mul:
  973|  8.21k|{
  974|  8.21k|    uint64_t table[192U] = { 0U };
  975|  8.21k|    uint64_t tmp[12U] = { 0U };
  976|  8.21k|    uint64_t *t0 = table;
  977|  8.21k|    uint64_t *t1 = table + (uint32_t)12U;
  978|  8.21k|    make_point_at_inf(t0);
  979|  8.21k|    memcpy(t1, p, (uint32_t)12U * sizeof(uint64_t));
  980|  8.21k|    KRML_MAYBE_FOR7(i,
  ------------------
  |  |  348|  8.21k|#define KRML_MAYBE_FOR7(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 7, k, x)
  |  |  ------------------
  |  |  |  |  288|  8.21k|    do {                               \
  |  |  |  |  289|  8.21k|        uint32_t i = z;                \
  |  |  |  |  290|  8.21k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  8.21k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  981|  8.21k|                    (uint32_t)0U,
  982|  8.21k|                    (uint32_t)7U,
  983|  8.21k|                    (uint32_t)1U,
  984|  8.21k|                    uint64_t *t11 = table + (i + (uint32_t)1U) * (uint32_t)12U;
  985|  8.21k|                    point_double(tmp, t11);
  986|  8.21k|                    memcpy(table + ((uint32_t)2U * i + (uint32_t)2U) * (uint32_t)12U,
  987|  8.21k|                           tmp,
  988|  8.21k|                           (uint32_t)12U * sizeof(uint64_t));
  989|  8.21k|                    uint64_t *t2 = table + ((uint32_t)2U * i + (uint32_t)2U) * (uint32_t)12U;
  990|  8.21k|                    point_add(tmp, p, t2);
  991|  8.21k|                    memcpy(table + ((uint32_t)2U * i + (uint32_t)3U) * (uint32_t)12U,
  992|  8.21k|                           tmp,
  993|  8.21k|                           (uint32_t)12U * sizeof(uint64_t)););
  994|  8.21k|    make_point_at_inf(res);
  995|  8.21k|    uint64_t tmp0[12U] = { 0U };
  996|   533k|    for (uint32_t i0 = (uint32_t)0U; i0 < (uint32_t)64U; i0++) {
  ------------------
  |  Branch (996:38): [True: 525k, False: 8.21k]
  ------------------
  997|   525k|        KRML_MAYBE_FOR4(i, (uint32_t)0U, (uint32_t)4U, (uint32_t)1U, point_double(res, res););
  ------------------
  |  |  330|   525k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|   525k|    do {                               \
  |  |  |  |  289|   525k|        uint32_t i = z;                \
  |  |  |  |  290|   525k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   525k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  998|   525k|        uint32_t k = (uint32_t)256U - (uint32_t)4U * i0 - (uint32_t)4U;
  999|   525k|        uint64_t bits_l = Hacl_Bignum_Lib_bn_get_bits_u64((uint32_t)4U, scalar, k, (uint32_t)4U);
 1000|   525k|        memcpy(tmp0, (uint64_t *)table, (uint32_t)12U * sizeof(uint64_t));
 1001|   525k|        KRML_MAYBE_FOR15(i1,
  ------------------
  |  |  396|   525k|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|   525k|    do {                               \
  |  |  |  |  289|   525k|        uint32_t i = z;                \
  |  |  |  |  290|   525k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   525k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1002|   525k|                         (uint32_t)0U,
 1003|   525k|                         (uint32_t)15U,
 1004|   525k|                         (uint32_t)1U,
 1005|   525k|                         uint64_t c = FStar_UInt64_eq_mask(bits_l, (uint64_t)(i1 + (uint32_t)1U));
 1006|   525k|                         const uint64_t *res_j = table + (i1 + (uint32_t)1U) * (uint32_t)12U;
 1007|   525k|                         KRML_MAYBE_FOR12(i,
 1008|   525k|                                          (uint32_t)0U,
 1009|   525k|                                          (uint32_t)12U,
 1010|   525k|                                          (uint32_t)1U,
 1011|   525k|                                          uint64_t *os = tmp0;
 1012|   525k|                                          uint64_t x = (c & res_j[i]) | (~c & tmp0[i]);
 1013|   525k|                                          os[i] = x;););
 1014|   525k|        point_add(res, res, tmp0);
 1015|   525k|    }
 1016|  8.21k|}
Hacl_P256.c:qmod_short:
 1178|  23.4k|{
 1179|  23.4k|    uint64_t tmp[4U] = { 0U };
 1180|  23.4k|    make_order(tmp);
 1181|  23.4k|    uint64_t c = bn_sub4(tmp, x, tmp);
 1182|  23.4k|    bn_cmovznz4(res, c, tmp, x);
 1183|  23.4k|}
Hacl_P256.c:bn_cmovznz4:
   78|  23.4k|{
   79|  23.4k|    uint64_t mask = ~FStar_UInt64_eq_mask(cin, (uint64_t)0U);
   80|  23.4k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  23.4k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  23.4k|    do {                               \
  |  |  |  |  289|  23.4k|        uint32_t i = z;                \
  |  |  |  |  290|  23.4k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  23.4k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   81|  23.4k|                    (uint32_t)0U,
   82|  23.4k|                    (uint32_t)4U,
   83|  23.4k|                    (uint32_t)1U,
   84|  23.4k|                    uint64_t *os = res;
   85|  23.4k|                    uint64_t uu____0 = x[i];
   86|  23.4k|                    uint64_t x1 = uu____0 ^ (mask & (y[i] ^ uu____0));
   87|  23.4k|                    os[i] = x1;);
   88|  23.4k|}
Hacl_P256.c:ecdsa_sign_msg_as_qelem:
 1504|  11.7k|{
 1505|  11.7k|    uint64_t rsdk_q[16U] = { 0U };
 1506|  11.7k|    uint64_t *r_q = rsdk_q;
 1507|  11.7k|    uint64_t *s_q = rsdk_q + (uint32_t)4U;
 1508|  11.7k|    uint64_t *d_a = rsdk_q + (uint32_t)8U;
 1509|  11.7k|    uint64_t *k_q = rsdk_q + (uint32_t)12U;
 1510|  11.7k|    bn_from_bytes_be4(d_a, private_key);
 1511|  11.7k|    uint64_t is_b_valid0 = bn_is_lt_order_and_gt_zero_mask4(d_a);
 1512|  11.7k|    uint64_t oneq0[4U] = { 0U };
 1513|  11.7k|    oneq0[0U] = (uint64_t)1U;
 1514|  11.7k|    oneq0[1U] = (uint64_t)0U;
 1515|  11.7k|    oneq0[2U] = (uint64_t)0U;
 1516|  11.7k|    oneq0[3U] = (uint64_t)0U;
 1517|  11.7k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  11.7k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1518|  11.7k|                    (uint32_t)0U,
 1519|  11.7k|                    (uint32_t)4U,
 1520|  11.7k|                    (uint32_t)1U,
 1521|  11.7k|                    uint64_t *os = d_a;
 1522|  11.7k|                    uint64_t uu____0 = oneq0[i];
 1523|  11.7k|                    uint64_t x = uu____0 ^ (is_b_valid0 & (d_a[i] ^ uu____0));
 1524|  11.7k|                    os[i] = x;);
 1525|  11.7k|    uint64_t is_sk_valid = is_b_valid0;
 1526|  11.7k|    bn_from_bytes_be4(k_q, nonce);
 1527|  11.7k|    uint64_t is_b_valid = bn_is_lt_order_and_gt_zero_mask4(k_q);
 1528|  11.7k|    uint64_t oneq[4U] = { 0U };
 1529|  11.7k|    oneq[0U] = (uint64_t)1U;
 1530|  11.7k|    oneq[1U] = (uint64_t)0U;
 1531|  11.7k|    oneq[2U] = (uint64_t)0U;
 1532|  11.7k|    oneq[3U] = (uint64_t)0U;
 1533|  11.7k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  11.7k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1534|  11.7k|                    (uint32_t)0U,
 1535|  11.7k|                    (uint32_t)4U,
 1536|  11.7k|                    (uint32_t)1U,
 1537|  11.7k|                    uint64_t *os = k_q;
 1538|  11.7k|                    uint64_t uu____1 = oneq[i];
 1539|  11.7k|                    uint64_t x = uu____1 ^ (is_b_valid & (k_q[i] ^ uu____1));
 1540|  11.7k|                    os[i] = x;);
 1541|  11.7k|    uint64_t is_nonce_valid = is_b_valid;
 1542|  11.7k|    uint64_t are_sk_nonce_valid = is_sk_valid & is_nonce_valid;
 1543|  11.7k|    uint64_t p[12U] = { 0U };
 1544|  11.7k|    point_mul_g(p, k_q);
 1545|  11.7k|    to_aff_point_x(r_q, p);
 1546|  11.7k|    qmod_short(r_q, r_q);
 1547|  11.7k|    uint64_t kinv[4U] = { 0U };
 1548|  11.7k|    qinv(kinv, k_q);
 1549|  11.7k|    qmul(s_q, r_q, d_a);
 1550|  11.7k|    from_qmont(m_q, m_q);
 1551|  11.7k|    qadd(s_q, m_q, s_q);
 1552|  11.7k|    qmul(s_q, kinv, s_q);
 1553|  11.7k|    bn2_to_bytes_be4(signature, r_q, s_q);
 1554|  11.7k|    uint64_t is_r_zero = bn_is_zero_mask4(r_q);
 1555|  11.7k|    uint64_t is_s_zero = bn_is_zero_mask4(s_q);
 1556|  11.7k|    uint64_t m = are_sk_nonce_valid & (~is_r_zero & ~is_s_zero);
 1557|  11.7k|    bool res = m == (uint64_t)0xFFFFFFFFFFFFFFFFU;
 1558|  11.7k|    return res;
 1559|  11.7k|}
Hacl_P256.c:to_aff_point_x:
  708|  11.7k|{
  709|  11.7k|    uint64_t zinv[4U] = { 0U };
  710|  11.7k|    uint64_t *px = p;
  711|  11.7k|    uint64_t *pz = p + (uint32_t)8U;
  712|  11.7k|    finv(zinv, pz);
  713|  11.7k|    fmul0(res, px, zinv);
  714|  11.7k|    from_mont(res, res);
  715|  11.7k|}
Hacl_P256.c:qinv:
 1345|  11.7k|{
 1346|  11.7k|    uint64_t tmp[28U] = { 0U };
 1347|  11.7k|    uint64_t *x6 = tmp;
 1348|  11.7k|    uint64_t *x_11 = tmp + (uint32_t)4U;
 1349|  11.7k|    uint64_t *x_101 = tmp + (uint32_t)8U;
 1350|  11.7k|    uint64_t *x_111 = tmp + (uint32_t)12U;
 1351|  11.7k|    uint64_t *x_1111 = tmp + (uint32_t)16U;
 1352|  11.7k|    uint64_t *x_10101 = tmp + (uint32_t)20U;
 1353|  11.7k|    uint64_t *x_101111 = tmp + (uint32_t)24U;
 1354|  11.7k|    memcpy(x6, r, (uint32_t)4U * sizeof(uint64_t));
 1355|  11.7k|    {
 1356|  11.7k|        qsqr(x6, x6);
 1357|  11.7k|    }
 1358|  11.7k|    qmul(x_11, x6, r);
 1359|  11.7k|    qmul(x_101, x6, x_11);
 1360|  11.7k|    qmul(x_111, x6, x_101);
 1361|  11.7k|    memcpy(x6, x_101, (uint32_t)4U * sizeof(uint64_t));
 1362|  11.7k|    {
 1363|  11.7k|        qsqr(x6, x6);
 1364|  11.7k|    }
 1365|  11.7k|    qmul(x_1111, x_101, x6);
 1366|  11.7k|    {
 1367|  11.7k|        qsqr(x6, x6);
 1368|  11.7k|    }
 1369|  11.7k|    qmul(x_10101, x6, r);
 1370|  11.7k|    memcpy(x6, x_10101, (uint32_t)4U * sizeof(uint64_t));
 1371|  11.7k|    {
 1372|  11.7k|        qsqr(x6, x6);
 1373|  11.7k|    }
 1374|  11.7k|    qmul(x_101111, x_101, x6);
 1375|  11.7k|    qmul(x6, x_10101, x6);
 1376|  11.7k|    uint64_t tmp1[4U] = { 0U };
 1377|  11.7k|    KRML_MAYBE_FOR2(i, (uint32_t)0U, (uint32_t)2U, (uint32_t)1U, qsqr(x6, x6););
  ------------------
  |  |  318|  11.7k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1378|  11.7k|    qmul(x6, x6, x_11);
 1379|  11.7k|    memcpy(tmp1, x6, (uint32_t)4U * sizeof(uint64_t));
 1380|  11.7k|    KRML_MAYBE_FOR8(i, (uint32_t)0U, (uint32_t)8U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  354|  11.7k|#define KRML_MAYBE_FOR8(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 8, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1381|  11.7k|    qmul(tmp1, tmp1, x6);
 1382|  11.7k|    memcpy(x6, tmp1, (uint32_t)4U * sizeof(uint64_t));
 1383|  11.7k|    KRML_MAYBE_FOR16(i, (uint32_t)0U, (uint32_t)16U, (uint32_t)1U, qsqr(x6, x6););
  ------------------
  |  |  402|  11.7k|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1384|  11.7k|    qmul(x6, x6, tmp1);
 1385|  11.7k|    memcpy(tmp1, x6, (uint32_t)4U * sizeof(uint64_t));
 1386|   761k|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)64U; i++) {
  ------------------
  |  Branch (1386:37): [True: 750k, False: 11.7k]
  ------------------
 1387|   750k|        qsqr(tmp1, tmp1);
 1388|   750k|    }
 1389|  11.7k|    qmul(tmp1, tmp1, x6);
 1390|   386k|    for (uint32_t i = (uint32_t)0U; i < (uint32_t)32U; i++) {
  ------------------
  |  Branch (1390:37): [True: 375k, False: 11.7k]
  ------------------
 1391|   375k|        qsqr(tmp1, tmp1);
 1392|   375k|    }
 1393|  11.7k|    qmul(tmp1, tmp1, x6);
 1394|  11.7k|    KRML_MAYBE_FOR6(i, (uint32_t)0U, (uint32_t)6U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  342|  11.7k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1395|  11.7k|    qmul(tmp1, tmp1, x_101111);
 1396|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1397|  11.7k|    qmul(tmp1, tmp1, x_111);
 1398|  11.7k|    KRML_MAYBE_FOR4(i, (uint32_t)0U, (uint32_t)4U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  330|  11.7k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1399|  11.7k|    qmul(tmp1, tmp1, x_11);
 1400|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1401|  11.7k|    qmul(tmp1, tmp1, x_1111);
 1402|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1403|  11.7k|    qmul(tmp1, tmp1, x_10101);
 1404|  11.7k|    KRML_MAYBE_FOR4(i, (uint32_t)0U, (uint32_t)4U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  330|  11.7k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1405|  11.7k|    qmul(tmp1, tmp1, x_101);
 1406|  11.7k|    KRML_MAYBE_FOR3(i, (uint32_t)0U, (uint32_t)3U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  324|  11.7k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1407|  11.7k|    qmul(tmp1, tmp1, x_101);
 1408|  11.7k|    KRML_MAYBE_FOR3(i, (uint32_t)0U, (uint32_t)3U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  324|  11.7k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1409|  11.7k|    qmul(tmp1, tmp1, x_101);
 1410|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1411|  11.7k|    qmul(tmp1, tmp1, x_111);
 1412|  11.7k|    KRML_MAYBE_FOR9(i, (uint32_t)0U, (uint32_t)9U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  360|  11.7k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1413|  11.7k|    qmul(tmp1, tmp1, x_101111);
 1414|  11.7k|    KRML_MAYBE_FOR6(i, (uint32_t)0U, (uint32_t)6U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  342|  11.7k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1415|  11.7k|    qmul(tmp1, tmp1, x_1111);
 1416|  11.7k|    KRML_MAYBE_FOR2(i, (uint32_t)0U, (uint32_t)2U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  318|  11.7k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1417|  11.7k|    qmul(tmp1, tmp1, r);
 1418|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1419|  11.7k|    qmul(tmp1, tmp1, r);
 1420|  11.7k|    KRML_MAYBE_FOR6(i, (uint32_t)0U, (uint32_t)6U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  342|  11.7k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1421|  11.7k|    qmul(tmp1, tmp1, x_1111);
 1422|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1423|  11.7k|    qmul(tmp1, tmp1, x_111);
 1424|  11.7k|    KRML_MAYBE_FOR4(i, (uint32_t)0U, (uint32_t)4U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  330|  11.7k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1425|  11.7k|    qmul(tmp1, tmp1, x_111);
 1426|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1427|  11.7k|    qmul(tmp1, tmp1, x_111);
 1428|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1429|  11.7k|    qmul(tmp1, tmp1, x_101);
 1430|  11.7k|    KRML_MAYBE_FOR3(i, (uint32_t)0U, (uint32_t)3U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  324|  11.7k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1431|  11.7k|    qmul(tmp1, tmp1, x_11);
 1432|  11.7k|    KRML_MAYBE_FOR10(i, (uint32_t)0U, (uint32_t)10U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  366|  11.7k|#define KRML_MAYBE_FOR10(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 10, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1433|  11.7k|    qmul(tmp1, tmp1, x_101111);
 1434|  11.7k|    KRML_MAYBE_FOR2(i, (uint32_t)0U, (uint32_t)2U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  318|  11.7k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1435|  11.7k|    qmul(tmp1, tmp1, x_11);
 1436|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1437|  11.7k|    qmul(tmp1, tmp1, x_11);
 1438|  11.7k|    KRML_MAYBE_FOR5(i, (uint32_t)0U, (uint32_t)5U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  336|  11.7k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1439|  11.7k|    qmul(tmp1, tmp1, x_11);
 1440|  11.7k|    KRML_MAYBE_FOR3(i, (uint32_t)0U, (uint32_t)3U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  324|  11.7k|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1441|  11.7k|    qmul(tmp1, tmp1, r);
 1442|  11.7k|    KRML_MAYBE_FOR7(i, (uint32_t)0U, (uint32_t)7U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  348|  11.7k|#define KRML_MAYBE_FOR7(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 7, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1443|  11.7k|    qmul(tmp1, tmp1, x_10101);
 1444|  11.7k|    KRML_MAYBE_FOR6(i, (uint32_t)0U, (uint32_t)6U, (uint32_t)1U, qsqr(tmp1, tmp1););
  ------------------
  |  |  342|  11.7k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  11.7k|    do {                               \
  |  |  |  |  289|  11.7k|        uint32_t i = z;                \
  |  |  |  |  290|  11.7k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  11.7k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1445|  11.7k|    qmul(tmp1, tmp1, x_1111);
 1446|  11.7k|    memcpy(x6, tmp1, (uint32_t)4U * sizeof(uint64_t));
 1447|  11.7k|    memcpy(res, x6, (uint32_t)4U * sizeof(uint64_t));
 1448|  11.7k|}
Hacl_P256.c:qsqr:
 1276|  2.97M|{
 1277|  2.97M|    uint64_t tmp[8U] = { 0U };
 1278|  2.97M|    bn_sqr4(tmp, x);
 1279|  2.97M|    qmont_reduction(res, tmp);
 1280|  2.97M|}
Hacl_P256.c:qmont_reduction:
 1195|  3.45M|{
 1196|  3.45M|    uint64_t n[4U] = { 0U };
 1197|  3.45M|    make_order(n);
 1198|  3.45M|    uint64_t c0 = (uint64_t)0U;
 1199|  3.45M|    KRML_MAYBE_FOR4(
  ------------------
  |  |  330|  3.45M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  3.45M|    do {                               \
  |  |  |  |  289|  3.45M|        uint32_t i = z;                \
  |  |  |  |  290|  3.45M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  3.45M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1200|  3.45M|        i0,
 1201|  3.45M|        (uint32_t)0U,
 1202|  3.45M|        (uint32_t)4U,
 1203|  3.45M|        (uint32_t)1U,
 1204|  3.45M|        uint64_t qj = (uint64_t)0xccd1c8aaee00bc4fU * x[i0];
 1205|  3.45M|        uint64_t *res_j0 = x + i0;
 1206|  3.45M|        uint64_t c = (uint64_t)0U;
 1207|  3.45M|        {
 1208|  3.45M|            uint64_t a_i = n[(uint32_t)4U * (uint32_t)0U];
 1209|  3.45M|            uint64_t *res_i0 = res_j0 + (uint32_t)4U * (uint32_t)0U;
 1210|  3.45M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, qj, c, res_i0);
 1211|  3.45M|            uint64_t a_i0 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
 1212|  3.45M|            uint64_t *res_i1 = res_j0 + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
 1213|  3.45M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, qj, c, res_i1);
 1214|  3.45M|            uint64_t a_i1 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
 1215|  3.45M|            uint64_t *res_i2 = res_j0 + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
 1216|  3.45M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, qj, c, res_i2);
 1217|  3.45M|            uint64_t a_i2 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
 1218|  3.45M|            uint64_t *res_i = res_j0 + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
 1219|  3.45M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, qj, c, res_i);
 1220|  3.45M|        } uint64_t r = c;
 1221|  3.45M|        uint64_t c1 = r;
 1222|  3.45M|        uint64_t *resb = x + (uint32_t)4U + i0;
 1223|  3.45M|        uint64_t res_j = x[(uint32_t)4U + i0];
 1224|  3.45M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, c1, res_j, resb););
 1225|  3.45M|    memcpy(res, x + (uint32_t)4U, (uint32_t)4U * sizeof(uint64_t));
 1226|  3.45M|    uint64_t c00 = c0;
 1227|  3.45M|    uint64_t tmp[4U] = { 0U };
 1228|  3.45M|    uint64_t c = (uint64_t)0U;
 1229|  3.45M|    {
 1230|  3.45M|        uint64_t t1 = res[(uint32_t)4U * (uint32_t)0U];
 1231|  3.45M|        uint64_t t20 = n[(uint32_t)4U * (uint32_t)0U];
 1232|  3.45M|        uint64_t *res_i0 = tmp + (uint32_t)4U * (uint32_t)0U;
 1233|  3.45M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t20, res_i0);
  ------------------
  |  |   89|  3.45M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
 1234|  3.45M|        uint64_t t10 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
 1235|  3.45M|        uint64_t t21 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)1U];
 1236|  3.45M|        uint64_t *res_i1 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)1U;
 1237|  3.45M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t10, t21, res_i1);
  ------------------
  |  |   89|  3.45M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
 1238|  3.45M|        uint64_t t11 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
 1239|  3.45M|        uint64_t t22 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)2U];
 1240|  3.45M|        uint64_t *res_i2 = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)2U;
 1241|  3.45M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t11, t22, res_i2);
  ------------------
  |  |   89|  3.45M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
 1242|  3.45M|        uint64_t t12 = res[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
 1243|  3.45M|        uint64_t t2 = n[(uint32_t)4U * (uint32_t)0U + (uint32_t)3U];
 1244|  3.45M|        uint64_t *res_i = tmp + (uint32_t)4U * (uint32_t)0U + (uint32_t)3U;
 1245|  3.45M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t12, t2, res_i);
  ------------------
  |  |   89|  3.45M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
 1246|  3.45M|    }
 1247|  3.45M|    uint64_t c1 = c;
 1248|  3.45M|    uint64_t c2 = c00 - c1;
 1249|  3.45M|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  3.45M|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  3.45M|    do {                               \
  |  |  |  |  289|  3.45M|        uint32_t i = z;                \
  |  |  |  |  290|  3.45M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  3.45M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1250|  3.45M|                    (uint32_t)0U,
 1251|  3.45M|                    (uint32_t)4U,
 1252|  3.45M|                    (uint32_t)1U,
 1253|  3.45M|                    uint64_t *os = res;
 1254|  3.45M|                    uint64_t x1 = (c2 & res[i]) | (~c2 & tmp[i]);
 1255|  3.45M|                    os[i] = x1;);
 1256|  3.45M|}
Hacl_P256.c:qmul:
 1268|   468k|{
 1269|   468k|    uint64_t tmp[8U] = { 0U };
 1270|   468k|    bn_mul4(tmp, x, y);
 1271|   468k|    qmont_reduction(res, tmp);
 1272|   468k|}
Hacl_P256.c:from_qmont:
 1260|  11.7k|{
 1261|  11.7k|    uint64_t tmp[8U] = { 0U };
 1262|  11.7k|    memcpy(tmp, x, (uint32_t)4U * sizeof(uint64_t));
 1263|  11.7k|    qmont_reduction(res, tmp);
 1264|  11.7k|}
Hacl_P256.c:qadd:
 1187|  11.7k|{
 1188|  11.7k|    uint64_t n[4U] = { 0U };
 1189|  11.7k|    make_order(n);
 1190|  11.7k|    bn_add_mod4(res, n, x, y);
 1191|  11.7k|}
Hacl_P256.c:bn_to_bytes_be4:
  304|  57.3k|{
  305|  57.3k|    uint8_t tmp[32U] = { 0U };
  306|  57.3k|    KRML_HOST_IGNORE(tmp);
  ------------------
  |  |   56|  57.3k|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  307|  57.3k|    KRML_MAYBE_FOR4(i,
  ------------------
  |  |  330|  57.3k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  57.3k|    do {                               \
  |  |  |  |  289|  57.3k|        uint32_t i = z;                \
  |  |  |  |  290|  57.3k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  57.3k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  308|  57.3k|                    (uint32_t)0U,
  309|  57.3k|                    (uint32_t)4U,
  310|  57.3k|                    (uint32_t)1U,
  311|  57.3k|                    store64_be(res + i * (uint32_t)8U, f[(uint32_t)4U - i - (uint32_t)1U]););
  312|  57.3k|}

Hacl_P384_validate_public_key:
 1360|  4.05k|{
 1361|  4.05k|    uint64_t point_jac[18U] = { 0U };
 1362|  4.05k|    uint64_t p_aff[12U] = { 0U };
 1363|  4.05k|    uint8_t *p_x = public_key;
 1364|  4.05k|    uint8_t *p_y = public_key + 48U;
 1365|  4.05k|    uint64_t *bn_p_x = p_aff;
 1366|  4.05k|    uint64_t *bn_p_y = p_aff + 6U;
 1367|  4.05k|    bn_from_bytes_be(bn_p_x, p_x);
 1368|  4.05k|    bn_from_bytes_be(bn_p_y, p_y);
 1369|  4.05k|    uint64_t *px0 = p_aff;
 1370|  4.05k|    uint64_t *py0 = p_aff + 6U;
 1371|  4.05k|    uint64_t lessX = bn_is_lt_prime_mask(px0);
 1372|  4.05k|    uint64_t lessY = bn_is_lt_prime_mask(py0);
 1373|  4.05k|    uint64_t res0 = lessX & lessY;
 1374|  4.05k|    bool is_xy_valid = res0 == 0xFFFFFFFFFFFFFFFFULL;
 1375|  4.05k|    bool res;
 1376|  4.05k|    if (!is_xy_valid) {
  ------------------
  |  Branch (1376:9): [True: 5, False: 4.05k]
  ------------------
 1377|      5|        res = false;
 1378|  4.05k|    } else {
 1379|  4.05k|        uint64_t rp[6U] = { 0U };
 1380|  4.05k|        uint64_t tx[6U] = { 0U };
 1381|  4.05k|        uint64_t ty[6U] = { 0U };
 1382|  4.05k|        uint64_t *px = p_aff;
 1383|  4.05k|        uint64_t *py = p_aff + 6U;
 1384|  4.05k|        to_mont(tx, px);
 1385|  4.05k|        to_mont(ty, py);
 1386|  4.05k|        uint64_t tmp[6U] = { 0U };
 1387|  4.05k|        fsqr0(rp, tx);
 1388|  4.05k|        fmul0(rp, rp, tx);
 1389|  4.05k|        p384_make_a_coeff(tmp);
 1390|  4.05k|        fmul0(tmp, tmp, tx);
 1391|  4.05k|        fadd0(rp, tmp, rp);
 1392|  4.05k|        p384_make_b_coeff(tmp);
 1393|  4.05k|        fadd0(rp, tmp, rp);
 1394|  4.05k|        fsqr0(ty, ty);
 1395|  4.05k|        uint64_t r = bn_is_eq_mask(ty, rp);
 1396|  4.05k|        uint64_t r0 = r;
 1397|  4.05k|        bool r1 = r0 == 0xFFFFFFFFFFFFFFFFULL;
 1398|  4.05k|        res = r1;
 1399|  4.05k|    }
 1400|  4.05k|    if (res) {
  ------------------
  |  Branch (1400:9): [True: 3.99k, False: 64]
  ------------------
 1401|  3.99k|        uint64_t *px = p_aff;
 1402|  3.99k|        uint64_t *py = p_aff + 6U;
 1403|  3.99k|        uint64_t *rx = point_jac;
 1404|  3.99k|        uint64_t *ry = point_jac + 6U;
 1405|  3.99k|        uint64_t *rz = point_jac + 12U;
 1406|  3.99k|        to_mont(rx, px);
 1407|  3.99k|        to_mont(ry, py);
 1408|  3.99k|        p384_make_fone(rz);
 1409|  3.99k|    }
 1410|  4.05k|    bool res1 = res;
 1411|  4.05k|    return res1;
 1412|  4.05k|}
Hacl_P384_validate_private_key:
 1426|  2.04k|{
 1427|  2.04k|    uint64_t bn_sk[6U] = { 0U };
 1428|  2.04k|    bn_from_bytes_be(bn_sk, private_key);
 1429|  2.04k|    uint64_t tmp[6U] = { 0U };
 1430|  2.04k|    p384_make_order(tmp);
 1431|  2.04k|    uint64_t c = bn_sub(tmp, bn_sk, tmp);
 1432|  2.04k|    uint64_t is_lt_order = FStar_UInt64_gte_mask(c, 0ULL) & ~FStar_UInt64_eq_mask(c, 0ULL);
 1433|  2.04k|    uint64_t bn_zero[6U] = { 0U };
 1434|  2.04k|    uint64_t res = bn_is_eq_mask(bn_sk, bn_zero);
 1435|  2.04k|    uint64_t is_eq_zero = res;
 1436|  2.04k|    uint64_t res0 = is_lt_order & ~is_eq_zero;
 1437|  2.04k|    return res0 == 0xFFFFFFFFFFFFFFFFULL;
 1438|  2.04k|}
Hacl_P384_dh_initiator:
 1594|  2.04k|{
 1595|  2.04k|    uint64_t tmp[24U] = { 0U };
 1596|  2.04k|    uint64_t *sk = tmp;
 1597|  2.04k|    uint64_t *pk = tmp + 6U;
 1598|  2.04k|    uint64_t is_sk_valid = load_qelem_conditional(sk, private_key);
 1599|  2.04k|    point_mul_g(pk, sk);
 1600|  2.04k|    uint64_t aff_p[12U] = { 0U };
 1601|  2.04k|    uint64_t zinv[6U] = { 0U };
 1602|  2.04k|    uint64_t *px = pk;
 1603|  2.04k|    uint64_t *py0 = pk + 6U;
 1604|  2.04k|    uint64_t *pz = pk + 12U;
 1605|  2.04k|    uint64_t *x = aff_p;
 1606|  2.04k|    uint64_t *y = aff_p + 6U;
 1607|  2.04k|    p384_finv(zinv, pz);
 1608|  2.04k|    fmul0(x, px, zinv);
 1609|  2.04k|    fmul0(y, py0, zinv);
 1610|  2.04k|    from_mont(x, x);
 1611|  2.04k|    from_mont(y, y);
 1612|  2.04k|    uint64_t *px0 = aff_p;
 1613|  2.04k|    uint64_t *py = aff_p + 6U;
 1614|  2.04k|    bn_to_bytes_be(public_key, px0);
 1615|  2.04k|    bn_to_bytes_be(public_key + 48U, py);
 1616|  2.04k|    return is_sk_valid == 0xFFFFFFFFFFFFFFFFULL;
 1617|  2.04k|}
Hacl_P384_dh_responder:
 1633|  1.94k|{
 1634|  1.94k|    uint64_t tmp[192U] = { 0U };
 1635|  1.94k|    uint64_t *sk = tmp;
 1636|  1.94k|    uint64_t *pk = tmp + 6U;
 1637|  1.94k|    uint64_t p_aff[12U] = { 0U };
 1638|  1.94k|    uint8_t *p_x = their_pubkey;
 1639|  1.94k|    uint8_t *p_y = their_pubkey + 48U;
 1640|  1.94k|    uint64_t *bn_p_x = p_aff;
 1641|  1.94k|    uint64_t *bn_p_y = p_aff + 6U;
 1642|  1.94k|    bn_from_bytes_be(bn_p_x, p_x);
 1643|  1.94k|    bn_from_bytes_be(bn_p_y, p_y);
 1644|  1.94k|    uint64_t *px0 = p_aff;
 1645|  1.94k|    uint64_t *py0 = p_aff + 6U;
 1646|  1.94k|    uint64_t lessX = bn_is_lt_prime_mask(px0);
 1647|  1.94k|    uint64_t lessY = bn_is_lt_prime_mask(py0);
 1648|  1.94k|    uint64_t res0 = lessX & lessY;
 1649|  1.94k|    bool is_xy_valid = res0 == 0xFFFFFFFFFFFFFFFFULL;
 1650|  1.94k|    bool res;
 1651|  1.94k|    if (!is_xy_valid) {
  ------------------
  |  Branch (1651:9): [True: 0, False: 1.94k]
  ------------------
 1652|      0|        res = false;
 1653|  1.94k|    } else {
 1654|  1.94k|        uint64_t rp[6U] = { 0U };
 1655|  1.94k|        uint64_t tx[6U] = { 0U };
 1656|  1.94k|        uint64_t ty[6U] = { 0U };
 1657|  1.94k|        uint64_t *px = p_aff;
 1658|  1.94k|        uint64_t *py = p_aff + 6U;
 1659|  1.94k|        to_mont(tx, px);
 1660|  1.94k|        to_mont(ty, py);
 1661|  1.94k|        uint64_t tmp1[6U] = { 0U };
 1662|  1.94k|        fsqr0(rp, tx);
 1663|  1.94k|        fmul0(rp, rp, tx);
 1664|  1.94k|        p384_make_a_coeff(tmp1);
 1665|  1.94k|        fmul0(tmp1, tmp1, tx);
 1666|  1.94k|        fadd0(rp, tmp1, rp);
 1667|  1.94k|        p384_make_b_coeff(tmp1);
 1668|  1.94k|        fadd0(rp, tmp1, rp);
 1669|  1.94k|        fsqr0(ty, ty);
 1670|  1.94k|        uint64_t r = bn_is_eq_mask(ty, rp);
 1671|  1.94k|        uint64_t r0 = r;
 1672|  1.94k|        bool r1 = r0 == 0xFFFFFFFFFFFFFFFFULL;
 1673|  1.94k|        res = r1;
 1674|  1.94k|    }
 1675|  1.94k|    if (res) {
  ------------------
  |  Branch (1675:9): [True: 1.94k, False: 0]
  ------------------
 1676|  1.94k|        uint64_t *px = p_aff;
 1677|  1.94k|        uint64_t *py = p_aff + 6U;
 1678|  1.94k|        uint64_t *rx = pk;
 1679|  1.94k|        uint64_t *ry = pk + 6U;
 1680|  1.94k|        uint64_t *rz = pk + 12U;
 1681|  1.94k|        to_mont(rx, px);
 1682|  1.94k|        to_mont(ry, py);
 1683|  1.94k|        p384_make_fone(rz);
 1684|  1.94k|    }
 1685|  1.94k|    bool is_pk_valid = res;
 1686|  1.94k|    uint64_t is_sk_valid = load_qelem_conditional(sk, private_key);
 1687|  1.94k|    uint64_t ss_proj[18U] = { 0U };
 1688|  1.94k|    if (is_pk_valid) {
  ------------------
  |  Branch (1688:9): [True: 1.94k, False: 0]
  ------------------
 1689|  1.94k|        point_mul(ss_proj, sk, pk);
 1690|  1.94k|        uint64_t aff_p[12U] = { 0U };
 1691|  1.94k|        uint64_t zinv[6U] = { 0U };
 1692|  1.94k|        uint64_t *px = ss_proj;
 1693|  1.94k|        uint64_t *py1 = ss_proj + 6U;
 1694|  1.94k|        uint64_t *pz = ss_proj + 12U;
 1695|  1.94k|        uint64_t *x = aff_p;
 1696|  1.94k|        uint64_t *y = aff_p + 6U;
 1697|  1.94k|        p384_finv(zinv, pz);
 1698|  1.94k|        fmul0(x, px, zinv);
 1699|  1.94k|        fmul0(y, py1, zinv);
 1700|  1.94k|        from_mont(x, x);
 1701|  1.94k|        from_mont(y, y);
 1702|  1.94k|        uint64_t *px1 = aff_p;
 1703|  1.94k|        uint64_t *py = aff_p + 6U;
 1704|  1.94k|        bn_to_bytes_be(shared_secret, px1);
 1705|  1.94k|        bn_to_bytes_be(shared_secret + 48U, py);
 1706|  1.94k|    }
 1707|  1.94k|    return is_sk_valid == 0xFFFFFFFFFFFFFFFFULL && is_pk_valid;
  ------------------
  |  Branch (1707:12): [True: 1.94k, False: 0]
  |  Branch (1707:52): [True: 1.94k, False: 0]
  ------------------
 1708|  1.94k|}
Hacl_P384.c:bn_from_bytes_be:
  327|  18.0k|{
  328|  18.0k|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  18.0k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  18.0k|    do {                               \
  |  |  |  |  289|  18.0k|        uint32_t i = z;                \
  |  |  |  |  290|  18.0k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  18.0k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  329|  18.0k|                    0U,
  330|  18.0k|                    6U,
  331|  18.0k|                    1U,
  332|  18.0k|                    uint64_t *os = a;
  333|  18.0k|                    uint64_t u = load64_be(b + (6U - i - 1U) * 8U);
  334|  18.0k|                    uint64_t x = u;
  335|  18.0k|                    os[i] = x;);
  336|  18.0k|}
Hacl_P384.c:bn_sqr:
  271|  6.27M|{
  272|  6.27M|    memset(a, 0U, 12U * sizeof(uint64_t));
  273|  6.27M|    KRML_MAYBE_FOR6(
  ------------------
  |  |  342|  6.27M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  6.27M|    do {                               \
  |  |  |  |  289|  6.27M|        uint32_t i = z;                \
  |  |  |  |  290|  6.27M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  6.27M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  274|  6.27M|        i0,
  275|  6.27M|        0U,
  276|  6.27M|        6U,
  277|  6.27M|        1U,
  278|  6.27M|        uint64_t *ab = b;
  279|  6.27M|        uint64_t a_j = b[i0];
  280|  6.27M|        uint64_t *res_j = a + i0;
  281|  6.27M|        uint64_t c = 0ULL;
  282|  6.27M|        for (uint32_t i = 0U; i < i0 / 4U; i++) {
  283|  6.27M|            uint64_t a_i = ab[4U * i];
  284|  6.27M|            uint64_t *res_i0 = res_j + 4U * i;
  285|  6.27M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, a_j, c, res_i0);
  286|  6.27M|            uint64_t a_i0 = ab[4U * i + 1U];
  287|  6.27M|            uint64_t *res_i1 = res_j + 4U * i + 1U;
  288|  6.27M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, a_j, c, res_i1);
  289|  6.27M|            uint64_t a_i1 = ab[4U * i + 2U];
  290|  6.27M|            uint64_t *res_i2 = res_j + 4U * i + 2U;
  291|  6.27M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, a_j, c, res_i2);
  292|  6.27M|            uint64_t a_i2 = ab[4U * i + 3U];
  293|  6.27M|            uint64_t *res_i = res_j + 4U * i + 3U;
  294|  6.27M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, a_j, c, res_i);
  295|  6.27M|        } for (uint32_t i = i0 / 4U * 4U; i < i0; i++) {
  296|  6.27M|            uint64_t a_i = ab[i];
  297|  6.27M|            uint64_t *res_i = res_j + i;
  298|  6.27M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, a_j, c, res_i);
  299|  6.27M|        } uint64_t r = c;
  300|  6.27M|        a[i0 + i0] = r;);
  301|  6.27M|    uint64_t c0 = Hacl_Bignum_Addition_bn_add_eq_len_u64(12U, a, a, a);
  302|  6.27M|    KRML_MAYBE_UNUSED_VAR(c0);
  ------------------
  |  |   60|  6.27M|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|  6.27M|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  303|  6.27M|    uint64_t tmp[12U] = { 0U };
  304|  6.27M|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  6.27M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  6.27M|    do {                               \
  |  |  |  |  289|  6.27M|        uint32_t i = z;                \
  |  |  |  |  290|  6.27M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  6.27M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  305|  6.27M|                    0U,
  306|  6.27M|                    6U,
  307|  6.27M|                    1U,
  308|  6.27M|                    FStar_UInt128_uint128 res = FStar_UInt128_mul_wide(b[i], b[i]);
  309|  6.27M|                    uint64_t hi = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(res, 64U));
  310|  6.27M|                    uint64_t lo = FStar_UInt128_uint128_to_uint64(res);
  311|  6.27M|                    tmp[2U * i] = lo;
  312|  6.27M|                    tmp[2U * i + 1U] = hi;);
  313|  6.27M|    uint64_t c1 = Hacl_Bignum_Addition_bn_add_eq_len_u64(12U, a, tmp, a);
  314|  6.27M|    KRML_MAYBE_UNUSED_VAR(c1);
  ------------------
  |  |   60|  6.27M|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|  6.27M|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  315|  6.27M|}
Hacl_P384.c:bn_mul:
  235|  21.7M|{
  236|  21.7M|    memset(a, 0U, 12U * sizeof(uint64_t));
  237|  21.7M|    KRML_MAYBE_FOR6(
  ------------------
  |  |  342|  21.7M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  21.7M|    do {                               \
  |  |  |  |  289|  21.7M|        uint32_t i = z;                \
  |  |  |  |  290|  21.7M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  21.7M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  238|  21.7M|        i0,
  239|  21.7M|        0U,
  240|  21.7M|        6U,
  241|  21.7M|        1U,
  242|  21.7M|        uint64_t bj = c[i0];
  243|  21.7M|        uint64_t *res_j = a + i0;
  244|  21.7M|        uint64_t c1 = 0ULL;
  245|  21.7M|        {
  246|  21.7M|            uint64_t a_i = b[4U * 0U];
  247|  21.7M|            uint64_t *res_i0 = res_j + 4U * 0U;
  248|  21.7M|            c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, bj, c1, res_i0);
  249|  21.7M|            uint64_t a_i0 = b[4U * 0U + 1U];
  250|  21.7M|            uint64_t *res_i1 = res_j + 4U * 0U + 1U;
  251|  21.7M|            c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, bj, c1, res_i1);
  252|  21.7M|            uint64_t a_i1 = b[4U * 0U + 2U];
  253|  21.7M|            uint64_t *res_i2 = res_j + 4U * 0U + 2U;
  254|  21.7M|            c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, bj, c1, res_i2);
  255|  21.7M|            uint64_t a_i2 = b[4U * 0U + 3U];
  256|  21.7M|            uint64_t *res_i = res_j + 4U * 0U + 3U;
  257|  21.7M|            c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, bj, c1, res_i);
  258|  21.7M|        } KRML_MAYBE_FOR2(i,
  259|  21.7M|                          4U,
  260|  21.7M|                          6U,
  261|  21.7M|                          1U,
  262|  21.7M|                          uint64_t a_i = b[i];
  263|  21.7M|                          uint64_t *res_i = res_j + i;
  264|  21.7M|                          c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, bj, c1, res_i););
  265|  21.7M|        uint64_t r = c1;
  266|  21.7M|        a[6U + i0] = r;);
  267|  21.7M|}
Hacl_P384.c:bn_add_mod:
   60|  31.6M|{
   61|  31.6M|    uint64_t c10 = 0ULL;
   62|  31.6M|    {
   63|  31.6M|        uint64_t t1 = c[4U * 0U];
   64|  31.6M|        uint64_t t20 = d[4U * 0U];
   65|  31.6M|        uint64_t *res_i0 = a + 4U * 0U;
   66|  31.6M|        c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t1, t20, res_i0);
  ------------------
  |  |   66|  31.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   67|  31.6M|        uint64_t t10 = c[4U * 0U + 1U];
   68|  31.6M|        uint64_t t21 = d[4U * 0U + 1U];
   69|  31.6M|        uint64_t *res_i1 = a + 4U * 0U + 1U;
   70|  31.6M|        c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t10, t21, res_i1);
  ------------------
  |  |   66|  31.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   71|  31.6M|        uint64_t t11 = c[4U * 0U + 2U];
   72|  31.6M|        uint64_t t22 = d[4U * 0U + 2U];
   73|  31.6M|        uint64_t *res_i2 = a + 4U * 0U + 2U;
   74|  31.6M|        c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t11, t22, res_i2);
  ------------------
  |  |   66|  31.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   75|  31.6M|        uint64_t t12 = c[4U * 0U + 3U];
   76|  31.6M|        uint64_t t2 = d[4U * 0U + 3U];
   77|  31.6M|        uint64_t *res_i = a + 4U * 0U + 3U;
   78|  31.6M|        c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t12, t2, res_i);
  ------------------
  |  |   66|  31.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   79|  31.6M|    }
   80|  31.6M|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|  31.6M|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  31.6M|    do {                               \
  |  |  |  |  289|  31.6M|        uint32_t i = z;                \
  |  |  |  |  290|  31.6M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  31.6M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   81|  31.6M|                    4U,
   82|  31.6M|                    6U,
   83|  31.6M|                    1U,
   84|  31.6M|                    uint64_t t1 = c[i];
   85|  31.6M|                    uint64_t t2 = d[i];
   86|  31.6M|                    uint64_t *res_i = a + i;
   87|  31.6M|                    c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t1, t2, res_i););
   88|  31.6M|    uint64_t c0 = c10;
   89|  31.6M|    uint64_t tmp[6U] = { 0U };
   90|  31.6M|    uint64_t c1 = 0ULL;
   91|  31.6M|    {
   92|  31.6M|        uint64_t t1 = a[4U * 0U];
   93|  31.6M|        uint64_t t20 = b[4U * 0U];
   94|  31.6M|        uint64_t *res_i0 = tmp + 4U * 0U;
   95|  31.6M|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t20, res_i0);
  ------------------
  |  |   89|  31.6M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   96|  31.6M|        uint64_t t10 = a[4U * 0U + 1U];
   97|  31.6M|        uint64_t t21 = b[4U * 0U + 1U];
   98|  31.6M|        uint64_t *res_i1 = tmp + 4U * 0U + 1U;
   99|  31.6M|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t10, t21, res_i1);
  ------------------
  |  |   89|  31.6M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  100|  31.6M|        uint64_t t11 = a[4U * 0U + 2U];
  101|  31.6M|        uint64_t t22 = b[4U * 0U + 2U];
  102|  31.6M|        uint64_t *res_i2 = tmp + 4U * 0U + 2U;
  103|  31.6M|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t11, t22, res_i2);
  ------------------
  |  |   89|  31.6M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  104|  31.6M|        uint64_t t12 = a[4U * 0U + 3U];
  105|  31.6M|        uint64_t t2 = b[4U * 0U + 3U];
  106|  31.6M|        uint64_t *res_i = tmp + 4U * 0U + 3U;
  107|  31.6M|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t12, t2, res_i);
  ------------------
  |  |   89|  31.6M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  108|  31.6M|    }
  109|  31.6M|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|  31.6M|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  31.6M|    do {                               \
  |  |  |  |  289|  31.6M|        uint32_t i = z;                \
  |  |  |  |  290|  31.6M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  31.6M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  110|  31.6M|                    4U,
  111|  31.6M|                    6U,
  112|  31.6M|                    1U,
  113|  31.6M|                    uint64_t t1 = a[i];
  114|  31.6M|                    uint64_t t2 = b[i];
  115|  31.6M|                    uint64_t *res_i = tmp + i;
  116|  31.6M|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t2, res_i););
  117|  31.6M|    uint64_t c11 = c1;
  118|  31.6M|    uint64_t c2 = c0 - c11;
  119|  31.6M|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  31.6M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  31.6M|    do {                               \
  |  |  |  |  289|  31.6M|        uint32_t i = z;                \
  |  |  |  |  290|  31.6M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  31.6M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  120|  31.6M|                    0U,
  121|  31.6M|                    6U,
  122|  31.6M|                    1U,
  123|  31.6M|                    uint64_t *os = a;
  124|  31.6M|                    uint64_t x = (c2 & a[i]) | (~c2 & tmp[i]);
  125|  31.6M|                    os[i] = x;);
  126|  31.6M|}
Hacl_P384.c:point_add:
  880|   411k|{
  881|   411k|    uint64_t tmp[54U] = { 0U };
  882|   411k|    uint64_t *t0 = tmp;
  883|   411k|    uint64_t *t1 = tmp + 36U;
  884|   411k|    uint64_t *x3 = t1;
  885|   411k|    uint64_t *y3 = t1 + 6U;
  886|   411k|    uint64_t *z3 = t1 + 12U;
  887|   411k|    uint64_t *t01 = t0;
  888|   411k|    uint64_t *t11 = t0 + 6U;
  889|   411k|    uint64_t *t2 = t0 + 12U;
  890|   411k|    uint64_t *t3 = t0 + 18U;
  891|   411k|    uint64_t *t4 = t0 + 24U;
  892|   411k|    uint64_t *t5 = t0 + 30U;
  893|   411k|    uint64_t *x1 = x;
  894|   411k|    uint64_t *y1 = x + 6U;
  895|   411k|    uint64_t *z10 = x + 12U;
  896|   411k|    uint64_t *x20 = y;
  897|   411k|    uint64_t *y20 = y + 6U;
  898|   411k|    uint64_t *z20 = y + 12U;
  899|   411k|    fmul0(t01, x1, x20);
  900|   411k|    fmul0(t11, y1, y20);
  901|   411k|    fmul0(t2, z10, z20);
  902|   411k|    fadd0(t3, x1, y1);
  903|   411k|    fadd0(t4, x20, y20);
  904|   411k|    fmul0(t3, t3, t4);
  905|   411k|    fadd0(t4, t01, t11);
  906|   411k|    uint64_t *y10 = x + 6U;
  907|   411k|    uint64_t *z11 = x + 12U;
  908|   411k|    uint64_t *y2 = y + 6U;
  909|   411k|    uint64_t *z21 = y + 12U;
  910|   411k|    fsub0(t3, t3, t4);
  911|   411k|    fadd0(t4, y10, z11);
  912|   411k|    fadd0(t5, y2, z21);
  913|   411k|    fmul0(t4, t4, t5);
  914|   411k|    fadd0(t5, t11, t2);
  915|   411k|    fsub0(t4, t4, t5);
  916|   411k|    uint64_t *x10 = x;
  917|   411k|    uint64_t *z1 = x + 12U;
  918|   411k|    uint64_t *x2 = y;
  919|   411k|    uint64_t *z2 = y + 12U;
  920|   411k|    fadd0(x3, x10, z1);
  921|   411k|    fadd0(y3, x2, z2);
  922|   411k|    fmul0(x3, x3, y3);
  923|   411k|    fadd0(y3, t01, t2);
  924|   411k|    fsub0(y3, x3, y3);
  925|   411k|    uint64_t b_coeff[6U] = { 0U };
  926|   411k|    p384_make_b_coeff(b_coeff);
  927|   411k|    fmul0(z3, b_coeff, t2);
  928|   411k|    fsub0(x3, y3, z3);
  929|   411k|    fadd0(z3, x3, x3);
  930|   411k|    fadd0(x3, x3, z3);
  931|   411k|    fsub0(z3, t11, x3);
  932|   411k|    fadd0(x3, t11, x3);
  933|   411k|    uint64_t b_coeff0[6U] = { 0U };
  934|   411k|    p384_make_b_coeff(b_coeff0);
  935|   411k|    fmul0(y3, b_coeff0, y3);
  936|   411k|    fadd0(t11, t2, t2);
  937|   411k|    fadd0(t2, t11, t2);
  938|   411k|    fsub0(y3, y3, t2);
  939|   411k|    fsub0(y3, y3, t01);
  940|   411k|    fadd0(t11, y3, y3);
  941|   411k|    fadd0(y3, t11, y3);
  942|   411k|    fadd0(t11, t01, t01);
  943|   411k|    fadd0(t01, t11, t01);
  944|   411k|    fsub0(t01, t01, t2);
  945|   411k|    fmul0(t11, t4, y3);
  946|   411k|    fmul0(t2, t01, y3);
  947|   411k|    fmul0(y3, x3, z3);
  948|   411k|    fadd0(y3, y3, t2);
  949|   411k|    fmul0(x3, t3, x3);
  950|   411k|    fsub0(x3, x3, t11);
  951|   411k|    fmul0(z3, t4, z3);
  952|   411k|    fmul0(t11, t3, t01);
  953|   411k|    fadd0(z3, z3, t11);
  954|   411k|    memcpy(xy, t1, 18U * sizeof(uint64_t));
  955|   411k|}
Hacl_P384.c:bn_is_lt_prime_mask:
  606|  12.0k|{
  607|  12.0k|    uint64_t tmp[6U] = { 0U };
  608|  12.0k|    p384_make_prime(tmp);
  609|  12.0k|    uint64_t c = bn_sub(tmp, f, tmp);
  610|  12.0k|    uint64_t m = FStar_UInt64_gte_mask(c, 0ULL) & ~FStar_UInt64_eq_mask(c, 0ULL);
  611|  12.0k|    return m;
  612|  12.0k|}
Hacl_P384.c:p384_make_prime:
  340|  72.8M|{
  341|  72.8M|    n[0U] = 0x00000000ffffffffULL;
  342|  72.8M|    n[1U] = 0xffffffff00000000ULL;
  343|  72.8M|    n[2U] = 0xfffffffffffffffeULL;
  344|  72.8M|    n[3U] = 0xffffffffffffffffULL;
  345|  72.8M|    n[4U] = 0xffffffffffffffffULL;
  346|  72.8M|    n[5U] = 0xffffffffffffffffULL;
  347|  72.8M|}
Hacl_P384.c:to_mont:
  656|  23.8k|{
  657|  23.8k|    uint64_t r2modn[6U] = { 0U };
  658|  23.8k|    p384_make_fmont_R2(r2modn);
  659|  23.8k|    uint64_t tmp[12U] = { 0U };
  660|  23.8k|    bn_mul(tmp, b, r2modn);
  661|  23.8k|    fmont_reduction(a, tmp);
  662|  23.8k|}
Hacl_P384.c:p384_make_fmont_R2:
  406|  23.8k|{
  407|  23.8k|    n[0U] = 0xfffffffe00000001ULL;
  408|  23.8k|    n[1U] = 0x0000000200000000ULL;
  409|  23.8k|    n[2U] = 0xfffffffe00000000ULL;
  410|  23.8k|    n[3U] = 0x0000000200000000ULL;
  411|  23.8k|    n[4U] = 0x0000000000000001ULL;
  412|  23.8k|    n[5U] = 0x0ULL;
  413|  23.8k|}
Hacl_P384.c:fmont_reduction:
  446|  28.0M|{
  447|  28.0M|    uint64_t n[6U] = { 0U };
  448|  28.0M|    p384_make_prime(n);
  449|  28.0M|    uint64_t c0 = 0ULL;
  450|  28.0M|    KRML_MAYBE_FOR6(
  ------------------
  |  |  342|  28.0M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.0M|    do {                               \
  |  |  |  |  289|  28.0M|        uint32_t i = z;                \
  |  |  |  |  290|  28.0M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.0M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  451|  28.0M|        i0,
  452|  28.0M|        0U,
  453|  28.0M|        6U,
  454|  28.0M|        1U,
  455|  28.0M|        uint64_t qj = 4294967297ULL * x[i0];
  456|  28.0M|        uint64_t *res_j0 = x + i0;
  457|  28.0M|        uint64_t c = 0ULL;
  458|  28.0M|        {
  459|  28.0M|            uint64_t a_i = n[4U * 0U];
  460|  28.0M|            uint64_t *res_i0 = res_j0 + 4U * 0U;
  461|  28.0M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, qj, c, res_i0);
  462|  28.0M|            uint64_t a_i0 = n[4U * 0U + 1U];
  463|  28.0M|            uint64_t *res_i1 = res_j0 + 4U * 0U + 1U;
  464|  28.0M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, qj, c, res_i1);
  465|  28.0M|            uint64_t a_i1 = n[4U * 0U + 2U];
  466|  28.0M|            uint64_t *res_i2 = res_j0 + 4U * 0U + 2U;
  467|  28.0M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, qj, c, res_i2);
  468|  28.0M|            uint64_t a_i2 = n[4U * 0U + 3U];
  469|  28.0M|            uint64_t *res_i = res_j0 + 4U * 0U + 3U;
  470|  28.0M|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, qj, c, res_i);
  471|  28.0M|        } KRML_MAYBE_FOR2(i,
  472|  28.0M|                          4U,
  473|  28.0M|                          6U,
  474|  28.0M|                          1U,
  475|  28.0M|                          uint64_t a_i = n[i];
  476|  28.0M|                          uint64_t *res_i = res_j0 + i;
  477|  28.0M|                          c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, qj, c, res_i););
  478|  28.0M|        uint64_t r = c;
  479|  28.0M|        uint64_t c1 = r;
  480|  28.0M|        uint64_t *resb = x + 6U + i0;
  481|  28.0M|        uint64_t res_j = x[6U + i0];
  482|  28.0M|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, c1, res_j, resb););
  483|  28.0M|    memcpy(res, x + 6U, 6U * sizeof(uint64_t));
  484|  28.0M|    uint64_t c00 = c0;
  485|  28.0M|    uint64_t tmp[6U] = { 0U };
  486|  28.0M|    uint64_t c = 0ULL;
  487|  28.0M|    {
  488|  28.0M|        uint64_t t1 = res[4U * 0U];
  489|  28.0M|        uint64_t t20 = n[4U * 0U];
  490|  28.0M|        uint64_t *res_i0 = tmp + 4U * 0U;
  491|  28.0M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t20, res_i0);
  ------------------
  |  |   89|  28.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  492|  28.0M|        uint64_t t10 = res[4U * 0U + 1U];
  493|  28.0M|        uint64_t t21 = n[4U * 0U + 1U];
  494|  28.0M|        uint64_t *res_i1 = tmp + 4U * 0U + 1U;
  495|  28.0M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t10, t21, res_i1);
  ------------------
  |  |   89|  28.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  496|  28.0M|        uint64_t t11 = res[4U * 0U + 2U];
  497|  28.0M|        uint64_t t22 = n[4U * 0U + 2U];
  498|  28.0M|        uint64_t *res_i2 = tmp + 4U * 0U + 2U;
  499|  28.0M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t11, t22, res_i2);
  ------------------
  |  |   89|  28.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  500|  28.0M|        uint64_t t12 = res[4U * 0U + 3U];
  501|  28.0M|        uint64_t t2 = n[4U * 0U + 3U];
  502|  28.0M|        uint64_t *res_i = tmp + 4U * 0U + 3U;
  503|  28.0M|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t12, t2, res_i);
  ------------------
  |  |   89|  28.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  504|  28.0M|    }
  505|  28.0M|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|  28.0M|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.0M|    do {                               \
  |  |  |  |  289|  28.0M|        uint32_t i = z;                \
  |  |  |  |  290|  28.0M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.0M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  506|  28.0M|                    4U,
  507|  28.0M|                    6U,
  508|  28.0M|                    1U,
  509|  28.0M|                    uint64_t t1 = res[i];
  510|  28.0M|                    uint64_t t2 = n[i];
  511|  28.0M|                    uint64_t *res_i = tmp + i;
  512|  28.0M|                    c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t2, res_i););
  513|  28.0M|    uint64_t c1 = c;
  514|  28.0M|    uint64_t c2 = c00 - c1;
  515|  28.0M|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  28.0M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  28.0M|    do {                               \
  |  |  |  |  289|  28.0M|        uint32_t i = z;                \
  |  |  |  |  290|  28.0M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  28.0M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  516|  28.0M|                    0U,
  517|  28.0M|                    6U,
  518|  28.0M|                    1U,
  519|  28.0M|                    uint64_t *os = res;
  520|  28.0M|                    uint64_t x1 = (c2 & res[i]) | (~c2 & tmp[i]);
  521|  28.0M|                    os[i] = x1;);
  522|  28.0M|}
Hacl_P384.c:fsqr0:
  640|  6.27M|{
  641|  6.27M|    uint64_t tmp[12U] = { 0U };
  642|  6.27M|    bn_sqr(tmp, b);
  643|  6.27M|    fmont_reduction(a, tmp);
  644|  6.27M|}
Hacl_P384.c:fmul0:
  632|  21.7M|{
  633|  21.7M|    uint64_t tmp[12U] = { 0U };
  634|  21.7M|    bn_mul(tmp, b, c);
  635|  21.7M|    fmont_reduction(a, tmp);
  636|  21.7M|}
Hacl_P384.c:p384_make_a_coeff:
  362|  6.00k|{
  363|  6.00k|    a[0U] = 0x00000003fffffffcULL;
  364|  6.00k|    a[1U] = 0xfffffffc00000000ULL;
  365|  6.00k|    a[2U] = 0xfffffffffffffffbULL;
  366|  6.00k|    a[3U] = 0xffffffffffffffffULL;
  367|  6.00k|    a[4U] = 0xffffffffffffffffULL;
  368|  6.00k|    a[5U] = 0xffffffffffffffffULL;
  369|  6.00k|}
Hacl_P384.c:fadd0:
  616|  31.6M|{
  617|  31.6M|    uint64_t n[6U] = { 0U };
  618|  31.6M|    p384_make_prime(n);
  619|  31.6M|    bn_add_mod(a, n, b, c);
  620|  31.6M|}
Hacl_P384.c:p384_make_b_coeff:
  373|  3.95M|{
  374|  3.95M|    b[0U] = 0x081188719d412dccULL;
  375|  3.95M|    b[1U] = 0xf729add87a4c32ecULL;
  376|  3.95M|    b[2U] = 0x77f2209b1920022eULL;
  377|  3.95M|    b[3U] = 0xe3374bee94938ae2ULL;
  378|  3.95M|    b[4U] = 0xb62b21f41f022094ULL;
  379|  3.95M|    b[5U] = 0xcd08114b604fbff9ULL;
  380|  3.95M|}
Hacl_P384.c:bn_is_eq_mask:
   32|  12.0k|{
   33|  12.0k|    uint64_t mask = 0xFFFFFFFFFFFFFFFFULL;
   34|  12.0k|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  12.0k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  12.0k|    do {                               \
  |  |  |  |  289|  12.0k|        uint32_t i = z;                \
  |  |  |  |  290|  12.0k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  12.0k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   35|  12.0k|                    0U,
   36|  12.0k|                    6U,
   37|  12.0k|                    1U,
   38|  12.0k|                    uint64_t uu____0 = FStar_UInt64_eq_mask(x[i], y[i]);
   39|  12.0k|                    mask = uu____0 & mask;);
   40|  12.0k|    uint64_t mask1 = mask;
   41|  12.0k|    return mask1;
   42|  12.0k|}
Hacl_P384.c:p384_make_fone:
  424|  19.9k|{
  425|  19.9k|    n[0U] = 0xffffffff00000001ULL;
  426|  19.9k|    n[1U] = 0x00000000ffffffffULL;
  427|  19.9k|    n[2U] = 0x1ULL;
  428|  19.9k|    n[3U] = 0x0ULL;
  429|  19.9k|    n[4U] = 0x0ULL;
  430|  19.9k|    n[5U] = 0x0ULL;
  431|  19.9k|}
Hacl_P384.c:p384_make_order:
  351|  6.04k|{
  352|  6.04k|    n[0U] = 0xecec196accc52973ULL;
  353|  6.04k|    n[1U] = 0x581a0db248b0a77aULL;
  354|  6.04k|    n[2U] = 0xc7634d81f4372ddfULL;
  355|  6.04k|    n[3U] = 0xffffffffffffffffULL;
  356|  6.04k|    n[4U] = 0xffffffffffffffffULL;
  357|  6.04k|    n[5U] = 0xffffffffffffffffULL;
  358|  6.04k|}
Hacl_P384.c:bn_sub:
  130|  18.0k|{
  131|  18.0k|    uint64_t c1 = 0ULL;
  132|  18.0k|    {
  133|  18.0k|        uint64_t t1 = b[4U * 0U];
  134|  18.0k|        uint64_t t20 = c[4U * 0U];
  135|  18.0k|        uint64_t *res_i0 = a + 4U * 0U;
  136|  18.0k|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t20, res_i0);
  ------------------
  |  |   89|  18.0k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  137|  18.0k|        uint64_t t10 = b[4U * 0U + 1U];
  138|  18.0k|        uint64_t t21 = c[4U * 0U + 1U];
  139|  18.0k|        uint64_t *res_i1 = a + 4U * 0U + 1U;
  140|  18.0k|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t10, t21, res_i1);
  ------------------
  |  |   89|  18.0k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  141|  18.0k|        uint64_t t11 = b[4U * 0U + 2U];
  142|  18.0k|        uint64_t t22 = c[4U * 0U + 2U];
  143|  18.0k|        uint64_t *res_i2 = a + 4U * 0U + 2U;
  144|  18.0k|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t11, t22, res_i2);
  ------------------
  |  |   89|  18.0k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  145|  18.0k|        uint64_t t12 = b[4U * 0U + 3U];
  146|  18.0k|        uint64_t t2 = c[4U * 0U + 3U];
  147|  18.0k|        uint64_t *res_i = a + 4U * 0U + 3U;
  148|  18.0k|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t12, t2, res_i);
  ------------------
  |  |   89|  18.0k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  149|  18.0k|    }
  150|  18.0k|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|  18.0k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  18.0k|    do {                               \
  |  |  |  |  289|  18.0k|        uint32_t i = z;                \
  |  |  |  |  290|  18.0k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  18.0k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  151|  18.0k|                    4U,
  152|  18.0k|                    6U,
  153|  18.0k|                    1U,
  154|  18.0k|                    uint64_t t1 = b[i];
  155|  18.0k|                    uint64_t t2 = c[i];
  156|  18.0k|                    uint64_t *res_i = a + i;
  157|  18.0k|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t2, res_i););
  158|  18.0k|    uint64_t c10 = c1;
  159|  18.0k|    return c10;
  160|  18.0k|}
Hacl_P384.c:fexp_consttime:
  666|  3.99k|{
  667|  3.99k|    uint64_t table[192U] = { 0U };
  668|  3.99k|    uint64_t tmp[6U] = { 0U };
  669|  3.99k|    uint64_t *t0 = table;
  670|  3.99k|    uint64_t *t1 = table + 6U;
  671|  3.99k|    p384_make_fone(t0);
  672|  3.99k|    memcpy(t1, a, 6U * sizeof(uint64_t));
  673|  3.99k|    KRML_MAYBE_FOR15(i,
  ------------------
  |  |  396|  3.99k|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|  3.99k|    do {                               \
  |  |  |  |  289|  3.99k|        uint32_t i = z;                \
  |  |  |  |  290|  3.99k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  3.99k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  674|  3.99k|                     0U,
  675|  3.99k|                     15U,
  676|  3.99k|                     1U,
  677|  3.99k|                     uint64_t *t11 = table + (i + 1U) * 6U;
  678|  3.99k|                     fsqr0(tmp, t11);
  679|  3.99k|                     memcpy(table + (2U * i + 2U) * 6U, tmp, 6U * sizeof(uint64_t));
  680|  3.99k|                     uint64_t *t2 = table + (2U * i + 2U) * 6U;
  681|  3.99k|                     fmul0(tmp, a, t2);
  682|  3.99k|                     memcpy(table + (2U * i + 3U) * 6U, tmp, 6U * sizeof(uint64_t)););
  683|  3.99k|    uint32_t i0 = 380U;
  684|  3.99k|    uint64_t bits_c = Hacl_Bignum_Lib_bn_get_bits_u64(6U, b, i0, 5U);
  685|  3.99k|    memcpy(out, (uint64_t *)table, 6U * sizeof(uint64_t));
  686|   127k|    for (uint32_t i1 = 0U; i1 < 31U; i1++) {
  ------------------
  |  Branch (686:28): [True: 123k, False: 3.99k]
  ------------------
  687|   123k|        uint64_t c = FStar_UInt64_eq_mask(bits_c, (uint64_t)(i1 + 1U));
  688|   123k|        const uint64_t *res_j = table + (i1 + 1U) * 6U;
  689|   123k|        KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|   123k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|   123k|    do {                               \
  |  |  |  |  289|   123k|        uint32_t i = z;                \
  |  |  |  |  290|   123k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   123k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  690|   123k|                        0U,
  691|   123k|                        6U,
  692|   123k|                        1U,
  693|   123k|                        uint64_t *os = out;
  694|   123k|                        uint64_t x = (c & res_j[i]) | (~c & out[i]);
  695|   123k|                        os[i] = x;);
  696|   123k|    }
  697|  3.99k|    uint64_t tmp0[6U] = { 0U };
  698|   307k|    for (uint32_t i1 = 0U; i1 < 76U; i1++) {
  ------------------
  |  Branch (698:28): [True: 303k, False: 3.99k]
  ------------------
  699|   303k|        KRML_MAYBE_FOR5(i, 0U, 5U, 1U, fsqr0(out, out););
  ------------------
  |  |  336|   303k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|   303k|    do {                               \
  |  |  |  |  289|   303k|        uint32_t i = z;                \
  |  |  |  |  290|   303k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   303k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  700|   303k|        uint32_t k = 380U - 5U * i1 - 5U;
  701|   303k|        uint64_t bits_l = Hacl_Bignum_Lib_bn_get_bits_u64(6U, b, k, 5U);
  702|   303k|        memcpy(tmp0, (uint64_t *)table, 6U * sizeof(uint64_t));
  703|  9.71M|        for (uint32_t i2 = 0U; i2 < 31U; i2++) {
  ------------------
  |  Branch (703:32): [True: 9.41M, False: 303k]
  ------------------
  704|  9.41M|            uint64_t c = FStar_UInt64_eq_mask(bits_l, (uint64_t)(i2 + 1U));
  705|  9.41M|            const uint64_t *res_j = table + (i2 + 1U) * 6U;
  706|  9.41M|            KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  9.41M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  9.41M|    do {                               \
  |  |  |  |  289|  9.41M|        uint32_t i = z;                \
  |  |  |  |  290|  9.41M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  9.41M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  707|  9.41M|                            0U,
  708|  9.41M|                            6U,
  709|  9.41M|                            1U,
  710|  9.41M|                            uint64_t *os = tmp0;
  711|  9.41M|                            uint64_t x = (c & res_j[i]) | (~c & tmp0[i]);
  712|  9.41M|                            os[i] = x;);
  713|  9.41M|        }
  714|   303k|        fmul0(out, out, tmp0);
  715|   303k|    }
  716|  3.99k|}
Hacl_P384.c:from_mont:
  648|  7.99k|{
  649|  7.99k|    uint64_t tmp[12U] = { 0U };
  650|  7.99k|    memcpy(tmp, b, 6U * sizeof(uint64_t));
  651|  7.99k|    fmont_reduction(a, tmp);
  652|  7.99k|}
Hacl_P384.c:fsub0:
  624|  13.0M|{
  625|  13.0M|    uint64_t n[6U] = { 0U };
  626|  13.0M|    p384_make_prime(n);
  627|  13.0M|    bn_sub_mod(a, n, b, c);
  628|  13.0M|}
Hacl_P384.c:bn_sub_mod:
  164|  13.0M|{
  165|  13.0M|    uint64_t c10 = 0ULL;
  166|  13.0M|    {
  167|  13.0M|        uint64_t t1 = c[4U * 0U];
  168|  13.0M|        uint64_t t20 = d[4U * 0U];
  169|  13.0M|        uint64_t *res_i0 = a + 4U * 0U;
  170|  13.0M|        c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t1, t20, res_i0);
  ------------------
  |  |   89|  13.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  171|  13.0M|        uint64_t t10 = c[4U * 0U + 1U];
  172|  13.0M|        uint64_t t21 = d[4U * 0U + 1U];
  173|  13.0M|        uint64_t *res_i1 = a + 4U * 0U + 1U;
  174|  13.0M|        c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t10, t21, res_i1);
  ------------------
  |  |   89|  13.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  175|  13.0M|        uint64_t t11 = c[4U * 0U + 2U];
  176|  13.0M|        uint64_t t22 = d[4U * 0U + 2U];
  177|  13.0M|        uint64_t *res_i2 = a + 4U * 0U + 2U;
  178|  13.0M|        c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t11, t22, res_i2);
  ------------------
  |  |   89|  13.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  179|  13.0M|        uint64_t t12 = c[4U * 0U + 3U];
  180|  13.0M|        uint64_t t2 = d[4U * 0U + 3U];
  181|  13.0M|        uint64_t *res_i = a + 4U * 0U + 3U;
  182|  13.0M|        c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t12, t2, res_i);
  ------------------
  |  |   89|  13.0M|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  183|  13.0M|    }
  184|  13.0M|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|  13.0M|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  13.0M|    do {                               \
  |  |  |  |  289|  13.0M|        uint32_t i = z;                \
  |  |  |  |  290|  13.0M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  13.0M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  185|  13.0M|                    4U,
  186|  13.0M|                    6U,
  187|  13.0M|                    1U,
  188|  13.0M|                    uint64_t t1 = c[i];
  189|  13.0M|                    uint64_t t2 = d[i];
  190|  13.0M|                    uint64_t *res_i = a + i;
  191|  13.0M|                    c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t1, t2, res_i););
  192|  13.0M|    uint64_t c0 = c10;
  193|  13.0M|    uint64_t tmp[6U] = { 0U };
  194|  13.0M|    uint64_t c1 = 0ULL;
  195|  13.0M|    {
  196|  13.0M|        uint64_t t1 = a[4U * 0U];
  197|  13.0M|        uint64_t t20 = b[4U * 0U];
  198|  13.0M|        uint64_t *res_i0 = tmp + 4U * 0U;
  199|  13.0M|        c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t1, t20, res_i0);
  ------------------
  |  |   66|  13.0M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  200|  13.0M|        uint64_t t10 = a[4U * 0U + 1U];
  201|  13.0M|        uint64_t t21 = b[4U * 0U + 1U];
  202|  13.0M|        uint64_t *res_i1 = tmp + 4U * 0U + 1U;
  203|  13.0M|        c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t10, t21, res_i1);
  ------------------
  |  |   66|  13.0M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  204|  13.0M|        uint64_t t11 = a[4U * 0U + 2U];
  205|  13.0M|        uint64_t t22 = b[4U * 0U + 2U];
  206|  13.0M|        uint64_t *res_i2 = tmp + 4U * 0U + 2U;
  207|  13.0M|        c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t11, t22, res_i2);
  ------------------
  |  |   66|  13.0M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  208|  13.0M|        uint64_t t12 = a[4U * 0U + 3U];
  209|  13.0M|        uint64_t t2 = b[4U * 0U + 3U];
  210|  13.0M|        uint64_t *res_i = tmp + 4U * 0U + 3U;
  211|  13.0M|        c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t12, t2, res_i);
  ------------------
  |  |   66|  13.0M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  212|  13.0M|    }
  213|  13.0M|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|  13.0M|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|  13.0M|    do {                               \
  |  |  |  |  289|  13.0M|        uint32_t i = z;                \
  |  |  |  |  290|  13.0M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  13.0M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  214|  13.0M|                    4U,
  215|  13.0M|                    6U,
  216|  13.0M|                    1U,
  217|  13.0M|                    uint64_t t1 = a[i];
  218|  13.0M|                    uint64_t t2 = b[i];
  219|  13.0M|                    uint64_t *res_i = tmp + i;
  220|  13.0M|                    c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t1, t2, res_i););
  221|  13.0M|    uint64_t c11 = c1;
  222|  13.0M|    KRML_MAYBE_UNUSED_VAR(c11);
  ------------------
  |  |   60|  13.0M|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|  13.0M|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  223|  13.0M|    uint64_t c2 = 0ULL - c0;
  224|  13.0M|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  13.0M|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  13.0M|    do {                               \
  |  |  |  |  289|  13.0M|        uint32_t i = z;                \
  |  |  |  |  290|  13.0M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  13.0M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  225|  13.0M|                    0U,
  226|  13.0M|                    6U,
  227|  13.0M|                    1U,
  228|  13.0M|                    uint64_t *os = a;
  229|  13.0M|                    uint64_t x = (c2 & tmp[i]) | (~c2 & a[i]);
  230|  13.0M|                    os[i] = x;);
  231|  13.0M|}
Hacl_P384.c:bn_to_bytes_be:
  319|  7.99k|{
  320|  7.99k|    uint8_t tmp[48U] = { 0U };
  321|  7.99k|    KRML_MAYBE_UNUSED_VAR(tmp);
  ------------------
  |  |   60|  7.99k|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|  7.99k|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  322|  7.99k|    KRML_MAYBE_FOR6(i, 0U, 6U, 1U, store64_be(a + i * 8U, b[6U - i - 1U]););
  ------------------
  |  |  342|  7.99k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  7.99k|    do {                               \
  |  |  |  |  289|  7.99k|        uint32_t i = z;                \
  |  |  |  |  290|  7.99k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  7.99k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  323|  7.99k|}
Hacl_P384.c:load_qelem_conditional:
  746|  3.99k|{
  747|  3.99k|    bn_from_bytes_be(a, b);
  748|  3.99k|    uint64_t tmp[6U] = { 0U };
  749|  3.99k|    p384_make_order(tmp);
  750|  3.99k|    uint64_t c = bn_sub(tmp, a, tmp);
  751|  3.99k|    uint64_t is_lt_order = FStar_UInt64_gte_mask(c, 0ULL) & ~FStar_UInt64_eq_mask(c, 0ULL);
  752|  3.99k|    uint64_t bn_zero[6U] = { 0U };
  753|  3.99k|    uint64_t res = bn_is_eq_mask(a, bn_zero);
  754|  3.99k|    uint64_t is_eq_zero = res;
  755|  3.99k|    uint64_t is_b_valid = is_lt_order & ~is_eq_zero;
  756|  3.99k|    uint64_t oneq[6U] = { 0U };
  757|  3.99k|    memset(oneq, 0U, 6U * sizeof(uint64_t));
  758|  3.99k|    oneq[0U] = 1ULL;
  759|  3.99k|    KRML_MAYBE_FOR6(i,
  ------------------
  |  |  342|  3.99k|#define KRML_MAYBE_FOR6(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 6, k, x)
  |  |  ------------------
  |  |  |  |  288|  3.99k|    do {                               \
  |  |  |  |  289|  3.99k|        uint32_t i = z;                \
  |  |  |  |  290|  3.99k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  3.99k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  760|  3.99k|                    0U,
  761|  3.99k|                    6U,
  762|  3.99k|                    1U,
  763|  3.99k|                    uint64_t *os = a;
  764|  3.99k|                    uint64_t uu____0 = oneq[i];
  765|  3.99k|                    uint64_t x = uu____0 ^ (is_b_valid & (a[i] ^ uu____0));
  766|  3.99k|                    os[i] = x;);
  767|  3.99k|    return is_b_valid;
  768|  3.99k|}
Hacl_P384.c:point_mul_g:
 1069|  2.04k|{
 1070|  2.04k|    uint64_t g[18U] = { 0U };
 1071|  2.04k|    uint64_t *x = g;
 1072|  2.04k|    uint64_t *y = g + 6U;
 1073|  2.04k|    uint64_t *z = g + 12U;
 1074|  2.04k|    p384_make_g_x(x);
 1075|  2.04k|    p384_make_g_y(y);
 1076|  2.04k|    p384_make_fone(z);
 1077|  2.04k|    point_mul(res, scalar, g);
 1078|  2.04k|}
Hacl_P384.c:p384_make_g_x:
  384|  2.04k|{
  385|  2.04k|    n[0U] = 0x3dd0756649c0b528ULL;
  386|  2.04k|    n[1U] = 0x20e378e2a0d6ce38ULL;
  387|  2.04k|    n[2U] = 0x879c3afc541b4d6eULL;
  388|  2.04k|    n[3U] = 0x6454868459a30effULL;
  389|  2.04k|    n[4U] = 0x812ff723614ede2bULL;
  390|  2.04k|    n[5U] = 0x4d3aadc2299e1513ULL;
  391|  2.04k|}
Hacl_P384.c:p384_make_g_y:
  395|  2.04k|{
  396|  2.04k|    n[0U] = 0x23043dad4b03a4feULL;
  397|  2.04k|    n[1U] = 0xa1bfa8bf7bb4a9acULL;
  398|  2.04k|    n[2U] = 0x8bade7562e83b050ULL;
  399|  2.04k|    n[3U] = 0xc6c3521968f4ffd9ULL;
  400|  2.04k|    n[4U] = 0xdd8002263969a840ULL;
  401|  2.04k|    n[5U] = 0x2b78abc25a15c5e9ULL;
  402|  2.04k|}
Hacl_P384.c:p384_finv:
  720|  3.99k|{
  721|  3.99k|    uint64_t b[6U] = { 0U };
  722|  3.99k|    b[0U] = 0x00000000fffffffdULL;
  723|  3.99k|    b[1U] = 0xffffffff00000000ULL;
  724|  3.99k|    b[2U] = 0xfffffffffffffffeULL;
  725|  3.99k|    b[3U] = 0xffffffffffffffffULL;
  726|  3.99k|    b[4U] = 0xffffffffffffffffULL;
  727|  3.99k|    b[5U] = 0xffffffffffffffffULL;
  728|  3.99k|    fexp_consttime(res, a, b);
  729|  3.99k|}
Hacl_P384.c:point_mul:
 1027|  3.99k|{
 1028|  3.99k|    uint64_t table[288U] = { 0U };
 1029|  3.99k|    uint64_t tmp[18U] = { 0U };
 1030|  3.99k|    uint64_t *t0 = table;
 1031|  3.99k|    uint64_t *t1 = table + 18U;
 1032|  3.99k|    point_zero(t0);
 1033|  3.99k|    memcpy(t1, p, 18U * sizeof(uint64_t));
 1034|  3.99k|    KRML_MAYBE_FOR7(i,
  ------------------
  |  |  348|  3.99k|#define KRML_MAYBE_FOR7(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 7, k, x)
  |  |  ------------------
  |  |  |  |  288|  3.99k|    do {                               \
  |  |  |  |  289|  3.99k|        uint32_t i = z;                \
  |  |  |  |  290|  3.99k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  3.99k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1035|  3.99k|                    0U,
 1036|  3.99k|                    7U,
 1037|  3.99k|                    1U,
 1038|  3.99k|                    uint64_t *t11 = table + (i + 1U) * 18U;
 1039|  3.99k|                    point_double(t11, tmp);
 1040|  3.99k|                    memcpy(table + (2U * i + 2U) * 18U, tmp, 18U * sizeof(uint64_t));
 1041|  3.99k|                    uint64_t *t2 = table + (2U * i + 2U) * 18U;
 1042|  3.99k|                    point_add(p, t2, tmp);
 1043|  3.99k|                    memcpy(table + (2U * i + 3U) * 18U, tmp, 18U * sizeof(uint64_t)););
 1044|  3.99k|    point_zero(res);
 1045|  3.99k|    uint64_t tmp0[18U] = { 0U };
 1046|   387k|    for (uint32_t i0 = 0U; i0 < 96U; i0++) {
  ------------------
  |  Branch (1046:28): [True: 383k, False: 3.99k]
  ------------------
 1047|   383k|        KRML_MAYBE_FOR4(i, 0U, 4U, 1U, point_double(res, res););
  ------------------
  |  |  330|   383k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|   383k|    do {                               \
  |  |  |  |  289|   383k|        uint32_t i = z;                \
  |  |  |  |  290|   383k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   383k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1048|   383k|        uint32_t k = 384U - 4U * i0 - 4U;
 1049|   383k|        uint64_t bits_l = Hacl_Bignum_Lib_bn_get_bits_u64(6U, scalar, k, 4U);
 1050|   383k|        memcpy(tmp0, (uint64_t *)table, 18U * sizeof(uint64_t));
 1051|   383k|        KRML_MAYBE_FOR15(
  ------------------
  |  |  396|   383k|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|   383k|    do {                               \
  |  |  |  |  289|   383k|        uint32_t i = z;                \
  |  |  |  |  290|   383k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   383k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1052|   383k|            i1,
 1053|   383k|            0U,
 1054|   383k|            15U,
 1055|   383k|            1U,
 1056|   383k|            uint64_t c = FStar_UInt64_eq_mask(bits_l, (uint64_t)(i1 + 1U));
 1057|   383k|            const uint64_t *res_j = table + (i1 + 1U) * 18U;
 1058|   383k|            for (uint32_t i = 0U; i < 18U; i++) {
 1059|   383k|                uint64_t *os = tmp0;
 1060|   383k|                uint64_t x = (c & res_j[i]) | (~c & tmp0[i]);
 1061|   383k|                os[i] = x;
 1062|   383k|            });
 1063|   383k|        point_add(res, tmp0, res);
 1064|   383k|    }
 1065|  3.99k|}
Hacl_P384.c:point_zero:
 1016|  7.99k|{
 1017|  7.99k|    uint64_t *x = one;
 1018|  7.99k|    uint64_t *y = one + 6U;
 1019|  7.99k|    uint64_t *z = one + 12U;
 1020|  7.99k|    p384_make_fzero(x);
 1021|  7.99k|    p384_make_fone(y);
 1022|  7.99k|    p384_make_fzero(z);
 1023|  7.99k|}
Hacl_P384.c:p384_make_fzero:
  417|  15.9k|{
  418|  15.9k|    memset(n, 0U, 6U * sizeof(uint64_t));
  419|  15.9k|    n[0U] = 0ULL;
  420|  15.9k|}
Hacl_P384.c:point_double:
  959|  1.56M|{
  960|  1.56M|    uint64_t tmp[30U] = { 0U };
  961|  1.56M|    uint64_t *x1 = x;
  962|  1.56M|    uint64_t *z = x + 12U;
  963|  1.56M|    uint64_t *x3 = xx;
  964|  1.56M|    uint64_t *y3 = xx + 6U;
  965|  1.56M|    uint64_t *z3 = xx + 12U;
  966|  1.56M|    uint64_t *t0 = tmp;
  967|  1.56M|    uint64_t *t1 = tmp + 6U;
  968|  1.56M|    uint64_t *t2 = tmp + 12U;
  969|  1.56M|    uint64_t *t3 = tmp + 18U;
  970|  1.56M|    uint64_t *t4 = tmp + 24U;
  971|  1.56M|    uint64_t *x2 = x;
  972|  1.56M|    uint64_t *y = x + 6U;
  973|  1.56M|    uint64_t *z1 = x + 12U;
  974|  1.56M|    fsqr0(t0, x2);
  975|  1.56M|    fsqr0(t1, y);
  976|  1.56M|    fsqr0(t2, z1);
  977|  1.56M|    fmul0(t3, x2, y);
  978|  1.56M|    fadd0(t3, t3, t3);
  979|  1.56M|    fmul0(t4, y, z1);
  980|  1.56M|    fmul0(z3, x1, z);
  981|  1.56M|    fadd0(z3, z3, z3);
  982|  1.56M|    uint64_t b_coeff[6U] = { 0U };
  983|  1.56M|    p384_make_b_coeff(b_coeff);
  984|  1.56M|    fmul0(y3, b_coeff, t2);
  985|  1.56M|    fsub0(y3, y3, z3);
  986|  1.56M|    fadd0(x3, y3, y3);
  987|  1.56M|    fadd0(y3, x3, y3);
  988|  1.56M|    fsub0(x3, t1, y3);
  989|  1.56M|    fadd0(y3, t1, y3);
  990|  1.56M|    fmul0(y3, x3, y3);
  991|  1.56M|    fmul0(x3, x3, t3);
  992|  1.56M|    fadd0(t3, t2, t2);
  993|  1.56M|    fadd0(t2, t2, t3);
  994|  1.56M|    uint64_t b_coeff0[6U] = { 0U };
  995|  1.56M|    p384_make_b_coeff(b_coeff0);
  996|  1.56M|    fmul0(z3, b_coeff0, z3);
  997|  1.56M|    fsub0(z3, z3, t2);
  998|  1.56M|    fsub0(z3, z3, t0);
  999|  1.56M|    fadd0(t3, z3, z3);
 1000|  1.56M|    fadd0(z3, z3, t3);
 1001|  1.56M|    fadd0(t3, t0, t0);
 1002|  1.56M|    fadd0(t0, t3, t0);
 1003|  1.56M|    fsub0(t0, t0, t2);
 1004|  1.56M|    fmul0(t0, t0, z3);
 1005|  1.56M|    fadd0(y3, y3, t0);
 1006|  1.56M|    fadd0(t0, t4, t4);
 1007|  1.56M|    fmul0(z3, t0, z3);
 1008|  1.56M|    fsub0(x3, x3, z3);
 1009|  1.56M|    fmul0(z3, t0, t1);
 1010|  1.56M|    fadd0(z3, z3, z3);
 1011|  1.56M|    fadd0(z3, z3, z3);
 1012|  1.56M|}

Hacl_P521_validate_public_key:
 1452|    103|{
 1453|    103|    uint64_t point_jac[27U] = { 0U };
 1454|    103|    uint64_t p_aff[18U] = { 0U };
 1455|    103|    uint8_t *p_x = public_key;
 1456|    103|    uint8_t *p_y = public_key + 66U;
 1457|    103|    uint64_t *bn_p_x = p_aff;
 1458|    103|    uint64_t *bn_p_y = p_aff + 9U;
 1459|    103|    bn_from_bytes_be(bn_p_x, p_x);
 1460|    103|    bn_from_bytes_be(bn_p_y, p_y);
 1461|    103|    uint64_t *px0 = p_aff;
 1462|    103|    uint64_t *py0 = p_aff + 9U;
 1463|    103|    uint64_t lessX = bn_is_lt_prime_mask(px0);
 1464|    103|    uint64_t lessY = bn_is_lt_prime_mask(py0);
 1465|    103|    uint64_t res0 = lessX & lessY;
 1466|    103|    bool is_xy_valid = res0 == 0xFFFFFFFFFFFFFFFFULL;
 1467|    103|    bool res;
 1468|    103|    if (!is_xy_valid) {
  ------------------
  |  Branch (1468:9): [True: 3, False: 100]
  ------------------
 1469|      3|        res = false;
 1470|    100|    } else {
 1471|    100|        uint64_t rp[9U] = { 0U };
 1472|    100|        uint64_t tx[9U] = { 0U };
 1473|    100|        uint64_t ty[9U] = { 0U };
 1474|    100|        uint64_t *px = p_aff;
 1475|    100|        uint64_t *py = p_aff + 9U;
 1476|    100|        to_mont(tx, px);
 1477|    100|        to_mont(ty, py);
 1478|    100|        uint64_t tmp[9U] = { 0U };
 1479|    100|        fsqr0(rp, tx);
 1480|    100|        fmul0(rp, rp, tx);
 1481|    100|        p521_make_a_coeff(tmp);
 1482|    100|        fmul0(tmp, tmp, tx);
 1483|    100|        fadd0(rp, tmp, rp);
 1484|    100|        p521_make_b_coeff(tmp);
 1485|    100|        fadd0(rp, tmp, rp);
 1486|    100|        fsqr0(ty, ty);
 1487|    100|        uint64_t r = bn_is_eq_mask(ty, rp);
 1488|    100|        uint64_t r0 = r;
 1489|    100|        bool r1 = r0 == 0xFFFFFFFFFFFFFFFFULL;
 1490|    100|        res = r1;
 1491|    100|    }
 1492|    103|    if (res) {
  ------------------
  |  Branch (1492:9): [True: 52, False: 51]
  ------------------
 1493|     52|        uint64_t *px = p_aff;
 1494|     52|        uint64_t *py = p_aff + 9U;
 1495|     52|        uint64_t *rx = point_jac;
 1496|     52|        uint64_t *ry = point_jac + 9U;
 1497|     52|        uint64_t *rz = point_jac + 18U;
 1498|     52|        to_mont(rx, px);
 1499|     52|        to_mont(ry, py);
 1500|     52|        p521_make_fone(rz);
 1501|     52|    }
 1502|    103|    bool res1 = res;
 1503|    103|    return res1;
 1504|    103|}
Hacl_P521_validate_private_key:
 1518|     52|{
 1519|     52|    uint64_t bn_sk[9U] = { 0U };
 1520|     52|    bn_from_bytes_be(bn_sk, private_key);
 1521|     52|    uint64_t tmp[9U] = { 0U };
 1522|     52|    p521_make_order(tmp);
 1523|     52|    uint64_t c = bn_sub(tmp, bn_sk, tmp);
 1524|     52|    uint64_t is_lt_order = FStar_UInt64_gte_mask(c, 0ULL) & ~FStar_UInt64_eq_mask(c, 0ULL);
 1525|     52|    uint64_t bn_zero[9U] = { 0U };
 1526|     52|    uint64_t res = bn_is_eq_mask(bn_sk, bn_zero);
 1527|     52|    uint64_t is_eq_zero = res;
 1528|     52|    uint64_t res0 = is_lt_order & ~is_eq_zero;
 1529|     52|    return res0 == 0xFFFFFFFFFFFFFFFFULL;
 1530|     52|}
Hacl_P521_dh_initiator:
 1686|     52|{
 1687|     52|    uint64_t tmp[36U] = { 0U };
 1688|     52|    uint64_t *sk = tmp;
 1689|     52|    uint64_t *pk = tmp + 9U;
 1690|     52|    uint64_t is_sk_valid = load_qelem_conditional(sk, private_key);
 1691|     52|    point_mul_g(pk, sk);
 1692|     52|    uint64_t aff_p[18U] = { 0U };
 1693|     52|    uint64_t zinv[9U] = { 0U };
 1694|     52|    uint64_t *px = pk;
 1695|     52|    uint64_t *py0 = pk + 9U;
 1696|     52|    uint64_t *pz = pk + 18U;
 1697|     52|    uint64_t *x = aff_p;
 1698|     52|    uint64_t *y = aff_p + 9U;
 1699|     52|    p521_finv(zinv, pz);
 1700|     52|    fmul0(x, px, zinv);
 1701|     52|    fmul0(y, py0, zinv);
 1702|     52|    from_mont(x, x);
 1703|     52|    from_mont(y, y);
 1704|     52|    uint64_t *px0 = aff_p;
 1705|     52|    uint64_t *py = aff_p + 9U;
 1706|     52|    bn_to_bytes_be(public_key, px0);
 1707|     52|    bn_to_bytes_be(public_key + 66U, py);
 1708|     52|    return is_sk_valid == 0xFFFFFFFFFFFFFFFFULL;
 1709|     52|}
Hacl_P521.c:bn_from_bytes_be:
  327|    310|{
  328|    310|    uint8_t tmp[72U] = { 0U };
  329|    310|    memcpy(tmp + 6U, b, 66U * sizeof(uint8_t));
  330|    310|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|    310|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|    310|    do {                               \
  |  |  |  |  289|    310|        uint32_t i = z;                \
  |  |  |  |  290|    310|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    310|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  331|    310|                    0U,
  332|    310|                    9U,
  333|    310|                    1U,
  334|    310|                    uint64_t *os = a;
  335|    310|                    uint64_t u = load64_be(tmp + (9U - i - 1U) * 8U);
  336|    310|                    uint64_t x = u;
  337|    310|                    os[i] = x;);
  338|    310|}
Hacl_P521.c:bn_sqr:
  271|   110k|{
  272|   110k|    memset(a, 0U, 18U * sizeof(uint64_t));
  273|   110k|    KRML_MAYBE_FOR9(
  ------------------
  |  |  360|   110k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   110k|    do {                               \
  |  |  |  |  289|   110k|        uint32_t i = z;                \
  |  |  |  |  290|   110k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   110k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  274|   110k|        i0,
  275|   110k|        0U,
  276|   110k|        9U,
  277|   110k|        1U,
  278|   110k|        uint64_t *ab = b;
  279|   110k|        uint64_t a_j = b[i0];
  280|   110k|        uint64_t *res_j = a + i0;
  281|   110k|        uint64_t c = 0ULL;
  282|   110k|        for (uint32_t i = 0U; i < i0 / 4U; i++) {
  283|   110k|            uint64_t a_i = ab[4U * i];
  284|   110k|            uint64_t *res_i0 = res_j + 4U * i;
  285|   110k|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, a_j, c, res_i0);
  286|   110k|            uint64_t a_i0 = ab[4U * i + 1U];
  287|   110k|            uint64_t *res_i1 = res_j + 4U * i + 1U;
  288|   110k|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, a_j, c, res_i1);
  289|   110k|            uint64_t a_i1 = ab[4U * i + 2U];
  290|   110k|            uint64_t *res_i2 = res_j + 4U * i + 2U;
  291|   110k|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, a_j, c, res_i2);
  292|   110k|            uint64_t a_i2 = ab[4U * i + 3U];
  293|   110k|            uint64_t *res_i = res_j + 4U * i + 3U;
  294|   110k|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, a_j, c, res_i);
  295|   110k|        } for (uint32_t i = i0 / 4U * 4U; i < i0; i++) {
  296|   110k|            uint64_t a_i = ab[i];
  297|   110k|            uint64_t *res_i = res_j + i;
  298|   110k|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, a_j, c, res_i);
  299|   110k|        } uint64_t r = c;
  300|   110k|        a[i0 + i0] = r;);
  301|   110k|    uint64_t c0 = Hacl_Bignum_Addition_bn_add_eq_len_u64(18U, a, a, a);
  302|   110k|    KRML_MAYBE_UNUSED_VAR(c0);
  ------------------
  |  |   60|   110k|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|   110k|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  303|   110k|    uint64_t tmp[18U] = { 0U };
  304|   110k|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|   110k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   110k|    do {                               \
  |  |  |  |  289|   110k|        uint32_t i = z;                \
  |  |  |  |  290|   110k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   110k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  305|   110k|                    0U,
  306|   110k|                    9U,
  307|   110k|                    1U,
  308|   110k|                    FStar_UInt128_uint128 res = FStar_UInt128_mul_wide(b[i], b[i]);
  309|   110k|                    uint64_t hi = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(res, 64U));
  310|   110k|                    uint64_t lo = FStar_UInt128_uint128_to_uint64(res);
  311|   110k|                    tmp[2U * i] = lo;
  312|   110k|                    tmp[2U * i + 1U] = hi;);
  313|   110k|    uint64_t c1 = Hacl_Bignum_Addition_bn_add_eq_len_u64(18U, a, tmp, a);
  314|   110k|    KRML_MAYBE_UNUSED_VAR(c1);
  ------------------
  |  |   60|   110k|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|   110k|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  315|   110k|}
Hacl_P521.c:bn_mul:
  235|   380k|{
  236|   380k|    memset(a, 0U, 18U * sizeof(uint64_t));
  237|   380k|    KRML_MAYBE_FOR9(
  ------------------
  |  |  360|   380k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   380k|    do {                               \
  |  |  |  |  289|   380k|        uint32_t i = z;                \
  |  |  |  |  290|   380k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   380k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  238|   380k|        i0,
  239|   380k|        0U,
  240|   380k|        9U,
  241|   380k|        1U,
  242|   380k|        uint64_t bj = c[i0];
  243|   380k|        uint64_t *res_j = a + i0;
  244|   380k|        uint64_t c1 = 0ULL;
  245|   380k|        KRML_MAYBE_FOR2(i,
  246|   380k|                        0U,
  247|   380k|                        2U,
  248|   380k|                        1U,
  249|   380k|                        uint64_t a_i = b[4U * i];
  250|   380k|                        uint64_t *res_i0 = res_j + 4U * i;
  251|   380k|                        c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, bj, c1, res_i0);
  252|   380k|                        uint64_t a_i0 = b[4U * i + 1U];
  253|   380k|                        uint64_t *res_i1 = res_j + 4U * i + 1U;
  254|   380k|                        c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, bj, c1, res_i1);
  255|   380k|                        uint64_t a_i1 = b[4U * i + 2U];
  256|   380k|                        uint64_t *res_i2 = res_j + 4U * i + 2U;
  257|   380k|                        c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, bj, c1, res_i2);
  258|   380k|                        uint64_t a_i2 = b[4U * i + 3U];
  259|   380k|                        uint64_t *res_i = res_j + 4U * i + 3U;
  260|   380k|                        c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, bj, c1, res_i););
  261|   380k|        {
  262|   380k|            uint64_t a_i = b[8U];
  263|   380k|            uint64_t *res_i = res_j + 8U;
  264|   380k|            c1 = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, bj, c1, res_i);
  265|   380k|        } uint64_t r = c1;
  266|   380k|        a[9U + i0] = r;);
  267|   380k|}
Hacl_P521.c:bn_add_mod:
   60|   553k|{
   61|   553k|    uint64_t c10 = 0ULL;
   62|   553k|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|   553k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|   553k|    do {                               \
  |  |  |  |  289|   553k|        uint32_t i = z;                \
  |  |  |  |  290|   553k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   553k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   63|   553k|                    0U,
   64|   553k|                    2U,
   65|   553k|                    1U,
   66|   553k|                    uint64_t t1 = c[4U * i];
   67|   553k|                    uint64_t t20 = d[4U * i];
   68|   553k|                    uint64_t *res_i0 = a + 4U * i;
   69|   553k|                    c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t1, t20, res_i0);
   70|   553k|                    uint64_t t10 = c[4U * i + 1U];
   71|   553k|                    uint64_t t21 = d[4U * i + 1U];
   72|   553k|                    uint64_t *res_i1 = a + 4U * i + 1U;
   73|   553k|                    c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t10, t21, res_i1);
   74|   553k|                    uint64_t t11 = c[4U * i + 2U];
   75|   553k|                    uint64_t t22 = d[4U * i + 2U];
   76|   553k|                    uint64_t *res_i2 = a + 4U * i + 2U;
   77|   553k|                    c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t11, t22, res_i2);
   78|   553k|                    uint64_t t12 = c[4U * i + 3U];
   79|   553k|                    uint64_t t2 = d[4U * i + 3U];
   80|   553k|                    uint64_t *res_i = a + 4U * i + 3U;
   81|   553k|                    c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t12, t2, res_i););
   82|   553k|    {
   83|   553k|        uint64_t t1 = c[8U];
   84|   553k|        uint64_t t2 = d[8U];
   85|   553k|        uint64_t *res_i = a + 8U;
   86|   553k|        c10 = Lib_IntTypes_Intrinsics_add_carry_u64(c10, t1, t2, res_i);
  ------------------
  |  |   66|   553k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
   87|   553k|    }
   88|   553k|    uint64_t c0 = c10;
   89|   553k|    uint64_t tmp[9U] = { 0U };
   90|   553k|    uint64_t c1 = 0ULL;
   91|   553k|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|   553k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|   553k|    do {                               \
  |  |  |  |  289|   553k|        uint32_t i = z;                \
  |  |  |  |  290|   553k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   553k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   92|   553k|                    0U,
   93|   553k|                    2U,
   94|   553k|                    1U,
   95|   553k|                    uint64_t t1 = a[4U * i];
   96|   553k|                    uint64_t t20 = b[4U * i];
   97|   553k|                    uint64_t *res_i0 = tmp + 4U * i;
   98|   553k|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t20, res_i0);
   99|   553k|                    uint64_t t10 = a[4U * i + 1U];
  100|   553k|                    uint64_t t21 = b[4U * i + 1U];
  101|   553k|                    uint64_t *res_i1 = tmp + 4U * i + 1U;
  102|   553k|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t10, t21, res_i1);
  103|   553k|                    uint64_t t11 = a[4U * i + 2U];
  104|   553k|                    uint64_t t22 = b[4U * i + 2U];
  105|   553k|                    uint64_t *res_i2 = tmp + 4U * i + 2U;
  106|   553k|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t11, t22, res_i2);
  107|   553k|                    uint64_t t12 = a[4U * i + 3U];
  108|   553k|                    uint64_t t2 = b[4U * i + 3U];
  109|   553k|                    uint64_t *res_i = tmp + 4U * i + 3U;
  110|   553k|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t12, t2, res_i););
  111|   553k|    {
  112|   553k|        uint64_t t1 = a[8U];
  113|   553k|        uint64_t t2 = b[8U];
  114|   553k|        uint64_t *res_i = tmp + 8U;
  115|   553k|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t2, res_i);
  ------------------
  |  |   89|   553k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  116|   553k|    }
  117|   553k|    uint64_t c11 = c1;
  118|   553k|    uint64_t c2 = c0 - c11;
  119|   553k|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|   553k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   553k|    do {                               \
  |  |  |  |  289|   553k|        uint32_t i = z;                \
  |  |  |  |  290|   553k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   553k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  120|   553k|                    0U,
  121|   553k|                    9U,
  122|   553k|                    1U,
  123|   553k|                    uint64_t *os = a;
  124|   553k|                    uint64_t x = (c2 & a[i]) | (~c2 & tmp[i]);
  125|   553k|                    os[i] = x;);
  126|   553k|}
Hacl_P521.c:point_add:
  960|  7.12k|{
  961|  7.12k|    uint64_t tmp[81U] = { 0U };
  962|  7.12k|    uint64_t *t0 = tmp;
  963|  7.12k|    uint64_t *t1 = tmp + 54U;
  964|  7.12k|    uint64_t *x3 = t1;
  965|  7.12k|    uint64_t *y3 = t1 + 9U;
  966|  7.12k|    uint64_t *z3 = t1 + 18U;
  967|  7.12k|    uint64_t *t01 = t0;
  968|  7.12k|    uint64_t *t11 = t0 + 9U;
  969|  7.12k|    uint64_t *t2 = t0 + 18U;
  970|  7.12k|    uint64_t *t3 = t0 + 27U;
  971|  7.12k|    uint64_t *t4 = t0 + 36U;
  972|  7.12k|    uint64_t *t5 = t0 + 45U;
  973|  7.12k|    uint64_t *x1 = x;
  974|  7.12k|    uint64_t *y1 = x + 9U;
  975|  7.12k|    uint64_t *z10 = x + 18U;
  976|  7.12k|    uint64_t *x20 = y;
  977|  7.12k|    uint64_t *y20 = y + 9U;
  978|  7.12k|    uint64_t *z20 = y + 18U;
  979|  7.12k|    fmul0(t01, x1, x20);
  980|  7.12k|    fmul0(t11, y1, y20);
  981|  7.12k|    fmul0(t2, z10, z20);
  982|  7.12k|    fadd0(t3, x1, y1);
  983|  7.12k|    fadd0(t4, x20, y20);
  984|  7.12k|    fmul0(t3, t3, t4);
  985|  7.12k|    fadd0(t4, t01, t11);
  986|  7.12k|    uint64_t *y10 = x + 9U;
  987|  7.12k|    uint64_t *z11 = x + 18U;
  988|  7.12k|    uint64_t *y2 = y + 9U;
  989|  7.12k|    uint64_t *z21 = y + 18U;
  990|  7.12k|    fsub0(t3, t3, t4);
  991|  7.12k|    fadd0(t4, y10, z11);
  992|  7.12k|    fadd0(t5, y2, z21);
  993|  7.12k|    fmul0(t4, t4, t5);
  994|  7.12k|    fadd0(t5, t11, t2);
  995|  7.12k|    fsub0(t4, t4, t5);
  996|  7.12k|    uint64_t *x10 = x;
  997|  7.12k|    uint64_t *z1 = x + 18U;
  998|  7.12k|    uint64_t *x2 = y;
  999|  7.12k|    uint64_t *z2 = y + 18U;
 1000|  7.12k|    fadd0(x3, x10, z1);
 1001|  7.12k|    fadd0(y3, x2, z2);
 1002|  7.12k|    fmul0(x3, x3, y3);
 1003|  7.12k|    fadd0(y3, t01, t2);
 1004|  7.12k|    fsub0(y3, x3, y3);
 1005|  7.12k|    uint64_t b_coeff[9U] = { 0U };
 1006|  7.12k|    p521_make_b_coeff(b_coeff);
 1007|  7.12k|    fmul0(z3, b_coeff, t2);
 1008|  7.12k|    fsub0(x3, y3, z3);
 1009|  7.12k|    fadd0(z3, x3, x3);
 1010|  7.12k|    fadd0(x3, x3, z3);
 1011|  7.12k|    fsub0(z3, t11, x3);
 1012|  7.12k|    fadd0(x3, t11, x3);
 1013|  7.12k|    uint64_t b_coeff0[9U] = { 0U };
 1014|  7.12k|    p521_make_b_coeff(b_coeff0);
 1015|  7.12k|    fmul0(y3, b_coeff0, y3);
 1016|  7.12k|    fadd0(t11, t2, t2);
 1017|  7.12k|    fadd0(t2, t11, t2);
 1018|  7.12k|    fsub0(y3, y3, t2);
 1019|  7.12k|    fsub0(y3, y3, t01);
 1020|  7.12k|    fadd0(t11, y3, y3);
 1021|  7.12k|    fadd0(y3, t11, y3);
 1022|  7.12k|    fadd0(t11, t01, t01);
 1023|  7.12k|    fadd0(t01, t11, t01);
 1024|  7.12k|    fsub0(t01, t01, t2);
 1025|  7.12k|    fmul0(t11, t4, y3);
 1026|  7.12k|    fmul0(t2, t01, y3);
 1027|  7.12k|    fmul0(y3, x3, z3);
 1028|  7.12k|    fadd0(y3, y3, t2);
 1029|  7.12k|    fmul0(x3, t3, x3);
 1030|  7.12k|    fsub0(x3, x3, t11);
 1031|  7.12k|    fmul0(z3, t4, z3);
 1032|  7.12k|    fmul0(t11, t3, t01);
 1033|  7.12k|    fadd0(z3, z3, t11);
 1034|  7.12k|    memcpy(xy, t1, 27U * sizeof(uint64_t));
 1035|  7.12k|}
Hacl_P521.c:bn_is_lt_prime_mask:
  635|    206|{
  636|    206|    uint64_t tmp[9U] = { 0U };
  637|    206|    p521_make_prime(tmp);
  638|    206|    uint64_t c = bn_sub(tmp, f, tmp);
  639|    206|    uint64_t m = FStar_UInt64_gte_mask(c, 0ULL) & ~FStar_UInt64_eq_mask(c, 0ULL);
  640|    206|    return m;
  641|    206|}
Hacl_P521.c:p521_make_prime:
  342|  1.27M|{
  343|  1.27M|    n[0U] = 0xffffffffffffffffULL;
  344|  1.27M|    n[1U] = 0xffffffffffffffffULL;
  345|  1.27M|    n[2U] = 0xffffffffffffffffULL;
  346|  1.27M|    n[3U] = 0xffffffffffffffffULL;
  347|  1.27M|    n[4U] = 0xffffffffffffffffULL;
  348|  1.27M|    n[5U] = 0xffffffffffffffffULL;
  349|  1.27M|    n[6U] = 0xffffffffffffffffULL;
  350|  1.27M|    n[7U] = 0xffffffffffffffffULL;
  351|  1.27M|    n[8U] = 0x1ffULL;
  352|  1.27M|}
Hacl_P521.c:to_mont:
  685|    304|{
  686|    304|    uint64_t r2modn[9U] = { 0U };
  687|    304|    p521_make_fmont_R2(r2modn);
  688|    304|    uint64_t tmp[18U] = { 0U };
  689|    304|    bn_mul(tmp, b, r2modn);
  690|    304|    fmont_reduction(a, tmp);
  691|    304|}
Hacl_P521.c:p521_make_fmont_R2:
  426|    304|{
  427|    304|    n[0U] = 0x0ULL;
  428|    304|    n[1U] = 0x400000000000ULL;
  429|    304|    n[2U] = 0x0ULL;
  430|    304|    n[3U] = 0x0ULL;
  431|    304|    n[4U] = 0x0ULL;
  432|    304|    n[5U] = 0x0ULL;
  433|    304|    n[6U] = 0x0ULL;
  434|    304|    n[7U] = 0x0ULL;
  435|    304|    n[8U] = 0x0ULL;
  436|    304|}
Hacl_P521.c:fmont_reduction:
  475|   490k|{
  476|   490k|    uint64_t n[9U] = { 0U };
  477|   490k|    p521_make_prime(n);
  478|   490k|    uint64_t c0 = 0ULL;
  479|   490k|    KRML_MAYBE_FOR9(
  ------------------
  |  |  360|   490k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   490k|    do {                               \
  |  |  |  |  289|   490k|        uint32_t i = z;                \
  |  |  |  |  290|   490k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   490k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  480|   490k|        i0,
  481|   490k|        0U,
  482|   490k|        9U,
  483|   490k|        1U,
  484|   490k|        uint64_t qj = 1ULL * x[i0];
  485|   490k|        uint64_t *res_j0 = x + i0;
  486|   490k|        uint64_t c = 0ULL;
  487|   490k|        KRML_MAYBE_FOR2(i,
  488|   490k|                        0U,
  489|   490k|                        2U,
  490|   490k|                        1U,
  491|   490k|                        uint64_t a_i = n[4U * i];
  492|   490k|                        uint64_t *res_i0 = res_j0 + 4U * i;
  493|   490k|                        c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, qj, c, res_i0);
  494|   490k|                        uint64_t a_i0 = n[4U * i + 1U];
  495|   490k|                        uint64_t *res_i1 = res_j0 + 4U * i + 1U;
  496|   490k|                        c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i0, qj, c, res_i1);
  497|   490k|                        uint64_t a_i1 = n[4U * i + 2U];
  498|   490k|                        uint64_t *res_i2 = res_j0 + 4U * i + 2U;
  499|   490k|                        c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i1, qj, c, res_i2);
  500|   490k|                        uint64_t a_i2 = n[4U * i + 3U];
  501|   490k|                        uint64_t *res_i = res_j0 + 4U * i + 3U;
  502|   490k|                        c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i2, qj, c, res_i););
  503|   490k|        {
  504|   490k|            uint64_t a_i = n[8U];
  505|   490k|            uint64_t *res_i = res_j0 + 8U;
  506|   490k|            c = Hacl_Bignum_Base_mul_wide_add2_u64(a_i, qj, c, res_i);
  507|   490k|        } uint64_t r = c;
  508|   490k|        uint64_t c1 = r;
  509|   490k|        uint64_t *resb = x + 9U + i0;
  510|   490k|        uint64_t res_j = x[9U + i0];
  511|   490k|        c0 = Lib_IntTypes_Intrinsics_add_carry_u64(c0, c1, res_j, resb););
  512|   490k|    memcpy(res, x + 9U, 9U * sizeof(uint64_t));
  513|   490k|    uint64_t c00 = c0;
  514|   490k|    uint64_t tmp[9U] = { 0U };
  515|   490k|    uint64_t c = 0ULL;
  516|   490k|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|   490k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|   490k|    do {                               \
  |  |  |  |  289|   490k|        uint32_t i = z;                \
  |  |  |  |  290|   490k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   490k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  517|   490k|                    0U,
  518|   490k|                    2U,
  519|   490k|                    1U,
  520|   490k|                    uint64_t t1 = res[4U * i];
  521|   490k|                    uint64_t t20 = n[4U * i];
  522|   490k|                    uint64_t *res_i0 = tmp + 4U * i;
  523|   490k|                    c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t20, res_i0);
  524|   490k|                    uint64_t t10 = res[4U * i + 1U];
  525|   490k|                    uint64_t t21 = n[4U * i + 1U];
  526|   490k|                    uint64_t *res_i1 = tmp + 4U * i + 1U;
  527|   490k|                    c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t10, t21, res_i1);
  528|   490k|                    uint64_t t11 = res[4U * i + 2U];
  529|   490k|                    uint64_t t22 = n[4U * i + 2U];
  530|   490k|                    uint64_t *res_i2 = tmp + 4U * i + 2U;
  531|   490k|                    c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t11, t22, res_i2);
  532|   490k|                    uint64_t t12 = res[4U * i + 3U];
  533|   490k|                    uint64_t t2 = n[4U * i + 3U];
  534|   490k|                    uint64_t *res_i = tmp + 4U * i + 3U;
  535|   490k|                    c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t12, t2, res_i););
  536|   490k|    {
  537|   490k|        uint64_t t1 = res[8U];
  538|   490k|        uint64_t t2 = n[8U];
  539|   490k|        uint64_t *res_i = tmp + 8U;
  540|   490k|        c = Lib_IntTypes_Intrinsics_sub_borrow_u64(c, t1, t2, res_i);
  ------------------
  |  |   89|   490k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  541|   490k|    }
  542|   490k|    uint64_t c1 = c;
  543|   490k|    uint64_t c2 = c00 - c1;
  544|   490k|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|   490k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   490k|    do {                               \
  |  |  |  |  289|   490k|        uint32_t i = z;                \
  |  |  |  |  290|   490k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   490k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  545|   490k|                    0U,
  546|   490k|                    9U,
  547|   490k|                    1U,
  548|   490k|                    uint64_t *os = res;
  549|   490k|                    uint64_t x1 = (c2 & res[i]) | (~c2 & tmp[i]);
  550|   490k|                    os[i] = x1;);
  551|   490k|}
Hacl_P521.c:fsqr0:
  669|   110k|{
  670|   110k|    uint64_t tmp[18U] = { 0U };
  671|   110k|    bn_sqr(tmp, b);
  672|   110k|    fmont_reduction(a, tmp);
  673|   110k|}
Hacl_P521.c:fmul0:
  661|   380k|{
  662|   380k|    uint64_t tmp[18U] = { 0U };
  663|   380k|    bn_mul(tmp, b, c);
  664|   380k|    fmont_reduction(a, tmp);
  665|   380k|}
Hacl_P521.c:p521_make_a_coeff:
  370|    100|{
  371|    100|    a[0U] = 0xfe7fffffffffffffULL;
  372|    100|    a[1U] = 0xffffffffffffffffULL;
  373|    100|    a[2U] = 0xffffffffffffffffULL;
  374|    100|    a[3U] = 0xffffffffffffffffULL;
  375|    100|    a[4U] = 0xffffffffffffffffULL;
  376|    100|    a[5U] = 0xffffffffffffffffULL;
  377|    100|    a[6U] = 0xffffffffffffffffULL;
  378|    100|    a[7U] = 0xffffffffffffffffULL;
  379|    100|    a[8U] = 0x01ffULL;
  380|    100|}
Hacl_P521.c:fadd0:
  645|   553k|{
  646|   553k|    uint64_t n[9U] = { 0U };
  647|   553k|    p521_make_prime(n);
  648|   553k|    bn_add_mod(a, n, b, c);
  649|   553k|}
Hacl_P521.c:p521_make_b_coeff:
  384|  69.1k|{
  385|  69.1k|    b[0U] = 0x8014654fae586387ULL;
  386|  69.1k|    b[1U] = 0x78f7a28fea35a81fULL;
  387|  69.1k|    b[2U] = 0x839ab9efc41e961aULL;
  388|  69.1k|    b[3U] = 0xbd8b29605e9dd8dfULL;
  389|  69.1k|    b[4U] = 0xf0ab0c9ca8f63f49ULL;
  390|  69.1k|    b[5U] = 0xf9dc5a44c8c77884ULL;
  391|  69.1k|    b[6U] = 0x77516d392dccd98aULL;
  392|  69.1k|    b[7U] = 0x0fc94d10d05b42a0ULL;
  393|  69.1k|    b[8U] = 0x4dULL;
  394|  69.1k|}
Hacl_P521.c:bn_is_eq_mask:
   32|    204|{
   33|    204|    uint64_t mask = 0xFFFFFFFFFFFFFFFFULL;
   34|    204|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|    204|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|    204|    do {                               \
  |  |  |  |  289|    204|        uint32_t i = z;                \
  |  |  |  |  290|    204|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    204|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   35|    204|                    0U,
   36|    204|                    9U,
   37|    204|                    1U,
   38|    204|                    uint64_t uu____0 = FStar_UInt64_eq_mask(x[i], y[i]);
   39|    204|                    mask = uu____0 & mask;);
   40|    204|    uint64_t mask1 = mask;
   41|    204|    return mask1;
   42|    204|}
Hacl_P521.c:p521_make_fone:
  447|    208|{
  448|    208|    n[0U] = 0x80000000000000ULL;
  449|    208|    n[1U] = 0x0ULL;
  450|    208|    n[2U] = 0x0ULL;
  451|    208|    n[3U] = 0x0ULL;
  452|    208|    n[4U] = 0x0ULL;
  453|    208|    n[5U] = 0x0ULL;
  454|    208|    n[6U] = 0x0ULL;
  455|    208|    n[7U] = 0x0ULL;
  456|    208|    n[8U] = 0x0ULL;
  457|    208|}
Hacl_P521.c:p521_make_order:
  356|    104|{
  357|    104|    n[0U] = 0xbb6fb71e91386409ULL;
  358|    104|    n[1U] = 0x3bb5c9b8899c47aeULL;
  359|    104|    n[2U] = 0x7fcc0148f709a5d0ULL;
  360|    104|    n[3U] = 0x51868783bf2f966bULL;
  361|    104|    n[4U] = 0xfffffffffffffffaULL;
  362|    104|    n[5U] = 0xffffffffffffffffULL;
  363|    104|    n[6U] = 0xffffffffffffffffULL;
  364|    104|    n[7U] = 0xffffffffffffffffULL;
  365|    104|    n[8U] = 0x1ffULL;
  366|    104|}
Hacl_P521.c:bn_sub:
  130|    310|{
  131|    310|    uint64_t c1 = 0ULL;
  132|    310|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|    310|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|    310|    do {                               \
  |  |  |  |  289|    310|        uint32_t i = z;                \
  |  |  |  |  290|    310|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    310|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  133|    310|                    0U,
  134|    310|                    2U,
  135|    310|                    1U,
  136|    310|                    uint64_t t1 = b[4U * i];
  137|    310|                    uint64_t t20 = c[4U * i];
  138|    310|                    uint64_t *res_i0 = a + 4U * i;
  139|    310|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t20, res_i0);
  140|    310|                    uint64_t t10 = b[4U * i + 1U];
  141|    310|                    uint64_t t21 = c[4U * i + 1U];
  142|    310|                    uint64_t *res_i1 = a + 4U * i + 1U;
  143|    310|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t10, t21, res_i1);
  144|    310|                    uint64_t t11 = b[4U * i + 2U];
  145|    310|                    uint64_t t22 = c[4U * i + 2U];
  146|    310|                    uint64_t *res_i2 = a + 4U * i + 2U;
  147|    310|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t11, t22, res_i2);
  148|    310|                    uint64_t t12 = b[4U * i + 3U];
  149|    310|                    uint64_t t2 = c[4U * i + 3U];
  150|    310|                    uint64_t *res_i = a + 4U * i + 3U;
  151|    310|                    c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t12, t2, res_i););
  152|    310|    {
  153|    310|        uint64_t t1 = b[8U];
  154|    310|        uint64_t t2 = c[8U];
  155|    310|        uint64_t *res_i = a + 8U;
  156|    310|        c1 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c1, t1, t2, res_i);
  ------------------
  |  |   89|    310|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  157|    310|    }
  158|    310|    uint64_t c10 = c1;
  159|    310|    return c10;
  160|    310|}
Hacl_P521.c:from_mont:
  677|    104|{
  678|    104|    uint64_t tmp[18U] = { 0U };
  679|    104|    memcpy(tmp, b, 9U * sizeof(uint64_t));
  680|    104|    fmont_reduction(a, tmp);
  681|    104|}
Hacl_P521.c:fsub0:
  653|   228k|{
  654|   228k|    uint64_t n[9U] = { 0U };
  655|   228k|    p521_make_prime(n);
  656|   228k|    bn_sub_mod(a, n, b, c);
  657|   228k|}
Hacl_P521.c:bn_sub_mod:
  164|   228k|{
  165|   228k|    uint64_t c10 = 0ULL;
  166|   228k|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|   228k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|   228k|    do {                               \
  |  |  |  |  289|   228k|        uint32_t i = z;                \
  |  |  |  |  290|   228k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   228k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  167|   228k|                    0U,
  168|   228k|                    2U,
  169|   228k|                    1U,
  170|   228k|                    uint64_t t1 = c[4U * i];
  171|   228k|                    uint64_t t20 = d[4U * i];
  172|   228k|                    uint64_t *res_i0 = a + 4U * i;
  173|   228k|                    c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t1, t20, res_i0);
  174|   228k|                    uint64_t t10 = c[4U * i + 1U];
  175|   228k|                    uint64_t t21 = d[4U * i + 1U];
  176|   228k|                    uint64_t *res_i1 = a + 4U * i + 1U;
  177|   228k|                    c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t10, t21, res_i1);
  178|   228k|                    uint64_t t11 = c[4U * i + 2U];
  179|   228k|                    uint64_t t22 = d[4U * i + 2U];
  180|   228k|                    uint64_t *res_i2 = a + 4U * i + 2U;
  181|   228k|                    c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t11, t22, res_i2);
  182|   228k|                    uint64_t t12 = c[4U * i + 3U];
  183|   228k|                    uint64_t t2 = d[4U * i + 3U];
  184|   228k|                    uint64_t *res_i = a + 4U * i + 3U;
  185|   228k|                    c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t12, t2, res_i););
  186|   228k|    {
  187|   228k|        uint64_t t1 = c[8U];
  188|   228k|        uint64_t t2 = d[8U];
  189|   228k|        uint64_t *res_i = a + 8U;
  190|   228k|        c10 = Lib_IntTypes_Intrinsics_sub_borrow_u64(c10, t1, t2, res_i);
  ------------------
  |  |   89|   228k|    (_subborrow_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  191|   228k|    }
  192|   228k|    uint64_t c0 = c10;
  193|   228k|    uint64_t tmp[9U] = { 0U };
  194|   228k|    uint64_t c1 = 0ULL;
  195|   228k|    KRML_MAYBE_FOR2(i,
  ------------------
  |  |  318|   228k|#define KRML_MAYBE_FOR2(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 2, k, x)
  |  |  ------------------
  |  |  |  |  288|   228k|    do {                               \
  |  |  |  |  289|   228k|        uint32_t i = z;                \
  |  |  |  |  290|   228k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   228k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  196|   228k|                    0U,
  197|   228k|                    2U,
  198|   228k|                    1U,
  199|   228k|                    uint64_t t1 = a[4U * i];
  200|   228k|                    uint64_t t20 = b[4U * i];
  201|   228k|                    uint64_t *res_i0 = tmp + 4U * i;
  202|   228k|                    c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t1, t20, res_i0);
  203|   228k|                    uint64_t t10 = a[4U * i + 1U];
  204|   228k|                    uint64_t t21 = b[4U * i + 1U];
  205|   228k|                    uint64_t *res_i1 = tmp + 4U * i + 1U;
  206|   228k|                    c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t10, t21, res_i1);
  207|   228k|                    uint64_t t11 = a[4U * i + 2U];
  208|   228k|                    uint64_t t22 = b[4U * i + 2U];
  209|   228k|                    uint64_t *res_i2 = tmp + 4U * i + 2U;
  210|   228k|                    c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t11, t22, res_i2);
  211|   228k|                    uint64_t t12 = a[4U * i + 3U];
  212|   228k|                    uint64_t t2 = b[4U * i + 3U];
  213|   228k|                    uint64_t *res_i = tmp + 4U * i + 3U;
  214|   228k|                    c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t12, t2, res_i););
  215|   228k|    {
  216|   228k|        uint64_t t1 = a[8U];
  217|   228k|        uint64_t t2 = b[8U];
  218|   228k|        uint64_t *res_i = tmp + 8U;
  219|   228k|        c1 = Lib_IntTypes_Intrinsics_add_carry_u64(c1, t1, t2, res_i);
  ------------------
  |  |   66|   228k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  220|   228k|    }
  221|   228k|    uint64_t c11 = c1;
  222|   228k|    KRML_MAYBE_UNUSED_VAR(c11);
  ------------------
  |  |   60|   228k|#define KRML_MAYBE_UNUSED_VAR(x) KRML_HOST_IGNORE(x)
  |  |  ------------------
  |  |  |  |   56|   228k|#define KRML_HOST_IGNORE(x) (void)(x)
  |  |  ------------------
  ------------------
  223|   228k|    uint64_t c2 = 0ULL - c0;
  224|   228k|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|   228k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   228k|    do {                               \
  |  |  |  |  289|   228k|        uint32_t i = z;                \
  |  |  |  |  290|   228k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   228k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  225|   228k|                    0U,
  226|   228k|                    9U,
  227|   228k|                    1U,
  228|   228k|                    uint64_t *os = a;
  229|   228k|                    uint64_t x = (c2 & tmp[i]) | (~c2 & a[i]);
  230|   228k|                    os[i] = x;);
  231|   228k|}
Hacl_P521.c:bn_to_bytes_be:
  319|    104|{
  320|    104|    uint8_t tmp[72U] = { 0U };
  321|    104|    KRML_MAYBE_FOR9(i, 0U, 9U, 1U, store64_be(tmp + i * 8U, b[9U - i - 1U]););
  ------------------
  |  |  360|    104|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|    104|    do {                               \
  |  |  |  |  289|    104|        uint32_t i = z;                \
  |  |  |  |  290|    104|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    104|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  322|    104|    memcpy(a, tmp + 6U, 66U * sizeof(uint8_t));
  323|    104|}
Hacl_P521.c:load_qelem_conditional:
  827|     52|{
  828|     52|    bn_from_bytes_be(a, b);
  829|     52|    uint64_t tmp[9U] = { 0U };
  830|     52|    p521_make_order(tmp);
  831|     52|    uint64_t c = bn_sub(tmp, a, tmp);
  832|     52|    uint64_t is_lt_order = FStar_UInt64_gte_mask(c, 0ULL) & ~FStar_UInt64_eq_mask(c, 0ULL);
  833|     52|    uint64_t bn_zero[9U] = { 0U };
  834|     52|    uint64_t res = bn_is_eq_mask(a, bn_zero);
  835|     52|    uint64_t is_eq_zero = res;
  836|     52|    uint64_t is_b_valid = is_lt_order & ~is_eq_zero;
  837|     52|    uint64_t oneq[9U] = { 0U };
  838|     52|    memset(oneq, 0U, 9U * sizeof(uint64_t));
  839|     52|    oneq[0U] = 1ULL;
  840|     52|    KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|     52|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|     52|    do {                               \
  |  |  |  |  289|     52|        uint32_t i = z;                \
  |  |  |  |  290|     52|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     52|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  841|     52|                    0U,
  842|     52|                    9U,
  843|     52|                    1U,
  844|     52|                    uint64_t *os = a;
  845|     52|                    uint64_t uu____0 = oneq[i];
  846|     52|                    uint64_t x = uu____0 ^ (is_b_valid & (a[i] ^ uu____0));
  847|     52|                    os[i] = x;);
  848|     52|    return is_b_valid;
  849|     52|}
Hacl_P521.c:point_mul_g:
 1163|     52|{
 1164|     52|    uint64_t g[27U] = { 0U };
 1165|     52|    uint64_t *x = g;
 1166|     52|    uint64_t *y = g + 9U;
 1167|     52|    uint64_t *z = g + 18U;
 1168|     52|    p521_make_g_x(x);
 1169|     52|    p521_make_g_y(y);
 1170|     52|    p521_make_fone(z);
 1171|     52|    point_mul(res, scalar, g);
 1172|     52|}
Hacl_P521.c:p521_make_g_x:
  398|     52|{
  399|     52|    n[0U] = 0xb331a16381adc101ULL;
  400|     52|    n[1U] = 0x4dfcbf3f18e172deULL;
  401|     52|    n[2U] = 0x6f19a459e0c2b521ULL;
  402|     52|    n[3U] = 0x947f0ee093d17fd4ULL;
  403|     52|    n[4U] = 0xdd50a5af3bf7f3acULL;
  404|     52|    n[5U] = 0x90fc1457b035a69eULL;
  405|     52|    n[6U] = 0x214e32409c829fdaULL;
  406|     52|    n[7U] = 0xe6cf1f65b311cadaULL;
  407|     52|    n[8U] = 0x74ULL;
  408|     52|}
Hacl_P521.c:p521_make_g_y:
  412|     52|{
  413|     52|    n[0U] = 0x28460e4a5a9e268eULL;
  414|     52|    n[1U] = 0x20445f4a3b4fe8b3ULL;
  415|     52|    n[2U] = 0xb09a9e3843513961ULL;
  416|     52|    n[3U] = 0x2062a85c809fd683ULL;
  417|     52|    n[4U] = 0x164bf7394caf7a13ULL;
  418|     52|    n[5U] = 0x340bd7de8b939f33ULL;
  419|     52|    n[6U] = 0xeccc7aa224abcda2ULL;
  420|     52|    n[7U] = 0x022e452fda163e8dULL;
  421|     52|    n[8U] = 0x1e0ULL;
  422|     52|}
Hacl_P521.c:p521_finv:
  695|     52|{
  696|     52|    uint64_t b[9U] = { 0U };
  697|     52|    b[0U] = 0xfffffffffffffffdULL;
  698|     52|    b[1U] = 0xffffffffffffffffULL;
  699|     52|    b[2U] = 0xffffffffffffffffULL;
  700|     52|    b[3U] = 0xffffffffffffffffULL;
  701|     52|    b[4U] = 0xffffffffffffffffULL;
  702|     52|    b[5U] = 0xffffffffffffffffULL;
  703|     52|    b[6U] = 0xffffffffffffffffULL;
  704|     52|    b[7U] = 0xffffffffffffffffULL;
  705|     52|    b[8U] = 0x1ffULL;
  706|     52|    uint64_t tmp[9U] = { 0U };
  707|     52|    memcpy(tmp, a, 9U * sizeof(uint64_t));
  708|     52|    uint64_t table[288U] = { 0U };
  709|     52|    uint64_t tmp1[9U] = { 0U };
  710|     52|    uint64_t *t0 = table;
  711|     52|    uint64_t *t1 = table + 9U;
  712|     52|    p521_make_fone(t0);
  713|     52|    memcpy(t1, tmp, 9U * sizeof(uint64_t));
  714|     52|    KRML_MAYBE_FOR15(i,
  ------------------
  |  |  396|     52|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|     52|    do {                               \
  |  |  |  |  289|     52|        uint32_t i = z;                \
  |  |  |  |  290|     52|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     52|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  715|     52|                     0U,
  716|     52|                     15U,
  717|     52|                     1U,
  718|     52|                     uint64_t *t11 = table + (i + 1U) * 9U;
  719|     52|                     fsqr0(tmp1, t11);
  720|     52|                     memcpy(table + (2U * i + 2U) * 9U, tmp1, 9U * sizeof(uint64_t));
  721|     52|                     uint64_t *t2 = table + (2U * i + 2U) * 9U;
  722|     52|                     fmul0(tmp1, tmp, t2);
  723|     52|                     memcpy(table + (2U * i + 3U) * 9U, tmp1, 9U * sizeof(uint64_t)););
  724|     52|    uint32_t i0 = 520U;
  725|     52|    uint64_t bits_c = Hacl_Bignum_Lib_bn_get_bits_u64(9U, b, i0, 5U);
  726|     52|    memcpy(res, (uint64_t *)table, 9U * sizeof(uint64_t));
  727|  1.66k|    for (uint32_t i1 = 0U; i1 < 31U; i1++) {
  ------------------
  |  Branch (727:28): [True: 1.61k, False: 52]
  ------------------
  728|  1.61k|        uint64_t c = FStar_UInt64_eq_mask(bits_c, (uint64_t)(i1 + 1U));
  729|  1.61k|        const uint64_t *res_j = table + (i1 + 1U) * 9U;
  730|  1.61k|        KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|  1.61k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|  1.61k|    do {                               \
  |  |  |  |  289|  1.61k|        uint32_t i = z;                \
  |  |  |  |  290|  1.61k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  1.61k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  731|  1.61k|                        0U,
  732|  1.61k|                        9U,
  733|  1.61k|                        1U,
  734|  1.61k|                        uint64_t *os = res;
  735|  1.61k|                        uint64_t x = (c & res_j[i]) | (~c & res[i]);
  736|  1.61k|                        os[i] = x;);
  737|  1.61k|    }
  738|     52|    uint64_t tmp10[9U] = { 0U };
  739|  5.46k|    for (uint32_t i1 = 0U; i1 < 104U; i1++) {
  ------------------
  |  Branch (739:28): [True: 5.40k, False: 52]
  ------------------
  740|  5.40k|        KRML_MAYBE_FOR5(i, 0U, 5U, 1U, fsqr0(res, res););
  ------------------
  |  |  336|  5.40k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  5.40k|    do {                               \
  |  |  |  |  289|  5.40k|        uint32_t i = z;                \
  |  |  |  |  290|  5.40k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  5.40k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  741|  5.40k|        uint32_t k = 520U - 5U * i1 - 5U;
  742|  5.40k|        uint64_t bits_l = Hacl_Bignum_Lib_bn_get_bits_u64(9U, b, k, 5U);
  743|  5.40k|        memcpy(tmp10, (uint64_t *)table, 9U * sizeof(uint64_t));
  744|   173k|        for (uint32_t i2 = 0U; i2 < 31U; i2++) {
  ------------------
  |  Branch (744:32): [True: 167k, False: 5.40k]
  ------------------
  745|   167k|            uint64_t c = FStar_UInt64_eq_mask(bits_l, (uint64_t)(i2 + 1U));
  746|   167k|            const uint64_t *res_j = table + (i2 + 1U) * 9U;
  747|   167k|            KRML_MAYBE_FOR9(i,
  ------------------
  |  |  360|   167k|#define KRML_MAYBE_FOR9(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 9, k, x)
  |  |  ------------------
  |  |  |  |  288|   167k|    do {                               \
  |  |  |  |  289|   167k|        uint32_t i = z;                \
  |  |  |  |  290|   167k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|   167k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  748|   167k|                            0U,
  749|   167k|                            9U,
  750|   167k|                            1U,
  751|   167k|                            uint64_t *os = tmp10;
  752|   167k|                            uint64_t x = (c & res_j[i]) | (~c & tmp10[i]);
  753|   167k|                            os[i] = x;);
  754|   167k|        }
  755|  5.40k|        fmul0(res, res, tmp10);
  756|  5.40k|    }
  757|     52|}
Hacl_P521.c:point_mul:
 1107|     52|{
 1108|     52|    uint64_t table[432U] = { 0U };
 1109|     52|    uint64_t tmp[27U] = { 0U };
 1110|     52|    uint64_t *t0 = table;
 1111|     52|    uint64_t *t1 = table + 27U;
 1112|     52|    point_zero(t0);
 1113|     52|    memcpy(t1, p, 27U * sizeof(uint64_t));
 1114|     52|    KRML_MAYBE_FOR7(i,
  ------------------
  |  |  348|     52|#define KRML_MAYBE_FOR7(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 7, k, x)
  |  |  ------------------
  |  |  |  |  288|     52|    do {                               \
  |  |  |  |  289|     52|        uint32_t i = z;                \
  |  |  |  |  290|     52|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     52|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1115|     52|                    0U,
 1116|     52|                    7U,
 1117|     52|                    1U,
 1118|     52|                    uint64_t *t11 = table + (i + 1U) * 27U;
 1119|     52|                    point_double(t11, tmp);
 1120|     52|                    memcpy(table + (2U * i + 2U) * 27U, tmp, 27U * sizeof(uint64_t));
 1121|     52|                    uint64_t *t2 = table + (2U * i + 2U) * 27U;
 1122|     52|                    point_add(p, t2, tmp);
 1123|     52|                    memcpy(table + (2U * i + 3U) * 27U, tmp, 27U * sizeof(uint64_t)););
 1124|     52|    uint32_t i0 = 520U;
 1125|     52|    uint64_t bits_c = Hacl_Bignum_Lib_bn_get_bits_u64(9U, scalar, i0, 4U);
 1126|     52|    memcpy(res, (uint64_t *)table, 27U * sizeof(uint64_t));
 1127|     52|    KRML_MAYBE_FOR15(
  ------------------
  |  |  396|     52|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|     52|    do {                               \
  |  |  |  |  289|     52|        uint32_t i = z;                \
  |  |  |  |  290|     52|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     52|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1128|     52|        i1,
 1129|     52|        0U,
 1130|     52|        15U,
 1131|     52|        1U,
 1132|     52|        uint64_t c = FStar_UInt64_eq_mask(bits_c, (uint64_t)(i1 + 1U));
 1133|     52|        const uint64_t *res_j = table + (i1 + 1U) * 27U;
 1134|     52|        for (uint32_t i = 0U; i < 27U; i++) {
 1135|     52|            uint64_t *os = res;
 1136|     52|            uint64_t x = (c & res_j[i]) | (~c & res[i]);
 1137|     52|            os[i] = x;
 1138|     52|        });
 1139|     52|    uint64_t tmp0[27U] = { 0U };
 1140|  6.81k|    for (uint32_t i1 = 0U; i1 < 130U; i1++) {
  ------------------
  |  Branch (1140:28): [True: 6.76k, False: 52]
  ------------------
 1141|  6.76k|        KRML_MAYBE_FOR4(i, 0U, 4U, 1U, point_double(res, res););
  ------------------
  |  |  330|  6.76k|#define KRML_MAYBE_FOR4(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 4, k, x)
  |  |  ------------------
  |  |  |  |  288|  6.76k|    do {                               \
  |  |  |  |  289|  6.76k|        uint32_t i = z;                \
  |  |  |  |  290|  6.76k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  6.76k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1142|  6.76k|        uint32_t k = 520U - 4U * i1 - 4U;
 1143|  6.76k|        uint64_t bits_l = Hacl_Bignum_Lib_bn_get_bits_u64(9U, scalar, k, 4U);
 1144|  6.76k|        memcpy(tmp0, (uint64_t *)table, 27U * sizeof(uint64_t));
 1145|  6.76k|        KRML_MAYBE_FOR15(
  ------------------
  |  |  396|  6.76k|#define KRML_MAYBE_FOR15(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 15, k, x)
  |  |  ------------------
  |  |  |  |  288|  6.76k|    do {                               \
  |  |  |  |  289|  6.76k|        uint32_t i = z;                \
  |  |  |  |  290|  6.76k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  6.76k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1146|  6.76k|            i2,
 1147|  6.76k|            0U,
 1148|  6.76k|            15U,
 1149|  6.76k|            1U,
 1150|  6.76k|            uint64_t c = FStar_UInt64_eq_mask(bits_l, (uint64_t)(i2 + 1U));
 1151|  6.76k|            const uint64_t *res_j = table + (i2 + 1U) * 27U;
 1152|  6.76k|            for (uint32_t i = 0U; i < 27U; i++) {
 1153|  6.76k|                uint64_t *os = tmp0;
 1154|  6.76k|                uint64_t x = (c & res_j[i]) | (~c & tmp0[i]);
 1155|  6.76k|                os[i] = x;
 1156|  6.76k|            });
 1157|  6.76k|        point_add(res, tmp0, res);
 1158|  6.76k|    }
 1159|     52|}
Hacl_P521.c:point_zero:
 1096|     52|{
 1097|     52|    uint64_t *x = one;
 1098|     52|    uint64_t *y = one + 9U;
 1099|     52|    uint64_t *z = one + 18U;
 1100|     52|    p521_make_fzero(x);
 1101|     52|    p521_make_fone(y);
 1102|     52|    p521_make_fzero(z);
 1103|     52|}
Hacl_P521.c:p521_make_fzero:
  440|    104|{
  441|    104|    memset(n, 0U, 9U * sizeof(uint64_t));
  442|    104|    n[0U] = 0ULL;
  443|    104|}
Hacl_P521.c:point_double:
 1039|  27.4k|{
 1040|  27.4k|    uint64_t tmp[45U] = { 0U };
 1041|  27.4k|    uint64_t *x1 = x;
 1042|  27.4k|    uint64_t *z = x + 18U;
 1043|  27.4k|    uint64_t *x3 = xx;
 1044|  27.4k|    uint64_t *y3 = xx + 9U;
 1045|  27.4k|    uint64_t *z3 = xx + 18U;
 1046|  27.4k|    uint64_t *t0 = tmp;
 1047|  27.4k|    uint64_t *t1 = tmp + 9U;
 1048|  27.4k|    uint64_t *t2 = tmp + 18U;
 1049|  27.4k|    uint64_t *t3 = tmp + 27U;
 1050|  27.4k|    uint64_t *t4 = tmp + 36U;
 1051|  27.4k|    uint64_t *x2 = x;
 1052|  27.4k|    uint64_t *y = x + 9U;
 1053|  27.4k|    uint64_t *z1 = x + 18U;
 1054|  27.4k|    fsqr0(t0, x2);
 1055|  27.4k|    fsqr0(t1, y);
 1056|  27.4k|    fsqr0(t2, z1);
 1057|  27.4k|    fmul0(t3, x2, y);
 1058|  27.4k|    fadd0(t3, t3, t3);
 1059|  27.4k|    fmul0(t4, y, z1);
 1060|  27.4k|    fmul0(z3, x1, z);
 1061|  27.4k|    fadd0(z3, z3, z3);
 1062|  27.4k|    uint64_t b_coeff[9U] = { 0U };
 1063|  27.4k|    p521_make_b_coeff(b_coeff);
 1064|  27.4k|    fmul0(y3, b_coeff, t2);
 1065|  27.4k|    fsub0(y3, y3, z3);
 1066|  27.4k|    fadd0(x3, y3, y3);
 1067|  27.4k|    fadd0(y3, x3, y3);
 1068|  27.4k|    fsub0(x3, t1, y3);
 1069|  27.4k|    fadd0(y3, t1, y3);
 1070|  27.4k|    fmul0(y3, x3, y3);
 1071|  27.4k|    fmul0(x3, x3, t3);
 1072|  27.4k|    fadd0(t3, t2, t2);
 1073|  27.4k|    fadd0(t2, t2, t3);
 1074|  27.4k|    uint64_t b_coeff0[9U] = { 0U };
 1075|  27.4k|    p521_make_b_coeff(b_coeff0);
 1076|  27.4k|    fmul0(z3, b_coeff0, z3);
 1077|  27.4k|    fsub0(z3, z3, t2);
 1078|  27.4k|    fsub0(z3, z3, t0);
 1079|  27.4k|    fadd0(t3, z3, z3);
 1080|  27.4k|    fadd0(z3, z3, t3);
 1081|  27.4k|    fadd0(t3, t0, t0);
 1082|  27.4k|    fadd0(t0, t3, t0);
 1083|  27.4k|    fsub0(t0, t0, t2);
 1084|  27.4k|    fmul0(t0, t0, z3);
 1085|  27.4k|    fadd0(y3, y3, t0);
 1086|  27.4k|    fadd0(t0, t4, t4);
 1087|  27.4k|    fmul0(z3, t0, z3);
 1088|  27.4k|    fsub0(x3, x3, z3);
 1089|  27.4k|    fmul0(z3, t0, t1);
 1090|  27.4k|    fadd0(z3, z3, z3);
 1091|  27.4k|    fadd0(z3, z3, z3);
 1092|  27.4k|}

libcrux_mlkem_portable.c:core_num__u64_9__from_le_bytes:
  150|  39.0k|{
  151|  39.0k|    return load64_le(buf);
  ------------------
  |  |  214|  39.0k|#define load64_le(b) (le64toh(load64(b)))
  ------------------
  152|  39.0k|}
libcrux_mlkem_portable.c:core_num__u64_9__to_le_bytes:
  145|  64.1k|{
  146|  64.1k|    store64_le(buf, v);
  ------------------
  |  |  215|  64.1k|#define store64_le(b, i) (store64(b, htole64(i)))
  ------------------
  147|  64.1k|}
libcrux_mlkem_portable.c:Eurydice_slice_to_array3:
  122|  60.2k|{
  123|  60.2k|    *dst_tag = 0;
  124|  60.2k|    memcpy(dst_ok, src.ptr, sz);
  125|  60.2k|}

Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fsqr:
  375|  3.71M|{
  376|  3.71M|    KRML_HOST_IGNORE(uu___);
  ------------------
  |  |   56|  3.71M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  377|  3.71M|    uint64_t f0 = f[0U];
  378|  3.71M|    uint64_t f1 = f[1U];
  379|  3.71M|    uint64_t f2 = f[2U];
  380|  3.71M|    uint64_t f3 = f[3U];
  381|  3.71M|    uint64_t f4 = f[4U];
  382|  3.71M|    uint64_t d0 = (uint64_t)2U * f0;
  383|  3.71M|    uint64_t d1 = (uint64_t)2U * f1;
  384|  3.71M|    uint64_t d2 = (uint64_t)38U * f2;
  385|  3.71M|    uint64_t d3 = (uint64_t)19U * f3;
  386|  3.71M|    uint64_t d419 = (uint64_t)19U * f4;
  387|  3.71M|    uint64_t d4 = (uint64_t)2U * d419;
  388|  3.71M|    FStar_UInt128_uint128
  389|  3.71M|        s0 =
  390|  3.71M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(f0, f0),
  391|  3.71M|                                                FStar_UInt128_mul_wide(d4, f1)),
  392|  3.71M|                              FStar_UInt128_mul_wide(d2, f3));
  393|  3.71M|    FStar_UInt128_uint128
  394|  3.71M|        s1 =
  395|  3.71M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f1),
  396|  3.71M|                                                FStar_UInt128_mul_wide(d4, f2)),
  397|  3.71M|                              FStar_UInt128_mul_wide(d3, f3));
  398|  3.71M|    FStar_UInt128_uint128
  399|  3.71M|        s2 =
  400|  3.71M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f2),
  401|  3.71M|                                                FStar_UInt128_mul_wide(f1, f1)),
  402|  3.71M|                              FStar_UInt128_mul_wide(d4, f3));
  403|  3.71M|    FStar_UInt128_uint128
  404|  3.71M|        s3 =
  405|  3.71M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f3),
  406|  3.71M|                                                FStar_UInt128_mul_wide(d1, f2)),
  407|  3.71M|                              FStar_UInt128_mul_wide(f4, d419));
  408|  3.71M|    FStar_UInt128_uint128
  409|  3.71M|        s4 =
  410|  3.71M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f4),
  411|  3.71M|                                                FStar_UInt128_mul_wide(d1, f3)),
  412|  3.71M|                              FStar_UInt128_mul_wide(f2, f2));
  413|  3.71M|    FStar_UInt128_uint128 o00 = s0;
  414|  3.71M|    FStar_UInt128_uint128 o10 = s1;
  415|  3.71M|    FStar_UInt128_uint128 o20 = s2;
  416|  3.71M|    FStar_UInt128_uint128 o30 = s3;
  417|  3.71M|    FStar_UInt128_uint128 o40 = s4;
  418|  3.71M|    FStar_UInt128_uint128
  419|  3.71M|        l_ = FStar_UInt128_add(o00, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  420|  3.71M|    uint64_t tmp0 = FStar_UInt128_uint128_to_uint64(l_) & (uint64_t)0x7ffffffffffffU;
  421|  3.71M|    uint64_t c0 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_, (uint32_t)51U));
  422|  3.71M|    FStar_UInt128_uint128 l_0 = FStar_UInt128_add(o10, FStar_UInt128_uint64_to_uint128(c0));
  423|  3.71M|    uint64_t tmp1 = FStar_UInt128_uint128_to_uint64(l_0) & (uint64_t)0x7ffffffffffffU;
  424|  3.71M|    uint64_t c1 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_0, (uint32_t)51U));
  425|  3.71M|    FStar_UInt128_uint128 l_1 = FStar_UInt128_add(o20, FStar_UInt128_uint64_to_uint128(c1));
  426|  3.71M|    uint64_t tmp2 = FStar_UInt128_uint128_to_uint64(l_1) & (uint64_t)0x7ffffffffffffU;
  427|  3.71M|    uint64_t c2 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_1, (uint32_t)51U));
  428|  3.71M|    FStar_UInt128_uint128 l_2 = FStar_UInt128_add(o30, FStar_UInt128_uint64_to_uint128(c2));
  429|  3.71M|    uint64_t tmp3 = FStar_UInt128_uint128_to_uint64(l_2) & (uint64_t)0x7ffffffffffffU;
  430|  3.71M|    uint64_t c3 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_2, (uint32_t)51U));
  431|  3.71M|    FStar_UInt128_uint128 l_3 = FStar_UInt128_add(o40, FStar_UInt128_uint64_to_uint128(c3));
  432|  3.71M|    uint64_t tmp4 = FStar_UInt128_uint128_to_uint64(l_3) & (uint64_t)0x7ffffffffffffU;
  433|  3.71M|    uint64_t c4 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_3, (uint32_t)51U));
  434|  3.71M|    uint64_t l_4 = tmp0 + c4 * (uint64_t)19U;
  435|  3.71M|    uint64_t tmp0_ = l_4 & (uint64_t)0x7ffffffffffffU;
  436|  3.71M|    uint64_t c5 = l_4 >> (uint32_t)51U;
  437|  3.71M|    uint64_t o0 = tmp0_;
  438|  3.71M|    uint64_t o1 = tmp1 + c5;
  439|  3.71M|    uint64_t o2 = tmp2;
  440|  3.71M|    uint64_t o3 = tmp3;
  441|  3.71M|    uint64_t o4 = tmp4;
  442|  3.71M|    out[0U] = o0;
  443|  3.71M|    out[1U] = o1;
  444|  3.71M|    out[2U] = o2;
  445|  3.71M|    out[3U] = o3;
  446|  3.71M|    out[4U] = o4;
  447|  3.71M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fmul:
   86|  3.86M|{
   87|  3.86M|    KRML_HOST_IGNORE(uu___);
  ------------------
  |  |   56|  3.86M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
   88|  3.86M|    uint64_t f10 = f1[0U];
   89|  3.86M|    uint64_t f11 = f1[1U];
   90|  3.86M|    uint64_t f12 = f1[2U];
   91|  3.86M|    uint64_t f13 = f1[3U];
   92|  3.86M|    uint64_t f14 = f1[4U];
   93|  3.86M|    uint64_t f20 = f2[0U];
   94|  3.86M|    uint64_t f21 = f2[1U];
   95|  3.86M|    uint64_t f22 = f2[2U];
   96|  3.86M|    uint64_t f23 = f2[3U];
   97|  3.86M|    uint64_t f24 = f2[4U];
   98|  3.86M|    uint64_t tmp1 = f21 * (uint64_t)19U;
   99|  3.86M|    uint64_t tmp2 = f22 * (uint64_t)19U;
  100|  3.86M|    uint64_t tmp3 = f23 * (uint64_t)19U;
  101|  3.86M|    uint64_t tmp4 = f24 * (uint64_t)19U;
  102|  3.86M|    FStar_UInt128_uint128 o00 = FStar_UInt128_mul_wide(f10, f20);
  103|  3.86M|    FStar_UInt128_uint128 o10 = FStar_UInt128_mul_wide(f10, f21);
  104|  3.86M|    FStar_UInt128_uint128 o20 = FStar_UInt128_mul_wide(f10, f22);
  105|  3.86M|    FStar_UInt128_uint128 o30 = FStar_UInt128_mul_wide(f10, f23);
  106|  3.86M|    FStar_UInt128_uint128 o40 = FStar_UInt128_mul_wide(f10, f24);
  107|  3.86M|    FStar_UInt128_uint128 o01 = FStar_UInt128_add(o00, FStar_UInt128_mul_wide(f11, tmp4));
  108|  3.86M|    FStar_UInt128_uint128 o11 = FStar_UInt128_add(o10, FStar_UInt128_mul_wide(f11, f20));
  109|  3.86M|    FStar_UInt128_uint128 o21 = FStar_UInt128_add(o20, FStar_UInt128_mul_wide(f11, f21));
  110|  3.86M|    FStar_UInt128_uint128 o31 = FStar_UInt128_add(o30, FStar_UInt128_mul_wide(f11, f22));
  111|  3.86M|    FStar_UInt128_uint128 o41 = FStar_UInt128_add(o40, FStar_UInt128_mul_wide(f11, f23));
  112|  3.86M|    FStar_UInt128_uint128 o02 = FStar_UInt128_add(o01, FStar_UInt128_mul_wide(f12, tmp3));
  113|  3.86M|    FStar_UInt128_uint128 o12 = FStar_UInt128_add(o11, FStar_UInt128_mul_wide(f12, tmp4));
  114|  3.86M|    FStar_UInt128_uint128 o22 = FStar_UInt128_add(o21, FStar_UInt128_mul_wide(f12, f20));
  115|  3.86M|    FStar_UInt128_uint128 o32 = FStar_UInt128_add(o31, FStar_UInt128_mul_wide(f12, f21));
  116|  3.86M|    FStar_UInt128_uint128 o42 = FStar_UInt128_add(o41, FStar_UInt128_mul_wide(f12, f22));
  117|  3.86M|    FStar_UInt128_uint128 o03 = FStar_UInt128_add(o02, FStar_UInt128_mul_wide(f13, tmp2));
  118|  3.86M|    FStar_UInt128_uint128 o13 = FStar_UInt128_add(o12, FStar_UInt128_mul_wide(f13, tmp3));
  119|  3.86M|    FStar_UInt128_uint128 o23 = FStar_UInt128_add(o22, FStar_UInt128_mul_wide(f13, tmp4));
  120|  3.86M|    FStar_UInt128_uint128 o33 = FStar_UInt128_add(o32, FStar_UInt128_mul_wide(f13, f20));
  121|  3.86M|    FStar_UInt128_uint128 o43 = FStar_UInt128_add(o42, FStar_UInt128_mul_wide(f13, f21));
  122|  3.86M|    FStar_UInt128_uint128 o04 = FStar_UInt128_add(o03, FStar_UInt128_mul_wide(f14, tmp1));
  123|  3.86M|    FStar_UInt128_uint128 o14 = FStar_UInt128_add(o13, FStar_UInt128_mul_wide(f14, tmp2));
  124|  3.86M|    FStar_UInt128_uint128 o24 = FStar_UInt128_add(o23, FStar_UInt128_mul_wide(f14, tmp3));
  125|  3.86M|    FStar_UInt128_uint128 o34 = FStar_UInt128_add(o33, FStar_UInt128_mul_wide(f14, tmp4));
  126|  3.86M|    FStar_UInt128_uint128 o44 = FStar_UInt128_add(o43, FStar_UInt128_mul_wide(f14, f20));
  127|  3.86M|    FStar_UInt128_uint128 tmp_w0 = o04;
  128|  3.86M|    FStar_UInt128_uint128 tmp_w1 = o14;
  129|  3.86M|    FStar_UInt128_uint128 tmp_w2 = o24;
  130|  3.86M|    FStar_UInt128_uint128 tmp_w3 = o34;
  131|  3.86M|    FStar_UInt128_uint128 tmp_w4 = o44;
  132|  3.86M|    FStar_UInt128_uint128
  133|  3.86M|        l_ = FStar_UInt128_add(tmp_w0, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  134|  3.86M|    uint64_t tmp01 = FStar_UInt128_uint128_to_uint64(l_) & (uint64_t)0x7ffffffffffffU;
  135|  3.86M|    uint64_t c0 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_, (uint32_t)51U));
  136|  3.86M|    FStar_UInt128_uint128 l_0 = FStar_UInt128_add(tmp_w1, FStar_UInt128_uint64_to_uint128(c0));
  137|  3.86M|    uint64_t tmp11 = FStar_UInt128_uint128_to_uint64(l_0) & (uint64_t)0x7ffffffffffffU;
  138|  3.86M|    uint64_t c1 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_0, (uint32_t)51U));
  139|  3.86M|    FStar_UInt128_uint128 l_1 = FStar_UInt128_add(tmp_w2, FStar_UInt128_uint64_to_uint128(c1));
  140|  3.86M|    uint64_t tmp21 = FStar_UInt128_uint128_to_uint64(l_1) & (uint64_t)0x7ffffffffffffU;
  141|  3.86M|    uint64_t c2 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_1, (uint32_t)51U));
  142|  3.86M|    FStar_UInt128_uint128 l_2 = FStar_UInt128_add(tmp_w3, FStar_UInt128_uint64_to_uint128(c2));
  143|  3.86M|    uint64_t tmp31 = FStar_UInt128_uint128_to_uint64(l_2) & (uint64_t)0x7ffffffffffffU;
  144|  3.86M|    uint64_t c3 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_2, (uint32_t)51U));
  145|  3.86M|    FStar_UInt128_uint128 l_3 = FStar_UInt128_add(tmp_w4, FStar_UInt128_uint64_to_uint128(c3));
  146|  3.86M|    uint64_t tmp41 = FStar_UInt128_uint128_to_uint64(l_3) & (uint64_t)0x7ffffffffffffU;
  147|  3.86M|    uint64_t c4 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_3, (uint32_t)51U));
  148|  3.86M|    uint64_t l_4 = tmp01 + c4 * (uint64_t)19U;
  149|  3.86M|    uint64_t tmp0_ = l_4 & (uint64_t)0x7ffffffffffffU;
  150|  3.86M|    uint64_t c5 = l_4 >> (uint32_t)51U;
  151|  3.86M|    uint64_t o0 = tmp0_;
  152|  3.86M|    uint64_t o1 = tmp11 + c5;
  153|  3.86M|    uint64_t o2 = tmp21;
  154|  3.86M|    uint64_t o3 = tmp31;
  155|  3.86M|    uint64_t o4 = tmp41;
  156|  3.86M|    out[0U] = o0;
  157|  3.86M|    out[1U] = o1;
  158|  3.86M|    out[2U] = o2;
  159|  3.86M|    out[3U] = o3;
  160|  3.86M|    out[4U] = o4;
  161|  3.86M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_cswap2:
  668|  3.69M|{
  669|  3.69M|    uint64_t mask = (uint64_t)0U - bit;
  670|  3.69M|    KRML_MAYBE_FOR10(i,
  ------------------
  |  |  366|  3.69M|#define KRML_MAYBE_FOR10(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 10, k, x)
  |  |  ------------------
  |  |  |  |  288|  3.69M|    do {                               \
  |  |  |  |  289|  3.69M|        uint32_t i = z;                \
  |  |  |  |  290|  3.69M|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  3.69M|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  671|  3.69M|                     (uint32_t)0U,
  672|  3.69M|                     (uint32_t)10U,
  673|  3.69M|                     (uint32_t)1U,
  674|  3.69M|                     uint64_t dummy = mask & (p1[i] ^ p2[i]);
  675|  3.69M|                     p1[i] = p1[i] ^ dummy;
  676|  3.69M|                     p2[i] = p2[i] ^ dummy;);
  677|  3.69M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fadd:
   42|  14.8M|{
   43|  14.8M|    uint64_t f10 = f1[0U];
   44|  14.8M|    uint64_t f20 = f2[0U];
   45|  14.8M|    uint64_t f11 = f1[1U];
   46|  14.8M|    uint64_t f21 = f2[1U];
   47|  14.8M|    uint64_t f12 = f1[2U];
   48|  14.8M|    uint64_t f22 = f2[2U];
   49|  14.8M|    uint64_t f13 = f1[3U];
   50|  14.8M|    uint64_t f23 = f2[3U];
   51|  14.8M|    uint64_t f14 = f1[4U];
   52|  14.8M|    uint64_t f24 = f2[4U];
   53|  14.8M|    out[0U] = f10 + f20;
   54|  14.8M|    out[1U] = f11 + f21;
   55|  14.8M|    out[2U] = f12 + f22;
   56|  14.8M|    out[3U] = f13 + f23;
   57|  14.8M|    out[4U] = f14 + f24;
   58|  14.8M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fsub:
   62|  14.8M|{
   63|  14.8M|    uint64_t f10 = f1[0U];
   64|  14.8M|    uint64_t f20 = f2[0U];
   65|  14.8M|    uint64_t f11 = f1[1U];
   66|  14.8M|    uint64_t f21 = f2[1U];
   67|  14.8M|    uint64_t f12 = f1[2U];
   68|  14.8M|    uint64_t f22 = f2[2U];
   69|  14.8M|    uint64_t f13 = f1[3U];
   70|  14.8M|    uint64_t f23 = f2[3U];
   71|  14.8M|    uint64_t f14 = f1[4U];
   72|  14.8M|    uint64_t f24 = f2[4U];
   73|  14.8M|    out[0U] = f10 + (uint64_t)0x3fffffffffff68U - f20;
   74|  14.8M|    out[1U] = f11 + (uint64_t)0x3ffffffffffff8U - f21;
   75|  14.8M|    out[2U] = f12 + (uint64_t)0x3ffffffffffff8U - f22;
   76|  14.8M|    out[3U] = f13 + (uint64_t)0x3ffffffffffff8U - f23;
   77|  14.8M|    out[4U] = f14 + (uint64_t)0x3ffffffffffff8U - f24;
   78|  14.8M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fmul2:
  169|  7.41M|{
  170|  7.41M|    KRML_HOST_IGNORE(uu___);
  ------------------
  |  |   56|  7.41M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  171|  7.41M|    uint64_t f10 = f1[0U];
  172|  7.41M|    uint64_t f11 = f1[1U];
  173|  7.41M|    uint64_t f12 = f1[2U];
  174|  7.41M|    uint64_t f13 = f1[3U];
  175|  7.41M|    uint64_t f14 = f1[4U];
  176|  7.41M|    uint64_t f20 = f2[0U];
  177|  7.41M|    uint64_t f21 = f2[1U];
  178|  7.41M|    uint64_t f22 = f2[2U];
  179|  7.41M|    uint64_t f23 = f2[3U];
  180|  7.41M|    uint64_t f24 = f2[4U];
  181|  7.41M|    uint64_t f30 = f1[5U];
  182|  7.41M|    uint64_t f31 = f1[6U];
  183|  7.41M|    uint64_t f32 = f1[7U];
  184|  7.41M|    uint64_t f33 = f1[8U];
  185|  7.41M|    uint64_t f34 = f1[9U];
  186|  7.41M|    uint64_t f40 = f2[5U];
  187|  7.41M|    uint64_t f41 = f2[6U];
  188|  7.41M|    uint64_t f42 = f2[7U];
  189|  7.41M|    uint64_t f43 = f2[8U];
  190|  7.41M|    uint64_t f44 = f2[9U];
  191|  7.41M|    uint64_t tmp11 = f21 * (uint64_t)19U;
  192|  7.41M|    uint64_t tmp12 = f22 * (uint64_t)19U;
  193|  7.41M|    uint64_t tmp13 = f23 * (uint64_t)19U;
  194|  7.41M|    uint64_t tmp14 = f24 * (uint64_t)19U;
  195|  7.41M|    uint64_t tmp21 = f41 * (uint64_t)19U;
  196|  7.41M|    uint64_t tmp22 = f42 * (uint64_t)19U;
  197|  7.41M|    uint64_t tmp23 = f43 * (uint64_t)19U;
  198|  7.41M|    uint64_t tmp24 = f44 * (uint64_t)19U;
  199|  7.41M|    FStar_UInt128_uint128 o00 = FStar_UInt128_mul_wide(f10, f20);
  200|  7.41M|    FStar_UInt128_uint128 o15 = FStar_UInt128_mul_wide(f10, f21);
  201|  7.41M|    FStar_UInt128_uint128 o25 = FStar_UInt128_mul_wide(f10, f22);
  202|  7.41M|    FStar_UInt128_uint128 o30 = FStar_UInt128_mul_wide(f10, f23);
  203|  7.41M|    FStar_UInt128_uint128 o40 = FStar_UInt128_mul_wide(f10, f24);
  204|  7.41M|    FStar_UInt128_uint128 o010 = FStar_UInt128_add(o00, FStar_UInt128_mul_wide(f11, tmp14));
  205|  7.41M|    FStar_UInt128_uint128 o110 = FStar_UInt128_add(o15, FStar_UInt128_mul_wide(f11, f20));
  206|  7.41M|    FStar_UInt128_uint128 o210 = FStar_UInt128_add(o25, FStar_UInt128_mul_wide(f11, f21));
  207|  7.41M|    FStar_UInt128_uint128 o310 = FStar_UInt128_add(o30, FStar_UInt128_mul_wide(f11, f22));
  208|  7.41M|    FStar_UInt128_uint128 o410 = FStar_UInt128_add(o40, FStar_UInt128_mul_wide(f11, f23));
  209|  7.41M|    FStar_UInt128_uint128 o020 = FStar_UInt128_add(o010, FStar_UInt128_mul_wide(f12, tmp13));
  210|  7.41M|    FStar_UInt128_uint128 o120 = FStar_UInt128_add(o110, FStar_UInt128_mul_wide(f12, tmp14));
  211|  7.41M|    FStar_UInt128_uint128 o220 = FStar_UInt128_add(o210, FStar_UInt128_mul_wide(f12, f20));
  212|  7.41M|    FStar_UInt128_uint128 o320 = FStar_UInt128_add(o310, FStar_UInt128_mul_wide(f12, f21));
  213|  7.41M|    FStar_UInt128_uint128 o420 = FStar_UInt128_add(o410, FStar_UInt128_mul_wide(f12, f22));
  214|  7.41M|    FStar_UInt128_uint128 o030 = FStar_UInt128_add(o020, FStar_UInt128_mul_wide(f13, tmp12));
  215|  7.41M|    FStar_UInt128_uint128 o130 = FStar_UInt128_add(o120, FStar_UInt128_mul_wide(f13, tmp13));
  216|  7.41M|    FStar_UInt128_uint128 o230 = FStar_UInt128_add(o220, FStar_UInt128_mul_wide(f13, tmp14));
  217|  7.41M|    FStar_UInt128_uint128 o330 = FStar_UInt128_add(o320, FStar_UInt128_mul_wide(f13, f20));
  218|  7.41M|    FStar_UInt128_uint128 o430 = FStar_UInt128_add(o420, FStar_UInt128_mul_wide(f13, f21));
  219|  7.41M|    FStar_UInt128_uint128 o040 = FStar_UInt128_add(o030, FStar_UInt128_mul_wide(f14, tmp11));
  220|  7.41M|    FStar_UInt128_uint128 o140 = FStar_UInt128_add(o130, FStar_UInt128_mul_wide(f14, tmp12));
  221|  7.41M|    FStar_UInt128_uint128 o240 = FStar_UInt128_add(o230, FStar_UInt128_mul_wide(f14, tmp13));
  222|  7.41M|    FStar_UInt128_uint128 o340 = FStar_UInt128_add(o330, FStar_UInt128_mul_wide(f14, tmp14));
  223|  7.41M|    FStar_UInt128_uint128 o440 = FStar_UInt128_add(o430, FStar_UInt128_mul_wide(f14, f20));
  224|  7.41M|    FStar_UInt128_uint128 tmp_w10 = o040;
  225|  7.41M|    FStar_UInt128_uint128 tmp_w11 = o140;
  226|  7.41M|    FStar_UInt128_uint128 tmp_w12 = o240;
  227|  7.41M|    FStar_UInt128_uint128 tmp_w13 = o340;
  228|  7.41M|    FStar_UInt128_uint128 tmp_w14 = o440;
  229|  7.41M|    FStar_UInt128_uint128 o0 = FStar_UInt128_mul_wide(f30, f40);
  230|  7.41M|    FStar_UInt128_uint128 o1 = FStar_UInt128_mul_wide(f30, f41);
  231|  7.41M|    FStar_UInt128_uint128 o2 = FStar_UInt128_mul_wide(f30, f42);
  232|  7.41M|    FStar_UInt128_uint128 o3 = FStar_UInt128_mul_wide(f30, f43);
  233|  7.41M|    FStar_UInt128_uint128 o4 = FStar_UInt128_mul_wide(f30, f44);
  234|  7.41M|    FStar_UInt128_uint128 o01 = FStar_UInt128_add(o0, FStar_UInt128_mul_wide(f31, tmp24));
  235|  7.41M|    FStar_UInt128_uint128 o111 = FStar_UInt128_add(o1, FStar_UInt128_mul_wide(f31, f40));
  236|  7.41M|    FStar_UInt128_uint128 o211 = FStar_UInt128_add(o2, FStar_UInt128_mul_wide(f31, f41));
  237|  7.41M|    FStar_UInt128_uint128 o31 = FStar_UInt128_add(o3, FStar_UInt128_mul_wide(f31, f42));
  238|  7.41M|    FStar_UInt128_uint128 o41 = FStar_UInt128_add(o4, FStar_UInt128_mul_wide(f31, f43));
  239|  7.41M|    FStar_UInt128_uint128 o02 = FStar_UInt128_add(o01, FStar_UInt128_mul_wide(f32, tmp23));
  240|  7.41M|    FStar_UInt128_uint128 o121 = FStar_UInt128_add(o111, FStar_UInt128_mul_wide(f32, tmp24));
  241|  7.41M|    FStar_UInt128_uint128 o221 = FStar_UInt128_add(o211, FStar_UInt128_mul_wide(f32, f40));
  242|  7.41M|    FStar_UInt128_uint128 o32 = FStar_UInt128_add(o31, FStar_UInt128_mul_wide(f32, f41));
  243|  7.41M|    FStar_UInt128_uint128 o42 = FStar_UInt128_add(o41, FStar_UInt128_mul_wide(f32, f42));
  244|  7.41M|    FStar_UInt128_uint128 o03 = FStar_UInt128_add(o02, FStar_UInt128_mul_wide(f33, tmp22));
  245|  7.41M|    FStar_UInt128_uint128 o131 = FStar_UInt128_add(o121, FStar_UInt128_mul_wide(f33, tmp23));
  246|  7.41M|    FStar_UInt128_uint128 o231 = FStar_UInt128_add(o221, FStar_UInt128_mul_wide(f33, tmp24));
  247|  7.41M|    FStar_UInt128_uint128 o33 = FStar_UInt128_add(o32, FStar_UInt128_mul_wide(f33, f40));
  248|  7.41M|    FStar_UInt128_uint128 o43 = FStar_UInt128_add(o42, FStar_UInt128_mul_wide(f33, f41));
  249|  7.41M|    FStar_UInt128_uint128 o04 = FStar_UInt128_add(o03, FStar_UInt128_mul_wide(f34, tmp21));
  250|  7.41M|    FStar_UInt128_uint128 o141 = FStar_UInt128_add(o131, FStar_UInt128_mul_wide(f34, tmp22));
  251|  7.41M|    FStar_UInt128_uint128 o241 = FStar_UInt128_add(o231, FStar_UInt128_mul_wide(f34, tmp23));
  252|  7.41M|    FStar_UInt128_uint128 o34 = FStar_UInt128_add(o33, FStar_UInt128_mul_wide(f34, tmp24));
  253|  7.41M|    FStar_UInt128_uint128 o44 = FStar_UInt128_add(o43, FStar_UInt128_mul_wide(f34, f40));
  254|  7.41M|    FStar_UInt128_uint128 tmp_w20 = o04;
  255|  7.41M|    FStar_UInt128_uint128 tmp_w21 = o141;
  256|  7.41M|    FStar_UInt128_uint128 tmp_w22 = o241;
  257|  7.41M|    FStar_UInt128_uint128 tmp_w23 = o34;
  258|  7.41M|    FStar_UInt128_uint128 tmp_w24 = o44;
  259|  7.41M|    FStar_UInt128_uint128
  260|  7.41M|        l_ = FStar_UInt128_add(tmp_w10, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  261|  7.41M|    uint64_t tmp00 = FStar_UInt128_uint128_to_uint64(l_) & (uint64_t)0x7ffffffffffffU;
  262|  7.41M|    uint64_t c00 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_, (uint32_t)51U));
  263|  7.41M|    FStar_UInt128_uint128 l_0 = FStar_UInt128_add(tmp_w11, FStar_UInt128_uint64_to_uint128(c00));
  264|  7.41M|    uint64_t tmp10 = FStar_UInt128_uint128_to_uint64(l_0) & (uint64_t)0x7ffffffffffffU;
  265|  7.41M|    uint64_t c10 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_0, (uint32_t)51U));
  266|  7.41M|    FStar_UInt128_uint128 l_1 = FStar_UInt128_add(tmp_w12, FStar_UInt128_uint64_to_uint128(c10));
  267|  7.41M|    uint64_t tmp20 = FStar_UInt128_uint128_to_uint64(l_1) & (uint64_t)0x7ffffffffffffU;
  268|  7.41M|    uint64_t c20 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_1, (uint32_t)51U));
  269|  7.41M|    FStar_UInt128_uint128 l_2 = FStar_UInt128_add(tmp_w13, FStar_UInt128_uint64_to_uint128(c20));
  270|  7.41M|    uint64_t tmp30 = FStar_UInt128_uint128_to_uint64(l_2) & (uint64_t)0x7ffffffffffffU;
  271|  7.41M|    uint64_t c30 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_2, (uint32_t)51U));
  272|  7.41M|    FStar_UInt128_uint128 l_3 = FStar_UInt128_add(tmp_w14, FStar_UInt128_uint64_to_uint128(c30));
  273|  7.41M|    uint64_t tmp40 = FStar_UInt128_uint128_to_uint64(l_3) & (uint64_t)0x7ffffffffffffU;
  274|  7.41M|    uint64_t c40 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_3, (uint32_t)51U));
  275|  7.41M|    uint64_t l_4 = tmp00 + c40 * (uint64_t)19U;
  276|  7.41M|    uint64_t tmp0_ = l_4 & (uint64_t)0x7ffffffffffffU;
  277|  7.41M|    uint64_t c50 = l_4 >> (uint32_t)51U;
  278|  7.41M|    uint64_t o100 = tmp0_;
  279|  7.41M|    uint64_t o112 = tmp10 + c50;
  280|  7.41M|    uint64_t o122 = tmp20;
  281|  7.41M|    uint64_t o132 = tmp30;
  282|  7.41M|    uint64_t o142 = tmp40;
  283|  7.41M|    FStar_UInt128_uint128
  284|  7.41M|        l_5 = FStar_UInt128_add(tmp_w20, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  285|  7.41M|    uint64_t tmp0 = FStar_UInt128_uint128_to_uint64(l_5) & (uint64_t)0x7ffffffffffffU;
  286|  7.41M|    uint64_t c0 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_5, (uint32_t)51U));
  287|  7.41M|    FStar_UInt128_uint128 l_6 = FStar_UInt128_add(tmp_w21, FStar_UInt128_uint64_to_uint128(c0));
  288|  7.41M|    uint64_t tmp1 = FStar_UInt128_uint128_to_uint64(l_6) & (uint64_t)0x7ffffffffffffU;
  289|  7.41M|    uint64_t c1 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_6, (uint32_t)51U));
  290|  7.41M|    FStar_UInt128_uint128 l_7 = FStar_UInt128_add(tmp_w22, FStar_UInt128_uint64_to_uint128(c1));
  291|  7.41M|    uint64_t tmp2 = FStar_UInt128_uint128_to_uint64(l_7) & (uint64_t)0x7ffffffffffffU;
  292|  7.41M|    uint64_t c2 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_7, (uint32_t)51U));
  293|  7.41M|    FStar_UInt128_uint128 l_8 = FStar_UInt128_add(tmp_w23, FStar_UInt128_uint64_to_uint128(c2));
  294|  7.41M|    uint64_t tmp3 = FStar_UInt128_uint128_to_uint64(l_8) & (uint64_t)0x7ffffffffffffU;
  295|  7.41M|    uint64_t c3 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_8, (uint32_t)51U));
  296|  7.41M|    FStar_UInt128_uint128 l_9 = FStar_UInt128_add(tmp_w24, FStar_UInt128_uint64_to_uint128(c3));
  297|  7.41M|    uint64_t tmp4 = FStar_UInt128_uint128_to_uint64(l_9) & (uint64_t)0x7ffffffffffffU;
  298|  7.41M|    uint64_t c4 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_9, (uint32_t)51U));
  299|  7.41M|    uint64_t l_10 = tmp0 + c4 * (uint64_t)19U;
  300|  7.41M|    uint64_t tmp0_0 = l_10 & (uint64_t)0x7ffffffffffffU;
  301|  7.41M|    uint64_t c5 = l_10 >> (uint32_t)51U;
  302|  7.41M|    uint64_t o200 = tmp0_0;
  303|  7.41M|    uint64_t o212 = tmp1 + c5;
  304|  7.41M|    uint64_t o222 = tmp2;
  305|  7.41M|    uint64_t o232 = tmp3;
  306|  7.41M|    uint64_t o242 = tmp4;
  307|  7.41M|    uint64_t o10 = o100;
  308|  7.41M|    uint64_t o11 = o112;
  309|  7.41M|    uint64_t o12 = o122;
  310|  7.41M|    uint64_t o13 = o132;
  311|  7.41M|    uint64_t o14 = o142;
  312|  7.41M|    uint64_t o20 = o200;
  313|  7.41M|    uint64_t o21 = o212;
  314|  7.41M|    uint64_t o22 = o222;
  315|  7.41M|    uint64_t o23 = o232;
  316|  7.41M|    uint64_t o24 = o242;
  317|  7.41M|    out[0U] = o10;
  318|  7.41M|    out[1U] = o11;
  319|  7.41M|    out[2U] = o12;
  320|  7.41M|    out[3U] = o13;
  321|  7.41M|    out[4U] = o14;
  322|  7.41M|    out[5U] = o20;
  323|  7.41M|    out[6U] = o21;
  324|  7.41M|    out[7U] = o22;
  325|  7.41M|    out[8U] = o23;
  326|  7.41M|    out[9U] = o24;
  327|  7.41M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fsqr2:
  451|  7.41M|{
  452|  7.41M|    KRML_HOST_IGNORE(uu___);
  ------------------
  |  |   56|  7.41M|#define KRML_HOST_IGNORE(x) (void)(x)
  ------------------
  453|  7.41M|    uint64_t f10 = f[0U];
  454|  7.41M|    uint64_t f11 = f[1U];
  455|  7.41M|    uint64_t f12 = f[2U];
  456|  7.41M|    uint64_t f13 = f[3U];
  457|  7.41M|    uint64_t f14 = f[4U];
  458|  7.41M|    uint64_t f20 = f[5U];
  459|  7.41M|    uint64_t f21 = f[6U];
  460|  7.41M|    uint64_t f22 = f[7U];
  461|  7.41M|    uint64_t f23 = f[8U];
  462|  7.41M|    uint64_t f24 = f[9U];
  463|  7.41M|    uint64_t d00 = (uint64_t)2U * f10;
  464|  7.41M|    uint64_t d10 = (uint64_t)2U * f11;
  465|  7.41M|    uint64_t d20 = (uint64_t)38U * f12;
  466|  7.41M|    uint64_t d30 = (uint64_t)19U * f13;
  467|  7.41M|    uint64_t d4190 = (uint64_t)19U * f14;
  468|  7.41M|    uint64_t d40 = (uint64_t)2U * d4190;
  469|  7.41M|    FStar_UInt128_uint128
  470|  7.41M|        s00 =
  471|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(f10, f10),
  472|  7.41M|                                                FStar_UInt128_mul_wide(d40, f11)),
  473|  7.41M|                              FStar_UInt128_mul_wide(d20, f13));
  474|  7.41M|    FStar_UInt128_uint128
  475|  7.41M|        s10 =
  476|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d00, f11),
  477|  7.41M|                                                FStar_UInt128_mul_wide(d40, f12)),
  478|  7.41M|                              FStar_UInt128_mul_wide(d30, f13));
  479|  7.41M|    FStar_UInt128_uint128
  480|  7.41M|        s20 =
  481|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d00, f12),
  482|  7.41M|                                                FStar_UInt128_mul_wide(f11, f11)),
  483|  7.41M|                              FStar_UInt128_mul_wide(d40, f13));
  484|  7.41M|    FStar_UInt128_uint128
  485|  7.41M|        s30 =
  486|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d00, f13),
  487|  7.41M|                                                FStar_UInt128_mul_wide(d10, f12)),
  488|  7.41M|                              FStar_UInt128_mul_wide(f14, d4190));
  489|  7.41M|    FStar_UInt128_uint128
  490|  7.41M|        s40 =
  491|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d00, f14),
  492|  7.41M|                                                FStar_UInt128_mul_wide(d10, f13)),
  493|  7.41M|                              FStar_UInt128_mul_wide(f12, f12));
  494|  7.41M|    FStar_UInt128_uint128 o100 = s00;
  495|  7.41M|    FStar_UInt128_uint128 o110 = s10;
  496|  7.41M|    FStar_UInt128_uint128 o120 = s20;
  497|  7.41M|    FStar_UInt128_uint128 o130 = s30;
  498|  7.41M|    FStar_UInt128_uint128 o140 = s40;
  499|  7.41M|    uint64_t d0 = (uint64_t)2U * f20;
  500|  7.41M|    uint64_t d1 = (uint64_t)2U * f21;
  501|  7.41M|    uint64_t d2 = (uint64_t)38U * f22;
  502|  7.41M|    uint64_t d3 = (uint64_t)19U * f23;
  503|  7.41M|    uint64_t d419 = (uint64_t)19U * f24;
  504|  7.41M|    uint64_t d4 = (uint64_t)2U * d419;
  505|  7.41M|    FStar_UInt128_uint128
  506|  7.41M|        s0 =
  507|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(f20, f20),
  508|  7.41M|                                                FStar_UInt128_mul_wide(d4, f21)),
  509|  7.41M|                              FStar_UInt128_mul_wide(d2, f23));
  510|  7.41M|    FStar_UInt128_uint128
  511|  7.41M|        s1 =
  512|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f21),
  513|  7.41M|                                                FStar_UInt128_mul_wide(d4, f22)),
  514|  7.41M|                              FStar_UInt128_mul_wide(d3, f23));
  515|  7.41M|    FStar_UInt128_uint128
  516|  7.41M|        s2 =
  517|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f22),
  518|  7.41M|                                                FStar_UInt128_mul_wide(f21, f21)),
  519|  7.41M|                              FStar_UInt128_mul_wide(d4, f23));
  520|  7.41M|    FStar_UInt128_uint128
  521|  7.41M|        s3 =
  522|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f23),
  523|  7.41M|                                                FStar_UInt128_mul_wide(d1, f22)),
  524|  7.41M|                              FStar_UInt128_mul_wide(f24, d419));
  525|  7.41M|    FStar_UInt128_uint128
  526|  7.41M|        s4 =
  527|  7.41M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(d0, f24),
  528|  7.41M|                                                FStar_UInt128_mul_wide(d1, f23)),
  529|  7.41M|                              FStar_UInt128_mul_wide(f22, f22));
  530|  7.41M|    FStar_UInt128_uint128 o200 = s0;
  531|  7.41M|    FStar_UInt128_uint128 o210 = s1;
  532|  7.41M|    FStar_UInt128_uint128 o220 = s2;
  533|  7.41M|    FStar_UInt128_uint128 o230 = s3;
  534|  7.41M|    FStar_UInt128_uint128 o240 = s4;
  535|  7.41M|    FStar_UInt128_uint128
  536|  7.41M|        l_ = FStar_UInt128_add(o100, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  537|  7.41M|    uint64_t tmp00 = FStar_UInt128_uint128_to_uint64(l_) & (uint64_t)0x7ffffffffffffU;
  538|  7.41M|    uint64_t c00 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_, (uint32_t)51U));
  539|  7.41M|    FStar_UInt128_uint128 l_0 = FStar_UInt128_add(o110, FStar_UInt128_uint64_to_uint128(c00));
  540|  7.41M|    uint64_t tmp10 = FStar_UInt128_uint128_to_uint64(l_0) & (uint64_t)0x7ffffffffffffU;
  541|  7.41M|    uint64_t c10 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_0, (uint32_t)51U));
  542|  7.41M|    FStar_UInt128_uint128 l_1 = FStar_UInt128_add(o120, FStar_UInt128_uint64_to_uint128(c10));
  543|  7.41M|    uint64_t tmp20 = FStar_UInt128_uint128_to_uint64(l_1) & (uint64_t)0x7ffffffffffffU;
  544|  7.41M|    uint64_t c20 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_1, (uint32_t)51U));
  545|  7.41M|    FStar_UInt128_uint128 l_2 = FStar_UInt128_add(o130, FStar_UInt128_uint64_to_uint128(c20));
  546|  7.41M|    uint64_t tmp30 = FStar_UInt128_uint128_to_uint64(l_2) & (uint64_t)0x7ffffffffffffU;
  547|  7.41M|    uint64_t c30 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_2, (uint32_t)51U));
  548|  7.41M|    FStar_UInt128_uint128 l_3 = FStar_UInt128_add(o140, FStar_UInt128_uint64_to_uint128(c30));
  549|  7.41M|    uint64_t tmp40 = FStar_UInt128_uint128_to_uint64(l_3) & (uint64_t)0x7ffffffffffffU;
  550|  7.41M|    uint64_t c40 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_3, (uint32_t)51U));
  551|  7.41M|    uint64_t l_4 = tmp00 + c40 * (uint64_t)19U;
  552|  7.41M|    uint64_t tmp0_ = l_4 & (uint64_t)0x7ffffffffffffU;
  553|  7.41M|    uint64_t c50 = l_4 >> (uint32_t)51U;
  554|  7.41M|    uint64_t o101 = tmp0_;
  555|  7.41M|    uint64_t o111 = tmp10 + c50;
  556|  7.41M|    uint64_t o121 = tmp20;
  557|  7.41M|    uint64_t o131 = tmp30;
  558|  7.41M|    uint64_t o141 = tmp40;
  559|  7.41M|    FStar_UInt128_uint128
  560|  7.41M|        l_5 = FStar_UInt128_add(o200, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  561|  7.41M|    uint64_t tmp0 = FStar_UInt128_uint128_to_uint64(l_5) & (uint64_t)0x7ffffffffffffU;
  562|  7.41M|    uint64_t c0 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_5, (uint32_t)51U));
  563|  7.41M|    FStar_UInt128_uint128 l_6 = FStar_UInt128_add(o210, FStar_UInt128_uint64_to_uint128(c0));
  564|  7.41M|    uint64_t tmp1 = FStar_UInt128_uint128_to_uint64(l_6) & (uint64_t)0x7ffffffffffffU;
  565|  7.41M|    uint64_t c1 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_6, (uint32_t)51U));
  566|  7.41M|    FStar_UInt128_uint128 l_7 = FStar_UInt128_add(o220, FStar_UInt128_uint64_to_uint128(c1));
  567|  7.41M|    uint64_t tmp2 = FStar_UInt128_uint128_to_uint64(l_7) & (uint64_t)0x7ffffffffffffU;
  568|  7.41M|    uint64_t c2 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_7, (uint32_t)51U));
  569|  7.41M|    FStar_UInt128_uint128 l_8 = FStar_UInt128_add(o230, FStar_UInt128_uint64_to_uint128(c2));
  570|  7.41M|    uint64_t tmp3 = FStar_UInt128_uint128_to_uint64(l_8) & (uint64_t)0x7ffffffffffffU;
  571|  7.41M|    uint64_t c3 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_8, (uint32_t)51U));
  572|  7.41M|    FStar_UInt128_uint128 l_9 = FStar_UInt128_add(o240, FStar_UInt128_uint64_to_uint128(c3));
  573|  7.41M|    uint64_t tmp4 = FStar_UInt128_uint128_to_uint64(l_9) & (uint64_t)0x7ffffffffffffU;
  574|  7.41M|    uint64_t c4 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_9, (uint32_t)51U));
  575|  7.41M|    uint64_t l_10 = tmp0 + c4 * (uint64_t)19U;
  576|  7.41M|    uint64_t tmp0_0 = l_10 & (uint64_t)0x7ffffffffffffU;
  577|  7.41M|    uint64_t c5 = l_10 >> (uint32_t)51U;
  578|  7.41M|    uint64_t o201 = tmp0_0;
  579|  7.41M|    uint64_t o211 = tmp1 + c5;
  580|  7.41M|    uint64_t o221 = tmp2;
  581|  7.41M|    uint64_t o231 = tmp3;
  582|  7.41M|    uint64_t o241 = tmp4;
  583|  7.41M|    uint64_t o10 = o101;
  584|  7.41M|    uint64_t o11 = o111;
  585|  7.41M|    uint64_t o12 = o121;
  586|  7.41M|    uint64_t o13 = o131;
  587|  7.41M|    uint64_t o14 = o141;
  588|  7.41M|    uint64_t o20 = o201;
  589|  7.41M|    uint64_t o21 = o211;
  590|  7.41M|    uint64_t o22 = o221;
  591|  7.41M|    uint64_t o23 = o231;
  592|  7.41M|    uint64_t o24 = o241;
  593|  7.41M|    out[0U] = o10;
  594|  7.41M|    out[1U] = o11;
  595|  7.41M|    out[2U] = o12;
  596|  7.41M|    out[3U] = o13;
  597|  7.41M|    out[4U] = o14;
  598|  7.41M|    out[5U] = o20;
  599|  7.41M|    out[6U] = o21;
  600|  7.41M|    out[7U] = o22;
  601|  7.41M|    out[8U] = o23;
  602|  7.41M|    out[9U] = o24;
  603|  7.41M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_fmul1:
  331|  3.72M|{
  332|  3.72M|    uint64_t f10 = f1[0U];
  333|  3.72M|    uint64_t f11 = f1[1U];
  334|  3.72M|    uint64_t f12 = f1[2U];
  335|  3.72M|    uint64_t f13 = f1[3U];
  336|  3.72M|    uint64_t f14 = f1[4U];
  337|  3.72M|    FStar_UInt128_uint128 tmp_w0 = FStar_UInt128_mul_wide(f2, f10);
  338|  3.72M|    FStar_UInt128_uint128 tmp_w1 = FStar_UInt128_mul_wide(f2, f11);
  339|  3.72M|    FStar_UInt128_uint128 tmp_w2 = FStar_UInt128_mul_wide(f2, f12);
  340|  3.72M|    FStar_UInt128_uint128 tmp_w3 = FStar_UInt128_mul_wide(f2, f13);
  341|  3.72M|    FStar_UInt128_uint128 tmp_w4 = FStar_UInt128_mul_wide(f2, f14);
  342|  3.72M|    FStar_UInt128_uint128
  343|  3.72M|        l_ = FStar_UInt128_add(tmp_w0, FStar_UInt128_uint64_to_uint128((uint64_t)0U));
  344|  3.72M|    uint64_t tmp0 = FStar_UInt128_uint128_to_uint64(l_) & (uint64_t)0x7ffffffffffffU;
  345|  3.72M|    uint64_t c0 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_, (uint32_t)51U));
  346|  3.72M|    FStar_UInt128_uint128 l_0 = FStar_UInt128_add(tmp_w1, FStar_UInt128_uint64_to_uint128(c0));
  347|  3.72M|    uint64_t tmp1 = FStar_UInt128_uint128_to_uint64(l_0) & (uint64_t)0x7ffffffffffffU;
  348|  3.72M|    uint64_t c1 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_0, (uint32_t)51U));
  349|  3.72M|    FStar_UInt128_uint128 l_1 = FStar_UInt128_add(tmp_w2, FStar_UInt128_uint64_to_uint128(c1));
  350|  3.72M|    uint64_t tmp2 = FStar_UInt128_uint128_to_uint64(l_1) & (uint64_t)0x7ffffffffffffU;
  351|  3.72M|    uint64_t c2 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_1, (uint32_t)51U));
  352|  3.72M|    FStar_UInt128_uint128 l_2 = FStar_UInt128_add(tmp_w3, FStar_UInt128_uint64_to_uint128(c2));
  353|  3.72M|    uint64_t tmp3 = FStar_UInt128_uint128_to_uint64(l_2) & (uint64_t)0x7ffffffffffffU;
  354|  3.72M|    uint64_t c3 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_2, (uint32_t)51U));
  355|  3.72M|    FStar_UInt128_uint128 l_3 = FStar_UInt128_add(tmp_w4, FStar_UInt128_uint64_to_uint128(c3));
  356|  3.72M|    uint64_t tmp4 = FStar_UInt128_uint128_to_uint64(l_3) & (uint64_t)0x7ffffffffffffU;
  357|  3.72M|    uint64_t c4 = FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(l_3, (uint32_t)51U));
  358|  3.72M|    uint64_t l_4 = tmp0 + c4 * (uint64_t)19U;
  359|  3.72M|    uint64_t tmp0_ = l_4 & (uint64_t)0x7ffffffffffffU;
  360|  3.72M|    uint64_t c5 = l_4 >> (uint32_t)51U;
  361|  3.72M|    uint64_t o0 = tmp0_;
  362|  3.72M|    uint64_t o1 = tmp1 + c5;
  363|  3.72M|    uint64_t o2 = tmp2;
  364|  3.72M|    uint64_t o3 = tmp3;
  365|  3.72M|    uint64_t o4 = tmp4;
  366|  3.72M|    out[0U] = o0;
  367|  3.72M|    out[1U] = o1;
  368|  3.72M|    out[2U] = o2;
  369|  3.72M|    out[3U] = o3;
  370|  3.72M|    out[4U] = o4;
  371|  3.72M|}
Hacl_Curve25519_51.c:Hacl_Impl_Curve25519_Field51_store_felem:
  607|  14.6k|{
  608|  14.6k|    uint64_t f0 = f[0U];
  609|  14.6k|    uint64_t f1 = f[1U];
  610|  14.6k|    uint64_t f2 = f[2U];
  611|  14.6k|    uint64_t f3 = f[3U];
  612|  14.6k|    uint64_t f4 = f[4U];
  613|  14.6k|    uint64_t l_ = f0 + (uint64_t)0U;
  614|  14.6k|    uint64_t tmp0 = l_ & (uint64_t)0x7ffffffffffffU;
  615|  14.6k|    uint64_t c0 = l_ >> (uint32_t)51U;
  616|  14.6k|    uint64_t l_0 = f1 + c0;
  617|  14.6k|    uint64_t tmp1 = l_0 & (uint64_t)0x7ffffffffffffU;
  618|  14.6k|    uint64_t c1 = l_0 >> (uint32_t)51U;
  619|  14.6k|    uint64_t l_1 = f2 + c1;
  620|  14.6k|    uint64_t tmp2 = l_1 & (uint64_t)0x7ffffffffffffU;
  621|  14.6k|    uint64_t c2 = l_1 >> (uint32_t)51U;
  622|  14.6k|    uint64_t l_2 = f3 + c2;
  623|  14.6k|    uint64_t tmp3 = l_2 & (uint64_t)0x7ffffffffffffU;
  624|  14.6k|    uint64_t c3 = l_2 >> (uint32_t)51U;
  625|  14.6k|    uint64_t l_3 = f4 + c3;
  626|  14.6k|    uint64_t tmp4 = l_3 & (uint64_t)0x7ffffffffffffU;
  627|  14.6k|    uint64_t c4 = l_3 >> (uint32_t)51U;
  628|  14.6k|    uint64_t l_4 = tmp0 + c4 * (uint64_t)19U;
  629|  14.6k|    uint64_t tmp0_ = l_4 & (uint64_t)0x7ffffffffffffU;
  630|  14.6k|    uint64_t c5 = l_4 >> (uint32_t)51U;
  631|  14.6k|    uint64_t f01 = tmp0_;
  632|  14.6k|    uint64_t f11 = tmp1 + c5;
  633|  14.6k|    uint64_t f21 = tmp2;
  634|  14.6k|    uint64_t f31 = tmp3;
  635|  14.6k|    uint64_t f41 = tmp4;
  636|  14.6k|    uint64_t m0 = FStar_UInt64_gte_mask(f01, (uint64_t)0x7ffffffffffedU);
  637|  14.6k|    uint64_t m1 = FStar_UInt64_eq_mask(f11, (uint64_t)0x7ffffffffffffU);
  638|  14.6k|    uint64_t m2 = FStar_UInt64_eq_mask(f21, (uint64_t)0x7ffffffffffffU);
  639|  14.6k|    uint64_t m3 = FStar_UInt64_eq_mask(f31, (uint64_t)0x7ffffffffffffU);
  640|  14.6k|    uint64_t m4 = FStar_UInt64_eq_mask(f41, (uint64_t)0x7ffffffffffffU);
  641|  14.6k|    uint64_t mask = (((m0 & m1) & m2) & m3) & m4;
  642|  14.6k|    uint64_t f0_ = f01 - (mask & (uint64_t)0x7ffffffffffedU);
  643|  14.6k|    uint64_t f1_ = f11 - (mask & (uint64_t)0x7ffffffffffffU);
  644|  14.6k|    uint64_t f2_ = f21 - (mask & (uint64_t)0x7ffffffffffffU);
  645|  14.6k|    uint64_t f3_ = f31 - (mask & (uint64_t)0x7ffffffffffffU);
  646|  14.6k|    uint64_t f4_ = f41 - (mask & (uint64_t)0x7ffffffffffffU);
  647|  14.6k|    uint64_t f02 = f0_;
  648|  14.6k|    uint64_t f12 = f1_;
  649|  14.6k|    uint64_t f22 = f2_;
  650|  14.6k|    uint64_t f32 = f3_;
  651|  14.6k|    uint64_t f42 = f4_;
  652|  14.6k|    uint64_t o00 = f02 | f12 << (uint32_t)51U;
  653|  14.6k|    uint64_t o10 = f12 >> (uint32_t)13U | f22 << (uint32_t)38U;
  654|  14.6k|    uint64_t o20 = f22 >> (uint32_t)26U | f32 << (uint32_t)25U;
  655|  14.6k|    uint64_t o30 = f32 >> (uint32_t)39U | f42 << (uint32_t)12U;
  656|  14.6k|    uint64_t o0 = o00;
  657|  14.6k|    uint64_t o1 = o10;
  658|  14.6k|    uint64_t o2 = o20;
  659|  14.6k|    uint64_t o3 = o30;
  660|  14.6k|    u64s[0U] = o0;
  661|  14.6k|    u64s[1U] = o1;
  662|  14.6k|    u64s[2U] = o2;
  663|  14.6k|    u64s[3U] = o3;
  664|  14.6k|}

Hacl_P256.c:Hacl_Bignum_Base_mul_wide_add2_u64:
   53|  2.44G|{
   54|  2.44G|    uint64_t out0 = out[0U];
   55|  2.44G|    FStar_UInt128_uint128
   56|  2.44G|        res =
   57|  2.44G|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(a, b),
   58|  2.44G|                                                FStar_UInt128_uint64_to_uint128(c_in)),
   59|  2.44G|                              FStar_UInt128_uint64_to_uint128(out0));
   60|  2.44G|    out[0U] = FStar_UInt128_uint128_to_uint64(res);
   61|  2.44G|    return FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(res, (uint32_t)64U));
   62|  2.44G|}
Hacl_P256.c:Hacl_Bignum_Addition_bn_add_eq_len_u64:
  242|  41.4M|{
  243|  41.4M|    uint64_t c = (uint64_t)0U;
  244|   124M|    for (uint32_t i = (uint32_t)0U; i < aLen / (uint32_t)4U; i++) {
  ------------------
  |  Branch (244:37): [True: 82.9M, False: 41.4M]
  ------------------
  245|  82.9M|        uint64_t t1 = a[(uint32_t)4U * i];
  246|  82.9M|        uint64_t t20 = b[(uint32_t)4U * i];
  247|  82.9M|        uint64_t *res_i0 = res + (uint32_t)4U * i;
  248|  82.9M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t20, res_i0);
  ------------------
  |  |   66|  82.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  249|  82.9M|        uint64_t t10 = a[(uint32_t)4U * i + (uint32_t)1U];
  250|  82.9M|        uint64_t t21 = b[(uint32_t)4U * i + (uint32_t)1U];
  251|  82.9M|        uint64_t *res_i1 = res + (uint32_t)4U * i + (uint32_t)1U;
  252|  82.9M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t10, t21, res_i1);
  ------------------
  |  |   66|  82.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  253|  82.9M|        uint64_t t11 = a[(uint32_t)4U * i + (uint32_t)2U];
  254|  82.9M|        uint64_t t22 = b[(uint32_t)4U * i + (uint32_t)2U];
  255|  82.9M|        uint64_t *res_i2 = res + (uint32_t)4U * i + (uint32_t)2U;
  256|  82.9M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t11, t22, res_i2);
  ------------------
  |  |   66|  82.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  257|  82.9M|        uint64_t t12 = a[(uint32_t)4U * i + (uint32_t)3U];
  258|  82.9M|        uint64_t t2 = b[(uint32_t)4U * i + (uint32_t)3U];
  259|  82.9M|        uint64_t *res_i = res + (uint32_t)4U * i + (uint32_t)3U;
  260|  82.9M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t12, t2, res_i);
  ------------------
  |  |   66|  82.9M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  261|  82.9M|    }
  262|  41.4M|    for (uint32_t i = aLen / (uint32_t)4U * (uint32_t)4U; i < aLen; i++) {
  ------------------
  |  Branch (262:59): [True: 0, False: 41.4M]
  ------------------
  263|      0|        uint64_t t1 = a[i];
  264|      0|        uint64_t t2 = b[i];
  265|      0|        uint64_t *res_i = res + i;
  266|      0|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t2, res_i);
  ------------------
  |  |   66|      0|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  267|      0|    }
  268|  41.4M|    return c;
  269|  41.4M|}
Hacl_P256.c:Hacl_Bignum_Lib_bn_get_bits_u64:
  134|  1.83M|{
  135|  1.83M|    uint32_t i1 = i / (uint32_t)64U;
  136|  1.83M|    uint32_t j = i % (uint32_t)64U;
  137|  1.83M|    uint64_t p1 = b[i1] >> j;
  138|  1.83M|    uint64_t ite;
  139|  1.83M|    if (i1 + (uint32_t)1U < len && (uint32_t)0U < j) {
  ------------------
  |  Branch (139:9): [True: 394k, False: 1.44M]
  |  Branch (139:36): [True: 369k, False: 24.6k]
  ------------------
  140|   369k|        ite = p1 | b[i1 + (uint32_t)1U] << ((uint32_t)64U - j);
  141|  1.46M|    } else {
  142|  1.46M|        ite = p1;
  143|  1.46M|    }
  144|  1.83M|    return ite & (((uint64_t)1U << l) - (uint64_t)1U);
  145|  1.83M|}
Hacl_P384.c:Hacl_Bignum_Base_mul_wide_add2_u64:
   53|  1.88G|{
   54|  1.88G|    uint64_t out0 = out[0U];
   55|  1.88G|    FStar_UInt128_uint128
   56|  1.88G|        res =
   57|  1.88G|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(a, b),
   58|  1.88G|                                                FStar_UInt128_uint64_to_uint128(c_in)),
   59|  1.88G|                              FStar_UInt128_uint64_to_uint128(out0));
   60|  1.88G|    out[0U] = FStar_UInt128_uint128_to_uint64(res);
   61|  1.88G|    return FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(res, (uint32_t)64U));
   62|  1.88G|}
Hacl_P384.c:Hacl_Bignum_Addition_bn_add_eq_len_u64:
  242|  12.5M|{
  243|  12.5M|    uint64_t c = (uint64_t)0U;
  244|  50.2M|    for (uint32_t i = (uint32_t)0U; i < aLen / (uint32_t)4U; i++) {
  ------------------
  |  Branch (244:37): [True: 37.6M, False: 12.5M]
  ------------------
  245|  37.6M|        uint64_t t1 = a[(uint32_t)4U * i];
  246|  37.6M|        uint64_t t20 = b[(uint32_t)4U * i];
  247|  37.6M|        uint64_t *res_i0 = res + (uint32_t)4U * i;
  248|  37.6M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t20, res_i0);
  ------------------
  |  |   66|  37.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  249|  37.6M|        uint64_t t10 = a[(uint32_t)4U * i + (uint32_t)1U];
  250|  37.6M|        uint64_t t21 = b[(uint32_t)4U * i + (uint32_t)1U];
  251|  37.6M|        uint64_t *res_i1 = res + (uint32_t)4U * i + (uint32_t)1U;
  252|  37.6M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t10, t21, res_i1);
  ------------------
  |  |   66|  37.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  253|  37.6M|        uint64_t t11 = a[(uint32_t)4U * i + (uint32_t)2U];
  254|  37.6M|        uint64_t t22 = b[(uint32_t)4U * i + (uint32_t)2U];
  255|  37.6M|        uint64_t *res_i2 = res + (uint32_t)4U * i + (uint32_t)2U;
  256|  37.6M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t11, t22, res_i2);
  ------------------
  |  |   66|  37.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  257|  37.6M|        uint64_t t12 = a[(uint32_t)4U * i + (uint32_t)3U];
  258|  37.6M|        uint64_t t2 = b[(uint32_t)4U * i + (uint32_t)3U];
  259|  37.6M|        uint64_t *res_i = res + (uint32_t)4U * i + (uint32_t)3U;
  260|  37.6M|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t12, t2, res_i);
  ------------------
  |  |   66|  37.6M|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  261|  37.6M|    }
  262|  12.5M|    for (uint32_t i = aLen / (uint32_t)4U * (uint32_t)4U; i < aLen; i++) {
  ------------------
  |  Branch (262:59): [True: 0, False: 12.5M]
  ------------------
  263|      0|        uint64_t t1 = a[i];
  264|      0|        uint64_t t2 = b[i];
  265|      0|        uint64_t *res_i = res + i;
  266|      0|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t2, res_i);
  ------------------
  |  |   66|      0|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  267|      0|    }
  268|  12.5M|    return c;
  269|  12.5M|}
Hacl_P384.c:Hacl_Bignum_Lib_bn_get_bits_u64:
  134|   691k|{
  135|   691k|    uint32_t i1 = i / (uint32_t)64U;
  136|   691k|    uint32_t j = i % (uint32_t)64U;
  137|   691k|    uint64_t p1 = b[i1] >> j;
  138|   691k|    uint64_t ite;
  139|   691k|    if (i1 + (uint32_t)1U < len && (uint32_t)0U < j) {
  ------------------
  |  Branch (139:9): [True: 575k, False: 115k]
  |  Branch (139:36): [True: 551k, False: 23.9k]
  ------------------
  140|   551k|        ite = p1 | b[i1 + (uint32_t)1U] << ((uint32_t)64U - j);
  141|   551k|    } else {
  142|   139k|        ite = p1;
  143|   139k|    }
  144|   691k|    return ite & (((uint64_t)1U << l) - (uint64_t)1U);
  145|   691k|}
Hacl_P521.c:Hacl_Bignum_Base_mul_wide_add2_u64:
   53|  74.5M|{
   54|  74.5M|    uint64_t out0 = out[0U];
   55|  74.5M|    FStar_UInt128_uint128
   56|  74.5M|        res =
   57|  74.5M|            FStar_UInt128_add(FStar_UInt128_add(FStar_UInt128_mul_wide(a, b),
   58|  74.5M|                                                FStar_UInt128_uint64_to_uint128(c_in)),
   59|  74.5M|                              FStar_UInt128_uint64_to_uint128(out0));
   60|  74.5M|    out[0U] = FStar_UInt128_uint128_to_uint64(res);
   61|  74.5M|    return FStar_UInt128_uint128_to_uint64(FStar_UInt128_shift_right(res, (uint32_t)64U));
   62|  74.5M|}
Hacl_P521.c:Hacl_Bignum_Addition_bn_add_eq_len_u64:
  242|   220k|{
  243|   220k|    uint64_t c = (uint64_t)0U;
  244|  1.10M|    for (uint32_t i = (uint32_t)0U; i < aLen / (uint32_t)4U; i++) {
  ------------------
  |  Branch (244:37): [True: 881k, False: 220k]
  ------------------
  245|   881k|        uint64_t t1 = a[(uint32_t)4U * i];
  246|   881k|        uint64_t t20 = b[(uint32_t)4U * i];
  247|   881k|        uint64_t *res_i0 = res + (uint32_t)4U * i;
  248|   881k|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t20, res_i0);
  ------------------
  |  |   66|   881k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  249|   881k|        uint64_t t10 = a[(uint32_t)4U * i + (uint32_t)1U];
  250|   881k|        uint64_t t21 = b[(uint32_t)4U * i + (uint32_t)1U];
  251|   881k|        uint64_t *res_i1 = res + (uint32_t)4U * i + (uint32_t)1U;
  252|   881k|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t10, t21, res_i1);
  ------------------
  |  |   66|   881k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  253|   881k|        uint64_t t11 = a[(uint32_t)4U * i + (uint32_t)2U];
  254|   881k|        uint64_t t22 = b[(uint32_t)4U * i + (uint32_t)2U];
  255|   881k|        uint64_t *res_i2 = res + (uint32_t)4U * i + (uint32_t)2U;
  256|   881k|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t11, t22, res_i2);
  ------------------
  |  |   66|   881k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  257|   881k|        uint64_t t12 = a[(uint32_t)4U * i + (uint32_t)3U];
  258|   881k|        uint64_t t2 = b[(uint32_t)4U * i + (uint32_t)3U];
  259|   881k|        uint64_t *res_i = res + (uint32_t)4U * i + (uint32_t)3U;
  260|   881k|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t12, t2, res_i);
  ------------------
  |  |   66|   881k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  261|   881k|    }
  262|   661k|    for (uint32_t i = aLen / (uint32_t)4U * (uint32_t)4U; i < aLen; i++) {
  ------------------
  |  Branch (262:59): [True: 440k, False: 220k]
  ------------------
  263|   440k|        uint64_t t1 = a[i];
  264|   440k|        uint64_t t2 = b[i];
  265|   440k|        uint64_t *res_i = res + i;
  266|   440k|        c = Lib_IntTypes_Intrinsics_add_carry_u64(c, t1, t2, res_i);
  ------------------
  |  |   66|   440k|    (_addcarry_u64(x1, x2, x3, (long long unsigned int *)x4))
  ------------------
  267|   440k|    }
  268|   220k|    return c;
  269|   220k|}
Hacl_P521.c:Hacl_Bignum_Lib_bn_get_bits_u64:
  134|  12.2k|{
  135|  12.2k|    uint32_t i1 = i / (uint32_t)64U;
  136|  12.2k|    uint32_t j = i % (uint32_t)64U;
  137|  12.2k|    uint64_t p1 = b[i1] >> j;
  138|  12.2k|    uint64_t ite;
  139|  12.2k|    if (i1 + (uint32_t)1U < len && (uint32_t)0U < j) {
  ------------------
  |  Branch (139:9): [True: 12.0k, False: 260]
  |  Branch (139:36): [True: 11.4k, False: 520]
  ------------------
  140|  11.4k|        ite = p1 | b[i1 + (uint32_t)1U] << ((uint32_t)64U - j);
  141|  11.4k|    } else {
  142|    780|        ite = p1;
  143|    780|    }
  144|  12.2k|    return ite & (((uint64_t)1U << l) - (uint64_t)1U);
  145|  12.2k|}

libcrux_mlkem_portable.c:libcrux_sha3_portable_incremental_shake128_init:
   32|    747|{
   33|    747|    return libcrux_sha3_generic_keccak_new_1e_cf();
   34|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_incremental_shake128_absorb_final:
   42|    747|{
   43|    747|    Eurydice_slice buf[1U] = { data0 };
   44|    747|    libcrux_sha3_generic_keccak_absorb_final_40(s, buf);
   45|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_incremental_shake128_squeeze_first_three_blocks:
   92|    747|{
   93|    747|    Eurydice_slice buf[1U] = { out0 };
   94|    747|    libcrux_sha3_generic_keccak_squeeze_first_three_blocks_5c(s, buf);
   95|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_squeeze_first_three_blocks_5c:
   68|    747|{
   69|    747|    Eurydice_slice_uint8_t_1size_t__x2 uu____0 =
   70|    747|        libcrux_sha3_portable_keccak_split_at_mut_n_5a(out, (size_t)168U);
   71|    747|    Eurydice_slice o0[1U];
   72|    747|    memcpy(o0, uu____0.fst, (size_t)1U * sizeof(Eurydice_slice));
   73|    747|    Eurydice_slice o10[1U];
   74|    747|    memcpy(o10, uu____0.snd, (size_t)1U * sizeof(Eurydice_slice));
   75|    747|    libcrux_sha3_generic_keccak_squeeze_first_block_7b(s, o0);
   76|    747|    Eurydice_slice_uint8_t_1size_t__x2 uu____1 =
   77|    747|        libcrux_sha3_portable_keccak_split_at_mut_n_5a(o10, (size_t)168U);
   78|    747|    Eurydice_slice o1[1U];
   79|    747|    memcpy(o1, uu____1.fst, (size_t)1U * sizeof(Eurydice_slice));
   80|    747|    Eurydice_slice o2[1U];
   81|    747|    memcpy(o2, uu____1.snd, (size_t)1U * sizeof(Eurydice_slice));
   82|    747|    libcrux_sha3_generic_keccak_squeeze_next_block_c2(s, o1);
   83|    747|    libcrux_sha3_generic_keccak_squeeze_next_block_c2(s, o2);
   84|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_incremental_shake128_squeeze_next_block:
   53|    240|{
   54|    240|    Eurydice_slice buf[1U] = { out0 };
   55|    240|    libcrux_sha3_generic_keccak_squeeze_next_block_c2(s, buf);
   56|    240|}

libcrux_mlkem_portable.c:load64:
  178|  39.0k|{
  179|  39.0k|    uint64_t x;
  180|  39.0k|    memcpy(&x, b, 8);
  181|  39.0k|    return x;
  182|  39.0k|}
libcrux_mlkem_portable.c:store64:
  198|  64.1k|{
  199|  64.1k|    memcpy(b, &i, 8);
  200|  64.1k|}
Hacl_P256.c:load64:
  178|   492k|{
  179|   492k|    uint64_t x;
  180|   492k|    memcpy(&x, b, 8);
  181|   492k|    return x;
  182|   492k|}
Hacl_P256.c:store64:
  198|   229k|{
  199|   229k|    memcpy(b, &i, 8);
  200|   229k|}
Hacl_P384.c:load64:
  178|   108k|{
  179|   108k|    uint64_t x;
  180|   108k|    memcpy(&x, b, 8);
  181|   108k|    return x;
  182|   108k|}
Hacl_P384.c:store64:
  198|  47.9k|{
  199|  47.9k|    memcpy(b, &i, 8);
  200|  47.9k|}
Hacl_P521.c:load64:
  178|  2.79k|{
  179|  2.79k|    uint64_t x;
  180|  2.79k|    memcpy(&x, b, 8);
  181|  2.79k|    return x;
  182|  2.79k|}
Hacl_P521.c:store64:
  198|    936|{
  199|    936|    memcpy(b, &i, 8);
  200|    936|}
Hacl_Chacha20.c:load32:
  170|  7.40M|{
  171|  7.40M|    uint32_t x;
  172|  7.40M|    memcpy(&x, b, 4);
  173|  7.40M|    return x;
  174|  7.40M|}
Hacl_Chacha20.c:store32:
  192|  4.38M|{
  193|  4.38M|    memcpy(b, &i, 4);
  194|  4.38M|}
Hacl_Curve25519_51.c:load64:
  178|  58.4k|{
  179|  58.4k|    uint64_t x;
  180|  58.4k|    memcpy(&x, b, 8);
  181|  58.4k|    return x;
  182|  58.4k|}
Hacl_Curve25519_51.c:store64:
  198|  58.4k|{
  199|  58.4k|    memcpy(b, &i, 8);
  200|  58.4k|}

Hacl_P256.c:FStar_UInt64_eq_mask:
   36|  27.9M|{
   37|  27.9M|    uint64_t x = a ^ b;
   38|  27.9M|    uint64_t minus_x = ~x + (uint64_t)1U;
   39|  27.9M|    uint64_t x_or_minus_x = x | minus_x;
   40|  27.9M|    uint64_t xnx = x_or_minus_x >> (uint32_t)63U;
   41|  27.9M|    return xnx - (uint64_t)1U;
   42|  27.9M|}
Hacl_P384.c:FStar_UInt64_gte_mask:
   46|  18.0k|{
   47|  18.0k|    uint64_t x = a;
   48|  18.0k|    uint64_t y = b;
   49|  18.0k|    uint64_t x_xor_y = x ^ y;
   50|  18.0k|    uint64_t x_sub_y = x - y;
   51|  18.0k|    uint64_t x_sub_y_xor_y = x_sub_y ^ y;
   52|  18.0k|    uint64_t q = x_xor_y | x_sub_y_xor_y;
   53|  18.0k|    uint64_t x_xor_q = x ^ q;
   54|  18.0k|    uint64_t x_xor_q_ = x_xor_q >> (uint32_t)63U;
   55|  18.0k|    return x_xor_q_ - (uint64_t)1U;
   56|  18.0k|}
Hacl_P384.c:FStar_UInt64_eq_mask:
   36|  15.3M|{
   37|  15.3M|    uint64_t x = a ^ b;
   38|  15.3M|    uint64_t minus_x = ~x + (uint64_t)1U;
   39|  15.3M|    uint64_t x_or_minus_x = x | minus_x;
   40|  15.3M|    uint64_t xnx = x_or_minus_x >> (uint32_t)63U;
   41|  15.3M|    return xnx - (uint64_t)1U;
   42|  15.3M|}
Hacl_P521.c:FStar_UInt64_gte_mask:
   46|    310|{
   47|    310|    uint64_t x = a;
   48|    310|    uint64_t y = b;
   49|    310|    uint64_t x_xor_y = x ^ y;
   50|    310|    uint64_t x_sub_y = x - y;
   51|    310|    uint64_t x_sub_y_xor_y = x_sub_y ^ y;
   52|    310|    uint64_t q = x_xor_y | x_sub_y_xor_y;
   53|    310|    uint64_t x_xor_q = x ^ q;
   54|    310|    uint64_t x_xor_q_ = x_xor_q >> (uint32_t)63U;
   55|    310|    return x_xor_q_ - (uint64_t)1U;
   56|    310|}
Hacl_P521.c:FStar_UInt64_eq_mask:
   36|   273k|{
   37|   273k|    uint64_t x = a ^ b;
   38|   273k|    uint64_t minus_x = ~x + (uint64_t)1U;
   39|   273k|    uint64_t x_or_minus_x = x | minus_x;
   40|   273k|    uint64_t xnx = x_or_minus_x >> (uint32_t)63U;
   41|   273k|    return xnx - (uint64_t)1U;
   42|   273k|}
Hacl_Curve25519_51.c:FStar_UInt64_gte_mask:
   46|  14.6k|{
   47|  14.6k|    uint64_t x = a;
   48|  14.6k|    uint64_t y = b;
   49|  14.6k|    uint64_t x_xor_y = x ^ y;
   50|  14.6k|    uint64_t x_sub_y = x - y;
   51|  14.6k|    uint64_t x_sub_y_xor_y = x_sub_y ^ y;
   52|  14.6k|    uint64_t q = x_xor_y | x_sub_y_xor_y;
   53|  14.6k|    uint64_t x_xor_q = x ^ q;
   54|  14.6k|    uint64_t x_xor_q_ = x_xor_q >> (uint32_t)63U;
   55|  14.6k|    return x_xor_q_ - (uint64_t)1U;
   56|  14.6k|}
Hacl_Curve25519_51.c:FStar_UInt64_eq_mask:
   36|  58.4k|{
   37|  58.4k|    uint64_t x = a ^ b;
   38|  58.4k|    uint64_t minus_x = ~x + (uint64_t)1U;
   39|  58.4k|    uint64_t x_or_minus_x = x | minus_x;
   40|  58.4k|    uint64_t xnx = x_or_minus_x >> (uint32_t)63U;
   41|  58.4k|    return xnx - (uint64_t)1U;
   42|  58.4k|}
Hacl_Curve25519_51.c:FStar_UInt8_eq_mask:
  186|   467k|{
  187|   467k|    uint8_t x = a ^ b;
  188|   467k|    uint8_t minus_x = ~x + (uint8_t)1U;
  189|   467k|    uint8_t x_or_minus_x = x | minus_x;
  190|   467k|    uint8_t xnx = x_or_minus_x >> (uint32_t)7U;
  191|   467k|    return xnx - (uint8_t)1U;
  192|   467k|}

Hacl_P256.c:FStar_UInt128_add:
   64|  4.89G|{
   65|  4.89G|    return x + y;
   66|  4.89G|}
Hacl_P256.c:FStar_UInt128_uint64_to_uint128:
  130|  4.89G|{
  131|  4.89G|    return (uint128_t)x;
  132|  4.89G|}
Hacl_P256.c:FStar_UInt128_mul_wide:
  142|  2.53G|{
  143|  2.53G|    return ((uint128_t)x) * y;
  144|  2.53G|}
Hacl_P256.c:FStar_UInt128_uint128_to_uint64:
  136|  5.06G|{
  137|  5.06G|    return (uint64_t)x;
  138|  5.06G|}
Hacl_P256.c:FStar_UInt128_shift_right:
  124|  2.53G|{
  125|  2.53G|    return x >> y;
  126|  2.53G|}
Hacl_P384.c:FStar_UInt128_add:
   64|  3.77G|{
   65|  3.77G|    return x + y;
   66|  3.77G|}
Hacl_P384.c:FStar_UInt128_uint64_to_uint128:
  130|  3.77G|{
  131|  3.77G|    return (uint128_t)x;
  132|  3.77G|}
Hacl_P384.c:FStar_UInt128_mul_wide:
  142|  1.92G|{
  143|  1.92G|    return ((uint128_t)x) * y;
  144|  1.92G|}
Hacl_P384.c:FStar_UInt128_uint128_to_uint64:
  136|  3.85G|{
  137|  3.85G|    return (uint64_t)x;
  138|  3.85G|}
Hacl_P384.c:FStar_UInt128_shift_right:
  124|  1.92G|{
  125|  1.92G|    return x >> y;
  126|  1.92G|}
Hacl_P521.c:FStar_UInt128_add:
   64|   149M|{
   65|   149M|    return x + y;
   66|   149M|}
Hacl_P521.c:FStar_UInt128_uint64_to_uint128:
  130|   149M|{
  131|   149M|    return (uint128_t)x;
  132|   149M|}
Hacl_P521.c:FStar_UInt128_mul_wide:
  142|  75.5M|{
  143|  75.5M|    return ((uint128_t)x) * y;
  144|  75.5M|}
Hacl_P521.c:FStar_UInt128_uint128_to_uint64:
  136|   151M|{
  137|   151M|    return (uint64_t)x;
  138|   151M|}
Hacl_P521.c:FStar_UInt128_shift_right:
  124|  75.5M|{
  125|  75.5M|    return x >> y;
  126|  75.5M|}
Hacl_Curve25519_51.c:FStar_UInt128_add:
   64|   763M|{
   65|   763M|    return x + y;
   66|   763M|}
Hacl_Curve25519_51.c:FStar_UInt128_mul_wide:
  142|   763M|{
  143|   763M|    return ((uint128_t)x) * y;
  144|   763M|}
Hacl_Curve25519_51.c:FStar_UInt128_uint64_to_uint128:
  130|   205M|{
  131|   205M|    return (uint128_t)x;
  132|   205M|}
Hacl_Curve25519_51.c:FStar_UInt128_uint128_to_uint64:
  136|   409M|{
  137|   409M|    return (uint64_t)x;
  138|   409M|}
Hacl_Curve25519_51.c:FStar_UInt128_shift_right:
  124|   204M|{
  125|   204M|    return x >> y;
  126|   204M|}

libcrux_ml_kem_types_from_01_330:
  316|     83|{
  317|       |    /* Passing arrays by value in Rust generates a copy in C */
  318|     83|    uint8_t copy_of_value[1088U];
  319|     83|    memcpy(copy_of_value, value, (size_t)1088U * sizeof(uint8_t));
  320|     83|    libcrux_ml_kem_mlkem768_MlKem768Ciphertext lit;
  321|     83|    memcpy(lit.value, copy_of_value, (size_t)1088U * sizeof(uint8_t));
  322|     83|    return lit;
  323|     83|}
libcrux_ml_kem_types_as_slice_cb_3d0:
  339|    166|{
  340|    166|    return self->value;
  341|    166|}
libcrux_ml_kem_utils_into_padded_array_6d2:
  515|     83|{
  516|     83|    uint8_t out[33U] = { 0U };
  517|     83|    uint8_t *uu____0 = out;
  518|     83|    Eurydice_slice_copy(
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
  519|     83|        Eurydice_array_to_subslice2(uu____0, (size_t)0U,
  520|     83|                                    Eurydice_slice_len(slice, uint8_t), uint8_t),
  521|     83|        slice, uint8_t);
  522|     83|    memcpy(ret, out, (size_t)33U * sizeof(uint8_t));
  523|     83|}
libcrux_ml_kem_utils_into_padded_array_6d1:
  536|     83|{
  537|     83|    uint8_t out[34U] = { 0U };
  538|     83|    uint8_t *uu____0 = out;
  539|     83|    Eurydice_slice_copy(
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
  540|     83|        Eurydice_array_to_subslice2(uu____0, (size_t)0U,
  541|     83|                                    Eurydice_slice_len(slice, uint8_t), uint8_t),
  542|     83|        slice, uint8_t);
  543|     83|    memcpy(ret, out, (size_t)34U * sizeof(uint8_t));
  544|     83|}
libcrux_ml_kem_utils_into_padded_array_6d:
  594|     83|{
  595|     83|    uint8_t out[64U] = { 0U };
  596|     83|    uint8_t *uu____0 = out;
  597|     83|    Eurydice_slice_copy(
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
  598|     83|        Eurydice_array_to_subslice2(uu____0, (size_t)0U,
  599|     83|                                    Eurydice_slice_len(slice, uint8_t), uint8_t),
  600|     83|        slice, uint8_t);
  601|     83|    memcpy(ret, out, (size_t)64U * sizeof(uint8_t));
  602|     83|}
core_result_unwrap_41_30:
  680|  21.2k|{
  681|  21.2k|    if (self.tag == core_result_Ok) {
  ------------------
  |  |   33|  21.2k|#define core_result_Ok 0
  ------------------
  |  Branch (681:9): [True: 21.2k, False: 0]
  ------------------
  682|  21.2k|        int16_t f0[16U];
  683|  21.2k|        memcpy(f0, self.val.case_Ok, (size_t)16U * sizeof(int16_t));
  684|  21.2k|        memcpy(ret, f0, (size_t)16U * sizeof(int16_t));
  685|  21.2k|    } else {
  686|      0|        KRML_HOST_EPRINTF("KaRaMeL abort at %s:%d\n%s\n", __FILE__, __LINE__,
  ------------------
  |  |   34|      0|#define KRML_HOST_EPRINTF(...) fprintf(stderr, __VA_ARGS__)
  ------------------
  687|      0|                          "unwrap not Ok");
  688|      0|        KRML_HOST_EXIT(255U);
  ------------------
  |  |   40|      0|#define KRML_HOST_EXIT exit
  ------------------
  689|      0|    }
  690|  21.2k|}
core_result_unwrap_41_0e:
  702|  39.0k|{
  703|  39.0k|    if (self.tag == core_result_Ok) {
  ------------------
  |  |   33|  39.0k|#define core_result_Ok 0
  ------------------
  |  Branch (703:9): [True: 39.0k, False: 0]
  ------------------
  704|  39.0k|        uint8_t f0[8U];
  705|  39.0k|        memcpy(f0, self.val.case_Ok, (size_t)8U * sizeof(uint8_t));
  706|  39.0k|        memcpy(ret, f0, (size_t)8U * sizeof(uint8_t));
  707|  39.0k|    } else {
  708|      0|        KRML_HOST_EPRINTF("KaRaMeL abort at %s:%d\n%s\n", __FILE__, __LINE__,
  ------------------
  |  |   34|      0|#define KRML_HOST_EPRINTF(...) fprintf(stderr, __VA_ARGS__)
  ------------------
  709|      0|                          "unwrap not Ok");
  710|      0|        KRML_HOST_EXIT(255U);
  ------------------
  |  |   40|      0|#define KRML_HOST_EXIT exit
  ------------------
  711|      0|    }
  712|  39.0k|}

libcrux_ml_kem_mlkem768_portable_encapsulate:
  104|     83|{
  105|     83|    libcrux_ml_kem_types_MlKemPublicKey_15 *uu____0 = public_key;
  106|       |    /* Passing arrays by value in Rust generates a copy in C */
  107|     83|    uint8_t copy_of_randomness[32U];
  108|     83|    memcpy(copy_of_randomness, randomness, (size_t)32U * sizeof(uint8_t));
  109|     83|    return encapsulate_02(uu____0, copy_of_randomness);
  110|     83|}
libcrux_ml_kem_mlkem768_portable_validate_public_key:
  207|     99|{
  208|     99|    return validate_public_key_7d(public_key->value);
  209|     99|}
libcrux_mlkem768_portable.c:encapsulate_02:
   85|     83|{
   86|     83|    libcrux_ml_kem_types_MlKemPublicKey_15 *uu____0 = public_key;
   87|       |    /* Passing arrays by value in Rust generates a copy in C */
   88|     83|    uint8_t copy_of_randomness[32U];
   89|     83|    memcpy(copy_of_randomness, randomness, (size_t)32U * sizeof(uint8_t));
   90|     83|    return libcrux_ml_kem_ind_cca_encapsulate_eb(uu____0, copy_of_randomness);
   91|     83|}
libcrux_mlkem768_portable.c:validate_public_key_7d:
  195|     99|{
  196|     99|    return libcrux_ml_kem_ind_cca_validate_public_key_b7(public_key);
  197|     99|}

libcrux_ml_kem_hash_functions_portable_G:
   22|     83|{
   23|     83|    uint8_t digest[64U] = { 0U };
   24|     83|    libcrux_sha3_portable_sha512(
   25|     83|        Eurydice_array_to_slice((size_t)64U, digest, uint8_t), input);
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
   26|     83|    memcpy(ret, digest, (size_t)64U * sizeof(uint8_t));
   27|     83|}
libcrux_ml_kem_hash_functions_portable_H:
   32|     83|{
   33|     83|    uint8_t digest[32U] = { 0U };
   34|     83|    libcrux_sha3_portable_sha256(
   35|     83|        Eurydice_array_to_slice((size_t)32U, digest, uint8_t), input);
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
   36|     83|    memcpy(ret, digest, (size_t)32U * sizeof(uint8_t));
   37|     83|}
libcrux_ml_kem_vector_portable_vector_type_from_i16_array:
   77|  21.2k|{
   78|  21.2k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector lit;
   79|  21.2k|    int16_t ret[16U];
   80|  21.2k|    core_result_Result_c0 dst;
   81|  21.2k|    Eurydice_slice_to_array2(
  ------------------
  |  |  116|  21.2k|    Eurydice_slice_to_array3(&(dst)->tag, (char *)&(dst)->val.case_Ok, src, \
  |  |  117|  21.2k|                             sizeof(t_arr))
  ------------------
   82|  21.2k|        &dst, Eurydice_slice_subslice2(array, (size_t)0U, (size_t)16U, int16_t),
   83|  21.2k|        Eurydice_slice, int16_t[16U]);
   84|  21.2k|    core_result_unwrap_41_30(dst, ret);
   85|  21.2k|    memcpy(lit.elements, ret, (size_t)16U * sizeof(int16_t));
   86|  21.2k|    return lit;
   87|  21.2k|}
libcrux_ml_kem_vector_portable_from_i16_array_0d:
   95|  21.2k|{
   96|  21.2k|    return libcrux_ml_kem_vector_portable_vector_type_from_i16_array(array);
   97|  21.2k|}
libcrux_ml_kem_vector_portable_vector_type_zero:
  288|   108k|{
  289|   108k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector lit;
  290|   108k|    lit.elements[0U] = (int16_t)0;
  291|   108k|    lit.elements[1U] = (int16_t)0;
  292|   108k|    lit.elements[2U] = (int16_t)0;
  293|   108k|    lit.elements[3U] = (int16_t)0;
  294|   108k|    lit.elements[4U] = (int16_t)0;
  295|   108k|    lit.elements[5U] = (int16_t)0;
  296|   108k|    lit.elements[6U] = (int16_t)0;
  297|   108k|    lit.elements[7U] = (int16_t)0;
  298|   108k|    lit.elements[8U] = (int16_t)0;
  299|   108k|    lit.elements[9U] = (int16_t)0;
  300|   108k|    lit.elements[10U] = (int16_t)0;
  301|   108k|    lit.elements[11U] = (int16_t)0;
  302|   108k|    lit.elements[12U] = (int16_t)0;
  303|   108k|    lit.elements[13U] = (int16_t)0;
  304|   108k|    lit.elements[14U] = (int16_t)0;
  305|   108k|    lit.elements[15U] = (int16_t)0;
  306|   108k|    return lit;
  307|   108k|}
libcrux_ml_kem_vector_portable_ZERO_0d:
  889|  82.5k|{
  890|  82.5k|    return libcrux_ml_kem_vector_portable_vector_type_zero();
  891|  82.5k|}
libcrux_ml_kem_vector_portable_arithmetic_add:
  897|  51.2k|{
  898|  51.2k|    for (size_t i = (size_t)0U;
  899|   870k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|   870k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (899:10): [True: 819k, False: 51.2k]
  ------------------
  900|   819k|        size_t i0 = i;
  901|   819k|        size_t uu____0 = i0;
  902|   819k|        lhs.elements[uu____0] = lhs.elements[uu____0] + rhs->elements[i0];
  903|   819k|    }
  904|  51.2k|    return lhs;
  905|  51.2k|}
libcrux_ml_kem_vector_portable_add_0d:
  915|  51.2k|{
  916|  51.2k|    return libcrux_ml_kem_vector_portable_arithmetic_add(lhs, rhs);
  917|  51.2k|}
libcrux_ml_kem_vector_portable_arithmetic_sub:
  923|  19.9k|{
  924|  19.9k|    for (size_t i = (size_t)0U;
  925|   338k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|   338k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (925:10): [True: 318k, False: 19.9k]
  ------------------
  926|   318k|        size_t i0 = i;
  927|   318k|        size_t uu____0 = i0;
  928|   318k|        lhs.elements[uu____0] = lhs.elements[uu____0] - rhs->elements[i0];
  929|   318k|    }
  930|  19.9k|    return lhs;
  931|  19.9k|}
libcrux_ml_kem_vector_portable_sub_0d:
  941|  19.9k|{
  942|  19.9k|    return libcrux_ml_kem_vector_portable_arithmetic_sub(lhs, rhs);
  943|  19.9k|}
libcrux_ml_kem_vector_portable_arithmetic_multiply_by_constant:
  948|  1.99k|{
  949|  1.99k|    for (size_t i = (size_t)0U;
  950|  33.8k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|  33.8k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (950:10): [True: 31.8k, False: 1.99k]
  ------------------
  951|  31.8k|        size_t i0 = i;
  952|  31.8k|        size_t uu____0 = i0;
  953|  31.8k|        v.elements[uu____0] = v.elements[uu____0] * c;
  954|  31.8k|    }
  955|  1.99k|    return v;
  956|  1.99k|}
libcrux_ml_kem_vector_portable_multiply_by_constant_0d:
  965|  1.99k|{
  966|  1.99k|    return libcrux_ml_kem_vector_portable_arithmetic_multiply_by_constant(v, c);
  967|  1.99k|}
libcrux_ml_kem_vector_portable_arithmetic_bitwise_and_with_constant:
  972|  11.3k|{
  973|  11.3k|    for (size_t i = (size_t)0U;
  974|   193k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|   193k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (974:10): [True: 182k, False: 11.3k]
  ------------------
  975|   182k|        size_t i0 = i;
  976|   182k|        size_t uu____0 = i0;
  977|   182k|        v.elements[uu____0] = v.elements[uu____0] & c;
  978|   182k|    }
  979|  11.3k|    return v;
  980|  11.3k|}
libcrux_ml_kem_vector_portable_bitwise_and_with_constant_0d:
  989|  11.3k|{
  990|  11.3k|    return libcrux_ml_kem_vector_portable_arithmetic_bitwise_and_with_constant(v,
  991|  11.3k|                                                                               c);
  992|  11.3k|}
libcrux_ml_kem_vector_portable_arithmetic_cond_subtract_3329:
  997|  8.73k|{
  998|  8.73k|    core_ops_range_Range_b3 iter =
  999|  8.73k|        core_iter_traits_collect___core__iter__traits__collect__IntoIterator_for_I__1__into_iter(
  ------------------
  |  |  246|  8.73k|    Eurydice_into_iter
  |  |  ------------------
  |  |  |  |  241|  8.73k|#define Eurydice_into_iter(x, t, _ret_t) (x)
  |  |  ------------------
  ------------------
 1000|  8.73k|            (CLITERAL(core_ops_range_Range_b3){
 1001|  8.73k|                .start = (size_t)0U,
 1002|  8.73k|                .end = LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR }),
 1003|  8.73k|            core_ops_range_Range_b3, core_ops_range_Range_b3);
 1004|   148k|    while (true) {
 1005|   148k|        core_option_Option_b3 uu____0 =
 1006|   148k|            core_iter_range___core__iter__traits__iterator__Iterator_for_core__ops__range__Range_A___6__next(
  ------------------
  |  |  238|   148k|    Eurydice_range_iter_next
  |  |  ------------------
  |  |  |  |  228|   148k|    (((iter_ptr)->start == (iter_ptr)->end)             \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (228:6): [True: 8.73k, False: 139k]
  |  |  |  |  ------------------
  |  |  |  |  229|   148k|         ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   38|  8.73k|#define core_option_None 0
  |  |  |  |  ------------------
  |  |  |  |  230|   148k|         : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   139k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|   139k|#define core_option_Some 1
  |  |  |  |  ------------------
  |  |  |  |  231|   139k|                             .f0 = (iter_ptr)->start++ }))
  |  |  ------------------
  ------------------
 1007|   148k|                &iter, size_t, core_option_Option_b3);
 1008|   148k|        if (!(uu____0.tag == core_option_None)) {
  ------------------
  |  |   38|   148k|#define core_option_None 0
  ------------------
  |  Branch (1008:13): [True: 139k, False: 8.73k]
  ------------------
 1009|   139k|            size_t i = uu____0.f0;
 1010|   139k|            if (v.elements[i] >= (int16_t)3329) {
  ------------------
  |  Branch (1010:17): [True: 4.32k, False: 135k]
  ------------------
 1011|  4.32k|                size_t uu____1 = i;
 1012|  4.32k|                v.elements[uu____1] = v.elements[uu____1] - (int16_t)3329;
 1013|  4.32k|            }
 1014|   139k|            continue;
 1015|   139k|        }
 1016|  8.73k|        return v;
 1017|   148k|    }
 1018|  8.73k|}
libcrux_ml_kem_vector_portable_cond_subtract_3329_0d:
 1027|  8.73k|{
 1028|  8.73k|    return libcrux_ml_kem_vector_portable_arithmetic_cond_subtract_3329(v);
 1029|  8.73k|}
libcrux_ml_kem_vector_portable_arithmetic_barrett_reduce_element:
 1047|   531k|{
 1048|   531k|    int32_t t = (int32_t)value *
 1049|   531k|                    LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_BARRETT_MULTIPLIER +
  ------------------
  |  |  200|   531k|    ((int32_t)20159)
  ------------------
 1050|   531k|                (LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_BARRETT_R >> 1U);
  ------------------
  |  |  205|   531k|    ((int32_t)1 << (uint32_t)                               \
  |  |  206|   531k|         LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_BARRETT_SHIFT)
  |  |  ------------------
  |  |  |  |  202|   531k|#define LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_BARRETT_SHIFT ((int32_t)26)
  |  |  ------------------
  ------------------
 1051|   531k|    int16_t quotient =
 1052|   531k|        (int16_t)(t >>
 1053|   531k|                  (uint32_t)
 1054|   531k|                      LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_BARRETT_SHIFT);
  ------------------
  |  |  202|   531k|#define LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_BARRETT_SHIFT ((int32_t)26)
  ------------------
 1055|   531k|    return value - quotient * LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS;
  ------------------
  |  |   34|   531k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS ((int16_t)3329)
  ------------------
 1056|   531k|}
libcrux_ml_kem_vector_portable_arithmetic_barrett_reduce:
 1061|  25.2k|{
 1062|  25.2k|    for (size_t i = (size_t)0U;
 1063|   428k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|   428k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (1063:10): [True: 403k, False: 25.2k]
  ------------------
 1064|   403k|        size_t i0 = i;
 1065|   403k|        v.elements[i0] =
 1066|   403k|            libcrux_ml_kem_vector_portable_arithmetic_barrett_reduce_element(
 1067|   403k|                v.elements[i0]);
 1068|   403k|    }
 1069|  25.2k|    return v;
 1070|  25.2k|}
libcrux_ml_kem_vector_portable_barrett_reduce_0d:
 1079|  25.2k|{
 1080|  25.2k|    return libcrux_ml_kem_vector_portable_arithmetic_barrett_reduce(v);
 1081|  25.2k|}
libcrux_ml_kem_vector_portable_arithmetic_montgomery_reduce_element:
 1100|   956k|{
 1101|   956k|    int32_t k =
 1102|   956k|        (int32_t)(int16_t)value *
 1103|   956k|        (int32_t)LIBCRUX_ML_KEM_VECTOR_TRAITS_INVERSE_OF_MODULUS_MOD_MONTGOMERY_R;
  ------------------
  |  |   40|   956k|    (62209U)
  ------------------
 1104|   956k|    int32_t k_times_modulus =
 1105|   956k|        (int32_t)(int16_t)k * (int32_t)LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS;
  ------------------
  |  |   34|   956k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS ((int16_t)3329)
  ------------------
 1106|   956k|    int16_t c =
 1107|   956k|        (int16_t)(k_times_modulus >>
 1108|   956k|                  (uint32_t)
 1109|   956k|                      LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_MONTGOMERY_SHIFT);
  ------------------
  |  |  236|   956k|#define LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_MONTGOMERY_SHIFT (16U)
  ------------------
 1110|   956k|    int16_t value_high =
 1111|   956k|        (int16_t)(value >>
 1112|   956k|                  (uint32_t)
 1113|   956k|                      LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_MONTGOMERY_SHIFT);
  ------------------
  |  |  236|   956k|#define LIBCRUX_ML_KEM_VECTOR_PORTABLE_ARITHMETIC_MONTGOMERY_SHIFT (16U)
  ------------------
 1114|   956k|    return value_high - c;
 1115|   956k|}
libcrux_ml_kem_vector_portable_arithmetic_montgomery_multiply_fe_by_fer:
 1131|   573k|{
 1132|   573k|    return libcrux_ml_kem_vector_portable_arithmetic_montgomery_reduce_element(
 1133|   573k|        (int32_t)fe * (int32_t)fer);
 1134|   573k|}
libcrux_ml_kem_vector_portable_arithmetic_montgomery_multiply_by_constant:
 1139|  21.9k|{
 1140|  21.9k|    for (size_t i = (size_t)0U;
 1141|   372k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|   372k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (1141:10): [True: 350k, False: 21.9k]
  ------------------
 1142|   350k|        size_t i0 = i;
 1143|   350k|        v.elements[i0] =
 1144|   350k|            libcrux_ml_kem_vector_portable_arithmetic_montgomery_multiply_fe_by_fer(
 1145|   350k|                v.elements[i0], c);
 1146|   350k|    }
 1147|  21.9k|    return v;
 1148|  21.9k|}
libcrux_ml_kem_vector_portable_montgomery_multiply_by_constant_0d:
 1157|  21.9k|{
 1158|  21.9k|    return libcrux_ml_kem_vector_portable_arithmetic_montgomery_multiply_by_constant(
 1159|  21.9k|        v, r);
 1160|  21.9k|}
libcrux_ml_kem_vector_portable_arithmetic_get_n_least_significant_bits:
 1223|  84.9k|{
 1224|  84.9k|    return value & ((1U << (uint32_t)n) - 1U);
 1225|  84.9k|}
libcrux_ml_kem_vector_portable_compress_compress_ciphertext_coefficient:
 1230|  84.9k|{
 1231|  84.9k|    uint64_t compressed = (uint64_t)fe << (uint32_t)coefficient_bits;
 1232|  84.9k|    compressed = compressed + 1664ULL;
 1233|  84.9k|    compressed = compressed * 10321340ULL;
 1234|  84.9k|    compressed = compressed >> 35U;
 1235|  84.9k|    return (int16_t)
 1236|  84.9k|        libcrux_ml_kem_vector_portable_arithmetic_get_n_least_significant_bits(
 1237|  84.9k|            coefficient_bits, (uint32_t)compressed);
 1238|  84.9k|}
libcrux_ml_kem_vector_portable_ntt_ntt_step:
 1244|  95.6k|{
 1245|  95.6k|    int16_t t =
 1246|  95.6k|        libcrux_ml_kem_vector_portable_arithmetic_montgomery_multiply_fe_by_fer(
 1247|  95.6k|            v->elements[j], zeta);
 1248|  95.6k|    v->elements[j] = v->elements[i] - t;
 1249|  95.6k|    v->elements[i] = v->elements[i] + t;
 1250|  95.6k|}
libcrux_ml_kem_vector_portable_ntt_ntt_layer_1_step:
 1256|  3.98k|{
 1257|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta0, (size_t)0U,
 1258|  3.98k|                                                (size_t)2U);
 1259|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta0, (size_t)1U,
 1260|  3.98k|                                                (size_t)3U);
 1261|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta1, (size_t)4U,
 1262|  3.98k|                                                (size_t)6U);
 1263|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta1, (size_t)5U,
 1264|  3.98k|                                                (size_t)7U);
 1265|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta2, (size_t)8U,
 1266|  3.98k|                                                (size_t)10U);
 1267|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta2, (size_t)9U,
 1268|  3.98k|                                                (size_t)11U);
 1269|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta3, (size_t)12U,
 1270|  3.98k|                                                (size_t)14U);
 1271|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta3, (size_t)13U,
 1272|  3.98k|                                                (size_t)15U);
 1273|  3.98k|    return v;
 1274|  3.98k|}
libcrux_ml_kem_vector_portable_ntt_layer_1_step_0d:
 1284|  3.98k|{
 1285|  3.98k|    return libcrux_ml_kem_vector_portable_ntt_ntt_layer_1_step(a, zeta0, zeta1,
 1286|  3.98k|                                                               zeta2, zeta3);
 1287|  3.98k|}
libcrux_ml_kem_vector_portable_ntt_ntt_layer_2_step:
 1293|  3.98k|{
 1294|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta0, (size_t)0U,
 1295|  3.98k|                                                (size_t)4U);
 1296|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta0, (size_t)1U,
 1297|  3.98k|                                                (size_t)5U);
 1298|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta0, (size_t)2U,
 1299|  3.98k|                                                (size_t)6U);
 1300|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta0, (size_t)3U,
 1301|  3.98k|                                                (size_t)7U);
 1302|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta1, (size_t)8U,
 1303|  3.98k|                                                (size_t)12U);
 1304|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta1, (size_t)9U,
 1305|  3.98k|                                                (size_t)13U);
 1306|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta1, (size_t)10U,
 1307|  3.98k|                                                (size_t)14U);
 1308|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta1, (size_t)11U,
 1309|  3.98k|                                                (size_t)15U);
 1310|  3.98k|    return v;
 1311|  3.98k|}
libcrux_ml_kem_vector_portable_ntt_layer_2_step_0d:
 1321|  3.98k|{
 1322|  3.98k|    return libcrux_ml_kem_vector_portable_ntt_ntt_layer_2_step(a, zeta0, zeta1);
 1323|  3.98k|}
libcrux_ml_kem_vector_portable_ntt_ntt_layer_3_step:
 1328|  3.98k|{
 1329|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)0U, (size_t)8U);
 1330|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)1U, (size_t)9U);
 1331|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)2U,
 1332|  3.98k|                                                (size_t)10U);
 1333|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)3U,
 1334|  3.98k|                                                (size_t)11U);
 1335|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)4U,
 1336|  3.98k|                                                (size_t)12U);
 1337|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)5U,
 1338|  3.98k|                                                (size_t)13U);
 1339|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)6U,
 1340|  3.98k|                                                (size_t)14U);
 1341|  3.98k|    libcrux_ml_kem_vector_portable_ntt_ntt_step(&v, zeta, (size_t)7U,
 1342|  3.98k|                                                (size_t)15U);
 1343|  3.98k|    return v;
 1344|  3.98k|}
libcrux_ml_kem_vector_portable_ntt_layer_3_step_0d:
 1353|  3.98k|{
 1354|  3.98k|    return libcrux_ml_kem_vector_portable_ntt_ntt_layer_3_step(a, zeta);
 1355|  3.98k|}
libcrux_ml_kem_vector_portable_ntt_inv_ntt_step:
 1361|   127k|{
 1362|   127k|    int16_t a_minus_b = v->elements[j] - v->elements[i];
 1363|   127k|    v->elements[i] =
 1364|   127k|        libcrux_ml_kem_vector_portable_arithmetic_barrett_reduce_element(
 1365|   127k|            v->elements[i] + v->elements[j]);
 1366|   127k|    v->elements[j] =
 1367|   127k|        libcrux_ml_kem_vector_portable_arithmetic_montgomery_multiply_fe_by_fer(
 1368|   127k|            a_minus_b, zeta);
 1369|   127k|}
libcrux_ml_kem_vector_portable_ntt_inv_ntt_layer_1_step:
 1375|  5.31k|{
 1376|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta0, (size_t)0U,
 1377|  5.31k|                                                    (size_t)2U);
 1378|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta0, (size_t)1U,
 1379|  5.31k|                                                    (size_t)3U);
 1380|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta1, (size_t)4U,
 1381|  5.31k|                                                    (size_t)6U);
 1382|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta1, (size_t)5U,
 1383|  5.31k|                                                    (size_t)7U);
 1384|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta2, (size_t)8U,
 1385|  5.31k|                                                    (size_t)10U);
 1386|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta2, (size_t)9U,
 1387|  5.31k|                                                    (size_t)11U);
 1388|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta3, (size_t)12U,
 1389|  5.31k|                                                    (size_t)14U);
 1390|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta3, (size_t)13U,
 1391|  5.31k|                                                    (size_t)15U);
 1392|  5.31k|    return v;
 1393|  5.31k|}
libcrux_ml_kem_vector_portable_inv_ntt_layer_1_step_0d:
 1403|  5.31k|{
 1404|  5.31k|    return libcrux_ml_kem_vector_portable_ntt_inv_ntt_layer_1_step(
 1405|  5.31k|        a, zeta0, zeta1, zeta2, zeta3);
 1406|  5.31k|}
libcrux_ml_kem_vector_portable_ntt_inv_ntt_layer_2_step:
 1412|  5.31k|{
 1413|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta0, (size_t)0U,
 1414|  5.31k|                                                    (size_t)4U);
 1415|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta0, (size_t)1U,
 1416|  5.31k|                                                    (size_t)5U);
 1417|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta0, (size_t)2U,
 1418|  5.31k|                                                    (size_t)6U);
 1419|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta0, (size_t)3U,
 1420|  5.31k|                                                    (size_t)7U);
 1421|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta1, (size_t)8U,
 1422|  5.31k|                                                    (size_t)12U);
 1423|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta1, (size_t)9U,
 1424|  5.31k|                                                    (size_t)13U);
 1425|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta1, (size_t)10U,
 1426|  5.31k|                                                    (size_t)14U);
 1427|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta1, (size_t)11U,
 1428|  5.31k|                                                    (size_t)15U);
 1429|  5.31k|    return v;
 1430|  5.31k|}
libcrux_ml_kem_vector_portable_inv_ntt_layer_2_step_0d:
 1440|  5.31k|{
 1441|  5.31k|    return libcrux_ml_kem_vector_portable_ntt_inv_ntt_layer_2_step(a, zeta0,
 1442|  5.31k|                                                                   zeta1);
 1443|  5.31k|}
libcrux_ml_kem_vector_portable_ntt_inv_ntt_layer_3_step:
 1448|  5.31k|{
 1449|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)0U,
 1450|  5.31k|                                                    (size_t)8U);
 1451|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)1U,
 1452|  5.31k|                                                    (size_t)9U);
 1453|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)2U,
 1454|  5.31k|                                                    (size_t)10U);
 1455|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)3U,
 1456|  5.31k|                                                    (size_t)11U);
 1457|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)4U,
 1458|  5.31k|                                                    (size_t)12U);
 1459|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)5U,
 1460|  5.31k|                                                    (size_t)13U);
 1461|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)6U,
 1462|  5.31k|                                                    (size_t)14U);
 1463|  5.31k|    libcrux_ml_kem_vector_portable_ntt_inv_ntt_step(&v, zeta, (size_t)7U,
 1464|  5.31k|                                                    (size_t)15U);
 1465|  5.31k|    return v;
 1466|  5.31k|}
libcrux_ml_kem_vector_portable_inv_ntt_layer_3_step_0d:
 1475|  5.31k|{
 1476|  5.31k|    return libcrux_ml_kem_vector_portable_ntt_inv_ntt_layer_3_step(a, zeta);
 1477|  5.31k|}
libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials:
 1507|   127k|{
 1508|   127k|    int16_t o0 = libcrux_ml_kem_vector_portable_arithmetic_montgomery_reduce_element(
 1509|   127k|        (int32_t)a->elements[i] * (int32_t)b->elements[i] +
 1510|   127k|        (int32_t)
 1511|   127k|                libcrux_ml_kem_vector_portable_arithmetic_montgomery_reduce_element(
 1512|   127k|                    (int32_t)a->elements[j] * (int32_t)b->elements[j]) *
 1513|   127k|            (int32_t)zeta);
 1514|   127k|    int16_t o1 =
 1515|   127k|        libcrux_ml_kem_vector_portable_arithmetic_montgomery_reduce_element(
 1516|   127k|            (int32_t)a->elements[i] * (int32_t)b->elements[j] +
 1517|   127k|            (int32_t)a->elements[j] * (int32_t)b->elements[i]);
 1518|   127k|    out->elements[i] = o0;
 1519|   127k|    out->elements[j] = o1;
 1520|   127k|}
libcrux_ml_kem_vector_portable_ntt_ntt_multiply:
 1527|  15.9k|{
 1528|  15.9k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector out =
 1529|  15.9k|        libcrux_ml_kem_vector_portable_vector_type_zero();
 1530|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1531|  15.9k|        lhs, rhs, zeta0, (size_t)0U, (size_t)1U, &out);
 1532|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1533|  15.9k|        lhs, rhs, -zeta0, (size_t)2U, (size_t)3U, &out);
 1534|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1535|  15.9k|        lhs, rhs, zeta1, (size_t)4U, (size_t)5U, &out);
 1536|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1537|  15.9k|        lhs, rhs, -zeta1, (size_t)6U, (size_t)7U, &out);
 1538|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1539|  15.9k|        lhs, rhs, zeta2, (size_t)8U, (size_t)9U, &out);
 1540|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1541|  15.9k|        lhs, rhs, -zeta2, (size_t)10U, (size_t)11U, &out);
 1542|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1543|  15.9k|        lhs, rhs, zeta3, (size_t)12U, (size_t)13U, &out);
 1544|  15.9k|    libcrux_ml_kem_vector_portable_ntt_ntt_multiply_binomials(
 1545|  15.9k|        lhs, rhs, -zeta3, (size_t)14U, (size_t)15U, &out);
 1546|  15.9k|    return out;
 1547|  15.9k|}
libcrux_ml_kem_vector_portable_ntt_multiply_0d:
 1558|  15.9k|{
 1559|  15.9k|    return libcrux_ml_kem_vector_portable_ntt_ntt_multiply(lhs, rhs, zeta0, zeta1,
 1560|  15.9k|                                                           zeta2, zeta3);
 1561|  15.9k|}
libcrux_ml_kem_vector_portable_serialize_deserialize_1:
 1596|  1.32k|{
 1597|  1.32k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector result =
 1598|  1.32k|        libcrux_ml_kem_vector_portable_vector_type_zero();
 1599|  1.32k|    KRML_MAYBE_FOR8(
  ------------------
  |  |  354|  1.32k|#define KRML_MAYBE_FOR8(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 8, k, x)
  |  |  ------------------
  |  |  |  |  288|  1.32k|    do {                               \
  |  |  |  |  289|  1.32k|        uint32_t i = z;                \
  |  |  |  |  290|  1.32k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  1.32k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1600|  1.32k|        i, (size_t)0U, (size_t)8U, (size_t)1U, size_t i0 = i;
 1601|  1.32k|        result.elements[i0] = (int16_t)((uint32_t)Eurydice_slice_index(
 1602|  1.32k|                                            v, (size_t)0U, uint8_t, uint8_t *) >>
 1603|  1.32k|                                            (uint32_t)i0 &
 1604|  1.32k|                                        1U););
 1605|  1.32k|    for (size_t i = (size_t)8U;
 1606|  11.9k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|  11.9k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (1606:10): [True: 10.6k, False: 1.32k]
  ------------------
 1607|  10.6k|        size_t i0 = i;
 1608|  10.6k|        result.elements[i0] = (int16_t)((uint32_t)Eurydice_slice_index(
  ------------------
  |  |   57|  10.6k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1609|  10.6k|                                            v, (size_t)1U, uint8_t, uint8_t *) >>
 1610|  10.6k|                                            (uint32_t)(i0 - (size_t)8U) &
 1611|  10.6k|                                        1U);
 1612|  10.6k|    }
 1613|  1.32k|    return result;
 1614|  1.32k|}
libcrux_ml_kem_vector_portable_deserialize_1_0d:
 1622|  1.32k|{
 1623|  1.32k|    return libcrux_ml_kem_vector_portable_serialize_deserialize_1(a);
 1624|  1.32k|}
libcrux_ml_kem_vector_portable_serialize_serialize_4_int:
 1628|  2.65k|{
 1629|  2.65k|    uint8_t result0 =
 1630|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)1U, int16_t, int16_t *)
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1631|  2.65k|            << 4U |
 1632|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)0U, int16_t,
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1633|  2.65k|                                                int16_t *);
 1634|  2.65k|    uint8_t result1 =
 1635|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)3U, int16_t, int16_t *)
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1636|  2.65k|            << 4U |
 1637|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)2U, int16_t,
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1638|  2.65k|                                                int16_t *);
 1639|  2.65k|    uint8_t result2 =
 1640|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)5U, int16_t, int16_t *)
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1641|  2.65k|            << 4U |
 1642|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)4U, int16_t,
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1643|  2.65k|                                                int16_t *);
 1644|  2.65k|    uint8_t result3 =
 1645|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)7U, int16_t, int16_t *)
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1646|  2.65k|            << 4U |
 1647|  2.65k|        (uint32_t)(uint8_t)Eurydice_slice_index(v, (size_t)6U, int16_t,
  ------------------
  |  |   57|  2.65k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1648|  2.65k|                                                int16_t *);
 1649|  2.65k|    return (CLITERAL(uint8_t_x4){
  ------------------
  |  |   27|  2.65k|#define CLITERAL(type) (type)
  ------------------
 1650|  2.65k|        .fst = result0, .snd = result1, .thd = result2, .f3 = result3 });
 1651|  2.65k|}
libcrux_ml_kem_vector_portable_serialize_serialize_4:
 1657|  1.32k|{
 1658|  1.32k|    uint8_t_x4 result0_3 =
 1659|  1.32k|        libcrux_ml_kem_vector_portable_serialize_serialize_4_int(
 1660|  1.32k|            Eurydice_array_to_subslice2(v.elements, (size_t)0U, (size_t)8U,
  ------------------
  |  |   75|  1.32k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  1.32k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  1.32k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1661|  1.32k|                                        int16_t));
 1662|  1.32k|    uint8_t_x4 result4_7 =
 1663|  1.32k|        libcrux_ml_kem_vector_portable_serialize_serialize_4_int(
 1664|  1.32k|            Eurydice_array_to_subslice2(v.elements, (size_t)8U, (size_t)16U,
  ------------------
  |  |   75|  1.32k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  1.32k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  1.32k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1665|  1.32k|                                        int16_t));
 1666|  1.32k|    uint8_t result[8U] = { 0U };
 1667|  1.32k|    result[0U] = result0_3.fst;
 1668|  1.32k|    result[1U] = result0_3.snd;
 1669|  1.32k|    result[2U] = result0_3.thd;
 1670|  1.32k|    result[3U] = result0_3.f3;
 1671|  1.32k|    result[4U] = result4_7.fst;
 1672|  1.32k|    result[5U] = result4_7.snd;
 1673|  1.32k|    result[6U] = result4_7.thd;
 1674|  1.32k|    result[7U] = result4_7.f3;
 1675|  1.32k|    memcpy(ret, result, (size_t)8U * sizeof(uint8_t));
 1676|  1.32k|}
libcrux_ml_kem_vector_portable_serialize_4_0d:
 1686|  1.32k|{
 1687|  1.32k|    libcrux_ml_kem_vector_portable_serialize_serialize_4(a, ret);
 1688|  1.32k|}
libcrux_ml_kem_vector_portable_serialize_serialize_10_int:
 1925|  15.9k|{
 1926|  15.9k|    uint8_t r0 =
 1927|  15.9k|        (uint8_t)(Eurydice_slice_index(v, (size_t)0U, int16_t, int16_t *) &
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1928|  15.9k|                  (int16_t)255);
 1929|  15.9k|    uint8_t r1 = (uint32_t)(uint8_t)(Eurydice_slice_index(v, (size_t)1U, int16_t,
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1930|  15.9k|                                                          int16_t *) &
 1931|  15.9k|                                     (int16_t)63)
 1932|  15.9k|                     << 2U |
 1933|  15.9k|                 (uint32_t)(uint8_t)(Eurydice_slice_index(v, (size_t)0U, int16_t,
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1934|  15.9k|                                                          int16_t *) >>
 1935|  15.9k|                                         8U &
 1936|  15.9k|                                     (int16_t)3);
 1937|  15.9k|    uint8_t r2 = (uint32_t)(uint8_t)(Eurydice_slice_index(v, (size_t)2U, int16_t,
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1938|  15.9k|                                                          int16_t *) &
 1939|  15.9k|                                     (int16_t)15)
 1940|  15.9k|                     << 4U |
 1941|  15.9k|                 (uint32_t)(uint8_t)(Eurydice_slice_index(v, (size_t)1U, int16_t,
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1942|  15.9k|                                                          int16_t *) >>
 1943|  15.9k|                                         6U &
 1944|  15.9k|                                     (int16_t)15);
 1945|  15.9k|    uint8_t r3 = (uint32_t)(uint8_t)(Eurydice_slice_index(v, (size_t)3U, int16_t,
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1946|  15.9k|                                                          int16_t *) &
 1947|  15.9k|                                     (int16_t)3)
 1948|  15.9k|                     << 6U |
 1949|  15.9k|                 (uint32_t)(uint8_t)(Eurydice_slice_index(v, (size_t)2U, int16_t,
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1950|  15.9k|                                                          int16_t *) >>
 1951|  15.9k|                                         4U &
 1952|  15.9k|                                     (int16_t)63);
 1953|  15.9k|    uint8_t r4 =
 1954|  15.9k|        (uint8_t)(Eurydice_slice_index(v, (size_t)3U, int16_t, int16_t *) >> 2U &
  ------------------
  |  |   57|  15.9k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 1955|  15.9k|                  (int16_t)255);
 1956|  15.9k|    return (CLITERAL(uint8_t_x5){
  ------------------
  |  |   27|  15.9k|#define CLITERAL(type) (type)
  ------------------
 1957|  15.9k|        .fst = r0, .snd = r1, .thd = r2, .f3 = r3, .f4 = r4 });
 1958|  15.9k|}
libcrux_ml_kem_vector_portable_serialize_serialize_10:
 1964|  3.98k|{
 1965|  3.98k|    uint8_t_x5 r0_4 = libcrux_ml_kem_vector_portable_serialize_serialize_10_int(
 1966|  3.98k|        Eurydice_array_to_subslice2(v.elements, (size_t)0U, (size_t)4U, int16_t));
  ------------------
  |  |   75|  3.98k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  3.98k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  3.98k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1967|  3.98k|    uint8_t_x5 r5_9 = libcrux_ml_kem_vector_portable_serialize_serialize_10_int(
 1968|  3.98k|        Eurydice_array_to_subslice2(v.elements, (size_t)4U, (size_t)8U, int16_t));
  ------------------
  |  |   75|  3.98k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  3.98k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  3.98k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1969|  3.98k|    uint8_t_x5 r10_14 = libcrux_ml_kem_vector_portable_serialize_serialize_10_int(
 1970|  3.98k|        Eurydice_array_to_subslice2(v.elements, (size_t)8U, (size_t)12U,
  ------------------
  |  |   75|  3.98k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  3.98k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  3.98k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1971|  3.98k|                                    int16_t));
 1972|  3.98k|    uint8_t_x5 r15_19 = libcrux_ml_kem_vector_portable_serialize_serialize_10_int(
 1973|  3.98k|        Eurydice_array_to_subslice2(v.elements, (size_t)12U, (size_t)16U,
  ------------------
  |  |   75|  3.98k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  3.98k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  3.98k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1974|  3.98k|                                    int16_t));
 1975|  3.98k|    uint8_t result[20U] = { 0U };
 1976|  3.98k|    result[0U] = r0_4.fst;
 1977|  3.98k|    result[1U] = r0_4.snd;
 1978|  3.98k|    result[2U] = r0_4.thd;
 1979|  3.98k|    result[3U] = r0_4.f3;
 1980|  3.98k|    result[4U] = r0_4.f4;
 1981|  3.98k|    result[5U] = r5_9.fst;
 1982|  3.98k|    result[6U] = r5_9.snd;
 1983|  3.98k|    result[7U] = r5_9.thd;
 1984|  3.98k|    result[8U] = r5_9.f3;
 1985|  3.98k|    result[9U] = r5_9.f4;
 1986|  3.98k|    result[10U] = r10_14.fst;
 1987|  3.98k|    result[11U] = r10_14.snd;
 1988|  3.98k|    result[12U] = r10_14.thd;
 1989|  3.98k|    result[13U] = r10_14.f3;
 1990|  3.98k|    result[14U] = r10_14.f4;
 1991|  3.98k|    result[15U] = r15_19.fst;
 1992|  3.98k|    result[16U] = r15_19.snd;
 1993|  3.98k|    result[17U] = r15_19.thd;
 1994|  3.98k|    result[18U] = r15_19.f3;
 1995|  3.98k|    result[19U] = r15_19.f4;
 1996|  3.98k|    memcpy(ret, result, (size_t)20U * sizeof(uint8_t));
 1997|  3.98k|}
libcrux_ml_kem_vector_portable_serialize_10_0d:
 2007|  3.98k|{
 2008|  3.98k|    libcrux_ml_kem_vector_portable_serialize_serialize_10(a, ret);
 2009|  3.98k|}
libcrux_ml_kem_vector_portable_serialize_serialize_12_int:
 2112|  38.0k|{
 2113|  38.0k|    uint8_t r0 =
 2114|  38.0k|        (uint8_t)(Eurydice_slice_index(v, (size_t)0U, int16_t, int16_t *) &
  ------------------
  |  |   57|  38.0k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2115|  38.0k|                  (int16_t)255);
 2116|  38.0k|    uint8_t r1 =
 2117|  38.0k|        (uint8_t)(Eurydice_slice_index(v, (size_t)0U, int16_t, int16_t *) >> 8U |
  ------------------
  |  |   57|  38.0k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2118|  38.0k|                  (Eurydice_slice_index(v, (size_t)1U, int16_t, int16_t *) &
  ------------------
  |  |   57|  38.0k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2119|  38.0k|                   (int16_t)15)
 2120|  38.0k|                      << 4U);
 2121|  38.0k|    uint8_t r2 =
 2122|  38.0k|        (uint8_t)(Eurydice_slice_index(v, (size_t)1U, int16_t, int16_t *) >> 4U &
  ------------------
  |  |   57|  38.0k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2123|  38.0k|                  (int16_t)255);
 2124|  38.0k|    return (CLITERAL(uint8_t_x3){ .fst = r0, .snd = r1, .thd = r2 });
  ------------------
  |  |   27|  38.0k|#define CLITERAL(type) (type)
  ------------------
 2125|  38.0k|}
libcrux_ml_kem_vector_portable_serialize_serialize_12:
 2131|  4.75k|{
 2132|  4.75k|    uint8_t_x3 r0_2 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2133|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)0U, (size_t)2U, int16_t));
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2134|  4.75k|    uint8_t_x3 r3_5 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2135|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)2U, (size_t)4U, int16_t));
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2136|  4.75k|    uint8_t_x3 r6_8 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2137|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)4U, (size_t)6U, int16_t));
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2138|  4.75k|    uint8_t_x3 r9_11 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2139|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)6U, (size_t)8U, int16_t));
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2140|  4.75k|    uint8_t_x3 r12_14 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2141|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)8U, (size_t)10U,
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2142|  4.75k|                                    int16_t));
 2143|  4.75k|    uint8_t_x3 r15_17 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2144|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)10U, (size_t)12U,
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2145|  4.75k|                                    int16_t));
 2146|  4.75k|    uint8_t_x3 r18_20 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2147|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)12U, (size_t)14U,
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2148|  4.75k|                                    int16_t));
 2149|  4.75k|    uint8_t_x3 r21_23 = libcrux_ml_kem_vector_portable_serialize_serialize_12_int(
 2150|  4.75k|        Eurydice_array_to_subslice2(v.elements, (size_t)14U, (size_t)16U,
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2151|  4.75k|                                    int16_t));
 2152|  4.75k|    uint8_t result[24U] = { 0U };
 2153|  4.75k|    result[0U] = r0_2.fst;
 2154|  4.75k|    result[1U] = r0_2.snd;
 2155|  4.75k|    result[2U] = r0_2.thd;
 2156|  4.75k|    result[3U] = r3_5.fst;
 2157|  4.75k|    result[4U] = r3_5.snd;
 2158|  4.75k|    result[5U] = r3_5.thd;
 2159|  4.75k|    result[6U] = r6_8.fst;
 2160|  4.75k|    result[7U] = r6_8.snd;
 2161|  4.75k|    result[8U] = r6_8.thd;
 2162|  4.75k|    result[9U] = r9_11.fst;
 2163|  4.75k|    result[10U] = r9_11.snd;
 2164|  4.75k|    result[11U] = r9_11.thd;
 2165|  4.75k|    result[12U] = r12_14.fst;
 2166|  4.75k|    result[13U] = r12_14.snd;
 2167|  4.75k|    result[14U] = r12_14.thd;
 2168|  4.75k|    result[15U] = r15_17.fst;
 2169|  4.75k|    result[16U] = r15_17.snd;
 2170|  4.75k|    result[17U] = r15_17.thd;
 2171|  4.75k|    result[18U] = r18_20.fst;
 2172|  4.75k|    result[19U] = r18_20.snd;
 2173|  4.75k|    result[20U] = r18_20.thd;
 2174|  4.75k|    result[21U] = r21_23.fst;
 2175|  4.75k|    result[22U] = r21_23.snd;
 2176|  4.75k|    result[23U] = r21_23.thd;
 2177|  4.75k|    memcpy(ret, result, (size_t)24U * sizeof(uint8_t));
 2178|  4.75k|}
libcrux_ml_kem_vector_portable_serialize_12_0d:
 2188|  4.75k|{
 2189|  4.75k|    libcrux_ml_kem_vector_portable_serialize_serialize_12(a, ret);
 2190|  4.75k|}
libcrux_ml_kem_vector_portable_serialize_deserialize_12_int:
 2195|  69.8k|{
 2196|  69.8k|    int16_t byte0 =
 2197|  69.8k|        (int16_t)Eurydice_slice_index(bytes, (size_t)0U, uint8_t, uint8_t *);
  ------------------
  |  |   57|  69.8k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2198|  69.8k|    int16_t byte1 =
 2199|  69.8k|        (int16_t)Eurydice_slice_index(bytes, (size_t)1U, uint8_t, uint8_t *);
  ------------------
  |  |   57|  69.8k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2200|  69.8k|    int16_t byte2 =
 2201|  69.8k|        (int16_t)Eurydice_slice_index(bytes, (size_t)2U, uint8_t, uint8_t *);
  ------------------
  |  |   57|  69.8k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2202|  69.8k|    int16_t r0 = (byte1 & (int16_t)15) << 8U | (byte0 & (int16_t)255);
 2203|  69.8k|    int16_t r1 = byte2 << 4U | (byte1 >> 4U & (int16_t)15);
 2204|  69.8k|    return (CLITERAL(int16_t_x2){ .fst = r0, .snd = r1 });
  ------------------
  |  |   27|  69.8k|#define CLITERAL(type) (type)
  ------------------
 2205|  69.8k|}
libcrux_ml_kem_vector_portable_serialize_deserialize_12:
 2209|  8.73k|{
 2210|  8.73k|    int16_t_x2 v0_1 = libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2211|  8.73k|        Eurydice_slice_subslice2(bytes, (size_t)0U, (size_t)3U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2212|  8.73k|    int16_t_x2 v2_3 = libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2213|  8.73k|        Eurydice_slice_subslice2(bytes, (size_t)3U, (size_t)6U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2214|  8.73k|    int16_t_x2 v4_5 = libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2215|  8.73k|        Eurydice_slice_subslice2(bytes, (size_t)6U, (size_t)9U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2216|  8.73k|    int16_t_x2 v6_7 = libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2217|  8.73k|        Eurydice_slice_subslice2(bytes, (size_t)9U, (size_t)12U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2218|  8.73k|    int16_t_x2 v8_9 = libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2219|  8.73k|        Eurydice_slice_subslice2(bytes, (size_t)12U, (size_t)15U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2220|  8.73k|    int16_t_x2 v10_11 =
 2221|  8.73k|        libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2222|  8.73k|            Eurydice_slice_subslice2(bytes, (size_t)15U, (size_t)18U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2223|  8.73k|    int16_t_x2 v12_13 =
 2224|  8.73k|        libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2225|  8.73k|            Eurydice_slice_subslice2(bytes, (size_t)18U, (size_t)21U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2226|  8.73k|    int16_t_x2 v14_15 =
 2227|  8.73k|        libcrux_ml_kem_vector_portable_serialize_deserialize_12_int(
 2228|  8.73k|            Eurydice_slice_subslice2(bytes, (size_t)21U, (size_t)24U, uint8_t));
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2229|  8.73k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector re =
 2230|  8.73k|        libcrux_ml_kem_vector_portable_vector_type_zero();
 2231|  8.73k|    re.elements[0U] = v0_1.fst;
 2232|  8.73k|    re.elements[1U] = v0_1.snd;
 2233|  8.73k|    re.elements[2U] = v2_3.fst;
 2234|  8.73k|    re.elements[3U] = v2_3.snd;
 2235|  8.73k|    re.elements[4U] = v4_5.fst;
 2236|  8.73k|    re.elements[5U] = v4_5.snd;
 2237|  8.73k|    re.elements[6U] = v6_7.fst;
 2238|  8.73k|    re.elements[7U] = v6_7.snd;
 2239|  8.73k|    re.elements[8U] = v8_9.fst;
 2240|  8.73k|    re.elements[9U] = v8_9.snd;
 2241|  8.73k|    re.elements[10U] = v10_11.fst;
 2242|  8.73k|    re.elements[11U] = v10_11.snd;
 2243|  8.73k|    re.elements[12U] = v12_13.fst;
 2244|  8.73k|    re.elements[13U] = v12_13.snd;
 2245|  8.73k|    re.elements[14U] = v14_15.fst;
 2246|  8.73k|    re.elements[15U] = v14_15.snd;
 2247|  8.73k|    return re;
 2248|  8.73k|}
libcrux_ml_kem_vector_portable_deserialize_12_0d:
 2256|  8.73k|{
 2257|  8.73k|    return libcrux_ml_kem_vector_portable_serialize_deserialize_12(a);
 2258|  8.73k|}
libcrux_ml_kem_vector_portable_sampling_rej_sample:
 2263|  15.1k|{
 2264|  15.1k|    size_t sampled = (size_t)0U;
 2265|   136k|    for (size_t i = (size_t)0U; i < Eurydice_slice_len(a, uint8_t) / (size_t)3U;
  ------------------
  |  |   82|   136k|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|   136k|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (2265:33): [True: 121k, False: 15.1k]
  ------------------
 2266|   121k|         i++) {
 2267|   121k|        size_t i0 = i;
 2268|   121k|        int16_t b1 = (int16_t)Eurydice_slice_index(a, i0 * (size_t)3U + (size_t)0U,
  ------------------
  |  |   57|   121k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2269|   121k|                                                   uint8_t, uint8_t *);
 2270|   121k|        int16_t b2 = (int16_t)Eurydice_slice_index(a, i0 * (size_t)3U + (size_t)1U,
  ------------------
  |  |   57|   121k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2271|   121k|                                                   uint8_t, uint8_t *);
 2272|   121k|        int16_t b3 = (int16_t)Eurydice_slice_index(a, i0 * (size_t)3U + (size_t)2U,
  ------------------
  |  |   57|   121k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2273|   121k|                                                   uint8_t, uint8_t *);
 2274|   121k|        int16_t d1 = (b2 & (int16_t)15) << 8U | b1;
 2275|   121k|        int16_t d2 = b3 << 4U | b2 >> 4U;
 2276|   121k|        bool uu____0;
 2277|   121k|        int16_t uu____1;
 2278|   121k|        bool uu____2;
 2279|   121k|        size_t uu____3;
 2280|   121k|        int16_t uu____4;
 2281|   121k|        size_t uu____5;
 2282|   121k|        int16_t uu____6;
 2283|   121k|        if (d1 < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS) {
  ------------------
  |  |   34|   121k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS ((int16_t)3329)
  ------------------
  |  Branch (2283:13): [True: 97.8k, False: 23.5k]
  ------------------
 2284|  97.8k|            if (sampled < (size_t)16U) {
  ------------------
  |  Branch (2284:17): [True: 97.8k, False: 0]
  ------------------
 2285|  97.8k|                Eurydice_slice_index(result, sampled, int16_t, int16_t *) = d1;
  ------------------
  |  |   57|  97.8k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2286|  97.8k|                sampled++;
 2287|  97.8k|                uu____1 = d2;
 2288|  97.8k|                uu____6 = LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS;
  ------------------
  |  |   34|  97.8k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS ((int16_t)3329)
  ------------------
 2289|  97.8k|                uu____0 = uu____1 < uu____6;
 2290|  97.8k|                if (uu____0) {
  ------------------
  |  Branch (2290:21): [True: 79.0k, False: 18.8k]
  ------------------
 2291|  79.0k|                    uu____3 = sampled;
 2292|  79.0k|                    uu____2 = uu____3 < (size_t)16U;
 2293|  79.0k|                    if (uu____2) {
  ------------------
  |  Branch (2293:25): [True: 79.0k, False: 0]
  ------------------
 2294|  79.0k|                        uu____4 = d2;
 2295|  79.0k|                        uu____5 = sampled;
 2296|  79.0k|                        Eurydice_slice_index(result, uu____5, int16_t, int16_t *) = uu____4;
  ------------------
  |  |   57|  79.0k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2297|  79.0k|                        sampled++;
 2298|  79.0k|                        continue;
 2299|  79.0k|                    }
 2300|  79.0k|                }
 2301|  18.8k|                continue;
 2302|  97.8k|            }
 2303|  97.8k|        }
 2304|  23.5k|        uu____1 = d2;
 2305|  23.5k|        uu____6 = LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS;
  ------------------
  |  |   34|  23.5k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS ((int16_t)3329)
  ------------------
 2306|  23.5k|        uu____0 = uu____1 < uu____6;
 2307|  23.5k|        if (uu____0) {
  ------------------
  |  Branch (2307:13): [True: 19.0k, False: 4.52k]
  ------------------
 2308|  19.0k|            uu____3 = sampled;
 2309|  19.0k|            uu____2 = uu____3 < (size_t)16U;
 2310|  19.0k|            if (uu____2) {
  ------------------
  |  Branch (2310:17): [True: 19.0k, False: 0]
  ------------------
 2311|  19.0k|                uu____4 = d2;
 2312|  19.0k|                uu____5 = sampled;
 2313|  19.0k|                Eurydice_slice_index(result, uu____5, int16_t, int16_t *) = uu____4;
  ------------------
  |  |   57|  19.0k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 2314|  19.0k|                sampled++;
 2315|  19.0k|                continue;
 2316|  19.0k|            }
 2317|  19.0k|        }
 2318|  23.5k|    }
 2319|  15.1k|    return sampled;
 2320|  15.1k|}
libcrux_ml_kem_vector_portable_rej_sample_0d:
 2329|  15.1k|{
 2330|  15.1k|    return libcrux_ml_kem_vector_portable_sampling_rej_sample(a, out);
 2331|  15.1k|}
libcrux_ml_kem_ind_cca_validate_public_key_b7:
 7657|     99|{
 7658|     99|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 deserialized_pk[3U];
 7659|     99|    deserialize_ring_elements_reduced_4f0(
 7660|     99|        Eurydice_array_to_subslice_to((size_t)1184U, public_key, (size_t)1152U,
  ------------------
  |  |   77|     99|    EURYDICE_SLICE((t *)x, 0, r)
  |  |  ------------------
  |  |  |  |   50|     99|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7661|     99|                                      uint8_t, size_t),
 7662|     99|        deserialized_pk);
 7663|     99|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 *uu____0 = deserialized_pk;
 7664|     99|    uint8_t public_key_serialized[1184U];
 7665|     99|    serialize_public_key_67(
 7666|     99|        uu____0,
 7667|     99|        Eurydice_array_to_subslice_from((size_t)1184U, public_key, (size_t)1152U,
  ------------------
  |  |   79|     99|    EURYDICE_SLICE((t *)x, r, size)
  |  |  ------------------
  |  |  |  |   50|     99|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7668|     99|                                        uint8_t, size_t),
 7669|     99|        public_key_serialized);
 7670|     99|    return core_array_equality___core__cmp__PartialEq__Array_U__N___for__Array_T__N____eq(
  ------------------
  |  |   97|     99|    Eurydice_array_eq(sz, a1, a2, t, _)
  |  |  ------------------
  |  |  |  |   94|     99|    (memcmp(a1, a2, sz * sizeof(t)) == 0)
  |  |  ------------------
  ------------------
 7671|     99|        (size_t)1184U, public_key, public_key_serialized, uint8_t, uint8_t, bool);
 7672|     99|}
libcrux_ml_kem_ind_cca_encapsulate_eb:
 8939|     83|{
 8940|     83|    uint8_t randomness0[32U];
 8941|     83|    entropy_preprocess_d8_9f(
 8942|     83|        Eurydice_array_to_slice((size_t)32U, randomness, uint8_t), randomness0);
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8943|     83|    uint8_t to_hash[64U];
 8944|     83|    libcrux_ml_kem_utils_into_padded_array_6d(
 8945|     83|        Eurydice_array_to_slice((size_t)32U, randomness0, uint8_t), to_hash);
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8946|     83|    Eurydice_slice uu____0 = Eurydice_array_to_subslice_from(
  ------------------
  |  |   79|     83|    EURYDICE_SLICE((t *)x, r, size)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8947|     83|        (size_t)64U, to_hash, LIBCRUX_ML_KEM_CONSTANTS_H_DIGEST_SIZE, uint8_t,
 8948|     83|        size_t);
 8949|     83|    uint8_t ret[32U];
 8950|     83|    H_f1_19(Eurydice_array_to_slice(
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8951|     83|                (size_t)1184U, libcrux_ml_kem_types_as_slice_cb_3d0(public_key),
 8952|     83|                uint8_t),
 8953|     83|            ret);
 8954|     83|    Eurydice_slice_copy(
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 8955|     83|        uu____0, Eurydice_array_to_slice((size_t)32U, ret, uint8_t), uint8_t);
 8956|     83|    uint8_t hashed[64U];
 8957|     83|    G_f1_38(Eurydice_array_to_slice((size_t)64U, to_hash, uint8_t), hashed);
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8958|     83|    Eurydice_slice_uint8_t_x2 uu____1 = Eurydice_slice_split_at(
  ------------------
  |  |  103|     83|    (CLITERAL(ret_t){                                             \
  |  |  ------------------
  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  ------------------
  |  |  104|     83|        .fst = EURYDICE_SLICE((element_type *)slice.ptr, 0, mid), \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  105|     83|        .snd = EURYDICE_SLICE((element_type *)slice.ptr, mid, slice.len) })
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8959|     83|        Eurydice_array_to_slice((size_t)64U, hashed, uint8_t),
 8960|     83|        LIBCRUX_ML_KEM_CONSTANTS_SHARED_SECRET_SIZE, uint8_t,
 8961|     83|        Eurydice_slice_uint8_t_x2);
 8962|     83|    Eurydice_slice shared_secret = uu____1.fst;
 8963|     83|    Eurydice_slice pseudorandomness = uu____1.snd;
 8964|     83|    Eurydice_slice uu____2 = Eurydice_array_to_slice(
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8965|     83|        (size_t)1184U, libcrux_ml_kem_types_as_slice_cb_3d0(public_key), uint8_t);
 8966|       |    /* Passing arrays by value in Rust generates a copy in C */
 8967|     83|    uint8_t copy_of_randomness[32U];
 8968|     83|    memcpy(copy_of_randomness, randomness0, (size_t)32U * sizeof(uint8_t));
 8969|     83|    uint8_t ciphertext[1088U];
 8970|     83|    encrypt_7b(uu____2, copy_of_randomness, pseudorandomness, ciphertext);
 8971|       |    /* Passing arrays by value in Rust generates a copy in C */
 8972|     83|    uint8_t copy_of_ciphertext[1088U];
 8973|     83|    memcpy(copy_of_ciphertext, ciphertext, (size_t)1088U * sizeof(uint8_t));
 8974|     83|    libcrux_ml_kem_mlkem768_MlKem768Ciphertext ciphertext0 =
 8975|     83|        libcrux_ml_kem_types_from_01_330(copy_of_ciphertext);
 8976|     83|    uint8_t shared_secret_array[32U];
 8977|     83|    kdf_d8_c5(shared_secret, shared_secret_array);
 8978|     83|    libcrux_ml_kem_mlkem768_MlKem768Ciphertext uu____5 = ciphertext0;
 8979|       |    /* Passing arrays by value in Rust generates a copy in C */
 8980|     83|    uint8_t copy_of_shared_secret_array[32U];
 8981|     83|    memcpy(copy_of_shared_secret_array, shared_secret_array,
 8982|     83|           (size_t)32U * sizeof(uint8_t));
 8983|     83|    tuple_3c lit;
 8984|     83|    lit.fst = uu____5;
 8985|     83|    memcpy(lit.snd, copy_of_shared_secret_array, (size_t)32U * sizeof(uint8_t));
 8986|     83|    return lit;
 8987|     83|}
libcrux_mlkem_portable.c:ZERO_89_c3:
 2356|  5.07k|{
 2357|  5.07k|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 lit;
 2358|  5.07k|    lit.coefficients[0U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2359|  5.07k|    lit.coefficients[1U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2360|  5.07k|    lit.coefficients[2U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2361|  5.07k|    lit.coefficients[3U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2362|  5.07k|    lit.coefficients[4U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2363|  5.07k|    lit.coefficients[5U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2364|  5.07k|    lit.coefficients[6U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2365|  5.07k|    lit.coefficients[7U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2366|  5.07k|    lit.coefficients[8U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2367|  5.07k|    lit.coefficients[9U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2368|  5.07k|    lit.coefficients[10U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2369|  5.07k|    lit.coefficients[11U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2370|  5.07k|    lit.coefficients[12U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2371|  5.07k|    lit.coefficients[13U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2372|  5.07k|    lit.coefficients[14U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2373|  5.07k|    lit.coefficients[15U] = libcrux_ml_kem_vector_portable_ZERO_0d();
 2374|  5.07k|    return lit;
 2375|  5.07k|}
libcrux_mlkem_portable.c:deserialize_to_reduced_ring_element_45:
 2391|    546|{
 2392|    546|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 re = ZERO_89_c3();
 2393|    546|    for (size_t i = (size_t)0U;
 2394|  9.28k|         i < Eurydice_slice_len(serialized, uint8_t) / (size_t)24U; i++) {
  ------------------
  |  |   82|  9.28k|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|  9.28k|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (2394:10): [True: 8.73k, False: 546]
  ------------------
 2395|  8.73k|        size_t i0 = i;
 2396|  8.73k|        Eurydice_slice bytes = Eurydice_slice_subslice2(
  ------------------
  |  |   63|  8.73k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  8.73k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  8.73k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2397|  8.73k|            serialized, i0 * (size_t)24U, i0 * (size_t)24U + (size_t)24U, uint8_t);
 2398|  8.73k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector coefficient =
 2399|  8.73k|            libcrux_ml_kem_vector_portable_deserialize_12_0d(bytes);
 2400|  8.73k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 2401|  8.73k|            libcrux_ml_kem_vector_portable_cond_subtract_3329_0d(coefficient);
 2402|  8.73k|        re.coefficients[i0] = uu____0;
 2403|  8.73k|    }
 2404|    546|    return re;
 2405|    546|}
libcrux_mlkem_portable.c:serialize_uncompressed_ring_element_3c:
 2505|    297|{
 2506|    297|    uint8_t serialized[384U] = { 0U };
 2507|    297|    for (size_t i = (size_t)0U;
 2508|  5.04k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  5.04k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  5.04k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  5.04k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  5.04k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (2508:10): [True: 4.75k, False: 297]
  ------------------
 2509|  4.75k|        size_t i0 = i;
 2510|  4.75k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector coefficient =
 2511|  4.75k|            to_unsigned_representative_84(re->coefficients[i0]);
 2512|  4.75k|        uint8_t bytes[24U];
 2513|  4.75k|        libcrux_ml_kem_vector_portable_serialize_12_0d(coefficient, bytes);
 2514|  4.75k|        Eurydice_slice uu____0 = Eurydice_array_to_subslice2(
  ------------------
  |  |   75|  4.75k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  4.75k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.75k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2515|  4.75k|            serialized, (size_t)24U * i0, (size_t)24U * i0 + (size_t)24U, uint8_t);
 2516|  4.75k|        Eurydice_slice_copy(
  ------------------
  |  |   84|  4.75k|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 2517|  4.75k|            uu____0, Eurydice_array_to_slice((size_t)24U, bytes, uint8_t), uint8_t);
 2518|  4.75k|    }
 2519|    297|    memcpy(ret, serialized, (size_t)384U * sizeof(uint8_t));
 2520|    297|}
libcrux_mlkem_portable.c:to_unsigned_representative_84:
 2487|  10.0k|{
 2488|  10.0k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector t =
 2489|  10.0k|        shift_right_0d_01(a);
 2490|  10.0k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector fm =
 2491|  10.0k|        libcrux_ml_kem_vector_portable_bitwise_and_with_constant_0d(
 2492|  10.0k|            t, LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS);
  ------------------
  |  |   34|  10.0k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_MODULUS ((int16_t)3329)
  ------------------
 2493|  10.0k|    return libcrux_ml_kem_vector_portable_add_0d(a, &fm);
 2494|  10.0k|}
libcrux_mlkem_portable.c:shift_right_0d_01:
 2474|  10.0k|{
 2475|  10.0k|    return shift_right_b0(v);
 2476|  10.0k|}
libcrux_mlkem_portable.c:shift_right_b0:
 2454|  10.0k|{
 2455|  10.0k|    for (size_t i = (size_t)0U;
 2456|   171k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|   171k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (2456:10): [True: 161k, False: 10.0k]
  ------------------
 2457|   161k|        size_t i0 = i;
 2458|   161k|        v.elements[i0] = v.elements[i0] >> (uint32_t)(int32_t)15;
 2459|   161k|    }
 2460|  10.0k|    return v;
 2461|  10.0k|}
libcrux_mlkem_portable.c:from_i16_array_89_33:
 3030|  1.32k|{
 3031|  1.32k|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 result = ZERO_89_c3();
 3032|  1.32k|    for (size_t i = (size_t)0U;
 3033|  22.5k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  22.5k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  22.5k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  22.5k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  22.5k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (3033:10): [True: 21.2k, False: 1.32k]
  ------------------
 3034|  21.2k|        size_t i0 = i;
 3035|  21.2k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 3036|  21.2k|            libcrux_ml_kem_vector_portable_from_i16_array_0d(
 3037|  21.2k|                Eurydice_slice_subslice2(a, i0 * (size_t)16U,
  ------------------
  |  |   63|  21.2k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  21.2k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  21.2k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3038|  21.2k|                                         (i0 + (size_t)1U) * (size_t)16U, int16_t));
 3039|  21.2k|        result.coefficients[i0] = uu____0;
 3040|  21.2k|    }
 3041|  1.32k|    return result;
 3042|  1.32k|}
libcrux_mlkem_portable.c:sample_from_binomial_distribution_ca:
 3356|    581|{
 3357|    581|    return sample_from_binomial_distribution_2_7b(randomness);
 3358|    581|}
libcrux_mlkem_portable.c:sample_from_binomial_distribution_2_7b:
 3265|    581|{
 3266|    581|    int16_t sampled_i16s[256U] = { 0U };
 3267|    581|    for (size_t i0 = (size_t)0U;
 3268|  19.1k|         i0 < Eurydice_slice_len(randomness, uint8_t) / (size_t)4U; i0++) {
  ------------------
  |  |   82|  19.1k|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|  19.1k|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (3268:10): [True: 18.5k, False: 581]
  ------------------
 3269|  18.5k|        size_t chunk_number = i0;
 3270|  18.5k|        Eurydice_slice byte_chunk = Eurydice_slice_subslice2(
  ------------------
  |  |   63|  18.5k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  18.5k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  18.5k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3271|  18.5k|            randomness, chunk_number * (size_t)4U,
 3272|  18.5k|            chunk_number * (size_t)4U + (size_t)4U, uint8_t);
 3273|  18.5k|        uint32_t random_bits_as_u32 =
 3274|  18.5k|            (((uint32_t)Eurydice_slice_index(byte_chunk, (size_t)0U, uint8_t,
  ------------------
  |  |   57|  18.5k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 3275|  18.5k|                                             uint8_t *) |
 3276|  18.5k|              (uint32_t)Eurydice_slice_index(byte_chunk, (size_t)1U, uint8_t,
  ------------------
  |  |   57|  18.5k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 3277|  18.5k|                                             uint8_t *)
 3278|  18.5k|                  << 8U) |
 3279|  18.5k|             (uint32_t)Eurydice_slice_index(byte_chunk, (size_t)2U, uint8_t,
  ------------------
  |  |   57|  18.5k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 3280|  18.5k|                                            uint8_t *)
 3281|  18.5k|                 << 16U) |
 3282|  18.5k|            (uint32_t)Eurydice_slice_index(byte_chunk, (size_t)3U, uint8_t,
  ------------------
  |  |   57|  18.5k|#define Eurydice_slice_index(s, i, t, t_ptr_t) (((t_ptr_t)s.ptr)[i])
  ------------------
 3283|  18.5k|                                           uint8_t *)
 3284|  18.5k|                << 24U;
 3285|  18.5k|        uint32_t even_bits = random_bits_as_u32 & 1431655765U;
 3286|  18.5k|        uint32_t odd_bits = random_bits_as_u32 >> 1U & 1431655765U;
 3287|  18.5k|        uint32_t coin_toss_outcomes = even_bits + odd_bits;
 3288|   167k|        for (uint32_t i = 0U; i < CORE_NUM__U32_8__BITS / 4U; i++) {
  ------------------
  |  |   24|   167k|#define CORE_NUM__U32_8__BITS (32U)
  ------------------
  |  Branch (3288:31): [True: 148k, False: 18.5k]
  ------------------
 3289|   148k|            uint32_t outcome_set = i;
 3290|   148k|            uint32_t outcome_set0 = outcome_set * 4U;
 3291|   148k|            int16_t outcome_1 =
 3292|   148k|                (int16_t)(coin_toss_outcomes >> (uint32_t)outcome_set0 & 3U);
 3293|   148k|            int16_t outcome_2 =
 3294|   148k|                (int16_t)(coin_toss_outcomes >> (uint32_t)(outcome_set0 + 2U) & 3U);
 3295|   148k|            size_t offset = (size_t)(outcome_set0 >> 2U);
 3296|   148k|            sampled_i16s[(size_t)8U * chunk_number + offset] = outcome_1 - outcome_2;
 3297|   148k|        }
 3298|  18.5k|    }
 3299|    581|    return from_i16_array_89_33(
 3300|    581|        Eurydice_array_to_slice((size_t)256U, sampled_i16s, int16_t));
  ------------------
  |  |   69|    581|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|    581|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    581|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|    581|                   end) /* x is already at an array type, no need for cast */
  ------------------
 3301|    581|}
libcrux_mlkem_portable.c:ntt_binomially_sampled_ring_element_63:
 3558|    249|{
 3559|    249|    ntt_at_layer_7_60(re);
 3560|    249|    size_t zeta_i = (size_t)1U;
 3561|    249|    ntt_at_layer_4_plus_8c(&zeta_i, re, (size_t)6U);
 3562|    249|    ntt_at_layer_4_plus_8c(&zeta_i, re, (size_t)5U);
 3563|    249|    ntt_at_layer_4_plus_8c(&zeta_i, re, (size_t)4U);
 3564|    249|    ntt_at_layer_3_34(&zeta_i, re);
 3565|    249|    ntt_at_layer_2_26(&zeta_i, re);
 3566|    249|    ntt_at_layer_1_3c(&zeta_i, re);
 3567|    249|    poly_barrett_reduce_89_d8(re);
 3568|    249|}
libcrux_mlkem_portable.c:ntt_at_layer_7_60:
 3369|    249|{
 3370|    249|    size_t step = LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT / (size_t)2U;
  ------------------
  |  |   29|    249|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|    249|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|    249|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|    249|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
 3371|  2.24k|    for (size_t i = (size_t)0U; i < step; i++) {
  ------------------
  |  Branch (3371:33): [True: 1.99k, False: 249]
  ------------------
 3372|  1.99k|        size_t j = i;
 3373|  1.99k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector t =
 3374|  1.99k|            libcrux_ml_kem_vector_portable_multiply_by_constant_0d(
 3375|  1.99k|                re->coefficients[j + step], (int16_t)-1600);
 3376|  1.99k|        re->coefficients[j + step] =
 3377|  1.99k|            libcrux_ml_kem_vector_portable_sub_0d(re->coefficients[j], &t);
 3378|  1.99k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____1 =
 3379|  1.99k|            libcrux_ml_kem_vector_portable_add_0d(re->coefficients[j], &t);
 3380|  1.99k|        re->coefficients[j] = uu____1;
 3381|  1.99k|    }
 3382|    249|}
libcrux_mlkem_portable.c:ntt_at_layer_4_plus_8c:
 3435|    747|{
 3436|    747|    size_t step = (size_t)1U << (uint32_t)layer;
 3437|  4.23k|    for (size_t i0 = (size_t)0U; i0 < (size_t)128U >> (uint32_t)layer; i0++) {
  ------------------
  |  Branch (3437:34): [True: 3.48k, False: 747]
  ------------------
 3438|  3.48k|        size_t round = i0;
 3439|  3.48k|        zeta_i[0U] = zeta_i[0U] + (size_t)1U;
 3440|  3.48k|        size_t offset = round * step * (size_t)2U;
 3441|  3.48k|        size_t offset_vec = offset / (size_t)16U;
 3442|  3.48k|        size_t step_vec = step / (size_t)16U;
 3443|  9.46k|        for (size_t i = offset_vec; i < offset_vec + step_vec; i++) {
  ------------------
  |  Branch (3443:37): [True: 5.97k, False: 3.48k]
  ------------------
 3444|  5.97k|            size_t j = i;
 3445|  5.97k|            libcrux_ml_kem_vector_portable_vector_type_PortableVector_x2 uu____0 =
 3446|  5.97k|                ntt_layer_int_vec_step_88(
 3447|  5.97k|                    re->coefficients[j], re->coefficients[j + step_vec],
 3448|  5.97k|                    libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]]);
 3449|  5.97k|            libcrux_ml_kem_vector_portable_vector_type_PortableVector x = uu____0.fst;
 3450|  5.97k|            libcrux_ml_kem_vector_portable_vector_type_PortableVector y = uu____0.snd;
 3451|  5.97k|            re->coefficients[j] = x;
 3452|  5.97k|            re->coefficients[j + step_vec] = y;
 3453|  5.97k|        }
 3454|  3.48k|    }
 3455|    747|}
libcrux_mlkem_portable.c:ntt_layer_int_vec_step_88:
 3415|  5.97k|{
 3416|  5.97k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector t =
 3417|  5.97k|        montgomery_multiply_fe_05(b, zeta_r);
 3418|  5.97k|    b = libcrux_ml_kem_vector_portable_sub_0d(a, &t);
 3419|  5.97k|    a = libcrux_ml_kem_vector_portable_add_0d(a, &t);
 3420|  5.97k|    return (
 3421|  5.97k|        CLITERAL(libcrux_ml_kem_vector_portable_vector_type_PortableVector_x2){
  ------------------
  |  |   27|  5.97k|#define CLITERAL(type) (type)
  ------------------
 3422|  5.97k|            .fst = a, .snd = b });
 3423|  5.97k|}
libcrux_mlkem_portable.c:montgomery_multiply_fe_05:
 3398|  16.6k|{
 3399|  16.6k|    return libcrux_ml_kem_vector_portable_montgomery_multiply_by_constant_0d(v,
 3400|  16.6k|                                                                             fer);
 3401|  16.6k|}
libcrux_mlkem_portable.c:ntt_at_layer_3_34:
 3466|    249|{
 3467|    249|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|    249|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3468|    249|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t round = i;
 3469|    249|        zeta_i[0U] = zeta_i[0U] + (size_t)1U;
 3470|    249|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 3471|    249|            libcrux_ml_kem_vector_portable_ntt_layer_3_step_0d(
 3472|    249|                re->coefficients[round],
 3473|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]]);
 3474|    249|        re->coefficients[round] = uu____0;);
 3475|    249|}
libcrux_mlkem_portable.c:ntt_at_layer_2_26:
 3486|    249|{
 3487|    249|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|    249|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3488|    249|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t round = i;
 3489|    249|        zeta_i[0U] = zeta_i[0U] + (size_t)1U;
 3490|    249|        re->coefficients[round] =
 3491|    249|            libcrux_ml_kem_vector_portable_ntt_layer_2_step_0d(
 3492|    249|                re->coefficients[round],
 3493|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]],
 3494|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] +
 3495|    249|                                                                   (size_t)1U]);
 3496|    249|        zeta_i[0U] = zeta_i[0U] + (size_t)1U;);
 3497|    249|}
libcrux_mlkem_portable.c:ntt_at_layer_1_3c:
 3508|    249|{
 3509|    249|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|    249|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3510|    249|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t round = i;
 3511|    249|        zeta_i[0U] = zeta_i[0U] + (size_t)1U;
 3512|    249|        re->coefficients[round] =
 3513|    249|            libcrux_ml_kem_vector_portable_ntt_layer_1_step_0d(
 3514|    249|                re->coefficients[round],
 3515|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]],
 3516|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] +
 3517|    249|                                                                   (size_t)1U],
 3518|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] +
 3519|    249|                                                                   (size_t)2U],
 3520|    249|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] +
 3521|    249|                                                                   (size_t)3U]);
 3522|    249|        zeta_i[0U] = zeta_i[0U] + (size_t)3U;);
 3523|    249|}
libcrux_mlkem_portable.c:poly_barrett_reduce_89_d8:
 3538|    581|{
 3539|    581|    for (size_t i = (size_t)0U;
 3540|  9.87k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  9.87k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  9.87k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  9.87k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  9.87k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (3540:10): [True: 9.29k, False: 581]
  ------------------
 3541|  9.29k|        size_t i0 = i;
 3542|  9.29k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 3543|  9.29k|            libcrux_ml_kem_vector_portable_barrett_reduce_0d(
 3544|  9.29k|                self->coefficients[i0]);
 3545|  9.29k|        self->coefficients[i0] = uu____0;
 3546|  9.29k|    }
 3547|    581|}
libcrux_mlkem_portable.c:ntt_multiply_89_3b:
 3660|    996|{
 3661|    996|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 out = ZERO_89_c3();
 3662|    996|    for (size_t i = (size_t)0U;
 3663|  16.9k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  16.9k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  16.9k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  16.9k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  16.9k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (3663:10): [True: 15.9k, False: 996]
  ------------------
 3664|  15.9k|        size_t i0 = i;
 3665|  15.9k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 3666|  15.9k|            libcrux_ml_kem_vector_portable_ntt_multiply_0d(
 3667|  15.9k|                &self->coefficients[i0], &rhs->coefficients[i0],
 3668|  15.9k|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[(size_t)64U +
 3669|  15.9k|                                                                   (size_t)4U * i0],
 3670|  15.9k|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[(size_t)64U +
 3671|  15.9k|                                                                   (size_t)4U * i0 +
 3672|  15.9k|                                                                   (size_t)1U],
 3673|  15.9k|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[(size_t)64U +
 3674|  15.9k|                                                                   (size_t)4U * i0 +
 3675|  15.9k|                                                                   (size_t)2U],
 3676|  15.9k|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[(size_t)64U +
 3677|  15.9k|                                                                   (size_t)4U * i0 +
 3678|  15.9k|                                                                   (size_t)3U]);
 3679|  15.9k|        out.coefficients[i0] = uu____0;
 3680|  15.9k|    }
 3681|    996|    return out;
 3682|    996|}
libcrux_mlkem_portable.c:PRF_7c0:
 4110|     83|{
 4111|     83|    uint8_t digest[128U] = { 0U };
 4112|     83|    libcrux_sha3_portable_shake256(
 4113|     83|        Eurydice_array_to_slice((size_t)128U, digest, uint8_t), input);
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 4114|     83|    memcpy(ret, digest, (size_t)128U * sizeof(uint8_t));
 4115|     83|}
libcrux_mlkem_portable.c:invert_ntt_at_layer_1_4b:
 4143|    332|{
 4144|    332|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|    332|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|    332|    do {                               \
  |  |  |  |  289|    332|        uint32_t i = z;                \
  |  |  |  |  290|    332|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    332|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4145|    332|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t round = i;
 4146|    332|        zeta_i[0U] = zeta_i[0U] - (size_t)1U;
 4147|    332|        re->coefficients[round] =
 4148|    332|            libcrux_ml_kem_vector_portable_inv_ntt_layer_1_step_0d(
 4149|    332|                re->coefficients[round],
 4150|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]],
 4151|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] -
 4152|    332|                                                                   (size_t)1U],
 4153|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] -
 4154|    332|                                                                   (size_t)2U],
 4155|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] -
 4156|    332|                                                                   (size_t)3U]);
 4157|    332|        zeta_i[0U] = zeta_i[0U] - (size_t)3U;);
 4158|    332|}
libcrux_mlkem_portable.c:invert_ntt_at_layer_2_2b:
 4169|    332|{
 4170|    332|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|    332|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|    332|    do {                               \
  |  |  |  |  289|    332|        uint32_t i = z;                \
  |  |  |  |  290|    332|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    332|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4171|    332|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t round = i;
 4172|    332|        zeta_i[0U] = zeta_i[0U] - (size_t)1U;
 4173|    332|        re->coefficients[round] =
 4174|    332|            libcrux_ml_kem_vector_portable_inv_ntt_layer_2_step_0d(
 4175|    332|                re->coefficients[round],
 4176|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]],
 4177|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U] -
 4178|    332|                                                                   (size_t)1U]);
 4179|    332|        zeta_i[0U] = zeta_i[0U] - (size_t)1U;);
 4180|    332|}
libcrux_mlkem_portable.c:invert_ntt_at_layer_3_97:
 4191|    332|{
 4192|    332|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|    332|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|    332|    do {                               \
  |  |  |  |  289|    332|        uint32_t i = z;                \
  |  |  |  |  290|    332|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    332|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4193|    332|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t round = i;
 4194|    332|        zeta_i[0U] = zeta_i[0U] - (size_t)1U;
 4195|    332|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 4196|    332|            libcrux_ml_kem_vector_portable_inv_ntt_layer_3_step_0d(
 4197|    332|                re->coefficients[round],
 4198|    332|                libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]]);
 4199|    332|        re->coefficients[round] = uu____0;);
 4200|    332|}
libcrux_mlkem_portable.c:invert_ntt_at_layer_4_plus_04:
 4235|  1.32k|{
 4236|  1.32k|    size_t step = (size_t)1U << (uint32_t)layer;
 4237|  6.30k|    for (size_t i0 = (size_t)0U; i0 < (size_t)128U >> (uint32_t)layer; i0++) {
  ------------------
  |  Branch (4237:34): [True: 4.98k, False: 1.32k]
  ------------------
 4238|  4.98k|        size_t round = i0;
 4239|  4.98k|        zeta_i[0U] = zeta_i[0U] - (size_t)1U;
 4240|  4.98k|        size_t offset = round * step * (size_t)2U;
 4241|  4.98k|        size_t offset_vec =
 4242|  4.98k|            offset / LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR;
  ------------------
  |  |   32|  4.98k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
 4243|  4.98k|        size_t step_vec =
 4244|  4.98k|            step / LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR;
  ------------------
  |  |   32|  4.98k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
 4245|  15.6k|        for (size_t i = offset_vec; i < offset_vec + step_vec; i++) {
  ------------------
  |  Branch (4245:37): [True: 10.6k, False: 4.98k]
  ------------------
 4246|  10.6k|            size_t j = i;
 4247|  10.6k|            libcrux_ml_kem_vector_portable_vector_type_PortableVector_x2 uu____0 =
 4248|  10.6k|                inv_ntt_layer_int_vec_step_reduce_aa(
 4249|  10.6k|                    re->coefficients[j], re->coefficients[j + step_vec],
 4250|  10.6k|                    libcrux_ml_kem_polynomial_ZETAS_TIMES_MONTGOMERY_R[zeta_i[0U]]);
 4251|  10.6k|            libcrux_ml_kem_vector_portable_vector_type_PortableVector x = uu____0.fst;
 4252|  10.6k|            libcrux_ml_kem_vector_portable_vector_type_PortableVector y = uu____0.snd;
 4253|  10.6k|            re->coefficients[j] = x;
 4254|  10.6k|            re->coefficients[j + step_vec] = y;
 4255|  10.6k|        }
 4256|  4.98k|    }
 4257|  1.32k|}
libcrux_mlkem_portable.c:inv_ntt_layer_int_vec_step_reduce_aa:
 4214|  10.6k|{
 4215|  10.6k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector a_minus_b =
 4216|  10.6k|        libcrux_ml_kem_vector_portable_sub_0d(b, &a);
 4217|  10.6k|    a = libcrux_ml_kem_vector_portable_barrett_reduce_0d(
 4218|  10.6k|        libcrux_ml_kem_vector_portable_add_0d(a, &b));
 4219|  10.6k|    b = montgomery_multiply_fe_05(a_minus_b, zeta_r);
 4220|  10.6k|    return (
 4221|  10.6k|        CLITERAL(libcrux_ml_kem_vector_portable_vector_type_PortableVector_x2){
  ------------------
  |  |   27|  10.6k|#define CLITERAL(type) (type)
  ------------------
 4222|  10.6k|            .fst = a, .snd = b });
 4223|  10.6k|}
libcrux_mlkem_portable.c:add_error_reduce_89_5d:
 4295|    249|{
 4296|    249|    for (size_t i = (size_t)0U;
 4297|  4.23k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  4.23k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  4.23k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  4.23k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  4.23k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (4297:10): [True: 3.98k, False: 249]
  ------------------
 4298|  3.98k|        size_t j = i;
 4299|  3.98k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector
 4300|  3.98k|            coefficient_normal_form =
 4301|  3.98k|                libcrux_ml_kem_vector_portable_montgomery_multiply_by_constant_0d(
 4302|  3.98k|                    self->coefficients[j], (int16_t)1441);
 4303|  3.98k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 4304|  3.98k|            libcrux_ml_kem_vector_portable_barrett_reduce_0d(
 4305|  3.98k|                libcrux_ml_kem_vector_portable_add_0d(coefficient_normal_form,
 4306|  3.98k|                                                      &error->coefficients[j]));
 4307|  3.98k|        self->coefficients[j] = uu____0;
 4308|  3.98k|    }
 4309|    249|}
libcrux_mlkem_portable.c:deserialize_then_decompress_message_f7:
 4383|     83|{
 4384|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 re = ZERO_89_c3();
 4385|     83|    KRML_MAYBE_FOR16(
  ------------------
  |  |  402|     83|#define KRML_MAYBE_FOR16(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 16, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4386|     83|        i, (size_t)0U, (size_t)16U, (size_t)1U, size_t i0 = i;
 4387|     83|        libcrux_ml_kem_vector_portable_vector_type_PortableVector
 4388|     83|            coefficient_compressed =
 4389|     83|                libcrux_ml_kem_vector_portable_deserialize_1_0d(
 4390|     83|                    Eurydice_array_to_subslice2(serialized, (size_t)2U * i0,
 4391|     83|                                                (size_t)2U * i0 + (size_t)2U,
 4392|     83|                                                uint8_t));
 4393|     83|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 4394|     83|            decompress_1_3e(coefficient_compressed);
 4395|     83|        re.coefficients[i0] = uu____0;);
 4396|     83|    return re;
 4397|     83|}
libcrux_mlkem_portable.c:decompress_1_3e:
 4368|  1.32k|{
 4369|  1.32k|    libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 4370|  1.32k|        libcrux_ml_kem_vector_portable_ZERO_0d();
 4371|  1.32k|    return libcrux_ml_kem_vector_portable_bitwise_and_with_constant_0d(
 4372|  1.32k|        libcrux_ml_kem_vector_portable_sub_0d(uu____0, &v), (int16_t)1665);
 4373|  1.32k|}
libcrux_mlkem_portable.c:add_message_error_reduce_89_c4:
 4414|     83|{
 4415|     83|    for (size_t i = (size_t)0U;
 4416|  1.41k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  1.41k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  1.41k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  1.41k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  1.41k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (4416:10): [True: 1.32k, False: 83]
  ------------------
 4417|  1.32k|        size_t i0 = i;
 4418|  1.32k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector
 4419|  1.32k|            coefficient_normal_form =
 4420|  1.32k|                libcrux_ml_kem_vector_portable_montgomery_multiply_by_constant_0d(
 4421|  1.32k|                    result.coefficients[i0], (int16_t)1441);
 4422|  1.32k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector tmp =
 4423|  1.32k|            libcrux_ml_kem_vector_portable_add_0d(self->coefficients[i0],
 4424|  1.32k|                                                  &message->coefficients[i0]);
 4425|  1.32k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector tmp0 =
 4426|  1.32k|            libcrux_ml_kem_vector_portable_add_0d(coefficient_normal_form, &tmp);
 4427|  1.32k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 4428|  1.32k|            libcrux_ml_kem_vector_portable_barrett_reduce_0d(tmp0);
 4429|  1.32k|        result.coefficients[i0] = uu____0;
 4430|  1.32k|    }
 4431|     83|    return result;
 4432|     83|}
libcrux_mlkem_portable.c:compress_then_serialize_ring_element_u_2e:
 6944|    249|{
 6945|    249|    uint8_t uu____0[320U];
 6946|    249|    compress_then_serialize_10_88(re, uu____0);
 6947|    249|    memcpy(ret, uu____0, (size_t)320U * sizeof(uint8_t));
 6948|    249|}
libcrux_mlkem_portable.c:compress_then_serialize_10_88:
 6917|    249|{
 6918|    249|    uint8_t serialized[320U] = { 0U };
 6919|    249|    for (size_t i = (size_t)0U;
 6920|  4.23k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  4.23k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  4.23k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  4.23k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  4.23k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (6920:10): [True: 3.98k, False: 249]
  ------------------
 6921|  3.98k|        size_t i0 = i;
 6922|  3.98k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector coefficient =
 6923|  3.98k|            compress_0d_96(to_unsigned_representative_84(re->coefficients[i0]));
 6924|  3.98k|        uint8_t bytes[20U];
 6925|  3.98k|        libcrux_ml_kem_vector_portable_serialize_10_0d(coefficient, bytes);
 6926|  3.98k|        Eurydice_slice uu____0 = Eurydice_array_to_subslice2(
  ------------------
  |  |   75|  3.98k|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|  3.98k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  3.98k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6927|  3.98k|            serialized, (size_t)20U * i0, (size_t)20U * i0 + (size_t)20U, uint8_t);
 6928|  3.98k|        Eurydice_slice_copy(
  ------------------
  |  |   84|  3.98k|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 6929|  3.98k|            uu____0, Eurydice_array_to_slice((size_t)20U, bytes, uint8_t), uint8_t);
 6930|  3.98k|    }
 6931|    249|    memcpy(ret, serialized, (size_t)320U * sizeof(uint8_t));
 6932|    249|}
libcrux_mlkem_portable.c:compress_0d_96:
 4491|  3.98k|{
 4492|  3.98k|    return compress_dc(v);
 4493|  3.98k|}
libcrux_mlkem_portable.c:compress_dc:
 4467|  3.98k|{
 4468|  3.98k|    for (size_t i = (size_t)0U;
 4469|  67.7k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|  67.7k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (4469:10): [True: 63.7k, False: 3.98k]
  ------------------
 4470|  63.7k|        size_t i0 = i;
 4471|  63.7k|        int16_t uu____0 =
 4472|  63.7k|            libcrux_ml_kem_vector_portable_compress_compress_ciphertext_coefficient(
 4473|  63.7k|                (uint8_t)(int32_t)10, (uint16_t)v.elements[i0]);
 4474|  63.7k|        v.elements[i0] = uu____0;
 4475|  63.7k|    }
 4476|  3.98k|    return v;
 4477|  3.98k|}
libcrux_mlkem_portable.c:compress_then_serialize_ring_element_v_65:
 6996|     83|{
 6997|     83|    compress_then_serialize_4_80(re, out);
 6998|     83|}
libcrux_mlkem_portable.c:compress_then_serialize_4_80:
 4651|     83|{
 4652|     83|    for (size_t i = (size_t)0U;
 4653|  1.41k|         i < LIBCRUX_ML_KEM_POLYNOMIAL_VECTORS_IN_RING_ELEMENT; i++) {
  ------------------
  |  |   29|  1.41k|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / \
  |  |  ------------------
  |  |  |  |   36|  1.41k|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  ------------------
  |  |   30|  1.41k|     LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR)
  |  |  ------------------
  |  |  |  |   32|  1.41k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  |  |  ------------------
  ------------------
  |  Branch (4653:10): [True: 1.32k, False: 83]
  ------------------
 4654|  1.32k|        size_t i0 = i;
 4655|  1.32k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector coefficient =
 4656|  1.32k|            compress_0d_961(to_unsigned_representative_84(re.coefficients[i0]));
 4657|  1.32k|        uint8_t bytes[8U];
 4658|  1.32k|        libcrux_ml_kem_vector_portable_serialize_4_0d(coefficient, bytes);
 4659|  1.32k|        Eurydice_slice_copy(
  ------------------
  |  |   84|  1.32k|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 4660|  1.32k|            Eurydice_slice_subslice2(serialized, (size_t)8U * i0,
 4661|  1.32k|                                     (size_t)8U * i0 + (size_t)8U, uint8_t),
 4662|  1.32k|            Eurydice_array_to_slice((size_t)8U, bytes, uint8_t), uint8_t);
 4663|  1.32k|    }
 4664|     83|}
libcrux_mlkem_portable.c:compress_0d_961:
 4637|  1.32k|{
 4638|  1.32k|    return compress_dc1(v);
 4639|  1.32k|}
libcrux_mlkem_portable.c:compress_dc1:
 4614|  1.32k|{
 4615|  1.32k|    for (size_t i = (size_t)0U;
 4616|  22.5k|         i < LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR; i++) {
  ------------------
  |  |   32|  22.5k|#define LIBCRUX_ML_KEM_VECTOR_TRAITS_FIELD_ELEMENTS_IN_VECTOR ((size_t)16U)
  ------------------
  |  Branch (4616:10): [True: 21.2k, False: 1.32k]
  ------------------
 4617|  21.2k|        size_t i0 = i;
 4618|  21.2k|        int16_t uu____0 =
 4619|  21.2k|            libcrux_ml_kem_vector_portable_compress_compress_ciphertext_coefficient(
 4620|  21.2k|                (uint8_t)(int32_t)4, (uint16_t)v.elements[i0]);
 4621|  21.2k|        v.elements[i0] = uu____0;
 4622|  21.2k|    }
 4623|  1.32k|    return v;
 4624|  1.32k|}
libcrux_mlkem_portable.c:deserialize_ring_elements_reduced_4f0:
 7550|     99|{
 7551|     99|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 deserialized_pk[3U];
 7552|     99|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|     99|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     99|    do {                               \
  |  |  |  |  289|     99|        uint32_t i = z;                \
  |  |  |  |  290|     99|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     99|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7553|     99|                    deserialized_pk[i] = ZERO_89_c3(););
 7554|     99|    for (size_t i = (size_t)0U;
 7555|    396|         i < Eurydice_slice_len(public_key, uint8_t) /
  ------------------
  |  |   82|    396|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    396|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (7555:10): [True: 297, False: 99]
  ------------------
 7556|    396|                 LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT;
  ------------------
  |  |   42|    396|    (LIBCRUX_ML_KEM_CONSTANTS_BITS_PER_RING_ELEMENT / (size_t)8U)
  |  |  ------------------
  |  |  |  |   39|    396|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT * (size_t)12U)
  |  |  |  |  ------------------
  |  |  |  |  |  |   36|    396|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7557|    297|         i++) {
 7558|    297|        size_t i0 = i;
 7559|    297|        Eurydice_slice ring_element = Eurydice_slice_subslice2(
  ------------------
  |  |   63|    297|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|    297|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    297|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7560|    297|            public_key, i0 * LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT,
 7561|    297|            i0 * LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT +
 7562|    297|                LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT,
 7563|    297|            uint8_t);
 7564|    297|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 uu____0 =
 7565|    297|            deserialize_to_reduced_ring_element_45(ring_element);
 7566|    297|        deserialized_pk[i0] = uu____0;
 7567|    297|    }
 7568|     99|    memcpy(
 7569|     99|        ret, deserialized_pk,
 7570|     99|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 7571|     99|}
libcrux_mlkem_portable.c:serialize_public_key_67:
 7625|     99|{
 7626|     99|    uint8_t public_key_serialized[1184U] = { 0U };
 7627|     99|    Eurydice_slice uu____0 = Eurydice_array_to_subslice2(
  ------------------
  |  |   75|     99|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|     99|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7628|     99|        public_key_serialized, (size_t)0U, (size_t)1152U, uint8_t);
 7629|     99|    uint8_t ret0[1152U];
 7630|     99|    serialize_secret_key_a3(t_as_ntt, ret0);
 7631|     99|    Eurydice_slice_copy(
  ------------------
  |  |   84|     99|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 7632|     99|        uu____0, Eurydice_array_to_slice((size_t)1152U, ret0, uint8_t), uint8_t);
 7633|     99|    Eurydice_slice_copy(
  ------------------
  |  |   84|     99|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 7634|     99|        Eurydice_array_to_subslice_from((size_t)1184U, public_key_serialized,
 7635|     99|                                        (size_t)1152U, uint8_t, size_t),
 7636|     99|        seed_for_a, uint8_t);
 7637|     99|    memcpy(ret, public_key_serialized, (size_t)1184U * sizeof(uint8_t));
 7638|     99|}
libcrux_mlkem_portable.c:serialize_secret_key_a3:
 7587|     99|{
 7588|     99|    uint8_t out[1152U] = { 0U };
 7589|     99|    for (size_t i = (size_t)0U;
 7590|    396|         i < Eurydice_slice_len(
  ------------------
  |  |   82|    396|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    396|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (7590:10): [True: 297, False: 99]
  ------------------
 7591|     99|                 Eurydice_array_to_slice(
 7592|     99|                     (size_t)3U, key,
 7593|     99|                     libcrux_ml_kem_polynomial_PolynomialRingElement_f0),
 7594|     99|                 libcrux_ml_kem_polynomial_PolynomialRingElement_f0);
 7595|    297|         i++) {
 7596|    297|        size_t i0 = i;
 7597|    297|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 re = key[i0];
 7598|    297|        Eurydice_slice uu____0 = Eurydice_array_to_subslice2(
  ------------------
  |  |   75|    297|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|    297|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    297|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7599|    297|            out, i0 * LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT,
 7600|    297|            (i0 + (size_t)1U) * LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT,
 7601|    297|            uint8_t);
 7602|    297|        uint8_t ret0[384U];
 7603|    297|        serialize_uncompressed_ring_element_3c(&re, ret0);
 7604|    297|        Eurydice_slice_copy(
  ------------------
  |  |   84|    297|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 7605|    297|            uu____0, Eurydice_array_to_slice((size_t)384U, ret0, uint8_t), uint8_t);
 7606|    297|    }
 7607|     99|    memcpy(ret, out, (size_t)1152U * sizeof(uint8_t));
 7608|     99|}
libcrux_mlkem_portable.c:H_f1_19:
 7685|     83|{
 7686|     83|    libcrux_ml_kem_hash_functions_portable_H(input, ret);
 7687|     83|}
libcrux_mlkem_portable.c:sample_matrix_A_e7:
 8145|     83|{
 8146|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 A_transpose[3U][3U];
 8147|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8148|     83|                    closure_fc(A_transpose[i]););
 8149|     83|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8150|     83|        i0, (size_t)0U, (size_t)3U, (size_t)1U, size_t i1 = i0;
 8151|       |        /* Passing arrays by value in Rust generates a copy in C */
 8152|     83|        uint8_t copy_of_seed[34U];
 8153|     83|        memcpy(copy_of_seed, seed, (size_t)34U * sizeof(uint8_t));
 8154|     83|        uint8_t seeds[3U][34U]; KRML_MAYBE_FOR3(
 8155|     83|            i, (size_t)0U, (size_t)3U, (size_t)1U,
 8156|     83|            memcpy(seeds[i], copy_of_seed, (size_t)34U * sizeof(uint8_t)););
 8157|     83|        KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U, size_t j = i;
 8158|     83|                        seeds[j][32U] = (uint8_t)i1; seeds[j][33U] = (uint8_t)j;);
 8159|       |        /* Passing arrays by value in Rust generates a copy in C */
 8160|     83|        uint8_t copy_of_seeds[3U][34U];
 8161|     83|        memcpy(copy_of_seeds, seeds, (size_t)3U * sizeof(uint8_t[34U]));
 8162|     83|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 sampled[3U];
 8163|     83|        sample_from_xof_46(copy_of_seeds, sampled);
 8164|     83|        for (size_t i = (size_t)0U;
 8165|     83|             i < Eurydice_slice_len(
 8166|     83|                     Eurydice_array_to_slice(
 8167|     83|                         (size_t)3U, sampled,
 8168|     83|                         libcrux_ml_kem_polynomial_PolynomialRingElement_f0),
 8169|     83|                     libcrux_ml_kem_polynomial_PolynomialRingElement_f0);
 8170|     83|             i++) {
 8171|     83|            size_t j = i;
 8172|     83|            libcrux_ml_kem_polynomial_PolynomialRingElement_f0 sample = sampled[j];
 8173|     83|            if (transpose) {
 8174|     83|                A_transpose[j][i1] = sample;
 8175|     83|            } else {
 8176|     83|                A_transpose[i1][j] = sample;
 8177|     83|            }
 8178|     83|        }
 8179|       |
 8180|     83|    );
 8181|     83|    memcpy(ret, A_transpose,
 8182|     83|           (size_t)3U *
 8183|     83|               sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0[3U]));
 8184|     83|}
libcrux_mlkem_portable.c:closure_fc:
 7773|    249|{
 7774|    249|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7775|    249|                    ret[i] = ZERO_89_c3(););
 7776|    249|}
libcrux_mlkem_portable.c:sample_from_xof_46:
 8095|    249|{
 8096|    249|    size_t sampled_coefficients[3U] = { 0U };
 8097|    249|    int16_t out[3U][272U] = { { 0U } };
 8098|       |    /* Passing arrays by value in Rust generates a copy in C */
 8099|    249|    uint8_t copy_of_seeds[3U][34U];
 8100|    249|    memcpy(copy_of_seeds, seeds, (size_t)3U * sizeof(uint8_t[34U]));
 8101|    249|    PortableHash_58 xof_state = shake128_init_absorb_f1_77(copy_of_seeds);
 8102|    249|    uint8_t randomness0[3U][504U];
 8103|    249|    shake128_squeeze_three_blocks_f1_84(&xof_state, randomness0);
 8104|       |    /* Passing arrays by value in Rust generates a copy in C */
 8105|    249|    uint8_t copy_of_randomness0[3U][504U];
 8106|    249|    memcpy(copy_of_randomness0, randomness0, (size_t)3U * sizeof(uint8_t[504U]));
 8107|    249|    bool done = sample_from_uniform_distribution_next_17(
 8108|    249|        copy_of_randomness0, sampled_coefficients, out);
 8109|    329|    while (true) {
 8110|    329|        if (done) {
  ------------------
  |  Branch (8110:13): [True: 249, False: 80]
  ------------------
 8111|    249|            break;
 8112|    249|        } else {
 8113|     80|            uint8_t randomness[3U][168U];
 8114|     80|            shake128_squeeze_block_f1_8e(&xof_state, randomness);
 8115|       |            /* Passing arrays by value in Rust generates a copy in C */
 8116|     80|            uint8_t copy_of_randomness[3U][168U];
 8117|     80|            memcpy(copy_of_randomness, randomness,
 8118|     80|                   (size_t)3U * sizeof(uint8_t[168U]));
 8119|     80|            done = sample_from_uniform_distribution_next_170(
 8120|     80|                copy_of_randomness, sampled_coefficients, out);
 8121|     80|        }
 8122|    329|    }
 8123|       |    /* Passing arrays by value in Rust generates a copy in C */
 8124|    249|    int16_t copy_of_out[3U][272U];
 8125|    249|    memcpy(copy_of_out, out, (size_t)3U * sizeof(int16_t[272U]));
 8126|    249|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 ret0[3U];
 8127|    249|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8128|    249|                    ret0[i] = closure_e4(copy_of_out[i]););
 8129|    249|    memcpy(
 8130|    249|        ret, ret0,
 8131|    249|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8132|    249|}
libcrux_mlkem_portable.c:shake128_init_absorb_f1_77:
 7826|    249|{
 7827|       |    /* Passing arrays by value in Rust generates a copy in C */
 7828|    249|    uint8_t copy_of_input[3U][34U];
 7829|    249|    memcpy(copy_of_input, input, (size_t)3U * sizeof(uint8_t[34U]));
 7830|    249|    return shake128_init_absorb_79(copy_of_input);
 7831|    249|}
libcrux_mlkem_portable.c:shake128_init_absorb_79:
 7794|    249|{
 7795|    249|    libcrux_sha3_generic_keccak_KeccakState_48 shake128_state[3U];
 7796|    249|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7797|    249|        i, (size_t)0U, (size_t)3U, (size_t)1U,
 7798|    249|        shake128_state[i] = libcrux_sha3_portable_incremental_shake128_init(););
 7799|    249|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7800|    249|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 7801|    249|        libcrux_sha3_portable_incremental_shake128_absorb_final(
 7802|    249|            &shake128_state[i0],
 7803|    249|            Eurydice_array_to_slice((size_t)34U, input[i0], uint8_t)););
 7804|       |    /* Passing arrays by value in Rust generates a copy in C */
 7805|    249|    libcrux_sha3_generic_keccak_KeccakState_48 copy_of_shake128_state[3U];
 7806|    249|    memcpy(copy_of_shake128_state, shake128_state,
 7807|    249|           (size_t)3U * sizeof(libcrux_sha3_generic_keccak_KeccakState_48));
 7808|    249|    PortableHash_58 lit;
 7809|    249|    memcpy(lit.shake128_state, copy_of_shake128_state,
 7810|    249|           (size_t)3U * sizeof(libcrux_sha3_generic_keccak_KeccakState_48));
 7811|    249|    return lit;
 7812|    249|}
libcrux_mlkem_portable.c:shake128_squeeze_three_blocks_f1_84:
 7865|    249|{
 7866|    249|    shake128_squeeze_three_blocks_eb(self, ret);
 7867|    249|}
libcrux_mlkem_portable.c:shake128_squeeze_three_blocks_eb:
 7842|    249|{
 7843|    249|    uint8_t out[3U][504U] = { { 0U } };
 7844|    249|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7845|    249|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 7846|    249|        libcrux_sha3_portable_incremental_shake128_squeeze_first_three_blocks(
 7847|    249|            &st->shake128_state[i0],
 7848|    249|            Eurydice_array_to_slice((size_t)504U, out[i0], uint8_t)););
 7849|    249|    memcpy(ret, out, (size_t)3U * sizeof(uint8_t[504U]));
 7850|    249|}
libcrux_mlkem_portable.c:sample_from_uniform_distribution_next_17:
 7921|    249|{
 7922|    249|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7923|    249|        i0, (size_t)0U, (size_t)3U, (size_t)1U, size_t i1 = i0;
 7924|    249|        for (size_t i = (size_t)0U; i < (size_t)504U / (size_t)24U; i++) {
 7925|    249|            size_t r = i;
 7926|    249|            if (sampled_coefficients[i1] <
 7927|    249|                LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT) {
 7928|    249|                Eurydice_slice uu____0 = Eurydice_array_to_subslice2(
 7929|    249|                    randomness[i1], r * (size_t)24U, r * (size_t)24U + (size_t)24U,
 7930|    249|                    uint8_t);
 7931|    249|                size_t sampled = libcrux_ml_kem_vector_portable_rej_sample_0d(
 7932|    249|                    uu____0, Eurydice_array_to_subslice2(
 7933|    249|                                 out[i1], sampled_coefficients[i1],
 7934|    249|                                 sampled_coefficients[i1] + (size_t)16U, int16_t));
 7935|    249|                size_t uu____1 = i1;
 7936|    249|                sampled_coefficients[uu____1] =
 7937|    249|                    sampled_coefficients[uu____1] + sampled;
 7938|    249|            }
 7939|    249|        });
 7940|    249|    bool done = true;
 7941|    249|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|    249|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    249|    do {                               \
  |  |  |  |  289|    249|        uint32_t i = z;                \
  |  |  |  |  290|    249|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    249|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7942|    249|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 7943|    249|        if (sampled_coefficients[i0] >=
 7944|    249|            LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT) {
 7945|    249|            sampled_coefficients[i0] =
 7946|    249|                LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT;
 7947|    249|        } else { done = false; });
 7948|    249|    return done;
 7949|    249|}
libcrux_mlkem_portable.c:shake128_squeeze_block_f1_8e:
 7983|     80|{
 7984|     80|    shake128_squeeze_block_3b(self, ret);
 7985|     80|}
libcrux_mlkem_portable.c:shake128_squeeze_block_3b:
 7960|     80|{
 7961|     80|    uint8_t out[3U][168U] = { { 0U } };
 7962|     80|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     80|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     80|    do {                               \
  |  |  |  |  289|     80|        uint32_t i = z;                \
  |  |  |  |  290|     80|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     80|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7963|     80|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 7964|     80|        libcrux_sha3_portable_incremental_shake128_squeeze_next_block(
 7965|     80|            &st->shake128_state[i0],
 7966|     80|            Eurydice_array_to_slice((size_t)168U, out[i0], uint8_t)););
 7967|     80|    memcpy(ret, out, (size_t)3U * sizeof(uint8_t[168U]));
 7968|     80|}
libcrux_mlkem_portable.c:sample_from_uniform_distribution_next_170:
 8039|     80|{
 8040|     80|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     80|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     80|    do {                               \
  |  |  |  |  289|     80|        uint32_t i = z;                \
  |  |  |  |  290|     80|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     80|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8041|     80|        i0, (size_t)0U, (size_t)3U, (size_t)1U, size_t i1 = i0;
 8042|     80|        for (size_t i = (size_t)0U; i < (size_t)168U / (size_t)24U; i++) {
 8043|     80|            size_t r = i;
 8044|     80|            if (sampled_coefficients[i1] <
 8045|     80|                LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT) {
 8046|     80|                Eurydice_slice uu____0 = Eurydice_array_to_subslice2(
 8047|     80|                    randomness[i1], r * (size_t)24U, r * (size_t)24U + (size_t)24U,
 8048|     80|                    uint8_t);
 8049|     80|                size_t sampled = libcrux_ml_kem_vector_portable_rej_sample_0d(
 8050|     80|                    uu____0, Eurydice_array_to_subslice2(
 8051|     80|                                 out[i1], sampled_coefficients[i1],
 8052|     80|                                 sampled_coefficients[i1] + (size_t)16U, int16_t));
 8053|     80|                size_t uu____1 = i1;
 8054|     80|                sampled_coefficients[uu____1] =
 8055|     80|                    sampled_coefficients[uu____1] + sampled;
 8056|     80|            }
 8057|     80|        });
 8058|     80|    bool done = true;
 8059|     80|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     80|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     80|    do {                               \
  |  |  |  |  289|     80|        uint32_t i = z;                \
  |  |  |  |  290|     80|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     80|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8060|     80|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 8061|     80|        if (sampled_coefficients[i0] >=
 8062|     80|            LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT) {
 8063|     80|            sampled_coefficients[i0] =
 8064|     80|                LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT;
 8065|     80|        } else { done = false; });
 8066|     80|    return done;
 8067|     80|}
libcrux_mlkem_portable.c:closure_e4:
 8079|    747|{
 8080|    747|    return from_i16_array_89_33(
 8081|    747|        Eurydice_array_to_subslice2(s, (size_t)0U, (size_t)256U, int16_t));
  ------------------
  |  |   75|    747|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|    747|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    747|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8082|    747|}
libcrux_mlkem_portable.c:sample_vector_cbd_then_ntt_78:
 8249|     83|{
 8250|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 re_as_ntt[3U];
 8251|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8252|     83|                    re_as_ntt[i] = ZERO_89_c3(););
 8253|       |    /* Passing arrays by value in Rust generates a copy in C */
 8254|     83|    uint8_t copy_of_prf_input[33U];
 8255|     83|    memcpy(copy_of_prf_input, prf_input, (size_t)33U * sizeof(uint8_t));
 8256|     83|    uint8_t prf_inputs[3U][33U];
 8257|     83|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8258|     83|        i, (size_t)0U, (size_t)3U, (size_t)1U,
 8259|     83|        memcpy(prf_inputs[i], copy_of_prf_input, (size_t)33U * sizeof(uint8_t)););
 8260|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8261|     83|                    prf_inputs[i0][32U] = domain_separator;
 8262|     83|                    domain_separator = (uint32_t)domain_separator + 1U;);
 8263|     83|    uint8_t prf_outputs[3U][128U];
 8264|     83|    PRFxN_f1_d5(prf_inputs, prf_outputs);
 8265|     83|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8266|     83|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 8267|     83|        re_as_ntt[i0] = sample_from_binomial_distribution_ca(
 8268|     83|            Eurydice_array_to_slice((size_t)128U, prf_outputs[i0], uint8_t));
 8269|     83|        ntt_binomially_sampled_ring_element_63(&re_as_ntt[i0]););
 8270|       |    /* Passing arrays by value in Rust generates a copy in C */
 8271|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 copy_of_re_as_ntt[3U];
 8272|     83|    memcpy(
 8273|     83|        copy_of_re_as_ntt, re_as_ntt,
 8274|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8275|     83|    tuple_b0 lit;
 8276|     83|    memcpy(
 8277|     83|        lit.fst, copy_of_re_as_ntt,
 8278|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8279|     83|    lit.snd = domain_separator;
 8280|     83|    return lit;
 8281|     83|}
libcrux_mlkem_portable.c:PRFxN_f1_d5:
 8229|    166|{
 8230|    166|    PRFxN_1c(input, ret);
 8231|    166|}
libcrux_mlkem_portable.c:PRFxN_1c:
 8206|    166|{
 8207|    166|    uint8_t out[3U][128U] = { { 0U } };
 8208|    166|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|    166|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|    166|    do {                               \
  |  |  |  |  289|    166|        uint32_t i = z;                \
  |  |  |  |  290|    166|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|    166|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8209|    166|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 8210|    166|        libcrux_sha3_portable_shake256(
 8211|    166|            Eurydice_array_to_slice((size_t)128U, out[i0], uint8_t),
 8212|    166|            Eurydice_array_to_slice((size_t)33U, input[i0], uint8_t)););
 8213|    166|    memcpy(ret, out, (size_t)3U * sizeof(uint8_t[128U]));
 8214|    166|}
libcrux_mlkem_portable.c:add_to_ring_element_89_1e:
 8301|    996|{
 8302|    996|    for (size_t i = (size_t)0U;
 8303|  16.9k|         i < Eurydice_slice_len(
  ------------------
  |  |   82|  16.9k|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|  16.9k|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (8303:10): [True: 15.9k, False: 996]
  ------------------
 8304|    996|                 Eurydice_array_to_slice(
 8305|    996|                     (size_t)16U, self->coefficients,
 8306|    996|                     libcrux_ml_kem_vector_portable_vector_type_PortableVector),
 8307|    996|                 libcrux_ml_kem_vector_portable_vector_type_PortableVector);
 8308|  15.9k|         i++) {
 8309|  15.9k|        size_t i0 = i;
 8310|  15.9k|        libcrux_ml_kem_vector_portable_vector_type_PortableVector uu____0 =
 8311|  15.9k|            libcrux_ml_kem_vector_portable_add_0d(self->coefficients[i0],
 8312|  15.9k|                                                  &rhs->coefficients[i0]);
 8313|  15.9k|        self->coefficients[i0] = uu____0;
 8314|  15.9k|    }
 8315|    996|}
libcrux_mlkem_portable.c:entropy_preprocess_d8_9f:
 8564|     83|{
 8565|     83|    uint8_t out[32U] = { 0U };
 8566|     83|    Eurydice_slice_copy(Eurydice_array_to_slice((size_t)32U, out, uint8_t),
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 8567|     83|                        randomness, uint8_t);
 8568|     83|    memcpy(ret, out, (size_t)32U * sizeof(uint8_t));
 8569|     83|}
libcrux_mlkem_portable.c:G_f1_38:
 7732|     83|{
 7733|     83|    libcrux_ml_kem_hash_functions_portable_G(input, ret);
 7734|     83|}
libcrux_mlkem_portable.c:encrypt_7b:
 8831|     83|{
 8832|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 t_as_ntt[3U];
 8833|     83|    deserialize_ring_elements_reduced_4f(
 8834|     83|        Eurydice_slice_subslice_to(public_key, (size_t)1152U, uint8_t, size_t),
  ------------------
  |  |   65|     83|    EURYDICE_SLICE((t *)s.ptr, 0, subslice_end_pos)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8835|     83|        t_as_ntt);
 8836|     83|    Eurydice_slice seed =
 8837|     83|        Eurydice_slice_subslice_from(public_key, (size_t)1152U, uint8_t, size_t);
  ------------------
  |  |   67|     83|    EURYDICE_SLICE((t *)s.ptr, subslice_start_pos, s.len)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8838|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 A[3U][3U];
 8839|     83|    uint8_t ret0[34U];
 8840|     83|    libcrux_ml_kem_utils_into_padded_array_6d1(seed, ret0);
 8841|     83|    sample_matrix_A_e7(ret0, false, A);
 8842|     83|    uint8_t prf_input[33U];
 8843|     83|    libcrux_ml_kem_utils_into_padded_array_6d2(randomness, prf_input);
 8844|       |    /* Passing arrays by value in Rust generates a copy in C */
 8845|     83|    uint8_t copy_of_prf_input0[33U];
 8846|     83|    memcpy(copy_of_prf_input0, prf_input, (size_t)33U * sizeof(uint8_t));
 8847|     83|    tuple_b0 uu____1 = sample_vector_cbd_then_ntt_78(copy_of_prf_input0, 0U);
 8848|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 r_as_ntt[3U];
 8849|     83|    memcpy(
 8850|     83|        r_as_ntt, uu____1.fst,
 8851|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8852|     83|    uint8_t domain_separator0 = uu____1.snd;
 8853|       |    /* Passing arrays by value in Rust generates a copy in C */
 8854|     83|    uint8_t copy_of_prf_input[33U];
 8855|     83|    memcpy(copy_of_prf_input, prf_input, (size_t)33U * sizeof(uint8_t));
 8856|     83|    tuple_b0 uu____3 =
 8857|     83|        sample_ring_element_cbd_a8(copy_of_prf_input, domain_separator0);
 8858|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 error_1[3U];
 8859|     83|    memcpy(
 8860|     83|        error_1, uu____3.fst,
 8861|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8862|     83|    uint8_t domain_separator = uu____3.snd;
 8863|     83|    prf_input[32U] = domain_separator;
 8864|     83|    uint8_t prf_output[128U];
 8865|     83|    PRF_f1_2e0(Eurydice_array_to_slice((size_t)33U, prf_input, uint8_t),
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8866|     83|               prf_output);
 8867|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 error_2 =
 8868|     83|        sample_from_binomial_distribution_ca(
 8869|     83|            Eurydice_array_to_slice((size_t)128U, prf_output, uint8_t));
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 8870|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 u[3U];
 8871|     83|    compute_vector_u_93(A, r_as_ntt, error_1, u);
 8872|       |    /* Passing arrays by value in Rust generates a copy in C */
 8873|     83|    uint8_t copy_of_message[32U];
 8874|     83|    memcpy(copy_of_message, message, (size_t)32U * sizeof(uint8_t));
 8875|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 message_as_ring_element =
 8876|     83|        deserialize_then_decompress_message_f7(copy_of_message);
 8877|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 v =
 8878|     83|        compute_ring_element_v_54(t_as_ntt, r_as_ntt, &error_2,
 8879|     83|                                  &message_as_ring_element);
 8880|     83|    uint8_t ciphertext[1088U] = { 0U };
 8881|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 uu____5[3U];
 8882|     83|    memcpy(
 8883|     83|        uu____5, u,
 8884|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8885|     83|    compress_then_serialize_u_28(
 8886|     83|        uu____5, Eurydice_array_to_subslice2(ciphertext, (size_t)0U, (size_t)960U,
  ------------------
  |  |   75|     83|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8887|     83|                                             uint8_t));
 8888|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 uu____6 = v;
 8889|     83|    compress_then_serialize_ring_element_v_65(
 8890|     83|        uu____6, Eurydice_array_to_subslice_from((size_t)1088U, ciphertext,
  ------------------
  |  |   79|     83|    EURYDICE_SLICE((t *)x, r, size)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8891|     83|                                                 (size_t)960U, uint8_t, size_t));
 8892|     83|    memcpy(ret, ciphertext, (size_t)1088U * sizeof(uint8_t));
 8893|     83|}
libcrux_mlkem_portable.c:deserialize_ring_elements_reduced_4f:
 8588|     83|{
 8589|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 deserialized_pk[3U];
 8590|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8591|     83|                    deserialized_pk[i] = ZERO_89_c3(););
 8592|     83|    for (size_t i = (size_t)0U;
 8593|    332|         i < Eurydice_slice_len(public_key, uint8_t) /
  ------------------
  |  |   82|    332|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    332|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (8593:10): [True: 249, False: 83]
  ------------------
 8594|    332|                 LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT;
  ------------------
  |  |   42|    332|    (LIBCRUX_ML_KEM_CONSTANTS_BITS_PER_RING_ELEMENT / (size_t)8U)
  |  |  ------------------
  |  |  |  |   39|    332|    (LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT * (size_t)12U)
  |  |  |  |  ------------------
  |  |  |  |  |  |   36|    332|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8595|    249|         i++) {
 8596|    249|        size_t i0 = i;
 8597|    249|        Eurydice_slice ring_element = Eurydice_slice_subslice2(
  ------------------
  |  |   63|    249|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|    249|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    249|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8598|    249|            public_key, i0 * LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT,
 8599|    249|            i0 * LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT +
 8600|    249|                LIBCRUX_ML_KEM_CONSTANTS_BYTES_PER_RING_ELEMENT,
 8601|    249|            uint8_t);
 8602|    249|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 uu____0 =
 8603|    249|            deserialize_to_reduced_ring_element_45(ring_element);
 8604|    249|        deserialized_pk[i0] = uu____0;
 8605|    249|    }
 8606|     83|    memcpy(
 8607|     83|        ret, deserialized_pk,
 8608|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8609|     83|}
libcrux_mlkem_portable.c:sample_ring_element_cbd_a8:
 8625|     83|{
 8626|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 error_1[3U];
 8627|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8628|     83|                    error_1[i] = ZERO_89_c3(););
 8629|       |    /* Passing arrays by value in Rust generates a copy in C */
 8630|     83|    uint8_t copy_of_prf_input[33U];
 8631|     83|    memcpy(copy_of_prf_input, prf_input, (size_t)33U * sizeof(uint8_t));
 8632|     83|    uint8_t prf_inputs[3U][33U];
 8633|     83|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8634|     83|        i, (size_t)0U, (size_t)3U, (size_t)1U,
 8635|     83|        memcpy(prf_inputs[i], copy_of_prf_input, (size_t)33U * sizeof(uint8_t)););
 8636|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8637|     83|                    prf_inputs[i0][32U] = domain_separator;
 8638|     83|                    domain_separator = (uint32_t)domain_separator + 1U;);
 8639|     83|    uint8_t prf_outputs[3U][128U];
 8640|     83|    PRFxN_f1_d5(prf_inputs, prf_outputs);
 8641|     83|    KRML_MAYBE_FOR3(
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8642|     83|        i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
 8643|     83|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 uu____1 =
 8644|     83|            sample_from_binomial_distribution_ca(
 8645|     83|                Eurydice_array_to_slice((size_t)128U, prf_outputs[i0], uint8_t));
 8646|     83|        error_1[i0] = uu____1;);
 8647|       |    /* Passing arrays by value in Rust generates a copy in C */
 8648|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 copy_of_error_1[3U];
 8649|     83|    memcpy(
 8650|     83|        copy_of_error_1, error_1,
 8651|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8652|     83|    tuple_b0 lit;
 8653|     83|    memcpy(
 8654|     83|        lit.fst, copy_of_error_1,
 8655|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8656|     83|    lit.snd = domain_separator;
 8657|     83|    return lit;
 8658|     83|}
libcrux_mlkem_portable.c:PRF_f1_2e0:
 8673|     83|{
 8674|     83|    PRF_7c0(input, ret);
 8675|     83|}
libcrux_mlkem_portable.c:compute_vector_u_93:
 8714|     83|{
 8715|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 result[3U];
 8716|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U,
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8717|     83|                    result[i] = ZERO_89_c3(););
 8718|     83|    for (size_t i0 = (size_t)0U;
 8719|    332|         i0 < Eurydice_slice_len(
  ------------------
  |  |   82|    332|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    332|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (8719:10): [True: 249, False: 83]
  ------------------
 8720|     83|                  Eurydice_array_to_slice(
 8721|     83|                      (size_t)3U, a_as_ntt,
 8722|     83|                      libcrux_ml_kem_polynomial_PolynomialRingElement_f0[3U]),
 8723|     83|                  libcrux_ml_kem_polynomial_PolynomialRingElement_f0[3U]);
 8724|    249|         i0++) {
 8725|    249|        size_t i1 = i0;
 8726|    249|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 *row = a_as_ntt[i1];
 8727|    249|        for (size_t i = (size_t)0U;
 8728|    996|             i < Eurydice_slice_len(
  ------------------
  |  |   82|    996|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    996|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (8728:14): [True: 747, False: 249]
  ------------------
 8729|    249|                     Eurydice_array_to_slice(
 8730|    249|                         (size_t)3U, row,
 8731|    249|                         libcrux_ml_kem_polynomial_PolynomialRingElement_f0),
 8732|    249|                     libcrux_ml_kem_polynomial_PolynomialRingElement_f0);
 8733|    747|             i++) {
 8734|    747|            size_t j = i;
 8735|    747|            libcrux_ml_kem_polynomial_PolynomialRingElement_f0 *a_element = &row[j];
 8736|    747|            libcrux_ml_kem_polynomial_PolynomialRingElement_f0 product =
 8737|    747|                ntt_multiply_89_3b(a_element, &r_as_ntt[j]);
 8738|    747|            add_to_ring_element_89_1e(&result[i1], &product);
 8739|    747|        }
 8740|    249|        invert_ntt_montgomery_c9(&result[i1]);
 8741|    249|        add_error_reduce_89_5d(&result[i1], &error_1[i1]);
 8742|    249|    }
 8743|     83|    memcpy(
 8744|     83|        ret, result,
 8745|     83|        (size_t)3U * sizeof(libcrux_ml_kem_polynomial_PolynomialRingElement_f0));
 8746|     83|}
libcrux_mlkem_portable.c:invert_ntt_montgomery_c9:
 8686|    332|{
 8687|    332|    size_t zeta_i =
 8688|    332|        LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT / (size_t)2U;
  ------------------
  |  |   36|    332|#define LIBCRUX_ML_KEM_CONSTANTS_COEFFICIENTS_IN_RING_ELEMENT ((size_t)256U)
  ------------------
 8689|    332|    invert_ntt_at_layer_1_4b(&zeta_i, re);
 8690|    332|    invert_ntt_at_layer_2_2b(&zeta_i, re);
 8691|    332|    invert_ntt_at_layer_3_97(&zeta_i, re);
 8692|    332|    invert_ntt_at_layer_4_plus_04(&zeta_i, re, (size_t)4U);
 8693|    332|    invert_ntt_at_layer_4_plus_04(&zeta_i, re, (size_t)5U);
 8694|    332|    invert_ntt_at_layer_4_plus_04(&zeta_i, re, (size_t)6U);
 8695|    332|    invert_ntt_at_layer_4_plus_04(&zeta_i, re, (size_t)7U);
 8696|    332|    poly_barrett_reduce_89_d8(re);
 8697|    332|}
libcrux_mlkem_portable.c:compute_ring_element_v_54:
 8763|     83|{
 8764|     83|    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 result = ZERO_89_c3();
 8765|     83|    KRML_MAYBE_FOR3(i, (size_t)0U, (size_t)3U, (size_t)1U, size_t i0 = i;
  ------------------
  |  |  324|     83|#define KRML_MAYBE_FOR3(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 3, k, x)
  |  |  ------------------
  |  |  |  |  288|     83|    do {                               \
  |  |  |  |  289|     83|        uint32_t i = z;                \
  |  |  |  |  290|     83|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|     83|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8766|     83|                    libcrux_ml_kem_polynomial_PolynomialRingElement_f0 product =
 8767|     83|                        ntt_multiply_89_3b(&t_as_ntt[i0], &r_as_ntt[i0]);
 8768|     83|                    add_to_ring_element_89_1e(&result, &product););
 8769|     83|    invert_ntt_montgomery_c9(&result);
 8770|     83|    result = add_message_error_reduce_89_c4(error_2, message, result);
 8771|     83|    return result;
 8772|     83|}
libcrux_mlkem_portable.c:compress_then_serialize_u_28:
 8790|     83|{
 8791|     83|    for (size_t i = (size_t)0U;
 8792|    332|         i < Eurydice_slice_len(
  ------------------
  |  |   82|    332|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    332|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (8792:10): [True: 249, False: 83]
  ------------------
 8793|     83|                 Eurydice_array_to_slice(
 8794|     83|                     (size_t)3U, input,
 8795|     83|                     libcrux_ml_kem_polynomial_PolynomialRingElement_f0),
 8796|     83|                 libcrux_ml_kem_polynomial_PolynomialRingElement_f0);
 8797|    249|         i++) {
 8798|    249|        size_t i0 = i;
 8799|    249|        libcrux_ml_kem_polynomial_PolynomialRingElement_f0 re = input[i0];
 8800|    249|        Eurydice_slice uu____0 = Eurydice_slice_subslice2(
  ------------------
  |  |   63|    249|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|    249|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    249|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8801|    249|            out, i0 * ((size_t)960U / (size_t)3U),
 8802|    249|            (i0 + (size_t)1U) * ((size_t)960U / (size_t)3U), uint8_t);
 8803|    249|        uint8_t ret[320U];
 8804|    249|        compress_then_serialize_ring_element_u_2e(&re, ret);
 8805|    249|        Eurydice_slice_copy(
  ------------------
  |  |   84|    249|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 8806|    249|            uu____0, Eurydice_array_to_slice((size_t)320U, ret, uint8_t), uint8_t);
 8807|    249|    }
 8808|     83|}
libcrux_mlkem_portable.c:kdf_d8_c5:
 8909|     83|{
 8910|     83|    uint8_t out[32U] = { 0U };
 8911|     83|    Eurydice_slice_copy(Eurydice_array_to_slice((size_t)32U, out, uint8_t),
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 8912|     83|                        shared_secret, uint8_t);
 8913|     83|    memcpy(ret, out, (size_t)32U * sizeof(uint8_t));
 8914|     83|}

libcrux_mlkem_portable.c:libcrux_sha3_portable_sha512:
   31|     83|{
   32|     83|    Eurydice_slice buf0[1U] = { data };
   33|     83|    Eurydice_slice buf[1U] = { digest };
   34|     83|    libcrux_sha3_portable_keccakx1_e4(buf0, buf);
   35|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_sha256:
   43|     83|{
   44|     83|    Eurydice_slice buf0[1U] = { data };
   45|     83|    Eurydice_slice buf[1U] = { digest };
   46|     83|    libcrux_sha3_portable_keccakx1_e40(buf0, buf);
   47|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_shake256:
   55|    581|{
   56|    581|    Eurydice_slice buf0[1U] = { data };
   57|    581|    Eurydice_slice buf[1U] = { digest };
   58|    581|    libcrux_sha3_portable_keccakx1_e41(buf0, buf);
   59|    581|}

libcrux_mlkem_portable.c:libcrux_sha3_portable_keccakx1_e4:
 3437|     83|{
 3438|       |    /* Passing arrays by value in Rust generates a copy in C */
 3439|     83|    Eurydice_slice copy_of_data[1U];
 3440|     83|    memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 3441|     83|    libcrux_sha3_generic_keccak_keccak_06(copy_of_data, out);
 3442|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_keccak_06:
 3364|     83|{
 3365|     83|    libcrux_sha3_generic_keccak_KeccakState_48 s =
 3366|     83|        libcrux_sha3_generic_keccak_new_1e_cf();
 3367|     83|    for (size_t i = (size_t)0U;
 3368|     83|         i < Eurydice_slice_len(data[0U], uint8_t) / (size_t)72U; i++) {
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (3368:10): [True: 0, False: 83]
  ------------------
 3369|      0|        size_t i0 = i;
 3370|      0|        libcrux_sha3_generic_keccak_KeccakState_48 *uu____0 = &s;
 3371|       |        /* Passing arrays by value in Rust generates a copy in C */
 3372|      0|        Eurydice_slice copy_of_data[1U];
 3373|      0|        memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 3374|      0|        Eurydice_slice ret[1U];
 3375|      0|        libcrux_sha3_portable_keccak_slice_n_5a(copy_of_data, i0 * (size_t)72U,
 3376|      0|                                                (size_t)72U, ret);
 3377|      0|        libcrux_sha3_generic_keccak_absorb_block_40(uu____0, ret);
 3378|      0|    }
 3379|     83|    size_t rem = Eurydice_slice_len(data[0U], uint8_t) % (size_t)72U;
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3380|     83|    libcrux_sha3_generic_keccak_KeccakState_48 *uu____2 = &s;
 3381|       |    /* Passing arrays by value in Rust generates a copy in C */
 3382|     83|    Eurydice_slice copy_of_data[1U];
 3383|     83|    memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 3384|     83|    Eurydice_slice ret[1U];
 3385|     83|    libcrux_sha3_portable_keccak_slice_n_5a(
 3386|     83|        copy_of_data, Eurydice_slice_len(data[0U], uint8_t) - rem, rem, ret);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3387|     83|    libcrux_sha3_generic_keccak_absorb_final_401(uu____2, ret);
 3388|     83|    size_t outlen = Eurydice_slice_len(out[0U], uint8_t);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3389|     83|    size_t blocks = outlen / (size_t)72U;
 3390|     83|    size_t last = outlen - outlen % (size_t)72U;
 3391|     83|    if (blocks == (size_t)0U) {
  ------------------
  |  Branch (3391:9): [True: 83, False: 0]
  ------------------
 3392|     83|        libcrux_sha3_generic_keccak_squeeze_first_and_last_88(&s, out);
 3393|     83|    } else {
 3394|      0|        Eurydice_slice_uint8_t_1size_t__x2 uu____4 =
 3395|      0|            libcrux_sha3_portable_keccak_split_at_mut_n_5a(out, (size_t)72U);
 3396|      0|        Eurydice_slice o0[1U];
 3397|      0|        memcpy(o0, uu____4.fst, (size_t)1U * sizeof(Eurydice_slice));
 3398|      0|        Eurydice_slice o1[1U];
 3399|      0|        memcpy(o1, uu____4.snd, (size_t)1U * sizeof(Eurydice_slice));
 3400|      0|        libcrux_sha3_generic_keccak_squeeze_first_block_7b1(&s, o0);
 3401|      0|        core_ops_range_Range_b3 iter =
 3402|      0|            core_iter_traits_collect___core__iter__traits__collect__IntoIterator_for_I__1__into_iter(
  ------------------
  |  |  246|      0|    Eurydice_into_iter
  |  |  ------------------
  |  |  |  |  241|      0|#define Eurydice_into_iter(x, t, _ret_t) (x)
  |  |  ------------------
  ------------------
 3403|      0|                (CLITERAL(core_ops_range_Range_b3){ .start = (size_t)1U,
 3404|      0|                                                    .end = blocks }),
 3405|      0|                core_ops_range_Range_b3, core_ops_range_Range_b3);
 3406|      0|        while (true) {
 3407|      0|            if (core_iter_range___core__iter__traits__iterator__Iterator_for_core__ops__range__Range_A___6__next(
  ------------------
  |  |  238|      0|    Eurydice_range_iter_next
  |  |  ------------------
  |  |  |  |  228|      0|    (((iter_ptr)->start == (iter_ptr)->end)             \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (228:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |  229|      0|         ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   38|      0|#define core_option_None 0
  |  |  |  |  ------------------
  |  |  |  |  230|      0|         : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      0|#define core_option_Some 1
  |  |  |  |  ------------------
  |  |  |  |  231|      0|                             .f0 = (iter_ptr)->start++ }))
  |  |  ------------------
  ------------------
  |  Branch (3407:17): [True: 0, False: 0]
  ------------------
 3408|      0|                    &iter, size_t, core_option_Option_b3)
 3409|      0|                    .tag == core_option_None) {
  ------------------
  |  |   38|      0|#define core_option_None 0
  ------------------
 3410|      0|                break;
 3411|      0|            } else {
 3412|      0|                Eurydice_slice_uint8_t_1size_t__x2 uu____5 =
 3413|      0|                    libcrux_sha3_portable_keccak_split_at_mut_n_5a(o1, (size_t)72U);
 3414|      0|                Eurydice_slice o[1U];
 3415|      0|                memcpy(o, uu____5.fst, (size_t)1U * sizeof(Eurydice_slice));
 3416|      0|                Eurydice_slice orest[1U];
 3417|      0|                memcpy(orest, uu____5.snd, (size_t)1U * sizeof(Eurydice_slice));
 3418|      0|                libcrux_sha3_generic_keccak_squeeze_next_block_c21(&s, o);
 3419|      0|                memcpy(o1, orest, (size_t)1U * sizeof(Eurydice_slice));
 3420|      0|            }
 3421|      0|        }
 3422|      0|        if (last < outlen) {
  ------------------
  |  Branch (3422:13): [True: 0, False: 0]
  ------------------
 3423|      0|            libcrux_sha3_generic_keccak_squeeze_last_ca(s, o1);
 3424|      0|        }
 3425|      0|    }
 3426|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_new_1e_cf:
  227|  1.49k|{
  228|  1.49k|    libcrux_sha3_generic_keccak_KeccakState_48 lit;
  229|  1.49k|    lit.st[0U][0U] = libcrux_sha3_portable_keccak_zero_5a();
  230|  1.49k|    lit.st[0U][1U] = libcrux_sha3_portable_keccak_zero_5a();
  231|  1.49k|    lit.st[0U][2U] = libcrux_sha3_portable_keccak_zero_5a();
  232|  1.49k|    lit.st[0U][3U] = libcrux_sha3_portable_keccak_zero_5a();
  233|  1.49k|    lit.st[0U][4U] = libcrux_sha3_portable_keccak_zero_5a();
  234|  1.49k|    lit.st[1U][0U] = libcrux_sha3_portable_keccak_zero_5a();
  235|  1.49k|    lit.st[1U][1U] = libcrux_sha3_portable_keccak_zero_5a();
  236|  1.49k|    lit.st[1U][2U] = libcrux_sha3_portable_keccak_zero_5a();
  237|  1.49k|    lit.st[1U][3U] = libcrux_sha3_portable_keccak_zero_5a();
  238|  1.49k|    lit.st[1U][4U] = libcrux_sha3_portable_keccak_zero_5a();
  239|  1.49k|    lit.st[2U][0U] = libcrux_sha3_portable_keccak_zero_5a();
  240|  1.49k|    lit.st[2U][1U] = libcrux_sha3_portable_keccak_zero_5a();
  241|  1.49k|    lit.st[2U][2U] = libcrux_sha3_portable_keccak_zero_5a();
  242|  1.49k|    lit.st[2U][3U] = libcrux_sha3_portable_keccak_zero_5a();
  243|  1.49k|    lit.st[2U][4U] = libcrux_sha3_portable_keccak_zero_5a();
  244|  1.49k|    lit.st[3U][0U] = libcrux_sha3_portable_keccak_zero_5a();
  245|  1.49k|    lit.st[3U][1U] = libcrux_sha3_portable_keccak_zero_5a();
  246|  1.49k|    lit.st[3U][2U] = libcrux_sha3_portable_keccak_zero_5a();
  247|  1.49k|    lit.st[3U][3U] = libcrux_sha3_portable_keccak_zero_5a();
  248|  1.49k|    lit.st[3U][4U] = libcrux_sha3_portable_keccak_zero_5a();
  249|  1.49k|    lit.st[4U][0U] = libcrux_sha3_portable_keccak_zero_5a();
  250|  1.49k|    lit.st[4U][1U] = libcrux_sha3_portable_keccak_zero_5a();
  251|  1.49k|    lit.st[4U][2U] = libcrux_sha3_portable_keccak_zero_5a();
  252|  1.49k|    lit.st[4U][3U] = libcrux_sha3_portable_keccak_zero_5a();
  253|  1.49k|    lit.st[4U][4U] = libcrux_sha3_portable_keccak_zero_5a();
  254|  1.49k|    return lit;
  255|  1.49k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_zero_5a:
   57|  37.3k|{
   58|  37.3k|    return 0ULL;
   59|  37.3k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_slice_n_5a:
  168|  1.41k|{
  169|       |    /* Passing arrays by value in Rust generates a copy in C */
  170|  1.41k|    Eurydice_slice copy_of_a[1U];
  171|  1.41k|    memcpy(copy_of_a, a, (size_t)1U * sizeof(Eurydice_slice));
  172|  1.41k|    Eurydice_slice ret0[1U];
  173|  1.41k|    libcrux_sha3_portable_keccak_slice_1(copy_of_a, start, len, ret0);
  174|  1.41k|    memcpy(ret, ret0, (size_t)1U * sizeof(Eurydice_slice));
  175|  1.41k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_slice_1:
  157|  1.41k|{
  158|  1.41k|    ret[0U] = Eurydice_slice_subslice2(a[0U], start, start + len, uint8_t);
  ------------------
  |  |   63|  1.41k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  1.41k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  1.41k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  159|  1.41k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_651:
 3071|     83|{
 3072|    830|    for (size_t i = (size_t)0U; i < (size_t)72U / (size_t)8U; i++) {
  ------------------
  |  Branch (3072:33): [True: 747, False: 83]
  ------------------
 3073|    747|        size_t i0 = i;
 3074|    747|        uint8_t uu____0[8U];
 3075|    747|        core_result_Result_56 dst;
 3076|    747|        Eurydice_slice_to_array2(
  ------------------
  |  |  116|    747|    Eurydice_slice_to_array3(&(dst)->tag, (char *)&(dst)->val.case_Ok, src, \
  |  |  117|    747|                             sizeof(t_arr))
  ------------------
 3077|    747|            &dst,
 3078|    747|            Eurydice_slice_subslice2(blocks[0U], (size_t)8U * i0,
 3079|    747|                                     (size_t)8U * i0 + (size_t)8U, uint8_t),
 3080|    747|            Eurydice_slice, uint8_t[8U]);
 3081|    747|        core_result_unwrap_41_0e(dst, uu____0);
 3082|    747|        size_t uu____1 = i0 / (size_t)5U;
 3083|    747|        size_t uu____2 = i0 % (size_t)5U;
 3084|    747|        s[uu____1][uu____2] =
 3085|    747|            s[uu____1][uu____2] ^ core_num__u64_9__from_le_bytes(uu____0);
 3086|    747|    }
 3087|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_keccakf1600_b8:
 1466|  3.89k|{
 1467|  97.3k|    for (size_t i = (size_t)0U; i < (size_t)24U; i++) {
  ------------------
  |  Branch (1467:33): [True: 93.4k, False: 3.89k]
  ------------------
 1468|  93.4k|        size_t i0 = i;
 1469|  93.4k|        libcrux_sha3_generic_keccak_theta_rho_a7(s);
 1470|  93.4k|        libcrux_sha3_generic_keccak_pi_d5(s);
 1471|  93.4k|        libcrux_sha3_generic_keccak_chi_3e(s);
 1472|  93.4k|        libcrux_sha3_generic_keccak_iota_00(s, i0);
 1473|  93.4k|    }
 1474|  3.89k|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_theta_rho_a7:
 1299|  93.4k|{
 1300|  93.4k|    uint64_t c[5U] = {
 1301|  93.4k|        libcrux_sha3_portable_keccak_xor5_5a(s->st[0U][0U], s->st[1U][0U],
 1302|  93.4k|                                             s->st[2U][0U], s->st[3U][0U],
 1303|  93.4k|                                             s->st[4U][0U]),
 1304|  93.4k|        libcrux_sha3_portable_keccak_xor5_5a(s->st[0U][1U], s->st[1U][1U],
 1305|  93.4k|                                             s->st[2U][1U], s->st[3U][1U],
 1306|  93.4k|                                             s->st[4U][1U]),
 1307|  93.4k|        libcrux_sha3_portable_keccak_xor5_5a(s->st[0U][2U], s->st[1U][2U],
 1308|  93.4k|                                             s->st[2U][2U], s->st[3U][2U],
 1309|  93.4k|                                             s->st[4U][2U]),
 1310|  93.4k|        libcrux_sha3_portable_keccak_xor5_5a(s->st[0U][3U], s->st[1U][3U],
 1311|  93.4k|                                             s->st[2U][3U], s->st[3U][3U],
 1312|  93.4k|                                             s->st[4U][3U]),
 1313|  93.4k|        libcrux_sha3_portable_keccak_xor5_5a(s->st[0U][4U], s->st[1U][4U],
 1314|  93.4k|                                             s->st[2U][4U], s->st[3U][4U],
 1315|  93.4k|                                             s->st[4U][4U])
 1316|  93.4k|    };
 1317|  93.4k|    uint64_t uu____0 = libcrux_sha3_portable_keccak_rotate_left1_and_xor_5a(
 1318|  93.4k|        c[((size_t)0U + (size_t)4U) % (size_t)5U],
 1319|  93.4k|        c[((size_t)0U + (size_t)1U) % (size_t)5U]);
 1320|  93.4k|    uint64_t uu____1 = libcrux_sha3_portable_keccak_rotate_left1_and_xor_5a(
 1321|  93.4k|        c[((size_t)1U + (size_t)4U) % (size_t)5U],
 1322|  93.4k|        c[((size_t)1U + (size_t)1U) % (size_t)5U]);
 1323|  93.4k|    uint64_t uu____2 = libcrux_sha3_portable_keccak_rotate_left1_and_xor_5a(
 1324|  93.4k|        c[((size_t)2U + (size_t)4U) % (size_t)5U],
 1325|  93.4k|        c[((size_t)2U + (size_t)1U) % (size_t)5U]);
 1326|  93.4k|    uint64_t uu____3 = libcrux_sha3_portable_keccak_rotate_left1_and_xor_5a(
 1327|  93.4k|        c[((size_t)3U + (size_t)4U) % (size_t)5U],
 1328|  93.4k|        c[((size_t)3U + (size_t)1U) % (size_t)5U]);
 1329|  93.4k|    uint64_t t[5U] = { uu____0, uu____1, uu____2, uu____3,
 1330|  93.4k|                       libcrux_sha3_portable_keccak_rotate_left1_and_xor_5a(
 1331|  93.4k|                           c[((size_t)4U + (size_t)4U) % (size_t)5U],
 1332|  93.4k|                           c[((size_t)4U + (size_t)1U) % (size_t)5U]) };
 1333|  93.4k|    s->st[0U][0U] = libcrux_sha3_portable_keccak_xor_5a(s->st[0U][0U], t[0U]);
 1334|  93.4k|    s->st[1U][0U] =
 1335|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_03(s->st[1U][0U], t[0U]);
 1336|  93.4k|    s->st[2U][0U] =
 1337|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_030(s->st[2U][0U], t[0U]);
 1338|  93.4k|    s->st[3U][0U] =
 1339|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_031(s->st[3U][0U], t[0U]);
 1340|  93.4k|    s->st[4U][0U] =
 1341|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_032(s->st[4U][0U], t[0U]);
 1342|  93.4k|    s->st[0U][1U] =
 1343|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_033(s->st[0U][1U], t[1U]);
 1344|  93.4k|    s->st[1U][1U] =
 1345|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_034(s->st[1U][1U], t[1U]);
 1346|  93.4k|    s->st[2U][1U] =
 1347|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_035(s->st[2U][1U], t[1U]);
 1348|  93.4k|    s->st[3U][1U] =
 1349|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_036(s->st[3U][1U], t[1U]);
 1350|  93.4k|    s->st[4U][1U] =
 1351|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_037(s->st[4U][1U], t[1U]);
 1352|  93.4k|    s->st[0U][2U] =
 1353|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_038(s->st[0U][2U], t[2U]);
 1354|  93.4k|    s->st[1U][2U] =
 1355|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_039(s->st[1U][2U], t[2U]);
 1356|  93.4k|    s->st[2U][2U] =
 1357|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0310(s->st[2U][2U], t[2U]);
 1358|  93.4k|    s->st[3U][2U] =
 1359|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0311(s->st[3U][2U], t[2U]);
 1360|  93.4k|    s->st[4U][2U] =
 1361|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0312(s->st[4U][2U], t[2U]);
 1362|  93.4k|    s->st[0U][3U] =
 1363|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0313(s->st[0U][3U], t[3U]);
 1364|  93.4k|    s->st[1U][3U] =
 1365|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0314(s->st[1U][3U], t[3U]);
 1366|  93.4k|    s->st[2U][3U] =
 1367|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0315(s->st[2U][3U], t[3U]);
 1368|  93.4k|    s->st[3U][3U] =
 1369|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0316(s->st[3U][3U], t[3U]);
 1370|  93.4k|    s->st[4U][3U] =
 1371|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0317(s->st[4U][3U], t[3U]);
 1372|  93.4k|    s->st[0U][4U] =
 1373|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0318(s->st[0U][4U], t[4U]);
 1374|  93.4k|    s->st[1U][4U] =
 1375|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0319(s->st[1U][4U], t[4U]);
 1376|  93.4k|    s->st[2U][4U] =
 1377|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0320(s->st[2U][4U], t[4U]);
 1378|  93.4k|    s->st[3U][4U] =
 1379|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0321(s->st[3U][4U], t[4U]);
 1380|  93.4k|    uint64_t uu____27 =
 1381|  93.4k|        libcrux_sha3_portable_keccak_xor_and_rotate_5a_0322(s->st[4U][4U], t[4U]);
 1382|  93.4k|    s->st[4U][4U] = uu____27;
 1383|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor5_5a:
   78|   467k|{
   79|   467k|    return libcrux_sha3_portable_keccak__veor5q_u64(a, b, c, d, e);
   80|   467k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__veor5q_u64:
   64|   467k|{
   65|   467k|    uint64_t ab = a ^ b;
   66|   467k|    uint64_t cd = c ^ d;
   67|   467k|    uint64_t abcd = ab ^ cd;
   68|   467k|    return abcd ^ e;
   69|   467k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left1_and_xor_5a:
  107|   467k|{
  108|   467k|    return libcrux_sha3_portable_keccak__vrax1q_u64(a, b);
  109|   467k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vrax1q_u64:
   96|   467k|{
   97|   467k|    uint64_t uu____0 = a;
   98|   467k|    return uu____0 ^ libcrux_sha3_portable_keccak_rotate_left_d6(b);
   99|   467k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d6:
   90|   560k|{
   91|   560k|    return x << (uint32_t)(int32_t)1 | x >> (uint32_t)(int32_t)63;
   92|   560k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_5a:
  150|  93.4k|{
  151|  93.4k|    return a ^ b;
  152|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_03:
  355|  93.4k|{
  356|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_74(a, b);
  357|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_74:
  338|  93.4k|{
  339|  93.4k|    uint64_t ab = a ^ b;
  340|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d60(ab);
  341|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d60:
  326|  93.4k|{
  327|  93.4k|    return x << (uint32_t)(int32_t)36 | x >> (uint32_t)(int32_t)28;
  328|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_030:
  396|  93.4k|{
  397|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_740(a, b);
  398|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_740:
  379|  93.4k|{
  380|  93.4k|    uint64_t ab = a ^ b;
  381|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d61(ab);
  382|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d61:
  367|  93.4k|{
  368|  93.4k|    return x << (uint32_t)(int32_t)3 | x >> (uint32_t)(int32_t)61;
  369|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_031:
  437|  93.4k|{
  438|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_741(a, b);
  439|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_741:
  420|  93.4k|{
  421|  93.4k|    uint64_t ab = a ^ b;
  422|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d62(ab);
  423|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d62:
  408|  93.4k|{
  409|  93.4k|    return x << (uint32_t)(int32_t)41 | x >> (uint32_t)(int32_t)23;
  410|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_032:
  478|  93.4k|{
  479|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_742(a, b);
  480|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_742:
  461|  93.4k|{
  462|  93.4k|    uint64_t ab = a ^ b;
  463|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d63(ab);
  464|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d63:
  449|  93.4k|{
  450|  93.4k|    return x << (uint32_t)(int32_t)18 | x >> (uint32_t)(int32_t)46;
  451|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_033:
  507|  93.4k|{
  508|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_743(a, b);
  509|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_743:
  490|  93.4k|{
  491|  93.4k|    uint64_t ab = a ^ b;
  492|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d6(ab);
  493|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_034:
  548|  93.4k|{
  549|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_744(a, b);
  550|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_744:
  531|  93.4k|{
  532|  93.4k|    uint64_t ab = a ^ b;
  533|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d64(ab);
  534|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d64:
  519|  93.4k|{
  520|  93.4k|    return x << (uint32_t)(int32_t)44 | x >> (uint32_t)(int32_t)20;
  521|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_035:
  589|  93.4k|{
  590|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_745(a, b);
  591|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_745:
  572|  93.4k|{
  573|  93.4k|    uint64_t ab = a ^ b;
  574|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d65(ab);
  575|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d65:
  560|  93.4k|{
  561|  93.4k|    return x << (uint32_t)(int32_t)10 | x >> (uint32_t)(int32_t)54;
  562|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_036:
  630|  93.4k|{
  631|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_746(a, b);
  632|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_746:
  613|  93.4k|{
  614|  93.4k|    uint64_t ab = a ^ b;
  615|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d66(ab);
  616|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d66:
  601|  93.4k|{
  602|  93.4k|    return x << (uint32_t)(int32_t)45 | x >> (uint32_t)(int32_t)19;
  603|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_037:
  671|  93.4k|{
  672|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_747(a, b);
  673|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_747:
  654|  93.4k|{
  655|  93.4k|    uint64_t ab = a ^ b;
  656|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d67(ab);
  657|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d67:
  642|  93.4k|{
  643|  93.4k|    return x << (uint32_t)(int32_t)2 | x >> (uint32_t)(int32_t)62;
  644|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_038:
  712|  93.4k|{
  713|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_748(a, b);
  714|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_748:
  695|  93.4k|{
  696|  93.4k|    uint64_t ab = a ^ b;
  697|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d68(ab);
  698|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d68:
  683|  93.4k|{
  684|  93.4k|    return x << (uint32_t)(int32_t)62 | x >> (uint32_t)(int32_t)2;
  685|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_039:
  753|  93.4k|{
  754|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_749(a, b);
  755|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_749:
  736|  93.4k|{
  737|  93.4k|    uint64_t ab = a ^ b;
  738|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d69(ab);
  739|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d69:
  724|  93.4k|{
  725|  93.4k|    return x << (uint32_t)(int32_t)6 | x >> (uint32_t)(int32_t)58;
  726|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0310:
  794|  93.4k|{
  795|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7410(a, b);
  796|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7410:
  777|  93.4k|{
  778|  93.4k|    uint64_t ab = a ^ b;
  779|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d610(ab);
  780|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d610:
  765|  93.4k|{
  766|  93.4k|    return x << (uint32_t)(int32_t)43 | x >> (uint32_t)(int32_t)21;
  767|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0311:
  835|  93.4k|{
  836|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7411(a, b);
  837|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7411:
  818|  93.4k|{
  819|  93.4k|    uint64_t ab = a ^ b;
  820|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d611(ab);
  821|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d611:
  806|  93.4k|{
  807|  93.4k|    return x << (uint32_t)(int32_t)15 | x >> (uint32_t)(int32_t)49;
  808|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0312:
  876|  93.4k|{
  877|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7412(a, b);
  878|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7412:
  859|  93.4k|{
  860|  93.4k|    uint64_t ab = a ^ b;
  861|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d612(ab);
  862|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d612:
  847|  93.4k|{
  848|  93.4k|    return x << (uint32_t)(int32_t)61 | x >> (uint32_t)(int32_t)3;
  849|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0313:
  917|  93.4k|{
  918|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7413(a, b);
  919|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7413:
  900|  93.4k|{
  901|  93.4k|    uint64_t ab = a ^ b;
  902|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d613(ab);
  903|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d613:
  888|  93.4k|{
  889|  93.4k|    return x << (uint32_t)(int32_t)28 | x >> (uint32_t)(int32_t)36;
  890|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0314:
  958|  93.4k|{
  959|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7414(a, b);
  960|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7414:
  941|  93.4k|{
  942|  93.4k|    uint64_t ab = a ^ b;
  943|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d614(ab);
  944|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d614:
  929|  93.4k|{
  930|  93.4k|    return x << (uint32_t)(int32_t)55 | x >> (uint32_t)(int32_t)9;
  931|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0315:
  999|  93.4k|{
 1000|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7415(a, b);
 1001|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7415:
  982|  93.4k|{
  983|  93.4k|    uint64_t ab = a ^ b;
  984|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d615(ab);
  985|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d615:
  970|  93.4k|{
  971|  93.4k|    return x << (uint32_t)(int32_t)25 | x >> (uint32_t)(int32_t)39;
  972|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0316:
 1040|  93.4k|{
 1041|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7416(a, b);
 1042|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7416:
 1023|  93.4k|{
 1024|  93.4k|    uint64_t ab = a ^ b;
 1025|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d616(ab);
 1026|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d616:
 1011|  93.4k|{
 1012|  93.4k|    return x << (uint32_t)(int32_t)21 | x >> (uint32_t)(int32_t)43;
 1013|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0317:
 1081|  93.4k|{
 1082|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7417(a, b);
 1083|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7417:
 1064|  93.4k|{
 1065|  93.4k|    uint64_t ab = a ^ b;
 1066|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d617(ab);
 1067|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d617:
 1052|  93.4k|{
 1053|  93.4k|    return x << (uint32_t)(int32_t)56 | x >> (uint32_t)(int32_t)8;
 1054|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0318:
 1122|  93.4k|{
 1123|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7418(a, b);
 1124|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7418:
 1105|  93.4k|{
 1106|  93.4k|    uint64_t ab = a ^ b;
 1107|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d618(ab);
 1108|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d618:
 1093|  93.4k|{
 1094|  93.4k|    return x << (uint32_t)(int32_t)27 | x >> (uint32_t)(int32_t)37;
 1095|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0319:
 1163|  93.4k|{
 1164|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7419(a, b);
 1165|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7419:
 1146|  93.4k|{
 1147|  93.4k|    uint64_t ab = a ^ b;
 1148|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d619(ab);
 1149|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d619:
 1134|  93.4k|{
 1135|  93.4k|    return x << (uint32_t)(int32_t)20 | x >> (uint32_t)(int32_t)44;
 1136|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0320:
 1204|  93.4k|{
 1205|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7420(a, b);
 1206|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7420:
 1187|  93.4k|{
 1188|  93.4k|    uint64_t ab = a ^ b;
 1189|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d620(ab);
 1190|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d620:
 1175|  93.4k|{
 1176|  93.4k|    return x << (uint32_t)(int32_t)39 | x >> (uint32_t)(int32_t)25;
 1177|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0321:
 1245|  93.4k|{
 1246|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7421(a, b);
 1247|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7421:
 1228|  93.4k|{
 1229|  93.4k|    uint64_t ab = a ^ b;
 1230|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d621(ab);
 1231|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d621:
 1216|  93.4k|{
 1217|  93.4k|    return x << (uint32_t)(int32_t)8 | x >> (uint32_t)(int32_t)56;
 1218|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_and_rotate_5a_0322:
 1286|  93.4k|{
 1287|  93.4k|    return libcrux_sha3_portable_keccak__vxarq_u64_7422(a, b);
 1288|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vxarq_u64_7422:
 1269|  93.4k|{
 1270|  93.4k|    uint64_t ab = a ^ b;
 1271|  93.4k|    return libcrux_sha3_portable_keccak_rotate_left_d622(ab);
 1272|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_rotate_left_d622:
 1257|  93.4k|{
 1258|  93.4k|    return x << (uint32_t)(int32_t)14 | x >> (uint32_t)(int32_t)50;
 1259|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_pi_d5:
 1394|  93.4k|{
 1395|  93.4k|    uint64_t old[5U][5U];
 1396|  93.4k|    memcpy(old, s->st, (size_t)5U * sizeof(uint64_t[5U]));
 1397|  93.4k|    s->st[0U][1U] = old[1U][1U];
 1398|  93.4k|    s->st[0U][2U] = old[2U][2U];
 1399|  93.4k|    s->st[0U][3U] = old[3U][3U];
 1400|  93.4k|    s->st[0U][4U] = old[4U][4U];
 1401|  93.4k|    s->st[1U][0U] = old[0U][3U];
 1402|  93.4k|    s->st[1U][1U] = old[1U][4U];
 1403|  93.4k|    s->st[1U][2U] = old[2U][0U];
 1404|  93.4k|    s->st[1U][3U] = old[3U][1U];
 1405|  93.4k|    s->st[1U][4U] = old[4U][2U];
 1406|  93.4k|    s->st[2U][0U] = old[0U][1U];
 1407|  93.4k|    s->st[2U][1U] = old[1U][2U];
 1408|  93.4k|    s->st[2U][2U] = old[2U][3U];
 1409|  93.4k|    s->st[2U][3U] = old[3U][4U];
 1410|  93.4k|    s->st[2U][4U] = old[4U][0U];
 1411|  93.4k|    s->st[3U][0U] = old[0U][4U];
 1412|  93.4k|    s->st[3U][1U] = old[1U][0U];
 1413|  93.4k|    s->st[3U][2U] = old[2U][1U];
 1414|  93.4k|    s->st[3U][3U] = old[3U][2U];
 1415|  93.4k|    s->st[3U][4U] = old[4U][3U];
 1416|  93.4k|    s->st[4U][0U] = old[0U][2U];
 1417|  93.4k|    s->st[4U][1U] = old[1U][3U];
 1418|  93.4k|    s->st[4U][2U] = old[2U][4U];
 1419|  93.4k|    s->st[4U][3U] = old[3U][0U];
 1420|  93.4k|    s->st[4U][4U] = old[4U][1U];
 1421|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_chi_3e:
 1432|  93.4k|{
 1433|  93.4k|    uint64_t old[5U][5U];
 1434|  93.4k|    memcpy(old, s->st, (size_t)5U * sizeof(uint64_t[5U]));
 1435|  93.4k|    KRML_MAYBE_FOR5(
  ------------------
  |  |  336|  93.4k|#define KRML_MAYBE_FOR5(i, z, n, k, x) KRML_UNROLL_FOR(i, z, 5, k, x)
  |  |  ------------------
  |  |  |  |  288|  93.4k|    do {                               \
  |  |  |  |  289|  93.4k|        uint32_t i = z;                \
  |  |  |  |  290|  93.4k|        KRML_LOOP##n(i, k, x)          \
  |  |  |  |  291|  93.4k|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (291:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1436|  93.4k|        i0, (size_t)0U, (size_t)5U, (size_t)1U, size_t i1 = i0; KRML_MAYBE_FOR5(
 1437|  93.4k|            i, (size_t)0U, (size_t)5U, (size_t)1U, size_t j = i;
 1438|  93.4k|            s->st[i1][j] = libcrux_sha3_portable_keccak_and_not_xor_5a(
 1439|  93.4k|                s->st[i1][j], old[i1][(j + (size_t)2U) % (size_t)5U],
 1440|  93.4k|                old[i1][(j + (size_t)1U) % (size_t)5U]);););
 1441|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_and_not_xor_5a:
  124|  2.33M|{
  125|  2.33M|    return libcrux_sha3_portable_keccak__vbcaxq_u64(a, b, c);
  126|  2.33M|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__vbcaxq_u64:
  113|  2.33M|{
  114|  2.33M|    return a ^ (b & ~c);
  115|  2.33M|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_iota_00:
 1452|  93.4k|{
 1453|  93.4k|    s->st[0U][0U] = libcrux_sha3_portable_keccak_xor_constant_5a(
 1454|  93.4k|        s->st[0U][0U], libcrux_sha3_generic_keccak_ROUNDCONSTANTS[i]);
 1455|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_xor_constant_5a:
  140|  93.4k|{
  141|  93.4k|    return libcrux_sha3_portable_keccak__veorq_n_u64(a, c);
  142|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak__veorq_n_u64:
  130|  93.4k|{
  131|  93.4k|    return a ^ c;
  132|  93.4k|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_absorb_final_401:
 3173|     83|{
 3174|     83|    size_t last_len = Eurydice_slice_len(last[0U], uint8_t);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3175|     83|    uint8_t blocks[1U][200U] = { { 0U } };
 3176|     83|    {
 3177|     83|        size_t i = (size_t)0U;
 3178|     83|        if (last_len > (size_t)0U) {
  ------------------
  |  Branch (3178:13): [True: 83, False: 0]
  ------------------
 3179|     83|            Eurydice_slice uu____0 =
 3180|     83|                Eurydice_array_to_subslice2(blocks[i], (size_t)0U, last_len, uint8_t);
  ------------------
  |  |   75|     83|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3181|     83|            Eurydice_slice_copy(uu____0, last[i], uint8_t);
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 3182|     83|        }
 3183|     83|        blocks[i][last_len] = 6U;
 3184|     83|        size_t uu____1 = i;
 3185|     83|        size_t uu____2 = (size_t)72U - (size_t)1U;
 3186|     83|        blocks[uu____1][uu____2] = (uint32_t)blocks[uu____1][uu____2] | 128U;
 3187|     83|    }
 3188|     83|    uint64_t(*uu____3)[5U] = s->st;
 3189|     83|    uint8_t uu____4[1U][200U];
 3190|     83|    memcpy(uu____4, blocks, (size_t)1U * sizeof(uint8_t[200U]));
 3191|     83|    libcrux_sha3_portable_keccak_load_block_full_5a_051(uu____3, uu____4);
 3192|     83|    libcrux_sha3_generic_keccak_keccakf1600_b8(s);
 3193|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_full_5a_051:
 3154|     83|{
 3155|     83|    uint64_t(*uu____0)[5U] = a;
 3156|       |    /* Passing arrays by value in Rust generates a copy in C */
 3157|     83|    uint8_t copy_of_b[1U][200U];
 3158|     83|    memcpy(copy_of_b, b, (size_t)1U * sizeof(uint8_t[200U]));
 3159|     83|    libcrux_sha3_portable_keccak_load_block_full_d41(uu____0, copy_of_b);
 3160|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_full_d41:
 3135|     83|{
 3136|     83|    Eurydice_slice buf[1U] = {
 3137|     83|        Eurydice_array_to_slice((size_t)200U, blocks[0U], uint8_t)
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 3138|     83|    };
 3139|     83|    libcrux_sha3_portable_keccak_load_block_651(s, buf);
 3140|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_squeeze_first_and_last_88:
 3261|     83|{
 3262|     83|    uint8_t b[1U][200U];
 3263|     83|    libcrux_sha3_portable_keccak_store_block_full_5a_27(s->st, b);
 3264|     83|    {
 3265|     83|        size_t i = (size_t)0U;
 3266|     83|        Eurydice_slice uu____0 = out[i];
 3267|     83|        uint8_t *uu____1 = b[i];
 3268|     83|        core_ops_range_Range_b3 lit;
 3269|     83|        lit.start = (size_t)0U;
 3270|     83|        lit.end = Eurydice_slice_len(out[i], uint8_t);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3271|     83|        Eurydice_slice_copy(
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 3272|     83|            uu____0,
 3273|     83|            Eurydice_array_to_subslice((size_t)200U, uu____1, lit, uint8_t,
 3274|     83|                                       core_ops_range_Range_b3),
 3275|     83|            uint8_t);
 3276|     83|    }
 3277|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_full_5a_27:
 3247|     83|{
 3248|     83|    libcrux_sha3_portable_keccak_store_block_full_7e(a, ret);
 3249|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_full_7e:
 3223|     83|{
 3224|     83|    uint8_t out[200U] = { 0U };
 3225|     83|    Eurydice_slice buf[1U] = {
 3226|     83|        Eurydice_array_to_slice((size_t)200U, out, uint8_t)
  ------------------
  |  |   69|     83|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|     83|                   end) /* x is already at an array type, no need for cast */
  ------------------
 3227|     83|    };
 3228|     83|    libcrux_sha3_portable_keccak_store_block_9b1(s, buf);
 3229|       |    /* Passing arrays by value in Rust generates a copy in C */
 3230|     83|    uint8_t copy_of_out[200U];
 3231|     83|    memcpy(copy_of_out, out, (size_t)200U * sizeof(uint8_t));
 3232|     83|    memcpy(ret[0U], copy_of_out, (size_t)200U * sizeof(uint8_t));
 3233|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_9b1:
 3203|     83|{
 3204|    830|    for (size_t i = (size_t)0U; i < (size_t)72U / (size_t)8U; i++) {
  ------------------
  |  Branch (3204:33): [True: 747, False: 83]
  ------------------
 3205|    747|        size_t i0 = i;
 3206|    747|        Eurydice_slice uu____0 = Eurydice_slice_subslice2(
  ------------------
  |  |   63|    747|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|    747|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    747|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3207|    747|            out[0U], (size_t)8U * i0, (size_t)8U * i0 + (size_t)8U, uint8_t);
 3208|    747|        uint8_t ret[8U];
 3209|    747|        core_num__u64_9__to_le_bytes(s[i0 / (size_t)5U][i0 % (size_t)5U], ret);
 3210|    747|        Eurydice_slice_copy(
  ------------------
  |  |   84|    747|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 3211|    747|            uu____0, Eurydice_array_to_slice((size_t)8U, ret, uint8_t), uint8_t);
 3212|    747|    }
 3213|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_split_at_mut_n_5a:
  198|  1.49k|{
  199|  1.49k|    return libcrux_sha3_portable_keccak_split_at_mut_1(a, mid);
  200|  1.49k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_split_at_mut_1:
  180|  1.49k|{
  181|  1.49k|    Eurydice_slice_uint8_t_x2 uu____0 = Eurydice_slice_split_at_mut(
  ------------------
  |  |  107|  1.49k|    (CLITERAL(ret_t){                                                   \
  |  |  ------------------
  |  |  |  |   27|  1.49k|#define CLITERAL(type) (type)
  |  |  ------------------
  |  |  108|  1.49k|        .fst = { .ptr = slice.ptr, .len = mid },                        \
  |  |  109|  1.49k|        .snd = { .ptr = (char *)slice.ptr + mid * sizeof(element_type), \
  |  |  110|  1.49k|                 .len = slice.len - mid } })
  ------------------
  182|  1.49k|        out[0U], mid, uint8_t, Eurydice_slice_uint8_t_x2);
  183|  1.49k|    Eurydice_slice out00 = uu____0.fst;
  184|  1.49k|    Eurydice_slice out01 = uu____0.snd;
  185|  1.49k|    Eurydice_slice_uint8_t_1size_t__x2 lit;
  186|  1.49k|    lit.fst[0U] = out00;
  187|  1.49k|    lit.snd[0U] = out01;
  188|  1.49k|    return lit;
  189|  1.49k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccakx1_e40:
 3056|     83|{
 3057|       |    /* Passing arrays by value in Rust generates a copy in C */
 3058|     83|    Eurydice_slice copy_of_data[1U];
 3059|     83|    memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 3060|     83|    libcrux_sha3_generic_keccak_keccak_060(copy_of_data, out);
 3061|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_keccak_060:
 2983|     83|{
 2984|     83|    libcrux_sha3_generic_keccak_KeccakState_48 s =
 2985|     83|        libcrux_sha3_generic_keccak_new_1e_cf();
 2986|     83|    for (size_t i = (size_t)0U;
 2987|    747|         i < Eurydice_slice_len(data[0U], uint8_t) / (size_t)136U; i++) {
  ------------------
  |  |   82|    747|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    747|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (2987:10): [True: 664, False: 83]
  ------------------
 2988|    664|        size_t i0 = i;
 2989|    664|        libcrux_sha3_generic_keccak_KeccakState_48 *uu____0 = &s;
 2990|       |        /* Passing arrays by value in Rust generates a copy in C */
 2991|    664|        Eurydice_slice copy_of_data[1U];
 2992|    664|        memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 2993|    664|        Eurydice_slice ret[1U];
 2994|    664|        libcrux_sha3_portable_keccak_slice_n_5a(copy_of_data, i0 * (size_t)136U,
 2995|    664|                                                (size_t)136U, ret);
 2996|    664|        libcrux_sha3_generic_keccak_absorb_block_400(uu____0, ret);
 2997|    664|    }
 2998|     83|    size_t rem = Eurydice_slice_len(data[0U], uint8_t) % (size_t)136U;
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 2999|     83|    libcrux_sha3_generic_keccak_KeccakState_48 *uu____2 = &s;
 3000|       |    /* Passing arrays by value in Rust generates a copy in C */
 3001|     83|    Eurydice_slice copy_of_data[1U];
 3002|     83|    memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 3003|     83|    Eurydice_slice ret[1U];
 3004|     83|    libcrux_sha3_portable_keccak_slice_n_5a(
 3005|     83|        copy_of_data, Eurydice_slice_len(data[0U], uint8_t) - rem, rem, ret);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3006|     83|    libcrux_sha3_generic_keccak_absorb_final_402(uu____2, ret);
 3007|     83|    size_t outlen = Eurydice_slice_len(out[0U], uint8_t);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 3008|     83|    size_t blocks = outlen / (size_t)136U;
 3009|     83|    size_t last = outlen - outlen % (size_t)136U;
 3010|     83|    if (blocks == (size_t)0U) {
  ------------------
  |  Branch (3010:9): [True: 83, False: 0]
  ------------------
 3011|     83|        libcrux_sha3_generic_keccak_squeeze_first_and_last_880(&s, out);
 3012|     83|    } else {
 3013|      0|        Eurydice_slice_uint8_t_1size_t__x2 uu____4 =
 3014|      0|            libcrux_sha3_portable_keccak_split_at_mut_n_5a(out, (size_t)136U);
 3015|      0|        Eurydice_slice o0[1U];
 3016|      0|        memcpy(o0, uu____4.fst, (size_t)1U * sizeof(Eurydice_slice));
 3017|      0|        Eurydice_slice o1[1U];
 3018|      0|        memcpy(o1, uu____4.snd, (size_t)1U * sizeof(Eurydice_slice));
 3019|      0|        libcrux_sha3_generic_keccak_squeeze_first_block_7b0(&s, o0);
 3020|      0|        core_ops_range_Range_b3 iter =
 3021|      0|            core_iter_traits_collect___core__iter__traits__collect__IntoIterator_for_I__1__into_iter(
  ------------------
  |  |  246|      0|    Eurydice_into_iter
  |  |  ------------------
  |  |  |  |  241|      0|#define Eurydice_into_iter(x, t, _ret_t) (x)
  |  |  ------------------
  ------------------
 3022|      0|                (CLITERAL(core_ops_range_Range_b3){ .start = (size_t)1U,
 3023|      0|                                                    .end = blocks }),
 3024|      0|                core_ops_range_Range_b3, core_ops_range_Range_b3);
 3025|      0|        while (true) {
 3026|      0|            if (core_iter_range___core__iter__traits__iterator__Iterator_for_core__ops__range__Range_A___6__next(
  ------------------
  |  |  238|      0|    Eurydice_range_iter_next
  |  |  ------------------
  |  |  |  |  228|      0|    (((iter_ptr)->start == (iter_ptr)->end)             \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (228:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |  229|      0|         ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   38|      0|#define core_option_None 0
  |  |  |  |  ------------------
  |  |  |  |  230|      0|         : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      0|#define core_option_Some 1
  |  |  |  |  ------------------
  |  |  |  |  231|      0|                             .f0 = (iter_ptr)->start++ }))
  |  |  ------------------
  ------------------
  |  Branch (3026:17): [True: 0, False: 0]
  ------------------
 3027|      0|                    &iter, size_t, core_option_Option_b3)
 3028|      0|                    .tag == core_option_None) {
  ------------------
  |  |   38|      0|#define core_option_None 0
  ------------------
 3029|      0|                break;
 3030|      0|            } else {
 3031|      0|                Eurydice_slice_uint8_t_1size_t__x2 uu____5 =
 3032|      0|                    libcrux_sha3_portable_keccak_split_at_mut_n_5a(o1, (size_t)136U);
 3033|      0|                Eurydice_slice o[1U];
 3034|      0|                memcpy(o, uu____5.fst, (size_t)1U * sizeof(Eurydice_slice));
 3035|      0|                Eurydice_slice orest[1U];
 3036|      0|                memcpy(orest, uu____5.snd, (size_t)1U * sizeof(Eurydice_slice));
 3037|      0|                libcrux_sha3_generic_keccak_squeeze_next_block_c20(&s, o);
 3038|      0|                memcpy(o1, orest, (size_t)1U * sizeof(Eurydice_slice));
 3039|      0|            }
 3040|      0|        }
 3041|      0|        if (last < outlen) {
  ------------------
  |  Branch (3041:13): [True: 0, False: 0]
  ------------------
 3042|      0|            libcrux_sha3_generic_keccak_squeeze_last_ca0(s, o1);
 3043|      0|        }
 3044|      0|    }
 3045|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_absorb_block_400:
 2747|    664|{
 2748|    664|    uint64_t(*uu____0)[5U] = s->st;
 2749|    664|    Eurydice_slice uu____1[1U];
 2750|    664|    memcpy(uu____1, blocks, (size_t)1U * sizeof(Eurydice_slice));
 2751|    664|    libcrux_sha3_portable_keccak_load_block_5a_35(uu____0, uu____1);
 2752|    664|    libcrux_sha3_generic_keccak_keccakf1600_b8(s);
 2753|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_5a_35:
 1745|    664|{
 1746|    664|    uint64_t(*uu____0)[5U] = a;
 1747|       |    /* Passing arrays by value in Rust generates a copy in C */
 1748|    664|    Eurydice_slice copy_of_b[1U];
 1749|    664|    memcpy(copy_of_b, b, (size_t)1U * sizeof(Eurydice_slice));
 1750|    664|    libcrux_sha3_portable_keccak_load_block_650(uu____0, copy_of_b);
 1751|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_650:
 1582|  1.32k|{
 1583|  23.9k|    for (size_t i = (size_t)0U; i < (size_t)136U / (size_t)8U; i++) {
  ------------------
  |  Branch (1583:33): [True: 22.5k, False: 1.32k]
  ------------------
 1584|  22.5k|        size_t i0 = i;
 1585|  22.5k|        uint8_t uu____0[8U];
 1586|  22.5k|        core_result_Result_56 dst;
 1587|  22.5k|        Eurydice_slice_to_array2(
  ------------------
  |  |  116|  22.5k|    Eurydice_slice_to_array3(&(dst)->tag, (char *)&(dst)->val.case_Ok, src, \
  |  |  117|  22.5k|                             sizeof(t_arr))
  ------------------
 1588|  22.5k|            &dst,
 1589|  22.5k|            Eurydice_slice_subslice2(blocks[0U], (size_t)8U * i0,
 1590|  22.5k|                                     (size_t)8U * i0 + (size_t)8U, uint8_t),
 1591|  22.5k|            Eurydice_slice, uint8_t[8U]);
 1592|  22.5k|        core_result_unwrap_41_0e(dst, uu____0);
 1593|  22.5k|        size_t uu____1 = i0 / (size_t)5U;
 1594|  22.5k|        size_t uu____2 = i0 % (size_t)5U;
 1595|  22.5k|        s[uu____1][uu____2] =
 1596|  22.5k|            s[uu____1][uu____2] ^ core_num__u64_9__from_le_bytes(uu____0);
 1597|  22.5k|    }
 1598|  1.32k|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_absorb_final_402:
 2950|     83|{
 2951|     83|    size_t last_len = Eurydice_slice_len(last[0U], uint8_t);
  ------------------
  |  |   82|     83|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|     83|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 2952|     83|    uint8_t blocks[1U][200U] = { { 0U } };
 2953|     83|    {
 2954|     83|        size_t i = (size_t)0U;
 2955|     83|        if (last_len > (size_t)0U) {
  ------------------
  |  Branch (2955:13): [True: 83, False: 0]
  ------------------
 2956|     83|            Eurydice_slice uu____0 =
 2957|     83|                Eurydice_array_to_subslice2(blocks[i], (size_t)0U, last_len, uint8_t);
  ------------------
  |  |   75|     83|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|     83|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     83|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2958|     83|            Eurydice_slice_copy(uu____0, last[i], uint8_t);
  ------------------
  |  |   84|     83|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 2959|     83|        }
 2960|     83|        blocks[i][last_len] = 6U;
 2961|     83|        size_t uu____1 = i;
 2962|     83|        size_t uu____2 = (size_t)136U - (size_t)1U;
 2963|     83|        blocks[uu____1][uu____2] = (uint32_t)blocks[uu____1][uu____2] | 128U;
 2964|     83|    }
 2965|     83|    uint64_t(*uu____3)[5U] = s->st;
 2966|     83|    uint8_t uu____4[1U][200U];
 2967|     83|    memcpy(uu____4, blocks, (size_t)1U * sizeof(uint8_t[200U]));
 2968|     83|    libcrux_sha3_portable_keccak_load_block_full_5a_050(uu____3, uu____4);
 2969|     83|    libcrux_sha3_generic_keccak_keccakf1600_b8(s);
 2970|     83|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_full_5a_050:
 1627|    664|{
 1628|    664|    uint64_t(*uu____0)[5U] = a;
 1629|       |    /* Passing arrays by value in Rust generates a copy in C */
 1630|    664|    uint8_t copy_of_b[1U][200U];
 1631|    664|    memcpy(copy_of_b, b, (size_t)1U * sizeof(uint8_t[200U]));
 1632|    664|    libcrux_sha3_portable_keccak_load_block_full_d40(uu____0, copy_of_b);
 1633|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_full_d40:
 1608|    664|{
 1609|    664|    Eurydice_slice buf[1U] = {
 1610|    664|        Eurydice_array_to_slice((size_t)200U, blocks[0U], uint8_t)
  ------------------
  |  |   69|    664|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|    664|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    664|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|    664|                   end) /* x is already at an array type, no need for cast */
  ------------------
 1611|    664|    };
 1612|    664|    libcrux_sha3_portable_keccak_load_block_650(s, buf);
 1613|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_squeeze_first_and_last_880:
 2801|    664|{
 2802|    664|    uint8_t b[1U][200U];
 2803|    664|    libcrux_sha3_portable_keccak_store_block_full_5a_270(s->st, b);
 2804|    664|    {
 2805|    664|        size_t i = (size_t)0U;
 2806|    664|        Eurydice_slice uu____0 = out[i];
 2807|    664|        uint8_t *uu____1 = b[i];
 2808|    664|        core_ops_range_Range_b3 lit;
 2809|    664|        lit.start = (size_t)0U;
 2810|    664|        lit.end = Eurydice_slice_len(out[i], uint8_t);
  ------------------
  |  |   82|    664|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    664|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 2811|    664|        Eurydice_slice_copy(
  ------------------
  |  |   84|    664|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 2812|    664|            uu____0,
 2813|    664|            Eurydice_array_to_subslice((size_t)200U, uu____1, lit, uint8_t,
 2814|    664|                                       core_ops_range_Range_b3),
 2815|    664|            uint8_t);
 2816|    664|    }
 2817|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_full_5a_270:
 2787|    664|{
 2788|    664|    libcrux_sha3_portable_keccak_store_block_full_7e0(a, ret);
 2789|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_full_7e0:
 2763|    664|{
 2764|    664|    uint8_t out[200U] = { 0U };
 2765|    664|    Eurydice_slice buf[1U] = {
 2766|    664|        Eurydice_array_to_slice((size_t)200U, out, uint8_t)
  ------------------
  |  |   69|    664|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|    664|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    664|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|    664|                   end) /* x is already at an array type, no need for cast */
  ------------------
 2767|    664|    };
 2768|    664|    libcrux_sha3_portable_keccak_store_block_9b0(s, buf);
 2769|       |    /* Passing arrays by value in Rust generates a copy in C */
 2770|    664|    uint8_t copy_of_out[200U];
 2771|    664|    memcpy(copy_of_out, out, (size_t)200U * sizeof(uint8_t));
 2772|    664|    memcpy(ret[0U], copy_of_out, (size_t)200U * sizeof(uint8_t));
 2773|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_9b0:
 1676|    664|{
 1677|  11.9k|    for (size_t i = (size_t)0U; i < (size_t)136U / (size_t)8U; i++) {
  ------------------
  |  Branch (1677:33): [True: 11.2k, False: 664]
  ------------------
 1678|  11.2k|        size_t i0 = i;
 1679|  11.2k|        Eurydice_slice uu____0 = Eurydice_slice_subslice2(
  ------------------
  |  |   63|  11.2k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  11.2k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  11.2k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1680|  11.2k|            out[0U], (size_t)8U * i0, (size_t)8U * i0 + (size_t)8U, uint8_t);
 1681|  11.2k|        uint8_t ret[8U];
 1682|  11.2k|        core_num__u64_9__to_le_bytes(s[i0 / (size_t)5U][i0 % (size_t)5U], ret);
 1683|  11.2k|        Eurydice_slice_copy(
  ------------------
  |  |   84|  11.2k|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 1684|  11.2k|            uu____0, Eurydice_array_to_slice((size_t)8U, ret, uint8_t), uint8_t);
 1685|  11.2k|    }
 1686|    664|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_absorb_final_40:
 1487|    747|{
 1488|    747|    size_t last_len = Eurydice_slice_len(last[0U], uint8_t);
  ------------------
  |  |   82|    747|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    747|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 1489|    747|    uint8_t blocks[1U][200U] = { { 0U } };
 1490|    747|    {
 1491|    747|        size_t i = (size_t)0U;
 1492|    747|        if (last_len > (size_t)0U) {
  ------------------
  |  Branch (1492:13): [True: 747, False: 0]
  ------------------
 1493|    747|            Eurydice_slice uu____0 =
 1494|    747|                Eurydice_array_to_subslice2(blocks[i], (size_t)0U, last_len, uint8_t);
  ------------------
  |  |   75|    747|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|    747|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    747|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1495|    747|            Eurydice_slice_copy(uu____0, last[i], uint8_t);
  ------------------
  |  |   84|    747|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 1496|    747|        }
 1497|    747|        blocks[i][last_len] = 31U;
 1498|    747|        size_t uu____1 = i;
 1499|    747|        size_t uu____2 = (size_t)168U - (size_t)1U;
 1500|    747|        blocks[uu____1][uu____2] = (uint32_t)blocks[uu____1][uu____2] | 128U;
 1501|    747|    }
 1502|    747|    uint64_t(*uu____3)[5U] = s->st;
 1503|    747|    uint8_t uu____4[1U][200U];
 1504|    747|    memcpy(uu____4, blocks, (size_t)1U * sizeof(uint8_t[200U]));
 1505|    747|    libcrux_sha3_portable_keccak_load_block_full_5a_05(uu____3, uu____4);
 1506|    747|    libcrux_sha3_generic_keccak_keccakf1600_b8(s);
 1507|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_full_5a_05:
  310|    747|{
  311|    747|    uint64_t(*uu____0)[5U] = a;
  312|       |    /* Passing arrays by value in Rust generates a copy in C */
  313|    747|    uint8_t copy_of_b[1U][200U];
  314|    747|    memcpy(copy_of_b, b, (size_t)1U * sizeof(uint8_t[200U]));
  315|    747|    libcrux_sha3_portable_keccak_load_block_full_d4(uu____0, copy_of_b);
  316|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_full_d4:
  291|    747|{
  292|    747|    Eurydice_slice buf[1U] = {
  293|    747|        Eurydice_array_to_slice((size_t)200U, blocks[0U], uint8_t)
  ------------------
  |  |   69|    747|    EURYDICE_SLICE(x, 0,                   \
  |  |  ------------------
  |  |  |  |   50|    747|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    747|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   70|    747|                   end) /* x is already at an array type, no need for cast */
  ------------------
  294|    747|    };
  295|    747|    libcrux_sha3_portable_keccak_load_block_65(s, buf);
  296|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_load_block_65:
  265|    747|{
  266|  16.4k|    for (size_t i = (size_t)0U; i < (size_t)168U / (size_t)8U; i++) {
  ------------------
  |  Branch (266:33): [True: 15.6k, False: 747]
  ------------------
  267|  15.6k|        size_t i0 = i;
  268|  15.6k|        uint8_t uu____0[8U];
  269|  15.6k|        core_result_Result_56 dst;
  270|  15.6k|        Eurydice_slice_to_array2(
  ------------------
  |  |  116|  15.6k|    Eurydice_slice_to_array3(&(dst)->tag, (char *)&(dst)->val.case_Ok, src, \
  |  |  117|  15.6k|                             sizeof(t_arr))
  ------------------
  271|  15.6k|            &dst,
  272|  15.6k|            Eurydice_slice_subslice2(blocks[0U], (size_t)8U * i0,
  273|  15.6k|                                     (size_t)8U * i0 + (size_t)8U, uint8_t),
  274|  15.6k|            Eurydice_slice, uint8_t[8U]);
  275|  15.6k|        core_result_unwrap_41_0e(dst, uu____0);
  276|  15.6k|        size_t uu____1 = i0 / (size_t)5U;
  277|  15.6k|        size_t uu____2 = i0 % (size_t)5U;
  278|  15.6k|        s[uu____1][uu____2] =
  279|  15.6k|            s[uu____1][uu____2] ^ core_num__u64_9__from_le_bytes(uu____0);
  280|  15.6k|    }
  281|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_squeeze_first_block_7b:
 1570|    747|{
 1571|    747|    libcrux_sha3_portable_keccak_store_block_5a_49(s->st, out);
 1572|    747|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_5a_49:
 1541|  2.48k|{
 1542|  2.48k|    libcrux_sha3_portable_keccak_store_block_9b(a, b);
 1543|  2.48k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccak_store_block_9b:
 1517|  2.48k|{
 1518|  54.5k|    for (size_t i = (size_t)0U; i < (size_t)168U / (size_t)8U; i++) {
  ------------------
  |  Branch (1518:33): [True: 52.1k, False: 2.48k]
  ------------------
 1519|  52.1k|        size_t i0 = i;
 1520|  52.1k|        Eurydice_slice uu____0 = Eurydice_slice_subslice2(
  ------------------
  |  |   63|  52.1k|    EURYDICE_SLICE((t *)s.ptr, start, end)
  |  |  ------------------
  |  |  |  |   50|  52.1k|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  52.1k|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1521|  52.1k|            out[0U], (size_t)8U * i0, (size_t)8U * i0 + (size_t)8U, uint8_t);
 1522|  52.1k|        uint8_t ret[8U];
 1523|  52.1k|        core_num__u64_9__to_le_bytes(s[i0 / (size_t)5U][i0 % (size_t)5U], ret);
 1524|  52.1k|        Eurydice_slice_copy(
  ------------------
  |  |   84|  52.1k|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 1525|  52.1k|            uu____0, Eurydice_array_to_slice((size_t)8U, ret, uint8_t), uint8_t);
 1526|  52.1k|    }
 1527|  2.48k|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_squeeze_next_block_c2:
 1555|  1.73k|{
 1556|  1.73k|    libcrux_sha3_generic_keccak_keccakf1600_b8(s);
 1557|  1.73k|    libcrux_sha3_portable_keccak_store_block_5a_49(s->st, out);
 1558|  1.73k|}
libcrux_mlkem_portable.c:libcrux_sha3_portable_keccakx1_e41:
 2932|    581|{
 2933|       |    /* Passing arrays by value in Rust generates a copy in C */
 2934|    581|    Eurydice_slice copy_of_data[1U];
 2935|    581|    memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 2936|    581|    libcrux_sha3_generic_keccak_keccak_061(copy_of_data, out);
 2937|    581|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_keccak_061:
 2859|    581|{
 2860|    581|    libcrux_sha3_generic_keccak_KeccakState_48 s =
 2861|    581|        libcrux_sha3_generic_keccak_new_1e_cf();
 2862|    581|    for (size_t i = (size_t)0U;
 2863|    581|         i < Eurydice_slice_len(data[0U], uint8_t) / (size_t)136U; i++) {
  ------------------
  |  |   82|    581|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    581|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
  |  Branch (2863:10): [True: 0, False: 581]
  ------------------
 2864|      0|        size_t i0 = i;
 2865|      0|        libcrux_sha3_generic_keccak_KeccakState_48 *uu____0 = &s;
 2866|       |        /* Passing arrays by value in Rust generates a copy in C */
 2867|      0|        Eurydice_slice copy_of_data[1U];
 2868|      0|        memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 2869|      0|        Eurydice_slice ret[1U];
 2870|      0|        libcrux_sha3_portable_keccak_slice_n_5a(copy_of_data, i0 * (size_t)136U,
 2871|      0|                                                (size_t)136U, ret);
 2872|      0|        libcrux_sha3_generic_keccak_absorb_block_400(uu____0, ret);
 2873|      0|    }
 2874|    581|    size_t rem = Eurydice_slice_len(data[0U], uint8_t) % (size_t)136U;
  ------------------
  |  |   82|    581|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    581|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 2875|    581|    libcrux_sha3_generic_keccak_KeccakState_48 *uu____2 = &s;
 2876|       |    /* Passing arrays by value in Rust generates a copy in C */
 2877|    581|    Eurydice_slice copy_of_data[1U];
 2878|    581|    memcpy(copy_of_data, data, (size_t)1U * sizeof(Eurydice_slice));
 2879|    581|    Eurydice_slice ret[1U];
 2880|    581|    libcrux_sha3_portable_keccak_slice_n_5a(
 2881|    581|        copy_of_data, Eurydice_slice_len(data[0U], uint8_t) - rem, rem, ret);
  ------------------
  |  |   82|    581|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    581|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 2882|    581|    libcrux_sha3_generic_keccak_absorb_final_400(uu____2, ret);
 2883|    581|    size_t outlen = Eurydice_slice_len(out[0U], uint8_t);
  ------------------
  |  |   82|    581|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    581|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 2884|    581|    size_t blocks = outlen / (size_t)136U;
 2885|    581|    size_t last = outlen - outlen % (size_t)136U;
 2886|    581|    if (blocks == (size_t)0U) {
  ------------------
  |  Branch (2886:9): [True: 581, False: 0]
  ------------------
 2887|    581|        libcrux_sha3_generic_keccak_squeeze_first_and_last_880(&s, out);
 2888|    581|    } else {
 2889|      0|        Eurydice_slice_uint8_t_1size_t__x2 uu____4 =
 2890|      0|            libcrux_sha3_portable_keccak_split_at_mut_n_5a(out, (size_t)136U);
 2891|      0|        Eurydice_slice o0[1U];
 2892|      0|        memcpy(o0, uu____4.fst, (size_t)1U * sizeof(Eurydice_slice));
 2893|      0|        Eurydice_slice o1[1U];
 2894|      0|        memcpy(o1, uu____4.snd, (size_t)1U * sizeof(Eurydice_slice));
 2895|      0|        libcrux_sha3_generic_keccak_squeeze_first_block_7b0(&s, o0);
 2896|      0|        core_ops_range_Range_b3 iter =
 2897|      0|            core_iter_traits_collect___core__iter__traits__collect__IntoIterator_for_I__1__into_iter(
  ------------------
  |  |  246|      0|    Eurydice_into_iter
  |  |  ------------------
  |  |  |  |  241|      0|#define Eurydice_into_iter(x, t, _ret_t) (x)
  |  |  ------------------
  ------------------
 2898|      0|                (CLITERAL(core_ops_range_Range_b3){ .start = (size_t)1U,
 2899|      0|                                                    .end = blocks }),
 2900|      0|                core_ops_range_Range_b3, core_ops_range_Range_b3);
 2901|      0|        while (true) {
 2902|      0|            if (core_iter_range___core__iter__traits__iterator__Iterator_for_core__ops__range__Range_A___6__next(
  ------------------
  |  |  238|      0|    Eurydice_range_iter_next
  |  |  ------------------
  |  |  |  |  228|      0|    (((iter_ptr)->start == (iter_ptr)->end)             \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (228:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |  229|      0|         ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        ? (CLITERAL(ret_t){ .tag = core_option_None }) \
  |  |  |  |  ------------------
  |  |  |  |  |  |   38|      0|#define core_option_None 0
  |  |  |  |  ------------------
  |  |  |  |  230|      0|         : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  |  |                        : (CLITERAL(ret_t){ .tag = core_option_Some,   \
  |  |  |  |  ------------------
  |  |  |  |  |  |   39|      0|#define core_option_Some 1
  |  |  |  |  ------------------
  |  |  |  |  231|      0|                             .f0 = (iter_ptr)->start++ }))
  |  |  ------------------
  ------------------
  |  Branch (2902:17): [True: 0, False: 0]
  ------------------
 2903|      0|                    &iter, size_t, core_option_Option_b3)
 2904|      0|                    .tag == core_option_None) {
  ------------------
  |  |   38|      0|#define core_option_None 0
  ------------------
 2905|      0|                break;
 2906|      0|            } else {
 2907|      0|                Eurydice_slice_uint8_t_1size_t__x2 uu____5 =
 2908|      0|                    libcrux_sha3_portable_keccak_split_at_mut_n_5a(o1, (size_t)136U);
 2909|      0|                Eurydice_slice o[1U];
 2910|      0|                memcpy(o, uu____5.fst, (size_t)1U * sizeof(Eurydice_slice));
 2911|      0|                Eurydice_slice orest[1U];
 2912|      0|                memcpy(orest, uu____5.snd, (size_t)1U * sizeof(Eurydice_slice));
 2913|      0|                libcrux_sha3_generic_keccak_squeeze_next_block_c20(&s, o);
 2914|      0|                memcpy(o1, orest, (size_t)1U * sizeof(Eurydice_slice));
 2915|      0|            }
 2916|      0|        }
 2917|      0|        if (last < outlen) {
  ------------------
  |  Branch (2917:13): [True: 0, False: 0]
  ------------------
 2918|      0|            libcrux_sha3_generic_keccak_squeeze_last_ca0(s, o1);
 2919|      0|        }
 2920|      0|    }
 2921|    581|}
libcrux_mlkem_portable.c:libcrux_sha3_generic_keccak_absorb_final_400:
 1646|    581|{
 1647|    581|    size_t last_len = Eurydice_slice_len(last[0U], uint8_t);
  ------------------
  |  |   82|    581|#define Eurydice_slice_len(s, t) EURYDICE_SLICE_LEN(s, t)
  |  |  ------------------
  |  |  |  |   51|    581|#define EURYDICE_SLICE_LEN(s, _) s.len
  |  |  ------------------
  ------------------
 1648|    581|    uint8_t blocks[1U][200U] = { { 0U } };
 1649|    581|    {
 1650|    581|        size_t i = (size_t)0U;
 1651|    581|        if (last_len > (size_t)0U) {
  ------------------
  |  Branch (1651:13): [True: 581, False: 0]
  ------------------
 1652|    581|            Eurydice_slice uu____0 =
 1653|    581|                Eurydice_array_to_subslice2(blocks[i], (size_t)0U, last_len, uint8_t);
  ------------------
  |  |   75|    581|    EURYDICE_SLICE((t *)x, start, end)
  |  |  ------------------
  |  |  |  |   50|    581|    (CLITERAL(Eurydice_slice){ .ptr = (void *)(x + start), .len = end - start })
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    581|#define CLITERAL(type) (type)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1654|    581|            Eurydice_slice_copy(uu____0, last[i], uint8_t);
  ------------------
  |  |   84|    581|    memcpy(dst.ptr, src.ptr, dst.len * sizeof(t))
  ------------------
 1655|    581|        }
 1656|    581|        blocks[i][last_len] = 31U;
 1657|    581|        size_t uu____1 = i;
 1658|    581|        size_t uu____2 = (size_t)136U - (size_t)1U;
 1659|    581|        blocks[uu____1][uu____2] = (uint32_t)blocks[uu____1][uu____2] | 128U;
 1660|    581|    }
 1661|    581|    uint64_t(*uu____3)[5U] = s->st;
 1662|    581|    uint8_t uu____4[1U][200U];
 1663|    581|    memcpy(uu____4, blocks, (size_t)1U * sizeof(uint8_t[200U]));
 1664|    581|    libcrux_sha3_portable_keccak_load_block_full_5a_050(uu____3, uu____4);
 1665|    581|    libcrux_sha3_generic_keccak_keccakf1600_b8(s);
 1666|    581|}

NSS_NoDB_Init:
  949|      1|{
  950|      1|    return nss_Init("", "", "", "", "", "", "", "", "", NULL, NULL,
  951|      1|                    PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE,
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
                                  PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE,
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
                                  PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE,
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
                                  PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE,
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
                                  PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE,
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
                                  PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE, PR_TRUE,
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  952|      1|                    PR_FALSE, PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                                  PR_FALSE, PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                                  PR_FALSE, PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  953|      1|}
NSS_RegisterShutdown:
  992|      4|{
  993|      4|    int i;
  994|       |
  995|       |    /* make sure our lock and condition variable are initialized one and only
  996|       |     * one time */
  997|      4|    if (PR_CallOnce(&nssInitOnce, nss_doLockInit) != PR_SUCCESS) {
  ------------------
  |  Branch (997:9): [True: 0, False: 4]
  ------------------
  998|      0|        return SECFailure;
  999|      0|    }
 1000|       |
 1001|      4|    PZ_Lock(nssInitLock);
  ------------------
  |  |  245|      4|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1002|      4|    if (!NSS_IsInitialized()) {
  ------------------
  |  Branch (1002:9): [True: 0, False: 4]
  ------------------
 1003|      0|        PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1004|      0|        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1005|      0|        return SECFailure;
 1006|      0|    }
 1007|      4|    PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      4|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1008|      4|    if (sFunc == NULL) {
  ------------------
  |  Branch (1008:9): [True: 0, False: 4]
  ------------------
 1009|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1010|      0|        return SECFailure;
 1011|      0|    }
 1012|       |
 1013|      4|    PORT_Assert(nssShutdownList.lock);
  ------------------
  |  |  120|      4|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1014|      4|    PZ_Lock(nssShutdownList.lock);
  ------------------
  |  |  245|      4|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1015|       |
 1016|       |    /* make sure we don't have a duplicate */
 1017|      4|    i = nss_GetShutdownEntry(sFunc, appData);
 1018|      4|    if (i >= 0) {
  ------------------
  |  Branch (1018:9): [True: 0, False: 4]
  ------------------
 1019|      0|        PZ_Unlock(nssShutdownList.lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1020|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1021|      0|        return SECFailure;
 1022|      0|    }
 1023|       |    /* find an empty slot */
 1024|      4|    i = nss_GetShutdownEntry(NULL, NULL);
 1025|      4|    if (i >= 0) {
  ------------------
  |  Branch (1025:9): [True: 0, False: 4]
  ------------------
 1026|      0|        nssShutdownList.funcs[i].func = sFunc;
 1027|      0|        nssShutdownList.funcs[i].appData = appData;
 1028|      0|        PZ_Unlock(nssShutdownList.lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1029|      0|        return SECSuccess;
 1030|      0|    }
 1031|      4|    if (nssShutdownList.allocatedFuncs == nssShutdownList.peakFuncs) {
  ------------------
  |  Branch (1031:9): [True: 0, False: 4]
  ------------------
 1032|      0|        struct NSSShutdownFuncPair *funcs =
 1033|      0|            (struct NSSShutdownFuncPair *)PORT_Realloc(nssShutdownList.funcs,
  ------------------
  |  |   64|      0|#define PORT_Realloc PORT_Realloc_Util
  ------------------
 1034|      0|                                                       (nssShutdownList.allocatedFuncs + NSS_SHUTDOWN_STEP) * sizeof(struct NSSShutdownFuncPair));
  ------------------
  |  |  955|      0|#define NSS_SHUTDOWN_STEP 10
  ------------------
 1035|      0|        if (!funcs) {
  ------------------
  |  Branch (1035:13): [True: 0, False: 0]
  ------------------
 1036|      0|            PZ_Unlock(nssShutdownList.lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1037|      0|            return SECFailure;
 1038|      0|        }
 1039|      0|        nssShutdownList.funcs = funcs;
 1040|      0|        nssShutdownList.allocatedFuncs += NSS_SHUTDOWN_STEP;
  ------------------
  |  |  955|      0|#define NSS_SHUTDOWN_STEP 10
  ------------------
 1041|      0|    }
 1042|      4|    nssShutdownList.funcs[nssShutdownList.peakFuncs].func = sFunc;
 1043|      4|    nssShutdownList.funcs[nssShutdownList.peakFuncs].appData = appData;
 1044|      4|    nssShutdownList.peakFuncs++;
 1045|      4|    PZ_Unlock(nssShutdownList.lock);
  ------------------
  |  |  246|      4|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1046|      4|    return SECSuccess;
 1047|      4|}
nss_Shutdown:
 1143|      1|{
 1144|      1|    SECStatus shutdownRV = SECSuccess;
 1145|      1|    SECStatus rv;
 1146|      1|    PRStatus status;
 1147|      1|    NSSInitContext *temp;
 1148|       |
 1149|      1|    rv = nss_ShutdownShutdownList();
 1150|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1150:9): [True: 0, False: 1]
  ------------------
 1151|      0|        shutdownRV = SECFailure;
 1152|      0|    }
 1153|      1|    cert_DestroyLocks();
 1154|      1|    ShutdownCRLCache();
 1155|      1|    OCSP_ShutdownGlobal();
 1156|       |#ifndef NSS_DISABLE_LIBPKIX
 1157|       |    PKIX_Shutdown(plContext);
 1158|       |#endif /* NSS_DISABLE_LIBPKIX */
 1159|      1|    SECOID_Shutdown();
 1160|      1|    status = STAN_Shutdown();
 1161|      1|    cert_DestroySubjectKeyIDHashTable();
 1162|      1|    pk11_SetInternalKeySlot(NULL);
 1163|      1|    rv = SECMOD_Shutdown();
 1164|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1164:9): [True: 0, False: 1]
  ------------------
 1165|      0|        shutdownRV = SECFailure;
 1166|      0|    }
 1167|      1|    pk11sdr_Shutdown();
 1168|      1|    nssArena_Shutdown();
 1169|      1|    if (status == PR_FAILURE) {
  ------------------
  |  Branch (1169:9): [True: 0, False: 1]
  ------------------
 1170|      0|        if (NSS_GetError() == NSS_ERROR_BUSY) {
  ------------------
  |  Branch (1170:13): [True: 0, False: 0]
  ------------------
 1171|      0|            PORT_SetError(SEC_ERROR_BUSY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1172|      0|        }
 1173|      0|        shutdownRV = SECFailure;
 1174|      0|    }
 1175|       |    /*
 1176|       |     * A thread's error stack is automatically destroyed when the thread
 1177|       |     * terminates, except for the primordial thread, whose error stack is
 1178|       |     * destroyed by PR_Cleanup.  Since NSS is usually shut down by the
 1179|       |     * primordial thread and many NSS-based apps don't call PR_Cleanup,
 1180|       |     * we destroy the calling thread's error stack here. This must be
 1181|       |     * done after any NSS_GetError call, otherwise NSS_GetError will
 1182|       |     * create the error stack again.
 1183|       |     */
 1184|      1|    nss_DestroyErrorStack();
 1185|      1|    nssIsInitted = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1186|      1|    temp = nssInitContextList;
 1187|      1|    nssInitContextList = NULL;
 1188|       |    /* free the old list. This is necessary when we are called from
 1189|       |     * NSS_Shutdown(). */
 1190|      1|    while (temp) {
  ------------------
  |  Branch (1190:12): [True: 0, False: 1]
  ------------------
 1191|      0|        NSSInitContext *next = temp->next;
 1192|      0|        temp->magic = 0;
 1193|      0|        PORT_Free(temp);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1194|      0|        temp = next;
 1195|      0|    }
 1196|      1|    return shutdownRV;
 1197|      1|}
NSS_Shutdown:
 1201|      1|{
 1202|      1|    SECStatus rv;
 1203|       |    /* make sure our lock and condition variable are initialized one and only
 1204|       |     * one time */
 1205|      1|    if (PR_CallOnce(&nssInitOnce, nss_doLockInit) != PR_SUCCESS) {
  ------------------
  |  Branch (1205:9): [True: 0, False: 1]
  ------------------
 1206|      0|        return SECFailure;
 1207|      0|    }
 1208|      1|    PZ_Lock(nssInitLock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1209|       |
 1210|      1|    if (!nssIsInitted) {
  ------------------
  |  Branch (1210:9): [True: 0, False: 1]
  ------------------
 1211|      0|        PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1212|      0|        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1213|      0|        return SECFailure;
 1214|      0|    }
 1215|       |
 1216|       |    /* If one or more threads are in the middle of init, wait for them
 1217|       |     * to complete */
 1218|      1|    while (nssIsInInit) {
  ------------------
  |  Branch (1218:12): [True: 0, False: 1]
  ------------------
 1219|      0|        PZ_WaitCondVar(nssInitCondition, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |  250|      0|#define PZ_WaitCondVar(v, t) PR_WaitCondVar((v), (t))
  ------------------
 1220|      0|    }
 1221|      1|    rv = nss_Shutdown();
 1222|      1|    PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1223|      1|    return rv;
 1224|      1|}
NSS_IsInitialized:
 1303|      5|{
 1304|      5|    return (nssIsInitted) || (nssInitContextList != NULL);
  ------------------
  |  Branch (1304:12): [True: 4, False: 1]
  |  Branch (1304:30): [True: 0, False: 1]
  ------------------
 1305|      5|}
nssinit.c:nss_Init:
  558|      1|{
  559|      1|    SECMODModule *parent = NULL;
  560|       |#ifndef NSS_DISABLE_LIBPKIX
  561|       |    PKIX_UInt32 actualMinorVersion = 0;
  562|       |    PKIX_Error *pkixError = NULL;
  563|       |#endif /* NSS_DISABLE_LIBPKIX */
  564|      1|    PRBool isReallyInitted;
  565|      1|    char *configStrings = NULL;
  566|      1|    char *configName = NULL;
  567|      1|    PRBool passwordRequired = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  568|       |#ifdef POLICY_FILE
  569|       |    char *ignoreVar;
  570|       |#endif
  571|       |
  572|       |    /* if we are trying to init with a traditional NSS_Init call, maintain
  573|       |     * the traditional idempotent behavior. */
  574|      1|    if (!initContextPtr && nssIsInitted) {
  ------------------
  |  Branch (574:9): [True: 1, False: 0]
  |  Branch (574:28): [True: 0, False: 1]
  ------------------
  575|      0|        return SECSuccess;
  576|      0|    }
  577|       |
  578|       |    /* make sure our lock and condition variable are initialized one and only
  579|       |     * one time */
  580|      1|    if (PR_CallOnce(&nssInitOnce, nss_doLockInit) != PR_SUCCESS) {
  ------------------
  |  Branch (580:9): [True: 0, False: 1]
  ------------------
  581|      0|        return SECFailure;
  582|      0|    }
  583|       |
  584|       |    /*
  585|       |     * if we haven't done basic initialization, single thread the
  586|       |     * initializations.
  587|       |     */
  588|      1|    PZ_Lock(nssInitLock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  589|      1|    isReallyInitted = NSS_IsInitialized();
  590|      1|    if (!isReallyInitted) {
  ------------------
  |  Branch (590:9): [True: 1, False: 0]
  ------------------
  591|      1|        while (!isReallyInitted && nssIsInInit) {
  ------------------
  |  Branch (591:16): [True: 1, False: 0]
  |  Branch (591:36): [True: 0, False: 1]
  ------------------
  592|      0|            PZ_WaitCondVar(nssInitCondition, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |  250|      0|#define PZ_WaitCondVar(v, t) PR_WaitCondVar((v), (t))
  ------------------
  593|      0|            isReallyInitted = NSS_IsInitialized();
  594|      0|        }
  595|       |        /* once we've completed basic initialization, we can allow more than
  596|       |         * one process initialize NSS at a time. */
  597|      1|    }
  598|      1|    nssIsInInit++;
  599|      1|    PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  600|       |
  601|       |    /* this tells us whether or not some library has already initialized us.
  602|       |     * if so, we don't want to double call some of the basic initialization
  603|       |     * functions */
  604|       |
  605|      1|    if (!isReallyInitted) {
  ------------------
  |  Branch (605:9): [True: 1, False: 0]
  ------------------
  606|      1|#ifdef DEBUG
  607|      1|        CERTCertificate dummyCert;
  608|       |        /* New option bits must not change the size of CERTCertificate. */
  609|      1|        PORT_Assert(sizeof(dummyCert.options) == sizeof(void *));
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  610|      1|#endif
  611|       |
  612|      1|        if (SECSuccess != cert_InitLocks()) {
  ------------------
  |  Branch (612:13): [True: 0, False: 1]
  ------------------
  613|      0|            goto loser;
  614|      0|        }
  615|       |
  616|      1|        if (SECSuccess != InitCRLCache()) {
  ------------------
  |  Branch (616:13): [True: 0, False: 1]
  ------------------
  617|      0|            goto loser;
  618|      0|        }
  619|       |
  620|      1|        if (SECSuccess != OCSP_InitGlobal()) {
  ------------------
  |  Branch (620:13): [True: 0, False: 1]
  ------------------
  621|      0|            goto loser;
  622|      0|        }
  623|      1|    }
  624|       |
  625|      1|    if (noSingleThreadedModules || allowAlreadyInitializedModules ||
  ------------------
  |  Branch (625:9): [True: 0, False: 1]
  |  Branch (625:36): [True: 0, False: 1]
  ------------------
  626|      1|        dontFinalizeModules) {
  ------------------
  |  Branch (626:9): [True: 0, False: 1]
  ------------------
  627|      0|        pk11_setGlobalOptions(noSingleThreadedModules,
  628|      0|                              allowAlreadyInitializedModules,
  629|      0|                              dontFinalizeModules);
  630|      0|    }
  631|       |
  632|      1|    if (initContextPtr) {
  ------------------
  |  Branch (632:9): [True: 0, False: 1]
  ------------------
  633|      0|        *initContextPtr = PORT_ZNew(NSSInitContext);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  634|      0|        if (*initContextPtr == NULL) {
  ------------------
  |  Branch (634:13): [True: 0, False: 0]
  ------------------
  635|      0|            goto loser;
  636|      0|        }
  637|       |        /*
  638|       |         * For traditional NSS_Init, we used the PK11_Configure() call to set
  639|       |         * globals. with InitContext, we pass those strings in as parameters.
  640|       |         *
  641|       |         * This allows old NSS_Init calls to work as before, while at the same
  642|       |         * time new calls and old calls will not interfere with each other.
  643|       |         */
  644|      0|        if (initParams) {
  ------------------
  |  Branch (644:13): [True: 0, False: 0]
  ------------------
  645|      0|            if (initParams->length < sizeof(NSSInitParameters)) {
  ------------------
  |  Branch (645:17): [True: 0, False: 0]
  ------------------
  646|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  647|      0|                goto loser;
  648|      0|            }
  649|      0|            configStrings = nss_MkConfigString(initParams->manufactureID,
  650|      0|                                               initParams->libraryDescription,
  651|      0|                                               initParams->cryptoTokenDescription,
  652|      0|                                               initParams->dbTokenDescription,
  653|      0|                                               initParams->cryptoSlotDescription,
  654|      0|                                               initParams->dbSlotDescription,
  655|      0|                                               initParams->FIPSSlotDescription,
  656|      0|                                               initParams->FIPSTokenDescription,
  657|      0|                                               initParams->minPWLen);
  658|      0|            if (configStrings == NULL) {
  ------------------
  |  Branch (658:17): [True: 0, False: 0]
  ------------------
  659|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  660|      0|                goto loser;
  661|      0|            }
  662|      0|            configName = initParams->libraryDescription;
  663|      0|            passwordRequired = initParams->passwordRequired;
  664|      0|        }
  665|       |
  666|       |        /* If we're NSS_ContextInit, we're probably a library. It could be
  667|       |         * possible that the application initialized NSS then forked(). The
  668|       |         * library would have no knowledge of that. If we call
  669|       |         * SECMOD_RestartModules() here, we will be able to continue on with
  670|       |         * NSS as normal. SECMOD_RestartModules() does have the side affect
  671|       |         * of losing all our PKCS #11 objects in the new process, but only if
  672|       |         * the module needs to be reinited. If it needs to be reinit those
  673|       |         * objects are inaccessible anyway, it's always save to call
  674|       |         * SECMOD_RestartModules(PR_FALSE).
  675|       |         */
  676|       |        /* NOTE: We could call SECMOD_Init() here, but if we aren't already
  677|       |         * inited, then there's no modules to restart, so SECMOD_RestartModules
  678|       |         * will return immediately */
  679|      0|        SECMOD_RestartModules(PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  680|      1|    } else {
  681|      1|        configStrings = pk11_config_strings;
  682|      1|        configName = pk11_config_name;
  683|      1|        passwordRequired = pk11_password_required;
  684|      1|    }
  685|       |
  686|       |    /* Skip the module init if we are already initted and we are trying
  687|       |     * to init with noCertDB and noModDB */
  688|      1|    if (!(isReallyInitted && noCertDB && noModDB)) {
  ------------------
  |  Branch (688:11): [True: 0, False: 1]
  |  Branch (688:30): [True: 0, False: 0]
  |  Branch (688:42): [True: 0, False: 0]
  ------------------
  689|      1|        parent = nss_InitModules(configdir, certPrefix, keyPrefix, secmodName,
  690|      1|                                 updateDir, updCertPrefix, updKeyPrefix, updateID,
  691|      1|                                 updateName, configName, configStrings, passwordRequired,
  692|      1|                                 readOnly, noCertDB, noModDB, forceOpen, optimizeSpace,
  693|      1|                                 (initContextPtr != NULL));
  694|       |
  695|      1|        if (parent == NULL) {
  ------------------
  |  Branch (695:13): [True: 0, False: 1]
  ------------------
  696|      0|            goto loser;
  697|      0|        }
  698|      1|    }
  699|       |
  700|       |    /* finish up initialization */
  701|      1|    if (!isReallyInitted) {
  ------------------
  |  Branch (701:9): [True: 1, False: 0]
  ------------------
  702|      1|        if (SECOID_Init() != SECSuccess) {
  ------------------
  |  Branch (702:13): [True: 0, False: 1]
  ------------------
  703|      0|            goto loser;
  704|      0|        }
  705|       |#ifdef POLICY_FILE
  706|       |        /* Load the system crypto policy file if it exists,
  707|       |         * unless the NSS_IGNORE_SYSTEM_POLICY environment
  708|       |         * variable has been set to 1. */
  709|       |        ignoreVar = PR_GetEnvSecure("NSS_IGNORE_SYSTEM_POLICY");
  710|       |        if (ignoreVar == NULL || strncmp(ignoreVar, "1", sizeof("1")) != 0) {
  711|       |            if (PR_Access(POLICY_PATH "/" POLICY_FILE, PR_ACCESS_READ_OK) == PR_SUCCESS) {
  712|       |                SECMODModule *module = SECMOD_LoadModule(
  713|       |                    "name=\"Policy File\" "
  714|       |                    "parameters=\"configdir='sql:" POLICY_PATH "' "
  715|       |                    "secmod='" POLICY_FILE "' "
  716|       |                    "flags=readOnly,noCertDB,forceSecmodChoice,forceOpen\" "
  717|       |                    "NSS=\"flags=internal,moduleDB,skipFirst,moduleDBOnly,critical\"",
  718|       |                    parent, PR_TRUE);
  719|       |                if (module) {
  720|       |                    PRBool isLoaded = module->loaded;
  721|       |                    SECMOD_DestroyModule(module);
  722|       |                    if (!isLoaded) {
  723|       |                        goto loser;
  724|       |                    }
  725|       |                }
  726|       |            }
  727|       |        }
  728|       |#endif
  729|      1|        if (STAN_LoadDefaultNSS3TrustDomain() != PR_SUCCESS) {
  ------------------
  |  Branch (729:13): [True: 0, False: 1]
  ------------------
  730|      0|            goto loser;
  731|      0|        }
  732|      1|        if (nss_InitShutdownList() != SECSuccess) {
  ------------------
  |  Branch (732:13): [True: 0, False: 1]
  ------------------
  733|      0|            goto loser;
  734|      0|        }
  735|      1|        CERT_SetDefaultCertDB((CERTCertDBHandle *)
  736|      1|                                  STAN_GetDefaultTrustDomain());
  737|      1|        if ((!noModDB) && (!noCertDB) && (!noRootInit)) {
  ------------------
  |  Branch (737:13): [True: 0, False: 1]
  |  Branch (737:27): [True: 0, False: 0]
  |  Branch (737:42): [True: 0, False: 0]
  ------------------
  738|      0|            if (!SECMOD_HasRootCerts()) {
  ------------------
  |  Branch (738:17): [True: 0, False: 0]
  ------------------
  739|      0|                const char *dbpath = configdir;
  740|       |                /* handle supported database modifiers */
  741|      0|                if (strncmp(dbpath, "sql:", 4) == 0) {
  ------------------
  |  Branch (741:21): [True: 0, False: 0]
  ------------------
  742|      0|                    dbpath += 4;
  743|      0|                } else if (strncmp(dbpath, "dbm:", 4) == 0) {
  ------------------
  |  Branch (743:28): [True: 0, False: 0]
  ------------------
  744|      0|                    dbpath += 4;
  745|      0|                } else if (strncmp(dbpath, "extern:", 7) == 0) {
  ------------------
  |  Branch (745:28): [True: 0, False: 0]
  ------------------
  746|      0|                    dbpath += 7;
  747|      0|                } else if (strncmp(dbpath, "rdb:", 4) == 0) {
  ------------------
  |  Branch (747:28): [True: 0, False: 0]
  ------------------
  748|       |                    /* if rdb: is specified, the configdir isn't really a
  749|       |                     * path. Skip it */
  750|      0|                    dbpath = NULL;
  751|      0|                }
  752|      0|                if (dbpath) {
  ------------------
  |  Branch (752:21): [True: 0, False: 0]
  ------------------
  753|      0|                    nss_FindExternalRoot(dbpath, secmodName);
  754|      0|                }
  755|      0|            }
  756|      0|        }
  757|      1|        pk11sdr_Init();
  758|      1|        cert_CreateSubjectKeyIDHashTable();
  759|       |
  760|       |#ifndef NSS_DISABLE_LIBPKIX
  761|       |        pkixError = PKIX_Initialize(PKIX_FALSE, PKIX_MAJOR_VERSION, PKIX_MINOR_VERSION,
  762|       |                                    PKIX_MINOR_VERSION, &actualMinorVersion, &plContext);
  763|       |
  764|       |        if (pkixError != NULL) {
  765|       |            goto loser;
  766|       |        } else {
  767|       |            char *ev = PR_GetEnvSecure("NSS_DISABLE_PKIX_VERIFY");
  768|       |            if (ev && ev[0]) {
  769|       |                CERT_SetUsePKIXForValidation(PR_FALSE);
  770|       |            }
  771|       |        }
  772|       |#endif /* NSS_DISABLE_LIBPKIX */
  773|      1|    }
  774|       |
  775|       |    /*
  776|       |     * Now mark the appropriate init state. If initContextPtr was passed
  777|       |     * in, then return the new context pointer and add it to the
  778|       |     * nssInitContextList. Otherwise set the global nss_isInitted flag
  779|       |     */
  780|      1|    PZ_Lock(nssInitLock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  781|      1|    if (!initContextPtr) {
  ------------------
  |  Branch (781:9): [True: 1, False: 0]
  ------------------
  782|      1|        nssIsInitted = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  783|      1|    } else {
  784|      0|        (*initContextPtr)->magic = NSS_INIT_MAGIC;
  ------------------
  |  |  523|      0|#define NSS_INIT_MAGIC 0x1413A91C
  ------------------
  785|      0|        (*initContextPtr)->next = nssInitContextList;
  786|      0|        nssInitContextList = (*initContextPtr);
  787|      0|    }
  788|      1|    nssIsInInit--;
  789|       |    /* now that we are inited, all waiters can move forward */
  790|      1|    PZ_NotifyAllCondVar(nssInitCondition);
  ------------------
  |  |  252|      1|#define PZ_NotifyAllCondVar(v) PR_NotifyAllCondVar((v))
  ------------------
  791|      1|    PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  792|       |
  793|      1|    if (initContextPtr && configStrings) {
  ------------------
  |  Branch (793:9): [True: 0, False: 1]
  |  Branch (793:27): [True: 0, False: 0]
  ------------------
  794|      0|        PR_smprintf_free(configStrings);
  795|      0|    }
  796|      1|    if (parent) {
  ------------------
  |  Branch (796:9): [True: 1, False: 0]
  ------------------
  797|      1|        SECMOD_DestroyModule(parent);
  798|      1|    }
  799|       |
  800|      1|    return SECSuccess;
  801|       |
  802|      0|loser:
  803|      0|    if (initContextPtr && *initContextPtr) {
  ------------------
  |  Branch (803:9): [True: 0, False: 0]
  |  Branch (803:27): [True: 0, False: 0]
  ------------------
  804|      0|        PORT_Free(*initContextPtr);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  805|      0|        *initContextPtr = NULL;
  806|      0|        if (configStrings) {
  ------------------
  |  Branch (806:13): [True: 0, False: 0]
  ------------------
  807|      0|            PR_smprintf_free(configStrings);
  808|      0|        }
  809|      0|    }
  810|      0|    PZ_Lock(nssInitLock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  811|      0|    nssIsInInit--;
  812|       |    /* We failed to init, allow one to move forward */
  813|      0|    PZ_NotifyCondVar(nssInitCondition);
  ------------------
  |  |  251|      0|#define PZ_NotifyCondVar(v) PR_NotifyCondVar((v))
  ------------------
  814|      0|    PZ_Unlock(nssInitLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  815|      0|    if (parent) {
  ------------------
  |  Branch (815:9): [True: 0, False: 0]
  ------------------
  816|      0|        SECMOD_DestroyModule(parent);
  817|      0|    }
  818|      0|    return SECFailure;
  819|      1|}
nssinit.c:nss_InitModules:
  366|      1|{
  367|      1|    SECMODModule *module = NULL;
  368|      1|    char *moduleSpec = NULL;
  369|      1|    char *flags = NULL;
  370|      1|    char *lconfigdir = NULL;
  371|      1|    char *lcertPrefix = NULL;
  372|      1|    char *lkeyPrefix = NULL;
  373|      1|    char *lsecmodName = NULL;
  374|      1|    char *lupdateDir = NULL;
  375|      1|    char *lupdCertPrefix = NULL;
  376|      1|    char *lupdKeyPrefix = NULL;
  377|      1|    char *lupdateID = NULL;
  378|      1|    char *lupdateName = NULL;
  379|       |
  380|      1|    if (NSS_InitializePRErrorTable() != SECSuccess) {
  ------------------
  |  Branch (380:9): [True: 0, False: 1]
  ------------------
  381|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  382|      0|        return NULL;
  383|      0|    }
  384|       |
  385|      1|    flags = nss_makeFlags(readOnly, noCertDB, noModDB, forceOpen,
  386|      1|                          pwRequired, optimizeSpace);
  387|      1|    if (flags == NULL)
  ------------------
  |  Branch (387:9): [True: 0, False: 1]
  ------------------
  388|      0|        return NULL;
  389|       |
  390|       |    /*
  391|       |     * configdir is double nested, and Windows uses the same character
  392|       |     * for file seps as we use for escapes! (sigh).
  393|       |     */
  394|      1|    lconfigdir = NSSUTIL_DoubleEscape(configdir, '\'', '\"');
  395|      1|    if (lconfigdir == NULL) {
  ------------------
  |  Branch (395:9): [True: 0, False: 1]
  ------------------
  396|      0|        goto loser;
  397|      0|    }
  398|      1|    lcertPrefix = NSSUTIL_DoubleEscape(certPrefix, '\'', '\"');
  399|      1|    if (lcertPrefix == NULL) {
  ------------------
  |  Branch (399:9): [True: 0, False: 1]
  ------------------
  400|      0|        goto loser;
  401|      0|    }
  402|      1|    lkeyPrefix = NSSUTIL_DoubleEscape(keyPrefix, '\'', '\"');
  403|      1|    if (lkeyPrefix == NULL) {
  ------------------
  |  Branch (403:9): [True: 0, False: 1]
  ------------------
  404|      0|        goto loser;
  405|      0|    }
  406|      1|    lsecmodName = NSSUTIL_DoubleEscape(secmodName, '\'', '\"');
  407|      1|    if (lsecmodName == NULL) {
  ------------------
  |  Branch (407:9): [True: 0, False: 1]
  ------------------
  408|      0|        goto loser;
  409|      0|    }
  410|      1|    lupdateDir = NSSUTIL_DoubleEscape(updateDir, '\'', '\"');
  411|      1|    if (lupdateDir == NULL) {
  ------------------
  |  Branch (411:9): [True: 0, False: 1]
  ------------------
  412|      0|        goto loser;
  413|      0|    }
  414|      1|    lupdCertPrefix = NSSUTIL_DoubleEscape(updCertPrefix, '\'', '\"');
  415|      1|    if (lupdCertPrefix == NULL) {
  ------------------
  |  Branch (415:9): [True: 0, False: 1]
  ------------------
  416|      0|        goto loser;
  417|      0|    }
  418|      1|    lupdKeyPrefix = NSSUTIL_DoubleEscape(updKeyPrefix, '\'', '\"');
  419|      1|    if (lupdKeyPrefix == NULL) {
  ------------------
  |  Branch (419:9): [True: 0, False: 1]
  ------------------
  420|      0|        goto loser;
  421|      0|    }
  422|      1|    lupdateID = NSSUTIL_DoubleEscape(updateID, '\'', '\"');
  423|      1|    if (lupdateID == NULL) {
  ------------------
  |  Branch (423:9): [True: 0, False: 1]
  ------------------
  424|      0|        goto loser;
  425|      0|    }
  426|      1|    lupdateName = NSSUTIL_DoubleEscape(updateName, '\'', '\"');
  427|      1|    if (lupdateName == NULL) {
  ------------------
  |  Branch (427:9): [True: 0, False: 1]
  ------------------
  428|      0|        goto loser;
  429|      0|    }
  430|       |
  431|      1|    moduleSpec = PR_smprintf(
  432|      1|        "name=\"%s\" parameters=\"configdir='%s' certPrefix='%s' keyPrefix='%s' "
  433|      1|        "secmod='%s' flags=%s updatedir='%s' updateCertPrefix='%s' "
  434|      1|        "updateKeyPrefix='%s' updateid='%s' updateTokenDescription='%s' %s\" "
  435|      1|        "NSS=\"flags=internal,moduleDB,moduleDBOnly,critical%s\"",
  436|      1|        configName ? configName : NSS_DEFAULT_MOD_NAME,
  ------------------
  |  |   58|      1|#define NSS_DEFAULT_MOD_NAME "NSS Internal Module"
  ------------------
  |  Branch (436:9): [True: 0, False: 1]
  ------------------
  437|      1|        lconfigdir, lcertPrefix, lkeyPrefix, lsecmodName, flags,
  438|      1|        lupdateDir, lupdCertPrefix, lupdKeyPrefix, lupdateID,
  439|      1|        lupdateName, configStrings ? configStrings : "",
  ------------------
  |  Branch (439:22): [True: 0, False: 1]
  ------------------
  440|      1|        isContextInit ? "" : ",defaultModDB,internalKeySlot");
  ------------------
  |  Branch (440:9): [True: 0, False: 1]
  ------------------
  441|       |
  442|      1|loser:
  443|      1|    PORT_Free(flags);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  444|      1|    if (lconfigdir)
  ------------------
  |  Branch (444:9): [True: 1, False: 0]
  ------------------
  445|      1|        PORT_Free(lconfigdir);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  446|      1|    if (lcertPrefix)
  ------------------
  |  Branch (446:9): [True: 1, False: 0]
  ------------------
  447|      1|        PORT_Free(lcertPrefix);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  448|      1|    if (lkeyPrefix)
  ------------------
  |  Branch (448:9): [True: 1, False: 0]
  ------------------
  449|      1|        PORT_Free(lkeyPrefix);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  450|      1|    if (lsecmodName)
  ------------------
  |  Branch (450:9): [True: 1, False: 0]
  ------------------
  451|      1|        PORT_Free(lsecmodName);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  452|      1|    if (lupdateDir)
  ------------------
  |  Branch (452:9): [True: 1, False: 0]
  ------------------
  453|      1|        PORT_Free(lupdateDir);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  454|      1|    if (lupdCertPrefix)
  ------------------
  |  Branch (454:9): [True: 1, False: 0]
  ------------------
  455|      1|        PORT_Free(lupdCertPrefix);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  456|      1|    if (lupdKeyPrefix)
  ------------------
  |  Branch (456:9): [True: 1, False: 0]
  ------------------
  457|      1|        PORT_Free(lupdKeyPrefix);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  458|      1|    if (lupdateID)
  ------------------
  |  Branch (458:9): [True: 1, False: 0]
  ------------------
  459|      1|        PORT_Free(lupdateID);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  460|      1|    if (lupdateName)
  ------------------
  |  Branch (460:9): [True: 1, False: 0]
  ------------------
  461|      1|        PORT_Free(lupdateName);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  462|       |
  463|      1|    if (moduleSpec) {
  ------------------
  |  Branch (463:9): [True: 1, False: 0]
  ------------------
  464|      1|        module = SECMOD_LoadModule(moduleSpec, NULL, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  465|      1|        PR_smprintf_free(moduleSpec);
  466|      1|        if (module && !module->loaded) {
  ------------------
  |  Branch (466:13): [True: 1, False: 0]
  |  Branch (466:23): [True: 0, False: 1]
  ------------------
  467|      0|            SECMOD_DestroyModule(module);
  468|      0|            return NULL;
  469|      0|        }
  470|      1|    }
  471|      1|    return module;
  472|      1|}
nssinit.c:nss_makeFlags:
   64|      1|{
   65|      1|    char *flags = (char *)PORT_Alloc(NSS_MAX_FLAG_SIZE);
  ------------------
  |  |   52|      1|#define PORT_Alloc PORT_Alloc_Util
  ------------------
                  char *flags = (char *)PORT_Alloc(NSS_MAX_FLAG_SIZE);
  ------------------
  |  |   55|      1|#define NSS_MAX_FLAG_SIZE sizeof("readOnly") + sizeof("noCertDB") +                                  \
  |  |   56|      1|                              sizeof("noModDB") + sizeof("forceOpen") + sizeof("passwordRequired") + \
  |  |   57|      1|                              sizeof("optimizeSpace") + sizeof("printPolicyFeedback")
  ------------------
   66|      1|    PRBool first = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
   67|       |
   68|      1|    PORT_Memset(flags, 0, NSS_MAX_FLAG_SIZE);
  ------------------
  |  |  182|      1|#define PORT_Memset memset
  ------------------
                  PORT_Memset(flags, 0, NSS_MAX_FLAG_SIZE);
  ------------------
  |  |   55|      1|#define NSS_MAX_FLAG_SIZE sizeof("readOnly") + sizeof("noCertDB") +                                  \
  |  |   56|      1|                              sizeof("noModDB") + sizeof("forceOpen") + sizeof("passwordRequired") + \
  |  |   57|      1|                              sizeof("optimizeSpace") + sizeof("printPolicyFeedback")
  ------------------
   69|      1|    if (readOnly) {
  ------------------
  |  Branch (69:9): [True: 1, False: 0]
  ------------------
   70|      1|        PORT_Strcat(flags, "readOnly");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   71|      1|        first = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   72|      1|    }
   73|      1|    if (noCertDB) {
  ------------------
  |  Branch (73:9): [True: 1, False: 0]
  ------------------
   74|      1|        if (!first)
  ------------------
  |  Branch (74:13): [True: 1, False: 0]
  ------------------
   75|      1|            PORT_Strcat(flags, ",");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   76|      1|        PORT_Strcat(flags, "noCertDB");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   77|      1|        first = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   78|      1|    }
   79|      1|    if (noModDB) {
  ------------------
  |  Branch (79:9): [True: 1, False: 0]
  ------------------
   80|      1|        if (!first)
  ------------------
  |  Branch (80:13): [True: 1, False: 0]
  ------------------
   81|      1|            PORT_Strcat(flags, ",");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   82|      1|        PORT_Strcat(flags, "noModDB");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   83|      1|        first = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   84|      1|    }
   85|      1|    if (forceOpen) {
  ------------------
  |  Branch (85:9): [True: 1, False: 0]
  ------------------
   86|      1|        if (!first)
  ------------------
  |  Branch (86:13): [True: 1, False: 0]
  ------------------
   87|      1|            PORT_Strcat(flags, ",");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   88|      1|        PORT_Strcat(flags, "forceOpen");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
   89|      1|        first = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   90|      1|    }
   91|      1|    if (passwordRequired) {
  ------------------
  |  Branch (91:9): [True: 0, False: 1]
  ------------------
   92|      0|        if (!first)
  ------------------
  |  Branch (92:13): [True: 0, False: 0]
  ------------------
   93|      0|            PORT_Strcat(flags, ",");
  ------------------
  |  |  185|      0|#define PORT_Strcat strcat
  ------------------
   94|      0|        PORT_Strcat(flags, "passwordRequired");
  ------------------
  |  |  185|      0|#define PORT_Strcat strcat
  ------------------
   95|      0|        first = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   96|      0|    }
   97|      1|    if (optimizeSpace) {
  ------------------
  |  Branch (97:9): [True: 1, False: 0]
  ------------------
   98|      1|        if (!first)
  ------------------
  |  Branch (98:13): [True: 1, False: 0]
  ------------------
   99|      1|            PORT_Strcat(flags, ",");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
  100|      1|        PORT_Strcat(flags, "optimizeSpace");
  ------------------
  |  |  185|      1|#define PORT_Strcat strcat
  ------------------
  101|      1|    }
  102|      1|    return flags;
  103|      1|}
nssinit.c:nss_InitShutdownList:
 1091|      1|{
 1092|      1|    if (nssShutdownList.lock != NULL) {
  ------------------
  |  Branch (1092:9): [True: 0, False: 1]
  ------------------
 1093|      0|        return SECSuccess;
 1094|      0|    }
 1095|      1|    nssShutdownList.lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 1096|      1|    if (nssShutdownList.lock == NULL) {
  ------------------
  |  Branch (1096:9): [True: 0, False: 1]
  ------------------
 1097|      0|        return SECFailure;
 1098|      0|    }
 1099|      1|    nssShutdownList.funcs = PORT_ZNewArray(struct NSSShutdownFuncPair,
  ------------------
  |  |  159|      1|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|      1|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1100|      1|                                           NSS_SHUTDOWN_STEP);
 1101|      1|    if (nssShutdownList.funcs == NULL) {
  ------------------
  |  Branch (1101:9): [True: 0, False: 1]
  ------------------
 1102|      0|        PZ_DestroyLock(nssShutdownList.lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1103|      0|        nssShutdownList.lock = NULL;
 1104|      0|        return SECFailure;
 1105|      0|    }
 1106|      1|    nssShutdownList.allocatedFuncs = NSS_SHUTDOWN_STEP;
  ------------------
  |  |  955|      1|#define NSS_SHUTDOWN_STEP 10
  ------------------
 1107|      1|    nssShutdownList.peakFuncs = 0;
 1108|       |
 1109|      1|    return SECSuccess;
 1110|      1|}
nssinit.c:nss_doLockInit:
  534|      1|{
  535|      1|    nssInitLock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  536|      1|    if (nssInitLock == NULL) {
  ------------------
  |  Branch (536:9): [True: 0, False: 1]
  ------------------
  537|      0|        return PR_FAILURE;
  538|      0|    }
  539|      1|    nssInitCondition = PZ_NewCondVar(nssInitLock);
  ------------------
  |  |  248|      1|#define PZ_NewCondVar(l) PR_NewCondVar((l))
  ------------------
  540|      1|    if (nssInitCondition == NULL) {
  ------------------
  |  Branch (540:9): [True: 0, False: 1]
  ------------------
  541|      0|        return PR_FAILURE;
  542|      0|    }
  543|      1|    return PR_SUCCESS;
  544|      1|}
nssinit.c:nss_GetShutdownEntry:
  974|      8|{
  975|      8|    int count, i;
  976|      8|    count = nssShutdownList.peakFuncs;
  977|       |
  978|     20|    for (i = 0; i < count; i++) {
  ------------------
  |  Branch (978:17): [True: 12, False: 8]
  ------------------
  979|     12|        if ((nssShutdownList.funcs[i].func == sFunc) &&
  ------------------
  |  Branch (979:13): [True: 0, False: 12]
  ------------------
  980|     12|            (nssShutdownList.funcs[i].appData == appData)) {
  ------------------
  |  Branch (980:13): [True: 0, False: 0]
  ------------------
  981|      0|            return i;
  982|      0|        }
  983|     12|    }
  984|      8|    return -1;
  985|      8|}
nssinit.c:nss_ShutdownShutdownList:
 1114|      1|{
 1115|      1|    SECStatus rv = SECSuccess;
 1116|      1|    int i;
 1117|       |
 1118|       |    /* call all the registerd functions first */
 1119|      5|    for (i = 0; i < nssShutdownList.peakFuncs; i++) {
  ------------------
  |  Branch (1119:17): [True: 4, False: 1]
  ------------------
 1120|      4|        struct NSSShutdownFuncPair *funcPair = &nssShutdownList.funcs[i];
 1121|      4|        if (funcPair->func) {
  ------------------
  |  Branch (1121:13): [True: 4, False: 0]
  ------------------
 1122|      4|            if ((*funcPair->func)(funcPair->appData, NULL) != SECSuccess) {
  ------------------
  |  Branch (1122:17): [True: 0, False: 4]
  ------------------
 1123|      0|                rv = SECFailure;
 1124|      0|            }
 1125|      4|        }
 1126|      4|    }
 1127|       |
 1128|      1|    nssShutdownList.peakFuncs = 0;
 1129|      1|    nssShutdownList.allocatedFuncs = 0;
 1130|      1|    PORT_Free(nssShutdownList.funcs);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
 1131|      1|    nssShutdownList.funcs = NULL;
 1132|      1|    if (nssShutdownList.lock) {
  ------------------
  |  Branch (1132:9): [True: 1, False: 0]
  ------------------
 1133|      1|        PZ_DestroyLock(nssShutdownList.lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1134|      1|    }
 1135|      1|    nssShutdownList.lock = NULL;
 1136|      1|    return rv;
 1137|      1|}

NSS_OptionGet:
  107|   819k|{
  108|   819k|    SECStatus rv = SECSuccess;
  109|       |
  110|   819k|    switch (which) {
  111|  38.5k|        case NSS_RSA_MIN_KEY_SIZE:
  ------------------
  |  |  286|  38.5k|#define NSS_RSA_MIN_KEY_SIZE 0x001
  ------------------
  |  Branch (111:9): [True: 38.5k, False: 780k]
  ------------------
  112|  38.5k|            *value = nss_ops.rsaMinKeySize;
  113|  38.5k|            break;
  114|  28.5k|        case NSS_DH_MIN_KEY_SIZE:
  ------------------
  |  |  287|  28.5k|#define NSS_DH_MIN_KEY_SIZE 0x002
  ------------------
  |  Branch (114:9): [True: 28.5k, False: 790k]
  ------------------
  115|  28.5k|            *value = nss_ops.dhMinKeySize;
  116|  28.5k|            break;
  117|      0|        case NSS_DSA_MIN_KEY_SIZE:
  ------------------
  |  |  288|      0|#define NSS_DSA_MIN_KEY_SIZE 0x004
  ------------------
  |  Branch (117:9): [True: 0, False: 819k]
  ------------------
  118|      0|            *value = nss_ops.dsaMinKeySize;
  119|      0|            break;
  120|      0|        case NSS_TLS_VERSION_MIN_POLICY:
  ------------------
  |  |  289|      0|#define NSS_TLS_VERSION_MIN_POLICY 0x008
  ------------------
  |  Branch (120:9): [True: 0, False: 819k]
  ------------------
  121|      0|            *value = nss_ops.tlsVersionMinPolicy;
  122|      0|            break;
  123|      0|        case NSS_TLS_VERSION_MAX_POLICY:
  ------------------
  |  |  290|      0|#define NSS_TLS_VERSION_MAX_POLICY 0x009
  ------------------
  |  Branch (123:9): [True: 0, False: 819k]
  ------------------
  124|      0|            *value = nss_ops.tlsVersionMaxPolicy;
  125|      0|            break;
  126|      0|        case NSS_DTLS_VERSION_MIN_POLICY:
  ------------------
  |  |  291|      0|#define NSS_DTLS_VERSION_MIN_POLICY 0x00a
  ------------------
  |  Branch (126:9): [True: 0, False: 819k]
  ------------------
  127|      0|            *value = nss_ops.dtlsVersionMinPolicy;
  128|      0|            break;
  129|      0|        case NSS_DTLS_VERSION_MAX_POLICY:
  ------------------
  |  |  292|      0|#define NSS_DTLS_VERSION_MAX_POLICY 0x00b
  ------------------
  |  Branch (129:9): [True: 0, False: 819k]
  ------------------
  130|      0|            *value = nss_ops.dtlsVersionMaxPolicy;
  131|      0|            break;
  132|      0|        case __NSS_PKCS12_DECODE_FORCE_UNICODE:
  ------------------
  |  |  301|      0|#define __NSS_PKCS12_DECODE_FORCE_UNICODE 0x00c
  ------------------
  |  Branch (132:9): [True: 0, False: 819k]
  ------------------
  133|      0|            *value = nss_ops.pkcs12DecodeForceUnicode;
  134|      0|            break;
  135|   690k|        case NSS_DEFAULT_LOCKS:
  ------------------
  |  |  302|   690k|#define NSS_DEFAULT_LOCKS 0x00d /* lock default values */
  ------------------
  |  Branch (135:9): [True: 690k, False: 129k]
  ------------------
  136|   690k|            *value = nss_ops.defaultLocks;
  137|   690k|            break;
  138|  50.2k|        case NSS_KEY_SIZE_POLICY_FLAGS:
  ------------------
  |  |  317|  50.2k|#define NSS_KEY_SIZE_POLICY_FLAGS 0x00e
  ------------------
  |  Branch (138:9): [True: 50.2k, False: 768k]
  ------------------
  139|  50.2k|        case NSS_KEY_SIZE_POLICY_SET_FLAGS:
  ------------------
  |  |  318|  50.2k|#define NSS_KEY_SIZE_POLICY_SET_FLAGS 0x00f
  ------------------
  |  Branch (139:9): [True: 0, False: 819k]
  ------------------
  140|  50.2k|            *value = nss_ops.keySizePolicyFlags;
  141|  50.2k|            break;
  142|      0|        case NSS_KEY_SIZE_POLICY_CLEAR_FLAGS:
  ------------------
  |  |  319|      0|#define NSS_KEY_SIZE_POLICY_CLEAR_FLAGS 0x010
  ------------------
  |  Branch (142:9): [True: 0, False: 819k]
  ------------------
  143|      0|            *value = ~nss_ops.keySizePolicyFlags;
  144|      0|            break;
  145|  11.7k|        case NSS_ECC_MIN_KEY_SIZE:
  ------------------
  |  |  327|  11.7k|#define NSS_ECC_MIN_KEY_SIZE 0x011
  ------------------
  |  Branch (145:9): [True: 11.7k, False: 807k]
  ------------------
  146|  11.7k|            *value = nss_ops.eccMinKeySize;
  147|  11.7k|            break;
  148|      0|        default:
  ------------------
  |  Branch (148:9): [True: 0, False: 819k]
  ------------------
  149|      0|            rv = SECFailure;
  150|   819k|    }
  151|       |
  152|   819k|    return rv;
  153|   819k|}

nssSession_ImportNSS3Session:
   29|      2|{
   30|      2|    nssSession *rvSession = NULL;
   31|      2|    if (session != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (31:9): [True: 2, False: 0]
  ------------------
   32|      2|        rvSession = nss_ZNEW(arenaOpt, nssSession);
  ------------------
  |  |  348|      2|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   33|      2|        if (rvSession) {
  ------------------
  |  Branch (33:13): [True: 2, False: 0]
  ------------------
   34|      2|            rvSession->handle = session;
   35|      2|            rvSession->lock = lock;
   36|      2|            rvSession->ownLock = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   37|      2|            rvSession->isRW = rw;
   38|      2|        }
   39|      2|    }
   40|      2|    return rvSession;
   41|      2|}
nssToken_CreateFromPK11SlotInfo:
  132|      2|{
  133|      2|    NSSToken *rvToken;
  134|      2|    NSSArena *arena;
  135|       |
  136|       |    /* Don't create a token object for a disabled slot */
  137|      2|    if (nss3slot->disabled) {
  ------------------
  |  Branch (137:9): [True: 0, False: 2]
  ------------------
  138|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  139|      0|        return NULL;
  140|      0|    }
  141|      2|    arena = nssArena_Create();
  142|      2|    if (!arena) {
  ------------------
  |  Branch (142:9): [True: 0, False: 2]
  ------------------
  143|      0|        return NULL;
  144|      0|    }
  145|      2|    rvToken = nss_ZNEW(arena, NSSToken);
  ------------------
  |  |  348|      2|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  146|      2|    if (!rvToken) {
  ------------------
  |  Branch (146:9): [True: 0, False: 2]
  ------------------
  147|      0|        nssArena_Destroy(arena);
  148|      0|        return NULL;
  149|      0|    }
  150|      2|    rvToken->base.refCount = 1;
  151|      2|    rvToken->base.lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  152|      2|    if (!rvToken->base.lock) {
  ------------------
  |  Branch (152:9): [True: 0, False: 2]
  ------------------
  153|      0|        nssArena_Destroy(arena);
  154|      0|        return NULL;
  155|      0|    }
  156|      2|    rvToken->base.arena = arena;
  157|      2|    rvToken->pk11slot = PK11_ReferenceSlot(nss3slot);
  158|      2|    rvToken->epv = nss3slot->functionList;
  159|      2|    rvToken->defaultSession = nssSession_ImportNSS3Session(td->arena,
  160|      2|                                                           nss3slot->session,
  161|      2|                                                           nss3slot->sessionLock,
  162|      2|                                                           nss3slot->defRWSession);
  163|       |#if 0 /* we should do this instead of blindly continuing. */
  164|       |    if (!rvToken->defaultSession) {
  165|       |    PORT_SetError(SEC_ERROR_NO_TOKEN);
  166|       |        goto loser;
  167|       |    }
  168|       |#endif
  169|      2|    if (!PK11_IsInternal(nss3slot) && PK11_IsHW(nss3slot)) {
  ------------------
  |  Branch (169:9): [True: 0, False: 2]
  |  Branch (169:39): [True: 0, False: 0]
  ------------------
  170|      0|        rvToken->cache = nssTokenObjectCache_Create(rvToken,
  171|      0|                                                    PR_TRUE, PR_TRUE, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                                                                  PR_TRUE, PR_TRUE, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                                                                  PR_TRUE, PR_TRUE, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  172|      0|        if (!rvToken->cache)
  ------------------
  |  Branch (172:13): [True: 0, False: 0]
  ------------------
  173|      0|            goto loser;
  174|      0|    }
  175|      2|    rvToken->trustDomain = td;
  176|       |    /* Grab the token name from the PKCS#11 fixed-length buffer */
  177|      2|    rvToken->base.name = nssUTF8_Duplicate(nss3slot->token_name, td->arena);
  178|      2|    rvToken->slot = nssSlot_CreateFromPK11SlotInfo(td, nss3slot);
  179|      2|    if (!rvToken->slot) {
  ------------------
  |  Branch (179:9): [True: 0, False: 2]
  ------------------
  180|      0|        goto loser;
  181|      0|    }
  182|      2|    if (rvToken->defaultSession)
  ------------------
  |  Branch (182:9): [True: 2, False: 0]
  ------------------
  183|      2|        rvToken->defaultSession->slot = rvToken->slot;
  184|      2|    return rvToken;
  185|      0|loser:
  186|      0|    PZ_DestroyLock(rvToken->base.lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  187|      0|    nssArena_Destroy(arena);
  188|      0|    return NULL;
  189|      2|}
nssToken_UpdateName:
  193|      2|{
  194|      2|    if (!token) {
  ------------------
  |  Branch (194:9): [True: 2, False: 0]
  ------------------
  195|      2|        return;
  196|      2|    }
  197|      0|    token->base.name = nssUTF8_Duplicate(token->pk11slot->token_name, token->base.arena);
  198|      0|}
nssSlot_IsPermanent:
  202|  23.4k|{
  203|  23.4k|    return slot->pk11slot->isPerm;
  204|  23.4k|}
nssToken_Refresh:
  214|      2|{
  215|      2|    PK11SlotInfo *nss3slot;
  216|       |
  217|      2|    if (!token) {
  ------------------
  |  Branch (217:9): [True: 2, False: 0]
  ------------------
  218|      2|        return PR_SUCCESS;
  219|      2|    }
  220|      0|    nss3slot = token->pk11slot;
  221|      0|    token->defaultSession =
  222|      0|        nssSession_ImportNSS3Session(token->slot->base.arena,
  223|      0|                                     nss3slot->session,
  224|      0|                                     nss3slot->sessionLock,
  225|      0|                                     nss3slot->defRWSession);
  226|      0|    return token->defaultSession ? PR_SUCCESS : PR_FAILURE;
  ------------------
  |  Branch (226:12): [True: 0, False: 0]
  ------------------
  227|      2|}
dev3hack.c:nssSlot_CreateFromPK11SlotInfo:
  102|      2|{
  103|      2|    NSSSlot *rvSlot;
  104|      2|    NSSArena *arena;
  105|      2|    arena = nssArena_Create();
  106|      2|    if (!arena) {
  ------------------
  |  Branch (106:9): [True: 0, False: 2]
  ------------------
  107|      0|        return NULL;
  108|      0|    }
  109|      2|    rvSlot = nss_ZNEW(arena, NSSSlot);
  ------------------
  |  |  348|      2|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  110|      2|    if (!rvSlot) {
  ------------------
  |  Branch (110:9): [True: 0, False: 2]
  ------------------
  111|      0|        nssArena_Destroy(arena);
  112|      0|        return NULL;
  113|      0|    }
  114|      2|    rvSlot->base.refCount = 1;
  115|      2|    rvSlot->base.lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  116|      2|    rvSlot->base.arena = arena;
  117|      2|    rvSlot->pk11slot = PK11_ReferenceSlot(nss3slot);
  118|      2|    rvSlot->epv = nss3slot->functionList;
  119|      2|    rvSlot->slotID = nss3slot->slotID;
  120|       |    /* Grab the slot name from the PKCS#11 fixed-length buffer */
  121|      2|    rvSlot->base.name = nssUTF8_Duplicate(nss3slot->slot_name, td->arena);
  122|      2|    rvSlot->lock = (nss3slot->isThreadSafe) ? NULL : nss3slot->sessionLock;
  ------------------
  |  Branch (122:20): [True: 2, False: 0]
  ------------------
  123|      2|    rvSlot->isPresentLock = PZ_NewLock(nssiLockOther);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  124|      2|    rvSlot->isPresentCondition = PR_NewCondVar(rvSlot->isPresentLock);
  125|      2|    rvSlot->isPresentThread = NULL;
  126|      2|    rvSlot->lastTokenPingState = nssSlotLastPingState_Reset;
  127|      2|    return rvSlot;
  128|      2|}

PK11_ImportPublicKey:
   72|  3.11k|{
   73|  3.11k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  3.11k|#define CK_TRUE 1
  ------------------
   74|  3.11k|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  3.11k|#define CK_FALSE 0
  ------------------
   75|  3.11k|    CK_OBJECT_CLASS keyClass = CKO_PUBLIC_KEY;
  ------------------
  |  |  327|  3.11k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
   76|  3.11k|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  3.11k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
   77|  3.11k|    CK_OBJECT_HANDLE objectID;
   78|  3.11k|    CK_ATTRIBUTE theTemplate[11];
   79|  3.11k|    CK_ATTRIBUTE *signedattr = NULL;
   80|  3.11k|    CK_ATTRIBUTE *attrs = theTemplate;
   81|  3.11k|    CK_NSS_KEM_PARAMETER_SET_TYPE kemParams;
   82|  3.11k|    SECItem *ckaId = NULL;
   83|  3.11k|    SECItem *pubValue = NULL;
   84|  3.11k|    int signedcount = 0;
   85|  3.11k|    unsigned int templateCount = 0;
   86|  3.11k|    SECStatus rv;
   87|       |
   88|       |    /* if we already have an object in the desired slot, use it */
   89|  3.11k|    if (!isToken && pubKey->pkcs11Slot == slot) {
  ------------------
  |  Branch (89:9): [True: 3.11k, False: 0]
  |  Branch (89:21): [True: 1, False: 3.11k]
  ------------------
   90|      1|        return pubKey->pkcs11ID;
   91|      1|    }
   92|       |
   93|       |    /* free the existing key */
   94|  3.11k|    if (pubKey->pkcs11Slot != NULL) {
  ------------------
  |  Branch (94:9): [True: 0, False: 3.11k]
  ------------------
   95|      0|        PK11SlotInfo *oSlot = pubKey->pkcs11Slot;
   96|      0|        if (!PK11_IsPermObject(pubKey->pkcs11Slot, pubKey->pkcs11ID)) {
  ------------------
  |  Branch (96:13): [True: 0, False: 0]
  ------------------
   97|      0|            PK11_EnterSlotMonitor(oSlot);
   98|      0|            (void)PK11_GETTAB(oSlot)->C_DestroyObject(oSlot->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
   99|      0|                                                      pubKey->pkcs11ID);
  100|      0|            PK11_ExitSlotMonitor(oSlot);
  101|      0|        }
  102|      0|        PK11_FreeSlot(oSlot);
  103|      0|        pubKey->pkcs11Slot = NULL;
  104|      0|    }
  105|  3.11k|    PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|  3.11k|    (x)->type = (id);              \
  |  |  105|  3.11k|    (x)->pValue = (v);             \
  |  |  106|  3.11k|    (x)->ulValueLen = (l);
  ------------------
  106|  3.11k|    attrs++;
  107|  3.11k|    PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|  3.11k|    (x)->type = (id);              \
  |  |  105|  3.11k|    (x)->pValue = (v);             \
  |  |  106|  3.11k|    (x)->ulValueLen = (l);
  ------------------
  108|  3.11k|    attrs++;
  109|  3.11k|    PK11_SETATTRS(attrs, CKA_TOKEN, isToken ? &cktrue : &ckfalse,
  ------------------
  |  |  104|  3.11k|    (x)->type = (id);              \
  |  |  105|  6.22k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 3.11k]
  |  |  ------------------
  |  |  106|  3.11k|    (x)->ulValueLen = (l);
  ------------------
  110|  3.11k|                  sizeof(CK_BBOOL));
  111|  3.11k|    attrs++;
  112|  3.11k|    if (isToken) {
  ------------------
  |  Branch (112:9): [True: 0, False: 3.11k]
  ------------------
  113|      0|        ckaId = pk11_MakeIDFromPublicKey(pubKey);
  114|      0|        if (ckaId == NULL) {
  ------------------
  |  Branch (114:13): [True: 0, False: 0]
  ------------------
  115|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  116|      0|            return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  117|      0|        }
  118|      0|        PK11_SETATTRS(attrs, CKA_ID, ckaId->data, ckaId->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  119|      0|        attrs++;
  120|      0|    }
  121|       |
  122|       |    /* now import the key */
  123|  3.11k|    {
  124|  3.11k|        switch (pubKey->keyType) {
  125|  3.01k|            case rsaKey:
  ------------------
  |  Branch (125:13): [True: 3.01k, False: 99]
  ------------------
  126|  3.01k|                keyType = CKK_RSA;
  ------------------
  |  |  372|  3.01k|#define CKK_RSA 0x00000000UL
  ------------------
  127|  3.01k|                PK11_SETATTRS(attrs, CKA_WRAP, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|  3.01k|    (x)->type = (id);              \
  |  |  105|  3.01k|    (x)->pValue = (v);             \
  |  |  106|  3.01k|    (x)->ulValueLen = (l);
  ------------------
  128|  3.01k|                attrs++;
  129|  3.01k|                PK11_SETATTRS(attrs, CKA_ENCRYPT, &cktrue,
  ------------------
  |  |  104|  3.01k|    (x)->type = (id);              \
  |  |  105|  3.01k|    (x)->pValue = (v);             \
  |  |  106|  3.01k|    (x)->ulValueLen = (l);
  ------------------
  130|  3.01k|                              sizeof(CK_BBOOL));
  131|  3.01k|                attrs++;
  132|  3.01k|                PK11_SETATTRS(attrs, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|  3.01k|    (x)->type = (id);              \
  |  |  105|  3.01k|    (x)->pValue = (v);             \
  |  |  106|  3.01k|    (x)->ulValueLen = (l);
  ------------------
  133|  3.01k|                attrs++;
  134|  3.01k|                signedattr = attrs;
  135|  3.01k|                PK11_SETATTRS(attrs, CKA_MODULUS, pubKey->u.rsa.modulus.data,
  ------------------
  |  |  104|  3.01k|    (x)->type = (id);              \
  |  |  105|  3.01k|    (x)->pValue = (v);             \
  |  |  106|  3.01k|    (x)->ulValueLen = (l);
  ------------------
  136|  3.01k|                              pubKey->u.rsa.modulus.len);
  137|  3.01k|                attrs++;
  138|  3.01k|                PK11_SETATTRS(attrs, CKA_PUBLIC_EXPONENT,
  ------------------
  |  |  104|  3.01k|    (x)->type = (id);              \
  |  |  105|  3.01k|    (x)->pValue = (v);             \
  |  |  106|  3.01k|    (x)->ulValueLen = (l);
  ------------------
  139|  3.01k|                              pubKey->u.rsa.publicExponent.data,
  140|  3.01k|                              pubKey->u.rsa.publicExponent.len);
  141|  3.01k|                attrs++;
  142|  3.01k|                break;
  143|      0|            case dsaKey:
  ------------------
  |  Branch (143:13): [True: 0, False: 3.11k]
  ------------------
  144|      0|                keyType = CKK_DSA;
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  145|      0|                PK11_SETATTRS(attrs, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  146|      0|                attrs++;
  147|      0|                signedattr = attrs;
  148|      0|                PK11_SETATTRS(attrs, CKA_PRIME, pubKey->u.dsa.params.prime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  149|      0|                              pubKey->u.dsa.params.prime.len);
  150|      0|                attrs++;
  151|      0|                PK11_SETATTRS(attrs, CKA_SUBPRIME, pubKey->u.dsa.params.subPrime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  152|      0|                              pubKey->u.dsa.params.subPrime.len);
  153|      0|                attrs++;
  154|      0|                PK11_SETATTRS(attrs, CKA_BASE, pubKey->u.dsa.params.base.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  155|      0|                              pubKey->u.dsa.params.base.len);
  156|      0|                attrs++;
  157|      0|                PK11_SETATTRS(attrs, CKA_VALUE, pubKey->u.dsa.publicValue.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  158|      0|                              pubKey->u.dsa.publicValue.len);
  159|      0|                attrs++;
  160|      0|                break;
  161|      0|            case fortezzaKey:
  ------------------
  |  Branch (161:13): [True: 0, False: 3.11k]
  ------------------
  162|      0|                keyType = CKK_DSA;
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  163|      0|                PK11_SETATTRS(attrs, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  164|      0|                attrs++;
  165|      0|                signedattr = attrs;
  166|      0|                PK11_SETATTRS(attrs, CKA_PRIME, pubKey->u.fortezza.params.prime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  167|      0|                              pubKey->u.fortezza.params.prime.len);
  168|      0|                attrs++;
  169|      0|                PK11_SETATTRS(attrs, CKA_SUBPRIME,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  170|      0|                              pubKey->u.fortezza.params.subPrime.data,
  171|      0|                              pubKey->u.fortezza.params.subPrime.len);
  172|      0|                attrs++;
  173|      0|                PK11_SETATTRS(attrs, CKA_BASE, pubKey->u.fortezza.params.base.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  174|      0|                              pubKey->u.fortezza.params.base.len);
  175|      0|                attrs++;
  176|      0|                PK11_SETATTRS(attrs, CKA_VALUE, pubKey->u.fortezza.DSSKey.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  177|      0|                              pubKey->u.fortezza.DSSKey.len);
  178|      0|                attrs++;
  179|      0|                break;
  180|      0|            case dhKey:
  ------------------
  |  Branch (180:13): [True: 0, False: 3.11k]
  ------------------
  181|      0|                keyType = CKK_DH;
  ------------------
  |  |  374|      0|#define CKK_DH 0x00000002UL
  ------------------
  182|      0|                PK11_SETATTRS(attrs, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  183|      0|                attrs++;
  184|      0|                signedattr = attrs;
  185|      0|                PK11_SETATTRS(attrs, CKA_PRIME, pubKey->u.dh.prime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  186|      0|                              pubKey->u.dh.prime.len);
  187|      0|                attrs++;
  188|      0|                PK11_SETATTRS(attrs, CKA_BASE, pubKey->u.dh.base.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  189|      0|                              pubKey->u.dh.base.len);
  190|      0|                attrs++;
  191|      0|                PK11_SETATTRS(attrs, CKA_VALUE, pubKey->u.dh.publicValue.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  192|      0|                              pubKey->u.dh.publicValue.len);
  193|      0|                attrs++;
  194|      0|                break;
  195|      0|            case edKey:
  ------------------
  |  Branch (195:13): [True: 0, False: 3.11k]
  ------------------
  196|      0|                keyType = CKK_EC_EDWARDS;
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  197|      0|                PK11_SETATTRS(attrs, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  198|      0|                attrs++;
  199|      0|                PK11_SETATTRS(attrs, CKA_EC_PARAMS,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  200|      0|                              pubKey->u.ec.DEREncodedParams.data,
  201|      0|                              pubKey->u.ec.DEREncodedParams.len);
  202|      0|                attrs++;
  203|      0|                PK11_SETATTRS(attrs, CKA_EC_POINT,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  204|      0|                              pubKey->u.ec.publicValue.data,
  205|      0|                              pubKey->u.ec.publicValue.len);
  206|      0|                attrs++;
  207|      0|                break;
  208|      0|            case ecMontKey:
  ------------------
  |  Branch (208:13): [True: 0, False: 3.11k]
  ------------------
  209|      0|                keyType = CKK_EC_MONTGOMERY;
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  210|      0|                PK11_SETATTRS(attrs, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  211|      0|                attrs++;
  212|      0|                PK11_SETATTRS(attrs, CKA_EC_PARAMS,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  213|      0|                              pubKey->u.ec.DEREncodedParams.data,
  214|      0|                              pubKey->u.ec.DEREncodedParams.len);
  215|      0|                attrs++;
  216|      0|                PK11_SETATTRS(attrs, CKA_EC_POINT,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  217|      0|                              pubKey->u.ec.publicValue.data,
  218|      0|                              pubKey->u.ec.publicValue.len);
  219|      0|                attrs++;
  220|      0|                break;
  221|      0|            case ecKey:
  ------------------
  |  Branch (221:13): [True: 0, False: 3.11k]
  ------------------
  222|      0|                keyType = CKK_EC;
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  223|      0|                PK11_SETATTRS(attrs, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  224|      0|                attrs++;
  225|      0|                PK11_SETATTRS(attrs, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  226|      0|                attrs++;
  227|      0|                PK11_SETATTRS(attrs, CKA_EC_PARAMS,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  228|      0|                              pubKey->u.ec.DEREncodedParams.data,
  229|      0|                              pubKey->u.ec.DEREncodedParams.len);
  230|      0|                attrs++;
  231|      0|                if (PR_GetEnvSecure("NSS_USE_DECODED_CKA_EC_POINT")) {
  ------------------
  |  Branch (231:21): [True: 0, False: 0]
  ------------------
  232|      0|                    PK11_SETATTRS(attrs, CKA_EC_POINT,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  233|      0|                                  pubKey->u.ec.publicValue.data,
  234|      0|                                  pubKey->u.ec.publicValue.len);
  235|      0|                    attrs++;
  236|      0|                } else {
  237|      0|                    pubValue = SEC_ASN1EncodeItem(NULL, NULL,
  ------------------
  |  |   89|      0|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
  238|      0|                                                  &pubKey->u.ec.publicValue,
  239|      0|                                                  SEC_ASN1_GET(SEC_OctetStringTemplate));
  ------------------
  |  |  188|      0|#define SEC_ASN1_GET(x) x
  ------------------
  240|      0|                    if (pubValue == NULL) {
  ------------------
  |  Branch (240:25): [True: 0, False: 0]
  ------------------
  241|      0|                        if (ckaId) {
  ------------------
  |  Branch (241:29): [True: 0, False: 0]
  ------------------
  242|      0|                            SECITEM_FreeItem(ckaId, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                                          SECITEM_FreeItem(ckaId, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  243|      0|                        }
  244|      0|                        return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  245|      0|                    }
  246|      0|                    PK11_SETATTRS(attrs, CKA_EC_POINT,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  247|      0|                                  pubValue->data, pubValue->len);
  248|      0|                    attrs++;
  249|      0|                }
  250|      0|                break;
  251|     99|            case kyberKey:
  ------------------
  |  Branch (251:13): [True: 99, False: 3.01k]
  ------------------
  252|     99|                switch (pubKey->u.kyber.params) {
  253|      0|                    case params_kyber768_round3:
  ------------------
  |  Branch (253:21): [True: 0, False: 99]
  ------------------
  254|      0|                    case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (254:21): [True: 0, False: 99]
  ------------------
  255|      0|                        keyType = CKK_NSS_KYBER;
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  256|      0|                        kemParams = CKP_NSS_KYBER_768_ROUND3;
  ------------------
  |  |  301|      0|#define CKP_NSS_KYBER_768_ROUND3 (CKP_NSS + 1)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  257|      0|                        break;
  258|     99|                    case params_ml_kem768:
  ------------------
  |  Branch (258:21): [True: 99, False: 0]
  ------------------
  259|     99|                    case params_ml_kem768_test_mode:
  ------------------
  |  Branch (259:21): [True: 0, False: 99]
  ------------------
  260|     99|                        keyType = CKK_NSS_ML_KEM;
  ------------------
  |  |   59|     99|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|     99|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|     99|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  261|     99|                        kemParams = CKP_NSS_ML_KEM_768;
  ------------------
  |  |  302|     99|#define CKP_NSS_ML_KEM_768 (CKP_NSS + 2)
  |  |  ------------------
  |  |  |  |  300|     99|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  262|     99|                        break;
  263|      0|                    default:
  ------------------
  |  Branch (263:21): [True: 0, False: 99]
  ------------------
  264|      0|                        kemParams = CKP_INVALID_ID;
  ------------------
  |  |  345|      0|#define CKP_INVALID_ID 0x00000000UL
  ------------------
  265|      0|                        break;
  266|     99|                }
  267|     99|                PK11_SETATTRS(attrs, CKA_NSS_PARAMETER_SET,
  ------------------
  |  |  104|     99|    (x)->type = (id);              \
  |  |  105|     99|    (x)->pValue = (v);             \
  |  |  106|     99|    (x)->ulValueLen = (l);
  ------------------
  268|     99|                              &kemParams,
  269|     99|                              sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE));
  270|     99|                attrs++;
  271|     99|                PK11_SETATTRS(attrs, CKA_VALUE, pubKey->u.kyber.publicValue.data,
  ------------------
  |  |  104|     99|    (x)->type = (id);              \
  |  |  105|     99|    (x)->pValue = (v);             \
  |  |  106|     99|    (x)->ulValueLen = (l);
  ------------------
  272|     99|                              pubKey->u.kyber.publicValue.len);
  273|     99|                attrs++;
  274|     99|                break;
  275|      0|            default:
  ------------------
  |  Branch (275:13): [True: 0, False: 3.11k]
  ------------------
  276|      0|                if (ckaId) {
  ------------------
  |  Branch (276:21): [True: 0, False: 0]
  ------------------
  277|      0|                    SECITEM_FreeItem(ckaId, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                                  SECITEM_FreeItem(ckaId, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  278|      0|                }
  279|      0|                PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  280|      0|                return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  281|  3.11k|        }
  282|  3.11k|        templateCount = attrs - theTemplate;
  283|  3.11k|        PORT_Assert(templateCount <= (sizeof(theTemplate) / sizeof(CK_ATTRIBUTE)));
  ------------------
  |  |  120|  3.11k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.11k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.11k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  284|  3.11k|        if (pubKey->keyType != ecKey && pubKey->keyType != kyberKey && pubKey->keyType != edKey &&
  ------------------
  |  Branch (284:13): [True: 3.11k, False: 0]
  |  Branch (284:41): [True: 3.01k, False: 99]
  |  Branch (284:72): [True: 3.01k, False: 0]
  ------------------
  285|  3.11k|            pubKey->keyType != ecMontKey) {
  ------------------
  |  Branch (285:13): [True: 3.01k, False: 0]
  ------------------
  286|  3.01k|            PORT_Assert(signedattr);
  ------------------
  |  |  120|  3.01k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.01k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.01k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  287|  3.01k|            signedcount = attrs - signedattr;
  288|  9.04k|            for (attrs = signedattr; signedcount; attrs++, signedcount--) {
  ------------------
  |  Branch (288:38): [True: 6.02k, False: 3.01k]
  ------------------
  289|  6.02k|                pk11_SignedToUnsigned(attrs);
  290|  6.02k|            }
  291|  3.01k|        }
  292|  3.11k|        rv = PK11_CreateNewObject(slot, CK_INVALID_HANDLE, theTemplate,
  ------------------
  |  |   78|  3.11k|#define CK_INVALID_HANDLE 0
  ------------------
  293|  3.11k|                                  templateCount, isToken, &objectID);
  294|  3.11k|        if (ckaId) {
  ------------------
  |  Branch (294:13): [True: 0, False: 3.11k]
  ------------------
  295|      0|            SECITEM_FreeItem(ckaId, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(ckaId, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  296|      0|        }
  297|  3.11k|        if (pubValue) {
  ------------------
  |  Branch (297:13): [True: 0, False: 3.11k]
  ------------------
  298|      0|            SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  299|      0|        }
  300|  3.11k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (300:13): [True: 0, False: 3.11k]
  ------------------
  301|      0|            return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  302|      0|        }
  303|  3.11k|    }
  304|       |
  305|  3.11k|    pubKey->pkcs11ID = objectID;
  306|  3.11k|    pubKey->pkcs11Slot = PK11_ReferenceSlot(slot);
  307|       |
  308|  3.11k|    return objectID;
  309|  3.11k|}
PK11_ExtractPublicKey:
  648|  47.3k|{
  649|  47.3k|    CK_OBJECT_CLASS keyClass = CKO_PUBLIC_KEY;
  ------------------
  |  |  327|  47.3k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  650|  47.3k|    PLArenaPool *arena;
  651|  47.3k|    PLArenaPool *tmp_arena;
  652|  47.3k|    SECKEYPublicKey *pubKey;
  653|  47.3k|    unsigned int templateCount = 0;
  654|  47.3k|    CK_KEY_TYPE pk11KeyType;
  655|  47.3k|    CK_RV crv;
  656|  47.3k|    CK_ATTRIBUTE template[8];
  657|  47.3k|    CK_ATTRIBUTE *attrs = template;
  658|  47.3k|    CK_ATTRIBUTE *modulus, *exponent, *base, *prime, *subprime, *value;
  659|  47.3k|    CK_ATTRIBUTE *ecparams, *kemParams;
  660|       |
  661|       |    /* if we didn't know the key type, get it */
  662|  47.3k|    if (keyType == nullKey) {
  ------------------
  |  Branch (662:9): [True: 0, False: 47.3k]
  ------------------
  663|       |
  664|      0|        pk11KeyType = PK11_ReadULongAttribute(slot, id, CKA_KEY_TYPE);
  ------------------
  |  |  543|      0|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  665|      0|        if (pk11KeyType == CK_UNAVAILABLE_INFORMATION) {
  ------------------
  |  |   64|      0|#define CK_UNAVAILABLE_INFORMATION (~0UL)
  ------------------
  |  Branch (665:13): [True: 0, False: 0]
  ------------------
  666|      0|            return NULL;
  667|      0|        }
  668|      0|        switch (pk11KeyType) {
  669|      0|            case CKK_RSA:
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (669:13): [True: 0, False: 0]
  ------------------
  670|      0|                keyType = rsaKey;
  671|      0|                break;
  672|      0|            case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (672:13): [True: 0, False: 0]
  ------------------
  673|      0|                keyType = dsaKey;
  674|      0|                break;
  675|      0|            case CKK_DH:
  ------------------
  |  |  374|      0|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (675:13): [True: 0, False: 0]
  ------------------
  676|      0|                keyType = dhKey;
  677|      0|                break;
  678|      0|            case CKK_EC:
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (678:13): [True: 0, False: 0]
  ------------------
  679|      0|                keyType = ecKey;
  680|      0|                break;
  681|      0|            case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (681:13): [True: 0, False: 0]
  ------------------
  682|      0|                keyType = ecMontKey;
  683|      0|                break;
  684|      0|            case CKK_EC_EDWARDS:
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (684:13): [True: 0, False: 0]
  ------------------
  685|      0|                keyType = edKey;
  686|      0|                break;
  687|      0|            case CKK_NSS_KYBER:
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (687:13): [True: 0, False: 0]
  ------------------
  688|      0|            case CKK_NSS_ML_KEM:
  ------------------
  |  |   59|      0|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (688:13): [True: 0, False: 0]
  ------------------
  689|      0|                keyType = kyberKey;
  690|      0|                break;
  691|      0|            default:
  ------------------
  |  Branch (691:13): [True: 0, False: 0]
  ------------------
  692|      0|                PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  693|      0|                return NULL;
  694|      0|        }
  695|      0|    }
  696|       |
  697|       |    /* now we need to create space for the public key */
  698|  47.3k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  47.3k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  47.3k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  699|  47.3k|    if (arena == NULL)
  ------------------
  |  Branch (699:9): [True: 0, False: 47.3k]
  ------------------
  700|      0|        return NULL;
  701|  47.3k|    tmp_arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  47.3k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  tmp_arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  47.3k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  702|  47.3k|    if (tmp_arena == NULL) {
  ------------------
  |  Branch (702:9): [True: 0, False: 47.3k]
  ------------------
  703|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  704|      0|        return NULL;
  705|      0|    }
  706|       |
  707|  47.3k|    pubKey = (SECKEYPublicKey *)
  708|  47.3k|        PORT_ArenaZAlloc(arena, sizeof(SECKEYPublicKey));
  ------------------
  |  |   59|  47.3k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  709|  47.3k|    if (pubKey == NULL) {
  ------------------
  |  Branch (709:9): [True: 0, False: 47.3k]
  ------------------
  710|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  711|      0|        PORT_FreeArena(tmp_arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(tmp_arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  712|      0|        return NULL;
  713|      0|    }
  714|       |
  715|  47.3k|    pubKey->arena = arena;
  716|  47.3k|    pubKey->keyType = keyType;
  717|  47.3k|    pubKey->pkcs11Slot = PK11_ReferenceSlot(slot);
  718|  47.3k|    pubKey->pkcs11ID = id;
  719|  47.3k|    PK11_SETATTRS(attrs, CKA_CLASS, &keyClass,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  47.3k|    (x)->pValue = (v);             \
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
  720|  47.3k|                  sizeof(keyClass));
  721|  47.3k|    attrs++;
  722|  47.3k|    PK11_SETATTRS(attrs, CKA_KEY_TYPE, &pk11KeyType,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  47.3k|    (x)->pValue = (v);             \
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
  723|  47.3k|                  sizeof(pk11KeyType));
  724|  47.3k|    attrs++;
  725|  47.3k|    switch (pubKey->keyType) {
  726|      0|        case rsaKey:
  ------------------
  |  Branch (726:9): [True: 0, False: 47.3k]
  ------------------
  727|      0|            modulus = attrs;
  728|      0|            PK11_SETATTRS(attrs, CKA_MODULUS, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  729|      0|            attrs++;
  730|      0|            exponent = attrs;
  731|      0|            PK11_SETATTRS(attrs, CKA_PUBLIC_EXPONENT, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  732|      0|            attrs++;
  733|       |
  734|      0|            templateCount = attrs - template;
  735|      0|            PR_ASSERT(templateCount <= sizeof(template) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  736|      0|            crv = PK11_GetAttributes(tmp_arena, slot, id, template, templateCount);
  737|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (737:17): [True: 0, False: 0]
  ------------------
  738|      0|                break;
  739|       |
  740|      0|            if ((keyClass != CKO_PUBLIC_KEY) || (pk11KeyType != CKK_RSA)) {
  ------------------
  |  |  327|      0|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
                          if ((keyClass != CKO_PUBLIC_KEY) || (pk11KeyType != CKK_RSA)) {
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (740:17): [True: 0, False: 0]
  |  Branch (740:49): [True: 0, False: 0]
  ------------------
  741|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  742|      0|                break;
  743|      0|            }
  744|      0|            crv = pk11_Attr2SecItem(arena, modulus, &pubKey->u.rsa.modulus);
  745|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (745:17): [True: 0, False: 0]
  ------------------
  746|      0|                break;
  747|      0|            crv = pk11_Attr2SecItem(arena, exponent, &pubKey->u.rsa.publicExponent);
  748|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (748:17): [True: 0, False: 0]
  ------------------
  749|      0|                break;
  750|      0|            break;
  751|      0|        case dsaKey:
  ------------------
  |  Branch (751:9): [True: 0, False: 47.3k]
  ------------------
  752|      0|            prime = attrs;
  753|      0|            PK11_SETATTRS(attrs, CKA_PRIME, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  754|      0|            attrs++;
  755|      0|            subprime = attrs;
  756|      0|            PK11_SETATTRS(attrs, CKA_SUBPRIME, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  757|      0|            attrs++;
  758|      0|            base = attrs;
  759|      0|            PK11_SETATTRS(attrs, CKA_BASE, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  760|      0|            attrs++;
  761|      0|            value = attrs;
  762|      0|            PK11_SETATTRS(attrs, CKA_VALUE, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  763|      0|            attrs++;
  764|      0|            templateCount = attrs - template;
  765|      0|            PR_ASSERT(templateCount <= sizeof(template) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  766|      0|            crv = PK11_GetAttributes(tmp_arena, slot, id, template, templateCount);
  767|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (767:17): [True: 0, False: 0]
  ------------------
  768|      0|                break;
  769|       |
  770|      0|            if ((keyClass != CKO_PUBLIC_KEY) || (pk11KeyType != CKK_DSA)) {
  ------------------
  |  |  327|      0|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
                          if ((keyClass != CKO_PUBLIC_KEY) || (pk11KeyType != CKK_DSA)) {
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (770:17): [True: 0, False: 0]
  |  Branch (770:49): [True: 0, False: 0]
  ------------------
  771|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  772|      0|                break;
  773|      0|            }
  774|      0|            crv = pk11_Attr2SecItem(arena, prime, &pubKey->u.dsa.params.prime);
  775|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (775:17): [True: 0, False: 0]
  ------------------
  776|      0|                break;
  777|      0|            crv = pk11_Attr2SecItem(arena, subprime, &pubKey->u.dsa.params.subPrime);
  778|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (778:17): [True: 0, False: 0]
  ------------------
  779|      0|                break;
  780|      0|            crv = pk11_Attr2SecItem(arena, base, &pubKey->u.dsa.params.base);
  781|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (781:17): [True: 0, False: 0]
  ------------------
  782|      0|                break;
  783|      0|            crv = pk11_Attr2SecItem(arena, value, &pubKey->u.dsa.publicValue);
  784|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (784:17): [True: 0, False: 0]
  ------------------
  785|      0|                break;
  786|      0|            break;
  787|  29.0k|        case dhKey:
  ------------------
  |  Branch (787:9): [True: 29.0k, False: 18.2k]
  ------------------
  788|  29.0k|            prime = attrs;
  789|  29.0k|            PK11_SETATTRS(attrs, CKA_PRIME, NULL, 0);
  ------------------
  |  |  104|  29.0k|    (x)->type = (id);              \
  |  |  105|  29.0k|    (x)->pValue = (v);             \
  |  |  106|  29.0k|    (x)->ulValueLen = (l);
  ------------------
  790|  29.0k|            attrs++;
  791|  29.0k|            base = attrs;
  792|  29.0k|            PK11_SETATTRS(attrs, CKA_BASE, NULL, 0);
  ------------------
  |  |  104|  29.0k|    (x)->type = (id);              \
  |  |  105|  29.0k|    (x)->pValue = (v);             \
  |  |  106|  29.0k|    (x)->ulValueLen = (l);
  ------------------
  793|  29.0k|            attrs++;
  794|  29.0k|            value = attrs;
  795|  29.0k|            PK11_SETATTRS(attrs, CKA_VALUE, NULL, 0);
  ------------------
  |  |  104|  29.0k|    (x)->type = (id);              \
  |  |  105|  29.0k|    (x)->pValue = (v);             \
  |  |  106|  29.0k|    (x)->ulValueLen = (l);
  ------------------
  796|  29.0k|            attrs++;
  797|  29.0k|            templateCount = attrs - template;
  798|  29.0k|            PR_ASSERT(templateCount <= sizeof(template) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  29.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 29.0k, False: 0]
  |  |  ------------------
  ------------------
  799|  29.0k|            crv = PK11_GetAttributes(tmp_arena, slot, id, template, templateCount);
  800|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (800:17): [True: 0, False: 29.0k]
  ------------------
  801|      0|                break;
  802|       |
  803|  29.0k|            if ((keyClass != CKO_PUBLIC_KEY) || (pk11KeyType != CKK_DH)) {
  ------------------
  |  |  327|  29.0k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
                          if ((keyClass != CKO_PUBLIC_KEY) || (pk11KeyType != CKK_DH)) {
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (803:17): [True: 0, False: 29.0k]
  |  Branch (803:49): [True: 0, False: 29.0k]
  ------------------
  804|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  805|      0|                break;
  806|      0|            }
  807|  29.0k|            crv = pk11_Attr2SecItem(arena, prime, &pubKey->u.dh.prime);
  808|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (808:17): [True: 0, False: 29.0k]
  ------------------
  809|      0|                break;
  810|  29.0k|            crv = pk11_Attr2SecItem(arena, base, &pubKey->u.dh.base);
  811|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (811:17): [True: 0, False: 29.0k]
  ------------------
  812|      0|                break;
  813|  29.0k|            crv = pk11_Attr2SecItem(arena, value, &pubKey->u.dh.publicValue);
  814|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (814:17): [True: 0, False: 29.0k]
  ------------------
  815|      0|                break;
  816|  29.0k|            break;
  817|  29.0k|        case edKey:
  ------------------
  |  Branch (817:9): [True: 0, False: 47.3k]
  ------------------
  818|  18.2k|        case ecKey:
  ------------------
  |  Branch (818:9): [True: 18.2k, False: 29.0k]
  ------------------
  819|  18.2k|        case ecMontKey:
  ------------------
  |  Branch (819:9): [True: 0, False: 47.3k]
  ------------------
  820|  18.2k|            pubKey->u.ec.size = 0;
  821|  18.2k|            ecparams = attrs;
  822|  18.2k|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, NULL, 0);
  ------------------
  |  |  104|  18.2k|    (x)->type = (id);              \
  |  |  105|  18.2k|    (x)->pValue = (v);             \
  |  |  106|  18.2k|    (x)->ulValueLen = (l);
  ------------------
  823|  18.2k|            attrs++;
  824|  18.2k|            value = attrs;
  825|  18.2k|            PK11_SETATTRS(attrs, CKA_EC_POINT, NULL, 0);
  ------------------
  |  |  104|  18.2k|    (x)->type = (id);              \
  |  |  105|  18.2k|    (x)->pValue = (v);             \
  |  |  106|  18.2k|    (x)->ulValueLen = (l);
  ------------------
  826|  18.2k|            attrs++;
  827|  18.2k|            templateCount = attrs - template;
  828|  18.2k|            PR_ASSERT(templateCount <= sizeof(template) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  18.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 18.2k, False: 0]
  |  |  ------------------
  ------------------
  829|  18.2k|            crv = PK11_GetAttributes(arena, slot, id, template, templateCount);
  830|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (830:17): [True: 0, False: 18.2k]
  ------------------
  831|      0|                break;
  832|       |
  833|  18.2k|            if ((keyClass != CKO_PUBLIC_KEY) ||
  ------------------
  |  |  327|  18.2k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  |  Branch (833:17): [True: 0, False: 18.2k]
  ------------------
  834|  18.2k|                (pubKey->keyType == ecKey && pk11KeyType != CKK_EC) ||
  ------------------
  |  |  379|  18.2k|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (834:18): [True: 18.2k, False: 0]
  |  Branch (834:46): [True: 0, False: 18.2k]
  ------------------
  835|  18.2k|                (pubKey->keyType == edKey && pk11KeyType != CKK_EC_EDWARDS) ||
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (835:18): [True: 0, False: 18.2k]
  |  Branch (835:46): [True: 0, False: 0]
  ------------------
  836|  18.2k|                (pubKey->keyType == ecMontKey && pk11KeyType != CKK_EC_MONTGOMERY)) {
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (836:18): [True: 0, False: 18.2k]
  |  Branch (836:50): [True: 0, False: 0]
  ------------------
  837|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  838|      0|                break;
  839|      0|            }
  840|       |
  841|  18.2k|            crv = pk11_Attr2SecItem(arena, ecparams,
  842|  18.2k|                                    &pubKey->u.ec.DEREncodedParams);
  843|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (843:17): [True: 0, False: 18.2k]
  ------------------
  844|      0|                break;
  845|  18.2k|            pubKey->u.ec.encoding = ECPoint_Undefined;
  846|  18.2k|            crv = pk11_get_Decoded_ECPoint(arena,
  847|  18.2k|                                           &pubKey->u.ec.DEREncodedParams, value,
  848|  18.2k|                                           &pubKey->u.ec.publicValue);
  849|  18.2k|            break;
  850|      0|        case kyberKey:
  ------------------
  |  Branch (850:9): [True: 0, False: 47.3k]
  ------------------
  851|      0|            value = attrs;
  852|      0|            PK11_SETATTRS(attrs, CKA_VALUE, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  853|      0|            attrs++;
  854|      0|            kemParams = attrs;
  855|      0|            PK11_SETATTRS(attrs, CKA_NSS_PARAMETER_SET, NULL, 0);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  856|      0|            attrs++;
  857|      0|            templateCount = attrs - template;
  858|      0|            PR_ASSERT(templateCount <= sizeof(template) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  859|       |
  860|      0|            crv = PK11_GetAttributes(arena, slot, id, template, templateCount);
  861|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (861:17): [True: 0, False: 0]
  ------------------
  862|      0|                break;
  863|       |
  864|      0|            if (keyClass != CKO_PUBLIC_KEY) {
  ------------------
  |  |  327|      0|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  |  Branch (864:17): [True: 0, False: 0]
  ------------------
  865|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  866|      0|                break;
  867|      0|            }
  868|       |
  869|      0|            if (pk11KeyType != CKK_NSS_KYBER && pk11KeyType != CKK_NSS_ML_KEM) {
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                          if (pk11KeyType != CKK_NSS_KYBER && pk11KeyType != CKK_NSS_ML_KEM) {
  ------------------
  |  |   59|      0|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (869:17): [True: 0, False: 0]
  |  Branch (869:49): [True: 0, False: 0]
  ------------------
  870|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  871|      0|                break;
  872|      0|            }
  873|       |
  874|      0|            if (kemParams->ulValueLen != sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE)) {
  ------------------
  |  Branch (874:17): [True: 0, False: 0]
  ------------------
  875|      0|                crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  876|      0|                break;
  877|      0|            }
  878|      0|            CK_NSS_KEM_PARAMETER_SET_TYPE *pPK11Params = kemParams->pValue;
  879|      0|            switch (*pPK11Params) {
  880|      0|                case CKP_NSS_KYBER_768_ROUND3:
  ------------------
  |  |  301|      0|#define CKP_NSS_KYBER_768_ROUND3 (CKP_NSS + 1)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (880:17): [True: 0, False: 0]
  ------------------
  881|      0|                    pubKey->u.kyber.params = params_kyber768_round3;
  882|      0|                    break;
  883|      0|                case CKP_NSS_ML_KEM_768:
  ------------------
  |  |  302|      0|#define CKP_NSS_ML_KEM_768 (CKP_NSS + 2)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (883:17): [True: 0, False: 0]
  ------------------
  884|      0|                    pubKey->u.kyber.params = params_ml_kem768;
  885|      0|                    break;
  886|      0|                default:
  ------------------
  |  Branch (886:17): [True: 0, False: 0]
  ------------------
  887|      0|                    pubKey->u.kyber.params = params_kyber_invalid;
  888|      0|                    break;
  889|      0|            }
  890|      0|            crv = pk11_Attr2SecItem(arena, value, &pubKey->u.kyber.publicValue);
  891|      0|            break;
  892|      0|        case fortezzaKey:
  ------------------
  |  Branch (892:9): [True: 0, False: 47.3k]
  ------------------
  893|      0|        case nullKey:
  ------------------
  |  Branch (893:9): [True: 0, False: 47.3k]
  ------------------
  894|      0|        default:
  ------------------
  |  Branch (894:9): [True: 0, False: 47.3k]
  ------------------
  895|      0|            crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  896|      0|            break;
  897|  47.3k|    }
  898|       |
  899|  47.3k|    PORT_FreeArena(tmp_arena, PR_FALSE);
  ------------------
  |  |   61|  47.3k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(tmp_arena, PR_FALSE);
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
  900|       |
  901|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (901:9): [True: 0, False: 47.3k]
  ------------------
  902|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  903|      0|        PK11_FreeSlot(slot);
  904|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  905|      0|        return NULL;
  906|      0|    }
  907|       |
  908|  47.3k|    return pubKey;
  909|  47.3k|}
PK11_MakePrivKey:
  917|  47.3k|{
  918|  47.3k|    PLArenaPool *arena;
  919|  47.3k|    SECKEYPrivateKey *privKey;
  920|  47.3k|    PRBool isPrivate;
  921|  47.3k|    SECStatus rv;
  922|       |
  923|       |    /* don't know? look it up */
  924|  47.3k|    if (keyType == nullKey) {
  ------------------
  |  Branch (924:9): [True: 0, False: 47.3k]
  ------------------
  925|      0|        CK_KEY_TYPE pk11Type = CKK_RSA;
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  926|       |
  927|      0|        pk11Type = PK11_ReadULongAttribute(slot, privID, CKA_KEY_TYPE);
  ------------------
  |  |  543|      0|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  928|      0|        isTemp = (PRBool)!PK11_HasAttributeSet(slot, privID, CKA_TOKEN, PR_FALSE);
  ------------------
  |  |  512|      0|#define CKA_TOKEN 0x00000001UL
  ------------------
                      isTemp = (PRBool)!PK11_HasAttributeSet(slot, privID, CKA_TOKEN, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  929|      0|        switch (pk11Type) {
  930|      0|            case CKK_RSA:
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (930:13): [True: 0, False: 0]
  ------------------
  931|      0|                keyType = rsaKey;
  932|      0|                break;
  933|      0|            case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (933:13): [True: 0, False: 0]
  ------------------
  934|      0|                keyType = dsaKey;
  935|      0|                break;
  936|      0|            case CKK_DH:
  ------------------
  |  |  374|      0|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (936:13): [True: 0, False: 0]
  ------------------
  937|      0|                keyType = dhKey;
  938|      0|                break;
  939|      0|            case CKK_KEA:
  ------------------
  |  |  381|      0|#define CKK_KEA 0x00000005UL
  ------------------
  |  Branch (939:13): [True: 0, False: 0]
  ------------------
  940|      0|                keyType = fortezzaKey;
  941|      0|                break;
  942|      0|            case CKK_EC:
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (942:13): [True: 0, False: 0]
  ------------------
  943|      0|                keyType = ecKey;
  944|      0|                break;
  945|      0|            case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (945:13): [True: 0, False: 0]
  ------------------
  946|      0|                keyType = ecMontKey;
  947|      0|                break;
  948|      0|            case CKK_EC_EDWARDS:
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (948:13): [True: 0, False: 0]
  ------------------
  949|      0|                keyType = edKey;
  950|      0|                break;
  951|      0|            case CKK_NSS_KYBER:
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (951:13): [True: 0, False: 0]
  ------------------
  952|      0|            case CKK_NSS_ML_KEM:
  ------------------
  |  |   59|      0|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (952:13): [True: 0, False: 0]
  ------------------
  953|      0|                keyType = kyberKey;
  954|      0|                break;
  955|      0|            default:
  ------------------
  |  Branch (955:13): [True: 0, False: 0]
  ------------------
  956|      0|                break;
  957|      0|        }
  958|      0|    }
  959|       |
  960|       |    /* if the key is private, make sure we are authenticated to the
  961|       |     * token before we try to use it */
  962|  47.3k|    isPrivate = (PRBool)PK11_HasAttributeSet(slot, privID, CKA_PRIVATE, PR_FALSE);
  ------------------
  |  |  513|  47.3k|#define CKA_PRIVATE 0x00000002UL
  ------------------
                  isPrivate = (PRBool)PK11_HasAttributeSet(slot, privID, CKA_PRIVATE, PR_FALSE);
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
  963|  47.3k|    if (isPrivate) {
  ------------------
  |  Branch (963:9): [True: 0, False: 47.3k]
  ------------------
  964|      0|        rv = PK11_Authenticate(slot, PR_TRUE, wincx);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  965|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (965:13): [True: 0, False: 0]
  ------------------
  966|      0|            return NULL;
  967|      0|        }
  968|      0|    }
  969|       |
  970|       |    /* now we need to create space for the private key */
  971|  47.3k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  47.3k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  47.3k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  972|  47.3k|    if (arena == NULL)
  ------------------
  |  Branch (972:9): [True: 0, False: 47.3k]
  ------------------
  973|      0|        return NULL;
  974|       |
  975|  47.3k|    privKey = (SECKEYPrivateKey *)
  976|  47.3k|        PORT_ArenaZAlloc(arena, sizeof(SECKEYPrivateKey));
  ------------------
  |  |   59|  47.3k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  977|  47.3k|    if (privKey == NULL) {
  ------------------
  |  Branch (977:9): [True: 0, False: 47.3k]
  ------------------
  978|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  979|      0|        return NULL;
  980|      0|    }
  981|       |
  982|  47.3k|    privKey->arena = arena;
  983|  47.3k|    privKey->keyType = keyType;
  984|  47.3k|    privKey->pkcs11Slot = PK11_ReferenceSlot(slot);
  985|  47.3k|    privKey->pkcs11ID = privID;
  986|  47.3k|    privKey->pkcs11IsTemp = isTemp;
  987|  47.3k|    privKey->wincx = wincx;
  988|       |
  989|  47.3k|    return privKey;
  990|  47.3k|}
PK11_GetSlotFromPrivateKey:
  994|  21.5k|{
  995|  21.5k|    PK11SlotInfo *slot = key->pkcs11Slot;
  996|  21.5k|    slot = PK11_ReferenceSlot(slot);
  997|  21.5k|    return slot;
  998|  21.5k|}
PK11_GetPrivateModulusLen:
 1005|  35.5k|{
 1006|  35.5k|    CK_ATTRIBUTE theTemplate = { CKA_MODULUS, NULL, 0 };
  ------------------
  |  |  558|  35.5k|#define CKA_MODULUS 0x00000120UL
  ------------------
 1007|  35.5k|    PK11SlotInfo *slot = key->pkcs11Slot;
 1008|  35.5k|    CK_RV crv;
 1009|  35.5k|    int length;
 1010|       |
 1011|  35.5k|    switch (key->keyType) {
 1012|  35.5k|        case rsaKey:
  ------------------
  |  Branch (1012:9): [True: 35.5k, False: 0]
  ------------------
 1013|  35.5k|            crv = PK11_GetAttributes(NULL, slot, key->pkcs11ID, &theTemplate, 1);
 1014|  35.5k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  35.5k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1014:17): [True: 0, False: 35.5k]
  ------------------
 1015|      0|                PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1016|      0|                return -1;
 1017|      0|            }
 1018|  35.5k|            if (theTemplate.pValue == NULL) {
  ------------------
  |  Branch (1018:17): [True: 0, False: 35.5k]
  ------------------
 1019|      0|                PORT_SetError(PK11_MapError(CKR_ATTRIBUTE_VALUE_INVALID));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                              PORT_SetError(PK11_MapError(CKR_ATTRIBUTE_VALUE_INVALID));
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 1020|      0|                return -1;
 1021|      0|            }
 1022|  35.5k|            length = theTemplate.ulValueLen;
 1023|  35.5k|            if (*(unsigned char *)theTemplate.pValue == 0) {
  ------------------
  |  Branch (1023:17): [True: 0, False: 35.5k]
  ------------------
 1024|      0|                length--;
 1025|      0|            }
 1026|  35.5k|            PORT_Free(theTemplate.pValue);
  ------------------
  |  |   60|  35.5k|#define PORT_Free PORT_Free_Util
  ------------------
 1027|  35.5k|            return (int)length;
 1028|       |
 1029|      0|        case fortezzaKey:
  ------------------
  |  Branch (1029:9): [True: 0, False: 35.5k]
  ------------------
 1030|      0|        case dsaKey:
  ------------------
  |  Branch (1030:9): [True: 0, False: 35.5k]
  ------------------
 1031|      0|        case dhKey:
  ------------------
  |  Branch (1031:9): [True: 0, False: 35.5k]
  ------------------
 1032|      0|        default:
  ------------------
  |  Branch (1032:9): [True: 0, False: 35.5k]
  ------------------
 1033|      0|            break;
 1034|  35.5k|    }
 1035|      0|    if (theTemplate.pValue != NULL)
  ------------------
  |  Branch (1035:9): [True: 0, False: 0]
  ------------------
 1036|      0|        PORT_Free(theTemplate.pValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1037|      0|    PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1038|      0|    return -1;
 1039|  35.5k|}
PK11_GenerateKeyPairWithOpFlags:
 1278|  47.3k|{
 1279|       |    /* we have to use these native types because when we call PKCS 11 modules
 1280|       |     * we have to make sure that we are using the correct sizes for all the
 1281|       |     * parameters. */
 1282|  47.3k|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  47.3k|#define CK_FALSE 0
  ------------------
 1283|  47.3k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 1284|  47.3k|    CK_ULONG modulusBits;
 1285|  47.3k|    CK_BYTE publicExponent[4];
 1286|  47.3k|    CK_ATTRIBUTE privTemplate[] = {
 1287|  47.3k|        { CKA_SENSITIVE, NULL, 0 },
  ------------------
  |  |  546|  47.3k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 1288|  47.3k|        { CKA_TOKEN, NULL, 0 },
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 1289|  47.3k|        { CKA_PRIVATE, NULL, 0 },
  ------------------
  |  |  513|  47.3k|#define CKA_PRIVATE 0x00000002UL
  ------------------
 1290|  47.3k|        { CKA_DERIVE, NULL, 0 },
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1291|  47.3k|        { CKA_UNWRAP, NULL, 0 },
  ------------------
  |  |  550|  47.3k|#define CKA_UNWRAP 0x00000107UL
  ------------------
 1292|  47.3k|        { CKA_SIGN, NULL, 0 },
  ------------------
  |  |  551|  47.3k|#define CKA_SIGN 0x00000108UL
  ------------------
 1293|  47.3k|        { CKA_DECRYPT, NULL, 0 },
  ------------------
  |  |  548|  47.3k|#define CKA_DECRYPT 0x00000105UL
  ------------------
 1294|  47.3k|        { CKA_EXTRACTABLE, NULL, 0 },
  ------------------
  |  |  585|  47.3k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 1295|  47.3k|        { CKA_MODIFIABLE, NULL, 0 },
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1296|  47.3k|    };
 1297|  47.3k|    CK_ATTRIBUTE rsaPubTemplate[] = {
 1298|  47.3k|        { CKA_MODULUS_BITS, NULL, 0 },
  ------------------
  |  |  559|  47.3k|#define CKA_MODULUS_BITS 0x00000121UL
  ------------------
 1299|  47.3k|        { CKA_PUBLIC_EXPONENT, NULL, 0 },
  ------------------
  |  |  560|  47.3k|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 1300|  47.3k|        { CKA_TOKEN, NULL, 0 },
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 1301|  47.3k|        { CKA_DERIVE, NULL, 0 },
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1302|  47.3k|        { CKA_WRAP, NULL, 0 },
  ------------------
  |  |  549|  47.3k|#define CKA_WRAP 0x00000106UL
  ------------------
 1303|  47.3k|        { CKA_VERIFY, NULL, 0 },
  ------------------
  |  |  553|  47.3k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1304|  47.3k|        { CKA_VERIFY_RECOVER, NULL, 0 },
  ------------------
  |  |  554|  47.3k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 1305|  47.3k|        { CKA_ENCRYPT, NULL, 0 },
  ------------------
  |  |  547|  47.3k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1306|  47.3k|        { CKA_MODIFIABLE, NULL, 0 },
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1307|  47.3k|    };
 1308|  47.3k|    CK_ATTRIBUTE dsaPubTemplate[] = {
 1309|  47.3k|        { CKA_PRIME, NULL, 0 },
  ------------------
  |  |  569|  47.3k|#define CKA_PRIME 0x00000130UL
  ------------------
 1310|  47.3k|        { CKA_SUBPRIME, NULL, 0 },
  ------------------
  |  |  570|  47.3k|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 1311|  47.3k|        { CKA_BASE, NULL, 0 },
  ------------------
  |  |  571|  47.3k|#define CKA_BASE 0x00000132UL
  ------------------
 1312|  47.3k|        { CKA_TOKEN, NULL, 0 },
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 1313|  47.3k|        { CKA_DERIVE, NULL, 0 },
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1314|  47.3k|        { CKA_WRAP, NULL, 0 },
  ------------------
  |  |  549|  47.3k|#define CKA_WRAP 0x00000106UL
  ------------------
 1315|  47.3k|        { CKA_VERIFY, NULL, 0 },
  ------------------
  |  |  553|  47.3k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1316|  47.3k|        { CKA_VERIFY_RECOVER, NULL, 0 },
  ------------------
  |  |  554|  47.3k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 1317|  47.3k|        { CKA_ENCRYPT, NULL, 0 },
  ------------------
  |  |  547|  47.3k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1318|  47.3k|        { CKA_MODIFIABLE, NULL, 0 },
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1319|  47.3k|    };
 1320|  47.3k|    CK_ATTRIBUTE dhPubTemplate[] = {
 1321|  47.3k|        { CKA_PRIME, NULL, 0 },
  ------------------
  |  |  569|  47.3k|#define CKA_PRIME 0x00000130UL
  ------------------
 1322|  47.3k|        { CKA_BASE, NULL, 0 },
  ------------------
  |  |  571|  47.3k|#define CKA_BASE 0x00000132UL
  ------------------
 1323|  47.3k|        { CKA_TOKEN, NULL, 0 },
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 1324|  47.3k|        { CKA_DERIVE, NULL, 0 },
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1325|  47.3k|        { CKA_WRAP, NULL, 0 },
  ------------------
  |  |  549|  47.3k|#define CKA_WRAP 0x00000106UL
  ------------------
 1326|  47.3k|        { CKA_VERIFY, NULL, 0 },
  ------------------
  |  |  553|  47.3k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1327|  47.3k|        { CKA_VERIFY_RECOVER, NULL, 0 },
  ------------------
  |  |  554|  47.3k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 1328|  47.3k|        { CKA_ENCRYPT, NULL, 0 },
  ------------------
  |  |  547|  47.3k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1329|  47.3k|        { CKA_MODIFIABLE, NULL, 0 },
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1330|  47.3k|    };
 1331|  47.3k|    CK_ATTRIBUTE ecPubTemplate[] = {
 1332|  47.3k|        { CKA_EC_PARAMS, NULL, 0 },
  ------------------
  |  |  602|  47.3k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 1333|  47.3k|        { CKA_TOKEN, NULL, 0 },
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 1334|  47.3k|        { CKA_DERIVE, NULL, 0 },
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1335|  47.3k|        { CKA_WRAP, NULL, 0 },
  ------------------
  |  |  549|  47.3k|#define CKA_WRAP 0x00000106UL
  ------------------
 1336|  47.3k|        { CKA_VERIFY, NULL, 0 },
  ------------------
  |  |  553|  47.3k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1337|  47.3k|        { CKA_VERIFY_RECOVER, NULL, 0 },
  ------------------
  |  |  554|  47.3k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 1338|  47.3k|        { CKA_ENCRYPT, NULL, 0 },
  ------------------
  |  |  547|  47.3k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1339|  47.3k|        { CKA_MODIFIABLE, NULL, 0 },
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1340|  47.3k|    };
 1341|  47.3k|    SECKEYECParams *ecParams;
 1342|       |
 1343|  47.3k|    CK_ATTRIBUTE kyberPubTemplate[] = {
 1344|  47.3k|        { CKA_NSS_PARAMETER_SET, NULL, 0 },
  ------------------
  |  |  113|  47.3k|#define CKA_NSS_PARAMETER_SET (CKA_NSS + 40)
  |  |  ------------------
  |  |  |  |   77|  47.3k|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|  47.3k|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  47.3k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1345|  47.3k|        { CKA_TOKEN, NULL, 0 },
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 1346|  47.3k|        { CKA_DERIVE, NULL, 0 },
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1347|  47.3k|        { CKA_WRAP, NULL, 0 },
  ------------------
  |  |  549|  47.3k|#define CKA_WRAP 0x00000106UL
  ------------------
 1348|  47.3k|        { CKA_VERIFY, NULL, 0 },
  ------------------
  |  |  553|  47.3k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1349|  47.3k|        { CKA_VERIFY_RECOVER, NULL, 0 },
  ------------------
  |  |  554|  47.3k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 1350|  47.3k|        { CKA_ENCRYPT, NULL, 0 },
  ------------------
  |  |  547|  47.3k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1351|  47.3k|        { CKA_MODIFIABLE, NULL, 0 },
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1352|  47.3k|    };
 1353|       |
 1354|       |    /*CK_ULONG key_size = 0;*/
 1355|  47.3k|    CK_ATTRIBUTE *pubTemplate;
 1356|  47.3k|    int privCount = 0;
 1357|  47.3k|    int pubCount = 0;
 1358|  47.3k|    PK11RSAGenParams *rsaParams;
 1359|  47.3k|    SECKEYPQGParams *dsaParams;
 1360|  47.3k|    SECKEYDHParams *dhParams;
 1361|  47.3k|    CK_NSS_KEM_PARAMETER_SET_TYPE *kemParams;
 1362|  47.3k|    CK_MECHANISM mechanism;
 1363|  47.3k|    CK_MECHANISM test_mech;
 1364|  47.3k|    CK_MECHANISM test_mech2;
 1365|  47.3k|    CK_SESSION_HANDLE session_handle;
 1366|  47.3k|    CK_RV crv;
 1367|  47.3k|    CK_OBJECT_HANDLE privID, pubID;
 1368|  47.3k|    SECKEYPrivateKey *privKey;
 1369|  47.3k|    KeyType keyType;
 1370|  47.3k|    PRBool restore;
 1371|  47.3k|    int peCount, i;
 1372|  47.3k|    CK_ATTRIBUTE *attrs;
 1373|  47.3k|    CK_ATTRIBUTE *privattrs;
 1374|  47.3k|    CK_ATTRIBUTE setTemplate;
 1375|  47.3k|    CK_MECHANISM_INFO mechanism_info;
 1376|  47.3k|    CK_OBJECT_CLASS keyClass;
 1377|  47.3k|    SECItem *cka_id;
 1378|  47.3k|    PRBool haslock = PR_FALSE;
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 1379|  47.3k|    PRBool pubIsToken = PR_FALSE;
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 1380|  47.3k|    PRBool token = ((attrFlags & PK11_ATTR_TOKEN) != 0);
  ------------------
  |  |  194|  47.3k|#define PK11_ATTR_TOKEN 0x00000001L
  ------------------
 1381|       |    /* subset of attrFlags applicable to the public key */
 1382|  47.3k|    PK11AttrFlags pubKeyAttrFlags = attrFlags &
 1383|  47.3k|                                    (PK11_ATTR_TOKEN | PK11_ATTR_SESSION | PK11_ATTR_MODIFIABLE | PK11_ATTR_UNMODIFIABLE);
  ------------------
  |  |  194|  47.3k|#define PK11_ATTR_TOKEN 0x00000001L
  ------------------
                                                  (PK11_ATTR_TOKEN | PK11_ATTR_SESSION | PK11_ATTR_MODIFIABLE | PK11_ATTR_UNMODIFIABLE);
  ------------------
  |  |  195|  47.3k|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
                                                  (PK11_ATTR_TOKEN | PK11_ATTR_SESSION | PK11_ATTR_MODIFIABLE | PK11_ATTR_UNMODIFIABLE);
  ------------------
  |  |  235|  47.3k|#define PK11_ATTR_MODIFIABLE 0x00000010L
  ------------------
                                                  (PK11_ATTR_TOKEN | PK11_ATTR_SESSION | PK11_ATTR_MODIFIABLE | PK11_ATTR_UNMODIFIABLE);
  ------------------
  |  |  236|  47.3k|#define PK11_ATTR_UNMODIFIABLE 0x00000020L
  ------------------
 1384|       |
 1385|  47.3k|    if (pk11_BadAttrFlags(attrFlags)) {
  ------------------
  |  Branch (1385:9): [True: 0, False: 47.3k]
  ------------------
 1386|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1387|      0|        return NULL;
 1388|      0|    }
 1389|       |
 1390|  47.3k|    if (!param) {
  ------------------
  |  Branch (1390:9): [True: 0, False: 47.3k]
  ------------------
 1391|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1392|      0|        return NULL;
 1393|      0|    }
 1394|       |
 1395|       |    /*
 1396|       |     * The opFlags and opFlagMask parameters allow us to control the
 1397|       |     * settings of the key usage attributes (CKA_ENCRYPT and friends).
 1398|       |     * opFlagMask is set to one if the flag is specified in opFlags and
 1399|       |     *  zero if it is to take on a default value calculated by
 1400|       |     *  PK11_GenerateKeyPairWithOpFlags.
 1401|       |     * opFlags specifies the actual value of the flag 1 or 0.
 1402|       |     *   Bits not corresponding to one bits in opFlagMask should be zero.
 1403|       |     */
 1404|       |
 1405|       |    /* if we are trying to turn on a flag, it better be in the mask */
 1406|  47.3k|    PORT_Assert((opFlags & ~opFlagsMask) == 0);
  ------------------
  |  |  120|  47.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  47.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 47.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1407|  47.3k|    opFlags &= opFlagsMask;
 1408|       |
 1409|  47.3k|    PORT_Assert(slot != NULL);
  ------------------
  |  |  120|  47.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  47.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 47.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1410|  47.3k|    if (slot == NULL) {
  ------------------
  |  Branch (1410:9): [True: 0, False: 47.3k]
  ------------------
 1411|      0|        PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1412|      0|        return NULL;
 1413|      0|    }
 1414|       |
 1415|       |    /* if our slot really doesn't do this mechanism, Generate the key
 1416|       |     * in our internal token and write it out */
 1417|  47.3k|    if (!PK11_DoesMechanism(slot, type)) {
  ------------------
  |  Branch (1417:9): [True: 0, False: 47.3k]
  ------------------
 1418|      0|        PK11SlotInfo *int_slot = PK11_GetInternalSlot();
 1419|       |
 1420|       |        /* don't loop forever looking for a slot */
 1421|      0|        if (slot == int_slot) {
  ------------------
  |  Branch (1421:13): [True: 0, False: 0]
  ------------------
 1422|      0|            PK11_FreeSlot(int_slot);
 1423|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1424|      0|            return NULL;
 1425|      0|        }
 1426|       |
 1427|       |        /* if there isn't a suitable slot, then we can't do the keygen */
 1428|      0|        if (int_slot == NULL) {
  ------------------
  |  Branch (1428:13): [True: 0, False: 0]
  ------------------
 1429|      0|            PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1430|      0|            return NULL;
 1431|      0|        }
 1432|       |
 1433|       |        /* generate the temporary key to load */
 1434|      0|        privKey = PK11_GenerateKeyPair(int_slot, type, param, pubKey, PR_FALSE,
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1435|      0|                                       PR_FALSE, wincx);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1436|      0|        PK11_FreeSlot(int_slot);
 1437|       |
 1438|       |        /* if successful, load the temp key into the new token */
 1439|      0|        if (privKey != NULL) {
  ------------------
  |  Branch (1439:13): [True: 0, False: 0]
  ------------------
 1440|      0|            SECKEYPrivateKey *newPrivKey = pk11_loadPrivKeyWithFlags(slot,
 1441|      0|                                                                     privKey, *pubKey, attrFlags);
 1442|      0|            SECKEY_DestroyPrivateKey(privKey);
 1443|      0|            if (newPrivKey == NULL) {
  ------------------
  |  Branch (1443:17): [True: 0, False: 0]
  ------------------
 1444|      0|                SECKEY_DestroyPublicKey(*pubKey);
 1445|      0|                *pubKey = NULL;
 1446|      0|            }
 1447|      0|            return newPrivKey;
 1448|      0|        }
 1449|      0|        return NULL;
 1450|      0|    }
 1451|       |
 1452|  47.3k|    mechanism.mechanism = type;
 1453|  47.3k|    mechanism.pParameter = NULL;
 1454|  47.3k|    mechanism.ulParameterLen = 0;
 1455|  47.3k|    test_mech.pParameter = NULL;
 1456|  47.3k|    test_mech.ulParameterLen = 0;
 1457|  47.3k|    test_mech2.mechanism = CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|  47.3k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
 1458|  47.3k|    test_mech2.pParameter = NULL;
 1459|  47.3k|    test_mech2.ulParameterLen = 0;
 1460|       |
 1461|       |    /* set up the private key template */
 1462|  47.3k|    privattrs = privTemplate;
 1463|  47.3k|    privattrs += pk11_AttrFlagsToAttributes(attrFlags, privattrs,
 1464|  47.3k|                                            &cktrue, &ckfalse);
 1465|       |
 1466|       |    /* set up the mechanism specific info */
 1467|  47.3k|    switch (type) {
 1468|      0|        case CKM_RSA_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  719|      0|#define CKM_RSA_PKCS_KEY_PAIR_GEN 0x00000000UL
  ------------------
  |  Branch (1468:9): [True: 0, False: 47.3k]
  ------------------
 1469|      0|        case CKM_RSA_X9_31_KEY_PAIR_GEN:
  ------------------
  |  |  738|      0|#define CKM_RSA_X9_31_KEY_PAIR_GEN 0x0000000AUL
  ------------------
  |  Branch (1469:9): [True: 0, False: 47.3k]
  ------------------
 1470|      0|            rsaParams = (PK11RSAGenParams *)param;
 1471|      0|            if (rsaParams->pe == 0) {
  ------------------
  |  Branch (1471:17): [True: 0, False: 0]
  ------------------
 1472|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1473|      0|                return NULL;
 1474|      0|            }
 1475|      0|            modulusBits = rsaParams->keySizeInBits;
 1476|      0|            peCount = 0;
 1477|       |
 1478|       |            /* convert pe to a PKCS #11 string */
 1479|      0|            for (i = 0; i < 4; i++) {
  ------------------
  |  Branch (1479:25): [True: 0, False: 0]
  ------------------
 1480|      0|                if (peCount || (rsaParams->pe &
  ------------------
  |  Branch (1480:21): [True: 0, False: 0]
  |  Branch (1480:32): [True: 0, False: 0]
  ------------------
 1481|      0|                                ((unsigned long)0xff000000L >> (i * 8)))) {
 1482|      0|                    publicExponent[peCount] =
 1483|      0|                        (CK_BYTE)((rsaParams->pe >> (3 - i) * 8) & 0xff);
 1484|      0|                    peCount++;
 1485|      0|                }
 1486|      0|            }
 1487|      0|            PORT_Assert(peCount != 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1488|      0|            attrs = rsaPubTemplate;
 1489|      0|            PK11_SETATTRS(attrs, CKA_MODULUS_BITS,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1490|      0|                          &modulusBits, sizeof(modulusBits));
 1491|      0|            attrs++;
 1492|      0|            PK11_SETATTRS(attrs, CKA_PUBLIC_EXPONENT,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1493|      0|                          publicExponent, peCount);
 1494|      0|            attrs++;
 1495|      0|            pubTemplate = rsaPubTemplate;
 1496|      0|            keyType = rsaKey;
 1497|      0|            test_mech.mechanism = CKM_RSA_PKCS;
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
 1498|      0|            break;
 1499|      0|        case CKM_DSA_KEY_PAIR_GEN:
  ------------------
  |  |  744|      0|#define CKM_DSA_KEY_PAIR_GEN 0x00000010UL
  ------------------
  |  Branch (1499:9): [True: 0, False: 47.3k]
  ------------------
 1500|      0|            dsaParams = (SECKEYPQGParams *)param;
 1501|      0|            attrs = dsaPubTemplate;
 1502|      0|            PK11_SETATTRS(attrs, CKA_PRIME, dsaParams->prime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1503|      0|                          dsaParams->prime.len);
 1504|      0|            attrs++;
 1505|      0|            PK11_SETATTRS(attrs, CKA_SUBPRIME, dsaParams->subPrime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1506|      0|                          dsaParams->subPrime.len);
 1507|      0|            attrs++;
 1508|      0|            PK11_SETATTRS(attrs, CKA_BASE, dsaParams->base.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1509|      0|                          dsaParams->base.len);
 1510|      0|            attrs++;
 1511|      0|            pubTemplate = dsaPubTemplate;
 1512|      0|            keyType = dsaKey;
 1513|      0|            test_mech.mechanism = CKM_DSA;
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
 1514|      0|            break;
 1515|  29.0k|        case CKM_DH_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  758|  29.0k|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  |  Branch (1515:9): [True: 29.0k, False: 18.2k]
  ------------------
 1516|  29.0k|            dhParams = (SECKEYDHParams *)param;
 1517|  29.0k|            attrs = dhPubTemplate;
 1518|  29.0k|            PK11_SETATTRS(attrs, CKA_PRIME, dhParams->prime.data,
  ------------------
  |  |  104|  29.0k|    (x)->type = (id);              \
  |  |  105|  29.0k|    (x)->pValue = (v);             \
  |  |  106|  29.0k|    (x)->ulValueLen = (l);
  ------------------
 1519|  29.0k|                          dhParams->prime.len);
 1520|  29.0k|            attrs++;
 1521|  29.0k|            PK11_SETATTRS(attrs, CKA_BASE, dhParams->base.data,
  ------------------
  |  |  104|  29.0k|    (x)->type = (id);              \
  |  |  105|  29.0k|    (x)->pValue = (v);             \
  |  |  106|  29.0k|    (x)->ulValueLen = (l);
  ------------------
 1522|  29.0k|                          dhParams->base.len);
 1523|  29.0k|            attrs++;
 1524|  29.0k|            pubTemplate = dhPubTemplate;
 1525|  29.0k|            keyType = dhKey;
 1526|  29.0k|            test_mech.mechanism = CKM_DH_PKCS_DERIVE;
  ------------------
  |  |  759|  29.0k|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
 1527|  29.0k|            break;
 1528|      1|        case CKM_EC_KEY_PAIR_GEN:
  ------------------
  |  | 1072|      1|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  |  Branch (1528:9): [True: 1, False: 47.3k]
  ------------------
 1529|  18.2k|        case CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN:
  ------------------
  |  |  274|  18.2k|#define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN (CKM_NSS + 47)
  |  |  ------------------
  |  |  |  |  162|  18.2k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  18.2k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  18.2k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1529:9): [True: 18.2k, False: 29.0k]
  ------------------
 1530|  18.2k|            ecParams = (SECKEYECParams *)param;
 1531|  18.2k|            attrs = ecPubTemplate;
 1532|  18.2k|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, ecParams->data,
  ------------------
  |  |  104|  18.2k|    (x)->type = (id);              \
  |  |  105|  18.2k|    (x)->pValue = (v);             \
  |  |  106|  18.2k|    (x)->ulValueLen = (l);
  ------------------
 1533|  18.2k|                          ecParams->len);
 1534|  18.2k|            attrs++;
 1535|  18.2k|            pubTemplate = ecPubTemplate;
 1536|  18.2k|            keyType = ecKey;
 1537|       |            /*
 1538|       |             * ECC supports 2 different mechanism types (unlike RSA, which
 1539|       |             * supports different usages with the same mechanism).
 1540|       |             * We may need to query both mechanism types and or the results
 1541|       |             * together -- but we only do that if either the user has
 1542|       |             * requested both usages, or not specified any usages.
 1543|       |             */
 1544|  18.2k|            if ((opFlags & (CKF_SIGN | CKF_DERIVE)) == (CKF_SIGN | CKF_DERIVE)) {
  ------------------
  |  | 1356|  18.2k|#define CKF_SIGN 0x00000800UL
  ------------------
                          if ((opFlags & (CKF_SIGN | CKF_DERIVE)) == (CKF_SIGN | CKF_DERIVE)) {
  ------------------
  |  | 1364|  18.2k|#define CKF_DERIVE 0x00080000UL
  ------------------
                          if ((opFlags & (CKF_SIGN | CKF_DERIVE)) == (CKF_SIGN | CKF_DERIVE)) {
  ------------------
  |  | 1356|  18.2k|#define CKF_SIGN 0x00000800UL
  ------------------
                          if ((opFlags & (CKF_SIGN | CKF_DERIVE)) == (CKF_SIGN | CKF_DERIVE)) {
  ------------------
  |  | 1364|  18.2k|#define CKF_DERIVE 0x00080000UL
  ------------------
  |  Branch (1544:17): [True: 0, False: 18.2k]
  ------------------
 1545|       |                /* We've explicitly turned on both flags, use both mechanism */
 1546|      0|                test_mech.mechanism = CKM_ECDH1_DERIVE;
  ------------------
  |  | 1086|      0|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
 1547|      0|                test_mech2.mechanism = CKM_ECDSA;
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
 1548|  18.2k|            } else if (opFlags & CKF_SIGN) {
  ------------------
  |  | 1356|  18.2k|#define CKF_SIGN 0x00000800UL
  ------------------
  |  Branch (1548:24): [True: 0, False: 18.2k]
  ------------------
 1549|       |                /* just do signing */
 1550|      0|                test_mech.mechanism = CKM_ECDSA;
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
 1551|  18.2k|            } else if (opFlags & CKF_DERIVE) {
  ------------------
  |  | 1364|  18.2k|#define CKF_DERIVE 0x00080000UL
  ------------------
  |  Branch (1551:24): [True: 18.2k, False: 0]
  ------------------
 1552|       |                /* just do ECDH */
 1553|  18.2k|                test_mech.mechanism = CKM_ECDH1_DERIVE;
  ------------------
  |  | 1086|  18.2k|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
 1554|  18.2k|            } else {
 1555|       |                /* neither was specified default to both */
 1556|      0|                test_mech.mechanism = CKM_ECDH1_DERIVE;
  ------------------
  |  | 1086|      0|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
 1557|      0|                test_mech2.mechanism = CKM_ECDSA;
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
 1558|      0|            }
 1559|  18.2k|            break;
 1560|      0|        case CKM_NSS_KYBER_KEY_PAIR_GEN:
  ------------------
  |  |  267|      0|#define CKM_NSS_KYBER_KEY_PAIR_GEN (CKM_NSS + 45)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1560:9): [True: 0, False: 47.3k]
  ------------------
 1561|      0|            kemParams = (CK_NSS_KEM_PARAMETER_SET_TYPE *)param;
 1562|      0|            attrs = kyberPubTemplate;
 1563|      0|            PK11_SETATTRS(attrs, CKA_NSS_PARAMETER_SET,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1564|      0|                          kemParams,
 1565|      0|                          sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE));
 1566|      0|            attrs++;
 1567|      0|            pubTemplate = kyberPubTemplate;
 1568|      0|            keyType = kyberKey;
 1569|      0|            test_mech.mechanism = CKM_NSS_KYBER;
  ------------------
  |  |  268|      0|#define CKM_NSS_KYBER (CKM_NSS + 46)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1570|      0|            break;
 1571|      0|        case CKM_NSS_ML_KEM_KEY_PAIR_GEN:
  ------------------
  |  |  277|      0|#define CKM_NSS_ML_KEM_KEY_PAIR_GEN (CKM_NSS + 48)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1571:9): [True: 0, False: 47.3k]
  ------------------
 1572|      0|            kemParams = (CK_NSS_KEM_PARAMETER_SET_TYPE *)param;
 1573|      0|            attrs = kyberPubTemplate;
 1574|      0|            PK11_SETATTRS(attrs, CKA_NSS_PARAMETER_SET,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1575|      0|                          kemParams,
 1576|      0|                          sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE));
 1577|      0|            attrs++;
 1578|      0|            pubTemplate = kyberPubTemplate;
 1579|      0|            keyType = kyberKey;
 1580|      0|            test_mech.mechanism = CKM_NSS_ML_KEM;
  ------------------
  |  |  278|      0|#define CKM_NSS_ML_KEM (CKM_NSS + 49)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1581|      0|            break;
 1582|      0|        case CKM_EC_MONTGOMERY_KEY_PAIR_GEN:
  ------------------
  |  | 1173|      0|#define CKM_EC_MONTGOMERY_KEY_PAIR_GEN 0x00001056UL
  ------------------
  |  Branch (1582:9): [True: 0, False: 47.3k]
  ------------------
 1583|      0|            ecParams = (SECKEYECParams *)param;
 1584|      0|            attrs = ecPubTemplate;
 1585|      0|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, ecParams->data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1586|      0|                          ecParams->len);
 1587|      0|            attrs++;
 1588|      0|            pubTemplate = ecPubTemplate;
 1589|      0|            keyType = ecMontKey;
 1590|      0|            test_mech.mechanism = CKM_ECDH1_DERIVE;
  ------------------
  |  | 1086|      0|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
 1591|      0|            break;
 1592|      0|        case CKM_EC_EDWARDS_KEY_PAIR_GEN:
  ------------------
  |  | 1172|      0|#define CKM_EC_EDWARDS_KEY_PAIR_GEN 0x00001055UL
  ------------------
  |  Branch (1592:9): [True: 0, False: 47.3k]
  ------------------
 1593|      0|            ecParams = (SECKEYECParams *)param;
 1594|      0|            attrs = ecPubTemplate;
 1595|      0|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, ecParams->data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1596|      0|                          ecParams->len);
 1597|      0|            attrs++;
 1598|      0|            pubTemplate = ecPubTemplate;
 1599|      0|            keyType = edKey;
 1600|      0|            test_mech.mechanism = CKM_EDDSA;
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
 1601|      0|            break;
 1602|      0|        default:
  ------------------
  |  Branch (1602:9): [True: 0, False: 47.3k]
  ------------------
 1603|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1604|      0|            return NULL;
 1605|  47.3k|    }
 1606|       |
 1607|       |    /* now query the slot to find out how "good" a key we can generate */
 1608|  47.3k|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1608:9): [True: 0, False: 47.3k]
  ------------------
 1609|      0|        PK11_EnterSlotMonitor(slot);
 1610|  47.3k|    crv = PK11_GETTAB(slot)->C_GetMechanismInfo(slot->slotID,
  ------------------
  |  |  102|  47.3k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1611|  47.3k|                                                test_mech.mechanism, &mechanism_info);
 1612|       |    /*
 1613|       |     * EC keys are used in multiple different types of mechanism, if we
 1614|       |     * are using dual use keys, we need to query the second mechanism
 1615|       |     * as well.
 1616|       |     */
 1617|  47.3k|    if (test_mech2.mechanism != CKM_INVALID_MECHANISM) {
  ------------------
  |  |  155|  47.3k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  |  Branch (1617:9): [True: 0, False: 47.3k]
  ------------------
 1618|      0|        CK_MECHANISM_INFO mechanism_info2;
 1619|      0|        CK_RV crv2;
 1620|       |
 1621|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1621:13): [True: 0, False: 0]
  ------------------
 1622|       |            /* the first failed, make sure there is no trash in the
 1623|       |             * mechanism flags when we or it below */
 1624|      0|            mechanism_info.flags = 0;
 1625|      0|        }
 1626|      0|        crv2 = PK11_GETTAB(slot)->C_GetMechanismInfo(slot->slotID,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1627|      0|                                                     test_mech2.mechanism, &mechanism_info2);
 1628|      0|        if (crv2 == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1628:13): [True: 0, False: 0]
  ------------------
 1629|      0|            crv = CKR_OK; /* succeed if either mechnaism info succeeds */
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 1630|       |            /* combine the 2 sets of mechnanism flags */
 1631|      0|            mechanism_info.flags |= mechanism_info2.flags;
 1632|      0|        }
 1633|      0|    }
 1634|  47.3k|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1634:9): [True: 0, False: 47.3k]
  ------------------
 1635|      0|        PK11_ExitSlotMonitor(slot);
 1636|  47.3k|    if ((crv != CKR_OK) || (mechanism_info.flags == 0)) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1636:9): [True: 0, False: 47.3k]
  |  Branch (1636:28): [True: 0, False: 47.3k]
  ------------------
 1637|       |        /* must be old module... guess what it should be... */
 1638|      0|        switch (test_mech.mechanism) {
 1639|      0|            case CKM_RSA_PKCS:
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (1639:13): [True: 0, False: 0]
  ------------------
 1640|      0|                mechanism_info.flags = (CKF_SIGN | CKF_DECRYPT |
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
                              mechanism_info.flags = (CKF_SIGN | CKF_DECRYPT |
  ------------------
  |  | 1354|      0|#define CKF_DECRYPT 0x00000200UL
  ------------------
 1641|      0|                                        CKF_WRAP | CKF_VERIFY_RECOVER | CKF_ENCRYPT | CKF_WRAP);
  ------------------
  |  | 1362|      0|#define CKF_WRAP 0x00020000UL
  ------------------
                                                      CKF_WRAP | CKF_VERIFY_RECOVER | CKF_ENCRYPT | CKF_WRAP);
  ------------------
  |  | 1359|      0|#define CKF_VERIFY_RECOVER 0x00004000UL
  ------------------
                                                      CKF_WRAP | CKF_VERIFY_RECOVER | CKF_ENCRYPT | CKF_WRAP);
  ------------------
  |  | 1353|      0|#define CKF_ENCRYPT 0x00000100UL
  ------------------
                                                      CKF_WRAP | CKF_VERIFY_RECOVER | CKF_ENCRYPT | CKF_WRAP);
  ------------------
  |  | 1362|      0|#define CKF_WRAP 0x00020000UL
  ------------------
 1642|      0|                break;
 1643|      0|            case CKM_DSA:
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (1643:13): [True: 0, False: 0]
  ------------------
 1644|      0|                mechanism_info.flags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
                              mechanism_info.flags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|      0|#define CKF_VERIFY 0x00002000
  ------------------
 1645|      0|                break;
 1646|      0|            case CKM_DH_PKCS_DERIVE:
  ------------------
  |  |  759|      0|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
  |  Branch (1646:13): [True: 0, False: 0]
  ------------------
 1647|      0|                mechanism_info.flags = CKF_DERIVE;
  ------------------
  |  | 1364|      0|#define CKF_DERIVE 0x00080000UL
  ------------------
 1648|      0|                break;
 1649|      0|            case CKM_ECDH1_DERIVE:
  ------------------
  |  | 1086|      0|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  |  Branch (1649:13): [True: 0, False: 0]
  ------------------
 1650|      0|                mechanism_info.flags = CKF_DERIVE;
  ------------------
  |  | 1364|      0|#define CKF_DERIVE 0x00080000UL
  ------------------
 1651|      0|                if (test_mech2.mechanism == CKM_ECDSA) {
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (1651:21): [True: 0, False: 0]
  ------------------
 1652|      0|                    mechanism_info.flags |= CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
                                  mechanism_info.flags |= CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|      0|#define CKF_VERIFY 0x00002000
  ------------------
 1653|      0|                }
 1654|      0|                break;
 1655|      0|            case CKM_ECDSA:
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (1655:13): [True: 0, False: 0]
  ------------------
 1656|      0|                mechanism_info.flags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
                              mechanism_info.flags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|      0|#define CKF_VERIFY 0x00002000
  ------------------
 1657|      0|                break;
 1658|      0|            case CKM_EDDSA:
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
  |  Branch (1658:13): [True: 0, False: 0]
  ------------------
 1659|      0|                mechanism_info.flags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
                              mechanism_info.flags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|      0|#define CKF_VERIFY 0x00002000
  ------------------
 1660|      0|                break;
 1661|       |
 1662|      0|            default:
  ------------------
  |  Branch (1662:13): [True: 0, False: 0]
  ------------------
 1663|      0|                break;
 1664|      0|        }
 1665|      0|    }
 1666|       |    /* now adjust our flags according to the user's key usage passed to us */
 1667|  47.3k|    mechanism_info.flags = (mechanism_info.flags & (~opFlagsMask)) | opFlags;
 1668|       |    /* set the public key attributes */
 1669|  47.3k|    attrs += pk11_AttrFlagsToAttributes(pubKeyAttrFlags, attrs,
 1670|  47.3k|                                        &cktrue, &ckfalse);
 1671|  47.3k|    PK11_SETATTRS(attrs, CKA_DERIVE,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 47.3k, False: 0]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1672|  47.3k|                  mechanism_info.flags & CKF_DERIVE ? &cktrue : &ckfalse,
 1673|  47.3k|                  sizeof(CK_BBOOL));
 1674|  47.3k|    attrs++;
 1675|  47.3k|    PK11_SETATTRS(attrs, CKA_WRAP,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1676|  47.3k|                  mechanism_info.flags & CKF_WRAP ? &cktrue : &ckfalse,
 1677|  47.3k|                  sizeof(CK_BBOOL));
 1678|  47.3k|    attrs++;
 1679|  47.3k|    PK11_SETATTRS(attrs, CKA_VERIFY,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1680|  47.3k|                  mechanism_info.flags & CKF_VERIFY ? &cktrue : &ckfalse,
 1681|  47.3k|                  sizeof(CK_BBOOL));
 1682|  47.3k|    attrs++;
 1683|  47.3k|    PK11_SETATTRS(attrs, CKA_VERIFY_RECOVER,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1684|  47.3k|                  mechanism_info.flags & CKF_VERIFY_RECOVER ? &cktrue : &ckfalse,
 1685|  47.3k|                  sizeof(CK_BBOOL));
 1686|  47.3k|    attrs++;
 1687|  47.3k|    PK11_SETATTRS(attrs, CKA_ENCRYPT,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1688|  47.3k|                  mechanism_info.flags & CKF_ENCRYPT ? &cktrue : &ckfalse,
 1689|  47.3k|                  sizeof(CK_BBOOL));
 1690|  47.3k|    attrs++;
 1691|       |    /* set the private key attributes */
 1692|  47.3k|    PK11_SETATTRS(privattrs, CKA_DERIVE,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 47.3k, False: 0]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1693|  47.3k|                  mechanism_info.flags & CKF_DERIVE ? &cktrue : &ckfalse,
 1694|  47.3k|                  sizeof(CK_BBOOL));
 1695|  47.3k|    privattrs++;
 1696|  47.3k|    PK11_SETATTRS(privattrs, CKA_UNWRAP,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1697|  47.3k|                  mechanism_info.flags & CKF_UNWRAP ? &cktrue : &ckfalse,
 1698|  47.3k|                  sizeof(CK_BBOOL));
 1699|  47.3k|    privattrs++;
 1700|  47.3k|    PK11_SETATTRS(privattrs, CKA_SIGN,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1701|  47.3k|                  mechanism_info.flags & CKF_SIGN ? &cktrue : &ckfalse,
 1702|  47.3k|                  sizeof(CK_BBOOL));
 1703|  47.3k|    privattrs++;
 1704|  47.3k|    PK11_SETATTRS(privattrs, CKA_DECRYPT,
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  94.7k|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1705|  47.3k|                  mechanism_info.flags & CKF_DECRYPT ? &cktrue : &ckfalse,
 1706|  47.3k|                  sizeof(CK_BBOOL));
 1707|  47.3k|    privattrs++;
 1708|       |
 1709|  47.3k|    if (token) {
  ------------------
  |  Branch (1709:9): [True: 0, False: 47.3k]
  ------------------
 1710|      0|        session_handle = PK11_GetRWSession(slot);
 1711|      0|        haslock = PK11_RWSessionHasLock(slot, session_handle);
 1712|      0|        restore = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1713|  47.3k|    } else {
 1714|  47.3k|        session_handle = slot->session;
 1715|  47.3k|        if (session_handle != CK_INVALID_HANDLE)
  ------------------
  |  |   78|  47.3k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1715:13): [True: 47.3k, False: 0]
  ------------------
 1716|  47.3k|            PK11_EnterSlotMonitor(slot);
 1717|  47.3k|        restore = PR_FALSE;
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 1718|  47.3k|        haslock = PR_TRUE;
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
 1719|  47.3k|    }
 1720|       |
 1721|  47.3k|    if (session_handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  47.3k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1721:9): [True: 0, False: 47.3k]
  ------------------
 1722|      0|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1723|      0|        return NULL;
 1724|      0|    }
 1725|  47.3k|    privCount = privattrs - privTemplate;
 1726|  47.3k|    pubCount = attrs - pubTemplate;
 1727|  47.3k|    crv = PK11_GETTAB(slot)->C_GenerateKeyPair(session_handle, &mechanism,
  ------------------
  |  |  102|  47.3k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1728|  47.3k|                                               pubTemplate, pubCount, privTemplate, privCount, &pubID, &privID);
 1729|       |
 1730|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1730:9): [True: 44, False: 47.3k]
  ------------------
 1731|     44|        if (restore) {
  ------------------
  |  Branch (1731:13): [True: 0, False: 44]
  ------------------
 1732|      0|            PK11_RestoreROSession(slot, session_handle);
 1733|      0|        } else
 1734|     44|            PK11_ExitSlotMonitor(slot);
 1735|     44|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|     44|#define PORT_SetError PORT_SetError_Util
  ------------------
 1736|     44|        return NULL;
 1737|     44|    }
 1738|       |    /* This locking code is dangerous and needs to be more thought
 1739|       |     * out... the real problem is that we're holding the mutex open this long
 1740|       |     */
 1741|  47.3k|    if (haslock) {
  ------------------
  |  Branch (1741:9): [True: 47.3k, False: 0]
  ------------------
 1742|  47.3k|        PK11_ExitSlotMonitor(slot);
 1743|  47.3k|    }
 1744|       |
 1745|       |    /* swap around the ID's for older PKCS #11 modules */
 1746|  47.3k|    keyClass = PK11_ReadULongAttribute(slot, pubID, CKA_CLASS);
  ------------------
  |  |  511|  47.3k|#define CKA_CLASS 0x00000000UL
  ------------------
 1747|  47.3k|    if (keyClass != CKO_PUBLIC_KEY) {
  ------------------
  |  |  327|  47.3k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  |  Branch (1747:9): [True: 0, False: 47.3k]
  ------------------
 1748|      0|        CK_OBJECT_HANDLE tmp = pubID;
 1749|      0|        pubID = privID;
 1750|      0|        privID = tmp;
 1751|      0|    }
 1752|       |
 1753|  47.3k|    *pubKey = PK11_ExtractPublicKey(slot, keyType, pubID);
 1754|  47.3k|    if (*pubKey == NULL) {
  ------------------
  |  Branch (1754:9): [True: 0, False: 47.3k]
  ------------------
 1755|      0|        if (restore) {
  ------------------
  |  Branch (1755:13): [True: 0, False: 0]
  ------------------
 1756|       |            /* we may have to restore the mutex so it get's exited properly
 1757|       |             * in RestoreROSession */
 1758|      0|            if (haslock)
  ------------------
  |  Branch (1758:17): [True: 0, False: 0]
  ------------------
 1759|      0|                PK11_EnterSlotMonitor(slot);
 1760|      0|            PK11_RestoreROSession(slot, session_handle);
 1761|      0|        }
 1762|      0|        PK11_DestroyObject(slot, pubID);
 1763|      0|        PK11_DestroyObject(slot, privID);
 1764|      0|        return NULL;
 1765|      0|    }
 1766|       |
 1767|       |    /* set the ID to the public key so we can find it again */
 1768|  47.3k|    cka_id = pk11_MakeIDFromPublicKey(*pubKey);
 1769|  47.3k|    pubIsToken = (PRBool)PK11_HasAttributeSet(slot, pubID, CKA_TOKEN, PR_FALSE);
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
                  pubIsToken = (PRBool)PK11_HasAttributeSet(slot, pubID, CKA_TOKEN, PR_FALSE);
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 1770|       |
 1771|  47.3k|    PK11_SETATTRS(&setTemplate, CKA_ID, cka_id->data, cka_id->len);
  ------------------
  |  |  104|  47.3k|    (x)->type = (id);              \
  |  |  105|  47.3k|    (x)->pValue = (v);             \
  |  |  106|  47.3k|    (x)->ulValueLen = (l);
  ------------------
 1772|       |
 1773|  47.3k|    if (haslock) {
  ------------------
  |  Branch (1773:9): [True: 47.3k, False: 0]
  ------------------
 1774|  47.3k|        PK11_EnterSlotMonitor(slot);
 1775|  47.3k|    }
 1776|  47.3k|    crv = PK11_GETTAB(slot)->C_SetAttributeValue(session_handle, privID,
  ------------------
  |  |  102|  47.3k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1777|  47.3k|                                                 &setTemplate, 1);
 1778|       |
 1779|  47.3k|    if (crv == CKR_OK && pubIsToken) {
  ------------------
  |  | 1388|  94.6k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1779:9): [True: 47.3k, False: 0]
  |  Branch (1779:26): [True: 0, False: 47.3k]
  ------------------
 1780|      0|        crv = PK11_GETTAB(slot)->C_SetAttributeValue(session_handle, pubID,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1781|      0|                                                     &setTemplate, 1);
 1782|      0|    }
 1783|       |
 1784|  47.3k|    if (restore) {
  ------------------
  |  Branch (1784:9): [True: 0, False: 47.3k]
  ------------------
 1785|      0|        PK11_RestoreROSession(slot, session_handle);
 1786|  47.3k|    } else {
 1787|  47.3k|        PK11_ExitSlotMonitor(slot);
 1788|  47.3k|    }
 1789|  47.3k|    SECITEM_FreeItem(cka_id, PR_TRUE);
  ------------------
  |  |  108|  47.3k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(cka_id, PR_TRUE);
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
 1790|       |
 1791|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1791:9): [True: 0, False: 47.3k]
  ------------------
 1792|      0|        PK11_DestroyObject(slot, pubID);
 1793|      0|        PK11_DestroyObject(slot, privID);
 1794|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1795|      0|        *pubKey = NULL;
 1796|      0|        return NULL;
 1797|      0|    }
 1798|       |
 1799|  47.3k|    privKey = PK11_MakePrivKey(slot, keyType, !token, privID, wincx);
 1800|  47.3k|    if (privKey == NULL) {
  ------------------
  |  Branch (1800:9): [True: 0, False: 47.3k]
  ------------------
 1801|      0|        SECKEY_DestroyPublicKey(*pubKey);
 1802|      0|        PK11_DestroyObject(slot, privID);
 1803|      0|        *pubKey = NULL;
 1804|      0|        return NULL;
 1805|      0|    }
 1806|       |
 1807|  47.3k|    return privKey;
 1808|  47.3k|}
PK11_GenerateKeyPairWithFlags:
 1813|  29.0k|{
 1814|  29.0k|    return PK11_GenerateKeyPairWithOpFlags(slot, type, param, pubKey, attrFlags,
 1815|  29.0k|                                           0, 0, wincx);
 1816|  29.0k|}
PK11_GenerateKeyPair:
 1825|  29.0k|{
 1826|  29.0k|    PK11AttrFlags attrFlags = 0;
 1827|       |
 1828|  29.0k|    if (token) {
  ------------------
  |  Branch (1828:9): [True: 0, False: 29.0k]
  ------------------
 1829|      0|        attrFlags |= PK11_ATTR_TOKEN;
  ------------------
  |  |  194|      0|#define PK11_ATTR_TOKEN 0x00000001L
  ------------------
 1830|  29.0k|    } else {
 1831|  29.0k|        attrFlags |= PK11_ATTR_SESSION;
  ------------------
  |  |  195|  29.0k|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
 1832|  29.0k|    }
 1833|  29.0k|    if (sensitive) {
  ------------------
  |  Branch (1833:9): [True: 0, False: 29.0k]
  ------------------
 1834|      0|        attrFlags |= (PK11_ATTR_SENSITIVE | PK11_ATTR_PRIVATE);
  ------------------
  |  |  260|      0|#define PK11_ATTR_SENSITIVE 0x00000040L
  ------------------
                      attrFlags |= (PK11_ATTR_SENSITIVE | PK11_ATTR_PRIVATE);
  ------------------
  |  |  216|      0|#define PK11_ATTR_PRIVATE 0x00000004L
  ------------------
 1835|  29.0k|    } else {
 1836|  29.0k|        attrFlags |= (PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC);
  ------------------
  |  |  261|  29.0k|#define PK11_ATTR_INSENSITIVE 0x00000080L
  ------------------
                      attrFlags |= (PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC);
  ------------------
  |  |  217|  29.0k|#define PK11_ATTR_PUBLIC 0x00000008L
  ------------------
 1837|  29.0k|    }
 1838|  29.0k|    return PK11_GenerateKeyPairWithFlags(slot, type, param, pubKey,
 1839|  29.0k|                                         attrFlags, wincx);
 1840|  29.0k|}
PK11_CopyTokenPrivKeyToSessionPrivKey:
 2467|      2|{
 2468|      2|    CK_RV crv;
 2469|      2|    CK_OBJECT_HANDLE newKeyID;
 2470|       |
 2471|      2|    static const CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|      2|#define CK_FALSE 0
  ------------------
 2472|      2|    static const CK_ATTRIBUTE template[1] = {
 2473|      2|        { CKA_TOKEN, (CK_BBOOL *)&ckfalse, sizeof ckfalse }
  ------------------
  |  |  512|      2|#define CKA_TOKEN 0x00000001UL
  ------------------
 2474|      2|    };
 2475|       |
 2476|      2|    if (destSlot && destSlot != privKey->pkcs11Slot) {
  ------------------
  |  Branch (2476:9): [True: 2, False: 0]
  |  Branch (2476:21): [True: 0, False: 2]
  ------------------
 2477|      0|        SECKEYPrivateKey *newKey =
 2478|      0|            pk11_loadPrivKey(destSlot,
 2479|      0|                             privKey,
 2480|      0|                             NULL,      /* pubKey    */
 2481|      0|                             PR_FALSE,  /* token     */
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2482|      0|                             PR_FALSE); /* sensitive */
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2483|      0|        if (newKey)
  ------------------
  |  Branch (2483:13): [True: 0, False: 0]
  ------------------
 2484|      0|            return newKey;
 2485|      0|    }
 2486|      2|    destSlot = privKey->pkcs11Slot;
 2487|      2|    PK11_Authenticate(destSlot, PR_TRUE, privKey->wincx);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 2488|      2|    PK11_EnterSlotMonitor(destSlot);
 2489|      2|    crv = PK11_GETTAB(destSlot)->C_CopyObject(destSlot->session,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2490|      2|                                              privKey->pkcs11ID,
 2491|      2|                                              (CK_ATTRIBUTE *)template,
 2492|      2|                                              1, &newKeyID);
 2493|      2|    PK11_ExitSlotMonitor(destSlot);
 2494|       |
 2495|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2495:9): [True: 0, False: 2]
  ------------------
 2496|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2497|      0|        return NULL;
 2498|      0|    }
 2499|       |
 2500|      2|    return PK11_MakePrivKey(destSlot, privKey->keyType, PR_TRUE /*isTemp*/,
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 2501|      2|                            newKeyID, privKey->wincx);
 2502|      2|}
PK11_MakeIDFromPubKey:
 2699|  47.3k|{
 2700|  47.3k|    PK11Context *context;
 2701|  47.3k|    SECItem *certCKA_ID;
 2702|  47.3k|    SECStatus rv;
 2703|       |
 2704|  47.3k|    if (pubKeyData->len <= SHA1_LENGTH) {
  ------------------
  |  |   39|  47.3k|#define SHA1_LENGTH 20
  ------------------
  |  Branch (2704:9): [True: 0, False: 47.3k]
  ------------------
 2705|       |        /* probably an already hashed value. The strongest known public
 2706|       |         * key values <= 160 bits would be less than 40 bit symetric in
 2707|       |         * strength. Don't hash them, just return the value. There are
 2708|       |         * none at the time of this writing supported by previous versions
 2709|       |         * of NSS, so change is binary compatible safe */
 2710|      0|        return SECITEM_DupItem(pubKeyData);
  ------------------
  |  |  107|      0|#define SECITEM_DupItem SECITEM_DupItem_Util
  ------------------
 2711|      0|    }
 2712|       |
 2713|  47.3k|    context = PK11_CreateDigestContext(SEC_OID_SHA1);
 2714|  47.3k|    if (context == NULL) {
  ------------------
  |  Branch (2714:9): [True: 0, False: 47.3k]
  ------------------
 2715|      0|        return NULL;
 2716|      0|    }
 2717|       |
 2718|  47.3k|    rv = PK11_DigestBegin(context);
 2719|  47.3k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (2719:9): [True: 47.3k, False: 0]
  ------------------
 2720|  47.3k|        rv = PK11_DigestOp(context, pubKeyData->data, pubKeyData->len);
 2721|  47.3k|    }
 2722|  47.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2722:9): [True: 0, False: 47.3k]
  ------------------
 2723|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2724|      0|        return NULL;
 2725|      0|    }
 2726|       |
 2727|  47.3k|    certCKA_ID = (SECItem *)PORT_Alloc(sizeof(SECItem));
  ------------------
  |  |   52|  47.3k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 2728|  47.3k|    if (certCKA_ID == NULL) {
  ------------------
  |  Branch (2728:9): [True: 0, False: 47.3k]
  ------------------
 2729|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2730|      0|        return NULL;
 2731|      0|    }
 2732|       |
 2733|  47.3k|    certCKA_ID->len = SHA1_LENGTH;
  ------------------
  |  |   39|  47.3k|#define SHA1_LENGTH 20
  ------------------
 2734|  47.3k|    certCKA_ID->data = (unsigned char *)PORT_Alloc(certCKA_ID->len);
  ------------------
  |  |   52|  47.3k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 2735|  47.3k|    if (certCKA_ID->data == NULL) {
  ------------------
  |  Branch (2735:9): [True: 0, False: 47.3k]
  ------------------
 2736|      0|        PORT_Free(certCKA_ID);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2737|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2738|      0|        return NULL;
 2739|      0|    }
 2740|       |
 2741|  47.3k|    rv = PK11_DigestFinal(context, certCKA_ID->data, &certCKA_ID->len,
 2742|  47.3k|                          SHA1_LENGTH);
  ------------------
  |  |   39|  47.3k|#define SHA1_LENGTH 20
  ------------------
 2743|  47.3k|    PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
 2744|  47.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2744:9): [True: 0, False: 47.3k]
  ------------------
 2745|      0|        SECITEM_FreeItem(certCKA_ID, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(certCKA_ID, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2746|      0|        return NULL;
 2747|      0|    }
 2748|       |
 2749|  47.3k|    return certCKA_ID;
 2750|  47.3k|}
pk11akey.c:pk11_MakeIDFromPublicKey:
   31|  47.3k|{
   32|       |    /* set the ID to the public key so we can find it again */
   33|  47.3k|    SECItem *pubKeyIndex = NULL;
   34|  47.3k|    switch (pubKey->keyType) {
   35|      0|        case rsaKey:
  ------------------
  |  Branch (35:9): [True: 0, False: 47.3k]
  ------------------
   36|      0|            pubKeyIndex = &pubKey->u.rsa.modulus;
   37|      0|            break;
   38|      0|        case dsaKey:
  ------------------
  |  Branch (38:9): [True: 0, False: 47.3k]
  ------------------
   39|      0|            pubKeyIndex = &pubKey->u.dsa.publicValue;
   40|      0|            break;
   41|  29.0k|        case dhKey:
  ------------------
  |  Branch (41:9): [True: 29.0k, False: 18.2k]
  ------------------
   42|  29.0k|            pubKeyIndex = &pubKey->u.dh.publicValue;
   43|  29.0k|            break;
   44|      0|        case edKey:
  ------------------
  |  Branch (44:9): [True: 0, False: 47.3k]
  ------------------
   45|  18.2k|        case ecKey:
  ------------------
  |  Branch (45:9): [True: 18.2k, False: 29.0k]
  ------------------
   46|  18.2k|        case ecMontKey:
  ------------------
  |  Branch (46:9): [True: 0, False: 47.3k]
  ------------------
   47|  18.2k|            pubKeyIndex = &pubKey->u.ec.publicValue;
   48|  18.2k|            break;
   49|      0|        case kyberKey:
  ------------------
  |  Branch (49:9): [True: 0, False: 47.3k]
  ------------------
   50|      0|            pubKeyIndex = &pubKey->u.kyber.publicValue;
   51|      0|            break;
   52|      0|        default:
  ------------------
  |  Branch (52:9): [True: 0, False: 47.3k]
  ------------------
   53|      0|            return NULL;
   54|  47.3k|    }
   55|  47.3k|    PORT_Assert(pubKeyIndex != NULL);
  ------------------
  |  |  120|  47.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  47.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 47.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   56|       |
   57|  47.3k|    return PK11_MakeIDFromPubKey(pubKeyIndex);
   58|  47.3k|}
pk11akey.c:pk11_Attr2SecItem:
  316|   112k|{
  317|   112k|    item->data = NULL;
  318|       |
  319|   112k|    (void)SECITEM_AllocItem(arena, item, attr->ulValueLen);
  ------------------
  |  |  103|   112k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  320|   112k|    if (item->data == NULL) {
  ------------------
  |  Branch (320:9): [True: 0, False: 112k]
  ------------------
  321|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  322|      0|    }
  323|   112k|    PORT_Memcpy(item->data, attr->pValue, item->len);
  ------------------
  |  |  180|   112k|#define PORT_Memcpy memcpy
  ------------------
  324|   112k|    return CKR_OK;
  ------------------
  |  | 1388|   112k|#define CKR_OK 0x00000000UL
  ------------------
  325|   112k|}
pk11akey.c:pk11_get_Decoded_ECPoint:
  465|  18.2k|{
  466|  18.2k|    SECItem encodedPublicValue;
  467|  18.2k|    SECStatus rv;
  468|  18.2k|    int keyLen;
  469|  18.2k|    PRBool plain = PR_FALSE;
  ------------------
  |  |  438|  18.2k|#define PR_FALSE 0
  ------------------
  470|       |
  471|  18.2k|    if (ecPoint->ulValueLen == 0) {
  ------------------
  |  Branch (471:9): [True: 0, False: 18.2k]
  ------------------
  472|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  473|      0|    }
  474|       |
  475|       |    /*
  476|       |     * The PKCS #11 spec requires ecPoints to be encoded as a DER OCTET String.
  477|       |     * NSS has mistakenly passed unencoded values, and some PKCS #11 vendors
  478|       |     * followed that mistake. Now we need to detect which encoding we were
  479|       |     * passed in. The task is made more complicated by the fact the the
  480|       |     * DER encoding byte (SEC_ASN_OCTET_STRING) is the same as the
  481|       |     * EC_POINT_FORM_UNCOMPRESSED byte (0x04), so we can't use that to
  482|       |     * determine which curve we are using.
  483|       |     */
  484|       |
  485|       |    /* get the expected key length for the passed in curve.
  486|       |     * pk11_get_EC_PointLenInBytes only returns valid values for curves
  487|       |     * NSS has traditionally recognized. If the curve is not recognized,
  488|       |     * it will return '0', and we have to figure out if the key was
  489|       |     * encoded or not heuristically. If the ecParams are invalid, it
  490|       |     * will return -1 for the keyLen.
  491|       |     */
  492|  18.2k|    keyLen = pk11_get_EC_PointLenInBytes(arena, ecParams, &plain);
  493|  18.2k|    if (keyLen < 0) {
  ------------------
  |  Branch (493:9): [True: 0, False: 18.2k]
  ------------------
  494|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  495|      0|    }
  496|       |
  497|       |    /*
  498|       |     * Some curves are not encoded but we don't have the name here.
  499|       |     * Instead, pk11_get_EC_PointLenInBytes returns true plain if this is the
  500|       |     * case.
  501|       |     */
  502|  18.2k|    if (plain && ecPoint->ulValueLen == (unsigned int)keyLen) {
  ------------------
  |  Branch (502:9): [True: 7.42k, False: 10.8k]
  |  Branch (502:18): [True: 7.42k, False: 0]
  ------------------
  503|  7.42k|        return pk11_Attr2SecItem(arena, ecPoint, publicKeyValue);
  504|  7.42k|    }
  505|       |
  506|       |    /* If the point is uncompressed and the lengths match, it
  507|       |     * must be an unencoded point */
  508|  10.8k|    if ((*((char *)ecPoint->pValue) == EC_POINT_FORM_UNCOMPRESSED) &&
  ------------------
  |  |   92|  10.8k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (508:9): [True: 10.8k, False: 0]
  ------------------
  509|  10.8k|        (ecPoint->ulValueLen == (unsigned int)keyLen)) {
  ------------------
  |  Branch (509:9): [True: 0, False: 10.8k]
  ------------------
  510|      0|        return pk11_Attr2SecItem(arena, ecPoint, publicKeyValue);
  511|      0|    }
  512|       |
  513|       |    /* now assume the key passed to us was encoded and decode it */
  514|  10.8k|    if (*((char *)ecPoint->pValue) == SEC_ASN1_OCTET_STRING) {
  ------------------
  |  |   80|  10.8k|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
  |  Branch (514:9): [True: 10.8k, False: 0]
  ------------------
  515|       |        /* OK, now let's try to decode it and see if it's valid */
  516|  10.8k|        encodedPublicValue.data = ecPoint->pValue;
  517|  10.8k|        encodedPublicValue.len = ecPoint->ulValueLen;
  518|  10.8k|        rv = SEC_QuickDERDecodeItem(arena, publicKeyValue,
  ------------------
  |  |  102|  10.8k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  519|  10.8k|                                    SEC_ASN1_GET(SEC_OctetStringTemplate), &encodedPublicValue);
  ------------------
  |  |  188|  10.8k|#define SEC_ASN1_GET(x) x
  ------------------
  520|       |
  521|       |        /* it coded correctly & we know the key length (and they match)
  522|       |         * then we are done, return the results. */
  523|  10.8k|        if (keyLen && rv == SECSuccess && publicKeyValue->len == (unsigned int)keyLen) {
  ------------------
  |  Branch (523:13): [True: 10.8k, False: 0]
  |  Branch (523:23): [True: 10.8k, False: 0]
  |  Branch (523:43): [True: 10.8k, False: 0]
  ------------------
  524|  10.8k|            return CKR_OK;
  ------------------
  |  | 1388|  10.8k|#define CKR_OK 0x00000000UL
  ------------------
  525|  10.8k|        }
  526|       |
  527|       |        /* if we know the key length, one of the above tests should have
  528|       |         * succeded. If it doesn't the module gave us bad data */
  529|      0|        if (keyLen) {
  ------------------
  |  Branch (529:13): [True: 0, False: 0]
  ------------------
  530|      0|            return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  531|      0|        }
  532|       |
  533|       |        /* We don't know the key length, so we don't know deterministically
  534|       |         * which encoding was used. We now will try to pick the most likely
  535|       |         * form that's correct, with a preference for the encoded form if we
  536|       |         * can't determine for sure. We do this by checking the key we got
  537|       |         * back from SEC_QuickDERDecodeItem for defects. If no defects are
  538|       |         * found, we assume the encoded parameter was was passed to us.
  539|       |         * our defect tests include:
  540|       |         *   1) it didn't decode.
  541|       |         *   2) The decode key had an invalid length (must be odd).
  542|       |         *   3) The decoded key wasn't an UNCOMPRESSED key.
  543|       |         *   4) The decoded key didn't include the entire encoded block
  544|       |         *   except the DER encoding values. (fixing DER length to one
  545|       |         *   particular value).
  546|       |         */
  547|      0|        if ((rv != SECSuccess) || ((publicKeyValue->len & 1) != 1) ||
  ------------------
  |  Branch (547:13): [True: 0, False: 0]
  |  Branch (547:35): [True: 0, False: 0]
  ------------------
  548|      0|            (publicKeyValue->data[0] != EC_POINT_FORM_UNCOMPRESSED) ||
  ------------------
  |  |   92|      0|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (548:13): [True: 0, False: 0]
  ------------------
  549|      0|            (PORT_Memcmp(&encodedPublicValue.data[encodedPublicValue.len - publicKeyValue->len],
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (549:13): [True: 0, False: 0]
  ------------------
  550|      0|                         publicKeyValue->data,
  551|      0|                         publicKeyValue->len) != 0)) {
  552|       |            /* The decoded public key was flawed, the original key must have
  553|       |             * already been in decoded form. Do a quick sanity check then
  554|       |             * return the original key value.
  555|       |             */
  556|      0|            if ((encodedPublicValue.len & 1) == 0) {
  ------------------
  |  Branch (556:17): [True: 0, False: 0]
  ------------------
  557|      0|                return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  558|      0|            }
  559|      0|            return pk11_Attr2SecItem(arena, ecPoint, publicKeyValue);
  560|      0|        }
  561|       |
  562|       |        /* as best we can figure, the passed in key was encoded, and we've
  563|       |         * now decoded it. Note: there is a chance this could be wrong if the
  564|       |         * following conditions hold:
  565|       |         *  1) The first byte or bytes of the X point looks like a valid length
  566|       |         * of precisely the right size (2*curveSize -1). this means for curves
  567|       |         * less than 512 bits (64 bytes), this will happen 1 in 256 times*.
  568|       |         * for curves between 512 and 1024, this will happen 1 in 65,536 times*
  569|       |         * for curves between 1024 and 256K this will happen 1 in 16 million*
  570|       |         *  2) The length of the 'DER length field' is odd
  571|       |         * (making both the encoded and decode
  572|       |         * values an odd length. this is true of all curves less than 512,
  573|       |         * as well as curves between 1024 and 256K).
  574|       |         *  3) The X[length of the 'DER length field'] == 0x04, 1 in 256.
  575|       |         *
  576|       |         *  (* assuming all values are equally likely in the first byte,
  577|       |         * This isn't true if the curve length is not a multiple of 8. In these
  578|       |         * cases, if the DER length is possible, it's more likely,
  579|       |         * if it's not possible, then we have no false decodes).
  580|       |         *
  581|       |         * For reference here are the odds for the various curves we currently
  582|       |         * have support for (and the only curves SSL will negotiate at this
  583|       |         * time). NOTE: None of the supported curves will show up here
  584|       |         * because we return a valid length for all of these curves.
  585|       |         * The only way to get here is to have some application (not SSL)
  586|       |         * which supports some unknown curve and have some vendor supplied
  587|       |         * PKCS #11 module support that curve. NOTE: in this case, one
  588|       |         * presumes that that pkcs #11 module is likely to be using the
  589|       |         * correct encodings.
  590|       |         *
  591|       |         * Prime Curves (GFp):
  592|       |         *   Bit    False       Odds of
  593|       |         *  Size    DER Len  False Decode Positive
  594|       |         *  112     27     1 in 65536
  595|       |         *  128     31     1 in 65536
  596|       |         *  160     39     1 in 65536
  597|       |         *  192     47     1 in 65536
  598|       |         *  224     55     1 in 65536
  599|       |         *  239     59     1 in 32768 (top byte can only be 0-127)
  600|       |         *  256     63     1 in 65536
  601|       |         *  521     129,131      0        (decoded value would be even)
  602|       |         *
  603|       |         * Binary curves (GF2m).
  604|       |         *   Bit    False       Odds of
  605|       |         *  Size    DER Len  False Decode Positive
  606|       |         *  131     33       0        (top byte can only be 0-7)
  607|       |         *  163     41       0        (top byte can only be 0-7)
  608|       |         *  176     43     1 in 65536
  609|       |         *  191     47     1 in 32768 (top byte can only be 0-127)
  610|       |         *  193     49       0        (top byte can only be 0-1)
  611|       |         *  208     51     1 in 65536
  612|       |         *  233     59       0        (top byte can only be 0-1)
  613|       |         *  239     59     1 in 32768 (top byte can only be 0-127)
  614|       |         *  272     67     1 in 65536
  615|       |         *  283     71       0        (top byte can only be 0-7)
  616|       |         *  304     75     1 in 65536
  617|       |         *  359     89     1 in 32768 (top byte can only be 0-127)
  618|       |         *  368     91     1 in 65536
  619|       |         *  409     103      0        (top byte can only be 0-1)
  620|       |         *  431     107    1 in 32768 (top byte can only be 0-127)
  621|       |         *  571     129,143      0        (decoded value would be even)
  622|       |         *
  623|       |         */
  624|       |
  625|      0|        return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  626|      0|    }
  627|       |
  628|       |    /* In theory, we should handle the case where the curve == 0 and
  629|       |     * the first byte is EC_POINT_FORM_UNCOMPRESSED, (which would be
  630|       |     * handled by doing a santity check on the key length and returning
  631|       |     * pk11_Attr2SecItem() to copy the ecPoint to the publicKeyValue).
  632|       |     *
  633|       |     * This test is unnecessary, however, due to the fact that
  634|       |     * EC_POINT_FORM_UNCOMPRESSED == SEC_ASIN1_OCTET_STRING, that case is
  635|       |     * handled in the above if. That means if we get here, the initial
  636|       |     * byte of our ecPoint value was invalid, so we can safely return.
  637|       |     * invalid attribute.
  638|       |     */
  639|       |
  640|      0|    return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  641|  10.8k|}
pk11akey.c:pk11_get_EC_PointLenInBytes:
  346|  18.2k|{
  347|  18.2k|    SECItem oid;
  348|  18.2k|    SECOidTag tag;
  349|  18.2k|    SECStatus rv;
  350|       |
  351|       |    /* decode the OID tag */
  352|  18.2k|    rv = SEC_QuickDERDecodeItem(arena, &oid,
  ------------------
  |  |  102|  18.2k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  353|  18.2k|                                SEC_ASN1_GET(SEC_ObjectIDTemplate), ecParams);
  ------------------
  |  |  188|  18.2k|#define SEC_ASN1_GET(x) x
  ------------------
  354|  18.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (354:9): [True: 0, False: 18.2k]
  ------------------
  355|       |        /* could be explict curves, allow them to work if the
  356|       |         * PKCS #11 module support them. If we try to parse the
  357|       |         * explicit curve value in the future, we may return -1 here
  358|       |         * to indicate an invalid parameter if the explicit curve
  359|       |         * decode fails. */
  360|      0|        return 0;
  361|      0|    }
  362|       |
  363|  18.2k|    *plain = PR_FALSE;
  ------------------
  |  |  438|  18.2k|#define PR_FALSE 0
  ------------------
  364|  18.2k|    tag = SECOID_FindOIDTag(&oid);
  ------------------
  |  |  117|  18.2k|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
  365|  18.2k|    switch (tag) {
  366|      0|        case SEC_OID_SECG_EC_SECP112R1:
  ------------------
  |  Branch (366:9): [True: 0, False: 18.2k]
  ------------------
  367|      0|        case SEC_OID_SECG_EC_SECP112R2:
  ------------------
  |  Branch (367:9): [True: 0, False: 18.2k]
  ------------------
  368|      0|            return 29; /* curve len in bytes = 14 bytes */
  369|      0|        case SEC_OID_SECG_EC_SECT113R1:
  ------------------
  |  Branch (369:9): [True: 0, False: 18.2k]
  ------------------
  370|      0|        case SEC_OID_SECG_EC_SECT113R2:
  ------------------
  |  Branch (370:9): [True: 0, False: 18.2k]
  ------------------
  371|      0|            return 31; /* curve len in bytes = 15 bytes */
  372|      0|        case SEC_OID_SECG_EC_SECP128R1:
  ------------------
  |  Branch (372:9): [True: 0, False: 18.2k]
  ------------------
  373|      0|        case SEC_OID_SECG_EC_SECP128R2:
  ------------------
  |  Branch (373:9): [True: 0, False: 18.2k]
  ------------------
  374|      0|            return 33; /* curve len in bytes = 16 bytes */
  375|      0|        case SEC_OID_SECG_EC_SECT131R1:
  ------------------
  |  Branch (375:9): [True: 0, False: 18.2k]
  ------------------
  376|      0|        case SEC_OID_SECG_EC_SECT131R2:
  ------------------
  |  Branch (376:9): [True: 0, False: 18.2k]
  ------------------
  377|      0|            return 35; /* curve len in bytes = 17 bytes */
  378|      0|        case SEC_OID_SECG_EC_SECP160K1:
  ------------------
  |  Branch (378:9): [True: 0, False: 18.2k]
  ------------------
  379|      0|        case SEC_OID_SECG_EC_SECP160R1:
  ------------------
  |  Branch (379:9): [True: 0, False: 18.2k]
  ------------------
  380|      0|        case SEC_OID_SECG_EC_SECP160R2:
  ------------------
  |  Branch (380:9): [True: 0, False: 18.2k]
  ------------------
  381|      0|            return 41; /* curve len in bytes = 20 bytes */
  382|      0|        case SEC_OID_SECG_EC_SECT163K1:
  ------------------
  |  Branch (382:9): [True: 0, False: 18.2k]
  ------------------
  383|      0|        case SEC_OID_SECG_EC_SECT163R1:
  ------------------
  |  Branch (383:9): [True: 0, False: 18.2k]
  ------------------
  384|      0|        case SEC_OID_SECG_EC_SECT163R2:
  ------------------
  |  Branch (384:9): [True: 0, False: 18.2k]
  ------------------
  385|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V1:
  ------------------
  |  Branch (385:9): [True: 0, False: 18.2k]
  ------------------
  386|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V2:
  ------------------
  |  Branch (386:9): [True: 0, False: 18.2k]
  ------------------
  387|      0|        case SEC_OID_ANSIX962_EC_C2PNB163V3:
  ------------------
  |  Branch (387:9): [True: 0, False: 18.2k]
  ------------------
  388|      0|            return 43; /* curve len in bytes = 21 bytes */
  389|      0|        case SEC_OID_ANSIX962_EC_C2PNB176V1:
  ------------------
  |  Branch (389:9): [True: 0, False: 18.2k]
  ------------------
  390|      0|            return 45; /* curve len in bytes = 22 bytes */
  391|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V1:
  ------------------
  |  Branch (391:9): [True: 0, False: 18.2k]
  ------------------
  392|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V2:
  ------------------
  |  Branch (392:9): [True: 0, False: 18.2k]
  ------------------
  393|      0|        case SEC_OID_ANSIX962_EC_C2TNB191V3:
  ------------------
  |  Branch (393:9): [True: 0, False: 18.2k]
  ------------------
  394|      0|        case SEC_OID_SECG_EC_SECP192K1:
  ------------------
  |  Branch (394:9): [True: 0, False: 18.2k]
  ------------------
  395|      0|        case SEC_OID_ANSIX962_EC_PRIME192V1:
  ------------------
  |  Branch (395:9): [True: 0, False: 18.2k]
  ------------------
  396|      0|        case SEC_OID_ANSIX962_EC_PRIME192V2:
  ------------------
  |  Branch (396:9): [True: 0, False: 18.2k]
  ------------------
  397|      0|        case SEC_OID_ANSIX962_EC_PRIME192V3:
  ------------------
  |  Branch (397:9): [True: 0, False: 18.2k]
  ------------------
  398|      0|            return 49; /*curve len in bytes = 24 bytes */
  399|      0|        case SEC_OID_SECG_EC_SECT193R1:
  ------------------
  |  Branch (399:9): [True: 0, False: 18.2k]
  ------------------
  400|      0|        case SEC_OID_SECG_EC_SECT193R2:
  ------------------
  |  Branch (400:9): [True: 0, False: 18.2k]
  ------------------
  401|      0|            return 51; /*curve len in bytes = 25 bytes */
  402|      0|        case SEC_OID_ANSIX962_EC_C2PNB208W1:
  ------------------
  |  Branch (402:9): [True: 0, False: 18.2k]
  ------------------
  403|      0|            return 53; /*curve len in bytes = 26 bytes */
  404|      0|        case SEC_OID_SECG_EC_SECP224K1:
  ------------------
  |  Branch (404:9): [True: 0, False: 18.2k]
  ------------------
  405|      0|        case SEC_OID_SECG_EC_SECP224R1:
  ------------------
  |  Branch (405:9): [True: 0, False: 18.2k]
  ------------------
  406|      0|            return 57; /*curve len in bytes = 28 bytes */
  407|      0|        case SEC_OID_SECG_EC_SECT233K1:
  ------------------
  |  Branch (407:9): [True: 0, False: 18.2k]
  ------------------
  408|      0|        case SEC_OID_SECG_EC_SECT233R1:
  ------------------
  |  Branch (408:9): [True: 0, False: 18.2k]
  ------------------
  409|      0|        case SEC_OID_SECG_EC_SECT239K1:
  ------------------
  |  Branch (409:9): [True: 0, False: 18.2k]
  ------------------
  410|      0|        case SEC_OID_ANSIX962_EC_PRIME239V1:
  ------------------
  |  Branch (410:9): [True: 0, False: 18.2k]
  ------------------
  411|      0|        case SEC_OID_ANSIX962_EC_PRIME239V2:
  ------------------
  |  Branch (411:9): [True: 0, False: 18.2k]
  ------------------
  412|      0|        case SEC_OID_ANSIX962_EC_PRIME239V3:
  ------------------
  |  Branch (412:9): [True: 0, False: 18.2k]
  ------------------
  413|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V1:
  ------------------
  |  Branch (413:9): [True: 0, False: 18.2k]
  ------------------
  414|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V2:
  ------------------
  |  Branch (414:9): [True: 0, False: 18.2k]
  ------------------
  415|      0|        case SEC_OID_ANSIX962_EC_C2TNB239V3:
  ------------------
  |  Branch (415:9): [True: 0, False: 18.2k]
  ------------------
  416|      0|            return 61; /*curve len in bytes = 30 bytes */
  417|  8.73k|        case SEC_OID_ANSIX962_EC_PRIME256V1:
  ------------------
  |  Branch (417:9): [True: 8.73k, False: 9.52k]
  ------------------
  418|  8.73k|        case SEC_OID_SECG_EC_SECP256K1:
  ------------------
  |  Branch (418:9): [True: 0, False: 18.2k]
  ------------------
  419|  8.73k|            return 65; /*curve len in bytes = 32 bytes */
  420|      0|        case SEC_OID_ANSIX962_EC_C2PNB272W1:
  ------------------
  |  Branch (420:9): [True: 0, False: 18.2k]
  ------------------
  421|      0|            return 69; /*curve len in bytes = 34 bytes */
  422|      0|        case SEC_OID_SECG_EC_SECT283K1:
  ------------------
  |  Branch (422:9): [True: 0, False: 18.2k]
  ------------------
  423|      0|        case SEC_OID_SECG_EC_SECT283R1:
  ------------------
  |  Branch (423:9): [True: 0, False: 18.2k]
  ------------------
  424|      0|            return 73; /*curve len in bytes = 36 bytes */
  425|      0|        case SEC_OID_ANSIX962_EC_C2PNB304W1:
  ------------------
  |  Branch (425:9): [True: 0, False: 18.2k]
  ------------------
  426|      0|            return 77; /*curve len in bytes = 38 bytes */
  427|      0|        case SEC_OID_ANSIX962_EC_C2TNB359V1:
  ------------------
  |  Branch (427:9): [True: 0, False: 18.2k]
  ------------------
  428|      0|            return 91; /*curve len in bytes = 45 bytes */
  429|      0|        case SEC_OID_ANSIX962_EC_C2PNB368W1:
  ------------------
  |  Branch (429:9): [True: 0, False: 18.2k]
  ------------------
  430|      0|            return 93; /*curve len in bytes = 46 bytes */
  431|  2.04k|        case SEC_OID_SECG_EC_SECP384R1:
  ------------------
  |  Branch (431:9): [True: 2.04k, False: 16.2k]
  ------------------
  432|  2.04k|            return 97; /*curve len in bytes = 48 bytes */
  433|      0|        case SEC_OID_SECG_EC_SECT409K1:
  ------------------
  |  Branch (433:9): [True: 0, False: 18.2k]
  ------------------
  434|      0|        case SEC_OID_SECG_EC_SECT409R1:
  ------------------
  |  Branch (434:9): [True: 0, False: 18.2k]
  ------------------
  435|      0|            return 105; /*curve len in bytes = 52 bytes */
  436|      0|        case SEC_OID_ANSIX962_EC_C2TNB431R1:
  ------------------
  |  Branch (436:9): [True: 0, False: 18.2k]
  ------------------
  437|      0|            return 109; /*curve len in bytes = 54 bytes */
  438|     52|        case SEC_OID_SECG_EC_SECP521R1:
  ------------------
  |  Branch (438:9): [True: 52, False: 18.2k]
  ------------------
  439|     52|            return 133; /*curve len in bytes = 66 bytes */
  440|      0|        case SEC_OID_SECG_EC_SECT571K1:
  ------------------
  |  Branch (440:9): [True: 0, False: 18.2k]
  ------------------
  441|      0|        case SEC_OID_SECG_EC_SECT571R1:
  ------------------
  |  Branch (441:9): [True: 0, False: 18.2k]
  ------------------
  442|      0|            return 145; /*curve len in bytes = 72 bytes */
  443|      0|        case SEC_OID_X25519:
  ------------------
  |  Branch (443:9): [True: 0, False: 18.2k]
  ------------------
  444|  7.42k|        case SEC_OID_CURVE25519:
  ------------------
  |  Branch (444:9): [True: 7.42k, False: 10.8k]
  ------------------
  445|  7.42k|        case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (445:9): [True: 0, False: 18.2k]
  ------------------
  446|  7.42k|            *plain = PR_TRUE;
  ------------------
  |  |  437|  7.42k|#define PR_TRUE 1
  ------------------
  447|  7.42k|            return 32; /* curve len in bytes = 32 bytes (only X) */
  448|       |        /* unknown or unrecognized OIDs. return unknown length */
  449|      0|        default:
  ------------------
  |  Branch (449:9): [True: 0, False: 18.2k]
  ------------------
  450|      0|            break;
  451|  18.2k|    }
  452|      0|    return 0;
  453|  18.2k|}

pk11_LoginStillRequired:
  311|  8.44k|{
  312|  8.44k|    return slot->needLogin && !PK11_IsLoggedIn(slot, wincx);
  ------------------
  |  Branch (312:12): [True: 0, False: 8.44k]
  |  Branch (312:31): [True: 0, False: 0]
  ------------------
  313|  8.44k|}
PK11_Authenticate:
  321|      2|{
  322|      2|    if (!slot) {
  ------------------
  |  Branch (322:9): [True: 0, False: 2]
  ------------------
  323|      0|        return SECFailure;
  324|      0|    }
  325|      2|    if (pk11_LoginStillRequired(slot, wincx)) {
  ------------------
  |  Branch (325:9): [True: 0, False: 2]
  ------------------
  326|      0|        return PK11_DoPassword(slot, slot->session, loadCerts, wincx,
  327|      0|                               PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
                                             PR_FALSE, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  328|      0|    }
  329|      2|    return SECSuccess;
  330|      2|}
pk11_AuthenticateUnfriendly:
  338|      2|{
  339|      2|    SECStatus rv = SECSuccess;
  340|      2|    if (!PK11_IsFriendly(slot)) {
  ------------------
  |  Branch (340:9): [True: 0, False: 2]
  ------------------
  341|      0|        rv = PK11_Authenticate(slot, loadCerts, wincx);
  342|      0|    }
  343|      2|    return rv;
  344|      2|}

PK11_TraverseSlotCerts:
  565|      1|{
  566|      1|    NSSTrustDomain *defaultTD = STAN_GetDefaultTrustDomain();
  567|      1|    struct fake_der_cb_argstr fda;
  568|      1|    struct nss3_cert_cbstr pk11cb;
  569|       |
  570|       |    /* authenticate to the tokens first */
  571|      1|    (void)pk11_TraverseAllSlots(NULL, NULL, PR_TRUE, wincx);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  572|       |
  573|      1|    fda.callback = callback;
  574|      1|    fda.arg = arg;
  575|      1|    pk11cb.callback = fake_der_cb;
  576|      1|    pk11cb.arg = &fda;
  577|      1|    NSSTrustDomain_TraverseCertificates(defaultTD, convert_cert, &pk11cb);
  578|      1|    return SECSuccess;
  579|      1|}

PK11_EnterContextMonitor:
   36|  1.82M|{
   37|       |    /* if we own the session and our slot is ThreadSafe, only monitor
   38|       |     * the Context */
   39|  1.82M|    if ((cx->ownSession) && (cx->slot->isThreadSafe)) {
  ------------------
  |  Branch (39:9): [True: 1.82M, False: 0]
  |  Branch (39:29): [True: 1.82M, False: 0]
  ------------------
   40|       |        /* Should this use monitors instead? */
   41|  1.82M|        PZ_Lock(cx->sessionLock);
  ------------------
  |  |  245|  1.82M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
   42|  1.82M|    } else {
   43|      0|        PK11_EnterSlotMonitor(cx->slot);
   44|      0|    }
   45|  1.82M|}
PK11_ExitContextMonitor:
   49|  1.82M|{
   50|       |    /* if we own the session and our slot is ThreadSafe, only monitor
   51|       |     * the Context */
   52|  1.82M|    if ((cx->ownSession) && (cx->slot->isThreadSafe)) {
  ------------------
  |  Branch (52:9): [True: 1.82M, False: 0]
  |  Branch (52:29): [True: 1.82M, False: 0]
  ------------------
   53|       |        /* Should this use monitors instead? */
   54|  1.82M|        PZ_Unlock(cx->sessionLock);
  ------------------
  |  |  246|  1.82M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
   55|  1.82M|    } else {
   56|      0|        PK11_ExitSlotMonitor(cx->slot);
   57|      0|    }
   58|  1.82M|}
PK11_DestroyContext:
   65|   774k|{
   66|   774k|    pk11_CloseSession(context->slot, context->session, context->ownSession);
   67|       |    /* initialize the critical fields of the context */
   68|   774k|    if (context->savedData != NULL)
  ------------------
  |  Branch (68:9): [True: 0, False: 774k]
  ------------------
   69|      0|        PORT_Free(context->savedData);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
   70|   774k|    if (context->key)
  ------------------
  |  Branch (70:9): [True: 543k, False: 231k]
  ------------------
   71|   543k|        PK11_FreeSymKey(context->key);
   72|   774k|    if (context->param && context->param != &pk11_null_params)
  ------------------
  |  Branch (72:9): [True: 774k, False: 0]
  |  Branch (72:27): [True: 208k, False: 565k]
  ------------------
   73|   208k|        SECITEM_FreeItem(context->param, PR_TRUE);
  ------------------
  |  |  108|   208k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(context->param, PR_TRUE);
  ------------------
  |  |  437|   208k|#define PR_TRUE 1
  ------------------
   74|   774k|    if (context->sessionLock)
  ------------------
  |  Branch (74:9): [True: 774k, False: 0]
  ------------------
   75|   774k|        PZ_DestroyLock(context->sessionLock);
  ------------------
  |  |  244|   774k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   76|   774k|    PK11_FreeSlot(context->slot);
   77|   774k|    if (freeit)
  ------------------
  |  Branch (77:9): [True: 774k, False: 0]
  ------------------
   78|   774k|        PORT_Free(context);
  ------------------
  |  |   60|   774k|#define PORT_Free PORT_Free_Util
  ------------------
   79|   774k|}
pk11_saveContext:
  116|  9.32k|{
  117|  9.32k|    return pk11_saveContextHelper(context,
  118|  9.32k|                                  (unsigned char *)space, savedLength);
  119|  9.32k|}
pk11_restoreContext:
  126|  34.8k|{
  127|  34.8k|    CK_RV crv;
  128|  34.8k|    CK_OBJECT_HANDLE objectID = context->objectID;
  129|       |
  130|  34.8k|    PORT_Assert(space != NULL);
  ------------------
  |  |  120|  34.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  34.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 34.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  131|  34.8k|    if (space == NULL) {
  ------------------
  |  Branch (131:9): [True: 0, False: 34.8k]
  ------------------
  132|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  133|      0|        return SECFailure;
  134|      0|    }
  135|  34.8k|    crv = PK11_GETTAB(context->slot)->C_SetOperationState(context->session, (CK_BYTE_PTR)space, savedLength, objectID, 0);
  ------------------
  |  |  102|  34.8k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  136|  34.8k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (136:9): [True: 0, False: 34.8k]
  ------------------
  137|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  138|      0|        return SECFailure;
  139|      0|    }
  140|  34.8k|    return SECSuccess;
  141|  34.8k|}
PK11_CreateContextBySymKey:
  495|   543k|{
  496|   543k|    PK11SymKey *newKey;
  497|   543k|    PK11Context *context;
  498|       |
  499|       |    /* if this slot doesn't support the mechanism, go to a slot that does */
  500|   543k|    newKey = pk11_ForceSlot(symKey, type, operation);
  501|   543k|    if (newKey == NULL) {
  ------------------
  |  Branch (501:9): [True: 543k, False: 0]
  ------------------
  502|   543k|        PK11_ReferenceSymKey(symKey);
  503|   543k|    } else {
  504|      0|        symKey = newKey;
  505|      0|    }
  506|       |
  507|       |    /* Context keeps its reference to the symKey, so it's safe to
  508|       |     * free our reference we we are through, even though we may have
  509|       |     * created the key using pk11_ForceSlot. */
  510|   543k|    context = pk11_CreateNewContextInSlot(type, symKey->slot, operation, symKey,
  511|   543k|                                          symKey->objectID, param, symKey->cx);
  512|   543k|    PK11_FreeSymKey(symKey);
  513|   543k|    return context;
  514|   543k|}
PK11_CreateDigestContext:
  579|   221k|{
  580|       |    /* digesting has to work without authentication to the slot */
  581|   221k|    CK_MECHANISM_TYPE type;
  582|   221k|    PK11SlotInfo *slot;
  583|   221k|    PK11Context *context;
  584|   221k|    SECItem param;
  585|       |
  586|   221k|    type = PK11_AlgtagToMechanism(hashAlg);
  587|   221k|    slot = PK11_GetBestSlot(type, NULL);
  588|   221k|    if (slot == NULL) {
  ------------------
  |  Branch (588:9): [True: 0, False: 221k]
  ------------------
  589|      0|        PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  590|      0|        return NULL;
  591|      0|    }
  592|       |
  593|       |    /* maybe should really be PK11_GenerateNewParam?? */
  594|   221k|    param.data = NULL;
  595|   221k|    param.len = 0;
  596|   221k|    param.type = 0;
  597|       |
  598|   221k|    context = pk11_CreateNewContextInSlot(type, slot, CKA_DIGEST, NULL,
  ------------------
  |  |   68|   221k|#define CKA_DIGEST 0x81000000L
  ------------------
  599|   221k|                                          CK_INVALID_HANDLE, &param, NULL);
  ------------------
  |  |   78|   221k|#define CK_INVALID_HANDLE 0
  ------------------
  600|   221k|    PK11_FreeSlot(slot);
  601|   221k|    return context;
  602|   221k|}
PK11_CloneContext:
  609|  9.32k|{
  610|  9.32k|    PK11Context *newcx;
  611|  9.32k|    PRBool needFree = PR_FALSE;
  ------------------
  |  |  438|  9.32k|#define PR_FALSE 0
  ------------------
  612|  9.32k|    SECStatus rv = SECSuccess;
  613|  9.32k|    void *data;
  614|  9.32k|    unsigned long len;
  615|       |
  616|  9.32k|    newcx = pk11_CreateNewContextInSlot(old->type, old->slot, old->operation,
  617|  9.32k|                                        old->key, old->objectID, old->param,
  618|  9.32k|                                        old->pwArg);
  619|  9.32k|    if (newcx == NULL)
  ------------------
  |  Branch (619:9): [True: 0, False: 9.32k]
  ------------------
  620|      0|        return NULL;
  621|       |
  622|       |    /* now clone the save state. First we need to find the save state
  623|       |     * of the old session. If the old context owns it's session,
  624|       |     * the state needs to be saved, otherwise the state is in saveData. */
  625|  9.32k|    if (old->ownSession) {
  ------------------
  |  Branch (625:9): [True: 9.32k, False: 0]
  ------------------
  626|  9.32k|        PK11_EnterContextMonitor(old);
  627|  9.32k|        data = pk11_saveContext(old, NULL, &len);
  628|  9.32k|        PK11_ExitContextMonitor(old);
  629|  9.32k|        needFree = PR_TRUE;
  ------------------
  |  |  437|  9.32k|#define PR_TRUE 1
  ------------------
  630|  9.32k|    } else {
  631|      0|        data = old->savedData;
  632|      0|        len = old->savedLength;
  633|      0|    }
  634|       |
  635|  9.32k|    if (data == NULL) {
  ------------------
  |  Branch (635:9): [True: 0, False: 9.32k]
  ------------------
  636|      0|        PK11_DestroyContext(newcx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  637|      0|        return NULL;
  638|      0|    }
  639|       |
  640|       |    /* now copy that state into our new context. Again we have different
  641|       |     * work if the new context owns it's own session. If it does, we
  642|       |     * restore the state gathered above. If it doesn't, we copy the
  643|       |     * saveData pointer... */
  644|  9.32k|    if (newcx->ownSession) {
  ------------------
  |  Branch (644:9): [True: 9.32k, False: 0]
  ------------------
  645|  9.32k|        PK11_EnterContextMonitor(newcx);
  646|  9.32k|        rv = pk11_restoreContext(newcx, data, len);
  647|  9.32k|        PK11_ExitContextMonitor(newcx);
  648|  9.32k|    } else {
  649|      0|        PORT_Assert(newcx->savedData != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  650|      0|        if ((newcx->savedData == NULL) || (newcx->savedLength < len)) {
  ------------------
  |  Branch (650:13): [True: 0, False: 0]
  |  Branch (650:43): [True: 0, False: 0]
  ------------------
  651|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  652|      0|            rv = SECFailure;
  653|      0|        } else {
  654|      0|            PORT_Memcpy(newcx->savedData, data, len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  655|      0|            newcx->savedLength = len;
  656|      0|        }
  657|      0|    }
  658|       |
  659|  9.32k|    if (needFree)
  ------------------
  |  Branch (659:9): [True: 9.32k, False: 0]
  ------------------
  660|  9.32k|        PORT_Free(data);
  ------------------
  |  |   60|  9.32k|#define PORT_Free PORT_Free_Util
  ------------------
  661|       |
  662|  9.32k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (662:9): [True: 0, False: 9.32k]
  ------------------
  663|      0|        PK11_DestroyContext(newcx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  664|      0|        return NULL;
  665|      0|    }
  666|  9.32k|    return newcx;
  667|  9.32k|}
PK11_SaveContextAlloc:
  707|  25.5k|{
  708|  25.5k|    unsigned char *stateBuf = NULL;
  709|  25.5k|    unsigned long length = (unsigned long)pabLen;
  710|       |
  711|  25.5k|    if (cx->ownSession) {
  ------------------
  |  Branch (711:9): [True: 25.5k, False: 0]
  ------------------
  712|  25.5k|        PK11_EnterContextMonitor(cx);
  713|  25.5k|        stateBuf = pk11_saveContextHelper(cx, preAllocBuf, &length);
  714|  25.5k|        PK11_ExitContextMonitor(cx);
  715|  25.5k|        *stateLen = (stateBuf != NULL) ? length : 0;
  ------------------
  |  Branch (715:21): [True: 25.5k, False: 0]
  ------------------
  716|  25.5k|    } else {
  717|      0|        if (pabLen < cx->savedLength) {
  ------------------
  |  Branch (717:13): [True: 0, False: 0]
  ------------------
  718|      0|            stateBuf = (unsigned char *)PORT_Alloc(cx->savedLength);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  719|      0|            if (!stateBuf) {
  ------------------
  |  Branch (719:17): [True: 0, False: 0]
  ------------------
  720|      0|                return (unsigned char *)NULL;
  721|      0|            }
  722|      0|        } else {
  723|      0|            stateBuf = preAllocBuf;
  724|      0|        }
  725|      0|        if (cx->savedData) {
  ------------------
  |  Branch (725:13): [True: 0, False: 0]
  ------------------
  726|      0|            PORT_Memcpy(stateBuf, cx->savedData, cx->savedLength);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  727|      0|        }
  728|      0|        *stateLen = cx->savedLength;
  729|      0|    }
  730|  25.5k|    return stateBuf;
  731|  25.5k|}
PK11_RestoreContext:
  739|  25.5k|{
  740|  25.5k|    SECStatus rv = SECSuccess;
  741|  25.5k|    if (cx->ownSession) {
  ------------------
  |  Branch (741:9): [True: 25.5k, False: 0]
  ------------------
  742|  25.5k|        PK11_EnterContextMonitor(cx);
  743|  25.5k|        pk11_Finalize(cx);
  744|  25.5k|        rv = pk11_restoreContext(cx, save, len);
  745|  25.5k|        PK11_ExitContextMonitor(cx);
  746|  25.5k|    } else {
  747|      0|        PORT_Assert(cx->savedData != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  748|      0|        if ((cx->savedData == NULL) || (cx->savedLength < (unsigned)len)) {
  ------------------
  |  Branch (748:13): [True: 0, False: 0]
  |  Branch (748:40): [True: 0, False: 0]
  ------------------
  749|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  750|      0|            rv = SECFailure;
  751|      0|        } else {
  752|      0|            PORT_Memcpy(cx->savedData, save, len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  753|      0|            cx->savedLength = len;
  754|      0|        }
  755|      0|    }
  756|  25.5k|    return rv;
  757|  25.5k|}
PK11_DigestBegin:
  781|   328k|{
  782|   328k|    CK_MECHANISM mech_info;
  783|   328k|    SECStatus rv;
  784|       |
  785|   328k|    if (cx->init == PR_TRUE) {
  ------------------
  |  |  437|   328k|#define PR_TRUE 1
  ------------------
  |  Branch (785:9): [True: 328k, False: 0]
  ------------------
  786|   328k|        return SECSuccess;
  787|   328k|    }
  788|       |
  789|       |    /*
  790|       |     * make sure the old context is clear first
  791|       |     */
  792|      0|    PK11_EnterContextMonitor(cx);
  793|      0|    pk11_Finalize(cx);
  794|      0|    PK11_ExitContextMonitor(cx);
  795|       |
  796|      0|    mech_info.mechanism = cx->type;
  797|      0|    mech_info.pParameter = cx->param->data;
  798|      0|    mech_info.ulParameterLen = cx->param->len;
  799|      0|    rv = pk11_context_init(cx, &mech_info);
  800|       |
  801|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (801:9): [True: 0, False: 0]
  ------------------
  802|      0|        return SECFailure;
  803|      0|    }
  804|      0|    cx->init = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  805|      0|    return SECSuccess;
  806|      0|}
PK11_HashBuf:
  811|  56.4k|{
  812|  56.4k|    PK11Context *context;
  813|  56.4k|    unsigned int max_length;
  814|  56.4k|    unsigned int out_length;
  815|  56.4k|    SECStatus rv;
  816|       |
  817|       |    /* len will be passed to PK11_DigestOp as unsigned. */
  818|  56.4k|    if (len < 0) {
  ------------------
  |  Branch (818:9): [True: 0, False: 56.4k]
  ------------------
  819|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  820|      0|        return SECFailure;
  821|      0|    }
  822|       |
  823|  56.4k|    context = PK11_CreateDigestContext(hashAlg);
  824|  56.4k|    if (context == NULL)
  ------------------
  |  Branch (824:9): [True: 0, False: 56.4k]
  ------------------
  825|      0|        return SECFailure;
  826|       |
  827|  56.4k|    rv = PK11_DigestBegin(context);
  828|  56.4k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (828:9): [True: 0, False: 56.4k]
  ------------------
  829|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  830|      0|        return rv;
  831|      0|    }
  832|       |
  833|  56.4k|    rv = PK11_DigestOp(context, in, len);
  834|  56.4k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (834:9): [True: 0, False: 56.4k]
  ------------------
  835|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  836|      0|        return rv;
  837|      0|    }
  838|       |
  839|       |    /* XXX This really should have been an argument to this function! */
  840|  56.4k|    max_length = HASH_ResultLenByOidTag(hashAlg);
  841|  56.4k|    PORT_Assert(max_length);
  ------------------
  |  |  120|  56.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  56.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 56.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  842|  56.4k|    if (!max_length)
  ------------------
  |  Branch (842:9): [True: 0, False: 56.4k]
  ------------------
  843|      0|        max_length = HASH_LENGTH_MAX;
  ------------------
  |  |   48|      0|#define HASH_LENGTH_MAX SHA512_LENGTH
  |  |  ------------------
  |  |  |  |   43|      0|#define SHA512_LENGTH 64
  |  |  ------------------
  ------------------
  844|       |
  845|  56.4k|    rv = PK11_DigestFinal(context, out, &out_length, max_length);
  846|  56.4k|    PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|  56.4k|#define PR_TRUE 1
  ------------------
  847|  56.4k|    return rv;
  848|  56.4k|}
PK11_DigestOp:
 1491|   648k|{
 1492|   648k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   648k|#define CKR_OK 0x00000000UL
  ------------------
 1493|   648k|    SECStatus rv = SECSuccess;
 1494|       |
 1495|   648k|    if (inLen == 0) {
  ------------------
  |  Branch (1495:9): [True: 12.1k, False: 636k]
  ------------------
 1496|  12.1k|        return SECSuccess;
 1497|  12.1k|    }
 1498|   636k|    if (!in) {
  ------------------
  |  Branch (1498:9): [True: 0, False: 636k]
  ------------------
 1499|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1500|      0|        return SECFailure;
 1501|      0|    }
 1502|       |
 1503|       |    /* if we ran out of session, we need to restore our previously stored
 1504|       |     * state.
 1505|       |     */
 1506|   636k|    context->init = PR_FALSE;
  ------------------
  |  |  438|   636k|#define PR_FALSE 0
  ------------------
 1507|   636k|    PK11_EnterContextMonitor(context);
 1508|   636k|    if (!context->ownSession) {
  ------------------
  |  Branch (1508:9): [True: 0, False: 636k]
  ------------------
 1509|      0|        rv = pk11_restoreContext(context, context->savedData,
 1510|      0|                                 context->savedLength);
 1511|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1511:13): [True: 0, False: 0]
  ------------------
 1512|      0|            PK11_ExitContextMonitor(context);
 1513|      0|            return rv;
 1514|      0|        }
 1515|      0|    }
 1516|       |
 1517|   636k|    switch (context->operation) {
 1518|       |        /* also for MAC'ing */
 1519|   106k|        case CKA_SIGN:
  ------------------
  |  |  551|   106k|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (1519:9): [True: 106k, False: 529k]
  ------------------
 1520|   106k|            crv = PK11_GETTAB(context->slot)->C_SignUpdate(context->session, (unsigned char *)in, inLen);
  ------------------
  |  |  102|   106k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1521|   106k|            break;
 1522|      0|        case CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (1522:9): [True: 0, False: 636k]
  ------------------
 1523|      0|            crv = PK11_GETTAB(context->slot)->C_VerifyUpdate(context->session, (unsigned char *)in, inLen);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1524|      0|            break;
 1525|   529k|        case CKA_DIGEST:
  ------------------
  |  |   68|   529k|#define CKA_DIGEST 0x81000000L
  ------------------
  |  Branch (1525:9): [True: 529k, False: 106k]
  ------------------
 1526|   529k|            crv = PK11_GETTAB(context->slot)->C_DigestUpdate(context->session, (unsigned char *)in, inLen);
  ------------------
  |  |  102|   529k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1527|   529k|            break;
 1528|      0|        default:
  ------------------
  |  Branch (1528:9): [True: 0, False: 636k]
  ------------------
 1529|      0|            crv = CKR_OPERATION_NOT_INITIALIZED;
  ------------------
  |  | 1454|      0|#define CKR_OPERATION_NOT_INITIALIZED 0x00000091UL
  ------------------
 1530|      0|            break;
 1531|   636k|    }
 1532|       |
 1533|   636k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   636k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1533:9): [True: 0, False: 636k]
  ------------------
 1534|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1535|      0|        rv = SECFailure;
 1536|      0|    }
 1537|       |
 1538|       |    /*
 1539|       |     * handle session starvation case.. use our last session to multiplex
 1540|       |     */
 1541|   636k|    if (!context->ownSession) {
  ------------------
  |  Branch (1541:9): [True: 0, False: 636k]
  ------------------
 1542|      0|        context->savedData = pk11_saveContext(context, context->savedData,
 1543|      0|                                              &context->savedLength);
 1544|      0|        if (context->savedData == NULL)
  ------------------
  |  Branch (1544:13): [True: 0, False: 0]
  ------------------
 1545|      0|            rv = SECFailure;
 1546|       |
 1547|       |        /* clear out out session for others to use */
 1548|      0|        pk11_Finalize(context);
 1549|      0|    }
 1550|   636k|    PK11_ExitContextMonitor(context);
 1551|   636k|    return rv;
 1552|   636k|}
pk11_Finalize:
 1642|  25.5k|{
 1643|  25.5k|    CK_ULONG count = 0;
 1644|  25.5k|    CK_RV crv;
 1645|  25.5k|    unsigned char stackBuf[256];
 1646|  25.5k|    unsigned char *buffer = NULL;
 1647|       |
 1648|  25.5k|    if (!context->ownSession) {
  ------------------
  |  Branch (1648:9): [True: 0, False: 25.5k]
  ------------------
 1649|      0|        return SECSuccess;
 1650|      0|    }
 1651|       |
 1652|  25.5k|finalize:
 1653|  25.5k|    switch (context->operation) {
 1654|      0|        case CKA_ENCRYPT:
  ------------------
  |  |  547|      0|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (1654:9): [True: 0, False: 25.5k]
  ------------------
 1655|      0|            crv = PK11_GETTAB(context->slot)->C_EncryptFinal(context->session, buffer, &count);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1656|      0|            break;
 1657|      0|        case CKA_DECRYPT:
  ------------------
  |  |  548|      0|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (1657:9): [True: 0, False: 25.5k]
  ------------------
 1658|      0|            crv = PK11_GETTAB(context->slot)->C_DecryptFinal(context->session, buffer, &count);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1659|      0|            break;
 1660|      0|        case CKA_SIGN:
  ------------------
  |  |  551|      0|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (1660:9): [True: 0, False: 25.5k]
  ------------------
 1661|      0|            crv = PK11_GETTAB(context->slot)->C_SignFinal(context->session, buffer, &count);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1662|      0|            break;
 1663|      0|        case CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (1663:9): [True: 0, False: 25.5k]
  ------------------
 1664|      0|            crv = PK11_GETTAB(context->slot)->C_VerifyFinal(context->session, buffer, count);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1665|      0|            break;
 1666|  25.5k|        case CKA_DIGEST:
  ------------------
  |  |   68|  25.5k|#define CKA_DIGEST 0x81000000L
  ------------------
  |  Branch (1666:9): [True: 25.5k, False: 0]
  ------------------
 1667|  25.5k|            crv = PK11_GETTAB(context->slot)->C_DigestFinal(context->session, buffer, &count);
  ------------------
  |  |  102|  25.5k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1668|  25.5k|            break;
 1669|      0|        case CKA_NSS_MESSAGE | CKA_ENCRYPT:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_ENCRYPT:
  ------------------
  |  |  547|      0|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (1669:9): [True: 0, False: 25.5k]
  ------------------
 1670|      0|            crv = PK11_GETTAB(context->slot)->C_MessageEncryptFinal(context->session);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1671|      0|            break;
 1672|      0|        case CKA_NSS_MESSAGE | CKA_DECRYPT:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_DECRYPT:
  ------------------
  |  |  548|      0|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (1672:9): [True: 0, False: 25.5k]
  ------------------
 1673|      0|            crv = PK11_GETTAB(context->slot)->C_MessageDecryptFinal(context->session);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1674|      0|            break;
 1675|      0|        case CKA_NSS_MESSAGE | CKA_SIGN:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_SIGN:
  ------------------
  |  |  551|      0|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (1675:9): [True: 0, False: 25.5k]
  ------------------
 1676|      0|            crv = PK11_GETTAB(context->slot)->C_MessageSignFinal(context->session);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1677|      0|            break;
 1678|      0|        case CKA_NSS_MESSAGE | CKA_VERIFY:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (1678:9): [True: 0, False: 25.5k]
  ------------------
 1679|      0|            crv = PK11_GETTAB(context->slot)->C_MessageVerifyFinal(context->session);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1680|      0|            break;
 1681|      0|        default:
  ------------------
  |  Branch (1681:9): [True: 0, False: 25.5k]
  ------------------
 1682|      0|            crv = CKR_OPERATION_NOT_INITIALIZED;
  ------------------
  |  | 1454|      0|#define CKR_OPERATION_NOT_INITIALIZED 0x00000091UL
  ------------------
 1683|      0|            break;
 1684|  25.5k|    }
 1685|       |
 1686|  25.5k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  25.5k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1686:9): [True: 25.5k, False: 0]
  ------------------
 1687|  25.5k|        if (buffer != stackBuf) {
  ------------------
  |  Branch (1687:13): [True: 25.5k, False: 0]
  ------------------
 1688|  25.5k|            PORT_Free(buffer);
  ------------------
  |  |   60|  25.5k|#define PORT_Free PORT_Free_Util
  ------------------
 1689|  25.5k|        }
 1690|  25.5k|        if (crv == CKR_OPERATION_NOT_INITIALIZED) {
  ------------------
  |  | 1454|  25.5k|#define CKR_OPERATION_NOT_INITIALIZED 0x00000091UL
  ------------------
  |  Branch (1690:13): [True: 25.5k, False: 0]
  ------------------
 1691|       |            /* if there's no operation, it is finalized */
 1692|  25.5k|            return SECSuccess;
 1693|  25.5k|        }
 1694|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1695|      0|        return SECFailure;
 1696|  25.5k|    }
 1697|       |
 1698|       |    /* Message interface does not need to allocate a final buffer */
 1699|      0|    if (((context->operation) & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|      0|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if (((context->operation) & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (1699:9): [True: 0, False: 0]
  ------------------
 1700|      0|        return SECSuccess;
 1701|      0|    }
 1702|       |
 1703|       |    /* try to finalize the session with a buffer */
 1704|      0|    if (buffer == NULL) {
  ------------------
  |  Branch (1704:9): [True: 0, False: 0]
  ------------------
 1705|      0|        if (count <= sizeof stackBuf) {
  ------------------
  |  Branch (1705:13): [True: 0, False: 0]
  ------------------
 1706|      0|            buffer = stackBuf;
 1707|      0|        } else {
 1708|      0|            buffer = PORT_Alloc(count);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1709|      0|            if (buffer == NULL) {
  ------------------
  |  Branch (1709:17): [True: 0, False: 0]
  ------------------
 1710|      0|                return SECFailure;
 1711|      0|            }
 1712|      0|        }
 1713|      0|        goto finalize;
 1714|      0|    }
 1715|      0|    if (buffer != stackBuf) {
  ------------------
  |  Branch (1715:9): [True: 0, False: 0]
  ------------------
 1716|      0|        PORT_Free(buffer);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1717|      0|    }
 1718|      0|    return SECSuccess;
 1719|      0|}
PK11_DigestFinal:
 1729|   348k|{
 1730|   348k|    CK_ULONG len;
 1731|   348k|    CK_RV crv;
 1732|   348k|    SECStatus rv;
 1733|       |
 1734|       |    /* message interface returns no data on Final, Should not use DigestFinal
 1735|       |     * in this case */
 1736|   348k|    if (((context->operation) & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|   348k|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if (((context->operation) & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|   348k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (1736:9): [True: 0, False: 348k]
  ------------------
 1737|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1738|      0|        return SECFailure;
 1739|      0|    }
 1740|       |
 1741|       |    /* if we ran out of session, we need to restore our previously stored
 1742|       |     * state.
 1743|       |     */
 1744|   348k|    PK11_EnterContextMonitor(context);
 1745|   348k|    if (!context->ownSession) {
  ------------------
  |  Branch (1745:9): [True: 0, False: 348k]
  ------------------
 1746|      0|        rv = pk11_restoreContext(context, context->savedData,
 1747|      0|                                 context->savedLength);
 1748|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1748:13): [True: 0, False: 0]
  ------------------
 1749|      0|            PK11_ExitContextMonitor(context);
 1750|      0|            return rv;
 1751|      0|        }
 1752|      0|    }
 1753|       |
 1754|   348k|    len = length;
 1755|   348k|    switch (context->operation) {
 1756|   106k|        case CKA_SIGN:
  ------------------
  |  |  551|   106k|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (1756:9): [True: 106k, False: 242k]
  ------------------
 1757|   106k|            crv = PK11_GETTAB(context->slot)->C_SignFinal(context->session, data, &len);
  ------------------
  |  |  102|   106k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1758|   106k|            break;
 1759|      0|        case CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (1759:9): [True: 0, False: 348k]
  ------------------
 1760|      0|            crv = PK11_GETTAB(context->slot)->C_VerifyFinal(context->session, data, len);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1761|      0|            break;
 1762|   242k|        case CKA_DIGEST:
  ------------------
  |  |   68|   242k|#define CKA_DIGEST 0x81000000L
  ------------------
  |  Branch (1762:9): [True: 242k, False: 106k]
  ------------------
 1763|   242k|            crv = PK11_GETTAB(context->slot)->C_DigestFinal(context->session, data, &len);
  ------------------
  |  |  102|   242k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1764|   242k|            break;
 1765|      0|        case CKA_ENCRYPT:
  ------------------
  |  |  547|      0|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (1765:9): [True: 0, False: 348k]
  ------------------
 1766|      0|            crv = PK11_GETTAB(context->slot)->C_EncryptFinal(context->session, data, &len);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1767|      0|            break;
 1768|      0|        case CKA_DECRYPT:
  ------------------
  |  |  548|      0|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (1768:9): [True: 0, False: 348k]
  ------------------
 1769|      0|            crv = PK11_GETTAB(context->slot)->C_DecryptFinal(context->session, data, &len);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1770|      0|            break;
 1771|      0|        default:
  ------------------
  |  Branch (1771:9): [True: 0, False: 348k]
  ------------------
 1772|      0|            crv = CKR_OPERATION_NOT_INITIALIZED;
  ------------------
  |  | 1454|      0|#define CKR_OPERATION_NOT_INITIALIZED 0x00000091UL
  ------------------
 1773|      0|            break;
 1774|   348k|    }
 1775|   348k|    PK11_ExitContextMonitor(context);
 1776|       |
 1777|   348k|    context->init = PR_FALSE; /* allow Begin to start up again */
  ------------------
  |  |  438|   348k|#define PR_FALSE 0
  ------------------
 1778|       |
 1779|   348k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   348k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1779:9): [True: 0, False: 348k]
  ------------------
 1780|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1781|      0|        return SECFailure;
 1782|      0|    }
 1783|   348k|    *outLen = (unsigned int)len;
 1784|   348k|    return SECSuccess;
 1785|   348k|}
pk11cxt.c:pk11_saveContextHelper:
   87|  34.8k|{
   88|  34.8k|    CK_RV crv;
   89|       |
   90|       |    /* If buffer is NULL, this will get the length */
   91|  34.8k|    crv = PK11_GETTAB(context->slot)->C_GetOperationState(context->session, (CK_BYTE_PTR)buffer, savedLength);
  ------------------
  |  |  102|  34.8k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
   92|  34.8k|    if (!buffer || (crv == CKR_BUFFER_TOO_SMALL)) {
  ------------------
  |  | 1514|  25.5k|#define CKR_BUFFER_TOO_SMALL 0x00000150UL
  ------------------
  |  Branch (92:9): [True: 9.32k, False: 25.5k]
  |  Branch (92:20): [True: 0, False: 25.5k]
  ------------------
   93|       |        /* the given buffer wasn't big enough (or was NULL), but we
   94|       |         * have the length, so try again with a new buffer and the
   95|       |         * correct length
   96|       |         */
   97|  9.32k|        unsigned long bufLen = *savedLength;
   98|  9.32k|        buffer = PORT_Alloc(bufLen);
  ------------------
  |  |   52|  9.32k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
   99|  9.32k|        if (buffer == NULL) {
  ------------------
  |  Branch (99:13): [True: 0, False: 9.32k]
  ------------------
  100|      0|            return (unsigned char *)NULL;
  101|      0|        }
  102|  9.32k|        crv = PK11_GETTAB(context->slot)->C_GetOperationState(context->session, (CK_BYTE_PTR)buffer, savedLength);
  ------------------
  |  |  102|  9.32k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  103|  9.32k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  9.32k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (103:13): [True: 0, False: 9.32k]
  ------------------
  104|      0|            PORT_ZFree(buffer, bufLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  105|      0|        }
  106|  9.32k|    }
  107|  34.8k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (107:9): [True: 0, False: 34.8k]
  ------------------
  108|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  109|      0|        return (unsigned char *)NULL;
  110|      0|    }
  111|  34.8k|    return buffer;
  112|  34.8k|}
pk11cxt.c:pk11_CreateNewContextInSlot:
  360|   774k|{
  361|   774k|    CK_MECHANISM mech_info;
  362|   774k|    PK11Context *context;
  363|   774k|    SECStatus rv;
  364|       |
  365|   774k|    PORT_Assert(slot != NULL);
  ------------------
  |  |  120|   774k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   774k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 774k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  366|   774k|    if (!slot || ((objectID == CK_INVALID_HANDLE) && ((operation != CKA_DIGEST) ||
  ------------------
  |  |   78|   774k|#define CK_INVALID_HANDLE 0
  ------------------
                  if (!slot || ((objectID == CK_INVALID_HANDLE) && ((operation != CKA_DIGEST) ||
  ------------------
  |  |   68|   231k|#define CKA_DIGEST 0x81000000L
  ------------------
  |  Branch (366:9): [True: 0, False: 774k]
  |  Branch (366:19): [True: 231k, False: 543k]
  |  Branch (366:55): [True: 0, False: 231k]
  ------------------
  367|   231k|                                                      (type == CKM_SKIPJACK_CBC64)))) {
  ------------------
  |  | 1049|   231k|#define CKM_SKIPJACK_CBC64 0x00001002UL
  ------------------
  |  Branch (367:55): [True: 0, False: 231k]
  ------------------
  368|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  369|      0|        return NULL;
  370|      0|    }
  371|   774k|    context = (PK11Context *)PORT_Alloc(sizeof(PK11Context));
  ------------------
  |  |   52|   774k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  372|   774k|    if (context == NULL) {
  ------------------
  |  Branch (372:9): [True: 0, False: 774k]
  ------------------
  373|      0|        return NULL;
  374|      0|    }
  375|       |
  376|       |    /* now deal with the fortezza hack... the fortezza hack is an attempt
  377|       |     * to get around the issue of the card not allowing you to do a FORTEZZA
  378|       |     * LoadIV/Encrypt, which was added because such a combination could be
  379|       |     * use to circumvent the key escrow system. Unfortunately SSL needs to
  380|       |     * do this kind of operation, so in SSL we do a loadIV (to verify it),
  381|       |     * Then GenerateIV, and through away the first 8 bytes on either side
  382|       |     * of the connection.*/
  383|   774k|    context->fortezzaHack = PR_FALSE;
  ------------------
  |  |  438|   774k|#define PR_FALSE 0
  ------------------
  384|   774k|    if (type == CKM_SKIPJACK_CBC64) {
  ------------------
  |  | 1049|   774k|#define CKM_SKIPJACK_CBC64 0x00001002UL
  ------------------
  |  Branch (384:9): [True: 0, False: 774k]
  ------------------
  385|      0|        if (symKey && (symKey->origin == PK11_OriginFortezzaHack)) {
  ------------------
  |  Branch (385:13): [True: 0, False: 0]
  |  Branch (385:23): [True: 0, False: 0]
  ------------------
  386|      0|            context->fortezzaHack = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  387|      0|        }
  388|      0|    }
  389|       |
  390|       |    /* initialize the critical fields of the context */
  391|   774k|    context->operation = operation;
  392|       |    /* If we were given a symKey, keep our own reference to it so
  393|       |     * that the key doesn't disappear in the middle of the operation
  394|       |     * if the caller frees it. Public and Private keys are not reference
  395|       |     * counted, so the caller just has to keep his copies around until
  396|       |     * the operation completes */
  397|   774k|    context->key = symKey ? PK11_ReferenceSymKey(symKey) : NULL;
  ------------------
  |  Branch (397:20): [True: 543k, False: 231k]
  ------------------
  398|   774k|    context->objectID = objectID;
  399|   774k|    context->slot = PK11_ReferenceSlot(slot);
  400|   774k|    context->session = pk11_GetNewSession(slot, &context->ownSession);
  401|   774k|    context->pwArg = pwArg;
  402|       |    /* get our session */
  403|   774k|    context->savedData = NULL;
  404|       |
  405|       |    /* save the parameters so that some digesting stuff can do multiple
  406|       |     * begins on a single context */
  407|   774k|    context->type = type;
  408|   774k|    if (param) {
  ------------------
  |  Branch (408:9): [True: 774k, False: 0]
  ------------------
  409|   774k|        if (param->len > 0) {
  ------------------
  |  Branch (409:13): [True: 208k, False: 565k]
  ------------------
  410|   208k|            context->param = SECITEM_DupItem(param);
  ------------------
  |  |  107|   208k|#define SECITEM_DupItem SECITEM_DupItem_Util
  ------------------
  411|   565k|        } else {
  412|   565k|            context->param = (SECItem *)&pk11_null_params;
  413|   565k|        }
  414|   774k|    } else {
  415|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  416|      0|        context->param = NULL;
  417|      0|    }
  418|   774k|    context->init = PR_FALSE;
  ------------------
  |  |  438|   774k|#define PR_FALSE 0
  ------------------
  419|   774k|    context->sessionLock = PZ_NewLock(nssILockPK11cxt);
  ------------------
  |  |  243|   774k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  420|   774k|    if ((context->param == NULL) || (context->sessionLock == NULL)) {
  ------------------
  |  Branch (420:9): [True: 0, False: 774k]
  |  Branch (420:37): [True: 0, False: 774k]
  ------------------
  421|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  422|      0|        return NULL;
  423|      0|    }
  424|       |
  425|   774k|    mech_info.mechanism = type;
  426|   774k|    mech_info.pParameter = param->data;
  427|   774k|    mech_info.ulParameterLen = param->len;
  428|   774k|    rv = pk11_context_init(context, &mech_info);
  429|       |
  430|   774k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (430:9): [True: 0, False: 774k]
  ------------------
  431|      0|        PK11_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  432|      0|        return NULL;
  433|      0|    }
  434|   774k|    context->init = PR_TRUE;
  ------------------
  |  |  437|   774k|#define PR_TRUE 1
  ------------------
  435|   774k|    return context;
  436|   774k|}
pk11cxt.c:pk11_context_init:
  198|   774k|{
  199|   774k|    CK_RV crv;
  200|   774k|    SECStatus rv = SECSuccess;
  201|       |
  202|   774k|    context->simulate_message = PR_FALSE;
  ------------------
  |  |  438|   774k|#define PR_FALSE 0
  ------------------
  203|   774k|    switch (context->operation) {
  204|  23.0k|        case CKA_ENCRYPT:
  ------------------
  |  |  547|  23.0k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (204:9): [True: 23.0k, False: 751k]
  ------------------
  205|  23.0k|            PK11_EnterContextMonitor(context);
  206|  23.0k|            crv = PK11_GETTAB(context->slot)->C_EncryptInit(context->session, mech_info, context->objectID);
  ------------------
  |  |  102|  23.0k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  207|  23.0k|            PK11_ExitContextMonitor(context);
  208|  23.0k|            break;
  209|  23.0k|        case CKA_DECRYPT:
  ------------------
  |  |  548|  23.0k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (209:9): [True: 23.0k, False: 751k]
  ------------------
  210|  23.0k|            PK11_EnterContextMonitor(context);
  211|  23.0k|            if (context->fortezzaHack) {
  ------------------
  |  Branch (211:17): [True: 0, False: 23.0k]
  ------------------
  212|      0|                CK_ULONG count = 0;
  213|       |                /* generate the IV for fortezza */
  214|      0|                crv = PK11_GETTAB(context->slot)->C_EncryptInit(context->session, mech_info, context->objectID);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  215|      0|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (215:21): [True: 0, False: 0]
  ------------------
  216|      0|                    PK11_ExitContextMonitor(context);
  217|      0|                    break;
  218|      0|                }
  219|      0|                PK11_GETTAB(context->slot)
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  220|      0|                    ->C_EncryptFinal(context->session,
  221|      0|                                     NULL, &count);
  222|      0|            }
  223|  23.0k|            crv = PK11_GETTAB(context->slot)->C_DecryptInit(context->session, mech_info, context->objectID);
  ------------------
  |  |  102|  23.0k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  224|  23.0k|            PK11_ExitContextMonitor(context);
  225|  23.0k|            break;
  226|   165k|        case CKA_SIGN:
  ------------------
  |  |  551|   165k|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (226:9): [True: 165k, False: 608k]
  ------------------
  227|   165k|            PK11_EnterContextMonitor(context);
  228|   165k|            crv = PK11_GETTAB(context->slot)->C_SignInit(context->session, mech_info, context->objectID);
  ------------------
  |  |  102|   165k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  229|   165k|            PK11_ExitContextMonitor(context);
  230|   165k|            break;
  231|      0|        case CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (231:9): [True: 0, False: 774k]
  ------------------
  232|       |            /* NOTE: we previously has this set to C_SignInit for Macing.
  233|       |             * It turns out now one could possibly use it that way, though,
  234|       |             * because PK11_HashOp() always called C_VerifyUpdate on CKA_VERIFY,
  235|       |             * which would have failed. So everyone just calls us with CKA_SIGN
  236|       |             * when Macing even when they are verifying, no need to 'do it
  237|       |             * for them'. It needs to be VerifyInit now so that we can do
  238|       |             * PKCS #11 hash/Verify combo operations. */
  239|      0|            PK11_EnterContextMonitor(context);
  240|      0|            crv = PK11_GETTAB(context->slot)->C_VerifyInit(context->session, mech_info, context->objectID);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  241|      0|            PK11_ExitContextMonitor(context);
  242|      0|            break;
  243|   231k|        case CKA_DIGEST:
  ------------------
  |  |   68|   231k|#define CKA_DIGEST 0x81000000L
  ------------------
  |  Branch (243:9): [True: 231k, False: 543k]
  ------------------
  244|   231k|            PK11_EnterContextMonitor(context);
  245|   231k|            crv = PK11_GETTAB(context->slot)->C_DigestInit(context->session, mech_info);
  ------------------
  |  |  102|   231k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  246|   231k|            PK11_ExitContextMonitor(context);
  247|   231k|            break;
  248|       |
  249|   161k|        case CKA_NSS_MESSAGE | CKA_ENCRYPT:
  ------------------
  |  |   69|   161k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_ENCRYPT:
  ------------------
  |  |  547|   161k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (249:9): [True: 161k, False: 612k]
  ------------------
  250|   161k|            crv = pk11_contextInitMessage(context, mech_info,
  251|   161k|                                          PK11_GETTAB(context->slot)->C_MessageEncryptInit,
  ------------------
  |  |  102|   161k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  252|   161k|                                          CKF_MESSAGE_ENCRYPT, CKR_OK);
  ------------------
  |  | 1339|   161k|#define CKF_MESSAGE_ENCRYPT 0x00000002UL
  ------------------
                                                        CKF_MESSAGE_ENCRYPT, CKR_OK);
  ------------------
  |  | 1388|   161k|#define CKR_OK 0x00000000UL
  ------------------
  253|   161k|            break;
  254|   169k|        case CKA_NSS_MESSAGE | CKA_DECRYPT:
  ------------------
  |  |   69|   169k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_DECRYPT:
  ------------------
  |  |  548|   169k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (254:9): [True: 169k, False: 604k]
  ------------------
  255|   169k|            crv = pk11_contextInitMessage(context, mech_info,
  256|   169k|                                          PK11_GETTAB(context->slot)->C_MessageDecryptInit,
  ------------------
  |  |  102|   169k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  257|   169k|                                          CKF_MESSAGE_DECRYPT, CKR_OK);
  ------------------
  |  | 1340|   169k|#define CKF_MESSAGE_DECRYPT 0x00000004UL
  ------------------
                                                        CKF_MESSAGE_DECRYPT, CKR_OK);
  ------------------
  |  | 1388|   169k|#define CKR_OK 0x00000000UL
  ------------------
  258|   169k|            break;
  259|      0|        case CKA_NSS_MESSAGE | CKA_SIGN:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_SIGN:
  ------------------
  |  |  551|      0|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (259:9): [True: 0, False: 774k]
  ------------------
  260|      0|            crv = pk11_contextInitMessage(context, mech_info,
  261|      0|                                          PK11_GETTAB(context->slot)->C_MessageSignInit,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  262|      0|                                          CKF_MESSAGE_SIGN, CKR_FUNCTION_NOT_SUPPORTED);
  ------------------
  |  | 1341|      0|#define CKF_MESSAGE_SIGN 0x00000008UL
  ------------------
                                                        CKF_MESSAGE_SIGN, CKR_FUNCTION_NOT_SUPPORTED);
  ------------------
  |  | 1426|      0|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
  263|      0|            break;
  264|      0|        case CKA_NSS_MESSAGE | CKA_VERIFY:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (264:9): [True: 0, False: 774k]
  ------------------
  265|      0|            crv = pk11_contextInitMessage(context, mech_info,
  266|      0|                                          PK11_GETTAB(context->slot)->C_MessageVerifyInit,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  267|      0|                                          CKF_MESSAGE_VERIFY, CKR_FUNCTION_NOT_SUPPORTED);
  ------------------
  |  | 1342|      0|#define CKF_MESSAGE_VERIFY 0x00000010UL
  ------------------
                                                        CKF_MESSAGE_VERIFY, CKR_FUNCTION_NOT_SUPPORTED);
  ------------------
  |  | 1426|      0|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
  268|      0|            break;
  269|      0|        default:
  ------------------
  |  Branch (269:9): [True: 0, False: 774k]
  ------------------
  270|      0|            crv = CKR_OPERATION_NOT_INITIALIZED;
  ------------------
  |  | 1454|      0|#define CKR_OPERATION_NOT_INITIALIZED 0x00000091UL
  ------------------
  271|      0|            break;
  272|   774k|    }
  273|       |
  274|   774k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   774k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (274:9): [True: 0, False: 774k]
  ------------------
  275|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  276|      0|        return SECFailure;
  277|      0|    }
  278|       |
  279|       |    /* handle the case where the token is using the old NSS mechanism */
  280|   774k|    if (context->simulate_message &&
  ------------------
  |  Branch (280:9): [True: 0, False: 774k]
  ------------------
  281|   774k|        !PK11_DoesMechanism(context->slot, context->simulate_mechanism)) {
  ------------------
  |  Branch (281:9): [True: 0, False: 0]
  ------------------
  282|      0|        if ((context->simulate_mechanism == CKM_CHACHA20_POLY1305) &&
  ------------------
  |  | 1287|      0|#define CKM_CHACHA20_POLY1305 0x00004021UL
  ------------------
  |  Branch (282:13): [True: 0, False: 0]
  ------------------
  283|      0|            PK11_DoesMechanism(context->slot, CKM_NSS_CHACHA20_POLY1305)) {
  ------------------
  |  |  243|      0|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (283:13): [True: 0, False: 0]
  ------------------
  284|      0|            context->simulate_mechanism = CKM_NSS_CHACHA20_POLY1305;
  ------------------
  |  |  243|      0|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  285|      0|        } else {
  286|      0|            PORT_SetError(PK11_MapError(CKR_MECHANISM_INVALID));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PK11_MapError(CKR_MECHANISM_INVALID));
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
  287|      0|            return SECFailure;
  288|      0|        }
  289|      0|    }
  290|       |
  291|       |    /*
  292|       |     * handle session starvation case.. use our last session to multiplex
  293|       |     */
  294|   774k|    if (!context->ownSession) {
  ------------------
  |  Branch (294:9): [True: 0, False: 774k]
  ------------------
  295|      0|        PK11_EnterContextMonitor(context);
  296|      0|        context->savedData = pk11_saveContext(context, context->savedData,
  297|      0|                                              &context->savedLength);
  298|      0|        if (context->savedData == NULL)
  ------------------
  |  Branch (298:13): [True: 0, False: 0]
  ------------------
  299|      0|            rv = SECFailure;
  300|       |        /* clear out out session for others to use */
  301|      0|        pk11_Finalize(context);
  302|      0|        PK11_ExitContextMonitor(context);
  303|      0|    }
  304|   774k|    return rv;
  305|   774k|}
pk11cxt.c:pk11_contextInitMessage:
  155|   331k|{
  156|   331k|    PK11SlotInfo *slot = context->slot;
  157|   331k|    CK_VERSION version = slot->module->cryptokiVersion;
  158|   331k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
  159|       |
  160|   331k|    context->ivCounter = 0;
  161|   331k|    context->ivMaxCount = 0;
  162|   331k|    context->ivFixedBits = 0;
  163|   331k|    context->ivLen = 0;
  164|   331k|    context->ivGen = CKG_NO_GENERATE;
  ------------------
  |  | 1991|   331k|#define CKG_NO_GENERATE 0x00000000UL
  ------------------
  165|   331k|    context->simulate_mechanism = (mech)->mechanism;
  166|   331k|    context->simulate_message = PR_FALSE;
  ------------------
  |  |  438|   331k|#define PR_FALSE 0
  ------------------
  167|       |    /* check that we can do the Message interface. We need to check
  168|       |     * for either 1) are we using a PKCS #11 v3 interface and 2) is the
  169|       |     * Message flag set on the mechanism. If either is false we simulate
  170|       |     * the message interface for the Encrypt and Decrypt cases using the
  171|       |     * PKCS #11 V2 interface.
  172|       |     * Sign and verify do not have V2 interfaces, so we go ahead and fail
  173|       |     * if those cases */
  174|   331k|    if ((version.major >= 3) &&
  ------------------
  |  Branch (174:9): [True: 331k, False: 0]
  ------------------
  175|   331k|        PK11_DoesMechanismFlag(slot, (mech)->mechanism, flags)) {
  ------------------
  |  Branch (175:9): [True: 331k, False: 0]
  ------------------
  176|   331k|        PK11_EnterContextMonitor(context);
  177|   331k|        crv = (*initFunc)((context)->session, (mech), (context)->objectID);
  178|   331k|        PK11_ExitContextMonitor(context);
  179|   331k|        if ((crv == CKR_FUNCTION_NOT_SUPPORTED) ||
  ------------------
  |  | 1426|   331k|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
  |  Branch (179:13): [True: 0, False: 331k]
  ------------------
  180|   331k|            (crv == CKR_MECHANISM_INVALID)) {
  ------------------
  |  | 1447|   331k|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
  |  Branch (180:13): [True: 0, False: 331k]
  ------------------
  181|       |            /* we have a 3.0 interface, and the flag was set (or ignored)
  182|       |             * but the implementation was not there, use the V2 interface */
  183|      0|            crv = (scrv);
  184|      0|            context->simulate_message = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  185|      0|        }
  186|   331k|    } else {
  187|      0|        crv = (scrv);
  188|      0|        context->simulate_message = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  189|      0|    }
  190|   331k|    return crv;
  191|   331k|}

PK11_MapError:
   37|  15.2k|{
   38|       |
   39|  15.2k|    switch (rv) {
   40|      0|#define MAPERROR(x, y) \
   41|      0|    case x:            \
   42|      0|        return y;
   43|       |
   44|      0|#endif
   45|       |
   46|       |    /* the guts mapping */
   47|       |    /* clang-format off */
   48|      0|    MAPERROR(CKR_OK, 0)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   49|      0|    MAPERROR(CKR_CANCEL, SEC_ERROR_IO)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   50|      0|    MAPERROR(CKR_HOST_MEMORY, SEC_ERROR_NO_MEMORY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   51|      0|    MAPERROR(CKR_SLOT_ID_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   52|  11.2k|    MAPERROR(CKR_ARGUMENTS_BAD, SEC_ERROR_INVALID_ARGS)
  ------------------
  |  |   41|  11.2k|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 11.2k, False: 4.01k]
  |  |  ------------------
  |  |   42|  11.2k|        return y;
  ------------------
   53|      0|    MAPERROR(CKR_ATTRIBUTE_READ_ONLY, SEC_ERROR_READ_ONLY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   54|      0|    MAPERROR(CKR_ATTRIBUTE_SENSITIVE, SEC_ERROR_IO) /* XX SENSITIVE */
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   55|      2|    MAPERROR(CKR_ATTRIBUTE_TYPE_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      2|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 2, False: 15.2k]
  |  |  ------------------
  |  |   42|      2|        return y;
  ------------------
   56|      0|    MAPERROR(CKR_ATTRIBUTE_VALUE_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   57|      0|    MAPERROR(CKR_BUFFER_TOO_SMALL, SEC_ERROR_OUTPUT_LEN)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   58|      0|    MAPERROR(CKR_DATA_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   59|      0|    MAPERROR(CKR_DATA_LEN_RANGE, SEC_ERROR_INPUT_LEN)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   60|      0|    MAPERROR(CKR_DEVICE_ERROR, SEC_ERROR_PKCS11_DEVICE_ERROR)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   61|      0|    MAPERROR(CKR_DEVICE_MEMORY, SEC_ERROR_NO_MEMORY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   62|      0|    MAPERROR(CKR_DEVICE_REMOVED, SEC_ERROR_NO_TOKEN)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   63|     44|    MAPERROR(CKR_DOMAIN_PARAMS_INVALID, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|     44|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 44, False: 15.1k]
  |  |  ------------------
  |  |   42|     44|        return y;
  ------------------
   64|      0|    MAPERROR(CKR_ENCRYPTED_DATA_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   65|      0|    MAPERROR(CKR_ENCRYPTED_DATA_LEN_RANGE, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   66|      0|    MAPERROR(CKR_FUNCTION_CANCELED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   67|      0|    MAPERROR(CKR_FUNCTION_FAILED, SEC_ERROR_PKCS11_FUNCTION_FAILED)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   68|      0|    MAPERROR(CKR_FUNCTION_NOT_PARALLEL, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   69|      0|    MAPERROR(CKR_FUNCTION_NOT_SUPPORTED, PR_NOT_IMPLEMENTED_ERROR)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   70|      0|    MAPERROR(CKR_GENERAL_ERROR, SEC_ERROR_PKCS11_GENERAL_ERROR)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   71|      0|    MAPERROR(CKR_KEY_HANDLE_INVALID, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   72|    225|    MAPERROR(CKR_KEY_SIZE_RANGE, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|    225|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 225, False: 15.0k]
  |  |  ------------------
  |  |   42|    225|        return y;
  ------------------
   73|    731|    MAPERROR(CKR_KEY_TYPE_INCONSISTENT, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|    731|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 731, False: 14.4k]
  |  |  ------------------
  |  |   42|    731|        return y;
  ------------------
   74|      0|    MAPERROR(CKR_MECHANISM_INVALID, SEC_ERROR_INVALID_ALGORITHM)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   75|      0|    MAPERROR(CKR_MECHANISM_PARAM_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   76|      0|    MAPERROR(CKR_NO_EVENT, SEC_ERROR_NO_EVENT)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   77|      0|    MAPERROR(CKR_OBJECT_HANDLE_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   78|      0|    MAPERROR(CKR_OPERATION_ACTIVE, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   79|      0|    MAPERROR(CKR_OPERATION_NOT_INITIALIZED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   80|      0|    MAPERROR(CKR_PIN_INCORRECT, SEC_ERROR_BAD_PASSWORD)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   81|      0|    MAPERROR(CKR_PIN_INVALID, SEC_ERROR_INVALID_PASSWORD)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   82|      0|    MAPERROR(CKR_PIN_LEN_RANGE, SEC_ERROR_INVALID_PASSWORD)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   83|      0|    MAPERROR(CKR_PIN_EXPIRED, SEC_ERROR_EXPIRED_PASSWORD)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   84|      0|    MAPERROR(CKR_PIN_LOCKED, SEC_ERROR_LOCKED_PASSWORD)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   85|      0|    MAPERROR(CKR_SESSION_CLOSED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   86|      0|    MAPERROR(CKR_SESSION_COUNT, SEC_ERROR_NO_MEMORY) /* XXXX? */
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   87|      0|    MAPERROR(CKR_SESSION_HANDLE_INVALID, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   88|      0|    MAPERROR(CKR_SESSION_PARALLEL_NOT_SUPPORTED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   89|      0|    MAPERROR(CKR_SESSION_READ_ONLY, SEC_ERROR_READ_ONLY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   90|  3.00k|    MAPERROR(CKR_SIGNATURE_INVALID, SEC_ERROR_BAD_SIGNATURE)
  ------------------
  |  |   41|  3.00k|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 3.00k, False: 12.2k]
  |  |  ------------------
  |  |   42|  3.00k|        return y;
  ------------------
   91|      0|    MAPERROR(CKR_SIGNATURE_LEN_RANGE, SEC_ERROR_BAD_SIGNATURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   92|      0|    MAPERROR(CKR_TEMPLATE_INCOMPLETE, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   93|      0|    MAPERROR(CKR_TEMPLATE_INCONSISTENT, SEC_ERROR_BAD_DATA)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   94|      0|    MAPERROR(CKR_TOKEN_NOT_PRESENT, SEC_ERROR_NO_TOKEN)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   95|      0|    MAPERROR(CKR_TOKEN_NOT_RECOGNIZED, SEC_ERROR_IO)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   96|      0|    MAPERROR(CKR_TOKEN_WRITE_PROTECTED, SEC_ERROR_READ_ONLY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   97|      0|    MAPERROR(CKR_UNWRAPPING_KEY_HANDLE_INVALID, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   98|      0|    MAPERROR(CKR_UNWRAPPING_KEY_SIZE_RANGE, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
   99|      0|    MAPERROR(CKR_UNWRAPPING_KEY_TYPE_INCONSISTENT, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  100|      0|    MAPERROR(CKR_USER_ALREADY_LOGGED_IN, 0)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  101|      0|    MAPERROR(CKR_USER_NOT_LOGGED_IN, SEC_ERROR_TOKEN_NOT_LOGGED_IN)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  102|      0|    MAPERROR(CKR_USER_PIN_NOT_INITIALIZED, SEC_ERROR_NO_TOKEN)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  103|      0|    MAPERROR(CKR_USER_TYPE_INVALID, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  104|      0|    MAPERROR(CKR_WRAPPED_KEY_INVALID, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  105|      0|    MAPERROR(CKR_WRAPPED_KEY_LEN_RANGE, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  106|      0|    MAPERROR(CKR_WRAPPING_KEY_HANDLE_INVALID, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  107|      0|    MAPERROR(CKR_WRAPPING_KEY_SIZE_RANGE, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  108|      0|    MAPERROR(CKR_WRAPPING_KEY_TYPE_INCONSISTENT, SEC_ERROR_INVALID_KEY)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  109|      0|    MAPERROR(CKR_VENDOR_DEFINED, SEC_ERROR_LIBRARY_FAILURE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  110|      0|    MAPERROR(CKR_NSS_CERTDB_FAILED, SEC_ERROR_BAD_DATABASE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  111|      0|    MAPERROR(CKR_NSS_KEYDB_FAILED, SEC_ERROR_BAD_DATABASE)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  112|      0|    MAPERROR(CKR_CANT_LOCK, SEC_ERROR_INCOMPATIBLE_PKCS11)
  ------------------
  |  |   41|      0|    case x:            \
  |  |  ------------------
  |  |  |  Branch (41:5): [True: 0, False: 15.2k]
  |  |  ------------------
  |  |   42|      0|        return y;
  ------------------
  113|       |/* clang-format on */
  114|       |
  115|       |#ifdef PK11_ERROR_USE_ARRAY
  116|       |};
  117|       |
  118|       |int
  119|       |PK11_MapError(CK_RV rv)
  120|       |{
  121|       |    int size = sizeof(pk11_error_map) / sizeof(pk11_error_map[0]);
  122|       |
  123|       |    for (i = 0; i < size; i++) {
  124|       |        if (pk11_error_map[i].pk11_error == rv) {
  125|       |            return pk11_error_map[i].sec_error;
  126|       |        }
  127|       |    }
  128|       |    return SEC_ERROR_UNKNOWN_PKCS11_ERROR;
  129|       |}
  130|       |
  131|       |#else
  132|       |
  133|       |            /* clang-format off */
  134|      0|    default :
  ------------------
  |  Branch (134:5): [True: 0, False: 15.2k]
  ------------------
  135|      0|        break;
  136|       |            /* clang-format on */
  137|  15.2k|    }
  138|      0|    return SEC_ERROR_UNKNOWN_PKCS11_ERROR;
  139|  15.2k|}

PK11_HPKE_DestroyContext:
  207|  9.90k|{
  208|  9.90k|    if (!cx) {
  ------------------
  |  Branch (208:9): [True: 9.90k, False: 0]
  ------------------
  209|  9.90k|        return;
  210|  9.90k|    }
  211|       |
  212|      0|    if (cx->aeadContext) {
  ------------------
  |  Branch (212:9): [True: 0, False: 0]
  ------------------
  213|      0|        PK11_DestroyContext((PK11Context *)cx->aeadContext, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  214|      0|        cx->aeadContext = NULL;
  215|      0|    }
  216|      0|    PK11_FreeSymKey(cx->exporterSecret);
  217|      0|    PK11_FreeSymKey(cx->sharedSecret);
  218|      0|    PK11_FreeSymKey(cx->key);
  219|      0|    PK11_FreeSymKey(cx->psk);
  220|      0|    SECITEM_FreeItem(cx->pskId, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(cx->pskId, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  221|      0|    SECITEM_FreeItem(cx->baseNonce, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(cx->baseNonce, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  222|      0|    SECITEM_FreeItem(cx->encapPubKey, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(cx->encapPubKey, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  223|      0|    cx->exporterSecret = NULL;
  224|      0|    cx->sharedSecret = NULL;
  225|      0|    cx->key = NULL;
  226|      0|    cx->psk = NULL;
  227|      0|    cx->pskId = NULL;
  228|      0|    cx->baseNonce = NULL;
  229|      0|    cx->encapPubKey = NULL;
  230|      0|    if (freeit) {
  ------------------
  |  Branch (230:9): [True: 0, False: 0]
  ------------------
  231|      0|        PORT_ZFree(cx, sizeof(HpkeContext));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  232|      0|    }
  233|      0|}

SECMOD_NewListLock:
   21|      1|{
   22|      1|    return NSSRWLock_New(10, "moduleListLock");
  ------------------
  |  |   49|      1|#define NSSRWLock_New NSSRWLock_New_Util
  ------------------
   23|      1|}
SECMOD_DestroyListLock:
   30|      1|{
   31|      1|    NSSRWLock_Destroy(lock);
  ------------------
  |  |   45|      1|#define NSSRWLock_Destroy NSSRWLock_Destroy_Util
  ------------------
   32|      1|}
SECMOD_GetReadLock:
   40|  4.22k|{
   41|  4.22k|    NSSRWLock_LockRead(modLock);
  ------------------
  |  |   47|  4.22k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  ------------------
   42|  4.22k|}
SECMOD_ReleaseReadLock:
   49|  4.22k|{
   50|  4.22k|    NSSRWLock_UnlockRead(modLock);
  ------------------
  |  |   50|  4.22k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  ------------------
   51|  4.22k|}
SECMOD_GetWriteLock:
   58|      2|{
   59|      2|    NSSRWLock_LockWrite(modLock);
  ------------------
  |  |   48|      2|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  ------------------
   60|      2|}
SECMOD_ReleaseWriteLock:
   68|      2|{
   69|      2|    NSSRWLock_UnlockWrite(modLock);
  ------------------
  |  |   51|      2|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  ------------------
   70|      2|}

secmod_ModuleInit:
  216|      1|{
  217|      1|    CK_C_INITIALIZE_ARGS moduleArgs;
  218|      1|    CK_VOID_PTR pInitArgs;
  219|      1|    CK_RV crv;
  220|       |
  221|      1|    if (reload) {
  ------------------
  |  Branch (221:9): [True: 1, False: 0]
  ------------------
  222|      1|        *reload = NULL;
  223|      1|    }
  224|       |
  225|      1|    if (!mod || !alreadyLoaded) {
  ------------------
  |  Branch (225:9): [True: 0, False: 1]
  |  Branch (225:17): [True: 0, False: 1]
  ------------------
  226|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  227|      0|        return SECFailure;
  228|      0|    }
  229|       |
  230|      1|    if (mod->libraryParams == NULL) {
  ------------------
  |  Branch (230:9): [True: 0, False: 1]
  ------------------
  231|      0|        if (mod->isThreadSafe) {
  ------------------
  |  Branch (231:13): [True: 0, False: 0]
  ------------------
  232|      0|            pInitArgs = (void *)&secmodLockFunctions;
  233|      0|        } else {
  234|      0|            pInitArgs = NULL;
  235|      0|        }
  236|      1|    } else {
  237|      1|        if (mod->isThreadSafe) {
  ------------------
  |  Branch (237:13): [True: 1, False: 0]
  ------------------
  238|      1|            moduleArgs = secmodLockFunctions;
  239|      1|        } else {
  240|      0|            moduleArgs = secmodNoLockArgs;
  241|      0|        }
  242|      1|        moduleArgs.LibraryParameters = (void *)mod->libraryParams;
  243|      1|        pInitArgs = &moduleArgs;
  244|      1|    }
  245|      1|    crv = PK11_GETTAB(mod)->C_Initialize(pInitArgs);
  ------------------
  |  |  102|      1|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  246|      1|    if (CKR_CRYPTOKI_ALREADY_INITIALIZED == crv) {
  ------------------
  |  | 1521|      1|#define CKR_CRYPTOKI_ALREADY_INITIALIZED 0x00000191UL
  ------------------
  |  Branch (246:9): [True: 0, False: 1]
  ------------------
  247|      0|        SECMODModule *oldModule = NULL;
  248|       |
  249|       |        /* Library has already been loaded once, if caller expects it, and it
  250|       |         * has additional configuration, try reloading it as well. */
  251|      0|        if (reload != NULL && mod->libraryParams) {
  ------------------
  |  Branch (251:13): [True: 0, False: 0]
  |  Branch (251:31): [True: 0, False: 0]
  ------------------
  252|      0|            oldModule = secmod_FindModuleByFuncPtr(mod->functionList);
  253|      0|        }
  254|       |        /* Library has been loaded by NSS. It means it may be capable of
  255|       |         * reloading */
  256|      0|        if (oldModule) {
  ------------------
  |  Branch (256:13): [True: 0, False: 0]
  ------------------
  257|      0|            SECStatus rv;
  258|      0|            rv = secmod_handleReload(oldModule, mod);
  259|      0|            if (rv == SECSuccess) {
  ------------------
  |  Branch (259:17): [True: 0, False: 0]
  ------------------
  260|       |                /* This module should go away soon, since we've
  261|       |                 * simply expanded the slots on the old module.
  262|       |                 * When it goes away, it should not Finalize since
  263|       |                 * that will close our old module as well. Setting
  264|       |                 * the function list to NULL will prevent that close */
  265|      0|                mod->functionList = NULL;
  266|      0|                *reload = oldModule;
  267|      0|                return SECSuccess;
  268|      0|            }
  269|      0|            SECMOD_DestroyModule(oldModule);
  270|      0|        }
  271|       |        /* reload not possible, fall back to old semantics */
  272|      0|        if (!enforceAlreadyInitializedError) {
  ------------------
  |  Branch (272:13): [True: 0, False: 0]
  ------------------
  273|      0|            *alreadyLoaded = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  274|      0|            return SECSuccess;
  275|      0|        }
  276|      0|    }
  277|      1|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (277:9): [True: 0, False: 1]
  ------------------
  278|      0|        if (!mod->isThreadSafe ||
  ------------------
  |  Branch (278:13): [True: 0, False: 0]
  ------------------
  279|      0|            crv == CKR_NSS_CERTDB_FAILED ||
  ------------------
  |  |  376|      0|#define CKR_NSS_CERTDB_FAILED (CKR_NSS + 1)
  |  |  ------------------
  |  |  |  |  374|      0|#define CKR_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKR_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (279:13): [True: 0, False: 0]
  ------------------
  280|      0|            crv == CKR_NSS_KEYDB_FAILED) {
  ------------------
  |  |  377|      0|#define CKR_NSS_KEYDB_FAILED (CKR_NSS + 2)
  |  |  ------------------
  |  |  |  |  374|      0|#define CKR_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKR_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (280:13): [True: 0, False: 0]
  ------------------
  281|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  282|      0|            return SECFailure;
  283|      0|        }
  284|       |        /* If we had attempted to init a single threaded module "with"
  285|       |         * parameters and it failed, should we retry "without" parameters?
  286|       |         * (currently we don't retry in this scenario) */
  287|       |
  288|      0|        if (!loadSingleThreadedModules) {
  ------------------
  |  Branch (288:13): [True: 0, False: 0]
  ------------------
  289|      0|            PORT_SetError(SEC_ERROR_INCOMPATIBLE_PKCS11);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  290|      0|            return SECFailure;
  291|      0|        }
  292|       |        /* If we arrive here, the module failed a ThreadSafe init. */
  293|      0|        mod->isThreadSafe = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  294|      0|        if (!mod->libraryParams) {
  ------------------
  |  Branch (294:13): [True: 0, False: 0]
  ------------------
  295|      0|            pInitArgs = NULL;
  296|      0|        } else {
  297|      0|            moduleArgs = secmodNoLockArgs;
  298|      0|            moduleArgs.LibraryParameters = (void *)mod->libraryParams;
  299|      0|            pInitArgs = &moduleArgs;
  300|      0|        }
  301|      0|        crv = PK11_GETTAB(mod)->C_Initialize(pInitArgs);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  302|      0|        if ((CKR_CRYPTOKI_ALREADY_INITIALIZED == crv) &&
  ------------------
  |  | 1521|      0|#define CKR_CRYPTOKI_ALREADY_INITIALIZED 0x00000191UL
  ------------------
  |  Branch (302:13): [True: 0, False: 0]
  ------------------
  303|      0|            (!enforceAlreadyInitializedError)) {
  ------------------
  |  Branch (303:13): [True: 0, False: 0]
  ------------------
  304|      0|            *alreadyLoaded = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  305|      0|            return SECSuccess;
  306|      0|        }
  307|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (307:13): [True: 0, False: 0]
  ------------------
  308|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  309|      0|            return SECFailure;
  310|      0|        }
  311|      0|    }
  312|      1|    return SECSuccess;
  313|      1|}
SECMOD_SetRootCerts:
  321|      2|{
  322|      2|    PK11PreSlotInfo *psi = NULL;
  323|      2|    int i;
  324|       |
  325|      2|    if (slot->hasRootCerts) {
  ------------------
  |  Branch (325:9): [True: 0, False: 2]
  ------------------
  326|      0|        for (i = 0; i < mod->slotInfoCount; i++) {
  ------------------
  |  Branch (326:21): [True: 0, False: 0]
  ------------------
  327|      0|            if (slot->slotID == mod->slotInfo[i].slotID) {
  ------------------
  |  Branch (327:17): [True: 0, False: 0]
  ------------------
  328|      0|                psi = &mod->slotInfo[i];
  329|      0|                break;
  330|      0|            }
  331|      0|        }
  332|      0|        if (psi == NULL) {
  ------------------
  |  Branch (332:13): [True: 0, False: 0]
  ------------------
  333|       |            /* allocate more slots */
  334|      0|            PK11PreSlotInfo *psi_list = (PK11PreSlotInfo *)
  335|      0|                PORT_ArenaAlloc(mod->arena,
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  336|      0|                                (mod->slotInfoCount + 1) * sizeof(PK11PreSlotInfo));
  337|       |            /* copy the old ones */
  338|      0|            if (mod->slotInfoCount > 0) {
  ------------------
  |  Branch (338:17): [True: 0, False: 0]
  ------------------
  339|      0|                PORT_Memcpy(psi_list, mod->slotInfo,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  340|      0|                            (mod->slotInfoCount) * sizeof(PK11PreSlotInfo));
  341|      0|            }
  342|       |            /* assign psi to the last new slot */
  343|      0|            psi = &psi_list[mod->slotInfoCount];
  344|      0|            psi->slotID = slot->slotID;
  345|      0|            psi->askpw = 0;
  346|      0|            psi->timeout = 0;
  347|      0|            psi->defaultFlags = 0;
  348|       |
  349|       |            /* increment module count & store new list */
  350|      0|            mod->slotInfo = psi_list;
  351|      0|            mod->slotInfoCount++;
  352|      0|        }
  353|      0|        psi->hasRootCerts = 1;
  354|      0|    }
  355|      2|}
secmod_DetermineModuleFunctionList:
  392|      2|{
  393|      2|    PRLibrary *library = NULL;
  394|      2|    CK_C_GetInterface ientry = NULL;
  395|      2|    CK_C_GetFunctionList fentry = NULL;
  396|      2|    char *disableUnload = NULL;
  397|       |#ifndef NSS_STATIC_SOFTOKEN
  398|       |    const char *nss_interface;
  399|       |    const char *nss_function;
  400|       |#endif
  401|      2|    CK_INTERFACE_PTR interface;
  402|       |
  403|       |    /* internal modules get loaded from their internal list */
  404|      2|    if (mod->internal && (mod->dllName == NULL)) {
  ------------------
  |  Branch (404:9): [True: 2, False: 0]
  |  Branch (404:26): [True: 2, False: 0]
  ------------------
  405|      2|#ifdef NSS_STATIC_SOFTOKEN
  406|      2|        ientry = (CK_C_GetInterface)NSC_GetInterface;
  407|       |#else
  408|       |        /*
  409|       |         * Loads softoken as a dynamic library,
  410|       |         * even though the rest of NSS assumes this as the "internal" module.
  411|       |         */
  412|       |        if (!softokenLib &&
  413|       |            PR_SUCCESS != PR_CallOnce(&loadSoftokenOnce, &softoken_LoadDSO))
  414|       |            return SECFailure;
  415|       |
  416|       |        PR_ATOMIC_INCREMENT(&softokenLoadCount);
  417|       |
  418|       |        if (mod->isFIPS) {
  419|       |            nss_interface = "FC_GetInterface";
  420|       |            nss_function = "FC_GetFunctionList";
  421|       |        } else {
  422|       |            nss_interface = "NSC_GetInterface";
  423|       |            nss_function = "NSC_GetFunctionList";
  424|       |        }
  425|       |
  426|       |        ientry = (CK_C_GetInterface)
  427|       |            PR_FindSymbol(softokenLib, nss_interface);
  428|       |        if (!ientry) {
  429|       |            fentry = (CK_C_GetFunctionList)
  430|       |                PR_FindSymbol(softokenLib, nss_function);
  431|       |            if (!fentry) {
  432|       |                return SECFailure;
  433|       |            }
  434|       |        }
  435|       |#endif
  436|       |
  437|      2|        if (mod->isModuleDB) {
  ------------------
  |  Branch (437:13): [True: 1, False: 1]
  ------------------
  438|      1|            mod->moduleDBFunc = (CK_C_GetFunctionList)
  439|      1|#ifdef NSS_STATIC_SOFTOKEN
  440|      1|                NSC_ModuleDBFunc;
  441|       |#else
  442|       |                PR_FindSymbol(softokenLib, "NSC_ModuleDBFunc");
  443|       |#endif
  444|      1|        }
  445|       |
  446|      2|        if (mod->moduleDBOnly) {
  ------------------
  |  Branch (446:13): [True: 1, False: 1]
  ------------------
  447|      1|            mod->loaded = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  448|      1|            return SECSuccess;
  449|      1|        }
  450|      2|    } else {
  451|       |        /* Not internal, load the DLL and look up C_GetFunctionList */
  452|      0|        if (mod->dllName == NULL) {
  ------------------
  |  Branch (452:13): [True: 0, False: 0]
  ------------------
  453|      0|            return SECFailure;
  454|      0|        }
  455|       |
  456|       |/* load the library. If this succeeds, then we have to remember to
  457|       | * unload the library if anything goes wrong from here on out...
  458|       | */
  459|       |#if defined(_WIN32)
  460|       |        if (nssUTF8_Length(mod->dllName, NULL)) {
  461|       |            wchar_t *dllNameWide = _NSSUTIL_UTF8ToWide(mod->dllName);
  462|       |            if (dllNameWide) {
  463|       |                PRLibSpec libSpec;
  464|       |                libSpec.type = PR_LibSpec_PathnameU;
  465|       |                libSpec.value.pathname_u = dllNameWide;
  466|       |                library = PR_LoadLibraryWithFlags(libSpec, 0);
  467|       |                PORT_Free(dllNameWide);
  468|       |            }
  469|       |        }
  470|       |        if (library == NULL) {
  471|       |            // fallback to system code page
  472|       |            library = PR_LoadLibrary(mod->dllName);
  473|       |        }
  474|       |#else
  475|      0|        library = PR_LoadLibrary(mod->dllName);
  476|      0|#endif // defined(_WIN32)
  477|      0|        mod->library = (void *)library;
  478|       |
  479|      0|        if (library == NULL) {
  ------------------
  |  Branch (479:13): [True: 0, False: 0]
  ------------------
  480|      0|            return SECFailure;
  481|      0|        }
  482|       |
  483|       |        /*
  484|       |         * now we need to get the entry point to find the function pointers
  485|       |         */
  486|      0|        if (!mod->moduleDBOnly) {
  ------------------
  |  Branch (486:13): [True: 0, False: 0]
  ------------------
  487|      0|            ientry = (CK_C_GetInterface)
  488|      0|                PR_FindSymbol(library, "C_GetInterface");
  489|      0|            if (!ientry) {
  ------------------
  |  Branch (489:17): [True: 0, False: 0]
  ------------------
  490|      0|                fentry = (CK_C_GetFunctionList)
  491|      0|                    PR_FindSymbol(library, "C_GetFunctionList");
  492|      0|            }
  493|      0|        }
  494|      0|        if (mod->isModuleDB) {
  ------------------
  |  Branch (494:13): [True: 0, False: 0]
  ------------------
  495|      0|            mod->moduleDBFunc = (void *)
  496|      0|                PR_FindSymbol(library, "NSS_ReturnModuleSpecData");
  497|      0|        }
  498|      0|        if (mod->moduleDBFunc == NULL)
  ------------------
  |  Branch (498:13): [True: 0, False: 0]
  ------------------
  499|      0|            mod->isModuleDB = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  500|      0|        if ((ientry == NULL) && (fentry == NULL)) {
  ------------------
  |  Branch (500:13): [True: 0, False: 0]
  |  Branch (500:33): [True: 0, False: 0]
  ------------------
  501|      0|            if (mod->isModuleDB) {
  ------------------
  |  Branch (501:17): [True: 0, False: 0]
  ------------------
  502|      0|                mod->loaded = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  503|      0|                mod->moduleDBOnly = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  504|      0|                return SECSuccess;
  505|      0|            }
  506|      0|            PR_UnloadLibrary(library);
  507|      0|            return SECFailure;
  508|      0|        }
  509|      0|    }
  510|       |
  511|       |    /*
  512|       |     * We need to get the function list
  513|       |     */
  514|      1|    if (ientry) {
  ------------------
  |  Branch (514:9): [True: 1, False: 0]
  ------------------
  515|       |        /* we first try to get a FORK_SAFE interface */
  516|      1|        if ((*ientry)((CK_UTF8CHAR_PTR) "PKCS 11", NULL, &interface,
  ------------------
  |  Branch (516:13): [True: 0, False: 1]
  ------------------
  517|      1|                      CKF_INTERFACE_FORK_SAFE) != CKR_OK) {
  ------------------
  |  | 1576|      1|#define CKF_INTERFACE_FORK_SAFE 0x00000001UL
  ------------------
                                    CKF_INTERFACE_FORK_SAFE) != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  518|       |            /* one is not appearantly available, get a non-fork safe version */
  519|      0|            if ((*ientry)((CK_UTF8CHAR_PTR) "PKCS 11", NULL, &interface, 0) != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (519:17): [True: 0, False: 0]
  ------------------
  520|      0|                goto fail;
  521|      0|            }
  522|      0|        }
  523|      1|        mod->functionList = interface->pFunctionList;
  524|      1|        mod->flags = interface->flags;
  525|       |        /* if we have a fips indicator, grab it */
  526|      1|        if ((*ientry)((CK_UTF8CHAR_PTR) "Vendor NSS FIPS Interface", NULL,
  ------------------
  |  Branch (526:13): [True: 1, False: 0]
  ------------------
  527|      1|                      &interface, 0) == CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  528|      1|            mod->fipsIndicator = ((CK_NSS_FIPS_FUNCTIONS *)(interface->pFunctionList))->NSC_NSSGetFIPSStatus;
  529|      1|        }
  530|      1|    } else {
  531|      0|        if ((*fentry)((CK_FUNCTION_LIST_PTR *)&mod->functionList) != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (531:13): [True: 0, False: 0]
  ------------------
  532|      0|            goto fail;
  533|      0|        mod->flags = 0;
  534|      0|    }
  535|       |
  536|      1|#ifdef DEBUG_MODULE
  537|      1|    modToDBG = PR_GetEnvSecure("NSS_DEBUG_PKCS11_MODULE");
  538|      1|    if (modToDBG && strcmp(mod->commonName, modToDBG) == 0) {
  ------------------
  |  Branch (538:9): [True: 0, False: 1]
  |  Branch (538:21): [True: 0, False: 0]
  ------------------
  539|      0|        mod->functionList = (void *)nss_InsertDeviceLog(
  540|      0|            (CK_FUNCTION_LIST_3_0_PTR)mod->functionList);
  541|      0|    }
  542|      1|#endif
  543|       |
  544|      1|    return SECSuccess;
  545|       |
  546|      0|fail:
  547|      0|    mod->functionList = NULL;
  548|      0|    disableUnload = PR_GetEnvSecure("NSS_DISABLE_UNLOAD");
  549|      0|    if (library && !disableUnload) {
  ------------------
  |  Branch (549:9): [True: 0, False: 0]
  |  Branch (549:20): [True: 0, False: 0]
  ------------------
  550|      0|        PR_UnloadLibrary(library);
  551|      0|    }
  552|      0|    return SECFailure;
  553|      1|}
secmod_InitializeModuleAndGetSlotInfo:
  557|      1|{
  558|      1|    CK_INFO info;
  559|      1|    CK_ULONG slotCount = 0;
  560|      1|    SECStatus rv;
  561|      1|    PRBool alreadyLoaded = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  562|       |
  563|       |    /* This test operation makes sure our locking system is
  564|       |     * consistent even if we are using non-thread safe tokens by
  565|       |     * simulating unsafe tokens with safe ones. */
  566|      1|    mod->isThreadSafe = !PR_GetEnvSecure("NSS_FORCE_TOKEN_LOCK");
  567|       |
  568|       |    /* Now we initialize the module */
  569|      1|    rv = secmod_ModuleInit(mod, oldModule, &alreadyLoaded);
  570|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (570:9): [True: 0, False: 1]
  ------------------
  571|      0|        goto fail;
  572|      0|    }
  573|       |
  574|       |    /* module has been reloaded, this module itself is done,
  575|       |     * return to the caller */
  576|      1|    if (mod->functionList == NULL) {
  ------------------
  |  Branch (576:9): [True: 0, False: 1]
  ------------------
  577|      0|        mod->loaded = PR_TRUE; /* technically the module is loaded.. */
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  578|      0|        return SECSuccess;
  579|      0|    }
  580|       |
  581|       |    /* check the version number */
  582|      1|    if (PK11_GETTAB(mod)->C_GetInfo(&info) != CKR_OK)
  ------------------
  |  |  102|      1|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
                  if (PK11_GETTAB(mod)->C_GetInfo(&info) != CKR_OK)
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (582:9): [True: 0, False: 1]
  ------------------
  583|      0|        goto fail2;
  584|      1|    if (info.cryptokiVersion.major < 2)
  ------------------
  |  Branch (584:9): [True: 0, False: 1]
  ------------------
  585|      0|        goto fail2;
  586|       |    /* all 2.0 are a priori *not* thread safe */
  587|      1|    if ((info.cryptokiVersion.major == 2) && (info.cryptokiVersion.minor < 1)) {
  ------------------
  |  Branch (587:9): [True: 0, False: 1]
  |  Branch (587:46): [True: 0, False: 0]
  ------------------
  588|      0|        if (!loadSingleThreadedModules) {
  ------------------
  |  Branch (588:13): [True: 0, False: 0]
  ------------------
  589|      0|            PORT_SetError(SEC_ERROR_INCOMPATIBLE_PKCS11);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  590|      0|            goto fail2;
  591|      0|        } else {
  592|      0|            mod->isThreadSafe = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  593|      0|        }
  594|      0|    }
  595|      1|    mod->cryptokiVersion = info.cryptokiVersion;
  596|       |
  597|       |    /* If we don't have a common name, get it from the PKCS 11 module */
  598|      1|    if ((mod->commonName == NULL) || (mod->commonName[0] == 0)) {
  ------------------
  |  Branch (598:9): [True: 0, False: 1]
  |  Branch (598:38): [True: 0, False: 1]
  ------------------
  599|      0|        mod->commonName = PK11_MakeString(mod->arena, NULL,
  600|      0|                                          (char *)info.libraryDescription, sizeof(info.libraryDescription));
  601|      0|        if (mod->commonName == NULL)
  ------------------
  |  Branch (601:13): [True: 0, False: 0]
  ------------------
  602|      0|            goto fail2;
  603|      0|    }
  604|       |
  605|       |    /* initialize the Slots */
  606|      1|    if (PK11_GETTAB(mod)->C_GetSlotList(CK_FALSE, NULL, &slotCount) == CKR_OK) {
  ------------------
  |  |  102|      1|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
                  if (PK11_GETTAB(mod)->C_GetSlotList(CK_FALSE, NULL, &slotCount) == CKR_OK) {
  ------------------
  |  |   23|      1|#define CK_FALSE 0
  ------------------
                  if (PK11_GETTAB(mod)->C_GetSlotList(CK_FALSE, NULL, &slotCount) == CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (606:9): [True: 1, False: 0]
  ------------------
  607|      1|        CK_SLOT_ID *slotIDs;
  608|      1|        int i;
  609|      1|        CK_RV crv;
  610|       |
  611|      1|        mod->slots = (PK11SlotInfo **)PORT_ArenaAlloc(mod->arena,
  ------------------
  |  |   53|      1|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  612|      1|                                                      sizeof(PK11SlotInfo *) * slotCount);
  613|      1|        if (mod->slots == NULL)
  ------------------
  |  Branch (613:13): [True: 0, False: 1]
  ------------------
  614|      0|            goto fail2;
  615|       |
  616|      1|        slotIDs = (CK_SLOT_ID *)PORT_Alloc(sizeof(CK_SLOT_ID) * slotCount);
  ------------------
  |  |   52|      1|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  617|      1|        if (slotIDs == NULL) {
  ------------------
  |  Branch (617:13): [True: 0, False: 1]
  ------------------
  618|      0|            goto fail2;
  619|      0|        }
  620|      1|        crv = PK11_GETTAB(mod)->C_GetSlotList(CK_FALSE, slotIDs, &slotCount);
  ------------------
  |  |  102|      1|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
                      crv = PK11_GETTAB(mod)->C_GetSlotList(CK_FALSE, slotIDs, &slotCount);
  ------------------
  |  |   23|      1|#define CK_FALSE 0
  ------------------
  621|      1|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (621:13): [True: 0, False: 1]
  ------------------
  622|      0|            PORT_Free(slotIDs);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  623|      0|            goto fail2;
  624|      0|        }
  625|       |
  626|       |        /* Initialize each slot */
  627|      3|        for (i = 0; i < (int)slotCount; i++) {
  ------------------
  |  Branch (627:21): [True: 2, False: 1]
  ------------------
  628|      2|            mod->slots[i] = PK11_NewSlotInfo(mod);
  629|      2|            PK11_InitSlot(mod, slotIDs[i], mod->slots[i]);
  630|       |            /* look down the slot info table */
  631|      2|            PK11_LoadSlotList(mod->slots[i], mod->slotInfo, mod->slotInfoCount);
  632|      2|            SECMOD_SetRootCerts(mod->slots[i], mod);
  633|       |            /* explicitly mark the internal slot as such if IsInternalKeySlot()
  634|       |             * is set */
  635|      2|            if (secmod_IsInternalKeySlot(mod) && (i == (mod->isFIPS ? 0 : 1))) {
  ------------------
  |  Branch (635:17): [True: 2, False: 0]
  |  Branch (635:50): [True: 1, False: 1]
  |  Branch (635:57): [True: 0, False: 2]
  ------------------
  636|      1|                pk11_SetInternalKeySlotIfFirst(mod->slots[i]);
  637|      1|            }
  638|      2|        }
  639|      1|        mod->slotCount = slotCount;
  640|      1|        mod->slotInfoCount = 0;
  641|      1|        PORT_Free(slotIDs);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  642|      1|    }
  643|       |
  644|      1|    mod->loaded = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  645|      1|    mod->moduleID = nextModuleID++;
  646|      1|    return SECSuccess;
  647|      0|fail2:
  648|      0|    if (enforceAlreadyInitializedError || (!alreadyLoaded)) {
  ------------------
  |  Branch (648:9): [True: 0, False: 0]
  |  Branch (648:43): [True: 0, False: 0]
  ------------------
  649|      0|        PK11_GETTAB(mod)->C_Finalize(NULL);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  650|      0|    }
  651|      0|fail:
  652|      0|    mod->functionList = NULL;
  653|      0|    return SECFailure;
  654|      0|}
secmod_LoadPKCS11Module:
  661|      2|{
  662|      2|    SECStatus rv = SECFailure;
  663|      2|    if (mod->loaded) {
  ------------------
  |  Branch (663:9): [True: 0, False: 2]
  ------------------
  664|      0|        return SECSuccess;
  665|      0|    }
  666|       |
  667|      2|    mod->fipsIndicator = NULL;
  668|       |
  669|      2|    rv = secmod_DetermineModuleFunctionList(mod);
  670|      2|    if (rv != SECSuccess) { // The error code is set up by secmod_DetermineModuleFunctionList.
  ------------------
  |  Branch (670:9): [True: 0, False: 2]
  ------------------
  671|      0|        return rv;
  672|      0|    }
  673|       |
  674|      2|    if (mod->loaded == PR_TRUE) {
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  |  Branch (674:9): [True: 1, False: 1]
  ------------------
  675|      1|        return SECSuccess;
  676|      1|    }
  677|       |
  678|      1|    rv = secmod_InitializeModuleAndGetSlotInfo(mod, oldModule);
  679|      1|    if (rv != SECSuccess) { // The error code is set up by secmod_InitializeModuleAndGetSlotInfo
  ------------------
  |  Branch (679:9): [True: 0, False: 1]
  ------------------
  680|      0|        return rv;
  681|      0|    }
  682|       |
  683|      1|    return SECSuccess;
  684|      1|}
SECMOD_UnloadModule:
  729|      2|{
  730|      2|    PRLibrary *library;
  731|      2|    char *disableUnload = NULL;
  732|       |
  733|      2|    if (!mod->loaded) {
  ------------------
  |  Branch (733:9): [True: 0, False: 2]
  ------------------
  734|      0|        return SECFailure;
  735|      0|    }
  736|      2|    if (finalizeModules) {
  ------------------
  |  Branch (736:9): [True: 2, False: 0]
  ------------------
  737|      2|        if (mod->functionList && !mod->moduleDBOnly) {
  ------------------
  |  Branch (737:13): [True: 1, False: 1]
  |  Branch (737:34): [True: 1, False: 0]
  ------------------
  738|      1|            PK11_GETTAB(mod)->C_Finalize(NULL);
  ------------------
  |  |  102|      1|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  739|      1|        }
  740|      2|    }
  741|      2|    mod->moduleID = 0;
  742|      2|    mod->loaded = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  743|       |
  744|       |    /* do we want the semantics to allow unloading the internal library?
  745|       |     * if not, we should change this to SECFailure and move it above the
  746|       |     * mod->loaded = PR_FALSE; */
  747|      2|    if (mod->internal && (mod->dllName == NULL)) {
  ------------------
  |  Branch (747:9): [True: 2, False: 0]
  |  Branch (747:26): [True: 2, False: 0]
  ------------------
  748|       |#ifndef NSS_STATIC_SOFTOKEN
  749|       |        if (0 == PR_ATOMIC_DECREMENT(&softokenLoadCount)) {
  750|       |            if (softokenLib) {
  751|       |                disableUnload = PR_GetEnvSecure("NSS_DISABLE_UNLOAD");
  752|       |                if (!disableUnload) {
  753|       |#ifdef DEBUG
  754|       |                    PRStatus status = PR_UnloadLibrary(softokenLib);
  755|       |                    PORT_Assert(PR_SUCCESS == status);
  756|       |#else
  757|       |                    PR_UnloadLibrary(softokenLib);
  758|       |#endif
  759|       |                }
  760|       |                softokenLib = NULL;
  761|       |            }
  762|       |            loadSoftokenOnce = pristineCallOnce;
  763|       |        }
  764|       |#endif
  765|      2|        return SECSuccess;
  766|      2|    }
  767|       |
  768|      0|    library = (PRLibrary *)mod->library;
  769|       |    /* if no library, then we should not unload it */
  770|      0|    if (library == NULL) {
  ------------------
  |  Branch (770:9): [True: 0, False: 0]
  ------------------
  771|      0|        return SECSuccess;
  772|      0|    }
  773|       |
  774|      0|    disableUnload = PR_GetEnvSecure("NSS_DISABLE_UNLOAD");
  775|      0|    if (!disableUnload) {
  ------------------
  |  Branch (775:9): [True: 0, False: 0]
  ------------------
  776|      0|        PR_UnloadLibrary(library);
  777|      0|    }
  778|      0|    return SECSuccess;
  779|      0|}
nss_DumpModuleLog:
  783|      1|{
  784|      1|#ifdef DEBUG_MODULE
  785|      1|    if (modToDBG) {
  ------------------
  |  Branch (785:9): [True: 0, False: 1]
  ------------------
  786|      0|        print_final_statistics();
  787|      0|    }
  788|      1|#endif
  789|      1|}

PK11_GetBestWrapMechanism:
   90|  33.9k|{
   91|  33.9k|    int i;
   92|  33.9k|    for (i = 0; i < wrapMechanismCount; i++) {
  ------------------
  |  Branch (92:17): [True: 33.9k, False: 0]
  ------------------
   93|  33.9k|        if (PK11_DoesMechanism(slot, wrapMechanismList[i])) {
  ------------------
  |  Branch (93:13): [True: 33.9k, False: 0]
  ------------------
   94|  33.9k|            return wrapMechanismList[i];
   95|  33.9k|        }
   96|  33.9k|    }
   97|      0|    return CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
   98|  33.9k|}
PK11_GetKeyType:
  216|  1.02M|{
  217|  1.02M|    switch (type) {
  218|      0|        case CKM_SEED_ECB:
  ------------------
  |  | 1156|      0|#define CKM_SEED_ECB 0x00000651UL
  ------------------
  |  Branch (218:9): [True: 0, False: 1.02M]
  ------------------
  219|    743|        case CKM_SEED_CBC:
  ------------------
  |  | 1157|    743|#define CKM_SEED_CBC 0x00000652UL
  ------------------
  |  Branch (219:9): [True: 743, False: 1.02M]
  ------------------
  220|    743|        case CKM_SEED_MAC:
  ------------------
  |  | 1158|    743|#define CKM_SEED_MAC 0x00000653UL
  ------------------
  |  Branch (220:9): [True: 0, False: 1.02M]
  ------------------
  221|    743|        case CKM_SEED_MAC_GENERAL:
  ------------------
  |  | 1159|    743|#define CKM_SEED_MAC_GENERAL 0x00000654UL
  ------------------
  |  Branch (221:9): [True: 0, False: 1.02M]
  ------------------
  222|    743|        case CKM_SEED_CBC_PAD:
  ------------------
  |  | 1160|    743|#define CKM_SEED_CBC_PAD 0x00000655UL
  ------------------
  |  Branch (222:9): [True: 0, False: 1.02M]
  ------------------
  223|    743|        case CKM_SEED_KEY_GEN:
  ------------------
  |  | 1155|    743|#define CKM_SEED_KEY_GEN 0x00000650UL
  ------------------
  |  Branch (223:9): [True: 0, False: 1.02M]
  ------------------
  224|    743|            return CKK_SEED;
  ------------------
  |  |  416|    743|#define CKK_SEED 0x0000002FUL /* was 2A */
  ------------------
  225|      0|        case CKM_CAMELLIA_ECB:
  ------------------
  |  | 1136|      0|#define CKM_CAMELLIA_ECB 0x00000551UL
  ------------------
  |  Branch (225:9): [True: 0, False: 1.02M]
  ------------------
  226|  1.01k|        case CKM_CAMELLIA_CBC:
  ------------------
  |  | 1137|  1.01k|#define CKM_CAMELLIA_CBC 0x00000552UL
  ------------------
  |  Branch (226:9): [True: 1.01k, False: 1.02M]
  ------------------
  227|  1.01k|        case CKM_CAMELLIA_MAC:
  ------------------
  |  | 1138|  1.01k|#define CKM_CAMELLIA_MAC 0x00000553UL
  ------------------
  |  Branch (227:9): [True: 0, False: 1.02M]
  ------------------
  228|  1.01k|        case CKM_CAMELLIA_MAC_GENERAL:
  ------------------
  |  | 1139|  1.01k|#define CKM_CAMELLIA_MAC_GENERAL 0x00000554UL
  ------------------
  |  Branch (228:9): [True: 0, False: 1.02M]
  ------------------
  229|  1.01k|        case CKM_CAMELLIA_CBC_PAD:
  ------------------
  |  | 1140|  1.01k|#define CKM_CAMELLIA_CBC_PAD 0x00000555UL
  ------------------
  |  Branch (229:9): [True: 0, False: 1.02M]
  ------------------
  230|  1.01k|        case CKM_CAMELLIA_KEY_GEN:
  ------------------
  |  | 1135|  1.01k|#define CKM_CAMELLIA_KEY_GEN 0x00000550UL
  ------------------
  |  Branch (230:9): [True: 0, False: 1.02M]
  ------------------
  231|  1.01k|            return CKK_CAMELLIA;
  ------------------
  |  |  414|  1.01k|#define CKK_CAMELLIA 0x00000025UL
  ------------------
  232|      0|        case CKM_NSS_CHACHA20_POLY1305:
  ------------------
  |  |  243|      0|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (232:9): [True: 0, False: 1.02M]
  ------------------
  233|      0|        case CKM_NSS_CHACHA20_KEY_GEN:
  ------------------
  |  |  242|      0|#define CKM_NSS_CHACHA20_KEY_GEN (CKM_NSS + 27)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (233:9): [True: 0, False: 1.02M]
  ------------------
  234|      0|        case CKM_NSS_CHACHA20_CTR:
  ------------------
  |  |  251|      0|#define CKM_NSS_CHACHA20_CTR (CKM_NSS + 33)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (234:9): [True: 0, False: 1.02M]
  ------------------
  235|      0|            return CKK_NSS_CHACHA20;
  ------------------
  |  |   56|      0|#define CKK_NSS_CHACHA20 (CKK_NSS + 4)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  236|  4.65k|        case CKM_CHACHA20_POLY1305:
  ------------------
  |  | 1287|  4.65k|#define CKM_CHACHA20_POLY1305 0x00004021UL
  ------------------
  |  Branch (236:9): [True: 4.65k, False: 1.02M]
  ------------------
  237|  4.65k|        case CKM_CHACHA20_KEY_GEN:
  ------------------
  |  | 1203|  4.65k|#define CKM_CHACHA20_KEY_GEN 0x00001225UL
  ------------------
  |  Branch (237:9): [True: 0, False: 1.02M]
  ------------------
  238|  4.65k|        case CKM_CHACHA20:
  ------------------
  |  | 1204|  4.65k|#define CKM_CHACHA20 0x00001226UL
  ------------------
  |  Branch (238:9): [True: 0, False: 1.02M]
  ------------------
  239|  4.65k|            return CKK_CHACHA20;
  ------------------
  |  |  433|  4.65k|#define CKK_CHACHA20 0x00000033UL
  ------------------
  240|      0|        case CKM_AES_ECB:
  ------------------
  |  | 1107|      0|#define CKM_AES_ECB 0x00001081UL
  ------------------
  |  Branch (240:9): [True: 0, False: 1.02M]
  ------------------
  241|  8.20k|        case CKM_AES_CBC:
  ------------------
  |  | 1108|  8.20k|#define CKM_AES_CBC 0x00001082UL
  ------------------
  |  Branch (241:9): [True: 8.20k, False: 1.02M]
  ------------------
  242|  8.20k|        case CKM_AES_CCM:
  ------------------
  |  | 1116|  8.20k|#define CKM_AES_CCM 0x00001088UL
  ------------------
  |  Branch (242:9): [True: 0, False: 1.02M]
  ------------------
  243|  8.20k|        case CKM_AES_CTR:
  ------------------
  |  | 1113|  8.20k|#define CKM_AES_CTR 0x00001086UL
  ------------------
  |  Branch (243:9): [True: 0, False: 1.02M]
  ------------------
  244|  8.20k|        case CKM_AES_CTS:
  ------------------
  |  | 1117|  8.20k|#define CKM_AES_CTS 0x00001089UL
  ------------------
  |  Branch (244:9): [True: 0, False: 1.02M]
  ------------------
  245|   308k|        case CKM_AES_GCM:
  ------------------
  |  | 1115|   308k|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (245:9): [True: 300k, False: 728k]
  ------------------
  246|   308k|        case CKM_AES_MAC:
  ------------------
  |  | 1109|   308k|#define CKM_AES_MAC 0x00001083UL
  ------------------
  |  Branch (246:9): [True: 0, False: 1.02M]
  ------------------
  247|   308k|        case CKM_AES_MAC_GENERAL:
  ------------------
  |  | 1110|   308k|#define CKM_AES_MAC_GENERAL 0x00001084UL
  ------------------
  |  Branch (247:9): [True: 0, False: 1.02M]
  ------------------
  248|   308k|        case CKM_AES_CMAC:
  ------------------
  |  | 1119|   308k|#define CKM_AES_CMAC 0x0000108AUL
  ------------------
  |  Branch (248:9): [True: 0, False: 1.02M]
  ------------------
  249|   308k|        case CKM_AES_CMAC_GENERAL:
  ------------------
  |  | 1120|   308k|#define CKM_AES_CMAC_GENERAL 0x0000108BUL
  ------------------
  |  Branch (249:9): [True: 0, False: 1.02M]
  ------------------
  250|   308k|        case CKM_AES_CBC_PAD:
  ------------------
  |  | 1111|   308k|#define CKM_AES_CBC_PAD 0x00001085UL
  ------------------
  |  Branch (250:9): [True: 0, False: 1.02M]
  ------------------
  251|   308k|        case CKM_AES_KEY_GEN:
  ------------------
  |  | 1106|   308k|#define CKM_AES_KEY_GEN 0x00001080UL
  ------------------
  |  Branch (251:9): [True: 0, False: 1.02M]
  ------------------
  252|   308k|        case CKM_NSS_AES_KEY_WRAP:
  ------------------
  |  |  164|   308k|#define CKM_NSS_AES_KEY_WRAP (CKM_NSS + 1)
  |  |  ------------------
  |  |  |  |  162|   308k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|   308k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   308k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (252:9): [True: 0, False: 1.02M]
  ------------------
  253|   308k|        case CKM_NSS_AES_KEY_WRAP_PAD:
  ------------------
  |  |  165|   308k|#define CKM_NSS_AES_KEY_WRAP_PAD (CKM_NSS + 2)
  |  |  ------------------
  |  |  |  |  162|   308k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|   308k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   308k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (253:9): [True: 0, False: 1.02M]
  ------------------
  254|   308k|        case CKM_AES_KEY_WRAP:
  ------------------
  |  | 1231|   308k|#define CKM_AES_KEY_WRAP 0x00002109UL
  ------------------
  |  Branch (254:9): [True: 0, False: 1.02M]
  ------------------
  255|   308k|        case CKM_AES_KEY_WRAP_KWP:
  ------------------
  |  | 1233|   308k|#define CKM_AES_KEY_WRAP_KWP 0x0000210BUL
  ------------------
  |  Branch (255:9): [True: 0, False: 1.02M]
  ------------------
  256|   308k|        case CKM_AES_XCBC_MAC:
  ------------------
  |  | 1121|   308k|#define CKM_AES_XCBC_MAC 0x0000108CUL
  ------------------
  |  Branch (256:9): [True: 0, False: 1.02M]
  ------------------
  257|   308k|        case CKM_AES_XCBC_MAC_96:
  ------------------
  |  | 1122|   308k|#define CKM_AES_XCBC_MAC_96 0x0000108DUL
  ------------------
  |  Branch (257:9): [True: 0, False: 1.02M]
  ------------------
  258|   308k|            return CKK_AES;
  ------------------
  |  |  402|   308k|#define CKK_AES 0x0000001FUL
  ------------------
  259|      0|        case CKM_DES_ECB:
  ------------------
  |  |  815|      0|#define CKM_DES_ECB 0x00000121UL
  ------------------
  |  Branch (259:9): [True: 0, False: 1.02M]
  ------------------
  260|  7.40k|        case CKM_DES_CBC:
  ------------------
  |  |  816|  7.40k|#define CKM_DES_CBC 0x00000122UL
  ------------------
  |  Branch (260:9): [True: 7.40k, False: 1.02M]
  ------------------
  261|  7.40k|        case CKM_DES_MAC:
  ------------------
  |  |  817|  7.40k|#define CKM_DES_MAC 0x00000123UL
  ------------------
  |  Branch (261:9): [True: 0, False: 1.02M]
  ------------------
  262|  7.40k|        case CKM_DES_MAC_GENERAL:
  ------------------
  |  |  820|  7.40k|#define CKM_DES_MAC_GENERAL 0x00000124UL
  ------------------
  |  Branch (262:9): [True: 0, False: 1.02M]
  ------------------
  263|  7.40k|        case CKM_DES_CBC_PAD:
  ------------------
  |  |  821|  7.40k|#define CKM_DES_CBC_PAD 0x00000125UL
  ------------------
  |  Branch (263:9): [True: 0, False: 1.02M]
  ------------------
  264|  7.40k|        case CKM_DES_KEY_GEN:
  ------------------
  |  |  814|  7.40k|#define CKM_DES_KEY_GEN 0x00000120UL
  ------------------
  |  Branch (264:9): [True: 0, False: 1.02M]
  ------------------
  265|  7.40k|        case CKM_KEY_WRAP_LYNKS:
  ------------------
  |  | 1035|  7.40k|#define CKM_KEY_WRAP_LYNKS 0x00000400UL
  ------------------
  |  Branch (265:9): [True: 0, False: 1.02M]
  ------------------
  266|  7.40k|        case CKM_PBE_MD2_DES_CBC:
  ------------------
  |  |  997|  7.40k|#define CKM_PBE_MD2_DES_CBC 0x000003A0UL
  ------------------
  |  Branch (266:9): [True: 0, False: 1.02M]
  ------------------
  267|  7.40k|        case CKM_PBE_MD5_DES_CBC:
  ------------------
  |  |  998|  7.40k|#define CKM_PBE_MD5_DES_CBC 0x000003A1UL
  ------------------
  |  Branch (267:9): [True: 0, False: 1.02M]
  ------------------
  268|  7.40k|            return CKK_DES;
  ------------------
  |  |  386|  7.40k|#define CKK_DES 0x00000013UL
  ------------------
  269|      1|        case CKM_DES3_ECB:
  ------------------
  |  |  825|      1|#define CKM_DES3_ECB 0x00000132UL
  ------------------
  |  Branch (269:9): [True: 1, False: 1.02M]
  ------------------
  270|  5.05k|        case CKM_DES3_CBC:
  ------------------
  |  |  826|  5.05k|#define CKM_DES3_CBC 0x00000133UL
  ------------------
  |  Branch (270:9): [True: 5.05k, False: 1.02M]
  ------------------
  271|  5.05k|        case CKM_DES3_MAC:
  ------------------
  |  |  827|  5.05k|#define CKM_DES3_MAC 0x00000134UL
  ------------------
  |  Branch (271:9): [True: 0, False: 1.02M]
  ------------------
  272|  5.05k|        case CKM_DES3_MAC_GENERAL:
  ------------------
  |  |  832|  5.05k|#define CKM_DES3_MAC_GENERAL 0x00000135UL
  ------------------
  |  Branch (272:9): [True: 0, False: 1.02M]
  ------------------
  273|  5.05k|        case CKM_DES3_CBC_PAD:
  ------------------
  |  |  833|  5.05k|#define CKM_DES3_CBC_PAD 0x00000136UL
  ------------------
  |  Branch (273:9): [True: 0, False: 1.02M]
  ------------------
  274|  5.05k|            return (len == 16) ? CKK_DES2 : CKK_DES3;
  ------------------
  |  |  387|      0|#define CKK_DES2 0x00000014UL
  ------------------
                          return (len == 16) ? CKK_DES2 : CKK_DES3;
  ------------------
  |  |  388|  5.05k|#define CKK_DES3 0x00000015UL
  ------------------
  |  Branch (274:20): [True: 0, False: 5.05k]
  ------------------
  275|      0|        case CKM_DES2_KEY_GEN:
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
  |  Branch (275:9): [True: 0, False: 1.02M]
  ------------------
  276|      0|        case CKM_PBE_SHA1_DES2_EDE_CBC:
  ------------------
  |  | 1008|      0|#define CKM_PBE_SHA1_DES2_EDE_CBC 0x000003A9UL
  ------------------
  |  Branch (276:9): [True: 0, False: 1.02M]
  ------------------
  277|      0|            return CKK_DES2;
  ------------------
  |  |  387|      0|#define CKK_DES2 0x00000014UL
  ------------------
  278|      0|        case CKM_PBE_SHA1_DES3_EDE_CBC:
  ------------------
  |  | 1007|      0|#define CKM_PBE_SHA1_DES3_EDE_CBC 0x000003A8UL
  ------------------
  |  Branch (278:9): [True: 0, False: 1.02M]
  ------------------
  279|      0|        case CKM_DES3_KEY_GEN:
  ------------------
  |  |  824|      0|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  |  Branch (279:9): [True: 0, False: 1.02M]
  ------------------
  280|      0|            return CKK_DES3;
  ------------------
  |  |  388|      0|#define CKK_DES3 0x00000015UL
  ------------------
  281|      0|        case CKM_CDMF_ECB:
  ------------------
  |  |  835|      0|#define CKM_CDMF_ECB 0x00000141UL
  ------------------
  |  Branch (281:9): [True: 0, False: 1.02M]
  ------------------
  282|      0|        case CKM_CDMF_CBC:
  ------------------
  |  |  836|      0|#define CKM_CDMF_CBC 0x00000142UL
  ------------------
  |  Branch (282:9): [True: 0, False: 1.02M]
  ------------------
  283|      0|        case CKM_CDMF_MAC:
  ------------------
  |  |  837|      0|#define CKM_CDMF_MAC 0x00000143UL
  ------------------
  |  Branch (283:9): [True: 0, False: 1.02M]
  ------------------
  284|      0|        case CKM_CDMF_MAC_GENERAL:
  ------------------
  |  |  838|      0|#define CKM_CDMF_MAC_GENERAL 0x00000144UL
  ------------------
  |  Branch (284:9): [True: 0, False: 1.02M]
  ------------------
  285|      0|        case CKM_CDMF_CBC_PAD:
  ------------------
  |  |  839|      0|#define CKM_CDMF_CBC_PAD 0x00000145UL
  ------------------
  |  Branch (285:9): [True: 0, False: 1.02M]
  ------------------
  286|      0|        case CKM_CDMF_KEY_GEN:
  ------------------
  |  |  834|      0|#define CKM_CDMF_KEY_GEN 0x00000140UL
  ------------------
  |  Branch (286:9): [True: 0, False: 1.02M]
  ------------------
  287|      0|            return CKK_CDMF;
  ------------------
  |  |  401|      0|#define CKK_CDMF 0x0000001EUL
  ------------------
  288|      0|        case CKM_RC2_ECB:
  ------------------
  |  |  804|      0|#define CKM_RC2_ECB 0x00000101UL
  ------------------
  |  Branch (288:9): [True: 0, False: 1.02M]
  ------------------
  289|      0|        case CKM_RC2_CBC:
  ------------------
  |  |  805|      0|#define CKM_RC2_CBC 0x00000102UL
  ------------------
  |  Branch (289:9): [True: 0, False: 1.02M]
  ------------------
  290|      0|        case CKM_RC2_MAC:
  ------------------
  |  |  806|      0|#define CKM_RC2_MAC 0x00000103UL
  ------------------
  |  Branch (290:9): [True: 0, False: 1.02M]
  ------------------
  291|      0|        case CKM_RC2_MAC_GENERAL:
  ------------------
  |  |  809|      0|#define CKM_RC2_MAC_GENERAL 0x00000104UL
  ------------------
  |  Branch (291:9): [True: 0, False: 1.02M]
  ------------------
  292|      0|        case CKM_RC2_CBC_PAD:
  ------------------
  |  |  810|      0|#define CKM_RC2_CBC_PAD 0x00000105UL
  ------------------
  |  Branch (292:9): [True: 0, False: 1.02M]
  ------------------
  293|      0|        case CKM_RC2_KEY_GEN:
  ------------------
  |  |  803|      0|#define CKM_RC2_KEY_GEN 0x00000100UL
  ------------------
  |  Branch (293:9): [True: 0, False: 1.02M]
  ------------------
  294|      0|        case CKM_PBE_SHA1_RC2_128_CBC:
  ------------------
  |  | 1009|      0|#define CKM_PBE_SHA1_RC2_128_CBC 0x000003AAUL
  ------------------
  |  Branch (294:9): [True: 0, False: 1.02M]
  ------------------
  295|      0|        case CKM_PBE_SHA1_RC2_40_CBC:
  ------------------
  |  | 1010|      0|#define CKM_PBE_SHA1_RC2_40_CBC 0x000003ABUL
  ------------------
  |  Branch (295:9): [True: 0, False: 1.02M]
  ------------------
  296|      0|            return CKK_RC2;
  ------------------
  |  |  384|      0|#define CKK_RC2 0x00000011UL
  ------------------
  297|    593|        case CKM_RC4:
  ------------------
  |  |  813|    593|#define CKM_RC4 0x00000111UL
  ------------------
  |  Branch (297:9): [True: 593, False: 1.02M]
  ------------------
  298|    593|        case CKM_RC4_KEY_GEN:
  ------------------
  |  |  812|    593|#define CKM_RC4_KEY_GEN 0x00000110UL
  ------------------
  |  Branch (298:9): [True: 0, False: 1.02M]
  ------------------
  299|    593|            return CKK_RC4;
  ------------------
  |  |  385|    593|#define CKK_RC4 0x00000012UL
  ------------------
  300|      0|        case CKM_RC5_ECB:
  ------------------
  |  |  942|      0|#define CKM_RC5_ECB 0x00000331UL
  ------------------
  |  Branch (300:9): [True: 0, False: 1.02M]
  ------------------
  301|      0|        case CKM_RC5_CBC:
  ------------------
  |  |  943|      0|#define CKM_RC5_CBC 0x00000332UL
  ------------------
  |  Branch (301:9): [True: 0, False: 1.02M]
  ------------------
  302|      0|        case CKM_RC5_MAC:
  ------------------
  |  |  944|      0|#define CKM_RC5_MAC 0x00000333UL
  ------------------
  |  Branch (302:9): [True: 0, False: 1.02M]
  ------------------
  303|      0|        case CKM_RC5_MAC_GENERAL:
  ------------------
  |  |  945|      0|#define CKM_RC5_MAC_GENERAL 0x00000334UL
  ------------------
  |  Branch (303:9): [True: 0, False: 1.02M]
  ------------------
  304|      0|        case CKM_RC5_CBC_PAD:
  ------------------
  |  |  946|      0|#define CKM_RC5_CBC_PAD 0x00000335UL
  ------------------
  |  Branch (304:9): [True: 0, False: 1.02M]
  ------------------
  305|      0|        case CKM_RC5_KEY_GEN:
  ------------------
  |  |  941|      0|#define CKM_RC5_KEY_GEN 0x00000330UL
  ------------------
  |  Branch (305:9): [True: 0, False: 1.02M]
  ------------------
  306|      0|            return CKK_RC5;
  ------------------
  |  |  396|      0|#define CKK_RC5 0x00000019UL
  ------------------
  307|      0|        case CKM_SKIPJACK_CBC64:
  ------------------
  |  | 1049|      0|#define CKM_SKIPJACK_CBC64 0x00001002UL
  ------------------
  |  Branch (307:9): [True: 0, False: 1.02M]
  ------------------
  308|      0|        case CKM_SKIPJACK_ECB64:
  ------------------
  |  | 1048|      0|#define CKM_SKIPJACK_ECB64 0x00001001UL
  ------------------
  |  Branch (308:9): [True: 0, False: 1.02M]
  ------------------
  309|      0|        case CKM_SKIPJACK_OFB64:
  ------------------
  |  | 1050|      0|#define CKM_SKIPJACK_OFB64 0x00001003UL
  ------------------
  |  Branch (309:9): [True: 0, False: 1.02M]
  ------------------
  310|      0|        case CKM_SKIPJACK_CFB64:
  ------------------
  |  | 1051|      0|#define CKM_SKIPJACK_CFB64 0x00001004UL
  ------------------
  |  Branch (310:9): [True: 0, False: 1.02M]
  ------------------
  311|      0|        case CKM_SKIPJACK_CFB32:
  ------------------
  |  | 1052|      0|#define CKM_SKIPJACK_CFB32 0x00001005UL
  ------------------
  |  Branch (311:9): [True: 0, False: 1.02M]
  ------------------
  312|      0|        case CKM_SKIPJACK_CFB16:
  ------------------
  |  | 1053|      0|#define CKM_SKIPJACK_CFB16 0x00001006UL
  ------------------
  |  Branch (312:9): [True: 0, False: 1.02M]
  ------------------
  313|      0|        case CKM_SKIPJACK_CFB8:
  ------------------
  |  | 1054|      0|#define CKM_SKIPJACK_CFB8 0x00001007UL
  ------------------
  |  Branch (313:9): [True: 0, False: 1.02M]
  ------------------
  314|      0|        case CKM_SKIPJACK_KEY_GEN:
  ------------------
  |  | 1047|      0|#define CKM_SKIPJACK_KEY_GEN 0x00001000UL
  ------------------
  |  Branch (314:9): [True: 0, False: 1.02M]
  ------------------
  315|      0|        case CKM_SKIPJACK_WRAP:
  ------------------
  |  | 1055|      0|#define CKM_SKIPJACK_WRAP 0x00001008UL
  ------------------
  |  Branch (315:9): [True: 0, False: 1.02M]
  ------------------
  316|      0|        case CKM_SKIPJACK_PRIVATE_WRAP:
  ------------------
  |  | 1056|      0|#define CKM_SKIPJACK_PRIVATE_WRAP 0x00001009UL
  ------------------
  |  Branch (316:9): [True: 0, False: 1.02M]
  ------------------
  317|      0|            return CKK_SKIPJACK;
  ------------------
  |  |  398|      0|#define CKK_SKIPJACK 0x0000001BUL
  ------------------
  318|      0|        case CKM_BATON_ECB128:
  ------------------
  |  | 1062|      0|#define CKM_BATON_ECB128 0x00001031UL
  ------------------
  |  Branch (318:9): [True: 0, False: 1.02M]
  ------------------
  319|      0|        case CKM_BATON_ECB96:
  ------------------
  |  | 1063|      0|#define CKM_BATON_ECB96 0x00001032UL
  ------------------
  |  Branch (319:9): [True: 0, False: 1.02M]
  ------------------
  320|      0|        case CKM_BATON_CBC128:
  ------------------
  |  | 1064|      0|#define CKM_BATON_CBC128 0x00001033UL
  ------------------
  |  Branch (320:9): [True: 0, False: 1.02M]
  ------------------
  321|      0|        case CKM_BATON_COUNTER:
  ------------------
  |  | 1065|      0|#define CKM_BATON_COUNTER 0x00001034UL
  ------------------
  |  Branch (321:9): [True: 0, False: 1.02M]
  ------------------
  322|      0|        case CKM_BATON_SHUFFLE:
  ------------------
  |  | 1066|      0|#define CKM_BATON_SHUFFLE 0x00001035UL
  ------------------
  |  Branch (322:9): [True: 0, False: 1.02M]
  ------------------
  323|      0|        case CKM_BATON_WRAP:
  ------------------
  |  | 1067|      0|#define CKM_BATON_WRAP 0x00001036UL
  ------------------
  |  Branch (323:9): [True: 0, False: 1.02M]
  ------------------
  324|      0|        case CKM_BATON_KEY_GEN:
  ------------------
  |  | 1061|      0|#define CKM_BATON_KEY_GEN 0x00001030UL
  ------------------
  |  Branch (324:9): [True: 0, False: 1.02M]
  ------------------
  325|      0|            return CKK_BATON;
  ------------------
  |  |  399|      0|#define CKK_BATON 0x0000001CUL
  ------------------
  326|      0|        case CKM_JUNIPER_ECB128:
  ------------------
  |  | 1095|      0|#define CKM_JUNIPER_ECB128 0x00001061UL
  ------------------
  |  Branch (326:9): [True: 0, False: 1.02M]
  ------------------
  327|      0|        case CKM_JUNIPER_CBC128:
  ------------------
  |  | 1096|      0|#define CKM_JUNIPER_CBC128 0x00001062UL
  ------------------
  |  Branch (327:9): [True: 0, False: 1.02M]
  ------------------
  328|      0|        case CKM_JUNIPER_COUNTER:
  ------------------
  |  | 1097|      0|#define CKM_JUNIPER_COUNTER 0x00001063UL
  ------------------
  |  Branch (328:9): [True: 0, False: 1.02M]
  ------------------
  329|      0|        case CKM_JUNIPER_SHUFFLE:
  ------------------
  |  | 1098|      0|#define CKM_JUNIPER_SHUFFLE 0x00001064UL
  ------------------
  |  Branch (329:9): [True: 0, False: 1.02M]
  ------------------
  330|      0|        case CKM_JUNIPER_WRAP:
  ------------------
  |  | 1099|      0|#define CKM_JUNIPER_WRAP 0x00001065UL
  ------------------
  |  Branch (330:9): [True: 0, False: 1.02M]
  ------------------
  331|      0|        case CKM_JUNIPER_KEY_GEN:
  ------------------
  |  | 1094|      0|#define CKM_JUNIPER_KEY_GEN 0x00001060UL
  ------------------
  |  Branch (331:9): [True: 0, False: 1.02M]
  ------------------
  332|      0|            return CKK_JUNIPER;
  ------------------
  |  |  400|      0|#define CKK_JUNIPER 0x0000001DUL
  ------------------
  333|      0|        case CKM_IDEA_CBC:
  ------------------
  |  |  949|      0|#define CKM_IDEA_CBC 0x00000342UL
  ------------------
  |  Branch (333:9): [True: 0, False: 1.02M]
  ------------------
  334|      0|        case CKM_IDEA_ECB:
  ------------------
  |  |  948|      0|#define CKM_IDEA_ECB 0x00000341UL
  ------------------
  |  Branch (334:9): [True: 0, False: 1.02M]
  ------------------
  335|      0|        case CKM_IDEA_MAC:
  ------------------
  |  |  950|      0|#define CKM_IDEA_MAC 0x00000343UL
  ------------------
  |  Branch (335:9): [True: 0, False: 1.02M]
  ------------------
  336|      0|        case CKM_IDEA_MAC_GENERAL:
  ------------------
  |  |  951|      0|#define CKM_IDEA_MAC_GENERAL 0x00000344UL
  ------------------
  |  Branch (336:9): [True: 0, False: 1.02M]
  ------------------
  337|      0|        case CKM_IDEA_CBC_PAD:
  ------------------
  |  |  952|      0|#define CKM_IDEA_CBC_PAD 0x00000345UL
  ------------------
  |  Branch (337:9): [True: 0, False: 1.02M]
  ------------------
  338|      0|        case CKM_IDEA_KEY_GEN:
  ------------------
  |  |  947|      0|#define CKM_IDEA_KEY_GEN 0x00000340UL
  ------------------
  |  Branch (338:9): [True: 0, False: 1.02M]
  ------------------
  339|      0|            return CKK_IDEA;
  ------------------
  |  |  397|      0|#define CKK_IDEA 0x0000001AUL
  ------------------
  340|      0|        case CKM_CAST_ECB:
  ------------------
  |  |  918|      0|#define CKM_CAST_ECB 0x00000301UL
  ------------------
  |  Branch (340:9): [True: 0, False: 1.02M]
  ------------------
  341|      0|        case CKM_CAST_CBC:
  ------------------
  |  |  919|      0|#define CKM_CAST_CBC 0x00000302UL
  ------------------
  |  Branch (341:9): [True: 0, False: 1.02M]
  ------------------
  342|      0|        case CKM_CAST_MAC:
  ------------------
  |  |  920|      0|#define CKM_CAST_MAC 0x00000303UL
  ------------------
  |  Branch (342:9): [True: 0, False: 1.02M]
  ------------------
  343|      0|        case CKM_CAST_MAC_GENERAL:
  ------------------
  |  |  921|      0|#define CKM_CAST_MAC_GENERAL 0x00000304UL
  ------------------
  |  Branch (343:9): [True: 0, False: 1.02M]
  ------------------
  344|      0|        case CKM_CAST_CBC_PAD:
  ------------------
  |  |  922|      0|#define CKM_CAST_CBC_PAD 0x00000305UL
  ------------------
  |  Branch (344:9): [True: 0, False: 1.02M]
  ------------------
  345|      0|        case CKM_CAST_KEY_GEN:
  ------------------
  |  |  917|      0|#define CKM_CAST_KEY_GEN 0x00000300UL
  ------------------
  |  Branch (345:9): [True: 0, False: 1.02M]
  ------------------
  346|      0|        case CKM_PBE_MD5_CAST_CBC:
  ------------------
  |  |  999|      0|#define CKM_PBE_MD5_CAST_CBC 0x000003A2UL
  ------------------
  |  Branch (346:9): [True: 0, False: 1.02M]
  ------------------
  347|      0|            return CKK_CAST;
  ------------------
  |  |  391|      0|#define CKK_CAST 0x00000016UL
  ------------------
  348|      0|        case CKM_CAST3_ECB:
  ------------------
  |  |  924|      0|#define CKM_CAST3_ECB 0x00000311UL
  ------------------
  |  Branch (348:9): [True: 0, False: 1.02M]
  ------------------
  349|      0|        case CKM_CAST3_CBC:
  ------------------
  |  |  925|      0|#define CKM_CAST3_CBC 0x00000312UL
  ------------------
  |  Branch (349:9): [True: 0, False: 1.02M]
  ------------------
  350|      0|        case CKM_CAST3_MAC:
  ------------------
  |  |  926|      0|#define CKM_CAST3_MAC 0x00000313UL
  ------------------
  |  Branch (350:9): [True: 0, False: 1.02M]
  ------------------
  351|      0|        case CKM_CAST3_MAC_GENERAL:
  ------------------
  |  |  927|      0|#define CKM_CAST3_MAC_GENERAL 0x00000314UL
  ------------------
  |  Branch (351:9): [True: 0, False: 1.02M]
  ------------------
  352|      0|        case CKM_CAST3_CBC_PAD:
  ------------------
  |  |  928|      0|#define CKM_CAST3_CBC_PAD 0x00000315UL
  ------------------
  |  Branch (352:9): [True: 0, False: 1.02M]
  ------------------
  353|      0|        case CKM_CAST3_KEY_GEN:
  ------------------
  |  |  923|      0|#define CKM_CAST3_KEY_GEN 0x00000310UL
  ------------------
  |  Branch (353:9): [True: 0, False: 1.02M]
  ------------------
  354|      0|        case CKM_PBE_MD5_CAST3_CBC:
  ------------------
  |  | 1000|      0|#define CKM_PBE_MD5_CAST3_CBC 0x000003A3UL
  ------------------
  |  Branch (354:9): [True: 0, False: 1.02M]
  ------------------
  355|      0|            return CKK_CAST3;
  ------------------
  |  |  392|      0|#define CKK_CAST3 0x00000017UL
  ------------------
  356|      0|        case CKM_CAST5_ECB:
  ------------------
  |  |  931|      0|#define CKM_CAST5_ECB 0x00000321UL
  ------------------
  |  Branch (356:9): [True: 0, False: 1.02M]
  ------------------
  357|      0|        case CKM_CAST5_CBC:
  ------------------
  |  |  933|      0|#define CKM_CAST5_CBC 0x00000322UL
  ------------------
  |  Branch (357:9): [True: 0, False: 1.02M]
  ------------------
  358|      0|        case CKM_CAST5_MAC:
  ------------------
  |  |  935|      0|#define CKM_CAST5_MAC 0x00000323UL
  ------------------
  |  Branch (358:9): [True: 0, False: 1.02M]
  ------------------
  359|      0|        case CKM_CAST5_MAC_GENERAL:
  ------------------
  |  |  937|      0|#define CKM_CAST5_MAC_GENERAL 0x00000324UL
  ------------------
  |  Branch (359:9): [True: 0, False: 1.02M]
  ------------------
  360|      0|        case CKM_CAST5_CBC_PAD:
  ------------------
  |  |  939|      0|#define CKM_CAST5_CBC_PAD 0x00000325UL
  ------------------
  |  Branch (360:9): [True: 0, False: 1.02M]
  ------------------
  361|      0|        case CKM_CAST5_KEY_GEN:
  ------------------
  |  |  929|      0|#define CKM_CAST5_KEY_GEN 0x00000320UL
  ------------------
  |  Branch (361:9): [True: 0, False: 1.02M]
  ------------------
  362|      0|        case CKM_PBE_MD5_CAST5_CBC:
  ------------------
  |  | 1001|      0|#define CKM_PBE_MD5_CAST5_CBC 0x000003A4UL
  ------------------
  |  Branch (362:9): [True: 0, False: 1.02M]
  ------------------
  363|      0|            return CKK_CAST5;
  ------------------
  |  |  394|      0|#define CKK_CAST5 0x00000018UL
  ------------------
  364|      0|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (364:9): [True: 0, False: 1.02M]
  ------------------
  365|      0|        case CKM_RSA_9796:
  ------------------
  |  |  721|      0|#define CKM_RSA_9796 0x00000002UL
  ------------------
  |  Branch (365:9): [True: 0, False: 1.02M]
  ------------------
  366|      0|        case CKM_RSA_X_509:
  ------------------
  |  |  722|      0|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (366:9): [True: 0, False: 1.02M]
  ------------------
  367|      0|        case CKM_MD2_RSA_PKCS:
  ------------------
  |  |  726|      0|#define CKM_MD2_RSA_PKCS 0x00000004UL
  ------------------
  |  Branch (367:9): [True: 0, False: 1.02M]
  ------------------
  368|      0|        case CKM_MD5_RSA_PKCS:
  ------------------
  |  |  727|      0|#define CKM_MD5_RSA_PKCS 0x00000005UL
  ------------------
  |  Branch (368:9): [True: 0, False: 1.02M]
  ------------------
  369|      0|        case CKM_SHA1_RSA_PKCS:
  ------------------
  |  |  728|      0|#define CKM_SHA1_RSA_PKCS 0x00000006UL
  ------------------
  |  Branch (369:9): [True: 0, False: 1.02M]
  ------------------
  370|      0|        case CKM_SHA224_RSA_PKCS:
  ------------------
  |  |  778|      0|#define CKM_SHA224_RSA_PKCS 0x00000046UL
  ------------------
  |  Branch (370:9): [True: 0, False: 1.02M]
  ------------------
  371|      0|        case CKM_SHA256_RSA_PKCS:
  ------------------
  |  |  770|      0|#define CKM_SHA256_RSA_PKCS 0x00000040UL
  ------------------
  |  Branch (371:9): [True: 0, False: 1.02M]
  ------------------
  372|      0|        case CKM_SHA384_RSA_PKCS:
  ------------------
  |  |  771|      0|#define CKM_SHA384_RSA_PKCS 0x00000041UL
  ------------------
  |  Branch (372:9): [True: 0, False: 1.02M]
  ------------------
  373|      0|        case CKM_SHA512_RSA_PKCS:
  ------------------
  |  |  772|      0|#define CKM_SHA512_RSA_PKCS 0x00000042UL
  ------------------
  |  Branch (373:9): [True: 0, False: 1.02M]
  ------------------
  374|      0|        case CKM_KEY_WRAP_SET_OAEP:
  ------------------
  |  | 1036|      0|#define CKM_KEY_WRAP_SET_OAEP 0x00000401UL
  ------------------
  |  Branch (374:9): [True: 0, False: 1.02M]
  ------------------
  375|      0|        case CKM_RSA_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  719|      0|#define CKM_RSA_PKCS_KEY_PAIR_GEN 0x00000000UL
  ------------------
  |  Branch (375:9): [True: 0, False: 1.02M]
  ------------------
  376|      0|        case CKM_RSA_X9_31_KEY_PAIR_GEN:
  ------------------
  |  |  738|      0|#define CKM_RSA_X9_31_KEY_PAIR_GEN 0x0000000AUL
  ------------------
  |  Branch (376:9): [True: 0, False: 1.02M]
  ------------------
  377|      0|            return CKK_RSA;
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  378|      0|        case CKM_DSA:
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (378:9): [True: 0, False: 1.02M]
  ------------------
  379|      0|        case CKM_DSA_SHA1:
  ------------------
  |  |  746|      0|#define CKM_DSA_SHA1 0x00000012UL
  ------------------
  |  Branch (379:9): [True: 0, False: 1.02M]
  ------------------
  380|      0|        case CKM_DSA_KEY_PAIR_GEN:
  ------------------
  |  |  744|      0|#define CKM_DSA_KEY_PAIR_GEN 0x00000010UL
  ------------------
  |  Branch (380:9): [True: 0, False: 1.02M]
  ------------------
  381|      0|            return CKK_DSA;
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  382|      0|        case CKM_DH_PKCS_DERIVE:
  ------------------
  |  |  759|      0|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
  |  Branch (382:9): [True: 0, False: 1.02M]
  ------------------
  383|      0|        case CKM_DH_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  758|      0|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  |  Branch (383:9): [True: 0, False: 1.02M]
  ------------------
  384|      0|            return CKK_DH;
  ------------------
  |  |  374|      0|#define CKK_DH 0x00000002UL
  ------------------
  385|      0|        case CKM_KEA_KEY_DERIVE:
  ------------------
  |  | 1059|      0|#define CKM_KEA_KEY_DERIVE 0x00001011UL
  ------------------
  |  Branch (385:9): [True: 0, False: 1.02M]
  ------------------
  386|      0|        case CKM_KEA_KEY_PAIR_GEN:
  ------------------
  |  | 1058|      0|#define CKM_KEA_KEY_PAIR_GEN 0x00001010UL
  ------------------
  |  Branch (386:9): [True: 0, False: 1.02M]
  ------------------
  387|      0|            return CKK_KEA;
  ------------------
  |  |  381|      0|#define CKK_KEA 0x00000005UL
  ------------------
  388|      0|        case CKM_ECDSA:
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (388:9): [True: 0, False: 1.02M]
  ------------------
  389|      0|        case CKM_ECDSA_SHA1:
  ------------------
  |  | 1075|      0|#define CKM_ECDSA_SHA1 0x00001042UL
  ------------------
  |  Branch (389:9): [True: 0, False: 1.02M]
  ------------------
  390|      0|        case CKM_EC_KEY_PAIR_GEN: /* aka CKM_ECDSA_KEY_PAIR_GEN */
  ------------------
  |  | 1072|      0|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  |  Branch (390:9): [True: 0, False: 1.02M]
  ------------------
  391|      0|        case CKM_ECDH1_DERIVE:
  ------------------
  |  | 1086|      0|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  |  Branch (391:9): [True: 0, False: 1.02M]
  ------------------
  392|      0|            return CKK_EC; /* CKK_ECDSA is deprecated */
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  393|      0|        case CKM_EC_EDWARDS_KEY_PAIR_GEN:
  ------------------
  |  | 1172|      0|#define CKM_EC_EDWARDS_KEY_PAIR_GEN 0x00001055UL
  ------------------
  |  Branch (393:9): [True: 0, False: 1.02M]
  ------------------
  394|      0|        case CKM_EDDSA:
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
  |  Branch (394:9): [True: 0, False: 1.02M]
  ------------------
  395|      0|            return CKK_EC_EDWARDS;
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  396|      0|        case CKM_HKDF_KEY_GEN:
  ------------------
  |  | 1298|      0|#define CKM_HKDF_KEY_GEN 0x0000402cUL
  ------------------
  |  Branch (396:9): [True: 0, False: 1.02M]
  ------------------
  397|   293k|        case CKM_HKDF_DERIVE:
  ------------------
  |  | 1296|   293k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  |  Branch (397:9): [True: 293k, False: 734k]
  ------------------
  398|   293k|        case CKM_HKDF_DATA:
  ------------------
  |  | 1297|   293k|#define CKM_HKDF_DATA 0x0000402bUL
  ------------------
  |  Branch (398:9): [True: 0, False: 1.02M]
  ------------------
  399|   293k|            return CKK_HKDF;
  ------------------
  |  |  450|   293k|#define CKK_HKDF 0x00000042UL
  ------------------
  400|      0|        case CKM_SSL3_PRE_MASTER_KEY_GEN:
  ------------------
  |  |  959|      0|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
  |  Branch (400:9): [True: 0, False: 1.02M]
  ------------------
  401|      0|        case CKM_GENERIC_SECRET_KEY_GEN:
  ------------------
  |  |  953|      0|#define CKM_GENERIC_SECRET_KEY_GEN 0x00000350UL
  ------------------
  |  Branch (401:9): [True: 0, False: 1.02M]
  ------------------
  402|  11.9k|        case CKM_SSL3_MASTER_KEY_DERIVE:
  ------------------
  |  |  960|  11.9k|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
  |  Branch (402:9): [True: 11.9k, False: 1.01M]
  ------------------
  403|  11.9k|        case CKM_SSL3_MASTER_KEY_DERIVE_DH:
  ------------------
  |  |  966|  11.9k|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
  |  Branch (403:9): [True: 0, False: 1.02M]
  ------------------
  404|  11.9k|        case CKM_SSL3_KEY_AND_MAC_DERIVE:
  ------------------
  |  |  961|  11.9k|#define CKM_SSL3_KEY_AND_MAC_DERIVE 0x00000372UL
  ------------------
  |  Branch (404:9): [True: 0, False: 1.02M]
  ------------------
  405|  11.9k|        case CKM_SSL3_SHA1_MAC:
  ------------------
  |  |  976|  11.9k|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
  |  Branch (405:9): [True: 0, False: 1.02M]
  ------------------
  406|  11.9k|        case CKM_SSL3_MD5_MAC:
  ------------------
  |  |  975|  11.9k|#define CKM_SSL3_MD5_MAC 0x00000380UL
  ------------------
  |  Branch (406:9): [True: 0, False: 1.02M]
  ------------------
  407|  11.9k|        case CKM_TLS_MASTER_KEY_DERIVE:
  ------------------
  |  |  968|  11.9k|#define CKM_TLS_MASTER_KEY_DERIVE 0x00000375UL
  ------------------
  |  Branch (407:9): [True: 0, False: 1.02M]
  ------------------
  408|  11.9k|        case CKM_NSS_TLS_MASTER_KEY_DERIVE_SHA256:
  ------------------
  |  |  234|  11.9k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_SHA256 (CKM_NSS + 22)
  |  |  ------------------
  |  |  |  |  162|  11.9k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  11.9k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  11.9k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (408:9): [True: 0, False: 1.02M]
  ------------------
  409|  40.7k|        case CKM_TLS_MASTER_KEY_DERIVE_DH:
  ------------------
  |  |  970|  40.7k|#define CKM_TLS_MASTER_KEY_DERIVE_DH 0x00000377UL
  ------------------
  |  Branch (409:9): [True: 28.7k, False: 999k]
  ------------------
  410|  40.7k|        case CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256:
  ------------------
  |  |  236|  40.7k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256 (CKM_NSS + 24)
  |  |  ------------------
  |  |  |  |  162|  40.7k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  40.7k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  40.7k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (410:9): [True: 0, False: 1.02M]
  ------------------
  411|  49.3k|        case CKM_TLS_KEY_AND_MAC_DERIVE:
  ------------------
  |  |  969|  49.3k|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
  |  Branch (411:9): [True: 8.60k, False: 1.01M]
  ------------------
  412|  49.3k|        case CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256:
  ------------------
  |  |  235|  49.3k|#define CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256 (CKM_NSS + 23)
  |  |  ------------------
  |  |  |  |  162|  49.3k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  49.3k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  49.3k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (412:9): [True: 0, False: 1.02M]
  ------------------
  413|  49.3k|        case CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE:
  ------------------
  |  |  239|  49.3k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE (CKM_NSS + 25)
  |  |  ------------------
  |  |  |  |  162|  49.3k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  49.3k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  49.3k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (413:9): [True: 0, False: 1.02M]
  ------------------
  414|  49.3k|        case CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH:
  ------------------
  |  |  240|  49.3k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH (CKM_NSS + 26)
  |  |  ------------------
  |  |  |  |  162|  49.3k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  49.3k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  49.3k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (414:9): [True: 0, False: 1.02M]
  ------------------
  415|  49.3k|        case CKM_SHA_1_HMAC:
  ------------------
  |  |  862|  49.3k|#define CKM_SHA_1_HMAC 0x00000221UL
  ------------------
  |  Branch (415:9): [True: 0, False: 1.02M]
  ------------------
  416|  49.3k|        case CKM_SHA_1_HMAC_GENERAL:
  ------------------
  |  |  863|  49.3k|#define CKM_SHA_1_HMAC_GENERAL 0x00000222UL
  ------------------
  |  Branch (416:9): [True: 0, False: 1.02M]
  ------------------
  417|  49.3k|        case CKM_SHA224_HMAC:
  ------------------
  |  |  888|  49.3k|#define CKM_SHA224_HMAC 0x00000256UL
  ------------------
  |  Branch (417:9): [True: 0, False: 1.02M]
  ------------------
  418|  49.3k|        case CKM_SHA224_HMAC_GENERAL:
  ------------------
  |  |  889|  49.3k|#define CKM_SHA224_HMAC_GENERAL 0x00000257UL
  ------------------
  |  Branch (418:9): [True: 0, False: 1.02M]
  ------------------
  419|  55.0k|        case CKM_SHA256_HMAC:
  ------------------
  |  |  877|  55.0k|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  |  Branch (419:9): [True: 5.70k, False: 1.02M]
  ------------------
  420|  55.0k|        case CKM_SHA256_HMAC_GENERAL:
  ------------------
  |  |  878|  55.0k|#define CKM_SHA256_HMAC_GENERAL 0x00000252UL
  ------------------
  |  Branch (420:9): [True: 0, False: 1.02M]
  ------------------
  421|   325k|        case CKM_SHA384_HMAC:
  ------------------
  |  |  880|   325k|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  |  Branch (421:9): [True: 270k, False: 757k]
  ------------------
  422|   325k|        case CKM_SHA384_HMAC_GENERAL:
  ------------------
  |  |  881|   325k|#define CKM_SHA384_HMAC_GENERAL 0x00000262UL
  ------------------
  |  Branch (422:9): [True: 0, False: 1.02M]
  ------------------
  423|   325k|        case CKM_SHA512_HMAC:
  ------------------
  |  |  883|   325k|#define CKM_SHA512_HMAC 0x00000271UL
  ------------------
  |  Branch (423:9): [True: 0, False: 1.02M]
  ------------------
  424|   325k|        case CKM_SHA512_HMAC_GENERAL:
  ------------------
  |  |  884|   325k|#define CKM_SHA512_HMAC_GENERAL 0x00000272UL
  ------------------
  |  Branch (424:9): [True: 0, False: 1.02M]
  ------------------
  425|   325k|        case CKM_MD2_HMAC:
  ------------------
  |  |  850|   325k|#define CKM_MD2_HMAC 0x00000201UL
  ------------------
  |  Branch (425:9): [True: 0, False: 1.02M]
  ------------------
  426|   325k|        case CKM_MD2_HMAC_GENERAL:
  ------------------
  |  |  851|   325k|#define CKM_MD2_HMAC_GENERAL 0x00000202UL
  ------------------
  |  Branch (426:9): [True: 0, False: 1.02M]
  ------------------
  427|   325k|        case CKM_MD5_HMAC:
  ------------------
  |  |  856|   325k|#define CKM_MD5_HMAC 0x00000211UL
  ------------------
  |  Branch (427:9): [True: 0, False: 1.02M]
  ------------------
  428|   325k|        case CKM_MD5_HMAC_GENERAL:
  ------------------
  |  |  857|   325k|#define CKM_MD5_HMAC_GENERAL 0x00000212UL
  ------------------
  |  Branch (428:9): [True: 0, False: 1.02M]
  ------------------
  429|   325k|        case CKM_TLS_PRF_GENERAL:
  ------------------
  |  |  297|   325k|#define CKM_TLS_PRF_GENERAL 0x80000373UL
  ------------------
  |  Branch (429:9): [True: 0, False: 1.02M]
  ------------------
  430|   325k|        case CKM_NSS_TLS_PRF_GENERAL_SHA256:
  ------------------
  |  |  233|   325k|#define CKM_NSS_TLS_PRF_GENERAL_SHA256 (CKM_NSS + 21)
  |  |  ------------------
  |  |  |  |  162|   325k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|   325k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   325k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (430:9): [True: 0, False: 1.02M]
  ------------------
  431|   325k|            return CKK_GENERIC_SECRET;
  ------------------
  |  |  383|   325k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  432|      0|        case CKM_NSS_KYBER_KEY_PAIR_GEN:
  ------------------
  |  |  267|      0|#define CKM_NSS_KYBER_KEY_PAIR_GEN (CKM_NSS + 45)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (432:9): [True: 0, False: 1.02M]
  ------------------
  433|      0|            return CKK_NSS_KYBER;
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  434|      0|        case CKM_NSS_ML_KEM_KEY_PAIR_GEN:
  ------------------
  |  |  277|      0|#define CKM_NSS_ML_KEM_KEY_PAIR_GEN (CKM_NSS + 48)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (434:9): [True: 0, False: 1.02M]
  ------------------
  435|      0|            return CKK_NSS_ML_KEM;
  ------------------
  |  |   59|      0|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  436|  80.8k|        default:
  ------------------
  |  Branch (436:9): [True: 80.8k, False: 947k]
  ------------------
  437|  80.8k|            return pk11_lookup(type)->keyType;
  438|  1.02M|    }
  439|  1.02M|}
PK11_GetKeyGenWithSize:
  453|  16.7k|{
  454|  16.7k|    switch (type) {
  455|      0|        case CKM_SEED_ECB:
  ------------------
  |  | 1156|      0|#define CKM_SEED_ECB 0x00000651UL
  ------------------
  |  Branch (455:9): [True: 0, False: 16.7k]
  ------------------
  456|      0|        case CKM_SEED_CBC:
  ------------------
  |  | 1157|      0|#define CKM_SEED_CBC 0x00000652UL
  ------------------
  |  Branch (456:9): [True: 0, False: 16.7k]
  ------------------
  457|      0|        case CKM_SEED_MAC:
  ------------------
  |  | 1158|      0|#define CKM_SEED_MAC 0x00000653UL
  ------------------
  |  Branch (457:9): [True: 0, False: 16.7k]
  ------------------
  458|      0|        case CKM_SEED_MAC_GENERAL:
  ------------------
  |  | 1159|      0|#define CKM_SEED_MAC_GENERAL 0x00000654UL
  ------------------
  |  Branch (458:9): [True: 0, False: 16.7k]
  ------------------
  459|      0|        case CKM_SEED_CBC_PAD:
  ------------------
  |  | 1160|      0|#define CKM_SEED_CBC_PAD 0x00000655UL
  ------------------
  |  Branch (459:9): [True: 0, False: 16.7k]
  ------------------
  460|      0|        case CKM_SEED_KEY_GEN:
  ------------------
  |  | 1155|      0|#define CKM_SEED_KEY_GEN 0x00000650UL
  ------------------
  |  Branch (460:9): [True: 0, False: 16.7k]
  ------------------
  461|      0|            return CKM_SEED_KEY_GEN;
  ------------------
  |  | 1155|      0|#define CKM_SEED_KEY_GEN 0x00000650UL
  ------------------
  462|      0|        case CKM_CAMELLIA_ECB:
  ------------------
  |  | 1136|      0|#define CKM_CAMELLIA_ECB 0x00000551UL
  ------------------
  |  Branch (462:9): [True: 0, False: 16.7k]
  ------------------
  463|      0|        case CKM_CAMELLIA_CBC:
  ------------------
  |  | 1137|      0|#define CKM_CAMELLIA_CBC 0x00000552UL
  ------------------
  |  Branch (463:9): [True: 0, False: 16.7k]
  ------------------
  464|      0|        case CKM_CAMELLIA_MAC:
  ------------------
  |  | 1138|      0|#define CKM_CAMELLIA_MAC 0x00000553UL
  ------------------
  |  Branch (464:9): [True: 0, False: 16.7k]
  ------------------
  465|      0|        case CKM_CAMELLIA_MAC_GENERAL:
  ------------------
  |  | 1139|      0|#define CKM_CAMELLIA_MAC_GENERAL 0x00000554UL
  ------------------
  |  Branch (465:9): [True: 0, False: 16.7k]
  ------------------
  466|      0|        case CKM_CAMELLIA_CBC_PAD:
  ------------------
  |  | 1140|      0|#define CKM_CAMELLIA_CBC_PAD 0x00000555UL
  ------------------
  |  Branch (466:9): [True: 0, False: 16.7k]
  ------------------
  467|      0|        case CKM_CAMELLIA_KEY_GEN:
  ------------------
  |  | 1135|      0|#define CKM_CAMELLIA_KEY_GEN 0x00000550UL
  ------------------
  |  Branch (467:9): [True: 0, False: 16.7k]
  ------------------
  468|      0|            return CKM_CAMELLIA_KEY_GEN;
  ------------------
  |  | 1135|      0|#define CKM_CAMELLIA_KEY_GEN 0x00000550UL
  ------------------
  469|  4.72k|        case CKM_NSS_CHACHA20_POLY1305:
  ------------------
  |  |  243|  4.72k|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|  4.72k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  4.72k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (469:9): [True: 4.72k, False: 11.9k]
  ------------------
  470|  4.72k|        case CKM_NSS_CHACHA20_CTR:
  ------------------
  |  |  251|  4.72k|#define CKM_NSS_CHACHA20_CTR (CKM_NSS + 33)
  |  |  ------------------
  |  |  |  |  162|  4.72k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  4.72k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (470:9): [True: 0, False: 16.7k]
  ------------------
  471|  4.72k|            return CKM_NSS_CHACHA20_KEY_GEN;
  ------------------
  |  |  242|  4.72k|#define CKM_NSS_CHACHA20_KEY_GEN (CKM_NSS + 27)
  |  |  ------------------
  |  |  |  |  162|  4.72k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  4.72k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  472|      0|        case CKM_CHACHA20_POLY1305:
  ------------------
  |  | 1287|      0|#define CKM_CHACHA20_POLY1305 0x00004021UL
  ------------------
  |  Branch (472:9): [True: 0, False: 16.7k]
  ------------------
  473|      0|        case CKM_CHACHA20:
  ------------------
  |  | 1204|      0|#define CKM_CHACHA20 0x00001226UL
  ------------------
  |  Branch (473:9): [True: 0, False: 16.7k]
  ------------------
  474|      0|            return CKM_CHACHA20_KEY_GEN;
  ------------------
  |  | 1203|      0|#define CKM_CHACHA20_KEY_GEN 0x00001225UL
  ------------------
  475|      0|        case CKM_AES_ECB:
  ------------------
  |  | 1107|      0|#define CKM_AES_ECB 0x00001081UL
  ------------------
  |  Branch (475:9): [True: 0, False: 16.7k]
  ------------------
  476|      1|        case CKM_AES_CBC:
  ------------------
  |  | 1108|      1|#define CKM_AES_CBC 0x00001082UL
  ------------------
  |  Branch (476:9): [True: 1, False: 16.7k]
  ------------------
  477|      1|        case CKM_AES_CCM:
  ------------------
  |  | 1116|      1|#define CKM_AES_CCM 0x00001088UL
  ------------------
  |  Branch (477:9): [True: 0, False: 16.7k]
  ------------------
  478|      1|        case CKM_AES_CTR:
  ------------------
  |  | 1113|      1|#define CKM_AES_CTR 0x00001086UL
  ------------------
  |  Branch (478:9): [True: 0, False: 16.7k]
  ------------------
  479|      1|        case CKM_AES_CTS:
  ------------------
  |  | 1117|      1|#define CKM_AES_CTS 0x00001089UL
  ------------------
  |  Branch (479:9): [True: 0, False: 16.7k]
  ------------------
  480|      1|        case CKM_AES_GCM:
  ------------------
  |  | 1115|      1|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (480:9): [True: 0, False: 16.7k]
  ------------------
  481|      1|        case CKM_AES_MAC:
  ------------------
  |  | 1109|      1|#define CKM_AES_MAC 0x00001083UL
  ------------------
  |  Branch (481:9): [True: 0, False: 16.7k]
  ------------------
  482|      1|        case CKM_AES_MAC_GENERAL:
  ------------------
  |  | 1110|      1|#define CKM_AES_MAC_GENERAL 0x00001084UL
  ------------------
  |  Branch (482:9): [True: 0, False: 16.7k]
  ------------------
  483|      1|        case CKM_AES_CMAC:
  ------------------
  |  | 1119|      1|#define CKM_AES_CMAC 0x0000108AUL
  ------------------
  |  Branch (483:9): [True: 0, False: 16.7k]
  ------------------
  484|      1|        case CKM_AES_CMAC_GENERAL:
  ------------------
  |  | 1120|      1|#define CKM_AES_CMAC_GENERAL 0x0000108BUL
  ------------------
  |  Branch (484:9): [True: 0, False: 16.7k]
  ------------------
  485|      1|        case CKM_AES_CBC_PAD:
  ------------------
  |  | 1111|      1|#define CKM_AES_CBC_PAD 0x00001085UL
  ------------------
  |  Branch (485:9): [True: 0, False: 16.7k]
  ------------------
  486|      1|        case CKM_AES_KEY_GEN:
  ------------------
  |  | 1106|      1|#define CKM_AES_KEY_GEN 0x00001080UL
  ------------------
  |  Branch (486:9): [True: 0, False: 16.7k]
  ------------------
  487|      1|            return CKM_AES_KEY_GEN;
  ------------------
  |  | 1106|      1|#define CKM_AES_KEY_GEN 0x00001080UL
  ------------------
  488|      0|        case CKM_DES_ECB:
  ------------------
  |  |  815|      0|#define CKM_DES_ECB 0x00000121UL
  ------------------
  |  Branch (488:9): [True: 0, False: 16.7k]
  ------------------
  489|      0|        case CKM_DES_CBC:
  ------------------
  |  |  816|      0|#define CKM_DES_CBC 0x00000122UL
  ------------------
  |  Branch (489:9): [True: 0, False: 16.7k]
  ------------------
  490|      0|        case CKM_DES_MAC:
  ------------------
  |  |  817|      0|#define CKM_DES_MAC 0x00000123UL
  ------------------
  |  Branch (490:9): [True: 0, False: 16.7k]
  ------------------
  491|      0|        case CKM_DES_MAC_GENERAL:
  ------------------
  |  |  820|      0|#define CKM_DES_MAC_GENERAL 0x00000124UL
  ------------------
  |  Branch (491:9): [True: 0, False: 16.7k]
  ------------------
  492|      0|        case CKM_KEY_WRAP_LYNKS:
  ------------------
  |  | 1035|      0|#define CKM_KEY_WRAP_LYNKS 0x00000400UL
  ------------------
  |  Branch (492:9): [True: 0, False: 16.7k]
  ------------------
  493|      0|        case CKM_DES_CBC_PAD:
  ------------------
  |  |  821|      0|#define CKM_DES_CBC_PAD 0x00000125UL
  ------------------
  |  Branch (493:9): [True: 0, False: 16.7k]
  ------------------
  494|      0|        case CKM_DES_KEY_GEN:
  ------------------
  |  |  814|      0|#define CKM_DES_KEY_GEN 0x00000120UL
  ------------------
  |  Branch (494:9): [True: 0, False: 16.7k]
  ------------------
  495|      0|            return CKM_DES_KEY_GEN;
  ------------------
  |  |  814|      0|#define CKM_DES_KEY_GEN 0x00000120UL
  ------------------
  496|      2|        case CKM_DES3_ECB:
  ------------------
  |  |  825|      2|#define CKM_DES3_ECB 0x00000132UL
  ------------------
  |  Branch (496:9): [True: 2, False: 16.6k]
  ------------------
  497|      2|        case CKM_DES3_CBC:
  ------------------
  |  |  826|      2|#define CKM_DES3_CBC 0x00000133UL
  ------------------
  |  Branch (497:9): [True: 0, False: 16.7k]
  ------------------
  498|      2|        case CKM_DES3_MAC:
  ------------------
  |  |  827|      2|#define CKM_DES3_MAC 0x00000134UL
  ------------------
  |  Branch (498:9): [True: 0, False: 16.7k]
  ------------------
  499|      2|        case CKM_DES3_MAC_GENERAL:
  ------------------
  |  |  832|      2|#define CKM_DES3_MAC_GENERAL 0x00000135UL
  ------------------
  |  Branch (499:9): [True: 0, False: 16.7k]
  ------------------
  500|      2|        case CKM_DES3_CBC_PAD:
  ------------------
  |  |  833|      2|#define CKM_DES3_CBC_PAD 0x00000136UL
  ------------------
  |  Branch (500:9): [True: 0, False: 16.7k]
  ------------------
  501|      2|            return (size == 16) ? CKM_DES2_KEY_GEN : CKM_DES3_KEY_GEN;
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
                          return (size == 16) ? CKM_DES2_KEY_GEN : CKM_DES3_KEY_GEN;
  ------------------
  |  |  824|      2|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  |  Branch (501:20): [True: 0, False: 2]
  ------------------
  502|      0|        case CKM_DES3_KEY_GEN:
  ------------------
  |  |  824|      0|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  |  Branch (502:9): [True: 0, False: 16.7k]
  ------------------
  503|      0|            return CKM_DES3_KEY_GEN;
  ------------------
  |  |  824|      0|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  504|      0|        case CKM_DES2_KEY_GEN:
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
  |  Branch (504:9): [True: 0, False: 16.7k]
  ------------------
  505|      0|            return CKM_DES2_KEY_GEN;
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
  506|      0|        case CKM_CDMF_ECB:
  ------------------
  |  |  835|      0|#define CKM_CDMF_ECB 0x00000141UL
  ------------------
  |  Branch (506:9): [True: 0, False: 16.7k]
  ------------------
  507|      0|        case CKM_CDMF_CBC:
  ------------------
  |  |  836|      0|#define CKM_CDMF_CBC 0x00000142UL
  ------------------
  |  Branch (507:9): [True: 0, False: 16.7k]
  ------------------
  508|      0|        case CKM_CDMF_MAC:
  ------------------
  |  |  837|      0|#define CKM_CDMF_MAC 0x00000143UL
  ------------------
  |  Branch (508:9): [True: 0, False: 16.7k]
  ------------------
  509|      0|        case CKM_CDMF_MAC_GENERAL:
  ------------------
  |  |  838|      0|#define CKM_CDMF_MAC_GENERAL 0x00000144UL
  ------------------
  |  Branch (509:9): [True: 0, False: 16.7k]
  ------------------
  510|      0|        case CKM_CDMF_CBC_PAD:
  ------------------
  |  |  839|      0|#define CKM_CDMF_CBC_PAD 0x00000145UL
  ------------------
  |  Branch (510:9): [True: 0, False: 16.7k]
  ------------------
  511|      0|        case CKM_CDMF_KEY_GEN:
  ------------------
  |  |  834|      0|#define CKM_CDMF_KEY_GEN 0x00000140UL
  ------------------
  |  Branch (511:9): [True: 0, False: 16.7k]
  ------------------
  512|      0|            return CKM_CDMF_KEY_GEN;
  ------------------
  |  |  834|      0|#define CKM_CDMF_KEY_GEN 0x00000140UL
  ------------------
  513|      0|        case CKM_RC2_ECB:
  ------------------
  |  |  804|      0|#define CKM_RC2_ECB 0x00000101UL
  ------------------
  |  Branch (513:9): [True: 0, False: 16.7k]
  ------------------
  514|      0|        case CKM_RC2_CBC:
  ------------------
  |  |  805|      0|#define CKM_RC2_CBC 0x00000102UL
  ------------------
  |  Branch (514:9): [True: 0, False: 16.7k]
  ------------------
  515|      0|        case CKM_RC2_MAC:
  ------------------
  |  |  806|      0|#define CKM_RC2_MAC 0x00000103UL
  ------------------
  |  Branch (515:9): [True: 0, False: 16.7k]
  ------------------
  516|      0|        case CKM_RC2_MAC_GENERAL:
  ------------------
  |  |  809|      0|#define CKM_RC2_MAC_GENERAL 0x00000104UL
  ------------------
  |  Branch (516:9): [True: 0, False: 16.7k]
  ------------------
  517|      0|        case CKM_RC2_CBC_PAD:
  ------------------
  |  |  810|      0|#define CKM_RC2_CBC_PAD 0x00000105UL
  ------------------
  |  Branch (517:9): [True: 0, False: 16.7k]
  ------------------
  518|      0|        case CKM_RC2_KEY_GEN:
  ------------------
  |  |  803|      0|#define CKM_RC2_KEY_GEN 0x00000100UL
  ------------------
  |  Branch (518:9): [True: 0, False: 16.7k]
  ------------------
  519|      0|            return CKM_RC2_KEY_GEN;
  ------------------
  |  |  803|      0|#define CKM_RC2_KEY_GEN 0x00000100UL
  ------------------
  520|      0|        case CKM_RC4:
  ------------------
  |  |  813|      0|#define CKM_RC4 0x00000111UL
  ------------------
  |  Branch (520:9): [True: 0, False: 16.7k]
  ------------------
  521|      0|        case CKM_RC4_KEY_GEN:
  ------------------
  |  |  812|      0|#define CKM_RC4_KEY_GEN 0x00000110UL
  ------------------
  |  Branch (521:9): [True: 0, False: 16.7k]
  ------------------
  522|      0|            return CKM_RC4_KEY_GEN;
  ------------------
  |  |  812|      0|#define CKM_RC4_KEY_GEN 0x00000110UL
  ------------------
  523|      0|        case CKM_RC5_ECB:
  ------------------
  |  |  942|      0|#define CKM_RC5_ECB 0x00000331UL
  ------------------
  |  Branch (523:9): [True: 0, False: 16.7k]
  ------------------
  524|      0|        case CKM_RC5_CBC:
  ------------------
  |  |  943|      0|#define CKM_RC5_CBC 0x00000332UL
  ------------------
  |  Branch (524:9): [True: 0, False: 16.7k]
  ------------------
  525|      0|        case CKM_RC5_MAC:
  ------------------
  |  |  944|      0|#define CKM_RC5_MAC 0x00000333UL
  ------------------
  |  Branch (525:9): [True: 0, False: 16.7k]
  ------------------
  526|      0|        case CKM_RC5_MAC_GENERAL:
  ------------------
  |  |  945|      0|#define CKM_RC5_MAC_GENERAL 0x00000334UL
  ------------------
  |  Branch (526:9): [True: 0, False: 16.7k]
  ------------------
  527|      0|        case CKM_RC5_CBC_PAD:
  ------------------
  |  |  946|      0|#define CKM_RC5_CBC_PAD 0x00000335UL
  ------------------
  |  Branch (527:9): [True: 0, False: 16.7k]
  ------------------
  528|      0|        case CKM_RC5_KEY_GEN:
  ------------------
  |  |  941|      0|#define CKM_RC5_KEY_GEN 0x00000330UL
  ------------------
  |  Branch (528:9): [True: 0, False: 16.7k]
  ------------------
  529|      0|            return CKM_RC5_KEY_GEN;
  ------------------
  |  |  941|      0|#define CKM_RC5_KEY_GEN 0x00000330UL
  ------------------
  530|      0|        case CKM_SKIPJACK_CBC64:
  ------------------
  |  | 1049|      0|#define CKM_SKIPJACK_CBC64 0x00001002UL
  ------------------
  |  Branch (530:9): [True: 0, False: 16.7k]
  ------------------
  531|      0|        case CKM_SKIPJACK_ECB64:
  ------------------
  |  | 1048|      0|#define CKM_SKIPJACK_ECB64 0x00001001UL
  ------------------
  |  Branch (531:9): [True: 0, False: 16.7k]
  ------------------
  532|      0|        case CKM_SKIPJACK_OFB64:
  ------------------
  |  | 1050|      0|#define CKM_SKIPJACK_OFB64 0x00001003UL
  ------------------
  |  Branch (532:9): [True: 0, False: 16.7k]
  ------------------
  533|      0|        case CKM_SKIPJACK_CFB64:
  ------------------
  |  | 1051|      0|#define CKM_SKIPJACK_CFB64 0x00001004UL
  ------------------
  |  Branch (533:9): [True: 0, False: 16.7k]
  ------------------
  534|      0|        case CKM_SKIPJACK_CFB32:
  ------------------
  |  | 1052|      0|#define CKM_SKIPJACK_CFB32 0x00001005UL
  ------------------
  |  Branch (534:9): [True: 0, False: 16.7k]
  ------------------
  535|      0|        case CKM_SKIPJACK_CFB16:
  ------------------
  |  | 1053|      0|#define CKM_SKIPJACK_CFB16 0x00001006UL
  ------------------
  |  Branch (535:9): [True: 0, False: 16.7k]
  ------------------
  536|      0|        case CKM_SKIPJACK_CFB8:
  ------------------
  |  | 1054|      0|#define CKM_SKIPJACK_CFB8 0x00001007UL
  ------------------
  |  Branch (536:9): [True: 0, False: 16.7k]
  ------------------
  537|      0|        case CKM_SKIPJACK_WRAP:
  ------------------
  |  | 1055|      0|#define CKM_SKIPJACK_WRAP 0x00001008UL
  ------------------
  |  Branch (537:9): [True: 0, False: 16.7k]
  ------------------
  538|      0|        case CKM_SKIPJACK_KEY_GEN:
  ------------------
  |  | 1047|      0|#define CKM_SKIPJACK_KEY_GEN 0x00001000UL
  ------------------
  |  Branch (538:9): [True: 0, False: 16.7k]
  ------------------
  539|      0|            return CKM_SKIPJACK_KEY_GEN;
  ------------------
  |  | 1047|      0|#define CKM_SKIPJACK_KEY_GEN 0x00001000UL
  ------------------
  540|      0|        case CKM_BATON_ECB128:
  ------------------
  |  | 1062|      0|#define CKM_BATON_ECB128 0x00001031UL
  ------------------
  |  Branch (540:9): [True: 0, False: 16.7k]
  ------------------
  541|      0|        case CKM_BATON_ECB96:
  ------------------
  |  | 1063|      0|#define CKM_BATON_ECB96 0x00001032UL
  ------------------
  |  Branch (541:9): [True: 0, False: 16.7k]
  ------------------
  542|      0|        case CKM_BATON_CBC128:
  ------------------
  |  | 1064|      0|#define CKM_BATON_CBC128 0x00001033UL
  ------------------
  |  Branch (542:9): [True: 0, False: 16.7k]
  ------------------
  543|      0|        case CKM_BATON_COUNTER:
  ------------------
  |  | 1065|      0|#define CKM_BATON_COUNTER 0x00001034UL
  ------------------
  |  Branch (543:9): [True: 0, False: 16.7k]
  ------------------
  544|      0|        case CKM_BATON_SHUFFLE:
  ------------------
  |  | 1066|      0|#define CKM_BATON_SHUFFLE 0x00001035UL
  ------------------
  |  Branch (544:9): [True: 0, False: 16.7k]
  ------------------
  545|      0|        case CKM_BATON_WRAP:
  ------------------
  |  | 1067|      0|#define CKM_BATON_WRAP 0x00001036UL
  ------------------
  |  Branch (545:9): [True: 0, False: 16.7k]
  ------------------
  546|      0|        case CKM_BATON_KEY_GEN:
  ------------------
  |  | 1061|      0|#define CKM_BATON_KEY_GEN 0x00001030UL
  ------------------
  |  Branch (546:9): [True: 0, False: 16.7k]
  ------------------
  547|      0|            return CKM_BATON_KEY_GEN;
  ------------------
  |  | 1061|      0|#define CKM_BATON_KEY_GEN 0x00001030UL
  ------------------
  548|      0|        case CKM_JUNIPER_ECB128:
  ------------------
  |  | 1095|      0|#define CKM_JUNIPER_ECB128 0x00001061UL
  ------------------
  |  Branch (548:9): [True: 0, False: 16.7k]
  ------------------
  549|      0|        case CKM_JUNIPER_CBC128:
  ------------------
  |  | 1096|      0|#define CKM_JUNIPER_CBC128 0x00001062UL
  ------------------
  |  Branch (549:9): [True: 0, False: 16.7k]
  ------------------
  550|      0|        case CKM_JUNIPER_COUNTER:
  ------------------
  |  | 1097|      0|#define CKM_JUNIPER_COUNTER 0x00001063UL
  ------------------
  |  Branch (550:9): [True: 0, False: 16.7k]
  ------------------
  551|      0|        case CKM_JUNIPER_SHUFFLE:
  ------------------
  |  | 1098|      0|#define CKM_JUNIPER_SHUFFLE 0x00001064UL
  ------------------
  |  Branch (551:9): [True: 0, False: 16.7k]
  ------------------
  552|      0|        case CKM_JUNIPER_WRAP:
  ------------------
  |  | 1099|      0|#define CKM_JUNIPER_WRAP 0x00001065UL
  ------------------
  |  Branch (552:9): [True: 0, False: 16.7k]
  ------------------
  553|      0|        case CKM_JUNIPER_KEY_GEN:
  ------------------
  |  | 1094|      0|#define CKM_JUNIPER_KEY_GEN 0x00001060UL
  ------------------
  |  Branch (553:9): [True: 0, False: 16.7k]
  ------------------
  554|      0|            return CKM_JUNIPER_KEY_GEN;
  ------------------
  |  | 1094|      0|#define CKM_JUNIPER_KEY_GEN 0x00001060UL
  ------------------
  555|      0|        case CKM_IDEA_CBC:
  ------------------
  |  |  949|      0|#define CKM_IDEA_CBC 0x00000342UL
  ------------------
  |  Branch (555:9): [True: 0, False: 16.7k]
  ------------------
  556|      0|        case CKM_IDEA_ECB:
  ------------------
  |  |  948|      0|#define CKM_IDEA_ECB 0x00000341UL
  ------------------
  |  Branch (556:9): [True: 0, False: 16.7k]
  ------------------
  557|      0|        case CKM_IDEA_MAC:
  ------------------
  |  |  950|      0|#define CKM_IDEA_MAC 0x00000343UL
  ------------------
  |  Branch (557:9): [True: 0, False: 16.7k]
  ------------------
  558|      0|        case CKM_IDEA_MAC_GENERAL:
  ------------------
  |  |  951|      0|#define CKM_IDEA_MAC_GENERAL 0x00000344UL
  ------------------
  |  Branch (558:9): [True: 0, False: 16.7k]
  ------------------
  559|      0|        case CKM_IDEA_CBC_PAD:
  ------------------
  |  |  952|      0|#define CKM_IDEA_CBC_PAD 0x00000345UL
  ------------------
  |  Branch (559:9): [True: 0, False: 16.7k]
  ------------------
  560|      0|        case CKM_IDEA_KEY_GEN:
  ------------------
  |  |  947|      0|#define CKM_IDEA_KEY_GEN 0x00000340UL
  ------------------
  |  Branch (560:9): [True: 0, False: 16.7k]
  ------------------
  561|      0|            return CKM_IDEA_KEY_GEN;
  ------------------
  |  |  947|      0|#define CKM_IDEA_KEY_GEN 0x00000340UL
  ------------------
  562|      0|        case CKM_CAST_ECB:
  ------------------
  |  |  918|      0|#define CKM_CAST_ECB 0x00000301UL
  ------------------
  |  Branch (562:9): [True: 0, False: 16.7k]
  ------------------
  563|      0|        case CKM_CAST_CBC:
  ------------------
  |  |  919|      0|#define CKM_CAST_CBC 0x00000302UL
  ------------------
  |  Branch (563:9): [True: 0, False: 16.7k]
  ------------------
  564|      0|        case CKM_CAST_MAC:
  ------------------
  |  |  920|      0|#define CKM_CAST_MAC 0x00000303UL
  ------------------
  |  Branch (564:9): [True: 0, False: 16.7k]
  ------------------
  565|      0|        case CKM_CAST_MAC_GENERAL:
  ------------------
  |  |  921|      0|#define CKM_CAST_MAC_GENERAL 0x00000304UL
  ------------------
  |  Branch (565:9): [True: 0, False: 16.7k]
  ------------------
  566|      0|        case CKM_CAST_CBC_PAD:
  ------------------
  |  |  922|      0|#define CKM_CAST_CBC_PAD 0x00000305UL
  ------------------
  |  Branch (566:9): [True: 0, False: 16.7k]
  ------------------
  567|      0|        case CKM_CAST_KEY_GEN:
  ------------------
  |  |  917|      0|#define CKM_CAST_KEY_GEN 0x00000300UL
  ------------------
  |  Branch (567:9): [True: 0, False: 16.7k]
  ------------------
  568|      0|            return CKM_CAST_KEY_GEN;
  ------------------
  |  |  917|      0|#define CKM_CAST_KEY_GEN 0x00000300UL
  ------------------
  569|      0|        case CKM_CAST3_ECB:
  ------------------
  |  |  924|      0|#define CKM_CAST3_ECB 0x00000311UL
  ------------------
  |  Branch (569:9): [True: 0, False: 16.7k]
  ------------------
  570|      0|        case CKM_CAST3_CBC:
  ------------------
  |  |  925|      0|#define CKM_CAST3_CBC 0x00000312UL
  ------------------
  |  Branch (570:9): [True: 0, False: 16.7k]
  ------------------
  571|      0|        case CKM_CAST3_MAC:
  ------------------
  |  |  926|      0|#define CKM_CAST3_MAC 0x00000313UL
  ------------------
  |  Branch (571:9): [True: 0, False: 16.7k]
  ------------------
  572|      0|        case CKM_CAST3_MAC_GENERAL:
  ------------------
  |  |  927|      0|#define CKM_CAST3_MAC_GENERAL 0x00000314UL
  ------------------
  |  Branch (572:9): [True: 0, False: 16.7k]
  ------------------
  573|      0|        case CKM_CAST3_CBC_PAD:
  ------------------
  |  |  928|      0|#define CKM_CAST3_CBC_PAD 0x00000315UL
  ------------------
  |  Branch (573:9): [True: 0, False: 16.7k]
  ------------------
  574|      0|        case CKM_CAST3_KEY_GEN:
  ------------------
  |  |  923|      0|#define CKM_CAST3_KEY_GEN 0x00000310UL
  ------------------
  |  Branch (574:9): [True: 0, False: 16.7k]
  ------------------
  575|      0|            return CKM_CAST3_KEY_GEN;
  ------------------
  |  |  923|      0|#define CKM_CAST3_KEY_GEN 0x00000310UL
  ------------------
  576|      0|        case CKM_CAST5_ECB:
  ------------------
  |  |  931|      0|#define CKM_CAST5_ECB 0x00000321UL
  ------------------
  |  Branch (576:9): [True: 0, False: 16.7k]
  ------------------
  577|      0|        case CKM_CAST5_CBC:
  ------------------
  |  |  933|      0|#define CKM_CAST5_CBC 0x00000322UL
  ------------------
  |  Branch (577:9): [True: 0, False: 16.7k]
  ------------------
  578|      0|        case CKM_CAST5_MAC:
  ------------------
  |  |  935|      0|#define CKM_CAST5_MAC 0x00000323UL
  ------------------
  |  Branch (578:9): [True: 0, False: 16.7k]
  ------------------
  579|      0|        case CKM_CAST5_MAC_GENERAL:
  ------------------
  |  |  937|      0|#define CKM_CAST5_MAC_GENERAL 0x00000324UL
  ------------------
  |  Branch (579:9): [True: 0, False: 16.7k]
  ------------------
  580|      0|        case CKM_CAST5_CBC_PAD:
  ------------------
  |  |  939|      0|#define CKM_CAST5_CBC_PAD 0x00000325UL
  ------------------
  |  Branch (580:9): [True: 0, False: 16.7k]
  ------------------
  581|      0|        case CKM_CAST5_KEY_GEN:
  ------------------
  |  |  929|      0|#define CKM_CAST5_KEY_GEN 0x00000320UL
  ------------------
  |  Branch (581:9): [True: 0, False: 16.7k]
  ------------------
  582|      0|            return CKM_CAST5_KEY_GEN;
  ------------------
  |  |  929|      0|#define CKM_CAST5_KEY_GEN 0x00000320UL
  ------------------
  583|      0|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (583:9): [True: 0, False: 16.7k]
  ------------------
  584|      0|        case CKM_RSA_9796:
  ------------------
  |  |  721|      0|#define CKM_RSA_9796 0x00000002UL
  ------------------
  |  Branch (584:9): [True: 0, False: 16.7k]
  ------------------
  585|      0|        case CKM_RSA_X_509:
  ------------------
  |  |  722|      0|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (585:9): [True: 0, False: 16.7k]
  ------------------
  586|      0|        case CKM_MD2_RSA_PKCS:
  ------------------
  |  |  726|      0|#define CKM_MD2_RSA_PKCS 0x00000004UL
  ------------------
  |  Branch (586:9): [True: 0, False: 16.7k]
  ------------------
  587|      0|        case CKM_MD5_RSA_PKCS:
  ------------------
  |  |  727|      0|#define CKM_MD5_RSA_PKCS 0x00000005UL
  ------------------
  |  Branch (587:9): [True: 0, False: 16.7k]
  ------------------
  588|      0|        case CKM_SHA1_RSA_PKCS:
  ------------------
  |  |  728|      0|#define CKM_SHA1_RSA_PKCS 0x00000006UL
  ------------------
  |  Branch (588:9): [True: 0, False: 16.7k]
  ------------------
  589|      0|        case CKM_SHA224_RSA_PKCS:
  ------------------
  |  |  778|      0|#define CKM_SHA224_RSA_PKCS 0x00000046UL
  ------------------
  |  Branch (589:9): [True: 0, False: 16.7k]
  ------------------
  590|      0|        case CKM_SHA256_RSA_PKCS:
  ------------------
  |  |  770|      0|#define CKM_SHA256_RSA_PKCS 0x00000040UL
  ------------------
  |  Branch (590:9): [True: 0, False: 16.7k]
  ------------------
  591|      0|        case CKM_SHA384_RSA_PKCS:
  ------------------
  |  |  771|      0|#define CKM_SHA384_RSA_PKCS 0x00000041UL
  ------------------
  |  Branch (591:9): [True: 0, False: 16.7k]
  ------------------
  592|      0|        case CKM_SHA512_RSA_PKCS:
  ------------------
  |  |  772|      0|#define CKM_SHA512_RSA_PKCS 0x00000042UL
  ------------------
  |  Branch (592:9): [True: 0, False: 16.7k]
  ------------------
  593|      0|        case CKM_KEY_WRAP_SET_OAEP:
  ------------------
  |  | 1036|      0|#define CKM_KEY_WRAP_SET_OAEP 0x00000401UL
  ------------------
  |  Branch (593:9): [True: 0, False: 16.7k]
  ------------------
  594|      0|        case CKM_RSA_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  719|      0|#define CKM_RSA_PKCS_KEY_PAIR_GEN 0x00000000UL
  ------------------
  |  Branch (594:9): [True: 0, False: 16.7k]
  ------------------
  595|      0|            return CKM_RSA_PKCS_KEY_PAIR_GEN;
  ------------------
  |  |  719|      0|#define CKM_RSA_PKCS_KEY_PAIR_GEN 0x00000000UL
  ------------------
  596|      0|        case CKM_RSA_X9_31_KEY_PAIR_GEN:
  ------------------
  |  |  738|      0|#define CKM_RSA_X9_31_KEY_PAIR_GEN 0x0000000AUL
  ------------------
  |  Branch (596:9): [True: 0, False: 16.7k]
  ------------------
  597|      0|            return CKM_RSA_X9_31_KEY_PAIR_GEN;
  ------------------
  |  |  738|      0|#define CKM_RSA_X9_31_KEY_PAIR_GEN 0x0000000AUL
  ------------------
  598|      0|        case CKM_DSA:
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (598:9): [True: 0, False: 16.7k]
  ------------------
  599|      0|        case CKM_DSA_SHA1:
  ------------------
  |  |  746|      0|#define CKM_DSA_SHA1 0x00000012UL
  ------------------
  |  Branch (599:9): [True: 0, False: 16.7k]
  ------------------
  600|      0|        case CKM_DSA_KEY_PAIR_GEN:
  ------------------
  |  |  744|      0|#define CKM_DSA_KEY_PAIR_GEN 0x00000010UL
  ------------------
  |  Branch (600:9): [True: 0, False: 16.7k]
  ------------------
  601|      0|            return CKM_DSA_KEY_PAIR_GEN;
  ------------------
  |  |  744|      0|#define CKM_DSA_KEY_PAIR_GEN 0x00000010UL
  ------------------
  602|      0|        case CKM_DH_PKCS_DERIVE:
  ------------------
  |  |  759|      0|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
  |  Branch (602:9): [True: 0, False: 16.7k]
  ------------------
  603|      0|        case CKM_DH_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  758|      0|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  |  Branch (603:9): [True: 0, False: 16.7k]
  ------------------
  604|      0|            return CKM_DH_PKCS_KEY_PAIR_GEN;
  ------------------
  |  |  758|      0|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  605|      0|        case CKM_KEA_KEY_DERIVE:
  ------------------
  |  | 1059|      0|#define CKM_KEA_KEY_DERIVE 0x00001011UL
  ------------------
  |  Branch (605:9): [True: 0, False: 16.7k]
  ------------------
  606|      0|        case CKM_KEA_KEY_PAIR_GEN:
  ------------------
  |  | 1058|      0|#define CKM_KEA_KEY_PAIR_GEN 0x00001010UL
  ------------------
  |  Branch (606:9): [True: 0, False: 16.7k]
  ------------------
  607|      0|            return CKM_KEA_KEY_PAIR_GEN;
  ------------------
  |  | 1058|      0|#define CKM_KEA_KEY_PAIR_GEN 0x00001010UL
  ------------------
  608|      0|        case CKM_ECDSA:
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (608:9): [True: 0, False: 16.7k]
  ------------------
  609|      0|        case CKM_ECDSA_SHA1:
  ------------------
  |  | 1075|      0|#define CKM_ECDSA_SHA1 0x00001042UL
  ------------------
  |  Branch (609:9): [True: 0, False: 16.7k]
  ------------------
  610|      0|        case CKM_EC_KEY_PAIR_GEN: /* aka CKM_ECDSA_KEY_PAIR_GEN */
  ------------------
  |  | 1072|      0|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  |  Branch (610:9): [True: 0, False: 16.7k]
  ------------------
  611|      0|        case CKM_ECDH1_DERIVE:
  ------------------
  |  | 1086|      0|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  |  Branch (611:9): [True: 0, False: 16.7k]
  ------------------
  612|      0|            return CKM_EC_KEY_PAIR_GEN;
  ------------------
  |  | 1072|      0|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  613|      0|        case CKM_EDDSA:
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
  |  Branch (613:9): [True: 0, False: 16.7k]
  ------------------
  614|      0|            return CKM_EC_EDWARDS_KEY_PAIR_GEN;
  ------------------
  |  | 1172|      0|#define CKM_EC_EDWARDS_KEY_PAIR_GEN 0x00001055UL
  ------------------
  615|  11.9k|        case CKM_SSL3_PRE_MASTER_KEY_GEN:
  ------------------
  |  |  959|  11.9k|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
  |  Branch (615:9): [True: 11.9k, False: 4.72k]
  ------------------
  616|  11.9k|        case CKM_SSL3_MASTER_KEY_DERIVE:
  ------------------
  |  |  960|  11.9k|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
  |  Branch (616:9): [True: 0, False: 16.7k]
  ------------------
  617|  11.9k|        case CKM_SSL3_KEY_AND_MAC_DERIVE:
  ------------------
  |  |  961|  11.9k|#define CKM_SSL3_KEY_AND_MAC_DERIVE 0x00000372UL
  ------------------
  |  Branch (617:9): [True: 0, False: 16.7k]
  ------------------
  618|  11.9k|        case CKM_SSL3_SHA1_MAC:
  ------------------
  |  |  976|  11.9k|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
  |  Branch (618:9): [True: 0, False: 16.7k]
  ------------------
  619|  11.9k|        case CKM_SSL3_MD5_MAC:
  ------------------
  |  |  975|  11.9k|#define CKM_SSL3_MD5_MAC 0x00000380UL
  ------------------
  |  Branch (619:9): [True: 0, False: 16.7k]
  ------------------
  620|  11.9k|        case CKM_TLS_MASTER_KEY_DERIVE:
  ------------------
  |  |  968|  11.9k|#define CKM_TLS_MASTER_KEY_DERIVE 0x00000375UL
  ------------------
  |  Branch (620:9): [True: 0, False: 16.7k]
  ------------------
  621|  11.9k|        case CKM_TLS_KEY_AND_MAC_DERIVE:
  ------------------
  |  |  969|  11.9k|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
  |  Branch (621:9): [True: 0, False: 16.7k]
  ------------------
  622|  11.9k|        case CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256:
  ------------------
  |  |  235|  11.9k|#define CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256 (CKM_NSS + 23)
  |  |  ------------------
  |  |  |  |  162|  11.9k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  11.9k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  11.9k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (622:9): [True: 0, False: 16.7k]
  ------------------
  623|  11.9k|        case CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE:
  ------------------
  |  |  239|  11.9k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE (CKM_NSS + 25)
  |  |  ------------------
  |  |  |  |  162|  11.9k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  11.9k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  11.9k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (623:9): [True: 0, False: 16.7k]
  ------------------
  624|  11.9k|        case CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH:
  ------------------
  |  |  240|  11.9k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH (CKM_NSS + 26)
  |  |  ------------------
  |  |  |  |  162|  11.9k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  11.9k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  11.9k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (624:9): [True: 0, False: 16.7k]
  ------------------
  625|  11.9k|            return CKM_SSL3_PRE_MASTER_KEY_GEN;
  ------------------
  |  |  959|  11.9k|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
  626|      0|        case CKM_SHA_1_HMAC:
  ------------------
  |  |  862|      0|#define CKM_SHA_1_HMAC 0x00000221UL
  ------------------
  |  Branch (626:9): [True: 0, False: 16.7k]
  ------------------
  627|      0|        case CKM_SHA_1_HMAC_GENERAL:
  ------------------
  |  |  863|      0|#define CKM_SHA_1_HMAC_GENERAL 0x00000222UL
  ------------------
  |  Branch (627:9): [True: 0, False: 16.7k]
  ------------------
  628|      0|        case CKM_SHA224_HMAC:
  ------------------
  |  |  888|      0|#define CKM_SHA224_HMAC 0x00000256UL
  ------------------
  |  Branch (628:9): [True: 0, False: 16.7k]
  ------------------
  629|      0|        case CKM_SHA224_HMAC_GENERAL:
  ------------------
  |  |  889|      0|#define CKM_SHA224_HMAC_GENERAL 0x00000257UL
  ------------------
  |  Branch (629:9): [True: 0, False: 16.7k]
  ------------------
  630|      1|        case CKM_SHA256_HMAC:
  ------------------
  |  |  877|      1|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  |  Branch (630:9): [True: 1, False: 16.7k]
  ------------------
  631|      1|        case CKM_SHA256_HMAC_GENERAL:
  ------------------
  |  |  878|      1|#define CKM_SHA256_HMAC_GENERAL 0x00000252UL
  ------------------
  |  Branch (631:9): [True: 0, False: 16.7k]
  ------------------
  632|      1|        case CKM_SHA384_HMAC:
  ------------------
  |  |  880|      1|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  |  Branch (632:9): [True: 0, False: 16.7k]
  ------------------
  633|      1|        case CKM_SHA384_HMAC_GENERAL:
  ------------------
  |  |  881|      1|#define CKM_SHA384_HMAC_GENERAL 0x00000262UL
  ------------------
  |  Branch (633:9): [True: 0, False: 16.7k]
  ------------------
  634|      1|        case CKM_SHA512_HMAC:
  ------------------
  |  |  883|      1|#define CKM_SHA512_HMAC 0x00000271UL
  ------------------
  |  Branch (634:9): [True: 0, False: 16.7k]
  ------------------
  635|      1|        case CKM_SHA512_HMAC_GENERAL:
  ------------------
  |  |  884|      1|#define CKM_SHA512_HMAC_GENERAL 0x00000272UL
  ------------------
  |  Branch (635:9): [True: 0, False: 16.7k]
  ------------------
  636|      1|        case CKM_MD2_HMAC:
  ------------------
  |  |  850|      1|#define CKM_MD2_HMAC 0x00000201UL
  ------------------
  |  Branch (636:9): [True: 0, False: 16.7k]
  ------------------
  637|      1|        case CKM_MD2_HMAC_GENERAL:
  ------------------
  |  |  851|      1|#define CKM_MD2_HMAC_GENERAL 0x00000202UL
  ------------------
  |  Branch (637:9): [True: 0, False: 16.7k]
  ------------------
  638|      1|        case CKM_MD5_HMAC:
  ------------------
  |  |  856|      1|#define CKM_MD5_HMAC 0x00000211UL
  ------------------
  |  Branch (638:9): [True: 0, False: 16.7k]
  ------------------
  639|      1|        case CKM_MD5_HMAC_GENERAL:
  ------------------
  |  |  857|      1|#define CKM_MD5_HMAC_GENERAL 0x00000212UL
  ------------------
  |  Branch (639:9): [True: 0, False: 16.7k]
  ------------------
  640|      1|        case CKM_TLS_PRF_GENERAL:
  ------------------
  |  |  297|      1|#define CKM_TLS_PRF_GENERAL 0x80000373UL
  ------------------
  |  Branch (640:9): [True: 0, False: 16.7k]
  ------------------
  641|      1|        case CKM_NSS_TLS_PRF_GENERAL_SHA256:
  ------------------
  |  |  233|      1|#define CKM_NSS_TLS_PRF_GENERAL_SHA256 (CKM_NSS + 21)
  |  |  ------------------
  |  |  |  |  162|      1|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      1|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      1|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (641:9): [True: 0, False: 16.7k]
  ------------------
  642|      1|        case CKM_GENERIC_SECRET_KEY_GEN:
  ------------------
  |  |  953|      1|#define CKM_GENERIC_SECRET_KEY_GEN 0x00000350UL
  ------------------
  |  Branch (642:9): [True: 0, False: 16.7k]
  ------------------
  643|      1|            return CKM_GENERIC_SECRET_KEY_GEN;
  ------------------
  |  |  953|      1|#define CKM_GENERIC_SECRET_KEY_GEN 0x00000350UL
  ------------------
  644|      0|        case CKM_PBE_MD2_DES_CBC:
  ------------------
  |  |  997|      0|#define CKM_PBE_MD2_DES_CBC 0x000003A0UL
  ------------------
  |  Branch (644:9): [True: 0, False: 16.7k]
  ------------------
  645|      0|        case CKM_PBE_MD5_DES_CBC:
  ------------------
  |  |  998|      0|#define CKM_PBE_MD5_DES_CBC 0x000003A1UL
  ------------------
  |  Branch (645:9): [True: 0, False: 16.7k]
  ------------------
  646|      0|        case CKM_PBA_SHA1_WITH_SHA1_HMAC:
  ------------------
  |  | 1015|      0|#define CKM_PBA_SHA1_WITH_SHA1_HMAC 0x000003C0UL
  ------------------
  |  Branch (646:9): [True: 0, False: 16.7k]
  ------------------
  647|      0|        case CKM_NSS_PBE_SHA1_HMAC_KEY_GEN:
  ------------------
  |  |  293|      0|#define CKM_NSS_PBE_SHA1_HMAC_KEY_GEN 0x80000009UL
  ------------------
  |  Branch (647:9): [True: 0, False: 16.7k]
  ------------------
  648|      0|        case CKM_NSS_PBE_MD5_HMAC_KEY_GEN:
  ------------------
  |  |  294|      0|#define CKM_NSS_PBE_MD5_HMAC_KEY_GEN 0x8000000aUL
  ------------------
  |  Branch (648:9): [True: 0, False: 16.7k]
  ------------------
  649|      0|        case CKM_NSS_PBE_MD2_HMAC_KEY_GEN:
  ------------------
  |  |  295|      0|#define CKM_NSS_PBE_MD2_HMAC_KEY_GEN 0x8000000bUL
  ------------------
  |  Branch (649:9): [True: 0, False: 16.7k]
  ------------------
  650|      0|        case CKM_NSS_PKCS12_PBE_SHA224_HMAC_KEY_GEN:
  ------------------
  |  |  246|      0|#define CKM_NSS_PKCS12_PBE_SHA224_HMAC_KEY_GEN (CKM_NSS + 29)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (650:9): [True: 0, False: 16.7k]
  ------------------
  651|      0|        case CKM_NSS_PKCS12_PBE_SHA256_HMAC_KEY_GEN:
  ------------------
  |  |  247|      0|#define CKM_NSS_PKCS12_PBE_SHA256_HMAC_KEY_GEN (CKM_NSS + 30)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (651:9): [True: 0, False: 16.7k]
  ------------------
  652|      0|        case CKM_NSS_PKCS12_PBE_SHA384_HMAC_KEY_GEN:
  ------------------
  |  |  248|      0|#define CKM_NSS_PKCS12_PBE_SHA384_HMAC_KEY_GEN (CKM_NSS + 31)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (652:9): [True: 0, False: 16.7k]
  ------------------
  653|      0|        case CKM_NSS_PKCS12_PBE_SHA512_HMAC_KEY_GEN:
  ------------------
  |  |  249|      0|#define CKM_NSS_PKCS12_PBE_SHA512_HMAC_KEY_GEN (CKM_NSS + 32)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (653:9): [True: 0, False: 16.7k]
  ------------------
  654|      0|        case CKM_NSS_PBE_SHA1_DES_CBC:
  ------------------
  |  |  286|      0|#define CKM_NSS_PBE_SHA1_DES_CBC 0x80000002UL
  ------------------
  |  Branch (654:9): [True: 0, False: 16.7k]
  ------------------
  655|      0|        case CKM_NSS_PBE_SHA1_40_BIT_RC2_CBC:
  ------------------
  |  |  288|      0|#define CKM_NSS_PBE_SHA1_40_BIT_RC2_CBC 0x80000004UL
  ------------------
  |  Branch (655:9): [True: 0, False: 16.7k]
  ------------------
  656|      0|        case CKM_NSS_PBE_SHA1_128_BIT_RC2_CBC:
  ------------------
  |  |  289|      0|#define CKM_NSS_PBE_SHA1_128_BIT_RC2_CBC 0x80000005UL
  ------------------
  |  Branch (656:9): [True: 0, False: 16.7k]
  ------------------
  657|      0|        case CKM_NSS_PBE_SHA1_40_BIT_RC4:
  ------------------
  |  |  290|      0|#define CKM_NSS_PBE_SHA1_40_BIT_RC4 0x80000006UL
  ------------------
  |  Branch (657:9): [True: 0, False: 16.7k]
  ------------------
  658|      0|        case CKM_NSS_PBE_SHA1_128_BIT_RC4:
  ------------------
  |  |  291|      0|#define CKM_NSS_PBE_SHA1_128_BIT_RC4 0x80000007UL
  ------------------
  |  Branch (658:9): [True: 0, False: 16.7k]
  ------------------
  659|      0|        case CKM_NSS_PBE_SHA1_TRIPLE_DES_CBC:
  ------------------
  |  |  287|      0|#define CKM_NSS_PBE_SHA1_TRIPLE_DES_CBC 0x80000003UL
  ------------------
  |  Branch (659:9): [True: 0, False: 16.7k]
  ------------------
  660|      0|        case CKM_NSS_PBE_SHA1_FAULTY_3DES_CBC:
  ------------------
  |  |  292|      0|#define CKM_NSS_PBE_SHA1_FAULTY_3DES_CBC 0x80000008UL
  ------------------
  |  Branch (660:9): [True: 0, False: 16.7k]
  ------------------
  661|      0|        case CKM_PBE_SHA1_RC2_40_CBC:
  ------------------
  |  | 1010|      0|#define CKM_PBE_SHA1_RC2_40_CBC 0x000003ABUL
  ------------------
  |  Branch (661:9): [True: 0, False: 16.7k]
  ------------------
  662|      0|        case CKM_PBE_SHA1_RC2_128_CBC:
  ------------------
  |  | 1009|      0|#define CKM_PBE_SHA1_RC2_128_CBC 0x000003AAUL
  ------------------
  |  Branch (662:9): [True: 0, False: 16.7k]
  ------------------
  663|      0|        case CKM_PBE_SHA1_RC4_40:
  ------------------
  |  | 1006|      0|#define CKM_PBE_SHA1_RC4_40 0x000003A7UL
  ------------------
  |  Branch (663:9): [True: 0, False: 16.7k]
  ------------------
  664|      0|        case CKM_PBE_SHA1_RC4_128:
  ------------------
  |  | 1005|      0|#define CKM_PBE_SHA1_RC4_128 0x000003A6UL
  ------------------
  |  Branch (664:9): [True: 0, False: 16.7k]
  ------------------
  665|      0|        case CKM_PBE_SHA1_DES3_EDE_CBC:
  ------------------
  |  | 1007|      0|#define CKM_PBE_SHA1_DES3_EDE_CBC 0x000003A8UL
  ------------------
  |  Branch (665:9): [True: 0, False: 16.7k]
  ------------------
  666|      0|        case CKM_PBE_SHA1_DES2_EDE_CBC:
  ------------------
  |  | 1008|      0|#define CKM_PBE_SHA1_DES2_EDE_CBC 0x000003A9UL
  ------------------
  |  Branch (666:9): [True: 0, False: 16.7k]
  ------------------
  667|      0|        case CKM_PKCS5_PBKD2:
  ------------------
  |  | 1013|      0|#define CKM_PKCS5_PBKD2 0x000003B0UL
  ------------------
  |  Branch (667:9): [True: 0, False: 16.7k]
  ------------------
  668|      0|            return type;
  669|      0|        default:
  ------------------
  |  Branch (669:9): [True: 0, False: 16.7k]
  ------------------
  670|      0|            return pk11_lookup(type)->keyGen;
  671|  16.7k|    }
  672|  16.7k|}
pk11_ParamFromIVWithLen:
  877|  45.9k|{
  878|  45.9k|    CK_RC2_CBC_PARAMS *rc2_params = NULL;
  879|  45.9k|    CK_RC2_PARAMS *rc2_ecb_params = NULL;
  880|  45.9k|    CK_RC5_PARAMS *rc5_params = NULL;
  881|  45.9k|    CK_RC5_CBC_PARAMS *rc5_cbc_params = NULL;
  882|  45.9k|    SECItem *param;
  883|       |
  884|  45.9k|    param = (SECItem *)PORT_Alloc(sizeof(SECItem));
  ------------------
  |  |   52|  45.9k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  885|  45.9k|    if (param == NULL)
  ------------------
  |  Branch (885:9): [True: 0, False: 45.9k]
  ------------------
  886|      0|        return NULL;
  887|  45.9k|    param->data = NULL;
  888|  45.9k|    param->len = 0;
  889|  45.9k|    param->type = 0;
  890|  45.9k|    switch (type) {
  891|      0|        case CKM_SEED_ECB:
  ------------------
  |  | 1156|      0|#define CKM_SEED_ECB 0x00000651UL
  ------------------
  |  Branch (891:9): [True: 0, False: 45.9k]
  ------------------
  892|      0|        case CKM_CAMELLIA_ECB:
  ------------------
  |  | 1136|      0|#define CKM_CAMELLIA_ECB 0x00000551UL
  ------------------
  |  Branch (892:9): [True: 0, False: 45.9k]
  ------------------
  893|      0|        case CKM_AES_ECB:
  ------------------
  |  | 1107|      0|#define CKM_AES_ECB 0x00001081UL
  ------------------
  |  Branch (893:9): [True: 0, False: 45.9k]
  ------------------
  894|      0|        case CKM_DES_ECB:
  ------------------
  |  |  815|      0|#define CKM_DES_ECB 0x00000121UL
  ------------------
  |  Branch (894:9): [True: 0, False: 45.9k]
  ------------------
  895|  33.9k|        case CKM_DES3_ECB:
  ------------------
  |  |  825|  33.9k|#define CKM_DES3_ECB 0x00000132UL
  ------------------
  |  Branch (895:9): [True: 33.9k, False: 11.9k]
  ------------------
  896|  45.9k|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|  45.9k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (896:9): [True: 11.9k, False: 33.9k]
  ------------------
  897|  45.9k|        case CKM_RSA_X_509:
  ------------------
  |  |  722|  45.9k|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (897:9): [True: 0, False: 45.9k]
  ------------------
  898|  45.9k|        case CKM_RSA_9796:
  ------------------
  |  |  721|  45.9k|#define CKM_RSA_9796 0x00000002UL
  ------------------
  |  Branch (898:9): [True: 0, False: 45.9k]
  ------------------
  899|  45.9k|        case CKM_IDEA_ECB:
  ------------------
  |  |  948|  45.9k|#define CKM_IDEA_ECB 0x00000341UL
  ------------------
  |  Branch (899:9): [True: 0, False: 45.9k]
  ------------------
  900|  45.9k|        case CKM_CDMF_ECB:
  ------------------
  |  |  835|  45.9k|#define CKM_CDMF_ECB 0x00000141UL
  ------------------
  |  Branch (900:9): [True: 0, False: 45.9k]
  ------------------
  901|  45.9k|        case CKM_CAST_ECB:
  ------------------
  |  |  918|  45.9k|#define CKM_CAST_ECB 0x00000301UL
  ------------------
  |  Branch (901:9): [True: 0, False: 45.9k]
  ------------------
  902|  45.9k|        case CKM_CAST3_ECB:
  ------------------
  |  |  924|  45.9k|#define CKM_CAST3_ECB 0x00000311UL
  ------------------
  |  Branch (902:9): [True: 0, False: 45.9k]
  ------------------
  903|  45.9k|        case CKM_CAST5_ECB:
  ------------------
  |  |  931|  45.9k|#define CKM_CAST5_ECB 0x00000321UL
  ------------------
  |  Branch (903:9): [True: 0, False: 45.9k]
  ------------------
  904|  45.9k|        case CKM_RC4:
  ------------------
  |  |  813|  45.9k|#define CKM_RC4 0x00000111UL
  ------------------
  |  Branch (904:9): [True: 0, False: 45.9k]
  ------------------
  905|  45.9k|            break;
  906|      0|        case CKM_RC2_ECB:
  ------------------
  |  |  804|      0|#define CKM_RC2_ECB 0x00000101UL
  ------------------
  |  Branch (906:9): [True: 0, False: 45.9k]
  ------------------
  907|      0|            rc2_ecb_params = (CK_RC2_PARAMS *)PORT_Alloc(sizeof(CK_RC2_PARAMS));
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  908|      0|            if (rc2_ecb_params == NULL)
  ------------------
  |  Branch (908:17): [True: 0, False: 0]
  ------------------
  909|      0|                break;
  910|       |            /*  Maybe we should pass the key size in too to get this value? */
  911|      0|            *rc2_ecb_params = keyLen ? keyLen * 8 : 128;
  ------------------
  |  Branch (911:31): [True: 0, False: 0]
  ------------------
  912|      0|            param->data = (unsigned char *)rc2_ecb_params;
  913|      0|            param->len = sizeof(CK_RC2_PARAMS);
  914|      0|            break;
  915|      0|        case CKM_RC2_CBC:
  ------------------
  |  |  805|      0|#define CKM_RC2_CBC 0x00000102UL
  ------------------
  |  Branch (915:9): [True: 0, False: 45.9k]
  ------------------
  916|      0|        case CKM_RC2_CBC_PAD:
  ------------------
  |  |  810|      0|#define CKM_RC2_CBC_PAD 0x00000105UL
  ------------------
  |  Branch (916:9): [True: 0, False: 45.9k]
  ------------------
  917|      0|            rc2_params = (CK_RC2_CBC_PARAMS *)PORT_Alloc(sizeof(CK_RC2_CBC_PARAMS));
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  918|      0|            if (rc2_params == NULL)
  ------------------
  |  Branch (918:17): [True: 0, False: 0]
  ------------------
  919|      0|                break;
  920|       |            /* Maybe we should pass the key size in too to get this value? */
  921|      0|            rc2_params->ulEffectiveBits = keyLen ? keyLen * 8 : 128;
  ------------------
  |  Branch (921:43): [True: 0, False: 0]
  ------------------
  922|      0|            if (iv && iv->data)
  ------------------
  |  Branch (922:17): [True: 0, False: 0]
  |  Branch (922:23): [True: 0, False: 0]
  ------------------
  923|      0|                PORT_Memcpy(rc2_params->iv, iv->data, sizeof(rc2_params->iv));
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  924|      0|            param->data = (unsigned char *)rc2_params;
  925|      0|            param->len = sizeof(CK_RC2_CBC_PARAMS);
  926|      0|            break;
  927|      0|        case CKM_RC5_CBC:
  ------------------
  |  |  943|      0|#define CKM_RC5_CBC 0x00000332UL
  ------------------
  |  Branch (927:9): [True: 0, False: 45.9k]
  ------------------
  928|      0|        case CKM_RC5_CBC_PAD:
  ------------------
  |  |  946|      0|#define CKM_RC5_CBC_PAD 0x00000335UL
  ------------------
  |  Branch (928:9): [True: 0, False: 45.9k]
  ------------------
  929|      0|            rc5_cbc_params = (CK_RC5_CBC_PARAMS *)
  930|      0|                PORT_Alloc(sizeof(CK_RC5_CBC_PARAMS) + ((iv) ? iv->len : 0));
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  |  Branch (930:57): [True: 0, False: 0]
  ------------------
  931|      0|            if (rc5_cbc_params == NULL)
  ------------------
  |  Branch (931:17): [True: 0, False: 0]
  ------------------
  932|      0|                break;
  933|      0|            if (iv && iv->data && iv->len) {
  ------------------
  |  Branch (933:17): [True: 0, False: 0]
  |  Branch (933:23): [True: 0, False: 0]
  |  Branch (933:35): [True: 0, False: 0]
  ------------------
  934|      0|                rc5_cbc_params->pIv = ((CK_BYTE_PTR)rc5_cbc_params) + sizeof(CK_RC5_CBC_PARAMS);
  935|      0|                PORT_Memcpy(rc5_cbc_params->pIv, iv->data, iv->len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  936|      0|                rc5_cbc_params->ulIvLen = iv->len;
  937|      0|                rc5_cbc_params->ulWordsize = iv->len / 2;
  938|      0|            } else {
  939|      0|                rc5_cbc_params->ulWordsize = 4;
  940|      0|                rc5_cbc_params->pIv = NULL;
  941|      0|                rc5_cbc_params->ulIvLen = 0;
  942|      0|            }
  943|      0|            rc5_cbc_params->ulRounds = 16;
  944|      0|            param->data = (unsigned char *)rc5_cbc_params;
  945|      0|            param->len = sizeof(CK_RC5_CBC_PARAMS);
  946|      0|            break;
  947|      0|        case CKM_RC5_ECB:
  ------------------
  |  |  942|      0|#define CKM_RC5_ECB 0x00000331UL
  ------------------
  |  Branch (947:9): [True: 0, False: 45.9k]
  ------------------
  948|      0|            rc5_params = (CK_RC5_PARAMS *)PORT_Alloc(sizeof(CK_RC5_PARAMS));
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  949|      0|            if (rc5_params == NULL)
  ------------------
  |  Branch (949:17): [True: 0, False: 0]
  ------------------
  950|      0|                break;
  951|      0|            if (iv && iv->data && iv->len) {
  ------------------
  |  Branch (951:17): [True: 0, False: 0]
  |  Branch (951:23): [True: 0, False: 0]
  |  Branch (951:35): [True: 0, False: 0]
  ------------------
  952|      0|                rc5_params->ulWordsize = iv->len / 2;
  953|      0|            } else {
  954|      0|                rc5_params->ulWordsize = 4;
  955|      0|            }
  956|      0|            rc5_params->ulRounds = 16;
  957|      0|            param->data = (unsigned char *)rc5_params;
  958|      0|            param->len = sizeof(CK_RC5_PARAMS);
  959|      0|            break;
  960|       |
  961|      0|        case CKM_SEED_CBC:
  ------------------
  |  | 1157|      0|#define CKM_SEED_CBC 0x00000652UL
  ------------------
  |  Branch (961:9): [True: 0, False: 45.9k]
  ------------------
  962|      0|        case CKM_CAMELLIA_CBC:
  ------------------
  |  | 1137|      0|#define CKM_CAMELLIA_CBC 0x00000552UL
  ------------------
  |  Branch (962:9): [True: 0, False: 45.9k]
  ------------------
  963|      0|        case CKM_AES_CBC:
  ------------------
  |  | 1108|      0|#define CKM_AES_CBC 0x00001082UL
  ------------------
  |  Branch (963:9): [True: 0, False: 45.9k]
  ------------------
  964|      0|        case CKM_DES_CBC:
  ------------------
  |  |  816|      0|#define CKM_DES_CBC 0x00000122UL
  ------------------
  |  Branch (964:9): [True: 0, False: 45.9k]
  ------------------
  965|      0|        case CKM_DES3_CBC:
  ------------------
  |  |  826|      0|#define CKM_DES3_CBC 0x00000133UL
  ------------------
  |  Branch (965:9): [True: 0, False: 45.9k]
  ------------------
  966|      0|        case CKM_IDEA_CBC:
  ------------------
  |  |  949|      0|#define CKM_IDEA_CBC 0x00000342UL
  ------------------
  |  Branch (966:9): [True: 0, False: 45.9k]
  ------------------
  967|      0|        case CKM_CDMF_CBC:
  ------------------
  |  |  836|      0|#define CKM_CDMF_CBC 0x00000142UL
  ------------------
  |  Branch (967:9): [True: 0, False: 45.9k]
  ------------------
  968|      0|        case CKM_CAST_CBC:
  ------------------
  |  |  919|      0|#define CKM_CAST_CBC 0x00000302UL
  ------------------
  |  Branch (968:9): [True: 0, False: 45.9k]
  ------------------
  969|      0|        case CKM_CAST3_CBC:
  ------------------
  |  |  925|      0|#define CKM_CAST3_CBC 0x00000312UL
  ------------------
  |  Branch (969:9): [True: 0, False: 45.9k]
  ------------------
  970|      0|        case CKM_CAST5_CBC:
  ------------------
  |  |  933|      0|#define CKM_CAST5_CBC 0x00000322UL
  ------------------
  |  Branch (970:9): [True: 0, False: 45.9k]
  ------------------
  971|      0|        case CKM_CAMELLIA_CBC_PAD:
  ------------------
  |  | 1140|      0|#define CKM_CAMELLIA_CBC_PAD 0x00000555UL
  ------------------
  |  Branch (971:9): [True: 0, False: 45.9k]
  ------------------
  972|      0|        case CKM_AES_CBC_PAD:
  ------------------
  |  | 1111|      0|#define CKM_AES_CBC_PAD 0x00001085UL
  ------------------
  |  Branch (972:9): [True: 0, False: 45.9k]
  ------------------
  973|      0|        case CKM_DES_CBC_PAD:
  ------------------
  |  |  821|      0|#define CKM_DES_CBC_PAD 0x00000125UL
  ------------------
  |  Branch (973:9): [True: 0, False: 45.9k]
  ------------------
  974|      0|        case CKM_DES3_CBC_PAD:
  ------------------
  |  |  833|      0|#define CKM_DES3_CBC_PAD 0x00000136UL
  ------------------
  |  Branch (974:9): [True: 0, False: 45.9k]
  ------------------
  975|      0|        case CKM_IDEA_CBC_PAD:
  ------------------
  |  |  952|      0|#define CKM_IDEA_CBC_PAD 0x00000345UL
  ------------------
  |  Branch (975:9): [True: 0, False: 45.9k]
  ------------------
  976|      0|        case CKM_CDMF_CBC_PAD:
  ------------------
  |  |  839|      0|#define CKM_CDMF_CBC_PAD 0x00000145UL
  ------------------
  |  Branch (976:9): [True: 0, False: 45.9k]
  ------------------
  977|      0|        case CKM_CAST_CBC_PAD:
  ------------------
  |  |  922|      0|#define CKM_CAST_CBC_PAD 0x00000305UL
  ------------------
  |  Branch (977:9): [True: 0, False: 45.9k]
  ------------------
  978|      0|        case CKM_CAST3_CBC_PAD:
  ------------------
  |  |  928|      0|#define CKM_CAST3_CBC_PAD 0x00000315UL
  ------------------
  |  Branch (978:9): [True: 0, False: 45.9k]
  ------------------
  979|      0|        case CKM_CAST5_CBC_PAD:
  ------------------
  |  |  939|      0|#define CKM_CAST5_CBC_PAD 0x00000325UL
  ------------------
  |  Branch (979:9): [True: 0, False: 45.9k]
  ------------------
  980|      0|        case CKM_SKIPJACK_CBC64:
  ------------------
  |  | 1049|      0|#define CKM_SKIPJACK_CBC64 0x00001002UL
  ------------------
  |  Branch (980:9): [True: 0, False: 45.9k]
  ------------------
  981|      0|        case CKM_SKIPJACK_ECB64:
  ------------------
  |  | 1048|      0|#define CKM_SKIPJACK_ECB64 0x00001001UL
  ------------------
  |  Branch (981:9): [True: 0, False: 45.9k]
  ------------------
  982|      0|        case CKM_SKIPJACK_OFB64:
  ------------------
  |  | 1050|      0|#define CKM_SKIPJACK_OFB64 0x00001003UL
  ------------------
  |  Branch (982:9): [True: 0, False: 45.9k]
  ------------------
  983|      0|        case CKM_SKIPJACK_CFB64:
  ------------------
  |  | 1051|      0|#define CKM_SKIPJACK_CFB64 0x00001004UL
  ------------------
  |  Branch (983:9): [True: 0, False: 45.9k]
  ------------------
  984|      0|        case CKM_SKIPJACK_CFB32:
  ------------------
  |  | 1052|      0|#define CKM_SKIPJACK_CFB32 0x00001005UL
  ------------------
  |  Branch (984:9): [True: 0, False: 45.9k]
  ------------------
  985|      0|        case CKM_SKIPJACK_CFB16:
  ------------------
  |  | 1053|      0|#define CKM_SKIPJACK_CFB16 0x00001006UL
  ------------------
  |  Branch (985:9): [True: 0, False: 45.9k]
  ------------------
  986|      0|        case CKM_SKIPJACK_CFB8:
  ------------------
  |  | 1054|      0|#define CKM_SKIPJACK_CFB8 0x00001007UL
  ------------------
  |  Branch (986:9): [True: 0, False: 45.9k]
  ------------------
  987|      0|        case CKM_BATON_ECB128:
  ------------------
  |  | 1062|      0|#define CKM_BATON_ECB128 0x00001031UL
  ------------------
  |  Branch (987:9): [True: 0, False: 45.9k]
  ------------------
  988|      0|        case CKM_BATON_ECB96:
  ------------------
  |  | 1063|      0|#define CKM_BATON_ECB96 0x00001032UL
  ------------------
  |  Branch (988:9): [True: 0, False: 45.9k]
  ------------------
  989|      0|        case CKM_BATON_CBC128:
  ------------------
  |  | 1064|      0|#define CKM_BATON_CBC128 0x00001033UL
  ------------------
  |  Branch (989:9): [True: 0, False: 45.9k]
  ------------------
  990|      0|        case CKM_BATON_COUNTER:
  ------------------
  |  | 1065|      0|#define CKM_BATON_COUNTER 0x00001034UL
  ------------------
  |  Branch (990:9): [True: 0, False: 45.9k]
  ------------------
  991|      0|        case CKM_BATON_SHUFFLE:
  ------------------
  |  | 1066|      0|#define CKM_BATON_SHUFFLE 0x00001035UL
  ------------------
  |  Branch (991:9): [True: 0, False: 45.9k]
  ------------------
  992|      0|        case CKM_JUNIPER_ECB128:
  ------------------
  |  | 1095|      0|#define CKM_JUNIPER_ECB128 0x00001061UL
  ------------------
  |  Branch (992:9): [True: 0, False: 45.9k]
  ------------------
  993|      0|        case CKM_JUNIPER_CBC128:
  ------------------
  |  | 1096|      0|#define CKM_JUNIPER_CBC128 0x00001062UL
  ------------------
  |  Branch (993:9): [True: 0, False: 45.9k]
  ------------------
  994|      0|        case CKM_JUNIPER_COUNTER:
  ------------------
  |  | 1097|      0|#define CKM_JUNIPER_COUNTER 0x00001063UL
  ------------------
  |  Branch (994:9): [True: 0, False: 45.9k]
  ------------------
  995|      0|        case CKM_JUNIPER_SHUFFLE:
  ------------------
  |  | 1098|      0|#define CKM_JUNIPER_SHUFFLE 0x00001064UL
  ------------------
  |  Branch (995:9): [True: 0, False: 45.9k]
  ------------------
  996|      0|            if ((iv == NULL) || (iv->data == NULL))
  ------------------
  |  Branch (996:17): [True: 0, False: 0]
  |  Branch (996:33): [True: 0, False: 0]
  ------------------
  997|      0|                break;
  998|      0|            param->data = (unsigned char *)PORT_Alloc(iv->len);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  999|      0|            if (param->data != NULL) {
  ------------------
  |  Branch (999:17): [True: 0, False: 0]
  ------------------
 1000|      0|                PORT_Memcpy(param->data, iv->data, iv->len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 1001|      0|                param->len = iv->len;
 1002|      0|            }
 1003|      0|            break;
 1004|       |        /* unknown mechanism, pass IV in if it's there */
 1005|      0|        default:
  ------------------
  |  Branch (1005:9): [True: 0, False: 45.9k]
  ------------------
 1006|      0|            if (pk11_lookup(type)->iv == 0) {
  ------------------
  |  Branch (1006:17): [True: 0, False: 0]
  ------------------
 1007|      0|                break;
 1008|      0|            }
 1009|      0|            if ((iv == NULL) || (iv->data == NULL)) {
  ------------------
  |  Branch (1009:17): [True: 0, False: 0]
  |  Branch (1009:33): [True: 0, False: 0]
  ------------------
 1010|      0|                break;
 1011|      0|            }
 1012|      0|            param->data = (unsigned char *)PORT_Alloc(iv->len);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1013|      0|            if (param->data != NULL) {
  ------------------
  |  Branch (1013:17): [True: 0, False: 0]
  ------------------
 1014|      0|                PORT_Memcpy(param->data, iv->data, iv->len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 1015|      0|                param->len = iv->len;
 1016|      0|            }
 1017|      0|            break;
 1018|  45.9k|    }
 1019|  45.9k|    return param;
 1020|  45.9k|}
PK11_ParamFromIV:
 1028|  45.9k|{
 1029|  45.9k|    return pk11_ParamFromIVWithLen(type, iv, 0);
 1030|  45.9k|}
PK11_AlgtagToMechanism:
 1755|   221k|{
 1756|   221k|    SECOidData *oid = SECOID_FindOIDByTag(algTag);
  ------------------
  |  |  116|   221k|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
 1757|       |
 1758|   221k|    if (oid)
  ------------------
  |  Branch (1758:9): [True: 221k, False: 0]
  ------------------
 1759|   221k|        return (CK_MECHANISM_TYPE)oid->mechanism;
 1760|      0|    return CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
 1761|   221k|}
PK11_MapSignKeyType:
 1931|  50.3k|{
 1932|  50.3k|    switch (keyType) {
 1933|  38.5k|        case rsaKey:
  ------------------
  |  Branch (1933:9): [True: 38.5k, False: 11.7k]
  ------------------
 1934|  38.5k|            return CKM_RSA_PKCS;
  ------------------
  |  |  720|  38.5k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
 1935|      0|        case fortezzaKey:
  ------------------
  |  Branch (1935:9): [True: 0, False: 50.3k]
  ------------------
 1936|      0|        case dsaKey:
  ------------------
  |  Branch (1936:9): [True: 0, False: 50.3k]
  ------------------
 1937|      0|            return CKM_DSA;
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
 1938|  11.7k|        case ecKey:
  ------------------
  |  Branch (1938:9): [True: 11.7k, False: 38.5k]
  ------------------
 1939|  11.7k|            return CKM_ECDSA;
  ------------------
  |  | 1074|  11.7k|#define CKM_ECDSA 0x00001041UL
  ------------------
 1940|      0|        case edKey:
  ------------------
  |  Branch (1940:9): [True: 0, False: 50.3k]
  ------------------
 1941|      0|            return CKM_EDDSA;
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
 1942|      0|        case dhKey:
  ------------------
  |  Branch (1942:9): [True: 0, False: 50.3k]
  ------------------
 1943|      0|        default:
  ------------------
  |  Branch (1943:9): [True: 0, False: 50.3k]
  ------------------
 1944|      0|            break;
 1945|  50.3k|    }
 1946|      0|    return CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
 1947|  50.3k|}
pk11_mapWrapKeyType:
 1951|  11.9k|{
 1952|  11.9k|    switch (keyType) {
 1953|  11.9k|        case rsaKey:
  ------------------
  |  Branch (1953:9): [True: 11.9k, False: 0]
  ------------------
 1954|  11.9k|            return CKM_RSA_PKCS;
  ------------------
  |  |  720|  11.9k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
 1955|       |        /* Add fortezza?? */
 1956|      0|        default:
  ------------------
  |  Branch (1956:9): [True: 0, False: 11.9k]
  ------------------
 1957|      0|            break;
 1958|  11.9k|    }
 1959|      0|    return CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
 1960|  11.9k|}
pk11mech.c:pk11_lookup:
   75|  80.8k|{
   76|  80.8k|    int i;
   77|  80.8k|    for (i = 0; i < pk11_MechEntrySize; i++) {
  ------------------
  |  Branch (77:17): [True: 0, False: 80.8k]
  ------------------
   78|      0|        if (pk11_MechanismTable[i].type == type) {
  ------------------
  |  Branch (78:13): [True: 0, False: 0]
  ------------------
   79|      0|            return (&pk11_MechanismTable[i]);
   80|      0|        }
   81|      0|    }
   82|  80.8k|    return &pk11_default;
   83|  80.8k|}

PK11_DestroyObject:
   55|  97.7k|{
   56|  97.7k|    CK_RV crv;
   57|       |
   58|  97.7k|    PK11_EnterSlotMonitor(slot);
   59|  97.7k|    crv = PK11_GETTAB(slot)->C_DestroyObject(slot->session, object);
  ------------------
  |  |  102|  97.7k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
   60|  97.7k|    PK11_ExitSlotMonitor(slot);
   61|  97.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  97.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (61:9): [True: 0, False: 97.7k]
  ------------------
   62|      0|        return SECFailure;
   63|      0|    }
   64|  97.7k|    return SECSuccess;
   65|  97.7k|}
PK11_ReadAttribute:
  100|   338k|{
  101|   338k|    CK_ATTRIBUTE attr = { 0, NULL, 0 };
  102|   338k|    CK_RV crv;
  103|       |
  104|   338k|    attr.type = type;
  105|       |
  106|   338k|    PK11_EnterSlotMonitor(slot);
  107|   338k|    crv = PK11_GETTAB(slot)->C_GetAttributeValue(slot->session, id, &attr, 1);
  ------------------
  |  |  102|   338k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  108|   338k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   338k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (108:9): [True: 0, False: 338k]
  ------------------
  109|      0|        PK11_ExitSlotMonitor(slot);
  110|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  111|      0|        return SECFailure;
  112|      0|    }
  113|   338k|    if (arena) {
  ------------------
  |  Branch (113:9): [True: 0, False: 338k]
  ------------------
  114|      0|        attr.pValue = PORT_ArenaAlloc(arena, attr.ulValueLen);
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  115|   338k|    } else {
  116|   338k|        attr.pValue = PORT_Alloc(attr.ulValueLen);
  ------------------
  |  |   52|   338k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  117|   338k|    }
  118|   338k|    if (attr.pValue == NULL) {
  ------------------
  |  Branch (118:9): [True: 0, False: 338k]
  ------------------
  119|      0|        PK11_ExitSlotMonitor(slot);
  120|      0|        return SECFailure;
  121|      0|    }
  122|   338k|    crv = PK11_GETTAB(slot)->C_GetAttributeValue(slot->session, id, &attr, 1);
  ------------------
  |  |  102|   338k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  123|   338k|    PK11_ExitSlotMonitor(slot);
  124|   338k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   338k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (124:9): [True: 0, False: 338k]
  ------------------
  125|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  126|      0|        if (!arena)
  ------------------
  |  Branch (126:13): [True: 0, False: 0]
  ------------------
  127|      0|            PORT_Free(attr.pValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  128|      0|        return SECFailure;
  129|      0|    }
  130|       |
  131|   338k|    result->data = (unsigned char *)attr.pValue;
  132|   338k|    result->len = attr.ulValueLen;
  133|       |
  134|   338k|    return SECSuccess;
  135|   338k|}
PK11_ReadULongAttribute:
  143|  47.4k|{
  144|  47.4k|    CK_ATTRIBUTE attr;
  145|  47.4k|    CK_ULONG value = CK_UNAVAILABLE_INFORMATION;
  ------------------
  |  |   64|  47.4k|#define CK_UNAVAILABLE_INFORMATION (~0UL)
  ------------------
  146|  47.4k|    CK_RV crv;
  147|       |
  148|  47.4k|    PK11_SETATTRS(&attr, type, &value, sizeof(value));
  ------------------
  |  |  104|  47.4k|    (x)->type = (id);              \
  |  |  105|  47.4k|    (x)->pValue = (v);             \
  |  |  106|  47.4k|    (x)->ulValueLen = (l);
  ------------------
  149|       |
  150|  47.4k|    PK11_EnterSlotMonitor(slot);
  151|  47.4k|    crv = PK11_GETTAB(slot)->C_GetAttributeValue(slot->session, id, &attr, 1);
  ------------------
  |  |  102|  47.4k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  152|  47.4k|    PK11_ExitSlotMonitor(slot);
  153|  47.4k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (153:9): [True: 0, False: 47.4k]
  ------------------
  154|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  155|      0|    }
  156|  47.4k|    return value;
  157|  47.4k|}
pk11_HasAttributeSet_Lock:
  165|   145k|{
  166|   145k|    CK_BBOOL ckvalue = CK_FALSE;
  ------------------
  |  |   23|   145k|#define CK_FALSE 0
  ------------------
  167|   145k|    CK_ATTRIBUTE theTemplate;
  168|   145k|    CK_RV crv;
  169|       |
  170|       |    /* Prepare to retrieve the attribute. */
  171|   145k|    PK11_SETATTRS(&theTemplate, type, &ckvalue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|   145k|    (x)->type = (id);              \
  |  |  105|   145k|    (x)->pValue = (v);             \
  |  |  106|   145k|    (x)->ulValueLen = (l);
  ------------------
  172|       |
  173|       |    /* Retrieve attribute value. */
  174|   145k|    if (!haslock)
  ------------------
  |  Branch (174:9): [True: 145k, False: 0]
  ------------------
  175|   145k|        PK11_EnterSlotMonitor(slot);
  176|   145k|    crv = PK11_GETTAB(slot)->C_GetAttributeValue(slot->session, id,
  ------------------
  |  |  102|   145k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  177|   145k|                                                 &theTemplate, 1);
  178|   145k|    if (!haslock)
  ------------------
  |  Branch (178:9): [True: 145k, False: 0]
  ------------------
  179|   145k|        PK11_ExitSlotMonitor(slot);
  180|   145k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   145k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (180:9): [True: 2, False: 145k]
  ------------------
  181|      2|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  182|      2|        return CK_FALSE;
  ------------------
  |  |   23|      2|#define CK_FALSE 0
  ------------------
  183|      2|    }
  184|       |
  185|   145k|    return ckvalue;
  186|   145k|}
PK11_HasAttributeSet:
  191|   145k|{
  192|   145k|    PR_ASSERT(haslock == PR_FALSE);
  ------------------
  |  |  208|   145k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 145k, False: 0]
  |  |  ------------------
  ------------------
  193|   145k|    return pk11_HasAttributeSet_Lock(slot, id, type, PR_FALSE);
  ------------------
  |  |  438|   145k|#define PR_FALSE 0
  ------------------
  194|   145k|}
PK11_GetAttributes:
  203|  82.9k|{
  204|  82.9k|    int i;
  205|       |    /* make pedantic happy... note that it's only used arena != NULL */
  206|  82.9k|    void *mark = NULL;
  207|  82.9k|    CK_RV crv;
  208|  82.9k|    if (slot->session == CK_INVALID_HANDLE)
  ------------------
  |  |   78|  82.9k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (208:9): [True: 0, False: 82.9k]
  ------------------
  209|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  210|       |
  211|       |    /*
  212|       |     * first get all the lengths of the parameters.
  213|       |     */
  214|  82.9k|    PK11_EnterSlotMonitor(slot);
  215|  82.9k|    crv = PK11_GETTAB(slot)->C_GetAttributeValue(slot->session, obj, attr, count);
  ------------------
  |  |  102|  82.9k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  216|  82.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  82.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (216:9): [True: 0, False: 82.9k]
  ------------------
  217|      0|        PK11_ExitSlotMonitor(slot);
  218|      0|        return crv;
  219|      0|    }
  220|       |
  221|  82.9k|    if (arena) {
  ------------------
  |  Branch (221:9): [True: 47.3k, False: 35.5k]
  ------------------
  222|  47.3k|        mark = PORT_ArenaMark(arena);
  ------------------
  |  |   55|  47.3k|#define PORT_ArenaMark PORT_ArenaMark_Util
  ------------------
  223|  47.3k|        if (mark == NULL)
  ------------------
  |  Branch (223:13): [True: 0, False: 47.3k]
  ------------------
  224|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  225|  47.3k|    }
  226|       |
  227|       |    /*
  228|       |     * now allocate space to store the results.
  229|       |     */
  230|   336k|    for (i = 0; i < count; i++) {
  ------------------
  |  Branch (230:17): [True: 253k, False: 82.9k]
  ------------------
  231|   253k|        if (attr[i].ulValueLen == 0)
  ------------------
  |  Branch (231:13): [True: 0, False: 253k]
  ------------------
  232|      0|            continue;
  233|   253k|        if (arena) {
  ------------------
  |  Branch (233:13): [True: 218k, False: 35.5k]
  ------------------
  234|   218k|            attr[i].pValue = PORT_ArenaAlloc(arena, attr[i].ulValueLen);
  ------------------
  |  |   53|   218k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  235|   218k|            if (attr[i].pValue == NULL) {
  ------------------
  |  Branch (235:17): [True: 0, False: 218k]
  ------------------
  236|       |                /* arena failures, just release the mark */
  237|      0|                PORT_ArenaRelease(arena, mark);
  ------------------
  |  |   56|      0|#define PORT_ArenaRelease PORT_ArenaRelease_Util
  ------------------
  238|      0|                PK11_ExitSlotMonitor(slot);
  239|      0|                return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  240|      0|            }
  241|   218k|        } else {
  242|  35.5k|            attr[i].pValue = PORT_Alloc(attr[i].ulValueLen);
  ------------------
  |  |   52|  35.5k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  243|  35.5k|            if (attr[i].pValue == NULL) {
  ------------------
  |  Branch (243:17): [True: 0, False: 35.5k]
  ------------------
  244|       |                /* Separate malloc failures, loop to release what we have
  245|       |                 * so far */
  246|      0|                int j;
  247|      0|                for (j = 0; j < i; j++) {
  ------------------
  |  Branch (247:29): [True: 0, False: 0]
  ------------------
  248|      0|                    PORT_Free(attr[j].pValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  249|       |                    /* don't give the caller pointers to freed memory */
  250|      0|                    attr[j].pValue = NULL;
  251|      0|                }
  252|      0|                PK11_ExitSlotMonitor(slot);
  253|      0|                return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  254|      0|            }
  255|  35.5k|        }
  256|   253k|    }
  257|       |
  258|       |    /*
  259|       |     * finally get the results.
  260|       |     */
  261|  82.9k|    crv = PK11_GETTAB(slot)->C_GetAttributeValue(slot->session, obj, attr, count);
  ------------------
  |  |  102|  82.9k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  262|  82.9k|    PK11_ExitSlotMonitor(slot);
  263|  82.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  82.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (263:9): [True: 0, False: 82.9k]
  ------------------
  264|      0|        if (arena) {
  ------------------
  |  Branch (264:13): [True: 0, False: 0]
  ------------------
  265|      0|            PORT_ArenaRelease(arena, mark);
  ------------------
  |  |   56|      0|#define PORT_ArenaRelease PORT_ArenaRelease_Util
  ------------------
  266|      0|        } else {
  267|      0|            for (i = 0; i < count; i++) {
  ------------------
  |  Branch (267:25): [True: 0, False: 0]
  ------------------
  268|      0|                PORT_Free(attr[i].pValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  269|       |                /* don't give the caller pointers to freed memory */
  270|      0|                attr[i].pValue = NULL;
  271|      0|            }
  272|      0|        }
  273|  82.9k|    } else if (arena && mark) {
  ------------------
  |  Branch (273:16): [True: 47.3k, False: 35.5k]
  |  Branch (273:25): [True: 47.3k, False: 0]
  ------------------
  274|  47.3k|        PORT_ArenaUnmark(arena, mark);
  ------------------
  |  |   58|  47.3k|#define PORT_ArenaUnmark PORT_ArenaUnmark_Util
  ------------------
  275|  47.3k|    }
  276|  82.9k|    return crv;
  277|  82.9k|}
PK11_IsPermObject:
  281|  50.3k|{
  282|  50.3k|    return (PRBool)PK11_HasAttributeSet(slot, handle, CKA_TOKEN, PR_FALSE);
  ------------------
  |  |  512|  50.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
                  return (PRBool)PK11_HasAttributeSet(slot, handle, CKA_TOKEN, PR_FALSE);
  ------------------
  |  |  438|  50.3k|#define PR_FALSE 0
  ------------------
  283|  50.3k|}
pk11_SignedToUnsigned:
  341|  6.03k|{
  342|  6.03k|    char *ptr = (char *)attrib->pValue;
  343|  6.03k|    unsigned long len = attrib->ulValueLen;
  344|       |
  345|  6.03k|    while ((len > 1) && (*ptr == 0)) {
  ------------------
  |  Branch (345:12): [True: 6.03k, False: 0]
  |  Branch (345:25): [True: 0, False: 6.03k]
  ------------------
  346|      0|        len--;
  347|      0|        ptr++;
  348|      0|    }
  349|  6.03k|    attrib->pValue = ptr;
  350|  6.03k|    attrib->ulValueLen = len;
  351|  6.03k|}
pk11_GetNewSession:
  359|   869k|{
  360|   869k|    CK_SESSION_HANDLE session;
  361|   869k|    *owner = PR_TRUE;
  ------------------
  |  |  437|   869k|#define PR_TRUE 1
  ------------------
  362|   869k|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (362:9): [True: 0, False: 869k]
  ------------------
  363|      0|        PK11_EnterSlotMonitor(slot);
  364|   869k|    if (PK11_GETTAB(slot)->C_OpenSession(slot->slotID, CKF_SERIAL_SESSION,
  ------------------
  |  |  102|   869k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
                  if (PK11_GETTAB(slot)->C_OpenSession(slot->slotID, CKF_SERIAL_SESSION,
  ------------------
  |  |  303|   869k|#define CKF_SERIAL_SESSION 0x00000004UL /* no parallel */
  ------------------
  |  Branch (364:9): [True: 0, False: 869k]
  ------------------
  365|   869k|                                         slot, pk11_notify, &session) != CKR_OK) {
  ------------------
  |  | 1388|   869k|#define CKR_OK 0x00000000UL
  ------------------
  366|      0|        *owner = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  367|      0|        session = slot->session;
  368|      0|    }
  369|   869k|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (369:9): [True: 0, False: 869k]
  ------------------
  370|      0|        PK11_ExitSlotMonitor(slot);
  371|       |
  372|   869k|    return session;
  373|   869k|}
pk11_CloseSession:
  377|   869k|{
  378|   869k|    if (!owner)
  ------------------
  |  Branch (378:9): [True: 8, False: 869k]
  ------------------
  379|      8|        return;
  380|   869k|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (380:9): [True: 0, False: 869k]
  ------------------
  381|      0|        PK11_EnterSlotMonitor(slot);
  382|   869k|    (void)PK11_GETTAB(slot)->C_CloseSession(session);
  ------------------
  |  |  102|   869k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  383|   869k|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (383:9): [True: 0, False: 869k]
  ------------------
  384|      0|        PK11_ExitSlotMonitor(slot);
  385|   869k|}
PK11_CreateNewObject:
  391|  6.77k|{
  392|  6.77k|    CK_SESSION_HANDLE rwsession;
  393|  6.77k|    CK_RV crv;
  394|  6.77k|    SECStatus rv = SECSuccess;
  395|       |
  396|  6.77k|    rwsession = session;
  397|  6.77k|    if (token) {
  ------------------
  |  Branch (397:9): [True: 0, False: 6.77k]
  ------------------
  398|      0|        rwsession = PK11_GetRWSession(slot);
  399|  6.77k|    } else if (rwsession == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  6.77k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (399:16): [True: 3.11k, False: 3.65k]
  ------------------
  400|  3.11k|        rwsession = slot->session;
  401|  3.11k|        if (rwsession != CK_INVALID_HANDLE)
  ------------------
  |  |   78|  3.11k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (401:13): [True: 3.11k, False: 0]
  ------------------
  402|  3.11k|            PK11_EnterSlotMonitor(slot);
  403|  3.11k|    }
  404|  6.77k|    if (rwsession == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  6.77k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (404:9): [True: 0, False: 6.77k]
  ------------------
  405|      0|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  406|      0|        return SECFailure;
  407|      0|    }
  408|  6.77k|    crv = PK11_GETTAB(slot)->C_CreateObject(rwsession,
  ------------------
  |  |  102|  6.77k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  409|  6.77k|                                            /* cast away const :-( */ (CK_ATTRIBUTE_PTR)theTemplate,
  410|  6.77k|                                            count, objectID);
  411|  6.77k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  6.77k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (411:9): [True: 0, False: 6.77k]
  ------------------
  412|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  413|      0|        rv = SECFailure;
  414|      0|    }
  415|  6.77k|    if (token) {
  ------------------
  |  Branch (415:9): [True: 0, False: 6.77k]
  ------------------
  416|      0|        PK11_RestoreROSession(slot, rwsession);
  417|  6.77k|    } else if (session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  6.77k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (417:16): [True: 3.11k, False: 3.65k]
  ------------------
  418|  3.11k|        PK11_ExitSlotMonitor(slot);
  419|  3.11k|    }
  420|       |
  421|  6.77k|    return rv;
  422|  6.77k|}
pk11_OpFlagsToAttributes:
  427|   928k|{
  428|       |
  429|   928k|    const static CK_ATTRIBUTE_TYPE attrTypes[12] = {
  430|   928k|        CKA_ENCRYPT, CKA_DECRYPT, 0 /* DIGEST */, CKA_SIGN,
  ------------------
  |  |  547|   928k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
                      CKA_ENCRYPT, CKA_DECRYPT, 0 /* DIGEST */, CKA_SIGN,
  ------------------
  |  |  548|   928k|#define CKA_DECRYPT 0x00000105UL
  ------------------
                      CKA_ENCRYPT, CKA_DECRYPT, 0 /* DIGEST */, CKA_SIGN,
  ------------------
  |  |  551|   928k|#define CKA_SIGN 0x00000108UL
  ------------------
  431|   928k|        CKA_SIGN_RECOVER, CKA_VERIFY, CKA_VERIFY_RECOVER, 0 /* GEN */,
  ------------------
  |  |  552|   928k|#define CKA_SIGN_RECOVER 0x00000109UL
  ------------------
                      CKA_SIGN_RECOVER, CKA_VERIFY, CKA_VERIFY_RECOVER, 0 /* GEN */,
  ------------------
  |  |  553|   928k|#define CKA_VERIFY 0x0000010AUL
  ------------------
                      CKA_SIGN_RECOVER, CKA_VERIFY, CKA_VERIFY_RECOVER, 0 /* GEN */,
  ------------------
  |  |  554|   928k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
  432|   928k|        0 /* GEN PAIR */, CKA_WRAP, CKA_UNWRAP, CKA_DERIVE
  ------------------
  |  |  549|   928k|#define CKA_WRAP 0x00000106UL
  ------------------
                      0 /* GEN PAIR */, CKA_WRAP, CKA_UNWRAP, CKA_DERIVE
  ------------------
  |  |  550|   928k|#define CKA_UNWRAP 0x00000107UL
  ------------------
                      0 /* GEN PAIR */, CKA_WRAP, CKA_UNWRAP, CKA_DERIVE
  ------------------
  |  |  555|   928k|#define CKA_DERIVE 0x0000010CUL
  ------------------
  433|   928k|    };
  434|       |
  435|   928k|    const CK_ATTRIBUTE_TYPE *pType = attrTypes;
  436|   928k|    CK_ATTRIBUTE *attr = attrs;
  437|   928k|    CK_FLAGS test = CKF_ENCRYPT;
  ------------------
  |  | 1353|   928k|#define CKF_ENCRYPT 0x00000100UL
  ------------------
  438|       |
  439|   928k|    PR_ASSERT(!(flags & ~CKF_KEY_OPERATION_FLAGS));
  ------------------
  |  |  208|   928k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 928k, False: 0]
  |  |  ------------------
  ------------------
  440|   928k|    flags &= CKF_KEY_OPERATION_FLAGS;
  ------------------
  |  |  203|   928k|#define CKF_KEY_OPERATION_FLAGS 0x000e7b00UL
  ------------------
  441|       |
  442|  6.45M|    for (; flags && test <= CKF_DERIVE; test <<= 1, ++pType) {
  ------------------
  |  | 1364|  5.52M|#define CKF_DERIVE 0x00080000UL
  ------------------
  |  Branch (442:12): [True: 5.52M, False: 928k]
  |  Branch (442:21): [True: 5.52M, False: 0]
  ------------------
  443|  5.52M|        if (test & flags) {
  ------------------
  |  Branch (443:13): [True: 1.85M, False: 3.67M]
  ------------------
  444|  1.85M|            flags ^= test;
  445|  1.85M|            PR_ASSERT(*pType);
  ------------------
  |  |  208|  1.85M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1.85M, False: 0]
  |  |  ------------------
  ------------------
  446|  1.85M|            PK11_SETATTRS(attr, *pType, ckTrue, sizeof *ckTrue);
  ------------------
  |  |  104|  1.85M|    (x)->type = (id);              \
  |  |  105|  1.85M|    (x)->pValue = (v);             \
  |  |  106|  1.85M|    (x)->ulValueLen = (l);
  ------------------
  447|  1.85M|            ++attr;
  448|  1.85M|        }
  449|  5.52M|    }
  450|   928k|    return (attr - attrs);
  451|   928k|}
pk11_BadAttrFlags:
  459|   175k|{
  460|   175k|    PK11AttrFlags trueFlags = attrFlags & 0x55555555;
  461|   175k|    PK11AttrFlags falseFlags = (attrFlags >> 1) & 0x55555555;
  462|   175k|    return ((trueFlags & falseFlags) != 0);
  463|   175k|}
pk11_AttrFlagsToAttributes:
  472|   111k|{
  473|   111k|    const static CK_ATTRIBUTE_TYPE attrTypes[5] = {
  474|   111k|        CKA_TOKEN, CKA_PRIVATE, CKA_MODIFIABLE, CKA_SENSITIVE,
  ------------------
  |  |  512|   111k|#define CKA_TOKEN 0x00000001UL
  ------------------
                      CKA_TOKEN, CKA_PRIVATE, CKA_MODIFIABLE, CKA_SENSITIVE,
  ------------------
  |  |  513|   111k|#define CKA_PRIVATE 0x00000002UL
  ------------------
                      CKA_TOKEN, CKA_PRIVATE, CKA_MODIFIABLE, CKA_SENSITIVE,
  ------------------
  |  |  593|   111k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
                      CKA_TOKEN, CKA_PRIVATE, CKA_MODIFIABLE, CKA_SENSITIVE,
  ------------------
  |  |  546|   111k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  475|   111k|        CKA_EXTRACTABLE
  ------------------
  |  |  585|   111k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  476|   111k|    };
  477|       |
  478|   111k|    const CK_ATTRIBUTE_TYPE *pType = attrTypes;
  479|   111k|    CK_ATTRIBUTE *attr = attrs;
  480|   111k|    PK11AttrFlags test = PK11_ATTR_TOKEN;
  ------------------
  |  |  194|   111k|#define PK11_ATTR_TOKEN 0x00000001L
  ------------------
  481|       |
  482|   111k|    PR_ASSERT(!pk11_BadAttrFlags(attrFlags));
  ------------------
  |  |  208|   111k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 111k, False: 0]
  |  |  ------------------
  ------------------
  483|       |
  484|       |    /* we test two related bitflags in each iteration */
  485|   348k|    for (; attrFlags && test <= PK11_ATTR_EXTRACTABLE; test <<= 2, ++pType) {
  ------------------
  |  |  278|   237k|#define PK11_ATTR_EXTRACTABLE 0x00000100L
  ------------------
  |  Branch (485:12): [True: 237k, False: 111k]
  |  Branch (485:25): [True: 237k, False: 0]
  ------------------
  486|   237k|        if (test & attrFlags) {
  ------------------
  |  Branch (486:13): [True: 44, False: 237k]
  ------------------
  487|     44|            attrFlags ^= test;
  488|     44|            PK11_SETATTRS(attr, *pType, ckTrue, sizeof *ckTrue);
  ------------------
  |  |  104|     44|    (x)->type = (id);              \
  |  |  105|     44|    (x)->pValue = (v);             \
  |  |  106|     44|    (x)->ulValueLen = (l);
  ------------------
  489|     44|            ++attr;
  490|   237k|        } else if ((test << 1) & attrFlags) {
  ------------------
  |  Branch (490:20): [True: 189k, False: 47.4k]
  ------------------
  491|   189k|            attrFlags ^= (test << 1);
  492|   189k|            PK11_SETATTRS(attr, *pType, ckFalse, sizeof *ckFalse);
  ------------------
  |  |  104|   189k|    (x)->type = (id);              \
  |  |  105|   189k|    (x)->pValue = (v);             \
  |  |  106|   189k|    (x)->ulValueLen = (l);
  ------------------
  493|   189k|            ++attr;
  494|   189k|        }
  495|   237k|    }
  496|   111k|    return (attr - attrs);
  497|   111k|}
PK11_SignatureLen:
  550|  47.3k|{
  551|  47.3k|    int val;
  552|  47.3k|    SECItem attributeItem = { siBuffer, NULL, 0 };
  553|  47.3k|    SECStatus rv;
  554|  47.3k|    int length;
  555|       |
  556|  47.3k|    switch (key->keyType) {
  557|  35.5k|        case rsaKey:
  ------------------
  |  Branch (557:9): [True: 35.5k, False: 11.7k]
  ------------------
  558|  35.5k|        case rsaPssKey:
  ------------------
  |  Branch (558:9): [True: 0, False: 47.3k]
  ------------------
  559|  35.5k|            val = PK11_GetPrivateModulusLen(key);
  560|  35.5k|            if (val == -1) {
  ------------------
  |  Branch (560:17): [True: 0, False: 35.5k]
  ------------------
  561|      0|                return pk11_backupGetSignLength(key);
  562|      0|            }
  563|  35.5k|            return (unsigned long)val;
  564|       |
  565|      0|        case fortezzaKey:
  ------------------
  |  Branch (565:9): [True: 0, False: 47.3k]
  ------------------
  566|      0|            return 40;
  567|       |
  568|      0|        case dsaKey:
  ------------------
  |  Branch (568:9): [True: 0, False: 47.3k]
  ------------------
  569|      0|            rv = PK11_ReadAttribute(key->pkcs11Slot, key->pkcs11ID, CKA_SUBPRIME,
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
  570|      0|                                    NULL, &attributeItem);
  571|      0|            if (rv == SECSuccess) {
  ------------------
  |  Branch (571:17): [True: 0, False: 0]
  ------------------
  572|      0|                length = attributeItem.len;
  573|      0|                if ((length > 0) && attributeItem.data[0] == 0) {
  ------------------
  |  Branch (573:21): [True: 0, False: 0]
  |  Branch (573:37): [True: 0, False: 0]
  ------------------
  574|      0|                    length--;
  575|      0|                }
  576|      0|                PORT_Free(attributeItem.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  577|      0|                return length * 2;
  578|      0|            }
  579|      0|            return pk11_backupGetSignLength(key);
  580|  11.7k|        case ecKey:
  ------------------
  |  Branch (580:9): [True: 11.7k, False: 35.5k]
  ------------------
  581|  11.7k|        case edKey:
  ------------------
  |  Branch (581:9): [True: 0, False: 47.3k]
  ------------------
  582|  11.7k|            rv = PK11_ReadAttribute(key->pkcs11Slot, key->pkcs11ID, CKA_EC_PARAMS,
  ------------------
  |  |  602|  11.7k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
  583|  11.7k|                                    NULL, &attributeItem);
  584|  11.7k|            if (rv == SECSuccess) {
  ------------------
  |  Branch (584:17): [True: 11.7k, False: 0]
  ------------------
  585|  11.7k|                length = SECKEY_ECParamsToBasePointOrderLen(&attributeItem);
  586|  11.7k|                PORT_Free(attributeItem.data);
  ------------------
  |  |   60|  11.7k|#define PORT_Free PORT_Free_Util
  ------------------
  587|  11.7k|                if (length != 0) {
  ------------------
  |  Branch (587:21): [True: 11.7k, False: 0]
  ------------------
  588|  11.7k|                    length = ((length + 7) / 8) * 2;
  589|  11.7k|                    return length;
  590|  11.7k|                }
  591|  11.7k|            }
  592|      0|            return pk11_backupGetSignLength(key);
  593|      0|        default:
  ------------------
  |  Branch (593:9): [True: 0, False: 47.3k]
  ------------------
  594|      0|            break;
  595|  47.3k|    }
  596|      0|    PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  597|      0|    return 0;
  598|  47.3k|}
PK11_CopyKey:
  605|      2|{
  606|      2|    CK_OBJECT_HANDLE destObject;
  607|      2|    CK_RV crv;
  608|       |
  609|      2|    PK11_EnterSlotMonitor(slot);
  610|      2|    crv = PK11_GETTAB(slot)->C_CopyObject(slot->session, srcObject, NULL, 0,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  611|      2|                                          &destObject);
  612|      2|    PK11_ExitSlotMonitor(slot);
  613|      2|    if (crv == CKR_OK)
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (613:9): [True: 2, False: 0]
  ------------------
  614|      2|        return destObject;
  615|      0|    PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  616|      0|    return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  617|      2|}
pk11_FindAttrInTemplate:
  622|  3.83M|{
  623|  10.9M|    for (; numAttrs > 0; ++attr, --numAttrs) {
  ------------------
  |  Branch (623:12): [True: 7.14M, False: 3.83M]
  ------------------
  624|  7.14M|        if (attr->type == target)
  ------------------
  |  Branch (624:13): [True: 0, False: 7.14M]
  ------------------
  625|      0|            return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  626|  7.14M|    }
  627|  3.83M|    return PR_FALSE;
  ------------------
  |  |  438|  3.83M|#define PR_FALSE 0
  ------------------
  628|  3.83M|}
PK11_VerifyRecover:
  637|  2.95k|{
  638|  2.95k|    PK11SlotInfo *slot = key->pkcs11Slot;
  639|  2.95k|    CK_OBJECT_HANDLE id = key->pkcs11ID;
  640|  2.95k|    CK_MECHANISM mech = { 0, NULL, 0 };
  641|  2.95k|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|  2.95k|#define PR_TRUE 1
  ------------------
  642|  2.95k|    CK_SESSION_HANDLE session;
  643|  2.95k|    CK_ULONG len;
  644|  2.95k|    CK_RV crv;
  645|       |
  646|  2.95k|    mech.mechanism = PK11_MapSignKeyType(key->keyType);
  647|       |
  648|  2.95k|    if (slot == NULL) {
  ------------------
  |  Branch (648:9): [True: 0, False: 2.95k]
  ------------------
  649|      0|        slot = PK11_GetBestSlotWithAttributes(mech.mechanism,
  650|      0|                                              CKF_VERIFY_RECOVER, 0, wincx);
  ------------------
  |  | 1359|      0|#define CKF_VERIFY_RECOVER 0x00004000UL
  ------------------
  651|      0|        if (slot == NULL) {
  ------------------
  |  Branch (651:13): [True: 0, False: 0]
  ------------------
  652|      0|            PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  653|      0|            return SECFailure;
  654|      0|        }
  655|      0|        id = PK11_ImportPublicKey(slot, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  656|  2.95k|    } else {
  657|  2.95k|        PK11_ReferenceSlot(slot);
  658|  2.95k|    }
  659|       |
  660|  2.95k|    if (id == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  2.95k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (660:9): [True: 0, False: 2.95k]
  ------------------
  661|      0|        PK11_FreeSlot(slot);
  662|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  663|      0|        return SECFailure;
  664|      0|    }
  665|       |
  666|  2.95k|    session = pk11_GetNewSession(slot, &owner);
  667|  2.95k|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (667:9): [True: 0, False: 2.95k]
  |  Branch (667:19): [True: 0, False: 2.95k]
  ------------------
  668|      0|        PK11_EnterSlotMonitor(slot);
  669|  2.95k|    crv = PK11_GETTAB(slot)->C_VerifyRecoverInit(session, &mech, id);
  ------------------
  |  |  102|  2.95k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  670|  2.95k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (670:9): [True: 0, False: 2.95k]
  ------------------
  671|      0|        if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (671:13): [True: 0, False: 0]
  |  Branch (671:23): [True: 0, False: 0]
  ------------------
  672|      0|            PK11_ExitSlotMonitor(slot);
  673|      0|        pk11_CloseSession(slot, session, owner);
  674|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  675|      0|        PK11_FreeSlot(slot);
  676|      0|        return SECFailure;
  677|      0|    }
  678|  2.95k|    len = dsig->len;
  679|  2.95k|    crv = PK11_GETTAB(slot)->C_VerifyRecover(session, sig->data,
  ------------------
  |  |  102|  2.95k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  680|  2.95k|                                             sig->len, dsig->data, &len);
  681|  2.95k|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (681:9): [True: 0, False: 2.95k]
  |  Branch (681:19): [True: 0, False: 2.95k]
  ------------------
  682|      0|        PK11_ExitSlotMonitor(slot);
  683|  2.95k|    pk11_CloseSession(slot, session, owner);
  684|  2.95k|    dsig->len = len;
  685|  2.95k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (685:9): [True: 2.94k, False: 4]
  ------------------
  686|  2.94k|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|  2.94k|#define PORT_SetError PORT_SetError_Util
  ------------------
  687|  2.94k|        PK11_FreeSlot(slot);
  688|  2.94k|        return SECFailure;
  689|  2.94k|    }
  690|      4|    PK11_FreeSlot(slot);
  691|      4|    return SECSuccess;
  692|  2.95k|}
PK11_VerifyWithMechanism:
  712|     60|{
  713|     60|    PK11SlotInfo *slot = key->pkcs11Slot;
  714|     60|    CK_OBJECT_HANDLE id = key->pkcs11ID;
  715|     60|    CK_MECHANISM mech = { 0, NULL, 0 };
  716|     60|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|     60|#define PR_TRUE 1
  ------------------
  717|     60|    CK_SESSION_HANDLE session;
  718|     60|    CK_RV crv;
  719|       |
  720|     60|    mech.mechanism = mechanism;
  721|     60|    if (param) {
  ------------------
  |  Branch (721:9): [True: 38, False: 22]
  ------------------
  722|     38|        mech.pParameter = param->data;
  723|     38|        mech.ulParameterLen = param->len;
  724|     38|    }
  725|       |
  726|     60|    if (slot == NULL) {
  ------------------
  |  Branch (726:9): [True: 60, False: 0]
  ------------------
  727|     60|        unsigned int length = 0;
  728|     60|        if ((mech.mechanism == CKM_DSA) &&
  ------------------
  |  |  745|     60|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (728:13): [True: 0, False: 60]
  ------------------
  729|       |            /* 129 is 1024 bits translated to bytes and
  730|       |             * padded with an optional '0' to maintain a
  731|       |             * positive sign */
  732|     60|            (key->u.dsa.params.prime.len > 129)) {
  ------------------
  |  Branch (732:13): [True: 0, False: 0]
  ------------------
  733|       |            /* we need to get a slot that not only can do DSA, but can do DSA2
  734|       |             * key lengths */
  735|      0|            length = key->u.dsa.params.prime.len;
  736|      0|            if (key->u.dsa.params.prime.data[0] == 0) {
  ------------------
  |  Branch (736:17): [True: 0, False: 0]
  ------------------
  737|      0|                length--;
  738|      0|            }
  739|       |            /* convert keysize to bits for slot lookup */
  740|      0|            length *= 8;
  741|      0|        }
  742|     60|        slot = PK11_GetBestSlotWithAttributes(mech.mechanism,
  743|     60|                                              CKF_VERIFY, length, wincx);
  ------------------
  |  | 1358|     60|#define CKF_VERIFY 0x00002000
  ------------------
  744|     60|        if (slot == NULL) {
  ------------------
  |  Branch (744:13): [True: 0, False: 60]
  ------------------
  745|      0|            PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  746|      0|            return SECFailure;
  747|      0|        }
  748|     60|        id = PK11_ImportPublicKey(slot, key, PR_FALSE);
  ------------------
  |  |  438|     60|#define PR_FALSE 0
  ------------------
  749|       |
  750|     60|    } else {
  751|      0|        PK11_ReferenceSlot(slot);
  752|      0|    }
  753|       |
  754|     60|    if (id == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|     60|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (754:9): [True: 0, False: 60]
  ------------------
  755|      0|        PK11_FreeSlot(slot);
  756|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  757|      0|        return SECFailure;
  758|      0|    }
  759|       |
  760|     60|    session = pk11_GetNewSession(slot, &owner);
  761|     60|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (761:9): [True: 0, False: 60]
  |  Branch (761:19): [True: 0, False: 60]
  ------------------
  762|      0|        PK11_EnterSlotMonitor(slot);
  763|     60|    crv = PK11_GETTAB(slot)->C_VerifyInit(session, &mech, id);
  ------------------
  |  |  102|     60|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  764|     60|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (764:9): [True: 0, False: 60]
  ------------------
  765|      0|        if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (765:13): [True: 0, False: 0]
  |  Branch (765:23): [True: 0, False: 0]
  ------------------
  766|      0|            PK11_ExitSlotMonitor(slot);
  767|      0|        pk11_CloseSession(slot, session, owner);
  768|      0|        PK11_FreeSlot(slot);
  769|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  770|      0|        return SECFailure;
  771|      0|    }
  772|     60|    crv = PK11_GETTAB(slot)->C_Verify(session, hash->data,
  ------------------
  |  |  102|     60|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  773|     60|                                      hash->len, sig->data, sig->len);
  774|     60|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (774:9): [True: 0, False: 60]
  |  Branch (774:19): [True: 0, False: 60]
  ------------------
  775|      0|        PK11_ExitSlotMonitor(slot);
  776|     60|    pk11_CloseSession(slot, session, owner);
  777|     60|    PK11_FreeSlot(slot);
  778|     60|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (778:9): [True: 60, False: 0]
  ------------------
  779|     60|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|     60|#define PORT_SetError PORT_SetError_Util
  ------------------
  780|     60|        return SECFailure;
  781|     60|    }
  782|      0|    return SECSuccess;
  783|     60|}
PK11_Sign:
  790|  38.3k|{
  791|  38.3k|    CK_MECHANISM_TYPE mech = PK11_MapSignKeyType(key->keyType);
  792|  38.3k|    return PK11_SignWithMechanism(key, mech, NULL, sig, hash);
  793|  38.3k|}
PK11_SignWithMechanism:
  801|  47.3k|{
  802|  47.3k|    PK11SlotInfo *slot = key->pkcs11Slot;
  803|  47.3k|    CK_MECHANISM mech = { 0, NULL, 0 };
  804|  47.3k|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
  805|  47.3k|    CK_SESSION_HANDLE session;
  806|  47.3k|    PRBool haslock = PR_FALSE;
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
  807|  47.3k|    CK_ULONG len;
  808|  47.3k|    CK_RV crv;
  809|       |
  810|  47.3k|    mech.mechanism = mechanism;
  811|  47.3k|    if (param) {
  ------------------
  |  Branch (811:9): [True: 4.81k, False: 42.4k]
  ------------------
  812|  4.81k|        mech.pParameter = param->data;
  813|  4.81k|        mech.ulParameterLen = param->len;
  814|  4.81k|    }
  815|       |
  816|  47.3k|    if (SECKEY_HAS_ATTRIBUTE_SET(key, CKA_PRIVATE)) {
  ------------------
  |  |  224|  47.3k|    (0 != (key->staticflags & SECKEY_Attributes_Cached)) ? (0 != (key->staticflags & SECKEY_##attribute)) : PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)
  |  |  ------------------
  |  |  |  |  212|  47.3k|#define SECKEY_Attributes_Cached 0x1 /* bit 0 states \
  |  |  ------------------
  |  |                   (0 != (key->staticflags & SECKEY_Attributes_Cached)) ? (0 != (key->staticflags & SECKEY_##attribute)) : PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)
  |  |  ------------------
  |  |  |  |  438|      0|#define PR_FALSE 0
  |  |  ------------------
  |  |  |  Branch (224:5): [True: 47.3k, False: 0]
  |  |  |  Branch (224:5): [True: 0, False: 47.3k]
  |  |  ------------------
  ------------------
  817|      0|        PK11_HandlePasswordCheck(slot, key->wincx);
  818|      0|    }
  819|       |
  820|  47.3k|    session = pk11_GetNewSession(slot, &owner);
  821|  47.3k|    haslock = (!owner || !(slot->isThreadSafe));
  ------------------
  |  Branch (821:16): [True: 0, False: 47.3k]
  |  Branch (821:26): [True: 0, False: 47.3k]
  ------------------
  822|  47.3k|    if (haslock)
  ------------------
  |  Branch (822:9): [True: 0, False: 47.3k]
  ------------------
  823|      0|        PK11_EnterSlotMonitor(slot);
  824|  47.3k|    crv = PK11_GETTAB(slot)->C_SignInit(session, &mech, key->pkcs11ID);
  ------------------
  |  |  102|  47.3k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  825|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (825:9): [True: 0, False: 47.3k]
  ------------------
  826|      0|        if (haslock)
  ------------------
  |  Branch (826:13): [True: 0, False: 0]
  ------------------
  827|      0|            PK11_ExitSlotMonitor(slot);
  828|      0|        pk11_CloseSession(slot, session, owner);
  829|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  830|      0|        return SECFailure;
  831|      0|    }
  832|       |
  833|       |    /* PKCS11 2.20 says if CKA_ALWAYS_AUTHENTICATE then
  834|       |     * do C_Login with CKU_CONTEXT_SPECIFIC
  835|       |     * between C_SignInit and C_Sign */
  836|  47.3k|    if (SECKEY_HAS_ATTRIBUTE_SET_LOCK(key, CKA_ALWAYS_AUTHENTICATE, haslock)) {
  ------------------
  |  |  227|  47.3k|    (0 != (key->staticflags & SECKEY_Attributes_Cached)) ? (0 != (key->staticflags & SECKEY_##attribute)) : pk11_HasAttributeSet_Lock(key->pkcs11Slot, key->pkcs11ID, attribute, haslock)
  |  |  ------------------
  |  |  |  |  212|  47.3k|#define SECKEY_Attributes_Cached 0x1 /* bit 0 states \
  |  |  ------------------
  |  |  |  Branch (227:5): [True: 47.3k, False: 0]
  |  |  |  Branch (227:5): [True: 0, False: 47.3k]
  |  |  ------------------
  ------------------
  837|      0|        PK11_DoPassword(slot, session, PR_FALSE, key->wincx, haslock, PR_TRUE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
                      PK11_DoPassword(slot, session, PR_FALSE, key->wincx, haslock, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  838|      0|    }
  839|       |
  840|  47.3k|    len = sig->len;
  841|  47.3k|    crv = PK11_GETTAB(slot)->C_Sign(session, hash->data,
  ------------------
  |  |  102|  47.3k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  842|  47.3k|                                    hash->len, sig->data, &len);
  843|  47.3k|    if (haslock)
  ------------------
  |  Branch (843:9): [True: 0, False: 47.3k]
  ------------------
  844|      0|        PK11_ExitSlotMonitor(slot);
  845|  47.3k|    pk11_CloseSession(slot, session, owner);
  846|  47.3k|    sig->len = len;
  847|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (847:9): [True: 0, False: 47.3k]
  ------------------
  848|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  849|      0|        return SECFailure;
  850|      0|    }
  851|  47.3k|    return SECSuccess;
  852|  47.3k|}
PK11_UnlinkGenericObject:
 1567|  2.44k|{
 1568|  2.44k|    if (object->prev != NULL) {
  ------------------
  |  Branch (1568:9): [True: 0, False: 2.44k]
  ------------------
 1569|      0|        object->prev->next = object->next;
 1570|      0|    }
 1571|  2.44k|    if (object->next != NULL) {
  ------------------
  |  Branch (1571:9): [True: 0, False: 2.44k]
  ------------------
 1572|      0|        object->next->prev = object->prev;
 1573|      0|    }
 1574|       |
 1575|  2.44k|    object->next = NULL;
 1576|  2.44k|    object->prev = NULL;
 1577|  2.44k|    return SECSuccess;
 1578|  2.44k|}
PK11_DestroyGenericObject:
 1587|  2.44k|{
 1588|  2.44k|    if (object == NULL) {
  ------------------
  |  Branch (1588:9): [True: 0, False: 2.44k]
  ------------------
 1589|      0|        return SECSuccess;
 1590|      0|    }
 1591|       |
 1592|  2.44k|    PK11_UnlinkGenericObject(object);
 1593|  2.44k|    if (object->slot) {
  ------------------
  |  Branch (1593:9): [True: 2.44k, False: 0]
  ------------------
 1594|  2.44k|        if (object->owner) {
  ------------------
  |  Branch (1594:13): [True: 0, False: 2.44k]
  ------------------
 1595|      0|            PK11_DestroyObject(object->slot, object->objectID);
 1596|      0|        }
 1597|  2.44k|        PK11_FreeSlot(object->slot);
 1598|  2.44k|    }
 1599|  2.44k|    PORT_Free(object);
  ------------------
  |  |   60|  2.44k|#define PORT_Free PORT_Free_Util
  ------------------
 1600|  2.44k|    return SECSuccess;
 1601|  2.44k|}
pk11_CreateGenericObjectHelper:
 1641|  2.44k|{
 1642|  2.44k|    CK_OBJECT_HANDLE objectID;
 1643|  2.44k|    PK11GenericObject *obj;
 1644|  2.44k|    CK_RV crv;
 1645|       |
 1646|  2.44k|    PK11_EnterSlotMonitor(slot);
 1647|  2.44k|    crv = PK11_CreateNewObject(slot, slot->session, pTemplate, count,
 1648|  2.44k|                               token, &objectID);
 1649|  2.44k|    PK11_ExitSlotMonitor(slot);
 1650|  2.44k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  2.44k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1650:9): [True: 0, False: 2.44k]
  ------------------
 1651|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1652|      0|        return NULL;
 1653|      0|    }
 1654|       |
 1655|  2.44k|    obj = PORT_New(PK11GenericObject);
  ------------------
  |  |  151|  2.44k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|  2.44k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 1656|  2.44k|    if (!obj) {
  ------------------
  |  Branch (1656:9): [True: 0, False: 2.44k]
  ------------------
 1657|       |        /* error set by PORT_New */
 1658|      0|        return NULL;
 1659|      0|    }
 1660|       |
 1661|       |    /* initialize it */
 1662|  2.44k|    obj->slot = PK11_ReferenceSlot(slot);
 1663|  2.44k|    obj->objectID = objectID;
 1664|  2.44k|    obj->owner = owner;
 1665|  2.44k|    obj->next = NULL;
 1666|  2.44k|    obj->prev = NULL;
 1667|  2.44k|    return obj;
 1668|  2.44k|}
PK11_CreateGenericObject:
 1681|  2.44k|{
 1682|  2.44k|    return pk11_CreateGenericObjectHelper(slot, pTemplate, count, token,
 1683|  2.44k|                                          PR_FALSE);
  ------------------
  |  |  438|  2.44k|#define PR_FALSE 0
  ------------------
 1684|  2.44k|}
PK11_GetObjectHandle:
 1701|  2.44k|{
 1702|  2.44k|    CK_OBJECT_HANDLE handle = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  2.44k|#define CK_INVALID_HANDLE 0
  ------------------
 1703|  2.44k|    PK11SlotInfo *slot = NULL;
 1704|       |
 1705|  2.44k|    switch (objType) {
 1706|  2.44k|        case PK11_TypeGeneric:
  ------------------
  |  Branch (1706:9): [True: 2.44k, False: 0]
  ------------------
 1707|  2.44k|            slot = ((PK11GenericObject *)objSpec)->slot;
 1708|  2.44k|            handle = ((PK11GenericObject *)objSpec)->objectID;
 1709|  2.44k|            break;
 1710|      0|        case PK11_TypePrivKey:
  ------------------
  |  Branch (1710:9): [True: 0, False: 2.44k]
  ------------------
 1711|      0|            slot = ((SECKEYPrivateKey *)objSpec)->pkcs11Slot;
 1712|      0|            handle = ((SECKEYPrivateKey *)objSpec)->pkcs11ID;
 1713|      0|            break;
 1714|      0|        case PK11_TypePubKey:
  ------------------
  |  Branch (1714:9): [True: 0, False: 2.44k]
  ------------------
 1715|      0|            slot = ((SECKEYPublicKey *)objSpec)->pkcs11Slot;
 1716|      0|            handle = ((SECKEYPublicKey *)objSpec)->pkcs11ID;
 1717|      0|            break;
 1718|      0|        case PK11_TypeSymKey:
  ------------------
  |  Branch (1718:9): [True: 0, False: 2.44k]
  ------------------
 1719|      0|            slot = ((PK11SymKey *)objSpec)->slot;
 1720|      0|            handle = ((PK11SymKey *)objSpec)->objectID;
 1721|      0|            break;
 1722|      0|        case PK11_TypeCert:
  ------------------
  |  Branch (1722:9): [True: 0, False: 2.44k]
  ------------------
 1723|      0|            handle = PK11_FindObjectForCert((CERTCertificate *)objSpec, NULL,
 1724|      0|                                            &slot);
 1725|      0|            break;
 1726|      0|        default:
  ------------------
  |  Branch (1726:9): [True: 0, False: 2.44k]
  ------------------
 1727|      0|            PORT_SetError(SEC_ERROR_UNKNOWN_OBJECT_TYPE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1728|      0|            break;
 1729|  2.44k|    }
 1730|  2.44k|    if (slotp) {
  ------------------
  |  Branch (1730:9): [True: 0, False: 2.44k]
  ------------------
 1731|      0|        *slotp = slot;
 1732|      0|    }
 1733|       |    /* paranoia. If the object doesn't have a slot, then it's handle isn't
 1734|       |     * valid either */
 1735|  2.44k|    if (slot == NULL) {
  ------------------
  |  Branch (1735:9): [True: 0, False: 2.44k]
  ------------------
 1736|      0|        handle = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 1737|      0|    }
 1738|  2.44k|    return handle;
 1739|  2.44k|}
pk11_FindObjectByTemplate:
 1866|      2|{
 1867|      2|    CK_OBJECT_HANDLE object;
 1868|      2|    CK_RV crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      2|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 1869|      2|    CK_ULONG objectCount;
 1870|       |
 1871|       |    /*
 1872|       |     * issue the find
 1873|       |     */
 1874|      2|    PK11_EnterSlotMonitor(slot);
 1875|      2|    if (slot->session != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1875:9): [True: 2, False: 0]
  ------------------
 1876|      2|        crv = PK11_GETTAB(slot)->C_FindObjectsInit(slot->session,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1877|      2|                                                   theTemplate, tsize);
 1878|      2|    }
 1879|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1879:9): [True: 0, False: 2]
  ------------------
 1880|      0|        PK11_ExitSlotMonitor(slot);
 1881|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1882|      0|        return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 1883|      0|    }
 1884|       |
 1885|      2|    crv = PK11_GETTAB(slot)->C_FindObjects(slot->session, &object, 1, &objectCount);
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1886|      2|    PK11_GETTAB(slot)->C_FindObjectsFinal(slot->session);
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1887|      2|    PK11_ExitSlotMonitor(slot);
 1888|      2|    if ((crv != CKR_OK) || (objectCount < 1)) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1888:9): [True: 0, False: 2]
  |  Branch (1888:28): [True: 2, False: 0]
  ------------------
 1889|       |        /* shouldn't use SSL_ERROR... here */
 1890|      2|        PORT_SetError(crv != CKR_OK ? PK11_MapError(crv) : SSL_ERROR_NO_CERTIFICATE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(crv != CKR_OK ? PK11_MapError(crv) : SSL_ERROR_NO_CERTIFICATE);
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1890:23): [True: 0, False: 2]
  ------------------
 1891|      2|        return CK_INVALID_HANDLE;
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
 1892|      2|    }
 1893|       |
 1894|       |    /* blow up if the PKCS #11 module returns us and invalid object handle */
 1895|      0|    PORT_Assert(object != CK_INVALID_HANDLE);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1896|      0|    return object;
 1897|      2|}
pk11_FindObjectsByTemplate:
 1905|      2|{
 1906|      2|    CK_OBJECT_HANDLE *objID = NULL;
 1907|      2|    CK_ULONG returned_count = 0;
 1908|      2|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1909|      2|    CK_SESSION_HANDLE session;
 1910|      2|    PRBool haslock = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1911|      2|    CK_RV crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      2|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 1912|       |
 1913|      2|    session = pk11_GetNewSession(slot, &owner);
 1914|      2|    haslock = (!owner || !(slot->isThreadSafe));
  ------------------
  |  Branch (1914:16): [True: 0, False: 2]
  |  Branch (1914:26): [True: 0, False: 2]
  ------------------
 1915|      2|    if (haslock) {
  ------------------
  |  Branch (1915:9): [True: 0, False: 2]
  ------------------
 1916|      0|        PK11_EnterSlotMonitor(slot);
 1917|      0|    }
 1918|      2|    if (session != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1918:9): [True: 2, False: 0]
  ------------------
 1919|      2|        crv = PK11_GETTAB(slot)->C_FindObjectsInit(session,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1920|      2|                                                   findTemplate, templCount);
 1921|      2|    }
 1922|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1922:9): [True: 0, False: 2]
  ------------------
 1923|      0|        if (haslock)
  ------------------
  |  Branch (1923:13): [True: 0, False: 0]
  ------------------
 1924|      0|            PK11_ExitSlotMonitor(slot);
 1925|      0|        pk11_CloseSession(slot, session, owner);
 1926|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1927|      0|        *object_count = -1;
 1928|      0|        return NULL;
 1929|      0|    }
 1930|       |
 1931|       |    /*
 1932|       |     * collect all the Matching Objects
 1933|       |     */
 1934|      2|    do {
 1935|      2|        CK_OBJECT_HANDLE *oldObjID = objID;
 1936|       |
 1937|      2|        if (objID == NULL) {
  ------------------
  |  Branch (1937:13): [True: 2, False: 0]
  ------------------
 1938|      2|            objID = (CK_OBJECT_HANDLE *)PORT_Alloc(sizeof(CK_OBJECT_HANDLE) *
  ------------------
  |  |   52|      2|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1939|      2|                                                   (*object_count + PK11_SEARCH_CHUNKSIZE));
  ------------------
  |  |   23|      2|#define PK11_SEARCH_CHUNKSIZE 10
  ------------------
 1940|      2|        } else {
 1941|      0|            objID = (CK_OBJECT_HANDLE *)PORT_Realloc(objID,
  ------------------
  |  |   64|      0|#define PORT_Realloc PORT_Realloc_Util
  ------------------
 1942|      0|                                                     sizeof(CK_OBJECT_HANDLE) * (*object_count + PK11_SEARCH_CHUNKSIZE));
  ------------------
  |  |   23|      0|#define PK11_SEARCH_CHUNKSIZE 10
  ------------------
 1943|      0|        }
 1944|       |
 1945|      2|        if (objID == NULL) {
  ------------------
  |  Branch (1945:13): [True: 0, False: 2]
  ------------------
 1946|      0|            if (oldObjID)
  ------------------
  |  Branch (1946:17): [True: 0, False: 0]
  ------------------
 1947|      0|                PORT_Free(oldObjID);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1948|      0|            break;
 1949|      0|        }
 1950|      2|        crv = PK11_GETTAB(slot)->C_FindObjects(session,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1951|      2|                                               &objID[*object_count], PK11_SEARCH_CHUNKSIZE, &returned_count);
  ------------------
  |  |   23|      2|#define PK11_SEARCH_CHUNKSIZE 10
  ------------------
 1952|      2|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1952:13): [True: 0, False: 2]
  ------------------
 1953|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1954|      0|            PORT_Free(objID);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1955|      0|            objID = NULL;
 1956|      0|            break;
 1957|      0|        }
 1958|      2|        *object_count += returned_count;
 1959|      2|    } while (returned_count == PK11_SEARCH_CHUNKSIZE);
  ------------------
  |  |   23|      2|#define PK11_SEARCH_CHUNKSIZE 10
  ------------------
  |  Branch (1959:14): [True: 0, False: 2]
  ------------------
 1960|       |
 1961|      2|    PK11_GETTAB(slot)->C_FindObjectsFinal(session);
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1962|      2|    if (haslock) {
  ------------------
  |  Branch (1962:9): [True: 0, False: 2]
  ------------------
 1963|      0|        PK11_ExitSlotMonitor(slot);
 1964|      0|    }
 1965|      2|    pk11_CloseSession(slot, session, owner);
 1966|       |
 1967|      2|    if (objID && (*object_count == 0)) {
  ------------------
  |  Branch (1967:9): [True: 2, False: 0]
  |  Branch (1967:18): [True: 2, False: 0]
  ------------------
 1968|      2|        PORT_Free(objID);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 1969|      2|        return NULL;
 1970|      2|    }
 1971|      0|    if (objID == NULL)
  ------------------
  |  Branch (1971:9): [True: 0, False: 0]
  ------------------
 1972|      0|        *object_count = -1;
 1973|      0|    return objID;
 1974|      2|}
pk11_TraverseAllSlots:
 2194|      1|{
 2195|      1|    PK11SlotList *list;
 2196|      1|    PK11SlotListElement *le;
 2197|      1|    SECStatus rv;
 2198|       |
 2199|       |    /* get them all! */
 2200|      1|    list = PK11_GetAllTokens(CKM_INVALID_MECHANISM, PR_FALSE, PR_FALSE, wincx);
  ------------------
  |  |  155|      1|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
                  list = PK11_GetAllTokens(CKM_INVALID_MECHANISM, PR_FALSE, PR_FALSE, wincx);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
                  list = PK11_GetAllTokens(CKM_INVALID_MECHANISM, PR_FALSE, PR_FALSE, wincx);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 2201|      1|    if (list == NULL)
  ------------------
  |  Branch (2201:9): [True: 0, False: 1]
  ------------------
 2202|      0|        return SECFailure;
 2203|       |
 2204|       |    /* look at each slot and authenticate as necessary */
 2205|      3|    for (le = list->head; le; le = le->next) {
  ------------------
  |  Branch (2205:27): [True: 2, False: 1]
  ------------------
 2206|      2|        if (forceLogin) {
  ------------------
  |  Branch (2206:13): [True: 2, False: 0]
  ------------------
 2207|      2|            rv = pk11_AuthenticateUnfriendly(le->slot, PR_FALSE, wincx);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2208|      2|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2208:17): [True: 0, False: 2]
  ------------------
 2209|      0|                continue;
 2210|      0|            }
 2211|      2|        }
 2212|      2|        if (callback) {
  ------------------
  |  Branch (2212:13): [True: 0, False: 2]
  ------------------
 2213|      0|            (*callback)(le->slot, arg);
 2214|      0|        }
 2215|      2|    }
 2216|       |
 2217|      1|    PK11_FreeSlotList(list);
 2218|       |
 2219|      1|    return SECSuccess;
 2220|      1|}

SECMOD_CreateModuleEx:
 1154|      2|{
 1155|      2|    SECMODModule *mod;
 1156|      2|    SECStatus rv;
 1157|      2|    char *slotParams, *ciphers;
 1158|      2|    PRBool printPolicyFeedback = NSSUTIL_ArgHasFlag("flags", "printPolicyFeedback", nss);
 1159|      2|    PRUint32 policyCheckFlags = secmod_parsePolicyCheckFlags(nss);
 1160|       |
 1161|      2|    rv = secmod_parseCryptoPolicy(config, printPolicyFeedback, policyCheckFlags);
 1162|       |
 1163|       |    /* do not load the module if policy parsing fails */
 1164|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1164:9): [True: 0, False: 2]
  ------------------
 1165|      0|        if (printPolicyFeedback) {
  ------------------
  |  Branch (1165:13): [True: 0, False: 0]
  ------------------
 1166|      0|            PR_SetEnv("NSS_POLICY_FAIL=1");
 1167|      0|            fprintf(stderr, "NSS-POLICY-FAIL: policy config parsing failed, not loading module %s\n", moduleName);
 1168|      0|        }
 1169|      0|        return NULL;
 1170|      0|    }
 1171|       |
 1172|      2|    mod = secmod_NewModule();
 1173|      2|    if (mod == NULL)
  ------------------
  |  Branch (1173:9): [True: 0, False: 2]
  ------------------
 1174|      0|        return NULL;
 1175|       |
 1176|      2|    mod->commonName = PORT_ArenaStrdup(mod->arena, moduleName ? moduleName : "");
  ------------------
  |  |   57|      2|#define PORT_ArenaStrdup PORT_ArenaStrdup_Util
  ------------------
  |  Branch (1176:52): [True: 2, False: 0]
  ------------------
 1177|      2|    if (library) {
  ------------------
  |  Branch (1177:9): [True: 0, False: 2]
  ------------------
 1178|      0|        mod->dllName = PORT_ArenaStrdup(mod->arena, library);
  ------------------
  |  |   57|      0|#define PORT_ArenaStrdup PORT_ArenaStrdup_Util
  ------------------
 1179|      0|    }
 1180|       |    /* new field */
 1181|      2|    if (parameters) {
  ------------------
  |  Branch (1181:9): [True: 2, False: 0]
  ------------------
 1182|      2|        mod->libraryParams = PORT_ArenaStrdup(mod->arena, parameters);
  ------------------
  |  |   57|      2|#define PORT_ArenaStrdup PORT_ArenaStrdup_Util
  ------------------
 1183|      2|    }
 1184|       |
 1185|      2|    mod->internal = NSSUTIL_ArgHasFlag("flags", "internal", nss);
 1186|      2|    mod->isFIPS = NSSUTIL_ArgHasFlag("flags", "FIPS", nss);
 1187|       |    /* if the system FIPS mode is enabled, force FIPS to be on */
 1188|      2|    if (SECMOD_GetSystemFIPSEnabled()) {
  ------------------
  |  Branch (1188:9): [True: 0, False: 2]
  ------------------
 1189|      0|        mod->isFIPS = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1190|      0|    }
 1191|      2|    mod->isCritical = NSSUTIL_ArgHasFlag("flags", "critical", nss);
 1192|      2|    slotParams = NSSUTIL_ArgGetParamValue("slotParams", nss);
 1193|      2|    mod->slotInfo = NSSUTIL_ArgParseSlotInfo(mod->arena, slotParams,
 1194|      2|                                             &mod->slotInfoCount);
 1195|      2|    if (slotParams)
  ------------------
  |  Branch (1195:9): [True: 1, False: 1]
  ------------------
 1196|      1|        PORT_Free(slotParams);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
 1197|       |    /* new field */
 1198|      2|    mod->trustOrder = NSSUTIL_ArgReadLong("trustOrder", nss,
 1199|      2|                                          NSSUTIL_DEFAULT_TRUST_ORDER, NULL);
  ------------------
  |  |   49|      2|#define NSSUTIL_DEFAULT_TRUST_ORDER 50
  ------------------
 1200|       |    /* new field */
 1201|      2|    mod->cipherOrder = NSSUTIL_ArgReadLong("cipherOrder", nss,
 1202|      2|                                           NSSUTIL_DEFAULT_CIPHER_ORDER, NULL);
  ------------------
  |  |   48|      2|#define NSSUTIL_DEFAULT_CIPHER_ORDER 0
  ------------------
 1203|       |    /* new field */
 1204|      2|    mod->isModuleDB = NSSUTIL_ArgHasFlag("flags", "moduleDB", nss);
 1205|      2|    mod->moduleDBOnly = NSSUTIL_ArgHasFlag("flags", "moduleDBOnly", nss);
 1206|      2|    if (mod->moduleDBOnly)
  ------------------
  |  Branch (1206:9): [True: 1, False: 1]
  ------------------
 1207|      1|        mod->isModuleDB = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1208|       |
 1209|       |    /* we need more bits, but we also want to preserve binary compatibility
 1210|       |     * so we overload the isModuleDB PRBool with additional flags.
 1211|       |     * These flags are only valid if mod->isModuleDB is already set.
 1212|       |     * NOTE: this depends on the fact that PRBool is at least a char on
 1213|       |     * all platforms. These flags are only valid if moduleDB is set, so
 1214|       |     * code checking if (mod->isModuleDB) will continue to work correctly. */
 1215|      2|    if (mod->isModuleDB) {
  ------------------
  |  Branch (1215:9): [True: 1, False: 1]
  ------------------
 1216|      1|        char flags = SECMOD_FLAG_MODULE_DB_IS_MODULE_DB;
  ------------------
  |  |  108|      1|#define SECMOD_FLAG_MODULE_DB_IS_MODULE_DB 0x01 /* must be set if any of the \
  ------------------
 1217|      1|        if (NSSUTIL_ArgHasFlag("flags", "skipFirst", nss)) {
  ------------------
  |  Branch (1217:13): [True: 0, False: 1]
  ------------------
 1218|      0|            flags |= SECMOD_FLAG_MODULE_DB_SKIP_FIRST;
  ------------------
  |  |  110|      0|#define SECMOD_FLAG_MODULE_DB_SKIP_FIRST 0x02
  ------------------
 1219|      0|        }
 1220|      1|        if (NSSUTIL_ArgHasFlag("flags", "defaultModDB", nss)) {
  ------------------
  |  Branch (1220:13): [True: 1, False: 0]
  ------------------
 1221|      1|            flags |= SECMOD_FLAG_MODULE_DB_DEFAULT_MODDB;
  ------------------
  |  |  111|      1|#define SECMOD_FLAG_MODULE_DB_DEFAULT_MODDB 0x04
  ------------------
 1222|      1|        }
 1223|      1|        if (NSSUTIL_ArgHasFlag("flags", "policyOnly", nss)) {
  ------------------
  |  Branch (1223:13): [True: 0, False: 1]
  ------------------
 1224|      0|            flags |= SECMOD_FLAG_MODULE_DB_POLICY_ONLY;
  ------------------
  |  |  112|      0|#define SECMOD_FLAG_MODULE_DB_POLICY_ONLY 0x08
  ------------------
 1225|      0|        }
 1226|       |        /* additional moduleDB flags could be added here in the future */
 1227|      1|        mod->isModuleDB = (PRBool)flags;
 1228|      1|    }
 1229|       |
 1230|      2|    if (mod->internal) {
  ------------------
  |  Branch (1230:9): [True: 2, False: 0]
  ------------------
 1231|      2|        char flags = SECMOD_FLAG_INTERNAL_IS_INTERNAL;
  ------------------
  |  |  126|      2|#define SECMOD_FLAG_INTERNAL_IS_INTERNAL 0x01 /* must be set if any of \
  ------------------
 1232|       |
 1233|      2|        if (NSSUTIL_ArgHasFlag("flags", "internalKeySlot", nss)) {
  ------------------
  |  Branch (1233:13): [True: 1, False: 1]
  ------------------
 1234|      1|            flags |= SECMOD_FLAG_INTERNAL_KEY_SLOT;
  ------------------
  |  |  128|      1|#define SECMOD_FLAG_INTERNAL_KEY_SLOT 0x02
  ------------------
 1235|      1|        }
 1236|      2|        mod->internal = (PRBool)flags;
 1237|      2|    }
 1238|       |
 1239|      2|    ciphers = NSSUTIL_ArgGetParamValue("ciphers", nss);
 1240|      2|    NSSUTIL_ArgParseCipherFlags(&mod->ssl[0], ciphers);
 1241|      2|    if (ciphers)
  ------------------
  |  Branch (1241:9): [True: 0, False: 2]
  ------------------
 1242|      0|        PORT_Free(ciphers);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1243|       |
 1244|      2|    secmod_PrivateModuleCount++;
 1245|       |
 1246|      2|    return mod;
 1247|      2|}
SECMOD_GetSkipFirstFlag:
 1251|      1|{
 1252|      1|    char flags = (char)mod->isModuleDB;
 1253|       |
 1254|      1|    return (flags & SECMOD_FLAG_MODULE_DB_SKIP_FIRST) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  110|      1|#define SECMOD_FLAG_MODULE_DB_SKIP_FIRST 0x02
  ------------------
                  return (flags & SECMOD_FLAG_MODULE_DB_SKIP_FIRST) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  return (flags & SECMOD_FLAG_MODULE_DB_SKIP_FIRST) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  |  Branch (1254:12): [True: 0, False: 1]
  ------------------
 1255|      1|}
secmod_PolicyOnly:
 1267|      2|{
 1268|      2|    char flags = (char)mod->isModuleDB;
 1269|       |
 1270|      2|    return (flags & SECMOD_FLAG_MODULE_DB_POLICY_ONLY) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  112|      2|#define SECMOD_FLAG_MODULE_DB_POLICY_ONLY 0x08
  ------------------
                  return (flags & SECMOD_FLAG_MODULE_DB_POLICY_ONLY) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  return (flags & SECMOD_FLAG_MODULE_DB_POLICY_ONLY) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  |  Branch (1270:12): [True: 0, False: 2]
  ------------------
 1271|      2|}
secmod_IsInternalKeySlot:
 1275|      3|{
 1276|      3|    char flags = (char)mod->internal;
 1277|       |
 1278|      3|    return (flags & SECMOD_FLAG_INTERNAL_KEY_SLOT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  128|      3|#define SECMOD_FLAG_INTERNAL_KEY_SLOT 0x02
  ------------------
                  return (flags & SECMOD_FLAG_INTERNAL_KEY_SLOT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
                  return (flags & SECMOD_FLAG_INTERNAL_KEY_SLOT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (1278:12): [True: 3, False: 0]
  ------------------
 1279|      3|}
SECMOD_GetModuleSpecList:
 2095|      1|{
 2096|      1|    SECMODModuleDBFunc func = (SECMODModuleDBFunc)module->moduleDBFunc;
 2097|      1|    if (func) {
  ------------------
  |  Branch (2097:9): [True: 1, False: 0]
  ------------------
 2098|      1|        return (*func)(SECMOD_MODULE_DB_FUNCTION_FIND,
  ------------------
  |  |  557|      1|#define SECMOD_MODULE_DB_FUNCTION_FIND 0
  ------------------
 2099|      1|                       module->libraryParams, NULL);
 2100|      1|    }
 2101|      0|    return NULL;
 2102|      1|}
SECMOD_FreeModuleSpecList:
 2150|      1|{
 2151|      1|    SECMODModuleDBFunc func = (SECMODModuleDBFunc)module->moduleDBFunc;
 2152|      1|    char **retString;
 2153|      1|    if (func) {
  ------------------
  |  Branch (2153:9): [True: 1, False: 0]
  ------------------
 2154|      1|        retString = (*func)(SECMOD_MODULE_DB_FUNCTION_RELEASE,
  ------------------
  |  |  560|      1|#define SECMOD_MODULE_DB_FUNCTION_RELEASE 3
  ------------------
 2155|      1|                            module->libraryParams, moduleSpecList);
 2156|      1|        if (retString != NULL)
  ------------------
  |  Branch (2156:13): [True: 1, False: 0]
  ------------------
 2157|      1|            return SECSuccess;
 2158|      1|    }
 2159|      0|    return SECFailure;
 2160|      1|}
SECMOD_LoadModule:
 2167|      2|{
 2168|      2|    char *library = NULL, *moduleName = NULL, *parameters = NULL, *nss = NULL;
 2169|      2|    char *config = NULL;
 2170|      2|    SECStatus status;
 2171|      2|    SECMODModule *module = NULL;
 2172|      2|    SECMODModule *oldModule = NULL;
 2173|      2|    SECStatus rv;
 2174|      2|    PRBool forwardPolicyFeedback = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2175|      2|    PRUint32 forwardPolicyCheckFlags;
 2176|       |
 2177|       |    /* initialize the underlying module structures */
 2178|      2|    SECMOD_Init();
 2179|       |
 2180|      2|    status = NSSUTIL_ArgParseModuleSpecEx(modulespec, &library, &moduleName,
 2181|      2|                                          &parameters, &nss,
 2182|      2|                                          &config);
 2183|      2|    if (status != SECSuccess) {
  ------------------
  |  Branch (2183:9): [True: 0, False: 2]
  ------------------
 2184|      0|        goto loser;
 2185|      0|    }
 2186|       |
 2187|      2|    module = SECMOD_CreateModuleEx(library, moduleName, parameters, nss, config);
 2188|      2|    forwardPolicyFeedback = NSSUTIL_ArgHasFlag("flags", "printPolicyFeedback", nss);
 2189|      2|    forwardPolicyCheckFlags = secmod_parsePolicyCheckFlags(nss);
 2190|       |
 2191|      2|    if (library)
  ------------------
  |  Branch (2191:9): [True: 0, False: 2]
  ------------------
 2192|      0|        PORT_Free(library);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2193|      2|    if (moduleName)
  ------------------
  |  Branch (2193:9): [True: 2, False: 0]
  ------------------
 2194|      2|        PORT_Free(moduleName);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 2195|      2|    if (parameters)
  ------------------
  |  Branch (2195:9): [True: 2, False: 0]
  ------------------
 2196|      2|        PORT_Free(parameters);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 2197|      2|    if (nss)
  ------------------
  |  Branch (2197:9): [True: 2, False: 0]
  ------------------
 2198|      2|        PORT_Free(nss);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 2199|      2|    if (config)
  ------------------
  |  Branch (2199:9): [True: 0, False: 2]
  ------------------
 2200|      0|        PORT_Free(config);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2201|      2|    if (!module) {
  ------------------
  |  Branch (2201:9): [True: 0, False: 2]
  ------------------
 2202|      0|        goto loser;
 2203|      0|    }
 2204|       |
 2205|       |    /* a policy only stanza doesn't actually get 'loaded'. policy has already
 2206|       |     * been parsed as a side effect of the CreateModuleEx call */
 2207|      2|    if (secmod_PolicyOnly(module)) {
  ------------------
  |  Branch (2207:9): [True: 0, False: 2]
  ------------------
 2208|      0|        return module;
 2209|      0|    }
 2210|      2|    if (parent) {
  ------------------
  |  Branch (2210:9): [True: 1, False: 1]
  ------------------
 2211|      1|        module->parent = SECMOD_ReferenceModule(parent);
 2212|      1|        if (module->internal && secmod_IsInternalKeySlot(parent)) {
  ------------------
  |  Branch (2212:13): [True: 1, False: 0]
  |  Branch (2212:33): [True: 1, False: 0]
  ------------------
 2213|      1|            module->internal = parent->internal;
 2214|      1|        }
 2215|      1|    }
 2216|       |
 2217|       |    /* load it */
 2218|      2|    rv = secmod_LoadPKCS11Module(module, &oldModule);
 2219|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2219:9): [True: 0, False: 2]
  ------------------
 2220|      0|        goto loser;
 2221|      0|    }
 2222|       |
 2223|       |    /* if we just reload an old module, no need to add it to any lists.
 2224|       |     * we simple release all our references */
 2225|      2|    if (oldModule) {
  ------------------
  |  Branch (2225:9): [True: 0, False: 2]
  ------------------
 2226|       |        /* This module already exists, don't link it anywhere. This
 2227|       |         * will probably destroy this module */
 2228|      0|        SECMOD_DestroyModule(module);
 2229|      0|        return oldModule;
 2230|      0|    }
 2231|       |
 2232|      2|    if (recurse && module->isModuleDB) {
  ------------------
  |  Branch (2232:9): [True: 2, False: 0]
  |  Branch (2232:20): [True: 1, False: 1]
  ------------------
 2233|      1|        char **moduleSpecList;
 2234|      1|        PORT_SetError(0);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 2235|       |
 2236|      1|        moduleSpecList = SECMOD_GetModuleSpecList(module);
 2237|      1|        if (moduleSpecList) {
  ------------------
  |  Branch (2237:13): [True: 1, False: 0]
  ------------------
 2238|      1|            char **index;
 2239|       |
 2240|      1|            index = moduleSpecList;
 2241|      1|            if (*index && SECMOD_GetSkipFirstFlag(module)) {
  ------------------
  |  Branch (2241:17): [True: 1, False: 0]
  |  Branch (2241:27): [True: 0, False: 1]
  ------------------
 2242|      0|                index++;
 2243|      0|            }
 2244|       |
 2245|      2|            for (; *index; index++) {
  ------------------
  |  Branch (2245:20): [True: 1, False: 1]
  ------------------
 2246|      1|                SECMODModule *child;
 2247|      1|                if (0 == PORT_Strcmp(*index, modulespec)) {
  ------------------
  |  |  188|      1|#define PORT_Strcmp strcmp
  ------------------
  |  Branch (2247:21): [True: 0, False: 1]
  ------------------
 2248|       |                    /* avoid trivial infinite recursion */
 2249|      0|                    PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2250|      0|                    rv = SECFailure;
 2251|      0|                    break;
 2252|      0|                }
 2253|      1|                if (!forwardPolicyFeedback) {
  ------------------
  |  Branch (2253:21): [True: 1, False: 0]
  ------------------
 2254|      1|                    child = SECMOD_LoadModule(*index, module, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 2255|      1|                } else {
 2256|       |                    /* Add printPolicyFeedback to the nss flags */
 2257|      0|                    char *specWithForwards =
 2258|      0|                        NSSUTIL_AddNSSFlagToModuleSpec(*index, "printPolicyFeedback");
 2259|      0|                    char *tmp;
 2260|      0|                    if (forwardPolicyCheckFlags & SECMOD_FLAG_POLICY_CHECK_IDENTIFIER) {
  ------------------
  |  |  131|      0|#define SECMOD_FLAG_POLICY_CHECK_IDENTIFIER 0x01
  ------------------
  |  Branch (2260:25): [True: 0, False: 0]
  ------------------
 2261|      0|                        tmp = NSSUTIL_AddNSSFlagToModuleSpec(specWithForwards, "policyCheckIdentifier");
 2262|      0|                        PORT_Free(specWithForwards);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2263|      0|                        specWithForwards = tmp;
 2264|      0|                    }
 2265|      0|                    if (forwardPolicyCheckFlags & SECMOD_FLAG_POLICY_CHECK_VALUE) {
  ------------------
  |  |  132|      0|#define SECMOD_FLAG_POLICY_CHECK_VALUE 0x02
  ------------------
  |  Branch (2265:25): [True: 0, False: 0]
  ------------------
 2266|      0|                        tmp = NSSUTIL_AddNSSFlagToModuleSpec(specWithForwards, "policyCheckValue");
 2267|      0|                        PORT_Free(specWithForwards);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2268|      0|                        specWithForwards = tmp;
 2269|      0|                    }
 2270|      0|                    child = SECMOD_LoadModule(specWithForwards, module, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2271|      0|                    PORT_Free(specWithForwards);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2272|      0|                }
 2273|      1|                if (!child)
  ------------------
  |  Branch (2273:21): [True: 0, False: 1]
  ------------------
 2274|      0|                    break;
 2275|      1|                if (child->isCritical && !child->loaded) {
  ------------------
  |  Branch (2275:21): [True: 1, False: 0]
  |  Branch (2275:42): [True: 0, False: 1]
  ------------------
 2276|      0|                    int err = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 2277|      0|                    if (!err)
  ------------------
  |  Branch (2277:25): [True: 0, False: 0]
  ------------------
 2278|      0|                        err = SEC_ERROR_NO_MODULE;
 2279|      0|                    SECMOD_DestroyModule(child);
 2280|      0|                    PORT_SetError(err);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2281|      0|                    rv = SECFailure;
 2282|      0|                    break;
 2283|      0|                }
 2284|      1|                SECMOD_DestroyModule(child);
 2285|      1|            }
 2286|      1|            SECMOD_FreeModuleSpecList(module, moduleSpecList);
 2287|      1|        } else {
 2288|      0|            if (!PORT_GetError())
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (2288:17): [True: 0, False: 0]
  ------------------
 2289|      0|                PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2290|      0|            rv = SECFailure;
 2291|      0|        }
 2292|      1|    }
 2293|       |
 2294|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2294:9): [True: 0, False: 2]
  ------------------
 2295|      0|        goto loser;
 2296|      0|    }
 2297|       |
 2298|       |    /* inherit the reference */
 2299|      2|    if (!module->moduleDBOnly) {
  ------------------
  |  Branch (2299:9): [True: 1, False: 1]
  ------------------
 2300|      1|        SECMOD_AddModuleToList(module);
 2301|      1|    } else {
 2302|      1|        SECMOD_AddModuleToDBOnlyList(module);
 2303|      1|    }
 2304|       |
 2305|       |    /* handle any additional work here */
 2306|      2|    return module;
 2307|       |
 2308|      0|loser:
 2309|      0|    if (module) {
  ------------------
  |  Branch (2309:9): [True: 0, False: 0]
  ------------------
 2310|      0|        if (module->loaded) {
  ------------------
  |  Branch (2310:13): [True: 0, False: 0]
  ------------------
 2311|      0|            SECMOD_UnloadModule(module);
 2312|      0|        }
 2313|      0|        SECMOD_AddModuleToUnloadList(module);
 2314|      0|    }
 2315|      0|    return module;
 2316|      2|}
pk11pars.c:secmod_parsePolicyCheckFlags:
 1133|      4|{
 1134|      4|    PRUint32 policyCheckFlags = 0;
 1135|       |
 1136|      4|    if (NSSUTIL_ArgHasFlag("flags", "policyCheckIdentifier", nss)) {
  ------------------
  |  Branch (1136:9): [True: 0, False: 4]
  ------------------
 1137|      0|        policyCheckFlags |= SECMOD_FLAG_POLICY_CHECK_IDENTIFIER;
  ------------------
  |  |  131|      0|#define SECMOD_FLAG_POLICY_CHECK_IDENTIFIER 0x01
  ------------------
 1138|      0|    }
 1139|       |
 1140|      4|    if (NSSUTIL_ArgHasFlag("flags", "policyCheckValue", nss)) {
  ------------------
  |  Branch (1140:9): [True: 0, False: 4]
  ------------------
 1141|      0|        policyCheckFlags |= SECMOD_FLAG_POLICY_CHECK_VALUE;
  ------------------
  |  |  132|      0|#define SECMOD_FLAG_POLICY_CHECK_VALUE 0x02
  ------------------
 1142|      0|    }
 1143|       |
 1144|      4|    return policyCheckFlags;
 1145|      4|}
pk11pars.c:secmod_parseCryptoPolicy:
 1061|      2|{
 1062|      2|    char *args;
 1063|      2|    SECStatus rv;
 1064|       |
 1065|      2|    if (policyConfig == NULL) {
  ------------------
  |  Branch (1065:9): [True: 2, False: 0]
  ------------------
 1066|      2|        return SECSuccess; /* no policy given */
 1067|      2|    }
 1068|       |    /* make sure we initialize the oid table and set all the default policy
 1069|       |     * values first so we can override them here */
 1070|      0|    rv = SECOID_Init();
 1071|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1071:9): [True: 0, False: 0]
  ------------------
 1072|      0|        return rv;
 1073|      0|    }
 1074|      0|    args = NSSUTIL_ArgGetParamValue("disallow", policyConfig);
 1075|      0|    rv = secmod_applyCryptoPolicy(args, NSS_DISALLOW, printPolicyFeedback,
 1076|      0|                                  policyCheckFlags);
 1077|      0|    if (args)
  ------------------
  |  Branch (1077:9): [True: 0, False: 0]
  ------------------
 1078|      0|        PORT_Free(args);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1079|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1079:9): [True: 0, False: 0]
  ------------------
 1080|      0|        return rv;
 1081|      0|    }
 1082|      0|    args = NSSUTIL_ArgGetParamValue("allow", policyConfig);
 1083|      0|    rv = secmod_applyCryptoPolicy(args, NSS_ALLOW, printPolicyFeedback,
 1084|      0|                                  policyCheckFlags);
 1085|      0|    if (args)
  ------------------
  |  Branch (1085:9): [True: 0, False: 0]
  ------------------
 1086|      0|        PORT_Free(args);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1087|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1087:9): [True: 0, False: 0]
  ------------------
 1088|      0|        return rv;
 1089|      0|    }
 1090|      0|    args = NSSUTIL_ArgGetParamValue("disable", policyConfig);
 1091|      0|    rv = secmod_applyCryptoPolicy(args, NSS_DISABLE, printPolicyFeedback,
 1092|      0|                                  policyCheckFlags);
 1093|      0|    if (args)
  ------------------
  |  Branch (1093:9): [True: 0, False: 0]
  ------------------
 1094|      0|        PORT_Free(args);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1095|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1095:9): [True: 0, False: 0]
  ------------------
 1096|      0|        return rv;
 1097|      0|    }
 1098|      0|    args = NSSUTIL_ArgGetParamValue("enable", policyConfig);
 1099|      0|    rv = secmod_applyCryptoPolicy(args, NSS_ENABLE, printPolicyFeedback,
 1100|      0|                                  policyCheckFlags);
 1101|      0|    if (args)
  ------------------
  |  Branch (1101:9): [True: 0, False: 0]
  ------------------
 1102|      0|        PORT_Free(args);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1103|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1103:9): [True: 0, False: 0]
  ------------------
 1104|      0|        return rv;
 1105|      0|    }
 1106|       |    /* this has to be last. Everything after this will be a noop */
 1107|      0|    if (NSSUTIL_ArgHasFlag("flags", "ssl-lock", policyConfig)) {
  ------------------
  |  Branch (1107:9): [True: 0, False: 0]
  ------------------
 1108|      0|        PRInt32 locks;
 1109|       |        /* don't overwrite other (future) lock flags */
 1110|      0|        rv = NSS_OptionGet(NSS_DEFAULT_LOCKS, &locks);
  ------------------
  |  |  302|      0|#define NSS_DEFAULT_LOCKS 0x00d /* lock default values */
  ------------------
 1111|      0|        if (rv == SECSuccess) {
  ------------------
  |  Branch (1111:13): [True: 0, False: 0]
  ------------------
 1112|      0|            rv = NSS_OptionSet(NSS_DEFAULT_LOCKS, locks | NSS_DEFAULT_SSL_LOCK);
  ------------------
  |  |  302|      0|#define NSS_DEFAULT_LOCKS 0x00d /* lock default values */
  ------------------
                          rv = NSS_OptionSet(NSS_DEFAULT_LOCKS, locks | NSS_DEFAULT_SSL_LOCK);
  ------------------
  |  |  303|      0|#define NSS_DEFAULT_SSL_LOCK 1  /* lock the ssl default values */
  ------------------
 1113|      0|        }
 1114|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1114:13): [True: 0, False: 0]
  ------------------
 1115|      0|            return rv;
 1116|      0|        }
 1117|      0|    }
 1118|      0|    if (NSSUTIL_ArgHasFlag("flags", "policy-lock", policyConfig)) {
  ------------------
  |  Branch (1118:9): [True: 0, False: 0]
  ------------------
 1119|      0|        NSS_LockPolicy();
 1120|      0|    }
 1121|      0|    if (printPolicyFeedback) {
  ------------------
  |  Branch (1121:9): [True: 0, False: 0]
  ------------------
 1122|       |        /* This helps to distinguish configurations that don't contain any
 1123|       |         * policy config= statement. */
 1124|      0|        PR_SetEnv("NSS_POLICY_LOADED=1");
 1125|      0|        fprintf(stderr, "NSS-POLICY-INFO: LOADED-SUCCESSFULLY\n");
 1126|      0|        secmod_sanityCheckCryptoPolicy();
 1127|      0|    }
 1128|      0|    return rv;
 1129|      0|}
pk11pars.c:secmod_NewModule:
   25|      2|{
   26|      2|    SECMODModule *newMod;
   27|      2|    PLArenaPool *arena;
   28|       |
   29|       |    /* create an arena in which dllName and commonName can be
   30|       |     * allocated.
   31|       |     */
   32|      2|    arena = PORT_NewArena(512);
  ------------------
  |  |   63|      2|#define PORT_NewArena PORT_NewArena_Util
  ------------------
   33|      2|    if (arena == NULL) {
  ------------------
  |  Branch (33:9): [True: 0, False: 2]
  ------------------
   34|      0|        return NULL;
   35|      0|    }
   36|       |
   37|      2|    newMod = (SECMODModule *)PORT_ArenaAlloc(arena, sizeof(SECMODModule));
  ------------------
  |  |   53|      2|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
   38|      2|    if (newMod == NULL) {
  ------------------
  |  Branch (38:9): [True: 0, False: 2]
  ------------------
   39|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   40|      0|        return NULL;
   41|      0|    }
   42|       |
   43|       |    /*
   44|       |     * initialize of the fields of the module
   45|       |     */
   46|      2|    newMod->arena = arena;
   47|      2|    newMod->internal = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   48|      2|    newMod->loaded = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   49|      2|    newMod->isFIPS = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   50|      2|    newMod->dllName = NULL;
   51|      2|    newMod->commonName = NULL;
   52|      2|    newMod->library = NULL;
   53|      2|    newMod->functionList = NULL;
   54|      2|    newMod->slotCount = 0;
   55|      2|    newMod->slots = NULL;
   56|      2|    newMod->slotInfo = NULL;
   57|      2|    newMod->slotInfoCount = 0;
   58|      2|    newMod->refCount = 1;
   59|      2|    newMod->ssl[0] = 0;
   60|      2|    newMod->ssl[1] = 0;
   61|      2|    newMod->libraryParams = NULL;
   62|      2|    newMod->moduleDBFunc = NULL;
   63|      2|    newMod->parent = NULL;
   64|      2|    newMod->isCritical = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   65|      2|    newMod->isModuleDB = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   66|      2|    newMod->moduleDBOnly = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
   67|      2|    newMod->trustOrder = 0;
   68|      2|    newMod->cipherOrder = 0;
   69|      2|    newMod->evControlMask = 0;
   70|      2|    newMod->refLock = PZ_NewLock(nssILockRefLock);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   71|      2|    if (newMod->refLock == NULL) {
  ------------------
  |  Branch (71:9): [True: 0, False: 2]
  ------------------
   72|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   73|      0|        return NULL;
   74|      0|    }
   75|      2|    return newMod;
   76|      2|}

PK11_ImportDERPrivateKeyInfoAndReturnKey:
  274|      2|{
  275|      2|    SECKEYPrivateKeyInfo *pki = NULL;
  276|      2|    PLArenaPool *temparena = NULL;
  277|      2|    SECStatus rv = SECFailure;
  278|       |
  279|      2|    temparena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|      2|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  temparena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|      2|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  280|      2|    if (!temparena) {
  ------------------
  |  Branch (280:9): [True: 0, False: 2]
  ------------------
  281|      0|        return rv;
  282|      0|    }
  283|       |
  284|      2|    pki = PORT_ArenaZNew(temparena, SECKEYPrivateKeyInfo);
  ------------------
  |  |  155|      2|    (type *)PORT_ArenaZAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   59|      2|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  |  |  ------------------
  ------------------
  285|      2|    if (!pki) {
  ------------------
  |  Branch (285:9): [True: 0, False: 2]
  ------------------
  286|      0|        PORT_FreeArena(temparena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(temparena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  287|      0|        return rv;
  288|      0|    }
  289|      2|    pki->arena = temparena;
  290|       |
  291|      2|    rv = SEC_ASN1DecodeItem(pki->arena, pki, SECKEY_PrivateKeyInfoTemplate,
  ------------------
  |  |   78|      2|#define SEC_ASN1DecodeItem SEC_ASN1DecodeItem_Util
  ------------------
  292|      2|                            derPKI);
  293|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (293:9): [True: 0, False: 2]
  ------------------
  294|       |        /* If SEC_ASN1DecodeItem fails, we cannot assume anything about the
  295|       |         * validity of the data in pki. The best we can do is free the arena
  296|       |         * and return. */
  297|      0|        PORT_FreeArena(temparena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(temparena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  298|      0|        return rv;
  299|      0|    }
  300|      2|    if (pki->privateKey.data == NULL) {
  ------------------
  |  Branch (300:9): [True: 0, False: 2]
  ------------------
  301|       |        /* If SEC_ASN1DecodeItems succeeds but SECKEYPrivateKeyInfo.privateKey
  302|       |         * is a zero-length octet string, free the arena and return a failure
  303|       |         * to avoid trying to zero the corresponding SECItem in
  304|       |         * SECKEY_DestroyPrivateKeyInfo(). */
  305|      0|        PORT_FreeArena(temparena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(temparena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  306|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  307|      0|        return SECFailure;
  308|      0|    }
  309|       |
  310|      2|    rv = PK11_ImportPrivateKeyInfoAndReturnKey(slot, pki, nickname,
  311|      2|                                               publicValue, isPerm, isPrivate,
  312|      2|                                               keyUsage, privk, wincx);
  313|       |
  314|       |    /* this zeroes the key and frees the arena */
  315|      2|    SECKEY_DestroyPrivateKeyInfo(pki, PR_TRUE /*freeit*/);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  316|      2|    return rv;
  317|      2|}
PK11_ImportAndReturnPrivateKey:
  324|      2|{
  325|      2|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|      2|#define CK_TRUE 1
  ------------------
  326|      2|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|      2|#define CK_FALSE 0
  ------------------
  327|      2|    CK_OBJECT_CLASS keyClass = CKO_PRIVATE_KEY;
  ------------------
  |  |  328|      2|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  328|      2|    CK_KEY_TYPE keyType = CKK_RSA;
  ------------------
  |  |  372|      2|#define CKK_RSA 0x00000000UL
  ------------------
  329|      2|    CK_OBJECT_HANDLE objectID;
  330|      2|    CK_ATTRIBUTE theTemplate[20];
  331|      2|    int templateCount = 0;
  332|      2|    SECStatus rv = SECFailure;
  333|      2|    CK_ATTRIBUTE *attrs;
  334|      2|    CK_ATTRIBUTE *signedattr = NULL;
  335|      2|    int signedcount = 0;
  336|      2|    CK_ATTRIBUTE *ap;
  337|      2|    SECItem *ck_id = NULL;
  338|       |
  339|      2|    attrs = theTemplate;
  340|       |
  341|      2|    PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
  342|      2|    attrs++;
  343|      2|    PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
  344|      2|    attrs++;
  345|      2|    PK11_SETATTRS(attrs, CKA_TOKEN, isPerm ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      4|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 2]
  |  |  ------------------
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
  346|      2|                  sizeof(CK_BBOOL));
  347|      2|    attrs++;
  348|      2|    PK11_SETATTRS(attrs, CKA_SENSITIVE, isPrivate ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      4|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 2]
  |  |  ------------------
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
  349|      2|                  sizeof(CK_BBOOL));
  350|      2|    attrs++;
  351|      2|    PK11_SETATTRS(attrs, CKA_PRIVATE, isPrivate ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      4|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 0, False: 2]
  |  |  ------------------
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
  352|      2|                  sizeof(CK_BBOOL));
  353|      2|    attrs++;
  354|       |
  355|      2|    switch (lpk->keyType) {
  356|      1|        case rsaKey:
  ------------------
  |  Branch (356:9): [True: 1, False: 1]
  ------------------
  357|      1|            keyType = CKK_RSA;
  ------------------
  |  |  372|      1|#define CKK_RSA 0x00000000UL
  ------------------
  358|      1|            PK11_SETATTRS(attrs, CKA_UNWRAP, (keyUsage & KU_KEY_ENCIPHERMENT) ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  359|      1|                          sizeof(CK_BBOOL));
  360|      1|            attrs++;
  361|      1|            PK11_SETATTRS(attrs, CKA_DECRYPT, (keyUsage & KU_DATA_ENCIPHERMENT) ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  362|      1|                          sizeof(CK_BBOOL));
  363|      1|            attrs++;
  364|      1|            PK11_SETATTRS(attrs, CKA_SIGN, (keyUsage & KU_DIGITAL_SIGNATURE) ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  365|      1|                          sizeof(CK_BBOOL));
  366|      1|            attrs++;
  367|      1|            PK11_SETATTRS(attrs, CKA_SIGN_RECOVER,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  368|      1|                          (keyUsage & KU_DIGITAL_SIGNATURE) ? &cktrue
  369|      1|                                                            : &ckfalse,
  370|      1|                          sizeof(CK_BBOOL));
  371|      1|            attrs++;
  372|      1|            ck_id = PK11_MakeIDFromPubKey(&lpk->u.rsa.modulus);
  373|      1|            if (ck_id == NULL) {
  ------------------
  |  Branch (373:17): [True: 0, False: 1]
  ------------------
  374|      0|                goto loser;
  375|      0|            }
  376|      1|            PK11_SETATTRS(attrs, CKA_ID, ck_id->data, ck_id->len);
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  377|      1|            attrs++;
  378|      1|            if (nickname) {
  ------------------
  |  Branch (378:17): [True: 0, False: 1]
  ------------------
  379|      0|                PK11_SETATTRS(attrs, CKA_LABEL, nickname->data, nickname->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  380|      0|                attrs++;
  381|      0|            }
  382|      1|            signedattr = attrs;
  383|      1|            PK11_SETATTRS(attrs, CKA_MODULUS, lpk->u.rsa.modulus.data,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  384|      1|                          lpk->u.rsa.modulus.len);
  385|      1|            attrs++;
  386|      1|            PK11_SETATTRS(attrs, CKA_PUBLIC_EXPONENT,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  387|      1|                          lpk->u.rsa.publicExponent.data,
  388|      1|                          lpk->u.rsa.publicExponent.len);
  389|      1|            attrs++;
  390|      1|            PK11_SETATTRS(attrs, CKA_PRIVATE_EXPONENT,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  391|      1|                          lpk->u.rsa.privateExponent.data,
  392|      1|                          lpk->u.rsa.privateExponent.len);
  393|      1|            attrs++;
  394|      1|            PK11_SETATTRS(attrs, CKA_PRIME_1,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  395|      1|                          lpk->u.rsa.prime1.data,
  396|      1|                          lpk->u.rsa.prime1.len);
  397|      1|            attrs++;
  398|      1|            PK11_SETATTRS(attrs, CKA_PRIME_2,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  399|      1|                          lpk->u.rsa.prime2.data,
  400|      1|                          lpk->u.rsa.prime2.len);
  401|      1|            attrs++;
  402|      1|            PK11_SETATTRS(attrs, CKA_EXPONENT_1,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  403|      1|                          lpk->u.rsa.exponent1.data,
  404|      1|                          lpk->u.rsa.exponent1.len);
  405|      1|            attrs++;
  406|      1|            PK11_SETATTRS(attrs, CKA_EXPONENT_2,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  407|      1|                          lpk->u.rsa.exponent2.data,
  408|      1|                          lpk->u.rsa.exponent2.len);
  409|      1|            attrs++;
  410|      1|            PK11_SETATTRS(attrs, CKA_COEFFICIENT,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  411|      1|                          lpk->u.rsa.coefficient.data,
  412|      1|                          lpk->u.rsa.coefficient.len);
  413|      1|            attrs++;
  414|      1|            break;
  415|      0|        case dsaKey:
  ------------------
  |  Branch (415:9): [True: 0, False: 2]
  ------------------
  416|      0|            keyType = CKK_DSA;
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  417|       |            /* To make our intenal PKCS #11 module work correctly with
  418|       |             * our database, we need to pass in the public key value for
  419|       |             * this dsa key. We have a netscape only CKA_ value to do this.
  420|       |             * Only send it to internal slots */
  421|      0|            if (publicValue == NULL) {
  ------------------
  |  Branch (421:17): [True: 0, False: 0]
  ------------------
  422|      0|                goto loser;
  423|      0|            }
  424|      0|            if (PK11_IsInternal(slot)) {
  ------------------
  |  Branch (424:17): [True: 0, False: 0]
  ------------------
  425|      0|                PK11_SETATTRS(attrs, CKA_NSS_DB,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  426|      0|                              publicValue->data, publicValue->len);
  427|      0|                attrs++;
  428|      0|            }
  429|      0|            PK11_SETATTRS(attrs, CKA_SIGN, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  430|      0|            attrs++;
  431|      0|            PK11_SETATTRS(attrs, CKA_SIGN_RECOVER, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  432|      0|            attrs++;
  433|      0|            if (nickname) {
  ------------------
  |  Branch (433:17): [True: 0, False: 0]
  ------------------
  434|      0|                PK11_SETATTRS(attrs, CKA_LABEL, nickname->data, nickname->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  435|      0|                attrs++;
  436|      0|            }
  437|      0|            ck_id = PK11_MakeIDFromPubKey(publicValue);
  438|      0|            if (ck_id == NULL) {
  ------------------
  |  Branch (438:17): [True: 0, False: 0]
  ------------------
  439|      0|                goto loser;
  440|      0|            }
  441|      0|            PK11_SETATTRS(attrs, CKA_ID, ck_id->data, ck_id->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  442|      0|            attrs++;
  443|      0|            signedattr = attrs;
  444|      0|            PK11_SETATTRS(attrs, CKA_PRIME, lpk->u.dsa.params.prime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  445|      0|                          lpk->u.dsa.params.prime.len);
  446|      0|            attrs++;
  447|      0|            PK11_SETATTRS(attrs, CKA_SUBPRIME, lpk->u.dsa.params.subPrime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  448|      0|                          lpk->u.dsa.params.subPrime.len);
  449|      0|            attrs++;
  450|      0|            PK11_SETATTRS(attrs, CKA_BASE, lpk->u.dsa.params.base.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  451|      0|                          lpk->u.dsa.params.base.len);
  452|      0|            attrs++;
  453|      0|            PK11_SETATTRS(attrs, CKA_VALUE, lpk->u.dsa.privateValue.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  454|      0|                          lpk->u.dsa.privateValue.len);
  455|      0|            attrs++;
  456|      0|            break;
  457|      0|        case dhKey:
  ------------------
  |  Branch (457:9): [True: 0, False: 2]
  ------------------
  458|      0|            keyType = CKK_DH;
  ------------------
  |  |  374|      0|#define CKK_DH 0x00000002UL
  ------------------
  459|       |            /* To make our intenal PKCS #11 module work correctly with
  460|       |             * our database, we need to pass in the public key value for
  461|       |             * this dh key. We have a netscape only CKA_ value to do this.
  462|       |             * Only send it to internal slots */
  463|      0|            if (PK11_IsInternal(slot)) {
  ------------------
  |  Branch (463:17): [True: 0, False: 0]
  ------------------
  464|      0|                PK11_SETATTRS(attrs, CKA_NSS_DB,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  465|      0|                              publicValue->data, publicValue->len);
  466|      0|                attrs++;
  467|      0|            }
  468|      0|            PK11_SETATTRS(attrs, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  469|      0|            attrs++;
  470|      0|            if (nickname) {
  ------------------
  |  Branch (470:17): [True: 0, False: 0]
  ------------------
  471|      0|                PK11_SETATTRS(attrs, CKA_LABEL, nickname->data, nickname->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  472|      0|                attrs++;
  473|      0|            }
  474|      0|            ck_id = PK11_MakeIDFromPubKey(publicValue);
  475|      0|            if (ck_id == NULL) {
  ------------------
  |  Branch (475:17): [True: 0, False: 0]
  ------------------
  476|      0|                goto loser;
  477|      0|            }
  478|      0|            PK11_SETATTRS(attrs, CKA_ID, ck_id->data, ck_id->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  479|      0|            attrs++;
  480|      0|            signedattr = attrs;
  481|      0|            PK11_SETATTRS(attrs, CKA_PRIME, lpk->u.dh.prime.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  482|      0|                          lpk->u.dh.prime.len);
  483|      0|            attrs++;
  484|      0|            PK11_SETATTRS(attrs, CKA_BASE, lpk->u.dh.base.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  485|      0|                          lpk->u.dh.base.len);
  486|      0|            attrs++;
  487|      0|            PK11_SETATTRS(attrs, CKA_VALUE, lpk->u.dh.privateValue.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  488|      0|                          lpk->u.dh.privateValue.len);
  489|      0|            attrs++;
  490|      0|            break;
  491|      1|        case ecKey:
  ------------------
  |  Branch (491:9): [True: 1, False: 1]
  ------------------
  492|      1|            keyType = CKK_EC;
  ------------------
  |  |  379|      1|#define CKK_EC 0x00000003UL
  ------------------
  493|      1|            if (lpk->u.ec.publicValue.len != 0) {
  ------------------
  |  Branch (493:17): [True: 1, False: 0]
  ------------------
  494|      1|                if (PK11_IsInternal(slot)) {
  ------------------
  |  Branch (494:21): [True: 1, False: 0]
  ------------------
  495|      1|                    PK11_SETATTRS(attrs, CKA_NSS_DB,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  496|      1|                                  lpk->u.ec.publicValue.data,
  497|      1|                                  lpk->u.ec.publicValue.len);
  498|      1|                    attrs++;
  499|      1|                }
  500|      1|            }
  501|       |
  502|      1|            PK11_SETATTRS(attrs, CKA_SIGN, (keyUsage & KU_DIGITAL_SIGNATURE) ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  503|      1|                          sizeof(CK_BBOOL));
  504|      1|            attrs++;
  505|      1|            PK11_SETATTRS(attrs, CKA_SIGN_RECOVER,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  506|      1|                          (keyUsage & KU_DIGITAL_SIGNATURE) ? &cktrue
  507|      1|                                                            : &ckfalse,
  508|      1|                          sizeof(CK_BBOOL));
  509|      1|            attrs++;
  510|      1|            PK11_SETATTRS(attrs, CKA_DERIVE, (keyUsage & KU_KEY_AGREEMENT) ? &cktrue : &ckfalse,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  ------------------
  |  |  |  Branch (105:20): [True: 1, False: 0]
  |  |  ------------------
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  511|      1|                          sizeof(CK_BBOOL));
  512|      1|            attrs++;
  513|      1|            if (nickname) {
  ------------------
  |  Branch (513:17): [True: 0, False: 1]
  ------------------
  514|      0|                PK11_SETATTRS(attrs, CKA_LABEL, nickname->data, nickname->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  515|      0|                attrs++;
  516|      0|            }
  517|      1|            ck_id = PK11_MakeIDFromPubKey(&lpk->u.ec.publicValue);
  518|      1|            if (ck_id == NULL) {
  ------------------
  |  Branch (518:17): [True: 0, False: 1]
  ------------------
  519|      0|                goto loser;
  520|      0|            }
  521|      1|            PK11_SETATTRS(attrs, CKA_ID, ck_id->data, ck_id->len);
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  522|      1|            attrs++;
  523|       |            /* No signed attrs for EC */
  524|       |            /* curveOID always is a copy of AlgorithmID.parameters. */
  525|      1|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, lpk->u.ec.curveOID.data,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  526|      1|                          lpk->u.ec.curveOID.len);
  527|      1|            attrs++;
  528|      1|            PK11_SETATTRS(attrs, CKA_VALUE, lpk->u.ec.privateValue.data,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  529|      1|                          lpk->u.ec.privateValue.len);
  530|      1|            attrs++;
  531|      1|            PK11_SETATTRS(attrs, CKA_EC_POINT, lpk->u.ec.publicValue.data,
  ------------------
  |  |  104|      1|    (x)->type = (id);              \
  |  |  105|      1|    (x)->pValue = (v);             \
  |  |  106|      1|    (x)->ulValueLen = (l);
  ------------------
  532|      1|                          lpk->u.ec.publicValue.len);
  533|      1|            attrs++;
  534|      1|            break;
  535|      0|        case edKey:
  ------------------
  |  Branch (535:9): [True: 0, False: 2]
  ------------------
  536|      0|            keyType = CKK_EC_EDWARDS;
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  537|      0|            PK11_SETATTRS(attrs, CKA_SIGN, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  538|      0|            attrs++;
  539|      0|            if (nickname) {
  ------------------
  |  Branch (539:17): [True: 0, False: 0]
  ------------------
  540|      0|                PK11_SETATTRS(attrs, CKA_LABEL, nickname->data, nickname->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  541|      0|                attrs++;
  542|      0|            }
  543|       |
  544|       |            /* No signed attrs for EC */
  545|       |            /* curveOID always is a copy of AlgorithmID.parameters. */
  546|      0|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, lpk->u.ec.curveOID.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  547|      0|                          lpk->u.ec.curveOID.len);
  548|      0|            attrs++;
  549|      0|            PK11_SETATTRS(attrs, CKA_VALUE, lpk->u.ec.privateValue.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  550|      0|                          lpk->u.ec.privateValue.len);
  551|      0|            attrs++;
  552|      0|            break;
  553|      0|        case ecMontKey:
  ------------------
  |  Branch (553:9): [True: 0, False: 2]
  ------------------
  554|      0|            keyType = CKK_EC_MONTGOMERY;
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  555|       |
  556|      0|            PK11_SETATTRS(attrs, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  557|      0|            attrs++;
  558|       |
  559|      0|            if (nickname) {
  ------------------
  |  Branch (559:17): [True: 0, False: 0]
  ------------------
  560|      0|                PK11_SETATTRS(attrs, CKA_LABEL, nickname->data, nickname->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  561|      0|                attrs++;
  562|      0|            }
  563|       |
  564|       |            /* No signed attrs for EC */
  565|       |            /* curveOID always is a copy of AlgorithmID.parameters. */
  566|      0|            PK11_SETATTRS(attrs, CKA_EC_PARAMS, lpk->u.ec.curveOID.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  567|      0|                          lpk->u.ec.curveOID.len);
  568|      0|            attrs++;
  569|       |
  570|      0|            PK11_SETATTRS(attrs, CKA_VALUE, lpk->u.ec.privateValue.data,
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  571|      0|                          lpk->u.ec.privateValue.len);
  572|      0|            attrs++;
  573|      0|            break;
  574|      0|        default:
  ------------------
  |  Branch (574:9): [True: 0, False: 2]
  ------------------
  575|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  576|      0|            goto loser;
  577|      2|    }
  578|      2|    templateCount = attrs - theTemplate;
  579|      2|    PORT_Assert(templateCount <= sizeof(theTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  580|      2|    if (lpk->keyType != ecKey && lpk->keyType != edKey && lpk->keyType != ecMontKey) {
  ------------------
  |  Branch (580:9): [True: 1, False: 1]
  |  Branch (580:34): [True: 1, False: 0]
  |  Branch (580:59): [True: 1, False: 0]
  ------------------
  581|      1|        PORT_Assert(signedattr);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  582|      1|        signedcount = attrs - signedattr;
  583|      9|        for (ap = signedattr; signedcount; ap++, signedcount--) {
  ------------------
  |  Branch (583:31): [True: 8, False: 1]
  ------------------
  584|      8|            pk11_SignedToUnsigned(ap);
  585|      8|        }
  586|      1|    }
  587|       |
  588|      2|    rv = PK11_CreateNewObject(slot, CK_INVALID_HANDLE,
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  589|      2|                              theTemplate, templateCount, isPerm, &objectID);
  590|       |
  591|       |    /* create and return a SECKEYPrivateKey */
  592|      2|    if (rv == SECSuccess && privk != NULL) {
  ------------------
  |  Branch (592:9): [True: 2, False: 0]
  |  Branch (592:29): [True: 2, False: 0]
  ------------------
  593|      2|        *privk = PK11_MakePrivKey(slot, lpk->keyType, !isPerm, objectID, wincx);
  594|      2|        if (*privk == NULL) {
  ------------------
  |  Branch (594:13): [True: 0, False: 2]
  ------------------
  595|      0|            rv = SECFailure;
  596|      0|        }
  597|      2|    }
  598|      2|loser:
  599|      2|    if (ck_id) {
  ------------------
  |  Branch (599:9): [True: 2, False: 0]
  ------------------
  600|      2|        SECITEM_ZfreeItem(ck_id, PR_TRUE);
  ------------------
  |  |  110|      2|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(ck_id, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  601|      2|    }
  602|      2|    return rv;
  603|      2|}
PK11_ImportPrivateKeyInfoAndReturnKey:
  610|      2|{
  611|      2|    SECStatus rv = SECFailure;
  612|      2|    SECKEYRawPrivateKey *lpk = NULL;
  613|      2|    const SEC_ASN1Template *keyTemplate, *paramTemplate;
  614|      2|    void *paramDest = NULL;
  615|      2|    PLArenaPool *arena = NULL;
  616|       |
  617|      2|    arena = PORT_NewArena(2048);
  ------------------
  |  |   63|      2|#define PORT_NewArena PORT_NewArena_Util
  ------------------
  618|      2|    if (!arena) {
  ------------------
  |  Branch (618:9): [True: 0, False: 2]
  ------------------
  619|      0|        return SECFailure;
  620|      0|    }
  621|       |
  622|       |    /* need to change this to use RSA/DSA keys */
  623|      2|    lpk = (SECKEYRawPrivateKey *)PORT_ArenaZAlloc(arena,
  ------------------
  |  |   59|      2|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  624|      2|                                                  sizeof(SECKEYRawPrivateKey));
  625|      2|    if (lpk == NULL) {
  ------------------
  |  Branch (625:9): [True: 0, False: 2]
  ------------------
  626|      0|        goto loser;
  627|      0|    }
  628|      2|    lpk->arena = arena;
  629|       |
  630|      2|    switch (SECOID_GetAlgorithmTag(&pki->algorithm)) {
  ------------------
  |  |  119|      2|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
  631|      1|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (631:9): [True: 1, False: 1]
  ------------------
  632|      1|            prepare_rsa_priv_key_export_for_asn1(lpk);
  633|      1|            keyTemplate = SECKEY_RSAPrivateKeyExportTemplate;
  634|      1|            paramTemplate = NULL;
  635|      1|            paramDest = NULL;
  636|      1|            lpk->keyType = rsaKey;
  637|      1|            break;
  638|      0|        case SEC_OID_ANSIX9_DSA_SIGNATURE:
  ------------------
  |  Branch (638:9): [True: 0, False: 2]
  ------------------
  639|      0|            prepare_dsa_priv_key_export_for_asn1(lpk);
  640|      0|            keyTemplate = SECKEY_DSAPrivateKeyExportTemplate;
  641|      0|            paramTemplate = SECKEY_PQGParamsTemplate;
  642|      0|            paramDest = &(lpk->u.dsa.params);
  643|      0|            lpk->keyType = dsaKey;
  644|      0|            break;
  645|      0|        case SEC_OID_X942_DIFFIE_HELMAN_KEY:
  ------------------
  |  Branch (645:9): [True: 0, False: 2]
  ------------------
  646|      0|            if (!publicValue) {
  ------------------
  |  Branch (646:17): [True: 0, False: 0]
  ------------------
  647|      0|                goto loser;
  648|      0|            }
  649|      0|            prepare_dh_priv_key_export_for_asn1(lpk);
  650|      0|            keyTemplate = SECKEY_DHPrivateKeyExportTemplate;
  651|      0|            paramTemplate = NULL;
  652|      0|            paramDest = NULL;
  653|      0|            lpk->keyType = dhKey;
  654|      0|            break;
  655|      0|        case SEC_OID_ED25519_PUBLIC_KEY:
  ------------------
  |  Branch (655:9): [True: 0, False: 2]
  ------------------
  656|      0|            keyTemplate = SECKEY_ECRawPrivateKeyTemplate;
  657|      0|            paramTemplate = NULL;
  658|      0|            paramDest = NULL;
  659|      0|            lpk->keyType = edKey;
  660|      0|            break;
  661|      0|        case SEC_OID_X25519:
  ------------------
  |  Branch (661:9): [True: 0, False: 2]
  ------------------
  662|      0|            keyTemplate = SECKEY_ECRawPrivateKeyTemplate;
  663|      0|            paramTemplate = NULL;
  664|      0|            paramDest = NULL;
  665|      0|            lpk->keyType = ecMontKey;
  666|      0|            break;
  667|      1|        case SEC_OID_ANSIX962_EC_PUBLIC_KEY:
  ------------------
  |  Branch (667:9): [True: 1, False: 1]
  ------------------
  668|      1|            prepare_ec_priv_key_export_for_asn1(lpk);
  669|      1|            keyTemplate = SECKEY_ECPrivateKeyExportTemplate;
  670|      1|            paramTemplate = NULL;
  671|      1|            paramDest = NULL;
  672|      1|            lpk->keyType = ecKey;
  673|      1|            break;
  674|       |
  675|      0|        default:
  ------------------
  |  Branch (675:9): [True: 0, False: 2]
  ------------------
  676|      0|            keyTemplate = NULL;
  677|      0|            paramTemplate = NULL;
  678|      0|            paramDest = NULL;
  679|      0|            break;
  680|      2|    }
  681|       |
  682|      2|    if (!keyTemplate) {
  ------------------
  |  Branch (682:9): [True: 0, False: 2]
  ------------------
  683|      0|        goto loser;
  684|      0|    }
  685|       |
  686|       |    /* decode the private key and any algorithm parameters */
  687|      2|    rv = SEC_QuickDERDecodeItem(arena, lpk, keyTemplate, &pki->privateKey);
  ------------------
  |  |  102|      2|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
  688|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (688:9): [True: 0, False: 2]
  ------------------
  689|      0|        goto loser;
  690|      0|    }
  691|       |
  692|      2|    if (lpk->keyType == ecKey) {
  ------------------
  |  Branch (692:9): [True: 1, False: 1]
  ------------------
  693|       |        /* Convert length in bits to length in bytes. */
  694|      1|        lpk->u.ec.publicValue.len >>= 3;
  695|       |
  696|       |        /* Always override curveOID, we're ignoring any given value. */
  697|      1|        rv = SECITEM_CopyItem(arena, &lpk->u.ec.curveOID,
  ------------------
  |  |  106|      1|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  698|      1|                              &pki->algorithm.parameters);
  699|      1|        if (rv != SECSuccess) {
  ------------------
  |  Branch (699:13): [True: 0, False: 1]
  ------------------
  700|      0|            goto loser;
  701|      0|        }
  702|      1|    }
  703|       |
  704|      2|    if (lpk->keyType == edKey || lpk->keyType == ecMontKey) {
  ------------------
  |  Branch (704:9): [True: 0, False: 2]
  |  Branch (704:34): [True: 0, False: 2]
  ------------------
  705|       |        /* SECKEY_ECRawPrivateKeyTemplate (used for both key types) does not reference
  706|       |           publicKey, curveOID, ec verion. */
  707|      0|        if (pki->algorithm.parameters.len != 0) {
  ------------------
  |  Branch (707:13): [True: 0, False: 0]
  ------------------
  708|       |            /* Currently supporting only (Pure)Ed25519/X25519 .*/
  709|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_KEYALG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  710|      0|            goto loser;
  711|      0|        }
  712|       |
  713|      0|        SECOidData *oid25519 = SECOID_FindOIDByTag(SECOID_GetAlgorithmTag(&pki->algorithm));
  ------------------
  |  |  116|      0|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
                      SECOidData *oid25519 = SECOID_FindOIDByTag(SECOID_GetAlgorithmTag(&pki->algorithm));
  ------------------
  |  |  119|      0|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
  714|      0|        if (!oid25519) {
  ------------------
  |  Branch (714:13): [True: 0, False: 0]
  ------------------
  715|      0|            goto loser;
  716|      0|        }
  717|       |
  718|      0|        if (!SECITEM_AllocItem(arena, &lpk->u.ec.curveOID, oid25519->oid.len + 2)) {
  ------------------
  |  |  103|      0|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (718:13): [True: 0, False: 0]
  ------------------
  719|      0|            goto loser;
  720|      0|        }
  721|      0|        lpk->u.ec.curveOID.data[0] = SEC_ASN1_OBJECT_ID;
  ------------------
  |  |   82|      0|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
  722|      0|        lpk->u.ec.curveOID.data[1] = oid25519->oid.len;
  723|      0|        PORT_Memcpy(lpk->u.ec.curveOID.data + 2, oid25519->oid.data, oid25519->oid.len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  724|      0|    }
  725|       |
  726|      2|    if (paramDest && paramTemplate) {
  ------------------
  |  Branch (726:9): [True: 0, False: 2]
  |  Branch (726:22): [True: 0, False: 0]
  ------------------
  727|      0|        rv = SEC_ASN1DecodeItem(arena, paramDest, paramTemplate,
  ------------------
  |  |   78|      0|#define SEC_ASN1DecodeItem SEC_ASN1DecodeItem_Util
  ------------------
  728|      0|                                &(pki->algorithm.parameters));
  729|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (729:13): [True: 0, False: 0]
  ------------------
  730|      0|            goto loser;
  731|      0|        }
  732|      0|    }
  733|       |
  734|      2|    rv = PK11_ImportAndReturnPrivateKey(slot, lpk, nickname, publicValue, isPerm,
  735|      2|                                        isPrivate, keyUsage, privk, wincx);
  736|      2|loser:
  737|      2|    if (arena != NULL) {
  ------------------
  |  Branch (737:9): [True: 2, False: 0]
  ------------------
  738|      2|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      2|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  739|      2|    }
  740|       |
  741|      2|    return rv;
  742|      2|}
pk11pk12.c:prepare_rsa_priv_key_export_for_asn1:
  221|      1|{
  222|      1|    key->u.rsa.modulus.type = siUnsignedInteger;
  223|      1|    key->u.rsa.publicExponent.type = siUnsignedInteger;
  224|      1|    key->u.rsa.privateExponent.type = siUnsignedInteger;
  225|      1|    key->u.rsa.prime1.type = siUnsignedInteger;
  226|      1|    key->u.rsa.prime2.type = siUnsignedInteger;
  227|      1|    key->u.rsa.exponent1.type = siUnsignedInteger;
  228|      1|    key->u.rsa.exponent2.type = siUnsignedInteger;
  229|      1|    key->u.rsa.coefficient.type = siUnsignedInteger;
  230|      1|}
pk11pk12.c:prepare_ec_priv_key_export_for_asn1:
  251|      1|{
  252|      1|    key->u.ec.version.type = siUnsignedInteger;
  253|      1|    key->u.ec.curveOID.type = siUnsignedInteger;
  254|      1|    key->u.ec.privateValue.type = siUnsignedInteger;
  255|      1|    key->u.ec.publicValue.type = siUnsignedInteger;
  256|      1|}

pk11sdr_Init:
  126|      1|{
  127|      1|    pk11sdrLock = PR_NewLock();
  128|      1|}
pk11sdr_Shutdown:
  132|      1|{
  133|      1|    if (pk11sdrLock) {
  ------------------
  |  Branch (133:9): [True: 1, False: 0]
  ------------------
  134|      1|        PR_DestroyLock(pk11sdrLock);
  135|      1|        pk11sdrLock = NULL;
  136|      1|    }
  137|      1|}

PK11_CleanKeyList:
  114|      2|{
  115|      2|    PK11SymKey *symKey = NULL;
  116|       |
  117|     19|    while (slot->freeSymKeysWithSessionHead) {
  ------------------
  |  Branch (117:12): [True: 17, False: 2]
  ------------------
  118|     17|        symKey = slot->freeSymKeysWithSessionHead;
  119|     17|        slot->freeSymKeysWithSessionHead = symKey->next;
  120|     17|        pk11_CloseSession(slot, symKey->session, symKey->sessionOwner);
  121|     17|        PORT_Free(symKey);
  ------------------
  |  |   60|     17|#define PORT_Free PORT_Free_Util
  ------------------
  122|     17|    }
  123|     10|    while (slot->freeSymKeysHead) {
  ------------------
  |  Branch (123:12): [True: 8, False: 2]
  ------------------
  124|      8|        symKey = slot->freeSymKeysHead;
  125|      8|        slot->freeSymKeysHead = symKey->next;
  126|      8|        pk11_CloseSession(slot, symKey->session, symKey->sessionOwner);
  127|      8|        PORT_Free(symKey);
  ------------------
  |  |   60|      8|#define PORT_Free PORT_Free_Util
  ------------------
  128|      8|    }
  129|      2|    return;
  130|      2|}
PK11_FreeSymKey:
  184|  3.38M|{
  185|  3.38M|    PK11SlotInfo *slot;
  186|  3.38M|    PRBool freeit = PR_TRUE;
  ------------------
  |  |  437|  3.38M|#define PR_TRUE 1
  ------------------
  187|       |
  188|  3.38M|    if (!symKey) {
  ------------------
  |  Branch (188:9): [True: 728k, False: 2.65M]
  ------------------
  189|   728k|        return;
  190|   728k|    }
  191|       |
  192|  2.65M|    if (PR_ATOMIC_DECREMENT(&symKey->refCount) == 0) {
  ------------------
  |  |  123|  2.65M|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (192:9): [True: 1.25M, False: 1.40M]
  ------------------
  193|  1.25M|        PK11SymKey *parent = symKey->parent;
  194|       |
  195|  1.25M|        symKey->parent = NULL;
  196|  1.25M|        if ((symKey->owner) && symKey->objectID != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  1.25M|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (196:13): [True: 1.25M, False: 0]
  |  Branch (196:32): [True: 1.19M, False: 68.0k]
  ------------------
  197|  1.19M|            pk11_EnterKeyMonitor(symKey);
  198|  1.19M|            (void)PK11_GETTAB(symKey->slot)->C_DestroyObject(symKey->session, symKey->objectID);
  ------------------
  |  |  102|  1.19M|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  199|  1.19M|            pk11_ExitKeyMonitor(symKey);
  200|  1.19M|        }
  201|  1.25M|        if (symKey->data.data) {
  ------------------
  |  Branch (201:13): [True: 281k, False: 977k]
  ------------------
  202|   281k|            PORT_Memset(symKey->data.data, 0, symKey->data.len);
  ------------------
  |  |  182|   281k|#define PORT_Memset memset
  ------------------
  203|   281k|            PORT_Free(symKey->data.data);
  ------------------
  |  |   60|   281k|#define PORT_Free PORT_Free_Util
  ------------------
  204|   281k|        }
  205|       |        /* free any existing data */
  206|  1.25M|        if (symKey->userData && symKey->freeFunc) {
  ------------------
  |  Branch (206:13): [True: 0, False: 1.25M]
  |  Branch (206:33): [True: 0, False: 0]
  ------------------
  207|      0|            (*symKey->freeFunc)(symKey->userData);
  208|      0|        }
  209|  1.25M|        slot = symKey->slot;
  210|  1.25M|        PZ_Lock(slot->freeListLock);
  ------------------
  |  |  245|  1.25M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  211|  1.25M|        if (slot->keyCount < slot->maxKeyCount) {
  ------------------
  |  Branch (211:13): [True: 1.25M, False: 0]
  ------------------
  212|       |            /*
  213|       |             * freeSymkeysWithSessionHead contain a list of reusable
  214|       |             *  SymKey structures with valid sessions.
  215|       |             *    sessionOwner must be true.
  216|       |             *    session must be valid.
  217|       |             * freeSymKeysHead contain a list of SymKey structures without
  218|       |             *  valid session.
  219|       |             *    session must be CK_INVALID_HANDLE.
  220|       |             *    though sessionOwner is false, callers should not depend on
  221|       |             *    this fact.
  222|       |             */
  223|  1.25M|            if (symKey->sessionOwner) {
  ------------------
  |  Branch (223:17): [True: 1.04M, False: 210k]
  ------------------
  224|  1.04M|                PORT_Assert(symKey->session != CK_INVALID_HANDLE);
  ------------------
  |  |  120|  1.04M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.04M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.04M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  225|  1.04M|                symKey->next = slot->freeSymKeysWithSessionHead;
  226|  1.04M|                slot->freeSymKeysWithSessionHead = symKey;
  227|  1.04M|            } else {
  228|   210k|                symKey->session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|   210k|#define CK_INVALID_HANDLE 0
  ------------------
  229|   210k|                symKey->next = slot->freeSymKeysHead;
  230|   210k|                slot->freeSymKeysHead = symKey;
  231|   210k|            }
  232|  1.25M|            slot->keyCount++;
  233|  1.25M|            symKey->slot = NULL;
  234|  1.25M|            freeit = PR_FALSE;
  ------------------
  |  |  438|  1.25M|#define PR_FALSE 0
  ------------------
  235|  1.25M|        }
  236|  1.25M|        PZ_Unlock(slot->freeListLock);
  ------------------
  |  |  246|  1.25M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  237|  1.25M|        if (freeit) {
  ------------------
  |  Branch (237:13): [True: 0, False: 1.25M]
  ------------------
  238|      0|            pk11_CloseSession(symKey->slot, symKey->session,
  239|      0|                              symKey->sessionOwner);
  240|      0|            PORT_Free(symKey);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  241|      0|        }
  242|  1.25M|        PK11_FreeSlot(slot);
  243|       |
  244|  1.25M|        if (parent) {
  ------------------
  |  Branch (244:13): [True: 210k, False: 1.04M]
  ------------------
  245|   210k|            PK11_FreeSymKey(parent);
  246|   210k|        }
  247|  1.25M|    }
  248|  2.65M|}
PK11_ReferenceSymKey:
  252|  1.40M|{
  253|  1.40M|    PR_ATOMIC_INCREMENT(&symKey->refCount);
  ------------------
  |  |  122|  1.40M|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  254|  1.40M|    return symKey;
  255|  1.40M|}
PK11_GetMechanism:
  262|  33.9k|{
  263|  33.9k|    return symKey->type;
  264|  33.9k|}
PK11_GetSlotFromKey:
  271|  91.0k|{
  272|  91.0k|    return PK11_ReferenceSlot(symKey->slot);
  273|  91.0k|}
PK11_SymKeyFromHandle:
  324|   212k|{
  325|   212k|    PK11SymKey *symKey;
  326|   212k|    PRBool needSession = !(owner && parent);
  ------------------
  |  Branch (326:28): [True: 212k, False: 0]
  |  Branch (326:37): [True: 210k, False: 2.44k]
  ------------------
  327|       |
  328|   212k|    if (keyID == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|   212k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (328:9): [True: 0, False: 212k]
  ------------------
  329|      0|        return NULL;
  330|      0|    }
  331|       |
  332|   212k|    symKey = pk11_CreateSymKey(slot, type, owner, needSession, wincx);
  333|   212k|    if (symKey == NULL) {
  ------------------
  |  Branch (333:9): [True: 0, False: 212k]
  ------------------
  334|      0|        return NULL;
  335|      0|    }
  336|       |
  337|   212k|    symKey->objectID = keyID;
  338|   212k|    symKey->origin = origin;
  339|       |
  340|       |    /* adopt the parent's session */
  341|       |    /* This is only used by SSL. What we really want here is a session
  342|       |     * structure with a ref count so  the session goes away only after all the
  343|       |     * keys do. */
  344|   212k|    if (!needSession) {
  ------------------
  |  Branch (344:9): [True: 210k, False: 2.44k]
  ------------------
  345|   210k|        symKey->sessionOwner = PR_FALSE;
  ------------------
  |  |  438|   210k|#define PR_FALSE 0
  ------------------
  346|   210k|        symKey->session = parent->session;
  347|   210k|        symKey->parent = PK11_ReferenceSymKey(parent);
  348|       |        /* This is the only case where pk11_CreateSymKey does not explicitly
  349|       |         * check symKey->session. We need to assert here to make sure.
  350|       |         * the session isn't invalid. */
  351|   210k|        PORT_Assert(parent->session != CK_INVALID_HANDLE);
  ------------------
  |  |  120|   210k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   210k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 210k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  352|   210k|        if (parent->session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|   210k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (352:13): [True: 0, False: 210k]
  ------------------
  353|      0|            PK11_FreeSymKey(symKey);
  354|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  355|      0|            return NULL;
  356|      0|        }
  357|   210k|    }
  358|       |
  359|   212k|    return symKey;
  360|   212k|}
PK11_VerifyKeyOK:
  431|  33.9k|{
  432|  33.9k|    if (!PK11_IsPresent(key->slot)) {
  ------------------
  |  Branch (432:9): [True: 0, False: 33.9k]
  ------------------
  433|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  434|      0|    }
  435|  33.9k|    return (PRBool)(key->series == key->slot->series);
  436|  33.9k|}
PK11_ImportDataKey:
  517|  2.44k|{
  518|  2.44k|    CK_OBJECT_CLASS ckoData = CKO_DATA;
  ------------------
  |  |  325|  2.44k|#define CKO_DATA 0x00000000UL
  ------------------
  519|  2.44k|    CK_ATTRIBUTE template[2] = { { CKA_CLASS, (CK_BYTE_PTR)&ckoData, sizeof(ckoData) },
  ------------------
  |  |  511|  2.44k|#define CKA_CLASS 0x00000000UL
  ------------------
  520|  2.44k|                                 { CKA_VALUE, (CK_BYTE_PTR)key->data, key->len } };
  ------------------
  |  |  516|  2.44k|#define CKA_VALUE 0x00000011UL
  ------------------
  521|  2.44k|    CK_OBJECT_HANDLE handle;
  522|  2.44k|    PK11GenericObject *genObject;
  523|       |
  524|  2.44k|    genObject = PK11_CreateGenericObject(slot, template, PR_ARRAY_SIZE(template), PR_FALSE);
  ------------------
  |  |  167|  2.44k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
                  genObject = PK11_CreateGenericObject(slot, template, PR_ARRAY_SIZE(template), PR_FALSE);
  ------------------
  |  |  438|  2.44k|#define PR_FALSE 0
  ------------------
  525|  2.44k|    if (genObject == NULL) {
  ------------------
  |  Branch (525:9): [True: 0, False: 2.44k]
  ------------------
  526|      0|        return NULL;
  527|      0|    }
  528|  2.44k|    handle = PK11_GetObjectHandle(PK11_TypeGeneric, genObject, NULL);
  529|       |    /* A note about ownership of the PKCS #11 handle:
  530|       |     * PK11_CreateGenericObject() will not destroy the object it creates
  531|       |     * on Free, For that you want PK11_CreateManagedGenericObject().
  532|       |     * Below we import the handle into the symKey structure. We pass
  533|       |     * PR_TRUE as the owner so that the symKey will destroy the object
  534|       |     * once it's freed. This is why it's safe to destroy genObject now. */
  535|  2.44k|    PK11_DestroyGenericObject(genObject);
  536|  2.44k|    if (handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  2.44k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (536:9): [True: 0, False: 2.44k]
  ------------------
  537|      0|        return NULL;
  538|      0|    }
  539|  2.44k|    return PK11_SymKeyFromHandle(slot, NULL, origin, type, handle, PR_TRUE, wincx);
  ------------------
  |  |  437|  2.44k|#define PR_TRUE 1
  ------------------
  540|  2.44k|}
PK11_ImportSymKeyWithFlags:
  547|  1.21k|{
  548|  1.21k|    PK11SymKey *symKey;
  549|  1.21k|    unsigned int templateCount = 0;
  550|  1.21k|    CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|  1.21k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  551|  1.21k|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  1.21k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  552|  1.21k|    CK_BBOOL cktrue = CK_TRUE; /* sigh */
  ------------------
  |  |   22|  1.21k|#define CK_TRUE 1
  ------------------
  553|  1.21k|    CK_ATTRIBUTE keyTemplate[MAX_TEMPL_ATTRS];
  554|  1.21k|    CK_ATTRIBUTE *attrs = keyTemplate;
  555|       |
  556|       |    /* CKA_NSS_MESSAGE is a fake operation to distinguish between
  557|       |     * Normal Encrypt/Decrypt and MessageEncrypt/Decrypt. Don't try to set
  558|       |     * it as a real attribute */
  559|  1.21k|    if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|  1.21k|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|  1.21k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (559:9): [True: 0, False: 1.21k]
  ------------------
  560|       |        /* Message is or'd with a real Attribute (CKA_ENCRYPT, CKA_DECRYPT),
  561|       |         * etc. Strip out the real attribute here */
  562|      0|        operation &= ~CKA_NSS_MESSAGE_MASK;
  ------------------
  |  |   70|      0|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
  563|      0|    }
  564|       |
  565|  1.21k|    PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|  1.21k|    (x)->type = (id);              \
  |  |  105|  1.21k|    (x)->pValue = (v);             \
  |  |  106|  1.21k|    (x)->ulValueLen = (l);
  ------------------
  566|  1.21k|    attrs++;
  567|  1.21k|    PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|  1.21k|    (x)->type = (id);              \
  |  |  105|  1.21k|    (x)->pValue = (v);             \
  |  |  106|  1.21k|    (x)->ulValueLen = (l);
  ------------------
  568|  1.21k|    attrs++;
  569|  1.21k|    if (isPerm) {
  ------------------
  |  Branch (569:9): [True: 0, False: 1.21k]
  ------------------
  570|      0|        PK11_SETATTRS(attrs, CKA_TOKEN, &cktrue, sizeof(cktrue));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  571|      0|        attrs++;
  572|       |        /* sigh some tokens think CKA_PRIVATE = false is a reasonable
  573|       |         * default for secret keys */
  574|      0|        PK11_SETATTRS(attrs, CKA_PRIVATE, &cktrue, sizeof(cktrue));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
  575|      0|        attrs++;
  576|      0|    }
  577|  1.21k|    attrs += pk11_OpFlagsToAttributes(flags, attrs, &cktrue);
  578|  1.21k|    if ((operation != CKA_FLAGS_ONLY) &&
  ------------------
  |  |   71|  1.21k|#define CKA_FLAGS_ONLY 0 /* CKA_CLASS */
  ------------------
  |  Branch (578:9): [True: 1.21k, False: 0]
  ------------------
  579|  1.21k|        !pk11_FindAttrInTemplate(keyTemplate, attrs - keyTemplate, operation)) {
  ------------------
  |  Branch (579:9): [True: 1.21k, False: 0]
  ------------------
  580|  1.21k|        PK11_SETATTRS(attrs, operation, &cktrue, sizeof(cktrue));
  ------------------
  |  |  104|  1.21k|    (x)->type = (id);              \
  |  |  105|  1.21k|    (x)->pValue = (v);             \
  |  |  106|  1.21k|    (x)->ulValueLen = (l);
  ------------------
  581|  1.21k|        attrs++;
  582|  1.21k|    }
  583|  1.21k|    templateCount = attrs - keyTemplate;
  584|  1.21k|    PR_ASSERT(templateCount + 1 <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  ------------------
  ------------------
  585|       |
  586|  1.21k|    keyType = PK11_GetKeyType(type, key->len);
  587|  1.21k|    symKey = pk11_ImportSymKeyWithTempl(slot, type, origin, isPerm,
  588|  1.21k|                                        keyTemplate, templateCount, key, wincx);
  589|  1.21k|    if (symKey && isPerm) {
  ------------------
  |  Branch (589:9): [True: 1.21k, False: 0]
  |  Branch (589:19): [True: 0, False: 1.21k]
  ------------------
  590|      0|        symKey->owner = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  591|      0|    }
  592|  1.21k|    return symKey;
  593|  1.21k|}
PK11_ExtractKeyValue:
  692|   279k|{
  693|   279k|    SECStatus rv;
  694|       |
  695|   279k|    if (symKey == NULL) {
  ------------------
  |  Branch (695:9): [True: 0, False: 279k]
  ------------------
  696|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  697|      0|        return SECFailure;
  698|      0|    }
  699|       |
  700|   279k|    if (symKey->data.data != NULL) {
  ------------------
  |  Branch (700:9): [True: 0, False: 279k]
  ------------------
  701|      0|        if (symKey->size == 0) {
  ------------------
  |  Branch (701:13): [True: 0, False: 0]
  ------------------
  702|      0|            symKey->size = symKey->data.len;
  703|      0|        }
  704|      0|        return SECSuccess;
  705|      0|    }
  706|       |
  707|   279k|    if (symKey->slot == NULL) {
  ------------------
  |  Branch (707:9): [True: 0, False: 279k]
  ------------------
  708|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  709|      0|        return SECFailure;
  710|      0|    }
  711|       |
  712|   279k|    rv = PK11_ReadAttribute(symKey->slot, symKey->objectID, CKA_VALUE, NULL,
  ------------------
  |  |  516|   279k|#define CKA_VALUE 0x00000011UL
  ------------------
  713|   279k|                            &symKey->data);
  714|   279k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (714:9): [True: 279k, False: 0]
  ------------------
  715|   279k|        symKey->size = symKey->data.len;
  716|   279k|    }
  717|   279k|    return rv;
  718|   279k|}
PK11_GetKeyData:
  733|   278k|{
  734|   278k|    return &symKey->data;
  735|   278k|}
pk11_GetPredefinedKeyLength:
  749|  17.5k|{
  750|  17.5k|    int length = 0;
  751|  17.5k|    switch (keyType) {
  752|      0|        case CKK_DES:
  ------------------
  |  |  386|      0|#define CKK_DES 0x00000013UL
  ------------------
  |  Branch (752:9): [True: 0, False: 17.5k]
  ------------------
  753|      0|            length = 8;
  754|      0|            break;
  755|      0|        case CKK_DES2:
  ------------------
  |  |  387|      0|#define CKK_DES2 0x00000014UL
  ------------------
  |  Branch (755:9): [True: 0, False: 17.5k]
  ------------------
  756|      0|            length = 16;
  757|      0|            break;
  758|      1|        case CKK_DES3:
  ------------------
  |  |  388|      1|#define CKK_DES3 0x00000015UL
  ------------------
  |  Branch (758:9): [True: 1, False: 17.5k]
  ------------------
  759|      1|            length = 24;
  760|      1|            break;
  761|      0|        case CKK_SKIPJACK:
  ------------------
  |  |  398|      0|#define CKK_SKIPJACK 0x0000001BUL
  ------------------
  |  Branch (761:9): [True: 0, False: 17.5k]
  ------------------
  762|      0|            length = 10;
  763|      0|            break;
  764|      0|        case CKK_BATON:
  ------------------
  |  |  399|      0|#define CKK_BATON 0x0000001CUL
  ------------------
  |  Branch (764:9): [True: 0, False: 17.5k]
  ------------------
  765|      0|            length = 20;
  766|      0|            break;
  767|      0|        case CKK_JUNIPER:
  ------------------
  |  |  400|      0|#define CKK_JUNIPER 0x0000001DUL
  ------------------
  |  Branch (767:9): [True: 0, False: 17.5k]
  ------------------
  768|      0|            length = 20;
  769|      0|            break;
  770|  17.5k|        default:
  ------------------
  |  Branch (770:9): [True: 17.5k, False: 1]
  ------------------
  771|  17.5k|            break;
  772|  17.5k|    }
  773|  17.5k|    return length;
  774|  17.5k|}
pk11_CopyToSlotPerm:
  903|  1.21k|{
  904|  1.21k|    SECStatus rv;
  905|  1.21k|    PK11SymKey *newKey = NULL;
  906|       |
  907|       |    /* Extract the raw key data if possible */
  908|  1.21k|    if (symKey->data.data == NULL) {
  ------------------
  |  Branch (908:9): [True: 1.21k, False: 0]
  ------------------
  909|  1.21k|        rv = PK11_ExtractKeyValue(symKey);
  910|       |        /* KEY is sensitive, we're try key exchanging it. */
  911|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (911:13): [True: 0, False: 1.21k]
  ------------------
  912|      0|            return pk11_KeyExchange(slot, type, operation,
  913|      0|                                    flags, isPerm, symKey);
  914|      0|        }
  915|  1.21k|    }
  916|       |
  917|  1.21k|    newKey = PK11_ImportSymKeyWithFlags(slot, type, symKey->origin,
  918|  1.21k|                                        operation, &symKey->data, flags, isPerm, symKey->cx);
  919|  1.21k|    if (newKey == NULL) {
  ------------------
  |  Branch (919:9): [True: 0, False: 1.21k]
  ------------------
  920|      0|        newKey = pk11_KeyExchange(slot, type, operation, flags, isPerm, symKey);
  921|      0|    }
  922|  1.21k|    return newKey;
  923|  1.21k|}
pk11_CopyToSlot:
  928|  1.21k|{
  929|  1.21k|    return pk11_CopyToSlotPerm(slot, type, operation, 0, PR_FALSE, symKey);
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
  930|  1.21k|}
pk11_ForceSlotMultiple:
  939|   543k|{
  940|   543k|    PK11SlotInfo *slot = symKey->slot;
  941|   543k|    PK11SymKey *newKey = NULL;
  942|   543k|    PRBool needToCopy = PR_FALSE;
  ------------------
  |  |  438|   543k|#define PR_FALSE 0
  ------------------
  943|   543k|    int i;
  944|       |
  945|   543k|    if (slot == NULL) {
  ------------------
  |  Branch (945:9): [True: 0, False: 543k]
  ------------------
  946|      0|        needToCopy = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  947|   543k|    } else {
  948|   543k|        i = 0;
  949|  1.08M|        while ((i < mechCount) && (needToCopy == PR_FALSE)) {
  ------------------
  |  |  438|   543k|#define PR_FALSE 0
  ------------------
  |  Branch (949:16): [True: 543k, False: 543k]
  |  Branch (949:35): [True: 543k, False: 0]
  ------------------
  950|   543k|            if (!PK11_DoesMechanism(slot, type[i])) {
  ------------------
  |  Branch (950:17): [True: 0, False: 543k]
  ------------------
  951|      0|                needToCopy = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  952|      0|            }
  953|   543k|            i++;
  954|   543k|        }
  955|   543k|    }
  956|       |
  957|   543k|    if (needToCopy == PR_TRUE) {
  ------------------
  |  |  437|   543k|#define PR_TRUE 1
  ------------------
  |  Branch (957:9): [True: 0, False: 543k]
  ------------------
  958|      0|        slot = PK11_GetBestSlotMultiple(type, mechCount, symKey->cx);
  959|      0|        if (slot == NULL) {
  ------------------
  |  Branch (959:13): [True: 0, False: 0]
  ------------------
  960|      0|            PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  961|      0|            return NULL;
  962|      0|        }
  963|      0|        newKey = pk11_CopyToSlot(slot, type[0], operation, symKey);
  964|      0|        PK11_FreeSlot(slot);
  965|      0|    }
  966|   543k|    return newKey;
  967|   543k|}
pk11_ForceSlot:
  975|   543k|{
  976|   543k|    return pk11_ForceSlotMultiple(symKey, &type, 1, operation);
  977|   543k|}
pk11_TokenKeyGenWithFlagsAndKeyType:
 1020|  16.7k|{
 1021|  16.7k|    PK11SymKey *symKey;
 1022|  16.7k|    CK_ATTRIBUTE genTemplate[MAX_TEMPL_ATTRS];
 1023|  16.7k|    CK_ATTRIBUTE *attrs = genTemplate;
 1024|  16.7k|    int count = sizeof(genTemplate) / sizeof(genTemplate[0]);
 1025|  16.7k|    CK_MECHANISM_TYPE keyGenType;
 1026|  16.7k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  16.7k|#define CK_TRUE 1
  ------------------
 1027|  16.7k|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  16.7k|#define CK_FALSE 0
  ------------------
 1028|  16.7k|    CK_ULONG ck_key_size; /* only used for variable-length keys */
 1029|       |
 1030|  16.7k|    if (pk11_BadAttrFlags(attrFlags)) {
  ------------------
  |  Branch (1030:9): [True: 0, False: 16.7k]
  ------------------
 1031|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1032|      0|        return NULL;
 1033|      0|    }
 1034|       |
 1035|  16.7k|    if ((keySize != 0) && (type != CKM_DES3_CBC) &&
  ------------------
  |  |  826|  4.72k|#define CKM_DES3_CBC 0x00000133UL
  ------------------
  |  Branch (1035:9): [True: 4.72k, False: 11.9k]
  |  Branch (1035:27): [True: 4.72k, False: 0]
  ------------------
 1036|  16.7k|        (type != CKM_DES3_CBC_PAD) && (type != CKM_DES3_ECB)) {
  ------------------
  |  |  833|  4.72k|#define CKM_DES3_CBC_PAD 0x00000136UL
  ------------------
                      (type != CKM_DES3_CBC_PAD) && (type != CKM_DES3_ECB)) {
  ------------------
  |  |  825|  4.72k|#define CKM_DES3_ECB 0x00000132UL
  ------------------
  |  Branch (1036:9): [True: 4.72k, False: 0]
  |  Branch (1036:39): [True: 4.72k, False: 0]
  ------------------
 1037|  4.72k|        ck_key_size = keySize; /* Convert to PK11 type */
 1038|       |
 1039|  4.72k|        PK11_SETATTRS(attrs, CKA_VALUE_LEN, &ck_key_size, sizeof(ck_key_size));
  ------------------
  |  |  104|  4.72k|    (x)->type = (id);              \
  |  |  105|  4.72k|    (x)->pValue = (v);             \
  |  |  106|  4.72k|    (x)->ulValueLen = (l);
  ------------------
 1040|  4.72k|        attrs++;
 1041|  4.72k|    }
 1042|       |
 1043|  16.7k|    if (keyType != -1) {
  ------------------
  |  Branch (1043:9): [True: 0, False: 16.7k]
  ------------------
 1044|      0|        PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(CK_KEY_TYPE));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1045|      0|        attrs++;
 1046|      0|    }
 1047|       |
 1048|       |    /* Include key id value if provided */
 1049|  16.7k|    if (keyid) {
  ------------------
  |  Branch (1049:9): [True: 0, False: 16.7k]
  ------------------
 1050|      0|        PK11_SETATTRS(attrs, CKA_ID, keyid->data, keyid->len);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 1051|      0|        attrs++;
 1052|      0|    }
 1053|       |
 1054|  16.7k|    attrs += pk11_AttrFlagsToAttributes(attrFlags, attrs, &cktrue, &ckfalse);
 1055|  16.7k|    attrs += pk11_OpFlagsToAttributes(opFlags, attrs, &cktrue);
 1056|       |
 1057|  16.7k|    count = attrs - genTemplate;
 1058|  16.7k|    PR_ASSERT(count <= sizeof(genTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  16.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 16.7k, False: 0]
  |  |  ------------------
  ------------------
 1059|       |
 1060|  16.7k|    keyGenType = PK11_GetKeyGenWithSize(type, keySize);
 1061|  16.7k|    if (keyGenType == CKM_FAKE_RANDOM) {
  ------------------
  |  |  154|  16.7k|#define CKM_FAKE_RANDOM 0x80000efeUL
  ------------------
  |  Branch (1061:9): [True: 0, False: 16.7k]
  ------------------
 1062|      0|        PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1063|      0|        return NULL;
 1064|      0|    }
 1065|  16.7k|    symKey = PK11_KeyGenWithTemplate(slot, type, keyGenType,
 1066|  16.7k|                                     param, genTemplate, count, wincx);
 1067|  16.7k|    if (symKey != NULL) {
  ------------------
  |  Branch (1067:9): [True: 16.7k, False: 0]
  ------------------
 1068|  16.7k|        symKey->size = keySize;
 1069|  16.7k|    }
 1070|  16.7k|    return symKey;
 1071|  16.7k|}
PK11_TokenKeyGen:
 1108|  16.7k|{
 1109|  16.7k|    PK11SymKey *symKey;
 1110|  16.7k|    PRBool weird = PR_FALSE; /* hack for fortezza */
  ------------------
  |  |  438|  16.7k|#define PR_FALSE 0
  ------------------
 1111|  16.7k|    CK_FLAGS opFlags = CKF_SIGN;
  ------------------
  |  | 1356|  16.7k|#define CKF_SIGN 0x00000800UL
  ------------------
 1112|  16.7k|    PK11AttrFlags attrFlags = 0;
 1113|       |
 1114|  16.7k|    if ((keySize == -1) && (type == CKM_SKIPJACK_CBC64)) {
  ------------------
  |  | 1049|      0|#define CKM_SKIPJACK_CBC64 0x00001002UL
  ------------------
  |  Branch (1114:9): [True: 0, False: 16.7k]
  |  Branch (1114:28): [True: 0, False: 0]
  ------------------
 1115|      0|        weird = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1116|      0|        keySize = 0;
 1117|      0|    }
 1118|       |
 1119|  16.7k|    opFlags |= weird ? CKF_DECRYPT : CKF_ENCRYPT;
  ------------------
  |  | 1354|      0|#define CKF_DECRYPT 0x00000200UL
  ------------------
                  opFlags |= weird ? CKF_DECRYPT : CKF_ENCRYPT;
  ------------------
  |  | 1353|  33.4k|#define CKF_ENCRYPT 0x00000100UL
  ------------------
  |  Branch (1119:16): [True: 0, False: 16.7k]
  ------------------
 1120|       |
 1121|  16.7k|    if (isToken) {
  ------------------
  |  Branch (1121:9): [True: 0, False: 16.7k]
  ------------------
 1122|      0|        attrFlags |= (PK11_ATTR_TOKEN | PK11_ATTR_PRIVATE);
  ------------------
  |  |  194|      0|#define PK11_ATTR_TOKEN 0x00000001L
  ------------------
                      attrFlags |= (PK11_ATTR_TOKEN | PK11_ATTR_PRIVATE);
  ------------------
  |  |  216|      0|#define PK11_ATTR_PRIVATE 0x00000004L
  ------------------
 1123|      0|    }
 1124|       |
 1125|  16.7k|    symKey = pk11_TokenKeyGenWithFlagsAndKeyType(slot, type, param,
 1126|  16.7k|                                                 -1, keySize, keyid, opFlags, attrFlags, wincx);
 1127|  16.7k|    if (symKey && weird) {
  ------------------
  |  Branch (1127:9): [True: 16.7k, False: 0]
  |  Branch (1127:19): [True: 0, False: 16.7k]
  ------------------
 1128|      0|        PK11_SetFortezzaHack(symKey);
 1129|      0|    }
 1130|       |
 1131|  16.7k|    return symKey;
 1132|  16.7k|}
PK11_KeyGen:
 1137|  16.7k|{
 1138|  16.7k|    return PK11_TokenKeyGen(slot, type, param, keySize, 0, PR_FALSE, wincx);
  ------------------
  |  |  438|  16.7k|#define PR_FALSE 0
  ------------------
 1139|  16.7k|}
PK11_KeyGenWithTemplate:
 1146|  16.7k|{
 1147|  16.7k|    PK11SymKey *symKey;
 1148|  16.7k|    CK_SESSION_HANDLE session;
 1149|  16.7k|    CK_MECHANISM mechanism;
 1150|  16.7k|    CK_RV crv;
 1151|  16.7k|    PRBool isToken = CK_FALSE;
  ------------------
  |  |   23|  16.7k|#define CK_FALSE 0
  ------------------
 1152|  16.7k|    CK_ULONG keySize = 0;
 1153|  16.7k|    unsigned i;
 1154|       |
 1155|       |    /* Extract the template's CKA_VALUE_LEN into keySize and CKA_TOKEN into
 1156|       |       isToken. */
 1157|  54.8k|    for (i = 0; i < attrsCount; ++i) {
  ------------------
  |  Branch (1157:17): [True: 38.1k, False: 16.7k]
  ------------------
 1158|  38.1k|        switch (attrs[i].type) {
  ------------------
  |  Branch (1158:17): [True: 33.4k, False: 4.72k]
  ------------------
 1159|  4.72k|            case CKA_VALUE_LEN:
  ------------------
  |  |  580|  4.72k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (1159:13): [True: 4.72k, False: 33.4k]
  ------------------
 1160|  4.72k|                if (attrs[i].pValue == NULL ||
  ------------------
  |  Branch (1160:21): [True: 0, False: 4.72k]
  ------------------
 1161|  4.72k|                    attrs[i].ulValueLen != sizeof(CK_ULONG)) {
  ------------------
  |  Branch (1161:21): [True: 0, False: 4.72k]
  ------------------
 1162|      0|                    PORT_SetError(PK11_MapError(CKR_TEMPLATE_INCONSISTENT));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                                  PORT_SetError(PK11_MapError(CKR_TEMPLATE_INCONSISTENT));
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 1163|      0|                    return NULL;
 1164|      0|                }
 1165|  4.72k|                keySize = *(CK_ULONG *)attrs[i].pValue;
 1166|  4.72k|                break;
 1167|      0|            case CKA_TOKEN:
  ------------------
  |  |  512|      0|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (1167:13): [True: 0, False: 38.1k]
  ------------------
 1168|      0|                if (attrs[i].pValue == NULL ||
  ------------------
  |  Branch (1168:21): [True: 0, False: 0]
  ------------------
 1169|      0|                    attrs[i].ulValueLen != sizeof(CK_BBOOL)) {
  ------------------
  |  Branch (1169:21): [True: 0, False: 0]
  ------------------
 1170|      0|                    PORT_SetError(PK11_MapError(CKR_TEMPLATE_INCONSISTENT));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                                  PORT_SetError(PK11_MapError(CKR_TEMPLATE_INCONSISTENT));
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 1171|      0|                    return NULL;
 1172|      0|                }
 1173|      0|                isToken = (*(CK_BBOOL *)attrs[i].pValue) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                              isToken = (*(CK_BBOOL *)attrs[i].pValue) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (1173:27): [True: 0, False: 0]
  ------------------
 1174|      0|                break;
 1175|  38.1k|        }
 1176|  38.1k|    }
 1177|       |
 1178|       |    /* find a slot to generate the key into */
 1179|       |    /* Only do slot management if this is not a token key */
 1180|  16.7k|    if (!isToken && (slot == NULL || !PK11_DoesMechanism(slot, type))) {
  ------------------
  |  Branch (1180:9): [True: 16.7k, False: 0]
  |  Branch (1180:22): [True: 0, False: 16.7k]
  |  Branch (1180:38): [True: 0, False: 16.7k]
  ------------------
 1181|      0|        PK11SlotInfo *bestSlot = PK11_GetBestSlot(type, wincx);
 1182|      0|        if (bestSlot == NULL) {
  ------------------
  |  Branch (1182:13): [True: 0, False: 0]
  ------------------
 1183|      0|            PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1184|      0|            return NULL;
 1185|      0|        }
 1186|      0|        symKey = pk11_CreateSymKey(bestSlot, type, !isToken, PR_TRUE, wincx);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1187|      0|        PK11_FreeSlot(bestSlot);
 1188|  16.7k|    } else {
 1189|  16.7k|        symKey = pk11_CreateSymKey(slot, type, !isToken, PR_TRUE, wincx);
  ------------------
  |  |  437|  16.7k|#define PR_TRUE 1
  ------------------
 1190|  16.7k|    }
 1191|  16.7k|    if (symKey == NULL)
  ------------------
  |  Branch (1191:9): [True: 0, False: 16.7k]
  ------------------
 1192|      0|        return NULL;
 1193|       |
 1194|  16.7k|    symKey->size = keySize;
 1195|  16.7k|    symKey->origin = PK11_OriginGenerated;
 1196|       |
 1197|       |    /* Set the parameters for the key gen if provided */
 1198|  16.7k|    mechanism.mechanism = keyGenType;
 1199|  16.7k|    mechanism.pParameter = NULL;
 1200|  16.7k|    mechanism.ulParameterLen = 0;
 1201|  16.7k|    if (param) {
  ------------------
  |  Branch (1201:9): [True: 11.9k, False: 4.72k]
  ------------------
 1202|  11.9k|        mechanism.pParameter = param->data;
 1203|  11.9k|        mechanism.ulParameterLen = param->len;
 1204|  11.9k|    }
 1205|       |
 1206|       |    /* Get session and perform locking */
 1207|  16.7k|    if (isToken) {
  ------------------
  |  Branch (1207:9): [True: 0, False: 16.7k]
  ------------------
 1208|      0|        PK11_Authenticate(symKey->slot, PR_TRUE, wincx);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1209|       |        /* Should always be original slot */
 1210|      0|        session = PK11_GetRWSession(symKey->slot);
 1211|      0|        symKey->owner = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1212|  16.7k|    } else {
 1213|  16.7k|        session = symKey->session;
 1214|  16.7k|        if (session != CK_INVALID_HANDLE)
  ------------------
  |  |   78|  16.7k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1214:13): [True: 16.7k, False: 0]
  ------------------
 1215|  16.7k|            pk11_EnterKeyMonitor(symKey);
 1216|  16.7k|    }
 1217|  16.7k|    if (session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  16.7k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1217:9): [True: 0, False: 16.7k]
  ------------------
 1218|      0|        PK11_FreeSymKey(symKey);
 1219|      0|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1220|      0|        return NULL;
 1221|      0|    }
 1222|       |
 1223|  16.7k|    crv = PK11_GETTAB(symKey->slot)->C_GenerateKey(session, &mechanism, attrs, attrsCount, &symKey->objectID);
  ------------------
  |  |  102|  16.7k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1224|       |
 1225|       |    /* Release lock and session */
 1226|  16.7k|    if (isToken) {
  ------------------
  |  Branch (1226:9): [True: 0, False: 16.7k]
  ------------------
 1227|      0|        PK11_RestoreROSession(symKey->slot, session);
 1228|  16.7k|    } else {
 1229|  16.7k|        pk11_ExitKeyMonitor(symKey);
 1230|  16.7k|    }
 1231|       |
 1232|  16.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1232:9): [True: 0, False: 16.7k]
  ------------------
 1233|      0|        PK11_FreeSymKey(symKey);
 1234|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1235|      0|        return NULL;
 1236|      0|    }
 1237|       |
 1238|  16.7k|    return symKey;
 1239|  16.7k|}
PK11_PubWrapSymKey:
 1286|      3|{
 1287|      3|    CK_MECHANISM_TYPE inferred = pk11_mapWrapKeyType(pubKey->keyType);
 1288|      3|    return PK11_PubWrapSymKeyWithMechanism(pubKey, inferred, NULL, symKey,
 1289|      3|                                           wrappedKey);
 1290|      3|}
PK11_PubWrapSymKeyWithMechanism:
 1298|      3|{
 1299|      3|    PK11SlotInfo *slot;
 1300|      3|    CK_ULONG len = wrappedKey->len;
 1301|      3|    PK11SymKey *newKey = NULL;
 1302|      3|    CK_OBJECT_HANDLE id;
 1303|      3|    CK_MECHANISM mechanism;
 1304|      3|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
 1305|      3|    CK_SESSION_HANDLE session;
 1306|      3|    CK_RV crv;
 1307|       |
 1308|      3|    if (symKey == NULL) {
  ------------------
  |  Branch (1308:9): [True: 0, False: 3]
  ------------------
 1309|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1310|      0|        return SECFailure;
 1311|      0|    }
 1312|       |
 1313|       |    /* if this slot doesn't support the mechanism, go to a slot that does */
 1314|      3|    newKey = pk11_ForceSlot(symKey, mechType, CKA_ENCRYPT);
  ------------------
  |  |  547|      3|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1315|      3|    if (newKey != NULL) {
  ------------------
  |  Branch (1315:9): [True: 0, False: 3]
  ------------------
 1316|      0|        symKey = newKey;
 1317|      0|    }
 1318|       |
 1319|      3|    if (symKey->slot == NULL) {
  ------------------
  |  Branch (1319:9): [True: 0, False: 3]
  ------------------
 1320|      0|        PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1321|      0|        return SECFailure;
 1322|      0|    }
 1323|       |
 1324|      3|    slot = symKey->slot;
 1325|       |
 1326|      3|    mechanism.mechanism = mechType;
 1327|      3|    if (param == NULL) {
  ------------------
  |  Branch (1327:9): [True: 3, False: 0]
  ------------------
 1328|      3|        mechanism.pParameter = NULL;
 1329|      3|        mechanism.ulParameterLen = 0;
 1330|      3|    } else {
 1331|      0|        mechanism.pParameter = param->data;
 1332|      0|        mechanism.ulParameterLen = param->len;
 1333|      0|    }
 1334|       |
 1335|      3|    id = PK11_ImportPublicKey(slot, pubKey, PR_FALSE);
  ------------------
  |  |  438|      3|#define PR_FALSE 0
  ------------------
 1336|      3|    if (id == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      3|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1336:9): [True: 0, False: 3]
  ------------------
 1337|      0|        if (newKey) {
  ------------------
  |  Branch (1337:13): [True: 0, False: 0]
  ------------------
 1338|      0|            PK11_FreeSymKey(newKey);
 1339|      0|        }
 1340|      0|        return SECFailure; /* Error code has been set. */
 1341|      0|    }
 1342|       |
 1343|      3|    session = pk11_GetNewSession(slot, &owner);
 1344|      3|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (1344:9): [True: 0, False: 3]
  |  Branch (1344:19): [True: 0, False: 3]
  ------------------
 1345|      0|        PK11_EnterSlotMonitor(slot);
 1346|      3|    crv = PK11_GETTAB(slot)->C_WrapKey(session, &mechanism,
  ------------------
  |  |  102|      3|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1347|      3|                                       id, symKey->objectID, wrappedKey->data, &len);
 1348|      3|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (1348:9): [True: 0, False: 3]
  |  Branch (1348:19): [True: 0, False: 3]
  ------------------
 1349|      0|        PK11_ExitSlotMonitor(slot);
 1350|      3|    pk11_CloseSession(slot, session, owner);
 1351|      3|    if (newKey) {
  ------------------
  |  Branch (1351:9): [True: 0, False: 3]
  ------------------
 1352|      0|        PK11_FreeSymKey(newKey);
 1353|      0|    }
 1354|       |
 1355|      3|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      3|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1355:9): [True: 0, False: 3]
  ------------------
 1356|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1357|      0|        return SECFailure;
 1358|      0|    }
 1359|      3|    wrappedKey->len = len;
 1360|      3|    return SECSuccess;
 1361|      3|}
PK11_SymKeysToSameSlot:
 1486|  35.2k|{
 1487|       |    /* usually don't return new keys */
 1488|  35.2k|    *newMovingKey = NULL;
 1489|  35.2k|    *newPreferedKey = NULL;
 1490|  35.2k|    if (movingKey->slot == preferedKey->slot) {
  ------------------
  |  Branch (1490:9): [True: 34.0k, False: 1.21k]
  ------------------
 1491|       |
 1492|       |        /* this should be the most common case */
 1493|  34.0k|        if ((preferedKey->slot != NULL) &&
  ------------------
  |  Branch (1493:13): [True: 34.0k, False: 0]
  ------------------
 1494|  34.0k|            PK11_DoesMechanism(preferedKey->slot, mech)) {
  ------------------
  |  Branch (1494:13): [True: 34.0k, False: 0]
  ------------------
 1495|  34.0k|            return SECSuccess;
 1496|  34.0k|        }
 1497|       |
 1498|       |        /* we are in the same slot, but it doesn't do the operation,
 1499|       |         * move both keys to an appropriate target slot */
 1500|      0|        return pk11_moveTwoKeys(mech, preferedOperation, movingOperation,
 1501|      0|                                preferedKey, movingKey,
 1502|      0|                                newPreferedKey, newMovingKey);
 1503|  34.0k|    }
 1504|       |
 1505|       |    /* keys are in different slot, try moving the moving key to the prefered
 1506|       |     * key's slot */
 1507|  1.21k|    if ((preferedKey->slot != NULL) &&
  ------------------
  |  Branch (1507:9): [True: 1.21k, False: 0]
  ------------------
 1508|  1.21k|        PK11_DoesMechanism(preferedKey->slot, mech)) {
  ------------------
  |  Branch (1508:9): [True: 1.21k, False: 0]
  ------------------
 1509|  1.21k|        *newMovingKey = pk11_CopyToSlot(preferedKey->slot, movingKey->type,
 1510|  1.21k|                                        movingOperation, movingKey);
 1511|  1.21k|        if (*newMovingKey != NULL) {
  ------------------
  |  Branch (1511:13): [True: 1.21k, False: 0]
  ------------------
 1512|  1.21k|            return SECSuccess;
 1513|  1.21k|        }
 1514|  1.21k|    }
 1515|       |    /* couldn't moving the moving key to the prefered slot, try moving
 1516|       |     * the prefered key */
 1517|      0|    if ((movingKey->slot != NULL) &&
  ------------------
  |  Branch (1517:9): [True: 0, False: 0]
  ------------------
 1518|      0|        PK11_DoesMechanism(movingKey->slot, mech)) {
  ------------------
  |  Branch (1518:9): [True: 0, False: 0]
  ------------------
 1519|      0|        *newPreferedKey = pk11_CopyToSlot(movingKey->slot, preferedKey->type,
 1520|      0|                                          preferedOperation, preferedKey);
 1521|      0|        if (*newPreferedKey != NULL) {
  ------------------
  |  Branch (1521:13): [True: 0, False: 0]
  ------------------
 1522|      0|            return SECSuccess;
 1523|      0|        }
 1524|      0|    }
 1525|       |    /* Neither succeeded, but that could be that they were not in slots that
 1526|       |     * supported the operation, try moving both keys into a common slot that
 1527|       |     * can do the operation. */
 1528|      0|    return pk11_moveTwoKeys(mech, preferedOperation, movingOperation,
 1529|      0|                            preferedKey, movingKey,
 1530|      0|                            newPreferedKey, newMovingKey);
 1531|      0|}
PK11_WrapSymKey:
 1540|  33.9k|{
 1541|  33.9k|    PK11SlotInfo *slot;
 1542|  33.9k|    CK_ULONG len = wrappedKey->len;
 1543|  33.9k|    PK11SymKey *newSymKey = NULL;
 1544|  33.9k|    PK11SymKey *newWrappingKey = NULL;
 1545|  33.9k|    SECItem *param_save = NULL;
 1546|  33.9k|    CK_MECHANISM mechanism;
 1547|  33.9k|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|  33.9k|#define PR_TRUE 1
  ------------------
 1548|  33.9k|    CK_SESSION_HANDLE session;
 1549|  33.9k|    CK_RV crv;
 1550|  33.9k|    SECStatus rv;
 1551|       |
 1552|       |    /* force the keys into same slot */
 1553|  33.9k|    rv = PK11_SymKeysToSameSlot(type, CKA_ENCRYPT, CKA_WRAP,
  ------------------
  |  |  547|  33.9k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
                  rv = PK11_SymKeysToSameSlot(type, CKA_ENCRYPT, CKA_WRAP,
  ------------------
  |  |  549|  33.9k|#define CKA_WRAP 0x00000106UL
  ------------------
 1554|  33.9k|                                symKey, wrappingKey,
 1555|  33.9k|                                &newSymKey, &newWrappingKey);
 1556|  33.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1556:9): [True: 0, False: 33.9k]
  ------------------
 1557|       |        /* Couldn't move the keys as desired, try to hand unwrap if possible */
 1558|      0|        if (symKey->data.data == NULL) {
  ------------------
  |  Branch (1558:13): [True: 0, False: 0]
  ------------------
 1559|      0|            rv = PK11_ExtractKeyValue(symKey);
 1560|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1560:17): [True: 0, False: 0]
  ------------------
 1561|      0|                PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1562|      0|                return SECFailure;
 1563|      0|            }
 1564|      0|        }
 1565|      0|        if (param == NULL) {
  ------------------
  |  Branch (1565:13): [True: 0, False: 0]
  ------------------
 1566|      0|            param_save = param = PK11_ParamFromIV(type, NULL);
 1567|      0|        }
 1568|      0|        rv = pk11_HandWrap(wrappingKey, param, type, &symKey->data, wrappedKey);
 1569|      0|        if (param_save)
  ------------------
  |  Branch (1569:13): [True: 0, False: 0]
  ------------------
 1570|      0|            SECITEM_FreeItem(param_save, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(param_save, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1571|      0|        return rv;
 1572|      0|    }
 1573|  33.9k|    if (newSymKey) {
  ------------------
  |  Branch (1573:9): [True: 0, False: 33.9k]
  ------------------
 1574|      0|        symKey = newSymKey;
 1575|      0|    }
 1576|  33.9k|    if (newWrappingKey) {
  ------------------
  |  Branch (1576:9): [True: 0, False: 33.9k]
  ------------------
 1577|      0|        wrappingKey = newWrappingKey;
 1578|      0|    }
 1579|       |
 1580|       |    /* at this point both keys are in the same token */
 1581|  33.9k|    slot = wrappingKey->slot;
 1582|  33.9k|    mechanism.mechanism = type;
 1583|       |    /* use NULL IV's for wrapping */
 1584|  33.9k|    if (param == NULL) {
  ------------------
  |  Branch (1584:9): [True: 33.9k, False: 0]
  ------------------
 1585|  33.9k|        param_save = param = PK11_ParamFromIV(type, NULL);
 1586|  33.9k|    }
 1587|  33.9k|    if (param) {
  ------------------
  |  Branch (1587:9): [True: 33.9k, False: 0]
  ------------------
 1588|  33.9k|        mechanism.pParameter = param->data;
 1589|  33.9k|        mechanism.ulParameterLen = param->len;
 1590|  33.9k|    } else {
 1591|      0|        mechanism.pParameter = NULL;
 1592|      0|        mechanism.ulParameterLen = 0;
 1593|      0|    }
 1594|       |
 1595|  33.9k|    len = wrappedKey->len;
 1596|       |
 1597|  33.9k|    session = pk11_GetNewSession(slot, &owner);
 1598|  33.9k|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (1598:9): [True: 0, False: 33.9k]
  |  Branch (1598:19): [True: 0, False: 33.9k]
  ------------------
 1599|      0|        PK11_EnterSlotMonitor(slot);
 1600|  33.9k|    crv = PK11_GETTAB(slot)->C_WrapKey(session, &mechanism,
  ------------------
  |  |  102|  33.9k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1601|  33.9k|                                       wrappingKey->objectID, symKey->objectID,
 1602|  33.9k|                                       wrappedKey->data, &len);
 1603|  33.9k|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (1603:9): [True: 0, False: 33.9k]
  |  Branch (1603:19): [True: 0, False: 33.9k]
  ------------------
 1604|      0|        PK11_ExitSlotMonitor(slot);
 1605|  33.9k|    pk11_CloseSession(slot, session, owner);
 1606|  33.9k|    rv = SECSuccess;
 1607|  33.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  33.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1607:9): [True: 0, False: 33.9k]
  ------------------
 1608|       |        /* can't wrap it? try hand wrapping it... */
 1609|      0|        do {
 1610|      0|            if (symKey->data.data == NULL) {
  ------------------
  |  Branch (1610:17): [True: 0, False: 0]
  ------------------
 1611|      0|                rv = PK11_ExtractKeyValue(symKey);
 1612|      0|                if (rv != SECSuccess)
  ------------------
  |  Branch (1612:21): [True: 0, False: 0]
  ------------------
 1613|      0|                    break;
 1614|      0|            }
 1615|      0|            rv = pk11_HandWrap(wrappingKey, param, type, &symKey->data,
 1616|      0|                               wrappedKey);
 1617|      0|        } while (PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  |  |  ------------------
  |  |  |  Branch (438:18): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1618|  33.9k|    } else {
 1619|  33.9k|        wrappedKey->len = len;
 1620|  33.9k|    }
 1621|      0|    PK11_FreeSymKey(newSymKey);
 1622|  33.9k|    PK11_FreeSymKey(newWrappingKey);
 1623|  33.9k|    if (param_save)
  ------------------
  |  Branch (1623:9): [True: 33.9k, False: 0]
  ------------------
 1624|  33.9k|        SECITEM_FreeItem(param_save, PR_TRUE);
  ------------------
  |  |  108|  33.9k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(param_save, PR_TRUE);
  ------------------
  |  |  437|  33.9k|#define PR_TRUE 1
  ------------------
 1625|  33.9k|    return rv;
 1626|  33.9k|}
PK11_Derive:
 1635|  59.5k|{
 1636|  59.5k|    return PK11_DeriveWithTemplate(baseKey, derive, param, target, operation,
 1637|  59.5k|                                   keySize, NULL, 0, PR_FALSE);
  ------------------
  |  |  438|  59.5k|#define PR_FALSE 0
  ------------------
 1638|  59.5k|}
PK11_DeriveWithFlags:
 1644|   910k|{
 1645|   910k|    CK_BBOOL ckTrue = CK_TRUE;
  ------------------
  |  |   22|   910k|#define CK_TRUE 1
  ------------------
 1646|   910k|    CK_ATTRIBUTE keyTemplate[MAX_TEMPL_ATTRS];
 1647|   910k|    unsigned int templateCount;
 1648|       |
 1649|   910k|    templateCount = pk11_OpFlagsToAttributes(flags, keyTemplate, &ckTrue);
 1650|   910k|    return PK11_DeriveWithTemplate(baseKey, derive, param, target, operation,
 1651|   910k|                                   keySize, keyTemplate, templateCount, PR_FALSE);
  ------------------
  |  |  438|   910k|#define PR_FALSE 0
  ------------------
 1652|   910k|}
PK11_DeriveWithTemplate:
 1680|   969k|{
 1681|   969k|    PK11SlotInfo *slot = baseKey->slot;
 1682|   969k|    PK11SymKey *symKey;
 1683|   969k|    PK11SymKey *newBaseKey = NULL;
 1684|   969k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|   969k|#define CK_TRUE 1
  ------------------
 1685|   969k|    CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|   969k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 1686|   969k|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|   969k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 1687|   969k|    CK_ULONG valueLen = 0;
 1688|   969k|    CK_MECHANISM mechanism;
 1689|   969k|    CK_RV crv;
 1690|   969k|#define MAX_ADD_ATTRS 4
 1691|   969k|    CK_ATTRIBUTE keyTemplate[MAX_TEMPL_ATTRS + MAX_ADD_ATTRS];
 1692|   969k|#undef MAX_ADD_ATTRS
 1693|   969k|    CK_ATTRIBUTE *attrs = keyTemplate;
 1694|   969k|    CK_SESSION_HANDLE session;
 1695|   969k|    unsigned int templateCount;
 1696|       |
 1697|   969k|    if (numAttrs > MAX_TEMPL_ATTRS) {
  ------------------
  |  |  200|   969k|#define MAX_TEMPL_ATTRS 16 /* maximum attributes in template */
  ------------------
  |  Branch (1697:9): [True: 0, False: 969k]
  ------------------
 1698|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1699|      0|        return NULL;
 1700|      0|    }
 1701|       |    /* CKA_NSS_MESSAGE is a fake operation to distinguish between
 1702|       |     * Normal Encrypt/Decrypt and MessageEncrypt/Decrypt. Don't try to set
 1703|       |     * it as a real attribute */
 1704|   969k|    if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|   969k|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|   969k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (1704:9): [True: 0, False: 969k]
  ------------------
 1705|       |        /* Message is or'd with a real Attribute (CKA_ENCRYPT, CKA_DECRYPT),
 1706|       |         * etc. Strip out the real attribute here */
 1707|      0|        operation &= ~CKA_NSS_MESSAGE_MASK;
  ------------------
  |  |   70|      0|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
 1708|      0|    }
 1709|       |
 1710|       |    /* first copy caller attributes in. */
 1711|  2.79M|    for (templateCount = 0; templateCount < numAttrs; ++templateCount) {
  ------------------
  |  Branch (1711:29): [True: 1.82M, False: 969k]
  ------------------
 1712|  1.82M|        *attrs++ = *userAttr++;
 1713|  1.82M|    }
 1714|       |
 1715|       |    /* We only add the following attributes to the template if the caller
 1716|       |    ** didn't already supply them.
 1717|       |    */
 1718|   969k|    if (!pk11_FindAttrInTemplate(keyTemplate, numAttrs, CKA_CLASS)) {
  ------------------
  |  |  511|   969k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (1718:9): [True: 969k, False: 0]
  ------------------
 1719|   969k|        PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof keyClass);
  ------------------
  |  |  104|   969k|    (x)->type = (id);              \
  |  |  105|   969k|    (x)->pValue = (v);             \
  |  |  106|   969k|    (x)->ulValueLen = (l);
  ------------------
 1720|   969k|        attrs++;
 1721|   969k|    }
 1722|   969k|    if (!pk11_FindAttrInTemplate(keyTemplate, numAttrs, CKA_KEY_TYPE)) {
  ------------------
  |  |  543|   969k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (1722:9): [True: 969k, False: 0]
  ------------------
 1723|   969k|        keyType = PK11_GetKeyType(target, keySize);
 1724|   969k|        PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof keyType);
  ------------------
  |  |  104|   969k|    (x)->type = (id);              \
  |  |  105|   969k|    (x)->pValue = (v);             \
  |  |  106|   969k|    (x)->ulValueLen = (l);
  ------------------
 1725|   969k|        attrs++;
 1726|   969k|    }
 1727|   969k|    if (keySize > 0 &&
  ------------------
  |  Branch (1727:9): [True: 891k, False: 77.9k]
  ------------------
 1728|   969k|        !pk11_FindAttrInTemplate(keyTemplate, numAttrs, CKA_VALUE_LEN)) {
  ------------------
  |  |  580|   891k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (1728:9): [True: 891k, False: 0]
  ------------------
 1729|   891k|        valueLen = (CK_ULONG)keySize;
 1730|   891k|        PK11_SETATTRS(attrs, CKA_VALUE_LEN, &valueLen, sizeof valueLen);
  ------------------
  |  |  104|   891k|    (x)->type = (id);              \
  |  |  105|   891k|    (x)->pValue = (v);             \
  |  |  106|   891k|    (x)->ulValueLen = (l);
  ------------------
 1731|   891k|        attrs++;
 1732|   891k|    }
 1733|   969k|    if ((operation != CKA_FLAGS_ONLY) &&
  ------------------
  |  |   71|   969k|#define CKA_FLAGS_ONLY 0 /* CKA_CLASS */
  ------------------
  |  Branch (1733:9): [True: 969k, False: 0]
  ------------------
 1734|   969k|        !pk11_FindAttrInTemplate(keyTemplate, numAttrs, operation)) {
  ------------------
  |  Branch (1734:9): [True: 969k, False: 0]
  ------------------
 1735|   969k|        PK11_SETATTRS(attrs, operation, &cktrue, sizeof cktrue);
  ------------------
  |  |  104|   969k|    (x)->type = (id);              \
  |  |  105|   969k|    (x)->pValue = (v);             \
  |  |  106|   969k|    (x)->ulValueLen = (l);
  ------------------
 1736|   969k|        attrs++;
 1737|   969k|    }
 1738|       |
 1739|   969k|    templateCount = attrs - keyTemplate;
 1740|   969k|    PR_ASSERT(templateCount <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|   969k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 969k, False: 0]
  |  |  ------------------
  ------------------
 1741|       |
 1742|       |    /* move the key to a slot that can do the function */
 1743|   969k|    if (!PK11_DoesMechanism(slot, derive)) {
  ------------------
  |  Branch (1743:9): [True: 0, False: 969k]
  ------------------
 1744|       |        /* get a new base key & slot */
 1745|      0|        PK11SlotInfo *newSlot = PK11_GetBestSlot(derive, baseKey->cx);
 1746|       |
 1747|      0|        if (newSlot == NULL)
  ------------------
  |  Branch (1747:13): [True: 0, False: 0]
  ------------------
 1748|      0|            return NULL;
 1749|       |
 1750|      0|        newBaseKey = pk11_CopyToSlot(newSlot, derive, CKA_DERIVE,
  ------------------
  |  |  555|      0|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1751|      0|                                     baseKey);
 1752|      0|        PK11_FreeSlot(newSlot);
 1753|      0|        if (newBaseKey == NULL)
  ------------------
  |  Branch (1753:13): [True: 0, False: 0]
  ------------------
 1754|      0|            return NULL;
 1755|      0|        baseKey = newBaseKey;
 1756|      0|        slot = baseKey->slot;
 1757|      0|    }
 1758|       |
 1759|       |    /* get our key Structure */
 1760|   969k|    symKey = pk11_CreateSymKey(slot, target, !isPerm, PR_TRUE, baseKey->cx);
  ------------------
  |  |  437|   969k|#define PR_TRUE 1
  ------------------
 1761|   969k|    if (symKey == NULL) {
  ------------------
  |  Branch (1761:9): [True: 0, False: 969k]
  ------------------
 1762|      0|        return NULL;
 1763|      0|    }
 1764|       |
 1765|   969k|    symKey->size = keySize;
 1766|       |
 1767|   969k|    mechanism.mechanism = derive;
 1768|   969k|    if (param) {
  ------------------
  |  Branch (1768:9): [True: 969k, False: 0]
  ------------------
 1769|   969k|        mechanism.pParameter = param->data;
 1770|   969k|        mechanism.ulParameterLen = param->len;
 1771|   969k|    } else {
 1772|      0|        mechanism.pParameter = NULL;
 1773|      0|        mechanism.ulParameterLen = 0;
 1774|      0|    }
 1775|   969k|    symKey->origin = PK11_OriginDerive;
 1776|       |
 1777|   969k|    if (isPerm) {
  ------------------
  |  Branch (1777:9): [True: 0, False: 969k]
  ------------------
 1778|      0|        session = PK11_GetRWSession(slot);
 1779|   969k|    } else {
 1780|   969k|        pk11_EnterKeyMonitor(symKey);
 1781|   969k|        session = symKey->session;
 1782|   969k|    }
 1783|   969k|    if (session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|   969k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1783:9): [True: 0, False: 969k]
  ------------------
 1784|      0|        if (!isPerm)
  ------------------
  |  Branch (1784:13): [True: 0, False: 0]
  ------------------
 1785|      0|            pk11_ExitKeyMonitor(symKey);
 1786|      0|        crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 1787|   969k|    } else {
 1788|   969k|        crv = PK11_GETTAB(slot)->C_DeriveKey(session, &mechanism,
  ------------------
  |  |  102|   969k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1789|   969k|                                             baseKey->objectID, keyTemplate, templateCount, &symKey->objectID);
 1790|   969k|        if (isPerm) {
  ------------------
  |  Branch (1790:13): [True: 0, False: 969k]
  ------------------
 1791|      0|            PK11_RestoreROSession(slot, session);
 1792|   969k|        } else {
 1793|   969k|            pk11_ExitKeyMonitor(symKey);
 1794|   969k|        }
 1795|   969k|    }
 1796|   969k|    if (newBaseKey)
  ------------------
  |  Branch (1796:9): [True: 0, False: 969k]
  ------------------
 1797|      0|        PK11_FreeSymKey(newBaseKey);
 1798|   969k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   969k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1798:9): [True: 731, False: 969k]
  ------------------
 1799|    731|        PK11_FreeSymKey(symKey);
 1800|    731|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|    731|#define PORT_SetError PORT_SetError_Util
  ------------------
 1801|    731|        return NULL;
 1802|    731|    }
 1803|   969k|    return symKey;
 1804|   969k|}
PK11_ConcatSymKeys:
 1853|     83|{
 1854|     83|    PK11SymKey *out = NULL;
 1855|     83|    PK11SymKey *copyOfLeft = NULL;
 1856|     83|    PK11SymKey *copyOfRight = NULL;
 1857|       |
 1858|     83|    if ((left == NULL) || (right == NULL)) {
  ------------------
  |  Branch (1858:9): [True: 0, False: 83]
  |  Branch (1858:27): [True: 0, False: 83]
  ------------------
 1859|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1860|      0|        return NULL;
 1861|      0|    }
 1862|       |
 1863|     83|    SECStatus rv = PK11_SymKeysToSameSlot(CKM_CONCATENATE_BASE_AND_KEY,
  ------------------
  |  |  954|     83|#define CKM_CONCATENATE_BASE_AND_KEY 0x00000360UL
  ------------------
 1864|     83|                                          CKA_DERIVE, CKA_DERIVE, left, right,
  ------------------
  |  |  555|     83|#define CKA_DERIVE 0x0000010CUL
  ------------------
                                                        CKA_DERIVE, CKA_DERIVE, left, right,
  ------------------
  |  |  555|     83|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1865|     83|                                          &copyOfLeft, &copyOfRight);
 1866|     83|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1866:9): [True: 0, False: 83]
  ------------------
 1867|       |        /* error code already set */
 1868|      0|        return NULL;
 1869|      0|    }
 1870|       |
 1871|     83|    out = pk11_ConcatenateBaseAndKey(copyOfLeft ? copyOfLeft : left, copyOfRight ? copyOfRight : right, target, operation, 0);
  ------------------
  |  Branch (1871:38): [True: 0, False: 83]
  |  Branch (1871:70): [True: 0, False: 83]
  ------------------
 1872|     83|    PK11_FreeSymKey(copyOfLeft);
 1873|     83|    PK11_FreeSymKey(copyOfRight);
 1874|     83|    return out;
 1875|     83|}
PK11_PubDerive:
 2107|  27.7k|{
 2108|  27.7k|    PK11SlotInfo *slot = privKey->pkcs11Slot;
 2109|  27.7k|    CK_MECHANISM mechanism;
 2110|  27.7k|    PK11SymKey *symKey;
 2111|  27.7k|    CK_RV crv;
 2112|       |
 2113|       |    /* get our key Structure */
 2114|  27.7k|    symKey = pk11_CreateSymKey(slot, target, PR_TRUE, PR_TRUE, wincx);
  ------------------
  |  |  437|  27.7k|#define PR_TRUE 1
  ------------------
                  symKey = pk11_CreateSymKey(slot, target, PR_TRUE, PR_TRUE, wincx);
  ------------------
  |  |  437|  27.7k|#define PR_TRUE 1
  ------------------
 2115|  27.7k|    if (symKey == NULL) {
  ------------------
  |  Branch (2115:9): [True: 0, False: 27.7k]
  ------------------
 2116|      0|        return NULL;
 2117|      0|    }
 2118|       |
 2119|       |    /* CKA_NSS_MESSAGE is a fake operation to distinguish between
 2120|       |     * Normal Encrypt/Decrypt and MessageEncrypt/Decrypt. Don't try to set
 2121|       |     * it as a real attribute */
 2122|  27.7k|    if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|  27.7k|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|  27.7k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (2122:9): [True: 0, False: 27.7k]
  ------------------
 2123|       |        /* Message is or'd with a real Attribute (CKA_ENCRYPT, CKA_DECRYPT),
 2124|       |         * etc. Strip out the real attribute here */
 2125|      0|        operation &= ~CKA_NSS_MESSAGE_MASK;
  ------------------
  |  |   70|      0|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
 2126|      0|    }
 2127|       |
 2128|  27.7k|    symKey->origin = PK11_OriginDerive;
 2129|       |
 2130|  27.7k|    switch (privKey->keyType) {
  ------------------
  |  Branch (2130:13): [True: 0, False: 27.7k]
  ------------------
 2131|      0|        case rsaKey:
  ------------------
  |  Branch (2131:9): [True: 0, False: 27.7k]
  ------------------
 2132|      0|        case rsaPssKey:
  ------------------
  |  Branch (2132:9): [True: 0, False: 27.7k]
  ------------------
 2133|      0|        case rsaOaepKey:
  ------------------
  |  Branch (2133:9): [True: 0, False: 27.7k]
  ------------------
 2134|      0|        case kyberKey:
  ------------------
  |  Branch (2134:9): [True: 0, False: 27.7k]
  ------------------
 2135|      0|        case nullKey:
  ------------------
  |  Branch (2135:9): [True: 0, False: 27.7k]
  ------------------
 2136|      0|        case edKey:
  ------------------
  |  Branch (2136:9): [True: 0, False: 27.7k]
  ------------------
 2137|      0|        case ecMontKey:
  ------------------
  |  Branch (2137:9): [True: 0, False: 27.7k]
  ------------------
 2138|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2139|      0|            break;
 2140|      0|        case dsaKey:
  ------------------
  |  Branch (2140:9): [True: 0, False: 27.7k]
  ------------------
 2141|      0|        case keaKey:
  ------------------
  |  Branch (2141:9): [True: 0, False: 27.7k]
  ------------------
 2142|      0|        case fortezzaKey: {
  ------------------
  |  Branch (2142:9): [True: 0, False: 27.7k]
  ------------------
 2143|      0|            static unsigned char rb_email[128] = { 0 };
 2144|      0|            CK_KEA_DERIVE_PARAMS param;
 2145|      0|            param.isSender = (CK_BBOOL)isSender;
 2146|      0|            param.ulRandomLen = randomA->len;
 2147|      0|            param.pRandomA = randomA->data;
 2148|      0|            param.pRandomB = rb_email;
 2149|      0|            param.pRandomB[127] = 1;
 2150|      0|            if (randomB)
  ------------------
  |  Branch (2150:17): [True: 0, False: 0]
  ------------------
 2151|      0|                param.pRandomB = randomB->data;
 2152|      0|            if (pubKey->keyType == fortezzaKey) {
  ------------------
  |  Branch (2152:17): [True: 0, False: 0]
  ------------------
 2153|      0|                param.ulPublicDataLen = pubKey->u.fortezza.KEAKey.len;
 2154|      0|                param.pPublicData = pubKey->u.fortezza.KEAKey.data;
 2155|      0|            } else {
 2156|       |                /* assert type == keaKey */
 2157|       |                /* XXX change to match key key types */
 2158|      0|                param.ulPublicDataLen = pubKey->u.fortezza.KEAKey.len;
 2159|      0|                param.pPublicData = pubKey->u.fortezza.KEAKey.data;
 2160|      0|            }
 2161|       |
 2162|      0|            mechanism.mechanism = derive;
 2163|      0|            mechanism.pParameter = &param;
 2164|      0|            mechanism.ulParameterLen = sizeof(param);
 2165|       |
 2166|       |            /* get a new symKey structure */
 2167|      0|            pk11_EnterKeyMonitor(symKey);
 2168|      0|            crv = PK11_GETTAB(slot)->C_DeriveKey(symKey->session, &mechanism,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2169|      0|                                                 privKey->pkcs11ID, NULL, 0,
 2170|      0|                                                 &symKey->objectID);
 2171|      0|            pk11_ExitKeyMonitor(symKey);
 2172|      0|            if (crv == CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2172:17): [True: 0, False: 0]
  ------------------
 2173|      0|                return symKey;
 2174|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2175|      0|        } break;
 2176|  27.7k|        case dhKey: {
  ------------------
  |  Branch (2176:9): [True: 27.7k, False: 0]
  ------------------
 2177|  27.7k|            CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  27.7k|#define CK_TRUE 1
  ------------------
 2178|  27.7k|            CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|  27.7k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 2179|  27.7k|            CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  27.7k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 2180|  27.7k|            CK_ULONG key_size = 0;
 2181|  27.7k|            CK_ATTRIBUTE keyTemplate[4];
 2182|  27.7k|            int templateCount;
 2183|  27.7k|            CK_ATTRIBUTE *attrs = keyTemplate;
 2184|       |
 2185|  27.7k|            if (pubKey->keyType != dhKey) {
  ------------------
  |  Branch (2185:17): [True: 0, False: 27.7k]
  ------------------
 2186|      0|                PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2187|      0|                break;
 2188|      0|            }
 2189|       |
 2190|  27.7k|            PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|  27.7k|    (x)->type = (id);              \
  |  |  105|  27.7k|    (x)->pValue = (v);             \
  |  |  106|  27.7k|    (x)->ulValueLen = (l);
  ------------------
 2191|  27.7k|            attrs++;
 2192|  27.7k|            PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|  27.7k|    (x)->type = (id);              \
  |  |  105|  27.7k|    (x)->pValue = (v);             \
  |  |  106|  27.7k|    (x)->ulValueLen = (l);
  ------------------
 2193|  27.7k|            attrs++;
 2194|  27.7k|            PK11_SETATTRS(attrs, operation, &cktrue, 1);
  ------------------
  |  |  104|  27.7k|    (x)->type = (id);              \
  |  |  105|  27.7k|    (x)->pValue = (v);             \
  |  |  106|  27.7k|    (x)->ulValueLen = (l);
  ------------------
 2195|  27.7k|            attrs++;
 2196|  27.7k|            PK11_SETATTRS(attrs, CKA_VALUE_LEN, &key_size, sizeof(key_size));
  ------------------
  |  |  104|  27.7k|    (x)->type = (id);              \
  |  |  105|  27.7k|    (x)->pValue = (v);             \
  |  |  106|  27.7k|    (x)->ulValueLen = (l);
  ------------------
 2197|  27.7k|            attrs++;
 2198|  27.7k|            templateCount = attrs - keyTemplate;
 2199|  27.7k|            PR_ASSERT(templateCount <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  27.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 27.7k, False: 0]
  |  |  ------------------
  ------------------
 2200|       |
 2201|  27.7k|            keyType = PK11_GetKeyType(target, keySize);
 2202|  27.7k|            key_size = keySize;
 2203|  27.7k|            symKey->size = keySize;
 2204|  27.7k|            if (key_size == 0)
  ------------------
  |  Branch (2204:17): [True: 27.1k, False: 545]
  ------------------
 2205|  27.1k|                templateCount--;
 2206|       |
 2207|  27.7k|            mechanism.mechanism = derive;
 2208|       |
 2209|       |            /* we can undefine these when we define diffie-helman keys */
 2210|       |
 2211|  27.7k|            mechanism.pParameter = pubKey->u.dh.publicValue.data;
 2212|  27.7k|            mechanism.ulParameterLen = pubKey->u.dh.publicValue.len;
 2213|       |
 2214|  27.7k|            pk11_EnterKeyMonitor(symKey);
 2215|  27.7k|            crv = PK11_GETTAB(slot)->C_DeriveKey(symKey->session, &mechanism,
  ------------------
  |  |  102|  27.7k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2216|  27.7k|                                                 privKey->pkcs11ID, keyTemplate,
 2217|  27.7k|                                                 templateCount, &symKey->objectID);
 2218|  27.7k|            pk11_ExitKeyMonitor(symKey);
 2219|  27.7k|            if (crv == CKR_OK)
  ------------------
  |  | 1388|  27.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2219:17): [True: 27.7k, False: 0]
  ------------------
 2220|  27.7k|                return symKey;
 2221|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2222|      0|        } break;
 2223|      0|        case ecKey: {
  ------------------
  |  Branch (2223:9): [True: 0, False: 27.7k]
  ------------------
 2224|      0|            CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|      0|#define CK_TRUE 1
  ------------------
 2225|      0|            CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|      0|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 2226|      0|            CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|      0|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 2227|      0|            CK_ULONG key_size = 0;
 2228|      0|            CK_ATTRIBUTE keyTemplate[4];
 2229|      0|            int templateCount;
 2230|      0|            CK_ATTRIBUTE *attrs = keyTemplate;
 2231|      0|            CK_ECDH1_DERIVE_PARAMS *mechParams = NULL;
 2232|       |
 2233|      0|            if (pubKey->keyType != ecKey) {
  ------------------
  |  Branch (2233:17): [True: 0, False: 0]
  ------------------
 2234|      0|                PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2235|      0|                break;
 2236|      0|            }
 2237|       |
 2238|      0|            PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 2239|      0|            attrs++;
 2240|      0|            PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 2241|      0|            attrs++;
 2242|      0|            PK11_SETATTRS(attrs, operation, &cktrue, 1);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 2243|      0|            attrs++;
 2244|      0|            PK11_SETATTRS(attrs, CKA_VALUE_LEN, &key_size, sizeof(key_size));
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 2245|      0|            attrs++;
 2246|      0|            templateCount = attrs - keyTemplate;
 2247|      0|            PR_ASSERT(templateCount <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2248|       |
 2249|      0|            keyType = PK11_GetKeyType(target, keySize);
 2250|      0|            key_size = keySize;
 2251|      0|            if (key_size == 0) {
  ------------------
  |  Branch (2251:17): [True: 0, False: 0]
  ------------------
 2252|      0|                if ((key_size = pk11_GetPredefinedKeyLength(keyType))) {
  ------------------
  |  Branch (2252:21): [True: 0, False: 0]
  ------------------
 2253|      0|                    templateCount--;
 2254|      0|                } else {
 2255|       |                    /* sigh, some tokens can't figure this out and require
 2256|       |                     * CKA_VALUE_LEN to be set */
 2257|      0|                    key_size = SHA1_LENGTH;
  ------------------
  |  |   39|      0|#define SHA1_LENGTH 20
  ------------------
 2258|      0|                }
 2259|      0|            }
 2260|      0|            symKey->size = key_size;
 2261|       |
 2262|      0|            mechParams = PORT_ZNew(CK_ECDH1_DERIVE_PARAMS);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 2263|      0|            mechParams->kdf = CKD_SHA1_KDF;
  ------------------
  |  | 1703|      0|#define CKD_SHA1_KDF 0x00000002UL
  ------------------
 2264|      0|            mechParams->ulSharedDataLen = 0;
 2265|      0|            mechParams->pSharedData = NULL;
 2266|      0|            mechParams->ulPublicDataLen = pubKey->u.ec.publicValue.len;
 2267|      0|            mechParams->pPublicData = pubKey->u.ec.publicValue.data;
 2268|       |
 2269|      0|            mechanism.mechanism = derive;
 2270|      0|            mechanism.pParameter = mechParams;
 2271|      0|            mechanism.ulParameterLen = sizeof(CK_ECDH1_DERIVE_PARAMS);
 2272|       |
 2273|      0|            pk11_EnterKeyMonitor(symKey);
 2274|      0|            crv = PK11_GETTAB(slot)->C_DeriveKey(symKey->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2275|      0|                                                 &mechanism, privKey->pkcs11ID, keyTemplate,
 2276|      0|                                                 templateCount, &symKey->objectID);
 2277|      0|            pk11_ExitKeyMonitor(symKey);
 2278|       |
 2279|       |            /* old PKCS #11 spec was ambiguous on what needed to be passed,
 2280|       |             * try this again with and encoded public key */
 2281|      0|            if (crv != CKR_OK && pk11_ECGetPubkeyEncoding(pubKey) != ECPoint_XOnly) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2281:17): [True: 0, False: 0]
  |  Branch (2281:34): [True: 0, False: 0]
  ------------------
 2282|      0|                SECItem *pubValue = SEC_ASN1EncodeItem(NULL, NULL,
  ------------------
  |  |   89|      0|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
 2283|      0|                                                       &pubKey->u.ec.publicValue,
 2284|      0|                                                       SEC_ASN1_GET(SEC_OctetStringTemplate));
  ------------------
  |  |  188|      0|#define SEC_ASN1_GET(x) x
  ------------------
 2285|      0|                if (pubValue == NULL) {
  ------------------
  |  Branch (2285:21): [True: 0, False: 0]
  ------------------
 2286|      0|                    PORT_ZFree(mechParams, sizeof(CK_ECDH1_DERIVE_PARAMS));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 2287|      0|                    break;
 2288|      0|                }
 2289|      0|                mechParams->ulPublicDataLen = pubValue->len;
 2290|      0|                mechParams->pPublicData = pubValue->data;
 2291|       |
 2292|      0|                pk11_EnterKeyMonitor(symKey);
 2293|      0|                crv = PK11_GETTAB(slot)->C_DeriveKey(symKey->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2294|      0|                                                     &mechanism, privKey->pkcs11ID, keyTemplate,
 2295|      0|                                                     templateCount, &symKey->objectID);
 2296|      0|                pk11_ExitKeyMonitor(symKey);
 2297|       |
 2298|      0|                SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2299|      0|            }
 2300|       |
 2301|      0|            PORT_ZFree(mechParams, sizeof(CK_ECDH1_DERIVE_PARAMS));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 2302|       |
 2303|      0|            if (crv == CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2303:17): [True: 0, False: 0]
  ------------------
 2304|      0|                return symKey;
 2305|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2306|      0|        }
 2307|  27.7k|    }
 2308|       |
 2309|      0|    PK11_FreeSymKey(symKey);
 2310|      0|    return NULL;
 2311|  27.7k|}
PK11_PubDeriveWithKDF:
 2591|  18.1k|{
 2592|       |
 2593|  18.1k|    switch (privKey->keyType) {
 2594|      0|        case rsaKey:
  ------------------
  |  Branch (2594:9): [True: 0, False: 18.1k]
  ------------------
 2595|      0|        case nullKey:
  ------------------
  |  Branch (2595:9): [True: 0, False: 18.1k]
  ------------------
 2596|      0|        case dsaKey:
  ------------------
  |  Branch (2596:9): [True: 0, False: 18.1k]
  ------------------
 2597|      0|        case keaKey:
  ------------------
  |  Branch (2597:9): [True: 0, False: 18.1k]
  ------------------
 2598|      0|        case fortezzaKey:
  ------------------
  |  Branch (2598:9): [True: 0, False: 18.1k]
  ------------------
 2599|    545|        case dhKey:
  ------------------
  |  Branch (2599:9): [True: 545, False: 17.5k]
  ------------------
 2600|    545|            return PK11_PubDerive(privKey, pubKey, isSender, randomA, randomB,
 2601|    545|                                  derive, target, operation, keySize, wincx);
 2602|  17.5k|        case ecKey:
  ------------------
  |  Branch (2602:9): [True: 17.5k, False: 545]
  ------------------
 2603|  17.5k|        case ecMontKey:
  ------------------
  |  Branch (2603:9): [True: 0, False: 18.1k]
  ------------------
 2604|  17.5k|            return pk11_PubDeriveECKeyWithKDF(privKey, pubKey, isSender,
 2605|  17.5k|                                              randomA, randomB, derive, target,
 2606|  17.5k|                                              operation, keySize,
 2607|  17.5k|                                              kdf, sharedData, wincx);
 2608|      0|        default:
  ------------------
  |  Branch (2608:9): [True: 0, False: 18.1k]
  ------------------
 2609|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2610|      0|            break;
 2611|  18.1k|    }
 2612|       |
 2613|      0|    return NULL;
 2614|  18.1k|}
PK11_PubUnwrapSymKey:
 2941|  11.9k|{
 2942|  11.9k|    CK_MECHANISM_TYPE wrapType = pk11_mapWrapKeyType(wrappingKey->keyType);
 2943|       |
 2944|  11.9k|    return PK11_PubUnwrapSymKeyWithMechanism(wrappingKey, wrapType, NULL,
 2945|  11.9k|                                             wrappedKey, target, operation,
 2946|  11.9k|                                             keySize);
 2947|  11.9k|}
PK11_PubUnwrapSymKeyWithMechanism:
 2955|  11.9k|{
 2956|  11.9k|    PK11SlotInfo *slot = wrappingKey->pkcs11Slot;
 2957|       |
 2958|  11.9k|    if (SECKEY_HAS_ATTRIBUTE_SET(wrappingKey, CKA_PRIVATE)) {
  ------------------
  |  |  224|  11.9k|    (0 != (key->staticflags & SECKEY_Attributes_Cached)) ? (0 != (key->staticflags & SECKEY_##attribute)) : PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)
  |  |  ------------------
  |  |  |  |  212|  11.9k|#define SECKEY_Attributes_Cached 0x1 /* bit 0 states \
  |  |  ------------------
  |  |                   (0 != (key->staticflags & SECKEY_Attributes_Cached)) ? (0 != (key->staticflags & SECKEY_##attribute)) : PK11_HasAttributeSet(key->pkcs11Slot, key->pkcs11ID, attribute, PR_FALSE)
  |  |  ------------------
  |  |  |  |  438|      0|#define PR_FALSE 0
  |  |  ------------------
  |  |  |  Branch (224:5): [True: 11.9k, False: 0]
  |  |  |  Branch (224:5): [True: 0, False: 11.9k]
  |  |  ------------------
  ------------------
 2959|      0|        PK11_HandlePasswordCheck(slot, wrappingKey->wincx);
 2960|      0|    }
 2961|       |
 2962|  11.9k|    return pk11_AnyUnwrapKey(slot, wrappingKey->pkcs11ID, mechType, param,
 2963|  11.9k|                             wrappedKey, target, operation, keySize,
 2964|  11.9k|                             wrappingKey->wincx, NULL, 0, PR_FALSE);
  ------------------
  |  |  438|  11.9k|#define PR_FALSE 0
  ------------------
 2965|  11.9k|}
PK11_GetSymKeyHandle:
 3078|  3.63k|{
 3079|  3.63k|    return symKey->objectID;
 3080|  3.63k|}
PK11_Encapsulate:
 3112|     99|{
 3113|     99|    PORT_Assert(pubKey);
  ------------------
  |  |  120|     99|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     99|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 99, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3114|     99|    PORT_Assert(outKey);
  ------------------
  |  |  120|     99|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     99|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 99, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3115|     99|    PORT_Assert(outCiphertext);
  ------------------
  |  |  120|     99|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     99|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 99, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3116|       |
 3117|     99|    PK11SlotInfo *slot = pubKey->pkcs11Slot;
 3118|       |
 3119|     99|    PK11SymKey *sharedSecret = NULL;
 3120|     99|    SECItem *ciphertext = NULL;
 3121|       |
 3122|     99|    CK_ATTRIBUTE keyTemplate[MAX_TEMPL_ATTRS];
 3123|     99|    unsigned int templateCount;
 3124|       |
 3125|     99|    CK_ATTRIBUTE *attrs;
 3126|     99|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|     99|#define CK_TRUE 1
  ------------------
 3127|     99|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|     99|#define CK_FALSE 0
  ------------------
 3128|     99|    CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|     99|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 3129|     99|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|     99|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 3130|       |
 3131|     99|    CK_INTERFACE_PTR KEMInterface = NULL;
 3132|     99|    CK_UTF8CHAR_PTR KEMInterfaceName = (CK_UTF8CHAR_PTR) "Vendor NSS KEM Interface";
 3133|     99|    CK_VERSION KEMInterfaceVersion = { 1, 0 };
 3134|     99|    CK_NSS_KEM_FUNCTIONS *KEMInterfaceFunctions = NULL;
 3135|       |
 3136|     99|    CK_RV crv;
 3137|       |
 3138|     99|    *outKey = NULL;
 3139|     99|    *outCiphertext = NULL;
 3140|       |
 3141|     99|    CK_MECHANISM_TYPE kemType;
 3142|     99|    CK_NSS_KEM_PARAMETER_SET_TYPE kemParameterSet = PK11_ReadULongAttribute(slot, pubKey->pkcs11ID, CKA_NSS_PARAMETER_SET);
  ------------------
  |  |  113|     99|#define CKA_NSS_PARAMETER_SET (CKA_NSS + 40)
  |  |  ------------------
  |  |  |  |   77|     99|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|     99|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3143|     99|    switch (kemParameterSet) {
 3144|      0|        case CKP_NSS_KYBER_768_ROUND3:
  ------------------
  |  |  301|      0|#define CKP_NSS_KYBER_768_ROUND3 (CKP_NSS + 1)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (3144:9): [True: 0, False: 99]
  ------------------
 3145|      0|            kemType = CKM_NSS_KYBER;
  ------------------
  |  |  268|      0|#define CKM_NSS_KYBER (CKM_NSS + 46)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3146|      0|            break;
 3147|     99|        case CKP_NSS_ML_KEM_768:
  ------------------
  |  |  302|     99|#define CKP_NSS_ML_KEM_768 (CKP_NSS + 2)
  |  |  ------------------
  |  |  |  |  300|     99|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (3147:9): [True: 99, False: 0]
  ------------------
 3148|     99|            kemType = CKM_NSS_ML_KEM;
  ------------------
  |  |  278|     99|#define CKM_NSS_ML_KEM (CKM_NSS + 49)
  |  |  ------------------
  |  |  |  |  162|     99|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3149|     99|            break;
 3150|      0|        default:
  ------------------
  |  Branch (3150:9): [True: 0, False: 99]
  ------------------
 3151|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3152|      0|            return SECFailure;
 3153|     99|    }
 3154|     99|    CK_MECHANISM mech = { kemType, &kemParameterSet, sizeof(kemParameterSet) };
 3155|       |
 3156|     99|    sharedSecret = pk11_CreateSymKey(slot, target, PR_TRUE, PR_TRUE, NULL);
  ------------------
  |  |  437|     99|#define PR_TRUE 1
  ------------------
                  sharedSecret = pk11_CreateSymKey(slot, target, PR_TRUE, PR_TRUE, NULL);
  ------------------
  |  |  437|     99|#define PR_TRUE 1
  ------------------
 3157|     99|    if (sharedSecret == NULL) {
  ------------------
  |  Branch (3157:9): [True: 0, False: 99]
  ------------------
 3158|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3159|      0|        return SECFailure;
 3160|      0|    }
 3161|     99|    sharedSecret->origin = PK11_OriginGenerated;
 3162|       |
 3163|     99|    attrs = keyTemplate;
 3164|     99|    PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|     99|    (x)->type = (id);              \
  |  |  105|     99|    (x)->pValue = (v);             \
  |  |  106|     99|    (x)->ulValueLen = (l);
  ------------------
 3165|     99|    attrs++;
 3166|       |
 3167|     99|    PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|     99|    (x)->type = (id);              \
  |  |  105|     99|    (x)->pValue = (v);             \
  |  |  106|     99|    (x)->ulValueLen = (l);
  ------------------
 3168|     99|    attrs++;
 3169|       |
 3170|     99|    attrs += pk11_AttrFlagsToAttributes(attrFlags, attrs, &cktrue, &ckfalse);
 3171|     99|    attrs += pk11_OpFlagsToAttributes(opFlags, attrs, &cktrue);
 3172|       |
 3173|     99|    templateCount = attrs - keyTemplate;
 3174|     99|    PR_ASSERT(templateCount <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|     99|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 99, False: 0]
  |  |  ------------------
  ------------------
 3175|       |
 3176|     99|    crv = PK11_GETTAB(slot)->C_GetInterface(KEMInterfaceName, &KEMInterfaceVersion, &KEMInterface, 0);
  ------------------
  |  |  102|     99|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 3177|     99|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|     99|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3177:9): [True: 0, False: 99]
  ------------------
 3178|      0|        goto error;
 3179|      0|    }
 3180|     99|    KEMInterfaceFunctions = (CK_NSS_KEM_FUNCTIONS *)(KEMInterface->pFunctionList);
 3181|       |
 3182|     99|    CK_ULONG ciphertextLen = pk11_KEMCiphertextLength(pubKey);
 3183|     99|    ciphertext = SECITEM_AllocItem(NULL, NULL, ciphertextLen);
  ------------------
  |  |  103|     99|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
 3184|     99|    if (ciphertext == NULL) {
  ------------------
  |  Branch (3184:9): [True: 0, False: 99]
  ------------------
 3185|      0|        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3186|      0|        goto error;
 3187|      0|    }
 3188|       |
 3189|     99|    pk11_EnterKeyMonitor(sharedSecret);
 3190|     99|    crv = KEMInterfaceFunctions->C_Encapsulate(sharedSecret->session,
 3191|     99|                                               &mech,
 3192|     99|                                               pubKey->pkcs11ID,
 3193|     99|                                               keyTemplate,
 3194|     99|                                               templateCount,
 3195|     99|                                               &sharedSecret->objectID,
 3196|     99|                                               ciphertext->data,
 3197|     99|                                               &ciphertextLen);
 3198|     99|    pk11_ExitKeyMonitor(sharedSecret);
 3199|     99|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|     99|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3199:9): [True: 16, False: 83]
  ------------------
 3200|     16|        goto error;
 3201|     16|    }
 3202|       |
 3203|     83|    PORT_Assert(ciphertextLen == ciphertext->len);
  ------------------
  |  |  120|     83|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     83|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 83, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3204|       |
 3205|     83|    *outKey = sharedSecret;
 3206|     83|    *outCiphertext = ciphertext;
 3207|       |
 3208|     83|    return SECSuccess;
 3209|       |
 3210|     16|error:
 3211|     16|    PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|     16|#define PORT_SetError PORT_SetError_Util
  ------------------
 3212|     16|    PK11_FreeSymKey(sharedSecret);
 3213|     16|    SECITEM_FreeItem(ciphertext, PR_TRUE);
  ------------------
  |  |  108|     16|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(ciphertext, PR_TRUE);
  ------------------
  |  |  437|     16|#define PR_TRUE 1
  ------------------
 3214|     16|    return SECFailure;
 3215|     99|}
pk11skey.c:pk11_EnterKeyMonitor:
   28|  2.23M|{
   29|  2.23M|    if (!symKey->sessionOwner || !(symKey->slot->isThreadSafe))
  ------------------
  |  Branch (29:9): [True: 210k, False: 2.02M]
  |  Branch (29:34): [True: 0, False: 2.02M]
  ------------------
   30|   210k|        PK11_EnterSlotMonitor(symKey->slot);
   31|  2.23M|}
pk11skey.c:pk11_ExitKeyMonitor:
   35|  2.23M|{
   36|  2.23M|    if (!symKey->sessionOwner || !(symKey->slot->isThreadSafe))
  ------------------
  |  Branch (36:9): [True: 210k, False: 2.02M]
  |  Branch (36:34): [True: 0, False: 2.02M]
  ------------------
   37|   210k|        PK11_ExitSlotMonitor(symKey->slot);
   38|  2.23M|}
pk11skey.c:pk11_CreateSymKey:
  144|  1.25M|{
  145|       |
  146|  1.25M|    PK11SymKey *symKey = pk11_getKeyFromList(slot, needSession);
  147|       |
  148|  1.25M|    if (symKey == NULL) {
  ------------------
  |  Branch (148:9): [True: 0, False: 1.25M]
  ------------------
  149|      0|        return NULL;
  150|      0|    }
  151|       |    /* if needSession was specified, make sure we have a valid session.
  152|       |     * callers which specify needSession as false should do their own
  153|       |     * check of the session before returning the symKey */
  154|  1.25M|    if (needSession && symKey->session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|  1.04M|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (154:9): [True: 1.04M, False: 210k]
  |  Branch (154:24): [True: 0, False: 1.04M]
  ------------------
  155|      0|        PK11_FreeSymKey(symKey);
  156|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  157|      0|        return NULL;
  158|      0|    }
  159|       |
  160|  1.25M|    symKey->type = type;
  161|  1.25M|    symKey->data.type = siBuffer;
  162|  1.25M|    symKey->data.data = NULL;
  163|  1.25M|    symKey->data.len = 0;
  164|  1.25M|    symKey->owner = owner;
  165|  1.25M|    symKey->objectID = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  1.25M|#define CK_INVALID_HANDLE 0
  ------------------
  166|  1.25M|    symKey->slot = slot;
  167|  1.25M|    symKey->series = slot->series;
  168|  1.25M|    symKey->cx = wincx;
  169|  1.25M|    symKey->size = 0;
  170|  1.25M|    symKey->refCount = 1;
  171|  1.25M|    symKey->origin = PK11_OriginNULL;
  172|  1.25M|    symKey->parent = NULL;
  173|  1.25M|    symKey->freeFunc = NULL;
  174|  1.25M|    symKey->userData = NULL;
  175|  1.25M|    PK11_ReferenceSlot(slot);
  176|  1.25M|    return symKey;
  177|  1.25M|}
pk11skey.c:pk11_getKeyFromList:
   47|  1.25M|{
   48|  1.25M|    PK11SymKey *symKey = NULL;
   49|       |
   50|  1.25M|    PZ_Lock(slot->freeListLock);
  ------------------
  |  |  245|  1.25M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
   51|       |    /* own session list are symkeys with sessions that the symkey owns.
   52|       |     * 'most' symkeys will own their own session. */
   53|  1.25M|    if (needSession) {
  ------------------
  |  Branch (53:9): [True: 1.04M, False: 210k]
  ------------------
   54|  1.04M|        if (slot->freeSymKeysWithSessionHead) {
  ------------------
  |  Branch (54:13): [True: 1.04M, False: 17]
  ------------------
   55|  1.04M|            symKey = slot->freeSymKeysWithSessionHead;
   56|  1.04M|            slot->freeSymKeysWithSessionHead = symKey->next;
   57|  1.04M|            slot->keyCount--;
   58|  1.04M|        }
   59|  1.04M|    }
   60|       |    /* if we don't need a symkey with its own session, or we couldn't find
   61|       |     * one on the owner list, get one from the non-owner free list. */
   62|  1.25M|    if (!symKey) {
  ------------------
  |  Branch (62:9): [True: 210k, False: 1.04M]
  ------------------
   63|   210k|        if (slot->freeSymKeysHead) {
  ------------------
  |  Branch (63:13): [True: 210k, False: 25]
  ------------------
   64|   210k|            symKey = slot->freeSymKeysHead;
   65|   210k|            slot->freeSymKeysHead = symKey->next;
   66|   210k|            slot->keyCount--;
   67|   210k|        }
   68|   210k|    }
   69|  1.25M|    PZ_Unlock(slot->freeListLock);
  ------------------
  |  |  246|  1.25M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
   70|  1.25M|    if (symKey) {
  ------------------
  |  Branch (70:9): [True: 1.25M, False: 25]
  ------------------
   71|  1.25M|        symKey->next = NULL;
   72|  1.25M|        if (!needSession) {
  ------------------
  |  Branch (72:13): [True: 210k, False: 1.04M]
  ------------------
   73|   210k|            return symKey;
   74|   210k|        }
   75|       |        /* if we are getting an owner key, make sure we have a valid session.
   76|       |         * session could be invalid if the token has been removed or because
   77|       |         * we got it from the non-owner free list */
   78|  1.04M|        if ((symKey->series != slot->series) ||
  ------------------
  |  Branch (78:13): [True: 0, False: 1.04M]
  ------------------
   79|  1.04M|            (symKey->session == CK_INVALID_HANDLE)) {
  ------------------
  |  |   78|  1.04M|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (79:13): [True: 9, False: 1.04M]
  ------------------
   80|      9|            symKey->session = pk11_GetNewSession(slot, &symKey->sessionOwner);
   81|      9|        }
   82|  1.04M|        PORT_Assert(symKey->session != CK_INVALID_HANDLE);
  ------------------
  |  |  120|  1.04M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.04M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.04M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   83|  1.04M|        if (symKey->session != CK_INVALID_HANDLE)
  ------------------
  |  |   78|  1.04M|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (83:13): [True: 1.04M, False: 0]
  ------------------
   84|  1.04M|            return symKey;
   85|      0|        PK11_FreeSymKey(symKey);
   86|       |        /* if we are here, we need a session, but couldn't get one, it's
   87|       |         * unlikely we pk11_GetNewSession will succeed if we call it a second
   88|       |         * time. */
   89|      0|        return NULL;
   90|  1.04M|    }
   91|       |
   92|     25|    symKey = PORT_New(PK11SymKey);
  ------------------
  |  |  151|     25|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|     25|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
   93|     25|    if (symKey == NULL) {
  ------------------
  |  Branch (93:9): [True: 0, False: 25]
  ------------------
   94|      0|        return NULL;
   95|      0|    }
   96|       |
   97|     25|    symKey->next = NULL;
   98|     25|    if (needSession) {
  ------------------
  |  Branch (98:9): [True: 8, False: 17]
  ------------------
   99|      8|        symKey->session = pk11_GetNewSession(slot, &symKey->sessionOwner);
  100|      8|        PORT_Assert(symKey->session != CK_INVALID_HANDLE);
  ------------------
  |  |  120|      8|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 8, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  101|      8|        if (symKey->session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      8|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (101:13): [True: 0, False: 8]
  ------------------
  102|      0|            PK11_FreeSymKey(symKey);
  103|      0|            symKey = NULL;
  104|      0|        }
  105|     17|    } else {
  106|     17|        symKey->session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|     17|#define CK_INVALID_HANDLE 0
  ------------------
  107|     17|    }
  108|     25|    return symKey;
  109|     25|}
pk11skey.c:pk11_ImportSymKeyWithTempl:
  442|  1.21k|{
  443|  1.21k|    PK11SymKey *symKey;
  444|  1.21k|    SECStatus rv;
  445|       |
  446|  1.21k|    symKey = pk11_CreateSymKey(slot, type, !isToken, PR_TRUE, wincx);
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
  447|  1.21k|    if (symKey == NULL) {
  ------------------
  |  Branch (447:9): [True: 0, False: 1.21k]
  ------------------
  448|      0|        return NULL;
  449|      0|    }
  450|       |
  451|  1.21k|    symKey->size = key->len;
  452|       |
  453|  1.21k|    PK11_SETATTRS(&keyTemplate[templateCount], CKA_VALUE, key->data, key->len);
  ------------------
  |  |  104|  1.21k|    (x)->type = (id);              \
  |  |  105|  1.21k|    (x)->pValue = (v);             \
  |  |  106|  1.21k|    (x)->ulValueLen = (l);
  ------------------
  454|  1.21k|    templateCount++;
  455|       |
  456|  1.21k|    if (SECITEM_CopyItem(NULL, &symKey->data, key) != SECSuccess) {
  ------------------
  |  |  106|  1.21k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (456:9): [True: 0, False: 1.21k]
  ------------------
  457|      0|        PK11_FreeSymKey(symKey);
  458|      0|        return NULL;
  459|      0|    }
  460|       |
  461|  1.21k|    symKey->origin = origin;
  462|       |
  463|       |    /* import the keys */
  464|  1.21k|    rv = PK11_CreateNewObject(slot, symKey->session, keyTemplate,
  465|  1.21k|                              templateCount, isToken, &symKey->objectID);
  466|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (466:9): [True: 0, False: 1.21k]
  ------------------
  467|      0|        PK11_FreeSymKey(symKey);
  468|      0|        return NULL;
  469|      0|    }
  470|       |
  471|  1.21k|    return symKey;
  472|  1.21k|}
pk11skey.c:pk11_ConcatenateBaseAndKey:
 1836|     83|{
 1837|     83|    SECItem param;
 1838|       |
 1839|     83|    if ((base == NULL) || (key == NULL)) {
  ------------------
  |  Branch (1839:9): [True: 0, False: 83]
  |  Branch (1839:27): [True: 0, False: 83]
  ------------------
 1840|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1841|      0|        return NULL;
 1842|      0|    }
 1843|       |
 1844|     83|    param.data = (unsigned char *)&(key->objectID);
 1845|     83|    param.len = sizeof(CK_OBJECT_HANDLE);
 1846|       |
 1847|     83|    return PK11_Derive(base, CKM_CONCATENATE_BASE_AND_KEY,
  ------------------
  |  |  954|     83|#define CKM_CONCATENATE_BASE_AND_KEY 0x00000360UL
  ------------------
 1848|     83|                       &param, target, operation, keySize);
 1849|     83|}
pk11skey.c:pk11_ECGetPubkeyEncoding:
 2317|  17.8k|{
 2318|  17.8k|    SECItem oid;
 2319|  17.8k|    SECStatus rv;
 2320|  17.8k|    PORTCheapArenaPool tmpArena;
 2321|  17.8k|    ECPointEncoding encoding = ECPoint_Undefined;
 2322|       |
 2323|  17.8k|    PORT_InitCheapArena(&tmpArena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  17.8k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 2324|       |
 2325|       |    /* decode the OID tag */
 2326|  17.8k|    rv = SEC_QuickDERDecodeItem(&tmpArena.arena, &oid,
  ------------------
  |  |  102|  17.8k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
 2327|  17.8k|                                SEC_ASN1_GET(SEC_ObjectIDTemplate),
  ------------------
  |  |  188|  17.8k|#define SEC_ASN1_GET(x) x
  ------------------
 2328|  17.8k|                                &pubKey->u.ec.DEREncodedParams);
 2329|  17.8k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (2329:9): [True: 17.8k, False: 0]
  ------------------
 2330|  17.8k|        SECOidTag tag = SECOID_FindOIDTag(&oid);
  ------------------
  |  |  117|  17.8k|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
 2331|  17.8k|        switch (tag) {
 2332|      0|            case SEC_OID_X25519:
  ------------------
  |  Branch (2332:13): [True: 0, False: 17.8k]
  ------------------
 2333|  7.22k|            case SEC_OID_CURVE25519:
  ------------------
  |  Branch (2333:13): [True: 7.22k, False: 10.5k]
  ------------------
 2334|  7.22k|                encoding = ECPoint_XOnly;
 2335|  7.22k|                break;
 2336|  8.46k|            case SEC_OID_SECG_EC_SECP256R1:
  ------------------
  |  |  543|  8.46k|#define SEC_OID_SECG_EC_SECP256R1 SEC_OID_ANSIX962_EC_PRIME256V1
  ------------------
  |  Branch (2336:13): [True: 8.46k, False: 9.34k]
  ------------------
 2337|  10.5k|            case SEC_OID_SECG_EC_SECP384R1:
  ------------------
  |  Branch (2337:13): [True: 2.05k, False: 15.7k]
  ------------------
 2338|  10.5k|            case SEC_OID_SECG_EC_SECP521R1:
  ------------------
  |  Branch (2338:13): [True: 74, False: 17.7k]
  ------------------
 2339|  10.5k|            default:
  ------------------
  |  Branch (2339:13): [True: 0, False: 17.8k]
  ------------------
 2340|       |                /* unknown curve, default to uncompressed */
 2341|  10.5k|                encoding = ECPoint_Uncompressed;
 2342|  17.8k|        }
 2343|  17.8k|    }
 2344|  17.8k|    PORT_DestroyCheapArena(&tmpArena);
 2345|  17.8k|    return encoding;
 2346|  17.8k|}
pk11skey.c:pk11_PubDeriveECKeyWithKDF:
 2374|  17.5k|{
 2375|  17.5k|    PK11SlotInfo *slot = privKey->pkcs11Slot;
 2376|  17.5k|    PK11SymKey *symKey;
 2377|  17.5k|    PK11SymKey *SharedSecret;
 2378|  17.5k|    CK_MECHANISM mechanism;
 2379|  17.5k|    CK_RV crv;
 2380|  17.5k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  17.5k|#define CK_TRUE 1
  ------------------
 2381|  17.5k|    CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|  17.5k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 2382|  17.5k|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  17.5k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 2383|  17.5k|    CK_ULONG key_size = 0;
 2384|  17.5k|    CK_ATTRIBUTE keyTemplate[4];
 2385|  17.5k|    int templateCount;
 2386|  17.5k|    CK_ATTRIBUTE *attrs = keyTemplate;
 2387|  17.5k|    CK_ECDH1_DERIVE_PARAMS *mechParams = NULL;
 2388|       |
 2389|  17.5k|    if (pubKey->keyType != ecKey && pubKey->keyType != ecMontKey) {
  ------------------
  |  Branch (2389:9): [True: 0, False: 17.5k]
  |  Branch (2389:37): [True: 0, False: 0]
  ------------------
 2390|      0|        PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2391|      0|        return NULL;
 2392|      0|    }
 2393|  17.5k|    if ((kdf != CKD_NULL) && (kdf != CKD_SHA1_KDF) &&
  ------------------
  |  | 1702|  17.5k|#define CKD_NULL 0x00000001UL
  ------------------
                  if ((kdf != CKD_NULL) && (kdf != CKD_SHA1_KDF) &&
  ------------------
  |  | 1703|      0|#define CKD_SHA1_KDF 0x00000002UL
  ------------------
  |  Branch (2393:9): [True: 0, False: 17.5k]
  |  Branch (2393:30): [True: 0, False: 0]
  ------------------
 2394|  17.5k|        (kdf != CKD_SHA224_KDF) && (kdf != CKD_SHA256_KDF) &&
  ------------------
  |  | 1704|      0|#define CKD_SHA224_KDF 0x00000005UL
  ------------------
                      (kdf != CKD_SHA224_KDF) && (kdf != CKD_SHA256_KDF) &&
  ------------------
  |  | 1705|      0|#define CKD_SHA256_KDF 0x00000006UL
  ------------------
  |  Branch (2394:9): [True: 0, False: 0]
  |  Branch (2394:36): [True: 0, False: 0]
  ------------------
 2395|  17.5k|        (kdf != CKD_SHA384_KDF) && (kdf != CKD_SHA512_KDF)) {
  ------------------
  |  | 1706|      0|#define CKD_SHA384_KDF 0x00000007UL
  ------------------
                      (kdf != CKD_SHA384_KDF) && (kdf != CKD_SHA512_KDF)) {
  ------------------
  |  | 1707|      0|#define CKD_SHA512_KDF 0x00000008UL
  ------------------
  |  Branch (2395:9): [True: 0, False: 0]
  |  Branch (2395:36): [True: 0, False: 0]
  ------------------
 2396|      0|        PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2397|      0|        return NULL;
 2398|      0|    }
 2399|       |
 2400|       |    /* get our key Structure */
 2401|  17.5k|    symKey = pk11_CreateSymKey(slot, target, PR_TRUE, PR_TRUE, wincx);
  ------------------
  |  |  437|  17.5k|#define PR_TRUE 1
  ------------------
                  symKey = pk11_CreateSymKey(slot, target, PR_TRUE, PR_TRUE, wincx);
  ------------------
  |  |  437|  17.5k|#define PR_TRUE 1
  ------------------
 2402|  17.5k|    if (symKey == NULL) {
  ------------------
  |  Branch (2402:9): [True: 0, False: 17.5k]
  ------------------
 2403|      0|        return NULL;
 2404|      0|    }
 2405|       |    /* CKA_NSS_MESSAGE is a fake operation to distinguish between
 2406|       |     * Normal Encrypt/Decrypt and MessageEncrypt/Decrypt. Don't try to set
 2407|       |     * it as a real attribute */
 2408|  17.5k|    if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|  17.5k|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|  17.5k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (2408:9): [True: 0, False: 17.5k]
  ------------------
 2409|       |        /* Message is or'd with a real Attribute (CKA_ENCRYPT, CKA_DECRYPT),
 2410|       |         * etc. Strip out the real attribute here */
 2411|      0|        operation &= ~CKA_NSS_MESSAGE_MASK;
  ------------------
  |  |   70|      0|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
 2412|      0|    }
 2413|       |
 2414|  17.5k|    symKey->origin = PK11_OriginDerive;
 2415|       |
 2416|  17.5k|    PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof(keyClass));
  ------------------
  |  |  104|  17.5k|    (x)->type = (id);              \
  |  |  105|  17.5k|    (x)->pValue = (v);             \
  |  |  106|  17.5k|    (x)->ulValueLen = (l);
  ------------------
 2417|  17.5k|    attrs++;
 2418|  17.5k|    PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  104|  17.5k|    (x)->type = (id);              \
  |  |  105|  17.5k|    (x)->pValue = (v);             \
  |  |  106|  17.5k|    (x)->ulValueLen = (l);
  ------------------
 2419|  17.5k|    attrs++;
 2420|  17.5k|    PK11_SETATTRS(attrs, operation, &cktrue, 1);
  ------------------
  |  |  104|  17.5k|    (x)->type = (id);              \
  |  |  105|  17.5k|    (x)->pValue = (v);             \
  |  |  106|  17.5k|    (x)->ulValueLen = (l);
  ------------------
 2421|  17.5k|    attrs++;
 2422|  17.5k|    PK11_SETATTRS(attrs, CKA_VALUE_LEN, &key_size, sizeof(key_size));
  ------------------
  |  |  104|  17.5k|    (x)->type = (id);              \
  |  |  105|  17.5k|    (x)->pValue = (v);             \
  |  |  106|  17.5k|    (x)->ulValueLen = (l);
  ------------------
 2423|  17.5k|    attrs++;
 2424|  17.5k|    templateCount = attrs - keyTemplate;
 2425|  17.5k|    PR_ASSERT(templateCount <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  ------------------
  ------------------
 2426|       |
 2427|  17.5k|    keyType = PK11_GetKeyType(target, keySize);
 2428|  17.5k|    key_size = keySize;
 2429|  17.5k|    if (key_size == 0) {
  ------------------
  |  Branch (2429:9): [True: 17.5k, False: 0]
  ------------------
 2430|  17.5k|        if ((key_size = pk11_GetPredefinedKeyLength(keyType))) {
  ------------------
  |  Branch (2430:13): [True: 1, False: 17.5k]
  ------------------
 2431|      1|            templateCount--;
 2432|  17.5k|        } else {
 2433|       |            /* sigh, some tokens can't figure this out and require
 2434|       |             * CKA_VALUE_LEN to be set */
 2435|  17.5k|            switch (kdf) {
 2436|  17.5k|                case CKD_NULL:
  ------------------
  |  | 1702|  17.5k|#define CKD_NULL 0x00000001UL
  ------------------
  |  Branch (2436:17): [True: 17.5k, False: 0]
  ------------------
 2437|  17.5k|                    key_size = pk11_ECPubKeySize(pubKey);
 2438|  17.5k|                    if (key_size == 0) {
  ------------------
  |  Branch (2438:25): [True: 5, False: 17.5k]
  ------------------
 2439|      5|                        PK11_FreeSymKey(symKey);
 2440|      5|                        return NULL;
 2441|      5|                    }
 2442|  17.5k|                    break;
 2443|  17.5k|                case CKD_SHA1_KDF:
  ------------------
  |  | 1703|      0|#define CKD_SHA1_KDF 0x00000002UL
  ------------------
  |  Branch (2443:17): [True: 0, False: 17.5k]
  ------------------
 2444|      0|                    key_size = SHA1_LENGTH;
  ------------------
  |  |   39|      0|#define SHA1_LENGTH 20
  ------------------
 2445|      0|                    break;
 2446|      0|                case CKD_SHA224_KDF:
  ------------------
  |  | 1704|      0|#define CKD_SHA224_KDF 0x00000005UL
  ------------------
  |  Branch (2446:17): [True: 0, False: 17.5k]
  ------------------
 2447|      0|                    key_size = SHA224_LENGTH;
  ------------------
  |  |   40|      0|#define SHA224_LENGTH 28
  ------------------
 2448|      0|                    break;
 2449|      0|                case CKD_SHA256_KDF:
  ------------------
  |  | 1705|      0|#define CKD_SHA256_KDF 0x00000006UL
  ------------------
  |  Branch (2449:17): [True: 0, False: 17.5k]
  ------------------
 2450|      0|                    key_size = SHA256_LENGTH;
  ------------------
  |  |   41|      0|#define SHA256_LENGTH 32
  ------------------
 2451|      0|                    break;
 2452|      0|                case CKD_SHA384_KDF:
  ------------------
  |  | 1706|      0|#define CKD_SHA384_KDF 0x00000007UL
  ------------------
  |  Branch (2452:17): [True: 0, False: 17.5k]
  ------------------
 2453|      0|                    key_size = SHA384_LENGTH;
  ------------------
  |  |   42|      0|#define SHA384_LENGTH 48
  ------------------
 2454|      0|                    break;
 2455|      0|                case CKD_SHA512_KDF:
  ------------------
  |  | 1707|      0|#define CKD_SHA512_KDF 0x00000008UL
  ------------------
  |  Branch (2455:17): [True: 0, False: 17.5k]
  ------------------
 2456|      0|                    key_size = SHA512_LENGTH;
  ------------------
  |  |   43|      0|#define SHA512_LENGTH 64
  ------------------
 2457|      0|                    break;
 2458|      0|                default:
  ------------------
  |  Branch (2458:17): [True: 0, False: 17.5k]
  ------------------
 2459|      0|                    PORT_AssertNotReached("Invalid CKD");
  ------------------
  |  |  127|      0|#define PORT_AssertNotReached(reasonStr) PR_NOT_REACHED(reasonStr)
  |  |  ------------------
  |  |  |  |  213|      0|    PR_Assert(_reasonStr,__FILE__,__LINE__)
  |  |  ------------------
  ------------------
 2460|      0|                    PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2461|      0|                    PK11_FreeSymKey(symKey);
 2462|      0|                    return NULL;
 2463|  17.5k|            }
 2464|  17.5k|        }
 2465|  17.5k|    }
 2466|  17.5k|    symKey->size = key_size;
 2467|       |
 2468|  17.5k|    mechParams = PORT_ZNew(CK_ECDH1_DERIVE_PARAMS);
  ------------------
  |  |  148|  17.5k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  17.5k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 2469|  17.5k|    if (!mechParams) {
  ------------------
  |  Branch (2469:9): [True: 0, False: 17.5k]
  ------------------
 2470|      0|        PK11_FreeSymKey(symKey);
 2471|      0|        return NULL;
 2472|      0|    }
 2473|  17.5k|    mechParams->kdf = kdf;
 2474|  17.5k|    if (sharedData == NULL) {
  ------------------
  |  Branch (2474:9): [True: 17.5k, False: 0]
  ------------------
 2475|  17.5k|        mechParams->ulSharedDataLen = 0;
 2476|  17.5k|        mechParams->pSharedData = NULL;
 2477|  17.5k|    } else {
 2478|      0|        mechParams->ulSharedDataLen = sharedData->len;
 2479|      0|        mechParams->pSharedData = sharedData->data;
 2480|      0|    }
 2481|  17.5k|    mechParams->ulPublicDataLen = pubKey->u.ec.publicValue.len;
 2482|  17.5k|    mechParams->pPublicData = pubKey->u.ec.publicValue.data;
 2483|       |
 2484|  17.5k|    mechanism.mechanism = derive;
 2485|  17.5k|    mechanism.pParameter = mechParams;
 2486|  17.5k|    mechanism.ulParameterLen = sizeof(CK_ECDH1_DERIVE_PARAMS);
 2487|       |
 2488|  17.5k|    pk11_EnterKeyMonitor(symKey);
 2489|  17.5k|    crv = PK11_GETTAB(slot)->C_DeriveKey(symKey->session, &mechanism,
  ------------------
  |  |  102|  17.5k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2490|  17.5k|                                         privKey->pkcs11ID, keyTemplate,
 2491|  17.5k|                                         templateCount, &symKey->objectID);
 2492|  17.5k|    pk11_ExitKeyMonitor(symKey);
 2493|       |
 2494|       |    /* old PKCS #11 spec was ambiguous on what needed to be passed,
 2495|       |     * try this again with an encoded public key */
 2496|  17.5k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  17.5k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2496:9): [True: 226, False: 17.3k]
  ------------------
 2497|       |        /* For curves that only use X as public value and no encoding we don't
 2498|       |         * have to try again. (Currently only Curve25519) */
 2499|    226|        if (pk11_ECGetPubkeyEncoding(pubKey) == ECPoint_XOnly) {
  ------------------
  |  Branch (2499:13): [True: 10, False: 216]
  ------------------
 2500|     10|            goto loser;
 2501|     10|        }
 2502|    216|        SECItem *pubValue = SEC_ASN1EncodeItem(NULL, NULL,
  ------------------
  |  |   89|    216|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
 2503|    216|                                               &pubKey->u.ec.publicValue,
 2504|    216|                                               SEC_ASN1_GET(SEC_OctetStringTemplate));
  ------------------
  |  |  188|    216|#define SEC_ASN1_GET(x) x
  ------------------
 2505|    216|        if (pubValue == NULL) {
  ------------------
  |  Branch (2505:13): [True: 0, False: 216]
  ------------------
 2506|      0|            goto loser;
 2507|      0|        }
 2508|    216|        mechParams->ulPublicDataLen = pubValue->len;
 2509|    216|        mechParams->pPublicData = pubValue->data;
 2510|       |
 2511|    216|        pk11_EnterKeyMonitor(symKey);
 2512|    216|        crv = PK11_GETTAB(slot)->C_DeriveKey(symKey->session,
  ------------------
  |  |  102|    216|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2513|    216|                                             &mechanism, privKey->pkcs11ID, keyTemplate,
 2514|    216|                                             templateCount, &symKey->objectID);
 2515|    216|        pk11_ExitKeyMonitor(symKey);
 2516|       |
 2517|    216|        if ((crv != CKR_OK) && (kdf != CKD_NULL)) {
  ------------------
  |  | 1388|    216|#define CKR_OK 0x00000000UL
  ------------------
                      if ((crv != CKR_OK) && (kdf != CKD_NULL)) {
  ------------------
  |  | 1702|    216|#define CKD_NULL 0x00000001UL
  ------------------
  |  Branch (2517:13): [True: 216, False: 0]
  |  Branch (2517:32): [True: 0, False: 216]
  ------------------
 2518|       |            /* Some PKCS #11 libraries cannot perform the key derivation
 2519|       |             * function. So, try calling C_DeriveKey with CKD_NULL and then
 2520|       |             * performing the KDF separately.
 2521|       |             */
 2522|      0|            CK_ULONG derivedKeySize = key_size;
 2523|       |
 2524|      0|            keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|      0|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 2525|      0|            key_size = pk11_ECPubKeySize(pubKey);
 2526|      0|            if (key_size == 0) {
  ------------------
  |  Branch (2526:17): [True: 0, False: 0]
  ------------------
 2527|      0|                SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2528|      0|                goto loser;
 2529|      0|            }
 2530|      0|            SharedSecret = symKey;
 2531|      0|            SharedSecret->size = key_size;
 2532|       |
 2533|      0|            mechParams->kdf = CKD_NULL;
  ------------------
  |  | 1702|      0|#define CKD_NULL 0x00000001UL
  ------------------
 2534|      0|            mechParams->ulSharedDataLen = 0;
 2535|      0|            mechParams->pSharedData = NULL;
 2536|      0|            mechParams->ulPublicDataLen = pubKey->u.ec.publicValue.len;
 2537|      0|            mechParams->pPublicData = pubKey->u.ec.publicValue.data;
 2538|       |
 2539|      0|            pk11_EnterKeyMonitor(SharedSecret);
 2540|      0|            crv = PK11_GETTAB(slot)->C_DeriveKey(SharedSecret->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2541|      0|                                                 &mechanism, privKey->pkcs11ID, keyTemplate,
 2542|      0|                                                 templateCount, &SharedSecret->objectID);
 2543|      0|            pk11_ExitKeyMonitor(SharedSecret);
 2544|       |
 2545|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2545:17): [True: 0, False: 0]
  ------------------
 2546|       |                /* old PKCS #11 spec was ambiguous on what needed to be passed,
 2547|       |                 * try this one final time with an encoded public key */
 2548|      0|                mechParams->ulPublicDataLen = pubValue->len;
 2549|      0|                mechParams->pPublicData = pubValue->data;
 2550|       |
 2551|      0|                pk11_EnterKeyMonitor(SharedSecret);
 2552|      0|                crv = PK11_GETTAB(slot)->C_DeriveKey(SharedSecret->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2553|      0|                                                     &mechanism, privKey->pkcs11ID, keyTemplate,
 2554|      0|                                                     templateCount, &SharedSecret->objectID);
 2555|      0|                pk11_ExitKeyMonitor(SharedSecret);
 2556|      0|            }
 2557|       |
 2558|       |            /* Perform KDF. */
 2559|      0|            if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2559:17): [True: 0, False: 0]
  ------------------
 2560|      0|                symKey = pk11_ANSIX963Derive(SharedSecret, kdf,
 2561|      0|                                             sharedData, target, operation,
 2562|      0|                                             derivedKeySize);
 2563|      0|                PK11_FreeSymKey(SharedSecret);
 2564|      0|                if (symKey == NULL) {
  ------------------
  |  Branch (2564:21): [True: 0, False: 0]
  ------------------
 2565|      0|                    SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                                  SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2566|      0|                    PORT_ZFree(mechParams, sizeof(CK_ECDH1_DERIVE_PARAMS));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 2567|      0|                    return NULL;
 2568|      0|                }
 2569|      0|            }
 2570|      0|        }
 2571|    216|        SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  108|    216|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  437|    216|#define PR_TRUE 1
  ------------------
 2572|    216|    }
 2573|       |
 2574|  17.5k|loser:
 2575|  17.5k|    PORT_ZFree(mechParams, sizeof(CK_ECDH1_DERIVE_PARAMS));
  ------------------
  |  |   75|  17.5k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 2576|       |
 2577|  17.5k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  17.5k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2577:9): [True: 226, False: 17.3k]
  ------------------
 2578|    226|        PK11_FreeSymKey(symKey);
 2579|    226|        symKey = NULL;
 2580|    226|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|    226|#define PORT_SetError PORT_SetError_Util
  ------------------
 2581|    226|    }
 2582|  17.5k|    return symKey;
 2583|  17.5k|}
pk11skey.c:pk11_ECPubKeySize:
 2352|  17.5k|{
 2353|  17.5k|    SECItem *publicValue = &pubKey->u.ec.publicValue;
 2354|       |
 2355|  17.5k|    ECPointEncoding encoding = pk11_ECGetPubkeyEncoding(pubKey);
 2356|  17.5k|    if (encoding == ECPoint_XOnly) {
  ------------------
  |  Branch (2356:9): [True: 7.21k, False: 10.3k]
  ------------------
 2357|  7.21k|        return publicValue->len;
 2358|  7.21k|    }
 2359|  10.3k|    if (encoding == ECPoint_Uncompressed) {
  ------------------
  |  Branch (2359:9): [True: 10.3k, False: 0]
  ------------------
 2360|       |        /* key encoded in uncompressed form */
 2361|  10.3k|        return ((publicValue->len - 1) / 2);
 2362|  10.3k|    }
 2363|       |    /* key encoding not recognized */
 2364|      0|    return 0;
 2365|  10.3k|}
pk11skey.c:pk11_AnyUnwrapKey:
 2716|  11.9k|{
 2717|  11.9k|    PK11SymKey *symKey;
 2718|  11.9k|    SECItem *param_free = NULL;
 2719|  11.9k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  11.9k|#define CK_TRUE 1
  ------------------
 2720|  11.9k|    CK_OBJECT_CLASS keyClass = CKO_SECRET_KEY;
  ------------------
  |  |  329|  11.9k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 2721|  11.9k|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  11.9k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 2722|  11.9k|    CK_ULONG valueLen = 0;
 2723|  11.9k|    CK_MECHANISM mechanism;
 2724|  11.9k|    CK_SESSION_HANDLE rwsession;
 2725|  11.9k|    CK_RV crv;
 2726|  11.9k|    CK_MECHANISM_INFO mechanism_info;
 2727|  11.9k|#define MAX_ADD_ATTRS 4
 2728|  11.9k|    CK_ATTRIBUTE keyTemplate[MAX_TEMPL_ATTRS + MAX_ADD_ATTRS];
 2729|  11.9k|#undef MAX_ADD_ATTRS
 2730|  11.9k|    CK_ATTRIBUTE *attrs = keyTemplate;
 2731|  11.9k|    unsigned int templateCount;
 2732|       |
 2733|  11.9k|    if (numAttrs > MAX_TEMPL_ATTRS) {
  ------------------
  |  |  200|  11.9k|#define MAX_TEMPL_ATTRS 16 /* maximum attributes in template */
  ------------------
  |  Branch (2733:9): [True: 0, False: 11.9k]
  ------------------
 2734|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2735|      0|        return NULL;
 2736|      0|    }
 2737|       |    /* CKA_NSS_MESSAGE is a fake operation to distinguish between
 2738|       |     * Normal Encrypt/Decrypt and MessageEncrypt/Decrypt. Don't try to set
 2739|       |     * it as a real attribute */
 2740|  11.9k|    if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   70|  11.9k|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
                  if ((operation & CKA_NSS_MESSAGE_MASK) == CKA_NSS_MESSAGE) {
  ------------------
  |  |   69|  11.9k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  |  Branch (2740:9): [True: 0, False: 11.9k]
  ------------------
 2741|       |        /* Message is or'd with a real Attribute (CKA_ENCRYPT, CKA_DECRYPT),
 2742|       |         * etc. Strip out the real attribute here */
 2743|      0|        operation &= ~CKA_NSS_MESSAGE_MASK;
  ------------------
  |  |   70|      0|#define CKA_NSS_MESSAGE_MASK 0xff000000L
  ------------------
 2744|      0|    }
 2745|       |
 2746|       |    /* first copy caller attributes in. */
 2747|  11.9k|    for (templateCount = 0; templateCount < numAttrs; ++templateCount) {
  ------------------
  |  Branch (2747:29): [True: 0, False: 11.9k]
  ------------------
 2748|      0|        *attrs++ = *userAttr++;
 2749|      0|    }
 2750|       |
 2751|       |    /* We only add the following attributes to the template if the caller
 2752|       |    ** didn't already supply them.
 2753|       |    */
 2754|  11.9k|    if (!pk11_FindAttrInTemplate(keyTemplate, numAttrs, CKA_CLASS)) {
  ------------------
  |  |  511|  11.9k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (2754:9): [True: 11.9k, False: 0]
  ------------------
 2755|  11.9k|        PK11_SETATTRS(attrs, CKA_CLASS, &keyClass, sizeof keyClass);
  ------------------
  |  |  104|  11.9k|    (x)->type = (id);              \
  |  |  105|  11.9k|    (x)->pValue = (v);             \
  |  |  106|  11.9k|    (x)->ulValueLen = (l);
  ------------------
 2756|  11.9k|        attrs++;
 2757|  11.9k|    }
 2758|  11.9k|    if (!pk11_FindAttrInTemplate(keyTemplate, numAttrs, CKA_KEY_TYPE)) {
  ------------------
  |  |  543|  11.9k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (2758:9): [True: 11.9k, False: 0]
  ------------------
 2759|  11.9k|        keyType = PK11_GetKeyType(target, keySize);
 2760|  11.9k|        PK11_SETATTRS(attrs, CKA_KEY_TYPE, &keyType, sizeof keyType);
  ------------------
  |  |  104|  11.9k|    (x)->type = (id);              \
  |  |  105|  11.9k|    (x)->pValue = (v);             \
  |  |  106|  11.9k|    (x)->ulValueLen = (l);
  ------------------
 2761|  11.9k|        attrs++;
 2762|  11.9k|    }
 2763|  11.9k|    if ((operation != CKA_FLAGS_ONLY) &&
  ------------------
  |  |   71|  11.9k|#define CKA_FLAGS_ONLY 0 /* CKA_CLASS */
  ------------------
  |  Branch (2763:9): [True: 11.9k, False: 0]
  ------------------
 2764|  11.9k|        !pk11_FindAttrInTemplate(keyTemplate, numAttrs, operation)) {
  ------------------
  |  Branch (2764:9): [True: 11.9k, False: 0]
  ------------------
 2765|  11.9k|        PK11_SETATTRS(attrs, operation, &cktrue, 1);
  ------------------
  |  |  104|  11.9k|    (x)->type = (id);              \
  |  |  105|  11.9k|    (x)->pValue = (v);             \
  |  |  106|  11.9k|    (x)->ulValueLen = (l);
  ------------------
 2766|  11.9k|        attrs++;
 2767|  11.9k|    }
 2768|       |
 2769|       |    /*
 2770|       |     * must be last in case we need to use this template to import the key
 2771|       |     */
 2772|  11.9k|    if (keySize > 0 &&
  ------------------
  |  Branch (2772:9): [True: 0, False: 11.9k]
  ------------------
 2773|  11.9k|        !pk11_FindAttrInTemplate(keyTemplate, numAttrs, CKA_VALUE_LEN)) {
  ------------------
  |  |  580|      0|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (2773:9): [True: 0, False: 0]
  ------------------
 2774|      0|        valueLen = (CK_ULONG)keySize;
 2775|      0|        PK11_SETATTRS(attrs, CKA_VALUE_LEN, &valueLen, sizeof valueLen);
  ------------------
  |  |  104|      0|    (x)->type = (id);              \
  |  |  105|      0|    (x)->pValue = (v);             \
  |  |  106|      0|    (x)->ulValueLen = (l);
  ------------------
 2776|      0|        attrs++;
 2777|      0|    }
 2778|       |
 2779|  11.9k|    templateCount = attrs - keyTemplate;
 2780|  11.9k|    PR_ASSERT(templateCount <= sizeof(keyTemplate) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  208|  11.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 11.9k, False: 0]
  |  |  ------------------
  ------------------
 2781|       |
 2782|       |    /* find out if we can do wrap directly. Because the RSA case if *very*
 2783|       |     * common, cache the results for it. */
 2784|  11.9k|    if ((wrapType == CKM_RSA_PKCS) && (slot->hasRSAInfo)) {
  ------------------
  |  |  720|  11.9k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (2784:9): [True: 11.9k, False: 0]
  |  Branch (2784:39): [True: 11.9k, False: 1]
  ------------------
 2785|  11.9k|        mechanism_info.flags = slot->RSAInfoFlags;
 2786|  11.9k|    } else {
 2787|      1|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (2787:13): [True: 0, False: 1]
  ------------------
 2788|      0|            PK11_EnterSlotMonitor(slot);
 2789|      1|        crv = PK11_GETTAB(slot)->C_GetMechanismInfo(slot->slotID, wrapType,
  ------------------
  |  |  102|      1|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2790|      1|                                                    &mechanism_info);
 2791|      1|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (2791:13): [True: 0, False: 1]
  ------------------
 2792|      0|            PK11_ExitSlotMonitor(slot);
 2793|      1|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2793:13): [True: 0, False: 1]
  ------------------
 2794|      0|            mechanism_info.flags = 0;
 2795|      0|        }
 2796|      1|        if (wrapType == CKM_RSA_PKCS) {
  ------------------
  |  |  720|      1|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (2796:13): [True: 1, False: 0]
  ------------------
 2797|      1|            slot->RSAInfoFlags = mechanism_info.flags;
 2798|      1|            slot->hasRSAInfo = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 2799|      1|        }
 2800|      1|    }
 2801|       |
 2802|       |    /* initialize the mechanism structure */
 2803|  11.9k|    mechanism.mechanism = wrapType;
 2804|       |    /* use NULL IV's for wrapping */
 2805|  11.9k|    if (param == NULL)
  ------------------
  |  Branch (2805:9): [True: 11.9k, False: 0]
  ------------------
 2806|  11.9k|        param = param_free = PK11_ParamFromIV(wrapType, NULL);
 2807|  11.9k|    if (param) {
  ------------------
  |  Branch (2807:9): [True: 11.9k, False: 0]
  ------------------
 2808|  11.9k|        mechanism.pParameter = param->data;
 2809|  11.9k|        mechanism.ulParameterLen = param->len;
 2810|  11.9k|    } else {
 2811|      0|        mechanism.pParameter = NULL;
 2812|      0|        mechanism.ulParameterLen = 0;
 2813|      0|    }
 2814|       |
 2815|  11.9k|    if ((mechanism_info.flags & CKF_DECRYPT) && !PK11_DoesMechanism(slot, target)) {
  ------------------
  |  | 1354|  11.9k|#define CKF_DECRYPT 0x00000200UL
  ------------------
  |  Branch (2815:9): [True: 11.9k, False: 0]
  |  Branch (2815:49): [True: 0, False: 11.9k]
  ------------------
 2816|      0|        symKey = pk11_HandUnwrap(slot, wrappingKey, &mechanism, wrappedKey,
 2817|      0|                                 target, keyTemplate, templateCount, keySize,
 2818|      0|                                 wincx, &crv, isPerm);
 2819|      0|        if (symKey) {
  ------------------
  |  Branch (2819:13): [True: 0, False: 0]
  ------------------
 2820|      0|            if (param_free)
  ------------------
  |  Branch (2820:17): [True: 0, False: 0]
  ------------------
 2821|      0|                SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2822|      0|            return symKey;
 2823|      0|        }
 2824|       |        /*
 2825|       |         * if the RSA OP simply failed, don't try to unwrap again
 2826|       |         * with this module.
 2827|       |         */
 2828|      0|        if (crv == CKR_DEVICE_ERROR) {
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  |  Branch (2828:13): [True: 0, False: 0]
  ------------------
 2829|      0|            if (param_free)
  ------------------
  |  Branch (2829:17): [True: 0, False: 0]
  ------------------
 2830|      0|                SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2831|      0|            return NULL;
 2832|      0|        }
 2833|       |        /* fall through, maybe they incorrectly set CKF_DECRYPT */
 2834|      0|    }
 2835|       |
 2836|       |    /* get our key Structure */
 2837|  11.9k|    symKey = pk11_CreateSymKey(slot, target, !isPerm, PR_TRUE, wincx);
  ------------------
  |  |  437|  11.9k|#define PR_TRUE 1
  ------------------
 2838|  11.9k|    if (symKey == NULL) {
  ------------------
  |  Branch (2838:9): [True: 0, False: 11.9k]
  ------------------
 2839|      0|        if (param_free)
  ------------------
  |  Branch (2839:13): [True: 0, False: 0]
  ------------------
 2840|      0|            SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2841|      0|        return NULL;
 2842|      0|    }
 2843|       |
 2844|  11.9k|    symKey->size = keySize;
 2845|  11.9k|    symKey->origin = PK11_OriginUnwrap;
 2846|       |
 2847|  11.9k|    if (isPerm) {
  ------------------
  |  Branch (2847:9): [True: 0, False: 11.9k]
  ------------------
 2848|      0|        rwsession = PK11_GetRWSession(slot);
 2849|  11.9k|    } else {
 2850|  11.9k|        pk11_EnterKeyMonitor(symKey);
 2851|  11.9k|        rwsession = symKey->session;
 2852|  11.9k|    }
 2853|  11.9k|    PORT_Assert(rwsession != CK_INVALID_HANDLE);
  ------------------
  |  |  120|  11.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2854|  11.9k|    if (rwsession == CK_INVALID_HANDLE)
  ------------------
  |  |   78|  11.9k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (2854:9): [True: 0, False: 11.9k]
  ------------------
 2855|      0|        crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 2856|  11.9k|    else
 2857|  11.9k|        crv = PK11_GETTAB(slot)->C_UnwrapKey(rwsession, &mechanism, wrappingKey,
  ------------------
  |  |  102|  11.9k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2858|  11.9k|                                             wrappedKey->data, wrappedKey->len,
 2859|  11.9k|                                             keyTemplate, templateCount,
 2860|  11.9k|                                             &symKey->objectID);
 2861|  11.9k|    if (isPerm) {
  ------------------
  |  Branch (2861:9): [True: 0, False: 11.9k]
  ------------------
 2862|      0|        if (rwsession != CK_INVALID_HANDLE)
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (2862:13): [True: 0, False: 0]
  ------------------
 2863|      0|            PK11_RestoreROSession(slot, rwsession);
 2864|  11.9k|    } else {
 2865|  11.9k|        pk11_ExitKeyMonitor(symKey);
 2866|  11.9k|    }
 2867|  11.9k|    if (param_free)
  ------------------
  |  Branch (2867:9): [True: 11.9k, False: 0]
  ------------------
 2868|  11.9k|        SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  108|  11.9k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(param_free, PR_TRUE);
  ------------------
  |  |  437|  11.9k|#define PR_TRUE 1
  ------------------
 2869|  11.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  11.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2869:9): [True: 11.2k, False: 772]
  ------------------
 2870|  11.2k|        PK11_FreeSymKey(symKey);
 2871|  11.2k|        symKey = NULL;
 2872|  11.2k|        if (crv != CKR_DEVICE_ERROR) {
  ------------------
  |  | 1416|  11.2k|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  |  Branch (2872:13): [True: 11.2k, False: 0]
  ------------------
 2873|       |            /* try hand Unwrapping */
 2874|  11.2k|            symKey = pk11_HandUnwrap(slot, wrappingKey, &mechanism, wrappedKey,
 2875|  11.2k|                                     target, keyTemplate, templateCount,
 2876|  11.2k|                                     keySize, wincx, NULL, isPerm);
 2877|  11.2k|        }
 2878|  11.2k|    }
 2879|       |
 2880|  11.9k|    return symKey;
 2881|  11.9k|}
pk11skey.c:pk11_HandUnwrap:
 2626|  11.2k|{
 2627|  11.2k|    CK_ULONG len;
 2628|  11.2k|    SECItem outKey;
 2629|  11.2k|    PK11SymKey *symKey;
 2630|  11.2k|    CK_RV crv;
 2631|  11.2k|    PRBool owner = PR_TRUE;
  ------------------
  |  |  437|  11.2k|#define PR_TRUE 1
  ------------------
 2632|  11.2k|    CK_SESSION_HANDLE session;
 2633|       |
 2634|       |    /* remove any VALUE_LEN parameters */
 2635|  11.2k|    if (keyTemplate[templateCount - 1].type == CKA_VALUE_LEN) {
  ------------------
  |  |  580|  11.2k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (2635:9): [True: 0, False: 11.2k]
  ------------------
 2636|      0|        templateCount--;
 2637|      0|    }
 2638|       |
 2639|       |    /* keys are almost always aligned, but if we get this far,
 2640|       |     * we've gone above and beyond anyway... */
 2641|  11.2k|    outKey.data = (unsigned char *)PORT_Alloc(inKey->len);
  ------------------
  |  |   52|  11.2k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 2642|  11.2k|    if (outKey.data == NULL) {
  ------------------
  |  Branch (2642:9): [True: 0, False: 11.2k]
  ------------------
 2643|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2644|      0|        if (crvp)
  ------------------
  |  Branch (2644:13): [True: 0, False: 0]
  ------------------
 2645|      0|            *crvp = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2646|      0|        return NULL;
 2647|      0|    }
 2648|  11.2k|    len = inKey->len;
 2649|       |
 2650|       |    /* use NULL IV's for wrapping */
 2651|  11.2k|    session = pk11_GetNewSession(slot, &owner);
 2652|  11.2k|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (2652:9): [True: 0, False: 11.2k]
  |  Branch (2652:19): [True: 0, False: 11.2k]
  ------------------
 2653|      0|        PK11_EnterSlotMonitor(slot);
 2654|  11.2k|    crv = PK11_GETTAB(slot)->C_DecryptInit(session, mech, wrappingKey);
  ------------------
  |  |  102|  11.2k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2655|  11.2k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  11.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2655:9): [True: 0, False: 11.2k]
  ------------------
 2656|      0|        if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (2656:13): [True: 0, False: 0]
  |  Branch (2656:23): [True: 0, False: 0]
  ------------------
 2657|      0|            PK11_ExitSlotMonitor(slot);
 2658|      0|        pk11_CloseSession(slot, session, owner);
 2659|      0|        PORT_Free(outKey.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2660|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2661|      0|        if (crvp)
  ------------------
  |  Branch (2661:13): [True: 0, False: 0]
  ------------------
 2662|      0|            *crvp = crv;
 2663|      0|        return NULL;
 2664|      0|    }
 2665|  11.2k|    crv = PK11_GETTAB(slot)->C_Decrypt(session, inKey->data, inKey->len,
  ------------------
  |  |  102|  11.2k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2666|  11.2k|                                       outKey.data, &len);
 2667|  11.2k|    if (!owner || !(slot->isThreadSafe))
  ------------------
  |  Branch (2667:9): [True: 0, False: 11.2k]
  |  Branch (2667:19): [True: 0, False: 11.2k]
  ------------------
 2668|      0|        PK11_ExitSlotMonitor(slot);
 2669|  11.2k|    pk11_CloseSession(slot, session, owner);
 2670|  11.2k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  11.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2670:9): [True: 11.2k, False: 0]
  ------------------
 2671|  11.2k|        PORT_Free(outKey.data);
  ------------------
  |  |   60|  11.2k|#define PORT_Free PORT_Free_Util
  ------------------
 2672|  11.2k|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|  11.2k|#define PORT_SetError PORT_SetError_Util
  ------------------
 2673|  11.2k|        if (crvp)
  ------------------
  |  Branch (2673:13): [True: 0, False: 11.2k]
  ------------------
 2674|      0|            *crvp = crv;
 2675|  11.2k|        return NULL;
 2676|  11.2k|    }
 2677|       |
 2678|      0|    outKey.len = (key_size == 0) ? len : key_size;
  ------------------
  |  Branch (2678:18): [True: 0, False: 0]
  ------------------
 2679|      0|    outKey.type = siBuffer;
 2680|       |
 2681|      0|    if (PK11_DoesMechanism(slot, target)) {
  ------------------
  |  Branch (2681:9): [True: 0, False: 0]
  ------------------
 2682|      0|        symKey = pk11_ImportSymKeyWithTempl(slot, target, PK11_OriginUnwrap,
 2683|      0|                                            isPerm, keyTemplate,
 2684|      0|                                            templateCount, &outKey, wincx);
 2685|      0|    } else {
 2686|      0|        slot = PK11_GetBestSlot(target, wincx);
 2687|      0|        if (slot == NULL) {
  ------------------
  |  Branch (2687:13): [True: 0, False: 0]
  ------------------
 2688|      0|            PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2689|      0|            PORT_Free(outKey.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2690|      0|            if (crvp)
  ------------------
  |  Branch (2690:17): [True: 0, False: 0]
  ------------------
 2691|      0|                *crvp = CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 2692|      0|            return NULL;
 2693|      0|        }
 2694|      0|        symKey = pk11_ImportSymKeyWithTempl(slot, target, PK11_OriginUnwrap,
 2695|      0|                                            isPerm, keyTemplate,
 2696|      0|                                            templateCount, &outKey, wincx);
 2697|      0|        PK11_FreeSlot(slot);
 2698|      0|    }
 2699|      0|    PORT_Free(outKey.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2700|       |
 2701|      0|    if (crvp)
  ------------------
  |  Branch (2701:9): [True: 0, False: 0]
  ------------------
 2702|      0|        *crvp = symKey ? CKR_OK : CKR_DEVICE_ERROR;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
                      *crvp = symKey ? CKR_OK : CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  |  Branch (2702:17): [True: 0, False: 0]
  ------------------
 2703|      0|    return symKey;
 2704|      0|}
pk11skey.c:pk11_KEMCiphertextLength:
 3099|     99|{
 3100|     99|    switch (pubKey->keyType) {
 3101|     99|        case kyberKey:
  ------------------
  |  Branch (3101:9): [True: 99, False: 0]
  ------------------
 3102|     99|            return pk11_KyberCiphertextLength(&pubKey->u.kyber);
 3103|      0|        default:
  ------------------
  |  Branch (3103:9): [True: 0, False: 99]
  ------------------
 3104|       |            // unreachable
 3105|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3106|      0|            return 0;
 3107|     99|    }
 3108|     99|}
pk11skey.c:pk11_KyberCiphertextLength:
 3084|     99|{
 3085|     99|    switch (pubKey->params) {
 3086|      0|        case params_kyber768_round3:
  ------------------
  |  Branch (3086:9): [True: 0, False: 99]
  ------------------
 3087|      0|        case params_kyber768_round3_test_mode:
  ------------------
  |  Branch (3087:9): [True: 0, False: 99]
  ------------------
 3088|     99|        case params_ml_kem768:
  ------------------
  |  Branch (3088:9): [True: 99, False: 0]
  ------------------
 3089|     99|        case params_ml_kem768_test_mode:
  ------------------
  |  Branch (3089:9): [True: 0, False: 99]
  ------------------
 3090|     99|            return KYBER768_CIPHERTEXT_BYTES;
  ------------------
  |  |   10|     99|#define KYBER768_CIPHERTEXT_BYTES 1088U
  ------------------
 3091|      0|        default:
  ------------------
  |  Branch (3091:9): [True: 0, False: 99]
  ------------------
 3092|       |            // unreachable
 3093|      0|            return 0;
 3094|     99|    }
 3095|     99|}

PK11_NewSlotList:
  108|  12.6k|{
  109|  12.6k|    PK11SlotList *list;
  110|       |
  111|  12.6k|    list = (PK11SlotList *)PORT_Alloc(sizeof(PK11SlotList));
  ------------------
  |  |   52|  12.6k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  112|  12.6k|    if (list == NULL)
  ------------------
  |  Branch (112:9): [True: 0, False: 12.6k]
  ------------------
  113|      0|        return NULL;
  114|  12.6k|    list->head = NULL;
  115|  12.6k|    list->tail = NULL;
  116|  12.6k|    list->lock = PZ_NewLock(nssILockList);
  ------------------
  |  |  243|  12.6k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  117|  12.6k|    if (list->lock == NULL) {
  ------------------
  |  Branch (117:9): [True: 0, False: 12.6k]
  ------------------
  118|      0|        PORT_Free(list);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  119|      0|        return NULL;
  120|      0|    }
  121|       |
  122|  12.6k|    return list;
  123|  12.6k|}
PK11_FreeSlotListElement:
  130|   391k|{
  131|   391k|    PRBool freeit = PR_FALSE;
  ------------------
  |  |  438|   391k|#define PR_FALSE 0
  ------------------
  132|       |
  133|   391k|    if (list == NULL || le == NULL) {
  ------------------
  |  Branch (133:9): [True: 0, False: 391k]
  |  Branch (133:25): [True: 0, False: 391k]
  ------------------
  134|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  135|      0|        return SECFailure;
  136|      0|    }
  137|       |
  138|   391k|    PZ_Lock(list->lock);
  ------------------
  |  |  245|   391k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  139|   391k|    if (le->refCount-- == 1) {
  ------------------
  |  Branch (139:9): [True: 8.45k, False: 383k]
  ------------------
  140|  8.45k|        freeit = PR_TRUE;
  ------------------
  |  |  437|  8.45k|#define PR_TRUE 1
  ------------------
  141|  8.45k|    }
  142|   391k|    PZ_Unlock(list->lock);
  ------------------
  |  |  246|   391k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  143|   391k|    if (freeit) {
  ------------------
  |  Branch (143:9): [True: 8.45k, False: 383k]
  ------------------
  144|  8.45k|        PK11_FreeSlot(le->slot);
  145|  8.45k|        PORT_Free(le);
  ------------------
  |  |   60|  8.45k|#define PORT_Free PORT_Free_Util
  ------------------
  146|  8.45k|    }
  147|   391k|    return SECSuccess;
  148|   391k|}
PK11_FreeSlotList:
  174|  12.6k|{
  175|  12.6k|    pk11_FreeSlotListStatic(list);
  176|  12.6k|    PORT_Free(list);
  ------------------
  |  |   60|  12.6k|#define PORT_Free PORT_Free_Util
  ------------------
  177|  12.6k|}
PK11_AddSlotToList:
  188|  8.45k|{
  189|  8.45k|    PK11SlotListElement *le;
  190|  8.45k|    PK11SlotListElement *element;
  191|       |
  192|  8.45k|    le = (PK11SlotListElement *)PORT_Alloc(sizeof(PK11SlotListElement));
  ------------------
  |  |   52|  8.45k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  193|  8.45k|    if (le == NULL)
  ------------------
  |  Branch (193:9): [True: 0, False: 8.45k]
  ------------------
  194|      0|        return SECFailure;
  195|       |
  196|  8.45k|    le->slot = PK11_ReferenceSlot(slot);
  197|  8.45k|    le->prev = NULL;
  198|  8.45k|    le->refCount = 1;
  199|  8.45k|    PZ_Lock(list->lock);
  ------------------
  |  |  245|  8.45k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  200|  8.45k|    element = list->head;
  201|       |    /* Insertion sort, with higher cipherOrders are sorted first in the list */
  202|  8.45k|    while (element && sorted && (element->slot->module->cipherOrder > le->slot->module->cipherOrder)) {
  ------------------
  |  Branch (202:12): [True: 4.22k, False: 4.23k]
  |  Branch (202:23): [True: 4.22k, False: 1]
  |  Branch (202:33): [True: 0, False: 4.22k]
  ------------------
  203|      0|        element = element->next;
  204|      0|    }
  205|  8.45k|    if (element) {
  ------------------
  |  Branch (205:9): [True: 4.22k, False: 4.23k]
  ------------------
  206|  4.22k|        le->prev = element->prev;
  207|  4.22k|        element->prev = le;
  208|  4.22k|        le->next = element;
  209|  4.23k|    } else {
  210|  4.23k|        le->prev = list->tail;
  211|  4.23k|        le->next = NULL;
  212|  4.23k|        list->tail = le;
  213|  4.23k|    }
  214|  8.45k|    if (le->prev)
  ------------------
  |  Branch (214:9): [True: 0, False: 8.45k]
  ------------------
  215|      0|        le->prev->next = le;
  216|  8.45k|    if (list->head == element)
  ------------------
  |  Branch (216:9): [True: 8.45k, False: 0]
  ------------------
  217|  8.45k|        list->head = le;
  218|  8.45k|    PZ_Unlock(list->lock);
  ------------------
  |  |  246|  8.45k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  219|       |
  220|  8.45k|    return SECSuccess;
  221|  8.45k|}
PK11_DeleteSlotFromList:
  228|     18|{
  229|     18|    PZ_Lock(list->lock);
  ------------------
  |  |  245|     18|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  230|     18|    if (le->prev)
  ------------------
  |  Branch (230:9): [True: 0, False: 18]
  ------------------
  231|      0|        le->prev->next = le->next;
  232|     18|    else
  233|     18|        list->head = le->next;
  234|     18|    if (le->next)
  ------------------
  |  Branch (234:9): [True: 1, False: 17]
  ------------------
  235|      1|        le->next->prev = le->prev;
  236|     17|    else
  237|     17|        list->tail = le->prev;
  238|     18|    le->next = le->prev = NULL;
  239|     18|    PZ_Unlock(list->lock);
  ------------------
  |  |  246|     18|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  240|     18|    PK11_FreeSlotListElement(list, le);
  241|     18|    return SECSuccess;
  242|     18|}
pk11_MoveListToList:
  251|  8.44k|{
  252|  8.44k|    if (src->head == NULL)
  ------------------
  |  Branch (252:9): [True: 8.44k, False: 0]
  ------------------
  253|  8.44k|        return SECSuccess;
  254|       |
  255|      0|    if (target->tail == NULL) {
  ------------------
  |  Branch (255:9): [True: 0, False: 0]
  ------------------
  256|      0|        target->head = src->head;
  257|      0|    } else {
  258|      0|        target->tail->next = src->head;
  259|      0|    }
  260|      0|    src->head->prev = target->tail;
  261|      0|    target->tail = src->tail;
  262|      0|    src->head = src->tail = NULL;
  263|      0|    return SECSuccess;
  264|  8.44k|}
PK11_GetFirstSafe:
  300|   383k|{
  301|   383k|    PK11SlotListElement *le;
  302|       |
  303|   383k|    PZ_Lock(list->lock);
  ------------------
  |  |  245|   383k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  304|   383k|    le = list->head;
  305|   383k|    if (le != NULL)
  ------------------
  |  Branch (305:9): [True: 383k, False: 0]
  ------------------
  306|   383k|        (le)->refCount++;
  307|   383k|    PZ_Unlock(list->lock);
  ------------------
  |  |  246|   383k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  308|   383k|    return le;
  309|   383k|}
PK11_FindSlotElement:
  342|     18|{
  343|     18|    PK11SlotListElement *le;
  344|       |
  345|     18|    for (le = PK11_GetFirstSafe(list); le;
  ------------------
  |  Branch (345:40): [True: 18, False: 0]
  ------------------
  346|     18|         le = PK11_GetNextSafe(list, le, PR_TRUE)) {
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  347|     18|        if (le->slot == slot)
  ------------------
  |  Branch (347:13): [True: 18, False: 0]
  ------------------
  348|     18|            return le;
  349|     18|    }
  350|      0|    return NULL;
  351|     18|}
PK11_NewSlotInfo:
  361|      2|{
  362|      2|    PK11SlotInfo *slot;
  363|       |
  364|      2|    slot = (PK11SlotInfo *)PORT_Alloc(sizeof(PK11SlotInfo));
  ------------------
  |  |   52|      2|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  365|      2|    if (slot == NULL) {
  ------------------
  |  Branch (365:9): [True: 0, False: 2]
  ------------------
  366|      0|        return slot;
  367|      0|    }
  368|      2|    slot->freeListLock = PZ_NewLock(nssILockFreelist);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  369|      2|    if (slot->freeListLock == NULL) {
  ------------------
  |  Branch (369:9): [True: 0, False: 2]
  ------------------
  370|      0|        PORT_Free(slot);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  371|      0|        return NULL;
  372|      0|    }
  373|      2|    slot->nssTokenLock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  374|      2|    if (slot->nssTokenLock == NULL) {
  ------------------
  |  Branch (374:9): [True: 0, False: 2]
  ------------------
  375|      0|        PZ_DestroyLock(slot->freeListLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  376|      0|        PORT_Free(slot);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  377|      0|        return NULL;
  378|      0|    }
  379|      2|    slot->sessionLock = mod->isThreadSafe ? PZ_NewLock(nssILockSession) : mod->refLock;
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  |  Branch (379:25): [True: 2, False: 0]
  ------------------
  380|      2|    if (slot->sessionLock == NULL) {
  ------------------
  |  Branch (380:9): [True: 0, False: 2]
  ------------------
  381|      0|        PZ_DestroyLock(slot->nssTokenLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  382|      0|        PZ_DestroyLock(slot->freeListLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  383|      0|        PORT_Free(slot);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  384|      0|        return NULL;
  385|      0|    }
  386|      2|    slot->freeSymKeysWithSessionHead = NULL;
  387|      2|    slot->freeSymKeysHead = NULL;
  388|      2|    slot->keyCount = 0;
  389|      2|    slot->maxKeyCount = 0;
  390|      2|    slot->functionList = NULL;
  391|      2|    slot->needTest = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  392|      2|    slot->isPerm = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  393|      2|    slot->isHW = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  394|      2|    slot->isInternal = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  395|      2|    slot->isThreadSafe = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  396|      2|    slot->disabled = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  397|      2|    slot->series = 1;
  398|      2|    slot->flagSeries = 0;
  399|      2|    slot->flagState = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  400|      2|    slot->wrapKey = 0;
  401|      2|    slot->wrapMechanism = CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|      2|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  402|      2|    slot->refKeys[0] = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  403|      2|    slot->reason = PK11_DIS_NONE;
  404|      2|    slot->readOnly = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  405|      2|    slot->needLogin = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  406|      2|    slot->hasRandom = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  407|      2|    slot->defRWSession = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  408|      2|    slot->protectedAuthPath = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  409|      2|    slot->flags = 0;
  410|      2|    slot->session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  411|      2|    slot->slotID = 0;
  412|      2|    slot->defaultFlags = 0;
  413|      2|    slot->refCount = 1;
  414|      2|    slot->askpw = 0;
  415|      2|    slot->timeout = 0;
  416|      2|    slot->mechanismList = NULL;
  417|      2|    slot->mechanismCount = 0;
  418|      2|    slot->cert_array = NULL;
  419|      2|    slot->cert_count = 0;
  420|      2|    slot->slot_name[0] = 0;
  421|      2|    slot->token_name[0] = 0;
  422|      2|    PORT_Memset(slot->serial, ' ', sizeof(slot->serial));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
  423|      2|    PORT_Memset(&slot->tokenInfo, 0, sizeof(slot->tokenInfo));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
  424|      2|    slot->module = NULL;
  425|      2|    slot->authTransact = 0;
  426|      2|    slot->authTime = LL_ZERO;
  ------------------
  |  |   41|      2|#define LL_ZERO     0L
  ------------------
  427|      2|    slot->minPassword = 0;
  428|      2|    slot->maxPassword = 0;
  429|      2|    slot->hasRootCerts = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  430|      2|    slot->hasRootTrust = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  431|      2|    slot->nssToken = NULL;
  432|      2|    slot->profileList = NULL;
  433|      2|    slot->profileCount = 0;
  434|      2|    return slot;
  435|      2|}
PK11_ReferenceSlot:
  440|  14.8M|{
  441|  14.8M|    PR_ATOMIC_INCREMENT(&slot->refCount);
  ------------------
  |  |  122|  14.8M|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  442|  14.8M|    return slot;
  443|  14.8M|}
PK11_DestroySlot:
  448|      2|{
  449|       |    /* free up the cached keys and sessions */
  450|      2|    PK11_CleanKeyList(slot);
  451|       |
  452|       |    /* free up all the sessions on this slot */
  453|      2|    if (slot->functionList) {
  ------------------
  |  Branch (453:9): [True: 2, False: 0]
  ------------------
  454|      2|        PK11_GETTAB(slot)
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
  455|      2|            ->C_CloseAllSessions(slot->slotID);
  456|      2|    }
  457|       |
  458|      2|    if (slot->mechanismList) {
  ------------------
  |  Branch (458:9): [True: 2, False: 0]
  ------------------
  459|      2|        PORT_Free(slot->mechanismList);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
  460|      2|    }
  461|      2|    if (slot->profileList) {
  ------------------
  |  Branch (461:9): [True: 0, False: 2]
  ------------------
  462|      0|        PORT_Free(slot->profileList);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  463|      0|    }
  464|      2|    if (slot->isThreadSafe && slot->sessionLock) {
  ------------------
  |  Branch (464:9): [True: 2, False: 0]
  |  Branch (464:31): [True: 2, False: 0]
  ------------------
  465|      2|        PZ_DestroyLock(slot->sessionLock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  466|      2|    }
  467|      2|    slot->sessionLock = NULL;
  468|      2|    if (slot->freeListLock) {
  ------------------
  |  Branch (468:9): [True: 2, False: 0]
  ------------------
  469|      2|        PZ_DestroyLock(slot->freeListLock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  470|      2|        slot->freeListLock = NULL;
  471|      2|    }
  472|      2|    if (slot->nssTokenLock) {
  ------------------
  |  Branch (472:9): [True: 2, False: 0]
  ------------------
  473|      2|        PZ_DestroyLock(slot->nssTokenLock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  474|      2|        slot->nssTokenLock = NULL;
  475|      2|    }
  476|       |
  477|       |    /* finally Tell our parent module that we've gone away so it can unload */
  478|      2|    if (slot->module) {
  ------------------
  |  Branch (478:9): [True: 2, False: 0]
  ------------------
  479|      2|        SECMOD_SlotDestroyModule(slot->module, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  480|      2|    }
  481|       |
  482|       |    /* ok, well not quit finally... now we free the memory */
  483|      2|    PORT_Free(slot);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
  484|      2|}
PK11_FreeSlot:
  489|  14.8M|{
  490|  14.8M|    if (PR_ATOMIC_DECREMENT(&slot->refCount) == 0) {
  ------------------
  |  |  123|  14.8M|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (490:9): [True: 2, False: 14.8M]
  ------------------
  491|      2|        PK11_DestroySlot(slot);
  492|      2|    }
  493|  14.8M|}
PK11_EnterSlotMonitor:
  497|  1.02M|{
  498|  1.02M|    PZ_Lock(slot->sessionLock);
  ------------------
  |  |  245|  1.02M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  499|  1.02M|}
PK11_ExitSlotMonitor:
  503|  1.02M|{
  504|  1.02M|    PZ_Unlock(slot->sessionLock);
  ------------------
  |  |  246|  1.02M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  505|  1.02M|}
PK11_InitSlotLists:
  831|      1|{
  832|      1|    pk11_InitSlotListStatic(&pk11_seedSlotList);
  833|      1|    pk11_InitSlotListStatic(&pk11_camelliaSlotList);
  834|      1|    pk11_InitSlotListStatic(&pk11_aesSlotList);
  835|      1|    pk11_InitSlotListStatic(&pk11_desSlotList);
  836|      1|    pk11_InitSlotListStatic(&pk11_rc4SlotList);
  837|      1|    pk11_InitSlotListStatic(&pk11_rc2SlotList);
  838|      1|    pk11_InitSlotListStatic(&pk11_rc5SlotList);
  839|      1|    pk11_InitSlotListStatic(&pk11_md5SlotList);
  840|      1|    pk11_InitSlotListStatic(&pk11_md2SlotList);
  841|      1|    pk11_InitSlotListStatic(&pk11_sha1SlotList);
  842|      1|    pk11_InitSlotListStatic(&pk11_rsaSlotList);
  843|      1|    pk11_InitSlotListStatic(&pk11_dsaSlotList);
  844|      1|    pk11_InitSlotListStatic(&pk11_dhSlotList);
  845|      1|    pk11_InitSlotListStatic(&pk11_ecSlotList);
  846|      1|    pk11_InitSlotListStatic(&pk11_ideaSlotList);
  847|      1|    pk11_InitSlotListStatic(&pk11_sslSlotList);
  848|      1|    pk11_InitSlotListStatic(&pk11_tlsSlotList);
  849|      1|    pk11_InitSlotListStatic(&pk11_randomSlotList);
  850|      1|    pk11_InitSlotListStatic(&pk11_sha256SlotList);
  851|      1|    pk11_InitSlotListStatic(&pk11_sha512SlotList);
  852|      1|    return SECSuccess;
  853|      1|}
PK11_DestroySlotLists:
  857|      1|{
  858|      1|    pk11_FreeSlotListStatic(&pk11_seedSlotList);
  859|      1|    pk11_FreeSlotListStatic(&pk11_camelliaSlotList);
  860|      1|    pk11_FreeSlotListStatic(&pk11_aesSlotList);
  861|      1|    pk11_FreeSlotListStatic(&pk11_desSlotList);
  862|      1|    pk11_FreeSlotListStatic(&pk11_rc4SlotList);
  863|      1|    pk11_FreeSlotListStatic(&pk11_rc2SlotList);
  864|      1|    pk11_FreeSlotListStatic(&pk11_rc5SlotList);
  865|      1|    pk11_FreeSlotListStatic(&pk11_md5SlotList);
  866|      1|    pk11_FreeSlotListStatic(&pk11_md2SlotList);
  867|      1|    pk11_FreeSlotListStatic(&pk11_sha1SlotList);
  868|      1|    pk11_FreeSlotListStatic(&pk11_rsaSlotList);
  869|      1|    pk11_FreeSlotListStatic(&pk11_dsaSlotList);
  870|      1|    pk11_FreeSlotListStatic(&pk11_dhSlotList);
  871|      1|    pk11_FreeSlotListStatic(&pk11_ecSlotList);
  872|      1|    pk11_FreeSlotListStatic(&pk11_ideaSlotList);
  873|      1|    pk11_FreeSlotListStatic(&pk11_sslSlotList);
  874|      1|    pk11_FreeSlotListStatic(&pk11_tlsSlotList);
  875|      1|    pk11_FreeSlotListStatic(&pk11_randomSlotList);
  876|      1|    pk11_FreeSlotListStatic(&pk11_sha256SlotList);
  877|      1|    pk11_FreeSlotListStatic(&pk11_sha512SlotList);
  878|      1|    return;
  879|      1|}
PK11_GetSlotList:
  884|   383k|{
  885|       |/* XXX a workaround for Bugzilla bug #55267 */
  886|       |#if defined(HPUX) && defined(__LP64__)
  887|       |    if (CKM_INVALID_MECHANISM == type)
  888|       |        return NULL;
  889|       |#endif
  890|   383k|    switch (type) {
  ------------------
  |  Branch (890:13): [True: 4.21k, False: 378k]
  ------------------
  891|      2|        case CKM_SEED_CBC:
  ------------------
  |  | 1157|      2|#define CKM_SEED_CBC 0x00000652UL
  ------------------
  |  Branch (891:9): [True: 2, False: 383k]
  ------------------
  892|      2|        case CKM_SEED_ECB:
  ------------------
  |  | 1156|      2|#define CKM_SEED_ECB 0x00000651UL
  ------------------
  |  Branch (892:9): [True: 0, False: 383k]
  ------------------
  893|      2|            return &pk11_seedSlotList;
  894|      2|        case CKM_CAMELLIA_CBC:
  ------------------
  |  | 1137|      2|#define CKM_CAMELLIA_CBC 0x00000552UL
  ------------------
  |  Branch (894:9): [True: 2, False: 383k]
  ------------------
  895|      2|        case CKM_CAMELLIA_ECB:
  ------------------
  |  | 1136|      2|#define CKM_CAMELLIA_ECB 0x00000551UL
  ------------------
  |  Branch (895:9): [True: 0, False: 383k]
  ------------------
  896|      2|            return &pk11_camelliaSlotList;
  897|      3|        case CKM_AES_CBC:
  ------------------
  |  | 1108|      3|#define CKM_AES_CBC 0x00001082UL
  ------------------
  |  Branch (897:9): [True: 3, False: 383k]
  ------------------
  898|      3|        case CKM_AES_CCM:
  ------------------
  |  | 1116|      3|#define CKM_AES_CCM 0x00001088UL
  ------------------
  |  Branch (898:9): [True: 0, False: 383k]
  ------------------
  899|      3|        case CKM_AES_CTR:
  ------------------
  |  | 1113|      3|#define CKM_AES_CTR 0x00001086UL
  ------------------
  |  Branch (899:9): [True: 0, False: 383k]
  ------------------
  900|      3|        case CKM_AES_CTS:
  ------------------
  |  | 1117|      3|#define CKM_AES_CTS 0x00001089UL
  ------------------
  |  Branch (900:9): [True: 0, False: 383k]
  ------------------
  901|      3|        case CKM_AES_GCM:
  ------------------
  |  | 1115|      3|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (901:9): [True: 0, False: 383k]
  ------------------
  902|      3|        case CKM_AES_ECB:
  ------------------
  |  | 1107|      3|#define CKM_AES_ECB 0x00001081UL
  ------------------
  |  Branch (902:9): [True: 0, False: 383k]
  ------------------
  903|      3|            return &pk11_aesSlotList;
  904|      2|        case CKM_DES_CBC:
  ------------------
  |  |  816|      2|#define CKM_DES_CBC 0x00000122UL
  ------------------
  |  Branch (904:9): [True: 2, False: 383k]
  ------------------
  905|      2|        case CKM_DES_ECB:
  ------------------
  |  |  815|      2|#define CKM_DES_ECB 0x00000121UL
  ------------------
  |  Branch (905:9): [True: 0, False: 383k]
  ------------------
  906|      2|        case CKM_DES3_ECB:
  ------------------
  |  |  825|      2|#define CKM_DES3_ECB 0x00000132UL
  ------------------
  |  Branch (906:9): [True: 0, False: 383k]
  ------------------
  907|      2|        case CKM_DES3_CBC:
  ------------------
  |  |  826|      2|#define CKM_DES3_CBC 0x00000133UL
  ------------------
  |  Branch (907:9): [True: 0, False: 383k]
  ------------------
  908|      2|            return &pk11_desSlotList;
  909|      2|        case CKM_RC4:
  ------------------
  |  |  813|      2|#define CKM_RC4 0x00000111UL
  ------------------
  |  Branch (909:9): [True: 2, False: 383k]
  ------------------
  910|      2|            return &pk11_rc4SlotList;
  911|      0|        case CKM_RC5_CBC:
  ------------------
  |  |  943|      0|#define CKM_RC5_CBC 0x00000332UL
  ------------------
  |  Branch (911:9): [True: 0, False: 383k]
  ------------------
  912|      0|            return &pk11_rc5SlotList;
  913|  98.7k|        case CKM_SHA_1:
  ------------------
  |  |  859|  98.7k|#define CKM_SHA_1 0x00000220UL
  ------------------
  |  Branch (913:9): [True: 98.7k, False: 284k]
  ------------------
  914|  98.7k|            return &pk11_sha1SlotList;
  915|      0|        case CKM_SHA224:
  ------------------
  |  |  887|      0|#define CKM_SHA224 0x00000255UL
  ------------------
  |  Branch (915:9): [True: 0, False: 383k]
  ------------------
  916|  60.3k|        case CKM_SHA256:
  ------------------
  |  |  876|  60.3k|#define CKM_SHA256 0x00000250UL
  ------------------
  |  Branch (916:9): [True: 60.3k, False: 322k]
  ------------------
  917|  60.3k|        case CKM_SHA3_224:
  ------------------
  |  |  902|  60.3k|#define CKM_SHA3_224 0x000002B5UL
  ------------------
  |  Branch (917:9): [True: 0, False: 383k]
  ------------------
  918|  60.3k|        case CKM_SHA3_256:
  ------------------
  |  |  898|  60.3k|#define CKM_SHA3_256 0x000002B0UL
  ------------------
  |  Branch (918:9): [True: 0, False: 383k]
  ------------------
  919|  60.3k|            return &pk11_sha256SlotList;
  920|  46.0k|        case CKM_SHA384:
  ------------------
  |  |  879|  46.0k|#define CKM_SHA384 0x00000260UL
  ------------------
  |  Branch (920:9): [True: 46.0k, False: 337k]
  ------------------
  921|  51.9k|        case CKM_SHA512:
  ------------------
  |  |  882|  51.9k|#define CKM_SHA512 0x00000270UL
  ------------------
  |  Branch (921:9): [True: 5.85k, False: 377k]
  ------------------
  922|  51.9k|        case CKM_SHA3_384:
  ------------------
  |  |  906|  51.9k|#define CKM_SHA3_384 0x000002C0UL
  ------------------
  |  Branch (922:9): [True: 0, False: 383k]
  ------------------
  923|  51.9k|        case CKM_SHA3_512:
  ------------------
  |  |  910|  51.9k|#define CKM_SHA3_512 0x000002D0UL
  ------------------
  |  Branch (923:9): [True: 0, False: 383k]
  ------------------
  924|  51.9k|            return &pk11_sha512SlotList;
  925|  10.7k|        case CKM_MD5:
  ------------------
  |  |  853|  10.7k|#define CKM_MD5 0x00000210UL
  ------------------
  |  Branch (925:9): [True: 10.7k, False: 372k]
  ------------------
  926|  10.7k|            return &pk11_md5SlotList;
  927|      2|        case CKM_MD2:
  ------------------
  |  |  847|      2|#define CKM_MD2 0x00000200UL
  ------------------
  |  Branch (927:9): [True: 2, False: 383k]
  ------------------
  928|      2|            return &pk11_md2SlotList;
  929|      0|        case CKM_RC2_ECB:
  ------------------
  |  |  804|      0|#define CKM_RC2_ECB 0x00000101UL
  ------------------
  |  Branch (929:9): [True: 0, False: 383k]
  ------------------
  930|      2|        case CKM_RC2_CBC:
  ------------------
  |  |  805|      2|#define CKM_RC2_CBC 0x00000102UL
  ------------------
  |  Branch (930:9): [True: 2, False: 383k]
  ------------------
  931|      2|            return &pk11_rc2SlotList;
  932|     24|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|     24|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (932:9): [True: 24, False: 383k]
  ------------------
  933|     24|        case CKM_RSA_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  719|     24|#define CKM_RSA_PKCS_KEY_PAIR_GEN 0x00000000UL
  ------------------
  |  Branch (933:9): [True: 0, False: 383k]
  ------------------
  934|     24|        case CKM_RSA_X_509:
  ------------------
  |  |  722|     24|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (934:9): [True: 0, False: 383k]
  ------------------
  935|     24|            return &pk11_rsaSlotList;
  936|      0|        case CKM_DSA:
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (936:9): [True: 0, False: 383k]
  ------------------
  937|      0|            return &pk11_dsaSlotList;
  938|  29.0k|        case CKM_DH_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  758|  29.0k|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  |  Branch (938:9): [True: 29.0k, False: 354k]
  ------------------
  939|  29.0k|        case CKM_DH_PKCS_DERIVE:
  ------------------
  |  |  759|  29.0k|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
  |  Branch (939:9): [True: 2, False: 383k]
  ------------------
  940|  29.0k|            return &pk11_dhSlotList;
  941|      2|        case CKM_EDDSA:
  ------------------
  |  | 1174|      2|#define CKM_EDDSA 0x00001057UL
  ------------------
  |  Branch (941:9): [True: 2, False: 383k]
  ------------------
  942|      2|        case CKM_EC_EDWARDS_KEY_PAIR_GEN:
  ------------------
  |  | 1172|      2|#define CKM_EC_EDWARDS_KEY_PAIR_GEN 0x00001055UL
  ------------------
  |  Branch (942:9): [True: 0, False: 383k]
  ------------------
  943|      4|        case CKM_ECDSA:
  ------------------
  |  | 1074|      4|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (943:9): [True: 2, False: 383k]
  ------------------
  944|      4|        case CKM_ECDSA_SHA1:
  ------------------
  |  | 1075|      4|#define CKM_ECDSA_SHA1 0x00001042UL
  ------------------
  |  Branch (944:9): [True: 0, False: 383k]
  ------------------
  945|      5|        case CKM_EC_KEY_PAIR_GEN: /* aka CKM_ECDSA_KEY_PAIR_GEN */
  ------------------
  |  | 1072|      5|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  |  Branch (945:9): [True: 1, False: 383k]
  ------------------
  946|      5|        case CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN:
  ------------------
  |  |  274|      5|#define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN (CKM_NSS + 47)
  |  |  ------------------
  |  |  |  |  162|      5|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      5|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      5|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (946:9): [True: 0, False: 383k]
  ------------------
  947|  7.01k|        case CKM_ECDH1_DERIVE:
  ------------------
  |  | 1086|  7.01k|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  |  Branch (947:9): [True: 7.00k, False: 376k]
  ------------------
  948|  7.01k|        case CKM_NSS_KYBER_KEY_PAIR_GEN: /* Bug 1893029 */
  ------------------
  |  |  267|  7.01k|#define CKM_NSS_KYBER_KEY_PAIR_GEN (CKM_NSS + 45)
  |  |  ------------------
  |  |  |  |  162|  7.01k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  7.01k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  7.01k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (948:9): [True: 0, False: 383k]
  ------------------
  949|  7.11k|        case CKM_NSS_KYBER:
  ------------------
  |  |  268|  7.11k|#define CKM_NSS_KYBER (CKM_NSS + 46)
  |  |  ------------------
  |  |  |  |  162|  7.11k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  7.11k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  7.11k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (949:9): [True: 99, False: 383k]
  ------------------
  950|  7.11k|        case CKM_NSS_ML_KEM_KEY_PAIR_GEN: /* Bug 1893029 */
  ------------------
  |  |  277|  7.11k|#define CKM_NSS_ML_KEM_KEY_PAIR_GEN (CKM_NSS + 48)
  |  |  ------------------
  |  |  |  |  162|  7.11k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  7.11k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  7.11k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (950:9): [True: 0, False: 383k]
  ------------------
  951|  7.11k|        case CKM_NSS_ML_KEM:
  ------------------
  |  |  278|  7.11k|#define CKM_NSS_ML_KEM (CKM_NSS + 49)
  |  |  ------------------
  |  |  |  |  162|  7.11k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  7.11k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  7.11k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (951:9): [True: 0, False: 383k]
  ------------------
  952|  7.11k|            return &pk11_ecSlotList;
  953|      2|        case CKM_SSL3_PRE_MASTER_KEY_GEN:
  ------------------
  |  |  959|      2|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
  |  Branch (953:9): [True: 2, False: 383k]
  ------------------
  954|      2|        case CKM_SSL3_MASTER_KEY_DERIVE:
  ------------------
  |  |  960|      2|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
  |  Branch (954:9): [True: 0, False: 383k]
  ------------------
  955|      2|        case CKM_SSL3_SHA1_MAC:
  ------------------
  |  |  976|      2|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
  |  Branch (955:9): [True: 0, False: 383k]
  ------------------
  956|      2|        case CKM_SSL3_MD5_MAC:
  ------------------
  |  |  975|      2|#define CKM_SSL3_MD5_MAC 0x00000380UL
  ------------------
  |  Branch (956:9): [True: 0, False: 383k]
  ------------------
  957|      2|            return &pk11_sslSlotList;
  958|      2|        case CKM_TLS_MASTER_KEY_DERIVE:
  ------------------
  |  |  968|      2|#define CKM_TLS_MASTER_KEY_DERIVE 0x00000375UL
  ------------------
  |  Branch (958:9): [True: 2, False: 383k]
  ------------------
  959|      2|        case CKM_TLS_KEY_AND_MAC_DERIVE:
  ------------------
  |  |  969|      2|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
  |  Branch (959:9): [True: 0, False: 383k]
  ------------------
  960|      2|        case CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256:
  ------------------
  |  |  235|      2|#define CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256 (CKM_NSS + 23)
  |  |  ------------------
  |  |  |  |  162|      2|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      2|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      2|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (960:9): [True: 0, False: 383k]
  ------------------
  961|      2|            return &pk11_tlsSlotList;
  962|      0|        case CKM_IDEA_CBC:
  ------------------
  |  |  949|      0|#define CKM_IDEA_CBC 0x00000342UL
  ------------------
  |  Branch (962:9): [True: 0, False: 383k]
  ------------------
  963|      0|        case CKM_IDEA_ECB:
  ------------------
  |  |  948|      0|#define CKM_IDEA_ECB 0x00000341UL
  ------------------
  |  Branch (963:9): [True: 0, False: 383k]
  ------------------
  964|      0|            return &pk11_ideaSlotList;
  965|   120k|        case CKM_FAKE_RANDOM:
  ------------------
  |  |  154|   120k|#define CKM_FAKE_RANDOM 0x80000efeUL
  ------------------
  |  Branch (965:9): [True: 120k, False: 262k]
  ------------------
  966|   120k|            return &pk11_randomSlotList;
  967|   383k|    }
  968|  4.21k|    return NULL;
  969|   383k|}
PK11_LoadSlotList:
  978|      2|{
  979|      2|    int i;
  980|       |
  981|      3|    for (i = 0; i < count; i++) {
  ------------------
  |  Branch (981:17): [True: 2, False: 1]
  ------------------
  982|      2|        if (psi[i].slotID == slot->slotID)
  ------------------
  |  Branch (982:13): [True: 1, False: 1]
  ------------------
  983|      1|            break;
  984|      2|    }
  985|       |
  986|      2|    if (i == count)
  ------------------
  |  Branch (986:9): [True: 1, False: 1]
  ------------------
  987|      1|        return;
  988|       |
  989|      1|    slot->defaultFlags = psi[i].defaultFlags;
  990|      1|    slot->askpw = psi[i].askpw;
  991|      1|    slot->timeout = psi[i].timeout;
  992|      1|    slot->hasRootCerts = psi[i].hasRootCerts;
  993|       |
  994|       |    /* if the slot is already disabled, don't load them into the
  995|       |     * default slot lists. We get here so we can save the default
  996|       |     * list value. */
  997|      1|    if (slot->disabled)
  ------------------
  |  Branch (997:9): [True: 0, False: 1]
  ------------------
  998|      0|        return;
  999|       |
 1000|       |    /* if the user has disabled us, don't load us in */
 1001|      1|    if (slot->defaultFlags & PK11_DISABLE_FLAG) {
  ------------------
  |  |   37|      1|#define PK11_DISABLE_FLAG 0x40000000L
  ------------------
  |  Branch (1001:9): [True: 0, False: 1]
  ------------------
 1002|      0|        slot->disabled = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1003|      0|        slot->reason = PK11_DIS_USER_SELECTED;
 1004|       |        /* free up sessions and things?? */
 1005|      0|        return;
 1006|      0|    }
 1007|       |
 1008|     23|    for (i = 0; i < num_pk11_default_mechanisms; i++) {
  ------------------
  |  Branch (1008:17): [True: 22, False: 1]
  ------------------
 1009|     22|        if (slot->defaultFlags & PK11_DefaultArray[i].flag) {
  ------------------
  |  Branch (1009:13): [True: 18, False: 4]
  ------------------
 1010|     18|            CK_MECHANISM_TYPE mechanism = PK11_DefaultArray[i].mechanism;
 1011|     18|            PK11SlotList *slotList = PK11_GetSlotList(mechanism);
 1012|       |
 1013|     18|            if (slotList)
  ------------------
  |  Branch (1013:17): [True: 18, False: 0]
  ------------------
 1014|     18|                PK11_AddSlotToList(slotList, slot, PR_FALSE);
  ------------------
  |  |  438|     18|#define PR_FALSE 0
  ------------------
 1015|     18|        }
 1016|     22|    }
 1017|       |
 1018|      1|    return;
 1019|      1|}
PK11_ClearSlotList:
 1065|      2|{
 1066|      2|    int i;
 1067|       |
 1068|      2|    if (slot->disabled)
  ------------------
  |  Branch (1068:9): [True: 0, False: 2]
  ------------------
 1069|      0|        return;
 1070|      2|    if (slot->defaultFlags == 0)
  ------------------
  |  Branch (1070:9): [True: 1, False: 1]
  ------------------
 1071|      1|        return;
 1072|       |
 1073|     23|    for (i = 0; i < num_pk11_default_mechanisms; i++) {
  ------------------
  |  Branch (1073:17): [True: 22, False: 1]
  ------------------
 1074|     22|        if (slot->defaultFlags & PK11_DefaultArray[i].flag) {
  ------------------
  |  Branch (1074:13): [True: 18, False: 4]
  ------------------
 1075|     18|            CK_MECHANISM_TYPE mechanism = PK11_DefaultArray[i].mechanism;
 1076|     18|            PK11SlotList *slotList = PK11_GetSlotList(mechanism);
 1077|     18|            PK11SlotListElement *le = NULL;
 1078|       |
 1079|     18|            if (slotList)
  ------------------
  |  Branch (1079:17): [True: 18, False: 0]
  ------------------
 1080|     18|                le = PK11_FindSlotElement(slotList, slot);
 1081|       |
 1082|     18|            if (le) {
  ------------------
  |  Branch (1082:17): [True: 18, False: 0]
  ------------------
 1083|     18|                PK11_DeleteSlotFromList(slotList, le);
 1084|     18|                PK11_FreeSlotListElement(slotList, le);
 1085|     18|            }
 1086|     18|        }
 1087|     22|    }
 1088|      1|}
PK11_MakeString:
 1099|      4|{
 1100|      4|    int i;
 1101|      4|    char *newString;
 1102|     71|    for (i = (stringLen - 1); i >= 0; i--) {
  ------------------
  |  Branch (1102:31): [True: 71, False: 0]
  ------------------
 1103|     71|        if (staticString[i] != ' ')
  ------------------
  |  Branch (1103:13): [True: 4, False: 67]
  ------------------
 1104|      4|            break;
 1105|     71|    }
 1106|       |    /* move i to point to the last space */
 1107|      4|    i++;
 1108|      4|    if (arena) {
  ------------------
  |  Branch (1108:9): [True: 0, False: 4]
  ------------------
 1109|      0|        newString = (char *)PORT_ArenaAlloc(arena, i + 1 /* space for NULL */);
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1110|      4|    } else if (space) {
  ------------------
  |  Branch (1110:16): [True: 4, False: 0]
  ------------------
 1111|      4|        newString = space;
 1112|      4|    } else {
 1113|      0|        newString = (char *)PORT_Alloc(i + 1 /* space for NULL */);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1114|      0|    }
 1115|      4|    if (newString == NULL)
  ------------------
  |  Branch (1115:9): [True: 0, False: 4]
  ------------------
 1116|      0|        return NULL;
 1117|       |
 1118|      4|    if (i)
  ------------------
  |  Branch (1118:9): [True: 4, False: 0]
  ------------------
 1119|      4|        PORT_Memcpy(newString, staticString, i);
  ------------------
  |  |  180|      4|#define PORT_Memcpy memcpy
  ------------------
 1120|      4|    newString[i] = 0;
 1121|       |
 1122|      4|    return newString;
 1123|      4|}
PK11_ReadMechanismList:
 1153|      2|{
 1154|      2|    CK_ULONG count;
 1155|      2|    CK_RV crv;
 1156|      2|    PRUint32 i;
 1157|       |
 1158|      2|    if (slot->mechanismList) {
  ------------------
  |  Branch (1158:9): [True: 0, False: 2]
  ------------------
 1159|      0|        PORT_Free(slot->mechanismList);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1160|      0|        slot->mechanismList = NULL;
 1161|      0|    }
 1162|      2|    slot->mechanismCount = 0;
 1163|       |
 1164|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1164:9): [True: 0, False: 2]
  ------------------
 1165|      0|        PK11_EnterSlotMonitor(slot);
 1166|      2|    crv = PK11_GETTAB(slot)->C_GetMechanismList(slot->slotID, NULL, &count);
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1167|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1167:9): [True: 0, False: 2]
  ------------------
 1168|      0|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (1168:13): [True: 0, False: 0]
  ------------------
 1169|      0|            PK11_ExitSlotMonitor(slot);
 1170|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1171|      0|        return SECFailure;
 1172|      0|    }
 1173|       |
 1174|      2|    slot->mechanismList = (CK_MECHANISM_TYPE *)
 1175|      2|        PORT_Alloc(count * sizeof(CK_MECHANISM_TYPE));
  ------------------
  |  |   52|      2|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1176|      2|    if (slot->mechanismList == NULL) {
  ------------------
  |  Branch (1176:9): [True: 0, False: 2]
  ------------------
 1177|      0|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (1177:13): [True: 0, False: 0]
  ------------------
 1178|      0|            PK11_ExitSlotMonitor(slot);
 1179|      0|        return SECFailure;
 1180|      0|    }
 1181|      2|    crv = PK11_GETTAB(slot)->C_GetMechanismList(slot->slotID,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1182|      2|                                                slot->mechanismList, &count);
 1183|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1183:9): [True: 0, False: 2]
  ------------------
 1184|      0|        PK11_ExitSlotMonitor(slot);
 1185|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1185:9): [True: 0, False: 2]
  ------------------
 1186|      0|        PORT_Free(slot->mechanismList);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1187|      0|        slot->mechanismList = NULL;
 1188|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1189|      0|        return SECSuccess;
 1190|      0|    }
 1191|      2|    slot->mechanismCount = count;
 1192|      2|    PORT_Memset(slot->mechanismBits, 0, sizeof(slot->mechanismBits));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 1193|       |
 1194|    409|    for (i = 0; i < count; i++) {
  ------------------
  |  Branch (1194:17): [True: 407, False: 2]
  ------------------
 1195|    407|        CK_MECHANISM_TYPE mech = slot->mechanismList[i];
 1196|    407|        if (mech < 0x7ff) {
  ------------------
  |  Branch (1196:13): [True: 240, False: 167]
  ------------------
 1197|    240|            slot->mechanismBits[mech & 0xff] |= 1 << (mech >> 8);
 1198|    240|        }
 1199|    407|    }
 1200|      2|    return SECSuccess;
 1201|      2|}
PK11_InitToken:
 1281|      2|{
 1282|      2|    CK_RV crv;
 1283|      2|    SECStatus rv;
 1284|      2|    PRStatus status;
 1285|      2|    NSSToken *nssToken;
 1286|       |
 1287|       |    /* set the slot flags to the current token values */
 1288|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1288:9): [True: 0, False: 2]
  ------------------
 1289|      0|        PK11_EnterSlotMonitor(slot);
 1290|      2|    crv = PK11_GETTAB(slot)->C_GetTokenInfo(slot->slotID, &slot->tokenInfo);
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1291|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1291:9): [True: 0, False: 2]
  ------------------
 1292|      0|        PK11_ExitSlotMonitor(slot);
 1293|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1293:9): [True: 0, False: 2]
  ------------------
 1294|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1295|      0|        return SECFailure;
 1296|      0|    }
 1297|       |
 1298|       |    /* set the slot flags to the current token values */
 1299|      2|    slot->series++; /* allow other objects to detect that the
 1300|       |                     * slot is different */
 1301|      2|    slot->flags = slot->tokenInfo.flags;
 1302|      2|    slot->needLogin = ((slot->tokenInfo.flags & CKF_LOGIN_REQUIRED) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  176|      2|#define CKF_LOGIN_REQUIRED 0x00000004UL       /* user must \
  ------------------
                  slot->needLogin = ((slot->tokenInfo.flags & CKF_LOGIN_REQUIRED) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  slot->needLogin = ((slot->tokenInfo.flags & CKF_LOGIN_REQUIRED) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  |  Branch (1302:24): [True: 0, False: 2]
  ------------------
 1303|      2|    slot->readOnly = ((slot->tokenInfo.flags & CKF_WRITE_PROTECTED) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  173|      2|#define CKF_WRITE_PROTECTED 0x00000002UL      /* token is \
  ------------------
                  slot->readOnly = ((slot->tokenInfo.flags & CKF_WRITE_PROTECTED) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
                  slot->readOnly = ((slot->tokenInfo.flags & CKF_WRITE_PROTECTED) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (1303:23): [True: 2, False: 0]
  ------------------
 1304|       |
 1305|      2|    slot->hasRandom = ((slot->tokenInfo.flags & CKF_RNG) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  171|      2|#define CKF_RNG 0x00000001UL                  /* has random # \
  ------------------
                  slot->hasRandom = ((slot->tokenInfo.flags & CKF_RNG) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
                  slot->hasRandom = ((slot->tokenInfo.flags & CKF_RNG) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (1305:24): [True: 2, False: 0]
  ------------------
 1306|      2|    slot->protectedAuthPath =
 1307|      2|        ((slot->tokenInfo.flags & CKF_PROTECTED_AUTHENTICATION_PATH)
  ------------------
  |  |  195|      2|#define CKF_PROTECTED_AUTHENTICATION_PATH 0x00000100UL
  ------------------
  |  Branch (1307:10): [True: 0, False: 2]
  ------------------
 1308|      2|             ? PR_TRUE
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1309|      2|             : PR_FALSE);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1310|      2|    slot->lastLoginCheck = 0;
 1311|      2|    slot->lastState = 0;
 1312|       |    /* on some platforms Active Card incorrectly sets the
 1313|       |     * CKF_PROTECTED_AUTHENTICATION_PATH bit when it doesn't mean to. */
 1314|      2|    if (slot->isActiveCard) {
  ------------------
  |  Branch (1314:9): [True: 0, False: 2]
  ------------------
 1315|      0|        slot->protectedAuthPath = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1316|      0|    }
 1317|      2|    (void)PK11_MakeString(NULL, slot->token_name,
 1318|      2|                          (char *)slot->tokenInfo.label, sizeof(slot->tokenInfo.label));
 1319|      2|    slot->minPassword = slot->tokenInfo.ulMinPinLen;
 1320|      2|    slot->maxPassword = slot->tokenInfo.ulMaxPinLen;
 1321|      2|    PORT_Memcpy(slot->serial, slot->tokenInfo.serialNumber, sizeof(slot->serial));
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 1322|       |
 1323|      2|    nssToken = PK11Slot_GetNSSToken(slot);
 1324|      2|    nssToken_UpdateName(nssToken); /* null token is OK */
 1325|      2|    (void)nssToken_Destroy(nssToken);
 1326|       |
 1327|      2|    slot->defRWSession = (PRBool)((!slot->readOnly) &&
  ------------------
  |  Branch (1327:35): [True: 0, False: 2]
  ------------------
 1328|      2|                                  (slot->tokenInfo.ulMaxSessionCount == 1));
  ------------------
  |  Branch (1328:35): [True: 0, False: 0]
  ------------------
 1329|      2|    rv = PK11_ReadMechanismList(slot);
 1330|      2|    if (rv != SECSuccess)
  ------------------
  |  Branch (1330:9): [True: 0, False: 2]
  ------------------
 1331|      0|        return rv;
 1332|       |
 1333|      2|    slot->hasRSAInfo = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1334|      2|    slot->RSAInfoFlags = 0;
 1335|       |
 1336|       |    /* initialize the maxKeyCount value */
 1337|      2|    if (slot->tokenInfo.ulMaxSessionCount == 0) {
  ------------------
  |  Branch (1337:9): [True: 2, False: 0]
  ------------------
 1338|      2|        slot->maxKeyCount = 800; /* should be #define or a config param */
 1339|      2|    } else if (slot->tokenInfo.ulMaxSessionCount < 20) {
  ------------------
  |  Branch (1339:16): [True: 0, False: 0]
  ------------------
 1340|       |        /* don't have enough sessions to keep that many keys around */
 1341|      0|        slot->maxKeyCount = 0;
 1342|      0|    } else {
 1343|      0|        slot->maxKeyCount = slot->tokenInfo.ulMaxSessionCount / 2;
 1344|      0|    }
 1345|       |
 1346|       |    /* Make sure our session handle is valid */
 1347|      2|    if (slot->session == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1347:9): [True: 2, False: 0]
  ------------------
 1348|       |        /* we know we don't have a valid session, go get one */
 1349|      2|        CK_SESSION_HANDLE session;
 1350|       |
 1351|       |        /* session should be Readonly, serial */
 1352|      2|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (1352:13): [True: 0, False: 2]
  ------------------
 1353|      0|            PK11_EnterSlotMonitor(slot);
 1354|      2|        crv = PK11_GETTAB(slot)->C_OpenSession(slot->slotID,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1355|      2|                                               (slot->defRWSession ? CKF_RW_SESSION : 0) | CKF_SERIAL_SESSION,
  ------------------
  |  |  302|      0|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
                                                             (slot->defRWSession ? CKF_RW_SESSION : 0) | CKF_SERIAL_SESSION,
  ------------------
  |  |  303|      2|#define CKF_SERIAL_SESSION 0x00000004UL /* no parallel */
  ------------------
  |  Branch (1355:49): [True: 0, False: 2]
  ------------------
 1356|      2|                                               slot, pk11_notify, &session);
 1357|      2|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (1357:13): [True: 0, False: 2]
  ------------------
 1358|      0|            PK11_ExitSlotMonitor(slot);
 1359|      2|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1359:13): [True: 0, False: 2]
  ------------------
 1360|      0|            PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1361|      0|            return SECFailure;
 1362|      0|        }
 1363|      2|        slot->session = session;
 1364|      2|    } else {
 1365|       |        /* The session we have may be defunct (the token associated with it)
 1366|       |         * has been removed   */
 1367|      0|        CK_SESSION_INFO sessionInfo;
 1368|       |
 1369|      0|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (1369:13): [True: 0, False: 0]
  ------------------
 1370|      0|            PK11_EnterSlotMonitor(slot);
 1371|      0|        crv = PK11_GETTAB(slot)->C_GetSessionInfo(slot->session, &sessionInfo);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1372|      0|        if (crv == CKR_DEVICE_ERROR) {
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  |  Branch (1372:13): [True: 0, False: 0]
  ------------------
 1373|      0|            PK11_GETTAB(slot)
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1374|      0|                ->C_CloseSession(slot->session);
 1375|      0|            crv = CKR_SESSION_CLOSED;
  ------------------
  |  | 1463|      0|#define CKR_SESSION_CLOSED 0x000000B0UL
  ------------------
 1376|      0|        }
 1377|      0|        if ((crv == CKR_SESSION_CLOSED) || (crv == CKR_SESSION_HANDLE_INVALID)) {
  ------------------
  |  | 1463|      0|#define CKR_SESSION_CLOSED 0x000000B0UL
  ------------------
                      if ((crv == CKR_SESSION_CLOSED) || (crv == CKR_SESSION_HANDLE_INVALID)) {
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  |  Branch (1377:13): [True: 0, False: 0]
  |  Branch (1377:44): [True: 0, False: 0]
  ------------------
 1378|      0|            crv = PK11_GETTAB(slot)->C_OpenSession(slot->slotID,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1379|      0|                                                   (slot->defRWSession ? CKF_RW_SESSION : 0) | CKF_SERIAL_SESSION,
  ------------------
  |  |  302|      0|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
                                                                 (slot->defRWSession ? CKF_RW_SESSION : 0) | CKF_SERIAL_SESSION,
  ------------------
  |  |  303|      0|#define CKF_SERIAL_SESSION 0x00000004UL /* no parallel */
  ------------------
  |  Branch (1379:53): [True: 0, False: 0]
  ------------------
 1380|      0|                                                   slot, pk11_notify, &slot->session);
 1381|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1381:17): [True: 0, False: 0]
  ------------------
 1382|      0|                PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1383|      0|                slot->session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 1384|      0|                if (!slot->isThreadSafe)
  ------------------
  |  Branch (1384:21): [True: 0, False: 0]
  ------------------
 1385|      0|                    PK11_ExitSlotMonitor(slot);
 1386|      0|                return SECFailure;
 1387|      0|            }
 1388|      0|        }
 1389|      0|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (1389:13): [True: 0, False: 0]
  ------------------
 1390|      0|            PK11_ExitSlotMonitor(slot);
 1391|      0|    }
 1392|       |
 1393|      2|    nssToken = PK11Slot_GetNSSToken(slot);
 1394|      2|    status = nssToken_Refresh(nssToken); /* null token is OK */
 1395|      2|    (void)nssToken_Destroy(nssToken);
 1396|      2|    if (status != PR_SUCCESS)
  ------------------
  |  Branch (1396:9): [True: 0, False: 2]
  ------------------
 1397|      0|        return SECFailure;
 1398|       |
 1399|       |    /* Not all tokens have profile objects or even recognize what profile
 1400|       |     * objects are it's OK for pk11_ReadProfileList to fail */
 1401|      2|    (void)pk11_ReadProfileList(slot);
 1402|       |
 1403|      2|    if (!(slot->isInternal) && (slot->hasRandom)) {
  ------------------
  |  Branch (1403:9): [True: 0, False: 2]
  |  Branch (1403:32): [True: 0, False: 0]
  ------------------
 1404|       |        /* if this slot has a random number generater, use it to add entropy
 1405|       |         * to the internal slot. */
 1406|      0|        PK11SlotInfo *int_slot = PK11_GetInternalSlot();
 1407|       |
 1408|      0|        if (int_slot) {
  ------------------
  |  Branch (1408:13): [True: 0, False: 0]
  ------------------
 1409|      0|            unsigned char random_bytes[32];
 1410|       |
 1411|       |            /* if this slot can issue random numbers, get some entropy from
 1412|       |             * that random number generater and give it to our internal token.
 1413|       |             */
 1414|      0|            PK11_EnterSlotMonitor(slot);
 1415|      0|            crv = PK11_GETTAB(slot)->C_GenerateRandom(slot->session, random_bytes, sizeof(random_bytes));
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1416|      0|            PK11_ExitSlotMonitor(slot);
 1417|      0|            if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1417:17): [True: 0, False: 0]
  ------------------
 1418|      0|                PK11_EnterSlotMonitor(int_slot);
 1419|      0|                PK11_GETTAB(int_slot)
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1420|      0|                    ->C_SeedRandom(int_slot->session,
 1421|      0|                                   random_bytes, sizeof(random_bytes));
 1422|      0|                PK11_ExitSlotMonitor(int_slot);
 1423|      0|            }
 1424|       |
 1425|       |            /* Now return the favor and send entropy to the token's random
 1426|       |             * number generater */
 1427|      0|            PK11_EnterSlotMonitor(int_slot);
 1428|      0|            crv = PK11_GETTAB(int_slot)->C_GenerateRandom(int_slot->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1429|      0|                                                          random_bytes, sizeof(random_bytes));
 1430|      0|            PK11_ExitSlotMonitor(int_slot);
 1431|      0|            if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1431:17): [True: 0, False: 0]
  ------------------
 1432|      0|                PK11_EnterSlotMonitor(slot);
 1433|      0|                crv = PK11_GETTAB(slot)->C_SeedRandom(slot->session,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1434|      0|                                                      random_bytes, sizeof(random_bytes));
 1435|      0|                PK11_ExitSlotMonitor(slot);
 1436|      0|            }
 1437|      0|            PK11_FreeSlot(int_slot);
 1438|      0|        }
 1439|      0|    }
 1440|       |    /* work around a problem in softoken where it incorrectly
 1441|       |     * reports databases opened read only as read/write. */
 1442|      2|    if (slot->isInternal && !slot->readOnly) {
  ------------------
  |  Branch (1442:9): [True: 2, False: 0]
  |  Branch (1442:29): [True: 0, False: 2]
  ------------------
 1443|      0|        CK_SESSION_HANDLE session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 1444|       |
 1445|       |        /* try to open a R/W session */
 1446|      0|        crv = PK11_GETTAB(slot)->C_OpenSession(slot->slotID,
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1447|      0|                                               CKF_RW_SESSION | CKF_SERIAL_SESSION, slot, pk11_notify, &session);
  ------------------
  |  |  302|      0|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
                                                             CKF_RW_SESSION | CKF_SERIAL_SESSION, slot, pk11_notify, &session);
  ------------------
  |  |  303|      0|#define CKF_SERIAL_SESSION 0x00000004UL /* no parallel */
  ------------------
 1448|       |        /* what a well behaved token should return if you open
 1449|       |         * a RW session on a read only token */
 1450|      0|        if (crv == CKR_TOKEN_WRITE_PROTECTED) {
  ------------------
  |  | 1481|      0|#define CKR_TOKEN_WRITE_PROTECTED 0x000000E2UL
  ------------------
  |  Branch (1450:13): [True: 0, False: 0]
  ------------------
 1451|      0|            slot->readOnly = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1452|      0|        } else if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1452:20): [True: 0, False: 0]
  ------------------
 1453|      0|            CK_SESSION_INFO sessionInfo;
 1454|       |
 1455|       |            /* Because of a second bug in softoken, which silently returns
 1456|       |             * a RO session, we need to check what type of session we got. */
 1457|      0|            crv = PK11_GETTAB(slot)->C_GetSessionInfo(session, &sessionInfo);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1458|      0|            if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1458:17): [True: 0, False: 0]
  ------------------
 1459|      0|                if ((sessionInfo.flags & CKF_RW_SESSION) == 0) {
  ------------------
  |  |  302|      0|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (1459:21): [True: 0, False: 0]
  ------------------
 1460|       |                    /* session was readonly, so this softoken slot must be readonly */
 1461|      0|                    slot->readOnly = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1462|      0|                }
 1463|      0|            }
 1464|      0|            PK11_GETTAB(slot)
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1465|      0|                ->C_CloseSession(session);
 1466|      0|        }
 1467|      0|    }
 1468|       |
 1469|      2|    return SECSuccess;
 1470|      2|}
PK11_InitSlot:
 1542|      2|{
 1543|      2|    SECStatus rv;
 1544|      2|    CK_SLOT_INFO slotInfo;
 1545|       |
 1546|      2|    slot->functionList = mod->functionList;
 1547|      2|    slot->isInternal = mod->internal;
 1548|      2|    slot->slotID = slotID;
 1549|      2|    slot->isThreadSafe = mod->isThreadSafe;
 1550|      2|    slot->hasRSAInfo = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1551|      2|    slot->module = mod; /* NOTE: we don't make a reference here because
 1552|       |                         * modules have references to their slots. This
 1553|       |                         * works because modules keep implicit references
 1554|       |                         * from their slots, and won't unload and disappear
 1555|       |                         * until all their slots have been freed */
 1556|       |
 1557|      2|    if (PK11_GetSlotInfo(slot, &slotInfo) != SECSuccess) {
  ------------------
  |  Branch (1557:9): [True: 0, False: 2]
  ------------------
 1558|      0|        slot->disabled = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1559|      0|        slot->reason = PK11_DIS_COULD_NOT_INIT_TOKEN;
 1560|      0|        return;
 1561|      0|    }
 1562|       |
 1563|       |    /* test to make sure claimed mechanism work */
 1564|      2|    slot->needTest = mod->internal ? PR_FALSE : PR_TRUE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
                  slot->needTest = mod->internal ? PR_FALSE : PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  |  Branch (1564:22): [True: 2, False: 0]
  ------------------
 1565|      2|    (void)PK11_MakeString(NULL, slot->slot_name,
 1566|      2|                          (char *)slotInfo.slotDescription, sizeof(slotInfo.slotDescription));
 1567|      2|    slot->isHW = (PRBool)((slotInfo.flags & CKF_HW_SLOT) == CKF_HW_SLOT);
  ------------------
  |  |  133|      2|#define CKF_HW_SLOT 0x00000004UL          /* hardware slot */
  ------------------
                  slot->isHW = (PRBool)((slotInfo.flags & CKF_HW_SLOT) == CKF_HW_SLOT);
  ------------------
  |  |  133|      2|#define CKF_HW_SLOT 0x00000004UL          /* hardware slot */
  ------------------
 1568|      2|#define ACTIVE_CARD "ActivCard SA"
 1569|      2|    slot->isActiveCard = (PRBool)(PORT_Strncmp((char *)slotInfo.manufacturerID,
  ------------------
  |  |  193|      2|#define PORT_Strncmp strncmp
  ------------------
 1570|      2|                                               ACTIVE_CARD, sizeof(ACTIVE_CARD) - 1) == 0);
  ------------------
  |  | 1568|      2|#define ACTIVE_CARD "ActivCard SA"
  ------------------
                                                             ACTIVE_CARD, sizeof(ACTIVE_CARD) - 1) == 0);
  ------------------
  |  | 1568|      2|#define ACTIVE_CARD "ActivCard SA"
  ------------------
 1571|      2|    if ((slotInfo.flags & CKF_REMOVABLE_DEVICE) == 0) {
  ------------------
  |  |  132|      2|#define CKF_REMOVABLE_DEVICE 0x00000002UL /* removable devices*/
  ------------------
  |  Branch (1571:9): [True: 2, False: 0]
  ------------------
 1572|      2|        slot->isPerm = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1573|       |        /* permanment slots must have the token present always */
 1574|      2|        if ((slotInfo.flags & CKF_TOKEN_PRESENT) == 0) {
  ------------------
  |  |  131|      2|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  |  Branch (1574:13): [True: 0, False: 2]
  ------------------
 1575|      0|            slot->disabled = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1576|      0|            slot->reason = PK11_DIS_TOKEN_NOT_PRESENT;
 1577|      0|            return; /* nothing else to do */
 1578|      0|        }
 1579|      2|    }
 1580|       |    /* if the token is present, initialize it */
 1581|      2|    if ((slotInfo.flags & CKF_TOKEN_PRESENT) != 0) {
  ------------------
  |  |  131|      2|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  |  Branch (1581:9): [True: 2, False: 0]
  ------------------
 1582|      2|        rv = PK11_InitToken(slot, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1583|       |        /* the only hard failures are on permanent devices, or function
 1584|       |         * verify failures... function verify failures are already handled
 1585|       |         * by tokenInit */
 1586|      2|        if ((rv != SECSuccess) && (slot->isPerm) && (!slot->disabled)) {
  ------------------
  |  Branch (1586:13): [True: 0, False: 2]
  |  Branch (1586:35): [True: 0, False: 0]
  |  Branch (1586:53): [True: 0, False: 0]
  ------------------
 1587|      0|            slot->disabled = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1588|      0|            slot->reason = PK11_DIS_COULD_NOT_INIT_TOKEN;
 1589|      0|        }
 1590|      2|        if (rv == SECSuccess && pk11_isRootSlot(slot)) {
  ------------------
  |  Branch (1590:13): [True: 2, False: 0]
  |  Branch (1590:33): [True: 0, False: 2]
  ------------------
 1591|      0|            if (!slot->hasRootCerts) {
  ------------------
  |  Branch (1591:17): [True: 0, False: 0]
  ------------------
 1592|      0|                slot->module->trustOrder = 100;
 1593|      0|            }
 1594|      0|            slot->hasRootCerts = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1595|      0|        }
 1596|      2|    }
 1597|      2|    if ((slotInfo.flags & CKF_USER_PIN_INITIALIZED) != 0) {
  ------------------
  |  |  178|      2|#define CKF_USER_PIN_INITIALIZED 0x00000008UL /* normal user's \
  ------------------
  |  Branch (1597:9): [True: 2, False: 0]
  ------------------
 1598|      2|        slot->flags |= CKF_USER_PIN_INITIALIZED;
  ------------------
  |  |  178|      2|#define CKF_USER_PIN_INITIALIZED 0x00000008UL /* normal user's \
  ------------------
 1599|      2|    }
 1600|      2|}
PK11_IsPresent:
 1690|   417k|{
 1691|   417k|    return pk11_IsPresentCertLoad(slot, PR_TRUE);
  ------------------
  |  |  437|   417k|#define PR_TRUE 1
  ------------------
 1692|   417k|}
PK11_IsDisabled:
 1697|  46.8k|{
 1698|  46.8k|    return slot->disabled;
 1699|  46.8k|}
PK11_IsInternal:
 1780|      3|{
 1781|      3|    return slot->isInternal;
 1782|      3|}
PK11_IsFriendly:
 1808|      2|{
 1809|       |    /* internal slot always has public readable certs */
 1810|      2|    return (PRBool)(slot->isInternal ||
  ------------------
  |  Branch (1810:21): [True: 2, False: 0]
  ------------------
 1811|      2|                    pk11_HasProfile(slot, CKP_PUBLIC_CERTIFICATES_TOKEN) ||
  ------------------
  |  |  349|      0|#define CKP_PUBLIC_CERTIFICATES_TOKEN 0x00000004UL
  ------------------
  |  Branch (1811:21): [True: 0, False: 0]
  ------------------
 1812|      2|                    ((slot->defaultFlags & SECMOD_FRIENDLY_FLAG) ==
  ------------------
  |  |   33|      0|#define SECMOD_FRIENDLY_FLAG 0x10000000L
  ------------------
  |  Branch (1812:21): [True: 0, False: 0]
  ------------------
 1813|      0|                     SECMOD_FRIENDLY_FLAG));
  ------------------
  |  |   33|      0|#define SECMOD_FRIENDLY_FLAG 0x10000000L
  ------------------
 1814|      2|}
PK11_GetSlotInfo:
 1929|      2|{
 1930|      2|    CK_RV crv;
 1931|       |
 1932|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1932:9): [True: 0, False: 2]
  ------------------
 1933|      0|        PK11_EnterSlotMonitor(slot);
 1934|       |    /*
 1935|       |     * some buggy drivers do not fill the buffer completely,
 1936|       |     * erase the buffer first
 1937|       |     */
 1938|      2|    PORT_Memset(info->slotDescription, ' ', sizeof(info->slotDescription));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 1939|      2|    PORT_Memset(info->manufacturerID, ' ', sizeof(info->manufacturerID));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 1940|      2|    crv = PK11_GETTAB(slot)->C_GetSlotInfo(slot->slotID, info);
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1941|      2|    pk11_zeroTerminatedToBlankPadded(info->slotDescription,
 1942|      2|                                     sizeof(info->slotDescription));
 1943|      2|    pk11_zeroTerminatedToBlankPadded(info->manufacturerID,
 1944|      2|                                     sizeof(info->manufacturerID));
 1945|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (1945:9): [True: 0, False: 2]
  ------------------
 1946|      0|        PK11_ExitSlotMonitor(slot);
 1947|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1947:9): [True: 0, False: 2]
  ------------------
 1948|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1949|      0|        return SECFailure;
 1950|      0|    }
 1951|      2|    return SECSuccess;
 1952|      2|}
pk11_SetInternalKeySlot:
 2053|      1|{
 2054|      1|    if (pk11InternalKeySlot) {
  ------------------
  |  Branch (2054:9): [True: 1, False: 0]
  ------------------
 2055|      1|        PK11_FreeSlot(pk11InternalKeySlot);
 2056|      1|    }
 2057|      1|    pk11InternalKeySlot = slot ? PK11_ReferenceSlot(slot) : NULL;
  ------------------
  |  Branch (2057:27): [True: 0, False: 1]
  ------------------
 2058|      1|}
pk11_SetInternalKeySlotIfFirst:
 2067|      1|{
 2068|      1|    if (pk11InternalKeySlot) {
  ------------------
  |  Branch (2068:9): [True: 0, False: 1]
  ------------------
 2069|      0|        return;
 2070|      0|    }
 2071|      1|    pk11InternalKeySlot = slot ? PK11_ReferenceSlot(slot) : NULL;
  ------------------
  |  Branch (2071:27): [True: 1, False: 0]
  ------------------
 2072|      1|}
PK11_GetInternalSlot:
 2109|  12.2M|{
 2110|  12.2M|    SECMODModule *mod = SECMOD_GetInternalModule();
 2111|  12.2M|    PORT_Assert(mod != NULL);
  ------------------
  |  |  120|  12.2M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  12.2M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 12.2M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2112|  12.2M|    if (!mod) {
  ------------------
  |  Branch (2112:9): [True: 0, False: 12.2M]
  ------------------
 2113|      0|        PORT_SetError(SEC_ERROR_NO_MODULE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2114|      0|        return NULL;
 2115|      0|    }
 2116|  12.2M|    if (mod->isFIPS) {
  ------------------
  |  Branch (2116:9): [True: 0, False: 12.2M]
  ------------------
 2117|      0|        return PK11_GetInternalKeySlot();
 2118|      0|    }
 2119|  12.2M|    return PK11_ReferenceSlot(mod->slots[0]);
 2120|  12.2M|}
PK11_DoesMechanism:
 2127|  14.2M|{
 2128|  14.2M|    int i;
 2129|       |
 2130|       |    /* CKM_FAKE_RANDOM is not a real PKCS mechanism. It's a marker to
 2131|       |     * tell us we're looking form someone that has implemented get
 2132|       |     * random bits */
 2133|  14.2M|    if (type == CKM_FAKE_RANDOM) {
  ------------------
  |  |  154|  14.2M|#define CKM_FAKE_RANDOM 0x80000efeUL
  ------------------
  |  Branch (2133:9): [True: 120k, False: 14.1M]
  ------------------
 2134|   120k|        return slot->hasRandom;
 2135|   120k|    }
 2136|       |
 2137|       |    /* for most mechanism, bypass the linear lookup */
 2138|  14.1M|    if (type < 0x7ff) {
  ------------------
  |  Branch (2138:9): [True: 7.83M, False: 6.32M]
  ------------------
 2139|  7.83M|        return (slot->mechanismBits[type & 0xff] & (1 << (type >> 8))) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|  7.83M|#define PR_TRUE 1
  ------------------
                      return (slot->mechanismBits[type & 0xff] & (1 << (type >> 8))) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (2139:16): [True: 7.83M, False: 0]
  ------------------
 2140|  7.83M|    }
 2141|       |
 2142|   403M|    for (i = 0; i < (int)slot->mechanismCount; i++) {
  ------------------
  |  Branch (2142:17): [True: 403M, False: 0]
  ------------------
 2143|   403M|        if (slot->mechanismList[i] == type)
  ------------------
  |  Branch (2143:13): [True: 6.32M, False: 397M]
  ------------------
 2144|  6.32M|            return PR_TRUE;
  ------------------
  |  |  437|  6.32M|#define PR_TRUE 1
  ------------------
 2145|   403M|    }
 2146|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2147|  6.32M|}
PK11_DoesMechanismFlag:
 2158|   331k|{
 2159|   331k|    return !pk11_filterSlot(slot, type, flags, 0);
 2160|   331k|}
PK11_TokenExists:
 2169|  12.1M|{
 2170|  12.1M|    SECMODModuleList *mlp;
 2171|  12.1M|    SECMODModuleList *modules;
 2172|  12.1M|    SECMODListLock *moduleLock = SECMOD_GetDefaultModuleListLock();
 2173|  12.1M|    PK11SlotInfo *slot;
 2174|  12.1M|    PRBool found = PR_FALSE;
  ------------------
  |  |  438|  12.1M|#define PR_FALSE 0
  ------------------
 2175|  12.1M|    int i;
 2176|       |
 2177|  12.1M|    if (!moduleLock) {
  ------------------
  |  Branch (2177:9): [True: 0, False: 12.1M]
  ------------------
 2178|      0|        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2179|      0|        return found;
 2180|      0|    }
 2181|       |    /* we only need to know if there is a token that does this mechanism.
 2182|       |     * check the internal module first because it's fast, and supports
 2183|       |     * almost everything. */
 2184|  12.1M|    slot = PK11_GetInternalSlot();
 2185|  12.1M|    if (slot) {
  ------------------
  |  Branch (2185:9): [True: 12.1M, False: 0]
  ------------------
 2186|  12.1M|        found = PK11_DoesMechanism(slot, type);
 2187|  12.1M|        PK11_FreeSlot(slot);
 2188|  12.1M|    }
 2189|  12.1M|    if (found)
  ------------------
  |  Branch (2189:9): [True: 12.1M, False: 0]
  ------------------
 2190|  12.1M|        return PR_TRUE; /* bypass getting module locks */
  ------------------
  |  |  437|  12.1M|#define PR_TRUE 1
  ------------------
 2191|       |
 2192|      0|    SECMOD_GetReadLock(moduleLock);
 2193|      0|    modules = SECMOD_GetDefaultModuleList();
 2194|      0|    for (mlp = modules; mlp != NULL && (!found); mlp = mlp->next) {
  ------------------
  |  Branch (2194:25): [True: 0, False: 0]
  |  Branch (2194:40): [True: 0, False: 0]
  ------------------
 2195|      0|        for (i = 0; i < mlp->module->slotCount; i++) {
  ------------------
  |  Branch (2195:21): [True: 0, False: 0]
  ------------------
 2196|      0|            slot = mlp->module->slots[i];
 2197|      0|            if (PK11_IsPresent(slot)) {
  ------------------
  |  Branch (2197:17): [True: 0, False: 0]
  ------------------
 2198|      0|                if (PK11_DoesMechanism(slot, type)) {
  ------------------
  |  Branch (2198:21): [True: 0, False: 0]
  ------------------
 2199|      0|                    found = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2200|      0|                    break;
 2201|      0|                }
 2202|      0|            }
 2203|      0|        }
 2204|      0|    }
 2205|      0|    SECMOD_ReleaseReadLock(moduleLock);
 2206|      0|    return found;
 2207|  12.1M|}
PK11_GetAllTokens:
 2218|  4.22k|{
 2219|  4.22k|    PK11SlotList *list;
 2220|  4.22k|    PK11SlotList *loginList;
 2221|  4.22k|    PK11SlotList *friendlyList;
 2222|  4.22k|    SECMODModuleList *mlp;
 2223|  4.22k|    SECMODModuleList *modules;
 2224|  4.22k|    SECMODListLock *moduleLock;
 2225|  4.22k|    int i;
 2226|       |
 2227|  4.22k|    moduleLock = SECMOD_GetDefaultModuleListLock();
 2228|  4.22k|    if (!moduleLock) {
  ------------------
  |  Branch (2228:9): [True: 0, False: 4.22k]
  ------------------
 2229|      0|        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2230|      0|        return NULL;
 2231|      0|    }
 2232|       |
 2233|  4.22k|    list = PK11_NewSlotList();
 2234|  4.22k|    loginList = PK11_NewSlotList();
 2235|  4.22k|    friendlyList = PK11_NewSlotList();
 2236|  4.22k|    if ((list == NULL) || (loginList == NULL) || (friendlyList == NULL)) {
  ------------------
  |  Branch (2236:9): [True: 0, False: 4.22k]
  |  Branch (2236:27): [True: 0, False: 4.22k]
  |  Branch (2236:50): [True: 0, False: 4.22k]
  ------------------
 2237|      0|        if (list)
  ------------------
  |  Branch (2237:13): [True: 0, False: 0]
  ------------------
 2238|      0|            PK11_FreeSlotList(list);
 2239|      0|        if (loginList)
  ------------------
  |  Branch (2239:13): [True: 0, False: 0]
  ------------------
 2240|      0|            PK11_FreeSlotList(loginList);
 2241|      0|        if (friendlyList)
  ------------------
  |  Branch (2241:13): [True: 0, False: 0]
  ------------------
 2242|      0|            PK11_FreeSlotList(friendlyList);
 2243|      0|        return NULL;
 2244|      0|    }
 2245|       |
 2246|  4.22k|    SECMOD_GetReadLock(moduleLock);
 2247|       |
 2248|  4.22k|    modules = SECMOD_GetDefaultModuleList();
 2249|  8.44k|    for (mlp = modules; mlp != NULL; mlp = mlp->next) {
  ------------------
  |  Branch (2249:25): [True: 4.22k, False: 4.22k]
  ------------------
 2250|  12.6k|        for (i = 0; i < mlp->module->slotCount; i++) {
  ------------------
  |  Branch (2250:21): [True: 8.44k, False: 4.22k]
  ------------------
 2251|  8.44k|            PK11SlotInfo *slot = mlp->module->slots[i];
 2252|       |
 2253|  8.44k|            if (pk11_IsPresentCertLoad(slot, loadCerts)) {
  ------------------
  |  Branch (2253:17): [True: 8.44k, False: 0]
  ------------------
 2254|  8.44k|                if (needRW && slot->readOnly)
  ------------------
  |  Branch (2254:21): [True: 0, False: 8.44k]
  |  Branch (2254:31): [True: 0, False: 0]
  ------------------
 2255|      0|                    continue;
 2256|  8.44k|                if ((type == CKM_INVALID_MECHANISM) || PK11_DoesMechanism(slot, type)) {
  ------------------
  |  |  155|  8.44k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  |  Branch (2256:21): [True: 2, False: 8.43k]
  |  Branch (2256:56): [True: 8.43k, False: 0]
  ------------------
 2257|  8.44k|                    if (pk11_LoginStillRequired(slot, wincx)) {
  ------------------
  |  Branch (2257:25): [True: 0, False: 8.44k]
  ------------------
 2258|      0|                        if (PK11_IsFriendly(slot)) {
  ------------------
  |  Branch (2258:29): [True: 0, False: 0]
  ------------------
 2259|      0|                            PK11_AddSlotToList(friendlyList, slot, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2260|      0|                        } else {
 2261|      0|                            PK11_AddSlotToList(loginList, slot, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2262|      0|                        }
 2263|  8.44k|                    } else {
 2264|  8.44k|                        PK11_AddSlotToList(list, slot, PR_TRUE);
  ------------------
  |  |  437|  8.44k|#define PR_TRUE 1
  ------------------
 2265|  8.44k|                    }
 2266|  8.44k|                }
 2267|  8.44k|            }
 2268|  8.44k|        }
 2269|  4.22k|    }
 2270|  4.22k|    SECMOD_ReleaseReadLock(moduleLock);
 2271|       |
 2272|  4.22k|    pk11_MoveListToList(list, friendlyList);
 2273|  4.22k|    PK11_FreeSlotList(friendlyList);
 2274|  4.22k|    pk11_MoveListToList(list, loginList);
 2275|  4.22k|    PK11_FreeSlotList(loginList);
 2276|       |
 2277|  4.22k|    return list;
 2278|  4.22k|}
pk11_filterSlot:
 2312|   334k|{
 2313|   334k|    CK_MECHANISM_INFO mechanism_info;
 2314|   334k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   334k|#define CKR_OK 0x00000000UL
  ------------------
 2315|       |
 2316|       |    /* handle the only case where we don't actually fetch the mechanisms
 2317|       |     * on the fly */
 2318|   334k|    if ((keySize == 0) && (mechanism == CKM_RSA_PKCS) && (slot->hasRSAInfo)) {
  ------------------
  |  |  720|   334k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (2318:9): [True: 334k, False: 0]
  |  Branch (2318:27): [True: 22, False: 334k]
  |  Branch (2318:58): [True: 22, False: 0]
  ------------------
 2319|     22|        mechanism_info.flags = slot->RSAInfoFlags;
 2320|   334k|    } else {
 2321|   334k|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (2321:13): [True: 0, False: 334k]
  ------------------
 2322|      0|            PK11_EnterSlotMonitor(slot);
 2323|   334k|        crv = PK11_GETTAB(slot)->C_GetMechanismInfo(slot->slotID, mechanism,
  ------------------
  |  |  102|   334k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2324|   334k|                                                    &mechanism_info);
 2325|   334k|        if (!slot->isThreadSafe)
  ------------------
  |  Branch (2325:13): [True: 0, False: 334k]
  ------------------
 2326|      0|            PK11_ExitSlotMonitor(slot);
 2327|       |        /* if we were getting the RSA flags, save them */
 2328|   334k|        if ((crv == CKR_OK) && (mechanism == CKM_RSA_PKCS) && (!slot->hasRSAInfo)) {
  ------------------
  |  | 1388|   334k|#define CKR_OK 0x00000000UL
  ------------------
                      if ((crv == CKR_OK) && (mechanism == CKM_RSA_PKCS) && (!slot->hasRSAInfo)) {
  ------------------
  |  |  720|   334k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (2328:13): [True: 334k, False: 0]
  |  Branch (2328:32): [True: 0, False: 334k]
  |  Branch (2328:63): [True: 0, False: 0]
  ------------------
 2329|      0|            slot->RSAInfoFlags = mechanism_info.flags;
 2330|      0|            slot->hasRSAInfo = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2331|      0|        }
 2332|   334k|    }
 2333|       |    /* couldn't get the mechanism info */
 2334|   334k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   334k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2334:9): [True: 0, False: 334k]
  ------------------
 2335|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2336|      0|    }
 2337|   334k|    if (keySize && ((mechanism_info.ulMinKeySize > keySize) || (mechanism_info.ulMaxKeySize < keySize))) {
  ------------------
  |  Branch (2337:9): [True: 0, False: 334k]
  |  Branch (2337:21): [True: 0, False: 0]
  |  Branch (2337:64): [True: 0, False: 0]
  ------------------
 2338|       |        /* Token can do mechanism, but not at the key size we
 2339|       |         * want */
 2340|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2341|      0|    }
 2342|   334k|    if (mechanismInfoFlags && ((mechanism_info.flags & mechanismInfoFlags) !=
  ------------------
  |  Branch (2342:9): [True: 334k, False: 0]
  |  Branch (2342:31): [True: 0, False: 334k]
  ------------------
 2343|   334k|                               mechanismInfoFlags)) {
 2344|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2345|      0|    }
 2346|   334k|    return PR_FALSE;
  ------------------
  |  |  438|   334k|#define PR_FALSE 0
  ------------------
 2347|   334k|}
PK11_GetBestSlotMultipleWithAttributes:
 2362|   383k|{
 2363|   383k|    PK11SlotList *list = NULL;
 2364|   383k|    PK11SlotListElement *le;
 2365|   383k|    PK11SlotInfo *slot = NULL;
 2366|   383k|    PRBool freeit = PR_FALSE;
  ------------------
  |  |  438|   383k|#define PR_FALSE 0
  ------------------
 2367|   383k|    PRBool listNeedLogin = PR_FALSE;
  ------------------
  |  |  438|   383k|#define PR_FALSE 0
  ------------------
 2368|   383k|    unsigned int i;
 2369|   383k|    SECStatus rv;
 2370|       |
 2371|   383k|    list = PK11_GetSlotList(type[0]);
 2372|       |
 2373|   383k|    if ((list == NULL) || (list->head == NULL)) {
  ------------------
  |  Branch (2373:9): [True: 4.21k, False: 378k]
  |  Branch (2373:27): [True: 0, False: 378k]
  ------------------
 2374|       |        /* We need to look up all the tokens for the mechanism */
 2375|  4.21k|        list = PK11_GetAllTokens(type[0], PR_FALSE, PR_TRUE, wincx);
  ------------------
  |  |  438|  4.21k|#define PR_FALSE 0
  ------------------
                      list = PK11_GetAllTokens(type[0], PR_FALSE, PR_TRUE, wincx);
  ------------------
  |  |  437|  4.21k|#define PR_TRUE 1
  ------------------
 2376|  4.21k|        freeit = PR_TRUE;
  ------------------
  |  |  437|  4.21k|#define PR_TRUE 1
  ------------------
 2377|  4.21k|    }
 2378|       |
 2379|       |    /* no one can do it! */
 2380|   383k|    if (list == NULL) {
  ------------------
  |  Branch (2380:9): [True: 0, False: 383k]
  ------------------
 2381|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2382|      0|        return NULL;
 2383|      0|    }
 2384|       |
 2385|   383k|    PORT_SetError(0);
  ------------------
  |  |   65|   383k|#define PORT_SetError PORT_SetError_Util
  ------------------
 2386|       |
 2387|   383k|    listNeedLogin = PR_FALSE;
  ------------------
  |  |  438|   383k|#define PR_FALSE 0
  ------------------
 2388|   725k|    for (i = 0; i < mech_count; i++) {
  ------------------
  |  Branch (2388:17): [True: 383k, False: 342k]
  ------------------
 2389|   383k|        if ((type[i] != CKM_FAKE_RANDOM) &&
  ------------------
  |  |  154|   383k|#define CKM_FAKE_RANDOM 0x80000efeUL
  ------------------
  |  Branch (2389:13): [True: 262k, False: 120k]
  ------------------
 2390|   383k|            (type[i] != CKM_SHA_1) &&
  ------------------
  |  |  859|   262k|#define CKM_SHA_1 0x00000220UL
  ------------------
  |  Branch (2390:13): [True: 163k, False: 98.7k]
  ------------------
 2391|   383k|            (type[i] != CKM_SHA224) &&
  ------------------
  |  |  887|   163k|#define CKM_SHA224 0x00000255UL
  ------------------
  |  Branch (2391:13): [True: 163k, False: 0]
  ------------------
 2392|   383k|            (type[i] != CKM_SHA256) &&
  ------------------
  |  |  876|   163k|#define CKM_SHA256 0x00000250UL
  ------------------
  |  Branch (2392:13): [True: 103k, False: 60.3k]
  ------------------
 2393|   383k|            (type[i] != CKM_SHA384) &&
  ------------------
  |  |  879|   103k|#define CKM_SHA384 0x00000260UL
  ------------------
  |  Branch (2393:13): [True: 57.0k, False: 46.0k]
  ------------------
 2394|   383k|            (type[i] != CKM_SHA512) &&
  ------------------
  |  |  882|  57.0k|#define CKM_SHA512 0x00000270UL
  ------------------
  |  Branch (2394:13): [True: 51.2k, False: 5.85k]
  ------------------
 2395|   383k|            (type[i] != CKM_MD5) &&
  ------------------
  |  |  853|  51.2k|#define CKM_MD5 0x00000210UL
  ------------------
  |  Branch (2395:13): [True: 40.4k, False: 10.7k]
  ------------------
 2396|   383k|            (type[i] != CKM_MD2)) {
  ------------------
  |  |  847|  40.4k|#define CKM_MD2 0x00000200UL
  ------------------
  |  Branch (2396:13): [True: 40.4k, False: 0]
  ------------------
 2397|  40.4k|            listNeedLogin = PR_TRUE;
  ------------------
  |  |  437|  40.4k|#define PR_TRUE 1
  ------------------
 2398|  40.4k|            break;
 2399|  40.4k|        }
 2400|   383k|    }
 2401|       |
 2402|   383k|    for (le = PK11_GetFirstSafe(list); le;
  ------------------
  |  Branch (2402:40): [True: 383k, False: 0]
  ------------------
 2403|   383k|         le = PK11_GetNextSafe(list, le, PR_TRUE)) {
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2404|   383k|        if (PK11_IsPresent(le->slot)) {
  ------------------
  |  Branch (2404:13): [True: 383k, False: 0]
  ------------------
 2405|   383k|            PRBool doExit = PR_FALSE;
  ------------------
  |  |  438|   383k|#define PR_FALSE 0
  ------------------
 2406|   766k|            for (i = 0; i < mech_count; i++) {
  ------------------
  |  Branch (2406:25): [True: 383k, False: 383k]
  ------------------
 2407|   383k|                if (!PK11_DoesMechanism(le->slot, type[i])) {
  ------------------
  |  Branch (2407:21): [True: 0, False: 383k]
  ------------------
 2408|      0|                    doExit = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2409|      0|                    break;
 2410|      0|                }
 2411|   383k|                if ((mechanismInfoFlags && mechanismInfoFlags[i]) ||
  ------------------
  |  Branch (2411:22): [True: 3.01k, False: 380k]
  |  Branch (2411:44): [True: 3.01k, False: 0]
  ------------------
 2412|   383k|                    (keySize && keySize[i])) {
  ------------------
  |  Branch (2412:22): [True: 0, False: 380k]
  |  Branch (2412:33): [True: 0, False: 0]
  ------------------
 2413|  3.01k|                    if (pk11_filterSlot(le->slot, type[i],
  ------------------
  |  Branch (2413:25): [True: 0, False: 3.01k]
  ------------------
 2414|  3.01k|                                        mechanismInfoFlags ? mechanismInfoFlags[i] : 0,
  ------------------
  |  Branch (2414:41): [True: 3.01k, False: 0]
  ------------------
 2415|  3.01k|                                        keySize ? keySize[i] : 0)) {
  ------------------
  |  Branch (2415:41): [True: 3.01k, False: 0]
  ------------------
 2416|      0|                        doExit = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2417|      0|                        break;
 2418|      0|                    }
 2419|  3.01k|                }
 2420|   383k|            }
 2421|       |
 2422|   383k|            if (doExit)
  ------------------
  |  Branch (2422:17): [True: 0, False: 383k]
  ------------------
 2423|      0|                continue;
 2424|       |
 2425|   383k|            if (listNeedLogin && le->slot->needLogin) {
  ------------------
  |  Branch (2425:17): [True: 40.4k, False: 342k]
  |  Branch (2425:34): [True: 0, False: 40.4k]
  ------------------
 2426|      0|                rv = PK11_Authenticate(le->slot, PR_TRUE, wincx);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2427|      0|                if (rv != SECSuccess)
  ------------------
  |  Branch (2427:21): [True: 0, False: 0]
  ------------------
 2428|      0|                    continue;
 2429|      0|            }
 2430|   383k|            slot = le->slot;
 2431|   383k|            PK11_ReferenceSlot(slot);
 2432|   383k|            PK11_FreeSlotListElement(list, le);
 2433|   383k|            if (freeit) {
  ------------------
  |  Branch (2433:17): [True: 4.21k, False: 378k]
  ------------------
 2434|  4.21k|                PK11_FreeSlotList(list);
 2435|  4.21k|            }
 2436|   383k|            return slot;
 2437|   383k|        }
 2438|   383k|    }
 2439|      0|    if (freeit) {
  ------------------
  |  Branch (2439:9): [True: 0, False: 0]
  ------------------
 2440|      0|        PK11_FreeSlotList(list);
 2441|      0|    }
 2442|      0|    if (PORT_GetError() == 0) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (2442:9): [True: 0, False: 0]
  ------------------
 2443|      0|        PORT_SetError(SEC_ERROR_NO_TOKEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2444|      0|    }
 2445|      0|    return NULL;
 2446|   383k|}
PK11_GetBestSlotMultiple:
 2451|      1|{
 2452|      1|    return PK11_GetBestSlotMultipleWithAttributes(type, NULL, NULL,
 2453|      1|                                                  mech_count, wincx);
 2454|      1|}
PK11_GetBestSlot:
 2459|   380k|{
 2460|   380k|    return PK11_GetBestSlotMultipleWithAttributes(&type, NULL, NULL, 1, wincx);
 2461|   380k|}
PK11_GetBestSlotWithAttributes:
 2466|  3.01k|{
 2467|  3.01k|    return PK11_GetBestSlotMultipleWithAttributes(&type, &mechanismFlags,
 2468|  3.01k|                                                  &keySize, 1, wincx);
 2469|  3.01k|}
PK11_GetBestKeyLength:
 2473|      2|{
 2474|      2|    CK_MECHANISM_INFO mechanism_info;
 2475|      2|    CK_RV crv;
 2476|       |
 2477|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (2477:9): [True: 0, False: 2]
  ------------------
 2478|      0|        PK11_EnterSlotMonitor(slot);
 2479|      2|    crv = PK11_GETTAB(slot)->C_GetMechanismInfo(slot->slotID,
  ------------------
  |  |  102|      2|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2480|      2|                                                mechanism, &mechanism_info);
 2481|      2|    if (!slot->isThreadSafe)
  ------------------
  |  Branch (2481:9): [True: 0, False: 2]
  ------------------
 2482|      0|        PK11_ExitSlotMonitor(slot);
 2483|      2|    if (crv != CKR_OK)
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2483:9): [True: 0, False: 2]
  ------------------
 2484|      0|        return 0;
 2485|       |
 2486|      2|    if (mechanism_info.ulMinKeySize == mechanism_info.ulMaxKeySize)
  ------------------
  |  Branch (2486:9): [True: 2, False: 0]
  ------------------
 2487|      2|        return 0;
 2488|      0|    return mechanism_info.ulMaxKeySize;
 2489|      2|}
PK11_GenerateRandomOnSlot:
 2574|   120k|{
 2575|   120k|    CK_RV crv;
 2576|       |
 2577|   120k|    if (!slot->isInternal)
  ------------------
  |  Branch (2577:9): [True: 0, False: 120k]
  ------------------
 2578|      0|        PK11_EnterSlotMonitor(slot);
 2579|   120k|    crv = PK11_GETTAB(slot)->C_GenerateRandom(slot->session, data,
  ------------------
  |  |  102|   120k|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 2580|   120k|                                              (CK_ULONG)len);
 2581|   120k|    if (!slot->isInternal)
  ------------------
  |  Branch (2581:9): [True: 0, False: 120k]
  ------------------
 2582|      0|        PK11_ExitSlotMonitor(slot);
 2583|   120k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   120k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2583:9): [True: 0, False: 120k]
  ------------------
 2584|      0|        PORT_SetError(PK11_MapError(crv));
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2585|      0|        return SECFailure;
 2586|      0|    }
 2587|   120k|    return SECSuccess;
 2588|   120k|}
PK11_GenerateRandom:
 2628|   120k|{
 2629|   120k|    PK11SlotInfo *slot;
 2630|   120k|    SECStatus rv;
 2631|       |
 2632|   120k|    slot = PK11_GetBestSlot(CKM_FAKE_RANDOM, NULL);
  ------------------
  |  |  154|   120k|#define CKM_FAKE_RANDOM 0x80000efeUL
  ------------------
 2633|   120k|    if (slot == NULL)
  ------------------
  |  Branch (2633:9): [True: 0, False: 120k]
  ------------------
 2634|      0|        return SECFailure;
 2635|       |
 2636|   120k|    rv = PK11_GenerateRandomOnSlot(slot, data, len);
 2637|   120k|    PK11_FreeSlot(slot);
 2638|   120k|    return rv;
 2639|   120k|}
PK11Slot_SetNSSToken:
 2693|      4|{
 2694|      4|    NSSToken *old;
 2695|      4|    if (nsst) {
  ------------------
  |  Branch (2695:9): [True: 2, False: 2]
  ------------------
 2696|      2|        nsst = nssToken_AddRef(nsst);
 2697|      2|    }
 2698|       |
 2699|      4|    PZ_Lock(sl->nssTokenLock);
  ------------------
  |  |  245|      4|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 2700|      4|    old = sl->nssToken;
 2701|      4|    sl->nssToken = nsst;
 2702|      4|    PZ_Unlock(sl->nssTokenLock);
  ------------------
  |  |  246|      4|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 2703|       |
 2704|      4|    if (old) {
  ------------------
  |  Branch (2704:9): [True: 2, False: 2]
  ------------------
 2705|      2|        (void)nssToken_Destroy(old);
 2706|      2|    }
 2707|      4|}
PK11Slot_GetNSSToken:
 2711|  23.4k|{
 2712|  23.4k|    NSSToken *rv = NULL;
 2713|       |
 2714|  23.4k|    PZ_Lock(sl->nssTokenLock);
  ------------------
  |  |  245|  23.4k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 2715|  23.4k|    if (sl->nssToken) {
  ------------------
  |  Branch (2715:9): [True: 23.4k, False: 4]
  ------------------
 2716|  23.4k|        rv = nssToken_AddRef(sl->nssToken);
 2717|  23.4k|    }
 2718|  23.4k|    PZ_Unlock(sl->nssTokenLock);
  ------------------
  |  |  246|  23.4k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 2719|       |
 2720|  23.4k|    return rv;
 2721|  23.4k|}
pk11slot.c:pk11_FreeSlotListStatic:
  152|  12.6k|{
  153|  12.6k|    PK11SlotListElement *le, *next;
  154|  12.6k|    if (list == NULL)
  ------------------
  |  Branch (154:9): [True: 0, False: 12.6k]
  ------------------
  155|      0|        return;
  156|       |
  157|  21.1k|    for (le = list->head; le; le = next) {
  ------------------
  |  Branch (157:27): [True: 8.44k, False: 12.6k]
  ------------------
  158|  8.44k|        next = le->next;
  159|  8.44k|        PK11_FreeSlotListElement(list, le);
  160|  8.44k|    }
  161|  12.6k|    if (list->lock) {
  ------------------
  |  Branch (161:9): [True: 12.6k, False: 0]
  ------------------
  162|  12.6k|        PZ_DestroyLock(list->lock);
  ------------------
  |  |  244|  12.6k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  163|  12.6k|    }
  164|  12.6k|    list->lock = NULL;
  165|  12.6k|    list->head = NULL;
  166|  12.6k|}
pk11slot.c:pk11_InitSlotListStatic:
  823|     20|{
  824|     20|    list->lock = PZ_NewLock(nssILockList);
  ------------------
  |  |  243|     20|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  825|     20|    list->head = NULL;
  826|     20|}
pk11slot.c:pk11_ReadProfileList:
 1205|      2|{
 1206|      2|    CK_ATTRIBUTE findTemp[2];
 1207|      2|    CK_ATTRIBUTE *attrs;
 1208|      2|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|      2|#define CK_TRUE 1
  ------------------
 1209|      2|    CK_OBJECT_CLASS oclass = CKO_PROFILE;
  ------------------
  |  |  334|      2|#define CKO_PROFILE 0x00000009UL
  ------------------
 1210|      2|    size_t tsize;
 1211|      2|    int objCount;
 1212|      2|    CK_OBJECT_HANDLE *handles = NULL;
 1213|      2|    int i;
 1214|       |
 1215|      2|    attrs = findTemp;
 1216|      2|    PK11_SETATTRS(attrs, CKA_TOKEN, &cktrue, sizeof(cktrue));
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
 1217|      2|    attrs++;
 1218|      2|    PK11_SETATTRS(attrs, CKA_CLASS, &oclass, sizeof(oclass));
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
 1219|      2|    attrs++;
 1220|      2|    tsize = attrs - findTemp;
 1221|      2|    PORT_Assert(tsize <= sizeof(findTemp) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1222|       |
 1223|      2|    if (slot->profileList) {
  ------------------
  |  Branch (1223:9): [True: 0, False: 2]
  ------------------
 1224|      0|        PORT_Free(slot->profileList);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1225|      0|        slot->profileList = NULL;
 1226|      0|    }
 1227|      2|    slot->profileCount = 0;
 1228|       |
 1229|      2|    objCount = 0;
 1230|      2|    handles = pk11_FindObjectsByTemplate(slot, findTemp, tsize, &objCount);
 1231|      2|    if (handles == NULL) {
  ------------------
  |  Branch (1231:9): [True: 2, False: 0]
  ------------------
 1232|      2|        if (objCount < 0) {
  ------------------
  |  Branch (1232:13): [True: 0, False: 2]
  ------------------
 1233|      0|            return SECFailure; /* error code is set */
 1234|      0|        }
 1235|      2|        PORT_Assert(objCount == 0);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1236|      2|        return SECSuccess;
 1237|      2|    }
 1238|       |
 1239|      0|    slot->profileList = (CK_PROFILE_ID *)
 1240|      0|        PORT_Alloc(objCount * sizeof(CK_PROFILE_ID));
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1241|      0|    if (slot->profileList == NULL) {
  ------------------
  |  Branch (1241:9): [True: 0, False: 0]
  ------------------
 1242|      0|        PORT_Free(handles);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1243|      0|        return SECFailure; /* error code is set */
 1244|      0|    }
 1245|       |
 1246|      0|    for (i = 0; i < objCount; i++) {
  ------------------
  |  Branch (1246:17): [True: 0, False: 0]
  ------------------
 1247|      0|        CK_ULONG value;
 1248|       |
 1249|      0|        value = PK11_ReadULongAttribute(slot, handles[i], CKA_PROFILE_ID);
  ------------------
  |  |  663|      0|#define CKA_PROFILE_ID 0x00000601UL
  ------------------
 1250|      0|        if (value == CK_UNAVAILABLE_INFORMATION) {
  ------------------
  |  |   64|      0|#define CK_UNAVAILABLE_INFORMATION (~0UL)
  ------------------
  |  Branch (1250:13): [True: 0, False: 0]
  ------------------
 1251|      0|            continue;
 1252|      0|        }
 1253|      0|        slot->profileList[slot->profileCount++] = value;
 1254|      0|    }
 1255|       |
 1256|      0|    PORT_Free(handles);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1257|      0|    return SECSuccess;
 1258|      0|}
pk11slot.c:pk11_isRootSlot:
 1512|      2|{
 1513|      2|    CK_ATTRIBUTE findTemp[1];
 1514|      2|    CK_ATTRIBUTE *attrs;
 1515|      2|    CK_OBJECT_CLASS oclass = CKO_NSS_BUILTIN_ROOT_LIST;
  ------------------
  |  |   38|      2|#define CKO_NSS_BUILTIN_ROOT_LIST (CKO_NSS + 4)
  |  |  ------------------
  |  |  |  |   33|      2|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|      2|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      2|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1516|      2|    size_t tsize;
 1517|      2|    CK_OBJECT_HANDLE handle;
 1518|       |
 1519|      2|    attrs = findTemp;
 1520|      2|    PK11_SETATTRS(attrs, CKA_CLASS, &oclass, sizeof(oclass));
  ------------------
  |  |  104|      2|    (x)->type = (id);              \
  |  |  105|      2|    (x)->pValue = (v);             \
  |  |  106|      2|    (x)->ulValueLen = (l);
  ------------------
 1521|      2|    attrs++;
 1522|      2|    tsize = attrs - findTemp;
 1523|      2|    PORT_Assert(tsize <= sizeof(findTemp) / sizeof(CK_ATTRIBUTE));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1524|       |
 1525|      2|    handle = pk11_FindObjectByTemplate(slot, findTemp, tsize);
 1526|      2|    if (handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      2|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1526:9): [True: 2, False: 0]
  ------------------
 1527|      2|        return PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1528|      2|    }
 1529|      0|    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1530|      2|}
pk11slot.c:pk11_IsPresentCertLoad:
 1613|   425k|{
 1614|   425k|    CK_SLOT_INFO slotInfo;
 1615|   425k|    CK_SESSION_INFO sessionInfo;
 1616|   425k|    CK_RV crv;
 1617|       |
 1618|       |    /* disabled slots are never present */
 1619|   425k|    if (slot->disabled) {
  ------------------
  |  Branch (1619:9): [True: 0, False: 425k]
  ------------------
 1620|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1621|      0|    }
 1622|       |
 1623|       |    /* permanent slots are always present */
 1624|   425k|    if (slot->isPerm && (slot->session != CK_INVALID_HANDLE)) {
  ------------------
  |  |   78|   425k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1624:9): [True: 425k, False: 0]
  |  Branch (1624:25): [True: 425k, False: 0]
  ------------------
 1625|   425k|        return PR_TRUE;
  ------------------
  |  |  437|   425k|#define PR_TRUE 1
  ------------------
 1626|   425k|    }
 1627|       |
 1628|      0|    NSSToken *nssToken = PK11Slot_GetNSSToken(slot);
 1629|      0|    if (nssToken) {
  ------------------
  |  Branch (1629:9): [True: 0, False: 0]
  ------------------
 1630|      0|        PRBool present = nssToken_IsPresent(nssToken);
 1631|      0|        (void)nssToken_Destroy(nssToken);
 1632|      0|        return present;
 1633|      0|    }
 1634|       |
 1635|       |    /* removable slots have a flag that says they are present */
 1636|      0|    if (PK11_GetSlotInfo(slot, &slotInfo) != SECSuccess) {
  ------------------
  |  Branch (1636:9): [True: 0, False: 0]
  ------------------
 1637|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1638|      0|    }
 1639|       |
 1640|      0|    if ((slotInfo.flags & CKF_TOKEN_PRESENT) == 0) {
  ------------------
  |  |  131|      0|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  |  Branch (1640:9): [True: 0, False: 0]
  ------------------
 1641|       |        /* if the slot is no longer present, close the session */
 1642|      0|        if (slot->session != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1642:13): [True: 0, False: 0]
  ------------------
 1643|      0|            if (!slot->isThreadSafe) {
  ------------------
  |  Branch (1643:17): [True: 0, False: 0]
  ------------------
 1644|      0|                PK11_EnterSlotMonitor(slot);
 1645|      0|            }
 1646|      0|            PK11_GETTAB(slot)
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1647|      0|                ->C_CloseSession(slot->session);
 1648|      0|            slot->session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 1649|      0|            if (!slot->isThreadSafe) {
  ------------------
  |  Branch (1649:17): [True: 0, False: 0]
  ------------------
 1650|      0|                PK11_ExitSlotMonitor(slot);
 1651|      0|            }
 1652|      0|        }
 1653|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1654|      0|    }
 1655|       |
 1656|       |    /* use the session Info to determine if the card has been removed and then
 1657|       |     * re-inserted */
 1658|      0|    if (slot->session != CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1658:9): [True: 0, False: 0]
  ------------------
 1659|      0|        if (slot->isThreadSafe) {
  ------------------
  |  Branch (1659:13): [True: 0, False: 0]
  ------------------
 1660|      0|            PK11_EnterSlotMonitor(slot);
 1661|      0|        }
 1662|      0|        crv = PK11_GETTAB(slot)->C_GetSessionInfo(slot->session, &sessionInfo);
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1663|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1663:13): [True: 0, False: 0]
  ------------------
 1664|      0|            PK11_GETTAB(slot)
  ------------------
  |  |  102|      0|#define PK11_GETTAB(x) ((CK_FUNCTION_LIST_3_0_PTR)((x)->functionList))
  ------------------
 1665|      0|                ->C_CloseSession(slot->session);
 1666|      0|            slot->session = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 1667|      0|        }
 1668|      0|        if (slot->isThreadSafe) {
  ------------------
  |  Branch (1668:13): [True: 0, False: 0]
  ------------------
 1669|      0|            PK11_ExitSlotMonitor(slot);
 1670|      0|        }
 1671|      0|    }
 1672|       |
 1673|       |    /* card has not been removed, current token info is correct */
 1674|      0|    if (slot->session != CK_INVALID_HANDLE)
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (1674:9): [True: 0, False: 0]
  ------------------
 1675|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1676|       |
 1677|       |    /* initialize the token info state */
 1678|      0|    if (PK11_InitToken(slot, loadCerts) != SECSuccess) {
  ------------------
  |  Branch (1678:9): [True: 0, False: 0]
  ------------------
 1679|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1680|      0|    }
 1681|       |
 1682|      0|    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1683|      0|}
pk11slot.c:pk11_zeroTerminatedToBlankPadded:
 1911|      4|{
 1912|      4|    CK_CHAR *walk = buffer;
 1913|      4|    CK_CHAR *end = buffer + buffer_size;
 1914|       |
 1915|       |    /* find the NULL */
 1916|    196|    while (walk < end && *walk != '\0') {
  ------------------
  |  Branch (1916:12): [True: 192, False: 4]
  |  Branch (1916:26): [True: 192, False: 0]
  ------------------
 1917|    192|        walk++;
 1918|    192|    }
 1919|       |
 1920|       |    /* clear out the buffer */
 1921|      4|    while (walk < end) {
  ------------------
  |  Branch (1921:12): [True: 0, False: 4]
  ------------------
 1922|      0|        *walk++ = ' ';
 1923|      0|    }
 1924|      4|}

SECMOD_Init:
   37|      2|{
   38|       |    /* don't initialize twice */
   39|      2|    if (moduleLock)
  ------------------
  |  Branch (39:9): [True: 1, False: 1]
  ------------------
   40|      1|        return;
   41|       |
   42|      1|    moduleLock = SECMOD_NewListLock();
   43|      1|    PK11_InitSlotLists();
   44|      1|}
SECMOD_Shutdown:
   48|      1|{
   49|       |    /* destroy the lock */
   50|      1|    if (moduleLock) {
  ------------------
  |  Branch (50:9): [True: 1, False: 0]
  ------------------
   51|      1|        SECMOD_DestroyListLock(moduleLock);
   52|      1|        moduleLock = NULL;
   53|      1|    }
   54|       |    /* free the internal module */
   55|      1|    if (internalModule) {
  ------------------
  |  Branch (55:9): [True: 1, False: 0]
  ------------------
   56|      1|        SECMOD_DestroyModule(internalModule);
   57|      1|        internalModule = NULL;
   58|      1|    }
   59|       |
   60|       |    /* free the default database module */
   61|      1|    if (defaultDBModule) {
  ------------------
  |  Branch (61:9): [True: 1, False: 0]
  ------------------
   62|      1|        SECMOD_DestroyModule(defaultDBModule);
   63|      1|        defaultDBModule = NULL;
   64|      1|    }
   65|       |
   66|       |    /* destroy the list */
   67|      1|    if (modules) {
  ------------------
  |  Branch (67:9): [True: 1, False: 0]
  ------------------
   68|      1|        SECMOD_DestroyModuleList(modules);
   69|      1|        modules = NULL;
   70|      1|    }
   71|       |
   72|      1|    if (modulesDB) {
  ------------------
  |  Branch (72:9): [True: 1, False: 0]
  ------------------
   73|      1|        SECMOD_DestroyModuleList(modulesDB);
   74|      1|        modulesDB = NULL;
   75|      1|    }
   76|       |
   77|      1|    if (modulesUnload) {
  ------------------
  |  Branch (77:9): [True: 0, False: 1]
  ------------------
   78|      0|        SECMOD_DestroyModuleList(modulesUnload);
   79|      0|        modulesUnload = NULL;
   80|      0|    }
   81|       |
   82|       |    /* make all the slots and the lists go away */
   83|      1|    PK11_DestroySlotLists();
   84|       |
   85|      1|    nss_DumpModuleLog();
   86|       |
   87|      1|#ifdef DEBUG
   88|      1|    if (PR_GetEnvSecure("NSS_STRICT_SHUTDOWN")) {
  ------------------
  |  Branch (88:9): [True: 0, False: 1]
  ------------------
   89|      0|        PORT_Assert(secmod_PrivateModuleCount == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   90|      0|    }
   91|      1|#endif
   92|      1|    if (secmod_PrivateModuleCount) {
  ------------------
  |  Branch (92:9): [True: 0, False: 1]
  ------------------
   93|      0|        PORT_SetError(SEC_ERROR_BUSY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   94|      0|        return SECFailure;
   95|      0|    }
   96|      1|    return SECSuccess;
   97|      1|}
SECMOD_GetSystemFIPSEnabled:
  101|      2|{
  102|      2|    return NSS_GetSystemFIPSEnabled();
  103|      2|}
SECMOD_GetInternalModule:
  110|  12.2M|{
  111|  12.2M|    return internalModule;
  112|  12.2M|}
secmod_AddModuleToList:
  116|      2|{
  117|      2|    SECMODModuleList *mlp, *newListElement, *last = NULL;
  118|       |
  119|      2|    newListElement = SECMOD_NewModuleListElement();
  120|      2|    if (newListElement == NULL) {
  ------------------
  |  Branch (120:9): [True: 0, False: 2]
  ------------------
  121|      0|        return SECFailure;
  122|      0|    }
  123|       |
  124|      2|    newListElement->module = SECMOD_ReferenceModule(newModule);
  125|       |
  126|      2|    SECMOD_GetWriteLock(moduleLock);
  127|       |    /* Added it to the end (This is very inefficient, but Adding a module
  128|       |     * on the fly should happen maybe 2-3 times through the life this program
  129|       |     * on a given computer, and this list should be *SHORT*. */
  130|      2|    for (mlp = *moduleList; mlp != NULL; mlp = mlp->next) {
  ------------------
  |  Branch (130:29): [True: 0, False: 2]
  ------------------
  131|      0|        last = mlp;
  132|      0|    }
  133|       |
  134|      2|    if (last == NULL) {
  ------------------
  |  Branch (134:9): [True: 2, False: 0]
  ------------------
  135|      2|        *moduleList = newListElement;
  136|      2|    } else {
  137|      0|        SECMOD_AddList(last, newListElement, NULL);
  138|      0|    }
  139|      2|    SECMOD_ReleaseWriteLock(moduleLock);
  140|      2|    return SECSuccess;
  141|      2|}
SECMOD_AddModuleToList:
  145|      1|{
  146|      1|    if (newModule->internal && !internalModule) {
  ------------------
  |  Branch (146:9): [True: 1, False: 0]
  |  Branch (146:32): [True: 1, False: 0]
  ------------------
  147|      1|        internalModule = SECMOD_ReferenceModule(newModule);
  148|      1|    }
  149|      1|    return secmod_AddModuleToList(&modules, newModule);
  150|      1|}
SECMOD_AddModuleToDBOnlyList:
  154|      1|{
  155|      1|    if (defaultDBModule && SECMOD_GetDefaultModDBFlag(newModule)) {
  ------------------
  |  Branch (155:9): [True: 0, False: 1]
  |  Branch (155:28): [True: 0, False: 0]
  ------------------
  156|      0|        SECMOD_DestroyModule(defaultDBModule);
  157|      0|        defaultDBModule = SECMOD_ReferenceModule(newModule);
  158|      1|    } else if (defaultDBModule == NULL) {
  ------------------
  |  Branch (158:16): [True: 1, False: 0]
  ------------------
  159|      1|        defaultDBModule = SECMOD_ReferenceModule(newModule);
  160|      1|    }
  161|      1|    return secmod_AddModuleToList(&modulesDB, newModule);
  162|      1|}
SECMOD_GetDefaultModuleList:
  175|  4.22k|{
  176|  4.22k|    return modules;
  177|  4.22k|}
SECMOD_GetDefaultModuleListLock:
  202|  12.2M|{
  203|  12.2M|    return moduleLock;
  204|  12.2M|}
PK11_IsFIPS:
  666|  18.2k|{
  667|  18.2k|    SECMODModule *mod = SECMOD_GetInternalModule();
  668|       |
  669|  18.2k|    if (mod && mod->internal) {
  ------------------
  |  Branch (669:9): [True: 18.2k, False: 0]
  |  Branch (669:16): [True: 18.2k, False: 0]
  ------------------
  670|  18.2k|        return mod->isFIPS;
  671|  18.2k|    }
  672|       |
  673|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  674|  18.2k|}
SECMOD_NewModuleListElement:
  839|      2|{
  840|      2|    SECMODModuleList *newModList;
  841|       |
  842|      2|    newModList = (SECMODModuleList *)PORT_Alloc(sizeof(SECMODModuleList));
  ------------------
  |  |   52|      2|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  843|      2|    if (newModList) {
  ------------------
  |  Branch (843:9): [True: 2, False: 0]
  ------------------
  844|      2|        newModList->next = NULL;
  845|      2|        newModList->module = NULL;
  846|      2|    }
  847|      2|    return newModList;
  848|      2|}
SECMOD_ReferenceModule:
  855|      5|{
  856|      5|    PZ_Lock(module->refLock);
  ------------------
  |  |  245|      5|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  857|      5|    PORT_Assert(module->refCount > 0);
  ------------------
  |  |  120|      5|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  858|       |
  859|      5|    module->refCount++;
  860|      5|    PZ_Unlock(module->refLock);
  ------------------
  |  |  246|      5|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  861|      5|    return module;
  862|      5|}
SECMOD_DestroyModule:
  867|      7|{
  868|      7|    PRBool willfree = PR_FALSE;
  ------------------
  |  |  438|      7|#define PR_FALSE 0
  ------------------
  869|      7|    int slotCount;
  870|      7|    int i;
  871|       |
  872|      7|    PZ_Lock(module->refLock);
  ------------------
  |  |  245|      7|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  873|      7|    if (module->refCount-- == 1) {
  ------------------
  |  Branch (873:9): [True: 2, False: 5]
  ------------------
  874|      2|        willfree = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  875|      2|    }
  876|      7|    PORT_Assert(willfree || (module->refCount > 0));
  ------------------
  |  |  120|      7|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     12|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2, False: 5]
  |  |  |  |  |  Branch (208:7): [True: 5, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  877|      7|    PZ_Unlock(module->refLock);
  ------------------
  |  |  246|      7|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  878|       |
  879|      7|    if (!willfree) {
  ------------------
  |  Branch (879:9): [True: 5, False: 2]
  ------------------
  880|      5|        return;
  881|      5|    }
  882|       |
  883|      2|    if (module->parent != NULL) {
  ------------------
  |  Branch (883:9): [True: 1, False: 1]
  ------------------
  884|      1|        SECMODModule *parent = module->parent;
  885|       |        /* paranoia, don't loop forever if the modules are looped */
  886|      1|        module->parent = NULL;
  887|      1|        SECMOD_DestroyModule(parent);
  888|      1|    }
  889|       |
  890|       |    /* slots can't really disappear until our module starts freeing them,
  891|       |     * so this check is safe */
  892|      2|    slotCount = module->slotCount;
  893|      2|    if (slotCount == 0) {
  ------------------
  |  Branch (893:9): [True: 1, False: 1]
  ------------------
  894|      1|        SECMOD_SlotDestroyModule(module, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  895|      1|        return;
  896|      1|    }
  897|       |
  898|       |    /* now free all out slots, when they are done, they will cause the
  899|       |     * module to disappear altogether */
  900|      3|    for (i = 0; i < slotCount; i++) {
  ------------------
  |  Branch (900:17): [True: 2, False: 1]
  ------------------
  901|      2|        if (!module->slots[i]->disabled) {
  ------------------
  |  Branch (901:13): [True: 2, False: 0]
  ------------------
  902|      2|            PK11_ClearSlotList(module->slots[i]);
  903|      2|        }
  904|      2|        PK11_FreeSlot(module->slots[i]);
  905|      2|    }
  906|       |    /* WARNING: once the last slot has been freed is it possible (even likely)
  907|       |     * that module is no more... touching it now is a good way to go south */
  908|      1|}
SECMOD_SlotDestroyModule:
  914|      3|{
  915|      3|    PRBool willfree = PR_FALSE;
  ------------------
  |  |  438|      3|#define PR_FALSE 0
  ------------------
  916|      3|    if (fromSlot) {
  ------------------
  |  Branch (916:9): [True: 2, False: 1]
  ------------------
  917|      2|        PORT_Assert(module->refCount == 0);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  918|      2|        PZ_Lock(module->refLock);
  ------------------
  |  |  245|      2|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  919|      2|        if (module->slotCount-- == 1) {
  ------------------
  |  Branch (919:13): [True: 1, False: 1]
  ------------------
  920|      1|            willfree = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  921|      1|        }
  922|      2|        PORT_Assert(willfree || (module->slotCount > 0));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 1]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  923|      2|        PZ_Unlock(module->refLock);
  ------------------
  |  |  246|      2|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  924|      2|        if (!willfree)
  ------------------
  |  Branch (924:13): [True: 1, False: 1]
  ------------------
  925|      1|            return;
  926|      2|    }
  927|       |
  928|      2|    if (module == pendingModule) {
  ------------------
  |  Branch (928:9): [True: 0, False: 2]
  ------------------
  929|      0|        pendingModule = NULL;
  930|      0|    }
  931|       |
  932|      2|    if (module->loaded) {
  ------------------
  |  Branch (932:9): [True: 2, False: 0]
  ------------------
  933|      2|        SECMOD_UnloadModule(module);
  934|      2|    }
  935|      2|    PZ_DestroyLock(module->refLock);
  ------------------
  |  |  244|      2|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  936|      2|    PORT_FreeArena(module->arena, PR_FALSE);
  ------------------
  |  |   61|      2|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(module->arena, PR_FALSE);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  937|      2|    secmod_PrivateModuleCount--;
  938|      2|}
SECMOD_DestroyModuleListElement:
  946|      2|{
  947|      2|    SECMODModuleList *next = element->next;
  948|       |
  949|      2|    if (element->module) {
  ------------------
  |  Branch (949:9): [True: 2, False: 0]
  ------------------
  950|      2|        SECMOD_DestroyModule(element->module);
  951|      2|        element->module = NULL;
  952|      2|    }
  953|      2|    PORT_Free(element);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
  954|      2|    return next;
  955|      2|}
SECMOD_DestroyModuleList:
  962|      2|{
  963|      2|    SECMODModuleList *lp;
  964|       |
  965|      4|    for (lp = list; lp != NULL; lp = SECMOD_DestroyModuleListElement(lp))
  ------------------
  |  Branch (965:21): [True: 2, False: 2]
  ------------------
  966|      2|        ;
  967|      2|}

nssDecodedCert_Destroy:
   46|  3.89k|{
   47|  3.89k|    if (!dc) {
  ------------------
  |  Branch (47:9): [True: 0, False: 3.89k]
  ------------------
   48|      0|        return PR_FAILURE;
   49|      0|    }
   50|  3.89k|    switch (dc->type) {
   51|  3.89k|        case NSSCertificateType_PKIX:
  ------------------
  |  Branch (51:9): [True: 3.89k, False: 0]
  ------------------
   52|  3.89k|            return nssDecodedPKIXCertificate_Destroy(dc);
   53|      0|        default:
  ------------------
  |  Branch (53:9): [True: 0, False: 3.89k]
  ------------------
   54|       |#if 0
   55|       |    nss_SetError(NSS_ERROR_INVALID_ARGUMENT);
   56|       |#endif
   57|      0|            break;
   58|  3.89k|    }
   59|      0|    return PR_FAILURE;
   60|  3.89k|}

nssCertificate_AddRef:
   79|   117k|{
   80|   117k|    if (c) {
  ------------------
  |  Branch (80:9): [True: 117k, False: 0]
  ------------------
   81|   117k|        nssPKIObject_AddRef(&c->object);
   82|   117k|    }
   83|   117k|    return c;
   84|   117k|}
nssCertificate_Destroy:
   89|   120k|{
   90|   120k|    nssCertificateStoreTrace lockTrace = { NULL, NULL, PR_FALSE, PR_FALSE };
  ------------------
  |  |  438|   120k|#define PR_FALSE 0
  ------------------
                  nssCertificateStoreTrace lockTrace = { NULL, NULL, PR_FALSE, PR_FALSE };
  ------------------
  |  |  438|   120k|#define PR_FALSE 0
  ------------------
   91|   120k|    nssCertificateStoreTrace unlockTrace = { NULL, NULL, PR_FALSE, PR_FALSE };
  ------------------
  |  |  438|   120k|#define PR_FALSE 0
  ------------------
                  nssCertificateStoreTrace unlockTrace = { NULL, NULL, PR_FALSE, PR_FALSE };
  ------------------
  |  |  438|   120k|#define PR_FALSE 0
  ------------------
   92|       |
   93|   120k|    if (c) {
  ------------------
  |  Branch (93:9): [True: 120k, False: 0]
  ------------------
   94|   120k|        PRUint32 i;
   95|   120k|        nssDecodedCert *dc = c->decoding;
   96|   120k|        NSSTrustDomain *td = STAN_GetDefaultTrustDomain();
   97|   120k|        NSSCryptoContext *cc = c->object.cryptoContext;
   98|       |
   99|   120k|        PR_ASSERT(c->object.refCount > 0);
  ------------------
  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  ------------------
  ------------------
  100|       |
  101|       |        /* --- LOCK storage --- */
  102|   120k|        if (cc) {
  ------------------
  |  Branch (102:13): [True: 120k, False: 0]
  ------------------
  103|   120k|            nssCertificateStore_Lock(cc->certStore, &lockTrace);
  104|   120k|        } else {
  105|      0|            nssTrustDomain_LockCertCache(td);
  106|      0|        }
  107|   120k|        if (PR_ATOMIC_DECREMENT(&c->object.refCount) == 0) {
  ------------------
  |  |  123|   120k|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (107:13): [True: 3.89k, False: 117k]
  ------------------
  108|       |            /* --- remove cert and UNLOCK storage --- */
  109|  3.89k|            if (cc) {
  ------------------
  |  Branch (109:17): [True: 3.89k, False: 0]
  ------------------
  110|  3.89k|                nssCertificateStore_RemoveCertLOCKED(cc->certStore, c);
  111|  3.89k|                nssCertificateStore_Unlock(cc->certStore, &lockTrace,
  112|  3.89k|                                           &unlockTrace);
  113|  3.89k|            } else {
  114|      0|                nssTrustDomain_RemoveCertFromCacheLOCKED(td, c);
  115|      0|                nssTrustDomain_UnlockCertCache(td);
  116|      0|            }
  117|       |            /* free cert data */
  118|  3.89k|            for (i = 0; i < c->object.numInstances; i++) {
  ------------------
  |  Branch (118:25): [True: 0, False: 3.89k]
  ------------------
  119|      0|                nssCryptokiObject_Destroy(c->object.instances[i]);
  120|      0|            }
  121|  3.89k|            nssPKIObject_DestroyLock(&c->object);
  122|  3.89k|            nssArena_Destroy(c->object.arena);
  123|  3.89k|            nssDecodedCert_Destroy(dc);
  124|   117k|        } else {
  125|       |            /* --- UNLOCK storage --- */
  126|   117k|            if (cc) {
  ------------------
  |  Branch (126:17): [True: 117k, False: 0]
  ------------------
  127|   117k|                nssCertificateStore_Unlock(cc->certStore,
  128|   117k|                                           &lockTrace,
  129|   117k|                                           &unlockTrace);
  130|   117k|            } else {
  131|      0|                nssTrustDomain_UnlockCertCache(td);
  132|      0|            }
  133|   117k|        }
  134|   120k|    }
  135|   120k|    return PR_SUCCESS;
  136|   120k|}
NSSCertificate_Destroy:
  140|   120k|{
  141|   120k|    return nssCertificate_Destroy(c);
  142|   120k|}
nssCertificate_GetEncoding:
  146|      2|{
  147|      2|    if (c->encoding.size > 0 && c->encoding.data) {
  ------------------
  |  Branch (147:9): [True: 2, False: 0]
  |  Branch (147:33): [True: 2, False: 0]
  ------------------
  148|      2|        return &c->encoding;
  149|      2|    } else {
  150|      0|        return (NSSDER *)NULL;
  151|      0|    }
  152|      2|}
nssCertificate_GetDecoding:
  263|    460|{
  264|    460|    nssDecodedCert *deco = NULL;
  265|    460|    if (c->type == NSSCertificateType_PKIX) {
  ------------------
  |  Branch (265:9): [True: 0, False: 460]
  ------------------
  266|      0|        (void)STAN_GetCERTCertificate(c);
  267|      0|    }
  268|    460|    nssPKIObject_Lock(&c->object);
  269|    460|    if (!c->decoding) {
  ------------------
  |  Branch (269:9): [True: 0, False: 460]
  ------------------
  270|      0|        deco = nssDecodedCert_Create(NULL, &c->encoding, c->type);
  271|      0|        PORT_Assert(!c->decoding);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  272|      0|        c->decoding = deco;
  273|    460|    } else {
  274|    460|        deco = c->decoding;
  275|    460|    }
  276|    460|    nssPKIObject_Unlock(&c->object);
  277|    460|    return deco;
  278|    460|}
nssCertificate_BuildChain:
  428|      2|{
  429|      2|    NSSCertificate **rvChain = NULL;
  430|      2|    NSSUsage issuerUsage = *usage;
  431|      2|    nssPKIObjectCollection *collection = NULL;
  432|      2|    PRUint32 rvCount = 0;
  433|      2|    PRStatus st;
  434|      2|    PRStatus ret = PR_SUCCESS;
  435|       |
  436|      2|    if (!c || !cc ||
  ------------------
  |  Branch (436:9): [True: 0, False: 2]
  |  Branch (436:15): [True: 0, False: 2]
  ------------------
  437|      2|        (!td && (td = NSSCertificate_GetTrustDomain(c)) == NULL)) {
  ------------------
  |  Branch (437:10): [True: 0, False: 2]
  |  Branch (437:17): [True: 0, False: 0]
  ------------------
  438|      0|        goto loser;
  439|      0|    }
  440|       |    /* bump the usage up to CA level */
  441|      2|    issuerUsage.nss3lookingForCA = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  442|      2|    collection = nssCertificateCollection_Create(td, NULL);
  443|      2|    if (!collection)
  ------------------
  |  Branch (443:9): [True: 0, False: 2]
  ------------------
  444|      0|        goto loser;
  445|      2|    st = nssPKIObjectCollection_AddObject(collection, (nssPKIObject *)c);
  446|      2|    if (st != PR_SUCCESS)
  ------------------
  |  Branch (446:9): [True: 0, False: 2]
  ------------------
  447|      0|        goto loser;
  448|      2|    for (rvCount = 1; (!rvLimit || rvCount < rvLimit); ++rvCount) {
  ------------------
  |  Branch (448:24): [True: 0, False: 2]
  |  Branch (448:36): [True: 2, False: 0]
  ------------------
  449|      2|        CERTCertificate *cCert = STAN_GetCERTCertificate(c);
  450|      2|        if (cCert->isRoot) {
  ------------------
  |  Branch (450:13): [True: 2, False: 0]
  ------------------
  451|       |            /* not including the issuer of the self-signed cert, which is,
  452|       |             * of course, itself
  453|       |             */
  454|      2|            break;
  455|      2|        }
  456|      0|        c = find_cert_issuer(c, timeOpt, &issuerUsage, policiesOpt, td, cc);
  457|      0|        if (!c) {
  ------------------
  |  Branch (457:13): [True: 0, False: 0]
  ------------------
  458|      0|            ret = PR_FAILURE;
  459|      0|            break;
  460|      0|        }
  461|      0|        st = nssPKIObjectCollection_AddObject(collection, (nssPKIObject *)c);
  462|      0|        nssCertificate_Destroy(c); /* collection has it */
  463|      0|        if (st != PR_SUCCESS)
  ------------------
  |  Branch (463:13): [True: 0, False: 0]
  ------------------
  464|      0|            goto loser;
  465|      0|    }
  466|      2|    rvChain = nssPKIObjectCollection_GetCertificates(collection,
  467|      2|                                                     rvOpt,
  468|      2|                                                     rvLimit,
  469|      2|                                                     arenaOpt);
  470|      2|    if (rvChain) {
  ------------------
  |  Branch (470:9): [True: 2, False: 0]
  ------------------
  471|      2|        nssPKIObjectCollection_Destroy(collection);
  472|      2|        if (statusOpt)
  ------------------
  |  Branch (472:13): [True: 0, False: 2]
  ------------------
  473|      0|            *statusOpt = ret;
  474|      2|        if (ret != PR_SUCCESS)
  ------------------
  |  Branch (474:13): [True: 0, False: 2]
  ------------------
  475|      0|            nss_SetError(NSS_ERROR_CERTIFICATE_ISSUER_NOT_FOUND);
  476|      2|        return rvChain;
  477|      2|    }
  478|       |
  479|      0|loser:
  480|      0|    if (collection)
  ------------------
  |  Branch (480:9): [True: 0, False: 0]
  ------------------
  481|      0|        nssPKIObjectCollection_Destroy(collection);
  482|      0|    if (statusOpt)
  ------------------
  |  Branch (482:9): [True: 0, False: 0]
  ------------------
  483|      0|        *statusOpt = PR_FAILURE;
  484|      0|    nss_SetError(NSS_ERROR_CERTIFICATE_ISSUER_NOT_FOUND);
  485|      0|    return rvChain;
  486|      2|}
NSSCertificate_BuildChain:
  500|      2|{
  501|      2|    return nssCertificate_BuildChain(c, timeOpt, usage, policiesOpt,
  502|      2|                                     rvOpt, rvLimit, arenaOpt, statusOpt,
  503|      2|                                     td, cc);
  504|      2|}
nssCertificate_SubjectListSort:
  696|    230|{
  697|    230|    NSSCertificate *c1 = (NSSCertificate *)v1;
  698|    230|    NSSCertificate *c2 = (NSSCertificate *)v2;
  699|    230|    nssDecodedCert *dc1 = nssCertificate_GetDecoding(c1);
  700|    230|    nssDecodedCert *dc2 = nssCertificate_GetDecoding(c2);
  701|    230|    if (!dc1) {
  ------------------
  |  Branch (701:9): [True: 0, False: 230]
  ------------------
  702|      0|        return dc2 ? 1 : 0;
  ------------------
  |  Branch (702:16): [True: 0, False: 0]
  ------------------
  703|    230|    } else if (!dc2) {
  ------------------
  |  Branch (703:16): [True: 0, False: 230]
  ------------------
  704|      0|        return -1;
  705|    230|    } else {
  706|    230|        return dc1->isNewerThan(dc1, dc2) ? -1 : 1;
  ------------------
  |  Branch (706:16): [True: 49, False: 181]
  ------------------
  707|    230|    }
  708|    230|}

nssCryptoContext_Create:
   24|      1|{
   25|      1|    NSSArena *arena;
   26|      1|    NSSCryptoContext *rvCC;
   27|      1|    arena = NSSArena_Create();
   28|      1|    if (!arena) {
  ------------------
  |  Branch (28:9): [True: 0, False: 1]
  ------------------
   29|      0|        return NULL;
   30|      0|    }
   31|      1|    rvCC = nss_ZNEW(arena, NSSCryptoContext);
  ------------------
  |  |  348|      1|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   32|      1|    if (!rvCC) {
  ------------------
  |  Branch (32:9): [True: 0, False: 1]
  ------------------
   33|      0|        return NULL;
   34|      0|    }
   35|      1|    rvCC->td = td;
   36|      1|    rvCC->arena = arena;
   37|      1|    rvCC->certStore = nssCertificateStore_Create(rvCC->arena);
   38|      1|    if (!rvCC->certStore) {
  ------------------
  |  Branch (38:9): [True: 0, False: 1]
  ------------------
   39|      0|        nssArena_Destroy(arena);
   40|      0|        return NULL;
   41|      0|    }
   42|       |
   43|      1|    return rvCC;
   44|      1|}
NSSCryptoContext_Destroy:
   48|      1|{
   49|      1|    PRStatus status = PR_SUCCESS;
   50|      1|    PORT_Assert(cc && cc->certStore);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   51|      1|    if (!cc) {
  ------------------
  |  Branch (51:9): [True: 0, False: 1]
  ------------------
   52|      0|        return PR_FAILURE;
   53|      0|    }
   54|      1|    if (cc->certStore) {
  ------------------
  |  Branch (54:9): [True: 1, False: 0]
  ------------------
   55|      1|        status = nssCertificateStore_Destroy(cc->certStore);
   56|      1|        if (status == PR_FAILURE) {
  ------------------
  |  Branch (56:13): [True: 0, False: 1]
  ------------------
   57|      0|            return status;
   58|      0|        }
   59|      1|    } else {
   60|      0|        status = PR_FAILURE;
   61|      0|    }
   62|      1|    nssArena_Destroy(cc->arena);
   63|      1|    return status;
   64|      1|}
NSSCryptoContext_FindOrImportCertificate:
   96|  3.89k|{
   97|  3.89k|    NSSCertificate *rvCert = NULL;
   98|       |
   99|  3.89k|    PORT_Assert(cc && cc->certStore);
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.78k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 3.89k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 3.89k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  100|  3.89k|    if (!cc || !cc->certStore) {
  ------------------
  |  Branch (100:9): [True: 0, False: 3.89k]
  |  Branch (100:16): [True: 0, False: 3.89k]
  ------------------
  101|      0|        nss_SetError(NSS_ERROR_INVALID_ARGUMENT);
  102|      0|        return rvCert;
  103|      0|    }
  104|  3.89k|    rvCert = nssCertificateStore_FindOrAdd(cc->certStore, c);
  105|  3.89k|    if (rvCert == c && c->object.cryptoContext != cc) {
  ------------------
  |  Branch (105:9): [True: 3.89k, False: 0]
  |  Branch (105:24): [True: 0, False: 3.89k]
  ------------------
  106|      0|        PORT_Assert(!c->object.cryptoContext);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  107|      0|        c->object.cryptoContext = cc;
  108|      0|    }
  109|  3.89k|    if (rvCert) {
  ------------------
  |  Branch (109:9): [True: 3.89k, False: 0]
  ------------------
  110|       |        /* an NSSCertificate cannot be part of two crypto contexts
  111|       |        ** simultaneously.  If this assertion fails, then there is
  112|       |        ** a serious Stan design flaw.
  113|       |        */
  114|  3.89k|        PORT_Assert(cc == c->object.cryptoContext);
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.89k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.89k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  115|  3.89k|    }
  116|  3.89k|    return rvCert;
  117|  3.89k|}
NSSCryptoContext_FindCertificateByEncodedCertificate:
  338|  4.07k|{
  339|  4.07k|    PORT_Assert(cc && cc->certStore);
  ------------------
  |  |  120|  4.07k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  8.14k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.07k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 4.07k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  340|  4.07k|    if (!cc || !cc->certStore) {
  ------------------
  |  Branch (340:9): [True: 0, False: 4.07k]
  |  Branch (340:16): [True: 0, False: 4.07k]
  ------------------
  341|      0|        return NULL;
  342|      0|    }
  343|  4.07k|    return nssCertificateStore_FindCertificateByEncodedCertificate(
  344|  4.07k|        cc->certStore,
  345|  4.07k|        encodedCertificate);
  346|  4.07k|}
nssCryptoContext_FindTrustForCertificate:
  493|  3.89k|{
  494|  3.89k|    PORT_Assert(cc && cc->certStore);
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.78k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 3.89k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 3.89k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  495|  3.89k|    if (!cc || !cc->certStore) {
  ------------------
  |  Branch (495:9): [True: 0, False: 3.89k]
  |  Branch (495:16): [True: 0, False: 3.89k]
  ------------------
  496|      0|        return NULL;
  497|      0|    }
  498|  3.89k|    return nssCertificateStore_FindTrustForCertificate(cc->certStore, cert);
  499|  3.89k|}

STAN_GetDefaultTrustDomain:
   49|   125k|{
   50|   125k|    return g_default_trust_domain;
   51|   125k|}
STAN_GetDefaultCryptoContext:
   55|  4.07k|{
   56|  4.07k|    return g_default_crypto_context;
   57|  4.07k|}
STAN_InitTokenForSlotInfo:
   64|      2|{
   65|      2|    NSSToken *token;
   66|      2|    if (!td) {
  ------------------
  |  Branch (66:9): [True: 0, False: 2]
  ------------------
   67|      0|        td = g_default_trust_domain;
   68|      0|        if (!td) {
  ------------------
  |  Branch (68:13): [True: 0, False: 0]
  ------------------
   69|       |            /* we're called while still initting. slot will get added
   70|       |             * appropriately through normal init processes */
   71|      0|            return PR_SUCCESS;
   72|      0|        }
   73|      0|    }
   74|      2|    token = nssToken_CreateFromPK11SlotInfo(td, slot);
   75|      2|    if (token) {
  ------------------
  |  Branch (75:9): [True: 2, False: 0]
  ------------------
   76|       |        /* PK11Slot_SetNSSToken increments the refcount on |token| to 2 */
   77|      2|        PK11Slot_SetNSSToken(slot, token);
   78|       |
   79|       |        /* we give our reference to |td->tokenList| */
   80|      2|        NSSRWLock_LockWrite(td->tokensLock);
  ------------------
  |  |   48|      2|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  ------------------
   81|      2|        nssList_Add(td->tokenList, token);
   82|      2|        NSSRWLock_UnlockWrite(td->tokensLock);
  ------------------
  |  |   51|      2|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  ------------------
   83|      2|    } else {
   84|      0|        PK11Slot_SetNSSToken(slot, NULL);
   85|      0|    }
   86|      2|    return PR_SUCCESS;
   87|      2|}
STAN_LoadDefaultNSS3TrustDomain:
  110|      1|{
  111|      1|    NSSTrustDomain *td;
  112|      1|    SECMODModuleList *mlp;
  113|      1|    SECMODListLock *moduleLock = SECMOD_GetDefaultModuleListLock();
  114|      1|    int i;
  115|       |
  116|      1|    if (g_default_trust_domain || g_default_crypto_context) {
  ------------------
  |  Branch (116:9): [True: 0, False: 1]
  |  Branch (116:35): [True: 0, False: 1]
  ------------------
  117|       |        /* Stan is already initialized or a previous shutdown failed. */
  118|      0|        nss_SetError(NSS_ERROR_ALREADY_INITIALIZED);
  119|      0|        return PR_FAILURE;
  120|      0|    }
  121|      1|    td = NSSTrustDomain_Create(NULL, NULL, NULL, NULL);
  122|      1|    if (!td) {
  ------------------
  |  Branch (122:9): [True: 0, False: 1]
  ------------------
  123|      0|        return PR_FAILURE;
  124|      0|    }
  125|       |    /*
  126|       |     * Deadlock warning: we should never acquire the moduleLock while
  127|       |     * we hold the tokensLock. We can use the NSSRWLock Rank feature to
  128|       |     * guarrentee this. tokensLock have a higher rank than module lock.
  129|       |     */
  130|      1|    td->tokenList = nssList_Create(td->arena, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  131|      1|    if (!td->tokenList) {
  ------------------
  |  Branch (131:9): [True: 0, False: 1]
  ------------------
  132|      0|        goto loser;
  133|      0|    }
  134|      1|    SECMOD_GetReadLock(moduleLock);
  135|      1|    NSSRWLock_LockWrite(td->tokensLock);
  ------------------
  |  |   48|      1|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  ------------------
  136|      2|    for (mlp = SECMOD_GetDefaultModuleList(); mlp != NULL; mlp = mlp->next) {
  ------------------
  |  Branch (136:47): [True: 1, False: 1]
  ------------------
  137|      3|        for (i = 0; i < mlp->module->slotCount; i++) {
  ------------------
  |  Branch (137:21): [True: 2, False: 1]
  ------------------
  138|      2|            STAN_InitTokenForSlotInfo(td, mlp->module->slots[i]);
  139|      2|        }
  140|      1|    }
  141|      1|    td->tokens = nssList_CreateIterator(td->tokenList);
  142|      1|    NSSRWLock_UnlockWrite(td->tokensLock);
  ------------------
  |  |   51|      1|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  ------------------
  143|      1|    SECMOD_ReleaseReadLock(moduleLock);
  144|      1|    if (!td->tokens) {
  ------------------
  |  Branch (144:9): [True: 0, False: 1]
  ------------------
  145|      0|        goto loser;
  146|      0|    }
  147|      1|    g_default_crypto_context = NSSTrustDomain_CreateCryptoContext(td, NULL);
  148|      1|    if (!g_default_crypto_context) {
  ------------------
  |  Branch (148:9): [True: 0, False: 1]
  ------------------
  149|      0|        goto loser;
  150|      0|    }
  151|      1|    g_default_trust_domain = td;
  152|      1|    return PR_SUCCESS;
  153|       |
  154|      0|loser:
  155|      0|    NSSTrustDomain_Destroy(td);
  156|      0|    return PR_FAILURE;
  157|      1|}
STAN_Shutdown:
  208|      1|{
  209|      1|    PRStatus status = PR_SUCCESS;
  210|      1|    if (g_default_trust_domain) {
  ------------------
  |  Branch (210:9): [True: 1, False: 0]
  ------------------
  211|      1|        if (NSSTrustDomain_Destroy(g_default_trust_domain) == PR_SUCCESS) {
  ------------------
  |  Branch (211:13): [True: 1, False: 0]
  ------------------
  212|      1|            g_default_trust_domain = NULL;
  213|      1|        } else {
  214|      0|            status = PR_FAILURE;
  215|      0|        }
  216|      1|    }
  217|      1|    if (g_default_crypto_context) {
  ------------------
  |  Branch (217:9): [True: 1, False: 0]
  ------------------
  218|      1|        if (NSSCryptoContext_Destroy(g_default_crypto_context) == PR_SUCCESS) {
  ------------------
  |  Branch (218:13): [True: 1, False: 0]
  ------------------
  219|      1|            g_default_crypto_context = NULL;
  220|      1|        } else {
  221|      0|            status = PR_FAILURE;
  222|      0|        }
  223|      1|    }
  224|      1|    return status;
  225|      1|}
nssPKIX509_GetIssuerAndSerialFromDER:
  257|  8.13k|{
  258|  8.13k|    SECItem derCert = { 0 };
  259|  8.13k|    SECItem derIssuer = { 0 };
  260|  8.13k|    SECItem derSerial = { 0 };
  261|  8.13k|    SECStatus secrv;
  262|  8.13k|    derCert.data = (unsigned char *)der->data;
  263|  8.13k|    derCert.len = der->size;
  264|  8.13k|    secrv = CERT_IssuerNameFromDERCert(&derCert, &derIssuer);
  265|  8.13k|    if (secrv != SECSuccess) {
  ------------------
  |  Branch (265:9): [True: 260, False: 7.87k]
  ------------------
  266|    260|        return PR_FAILURE;
  267|    260|    }
  268|  7.87k|    secrv = CERT_SerialNumberFromDERCert(&derCert, &derSerial);
  269|  7.87k|    if (secrv != SECSuccess) {
  ------------------
  |  Branch (269:9): [True: 0, False: 7.87k]
  ------------------
  270|      0|        PORT_Free(derSerial.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  271|      0|        return PR_FAILURE;
  272|      0|    }
  273|  7.87k|    issuer->data = derIssuer.data;
  274|  7.87k|    issuer->size = derIssuer.len;
  275|  7.87k|    serial->data = derSerial.data;
  276|  7.87k|    serial->size = derSerial.len;
  277|  7.87k|    return PR_SUCCESS;
  278|  7.87k|}
nssDecodedPKIXCertificate_Create:
  490|  4.06k|{
  491|  4.06k|    nssDecodedCert *rvDC = NULL;
  492|  4.06k|    CERTCertificate *cert;
  493|  4.06k|    SECItem secDER;
  494|       |
  495|  4.06k|    SECITEM_FROM_NSSITEM(&secDER, encoding);
  ------------------
  |  |   31|  4.06k|    (secit)->data = (unsigned char *)(nssit)->data; \
  |  |   32|  4.06k|    (secit)->len = (unsigned int)(nssit)->size;
  ------------------
  496|  4.06k|    cert = CERT_DecodeDERCertificate(&secDER, PR_TRUE, NULL);
  ------------------
  |  |  437|  4.06k|#define PR_TRUE 1
  ------------------
  497|  4.06k|    if (cert) {
  ------------------
  |  Branch (497:9): [True: 3.89k, False: 174]
  ------------------
  498|  3.89k|        rvDC = nss_ZNEW(arenaOpt, nssDecodedCert);
  ------------------
  |  |  348|  3.89k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  499|  3.89k|        if (rvDC) {
  ------------------
  |  Branch (499:13): [True: 3.89k, False: 0]
  ------------------
  500|  3.89k|            rvDC->type = NSSCertificateType_PKIX;
  501|  3.89k|            rvDC->data = (void *)cert;
  502|  3.89k|            rvDC->getIdentifier = nss3certificate_getIdentifier;
  503|  3.89k|            rvDC->getIssuerIdentifier = nss3certificate_getIssuerIdentifier;
  504|  3.89k|            rvDC->matchIdentifier = nss3certificate_matchIdentifier;
  505|  3.89k|            rvDC->isValidIssuer = nss3certificate_isValidIssuer;
  506|  3.89k|            rvDC->getUsage = nss3certificate_getUsage;
  507|  3.89k|            rvDC->isValidAtTime = nss3certificate_isValidAtTime;
  508|  3.89k|            rvDC->isNewerThan = nss3certificate_isNewerThan;
  509|  3.89k|            rvDC->matchUsage = nss3certificate_matchUsage;
  510|  3.89k|            rvDC->isTrustedForUsage = nss3certificate_isTrustedForUsage;
  511|  3.89k|            rvDC->getEmailAddress = nss3certificate_getEmailAddress;
  512|  3.89k|            rvDC->getDERSerialNumber = nss3certificate_getDERSerialNumber;
  513|  3.89k|        } else {
  514|      0|            CERT_DestroyCertificate(cert);
  515|      0|        }
  516|  3.89k|    }
  517|  4.06k|    return rvDC;
  518|  4.06k|}
nssDecodedPKIXCertificate_Destroy:
  546|  3.89k|{
  547|  3.89k|    CERTCertificate *cert = (CERTCertificate *)dc->data;
  548|       |
  549|       |    /* The decoder may only be half initialized (the case where we find we
  550|       |     * could not decode the certificate). In this case, there is not cert to
  551|       |     * free, just free the dc structure. */
  552|  3.89k|    if (cert) {
  ------------------
  |  Branch (552:9): [True: 3.89k, False: 0]
  ------------------
  553|  3.89k|        PRBool freeSlot = cert->ownSlot;
  554|  3.89k|        PK11SlotInfo *slot = cert->slot;
  555|  3.89k|        PLArenaPool *arena = cert->arena;
  556|       |        /* zero cert before freeing. Any stale references to this cert
  557|       |         * after this point will probably cause an exception.  */
  558|  3.89k|        PORT_Memset(cert, 0, sizeof *cert);
  ------------------
  |  |  182|  3.89k|#define PORT_Memset memset
  ------------------
  559|       |        /* free the arena that contains the cert. */
  560|  3.89k|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|  3.89k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  561|  3.89k|        if (slot && freeSlot) {
  ------------------
  |  Branch (561:13): [True: 0, False: 3.89k]
  |  Branch (561:21): [True: 0, False: 0]
  ------------------
  562|      0|            PK11_FreeSlot(slot);
  563|      0|        }
  564|  3.89k|    }
  565|  3.89k|    nss_ZFreeIf(dc);
  566|  3.89k|    return PR_SUCCESS;
  567|  3.89k|}
STAN_GetCERTCertificate:
  977|  4.07k|{
  978|  4.07k|    return stan_GetCERTCertificate(c, PR_FALSE);
  ------------------
  |  |  438|  4.07k|#define PR_FALSE 0
  ------------------
  979|  4.07k|}
STAN_GetCERTCertificateOrRelease:
  990|  3.89k|{
  991|  3.89k|    CERTCertificate *nss3cert = stan_GetCERTCertificate(c, PR_FALSE);
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  992|  3.89k|    if (!nss3cert) {
  ------------------
  |  Branch (992:9): [True: 0, False: 3.89k]
  ------------------
  993|      0|        nssCertificate_Destroy(c);
  994|      0|    }
  995|  3.89k|    return nss3cert;
  996|  3.89k|}
STAN_GetNSSCertificate:
 1024|   113k|{
 1025|   113k|    NSSCertificate *c;
 1026|   113k|    nssCryptokiInstance *instance;
 1027|   113k|    nssPKIObject *pkiob;
 1028|   113k|    NSSArena *arena;
 1029|   113k|    CERT_LockCertTempPerm(cc);
 1030|   113k|    c = cc->nssCertificate;
 1031|   113k|    CERT_UnlockCertTempPerm(cc);
 1032|   113k|    if (c) {
  ------------------
  |  Branch (1032:9): [True: 113k, False: 0]
  ------------------
 1033|   113k|        return c;
 1034|   113k|    }
 1035|       |    /* i don't think this should happen.  but if it can, need to create
 1036|       |     * NSSCertificate from CERTCertificate values here.  */
 1037|       |    /* Yup, it can happen. */
 1038|      0|    arena = NSSArena_Create();
 1039|      0|    if (!arena) {
  ------------------
  |  Branch (1039:9): [True: 0, False: 0]
  ------------------
 1040|      0|        return NULL;
 1041|      0|    }
 1042|      0|    c = nss_ZNEW(arena, NSSCertificate);
  ------------------
  |  |  348|      0|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
 1043|      0|    if (!c) {
  ------------------
  |  Branch (1043:9): [True: 0, False: 0]
  ------------------
 1044|      0|        nssArena_Destroy(arena);
 1045|      0|        return NULL;
 1046|      0|    }
 1047|      0|    NSSITEM_FROM_SECITEM(&c->encoding, &cc->derCert);
  ------------------
  |  |   27|      0|    (nssit)->data = (void *)(secit)->data; \
  |  |   28|      0|    (nssit)->size = (PRUint32)(secit)->len;
  ------------------
 1048|      0|    c->type = NSSCertificateType_PKIX;
 1049|      0|    pkiob = nssPKIObject_Create(arena, NULL, cc->dbhandle, NULL, nssPKIMonitor);
 1050|      0|    if (!pkiob) {
  ------------------
  |  Branch (1050:9): [True: 0, False: 0]
  ------------------
 1051|      0|        nssArena_Destroy(arena);
 1052|      0|        return NULL;
 1053|      0|    }
 1054|      0|    c->object = *pkiob;
 1055|      0|    nssItem_Create(arena,
 1056|      0|                   &c->issuer, cc->derIssuer.len, cc->derIssuer.data);
 1057|      0|    nssItem_Create(arena,
 1058|      0|                   &c->subject, cc->derSubject.len, cc->derSubject.data);
 1059|       |    /* CERTCertificate stores serial numbers decoded.  I need the DER
 1060|       |     * here.  sigh.
 1061|       |     */
 1062|      0|    SECItem derSerial;
 1063|      0|    SECStatus secrv;
 1064|      0|    secrv = CERT_SerialNumberFromDERCert(&cc->derCert, &derSerial);
 1065|      0|    if (secrv == SECFailure) {
  ------------------
  |  Branch (1065:9): [True: 0, False: 0]
  ------------------
 1066|      0|        nssArena_Destroy(arena);
 1067|      0|        return NULL;
 1068|      0|    }
 1069|      0|    nssItem_Create(arena, &c->serial, derSerial.len, derSerial.data);
 1070|      0|    PORT_Free(derSerial.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1071|       |
 1072|      0|    if (cc->emailAddr && cc->emailAddr[0]) {
  ------------------
  |  Branch (1072:9): [True: 0, False: 0]
  |  Branch (1072:26): [True: 0, False: 0]
  ------------------
 1073|      0|        c->email = nssUTF8_Create(arena,
 1074|      0|                                  nssStringType_PrintableString,
 1075|      0|                                  (NSSUTF8 *)cc->emailAddr,
 1076|      0|                                  PORT_Strlen(cc->emailAddr));
  ------------------
  |  |  190|      0|#define PORT_Strlen(s) strlen(s)
  ------------------
 1077|      0|    }
 1078|      0|    if (cc->slot) {
  ------------------
  |  Branch (1078:9): [True: 0, False: 0]
  ------------------
 1079|      0|        instance = nss_ZNEW(arena, nssCryptokiInstance);
  ------------------
  |  |  348|      0|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
 1080|      0|        if (!instance) {
  ------------------
  |  Branch (1080:13): [True: 0, False: 0]
  ------------------
 1081|      0|            nssArena_Destroy(arena);
 1082|      0|            return NULL;
 1083|      0|        }
 1084|      0|        instance->token = PK11Slot_GetNSSToken(cc->slot);
 1085|      0|        if (!instance->token) {
  ------------------
  |  Branch (1085:13): [True: 0, False: 0]
  ------------------
 1086|      0|            nssArena_Destroy(arena);
 1087|      0|            return NULL;
 1088|      0|        }
 1089|      0|        instance->handle = cc->pkcs11ID;
 1090|      0|        instance->isTokenObject = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1091|      0|        if (cc->nickname) {
  ------------------
  |  Branch (1091:13): [True: 0, False: 0]
  ------------------
 1092|      0|            instance->label = nssUTF8_Create(arena,
 1093|      0|                                             nssStringType_UTF8String,
 1094|      0|                                             (NSSUTF8 *)cc->nickname,
 1095|      0|                                             PORT_Strlen(cc->nickname));
  ------------------
  |  |  190|      0|#define PORT_Strlen(s) strlen(s)
  ------------------
 1096|      0|        }
 1097|      0|        nssPKIObject_AddInstance(&c->object, instance);
 1098|      0|    }
 1099|      0|    c->decoding = create_decoded_pkix_cert_from_nss3cert(NULL, cc);
 1100|      0|    CERT_LockCertTempPerm(cc);
 1101|      0|    cc->nssCertificate = c;
 1102|      0|    CERT_UnlockCertTempPerm(cc);
 1103|      0|    return c;
 1104|      0|}
pki3hack.c:nss3certificate_isNewerThan:
  367|    230|{
  368|       |    /* I know this isn't right, but this is glue code anyway */
  369|    230|    if (cmpdc->type == dc->type) {
  ------------------
  |  Branch (369:9): [True: 230, False: 0]
  ------------------
  370|    230|        CERTCertificate *certa = (CERTCertificate *)dc->data;
  371|    230|        CERTCertificate *certb = (CERTCertificate *)cmpdc->data;
  372|    230|        return CERT_IsNewer(certa, certb);
  373|    230|    }
  374|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  375|    230|}
pki3hack.c:get_cert_instance:
  643|  3.89k|{
  644|  3.89k|    nssCryptokiObject *instance, **ci;
  645|  3.89k|    nssCryptokiObject **instances = nssPKIObject_GetInstances(&c->object);
  646|  3.89k|    if (!instances) {
  ------------------
  |  Branch (646:9): [True: 3.89k, False: 0]
  ------------------
  647|  3.89k|        return NULL;
  648|  3.89k|    }
  649|      0|    instance = NULL;
  650|      0|    for (ci = instances; *ci; ci++) {
  ------------------
  |  Branch (650:26): [True: 0, False: 0]
  ------------------
  651|      0|        if (!instance) {
  ------------------
  |  Branch (651:13): [True: 0, False: 0]
  ------------------
  652|      0|            instance = nssCryptokiObject_Clone(*ci);
  653|      0|        } else {
  654|       |            /* This only really works for two instances...  But 3.4 can't
  655|       |             * handle more anyway.  The logic is, if there are multiple
  656|       |             * instances, prefer the one that is not internal (e.g., on
  657|       |             * a hardware device.
  658|       |             */
  659|      0|            if (PK11_IsInternal(instance->token->pk11slot)) {
  ------------------
  |  Branch (659:17): [True: 0, False: 0]
  ------------------
  660|      0|                nssCryptokiObject_Destroy(instance);
  661|      0|                instance = nssCryptokiObject_Clone(*ci);
  662|      0|            }
  663|      0|        }
  664|      0|    }
  665|      0|    nssCryptokiObjectArray_Destroy(instances);
  666|      0|    return instance;
  667|  3.89k|}
pki3hack.c:stan_GetCERTCertificate:
  889|  7.96k|{
  890|  7.96k|    nssDecodedCert *dc = NULL;
  891|  7.96k|    CERTCertificate *cc = NULL;
  892|  7.96k|    CERTCertTrust certTrust;
  893|       |
  894|       |    /* make sure object does not go away until we finish */
  895|  7.96k|    nssPKIObject_AddRef(&c->object);
  896|  7.96k|    nssPKIObject_Lock(&c->object);
  897|       |
  898|  7.96k|    dc = c->decoding;
  899|  7.96k|    if (!dc) {
  ------------------
  |  Branch (899:9): [True: 4.06k, False: 3.89k]
  ------------------
  900|  4.06k|        dc = nssDecodedPKIXCertificate_Create(NULL, &c->encoding);
  901|  4.06k|        if (!dc) {
  ------------------
  |  Branch (901:13): [True: 174, False: 3.89k]
  ------------------
  902|    174|            goto loser;
  903|    174|        }
  904|  3.89k|        cc = (CERTCertificate *)dc->data;
  905|  3.89k|        PORT_Assert(cc); /* software error */
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.89k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.89k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  906|  3.89k|        if (!cc) {
  ------------------
  |  Branch (906:13): [True: 0, False: 3.89k]
  ------------------
  907|      0|            nssDecodedPKIXCertificate_Destroy(dc);
  908|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR);
  909|      0|            goto loser;
  910|      0|        }
  911|  3.89k|        PORT_Assert(!c->decoding);
  ------------------
  |  |  120|  3.89k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.89k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.89k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  912|  3.89k|        if (!c->decoding) {
  ------------------
  |  Branch (912:13): [True: 3.89k, False: 0]
  ------------------
  913|  3.89k|            c->decoding = dc;
  914|  3.89k|        } else {
  915|       |            /* this should never happen. Fail. */
  916|      0|            nssDecodedPKIXCertificate_Destroy(dc);
  917|      0|            nss_SetError(NSS_ERROR_INTERNAL_ERROR);
  918|      0|            goto loser;
  919|      0|        }
  920|  3.89k|    }
  921|  7.78k|    cc = (CERTCertificate *)dc->data;
  922|  7.78k|    PORT_Assert(cc);
  ------------------
  |  |  120|  7.78k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.78k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.78k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  923|  7.78k|    if (!cc) {
  ------------------
  |  Branch (923:9): [True: 0, False: 7.78k]
  ------------------
  924|      0|        nss_SetError(NSS_ERROR_INTERNAL_ERROR);
  925|      0|        goto loser;
  926|      0|    }
  927|  7.78k|    CERT_LockCertTempPerm(cc);
  928|  7.78k|    NSSCertificate *nssCert = cc->nssCertificate;
  929|  7.78k|    CERT_UnlockCertTempPerm(cc);
  930|  7.78k|    if (!nssCert || forceUpdate) {
  ------------------
  |  Branch (930:9): [True: 3.89k, False: 3.89k]
  |  Branch (930:21): [True: 0, False: 3.89k]
  ------------------
  931|  3.89k|        fill_CERTCertificateFields(c, cc, forceUpdate);
  932|  3.89k|    } else if (CERT_GetCertTrust(cc, &certTrust) != SECSuccess) {
  ------------------
  |  Branch (932:16): [True: 3.89k, False: 0]
  ------------------
  933|  3.89k|        CERTCertTrust *trust;
  934|  3.89k|        if (!c->object.cryptoContext) {
  ------------------
  |  Branch (934:13): [True: 0, False: 3.89k]
  ------------------
  935|       |            /* If it's a perm cert, it might have been stored before the
  936|       |             * trust, so look for the trust again.
  937|       |             */
  938|      0|            trust = nssTrust_GetCERTCertTrustForCert(c, cc);
  939|  3.89k|        } else {
  940|       |            /* If it's a temp cert, it might have been stored before the
  941|       |             * builtin trust module is loaded, so look for the trust
  942|       |             * again, but don't set the empty trust if it is not found.
  943|       |             */
  944|  3.89k|            NSSTrust *t = nssTrustDomain_FindTrustForCertificate(c->object.cryptoContext->td, c);
  945|  3.89k|            if (!t) {
  ------------------
  |  Branch (945:17): [True: 3.89k, False: 0]
  ------------------
  946|  3.89k|                goto loser;
  947|  3.89k|            }
  948|      0|            trust = cert_trust_from_stan_trust(t, cc->arena);
  949|      0|            nssTrust_Destroy(t);
  950|      0|            if (!trust) {
  ------------------
  |  Branch (950:17): [True: 0, False: 0]
  ------------------
  951|      0|                goto loser;
  952|      0|            }
  953|      0|        }
  954|       |
  955|      0|        CERT_LockCertTrust(cc);
  956|      0|        cc->trust = trust;
  957|      0|        CERT_UnlockCertTrust(cc);
  958|      0|    }
  959|       |
  960|  7.96k|loser:
  961|  7.96k|    nssPKIObject_Unlock(&c->object);
  962|  7.96k|    nssPKIObject_Destroy(&c->object);
  963|  7.96k|    return cc;
  964|  7.78k|}
pki3hack.c:fill_CERTCertificateFields:
  731|  3.89k|{
  732|  3.89k|    CERTCertTrust *trust = NULL;
  733|  3.89k|    NSSTrust *nssTrust;
  734|  3.89k|    NSSCryptoContext *context = c->object.cryptoContext;
  735|  3.89k|    nssCryptokiInstance *instance;
  736|  3.89k|    NSSUTF8 *stanNick = NULL;
  737|       |
  738|       |    /* We are holding the base class object's lock on entry of this function
  739|       |     * This lock protects writes to fields of the CERTCertificate .
  740|       |     * It is also needed by some functions to compute values such as trust.
  741|       |     */
  742|  3.89k|    instance = get_cert_instance(c);
  743|       |
  744|  3.89k|    if (instance) {
  ------------------
  |  Branch (744:9): [True: 0, False: 3.89k]
  ------------------
  745|      0|        stanNick = instance->label;
  746|  3.89k|    } else if (context) {
  ------------------
  |  Branch (746:16): [True: 3.89k, False: 0]
  ------------------
  747|  3.89k|        stanNick = c->object.tempName;
  748|  3.89k|    }
  749|       |    /* fill other fields needed by NSS3 functions using CERTCertificate */
  750|  3.89k|    if ((!cc->nickname && stanNick) || forced) {
  ------------------
  |  Branch (750:10): [True: 3.89k, False: 0]
  |  Branch (750:27): [True: 0, False: 3.89k]
  |  Branch (750:40): [True: 0, False: 3.89k]
  ------------------
  751|      0|        PRStatus nssrv;
  752|      0|        int nicklen, tokenlen, len;
  753|      0|        NSSUTF8 *tokenName = NULL;
  754|      0|        char *nick;
  755|      0|        if (instance &&
  ------------------
  |  Branch (755:13): [True: 0, False: 0]
  ------------------
  756|      0|            (!PK11_IsInternalKeySlot(instance->token->pk11slot) ||
  ------------------
  |  Branch (756:14): [True: 0, False: 0]
  ------------------
  757|      0|             (stanNick && PORT_Strchr(stanNick, ':') != NULL))) {
  ------------------
  |  |  186|      0|#define PORT_Strchr strchr
  ------------------
  |  Branch (757:15): [True: 0, False: 0]
  |  Branch (757:27): [True: 0, False: 0]
  ------------------
  758|      0|            tokenName = nssToken_GetName(instance->token);
  759|      0|            tokenlen = nssUTF8_Size(tokenName, &nssrv);
  760|      0|        } else {
  761|       |            /* don't use token name for internal slot; 3.3 didn't */
  762|      0|            tokenlen = 0;
  763|      0|        }
  764|      0|        if (stanNick) {
  ------------------
  |  Branch (764:13): [True: 0, False: 0]
  ------------------
  765|      0|            nicklen = nssUTF8_Size(stanNick, &nssrv);
  766|      0|            len = tokenlen + nicklen;
  767|      0|            nick = PORT_ArenaAlloc(cc->arena, len);
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  768|      0|            if (tokenName) {
  ------------------
  |  Branch (768:17): [True: 0, False: 0]
  ------------------
  769|      0|                memcpy(nick, tokenName, tokenlen - 1);
  770|      0|                nick[tokenlen - 1] = ':';
  771|      0|                memcpy(nick + tokenlen, stanNick, nicklen - 1);
  772|      0|            } else {
  773|      0|                memcpy(nick, stanNick, nicklen - 1);
  774|      0|            }
  775|      0|            nick[len - 1] = '\0';
  776|      0|            cc->nickname = nick;
  777|      0|        } else {
  778|      0|            cc->nickname = NULL;
  779|      0|        }
  780|      0|    }
  781|  3.89k|    if (context) {
  ------------------
  |  Branch (781:9): [True: 3.89k, False: 0]
  ------------------
  782|       |        /* trust */
  783|  3.89k|        nssTrust = nssCryptoContext_FindTrustForCertificate(context, c);
  784|  3.89k|        if (!nssTrust) {
  ------------------
  |  Branch (784:13): [True: 3.89k, False: 0]
  ------------------
  785|       |            /* chicken and egg issue:
  786|       |             *
  787|       |             * c->issuer and c->serial are empty at this point, but
  788|       |             * nssTrustDomain_FindTrustForCertificate use them to look up
  789|       |             * up the trust object, so we point them to cc->derIssuer and
  790|       |             * cc->serialNumber.
  791|       |             *
  792|       |             * Our caller will fill these in with proper arena copies when we
  793|       |             * return. */
  794|  3.89k|            c->issuer.data = cc->derIssuer.data;
  795|  3.89k|            c->issuer.size = cc->derIssuer.len;
  796|  3.89k|            c->serial.data = cc->serialNumber.data;
  797|  3.89k|            c->serial.size = cc->serialNumber.len;
  798|  3.89k|            nssTrust = nssTrustDomain_FindTrustForCertificate(context->td, c);
  799|  3.89k|        }
  800|  3.89k|        if (nssTrust) {
  ------------------
  |  Branch (800:13): [True: 0, False: 3.89k]
  ------------------
  801|      0|            trust = cert_trust_from_stan_trust(nssTrust, cc->arena);
  802|      0|            if (trust) {
  ------------------
  |  Branch (802:17): [True: 0, False: 0]
  ------------------
  803|       |                /* we should destroy cc->trust before replacing it, but it's
  804|       |                   allocated in cc->arena, so memory growth will occur on each
  805|       |                   refresh */
  806|      0|                CERT_LockCertTrust(cc);
  807|      0|                cc->trust = trust;
  808|      0|                CERT_UnlockCertTrust(cc);
  809|      0|            }
  810|      0|            nssTrust_Destroy(nssTrust);
  811|      0|        }
  812|  3.89k|    } else if (instance) {
  ------------------
  |  Branch (812:16): [True: 0, False: 0]
  ------------------
  813|       |        /* slot */
  814|      0|        if (cc->slot != instance->token->pk11slot) {
  ------------------
  |  Branch (814:13): [True: 0, False: 0]
  ------------------
  815|      0|            if (cc->slot) {
  ------------------
  |  Branch (815:17): [True: 0, False: 0]
  ------------------
  816|      0|                PK11_FreeSlot(cc->slot);
  817|      0|            }
  818|      0|            cc->slot = PK11_ReferenceSlot(instance->token->pk11slot);
  819|      0|        }
  820|      0|        cc->ownSlot = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  821|       |        /* pkcs11ID */
  822|      0|        cc->pkcs11ID = instance->handle;
  823|       |        /* trust */
  824|      0|        trust = nssTrust_GetCERTCertTrustForCert(c, cc);
  825|      0|        if (trust) {
  ------------------
  |  Branch (825:13): [True: 0, False: 0]
  ------------------
  826|       |            /* we should destroy cc->trust before replacing it, but it's
  827|       |               allocated in cc->arena, so memory growth will occur on each
  828|       |               refresh */
  829|      0|            CERT_LockCertTrust(cc);
  830|      0|            cc->trust = trust;
  831|      0|            CERT_UnlockCertTrust(cc);
  832|      0|        }
  833|       |        /* Read the distrust fields from a nssckbi/builtins certificate and
  834|       |         * fill the fields in CERTCertificate structure when any valid date
  835|       |         * is found. */
  836|      0|        if (PK11_IsReadOnly(cc->slot) && PK11_HasRootCerts(cc->slot)) {
  ------------------
  |  Branch (836:13): [True: 0, False: 0]
  |  Branch (836:42): [True: 0, False: 0]
  ------------------
  837|       |            /* The values are hard-coded and readonly. Read just once. */
  838|      0|            if (cc->distrust == NULL) {
  ------------------
  |  Branch (838:17): [True: 0, False: 0]
  ------------------
  839|      0|                CERTCertDistrust distrustModel;
  840|      0|                SECItem model = { siUTCTime, NULL, 0 };
  841|      0|                distrustModel.serverDistrustAfter = model;
  842|      0|                distrustModel.emailDistrustAfter = model;
  843|      0|                SECStatus rServer = PK11_ReadAttribute(
  844|      0|                    cc->slot, cc->pkcs11ID, CKA_NSS_SERVER_DISTRUST_AFTER,
  ------------------
  |  |  105|      0|#define CKA_NSS_SERVER_DISTRUST_AFTER (CKA_NSS + 35)
  |  |  ------------------
  |  |  |  |   77|      0|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|      0|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  845|      0|                    cc->arena, &distrustModel.serverDistrustAfter);
  846|      0|                SECStatus rEmail = PK11_ReadAttribute(
  847|      0|                    cc->slot, cc->pkcs11ID, CKA_NSS_EMAIL_DISTRUST_AFTER,
  ------------------
  |  |  106|      0|#define CKA_NSS_EMAIL_DISTRUST_AFTER (CKA_NSS + 36)
  |  |  ------------------
  |  |  |  |   77|      0|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|      0|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  848|      0|                    cc->arena, &distrustModel.emailDistrustAfter);
  849|       |                /* Only allocate the Distrust structure if a valid date is found.
  850|       |                 * The result length of a encoded valid timestamp is exactly 13 */
  851|      0|                const unsigned int kDistrustFieldSize = 13;
  852|      0|                if ((rServer == SECSuccess && rEmail == SECSuccess) &&
  ------------------
  |  Branch (852:22): [True: 0, False: 0]
  |  Branch (852:47): [True: 0, False: 0]
  ------------------
  853|      0|                    (distrustModel.serverDistrustAfter.len == kDistrustFieldSize ||
  ------------------
  |  Branch (853:22): [True: 0, False: 0]
  ------------------
  854|      0|                     distrustModel.emailDistrustAfter.len == kDistrustFieldSize)) {
  ------------------
  |  Branch (854:22): [True: 0, False: 0]
  ------------------
  855|      0|                    CERTCertDistrust *tmpPtr = PORT_ArenaAlloc(
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  856|      0|                        cc->arena, sizeof(CERTCertDistrust));
  857|      0|                    PORT_Memcpy(tmpPtr, &distrustModel,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  858|      0|                                sizeof(CERTCertDistrust));
  859|      0|                    cc->distrust = tmpPtr;
  860|      0|                }
  861|      0|            }
  862|      0|        }
  863|      0|    }
  864|  3.89k|    if (instance) {
  ------------------
  |  Branch (864:9): [True: 0, False: 3.89k]
  ------------------
  865|      0|        nssCryptokiObject_Destroy(instance);
  866|      0|    }
  867|       |    /* database handle is now the trust domain */
  868|  3.89k|    cc->dbhandle = c->object.trustDomain;
  869|       |    /* subjectList ? */
  870|       |    /* istemp and isperm are supported in NSS 3.4 */
  871|  3.89k|    CERT_LockCertTempPerm(cc);
  872|  3.89k|    cc->istemp = PR_FALSE; /* CERT_NewTemp will override this */
  ------------------
  |  |  438|  3.89k|#define PR_FALSE 0
  ------------------
  873|  3.89k|    cc->isperm = PR_TRUE;  /* by default */
  ------------------
  |  |  437|  3.89k|#define PR_TRUE 1
  ------------------
  874|       |    /* pointer back */
  875|  3.89k|    cc->nssCertificate = c;
  876|  3.89k|    CERT_UnlockCertTempPerm(cc);
  877|  3.89k|    if (trust) {
  ------------------
  |  Branch (877:9): [True: 0, False: 3.89k]
  ------------------
  878|       |        /* force the cert type to be recomputed to include trust info */
  879|      0|        PRUint32 nsCertType = cert_ComputeCertType(cc);
  880|       |
  881|       |        /* Assert that it is safe to cast &cc->nsCertType to "PRInt32 *" */
  882|      0|        PORT_Assert(sizeof(cc->nsCertType) == sizeof(PRInt32));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  883|      0|        PR_ATOMIC_SET((PRInt32 *)&cc->nsCertType, nsCertType);
  ------------------
  |  |  124|      0|#define PR_ATOMIC_SET(val, newval) __sync_lock_test_and_set(val, newval)
  ------------------
  884|      0|    }
  885|  3.89k|}

nssPKIObject_Lock:
   19|  12.3k|{
   20|  12.3k|    switch (object->lockType) {
   21|  12.3k|        case nssPKIMonitor:
  ------------------
  |  Branch (21:9): [True: 12.3k, False: 0]
  ------------------
   22|  12.3k|            PZ_EnterMonitor(object->sync.mlock);
  ------------------
  |  |  256|  12.3k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  ------------------
   23|  12.3k|            break;
   24|      0|        case nssPKILock:
  ------------------
  |  Branch (24:9): [True: 0, False: 12.3k]
  ------------------
   25|      0|            PZ_Lock(object->sync.lock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
   26|      0|            break;
   27|      0|        default:
  ------------------
  |  Branch (27:9): [True: 0, False: 12.3k]
  ------------------
   28|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   29|  12.3k|    }
   30|  12.3k|}
nssPKIObject_Unlock:
   34|  12.3k|{
   35|  12.3k|    switch (object->lockType) {
   36|  12.3k|        case nssPKIMonitor:
  ------------------
  |  Branch (36:9): [True: 12.3k, False: 0]
  ------------------
   37|  12.3k|            PZ_ExitMonitor(object->sync.mlock);
  ------------------
  |  |  257|  12.3k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  ------------------
   38|  12.3k|            break;
   39|      0|        case nssPKILock:
  ------------------
  |  Branch (39:9): [True: 0, False: 12.3k]
  ------------------
   40|      0|            PZ_Unlock(object->sync.lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
   41|      0|            break;
   42|      0|        default:
  ------------------
  |  Branch (42:9): [True: 0, False: 12.3k]
  ------------------
   43|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   44|  12.3k|    }
   45|  12.3k|}
nssPKIObject_NewLock:
   49|  4.06k|{
   50|  4.06k|    object->lockType = lockType;
   51|  4.06k|    switch (lockType) {
   52|  4.06k|        case nssPKIMonitor:
  ------------------
  |  Branch (52:9): [True: 4.06k, False: 0]
  ------------------
   53|  4.06k|            object->sync.mlock = PZ_NewMonitor(nssILockSSL);
  ------------------
  |  |  254|  4.06k|#define PZ_NewMonitor(t) PR_NewMonitor()
  ------------------
   54|  4.06k|            return (object->sync.mlock ? PR_SUCCESS : PR_FAILURE);
  ------------------
  |  Branch (54:21): [True: 4.06k, False: 0]
  ------------------
   55|      0|        case nssPKILock:
  ------------------
  |  Branch (55:9): [True: 0, False: 4.06k]
  ------------------
   56|      0|            object->sync.lock = PZ_NewLock(nssILockSSL);
  ------------------
  |  |  243|      0|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   57|      0|            return (object->sync.lock ? PR_SUCCESS : PR_FAILURE);
  ------------------
  |  Branch (57:21): [True: 0, False: 0]
  ------------------
   58|      0|        default:
  ------------------
  |  Branch (58:9): [True: 0, False: 4.06k]
  ------------------
   59|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   60|      0|            return PR_FAILURE;
   61|  4.06k|    }
   62|  4.06k|}
nssPKIObject_DestroyLock:
   66|  4.06k|{
   67|  4.06k|    switch (object->lockType) {
   68|  4.06k|        case nssPKIMonitor:
  ------------------
  |  Branch (68:9): [True: 4.06k, False: 0]
  ------------------
   69|  4.06k|            PZ_DestroyMonitor(object->sync.mlock);
  ------------------
  |  |  255|  4.06k|#define PZ_DestroyMonitor(m) PR_DestroyMonitor((m))
  ------------------
   70|  4.06k|            object->sync.mlock = NULL;
   71|  4.06k|            break;
   72|      0|        case nssPKILock:
  ------------------
  |  Branch (72:9): [True: 0, False: 4.06k]
  ------------------
   73|      0|            PZ_DestroyLock(object->sync.lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   74|      0|            object->sync.lock = NULL;
   75|      0|            break;
   76|      0|        default:
  ------------------
  |  Branch (76:9): [True: 0, False: 4.06k]
  ------------------
   77|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   78|  4.06k|    }
   79|  4.06k|}
nssPKIObject_Create:
   88|  4.06k|{
   89|  4.06k|    NSSArena *arena;
   90|  4.06k|    nssArenaMark *mark = NULL;
   91|  4.06k|    nssPKIObject *object;
   92|  4.06k|    if (arenaOpt) {
  ------------------
  |  Branch (92:9): [True: 0, False: 4.06k]
  ------------------
   93|      0|        arena = arenaOpt;
   94|      0|        mark = nssArena_Mark(arena);
   95|  4.06k|    } else {
   96|  4.06k|        arena = nssArena_Create();
   97|  4.06k|        if (!arena) {
  ------------------
  |  Branch (97:13): [True: 0, False: 4.06k]
  ------------------
   98|      0|            return (nssPKIObject *)NULL;
   99|      0|        }
  100|  4.06k|    }
  101|  4.06k|    object = nss_ZNEW(arena, nssPKIObject);
  ------------------
  |  |  348|  4.06k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  102|  4.06k|    if (!object) {
  ------------------
  |  Branch (102:9): [True: 0, False: 4.06k]
  ------------------
  103|      0|        goto loser;
  104|      0|    }
  105|  4.06k|    object->arena = arena;
  106|  4.06k|    object->trustDomain = td; /* XXX */
  107|  4.06k|    object->cryptoContext = cc;
  108|  4.06k|    if (PR_SUCCESS != nssPKIObject_NewLock(object, lockType)) {
  ------------------
  |  Branch (108:9): [True: 0, False: 4.06k]
  ------------------
  109|      0|        goto loser;
  110|      0|    }
  111|  4.06k|    if (instanceOpt) {
  ------------------
  |  Branch (111:9): [True: 0, False: 4.06k]
  ------------------
  112|      0|        if (nssPKIObject_AddInstance(object, instanceOpt) != PR_SUCCESS) {
  ------------------
  |  Branch (112:13): [True: 0, False: 0]
  ------------------
  113|      0|            goto loser;
  114|      0|        }
  115|      0|    }
  116|  4.06k|    PR_ATOMIC_INCREMENT(&object->refCount);
  ------------------
  |  |  122|  4.06k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  117|  4.06k|    if (mark) {
  ------------------
  |  Branch (117:9): [True: 0, False: 4.06k]
  ------------------
  118|      0|        nssArena_Unmark(arena, mark);
  119|      0|    }
  120|  4.06k|    return object;
  121|      0|loser:
  122|      0|    if (mark) {
  ------------------
  |  Branch (122:9): [True: 0, False: 0]
  ------------------
  123|      0|        nssArena_Release(arena, mark);
  124|      0|    } else {
  125|      0|        nssArena_Destroy(arena);
  126|      0|    }
  127|      0|    return (nssPKIObject *)NULL;
  128|  4.06k|}
nssPKIObject_Destroy:
  133|  8.13k|{
  134|  8.13k|    PRUint32 i;
  135|  8.13k|    PR_ASSERT(object->refCount > 0);
  ------------------
  |  |  208|  8.13k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 8.13k, False: 0]
  |  |  ------------------
  ------------------
  136|  8.13k|    if (PR_ATOMIC_DECREMENT(&object->refCount) == 0) {
  ------------------
  |  |  123|  8.13k|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (136:9): [True: 174, False: 7.96k]
  ------------------
  137|    174|        for (i = 0; i < object->numInstances; i++) {
  ------------------
  |  Branch (137:21): [True: 0, False: 174]
  ------------------
  138|      0|            nssCryptokiObject_Destroy(object->instances[i]);
  139|      0|        }
  140|    174|        nssPKIObject_DestroyLock(object);
  141|    174|        nssArena_Destroy(object->arena);
  142|    174|        return PR_TRUE;
  ------------------
  |  |  437|    174|#define PR_TRUE 1
  ------------------
  143|    174|    }
  144|  7.96k|    return PR_FALSE;
  ------------------
  |  |  438|  7.96k|#define PR_FALSE 0
  ------------------
  145|  8.13k|}
nssPKIObject_AddRef:
  150|   125k|{
  151|   125k|    PR_ATOMIC_INCREMENT(&object->refCount);
  ------------------
  |  |  122|   125k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  152|   125k|    return object;
  153|   125k|}
nssPKIObject_GetInstances:
  333|  3.89k|{
  334|  3.89k|    nssCryptokiObject **instances = NULL;
  335|  3.89k|    PRUint32 i;
  336|       |
  337|  3.89k|    nssPKIObject_Lock(object);
  338|  3.89k|    if (object->numInstances == 0) {
  ------------------
  |  Branch (338:9): [True: 3.89k, False: 0]
  ------------------
  339|  3.89k|        nssPKIObject_Unlock(object);
  340|  3.89k|        return (nssCryptokiObject **)NULL;
  341|  3.89k|    }
  342|      0|    instances = nss_ZNEWARRAY(NULL, nssCryptokiObject *,
  ------------------
  |  |  371|      0|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
  343|      0|                              object->numInstances + 1);
  344|      0|    if (instances) {
  ------------------
  |  Branch (344:9): [True: 0, False: 0]
  ------------------
  345|      0|        for (i = 0; i < object->numInstances; i++) {
  ------------------
  |  Branch (345:21): [True: 0, False: 0]
  ------------------
  346|      0|            instances[i] = nssCryptokiObject_Clone(object->instances[i]);
  347|      0|        }
  348|      0|    }
  349|      0|    nssPKIObject_Unlock(object);
  350|      0|    return instances;
  351|  3.89k|}
nssCertificateArray_Destroy:
  356|      1|{
  357|      1|    if (certs) {
  ------------------
  |  Branch (357:9): [True: 0, False: 1]
  ------------------
  358|      0|        NSSCertificate **certp;
  359|      0|        for (certp = certs; *certp; certp++) {
  ------------------
  |  Branch (359:29): [True: 0, False: 0]
  ------------------
  360|      0|            if ((*certp)->decoding) {
  ------------------
  |  Branch (360:17): [True: 0, False: 0]
  ------------------
  361|      0|                CERTCertificate *cc = STAN_GetCERTCertificate(*certp);
  362|      0|                if (cc) {
  ------------------
  |  Branch (362:21): [True: 0, False: 0]
  ------------------
  363|      0|                    CERT_DestroyCertificate(cc);
  364|      0|                }
  365|      0|                continue;
  366|      0|            }
  367|      0|            nssCertificate_Destroy(*certp);
  368|      0|        }
  369|      0|        nss_ZFreeIf(certs);
  370|      0|    }
  371|      1|}
nssPKIObjectCollection_Destroy:
  639|      3|{
  640|      3|    if (collection) {
  ------------------
  |  Branch (640:9): [True: 3, False: 0]
  ------------------
  641|      3|        PRCList *link;
  642|      3|        pkiObjectCollectionNode *node;
  643|       |        /* first destroy any objects in the collection */
  644|      3|        link = PR_NEXT_LINK(&collection->head);
  ------------------
  |  |   47|      3|        ((_e)->next)
  ------------------
  645|      5|        while (link != &collection->head) {
  ------------------
  |  Branch (645:16): [True: 2, False: 3]
  ------------------
  646|      2|            node = (pkiObjectCollectionNode *)link;
  647|      2|            if (node->haveObject) {
  ------------------
  |  Branch (647:17): [True: 2, False: 0]
  ------------------
  648|      2|                (*collection->destroyObject)(node->object);
  649|      2|            } else {
  650|      0|                nssPKIObject_Destroy(node->object);
  651|      0|            }
  652|      2|            link = PR_NEXT_LINK(link);
  ------------------
  |  |   47|      2|        ((_e)->next)
  ------------------
  653|      2|        }
  654|       |        /* then destroy it */
  655|      3|        nssArena_Destroy(collection->arena);
  656|      3|    }
  657|      3|}
nssPKIObjectCollection_AddObject:
  670|      2|{
  671|      2|    pkiObjectCollectionNode *node;
  672|      2|    node = nss_ZNEW(collection->arena, pkiObjectCollectionNode);
  ------------------
  |  |  348|      2|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  673|      2|    if (!node) {
  ------------------
  |  Branch (673:9): [True: 0, False: 2]
  ------------------
  674|      0|        return PR_FAILURE;
  675|      0|    }
  676|      2|    node->haveObject = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  677|      2|    node->object = nssPKIObject_AddRef(object);
  678|      2|    (*collection->getUIDFromObject)(object, node->uid);
  679|      2|    PR_INIT_CLIST(&node->link);
  ------------------
  |  |  100|      2|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      2|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      2|    (_l)->next = (_l); \
  |  |  102|      2|    (_l)->prev = (_l); \
  |  |  103|      2|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      2|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  680|      2|    PR_INSERT_BEFORE(&node->link, &collection->head);
  ------------------
  |  |   25|      2|    PR_BEGIN_MACRO       \
  |  |  ------------------
  |  |  |  |  123|      2|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   26|      2|    (_e)->next = (_l);   \
  |  |   27|      2|    (_e)->prev = (_l)->prev; \
  |  |   28|      2|    (_l)->prev->next = (_e); \
  |  |   29|      2|    (_l)->prev = (_e);   \
  |  |   30|      2|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      2|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  681|      2|    collection->size++;
  682|      2|    return PR_SUCCESS;
  683|      2|}
nssPKIObjectCollection_Traverse:
  878|      1|{
  879|      1|    PRCList *link = PR_NEXT_LINK(&collection->head);
  ------------------
  |  |   47|      1|        ((_e)->next)
  ------------------
  880|      1|    pkiObjectCollectionNode *node;
  881|      1|    while (link != &collection->head) {
  ------------------
  |  Branch (881:12): [True: 0, False: 1]
  ------------------
  882|      0|        node = (pkiObjectCollectionNode *)link;
  883|      0|        if (!node->haveObject) {
  ------------------
  |  Branch (883:13): [True: 0, False: 0]
  ------------------
  884|      0|            node->object = (*collection->createObject)(node->object);
  885|      0|            if (!node->object) {
  ------------------
  |  Branch (885:17): [True: 0, False: 0]
  ------------------
  886|      0|                link = PR_NEXT_LINK(link);
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  887|       |                /*remove bogus object from list*/
  888|      0|                nssPKIObjectCollection_RemoveNode(collection, node);
  889|      0|                continue;
  890|      0|            }
  891|      0|            node->haveObject = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  892|      0|        }
  893|      0|        switch (collection->objectType) {
  ------------------
  |  Branch (893:17): [True: 0, False: 0]
  ------------------
  894|      0|            case pkiObjectType_Certificate:
  ------------------
  |  Branch (894:13): [True: 0, False: 0]
  ------------------
  895|      0|                (void)(*callback->func.cert)((NSSCertificate *)node->object,
  896|      0|                                             callback->arg);
  897|      0|                break;
  898|      0|            case pkiObjectType_CRL:
  ------------------
  |  Branch (898:13): [True: 0, False: 0]
  ------------------
  899|      0|                (void)(*callback->func.crl)((NSSCRL *)node->object,
  900|      0|                                            callback->arg);
  901|      0|                break;
  902|      0|            case pkiObjectType_PrivateKey:
  ------------------
  |  Branch (902:13): [True: 0, False: 0]
  ------------------
  903|      0|                (void)(*callback->func.pvkey)((NSSPrivateKey *)node->object,
  904|      0|                                              callback->arg);
  905|      0|                break;
  906|      0|            case pkiObjectType_PublicKey:
  ------------------
  |  Branch (906:13): [True: 0, False: 0]
  ------------------
  907|      0|                (void)(*callback->func.pbkey)((NSSPublicKey *)node->object,
  908|      0|                                              callback->arg);
  909|      0|                break;
  910|      0|        }
  911|      0|        link = PR_NEXT_LINK(link);
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  912|      0|    }
  913|      1|    return PR_SUCCESS;
  914|      1|}
nssCertificateCollection_Create:
 1034|      3|{
 1035|      3|    nssPKIObjectCollection *collection;
 1036|      3|    collection = nssPKIObjectCollection_Create(td, NULL, nssPKIMonitor);
 1037|      3|    if (!collection) {
  ------------------
  |  Branch (1037:9): [True: 0, False: 3]
  ------------------
 1038|      0|        return NULL;
 1039|      0|    }
 1040|      3|    collection->objectType = pkiObjectType_Certificate;
 1041|      3|    collection->destroyObject = cert_destroyObject;
 1042|      3|    collection->getUIDFromObject = cert_getUIDFromObject;
 1043|      3|    collection->getUIDFromInstance = cert_getUIDFromInstance;
 1044|      3|    collection->createObject = cert_createObject;
 1045|      3|    if (certsOpt) {
  ------------------
  |  Branch (1045:9): [True: 0, False: 3]
  ------------------
 1046|      0|        for (; *certsOpt; certsOpt++) {
  ------------------
  |  Branch (1046:16): [True: 0, False: 0]
  ------------------
 1047|      0|            nssPKIObject *object = (nssPKIObject *)(*certsOpt);
 1048|      0|            (void)nssPKIObjectCollection_AddObject(collection, object);
 1049|      0|        }
 1050|      0|    }
 1051|      3|    return collection;
 1052|      3|}
nssPKIObjectCollection_GetCertificates:
 1060|      2|{
 1061|      2|    PRStatus status;
 1062|      2|    PRUint32 rvSize;
 1063|      2|    PRBool allocated = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1064|      2|    if (collection->size == 0) {
  ------------------
  |  Branch (1064:9): [True: 0, False: 2]
  ------------------
 1065|      0|        return (NSSCertificate **)NULL;
 1066|      0|    }
 1067|      2|    if (maximumOpt == 0) {
  ------------------
  |  Branch (1067:9): [True: 0, False: 2]
  ------------------
 1068|      0|        rvSize = collection->size;
 1069|      2|    } else {
 1070|      2|        rvSize = PR_MIN(collection->size, maximumOpt);
  ------------------
  |  |  158|      2|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 2, False: 0]
  |  |  ------------------
  ------------------
 1071|      2|    }
 1072|      2|    if (!rvOpt) {
  ------------------
  |  Branch (1072:9): [True: 2, False: 0]
  ------------------
 1073|      2|        rvOpt = nss_ZNEWARRAY(arenaOpt, NSSCertificate *, rvSize + 1);
  ------------------
  |  |  371|      2|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
 1074|      2|        if (!rvOpt) {
  ------------------
  |  Branch (1074:13): [True: 0, False: 2]
  ------------------
 1075|      0|            return (NSSCertificate **)NULL;
 1076|      0|        }
 1077|      2|        allocated = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1078|      2|    }
 1079|      2|    status = nssPKIObjectCollection_GetObjects(collection,
 1080|      2|                                               (nssPKIObject **)rvOpt,
 1081|      2|                                               rvSize);
 1082|      2|    if (status != PR_SUCCESS) {
  ------------------
  |  Branch (1082:9): [True: 0, False: 2]
  ------------------
 1083|      0|        if (allocated) {
  ------------------
  |  Branch (1083:13): [True: 0, False: 0]
  ------------------
 1084|      0|            nss_ZFreeIf(rvOpt);
 1085|      0|        }
 1086|      0|        return (NSSCertificate **)NULL;
 1087|      0|    }
 1088|      2|    return rvOpt;
 1089|      2|}
pkibase.c:nssPKIObjectCollection_Create:
  614|      3|{
  615|      3|    NSSArena *arena;
  616|      3|    nssPKIObjectCollection *rvCollection = NULL;
  617|      3|    arena = nssArena_Create();
  618|      3|    if (!arena) {
  ------------------
  |  Branch (618:9): [True: 0, False: 3]
  ------------------
  619|      0|        return (nssPKIObjectCollection *)NULL;
  620|      0|    }
  621|      3|    rvCollection = nss_ZNEW(arena, nssPKIObjectCollection);
  ------------------
  |  |  348|      3|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  622|      3|    if (!rvCollection) {
  ------------------
  |  Branch (622:9): [True: 0, False: 3]
  ------------------
  623|      0|        goto loser;
  624|      0|    }
  625|      3|    PR_INIT_CLIST(&rvCollection->head);
  ------------------
  |  |  100|      6|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      3|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      6|    (_l)->next = (_l); \
  |  |  102|      6|    (_l)->prev = (_l); \
  |  |  103|      6|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      3|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  626|      3|    rvCollection->arena = arena;
  627|      3|    rvCollection->td = td; /* XXX */
  628|      3|    rvCollection->cc = ccOpt;
  629|      3|    rvCollection->lockType = lockType;
  630|      3|    return rvCollection;
  631|      0|loser:
  632|      0|    nssArena_Destroy(arena);
  633|      0|    return (nssPKIObjectCollection *)NULL;
  634|      3|}
pkibase.c:cert_destroyObject:
  957|      2|{
  958|      2|    NSSCertificate *c = (NSSCertificate *)o;
  959|      2|    if (c->decoding) {
  ------------------
  |  Branch (959:9): [True: 2, False: 0]
  ------------------
  960|      2|        CERTCertificate *cc = STAN_GetCERTCertificate(c);
  961|      2|        if (cc) {
  ------------------
  |  Branch (961:13): [True: 2, False: 0]
  ------------------
  962|      2|            CERT_DestroyCertificate(cc);
  963|      2|            return;
  964|      2|        } /* else destroy it as NSSCertificate below */
  965|      2|    }
  966|      0|    nssCertificate_Destroy(c);
  967|      0|}
pkibase.c:cert_getUIDFromObject:
  971|      2|{
  972|      2|    NSSCertificate *c = (NSSCertificate *)o;
  973|       |    /* The builtins are still returning decoded serial numbers.  Until
  974|       |     * this compatibility issue is resolved, use the full DER of the
  975|       |     * cert to uniquely identify it.
  976|       |     */
  977|      2|    NSSDER *derCert;
  978|      2|    derCert = nssCertificate_GetEncoding(c);
  979|      2|    uid[0].data = NULL;
  980|      2|    uid[0].size = 0;
  981|      2|    uid[1].data = NULL;
  982|      2|    uid[1].size = 0;
  983|      2|    if (derCert != NULL) {
  ------------------
  |  Branch (983:9): [True: 2, False: 0]
  ------------------
  984|      2|        uid[0] = *derCert;
  985|      2|    }
  986|      2|    return PR_SUCCESS;
  987|      2|}
pkibase.c:nssPKIObjectCollection_GetObjects:
  846|      2|{
  847|      2|    PRUint32 i = 0;
  848|      2|    PRCList *link = PR_NEXT_LINK(&collection->head);
  ------------------
  |  |   47|      2|        ((_e)->next)
  ------------------
  849|      2|    pkiObjectCollectionNode *node;
  850|      2|    int error = 0;
  851|      4|    while ((i < rvSize) && (link != &collection->head)) {
  ------------------
  |  Branch (851:12): [True: 2, False: 2]
  |  Branch (851:28): [True: 2, False: 0]
  ------------------
  852|      2|        node = (pkiObjectCollectionNode *)link;
  853|      2|        if (!node->haveObject) {
  ------------------
  |  Branch (853:13): [True: 0, False: 2]
  ------------------
  854|       |            /* Convert the proto-object to an object */
  855|      0|            node->object = (*collection->createObject)(node->object);
  856|      0|            if (!node->object) {
  ------------------
  |  Branch (856:17): [True: 0, False: 0]
  ------------------
  857|      0|                link = PR_NEXT_LINK(link);
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  858|       |                /*remove bogus object from list*/
  859|      0|                nssPKIObjectCollection_RemoveNode(collection, node);
  860|      0|                error++;
  861|      0|                continue;
  862|      0|            }
  863|      0|            node->haveObject = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  864|      0|        }
  865|      2|        rvObjects[i++] = nssPKIObject_AddRef(node->object);
  866|      2|        link = PR_NEXT_LINK(link);
  ------------------
  |  |   47|      2|        ((_e)->next)
  ------------------
  867|      2|    }
  868|      2|    if (!error && *rvObjects == NULL) {
  ------------------
  |  Branch (868:9): [True: 2, False: 0]
  |  Branch (868:19): [True: 0, False: 2]
  ------------------
  869|      0|        nss_SetError(NSS_ERROR_NOT_FOUND);
  870|      0|    }
  871|      2|    return PR_SUCCESS;
  872|      2|}

nssCertificateStore_Create:
   64|      1|{
   65|      1|    NSSArena *arena;
   66|      1|    nssCertificateStore *store;
   67|      1|    PRBool i_alloced_arena;
   68|      1|    if (arenaOpt) {
  ------------------
  |  Branch (68:9): [True: 1, False: 0]
  ------------------
   69|      1|        arena = arenaOpt;
   70|      1|        i_alloced_arena = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   71|      1|    } else {
   72|      0|        arena = nssArena_Create();
   73|      0|        if (!arena) {
  ------------------
  |  Branch (73:13): [True: 0, False: 0]
  ------------------
   74|      0|            return NULL;
   75|      0|        }
   76|      0|        i_alloced_arena = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
   77|      0|    }
   78|      1|    store = nss_ZNEW(arena, nssCertificateStore);
  ------------------
  |  |  348|      1|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   79|      1|    if (!store) {
  ------------------
  |  Branch (79:9): [True: 0, False: 1]
  ------------------
   80|      0|        goto loser;
   81|      0|    }
   82|      1|    store->lock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   83|      1|    if (!store->lock) {
  ------------------
  |  Branch (83:9): [True: 0, False: 1]
  ------------------
   84|      0|        goto loser;
   85|      0|    }
   86|       |    /* Create the issuer/serial --> {cert, trust, S/MIME profile } hash */
   87|      1|    store->issuer_and_serial = nssHash_CreateCertificate(arena, 0);
   88|      1|    if (!store->issuer_and_serial) {
  ------------------
  |  Branch (88:9): [True: 0, False: 1]
  ------------------
   89|      0|        goto loser;
   90|      0|    }
   91|       |    /* Create the subject DER --> subject list hash */
   92|      1|    store->subject = nssHash_CreateItem(arena, 0);
   93|      1|    if (!store->subject) {
  ------------------
  |  Branch (93:9): [True: 0, False: 1]
  ------------------
   94|      0|        goto loser;
   95|      0|    }
   96|      1|    store->arena = arena;
   97|      1|    store->i_alloced_arena = i_alloced_arena;
   98|      1|    return store;
   99|      0|loser:
  100|      0|    if (store) {
  ------------------
  |  Branch (100:9): [True: 0, False: 0]
  ------------------
  101|      0|        if (store->lock) {
  ------------------
  |  Branch (101:13): [True: 0, False: 0]
  ------------------
  102|      0|            PZ_DestroyLock(store->lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  103|      0|        }
  104|      0|        if (store->issuer_and_serial) {
  ------------------
  |  Branch (104:13): [True: 0, False: 0]
  ------------------
  105|      0|            nssHash_Destroy(store->issuer_and_serial);
  106|      0|        }
  107|      0|        if (store->subject) {
  ------------------
  |  Branch (107:13): [True: 0, False: 0]
  ------------------
  108|      0|            nssHash_Destroy(store->subject);
  109|      0|        }
  110|      0|    }
  111|      0|    if (i_alloced_arena) {
  ------------------
  |  Branch (111:9): [True: 0, False: 0]
  ------------------
  112|      0|        nssArena_Destroy(arena);
  113|      0|    }
  114|      0|    return NULL;
  115|      1|}
nssCertificateStore_Destroy:
  121|      1|{
  122|      1|    if (nssHash_Count(store->issuer_and_serial) > 0) {
  ------------------
  |  Branch (122:9): [True: 0, False: 1]
  ------------------
  123|      0|        nss_SetError(NSS_ERROR_BUSY);
  124|      0|        return PR_FAILURE;
  125|      0|    }
  126|      1|    PZ_DestroyLock(store->lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  127|      1|    nssHash_Destroy(store->issuer_and_serial);
  128|      1|    nssHash_Destroy(store->subject);
  129|      1|    if (store->i_alloced_arena) {
  ------------------
  |  Branch (129:9): [True: 0, False: 1]
  ------------------
  130|      0|        nssArena_Destroy(store->arena);
  131|      1|    } else {
  132|      1|        nss_ZFreeIf(store);
  133|      1|    }
  134|      1|    return PR_SUCCESS;
  135|      1|}
nssCertificateStore_FindOrAdd:
  211|  3.89k|{
  212|  3.89k|    PRStatus nssrv;
  213|  3.89k|    NSSCertificate *rvCert = NULL;
  214|       |
  215|  3.89k|    PZ_Lock(store->lock);
  ------------------
  |  |  245|  3.89k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  216|  3.89k|    rvCert = nssCertStore_FindCertByIssuerAndSerialNumberLocked(
  217|  3.89k|        store, &c->issuer, &c->serial);
  218|  3.89k|    if (!rvCert) {
  ------------------
  |  Branch (218:9): [True: 3.89k, False: 0]
  ------------------
  219|  3.89k|        nssrv = nssCertificateStore_AddLocked(store, c);
  220|  3.89k|        if (PR_SUCCESS == nssrv) {
  ------------------
  |  Branch (220:13): [True: 3.89k, False: 0]
  ------------------
  221|  3.89k|            rvCert = nssCertificate_AddRef(c);
  222|  3.89k|        }
  223|  3.89k|    }
  224|  3.89k|    PZ_Unlock(store->lock);
  ------------------
  |  |  246|  3.89k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  225|  3.89k|    return rvCert;
  226|  3.89k|}
nssCertificateStore_RemoveCertLOCKED:
  278|  3.89k|{
  279|  3.89k|    certificate_hash_entry *entry;
  280|  3.89k|    entry = (certificate_hash_entry *)
  281|  3.89k|        nssHash_Lookup(store->issuer_and_serial, cert);
  282|  3.89k|    if (entry && entry->cert == cert) {
  ------------------
  |  Branch (282:9): [True: 3.89k, False: 0]
  |  Branch (282:18): [True: 3.89k, False: 0]
  ------------------
  283|  3.89k|        remove_certificate_entry(store, cert);
  284|  3.89k|        remove_subject_entry(store, cert);
  285|  3.89k|    }
  286|  3.89k|}
nssCertificateStore_Lock:
  290|   120k|{
  291|   120k|#ifdef DEBUG
  292|   120k|    PORT_Assert(out);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  293|   120k|    out->store = store;
  294|   120k|    out->lock = store->lock;
  295|   120k|    out->locked = PR_TRUE;
  ------------------
  |  |  437|   120k|#define PR_TRUE 1
  ------------------
  296|   120k|    PZ_Lock(out->lock);
  ------------------
  |  |  245|   120k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  297|       |#else
  298|       |    PZ_Lock(store->lock);
  299|       |#endif
  300|   120k|}
nssCertificateStore_Unlock:
  306|   120k|{
  307|   120k|#ifdef DEBUG
  308|   120k|    PORT_Assert(in);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  309|   120k|    PORT_Assert(out);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  310|   120k|    out->store = store;
  311|   120k|    out->lock = store->lock;
  312|   120k|    PORT_Assert(!out->locked);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  313|   120k|    out->unlocked = PR_TRUE;
  ------------------
  |  |  437|   120k|#define PR_TRUE 1
  ------------------
  314|       |
  315|   120k|    PORT_Assert(in->store == out->store);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  316|   120k|    PORT_Assert(in->lock == out->lock);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  317|   120k|    PORT_Assert(in->locked);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  318|   120k|    PORT_Assert(!in->unlocked);
  ------------------
  |  |  120|   120k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   120k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 120k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  319|       |
  320|   120k|    PZ_Unlock(out->lock);
  ------------------
  |  |  246|   120k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  321|       |#else
  322|       |    PZ_Unlock(store->lock);
  323|       |#endif
  324|   120k|}
nssCertificateStore_FindCertificateByIssuerAndSerialNumber:
  520|  3.94k|{
  521|  3.94k|    NSSCertificate *rvCert = NULL;
  522|       |
  523|  3.94k|    PZ_Lock(store->lock);
  ------------------
  |  |  245|  3.94k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  524|  3.94k|    rvCert = nssCertStore_FindCertByIssuerAndSerialNumberLocked(
  525|  3.94k|        store, issuer, serial);
  526|  3.94k|    PZ_Unlock(store->lock);
  ------------------
  |  |  246|  3.94k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  527|  3.94k|    return rvCert;
  528|  3.94k|}
nssCertificateStore_FindCertificateByEncodedCertificate:
  534|  4.07k|{
  535|  4.07k|    PRStatus nssrv = PR_FAILURE;
  536|  4.07k|    NSSDER issuer, serial;
  537|  4.07k|    NSSCertificate *rvCert = NULL;
  538|  4.07k|    nssrv = nssPKIX509_GetIssuerAndSerialFromDER(encoding, &issuer, &serial);
  539|  4.07k|    if (nssrv != PR_SUCCESS) {
  ------------------
  |  Branch (539:9): [True: 130, False: 3.94k]
  ------------------
  540|    130|        return NULL;
  541|    130|    }
  542|  3.94k|    rvCert = nssCertificateStore_FindCertificateByIssuerAndSerialNumber(store,
  543|  3.94k|                                                                        &issuer,
  544|  3.94k|                                                                        &serial);
  545|  3.94k|    PORT_Free(issuer.data);
  ------------------
  |  |   60|  3.94k|#define PORT_Free PORT_Free_Util
  ------------------
  546|  3.94k|    PORT_Free(serial.data);
  ------------------
  |  |   60|  3.94k|#define PORT_Free PORT_Free_Util
  ------------------
  547|  3.94k|    return rvCert;
  548|  4.07k|}
nssCertificateStore_FindTrustForCertificate:
  576|  3.89k|{
  577|  3.89k|    certificate_hash_entry *entry;
  578|  3.89k|    NSSTrust *rvTrust = NULL;
  579|  3.89k|    PZ_Lock(store->lock);
  ------------------
  |  |  245|  3.89k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  580|  3.89k|    entry = (certificate_hash_entry *)
  581|  3.89k|        nssHash_Lookup(store->issuer_and_serial, cert);
  582|  3.89k|    if (entry && entry->trust) {
  ------------------
  |  Branch (582:9): [True: 0, False: 3.89k]
  |  Branch (582:18): [True: 0, False: 0]
  ------------------
  583|      0|        rvTrust = nssTrust_AddRef(entry->trust);
  584|      0|    }
  585|  3.89k|    PZ_Unlock(store->lock);
  ------------------
  |  |  246|  3.89k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  586|  3.89k|    return rvTrust;
  587|  3.89k|}
nssHash_CreateCertificate:
  658|      2|{
  659|      2|    return nssHash_Create(arenaOpt,
  660|      2|                          numBuckets,
  661|      2|                          nss_certificate_hash,
  662|      2|                          nss_compare_certs,
  663|      2|                          PL_CompareValues);
  664|      2|}
pkistore.c:nssCertificateStore_AddLocked:
  196|  3.89k|{
  197|  3.89k|    PRStatus nssrv = add_certificate_entry(store, cert);
  198|  3.89k|    if (nssrv == PR_SUCCESS) {
  ------------------
  |  Branch (198:9): [True: 3.89k, False: 0]
  ------------------
  199|  3.89k|        nssrv = add_subject_entry(store, cert);
  200|  3.89k|        if (nssrv == PR_FAILURE) {
  ------------------
  |  Branch (200:13): [True: 0, False: 3.89k]
  ------------------
  201|      0|            remove_certificate_entry(store, cert);
  202|      0|        }
  203|  3.89k|    }
  204|  3.89k|    return nssrv;
  205|  3.89k|}
pkistore.c:add_certificate_entry:
  141|  3.89k|{
  142|  3.89k|    PRStatus nssrv;
  143|  3.89k|    certificate_hash_entry *entry;
  144|  3.89k|    entry = nss_ZNEW(cert->object.arena, certificate_hash_entry);
  ------------------
  |  |  348|  3.89k|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  145|  3.89k|    if (!entry) {
  ------------------
  |  Branch (145:9): [True: 0, False: 3.89k]
  ------------------
  146|      0|        return PR_FAILURE;
  147|      0|    }
  148|  3.89k|    entry->cert = cert;
  149|  3.89k|    nssrv = nssHash_Add(store->issuer_and_serial, cert, entry);
  150|  3.89k|    if (nssrv != PR_SUCCESS) {
  ------------------
  |  Branch (150:9): [True: 0, False: 3.89k]
  ------------------
  151|      0|        nss_ZFreeIf(entry);
  152|      0|    }
  153|  3.89k|    return nssrv;
  154|  3.89k|}
pkistore.c:add_subject_entry:
  160|  3.89k|{
  161|  3.89k|    PRStatus nssrv;
  162|  3.89k|    nssList *subjectList;
  163|  3.89k|    subjectList = (nssList *)nssHash_Lookup(store->subject, &cert->subject);
  164|  3.89k|    if (subjectList) {
  ------------------
  |  Branch (164:9): [True: 230, False: 3.66k]
  ------------------
  165|       |        /* The subject is already in, add this cert to the list */
  166|    230|        nssrv = nssList_AddUnique(subjectList, cert);
  167|  3.66k|    } else {
  168|       |        /* Create a new subject list for the subject */
  169|  3.66k|        subjectList = nssList_Create(NULL, PR_FALSE);
  ------------------
  |  |  438|  3.66k|#define PR_FALSE 0
  ------------------
  170|  3.66k|        if (!subjectList) {
  ------------------
  |  Branch (170:13): [True: 0, False: 3.66k]
  ------------------
  171|      0|            return PR_FAILURE;
  172|      0|        }
  173|  3.66k|        nssList_SetSortFunction(subjectList, nssCertificate_SubjectListSort);
  174|       |        /* Add the cert entry to this list of subjects */
  175|  3.66k|        nssrv = nssList_Add(subjectList, cert);
  176|  3.66k|        if (nssrv != PR_SUCCESS) {
  ------------------
  |  Branch (176:13): [True: 0, False: 3.66k]
  ------------------
  177|      0|            return nssrv;
  178|      0|        }
  179|       |        /* Add the subject list to the cache */
  180|  3.66k|        nssrv = nssHash_Add(store->subject, &cert->subject, subjectList);
  181|  3.66k|    }
  182|  3.89k|    return nssrv;
  183|  3.89k|}
pkistore.c:remove_certificate_entry:
  232|  3.89k|{
  233|  3.89k|    certificate_hash_entry *entry;
  234|  3.89k|    entry = (certificate_hash_entry *)
  235|  3.89k|        nssHash_Lookup(store->issuer_and_serial, cert);
  236|  3.89k|    if (entry) {
  ------------------
  |  Branch (236:9): [True: 3.89k, False: 0]
  ------------------
  237|  3.89k|        nssHash_Remove(store->issuer_and_serial, cert);
  238|  3.89k|        if (entry->trust) {
  ------------------
  |  Branch (238:13): [True: 0, False: 3.89k]
  ------------------
  239|      0|            nssTrust_Destroy(entry->trust);
  240|      0|        }
  241|  3.89k|        if (entry->profile) {
  ------------------
  |  Branch (241:13): [True: 0, False: 3.89k]
  ------------------
  242|      0|            nssSMIMEProfile_Destroy(entry->profile);
  243|      0|        }
  244|  3.89k|        nss_ZFreeIf(entry);
  245|  3.89k|    }
  246|  3.89k|}
pkistore.c:remove_subject_entry:
  252|  3.89k|{
  253|  3.89k|    nssList *subjectList;
  254|       |    /* Get the subject list for the cert's subject */
  255|  3.89k|    subjectList = (nssList *)nssHash_Lookup(store->subject, &cert->subject);
  256|  3.89k|    if (subjectList) {
  ------------------
  |  Branch (256:9): [True: 3.89k, False: 0]
  ------------------
  257|       |        /* Remove the cert from the subject hash */
  258|  3.89k|        nssList_Remove(subjectList, cert);
  259|  3.89k|        nssHash_Remove(store->subject, &cert->subject);
  260|  3.89k|        if (nssList_Count(subjectList) == 0) {
  ------------------
  |  Branch (260:13): [True: 3.66k, False: 230]
  ------------------
  261|  3.66k|            nssList_Destroy(subjectList);
  262|  3.66k|        } else {
  263|       |            /* The cert being released may have keyed the subject entry.
  264|       |             * Since there are still subject certs around, get another and
  265|       |             * rekey the entry just in case.
  266|       |             */
  267|    230|            NSSCertificate *subjectCert;
  268|    230|            (void)nssList_GetArray(subjectList, (void **)&subjectCert, 1);
  269|    230|            nssHash_Add(store->subject, &subjectCert->subject, subjectList);
  270|    230|        }
  271|  3.89k|    }
  272|  3.89k|}
pkistore.c:nssCertStore_FindCertByIssuerAndSerialNumberLocked:
  500|  7.83k|{
  501|  7.83k|    certificate_hash_entry *entry;
  502|  7.83k|    NSSCertificate *rvCert = NULL;
  503|  7.83k|    NSSCertificate index;
  504|       |
  505|  7.83k|    index.issuer = *issuer;
  506|  7.83k|    index.serial = *serial;
  507|  7.83k|    entry = (certificate_hash_entry *)
  508|  7.83k|        nssHash_Lookup(store->issuer_and_serial, &index);
  509|  7.83k|    if (entry) {
  ------------------
  |  Branch (509:9): [True: 5, False: 7.82k]
  ------------------
  510|      5|        rvCert = nssCertificate_AddRef(entry->cert);
  511|      5|    }
  512|  7.83k|    return rvCert;
  513|  7.83k|}
pkistore.c:nss_certificate_hash:
  632|  31.2k|{
  633|  31.2k|    unsigned int i;
  634|  31.2k|    PLHashNumber h;
  635|  31.2k|    NSSCertificate *c = (NSSCertificate *)key;
  636|  31.2k|    h = 0;
  637|   762k|    for (i = 0; i < c->issuer.size; i++)
  ------------------
  |  Branch (637:17): [True: 731k, False: 31.2k]
  ------------------
  638|   731k|        h = PR_ROTATE_LEFT32(h, 4) ^ ((unsigned char *)c->issuer.data)[i];
  ------------------
  |  |  147|   731k|#define PR_ROTATE_LEFT32(a, bits) (((a) << (bits)) | ((a) >> (32 - (bits))))
  ------------------
  639|   146k|    for (i = 0; i < c->serial.size; i++)
  ------------------
  |  Branch (639:17): [True: 114k, False: 31.2k]
  ------------------
  640|   114k|        h = PR_ROTATE_LEFT32(h, 4) ^ ((unsigned char *)c->serial.data)[i];
  ------------------
  |  |  147|   114k|#define PR_ROTATE_LEFT32(a, bits) (((a) << (bits)) | ((a) >> (32 - (bits))))
  ------------------
  641|  31.2k|    return h;
  642|  31.2k|}
pkistore.c:nss_compare_certs:
  646|  11.6k|{
  647|  11.6k|    PRStatus ignore;
  648|  11.6k|    NSSCertificate *c1 = (NSSCertificate *)v1;
  649|  11.6k|    NSSCertificate *c2 = (NSSCertificate *)v2;
  650|  11.6k|    return (int)(nssItem_Equal(&c1->issuer, &c2->issuer, &ignore) &&
  ------------------
  |  Branch (650:18): [True: 11.6k, False: 7]
  ------------------
  651|  11.6k|                 nssItem_Equal(&c1->serial, &c2->serial, &ignore));
  ------------------
  |  Branch (651:18): [True: 11.6k, False: 1]
  ------------------
  652|  11.6k|}

nssTrustDomain_InitializeCache:
  121|      1|{
  122|      1|    NSSArena *arena;
  123|      1|    nssTDCertificateCache *cache = td->cache;
  124|       |#ifdef DEBUG_CACHE
  125|       |    s_log = PR_NewLogModule("nss_cache");
  126|       |    PR_ASSERT(s_log);
  127|       |#endif
  128|      1|    PR_ASSERT(!cache);
  ------------------
  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  ------------------
  ------------------
  129|      1|    arena = nssArena_Create();
  130|      1|    if (!arena) {
  ------------------
  |  Branch (130:9): [True: 0, False: 1]
  ------------------
  131|      0|        return PR_FAILURE;
  132|      0|    }
  133|      1|    cache = nss_ZNEW(arena, nssTDCertificateCache);
  ------------------
  |  |  348|      1|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
  134|      1|    if (!cache) {
  ------------------
  |  Branch (134:9): [True: 0, False: 1]
  ------------------
  135|      0|        nssArena_Destroy(arena);
  136|      0|        return PR_FAILURE;
  137|      0|    }
  138|      1|    cache->lock = PZ_NewLock(nssILockCache);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  139|      1|    if (!cache->lock) {
  ------------------
  |  Branch (139:9): [True: 0, False: 1]
  ------------------
  140|      0|        nssArena_Destroy(arena);
  141|      0|        return PR_FAILURE;
  142|      0|    }
  143|       |    /* Create the issuer and serial DER --> certificate hash */
  144|      1|    cache->issuerAndSN = nssHash_CreateCertificate(arena, cacheSize);
  145|      1|    if (!cache->issuerAndSN) {
  ------------------
  |  Branch (145:9): [True: 0, False: 1]
  ------------------
  146|      0|        goto loser;
  147|      0|    }
  148|       |    /* Create the subject DER --> subject list hash */
  149|      1|    cache->subject = nssHash_CreateItem(arena, cacheSize);
  150|      1|    if (!cache->subject) {
  ------------------
  |  Branch (150:9): [True: 0, False: 1]
  ------------------
  151|      0|        goto loser;
  152|      0|    }
  153|       |    /* Create the nickname --> subject list hash */
  154|      1|    cache->nickname = nssHash_CreateString(arena, cacheSize);
  155|      1|    if (!cache->nickname) {
  ------------------
  |  Branch (155:9): [True: 0, False: 1]
  ------------------
  156|      0|        goto loser;
  157|      0|    }
  158|       |    /* Create the email --> list of subject lists hash */
  159|      1|    cache->email = nssHash_CreateString(arena, cacheSize);
  160|      1|    if (!cache->email) {
  ------------------
  |  Branch (160:9): [True: 0, False: 1]
  ------------------
  161|      0|        goto loser;
  162|      0|    }
  163|      1|    cache->arena = arena;
  164|      1|    td->cache = cache;
  165|       |#ifdef DEBUG_CACHE
  166|       |    PR_LOG(s_log, PR_LOG_DEBUG, ("Cache initialized."));
  167|       |#endif
  168|      1|    return PR_SUCCESS;
  169|      0|loser:
  170|      0|    PZ_DestroyLock(cache->lock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  171|      0|    nssArena_Destroy(arena);
  172|      0|    td->cache = NULL;
  173|       |#ifdef DEBUG_CACHE
  174|       |    PR_LOG(s_log, PR_LOG_DEBUG, ("Cache initialization failed."));
  175|       |#endif
  176|      0|    return PR_FAILURE;
  177|      1|}
nssTrustDomain_DestroyCache:
  191|      1|{
  192|      1|    if (!td->cache) {
  ------------------
  |  Branch (192:9): [True: 0, False: 1]
  ------------------
  193|      0|        nss_SetError(NSS_ERROR_INTERNAL_ERROR);
  194|      0|        return PR_FAILURE;
  195|      0|    }
  196|      1|    if (nssHash_Count(td->cache->issuerAndSN) > 0) {
  ------------------
  |  Branch (196:9): [True: 0, False: 1]
  ------------------
  197|      0|        nss_SetError(NSS_ERROR_BUSY);
  198|      0|        return PR_FAILURE;
  199|      0|    }
  200|      1|    PZ_DestroyLock(td->cache->lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  201|      1|    nssHash_Destroy(td->cache->issuerAndSN);
  202|      1|    nssHash_Destroy(td->cache->subject);
  203|      1|    nssHash_Destroy(td->cache->nickname);
  204|      1|    nssHash_Destroy(td->cache->email);
  205|      1|    nssArena_Destroy(td->cache->arena);
  206|      1|    td->cache = NULL;
  207|       |#ifdef DEBUG_CACHE
  208|       |    PR_LOG(s_log, PR_LOG_DEBUG, ("Cache destroyed."));
  209|       |#endif
  210|      1|    return PR_SUCCESS;
  211|      1|}
nssTrustDomain_GetCertForIssuerAndSNFromCache:
 1017|  3.93k|{
 1018|  3.93k|    NSSCertificate certkey;
 1019|  3.93k|    NSSCertificate *rvCert = NULL;
 1020|  3.93k|    cache_entry *ce;
 1021|  3.93k|    certkey.issuer.data = issuer->data;
 1022|  3.93k|    certkey.issuer.size = issuer->size;
 1023|  3.93k|    certkey.serial.data = serial->data;
 1024|  3.93k|    certkey.serial.size = serial->size;
 1025|       |#ifdef DEBUG_CACHE
 1026|       |    log_item_dump("looking for cert by issuer/sn, issuer", issuer);
 1027|       |    log_item_dump("                               serial", serial);
 1028|       |#endif
 1029|  3.93k|    PZ_Lock(td->cache->lock);
  ------------------
  |  |  245|  3.93k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1030|  3.93k|    ce = (cache_entry *)nssHash_Lookup(td->cache->issuerAndSN, &certkey);
 1031|  3.93k|    if (ce) {
  ------------------
  |  Branch (1031:9): [True: 0, False: 3.93k]
  ------------------
 1032|      0|        ce->hits++;
 1033|      0|        ce->lastHit = PR_Now();
 1034|      0|        rvCert = nssCertificate_AddRef(ce->entry.cert);
 1035|       |#ifdef DEBUG_CACHE
 1036|       |        PR_LOG(s_log, PR_LOG_DEBUG, ("... found, %d hits", ce->hits));
 1037|       |#endif
 1038|      0|    }
 1039|  3.93k|    PZ_Unlock(td->cache->lock);
  ------------------
  |  |  246|  3.93k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1040|  3.93k|    return rvCert;
 1041|  3.93k|}
nssTrustDomain_GetCertsFromCache:
 1080|      1|{
 1081|      1|    NSSCertificate **rvArray = NULL;
 1082|      1|    nssList *certList;
 1083|      1|    if (certListOpt) {
  ------------------
  |  Branch (1083:9): [True: 1, False: 0]
  ------------------
 1084|      1|        certList = certListOpt;
 1085|      1|    } else {
 1086|      0|        certList = nssList_Create(NULL, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1087|      0|        if (!certList) {
  ------------------
  |  Branch (1087:13): [True: 0, False: 0]
  ------------------
 1088|      0|            return NULL;
 1089|      0|        }
 1090|      0|    }
 1091|      1|    PZ_Lock(td->cache->lock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1092|      1|    nssHash_Iterate(td->cache->issuerAndSN, cert_iter, (void *)certList);
 1093|      1|    PZ_Unlock(td->cache->lock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1094|      1|    if (!certListOpt) {
  ------------------
  |  Branch (1094:9): [True: 0, False: 1]
  ------------------
 1095|      0|        PRUint32 count = nssList_Count(certList);
 1096|      0|        rvArray = nss_ZNEWARRAY(NULL, NSSCertificate *, count);
  ------------------
  |  |  371|      0|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
 1097|      0|        nssList_GetArray(certList, (void **)rvArray, count);
 1098|       |        /* array takes the references */
 1099|      0|        nssList_Destroy(certList);
 1100|      0|    }
 1101|      1|    return rvArray;
 1102|      1|}

NSSTrustDomain_Create:
   32|      1|{
   33|      1|    NSSArena *arena;
   34|      1|    NSSTrustDomain *rvTD;
   35|      1|    arena = NSSArena_Create();
   36|      1|    if (!arena) {
  ------------------
  |  Branch (36:9): [True: 0, False: 1]
  ------------------
   37|      0|        return (NSSTrustDomain *)NULL;
   38|      0|    }
   39|      1|    rvTD = nss_ZNEW(arena, NSSTrustDomain);
  ------------------
  |  |  348|      1|#define nss_ZNEW(arenaOpt, type) ((type *)nss_ZAlloc((arenaOpt), sizeof(type)))
  ------------------
   40|      1|    if (!rvTD) {
  ------------------
  |  Branch (40:9): [True: 0, False: 1]
  ------------------
   41|      0|        goto loser;
   42|      0|    }
   43|       |    /* protect the token list and the token iterator */
   44|      1|    rvTD->tokensLock = NSSRWLock_New(100, "tokens");
  ------------------
  |  |   49|      1|#define NSSRWLock_New NSSRWLock_New_Util
  ------------------
   45|      1|    if (!rvTD->tokensLock) {
  ------------------
  |  Branch (45:9): [True: 0, False: 1]
  ------------------
   46|      0|        goto loser;
   47|      0|    }
   48|      1|    nssTrustDomain_InitializeCache(rvTD, NSSTRUSTDOMAIN_DEFAULT_CACHE_SIZE);
  ------------------
  |  |   20|      1|#define NSSTRUSTDOMAIN_DEFAULT_CACHE_SIZE 32
  ------------------
   49|      1|    rvTD->arena = arena;
   50|      1|    rvTD->refCount = 1;
   51|      1|    rvTD->statusConfig = NULL;
   52|      1|    return rvTD;
   53|      0|loser:
   54|      0|    if (rvTD && rvTD->tokensLock) {
  ------------------
  |  Branch (54:9): [True: 0, False: 0]
  |  Branch (54:17): [True: 0, False: 0]
  ------------------
   55|      0|        NSSRWLock_Destroy(rvTD->tokensLock);
  ------------------
  |  |   45|      0|#define NSSRWLock_Destroy NSSRWLock_Destroy_Util
  ------------------
   56|      0|    }
   57|      0|    nssArena_Destroy(arena);
   58|      0|    return (NSSTrustDomain *)NULL;
   59|      1|}
NSSTrustDomain_Destroy:
   78|      1|{
   79|      1|    PRStatus status = PR_SUCCESS;
   80|      1|    if (--td->refCount == 0) {
  ------------------
  |  Branch (80:9): [True: 1, False: 0]
  ------------------
   81|       |        /* Destroy each token in the list of tokens */
   82|      1|        if (td->tokens) {
  ------------------
  |  Branch (82:13): [True: 1, False: 0]
  ------------------
   83|      1|            nssListIterator_Destroy(td->tokens);
   84|      1|            td->tokens = NULL;
   85|      1|        }
   86|      1|        if (td->tokenList) {
  ------------------
  |  Branch (86:13): [True: 1, False: 0]
  ------------------
   87|      1|            nssList_Clear(td->tokenList, token_destructor);
   88|      1|            nssList_Destroy(td->tokenList);
   89|      1|            td->tokenList = NULL;
   90|      1|        }
   91|      1|        NSSRWLock_Destroy(td->tokensLock);
  ------------------
  |  |   45|      1|#define NSSRWLock_Destroy NSSRWLock_Destroy_Util
  ------------------
   92|      1|        td->tokensLock = NULL;
   93|      1|        status = nssTrustDomain_DestroyCache(td);
   94|      1|        if (status == PR_FAILURE) {
  ------------------
  |  Branch (94:13): [True: 0, False: 1]
  ------------------
   95|      0|            return status;
   96|      0|        }
   97|      1|        if (td->statusConfig) {
  ------------------
  |  Branch (97:13): [True: 0, False: 1]
  ------------------
   98|      0|            td->statusConfig->statusDestroy(td->statusConfig);
   99|      0|            td->statusConfig = NULL;
  100|      0|        }
  101|       |        /* Destroy the trust domain */
  102|      1|        nssArena_Destroy(td->arena);
  103|      1|    }
  104|      1|    return status;
  105|      1|}
nssTrustDomain_FindCertificateByIssuerAndSerialNumber:
  751|  3.93k|{
  752|  3.93k|    NSSSlot **slots = NULL;
  753|  3.93k|    NSSSlot **slotp;
  754|  3.93k|    NSSCertificate *rvCert = NULL;
  755|  3.93k|    nssPKIObjectCollection *collection = NULL;
  756|  3.93k|    nssUpdateLevel updateLevel;
  757|       |
  758|       |    /* see if this search is already cached */
  759|  3.93k|    rvCert = nssTrustDomain_GetCertForIssuerAndSNFromCache(td,
  760|  3.93k|                                                           issuer,
  761|  3.93k|                                                           serial);
  762|  3.93k|    if (rvCert) {
  ------------------
  |  Branch (762:9): [True: 0, False: 3.93k]
  ------------------
  763|      0|        return rvCert;
  764|      0|    }
  765|  3.93k|    slots = nssTrustDomain_GetActiveSlots(td, &updateLevel);
  766|  3.93k|    if (slots) {
  ------------------
  |  Branch (766:9): [True: 3.93k, False: 0]
  ------------------
  767|  11.8k|        for (slotp = slots; *slotp; slotp++) {
  ------------------
  |  Branch (767:29): [True: 7.87k, False: 3.93k]
  ------------------
  768|  7.87k|            NSSToken *token = nssSlot_GetToken(*slotp);
  769|  7.87k|            nssSession *session;
  770|  7.87k|            nssCryptokiObject *instance;
  771|  7.87k|            nssTokenSearchType tokenOnly = nssTokenSearchType_TokenOnly;
  772|  7.87k|            PRStatus status = PR_FAILURE;
  773|       |
  774|  7.87k|            if (!token)
  ------------------
  |  Branch (774:17): [True: 0, False: 7.87k]
  ------------------
  775|      0|                continue;
  776|  7.87k|            session = nssTrustDomain_GetSessionForToken(td, token);
  777|  7.87k|            if (session) {
  ------------------
  |  Branch (777:17): [True: 7.87k, False: 0]
  ------------------
  778|  7.87k|                instance = nssToken_FindCertificateByIssuerAndSerialNumber(
  779|  7.87k|                    token,
  780|  7.87k|                    session,
  781|  7.87k|                    issuer,
  782|  7.87k|                    serial,
  783|  7.87k|                    tokenOnly,
  784|  7.87k|                    &status);
  785|  7.87k|            }
  786|  7.87k|            (void)nssToken_Destroy(token);
  787|  7.87k|            if (status != PR_SUCCESS) {
  ------------------
  |  Branch (787:17): [True: 0, False: 7.87k]
  ------------------
  788|      0|                continue;
  789|      0|            }
  790|  7.87k|            if (instance) {
  ------------------
  |  Branch (790:17): [True: 0, False: 7.87k]
  ------------------
  791|      0|                if (!collection) {
  ------------------
  |  Branch (791:21): [True: 0, False: 0]
  ------------------
  792|      0|                    collection = nssCertificateCollection_Create(td, NULL);
  793|      0|                    if (!collection) {
  ------------------
  |  Branch (793:25): [True: 0, False: 0]
  ------------------
  794|      0|                        break; /* don't keep looping if out if memory */
  795|      0|                    }
  796|      0|                }
  797|      0|                status = nssPKIObjectCollection_AddInstances(collection,
  798|      0|                                                             &instance, 1);
  799|      0|                if (status == PR_SUCCESS) {
  ------------------
  |  Branch (799:21): [True: 0, False: 0]
  ------------------
  800|      0|                    (void)nssPKIObjectCollection_GetCertificates(
  801|      0|                        collection, &rvCert, 1, NULL);
  802|      0|                }
  803|      0|                if (rvCert) {
  ------------------
  |  Branch (803:21): [True: 0, False: 0]
  ------------------
  804|      0|                    break; /* found one cert, all done */
  805|      0|                }
  806|      0|            }
  807|  7.87k|        }
  808|  3.93k|    }
  809|  3.93k|    if (collection) {
  ------------------
  |  Branch (809:9): [True: 0, False: 3.93k]
  ------------------
  810|      0|        nssPKIObjectCollection_Destroy(collection);
  811|      0|    }
  812|  3.93k|    if (slots) {
  ------------------
  |  Branch (812:9): [True: 3.93k, False: 0]
  ------------------
  813|  3.93k|        nssSlotArray_Destroy(slots);
  814|  3.93k|    }
  815|  3.93k|    return rvCert;
  816|  3.93k|}
nssTrustDomain_FindCertificateByEncodedCertificate:
  833|  4.06k|{
  834|  4.06k|    PRStatus status;
  835|  4.06k|    NSSCertificate *rvCert = NULL;
  836|  4.06k|    NSSDER issuer = { 0 };
  837|  4.06k|    NSSDER serial = { 0 };
  838|       |    /* XXX this is not generic...  will any cert crack into issuer/serial? */
  839|  4.06k|    status = nssPKIX509_GetIssuerAndSerialFromDER(ber, &issuer, &serial);
  840|  4.06k|    if (status != PR_SUCCESS) {
  ------------------
  |  Branch (840:9): [True: 130, False: 3.93k]
  ------------------
  841|    130|        return NULL;
  842|    130|    }
  843|  3.93k|    rvCert = nssTrustDomain_FindCertificateByIssuerAndSerialNumber(td,
  844|  3.93k|                                                                   &issuer,
  845|  3.93k|                                                                   &serial);
  846|  3.93k|    PORT_Free(issuer.data);
  ------------------
  |  |   60|  3.93k|#define PORT_Free PORT_Free_Util
  ------------------
  847|  3.93k|    PORT_Free(serial.data);
  ------------------
  |  |   60|  3.93k|#define PORT_Free PORT_Free_Util
  ------------------
  848|  3.93k|    return rvCert;
  849|  4.06k|}
NSSTrustDomain_FindCertificateByEncodedCertificate:
  855|  4.06k|{
  856|  4.06k|    return nssTrustDomain_FindCertificateByEncodedCertificate(td, ber);
  857|  4.06k|}
NSSTrustDomain_TraverseCertificates:
  986|      1|{
  987|      1|    NSSToken *token = NULL;
  988|      1|    NSSSlot **slots = NULL;
  989|      1|    NSSSlot **slotp;
  990|      1|    nssPKIObjectCollection *collection = NULL;
  991|      1|    nssPKIObjectCallback pkiCallback;
  992|      1|    nssUpdateLevel updateLevel;
  993|      1|    NSSCertificate **cached = NULL;
  994|      1|    nssList *certList;
  995|       |
  996|      1|    certList = nssList_Create(NULL, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  997|      1|    if (!certList)
  ------------------
  |  Branch (997:9): [True: 0, False: 1]
  ------------------
  998|      0|        return NULL;
  999|      1|    (void)nssTrustDomain_GetCertsFromCache(td, certList);
 1000|      1|    cached = get_certs_from_list(certList);
 1001|      1|    collection = nssCertificateCollection_Create(td, cached);
 1002|      1|    nssCertificateArray_Destroy(cached);
 1003|      1|    nssList_Destroy(certList);
 1004|      1|    if (!collection) {
  ------------------
  |  Branch (1004:9): [True: 0, False: 1]
  ------------------
 1005|      0|        return (PRStatus *)NULL;
 1006|      0|    }
 1007|       |    /* obtain the current set of active slots in the trust domain */
 1008|      1|    slots = nssTrustDomain_GetActiveSlots(td, &updateLevel);
 1009|      1|    if (!slots) {
  ------------------
  |  Branch (1009:9): [True: 0, False: 1]
  ------------------
 1010|      0|        goto loser;
 1011|      0|    }
 1012|       |    /* iterate over the slots */
 1013|      3|    for (slotp = slots; *slotp; slotp++) {
  ------------------
  |  Branch (1013:25): [True: 2, False: 1]
  ------------------
 1014|       |        /* get the token for the slot, if present */
 1015|      2|        token = nssSlot_GetToken(*slotp);
 1016|      2|        if (token) {
  ------------------
  |  Branch (1016:13): [True: 2, False: 0]
  ------------------
 1017|      2|            nssSession *session;
 1018|      2|            nssTokenSearchType tokenOnly = nssTokenSearchType_TokenOnly;
 1019|       |            /* get a session for the token */
 1020|      2|            session = nssTrustDomain_GetSessionForToken(td, token);
 1021|      2|            if (session) {
  ------------------
  |  Branch (1021:17): [True: 2, False: 0]
  ------------------
 1022|       |                /* perform the traversal */
 1023|      2|                (void)nssToken_TraverseCertificates(token,
 1024|      2|                                                    session,
 1025|      2|                                                    tokenOnly,
 1026|      2|                                                    collector,
 1027|      2|                                                    collection);
 1028|      2|            }
 1029|      2|            (void)nssToken_Destroy(token);
 1030|      2|        }
 1031|      2|    }
 1032|       |
 1033|       |    /* Traverse the collection */
 1034|      1|    pkiCallback.func.cert = callback;
 1035|      1|    pkiCallback.arg = arg;
 1036|      1|    (void)nssPKIObjectCollection_Traverse(collection, &pkiCallback);
 1037|      1|loser:
 1038|      1|    if (slots) {
  ------------------
  |  Branch (1038:9): [True: 1, False: 0]
  ------------------
 1039|      1|        nssSlotArray_Destroy(slots);
 1040|      1|    }
 1041|      1|    if (collection) {
  ------------------
  |  Branch (1041:9): [True: 1, False: 0]
  ------------------
 1042|      1|        nssPKIObjectCollection_Destroy(collection);
 1043|      1|    }
 1044|      1|    return NULL;
 1045|      1|}
nssTrustDomain_FindTrustForCertificate:
 1051|  7.78k|{
 1052|  7.78k|    NSSSlot **slots;
 1053|  7.78k|    NSSSlot **slotp;
 1054|  7.78k|    nssCryptokiObject *to = NULL;
 1055|  7.78k|    nssPKIObject *pkio = NULL;
 1056|  7.78k|    NSSTrust *rvt = NULL;
 1057|  7.78k|    nssUpdateLevel updateLevel;
 1058|  7.78k|    slots = nssTrustDomain_GetActiveSlots(td, &updateLevel);
 1059|  7.78k|    if (!slots) {
  ------------------
  |  Branch (1059:9): [True: 0, False: 7.78k]
  ------------------
 1060|      0|        return (NSSTrust *)NULL;
 1061|      0|    }
 1062|  23.3k|    for (slotp = slots; *slotp; slotp++) {
  ------------------
  |  Branch (1062:25): [True: 15.5k, False: 7.78k]
  ------------------
 1063|  15.5k|        NSSToken *token = nssSlot_GetToken(*slotp);
 1064|       |
 1065|  15.5k|        if (token) {
  ------------------
  |  Branch (1065:13): [True: 15.5k, False: 0]
  ------------------
 1066|  15.5k|            to = nssToken_FindTrustForCertificate(token, NULL,
 1067|  15.5k|                                                  &c->encoding,
 1068|  15.5k|                                                  &c->issuer,
 1069|  15.5k|                                                  &c->serial,
 1070|  15.5k|                                                  nssTokenSearchType_TokenOnly);
 1071|  15.5k|            if (to) {
  ------------------
  |  Branch (1071:17): [True: 0, False: 15.5k]
  ------------------
 1072|      0|                PRStatus status;
 1073|      0|                if (!pkio) {
  ------------------
  |  Branch (1073:21): [True: 0, False: 0]
  ------------------
 1074|      0|                    pkio = nssPKIObject_Create(NULL, to, td, NULL, nssPKILock);
 1075|      0|                    status = pkio ? PR_SUCCESS : PR_FAILURE;
  ------------------
  |  Branch (1075:30): [True: 0, False: 0]
  ------------------
 1076|      0|                } else {
 1077|      0|                    status = nssPKIObject_AddInstance(pkio, to);
 1078|      0|                }
 1079|      0|                if (status != PR_SUCCESS) {
  ------------------
  |  Branch (1079:21): [True: 0, False: 0]
  ------------------
 1080|      0|                    nssCryptokiObject_Destroy(to);
 1081|      0|                }
 1082|      0|            }
 1083|  15.5k|            (void)nssToken_Destroy(token);
 1084|  15.5k|        }
 1085|  15.5k|    }
 1086|  7.78k|    if (pkio) {
  ------------------
  |  Branch (1086:9): [True: 0, False: 7.78k]
  ------------------
 1087|      0|        rvt = nssTrust_Create(pkio, &c->encoding);
 1088|      0|        if (rvt) {
  ------------------
  |  Branch (1088:13): [True: 0, False: 0]
  ------------------
 1089|      0|            pkio = NULL; /* rvt object now owns the pkio reference */
 1090|      0|        }
 1091|      0|    }
 1092|  7.78k|    nssSlotArray_Destroy(slots);
 1093|  7.78k|    if (pkio) {
  ------------------
  |  Branch (1093:9): [True: 0, False: 7.78k]
  ------------------
 1094|      0|        nssPKIObject_Destroy(pkio);
 1095|      0|    }
 1096|  7.78k|    return rvt;
 1097|  7.78k|}
nssTrustDomain_CreateCryptoContext:
 1202|      1|{
 1203|      1|    return nssCryptoContext_Create(td, uhhOpt);
 1204|      1|}
NSSTrustDomain_CreateCryptoContext:
 1210|      1|{
 1211|      1|    return nssTrustDomain_CreateCryptoContext(td, uhhOpt);
 1212|      1|}
trustdomain.c:token_destructor:
   63|      2|{
   64|      2|    NSSToken *tok = (NSSToken *)t;
   65|       |    /* Remove the token list's reference to the token */
   66|      2|    (void)nssToken_Destroy(tok);
   67|       |
   68|       |    /* Signal that the slot should not give out any more references to the
   69|       |     * token. The token might still have a positive refcount after this call.
   70|       |     * The token has a reference to the slot, so the slot will not be destroyed
   71|       |     * until after the token's refcount drops to 0. */
   72|      2|    PK11Slot_SetNSSToken(tok->pk11slot, NULL);
   73|      2|}
trustdomain.c:get_certs_from_list:
  406|      1|{
  407|      1|    PRUint32 count = nssList_Count(list);
  408|      1|    NSSCertificate **certs = NULL;
  409|      1|    if (count > 0) {
  ------------------
  |  Branch (409:9): [True: 0, False: 1]
  ------------------
  410|      0|        certs = nss_ZNEWARRAY(NULL, NSSCertificate *, count + 1);
  ------------------
  |  |  371|      0|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
  411|      0|        if (certs) {
  ------------------
  |  Branch (411:13): [True: 0, False: 0]
  ------------------
  412|      0|            nssList_GetArray(list, (void **)certs, count);
  413|      0|        }
  414|      0|    }
  415|      1|    return certs;
  416|      1|}
trustdomain.c:nssTrustDomain_GetActiveSlots:
  112|  11.7k|{
  113|  11.7k|    PRUint32 count;
  114|  11.7k|    NSSSlot **slots = NULL;
  115|  11.7k|    NSSToken **tp, **tokens;
  116|  11.7k|    *updateLevel = 1;
  117|  11.7k|    if (!td->tokenList) {
  ------------------
  |  Branch (117:9): [True: 0, False: 11.7k]
  ------------------
  118|      0|        return NULL;
  119|      0|    }
  120|  11.7k|    NSSRWLock_LockRead(td->tokensLock);
  ------------------
  |  |   47|  11.7k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  ------------------
  121|  11.7k|    count = nssList_Count(td->tokenList);
  122|  11.7k|    tokens = nss_ZNEWARRAY(NULL, NSSToken *, count + 1);
  ------------------
  |  |  371|  11.7k|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
  123|  11.7k|    if (!tokens) {
  ------------------
  |  Branch (123:9): [True: 0, False: 11.7k]
  ------------------
  124|      0|        NSSRWLock_UnlockRead(td->tokensLock);
  ------------------
  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  ------------------
  125|      0|        return NULL;
  126|      0|    }
  127|  11.7k|    slots = nss_ZNEWARRAY(NULL, NSSSlot *, count + 1);
  ------------------
  |  |  371|  11.7k|    ((type *)nss_ZAlloc((arenaOpt), sizeof(type) * (quantity)))
  ------------------
  128|  11.7k|    if (!slots) {
  ------------------
  |  Branch (128:9): [True: 0, False: 11.7k]
  ------------------
  129|      0|        NSSRWLock_UnlockRead(td->tokensLock);
  ------------------
  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  ------------------
  130|      0|        nss_ZFreeIf(tokens);
  131|      0|        return NULL;
  132|      0|    }
  133|  11.7k|    nssList_GetArray(td->tokenList, (void **)tokens, count);
  134|  11.7k|    count = 0;
  135|  35.1k|    for (tp = tokens; *tp; tp++) {
  ------------------
  |  Branch (135:23): [True: 23.4k, False: 11.7k]
  ------------------
  136|  23.4k|        NSSSlot *slot = nssToken_GetSlot(*tp);
  137|  23.4k|        if (!PK11_IsDisabled(slot->pk11slot)) {
  ------------------
  |  Branch (137:13): [True: 23.4k, False: 0]
  ------------------
  138|  23.4k|            slots[count++] = slot;
  139|  23.4k|        } else {
  140|      0|            nssSlot_Destroy(slot);
  141|      0|        }
  142|  23.4k|    }
  143|  11.7k|    NSSRWLock_UnlockRead(td->tokensLock);
  ------------------
  |  |   50|  11.7k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  ------------------
  144|  11.7k|    nss_ZFreeIf(tokens);
  145|  11.7k|    if (!count) {
  ------------------
  |  Branch (145:9): [True: 0, False: 11.7k]
  ------------------
  146|      0|        nss_ZFreeIf(slots);
  147|      0|        slots = NULL;
  148|      0|    }
  149|  11.7k|    return slots;
  150|  11.7k|}
trustdomain.c:nssTrustDomain_GetSessionForToken:
  157|  7.87k|{
  158|  7.87k|    return nssToken_GetDefaultSession(token);
  159|  7.87k|}

sftk_kyber_PK11ParamToInternal:
   16|     99|{
   17|     99|    switch (pk11ParamSet) {
   18|      0|        case CKP_NSS_KYBER_768_ROUND3:
  ------------------
  |  |  301|      0|#define CKP_NSS_KYBER_768_ROUND3 (CKP_NSS + 1)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (18:9): [True: 0, False: 99]
  ------------------
   19|      0|            return params_kyber768_round3;
   20|     99|        case CKP_NSS_ML_KEM_768:
  ------------------
  |  |  302|     99|#define CKP_NSS_ML_KEM_768 (CKP_NSS + 2)
  |  |  ------------------
  |  |  |  |  300|     99|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (20:9): [True: 99, False: 0]
  ------------------
   21|     99|            return params_ml_kem768;
   22|      0|        default:
  ------------------
  |  Branch (22:9): [True: 0, False: 99]
  ------------------
   23|      0|            return params_kyber_invalid;
   24|     99|    }
   25|     99|}
NSC_Encapsulate:
  134|     99|{
  135|     99|    SFTKSession *session = NULL;
  136|     99|    SFTKSlot *slot = NULL;
  137|       |
  138|     99|    SFTKObject *key = NULL;
  139|       |
  140|     99|    SFTKObject *encapsulationKeyObject = NULL;
  141|     99|    SFTKAttribute *encapsulationKey = NULL;
  142|       |
  143|     99|    CK_RV crv;
  144|     99|    SFTKFreeStatus status;
  145|       |
  146|     99|    CHECK_FORK();
  147|       |
  148|     99|    if (!pMechanism || !phKey || !pulCiphertextLen) {
  ------------------
  |  Branch (148:9): [True: 0, False: 99]
  |  Branch (148:24): [True: 0, False: 99]
  |  Branch (148:34): [True: 0, False: 99]
  ------------------
  149|      0|        return CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
  150|      0|    }
  151|       |
  152|     99|    if (!sftk_kem_ValidateMechanism(pMechanism)) {
  ------------------
  |  Branch (152:9): [True: 0, False: 99]
  ------------------
  153|      0|        return CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
  154|      0|    }
  155|       |
  156|     99|    CK_ULONG ciphertextLen = sftk_kem_CiphertextLen(pMechanism);
  157|     99|    if (!pCiphertext || *pulCiphertextLen < ciphertextLen) {
  ------------------
  |  Branch (157:9): [True: 0, False: 99]
  |  Branch (157:25): [True: 0, False: 99]
  ------------------
  158|      0|        *pulCiphertextLen = ciphertextLen;
  159|      0|        return CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
  160|      0|    }
  161|     99|    *phKey = CK_INVALID_HANDLE;
  ------------------
  |  |   78|     99|#define CK_INVALID_HANDLE 0
  ------------------
  162|       |
  163|     99|    session = sftk_SessionFromHandle(hSession);
  164|     99|    if (session == NULL) {
  ------------------
  |  Branch (164:9): [True: 0, False: 99]
  ------------------
  165|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  166|      0|    }
  167|     99|    slot = sftk_SlotFromSessionHandle(hSession);
  168|     99|    if (slot == NULL) {
  ------------------
  |  Branch (168:9): [True: 0, False: 99]
  ------------------
  169|      0|        crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  170|      0|        goto cleanup;
  171|      0|    }
  172|       |
  173|     99|    key = sftk_NewObject(slot);
  174|     99|    if (key == NULL) {
  ------------------
  |  Branch (174:9): [True: 0, False: 99]
  ------------------
  175|      0|        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  176|      0|        goto cleanup;
  177|      0|    }
  178|    693|    for (unsigned long int i = 0; i < ulAttributeCount; i++) {
  ------------------
  |  Branch (178:35): [True: 594, False: 99]
  ------------------
  179|    594|        crv = sftk_AddAttributeType(key, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|    594|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
  180|    594|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|    594|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (180:13): [True: 0, False: 594]
  ------------------
  181|      0|            goto cleanup;
  182|      0|        }
  183|    594|    }
  184|       |
  185|     99|    encapsulationKeyObject = sftk_ObjectFromHandle(hPublicKey, session);
  186|     99|    if (encapsulationKeyObject == NULL) {
  ------------------
  |  Branch (186:9): [True: 0, False: 99]
  ------------------
  187|      0|        crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  188|      0|        goto cleanup;
  189|      0|    }
  190|     99|    encapsulationKey = sftk_FindAttribute(encapsulationKeyObject, CKA_VALUE);
  ------------------
  |  |  516|     99|#define CKA_VALUE 0x00000011UL
  ------------------
  191|     99|    if (encapsulationKey == NULL) {
  ------------------
  |  Branch (191:9): [True: 0, False: 99]
  ------------------
  192|      0|        crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  193|      0|        goto cleanup;
  194|      0|    }
  195|       |
  196|     99|    SECItem ciphertext = { siBuffer, pCiphertext, ciphertextLen };
  197|     99|    SECItem pubKey = { siBuffer, encapsulationKey->attrib.pValue, encapsulationKey->attrib.ulValueLen };
  198|       |
  199|       |    /* The length of secretBuf can be increased if we ever support other KEMs */
  200|     99|    uint8_t secretBuf[KYBER_SHARED_SECRET_BYTES] = { 0 };
  201|     99|    SECItem secret = { siBuffer, secretBuf, sizeof secretBuf };
  202|       |
  203|     99|    switch (pMechanism->mechanism) {
  204|      0|        case CKM_NSS_KYBER:
  ------------------
  |  |  268|      0|#define CKM_NSS_KYBER (CKM_NSS + 46)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (204:9): [True: 0, False: 99]
  ------------------
  205|     99|        case CKM_NSS_ML_KEM:
  ------------------
  |  |  278|     99|#define CKM_NSS_ML_KEM (CKM_NSS + 49)
  |  |  ------------------
  |  |  |  |  162|     99|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (205:9): [True: 99, False: 0]
  ------------------
  206|     99|            PORT_Assert(secret.len == KYBER_SHARED_SECRET_BYTES);
  ------------------
  |  |  120|     99|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     99|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 99, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  207|     99|            CK_NSS_KEM_PARAMETER_SET_TYPE *pParameter = pMechanism->pParameter;
  208|     99|            KyberParams kyberParams = sftk_kyber_PK11ParamToInternal(*pParameter);
  209|     99|            SECStatus rv = Kyber_Encapsulate(kyberParams, /* seed */ NULL, &pubKey, &ciphertext, &secret);
  210|     99|            if (rv != SECSuccess) {
  ------------------
  |  Branch (210:17): [True: 16, False: 83]
  ------------------
  211|     16|                crv = (PORT_GetError() == SEC_ERROR_INVALID_ARGS) ? CKR_ARGUMENTS_BAD : CKR_FUNCTION_FAILED;
  ------------------
  |  |   62|     16|#define PORT_GetError PORT_GetError_Util
  ------------------
                              crv = (PORT_GetError() == SEC_ERROR_INVALID_ARGS) ? CKR_ARGUMENTS_BAD : CKR_FUNCTION_FAILED;
  ------------------
  |  | 1401|     16|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
                              crv = (PORT_GetError() == SEC_ERROR_INVALID_ARGS) ? CKR_ARGUMENTS_BAD : CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|     16|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
  |  Branch (211:23): [True: 16, False: 0]
  ------------------
  212|     16|                goto cleanup;
  213|     16|            }
  214|       |
  215|     83|            crv = sftk_forceAttribute(key, CKA_VALUE, sftk_item_expand(&secret));
  ------------------
  |  |  516|     83|#define CKA_VALUE 0x00000011UL
  ------------------
                          crv = sftk_forceAttribute(key, CKA_VALUE, sftk_item_expand(&secret));
  ------------------
  |  |  588|     83|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
  216|     83|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|     83|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (216:17): [True: 0, False: 83]
  ------------------
  217|      0|                goto cleanup;
  218|      0|            }
  219|       |
  220|     83|            crv = sftk_handleObject(key, session);
  221|     83|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|     83|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (221:17): [True: 0, False: 83]
  ------------------
  222|      0|                goto cleanup;
  223|      0|            }
  224|       |
  225|       |            /* We wrote the ciphertext out directly in Kyber_Encapsulate */
  226|     83|            *phKey = key->handle;
  227|     83|            *pulCiphertextLen = ciphertext.len;
  228|     83|            break;
  229|      0|        default:
  ------------------
  |  Branch (229:9): [True: 0, False: 99]
  ------------------
  230|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
  231|      0|            goto cleanup;
  232|     99|    }
  233|       |
  234|     99|cleanup:
  235|     99|    if (session) {
  ------------------
  |  Branch (235:9): [True: 99, False: 0]
  ------------------
  236|     99|        sftk_FreeSession(session);
  237|     99|    }
  238|     99|    if (key) {
  ------------------
  |  Branch (238:9): [True: 99, False: 0]
  ------------------
  239|     99|        status = sftk_FreeObject(key);
  240|     99|        if (status == SFTK_DestroyFailure) {
  ------------------
  |  Branch (240:13): [True: 0, False: 99]
  ------------------
  241|      0|            return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  242|      0|        }
  243|     99|    }
  244|     99|    if (encapsulationKeyObject) {
  ------------------
  |  Branch (244:9): [True: 99, False: 0]
  ------------------
  245|     99|        status = sftk_FreeObject(encapsulationKeyObject);
  246|     99|        if (status == SFTK_DestroyFailure) {
  ------------------
  |  Branch (246:13): [True: 0, False: 99]
  ------------------
  247|      0|            return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  248|      0|        }
  249|     99|    }
  250|     99|    if (encapsulationKey) {
  ------------------
  |  Branch (250:9): [True: 99, False: 0]
  ------------------
  251|     99|        sftk_FreeAttribute(encapsulationKey);
  252|     99|    }
  253|     99|    return crv;
  254|     99|}
kem.c:sftk_kem_ValidateMechanism:
   86|    198|{
   87|    198|    if (!pMechanism) {
  ------------------
  |  Branch (87:9): [True: 0, False: 198]
  ------------------
   88|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   89|      0|    }
   90|    198|    switch (pMechanism->mechanism) {
   91|      0|        case CKM_NSS_KYBER:
  ------------------
  |  |  268|      0|#define CKM_NSS_KYBER (CKM_NSS + 46)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (91:9): [True: 0, False: 198]
  ------------------
   92|    198|        case CKM_NSS_ML_KEM:
  ------------------
  |  |  278|    198|#define CKM_NSS_ML_KEM (CKM_NSS + 49)
  |  |  ------------------
  |  |  |  |  162|    198|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|    198|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    198|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (92:9): [True: 198, False: 0]
  ------------------
   93|    198|            return pMechanism->ulParameterLen == sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE) && sftk_kyber_ValidateParams(pMechanism->pParameter);
  ------------------
  |  Branch (93:20): [True: 198, False: 0]
  |  Branch (93:91): [True: 198, False: 0]
  ------------------
   94|      0|        default:
  ------------------
  |  Branch (94:9): [True: 0, False: 198]
  ------------------
   95|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   96|    198|    }
   97|    198|}
kem.c:sftk_kyber_ValidateParams:
   71|    198|{
   72|    198|    if (!params) {
  ------------------
  |  Branch (72:9): [True: 0, False: 198]
  ------------------
   73|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   74|      0|    }
   75|    198|    switch (*params) {
   76|      0|        case CKP_NSS_KYBER_768_ROUND3:
  ------------------
  |  |  301|      0|#define CKP_NSS_KYBER_768_ROUND3 (CKP_NSS + 1)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (76:9): [True: 0, False: 198]
  ------------------
   77|    198|        case CKP_NSS_ML_KEM_768:
  ------------------
  |  |  302|    198|#define CKP_NSS_ML_KEM_768 (CKP_NSS + 2)
  |  |  ------------------
  |  |  |  |  300|    198|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|    198|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|    198|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (77:9): [True: 198, False: 0]
  ------------------
   78|    198|            return PR_TRUE;
  ------------------
  |  |  437|    198|#define PR_TRUE 1
  ------------------
   79|      0|        default:
  ------------------
  |  Branch (79:9): [True: 0, False: 198]
  ------------------
   80|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   81|    198|    }
   82|    198|}
kem.c:sftk_kem_CiphertextLen:
  101|     99|{
  102|     99|#ifdef DEBUG
  103|     99|    if (!sftk_kem_ValidateMechanism(pMechanism)) {
  ------------------
  |  Branch (103:9): [True: 0, False: 99]
  ------------------
  104|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  105|      0|        return 0;
  106|      0|    }
  107|     99|#endif
  108|       |
  109|       |    /* Assumes pMechanism has been validated with sftk_kem_ValidateMechanism */
  110|     99|    CK_NSS_KEM_PARAMETER_SET_TYPE *pParameterSet = pMechanism->pParameter;
  111|     99|    switch (*pParameterSet) {
  112|      0|        case CKP_NSS_KYBER_768_ROUND3:
  ------------------
  |  |  301|      0|#define CKP_NSS_KYBER_768_ROUND3 (CKP_NSS + 1)
  |  |  ------------------
  |  |  |  |  300|      0|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (112:9): [True: 0, False: 99]
  ------------------
  113|     99|        case CKP_NSS_ML_KEM_768:
  ------------------
  |  |  302|     99|#define CKP_NSS_ML_KEM_768 (CKP_NSS + 2)
  |  |  ------------------
  |  |  |  |  300|     99|#define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKP_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (113:9): [True: 99, False: 0]
  ------------------
  114|     99|            return KYBER768_CIPHERTEXT_BYTES;
  ------------------
  |  |   10|     99|#define KYBER768_CIPHERTEXT_BYTES 1088U
  ------------------
  115|      0|        default:
  ------------------
  |  Branch (115:9): [True: 0, False: 99]
  ------------------
  116|       |            /* unreachable if pMechanism has been validated */
  117|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  118|      0|            return 0;
  119|     99|    }
  120|     99|}

nsslowkey_DestroyPrivateKey:
  214|  47.3k|{
  215|  47.3k|    if (privk && privk->arena) {
  ------------------
  |  Branch (215:9): [True: 47.3k, False: 0]
  |  Branch (215:18): [True: 47.3k, False: 0]
  ------------------
  216|  47.3k|        PORT_FreeArena(privk->arena, PR_TRUE);
  ------------------
  |  |   61|  47.3k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(privk->arena, PR_TRUE);
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
  217|  47.3k|    }
  218|  47.3k|}
nsslowkey_DestroyPublicKey:
  222|  50.4k|{
  223|  50.4k|    if (pubk && pubk->arena) {
  ------------------
  |  Branch (223:9): [True: 50.4k, False: 0]
  |  Branch (223:17): [True: 50.4k, False: 0]
  ------------------
  224|  50.4k|        PORT_FreeArena(pubk->arena, PR_TRUE);
  ------------------
  |  |   61|  50.4k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(pubk->arena, PR_TRUE);
  ------------------
  |  |  437|  50.4k|#define PR_TRUE 1
  ------------------
  225|  50.4k|    }
  226|  50.4k|}
nsslowkey_PublicModulusLen:
  229|      3|{
  230|       |    /* interpret modulus length as key strength... in
  231|       |     * fortezza that's the public key length */
  232|       |
  233|      3|    switch (pubk->keyType) {
  234|      3|        case NSSLOWKEYRSAKey:
  ------------------
  |  Branch (234:9): [True: 3, False: 0]
  ------------------
  235|      3|            if (pubk->u.rsa.modulus.len == 0) {
  ------------------
  |  Branch (235:17): [True: 0, False: 3]
  ------------------
  236|      0|                return 0;
  237|      0|            }
  238|      3|            if (pubk->u.rsa.modulus.data[0] == 0) {
  ------------------
  |  Branch (238:17): [True: 0, False: 3]
  ------------------
  239|      0|                return pubk->u.rsa.modulus.len - 1;
  240|      0|            }
  241|      3|            return pubk->u.rsa.modulus.len;
  242|      0|        default:
  ------------------
  |  Branch (242:9): [True: 0, False: 3]
  ------------------
  243|      0|            break;
  244|      3|    }
  245|      0|    return 0;
  246|      3|}
nsslowkey_PrivateModulusLen:
  250|  58.7k|{
  251|  58.7k|    switch (privk->keyType) {
  252|  58.7k|        case NSSLOWKEYRSAKey:
  ------------------
  |  Branch (252:9): [True: 58.7k, False: 0]
  ------------------
  253|  58.7k|            if (privk->u.rsa.modulus.len == 0) {
  ------------------
  |  Branch (253:17): [True: 0, False: 58.7k]
  ------------------
  254|      0|                return 0;
  255|      0|            }
  256|  58.7k|            if (privk->u.rsa.modulus.data[0] == 0) {
  ------------------
  |  Branch (256:17): [True: 0, False: 58.7k]
  ------------------
  257|      0|                return privk->u.rsa.modulus.len - 1;
  258|      0|            }
  259|  58.7k|            return privk->u.rsa.modulus.len;
  260|      0|        default:
  ------------------
  |  Branch (260:9): [True: 0, False: 58.7k]
  ------------------
  261|      0|            break;
  262|  58.7k|    }
  263|      0|    return 0;
  264|  58.7k|}

sftk_PBELockInit:
  585|      1|{
  586|      1|    if (!PBECache.lock) {
  ------------------
  |  Branch (586:9): [True: 1, False: 0]
  ------------------
  587|      1|        PBECache.lock = PZ_NewLock(nssIPBECacheLock);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  588|      1|    }
  589|      1|}
sftk_PBELockShutdown:
  716|      1|{
  717|      1|    int i;
  718|      1|    if (PBECache.lock) {
  ------------------
  |  Branch (718:9): [True: 1, False: 0]
  ------------------
  719|      1|        PZ_DestroyLock(PBECache.lock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  720|      1|        PBECache.lock = 0;
  721|      1|    }
  722|      1|    sftk_clearPBECommonCacheItemsLocked(&PBECache.cacheKDF1.common);
  723|    151|    for (i = 0; i < KDF2_CACHE_COUNT; i++) {
  ------------------
  |  |  569|    151|#define KDF2_CACHE_COUNT 150
  ------------------
  |  Branch (723:17): [True: 150, False: 1]
  ------------------
  724|    150|        sftk_clearPBECommonCacheItemsLocked(&PBECache.cacheKDF2.common[i]);
  725|    150|    }
  726|      1|    PBECache.cacheKDF2.next = 0;
  727|      1|}
lowpbe.c:sftk_clearPBECommonCacheItemsLocked:
  593|    151|{
  594|    151|    if (item->hash) {
  ------------------
  |  Branch (594:9): [True: 0, False: 151]
  ------------------
  595|      0|        SECITEM_ZfreeItem(item->hash, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(item->hash, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  596|      0|        item->hash = NULL;
  597|      0|    }
  598|    151|    if (item->salt) {
  ------------------
  |  Branch (598:9): [True: 0, False: 151]
  ------------------
  599|      0|        SECITEM_ZfreeItem(item->salt, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(item->salt, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  600|      0|        item->salt = NULL;
  601|      0|    }
  602|    151|    if (item->pwItem) {
  ------------------
  |  Branch (602:9): [True: 0, False: 151]
  ------------------
  603|      0|        SECITEM_ZfreeItem(item->pwItem, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(item->pwItem, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  604|      0|        item->pwItem = NULL;
  605|      0|    }
  606|    151|}

SFTKFree_nsslowkey_DestroyPublicKey:
  678|  50.4k|    {                              \
  679|  50.4k|        ctxtype *p = vp;           \
  680|  50.4k|        mmm(p);                    \
  681|  50.4k|    }
SFTKFree_nsslowkey_DestroyPrivateKey:
  678|  47.3k|    {                              \
  679|  47.3k|        ctxtype *p = vp;           \
  680|  47.3k|        mmm(p);                    \
  681|  47.3k|    }
sftk_defaultAttribute:
  793|  18.9M|{
  794|  18.9M|    if (!sftk_hasAttribute(object, type)) {
  ------------------
  |  Branch (794:9): [True: 14.4M, False: 4.52M]
  ------------------
  795|  14.4M|        return sftk_AddAttributeType(object, type, value, len);
  796|  14.4M|    }
  797|  4.52M|    return CKR_OK;
  ------------------
  |  | 1388|  4.52M|#define CKR_OK 0x00000000UL
  ------------------
  798|  18.9M|}
sftk_handleObject:
 1756|  1.28M|{
 1757|  1.28M|    SFTKSlot *slot = session->slot;
 1758|  1.28M|    SFTKAttribute *attribute;
 1759|  1.28M|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  1.28M|#define CK_FALSE 0
  ------------------
 1760|  1.28M|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  1.28M|#define CK_TRUE 1
  ------------------
 1761|  1.28M|    PRBool isLoggedIn, needLogin;
 1762|  1.28M|    CK_RV crv;
 1763|       |
 1764|       |    /* make sure all the base object types are defined. If not set the
 1765|       |     * defaults */
 1766|  1.28M|    crv = sftk_defaultAttribute(object, CKA_TOKEN, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  512|  1.28M|#define CKA_TOKEN 0x00000001UL
  ------------------
 1767|  1.28M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1767:9): [True: 0, False: 1.28M]
  ------------------
 1768|      0|        return crv;
 1769|  1.28M|    crv = sftk_defaultAttribute(object, CKA_PRIVATE, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  513|  1.28M|#define CKA_PRIVATE 0x00000002UL
  ------------------
 1770|  1.28M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1770:9): [True: 0, False: 1.28M]
  ------------------
 1771|      0|        return crv;
 1772|  1.28M|    crv = sftk_defaultAttribute(object, CKA_LABEL, NULL, 0);
  ------------------
  |  |  514|  1.28M|#define CKA_LABEL 0x00000003UL
  ------------------
 1773|  1.28M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1773:9): [True: 0, False: 1.28M]
  ------------------
 1774|      0|        return crv;
 1775|  1.28M|    crv = sftk_defaultAttribute(object, CKA_MODIFIABLE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  593|  1.28M|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
 1776|  1.28M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1776:9): [True: 0, False: 1.28M]
  ------------------
 1777|      0|        return crv;
 1778|       |
 1779|  1.28M|    PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|  1.28M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1780|  1.28M|    isLoggedIn = slot->isLoggedIn;
 1781|  1.28M|    needLogin = slot->needLogin;
 1782|  1.28M|    PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|  1.28M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1783|       |
 1784|       |    /* don't create a private object if we aren't logged in */
 1785|  1.28M|    if (!isLoggedIn && needLogin && sftk_isTrue(object, CKA_PRIVATE)) {
  ------------------
  |  |  513|      0|#define CKA_PRIVATE 0x00000002UL
  ------------------
  |  Branch (1785:9): [True: 1.28M, False: 0]
  |  Branch (1785:24): [True: 0, False: 1.28M]
  |  Branch (1785:37): [True: 0, False: 0]
  ------------------
 1786|      0|        return CKR_USER_NOT_LOGGED_IN;
  ------------------
  |  | 1486|      0|#define CKR_USER_NOT_LOGGED_IN 0x00000101UL
  ------------------
 1787|      0|    }
 1788|       |
 1789|  1.28M|    if (((session->info.flags & CKF_RW_SESSION) == 0) &&
  ------------------
  |  |  302|  1.28M|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (1789:9): [True: 1.28M, False: 0]
  ------------------
 1790|  1.28M|        (sftk_isTrue(object, CKA_TOKEN))) {
  ------------------
  |  |  512|  1.28M|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (1790:9): [True: 0, False: 1.28M]
  ------------------
 1791|      0|        return CKR_SESSION_READ_ONLY;
  ------------------
  |  | 1467|      0|#define CKR_SESSION_READ_ONLY 0x000000B5UL
  ------------------
 1792|      0|    }
 1793|       |
 1794|       |    /* Assign a unique SESSION object handle to every new object,
 1795|       |     * whether it is a session object or a token object.
 1796|       |     * At this point, all new objects are structured as session objects.
 1797|       |     * Objects with the CKA_TOKEN attribute true will be turned into
 1798|       |     * token objects and will have a token object handle assigned to
 1799|       |     * them by a call to sftk_mkHandle in the handler for each object
 1800|       |     * class, invoked below.
 1801|       |     *
 1802|       |     * It may be helpful to note/remember that
 1803|       |     * sftk_narrowToXxxObject uses sftk_isToken,
 1804|       |     * sftk_isToken examines the sign bit of the object's handle, but
 1805|       |     * sftk_isTrue(...,CKA_TOKEN) examines the CKA_TOKEN attribute.
 1806|       |     */
 1807|  1.28M|    object->handle = sftk_getNextHandle(slot);
 1808|       |
 1809|       |    /* get the object class */
 1810|  1.28M|    attribute = sftk_FindAttribute(object, CKA_CLASS);
  ------------------
  |  |  511|  1.28M|#define CKA_CLASS 0x00000000UL
  ------------------
 1811|  1.28M|    if (attribute == NULL) {
  ------------------
  |  Branch (1811:9): [True: 0, False: 1.28M]
  ------------------
 1812|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1813|      0|    }
 1814|  1.28M|    object->objclass = *(CK_OBJECT_CLASS *)attribute->attrib.pValue;
 1815|  1.28M|    sftk_FreeAttribute(attribute);
 1816|       |
 1817|       |    /* Now handle the specific object class.
 1818|       |     * At this point, all objects are session objects, and the session
 1819|       |     * number must be passed to the object class handlers.
 1820|       |     */
 1821|  1.28M|    switch (object->objclass) {
 1822|   281k|        case CKO_DATA:
  ------------------
  |  |  325|   281k|#define CKO_DATA 0x00000000UL
  ------------------
  |  Branch (1822:9): [True: 281k, False: 1.00M]
  ------------------
 1823|   281k|            crv = sftk_handleDataObject(session, object);
 1824|   281k|            break;
 1825|      0|        case CKO_CERTIFICATE:
  ------------------
  |  |  326|      0|#define CKO_CERTIFICATE 0x00000001UL
  ------------------
  |  Branch (1825:9): [True: 0, False: 1.28M]
  ------------------
 1826|      0|            crv = sftk_handleCertObject(session, object);
 1827|      0|            break;
 1828|      0|        case CKO_NSS_TRUST:
  ------------------
  |  |   37|      0|#define CKO_NSS_TRUST (CKO_NSS + 3)
  |  |  ------------------
  |  |  |  |   33|      0|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|      0|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1828:9): [True: 0, False: 1.28M]
  ------------------
 1829|      0|            crv = sftk_handleTrustObject(session, object);
 1830|      0|            break;
 1831|      0|        case CKO_NSS_CRL:
  ------------------
  |  |   35|      0|#define CKO_NSS_CRL (CKO_NSS + 1)
  |  |  ------------------
  |  |  |  |   33|      0|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|      0|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1831:9): [True: 0, False: 1.28M]
  ------------------
 1832|      0|            crv = sftk_handleCrlObject(session, object);
 1833|      0|            break;
 1834|      0|        case CKO_NSS_SMIME:
  ------------------
  |  |   36|      0|#define CKO_NSS_SMIME (CKO_NSS + 2)
  |  |  ------------------
  |  |  |  |   33|      0|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|      0|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1834:9): [True: 0, False: 1.28M]
  ------------------
 1835|      0|            crv = sftk_handleSMimeObject(session, object);
 1836|      0|            break;
 1837|  47.3k|        case CKO_PRIVATE_KEY:
  ------------------
  |  |  328|  47.3k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (1837:9): [True: 47.3k, False: 1.24M]
  ------------------
 1838|  97.7k|        case CKO_PUBLIC_KEY:
  ------------------
  |  |  327|  97.7k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  |  Branch (1838:9): [True: 50.4k, False: 1.23M]
  ------------------
 1839|  1.00M|        case CKO_SECRET_KEY:
  ------------------
  |  |  329|  1.00M|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  |  Branch (1839:9): [True: 909k, False: 378k]
  ------------------
 1840|  1.00M|            crv = sftk_handleKeyObject(session, object);
 1841|  1.00M|            break;
 1842|      0|        case CKO_DOMAIN_PARAMETERS:
  ------------------
  |  |  331|      0|#define CKO_DOMAIN_PARAMETERS 0x00000006UL
  ------------------
  |  Branch (1842:9): [True: 0, False: 1.28M]
  ------------------
 1843|      0|            crv = sftk_handleKeyParameterObject(session, object);
 1844|      0|            break;
 1845|      0|        default:
  ------------------
  |  Branch (1845:9): [True: 0, False: 1.28M]
  ------------------
 1846|      0|            crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 1847|      0|            break;
 1848|  1.28M|    }
 1849|       |
 1850|       |    /* can't fail from here on out unless the pk_handlXXX functions have
 1851|       |     * failed the request */
 1852|  1.28M|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1852:9): [True: 0, False: 1.28M]
  ------------------
 1853|      0|        return crv;
 1854|      0|    }
 1855|       |
 1856|       |    /* Now link the object into the slot and session structures.
 1857|       |     * If the object has a true CKA_TOKEN attribute, the above object
 1858|       |     * class handlers will have set the sign bit in the object handle,
 1859|       |     * causing the following test to be true.
 1860|       |     */
 1861|  1.28M|    if (sftk_isToken(object->handle)) {
  ------------------
  |  |  504|  1.28M|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|  1.28M|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|  1.28M|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  |  |  |  Branch (504:26): [True: 0, False: 1.28M]
  |  |  ------------------
  ------------------
 1862|      0|        sftk_convertSessionToToken(object);
 1863|  1.28M|    } else {
 1864|  1.28M|        object->slot = slot;
 1865|  1.28M|        sftk_AddObject(session, object);
 1866|  1.28M|    }
 1867|       |
 1868|  1.28M|    return CKR_OK;
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
 1869|  1.28M|}
sftk_GetPubKey:
 1878|  53.4k|{
 1879|  53.4k|    NSSLOWKEYPublicKey *pubKey;
 1880|  53.4k|    PLArenaPool *arena;
 1881|  53.4k|    CK_RV crv;
 1882|       |
 1883|  53.4k|    if (object->objclass != CKO_PUBLIC_KEY) {
  ------------------
  |  |  327|  53.4k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  |  Branch (1883:9): [True: 0, False: 53.4k]
  ------------------
 1884|      0|        *crvp = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1885|      0|        return NULL;
 1886|      0|    }
 1887|       |
 1888|  53.4k|    if (sftk_isToken(object->handle)) {
  ------------------
  |  |  504|  53.4k|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|  53.4k|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|  53.4k|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  |  |  |  Branch (504:26): [True: 0, False: 53.4k]
  |  |  ------------------
  ------------------
 1889|       |        /* ferret out the token object handle */
 1890|      0|    }
 1891|       |
 1892|       |    /* If we already have a key, use it */
 1893|  53.4k|    if (object->objectInfo) {
  ------------------
  |  Branch (1893:9): [True: 3.01k, False: 50.4k]
  ------------------
 1894|  3.01k|        *crvp = CKR_OK;
  ------------------
  |  | 1388|  3.01k|#define CKR_OK 0x00000000UL
  ------------------
 1895|  3.01k|        return (NSSLOWKEYPublicKey *)object->objectInfo;
 1896|  3.01k|    }
 1897|       |
 1898|       |    /* allocate the structure */
 1899|  50.4k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  50.4k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  50.4k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 1900|  50.4k|    if (arena == NULL) {
  ------------------
  |  Branch (1900:9): [True: 0, False: 50.4k]
  ------------------
 1901|      0|        *crvp = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1902|      0|        return NULL;
 1903|      0|    }
 1904|       |
 1905|  50.4k|    pubKey = (NSSLOWKEYPublicKey *)
 1906|  50.4k|        PORT_ArenaAlloc(arena, sizeof(NSSLOWKEYPublicKey));
  ------------------
  |  |   53|  50.4k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1907|  50.4k|    if (pubKey == NULL) {
  ------------------
  |  Branch (1907:9): [True: 0, False: 50.4k]
  ------------------
 1908|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1909|      0|        *crvp = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1910|      0|        return NULL;
 1911|      0|    }
 1912|       |
 1913|       |    /* fill in the structure */
 1914|  50.4k|    pubKey->arena = arena;
 1915|  50.4k|    switch (key_type) {
 1916|  3.01k|        case CKK_RSA:
  ------------------
  |  |  372|  3.01k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (1916:9): [True: 3.01k, False: 47.4k]
  ------------------
 1917|  3.01k|            pubKey->keyType = NSSLOWKEYRSAKey;
 1918|  3.01k|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.rsa.modulus,
 1919|  3.01k|                                          object, CKA_MODULUS);
  ------------------
  |  |  558|  3.01k|#define CKA_MODULUS 0x00000120UL
  ------------------
 1920|  3.01k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  3.01k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1920:17): [True: 0, False: 3.01k]
  ------------------
 1921|      0|                break;
 1922|  3.01k|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.rsa.publicExponent,
 1923|  3.01k|                                          object, CKA_PUBLIC_EXPONENT);
  ------------------
  |  |  560|  3.01k|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 1924|  3.01k|            break;
 1925|      0|        case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (1925:9): [True: 0, False: 50.4k]
  ------------------
 1926|      0|            pubKey->keyType = NSSLOWKEYDSAKey;
 1927|      0|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dsa.params.prime,
 1928|      0|                                          object, CKA_PRIME);
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 1929|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1929:17): [True: 0, False: 0]
  ------------------
 1930|      0|                break;
 1931|      0|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dsa.params.subPrime,
 1932|      0|                                          object, CKA_SUBPRIME);
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 1933|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1933:17): [True: 0, False: 0]
  ------------------
 1934|      0|                break;
 1935|      0|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dsa.params.base,
 1936|      0|                                          object, CKA_BASE);
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
 1937|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1937:17): [True: 0, False: 0]
  ------------------
 1938|      0|                break;
 1939|      0|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dsa.publicValue,
 1940|      0|                                          object, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 1941|      0|            break;
 1942|  29.0k|        case CKK_DH:
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (1942:9): [True: 29.0k, False: 21.3k]
  ------------------
 1943|  29.0k|            pubKey->keyType = NSSLOWKEYDHKey;
 1944|  29.0k|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dh.prime,
 1945|  29.0k|                                          object, CKA_PRIME);
  ------------------
  |  |  569|  29.0k|#define CKA_PRIME 0x00000130UL
  ------------------
 1946|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1946:17): [True: 0, False: 29.0k]
  ------------------
 1947|      0|                break;
 1948|  29.0k|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dh.base,
 1949|  29.0k|                                          object, CKA_BASE);
  ------------------
  |  |  571|  29.0k|#define CKA_BASE 0x00000132UL
  ------------------
 1950|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1950:17): [True: 0, False: 29.0k]
  ------------------
 1951|      0|                break;
 1952|  29.0k|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.dh.publicValue,
 1953|  29.0k|                                          object, CKA_VALUE);
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
 1954|  29.0k|            break;
 1955|      0|        case CKK_EC_EDWARDS:
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (1955:9): [True: 0, False: 50.4k]
  ------------------
 1956|      0|        case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (1956:9): [True: 0, False: 50.4k]
  ------------------
 1957|  18.2k|        case CKK_EC:
  ------------------
  |  |  379|  18.2k|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (1957:9): [True: 18.2k, False: 32.1k]
  ------------------
 1958|  18.2k|            pubKey->keyType = NSSLOWKEYECKey;
 1959|  18.2k|            crv = sftk_Attribute2SSecItem(arena,
 1960|  18.2k|                                          &pubKey->u.ec.ecParams.DEREncoding,
 1961|  18.2k|                                          object, CKA_EC_PARAMS);
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 1962|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1962:17): [True: 0, False: 18.2k]
  ------------------
 1963|      0|                break;
 1964|       |
 1965|       |            /* Fill out the rest of the ecParams structure
 1966|       |             * based on the encoded params
 1967|       |             */
 1968|  18.2k|            if (EC_FillParams(arena, &pubKey->u.ec.ecParams.DEREncoding,
  ------------------
  |  Branch (1968:17): [True: 0, False: 18.2k]
  ------------------
 1969|  18.2k|                              &pubKey->u.ec.ecParams) != SECSuccess) {
 1970|      0|                crv = CKR_DOMAIN_PARAMS_INVALID;
  ------------------
  |  | 1508|      0|#define CKR_DOMAIN_PARAMS_INVALID 0x00000130UL
  ------------------
 1971|      0|                break;
 1972|      0|            }
 1973|       |
 1974|  18.2k|            crv = sftk_Attribute2SSecItem(arena, &pubKey->u.ec.publicValue,
 1975|  18.2k|                                          object, CKA_EC_POINT);
  ------------------
  |  |  604|  18.2k|#define CKA_EC_POINT 0x00000181UL
  ------------------
 1976|  18.2k|            if (crv == CKR_OK) {
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1976:17): [True: 18.2k, False: 0]
  ------------------
 1977|  18.2k|                unsigned int keyLen = EC_GetPointSize(&pubKey->u.ec.ecParams);
 1978|       |
 1979|       |                /* special note: We can't just use the first byte to distinguish
 1980|       |                 * between EC_POINT_FORM_UNCOMPRESSED and SEC_ASN1_OCTET_STRING.
 1981|       |                 * Both are 0x04. */
 1982|       |
 1983|       |                /* Handle the non-DER encoded case.
 1984|       |                 * Some curves are always pressumed to be non-DER.
 1985|       |                 */
 1986|  18.2k|                if (pubKey->u.ec.ecParams.type != ec_params_named ||
  ------------------
  |  Branch (1986:21): [True: 7.42k, False: 10.8k]
  ------------------
 1987|  18.2k|                    (pubKey->u.ec.publicValue.len == keyLen &&
  ------------------
  |  Branch (1987:22): [True: 0, False: 10.8k]
  ------------------
 1988|  10.8k|                     pubKey->u.ec.publicValue.data[0] == EC_POINT_FORM_UNCOMPRESSED)) {
  ------------------
  |  |   92|      0|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (1988:22): [True: 0, False: 0]
  ------------------
 1989|  7.42k|                    break; /* key was not DER encoded, no need to unwrap */
 1990|  7.42k|                }
 1991|       |
 1992|       |                /* handle the encoded case */
 1993|  10.8k|                if ((pubKey->u.ec.publicValue.data[0] == SEC_ASN1_OCTET_STRING) &&
  ------------------
  |  |   80|  10.8k|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
  |  Branch (1993:21): [True: 10.8k, False: 0]
  ------------------
 1994|  10.8k|                    pubKey->u.ec.publicValue.len > keyLen) {
  ------------------
  |  Branch (1994:21): [True: 10.8k, False: 0]
  ------------------
 1995|  10.8k|                    SECItem publicValue;
 1996|  10.8k|                    SECStatus rv;
 1997|       |
 1998|  10.8k|                    rv = SEC_QuickDERDecodeItem(arena, &publicValue,
  ------------------
  |  |  102|  10.8k|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
 1999|  10.8k|                                                SEC_ASN1_GET(SEC_OctetStringTemplate),
  ------------------
  |  |  188|  10.8k|#define SEC_ASN1_GET(x) x
  ------------------
 2000|  10.8k|                                                &pubKey->u.ec.publicValue);
 2001|       |                    /* nope, didn't decode correctly */
 2002|  10.8k|                    if ((rv != SECSuccess) || (publicValue.len != keyLen)) {
  ------------------
  |  Branch (2002:25): [True: 0, False: 10.8k]
  |  Branch (2002:47): [True: 0, False: 10.8k]
  ------------------
 2003|      0|                        crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 2004|      0|                        break;
 2005|      0|                    }
 2006|       |                    /* we don't handle compressed points except in the case of ECCurve25519 */
 2007|  10.8k|                    if (publicValue.data[0] != EC_POINT_FORM_UNCOMPRESSED) {
  ------------------
  |  |   92|  10.8k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (2007:25): [True: 0, False: 10.8k]
  ------------------
 2008|      0|                        crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 2009|      0|                        break;
 2010|      0|                    }
 2011|       |                    /* replace our previous with the decoded key */
 2012|  10.8k|                    pubKey->u.ec.publicValue = publicValue;
 2013|  10.8k|                    break;
 2014|  10.8k|                }
 2015|      0|                crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 2016|      0|            }
 2017|      0|            break;
 2018|      0|        case CKK_NSS_KYBER:
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (2018:9): [True: 0, False: 50.4k]
  ------------------
 2019|     99|        case CKK_NSS_ML_KEM:
  ------------------
  |  |   59|     99|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|     99|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|     99|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (2019:9): [True: 99, False: 50.3k]
  ------------------
 2020|     99|            crv = CKR_OK;
  ------------------
  |  | 1388|     99|#define CKR_OK 0x00000000UL
  ------------------
 2021|     99|            break;
 2022|      0|        default:
  ------------------
  |  Branch (2022:9): [True: 0, False: 50.4k]
  ------------------
 2023|      0|            crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 2024|      0|            break;
 2025|  50.4k|    }
 2026|  50.4k|    *crvp = crv;
 2027|  50.4k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2027:9): [True: 0, False: 50.4k]
  ------------------
 2028|      0|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2029|      0|        return NULL;
 2030|      0|    }
 2031|       |
 2032|  50.4k|    object->objectInfo = pubKey;
 2033|  50.4k|    object->infoFree = SFTKFree_nsslowkey_DestroyPublicKey;
 2034|  50.4k|    return pubKey;
 2035|  50.4k|}
sftk_GetPrivKey:
 2377|   117k|{
 2378|   117k|    NSSLOWKEYPrivateKey *priv = NULL;
 2379|       |
 2380|   117k|    if (object->objclass != CKO_PRIVATE_KEY) {
  ------------------
  |  |  328|   117k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (2380:9): [True: 0, False: 117k]
  ------------------
 2381|      0|        *crvp = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 2382|      0|        return NULL;
 2383|      0|    }
 2384|   117k|    if (object->objectInfo) {
  ------------------
  |  Branch (2384:9): [True: 117k, False: 0]
  ------------------
 2385|   117k|        *crvp = CKR_OK;
  ------------------
  |  | 1388|   117k|#define CKR_OK 0x00000000UL
  ------------------
 2386|   117k|        return (NSSLOWKEYPrivateKey *)object->objectInfo;
 2387|   117k|    }
 2388|       |
 2389|      0|    priv = sftk_mkPrivKey(object, key_type, crvp);
 2390|      0|    object->objectInfo = priv;
 2391|      0|    object->infoFree = SFTKFree_nsslowkey_DestroyPrivateKey;
 2392|      0|    return priv;
 2393|   117k|}
sftk_FormatDESKey:
 2523|  24.9k|{
 2524|  24.9k|    int i;
 2525|       |
 2526|       |    /* format the des key */
 2527|   386k|    for (i = 0; i < length; i++) {
  ------------------
  |  Branch (2527:17): [True: 361k, False: 24.9k]
  ------------------
 2528|   361k|        key[i] = parityTable[key[i] >> 1];
 2529|   361k|    }
 2530|  24.9k|}
sftk_IsWeakKey:
 2556|      2|{
 2557|       |
 2558|      2|    switch (key_type) {
 2559|      0|        case CKK_DES:
  ------------------
  |  |  386|      0|#define CKK_DES 0x00000013UL
  ------------------
  |  Branch (2559:9): [True: 0, False: 2]
  ------------------
 2560|      0|            return sftk_CheckDESKey(key);
 2561|      0|        case CKM_DES2_KEY_GEN:
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
  |  Branch (2561:9): [True: 0, False: 2]
  ------------------
 2562|      0|            if (sftk_CheckDESKey(key))
  ------------------
  |  Branch (2562:17): [True: 0, False: 0]
  ------------------
 2563|      0|                return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2564|      0|            return sftk_CheckDESKey(&key[8]);
 2565|      0|        case CKM_DES3_KEY_GEN:
  ------------------
  |  |  824|      0|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  |  Branch (2565:9): [True: 0, False: 2]
  ------------------
 2566|      0|            if (sftk_CheckDESKey(key))
  ------------------
  |  Branch (2566:17): [True: 0, False: 0]
  ------------------
 2567|      0|                return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2568|      0|            if (sftk_CheckDESKey(&key[8]))
  ------------------
  |  Branch (2568:17): [True: 0, False: 0]
  ------------------
 2569|      0|                return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2570|      0|            return sftk_CheckDESKey(&key[16]);
 2571|      2|        default:
  ------------------
  |  Branch (2571:9): [True: 2, False: 0]
  ------------------
 2572|      2|            break;
 2573|      2|    }
 2574|      2|    return PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2575|      2|}
NSC_GetInterface:
 2642|    101|{
 2643|    101|    int i;
 2644|    500|    for (i = 0; i < NSS_INTERFACE_COUNT; i++) {
  ------------------
  |  |  191|    500|#define NSS_INTERFACE_COUNT 5
  ------------------
  |  Branch (2644:17): [True: 500, False: 0]
  ------------------
 2645|    500|        CK_INTERFACE_PTR interface = &nss_interfaces[i];
 2646|    500|        if (pInterfaceName && PORT_Strcmp((char *)pInterfaceName, (char *)interface->pInterfaceName) != 0) {
  ------------------
  |  |  188|    500|#define PORT_Strcmp strcmp
  ------------------
  |  Branch (2646:13): [True: 500, False: 0]
  |  Branch (2646:31): [True: 399, False: 101]
  ------------------
 2647|    399|            continue;
 2648|    399|        }
 2649|    101|        if (pVersion && PORT_Memcmp(pVersion, (CK_VERSION *)interface->pFunctionList, sizeof(CK_VERSION)) != 0) {
  ------------------
  |  |  179|     99|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (2649:13): [True: 99, False: 2]
  |  Branch (2649:25): [True: 0, False: 99]
  ------------------
 2650|      0|            continue;
 2651|      0|        }
 2652|    101|        if (flags & ((interface->flags & flags) != flags)) {
  ------------------
  |  Branch (2652:13): [True: 0, False: 101]
  ------------------
 2653|      0|            continue;
 2654|      0|        }
 2655|    101|        *ppInterface = interface;
 2656|    101|        return CKR_OK;
  ------------------
  |  | 1388|    101|#define CKR_OK 0x00000000UL
  ------------------
 2657|    101|    }
 2658|      0|    return CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 2659|    101|}
sftk_getDefTokName:
 2689|      2|{
 2690|      2|    static char buf[33];
 2691|       |
 2692|      2|    switch (slotID) {
 2693|      1|        case NETSCAPE_SLOT_ID:
  ------------------
  |  |  498|      1|#define NETSCAPE_SLOT_ID 1
  ------------------
  |  Branch (2693:9): [True: 1, False: 1]
  ------------------
 2694|      1|            return "NSS Generic Crypto Services     ";
 2695|      1|        case PRIVATE_KEY_SLOT_ID:
  ------------------
  |  |  499|      1|#define PRIVATE_KEY_SLOT_ID 2
  ------------------
  |  Branch (2695:9): [True: 1, False: 1]
  ------------------
 2696|      1|            return "NSS Certificate DB              ";
 2697|      0|        case FIPS_SLOT_ID:
  ------------------
  |  |  500|      0|#define FIPS_SLOT_ID 3
  ------------------
  |  Branch (2697:9): [True: 0, False: 2]
  ------------------
 2698|      0|            return "NSS FIPS 140-2 Certificate DB   ";
 2699|      0|        default:
  ------------------
  |  Branch (2699:9): [True: 0, False: 2]
  ------------------
 2700|      0|            break;
 2701|      2|    }
 2702|      0|    snprintf(buf, sizeof(buf), "NSS Application Token %08x  ", (unsigned int)slotID);
 2703|      0|    return buf;
 2704|      2|}
sftk_getDefSlotName:
 2708|      2|{
 2709|      2|    static char buf[65];
 2710|       |
 2711|      2|    switch (slotID) {
 2712|      1|        case NETSCAPE_SLOT_ID:
  ------------------
  |  |  498|      1|#define NETSCAPE_SLOT_ID 1
  ------------------
  |  Branch (2712:9): [True: 1, False: 1]
  ------------------
 2713|      1|            return "NSS Internal Cryptographic Services                             ";
 2714|      1|        case PRIVATE_KEY_SLOT_ID:
  ------------------
  |  |  499|      1|#define PRIVATE_KEY_SLOT_ID 2
  ------------------
  |  Branch (2714:9): [True: 1, False: 1]
  ------------------
 2715|      1|            return "NSS User Private Key and Certificate Services                   ";
 2716|      0|        case FIPS_SLOT_ID:
  ------------------
  |  |  500|      0|#define FIPS_SLOT_ID 3
  ------------------
  |  Branch (2716:9): [True: 0, False: 2]
  ------------------
 2717|      0|            return "NSS FIPS 140-2 User Private Key Services                        ";
 2718|      0|        default:
  ------------------
  |  Branch (2718:9): [True: 0, False: 2]
  ------------------
 2719|      0|            break;
 2720|      2|    }
 2721|      0|    snprintf(buf, sizeof(buf),
 2722|      0|             "NSS Application Slot %08x                                   ",
 2723|      0|             (unsigned int)slotID);
 2724|      0|    return buf;
 2725|      2|}
sftk_SlotFromID:
 2747|  13.0M|{
 2748|  13.0M|    SFTKSlot *slot;
 2749|  13.0M|    unsigned int index = sftk_GetModuleIndex(slotID);
 2750|       |
 2751|  13.0M|    if (nscSlotHashTable[index] == NULL)
  ------------------
  |  Branch (2751:9): [True: 0, False: 13.0M]
  ------------------
 2752|      0|        return NULL;
 2753|  13.0M|    slot = (SFTKSlot *)PL_HashTableLookupConst(nscSlotHashTable[index],
 2754|  13.0M|                                               (void *)(uintptr_t)slotID);
 2755|       |    /* cleared slots shouldn't 'show up' */
 2756|  13.0M|    if (slot && !all && !slot->present)
  ------------------
  |  Branch (2756:9): [True: 13.0M, False: 0]
  |  Branch (2756:17): [True: 13.0M, False: 2]
  |  Branch (2756:25): [True: 0, False: 13.0M]
  ------------------
 2757|      0|        slot = NULL;
 2758|  13.0M|    return slot;
 2759|  13.0M|}
sftk_SlotIDFromSessionHandle:
 2763|  11.2M|{
 2764|  11.2M|    CK_ULONG slotIDIndex = (handle >> 24) & 0x7f;
 2765|  11.2M|    CK_ULONG moduleIndex = (handle >> 31) & 1;
 2766|       |
 2767|  11.2M|    if (slotIDIndex >= nscSlotCount[moduleIndex]) {
  ------------------
  |  Branch (2767:9): [True: 0, False: 11.2M]
  ------------------
 2768|      0|        return (CK_SLOT_ID)-1;
 2769|      0|    }
 2770|  11.2M|    return nscSlotList[moduleIndex][slotIDIndex];
 2771|  11.2M|}
sftk_SlotFromSessionHandle:
 2775|  11.2M|{
 2776|  11.2M|    return sftk_SlotFromID(sftk_SlotIDFromSessionHandle(handle), PR_FALSE);
  ------------------
  |  |  438|  11.2M|#define PR_FALSE 0
  ------------------
 2777|  11.2M|}
SFTK_SlotReInit:
 2861|      2|{
 2862|      2|    PRBool needLogin = !params->noKeyDB;
 2863|      2|    CK_RV crv;
 2864|       |
 2865|      2|    slot->hasTokens = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2866|      2|    slot->sessionIDConflict = 0;
 2867|      2|    slot->sessionCount = 0;
 2868|      2|    slot->rwSessionCount = 0;
 2869|      2|    slot->needLogin = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2870|      2|    slot->isLoggedIn = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2871|      2|    slot->ssoLoggedIn = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2872|      2|    slot->DB_loaded = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2873|      2|    slot->certDB = NULL;
 2874|      2|    slot->keyDB = NULL;
 2875|      2|    slot->minimumPinLen = 0;
 2876|      2|    slot->readOnly = params->readOnly;
 2877|      2|    sftk_setStringName(params->tokdes ? params->tokdes : sftk_getDefTokName(slot->slotID), slot->tokDescription,
  ------------------
  |  Branch (2877:24): [True: 0, False: 2]
  ------------------
 2878|      2|                       sizeof(slot->tokDescription), PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 2879|      2|    sftk_setStringName(params->updtokdes ? params->updtokdes : " ",
  ------------------
  |  Branch (2879:24): [True: 1, False: 1]
  ------------------
 2880|      2|                       slot->updateTokDescription,
 2881|      2|                       sizeof(slot->updateTokDescription), PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 2882|       |
 2883|      2|    if ((!params->noCertDB) || (!params->noKeyDB)) {
  ------------------
  |  Branch (2883:9): [True: 0, False: 2]
  |  Branch (2883:32): [True: 0, False: 2]
  ------------------
 2884|      0|        SFTKDBHandle *certHandle = NULL;
 2885|      0|        SFTKDBHandle *keyHandle = NULL;
 2886|      0|        crv = sftk_DBInit(params->configdir ? params->configdir : configdir,
  ------------------
  |  Branch (2886:27): [True: 0, False: 0]
  ------------------
 2887|      0|                          params->certPrefix, params->keyPrefix,
 2888|      0|                          params->updatedir ? params->updatedir : updatedir,
  ------------------
  |  Branch (2888:27): [True: 0, False: 0]
  ------------------
 2889|      0|                          params->updCertPrefix, params->updKeyPrefix,
 2890|      0|                          params->updateID ? params->updateID : updateID,
  ------------------
  |  Branch (2890:27): [True: 0, False: 0]
  ------------------
 2891|      0|                          params->readOnly, params->noCertDB, params->noKeyDB,
 2892|      0|                          params->forceOpen,
 2893|      0|                          moduleIndex == NSC_FIPS_MODULE,
  ------------------
  |  |   54|      0|#define NSC_FIPS_MODULE 1
  ------------------
 2894|      0|                          &certHandle, &keyHandle);
 2895|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2895:13): [True: 0, False: 0]
  ------------------
 2896|      0|            goto loser;
 2897|      0|        }
 2898|       |
 2899|      0|        slot->certDB = certHandle;
 2900|      0|        slot->keyDB = keyHandle;
 2901|      0|    }
 2902|      2|    if (needLogin) {
  ------------------
  |  Branch (2902:9): [True: 0, False: 2]
  ------------------
 2903|       |        /* if the data base is initialized with a null password,remember that */
 2904|      0|        slot->needLogin =
 2905|      0|            (PRBool)!sftk_hasNullPassword(slot, slot->keyDB);
 2906|      0|        if ((params->minPW >= 0) && (params->minPW <= SFTK_MAX_PIN)) {
  ------------------
  |  |  493|      0|#define SFTK_MAX_PIN 500
  ------------------
  |  Branch (2906:13): [True: 0, False: 0]
  |  Branch (2906:37): [True: 0, False: 0]
  ------------------
 2907|      0|            slot->minimumPinLen = params->minPW;
 2908|      0|        }
 2909|      0|        if ((slot->minimumPinLen == 0) && (params->pwRequired)) {
  ------------------
  |  Branch (2909:13): [True: 0, False: 0]
  |  Branch (2909:43): [True: 0, False: 0]
  ------------------
 2910|      0|            slot->minimumPinLen = 1;
 2911|      0|        }
 2912|       |        /* Make sure the pin len is set to the Minimum allowed value for fips
 2913|       |         * when in FIPS mode. NOTE: we don't set it if the database has not
 2914|       |         * been initialized yet so that we can init into level1 mode if needed
 2915|       |         */
 2916|      0|        if ((sftkdb_HasPasswordSet(slot->keyDB) == SECSuccess) &&
  ------------------
  |  Branch (2916:13): [True: 0, False: 0]
  ------------------
 2917|      0|            (moduleIndex == NSC_FIPS_MODULE) &&
  ------------------
  |  |   54|      0|#define NSC_FIPS_MODULE 1
  ------------------
  |  Branch (2917:13): [True: 0, False: 0]
  ------------------
 2918|      0|            (slot->minimumPinLen < FIPS_MIN_PIN)) {
  ------------------
  |  |  495|      0|#define FIPS_MIN_PIN 7
  ------------------
  |  Branch (2918:13): [True: 0, False: 0]
  ------------------
 2919|      0|            slot->minimumPinLen = FIPS_MIN_PIN;
  ------------------
  |  |  495|      0|#define FIPS_MIN_PIN 7
  ------------------
 2920|      0|        }
 2921|      0|    }
 2922|       |
 2923|      2|    slot->present = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 2924|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 2925|       |
 2926|      0|loser:
 2927|      0|    SFTK_ShutdownSlot(slot);
 2928|      0|    return crv;
 2929|      2|}
SFTK_SlotInit:
 2937|      2|{
 2938|      2|    unsigned int i;
 2939|      2|    CK_SLOT_ID slotID = params->slotID;
 2940|      2|    SFTKSlot *slot;
 2941|      2|    CK_RV crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      2|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2942|       |
 2943|       |    /*
 2944|       |     * first we initialize everything that is 'permanent' with this slot.
 2945|       |     * that is everything we aren't going to shutdown if we close this slot
 2946|       |     * and open it up again with different databases */
 2947|       |
 2948|      2|    slot = PORT_ZNew(SFTKSlot);
  ------------------
  |  |  148|      2|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      2|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 2949|       |
 2950|      2|    if (slot == NULL) {
  ------------------
  |  Branch (2950:9): [True: 0, False: 2]
  ------------------
 2951|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2952|      0|    }
 2953|       |
 2954|      2|    slot->optimizeSpace = params->optimizeSpace;
 2955|      2|    if (slot->optimizeSpace) {
  ------------------
  |  Branch (2955:9): [True: 2, False: 0]
  ------------------
 2956|      2|        slot->sessObjHashSize = SPACE_SESSION_OBJECT_HASH_SIZE;
  ------------------
  |  |   66|      2|#define SPACE_SESSION_OBJECT_HASH_SIZE 32
  ------------------
 2957|      2|        slot->sessHashSize = SPACE_SESSION_HASH_SIZE;
  ------------------
  |  |   67|      2|#define SPACE_SESSION_HASH_SIZE 32
  ------------------
 2958|      2|        slot->numSessionLocks = 1;
 2959|      2|    } else {
 2960|      0|        slot->sessObjHashSize = TIME_SESSION_OBJECT_HASH_SIZE;
  ------------------
  |  |   69|      0|#define TIME_SESSION_OBJECT_HASH_SIZE 1024
  ------------------
 2961|      0|        slot->sessHashSize = TIME_SESSION_HASH_SIZE;
  ------------------
  |  |   70|      0|#define TIME_SESSION_HASH_SIZE 1024
  ------------------
 2962|      0|        slot->numSessionLocks = slot->sessHashSize / BUCKETS_PER_SESSION_LOCK;
  ------------------
  |  |   93|      0|#define BUCKETS_PER_SESSION_LOCK (1 << (LOG2_BUCKETS_PER_SESSION_LOCK))
  |  |  ------------------
  |  |  |  |   92|      0|#define LOG2_BUCKETS_PER_SESSION_LOCK 1
  |  |  ------------------
  ------------------
 2963|      0|    }
 2964|      2|    slot->sessionLockMask = slot->numSessionLocks - 1;
 2965|       |
 2966|      2|    slot->slotLock = PZ_NewLock(nssILockSession);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 2967|      2|    if (slot->slotLock == NULL)
  ------------------
  |  Branch (2967:9): [True: 0, False: 2]
  ------------------
 2968|      0|        goto mem_loser;
 2969|      2|    slot->sessionLock = PORT_ZNewArray(PZLock *, slot->numSessionLocks);
  ------------------
  |  |  159|      2|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|      2|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 2970|      2|    if (slot->sessionLock == NULL)
  ------------------
  |  Branch (2970:9): [True: 0, False: 2]
  ------------------
 2971|      0|        goto mem_loser;
 2972|      4|    for (i = 0; i < slot->numSessionLocks; i++) {
  ------------------
  |  Branch (2972:17): [True: 2, False: 2]
  ------------------
 2973|      2|        slot->sessionLock[i] = PZ_NewLock(nssILockSession);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 2974|      2|        if (slot->sessionLock[i] == NULL)
  ------------------
  |  Branch (2974:13): [True: 0, False: 2]
  ------------------
 2975|      0|            goto mem_loser;
 2976|      2|    }
 2977|      2|    slot->objectLock = PZ_NewLock(nssILockObject);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 2978|      2|    if (slot->objectLock == NULL)
  ------------------
  |  Branch (2978:9): [True: 0, False: 2]
  ------------------
 2979|      0|        goto mem_loser;
 2980|      2|    slot->pwCheckLock = PR_NewLock();
 2981|      2|    if (slot->pwCheckLock == NULL)
  ------------------
  |  Branch (2981:9): [True: 0, False: 2]
  ------------------
 2982|      0|        goto mem_loser;
 2983|      2|    slot->head = PORT_ZNewArray(SFTKSession *, slot->sessHashSize);
  ------------------
  |  |  159|      2|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|      2|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 2984|      2|    if (slot->head == NULL)
  ------------------
  |  Branch (2984:9): [True: 0, False: 2]
  ------------------
 2985|      0|        goto mem_loser;
 2986|      2|    slot->sessObjHashTable = PORT_ZNewArray(SFTKObject *, slot->sessObjHashSize);
  ------------------
  |  |  159|      2|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|      2|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 2987|      2|    if (slot->sessObjHashTable == NULL)
  ------------------
  |  Branch (2987:9): [True: 0, False: 2]
  ------------------
 2988|      0|        goto mem_loser;
 2989|      2|    slot->tokObjHashTable = PL_NewHashTable(64, sftk_HashNumber, PL_CompareValues,
 2990|      2|                                            SECITEM_HashCompare, NULL, 0);
 2991|      2|    if (slot->tokObjHashTable == NULL)
  ------------------
  |  Branch (2991:9): [True: 0, False: 2]
  ------------------
 2992|      0|        goto mem_loser;
 2993|       |
 2994|      2|    slot->sessionIDCount = 0;
 2995|      2|    slot->sessionObjectHandleCount = NSC_MIN_SESSION_OBJECT_HANDLE;
  ------------------
  |  |   52|      2|#define NSC_MIN_SESSION_OBJECT_HANDLE 1U
  ------------------
 2996|      2|    slot->slotID = slotID;
 2997|      2|    sftk_setStringName(params->slotdes ? params->slotdes : sftk_getDefSlotName(slotID), slot->slotDescription,
  ------------------
  |  Branch (2997:24): [True: 0, False: 2]
  ------------------
 2998|      2|                       sizeof(slot->slotDescription), PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 2999|      2|    crv = sftk_InitSession(&slot->moduleObjects, slot, slotID, NULL, NULL,
 3000|      2|                           CKF_SERIAL_SESSION);
  ------------------
  |  |  303|      2|#define CKF_SERIAL_SESSION 0x00000004UL /* no parallel */
  ------------------
 3001|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3001:9): [True: 0, False: 2]
  ------------------
 3002|      0|        goto loser;
 3003|      0|    }
 3004|       |
 3005|       |    /* call the reinit code to set everything that changes between token
 3006|       |     * init calls */
 3007|      2|    crv = SFTK_SlotReInit(slot, configdir, updatedir, updateID,
 3008|      2|                          params, moduleIndex);
 3009|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3009:9): [True: 0, False: 2]
  ------------------
 3010|      0|        goto loser;
 3011|      0|    }
 3012|      2|    if (sftk_isFIPS(slotID)) {
  ------------------
  |  |  506|      2|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|      2|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|      2|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 2]
  |  |  |  Branch (506:32): [True: 0, False: 2]
  |  |  ------------------
  ------------------
 3013|      0|        crv = sftk_CreateValidationObjects(slot);
 3014|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3014:13): [True: 0, False: 0]
  ------------------
 3015|      0|            goto loser;
 3016|      0|        }
 3017|      0|    }
 3018|      2|    crv = sftk_RegisterSlot(slot, moduleIndex);
 3019|      2|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3019:9): [True: 0, False: 2]
  ------------------
 3020|      0|        goto loser;
 3021|      0|    }
 3022|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 3023|       |
 3024|      0|mem_loser:
 3025|      0|    crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3026|      0|loser:
 3027|      0|    SFTK_DestroySlotData(slot);
 3028|      0|    return crv;
 3029|      0|}
sftk_CloseAllSessions:
 3033|      6|{
 3034|      6|    SFTKSession *session;
 3035|      6|    unsigned int i;
 3036|      6|    SFTKDBHandle *handle;
 3037|       |
 3038|       |    /* first log out the card */
 3039|       |    /* special case - if we are in a middle of upgrade, we want to close the
 3040|       |     * sessions to fake a token removal to tell the upper level code we have
 3041|       |     * switched from one database to another, but we don't want to
 3042|       |     * explicity logout in case we can continue the upgrade with the
 3043|       |     * existing password if possible.
 3044|       |     */
 3045|      6|    if (logout) {
  ------------------
  |  Branch (3045:9): [True: 6, False: 0]
  ------------------
 3046|      6|        handle = sftk_getKeyDB(slot);
 3047|      6|        SKIP_AFTER_FORK(PZ_Lock(slot->slotLock));
  ------------------
  |  |  256|      6|#define SKIP_AFTER_FORK(x) x
  ------------------
 3048|      6|        slot->isLoggedIn = PR_FALSE;
  ------------------
  |  |  438|      6|#define PR_FALSE 0
  ------------------
 3049|      6|        if (slot->needLogin && handle) {
  ------------------
  |  Branch (3049:13): [True: 0, False: 6]
  |  Branch (3049:32): [True: 0, False: 0]
  ------------------
 3050|      0|            sftkdb_ClearPassword(handle);
 3051|      0|        }
 3052|      6|        SKIP_AFTER_FORK(PZ_Unlock(slot->slotLock));
  ------------------
  |  |  256|      6|#define SKIP_AFTER_FORK(x) x
  ------------------
 3053|      6|        if (handle) {
  ------------------
  |  Branch (3053:13): [True: 0, False: 6]
  ------------------
 3054|      0|            sftk_freeDB(handle);
 3055|      0|        }
 3056|      6|    }
 3057|       |
 3058|       |    /* now close all the current sessions */
 3059|       |    /* NOTE: If you try to open new sessions before NSC_CloseAllSessions
 3060|       |     * completes, some of those new sessions may or may not be closed by
 3061|       |     * NSC_CloseAllSessions... but any session running when this code starts
 3062|       |     * will guarrenteed be close, and no session will be partially closed */
 3063|    198|    for (i = 0; i < slot->sessHashSize; i++) {
  ------------------
  |  Branch (3063:17): [True: 192, False: 6]
  ------------------
 3064|    192|        PZLock *lock = SFTK_SESSION_LOCK(slot, i);
  ------------------
  |  |  185|    192|#define PZLock PRLock
  ------------------
                      PZLock *lock = SFTK_SESSION_LOCK(slot, i);
  ------------------
  |  |  583|    192|    ((slot)->sessionLock[(handle) & (slot)->sessionLockMask])
  ------------------
 3065|    194|        do {
 3066|    194|            SKIP_AFTER_FORK(PZ_Lock(lock));
  ------------------
  |  |  256|    194|#define SKIP_AFTER_FORK(x) x
  ------------------
 3067|    194|            session = slot->head[i];
 3068|       |            /* hand deque */
 3069|       |            /* this duplicates function of NSC_close session functions, but
 3070|       |             * because we know that we are freeing all the sessions, we can
 3071|       |             * do more efficient processing */
 3072|    194|            if (session) {
  ------------------
  |  Branch (3072:17): [True: 2, False: 192]
  ------------------
 3073|      2|                slot->head[i] = session->next;
 3074|      2|                if (session->next)
  ------------------
  |  Branch (3074:21): [True: 0, False: 2]
  ------------------
 3075|      0|                    session->next->prev = NULL;
 3076|      2|                session->next = session->prev = NULL;
 3077|      2|                SKIP_AFTER_FORK(PZ_Unlock(lock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3078|      2|                SKIP_AFTER_FORK(PZ_Lock(slot->slotLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3079|      2|                --slot->sessionCount;
 3080|      2|                SKIP_AFTER_FORK(PZ_Unlock(slot->slotLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3081|      2|                if (session->info.flags & CKF_RW_SESSION) {
  ------------------
  |  |  302|      2|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (3081:21): [True: 0, False: 2]
  ------------------
 3082|      0|                    (void)PR_ATOMIC_DECREMENT(&slot->rwSessionCount);
  ------------------
  |  |  123|      0|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
 3083|      0|                }
 3084|    192|            } else {
 3085|    192|                SKIP_AFTER_FORK(PZ_Unlock(lock));
  ------------------
  |  |  256|    192|#define SKIP_AFTER_FORK(x) x
  ------------------
 3086|    192|            }
 3087|    194|            if (session) {
  ------------------
  |  Branch (3087:17): [True: 2, False: 192]
  ------------------
 3088|      2|                sftk_DestroySession(session);
 3089|      2|            }
 3090|    194|        } while (session != NULL);
  ------------------
  |  Branch (3090:18): [True: 2, False: 192]
  ------------------
 3091|    192|    }
 3092|      6|    return CKR_OK;
  ------------------
  |  | 1388|      6|#define CKR_OK 0x00000000UL
  ------------------
 3093|      6|}
SFTK_ShutdownSlot:
 3126|      2|{
 3127|       |    /* make sure no new PK11 calls work except C_GetSlotInfo */
 3128|      2|    slot->present = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 3129|       |
 3130|       |    /* close all outstanding sessions
 3131|       |     * the sessHashSize variable guarentees we have all the session
 3132|       |     * mechanism set up */
 3133|      2|    if (slot->head) {
  ------------------
  |  Branch (3133:9): [True: 2, False: 0]
  ------------------
 3134|      2|        sftk_CloseAllSessions(slot, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 3135|      2|    }
 3136|       |
 3137|       |    /* clear all objects.. session objects are cleared as a result of
 3138|       |     * closing all the sessions. We just need to clear the token object
 3139|       |     * cache. slot->tokObjHashTable guarentees we have the token
 3140|       |     * infrastructure set up. */
 3141|      2|    if (slot->tokObjHashTable) {
  ------------------
  |  Branch (3141:9): [True: 2, False: 0]
  ------------------
 3142|      2|        SFTK_ClearTokenKeyHashTable(slot);
 3143|      2|    }
 3144|       |
 3145|       |    /* clear the slot description for the next guy */
 3146|      2|    PORT_Memset(slot->tokDescription, 0, sizeof(slot->tokDescription));
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 3147|       |
 3148|       |    /* now shut down the databases. */
 3149|      2|    sftk_DBShutdown(slot);
 3150|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 3151|      2|}
SFTK_DestroySlotData:
 3158|      2|{
 3159|      2|    unsigned int i;
 3160|       |
 3161|      2|    SFTK_ShutdownSlot(slot);
 3162|       |
 3163|      2|    sftk_ClearSession(&slot->moduleObjects);
 3164|       |
 3165|      2|    if (slot->tokObjHashTable) {
  ------------------
  |  Branch (3165:9): [True: 2, False: 0]
  ------------------
 3166|      2|        PL_HashTableDestroy(slot->tokObjHashTable);
 3167|      2|        slot->tokObjHashTable = NULL;
 3168|      2|    }
 3169|       |
 3170|      2|    if (slot->sessObjHashTable) {
  ------------------
  |  Branch (3170:9): [True: 2, False: 0]
  ------------------
 3171|      2|        PORT_Free(slot->sessObjHashTable);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 3172|      2|        slot->sessObjHashTable = NULL;
 3173|      2|    }
 3174|      2|    slot->sessObjHashSize = 0;
 3175|       |
 3176|      2|    if (slot->head) {
  ------------------
  |  Branch (3176:9): [True: 2, False: 0]
  ------------------
 3177|      2|        PORT_Free(slot->head);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 3178|      2|        slot->head = NULL;
 3179|      2|    }
 3180|      2|    slot->sessHashSize = 0;
 3181|       |
 3182|       |    /* OK everything has been disassembled, now we can finally get rid
 3183|       |     * of the locks */
 3184|      2|    SKIP_AFTER_FORK(PZ_DestroyLock(slot->slotLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3185|      2|    slot->slotLock = NULL;
 3186|      2|    if (slot->sessionLock) {
  ------------------
  |  Branch (3186:9): [True: 2, False: 0]
  ------------------
 3187|      4|        for (i = 0; i < slot->numSessionLocks; i++) {
  ------------------
  |  Branch (3187:21): [True: 2, False: 2]
  ------------------
 3188|      2|            if (slot->sessionLock[i]) {
  ------------------
  |  Branch (3188:17): [True: 2, False: 0]
  ------------------
 3189|      2|                SKIP_AFTER_FORK(PZ_DestroyLock(slot->sessionLock[i]));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3190|      2|                slot->sessionLock[i] = NULL;
 3191|      2|            }
 3192|      2|        }
 3193|      2|        PORT_Free(slot->sessionLock);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 3194|      2|        slot->sessionLock = NULL;
 3195|      2|    }
 3196|      2|    if (slot->objectLock) {
  ------------------
  |  Branch (3196:9): [True: 2, False: 0]
  ------------------
 3197|      2|        SKIP_AFTER_FORK(PZ_DestroyLock(slot->objectLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3198|      2|        slot->objectLock = NULL;
 3199|      2|    }
 3200|      2|    if (slot->pwCheckLock) {
  ------------------
  |  Branch (3200:9): [True: 2, False: 0]
  ------------------
 3201|      2|        SKIP_AFTER_FORK(PR_DestroyLock(slot->pwCheckLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3202|      2|        slot->pwCheckLock = NULL;
 3203|      2|    }
 3204|      2|    PORT_Free(slot);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 3205|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 3206|      2|}
NSC_ModuleDBFunc:
 3213|      2|{
 3214|      2|#ifdef NSS_DISABLE_DBM
 3215|      2|    return NSSUTIL_DoModuleDBFunction(function, parameters, args);
 3216|       |#else
 3217|       |    char *secmod = NULL;
 3218|       |    char *appName = NULL;
 3219|       |    char *filename = NULL;
 3220|       |    NSSDBType dbType = NSS_DB_TYPE_NONE;
 3221|       |    PRBool rw;
 3222|       |    static char *success = "Success";
 3223|       |    char **rvstr = NULL;
 3224|       |
 3225|       |    rvstr = NSSUTIL_DoModuleDBFunction(function, parameters, args);
 3226|       |    if (rvstr != NULL) {
 3227|       |        return rvstr;
 3228|       |    }
 3229|       |
 3230|       |    if (PORT_GetError() != SEC_ERROR_LEGACY_DATABASE) {
 3231|       |        return NULL;
 3232|       |    }
 3233|       |
 3234|       |    /* The legacy database uses the old dbm, which is only linked with the
 3235|       |     * legacy DB handler, which is only callable from softoken */
 3236|       |
 3237|       |    secmod = _NSSUTIL_GetSecmodName(parameters, &dbType, &appName,
 3238|       |                                    &filename, &rw);
 3239|       |
 3240|       |    switch (function) {
 3241|       |        case SECMOD_MODULE_DB_FUNCTION_FIND:
 3242|       |            if (secmod == NULL) {
 3243|       |                PORT_SetError(SEC_ERROR_INVALID_ARGS);
 3244|       |                goto loser;
 3245|       |            }
 3246|       |            if (rw && (dbType != NSS_DB_TYPE_LEGACY) &&
 3247|       |                (dbType != NSS_DB_TYPE_MULTIACCESS)) {
 3248|       |                /* if we get here, we are trying to update the local database */
 3249|       |                /* force data from the legacy DB */
 3250|       |                char *oldSecmod = NULL;
 3251|       |                char *oldAppName = NULL;
 3252|       |                char *oldFilename = NULL;
 3253|       |                PRBool oldrw;
 3254|       |                char **strings = NULL;
 3255|       |                int i;
 3256|       |
 3257|       |                dbType = NSS_DB_TYPE_LEGACY;
 3258|       |                oldSecmod = _NSSUTIL_GetSecmodName(parameters, &dbType, &oldAppName,
 3259|       |                                                   &oldFilename, &oldrw);
 3260|       |                strings = sftkdbCall_ReadSecmodDB(appName, oldFilename, oldSecmod,
 3261|       |                                                  (char *)parameters, oldrw);
 3262|       |                if (strings) {
 3263|       |                    /* write out the strings */
 3264|       |                    for (i = 0; strings[i]; i++) {
 3265|       |                        NSSUTIL_DoModuleDBFunction(SECMOD_MODULE_DB_FUNCTION_ADD,
 3266|       |                                                   parameters, strings[i]);
 3267|       |                    }
 3268|       |                    sftkdbCall_ReleaseSecmodDBData(oldAppName, oldFilename, oldSecmod,
 3269|       |                                                   (char **)strings, oldrw);
 3270|       |                } else {
 3271|       |                    /* write out a dummy record */
 3272|       |                    NSSUTIL_DoModuleDBFunction(SECMOD_MODULE_DB_FUNCTION_ADD,
 3273|       |                                               parameters, " ");
 3274|       |                }
 3275|       |                if (oldSecmod) {
 3276|       |                    PR_smprintf_free(oldSecmod);
 3277|       |                }
 3278|       |                if (oldAppName) {
 3279|       |                    PORT_Free(oldAppName);
 3280|       |                }
 3281|       |                if (oldFilename) {
 3282|       |                    PORT_Free(oldFilename);
 3283|       |                }
 3284|       |                rvstr = NSSUTIL_DoModuleDBFunction(function, parameters, args);
 3285|       |                break;
 3286|       |            }
 3287|       |            rvstr = sftkdbCall_ReadSecmodDB(appName, filename, secmod,
 3288|       |                                            (char *)parameters, rw);
 3289|       |            break;
 3290|       |        case SECMOD_MODULE_DB_FUNCTION_ADD:
 3291|       |            if (secmod == NULL) {
 3292|       |                PORT_SetError(SEC_ERROR_INVALID_ARGS);
 3293|       |                goto loser;
 3294|       |            }
 3295|       |            rvstr = (sftkdbCall_AddSecmodDB(appName, filename, secmod,
 3296|       |                                            (char *)args, rw) == SECSuccess)
 3297|       |                        ? &success
 3298|       |                        : NULL;
 3299|       |            break;
 3300|       |        case SECMOD_MODULE_DB_FUNCTION_DEL:
 3301|       |            if (secmod == NULL) {
 3302|       |                PORT_SetError(SEC_ERROR_INVALID_ARGS);
 3303|       |                goto loser;
 3304|       |            }
 3305|       |            rvstr = (sftkdbCall_DeleteSecmodDB(appName, filename, secmod,
 3306|       |                                               (char *)args, rw) == SECSuccess)
 3307|       |                        ? &success
 3308|       |                        : NULL;
 3309|       |            break;
 3310|       |        case SECMOD_MODULE_DB_FUNCTION_RELEASE:
 3311|       |            rvstr = (sftkdbCall_ReleaseSecmodDBData(appName, filename, secmod,
 3312|       |                                                    (char **)args, rw) == SECSuccess)
 3313|       |                        ? &success
 3314|       |                        : NULL;
 3315|       |            break;
 3316|       |    }
 3317|       |
 3318|       |loser:
 3319|       |    if (secmod)
 3320|       |        PR_smprintf_free(secmod);
 3321|       |    if (appName)
 3322|       |        PORT_Free(appName);
 3323|       |    if (filename)
 3324|       |        PORT_Free(filename);
 3325|       |    return rvstr;
 3326|       |#endif /* NSS_DISABLE_DBM */
 3327|      2|}
nsc_CommonInitialize:
 3467|      1|{
 3468|      1|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3469|      1|    SECStatus rv;
 3470|      1|    CK_C_INITIALIZE_ARGS *init_args = (CK_C_INITIALIZE_ARGS *)pReserved;
 3471|      1|    PRBool destroy_freelist_on_error = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 3472|      1|    int i;
 3473|      1|    unsigned int moduleIndex = isFIPS ? NSC_FIPS_MODULE : NSC_NON_FIPS_MODULE;
  ------------------
  |  |   54|      0|#define NSC_FIPS_MODULE 1
  ------------------
                  unsigned int moduleIndex = isFIPS ? NSC_FIPS_MODULE : NSC_NON_FIPS_MODULE;
  ------------------
  |  |   55|      2|#define NSC_NON_FIPS_MODULE 0
  ------------------
  |  Branch (3473:32): [True: 0, False: 1]
  ------------------
 3474|       |
 3475|      1|    if (isFIPS) {
  ------------------
  |  Branch (3475:9): [True: 0, False: 1]
  ------------------
 3476|      0|        loginWaitTime = PR_SecondsToInterval(1);
 3477|      0|    }
 3478|       |
 3479|      1|    ENABLE_FORK_CHECK();
 3480|       |
 3481|      1|    sftk_PBELockInit();
 3482|       |
 3483|      1|    rv = SECOID_Init();
 3484|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3484:9): [True: 0, False: 1]
  ------------------
 3485|      0|        crv = CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 3486|      0|        return crv;
 3487|      0|    }
 3488|       |
 3489|      1|    rv = BL_Init(); /* initialize freebl engine */
 3490|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3490:9): [True: 0, False: 1]
  ------------------
 3491|      0|        crv = CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 3492|      0|        return crv;
 3493|      0|    }
 3494|       |
 3495|      1|    rv = RNG_RNGInit(); /* initialize random number generator */
 3496|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3496:9): [True: 0, False: 1]
  ------------------
 3497|      0|        crv = CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 3498|      0|        return crv;
 3499|      0|    }
 3500|       |
 3501|       |    /* NOTE:
 3502|       |     * we should be getting out mutexes from this list, not statically binding
 3503|       |     * them from NSPR. This should happen before we allow the internal to split
 3504|       |     * off from the rest on NSS.
 3505|       |     */
 3506|       |
 3507|       |    /* initialize the key and cert db's */
 3508|      1|    if (init_args && (!(init_args->flags & CKF_OS_LOCKING_OK))) {
  ------------------
  |  | 1627|      1|#define CKF_OS_LOCKING_OK 0x00000002UL
  ------------------
  |  Branch (3508:9): [True: 1, False: 0]
  |  Branch (3508:22): [True: 0, False: 1]
  ------------------
 3509|      0|        if (init_args->CreateMutex && init_args->DestroyMutex &&
  ------------------
  |  Branch (3509:13): [True: 0, False: 0]
  |  Branch (3509:39): [True: 0, False: 0]
  ------------------
 3510|      0|            init_args->LockMutex && init_args->UnlockMutex) {
  ------------------
  |  Branch (3510:13): [True: 0, False: 0]
  |  Branch (3510:37): [True: 0, False: 0]
  ------------------
 3511|       |            /* softoken always uses NSPR (ie. OS locking), and doesn't know how
 3512|       |             * to use the lock functions provided by the application.
 3513|       |             */
 3514|      0|            crv = CKR_CANT_LOCK;
  ------------------
  |  | 1404|      0|#define CKR_CANT_LOCK 0x0000000AUL
  ------------------
 3515|      0|            return crv;
 3516|      0|        }
 3517|      0|        if (init_args->CreateMutex || init_args->DestroyMutex ||
  ------------------
  |  Branch (3517:13): [True: 0, False: 0]
  |  Branch (3517:39): [True: 0, False: 0]
  ------------------
 3518|      0|            init_args->LockMutex || init_args->UnlockMutex) {
  ------------------
  |  Branch (3518:13): [True: 0, False: 0]
  |  Branch (3518:37): [True: 0, False: 0]
  ------------------
 3519|       |            /* only some of the lock functions were provided by the
 3520|       |             * application. This is invalid per PKCS#11 spec.
 3521|       |             */
 3522|      0|            crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 3523|      0|            return crv;
 3524|      0|        }
 3525|      0|    }
 3526|       |
 3527|      1|    sftk_parameters paramStrings;
 3528|       |
 3529|       |    /* load and parse the library parameters */
 3530|      1|    crv = sftk_getParameters(init_args, isFIPS, &paramStrings);
 3531|      1|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3531:9): [True: 0, False: 1]
  ------------------
 3532|      0|        goto loser;
 3533|      0|    }
 3534|       |
 3535|      1|    crv = sftk_configure(paramStrings.man, paramStrings.libdes);
 3536|      1|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3536:9): [True: 0, False: 1]
  ------------------
 3537|      0|        goto loser;
 3538|      0|    }
 3539|       |
 3540|       |    /* if we have a peer already open, have him close his DB's so we
 3541|       |     * don't clobber each other. */
 3542|      1|    if ((isFIPS && nsc_init) || (!isFIPS && nsf_init)) {
  ------------------
  |  Branch (3542:10): [True: 0, False: 1]
  |  Branch (3542:20): [True: 0, False: 0]
  |  Branch (3542:34): [True: 1, False: 0]
  |  Branch (3542:45): [True: 0, False: 1]
  ------------------
 3543|      0|        sftk_closePeer(isFIPS);
 3544|      0|        if (sftk_audit_enabled) {
  ------------------
  |  Branch (3544:13): [True: 0, False: 0]
  ------------------
 3545|      0|            if (isFIPS && nsc_init) {
  ------------------
  |  Branch (3545:17): [True: 0, False: 0]
  |  Branch (3545:27): [True: 0, False: 0]
  ------------------
 3546|      0|                sftk_LogAuditMessage(NSS_AUDIT_INFO, NSS_AUDIT_FIPS_STATE,
 3547|      0|                                     "enabled FIPS mode");
 3548|      0|            } else {
 3549|      0|                sftk_LogAuditMessage(NSS_AUDIT_INFO, NSS_AUDIT_FIPS_STATE,
 3550|      0|                                     "disabled FIPS mode");
 3551|      0|            }
 3552|      0|        }
 3553|       |        /* if we have a peer open, we don't want to destroy the freelist
 3554|       |         * from under the peer if we fail, the free list will be
 3555|       |         * destroyed in that case when the C_Finalize is called for
 3556|       |         * the peer */
 3557|      0|        destroy_freelist_on_error = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3558|      0|    }
 3559|       |    /* allow us to create objects in SFTK_SlotInit */
 3560|      1|    sftk_InitFreeLists();
 3561|       |
 3562|      3|    for (i = 0; i < paramStrings.token_count; i++) {
  ------------------
  |  Branch (3562:17): [True: 2, False: 1]
  ------------------
 3563|      2|        crv = SFTK_SlotInit(paramStrings.configdir,
 3564|      2|                            paramStrings.updatedir, paramStrings.updateID,
 3565|      2|                            &paramStrings.tokens[i], moduleIndex);
 3566|      2|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3566:13): [True: 0, False: 2]
  ------------------
 3567|      0|            nscFreeAllSlots(moduleIndex);
 3568|      0|            break;
 3569|      0|        }
 3570|      2|    }
 3571|       |
 3572|      1|loser:
 3573|       |
 3574|      1|    sftk_freeParams(&paramStrings);
 3575|       |
 3576|      1|    if (destroy_freelist_on_error && (CKR_OK != crv)) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3576:9): [True: 1, False: 0]
  |  Branch (3576:38): [True: 0, False: 1]
  ------------------
 3577|       |        /* idempotent. If the list are already freed, this is a noop */
 3578|      0|        sftk_CleanupFreeLists();
 3579|      0|    }
 3580|       |
 3581|       |#ifndef NO_FORK_CHECK
 3582|       |    if (CKR_OK == crv) {
 3583|       |#if defined(CHECK_FORK_MIXED)
 3584|       |        /* Before Solaris 10, fork handlers are not unregistered at dlclose()
 3585|       |         * time. So, we only use pthread_atfork on Solaris 10 and later. For
 3586|       |         * earlier versions, we use PID checks.
 3587|       |         */
 3588|       |        char buf[200];
 3589|       |        int major = 0, minor = 0;
 3590|       |
 3591|       |        long rv = sysinfo(SI_RELEASE, buf, sizeof(buf));
 3592|       |        if (rv > 0 && rv < sizeof(buf)) {
 3593|       |            if (2 == sscanf(buf, "%d.%d", &major, &minor)) {
 3594|       |                /* Are we on Solaris 10 or greater ? */
 3595|       |                if (major > 5 || (5 == major && minor >= 10)) {
 3596|       |                    /* we are safe to use pthread_atfork */
 3597|       |                    usePthread_atfork = PR_TRUE;
 3598|       |                }
 3599|       |            }
 3600|       |        }
 3601|       |        if (usePthread_atfork) {
 3602|       |            pthread_atfork(NULL, NULL, ForkedChild);
 3603|       |        } else {
 3604|       |            myPid = getpid();
 3605|       |        }
 3606|       |
 3607|       |#elif defined(CHECK_FORK_PTHREAD)
 3608|       |        pthread_atfork(NULL, NULL, ForkedChild);
 3609|       |#elif defined(CHECK_FORK_GETPID)
 3610|       |        myPid = getpid();
 3611|       |#else
 3612|       |#error Incorrect fork check method.
 3613|       |#endif
 3614|       |    }
 3615|       |#endif
 3616|      1|    return crv;
 3617|      1|}
NSC_Initialize:
 3621|      1|{
 3622|      1|    CK_RV crv;
 3623|       |
 3624|      1|    sftk_ForkReset(pReserved, &crv);
 3625|       |
 3626|      1|    if (nsc_init) {
  ------------------
  |  Branch (3626:9): [True: 0, False: 1]
  ------------------
 3627|      0|        return CKR_CRYPTOKI_ALREADY_INITIALIZED;
  ------------------
  |  | 1521|      0|#define CKR_CRYPTOKI_ALREADY_INITIALIZED 0x00000191UL
  ------------------
 3628|      0|    }
 3629|      1|    crv = nsc_CommonInitialize(pReserved, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3630|      1|    nsc_init = (PRBool)(crv == CKR_OK);
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3631|      1|    return crv;
 3632|      1|}
nsc_CommonFinalize:
 3638|      1|{
 3639|       |    /* propagate the fork status to freebl and util */
 3640|      1|    BL_SetForkState(parentForkedAfterC_Initialize);
 3641|      1|    UTIL_SetForkState(parentForkedAfterC_Initialize);
 3642|       |
 3643|      1|    nscFreeAllSlots(isFIPS ? NSC_FIPS_MODULE : NSC_NON_FIPS_MODULE);
  ------------------
  |  |   54|      0|#define NSC_FIPS_MODULE 1
  ------------------
                  nscFreeAllSlots(isFIPS ? NSC_FIPS_MODULE : NSC_NON_FIPS_MODULE);
  ------------------
  |  |   55|      2|#define NSC_NON_FIPS_MODULE 0
  ------------------
  |  Branch (3643:21): [True: 0, False: 1]
  ------------------
 3644|       |
 3645|       |    /* don't muck with the globals if our peer is still initialized */
 3646|      1|    if (isFIPS && nsc_init) {
  ------------------
  |  Branch (3646:9): [True: 0, False: 1]
  |  Branch (3646:19): [True: 0, False: 0]
  ------------------
 3647|      0|        return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 3648|      0|    }
 3649|      1|    if (!isFIPS && nsf_init) {
  ------------------
  |  Branch (3649:9): [True: 1, False: 0]
  |  Branch (3649:20): [True: 0, False: 1]
  ------------------
 3650|      0|        return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 3651|      0|    }
 3652|       |
 3653|      1|    sftk_CleanupFreeLists();
 3654|      1|    sftkdb_Shutdown();
 3655|       |
 3656|       |    /* This function does not discard all our previously aquired entropy. */
 3657|      1|    RNG_RNGShutdown();
 3658|       |
 3659|       |    /* tell freeBL to clean up after itself */
 3660|      1|    BL_Cleanup();
 3661|       |
 3662|       |    /* reset fork status in freebl. We must do this before BL_Unload so that
 3663|       |     * this call doesn't force freebl to be reloaded. */
 3664|      1|    BL_SetForkState(PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3665|       |
 3666|       |#ifndef NSS_STATIC_SOFTOKEN
 3667|       |    /* unload freeBL shared library from memory. This may only decrement the
 3668|       |     * OS refcount if it's been loaded multiple times, eg. by libssl */
 3669|       |    BL_Unload();
 3670|       |#endif
 3671|       |
 3672|       |    /* clean up the default OID table */
 3673|      1|    SECOID_Shutdown();
 3674|       |
 3675|      1|    sftk_PBELockShutdown();
 3676|       |
 3677|       |    /* reset fork status in util */
 3678|      1|    UTIL_SetForkState(PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3679|       |
 3680|      1|    nsc_init = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3681|       |
 3682|       |#ifndef NO_FORK_CHECK
 3683|       |#ifdef CHECK_FORK_MIXED
 3684|       |    if (!usePthread_atfork) {
 3685|       |        myPid = 0; /* allow CHECK_FORK in the next softoken initialization to
 3686|       |                    * succeed */
 3687|       |    } else {
 3688|       |        forked = PR_FALSE; /* allow reinitialization */
 3689|       |    }
 3690|       |#elif defined(CHECK_FORK_GETPID)
 3691|       |    myPid = 0; /* allow reinitialization */
 3692|       |#elif defined(CHECK_FORK_PTHREAD)
 3693|       |    forked = PR_FALSE; /* allow reinitialization */
 3694|       |#endif
 3695|       |#endif
 3696|      1|    return CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3697|      1|}
sftk_ForkReset:
 3703|      2|{
 3704|       |#ifndef NO_FORK_CHECK
 3705|       |    if (PARENT_FORKED()) {
 3706|       |        parentForkedAfterC_Initialize = PR_TRUE;
 3707|       |        if (nsc_init) {
 3708|       |            /* finalize non-FIPS token */
 3709|       |            *crv = nsc_CommonFinalize(pReserved, PR_FALSE);
 3710|       |            PORT_Assert(CKR_OK == *crv);
 3711|       |            nsc_init = (PRBool) !(*crv == CKR_OK);
 3712|       |        }
 3713|       |        if (nsf_init) {
 3714|       |            /* finalize FIPS token */
 3715|       |            *crv = nsc_CommonFinalize(pReserved, PR_TRUE);
 3716|       |            PORT_Assert(CKR_OK == *crv);
 3717|       |            nsf_init = (PRBool) !(*crv == CKR_OK);
 3718|       |        }
 3719|       |        parentForkedAfterC_Initialize = PR_FALSE;
 3720|       |        return PR_TRUE;
 3721|       |    }
 3722|       |#endif
 3723|      2|    return PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 3724|      2|}
NSC_Finalize:
 3730|      1|{
 3731|      1|    CK_RV crv;
 3732|       |
 3733|       |    /* reset entire PKCS#11 module upon fork */
 3734|      1|    if (sftk_ForkReset(pReserved, &crv)) {
  ------------------
  |  Branch (3734:9): [True: 0, False: 1]
  ------------------
 3735|      0|        return crv;
 3736|      0|    }
 3737|       |
 3738|      1|    if (!nsc_init) {
  ------------------
  |  Branch (3738:9): [True: 0, False: 1]
  ------------------
 3739|      0|        return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 3740|      0|    }
 3741|       |
 3742|      1|    crv = nsc_CommonFinalize(pReserved, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3743|       |
 3744|      1|    nsc_init = (PRBool) !(crv == CKR_OK);
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3745|       |
 3746|      1|    return crv;
 3747|      1|}
NSC_GetInfo:
 3754|      1|{
 3755|      1|#define NSS_VERSION_VARIABLE __nss_softokn_version
 3756|      1|#include "verref.h"
  ------------------
  |  |    1|       |/* This Source Code Form is subject to the terms of the Mozilla Public
  |  |    2|       | * License, v. 2.0. If a copy of the MPL was not distributed with this
  |  |    3|       | * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
  |  |    4|       |
  |  |    5|       |/* This header is used inline in a function to ensure that a version string
  |  |    6|       | * symbol is linked in and not optimized out. A volatile reference is added to
  |  |    7|       | * the variable identified by NSS_VERSION_VARIABLE.
  |  |    8|       | *
  |  |    9|       | * Use this as follows:
  |  |   10|       | *
  |  |   11|       | * #define NSS_VERSION_VARIABLE __nss_ssl_version
  |  |   12|       | * #include "verref.h"
  |  |   13|       | */
  |  |   14|       |
  |  |   15|       |/* Suppress unused variable warnings. */
  |  |   16|       |#ifdef _MSC_VER
  |  |   17|       |#pragma warning(push)
  |  |   18|       |#pragma warning(disable : 4101)
  |  |   19|       |#endif
  |  |   20|       |/* This works for both gcc and clang */
  |  |   21|      1|#if defined(__GNUC__) && !defined(NSS_NO_GCC48)
  |  |   22|      1|#pragma GCC diagnostic push
  |  |   23|      1|#pragma GCC diagnostic ignored "-Wunused-variable"
  |  |   24|      1|#endif
  |  |   25|       |
  |  |   26|       |#ifndef NSS_VERSION_VARIABLE
  |  |   27|       |#error NSS_VERSION_VARIABLE must be set before including "verref.h"
  |  |   28|       |#endif
  |  |   29|      1|{
  |  |   30|      1|    extern const char NSS_VERSION_VARIABLE[];
  |  |   31|      1|#if defined(__GNUC__) || defined(__clang__)
  |  |   32|      1|    __attribute__((unused))
  |  |   33|      1|#endif
  |  |   34|      1|    volatile const char _nss_version_c = NSS_VERSION_VARIABLE[0];
  |  |  ------------------
  |  |  |  | 3755|      1|#define NSS_VERSION_VARIABLE __nss_softokn_version
  |  |  ------------------
  |  |   35|      1|}
  |  |   36|      1|#undef NSS_VERSION_VARIABLE
  |  |   37|       |
  |  |   38|       |#ifdef _MSC_VER
  |  |   39|       |#pragma warning(pop)
  |  |   40|       |#endif
  |  |   41|      1|#if defined(__GNUC__) && !defined(NSS_NO_GCC48)
  |  |   42|      1|#pragma GCC diagnostic pop
  |  |   43|      1|#endif
  ------------------
 3757|       |
 3758|      1|    CHECK_FORK();
 3759|       |
 3760|      1|    pInfo->cryptokiVersion.major = CRYPTOKI_VERSION_MAJOR;
  ------------------
  |  |   37|      1|#define CRYPTOKI_VERSION_MAJOR 3
  ------------------
 3761|      1|    pInfo->cryptokiVersion.minor = CRYPTOKI_VERSION_MINOR;
  ------------------
  |  |   38|      1|#define CRYPTOKI_VERSION_MINOR 1
  ------------------
 3762|      1|    PORT_Memcpy(pInfo->manufacturerID, manufacturerID, 32);
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
 3763|      1|    pInfo->libraryVersion.major = SOFTOKEN_VMAJOR;
  ------------------
  |  |   21|      1|#define SOFTOKEN_VMAJOR 3
  ------------------
 3764|      1|    pInfo->libraryVersion.minor = SOFTOKEN_VMINOR;
  ------------------
  |  |   22|      1|#define SOFTOKEN_VMINOR 111
  ------------------
 3765|      1|    PORT_Memcpy(pInfo->libraryDescription, libraryDescription, 32);
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
 3766|      1|    pInfo->flags = 0;
 3767|      1|    return CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3768|      1|}
nsc_CommonGetSlotList:
 3791|      2|{
 3792|      2|    *pulCount = nscSlotCount[moduleIndex];
 3793|      2|    if (pSlotList != NULL) {
  ------------------
  |  Branch (3793:9): [True: 1, False: 1]
  ------------------
 3794|      1|        PORT_Memcpy(pSlotList, nscSlotList[moduleIndex],
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
 3795|      1|                    nscSlotCount[moduleIndex] * sizeof(CK_SLOT_ID));
 3796|      1|    }
 3797|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 3798|      2|}
NSC_GetSlotList:
 3804|      2|{
 3805|      2|    CHECK_FORK();
 3806|      2|    return nsc_CommonGetSlotList(tokenPresent, pSlotList, pulCount,
 3807|      2|                                 NSC_NON_FIPS_MODULE);
  ------------------
  |  |   55|      2|#define NSC_NON_FIPS_MODULE 0
  ------------------
 3808|      2|}
NSC_GetSlotInfo:
 3813|      2|{
 3814|      2|    SFTKSlot *slot = sftk_SlotFromID(slotID, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 3815|       |
 3816|      2|    CHECK_FORK();
 3817|       |
 3818|      2|    if (slot == NULL)
  ------------------
  |  Branch (3818:9): [True: 0, False: 2]
  ------------------
 3819|      0|        return CKR_SLOT_ID_INVALID;
  ------------------
  |  | 1391|      0|#define CKR_SLOT_ID_INVALID 0x00000003UL
  ------------------
 3820|       |
 3821|      2|    PORT_Memcpy(pInfo->manufacturerID, manufacturerID,
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3822|      2|                sizeof(pInfo->manufacturerID));
 3823|      2|    PORT_Memcpy(pInfo->slotDescription, slot->slotDescription,
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3824|      2|                sizeof(pInfo->slotDescription));
 3825|      2|    pInfo->flags = (slot->present) ? CKF_TOKEN_PRESENT : 0;
  ------------------
  |  |  131|      2|#define CKF_TOKEN_PRESENT 0x00000001UL    /* a token is there */
  ------------------
  |  Branch (3825:20): [True: 2, False: 0]
  ------------------
 3826|       |
 3827|       |    /* all user defined slots are defined as removable */
 3828|      2|    if (slotID >= SFTK_MIN_USER_SLOT_ID) {
  ------------------
  |  |  565|      2|#define SFTK_MIN_USER_SLOT_ID 4
  ------------------
  |  Branch (3828:9): [True: 0, False: 2]
  ------------------
 3829|      0|        pInfo->flags |= CKF_REMOVABLE_DEVICE;
  ------------------
  |  |  132|      0|#define CKF_REMOVABLE_DEVICE 0x00000002UL /* removable devices*/
  ------------------
 3830|      2|    } else {
 3831|       |        /* In the case where we are doing a merge update, we need
 3832|       |         * the DB slot to be removable so the token name can change
 3833|       |         * appropriately. */
 3834|      2|        SFTKDBHandle *handle = sftk_getKeyDB(slot);
 3835|      2|        if (handle) {
  ------------------
  |  Branch (3835:13): [True: 0, False: 2]
  ------------------
 3836|      0|            if (sftkdb_InUpdateMerge(handle)) {
  ------------------
  |  Branch (3836:17): [True: 0, False: 0]
  ------------------
 3837|      0|                pInfo->flags |= CKF_REMOVABLE_DEVICE;
  ------------------
  |  |  132|      0|#define CKF_REMOVABLE_DEVICE 0x00000002UL /* removable devices*/
  ------------------
 3838|      0|            }
 3839|      0|            sftk_freeDB(handle);
 3840|      0|        }
 3841|      2|    }
 3842|       |
 3843|       |    /* If there is no key database, this is for example the case when NSS was
 3844|       |     * initialized with NSS_NoDbInit(), then there won't be any point in
 3845|       |     * requesting a PIN. Set the CKF_USER_PIN_INITIALIZED bit so that
 3846|       |     * PK11_NeedUserInit() doesn't indicate that a PIN is needed.
 3847|       |     */
 3848|      2|    if (slot->keyDB == NULL) {
  ------------------
  |  Branch (3848:9): [True: 2, False: 0]
  ------------------
 3849|      2|        pInfo->flags |= CKF_USER_PIN_INITIALIZED;
  ------------------
  |  |  178|      2|#define CKF_USER_PIN_INITIALIZED 0x00000008UL /* normal user's \
  ------------------
 3850|      2|    }
 3851|       |
 3852|       |    /* ok we really should read it out of the keydb file. */
 3853|       |    /* pInfo->hardwareVersion.major = NSSLOWKEY_DB_FILE_VERSION; */
 3854|      2|    pInfo->hardwareVersion.major = SOFTOKEN_VMAJOR;
  ------------------
  |  |   21|      2|#define SOFTOKEN_VMAJOR 3
  ------------------
 3855|      2|    pInfo->hardwareVersion.minor = SOFTOKEN_VMINOR;
  ------------------
  |  |   22|      2|#define SOFTOKEN_VMINOR 111
  ------------------
 3856|      2|    pInfo->firmwareVersion.major = SOFTOKEN_VPATCH;
  ------------------
  |  |   23|      2|#define SOFTOKEN_VPATCH 0
  ------------------
 3857|      2|    pInfo->firmwareVersion.minor = SOFTOKEN_VBUILD;
  ------------------
  |  |   24|      2|#define SOFTOKEN_VBUILD 0
  ------------------
 3858|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 3859|      2|}
NSC_GetTokenInfo:
 3898|      2|{
 3899|      2|    SFTKSlot *slot;
 3900|      2|    SFTKDBHandle *handle;
 3901|       |
 3902|      2|    CHECK_FORK();
 3903|       |
 3904|      2|    if (!nsc_init && !nsf_init)
  ------------------
  |  Branch (3904:9): [True: 0, False: 2]
  |  Branch (3904:22): [True: 0, False: 0]
  ------------------
 3905|      0|        return CKR_CRYPTOKI_NOT_INITIALIZED;
  ------------------
  |  | 1520|      0|#define CKR_CRYPTOKI_NOT_INITIALIZED 0x00000190UL
  ------------------
 3906|      2|    slot = sftk_SlotFromID(slotID, PR_FALSE);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 3907|      2|    if (slot == NULL)
  ------------------
  |  Branch (3907:9): [True: 0, False: 2]
  ------------------
 3908|      0|        return CKR_SLOT_ID_INVALID;
  ------------------
  |  | 1391|      0|#define CKR_SLOT_ID_INVALID 0x00000003UL
  ------------------
 3909|       |
 3910|      2|    PORT_Memcpy(pInfo->manufacturerID, manufacturerID, 32);
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3911|      2|    PORT_Memcpy(pInfo->model, "NSS 3           ", 16);
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3912|      2|    PORT_Memcpy(pInfo->serialNumber, "0000000000000000", 16);
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3913|      2|    PORT_Memcpy(pInfo->utcTime, "0000000000000000", 16);
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3914|      2|    pInfo->ulMaxSessionCount = 0;   /* arbitrarily large */
 3915|      2|    pInfo->ulMaxRwSessionCount = 0; /* arbitarily large */
 3916|      2|    PZ_Lock(slot->slotLock);        /* Protect sessionCount / rwSessioncount */
  ------------------
  |  |  245|      2|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 3917|      2|    pInfo->ulSessionCount = slot->sessionCount;
 3918|      2|    pInfo->ulRwSessionCount = slot->rwSessionCount;
 3919|      2|    PZ_Unlock(slot->slotLock); /* Unlock before sftk_getKeyDB */
  ------------------
  |  |  246|      2|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 3920|      2|    pInfo->firmwareVersion.major = 0;
 3921|      2|    pInfo->firmwareVersion.minor = 0;
 3922|      2|    PORT_Memcpy(pInfo->label, slot->tokDescription, sizeof(pInfo->label));
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
 3923|      2|    handle = sftk_getKeyDB(slot);
 3924|      2|    pInfo->flags = CKF_RNG | CKF_DUAL_CRYPTO_OPERATIONS;
  ------------------
  |  |  171|      2|#define CKF_RNG 0x00000001UL                  /* has random # \
  ------------------
                  pInfo->flags = CKF_RNG | CKF_DUAL_CRYPTO_OPERATIONS;
  ------------------
  |  |  202|      2|#define CKF_DUAL_CRYPTO_OPERATIONS 0x00000200UL
  ------------------
 3925|      2|    if (handle == NULL) {
  ------------------
  |  Branch (3925:9): [True: 2, False: 0]
  ------------------
 3926|      2|        pInfo->flags |= CKF_WRITE_PROTECTED;
  ------------------
  |  |  173|      2|#define CKF_WRITE_PROTECTED 0x00000002UL      /* token is \
  ------------------
 3927|      2|        pInfo->ulMaxPinLen = 0;
 3928|      2|        pInfo->ulMinPinLen = 0;
 3929|      2|        pInfo->ulTotalPublicMemory = 0;
 3930|      2|        pInfo->ulFreePublicMemory = 0;
 3931|      2|        pInfo->ulTotalPrivateMemory = 0;
 3932|      2|        pInfo->ulFreePrivateMemory = 0;
 3933|      2|        pInfo->hardwareVersion.major = 4;
 3934|      2|        pInfo->hardwareVersion.minor = 0;
 3935|      2|    } else {
 3936|       |        /*
 3937|       |         * we have three possible states which we may be in:
 3938|       |         *   (1) No DB password has been initialized. This also means we
 3939|       |         *   have no keys in the key db.
 3940|       |         *   (2) Password initialized to NULL. This means we have keys, but
 3941|       |         *   the user has chosen not use a password.
 3942|       |         *   (3) Finally we have an initialized password whicn is not NULL, and
 3943|       |         *   we will need to prompt for it.
 3944|       |         */
 3945|      0|        if (sftkdb_HasPasswordSet(handle) == SECFailure) {
  ------------------
  |  Branch (3945:13): [True: 0, False: 0]
  ------------------
 3946|      0|            pInfo->flags |= CKF_LOGIN_REQUIRED;
  ------------------
  |  |  176|      0|#define CKF_LOGIN_REQUIRED 0x00000004UL       /* user must \
  ------------------
 3947|      0|        } else if (!sftk_checkNeedLogin(slot, handle)) {
  ------------------
  |  Branch (3947:20): [True: 0, False: 0]
  ------------------
 3948|      0|            pInfo->flags |= CKF_USER_PIN_INITIALIZED;
  ------------------
  |  |  178|      0|#define CKF_USER_PIN_INITIALIZED 0x00000008UL /* normal user's \
  ------------------
 3949|      0|        } else {
 3950|      0|            pInfo->flags |= CKF_LOGIN_REQUIRED | CKF_USER_PIN_INITIALIZED;
  ------------------
  |  |  176|      0|#define CKF_LOGIN_REQUIRED 0x00000004UL       /* user must \
  ------------------
                          pInfo->flags |= CKF_LOGIN_REQUIRED | CKF_USER_PIN_INITIALIZED;
  ------------------
  |  |  178|      0|#define CKF_USER_PIN_INITIALIZED 0x00000008UL /* normal user's \
  ------------------
 3951|       |            /*
 3952|       |             * if we are doing a merge style update, and we need to get the password
 3953|       |             * of our source database (the database we are updating from), make sure we
 3954|       |             * return a token name that will match the database we are prompting for.
 3955|       |             */
 3956|      0|            if (sftkdb_NeedUpdateDBPassword(handle)) {
  ------------------
  |  Branch (3956:17): [True: 0, False: 0]
  ------------------
 3957|       |                /* if we have an update tok description, use it. otherwise
 3958|       |                 * use the updateID for this database */
 3959|      0|                if (!sftk_isBlank(slot->updateTokDescription,
  ------------------
  |  Branch (3959:21): [True: 0, False: 0]
  ------------------
 3960|      0|                                  sizeof(pInfo->label))) {
 3961|      0|                    PORT_Memcpy(pInfo->label, slot->updateTokDescription,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 3962|      0|                                sizeof(pInfo->label));
 3963|      0|                } else {
 3964|       |                    /* build from updateID */
 3965|      0|                    const char *updateID = sftkdb_GetUpdateID(handle);
 3966|      0|                    if (updateID) {
  ------------------
  |  Branch (3966:25): [True: 0, False: 0]
  ------------------
 3967|      0|                        sftk_setStringName(updateID, (char *)pInfo->label,
 3968|      0|                                           sizeof(pInfo->label), PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3969|      0|                    }
 3970|      0|                }
 3971|      0|            }
 3972|      0|        }
 3973|      0|        pInfo->ulMaxPinLen = SFTK_MAX_PIN;
  ------------------
  |  |  493|      0|#define SFTK_MAX_PIN 500
  ------------------
 3974|      0|        pInfo->ulMinPinLen = (CK_ULONG)slot->minimumPinLen;
 3975|      0|        pInfo->ulTotalPublicMemory = 1;
 3976|      0|        pInfo->ulFreePublicMemory = 1;
 3977|      0|        pInfo->ulTotalPrivateMemory = 1;
 3978|      0|        pInfo->ulFreePrivateMemory = 1;
 3979|       |#ifdef SHDB_FIXME
 3980|       |        pInfo->hardwareVersion.major = CERT_DB_FILE_VERSION;
 3981|       |        pInfo->hardwareVersion.minor = handle->version;
 3982|       |#else
 3983|      0|        pInfo->hardwareVersion.major = 0;
 3984|      0|        pInfo->hardwareVersion.minor = 0;
 3985|      0|#endif
 3986|      0|        sftk_freeDB(handle);
 3987|      0|    }
 3988|       |    /*
 3989|       |     * CKF_LOGIN_REQUIRED CKF_USER_PIN_INITIALIZED  how CKF_TOKEN_INITIALIZED
 3990|       |     *                                              should be set
 3991|       |     *         0                   0                           1
 3992|       |     *         1                   0                           0
 3993|       |     *         0                   1                           1
 3994|       |     *         1                   1                           1
 3995|       |     */
 3996|      2|    if (!(pInfo->flags & CKF_LOGIN_REQUIRED) ||
  ------------------
  |  |  176|      2|#define CKF_LOGIN_REQUIRED 0x00000004UL       /* user must \
  ------------------
  |  Branch (3996:9): [True: 2, False: 0]
  ------------------
 3997|      2|        (pInfo->flags & CKF_USER_PIN_INITIALIZED)) {
  ------------------
  |  |  178|      0|#define CKF_USER_PIN_INITIALIZED 0x00000008UL /* normal user's \
  ------------------
  |  Branch (3997:9): [True: 0, False: 0]
  ------------------
 3998|      2|        pInfo->flags |= CKF_TOKEN_INITIALIZED;
  ------------------
  |  |  209|      2|#define CKF_TOKEN_INITIALIZED 0x00000400UL
  ------------------
 3999|      2|    }
 4000|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 4001|      2|}
NSC_GetMechanismList:
 4008|      4|{
 4009|      4|    CK_ULONG i;
 4010|       |
 4011|      4|    CHECK_FORK();
 4012|       |
 4013|      4|    switch (slotID) {
 4014|       |        /* default: */
 4015|      2|        case NETSCAPE_SLOT_ID:
  ------------------
  |  |  498|      2|#define NETSCAPE_SLOT_ID 1
  ------------------
  |  Branch (4015:9): [True: 2, False: 2]
  ------------------
 4016|      2|            *pulCount = mechanismCount;
 4017|      2|            if (pMechanismList != NULL) {
  ------------------
  |  Branch (4017:17): [True: 1, False: 1]
  ------------------
 4018|    231|                for (i = 0; i < mechanismCount; i++) {
  ------------------
  |  Branch (4018:29): [True: 230, False: 1]
  ------------------
 4019|    230|                    pMechanismList[i] = mechanisms[i].type;
 4020|    230|                }
 4021|      1|            }
 4022|      2|            break;
 4023|      2|        default:
  ------------------
  |  Branch (4023:9): [True: 2, False: 2]
  ------------------
 4024|      2|            *pulCount = 0;
 4025|    462|            for (i = 0; i < mechanismCount; i++) {
  ------------------
  |  Branch (4025:25): [True: 460, False: 2]
  ------------------
 4026|    460|                if (mechanisms[i].privkey) {
  ------------------
  |  Branch (4026:21): [True: 354, False: 106]
  ------------------
 4027|    354|                    (*pulCount)++;
 4028|    354|                    if (pMechanismList != NULL) {
  ------------------
  |  Branch (4028:25): [True: 177, False: 177]
  ------------------
 4029|    177|                        *pMechanismList++ = mechanisms[i].type;
 4030|    177|                    }
 4031|    354|                }
 4032|    460|            }
 4033|      2|            break;
 4034|      4|    }
 4035|      4|    return CKR_OK;
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
 4036|      4|}
NSC_GetMechanismInfo:
 4043|   381k|{
 4044|   381k|    PRBool isPrivateKey;
 4045|   381k|    CK_ULONG i;
 4046|       |
 4047|   381k|    CHECK_FORK();
 4048|       |
 4049|   381k|    switch (slotID) {
 4050|   378k|        case NETSCAPE_SLOT_ID:
  ------------------
  |  |  498|   378k|#define NETSCAPE_SLOT_ID 1
  ------------------
  |  Branch (4050:9): [True: 378k, False: 2.99k]
  ------------------
 4051|   378k|            isPrivateKey = PR_FALSE;
  ------------------
  |  |  438|   378k|#define PR_FALSE 0
  ------------------
 4052|   378k|            break;
 4053|  2.99k|        default:
  ------------------
  |  Branch (4053:9): [True: 2.99k, False: 378k]
  ------------------
 4054|  2.99k|            isPrivateKey = PR_TRUE;
  ------------------
  |  |  437|  2.99k|#define PR_TRUE 1
  ------------------
 4055|  2.99k|            break;
 4056|   381k|    }
 4057|  26.9M|    for (i = 0; i < mechanismCount; i++) {
  ------------------
  |  Branch (4057:17): [True: 26.9M, False: 0]
  ------------------
 4058|  26.9M|        if (type == mechanisms[i].type) {
  ------------------
  |  Branch (4058:13): [True: 381k, False: 26.5M]
  ------------------
 4059|   381k|            if (isPrivateKey && !mechanisms[i].privkey) {
  ------------------
  |  Branch (4059:17): [True: 2.99k, False: 378k]
  |  Branch (4059:33): [True: 0, False: 2.99k]
  ------------------
 4060|      0|                return CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4061|      0|            }
 4062|   381k|            PORT_Memcpy(pInfo, &mechanisms[i].info, sizeof(CK_MECHANISM_INFO));
  ------------------
  |  |  180|   381k|#define PORT_Memcpy memcpy
  ------------------
 4063|   381k|            return CKR_OK;
  ------------------
  |  | 1388|   381k|#define CKR_OK 0x00000000UL
  ------------------
 4064|   381k|        }
 4065|  26.9M|    }
 4066|      0|    return CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4067|   381k|}
sftk_MechAllowsOperation:
 4087|   434k|{
 4088|   434k|    CK_ULONG i;
 4089|   434k|    CK_FLAGS flags = sftk_AttributeToFlags(op);
 4090|       |
 4091|   434k|    if (flags == 0) {
  ------------------
  |  Branch (4091:9): [True: 0, False: 434k]
  ------------------
 4092|      0|        return CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 4093|      0|    }
 4094|  30.3M|    for (i = 0; i < mechanismCount; i++) {
  ------------------
  |  Branch (4094:17): [True: 30.3M, False: 0]
  ------------------
 4095|  30.3M|        if (type == mechanisms[i].type) {
  ------------------
  |  Branch (4095:13): [True: 434k, False: 29.9M]
  ------------------
 4096|   434k|            return (flags & mechanisms[i].info.flags) ? CKR_OK
  ------------------
  |  | 1388|   434k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4096:20): [True: 434k, False: 0]
  ------------------
 4097|   434k|                                                      : CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4098|   434k|        }
 4099|  30.3M|    }
 4100|      0|    return CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4101|   434k|}
NSC_OpenSession:
 4381|   869k|{
 4382|   869k|    SFTKSlot *slot;
 4383|   869k|    CK_SESSION_HANDLE sessionID;
 4384|   869k|    SFTKSession *session;
 4385|   869k|    SFTKSession *sameID;
 4386|       |
 4387|   869k|    CHECK_FORK();
 4388|       |
 4389|   869k|    slot = sftk_SlotFromID(slotID, PR_FALSE);
  ------------------
  |  |  438|   869k|#define PR_FALSE 0
  ------------------
 4390|   869k|    if (slot == NULL)
  ------------------
  |  Branch (4390:9): [True: 0, False: 869k]
  ------------------
 4391|      0|        return CKR_SLOT_ID_INVALID;
  ------------------
  |  | 1391|      0|#define CKR_SLOT_ID_INVALID 0x00000003UL
  ------------------
 4392|       |
 4393|       |    /* new session (we only have serial sessions) */
 4394|   869k|    session = sftk_NewSession(slotID, Notify, pApplication,
 4395|   869k|                              flags | CKF_SERIAL_SESSION);
  ------------------
  |  |  303|   869k|#define CKF_SERIAL_SESSION 0x00000004UL /* no parallel */
  ------------------
 4396|   869k|    if (session == NULL)
  ------------------
  |  Branch (4396:9): [True: 0, False: 869k]
  ------------------
 4397|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 4398|       |
 4399|   869k|    if (slot->readOnly && (flags & CKF_RW_SESSION)) {
  ------------------
  |  |  302|  2.99k|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (4399:9): [True: 2.99k, False: 866k]
  |  Branch (4399:27): [True: 0, False: 2.99k]
  ------------------
 4400|       |        /* NETSCAPE_SLOT_ID is Read ONLY */
 4401|      0|        session->info.flags &= ~CKF_RW_SESSION;
  ------------------
  |  |  302|      0|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
 4402|      0|    }
 4403|   869k|    PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|   869k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 4404|   869k|    ++slot->sessionCount;
 4405|   869k|    PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|   869k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 4406|   869k|    if (session->info.flags & CKF_RW_SESSION) {
  ------------------
  |  |  302|   869k|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (4406:9): [True: 0, False: 869k]
  ------------------
 4407|      0|        (void)PR_ATOMIC_INCREMENT(&slot->rwSessionCount);
  ------------------
  |  |  122|      0|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
 4408|      0|    }
 4409|       |
 4410|   869k|    do {
 4411|   869k|        PZLock *lock;
  ------------------
  |  |  185|   869k|#define PZLock PRLock
  ------------------
 4412|   869k|        do {
 4413|   869k|            sessionID = (PR_ATOMIC_INCREMENT(&slot->sessionIDCount) & 0xffffff) | (slot->index << 24);
  ------------------
  |  |  122|   869k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
 4414|   869k|        } while (sessionID == CK_INVALID_HANDLE);
  ------------------
  |  |   78|   869k|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (4414:18): [True: 0, False: 869k]
  ------------------
 4415|   869k|        lock = SFTK_SESSION_LOCK(slot, sessionID);
  ------------------
  |  |  583|   869k|    ((slot)->sessionLock[(handle) & (slot)->sessionLockMask])
  ------------------
 4416|   869k|        PZ_Lock(lock);
  ------------------
  |  |  245|   869k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 4417|   869k|        sftkqueue_find(sameID, sessionID, slot->head, slot->sessHashSize);
  ------------------
  |  |  524|  1.30M|    for ((element) = (head)[sftk_hash(id, hash_size)]; (element) != NULL; \
  |  |  ------------------
  |  |  |  |  513|   869k|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|   869k|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (524:56): [True: 439k, False: 869k]
  |  |  ------------------
  |  |  525|   869k|         (element) = (element)->next) {                                   \
  |  |  526|   439k|        if ((element)->handle == (id)) {                                  \
  |  |  ------------------
  |  |  |  Branch (526:13): [True: 0, False: 439k]
  |  |  ------------------
  |  |  527|      0|            break;                                                        \
  |  |  528|      0|        }                                                                 \
  |  |  529|   439k|    }
  ------------------
 4418|   869k|        if (sameID == NULL) {
  ------------------
  |  Branch (4418:13): [True: 869k, False: 0]
  ------------------
 4419|   869k|            session->handle = sessionID;
 4420|   869k|            sftk_update_state(slot, session);
 4421|   869k|            sftkqueue_add(session, sessionID, slot->head, slot->sessHashSize);
  ------------------
  |  |  515|   869k|    {                                               \
  |  |  516|   869k|        int tmp = sftk_hash(id, hash_size);         \
  |  |  ------------------
  |  |  |  |  513|   869k|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|   869k|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  517|   869k|        (element)->next = (head)[tmp];              \
  |  |  518|   869k|        (element)->prev = NULL;                     \
  |  |  519|   869k|        if ((head)[tmp])                            \
  |  |  ------------------
  |  |  |  Branch (519:13): [True: 276k, False: 593k]
  |  |  ------------------
  |  |  520|   869k|            (head)[tmp]->prev = (element);          \
  |  |  521|   869k|        (head)[tmp] = (element);                    \
  |  |  522|   869k|    }
  ------------------
 4422|   869k|        } else {
 4423|      0|            slot->sessionIDConflict++; /* for debugging */
 4424|      0|        }
 4425|   869k|        PZ_Unlock(lock);
  ------------------
  |  |  246|   869k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 4426|   869k|    } while (sameID != NULL);
  ------------------
  |  Branch (4426:14): [True: 0, False: 869k]
  ------------------
 4427|       |
 4428|   869k|    *phSession = sessionID;
 4429|   869k|    return CKR_OK;
  ------------------
  |  | 1388|   869k|#define CKR_OK 0x00000000UL
  ------------------
 4430|   869k|}
NSC_CloseSession:
 4435|   869k|{
 4436|   869k|    SFTKSlot *slot;
 4437|   869k|    SFTKSession *session;
 4438|   869k|    PRBool sessionFound;
 4439|   869k|    PZLock *lock;
  ------------------
  |  |  185|   869k|#define PZLock PRLock
  ------------------
 4440|       |
 4441|   869k|    CHECK_FORK();
 4442|       |
 4443|   869k|    session = sftk_SessionFromHandle(hSession);
 4444|   869k|    if (session == NULL)
  ------------------
  |  Branch (4444:9): [True: 0, False: 869k]
  ------------------
 4445|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4446|   869k|    slot = sftk_SlotFromSession(session);
  ------------------
  |  |  503|   869k|#define sftk_SlotFromSession(sp) ((sp)->slot)
  ------------------
 4447|   869k|    sessionFound = PR_FALSE;
  ------------------
  |  |  438|   869k|#define PR_FALSE 0
  ------------------
 4448|       |
 4449|       |    /* lock */
 4450|   869k|    lock = SFTK_SESSION_LOCK(slot, hSession);
  ------------------
  |  |  583|   869k|    ((slot)->sessionLock[(handle) & (slot)->sessionLockMask])
  ------------------
 4451|   869k|    PZ_Lock(lock);
  ------------------
  |  |  245|   869k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 4452|   869k|    if (sftkqueue_is_queued(session, hSession, slot->head, slot->sessHashSize)) {
  ------------------
  |  |  531|   869k|    (((element)->next) || ((element)->prev) ||            \
  |  |  ------------------
  |  |  |  Branch (531:6): [True: 275k, False: 593k]
  |  |  |  Branch (531:27): [True: 47, False: 593k]
  |  |  ------------------
  |  |  532|   869k|     ((head)[sftk_hash(id, hash_size)] == (element)))
  |  |  ------------------
  |  |  |  |  513|   593k|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|   593k|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (532:6): [True: 593k, False: 0]
  |  |  ------------------
  ------------------
 4453|   869k|        sessionFound = PR_TRUE;
  ------------------
  |  |  437|   869k|#define PR_TRUE 1
  ------------------
 4454|   869k|        sftkqueue_delete(session, hSession, slot->head, slot->sessHashSize);
  ------------------
  |  |  534|   869k|    if ((element)->next)                                      \
  |  |  ------------------
  |  |  |  Branch (534:9): [True: 275k, False: 593k]
  |  |  ------------------
  |  |  535|   869k|        (element)->next->prev = (element)->prev;              \
  |  |  536|   869k|    if ((element)->prev)                                      \
  |  |  ------------------
  |  |  |  Branch (536:9): [True: 58, False: 869k]
  |  |  ------------------
  |  |  537|   869k|        (element)->prev->next = (element)->next;              \
  |  |  538|   869k|    else                                                      \
  |  |  539|   869k|        (head)[sftk_hash(id, hash_size)] = ((element)->next); \
  |  |  ------------------
  |  |  |  |  513|   869k|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|   869k|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  540|   869k|    (element)->next = NULL;                                   \
  |  |  541|   869k|    (element)->prev = NULL;
  ------------------
 4455|   869k|    }
 4456|   869k|    PZ_Unlock(lock);
  ------------------
  |  |  246|   869k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 4457|       |
 4458|   869k|    if (sessionFound) {
  ------------------
  |  Branch (4458:9): [True: 869k, False: 0]
  ------------------
 4459|   869k|        SFTKDBHandle *handle;
 4460|   869k|        handle = sftk_getKeyDB(slot);
 4461|   869k|        PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|   869k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 4462|   869k|        if (--slot->sessionCount == 0) {
  ------------------
  |  Branch (4462:13): [True: 0, False: 869k]
  ------------------
 4463|      0|            slot->isLoggedIn = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4464|      0|            if (slot->needLogin && handle) {
  ------------------
  |  Branch (4464:17): [True: 0, False: 0]
  |  Branch (4464:36): [True: 0, False: 0]
  ------------------
 4465|      0|                sftkdb_ClearPassword(handle);
 4466|      0|            }
 4467|      0|        }
 4468|   869k|        PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|   869k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 4469|   869k|        if (handle) {
  ------------------
  |  Branch (4469:13): [True: 0, False: 869k]
  ------------------
 4470|      0|            sftk_freeDB(handle);
 4471|      0|        }
 4472|   869k|        if (session->info.flags & CKF_RW_SESSION) {
  ------------------
  |  |  302|   869k|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (4472:13): [True: 0, False: 869k]
  ------------------
 4473|      0|            (void)PR_ATOMIC_DECREMENT(&slot->rwSessionCount);
  ------------------
  |  |  123|      0|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
 4474|      0|        }
 4475|   869k|        sftk_DestroySession(session);
 4476|   869k|        session = NULL;
 4477|   869k|    }
 4478|       |
 4479|   869k|    return CKR_OK;
  ------------------
  |  | 1388|   869k|#define CKR_OK 0x00000000UL
  ------------------
 4480|   869k|}
NSC_CloseAllSessions:
 4485|      4|{
 4486|      4|    SFTKSlot *slot;
 4487|       |
 4488|       |#ifndef NO_FORK_CHECK
 4489|       |    /* skip fork check if we are being called from C_Initialize or C_Finalize */
 4490|       |    if (!parentForkedAfterC_Initialize) {
 4491|       |        CHECK_FORK();
 4492|       |    }
 4493|       |#endif
 4494|       |
 4495|      4|    slot = sftk_SlotFromID(slotID, PR_FALSE);
  ------------------
  |  |  438|      4|#define PR_FALSE 0
  ------------------
 4496|      4|    if (slot == NULL)
  ------------------
  |  Branch (4496:9): [True: 0, False: 4]
  ------------------
 4497|      0|        return CKR_SLOT_ID_INVALID;
  ------------------
  |  | 1391|      0|#define CKR_SLOT_ID_INVALID 0x00000003UL
  ------------------
 4498|       |
 4499|      4|    return sftk_CloseAllSessions(slot, PR_TRUE);
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
 4500|      4|}
NSC_CreateObject:
 4815|  6.77k|{
 4816|  6.77k|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 4817|  6.77k|    SFTKSession *session;
 4818|  6.77k|    SFTKObject *object;
 4819|       |    /* make sure class isn't randomly CKO_NSS_NEWSLOT or
 4820|       |     * CKO_NETSCPE_DELSLOT. */
 4821|  6.77k|    CK_OBJECT_CLASS class = CKO_VENDOR_DEFINED;
  ------------------
  |  |  335|  6.77k|#define CKO_VENDOR_DEFINED 0x80000000UL
  ------------------
 4822|  6.77k|    CK_RV crv;
 4823|  6.77k|    int i;
 4824|       |
 4825|  6.77k|    CHECK_FORK();
 4826|       |
 4827|  6.77k|    *phObject = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  6.77k|#define CK_INVALID_HANDLE 0
  ------------------
 4828|       |
 4829|  6.77k|    if (slot == NULL) {
  ------------------
  |  Branch (4829:9): [True: 0, False: 6.77k]
  ------------------
 4830|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4831|      0|    }
 4832|       |    /*
 4833|       |     * now lets create an object to hang the attributes off of
 4834|       |     */
 4835|  6.77k|    object = sftk_NewObject(slot); /* fill in the handle later */
 4836|  6.77k|    if (object == NULL) {
  ------------------
  |  Branch (4836:9): [True: 0, False: 6.77k]
  ------------------
 4837|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 4838|      0|    }
 4839|       |
 4840|       |    /*
 4841|       |     * sftk_NewObject will set object->isFIPS to PR_TRUE if the slot is FIPS.
 4842|       |     * We don't need to worry about that here, as FC_CreateObject will always
 4843|       |     * disallow the import of secret and private keys, regardless of isFIPS
 4844|       |     * approval status. Therefore, at this point we know that the key is a
 4845|       |     * public key, which is acceptable to be imported in plaintext.
 4846|       |     */
 4847|       |
 4848|       |    /*
 4849|       |     * load the template values into the object
 4850|       |     */
 4851|  41.1k|    for (i = 0; i < (int)ulCount; i++) {
  ------------------
  |  Branch (4851:17): [True: 34.3k, False: 6.77k]
  ------------------
 4852|  34.3k|        crv = sftk_AddAttributeType(object, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|  34.3k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 4853|  34.3k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  34.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4853:13): [True: 0, False: 34.3k]
  ------------------
 4854|      0|            sftk_FreeObject(object);
 4855|      0|            return crv;
 4856|      0|        }
 4857|  34.3k|        if ((pTemplate[i].type == CKA_CLASS) && pTemplate[i].pValue) {
  ------------------
  |  |  511|  34.3k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (4857:13): [True: 6.77k, False: 27.6k]
  |  Branch (4857:49): [True: 6.77k, False: 0]
  ------------------
 4858|  6.77k|            class = *(CK_OBJECT_CLASS *)pTemplate[i].pValue;
 4859|  6.77k|        }
 4860|  34.3k|    }
 4861|       |
 4862|       |    /* get the session */
 4863|  6.77k|    session = sftk_SessionFromHandle(hSession);
 4864|  6.77k|    if (session == NULL) {
  ------------------
  |  Branch (4864:9): [True: 0, False: 6.77k]
  ------------------
 4865|      0|        sftk_FreeObject(object);
 4866|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4867|      0|    }
 4868|       |
 4869|       |    /*
 4870|       |     * handle pseudo objects (CKO_NEWSLOT)
 4871|       |     */
 4872|  6.77k|    if ((class == CKO_NSS_NEWSLOT) || (class == CKO_NSS_DELSLOT)) {
  ------------------
  |  |   39|  6.77k|#define CKO_NSS_NEWSLOT (CKO_NSS + 5)
  |  |  ------------------
  |  |  |  |   33|  6.77k|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|  6.77k|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  6.77k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  if ((class == CKO_NSS_NEWSLOT) || (class == CKO_NSS_DELSLOT)) {
  ------------------
  |  |   40|  6.77k|#define CKO_NSS_DELSLOT (CKO_NSS + 6)
  |  |  ------------------
  |  |  |  |   33|  6.77k|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|  6.77k|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  6.77k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4872:9): [True: 0, False: 6.77k]
  |  Branch (4872:39): [True: 0, False: 6.77k]
  ------------------
 4873|      0|        crv = sftk_CreateNewSlot(slot, class, object);
 4874|      0|        goto done;
 4875|      0|    }
 4876|       |
 4877|       |    /*
 4878|       |     * handle the base object stuff
 4879|       |     */
 4880|  6.77k|    crv = sftk_handleObject(object, session);
 4881|  6.77k|    *phObject = object->handle;
 4882|  6.77k|done:
 4883|  6.77k|    sftk_FreeSession(session);
 4884|  6.77k|    sftk_FreeObject(object);
 4885|       |
 4886|  6.77k|    return crv;
 4887|  6.77k|}
NSC_CopyObject:
 4894|      4|{
 4895|      4|    SFTKObject *destObject, *srcObject;
 4896|      4|    SFTKSession *session;
 4897|      4|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
 4898|      4|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 4899|      4|    int i;
 4900|       |
 4901|      4|    CHECK_FORK();
 4902|       |
 4903|      4|    if (slot == NULL) {
  ------------------
  |  Branch (4903:9): [True: 0, False: 4]
  ------------------
 4904|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4905|      0|    }
 4906|       |    /* Get srcObject so we can find the class */
 4907|      4|    session = sftk_SessionFromHandle(hSession);
 4908|      4|    if (session == NULL) {
  ------------------
  |  Branch (4908:9): [True: 0, False: 4]
  ------------------
 4909|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4910|      0|    }
 4911|      4|    srcObject = sftk_ObjectFromHandle(hObject, session);
 4912|      4|    if (srcObject == NULL) {
  ------------------
  |  Branch (4912:9): [True: 0, False: 4]
  ------------------
 4913|      0|        sftk_FreeSession(session);
 4914|      0|        return CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
 4915|      0|    }
 4916|       |    /*
 4917|       |     * create an object to hang the attributes off of
 4918|       |     */
 4919|      4|    destObject = sftk_NewObject(slot); /* fill in the handle later */
 4920|      4|    if (destObject == NULL) {
  ------------------
  |  Branch (4920:9): [True: 0, False: 4]
  ------------------
 4921|      0|        sftk_FreeSession(session);
 4922|      0|        sftk_FreeObject(srcObject);
 4923|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 4924|      0|    }
 4925|       |
 4926|       |    /*
 4927|       |     * load the template values into the object
 4928|       |     */
 4929|      6|    for (i = 0; i < (int)ulCount; i++) {
  ------------------
  |  Branch (4929:17): [True: 2, False: 4]
  ------------------
 4930|      2|        if (sftk_modifyType(pTemplate[i].type, srcObject->objclass) == SFTK_NEVER) {
  ------------------
  |  Branch (4930:13): [True: 0, False: 2]
  ------------------
 4931|      0|            crv = CKR_ATTRIBUTE_READ_ONLY;
  ------------------
  |  | 1406|      0|#define CKR_ATTRIBUTE_READ_ONLY 0x00000010UL
  ------------------
 4932|      0|            break;
 4933|      0|        }
 4934|      2|        crv = sftk_AddAttributeType(destObject, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|      2|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 4935|      2|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4935:13): [True: 0, False: 2]
  ------------------
 4936|      0|            break;
 4937|      0|        }
 4938|      2|    }
 4939|      4|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4939:9): [True: 0, False: 4]
  ------------------
 4940|      0|        sftk_FreeSession(session);
 4941|      0|        sftk_FreeObject(srcObject);
 4942|      0|        sftk_FreeObject(destObject);
 4943|      0|        return crv;
 4944|      0|    }
 4945|       |
 4946|       |    /* sensitive can only be changed to CK_TRUE */
 4947|      4|    if (sftk_hasAttribute(destObject, CKA_SENSITIVE)) {
  ------------------
  |  |  546|      4|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (4947:9): [True: 0, False: 4]
  ------------------
 4948|      0|        if (!sftk_isTrue(destObject, CKA_SENSITIVE)) {
  ------------------
  |  |  546|      0|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (4948:13): [True: 0, False: 0]
  ------------------
 4949|      0|            sftk_FreeSession(session);
 4950|      0|            sftk_FreeObject(srcObject);
 4951|      0|            sftk_FreeObject(destObject);
 4952|      0|            return CKR_ATTRIBUTE_READ_ONLY;
  ------------------
  |  | 1406|      0|#define CKR_ATTRIBUTE_READ_ONLY 0x00000010UL
  ------------------
 4953|      0|        }
 4954|      0|    }
 4955|       |
 4956|       |    /*
 4957|       |     * now copy the old attributes from the new attributes
 4958|       |     */
 4959|       |    /* don't create a token object if we aren't in a rw session */
 4960|       |    /* we need to hold the lock to copy a consistant version of
 4961|       |     * the object. */
 4962|      4|    crv = sftk_CopyObject(destObject, srcObject);
 4963|       |
 4964|      4|    destObject->objclass = srcObject->objclass;
 4965|      4|    sftk_FreeObject(srcObject);
 4966|      4|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4966:9): [True: 0, False: 4]
  ------------------
 4967|      0|        sftk_FreeObject(destObject);
 4968|      0|        sftk_FreeSession(session);
 4969|      0|        return crv;
 4970|      0|    }
 4971|       |
 4972|      4|    crv = sftk_handleObject(destObject, session);
 4973|      4|    *phNewObject = destObject->handle;
 4974|      4|    sftk_FreeSession(session);
 4975|      4|    sftk_FreeObject(destObject);
 4976|       |
 4977|      4|    return crv;
 4978|      4|}
NSC_GetAttributeValue:
 5033|  1.03M|{
 5034|  1.03M|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 5035|  1.03M|    SFTKSession *session;
 5036|  1.03M|    SFTKObject *object;
 5037|  1.03M|    SFTKAttribute *attribute;
 5038|  1.03M|    PRBool sensitive, isLoggedIn, needLogin;
 5039|  1.03M|    CK_RV crv;
 5040|  1.03M|    int i;
 5041|       |
 5042|  1.03M|    CHECK_FORK();
 5043|       |
 5044|  1.03M|    if (slot == NULL) {
  ------------------
  |  Branch (5044:9): [True: 0, False: 1.03M]
  ------------------
 5045|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5046|      0|    }
 5047|       |    /*
 5048|       |     * make sure we're allowed
 5049|       |     */
 5050|  1.03M|    session = sftk_SessionFromHandle(hSession);
 5051|  1.03M|    if (session == NULL) {
  ------------------
  |  Branch (5051:9): [True: 0, False: 1.03M]
  ------------------
 5052|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5053|      0|    }
 5054|       |
 5055|       |    /* short circuit everything for token objects */
 5056|  1.03M|    if (sftk_isToken(hObject)) {
  ------------------
  |  |  504|  1.03M|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|  1.03M|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|  1.03M|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  |  |  |  Branch (504:26): [True: 0, False: 1.03M]
  |  |  ------------------
  ------------------
 5057|      0|        crv = nsc_GetTokenAttributeValue(session, hObject, pTemplate, ulCount);
 5058|      0|        sftk_FreeSession(session);
 5059|      0|        return crv;
 5060|      0|    }
 5061|       |
 5062|       |    /* handle the session object */
 5063|  1.03M|    object = sftk_ObjectFromHandle(hObject, session);
 5064|  1.03M|    sftk_FreeSession(session);
 5065|  1.03M|    if (object == NULL) {
  ------------------
  |  Branch (5065:9): [True: 0, False: 1.03M]
  ------------------
 5066|      0|        return CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
 5067|      0|    }
 5068|       |
 5069|  1.03M|    PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|  1.03M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 5070|  1.03M|    isLoggedIn = slot->isLoggedIn;
 5071|  1.03M|    needLogin = slot->needLogin;
 5072|  1.03M|    PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|  1.03M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 5073|       |
 5074|       |    /* don't read a private object if we aren't logged in */
 5075|  1.03M|    if (!isLoggedIn && needLogin && sftk_isTrue(object, CKA_PRIVATE)) {
  ------------------
  |  |  513|      0|#define CKA_PRIVATE 0x00000002UL
  ------------------
  |  Branch (5075:9): [True: 1.03M, False: 0]
  |  Branch (5075:24): [True: 0, False: 1.03M]
  |  Branch (5075:37): [True: 0, False: 0]
  ------------------
 5076|      0|        sftk_FreeObject(object);
 5077|      0|        return CKR_USER_NOT_LOGGED_IN;
  ------------------
  |  | 1486|      0|#define CKR_USER_NOT_LOGGED_IN 0x00000101UL
  ------------------
 5078|      0|    }
 5079|       |
 5080|  1.03M|    crv = CKR_OK;
  ------------------
  |  | 1388|  1.03M|#define CKR_OK 0x00000000UL
  ------------------
 5081|  1.03M|    sensitive = sftk_isTrue(object, CKA_SENSITIVE);
  ------------------
  |  |  546|  1.03M|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 5082|  2.41M|    for (i = 0; i < (int)ulCount; i++) {
  ------------------
  |  Branch (5082:17): [True: 1.37M, False: 1.03M]
  ------------------
 5083|       |        /* Make sure that this attribute is retrievable */
 5084|  1.37M|        if (sensitive && sftk_isSensitive(pTemplate[i].type, object->objclass)) {
  ------------------
  |  Branch (5084:13): [True: 0, False: 1.37M]
  |  Branch (5084:26): [True: 0, False: 0]
  ------------------
 5085|      0|            crv = CKR_ATTRIBUTE_SENSITIVE;
  ------------------
  |  | 1407|      0|#define CKR_ATTRIBUTE_SENSITIVE 0x00000011UL
  ------------------
 5086|      0|            pTemplate[i].ulValueLen = -1;
 5087|      0|            continue;
 5088|      0|        }
 5089|  1.37M|        attribute = sftk_FindAttribute(object, pTemplate[i].type);
 5090|  1.37M|        if (attribute == NULL) {
  ------------------
  |  Branch (5090:13): [True: 2, False: 1.37M]
  ------------------
 5091|      2|            crv = CKR_ATTRIBUTE_TYPE_INVALID;
  ------------------
  |  | 1408|      2|#define CKR_ATTRIBUTE_TYPE_INVALID 0x00000012UL
  ------------------
 5092|      2|            pTemplate[i].ulValueLen = -1;
 5093|      2|            continue;
 5094|      2|        }
 5095|  1.37M|        if (pTemplate[i].pValue != NULL) {
  ------------------
  |  Branch (5095:13): [True: 879k, False: 498k]
  ------------------
 5096|   879k|            PORT_Memcpy(pTemplate[i].pValue, attribute->attrib.pValue,
  ------------------
  |  |  180|   879k|#define PORT_Memcpy memcpy
  ------------------
 5097|   879k|                        attribute->attrib.ulValueLen);
 5098|   879k|        }
 5099|  1.37M|        pTemplate[i].ulValueLen = attribute->attrib.ulValueLen;
 5100|  1.37M|        sftk_FreeAttribute(attribute);
 5101|  1.37M|    }
 5102|       |
 5103|  1.03M|    sftk_FreeObject(object);
 5104|  1.03M|    return crv;
 5105|  1.03M|}
NSC_SetAttributeValue:
 5111|  47.3k|{
 5112|  47.3k|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 5113|  47.3k|    SFTKSession *session;
 5114|  47.3k|    SFTKAttribute *attribute;
 5115|  47.3k|    SFTKObject *object;
 5116|  47.3k|    PRBool isToken, isLoggedIn, needLogin;
 5117|  47.3k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
 5118|  47.3k|    CK_BBOOL legal;
 5119|  47.3k|    int i;
 5120|       |
 5121|  47.3k|    CHECK_FORK();
 5122|       |
 5123|  47.3k|    if (slot == NULL) {
  ------------------
  |  Branch (5123:9): [True: 0, False: 47.3k]
  ------------------
 5124|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5125|      0|    }
 5126|       |    /*
 5127|       |     * make sure we're allowed
 5128|       |     */
 5129|  47.3k|    session = sftk_SessionFromHandle(hSession);
 5130|  47.3k|    if (session == NULL) {
  ------------------
  |  Branch (5130:9): [True: 0, False: 47.3k]
  ------------------
 5131|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5132|      0|    }
 5133|       |
 5134|  47.3k|    object = sftk_ObjectFromHandle(hObject, session);
 5135|  47.3k|    if (object == NULL) {
  ------------------
  |  Branch (5135:9): [True: 0, False: 47.3k]
  ------------------
 5136|      0|        sftk_FreeSession(session);
 5137|      0|        return CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
 5138|      0|    }
 5139|       |
 5140|  47.3k|    PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|  47.3k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 5141|  47.3k|    isLoggedIn = slot->isLoggedIn;
 5142|  47.3k|    needLogin = slot->needLogin;
 5143|  47.3k|    PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|  47.3k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 5144|       |
 5145|       |    /* don't modify a private object if we aren't logged in */
 5146|  47.3k|    if (!isLoggedIn && needLogin && sftk_isTrue(object, CKA_PRIVATE)) {
  ------------------
  |  |  513|      0|#define CKA_PRIVATE 0x00000002UL
  ------------------
  |  Branch (5146:9): [True: 47.3k, False: 0]
  |  Branch (5146:24): [True: 0, False: 47.3k]
  |  Branch (5146:37): [True: 0, False: 0]
  ------------------
 5147|      0|        sftk_FreeSession(session);
 5148|      0|        sftk_FreeObject(object);
 5149|      0|        return CKR_USER_NOT_LOGGED_IN;
  ------------------
  |  | 1486|      0|#define CKR_USER_NOT_LOGGED_IN 0x00000101UL
  ------------------
 5150|      0|    }
 5151|       |
 5152|       |    /* don't modify a token object if we aren't in a rw session */
 5153|  47.3k|    isToken = sftk_isTrue(object, CKA_TOKEN);
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
 5154|  47.3k|    if (((session->info.flags & CKF_RW_SESSION) == 0) && isToken) {
  ------------------
  |  |  302|  47.3k|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (5154:9): [True: 47.3k, False: 0]
  |  Branch (5154:58): [True: 0, False: 47.3k]
  ------------------
 5155|      0|        sftk_FreeSession(session);
 5156|      0|        sftk_FreeObject(object);
 5157|      0|        return CKR_SESSION_READ_ONLY;
  ------------------
  |  | 1467|      0|#define CKR_SESSION_READ_ONLY 0x000000B5UL
  ------------------
 5158|      0|    }
 5159|  47.3k|    sftk_FreeSession(session);
 5160|       |
 5161|       |    /* only change modifiable objects */
 5162|  47.3k|    if (!sftk_isTrue(object, CKA_MODIFIABLE)) {
  ------------------
  |  |  593|  47.3k|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
  |  Branch (5162:9): [True: 0, False: 47.3k]
  ------------------
 5163|      0|        sftk_FreeObject(object);
 5164|      0|        return CKR_ATTRIBUTE_READ_ONLY;
  ------------------
  |  | 1406|      0|#define CKR_ATTRIBUTE_READ_ONLY 0x00000010UL
  ------------------
 5165|      0|    }
 5166|       |
 5167|  94.6k|    for (i = 0; i < (int)ulCount; i++) {
  ------------------
  |  Branch (5167:17): [True: 47.3k, False: 47.3k]
  ------------------
 5168|       |        /* Make sure that this attribute is changeable */
 5169|  47.3k|        switch (sftk_modifyType(pTemplate[i].type, object->objclass)) {
 5170|      0|            case SFTK_NEVER:
  ------------------
  |  Branch (5170:13): [True: 0, False: 47.3k]
  ------------------
 5171|      0|            case SFTK_ONCOPY:
  ------------------
  |  Branch (5171:13): [True: 0, False: 47.3k]
  ------------------
 5172|      0|            default:
  ------------------
  |  Branch (5172:13): [True: 0, False: 47.3k]
  ------------------
 5173|      0|                crv = CKR_ATTRIBUTE_READ_ONLY;
  ------------------
  |  | 1406|      0|#define CKR_ATTRIBUTE_READ_ONLY 0x00000010UL
  ------------------
 5174|      0|                break;
 5175|       |
 5176|      0|            case SFTK_SENSITIVE:
  ------------------
  |  Branch (5176:13): [True: 0, False: 47.3k]
  ------------------
 5177|      0|                legal = (pTemplate[i].type == CKA_EXTRACTABLE) ? CK_FALSE : CK_TRUE;
  ------------------
  |  |  585|      0|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
                              legal = (pTemplate[i].type == CKA_EXTRACTABLE) ? CK_FALSE : CK_TRUE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
                              legal = (pTemplate[i].type == CKA_EXTRACTABLE) ? CK_FALSE : CK_TRUE;
  ------------------
  |  |   22|      0|#define CK_TRUE 1
  ------------------
  |  Branch (5177:25): [True: 0, False: 0]
  ------------------
 5178|      0|                if ((*(CK_BBOOL *)pTemplate[i].pValue) != legal) {
  ------------------
  |  Branch (5178:21): [True: 0, False: 0]
  ------------------
 5179|      0|                    crv = CKR_ATTRIBUTE_READ_ONLY;
  ------------------
  |  | 1406|      0|#define CKR_ATTRIBUTE_READ_ONLY 0x00000010UL
  ------------------
 5180|      0|                }
 5181|      0|                break;
 5182|  47.3k|            case SFTK_ALWAYS:
  ------------------
  |  Branch (5182:13): [True: 47.3k, False: 0]
  ------------------
 5183|  47.3k|                break;
 5184|  47.3k|        }
 5185|  47.3k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5185:13): [True: 0, False: 47.3k]
  ------------------
 5186|      0|            break;
 5187|       |
 5188|       |        /* find the old attribute */
 5189|  47.3k|        attribute = sftk_FindAttribute(object, pTemplate[i].type);
 5190|  47.3k|        if (attribute == NULL) {
  ------------------
  |  Branch (5190:13): [True: 0, False: 47.3k]
  ------------------
 5191|      0|            crv = CKR_ATTRIBUTE_TYPE_INVALID;
  ------------------
  |  | 1408|      0|#define CKR_ATTRIBUTE_TYPE_INVALID 0x00000012UL
  ------------------
 5192|      0|            break;
 5193|      0|        }
 5194|  47.3k|        sftk_FreeAttribute(attribute);
 5195|  47.3k|        crv = sftk_forceAttribute(object, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|  47.3k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 5196|  47.3k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5196:13): [True: 0, False: 47.3k]
  ------------------
 5197|      0|            break;
 5198|  47.3k|    }
 5199|       |
 5200|  47.3k|    sftk_FreeObject(object);
 5201|  47.3k|    return crv;
 5202|  47.3k|}
sftk_emailhack:
 5250|  23.4k|{
 5251|  23.4k|    PRBool isCert = PR_FALSE;
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
 5252|  23.4k|    int emailIndex = -1;
 5253|  23.4k|    unsigned int i;
 5254|  23.4k|    SFTKSearchResults smime_search;
 5255|  23.4k|    CK_ATTRIBUTE smime_template[2];
 5256|  23.4k|    CK_OBJECT_CLASS smime_class = CKO_NSS_SMIME;
  ------------------
  |  |   36|  23.4k|#define CKO_NSS_SMIME (CKO_NSS + 2)
  |  |  ------------------
  |  |  |  |   33|  23.4k|#define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  335|  23.4k|#define CKO_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKO_NSS (CKO_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  23.4k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5257|  23.4k|    SFTKAttribute *attribute = NULL;
 5258|  23.4k|    SFTKObject *object = NULL;
 5259|  23.4k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5260|       |
 5261|  23.4k|    smime_search.handles = NULL; /* paranoia, some one is bound to add a goto
 5262|       |                                  * loser before this gets initialized */
 5263|       |
 5264|       |    /* see if we are looking for email certs */
 5265|  70.5k|    for (i = 0; i < ulCount; i++) {
  ------------------
  |  Branch (5265:17): [True: 62.6k, False: 7.87k]
  ------------------
 5266|  62.6k|        if (pTemplate[i].type == CKA_CLASS) {
  ------------------
  |  |  511|  62.6k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (5266:13): [True: 23.4k, False: 39.1k]
  ------------------
 5267|  23.4k|            if ((pTemplate[i].ulValueLen != sizeof(CK_OBJECT_CLASS) ||
  ------------------
  |  Branch (5267:18): [True: 0, False: 23.4k]
  ------------------
 5268|  23.4k|                 (*(CK_OBJECT_CLASS *)pTemplate[i].pValue) != CKO_CERTIFICATE)) {
  ------------------
  |  |  326|  23.4k|#define CKO_CERTIFICATE 0x00000001UL
  ------------------
  |  Branch (5268:18): [True: 15.5k, False: 7.87k]
  ------------------
 5269|       |                /* not a cert, skip out */
 5270|  15.5k|                break;
 5271|  15.5k|            }
 5272|  7.87k|            isCert = PR_TRUE;
  ------------------
  |  |  437|  7.87k|#define PR_TRUE 1
  ------------------
 5273|  39.1k|        } else if (pTemplate[i].type == CKA_NSS_EMAIL) {
  ------------------
  |  |   80|  39.1k|#define CKA_NSS_EMAIL (CKA_NSS + 2)
  |  |  ------------------
  |  |  |  |   77|  39.1k|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|  39.1k|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  39.1k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (5273:20): [True: 0, False: 39.1k]
  ------------------
 5274|      0|            emailIndex = i;
 5275|      0|        }
 5276|  47.0k|        if (isCert && (emailIndex != -1))
  ------------------
  |  Branch (5276:13): [True: 23.6k, False: 23.4k]
  |  Branch (5276:23): [True: 0, False: 23.6k]
  ------------------
 5277|      0|            break;
 5278|  47.0k|    }
 5279|       |
 5280|  23.4k|    if (!isCert || (emailIndex == -1)) {
  ------------------
  |  Branch (5280:9): [True: 15.5k, False: 7.87k]
  |  Branch (5280:20): [True: 7.87k, False: 0]
  ------------------
 5281|  23.4k|        return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5282|  23.4k|    }
 5283|       |
 5284|       |    /* we are doing a cert and email search, find the SMimeEntry */
 5285|      0|    smime_template[0].type = CKA_CLASS;
  ------------------
  |  |  511|      0|#define CKA_CLASS 0x00000000UL
  ------------------
 5286|      0|    smime_template[0].pValue = &smime_class;
 5287|      0|    smime_template[0].ulValueLen = sizeof(smime_class);
 5288|      0|    smime_template[1] = pTemplate[emailIndex];
 5289|       |
 5290|      0|    smime_search.handles = (CK_OBJECT_HANDLE *)
 5291|      0|        PORT_Alloc(sizeof(CK_OBJECT_HANDLE) * NSC_SEARCH_BLOCK_SIZE);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
                      PORT_Alloc(sizeof(CK_OBJECT_HANDLE) * NSC_SEARCH_BLOCK_SIZE);
  ------------------
  |  |   49|      0|#define NSC_SEARCH_BLOCK_SIZE 5
  ------------------
 5292|      0|    if (smime_search.handles == NULL) {
  ------------------
  |  Branch (5292:9): [True: 0, False: 0]
  ------------------
 5293|      0|        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5294|      0|        goto loser;
 5295|      0|    }
 5296|      0|    smime_search.index = 0;
 5297|      0|    smime_search.size = 0;
 5298|      0|    smime_search.array_size = NSC_SEARCH_BLOCK_SIZE;
  ------------------
  |  |   49|      0|#define NSC_SEARCH_BLOCK_SIZE 5
  ------------------
 5299|       |
 5300|      0|    crv = sftk_searchDatabase(handle, &smime_search, smime_template, 2);
 5301|      0|    if (crv != CKR_OK || smime_search.size == 0) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5301:9): [True: 0, False: 0]
  |  Branch (5301:26): [True: 0, False: 0]
  ------------------
 5302|      0|        goto loser;
 5303|      0|    }
 5304|       |
 5305|       |    /* get the SMime subject */
 5306|      0|    object = sftk_NewTokenObject(slot, NULL, smime_search.handles[0]);
 5307|      0|    if (object == NULL) {
  ------------------
  |  Branch (5307:9): [True: 0, False: 0]
  ------------------
 5308|      0|        crv = CKR_HOST_MEMORY; /* is there any other reason for this failure? */
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5309|      0|        goto loser;
 5310|      0|    }
 5311|      0|    attribute = sftk_FindAttribute(object, CKA_SUBJECT);
  ------------------
  |  |  544|      0|#define CKA_SUBJECT 0x00000101UL
  ------------------
 5312|      0|    if (attribute == NULL) {
  ------------------
  |  Branch (5312:9): [True: 0, False: 0]
  ------------------
 5313|      0|        crv = CKR_ATTRIBUTE_TYPE_INVALID;
  ------------------
  |  | 1408|      0|#define CKR_ATTRIBUTE_TYPE_INVALID 0x00000012UL
  ------------------
 5314|      0|        goto loser;
 5315|      0|    }
 5316|       |
 5317|       |    /* now find the certs with that subject */
 5318|      0|    pTemplate[emailIndex] = attribute->attrib;
 5319|       |    /* now add the appropriate certs to the search list */
 5320|      0|    crv = sftk_searchDatabase(handle, search, pTemplate, ulCount);
 5321|      0|    pTemplate[emailIndex] = smime_template[1]; /* restore the user's template*/
 5322|       |
 5323|      0|loser:
 5324|      0|    if (attribute) {
  ------------------
  |  Branch (5324:9): [True: 0, False: 0]
  ------------------
 5325|      0|        sftk_FreeAttribute(attribute);
 5326|      0|    }
 5327|      0|    if (object) {
  ------------------
  |  Branch (5327:9): [True: 0, False: 0]
  ------------------
 5328|      0|        sftk_FreeObject(object);
 5329|      0|    }
 5330|      0|    if (smime_search.handles) {
  ------------------
  |  Branch (5330:9): [True: 0, False: 0]
  ------------------
 5331|      0|        PORT_Free(smime_search.handles);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5332|      0|    }
 5333|       |
 5334|      0|    return crv;
 5335|      0|}
NSC_FindObjectsInit:
 5392|  23.4k|{
 5393|  23.4k|    SFTKSearchResults *search = NULL, *freeSearch = NULL;
 5394|  23.4k|    SFTKSession *session = NULL;
 5395|  23.4k|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 5396|  23.4k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5397|  23.4k|    PRBool isLoggedIn;
 5398|       |
 5399|  23.4k|    CHECK_FORK();
 5400|       |
 5401|  23.4k|    if (slot == NULL) {
  ------------------
  |  Branch (5401:9): [True: 0, False: 23.4k]
  ------------------
 5402|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5403|      0|    }
 5404|  23.4k|    session = sftk_SessionFromHandle(hSession);
 5405|  23.4k|    if (session == NULL) {
  ------------------
  |  Branch (5405:9): [True: 0, False: 23.4k]
  ------------------
 5406|      0|        crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5407|      0|        goto loser;
 5408|      0|    }
 5409|       |
 5410|  23.4k|    search = (SFTKSearchResults *)PORT_Alloc(sizeof(SFTKSearchResults));
  ------------------
  |  |   52|  23.4k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 5411|  23.4k|    if (search == NULL) {
  ------------------
  |  Branch (5411:9): [True: 0, False: 23.4k]
  ------------------
 5412|      0|        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5413|      0|        goto loser;
 5414|      0|    }
 5415|  23.4k|    search->handles = (CK_OBJECT_HANDLE *)
 5416|  23.4k|        PORT_Alloc(sizeof(CK_OBJECT_HANDLE) * NSC_SEARCH_BLOCK_SIZE);
  ------------------
  |  |   52|  23.4k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
                      PORT_Alloc(sizeof(CK_OBJECT_HANDLE) * NSC_SEARCH_BLOCK_SIZE);
  ------------------
  |  |   49|  23.4k|#define NSC_SEARCH_BLOCK_SIZE 5
  ------------------
 5417|  23.4k|    if (search->handles == NULL) {
  ------------------
  |  Branch (5417:9): [True: 0, False: 23.4k]
  ------------------
 5418|      0|        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5419|      0|        goto loser;
 5420|      0|    }
 5421|  23.4k|    search->index = 0;
 5422|  23.4k|    search->size = 0;
 5423|  23.4k|    search->array_size = NSC_SEARCH_BLOCK_SIZE;
  ------------------
  |  |   49|  23.4k|#define NSC_SEARCH_BLOCK_SIZE 5
  ------------------
 5424|       |
 5425|  23.4k|    PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|  23.4k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 5426|  23.4k|    isLoggedIn = (PRBool)((!slot->needLogin) || slot->isLoggedIn);
  ------------------
  |  Branch (5426:27): [True: 23.4k, False: 0]
  |  Branch (5426:49): [True: 0, False: 0]
  ------------------
 5427|  23.4k|    PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|  23.4k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 5428|       |
 5429|  23.4k|    PRBool validTokenAttribute = PR_FALSE;
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
 5430|  23.4k|    PRBool tokenAttributeValue = PR_FALSE;
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
 5431|  23.4k|    for (CK_ULONG i = 0; i < ulCount; i++) {
  ------------------
  |  Branch (5431:26): [True: 23.4k, False: 2]
  ------------------
 5432|  23.4k|        CK_ATTRIBUTE_PTR attr = &pTemplate[i];
 5433|  23.4k|        if (attr->type == CKA_TOKEN && attr->pValue && attr->ulValueLen == sizeof(CK_BBOOL)) {
  ------------------
  |  |  512|  46.9k|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (5433:13): [True: 23.4k, False: 2]
  |  Branch (5433:40): [True: 23.4k, False: 0]
  |  Branch (5433:56): [True: 23.4k, False: 0]
  ------------------
 5434|  23.4k|            if (*(CK_BBOOL *)attr->pValue == CK_TRUE) {
  ------------------
  |  |   22|  23.4k|#define CK_TRUE 1
  ------------------
  |  Branch (5434:17): [True: 23.4k, False: 0]
  ------------------
 5435|  23.4k|                validTokenAttribute = PR_TRUE;
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  ------------------
 5436|  23.4k|                tokenAttributeValue = PR_TRUE;
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  ------------------
 5437|  23.4k|            } else if (*(CK_BBOOL *)attr->pValue == CK_FALSE) {
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
  |  Branch (5437:24): [True: 0, False: 0]
  ------------------
 5438|      0|                validTokenAttribute = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5439|      0|                tokenAttributeValue = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5440|      0|            }
 5441|  23.4k|            break;
 5442|  23.4k|        }
 5443|  23.4k|    }
 5444|       |
 5445|       |    // Search over the token object list if the template's CKA_TOKEN attribute is set to
 5446|       |    // CK_TRUE or if it is not set.
 5447|  23.4k|    if (validTokenAttribute == PR_FALSE || tokenAttributeValue == PR_TRUE) {
  ------------------
  |  |  438|  46.9k|#define PR_FALSE 0
  ------------------
                  if (validTokenAttribute == PR_FALSE || tokenAttributeValue == PR_TRUE) {
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  ------------------
  |  Branch (5447:9): [True: 2, False: 23.4k]
  |  Branch (5447:44): [True: 23.4k, False: 0]
  ------------------
 5448|  23.4k|        crv = sftk_searchTokenList(slot, search, pTemplate, ulCount, isLoggedIn);
 5449|  23.4k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5449:13): [True: 0, False: 23.4k]
  ------------------
 5450|      0|            goto loser;
 5451|      0|        }
 5452|  23.4k|    }
 5453|       |
 5454|       |    // Search over the session object list if the template's CKA_TOKEN attribute is set to
 5455|       |    // CK_FALSE or if it is not set.
 5456|  23.4k|    if (validTokenAttribute == PR_FALSE || tokenAttributeValue == PR_FALSE) {
  ------------------
  |  |  438|  46.9k|#define PR_FALSE 0
  ------------------
                  if (validTokenAttribute == PR_FALSE || tokenAttributeValue == PR_FALSE) {
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
  |  Branch (5456:9): [True: 2, False: 23.4k]
  |  Branch (5456:44): [True: 0, False: 23.4k]
  ------------------
 5457|      2|        crv = sftk_searchObjectList(search, slot->sessObjHashTable,
 5458|      2|                                    slot->sessObjHashSize, slot->objectLock,
 5459|      2|                                    pTemplate, ulCount, isLoggedIn);
 5460|      2|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5460:13): [True: 0, False: 2]
  ------------------
 5461|      0|            goto loser;
 5462|      0|        }
 5463|      2|    }
 5464|       |
 5465|  23.4k|    if ((freeSearch = session->search) != NULL) {
  ------------------
  |  Branch (5465:9): [True: 0, False: 23.4k]
  ------------------
 5466|      0|        session->search = NULL;
 5467|      0|        sftk_FreeSearch(freeSearch);
 5468|      0|    }
 5469|  23.4k|    session->search = search;
 5470|  23.4k|    sftk_FreeSession(session);
 5471|  23.4k|    return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5472|       |
 5473|      0|loser:
 5474|      0|    if (search) {
  ------------------
  |  Branch (5474:9): [True: 0, False: 0]
  ------------------
 5475|      0|        sftk_FreeSearch(search);
 5476|      0|    }
 5477|      0|    if (session) {
  ------------------
  |  Branch (5477:9): [True: 0, False: 0]
  ------------------
 5478|      0|        sftk_FreeSession(session);
 5479|      0|    }
 5480|      0|    return crv;
 5481|  23.4k|}
NSC_FindObjects:
 5489|  23.4k|{
 5490|  23.4k|    SFTKSession *session;
 5491|  23.4k|    SFTKSearchResults *search;
 5492|  23.4k|    int transfer;
 5493|  23.4k|    int left;
 5494|       |
 5495|  23.4k|    CHECK_FORK();
 5496|       |
 5497|  23.4k|    *pulObjectCount = 0;
 5498|  23.4k|    session = sftk_SessionFromHandle(hSession);
 5499|  23.4k|    if (session == NULL)
  ------------------
  |  Branch (5499:9): [True: 0, False: 23.4k]
  ------------------
 5500|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5501|  23.4k|    if (session->search == NULL) {
  ------------------
  |  Branch (5501:9): [True: 0, False: 23.4k]
  ------------------
 5502|      0|        sftk_FreeSession(session);
 5503|      0|        return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 5504|      0|    }
 5505|  23.4k|    search = session->search;
 5506|  23.4k|    left = session->search->size - session->search->index;
 5507|  23.4k|    transfer = ((int)ulMaxObjectCount > left) ? left : ulMaxObjectCount;
  ------------------
  |  Branch (5507:16): [True: 23.4k, False: 0]
  ------------------
 5508|  23.4k|    if (transfer > 0) {
  ------------------
  |  Branch (5508:9): [True: 0, False: 23.4k]
  ------------------
 5509|      0|        PORT_Memcpy(phObject, &search->handles[search->index],
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 5510|      0|                    transfer * sizeof(CK_OBJECT_HANDLE));
 5511|  23.4k|    } else {
 5512|  23.4k|        *phObject = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  23.4k|#define CK_INVALID_HANDLE 0
  ------------------
 5513|  23.4k|    }
 5514|       |
 5515|  23.4k|    search->index += transfer;
 5516|  23.4k|    if (search->index == search->size) {
  ------------------
  |  Branch (5516:9): [True: 23.4k, False: 0]
  ------------------
 5517|  23.4k|        session->search = NULL;
 5518|  23.4k|        sftk_FreeSearch(search);
 5519|  23.4k|    }
 5520|  23.4k|    *pulObjectCount = transfer;
 5521|  23.4k|    sftk_FreeSession(session);
 5522|  23.4k|    return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5523|  23.4k|}
NSC_FindObjectsFinal:
 5528|  23.4k|{
 5529|  23.4k|    SFTKSession *session;
 5530|  23.4k|    SFTKSearchResults *search;
 5531|       |
 5532|  23.4k|    CHECK_FORK();
 5533|       |
 5534|  23.4k|    session = sftk_SessionFromHandle(hSession);
 5535|  23.4k|    if (session == NULL)
  ------------------
  |  Branch (5535:9): [True: 0, False: 23.4k]
  ------------------
 5536|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5537|  23.4k|    search = session->search;
 5538|  23.4k|    session->search = NULL;
 5539|  23.4k|    sftk_FreeSession(session);
 5540|  23.4k|    if (search != NULL) {
  ------------------
  |  Branch (5540:9): [True: 0, False: 23.4k]
  ------------------
 5541|      0|        sftk_FreeSearch(search);
 5542|      0|    }
 5543|  23.4k|    return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5544|  23.4k|}
pkcs11.c:sftk_handleDataObject:
  805|   281k|{
  806|   281k|    CK_RV crv;
  807|       |
  808|       |    /* first reject private and token data objects */
  809|   281k|    if (sftk_isTrue(object, CKA_PRIVATE) || sftk_isTrue(object, CKA_TOKEN)) {
  ------------------
  |  |  513|   281k|#define CKA_PRIVATE 0x00000002UL
  ------------------
                  if (sftk_isTrue(object, CKA_PRIVATE) || sftk_isTrue(object, CKA_TOKEN)) {
  ------------------
  |  |  512|   281k|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (809:9): [True: 0, False: 281k]
  |  Branch (809:45): [True: 0, False: 281k]
  ------------------
  810|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  811|      0|    }
  812|       |
  813|       |    /* now just verify the required date fields */
  814|   281k|    crv = sftk_defaultAttribute(object, CKA_APPLICATION, NULL, 0);
  ------------------
  |  |  515|   281k|#define CKA_APPLICATION 0x00000010UL
  ------------------
  815|   281k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   281k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (815:9): [True: 0, False: 281k]
  ------------------
  816|      0|        return crv;
  817|   281k|    crv = sftk_defaultAttribute(object, CKA_VALUE, NULL, 0);
  ------------------
  |  |  516|   281k|#define CKA_VALUE 0x00000011UL
  ------------------
  818|   281k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   281k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (818:9): [True: 0, False: 281k]
  ------------------
  819|      0|        return crv;
  820|       |
  821|   281k|    return CKR_OK;
  ------------------
  |  | 1388|   281k|#define CKR_OK 0x00000000UL
  ------------------
  822|   281k|}
pkcs11.c:sftk_handleKeyObject:
 1552|  1.00M|{
 1553|  1.00M|    SFTKAttribute *attribute;
 1554|  1.00M|    CK_KEY_TYPE key_type;
 1555|  1.00M|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  1.00M|#define CK_FALSE 0
  ------------------
 1556|  1.00M|    CK_RV crv;
 1557|       |
 1558|       |    /* verify the required fields */
 1559|  1.00M|    if (!sftk_hasAttribute(object, CKA_KEY_TYPE)) {
  ------------------
  |  |  543|  1.00M|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (1559:9): [True: 0, False: 1.00M]
  ------------------
 1560|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1561|      0|    }
 1562|       |
 1563|       |    /* now verify the common fields */
 1564|  1.00M|    crv = sftk_defaultAttribute(object, CKA_ID, NULL, 0);
  ------------------
  |  |  545|  1.00M|#define CKA_ID 0x00000102UL
  ------------------
 1565|  1.00M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.00M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1565:9): [True: 0, False: 1.00M]
  ------------------
 1566|      0|        return crv;
 1567|  1.00M|    crv = sftk_defaultAttribute(object, CKA_START_DATE, NULL, 0);
  ------------------
  |  |  556|  1.00M|#define CKA_START_DATE 0x00000110UL
  ------------------
 1568|  1.00M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.00M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1568:9): [True: 0, False: 1.00M]
  ------------------
 1569|      0|        return crv;
 1570|  1.00M|    crv = sftk_defaultAttribute(object, CKA_END_DATE, NULL, 0);
  ------------------
  |  |  557|  1.00M|#define CKA_END_DATE 0x00000111UL
  ------------------
 1571|  1.00M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.00M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1571:9): [True: 0, False: 1.00M]
  ------------------
 1572|      0|        return crv;
 1573|       |    /* CKA_DERIVE is common to all keys, but it's default value is
 1574|       |     * key dependent */
 1575|  1.00M|    crv = sftk_defaultAttribute(object, CKA_LOCAL, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  586|  1.00M|#define CKA_LOCAL 0x00000163UL
  ------------------
 1576|  1.00M|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  1.00M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1576:9): [True: 0, False: 1.00M]
  ------------------
 1577|      0|        return crv;
 1578|       |
 1579|       |    /* get the key type */
 1580|  1.00M|    attribute = sftk_FindAttribute(object, CKA_KEY_TYPE);
  ------------------
  |  |  543|  1.00M|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 1581|  1.00M|    if (!attribute) {
  ------------------
  |  Branch (1581:9): [True: 0, False: 1.00M]
  ------------------
 1582|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 1583|      0|    }
 1584|  1.00M|    key_type = *(CK_KEY_TYPE *)attribute->attrib.pValue;
 1585|  1.00M|    sftk_FreeAttribute(attribute);
 1586|       |
 1587|  1.00M|    switch (object->objclass) {
 1588|  50.4k|        case CKO_PUBLIC_KEY:
  ------------------
  |  |  327|  50.4k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
  |  Branch (1588:9): [True: 50.4k, False: 956k]
  ------------------
 1589|  50.4k|            return sftk_handlePublicKeyObject(session, object, key_type);
 1590|  47.3k|        case CKO_PRIVATE_KEY:
  ------------------
  |  |  328|  47.3k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (1590:9): [True: 47.3k, False: 959k]
  ------------------
 1591|  47.3k|            return sftk_handlePrivateKeyObject(session, object, key_type);
 1592|   909k|        case CKO_SECRET_KEY:
  ------------------
  |  |  329|   909k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  |  Branch (1592:9): [True: 909k, False: 97.7k]
  ------------------
 1593|       |            /* make sure the required fields exist */
 1594|   909k|            return sftk_handleSecretKeyObject(session, object, key_type,
 1595|   909k|                                              (PRBool)(sftk_isFIPS(session->slot->slotID)));
  ------------------
  |  |  506|   909k|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|   909k|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|   909k|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 909k]
  |  |  |  Branch (506:32): [True: 0, False: 909k]
  |  |  ------------------
  ------------------
 1596|      0|        default:
  ------------------
  |  Branch (1596:9): [True: 0, False: 1.00M]
  ------------------
 1597|      0|            break;
 1598|  1.00M|    }
 1599|      0|    return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 1600|  1.00M|}
pkcs11.c:sftk_handlePublicKeyObject:
 1031|  50.4k|{
 1032|  50.4k|    CK_BBOOL encrypt = CK_TRUE;
  ------------------
  |  |   22|  50.4k|#define CK_TRUE 1
  ------------------
 1033|  50.4k|    CK_BBOOL recover = CK_TRUE;
  ------------------
  |  |   22|  50.4k|#define CK_TRUE 1
  ------------------
 1034|  50.4k|    CK_BBOOL wrap = CK_TRUE;
  ------------------
  |  |   22|  50.4k|#define CK_TRUE 1
  ------------------
 1035|  50.4k|    CK_BBOOL derive = CK_FALSE;
  ------------------
  |  |   23|  50.4k|#define CK_FALSE 0
  ------------------
 1036|  50.4k|    CK_BBOOL verify = CK_TRUE;
  ------------------
  |  |   22|  50.4k|#define CK_TRUE 1
  ------------------
 1037|  50.4k|    CK_RV crv;
 1038|       |
 1039|  50.4k|    switch (key_type) {
 1040|  3.01k|        case CKK_RSA:
  ------------------
  |  |  372|  3.01k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (1040:9): [True: 3.01k, False: 47.4k]
  ------------------
 1041|  3.01k|            crv = sftk_ConstrainAttribute(object, CKA_MODULUS,
  ------------------
  |  |  558|  3.01k|#define CKA_MODULUS 0x00000120UL
  ------------------
 1042|  3.01k|                                          RSA_MIN_MODULUS_BITS, 0, 0);
  ------------------
  |  |  151|  3.01k|#define RSA_MIN_MODULUS_BITS 128
  ------------------
 1043|  3.01k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  3.01k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1043:17): [True: 0, False: 3.01k]
  ------------------
 1044|      0|                return crv;
 1045|      0|            }
 1046|  3.01k|            crv = sftk_ConstrainAttribute(object, CKA_PUBLIC_EXPONENT, 2, 0, 0);
  ------------------
  |  |  560|  3.01k|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 1047|  3.01k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  3.01k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1047:17): [True: 0, False: 3.01k]
  ------------------
 1048|      0|                return crv;
 1049|      0|            }
 1050|  3.01k|            break;
 1051|  3.01k|        case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (1051:9): [True: 0, False: 50.4k]
  ------------------
 1052|      0|            crv = sftk_ConstrainAttribute(object, CKA_SUBPRIME,
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 1053|      0|                                          DSA_MIN_Q_BITS, DSA_MAX_Q_BITS, 0);
  ------------------
  |  |  200|      0|#define DSA_MIN_Q_BITS 160
  ------------------
                                                        DSA_MIN_Q_BITS, DSA_MAX_Q_BITS, 0);
  ------------------
  |  |  199|      0|#define DSA_MAX_Q_BITS 256
  ------------------
 1054|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1054:17): [True: 0, False: 0]
  ------------------
 1055|      0|                return crv;
 1056|      0|            }
 1057|      0|            crv = sftk_ConstrainAttribute(object, CKA_PRIME,
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 1058|      0|                                          DSA_MIN_P_BITS, DSA_MAX_P_BITS, 64);
  ------------------
  |  |  198|      0|#define DSA_MIN_P_BITS 512
  ------------------
                                                        DSA_MIN_P_BITS, DSA_MAX_P_BITS, 64);
  ------------------
  |  |  197|      0|#define DSA_MAX_P_BITS 3072
  ------------------
 1059|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1059:17): [True: 0, False: 0]
  ------------------
 1060|      0|                return crv;
 1061|      0|            }
 1062|      0|            crv = sftk_ConstrainAttribute(object, CKA_BASE, 2, DSA_MAX_P_BITS, 0);
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
                          crv = sftk_ConstrainAttribute(object, CKA_BASE, 2, DSA_MAX_P_BITS, 0);
  ------------------
  |  |  197|      0|#define DSA_MAX_P_BITS 3072
  ------------------
 1063|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1063:17): [True: 0, False: 0]
  ------------------
 1064|      0|                return crv;
 1065|      0|            }
 1066|      0|            crv = sftk_ConstrainAttribute(object, CKA_VALUE, 2, DSA_MAX_P_BITS, 0);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
                          crv = sftk_ConstrainAttribute(object, CKA_VALUE, 2, DSA_MAX_P_BITS, 0);
  ------------------
  |  |  197|      0|#define DSA_MAX_P_BITS 3072
  ------------------
 1067|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1067:17): [True: 0, False: 0]
  ------------------
 1068|      0|                return crv;
 1069|      0|            }
 1070|      0|            encrypt = CK_FALSE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
 1071|      0|            recover = CK_FALSE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
 1072|      0|            wrap = CK_FALSE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
 1073|      0|            break;
 1074|  29.0k|        case CKK_DH:
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (1074:9): [True: 29.0k, False: 21.3k]
  ------------------
 1075|  29.0k|            crv = sftk_ConstrainAttribute(object, CKA_PRIME,
  ------------------
  |  |  569|  29.0k|#define CKA_PRIME 0x00000130UL
  ------------------
 1076|  29.0k|                                          DH_MIN_P_BITS, DH_MAX_P_BITS, 0);
  ------------------
  |  |  154|  29.0k|#define DH_MIN_P_BITS 128
  ------------------
                                                        DH_MIN_P_BITS, DH_MAX_P_BITS, 0);
  ------------------
  |  |  155|  29.0k|#define DH_MAX_P_BITS 16384
  ------------------
 1077|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1077:17): [True: 0, False: 29.0k]
  ------------------
 1078|      0|                return crv;
 1079|      0|            }
 1080|  29.0k|            crv = sftk_ConstrainAttribute(object, CKA_BASE, 2, DH_MAX_P_BITS, 0);
  ------------------
  |  |  571|  29.0k|#define CKA_BASE 0x00000132UL
  ------------------
                          crv = sftk_ConstrainAttribute(object, CKA_BASE, 2, DH_MAX_P_BITS, 0);
  ------------------
  |  |  155|  29.0k|#define DH_MAX_P_BITS 16384
  ------------------
 1081|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1081:17): [True: 0, False: 29.0k]
  ------------------
 1082|      0|                return crv;
 1083|      0|            }
 1084|  29.0k|            crv = sftk_ConstrainAttribute(object, CKA_VALUE, 2, DH_MAX_P_BITS, 0);
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
                          crv = sftk_ConstrainAttribute(object, CKA_VALUE, 2, DH_MAX_P_BITS, 0);
  ------------------
  |  |  155|  29.0k|#define DH_MAX_P_BITS 16384
  ------------------
 1085|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1085:17): [True: 0, False: 29.0k]
  ------------------
 1086|      0|                return crv;
 1087|      0|            }
 1088|  29.0k|            verify = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1089|  29.0k|            derive = CK_TRUE;
  ------------------
  |  |   22|  29.0k|#define CK_TRUE 1
  ------------------
 1090|  29.0k|            encrypt = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1091|  29.0k|            recover = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1092|  29.0k|            wrap = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1093|  29.0k|            break;
 1094|      0|        case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (1094:9): [True: 0, False: 50.4k]
  ------------------
 1095|      0|        case CKK_EC_EDWARDS:
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (1095:9): [True: 0, False: 50.4k]
  ------------------
 1096|  18.2k|        case CKK_EC:
  ------------------
  |  |  379|  18.2k|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (1096:9): [True: 18.2k, False: 32.1k]
  ------------------
 1097|  18.2k|            if (!sftk_hasAttribute(object, CKA_EC_PARAMS)) {
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
  |  Branch (1097:17): [True: 0, False: 18.2k]
  ------------------
 1098|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1099|      0|            }
 1100|  18.2k|            if (!sftk_hasAttribute(object, CKA_EC_POINT)) {
  ------------------
  |  |  604|  18.2k|#define CKA_EC_POINT 0x00000181UL
  ------------------
  |  Branch (1100:17): [True: 0, False: 18.2k]
  ------------------
 1101|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1102|      0|            }
 1103|       |            /* for ECDSA and EDDSA. Change if the structure of any of them is modified. */
 1104|  18.2k|            derive = (key_type == CKK_EC_EDWARDS) ? CK_FALSE : CK_TRUE;    /* CK_TRUE for ECDH */
  ------------------
  |  |  448|  18.2k|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
                          derive = (key_type == CKK_EC_EDWARDS) ? CK_FALSE : CK_TRUE;    /* CK_TRUE for ECDH */
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
                          derive = (key_type == CKK_EC_EDWARDS) ? CK_FALSE : CK_TRUE;    /* CK_TRUE for ECDH */
  ------------------
  |  |   22|  36.5k|#define CK_TRUE 1
  ------------------
  |  Branch (1104:22): [True: 0, False: 18.2k]
  ------------------
 1105|  18.2k|            verify = (key_type == CKK_EC_MONTGOMERY) ? CK_FALSE : CK_TRUE; /* for ECDSA and EDDSA */
  ------------------
  |  |  449|  18.2k|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
                          verify = (key_type == CKK_EC_MONTGOMERY) ? CK_FALSE : CK_TRUE; /* for ECDSA and EDDSA */
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
                          verify = (key_type == CKK_EC_MONTGOMERY) ? CK_FALSE : CK_TRUE; /* for ECDSA and EDDSA */
  ------------------
  |  |   22|  36.5k|#define CK_TRUE 1
  ------------------
  |  Branch (1105:22): [True: 0, False: 18.2k]
  ------------------
 1106|  18.2k|            encrypt = CK_FALSE;
  ------------------
  |  |   23|  18.2k|#define CK_FALSE 0
  ------------------
 1107|  18.2k|            recover = CK_FALSE;
  ------------------
  |  |   23|  18.2k|#define CK_FALSE 0
  ------------------
 1108|  18.2k|            wrap = CK_FALSE;
  ------------------
  |  |   23|  18.2k|#define CK_FALSE 0
  ------------------
 1109|  18.2k|            break;
 1110|      0|        case CKK_NSS_KYBER:
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1110:9): [True: 0, False: 50.4k]
  ------------------
 1111|     99|        case CKK_NSS_ML_KEM:
  ------------------
  |  |   59|     99|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|     99|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|     99|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1111:9): [True: 99, False: 50.3k]
  ------------------
 1112|     99|            if (!sftk_hasAttribute(object, CKA_NSS_PARAMETER_SET)) {
  ------------------
  |  |  113|     99|#define CKA_NSS_PARAMETER_SET (CKA_NSS + 40)
  |  |  ------------------
  |  |  |  |   77|     99|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|     99|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1112:17): [True: 0, False: 99]
  ------------------
 1113|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1114|      0|            }
 1115|     99|            derive = CK_FALSE;
  ------------------
  |  |   23|     99|#define CK_FALSE 0
  ------------------
 1116|     99|            verify = CK_FALSE;
  ------------------
  |  |   23|     99|#define CK_FALSE 0
  ------------------
 1117|     99|            encrypt = CK_FALSE;
  ------------------
  |  |   23|     99|#define CK_FALSE 0
  ------------------
 1118|     99|            recover = CK_FALSE;
  ------------------
  |  |   23|     99|#define CK_FALSE 0
  ------------------
 1119|     99|            wrap = CK_FALSE;
  ------------------
  |  |   23|     99|#define CK_FALSE 0
  ------------------
 1120|     99|            break;
 1121|      0|        default:
  ------------------
  |  Branch (1121:9): [True: 0, False: 50.4k]
  ------------------
 1122|      0|            return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 1123|  50.4k|    }
 1124|       |
 1125|       |    /* make sure the required fields exist */
 1126|  50.4k|    crv = sftk_defaultAttribute(object, CKA_SUBJECT, NULL, 0);
  ------------------
  |  |  544|  50.4k|#define CKA_SUBJECT 0x00000101UL
  ------------------
 1127|  50.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1127:9): [True: 0, False: 50.4k]
  ------------------
 1128|      0|        return crv;
 1129|  50.4k|    crv = sftk_defaultAttribute(object, CKA_ENCRYPT, &encrypt, sizeof(CK_BBOOL));
  ------------------
  |  |  547|  50.4k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1130|  50.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1130:9): [True: 0, False: 50.4k]
  ------------------
 1131|      0|        return crv;
 1132|  50.4k|    crv = sftk_defaultAttribute(object, CKA_VERIFY, &verify, sizeof(CK_BBOOL));
  ------------------
  |  |  553|  50.4k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1133|  50.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1133:9): [True: 0, False: 50.4k]
  ------------------
 1134|      0|        return crv;
 1135|  50.4k|    crv = sftk_defaultAttribute(object, CKA_VERIFY_RECOVER,
  ------------------
  |  |  554|  50.4k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 1136|  50.4k|                                &recover, sizeof(CK_BBOOL));
 1137|  50.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1137:9): [True: 0, False: 50.4k]
  ------------------
 1138|      0|        return crv;
 1139|  50.4k|    crv = sftk_defaultAttribute(object, CKA_WRAP, &wrap, sizeof(CK_BBOOL));
  ------------------
  |  |  549|  50.4k|#define CKA_WRAP 0x00000106UL
  ------------------
 1140|  50.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1140:9): [True: 0, False: 50.4k]
  ------------------
 1141|      0|        return crv;
 1142|  50.4k|    crv = sftk_defaultAttribute(object, CKA_DERIVE, &derive, sizeof(CK_BBOOL));
  ------------------
  |  |  555|  50.4k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1143|  50.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1143:9): [True: 0, False: 50.4k]
  ------------------
 1144|      0|        return crv;
 1145|       |
 1146|  50.4k|    object->objectInfo = sftk_GetPubKey(object, key_type, &crv);
 1147|  50.4k|    if (object->objectInfo == NULL) {
  ------------------
  |  Branch (1147:9): [True: 0, False: 50.4k]
  ------------------
 1148|      0|        return crv;
 1149|      0|    }
 1150|  50.4k|    object->infoFree = SFTKFree_nsslowkey_DestroyPublicKey;
 1151|       |
 1152|       |    /* Check that an imported EC key is valid */
 1153|  50.4k|    if (key_type == CKK_EC || key_type == CKK_EC_EDWARDS || key_type == CKK_EC_MONTGOMERY) {
  ------------------
  |  |  379|   100k|#define CKK_EC 0x00000003UL
  ------------------
                  if (key_type == CKK_EC || key_type == CKK_EC_EDWARDS || key_type == CKK_EC_MONTGOMERY) {
  ------------------
  |  |  448|  82.6k|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
                  if (key_type == CKK_EC || key_type == CKK_EC_EDWARDS || key_type == CKK_EC_MONTGOMERY) {
  ------------------
  |  |  449|  32.1k|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (1153:9): [True: 18.2k, False: 32.1k]
  |  Branch (1153:31): [True: 0, False: 32.1k]
  |  Branch (1153:61): [True: 0, False: 32.1k]
  ------------------
 1154|  18.2k|        NSSLOWKEYPublicKey *pubKey = (NSSLOWKEYPublicKey *)object->objectInfo;
 1155|  18.2k|        SECStatus rv = EC_ValidatePublicKey(&pubKey->u.ec.ecParams,
 1156|  18.2k|                                            &pubKey->u.ec.publicValue);
 1157|       |
 1158|  18.2k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1158:13): [True: 0, False: 18.2k]
  ------------------
 1159|      0|            return CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 1160|      0|        }
 1161|  18.2k|    }
 1162|       |
 1163|  50.4k|    if (sftk_isTrue(object, CKA_TOKEN)) {
  ------------------
  |  |  512|  50.4k|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (1163:9): [True: 0, False: 50.4k]
  ------------------
 1164|      0|        SFTKSlot *slot = session->slot;
 1165|      0|        SFTKDBHandle *certHandle = sftk_getCertDB(slot);
 1166|       |
 1167|      0|        if (certHandle == NULL) {
  ------------------
  |  Branch (1167:13): [True: 0, False: 0]
  ------------------
 1168|      0|            return CKR_TOKEN_WRITE_PROTECTED;
  ------------------
  |  | 1481|      0|#define CKR_TOKEN_WRITE_PROTECTED 0x000000E2UL
  ------------------
 1169|      0|        }
 1170|       |
 1171|      0|        crv = sftkdb_write(certHandle, object, &object->handle);
 1172|      0|        sftk_freeDB(certHandle);
 1173|      0|        return crv;
 1174|      0|    }
 1175|       |
 1176|  50.4k|    return CKR_OK;
  ------------------
  |  | 1388|  50.4k|#define CKR_OK 0x00000000UL
  ------------------
 1177|  50.4k|}
pkcs11.c:sftk_handlePrivateKeyObject:
 1190|  47.3k|{
 1191|  47.3k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 1192|  47.3k|    CK_BBOOL encrypt = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 1193|  47.3k|    CK_BBOOL sign = CK_FALSE;
  ------------------
  |  |   23|  47.3k|#define CK_FALSE 0
  ------------------
 1194|  47.3k|    CK_BBOOL recover = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 1195|  47.3k|    CK_BBOOL wrap = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 1196|  47.3k|    CK_BBOOL derive = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 1197|  47.3k|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  47.3k|#define CK_FALSE 0
  ------------------
 1198|  47.3k|    PRBool createObjectInfo = PR_TRUE;
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
 1199|  47.3k|    PRBool fillPrivateKey = PR_FALSE;
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 1200|  47.3k|    int missing_rsa_mod_component = 0;
 1201|  47.3k|    int missing_rsa_exp_component = 0;
 1202|  47.3k|    int missing_rsa_crt_component = 0;
 1203|       |
 1204|  47.3k|    SECItem mod;
 1205|  47.3k|    CK_RV crv;
 1206|  47.3k|    SECStatus rv;
 1207|       |
 1208|  47.3k|    switch (key_type) {
 1209|      4|        case CKK_RSA:
  ------------------
  |  |  372|      4|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (1209:9): [True: 4, False: 47.3k]
  ------------------
 1210|      4|            if (!sftk_hasAttribute(object, CKA_MODULUS)) {
  ------------------
  |  |  558|      4|#define CKA_MODULUS 0x00000120UL
  ------------------
  |  Branch (1210:17): [True: 0, False: 4]
  ------------------
 1211|      0|                missing_rsa_mod_component++;
 1212|      0|            }
 1213|      4|            if (!sftk_hasAttribute(object, CKA_PUBLIC_EXPONENT)) {
  ------------------
  |  |  560|      4|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
  |  Branch (1213:17): [True: 0, False: 4]
  ------------------
 1214|      0|                missing_rsa_exp_component++;
 1215|      0|            }
 1216|      4|            if (!sftk_hasAttribute(object, CKA_PRIVATE_EXPONENT)) {
  ------------------
  |  |  561|      4|#define CKA_PRIVATE_EXPONENT 0x00000123UL
  ------------------
  |  Branch (1216:17): [True: 0, False: 4]
  ------------------
 1217|      0|                missing_rsa_exp_component++;
 1218|      0|            }
 1219|      4|            if (!sftk_hasAttribute(object, CKA_PRIME_1)) {
  ------------------
  |  |  562|      4|#define CKA_PRIME_1 0x00000124UL
  ------------------
  |  Branch (1219:17): [True: 0, False: 4]
  ------------------
 1220|      0|                missing_rsa_mod_component++;
 1221|      0|            }
 1222|      4|            if (!sftk_hasAttribute(object, CKA_PRIME_2)) {
  ------------------
  |  |  563|      4|#define CKA_PRIME_2 0x00000125UL
  ------------------
  |  Branch (1222:17): [True: 0, False: 4]
  ------------------
 1223|      0|                missing_rsa_mod_component++;
 1224|      0|            }
 1225|      4|            if (!sftk_hasAttribute(object, CKA_EXPONENT_1)) {
  ------------------
  |  |  564|      4|#define CKA_EXPONENT_1 0x00000126UL
  ------------------
  |  Branch (1225:17): [True: 0, False: 4]
  ------------------
 1226|      0|                missing_rsa_crt_component++;
 1227|      0|            }
 1228|      4|            if (!sftk_hasAttribute(object, CKA_EXPONENT_2)) {
  ------------------
  |  |  565|      4|#define CKA_EXPONENT_2 0x00000127UL
  ------------------
  |  Branch (1228:17): [True: 0, False: 4]
  ------------------
 1229|      0|                missing_rsa_crt_component++;
 1230|      0|            }
 1231|      4|            if (!sftk_hasAttribute(object, CKA_COEFFICIENT)) {
  ------------------
  |  |  566|      4|#define CKA_COEFFICIENT 0x00000128UL
  ------------------
  |  Branch (1231:17): [True: 0, False: 4]
  ------------------
 1232|      0|                missing_rsa_crt_component++;
 1233|      0|            }
 1234|      4|            if (missing_rsa_mod_component || missing_rsa_exp_component ||
  ------------------
  |  Branch (1234:17): [True: 0, False: 4]
  |  Branch (1234:46): [True: 0, False: 4]
  ------------------
 1235|      4|                missing_rsa_crt_component) {
  ------------------
  |  Branch (1235:17): [True: 0, False: 4]
  ------------------
 1236|       |                /* we are missing a component, see if we have enough to rebuild
 1237|       |                 * the rest */
 1238|      0|                int have_exp = 2 - missing_rsa_exp_component;
 1239|      0|                int have_component = 5 -
 1240|      0|                                     (missing_rsa_exp_component + missing_rsa_mod_component);
 1241|       |
 1242|      0|                if ((have_exp == 0) || (have_component < 3)) {
  ------------------
  |  Branch (1242:21): [True: 0, False: 0]
  |  Branch (1242:40): [True: 0, False: 0]
  ------------------
 1243|       |                    /* nope, not enough to reconstruct the private key */
 1244|      0|                    return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1245|      0|                }
 1246|      0|                fillPrivateKey = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1247|      0|            }
 1248|       |            /*verify the parameters for consistency*/
 1249|      4|            rv = sftk_verifyRSAPrivateKey(object, fillPrivateKey);
 1250|      4|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1250:17): [True: 0, False: 4]
  ------------------
 1251|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1252|      0|            }
 1253|       |
 1254|       |            /* make sure Netscape DB attribute is set correctly */
 1255|      4|            crv = sftk_Attribute2SSecItem(NULL, &mod, object, CKA_MODULUS);
  ------------------
  |  |  558|      4|#define CKA_MODULUS 0x00000120UL
  ------------------
 1256|      4|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1256:17): [True: 0, False: 4]
  ------------------
 1257|      0|                return crv;
 1258|      4|            crv = sftk_forceAttribute(object, CKA_NSS_DB,
  ------------------
  |  |  150|      4|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 1259|      4|                                      sftk_item_expand(&mod));
  ------------------
  |  |  588|      4|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 1260|      4|            if (mod.data)
  ------------------
  |  Branch (1260:17): [True: 4, False: 0]
  ------------------
 1261|      4|                SECITEM_ZfreeItem(&mod, PR_FALSE);
  ------------------
  |  |  110|      4|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&mod, PR_FALSE);
  ------------------
  |  |  438|      4|#define PR_FALSE 0
  ------------------
 1262|      4|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1262:17): [True: 0, False: 4]
  ------------------
 1263|      0|                return crv;
 1264|       |
 1265|      4|            sign = CK_TRUE;
  ------------------
  |  |   22|      4|#define CK_TRUE 1
  ------------------
 1266|      4|            derive = CK_FALSE;
  ------------------
  |  |   23|      4|#define CK_FALSE 0
  ------------------
 1267|      4|            break;
 1268|      0|        case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (1268:9): [True: 0, False: 47.3k]
  ------------------
 1269|      0|            if (!sftk_hasAttribute(object, CKA_SUBPRIME)) {
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
  |  Branch (1269:17): [True: 0, False: 0]
  ------------------
 1270|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1271|      0|            }
 1272|      0|            sign = CK_TRUE;
  ------------------
  |  |   22|      0|#define CK_TRUE 1
  ------------------
 1273|      0|            derive = CK_FALSE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
 1274|       |        /* fall through */
 1275|  29.0k|        case CKK_DH:
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (1275:9): [True: 29.0k, False: 18.2k]
  ------------------
 1276|  29.0k|            if (!sftk_hasAttribute(object, CKA_PRIME)) {
  ------------------
  |  |  569|  29.0k|#define CKA_PRIME 0x00000130UL
  ------------------
  |  Branch (1276:17): [True: 0, False: 29.0k]
  ------------------
 1277|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1278|      0|            }
 1279|  29.0k|            if (!sftk_hasAttribute(object, CKA_BASE)) {
  ------------------
  |  |  571|  29.0k|#define CKA_BASE 0x00000132UL
  ------------------
  |  Branch (1279:17): [True: 0, False: 29.0k]
  ------------------
 1280|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1281|      0|            }
 1282|  29.0k|            if (!sftk_hasAttribute(object, CKA_VALUE)) {
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
  |  Branch (1282:17): [True: 0, False: 29.0k]
  ------------------
 1283|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1284|      0|            }
 1285|       |            /* allow subprime to be set after the fact */
 1286|  29.0k|            crv = sftk_defaultAttribute(object, CKA_SUBPRIME, NULL, 0);
  ------------------
  |  |  570|  29.0k|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 1287|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1287:17): [True: 0, False: 29.0k]
  ------------------
 1288|      0|                return crv;
 1289|      0|            }
 1290|  29.0k|            encrypt = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1291|  29.0k|            recover = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1292|  29.0k|            wrap = CK_FALSE;
  ------------------
  |  |   23|  29.0k|#define CK_FALSE 0
  ------------------
 1293|  29.0k|            break;
 1294|  18.2k|        case CKK_EC:
  ------------------
  |  |  379|  18.2k|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (1294:9): [True: 18.2k, False: 29.0k]
  ------------------
 1295|  18.2k|        case CKK_EC_EDWARDS:
  ------------------
  |  |  448|  18.2k|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (1295:9): [True: 0, False: 47.3k]
  ------------------
 1296|  18.2k|        case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|  18.2k|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (1296:9): [True: 0, False: 47.3k]
  ------------------
 1297|  18.2k|            if (!sftk_hasAttribute(object, CKA_EC_PARAMS)) {
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
  |  Branch (1297:17): [True: 0, False: 18.2k]
  ------------------
 1298|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1299|      0|            }
 1300|  18.2k|            if (!sftk_hasAttribute(object, CKA_VALUE)) {
  ------------------
  |  |  516|  18.2k|#define CKA_VALUE 0x00000011UL
  ------------------
  |  Branch (1300:17): [True: 0, False: 18.2k]
  ------------------
 1301|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1302|      0|            }
 1303|       |            /* for ECDSA and EDDSA. Change if the structure of any of them is modified. */
 1304|  18.2k|            derive = (key_type == CKK_EC_EDWARDS) ? CK_FALSE : CK_TRUE;  /* CK_TRUE for ECDH */
  ------------------
  |  |  448|  18.2k|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
                          derive = (key_type == CKK_EC_EDWARDS) ? CK_FALSE : CK_TRUE;  /* CK_TRUE for ECDH */
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
                          derive = (key_type == CKK_EC_EDWARDS) ? CK_FALSE : CK_TRUE;  /* CK_TRUE for ECDH */
  ------------------
  |  |   22|  36.5k|#define CK_TRUE 1
  ------------------
  |  Branch (1304:22): [True: 0, False: 18.2k]
  ------------------
 1305|  18.2k|            sign = (key_type == CKK_EC_MONTGOMERY) ? CK_FALSE : CK_TRUE; /* for ECDSA and EDDSA */
  ------------------
  |  |  449|  18.2k|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
                          sign = (key_type == CKK_EC_MONTGOMERY) ? CK_FALSE : CK_TRUE; /* for ECDSA and EDDSA */
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
                          sign = (key_type == CKK_EC_MONTGOMERY) ? CK_FALSE : CK_TRUE; /* for ECDSA and EDDSA */
  ------------------
  |  |   22|  36.5k|#define CK_TRUE 1
  ------------------
  |  Branch (1305:20): [True: 0, False: 18.2k]
  ------------------
 1306|  18.2k|            encrypt = CK_FALSE;
  ------------------
  |  |   23|  18.2k|#define CK_FALSE 0
  ------------------
 1307|  18.2k|            recover = CK_FALSE;
  ------------------
  |  |   23|  18.2k|#define CK_FALSE 0
  ------------------
 1308|  18.2k|            wrap = CK_FALSE;
  ------------------
  |  |   23|  18.2k|#define CK_FALSE 0
  ------------------
 1309|  18.2k|            break;
 1310|      0|        case CKK_NSS_JPAKE_ROUND1:
  ------------------
  |  |   53|      0|#define CKK_NSS_JPAKE_ROUND1 (CKK_NSS + 2)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1310:9): [True: 0, False: 47.3k]
  ------------------
 1311|      0|            if (!sftk_hasAttribute(object, CKA_PRIME) ||
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
  |  Branch (1311:17): [True: 0, False: 0]
  ------------------
 1312|      0|                !sftk_hasAttribute(object, CKA_SUBPRIME) ||
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
  |  Branch (1312:17): [True: 0, False: 0]
  ------------------
 1313|      0|                !sftk_hasAttribute(object, CKA_BASE)) {
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
  |  Branch (1313:17): [True: 0, False: 0]
  ------------------
 1314|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1315|      0|            }
 1316|       |        /* fall through */
 1317|      0|        case CKK_NSS_JPAKE_ROUND2:
  ------------------
  |  |   54|      0|#define CKK_NSS_JPAKE_ROUND2 (CKK_NSS + 3)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1317:9): [True: 0, False: 47.3k]
  ------------------
 1318|       |            /* CKA_NSS_JPAKE_SIGNERID and CKA_NSS_JPAKE_PEERID are checked in
 1319|       |               the J-PAKE code. */
 1320|      0|            encrypt = sign = recover = wrap = CK_FALSE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
 1321|      0|            derive = CK_TRUE;
  ------------------
  |  |   22|      0|#define CK_TRUE 1
  ------------------
 1322|      0|            createObjectInfo = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1323|      0|            break;
 1324|      0|        case CKK_NSS_KYBER:
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1324:9): [True: 0, False: 47.3k]
  ------------------
 1325|      0|        case CKK_NSS_ML_KEM:
  ------------------
  |  |   59|      0|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1325:9): [True: 0, False: 47.3k]
  ------------------
 1326|      0|            if (!sftk_hasAttribute(object, CKA_KEY_TYPE)) {
  ------------------
  |  |  543|      0|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (1326:17): [True: 0, False: 0]
  ------------------
 1327|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1328|      0|            }
 1329|      0|            if (!sftk_hasAttribute(object, CKA_VALUE)) {
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
  |  Branch (1329:17): [True: 0, False: 0]
  ------------------
 1330|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1331|      0|            }
 1332|      0|            encrypt = sign = recover = wrap = CK_FALSE;
  ------------------
  |  |   23|      0|#define CK_FALSE 0
  ------------------
 1333|      0|            break;
 1334|      0|        default:
  ------------------
  |  Branch (1334:9): [True: 0, False: 47.3k]
  ------------------
 1335|      0|            return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 1336|  47.3k|    }
 1337|  47.3k|    crv = sftk_defaultAttribute(object, CKA_SUBJECT, NULL, 0);
  ------------------
  |  |  544|  47.3k|#define CKA_SUBJECT 0x00000101UL
  ------------------
 1338|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1338:9): [True: 0, False: 47.3k]
  ------------------
 1339|      0|        return crv;
 1340|  47.3k|    crv = sftk_defaultAttribute(object, CKA_SENSITIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  546|  47.3k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 1341|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1341:9): [True: 0, False: 47.3k]
  ------------------
 1342|      0|        return crv;
 1343|  47.3k|    crv = sftk_defaultAttribute(object, CKA_EXTRACTABLE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  585|  47.3k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 1344|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1344:9): [True: 0, False: 47.3k]
  ------------------
 1345|      0|        return crv;
 1346|  47.3k|    crv = sftk_defaultAttribute(object, CKA_DECRYPT, &encrypt, sizeof(CK_BBOOL));
  ------------------
  |  |  548|  47.3k|#define CKA_DECRYPT 0x00000105UL
  ------------------
 1347|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1347:9): [True: 0, False: 47.3k]
  ------------------
 1348|      0|        return crv;
 1349|  47.3k|    crv = sftk_defaultAttribute(object, CKA_SIGN, &sign, sizeof(CK_BBOOL));
  ------------------
  |  |  551|  47.3k|#define CKA_SIGN 0x00000108UL
  ------------------
 1350|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1350:9): [True: 0, False: 47.3k]
  ------------------
 1351|      0|        return crv;
 1352|  47.3k|    crv = sftk_defaultAttribute(object, CKA_SIGN_RECOVER, &recover,
  ------------------
  |  |  552|  47.3k|#define CKA_SIGN_RECOVER 0x00000109UL
  ------------------
 1353|  47.3k|                                sizeof(CK_BBOOL));
 1354|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1354:9): [True: 0, False: 47.3k]
  ------------------
 1355|      0|        return crv;
 1356|  47.3k|    crv = sftk_defaultAttribute(object, CKA_UNWRAP, &wrap, sizeof(CK_BBOOL));
  ------------------
  |  |  550|  47.3k|#define CKA_UNWRAP 0x00000107UL
  ------------------
 1357|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1357:9): [True: 0, False: 47.3k]
  ------------------
 1358|      0|        return crv;
 1359|  47.3k|    crv = sftk_defaultAttribute(object, CKA_DERIVE, &derive, sizeof(CK_BBOOL));
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 1360|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1360:9): [True: 0, False: 47.3k]
  ------------------
 1361|      0|        return crv;
 1362|       |    /* the next two bits get modified only in the key gen and token cases */
 1363|  47.3k|    crv = sftk_forceAttribute(object, CKA_ALWAYS_SENSITIVE,
  ------------------
  |  |  588|  47.3k|#define CKA_ALWAYS_SENSITIVE 0x00000165UL
  ------------------
 1364|  47.3k|                              &ckfalse, sizeof(CK_BBOOL));
 1365|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1365:9): [True: 0, False: 47.3k]
  ------------------
 1366|      0|        return crv;
 1367|  47.3k|    crv = sftk_forceAttribute(object, CKA_NEVER_EXTRACTABLE,
  ------------------
  |  |  587|  47.3k|#define CKA_NEVER_EXTRACTABLE 0x00000164UL
  ------------------
 1368|  47.3k|                              &ckfalse, sizeof(CK_BBOOL));
 1369|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1369:9): [True: 0, False: 47.3k]
  ------------------
 1370|      0|        return crv;
 1371|       |
 1372|       |    /* should we check the non-token RSA private keys? */
 1373|       |
 1374|  47.3k|    if (sftk_isTrue(object, CKA_TOKEN)) {
  ------------------
  |  |  512|  47.3k|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (1374:9): [True: 0, False: 47.3k]
  ------------------
 1375|      0|        SFTKSlot *slot = session->slot;
 1376|      0|        SFTKDBHandle *keyHandle = sftk_getKeyDB(slot);
 1377|       |
 1378|      0|        if (keyHandle == NULL) {
  ------------------
  |  Branch (1378:13): [True: 0, False: 0]
  ------------------
 1379|      0|            return CKR_TOKEN_WRITE_PROTECTED;
  ------------------
  |  | 1481|      0|#define CKR_TOKEN_WRITE_PROTECTED 0x000000E2UL
  ------------------
 1380|      0|        }
 1381|       |
 1382|      0|        crv = sftkdb_write(keyHandle, object, &object->handle);
 1383|      0|        sftk_freeDB(keyHandle);
 1384|      0|        return crv;
 1385|  47.3k|    } else if (createObjectInfo) {
  ------------------
  |  Branch (1385:16): [True: 47.3k, False: 0]
  ------------------
 1386|  47.3k|        object->objectInfo = sftk_mkPrivKey(object, key_type, &crv);
 1387|  47.3k|        if (object->objectInfo == NULL)
  ------------------
  |  Branch (1387:13): [True: 0, False: 47.3k]
  ------------------
 1388|      0|            return crv;
 1389|  47.3k|        object->infoFree = SFTKFree_nsslowkey_DestroyPrivateKey;
 1390|  47.3k|    }
 1391|  47.3k|    return CKR_OK;
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
 1392|  47.3k|}
pkcs11.c:sftk_verifyRSAPrivateKey:
 2216|      4|{
 2217|      4|    RSAPrivateKey tmpKey = { 0 };
 2218|      4|    SFTKAttribute *modulus = NULL;
 2219|      4|    SFTKAttribute *prime1 = NULL;
 2220|      4|    SFTKAttribute *prime2 = NULL;
 2221|      4|    SFTKAttribute *privateExponent = NULL;
 2222|      4|    SFTKAttribute *publicExponent = NULL;
 2223|      4|    SFTKAttribute *exponent1 = NULL;
 2224|      4|    SFTKAttribute *exponent2 = NULL;
 2225|      4|    SFTKAttribute *coefficient = NULL;
 2226|      4|    SECStatus rv;
 2227|      4|    CK_RV crv;
 2228|       |
 2229|       |    /* first fill in the components that we have. Populate only uses
 2230|       |     * the non-crt components, so only fill those in  */
 2231|      4|    tmpKey.arena = NULL;
 2232|      4|    modulus = sftk_FindAttribute(object, CKA_MODULUS);
  ------------------
  |  |  558|      4|#define CKA_MODULUS 0x00000120UL
  ------------------
 2233|      4|    if (modulus) {
  ------------------
  |  Branch (2233:9): [True: 4, False: 0]
  ------------------
 2234|      4|        tmpKey.modulus.data = modulus->attrib.pValue;
 2235|      4|        tmpKey.modulus.len = modulus->attrib.ulValueLen;
 2236|      4|    }
 2237|      4|    prime1 = sftk_FindAttribute(object, CKA_PRIME_1);
  ------------------
  |  |  562|      4|#define CKA_PRIME_1 0x00000124UL
  ------------------
 2238|      4|    if (prime1) {
  ------------------
  |  Branch (2238:9): [True: 4, False: 0]
  ------------------
 2239|      4|        tmpKey.prime1.data = prime1->attrib.pValue;
 2240|      4|        tmpKey.prime1.len = prime1->attrib.ulValueLen;
 2241|      4|    }
 2242|      4|    prime2 = sftk_FindAttribute(object, CKA_PRIME_2);
  ------------------
  |  |  563|      4|#define CKA_PRIME_2 0x00000125UL
  ------------------
 2243|      4|    if (prime2) {
  ------------------
  |  Branch (2243:9): [True: 4, False: 0]
  ------------------
 2244|      4|        tmpKey.prime2.data = prime2->attrib.pValue;
 2245|      4|        tmpKey.prime2.len = prime2->attrib.ulValueLen;
 2246|      4|    }
 2247|      4|    privateExponent = sftk_FindAttribute(object, CKA_PRIVATE_EXPONENT);
  ------------------
  |  |  561|      4|#define CKA_PRIVATE_EXPONENT 0x00000123UL
  ------------------
 2248|      4|    if (privateExponent) {
  ------------------
  |  Branch (2248:9): [True: 4, False: 0]
  ------------------
 2249|      4|        tmpKey.privateExponent.data = privateExponent->attrib.pValue;
 2250|      4|        tmpKey.privateExponent.len = privateExponent->attrib.ulValueLen;
 2251|      4|    }
 2252|      4|    publicExponent = sftk_FindAttribute(object, CKA_PUBLIC_EXPONENT);
  ------------------
  |  |  560|      4|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 2253|      4|    if (publicExponent) {
  ------------------
  |  Branch (2253:9): [True: 4, False: 0]
  ------------------
 2254|      4|        tmpKey.publicExponent.data = publicExponent->attrib.pValue;
 2255|      4|        tmpKey.publicExponent.len = publicExponent->attrib.ulValueLen;
 2256|      4|    }
 2257|      4|    exponent1 = sftk_FindAttribute(object, CKA_EXPONENT_1);
  ------------------
  |  |  564|      4|#define CKA_EXPONENT_1 0x00000126UL
  ------------------
 2258|      4|    if (exponent1) {
  ------------------
  |  Branch (2258:9): [True: 4, False: 0]
  ------------------
 2259|      4|        tmpKey.exponent1.data = exponent1->attrib.pValue;
 2260|      4|        tmpKey.exponent1.len = exponent1->attrib.ulValueLen;
 2261|      4|    }
 2262|      4|    exponent2 = sftk_FindAttribute(object, CKA_EXPONENT_2);
  ------------------
  |  |  565|      4|#define CKA_EXPONENT_2 0x00000127UL
  ------------------
 2263|      4|    if (exponent2) {
  ------------------
  |  Branch (2263:9): [True: 4, False: 0]
  ------------------
 2264|      4|        tmpKey.exponent2.data = exponent2->attrib.pValue;
 2265|      4|        tmpKey.exponent2.len = exponent2->attrib.ulValueLen;
 2266|      4|    }
 2267|      4|    coefficient = sftk_FindAttribute(object, CKA_COEFFICIENT);
  ------------------
  |  |  566|      4|#define CKA_COEFFICIENT 0x00000128UL
  ------------------
 2268|      4|    if (coefficient) {
  ------------------
  |  Branch (2268:9): [True: 4, False: 0]
  ------------------
 2269|      4|        tmpKey.coefficient.data = coefficient->attrib.pValue;
 2270|      4|        tmpKey.coefficient.len = coefficient->attrib.ulValueLen;
 2271|      4|    }
 2272|       |
 2273|      4|    if (fillIfNeeded) {
  ------------------
  |  Branch (2273:9): [True: 0, False: 4]
  ------------------
 2274|       |        /*
 2275|       |         * populate requires one exponent plus 2 other components to work.
 2276|       |         * we expected our caller to check that first. If that didn't happen,
 2277|       |         * populate will simply return an error here.
 2278|       |         */
 2279|      0|        rv = RSA_PopulatePrivateKey(&tmpKey);
 2280|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2280:13): [True: 0, False: 0]
  ------------------
 2281|      0|            goto loser;
 2282|      0|        }
 2283|      0|    }
 2284|      4|    rv = RSA_PrivateKeyCheck(&tmpKey);
 2285|      4|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2285:9): [True: 0, False: 4]
  ------------------
 2286|      0|        goto loser;
 2287|      0|    }
 2288|       |    /* now that we have a fully populated key, set all our attribute values */
 2289|      4|    rv = SECFailure;
 2290|      4|    if (!modulus || modulus->attrib.pValue != tmpKey.modulus.data) {
  ------------------
  |  Branch (2290:9): [True: 0, False: 4]
  |  Branch (2290:21): [True: 0, False: 4]
  ------------------
 2291|      0|        crv = sftk_forceAttribute(object, CKA_MODULUS,
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
 2292|      0|                                  sftk_item_expand(&tmpKey.modulus));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2293|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2293:13): [True: 0, False: 0]
  ------------------
 2294|      0|            goto loser;
 2295|      0|    }
 2296|      4|    if (!publicExponent ||
  ------------------
  |  Branch (2296:9): [True: 0, False: 4]
  ------------------
 2297|      4|        publicExponent->attrib.pValue != tmpKey.publicExponent.data) {
  ------------------
  |  Branch (2297:9): [True: 0, False: 4]
  ------------------
 2298|      0|        crv = sftk_forceAttribute(object, CKA_PUBLIC_EXPONENT,
  ------------------
  |  |  560|      0|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 2299|      0|                                  sftk_item_expand(&tmpKey.publicExponent));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2300|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2300:13): [True: 0, False: 0]
  ------------------
 2301|      0|            goto loser;
 2302|      0|    }
 2303|      4|    if (!privateExponent ||
  ------------------
  |  Branch (2303:9): [True: 0, False: 4]
  ------------------
 2304|      4|        privateExponent->attrib.pValue != tmpKey.privateExponent.data) {
  ------------------
  |  Branch (2304:9): [True: 0, False: 4]
  ------------------
 2305|      0|        crv = sftk_forceAttribute(object, CKA_PRIVATE_EXPONENT,
  ------------------
  |  |  561|      0|#define CKA_PRIVATE_EXPONENT 0x00000123UL
  ------------------
 2306|      0|                                  sftk_item_expand(&tmpKey.privateExponent));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2307|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2307:13): [True: 0, False: 0]
  ------------------
 2308|      0|            goto loser;
 2309|      0|    }
 2310|      4|    if (!prime1 || prime1->attrib.pValue != tmpKey.prime1.data) {
  ------------------
  |  Branch (2310:9): [True: 0, False: 4]
  |  Branch (2310:20): [True: 0, False: 4]
  ------------------
 2311|      0|        crv = sftk_forceAttribute(object, CKA_PRIME_1,
  ------------------
  |  |  562|      0|#define CKA_PRIME_1 0x00000124UL
  ------------------
 2312|      0|                                  sftk_item_expand(&tmpKey.prime1));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2313|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2313:13): [True: 0, False: 0]
  ------------------
 2314|      0|            goto loser;
 2315|      0|    }
 2316|      4|    if (!prime2 || prime2->attrib.pValue != tmpKey.prime2.data) {
  ------------------
  |  Branch (2316:9): [True: 0, False: 4]
  |  Branch (2316:20): [True: 0, False: 4]
  ------------------
 2317|      0|        crv = sftk_forceAttribute(object, CKA_PRIME_2,
  ------------------
  |  |  563|      0|#define CKA_PRIME_2 0x00000125UL
  ------------------
 2318|      0|                                  sftk_item_expand(&tmpKey.prime2));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2319|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2319:13): [True: 0, False: 0]
  ------------------
 2320|      0|            goto loser;
 2321|      0|    }
 2322|      4|    if (!exponent1 || exponent1->attrib.pValue != tmpKey.exponent1.data) {
  ------------------
  |  Branch (2322:9): [True: 0, False: 4]
  |  Branch (2322:23): [True: 0, False: 4]
  ------------------
 2323|      0|        crv = sftk_forceAttribute(object, CKA_EXPONENT_1,
  ------------------
  |  |  564|      0|#define CKA_EXPONENT_1 0x00000126UL
  ------------------
 2324|      0|                                  sftk_item_expand(&tmpKey.exponent1));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2325|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2325:13): [True: 0, False: 0]
  ------------------
 2326|      0|            goto loser;
 2327|      0|    }
 2328|      4|    if (!exponent2 || exponent2->attrib.pValue != tmpKey.exponent2.data) {
  ------------------
  |  Branch (2328:9): [True: 0, False: 4]
  |  Branch (2328:23): [True: 0, False: 4]
  ------------------
 2329|      0|        crv = sftk_forceAttribute(object, CKA_EXPONENT_2,
  ------------------
  |  |  565|      0|#define CKA_EXPONENT_2 0x00000127UL
  ------------------
 2330|      0|                                  sftk_item_expand(&tmpKey.exponent2));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2331|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2331:13): [True: 0, False: 0]
  ------------------
 2332|      0|            goto loser;
 2333|      0|    }
 2334|      4|    if (!coefficient || coefficient->attrib.pValue != tmpKey.coefficient.data) {
  ------------------
  |  Branch (2334:9): [True: 0, False: 4]
  |  Branch (2334:25): [True: 0, False: 4]
  ------------------
 2335|      0|        crv = sftk_forceAttribute(object, CKA_COEFFICIENT,
  ------------------
  |  |  566|      0|#define CKA_COEFFICIENT 0x00000128UL
  ------------------
 2336|      0|                                  sftk_item_expand(&tmpKey.coefficient));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 2337|      0|        if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2337:13): [True: 0, False: 0]
  ------------------
 2338|      0|            goto loser;
 2339|      0|    }
 2340|      4|    rv = SECSuccess;
 2341|       |
 2342|       |/* we're done (one way or the other), clean up all our stuff */
 2343|      4|loser:
 2344|      4|    if (tmpKey.arena) {
  ------------------
  |  Branch (2344:9): [True: 0, False: 4]
  ------------------
 2345|      0|        PORT_FreeArena(tmpKey.arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(tmpKey.arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2346|      0|    }
 2347|      4|    if (modulus) {
  ------------------
  |  Branch (2347:9): [True: 4, False: 0]
  ------------------
 2348|      4|        sftk_FreeAttribute(modulus);
 2349|      4|    }
 2350|      4|    if (prime1) {
  ------------------
  |  Branch (2350:9): [True: 4, False: 0]
  ------------------
 2351|      4|        sftk_FreeAttribute(prime1);
 2352|      4|    }
 2353|      4|    if (prime2) {
  ------------------
  |  Branch (2353:9): [True: 4, False: 0]
  ------------------
 2354|      4|        sftk_FreeAttribute(prime2);
 2355|      4|    }
 2356|      4|    if (privateExponent) {
  ------------------
  |  Branch (2356:9): [True: 4, False: 0]
  ------------------
 2357|      4|        sftk_FreeAttribute(privateExponent);
 2358|      4|    }
 2359|      4|    if (publicExponent) {
  ------------------
  |  Branch (2359:9): [True: 4, False: 0]
  ------------------
 2360|      4|        sftk_FreeAttribute(publicExponent);
 2361|      4|    }
 2362|      4|    if (exponent1) {
  ------------------
  |  Branch (2362:9): [True: 4, False: 0]
  ------------------
 2363|      4|        sftk_FreeAttribute(exponent1);
 2364|      4|    }
 2365|      4|    if (exponent2) {
  ------------------
  |  Branch (2365:9): [True: 4, False: 0]
  ------------------
 2366|      4|        sftk_FreeAttribute(exponent2);
 2367|      4|    }
 2368|      4|    if (coefficient) {
  ------------------
  |  Branch (2368:9): [True: 4, False: 0]
  ------------------
 2369|      4|        sftk_FreeAttribute(coefficient);
 2370|      4|    }
 2371|      4|    return rv;
 2372|      4|}
pkcs11.c:sftk_handleSecretKeyObject:
 1520|   909k|{
 1521|   909k|    CK_RV crv;
 1522|       |
 1523|       |    /* First validate and set defaults */
 1524|   909k|    crv = validateSecretKey(session, object, key_type, isFIPS);
 1525|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1525:9): [True: 0, False: 909k]
  ------------------
 1526|      0|        goto loser;
 1527|       |
 1528|       |    /* If the object is a TOKEN object, store in the database */
 1529|   909k|    if (sftk_isTrue(object, CKA_TOKEN)) {
  ------------------
  |  |  512|   909k|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (1529:9): [True: 0, False: 909k]
  ------------------
 1530|      0|        SFTKSlot *slot = session->slot;
 1531|      0|        SFTKDBHandle *keyHandle = sftk_getKeyDB(slot);
 1532|       |
 1533|      0|        if (keyHandle == NULL) {
  ------------------
  |  Branch (1533:13): [True: 0, False: 0]
  ------------------
 1534|      0|            return CKR_TOKEN_WRITE_PROTECTED;
  ------------------
  |  | 1481|      0|#define CKR_TOKEN_WRITE_PROTECTED 0x000000E2UL
  ------------------
 1535|      0|        }
 1536|       |
 1537|      0|        crv = sftkdb_write(keyHandle, object, &object->handle);
 1538|      0|        sftk_freeDB(keyHandle);
 1539|      0|        return crv;
 1540|      0|    }
 1541|       |
 1542|   909k|loser:
 1543|       |
 1544|   909k|    return crv;
 1545|   909k|}
pkcs11.c:validateSecretKey:
 1401|   909k|{
 1402|   909k|    CK_RV crv;
 1403|   909k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|   909k|#define CK_TRUE 1
  ------------------
 1404|   909k|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|   909k|#define CK_FALSE 0
  ------------------
 1405|   909k|    SFTKAttribute *attribute = NULL;
 1406|   909k|    unsigned long requiredLen;
 1407|       |
 1408|   909k|    crv = sftk_defaultAttribute(object, CKA_SENSITIVE,
  ------------------
  |  |  546|   909k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 1409|   909k|                                isFIPS ? &cktrue : &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  Branch (1409:33): [True: 0, False: 909k]
  ------------------
 1410|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1410:9): [True: 0, False: 909k]
  ------------------
 1411|      0|        return crv;
 1412|   909k|    crv = sftk_defaultAttribute(object, CKA_EXTRACTABLE,
  ------------------
  |  |  585|   909k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 1413|   909k|                                &cktrue, sizeof(CK_BBOOL));
 1414|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1414:9): [True: 0, False: 909k]
  ------------------
 1415|      0|        return crv;
 1416|   909k|    crv = sftk_defaultAttribute(object, CKA_ENCRYPT, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  547|   909k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1417|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1417:9): [True: 0, False: 909k]
  ------------------
 1418|      0|        return crv;
 1419|   909k|    crv = sftk_defaultAttribute(object, CKA_DECRYPT, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  548|   909k|#define CKA_DECRYPT 0x00000105UL
  ------------------
 1420|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1420:9): [True: 0, False: 909k]
  ------------------
 1421|      0|        return crv;
 1422|   909k|    crv = sftk_defaultAttribute(object, CKA_SIGN, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  551|   909k|#define CKA_SIGN 0x00000108UL
  ------------------
 1423|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1423:9): [True: 0, False: 909k]
  ------------------
 1424|      0|        return crv;
 1425|   909k|    crv = sftk_defaultAttribute(object, CKA_VERIFY, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  553|   909k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 1426|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1426:9): [True: 0, False: 909k]
  ------------------
 1427|      0|        return crv;
 1428|   909k|    crv = sftk_defaultAttribute(object, CKA_WRAP, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  549|   909k|#define CKA_WRAP 0x00000106UL
  ------------------
 1429|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1429:9): [True: 0, False: 909k]
  ------------------
 1430|      0|        return crv;
 1431|   909k|    crv = sftk_defaultAttribute(object, CKA_UNWRAP, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  550|   909k|#define CKA_UNWRAP 0x00000107UL
  ------------------
 1432|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1432:9): [True: 0, False: 909k]
  ------------------
 1433|      0|        return crv;
 1434|       |
 1435|   909k|    if (!sftk_hasAttribute(object, CKA_VALUE)) {
  ------------------
  |  |  516|   909k|#define CKA_VALUE 0x00000011UL
  ------------------
  |  Branch (1435:9): [True: 0, False: 909k]
  ------------------
 1436|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1437|      0|    }
 1438|       |    /* the next two bits get modified only in the key gen and token cases */
 1439|   909k|    crv = sftk_forceAttribute(object, CKA_ALWAYS_SENSITIVE,
  ------------------
  |  |  588|   909k|#define CKA_ALWAYS_SENSITIVE 0x00000165UL
  ------------------
 1440|   909k|                              &ckfalse, sizeof(CK_BBOOL));
 1441|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1441:9): [True: 0, False: 909k]
  ------------------
 1442|      0|        return crv;
 1443|   909k|    crv = sftk_forceAttribute(object, CKA_NEVER_EXTRACTABLE,
  ------------------
  |  |  587|   909k|#define CKA_NEVER_EXTRACTABLE 0x00000164UL
  ------------------
 1444|   909k|                              &ckfalse, sizeof(CK_BBOOL));
 1445|   909k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1445:9): [True: 0, False: 909k]
  ------------------
 1446|      0|        return crv;
 1447|       |
 1448|       |    /* some types of keys have a value length */
 1449|   909k|    crv = CKR_OK;
  ------------------
  |  | 1388|   909k|#define CKR_OK 0x00000000UL
  ------------------
 1450|   909k|    switch (key_type) {
 1451|       |        /* force CKA_VALUE_LEN to be set */
 1452|   511k|        case CKK_GENERIC_SECRET:
  ------------------
  |  |  383|   511k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  |  Branch (1452:9): [True: 511k, False: 397k]
  ------------------
 1453|   511k|        case CKK_RC2:
  ------------------
  |  |  384|   511k|#define CKK_RC2 0x00000011UL
  ------------------
  |  Branch (1453:9): [True: 0, False: 909k]
  ------------------
 1454|   512k|        case CKK_RC4:
  ------------------
  |  |  385|   512k|#define CKK_RC4 0x00000012UL
  ------------------
  |  Branch (1454:9): [True: 1.18k, False: 907k]
  ------------------
 1455|       |#if NSS_SOFTOKEN_DOES_RC5
 1456|       |        case CKK_RC5:
 1457|       |#endif
 1458|       |#ifdef NSS_SOFTOKEN_DOES_CAST
 1459|       |        case CKK_CAST:
 1460|       |        case CKK_CAST3:
 1461|       |        case CKK_CAST5:
 1462|       |#endif
 1463|       |#if NSS_SOFTOKEN_DOES_IDEA
 1464|       |        case CKK_IDEA:
 1465|       |#endif
 1466|   512k|            attribute = sftk_FindAttribute(object, CKA_VALUE);
  ------------------
  |  |  516|   512k|#define CKA_VALUE 0x00000011UL
  ------------------
 1467|       |            /* shouldn't happen */
 1468|   512k|            if (attribute == NULL)
  ------------------
  |  Branch (1468:17): [True: 0, False: 512k]
  ------------------
 1469|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1470|   512k|            crv = sftk_forceAttribute(object, CKA_VALUE_LEN,
  ------------------
  |  |  580|   512k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
 1471|   512k|                                      &attribute->attrib.ulValueLen, sizeof(CK_ULONG));
 1472|   512k|            sftk_FreeAttribute(attribute);
 1473|   512k|            break;
 1474|       |        /* force the value to have the correct parity */
 1475|  14.8k|        case CKK_DES:
  ------------------
  |  |  386|  14.8k|#define CKK_DES 0x00000013UL
  ------------------
  |  Branch (1475:9): [True: 14.8k, False: 894k]
  ------------------
 1476|  14.8k|        case CKK_DES2:
  ------------------
  |  |  387|  14.8k|#define CKK_DES2 0x00000014UL
  ------------------
  |  Branch (1476:9): [True: 0, False: 909k]
  ------------------
 1477|  24.9k|        case CKK_DES3:
  ------------------
  |  |  388|  24.9k|#define CKK_DES3 0x00000015UL
  ------------------
  |  Branch (1477:9): [True: 10.1k, False: 898k]
  ------------------
 1478|  24.9k|        case CKK_CDMF:
  ------------------
  |  |  401|  24.9k|#define CKK_CDMF 0x0000001EUL
  ------------------
  |  Branch (1478:9): [True: 0, False: 909k]
  ------------------
 1479|  24.9k|            attribute = sftk_FindAttribute(object, CKA_VALUE);
  ------------------
  |  |  516|  24.9k|#define CKA_VALUE 0x00000011UL
  ------------------
 1480|       |            /* shouldn't happen */
 1481|  24.9k|            if (attribute == NULL)
  ------------------
  |  Branch (1481:17): [True: 0, False: 24.9k]
  ------------------
 1482|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1483|  24.9k|            requiredLen = sftk_MapKeySize(key_type);
 1484|  24.9k|            if (attribute->attrib.ulValueLen != requiredLen) {
  ------------------
  |  Branch (1484:17): [True: 0, False: 24.9k]
  ------------------
 1485|      0|                sftk_FreeAttribute(attribute);
 1486|      0|                return CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
 1487|      0|            }
 1488|  24.9k|            sftk_FormatDESKey((unsigned char *)attribute->attrib.pValue,
 1489|  24.9k|                              attribute->attrib.ulValueLen);
 1490|  24.9k|            sftk_FreeAttribute(attribute);
 1491|  24.9k|            break;
 1492|   343k|        case CKK_AES:
  ------------------
  |  |  402|   343k|#define CKK_AES 0x0000001FUL
  ------------------
  |  Branch (1492:9): [True: 343k, False: 566k]
  ------------------
 1493|   343k|            attribute = sftk_FindAttribute(object, CKA_VALUE);
  ------------------
  |  |  516|   343k|#define CKA_VALUE 0x00000011UL
  ------------------
 1494|       |            /* shouldn't happen */
 1495|   343k|            if (attribute == NULL)
  ------------------
  |  Branch (1495:17): [True: 0, False: 343k]
  ------------------
 1496|      0|                return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 1497|   343k|            if (attribute->attrib.ulValueLen != 16 &&
  ------------------
  |  Branch (1497:17): [True: 320k, False: 22.7k]
  ------------------
 1498|   343k|                attribute->attrib.ulValueLen != 24 &&
  ------------------
  |  Branch (1498:17): [True: 320k, False: 0]
  ------------------
 1499|   343k|                attribute->attrib.ulValueLen != 32) {
  ------------------
  |  Branch (1499:17): [True: 0, False: 320k]
  ------------------
 1500|      0|                sftk_FreeAttribute(attribute);
 1501|      0|                return CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
 1502|      0|            }
 1503|   343k|            crv = sftk_forceAttribute(object, CKA_VALUE_LEN,
  ------------------
  |  |  580|   343k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
 1504|   343k|                                      &attribute->attrib.ulValueLen, sizeof(CK_ULONG));
 1505|   343k|            sftk_FreeAttribute(attribute);
 1506|   343k|            break;
 1507|  28.3k|        default:
  ------------------
  |  Branch (1507:9): [True: 28.3k, False: 880k]
  ------------------
 1508|  28.3k|            break;
 1509|   909k|    }
 1510|       |
 1511|   909k|    return crv;
 1512|   909k|}
pkcs11.c:sftk_mkPrivKey:
 2040|  47.3k|{
 2041|  47.3k|    NSSLOWKEYPrivateKey *privKey;
 2042|  47.3k|    SFTKItemTemplate itemTemplate[SFTK_MAX_ITEM_TEMPLATE];
 2043|  47.3k|    int itemTemplateCount = 0;
 2044|  47.3k|    PLArenaPool *arena;
 2045|  47.3k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
 2046|  47.3k|    SECStatus rv;
 2047|       |
 2048|  47.3k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  47.3k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  47.3k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 2049|  47.3k|    if (arena == NULL) {
  ------------------
  |  Branch (2049:9): [True: 0, False: 47.3k]
  ------------------
 2050|      0|        *crvp = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2051|      0|        return NULL;
 2052|      0|    }
 2053|       |
 2054|  47.3k|    privKey = (NSSLOWKEYPrivateKey *)
 2055|  47.3k|        PORT_ArenaZAlloc(arena, sizeof(NSSLOWKEYPrivateKey));
  ------------------
  |  |   59|  47.3k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 2056|  47.3k|    if (privKey == NULL) {
  ------------------
  |  Branch (2056:9): [True: 0, False: 47.3k]
  ------------------
 2057|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2058|      0|        *crvp = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2059|      0|        return NULL;
 2060|      0|    }
 2061|       |
 2062|       |    /* in future this would be a switch on key_type */
 2063|  47.3k|    privKey->arena = arena;
 2064|  47.3k|    switch (key_type) {
 2065|      4|        case CKK_RSA:
  ------------------
  |  |  372|      4|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (2065:9): [True: 4, False: 47.3k]
  ------------------
 2066|      4|            privKey->keyType = NSSLOWKEYRSAKey;
 2067|       |
 2068|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2069|      4|                                   &privKey->u.rsa.modulus, CKA_MODULUS);
 2070|      4|            itemTemplateCount++;
 2071|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2072|      4|                                   &privKey->u.rsa.publicExponent, CKA_PUBLIC_EXPONENT);
 2073|      4|            itemTemplateCount++;
 2074|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2075|      4|                                   &privKey->u.rsa.privateExponent, CKA_PRIVATE_EXPONENT);
 2076|      4|            itemTemplateCount++;
 2077|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2078|      4|                                   &privKey->u.rsa.prime1, CKA_PRIME_1);
 2079|      4|            itemTemplateCount++;
 2080|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2081|      4|                                   &privKey->u.rsa.prime2, CKA_PRIME_2);
 2082|      4|            itemTemplateCount++;
 2083|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2084|      4|                                   &privKey->u.rsa.exponent1, CKA_EXPONENT_1);
 2085|      4|            itemTemplateCount++;
 2086|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2087|      4|                                   &privKey->u.rsa.exponent2, CKA_EXPONENT_2);
 2088|      4|            itemTemplateCount++;
 2089|      4|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      4|    templ[count].type = attr;                               \
  |  |  466|      4|    templ[count].item = itemPtr
  ------------------
 2090|      4|                                   &privKey->u.rsa.coefficient, CKA_COEFFICIENT);
 2091|      4|            itemTemplateCount++;
 2092|      4|            rv = DER_SetUInteger(privKey->arena, &privKey->u.rsa.version,
 2093|      4|                                 NSSLOWKEY_PRIVATE_KEY_INFO_VERSION);
  ------------------
  |  |   51|      4|#define NSSLOWKEY_PRIVATE_KEY_INFO_VERSION 0 /* what we *create* */
  ------------------
 2094|      4|            if (rv != SECSuccess)
  ------------------
  |  Branch (2094:17): [True: 0, False: 4]
  ------------------
 2095|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2096|      4|            break;
 2097|       |
 2098|      0|        case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (2098:9): [True: 0, False: 47.3k]
  ------------------
 2099|      0|            privKey->keyType = NSSLOWKEYDSAKey;
 2100|      0|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      0|    templ[count].type = attr;                               \
  |  |  466|      0|    templ[count].item = itemPtr
  ------------------
 2101|      0|                                   &privKey->u.dsa.params.prime, CKA_PRIME);
 2102|      0|            itemTemplateCount++;
 2103|      0|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      0|    templ[count].type = attr;                               \
  |  |  466|      0|    templ[count].item = itemPtr
  ------------------
 2104|      0|                                   &privKey->u.dsa.params.subPrime, CKA_SUBPRIME);
 2105|      0|            itemTemplateCount++;
 2106|      0|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      0|    templ[count].type = attr;                               \
  |  |  466|      0|    templ[count].item = itemPtr
  ------------------
 2107|      0|                                   &privKey->u.dsa.params.base, CKA_BASE);
 2108|      0|            itemTemplateCount++;
 2109|      0|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|      0|    templ[count].type = attr;                               \
  |  |  466|      0|    templ[count].item = itemPtr
  ------------------
 2110|      0|                                   &privKey->u.dsa.privateValue, CKA_VALUE);
 2111|      0|            itemTemplateCount++;
 2112|       |            /* privKey was zero'd so public value is already set to NULL, 0
 2113|       |             * if we don't set it explicitly */
 2114|      0|            break;
 2115|       |
 2116|  29.0k|        case CKK_DH:
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (2116:9): [True: 29.0k, False: 18.2k]
  ------------------
 2117|  29.0k|            privKey->keyType = NSSLOWKEYDHKey;
 2118|  29.0k|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|  29.0k|    templ[count].type = attr;                               \
  |  |  466|  29.0k|    templ[count].item = itemPtr
  ------------------
 2119|  29.0k|                                   &privKey->u.dh.prime, CKA_PRIME);
 2120|  29.0k|            itemTemplateCount++;
 2121|  29.0k|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|  29.0k|    templ[count].type = attr;                               \
  |  |  466|  29.0k|    templ[count].item = itemPtr
  ------------------
 2122|  29.0k|                                   &privKey->u.dh.base, CKA_BASE);
 2123|  29.0k|            itemTemplateCount++;
 2124|  29.0k|            SFTK_SET_ITEM_TEMPLATE(itemTemplate, itemTemplateCount,
  ------------------
  |  |  465|  29.0k|    templ[count].type = attr;                               \
  |  |  466|  29.0k|    templ[count].item = itemPtr
  ------------------
 2125|  29.0k|                                   &privKey->u.dh.privateValue, CKA_VALUE);
 2126|  29.0k|            itemTemplateCount++;
 2127|       |            /* privKey was zero'd so public value is already set to NULL, 0
 2128|       |             * if we don't set it explicitly */
 2129|  29.0k|            break;
 2130|      0|        case CKK_EC_EDWARDS:
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (2130:9): [True: 0, False: 47.3k]
  ------------------
 2131|      0|        case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (2131:9): [True: 0, False: 47.3k]
  ------------------
 2132|  18.2k|        case CKK_EC:
  ------------------
  |  |  379|  18.2k|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (2132:9): [True: 18.2k, False: 29.0k]
  ------------------
 2133|  18.2k|            privKey->keyType = NSSLOWKEYECKey;
 2134|  18.2k|            crv = sftk_Attribute2SSecItem(arena,
 2135|  18.2k|                                          &privKey->u.ec.ecParams.DEREncoding,
 2136|  18.2k|                                          object, CKA_EC_PARAMS);
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 2137|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2137:17): [True: 0, False: 18.2k]
  ------------------
 2138|      0|                break;
 2139|       |
 2140|       |            /* Fill out the rest of the ecParams structure
 2141|       |             * based on the encoded params
 2142|       |             */
 2143|  18.2k|            if (EC_FillParams(arena, &privKey->u.ec.ecParams.DEREncoding,
  ------------------
  |  Branch (2143:17): [True: 0, False: 18.2k]
  ------------------
 2144|  18.2k|                              &privKey->u.ec.ecParams) != SECSuccess) {
 2145|      0|                crv = CKR_DOMAIN_PARAMS_INVALID;
  ------------------
  |  | 1508|      0|#define CKR_DOMAIN_PARAMS_INVALID 0x00000130UL
  ------------------
 2146|      0|                break;
 2147|      0|            }
 2148|  18.2k|            crv = sftk_Attribute2SSecItem(arena, &privKey->u.ec.privateValue,
 2149|  18.2k|                                          object, CKA_VALUE);
  ------------------
  |  |  516|  18.2k|#define CKA_VALUE 0x00000011UL
  ------------------
 2150|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2150:17): [True: 0, False: 18.2k]
  ------------------
 2151|      0|                break;
 2152|       |
 2153|  18.2k|            if (sftk_hasAttribute(object, CKA_NSS_DB)) {
  ------------------
  |  |  150|  18.2k|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
  |  Branch (2153:17): [True: 18.2k, False: 0]
  ------------------
 2154|  18.2k|                crv = sftk_Attribute2SSecItem(arena, &privKey->u.ec.publicValue,
 2155|  18.2k|                                              object, CKA_NSS_DB);
  ------------------
  |  |  150|  18.2k|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 2156|  18.2k|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2156:21): [True: 0, False: 18.2k]
  ------------------
 2157|      0|                    break;
 2158|      0|                }
 2159|       |                /* privKey was zero'd so public value is already set to NULL, 0
 2160|       |                 * if we don't set it explicitly */
 2161|  18.2k|            } else if (key_type == CKK_EC) {
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (2161:24): [True: 0, False: 0]
  ------------------
 2162|       |                /* as no public key was provided during the import, we need to derive it here.
 2163|       |                 See: PK11_ImportAndReturnPrivateKey*/
 2164|      0|                (void)SECITEM_AllocItem(arena, &privKey->u.ec.publicValue, EC_GetPointSize(&privKey->u.ec.ecParams));
  ------------------
  |  |  103|      0|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
 2165|      0|                rv = EC_DerivePublicKey(&privKey->u.ec.privateValue, &privKey->u.ec.ecParams, &privKey->u.ec.publicValue);
 2166|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (2166:21): [True: 0, False: 0]
  ------------------
 2167|      0|                    break;
 2168|      0|                }
 2169|      0|                sftk_forceAttribute(object, CKA_NSS_DB, privKey->u.ec.publicValue.data, privKey->u.ec.publicValue.len);
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 2170|      0|            }
 2171|       |
 2172|  18.2k|            rv = DER_SetUInteger(privKey->arena, &privKey->u.ec.version,
 2173|  18.2k|                                 NSSLOWKEY_EC_PRIVATE_KEY_VERSION);
  ------------------
  |  |   23|  18.2k|#define NSSLOWKEY_EC_PRIVATE_KEY_VERSION 1 /* as per SECG 1 C.4 */
  ------------------
 2174|  18.2k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2174:17): [True: 0, False: 18.2k]
  ------------------
 2175|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2176|       |/* The following ifdef is needed for Linux arm distros and
 2177|       | * Android as gcc 4.6 has a bug when targeting arm (but not
 2178|       | * thumb). The bug has been fixed in gcc 4.7.
 2179|       | * http://gcc.gnu.org/bugzilla/show_bug.cgi?id=56561
 2180|       | */
 2181|       |#if defined(__arm__) && !defined(__thumb__) && defined(__GNUC__)
 2182|       |                *crvp = CKR_HOST_MEMORY;
 2183|       |                break;
 2184|       |#endif
 2185|      0|            }
 2186|  18.2k|            break;
 2187|       |
 2188|      0|        case CKK_NSS_KYBER:
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (2188:9): [True: 0, False: 47.3k]
  ------------------
 2189|      0|        case CKK_NSS_ML_KEM:
  ------------------
  |  |   59|      0|#define CKK_NSS_ML_KEM (CKK_NSS + 6)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (2189:9): [True: 0, False: 47.3k]
  ------------------
 2190|      0|            break;
 2191|       |
 2192|      0|        default:
  ------------------
  |  Branch (2192:9): [True: 0, False: 47.3k]
  ------------------
 2193|      0|            crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 2194|      0|            break;
 2195|  47.3k|    }
 2196|  47.3k|    if (crv == CKR_OK && itemTemplateCount != 0) {
  ------------------
  |  | 1388|  94.6k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2196:9): [True: 47.3k, False: 0]
  |  Branch (2196:26): [True: 29.0k, False: 18.2k]
  ------------------
 2197|  29.0k|        PORT_Assert(itemTemplateCount > 0);
  ------------------
  |  |  120|  29.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 29.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2198|  29.0k|        PORT_Assert(itemTemplateCount <= SFTK_MAX_ITEM_TEMPLATE);
  ------------------
  |  |  120|  29.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 29.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2199|  29.0k|        crv = sftk_MultipleAttribute2SecItem(arena, object, itemTemplate,
 2200|  29.0k|                                             itemTemplateCount);
 2201|  29.0k|    }
 2202|  47.3k|    *crvp = crv;
 2203|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2203:9): [True: 0, False: 47.3k]
  ------------------
 2204|      0|        PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2205|      0|        return NULL;
 2206|      0|    }
 2207|  47.3k|    return privKey;
 2208|  47.3k|}
pkcs11.c:sftk_GetModuleIndex:
 2734|  13.0M|{
 2735|  13.0M|    if (sftk_isFIPS(slotID)) {
  ------------------
  |  |  506|  13.0M|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|  13.0M|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|  13.0M|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 13.0M]
  |  |  |  Branch (506:32): [True: 0, False: 13.0M]
  |  |  ------------------
  ------------------
 2736|      0|        return NSC_FIPS_MODULE;
  ------------------
  |  |   54|      0|#define NSC_FIPS_MODULE 1
  ------------------
 2737|      0|    }
 2738|  13.0M|    return NSC_NON_FIPS_MODULE;
  ------------------
  |  |   55|  13.0M|#define NSC_NON_FIPS_MODULE 0
  ------------------
 2739|  13.0M|}
pkcs11.c:sftk_setStringName:
  688|      6|{
  689|      6|    int full_length, string_length;
  690|       |
  691|      6|    full_length = nullTerminate ? buffer_length - 1 : buffer_length;
  ------------------
  |  Branch (691:19): [True: 6, False: 0]
  ------------------
  692|      6|    string_length = PORT_Strlen(inString);
  ------------------
  |  |  190|      6|#define PORT_Strlen(s) strlen(s)
  ------------------
  693|       |    /*
  694|       |     *  shorten the string, respecting utf8 encoding
  695|       |     *  to do so, we work backward from the end
  696|       |     *  bytes looking from the end are either:
  697|       |     *    - ascii [0x00,0x7f]
  698|       |     *    - the [2-n]th byte of a multibyte sequence
  699|       |     *        [0x3F,0xBF], i.e, most significant 2 bits are '10'
  700|       |     *    - the first byte of a multibyte sequence [0xC0,0xFD],
  701|       |     *        i.e, most significant 2 bits are '11'
  702|       |     *
  703|       |     *    When the string is too long, we lop off any trailing '10' bytes,
  704|       |     *  if any. When these are all eliminated we lop off
  705|       |     *  one additional byte. Thus if we lopped any '10'
  706|       |     *  we'll be lopping a '11' byte (the first byte of the multibyte sequence),
  707|       |     *  otherwise we're lopping off an ascii character.
  708|       |     *
  709|       |     *    To test for '10' bytes, we first AND it with
  710|       |     *  11000000 (0xc0) so that we get 10000000 (0x80) if and only if
  711|       |     *  the byte starts with 10. We test for equality.
  712|       |     */
  713|      6|    while (string_length > full_length) {
  ------------------
  |  Branch (713:12): [True: 0, False: 6]
  ------------------
  714|       |        /* need to shorten */
  715|      0|        while (string_length > 0 &&
  ------------------
  |  Branch (715:16): [True: 0, False: 0]
  ------------------
  716|      0|               ((inString[string_length - 1] & (char)0xc0) == (char)0x80)) {
  ------------------
  |  Branch (716:16): [True: 0, False: 0]
  ------------------
  717|       |            /* lop off '10' byte */
  718|      0|            string_length--;
  719|      0|        }
  720|       |        /*
  721|       |         * test string_length in case bad data is received
  722|       |         * and string consisted of all '10' bytes,
  723|       |         * avoiding any infinite loop
  724|       |         */
  725|      0|        if (string_length) {
  ------------------
  |  Branch (725:13): [True: 0, False: 0]
  ------------------
  726|       |            /* remove either '11' byte or an asci byte */
  727|      0|            string_length--;
  728|      0|        }
  729|      0|    }
  730|      6|    PORT_Memset(buffer, ' ', full_length);
  ------------------
  |  |  182|      6|#define PORT_Memset memset
  ------------------
  731|      6|    if (nullTerminate) {
  ------------------
  |  Branch (731:9): [True: 6, False: 0]
  ------------------
  732|      6|        buffer[full_length] = 0;
  733|      6|    }
  734|      6|    PORT_Memcpy(buffer, inString, string_length);
  ------------------
  |  |  180|      6|#define PORT_Memcpy memcpy
  ------------------
  735|      6|    return buffer;
  736|      6|}
pkcs11.c:sftk_HashNumber:
 2678|  13.0M|{
 2679|  13.0M|    return (PLHashNumber)((char *)key - (char *)NULL);
 2680|  13.0M|}
pkcs11.c:sftk_RegisterSlot:
 2781|      2|{
 2782|      2|    PLHashEntry *entry;
 2783|      2|    unsigned int index;
 2784|       |
 2785|      2|    index = sftk_GetModuleIndex(slot->slotID);
 2786|       |
 2787|       |    /* make sure the slotID for this module is valid */
 2788|      2|    if (moduleIndex != index) {
  ------------------
  |  Branch (2788:9): [True: 0, False: 2]
  ------------------
 2789|      0|        return CKR_SLOT_ID_INVALID;
  ------------------
  |  | 1391|      0|#define CKR_SLOT_ID_INVALID 0x00000003UL
  ------------------
 2790|      0|    }
 2791|       |
 2792|      2|    if (nscSlotList[index] == NULL) {
  ------------------
  |  Branch (2792:9): [True: 1, False: 1]
  ------------------
 2793|      1|        nscSlotListSize[index] = NSC_SLOT_LIST_BLOCK_SIZE;
  ------------------
  |  |   50|      1|#define NSC_SLOT_LIST_BLOCK_SIZE 10
  ------------------
 2794|      1|        nscSlotList[index] = (CK_SLOT_ID *)
 2795|      1|            PORT_ZAlloc(nscSlotListSize[index] * sizeof(CK_SLOT_ID));
  ------------------
  |  |   72|      1|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 2796|      1|        if (nscSlotList[index] == NULL) {
  ------------------
  |  Branch (2796:13): [True: 0, False: 1]
  ------------------
 2797|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2798|      0|        }
 2799|      1|    }
 2800|      2|    if (nscSlotCount[index] >= nscSlotListSize[index]) {
  ------------------
  |  Branch (2800:9): [True: 0, False: 2]
  ------------------
 2801|      0|        CK_SLOT_ID *oldNscSlotList = nscSlotList[index];
 2802|      0|        CK_ULONG oldNscSlotListSize = nscSlotListSize[index];
 2803|      0|        nscSlotListSize[index] += NSC_SLOT_LIST_BLOCK_SIZE;
  ------------------
  |  |   50|      0|#define NSC_SLOT_LIST_BLOCK_SIZE 10
  ------------------
 2804|      0|        nscSlotList[index] = (CK_SLOT_ID *)PORT_Realloc(oldNscSlotList,
  ------------------
  |  |   64|      0|#define PORT_Realloc PORT_Realloc_Util
  ------------------
 2805|      0|                                                        nscSlotListSize[index] * sizeof(CK_SLOT_ID));
 2806|      0|        if (nscSlotList[index] == NULL) {
  ------------------
  |  Branch (2806:13): [True: 0, False: 0]
  ------------------
 2807|       |            /* evidently coverity doesn't know realloc does not
 2808|       |             * free var if it fails ! */
 2809|       |            /* coverity [use_after_free : FALSE] */
 2810|      0|            nscSlotList[index] = oldNscSlotList;
 2811|      0|            nscSlotListSize[index] = oldNscSlotListSize;
 2812|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2813|      0|        }
 2814|      0|    }
 2815|       |
 2816|      2|    if (nscSlotHashTable[index] == NULL) {
  ------------------
  |  Branch (2816:9): [True: 1, False: 1]
  ------------------
 2817|      1|        nscSlotHashTable[index] = PL_NewHashTable(64, sftk_HashNumber,
 2818|      1|                                                  PL_CompareValues, PL_CompareValues, NULL, 0);
 2819|      1|        if (nscSlotHashTable[index] == NULL) {
  ------------------
  |  Branch (2819:13): [True: 0, False: 1]
  ------------------
 2820|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2821|      0|        }
 2822|      1|    }
 2823|       |
 2824|      2|    entry = PL_HashTableAdd(nscSlotHashTable[index], (void *)(uintptr_t)slot->slotID, slot);
 2825|      2|    if (entry == NULL) {
  ------------------
  |  Branch (2825:9): [True: 0, False: 2]
  ------------------
 2826|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2827|      0|    }
 2828|      2|    slot->index = (nscSlotCount[index] & 0x7f) | ((index << 7) & 0x80);
 2829|      2|    nscSlotList[index][nscSlotCount[index]++] = slot->slotID;
 2830|       |
 2831|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 2832|      2|}
pkcs11.c:sftk_DBShutdown:
 3107|      2|{
 3108|      2|    SFTKDBHandle *certHandle;
 3109|      2|    SFTKDBHandle *keyHandle;
 3110|      2|    SKIP_AFTER_FORK(PZ_Lock(slot->slotLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3111|      2|    certHandle = slot->certDB;
 3112|      2|    slot->certDB = NULL;
 3113|      2|    keyHandle = slot->keyDB;
 3114|      2|    slot->keyDB = NULL;
 3115|      2|    SKIP_AFTER_FORK(PZ_Unlock(slot->slotLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 3116|      2|    if (certHandle) {
  ------------------
  |  Branch (3116:9): [True: 0, False: 2]
  ------------------
 3117|      0|        sftk_freeDB(certHandle);
 3118|      0|    }
 3119|      2|    if (keyHandle) {
  ------------------
  |  Branch (3119:9): [True: 0, False: 2]
  ------------------
 3120|      0|        sftk_freeDB(keyHandle);
 3121|      0|    }
 3122|      2|}
pkcs11.c:sftk_getParameters:
 3399|      1|{
 3400|      1|    CK_RV crv;
 3401|      1|    char *libParams;
 3402|      1|    const char *filename;
 3403|      1|    PRFileDesc *file_dc;
 3404|      1|    PRBool free_mem = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 3405|       |
 3406|      1|    if (!init_args || !init_args->LibraryParameters) {
  ------------------
  |  Branch (3406:9): [True: 0, False: 1]
  |  Branch (3406:23): [True: 0, False: 1]
  ------------------
 3407|       |        /* Library parameters were not provided via C_Initialize_args*/
 3408|       |
 3409|       |        /* Enviromental value has precedence to configuration filename */
 3410|      0|        libParams = PR_GetEnvSecure("NSS_LIB_PARAMS");
 3411|       |
 3412|      0|        if (!libParams) {
  ------------------
  |  Branch (3412:13): [True: 0, False: 0]
  ------------------
 3413|       |            /* Load from config filename or use default */
 3414|      0|            filename = PR_GetEnvSecure("NSS_LIB_PARAMS_FILE");
 3415|      0|#ifdef XP_UNIX
 3416|       |            /* Use default configuration file for Linux only */
 3417|      0|            if (!filename)
  ------------------
  |  Branch (3417:17): [True: 0, False: 0]
  ------------------
 3418|      0|                filename = LIB_PARAM_DEFAULT_FILE_LOCATION;
  ------------------
  |  |   65|      0|#define LIB_PARAM_DEFAULT_FILE_LOCATION "/etc/nss/params.config"
  ------------------
 3419|      0|#endif
 3420|      0|            if (filename) {
  ------------------
  |  Branch (3420:17): [True: 0, False: 0]
  ------------------
 3421|      0|                file_dc = PR_OpenFile(filename, PR_RDONLY, 444);
  ------------------
  |  |  577|      0|#define PR_RDONLY       0x01
  ------------------
 3422|      0|                if (file_dc) {
  ------------------
  |  Branch (3422:21): [True: 0, False: 0]
  ------------------
 3423|       |                    /* file opened */
 3424|      0|                    PRInt32 len = PR_Available(file_dc);
 3425|      0|                    libParams = PORT_NewArray(char, len + 1);
  ------------------
  |  |  157|      0|    (type *)PORT_Alloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 3426|      0|                    if (libParams) {
  ------------------
  |  Branch (3426:25): [True: 0, False: 0]
  ------------------
 3427|       |                        /* memory allocated */
 3428|      0|                        if (PR_Read(file_dc, libParams, len) == -1) {
  ------------------
  |  Branch (3428:29): [True: 0, False: 0]
  ------------------
 3429|      0|                            PORT_Free(libParams);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3430|      0|                            libParams = NULL;
 3431|      0|                        } else {
 3432|      0|                            free_mem = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3433|      0|                            libParams[len] = '\0';
 3434|      0|                        }
 3435|      0|                    }
 3436|       |
 3437|      0|                    PR_Close(file_dc);
 3438|      0|                }
 3439|      0|            }
 3440|      0|        }
 3441|       |
 3442|      0|        if (libParams == NULL)
  ------------------
  |  Branch (3442:13): [True: 0, False: 0]
  ------------------
 3443|      0|            libParams = LIB_PARAM_DEFAULT;
  ------------------
  |  |   68|      0|#define LIB_PARAM_DEFAULT " configdir='' certPrefix='' keyPrefix='' secmod='' flags=noCertDB,noModDB "
  ------------------
 3444|       |
 3445|      1|    } else {
 3446|       |        /* Use parameters provided with C_Initialize_args */
 3447|      1|        libParams = (char *)init_args->LibraryParameters;
 3448|      1|    }
 3449|       |
 3450|      1|    crv = sftk_parseParameters(libParams, paramStrings, isFIPS);
 3451|      1|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3451:9): [True: 0, False: 1]
  ------------------
 3452|      0|        crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 3453|      0|        goto loser;
 3454|      0|    }
 3455|       |
 3456|      1|    crv = CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3457|      1|loser:
 3458|      1|    if (free_mem)
  ------------------
  |  Branch (3458:9): [True: 0, False: 1]
  ------------------
 3459|      0|        PORT_Free(libParams);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3460|       |
 3461|      1|    return crv;
 3462|      1|}
pkcs11.c:sftk_configure:
  742|      1|{
  743|       |
  744|       |    /* make sure the internationalization was done correctly... */
  745|      1|    if (man) {
  ------------------
  |  Branch (745:9): [True: 0, False: 1]
  ------------------
  746|      0|        manufacturerID = sftk_setStringName(man, manufacturerID_space,
  747|      0|                                            sizeof(manufacturerID_space), PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  748|      0|    }
  749|      1|    if (libdes) {
  ------------------
  |  Branch (749:9): [True: 0, False: 1]
  ------------------
  750|      0|        libraryDescription = sftk_setStringName(libdes,
  751|      0|                                                libraryDescription_space, sizeof(libraryDescription_space),
  752|      0|                                                PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  753|      0|    }
  754|       |
  755|      1|    return CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  756|      1|}
pkcs11.c:nscFreeAllSlots:
 3331|      1|{
 3332|       |    /* free all the slots */
 3333|      1|    SFTKSlot *slot = NULL;
 3334|      1|    CK_SLOT_ID slotID;
 3335|      1|    int i;
 3336|       |
 3337|      1|    if (nscSlotList[moduleIndex]) {
  ------------------
  |  Branch (3337:9): [True: 1, False: 0]
  ------------------
 3338|      1|        CK_ULONG tmpSlotCount = nscSlotCount[moduleIndex];
 3339|      1|        CK_SLOT_ID_PTR tmpSlotList = nscSlotList[moduleIndex];
 3340|      1|        PLHashTable *tmpSlotHashTable = nscSlotHashTable[moduleIndex];
 3341|       |
 3342|       |        /* first close all the session */
 3343|      3|        for (i = 0; i < (int)tmpSlotCount; i++) {
  ------------------
  |  Branch (3343:21): [True: 2, False: 1]
  ------------------
 3344|      2|            slotID = tmpSlotList[i];
 3345|      2|            (void)NSC_CloseAllSessions(slotID);
 3346|      2|        }
 3347|       |
 3348|       |        /* now clear out the statics */
 3349|      1|        nscSlotList[moduleIndex] = NULL;
 3350|      1|        nscSlotCount[moduleIndex] = 0;
 3351|      1|        nscSlotHashTable[moduleIndex] = NULL;
 3352|      1|        nscSlotListSize[moduleIndex] = 0;
 3353|       |
 3354|      3|        for (i = 0; i < (int)tmpSlotCount; i++) {
  ------------------
  |  Branch (3354:21): [True: 2, False: 1]
  ------------------
 3355|      2|            slotID = tmpSlotList[i];
 3356|      2|            slot = (SFTKSlot *)
 3357|      2|                PL_HashTableLookup(tmpSlotHashTable, (void *)(uintptr_t)slotID);
 3358|      2|            PORT_Assert(slot);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3359|      2|            if (!slot)
  ------------------
  |  Branch (3359:17): [True: 0, False: 2]
  ------------------
 3360|      0|                continue;
 3361|      2|            SFTK_DestroySlotData(slot);
 3362|      2|            PL_HashTableRemove(tmpSlotHashTable, (void *)(uintptr_t)slotID);
 3363|      2|        }
 3364|      1|        PORT_Free(tmpSlotList);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
 3365|      1|        PL_HashTableDestroy(tmpSlotHashTable);
 3366|      1|    }
 3367|      1|}
pkcs11.c:sftk_searchDatabase:
 5216|  23.4k|{
 5217|  23.4k|    CK_RV crv;
 5218|  23.4k|    int objectListSize = search->array_size - search->size;
 5219|  23.4k|    CK_OBJECT_HANDLE *array = &search->handles[search->size];
 5220|  23.4k|    SDBFind *find;
 5221|  23.4k|    CK_ULONG count;
 5222|       |
 5223|  23.4k|    crv = sftkdb_FindObjectsInit(handle, pTemplate, ulCount, &find);
 5224|  23.4k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5224:9): [True: 0, False: 23.4k]
  ------------------
 5225|      0|        return crv;
 5226|  23.4k|    do {
 5227|  23.4k|        crv = sftkdb_FindObjects(handle, find, array, objectListSize, &count);
 5228|  23.4k|        if ((crv != CKR_OK) || (count == 0))
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5228:13): [True: 0, False: 23.4k]
  |  Branch (5228:32): [True: 23.4k, False: 0]
  ------------------
 5229|  23.4k|            break;
 5230|      0|        search->size += count;
 5231|      0|        objectListSize -= count;
 5232|      0|        if (objectListSize > 0)
  ------------------
  |  Branch (5232:13): [True: 0, False: 0]
  ------------------
 5233|      0|            break;
 5234|      0|        crv = sftk_expandSearchList(search, NSC_SEARCH_BLOCK_SIZE);
  ------------------
  |  |   49|      0|#define NSC_SEARCH_BLOCK_SIZE 5
  ------------------
 5235|      0|        objectListSize = NSC_SEARCH_BLOCK_SIZE;
  ------------------
  |  |   49|      0|#define NSC_SEARCH_BLOCK_SIZE 5
  ------------------
 5236|      0|        array = &search->handles[search->size];
 5237|      0|    } while (crv == CKR_OK);
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5237:14): [True: 0, False: 0]
  ------------------
 5238|      0|    sftkdb_FindObjectsFinal(handle, find);
 5239|       |
 5240|  23.4k|    return crv;
 5241|  23.4k|}
pkcs11.c:sftk_searchTokenList:
 5362|  23.4k|{
 5363|  23.4k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 5364|  23.4k|    CK_RV crv2;
 5365|  23.4k|    PRBool searchCertDB;
 5366|  23.4k|    PRBool searchKeyDB;
 5367|       |
 5368|  23.4k|    sftk_pruneSearch(pTemplate, ulCount, &searchCertDB, &searchKeyDB);
 5369|       |
 5370|  23.4k|    if (searchCertDB) {
  ------------------
  |  Branch (5370:9): [True: 23.4k, False: 0]
  ------------------
 5371|  23.4k|        SFTKDBHandle *certHandle = sftk_getCertDB(slot);
 5372|  23.4k|        crv = sftk_searchDatabase(certHandle, search, pTemplate, ulCount);
 5373|  23.4k|        crv2 = sftk_emailhack(slot, certHandle, search, pTemplate, ulCount);
 5374|  23.4k|        if (crv == CKR_OK)
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5374:13): [True: 23.4k, False: 0]
  ------------------
 5375|  23.4k|            crv = crv2;
 5376|  23.4k|        sftk_freeDB(certHandle);
 5377|  23.4k|    }
 5378|       |
 5379|  23.4k|    if (crv == CKR_OK && isLoggedIn && searchKeyDB) {
  ------------------
  |  | 1388|  46.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5379:9): [True: 23.4k, False: 0]
  |  Branch (5379:26): [True: 23.4k, False: 0]
  |  Branch (5379:40): [True: 0, False: 23.4k]
  ------------------
 5380|      0|        SFTKDBHandle *keyHandle = sftk_getKeyDB(slot);
 5381|      0|        crv = sftk_searchDatabase(keyHandle, search, pTemplate, ulCount);
 5382|      0|        sftk_freeDB(keyHandle);
 5383|      0|    }
 5384|  23.4k|    return crv;
 5385|  23.4k|}
pkcs11.c:sftk_pruneSearch:
 5340|  23.4k|{
 5341|  23.4k|    CK_ULONG i;
 5342|       |
 5343|  23.4k|    *searchCertDB = PR_TRUE;
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  ------------------
 5344|  23.4k|    *searchKeyDB = PR_TRUE;
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  ------------------
 5345|  46.9k|    for (i = 0; i < ulCount; i++) {
  ------------------
  |  Branch (5345:17): [True: 46.9k, False: 0]
  ------------------
 5346|  46.9k|        if (pTemplate[i].type == CKA_CLASS && pTemplate[i].pValue != NULL) {
  ------------------
  |  |  511|  93.8k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (5346:13): [True: 23.4k, False: 23.4k]
  |  Branch (5346:47): [True: 23.4k, False: 0]
  ------------------
 5347|  23.4k|            CK_OBJECT_CLASS class = *((CK_OBJECT_CLASS *)pTemplate[i].pValue);
 5348|  23.4k|            if (class == CKO_PRIVATE_KEY || class == CKO_SECRET_KEY) {
  ------------------
  |  |  328|  46.9k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
                          if (class == CKO_PRIVATE_KEY || class == CKO_SECRET_KEY) {
  ------------------
  |  |  329|  23.4k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  |  Branch (5348:17): [True: 0, False: 23.4k]
  |  Branch (5348:45): [True: 0, False: 23.4k]
  ------------------
 5349|      0|                *searchCertDB = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5350|  23.4k|            } else {
 5351|  23.4k|                *searchKeyDB = PR_FALSE;
  ------------------
  |  |  438|  23.4k|#define PR_FALSE 0
  ------------------
 5352|  23.4k|            }
 5353|  23.4k|            break;
 5354|  23.4k|        }
 5355|  46.9k|    }
 5356|  23.4k|}

NSC_DestroyObject:
  272|  1.28M|{
  273|  1.28M|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
  274|  1.28M|    SFTKSession *session;
  275|  1.28M|    SFTKObject *object;
  276|  1.28M|    SFTKFreeStatus status;
  277|       |
  278|  1.28M|    CHECK_FORK();
  279|       |
  280|  1.28M|    if (slot == NULL) {
  ------------------
  |  Branch (280:9): [True: 0, False: 1.28M]
  ------------------
  281|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  282|      0|    }
  283|       |    /*
  284|       |     * This whole block just makes sure we really can destroy the
  285|       |     * requested object.
  286|       |     */
  287|  1.28M|    session = sftk_SessionFromHandle(hSession);
  288|  1.28M|    if (session == NULL) {
  ------------------
  |  Branch (288:9): [True: 0, False: 1.28M]
  ------------------
  289|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  290|      0|    }
  291|       |
  292|  1.28M|    object = sftk_ObjectFromHandle(hObject, session);
  293|  1.28M|    if (object == NULL) {
  ------------------
  |  Branch (293:9): [True: 0, False: 1.28M]
  ------------------
  294|      0|        sftk_FreeSession(session);
  295|      0|        return CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  296|      0|    }
  297|       |
  298|       |    /* don't destroy a private object if we aren't logged in */
  299|  1.28M|    if ((!slot->isLoggedIn) && (slot->needLogin) &&
  ------------------
  |  Branch (299:9): [True: 1.28M, False: 0]
  |  Branch (299:32): [True: 0, False: 1.28M]
  ------------------
  300|  1.28M|        (sftk_isTrue(object, CKA_PRIVATE))) {
  ------------------
  |  |  513|      0|#define CKA_PRIVATE 0x00000002UL
  ------------------
  |  Branch (300:9): [True: 0, False: 0]
  ------------------
  301|      0|        sftk_FreeSession(session);
  302|      0|        sftk_FreeObject(object);
  303|      0|        return CKR_USER_NOT_LOGGED_IN;
  ------------------
  |  | 1486|      0|#define CKR_USER_NOT_LOGGED_IN 0x00000101UL
  ------------------
  304|      0|    }
  305|       |
  306|       |    /* don't destroy a token object if we aren't in a rw session */
  307|       |
  308|  1.28M|    if (((session->info.flags & CKF_RW_SESSION) == 0) &&
  ------------------
  |  |  302|  1.28M|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (308:9): [True: 1.28M, False: 0]
  ------------------
  309|  1.28M|        (sftk_isTrue(object, CKA_TOKEN))) {
  ------------------
  |  |  512|  1.28M|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (309:9): [True: 0, False: 1.28M]
  ------------------
  310|      0|        sftk_FreeSession(session);
  311|      0|        sftk_FreeObject(object);
  312|      0|        return CKR_SESSION_READ_ONLY;
  ------------------
  |  | 1467|      0|#define CKR_SESSION_READ_ONLY 0x000000B5UL
  ------------------
  313|      0|    }
  314|       |
  315|  1.28M|    sftk_DeleteObject(session, object);
  316|       |
  317|  1.28M|    sftk_FreeSession(session);
  318|       |
  319|       |    /*
  320|       |     * get some indication if the object is destroyed. Note: this is not
  321|       |     * 100%. Someone may have an object reference outstanding (though that
  322|       |     * should not be the case by here. Also note that the object is "half"
  323|       |     * destroyed. Our internal representation is destroyed, but it may still
  324|       |     * be in the data base.
  325|       |     */
  326|  1.28M|    status = sftk_FreeObject(object);
  327|       |
  328|  1.28M|    return (status != SFTK_DestroyFailure) ? CKR_OK : CKR_DEVICE_ERROR;
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
                  return (status != SFTK_DestroyFailure) ? CKR_OK : CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  |  Branch (328:12): [True: 1.28M, False: 0]
  ------------------
  329|  1.28M|}
sftk_ReturnContextByType:
  376|  2.18M|{
  377|  2.18M|    switch (type) {
  ------------------
  |  Branch (377:13): [True: 0, False: 2.18M]
  ------------------
  378|   124k|        case SFTK_ENCRYPT:
  ------------------
  |  Branch (378:9): [True: 124k, False: 2.05M]
  ------------------
  379|   194k|        case SFTK_DECRYPT:
  ------------------
  |  Branch (379:9): [True: 69.3k, False: 2.11M]
  ------------------
  380|   355k|        case SFTK_MESSAGE_ENCRYPT:
  ------------------
  |  Branch (380:9): [True: 161k, False: 2.02M]
  ------------------
  381|   525k|        case SFTK_MESSAGE_DECRYPT:
  ------------------
  |  Branch (381:9): [True: 169k, False: 2.01M]
  ------------------
  382|   525k|            return session->enc_context;
  383|  1.17M|        case SFTK_HASH:
  ------------------
  |  Branch (383:9): [True: 1.17M, False: 1.00M]
  ------------------
  384|  1.17M|            return session->hash_context;
  385|   473k|        case SFTK_SIGN:
  ------------------
  |  Branch (385:9): [True: 473k, False: 1.70M]
  ------------------
  386|   473k|        case SFTK_SIGN_RECOVER:
  ------------------
  |  Branch (386:9): [True: 0, False: 2.18M]
  ------------------
  387|   473k|        case SFTK_VERIFY:
  ------------------
  |  Branch (387:9): [True: 120, False: 2.18M]
  ------------------
  388|   479k|        case SFTK_VERIFY_RECOVER:
  ------------------
  |  Branch (388:9): [True: 5.90k, False: 2.17M]
  ------------------
  389|   479k|        case SFTK_MESSAGE_SIGN:
  ------------------
  |  Branch (389:9): [True: 0, False: 2.18M]
  ------------------
  390|   479k|        case SFTK_MESSAGE_VERIFY:
  ------------------
  |  Branch (390:9): [True: 0, False: 2.18M]
  ------------------
  391|   479k|            return session->hash_context;
  392|  2.18M|    }
  393|      0|    return NULL;
  394|  2.18M|}
sftk_SetContextByType:
  402|  1.40M|{
  403|  1.40M|    switch (type) {
  ------------------
  |  Branch (403:13): [True: 0, False: 1.40M]
  ------------------
  404|  90.9k|        case SFTK_ENCRYPT:
  ------------------
  |  Branch (404:9): [True: 90.9k, False: 1.31M]
  ------------------
  405|   160k|        case SFTK_DECRYPT:
  ------------------
  |  Branch (405:9): [True: 69.3k, False: 1.33M]
  ------------------
  406|   321k|        case SFTK_MESSAGE_ENCRYPT:
  ------------------
  |  Branch (406:9): [True: 161k, False: 1.24M]
  ------------------
  407|   491k|        case SFTK_MESSAGE_DECRYPT:
  ------------------
  |  Branch (407:9): [True: 169k, False: 1.23M]
  ------------------
  408|   491k|            session->enc_context = context;
  409|   491k|            break;
  410|   542k|        case SFTK_HASH:
  ------------------
  |  Branch (410:9): [True: 542k, False: 864k]
  ------------------
  411|   542k|            session->hash_context = context;
  412|   542k|            break;
  413|   366k|        case SFTK_SIGN:
  ------------------
  |  Branch (413:9): [True: 366k, False: 1.04M]
  ------------------
  414|   366k|        case SFTK_SIGN_RECOVER:
  ------------------
  |  Branch (414:9): [True: 0, False: 1.40M]
  ------------------
  415|   367k|        case SFTK_VERIFY:
  ------------------
  |  Branch (415:9): [True: 120, False: 1.40M]
  ------------------
  416|   372k|        case SFTK_VERIFY_RECOVER:
  ------------------
  |  Branch (416:9): [True: 5.90k, False: 1.40M]
  ------------------
  417|   372k|        case SFTK_MESSAGE_SIGN:
  ------------------
  |  Branch (417:9): [True: 0, False: 1.40M]
  ------------------
  418|   372k|        case SFTK_MESSAGE_VERIFY:
  ------------------
  |  Branch (418:9): [True: 0, False: 1.40M]
  ------------------
  419|   372k|            session->hash_context = context;
  420|   372k|            break;
  421|  1.40M|    }
  422|  1.40M|    return;
  423|  1.40M|}
sftk_GetContext:
  435|  1.23M|{
  436|  1.23M|    SFTKSession *session;
  437|  1.23M|    SFTKSessionContext *context;
  438|       |
  439|  1.23M|    session = sftk_SessionFromHandle(handle);
  440|  1.23M|    if (session == NULL)
  ------------------
  |  Branch (440:9): [True: 0, False: 1.23M]
  ------------------
  441|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  442|  1.23M|    context = sftk_ReturnContextByType(session, type);
  443|       |    /* make sure the context is valid */
  444|  1.23M|    if ((context == NULL) || (context->type != type) || (needMulti && !(context->multi))) {
  ------------------
  |  Branch (444:9): [True: 25.5k, False: 1.20M]
  |  Branch (444:30): [True: 0, False: 1.20M]
  |  Branch (444:58): [True: 1.06M, False: 141k]
  |  Branch (444:71): [True: 0, False: 1.06M]
  ------------------
  445|  25.5k|        sftk_FreeSession(session);
  446|  25.5k|        return CKR_OPERATION_NOT_INITIALIZED;
  ------------------
  |  | 1454|  25.5k|#define CKR_OPERATION_NOT_INITIALIZED 0x00000091UL
  ------------------
  447|  25.5k|    }
  448|  1.20M|    *contextPtr = context;
  449|  1.20M|    if (sessionPtr != NULL) {
  ------------------
  |  Branch (449:9): [True: 607k, False: 598k]
  ------------------
  450|   607k|        *sessionPtr = session;
  451|   607k|    } else {
  452|   598k|        sftk_FreeSession(session);
  453|   598k|    }
  454|  1.20M|    return CKR_OK;
  ------------------
  |  | 1388|  1.20M|#define CKR_OK 0x00000000UL
  ------------------
  455|  1.23M|}
sftk_TerminateOp:
  463|   456k|{
  464|   456k|    session->lastOpWasFIPS = context->isFIPS;
  465|   456k|    sftk_FreeContext(context);
  466|   456k|    sftk_SetContextByType(session, ctype, NULL);
  467|   456k|}
sftk_InitGeneric:
  483|   916k|{
  484|   916k|    SFTKObject *key = NULL;
  485|   916k|    SFTKAttribute *att;
  486|   916k|    SFTKSessionContext *context;
  487|       |
  488|       |    /* We can only init if there is not current context active */
  489|   916k|    if (sftk_ReturnContextByType(session, ctype) != NULL) {
  ------------------
  |  Branch (489:9): [True: 0, False: 916k]
  ------------------
  490|      0|        return CKR_OPERATION_ACTIVE;
  ------------------
  |  | 1453|      0|#define CKR_OPERATION_ACTIVE 0x00000090UL
  ------------------
  491|      0|    }
  492|       |
  493|       |    /* find the key */
  494|   916k|    if (keyPtr) {
  ------------------
  |  Branch (494:9): [True: 650k, False: 265k]
  ------------------
  495|   650k|        key = sftk_ObjectFromHandle(hKey, session);
  496|   650k|        if (key == NULL) {
  ------------------
  |  Branch (496:13): [True: 0, False: 650k]
  ------------------
  497|      0|            return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  498|      0|        }
  499|       |
  500|       |        /* make sure it's a valid  key for this operation */
  501|   650k|        if (((key->objclass != CKO_SECRET_KEY) &&
  ------------------
  |  |  329|   650k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  |  Branch (501:14): [True: 73.4k, False: 577k]
  ------------------
  502|   650k|             (key->objclass != pubKeyType)) ||
  ------------------
  |  Branch (502:14): [True: 0, False: 73.4k]
  ------------------
  503|   650k|            !sftk_isTrue(key, operation)) {
  ------------------
  |  Branch (503:13): [True: 0, False: 650k]
  ------------------
  504|      0|            sftk_FreeObject(key);
  505|      0|            return CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
  506|      0|        }
  507|       |        /* get the key type */
  508|   650k|        att = sftk_FindAttribute(key, CKA_KEY_TYPE);
  ------------------
  |  |  543|   650k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  509|   650k|        if (att == NULL) {
  ------------------
  |  Branch (509:13): [True: 0, False: 650k]
  ------------------
  510|      0|            sftk_FreeObject(key);
  511|      0|            return CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
  512|      0|        }
  513|   650k|        PORT_Assert(att->attrib.ulValueLen == sizeof(CK_KEY_TYPE));
  ------------------
  |  |  120|   650k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   650k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 650k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  514|   650k|        if (att->attrib.ulValueLen != sizeof(CK_KEY_TYPE)) {
  ------------------
  |  Branch (514:13): [True: 0, False: 650k]
  ------------------
  515|      0|            sftk_FreeAttribute(att);
  516|      0|            sftk_FreeObject(key);
  517|      0|            return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  518|      0|        }
  519|   650k|        PORT_Memcpy(keyTypePtr, att->attrib.pValue, sizeof(CK_KEY_TYPE));
  ------------------
  |  |  180|   650k|#define PORT_Memcpy memcpy
  ------------------
  520|   650k|        sftk_FreeAttribute(att);
  521|   650k|        *keyPtr = key;
  522|   650k|    }
  523|       |
  524|       |    /* allocate the context structure */
  525|   916k|    context = (SFTKSessionContext *)PORT_Alloc(sizeof(SFTKSessionContext));
  ------------------
  |  |   52|   916k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  526|   916k|    if (context == NULL) {
  ------------------
  |  Branch (526:9): [True: 0, False: 916k]
  ------------------
  527|      0|        if (key)
  ------------------
  |  Branch (527:13): [True: 0, False: 0]
  ------------------
  528|      0|            sftk_FreeObject(key);
  529|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  530|      0|    }
  531|   916k|    context->type = ctype;
  532|   916k|    context->multi = PR_TRUE;
  ------------------
  |  |  437|   916k|#define PR_TRUE 1
  ------------------
  533|   916k|    context->rsa = PR_FALSE;
  ------------------
  |  |  438|   916k|#define PR_FALSE 0
  ------------------
  534|   916k|    context->cipherInfo = NULL;
  535|   916k|    context->hashInfo = NULL;
  536|   916k|    context->doPad = PR_FALSE;
  ------------------
  |  |  438|   916k|#define PR_FALSE 0
  ------------------
  537|   916k|    context->padDataLength = 0;
  538|   916k|    context->key = key;
  539|   916k|    context->blockSize = 0;
  540|   916k|    context->maxLen = 0;
  541|   916k|    context->isFIPS = sftk_operationIsFIPS(session->slot, pMechanism,
  542|   916k|                                           operation, key);
  543|   916k|    *contextPtr = context;
  544|   916k|    return CKR_OK;
  ------------------
  |  | 1388|   916k|#define CKR_OK 0x00000000UL
  ------------------
  545|   916k|}
sftk_CryptInit:
  859|   103k|{
  860|   103k|    SFTKSession *session;
  861|   103k|    SFTKObject *key;
  862|   103k|    SFTKSessionContext *context;
  863|   103k|    SFTKAttribute *att;
  864|   103k|#ifndef NSS_DISABLE_DEPRECATED_RC2
  865|   103k|    CK_RC2_CBC_PARAMS *rc2_param;
  866|   103k|    unsigned effectiveKeyLength;
  867|   103k|#endif
  868|       |#if NSS_SOFTOKEN_DOES_RC5
  869|       |    CK_RC5_CBC_PARAMS *rc5_param;
  870|       |    SECItem rc5Key;
  871|       |#endif
  872|   103k|    CK_NSS_GCM_PARAMS nss_gcm_param;
  873|   103k|    void *aes_param;
  874|   103k|    CK_NSS_AEAD_PARAMS nss_aead_params;
  875|   103k|    CK_NSS_AEAD_PARAMS *nss_aead_params_ptr = NULL;
  876|   103k|    CK_KEY_TYPE key_type;
  877|   103k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   103k|#define CKR_OK 0x00000000UL
  ------------------
  878|   103k|    unsigned char newdeskey[24];
  879|   103k|    PRBool useNewKey = PR_FALSE;
  ------------------
  |  |  438|   103k|#define PR_FALSE 0
  ------------------
  880|   103k|    int t;
  881|       |
  882|   103k|    if (!pMechanism) {
  ------------------
  |  Branch (882:9): [True: 0, False: 103k]
  ------------------
  883|      0|        return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
  884|      0|    }
  885|       |
  886|   103k|    crv = sftk_MechAllowsOperation(pMechanism->mechanism, mechUsage);
  887|   103k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   103k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (887:9): [True: 0, False: 103k]
  ------------------
  888|      0|        return crv;
  889|       |
  890|   103k|    session = sftk_SessionFromHandle(hSession);
  891|   103k|    if (session == NULL)
  ------------------
  |  Branch (891:9): [True: 0, False: 103k]
  ------------------
  892|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  893|       |
  894|   103k|    crv = sftk_InitGeneric(session, pMechanism, &context, contextType, &key,
  895|   103k|                           hKey, &key_type,
  896|   103k|                           isEncrypt ? CKO_PUBLIC_KEY : CKO_PRIVATE_KEY,
  ------------------
  |  |  327|  57.0k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
                                         isEncrypt ? CKO_PUBLIC_KEY : CKO_PRIVATE_KEY,
  ------------------
  |  |  328|  46.1k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (896:28): [True: 57.0k, False: 46.1k]
  ------------------
  897|   103k|                           keyUsage);
  898|       |
  899|   103k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   103k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (899:9): [True: 0, False: 103k]
  ------------------
  900|      0|        sftk_FreeSession(session);
  901|      0|        return crv;
  902|      0|    }
  903|       |
  904|   103k|    context->doPad = PR_FALSE;
  ------------------
  |  |  438|   103k|#define PR_FALSE 0
  ------------------
  905|   103k|    switch (pMechanism->mechanism) {
  906|  23.1k|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|  23.1k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (906:9): [True: 23.1k, False: 80.0k]
  ------------------
  907|  23.1k|        case CKM_RSA_X_509:
  ------------------
  |  |  722|  23.1k|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (907:9): [True: 0, False: 103k]
  ------------------
  908|  23.1k|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|  23.1k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (908:17): [True: 0, False: 23.1k]
  ------------------
  909|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
  910|      0|                break;
  911|      0|            }
  912|  23.1k|            context->multi = PR_FALSE;
  ------------------
  |  |  438|  23.1k|#define PR_FALSE 0
  ------------------
  913|  23.1k|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|  23.1k|#define PR_TRUE 1
  ------------------
  914|  23.1k|            if (isEncrypt) {
  ------------------
  |  Branch (914:17): [True: 3, False: 23.1k]
  ------------------
  915|      3|                NSSLOWKEYPublicKey *pubKey = sftk_GetPubKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|      3|#define CKK_RSA 0x00000000UL
  ------------------
  916|      3|                if (pubKey == NULL) {
  ------------------
  |  Branch (916:21): [True: 0, False: 3]
  ------------------
  917|      0|                    crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  918|      0|                    break;
  919|      0|                }
  920|      3|                context->maxLen = nsslowkey_PublicModulusLen(pubKey);
  921|      3|                context->cipherInfo = (void *)pubKey;
  922|      3|                context->update = pMechanism->mechanism == CKM_RSA_X_509
  ------------------
  |  |  722|      3|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (922:35): [True: 0, False: 3]
  ------------------
  923|      3|                                      ? sftk_RSAEncryptRaw
  924|      3|                                      : sftk_RSAEncrypt;
  925|  23.1k|            } else {
  926|  23.1k|                NSSLOWKEYPrivateKey *privKey = sftk_GetPrivKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|  23.1k|#define CKK_RSA 0x00000000UL
  ------------------
  927|  23.1k|                if (privKey == NULL) {
  ------------------
  |  Branch (927:21): [True: 0, False: 23.1k]
  ------------------
  928|      0|                    crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  929|      0|                    break;
  930|      0|                }
  931|  23.1k|                context->maxLen = nsslowkey_PrivateModulusLen(privKey);
  932|  23.1k|                context->cipherInfo = (void *)privKey;
  933|  23.1k|                context->update = pMechanism->mechanism == CKM_RSA_X_509
  ------------------
  |  |  722|  23.1k|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (933:35): [True: 0, False: 23.1k]
  ------------------
  934|  23.1k|                                      ? sftk_RSADecryptRaw
  935|  23.1k|                                      : sftk_RSADecrypt;
  936|  23.1k|            }
  937|  23.1k|            context->destroy = sftk_Null;
  938|  23.1k|            break;
  939|      0|        case CKM_RSA_PKCS_OAEP:
  ------------------
  |  |  734|      0|#define CKM_RSA_PKCS_OAEP 0x00000009UL
  ------------------
  |  Branch (939:9): [True: 0, False: 103k]
  ------------------
  940|      0|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (940:17): [True: 0, False: 0]
  ------------------
  941|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
  942|      0|                break;
  943|      0|            }
  944|      0|            if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_OAEP_PARAMS) ||
  ------------------
  |  Branch (944:17): [True: 0, False: 0]
  ------------------
  945|      0|                !sftk_ValidateOaepParams((CK_RSA_PKCS_OAEP_PARAMS *)pMechanism->pParameter)) {
  ------------------
  |  Branch (945:17): [True: 0, False: 0]
  ------------------
  946|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
  947|      0|                break;
  948|      0|            }
  949|      0|            context->multi = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  950|      0|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  951|      0|            {
  952|      0|                SFTKOAEPInfo *info;
  953|      0|                CK_RSA_PKCS_OAEP_PARAMS *params =
  954|      0|                    (CK_RSA_PKCS_OAEP_PARAMS *)pMechanism->pParameter;
  955|       |                /* make a copy of the source data value for future
  956|       |                 * use (once the user has reclaimed his data in pParameter)*/
  957|      0|                void *newSource = NULL;
  958|      0|                if (params->pSourceData) {
  ------------------
  |  Branch (958:21): [True: 0, False: 0]
  ------------------
  959|      0|                    newSource = PORT_Alloc(params->ulSourceDataLen);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  960|      0|                    if (newSource == NULL) {
  ------------------
  |  Branch (960:25): [True: 0, False: 0]
  ------------------
  961|      0|                        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  962|      0|                        break;
  963|      0|                    }
  964|      0|                    PORT_Memcpy(newSource, params->pSourceData, params->ulSourceDataLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  965|      0|                }
  966|      0|                info = PORT_New(SFTKOAEPInfo);
  ------------------
  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  967|      0|                if (info == NULL) {
  ------------------
  |  Branch (967:21): [True: 0, False: 0]
  ------------------
  968|      0|                    PORT_ZFree(newSource, params->ulSourceDataLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  969|      0|                    crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  970|      0|                    break;
  971|      0|                }
  972|      0|                info->params = *params;
  973|      0|                info->params.pSourceData = newSource;
  974|      0|                info->isEncrypt = isEncrypt;
  975|       |
  976|       |                /* now setup encryption and decryption contexts */
  977|      0|                if (isEncrypt) {
  ------------------
  |  Branch (977:21): [True: 0, False: 0]
  ------------------
  978|      0|                    info->key.pub = sftk_GetPubKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  979|      0|                    if (info->key.pub == NULL) {
  ------------------
  |  Branch (979:25): [True: 0, False: 0]
  ------------------
  980|      0|                        sftk_freeRSAOAEPInfo(info, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  981|      0|                        crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  982|      0|                        break;
  983|      0|                    }
  984|      0|                    context->update = sftk_RSAEncryptOAEP;
  985|      0|                    context->maxLen = nsslowkey_PublicModulusLen(info->key.pub);
  986|      0|                } else {
  987|      0|                    info->key.priv = sftk_GetPrivKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  988|      0|                    if (info->key.priv == NULL) {
  ------------------
  |  Branch (988:25): [True: 0, False: 0]
  ------------------
  989|      0|                        sftk_freeRSAOAEPInfo(info, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  990|      0|                        crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  991|      0|                        break;
  992|      0|                    }
  993|      0|                    context->update = sftk_RSADecryptOAEP;
  994|      0|                    context->maxLen = nsslowkey_PrivateModulusLen(info->key.priv);
  995|      0|                }
  996|      0|                context->cipherInfo = info;
  997|      0|            }
  998|      0|            context->destroy = sftk_freeRSAOAEPInfo;
  999|      0|            break;
 1000|      0|#ifndef NSS_DISABLE_DEPRECATED_RC2
 1001|      0|        case CKM_RC2_CBC_PAD:
  ------------------
  |  |  810|      0|#define CKM_RC2_CBC_PAD 0x00000105UL
  ------------------
  |  Branch (1001:9): [True: 0, False: 103k]
  ------------------
 1002|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1003|       |        /* fall thru */
 1004|      0|        case CKM_RC2_ECB:
  ------------------
  |  |  804|      0|#define CKM_RC2_ECB 0x00000101UL
  ------------------
  |  Branch (1004:9): [True: 0, False: 103k]
  ------------------
 1005|      0|        case CKM_RC2_CBC:
  ------------------
  |  |  805|      0|#define CKM_RC2_CBC 0x00000102UL
  ------------------
  |  Branch (1005:9): [True: 0, False: 103k]
  ------------------
 1006|      0|            context->blockSize = 8;
 1007|      0|            if (key_type != CKK_RC2) {
  ------------------
  |  |  384|      0|#define CKK_RC2 0x00000011UL
  ------------------
  |  Branch (1007:17): [True: 0, False: 0]
  ------------------
 1008|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1009|      0|                break;
 1010|      0|            }
 1011|      0|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 1012|      0|            if (att == NULL) {
  ------------------
  |  Branch (1012:17): [True: 0, False: 0]
  ------------------
 1013|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1014|      0|                break;
 1015|      0|            }
 1016|       |
 1017|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_RC2_CBC_PARAMS))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1018|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1019|      0|                break;
 1020|      0|            }
 1021|      0|            rc2_param = (CK_RC2_CBC_PARAMS *)pMechanism->pParameter;
 1022|      0|            effectiveKeyLength = (rc2_param->ulEffectiveBits + 7) / 8;
 1023|      0|            context->cipherInfo =
 1024|      0|                RC2_CreateContext((unsigned char *)att->attrib.pValue,
 1025|      0|                                  att->attrib.ulValueLen, rc2_param->iv,
 1026|      0|                                  pMechanism->mechanism == CKM_RC2_ECB ? NSS_RC2 : NSS_RC2_CBC, effectiveKeyLength);
  ------------------
  |  |  804|      0|#define CKM_RC2_ECB 0x00000101UL
  ------------------
                                                pMechanism->mechanism == CKM_RC2_ECB ? NSS_RC2 : NSS_RC2_CBC, effectiveKeyLength);
  ------------------
  |  |   17|      0|#define NSS_RC2 0
  ------------------
                                                pMechanism->mechanism == CKM_RC2_ECB ? NSS_RC2 : NSS_RC2_CBC, effectiveKeyLength);
  ------------------
  |  |   18|      0|#define NSS_RC2_CBC 1
  ------------------
  |  Branch (1026:35): [True: 0, False: 0]
  ------------------
 1027|      0|            sftk_FreeAttribute(att);
 1028|      0|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1028:17): [True: 0, False: 0]
  ------------------
 1029|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1030|      0|                break;
 1031|      0|            }
 1032|      0|            context->update = isEncrypt ? SFTKCipher_RC2_Encrypt : SFTKCipher_RC2_Decrypt;
  ------------------
  |  Branch (1032:31): [True: 0, False: 0]
  ------------------
 1033|      0|            context->destroy = SFTKCipher_RC2_DestroyContext;
 1034|      0|            break;
 1035|      0|#endif /* NSS_DISABLE_DEPRECATED_RC2 */
 1036|       |
 1037|       |#if NSS_SOFTOKEN_DOES_RC5
 1038|       |        case CKM_RC5_CBC_PAD:
 1039|       |            context->doPad = PR_TRUE;
 1040|       |        /* fall thru */
 1041|       |        case CKM_RC5_ECB:
 1042|       |        case CKM_RC5_CBC:
 1043|       |            if (key_type != CKK_RC5) {
 1044|       |                crv = CKR_KEY_TYPE_INCONSISTENT;
 1045|       |                break;
 1046|       |            }
 1047|       |            att = sftk_FindAttribute(key, CKA_VALUE);
 1048|       |            if (att == NULL) {
 1049|       |                crv = CKR_KEY_HANDLE_INVALID;
 1050|       |                break;
 1051|       |            }
 1052|       |
 1053|       |            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_RC5_CBC_PARAMS))) {
 1054|       |                crv = CKR_MECHANISM_PARAM_INVALID;
 1055|       |                break;
 1056|       |            }
 1057|       |            rc5_param = (CK_RC5_CBC_PARAMS *)pMechanism->pParameter;
 1058|       |            context->blockSize = rc5_param->ulWordsize * 2;
 1059|       |            rc5Key.data = (unsigned char *)att->attrib.pValue;
 1060|       |            rc5Key.len = att->attrib.ulValueLen;
 1061|       |            context->cipherInfo = RC5_CreateContext(&rc5Key, rc5_param->ulRounds,
 1062|       |                                                    rc5_param->ulWordsize, rc5_param->pIv,
 1063|       |                                                    pMechanism->mechanism == CKM_RC5_ECB ? NSS_RC5 : NSS_RC5_CBC);
 1064|       |            sftk_FreeAttribute(att);
 1065|       |            if (context->cipherInfo == NULL) {
 1066|       |                crv = CKR_HOST_MEMORY;
 1067|       |                break;
 1068|       |            }
 1069|       |            context->update = isEncrypt ? SFTKCipher_RC5_Encrypt : SFTKCipher_RC5_Decrypt;
 1070|       |            context->destroy = SFTKCipher_RC5_DestroyContext;
 1071|       |            break;
 1072|       |#endif
 1073|  1.18k|        case CKM_RC4:
  ------------------
  |  |  813|  1.18k|#define CKM_RC4 0x00000111UL
  ------------------
  |  Branch (1073:9): [True: 1.18k, False: 102k]
  ------------------
 1074|  1.18k|            if (key_type != CKK_RC4) {
  ------------------
  |  |  385|  1.18k|#define CKK_RC4 0x00000012UL
  ------------------
  |  Branch (1074:17): [True: 0, False: 1.18k]
  ------------------
 1075|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1076|      0|                break;
 1077|      0|            }
 1078|  1.18k|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  1.18k|#define CKA_VALUE 0x00000011UL
  ------------------
 1079|  1.18k|            if (att == NULL) {
  ------------------
  |  Branch (1079:17): [True: 0, False: 1.18k]
  ------------------
 1080|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1081|      0|                break;
 1082|      0|            }
 1083|  1.18k|            context->cipherInfo =
 1084|  1.18k|                RC4_CreateContext((unsigned char *)att->attrib.pValue,
 1085|  1.18k|                                  att->attrib.ulValueLen);
 1086|  1.18k|            sftk_FreeAttribute(att);
 1087|  1.18k|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1087:17): [True: 0, False: 1.18k]
  ------------------
 1088|      0|                crv = CKR_HOST_MEMORY; /* WRONG !!! */
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1089|      0|                break;
 1090|      0|            }
 1091|  1.18k|            context->update = isEncrypt ? SFTKCipher_RC4_Encrypt : SFTKCipher_RC4_Decrypt;
  ------------------
  |  Branch (1091:31): [True: 593, False: 593]
  ------------------
 1092|  1.18k|            context->destroy = SFTKCipher_RC4_DestroyContext;
 1093|  1.18k|            break;
 1094|      0|        case CKM_CDMF_CBC_PAD:
  ------------------
  |  |  839|      0|#define CKM_CDMF_CBC_PAD 0x00000145UL
  ------------------
  |  Branch (1094:9): [True: 0, False: 103k]
  ------------------
 1095|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1096|       |        /* fall thru */
 1097|      0|        case CKM_CDMF_ECB:
  ------------------
  |  |  835|      0|#define CKM_CDMF_ECB 0x00000141UL
  ------------------
  |  Branch (1097:9): [True: 0, False: 103k]
  ------------------
 1098|      0|        case CKM_CDMF_CBC:
  ------------------
  |  |  836|      0|#define CKM_CDMF_CBC 0x00000142UL
  ------------------
  |  Branch (1098:9): [True: 0, False: 103k]
  ------------------
 1099|      0|            if (key_type != CKK_CDMF) {
  ------------------
  |  |  401|      0|#define CKK_CDMF 0x0000001EUL
  ------------------
  |  Branch (1099:17): [True: 0, False: 0]
  ------------------
 1100|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1101|      0|                break;
 1102|      0|            }
 1103|      0|            t = (pMechanism->mechanism == CKM_CDMF_ECB) ? NSS_DES : NSS_DES_CBC;
  ------------------
  |  |  835|      0|#define CKM_CDMF_ECB 0x00000141UL
  ------------------
                          t = (pMechanism->mechanism == CKM_CDMF_ECB) ? NSS_DES : NSS_DES_CBC;
  ------------------
  |  |   25|      0|#define NSS_DES 0
  ------------------
                          t = (pMechanism->mechanism == CKM_CDMF_ECB) ? NSS_DES : NSS_DES_CBC;
  ------------------
  |  |   26|      0|#define NSS_DES_CBC 1
  ------------------
  |  Branch (1103:17): [True: 0, False: 0]
  ------------------
 1104|      0|            goto finish_des;
 1105|      0|        case CKM_DES_ECB:
  ------------------
  |  |  815|      0|#define CKM_DES_ECB 0x00000121UL
  ------------------
  |  Branch (1105:9): [True: 0, False: 103k]
  ------------------
 1106|      0|            if (key_type != CKK_DES) {
  ------------------
  |  |  386|      0|#define CKK_DES 0x00000013UL
  ------------------
  |  Branch (1106:17): [True: 0, False: 0]
  ------------------
 1107|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1108|      0|                break;
 1109|      0|            }
 1110|      0|            t = NSS_DES;
  ------------------
  |  |   25|      0|#define NSS_DES 0
  ------------------
 1111|      0|            goto finish_des;
 1112|      0|        case CKM_DES_CBC_PAD:
  ------------------
  |  |  821|      0|#define CKM_DES_CBC_PAD 0x00000125UL
  ------------------
  |  Branch (1112:9): [True: 0, False: 103k]
  ------------------
 1113|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1114|       |        /* fall thru */
 1115|  14.8k|        case CKM_DES_CBC:
  ------------------
  |  |  816|  14.8k|#define CKM_DES_CBC 0x00000122UL
  ------------------
  |  Branch (1115:9): [True: 14.8k, False: 88.3k]
  ------------------
 1116|  14.8k|            if (key_type != CKK_DES) {
  ------------------
  |  |  386|  14.8k|#define CKK_DES 0x00000013UL
  ------------------
  |  Branch (1116:17): [True: 0, False: 14.8k]
  ------------------
 1117|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1118|      0|                break;
 1119|      0|            }
 1120|  14.8k|            t = NSS_DES_CBC;
  ------------------
  |  |   26|  14.8k|#define NSS_DES_CBC 1
  ------------------
 1121|  14.8k|            goto finish_des;
 1122|  33.9k|        case CKM_DES3_ECB:
  ------------------
  |  |  825|  33.9k|#define CKM_DES3_ECB 0x00000132UL
  ------------------
  |  Branch (1122:9): [True: 33.9k, False: 69.2k]
  ------------------
 1123|  33.9k|            if ((key_type != CKK_DES2) && (key_type != CKK_DES3)) {
  ------------------
  |  |  387|  33.9k|#define CKK_DES2 0x00000014UL
  ------------------
                          if ((key_type != CKK_DES2) && (key_type != CKK_DES3)) {
  ------------------
  |  |  388|  33.9k|#define CKK_DES3 0x00000015UL
  ------------------
  |  Branch (1123:17): [True: 33.9k, False: 0]
  |  Branch (1123:43): [True: 0, False: 33.9k]
  ------------------
 1124|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1125|      0|                break;
 1126|      0|            }
 1127|  33.9k|            t = NSS_DES_EDE3;
  ------------------
  |  |   27|  33.9k|#define NSS_DES_EDE3 2
  ------------------
 1128|  33.9k|            goto finish_des;
 1129|      0|        case CKM_DES3_CBC_PAD:
  ------------------
  |  |  833|      0|#define CKM_DES3_CBC_PAD 0x00000136UL
  ------------------
  |  Branch (1129:9): [True: 0, False: 103k]
  ------------------
 1130|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1131|       |        /* fall thru */
 1132|  10.1k|        case CKM_DES3_CBC:
  ------------------
  |  |  826|  10.1k|#define CKM_DES3_CBC 0x00000133UL
  ------------------
  |  Branch (1132:9): [True: 10.1k, False: 93.0k]
  ------------------
 1133|  10.1k|            if ((key_type != CKK_DES2) && (key_type != CKK_DES3)) {
  ------------------
  |  |  387|  10.1k|#define CKK_DES2 0x00000014UL
  ------------------
                          if ((key_type != CKK_DES2) && (key_type != CKK_DES3)) {
  ------------------
  |  |  388|  10.1k|#define CKK_DES3 0x00000015UL
  ------------------
  |  Branch (1133:17): [True: 10.1k, False: 0]
  |  Branch (1133:43): [True: 0, False: 10.1k]
  ------------------
 1134|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1135|      0|                break;
 1136|      0|            }
 1137|  10.1k|            t = NSS_DES_EDE3_CBC;
  ------------------
  |  |   28|  10.1k|#define NSS_DES_EDE3_CBC 3
  ------------------
 1138|  58.9k|        finish_des:
 1139|  58.9k|            if ((t != NSS_DES && t != NSS_DES_EDE3) && (pMechanism->pParameter == NULL ||
  ------------------
  |  |   25|   117k|#define NSS_DES 0
  ------------------
                          if ((t != NSS_DES && t != NSS_DES_EDE3) && (pMechanism->pParameter == NULL ||
  ------------------
  |  |   27|  58.9k|#define NSS_DES_EDE3 2
  ------------------
  |  Branch (1139:18): [True: 58.9k, False: 0]
  |  Branch (1139:34): [True: 24.9k, False: 33.9k]
  |  Branch (1139:57): [True: 0, False: 24.9k]
  ------------------
 1140|  24.9k|                                                        pMechanism->ulParameterLen < 8)) {
  ------------------
  |  Branch (1140:57): [True: 0, False: 24.9k]
  ------------------
 1141|      0|                crv = CKR_DOMAIN_PARAMS_INVALID;
  ------------------
  |  | 1508|      0|#define CKR_DOMAIN_PARAMS_INVALID 0x00000130UL
  ------------------
 1142|      0|                break;
 1143|      0|            }
 1144|  58.9k|            context->blockSize = 8;
 1145|  58.9k|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  58.9k|#define CKA_VALUE 0x00000011UL
  ------------------
 1146|  58.9k|            if (att == NULL) {
  ------------------
  |  Branch (1146:17): [True: 0, False: 58.9k]
  ------------------
 1147|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1148|      0|                break;
 1149|      0|            }
 1150|  58.9k|            if (key_type == CKK_DES2 &&
  ------------------
  |  |  387|   117k|#define CKK_DES2 0x00000014UL
  ------------------
  |  Branch (1150:17): [True: 0, False: 58.9k]
  ------------------
 1151|  58.9k|                (t == NSS_DES_EDE3_CBC || t == NSS_DES_EDE3)) {
  ------------------
  |  |   28|      0|#define NSS_DES_EDE3_CBC 3
  ------------------
                              (t == NSS_DES_EDE3_CBC || t == NSS_DES_EDE3)) {
  ------------------
  |  |   27|      0|#define NSS_DES_EDE3 2
  ------------------
  |  Branch (1151:18): [True: 0, False: 0]
  |  Branch (1151:43): [True: 0, False: 0]
  ------------------
 1152|       |                /* extend DES2 key to DES3 key. */
 1153|      0|                memcpy(newdeskey, att->attrib.pValue, 16);
 1154|      0|                memcpy(newdeskey + 16, newdeskey, 8);
 1155|      0|                useNewKey = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1156|  58.9k|            } else if (key_type == CKK_CDMF) {
  ------------------
  |  |  401|  58.9k|#define CKK_CDMF 0x0000001EUL
  ------------------
  |  Branch (1156:24): [True: 0, False: 58.9k]
  ------------------
 1157|      0|                crv = sftk_cdmf2des((unsigned char *)att->attrib.pValue, newdeskey);
 1158|      0|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1158:21): [True: 0, False: 0]
  ------------------
 1159|      0|                    sftk_FreeAttribute(att);
 1160|      0|                    break;
 1161|      0|                }
 1162|      0|                useNewKey = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1163|      0|            }
 1164|  58.9k|            context->cipherInfo = DES_CreateContext(
 1165|  58.9k|                useNewKey ? newdeskey : (unsigned char *)att->attrib.pValue,
  ------------------
  |  Branch (1165:17): [True: 0, False: 58.9k]
  ------------------
 1166|  58.9k|                (unsigned char *)pMechanism->pParameter, t, isEncrypt);
 1167|  58.9k|            if (useNewKey)
  ------------------
  |  Branch (1167:17): [True: 0, False: 58.9k]
  ------------------
 1168|      0|                memset(newdeskey, 0, sizeof newdeskey);
 1169|  58.9k|            sftk_FreeAttribute(att);
 1170|  58.9k|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1170:17): [True: 0, False: 58.9k]
  ------------------
 1171|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1172|      0|                break;
 1173|      0|            }
 1174|  58.9k|            context->update = isEncrypt ? SFTKCipher_DES_Encrypt : SFTKCipher_DES_Decrypt;
  ------------------
  |  Branch (1174:31): [True: 46.4k, False: 12.4k]
  ------------------
 1175|  58.9k|            context->destroy = SFTKCipher_DES_DestroyContext;
 1176|  58.9k|            break;
 1177|      0|#ifndef NSS_DISABLE_DEPRECATED_SEED
 1178|      0|        case CKM_SEED_CBC_PAD:
  ------------------
  |  | 1160|      0|#define CKM_SEED_CBC_PAD 0x00000655UL
  ------------------
  |  Branch (1178:9): [True: 0, False: 103k]
  ------------------
 1179|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1180|       |        /* fall thru */
 1181|  1.48k|        case CKM_SEED_CBC:
  ------------------
  |  | 1157|  1.48k|#define CKM_SEED_CBC 0x00000652UL
  ------------------
  |  Branch (1181:9): [True: 1.48k, False: 101k]
  ------------------
 1182|  1.48k|            if (!pMechanism->pParameter ||
  ------------------
  |  Branch (1182:17): [True: 0, False: 1.48k]
  ------------------
 1183|  1.48k|                pMechanism->ulParameterLen != 16) {
  ------------------
  |  Branch (1183:17): [True: 0, False: 1.48k]
  ------------------
 1184|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1185|      0|                break;
 1186|      0|            }
 1187|       |        /* fall thru */
 1188|  1.48k|        case CKM_SEED_ECB:
  ------------------
  |  | 1156|  1.48k|#define CKM_SEED_ECB 0x00000651UL
  ------------------
  |  Branch (1188:9): [True: 0, False: 103k]
  ------------------
 1189|  1.48k|            context->blockSize = 16;
 1190|  1.48k|            if (key_type != CKK_SEED) {
  ------------------
  |  |  416|  1.48k|#define CKK_SEED 0x0000002FUL /* was 2A */
  ------------------
  |  Branch (1190:17): [True: 0, False: 1.48k]
  ------------------
 1191|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1192|      0|                break;
 1193|      0|            }
 1194|  1.48k|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  1.48k|#define CKA_VALUE 0x00000011UL
  ------------------
 1195|  1.48k|            if (att == NULL) {
  ------------------
  |  Branch (1195:17): [True: 0, False: 1.48k]
  ------------------
 1196|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1197|      0|                break;
 1198|      0|            }
 1199|  1.48k|            context->cipherInfo = SEED_CreateContext(
 1200|  1.48k|                (unsigned char *)att->attrib.pValue,
 1201|  1.48k|                (unsigned char *)pMechanism->pParameter,
 1202|  1.48k|                pMechanism->mechanism == CKM_SEED_ECB ? NSS_SEED : NSS_SEED_CBC,
  ------------------
  |  | 1156|  1.48k|#define CKM_SEED_ECB 0x00000651UL
  ------------------
                              pMechanism->mechanism == CKM_SEED_ECB ? NSS_SEED : NSS_SEED_CBC,
  ------------------
  |  |   46|      0|#define NSS_SEED 0
  ------------------
                              pMechanism->mechanism == CKM_SEED_ECB ? NSS_SEED : NSS_SEED_CBC,
  ------------------
  |  |   47|  1.48k|#define NSS_SEED_CBC 1
  ------------------
  |  Branch (1202:17): [True: 0, False: 1.48k]
  ------------------
 1203|  1.48k|                isEncrypt);
 1204|  1.48k|            sftk_FreeAttribute(att);
 1205|  1.48k|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1205:17): [True: 0, False: 1.48k]
  ------------------
 1206|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1207|      0|                break;
 1208|      0|            }
 1209|  1.48k|            context->update = isEncrypt ? SFTKCipher_SEED_Encrypt : SFTKCipher_SEED_Decrypt;
  ------------------
  |  Branch (1209:31): [True: 743, False: 743]
  ------------------
 1210|  1.48k|            context->destroy = SFTKCipher_SEED_DestroyContext;
 1211|  1.48k|            break;
 1212|      0|#endif /* NSS_DISABLE_DEPRECATED_SEED */
 1213|      0|        case CKM_CAMELLIA_CBC_PAD:
  ------------------
  |  | 1140|      0|#define CKM_CAMELLIA_CBC_PAD 0x00000555UL
  ------------------
  |  Branch (1213:9): [True: 0, False: 103k]
  ------------------
 1214|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1215|       |        /* fall thru */
 1216|  2.03k|        case CKM_CAMELLIA_CBC:
  ------------------
  |  | 1137|  2.03k|#define CKM_CAMELLIA_CBC 0x00000552UL
  ------------------
  |  Branch (1216:9): [True: 2.03k, False: 101k]
  ------------------
 1217|  2.03k|            if (!pMechanism->pParameter ||
  ------------------
  |  Branch (1217:17): [True: 0, False: 2.03k]
  ------------------
 1218|  2.03k|                pMechanism->ulParameterLen != 16) {
  ------------------
  |  Branch (1218:17): [True: 0, False: 2.03k]
  ------------------
 1219|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1220|      0|                break;
 1221|      0|            }
 1222|       |        /* fall thru */
 1223|  2.03k|        case CKM_CAMELLIA_ECB:
  ------------------
  |  | 1136|  2.03k|#define CKM_CAMELLIA_ECB 0x00000551UL
  ------------------
  |  Branch (1223:9): [True: 0, False: 103k]
  ------------------
 1224|  2.03k|            context->blockSize = 16;
 1225|  2.03k|            if (key_type != CKK_CAMELLIA) {
  ------------------
  |  |  414|  2.03k|#define CKK_CAMELLIA 0x00000025UL
  ------------------
  |  Branch (1225:17): [True: 0, False: 2.03k]
  ------------------
 1226|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1227|      0|                break;
 1228|      0|            }
 1229|  2.03k|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  2.03k|#define CKA_VALUE 0x00000011UL
  ------------------
 1230|  2.03k|            if (att == NULL) {
  ------------------
  |  Branch (1230:17): [True: 0, False: 2.03k]
  ------------------
 1231|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1232|      0|                break;
 1233|      0|            }
 1234|  2.03k|            context->cipherInfo = Camellia_CreateContext(
 1235|  2.03k|                (unsigned char *)att->attrib.pValue,
 1236|  2.03k|                (unsigned char *)pMechanism->pParameter,
 1237|  2.03k|                pMechanism->mechanism ==
  ------------------
  |  Branch (1237:17): [True: 0, False: 2.03k]
  ------------------
 1238|  2.03k|                        CKM_CAMELLIA_ECB
  ------------------
  |  | 1136|  2.03k|#define CKM_CAMELLIA_ECB 0x00000551UL
  ------------------
 1239|  2.03k|                    ? NSS_CAMELLIA
  ------------------
  |  |   42|      0|#define NSS_CAMELLIA 0
  ------------------
 1240|  2.03k|                    : NSS_CAMELLIA_CBC,
  ------------------
  |  |   43|  2.03k|#define NSS_CAMELLIA_CBC 1
  ------------------
 1241|  2.03k|                isEncrypt, att->attrib.ulValueLen);
 1242|  2.03k|            sftk_FreeAttribute(att);
 1243|  2.03k|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1243:17): [True: 0, False: 2.03k]
  ------------------
 1244|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1245|      0|                break;
 1246|      0|            }
 1247|  2.03k|            context->update = isEncrypt ? SFTKCipher_Camellia_Encrypt : SFTKCipher_Camellia_Decrypt;
  ------------------
  |  Branch (1247:31): [True: 1.01k, False: 1.01k]
  ------------------
 1248|  2.03k|            context->destroy = SFTKCipher_Camellia_DestroyContext;
 1249|  2.03k|            break;
 1250|       |
 1251|      0|        case CKM_AES_CBC_PAD:
  ------------------
  |  | 1111|      0|#define CKM_AES_CBC_PAD 0x00001085UL
  ------------------
  |  Branch (1251:9): [True: 0, False: 103k]
  ------------------
 1252|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1253|       |        /* fall thru */
 1254|      0|        case CKM_AES_ECB:
  ------------------
  |  | 1107|      0|#define CKM_AES_ECB 0x00001081UL
  ------------------
  |  Branch (1254:9): [True: 0, False: 103k]
  ------------------
 1255|  16.4k|        case CKM_AES_CBC:
  ------------------
  |  | 1108|  16.4k|#define CKM_AES_CBC 0x00001082UL
  ------------------
  |  Branch (1255:9): [True: 16.4k, False: 86.7k]
  ------------------
 1256|  16.4k|            context->blockSize = 16;
 1257|  16.4k|        case CKM_AES_CTS:
  ------------------
  |  | 1117|  16.4k|#define CKM_AES_CTS 0x00001089UL
  ------------------
  |  Branch (1257:9): [True: 0, False: 103k]
  ------------------
 1258|  16.4k|        case CKM_AES_CTR:
  ------------------
  |  | 1113|  16.4k|#define CKM_AES_CTR 0x00001086UL
  ------------------
  |  Branch (1258:9): [True: 0, False: 103k]
  ------------------
 1259|  16.4k|        case CKM_AES_GCM:
  ------------------
  |  | 1115|  16.4k|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (1259:9): [True: 0, False: 103k]
  ------------------
 1260|  16.4k|            aes_param = pMechanism->pParameter;
 1261|       |            /*
 1262|       |             *  Due to a mismatch between the documentation and the header
 1263|       |             *  file, two different definitions for CK_GCM_PARAMS exist.
 1264|       |             *  The header file is normative according to Oasis, but NSS used
 1265|       |             *  the documentation. In PKCS #11 v3.0, this was reconciled in
 1266|       |             *  favor of the header file definition. To maintain binary
 1267|       |             *  compatibility, NSS now defines CK_GCM_PARAMS_V3 as the official
 1268|       |             *  version v3 (V2.4 header file) and CK_NSS_GCM_PARAMS as the
 1269|       |             *  legacy (V2.4 documentation, NSS version). CK_GCM_PARAMS
 1270|       |             *  is defined as CK_GCM_PARAMS_V3 if NSS_PKCS11_2_0_COMPAT is not
 1271|       |             *  defined and CK_NSS_GCM_PARAMS if it is. Internally
 1272|       |             *  softoken continues to use the legacy version. The code below
 1273|       |             *  automatically detects which parameter was passed in and
 1274|       |             *  converts CK_GCM_PARAMS_V3 to the CK_NSS_GCM_PARAMS (legacy
 1275|       |             *  version) on the fly. NSS proper will eventually start
 1276|       |             *  using the CK_GCM_PARAMS_V3 version and fall back to the
 1277|       |             *  CK_NSS_GCM_PARAMS if the CK_GCM_PARAMS_V3 version fails with
 1278|       |             *  CKR_MECHANISM_PARAM_INVALID.
 1279|       |             */
 1280|  16.4k|            if (pMechanism->mechanism == CKM_AES_GCM) {
  ------------------
  |  | 1115|  16.4k|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (1280:17): [True: 0, False: 16.4k]
  ------------------
 1281|      0|                if (!aes_param) {
  ------------------
  |  Branch (1281:21): [True: 0, False: 0]
  ------------------
 1282|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1283|      0|                    break;
 1284|      0|                }
 1285|      0|                if (pMechanism->ulParameterLen == sizeof(CK_GCM_PARAMS_V3)) {
  ------------------
  |  Branch (1285:21): [True: 0, False: 0]
  ------------------
 1286|       |                    /* convert the true V3 parameters into the old NSS parameters */
 1287|      0|                    CK_GCM_PARAMS_V3 *gcm_params = (CK_GCM_PARAMS_V3 *)aes_param;
 1288|      0|                    if (gcm_params->ulIvLen * 8 != gcm_params->ulIvBits) {
  ------------------
  |  Branch (1288:25): [True: 0, False: 0]
  ------------------
 1289|       |                        /* only support byte aligned IV lengths */
 1290|      0|                        crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1291|      0|                        break;
 1292|      0|                    }
 1293|      0|                    aes_param = (void *)&nss_gcm_param;
 1294|      0|                    nss_gcm_param.pIv = gcm_params->pIv;
 1295|      0|                    nss_gcm_param.ulIvLen = gcm_params->ulIvLen;
 1296|      0|                    nss_gcm_param.pAAD = gcm_params->pAAD;
 1297|      0|                    nss_gcm_param.ulAADLen = gcm_params->ulAADLen;
 1298|      0|                    nss_gcm_param.ulTagBits = gcm_params->ulTagBits;
 1299|      0|                } else if (pMechanism->ulParameterLen != sizeof(CK_NSS_GCM_PARAMS)) {
  ------------------
  |  Branch (1299:28): [True: 0, False: 0]
  ------------------
 1300|       |                    /* neither old nor new style params, must be invalid */
 1301|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1302|      0|                    break;
 1303|      0|                }
 1304|  16.4k|            } else if ((pMechanism->mechanism == CKM_AES_CTR && BAD_PARAM_CAST(pMechanism, sizeof(CK_AES_CTR_PARAMS))) ||
  ------------------
  |  | 1113|  32.8k|#define CKM_AES_CTR 0x00001086UL
  ------------------
                          } else if ((pMechanism->mechanism == CKM_AES_CTR && BAD_PARAM_CAST(pMechanism, sizeof(CK_AES_CTR_PARAMS))) ||
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  |  Branch (1304:25): [True: 0, False: 16.4k]
  ------------------
 1305|  16.4k|                       ((pMechanism->mechanism == CKM_AES_CBC || pMechanism->mechanism == CKM_AES_CTS) && BAD_PARAM_CAST(pMechanism, AES_BLOCK_SIZE))) {
  ------------------
  |  | 1108|  32.8k|#define CKM_AES_CBC 0x00001082UL
  ------------------
                                     ((pMechanism->mechanism == CKM_AES_CBC || pMechanism->mechanism == CKM_AES_CTS) && BAD_PARAM_CAST(pMechanism, AES_BLOCK_SIZE))) {
  ------------------
  |  | 1117|      0|#define CKM_AES_CTS 0x00001089UL
  ------------------
                                     ((pMechanism->mechanism == CKM_AES_CBC || pMechanism->mechanism == CKM_AES_CTS) && BAD_PARAM_CAST(pMechanism, AES_BLOCK_SIZE))) {
  ------------------
  |  |   50|  16.4k|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 16.4k]
  |  |  |  Branch (50:64): [True: 0, False: 16.4k]
  |  |  ------------------
  ------------------
  |  Branch (1305:26): [True: 16.4k, False: 0]
  |  Branch (1305:66): [True: 0, False: 0]
  ------------------
 1306|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1307|      0|                break;
 1308|      0|            }
 1309|       |
 1310|  16.4k|            if (pMechanism->mechanism == CKM_AES_GCM) {
  ------------------
  |  | 1115|  16.4k|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (1310:17): [True: 0, False: 16.4k]
  ------------------
 1311|      0|                context->multi = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1312|      0|            }
 1313|  16.4k|            if (key_type != CKK_AES) {
  ------------------
  |  |  402|  16.4k|#define CKK_AES 0x0000001FUL
  ------------------
  |  Branch (1313:17): [True: 0, False: 16.4k]
  ------------------
 1314|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1315|      0|                break;
 1316|      0|            }
 1317|  16.4k|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  16.4k|#define CKA_VALUE 0x00000011UL
  ------------------
 1318|  16.4k|            if (att == NULL) {
  ------------------
  |  Branch (1318:17): [True: 0, False: 16.4k]
  ------------------
 1319|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1320|      0|                break;
 1321|      0|            }
 1322|  16.4k|            context->cipherInfo = AES_CreateContext(
 1323|  16.4k|                (unsigned char *)att->attrib.pValue,
 1324|  16.4k|                (unsigned char *)aes_param,
 1325|  16.4k|                sftk_aes_mode(pMechanism->mechanism),
 1326|  16.4k|                isEncrypt, att->attrib.ulValueLen, 16);
 1327|  16.4k|            sftk_FreeAttribute(att);
 1328|  16.4k|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1328:17): [True: 0, False: 16.4k]
  ------------------
 1329|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1330|      0|                break;
 1331|      0|            }
 1332|  16.4k|            context->update = isEncrypt ? SFTKCipher_AES_Encrypt : SFTKCipher_AES_Decrypt;
  ------------------
  |  Branch (1332:31): [True: 8.20k, False: 8.20k]
  ------------------
 1333|  16.4k|            context->destroy = SFTKCipher_AES_DestroyContext;
 1334|  16.4k|            break;
 1335|       |
 1336|      0|        case CKM_NSS_CHACHA20_POLY1305:
  ------------------
  |  |  243|      0|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1336:9): [True: 0, False: 103k]
  ------------------
 1337|      0|        case CKM_CHACHA20_POLY1305:
  ------------------
  |  | 1287|      0|#define CKM_CHACHA20_POLY1305 0x00004021UL
  ------------------
  |  Branch (1337:9): [True: 0, False: 103k]
  ------------------
 1338|      0|            if (pMechanism->mechanism == CKM_NSS_CHACHA20_POLY1305) {
  ------------------
  |  |  243|      0|#define CKM_NSS_CHACHA20_POLY1305 (CKM_NSS + 28)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1338:17): [True: 0, False: 0]
  ------------------
 1339|      0|                if (key_type != CKK_NSS_CHACHA20) {
  ------------------
  |  |   56|      0|#define CKK_NSS_CHACHA20 (CKK_NSS + 4)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1339:21): [True: 0, False: 0]
  ------------------
 1340|      0|                    crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1341|      0|                    break;
 1342|      0|                }
 1343|      0|                if ((pMechanism->pParameter == NULL) ||
  ------------------
  |  Branch (1343:21): [True: 0, False: 0]
  ------------------
 1344|      0|                    (pMechanism->ulParameterLen != sizeof(CK_NSS_AEAD_PARAMS))) {
  ------------------
  |  Branch (1344:21): [True: 0, False: 0]
  ------------------
 1345|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1346|      0|                    break;
 1347|      0|                }
 1348|      0|                nss_aead_params_ptr = (CK_NSS_AEAD_PARAMS *)pMechanism->pParameter;
 1349|      0|            } else {
 1350|      0|                CK_SALSA20_CHACHA20_POLY1305_PARAMS_PTR chacha_poly_params;
 1351|      0|                if (key_type != CKK_CHACHA20) {
  ------------------
  |  |  433|      0|#define CKK_CHACHA20 0x00000033UL
  ------------------
  |  Branch (1351:21): [True: 0, False: 0]
  ------------------
 1352|      0|                    crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1353|      0|                    break;
 1354|      0|                }
 1355|      0|                if ((pMechanism->pParameter == NULL) ||
  ------------------
  |  Branch (1355:21): [True: 0, False: 0]
  ------------------
 1356|      0|                    (pMechanism->ulParameterLen !=
  ------------------
  |  Branch (1356:21): [True: 0, False: 0]
  ------------------
 1357|      0|                     sizeof(CK_SALSA20_CHACHA20_POLY1305_PARAMS))) {
 1358|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1359|      0|                    break;
 1360|      0|                }
 1361|      0|                chacha_poly_params = (CK_SALSA20_CHACHA20_POLY1305_PARAMS_PTR)
 1362|      0|                                         pMechanism->pParameter;
 1363|      0|                nss_aead_params_ptr = &nss_aead_params;
 1364|      0|                nss_aead_params.pNonce = chacha_poly_params->pNonce;
 1365|      0|                nss_aead_params.ulNonceLen = chacha_poly_params->ulNonceLen;
 1366|      0|                nss_aead_params.pAAD = chacha_poly_params->pAAD;
 1367|      0|                nss_aead_params.ulAADLen = chacha_poly_params->ulAADLen;
 1368|      0|                nss_aead_params.ulTagLen = 16; /* Poly1305 is always 16 */
 1369|      0|            }
 1370|       |
 1371|      0|            context->multi = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1372|      0|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 1373|      0|            if (att == NULL) {
  ------------------
  |  Branch (1373:17): [True: 0, False: 0]
  ------------------
 1374|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1375|      0|                break;
 1376|      0|            }
 1377|      0|            context->cipherInfo = sftk_ChaCha20Poly1305_CreateContext(
 1378|      0|                (unsigned char *)att->attrib.pValue, att->attrib.ulValueLen,
 1379|      0|                nss_aead_params_ptr);
 1380|      0|            sftk_FreeAttribute(att);
 1381|      0|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1381:17): [True: 0, False: 0]
  ------------------
 1382|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 1383|      0|                break;
 1384|      0|            }
 1385|      0|            context->update = isEncrypt ? sftk_ChaCha20Poly1305_Encrypt : sftk_ChaCha20Poly1305_Decrypt;
  ------------------
  |  Branch (1385:31): [True: 0, False: 0]
  ------------------
 1386|      0|            context->destroy = sftk_ChaCha20Poly1305_DestroyContext;
 1387|      0|            break;
 1388|       |
 1389|      0|        case CKM_NSS_CHACHA20_CTR: /* old NSS private version */
  ------------------
  |  |  251|      0|#define CKM_NSS_CHACHA20_CTR (CKM_NSS + 33)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1389:9): [True: 0, False: 103k]
  ------------------
 1390|      0|        case CKM_CHACHA20:         /* PKCS #11 v3 version */
  ------------------
  |  | 1204|      0|#define CKM_CHACHA20 0x00001226UL
  ------------------
  |  Branch (1390:9): [True: 0, False: 103k]
  ------------------
 1391|      0|        {
 1392|      0|            unsigned char *counter;
 1393|      0|            unsigned char *nonce;
 1394|      0|            unsigned long counter_len;
 1395|      0|            unsigned long nonce_len;
 1396|      0|            context->multi = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1397|      0|            if (pMechanism->mechanism == CKM_NSS_CHACHA20_CTR) {
  ------------------
  |  |  251|      0|#define CKM_NSS_CHACHA20_CTR (CKM_NSS + 33)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1397:17): [True: 0, False: 0]
  ------------------
 1398|      0|                if (key_type != CKK_NSS_CHACHA20) {
  ------------------
  |  |   56|      0|#define CKK_NSS_CHACHA20 (CKK_NSS + 4)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1398:21): [True: 0, False: 0]
  ------------------
 1399|      0|                    crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1400|      0|                    break;
 1401|      0|                }
 1402|      0|                if (pMechanism->pParameter == NULL || pMechanism->ulParameterLen != 16) {
  ------------------
  |  Branch (1402:21): [True: 0, False: 0]
  |  Branch (1402:55): [True: 0, False: 0]
  ------------------
 1403|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1404|      0|                    break;
 1405|      0|                }
 1406|      0|                counter_len = 4;
 1407|      0|                counter = pMechanism->pParameter;
 1408|      0|                nonce = counter + 4;
 1409|      0|                nonce_len = 12;
 1410|      0|            } else {
 1411|      0|                CK_CHACHA20_PARAMS_PTR chacha20_param_ptr;
 1412|      0|                if (key_type != CKK_CHACHA20) {
  ------------------
  |  |  433|      0|#define CKK_CHACHA20 0x00000033UL
  ------------------
  |  Branch (1412:21): [True: 0, False: 0]
  ------------------
 1413|      0|                    crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1414|      0|                    break;
 1415|      0|                }
 1416|      0|                if (pMechanism->pParameter == NULL || pMechanism->ulParameterLen != sizeof(CK_CHACHA20_PARAMS)) {
  ------------------
  |  Branch (1416:21): [True: 0, False: 0]
  |  Branch (1416:55): [True: 0, False: 0]
  ------------------
 1417|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1418|      0|                    break;
 1419|      0|                }
 1420|      0|                chacha20_param_ptr = (CK_CHACHA20_PARAMS_PTR)pMechanism->pParameter;
 1421|      0|                if ((chacha20_param_ptr->blockCounterBits != 32) &&
  ------------------
  |  Branch (1421:21): [True: 0, False: 0]
  ------------------
 1422|      0|                    (chacha20_param_ptr->blockCounterBits != 64)) {
  ------------------
  |  Branch (1422:21): [True: 0, False: 0]
  ------------------
 1423|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1424|      0|                    break;
 1425|      0|                }
 1426|      0|                counter_len = chacha20_param_ptr->blockCounterBits / PR_BITS_PER_BYTE;
  ------------------
  |  |  286|      0|#define PR_BITS_PER_BYTE    8
  ------------------
 1427|      0|                counter = chacha20_param_ptr->pBlockCounter;
 1428|      0|                nonce = chacha20_param_ptr->pNonce;
 1429|      0|                nonce_len = chacha20_param_ptr->ulNonceBits / PR_BITS_PER_BYTE;
  ------------------
  |  |  286|      0|#define PR_BITS_PER_BYTE    8
  ------------------
 1430|      0|            }
 1431|       |
 1432|      0|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 1433|      0|            if (att == NULL) {
  ------------------
  |  Branch (1433:17): [True: 0, False: 0]
  ------------------
 1434|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1435|      0|                break;
 1436|      0|            }
 1437|      0|            SFTKChaCha20CtrInfo *ctx = PORT_ZNew(SFTKChaCha20CtrInfo);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1438|      0|            if (!ctx) {
  ------------------
  |  Branch (1438:17): [True: 0, False: 0]
  ------------------
 1439|      0|                sftk_FreeAttribute(att);
 1440|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1441|      0|                break;
 1442|      0|            }
 1443|      0|            if (att->attrib.ulValueLen != sizeof(ctx->key)) {
  ------------------
  |  Branch (1443:17): [True: 0, False: 0]
  ------------------
 1444|      0|                sftk_FreeAttribute(att);
 1445|      0|                PORT_Free(ctx);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1446|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1447|      0|                break;
 1448|      0|            }
 1449|      0|            memcpy(ctx->key, att->attrib.pValue, att->attrib.ulValueLen);
 1450|      0|            sftk_FreeAttribute(att);
 1451|       |
 1452|       |            /* make sure we don't overflow our parameters */
 1453|      0|            if ((sizeof(ctx->counter) < counter_len) ||
  ------------------
  |  Branch (1453:17): [True: 0, False: 0]
  ------------------
 1454|      0|                (sizeof(ctx->nonce) < nonce_len)) {
  ------------------
  |  Branch (1454:17): [True: 0, False: 0]
  ------------------
 1455|      0|                PORT_Free(ctx);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1456|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 1457|      0|                break;
 1458|      0|            }
 1459|       |
 1460|       |            /* The counter is little endian. */
 1461|      0|            int i = 0;
 1462|      0|            for (; i < counter_len; ++i) {
  ------------------
  |  Branch (1462:20): [True: 0, False: 0]
  ------------------
 1463|      0|                ctx->counter |= (PRUint32)counter[i] << (i * 8);
 1464|      0|            }
 1465|      0|            memcpy(ctx->nonce, nonce, nonce_len);
 1466|      0|            context->cipherInfo = ctx;
 1467|      0|            context->update = sftk_ChaCha20Ctr;
 1468|      0|            context->destroy = sftk_ChaCha20Ctr_DestroyContext;
 1469|      0|            break;
 1470|      0|        }
 1471|       |
 1472|      0|        case CKM_NSS_AES_KEY_WRAP_PAD:
  ------------------
  |  |  165|      0|#define CKM_NSS_AES_KEY_WRAP_PAD (CKM_NSS + 2)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1472:9): [True: 0, False: 103k]
  ------------------
 1473|      0|        case CKM_AES_KEY_WRAP_PAD:
  ------------------
  |  | 1232|      0|#define CKM_AES_KEY_WRAP_PAD 0x0000210AUL
  ------------------
  |  Branch (1473:9): [True: 0, False: 103k]
  ------------------
 1474|      0|            context->doPad = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1475|       |        /* fall thru */
 1476|      0|        case CKM_NSS_AES_KEY_WRAP:
  ------------------
  |  |  164|      0|#define CKM_NSS_AES_KEY_WRAP (CKM_NSS + 1)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (1476:9): [True: 0, False: 103k]
  ------------------
 1477|      0|        case CKM_AES_KEY_WRAP:
  ------------------
  |  | 1231|      0|#define CKM_AES_KEY_WRAP 0x00002109UL
  ------------------
  |  Branch (1477:9): [True: 0, False: 103k]
  ------------------
 1478|      0|            context->blockSize = 8;
 1479|      0|        case CKM_AES_KEY_WRAP_KWP:
  ------------------
  |  | 1233|      0|#define CKM_AES_KEY_WRAP_KWP 0x0000210BUL
  ------------------
  |  Branch (1479:9): [True: 0, False: 103k]
  ------------------
 1480|      0|            context->multi = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1481|      0|            if (key_type != CKK_AES) {
  ------------------
  |  |  402|      0|#define CKK_AES 0x0000001FUL
  ------------------
  |  Branch (1481:17): [True: 0, False: 0]
  ------------------
 1482|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 1483|      0|                break;
 1484|      0|            }
 1485|      0|            att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 1486|      0|            if (att == NULL) {
  ------------------
  |  Branch (1486:17): [True: 0, False: 0]
  ------------------
 1487|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 1488|      0|                break;
 1489|      0|            }
 1490|      0|            context->cipherInfo = AESKeyWrap_CreateContext(
 1491|      0|                (unsigned char *)att->attrib.pValue,
 1492|      0|                (unsigned char *)pMechanism->pParameter,
 1493|      0|                isEncrypt, att->attrib.ulValueLen);
 1494|      0|            sftk_FreeAttribute(att);
 1495|      0|            if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (1495:17): [True: 0, False: 0]
  ------------------
 1496|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1497|      0|                break;
 1498|      0|            }
 1499|      0|            if (pMechanism->mechanism == CKM_AES_KEY_WRAP_KWP) {
  ------------------
  |  | 1233|      0|#define CKM_AES_KEY_WRAP_KWP 0x0000210BUL
  ------------------
  |  Branch (1499:17): [True: 0, False: 0]
  ------------------
 1500|      0|                context->update = isEncrypt ? SFTKCipher_AESKeyWrap_EncryptKWP
  ------------------
  |  Branch (1500:35): [True: 0, False: 0]
  ------------------
 1501|      0|                                            : SFTKCipher_AESKeyWrap_DecryptKWP;
 1502|      0|            } else {
 1503|      0|                context->update = isEncrypt ? SFTKCipher_AESKeyWrap_Encrypt
  ------------------
  |  Branch (1503:35): [True: 0, False: 0]
  ------------------
 1504|      0|                                            : SFTKCipher_AESKeyWrap_Decrypt;
 1505|      0|            }
 1506|      0|            context->destroy = SFTKCipher_AESKeyWrap_DestroyContext;
 1507|      0|            break;
 1508|       |
 1509|      0|        default:
  ------------------
  |  Branch (1509:9): [True: 0, False: 103k]
  ------------------
 1510|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 1511|      0|            break;
 1512|   103k|    }
 1513|       |
 1514|   103k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   103k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1514:9): [True: 0, False: 103k]
  ------------------
 1515|      0|        sftk_FreeContext(context);
 1516|      0|        sftk_FreeSession(session);
 1517|      0|        return crv;
 1518|      0|    }
 1519|   103k|    sftk_SetContextByType(session, contextType, context);
 1520|   103k|    sftk_FreeSession(session);
 1521|   103k|    return CKR_OK;
  ------------------
  |  | 1388|   103k|#define CKR_OK 0x00000000UL
  ------------------
 1522|   103k|}
NSC_EncryptInit:
 1528|  23.0k|{
 1529|  23.0k|    CHECK_FORK();
 1530|  23.0k|    return sftk_CryptInit(hSession, pMechanism, hKey, CKA_ENCRYPT, CKA_ENCRYPT,
  ------------------
  |  |  547|  23.0k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
                  return sftk_CryptInit(hSession, pMechanism, hKey, CKA_ENCRYPT, CKA_ENCRYPT,
  ------------------
  |  |  547|  23.0k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 1531|  23.0k|                          SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  437|  23.0k|#define PR_TRUE 1
  ------------------
 1532|  23.0k|}
NSC_Encrypt:
 1673|  33.9k|{
 1674|  33.9k|    SFTKSession *session;
 1675|  33.9k|    SFTKSessionContext *context;
 1676|  33.9k|    unsigned int outlen;
 1677|  33.9k|    unsigned int maxoutlen = *pulEncryptedDataLen;
 1678|  33.9k|    CK_RV crv;
 1679|  33.9k|    CK_RV crv2;
 1680|  33.9k|    SECStatus rv = SECSuccess;
 1681|  33.9k|    SECItem pText;
 1682|       |
 1683|  33.9k|    pText.type = siBuffer;
 1684|  33.9k|    pText.data = pData;
 1685|  33.9k|    pText.len = ulDataLen;
 1686|       |
 1687|  33.9k|    CHECK_FORK();
 1688|       |
 1689|       |    /* make sure we're legal */
 1690|  33.9k|    crv = sftk_GetContext(hSession, &context, SFTK_ENCRYPT, PR_FALSE, &session);
  ------------------
  |  |  438|  33.9k|#define PR_FALSE 0
  ------------------
 1691|  33.9k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  33.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1691:9): [True: 0, False: 33.9k]
  ------------------
 1692|      0|        return crv;
 1693|       |
 1694|  33.9k|    if (!pEncryptedData) {
  ------------------
  |  Branch (1694:9): [True: 0, False: 33.9k]
  ------------------
 1695|      0|        outlen = context->rsa ? context->maxLen : ulDataLen + 2 * context->blockSize;
  ------------------
  |  Branch (1695:18): [True: 0, False: 0]
  ------------------
 1696|      0|        goto done;
 1697|      0|    }
 1698|       |
 1699|  33.9k|    if (context->doPad) {
  ------------------
  |  Branch (1699:9): [True: 0, False: 33.9k]
  ------------------
 1700|      0|        if (context->multi) {
  ------------------
  |  Branch (1700:13): [True: 0, False: 0]
  ------------------
 1701|      0|            CK_ULONG updateLen = maxoutlen;
 1702|      0|            CK_ULONG finalLen;
 1703|       |            /* padding is fairly complicated, have the update and final
 1704|       |             * code deal with it */
 1705|      0|            sftk_FreeSession(session);
 1706|      0|            crv = NSC_EncryptUpdate(hSession, pData, ulDataLen, pEncryptedData,
 1707|      0|                                    &updateLen);
 1708|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1708:17): [True: 0, False: 0]
  ------------------
 1709|      0|                updateLen = 0;
 1710|      0|            }
 1711|      0|            maxoutlen -= updateLen;
 1712|      0|            pEncryptedData += updateLen;
 1713|      0|            finalLen = maxoutlen;
 1714|      0|            crv2 = NSC_EncryptFinal(hSession, pEncryptedData, &finalLen);
 1715|      0|            if (crv == CKR_OK && crv2 == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
                          if (crv == CKR_OK && crv2 == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1715:17): [True: 0, False: 0]
  |  Branch (1715:34): [True: 0, False: 0]
  ------------------
 1716|      0|                *pulEncryptedDataLen = updateLen + finalLen;
 1717|      0|            }
 1718|      0|            return crv == CKR_OK ? crv2 : crv;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1718:20): [True: 0, False: 0]
  ------------------
 1719|      0|        }
 1720|       |        /* doPad without multi means that padding must be done on the first
 1721|       |        ** and only update.  There will be no final.
 1722|       |        */
 1723|      0|        PORT_Assert(context->blockSize > 1);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1724|      0|        if (context->blockSize > 1) {
  ------------------
  |  Branch (1724:13): [True: 0, False: 0]
  ------------------
 1725|      0|            CK_ULONG remainder = ulDataLen % context->blockSize;
 1726|      0|            CK_ULONG padding = context->blockSize - remainder;
 1727|      0|            pText.len += padding;
 1728|      0|            pText.data = PORT_ZAlloc(pText.len);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 1729|      0|            if (pText.data) {
  ------------------
  |  Branch (1729:17): [True: 0, False: 0]
  ------------------
 1730|      0|                memcpy(pText.data, pData, ulDataLen);
 1731|      0|                memset(pText.data + ulDataLen, padding, padding);
 1732|      0|            } else {
 1733|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1734|      0|                goto fail;
 1735|      0|            }
 1736|      0|        }
 1737|      0|    }
 1738|       |
 1739|       |    /* do it: NOTE: this assumes buf size is big enough. */
 1740|  33.9k|    rv = (*context->update)(context->cipherInfo, pEncryptedData,
 1741|  33.9k|                            &outlen, maxoutlen, pText.data, pText.len);
 1742|  33.9k|    crv = (rv == SECSuccess) ? CKR_OK : sftk_MapCryptError(PORT_GetError());
  ------------------
  |  | 1388|  33.9k|#define CKR_OK 0x00000000UL
  ------------------
                  crv = (rv == SECSuccess) ? CKR_OK : sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (1742:11): [True: 33.9k, False: 0]
  ------------------
 1743|  33.9k|    if (pText.data != pData)
  ------------------
  |  Branch (1743:9): [True: 0, False: 33.9k]
  ------------------
 1744|      0|        PORT_ZFree(pText.data, pText.len);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 1745|  33.9k|fail:
 1746|  33.9k|    sftk_TerminateOp(session, SFTK_ENCRYPT, context);
 1747|  33.9k|done:
 1748|  33.9k|    sftk_FreeSession(session);
 1749|  33.9k|    if (crv == CKR_OK) {
  ------------------
  |  | 1388|  33.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1749:9): [True: 33.9k, False: 0]
  ------------------
 1750|  33.9k|        *pulEncryptedDataLen = (CK_ULONG)outlen;
 1751|  33.9k|    }
 1752|  33.9k|    return crv;
 1753|  33.9k|}
NSC_DecryptInit:
 1763|  34.2k|{
 1764|  34.2k|    CHECK_FORK();
 1765|  34.2k|    return sftk_CryptInit(hSession, pMechanism, hKey, CKA_DECRYPT, CKA_DECRYPT,
  ------------------
  |  |  548|  34.2k|#define CKA_DECRYPT 0x00000105UL
  ------------------
                  return sftk_CryptInit(hSession, pMechanism, hKey, CKA_DECRYPT, CKA_DECRYPT,
  ------------------
  |  |  548|  34.2k|#define CKA_DECRYPT 0x00000105UL
  ------------------
 1766|  34.2k|                          SFTK_DECRYPT, PR_FALSE);
  ------------------
  |  |  438|  34.2k|#define PR_FALSE 0
  ------------------
 1767|  34.2k|}
NSC_Decrypt:
 1905|  23.1k|{
 1906|  23.1k|    SFTKSession *session;
 1907|  23.1k|    SFTKSessionContext *context;
 1908|  23.1k|    unsigned int outlen;
 1909|  23.1k|    unsigned int maxoutlen = *pulDataLen;
 1910|  23.1k|    CK_RV crv;
 1911|  23.1k|    CK_RV crv2;
 1912|  23.1k|    SECStatus rv = SECSuccess;
 1913|       |
 1914|  23.1k|    CHECK_FORK();
 1915|       |
 1916|       |    /* make sure we're legal */
 1917|  23.1k|    crv = sftk_GetContext(hSession, &context, SFTK_DECRYPT, PR_FALSE, &session);
  ------------------
  |  |  438|  23.1k|#define PR_FALSE 0
  ------------------
 1918|  23.1k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  23.1k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1918:9): [True: 0, False: 23.1k]
  ------------------
 1919|      0|        return crv;
 1920|       |
 1921|  23.1k|    if (!pData) {
  ------------------
  |  Branch (1921:9): [True: 0, False: 23.1k]
  ------------------
 1922|      0|        *pulDataLen = (CK_ULONG)(ulEncryptedDataLen + context->blockSize);
 1923|      0|        goto done;
 1924|      0|    }
 1925|       |
 1926|  23.1k|    if (context->doPad && context->multi) {
  ------------------
  |  Branch (1926:9): [True: 0, False: 23.1k]
  |  Branch (1926:27): [True: 0, False: 0]
  ------------------
 1927|      0|        CK_ULONG updateLen = maxoutlen;
 1928|      0|        CK_ULONG finalLen;
 1929|       |        /* padding is fairly complicated, have the update and final
 1930|       |         * code deal with it */
 1931|      0|        sftk_FreeSession(session);
 1932|      0|        crv = NSC_DecryptUpdate(hSession, pEncryptedData, ulEncryptedDataLen,
 1933|      0|                                pData, &updateLen);
 1934|      0|        if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1934:13): [True: 0, False: 0]
  ------------------
 1935|      0|            maxoutlen -= updateLen;
 1936|      0|            pData += updateLen;
 1937|      0|        }
 1938|      0|        finalLen = maxoutlen;
 1939|      0|        crv2 = NSC_DecryptFinal(hSession, pData, &finalLen);
 1940|      0|        if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1940:13): [True: 0, False: 0]
  ------------------
 1941|      0|            *pulDataLen = PORT_CT_SEL(sftk_CKRVToMask(crv2), updateLen + finalLen, *pulDataLen);
  ------------------
  |  |  348|      0|#define PORT_CT_SEL(m, l, r) (((m) & (l)) | (~(m) & (r)))
  ------------------
 1942|      0|            return crv2;
 1943|      0|        } else {
 1944|      0|            return crv;
 1945|      0|        }
 1946|      0|    }
 1947|       |
 1948|  23.1k|    rv = (*context->update)(context->cipherInfo, pData, &outlen, maxoutlen,
 1949|  23.1k|                            pEncryptedData, ulEncryptedDataLen);
 1950|       |    /* XXX need to do MUCH better error mapping than this. */
 1951|  23.1k|    crv = (rv == SECSuccess) ? CKR_OK : sftk_MapDecryptError(PORT_GetError());
  ------------------
  |  | 1388|    772|#define CKR_OK 0x00000000UL
  ------------------
                  crv = (rv == SECSuccess) ? CKR_OK : sftk_MapDecryptError(PORT_GetError());
  ------------------
  |  |   62|  22.4k|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (1951:11): [True: 772, False: 22.4k]
  ------------------
 1952|  23.1k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (1952:9): [True: 772, False: 22.4k]
  ------------------
 1953|    772|        if (context->doPad) {
  ------------------
  |  Branch (1953:13): [True: 0, False: 772]
  ------------------
 1954|      0|            unsigned int padSize = 0;
 1955|      0|            crv = sftk_CheckCBCPadding(pData, outlen, context->blockSize,
 1956|      0|                                       &padSize);
 1957|       |            /* Update pulDataLen, in constant time, if crv is OK */
 1958|      0|            *pulDataLen = PORT_CT_SEL(sftk_CKRVToMask(crv), outlen - padSize, *pulDataLen);
  ------------------
  |  |  348|      0|#define PORT_CT_SEL(m, l, r) (((m) & (l)) | (~(m) & (r)))
  ------------------
 1959|    772|        } else {
 1960|    772|            *pulDataLen = (CK_ULONG)outlen;
 1961|    772|        }
 1962|    772|    }
 1963|  23.1k|    sftk_TerminateOp(session, SFTK_DECRYPT, context);
 1964|  23.1k|done:
 1965|  23.1k|    sftk_FreeSession(session);
 1966|  23.1k|    return crv;
 1967|  23.1k|}
NSC_DigestInit:
 1977|   265k|{
 1978|   265k|    SFTKSession *session;
 1979|   265k|    SFTKSessionContext *context;
 1980|   265k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   265k|#define CKR_OK 0x00000000UL
  ------------------
 1981|       |
 1982|   265k|    CHECK_FORK();
 1983|       |
 1984|   265k|    session = sftk_SessionFromHandle(hSession);
 1985|   265k|    if (session == NULL)
  ------------------
  |  Branch (1985:9): [True: 0, False: 265k]
  ------------------
 1986|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 1987|   265k|    crv = sftk_InitGeneric(session, pMechanism, &context, SFTK_HASH,
 1988|   265k|                           NULL, 0, NULL, 0, CKA_DIGEST);
  ------------------
  |  |   68|   265k|#define CKA_DIGEST 0x81000000L
  ------------------
 1989|   265k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   265k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1989:9): [True: 0, False: 265k]
  ------------------
 1990|      0|        sftk_FreeSession(session);
 1991|      0|        return crv;
 1992|      0|    }
 1993|       |
 1994|   265k|#define INIT_MECH(mmm)                                         \
 1995|   265k|    case CKM_##mmm: {                                          \
 1996|   265k|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
 1997|   265k|        context->cipherInfo = (void *)mmm##_ctx;               \
 1998|   265k|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
 1999|   265k|        context->currentMech = CKM_##mmm;                      \
 2000|   265k|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
 2001|   265k|        context->end = SFTKHash_##mmm##_End;                   \
 2002|   265k|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
 2003|   265k|        context->maxLen = mmm##_LENGTH;                        \
 2004|   265k|        if (mmm##_ctx)                                         \
 2005|   265k|            mmm##_Begin(mmm##_ctx);                            \
 2006|   265k|        else                                                   \
 2007|   265k|            crv = CKR_HOST_MEMORY;                             \
 2008|   265k|        break;                                                 \
 2009|   265k|    }
 2010|       |
 2011|   265k|    switch (pMechanism->mechanism) {
 2012|      0|        INIT_MECH(MD2)
  ------------------
  |  | 1995|      0|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 0, False: 265k]
  |  |  ------------------
  |  | 1996|      0|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|      0|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|      0|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|      0|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|      0|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|      0|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|      0|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|      0|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|      0|        if (mmm##_ctx)                                         \
  |  | 2005|      0|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|      0|        else                                                   \
  |  | 2007|      0|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|      0|        break;                                                 \
  |  | 2009|      0|    }
  ------------------
 2013|  23.5k|        INIT_MECH(MD5)
  ------------------
  |  | 1995|  23.5k|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 23.5k, False: 242k]
  |  |  ------------------
  |  | 1996|  23.5k|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|  23.5k|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|  23.5k|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|  23.5k|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|  23.5k|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|  23.5k|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|  23.5k|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|  23.5k|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|  23.5k|        if (mmm##_ctx)                                         \
  |  | 2005|  23.5k|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|  23.5k|        else                                                   \
  |  | 2007|  23.5k|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|  23.5k|        break;                                                 \
  |  | 2009|  23.5k|    }
  ------------------
 2014|   111k|        INIT_MECH(SHA1)
  ------------------
  |  | 1995|   111k|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 111k, False: 154k]
  |  |  ------------------
  |  | 1996|   111k|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|   111k|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|   111k|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|   111k|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|   111k|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|   111k|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|   111k|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|   111k|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|   111k|        if (mmm##_ctx)                                         \
  |  | 2005|   111k|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|   111k|        else                                                   \
  |  | 2007|   111k|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|   111k|        break;                                                 \
  |  | 2009|   111k|    }
  ------------------
 2015|      0|        INIT_MECH(SHA224)
  ------------------
  |  | 1995|      0|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 0, False: 265k]
  |  |  ------------------
  |  | 1996|      0|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|      0|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|      0|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|      0|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|      0|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|      0|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|      0|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|      0|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|      0|        if (mmm##_ctx)                                         \
  |  | 2005|      0|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|      0|        else                                                   \
  |  | 2007|      0|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|      0|        break;                                                 \
  |  | 2009|      0|    }
  ------------------
 2016|  69.6k|        INIT_MECH(SHA256)
  ------------------
  |  | 1995|  69.6k|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 69.6k, False: 196k]
  |  |  ------------------
  |  | 1996|  69.6k|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|  69.6k|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|  69.6k|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|  69.6k|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|  69.6k|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|  69.6k|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|  69.6k|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|  69.6k|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|  69.6k|        if (mmm##_ctx)                                         \
  |  | 2005|  69.6k|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|  69.6k|        else                                                   \
  |  | 2007|  69.6k|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|  69.6k|        break;                                                 \
  |  | 2009|  69.6k|    }
  ------------------
 2017|  55.4k|        INIT_MECH(SHA384)
  ------------------
  |  | 1995|  55.4k|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 55.4k, False: 210k]
  |  |  ------------------
  |  | 1996|  55.4k|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|  55.4k|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|  55.4k|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|  55.4k|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|  55.4k|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|  55.4k|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|  55.4k|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|  55.4k|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|  55.4k|        if (mmm##_ctx)                                         \
  |  | 2005|  55.4k|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|  55.4k|        else                                                   \
  |  | 2007|  55.4k|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|  55.4k|        break;                                                 \
  |  | 2009|  55.4k|    }
  ------------------
 2018|  5.85k|        INIT_MECH(SHA512)
  ------------------
  |  | 1995|  5.85k|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 5.85k, False: 260k]
  |  |  ------------------
  |  | 1996|  5.85k|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|  5.85k|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|  5.85k|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|  5.85k|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|  5.85k|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|  5.85k|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|  5.85k|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|  5.85k|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|  5.85k|        if (mmm##_ctx)                                         \
  |  | 2005|  5.85k|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|  5.85k|        else                                                   \
  |  | 2007|  5.85k|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|  5.85k|        break;                                                 \
  |  | 2009|  5.85k|    }
  ------------------
 2019|      0|        INIT_MECH(SHA3_224)
  ------------------
  |  | 1995|      0|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 0, False: 265k]
  |  |  ------------------
  |  | 1996|      0|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|      0|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|      0|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|      0|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|      0|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|      0|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|      0|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|      0|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|      0|        if (mmm##_ctx)                                         \
  |  | 2005|      0|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|      0|        else                                                   \
  |  | 2007|      0|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|      0|        break;                                                 \
  |  | 2009|      0|    }
  ------------------
 2020|      0|        INIT_MECH(SHA3_256)
  ------------------
  |  | 1995|      0|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 0, False: 265k]
  |  |  ------------------
  |  | 1996|      0|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|      0|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|      0|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|      0|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|      0|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|      0|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|      0|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|      0|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|      0|        if (mmm##_ctx)                                         \
  |  | 2005|      0|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|      0|        else                                                   \
  |  | 2007|      0|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|      0|        break;                                                 \
  |  | 2009|      0|    }
  ------------------
 2021|      0|        INIT_MECH(SHA3_384)
  ------------------
  |  | 1995|      0|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 0, False: 265k]
  |  |  ------------------
  |  | 1996|      0|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|      0|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|      0|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|      0|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|      0|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|      0|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|      0|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|      0|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|      0|        if (mmm##_ctx)                                         \
  |  | 2005|      0|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|      0|        else                                                   \
  |  | 2007|      0|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|      0|        break;                                                 \
  |  | 2009|      0|    }
  ------------------
 2022|      0|        INIT_MECH(SHA3_512)
  ------------------
  |  | 1995|      0|    case CKM_##mmm: {                                          \
  |  |  ------------------
  |  |  |  Branch (1995:5): [True: 0, False: 265k]
  |  |  ------------------
  |  | 1996|      0|        mmm##Context *mmm##_ctx = mmm##_NewContext();          \
  |  | 1997|      0|        context->cipherInfo = (void *)mmm##_ctx;               \
  |  | 1998|      0|        context->cipherInfoLen = mmm##_FlattenSize(mmm##_ctx); \
  |  | 1999|      0|        context->currentMech = CKM_##mmm;                      \
  |  | 2000|      0|        context->hashUpdate = SFTKHash_##mmm##_Update;         \
  |  | 2001|      0|        context->end = SFTKHash_##mmm##_End;                   \
  |  | 2002|      0|        context->destroy = SFTKHash_##mmm##_DestroyContext;    \
  |  | 2003|      0|        context->maxLen = mmm##_LENGTH;                        \
  |  | 2004|      0|        if (mmm##_ctx)                                         \
  |  | 2005|      0|            mmm##_Begin(mmm##_ctx);                            \
  |  | 2006|      0|        else                                                   \
  |  | 2007|      0|            crv = CKR_HOST_MEMORY;                             \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2008|      0|        break;                                                 \
  |  | 2009|      0|    }
  ------------------
 2023|       |
 2024|      0|        default:
  ------------------
  |  Branch (2024:9): [True: 0, False: 265k]
  ------------------
 2025|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 2026|      0|            break;
 2027|   265k|    }
 2028|       |
 2029|   265k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   265k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2029:9): [True: 0, False: 265k]
  ------------------
 2030|      0|        sftk_FreeContext(context);
 2031|      0|        sftk_FreeSession(session);
 2032|      0|        return crv;
 2033|      0|    }
 2034|   265k|    sftk_SetContextByType(session, SFTK_HASH, context);
 2035|   265k|    sftk_FreeSession(session);
 2036|   265k|    return CKR_OK;
  ------------------
  |  | 1388|   265k|#define CKR_OK 0x00000000UL
  ------------------
 2037|   265k|}
NSC_DigestUpdate:
 2088|   529k|{
 2089|   529k|    SFTKSessionContext *context;
 2090|   529k|    CK_RV crv;
 2091|       |
 2092|   529k|    CHECK_FORK();
 2093|       |
 2094|       |    /* make sure we're legal */
 2095|   529k|    crv = sftk_GetContext(hSession, &context, SFTK_HASH, PR_TRUE, NULL);
  ------------------
  |  |  437|   529k|#define PR_TRUE 1
  ------------------
 2096|   529k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   529k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2096:9): [True: 0, False: 529k]
  ------------------
 2097|      0|        return crv;
 2098|       |
 2099|   529k|#if (ULONG_MAX > UINT_MAX)
 2100|       |    /* The context->hashUpdate function takes an unsigned int for its data
 2101|       |     * length argument, but NSC_DigestUpdate takes an unsigned long. */
 2102|   529k|    while (ulPartLen > UINT_MAX) {
  ------------------
  |  Branch (2102:12): [True: 0, False: 529k]
  ------------------
 2103|      0|        (*context->hashUpdate)(context->cipherInfo, pPart, UINT_MAX);
 2104|      0|        pPart += UINT_MAX;
 2105|      0|        ulPartLen -= UINT_MAX;
 2106|      0|    }
 2107|   529k|#endif
 2108|   529k|    (*context->hashUpdate)(context->cipherInfo, pPart, ulPartLen);
 2109|       |
 2110|   529k|    return CKR_OK;
  ------------------
  |  | 1388|   529k|#define CKR_OK 0x00000000UL
  ------------------
 2111|   529k|}
NSC_DigestFinal:
 2117|   267k|{
 2118|   267k|    SFTKSession *session;
 2119|   267k|    SFTKSessionContext *context;
 2120|   267k|    unsigned int maxout = *pulDigestLen;
 2121|   267k|    unsigned int digestLen;
 2122|   267k|    CK_RV crv;
 2123|       |
 2124|   267k|    CHECK_FORK();
 2125|       |
 2126|       |    /* make sure we're legal */
 2127|   267k|    crv = sftk_GetContext(hSession, &context, SFTK_HASH, PR_TRUE, &session);
  ------------------
  |  |  437|   267k|#define PR_TRUE 1
  ------------------
 2128|   267k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   267k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2128:9): [True: 25.5k, False: 242k]
  ------------------
 2129|  25.5k|        return crv;
 2130|       |
 2131|   242k|    if (pDigest != NULL) {
  ------------------
  |  Branch (2131:9): [True: 242k, False: 0]
  ------------------
 2132|   242k|        (*context->end)(context->cipherInfo, pDigest, &digestLen, maxout);
 2133|   242k|        *pulDigestLen = digestLen;
 2134|   242k|        sftk_TerminateOp(session, SFTK_HASH, context);
 2135|   242k|    } else {
 2136|      0|        *pulDigestLen = context->maxLen;
 2137|      0|    }
 2138|       |
 2139|   242k|    sftk_FreeSession(session);
 2140|   242k|    return CKR_OK;
  ------------------
  |  | 1388|   242k|#define CKR_OK 0x00000000UL
  ------------------
 2141|   267k|}
NSC_SignInit:
 2877|   212k|{
 2878|   212k|    SFTKSession *session;
 2879|   212k|    SFTKObject *key;
 2880|   212k|    SFTKSessionContext *context;
 2881|   212k|    CK_KEY_TYPE key_type;
 2882|   212k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   212k|#define CKR_OK 0x00000000UL
  ------------------
 2883|   212k|    NSSLOWKEYPrivateKey *privKey;
 2884|   212k|    SFTKHashSignInfo *info = NULL;
 2885|   212k|    SFTKPSSSignInfo *pinfo = NULL;
 2886|       |
 2887|   212k|    CHECK_FORK();
 2888|       |
 2889|       |    /* Block Cipher MACing Algorithms use a different Context init method..*/
 2890|   212k|    crv = sftk_InitCBCMac(hSession, pMechanism, hKey, CKA_SIGN, SFTK_SIGN);
  ------------------
  |  |  551|   212k|#define CKA_SIGN 0x00000108UL
  ------------------
 2891|   212k|    if (crv != CKR_FUNCTION_NOT_SUPPORTED)
  ------------------
  |  | 1426|   212k|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
  |  Branch (2891:9): [True: 0, False: 212k]
  ------------------
 2892|      0|        return crv;
 2893|       |
 2894|       |    /* we're not using a block cipher mac */
 2895|   212k|    session = sftk_SessionFromHandle(hSession);
 2896|   212k|    if (session == NULL)
  ------------------
  |  Branch (2896:9): [True: 0, False: 212k]
  ------------------
 2897|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 2898|   212k|    crv = sftk_InitGeneric(session, pMechanism, &context, SFTK_SIGN, &key,
 2899|   212k|                           hKey, &key_type, CKO_PRIVATE_KEY, CKA_SIGN);
  ------------------
  |  |  328|   212k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
                                         hKey, &key_type, CKO_PRIVATE_KEY, CKA_SIGN);
  ------------------
  |  |  551|   212k|#define CKA_SIGN 0x00000108UL
  ------------------
 2900|   212k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   212k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2900:9): [True: 0, False: 212k]
  ------------------
 2901|      0|        sftk_FreeSession(session);
 2902|      0|        return crv;
 2903|      0|    }
 2904|       |
 2905|   212k|    context->multi = PR_FALSE;
  ------------------
  |  |  438|   212k|#define PR_FALSE 0
  ------------------
 2906|       |
 2907|   212k|#define INIT_RSA_SIGN_MECH(mmm)             \
 2908|   212k|    case CKM_##mmm##_RSA_PKCS:              \
 2909|   212k|        context->multi = PR_TRUE;           \
 2910|   212k|        crv = sftk_doSub##mmm(context);     \
 2911|   212k|        if (crv != CKR_OK)                  \
 2912|   212k|            break;                          \
 2913|   212k|        context->update = sftk_RSAHashSign; \
 2914|   212k|        info = PORT_New(SFTKHashSignInfo);  \
 2915|   212k|        if (info == NULL) {                 \
 2916|   212k|            crv = CKR_HOST_MEMORY;          \
 2917|   212k|            break;                          \
 2918|   212k|        }                                   \
 2919|   212k|        info->hashOid = SEC_OID_##mmm;      \
 2920|   212k|        goto finish_rsa;
 2921|       |
 2922|   212k|    switch (pMechanism->mechanism) {
 2923|      0|        INIT_RSA_SIGN_MECH(MD5)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2924|      0|        INIT_RSA_SIGN_MECH(MD2)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2925|      0|        INIT_RSA_SIGN_MECH(SHA1)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2926|      0|        INIT_RSA_SIGN_MECH(SHA224)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2927|      0|        INIT_RSA_SIGN_MECH(SHA256)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2928|      0|        INIT_RSA_SIGN_MECH(SHA384)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2929|      0|        INIT_RSA_SIGN_MECH(SHA512)
  ------------------
  |  | 2908|      0|    case CKM_##mmm##_RSA_PKCS:              \
  |  |  ------------------
  |  |  |  Branch (2908:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2909|      0|        context->multi = PR_TRUE;           \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2910|      0|        crv = sftk_doSub##mmm(context);     \
  |  | 2911|      0|        if (crv != CKR_OK)                  \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2911:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2912|      0|            break;                          \
  |  | 2913|      0|        context->update = sftk_RSAHashSign; \
  |  | 2914|      0|        info = PORT_New(SFTKHashSignInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 2915|      0|        if (info == NULL) {                 \
  |  |  ------------------
  |  |  |  Branch (2915:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2916|      0|            crv = CKR_HOST_MEMORY;          \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 2917|      0|            break;                          \
  |  | 2918|      0|        }                                   \
  |  | 2919|      0|        info->hashOid = SEC_OID_##mmm;      \
  |  | 2920|      0|        goto finish_rsa;
  ------------------
 2930|       |
 2931|  30.7k|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|  30.7k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (2931:9): [True: 30.7k, False: 182k]
  ------------------
 2932|  30.7k|            context->update = sftk_RSASign;
 2933|  30.7k|            goto finish_rsa;
 2934|      0|        case CKM_RSA_X_509:
  ------------------
  |  |  722|      0|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (2934:9): [True: 0, False: 212k]
  ------------------
 2935|      0|            context->update = sftk_RSASignRaw;
 2936|  30.7k|        finish_rsa:
 2937|  30.7k|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|  30.7k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (2937:17): [True: 0, False: 30.7k]
  ------------------
 2938|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 2939|      0|                break;
 2940|      0|            }
 2941|  30.7k|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|  30.7k|#define PR_TRUE 1
  ------------------
 2942|  30.7k|            privKey = sftk_GetPrivKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|  30.7k|#define CKK_RSA 0x00000000UL
  ------------------
 2943|  30.7k|            if (privKey == NULL) {
  ------------------
  |  Branch (2943:17): [True: 0, False: 30.7k]
  ------------------
 2944|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 2945|      0|                break;
 2946|      0|            }
 2947|       |            /* OK, info is allocated only if we're doing hash and sign mechanism.
 2948|       |             * It's necessary to be able to set the correct OID in the final
 2949|       |             * signature.
 2950|       |             */
 2951|  30.7k|            if (info) {
  ------------------
  |  Branch (2951:17): [True: 0, False: 30.7k]
  ------------------
 2952|      0|                info->key = privKey;
 2953|      0|                context->cipherInfo = info;
 2954|      0|                context->destroy = sftk_Space;
 2955|  30.7k|            } else {
 2956|  30.7k|                context->cipherInfo = privKey;
 2957|  30.7k|                context->destroy = sftk_Null;
 2958|  30.7k|            }
 2959|  30.7k|            context->maxLen = nsslowkey_PrivateModulusLen(privKey);
 2960|  30.7k|            break;
 2961|       |
 2962|      0|#define INIT_RSA_PSS_SIG_MECH(mmm)                                                            \
 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
 2964|      0|        context->multi = PR_TRUE;                                                             \
 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
 2966|      0|        if (crv != CKR_OK)                                                                    \
 2967|      0|            break;                                                                            \
 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
 2970|      0|            break;                                                                            \
 2971|      0|        }                                                                                     \
 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
 2974|      0|            break;                                                                            \
 2975|      0|        }                                                                                     \
 2976|      0|        goto finish_rsa_pss;
 2977|      0|            INIT_RSA_PSS_SIG_MECH(SHA1)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 2978|      0|            INIT_RSA_PSS_SIG_MECH(SHA224)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 2979|      0|            INIT_RSA_PSS_SIG_MECH(SHA256)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 2980|      0|            INIT_RSA_PSS_SIG_MECH(SHA384)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 2981|      0|            INIT_RSA_PSS_SIG_MECH(SHA512)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 2982|  4.81k|        case CKM_RSA_PKCS_PSS:
  ------------------
  |  |  741|  4.81k|#define CKM_RSA_PKCS_PSS 0x0000000DUL
  ------------------
  |  Branch (2982:9): [True: 4.81k, False: 208k]
  ------------------
 2983|  4.81k|        finish_rsa_pss:
 2984|  4.81k|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|  4.81k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (2984:17): [True: 0, False: 4.81k]
  ------------------
 2985|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 2986|      0|                break;
 2987|      0|            }
 2988|  4.81k|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|  4.81k|#define PR_TRUE 1
  ------------------
 2989|  4.81k|            if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS) ||
  ------------------
  |  Branch (2989:17): [True: 0, False: 4.81k]
  ------------------
 2990|  4.81k|                !sftk_ValidatePssParams((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)) {
  ------------------
  |  Branch (2990:17): [True: 0, False: 4.81k]
  ------------------
 2991|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 2992|      0|                break;
 2993|      0|            }
 2994|  4.81k|            pinfo = PORT_New(SFTKPSSSignInfo);
  ------------------
  |  |  151|  4.81k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|  4.81k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 2995|  4.81k|            if (pinfo == NULL) {
  ------------------
  |  Branch (2995:17): [True: 0, False: 4.81k]
  ------------------
 2996|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2997|      0|                break;
 2998|      0|            }
 2999|  4.81k|            pinfo->size = sizeof(SFTKPSSSignInfo);
 3000|  4.81k|            pinfo->params = *(CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter;
 3001|  4.81k|            pinfo->key = sftk_GetPrivKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|  4.81k|#define CKK_RSA 0x00000000UL
  ------------------
 3002|  4.81k|            if (pinfo->key == NULL) {
  ------------------
  |  Branch (3002:17): [True: 0, False: 4.81k]
  ------------------
 3003|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3004|      0|                break;
 3005|      0|            }
 3006|  4.81k|            context->cipherInfo = pinfo;
 3007|  4.81k|            context->destroy = sftk_ZSpace;
 3008|  4.81k|            context->update = sftk_RSASignPSS;
 3009|  4.81k|            context->maxLen = nsslowkey_PrivateModulusLen(pinfo->key);
 3010|  4.81k|            break;
 3011|       |
 3012|      0|#define INIT_DSA_SIG_MECH(mmm)          \
 3013|      0|    case CKM_DSA_##mmm:                 \
 3014|      0|        context->multi = PR_TRUE;       \
 3015|      0|        crv = sftk_doSub##mmm(context); \
 3016|      0|        if (crv != CKR_OK)              \
 3017|      0|            break;                      \
 3018|      0|        goto finish_dsa;
 3019|      0|            INIT_DSA_SIG_MECH(SHA1)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3020|      0|            INIT_DSA_SIG_MECH(SHA224)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3021|      0|            INIT_DSA_SIG_MECH(SHA256)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3022|      0|            INIT_DSA_SIG_MECH(SHA384)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3023|      0|            INIT_DSA_SIG_MECH(SHA512)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3024|      0|        case CKM_DSA:
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (3024:9): [True: 0, False: 212k]
  ------------------
 3025|      0|        finish_dsa:
 3026|      0|            if (key_type != CKK_DSA) {
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (3026:17): [True: 0, False: 0]
  ------------------
 3027|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3028|      0|                break;
 3029|      0|            }
 3030|      0|            privKey = sftk_GetPrivKey(key, CKK_DSA, &crv);
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
 3031|      0|            if (privKey == NULL) {
  ------------------
  |  Branch (3031:17): [True: 0, False: 0]
  ------------------
 3032|      0|                break;
 3033|      0|            }
 3034|      0|            context->cipherInfo = privKey;
 3035|      0|            context->update = nsc_DSA_Sign_Stub;
 3036|      0|            context->destroy = (privKey == key->objectInfo) ? sftk_Null : sftk_FreePrivKey;
  ------------------
  |  Branch (3036:32): [True: 0, False: 0]
  ------------------
 3037|      0|            context->maxLen = DSA_MAX_SIGNATURE_LEN;
  ------------------
  |  |   52|      0|#define DSA_MAX_SIGNATURE_LEN (DSA_MAX_SUBPRIME_LEN * 2) /* Bytes */
  |  |  ------------------
  |  |  |  |   51|      0|#define DSA_MAX_SUBPRIME_LEN 32                          /* Bytes */
  |  |  ------------------
  ------------------
 3038|       |
 3039|      0|            break;
 3040|       |
 3041|      0|#define INIT_ECDSA_SIG_MECH(mmm)        \
 3042|      0|    case CKM_ECDSA_##mmm:               \
 3043|      0|        context->multi = PR_TRUE;       \
 3044|      0|        crv = sftk_doSub##mmm(context); \
 3045|      0|        if (crv != CKR_OK)              \
 3046|      0|            break;                      \
 3047|      0|        goto finish_ecdsa;
 3048|      0|            INIT_ECDSA_SIG_MECH(SHA1)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3049|      0|            INIT_ECDSA_SIG_MECH(SHA224)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3050|      0|            INIT_ECDSA_SIG_MECH(SHA256)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3051|      0|            INIT_ECDSA_SIG_MECH(SHA384)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3052|      0|            INIT_ECDSA_SIG_MECH(SHA512)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3053|  11.7k|        case CKM_ECDSA:
  ------------------
  |  | 1074|  11.7k|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (3053:9): [True: 11.7k, False: 201k]
  ------------------
 3054|  11.7k|        finish_ecdsa:
 3055|  11.7k|            if (key_type != CKK_EC) {
  ------------------
  |  |  379|  11.7k|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (3055:17): [True: 0, False: 11.7k]
  ------------------
 3056|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3057|      0|                break;
 3058|      0|            }
 3059|  11.7k|            privKey = sftk_GetPrivKey(key, CKK_EC, &crv);
  ------------------
  |  |  379|  11.7k|#define CKK_EC 0x00000003UL
  ------------------
 3060|  11.7k|            if (privKey == NULL) {
  ------------------
  |  Branch (3060:17): [True: 0, False: 11.7k]
  ------------------
 3061|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3062|      0|                break;
 3063|      0|            }
 3064|  11.7k|            context->cipherInfo = privKey;
 3065|  11.7k|            context->update = nsc_ECDSASignStub;
 3066|  11.7k|            context->destroy = (privKey == key->objectInfo) ? sftk_Null : sftk_FreePrivKey;
  ------------------
  |  Branch (3066:32): [True: 11.7k, False: 0]
  ------------------
 3067|  11.7k|            context->maxLen = MAX_ECKEY_LEN * 2;
  ------------------
  |  |   81|  11.7k|#define MAX_ECKEY_LEN 72 /* Bytes */
  ------------------
 3068|       |
 3069|  11.7k|            break;
 3070|       |
 3071|      0|        case CKM_EDDSA:
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
  |  Branch (3071:9): [True: 0, False: 212k]
  ------------------
 3072|      0|            if (key_type != CKK_EC_EDWARDS) {
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (3072:17): [True: 0, False: 0]
  ------------------
 3073|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3074|      0|                break;
 3075|      0|            }
 3076|       |
 3077|      0|            if (pMechanism->pParameter) {
  ------------------
  |  Branch (3077:17): [True: 0, False: 0]
  ------------------
 3078|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3079|      0|                break;
 3080|      0|            }
 3081|       |
 3082|      0|            privKey = sftk_GetPrivKey(key, CKK_EC_EDWARDS, &crv);
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
 3083|      0|            if (privKey == NULL) {
  ------------------
  |  Branch (3083:17): [True: 0, False: 0]
  ------------------
 3084|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3085|      0|                break;
 3086|      0|            }
 3087|      0|            context->cipherInfo = privKey;
 3088|      0|            context->update = nsc_EDDSASignStub;
 3089|      0|            context->destroy = (privKey == key->objectInfo) ? sftk_Null : sftk_FreePrivKey;
  ------------------
  |  Branch (3089:32): [True: 0, False: 0]
  ------------------
 3090|      0|            context->maxLen = MAX_ECKEY_LEN * 2;
  ------------------
  |  |   81|      0|#define MAX_ECKEY_LEN 72 /* Bytes */
  ------------------
 3091|       |
 3092|      0|            break;
 3093|       |
 3094|      0|#define INIT_HMAC_MECH(mmm)                                        \
 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
 3097|      0|        if (!pMechanism->pParameter) {                             \
 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
 3099|      0|            break;                                                 \
 3100|      0|        }                                                          \
 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
 3103|      0|        break;                                                     \
 3104|      0|    case CKM_##mmm##_HMAC:                                         \
 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
 3106|      0|                             mmm##_LENGTH);                        \
 3107|      0|        break;
 3108|       |
 3109|      0|            INIT_HMAC_MECH(MD2)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3110|      0|            INIT_HMAC_MECH(MD5)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|  4.87k|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 4.87k, False: 208k]
  |  |  ------------------
  |  | 3105|  4.87k|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|  4.87k|                             mmm##_LENGTH);                        \
  |  | 3107|  4.87k|        break;
  ------------------
 3111|      0|            INIT_HMAC_MECH(SHA1)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|  51.7k|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 51.7k, False: 161k]
  |  |  ------------------
  |  | 3105|  51.7k|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|  51.7k|                             mmm##_LENGTH);                        \
  |  | 3107|  51.7k|        break;
  ------------------
 3112|      0|            INIT_HMAC_MECH(SHA224)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3113|      0|            INIT_HMAC_MECH(SHA256)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|  2.22k|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 2.22k, False: 210k]
  |  |  ------------------
  |  | 3105|  2.22k|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|  2.22k|                             mmm##_LENGTH);                        \
  |  | 3107|  2.22k|        break;
  ------------------
 3114|      0|            INIT_HMAC_MECH(SHA384)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|  1.62k|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 1.62k, False: 211k]
  |  |  ------------------
  |  | 3105|  1.62k|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|  1.62k|                             mmm##_LENGTH);                        \
  |  | 3107|  1.62k|        break;
  ------------------
 3115|      0|            INIT_HMAC_MECH(SHA512)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3116|      0|            INIT_HMAC_MECH(SHA3_224)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3117|      0|            INIT_HMAC_MECH(SHA3_256)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3118|      0|            INIT_HMAC_MECH(SHA3_384)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3119|      0|            INIT_HMAC_MECH(SHA3_512)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 212k]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3120|       |
 3121|      0|        case CKM_AES_CMAC_GENERAL:
  ------------------
  |  | 1120|      0|#define CKM_AES_CMAC_GENERAL 0x0000108BUL
  ------------------
  |  Branch (3121:9): [True: 0, False: 212k]
  ------------------
 3122|      0|            PORT_Assert(pMechanism->pParameter);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3123|      0|            if (!pMechanism->pParameter || pMechanism->ulParameterLen != sizeof(CK_MAC_GENERAL_PARAMS)) {
  ------------------
  |  Branch (3123:17): [True: 0, False: 0]
  |  Branch (3123:44): [True: 0, False: 0]
  ------------------
 3124|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3125|      0|                break;
 3126|      0|            }
 3127|      0|            crv = sftk_doMACInit(pMechanism->mechanism, context, key, *(CK_ULONG *)pMechanism->pParameter);
 3128|      0|            break;
 3129|      0|        case CKM_AES_CMAC:
  ------------------
  |  | 1119|      0|#define CKM_AES_CMAC 0x0000108AUL
  ------------------
  |  Branch (3129:9): [True: 0, False: 212k]
  ------------------
 3130|      0|            crv = sftk_doMACInit(pMechanism->mechanism, context, key, AES_BLOCK_SIZE);
  ------------------
  |  |  130|      0|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
 3131|      0|            break;
 3132|      0|        case CKM_SSL3_MD5_MAC:
  ------------------
  |  |  975|      0|#define CKM_SSL3_MD5_MAC 0x00000380UL
  ------------------
  |  Branch (3132:9): [True: 0, False: 212k]
  ------------------
 3133|      0|            PORT_Assert(pMechanism->pParameter);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3134|      0|            if (!pMechanism->pParameter) {
  ------------------
  |  Branch (3134:17): [True: 0, False: 0]
  ------------------
 3135|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3136|      0|                break;
 3137|      0|            }
 3138|      0|            crv = sftk_doSSLMACInit(context, SEC_OID_MD5, key,
 3139|      0|                                    *(CK_ULONG *)pMechanism->pParameter);
 3140|      0|            break;
 3141|      0|        case CKM_SSL3_SHA1_MAC:
  ------------------
  |  |  976|      0|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
  |  Branch (3141:9): [True: 0, False: 212k]
  ------------------
 3142|      0|            PORT_Assert(pMechanism->pParameter);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3143|      0|            if (!pMechanism->pParameter) {
  ------------------
  |  Branch (3143:17): [True: 0, False: 0]
  ------------------
 3144|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3145|      0|                break;
 3146|      0|            }
 3147|      0|            crv = sftk_doSSLMACInit(context, SEC_OID_SHA1, key,
 3148|      0|                                    *(CK_ULONG *)pMechanism->pParameter);
 3149|      0|            break;
 3150|      0|        case CKM_TLS_PRF_GENERAL:
  ------------------
  |  |  297|      0|#define CKM_TLS_PRF_GENERAL 0x80000373UL
  ------------------
  |  Branch (3150:9): [True: 0, False: 212k]
  ------------------
 3151|      0|            crv = sftk_TLSPRFInit(context, key, key_type, HASH_AlgNULL, 0);
 3152|      0|            break;
 3153|   105k|        case CKM_TLS_MAC: {
  ------------------
  |  | 1032|   105k|#define CKM_TLS_MAC 0x000003E4UL
  ------------------
  |  Branch (3153:9): [True: 105k, False: 107k]
  ------------------
 3154|   105k|            CK_TLS_MAC_PARAMS *tls12_mac_params;
 3155|   105k|            HASH_HashType tlsPrfHash;
 3156|   105k|            const char *label;
 3157|       |
 3158|   105k|            if (pMechanism->ulParameterLen != sizeof(CK_TLS_MAC_PARAMS)) {
  ------------------
  |  Branch (3158:17): [True: 0, False: 105k]
  ------------------
 3159|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3160|      0|                break;
 3161|      0|            }
 3162|   105k|            tls12_mac_params = (CK_TLS_MAC_PARAMS *)pMechanism->pParameter;
 3163|   105k|            if (tls12_mac_params->prfHashMechanism == CKM_TLS_PRF) {
  ------------------
  |  |  973|   105k|#define CKM_TLS_PRF 0x00000378UL
  ------------------
  |  Branch (3163:17): [True: 12.0k, False: 93.0k]
  ------------------
 3164|       |                /* The TLS 1.0 and 1.1 PRF */
 3165|  12.0k|                tlsPrfHash = HASH_AlgNULL;
 3166|  12.0k|                if (tls12_mac_params->ulMacLength != 12) {
  ------------------
  |  Branch (3166:21): [True: 0, False: 12.0k]
  ------------------
 3167|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3168|      0|                    break;
 3169|      0|                }
 3170|  93.0k|            } else {
 3171|       |                /* The hash function for the TLS 1.2 PRF */
 3172|  93.0k|                tlsPrfHash =
 3173|  93.0k|                    sftk_GetHashTypeFromMechanism(tls12_mac_params->prfHashMechanism);
 3174|  93.0k|                if (tlsPrfHash == HASH_AlgNULL ||
  ------------------
  |  Branch (3174:21): [True: 0, False: 93.0k]
  ------------------
 3175|  93.0k|                    tls12_mac_params->ulMacLength < 12) {
  ------------------
  |  Branch (3175:21): [True: 0, False: 93.0k]
  ------------------
 3176|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3177|      0|                    break;
 3178|      0|                }
 3179|  93.0k|            }
 3180|   105k|            if (tls12_mac_params->ulServerOrClient == 1) {
  ------------------
  |  Branch (3180:17): [True: 52.5k, False: 52.5k]
  ------------------
 3181|  52.5k|                label = "server finished";
 3182|  52.5k|            } else if (tls12_mac_params->ulServerOrClient == 2) {
  ------------------
  |  Branch (3182:24): [True: 52.5k, False: 0]
  ------------------
 3183|  52.5k|                label = "client finished";
 3184|  52.5k|            } else {
 3185|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3186|      0|                break;
 3187|      0|            }
 3188|   105k|            crv = sftk_TLSPRFInit(context, key, key_type, tlsPrfHash,
 3189|   105k|                                  tls12_mac_params->ulMacLength);
 3190|   105k|            if (crv == CKR_OK) {
  ------------------
  |  | 1388|   105k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3190:17): [True: 105k, False: 0]
  ------------------
 3191|   105k|                context->hashUpdate(context->hashInfo, (unsigned char *)label, 15);
 3192|   105k|            }
 3193|   105k|            break;
 3194|   105k|        }
 3195|      0|        case CKM_NSS_TLS_PRF_GENERAL_SHA256:
  ------------------
  |  |  233|      0|#define CKM_NSS_TLS_PRF_GENERAL_SHA256 (CKM_NSS + 21)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (3195:9): [True: 0, False: 212k]
  ------------------
 3196|      0|            crv = sftk_TLSPRFInit(context, key, key_type, HASH_AlgSHA256, 0);
 3197|      0|            break;
 3198|       |
 3199|      0|        case CKM_NSS_HMAC_CONSTANT_TIME: {
  ------------------
  |  |  229|      0|#define CKM_NSS_HMAC_CONSTANT_TIME (CKM_NSS + 19)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (3199:9): [True: 0, False: 212k]
  ------------------
 3200|      0|            sftk_MACConstantTimeCtx *ctx =
 3201|      0|                sftk_HMACConstantTime_New(pMechanism, key);
 3202|      0|            CK_ULONG *intpointer;
 3203|       |
 3204|      0|            if (ctx == NULL) {
  ------------------
  |  Branch (3204:17): [True: 0, False: 0]
  ------------------
 3205|      0|                crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 3206|      0|                break;
 3207|      0|            }
 3208|      0|            intpointer = PORT_New(CK_ULONG);
  ------------------
  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 3209|      0|            if (intpointer == NULL) {
  ------------------
  |  Branch (3209:17): [True: 0, False: 0]
  ------------------
 3210|      0|                PORT_Free(ctx);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3211|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3212|      0|                break;
 3213|      0|            }
 3214|      0|            *intpointer = ctx->hash->length;
 3215|       |
 3216|      0|            context->cipherInfo = intpointer;
 3217|      0|            context->hashInfo = ctx;
 3218|      0|            context->currentMech = pMechanism->mechanism;
 3219|      0|            context->hashUpdate = sftk_HMACConstantTime_Update;
 3220|      0|            context->hashdestroy = sftk_MACConstantTime_DestroyContext;
 3221|      0|            context->end = sftk_MACConstantTime_EndHash;
 3222|      0|            context->update = sftk_SignCopy;
 3223|      0|            context->destroy = sftk_Space;
 3224|      0|            context->maxLen = 64;
 3225|      0|            context->multi = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3226|      0|            break;
 3227|      0|        }
 3228|       |
 3229|      0|        case CKM_NSS_SSL3_MAC_CONSTANT_TIME: {
  ------------------
  |  |  230|      0|#define CKM_NSS_SSL3_MAC_CONSTANT_TIME (CKM_NSS + 20)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (3229:9): [True: 0, False: 212k]
  ------------------
 3230|      0|            sftk_MACConstantTimeCtx *ctx =
 3231|      0|                sftk_SSLv3MACConstantTime_New(pMechanism, key);
 3232|      0|            CK_ULONG *intpointer;
 3233|       |
 3234|      0|            if (ctx == NULL) {
  ------------------
  |  Branch (3234:17): [True: 0, False: 0]
  ------------------
 3235|      0|                crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 3236|      0|                break;
 3237|      0|            }
 3238|      0|            intpointer = PORT_New(CK_ULONG);
  ------------------
  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 3239|      0|            if (intpointer == NULL) {
  ------------------
  |  Branch (3239:17): [True: 0, False: 0]
  ------------------
 3240|      0|                PORT_Free(ctx);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3241|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3242|      0|                break;
 3243|      0|            }
 3244|      0|            *intpointer = ctx->hash->length;
 3245|       |
 3246|      0|            context->cipherInfo = intpointer;
 3247|      0|            context->hashInfo = ctx;
 3248|      0|            context->currentMech = pMechanism->mechanism;
 3249|      0|            context->hashUpdate = sftk_SSLv3MACConstantTime_Update;
 3250|      0|            context->hashdestroy = sftk_MACConstantTime_DestroyContext;
 3251|      0|            context->end = sftk_MACConstantTime_EndHash;
 3252|      0|            context->update = sftk_SignCopy;
 3253|      0|            context->destroy = sftk_Space;
 3254|      0|            context->maxLen = 64;
 3255|      0|            context->multi = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3256|      0|            break;
 3257|      0|        }
 3258|       |
 3259|      0|        default:
  ------------------
  |  Branch (3259:9): [True: 0, False: 212k]
  ------------------
 3260|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 3261|      0|            break;
 3262|   212k|    }
 3263|       |
 3264|   212k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   212k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3264:9): [True: 0, False: 212k]
  ------------------
 3265|      0|        if (info)
  ------------------
  |  Branch (3265:13): [True: 0, False: 0]
  ------------------
 3266|      0|            PORT_Free(info);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3267|      0|        if (pinfo)
  ------------------
  |  Branch (3267:13): [True: 0, False: 0]
  ------------------
 3268|      0|            PORT_ZFree(pinfo, pinfo->size);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 3269|      0|        sftk_FreeContext(context);
 3270|      0|        sftk_FreeSession(session);
 3271|      0|        return crv;
 3272|      0|    }
 3273|   212k|    sftk_SetContextByType(session, SFTK_SIGN, context);
 3274|   212k|    sftk_FreeSession(session);
 3275|   212k|    return CKR_OK;
  ------------------
  |  | 1388|   212k|#define CKR_OK 0x00000000UL
  ------------------
 3276|   212k|}
NSC_SignUpdate:
 3394|   106k|{
 3395|   106k|    CHECK_FORK();
 3396|   106k|    return sftk_MACUpdate(hSession, pPart, ulPartLen, SFTK_SIGN);
 3397|   106k|}
NSC_SignFinal:
 3460|   106k|{
 3461|   106k|    SFTKSession *session;
 3462|   106k|    SFTKSessionContext *context;
 3463|   106k|    unsigned int outlen;
 3464|   106k|    unsigned int maxoutlen = *pulSignatureLen;
 3465|   106k|    CK_RV crv;
 3466|       |
 3467|   106k|    CHECK_FORK();
 3468|       |
 3469|       |    /* make sure we're legal */
 3470|   106k|    crv = sftk_GetContext(hSession, &context, SFTK_SIGN, PR_TRUE, &session);
  ------------------
  |  |  437|   106k|#define PR_TRUE 1
  ------------------
 3471|   106k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   106k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3471:9): [True: 0, False: 106k]
  ------------------
 3472|      0|        return crv;
 3473|       |
 3474|   106k|    if (context->hashInfo) {
  ------------------
  |  Branch (3474:9): [True: 106k, False: 0]
  ------------------
 3475|   106k|        unsigned int digestLen;
 3476|   106k|        unsigned char tmpbuf[SFTK_MAX_MAC_LENGTH];
 3477|       |
 3478|   106k|        if (!pSignature) {
  ------------------
  |  Branch (3478:13): [True: 0, False: 106k]
  ------------------
 3479|      0|            outlen = context->maxLen;
 3480|      0|            goto finish;
 3481|      0|        }
 3482|   106k|        (*context->end)(context->hashInfo, tmpbuf, &digestLen, sizeof(tmpbuf));
 3483|   106k|        if (SECSuccess != (context->update)(context->cipherInfo, pSignature,
  ------------------
  |  Branch (3483:13): [True: 0, False: 106k]
  ------------------
 3484|   106k|                                            &outlen, maxoutlen, tmpbuf, digestLen))
 3485|      0|            crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 3486|       |        /* CKR_BUFFER_TOO_SMALL here isn't continuable, let operation terminate.
 3487|       |         * Keeping "too small" CK_RV intact is a standard violation, but allows
 3488|       |         * application read EXACT signature length */
 3489|   106k|        PORT_Memset(tmpbuf, 0, sizeof tmpbuf);
  ------------------
  |  |  182|   106k|#define PORT_Memset memset
  ------------------
 3490|   106k|    } else {
 3491|       |        /* must be block cipher MACing */
 3492|      0|        outlen = context->macSize;
 3493|       |        /* null or "too small" buf doesn't terminate operation [PKCS#11,v2.11]*/
 3494|      0|        if (!pSignature || maxoutlen < outlen) {
  ------------------
  |  Branch (3494:13): [True: 0, False: 0]
  |  Branch (3494:28): [True: 0, False: 0]
  ------------------
 3495|      0|            if (pSignature)
  ------------------
  |  Branch (3495:17): [True: 0, False: 0]
  ------------------
 3496|      0|                crv = CKR_BUFFER_TOO_SMALL;
  ------------------
  |  | 1514|      0|#define CKR_BUFFER_TOO_SMALL 0x00000150UL
  ------------------
 3497|      0|            goto finish;
 3498|      0|        }
 3499|      0|        if (CKR_OK == (crv = sftk_MACFinal(context)))
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3499:13): [True: 0, False: 0]
  ------------------
 3500|      0|            PORT_Memcpy(pSignature, context->macBuf, outlen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 3501|      0|    }
 3502|       |
 3503|   106k|    sftk_TerminateOp(session, SFTK_SIGN, context);
 3504|   106k|finish:
 3505|   106k|    *pulSignatureLen = outlen;
 3506|   106k|    sftk_FreeSession(session);
 3507|   106k|    return crv;
 3508|   106k|}
NSC_Sign:
 3517|  47.3k|{
 3518|  47.3k|    SFTKSession *session;
 3519|  47.3k|    SFTKSessionContext *context;
 3520|  47.3k|    CK_RV crv;
 3521|       |
 3522|  47.3k|    CHECK_FORK();
 3523|       |
 3524|       |    /* make sure we're legal */
 3525|  47.3k|    crv = sftk_GetContext(hSession, &context, SFTK_SIGN, PR_FALSE, &session);
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 3526|  47.3k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3526:9): [True: 0, False: 47.3k]
  ------------------
 3527|      0|        return crv;
 3528|       |
 3529|  47.3k|    if (!pSignature) {
  ------------------
  |  Branch (3529:9): [True: 0, False: 47.3k]
  ------------------
 3530|       |        /* see also how C_SignUpdate implements this */
 3531|      0|        *pulSignatureLen = (!context->multi || context->hashInfo)
  ------------------
  |  Branch (3531:29): [True: 0, False: 0]
  |  Branch (3531:48): [True: 0, False: 0]
  ------------------
 3532|      0|                               ? context->maxLen
 3533|      0|                               : context->macSize; /* must be block cipher MACing */
 3534|      0|        goto finish;
 3535|      0|    }
 3536|       |
 3537|       |    /* multi part Signing are completely implemented by SignUpdate and
 3538|       |     * sign Final */
 3539|  47.3k|    if (context->multi) {
  ------------------
  |  Branch (3539:9): [True: 0, False: 47.3k]
  ------------------
 3540|       |        /* SignFinal can't follow failed SignUpdate */
 3541|      0|        if (CKR_OK == (crv = NSC_SignUpdate(hSession, pData, ulDataLen)))
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3541:13): [True: 0, False: 0]
  ------------------
 3542|      0|            crv = NSC_SignFinal(hSession, pSignature, pulSignatureLen);
 3543|  47.3k|    } else {
 3544|       |        /* single-part PKC signature (e.g. CKM_ECDSA) */
 3545|  47.3k|        unsigned int outlen;
 3546|  47.3k|        unsigned int maxoutlen = *pulSignatureLen;
 3547|  47.3k|        if (SECSuccess != (*context->update)(context->cipherInfo, pSignature,
  ------------------
  |  Branch (3547:13): [True: 0, False: 47.3k]
  ------------------
 3548|  47.3k|                                             &outlen, maxoutlen, pData, ulDataLen))
 3549|      0|            crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 3550|  47.3k|        *pulSignatureLen = (CK_ULONG)outlen;
 3551|       |        /*  "too small" here is certainly continuable */
 3552|  47.3k|        if (crv != CKR_BUFFER_TOO_SMALL)
  ------------------
  |  | 1514|  47.3k|#define CKR_BUFFER_TOO_SMALL 0x00000150UL
  ------------------
  |  Branch (3552:13): [True: 47.3k, False: 0]
  ------------------
 3553|  47.3k|            sftk_TerminateOp(session, SFTK_SIGN, context);
 3554|  47.3k|    } /* single-part */
 3555|       |
 3556|  47.3k|finish:
 3557|  47.3k|    sftk_FreeSession(session);
 3558|  47.3k|    return crv;
 3559|  47.3k|}
NSC_VerifyInit:
 3715|     60|{
 3716|     60|    SFTKSession *session;
 3717|     60|    SFTKObject *key;
 3718|     60|    SFTKSessionContext *context;
 3719|     60|    CK_KEY_TYPE key_type;
 3720|     60|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
 3721|     60|    NSSLOWKEYPublicKey *pubKey;
 3722|     60|    SFTKHashVerifyInfo *info = NULL;
 3723|     60|    SFTKPSSVerifyInfo *pinfo = NULL;
 3724|       |
 3725|     60|    CHECK_FORK();
 3726|       |
 3727|       |    /* Block Cipher MACing Algorithms use a different Context init method..*/
 3728|     60|    crv = sftk_InitCBCMac(hSession, pMechanism, hKey, CKA_VERIFY, SFTK_VERIFY);
  ------------------
  |  |  553|     60|#define CKA_VERIFY 0x0000010AUL
  ------------------
 3729|     60|    if (crv != CKR_FUNCTION_NOT_SUPPORTED)
  ------------------
  |  | 1426|     60|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
  |  Branch (3729:9): [True: 0, False: 60]
  ------------------
 3730|      0|        return crv;
 3731|       |
 3732|     60|    session = sftk_SessionFromHandle(hSession);
 3733|     60|    if (session == NULL)
  ------------------
  |  Branch (3733:9): [True: 0, False: 60]
  ------------------
 3734|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 3735|     60|    crv = sftk_InitGeneric(session, pMechanism, &context, SFTK_VERIFY, &key,
 3736|     60|                           hKey, &key_type, CKO_PUBLIC_KEY, CKA_VERIFY);
  ------------------
  |  |  327|     60|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
                                         hKey, &key_type, CKO_PUBLIC_KEY, CKA_VERIFY);
  ------------------
  |  |  553|     60|#define CKA_VERIFY 0x0000010AUL
  ------------------
 3737|     60|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3737:9): [True: 0, False: 60]
  ------------------
 3738|      0|        sftk_FreeSession(session);
 3739|      0|        return crv;
 3740|      0|    }
 3741|       |
 3742|     60|    context->multi = PR_FALSE;
  ------------------
  |  |  438|     60|#define PR_FALSE 0
  ------------------
 3743|       |
 3744|     60|#define INIT_RSA_VFY_MECH(mmm)                \
 3745|     60|    case CKM_##mmm##_RSA_PKCS:                \
 3746|     60|        context->multi = PR_TRUE;             \
 3747|     60|        crv = sftk_doSub##mmm(context);       \
 3748|     60|        if (crv != CKR_OK)                    \
 3749|     60|            break;                            \
 3750|     60|        context->verify = sftk_hashCheckSign; \
 3751|     60|        info = PORT_New(SFTKHashVerifyInfo);  \
 3752|     60|        if (info == NULL) {                   \
 3753|     60|            crv = CKR_HOST_MEMORY;            \
 3754|     60|            break;                            \
 3755|     60|        }                                     \
 3756|     60|        info->hashOid = SEC_OID_##mmm;        \
 3757|     60|        goto finish_rsa;
 3758|       |
 3759|     60|    switch (pMechanism->mechanism) {
 3760|      0|        INIT_RSA_VFY_MECH(MD5)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3761|      0|        INIT_RSA_VFY_MECH(MD2)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3762|      0|        INIT_RSA_VFY_MECH(SHA1)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3763|      0|        INIT_RSA_VFY_MECH(SHA224)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3764|      0|        INIT_RSA_VFY_MECH(SHA256)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3765|      0|        INIT_RSA_VFY_MECH(SHA384)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3766|      0|        INIT_RSA_VFY_MECH(SHA512)
  ------------------
  |  | 3745|      0|    case CKM_##mmm##_RSA_PKCS:                \
  |  |  ------------------
  |  |  |  Branch (3745:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3746|      0|        context->multi = PR_TRUE;             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3747|      0|        crv = sftk_doSub##mmm(context);       \
  |  | 3748|      0|        if (crv != CKR_OK)                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3748:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3749|      0|            break;                            \
  |  | 3750|      0|        context->verify = sftk_hashCheckSign; \
  |  | 3751|      0|        info = PORT_New(SFTKHashVerifyInfo);  \
  |  |  ------------------
  |  |  |  |  151|      0|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  |  |  ------------------
  |  |  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3752|      0|        if (info == NULL) {                   \
  |  |  ------------------
  |  |  |  Branch (3752:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3753|      0|            crv = CKR_HOST_MEMORY;            \
  |  |  ------------------
  |  |  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  |  |  ------------------
  |  | 3754|      0|            break;                            \
  |  | 3755|      0|        }                                     \
  |  | 3756|      0|        info->hashOid = SEC_OID_##mmm;        \
  |  | 3757|      0|        goto finish_rsa;
  ------------------
 3767|       |
 3768|     22|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|     22|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (3768:9): [True: 22, False: 38]
  ------------------
 3769|     22|            context->verify = sftk_RSACheckSign;
 3770|     22|            goto finish_rsa;
 3771|      0|        case CKM_RSA_X_509:
  ------------------
  |  |  722|      0|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (3771:9): [True: 0, False: 60]
  ------------------
 3772|      0|            context->verify = sftk_RSACheckSignRaw;
 3773|     22|        finish_rsa:
 3774|     22|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|     22|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (3774:17): [True: 0, False: 22]
  ------------------
 3775|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3776|      0|                break;
 3777|      0|            }
 3778|     22|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|     22|#define PR_TRUE 1
  ------------------
 3779|     22|            pubKey = sftk_GetPubKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|     22|#define CKK_RSA 0x00000000UL
  ------------------
 3780|     22|            if (pubKey == NULL) {
  ------------------
  |  Branch (3780:17): [True: 0, False: 22]
  ------------------
 3781|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3782|      0|                break;
 3783|      0|            }
 3784|     22|            if (info) {
  ------------------
  |  Branch (3784:17): [True: 0, False: 22]
  ------------------
 3785|      0|                info->key = pubKey;
 3786|      0|                context->cipherInfo = info;
 3787|      0|                context->destroy = sftk_Space;
 3788|     22|            } else {
 3789|     22|                context->cipherInfo = pubKey;
 3790|     22|                context->destroy = sftk_Null;
 3791|     22|            }
 3792|     22|            break;
 3793|       |
 3794|      0|            INIT_RSA_PSS_SIG_MECH(SHA1)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 3795|      0|            INIT_RSA_PSS_SIG_MECH(SHA224)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 3796|      0|            INIT_RSA_PSS_SIG_MECH(SHA256)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 3797|      0|            INIT_RSA_PSS_SIG_MECH(SHA384)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 3798|      0|            INIT_RSA_PSS_SIG_MECH(SHA512)
  ------------------
  |  | 2963|      0|    case CKM_##mmm##_RSA_PKCS_PSS:                                                            \
  |  |  ------------------
  |  |  |  Branch (2963:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 2964|      0|        context->multi = PR_TRUE;                                                             \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 2965|      0|        crv = sftk_doSub##mmm(context);                                                       \
  |  | 2966|      0|        if (crv != CKR_OK)                                                                    \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (2966:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2967|      0|            break;                                                                            \
  |  | 2968|      0|        if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS)) {                   \
  |  |  ------------------
  |  |  |  Branch (2968:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2969|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2970|      0|            break;                                                                            \
  |  | 2971|      0|        }                                                                                     \
  |  | 2972|      0|        if (((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)->hashAlg != CKM_##mmm) { \
  |  |  ------------------
  |  |  |  Branch (2972:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 2973|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                                                \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 2974|      0|            break;                                                                            \
  |  | 2975|      0|        }                                                                                     \
  |  | 2976|      0|        goto finish_rsa_pss;
  ------------------
 3799|     38|        case CKM_RSA_PKCS_PSS:
  ------------------
  |  |  741|     38|#define CKM_RSA_PKCS_PSS 0x0000000DUL
  ------------------
  |  Branch (3799:9): [True: 38, False: 22]
  ------------------
 3800|     38|        finish_rsa_pss:
 3801|     38|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|     38|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (3801:17): [True: 0, False: 38]
  ------------------
 3802|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3803|      0|                break;
 3804|      0|            }
 3805|     38|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|     38|#define PR_TRUE 1
  ------------------
 3806|     38|            if (pMechanism->ulParameterLen != sizeof(CK_RSA_PKCS_PSS_PARAMS) ||
  ------------------
  |  Branch (3806:17): [True: 0, False: 38]
  ------------------
 3807|     38|                !sftk_ValidatePssParams((const CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter)) {
  ------------------
  |  Branch (3807:17): [True: 0, False: 38]
  ------------------
 3808|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3809|      0|                break;
 3810|      0|            }
 3811|     38|            pinfo = PORT_New(SFTKPSSVerifyInfo);
  ------------------
  |  |  151|     38|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|     38|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 3812|     38|            if (pinfo == NULL) {
  ------------------
  |  Branch (3812:17): [True: 0, False: 38]
  ------------------
 3813|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3814|      0|                break;
 3815|      0|            }
 3816|     38|            pinfo->size = sizeof(SFTKPSSVerifyInfo);
 3817|     38|            pinfo->params = *(CK_RSA_PKCS_PSS_PARAMS *)pMechanism->pParameter;
 3818|     38|            pinfo->key = sftk_GetPubKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|     38|#define CKK_RSA 0x00000000UL
  ------------------
 3819|     38|            if (pinfo->key == NULL) {
  ------------------
  |  Branch (3819:17): [True: 0, False: 38]
  ------------------
 3820|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3821|      0|                break;
 3822|      0|            }
 3823|     38|            context->cipherInfo = pinfo;
 3824|     38|            context->destroy = sftk_ZSpace;
 3825|     38|            context->verify = sftk_RSACheckSignPSS;
 3826|     38|            break;
 3827|       |
 3828|      0|            INIT_DSA_SIG_MECH(SHA1)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3829|      0|            INIT_DSA_SIG_MECH(SHA224)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3830|      0|            INIT_DSA_SIG_MECH(SHA256)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3831|      0|            INIT_DSA_SIG_MECH(SHA384)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3832|      0|            INIT_DSA_SIG_MECH(SHA512)
  ------------------
  |  | 3013|      0|    case CKM_DSA_##mmm:                 \
  |  |  ------------------
  |  |  |  Branch (3013:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3014|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3015|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3016|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3016:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3017|      0|            break;                      \
  |  | 3018|      0|        goto finish_dsa;
  ------------------
 3833|      0|        case CKM_DSA:
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
  |  Branch (3833:9): [True: 0, False: 60]
  ------------------
 3834|      0|        finish_dsa:
 3835|      0|            if (key_type != CKK_DSA) {
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (3835:17): [True: 0, False: 0]
  ------------------
 3836|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3837|      0|                break;
 3838|      0|            }
 3839|      0|            pubKey = sftk_GetPubKey(key, CKK_DSA, &crv);
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
 3840|      0|            if (pubKey == NULL) {
  ------------------
  |  Branch (3840:17): [True: 0, False: 0]
  ------------------
 3841|      0|                break;
 3842|      0|            }
 3843|      0|            context->cipherInfo = pubKey;
 3844|      0|            context->verify = nsc_DSA_Verify_Stub;
 3845|      0|            context->destroy = sftk_Null;
 3846|      0|            break;
 3847|       |
 3848|      0|            INIT_ECDSA_SIG_MECH(SHA1)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3849|      0|            INIT_ECDSA_SIG_MECH(SHA224)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3850|      0|            INIT_ECDSA_SIG_MECH(SHA256)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3851|      0|            INIT_ECDSA_SIG_MECH(SHA384)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3852|      0|            INIT_ECDSA_SIG_MECH(SHA512)
  ------------------
  |  | 3042|      0|    case CKM_ECDSA_##mmm:               \
  |  |  ------------------
  |  |  |  Branch (3042:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3043|      0|        context->multi = PR_TRUE;       \
  |  |  ------------------
  |  |  |  |  437|      0|#define PR_TRUE 1
  |  |  ------------------
  |  | 3044|      0|        crv = sftk_doSub##mmm(context); \
  |  | 3045|      0|        if (crv != CKR_OK)              \
  |  |  ------------------
  |  |  |  | 1388|      0|#define CKR_OK 0x00000000UL
  |  |  ------------------
  |  |  |  Branch (3045:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3046|      0|            break;                      \
  |  | 3047|      0|        goto finish_ecdsa;
  ------------------
 3853|      0|        case CKM_ECDSA:
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
  |  Branch (3853:9): [True: 0, False: 60]
  ------------------
 3854|      0|        finish_ecdsa:
 3855|      0|            if (key_type != CKK_EC) {
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (3855:17): [True: 0, False: 0]
  ------------------
 3856|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3857|      0|                break;
 3858|      0|            }
 3859|      0|            pubKey = sftk_GetPubKey(key, CKK_EC, &crv);
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
 3860|      0|            if (pubKey == NULL) {
  ------------------
  |  Branch (3860:17): [True: 0, False: 0]
  ------------------
 3861|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3862|      0|                break;
 3863|      0|            }
 3864|      0|            context->cipherInfo = pubKey;
 3865|      0|            context->verify = nsc_ECDSAVerifyStub;
 3866|      0|            context->destroy = sftk_Null;
 3867|      0|            break;
 3868|       |
 3869|      0|            INIT_HMAC_MECH(MD2)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3870|      0|            INIT_HMAC_MECH(MD5)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3871|      0|            INIT_HMAC_MECH(SHA1)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3872|      0|            INIT_HMAC_MECH(SHA224)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3873|      0|            INIT_HMAC_MECH(SHA256)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3874|      0|            INIT_HMAC_MECH(SHA384)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3875|      0|            INIT_HMAC_MECH(SHA512)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3876|      0|            INIT_HMAC_MECH(SHA3_224)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3877|      0|            INIT_HMAC_MECH(SHA3_256)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3878|      0|            INIT_HMAC_MECH(SHA3_384)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3879|      0|            INIT_HMAC_MECH(SHA3_512)
  ------------------
  |  | 3095|      0|    case CKM_##mmm##_HMAC_GENERAL:                                 \
  |  |  ------------------
  |  |  |  Branch (3095:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3096|      0|        PORT_Assert(pMechanism->pParameter);                       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 3097|      0|        if (!pMechanism->pParameter) {                             \
  |  |  ------------------
  |  |  |  Branch (3097:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 3098|      0|            crv = CKR_MECHANISM_PARAM_INVALID;                     \
  |  |  ------------------
  |  |  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  |  |  ------------------
  |  | 3099|      0|            break;                                                 \
  |  | 3100|      0|        }                                                          \
  |  | 3101|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3102|      0|                             *(CK_ULONG *)pMechanism->pParameter); \
  |  | 3103|      0|        break;                                                     \
  |  | 3104|      0|    case CKM_##mmm##_HMAC:                                         \
  |  |  ------------------
  |  |  |  Branch (3104:5): [True: 0, False: 60]
  |  |  ------------------
  |  | 3105|      0|        crv = sftk_doMACInit(pMechanism->mechanism, context, key,  \
  |  | 3106|      0|                             mmm##_LENGTH);                        \
  |  | 3107|      0|        break;
  ------------------
 3880|       |
 3881|      0|        case CKM_EDDSA:
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
  |  Branch (3881:9): [True: 0, False: 60]
  ------------------
 3882|      0|            if (key_type != CKK_EC_EDWARDS) {
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (3882:17): [True: 0, False: 0]
  ------------------
 3883|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 3884|      0|                break;
 3885|      0|            }
 3886|      0|            pubKey = sftk_GetPubKey(key, CKK_EC_EDWARDS, &crv);
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
 3887|      0|            if (pubKey == NULL) {
  ------------------
  |  Branch (3887:17): [True: 0, False: 0]
  ------------------
 3888|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 3889|      0|                break;
 3890|      0|            }
 3891|       |
 3892|      0|            if (pMechanism->pParameter) {
  ------------------
  |  Branch (3892:17): [True: 0, False: 0]
  ------------------
 3893|      0|                crv = CKR_FUNCTION_NOT_SUPPORTED;
  ------------------
  |  | 1426|      0|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
 3894|      0|                break;
 3895|      0|            }
 3896|       |
 3897|      0|            context->cipherInfo = pubKey;
 3898|      0|            context->verify = nsc_EDDSAVerifyStub;
 3899|      0|            context->destroy = sftk_Null;
 3900|      0|            break;
 3901|       |
 3902|      0|        case CKM_SSL3_MD5_MAC:
  ------------------
  |  |  975|      0|#define CKM_SSL3_MD5_MAC 0x00000380UL
  ------------------
  |  Branch (3902:9): [True: 0, False: 60]
  ------------------
 3903|      0|            PORT_Assert(pMechanism->pParameter);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3904|      0|            if (!pMechanism->pParameter) {
  ------------------
  |  Branch (3904:17): [True: 0, False: 0]
  ------------------
 3905|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3906|      0|                break;
 3907|      0|            }
 3908|      0|            crv = sftk_doSSLMACInit(context, SEC_OID_MD5, key,
 3909|      0|                                    *(CK_ULONG *)pMechanism->pParameter);
 3910|      0|            break;
 3911|      0|        case CKM_SSL3_SHA1_MAC:
  ------------------
  |  |  976|      0|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
  |  Branch (3911:9): [True: 0, False: 60]
  ------------------
 3912|      0|            PORT_Assert(pMechanism->pParameter);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3913|      0|            if (!pMechanism->pParameter) {
  ------------------
  |  Branch (3913:17): [True: 0, False: 0]
  ------------------
 3914|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 3915|      0|                break;
 3916|      0|            }
 3917|      0|            crv = sftk_doSSLMACInit(context, SEC_OID_SHA1, key,
 3918|      0|                                    *(CK_ULONG *)pMechanism->pParameter);
 3919|      0|            break;
 3920|      0|        case CKM_TLS_PRF_GENERAL:
  ------------------
  |  |  297|      0|#define CKM_TLS_PRF_GENERAL 0x80000373UL
  ------------------
  |  Branch (3920:9): [True: 0, False: 60]
  ------------------
 3921|      0|            crv = sftk_TLSPRFInit(context, key, key_type, HASH_AlgNULL, 0);
 3922|      0|            break;
 3923|      0|        case CKM_NSS_TLS_PRF_GENERAL_SHA256:
  ------------------
  |  |  233|      0|#define CKM_NSS_TLS_PRF_GENERAL_SHA256 (CKM_NSS + 21)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (3923:9): [True: 0, False: 60]
  ------------------
 3924|      0|            crv = sftk_TLSPRFInit(context, key, key_type, HASH_AlgSHA256, 0);
 3925|      0|            break;
 3926|       |
 3927|      0|        default:
  ------------------
  |  Branch (3927:9): [True: 0, False: 60]
  ------------------
 3928|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 3929|      0|            break;
 3930|     60|    }
 3931|       |
 3932|     60|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3932:9): [True: 0, False: 60]
  ------------------
 3933|      0|        if (info)
  ------------------
  |  Branch (3933:13): [True: 0, False: 0]
  ------------------
 3934|      0|            PORT_Free(info);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3935|      0|        if (pinfo)
  ------------------
  |  Branch (3935:13): [True: 0, False: 0]
  ------------------
 3936|      0|            PORT_ZFree(pinfo, pinfo->size);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 3937|      0|        sftk_FreeContext(context);
 3938|      0|        sftk_FreeSession(session);
 3939|      0|        return crv;
 3940|      0|    }
 3941|     60|    sftk_SetContextByType(session, SFTK_VERIFY, context);
 3942|     60|    sftk_FreeSession(session);
 3943|     60|    return CKR_OK;
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
 3944|     60|}
NSC_Verify:
 3952|     60|{
 3953|     60|    SFTKSession *session;
 3954|     60|    SFTKSessionContext *context;
 3955|     60|    CK_RV crv;
 3956|       |
 3957|     60|    CHECK_FORK();
 3958|       |
 3959|       |    /* make sure we're legal */
 3960|     60|    crv = sftk_GetContext(hSession, &context, SFTK_VERIFY, PR_FALSE, &session);
  ------------------
  |  |  438|     60|#define PR_FALSE 0
  ------------------
 3961|     60|    if (crv != CKR_OK)
  ------------------
  |  | 1388|     60|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3961:9): [True: 0, False: 60]
  ------------------
 3962|      0|        return crv;
 3963|       |
 3964|       |    /* multi part Verifying are completely implemented by VerifyUpdate and
 3965|       |     * VerifyFinal */
 3966|     60|    if (context->multi) {
  ------------------
  |  Branch (3966:9): [True: 0, False: 60]
  ------------------
 3967|       |        /* VerifyFinal can't follow failed VerifyUpdate */
 3968|      0|        if (CKR_OK == (crv = NSC_VerifyUpdate(hSession, pData, ulDataLen)))
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3968:13): [True: 0, False: 0]
  ------------------
 3969|      0|            crv = NSC_VerifyFinal(hSession, pSignature, ulSignatureLen);
 3970|     60|    } else {
 3971|     60|        if (SECSuccess != (*context->verify)(context->cipherInfo, pSignature,
  ------------------
  |  Branch (3971:13): [True: 60, False: 0]
  ------------------
 3972|     60|                                             ulSignatureLen, pData, ulDataLen))
 3973|     60|            crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|     60|#define PORT_GetError PORT_GetError_Util
  ------------------
 3974|       |
 3975|     60|        sftk_TerminateOp(session, SFTK_VERIFY, context);
 3976|     60|    }
 3977|     60|    sftk_FreeSession(session);
 3978|     60|    return crv;
 3979|     60|}
NSC_VerifyRecoverInit:
 4078|  2.95k|{
 4079|  2.95k|    SFTKSession *session;
 4080|  2.95k|    SFTKObject *key;
 4081|  2.95k|    SFTKSessionContext *context;
 4082|  2.95k|    CK_KEY_TYPE key_type;
 4083|  2.95k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
 4084|  2.95k|    NSSLOWKEYPublicKey *pubKey;
 4085|       |
 4086|  2.95k|    CHECK_FORK();
 4087|       |
 4088|  2.95k|    session = sftk_SessionFromHandle(hSession);
 4089|  2.95k|    if (session == NULL)
  ------------------
  |  Branch (4089:9): [True: 0, False: 2.95k]
  ------------------
 4090|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4091|  2.95k|    crv = sftk_InitGeneric(session, pMechanism, &context, SFTK_VERIFY_RECOVER,
 4092|  2.95k|                           &key, hKey, &key_type, CKO_PUBLIC_KEY, CKA_VERIFY_RECOVER);
  ------------------
  |  |  327|  2.95k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
                                         &key, hKey, &key_type, CKO_PUBLIC_KEY, CKA_VERIFY_RECOVER);
  ------------------
  |  |  554|  2.95k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
 4093|  2.95k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4093:9): [True: 0, False: 2.95k]
  ------------------
 4094|      0|        sftk_FreeSession(session);
 4095|      0|        return crv;
 4096|      0|    }
 4097|       |
 4098|  2.95k|    context->multi = PR_TRUE;
  ------------------
  |  |  437|  2.95k|#define PR_TRUE 1
  ------------------
 4099|       |
 4100|  2.95k|    switch (pMechanism->mechanism) {
 4101|  2.95k|        case CKM_RSA_PKCS:
  ------------------
  |  |  720|  2.95k|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (4101:9): [True: 2.95k, False: 0]
  ------------------
 4102|  2.95k|        case CKM_RSA_X_509:
  ------------------
  |  |  722|  2.95k|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (4102:9): [True: 0, False: 2.95k]
  ------------------
 4103|  2.95k|            if (key_type != CKK_RSA) {
  ------------------
  |  |  372|  2.95k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (4103:17): [True: 0, False: 2.95k]
  ------------------
 4104|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 4105|      0|                break;
 4106|      0|            }
 4107|  2.95k|            context->multi = PR_FALSE;
  ------------------
  |  |  438|  2.95k|#define PR_FALSE 0
  ------------------
 4108|  2.95k|            context->rsa = PR_TRUE;
  ------------------
  |  |  437|  2.95k|#define PR_TRUE 1
  ------------------
 4109|  2.95k|            pubKey = sftk_GetPubKey(key, CKK_RSA, &crv);
  ------------------
  |  |  372|  2.95k|#define CKK_RSA 0x00000000UL
  ------------------
 4110|  2.95k|            if (pubKey == NULL) {
  ------------------
  |  Branch (4110:17): [True: 0, False: 2.95k]
  ------------------
 4111|      0|                break;
 4112|      0|            }
 4113|  2.95k|            context->cipherInfo = pubKey;
 4114|  2.95k|            context->update = pMechanism->mechanism == CKM_RSA_X_509
  ------------------
  |  |  722|  2.95k|#define CKM_RSA_X_509 0x00000003UL
  ------------------
  |  Branch (4114:31): [True: 0, False: 2.95k]
  ------------------
 4115|  2.95k|                                  ? sftk_RSACheckSignRecoverRaw
 4116|  2.95k|                                  : sftk_RSACheckSignRecover;
 4117|  2.95k|            context->destroy = sftk_Null;
 4118|  2.95k|            break;
 4119|      0|        default:
  ------------------
  |  Branch (4119:9): [True: 0, False: 2.95k]
  ------------------
 4120|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4121|      0|            break;
 4122|  2.95k|    }
 4123|       |
 4124|  2.95k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4124:9): [True: 0, False: 2.95k]
  ------------------
 4125|      0|        PORT_Free(context);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 4126|      0|        sftk_FreeSession(session);
 4127|      0|        return crv;
 4128|      0|    }
 4129|  2.95k|    sftk_SetContextByType(session, SFTK_VERIFY_RECOVER, context);
 4130|  2.95k|    sftk_FreeSession(session);
 4131|  2.95k|    return CKR_OK;
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
 4132|  2.95k|}
NSC_VerifyRecover:
 4141|  2.95k|{
 4142|  2.95k|    SFTKSession *session;
 4143|  2.95k|    SFTKSessionContext *context;
 4144|  2.95k|    unsigned int outlen;
 4145|  2.95k|    unsigned int maxoutlen = *pulDataLen;
 4146|  2.95k|    CK_RV crv;
 4147|  2.95k|    SECStatus rv;
 4148|       |
 4149|  2.95k|    CHECK_FORK();
 4150|       |
 4151|       |    /* make sure we're legal */
 4152|  2.95k|    crv = sftk_GetContext(hSession, &context, SFTK_VERIFY_RECOVER,
 4153|  2.95k|                          PR_FALSE, &session);
  ------------------
  |  |  438|  2.95k|#define PR_FALSE 0
  ------------------
 4154|  2.95k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  2.95k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4154:9): [True: 0, False: 2.95k]
  ------------------
 4155|      0|        return crv;
 4156|  2.95k|    if (pData == NULL) {
  ------------------
  |  Branch (4156:9): [True: 0, False: 2.95k]
  ------------------
 4157|       |        /* to return the actual size, we need  to do the decrypt, just return
 4158|       |         * the max size, which is the size of the input signature. */
 4159|      0|        *pulDataLen = ulSignatureLen;
 4160|      0|        rv = SECSuccess;
 4161|      0|        goto finish;
 4162|      0|    }
 4163|       |
 4164|  2.95k|    rv = (*context->update)(context->cipherInfo, pData, &outlen, maxoutlen,
 4165|  2.95k|                            pSignature, ulSignatureLen);
 4166|  2.95k|    *pulDataLen = (CK_ULONG)outlen;
 4167|       |
 4168|  2.95k|    sftk_TerminateOp(session, SFTK_VERIFY_RECOVER, context);
 4169|  2.95k|finish:
 4170|  2.95k|    sftk_FreeSession(session);
 4171|  2.95k|    return (rv == SECSuccess) ? CKR_OK : sftk_MapVerifyError(PORT_GetError());
  ------------------
  |  | 1388|      4|#define CKR_OK 0x00000000UL
  ------------------
                  return (rv == SECSuccess) ? CKR_OK : sftk_MapVerifyError(PORT_GetError());
  ------------------
  |  |   62|  2.94k|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (4171:12): [True: 4, False: 2.94k]
  ------------------
 4172|  2.95k|}
NSC_GenerateRandom:
 4196|   137k|{
 4197|   137k|    SECStatus rv;
 4198|       |
 4199|   137k|    CHECK_FORK();
 4200|       |
 4201|   137k|    rv = RNG_GenerateGlobalRandomBytes(pRandomData, ulRandomLen);
 4202|       |    /*
 4203|       |     * This may fail with SEC_ERROR_NEED_RANDOM, which means the RNG isn't
 4204|       |     * seeded with enough entropy.
 4205|       |     */
 4206|   137k|    return (rv == SECSuccess) ? CKR_OK : sftk_MapCryptError(PORT_GetError());
  ------------------
  |  | 1388|   137k|#define CKR_OK 0x00000000UL
  ------------------
                  return (rv == SECSuccess) ? CKR_OK : sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (4206:12): [True: 137k, False: 0]
  ------------------
 4207|   137k|}
NSC_GenerateKey:
 4761|  16.7k|{
 4762|  16.7k|    SFTKObject *key;
 4763|  16.7k|    SFTKSession *session;
 4764|  16.7k|    PRBool checkWeak = PR_FALSE;
  ------------------
  |  |  438|  16.7k|#define PR_FALSE 0
  ------------------
 4765|  16.7k|    CK_ULONG key_length = 0;
 4766|  16.7k|    CK_KEY_TYPE key_type = CKK_INVALID_KEY_TYPE;
  ------------------
  |  | 2759|  16.7k|#define CKK_INVALID_KEY_TYPE 0xffffffffUL
  ------------------
 4767|  16.7k|    CK_OBJECT_CLASS objclass = CKO_SECRET_KEY;
  ------------------
  |  |  329|  16.7k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 4768|  16.7k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
 4769|  16.7k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  16.7k|#define CK_TRUE 1
  ------------------
 4770|  16.7k|    NSSPKCS5PBEParameter *pbe_param = NULL;
 4771|  16.7k|    int i;
 4772|  16.7k|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 4773|  16.7k|    unsigned char buf[MAX_KEY_LEN];
 4774|  16.7k|    enum { nsc_pbe,
 4775|  16.7k|           nsc_ssl,
 4776|  16.7k|           nsc_bulk,
 4777|  16.7k|           nsc_param,
 4778|  16.7k|           nsc_jpake } key_gen_type;
 4779|  16.7k|    SSL3RSAPreMasterSecret *rsa_pms;
 4780|  16.7k|    CK_VERSION *version;
 4781|       |    /* in very old versions of NSS, there were implementation errors with key
 4782|       |     * generation methods.  We want to beable to read these, but not
 4783|       |     * produce them any more.  The affected algorithm was 3DES.
 4784|       |     */
 4785|  16.7k|    PRBool faultyPBE3DES = PR_FALSE;
  ------------------
  |  |  438|  16.7k|#define PR_FALSE 0
  ------------------
 4786|  16.7k|    HASH_HashType hashType = HASH_AlgNULL;
 4787|       |
 4788|  16.7k|    CHECK_FORK();
 4789|       |
 4790|  16.7k|    if (!slot) {
  ------------------
  |  Branch (4790:9): [True: 0, False: 16.7k]
  ------------------
 4791|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 4792|      0|    }
 4793|       |    /*
 4794|       |     * now lets create an object to hang the attributes off of
 4795|       |     */
 4796|  16.7k|    key = sftk_NewObject(slot); /* fill in the handle later */
 4797|  16.7k|    if (key == NULL) {
  ------------------
  |  Branch (4797:9): [True: 0, False: 16.7k]
  ------------------
 4798|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 4799|      0|    }
 4800|       |
 4801|       |    /*
 4802|       |     * load the template values into the object
 4803|       |     */
 4804|  54.8k|    for (i = 0; i < (int)ulCount; i++) {
  ------------------
  |  Branch (4804:17): [True: 38.1k, False: 16.7k]
  ------------------
 4805|  38.1k|        if (pTemplate[i].type == CKA_VALUE_LEN) {
  ------------------
  |  |  580|  38.1k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (4805:13): [True: 4.72k, False: 33.4k]
  ------------------
 4806|  4.72k|            key_length = *(CK_ULONG *)pTemplate[i].pValue;
 4807|  4.72k|            continue;
 4808|  4.72k|        }
 4809|       |        /* some algorithms need keytype specified */
 4810|  33.4k|        if (pTemplate[i].type == CKA_KEY_TYPE) {
  ------------------
  |  |  543|  33.4k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (4810:13): [True: 0, False: 33.4k]
  ------------------
 4811|      0|            key_type = *(CK_ULONG *)pTemplate[i].pValue;
 4812|      0|            continue;
 4813|      0|        }
 4814|       |
 4815|  33.4k|        crv = sftk_AddAttributeType(key, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|  33.4k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 4816|  33.4k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  33.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4816:13): [True: 0, False: 33.4k]
  ------------------
 4817|      0|            break;
 4818|      0|        }
 4819|  33.4k|    }
 4820|  16.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4820:9): [True: 0, False: 16.7k]
  ------------------
 4821|      0|        goto loser;
 4822|      0|    }
 4823|       |
 4824|       |    /* make sure we don't have any class, key_type, or value fields */
 4825|  16.7k|    sftk_DeleteAttributeType(key, CKA_CLASS);
  ------------------
  |  |  511|  16.7k|#define CKA_CLASS 0x00000000UL
  ------------------
 4826|  16.7k|    sftk_DeleteAttributeType(key, CKA_KEY_TYPE);
  ------------------
  |  |  543|  16.7k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 4827|  16.7k|    sftk_DeleteAttributeType(key, CKA_VALUE);
  ------------------
  |  |  516|  16.7k|#define CKA_VALUE 0x00000011UL
  ------------------
 4828|       |
 4829|       |    /* Now Set up the parameters to generate the key (based on mechanism) */
 4830|  16.7k|    key_gen_type = nsc_bulk; /* bulk key by default */
 4831|  16.7k|    switch (pMechanism->mechanism) {
 4832|      0|        case CKM_CDMF_KEY_GEN:
  ------------------
  |  |  834|      0|#define CKM_CDMF_KEY_GEN 0x00000140UL
  ------------------
  |  Branch (4832:9): [True: 0, False: 16.7k]
  ------------------
 4833|      0|        case CKM_DES_KEY_GEN:
  ------------------
  |  |  814|      0|#define CKM_DES_KEY_GEN 0x00000120UL
  ------------------
  |  Branch (4833:9): [True: 0, False: 16.7k]
  ------------------
 4834|      0|        case CKM_DES2_KEY_GEN:
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
  |  Branch (4834:9): [True: 0, False: 16.7k]
  ------------------
 4835|      2|        case CKM_DES3_KEY_GEN:
  ------------------
  |  |  824|      2|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  |  Branch (4835:9): [True: 2, False: 16.6k]
  ------------------
 4836|      2|            checkWeak = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 4837|       |/* fall through */
 4838|      2|#ifndef NSS_DISABLE_DEPRECATED_RC2
 4839|      2|        case CKM_RC2_KEY_GEN:
  ------------------
  |  |  803|      2|#define CKM_RC2_KEY_GEN 0x00000100UL
  ------------------
  |  Branch (4839:9): [True: 0, False: 16.7k]
  ------------------
 4840|      2|#endif
 4841|      2|        case CKM_RC4_KEY_GEN:
  ------------------
  |  |  812|      2|#define CKM_RC4_KEY_GEN 0x00000110UL
  ------------------
  |  Branch (4841:9): [True: 0, False: 16.7k]
  ------------------
 4842|      3|        case CKM_GENERIC_SECRET_KEY_GEN:
  ------------------
  |  |  953|      3|#define CKM_GENERIC_SECRET_KEY_GEN 0x00000350UL
  ------------------
  |  Branch (4842:9): [True: 1, False: 16.7k]
  ------------------
 4843|      3|#ifndef NSS_DISABLE_DEPRECATED_SEED
 4844|      3|        case CKM_SEED_KEY_GEN:
  ------------------
  |  | 1155|      3|#define CKM_SEED_KEY_GEN 0x00000650UL
  ------------------
  |  Branch (4844:9): [True: 0, False: 16.7k]
  ------------------
 4845|      3|#endif
 4846|      3|        case CKM_CAMELLIA_KEY_GEN:
  ------------------
  |  | 1135|      3|#define CKM_CAMELLIA_KEY_GEN 0x00000550UL
  ------------------
  |  Branch (4846:9): [True: 0, False: 16.7k]
  ------------------
 4847|      4|        case CKM_AES_KEY_GEN:
  ------------------
  |  | 1106|      4|#define CKM_AES_KEY_GEN 0x00001080UL
  ------------------
  |  Branch (4847:9): [True: 1, False: 16.7k]
  ------------------
 4848|  4.72k|        case CKM_NSS_CHACHA20_KEY_GEN:
  ------------------
  |  |  242|  4.72k|#define CKM_NSS_CHACHA20_KEY_GEN (CKM_NSS + 27)
  |  |  ------------------
  |  |  |  |  162|  4.72k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  4.72k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4848:9): [True: 4.72k, False: 11.9k]
  ------------------
 4849|  4.72k|        case CKM_CHACHA20_KEY_GEN:
  ------------------
  |  | 1203|  4.72k|#define CKM_CHACHA20_KEY_GEN 0x00001225UL
  ------------------
  |  Branch (4849:9): [True: 0, False: 16.7k]
  ------------------
 4850|       |#if NSS_SOFTOKEN_DOES_RC5
 4851|       |        case CKM_RC5_KEY_GEN:
 4852|       |#endif
 4853|  4.72k|            crv = nsc_SetupBulkKeyGen(pMechanism->mechanism, &key_type, &key_length);
 4854|  4.72k|            break;
 4855|  11.9k|        case CKM_SSL3_PRE_MASTER_KEY_GEN:
  ------------------
  |  |  959|  11.9k|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
  |  Branch (4855:9): [True: 11.9k, False: 4.72k]
  ------------------
 4856|  11.9k|            key_type = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  11.9k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 4857|  11.9k|            key_length = 48;
 4858|  11.9k|            key_gen_type = nsc_ssl;
 4859|  11.9k|            break;
 4860|      0|        case CKM_PBA_SHA1_WITH_SHA1_HMAC:
  ------------------
  |  | 1015|      0|#define CKM_PBA_SHA1_WITH_SHA1_HMAC 0x000003C0UL
  ------------------
  |  Branch (4860:9): [True: 0, False: 16.7k]
  ------------------
 4861|      0|        case CKM_NSS_PBE_SHA1_HMAC_KEY_GEN:
  ------------------
  |  |  293|      0|#define CKM_NSS_PBE_SHA1_HMAC_KEY_GEN 0x80000009UL
  ------------------
  |  Branch (4861:9): [True: 0, False: 16.7k]
  ------------------
 4862|      0|        case CKM_NSS_PBE_MD5_HMAC_KEY_GEN:
  ------------------
  |  |  294|      0|#define CKM_NSS_PBE_MD5_HMAC_KEY_GEN 0x8000000aUL
  ------------------
  |  Branch (4862:9): [True: 0, False: 16.7k]
  ------------------
 4863|      0|        case CKM_NSS_PBE_MD2_HMAC_KEY_GEN:
  ------------------
  |  |  295|      0|#define CKM_NSS_PBE_MD2_HMAC_KEY_GEN 0x8000000bUL
  ------------------
  |  Branch (4863:9): [True: 0, False: 16.7k]
  ------------------
 4864|      0|        case CKM_NSS_PKCS12_PBE_SHA224_HMAC_KEY_GEN:
  ------------------
  |  |  246|      0|#define CKM_NSS_PKCS12_PBE_SHA224_HMAC_KEY_GEN (CKM_NSS + 29)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4864:9): [True: 0, False: 16.7k]
  ------------------
 4865|      0|        case CKM_NSS_PKCS12_PBE_SHA256_HMAC_KEY_GEN:
  ------------------
  |  |  247|      0|#define CKM_NSS_PKCS12_PBE_SHA256_HMAC_KEY_GEN (CKM_NSS + 30)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4865:9): [True: 0, False: 16.7k]
  ------------------
 4866|      0|        case CKM_NSS_PKCS12_PBE_SHA384_HMAC_KEY_GEN:
  ------------------
  |  |  248|      0|#define CKM_NSS_PKCS12_PBE_SHA384_HMAC_KEY_GEN (CKM_NSS + 31)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4866:9): [True: 0, False: 16.7k]
  ------------------
 4867|      0|        case CKM_NSS_PKCS12_PBE_SHA512_HMAC_KEY_GEN:
  ------------------
  |  |  249|      0|#define CKM_NSS_PKCS12_PBE_SHA512_HMAC_KEY_GEN (CKM_NSS + 32)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4867:9): [True: 0, False: 16.7k]
  ------------------
 4868|      0|            key_gen_type = nsc_pbe;
 4869|      0|            key_type = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|      0|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 4870|      0|            crv = nsc_SetupHMACKeyGen(pMechanism, &pbe_param);
 4871|      0|            break;
 4872|      0|        case CKM_NSS_PBE_SHA1_FAULTY_3DES_CBC:
  ------------------
  |  |  292|      0|#define CKM_NSS_PBE_SHA1_FAULTY_3DES_CBC 0x80000008UL
  ------------------
  |  Branch (4872:9): [True: 0, False: 16.7k]
  ------------------
 4873|      0|            faultyPBE3DES = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 4874|       |        /* fall through */
 4875|      0|        case CKM_NSS_PBE_SHA1_TRIPLE_DES_CBC:
  ------------------
  |  |  287|      0|#define CKM_NSS_PBE_SHA1_TRIPLE_DES_CBC 0x80000003UL
  ------------------
  |  Branch (4875:9): [True: 0, False: 16.7k]
  ------------------
 4876|      0|#ifndef NSS_DISABLE_DEPRECATED_RC2
 4877|      0|        case CKM_NSS_PBE_SHA1_40_BIT_RC2_CBC:
  ------------------
  |  |  288|      0|#define CKM_NSS_PBE_SHA1_40_BIT_RC2_CBC 0x80000004UL
  ------------------
  |  Branch (4877:9): [True: 0, False: 16.7k]
  ------------------
 4878|      0|        case CKM_NSS_PBE_SHA1_128_BIT_RC2_CBC:
  ------------------
  |  |  289|      0|#define CKM_NSS_PBE_SHA1_128_BIT_RC2_CBC 0x80000005UL
  ------------------
  |  Branch (4878:9): [True: 0, False: 16.7k]
  ------------------
 4879|      0|        case CKM_PBE_SHA1_RC2_128_CBC:
  ------------------
  |  | 1009|      0|#define CKM_PBE_SHA1_RC2_128_CBC 0x000003AAUL
  ------------------
  |  Branch (4879:9): [True: 0, False: 16.7k]
  ------------------
 4880|      0|        case CKM_PBE_SHA1_RC2_40_CBC:
  ------------------
  |  | 1010|      0|#define CKM_PBE_SHA1_RC2_40_CBC 0x000003ABUL
  ------------------
  |  Branch (4880:9): [True: 0, False: 16.7k]
  ------------------
 4881|      0|#endif
 4882|      0|        case CKM_NSS_PBE_SHA1_DES_CBC:
  ------------------
  |  |  286|      0|#define CKM_NSS_PBE_SHA1_DES_CBC 0x80000002UL
  ------------------
  |  Branch (4882:9): [True: 0, False: 16.7k]
  ------------------
 4883|      0|        case CKM_NSS_PBE_SHA1_40_BIT_RC4:
  ------------------
  |  |  290|      0|#define CKM_NSS_PBE_SHA1_40_BIT_RC4 0x80000006UL
  ------------------
  |  Branch (4883:9): [True: 0, False: 16.7k]
  ------------------
 4884|      0|        case CKM_NSS_PBE_SHA1_128_BIT_RC4:
  ------------------
  |  |  291|      0|#define CKM_NSS_PBE_SHA1_128_BIT_RC4 0x80000007UL
  ------------------
  |  Branch (4884:9): [True: 0, False: 16.7k]
  ------------------
 4885|      0|        case CKM_PBE_SHA1_DES3_EDE_CBC:
  ------------------
  |  | 1007|      0|#define CKM_PBE_SHA1_DES3_EDE_CBC 0x000003A8UL
  ------------------
  |  Branch (4885:9): [True: 0, False: 16.7k]
  ------------------
 4886|      0|        case CKM_PBE_SHA1_DES2_EDE_CBC:
  ------------------
  |  | 1008|      0|#define CKM_PBE_SHA1_DES2_EDE_CBC 0x000003A9UL
  ------------------
  |  Branch (4886:9): [True: 0, False: 16.7k]
  ------------------
 4887|      0|        case CKM_PBE_SHA1_RC4_128:
  ------------------
  |  | 1005|      0|#define CKM_PBE_SHA1_RC4_128 0x000003A6UL
  ------------------
  |  Branch (4887:9): [True: 0, False: 16.7k]
  ------------------
 4888|      0|        case CKM_PBE_SHA1_RC4_40:
  ------------------
  |  | 1006|      0|#define CKM_PBE_SHA1_RC4_40 0x000003A7UL
  ------------------
  |  Branch (4888:9): [True: 0, False: 16.7k]
  ------------------
 4889|      0|        case CKM_PBE_MD5_DES_CBC:
  ------------------
  |  |  998|      0|#define CKM_PBE_MD5_DES_CBC 0x000003A1UL
  ------------------
  |  Branch (4889:9): [True: 0, False: 16.7k]
  ------------------
 4890|      0|        case CKM_PBE_MD2_DES_CBC:
  ------------------
  |  |  997|      0|#define CKM_PBE_MD2_DES_CBC 0x000003A0UL
  ------------------
  |  Branch (4890:9): [True: 0, False: 16.7k]
  ------------------
 4891|      0|        case CKM_PKCS5_PBKD2:
  ------------------
  |  | 1013|      0|#define CKM_PKCS5_PBKD2 0x000003B0UL
  ------------------
  |  Branch (4891:9): [True: 0, False: 16.7k]
  ------------------
 4892|      0|            key_gen_type = nsc_pbe;
 4893|      0|            crv = nsc_SetupPBEKeyGen(pMechanism, &pbe_param, &key_type, &key_length);
 4894|      0|            break;
 4895|      0|        case CKM_DSA_PARAMETER_GEN:
  ------------------
  |  | 1212|      0|#define CKM_DSA_PARAMETER_GEN 0x00002000UL
  ------------------
  |  Branch (4895:9): [True: 0, False: 16.7k]
  ------------------
 4896|      0|            key_gen_type = nsc_param;
 4897|      0|            key_type = CKK_DSA;
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
 4898|      0|            objclass = CKO_DOMAIN_PARAMETERS;
  ------------------
  |  |  331|      0|#define CKO_DOMAIN_PARAMETERS 0x00000006UL
  ------------------
 4899|      0|            crv = CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 4900|      0|            break;
 4901|      0|        case CKM_NSS_JPAKE_ROUND1_SHA1:
  ------------------
  |  |  182|      0|#define CKM_NSS_JPAKE_ROUND1_SHA1 (CKM_NSS + 7)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4901:9): [True: 0, False: 16.7k]
  ------------------
 4902|      0|            hashType = HASH_AlgSHA1;
 4903|      0|            goto jpake1;
 4904|      0|        case CKM_NSS_JPAKE_ROUND1_SHA256:
  ------------------
  |  |  183|      0|#define CKM_NSS_JPAKE_ROUND1_SHA256 (CKM_NSS + 8)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4904:9): [True: 0, False: 16.7k]
  ------------------
 4905|      0|            hashType = HASH_AlgSHA256;
 4906|      0|            goto jpake1;
 4907|      0|        case CKM_NSS_JPAKE_ROUND1_SHA384:
  ------------------
  |  |  184|      0|#define CKM_NSS_JPAKE_ROUND1_SHA384 (CKM_NSS + 9)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4907:9): [True: 0, False: 16.7k]
  ------------------
 4908|      0|            hashType = HASH_AlgSHA384;
 4909|      0|            goto jpake1;
 4910|      0|        case CKM_NSS_JPAKE_ROUND1_SHA512:
  ------------------
  |  |  185|      0|#define CKM_NSS_JPAKE_ROUND1_SHA512 (CKM_NSS + 10)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4910:9): [True: 0, False: 16.7k]
  ------------------
 4911|      0|            hashType = HASH_AlgSHA512;
 4912|      0|            goto jpake1;
 4913|      0|        jpake1:
 4914|      0|            key_gen_type = nsc_jpake;
 4915|      0|            key_type = CKK_NSS_JPAKE_ROUND1;
  ------------------
  |  |   53|      0|#define CKK_NSS_JPAKE_ROUND1 (CKK_NSS + 2)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4916|      0|            objclass = CKO_PRIVATE_KEY;
  ------------------
  |  |  328|      0|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
 4917|      0|            if (pMechanism->pParameter == NULL ||
  ------------------
  |  Branch (4917:17): [True: 0, False: 0]
  ------------------
 4918|      0|                pMechanism->ulParameterLen != sizeof(CK_NSS_JPAKERound1Params)) {
  ------------------
  |  Branch (4918:17): [True: 0, False: 0]
  ------------------
 4919|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 4920|      0|                break;
 4921|      0|            }
 4922|      0|            if (sftk_isTrue(key, CKA_TOKEN)) {
  ------------------
  |  |  512|      0|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (4922:17): [True: 0, False: 0]
  ------------------
 4923|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 4924|      0|                break;
 4925|      0|            }
 4926|      0|            crv = CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 4927|      0|            break;
 4928|      0|        default:
  ------------------
  |  Branch (4928:9): [True: 0, False: 16.7k]
  ------------------
 4929|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4930|      0|            break;
 4931|  16.7k|    }
 4932|       |
 4933|       |    /* make sure we aren't going to overflow the buffer */
 4934|  16.7k|    if (sizeof(buf) < key_length) {
  ------------------
  |  Branch (4934:9): [True: 0, False: 16.7k]
  ------------------
 4935|       |        /* someone is getting pretty optimistic about how big their key can
 4936|       |         * be... */
 4937|      0|        crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 4938|      0|    }
 4939|       |
 4940|  16.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4940:9): [True: 0, False: 16.7k]
  ------------------
 4941|      0|        if (pbe_param) {
  ------------------
  |  Branch (4941:13): [True: 0, False: 0]
  ------------------
 4942|      0|            nsspkcs5_DestroyPBEParameter(pbe_param);
 4943|      0|        }
 4944|      0|        goto loser;
 4945|      0|    }
 4946|       |
 4947|       |    /* if there was no error,
 4948|       |     * key_type *MUST* be set in the switch statement above */
 4949|  16.7k|    PORT_Assert(key_type != CKK_INVALID_KEY_TYPE);
  ------------------
  |  |  120|  16.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  16.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 16.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4950|       |
 4951|       |    /*
 4952|       |     * now to the actual key gen.
 4953|       |     */
 4954|  16.7k|    switch (key_gen_type) {
  ------------------
  |  Branch (4954:13): [True: 0, False: 16.7k]
  ------------------
 4955|      0|        case nsc_pbe:
  ------------------
  |  Branch (4955:9): [True: 0, False: 16.7k]
  ------------------
 4956|      0|            crv = nsc_pbe_key_gen(pbe_param, pMechanism, buf, &key_length,
 4957|      0|                                  faultyPBE3DES);
 4958|      0|            nsspkcs5_DestroyPBEParameter(pbe_param);
 4959|      0|            break;
 4960|  11.9k|        case nsc_ssl:
  ------------------
  |  Branch (4960:9): [True: 11.9k, False: 4.72k]
  ------------------
 4961|  11.9k|            rsa_pms = (SSL3RSAPreMasterSecret *)buf;
 4962|  11.9k|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_VERSION))) {
  ------------------
  |  |   50|  11.9k|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 11.9k]
  |  |  |  Branch (50:64): [True: 0, False: 11.9k]
  |  |  ------------------
  ------------------
 4963|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 4964|      0|                goto loser;
 4965|      0|            }
 4966|  11.9k|            version = (CK_VERSION *)pMechanism->pParameter;
 4967|  11.9k|            rsa_pms->client_version[0] = version->major;
 4968|  11.9k|            rsa_pms->client_version[1] = version->minor;
 4969|  11.9k|            crv =
 4970|  11.9k|                NSC_GenerateRandom(0, &rsa_pms->random[0], sizeof(rsa_pms->random));
 4971|  11.9k|            break;
 4972|  4.72k|        case nsc_bulk:
  ------------------
  |  Branch (4972:9): [True: 4.72k, False: 11.9k]
  ------------------
 4973|       |            /* get the key, check for weak keys and repeat if found */
 4974|  4.72k|            do {
 4975|  4.72k|                crv = NSC_GenerateRandom(0, buf, key_length);
 4976|  4.72k|            } while (crv == CKR_OK && checkWeak && sftk_IsWeakKey(buf, key_type));
  ------------------
  |  | 1388|  9.45k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4976:22): [True: 4.72k, False: 0]
  |  Branch (4976:39): [True: 2, False: 4.72k]
  |  Branch (4976:52): [True: 0, False: 2]
  ------------------
 4977|  4.72k|            break;
 4978|      0|        case nsc_param:
  ------------------
  |  Branch (4978:9): [True: 0, False: 16.7k]
  ------------------
 4979|       |            /* generate parameters */
 4980|      0|            *buf = 0;
 4981|      0|            crv = nsc_parameter_gen(key_type, key);
 4982|      0|            break;
 4983|      0|        case nsc_jpake:
  ------------------
  |  Branch (4983:9): [True: 0, False: 16.7k]
  ------------------
 4984|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_NSS_JPAKERound1Params))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4985|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 4986|      0|                goto loser;
 4987|      0|            }
 4988|      0|            crv = jpake_Round1(hashType,
 4989|      0|                               (CK_NSS_JPAKERound1Params *)pMechanism->pParameter,
 4990|      0|                               key);
 4991|      0|            break;
 4992|  16.7k|    }
 4993|       |
 4994|  16.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (4994:9): [True: 0, False: 16.7k]
  ------------------
 4995|      0|        goto loser;
 4996|      0|    }
 4997|       |
 4998|       |    /* Add the class, key_type, and value */
 4999|  16.7k|    crv = sftk_AddAttributeType(key, CKA_CLASS, &objclass, sizeof(CK_OBJECT_CLASS));
  ------------------
  |  |  511|  16.7k|#define CKA_CLASS 0x00000000UL
  ------------------
 5000|  16.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5000:9): [True: 0, False: 16.7k]
  ------------------
 5001|      0|        goto loser;
 5002|      0|    }
 5003|  16.7k|    crv = sftk_AddAttributeType(key, CKA_KEY_TYPE, &key_type, sizeof(CK_KEY_TYPE));
  ------------------
  |  |  543|  16.7k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 5004|  16.7k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5004:9): [True: 0, False: 16.7k]
  ------------------
 5005|      0|        goto loser;
 5006|      0|    }
 5007|  16.7k|    if (key_length != 0) {
  ------------------
  |  Branch (5007:9): [True: 16.7k, False: 0]
  ------------------
 5008|  16.7k|        crv = sftk_AddAttributeType(key, CKA_VALUE, buf, key_length);
  ------------------
  |  |  516|  16.7k|#define CKA_VALUE 0x00000011UL
  ------------------
 5009|  16.7k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5009:13): [True: 0, False: 16.7k]
  ------------------
 5010|      0|            goto loser;
 5011|      0|        }
 5012|  16.7k|    }
 5013|       |
 5014|       |    /* get the session */
 5015|  16.7k|    session = sftk_SessionFromHandle(hSession);
 5016|  16.7k|    if (session == NULL) {
  ------------------
  |  Branch (5016:9): [True: 0, False: 16.7k]
  ------------------
 5017|      0|        crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5018|      0|        goto loser;
 5019|      0|    }
 5020|       |
 5021|       |    /*
 5022|       |     * handle the base object stuff
 5023|       |     */
 5024|  16.7k|    crv = sftk_handleObject(key, session);
 5025|  16.7k|    sftk_FreeSession(session);
 5026|  16.7k|    if (crv == CKR_OK && sftk_isTrue(key, CKA_SENSITIVE)) {
  ------------------
  |  | 1388|  33.4k|#define CKR_OK 0x00000000UL
  ------------------
                  if (crv == CKR_OK && sftk_isTrue(key, CKA_SENSITIVE)) {
  ------------------
  |  |  546|  16.7k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (5026:9): [True: 16.7k, False: 0]
  |  Branch (5026:26): [True: 0, False: 16.7k]
  ------------------
 5027|      0|        crv = sftk_forceAttribute(key, CKA_ALWAYS_SENSITIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  588|      0|#define CKA_ALWAYS_SENSITIVE 0x00000165UL
  ------------------
 5028|      0|    }
 5029|  16.7k|    if (crv == CKR_OK && !sftk_isTrue(key, CKA_EXTRACTABLE)) {
  ------------------
  |  | 1388|  33.4k|#define CKR_OK 0x00000000UL
  ------------------
                  if (crv == CKR_OK && !sftk_isTrue(key, CKA_EXTRACTABLE)) {
  ------------------
  |  |  585|  16.7k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  |  Branch (5029:9): [True: 16.7k, False: 0]
  |  Branch (5029:26): [True: 0, False: 16.7k]
  ------------------
 5030|      0|        crv = sftk_forceAttribute(key, CKA_NEVER_EXTRACTABLE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  587|      0|#define CKA_NEVER_EXTRACTABLE 0x00000164UL
  ------------------
 5031|      0|    }
 5032|  16.7k|    if (crv == CKR_OK) {
  ------------------
  |  | 1388|  16.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5032:9): [True: 16.7k, False: 0]
  ------------------
 5033|  16.7k|        *phKey = key->handle;
 5034|  16.7k|    }
 5035|  16.7k|loser:
 5036|  16.7k|    PORT_Memset(buf, 0, sizeof buf);
  ------------------
  |  |  182|  16.7k|#define PORT_Memset memset
  ------------------
 5037|  16.7k|    sftk_FreeObject(key);
 5038|  16.7k|    return crv;
 5039|  16.7k|}
NSC_GenerateKeyPair:
 5495|  47.3k|{
 5496|  47.3k|    SFTKObject *publicKey, *privateKey;
 5497|  47.3k|    SFTKSession *session;
 5498|  47.3k|    CK_KEY_TYPE key_type;
 5499|  47.3k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
 5500|  47.3k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  47.3k|#define CK_TRUE 1
  ------------------
 5501|  47.3k|    SECStatus rv;
 5502|  47.3k|    CK_OBJECT_CLASS pubClass = CKO_PUBLIC_KEY;
  ------------------
  |  |  327|  47.3k|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
 5503|  47.3k|    CK_OBJECT_CLASS privClass = CKO_PRIVATE_KEY;
  ------------------
  |  |  328|  47.3k|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
 5504|  47.3k|    int i;
 5505|  47.3k|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 5506|  47.3k|    unsigned int bitSize;
 5507|       |
 5508|       |    /* RSA */
 5509|  47.3k|    int public_modulus_bits = 0;
 5510|  47.3k|    SECItem pubExp;
 5511|  47.3k|    RSAPrivateKey *rsaPriv;
 5512|       |
 5513|       |    /* DSA */
 5514|  47.3k|    PQGParams pqgParam;
 5515|  47.3k|    DHParams dhParam;
 5516|  47.3k|    DSAPrivateKey *dsaPriv;
 5517|       |
 5518|       |    /* Diffie Hellman */
 5519|  47.3k|    DHPrivateKey *dhPriv;
 5520|       |
 5521|       |    /* Elliptic Curve Cryptography */
 5522|  47.3k|    SECItem ecEncodedParams; /* DER Encoded parameters */
 5523|  47.3k|    ECPrivateKey *ecPriv;
 5524|  47.3k|    ECParams *ecParams;
 5525|       |
 5526|       |    /* Kyber */
 5527|  47.3k|    CK_NSS_KEM_PARAMETER_SET_TYPE ckKyberParamSet;
 5528|       |
 5529|  47.3k|    CHECK_FORK();
 5530|       |
 5531|  47.3k|    if (!slot) {
  ------------------
  |  Branch (5531:9): [True: 0, False: 47.3k]
  ------------------
 5532|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 5533|      0|    }
 5534|       |    /*
 5535|       |     * now lets create an object to hang the attributes off of
 5536|       |     */
 5537|  47.3k|    publicKey = sftk_NewObject(slot); /* fill in the handle later */
 5538|  47.3k|    if (publicKey == NULL) {
  ------------------
  |  Branch (5538:9): [True: 0, False: 47.3k]
  ------------------
 5539|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5540|      0|    }
 5541|       |
 5542|       |    /*
 5543|       |     * load the template values into the publicKey
 5544|       |     */
 5545|   408k|    for (i = 0; i < (int)ulPublicKeyAttributeCount; i++) {
  ------------------
  |  Branch (5545:17): [True: 360k, False: 47.3k]
  ------------------
 5546|   360k|        if (pPublicKeyTemplate[i].type == CKA_MODULUS_BITS) {
  ------------------
  |  |  559|   360k|#define CKA_MODULUS_BITS 0x00000121UL
  ------------------
  |  Branch (5546:13): [True: 0, False: 360k]
  ------------------
 5547|      0|            public_modulus_bits = *(CK_ULONG *)pPublicKeyTemplate[i].pValue;
 5548|      0|            continue;
 5549|      0|        }
 5550|       |
 5551|   360k|        if (pPublicKeyTemplate[i].type == CKA_NSS_PARAMETER_SET) {
  ------------------
  |  |  113|   360k|#define CKA_NSS_PARAMETER_SET (CKA_NSS + 40)
  |  |  ------------------
  |  |  |  |   77|   360k|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|   360k|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   360k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (5551:13): [True: 0, False: 360k]
  ------------------
 5552|      0|            ckKyberParamSet = *(CK_NSS_KEM_PARAMETER_SET_TYPE *)pPublicKeyTemplate[i].pValue;
 5553|      0|            continue;
 5554|      0|        }
 5555|       |
 5556|   360k|        crv = sftk_AddAttributeType(publicKey,
 5557|   360k|                                    sftk_attr_expand(&pPublicKeyTemplate[i]));
  ------------------
  |  |  587|   360k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 5558|   360k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   360k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5558:13): [True: 0, False: 360k]
  ------------------
 5559|      0|            break;
 5560|   360k|    }
 5561|       |
 5562|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5562:9): [True: 0, False: 47.3k]
  ------------------
 5563|      0|        sftk_FreeObject(publicKey);
 5564|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5565|      0|    }
 5566|       |
 5567|  47.3k|    privateKey = sftk_NewObject(slot); /* fill in the handle later */
 5568|  47.3k|    if (privateKey == NULL) {
  ------------------
  |  Branch (5568:9): [True: 0, False: 47.3k]
  ------------------
 5569|      0|        sftk_FreeObject(publicKey);
 5570|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5571|      0|    }
 5572|       |    /*
 5573|       |     * now load the private key template
 5574|       |     */
 5575|   379k|    for (i = 0; i < (int)ulPrivateKeyAttributeCount; i++) {
  ------------------
  |  Branch (5575:17): [True: 331k, False: 47.3k]
  ------------------
 5576|   331k|        if (pPrivateKeyTemplate[i].type == CKA_VALUE_BITS) {
  ------------------
  |  |  579|   331k|#define CKA_VALUE_BITS 0x00000160UL
  ------------------
  |  Branch (5576:13): [True: 0, False: 331k]
  ------------------
 5577|      0|            continue;
 5578|      0|        }
 5579|       |
 5580|   331k|        crv = sftk_AddAttributeType(privateKey,
 5581|   331k|                                    sftk_attr_expand(&pPrivateKeyTemplate[i]));
  ------------------
  |  |  587|   331k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 5582|   331k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5582:13): [True: 0, False: 331k]
  ------------------
 5583|      0|            break;
 5584|   331k|    }
 5585|       |
 5586|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5586:9): [True: 0, False: 47.3k]
  ------------------
 5587|      0|        sftk_FreeObject(publicKey);
 5588|      0|        sftk_FreeObject(privateKey);
 5589|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5590|      0|    }
 5591|  47.3k|    sftk_DeleteAttributeType(privateKey, CKA_CLASS);
  ------------------
  |  |  511|  47.3k|#define CKA_CLASS 0x00000000UL
  ------------------
 5592|  47.3k|    sftk_DeleteAttributeType(privateKey, CKA_KEY_TYPE);
  ------------------
  |  |  543|  47.3k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 5593|  47.3k|    sftk_DeleteAttributeType(privateKey, CKA_VALUE);
  ------------------
  |  |  516|  47.3k|#define CKA_VALUE 0x00000011UL
  ------------------
 5594|  47.3k|    sftk_DeleteAttributeType(publicKey, CKA_CLASS);
  ------------------
  |  |  511|  47.3k|#define CKA_CLASS 0x00000000UL
  ------------------
 5595|  47.3k|    sftk_DeleteAttributeType(publicKey, CKA_KEY_TYPE);
  ------------------
  |  |  543|  47.3k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 5596|  47.3k|    sftk_DeleteAttributeType(publicKey, CKA_VALUE);
  ------------------
  |  |  516|  47.3k|#define CKA_VALUE 0x00000011UL
  ------------------
 5597|       |
 5598|       |    /* Now Set up the parameters to generate the key (based on mechanism) */
 5599|  47.3k|    switch (pMechanism->mechanism) {
 5600|      0|        case CKM_RSA_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  719|      0|#define CKM_RSA_PKCS_KEY_PAIR_GEN 0x00000000UL
  ------------------
  |  Branch (5600:9): [True: 0, False: 47.3k]
  ------------------
 5601|       |            /* format the keys */
 5602|      0|            sftk_DeleteAttributeType(publicKey, CKA_MODULUS);
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
 5603|      0|            sftk_DeleteAttributeType(privateKey, CKA_NSS_DB);
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5604|      0|            sftk_DeleteAttributeType(privateKey, CKA_MODULUS);
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
 5605|      0|            sftk_DeleteAttributeType(privateKey, CKA_PRIVATE_EXPONENT);
  ------------------
  |  |  561|      0|#define CKA_PRIVATE_EXPONENT 0x00000123UL
  ------------------
 5606|      0|            sftk_DeleteAttributeType(privateKey, CKA_PUBLIC_EXPONENT);
  ------------------
  |  |  560|      0|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 5607|      0|            sftk_DeleteAttributeType(privateKey, CKA_PRIME_1);
  ------------------
  |  |  562|      0|#define CKA_PRIME_1 0x00000124UL
  ------------------
 5608|      0|            sftk_DeleteAttributeType(privateKey, CKA_PRIME_2);
  ------------------
  |  |  563|      0|#define CKA_PRIME_2 0x00000125UL
  ------------------
 5609|      0|            sftk_DeleteAttributeType(privateKey, CKA_EXPONENT_1);
  ------------------
  |  |  564|      0|#define CKA_EXPONENT_1 0x00000126UL
  ------------------
 5610|      0|            sftk_DeleteAttributeType(privateKey, CKA_EXPONENT_2);
  ------------------
  |  |  565|      0|#define CKA_EXPONENT_2 0x00000127UL
  ------------------
 5611|      0|            sftk_DeleteAttributeType(privateKey, CKA_COEFFICIENT);
  ------------------
  |  |  566|      0|#define CKA_COEFFICIENT 0x00000128UL
  ------------------
 5612|      0|            key_type = CKK_RSA;
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
 5613|      0|            if (public_modulus_bits == 0) {
  ------------------
  |  Branch (5613:17): [True: 0, False: 0]
  ------------------
 5614|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 5615|      0|                break;
 5616|      0|            }
 5617|      0|            if (public_modulus_bits < RSA_MIN_MODULUS_BITS) {
  ------------------
  |  |  151|      0|#define RSA_MIN_MODULUS_BITS 128
  ------------------
  |  Branch (5617:17): [True: 0, False: 0]
  ------------------
 5618|      0|                crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5619|      0|                break;
 5620|      0|            }
 5621|      0|            if (public_modulus_bits % 2 != 0) {
  ------------------
  |  Branch (5621:17): [True: 0, False: 0]
  ------------------
 5622|      0|                crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5623|      0|                break;
 5624|      0|            }
 5625|       |
 5626|       |            /* extract the exponent */
 5627|      0|            crv = sftk_Attribute2SSecItem(NULL, &pubExp, publicKey, CKA_PUBLIC_EXPONENT);
  ------------------
  |  |  560|      0|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 5628|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5628:17): [True: 0, False: 0]
  ------------------
 5629|      0|                break;
 5630|      0|            bitSize = sftk_GetLengthInBits(pubExp.data, pubExp.len);
 5631|      0|            if (bitSize < 2) {
  ------------------
  |  Branch (5631:17): [True: 0, False: 0]
  ------------------
 5632|      0|                crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5633|      0|                SECITEM_ZfreeItem(&pubExp, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pubExp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5634|      0|                break;
 5635|      0|            }
 5636|      0|            crv = sftk_AddAttributeType(privateKey, CKA_PUBLIC_EXPONENT,
  ------------------
  |  |  560|      0|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
 5637|      0|                                        sftk_item_expand(&pubExp));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5638|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5638:17): [True: 0, False: 0]
  ------------------
 5639|      0|                SECITEM_ZfreeItem(&pubExp, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pubExp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5640|      0|                break;
 5641|      0|            }
 5642|       |
 5643|      0|            rsaPriv = RSA_NewKey(public_modulus_bits, &pubExp);
 5644|      0|            SECITEM_ZfreeItem(&pubExp, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&pubExp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5645|      0|            if (rsaPriv == NULL) {
  ------------------
  |  Branch (5645:17): [True: 0, False: 0]
  ------------------
 5646|      0|                if (PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (5646:21): [True: 0, False: 0]
  ------------------
 5647|      0|                    sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5648|      0|                }
 5649|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 5650|      0|                break;
 5651|      0|            }
 5652|       |            /* now fill in the RSA dependent paramenters in the public key */
 5653|      0|            crv = sftk_AddAttributeType(publicKey, CKA_MODULUS,
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
 5654|      0|                                        sftk_item_expand(&rsaPriv->modulus));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5655|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5655:17): [True: 0, False: 0]
  ------------------
 5656|      0|                goto kpg_done;
 5657|       |            /* now fill in the RSA dependent paramenters in the private key */
 5658|      0|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_DB,
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5659|      0|                                        sftk_item_expand(&rsaPriv->modulus));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5660|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5660:17): [True: 0, False: 0]
  ------------------
 5661|      0|                goto kpg_done;
 5662|      0|            crv = sftk_AddAttributeType(privateKey, CKA_MODULUS,
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
 5663|      0|                                        sftk_item_expand(&rsaPriv->modulus));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5664|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5664:17): [True: 0, False: 0]
  ------------------
 5665|      0|                goto kpg_done;
 5666|      0|            crv = sftk_AddAttributeType(privateKey, CKA_PRIVATE_EXPONENT,
  ------------------
  |  |  561|      0|#define CKA_PRIVATE_EXPONENT 0x00000123UL
  ------------------
 5667|      0|                                        sftk_item_expand(&rsaPriv->privateExponent));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5668|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5668:17): [True: 0, False: 0]
  ------------------
 5669|      0|                goto kpg_done;
 5670|      0|            crv = sftk_AddAttributeType(privateKey, CKA_PRIME_1,
  ------------------
  |  |  562|      0|#define CKA_PRIME_1 0x00000124UL
  ------------------
 5671|      0|                                        sftk_item_expand(&rsaPriv->prime1));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5672|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5672:17): [True: 0, False: 0]
  ------------------
 5673|      0|                goto kpg_done;
 5674|      0|            crv = sftk_AddAttributeType(privateKey, CKA_PRIME_2,
  ------------------
  |  |  563|      0|#define CKA_PRIME_2 0x00000125UL
  ------------------
 5675|      0|                                        sftk_item_expand(&rsaPriv->prime2));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5676|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5676:17): [True: 0, False: 0]
  ------------------
 5677|      0|                goto kpg_done;
 5678|      0|            crv = sftk_AddAttributeType(privateKey, CKA_EXPONENT_1,
  ------------------
  |  |  564|      0|#define CKA_EXPONENT_1 0x00000126UL
  ------------------
 5679|      0|                                        sftk_item_expand(&rsaPriv->exponent1));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5680|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5680:17): [True: 0, False: 0]
  ------------------
 5681|      0|                goto kpg_done;
 5682|      0|            crv = sftk_AddAttributeType(privateKey, CKA_EXPONENT_2,
  ------------------
  |  |  565|      0|#define CKA_EXPONENT_2 0x00000127UL
  ------------------
 5683|      0|                                        sftk_item_expand(&rsaPriv->exponent2));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5684|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5684:17): [True: 0, False: 0]
  ------------------
 5685|      0|                goto kpg_done;
 5686|      0|            crv = sftk_AddAttributeType(privateKey, CKA_COEFFICIENT,
  ------------------
  |  |  566|      0|#define CKA_COEFFICIENT 0x00000128UL
  ------------------
 5687|      0|                                        sftk_item_expand(&rsaPriv->coefficient));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5688|      0|        kpg_done:
 5689|       |            /* Should zeroize the contents first, since this func doesn't. */
 5690|      0|            PORT_FreeArena(rsaPriv->arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(rsaPriv->arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5691|      0|            break;
 5692|      0|        case CKM_DSA_KEY_PAIR_GEN:
  ------------------
  |  |  744|      0|#define CKM_DSA_KEY_PAIR_GEN 0x00000010UL
  ------------------
  |  Branch (5692:9): [True: 0, False: 47.3k]
  ------------------
 5693|      0|            sftk_DeleteAttributeType(publicKey, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 5694|      0|            sftk_DeleteAttributeType(privateKey, CKA_NSS_DB);
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5695|      0|            sftk_DeleteAttributeType(privateKey, CKA_PRIME);
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 5696|      0|            sftk_DeleteAttributeType(privateKey, CKA_SUBPRIME);
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 5697|      0|            sftk_DeleteAttributeType(privateKey, CKA_BASE);
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
 5698|      0|            key_type = CKK_DSA;
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
 5699|       |
 5700|       |            /* extract the necessary parameters and copy them to the private key */
 5701|      0|            crv = sftk_Attribute2SSecItem(NULL, &pqgParam.prime, publicKey, CKA_PRIME);
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 5702|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5702:17): [True: 0, False: 0]
  ------------------
 5703|      0|                break;
 5704|      0|            crv = sftk_Attribute2SSecItem(NULL, &pqgParam.subPrime, publicKey,
 5705|      0|                                          CKA_SUBPRIME);
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 5706|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5706:17): [True: 0, False: 0]
  ------------------
 5707|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5708|      0|                break;
 5709|      0|            }
 5710|      0|            crv = sftk_Attribute2SSecItem(NULL, &pqgParam.base, publicKey, CKA_BASE);
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
 5711|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5711:17): [True: 0, False: 0]
  ------------------
 5712|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5713|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5714|      0|                break;
 5715|      0|            }
 5716|      0|            crv = sftk_AddAttributeType(privateKey, CKA_PRIME,
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 5717|      0|                                        sftk_item_expand(&pqgParam.prime));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5718|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5718:17): [True: 0, False: 0]
  ------------------
 5719|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5720|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5721|      0|                SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5722|      0|                break;
 5723|      0|            }
 5724|      0|            crv = sftk_AddAttributeType(privateKey, CKA_SUBPRIME,
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 5725|      0|                                        sftk_item_expand(&pqgParam.subPrime));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5726|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5726:17): [True: 0, False: 0]
  ------------------
 5727|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5728|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5729|      0|                SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5730|      0|                break;
 5731|      0|            }
 5732|      0|            crv = sftk_AddAttributeType(privateKey, CKA_BASE,
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
 5733|      0|                                        sftk_item_expand(&pqgParam.base));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5734|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5734:17): [True: 0, False: 0]
  ------------------
 5735|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5736|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5737|      0|                SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5738|      0|                break;
 5739|      0|            }
 5740|       |
 5741|       |            /*
 5742|       |             * these are checked by DSA_NewKey
 5743|       |             */
 5744|      0|            bitSize = sftk_GetLengthInBits(pqgParam.subPrime.data,
 5745|      0|                                           pqgParam.subPrime.len);
 5746|      0|            if ((bitSize < DSA_MIN_Q_BITS) || (bitSize > DSA_MAX_Q_BITS)) {
  ------------------
  |  |  200|      0|#define DSA_MIN_Q_BITS 160
  ------------------
                          if ((bitSize < DSA_MIN_Q_BITS) || (bitSize > DSA_MAX_Q_BITS)) {
  ------------------
  |  |  199|      0|#define DSA_MAX_Q_BITS 256
  ------------------
  |  Branch (5746:17): [True: 0, False: 0]
  |  Branch (5746:47): [True: 0, False: 0]
  ------------------
 5747|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 5748|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5749|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5750|      0|                SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5751|      0|                break;
 5752|      0|            }
 5753|      0|            bitSize = sftk_GetLengthInBits(pqgParam.prime.data, pqgParam.prime.len);
 5754|      0|            if ((bitSize < DSA_MIN_P_BITS) || (bitSize > DSA_MAX_P_BITS)) {
  ------------------
  |  |  198|      0|#define DSA_MIN_P_BITS 512
  ------------------
                          if ((bitSize < DSA_MIN_P_BITS) || (bitSize > DSA_MAX_P_BITS)) {
  ------------------
  |  |  197|      0|#define DSA_MAX_P_BITS 3072
  ------------------
  |  Branch (5754:17): [True: 0, False: 0]
  |  Branch (5754:47): [True: 0, False: 0]
  ------------------
 5755|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 5756|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5757|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5758|      0|                SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5759|      0|                break;
 5760|      0|            }
 5761|      0|            bitSize = sftk_GetLengthInBits(pqgParam.base.data, pqgParam.base.len);
 5762|      0|            if ((bitSize < 2) || (bitSize > DSA_MAX_P_BITS)) {
  ------------------
  |  |  197|      0|#define DSA_MAX_P_BITS 3072
  ------------------
  |  Branch (5762:17): [True: 0, False: 0]
  |  Branch (5762:34): [True: 0, False: 0]
  ------------------
 5763|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 5764|      0|                SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5765|      0|                SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5766|      0|                SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5767|      0|                break;
 5768|      0|            }
 5769|       |
 5770|       |            /* Generate the key */
 5771|      0|            rv = DSA_NewKey(&pqgParam, &dsaPriv);
 5772|       |
 5773|      0|            SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&pqgParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5774|      0|            SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&pqgParam.subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5775|      0|            SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&pqgParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5776|       |
 5777|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (5777:17): [True: 0, False: 0]
  ------------------
 5778|      0|                if (PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (5778:21): [True: 0, False: 0]
  ------------------
 5779|      0|                    sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5780|      0|                }
 5781|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 5782|      0|                break;
 5783|      0|            }
 5784|       |
 5785|       |            /* store the generated key into the attributes */
 5786|      0|            crv = sftk_AddAttributeType(publicKey, CKA_VALUE,
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 5787|      0|                                        sftk_item_expand(&dsaPriv->publicValue));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5788|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5788:17): [True: 0, False: 0]
  ------------------
 5789|      0|                goto dsagn_done;
 5790|       |
 5791|       |            /* now fill in the RSA dependent paramenters in the private key */
 5792|      0|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_DB,
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5793|      0|                                        sftk_item_expand(&dsaPriv->publicValue));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5794|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5794:17): [True: 0, False: 0]
  ------------------
 5795|      0|                goto dsagn_done;
 5796|      0|            crv = sftk_AddAttributeType(privateKey, CKA_VALUE,
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 5797|      0|                                        sftk_item_expand(&dsaPriv->privateValue));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5798|       |
 5799|      0|        dsagn_done:
 5800|       |            /* should zeroize, since this function doesn't. */
 5801|      0|            PORT_FreeArena(dsaPriv->params.arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(dsaPriv->params.arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5802|      0|            break;
 5803|       |
 5804|  29.0k|        case CKM_DH_PKCS_KEY_PAIR_GEN:
  ------------------
  |  |  758|  29.0k|#define CKM_DH_PKCS_KEY_PAIR_GEN 0x00000020UL
  ------------------
  |  Branch (5804:9): [True: 29.0k, False: 18.2k]
  ------------------
 5805|  29.0k|            sftk_DeleteAttributeType(privateKey, CKA_PRIME);
  ------------------
  |  |  569|  29.0k|#define CKA_PRIME 0x00000130UL
  ------------------
 5806|  29.0k|            sftk_DeleteAttributeType(privateKey, CKA_BASE);
  ------------------
  |  |  571|  29.0k|#define CKA_BASE 0x00000132UL
  ------------------
 5807|  29.0k|            sftk_DeleteAttributeType(privateKey, CKA_VALUE);
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
 5808|  29.0k|            sftk_DeleteAttributeType(privateKey, CKA_NSS_DB);
  ------------------
  |  |  150|  29.0k|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5809|  29.0k|            key_type = CKK_DH;
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
 5810|       |
 5811|       |            /* extract the necessary parameters and copy them to private keys */
 5812|  29.0k|            crv = sftk_Attribute2SSecItem(NULL, &dhParam.prime, publicKey,
 5813|  29.0k|                                          CKA_PRIME);
  ------------------
  |  |  569|  29.0k|#define CKA_PRIME 0x00000130UL
  ------------------
 5814|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5814:17): [True: 0, False: 29.0k]
  ------------------
 5815|      0|                break;
 5816|  29.0k|            crv = sftk_Attribute2SSecItem(NULL, &dhParam.base, publicKey, CKA_BASE);
  ------------------
  |  |  571|  29.0k|#define CKA_BASE 0x00000132UL
  ------------------
 5817|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5817:17): [True: 0, False: 29.0k]
  ------------------
 5818|      0|                SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5819|      0|                break;
 5820|      0|            }
 5821|  29.0k|            crv = sftk_AddAttributeType(privateKey, CKA_PRIME,
  ------------------
  |  |  569|  29.0k|#define CKA_PRIME 0x00000130UL
  ------------------
 5822|  29.0k|                                        sftk_item_expand(&dhParam.prime));
  ------------------
  |  |  588|  29.0k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5823|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5823:17): [True: 0, False: 29.0k]
  ------------------
 5824|      0|                SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5825|      0|                SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5826|      0|                break;
 5827|      0|            }
 5828|  29.0k|            crv = sftk_AddAttributeType(privateKey, CKA_BASE,
  ------------------
  |  |  571|  29.0k|#define CKA_BASE 0x00000132UL
  ------------------
 5829|  29.0k|                                        sftk_item_expand(&dhParam.base));
  ------------------
  |  |  588|  29.0k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5830|  29.0k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5830:17): [True: 0, False: 29.0k]
  ------------------
 5831|      0|                SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5832|      0|                SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5833|      0|                break;
 5834|      0|            }
 5835|  29.0k|            bitSize = sftk_GetLengthInBits(dhParam.prime.data, dhParam.prime.len);
 5836|  29.0k|            if ((bitSize < DH_MIN_P_BITS) || (bitSize > DH_MAX_P_BITS)) {
  ------------------
  |  |  154|  29.0k|#define DH_MIN_P_BITS 128
  ------------------
                          if ((bitSize < DH_MIN_P_BITS) || (bitSize > DH_MAX_P_BITS)) {
  ------------------
  |  |  155|  29.0k|#define DH_MAX_P_BITS 16384
  ------------------
  |  Branch (5836:17): [True: 0, False: 29.0k]
  |  Branch (5836:46): [True: 0, False: 29.0k]
  ------------------
 5837|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 5838|      0|                SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5839|      0|                SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5840|      0|                break;
 5841|      0|            }
 5842|  29.0k|            bitSize = sftk_GetLengthInBits(dhParam.base.data, dhParam.base.len);
 5843|  29.0k|            if ((bitSize < 1) || (bitSize > DH_MAX_P_BITS)) {
  ------------------
  |  |  155|  29.0k|#define DH_MAX_P_BITS 16384
  ------------------
  |  Branch (5843:17): [True: 0, False: 29.0k]
  |  Branch (5843:34): [True: 0, False: 29.0k]
  ------------------
 5844|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 5845|      0|                SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5846|      0|                SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5847|      0|                break;
 5848|      0|            }
 5849|       |
 5850|  29.0k|            rv = DH_NewKey(&dhParam, &dhPriv);
 5851|  29.0k|            SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  110|  29.0k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&dhParam.prime, PR_FALSE);
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
 5852|  29.0k|            SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  110|  29.0k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&dhParam.base, PR_FALSE);
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
 5853|  29.0k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (5853:17): [True: 0, False: 29.0k]
  ------------------
 5854|      0|                if (PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (5854:21): [True: 0, False: 0]
  ------------------
 5855|      0|                    sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5856|      0|                }
 5857|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 5858|      0|                break;
 5859|      0|            }
 5860|       |
 5861|  29.0k|            crv = sftk_AddAttributeType(publicKey, CKA_VALUE,
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
 5862|  29.0k|                                        sftk_item_expand(&dhPriv->publicValue));
  ------------------
  |  |  588|  29.0k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5863|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5863:17): [True: 0, False: 29.0k]
  ------------------
 5864|      0|                goto dhgn_done;
 5865|       |
 5866|  29.0k|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_DB,
  ------------------
  |  |  150|  29.0k|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5867|  29.0k|                                        sftk_item_expand(&dhPriv->publicValue));
  ------------------
  |  |  588|  29.0k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5868|  29.0k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5868:17): [True: 0, False: 29.0k]
  ------------------
 5869|      0|                goto dhgn_done;
 5870|       |
 5871|  29.0k|            crv = sftk_AddAttributeType(privateKey, CKA_VALUE,
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
 5872|  29.0k|                                        sftk_item_expand(&dhPriv->privateValue));
  ------------------
  |  |  588|  29.0k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5873|       |
 5874|  29.0k|        dhgn_done:
 5875|       |            /* should zeroize, since this function doesn't. */
 5876|  29.0k|            PORT_FreeArena(dhPriv->arena, PR_TRUE);
  ------------------
  |  |   61|  29.0k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(dhPriv->arena, PR_TRUE);
  ------------------
  |  |  437|  29.0k|#define PR_TRUE 1
  ------------------
 5877|  29.0k|            break;
 5878|       |
 5879|      1|        case CKM_EC_KEY_PAIR_GEN:
  ------------------
  |  | 1072|      1|#define CKM_EC_KEY_PAIR_GEN 0x00001040UL
  ------------------
  |  Branch (5879:9): [True: 1, False: 47.3k]
  ------------------
 5880|  18.2k|        case CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN:
  ------------------
  |  |  274|  18.2k|#define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN (CKM_NSS + 47)
  |  |  ------------------
  |  |  |  |  162|  18.2k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  18.2k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  18.2k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (5880:9): [True: 18.2k, False: 29.0k]
  ------------------
 5881|  18.2k|            sftk_DeleteAttributeType(privateKey, CKA_EC_PARAMS);
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 5882|  18.2k|            sftk_DeleteAttributeType(privateKey, CKA_VALUE);
  ------------------
  |  |  516|  18.2k|#define CKA_VALUE 0x00000011UL
  ------------------
 5883|  18.2k|            sftk_DeleteAttributeType(privateKey, CKA_NSS_DB);
  ------------------
  |  |  150|  18.2k|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5884|  18.2k|            key_type = CKK_EC;
  ------------------
  |  |  379|  18.2k|#define CKK_EC 0x00000003UL
  ------------------
 5885|       |
 5886|       |            /* extract the necessary parameters and copy them to private keys */
 5887|  18.2k|            crv = sftk_Attribute2SSecItem(NULL, &ecEncodedParams, publicKey,
 5888|  18.2k|                                          CKA_EC_PARAMS);
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 5889|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5889:17): [True: 0, False: 18.2k]
  ------------------
 5890|      0|                break;
 5891|       |
 5892|  18.2k|            crv = sftk_AddAttributeType(privateKey, CKA_EC_PARAMS,
  ------------------
  |  |  602|  18.2k|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 5893|  18.2k|                                        sftk_item_expand(&ecEncodedParams));
  ------------------
  |  |  588|  18.2k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5894|  18.2k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5894:17): [True: 0, False: 18.2k]
  ------------------
 5895|      0|                SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5896|      0|                break;
 5897|      0|            }
 5898|       |
 5899|       |            /* Decode ec params before calling EC_NewKey */
 5900|  18.2k|            rv = EC_DecodeParams(&ecEncodedParams, &ecParams);
 5901|  18.2k|            SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  110|  18.2k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  438|  18.2k|#define PR_FALSE 0
  ------------------
 5902|  18.2k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (5902:17): [True: 44, False: 18.2k]
  ------------------
 5903|     44|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|     44|#define PORT_GetError PORT_GetError_Util
  ------------------
 5904|     44|                break;
 5905|     44|            }
 5906|  18.2k|            rv = EC_NewKey(ecParams, &ecPriv);
 5907|  18.2k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (5907:17): [True: 0, False: 18.2k]
  ------------------
 5908|      0|                if (PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (5908:21): [True: 0, False: 0]
  ------------------
 5909|      0|                    sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5910|      0|                }
 5911|      0|                PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5912|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 5913|      0|                break;
 5914|      0|            }
 5915|       |
 5916|  18.2k|            if (PR_GetEnvSecure("NSS_USE_DECODED_CKA_EC_POINT") ||
  ------------------
  |  Branch (5916:17): [True: 0, False: 18.2k]
  ------------------
 5917|  18.2k|                ecParams->type != ec_params_named) {
  ------------------
  |  Branch (5917:17): [True: 7.42k, False: 10.8k]
  ------------------
 5918|  7.42k|                PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |   61|  7.42k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |  437|  7.42k|#define PR_TRUE 1
  ------------------
 5919|  7.42k|                crv = sftk_AddAttributeType(publicKey, CKA_EC_POINT,
  ------------------
  |  |  604|  7.42k|#define CKA_EC_POINT 0x00000181UL
  ------------------
 5920|  7.42k|                                            sftk_item_expand(&ecPriv->publicValue));
  ------------------
  |  |  588|  7.42k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5921|  10.8k|            } else {
 5922|  10.8k|                PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |   61|  10.8k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |  437|  10.8k|#define PR_TRUE 1
  ------------------
 5923|  10.8k|                SECItem *pubValue = SEC_ASN1EncodeItem(NULL, NULL,
  ------------------
  |  |   89|  10.8k|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
 5924|  10.8k|                                                       &ecPriv->publicValue,
 5925|  10.8k|                                                       SEC_ASN1_GET(SEC_OctetStringTemplate));
  ------------------
  |  |  188|  10.8k|#define SEC_ASN1_GET(x) x
  ------------------
 5926|  10.8k|                if (!pubValue) {
  ------------------
  |  Branch (5926:21): [True: 0, False: 10.8k]
  ------------------
 5927|      0|                    crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 5928|      0|                    goto ecgn_done;
 5929|      0|                }
 5930|  10.8k|                crv = sftk_AddAttributeType(publicKey, CKA_EC_POINT,
  ------------------
  |  |  604|  10.8k|#define CKA_EC_POINT 0x00000181UL
  ------------------
 5931|  10.8k|                                            sftk_item_expand(pubValue));
  ------------------
  |  |  588|  10.8k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5932|  10.8k|                SECITEM_ZfreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  110|  10.8k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(pubValue, PR_TRUE);
  ------------------
  |  |  437|  10.8k|#define PR_TRUE 1
  ------------------
 5933|  10.8k|            }
 5934|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5934:17): [True: 0, False: 18.2k]
  ------------------
 5935|      0|                goto ecgn_done;
 5936|       |
 5937|  18.2k|            crv = sftk_AddAttributeType(privateKey, CKA_VALUE,
  ------------------
  |  |  516|  18.2k|#define CKA_VALUE 0x00000011UL
  ------------------
 5938|  18.2k|                                        sftk_item_expand(&ecPriv->privateValue));
  ------------------
  |  |  588|  18.2k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5939|  18.2k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  18.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5939:17): [True: 0, False: 18.2k]
  ------------------
 5940|      0|                goto ecgn_done;
 5941|       |
 5942|  18.2k|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_DB,
  ------------------
  |  |  150|  18.2k|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5943|  18.2k|                                        sftk_item_expand(&ecPriv->publicValue));
  ------------------
  |  |  588|  18.2k|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5944|  18.2k|        ecgn_done:
 5945|       |            /* should zeroize, since this function doesn't. */
 5946|  18.2k|            PORT_FreeArena(ecPriv->ecParams.arena, PR_TRUE);
  ------------------
  |  |   61|  18.2k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(ecPriv->ecParams.arena, PR_TRUE);
  ------------------
  |  |  437|  18.2k|#define PR_TRUE 1
  ------------------
 5947|  18.2k|            break;
 5948|       |
 5949|      0|        case CKM_NSS_KYBER_KEY_PAIR_GEN:
  ------------------
  |  |  267|      0|#define CKM_NSS_KYBER_KEY_PAIR_GEN (CKM_NSS + 45)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (5949:9): [True: 0, False: 47.3k]
  ------------------
 5950|      0|        case CKM_NSS_ML_KEM_KEY_PAIR_GEN:
  ------------------
  |  |  277|      0|#define CKM_NSS_ML_KEM_KEY_PAIR_GEN (CKM_NSS + 48)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (5950:9): [True: 0, False: 47.3k]
  ------------------
 5951|      0|            sftk_DeleteAttributeType(privateKey, CKA_NSS_DB);
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5952|      0|            key_type = CKK_NSS_KYBER;
  ------------------
  |  |   58|      0|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|      0|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|      0|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5953|       |
 5954|      0|            SECItem privKey = { siBuffer, NULL, 0 };
 5955|      0|            SECItem pubKey = { siBuffer, NULL, 0 };
 5956|      0|            KyberParams kyberParams = sftk_kyber_PK11ParamToInternal(ckKyberParamSet);
 5957|      0|            if (!sftk_kyber_AllocPrivKeyItem(kyberParams, &privKey)) {
  ------------------
  |  Branch (5957:17): [True: 0, False: 0]
  ------------------
 5958|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5959|      0|                goto kyber_done;
 5960|      0|            }
 5961|      0|            if (!sftk_kyber_AllocPubKeyItem(kyberParams, &pubKey)) {
  ------------------
  |  Branch (5961:17): [True: 0, False: 0]
  ------------------
 5962|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5963|      0|                goto kyber_done;
 5964|      0|            }
 5965|      0|            rv = Kyber_NewKey(kyberParams, NULL, &privKey, &pubKey);
 5966|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (5966:17): [True: 0, False: 0]
  ------------------
 5967|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 5968|      0|                goto kyber_done;
 5969|      0|            }
 5970|       |
 5971|      0|            crv = sftk_AddAttributeType(publicKey, CKA_VALUE, sftk_item_expand(&pubKey));
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
                          crv = sftk_AddAttributeType(publicKey, CKA_VALUE, sftk_item_expand(&pubKey));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5972|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5972:17): [True: 0, False: 0]
  ------------------
 5973|      0|                goto kyber_done;
 5974|      0|            }
 5975|      0|            crv = sftk_AddAttributeType(publicKey, CKA_NSS_PARAMETER_SET,
  ------------------
  |  |  113|      0|#define CKA_NSS_PARAMETER_SET (CKA_NSS + 40)
  |  |  ------------------
  |  |  |  |   77|      0|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|      0|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5976|      0|                                        &ckKyberParamSet, sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE));
 5977|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5977:17): [True: 0, False: 0]
  ------------------
 5978|      0|                goto kyber_done;
 5979|      0|            }
 5980|      0|            crv = sftk_AddAttributeType(privateKey, CKA_VALUE,
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 5981|      0|                                        sftk_item_expand(&privKey));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5982|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5982:17): [True: 0, False: 0]
  ------------------
 5983|      0|                goto kyber_done;
 5984|      0|            }
 5985|      0|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_PARAMETER_SET,
  ------------------
  |  |  113|      0|#define CKA_NSS_PARAMETER_SET (CKA_NSS + 40)
  |  |  ------------------
  |  |  |  |   77|      0|#define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  692|      0|#define CKA_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKA_NSS (CKA_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5986|      0|                                        &ckKyberParamSet, sizeof(CK_NSS_KEM_PARAMETER_SET_TYPE));
 5987|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5987:17): [True: 0, False: 0]
  ------------------
 5988|      0|                goto kyber_done;
 5989|      0|            }
 5990|      0|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_DB,
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 5991|      0|                                        sftk_item_expand(&pubKey));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 5992|      0|        kyber_done:
 5993|      0|            SECITEM_ZfreeItem(&privKey, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&privKey, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5994|      0|            SECITEM_FreeItem(&pubKey, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(&pubKey, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5995|      0|            break;
 5996|       |
 5997|      0|        case CKM_EC_MONTGOMERY_KEY_PAIR_GEN:
  ------------------
  |  | 1173|      0|#define CKM_EC_MONTGOMERY_KEY_PAIR_GEN 0x00001056UL
  ------------------
  |  Branch (5997:9): [True: 0, False: 47.3k]
  ------------------
 5998|      0|        case CKM_EC_EDWARDS_KEY_PAIR_GEN:
  ------------------
  |  | 1172|      0|#define CKM_EC_EDWARDS_KEY_PAIR_GEN 0x00001055UL
  ------------------
  |  Branch (5998:9): [True: 0, False: 47.3k]
  ------------------
 5999|      0|            sftk_DeleteAttributeType(privateKey, CKA_EC_PARAMS);
  ------------------
  |  |  602|      0|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 6000|      0|            sftk_DeleteAttributeType(privateKey, CKA_VALUE);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 6001|      0|            sftk_DeleteAttributeType(privateKey, CKA_NSS_DB);
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 6002|      0|            key_type = (pMechanism->mechanism == CKM_EC_EDWARDS_KEY_PAIR_GEN) ? CKK_EC_EDWARDS : CKK_EC_MONTGOMERY;
  ------------------
  |  | 1172|      0|#define CKM_EC_EDWARDS_KEY_PAIR_GEN 0x00001055UL
  ------------------
                          key_type = (pMechanism->mechanism == CKM_EC_EDWARDS_KEY_PAIR_GEN) ? CKK_EC_EDWARDS : CKK_EC_MONTGOMERY;
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
                          key_type = (pMechanism->mechanism == CKM_EC_EDWARDS_KEY_PAIR_GEN) ? CKK_EC_EDWARDS : CKK_EC_MONTGOMERY;
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (6002:24): [True: 0, False: 0]
  ------------------
 6003|       |
 6004|       |            /* extract the necessary parameters and copy them to private keys */
 6005|      0|            crv = sftk_Attribute2SSecItem(NULL, &ecEncodedParams, publicKey,
 6006|      0|                                          CKA_EC_PARAMS);
  ------------------
  |  |  602|      0|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 6007|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6007:17): [True: 0, False: 0]
  ------------------
 6008|      0|                break;
 6009|      0|            }
 6010|       |
 6011|      0|            crv = sftk_AddAttributeType(privateKey, CKA_EC_PARAMS,
  ------------------
  |  |  602|      0|#define CKA_EC_PARAMS 0x00000180UL
  ------------------
 6012|      0|                                        sftk_item_expand(&ecEncodedParams));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 6013|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6013:17): [True: 0, False: 0]
  ------------------
 6014|      0|                SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6015|      0|                break;
 6016|      0|            }
 6017|       |
 6018|       |            /* Decode ec params before calling EC_NewKey */
 6019|      0|            rv = EC_DecodeParams(&ecEncodedParams, &ecParams);
 6020|      0|            SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&ecEncodedParams, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6021|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (6021:17): [True: 0, False: 0]
  ------------------
 6022|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 6023|      0|                break;
 6024|      0|            }
 6025|       |
 6026|      0|            rv = EC_NewKey(ecParams, &ecPriv);
 6027|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (6027:17): [True: 0, False: 0]
  ------------------
 6028|      0|                if (PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (6028:21): [True: 0, False: 0]
  ------------------
 6029|      0|                    sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6030|      0|                }
 6031|      0|                PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6032|      0|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 6033|      0|                break;
 6034|      0|            }
 6035|      0|            PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(ecParams->arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6036|      0|            crv = sftk_AddAttributeType(publicKey, CKA_EC_POINT,
  ------------------
  |  |  604|      0|#define CKA_EC_POINT 0x00000181UL
  ------------------
 6037|      0|                                        sftk_item_expand(&ecPriv->publicValue));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 6038|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6038:17): [True: 0, False: 0]
  ------------------
 6039|      0|                goto edgn_done;
 6040|       |
 6041|      0|            crv = sftk_AddAttributeType(privateKey, CKA_VALUE,
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 6042|      0|                                        sftk_item_expand(&ecPriv->privateValue));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 6043|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6043:17): [True: 0, False: 0]
  ------------------
 6044|      0|                goto edgn_done;
 6045|       |
 6046|      0|            crv = sftk_AddAttributeType(privateKey, CKA_NSS_DB,
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
 6047|      0|                                        sftk_item_expand(&ecPriv->publicValue));
  ------------------
  |  |  588|      0|#define sftk_item_expand(ip) (ip)->data, (ip)->len
  ------------------
 6048|      0|        edgn_done:
 6049|       |            /* should zeroize, since this function doesn't. */
 6050|      0|            PORT_FreeArena(ecPriv->ecParams.arena, PR_TRUE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(ecPriv->ecParams.arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6051|      0|            break;
 6052|       |
 6053|      0|        default:
  ------------------
  |  Branch (6053:9): [True: 0, False: 47.3k]
  ------------------
 6054|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 6055|  47.3k|    }
 6056|       |
 6057|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6057:9): [True: 44, False: 47.3k]
  ------------------
 6058|     44|        sftk_FreeObject(privateKey);
 6059|     44|        sftk_FreeObject(publicKey);
 6060|     44|        return crv;
 6061|     44|    }
 6062|       |
 6063|       |    /* Add the class, key_type The loop lets us check errors blow out
 6064|       |     *  on errors and clean up at the bottom */
 6065|  47.3k|    session = NULL; /* make pedtantic happy... session cannot leave the*/
 6066|       |                    /* loop below NULL unless an error is set... */
 6067|  47.3k|    do {
 6068|  47.3k|        crv = sftk_AddAttributeType(privateKey, CKA_CLASS, &privClass,
  ------------------
  |  |  511|  47.3k|#define CKA_CLASS 0x00000000UL
  ------------------
 6069|  47.3k|                                    sizeof(CK_OBJECT_CLASS));
 6070|  47.3k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6070:13): [True: 0, False: 47.3k]
  ------------------
 6071|      0|            break;
 6072|  47.3k|        crv = sftk_AddAttributeType(publicKey, CKA_CLASS, &pubClass,
  ------------------
  |  |  511|  47.3k|#define CKA_CLASS 0x00000000UL
  ------------------
 6073|  47.3k|                                    sizeof(CK_OBJECT_CLASS));
 6074|  47.3k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6074:13): [True: 0, False: 47.3k]
  ------------------
 6075|      0|            break;
 6076|  47.3k|        crv = sftk_AddAttributeType(privateKey, CKA_KEY_TYPE, &key_type,
  ------------------
  |  |  543|  47.3k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 6077|  47.3k|                                    sizeof(CK_KEY_TYPE));
 6078|  47.3k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6078:13): [True: 0, False: 47.3k]
  ------------------
 6079|      0|            break;
 6080|  47.3k|        crv = sftk_AddAttributeType(publicKey, CKA_KEY_TYPE, &key_type,
  ------------------
  |  |  543|  47.3k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 6081|  47.3k|                                    sizeof(CK_KEY_TYPE));
 6082|  47.3k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6082:13): [True: 0, False: 47.3k]
  ------------------
 6083|      0|            break;
 6084|  47.3k|        session = sftk_SessionFromHandle(hSession);
 6085|  47.3k|        if (session == NULL)
  ------------------
  |  Branch (6085:13): [True: 0, False: 47.3k]
  ------------------
 6086|      0|            crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 6087|  47.3k|    } while (0);
  ------------------
  |  Branch (6087:14): [Folded - Ignored]
  ------------------
 6088|       |
 6089|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6089:9): [True: 0, False: 47.3k]
  ------------------
 6090|      0|        sftk_FreeObject(privateKey);
 6091|      0|        sftk_FreeObject(publicKey);
 6092|      0|        return crv;
 6093|      0|    }
 6094|       |
 6095|       |    /*
 6096|       |     * handle the base object cleanup for the public Key
 6097|       |     */
 6098|  47.3k|    crv = sftk_handleObject(privateKey, session);
 6099|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6099:9): [True: 0, False: 47.3k]
  ------------------
 6100|      0|        sftk_FreeSession(session);
 6101|      0|        sftk_FreeObject(privateKey);
 6102|      0|        sftk_FreeObject(publicKey);
 6103|      0|        return crv;
 6104|      0|    }
 6105|       |
 6106|       |    /*
 6107|       |     * handle the base object cleanup for the private Key
 6108|       |     * If we have any problems, we destroy the public Key we've
 6109|       |     * created and linked.
 6110|       |     */
 6111|  47.3k|    crv = sftk_handleObject(publicKey, session);
 6112|  47.3k|    sftk_FreeSession(session);
 6113|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6113:9): [True: 0, False: 47.3k]
  ------------------
 6114|      0|        sftk_FreeObject(publicKey);
 6115|      0|        NSC_DestroyObject(hSession, privateKey->handle);
 6116|      0|        sftk_FreeObject(privateKey);
 6117|      0|        return crv;
 6118|      0|    }
 6119|  47.3k|    if (sftk_isTrue(privateKey, CKA_SENSITIVE)) {
  ------------------
  |  |  546|  47.3k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (6119:9): [True: 0, False: 47.3k]
  ------------------
 6120|      0|        crv = sftk_forceAttribute(privateKey, CKA_ALWAYS_SENSITIVE,
  ------------------
  |  |  588|      0|#define CKA_ALWAYS_SENSITIVE 0x00000165UL
  ------------------
 6121|      0|                                  &cktrue, sizeof(CK_BBOOL));
 6122|      0|    }
 6123|  47.3k|    if (crv == CKR_OK && sftk_isTrue(publicKey, CKA_SENSITIVE)) {
  ------------------
  |  | 1388|  94.6k|#define CKR_OK 0x00000000UL
  ------------------
                  if (crv == CKR_OK && sftk_isTrue(publicKey, CKA_SENSITIVE)) {
  ------------------
  |  |  546|  47.3k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (6123:9): [True: 47.3k, False: 0]
  |  Branch (6123:26): [True: 0, False: 47.3k]
  ------------------
 6124|      0|        crv = sftk_forceAttribute(publicKey, CKA_ALWAYS_SENSITIVE,
  ------------------
  |  |  588|      0|#define CKA_ALWAYS_SENSITIVE 0x00000165UL
  ------------------
 6125|      0|                                  &cktrue, sizeof(CK_BBOOL));
 6126|      0|    }
 6127|  47.3k|    if (crv == CKR_OK && !sftk_isTrue(privateKey, CKA_EXTRACTABLE)) {
  ------------------
  |  | 1388|  94.6k|#define CKR_OK 0x00000000UL
  ------------------
                  if (crv == CKR_OK && !sftk_isTrue(privateKey, CKA_EXTRACTABLE)) {
  ------------------
  |  |  585|  47.3k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  |  Branch (6127:9): [True: 47.3k, False: 0]
  |  Branch (6127:26): [True: 0, False: 47.3k]
  ------------------
 6128|      0|        crv = sftk_forceAttribute(privateKey, CKA_NEVER_EXTRACTABLE,
  ------------------
  |  |  587|      0|#define CKA_NEVER_EXTRACTABLE 0x00000164UL
  ------------------
 6129|      0|                                  &cktrue, sizeof(CK_BBOOL));
 6130|      0|    }
 6131|  47.3k|    if (crv == CKR_OK && !sftk_isTrue(publicKey, CKA_EXTRACTABLE)) {
  ------------------
  |  | 1388|  94.6k|#define CKR_OK 0x00000000UL
  ------------------
                  if (crv == CKR_OK && !sftk_isTrue(publicKey, CKA_EXTRACTABLE)) {
  ------------------
  |  |  585|  47.3k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  |  Branch (6131:9): [True: 47.3k, False: 0]
  |  Branch (6131:26): [True: 47.3k, False: 0]
  ------------------
 6132|  47.3k|        crv = sftk_forceAttribute(publicKey, CKA_NEVER_EXTRACTABLE,
  ------------------
  |  |  587|  47.3k|#define CKA_NEVER_EXTRACTABLE 0x00000164UL
  ------------------
 6133|  47.3k|                                  &cktrue, sizeof(CK_BBOOL));
 6134|  47.3k|    }
 6135|       |
 6136|  47.3k|    if (crv == CKR_OK && pMechanism->mechanism != CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN && key_type != CKK_NSS_KYBER) {
  ------------------
  |  | 1388|  94.6k|#define CKR_OK 0x00000000UL
  ------------------
                  if (crv == CKR_OK && pMechanism->mechanism != CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN && key_type != CKK_NSS_KYBER) {
  ------------------
  |  |  274|  94.6k|#define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN (CKM_NSS + 47)
  |  |  ------------------
  |  |  |  |  162|  47.3k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  47.3k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  47.3k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
                  if (crv == CKR_OK && pMechanism->mechanism != CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN && key_type != CKK_NSS_KYBER) {
  ------------------
  |  |   58|  29.0k|#define CKK_NSS_KYBER (CKK_NSS + 5)
  |  |  ------------------
  |  |  |  |   49|  29.0k|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|  29.0k|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  29.0k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (6136:9): [True: 47.3k, False: 0]
  |  Branch (6136:26): [True: 29.0k, False: 18.2k]
  |  Branch (6136:99): [True: 29.0k, False: 0]
  ------------------
 6137|       |        /* Perform FIPS 140-2 pairwise consistency check. */
 6138|  29.0k|        crv = sftk_PairwiseConsistencyCheck(hSession, slot,
 6139|  29.0k|                                            publicKey, privateKey, key_type);
 6140|  29.0k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6140:13): [True: 0, False: 29.0k]
  ------------------
 6141|      0|            if (sftk_audit_enabled) {
  ------------------
  |  Branch (6141:17): [True: 0, False: 0]
  ------------------
 6142|      0|                char msg[128];
 6143|      0|                PR_snprintf(msg, sizeof msg,
 6144|      0|                            "C_GenerateKeyPair(hSession=0x%08lX, "
 6145|      0|                            "pMechanism->mechanism=0x%08lX)=0x%08lX "
 6146|      0|                            "self-test: pair-wise consistency test failed",
 6147|      0|                            (PRUint32)hSession, (PRUint32)pMechanism->mechanism,
 6148|      0|                            (PRUint32)crv);
 6149|      0|                sftk_LogAuditMessage(NSS_AUDIT_ERROR, NSS_AUDIT_SELF_TEST, msg);
 6150|      0|            }
 6151|      0|        }
 6152|  29.0k|    }
 6153|       |
 6154|  47.3k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6154:9): [True: 0, False: 47.3k]
  ------------------
 6155|      0|        NSC_DestroyObject(hSession, publicKey->handle);
 6156|      0|        sftk_FreeObject(publicKey);
 6157|      0|        NSC_DestroyObject(hSession, privateKey->handle);
 6158|      0|        sftk_FreeObject(privateKey);
 6159|      0|        return crv;
 6160|      0|    }
 6161|  47.3k|    *phPrivateKey = privateKey->handle;
 6162|  47.3k|    *phPublicKey = publicKey->handle;
 6163|  47.3k|    sftk_FreeObject(publicKey);
 6164|  47.3k|    sftk_FreeObject(privateKey);
 6165|       |
 6166|  47.3k|    return CKR_OK;
  ------------------
  |  | 1388|  47.3k|#define CKR_OK 0x00000000UL
  ------------------
 6167|  47.3k|}
NSC_WrapKey:
 6384|  33.9k|{
 6385|  33.9k|    SFTKSession *session;
 6386|  33.9k|    SFTKAttribute *attribute;
 6387|  33.9k|    SFTKObject *key;
 6388|  33.9k|    CK_RV crv;
 6389|       |
 6390|  33.9k|    CHECK_FORK();
 6391|       |
 6392|  33.9k|    session = sftk_SessionFromHandle(hSession);
 6393|  33.9k|    if (session == NULL) {
  ------------------
  |  Branch (6393:9): [True: 0, False: 33.9k]
  ------------------
 6394|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 6395|      0|    }
 6396|       |
 6397|  33.9k|    key = sftk_ObjectFromHandle(hKey, session);
 6398|  33.9k|    if (key == NULL) {
  ------------------
  |  Branch (6398:9): [True: 0, False: 33.9k]
  ------------------
 6399|      0|        sftk_FreeSession(session);
 6400|      0|        return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 6401|      0|    }
 6402|       |
 6403|  33.9k|    switch (key->objclass) {
 6404|  33.9k|        case CKO_SECRET_KEY: {
  ------------------
  |  |  329|  33.9k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  |  Branch (6404:9): [True: 33.9k, False: 0]
  ------------------
 6405|  33.9k|            SFTKSessionContext *context = NULL;
 6406|  33.9k|            SECItem pText;
 6407|       |
 6408|  33.9k|            attribute = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  33.9k|#define CKA_VALUE 0x00000011UL
  ------------------
 6409|       |
 6410|  33.9k|            if (attribute == NULL) {
  ------------------
  |  Branch (6410:17): [True: 0, False: 33.9k]
  ------------------
 6411|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 6412|      0|                break;
 6413|      0|            }
 6414|  33.9k|            crv = sftk_CryptInit(hSession, pMechanism, hWrappingKey,
 6415|  33.9k|                                 CKA_WRAP, CKA_WRAP, SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  549|  33.9k|#define CKA_WRAP 0x00000106UL
  ------------------
                                               CKA_WRAP, CKA_WRAP, SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  549|  33.9k|#define CKA_WRAP 0x00000106UL
  ------------------
                                               CKA_WRAP, CKA_WRAP, SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  437|  33.9k|#define PR_TRUE 1
  ------------------
 6416|  33.9k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  33.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6416:17): [True: 0, False: 33.9k]
  ------------------
 6417|      0|                sftk_FreeAttribute(attribute);
 6418|      0|                break;
 6419|      0|            }
 6420|       |
 6421|  33.9k|            pText.type = siBuffer;
 6422|  33.9k|            pText.data = (unsigned char *)attribute->attrib.pValue;
 6423|  33.9k|            pText.len = attribute->attrib.ulValueLen;
 6424|       |
 6425|       |            /* Find out if this is a block cipher. */
 6426|  33.9k|            crv = sftk_GetContext(hSession, &context, SFTK_ENCRYPT, PR_FALSE, NULL);
  ------------------
  |  |  438|  33.9k|#define PR_FALSE 0
  ------------------
 6427|  33.9k|            if (crv != CKR_OK || !context)
  ------------------
  |  | 1388|  67.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6427:17): [True: 0, False: 33.9k]
  |  Branch (6427:34): [True: 0, False: 33.9k]
  ------------------
 6428|      0|                break;
 6429|  33.9k|            if (context->blockSize > 1) {
  ------------------
  |  Branch (6429:17): [True: 33.9k, False: 3]
  ------------------
 6430|  33.9k|                unsigned int remainder = pText.len % context->blockSize;
 6431|  33.9k|                if (!context->doPad && remainder) {
  ------------------
  |  Branch (6431:21): [True: 33.9k, False: 0]
  |  Branch (6431:40): [True: 0, False: 33.9k]
  ------------------
 6432|       |                    /* When wrapping secret keys with unpadded block ciphers,
 6433|       |                    ** the keys are zero padded, if necessary, to fill out
 6434|       |                    ** a full block.
 6435|       |                    */
 6436|      0|                    pText.len += context->blockSize - remainder;
 6437|      0|                    pText.data = PORT_ZAlloc(pText.len);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 6438|      0|                    if (pText.data)
  ------------------
  |  Branch (6438:25): [True: 0, False: 0]
  ------------------
 6439|      0|                        memcpy(pText.data, attribute->attrib.pValue,
 6440|      0|                               attribute->attrib.ulValueLen);
 6441|      0|                    else {
 6442|      0|                        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 6443|      0|                        break;
 6444|      0|                    }
 6445|      0|                }
 6446|  33.9k|            }
 6447|       |
 6448|  33.9k|            crv = NSC_Encrypt(hSession, (CK_BYTE_PTR)pText.data,
 6449|  33.9k|                              pText.len, pWrappedKey, pulWrappedKeyLen);
 6450|       |            /* always force a finalize, both on errors and when
 6451|       |             * we are just getting the size */
 6452|  33.9k|            if (crv != CKR_OK || pWrappedKey == NULL) {
  ------------------
  |  | 1388|  67.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6452:17): [True: 0, False: 33.9k]
  |  Branch (6452:34): [True: 0, False: 33.9k]
  ------------------
 6453|      0|                CK_RV lcrv;
 6454|      0|                lcrv = sftk_GetContext(hSession, &context,
 6455|      0|                                       SFTK_ENCRYPT, PR_FALSE, NULL);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6456|      0|                sftk_SetContextByType(session, SFTK_ENCRYPT, NULL);
 6457|      0|                if (lcrv == CKR_OK && context) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6457:21): [True: 0, False: 0]
  |  Branch (6457:39): [True: 0, False: 0]
  ------------------
 6458|      0|                    sftk_FreeContext(context);
 6459|      0|                }
 6460|      0|            }
 6461|       |
 6462|  33.9k|            if (pText.data != (unsigned char *)attribute->attrib.pValue)
  ------------------
  |  Branch (6462:17): [True: 0, False: 33.9k]
  ------------------
 6463|      0|                PORT_ZFree(pText.data, pText.len);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 6464|  33.9k|            sftk_FreeAttribute(attribute);
 6465|  33.9k|            break;
 6466|  33.9k|        }
 6467|       |
 6468|      0|        case CKO_PRIVATE_KEY: {
  ------------------
  |  |  328|      0|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (6468:9): [True: 0, False: 33.9k]
  ------------------
 6469|      0|            SECItem *bpki = sftk_PackagePrivateKey(key, &crv);
 6470|      0|            SFTKSessionContext *context = NULL;
 6471|       |
 6472|      0|            if (!bpki) {
  ------------------
  |  Branch (6472:17): [True: 0, False: 0]
  ------------------
 6473|      0|                break;
 6474|      0|            }
 6475|       |
 6476|      0|            crv = sftk_CryptInit(hSession, pMechanism, hWrappingKey,
 6477|      0|                                 CKA_WRAP, CKA_WRAP, SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  549|      0|#define CKA_WRAP 0x00000106UL
  ------------------
                                               CKA_WRAP, CKA_WRAP, SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  549|      0|#define CKA_WRAP 0x00000106UL
  ------------------
                                               CKA_WRAP, CKA_WRAP, SFTK_ENCRYPT, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6478|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6478:17): [True: 0, False: 0]
  ------------------
 6479|      0|                SECITEM_ZfreeItem(bpki, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(bpki, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6480|      0|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 6481|      0|                break;
 6482|      0|            }
 6483|       |
 6484|      0|            crv = NSC_Encrypt(hSession, bpki->data, bpki->len,
 6485|      0|                              pWrappedKey, pulWrappedKeyLen);
 6486|       |            /* always force a finalize */
 6487|      0|            if (crv != CKR_OK || pWrappedKey == NULL) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6487:17): [True: 0, False: 0]
  |  Branch (6487:34): [True: 0, False: 0]
  ------------------
 6488|      0|                CK_RV lcrv;
 6489|      0|                lcrv = sftk_GetContext(hSession, &context,
 6490|      0|                                       SFTK_ENCRYPT, PR_FALSE, NULL);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6491|      0|                sftk_SetContextByType(session, SFTK_ENCRYPT, NULL);
 6492|      0|                if (lcrv == CKR_OK && context) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6492:21): [True: 0, False: 0]
  |  Branch (6492:39): [True: 0, False: 0]
  ------------------
 6493|      0|                    sftk_FreeContext(context);
 6494|      0|                }
 6495|      0|            }
 6496|      0|            SECITEM_ZfreeItem(bpki, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(bpki, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 6497|      0|            break;
 6498|      0|        }
 6499|       |
 6500|      0|        default:
  ------------------
  |  Branch (6500:9): [True: 0, False: 33.9k]
  ------------------
 6501|      0|            crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 6502|      0|            break;
 6503|  33.9k|    }
 6504|  33.9k|    sftk_FreeObject(key);
 6505|  33.9k|    sftk_FreeSession(session);
 6506|  33.9k|    return sftk_mapWrap(crv);
 6507|  33.9k|}
NSC_UnwrapKey:
 6814|  11.9k|{
 6815|  11.9k|    SFTKObject *key = NULL;
 6816|  11.9k|    SFTKSession *session;
 6817|  11.9k|    CK_ULONG key_length = 0;
 6818|  11.9k|    unsigned char *buf = NULL;
 6819|  11.9k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  11.9k|#define CKR_OK 0x00000000UL
  ------------------
 6820|  11.9k|    int i;
 6821|  11.9k|    CK_ULONG bsize = ulWrappedKeyLen;
 6822|  11.9k|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 6823|  11.9k|    SECItem bpki;
 6824|  11.9k|    CK_OBJECT_CLASS target_type = CKO_SECRET_KEY;
  ------------------
  |  |  329|  11.9k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 6825|       |
 6826|  11.9k|    CHECK_FORK();
 6827|       |
 6828|  11.9k|    if (!slot) {
  ------------------
  |  Branch (6828:9): [True: 0, False: 11.9k]
  ------------------
 6829|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 6830|      0|    }
 6831|       |    /*
 6832|       |     * now lets create an object to hang the attributes off of
 6833|       |     */
 6834|  11.9k|    key = sftk_NewObject(slot); /* fill in the handle later */
 6835|  11.9k|    if (key == NULL) {
  ------------------
  |  Branch (6835:9): [True: 0, False: 11.9k]
  ------------------
 6836|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 6837|      0|    }
 6838|       |
 6839|       |    /*
 6840|       |     * load the template values into the object
 6841|       |     */
 6842|  47.8k|    for (i = 0; i < (int)ulAttributeCount; i++) {
  ------------------
  |  Branch (6842:17): [True: 35.9k, False: 11.9k]
  ------------------
 6843|  35.9k|        if (pTemplate[i].type == CKA_VALUE_LEN) {
  ------------------
  |  |  580|  35.9k|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (6843:13): [True: 0, False: 35.9k]
  ------------------
 6844|      0|            key_length = *(CK_ULONG *)pTemplate[i].pValue;
 6845|      0|            continue;
 6846|      0|        }
 6847|  35.9k|        if (pTemplate[i].type == CKA_CLASS) {
  ------------------
  |  |  511|  35.9k|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (6847:13): [True: 11.9k, False: 23.9k]
  ------------------
 6848|  11.9k|            target_type = *(CK_OBJECT_CLASS *)pTemplate[i].pValue;
 6849|  11.9k|        }
 6850|  35.9k|        crv = sftk_AddAttributeType(key, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|  35.9k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 6851|  35.9k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  35.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6851:13): [True: 0, False: 35.9k]
  ------------------
 6852|      0|            break;
 6853|  35.9k|    }
 6854|  11.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  11.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6854:9): [True: 0, False: 11.9k]
  ------------------
 6855|      0|        sftk_FreeObject(key);
 6856|      0|        return crv;
 6857|      0|    }
 6858|       |
 6859|  11.9k|    crv = sftk_CryptInit(hSession, pMechanism, hUnwrappingKey, CKA_UNWRAP,
  ------------------
  |  |  550|  11.9k|#define CKA_UNWRAP 0x00000107UL
  ------------------
 6860|  11.9k|                         CKA_UNWRAP, SFTK_DECRYPT, PR_FALSE);
  ------------------
  |  |  550|  11.9k|#define CKA_UNWRAP 0x00000107UL
  ------------------
                                       CKA_UNWRAP, SFTK_DECRYPT, PR_FALSE);
  ------------------
  |  |  438|  11.9k|#define PR_FALSE 0
  ------------------
 6861|  11.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  11.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6861:9): [True: 0, False: 11.9k]
  ------------------
 6862|      0|        sftk_FreeObject(key);
 6863|      0|        return sftk_mapWrap(crv);
 6864|      0|    }
 6865|       |
 6866|       |    /* allocate the buffer to decrypt into
 6867|       |     * this assumes the unwrapped key is never larger than the
 6868|       |     * wrapped key. For all the mechanisms we support this is true */
 6869|  11.9k|    buf = (unsigned char *)PORT_Alloc(ulWrappedKeyLen);
  ------------------
  |  |   52|  11.9k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 6870|  11.9k|    bsize = ulWrappedKeyLen;
 6871|       |
 6872|  11.9k|    crv = NSC_Decrypt(hSession, pWrappedKey, ulWrappedKeyLen, buf, &bsize);
 6873|  11.9k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  11.9k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6873:9): [True: 11.2k, False: 772]
  ------------------
 6874|  11.2k|        sftk_FreeObject(key);
 6875|  11.2k|        PORT_Free(buf);
  ------------------
  |  |   60|  11.2k|#define PORT_Free PORT_Free_Util
  ------------------
 6876|  11.2k|        return sftk_mapWrap(crv);
 6877|  11.2k|    }
 6878|       |
 6879|    772|    switch (target_type) {
 6880|    772|        case CKO_SECRET_KEY:
  ------------------
  |  |  329|    772|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  |  Branch (6880:9): [True: 772, False: 0]
  ------------------
 6881|    772|            if (!sftk_hasAttribute(key, CKA_KEY_TYPE)) {
  ------------------
  |  |  543|    772|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (6881:17): [True: 0, False: 772]
  ------------------
 6882|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 6883|      0|                break;
 6884|      0|            }
 6885|       |
 6886|    772|            if (key_length == 0 || key_length > bsize) {
  ------------------
  |  Branch (6886:17): [True: 772, False: 0]
  |  Branch (6886:36): [True: 0, False: 0]
  ------------------
 6887|    772|                key_length = bsize;
 6888|    772|            }
 6889|    772|            if (key_length > MAX_KEY_LEN) {
  ------------------
  |  |   74|    772|#define MAX_KEY_LEN 256 /* maximum symmetric key length in bytes */
  ------------------
  |  Branch (6889:17): [True: 0, False: 772]
  ------------------
 6890|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 6891|      0|                break;
 6892|      0|            }
 6893|       |
 6894|       |            /* add the value */
 6895|    772|            crv = sftk_AddAttributeType(key, CKA_VALUE, buf, key_length);
  ------------------
  |  |  516|    772|#define CKA_VALUE 0x00000011UL
  ------------------
 6896|    772|            break;
 6897|      0|        case CKO_PRIVATE_KEY:
  ------------------
  |  |  328|      0|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (6897:9): [True: 0, False: 772]
  ------------------
 6898|      0|            bpki.data = (unsigned char *)buf;
 6899|      0|            bpki.len = bsize;
 6900|      0|            crv = CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 6901|      0|            if (sftk_unwrapPrivateKey(key, &bpki) != SECSuccess) {
  ------------------
  |  Branch (6901:17): [True: 0, False: 0]
  ------------------
 6902|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 6903|      0|            }
 6904|      0|            break;
 6905|      0|        default:
  ------------------
  |  Branch (6905:9): [True: 0, False: 772]
  ------------------
 6906|      0|            crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 6907|      0|            break;
 6908|    772|    }
 6909|       |
 6910|    772|    PORT_ZFree(buf, bsize);
  ------------------
  |  |   75|    772|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 6911|    772|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|    772|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6911:9): [True: 0, False: 772]
  ------------------
 6912|      0|        sftk_FreeObject(key);
 6913|      0|        return crv;
 6914|      0|    }
 6915|       |
 6916|       |    /* get the session */
 6917|    772|    session = sftk_SessionFromHandle(hSession);
 6918|    772|    if (session == NULL) {
  ------------------
  |  Branch (6918:9): [True: 0, False: 772]
  ------------------
 6919|      0|        sftk_FreeObject(key);
 6920|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 6921|      0|    }
 6922|       |
 6923|       |    /* mark the key as FIPS if the previous operation was all FIPS */
 6924|    772|    key->isFIPS = session->lastOpWasFIPS;
 6925|       |
 6926|       |    /*
 6927|       |     * handle the base object stuff
 6928|       |     */
 6929|    772|    crv = sftk_handleObject(key, session);
 6930|    772|    *phKey = key->handle;
 6931|    772|    sftk_FreeSession(session);
 6932|    772|    sftk_FreeObject(key);
 6933|       |
 6934|    772|    return crv;
 6935|    772|}
sftk_MapKeySize:
 7145|   130k|{
 7146|   130k|    switch (keyType) {
 7147|      0|        case CKK_CDMF:
  ------------------
  |  |  401|      0|#define CKK_CDMF 0x0000001EUL
  ------------------
  |  Branch (7147:9): [True: 0, False: 130k]
  ------------------
 7148|      0|            return 8;
 7149|  14.8k|        case CKK_DES:
  ------------------
  |  |  386|  14.8k|#define CKK_DES 0x00000013UL
  ------------------
  |  Branch (7149:9): [True: 14.8k, False: 115k]
  ------------------
 7150|  14.8k|            return 8;
 7151|      0|        case CKK_DES2:
  ------------------
  |  |  387|      0|#define CKK_DES2 0x00000014UL
  ------------------
  |  Branch (7151:9): [True: 0, False: 130k]
  ------------------
 7152|      0|            return 16;
 7153|  10.1k|        case CKK_DES3:
  ------------------
  |  |  388|  10.1k|#define CKK_DES3 0x00000015UL
  ------------------
  |  Branch (7153:9): [True: 10.1k, False: 119k]
  ------------------
 7154|  10.1k|            return 24;
 7155|       |        /* IDEA and CAST need to be added */
 7156|   105k|        default:
  ------------------
  |  Branch (7156:9): [True: 105k, False: 24.9k]
  ------------------
 7157|   105k|            break;
 7158|   130k|    }
 7159|   105k|    return 0;
 7160|   130k|}
sftk_HKDF:
 7318|   846k|{
 7319|   846k|    SFTKSession *session;
 7320|   846k|    SFTKAttribute *saltKey_att = NULL;
 7321|   846k|    const SECHashObject *rawHash;
 7322|   846k|    unsigned hashLen;
 7323|   846k|    unsigned genLen = 0;
 7324|   846k|    unsigned char hashbuf[HASH_LENGTH_MAX];
 7325|   846k|    unsigned char keyBlock[9 * SFTK_MAX_MAC_LENGTH];
 7326|   846k|    unsigned char *keyBlockAlloc = NULL;    /* allocated keyBlock */
 7327|   846k|    unsigned char *keyBlockData = keyBlock; /* pointer to current keyBlock */
 7328|   846k|    const unsigned char *prk;               /* psuedo-random key */
 7329|   846k|    CK_ULONG prkLen;
 7330|   846k|    const unsigned char *okm; /* output keying material */
 7331|   846k|    HASH_HashType hashType = sftk_GetHashTypeFromMechanism(params->prfHashMechanism);
 7332|   846k|    SFTKObject *saltKey = NULL;
 7333|   846k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   846k|#define CKR_OK 0x00000000UL
  ------------------
 7334|       |
 7335|       |    /* Spec says it should be the base hash, but also accept the HMAC */
 7336|   846k|    if (hashType == HASH_AlgNULL) {
  ------------------
  |  Branch (7336:9): [True: 0, False: 846k]
  ------------------
 7337|      0|        hashType = sftk_HMACMechanismToHash(params->prfHashMechanism);
 7338|      0|    }
 7339|   846k|    rawHash = HASH_GetRawHashObject(hashType);
 7340|   846k|    if (rawHash == NULL || rawHash->length > sizeof(hashbuf)) {
  ------------------
  |  Branch (7340:9): [True: 0, False: 846k]
  |  Branch (7340:28): [True: 0, False: 846k]
  ------------------
 7341|      0|        return CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 7342|      0|    }
 7343|   846k|    hashLen = rawHash->length;
 7344|       |
 7345|   846k|    if ((!params->bExpand && !params->bExtract) ||
  ------------------
  |  Branch (7345:10): [True: 3.65k, False: 842k]
  |  Branch (7345:30): [True: 0, False: 3.65k]
  ------------------
 7346|   846k|        (params->bExtract && params->ulSaltLen > 0 && !params->pSalt) ||
  ------------------
  |  Branch (7346:10): [True: 3.65k, False: 842k]
  |  Branch (7346:30): [True: 0, False: 3.65k]
  |  Branch (7346:55): [True: 0, False: 0]
  ------------------
 7347|   846k|        (params->bExpand && params->ulInfoLen > 0 && !params->pInfo)) {
  ------------------
  |  Branch (7347:10): [True: 842k, False: 3.65k]
  |  Branch (7347:29): [True: 842k, False: 0]
  |  Branch (7347:54): [True: 0, False: 842k]
  ------------------
 7348|      0|        return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7349|      0|    }
 7350|   846k|    if ((params->bExpand && keySize == 0) ||
  ------------------
  |  Branch (7350:10): [True: 842k, False: 3.65k]
  |  Branch (7350:29): [True: 0, False: 842k]
  ------------------
 7351|   846k|        (!params->bExpand && keySize > hashLen) ||
  ------------------
  |  Branch (7351:10): [True: 3.65k, False: 842k]
  |  Branch (7351:30): [True: 0, False: 3.65k]
  ------------------
 7352|   846k|        (params->bExpand && keySize > 255 * hashLen)) {
  ------------------
  |  Branch (7352:10): [True: 842k, False: 3.65k]
  |  Branch (7352:29): [True: 0, False: 842k]
  ------------------
 7353|      0|        return CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 7354|      0|    }
 7355|       |
 7356|       |    /* sourceKey is NULL if we are called from the POST, skip the
 7357|       |     * sensitiveCheck */
 7358|   846k|    if (sourceKey != NULL) {
  ------------------
  |  Branch (7358:9): [True: 846k, False: 0]
  ------------------
 7359|   846k|        crv = sftk_DeriveSensitiveCheck(sourceKey, key, canBeData);
 7360|   846k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   846k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7360:13): [True: 0, False: 846k]
  ------------------
 7361|      0|            return crv;
 7362|   846k|    }
 7363|       |
 7364|       |    /* HKDF-Extract(salt, base key value) */
 7365|   846k|    if (params->bExtract) {
  ------------------
  |  Branch (7365:9): [True: 3.65k, False: 842k]
  ------------------
 7366|  3.65k|        CK_BYTE *salt;
 7367|  3.65k|        CK_ULONG saltLen;
 7368|  3.65k|        HMACContext *hmac;
 7369|  3.65k|        unsigned int bufLen;
 7370|       |
 7371|  3.65k|        switch (params->ulSaltType) {
 7372|  1.22k|            case CKF_HKDF_SALT_NULL:
  ------------------
  |  | 2252|  1.22k|#define CKF_HKDF_SALT_NULL 0x00000001UL
  ------------------
  |  Branch (7372:13): [True: 1.22k, False: 2.42k]
  ------------------
 7373|  1.22k|                saltLen = hashLen;
 7374|  1.22k|                salt = hashbuf;
 7375|  1.22k|                memset(salt, 0, saltLen);
 7376|  1.22k|                break;
 7377|      0|            case CKF_HKDF_SALT_DATA:
  ------------------
  |  | 2253|      0|#define CKF_HKDF_SALT_DATA 0x00000002UL
  ------------------
  |  Branch (7377:13): [True: 0, False: 3.65k]
  ------------------
 7378|      0|                salt = params->pSalt;
 7379|      0|                saltLen = params->ulSaltLen;
 7380|      0|                if ((salt == NULL) || (params->ulSaltLen == 0)) {
  ------------------
  |  Branch (7380:21): [True: 0, False: 0]
  |  Branch (7380:39): [True: 0, False: 0]
  ------------------
 7381|      0|                    return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7382|      0|                }
 7383|      0|                break;
 7384|  2.42k|            case CKF_HKDF_SALT_KEY:
  ------------------
  |  | 2254|  2.42k|#define CKF_HKDF_SALT_KEY 0x00000004UL
  ------------------
  |  Branch (7384:13): [True: 2.42k, False: 1.22k]
  ------------------
 7385|       |                /* lookup key */
 7386|  2.42k|                session = sftk_SessionFromHandle(hSession);
 7387|  2.42k|                if (session == NULL) {
  ------------------
  |  Branch (7387:21): [True: 0, False: 2.42k]
  ------------------
 7388|      0|                    return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 7389|      0|                }
 7390|       |
 7391|  2.42k|                saltKey = sftk_ObjectFromHandle(params->hSaltKey, session);
 7392|  2.42k|                sftk_FreeSession(session);
 7393|  2.42k|                if (saltKey == NULL) {
  ------------------
  |  Branch (7393:21): [True: 0, False: 2.42k]
  ------------------
 7394|      0|                    return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 7395|      0|                }
 7396|       |                /* if the base key is not fips, but the salt key is, the
 7397|       |                 * resulting key can be fips */
 7398|  2.42k|                if (isFIPS && (key->isFIPS == 0) && (saltKey->isFIPS == 1)) {
  ------------------
  |  Branch (7398:21): [True: 0, False: 2.42k]
  |  Branch (7398:31): [True: 0, False: 0]
  |  Branch (7398:53): [True: 0, False: 0]
  ------------------
 7399|      0|                    CK_MECHANISM mech;
 7400|      0|                    mech.mechanism = CKM_HKDF_DERIVE;
  ------------------
  |  | 1296|      0|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
 7401|      0|                    mech.pParameter = params;
 7402|      0|                    mech.ulParameterLen = sizeof(*params);
 7403|      0|                    key->isFIPS = sftk_operationIsFIPS(saltKey->slot, &mech,
 7404|      0|                                                       CKA_DERIVE, saltKey);
  ------------------
  |  |  555|      0|#define CKA_DERIVE 0x0000010CUL
  ------------------
 7405|      0|                }
 7406|  2.42k|                saltKey_att = sftk_FindAttribute(saltKey, CKA_VALUE);
  ------------------
  |  |  516|  2.42k|#define CKA_VALUE 0x00000011UL
  ------------------
 7407|  2.42k|                if (saltKey_att == NULL) {
  ------------------
  |  Branch (7407:21): [True: 0, False: 2.42k]
  ------------------
 7408|      0|                    sftk_FreeObject(saltKey);
 7409|      0|                    return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 7410|      0|                }
 7411|       |                /* save the resulting salt */
 7412|  2.42k|                salt = saltKey_att->attrib.pValue;
 7413|  2.42k|                saltLen = saltKey_att->attrib.ulValueLen;
 7414|  2.42k|                break;
 7415|      0|            default:
  ------------------
  |  Branch (7415:13): [True: 0, False: 3.65k]
  ------------------
 7416|      0|                return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7417|      0|                break;
 7418|  3.65k|        }
 7419|       |
 7420|  3.65k|        hmac = HMAC_Create(rawHash, salt, saltLen, isFIPS);
 7421|  3.65k|        if (saltKey_att) {
  ------------------
  |  Branch (7421:13): [True: 2.42k, False: 1.22k]
  ------------------
 7422|  2.42k|            sftk_FreeAttribute(saltKey_att);
 7423|  2.42k|        }
 7424|  3.65k|        if (saltKey) {
  ------------------
  |  Branch (7424:13): [True: 2.42k, False: 1.22k]
  ------------------
 7425|  2.42k|            sftk_FreeObject(saltKey);
 7426|  2.42k|        }
 7427|  3.65k|        if (!hmac) {
  ------------------
  |  Branch (7427:13): [True: 0, False: 3.65k]
  ------------------
 7428|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 7429|      0|        }
 7430|  3.65k|        HMAC_Begin(hmac);
 7431|  3.65k|        HMAC_Update(hmac, sourceKeyBytes, sourceKeyLen);
 7432|  3.65k|        HMAC_Finish(hmac, hashbuf, &bufLen, sizeof(hashbuf));
 7433|  3.65k|        HMAC_Destroy(hmac, PR_TRUE);
  ------------------
  |  |  437|  3.65k|#define PR_TRUE 1
  ------------------
 7434|  3.65k|        PORT_Assert(bufLen == rawHash->length);
  ------------------
  |  |  120|  3.65k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.65k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7435|  3.65k|        prk = hashbuf;
 7436|  3.65k|        prkLen = bufLen;
 7437|   842k|    } else {
 7438|       |        /* PRK = base key value */
 7439|   842k|        prk = sourceKeyBytes;
 7440|   842k|        prkLen = sourceKeyLen;
 7441|   842k|    }
 7442|       |
 7443|       |    /* HKDF-Expand */
 7444|   846k|    if (!params->bExpand) {
  ------------------
  |  Branch (7444:9): [True: 3.65k, False: 842k]
  ------------------
 7445|  3.65k|        okm = prk;
 7446|  3.65k|        keySize = genLen = hashLen;
 7447|   842k|    } else {
 7448|       |        /* T(1) = HMAC-Hash(prk, "" | info | 0x01)
 7449|       |         * T(n) = HMAC-Hash(prk, T(n-1) | info | n
 7450|       |         * key material = T(1) | ... | T(n)
 7451|       |         */
 7452|   842k|        HMACContext *hmac;
 7453|   842k|        CK_BYTE bi;
 7454|   842k|        unsigned iterations;
 7455|       |
 7456|   842k|        genLen = PR_ROUNDUP(keySize, hashLen);
  ------------------
  |  |  157|   842k|#define PR_ROUNDUP(x,y) ((((x)+((y)-1))/(y))*(y))
  ------------------
 7457|   842k|        iterations = genLen / hashLen;
 7458|       |
 7459|   842k|        if (genLen > sizeof(keyBlock)) {
  ------------------
  |  Branch (7459:13): [True: 0, False: 842k]
  ------------------
 7460|      0|            keyBlockAlloc = PORT_Alloc(genLen);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 7461|      0|            if (keyBlockAlloc == NULL) {
  ------------------
  |  Branch (7461:17): [True: 0, False: 0]
  ------------------
 7462|      0|                return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 7463|      0|            }
 7464|      0|            keyBlockData = keyBlockAlloc;
 7465|      0|        }
 7466|   842k|        hmac = HMAC_Create(rawHash, prk, prkLen, isFIPS);
 7467|   842k|        if (hmac == NULL) {
  ------------------
  |  Branch (7467:13): [True: 0, False: 842k]
  ------------------
 7468|      0|            PORT_Free(keyBlockAlloc);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 7469|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 7470|      0|        }
 7471|  1.68M|        for (bi = 1; bi <= iterations && bi > 0; ++bi) {
  ------------------
  |  Branch (7471:22): [True: 842k, False: 842k]
  |  Branch (7471:42): [True: 842k, False: 0]
  ------------------
 7472|   842k|            unsigned len;
 7473|   842k|            HMAC_Begin(hmac);
 7474|   842k|            if (bi > 1) {
  ------------------
  |  Branch (7474:17): [True: 0, False: 842k]
  ------------------
 7475|      0|                HMAC_Update(hmac, &keyBlockData[(bi - 2) * hashLen], hashLen);
 7476|      0|            }
 7477|   842k|            if (params->ulInfoLen != 0) {
  ------------------
  |  Branch (7477:17): [True: 842k, False: 0]
  ------------------
 7478|   842k|                HMAC_Update(hmac, params->pInfo, params->ulInfoLen);
 7479|   842k|            }
 7480|   842k|            HMAC_Update(hmac, &bi, 1);
 7481|   842k|            HMAC_Finish(hmac, &keyBlockData[(bi - 1) * hashLen], &len,
 7482|   842k|                        hashLen);
 7483|   842k|            PORT_Assert(len == hashLen);
  ------------------
  |  |  120|   842k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   842k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 842k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7484|   842k|        }
 7485|   842k|        HMAC_Destroy(hmac, PR_TRUE);
  ------------------
  |  |  437|   842k|#define PR_TRUE 1
  ------------------
 7486|   842k|        okm = &keyBlockData[0];
 7487|   842k|    }
 7488|       |    /* key material = okm */
 7489|   846k|    crv = CKR_OK;
  ------------------
  |  | 1388|   846k|#define CKR_OK 0x00000000UL
  ------------------
 7490|   846k|    if (key) {
  ------------------
  |  Branch (7490:9): [True: 846k, False: 0]
  ------------------
 7491|   846k|        crv = sftk_forceAttribute(key, CKA_VALUE, okm, keySize);
  ------------------
  |  |  516|   846k|#define CKA_VALUE 0x00000011UL
  ------------------
 7492|   846k|    } else {
 7493|      0|        PORT_Assert(outKeyBytes != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7494|      0|        PORT_Memcpy(outKeyBytes, okm, keySize);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 7495|      0|    }
 7496|   846k|    PORT_Memset(keyBlockData, 0, genLen);
  ------------------
  |  |  182|   846k|#define PORT_Memset memset
  ------------------
 7497|   846k|    PORT_Memset(hashbuf, 0, sizeof(hashbuf));
  ------------------
  |  |  182|   846k|#define PORT_Memset memset
  ------------------
 7498|   846k|    PORT_Free(keyBlockAlloc);
  ------------------
  |  |   60|   846k|#define PORT_Free PORT_Free_Util
  ------------------
 7499|   846k|    return crv;
 7500|   846k|}
NSC_DeriveKey:
 7527|  1.01M|{
 7528|  1.01M|    SFTKSession *session;
 7529|  1.01M|    SFTKSlot *slot = sftk_SlotFromSessionHandle(hSession);
 7530|  1.01M|    SFTKObject *key;
 7531|  1.01M|    SFTKObject *sourceKey;
 7532|  1.01M|    SFTKAttribute *att = NULL;
 7533|  1.01M|    SFTKAttribute *att2 = NULL;
 7534|  1.01M|    unsigned char *buf;
 7535|  1.01M|    SHA1Context *sha;
 7536|  1.01M|    MD5Context *md5;
 7537|  1.01M|    MD2Context *md2;
 7538|  1.01M|    CK_ULONG macSize;
 7539|  1.01M|    CK_ULONG tmpKeySize;
 7540|  1.01M|    CK_ULONG IVSize;
 7541|  1.01M|    CK_ULONG keySize = 0;
 7542|  1.01M|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  1.01M|#define CKR_OK 0x00000000UL
  ------------------
 7543|  1.01M|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|  1.01M|#define CK_TRUE 1
  ------------------
 7544|  1.01M|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|  1.01M|#define CK_FALSE 0
  ------------------
 7545|  1.01M|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  1.01M|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 7546|  1.01M|    CK_OBJECT_CLASS classType = CKO_SECRET_KEY;
  ------------------
  |  |  329|  1.01M|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 7547|  1.01M|    CK_KEY_DERIVATION_STRING_DATA *stringPtr;
 7548|  1.01M|    PRBool isTLS = PR_FALSE;
  ------------------
  |  |  438|  1.01M|#define PR_FALSE 0
  ------------------
 7549|  1.01M|    PRBool isDH = PR_FALSE;
  ------------------
  |  |  438|  1.01M|#define PR_FALSE 0
  ------------------
 7550|  1.01M|    HASH_HashType tlsPrfHash = HASH_AlgNULL;
 7551|  1.01M|    SECStatus rv;
 7552|  1.01M|    int i;
 7553|  1.01M|    unsigned int outLen;
 7554|  1.01M|    unsigned char sha_out[SHA1_LENGTH];
 7555|  1.01M|    unsigned char key_block[NUM_MIXERS * SFTK_MAX_MAC_LENGTH];
 7556|  1.01M|    PRBool isFIPS;
 7557|  1.01M|    HASH_HashType hashType;
 7558|  1.01M|    CK_MECHANISM_TYPE hashMech;
 7559|  1.01M|    PRBool extractValue = PR_TRUE;
  ------------------
  |  |  437|  1.01M|#define PR_TRUE 1
  ------------------
 7560|  1.01M|    CK_NSS_IKE1_APP_B_PRF_DERIVE_PARAMS ikeAppB;
 7561|  1.01M|    CK_NSS_IKE1_APP_B_PRF_DERIVE_PARAMS *pIkeAppB;
 7562|       |
 7563|  1.01M|    CHECK_FORK();
 7564|       |
 7565|  1.01M|    if (!slot) {
  ------------------
  |  Branch (7565:9): [True: 0, False: 1.01M]
  ------------------
 7566|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 7567|      0|    }
 7568|  1.01M|    if (!pMechanism) {
  ------------------
  |  Branch (7568:9): [True: 0, False: 1.01M]
  ------------------
 7569|      0|        return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7570|      0|    }
 7571|  1.01M|    CK_MECHANISM_TYPE mechanism = pMechanism->mechanism;
 7572|       |
 7573|       |    /*
 7574|       |     * now lets create an object to hang the attributes off of
 7575|       |     */
 7576|  1.01M|    if (phKey) {
  ------------------
  |  Branch (7576:9): [True: 1.01M, False: 0]
  ------------------
 7577|  1.01M|        *phKey = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  1.01M|#define CK_INVALID_HANDLE 0
  ------------------
 7578|  1.01M|    }
 7579|       |
 7580|  1.01M|    key = sftk_NewObject(slot); /* fill in the handle later */
 7581|  1.01M|    if (key == NULL) {
  ------------------
  |  Branch (7581:9): [True: 0, False: 1.01M]
  ------------------
 7582|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 7583|      0|    }
 7584|  1.01M|    isFIPS = sftk_isFIPS(slot->slotID);
  ------------------
  |  |  506|  1.01M|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|  1.01M|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|  1.01M|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 1.01M]
  |  |  |  Branch (506:32): [True: 0, False: 1.01M]
  |  |  ------------------
  ------------------
 7585|       |
 7586|       |    /*
 7587|       |     * load the template values into the object
 7588|       |     */
 7589|  6.79M|    for (i = 0; i < (int)ulAttributeCount; i++) {
  ------------------
  |  Branch (7589:17): [True: 5.77M, False: 1.01M]
  ------------------
 7590|  5.77M|        crv = sftk_AddAttributeType(key, sftk_attr_expand(&pTemplate[i]));
  ------------------
  |  |  587|  5.77M|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 7591|  5.77M|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  5.77M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7591:13): [True: 0, False: 5.77M]
  ------------------
 7592|      0|            break;
 7593|       |
 7594|  5.77M|        if (pTemplate[i].type == CKA_KEY_TYPE) {
  ------------------
  |  |  543|  5.77M|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (7594:13): [True: 1.01M, False: 4.76M]
  ------------------
 7595|  1.01M|            keyType = *(CK_KEY_TYPE *)pTemplate[i].pValue;
 7596|  1.01M|        }
 7597|  5.77M|        if (pTemplate[i].type == CKA_VALUE_LEN) {
  ------------------
  |  |  580|  5.77M|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (7597:13): [True: 910k, False: 4.86M]
  ------------------
 7598|   910k|            keySize = *(CK_ULONG *)pTemplate[i].pValue;
 7599|   910k|        }
 7600|  5.77M|    }
 7601|  1.01M|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  1.01M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7601:9): [True: 0, False: 1.01M]
  ------------------
 7602|      0|        sftk_FreeObject(key);
 7603|      0|        return crv;
 7604|      0|    }
 7605|       |
 7606|  1.01M|    if (keySize == 0) {
  ------------------
  |  Branch (7606:9): [True: 105k, False: 910k]
  ------------------
 7607|   105k|        keySize = sftk_MapKeySize(keyType);
 7608|   105k|    }
 7609|       |
 7610|  1.01M|    switch (mechanism) {
 7611|      0|        case CKM_NSS_JPAKE_ROUND2_SHA1:   /* fall through */
  ------------------
  |  |  195|      0|#define CKM_NSS_JPAKE_ROUND2_SHA1 (CKM_NSS + 11)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7611:9): [True: 0, False: 1.01M]
  ------------------
 7612|      0|        case CKM_NSS_JPAKE_ROUND2_SHA256: /* fall through */
  ------------------
  |  |  196|      0|#define CKM_NSS_JPAKE_ROUND2_SHA256 (CKM_NSS + 12)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7612:9): [True: 0, False: 1.01M]
  ------------------
 7613|      0|        case CKM_NSS_JPAKE_ROUND2_SHA384: /* fall through */
  ------------------
  |  |  197|      0|#define CKM_NSS_JPAKE_ROUND2_SHA384 (CKM_NSS + 13)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7613:9): [True: 0, False: 1.01M]
  ------------------
 7614|      0|        case CKM_NSS_JPAKE_ROUND2_SHA512:
  ------------------
  |  |  198|      0|#define CKM_NSS_JPAKE_ROUND2_SHA512 (CKM_NSS + 14)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7614:9): [True: 0, False: 1.01M]
  ------------------
 7615|      0|            extractValue = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 7616|      0|            classType = CKO_PRIVATE_KEY;
  ------------------
  |  |  328|      0|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
 7617|      0|            break;
 7618|      0|        case CKM_NSS_PUB_FROM_PRIV:
  ------------------
  |  |  259|      0|#define CKM_NSS_PUB_FROM_PRIV (CKM_NSS + 40)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7618:9): [True: 0, False: 1.01M]
  ------------------
 7619|      0|            extractValue = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 7620|      0|            classType = CKO_PUBLIC_KEY;
  ------------------
  |  |  327|      0|#define CKO_PUBLIC_KEY 0x00000002UL
  ------------------
 7621|      0|            break;
 7622|   278k|        case CKM_HKDF_DATA:                              /* fall through */
  ------------------
  |  | 1297|   278k|#define CKM_HKDF_DATA 0x0000402bUL
  ------------------
  |  Branch (7622:9): [True: 278k, False: 736k]
  ------------------
 7623|   278k|        case CKM_NSS_SP800_108_COUNTER_KDF_DERIVE_DATA:  /* fall through */
  ------------------
  |  |  262|   278k|#define CKM_NSS_SP800_108_COUNTER_KDF_DERIVE_DATA (CKM_NSS + 42)
  |  |  ------------------
  |  |  |  |  162|   278k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|   278k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   278k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7623:9): [True: 0, False: 1.01M]
  ------------------
 7624|   278k|        case CKM_NSS_SP800_108_FEEDBACK_KDF_DERIVE_DATA: /* fall through */
  ------------------
  |  |  263|   278k|#define CKM_NSS_SP800_108_FEEDBACK_KDF_DERIVE_DATA (CKM_NSS + 43)
  |  |  ------------------
  |  |  |  |  162|   278k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|   278k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   278k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7624:9): [True: 0, False: 1.01M]
  ------------------
 7625|   278k|        case CKM_NSS_SP800_108_DOUBLE_PIPELINE_KDF_DERIVE_DATA:
  ------------------
  |  |  264|   278k|#define CKM_NSS_SP800_108_DOUBLE_PIPELINE_KDF_DERIVE_DATA (CKM_NSS + 44)
  |  |  ------------------
  |  |  |  |  162|   278k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|   278k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|   278k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7625:9): [True: 0, False: 1.01M]
  ------------------
 7626|   278k|            classType = CKO_DATA;
  ------------------
  |  |  325|   278k|#define CKO_DATA 0x00000000UL
  ------------------
 7627|   278k|            break;
 7628|      0|        case CKM_NSS_JPAKE_FINAL_SHA1:   /* fall through */
  ------------------
  |  |  210|      0|#define CKM_NSS_JPAKE_FINAL_SHA1 (CKM_NSS + 15)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7628:9): [True: 0, False: 1.01M]
  ------------------
 7629|      0|        case CKM_NSS_JPAKE_FINAL_SHA256: /* fall through */
  ------------------
  |  |  211|      0|#define CKM_NSS_JPAKE_FINAL_SHA256 (CKM_NSS + 16)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7629:9): [True: 0, False: 1.01M]
  ------------------
 7630|      0|        case CKM_NSS_JPAKE_FINAL_SHA384: /* fall through */
  ------------------
  |  |  212|      0|#define CKM_NSS_JPAKE_FINAL_SHA384 (CKM_NSS + 17)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7630:9): [True: 0, False: 1.01M]
  ------------------
 7631|      0|        case CKM_NSS_JPAKE_FINAL_SHA512:
  ------------------
  |  |  213|      0|#define CKM_NSS_JPAKE_FINAL_SHA512 (CKM_NSS + 18)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7631:9): [True: 0, False: 1.01M]
  ------------------
 7632|      0|            extractValue = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 7633|       |        /* fall through */
 7634|   736k|        default:
  ------------------
  |  Branch (7634:9): [True: 736k, False: 278k]
  ------------------
 7635|   736k|            classType = CKO_SECRET_KEY;
  ------------------
  |  |  329|   736k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
 7636|  1.01M|    }
 7637|       |
 7638|  1.01M|    crv = sftk_forceAttribute(key, CKA_CLASS, &classType, sizeof(classType));
  ------------------
  |  |  511|  1.01M|#define CKA_CLASS 0x00000000UL
  ------------------
 7639|  1.01M|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  1.01M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7639:9): [True: 0, False: 1.01M]
  ------------------
 7640|      0|        sftk_FreeObject(key);
 7641|      0|        return crv;
 7642|      0|    }
 7643|       |
 7644|       |    /* look up the base key we're deriving with */
 7645|  1.01M|    session = sftk_SessionFromHandle(hSession);
 7646|  1.01M|    if (session == NULL) {
  ------------------
  |  Branch (7646:9): [True: 0, False: 1.01M]
  ------------------
 7647|      0|        sftk_FreeObject(key);
 7648|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 7649|      0|    }
 7650|       |
 7651|  1.01M|    sourceKey = sftk_ObjectFromHandle(hBaseKey, session);
 7652|  1.01M|    sftk_FreeSession(session);
 7653|       |    /* is this eventually succeeds, lastOpWasFIPS will be set the resulting key's
 7654|       |     * FIPS state below. */
 7655|  1.01M|    session->lastOpWasFIPS = PR_FALSE;
  ------------------
  |  |  438|  1.01M|#define PR_FALSE 0
  ------------------
 7656|  1.01M|    if (sourceKey == NULL) {
  ------------------
  |  Branch (7656:9): [True: 0, False: 1.01M]
  ------------------
 7657|      0|        sftk_FreeObject(key);
 7658|      0|        return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 7659|      0|    }
 7660|       |
 7661|  1.01M|    if (extractValue) {
  ------------------
  |  Branch (7661:9): [True: 1.01M, False: 0]
  ------------------
 7662|       |        /* get the value of the base key */
 7663|  1.01M|        att = sftk_FindAttribute(sourceKey, CKA_VALUE);
  ------------------
  |  |  516|  1.01M|#define CKA_VALUE 0x00000011UL
  ------------------
 7664|  1.01M|        if (att == NULL) {
  ------------------
  |  Branch (7664:13): [True: 0, False: 1.01M]
  ------------------
 7665|      0|            sftk_FreeObject(key);
 7666|      0|            sftk_FreeObject(sourceKey);
 7667|      0|            return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 7668|      0|        }
 7669|  1.01M|    }
 7670|  1.01M|    key->isFIPS = sftk_operationIsFIPS(slot, pMechanism, CKA_DERIVE, sourceKey);
  ------------------
  |  |  555|  1.01M|#define CKA_DERIVE 0x0000010CUL
  ------------------
 7671|       |
 7672|  1.01M|    switch (mechanism) {
 7673|       |        /* get a public key from a private key. nsslowkey_ConvertToPublickey()
 7674|       |         * will generate the public portion if it doesn't already exist. */
 7675|      0|        case CKM_NSS_PUB_FROM_PRIV: {
  ------------------
  |  |  259|      0|#define CKM_NSS_PUB_FROM_PRIV (CKM_NSS + 40)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7675:9): [True: 0, False: 1.01M]
  ------------------
 7676|      0|            NSSLOWKEYPrivateKey *privKey;
 7677|      0|            NSSLOWKEYPublicKey *pubKey;
 7678|      0|            int error;
 7679|       |
 7680|      0|            crv = sftk_GetULongAttribute(sourceKey, CKA_KEY_TYPE, &keyType);
  ------------------
  |  |  543|      0|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 7681|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7681:17): [True: 0, False: 0]
  ------------------
 7682|      0|                break;
 7683|      0|            }
 7684|       |
 7685|       |            /* privKey is stored in sourceKey and will be destroyed when
 7686|       |             * the sourceKey is freed. */
 7687|      0|            privKey = sftk_GetPrivKey(sourceKey, keyType, &crv);
 7688|      0|            if (privKey == NULL) {
  ------------------
  |  Branch (7688:17): [True: 0, False: 0]
  ------------------
 7689|      0|                break;
 7690|      0|            }
 7691|      0|            pubKey = nsslowkey_ConvertToPublicKey(privKey);
 7692|      0|            if (pubKey == NULL) {
  ------------------
  |  Branch (7692:17): [True: 0, False: 0]
  ------------------
 7693|      0|                error = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 7694|      0|                crv = sftk_MapCryptError(error);
 7695|      0|                break;
 7696|      0|            }
 7697|      0|            crv = sftk_PutPubKey(key, sourceKey, keyType, pubKey);
 7698|      0|            nsslowkey_DestroyPublicKey(pubKey);
 7699|      0|            break;
 7700|      0|        }
 7701|      0|        case CKM_NSS_IKE_PRF_DERIVE:
  ------------------
  |  |  255|      0|#define CKM_NSS_IKE_PRF_DERIVE (CKM_NSS + 35)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7701:9): [True: 0, False: 1.01M]
  ------------------
 7702|      0|            if (pMechanism->ulParameterLen !=
  ------------------
  |  Branch (7702:17): [True: 0, False: 0]
  ------------------
 7703|      0|                sizeof(CK_NSS_IKE_PRF_DERIVE_PARAMS)) {
 7704|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7705|      0|                break;
 7706|      0|            }
 7707|      0|            crv = sftk_ike_prf(hSession, att,
 7708|      0|                               (CK_NSS_IKE_PRF_DERIVE_PARAMS *)pMechanism->pParameter, key);
 7709|      0|            break;
 7710|      0|        case CKM_NSS_IKE1_PRF_DERIVE:
  ------------------
  |  |  256|      0|#define CKM_NSS_IKE1_PRF_DERIVE (CKM_NSS + 36)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7710:9): [True: 0, False: 1.01M]
  ------------------
 7711|      0|            if (pMechanism->ulParameterLen !=
  ------------------
  |  Branch (7711:17): [True: 0, False: 0]
  ------------------
 7712|      0|                sizeof(CK_NSS_IKE1_PRF_DERIVE_PARAMS)) {
 7713|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7714|      0|                break;
 7715|      0|            }
 7716|      0|            crv = sftk_ike1_prf(hSession, att,
 7717|      0|                                (CK_NSS_IKE1_PRF_DERIVE_PARAMS *)pMechanism->pParameter,
 7718|      0|                                key, keySize);
 7719|      0|            break;
 7720|      0|        case CKM_NSS_IKE1_APP_B_PRF_DERIVE:
  ------------------
  |  |  257|      0|#define CKM_NSS_IKE1_APP_B_PRF_DERIVE (CKM_NSS + 37)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7720:9): [True: 0, False: 1.01M]
  ------------------
 7721|      0|            pIkeAppB = (CK_NSS_IKE1_APP_B_PRF_DERIVE_PARAMS *)pMechanism->pParameter;
 7722|      0|            if (pMechanism->ulParameterLen ==
  ------------------
  |  Branch (7722:17): [True: 0, False: 0]
  ------------------
 7723|      0|                sizeof(CK_MECHANISM_TYPE)) {
 7724|      0|                ikeAppB.prfMechanism = *(CK_MECHANISM_TYPE *)pMechanism->pParameter;
 7725|      0|                ikeAppB.bHasKeygxy = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 7726|      0|                ikeAppB.hKeygxy = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 7727|      0|                ikeAppB.pExtraData = NULL;
 7728|      0|                ikeAppB.ulExtraDataLen = 0;
 7729|      0|                pIkeAppB = &ikeAppB;
 7730|      0|            } else if (pMechanism->ulParameterLen !=
  ------------------
  |  Branch (7730:24): [True: 0, False: 0]
  ------------------
 7731|      0|                       sizeof(CK_NSS_IKE1_APP_B_PRF_DERIVE_PARAMS)) {
 7732|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7733|      0|                break;
 7734|      0|            }
 7735|      0|            crv = sftk_ike1_appendix_b_prf(hSession, att, pIkeAppB, key,
 7736|      0|                                           keySize);
 7737|      0|            break;
 7738|      0|        case CKM_NSS_IKE_PRF_PLUS_DERIVE:
  ------------------
  |  |  254|      0|#define CKM_NSS_IKE_PRF_PLUS_DERIVE (CKM_NSS + 34)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7738:9): [True: 0, False: 1.01M]
  ------------------
 7739|      0|            if (pMechanism->ulParameterLen !=
  ------------------
  |  Branch (7739:17): [True: 0, False: 0]
  ------------------
 7740|      0|                sizeof(CK_NSS_IKE_PRF_PLUS_DERIVE_PARAMS)) {
 7741|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7742|      0|                break;
 7743|      0|            }
 7744|      0|            crv = sftk_ike_prf_plus(hSession, att,
 7745|      0|                                    (CK_NSS_IKE_PRF_PLUS_DERIVE_PARAMS *)pMechanism->pParameter,
 7746|      0|                                    key, keySize);
 7747|      0|            break;
 7748|       |        /*
 7749|       |         * generate the master secret
 7750|       |         */
 7751|  18.1k|        case CKM_TLS12_MASTER_KEY_DERIVE:
  ------------------
  |  | 1026|  18.1k|#define CKM_TLS12_MASTER_KEY_DERIVE 0x000003E0UL
  ------------------
  |  Branch (7751:9): [True: 18.1k, False: 997k]
  ------------------
 7752|  53.2k|        case CKM_TLS12_MASTER_KEY_DERIVE_DH:
  ------------------
  |  | 1028|  53.2k|#define CKM_TLS12_MASTER_KEY_DERIVE_DH 0x000003E2UL
  ------------------
  |  Branch (7752:9): [True: 35.1k, False: 980k]
  ------------------
 7753|  53.2k|        case CKM_NSS_TLS_MASTER_KEY_DERIVE_SHA256:
  ------------------
  |  |  234|  53.2k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_SHA256 (CKM_NSS + 22)
  |  |  ------------------
  |  |  |  |  162|  53.2k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  53.2k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  53.2k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7753:9): [True: 0, False: 1.01M]
  ------------------
 7754|  53.2k|        case CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256:
  ------------------
  |  |  236|  53.2k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256 (CKM_NSS + 24)
  |  |  ------------------
  |  |  |  |  162|  53.2k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  53.2k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  53.2k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7754:9): [True: 0, False: 1.01M]
  ------------------
 7755|  57.6k|        case CKM_TLS_MASTER_KEY_DERIVE:
  ------------------
  |  |  968|  57.6k|#define CKM_TLS_MASTER_KEY_DERIVE 0x00000375UL
  ------------------
  |  Branch (7755:9): [True: 4.32k, False: 1.01M]
  ------------------
 7756|  61.2k|        case CKM_TLS_MASTER_KEY_DERIVE_DH:
  ------------------
  |  |  970|  61.2k|#define CKM_TLS_MASTER_KEY_DERIVE_DH 0x00000377UL
  ------------------
  |  Branch (7756:9): [True: 3.60k, False: 1.01M]
  ------------------
 7757|  61.2k|        case CKM_SSL3_MASTER_KEY_DERIVE:
  ------------------
  |  |  960|  61.2k|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
  |  Branch (7757:9): [True: 0, False: 1.01M]
  ------------------
 7758|  61.2k|        case CKM_SSL3_MASTER_KEY_DERIVE_DH: {
  ------------------
  |  |  966|  61.2k|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
  |  Branch (7758:9): [True: 0, False: 1.01M]
  ------------------
 7759|  61.2k|            CK_SSL3_MASTER_KEY_DERIVE_PARAMS *ssl3_master;
 7760|  61.2k|            SSL3RSAPreMasterSecret *rsa_pms;
 7761|  61.2k|            unsigned char crsrdata[SSL3_RANDOM_LENGTH * 2];
 7762|       |
 7763|  61.2k|            if ((mechanism == CKM_TLS12_MASTER_KEY_DERIVE) ||
  ------------------
  |  | 1026|  61.2k|#define CKM_TLS12_MASTER_KEY_DERIVE 0x000003E0UL
  ------------------
  |  Branch (7763:17): [True: 18.1k, False: 43.0k]
  ------------------
 7764|  61.2k|                (mechanism == CKM_TLS12_MASTER_KEY_DERIVE_DH)) {
  ------------------
  |  | 1028|  43.0k|#define CKM_TLS12_MASTER_KEY_DERIVE_DH 0x000003E2UL
  ------------------
  |  Branch (7764:17): [True: 35.1k, False: 7.92k]
  ------------------
 7765|  53.2k|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_TLS12_MASTER_KEY_DERIVE_PARAMS))) {
  ------------------
  |  |   50|  53.2k|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 53.2k]
  |  |  |  Branch (50:64): [True: 0, False: 53.2k]
  |  |  ------------------
  ------------------
 7766|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7767|      0|                    break;
 7768|      0|                }
 7769|  53.2k|                CK_TLS12_MASTER_KEY_DERIVE_PARAMS *tls12_master =
 7770|  53.2k|                    (CK_TLS12_MASTER_KEY_DERIVE_PARAMS *)pMechanism->pParameter;
 7771|  53.2k|                tlsPrfHash = sftk_GetHashTypeFromMechanism(tls12_master->prfHashMechanism);
 7772|  53.2k|                if (tlsPrfHash == HASH_AlgNULL) {
  ------------------
  |  Branch (7772:21): [True: 0, False: 53.2k]
  ------------------
 7773|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7774|      0|                    break;
 7775|      0|                }
 7776|  53.2k|            } else if ((mechanism == CKM_NSS_TLS_MASTER_KEY_DERIVE_SHA256) ||
  ------------------
  |  |  234|  7.92k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_SHA256 (CKM_NSS + 22)
  |  |  ------------------
  |  |  |  |  162|  7.92k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  7.92k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  7.92k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7776:24): [True: 0, False: 7.92k]
  ------------------
 7777|  7.92k|                       (mechanism == CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256)) {
  ------------------
  |  |  236|  7.92k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256 (CKM_NSS + 24)
  |  |  ------------------
  |  |  |  |  162|  7.92k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  7.92k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  7.92k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7777:24): [True: 0, False: 7.92k]
  ------------------
 7778|      0|                tlsPrfHash = HASH_AlgSHA256;
 7779|      0|            }
 7780|       |
 7781|  61.2k|            if ((mechanism != CKM_SSL3_MASTER_KEY_DERIVE) &&
  ------------------
  |  |  960|  61.2k|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
  |  Branch (7781:17): [True: 61.2k, False: 0]
  ------------------
 7782|  61.2k|                (mechanism != CKM_SSL3_MASTER_KEY_DERIVE_DH)) {
  ------------------
  |  |  966|  61.2k|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
  |  Branch (7782:17): [True: 61.2k, False: 0]
  ------------------
 7783|  61.2k|                isTLS = PR_TRUE;
  ------------------
  |  |  437|  61.2k|#define PR_TRUE 1
  ------------------
 7784|  61.2k|            }
 7785|  61.2k|            if ((mechanism == CKM_SSL3_MASTER_KEY_DERIVE_DH) ||
  ------------------
  |  |  966|  61.2k|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
  |  Branch (7785:17): [True: 0, False: 61.2k]
  ------------------
 7786|  61.2k|                (mechanism == CKM_TLS_MASTER_KEY_DERIVE_DH) ||
  ------------------
  |  |  970|  61.2k|#define CKM_TLS_MASTER_KEY_DERIVE_DH 0x00000377UL
  ------------------
  |  Branch (7786:17): [True: 3.60k, False: 57.6k]
  ------------------
 7787|  61.2k|                (mechanism == CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256) ||
  ------------------
  |  |  236|  57.6k|#define CKM_NSS_TLS_MASTER_KEY_DERIVE_DH_SHA256 (CKM_NSS + 24)
  |  |  ------------------
  |  |  |  |  162|  57.6k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  57.6k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  57.6k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7787:17): [True: 0, False: 57.6k]
  ------------------
 7788|  61.2k|                (mechanism == CKM_TLS12_MASTER_KEY_DERIVE_DH)) {
  ------------------
  |  | 1028|  57.6k|#define CKM_TLS12_MASTER_KEY_DERIVE_DH 0x000003E2UL
  ------------------
  |  Branch (7788:17): [True: 35.1k, False: 22.5k]
  ------------------
 7789|  38.7k|                isDH = PR_TRUE;
  ------------------
  |  |  437|  38.7k|#define PR_TRUE 1
  ------------------
 7790|  38.7k|            }
 7791|       |
 7792|       |            /* first do the consistency checks */
 7793|  61.2k|            if (!isDH && (att->attrib.ulValueLen != SSL3_PMS_LENGTH)) {
  ------------------
  |  | 7517|  22.5k|#define SSL3_PMS_LENGTH 48
  ------------------
  |  Branch (7793:17): [True: 22.5k, False: 38.7k]
  |  Branch (7793:26): [True: 723, False: 21.7k]
  ------------------
 7794|    723|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|    723|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 7795|    723|                break;
 7796|    723|            }
 7797|  60.4k|            att2 = sftk_FindAttribute(sourceKey, CKA_KEY_TYPE);
  ------------------
  |  |  543|  60.4k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 7798|  60.4k|            if ((att2 == NULL) || (*(CK_KEY_TYPE *)att2->attrib.pValue !=
  ------------------
  |  Branch (7798:17): [True: 0, False: 60.4k]
  |  Branch (7798:35): [True: 0, False: 60.4k]
  ------------------
 7799|  60.4k|                                   CKK_GENERIC_SECRET)) {
  ------------------
  |  |  383|  60.4k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 7800|      0|                if (att2)
  ------------------
  |  Branch (7800:21): [True: 0, False: 0]
  ------------------
 7801|      0|                    sftk_FreeAttribute(att2);
 7802|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7803|      0|                break;
 7804|      0|            }
 7805|  60.4k|            sftk_FreeAttribute(att2);
 7806|  60.4k|            if (keyType != CKK_GENERIC_SECRET) {
  ------------------
  |  |  383|  60.4k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  |  Branch (7806:17): [True: 0, False: 60.4k]
  ------------------
 7807|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7808|      0|                break;
 7809|      0|            }
 7810|  60.4k|            if ((keySize != 0) && (keySize != SSL3_MASTER_SECRET_LENGTH)) {
  ------------------
  |  | 7518|      0|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
  |  Branch (7810:17): [True: 0, False: 60.4k]
  |  Branch (7810:35): [True: 0, False: 0]
  ------------------
 7811|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7812|      0|                break;
 7813|      0|            }
 7814|       |
 7815|       |            /* finally do the key gen */
 7816|  60.4k|            ssl3_master = (CK_SSL3_MASTER_KEY_DERIVE_PARAMS *)
 7817|  60.4k|                              pMechanism->pParameter;
 7818|       |
 7819|  60.4k|            if (ssl3_master->pVersion) {
  ------------------
  |  Branch (7819:17): [True: 21.7k, False: 38.7k]
  ------------------
 7820|  21.7k|                SFTKSessionObject *sessKey = sftk_narrowToSessionObject(key);
 7821|  21.7k|                rsa_pms = (SSL3RSAPreMasterSecret *)att->attrib.pValue;
 7822|       |                /* don't leak more key material then necessary for SSL to work */
 7823|  21.7k|                if ((sessKey == NULL) || sessKey->wasDerived) {
  ------------------
  |  Branch (7823:21): [True: 0, False: 21.7k]
  |  Branch (7823:42): [True: 0, False: 21.7k]
  ------------------
 7824|      0|                    ssl3_master->pVersion->major = 0xff;
 7825|      0|                    ssl3_master->pVersion->minor = 0xff;
 7826|  21.7k|                } else {
 7827|  21.7k|                    ssl3_master->pVersion->major = rsa_pms->client_version[0];
 7828|  21.7k|                    ssl3_master->pVersion->minor = rsa_pms->client_version[1];
 7829|  21.7k|                }
 7830|  21.7k|            }
 7831|  60.4k|            if (ssl3_master->RandomInfo.ulClientRandomLen != SSL3_RANDOM_LENGTH) {
  ------------------
  |  | 7519|  60.4k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  |  Branch (7831:17): [True: 0, False: 60.4k]
  ------------------
 7832|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7833|      0|                break;
 7834|      0|            }
 7835|  60.4k|            if (ssl3_master->RandomInfo.ulServerRandomLen != SSL3_RANDOM_LENGTH) {
  ------------------
  |  | 7519|  60.4k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  |  Branch (7835:17): [True: 0, False: 60.4k]
  ------------------
 7836|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7837|      0|                break;
 7838|      0|            }
 7839|  60.4k|            PORT_Memcpy(crsrdata,
  ------------------
  |  |  180|  60.4k|#define PORT_Memcpy memcpy
  ------------------
 7840|  60.4k|                        ssl3_master->RandomInfo.pClientRandom, SSL3_RANDOM_LENGTH);
  ------------------
  |  | 7519|  60.4k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 7841|  60.4k|            PORT_Memcpy(crsrdata + SSL3_RANDOM_LENGTH,
  ------------------
  |  |  180|  60.4k|#define PORT_Memcpy memcpy
  ------------------
                          PORT_Memcpy(crsrdata + SSL3_RANDOM_LENGTH,
  ------------------
  |  | 7519|  60.4k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 7842|  60.4k|                        ssl3_master->RandomInfo.pServerRandom, SSL3_RANDOM_LENGTH);
  ------------------
  |  | 7519|  60.4k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 7843|       |
 7844|  60.4k|            if (isTLS) {
  ------------------
  |  Branch (7844:17): [True: 60.4k, False: 0]
  ------------------
 7845|  60.4k|                SECStatus status;
 7846|  60.4k|                SECItem crsr = { siBuffer, NULL, 0 };
 7847|  60.4k|                SECItem master = { siBuffer, NULL, 0 };
 7848|  60.4k|                SECItem pms = { siBuffer, NULL, 0 };
 7849|       |
 7850|  60.4k|                crsr.data = crsrdata;
 7851|  60.4k|                crsr.len = sizeof crsrdata;
 7852|  60.4k|                master.data = key_block;
 7853|  60.4k|                master.len = SSL3_MASTER_SECRET_LENGTH;
  ------------------
  |  | 7518|  60.4k|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
 7854|  60.4k|                pms.data = (unsigned char *)att->attrib.pValue;
 7855|  60.4k|                pms.len = att->attrib.ulValueLen;
 7856|       |
 7857|  60.4k|                if (tlsPrfHash != HASH_AlgNULL) {
  ------------------
  |  Branch (7857:21): [True: 52.6k, False: 7.86k]
  ------------------
 7858|  52.6k|                    status = TLS_P_hash(tlsPrfHash, &pms, "master secret",
 7859|  52.6k|                                        &crsr, &master, isFIPS);
 7860|  52.6k|                } else {
 7861|  7.86k|                    status = TLS_PRF(&pms, "master secret", &crsr, &master, isFIPS);
 7862|  7.86k|                }
 7863|  60.4k|                if (status != SECSuccess) {
  ------------------
  |  Branch (7863:21): [True: 0, False: 60.4k]
  ------------------
 7864|      0|                    PORT_Memset(crsrdata, 0, sizeof crsrdata);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 7865|      0|                    crv = CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
 7866|      0|                    break;
 7867|      0|                }
 7868|  60.4k|            } else {
 7869|       |                /* now allocate the hash contexts */
 7870|      0|                md5 = MD5_NewContext();
 7871|      0|                if (md5 == NULL) {
  ------------------
  |  Branch (7871:21): [True: 0, False: 0]
  ------------------
 7872|      0|                    PORT_Memset(crsrdata, 0, sizeof crsrdata);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 7873|      0|                    crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 7874|      0|                    break;
 7875|      0|                }
 7876|      0|                sha = SHA1_NewContext();
 7877|      0|                if (sha == NULL) {
  ------------------
  |  Branch (7877:21): [True: 0, False: 0]
  ------------------
 7878|      0|                    PORT_Memset(crsrdata, 0, sizeof crsrdata);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 7879|      0|                    PORT_Free(md5);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 7880|      0|                    crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 7881|      0|                    break;
 7882|      0|                }
 7883|      0|                for (i = 0; i < 3; i++) {
  ------------------
  |  Branch (7883:29): [True: 0, False: 0]
  ------------------
 7884|      0|                    SHA1_Begin(sha);
 7885|      0|                    SHA1_Update(sha, (unsigned char *)mixers[i], strlen(mixers[i]));
 7886|      0|                    SHA1_Update(sha, (const unsigned char *)att->attrib.pValue,
 7887|      0|                                att->attrib.ulValueLen);
 7888|      0|                    SHA1_Update(sha, crsrdata, sizeof crsrdata);
 7889|      0|                    SHA1_End(sha, sha_out, &outLen, SHA1_LENGTH);
  ------------------
  |  |   39|      0|#define SHA1_LENGTH 20
  ------------------
 7890|      0|                    PORT_Assert(outLen == SHA1_LENGTH);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7891|       |
 7892|      0|                    MD5_Begin(md5);
 7893|      0|                    MD5_Update(md5, (const unsigned char *)att->attrib.pValue,
 7894|      0|                               att->attrib.ulValueLen);
 7895|      0|                    MD5_Update(md5, sha_out, outLen);
 7896|      0|                    MD5_End(md5, &key_block[i * MD5_LENGTH], &outLen, MD5_LENGTH);
  ------------------
  |  |   38|      0|#define MD5_LENGTH 16
  ------------------
                                  MD5_End(md5, &key_block[i * MD5_LENGTH], &outLen, MD5_LENGTH);
  ------------------
  |  |   38|      0|#define MD5_LENGTH 16
  ------------------
 7897|      0|                    PORT_Assert(outLen == MD5_LENGTH);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7898|      0|                }
 7899|      0|                PORT_Free(md5);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 7900|      0|                PORT_Free(sha);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 7901|      0|                PORT_Memset(crsrdata, 0, sizeof crsrdata);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 7902|      0|                PORT_Memset(sha_out, 0, sizeof sha_out);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 7903|      0|            }
 7904|       |
 7905|       |            /* store the results */
 7906|  60.4k|            crv = sftk_forceAttribute(key, CKA_VALUE, key_block, SSL3_MASTER_SECRET_LENGTH);
  ------------------
  |  |  516|  60.4k|#define CKA_VALUE 0x00000011UL
  ------------------
                          crv = sftk_forceAttribute(key, CKA_VALUE, key_block, SSL3_MASTER_SECRET_LENGTH);
  ------------------
  |  | 7518|  60.4k|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
 7907|  60.4k|            PORT_Memset(key_block, 0, sizeof key_block);
  ------------------
  |  |  182|  60.4k|#define PORT_Memset memset
  ------------------
 7908|  60.4k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7908:17): [True: 0, False: 60.4k]
  ------------------
 7909|      0|                break;
 7910|  60.4k|            keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|  60.4k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 7911|  60.4k|            crv = sftk_forceAttribute(key, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  543|  60.4k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 7912|  60.4k|            if (isTLS) {
  ------------------
  |  Branch (7912:17): [True: 60.4k, False: 0]
  ------------------
 7913|       |                /* TLS's master secret is used to "sign" finished msgs with PRF. */
 7914|       |                /* XXX This seems like a hack.   But SFTK_Derive only accepts
 7915|       |                 * one "operation" argument. */
 7916|  60.4k|                crv = sftk_forceAttribute(key, CKA_SIGN, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  551|  60.4k|#define CKA_SIGN 0x00000108UL
  ------------------
 7917|  60.4k|                if (crv != CKR_OK)
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7917:21): [True: 0, False: 60.4k]
  ------------------
 7918|      0|                    break;
 7919|  60.4k|                crv = sftk_forceAttribute(key, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  553|  60.4k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 7920|  60.4k|                if (crv != CKR_OK)
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7920:21): [True: 0, False: 60.4k]
  ------------------
 7921|      0|                    break;
 7922|       |                /* While we're here, we might as well force this, too. */
 7923|  60.4k|                crv = sftk_forceAttribute(key, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  555|  60.4k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 7924|  60.4k|                if (crv != CKR_OK)
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7924:21): [True: 0, False: 60.4k]
  ------------------
 7925|      0|                    break;
 7926|  60.4k|            }
 7927|  60.4k|            break;
 7928|  60.4k|        }
 7929|       |
 7930|       |        /* Extended master key derivation [draft-ietf-tls-session-hash] */
 7931|  60.4k|        case CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE:
  ------------------
  |  |  239|  1.44k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE (CKM_NSS + 25)
  |  |  ------------------
  |  |  |  |  162|  1.44k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  1.44k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  1.44k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7931:9): [True: 1.44k, False: 1.01M]
  ------------------
 7932|  6.58k|        case CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH: {
  ------------------
  |  |  240|  6.58k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH (CKM_NSS + 26)
  |  |  ------------------
  |  |  |  |  162|  6.58k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  6.58k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  6.58k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7932:9): [True: 5.14k, False: 1.01M]
  ------------------
 7933|  6.58k|            CK_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_PARAMS *ems_params;
 7934|  6.58k|            SSL3RSAPreMasterSecret *rsa_pms;
 7935|  6.58k|            SECStatus status;
 7936|  6.58k|            SECItem pms = { siBuffer, NULL, 0 };
 7937|  6.58k|            SECItem seed = { siBuffer, NULL, 0 };
 7938|  6.58k|            SECItem master = { siBuffer, NULL, 0 };
 7939|       |
 7940|  6.58k|            ems_params = (CK_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_PARAMS *)
 7941|  6.58k|                             pMechanism->pParameter;
 7942|       |
 7943|       |            /* First do the consistency checks */
 7944|  6.58k|            if ((mechanism == CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE) &&
  ------------------
  |  |  239|  6.58k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE (CKM_NSS + 25)
  |  |  ------------------
  |  |  |  |  162|  6.58k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  6.58k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  6.58k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (7944:17): [True: 1.44k, False: 5.14k]
  ------------------
 7945|  6.58k|                (att->attrib.ulValueLen != SSL3_PMS_LENGTH)) {
  ------------------
  |  | 7517|  1.44k|#define SSL3_PMS_LENGTH 48
  ------------------
  |  Branch (7945:17): [True: 8, False: 1.43k]
  ------------------
 7946|      8|                crv = CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      8|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 7947|      8|                break;
 7948|      8|            }
 7949|  6.58k|            att2 = sftk_FindAttribute(sourceKey, CKA_KEY_TYPE);
  ------------------
  |  |  543|  6.58k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 7950|  6.58k|            if ((att2 == NULL) ||
  ------------------
  |  Branch (7950:17): [True: 0, False: 6.58k]
  ------------------
 7951|  6.58k|                (*(CK_KEY_TYPE *)att2->attrib.pValue != CKK_GENERIC_SECRET)) {
  ------------------
  |  |  383|  6.58k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  |  Branch (7951:17): [True: 0, False: 6.58k]
  ------------------
 7952|      0|                if (att2)
  ------------------
  |  Branch (7952:21): [True: 0, False: 0]
  ------------------
 7953|      0|                    sftk_FreeAttribute(att2);
 7954|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7955|      0|                break;
 7956|      0|            }
 7957|  6.58k|            sftk_FreeAttribute(att2);
 7958|  6.58k|            if (keyType != CKK_GENERIC_SECRET) {
  ------------------
  |  |  383|  6.58k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  |  Branch (7958:17): [True: 0, False: 6.58k]
  ------------------
 7959|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7960|      0|                break;
 7961|      0|            }
 7962|  6.58k|            if ((keySize != 0) && (keySize != SSL3_MASTER_SECRET_LENGTH)) {
  ------------------
  |  | 7518|      0|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
  |  Branch (7962:17): [True: 0, False: 6.58k]
  |  Branch (7962:35): [True: 0, False: 0]
  ------------------
 7963|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7964|      0|                break;
 7965|      0|            }
 7966|       |
 7967|       |            /* Do the key derivation */
 7968|  6.58k|            pms.data = (unsigned char *)att->attrib.pValue;
 7969|  6.58k|            pms.len = att->attrib.ulValueLen;
 7970|  6.58k|            seed.data = ems_params->pSessionHash;
 7971|  6.58k|            seed.len = ems_params->ulSessionHashLen;
 7972|  6.58k|            master.data = key_block;
 7973|  6.58k|            master.len = SSL3_MASTER_SECRET_LENGTH;
  ------------------
  |  | 7518|  6.58k|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
 7974|  6.58k|            if (ems_params->prfHashMechanism == CKM_TLS_PRF) {
  ------------------
  |  |  973|  6.58k|#define CKM_TLS_PRF 0x00000378UL
  ------------------
  |  Branch (7974:17): [True: 677, False: 5.90k]
  ------------------
 7975|       |                /*
 7976|       |                 * In this case, the session hash is the concatenation of SHA-1
 7977|       |                 * and MD5, so it should be 36 bytes long.
 7978|       |                 */
 7979|    677|                if (seed.len != MD5_LENGTH + SHA1_LENGTH) {
  ------------------
  |  |   38|    677|#define MD5_LENGTH 16
  ------------------
                              if (seed.len != MD5_LENGTH + SHA1_LENGTH) {
  ------------------
  |  |   39|    677|#define SHA1_LENGTH 20
  ------------------
  |  Branch (7979:21): [True: 0, False: 677]
  ------------------
 7980|      0|                    crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 7981|      0|                    break;
 7982|      0|                }
 7983|       |
 7984|    677|                status = TLS_PRF(&pms, "extended master secret",
 7985|    677|                                 &seed, &master, isFIPS);
 7986|  5.90k|            } else {
 7987|  5.90k|                const SECHashObject *hashObj;
 7988|       |
 7989|  5.90k|                tlsPrfHash = sftk_GetHashTypeFromMechanism(ems_params->prfHashMechanism);
 7990|  5.90k|                if (tlsPrfHash == HASH_AlgNULL) {
  ------------------
  |  Branch (7990:21): [True: 0, False: 5.90k]
  ------------------
 7991|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 7992|      0|                    break;
 7993|      0|                }
 7994|       |
 7995|  5.90k|                hashObj = HASH_GetRawHashObject(tlsPrfHash);
 7996|  5.90k|                if (seed.len != hashObj->length) {
  ------------------
  |  Branch (7996:21): [True: 0, False: 5.90k]
  ------------------
 7997|      0|                    crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 7998|      0|                    break;
 7999|      0|                }
 8000|       |
 8001|  5.90k|                status = TLS_P_hash(tlsPrfHash, &pms, "extended master secret",
 8002|  5.90k|                                    &seed, &master, isFIPS);
 8003|  5.90k|            }
 8004|  6.58k|            if (status != SECSuccess) {
  ------------------
  |  Branch (8004:17): [True: 0, False: 6.58k]
  ------------------
 8005|      0|                crv = CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
 8006|      0|                break;
 8007|      0|            }
 8008|       |
 8009|       |            /* Reflect the version if required */
 8010|  6.58k|            if (ems_params->pVersion) {
  ------------------
  |  Branch (8010:17): [True: 1.43k, False: 5.14k]
  ------------------
 8011|  1.43k|                SFTKSessionObject *sessKey = sftk_narrowToSessionObject(key);
 8012|  1.43k|                rsa_pms = (SSL3RSAPreMasterSecret *)att->attrib.pValue;
 8013|       |                /* don't leak more key material than necessary for SSL to work */
 8014|  1.43k|                if ((sessKey == NULL) || sessKey->wasDerived) {
  ------------------
  |  Branch (8014:21): [True: 0, False: 1.43k]
  |  Branch (8014:42): [True: 0, False: 1.43k]
  ------------------
 8015|      0|                    ems_params->pVersion->major = 0xff;
 8016|      0|                    ems_params->pVersion->minor = 0xff;
 8017|  1.43k|                } else {
 8018|  1.43k|                    ems_params->pVersion->major = rsa_pms->client_version[0];
 8019|  1.43k|                    ems_params->pVersion->minor = rsa_pms->client_version[1];
 8020|  1.43k|                }
 8021|  1.43k|            }
 8022|       |
 8023|       |            /* Store the results */
 8024|  6.58k|            crv = sftk_forceAttribute(key, CKA_VALUE, key_block,
  ------------------
  |  |  516|  6.58k|#define CKA_VALUE 0x00000011UL
  ------------------
 8025|  6.58k|                                      SSL3_MASTER_SECRET_LENGTH);
  ------------------
  |  | 7518|  6.58k|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
 8026|  6.58k|            PORT_Memset(key_block, 0, sizeof key_block);
  ------------------
  |  |  182|  6.58k|#define PORT_Memset memset
  ------------------
 8027|  6.58k|            break;
 8028|  6.58k|        }
 8029|       |
 8030|  49.5k|        case CKM_TLS12_KEY_AND_MAC_DERIVE:
  ------------------
  |  | 1027|  49.5k|#define CKM_TLS12_KEY_AND_MAC_DERIVE 0x000003E1UL
  ------------------
  |  Branch (8030:9): [True: 49.5k, False: 965k]
  ------------------
 8031|  49.5k|        case CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256:
  ------------------
  |  |  235|  49.5k|#define CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256 (CKM_NSS + 23)
  |  |  ------------------
  |  |  |  |  162|  49.5k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  49.5k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  49.5k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (8031:9): [True: 0, False: 1.01M]
  ------------------
 8032|  55.8k|        case CKM_TLS_KEY_AND_MAC_DERIVE:
  ------------------
  |  |  969|  55.8k|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
  |  Branch (8032:9): [True: 6.27k, False: 1.00M]
  ------------------
 8033|  55.8k|        case CKM_SSL3_KEY_AND_MAC_DERIVE: {
  ------------------
  |  |  961|  55.8k|#define CKM_SSL3_KEY_AND_MAC_DERIVE 0x00000372UL
  ------------------
  |  Branch (8033:9): [True: 0, False: 1.01M]
  ------------------
 8034|  55.8k|            CK_SSL3_KEY_MAT_PARAMS *ssl3_keys;
 8035|  55.8k|            CK_SSL3_KEY_MAT_OUT *ssl3_keys_out;
 8036|  55.8k|            CK_ULONG effKeySize;
 8037|  55.8k|            unsigned int block_needed;
 8038|  55.8k|            unsigned char srcrdata[SSL3_RANDOM_LENGTH * 2];
 8039|       |
 8040|  55.8k|            if (mechanism == CKM_TLS12_KEY_AND_MAC_DERIVE) {
  ------------------
  |  | 1027|  55.8k|#define CKM_TLS12_KEY_AND_MAC_DERIVE 0x000003E1UL
  ------------------
  |  Branch (8040:17): [True: 49.5k, False: 6.27k]
  ------------------
 8041|  49.5k|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_TLS12_KEY_MAT_PARAMS))) {
  ------------------
  |  |   50|  49.5k|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 49.5k]
  |  |  |  Branch (50:64): [True: 0, False: 49.5k]
  |  |  ------------------
  ------------------
 8042|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8043|      0|                    break;
 8044|      0|                }
 8045|  49.5k|                CK_TLS12_KEY_MAT_PARAMS *tls12_keys =
 8046|  49.5k|                    (CK_TLS12_KEY_MAT_PARAMS *)pMechanism->pParameter;
 8047|  49.5k|                tlsPrfHash = sftk_GetHashTypeFromMechanism(tls12_keys->prfHashMechanism);
 8048|  49.5k|                if (tlsPrfHash == HASH_AlgNULL) {
  ------------------
  |  Branch (8048:21): [True: 0, False: 49.5k]
  ------------------
 8049|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8050|      0|                    break;
 8051|      0|                }
 8052|  49.5k|            } else if (mechanism == CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256) {
  ------------------
  |  |  235|  6.27k|#define CKM_NSS_TLS_KEY_AND_MAC_DERIVE_SHA256 (CKM_NSS + 23)
  |  |  ------------------
  |  |  |  |  162|  6.27k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  6.27k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  6.27k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (8052:24): [True: 0, False: 6.27k]
  ------------------
 8053|      0|                tlsPrfHash = HASH_AlgSHA256;
 8054|      0|            }
 8055|       |
 8056|  55.8k|            if (mechanism != CKM_SSL3_KEY_AND_MAC_DERIVE) {
  ------------------
  |  |  961|  55.8k|#define CKM_SSL3_KEY_AND_MAC_DERIVE 0x00000372UL
  ------------------
  |  Branch (8056:17): [True: 55.8k, False: 0]
  ------------------
 8057|  55.8k|                isTLS = PR_TRUE;
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 8058|  55.8k|            }
 8059|       |
 8060|  55.8k|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|  55.8k|#define PR_FALSE 0
  ------------------
 8061|  55.8k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  55.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8061:17): [True: 0, False: 55.8k]
  ------------------
 8062|      0|                break;
 8063|       |
 8064|  55.8k|            if (att->attrib.ulValueLen != SSL3_MASTER_SECRET_LENGTH) {
  ------------------
  |  | 7518|  55.8k|#define SSL3_MASTER_SECRET_LENGTH 48
  ------------------
  |  Branch (8064:17): [True: 0, False: 55.8k]
  ------------------
 8065|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 8066|      0|                break;
 8067|      0|            }
 8068|  55.8k|            att2 = sftk_FindAttribute(sourceKey, CKA_KEY_TYPE);
  ------------------
  |  |  543|  55.8k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 8069|  55.8k|            if ((att2 == NULL) || (*(CK_KEY_TYPE *)att2->attrib.pValue !=
  ------------------
  |  Branch (8069:17): [True: 0, False: 55.8k]
  |  Branch (8069:35): [True: 0, False: 55.8k]
  ------------------
 8070|  55.8k|                                   CKK_GENERIC_SECRET)) {
  ------------------
  |  |  383|  55.8k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 8071|      0|                if (att2)
  ------------------
  |  Branch (8071:21): [True: 0, False: 0]
  ------------------
 8072|      0|                    sftk_FreeAttribute(att2);
 8073|      0|                crv = CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 8074|      0|                break;
 8075|      0|            }
 8076|  55.8k|            sftk_FreeAttribute(att2);
 8077|  55.8k|            md5 = MD5_NewContext();
 8078|  55.8k|            if (md5 == NULL) {
  ------------------
  |  Branch (8078:17): [True: 0, False: 55.8k]
  ------------------
 8079|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8080|      0|                break;
 8081|      0|            }
 8082|  55.8k|            sha = SHA1_NewContext();
 8083|  55.8k|            if (sha == NULL) {
  ------------------
  |  Branch (8083:17): [True: 0, False: 55.8k]
  ------------------
 8084|      0|                MD5_DestroyContext(md5, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8085|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8086|      0|                break;
 8087|      0|            }
 8088|       |
 8089|  55.8k|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_SSL3_KEY_MAT_PARAMS))) {
  ------------------
  |  |   50|  55.8k|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 55.8k]
  |  |  |  Branch (50:64): [True: 0, False: 55.8k]
  |  |  ------------------
  ------------------
 8090|      0|                MD5_DestroyContext(md5, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8091|      0|                SHA1_DestroyContext(sha, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8092|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8093|      0|                break;
 8094|      0|            }
 8095|  55.8k|            ssl3_keys = (CK_SSL3_KEY_MAT_PARAMS *)pMechanism->pParameter;
 8096|       |
 8097|  55.8k|            PORT_Memcpy(srcrdata,
  ------------------
  |  |  180|  55.8k|#define PORT_Memcpy memcpy
  ------------------
 8098|  55.8k|                        ssl3_keys->RandomInfo.pServerRandom, SSL3_RANDOM_LENGTH);
  ------------------
  |  | 7519|  55.8k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 8099|  55.8k|            PORT_Memcpy(srcrdata + SSL3_RANDOM_LENGTH,
  ------------------
  |  |  180|  55.8k|#define PORT_Memcpy memcpy
  ------------------
                          PORT_Memcpy(srcrdata + SSL3_RANDOM_LENGTH,
  ------------------
  |  | 7519|  55.8k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 8100|  55.8k|                        ssl3_keys->RandomInfo.pClientRandom, SSL3_RANDOM_LENGTH);
  ------------------
  |  | 7519|  55.8k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 8101|       |
 8102|       |            /*
 8103|       |             * clear out our returned keys so we can recover on failure
 8104|       |             */
 8105|  55.8k|            ssl3_keys_out = ssl3_keys->pReturnedKeyMaterial;
 8106|  55.8k|            ssl3_keys_out->hClientMacSecret = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  55.8k|#define CK_INVALID_HANDLE 0
  ------------------
 8107|  55.8k|            ssl3_keys_out->hServerMacSecret = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  55.8k|#define CK_INVALID_HANDLE 0
  ------------------
 8108|  55.8k|            ssl3_keys_out->hClientKey = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  55.8k|#define CK_INVALID_HANDLE 0
  ------------------
 8109|  55.8k|            ssl3_keys_out->hServerKey = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  55.8k|#define CK_INVALID_HANDLE 0
  ------------------
 8110|       |
 8111|       |            /*
 8112|       |             * How much key material do we need?
 8113|       |             */
 8114|  55.8k|            macSize = ssl3_keys->ulMacSizeInBits / 8;
 8115|  55.8k|            effKeySize = ssl3_keys->ulKeySizeInBits / 8;
 8116|  55.8k|            IVSize = ssl3_keys->ulIVSizeInBits / 8;
 8117|  55.8k|            if (keySize == 0) {
  ------------------
  |  Branch (8117:17): [True: 6.40k, False: 49.4k]
  ------------------
 8118|  6.40k|                effKeySize = keySize;
 8119|  6.40k|            }
 8120|       |
 8121|       |            /* bIsExport must be false. */
 8122|  55.8k|            if (ssl3_keys->bIsExport) {
  ------------------
  |  Branch (8122:17): [True: 0, False: 55.8k]
  ------------------
 8123|      0|                MD5_DestroyContext(md5, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8124|      0|                SHA1_DestroyContext(sha, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8125|      0|                PORT_Memset(srcrdata, 0, sizeof srcrdata);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 8126|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8127|      0|                break;
 8128|      0|            }
 8129|       |
 8130|  55.8k|            block_needed = 2 * (macSize + effKeySize + IVSize);
 8131|  55.8k|            PORT_Assert(block_needed <= sizeof key_block);
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  55.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 55.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8132|  55.8k|            if (block_needed > sizeof key_block)
  ------------------
  |  Branch (8132:17): [True: 0, False: 55.8k]
  ------------------
 8133|      0|                block_needed = sizeof key_block;
 8134|       |
 8135|       |            /*
 8136|       |             * generate the key material: This looks amazingly similar to the
 8137|       |             * PMS code, and is clearly crying out for a function to provide it.
 8138|       |             */
 8139|  55.8k|            if (isTLS) {
  ------------------
  |  Branch (8139:17): [True: 55.8k, False: 0]
  ------------------
 8140|  55.8k|                SECStatus status;
 8141|  55.8k|                SECItem srcr = { siBuffer, NULL, 0 };
 8142|  55.8k|                SECItem keyblk = { siBuffer, NULL, 0 };
 8143|  55.8k|                SECItem master = { siBuffer, NULL, 0 };
 8144|       |
 8145|  55.8k|                srcr.data = srcrdata;
 8146|  55.8k|                srcr.len = sizeof srcrdata;
 8147|  55.8k|                keyblk.data = key_block;
 8148|  55.8k|                keyblk.len = block_needed;
 8149|  55.8k|                master.data = (unsigned char *)att->attrib.pValue;
 8150|  55.8k|                master.len = att->attrib.ulValueLen;
 8151|       |
 8152|  55.8k|                if (tlsPrfHash != HASH_AlgNULL) {
  ------------------
  |  Branch (8152:21): [True: 49.5k, False: 6.27k]
  ------------------
 8153|  49.5k|                    status = TLS_P_hash(tlsPrfHash, &master, "key expansion",
 8154|  49.5k|                                        &srcr, &keyblk, isFIPS);
 8155|  49.5k|                } else {
 8156|  6.27k|                    status = TLS_PRF(&master, "key expansion", &srcr, &keyblk,
 8157|  6.27k|                                     isFIPS);
 8158|  6.27k|                }
 8159|  55.8k|                if (status != SECSuccess) {
  ------------------
  |  Branch (8159:21): [True: 0, False: 55.8k]
  ------------------
 8160|      0|                    goto key_and_mac_derive_fail;
 8161|      0|                }
 8162|  55.8k|            } else {
 8163|      0|                unsigned int block_bytes = 0;
 8164|       |                /* key_block =
 8165|       |                 *     MD5(master_secret + SHA('A' + master_secret +
 8166|       |                 *                      ServerHello.random + ClientHello.random)) +
 8167|       |                 *     MD5(master_secret + SHA('BB' + master_secret +
 8168|       |                 *                      ServerHello.random + ClientHello.random)) +
 8169|       |                 *     MD5(master_secret + SHA('CCC' + master_secret +
 8170|       |                 *                      ServerHello.random + ClientHello.random)) +
 8171|       |                 *     [...];
 8172|       |                 */
 8173|      0|                for (i = 0; i < NUM_MIXERS && block_bytes < block_needed; i++) {
  ------------------
  |  | 7505|      0|#define NUM_MIXERS 9
  ------------------
  |  Branch (8173:29): [True: 0, False: 0]
  |  Branch (8173:47): [True: 0, False: 0]
  ------------------
 8174|      0|                    SHA1_Begin(sha);
 8175|      0|                    SHA1_Update(sha, (unsigned char *)mixers[i], strlen(mixers[i]));
 8176|      0|                    SHA1_Update(sha, (const unsigned char *)att->attrib.pValue,
 8177|      0|                                att->attrib.ulValueLen);
 8178|      0|                    SHA1_Update(sha, srcrdata, sizeof srcrdata);
 8179|      0|                    SHA1_End(sha, sha_out, &outLen, SHA1_LENGTH);
  ------------------
  |  |   39|      0|#define SHA1_LENGTH 20
  ------------------
 8180|      0|                    PORT_Assert(outLen == SHA1_LENGTH);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8181|      0|                    MD5_Begin(md5);
 8182|      0|                    MD5_Update(md5, (const unsigned char *)att->attrib.pValue,
 8183|      0|                               att->attrib.ulValueLen);
 8184|      0|                    MD5_Update(md5, sha_out, outLen);
 8185|      0|                    MD5_End(md5, &key_block[i * MD5_LENGTH], &outLen, MD5_LENGTH);
  ------------------
  |  |   38|      0|#define MD5_LENGTH 16
  ------------------
                                  MD5_End(md5, &key_block[i * MD5_LENGTH], &outLen, MD5_LENGTH);
  ------------------
  |  |   38|      0|#define MD5_LENGTH 16
  ------------------
 8186|      0|                    PORT_Assert(outLen == MD5_LENGTH);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8187|      0|                    block_bytes += outLen;
 8188|      0|                }
 8189|      0|                PORT_Memset(sha_out, 0, sizeof sha_out);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 8190|      0|            }
 8191|       |
 8192|       |            /*
 8193|       |             * Put the key material where it goes.
 8194|       |             */
 8195|  55.8k|            i = 0; /* now shows how much consumed */
 8196|       |
 8197|       |            /*
 8198|       |             * The key_block is partitioned as follows:
 8199|       |             * client_write_MAC_secret[CipherSpec.hash_size]
 8200|       |             */
 8201|  55.8k|            crv = sftk_buildSSLKey(hSession, key, PR_TRUE, &key_block[i], macSize,
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 8202|  55.8k|                                   &ssl3_keys_out->hClientMacSecret);
 8203|  55.8k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  55.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8203:17): [True: 0, False: 55.8k]
  ------------------
 8204|      0|                goto key_and_mac_derive_fail;
 8205|       |
 8206|  55.8k|            i += macSize;
 8207|       |
 8208|       |            /*
 8209|       |             * server_write_MAC_secret[CipherSpec.hash_size]
 8210|       |             */
 8211|  55.8k|            crv = sftk_buildSSLKey(hSession, key, PR_TRUE, &key_block[i], macSize,
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 8212|  55.8k|                                   &ssl3_keys_out->hServerMacSecret);
 8213|  55.8k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  55.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8213:17): [True: 0, False: 55.8k]
  ------------------
 8214|      0|                goto key_and_mac_derive_fail;
 8215|      0|            }
 8216|  55.8k|            i += macSize;
 8217|       |
 8218|  55.8k|            if (keySize) {
  ------------------
  |  Branch (8218:17): [True: 49.4k, False: 6.40k]
  ------------------
 8219|       |                /*
 8220|       |                ** Generate Domestic write keys and IVs.
 8221|       |                ** client_write_key[CipherSpec.key_material]
 8222|       |                */
 8223|  49.4k|                crv = sftk_buildSSLKey(hSession, key, PR_FALSE, &key_block[i],
  ------------------
  |  |  438|  49.4k|#define PR_FALSE 0
  ------------------
 8224|  49.4k|                                       keySize, &ssl3_keys_out->hClientKey);
 8225|  49.4k|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|  49.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8225:21): [True: 0, False: 49.4k]
  ------------------
 8226|      0|                    goto key_and_mac_derive_fail;
 8227|      0|                }
 8228|  49.4k|                i += keySize;
 8229|       |
 8230|       |                /*
 8231|       |                ** server_write_key[CipherSpec.key_material]
 8232|       |                */
 8233|  49.4k|                crv = sftk_buildSSLKey(hSession, key, PR_FALSE, &key_block[i],
  ------------------
  |  |  438|  49.4k|#define PR_FALSE 0
  ------------------
 8234|  49.4k|                                       keySize, &ssl3_keys_out->hServerKey);
 8235|  49.4k|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|  49.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8235:21): [True: 0, False: 49.4k]
  ------------------
 8236|      0|                    goto key_and_mac_derive_fail;
 8237|      0|                }
 8238|  49.4k|                i += keySize;
 8239|       |
 8240|       |                /*
 8241|       |                ** client_write_IV[CipherSpec.IV_size]
 8242|       |                */
 8243|  49.4k|                if (IVSize > 0) {
  ------------------
  |  Branch (8243:21): [True: 48.8k, False: 593]
  ------------------
 8244|  48.8k|                    PORT_Memcpy(ssl3_keys_out->pIVClient,
  ------------------
  |  |  180|  48.8k|#define PORT_Memcpy memcpy
  ------------------
 8245|  48.8k|                                &key_block[i], IVSize);
 8246|  48.8k|                    i += IVSize;
 8247|  48.8k|                }
 8248|       |
 8249|       |                /*
 8250|       |                ** server_write_IV[CipherSpec.IV_size]
 8251|       |                */
 8252|  49.4k|                if (IVSize > 0) {
  ------------------
  |  Branch (8252:21): [True: 48.8k, False: 593]
  ------------------
 8253|  48.8k|                    PORT_Memcpy(ssl3_keys_out->pIVServer,
  ------------------
  |  |  180|  48.8k|#define PORT_Memcpy memcpy
  ------------------
 8254|  48.8k|                                &key_block[i], IVSize);
 8255|  48.8k|                    i += IVSize;
 8256|  48.8k|                }
 8257|  49.4k|                PORT_Assert(i <= sizeof key_block);
  ------------------
  |  |  120|  49.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  49.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 49.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8258|  49.4k|            }
 8259|       |
 8260|  55.8k|            crv = CKR_OK;
  ------------------
  |  | 1388|  55.8k|#define CKR_OK 0x00000000UL
  ------------------
 8261|       |
 8262|  55.8k|            if (0) {
  ------------------
  |  Branch (8262:17): [Folded - Ignored]
  ------------------
 8263|      0|            key_and_mac_derive_fail:
 8264|      0|                if (crv == CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8264:21): [True: 0, False: 0]
  ------------------
 8265|      0|                    crv = CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
 8266|      0|                sftk_freeSSLKeys(hSession, ssl3_keys_out);
 8267|      0|            }
 8268|  55.8k|            PORT_Memset(srcrdata, 0, sizeof srcrdata);
  ------------------
  |  |  182|  55.8k|#define PORT_Memset memset
  ------------------
 8269|  55.8k|            PORT_Memset(key_block, 0, sizeof key_block);
  ------------------
  |  |  182|  55.8k|#define PORT_Memset memset
  ------------------
 8270|  55.8k|            MD5_DestroyContext(md5, PR_TRUE);
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 8271|  55.8k|            SHA1_DestroyContext(sha, PR_TRUE);
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 8272|  55.8k|            sftk_FreeObject(key);
 8273|  55.8k|            key = NULL;
 8274|  55.8k|            break;
 8275|  55.8k|        }
 8276|       |
 8277|      0|        case CKM_DES3_ECB_ENCRYPT_DATA:
  ------------------
  |  | 1184|      0|#define CKM_DES3_ECB_ENCRYPT_DATA 0x00001102UL
  ------------------
  |  Branch (8277:9): [True: 0, False: 1.01M]
  ------------------
 8278|      0|        case CKM_DES3_CBC_ENCRYPT_DATA: {
  ------------------
  |  | 1185|      0|#define CKM_DES3_CBC_ENCRYPT_DATA 0x00001103UL
  ------------------
  |  Branch (8278:9): [True: 0, False: 1.01M]
  ------------------
 8279|      0|            void *cipherInfo;
 8280|      0|            unsigned char des3key[MAX_DES3_KEY_SIZE];
 8281|      0|            CK_DES_CBC_ENCRYPT_DATA_PARAMS *desEncryptPtr;
 8282|      0|            int mode;
 8283|      0|            unsigned char *iv;
 8284|      0|            unsigned char *data;
 8285|      0|            CK_ULONG len;
 8286|       |
 8287|      0|            if (mechanism == CKM_DES3_ECB_ENCRYPT_DATA) {
  ------------------
  |  | 1184|      0|#define CKM_DES3_ECB_ENCRYPT_DATA 0x00001102UL
  ------------------
  |  Branch (8287:17): [True: 0, False: 0]
  ------------------
 8288|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8289|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8290|      0|                    break;
 8291|      0|                }
 8292|      0|                stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)
 8293|      0|                                pMechanism->pParameter;
 8294|      0|                mode = NSS_DES_EDE3;
  ------------------
  |  |   27|      0|#define NSS_DES_EDE3 2
  ------------------
 8295|      0|                iv = NULL;
 8296|      0|                data = stringPtr->pData;
 8297|      0|                len = stringPtr->ulLen;
 8298|      0|            } else {
 8299|      0|                mode = NSS_DES_EDE3_CBC;
  ------------------
  |  |   28|      0|#define NSS_DES_EDE3_CBC 3
  ------------------
 8300|      0|                desEncryptPtr =
 8301|      0|                    (CK_DES_CBC_ENCRYPT_DATA_PARAMS *)
 8302|      0|                        pMechanism->pParameter;
 8303|      0|                iv = desEncryptPtr->iv;
 8304|      0|                data = desEncryptPtr->pData;
 8305|      0|                len = desEncryptPtr->length;
 8306|      0|            }
 8307|      0|            if (att->attrib.ulValueLen == 16) {
  ------------------
  |  Branch (8307:17): [True: 0, False: 0]
  ------------------
 8308|      0|                PORT_Memcpy(des3key, att->attrib.pValue, 16);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8309|      0|                PORT_Memcpy(des3key + 16, des3key, 8);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8310|      0|            } else if (att->attrib.ulValueLen == 24) {
  ------------------
  |  Branch (8310:24): [True: 0, False: 0]
  ------------------
 8311|      0|                PORT_Memcpy(des3key, att->attrib.pValue, 24);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8312|      0|            } else {
 8313|      0|                crv = CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
 8314|      0|                break;
 8315|      0|            }
 8316|      0|            cipherInfo = DES_CreateContext(des3key, iv, mode, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8317|      0|            PORT_Memset(des3key, 0, 24);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 8318|      0|            if (cipherInfo == NULL) {
  ------------------
  |  Branch (8318:17): [True: 0, False: 0]
  ------------------
 8319|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8320|      0|                break;
 8321|      0|            }
 8322|      0|            crv = sftk_DeriveEncrypt(SFTKCipher_DES_Encrypt,
 8323|      0|                                     cipherInfo, 8, key, keySize,
 8324|      0|                                     data, len);
 8325|      0|            DES_DestroyContext(cipherInfo, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8326|      0|            break;
 8327|      0|        }
 8328|       |
 8329|      0|        case CKM_AES_ECB_ENCRYPT_DATA:
  ------------------
  |  | 1186|      0|#define CKM_AES_ECB_ENCRYPT_DATA 0x00001104UL
  ------------------
  |  Branch (8329:9): [True: 0, False: 1.01M]
  ------------------
 8330|      0|        case CKM_AES_CBC_ENCRYPT_DATA: {
  ------------------
  |  | 1187|      0|#define CKM_AES_CBC_ENCRYPT_DATA 0x00001105UL
  ------------------
  |  Branch (8330:9): [True: 0, False: 1.01M]
  ------------------
 8331|      0|            void *cipherInfo;
 8332|      0|            CK_AES_CBC_ENCRYPT_DATA_PARAMS *aesEncryptPtr;
 8333|      0|            int mode;
 8334|      0|            unsigned char *iv;
 8335|      0|            unsigned char *data;
 8336|      0|            CK_ULONG len;
 8337|       |
 8338|      0|            if (mechanism == CKM_AES_ECB_ENCRYPT_DATA) {
  ------------------
  |  | 1186|      0|#define CKM_AES_ECB_ENCRYPT_DATA 0x00001104UL
  ------------------
  |  Branch (8338:17): [True: 0, False: 0]
  ------------------
 8339|      0|                mode = NSS_AES;
  ------------------
  |  |   35|      0|#define NSS_AES 0
  ------------------
 8340|      0|                iv = NULL;
 8341|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8342|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8343|      0|                    break;
 8344|      0|                }
 8345|      0|                stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)pMechanism->pParameter;
 8346|      0|                data = stringPtr->pData;
 8347|      0|                len = stringPtr->ulLen;
 8348|      0|            } else {
 8349|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_AES_CBC_ENCRYPT_DATA_PARAMS))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8350|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8351|      0|                    break;
 8352|      0|                }
 8353|      0|                aesEncryptPtr =
 8354|      0|                    (CK_AES_CBC_ENCRYPT_DATA_PARAMS *)pMechanism->pParameter;
 8355|      0|                mode = NSS_AES_CBC;
  ------------------
  |  |   36|      0|#define NSS_AES_CBC 1
  ------------------
 8356|      0|                iv = aesEncryptPtr->iv;
 8357|      0|                data = aesEncryptPtr->pData;
 8358|      0|                len = aesEncryptPtr->length;
 8359|      0|            }
 8360|       |
 8361|      0|            cipherInfo = AES_CreateContext((unsigned char *)att->attrib.pValue,
 8362|      0|                                           iv, mode, PR_TRUE,
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8363|      0|                                           att->attrib.ulValueLen, 16);
 8364|      0|            if (cipherInfo == NULL) {
  ------------------
  |  Branch (8364:17): [True: 0, False: 0]
  ------------------
 8365|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8366|      0|                break;
 8367|      0|            }
 8368|      0|            crv = sftk_DeriveEncrypt(SFTKCipher_AES_Encrypt,
 8369|      0|                                     cipherInfo, 16, key, keySize,
 8370|      0|                                     data, len);
 8371|      0|            AES_DestroyContext(cipherInfo, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8372|      0|            break;
 8373|      0|        }
 8374|       |
 8375|      0|        case CKM_CAMELLIA_ECB_ENCRYPT_DATA:
  ------------------
  |  | 1141|      0|#define CKM_CAMELLIA_ECB_ENCRYPT_DATA 0x00000556UL
  ------------------
  |  Branch (8375:9): [True: 0, False: 1.01M]
  ------------------
 8376|      0|        case CKM_CAMELLIA_CBC_ENCRYPT_DATA: {
  ------------------
  |  | 1142|      0|#define CKM_CAMELLIA_CBC_ENCRYPT_DATA 0x00000557UL
  ------------------
  |  Branch (8376:9): [True: 0, False: 1.01M]
  ------------------
 8377|      0|            void *cipherInfo;
 8378|      0|            CK_AES_CBC_ENCRYPT_DATA_PARAMS *aesEncryptPtr;
 8379|      0|            int mode;
 8380|      0|            unsigned char *iv;
 8381|      0|            unsigned char *data;
 8382|      0|            CK_ULONG len;
 8383|       |
 8384|      0|            if (mechanism == CKM_CAMELLIA_ECB_ENCRYPT_DATA) {
  ------------------
  |  | 1141|      0|#define CKM_CAMELLIA_ECB_ENCRYPT_DATA 0x00000556UL
  ------------------
  |  Branch (8384:17): [True: 0, False: 0]
  ------------------
 8385|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8386|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8387|      0|                    break;
 8388|      0|                }
 8389|      0|                stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)
 8390|      0|                                pMechanism->pParameter;
 8391|      0|                aesEncryptPtr = NULL;
 8392|      0|                mode = NSS_CAMELLIA;
  ------------------
  |  |   42|      0|#define NSS_CAMELLIA 0
  ------------------
 8393|      0|                data = stringPtr->pData;
 8394|      0|                len = stringPtr->ulLen;
 8395|      0|                iv = NULL;
 8396|      0|            } else {
 8397|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_AES_CBC_ENCRYPT_DATA_PARAMS))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8398|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8399|      0|                    break;
 8400|      0|                }
 8401|      0|                stringPtr = NULL;
 8402|      0|                aesEncryptPtr = (CK_AES_CBC_ENCRYPT_DATA_PARAMS *)
 8403|      0|                                    pMechanism->pParameter;
 8404|      0|                mode = NSS_CAMELLIA_CBC;
  ------------------
  |  |   43|      0|#define NSS_CAMELLIA_CBC 1
  ------------------
 8405|      0|                iv = aesEncryptPtr->iv;
 8406|      0|                data = aesEncryptPtr->pData;
 8407|      0|                len = aesEncryptPtr->length;
 8408|      0|            }
 8409|       |
 8410|      0|            cipherInfo = Camellia_CreateContext((unsigned char *)att->attrib.pValue,
 8411|      0|                                                iv, mode, PR_TRUE,
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8412|      0|                                                att->attrib.ulValueLen);
 8413|      0|            if (cipherInfo == NULL) {
  ------------------
  |  Branch (8413:17): [True: 0, False: 0]
  ------------------
 8414|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8415|      0|                break;
 8416|      0|            }
 8417|      0|            crv = sftk_DeriveEncrypt(SFTKCipher_Camellia_Encrypt,
 8418|      0|                                     cipherInfo, 16, key, keySize,
 8419|      0|                                     data, len);
 8420|      0|            Camellia_DestroyContext(cipherInfo, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8421|      0|            break;
 8422|      0|        }
 8423|       |
 8424|      0|#ifndef NSS_DISABLE_DEPRECATED_SEED
 8425|      0|        case CKM_SEED_ECB_ENCRYPT_DATA:
  ------------------
  |  | 1161|      0|#define CKM_SEED_ECB_ENCRYPT_DATA 0x00000656UL
  ------------------
  |  Branch (8425:9): [True: 0, False: 1.01M]
  ------------------
 8426|      0|        case CKM_SEED_CBC_ENCRYPT_DATA: {
  ------------------
  |  | 1162|      0|#define CKM_SEED_CBC_ENCRYPT_DATA 0x00000657UL
  ------------------
  |  Branch (8426:9): [True: 0, False: 1.01M]
  ------------------
 8427|      0|            void *cipherInfo;
 8428|      0|            CK_AES_CBC_ENCRYPT_DATA_PARAMS *aesEncryptPtr;
 8429|      0|            int mode;
 8430|      0|            unsigned char *iv;
 8431|      0|            unsigned char *data;
 8432|      0|            CK_ULONG len;
 8433|       |
 8434|      0|            if (mechanism == CKM_SEED_ECB_ENCRYPT_DATA) {
  ------------------
  |  | 1161|      0|#define CKM_SEED_ECB_ENCRYPT_DATA 0x00000656UL
  ------------------
  |  Branch (8434:17): [True: 0, False: 0]
  ------------------
 8435|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8436|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8437|      0|                    break;
 8438|      0|                }
 8439|      0|                mode = NSS_SEED;
  ------------------
  |  |   46|      0|#define NSS_SEED 0
  ------------------
 8440|      0|                stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)
 8441|      0|                                pMechanism->pParameter;
 8442|      0|                aesEncryptPtr = NULL;
 8443|      0|                data = stringPtr->pData;
 8444|      0|                len = stringPtr->ulLen;
 8445|      0|                iv = NULL;
 8446|      0|            } else {
 8447|      0|                if (BAD_PARAM_CAST(pMechanism, sizeof(CK_AES_CBC_ENCRYPT_DATA_PARAMS))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8448|      0|                    crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8449|      0|                    break;
 8450|      0|                }
 8451|      0|                mode = NSS_SEED_CBC;
  ------------------
  |  |   47|      0|#define NSS_SEED_CBC 1
  ------------------
 8452|      0|                aesEncryptPtr = (CK_AES_CBC_ENCRYPT_DATA_PARAMS *)
 8453|      0|                                    pMechanism->pParameter;
 8454|      0|                iv = aesEncryptPtr->iv;
 8455|      0|                data = aesEncryptPtr->pData;
 8456|      0|                len = aesEncryptPtr->length;
 8457|      0|            }
 8458|       |
 8459|      0|            cipherInfo = SEED_CreateContext((unsigned char *)att->attrib.pValue,
 8460|      0|                                            iv, mode, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8461|      0|            if (cipherInfo == NULL) {
  ------------------
  |  Branch (8461:17): [True: 0, False: 0]
  ------------------
 8462|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8463|      0|                break;
 8464|      0|            }
 8465|      0|            crv = sftk_DeriveEncrypt(SFTKCipher_SEED_Encrypt,
 8466|      0|                                     cipherInfo, 16, key, keySize,
 8467|      0|                                     data, len);
 8468|      0|            SEED_DestroyContext(cipherInfo, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8469|      0|            break;
 8470|      0|        }
 8471|      0|#endif /* NSS_DISABLE_DEPRECATED_SEED */
 8472|       |
 8473|     83|        case CKM_CONCATENATE_BASE_AND_KEY: {
  ------------------
  |  |  954|     83|#define CKM_CONCATENATE_BASE_AND_KEY 0x00000360UL
  ------------------
  |  Branch (8473:9): [True: 83, False: 1.01M]
  ------------------
 8474|     83|            SFTKObject *paramKey;
 8475|       |
 8476|     83|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|     83|#define PR_FALSE 0
  ------------------
 8477|     83|            if (crv != CKR_OK)
  ------------------
  |  | 1388|     83|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8477:17): [True: 0, False: 83]
  ------------------
 8478|      0|                break;
 8479|       |
 8480|     83|            session = sftk_SessionFromHandle(hSession);
 8481|     83|            if (session == NULL) {
  ------------------
  |  Branch (8481:17): [True: 0, False: 83]
  ------------------
 8482|      0|                crv = CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 8483|      0|                break;
 8484|      0|            }
 8485|       |
 8486|     83|            paramKey = sftk_ObjectFromHandle(*(CK_OBJECT_HANDLE *)
 8487|     83|                                                  pMechanism->pParameter,
 8488|     83|                                             session);
 8489|     83|            sftk_FreeSession(session);
 8490|     83|            if (paramKey == NULL) {
  ------------------
  |  Branch (8490:17): [True: 0, False: 83]
  ------------------
 8491|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 8492|      0|                break;
 8493|      0|            }
 8494|       |
 8495|     83|            if (sftk_isTrue(paramKey, CKA_SENSITIVE)) {
  ------------------
  |  |  546|     83|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (8495:17): [True: 0, False: 83]
  ------------------
 8496|      0|                crv = sftk_forceAttribute(key, CKA_SENSITIVE, &cktrue,
  ------------------
  |  |  546|      0|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 8497|      0|                                          sizeof(CK_BBOOL));
 8498|      0|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8498:21): [True: 0, False: 0]
  ------------------
 8499|      0|                    sftk_FreeObject(paramKey);
 8500|      0|                    break;
 8501|      0|                }
 8502|      0|            }
 8503|       |
 8504|     83|            if (sftk_hasAttribute(paramKey, CKA_EXTRACTABLE) && !sftk_isTrue(paramKey, CKA_EXTRACTABLE)) {
  ------------------
  |  |  585|     83|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
                          if (sftk_hasAttribute(paramKey, CKA_EXTRACTABLE) && !sftk_isTrue(paramKey, CKA_EXTRACTABLE)) {
  ------------------
  |  |  585|     83|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  |  Branch (8504:17): [True: 83, False: 0]
  |  Branch (8504:65): [True: 0, False: 83]
  ------------------
 8505|      0|                crv = sftk_forceAttribute(key, CKA_EXTRACTABLE, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  585|      0|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 8506|      0|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8506:21): [True: 0, False: 0]
  ------------------
 8507|      0|                    sftk_FreeObject(paramKey);
 8508|      0|                    break;
 8509|      0|                }
 8510|      0|            }
 8511|       |
 8512|     83|            att2 = sftk_FindAttribute(paramKey, CKA_VALUE);
  ------------------
  |  |  516|     83|#define CKA_VALUE 0x00000011UL
  ------------------
 8513|     83|            if (att2 == NULL) {
  ------------------
  |  Branch (8513:17): [True: 0, False: 83]
  ------------------
 8514|      0|                sftk_FreeObject(paramKey);
 8515|      0|                crv = CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
 8516|      0|                break;
 8517|      0|            }
 8518|     83|            tmpKeySize = att->attrib.ulValueLen + att2->attrib.ulValueLen;
 8519|     83|            if (keySize == 0)
  ------------------
  |  Branch (8519:17): [True: 83, False: 0]
  ------------------
 8520|     83|                keySize = tmpKeySize;
 8521|     83|            if (keySize > tmpKeySize) {
  ------------------
  |  Branch (8521:17): [True: 0, False: 83]
  ------------------
 8522|      0|                sftk_FreeObject(paramKey);
 8523|      0|                sftk_FreeAttribute(att2);
 8524|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 8525|      0|                break;
 8526|      0|            }
 8527|     83|            buf = (unsigned char *)PORT_Alloc(tmpKeySize);
  ------------------
  |  |   52|     83|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 8528|     83|            if (buf == NULL) {
  ------------------
  |  Branch (8528:17): [True: 0, False: 83]
  ------------------
 8529|      0|                sftk_FreeAttribute(att2);
 8530|      0|                sftk_FreeObject(paramKey);
 8531|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8532|      0|                break;
 8533|      0|            }
 8534|       |
 8535|     83|            PORT_Memcpy(buf, att->attrib.pValue, att->attrib.ulValueLen);
  ------------------
  |  |  180|     83|#define PORT_Memcpy memcpy
  ------------------
 8536|     83|            PORT_Memcpy(buf + att->attrib.ulValueLen,
  ------------------
  |  |  180|     83|#define PORT_Memcpy memcpy
  ------------------
 8537|     83|                        att2->attrib.pValue, att2->attrib.ulValueLen);
 8538|       |
 8539|     83|            crv = sftk_forceAttribute(key, CKA_VALUE, buf, keySize);
  ------------------
  |  |  516|     83|#define CKA_VALUE 0x00000011UL
  ------------------
 8540|     83|            PORT_ZFree(buf, tmpKeySize);
  ------------------
  |  |   75|     83|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8541|     83|            sftk_FreeAttribute(att2);
 8542|     83|            sftk_FreeObject(paramKey);
 8543|     83|            break;
 8544|     83|        }
 8545|       |
 8546|      0|        case CKM_CONCATENATE_BASE_AND_DATA:
  ------------------
  |  |  955|      0|#define CKM_CONCATENATE_BASE_AND_DATA 0x00000362UL
  ------------------
  |  Branch (8546:9): [True: 0, False: 1.01M]
  ------------------
 8547|      0|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8548|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8548:17): [True: 0, False: 0]
  ------------------
 8549|      0|                break;
 8550|       |
 8551|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8552|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8553|      0|                break;
 8554|      0|            }
 8555|      0|            stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)pMechanism->pParameter;
 8556|      0|            tmpKeySize = att->attrib.ulValueLen + stringPtr->ulLen;
 8557|      0|            if (keySize == 0)
  ------------------
  |  Branch (8557:17): [True: 0, False: 0]
  ------------------
 8558|      0|                keySize = tmpKeySize;
 8559|      0|            if (keySize > tmpKeySize) {
  ------------------
  |  Branch (8559:17): [True: 0, False: 0]
  ------------------
 8560|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 8561|      0|                break;
 8562|      0|            }
 8563|      0|            buf = (unsigned char *)PORT_Alloc(tmpKeySize);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 8564|      0|            if (buf == NULL) {
  ------------------
  |  Branch (8564:17): [True: 0, False: 0]
  ------------------
 8565|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8566|      0|                break;
 8567|      0|            }
 8568|       |
 8569|      0|            PORT_Memcpy(buf, att->attrib.pValue, att->attrib.ulValueLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8570|      0|            PORT_Memcpy(buf + att->attrib.ulValueLen, stringPtr->pData,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8571|      0|                        stringPtr->ulLen);
 8572|       |
 8573|      0|            crv = sftk_forceAttribute(key, CKA_VALUE, buf, keySize);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 8574|      0|            PORT_ZFree(buf, tmpKeySize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8575|      0|            break;
 8576|      0|        case CKM_CONCATENATE_DATA_AND_BASE:
  ------------------
  |  |  956|      0|#define CKM_CONCATENATE_DATA_AND_BASE 0x00000363UL
  ------------------
  |  Branch (8576:9): [True: 0, False: 1.01M]
  ------------------
 8577|      0|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8578|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8578:17): [True: 0, False: 0]
  ------------------
 8579|      0|                break;
 8580|       |
 8581|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8582|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8583|      0|                break;
 8584|      0|            }
 8585|      0|            stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)pMechanism->pParameter;
 8586|      0|            tmpKeySize = att->attrib.ulValueLen + stringPtr->ulLen;
 8587|      0|            if (keySize == 0)
  ------------------
  |  Branch (8587:17): [True: 0, False: 0]
  ------------------
 8588|      0|                keySize = tmpKeySize;
 8589|      0|            if (keySize > tmpKeySize) {
  ------------------
  |  Branch (8589:17): [True: 0, False: 0]
  ------------------
 8590|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 8591|      0|                break;
 8592|      0|            }
 8593|      0|            buf = (unsigned char *)PORT_Alloc(tmpKeySize);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 8594|      0|            if (buf == NULL) {
  ------------------
  |  Branch (8594:17): [True: 0, False: 0]
  ------------------
 8595|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8596|      0|                break;
 8597|      0|            }
 8598|       |
 8599|      0|            PORT_Memcpy(buf, stringPtr->pData, stringPtr->ulLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8600|      0|            PORT_Memcpy(buf + stringPtr->ulLen, att->attrib.pValue,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8601|      0|                        att->attrib.ulValueLen);
 8602|       |
 8603|      0|            crv = sftk_forceAttribute(key, CKA_VALUE, buf, keySize);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 8604|      0|            PORT_ZFree(buf, tmpKeySize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8605|      0|            break;
 8606|      0|        case CKM_XOR_BASE_AND_DATA:
  ------------------
  |  |  957|      0|#define CKM_XOR_BASE_AND_DATA 0x00000364UL
  ------------------
  |  Branch (8606:9): [True: 0, False: 1.01M]
  ------------------
 8607|      0|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8608|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8608:17): [True: 0, False: 0]
  ------------------
 8609|      0|                break;
 8610|       |
 8611|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_KEY_DERIVATION_STRING_DATA))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8612|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8613|      0|                break;
 8614|      0|            }
 8615|      0|            stringPtr = (CK_KEY_DERIVATION_STRING_DATA *)pMechanism->pParameter;
 8616|      0|            tmpKeySize = PR_MIN(att->attrib.ulValueLen, stringPtr->ulLen);
  ------------------
  |  |  158|      0|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8617|      0|            if (keySize == 0)
  ------------------
  |  Branch (8617:17): [True: 0, False: 0]
  ------------------
 8618|      0|                keySize = tmpKeySize;
 8619|      0|            if (keySize > tmpKeySize) {
  ------------------
  |  Branch (8619:17): [True: 0, False: 0]
  ------------------
 8620|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 8621|      0|                break;
 8622|      0|            }
 8623|      0|            buf = (unsigned char *)PORT_Alloc(keySize);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 8624|      0|            if (buf == NULL) {
  ------------------
  |  Branch (8624:17): [True: 0, False: 0]
  ------------------
 8625|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8626|      0|                break;
 8627|      0|            }
 8628|       |
 8629|      0|            PORT_Memcpy(buf, att->attrib.pValue, keySize);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8630|      0|            for (i = 0; i < (int)keySize; i++) {
  ------------------
  |  Branch (8630:25): [True: 0, False: 0]
  ------------------
 8631|      0|                buf[i] ^= stringPtr->pData[i];
 8632|      0|            }
 8633|       |
 8634|      0|            crv = sftk_forceAttribute(key, CKA_VALUE, buf, keySize);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 8635|      0|            PORT_ZFree(buf, keySize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8636|      0|            break;
 8637|       |
 8638|      0|        case CKM_EXTRACT_KEY_FROM_KEY: {
  ------------------
  |  |  958|      0|#define CKM_EXTRACT_KEY_FROM_KEY 0x00000365UL
  ------------------
  |  Branch (8638:9): [True: 0, False: 1.01M]
  ------------------
 8639|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_EXTRACT_PARAMS))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 8640|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8641|      0|                break;
 8642|      0|            }
 8643|       |            /* the following assumes 8 bits per byte */
 8644|      0|            CK_ULONG extract = *(CK_EXTRACT_PARAMS *)pMechanism->pParameter;
 8645|      0|            CK_ULONG shift = extract & 0x7; /* extract mod 8 the fast way */
 8646|      0|            CK_ULONG offset = extract >> 3; /* extract div 8 the fast way */
 8647|       |
 8648|      0|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8649|      0|            if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8649:17): [True: 0, False: 0]
  ------------------
 8650|      0|                break;
 8651|       |
 8652|      0|            if (keySize == 0) {
  ------------------
  |  Branch (8652:17): [True: 0, False: 0]
  ------------------
 8653|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 8654|      0|                break;
 8655|      0|            }
 8656|       |            /* make sure we have enough bits in the original key */
 8657|      0|            if (att->attrib.ulValueLen <
  ------------------
  |  Branch (8657:17): [True: 0, False: 0]
  ------------------
 8658|      0|                (offset + keySize + ((shift != 0) ? 1 : 0))) {
  ------------------
  |  Branch (8658:38): [True: 0, False: 0]
  ------------------
 8659|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8660|      0|                break;
 8661|      0|            }
 8662|      0|            buf = (unsigned char *)PORT_Alloc(keySize);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 8663|      0|            if (buf == NULL) {
  ------------------
  |  Branch (8663:17): [True: 0, False: 0]
  ------------------
 8664|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8665|      0|                break;
 8666|      0|            }
 8667|       |
 8668|       |            /* copy the bits we need into the new key */
 8669|      0|            for (i = 0; i < (int)keySize; i++) {
  ------------------
  |  Branch (8669:25): [True: 0, False: 0]
  ------------------
 8670|      0|                unsigned char *value =
 8671|      0|                    ((unsigned char *)att->attrib.pValue) + offset + i;
 8672|      0|                if (shift) {
  ------------------
  |  Branch (8672:21): [True: 0, False: 0]
  ------------------
 8673|      0|                    buf[i] = (value[0] << (shift)) | (value[1] >> (8 - shift));
 8674|      0|                } else {
 8675|      0|                    buf[i] = value[0];
 8676|      0|                }
 8677|      0|            }
 8678|       |
 8679|      0|            crv = sftk_forceAttribute(key, CKA_VALUE, buf, keySize);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 8680|      0|            PORT_ZFree(buf, keySize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8681|      0|            break;
 8682|      0|        }
 8683|      0|        case CKM_MD2_KEY_DERIVATION:
  ------------------
  |  |  978|      0|#define CKM_MD2_KEY_DERIVATION 0x00000391UL
  ------------------
  |  Branch (8683:9): [True: 0, False: 1.01M]
  ------------------
 8684|      0|            if (keySize == 0)
  ------------------
  |  Branch (8684:17): [True: 0, False: 0]
  ------------------
 8685|      0|                keySize = MD2_LENGTH;
  ------------------
  |  |   37|      0|#define MD2_LENGTH 16
  ------------------
 8686|      0|            if (keySize > MD2_LENGTH) {
  ------------------
  |  |   37|      0|#define MD2_LENGTH 16
  ------------------
  |  Branch (8686:17): [True: 0, False: 0]
  ------------------
 8687|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 8688|      0|                break;
 8689|      0|            }
 8690|       |            /* now allocate the hash contexts */
 8691|      0|            md2 = MD2_NewContext();
 8692|      0|            if (md2 == NULL) {
  ------------------
  |  Branch (8692:17): [True: 0, False: 0]
  ------------------
 8693|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8694|      0|                break;
 8695|      0|            }
 8696|      0|            MD2_Begin(md2);
 8697|      0|            MD2_Update(md2, (const unsigned char *)att->attrib.pValue,
 8698|      0|                       att->attrib.ulValueLen);
 8699|      0|            MD2_End(md2, key_block, &outLen, MD2_LENGTH);
  ------------------
  |  |   37|      0|#define MD2_LENGTH 16
  ------------------
 8700|      0|            MD2_DestroyContext(md2, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8701|       |
 8702|      0|            crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
 8703|      0|            PORT_Memset(key_block, 0, MD2_LENGTH);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
                          PORT_Memset(key_block, 0, MD2_LENGTH);
  ------------------
  |  |   37|      0|#define MD2_LENGTH 16
  ------------------
 8704|      0|            break;
 8705|      0|#define DERIVE_KEY_HASH(hash)                                                \
 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
 8707|      0|        if (keySize == 0)                                                    \
 8708|      0|            keySize = hash##_LENGTH;                                         \
 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
 8711|      0|            break;                                                           \
 8712|      0|        }                                                                    \
 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
 8714|      0|                       att->attrib.ulValueLen);                              \
 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
 8717|      0|        break;
 8718|      0|            DERIVE_KEY_HASH(MD5)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8719|      0|            DERIVE_KEY_HASH(SHA1)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8720|      0|            DERIVE_KEY_HASH(SHA224)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8721|      0|            DERIVE_KEY_HASH(SHA256)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8722|      0|            DERIVE_KEY_HASH(SHA384)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8723|      0|            DERIVE_KEY_HASH(SHA512)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8724|      0|            DERIVE_KEY_HASH(SHA3_224)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8725|      0|            DERIVE_KEY_HASH(SHA3_256)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8726|      0|            DERIVE_KEY_HASH(SHA3_384)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8727|      0|            DERIVE_KEY_HASH(SHA3_512)
  ------------------
  |  | 8706|      0|    case CKM_##hash##_KEY_DERIVATION:                                        \
  |  |  ------------------
  |  |  |  Branch (8706:5): [True: 0, False: 1.01M]
  |  |  ------------------
  |  | 8707|      0|        if (keySize == 0)                                                    \
  |  |  ------------------
  |  |  |  Branch (8707:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8708|      0|            keySize = hash##_LENGTH;                                         \
  |  | 8709|      0|        if (keySize > hash##_LENGTH) {                                       \
  |  |  ------------------
  |  |  |  Branch (8709:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 8710|      0|            crv = CKR_TEMPLATE_INCONSISTENT;                                 \
  |  |  ------------------
  |  |  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  |  |  ------------------
  |  | 8711|      0|            break;                                                           \
  |  | 8712|      0|        }                                                                    \
  |  | 8713|      0|        hash##_HashBuf(key_block, (const unsigned char *)att->attrib.pValue, \
  |  | 8714|      0|                       att->attrib.ulValueLen);                              \
  |  | 8715|      0|        crv = sftk_forceAttribute(key, CKA_VALUE, key_block, keySize);       \
  |  |  ------------------
  |  |  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  |  |  ------------------
  |  | 8716|      0|        PORT_Memset(key_block, 0, hash##_LENGTH);                            \
  |  |  ------------------
  |  |  |  |  182|      0|#define PORT_Memset memset
  |  |  ------------------
  |  | 8717|      0|        break;
  ------------------
 8728|       |
 8729|  27.7k|        case CKM_DH_PKCS_DERIVE: {
  ------------------
  |  |  759|  27.7k|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
  |  Branch (8729:9): [True: 27.7k, False: 987k]
  ------------------
 8730|  27.7k|            SECItem derived, dhPublic;
 8731|  27.7k|            SECItem dhPrime, dhValue;
 8732|  27.7k|            const SECItem *subPrime;
 8733|       |            /* sourceKey - values for the local existing low key */
 8734|       |            /* get prime and value attributes */
 8735|  27.7k|            crv = sftk_Attribute2SecItem(NULL, &dhPrime, sourceKey, CKA_PRIME);
  ------------------
  |  |  569|  27.7k|#define CKA_PRIME 0x00000130UL
  ------------------
 8736|  27.7k|            if (crv != CKR_OK)
  ------------------
  |  | 1388|  27.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8736:17): [True: 0, False: 27.7k]
  ------------------
 8737|      0|                break;
 8738|       |
 8739|  27.7k|            dhPublic.data = pMechanism->pParameter;
 8740|  27.7k|            dhPublic.len = pMechanism->ulParameterLen;
 8741|       |
 8742|       |            /* if the prime is an approved prime, we can skip all the other
 8743|       |             * checks. */
 8744|  27.7k|            subPrime = sftk_VerifyDH_Prime(&dhPrime, NULL, isFIPS);
 8745|  27.7k|            if (subPrime == NULL) {
  ------------------
  |  Branch (8745:17): [True: 0, False: 27.7k]
  ------------------
 8746|      0|                SECItem dhSubPrime;
 8747|       |                /* If the caller set the subprime value, it means that
 8748|       |                 * either the caller knows the subprime value and wants us
 8749|       |                 * to validate the key against the subprime, or that the
 8750|       |                 * caller wants us to verify that the prime is a safe prime
 8751|       |                 * by passing in subprime = (prime-1)/2 */
 8752|      0|                dhSubPrime.data = NULL;
 8753|      0|                dhSubPrime.len = 0;
 8754|      0|                crv = sftk_Attribute2SecItem(NULL, &dhSubPrime,
 8755|      0|                                             sourceKey, CKA_SUBPRIME);
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 8756|       |                /* we ignore the value of crv here, We treat a valid
 8757|       |                 * return of len = 0 and a failure to find a subrime the same
 8758|       |                 * NOTE: we free the subprime in both cases depending on
 8759|       |                 * PORT_Free of NULL to be a noop */
 8760|      0|                if (dhSubPrime.len != 0) {
  ------------------
  |  Branch (8760:21): [True: 0, False: 0]
  ------------------
 8761|      0|                    PRBool isSafe = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8762|       |
 8763|       |                    /* Callers can set dhSubPrime to q=(p-1)/2 to force
 8764|       |                     * checks for safe primes. If so we only need to check
 8765|       |                     * q and p for primality and skip the group test.  */
 8766|      0|                    rv = sftk_IsSafePrime(&dhPrime, &dhSubPrime, &isSafe);
 8767|      0|                    if (rv != SECSuccess) {
  ------------------
  |  Branch (8767:25): [True: 0, False: 0]
  ------------------
 8768|       |                        /* either p or q was even and therefore not prime,
 8769|       |                         * we can stop processing here and fail now */
 8770|      0|                        crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 8771|      0|                        SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                      SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8772|      0|                        SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                      SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8773|      0|                        break;
 8774|      0|                    }
 8775|       |
 8776|       |                    /* first make sure the primes are really prime */
 8777|      0|                    if (!KEA_PrimeCheck(&dhPrime)) {
  ------------------
  |  Branch (8777:25): [True: 0, False: 0]
  ------------------
 8778|      0|                        crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 8779|      0|                        SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                      SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8780|      0|                        SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                      SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8781|      0|                        break;
 8782|      0|                    }
 8783|      0|                    if (!KEA_PrimeCheck(&dhSubPrime)) {
  ------------------
  |  Branch (8783:25): [True: 0, False: 0]
  ------------------
 8784|      0|                        crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 8785|      0|                        SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                      SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8786|      0|                        SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                      SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8787|      0|                        break;
 8788|      0|                    }
 8789|      0|                    if (isFIPS || !isSafe) {
  ------------------
  |  Branch (8789:25): [True: 0, False: 0]
  |  Branch (8789:35): [True: 0, False: 0]
  ------------------
 8790|       |                        /* With safe primes, there is only one other small
 8791|       |                         * subgroup. As long as y isn't 0, 1, or -1 mod p,
 8792|       |                         * any other y is safe. Only do the full check for
 8793|       |                         * non-safe primes, except in FIPS mode we need
 8794|       |                         * to do this check on all primes in which
 8795|       |                         * we receive the subprime value */
 8796|      0|                        if (!KEA_Verify(&dhPublic, &dhPrime, &dhSubPrime)) {
  ------------------
  |  Branch (8796:29): [True: 0, False: 0]
  ------------------
 8797|      0|                            crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 8798|      0|                            SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                          SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8799|      0|                            SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                          SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8800|      0|                            break;
 8801|      0|                        }
 8802|      0|                    }
 8803|      0|                } else if (isFIPS) {
  ------------------
  |  Branch (8803:28): [True: 0, False: 0]
  ------------------
 8804|       |                    /* In FIPS mode we only accept approved primes, or
 8805|       |                     * primes with the full subprime value */
 8806|      0|                    crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|      0|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 8807|      0|                    SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                                  SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8808|      0|                    break;
 8809|      0|                }
 8810|       |                /* checks are complete, no need for the subPrime any longer */
 8811|      0|                SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhSubPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8812|      0|            }
 8813|       |
 8814|       |            /* now that the prime is validated, get the private value */
 8815|  27.7k|            crv = sftk_Attribute2SecItem(NULL, &dhValue, sourceKey, CKA_VALUE);
  ------------------
  |  |  516|  27.7k|#define CKA_VALUE 0x00000011UL
  ------------------
 8816|  27.7k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  27.7k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8816:17): [True: 0, False: 27.7k]
  ------------------
 8817|      0|                SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8818|      0|                break;
 8819|      0|            }
 8820|       |
 8821|       |            /* calculate private value - oct */
 8822|  27.7k|            rv = DH_Derive(&dhPublic, &dhPrime, &dhValue, &derived, keySize);
 8823|       |
 8824|  27.7k|            SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  110|  27.7k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&dhPrime, PR_FALSE);
  ------------------
  |  |  438|  27.7k|#define PR_FALSE 0
  ------------------
 8825|  27.7k|            SECITEM_ZfreeItem(&dhValue, PR_FALSE);
  ------------------
  |  |  110|  27.7k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&dhValue, PR_FALSE);
  ------------------
  |  |  438|  27.7k|#define PR_FALSE 0
  ------------------
 8826|       |
 8827|  27.7k|            if (rv == SECSuccess) {
  ------------------
  |  Branch (8827:17): [True: 27.7k, False: 0]
  ------------------
 8828|  27.7k|                sftk_forceAttribute(key, CKA_VALUE, derived.data, derived.len);
  ------------------
  |  |  516|  27.7k|#define CKA_VALUE 0x00000011UL
  ------------------
 8829|  27.7k|                SECITEM_ZfreeItem(&derived, PR_FALSE);
  ------------------
  |  |  110|  27.7k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&derived, PR_FALSE);
  ------------------
  |  |  438|  27.7k|#define PR_FALSE 0
  ------------------
 8830|  27.7k|                crv = CKR_OK;
  ------------------
  |  | 1388|  27.7k|#define CKR_OK 0x00000000UL
  ------------------
 8831|  27.7k|            } else
 8832|      0|                crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8833|       |
 8834|  27.7k|            break;
 8835|  27.7k|        }
 8836|       |
 8837|  17.8k|        case CKM_ECDH1_DERIVE:
  ------------------
  |  | 1086|  17.8k|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  |  Branch (8837:9): [True: 17.8k, False: 997k]
  ------------------
 8838|  17.8k|        case CKM_ECDH1_COFACTOR_DERIVE: {
  ------------------
  |  | 1087|  17.8k|#define CKM_ECDH1_COFACTOR_DERIVE 0x00001051UL
  ------------------
  |  Branch (8838:9): [True: 0, False: 1.01M]
  ------------------
 8839|  17.8k|            SECItem ecScalar, ecPoint;
 8840|  17.8k|            SECItem tmp;
 8841|  17.8k|            PRBool withCofactor = PR_FALSE;
  ------------------
  |  |  438|  17.8k|#define PR_FALSE 0
  ------------------
 8842|  17.8k|            unsigned char *secret;
 8843|  17.8k|            unsigned char *keyData = NULL;
 8844|  17.8k|            unsigned int secretlen, pubKeyLen;
 8845|  17.8k|            CK_ECDH1_DERIVE_PARAMS *mechParams;
 8846|  17.8k|            NSSLOWKEYPrivateKey *privKey;
 8847|  17.8k|            PLArenaPool *arena = NULL;
 8848|       |
 8849|       |            /* Check mechanism parameters */
 8850|  17.8k|            mechParams = (CK_ECDH1_DERIVE_PARAMS *)pMechanism->pParameter;
 8851|  17.8k|            if ((pMechanism->ulParameterLen != sizeof(CK_ECDH1_DERIVE_PARAMS)) ||
  ------------------
  |  Branch (8851:17): [True: 0, False: 17.8k]
  ------------------
 8852|  17.8k|                ((mechParams->kdf == CKD_NULL) &&
  ------------------
  |  | 1702|  17.8k|#define CKD_NULL 0x00000001UL
  ------------------
  |  Branch (8852:18): [True: 17.8k, False: 0]
  ------------------
 8853|  17.8k|                 ((mechParams->ulSharedDataLen != 0) ||
  ------------------
  |  Branch (8853:19): [True: 0, False: 17.8k]
  ------------------
 8854|  17.8k|                  (mechParams->pSharedData != NULL)))) {
  ------------------
  |  Branch (8854:19): [True: 0, False: 17.8k]
  ------------------
 8855|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8856|      0|                break;
 8857|      0|            }
 8858|       |
 8859|  17.8k|            privKey = sftk_GetPrivKey(sourceKey, CKK_EC, &crv);
  ------------------
  |  |  379|  17.8k|#define CKK_EC 0x00000003UL
  ------------------
 8860|  17.8k|            if (privKey == NULL) {
  ------------------
  |  Branch (8860:17): [True: 0, False: 17.8k]
  ------------------
 8861|      0|                break;
 8862|      0|            }
 8863|       |
 8864|       |            /* Now we are working with a non-NULL private key */
 8865|  17.8k|            SECITEM_CopyItem(NULL, &ecScalar, &privKey->u.ec.privateValue);
  ------------------
  |  |  106|  17.8k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 8866|       |
 8867|  17.8k|            ecPoint.data = mechParams->pPublicData;
 8868|  17.8k|            ecPoint.len = mechParams->ulPublicDataLen;
 8869|       |
 8870|  17.8k|            pubKeyLen = EC_GetPointSize(&privKey->u.ec.ecParams);
 8871|       |
 8872|       |            /* if the len is too large, might be an encoded point */
 8873|  17.8k|            if (ecPoint.len > pubKeyLen) {
  ------------------
  |  Branch (8873:17): [True: 239, False: 17.5k]
  ------------------
 8874|    239|                SECItem newPoint;
 8875|       |
 8876|    239|                arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|    239|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                              arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|    239|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 8877|    239|                if (arena == NULL) {
  ------------------
  |  Branch (8877:21): [True: 0, False: 239]
  ------------------
 8878|      0|                    goto ec_loser;
 8879|      0|                }
 8880|       |
 8881|    239|                rv = SEC_QuickDERDecodeItem(arena, &newPoint,
  ------------------
  |  |  102|    239|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
 8882|    239|                                            SEC_ASN1_GET(SEC_OctetStringTemplate),
  ------------------
  |  |  188|    239|#define SEC_ASN1_GET(x) x
  ------------------
 8883|    239|                                            &ecPoint);
 8884|    239|                if (rv != SECSuccess) {
  ------------------
  |  Branch (8884:21): [True: 67, False: 172]
  ------------------
 8885|     67|                    goto ec_loser;
 8886|     67|                }
 8887|    172|                ecPoint = newPoint;
 8888|    172|            }
 8889|       |
 8890|  17.7k|            if (mechanism == CKM_ECDH1_COFACTOR_DERIVE) {
  ------------------
  |  | 1087|  17.7k|#define CKM_ECDH1_COFACTOR_DERIVE 0x00001051UL
  ------------------
  |  Branch (8890:17): [True: 0, False: 17.7k]
  ------------------
 8891|      0|                withCofactor = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 8892|      0|            }
 8893|       |
 8894|  17.7k|            rv = ECDH_Derive(&ecPoint, &privKey->u.ec.ecParams, &ecScalar,
 8895|  17.7k|                             withCofactor, &tmp);
 8896|  17.7k|            SECITEM_ZfreeItem(&ecScalar, PR_FALSE);
  ------------------
  |  |  110|  17.7k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&ecScalar, PR_FALSE);
  ------------------
  |  |  438|  17.7k|#define PR_FALSE 0
  ------------------
 8897|  17.7k|            ecScalar.data = NULL;
 8898|  17.7k|            if (privKey != sourceKey->objectInfo) {
  ------------------
  |  Branch (8898:17): [True: 0, False: 17.7k]
  ------------------
 8899|      0|                nsslowkey_DestroyPrivateKey(privKey);
 8900|      0|                privKey = NULL;
 8901|      0|            }
 8902|  17.7k|            if (arena) {
  ------------------
  |  Branch (8902:17): [True: 172, False: 17.5k]
  ------------------
 8903|    172|                PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|    172|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|    172|#define PR_FALSE 0
  ------------------
 8904|    172|                arena = NULL;
 8905|    172|            }
 8906|       |
 8907|  17.7k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (8907:17): [True: 375, False: 17.3k]
  ------------------
 8908|    375|                crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|    375|#define PORT_GetError PORT_GetError_Util
  ------------------
 8909|    375|                break;
 8910|    375|            }
 8911|       |
 8912|       |            /*
 8913|       |             * apply the kdf function.
 8914|       |             */
 8915|  17.3k|            if (mechParams->kdf == CKD_NULL) {
  ------------------
  |  | 1702|  17.3k|#define CKD_NULL 0x00000001UL
  ------------------
  |  Branch (8915:17): [True: 17.3k, False: 0]
  ------------------
 8916|       |                /*
 8917|       |                 * tmp is the raw data created by ECDH_Derive,
 8918|       |                 * secret and secretlen are the values we will
 8919|       |                 * eventually pass as our generated key.
 8920|       |                 */
 8921|  17.3k|                secret = tmp.data;
 8922|  17.3k|                secretlen = tmp.len;
 8923|  17.3k|            } else {
 8924|      0|                secretlen = keySize;
 8925|      0|                crv = sftk_ANSI_X9_63_kdf(&secret, keySize,
 8926|      0|                                          &tmp, mechParams->pSharedData,
 8927|      0|                                          mechParams->ulSharedDataLen, mechParams->kdf);
 8928|      0|                PORT_ZFree(tmp.data, tmp.len);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8929|      0|                if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (8929:21): [True: 0, False: 0]
  ------------------
 8930|      0|                    break;
 8931|      0|                }
 8932|      0|                tmp.data = secret;
 8933|      0|                tmp.len = secretlen;
 8934|      0|            }
 8935|       |
 8936|       |            /*
 8937|       |             * if keySize is supplied, then we are generating a key of a specific
 8938|       |             * length. This is done by taking the least significant 'keySize'
 8939|       |             * bytes from the unsigned value calculated by ECDH. Note: this may
 8940|       |             * mean padding temp with extra leading zeros from what ECDH_Derive
 8941|       |             * already returned (which itself may contain leading zeros).
 8942|       |             */
 8943|  17.3k|            if (keySize) {
  ------------------
  |  Branch (8943:17): [True: 17.3k, False: 0]
  ------------------
 8944|  17.3k|                if (secretlen < keySize) {
  ------------------
  |  Branch (8944:21): [True: 0, False: 17.3k]
  ------------------
 8945|      0|                    keyData = PORT_ZAlloc(keySize);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 8946|      0|                    if (!keyData) {
  ------------------
  |  Branch (8946:25): [True: 0, False: 0]
  ------------------
 8947|      0|                        PORT_ZFree(tmp.data, tmp.len);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8948|      0|                        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 8949|      0|                        break;
 8950|      0|                    }
 8951|      0|                    PORT_Memcpy(&keyData[keySize - secretlen], secret, secretlen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 8952|      0|                    secret = keyData;
 8953|  17.3k|                } else {
 8954|  17.3k|                    secret += (secretlen - keySize);
 8955|  17.3k|                }
 8956|  17.3k|                secretlen = keySize;
 8957|  17.3k|            }
 8958|       |
 8959|  17.3k|            sftk_forceAttribute(key, CKA_VALUE, secret, secretlen);
  ------------------
  |  |  516|  17.3k|#define CKA_VALUE 0x00000011UL
  ------------------
 8960|  17.3k|            PORT_ZFree(tmp.data, tmp.len);
  ------------------
  |  |   75|  17.3k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8961|  17.3k|            if (keyData) {
  ------------------
  |  Branch (8961:17): [True: 0, False: 17.3k]
  ------------------
 8962|      0|                PORT_ZFree(keyData, keySize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 8963|      0|            }
 8964|  17.3k|            break;
 8965|       |
 8966|     67|        ec_loser:
 8967|     67|            crv = CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|     67|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
 8968|     67|            SECITEM_ZfreeItem(&ecScalar, PR_FALSE);
  ------------------
  |  |  110|     67|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&ecScalar, PR_FALSE);
  ------------------
  |  |  438|     67|#define PR_FALSE 0
  ------------------
 8969|     67|            if (privKey != sourceKey->objectInfo)
  ------------------
  |  Branch (8969:17): [True: 0, False: 67]
  ------------------
 8970|      0|                nsslowkey_DestroyPrivateKey(privKey);
 8971|     67|            if (arena) {
  ------------------
  |  Branch (8971:17): [True: 67, False: 0]
  ------------------
 8972|     67|                PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |   61|     67|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(arena, PR_TRUE);
  ------------------
  |  |  437|     67|#define PR_TRUE 1
  ------------------
 8973|     67|            }
 8974|     67|            break;
 8975|  17.3k|        }
 8976|       |        /* See RFC 5869 and CK_NSS_HKDFParams for documentation. */
 8977|      0|        case CKM_NSS_HKDF_SHA1:
  ------------------
  |  |  168|      0|#define CKM_NSS_HKDF_SHA1 (CKM_NSS + 3)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (8977:9): [True: 0, False: 1.01M]
  ------------------
 8978|      0|            hashMech = CKM_SHA_1;
  ------------------
  |  |  859|      0|#define CKM_SHA_1 0x00000220UL
  ------------------
 8979|      0|            goto hkdf;
 8980|      0|        case CKM_NSS_HKDF_SHA256:
  ------------------
  |  |  169|      0|#define CKM_NSS_HKDF_SHA256 (CKM_NSS + 4)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (8980:9): [True: 0, False: 1.01M]
  ------------------
 8981|      0|            hashMech = CKM_SHA256;
  ------------------
  |  |  876|      0|#define CKM_SHA256 0x00000250UL
  ------------------
 8982|      0|            goto hkdf;
 8983|      0|        case CKM_NSS_HKDF_SHA384:
  ------------------
  |  |  170|      0|#define CKM_NSS_HKDF_SHA384 (CKM_NSS + 5)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (8983:9): [True: 0, False: 1.01M]
  ------------------
 8984|      0|            hashMech = CKM_SHA384;
  ------------------
  |  |  879|      0|#define CKM_SHA384 0x00000260UL
  ------------------
 8985|      0|            goto hkdf;
 8986|      0|        case CKM_NSS_HKDF_SHA512:
  ------------------
  |  |  171|      0|#define CKM_NSS_HKDF_SHA512 (CKM_NSS + 6)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (8986:9): [True: 0, False: 1.01M]
  ------------------
 8987|      0|            hashMech = CKM_SHA512;
  ------------------
  |  |  882|      0|#define CKM_SHA512 0x00000270UL
  ------------------
 8988|      0|            goto hkdf;
 8989|      0|        hkdf : {
 8990|      0|            const CK_NSS_HKDFParams *params =
 8991|      0|                (const CK_NSS_HKDFParams *)pMechanism->pParameter;
 8992|      0|            CK_HKDF_PARAMS hkdfParams;
 8993|       |
 8994|      0|            if (pMechanism->ulParameterLen != sizeof(CK_NSS_HKDFParams)) {
  ------------------
  |  Branch (8994:17): [True: 0, False: 0]
  ------------------
 8995|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 8996|      0|                break;
 8997|      0|            }
 8998|      0|            hkdfParams.bExtract = params->bExtract;
 8999|      0|            hkdfParams.bExpand = params->bExpand;
 9000|      0|            if (params->pSalt) {
  ------------------
  |  Branch (9000:17): [True: 0, False: 0]
  ------------------
 9001|      0|                hkdfParams.ulSaltType = CKF_HKDF_SALT_DATA;
  ------------------
  |  | 2253|      0|#define CKF_HKDF_SALT_DATA 0x00000002UL
  ------------------
 9002|      0|            } else {
 9003|      0|                hkdfParams.ulSaltType = CKF_HKDF_SALT_NULL;
  ------------------
  |  | 2252|      0|#define CKF_HKDF_SALT_NULL 0x00000001UL
  ------------------
 9004|      0|            }
 9005|      0|            hkdfParams.pSalt = params->pSalt;
 9006|      0|            hkdfParams.ulSaltLen = params->ulSaltLen;
 9007|      0|            hkdfParams.hSaltKey = CK_INVALID_HANDLE;
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
 9008|      0|            hkdfParams.pInfo = params->pInfo;
 9009|      0|            hkdfParams.ulInfoLen = params->ulInfoLen;
 9010|      0|            hkdfParams.prfHashMechanism = hashMech;
 9011|       |
 9012|      0|            crv = sftk_HKDF(&hkdfParams, hSession, sourceKey,
 9013|      0|                            att->attrib.pValue, att->attrib.ulValueLen,
 9014|      0|                            key, NULL, keySize, PR_FALSE, isFIPS);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 9015|      0|        } break;
 9016|   567k|        case CKM_HKDF_DERIVE:
  ------------------
  |  | 1296|   567k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  |  Branch (9016:9): [True: 567k, False: 447k]
  ------------------
 9017|   846k|        case CKM_HKDF_DATA: /* only difference is the class of key */
  ------------------
  |  | 1297|   846k|#define CKM_HKDF_DATA 0x0000402bUL
  ------------------
  |  Branch (9017:9): [True: 278k, False: 736k]
  ------------------
 9018|   846k|            if ((pMechanism->pParameter == NULL) ||
  ------------------
  |  Branch (9018:17): [True: 0, False: 846k]
  ------------------
 9019|   846k|                (pMechanism->ulParameterLen != sizeof(CK_HKDF_PARAMS))) {
  ------------------
  |  Branch (9019:17): [True: 0, False: 846k]
  ------------------
 9020|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 9021|      0|                break;
 9022|      0|            }
 9023|   846k|            crv = sftk_HKDF((CK_HKDF_PARAMS_PTR)pMechanism->pParameter,
 9024|   846k|                            hSession, sourceKey, att->attrib.pValue,
 9025|   846k|                            att->attrib.ulValueLen, key, NULL, keySize, PR_TRUE,
  ------------------
  |  |  437|   846k|#define PR_TRUE 1
  ------------------
 9026|   846k|                            isFIPS);
 9027|   846k|            break;
 9028|      0|        case CKM_NSS_JPAKE_ROUND2_SHA1:
  ------------------
  |  |  195|      0|#define CKM_NSS_JPAKE_ROUND2_SHA1 (CKM_NSS + 11)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9028:9): [True: 0, False: 1.01M]
  ------------------
 9029|      0|            hashType = HASH_AlgSHA1;
 9030|      0|            goto jpake2;
 9031|      0|        case CKM_NSS_JPAKE_ROUND2_SHA256:
  ------------------
  |  |  196|      0|#define CKM_NSS_JPAKE_ROUND2_SHA256 (CKM_NSS + 12)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9031:9): [True: 0, False: 1.01M]
  ------------------
 9032|      0|            hashType = HASH_AlgSHA256;
 9033|      0|            goto jpake2;
 9034|      0|        case CKM_NSS_JPAKE_ROUND2_SHA384:
  ------------------
  |  |  197|      0|#define CKM_NSS_JPAKE_ROUND2_SHA384 (CKM_NSS + 13)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9034:9): [True: 0, False: 1.01M]
  ------------------
 9035|      0|            hashType = HASH_AlgSHA384;
 9036|      0|            goto jpake2;
 9037|      0|        case CKM_NSS_JPAKE_ROUND2_SHA512:
  ------------------
  |  |  198|      0|#define CKM_NSS_JPAKE_ROUND2_SHA512 (CKM_NSS + 14)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9037:9): [True: 0, False: 1.01M]
  ------------------
 9038|      0|            hashType = HASH_AlgSHA512;
 9039|      0|            goto jpake2;
 9040|      0|        jpake2:
 9041|      0|            if (pMechanism->pParameter == NULL ||
  ------------------
  |  Branch (9041:17): [True: 0, False: 0]
  ------------------
 9042|      0|                pMechanism->ulParameterLen != sizeof(CK_NSS_JPAKERound2Params))
  ------------------
  |  Branch (9042:17): [True: 0, False: 0]
  ------------------
 9043|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 9044|      0|            if (crv == CKR_OK && sftk_isTrue(key, CKA_TOKEN))
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
                          if (crv == CKR_OK && sftk_isTrue(key, CKA_TOKEN))
  ------------------
  |  |  512|      0|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (9044:17): [True: 0, False: 0]
  |  Branch (9044:34): [True: 0, False: 0]
  ------------------
 9045|      0|                crv = CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
 9046|      0|            if (crv == CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9046:17): [True: 0, False: 0]
  ------------------
 9047|      0|                crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 9048|      0|            if (crv == CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9048:17): [True: 0, False: 0]
  ------------------
 9049|      0|                crv = jpake_Round2(hashType,
 9050|      0|                                   (CK_NSS_JPAKERound2Params *)pMechanism->pParameter,
 9051|      0|                                   sourceKey, key);
 9052|      0|            break;
 9053|       |
 9054|      0|        case CKM_NSS_JPAKE_FINAL_SHA1:
  ------------------
  |  |  210|      0|#define CKM_NSS_JPAKE_FINAL_SHA1 (CKM_NSS + 15)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9054:9): [True: 0, False: 1.01M]
  ------------------
 9055|      0|            hashType = HASH_AlgSHA1;
 9056|      0|            goto jpakeFinal;
 9057|      0|        case CKM_NSS_JPAKE_FINAL_SHA256:
  ------------------
  |  |  211|      0|#define CKM_NSS_JPAKE_FINAL_SHA256 (CKM_NSS + 16)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9057:9): [True: 0, False: 1.01M]
  ------------------
 9058|      0|            hashType = HASH_AlgSHA256;
 9059|      0|            goto jpakeFinal;
 9060|      0|        case CKM_NSS_JPAKE_FINAL_SHA384:
  ------------------
  |  |  212|      0|#define CKM_NSS_JPAKE_FINAL_SHA384 (CKM_NSS + 17)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9060:9): [True: 0, False: 1.01M]
  ------------------
 9061|      0|            hashType = HASH_AlgSHA384;
 9062|      0|            goto jpakeFinal;
 9063|      0|        case CKM_NSS_JPAKE_FINAL_SHA512:
  ------------------
  |  |  213|      0|#define CKM_NSS_JPAKE_FINAL_SHA512 (CKM_NSS + 18)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9063:9): [True: 0, False: 1.01M]
  ------------------
 9064|      0|            hashType = HASH_AlgSHA512;
 9065|      0|            goto jpakeFinal;
 9066|      0|        jpakeFinal:
 9067|      0|            if (pMechanism->pParameter == NULL ||
  ------------------
  |  Branch (9067:17): [True: 0, False: 0]
  ------------------
 9068|      0|                pMechanism->ulParameterLen != sizeof(CK_NSS_JPAKEFinalParams))
  ------------------
  |  Branch (9068:17): [True: 0, False: 0]
  ------------------
 9069|      0|                crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 9070|       |            /* We purposely do not do the derive sensitivity check; we want to be
 9071|       |               able to derive non-sensitive keys while allowing the ROUND1 and
 9072|       |               ROUND2 keys to be sensitive (which they always are, since they are
 9073|       |               in the CKO_PRIVATE_KEY class). The caller must include CKA_SENSITIVE
 9074|       |               in the template in order for the resultant keyblock key to be
 9075|       |               sensitive.
 9076|       |             */
 9077|      0|            if (crv == CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9077:17): [True: 0, False: 0]
  ------------------
 9078|      0|                crv = jpake_Final(hashType,
 9079|      0|                                  (CK_NSS_JPAKEFinalParams *)pMechanism->pParameter,
 9080|      0|                                  sourceKey, key);
 9081|      0|            break;
 9082|       |
 9083|      0|        case CKM_NSS_SP800_108_COUNTER_KDF_DERIVE_DATA:         /* fall through */
  ------------------
  |  |  262|      0|#define CKM_NSS_SP800_108_COUNTER_KDF_DERIVE_DATA (CKM_NSS + 42)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9083:9): [True: 0, False: 1.01M]
  ------------------
 9084|      0|        case CKM_NSS_SP800_108_FEEDBACK_KDF_DERIVE_DATA:        /* fall through */
  ------------------
  |  |  263|      0|#define CKM_NSS_SP800_108_FEEDBACK_KDF_DERIVE_DATA (CKM_NSS + 43)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9084:9): [True: 0, False: 1.01M]
  ------------------
 9085|      0|        case CKM_NSS_SP800_108_DOUBLE_PIPELINE_KDF_DERIVE_DATA: /* fall through */
  ------------------
  |  |  264|      0|#define CKM_NSS_SP800_108_DOUBLE_PIPELINE_KDF_DERIVE_DATA (CKM_NSS + 44)
  |  |  ------------------
  |  |  |  |  162|      0|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|      0|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|      0|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (9085:9): [True: 0, False: 1.01M]
  ------------------
 9086|      0|        case CKM_SP800_108_COUNTER_KDF:                         /* fall through */
  ------------------
  |  | 1244|      0|#define CKM_SP800_108_COUNTER_KDF 0x000003acUL
  ------------------
  |  Branch (9086:9): [True: 0, False: 1.01M]
  ------------------
 9087|      0|        case CKM_SP800_108_FEEDBACK_KDF:                        /* fall through */
  ------------------
  |  | 1245|      0|#define CKM_SP800_108_FEEDBACK_KDF 0x000003adUL
  ------------------
  |  Branch (9087:9): [True: 0, False: 1.01M]
  ------------------
 9088|      0|        case CKM_SP800_108_DOUBLE_PIPELINE_KDF:
  ------------------
  |  | 1246|      0|#define CKM_SP800_108_DOUBLE_PIPELINE_KDF 0x000003aeUL
  ------------------
  |  Branch (9088:9): [True: 0, False: 1.01M]
  ------------------
 9089|      0|            crv = sftk_DeriveSensitiveCheck(sourceKey, key, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 9090|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9090:17): [True: 0, False: 0]
  ------------------
 9091|      0|                break;
 9092|      0|            }
 9093|       |
 9094|      0|            crv = kbkdf_Dispatch(mechanism, hSession, pMechanism, sourceKey, key, keySize);
 9095|      0|            break;
 9096|      0|        default:
  ------------------
  |  Branch (9096:9): [True: 0, False: 1.01M]
  ------------------
 9097|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 9098|  1.01M|    }
 9099|  1.01M|    if (att) {
  ------------------
  |  Branch (9099:9): [True: 1.01M, False: 0]
  ------------------
 9100|  1.01M|        sftk_FreeAttribute(att);
 9101|  1.01M|    }
 9102|  1.01M|    sftk_FreeObject(sourceKey);
 9103|  1.01M|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  1.01M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9103:9): [True: 1.17k, False: 1.01M]
  ------------------
 9104|  1.17k|        if (key)
  ------------------
  |  Branch (9104:13): [True: 1.17k, False: 0]
  ------------------
 9105|  1.17k|            sftk_FreeObject(key);
 9106|  1.17k|        return crv;
 9107|  1.17k|    }
 9108|       |
 9109|       |    /* link the key object into the list */
 9110|  1.01M|    if (key) {
  ------------------
  |  Branch (9110:9): [True: 958k, False: 55.8k]
  ------------------
 9111|   958k|        SFTKSessionObject *sessKey = sftk_narrowToSessionObject(key);
 9112|   958k|        PORT_Assert(sessKey);
  ------------------
  |  |  120|   958k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   958k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 958k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 9113|       |        /* get the session */
 9114|   958k|        sessKey->wasDerived = PR_TRUE;
  ------------------
  |  |  437|   958k|#define PR_TRUE 1
  ------------------
 9115|   958k|        session = sftk_SessionFromHandle(hSession);
 9116|   958k|        if (session == NULL) {
  ------------------
  |  Branch (9116:13): [True: 0, False: 958k]
  ------------------
 9117|      0|            sftk_FreeObject(key);
 9118|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 9119|      0|        }
 9120|       |
 9121|   958k|        crv = sftk_handleObject(key, session);
 9122|   958k|        session->lastOpWasFIPS = key->isFIPS;
 9123|   958k|        sftk_FreeSession(session);
 9124|   958k|        if (phKey) {
  ------------------
  |  Branch (9124:13): [True: 958k, False: 0]
  ------------------
 9125|   958k|            *phKey = key->handle;
 9126|   958k|        }
 9127|   958k|        sftk_FreeObject(key);
 9128|   958k|    }
 9129|  1.01M|    return crv;
 9130|  1.01M|}
NSC_GetOperationState:
 9159|  44.1k|{
 9160|  44.1k|    SFTKSessionContext *context;
 9161|  44.1k|    SFTKSession *session;
 9162|  44.1k|    CK_RV crv;
 9163|  44.1k|    CK_ULONG pOSLen = *pulOperationStateLen;
 9164|       |
 9165|  44.1k|    CHECK_FORK();
 9166|       |
 9167|       |    /* make sure we're legal */
 9168|  44.1k|    crv = sftk_GetContext(hSession, &context, SFTK_HASH, PR_TRUE, &session);
  ------------------
  |  |  437|  44.1k|#define PR_TRUE 1
  ------------------
 9169|  44.1k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|  44.1k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9169:9): [True: 0, False: 44.1k]
  ------------------
 9170|      0|        return crv;
 9171|       |
 9172|       |    /* a zero cipherInfoLen signals that this context cannot be serialized */
 9173|  44.1k|    if (context->cipherInfoLen == 0) {
  ------------------
  |  Branch (9173:9): [True: 0, False: 44.1k]
  ------------------
 9174|      0|        return CKR_STATE_UNSAVEABLE;
  ------------------
  |  | 1517|      0|#define CKR_STATE_UNSAVEABLE 0x00000180UL
  ------------------
 9175|      0|    }
 9176|       |
 9177|  44.1k|    *pulOperationStateLen = context->cipherInfoLen + sizeof(CK_MECHANISM_TYPE) + sizeof(SFTKContextType);
 9178|  44.1k|    if (pOperationState == NULL) {
  ------------------
  |  Branch (9178:9): [True: 9.32k, False: 34.8k]
  ------------------
 9179|  9.32k|        sftk_FreeSession(session);
 9180|  9.32k|        return CKR_OK;
  ------------------
  |  | 1388|  9.32k|#define CKR_OK 0x00000000UL
  ------------------
 9181|  34.8k|    } else {
 9182|  34.8k|        if (pOSLen < *pulOperationStateLen) {
  ------------------
  |  Branch (9182:13): [True: 0, False: 34.8k]
  ------------------
 9183|      0|            return CKR_BUFFER_TOO_SMALL;
  ------------------
  |  | 1514|      0|#define CKR_BUFFER_TOO_SMALL 0x00000150UL
  ------------------
 9184|      0|        }
 9185|  34.8k|    }
 9186|  34.8k|    PORT_Memcpy(pOperationState, &context->type, sizeof(SFTKContextType));
  ------------------
  |  |  180|  34.8k|#define PORT_Memcpy memcpy
  ------------------
 9187|  34.8k|    pOperationState += sizeof(SFTKContextType);
 9188|  34.8k|    PORT_Memcpy(pOperationState, &context->currentMech,
  ------------------
  |  |  180|  34.8k|#define PORT_Memcpy memcpy
  ------------------
 9189|  34.8k|                sizeof(CK_MECHANISM_TYPE));
 9190|  34.8k|    pOperationState += sizeof(CK_MECHANISM_TYPE);
 9191|  34.8k|    PORT_Memcpy(pOperationState, context->cipherInfo, context->cipherInfoLen);
  ------------------
  |  |  180|  34.8k|#define PORT_Memcpy memcpy
  ------------------
 9192|  34.8k|    sftk_FreeSession(session);
 9193|  34.8k|    return CKR_OK;
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
 9194|  44.1k|}
NSC_SetOperationState:
 9206|  34.8k|{
 9207|  34.8k|    SFTKSessionContext *context;
 9208|  34.8k|    SFTKSession *session;
 9209|  34.8k|    SFTKContextType type;
 9210|  34.8k|    CK_MECHANISM mech;
 9211|  34.8k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
 9212|       |
 9213|  34.8k|    CHECK_FORK();
 9214|       |
 9215|  69.6k|    while (ulOperationStateLen != 0) {
  ------------------
  |  Branch (9215:12): [True: 34.8k, False: 34.8k]
  ------------------
 9216|       |        /* get what type of state we're dealing with... */
 9217|  34.8k|        PORT_Memcpy(&type, pOperationState, sizeof(SFTKContextType));
  ------------------
  |  |  180|  34.8k|#define PORT_Memcpy memcpy
  ------------------
 9218|       |
 9219|       |        /* fix up session contexts based on type */
 9220|  34.8k|        session = sftk_SessionFromHandle(hSession);
 9221|  34.8k|        if (session == NULL)
  ------------------
  |  Branch (9221:13): [True: 0, False: 34.8k]
  ------------------
 9222|      0|            return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
 9223|  34.8k|        context = sftk_ReturnContextByType(session, type);
 9224|  34.8k|        sftk_SetContextByType(session, type, NULL);
 9225|  34.8k|        if (context) {
  ------------------
  |  Branch (9225:13): [True: 9.32k, False: 25.5k]
  ------------------
 9226|  9.32k|            sftk_FreeContext(context);
 9227|  9.32k|        }
 9228|  34.8k|        pOperationState += sizeof(SFTKContextType);
 9229|  34.8k|        sftk_Decrement(ulOperationStateLen, sizeof(SFTKContextType));
  ------------------
  |  | 9197|  34.8k|    stateSize = ((stateSize) > (CK_ULONG)(len)) ? ((stateSize) - (CK_ULONG)(len)) : 0;
  |  |  ------------------
  |  |  |  Branch (9197:17): [True: 34.8k, False: 0]
  |  |  ------------------
  ------------------
 9230|       |
 9231|       |        /* get the mechanism structure */
 9232|  34.8k|        PORT_Memcpy(&mech.mechanism, pOperationState, sizeof(CK_MECHANISM_TYPE));
  ------------------
  |  |  180|  34.8k|#define PORT_Memcpy memcpy
  ------------------
 9233|  34.8k|        pOperationState += sizeof(CK_MECHANISM_TYPE);
 9234|  34.8k|        sftk_Decrement(ulOperationStateLen, sizeof(CK_MECHANISM_TYPE));
  ------------------
  |  | 9197|  34.8k|    stateSize = ((stateSize) > (CK_ULONG)(len)) ? ((stateSize) - (CK_ULONG)(len)) : 0;
  |  |  ------------------
  |  |  |  Branch (9197:17): [True: 34.8k, False: 0]
  |  |  ------------------
  ------------------
 9235|       |        /* should be filled in... but not necessary for hash */
 9236|  34.8k|        mech.pParameter = NULL;
 9237|  34.8k|        mech.ulParameterLen = 0;
 9238|  34.8k|        switch (type) {
 9239|  34.8k|            case SFTK_HASH:
  ------------------
  |  Branch (9239:13): [True: 34.8k, False: 0]
  ------------------
 9240|  34.8k|                crv = NSC_DigestInit(hSession, &mech);
 9241|  34.8k|                if (crv != CKR_OK)
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9241:21): [True: 0, False: 34.8k]
  ------------------
 9242|      0|                    break;
 9243|  34.8k|                crv = sftk_GetContext(hSession, &context, SFTK_HASH, PR_TRUE,
  ------------------
  |  |  437|  34.8k|#define PR_TRUE 1
  ------------------
 9244|  34.8k|                                      NULL);
 9245|  34.8k|                if (crv != CKR_OK)
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9245:21): [True: 0, False: 34.8k]
  ------------------
 9246|      0|                    break;
 9247|  34.8k|                if (context->cipherInfoLen == 0) {
  ------------------
  |  Branch (9247:21): [True: 0, False: 34.8k]
  ------------------
 9248|      0|                    crv = CKR_SAVED_STATE_INVALID;
  ------------------
  |  | 1515|      0|#define CKR_SAVED_STATE_INVALID 0x00000160UL
  ------------------
 9249|      0|                    break;
 9250|      0|                }
 9251|  34.8k|                PORT_Memcpy(context->cipherInfo, pOperationState,
  ------------------
  |  |  180|  34.8k|#define PORT_Memcpy memcpy
  ------------------
 9252|  34.8k|                            context->cipherInfoLen);
 9253|  34.8k|                pOperationState += context->cipherInfoLen;
 9254|  34.8k|                sftk_Decrement(ulOperationStateLen, context->cipherInfoLen);
  ------------------
  |  | 9197|  34.8k|    stateSize = ((stateSize) > (CK_ULONG)(len)) ? ((stateSize) - (CK_ULONG)(len)) : 0;
  |  |  ------------------
  |  |  |  Branch (9197:17): [True: 0, False: 34.8k]
  |  |  ------------------
  ------------------
 9255|  34.8k|                break;
 9256|      0|            default:
  ------------------
  |  Branch (9256:13): [True: 0, False: 34.8k]
  ------------------
 9257|       |                /* do sign/encrypt/decrypt later */
 9258|      0|                crv = CKR_SAVED_STATE_INVALID;
  ------------------
  |  | 1515|      0|#define CKR_SAVED_STATE_INVALID 0x00000160UL
  ------------------
 9259|  34.8k|        }
 9260|  34.8k|        sftk_FreeSession(session);
 9261|  34.8k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|  34.8k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (9261:13): [True: 0, False: 34.8k]
  ------------------
 9262|      0|            break;
 9263|  34.8k|    }
 9264|  34.8k|    return crv;
 9265|  34.8k|}
pkcs11c.c:sftk_RSAEncrypt:
  616|      3|{
  617|      3|    NSSLOWKEYPublicKey *key = ctx;
  618|      3|    SECStatus rv = SECFailure;
  619|       |
  620|      3|    PORT_Assert(key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  621|      3|    if (key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (621:9): [True: 0, False: 3]
  ------------------
  622|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  623|      0|        return SECFailure;
  624|      0|    }
  625|       |
  626|      3|    rv = RSA_EncryptBlock(&key->u.rsa, output, outputLen, maxLen, input,
  627|      3|                          inputLen);
  628|      3|    if (rv != SECSuccess && PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (628:9): [True: 0, False: 3]
  |  Branch (628:29): [True: 0, False: 0]
  ------------------
  629|      0|        sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  630|      0|    }
  631|       |
  632|      3|    return rv;
  633|      3|}
pkcs11c.c:sftk_RSADecrypt:
  639|  23.1k|{
  640|  23.1k|    NSSLOWKEYPrivateKey *key = ctx;
  641|  23.1k|    SECStatus rv = SECFailure;
  642|       |
  643|  23.1k|    PORT_Assert(key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|  23.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  23.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 23.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  644|  23.1k|    if (key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (644:9): [True: 0, False: 23.1k]
  ------------------
  645|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  646|      0|        return SECFailure;
  647|      0|    }
  648|       |
  649|  23.1k|    rv = RSA_DecryptBlock(&key->u.rsa, output, outputLen, maxLen, input,
  650|  23.1k|                          inputLen);
  651|  23.1k|    if (rv != SECSuccess && PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|  22.4k|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (651:9): [True: 22.4k, False: 772]
  |  Branch (651:29): [True: 0, False: 22.4k]
  ------------------
  652|      0|        sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  653|      0|    }
  654|       |
  655|  23.1k|    return rv;
  656|  23.1k|}
pkcs11c.c:sftk_Null:
   80|  68.6k|{
   81|  68.6k|    return;
   82|  68.6k|}
pkcs11c.c:SFTKCipher_RC4_DestroyContext:
  164|  1.18k|    {                                                                        \
  165|  1.18k|        ctxtype *ctx = vctx;                                                 \
  166|  1.18k|        mmm##_DestroyContext(ctx, freeit);                                   \
  167|  1.18k|    }
pkcs11c.c:SFTKCipher_DES_Encrypt:
  151|  33.9k|    {                                                                        \
  152|  33.9k|        ctxtype *ctx = vctx;                                                 \
  153|  33.9k|        return mmm(ctx, output, outputLen, maxOutputLen,                     \
  154|  33.9k|                   input, inputLen);                                         \
  155|  33.9k|    }
pkcs11c.c:SFTKCipher_DES_DestroyContext:
  164|  58.9k|    {                                                                        \
  165|  58.9k|        ctxtype *ctx = vctx;                                                 \
  166|  58.9k|        mmm##_DestroyContext(ctx, freeit);                                   \
  167|  58.9k|    }
pkcs11c.c:SFTKCipher_SEED_DestroyContext:
  164|  1.48k|    {                                                                        \
  165|  1.48k|        ctxtype *ctx = vctx;                                                 \
  166|  1.48k|        mmm##_DestroyContext(ctx, freeit);                                   \
  167|  1.48k|    }
pkcs11c.c:SFTKCipher_Camellia_DestroyContext:
  164|  2.03k|    {                                                                        \
  165|  2.03k|        ctxtype *ctx = vctx;                                                 \
  166|  2.03k|        mmm##_DestroyContext(ctx, freeit);                                   \
  167|  2.03k|    }
pkcs11c.c:sftk_aes_mode:
  549|  16.4k|{
  550|  16.4k|    switch (mechanism) {
  ------------------
  |  Branch (550:13): [True: 0, False: 16.4k]
  ------------------
  551|      0|        case CKM_AES_CBC_PAD:
  ------------------
  |  | 1111|      0|#define CKM_AES_CBC_PAD 0x00001085UL
  ------------------
  |  Branch (551:9): [True: 0, False: 16.4k]
  ------------------
  552|  16.4k|        case CKM_AES_CBC:
  ------------------
  |  | 1108|  16.4k|#define CKM_AES_CBC 0x00001082UL
  ------------------
  |  Branch (552:9): [True: 16.4k, False: 0]
  ------------------
  553|  16.4k|            return NSS_AES_CBC;
  ------------------
  |  |   36|  16.4k|#define NSS_AES_CBC 1
  ------------------
  554|      0|        case CKM_AES_ECB:
  ------------------
  |  | 1107|      0|#define CKM_AES_ECB 0x00001081UL
  ------------------
  |  Branch (554:9): [True: 0, False: 16.4k]
  ------------------
  555|      0|            return NSS_AES;
  ------------------
  |  |   35|      0|#define NSS_AES 0
  ------------------
  556|      0|        case CKM_AES_CTS:
  ------------------
  |  | 1117|      0|#define CKM_AES_CTS 0x00001089UL
  ------------------
  |  Branch (556:9): [True: 0, False: 16.4k]
  ------------------
  557|      0|            return NSS_AES_CTS;
  ------------------
  |  |   37|      0|#define NSS_AES_CTS 2
  ------------------
  558|      0|        case CKM_AES_CTR:
  ------------------
  |  | 1113|      0|#define CKM_AES_CTR 0x00001086UL
  ------------------
  |  Branch (558:9): [True: 0, False: 16.4k]
  ------------------
  559|      0|            return NSS_AES_CTR;
  ------------------
  |  |   38|      0|#define NSS_AES_CTR 3
  ------------------
  560|      0|        case CKM_AES_GCM:
  ------------------
  |  | 1115|      0|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (560:9): [True: 0, False: 16.4k]
  ------------------
  561|      0|            return NSS_AES_GCM;
  ------------------
  |  |   39|      0|#define NSS_AES_GCM 4
  ------------------
  562|  16.4k|    }
  563|      0|    return -1;
  564|  16.4k|}
pkcs11c.c:SFTKCipher_AES_DestroyContext:
  164|  16.4k|    {                                                                        \
  165|  16.4k|        ctxtype *ctx = vctx;                                                 \
  166|  16.4k|        mmm##_DestroyContext(ctx, freeit);                                   \
  167|  16.4k|    }
pkcs11c.c:SFTKHash_MD5_Update:
  101|   152k|    {                                                                                     \
  102|   152k|        ctxtype *ctx = vctx;                                                              \
  103|   152k|        mmm##_Update(ctx, input, len);                                                    \
  104|   152k|    }                                                                                     \
pkcs11c.c:SFTKHash_MD5_End:
  108|  16.9k|    {                                                                                     \
  109|  16.9k|        ctxtype *ctx = vctx;                                                              \
  110|  16.9k|        mmm##_End(ctx, digest, len, maxLen);                                              \
  111|  16.9k|    }                                                                                     \
pkcs11c.c:SFTKHash_MD5_DestroyContext:
  114|  23.5k|    {                                                                                     \
  115|  23.5k|        ctxtype *ctx = vctx;                                                              \
  116|  23.5k|        mmm##_DestroyContext(ctx, freeit);                                                \
  117|  23.5k|    }
pkcs11c.c:SFTKHash_SHA1_Update:
  101|   240k|    {                                                                                     \
  102|   240k|        ctxtype *ctx = vctx;                                                              \
  103|   240k|        mmm##_Update(ctx, input, len);                                                    \
  104|   240k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA1_End:
  108|   104k|    {                                                                                     \
  109|   104k|        ctxtype *ctx = vctx;                                                              \
  110|   104k|        mmm##_End(ctx, digest, len, maxLen);                                              \
  111|   104k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA1_DestroyContext:
  114|   111k|    {                                                                                     \
  115|   111k|        ctxtype *ctx = vctx;                                                              \
  116|   111k|        mmm##_DestroyContext(ctx, freeit);                                                \
  117|   111k|    }
pkcs11c.c:SFTKHash_SHA256_Update:
  101|  72.8k|    {                                                                                     \
  102|  72.8k|        ctxtype *ctx = vctx;                                                              \
  103|  72.8k|        mmm##_Update(ctx, input, len);                                                    \
  104|  72.8k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA256_End:
  108|  64.3k|    {                                                                                     \
  109|  64.3k|        ctxtype *ctx = vctx;                                                              \
  110|  64.3k|        mmm##_End(ctx, digest, len, maxLen);                                              \
  111|  64.3k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA256_DestroyContext:
  114|  69.6k|    {                                                                                     \
  115|  69.6k|        ctxtype *ctx = vctx;                                                              \
  116|  69.6k|        mmm##_DestroyContext(ctx, freeit);                                                \
  117|  69.6k|    }
pkcs11c.c:SFTKHash_SHA384_Update:
  101|  57.1k|    {                                                                                     \
  102|  57.1k|        ctxtype *ctx = vctx;                                                              \
  103|  57.1k|        mmm##_Update(ctx, input, len);                                                    \
  104|  57.1k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA384_End:
  108|  50.1k|    {                                                                                     \
  109|  50.1k|        ctxtype *ctx = vctx;                                                              \
  110|  50.1k|        mmm##_End(ctx, digest, len, maxLen);                                              \
  111|  50.1k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA384_DestroyContext:
  114|  55.4k|    {                                                                                     \
  115|  55.4k|        ctxtype *ctx = vctx;                                                              \
  116|  55.4k|        mmm##_DestroyContext(ctx, freeit);                                                \
  117|  55.4k|    }
pkcs11c.c:SFTKHash_SHA512_Update:
  101|  6.94k|    {                                                                                     \
  102|  6.94k|        ctxtype *ctx = vctx;                                                              \
  103|  6.94k|        mmm##_Update(ctx, input, len);                                                    \
  104|  6.94k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA512_End:
  108|  5.85k|    {                                                                                     \
  109|  5.85k|        ctxtype *ctx = vctx;                                                              \
  110|  5.85k|        mmm##_End(ctx, digest, len, maxLen);                                              \
  111|  5.85k|    }                                                                                     \
pkcs11c.c:SFTKHash_SHA512_DestroyContext:
  114|  5.85k|    {                                                                                     \
  115|  5.85k|        ctxtype *ctx = vctx;                                                              \
  116|  5.85k|        mmm##_DestroyContext(ctx, freeit);                                                \
  117|  5.85k|    }
pkcs11c.c:sftk_InitCBCMac:
 2402|   212k|{
 2403|   212k|    CK_MECHANISM cbc_mechanism;
 2404|   212k|    CK_ULONG mac_bytes = SFTK_INVALID_MAC_SIZE;
  ------------------
  |  |  256|   212k|#define SFTK_INVALID_MAC_SIZE 0xffffffff
  ------------------
 2405|   212k|#ifndef NSS_DISABLE_DEPRECATED_RC2
 2406|   212k|    CK_RC2_CBC_PARAMS rc2_params;
 2407|   212k|#endif
 2408|       |#if NSS_SOFTOKEN_DOES_RC5
 2409|       |    CK_RC5_CBC_PARAMS rc5_params;
 2410|       |    CK_RC5_MAC_GENERAL_PARAMS *rc5_mac;
 2411|       |#endif
 2412|   212k|    unsigned char ivBlock[SFTK_MAX_BLOCK_SIZE];
 2413|   212k|    unsigned char k2[SFTK_MAX_BLOCK_SIZE];
 2414|   212k|    unsigned char k3[SFTK_MAX_BLOCK_SIZE];
 2415|   212k|    SFTKSessionContext *context;
 2416|   212k|    CK_RV crv;
 2417|   212k|    unsigned int blockSize;
 2418|   212k|    PRBool isXCBC = PR_FALSE;
  ------------------
  |  |  438|   212k|#define PR_FALSE 0
  ------------------
 2419|       |
 2420|   212k|    if (!pMechanism) {
  ------------------
  |  Branch (2420:9): [True: 0, False: 212k]
  ------------------
 2421|      0|        return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 2422|      0|    }
 2423|       |
 2424|   212k|    switch (pMechanism->mechanism) {
 2425|      0|#ifndef NSS_DISABLE_DEPRECATED_RC2
 2426|      0|        case CKM_RC2_MAC_GENERAL:
  ------------------
  |  |  809|      0|#define CKM_RC2_MAC_GENERAL 0x00000104UL
  ------------------
  |  Branch (2426:9): [True: 0, False: 212k]
  ------------------
 2427|      0|            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_RC2_MAC_GENERAL_PARAMS))) {
  ------------------
  |  |   50|      0|#define BAD_PARAM_CAST(pMech, typeSize) (!pMech->pParameter || pMech->ulParameterLen < typeSize)
  |  |  ------------------
  |  |  |  Branch (50:42): [True: 0, False: 0]
  |  |  |  Branch (50:64): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2428|      0|                return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 2429|      0|            }
 2430|      0|            mac_bytes =
 2431|      0|                ((CK_RC2_MAC_GENERAL_PARAMS *)pMechanism->pParameter)->ulMacLength;
 2432|       |        /* fall through */
 2433|      0|        case CKM_RC2_MAC:
  ------------------
  |  |  806|      0|#define CKM_RC2_MAC 0x00000103UL
  ------------------
  |  Branch (2433:9): [True: 0, False: 212k]
  ------------------
 2434|       |            /* this works because ulEffectiveBits is in the same place in both the
 2435|       |             * CK_RC2_MAC_GENERAL_PARAMS and CK_RC2_CBC_PARAMS */
 2436|      0|            rc2_params.ulEffectiveBits = ((CK_RC2_MAC_GENERAL_PARAMS *)
 2437|      0|                                              pMechanism->pParameter)
 2438|      0|                                             ->ulEffectiveBits;
 2439|      0|            PORT_Memset(rc2_params.iv, 0, sizeof(rc2_params.iv));
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2440|      0|            cbc_mechanism.mechanism = CKM_RC2_CBC;
  ------------------
  |  |  805|      0|#define CKM_RC2_CBC 0x00000102UL
  ------------------
 2441|      0|            cbc_mechanism.pParameter = &rc2_params;
 2442|      0|            cbc_mechanism.ulParameterLen = sizeof(rc2_params);
 2443|      0|            blockSize = 8;
 2444|      0|            break;
 2445|      0|#endif /* NSS_DISABLE_DEPRECATED_RC2 */
 2446|       |
 2447|       |#if NSS_SOFTOKEN_DOES_RC5
 2448|       |        case CKM_RC5_MAC_GENERAL:
 2449|       |            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_RC5_MAC_GENERAL_PARAMS))) {
 2450|       |                return CKR_MECHANISM_PARAM_INVALID;
 2451|       |            }
 2452|       |            mac_bytes =
 2453|       |                ((CK_RC5_MAC_GENERAL_PARAMS *)pMechanism->pParameter)->ulMacLength;
 2454|       |        /* fall through */
 2455|       |        case CKM_RC5_MAC:
 2456|       |            /* this works because ulEffectiveBits is in the same place in both the
 2457|       |             * CK_RC5_MAC_GENERAL_PARAMS and CK_RC5_CBC_PARAMS */
 2458|       |            if (BAD_PARAM_CAST(pMechanism, sizeof(CK_RC5_MAC_GENERAL_PARAMS))) {
 2459|       |                return CKR_MECHANISM_PARAM_INVALID;
 2460|       |            }
 2461|       |            rc5_mac = (CK_RC5_MAC_GENERAL_PARAMS *)pMechanism->pParameter;
 2462|       |            rc5_params.ulWordsize = rc5_mac->ulWordsize;
 2463|       |            rc5_params.ulRounds = rc5_mac->ulRounds;
 2464|       |            rc5_params.pIv = ivBlock;
 2465|       |            if ((blockSize = rc5_mac->ulWordsize * 2) > SFTK_MAX_BLOCK_SIZE)
 2466|       |                return CKR_MECHANISM_PARAM_INVALID;
 2467|       |            rc5_params.ulIvLen = blockSize;
 2468|       |            PORT_Memset(ivBlock, 0, blockSize);
 2469|       |            cbc_mechanism.mechanism = CKM_RC5_CBC;
 2470|       |            cbc_mechanism.pParameter = &rc5_params;
 2471|       |            cbc_mechanism.ulParameterLen = sizeof(rc5_params);
 2472|       |            break;
 2473|       |#endif
 2474|       |        /* add cast and idea later */
 2475|      0|        case CKM_DES_MAC_GENERAL:
  ------------------
  |  |  820|      0|#define CKM_DES_MAC_GENERAL 0x00000124UL
  ------------------
  |  Branch (2475:9): [True: 0, False: 212k]
  ------------------
 2476|      0|            mac_bytes = *(CK_ULONG *)pMechanism->pParameter;
 2477|       |        /* fall through */
 2478|      0|        case CKM_DES_MAC:
  ------------------
  |  |  817|      0|#define CKM_DES_MAC 0x00000123UL
  ------------------
  |  Branch (2478:9): [True: 0, False: 212k]
  ------------------
 2479|      0|            blockSize = 8;
 2480|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2481|      0|            cbc_mechanism.mechanism = CKM_DES_CBC;
  ------------------
  |  |  816|      0|#define CKM_DES_CBC 0x00000122UL
  ------------------
 2482|      0|            cbc_mechanism.pParameter = &ivBlock;
 2483|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2484|      0|            break;
 2485|      0|        case CKM_DES3_MAC_GENERAL:
  ------------------
  |  |  832|      0|#define CKM_DES3_MAC_GENERAL 0x00000135UL
  ------------------
  |  Branch (2485:9): [True: 0, False: 212k]
  ------------------
 2486|      0|            mac_bytes = *(CK_ULONG *)pMechanism->pParameter;
 2487|       |        /* fall through */
 2488|      0|        case CKM_DES3_MAC:
  ------------------
  |  |  827|      0|#define CKM_DES3_MAC 0x00000134UL
  ------------------
  |  Branch (2488:9): [True: 0, False: 212k]
  ------------------
 2489|      0|            blockSize = 8;
 2490|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2491|      0|            cbc_mechanism.mechanism = CKM_DES3_CBC;
  ------------------
  |  |  826|      0|#define CKM_DES3_CBC 0x00000133UL
  ------------------
 2492|      0|            cbc_mechanism.pParameter = &ivBlock;
 2493|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2494|      0|            break;
 2495|      0|        case CKM_CDMF_MAC_GENERAL:
  ------------------
  |  |  838|      0|#define CKM_CDMF_MAC_GENERAL 0x00000144UL
  ------------------
  |  Branch (2495:9): [True: 0, False: 212k]
  ------------------
 2496|      0|            mac_bytes = *(CK_ULONG *)pMechanism->pParameter;
 2497|       |        /* fall through */
 2498|      0|        case CKM_CDMF_MAC:
  ------------------
  |  |  837|      0|#define CKM_CDMF_MAC 0x00000143UL
  ------------------
  |  Branch (2498:9): [True: 0, False: 212k]
  ------------------
 2499|      0|            blockSize = 8;
 2500|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2501|      0|            cbc_mechanism.mechanism = CKM_CDMF_CBC;
  ------------------
  |  |  836|      0|#define CKM_CDMF_CBC 0x00000142UL
  ------------------
 2502|      0|            cbc_mechanism.pParameter = &ivBlock;
 2503|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2504|      0|            break;
 2505|      0|#ifndef NSS_DISABLE_DEPRECATED_SEED
 2506|      0|        case CKM_SEED_MAC_GENERAL:
  ------------------
  |  | 1159|      0|#define CKM_SEED_MAC_GENERAL 0x00000654UL
  ------------------
  |  Branch (2506:9): [True: 0, False: 212k]
  ------------------
 2507|      0|            mac_bytes = *(CK_ULONG *)pMechanism->pParameter;
 2508|       |        /* fall through */
 2509|      0|        case CKM_SEED_MAC:
  ------------------
  |  | 1158|      0|#define CKM_SEED_MAC 0x00000653UL
  ------------------
  |  Branch (2509:9): [True: 0, False: 212k]
  ------------------
 2510|      0|            blockSize = 16;
 2511|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2512|      0|            cbc_mechanism.mechanism = CKM_SEED_CBC;
  ------------------
  |  | 1157|      0|#define CKM_SEED_CBC 0x00000652UL
  ------------------
 2513|      0|            cbc_mechanism.pParameter = &ivBlock;
 2514|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2515|      0|            break;
 2516|      0|#endif /* NSS_DISABLE_DEPRECATED_SEED */
 2517|      0|        case CKM_CAMELLIA_MAC_GENERAL:
  ------------------
  |  | 1139|      0|#define CKM_CAMELLIA_MAC_GENERAL 0x00000554UL
  ------------------
  |  Branch (2517:9): [True: 0, False: 212k]
  ------------------
 2518|      0|            mac_bytes = *(CK_ULONG *)pMechanism->pParameter;
 2519|       |        /* fall through */
 2520|      0|        case CKM_CAMELLIA_MAC:
  ------------------
  |  | 1138|      0|#define CKM_CAMELLIA_MAC 0x00000553UL
  ------------------
  |  Branch (2520:9): [True: 0, False: 212k]
  ------------------
 2521|      0|            blockSize = 16;
 2522|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2523|      0|            cbc_mechanism.mechanism = CKM_CAMELLIA_CBC;
  ------------------
  |  | 1137|      0|#define CKM_CAMELLIA_CBC 0x00000552UL
  ------------------
 2524|      0|            cbc_mechanism.pParameter = &ivBlock;
 2525|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2526|      0|            break;
 2527|      0|        case CKM_AES_MAC_GENERAL:
  ------------------
  |  | 1110|      0|#define CKM_AES_MAC_GENERAL 0x00001084UL
  ------------------
  |  Branch (2527:9): [True: 0, False: 212k]
  ------------------
 2528|      0|            mac_bytes = *(CK_ULONG *)pMechanism->pParameter;
 2529|       |        /* fall through */
 2530|      0|        case CKM_AES_MAC:
  ------------------
  |  | 1109|      0|#define CKM_AES_MAC 0x00001083UL
  ------------------
  |  Branch (2530:9): [True: 0, False: 212k]
  ------------------
 2531|      0|            blockSize = 16;
 2532|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2533|      0|            cbc_mechanism.mechanism = CKM_AES_CBC;
  ------------------
  |  | 1108|      0|#define CKM_AES_CBC 0x00001082UL
  ------------------
 2534|      0|            cbc_mechanism.pParameter = &ivBlock;
 2535|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2536|      0|            break;
 2537|      0|        case CKM_AES_XCBC_MAC_96:
  ------------------
  |  | 1122|      0|#define CKM_AES_XCBC_MAC_96 0x0000108DUL
  ------------------
  |  Branch (2537:9): [True: 0, False: 212k]
  ------------------
 2538|      0|        case CKM_AES_XCBC_MAC:
  ------------------
  |  | 1121|      0|#define CKM_AES_XCBC_MAC 0x0000108CUL
  ------------------
  |  Branch (2538:9): [True: 0, False: 212k]
  ------------------
 2539|       |            /* The only difference between CKM_AES_XCBC_MAC
 2540|       |             * and CKM_AES_XCBC_MAC_96 is the size of the returned mac. */
 2541|      0|            mac_bytes = pMechanism->mechanism == CKM_AES_XCBC_MAC_96 ? 12 : 16;
  ------------------
  |  | 1122|      0|#define CKM_AES_XCBC_MAC_96 0x0000108DUL
  ------------------
  |  Branch (2541:25): [True: 0, False: 0]
  ------------------
 2542|      0|            blockSize = 16;
 2543|      0|            PORT_Memset(ivBlock, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2544|      0|            cbc_mechanism.mechanism = CKM_AES_CBC;
  ------------------
  |  | 1108|      0|#define CKM_AES_CBC 0x00001082UL
  ------------------
 2545|      0|            cbc_mechanism.pParameter = &ivBlock;
 2546|      0|            cbc_mechanism.ulParameterLen = blockSize;
 2547|       |            /* is XCBC requires extra processing at the end of the operation */
 2548|      0|            isXCBC = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2549|       |            /* The input key is used to generate k1, k2, and k3. k2 and k3
 2550|       |             * are used at the end in the pad step. k1 replaces the input
 2551|       |             * key in the aes cbc mac */
 2552|      0|            crv = sftk_aes_xcbc_new_keys(hSession, hKey, &hKey, k2, k3);
 2553|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2553:17): [True: 0, False: 0]
  ------------------
 2554|      0|                return crv;
 2555|      0|            }
 2556|      0|            break;
 2557|   212k|        default:
  ------------------
  |  Branch (2557:9): [True: 212k, False: 0]
  ------------------
 2558|   212k|            return CKR_FUNCTION_NOT_SUPPORTED;
  ------------------
  |  | 1426|   212k|#define CKR_FUNCTION_NOT_SUPPORTED 0x00000054UL
  ------------------
 2559|   212k|    }
 2560|       |
 2561|       |    /* if MAC size is externally supplied, it should be checked.
 2562|       |     */
 2563|      0|    if (mac_bytes == SFTK_INVALID_MAC_SIZE)
  ------------------
  |  |  256|      0|#define SFTK_INVALID_MAC_SIZE 0xffffffff
  ------------------
  |  Branch (2563:9): [True: 0, False: 0]
  ------------------
 2564|      0|        mac_bytes = blockSize >> 1;
 2565|      0|    else {
 2566|      0|        if (mac_bytes > blockSize) {
  ------------------
  |  Branch (2566:13): [True: 0, False: 0]
  ------------------
 2567|      0|            crv = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
 2568|      0|            goto fail;
 2569|      0|        }
 2570|      0|    }
 2571|       |
 2572|      0|    crv = sftk_CryptInit(hSession, &cbc_mechanism, hKey,
 2573|      0|                         CKA_ENCRYPT, /* CBC mech is able to ENCRYPT, not SIGN/VERIFY */
  ------------------
  |  |  547|      0|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 2574|      0|                         keyUsage, contextType, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2575|      0|    if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2575:9): [True: 0, False: 0]
  ------------------
 2576|      0|        goto fail;
 2577|      0|    crv = sftk_GetContext(hSession, &context, contextType, PR_TRUE, NULL);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2578|       |
 2579|       |    /* this shouldn't happen! */
 2580|      0|    PORT_Assert(crv == CKR_OK);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2581|      0|    if (crv != CKR_OK)
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2581:9): [True: 0, False: 0]
  ------------------
 2582|      0|        goto fail;
 2583|      0|    context->blockSize = blockSize;
 2584|      0|    context->macSize = mac_bytes;
 2585|      0|    context->isXCBC = isXCBC;
 2586|      0|    if (isXCBC) {
  ------------------
  |  Branch (2586:9): [True: 0, False: 0]
  ------------------
 2587|       |        /* save the xcbc specific parameters */
 2588|      0|        PORT_Memcpy(context->k2, k2, blockSize);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 2589|      0|        PORT_Memcpy(context->k3, k3, blockSize);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 2590|      0|        PORT_Memset(k2, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2591|      0|        PORT_Memset(k3, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2592|       |        /* get rid of the temp key now that the context has been created */
 2593|      0|        NSC_DestroyObject(hSession, hKey);
 2594|      0|    }
 2595|      0|    return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
 2596|      0|fail:
 2597|      0|    if (isXCBC) {
  ------------------
  |  Branch (2597:9): [True: 0, False: 0]
  ------------------
 2598|      0|        PORT_Memset(k2, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2599|      0|        PORT_Memset(k3, 0, blockSize);
  ------------------
  |  |  182|      0|#define PORT_Memset memset
  ------------------
 2600|      0|        NSC_DestroyObject(hSession, hKey); /* get rid of our temp key */
 2601|      0|    }
 2602|      0|    return crv;
 2603|      0|}
pkcs11c.c:sftk_RSASign:
 2704|  30.7k|{
 2705|  30.7k|    NSSLOWKEYPrivateKey *key = ctx;
 2706|  30.7k|    SECStatus rv = SECFailure;
 2707|       |
 2708|  30.7k|    PORT_Assert(key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|  30.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2709|  30.7k|    if (key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (2709:9): [True: 0, False: 30.7k]
  ------------------
 2710|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2711|      0|        return SECFailure;
 2712|      0|    }
 2713|       |
 2714|  30.7k|    rv = RSA_Sign(&key->u.rsa, output, outputLen, maxOutputLen, input,
 2715|  30.7k|                  inputLen);
 2716|  30.7k|    if (rv != SECSuccess && PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (2716:9): [True: 0, False: 30.7k]
  |  Branch (2716:29): [True: 0, False: 0]
  ------------------
 2717|      0|        sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2718|      0|    }
 2719|  30.7k|    return rv;
 2720|  30.7k|}
pkcs11c.c:sftk_Space:
  194|  60.4k|{
  195|  60.4k|    PORT_Free(data);
  ------------------
  |  |   60|  60.4k|#define PORT_Free PORT_Free_Util
  ------------------
  196|  60.4k|}
pkcs11c.c:sftk_ValidatePssParams:
  336|  4.85k|{
  337|  4.85k|    if (!params) {
  ------------------
  |  Branch (337:9): [True: 0, False: 4.85k]
  ------------------
  338|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  339|      0|    }
  340|  4.85k|    if (sftk_GetHashTypeFromMechanism(params->hashAlg) == HASH_AlgNULL ||
  ------------------
  |  Branch (340:9): [True: 0, False: 4.85k]
  ------------------
  341|  4.85k|        sftk_GetHashTypeFromMechanism(params->mgf) == HASH_AlgNULL) {
  ------------------
  |  Branch (341:9): [True: 0, False: 4.85k]
  ------------------
  342|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  343|      0|    }
  344|  4.85k|    return PR_TRUE;
  ------------------
  |  |  437|  4.85k|#define PR_TRUE 1
  ------------------
  345|  4.85k|}
pkcs11c.c:sftk_ZSpace:
  200|  4.85k|{
  201|  4.85k|    size_t len = *(size_t *)data;
  202|  4.85k|    PORT_ZFree(data, len);
  ------------------
  |  |   75|  4.85k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  203|  4.85k|}
pkcs11c.c:sftk_RSASignPSS:
 2748|  4.81k|{
 2749|  4.81k|    SFTKPSSSignInfo *info = ctx;
 2750|  4.81k|    SECStatus rv = SECFailure;
 2751|  4.81k|    HASH_HashType hashAlg;
 2752|  4.81k|    HASH_HashType maskHashAlg;
 2753|  4.81k|    CK_RSA_PKCS_PSS_PARAMS *params = &info->params;
 2754|       |
 2755|  4.81k|    PORT_Assert(info->key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|  4.81k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.81k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4.81k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2756|  4.81k|    if (info->key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (2756:9): [True: 0, False: 4.81k]
  ------------------
 2757|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2758|      0|        return SECFailure;
 2759|      0|    }
 2760|       |
 2761|  4.81k|    hashAlg = sftk_GetHashTypeFromMechanism(params->hashAlg);
 2762|  4.81k|    maskHashAlg = sftk_GetHashTypeFromMechanism(params->mgf);
 2763|       |
 2764|  4.81k|    rv = RSA_SignPSS(&info->key->u.rsa, hashAlg, maskHashAlg, NULL,
 2765|  4.81k|                     params->sLen, sig, sigLen, maxLen, hash, hashLen);
 2766|  4.81k|    if (rv != SECSuccess && PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (2766:9): [True: 0, False: 4.81k]
  |  Branch (2766:29): [True: 0, False: 0]
  ------------------
 2767|      0|        sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2768|      0|    }
 2769|  4.81k|    return rv;
 2770|  4.81k|}
pkcs11c.c:nsc_ECDSASignStub:
 2812|  11.7k|{
 2813|  11.7k|    NSSLOWKEYPrivateKey *key = ctx;
 2814|  11.7k|    SECItem signature = { siBuffer, sigBuf, maxSigLen };
 2815|  11.7k|    SECItem digest = { siBuffer, (unsigned char *)dataBuf, dataLen };
 2816|       |
 2817|  11.7k|    SECStatus rv = ECDSA_SignDigest(&(key->u.ec), &signature, &digest);
 2818|  11.7k|    if (rv != SECSuccess && PORT_GetError() == SEC_ERROR_LIBRARY_FAILURE) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (2818:9): [True: 0, False: 11.7k]
  |  Branch (2818:29): [True: 0, False: 0]
  ------------------
 2819|      0|        sftk_fatalError = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2820|      0|    }
 2821|  11.7k|    *sigLen = signature.len;
 2822|  11.7k|    return rv;
 2823|  11.7k|}
pkcs11c.c:sftk_doMACInit:
 2212|  60.4k|{
 2213|  60.4k|    CK_RV crv;
 2214|  60.4k|    sftk_MACCtx *context;
 2215|  60.4k|    CK_ULONG *intpointer;
 2216|  60.4k|    PRBool isFIPS = sftk_isFIPS(key->slot->slotID);
  ------------------
  |  |  506|  60.4k|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|  60.4k|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|  60.4k|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 60.4k]
  |  |  |  Branch (506:32): [True: 0, False: 60.4k]
  |  |  ------------------
  ------------------
 2217|       |
 2218|       |    /* Set up the initial context. */
 2219|  60.4k|    crv = sftk_MAC_Create(mech, key, &context);
 2220|  60.4k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (2220:9): [True: 0, False: 60.4k]
  ------------------
 2221|      0|        return crv;
 2222|      0|    }
 2223|       |
 2224|  60.4k|    session->hashInfo = context;
 2225|  60.4k|    session->multi = PR_TRUE;
  ------------------
  |  |  437|  60.4k|#define PR_TRUE 1
  ------------------
 2226|       |
 2227|       |    /* Required by FIPS 198 Section 4. Delay this check until after the MAC
 2228|       |     * has been initialized to steal the output size of the MAC. */
 2229|  60.4k|    if (isFIPS && (mac_size < 4 || mac_size < context->mac_size / 2)) {
  ------------------
  |  Branch (2229:9): [True: 0, False: 60.4k]
  |  Branch (2229:20): [True: 0, False: 0]
  |  Branch (2229:36): [True: 0, False: 0]
  ------------------
 2230|      0|        sftk_MAC_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2231|      0|        return CKR_BUFFER_TOO_SMALL;
  ------------------
  |  | 1514|      0|#define CKR_BUFFER_TOO_SMALL 0x00000150UL
  ------------------
 2232|      0|    }
 2233|       |
 2234|       |    /* Configure our helper functions appropriately. Note that these casts
 2235|       |     * ignore the return values. */
 2236|  60.4k|    session->hashUpdate = SFTKHash_sftk_MAC_Update;
 2237|  60.4k|    session->end = SFTKHash_sftk_MAC_End;
 2238|  60.4k|    session->hashdestroy = SFTKHash_sftk_MAC_DestroyContext;
 2239|       |
 2240|  60.4k|    intpointer = PORT_New(CK_ULONG);
  ------------------
  |  |  151|  60.4k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|  60.4k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
 2241|  60.4k|    if (intpointer == NULL) {
  ------------------
  |  Branch (2241:9): [True: 0, False: 60.4k]
  ------------------
 2242|      0|        sftk_MAC_DestroyContext(context, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2243|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 2244|      0|    }
 2245|  60.4k|    *intpointer = mac_size;
 2246|  60.4k|    session->cipherInfo = intpointer;
 2247|       |
 2248|       |    /* Since we're only "hashing", copy the result from session->end to the
 2249|       |     * caller using sftk_SignCopy. */
 2250|  60.4k|    session->update = sftk_SignCopy;
 2251|  60.4k|    session->verify = sftk_HMACCmp;
 2252|  60.4k|    session->destroy = sftk_Space;
 2253|       |
 2254|  60.4k|    session->maxLen = context->mac_size;
 2255|       |
 2256|  60.4k|    return CKR_OK;
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
 2257|  60.4k|}
pkcs11c.c:SFTKHash_sftk_MAC_Update:
  101|  1.63k|    {                                                                                     \
  102|  1.63k|        ctxtype *ctx = vctx;                                                              \
  103|  1.63k|        mmm##_Update(ctx, input, len);                                                    \
  104|  1.63k|    }                                                                                     \
pkcs11c.c:SFTKHash_sftk_MAC_End:
  108|  1.63k|    {                                                                                     \
  109|  1.63k|        ctxtype *ctx = vctx;                                                              \
  110|  1.63k|        mmm##_End(ctx, digest, len, maxLen);                                              \
  111|  1.63k|    }                                                                                     \
pkcs11c.c:SFTKHash_sftk_MAC_DestroyContext:
  114|  60.4k|    {                                                                                     \
  115|  60.4k|        ctxtype *ctx = vctx;                                                              \
  116|  60.4k|        mmm##_DestroyContext(ctx, freeit);                                                \
  117|  60.4k|    }
pkcs11c.c:sftk_SignCopy:
 2178|  1.63k|{
 2179|  1.63k|    unsigned int toCopy = *(CK_ULONG *)copyLen;
 2180|  1.63k|    if (toCopy > maxLength) {
  ------------------
  |  Branch (2180:9): [True: 0, False: 1.63k]
  ------------------
 2181|      0|        toCopy = maxLength;
 2182|      0|    }
 2183|  1.63k|    if (toCopy > hashResultLength) {
  ------------------
  |  Branch (2183:9): [True: 0, False: 1.63k]
  ------------------
 2184|      0|        toCopy = hashResultLength;
 2185|      0|    }
 2186|  1.63k|    memcpy(out, hashResult, toCopy);
 2187|  1.63k|    if (outLength) {
  ------------------
  |  Branch (2187:9): [True: 1.63k, False: 0]
  ------------------
 2188|  1.63k|        *outLength = toCopy;
 2189|  1.63k|    }
 2190|  1.63k|    return SECSuccess;
 2191|  1.63k|}
pkcs11c.c:sftk_MACUpdate:
 3322|   106k|{
 3323|   106k|    SFTKSession *session;
 3324|   106k|    SFTKSessionContext *context;
 3325|   106k|    CK_RV crv;
 3326|       |
 3327|       |    /* make sure we're legal */
 3328|   106k|    crv = sftk_GetContext(hSession, &context, type, PR_TRUE, &session);
  ------------------
  |  |  437|   106k|#define PR_TRUE 1
  ------------------
 3329|   106k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   106k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3329:9): [True: 0, False: 106k]
  ------------------
 3330|      0|        return crv;
 3331|       |
 3332|   106k|    if (context->hashInfo) {
  ------------------
  |  Branch (3332:9): [True: 106k, False: 0]
  ------------------
 3333|   106k|#if (ULONG_MAX > UINT_MAX)
 3334|   106k|        while (ulPartLen > UINT_MAX) {
  ------------------
  |  Branch (3334:16): [True: 0, False: 106k]
  ------------------
 3335|      0|            (*context->hashUpdate)(context->cipherInfo, pPart, UINT_MAX);
 3336|      0|            pPart += UINT_MAX;
 3337|      0|            ulPartLen -= UINT_MAX;
 3338|      0|        }
 3339|   106k|#endif
 3340|   106k|        (*context->hashUpdate)(context->hashInfo, pPart, ulPartLen);
 3341|   106k|    } else {
 3342|       |        /* must be block cipher MACing */
 3343|       |
 3344|      0|        unsigned int blkSize = context->blockSize;
 3345|      0|        unsigned char *residual = /* free room in context->padBuf */
 3346|      0|            context->padBuf + context->padDataLength;
 3347|      0|        unsigned int minInput = /* min input for MACing at least one block */
 3348|      0|            blkSize - context->padDataLength;
 3349|       |
 3350|       |        /* not enough data even for one block */
 3351|      0|        if (ulPartLen <= minInput) {
  ------------------
  |  Branch (3351:13): [True: 0, False: 0]
  ------------------
 3352|      0|            PORT_Memcpy(residual, pPart, ulPartLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 3353|      0|            context->padDataLength += ulPartLen;
 3354|      0|            goto cleanup;
 3355|      0|        }
 3356|       |        /* MACing residual */
 3357|      0|        if (context->padDataLength) {
  ------------------
  |  Branch (3357:13): [True: 0, False: 0]
  ------------------
 3358|      0|            PORT_Memcpy(residual, pPart, minInput);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 3359|      0|            ulPartLen -= minInput;
 3360|      0|            pPart += minInput;
 3361|      0|            if (CKR_OK != (crv = sftk_MACBlock(context, context->padBuf)))
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3361:17): [True: 0, False: 0]
  ------------------
 3362|      0|                goto terminate;
 3363|      0|        }
 3364|       |        /* MACing full blocks */
 3365|      0|        while (ulPartLen > blkSize) {
  ------------------
  |  Branch (3365:16): [True: 0, False: 0]
  ------------------
 3366|      0|            if (CKR_OK != (crv = sftk_MACBlock(context, pPart)))
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (3366:17): [True: 0, False: 0]
  ------------------
 3367|      0|                goto terminate;
 3368|      0|            ulPartLen -= blkSize;
 3369|      0|            pPart += blkSize;
 3370|      0|        }
 3371|       |        /* save the residual */
 3372|      0|        if ((context->padDataLength = ulPartLen))
  ------------------
  |  Branch (3372:13): [True: 0, False: 0]
  ------------------
 3373|      0|            PORT_Memcpy(context->padBuf, pPart, ulPartLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 3374|      0|    } /* blk cipher MACing */
 3375|       |
 3376|   106k|    goto cleanup;
 3377|       |
 3378|   106k|terminate:
 3379|      0|    sftk_TerminateOp(session, type, context);
 3380|   106k|cleanup:
 3381|   106k|    sftk_FreeSession(session);
 3382|   106k|    return crv;
 3383|      0|}
pkcs11c.c:sftk_RSACheckSign:
 3660|     22|{
 3661|     22|    NSSLOWKEYPublicKey *key = ctx;
 3662|     22|    PORT_Assert(key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|     22|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     22|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 22, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3663|     22|    if (key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (3663:9): [True: 0, False: 22]
  ------------------
 3664|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3665|      0|        return SECFailure;
 3666|      0|    }
 3667|       |
 3668|     22|    return RSA_CheckSign(&key->u.rsa, sig, sigLen, digest, digestLen);
 3669|     22|}
pkcs11c.c:sftk_RSACheckSignPSS:
 3690|     38|{
 3691|     38|    SFTKPSSVerifyInfo *info = ctx;
 3692|     38|    HASH_HashType hashAlg;
 3693|     38|    HASH_HashType maskHashAlg;
 3694|     38|    CK_RSA_PKCS_PSS_PARAMS *params = &info->params;
 3695|       |
 3696|     38|    PORT_Assert(info->key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|     38|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     38|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 38, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3697|     38|    if (info->key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (3697:9): [True: 0, False: 38]
  ------------------
 3698|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3699|      0|        return SECFailure;
 3700|      0|    }
 3701|       |
 3702|     38|    hashAlg = sftk_GetHashTypeFromMechanism(params->hashAlg);
 3703|     38|    maskHashAlg = sftk_GetHashTypeFromMechanism(params->mgf);
 3704|       |
 3705|     38|    return RSA_CheckSignPSS(&info->key->u.rsa, hashAlg, maskHashAlg,
 3706|     38|                            params->sLen, sig, sigLen, digest, digestLen);
 3707|     38|}
pkcs11c.c:sftk_RSACheckSignRecover:
 4044|  2.95k|{
 4045|  2.95k|    NSSLOWKEYPublicKey *key = ctx;
 4046|  2.95k|    PORT_Assert(key->keyType == NSSLOWKEYRSAKey);
  ------------------
  |  |  120|  2.95k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.95k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.95k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4047|  2.95k|    if (key->keyType != NSSLOWKEYRSAKey) {
  ------------------
  |  Branch (4047:9): [True: 0, False: 2.95k]
  ------------------
 4048|      0|        PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4049|      0|        return SECFailure;
 4050|      0|    }
 4051|       |
 4052|  2.95k|    return RSA_CheckSignRecover(&key->u.rsa, data, dataLen, maxDataLen,
 4053|  2.95k|                                sig, sigLen);
 4054|  2.95k|}
pkcs11c.c:nsc_SetupBulkKeyGen:
 4477|  4.72k|{
 4478|  4.72k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  4.72k|#define CKR_OK 0x00000000UL
  ------------------
 4479|       |
 4480|  4.72k|    switch (mechanism) {
 4481|      0|#ifndef NSS_DISABLE_DEPRECATED_RC2
 4482|      0|        case CKM_RC2_KEY_GEN:
  ------------------
  |  |  803|      0|#define CKM_RC2_KEY_GEN 0x00000100UL
  ------------------
  |  Branch (4482:9): [True: 0, False: 4.72k]
  ------------------
 4483|      0|            *key_type = CKK_RC2;
  ------------------
  |  |  384|      0|#define CKK_RC2 0x00000011UL
  ------------------
 4484|      0|            if (*key_length == 0)
  ------------------
  |  Branch (4484:17): [True: 0, False: 0]
  ------------------
 4485|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 4486|      0|            break;
 4487|      0|#endif /* NSS_DISABLE_DEPRECATED_RC2 */
 4488|       |#if NSS_SOFTOKEN_DOES_RC5
 4489|       |        case CKM_RC5_KEY_GEN:
 4490|       |            *key_type = CKK_RC5;
 4491|       |            if (*key_length == 0)
 4492|       |                crv = CKR_TEMPLATE_INCOMPLETE;
 4493|       |            break;
 4494|       |#endif
 4495|      0|        case CKM_RC4_KEY_GEN:
  ------------------
  |  |  812|      0|#define CKM_RC4_KEY_GEN 0x00000110UL
  ------------------
  |  Branch (4495:9): [True: 0, False: 4.72k]
  ------------------
 4496|      0|            *key_type = CKK_RC4;
  ------------------
  |  |  385|      0|#define CKK_RC4 0x00000012UL
  ------------------
 4497|      0|            if (*key_length == 0)
  ------------------
  |  Branch (4497:17): [True: 0, False: 0]
  ------------------
 4498|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 4499|      0|            break;
 4500|      1|        case CKM_GENERIC_SECRET_KEY_GEN:
  ------------------
  |  |  953|      1|#define CKM_GENERIC_SECRET_KEY_GEN 0x00000350UL
  ------------------
  |  Branch (4500:9): [True: 1, False: 4.72k]
  ------------------
 4501|      1|            *key_type = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|      1|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 4502|      1|            if (*key_length == 0)
  ------------------
  |  Branch (4502:17): [True: 0, False: 1]
  ------------------
 4503|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 4504|      1|            break;
 4505|      0|        case CKM_CDMF_KEY_GEN:
  ------------------
  |  |  834|      0|#define CKM_CDMF_KEY_GEN 0x00000140UL
  ------------------
  |  Branch (4505:9): [True: 0, False: 4.72k]
  ------------------
 4506|      0|            *key_type = CKK_CDMF;
  ------------------
  |  |  401|      0|#define CKK_CDMF 0x0000001EUL
  ------------------
 4507|      0|            *key_length = 8;
 4508|      0|            break;
 4509|      0|        case CKM_DES_KEY_GEN:
  ------------------
  |  |  814|      0|#define CKM_DES_KEY_GEN 0x00000120UL
  ------------------
  |  Branch (4509:9): [True: 0, False: 4.72k]
  ------------------
 4510|      0|            *key_type = CKK_DES;
  ------------------
  |  |  386|      0|#define CKK_DES 0x00000013UL
  ------------------
 4511|      0|            *key_length = 8;
 4512|      0|            break;
 4513|      0|        case CKM_DES2_KEY_GEN:
  ------------------
  |  |  823|      0|#define CKM_DES2_KEY_GEN 0x00000130UL
  ------------------
  |  Branch (4513:9): [True: 0, False: 4.72k]
  ------------------
 4514|      0|            *key_type = CKK_DES2;
  ------------------
  |  |  387|      0|#define CKK_DES2 0x00000014UL
  ------------------
 4515|      0|            *key_length = 16;
 4516|      0|            break;
 4517|      2|        case CKM_DES3_KEY_GEN:
  ------------------
  |  |  824|      2|#define CKM_DES3_KEY_GEN 0x00000131UL
  ------------------
  |  Branch (4517:9): [True: 2, False: 4.72k]
  ------------------
 4518|      2|            *key_type = CKK_DES3;
  ------------------
  |  |  388|      2|#define CKK_DES3 0x00000015UL
  ------------------
 4519|      2|            *key_length = 24;
 4520|      2|            break;
 4521|      0|#ifndef NSS_DISABLE_DEPRECATED_SEED
 4522|      0|        case CKM_SEED_KEY_GEN:
  ------------------
  |  | 1155|      0|#define CKM_SEED_KEY_GEN 0x00000650UL
  ------------------
  |  Branch (4522:9): [True: 0, False: 4.72k]
  ------------------
 4523|      0|            *key_type = CKK_SEED;
  ------------------
  |  |  416|      0|#define CKK_SEED 0x0000002FUL /* was 2A */
  ------------------
 4524|      0|            *key_length = 16;
 4525|      0|            break;
 4526|      0|#endif /* NSS_DISABLE_DEPRECATED_SEED */
 4527|      0|        case CKM_CAMELLIA_KEY_GEN:
  ------------------
  |  | 1135|      0|#define CKM_CAMELLIA_KEY_GEN 0x00000550UL
  ------------------
  |  Branch (4527:9): [True: 0, False: 4.72k]
  ------------------
 4528|      0|            *key_type = CKK_CAMELLIA;
  ------------------
  |  |  414|      0|#define CKK_CAMELLIA 0x00000025UL
  ------------------
 4529|      0|            if (*key_length == 0)
  ------------------
  |  Branch (4529:17): [True: 0, False: 0]
  ------------------
 4530|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 4531|      0|            break;
 4532|      1|        case CKM_AES_KEY_GEN:
  ------------------
  |  | 1106|      1|#define CKM_AES_KEY_GEN 0x00001080UL
  ------------------
  |  Branch (4532:9): [True: 1, False: 4.72k]
  ------------------
 4533|      1|            *key_type = CKK_AES;
  ------------------
  |  |  402|      1|#define CKK_AES 0x0000001FUL
  ------------------
 4534|      1|            if (*key_length == 0)
  ------------------
  |  Branch (4534:17): [True: 0, False: 1]
  ------------------
 4535|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 4536|      1|            break;
 4537|  4.72k|        case CKM_NSS_CHACHA20_KEY_GEN:
  ------------------
  |  |  242|  4.72k|#define CKM_NSS_CHACHA20_KEY_GEN (CKM_NSS + 27)
  |  |  ------------------
  |  |  |  |  162|  4.72k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  4.72k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (4537:9): [True: 4.72k, False: 4]
  ------------------
 4538|  4.72k|            *key_type = CKK_NSS_CHACHA20;
  ------------------
  |  |   56|  4.72k|#define CKK_NSS_CHACHA20 (CKK_NSS + 4)
  |  |  ------------------
  |  |  |  |   49|  4.72k|#define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |  458|  4.72k|#define CKK_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKK_NSS (CKK_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  4.72k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4539|  4.72k|            *key_length = 32;
 4540|  4.72k|            break;
 4541|      0|        case CKM_CHACHA20_KEY_GEN:
  ------------------
  |  | 1203|      0|#define CKM_CHACHA20_KEY_GEN 0x00001225UL
  ------------------
  |  Branch (4541:9): [True: 0, False: 4.72k]
  ------------------
 4542|      0|            *key_type = CKK_CHACHA20;
  ------------------
  |  |  433|      0|#define CKK_CHACHA20 0x00000033UL
  ------------------
 4543|      0|            *key_length = 32;
 4544|      0|            break;
 4545|      0|        case CKM_HKDF_KEY_GEN:
  ------------------
  |  | 1298|      0|#define CKM_HKDF_KEY_GEN 0x0000402cUL
  ------------------
  |  Branch (4545:9): [True: 0, False: 4.72k]
  ------------------
 4546|      0|            *key_type = CKK_HKDF;
  ------------------
  |  |  450|      0|#define CKK_HKDF 0x00000042UL
  ------------------
 4547|      0|            if (*key_length == 0)
  ------------------
  |  Branch (4547:17): [True: 0, False: 0]
  ------------------
 4548|      0|                crv = CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
 4549|      0|            break;
 4550|      0|        default:
  ------------------
  |  Branch (4550:9): [True: 0, False: 4.72k]
  ------------------
 4551|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4552|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
 4553|      0|            break;
 4554|  4.72k|    }
 4555|       |
 4556|  4.72k|    return crv;
 4557|  4.72k|}
pkcs11c.c:sftk_PairwiseConsistencyCheck:
 5056|  29.0k|{
 5057|       |    /*
 5058|       |     *                      Key type    Mechanism type
 5059|       |     *                      --------------------------------
 5060|       |     * For encrypt/decrypt: CKK_RSA  => CKM_RSA_PKCS
 5061|       |     *                      others   => CKM_INVALID_MECHANISM
 5062|       |     *
 5063|       |     * For sign/verify:     CKK_RSA  => CKM_RSA_PKCS
 5064|       |     *                      CKK_DSA  => CKM_DSA
 5065|       |     *                      CKK_EC   => CKM_ECDSA
 5066|       |     *                      others   => CKM_INVALID_MECHANISM
 5067|       |     *
 5068|       |     * None of these mechanisms has a parameter.
 5069|       |     *
 5070|       |     * For derive           CKK_DH   => CKM_DH_PKCS_DERIVE
 5071|       |     *                      CKK_EC   => CKM_ECDH1_DERIVE
 5072|       |     *                      CKK_EC_MONTGOMERY   => CKM_ECDH1_DERIVE
 5073|       |     *                      others   => CKM_INVALID_MECHANISM
 5074|       |     *
 5075|       |     * The parameters for these mechanisms is the public key.
 5076|       |     */
 5077|  29.0k|    CK_MECHANISM mech = { 0, NULL, 0 };
 5078|       |
 5079|  29.0k|    CK_ULONG modulusLen = 0;
 5080|  29.0k|    CK_ULONG subPrimeLen = 0;
 5081|  29.0k|    PRBool isEncryptable = PR_FALSE;
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
 5082|  29.0k|    PRBool canSignVerify = PR_FALSE;
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
 5083|  29.0k|    PRBool isDerivable = PR_FALSE;
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
 5084|  29.0k|    CK_RV crv;
 5085|       |
 5086|       |    /* Variables used for Encrypt/Decrypt functions. */
 5087|  29.0k|    unsigned char *known_message = (unsigned char *)"Known Crypto Message";
 5088|  29.0k|    unsigned char plaintext[PAIRWISE_MESSAGE_LENGTH];
 5089|  29.0k|    CK_ULONG bytes_decrypted;
 5090|  29.0k|    unsigned char *ciphertext;
 5091|  29.0k|    unsigned char *text_compared;
 5092|  29.0k|    CK_ULONG bytes_encrypted;
 5093|  29.0k|    CK_ULONG bytes_compared;
 5094|  29.0k|    CK_ULONG pairwise_digest_length = PAIRWISE_DIGEST_LENGTH;
  ------------------
  |  | 5041|  29.0k|#define PAIRWISE_DIGEST_LENGTH SHA1_LENGTH /* 160-bits */
  |  |  ------------------
  |  |  |  |   39|  29.0k|#define SHA1_LENGTH 20
  |  |  ------------------
  ------------------
 5095|       |
 5096|       |    /* Variables used for Signature/Verification functions. */
 5097|       |    /* Must be at least 256 bits for DSA2 digest */
 5098|  29.0k|    unsigned char *known_digest = (unsigned char *)"Mozilla Rules the World through NSS!";
 5099|  29.0k|    unsigned char *signature;
 5100|  29.0k|    CK_ULONG signature_length;
 5101|       |
 5102|  29.0k|    if (keyType == CKK_RSA) {
  ------------------
  |  |  372|  29.0k|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (5102:9): [True: 0, False: 29.0k]
  ------------------
 5103|      0|        SFTKAttribute *attribute;
 5104|       |
 5105|       |        /* Get modulus length of private key. */
 5106|      0|        attribute = sftk_FindAttribute(privateKey, CKA_MODULUS);
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
 5107|      0|        if (attribute == NULL) {
  ------------------
  |  Branch (5107:13): [True: 0, False: 0]
  ------------------
 5108|      0|            return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 5109|      0|        }
 5110|      0|        modulusLen = attribute->attrib.ulValueLen;
 5111|      0|        if (*(unsigned char *)attribute->attrib.pValue == 0) {
  ------------------
  |  Branch (5111:13): [True: 0, False: 0]
  ------------------
 5112|      0|            modulusLen--;
 5113|      0|        }
 5114|      0|        sftk_FreeAttribute(attribute);
 5115|  29.0k|    } else if (keyType == CKK_DSA) {
  ------------------
  |  |  373|  29.0k|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (5115:16): [True: 0, False: 29.0k]
  ------------------
 5116|      0|        SFTKAttribute *attribute;
 5117|       |
 5118|       |        /* Get subprime length of private key. */
 5119|      0|        attribute = sftk_FindAttribute(privateKey, CKA_SUBPRIME);
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
 5120|      0|        if (attribute == NULL) {
  ------------------
  |  Branch (5120:13): [True: 0, False: 0]
  ------------------
 5121|      0|            return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 5122|      0|        }
 5123|      0|        subPrimeLen = attribute->attrib.ulValueLen;
 5124|      0|        if (subPrimeLen > 1 && *(unsigned char *)attribute->attrib.pValue == 0) {
  ------------------
  |  Branch (5124:13): [True: 0, False: 0]
  |  Branch (5124:32): [True: 0, False: 0]
  ------------------
 5125|      0|            subPrimeLen--;
 5126|      0|        }
 5127|      0|        sftk_FreeAttribute(attribute);
 5128|      0|    }
 5129|       |
 5130|       |    /**************************************************/
 5131|       |    /* Pairwise Consistency Check of Encrypt/Decrypt. */
 5132|       |    /**************************************************/
 5133|       |
 5134|  29.0k|    isEncryptable = sftk_isTrue(privateKey, CKA_DECRYPT);
  ------------------
  |  |  548|  29.0k|#define CKA_DECRYPT 0x00000105UL
  ------------------
 5135|       |
 5136|       |    /*
 5137|       |     * If the decryption attribute is set, attempt to encrypt
 5138|       |     * with the public key and decrypt with the private key.
 5139|       |     */
 5140|  29.0k|    if (isEncryptable) {
  ------------------
  |  Branch (5140:9): [True: 0, False: 29.0k]
  ------------------
 5141|      0|        if (keyType != CKK_RSA) {
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (5141:13): [True: 0, False: 0]
  ------------------
 5142|      0|            return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 5143|      0|        }
 5144|      0|        bytes_encrypted = modulusLen;
 5145|      0|        mech.mechanism = CKM_RSA_PKCS;
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
 5146|       |
 5147|       |        /* Allocate space for ciphertext. */
 5148|      0|        ciphertext = (unsigned char *)PORT_ZAlloc(bytes_encrypted);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 5149|      0|        if (ciphertext == NULL) {
  ------------------
  |  Branch (5149:13): [True: 0, False: 0]
  ------------------
 5150|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5151|      0|        }
 5152|       |
 5153|       |        /* Prepare for encryption using the public key. */
 5154|      0|        crv = NSC_EncryptInit(hSession, &mech, publicKey->handle);
 5155|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5155:13): [True: 0, False: 0]
  ------------------
 5156|      0|            PORT_Free(ciphertext);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5157|      0|            return crv;
 5158|      0|        }
 5159|       |
 5160|       |        /* Encrypt using the public key. */
 5161|      0|        crv = NSC_Encrypt(hSession,
 5162|      0|                          known_message,
 5163|      0|                          PAIRWISE_MESSAGE_LENGTH,
  ------------------
  |  | 5042|      0|#define PAIRWISE_MESSAGE_LENGTH 20         /* 160-bits */
  ------------------
 5164|      0|                          ciphertext,
 5165|      0|                          &bytes_encrypted);
 5166|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5166:13): [True: 0, False: 0]
  ------------------
 5167|      0|            PORT_Free(ciphertext);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5168|      0|            return crv;
 5169|      0|        }
 5170|       |
 5171|       |        /* Always use the smaller of these two values . . . */
 5172|      0|        bytes_compared = PR_MIN(bytes_encrypted, PAIRWISE_MESSAGE_LENGTH);
  ------------------
  |  |  158|      0|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 5173|       |
 5174|       |        /*
 5175|       |         * If there was a failure, the plaintext
 5176|       |         * goes at the end, therefore . . .
 5177|       |         */
 5178|      0|        text_compared = ciphertext + bytes_encrypted - bytes_compared;
 5179|       |
 5180|       |        /*
 5181|       |         * Check to ensure that ciphertext does
 5182|       |         * NOT EQUAL known input message text
 5183|       |         * per FIPS PUB 140-2 directive.
 5184|       |         */
 5185|      0|        if (PORT_Memcmp(text_compared, known_message,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (5185:13): [True: 0, False: 0]
  ------------------
 5186|      0|                        bytes_compared) == 0) {
 5187|       |            /* Set error to Invalid PRIVATE Key. */
 5188|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5189|      0|            PORT_Free(ciphertext);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5190|      0|            return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5191|      0|        }
 5192|       |
 5193|       |        /* Prepare for decryption using the private key. */
 5194|      0|        crv = NSC_DecryptInit(hSession, &mech, privateKey->handle);
 5195|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5195:13): [True: 0, False: 0]
  ------------------
 5196|      0|            PORT_Free(ciphertext);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5197|      0|            return crv;
 5198|      0|        }
 5199|       |
 5200|      0|        memset(plaintext, 0, PAIRWISE_MESSAGE_LENGTH);
  ------------------
  |  | 5042|      0|#define PAIRWISE_MESSAGE_LENGTH 20         /* 160-bits */
  ------------------
 5201|       |
 5202|       |        /*
 5203|       |         * Initialize bytes decrypted to be the
 5204|       |         * expected PAIRWISE_MESSAGE_LENGTH.
 5205|       |         */
 5206|      0|        bytes_decrypted = PAIRWISE_MESSAGE_LENGTH;
  ------------------
  |  | 5042|      0|#define PAIRWISE_MESSAGE_LENGTH 20         /* 160-bits */
  ------------------
 5207|       |
 5208|       |        /*
 5209|       |         * Decrypt using the private key.
 5210|       |         * NOTE:  No need to reset the
 5211|       |         *        value of bytes_encrypted.
 5212|       |         */
 5213|      0|        crv = NSC_Decrypt(hSession,
 5214|      0|                          ciphertext,
 5215|      0|                          bytes_encrypted,
 5216|      0|                          plaintext,
 5217|      0|                          &bytes_decrypted);
 5218|       |
 5219|       |        /* Finished with ciphertext; free it. */
 5220|      0|        PORT_Free(ciphertext);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5221|       |
 5222|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5222:13): [True: 0, False: 0]
  ------------------
 5223|      0|            return crv;
 5224|      0|        }
 5225|       |
 5226|       |        /*
 5227|       |         * Check to ensure that the output plaintext
 5228|       |         * does EQUAL known input message text.
 5229|       |         */
 5230|      0|        if ((bytes_decrypted != PAIRWISE_MESSAGE_LENGTH) ||
  ------------------
  |  | 5042|      0|#define PAIRWISE_MESSAGE_LENGTH 20         /* 160-bits */
  ------------------
  |  Branch (5230:13): [True: 0, False: 0]
  ------------------
 5231|      0|            (PORT_Memcmp(plaintext, known_message,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (5231:13): [True: 0, False: 0]
  ------------------
 5232|      0|                         PAIRWISE_MESSAGE_LENGTH) != 0)) {
  ------------------
  |  | 5042|      0|#define PAIRWISE_MESSAGE_LENGTH 20         /* 160-bits */
  ------------------
 5233|       |            /* Set error to Bad PUBLIC Key. */
 5234|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5235|      0|            return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5236|      0|        }
 5237|      0|    }
 5238|       |
 5239|       |    /**********************************************/
 5240|       |    /* Pairwise Consistency Check of Sign/Verify. */
 5241|       |    /**********************************************/
 5242|       |
 5243|  29.0k|    canSignVerify = sftk_isTrue(privateKey, CKA_SIGN);
  ------------------
  |  |  551|  29.0k|#define CKA_SIGN 0x00000108UL
  ------------------
 5244|       |    /* Unfortunately CKA_SIGN is always true in lg dbs. We have to check the
 5245|       |     * actual curve to determine if we can do sign/verify. */
 5246|  29.0k|    if (canSignVerify && keyType == CKK_EC) {
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (5246:9): [True: 0, False: 29.0k]
  |  Branch (5246:26): [True: 0, False: 0]
  ------------------
 5247|      0|        NSSLOWKEYPrivateKey *privKey = sftk_GetPrivKey(privateKey, CKK_EC, &crv);
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
 5248|      0|        if (privKey && privKey->u.ec.ecParams.name == ECCurve25519) {
  ------------------
  |  Branch (5248:13): [True: 0, False: 0]
  |  Branch (5248:24): [True: 0, False: 0]
  ------------------
 5249|      0|            canSignVerify = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5250|      0|        }
 5251|      0|    }
 5252|       |
 5253|  29.0k|    if (canSignVerify) {
  ------------------
  |  Branch (5253:9): [True: 0, False: 29.0k]
  ------------------
 5254|       |        /* Determine length of signature. */
 5255|      0|        switch (keyType) {
 5256|      0|            case CKK_RSA:
  ------------------
  |  |  372|      0|#define CKK_RSA 0x00000000UL
  ------------------
  |  Branch (5256:13): [True: 0, False: 0]
  ------------------
 5257|      0|                signature_length = modulusLen;
 5258|      0|                mech.mechanism = CKM_RSA_PKCS;
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
 5259|      0|                break;
 5260|      0|            case CKK_DSA:
  ------------------
  |  |  373|      0|#define CKK_DSA 0x00000001UL
  ------------------
  |  Branch (5260:13): [True: 0, False: 0]
  ------------------
 5261|      0|                signature_length = DSA_MAX_SIGNATURE_LEN;
  ------------------
  |  |   52|      0|#define DSA_MAX_SIGNATURE_LEN (DSA_MAX_SUBPRIME_LEN * 2) /* Bytes */
  |  |  ------------------
  |  |  |  |   51|      0|#define DSA_MAX_SUBPRIME_LEN 32                          /* Bytes */
  |  |  ------------------
  ------------------
 5262|      0|                pairwise_digest_length = subPrimeLen;
 5263|      0|                mech.mechanism = CKM_DSA;
  ------------------
  |  |  745|      0|#define CKM_DSA 0x00000011UL
  ------------------
 5264|      0|                break;
 5265|      0|            case CKK_EC:
  ------------------
  |  |  379|      0|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (5265:13): [True: 0, False: 0]
  ------------------
 5266|      0|                signature_length = MAX_ECKEY_LEN * 2;
  ------------------
  |  |   81|      0|#define MAX_ECKEY_LEN 72 /* Bytes */
  ------------------
 5267|      0|                mech.mechanism = CKM_ECDSA;
  ------------------
  |  | 1074|      0|#define CKM_ECDSA 0x00001041UL
  ------------------
 5268|      0|                break;
 5269|      0|            case CKK_EC_EDWARDS:
  ------------------
  |  |  448|      0|#define CKK_EC_EDWARDS 0x00000040UL
  ------------------
  |  Branch (5269:13): [True: 0, False: 0]
  ------------------
 5270|      0|                signature_length = ED25519_SIGN_LEN;
  ------------------
  |  |   32|      0|#define ED25519_SIGN_LEN 64U /* Bytes */
  ------------------
 5271|      0|                mech.mechanism = CKM_EDDSA;
  ------------------
  |  | 1174|      0|#define CKM_EDDSA 0x00001057UL
  ------------------
 5272|      0|                break;
 5273|      0|            default:
  ------------------
  |  Branch (5273:13): [True: 0, False: 0]
  ------------------
 5274|      0|                return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 5275|      0|        }
 5276|       |
 5277|       |        /* Allocate space for signature data. */
 5278|      0|        signature = (unsigned char *)PORT_ZAlloc(signature_length);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 5279|      0|        if (signature == NULL) {
  ------------------
  |  Branch (5279:13): [True: 0, False: 0]
  ------------------
 5280|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 5281|      0|        }
 5282|       |
 5283|       |        /* Sign the known hash using the private key. */
 5284|      0|        crv = NSC_SignInit(hSession, &mech, privateKey->handle);
 5285|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5285:13): [True: 0, False: 0]
  ------------------
 5286|      0|            PORT_Free(signature);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5287|      0|            return crv;
 5288|      0|        }
 5289|       |
 5290|      0|        crv = NSC_Sign(hSession,
 5291|      0|                       known_digest,
 5292|      0|                       pairwise_digest_length,
 5293|      0|                       signature,
 5294|      0|                       &signature_length);
 5295|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5295:13): [True: 0, False: 0]
  ------------------
 5296|      0|            PORT_Free(signature);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5297|      0|            return crv;
 5298|      0|        }
 5299|       |
 5300|       |        /* detect trivial signing transforms */
 5301|      0|        if ((signature_length >= pairwise_digest_length) &&
  ------------------
  |  Branch (5301:13): [True: 0, False: 0]
  ------------------
 5302|      0|            (PORT_Memcmp(known_digest, signature + (signature_length - pairwise_digest_length), pairwise_digest_length) == 0)) {
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (5302:13): [True: 0, False: 0]
  ------------------
 5303|      0|            PORT_Free(signature);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5304|      0|            return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5305|      0|        }
 5306|       |
 5307|       |        /* Verify the known hash using the public key. */
 5308|      0|        crv = NSC_VerifyInit(hSession, &mech, publicKey->handle);
 5309|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5309:13): [True: 0, False: 0]
  ------------------
 5310|      0|            PORT_Free(signature);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5311|      0|            return crv;
 5312|      0|        }
 5313|       |
 5314|      0|        crv = NSC_Verify(hSession,
 5315|      0|                         known_digest,
 5316|      0|                         pairwise_digest_length,
 5317|      0|                         signature,
 5318|      0|                         signature_length);
 5319|       |
 5320|       |        /* Free signature data. */
 5321|      0|        PORT_Free(signature);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 5322|       |
 5323|      0|        if ((crv == CKR_SIGNATURE_LEN_RANGE) ||
  ------------------
  |  | 1476|      0|#define CKR_SIGNATURE_LEN_RANGE 0x000000C1UL
  ------------------
  |  Branch (5323:13): [True: 0, False: 0]
  ------------------
 5324|      0|            (crv == CKR_SIGNATURE_INVALID)) {
  ------------------
  |  | 1475|      0|#define CKR_SIGNATURE_INVALID 0x000000C0UL
  ------------------
  |  Branch (5324:13): [True: 0, False: 0]
  ------------------
 5325|      0|            return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5326|      0|        }
 5327|      0|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5327:13): [True: 0, False: 0]
  ------------------
 5328|      0|            return crv;
 5329|      0|        }
 5330|      0|    }
 5331|       |
 5332|       |    /**********************************************/
 5333|       |    /* Pairwise Consistency Check for Derivation  */
 5334|       |    /**********************************************/
 5335|       |
 5336|  29.0k|    isDerivable = sftk_isTrue(privateKey, CKA_DERIVE);
  ------------------
  |  |  555|  29.0k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 5337|       |
 5338|  29.0k|    if (isDerivable) {
  ------------------
  |  Branch (5338:9): [True: 29.0k, False: 0]
  ------------------
 5339|  29.0k|        SFTKAttribute *pubAttribute = NULL;
 5340|  29.0k|        PRBool isFIPS = sftk_isFIPS(slot->slotID);
  ------------------
  |  |  506|  29.0k|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|  29.0k|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|  29.0k|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 29.0k]
  |  |  |  Branch (506:32): [True: 0, False: 29.0k]
  |  |  ------------------
  ------------------
 5341|  29.0k|        NSSLOWKEYPrivateKey *lowPrivKey = NULL;
 5342|  29.0k|        ECPrivateKey *ecPriv = NULL;
 5343|  29.0k|        SECItem *lowPubValue = NULL;
 5344|  29.0k|        SECItem item = { siBuffer, NULL, 0 };
 5345|  29.0k|        SECStatus rv;
 5346|       |
 5347|  29.0k|        crv = CKR_OK; /*paranoia, already get's set before we drop to the end */
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
 5348|       |
 5349|       |        /* FIPS 140-3 requires we verify that the resulting key is a valid key
 5350|       |         * by recalculating the public can an compare it to our own public
 5351|       |         * key. */
 5352|  29.0k|        lowPrivKey = sftk_GetPrivKey(privateKey, keyType, &crv);
 5353|  29.0k|        if (lowPrivKey == NULL) {
  ------------------
  |  Branch (5353:13): [True: 0, False: 29.0k]
  ------------------
 5354|      0|            return sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 5355|      0|        }
 5356|       |        /* recalculate the public key from the private key */
 5357|  29.0k|        switch (keyType) {
 5358|  29.0k|            case CKK_DH:
  ------------------
  |  |  374|  29.0k|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (5358:13): [True: 29.0k, False: 1]
  ------------------
 5359|  29.0k|                rv = DH_Derive(&lowPrivKey->u.dh.base, &lowPrivKey->u.dh.prime,
 5360|  29.0k|                               &lowPrivKey->u.dh.privateValue, &item, 0);
 5361|  29.0k|                if (rv != SECSuccess) {
  ------------------
  |  Branch (5361:21): [True: 0, False: 29.0k]
  ------------------
 5362|      0|                    return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5363|      0|                }
 5364|  29.0k|                lowPubValue = SECITEM_DupItem(&item);
  ------------------
  |  |  107|  29.0k|#define SECITEM_DupItem SECITEM_DupItem_Util
  ------------------
 5365|  29.0k|                SECITEM_ZfreeItem(&item, PR_FALSE);
  ------------------
  |  |  110|  29.0k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(&item, PR_FALSE);
  ------------------
  |  |  438|  29.0k|#define PR_FALSE 0
  ------------------
 5366|  29.0k|                pubAttribute = sftk_FindAttribute(publicKey, CKA_VALUE);
  ------------------
  |  |  516|  29.0k|#define CKA_VALUE 0x00000011UL
  ------------------
 5367|  29.0k|                break;
 5368|      0|            case CKK_EC_MONTGOMERY:
  ------------------
  |  |  449|      0|#define CKK_EC_MONTGOMERY 0x00000041UL
  ------------------
  |  Branch (5368:13): [True: 0, False: 29.0k]
  ------------------
 5369|      1|            case CKK_EC:
  ------------------
  |  |  379|      1|#define CKK_EC 0x00000003UL
  ------------------
  |  Branch (5369:13): [True: 1, False: 29.0k]
  ------------------
 5370|      1|                rv = EC_NewKeyFromSeed(&lowPrivKey->u.ec.ecParams, &ecPriv,
 5371|      1|                                       lowPrivKey->u.ec.privateValue.data,
 5372|      1|                                       lowPrivKey->u.ec.privateValue.len);
 5373|      1|                if (rv != SECSuccess) {
  ------------------
  |  Branch (5373:21): [True: 0, False: 1]
  ------------------
 5374|      0|                    return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5375|      0|                }
 5376|       |                /* make sure it has the same encoding */
 5377|      1|                if (PR_GetEnvSecure("NSS_USE_DECODED_CKA_EC_POINT") ||
  ------------------
  |  Branch (5377:21): [True: 0, False: 1]
  ------------------
 5378|      1|                    lowPrivKey->u.ec.ecParams.type != ec_params_named) {
  ------------------
  |  Branch (5378:21): [True: 0, False: 1]
  ------------------
 5379|      0|                    lowPubValue = SECITEM_DupItem(&ecPriv->publicValue);
  ------------------
  |  |  107|      0|#define SECITEM_DupItem SECITEM_DupItem_Util
  ------------------
 5380|      1|                } else {
 5381|      1|                    lowPubValue = SEC_ASN1EncodeItem(NULL, NULL, &ecPriv->publicValue,
  ------------------
  |  |   89|      1|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
 5382|      1|                                                     SEC_ASN1_GET(SEC_OctetStringTemplate));
  ------------------
  |  |  188|      1|#define SEC_ASN1_GET(x) x
  ------------------
 5383|      1|                }
 5384|      1|                pubAttribute = sftk_FindAttribute(publicKey, CKA_EC_POINT);
  ------------------
  |  |  604|      1|#define CKA_EC_POINT 0x00000181UL
  ------------------
 5385|       |                /* clear out our generated private key */
 5386|      1|                PORT_FreeArena(ecPriv->ecParams.arena, PR_TRUE);
  ------------------
  |  |   61|      1|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                              PORT_FreeArena(ecPriv->ecParams.arena, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 5387|      1|                break;
 5388|      0|            default:
  ------------------
  |  Branch (5388:13): [True: 0, False: 29.0k]
  ------------------
 5389|      0|                return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
 5390|  29.0k|        }
 5391|       |
 5392|       |        /* now compare new public key with our already generated key */
 5393|  29.0k|        if ((pubAttribute == NULL) || (lowPubValue == NULL) ||
  ------------------
  |  Branch (5393:13): [True: 0, False: 29.0k]
  |  Branch (5393:39): [True: 0, False: 29.0k]
  ------------------
 5394|  29.0k|            (pubAttribute->attrib.ulValueLen != lowPubValue->len) ||
  ------------------
  |  Branch (5394:13): [True: 0, False: 29.0k]
  ------------------
 5395|  29.0k|            (PORT_Memcmp(pubAttribute->attrib.pValue, lowPubValue->data,
  ------------------
  |  |  179|  29.0k|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (5395:13): [True: 0, False: 29.0k]
  ------------------
 5396|  29.0k|                         lowPubValue->len) != 0)) {
 5397|      0|            if (pubAttribute)
  ------------------
  |  Branch (5397:17): [True: 0, False: 0]
  ------------------
 5398|      0|                sftk_FreeAttribute(pubAttribute);
 5399|      0|            if (lowPubValue)
  ------------------
  |  Branch (5399:17): [True: 0, False: 0]
  ------------------
 5400|      0|                SECITEM_ZfreeItem(lowPubValue, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                              SECITEM_ZfreeItem(lowPubValue, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5401|      0|            PORT_SetError(SEC_ERROR_BAD_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5402|      0|            return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
 5403|      0|        }
 5404|  29.0k|        SECITEM_ZfreeItem(lowPubValue, PR_TRUE);
  ------------------
  |  |  110|  29.0k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(lowPubValue, PR_TRUE);
  ------------------
  |  |  437|  29.0k|#define PR_TRUE 1
  ------------------
 5405|       |
 5406|       |        /* FIPS requires full validation, but in fipx mode NSC_Derive
 5407|       |         * only does partial validation with approved primes, now handle
 5408|       |         * full validation */
 5409|  29.0k|        if (isFIPS && keyType == CKK_DH) {
  ------------------
  |  |  374|      0|#define CKK_DH 0x00000002UL
  ------------------
  |  Branch (5409:13): [True: 0, False: 29.0k]
  |  Branch (5409:23): [True: 0, False: 0]
  ------------------
 5410|      0|            SECItem pubKey = { siBuffer, pubAttribute->attrib.pValue,
 5411|      0|                               pubAttribute->attrib.ulValueLen };
 5412|      0|            SECItem base = { siBuffer, NULL, 0 };
 5413|      0|            SECItem prime = { siBuffer, NULL, 0 };
 5414|      0|            SECItem subPrime = { siBuffer, NULL, 0 };
 5415|      0|            SECItem generator = { siBuffer, NULL, 0 };
 5416|      0|            const SECItem *subPrimePtr = &subPrime;
 5417|       |
 5418|      0|            crv = sftk_Attribute2SecItem(NULL, &prime, privateKey, CKA_PRIME);
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
 5419|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5419:17): [True: 0, False: 0]
  ------------------
 5420|      0|                goto done;
 5421|      0|            }
 5422|      0|            crv = sftk_Attribute2SecItem(NULL, &base, privateKey, CKA_BASE);
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
 5423|      0|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5423:17): [True: 0, False: 0]
  ------------------
 5424|      0|                goto done;
 5425|      0|            }
 5426|       |            /* we ignore the return code an only look at the length */
 5427|       |            /* do we have a known prime ? */
 5428|      0|            subPrimePtr = sftk_VerifyDH_Prime(&prime, &generator, isFIPS);
 5429|      0|            if (subPrimePtr == NULL) {
  ------------------
  |  Branch (5429:17): [True: 0, False: 0]
  ------------------
 5430|      0|                if (subPrime.len == 0) {
  ------------------
  |  Branch (5430:21): [True: 0, False: 0]
  ------------------
 5431|       |                    /* if not a known prime, subprime must be supplied */
 5432|      0|                    crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5433|      0|                    goto done;
 5434|      0|                } else {
 5435|       |                    /* not a known prime, check for primality of prime
 5436|       |                     * and subPrime */
 5437|      0|                    if (!KEA_PrimeCheck(&prime)) {
  ------------------
  |  Branch (5437:25): [True: 0, False: 0]
  ------------------
 5438|      0|                        crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5439|      0|                        goto done;
 5440|      0|                    }
 5441|      0|                    if (!KEA_PrimeCheck(&subPrime)) {
  ------------------
  |  Branch (5441:25): [True: 0, False: 0]
  ------------------
 5442|      0|                        crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5443|      0|                        goto done;
 5444|      0|                    }
 5445|       |                    /* if we aren't using a defined group, make sure base is in the
 5446|       |                     * subgroup. If it's not, then our key could fail or succeed sometimes.
 5447|       |                     * This makes the failure reliable */
 5448|      0|                    if (!KEA_Verify(&base, &prime, &subPrime)) {
  ------------------
  |  Branch (5448:25): [True: 0, False: 0]
  ------------------
 5449|      0|                        crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5450|      0|                    }
 5451|      0|                }
 5452|      0|                subPrimePtr = &subPrime;
 5453|      0|            } else {
 5454|       |                /* we're using a known group, make sure we are using the known generator for that group */
 5455|      0|                if (SECITEM_CompareItem(&generator, &base) != 0) {
  ------------------
  |  |  105|      0|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (5455:21): [True: 0, False: 0]
  ------------------
 5456|      0|                    crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5457|      0|                    goto done;
 5458|      0|                }
 5459|      0|                if (subPrime.len != 0) {
  ------------------
  |  Branch (5459:21): [True: 0, False: 0]
  ------------------
 5460|       |                    /* we have a known prime and a supplied subPrime,
 5461|       |                     * make sure the subPrime matches the subPrime for
 5462|       |                     * the known Prime */
 5463|      0|                    if (SECITEM_CompareItem(subPrimePtr, &subPrime) != 0) {
  ------------------
  |  |  105|      0|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (5463:25): [True: 0, False: 0]
  ------------------
 5464|      0|                        crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5465|      0|                        goto done;
 5466|      0|                    }
 5467|      0|                }
 5468|      0|            }
 5469|      0|            if (!KEA_Verify(&pubKey, &prime, (SECItem *)subPrimePtr)) {
  ------------------
  |  Branch (5469:17): [True: 0, False: 0]
  ------------------
 5470|      0|                crv = CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
 5471|      0|            }
 5472|      0|        done:
 5473|      0|            SECITEM_ZfreeItem(&base, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&base, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5474|      0|            SECITEM_ZfreeItem(&subPrime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&subPrime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5475|      0|            SECITEM_ZfreeItem(&prime, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&prime, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5476|      0|        }
 5477|       |        /* clean up before we return */
 5478|  29.0k|        sftk_FreeAttribute(pubAttribute);
 5479|  29.0k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (5479:13): [True: 0, False: 29.0k]
  ------------------
 5480|      0|            return crv;
 5481|      0|        }
 5482|  29.0k|    }
 5483|       |
 5484|  29.0k|    return CKR_OK;
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
 5485|  29.0k|}
pkcs11c.c:sftk_mapWrap:
 6369|  45.1k|{
 6370|  45.1k|    switch (crv) {
  ------------------
  |  Branch (6370:13): [True: 45.1k, False: 0]
  ------------------
 6371|      0|        case CKR_ENCRYPTED_DATA_INVALID:
  ------------------
  |  | 1419|      0|#define CKR_ENCRYPTED_DATA_INVALID 0x00000040UL
  ------------------
  |  Branch (6371:9): [True: 0, False: 45.1k]
  ------------------
 6372|      0|            crv = CKR_WRAPPED_KEY_INVALID;
  ------------------
  |  | 1497|      0|#define CKR_WRAPPED_KEY_INVALID 0x00000110UL
  ------------------
 6373|      0|            break;
 6374|  45.1k|    }
 6375|  45.1k|    return crv;
 6376|  45.1k|}
pkcs11c.c:sftk_DeriveSensitiveCheck:
 7041|   902k|{
 7042|   902k|    PRBool hasSensitive;
 7043|   902k|    PRBool sensitive = PR_FALSE;
  ------------------
  |  |  438|   902k|#define PR_FALSE 0
  ------------------
 7044|   902k|    CK_BBOOL bFalse = CK_FALSE;
  ------------------
  |  |   23|   902k|#define CK_FALSE 0
  ------------------
 7045|   902k|    PRBool hasExtractable;
 7046|   902k|    PRBool extractable = PR_TRUE;
  ------------------
  |  |  437|   902k|#define PR_TRUE 1
  ------------------
 7047|   902k|    CK_BBOOL bTrue = CK_TRUE;
  ------------------
  |  |   22|   902k|#define CK_TRUE 1
  ------------------
 7048|   902k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   902k|#define CKR_OK 0x00000000UL
  ------------------
 7049|   902k|    SFTKAttribute *att;
 7050|   902k|    PRBool isData = PR_TRUE;
  ------------------
  |  |  437|   902k|#define PR_TRUE 1
  ------------------
 7051|       |
 7052|   902k|    if (canBeData) {
  ------------------
  |  Branch (7052:9): [True: 846k, False: 55.9k]
  ------------------
 7053|   846k|        CK_OBJECT_CLASS objClass;
 7054|       |
 7055|       |        /* if the target key is actually data, don't set the unexpected
 7056|       |         * attributes */
 7057|   846k|        crv = sftk_GetULongAttribute(destKey, CKA_CLASS, &objClass);
  ------------------
  |  |  511|   846k|#define CKA_CLASS 0x00000000UL
  ------------------
 7058|   846k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|   846k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7058:13): [True: 0, False: 846k]
  ------------------
 7059|      0|            return crv;
 7060|      0|        }
 7061|   846k|        if (objClass == CKO_DATA) {
  ------------------
  |  |  325|   846k|#define CKO_DATA 0x00000000UL
  ------------------
  |  Branch (7061:13): [True: 278k, False: 567k]
  ------------------
 7062|   278k|            return CKR_OK;
  ------------------
  |  | 1388|   278k|#define CKR_OK 0x00000000UL
  ------------------
 7063|   278k|        }
 7064|       |
 7065|       |        /* if the base key is data, it doesn't have sensitive attributes,
 7066|       |         * allow the destKey to get it's own */
 7067|   567k|        crv = sftk_GetULongAttribute(baseKey, CKA_CLASS, &objClass);
  ------------------
  |  |  511|   567k|#define CKA_CLASS 0x00000000UL
  ------------------
 7068|   567k|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|   567k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7068:13): [True: 0, False: 567k]
  ------------------
 7069|      0|            return crv;
 7070|      0|        }
 7071|   567k|        if (objClass == CKO_DATA) {
  ------------------
  |  |  325|   567k|#define CKO_DATA 0x00000000UL
  ------------------
  |  Branch (7071:13): [True: 2.44k, False: 565k]
  ------------------
 7072|  2.44k|            isData = PR_TRUE;
  ------------------
  |  |  437|  2.44k|#define PR_TRUE 1
  ------------------
 7073|  2.44k|        }
 7074|   567k|    }
 7075|       |
 7076|   623k|    hasSensitive = PR_FALSE;
  ------------------
  |  |  438|   623k|#define PR_FALSE 0
  ------------------
 7077|   623k|    att = sftk_FindAttribute(destKey, CKA_SENSITIVE);
  ------------------
  |  |  546|   623k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 7078|   623k|    if (att) {
  ------------------
  |  Branch (7078:9): [True: 0, False: 623k]
  ------------------
 7079|      0|        hasSensitive = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 7080|      0|        sensitive = (PRBool) * (CK_BBOOL *)att->attrib.pValue;
 7081|      0|        sftk_FreeAttribute(att);
 7082|      0|    }
 7083|       |
 7084|   623k|    hasExtractable = PR_FALSE;
  ------------------
  |  |  438|   623k|#define PR_FALSE 0
  ------------------
 7085|   623k|    att = sftk_FindAttribute(destKey, CKA_EXTRACTABLE);
  ------------------
  |  |  585|   623k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 7086|   623k|    if (att) {
  ------------------
  |  Branch (7086:9): [True: 0, False: 623k]
  ------------------
 7087|      0|        hasExtractable = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 7088|      0|        extractable = (PRBool) * (CK_BBOOL *)att->attrib.pValue;
 7089|      0|        sftk_FreeAttribute(att);
 7090|      0|    }
 7091|       |
 7092|       |    /* don't make a key more accessible */
 7093|   623k|    if (sftk_isTrue(baseKey, CKA_SENSITIVE) && hasSensitive &&
  ------------------
  |  |  546|   623k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (7093:9): [True: 0, False: 623k]
  |  Branch (7093:48): [True: 0, False: 0]
  ------------------
 7094|   623k|        (sensitive == PR_FALSE)) {
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (7094:9): [True: 0, False: 0]
  ------------------
 7095|      0|        return CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7096|      0|    }
 7097|   623k|    if (!sftk_isTrue(baseKey, CKA_EXTRACTABLE) && hasExtractable &&
  ------------------
  |  |  585|   623k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  |  Branch (7097:9): [True: 2.44k, False: 621k]
  |  Branch (7097:51): [True: 0, False: 2.44k]
  ------------------
 7098|   623k|        (extractable == PR_TRUE)) {
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  |  Branch (7098:9): [True: 0, False: 0]
  ------------------
 7099|      0|        return CKR_KEY_FUNCTION_NOT_PERMITTED;
  ------------------
  |  | 1443|      0|#define CKR_KEY_FUNCTION_NOT_PERMITTED 0x00000068UL
  ------------------
 7100|      0|    }
 7101|       |
 7102|       |    /* inherit parent's sensitivity */
 7103|   623k|    if (!hasSensitive) {
  ------------------
  |  Branch (7103:9): [True: 623k, False: 0]
  ------------------
 7104|   623k|        att = sftk_FindAttribute(baseKey, CKA_SENSITIVE);
  ------------------
  |  |  546|   623k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 7105|   623k|        if (att != NULL) {
  ------------------
  |  Branch (7105:13): [True: 621k, False: 2.44k]
  ------------------
 7106|   621k|            crv = sftk_defaultAttribute(destKey,
 7107|   621k|                                        sftk_attr_expand(&att->attrib));
  ------------------
  |  |  587|   621k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 7108|   621k|            sftk_FreeAttribute(att);
 7109|   621k|        } else if (isData) {
  ------------------
  |  Branch (7109:20): [True: 2.44k, False: 0]
  ------------------
 7110|  2.44k|            crv = sftk_defaultAttribute(destKey, CKA_SENSITIVE,
  ------------------
  |  |  546|  2.44k|#define CKA_SENSITIVE 0x00000103UL
  ------------------
 7111|  2.44k|                                        &bFalse, sizeof(bFalse));
 7112|  2.44k|        } else {
 7113|      0|            return CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 7114|      0|        }
 7115|   623k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   623k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7115:13): [True: 0, False: 623k]
  ------------------
 7116|      0|            return crv;
 7117|   623k|    }
 7118|   623k|    if (!hasExtractable) {
  ------------------
  |  Branch (7118:9): [True: 623k, False: 0]
  ------------------
 7119|   623k|        att = sftk_FindAttribute(baseKey, CKA_EXTRACTABLE);
  ------------------
  |  |  585|   623k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 7120|   623k|        if (att != NULL) {
  ------------------
  |  Branch (7120:13): [True: 621k, False: 2.44k]
  ------------------
 7121|   621k|            crv = sftk_defaultAttribute(destKey,
 7122|   621k|                                        sftk_attr_expand(&att->attrib));
  ------------------
  |  |  587|   621k|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 7123|   621k|            sftk_FreeAttribute(att);
 7124|   621k|        } else if (isData) {
  ------------------
  |  Branch (7124:20): [True: 2.44k, False: 0]
  ------------------
 7125|  2.44k|            crv = sftk_defaultAttribute(destKey, CKA_EXTRACTABLE,
  ------------------
  |  |  585|  2.44k|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
 7126|  2.44k|                                        &bTrue, sizeof(bTrue));
 7127|  2.44k|        } else {
 7128|      0|            return CKR_KEY_TYPE_INCONSISTENT;
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
 7129|      0|        }
 7130|   623k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   623k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (7130:13): [True: 0, False: 623k]
  ------------------
 7131|      0|            return crv;
 7132|   623k|    }
 7133|       |
 7134|       |    /* we should inherit the parent's always extractable/ never sensitive info,
 7135|       |     * but handleObject always forces this attributes, so we would need to do
 7136|       |     * something special. */
 7137|   623k|    return CKR_OK;
  ------------------
  |  | 1388|   623k|#define CKR_OK 0x00000000UL
  ------------------
 7138|   623k|}
pkcs11c.c:sftk_buildSSLKey:
 6945|   210k|{
 6946|   210k|    SFTKObject *key;
 6947|   210k|    SFTKSession *session;
 6948|   210k|    CK_KEY_TYPE keyType = CKK_GENERIC_SECRET;
  ------------------
  |  |  383|   210k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
 6949|   210k|    CK_BBOOL cktrue = CK_TRUE;
  ------------------
  |  |   22|   210k|#define CK_TRUE 1
  ------------------
 6950|   210k|    CK_BBOOL ckfalse = CK_FALSE;
  ------------------
  |  |   23|   210k|#define CK_FALSE 0
  ------------------
 6951|   210k|    CK_RV crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|   210k|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 6952|       |
 6953|       |    /*
 6954|       |     * now lets create an object to hang the attributes off of
 6955|       |     */
 6956|   210k|    *keyHandle = CK_INVALID_HANDLE;
  ------------------
  |  |   78|   210k|#define CK_INVALID_HANDLE 0
  ------------------
 6957|   210k|    key = sftk_NewObject(baseKey->slot);
 6958|   210k|    if (key == NULL)
  ------------------
  |  Branch (6958:9): [True: 0, False: 210k]
  ------------------
 6959|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 6960|   210k|    sftk_narrowToSessionObject(key)->wasDerived = PR_TRUE;
  ------------------
  |  |  437|   210k|#define PR_TRUE 1
  ------------------
 6961|       |
 6962|   210k|    crv = sftk_CopyObject(key, baseKey);
 6963|   210k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   210k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6963:9): [True: 0, False: 210k]
  ------------------
 6964|      0|        goto loser;
 6965|   210k|    if (isMacKey) {
  ------------------
  |  Branch (6965:9): [True: 111k, False: 98.8k]
  ------------------
 6966|   111k|        crv = sftk_forceAttribute(key, CKA_KEY_TYPE, &keyType, sizeof(keyType));
  ------------------
  |  |  543|   111k|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
 6967|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6967:13): [True: 0, False: 111k]
  ------------------
 6968|      0|            goto loser;
 6969|   111k|        crv = sftk_forceAttribute(key, CKA_DERIVE, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  555|   111k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 6970|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6970:13): [True: 0, False: 111k]
  ------------------
 6971|      0|            goto loser;
 6972|   111k|        crv = sftk_forceAttribute(key, CKA_ENCRYPT, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  547|   111k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 6973|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6973:13): [True: 0, False: 111k]
  ------------------
 6974|      0|            goto loser;
 6975|   111k|        crv = sftk_forceAttribute(key, CKA_DECRYPT, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  548|   111k|#define CKA_DECRYPT 0x00000105UL
  ------------------
 6976|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6976:13): [True: 0, False: 111k]
  ------------------
 6977|      0|            goto loser;
 6978|   111k|        crv = sftk_forceAttribute(key, CKA_SIGN, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  551|   111k|#define CKA_SIGN 0x00000108UL
  ------------------
 6979|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6979:13): [True: 0, False: 111k]
  ------------------
 6980|      0|            goto loser;
 6981|   111k|        crv = sftk_forceAttribute(key, CKA_VERIFY, &cktrue, sizeof(CK_BBOOL));
  ------------------
  |  |  553|   111k|#define CKA_VERIFY 0x0000010AUL
  ------------------
 6982|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6982:13): [True: 0, False: 111k]
  ------------------
 6983|      0|            goto loser;
 6984|   111k|        crv = sftk_forceAttribute(key, CKA_WRAP, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  549|   111k|#define CKA_WRAP 0x00000106UL
  ------------------
 6985|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6985:13): [True: 0, False: 111k]
  ------------------
 6986|      0|            goto loser;
 6987|   111k|        crv = sftk_forceAttribute(key, CKA_UNWRAP, &ckfalse, sizeof(CK_BBOOL));
  ------------------
  |  |  550|   111k|#define CKA_UNWRAP 0x00000107UL
  ------------------
 6988|   111k|        if (crv != CKR_OK)
  ------------------
  |  | 1388|   111k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6988:13): [True: 0, False: 111k]
  ------------------
 6989|      0|            goto loser;
 6990|   111k|    }
 6991|   210k|    crv = sftk_forceAttribute(key, CKA_VALUE, keyBlock, keySize);
  ------------------
  |  |  516|   210k|#define CKA_VALUE 0x00000011UL
  ------------------
 6992|   210k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   210k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (6992:9): [True: 0, False: 210k]
  ------------------
 6993|      0|        goto loser;
 6994|       |
 6995|       |    /* get the session */
 6996|   210k|    crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|   210k|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 6997|   210k|    session = sftk_SessionFromHandle(hSession);
 6998|   210k|    if (session == NULL) {
  ------------------
  |  Branch (6998:9): [True: 0, False: 210k]
  ------------------
 6999|      0|        goto loser;
 7000|      0|    }
 7001|       |
 7002|   210k|    crv = sftk_handleObject(key, session);
 7003|   210k|    sftk_FreeSession(session);
 7004|   210k|    *keyHandle = key->handle;
 7005|   210k|loser:
 7006|   210k|    if (key)
  ------------------
  |  Branch (7006:9): [True: 210k, False: 0]
  ------------------
 7007|   210k|        sftk_FreeObject(key);
 7008|   210k|    return crv;
 7009|   210k|}

sftk_MapCryptError:
   40|  25.8k|{
   41|  25.8k|    switch (error) {
  ------------------
  |  Branch (41:13): [True: 0, False: 25.8k]
  ------------------
   42|  22.4k|        case SEC_ERROR_INVALID_ARGS:
  ------------------
  |  Branch (42:9): [True: 22.4k, False: 3.42k]
  ------------------
   43|  22.4k|        case SEC_ERROR_BAD_DATA: /* MP_RANGE gets mapped to this */
  ------------------
  |  Branch (43:9): [True: 0, False: 25.8k]
  ------------------
   44|  22.4k|            return CKR_ARGUMENTS_BAD;
  ------------------
  |  | 1401|  22.4k|#define CKR_ARGUMENTS_BAD 0x00000007UL
  ------------------
   45|      0|        case SEC_ERROR_INPUT_LEN:
  ------------------
  |  Branch (45:9): [True: 0, False: 25.8k]
  ------------------
   46|      0|            return CKR_DATA_LEN_RANGE;
  ------------------
  |  | 1415|      0|#define CKR_DATA_LEN_RANGE 0x00000021UL
  ------------------
   47|      0|        case SEC_ERROR_OUTPUT_LEN:
  ------------------
  |  Branch (47:9): [True: 0, False: 25.8k]
  ------------------
   48|      0|            return CKR_BUFFER_TOO_SMALL;
  ------------------
  |  | 1514|      0|#define CKR_BUFFER_TOO_SMALL 0x00000150UL
  ------------------
   49|      0|        case SEC_ERROR_LIBRARY_FAILURE:
  ------------------
  |  Branch (49:9): [True: 0, False: 25.8k]
  ------------------
   50|      0|            return CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
   51|      0|        case SEC_ERROR_NO_MEMORY:
  ------------------
  |  Branch (51:9): [True: 0, False: 25.8k]
  ------------------
   52|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
   53|  3.00k|        case SEC_ERROR_BAD_SIGNATURE:
  ------------------
  |  Branch (53:9): [True: 3.00k, False: 22.8k]
  ------------------
   54|  3.00k|            return CKR_SIGNATURE_INVALID;
  ------------------
  |  | 1475|  3.00k|#define CKR_SIGNATURE_INVALID 0x000000C0UL
  ------------------
   55|      0|        case SEC_ERROR_INVALID_KEY:
  ------------------
  |  Branch (55:9): [True: 0, False: 25.8k]
  ------------------
   56|      0|            return CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
   57|    375|        case SEC_ERROR_BAD_KEY:        /* an EC public key that fails validation */
  ------------------
  |  Branch (57:9): [True: 375, False: 25.4k]
  ------------------
   58|    375|            return CKR_KEY_SIZE_RANGE; /* the closest error code */
  ------------------
  |  | 1432|    375|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
   59|      0|        case SEC_ERROR_UNSUPPORTED_EC_POINT_FORM:
  ------------------
  |  Branch (59:9): [True: 0, False: 25.8k]
  ------------------
   60|      0|            return CKR_TEMPLATE_INCONSISTENT;
  ------------------
  |  | 1478|      0|#define CKR_TEMPLATE_INCONSISTENT 0x000000D1UL
  ------------------
   61|      0|        case SEC_ERROR_UNSUPPORTED_KEYALG:
  ------------------
  |  Branch (61:9): [True: 0, False: 25.8k]
  ------------------
   62|      0|            return CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
   63|     44|        case SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE:
  ------------------
  |  Branch (63:9): [True: 44, False: 25.7k]
  ------------------
   64|     44|            return CKR_DOMAIN_PARAMS_INVALID;
  ------------------
  |  | 1508|     44|#define CKR_DOMAIN_PARAMS_INVALID 0x00000130UL
  ------------------
   65|       |        /* key pair generation failed after max number of attempts */
   66|      0|        case SEC_ERROR_NEED_RANDOM:
  ------------------
  |  Branch (66:9): [True: 0, False: 25.8k]
  ------------------
   67|      0|            return CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
   68|  25.8k|    }
   69|      0|    return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
   70|  25.8k|}
sftk_MapDecryptError:
   80|  22.4k|{
   81|  22.4k|    switch (error) {
   82|       |        /* usually a padding error, or aead tag mismatch */
   83|      0|        case SEC_ERROR_BAD_DATA:
  ------------------
  |  Branch (83:9): [True: 0, False: 22.4k]
  ------------------
   84|      0|            return CKR_ENCRYPTED_DATA_INVALID;
  ------------------
  |  | 1419|      0|#define CKR_ENCRYPTED_DATA_INVALID 0x00000040UL
  ------------------
   85|  22.4k|        default:
  ------------------
  |  Branch (85:9): [True: 22.4k, False: 0]
  ------------------
   86|  22.4k|            return sftk_MapCryptError(error);
   87|  22.4k|    }
   88|  22.4k|}
sftk_MapVerifyError:
   96|  2.94k|{
   97|  2.94k|    CK_RV crv = sftk_MapCryptError(error);
   98|  2.94k|    if (crv == CKR_DEVICE_ERROR)
  ------------------
  |  | 1416|  2.94k|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  |  Branch (98:9): [True: 0, False: 2.94k]
  ------------------
   99|      0|        crv = CKR_SIGNATURE_INVALID;
  ------------------
  |  | 1475|      0|#define CKR_SIGNATURE_INVALID 0x000000C0UL
  ------------------
  100|  2.94k|    return crv;
  101|  2.94k|}
sftk_FreeAttribute:
  191|  18.7M|{
  192|  18.7M|    if (attribute && attribute->freeAttr) {
  ------------------
  |  Branch (192:9): [True: 18.7M, False: 0]
  |  Branch (192:22): [True: 0, False: 18.7M]
  ------------------
  193|      0|        sftk_DestroyAttribute(attribute);
  194|      0|        return;
  195|      0|    }
  196|  18.7M|}
sftk_FindAttribute:
  261|  25.6M|{
  262|  25.6M|    SFTKAttribute *attribute;
  263|  25.6M|    SFTKSessionObject *sessObject = sftk_narrowToSessionObject(object);
  264|       |
  265|  25.6M|    if (sessObject == NULL) {
  ------------------
  |  Branch (265:9): [True: 0, False: 25.6M]
  ------------------
  266|      0|        return sftk_FindTokenAttribute(sftk_narrowToTokenObject(object), type);
  267|      0|    }
  268|       |
  269|  25.6M|    PZ_Lock(sessObject->attributeLock);
  ------------------
  |  |  245|  25.6M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  270|  25.6M|    sftkqueue_find(attribute, type, sessObject->head, sessObject->hashSize);
  ------------------
  |  |  524|  43.7M|    for ((element) = (head)[sftk_hash(id, hash_size)]; (element) != NULL; \
  |  |  ------------------
  |  |  |  |  513|  25.6M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|  25.6M|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (524:56): [True: 37.1M, False: 6.57M]
  |  |  ------------------
  |  |  525|  37.1M|         (element) = (element)->next) {                                   \
  |  |  526|  37.1M|        if ((element)->handle == (id)) {                                  \
  |  |  ------------------
  |  |  |  Branch (526:13): [True: 19.0M, False: 18.1M]
  |  |  ------------------
  |  |  527|  19.0M|            break;                                                        \
  |  |  528|  19.0M|        }                                                                 \
  |  |  529|  37.1M|    }
  ------------------
  271|  25.6M|    PZ_Unlock(sessObject->attributeLock);
  ------------------
  |  |  246|  25.6M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  272|       |
  273|  25.6M|    return (attribute);
  274|  25.6M|}
sftk_GetLengthInBits:
  281|   151k|{
  282|   151k|    unsigned int size = bufLen * 8;
  283|   151k|    unsigned int i;
  284|       |
  285|       |    /* Get the real length in bytes */
  286|   151k|    for (i = 0; i < bufLen; i++) {
  ------------------
  |  Branch (286:17): [True: 151k, False: 0]
  ------------------
  287|   151k|        unsigned char c = *buf++;
  288|   151k|        if (c != 0) {
  ------------------
  |  Branch (288:13): [True: 151k, False: 0]
  ------------------
  289|   151k|            unsigned char m;
  290|   538k|            for (m = 0x80; m > 0; m = m >> 1) {
  ------------------
  |  Branch (290:28): [True: 538k, False: 0]
  ------------------
  291|   538k|                if ((c & m) != 0) {
  ------------------
  |  Branch (291:21): [True: 151k, False: 387k]
  ------------------
  292|   151k|                    break;
  293|   151k|                }
  294|   387k|                size--;
  295|   387k|            }
  296|   151k|            break;
  297|   151k|        }
  298|      0|        size -= 8;
  299|      0|    }
  300|   151k|    return size;
  301|   151k|}
sftk_ConstrainAttribute:
  314|  93.2k|{
  315|  93.2k|    SFTKAttribute *attribute;
  316|  93.2k|    int size;
  317|  93.2k|    unsigned char *ptr;
  318|       |
  319|  93.2k|    attribute = sftk_FindAttribute(object, type);
  320|  93.2k|    if (!attribute) {
  ------------------
  |  Branch (320:9): [True: 0, False: 93.2k]
  ------------------
  321|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
  322|      0|    }
  323|  93.2k|    ptr = (unsigned char *)attribute->attrib.pValue;
  324|  93.2k|    if (ptr == NULL) {
  ------------------
  |  Branch (324:9): [True: 0, False: 93.2k]
  ------------------
  325|      0|        sftk_FreeAttribute(attribute);
  326|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  327|      0|    }
  328|  93.2k|    size = sftk_GetLengthInBits(ptr, attribute->attrib.ulValueLen);
  329|  93.2k|    sftk_FreeAttribute(attribute);
  330|       |
  331|  93.2k|    if ((minLength != 0) && (size < minLength)) {
  ------------------
  |  Branch (331:9): [True: 93.2k, False: 0]
  |  Branch (331:29): [True: 0, False: 93.2k]
  ------------------
  332|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  333|      0|    }
  334|  93.2k|    if ((maxLength != 0) && (size > maxLength)) {
  ------------------
  |  Branch (334:9): [True: 87.2k, False: 6.02k]
  |  Branch (334:29): [True: 0, False: 87.2k]
  ------------------
  335|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  336|      0|    }
  337|  93.2k|    if ((minMultiple != 0) && ((size % minMultiple) != 0)) {
  ------------------
  |  Branch (337:9): [True: 0, False: 93.2k]
  |  Branch (337:31): [True: 0, False: 0]
  ------------------
  338|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  339|      0|    }
  340|  93.2k|    return CKR_OK;
  ------------------
  |  | 1388|  93.2k|#define CKR_OK 0x00000000UL
  ------------------
  341|  93.2k|}
sftk_hasAttribute:
  367|  22.3M|{
  368|  22.3M|    SFTKAttribute *attribute;
  369|  22.3M|    SFTKSessionObject *sessObject = sftk_narrowToSessionObject(object);
  370|       |
  371|  22.3M|    if (sessObject == NULL) {
  ------------------
  |  Branch (371:9): [True: 0, False: 22.3M]
  ------------------
  372|      0|        return sftk_hasAttributeToken(sftk_narrowToTokenObject(object), type);
  373|      0|    }
  374|       |
  375|  22.3M|    PZ_Lock(sessObject->attributeLock);
  ------------------
  |  |  245|  22.3M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  376|  22.3M|    sftkqueue_find(attribute, type, sessObject->head, sessObject->hashSize);
  ------------------
  |  |  524|  36.5M|    for ((element) = (head)[sftk_hash(id, hash_size)]; (element) != NULL; \
  |  |  ------------------
  |  |  |  |  513|  22.3M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|  22.3M|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (524:56): [True: 20.8M, False: 15.6M]
  |  |  ------------------
  |  |  525|  22.3M|         (element) = (element)->next) {                                   \
  |  |  526|  20.8M|        if ((element)->handle == (id)) {                                  \
  |  |  ------------------
  |  |  |  Branch (526:13): [True: 6.62M, False: 14.2M]
  |  |  ------------------
  |  |  527|  6.62M|            break;                                                        \
  |  |  528|  6.62M|        }                                                                 \
  |  |  529|  20.8M|    }
  ------------------
  377|  22.3M|    PZ_Unlock(sessObject->attributeLock);
  ------------------
  |  |  246|  22.3M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  378|       |
  379|  22.3M|    return (PRBool)(attribute != NULL);
  380|  22.3M|}
sftk_Attribute2SSecItem:
  405|   261k|{
  406|   261k|    SFTKAttribute *attribute;
  407|       |
  408|   261k|    item->data = NULL;
  409|       |
  410|   261k|    attribute = sftk_FindAttribute(object, type);
  411|   261k|    if (attribute == NULL)
  ------------------
  |  Branch (411:9): [True: 0, False: 261k]
  ------------------
  412|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
  413|       |
  414|   261k|    (void)SECITEM_AllocItem(arena, item, attribute->attrib.ulValueLen);
  ------------------
  |  |  103|   261k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  415|   261k|    if (item->data == NULL) {
  ------------------
  |  Branch (415:9): [True: 0, False: 261k]
  ------------------
  416|      0|        sftk_FreeAttribute(attribute);
  417|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  418|      0|    }
  419|   261k|    PORT_Memcpy(item->data, attribute->attrib.pValue, item->len);
  ------------------
  |  |  180|   261k|#define PORT_Memcpy memcpy
  ------------------
  420|   261k|    sftk_FreeAttribute(attribute);
  421|   261k|    return CKR_OK;
  ------------------
  |  | 1388|   261k|#define CKR_OK 0x00000000UL
  ------------------
  422|   261k|}
sftk_MultipleAttribute2SecItem:
  431|  29.0k|{
  432|       |
  433|  29.0k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  434|  29.0k|    CK_ATTRIBUTE templateSpace[SFTK_MAX_ITEM_TEMPLATE];
  435|  29.0k|    CK_ATTRIBUTE *template;
  436|  29.0k|    SFTKTokenObject *tokObject;
  437|  29.0k|    SFTKDBHandle *dbHandle = NULL;
  438|  29.0k|    int i;
  439|       |
  440|  29.0k|    tokObject = sftk_narrowToTokenObject(object);
  441|       |
  442|       |    /* session objects, just loop through the list */
  443|  29.0k|    if (tokObject == NULL) {
  ------------------
  |  Branch (443:9): [True: 29.0k, False: 0]
  ------------------
  444|   116k|        for (i = 0; i < itemTemplateCount; i++) {
  ------------------
  |  Branch (444:21): [True: 87.2k, False: 29.0k]
  ------------------
  445|  87.2k|            crv = sftk_Attribute2SecItem(arena, itemTemplate[i].item, object,
  446|  87.2k|                                         itemTemplate[i].type);
  447|  87.2k|            if (crv != CKR_OK) {
  ------------------
  |  | 1388|  87.2k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (447:17): [True: 0, False: 87.2k]
  ------------------
  448|      0|                return crv;
  449|      0|            }
  450|  87.2k|        }
  451|  29.0k|        return CKR_OK;
  ------------------
  |  | 1388|  29.0k|#define CKR_OK 0x00000000UL
  ------------------
  452|  29.0k|    }
  453|       |
  454|       |    /* don't do any work if none is required */
  455|      0|    if (itemTemplateCount == 0) {
  ------------------
  |  Branch (455:9): [True: 0, False: 0]
  ------------------
  456|      0|        return CKR_OK;
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  457|      0|    }
  458|       |
  459|       |    /* don't allocate the template unless we need it */
  460|      0|    if (itemTemplateCount > SFTK_MAX_ITEM_TEMPLATE) {
  ------------------
  |  |  468|      0|#define SFTK_MAX_ITEM_TEMPLATE 10
  ------------------
  |  Branch (460:9): [True: 0, False: 0]
  ------------------
  461|      0|        template = PORT_NewArray(CK_ATTRIBUTE, itemTemplateCount);
  ------------------
  |  |  157|      0|    (type *)PORT_Alloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  462|      0|    } else {
  463|      0|        template = templateSpace;
  464|      0|    }
  465|       |
  466|      0|    if (template == NULL) {
  ------------------
  |  Branch (466:9): [True: 0, False: 0]
  ------------------
  467|      0|        crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  468|      0|        goto loser;
  469|      0|    }
  470|       |
  471|      0|    dbHandle = sftk_getDBForTokenObject(object->slot, object->handle);
  472|      0|    if (dbHandle == NULL) {
  ------------------
  |  Branch (472:9): [True: 0, False: 0]
  ------------------
  473|      0|        crv = CKR_OBJECT_HANDLE_INVALID;
  ------------------
  |  | 1452|      0|#define CKR_OBJECT_HANDLE_INVALID 0x00000082UL
  ------------------
  474|      0|        goto loser;
  475|      0|    }
  476|       |
  477|       |    /* set up the PKCS #11 template */
  478|      0|    for (i = 0; i < itemTemplateCount; i++) {
  ------------------
  |  Branch (478:17): [True: 0, False: 0]
  ------------------
  479|      0|        template[i].type = itemTemplate[i].type;
  480|      0|        template[i].pValue = NULL;
  481|      0|        template[i].ulValueLen = 0;
  482|      0|    }
  483|       |
  484|       |    /* fetch the attribute lengths */
  485|      0|    crv = sftkdb_GetAttributeValue(dbHandle, object->handle,
  486|      0|                                   template, itemTemplateCount);
  487|      0|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (487:9): [True: 0, False: 0]
  ------------------
  488|      0|        goto loser;
  489|      0|    }
  490|       |
  491|       |    /* allocate space for the attributes */
  492|      0|    for (i = 0; i < itemTemplateCount; i++) {
  ------------------
  |  Branch (492:17): [True: 0, False: 0]
  ------------------
  493|      0|        template[i].pValue = PORT_ArenaAlloc(arena, template[i].ulValueLen);
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  494|      0|        if (template[i].pValue == NULL) {
  ------------------
  |  Branch (494:13): [True: 0, False: 0]
  ------------------
  495|      0|            crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  496|      0|            goto loser;
  497|      0|        }
  498|      0|    }
  499|       |
  500|       |    /* fetch the attributes */
  501|      0|    crv = sftkdb_GetAttributeValue(dbHandle, object->handle,
  502|      0|                                   template, itemTemplateCount);
  503|      0|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (503:9): [True: 0, False: 0]
  ------------------
  504|      0|        goto loser;
  505|      0|    }
  506|       |
  507|       |    /* Fill in the items */
  508|      0|    for (i = 0; i < itemTemplateCount; i++) {
  ------------------
  |  Branch (508:17): [True: 0, False: 0]
  ------------------
  509|      0|        itemTemplate[i].item->data = template[i].pValue;
  510|      0|        itemTemplate[i].item->len = template[i].ulValueLen;
  511|      0|    }
  512|       |
  513|      0|loser:
  514|      0|    if (template != templateSpace) {
  ------------------
  |  Branch (514:9): [True: 0, False: 0]
  ------------------
  515|      0|        PORT_Free(template);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  516|      0|    }
  517|      0|    if (dbHandle) {
  ------------------
  |  Branch (517:9): [True: 0, False: 0]
  ------------------
  518|      0|        sftk_freeDB(dbHandle);
  519|      0|    }
  520|       |
  521|      0|    return crv;
  522|      0|}
sftk_isTrue:
  550|  7.48M|{
  551|  7.48M|    SFTKAttribute *attribute;
  552|  7.48M|    PRBool tok = PR_FALSE;
  ------------------
  |  |  438|  7.48M|#define PR_FALSE 0
  ------------------
  553|       |
  554|  7.48M|    attribute = sftk_FindAttribute(object, type);
  555|  7.48M|    if (attribute == NULL) {
  ------------------
  |  Branch (555:9): [True: 896k, False: 6.58M]
  ------------------
  556|   896k|        return PR_FALSE;
  ------------------
  |  |  438|   896k|#define PR_FALSE 0
  ------------------
  557|   896k|    }
  558|  6.58M|    tok = (PRBool)(*(CK_BBOOL *)attribute->attrib.pValue);
  559|  6.58M|    sftk_FreeAttribute(attribute);
  560|       |
  561|  6.58M|    return tok;
  562|  7.48M|}
sftk_forceAttribute:
  621|  6.18M|{
  622|  6.18M|    SFTKAttribute *attribute;
  623|  6.18M|    void *att_val = NULL;
  624|  6.18M|    PRBool freeData = PR_FALSE;
  ------------------
  |  |  438|  6.18M|#define PR_FALSE 0
  ------------------
  625|       |
  626|  6.18M|    PORT_Assert(object);
  ------------------
  |  |  120|  6.18M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.18M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 6.18M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  627|  6.18M|    PORT_Assert(object->refCount);
  ------------------
  |  |  120|  6.18M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.18M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 6.18M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  628|  6.18M|    PORT_Assert(object->slot);
  ------------------
  |  |  120|  6.18M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.18M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 6.18M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  629|  6.18M|    if (!object ||
  ------------------
  |  Branch (629:9): [True: 0, False: 6.18M]
  ------------------
  630|  6.18M|        !object->refCount ||
  ------------------
  |  Branch (630:9): [True: 0, False: 6.18M]
  ------------------
  631|  6.18M|        !object->slot) {
  ------------------
  |  Branch (631:9): [True: 0, False: 6.18M]
  ------------------
  632|      0|        return CKR_DEVICE_ERROR;
  ------------------
  |  | 1416|      0|#define CKR_DEVICE_ERROR 0x00000030UL
  ------------------
  633|      0|    }
  634|  6.18M|    if (sftk_isToken(object->handle)) {
  ------------------
  |  |  504|  6.18M|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|  6.18M|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|  6.18M|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  |  |  |  Branch (504:26): [True: 0, False: 6.18M]
  |  |  ------------------
  ------------------
  635|      0|        return sftk_forceTokenAttribute(object, type, value, len);
  636|      0|    }
  637|  6.18M|    attribute = sftk_FindAttribute(object, type);
  638|  6.18M|    if (attribute == NULL)
  ------------------
  |  Branch (638:9): [True: 3.91M, False: 2.26M]
  ------------------
  639|  3.91M|        return sftk_AddAttributeType(object, type, value, len);
  640|       |
  641|  2.26M|    if (value) {
  ------------------
  |  Branch (641:9): [True: 2.26M, False: 0]
  ------------------
  642|  2.26M|        if (len <= ATTR_SPACE) {
  ------------------
  |  |   39|  2.26M|#define ATTR_SPACE 50     /* Maximum size of attribute data before extra \
  ------------------
  |  Branch (642:13): [True: 2.26M, False: 3]
  ------------------
  643|  2.26M|            att_val = attribute->space;
  644|  2.26M|        } else {
  645|      3|            att_val = PORT_Alloc(len);
  ------------------
  |  |   52|      3|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  646|      3|            freeData = PR_TRUE;
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
  647|      3|        }
  648|  2.26M|        if (att_val == NULL) {
  ------------------
  |  Branch (648:13): [True: 0, False: 2.26M]
  ------------------
  649|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  650|      0|        }
  651|  2.26M|        if (attribute->attrib.pValue == att_val) {
  ------------------
  |  Branch (651:13): [True: 2.21M, False: 47.3k]
  ------------------
  652|  2.21M|            PORT_Memset(attribute->attrib.pValue, 0,
  ------------------
  |  |  182|  2.21M|#define PORT_Memset memset
  ------------------
  653|  2.21M|                        attribute->attrib.ulValueLen);
  654|  2.21M|        }
  655|  2.26M|        PORT_Memcpy(att_val, value, len);
  ------------------
  |  |  180|  2.26M|#define PORT_Memcpy memcpy
  ------------------
  656|  2.26M|    }
  657|  2.26M|    if (attribute->attrib.pValue != NULL) {
  ------------------
  |  Branch (657:9): [True: 2.21M, False: 47.3k]
  ------------------
  658|  2.21M|        if (attribute->attrib.pValue != att_val) {
  ------------------
  |  Branch (658:13): [True: 3, False: 2.21M]
  ------------------
  659|      3|            PORT_Memset(attribute->attrib.pValue, 0,
  ------------------
  |  |  182|      3|#define PORT_Memset memset
  ------------------
  660|      3|                        attribute->attrib.ulValueLen);
  661|      3|        }
  662|  2.21M|        if (attribute->freeData) {
  ------------------
  |  Branch (662:13): [True: 3, False: 2.21M]
  ------------------
  663|      3|            PORT_Free(attribute->attrib.pValue);
  ------------------
  |  |   60|      3|#define PORT_Free PORT_Free_Util
  ------------------
  664|      3|        }
  665|  2.21M|        attribute->freeData = PR_FALSE;
  ------------------
  |  |  438|  2.21M|#define PR_FALSE 0
  ------------------
  666|  2.21M|        attribute->attrib.pValue = NULL;
  667|  2.21M|        attribute->attrib.ulValueLen = 0;
  668|  2.21M|    }
  669|  2.26M|    if (att_val) {
  ------------------
  |  Branch (669:9): [True: 2.26M, False: 0]
  ------------------
  670|  2.26M|        attribute->attrib.pValue = att_val;
  671|  2.26M|        attribute->attrib.ulValueLen = len;
  672|  2.26M|        attribute->freeData = freeData;
  673|  2.26M|    }
  674|  2.26M|    sftk_FreeAttribute(attribute);
  675|  2.26M|    return CKR_OK;
  ------------------
  |  | 1388|  2.26M|#define CKR_OK 0x00000000UL
  ------------------
  676|  2.26M|}
sftk_modifyType:
  721|  47.3k|{
  722|       |    /* if we don't know about it, user user defined, always allow modify */
  723|  47.3k|    SFTKModifyType mtype = SFTK_ALWAYS;
  724|       |
  725|  47.3k|    switch (type) {
  726|       |        /* NEVER */
  727|      0|        case CKA_CLASS:
  ------------------
  |  |  511|      0|#define CKA_CLASS 0x00000000UL
  ------------------
  |  Branch (727:9): [True: 0, False: 47.3k]
  ------------------
  728|      0|        case CKA_CERTIFICATE_TYPE:
  ------------------
  |  |  521|      0|#define CKA_CERTIFICATE_TYPE 0x00000080UL
  ------------------
  |  Branch (728:9): [True: 0, False: 47.3k]
  ------------------
  729|      0|        case CKA_KEY_TYPE:
  ------------------
  |  |  543|      0|#define CKA_KEY_TYPE 0x00000100UL
  ------------------
  |  Branch (729:9): [True: 0, False: 47.3k]
  ------------------
  730|      0|        case CKA_MODULUS:
  ------------------
  |  |  558|      0|#define CKA_MODULUS 0x00000120UL
  ------------------
  |  Branch (730:9): [True: 0, False: 47.3k]
  ------------------
  731|      0|        case CKA_MODULUS_BITS:
  ------------------
  |  |  559|      0|#define CKA_MODULUS_BITS 0x00000121UL
  ------------------
  |  Branch (731:9): [True: 0, False: 47.3k]
  ------------------
  732|      0|        case CKA_PUBLIC_EXPONENT:
  ------------------
  |  |  560|      0|#define CKA_PUBLIC_EXPONENT 0x00000122UL
  ------------------
  |  Branch (732:9): [True: 0, False: 47.3k]
  ------------------
  733|      0|        case CKA_PRIVATE_EXPONENT:
  ------------------
  |  |  561|      0|#define CKA_PRIVATE_EXPONENT 0x00000123UL
  ------------------
  |  Branch (733:9): [True: 0, False: 47.3k]
  ------------------
  734|      0|        case CKA_PRIME:
  ------------------
  |  |  569|      0|#define CKA_PRIME 0x00000130UL
  ------------------
  |  Branch (734:9): [True: 0, False: 47.3k]
  ------------------
  735|      0|        case CKA_BASE:
  ------------------
  |  |  571|      0|#define CKA_BASE 0x00000132UL
  ------------------
  |  Branch (735:9): [True: 0, False: 47.3k]
  ------------------
  736|      0|        case CKA_PRIME_1:
  ------------------
  |  |  562|      0|#define CKA_PRIME_1 0x00000124UL
  ------------------
  |  Branch (736:9): [True: 0, False: 47.3k]
  ------------------
  737|      0|        case CKA_PRIME_2:
  ------------------
  |  |  563|      0|#define CKA_PRIME_2 0x00000125UL
  ------------------
  |  Branch (737:9): [True: 0, False: 47.3k]
  ------------------
  738|      0|        case CKA_EXPONENT_1:
  ------------------
  |  |  564|      0|#define CKA_EXPONENT_1 0x00000126UL
  ------------------
  |  Branch (738:9): [True: 0, False: 47.3k]
  ------------------
  739|      0|        case CKA_EXPONENT_2:
  ------------------
  |  |  565|      0|#define CKA_EXPONENT_2 0x00000127UL
  ------------------
  |  Branch (739:9): [True: 0, False: 47.3k]
  ------------------
  740|      0|        case CKA_COEFFICIENT:
  ------------------
  |  |  566|      0|#define CKA_COEFFICIENT 0x00000128UL
  ------------------
  |  Branch (740:9): [True: 0, False: 47.3k]
  ------------------
  741|      0|        case CKA_VALUE_LEN:
  ------------------
  |  |  580|      0|#define CKA_VALUE_LEN 0x00000161UL
  ------------------
  |  Branch (741:9): [True: 0, False: 47.3k]
  ------------------
  742|      0|        case CKA_ALWAYS_SENSITIVE:
  ------------------
  |  |  588|      0|#define CKA_ALWAYS_SENSITIVE 0x00000165UL
  ------------------
  |  Branch (742:9): [True: 0, False: 47.3k]
  ------------------
  743|      0|        case CKA_NEVER_EXTRACTABLE:
  ------------------
  |  |  587|      0|#define CKA_NEVER_EXTRACTABLE 0x00000164UL
  ------------------
  |  Branch (743:9): [True: 0, False: 47.3k]
  ------------------
  744|      0|        case CKA_NSS_DB:
  ------------------
  |  |  150|      0|#define CKA_NSS_DB 0xD5A0DB00L
  ------------------
  |  Branch (744:9): [True: 0, False: 47.3k]
  ------------------
  745|      0|            mtype = SFTK_NEVER;
  746|      0|            break;
  747|       |
  748|       |        /* ONCOPY */
  749|      2|        case CKA_TOKEN:
  ------------------
  |  |  512|      2|#define CKA_TOKEN 0x00000001UL
  ------------------
  |  Branch (749:9): [True: 2, False: 47.3k]
  ------------------
  750|      2|        case CKA_PRIVATE:
  ------------------
  |  |  513|      2|#define CKA_PRIVATE 0x00000002UL
  ------------------
  |  Branch (750:9): [True: 0, False: 47.3k]
  ------------------
  751|      2|        case CKA_MODIFIABLE:
  ------------------
  |  |  593|      2|#define CKA_MODIFIABLE 0x00000170UL
  ------------------
  |  Branch (751:9): [True: 0, False: 47.3k]
  ------------------
  752|      2|            mtype = SFTK_ONCOPY;
  753|      2|            break;
  754|       |
  755|       |        /* SENSITIVE */
  756|      0|        case CKA_SENSITIVE:
  ------------------
  |  |  546|      0|#define CKA_SENSITIVE 0x00000103UL
  ------------------
  |  Branch (756:9): [True: 0, False: 47.3k]
  ------------------
  757|      0|        case CKA_EXTRACTABLE:
  ------------------
  |  |  585|      0|#define CKA_EXTRACTABLE 0x00000162UL
  ------------------
  |  Branch (757:9): [True: 0, False: 47.3k]
  ------------------
  758|      0|            mtype = SFTK_SENSITIVE;
  759|      0|            break;
  760|       |
  761|       |        /* ALWAYS */
  762|      0|        case CKA_LABEL:
  ------------------
  |  |  514|      0|#define CKA_LABEL 0x00000003UL
  ------------------
  |  Branch (762:9): [True: 0, False: 47.3k]
  ------------------
  763|      0|        case CKA_APPLICATION:
  ------------------
  |  |  515|      0|#define CKA_APPLICATION 0x00000010UL
  ------------------
  |  Branch (763:9): [True: 0, False: 47.3k]
  ------------------
  764|  47.3k|        case CKA_ID:
  ------------------
  |  |  545|  47.3k|#define CKA_ID 0x00000102UL
  ------------------
  |  Branch (764:9): [True: 47.3k, False: 2]
  ------------------
  765|  47.3k|        case CKA_SERIAL_NUMBER:
  ------------------
  |  |  523|  47.3k|#define CKA_SERIAL_NUMBER 0x00000082UL
  ------------------
  |  Branch (765:9): [True: 0, False: 47.3k]
  ------------------
  766|  47.3k|        case CKA_START_DATE:
  ------------------
  |  |  556|  47.3k|#define CKA_START_DATE 0x00000110UL
  ------------------
  |  Branch (766:9): [True: 0, False: 47.3k]
  ------------------
  767|  47.3k|        case CKA_END_DATE:
  ------------------
  |  |  557|  47.3k|#define CKA_END_DATE 0x00000111UL
  ------------------
  |  Branch (767:9): [True: 0, False: 47.3k]
  ------------------
  768|  47.3k|        case CKA_DERIVE:
  ------------------
  |  |  555|  47.3k|#define CKA_DERIVE 0x0000010CUL
  ------------------
  |  Branch (768:9): [True: 0, False: 47.3k]
  ------------------
  769|  47.3k|        case CKA_ENCRYPT:
  ------------------
  |  |  547|  47.3k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (769:9): [True: 0, False: 47.3k]
  ------------------
  770|  47.3k|        case CKA_DECRYPT:
  ------------------
  |  |  548|  47.3k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (770:9): [True: 0, False: 47.3k]
  ------------------
  771|  47.3k|        case CKA_SIGN:
  ------------------
  |  |  551|  47.3k|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (771:9): [True: 0, False: 47.3k]
  ------------------
  772|  47.3k|        case CKA_VERIFY:
  ------------------
  |  |  553|  47.3k|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (772:9): [True: 0, False: 47.3k]
  ------------------
  773|  47.3k|        case CKA_SIGN_RECOVER:
  ------------------
  |  |  552|  47.3k|#define CKA_SIGN_RECOVER 0x00000109UL
  ------------------
  |  Branch (773:9): [True: 0, False: 47.3k]
  ------------------
  774|  47.3k|        case CKA_VERIFY_RECOVER:
  ------------------
  |  |  554|  47.3k|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
  |  Branch (774:9): [True: 0, False: 47.3k]
  ------------------
  775|  47.3k|        case CKA_WRAP:
  ------------------
  |  |  549|  47.3k|#define CKA_WRAP 0x00000106UL
  ------------------
  |  Branch (775:9): [True: 0, False: 47.3k]
  ------------------
  776|  47.3k|        case CKA_UNWRAP:
  ------------------
  |  |  550|  47.3k|#define CKA_UNWRAP 0x00000107UL
  ------------------
  |  Branch (776:9): [True: 0, False: 47.3k]
  ------------------
  777|  47.3k|            mtype = SFTK_ALWAYS;
  778|  47.3k|            break;
  779|       |
  780|       |        /* DEPENDS ON CLASS */
  781|      0|        case CKA_VALUE:
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
  |  Branch (781:9): [True: 0, False: 47.3k]
  ------------------
  782|      0|            mtype = (inClass == CKO_DATA) ? SFTK_ALWAYS : SFTK_NEVER;
  ------------------
  |  |  325|      0|#define CKO_DATA 0x00000000UL
  ------------------
  |  Branch (782:21): [True: 0, False: 0]
  ------------------
  783|      0|            break;
  784|       |
  785|      0|        case CKA_SUBPRIME:
  ------------------
  |  |  570|      0|#define CKA_SUBPRIME 0x00000131UL
  ------------------
  |  Branch (785:9): [True: 0, False: 47.3k]
  ------------------
  786|       |            /* allow the CKA_SUBPRIME to be added to dh private keys */
  787|      0|            mtype = (inClass == CKO_PRIVATE_KEY) ? SFTK_ALWAYS : SFTK_NEVER;
  ------------------
  |  |  328|      0|#define CKO_PRIVATE_KEY 0x00000003UL
  ------------------
  |  Branch (787:21): [True: 0, False: 0]
  ------------------
  788|      0|            break;
  789|       |
  790|      0|        case CKA_SUBJECT:
  ------------------
  |  |  544|      0|#define CKA_SUBJECT 0x00000101UL
  ------------------
  |  Branch (790:9): [True: 0, False: 47.3k]
  ------------------
  791|      0|            mtype = (inClass == CKO_CERTIFICATE) ? SFTK_NEVER : SFTK_ALWAYS;
  ------------------
  |  |  326|      0|#define CKO_CERTIFICATE 0x00000001UL
  ------------------
  |  Branch (791:21): [True: 0, False: 0]
  ------------------
  792|      0|            break;
  793|      0|        default:
  ------------------
  |  Branch (793:9): [True: 0, False: 47.3k]
  ------------------
  794|      0|            break;
  795|  47.3k|    }
  796|  47.3k|    return mtype;
  797|  47.3k|}
sftk_Attribute2SecItem:
  832|   142k|{
  833|   142k|    int len;
  834|   142k|    SFTKAttribute *attribute;
  835|       |
  836|   142k|    attribute = sftk_FindAttribute(object, type);
  837|   142k|    if (attribute == NULL)
  ------------------
  |  Branch (837:9): [True: 0, False: 142k]
  ------------------
  838|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
  839|   142k|    len = attribute->attrib.ulValueLen;
  840|       |
  841|   142k|    if (arena) {
  ------------------
  |  Branch (841:9): [True: 87.2k, False: 55.4k]
  ------------------
  842|  87.2k|        item->data = (unsigned char *)PORT_ArenaAlloc(arena, len);
  ------------------
  |  |   53|  87.2k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  843|  87.2k|    } else {
  844|  55.4k|        item->data = (unsigned char *)PORT_Alloc(len);
  ------------------
  |  |   52|  55.4k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  845|  55.4k|    }
  846|   142k|    if (item->data == NULL) {
  ------------------
  |  Branch (846:9): [True: 0, False: 142k]
  ------------------
  847|      0|        sftk_FreeAttribute(attribute);
  848|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  849|      0|    }
  850|   142k|    item->len = len;
  851|   142k|    PORT_Memcpy(item->data, attribute->attrib.pValue, len);
  ------------------
  |  |  180|   142k|#define PORT_Memcpy memcpy
  ------------------
  852|   142k|    sftk_FreeAttribute(attribute);
  853|   142k|    return CKR_OK;
  ------------------
  |  | 1388|   142k|#define CKR_OK 0x00000000UL
  ------------------
  854|   142k|}
sftk_GetULongAttribute:
  859|  1.41M|{
  860|  1.41M|    SFTKAttribute *attribute;
  861|       |
  862|  1.41M|    attribute = sftk_FindAttribute(object, type);
  863|  1.41M|    if (attribute == NULL)
  ------------------
  |  Branch (863:9): [True: 0, False: 1.41M]
  ------------------
  864|      0|        return CKR_TEMPLATE_INCOMPLETE;
  ------------------
  |  | 1477|      0|#define CKR_TEMPLATE_INCOMPLETE 0x000000D0UL
  ------------------
  865|       |
  866|  1.41M|    if (attribute->attrib.ulValueLen != sizeof(CK_ULONG)) {
  ------------------
  |  Branch (866:9): [True: 0, False: 1.41M]
  ------------------
  867|      0|        return CKR_ATTRIBUTE_VALUE_INVALID;
  ------------------
  |  | 1409|      0|#define CKR_ATTRIBUTE_VALUE_INVALID 0x00000013UL
  ------------------
  868|      0|    }
  869|       |
  870|  1.41M|    *longData = *(CK_ULONG *)attribute->attrib.pValue;
  871|  1.41M|    sftk_FreeAttribute(attribute);
  872|  1.41M|    return CKR_OK;
  ------------------
  |  | 1388|  1.41M|#define CKR_OK 0x00000000UL
  ------------------
  873|  1.41M|}
sftk_DeleteAttributeType:
  877|   505k|{
  878|   505k|    SFTKAttribute *attribute;
  879|   505k|    attribute = sftk_FindAttribute(object, type);
  880|   505k|    if (attribute == NULL)
  ------------------
  |  Branch (880:9): [True: 505k, False: 0]
  ------------------
  881|   505k|        return;
  882|      0|    sftk_DeleteAttribute(object, attribute);
  883|      0|    sftk_DestroyAttribute(attribute);
  884|      0|}
sftk_AddAttributeType:
  889|  25.3M|{
  890|  25.3M|    SFTKAttribute *attribute;
  891|  25.3M|    attribute = sftk_NewAttribute(object, type, valPtr, length);
  892|  25.3M|    if (attribute == NULL) {
  ------------------
  |  Branch (892:9): [True: 0, False: 25.3M]
  ------------------
  893|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  894|      0|    }
  895|  25.3M|    sftk_AddAttribute(object, attribute);
  896|  25.3M|    return CKR_OK;
  ------------------
  |  | 1388|  25.3M|#define CKR_OK 0x00000000UL
  ------------------
  897|  25.3M|}
SFTK_ClearTokenKeyHashTable:
  938|      2|{
  939|      2|    sftk_tokenKeyLock(slot);
  940|      2|    PORT_Assert(!slot->present);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  941|      2|    PL_HashTableEnumerateEntries(slot->tokObjHashTable, sftk_freeHashItem, NULL);
  942|      2|    sftk_tokenKeyUnlock(slot);
  943|      2|    return CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
  944|      2|}
sftk_GetObjectFromList:
  953|  1.35M|{
  954|  1.35M|    SFTKObject *object;
  955|  1.35M|    int size = 0;
  956|       |
  957|  1.35M|    if (!optimizeSpace) {
  ------------------
  |  Branch (957:9): [True: 0, False: 1.35M]
  ------------------
  958|      0|        PZ_Lock(list->lock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  959|      0|        object = list->head;
  960|      0|        if (object) {
  ------------------
  |  Branch (960:13): [True: 0, False: 0]
  ------------------
  961|      0|            list->head = object->next;
  962|      0|            list->count--;
  963|      0|        }
  964|      0|        PZ_Unlock(list->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  965|      0|        if (object) {
  ------------------
  |  Branch (965:13): [True: 0, False: 0]
  ------------------
  966|       |            // As a safeguard against misuse of the library, ensure we don't
  967|       |            // hand out live objects that somehow land in the free list.
  968|      0|            PORT_Assert(object->refCount == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  969|      0|            if (object->refCount == 0) {
  ------------------
  |  Branch (969:17): [True: 0, False: 0]
  ------------------
  970|      0|                object->next = object->prev = NULL;
  971|      0|                *hasLocks = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  972|      0|                return object;
  973|      0|            }
  974|      0|        }
  975|      0|    }
  976|  1.35M|    size = isSessionObject ? sizeof(SFTKSessionObject) + hashSize * sizeof(SFTKAttribute *) : sizeof(SFTKTokenObject);
  ------------------
  |  Branch (976:12): [True: 1.35M, False: 0]
  ------------------
  977|       |
  978|  1.35M|    object = (SFTKObject *)PORT_ZAlloc(size);
  ------------------
  |  |   72|  1.35M|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  979|  1.35M|    if (isSessionObject && object) {
  ------------------
  |  Branch (979:9): [True: 1.35M, False: 0]
  |  Branch (979:28): [True: 1.35M, False: 0]
  ------------------
  980|  1.35M|        ((SFTKSessionObject *)object)->hashSize = hashSize;
  981|  1.35M|    }
  982|  1.35M|    *hasLocks = PR_FALSE;
  ------------------
  |  |  438|  1.35M|#define PR_FALSE 0
  ------------------
  983|  1.35M|    return object;
  984|  1.35M|}
sftk_InitFreeLists:
 1039|      1|{
 1040|      1|    sftk_InitFreeList(&sessionObjectList);
 1041|      1|    sftk_InitFreeList(&tokenObjectList);
 1042|      1|}
sftk_CleanupFreeLists:
 1069|      1|{
 1070|      1|    sftk_CleanupFreeList(&sessionObjectList, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1071|      1|    sftk_CleanupFreeList(&tokenObjectList, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1072|      1|}
sftk_NewObject:
 1079|  1.35M|{
 1080|  1.35M|    SFTKObject *object;
 1081|  1.35M|    SFTKSessionObject *sessObject;
 1082|  1.35M|    PRBool hasLocks = PR_FALSE;
  ------------------
  |  |  438|  1.35M|#define PR_FALSE 0
  ------------------
 1083|  1.35M|    unsigned int i;
 1084|  1.35M|    unsigned int hashSize = 0;
 1085|       |
 1086|  1.35M|    hashSize = (slot->optimizeSpace) ? SPACE_ATTRIBUTE_HASH_SIZE : TIME_ATTRIBUTE_HASH_SIZE;
  ------------------
  |  |   65|  1.35M|#define SPACE_ATTRIBUTE_HASH_SIZE 32
  ------------------
                  hashSize = (slot->optimizeSpace) ? SPACE_ATTRIBUTE_HASH_SIZE : TIME_ATTRIBUTE_HASH_SIZE;
  ------------------
  |  |   68|  1.35M|#define TIME_ATTRIBUTE_HASH_SIZE 32
  ------------------
  |  Branch (1086:16): [True: 1.35M, False: 0]
  ------------------
 1087|       |
 1088|  1.35M|    object = sftk_GetObjectFromList(&hasLocks, slot->optimizeSpace,
 1089|  1.35M|                                    &sessionObjectList, hashSize, PR_TRUE);
  ------------------
  |  |  437|  1.35M|#define PR_TRUE 1
  ------------------
 1090|  1.35M|    if (object == NULL) {
  ------------------
  |  Branch (1090:9): [True: 0, False: 1.35M]
  ------------------
 1091|      0|        return NULL;
 1092|      0|    }
 1093|  1.35M|    sessObject = (SFTKSessionObject *)object;
 1094|  1.35M|    sessObject->nextAttr = 0;
 1095|       |
 1096|  62.3M|    for (i = 0; i < MAX_OBJS_ATTRS; i++) {
  ------------------
  |  |   37|  62.3M|#define MAX_OBJS_ATTRS 45 /* number of attributes to preallocate in \
  ------------------
  |  Branch (1096:17): [True: 61.0M, False: 1.35M]
  ------------------
 1097|  61.0M|        sessObject->attrList[i].attrib.pValue = NULL;
 1098|  61.0M|        sessObject->attrList[i].freeData = PR_FALSE;
  ------------------
  |  |  438|  61.0M|#define PR_FALSE 0
  ------------------
 1099|  61.0M|    }
 1100|  1.35M|    sessObject->optimizeSpace = slot->optimizeSpace;
 1101|       |
 1102|  1.35M|    object->handle = 0;
 1103|  1.35M|    object->next = object->prev = NULL;
 1104|  1.35M|    object->slot = slot;
 1105|  1.35M|    object->isFIPS = sftk_isFIPS(slot->slotID);
  ------------------
  |  |  506|  1.35M|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|  1.35M|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|  1.35M|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 1.35M]
  |  |  |  Branch (506:32): [True: 0, False: 1.35M]
  |  |  ------------------
  ------------------
 1106|       |
 1107|  1.35M|    object->refCount = 1;
 1108|  1.35M|    sessObject->sessionList.next = NULL;
 1109|  1.35M|    sessObject->sessionList.prev = NULL;
 1110|  1.35M|    sessObject->sessionList.parent = object;
 1111|  1.35M|    sessObject->session = NULL;
 1112|  1.35M|    sessObject->wasDerived = PR_FALSE;
  ------------------
  |  |  438|  1.35M|#define PR_FALSE 0
  ------------------
 1113|  1.35M|    if (!hasLocks)
  ------------------
  |  Branch (1113:9): [True: 1.35M, False: 0]
  ------------------
 1114|  1.35M|        object->refLock = PZ_NewLock(nssILockRefLock);
  ------------------
  |  |  243|  1.35M|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 1115|  1.35M|    if (object->refLock == NULL) {
  ------------------
  |  Branch (1115:9): [True: 0, False: 1.35M]
  ------------------
 1116|      0|        PORT_Free(object);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1117|      0|        return NULL;
 1118|      0|    }
 1119|  1.35M|    if (!hasLocks)
  ------------------
  |  Branch (1119:9): [True: 1.35M, False: 0]
  ------------------
 1120|  1.35M|        sessObject->attributeLock = PZ_NewLock(nssILockAttribute);
  ------------------
  |  |  243|  1.35M|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 1121|  1.35M|    if (sessObject->attributeLock == NULL) {
  ------------------
  |  Branch (1121:9): [True: 0, False: 1.35M]
  ------------------
 1122|      0|        PZ_DestroyLock(object->refLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1123|      0|        PORT_Free(object);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1124|      0|        return NULL;
 1125|      0|    }
 1126|  44.7M|    for (i = 0; i < sessObject->hashSize; i++) {
  ------------------
  |  Branch (1126:17): [True: 43.3M, False: 1.35M]
  ------------------
 1127|  43.3M|        sessObject->head[i] = NULL;
 1128|  43.3M|    }
 1129|  1.35M|    object->objectInfo = NULL;
 1130|  1.35M|    object->infoFree = NULL;
 1131|  1.35M|    return object;
 1132|  1.35M|}
sftk_ReferenceObject:
 1192|  5.36M|{
 1193|  5.36M|    PZ_Lock(object->refLock);
  ------------------
  |  |  245|  5.36M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1194|  5.36M|    PORT_Assert(object->refCount > 0);
  ------------------
  |  |  120|  5.36M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.36M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5.36M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1195|  5.36M|    object->refCount++;
 1196|  5.36M|    PZ_Unlock(object->refLock);
  ------------------
  |  |  246|  5.36M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1197|  5.36M|}
sftk_ObjectFromHandle:
 1225|  4.07M|{
 1226|  4.07M|    SFTKSlot *slot = sftk_SlotFromSession(session);
  ------------------
  |  |  503|  4.07M|#define sftk_SlotFromSession(sp) ((sp)->slot)
  ------------------
 1227|       |
 1228|  4.07M|    return sftk_ObjectFromHandleOnSlot(handle, slot);
 1229|  4.07M|}
sftk_FreeObject:
 1236|  6.71M|{
 1237|  6.71M|    PRBool destroy = PR_FALSE;
  ------------------
  |  |  438|  6.71M|#define PR_FALSE 0
  ------------------
 1238|  6.71M|    CK_RV crv;
 1239|       |
 1240|  6.71M|    PZ_Lock(object->refLock);
  ------------------
  |  |  245|  6.71M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1241|  6.71M|    if (object->refCount == 1)
  ------------------
  |  Branch (1241:9): [True: 1.35M, False: 5.36M]
  ------------------
 1242|  1.35M|        destroy = PR_TRUE;
  ------------------
  |  |  437|  1.35M|#define PR_TRUE 1
  ------------------
 1243|  6.71M|    object->refCount--;
 1244|  6.71M|    PZ_Unlock(object->refLock);
  ------------------
  |  |  246|  6.71M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1245|       |
 1246|  6.71M|    if (destroy) {
  ------------------
  |  Branch (1246:9): [True: 1.35M, False: 5.36M]
  ------------------
 1247|  1.35M|        crv = sftk_DestroyObject(object);
 1248|  1.35M|        if (crv != CKR_OK) {
  ------------------
  |  | 1388|  1.35M|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1248:13): [True: 0, False: 1.35M]
  ------------------
 1249|      0|            return SFTK_DestroyFailure;
 1250|      0|        }
 1251|  1.35M|        return SFTK_Destroyed;
 1252|  1.35M|    }
 1253|  5.36M|    return SFTK_Busy;
 1254|  6.71M|}
sftk_getNextHandle:
 1263|  1.28M|{
 1264|  1.28M|    CK_OBJECT_HANDLE handle;
 1265|  1.28M|    SFTKObject *duplicateObject = NULL;
 1266|  1.28M|    do {
 1267|  1.28M|        PRUint32 wrappedAround;
 1268|       |
 1269|  1.28M|        duplicateObject = NULL;
 1270|  1.28M|        PZ_Lock(slot->objectLock);
  ------------------
  |  |  245|  1.28M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1271|  1.28M|        wrappedAround = slot->sessionObjectHandleCount & SFTK_TOKEN_MASK;
  ------------------
  |  |  478|  1.28M|#define SFTK_TOKEN_MASK 0x80000000L
  ------------------
 1272|  1.28M|        handle = slot->sessionObjectHandleCount & ~SFTK_TOKEN_MASK;
  ------------------
  |  |  478|  1.28M|#define SFTK_TOKEN_MASK 0x80000000L
  ------------------
 1273|  1.28M|        if (!handle) /* don't allow zero handle */
  ------------------
  |  Branch (1273:13): [True: 0, False: 1.28M]
  ------------------
 1274|      0|            handle = NSC_MIN_SESSION_OBJECT_HANDLE;
  ------------------
  |  |   52|      0|#define NSC_MIN_SESSION_OBJECT_HANDLE 1U
  ------------------
 1275|  1.28M|        slot->sessionObjectHandleCount = (handle + 1U) | wrappedAround;
 1276|       |        /* Is there already a session object with this handle? */
 1277|  1.28M|        if (wrappedAround) {
  ------------------
  |  Branch (1277:13): [True: 0, False: 1.28M]
  ------------------
 1278|      0|            sftkqueue_find(duplicateObject, handle, slot->sessObjHashTable,
  ------------------
  |  |  524|      0|    for ((element) = (head)[sftk_hash(id, hash_size)]; (element) != NULL; \
  |  |  ------------------
  |  |  |  |  513|      0|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|      0|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (524:56): [True: 0, False: 0]
  |  |  ------------------
  |  |  525|      0|         (element) = (element)->next) {                                   \
  |  |  526|      0|        if ((element)->handle == (id)) {                                  \
  |  |  ------------------
  |  |  |  Branch (526:13): [True: 0, False: 0]
  |  |  ------------------
  |  |  527|      0|            break;                                                        \
  |  |  528|      0|        }                                                                 \
  |  |  529|      0|    }
  ------------------
 1279|      0|                           slot->sessObjHashSize);
 1280|      0|        }
 1281|  1.28M|        PZ_Unlock(slot->objectLock);
  ------------------
  |  |  246|  1.28M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1282|  1.28M|    } while (duplicateObject != NULL);
  ------------------
  |  Branch (1282:14): [True: 0, False: 1.28M]
  ------------------
 1283|  1.28M|    return handle;
 1284|  1.28M|}
sftk_AddSlotObject:
 1292|  1.28M|{
 1293|  1.28M|    PRUint32 index = sftk_hash(object->handle, slot->sessObjHashSize);
  ------------------
  |  |  513|  1.28M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  ------------------
  |  |  |  |  509|  1.28M|#define SHMULTIPLIER 1791398085
  |  |  ------------------
  ------------------
 1294|  1.28M|    sftkqueue_init_element(object);
  ------------------
  |  |  544|  1.28M|    (element)->prev = NULL;
  ------------------
 1295|  1.28M|    PZ_Lock(slot->objectLock);
  ------------------
  |  |  245|  1.28M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1296|  1.28M|    sftkqueue_add2(object, object->handle, index, slot->sessObjHashTable);
  ------------------
  |  |  547|  1.28M|    {                                            \
  |  |  548|  1.28M|        (element)->next = (head)[index];         \
  |  |  549|  1.28M|        if ((head)[index])                       \
  |  |  ------------------
  |  |  |  Branch (549:13): [True: 334k, False: 953k]
  |  |  ------------------
  |  |  550|  1.28M|            (head)[index]->prev = (element);     \
  |  |  551|  1.28M|        (head)[index] = (element);               \
  |  |  552|  1.28M|    }
  ------------------
 1297|  1.28M|    PZ_Unlock(slot->objectLock);
  ------------------
  |  |  246|  1.28M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1298|  1.28M|}
sftk_AddObject:
 1302|  1.28M|{
 1303|  1.28M|    SFTKSlot *slot = sftk_SlotFromSession(session);
  ------------------
  |  |  503|  1.28M|#define sftk_SlotFromSession(sp) ((sp)->slot)
  ------------------
 1304|  1.28M|    SFTKSessionObject *so = sftk_narrowToSessionObject(object);
 1305|       |
 1306|  1.28M|    if (so) {
  ------------------
  |  Branch (1306:9): [True: 1.28M, False: 0]
  ------------------
 1307|  1.28M|        PZ_Lock(session->objectLock);
  ------------------
  |  |  245|  1.28M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1308|  1.28M|        sftkqueue_add(&so->sessionList, 0, session->objects, 0);
  ------------------
  |  |  515|  1.28M|    {                                               \
  |  |  516|  1.28M|        int tmp = sftk_hash(id, hash_size);         \
  |  |  ------------------
  |  |  |  |  513|  1.28M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|  1.28M|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  517|  1.28M|        (element)->next = (head)[tmp];              \
  |  |  518|  1.28M|        (element)->prev = NULL;                     \
  |  |  519|  1.28M|        if ((head)[tmp])                            \
  |  |  ------------------
  |  |  |  Branch (519:13): [True: 250k, False: 1.03M]
  |  |  ------------------
  |  |  520|  1.28M|            (head)[tmp]->prev = (element);          \
  |  |  521|  1.28M|        (head)[tmp] = (element);                    \
  |  |  522|  1.28M|    }
  ------------------
 1309|  1.28M|        so->session = session;
 1310|  1.28M|        PZ_Unlock(session->objectLock);
  ------------------
  |  |  246|  1.28M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1311|  1.28M|    }
 1312|  1.28M|    sftk_AddSlotObject(slot, object);
 1313|  1.28M|    sftk_ReferenceObject(object);
 1314|  1.28M|}
sftk_DeleteObject:
 1321|  1.28M|{
 1322|  1.28M|    SFTKSlot *slot = sftk_SlotFromSession(session);
  ------------------
  |  |  503|  1.28M|#define sftk_SlotFromSession(sp) ((sp)->slot)
  ------------------
 1323|  1.28M|    SFTKSessionObject *so = sftk_narrowToSessionObject(object);
 1324|  1.28M|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  1.28M|#define CKR_OK 0x00000000UL
  ------------------
 1325|  1.28M|    PRUint32 index = sftk_hash(object->handle, slot->sessObjHashSize);
  ------------------
  |  |  513|  1.28M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  ------------------
  |  |  |  |  509|  1.28M|#define SHMULTIPLIER 1791398085
  |  |  ------------------
  ------------------
 1326|       |
 1327|       |    /* Handle Token case */
 1328|  1.28M|    if (so && so->session) {
  ------------------
  |  Branch (1328:9): [True: 1.28M, False: 0]
  |  Branch (1328:15): [True: 1.28M, False: 0]
  ------------------
 1329|  1.28M|        session = so->session;
 1330|  1.28M|        PZ_Lock(session->objectLock);
  ------------------
  |  |  245|  1.28M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1331|  1.28M|        sftkqueue_delete(&so->sessionList, 0, session->objects, 0);
  ------------------
  |  |  534|  1.28M|    if ((element)->next)                                      \
  |  |  ------------------
  |  |  |  Branch (534:9): [True: 200k, False: 1.08M]
  |  |  ------------------
  |  |  535|  1.28M|        (element)->next->prev = (element)->prev;              \
  |  |  536|  1.28M|    if ((element)->prev)                                      \
  |  |  ------------------
  |  |  |  Branch (536:9): [True: 147k, False: 1.14M]
  |  |  ------------------
  |  |  537|  1.28M|        (element)->prev->next = (element)->next;              \
  |  |  538|  1.28M|    else                                                      \
  |  |  539|  1.28M|        (head)[sftk_hash(id, hash_size)] = ((element)->next); \
  |  |  ------------------
  |  |  |  |  513|  1.14M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|  1.14M|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  540|  1.28M|    (element)->next = NULL;                                   \
  |  |  541|  1.28M|    (element)->prev = NULL;
  ------------------
 1332|  1.28M|        PZ_Unlock(session->objectLock);
  ------------------
  |  |  246|  1.28M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1333|  1.28M|        PZ_Lock(slot->objectLock);
  ------------------
  |  |  245|  1.28M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1334|  1.28M|        sftkqueue_delete2(object, object->handle, index, slot->sessObjHashTable);
  ------------------
  |  |  564|  1.28M|    if ((element)->next)                            \
  |  |  ------------------
  |  |  |  Branch (564:9): [True: 334k, False: 953k]
  |  |  ------------------
  |  |  565|  1.28M|        (element)->next->prev = (element)->prev;    \
  |  |  566|  1.28M|    if ((element)->prev)                            \
  |  |  ------------------
  |  |  |  Branch (566:9): [True: 98, False: 1.28M]
  |  |  ------------------
  |  |  567|  1.28M|        (element)->prev->next = (element)->next;    \
  |  |  568|  1.28M|    else                                            \
  |  |  569|  1.28M|        (head)[index] = ((element)->next);
  ------------------
 1335|  1.28M|        PZ_Unlock(slot->objectLock);
  ------------------
  |  |  246|  1.28M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1336|  1.28M|        sftkqueue_clear_deleted_element(object);
  ------------------
  |  |  572|  1.28M|    (element)->next = NULL;                      \
  |  |  573|  1.28M|    (element)->prev = NULL;
  ------------------
 1337|  1.28M|        sftk_FreeObject(object); /* free the reference owned by the queue */
 1338|  1.28M|    } else {
 1339|      0|        SFTKDBHandle *handle = sftk_getDBForTokenObject(slot, object->handle);
 1340|      0|#ifdef DEBUG
 1341|      0|        SFTKTokenObject *to = sftk_narrowToTokenObject(object);
 1342|      0|        PORT_Assert(to);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1343|      0|#endif
 1344|      0|        crv = sftkdb_DestroyObject(handle, object->handle, object->objclass);
 1345|      0|        sftk_freeDB(handle);
 1346|      0|    }
 1347|  1.28M|    return crv;
 1348|  1.28M|}
sftk_CopyObject:
 1685|   210k|{
 1686|   210k|    SFTKAttribute *attribute;
 1687|   210k|    SFTKSessionObject *src_so = sftk_narrowToSessionObject(srcObject);
 1688|   210k|    unsigned int i;
 1689|       |
 1690|   210k|    destObject->isFIPS = srcObject->isFIPS;
 1691|   210k|    if (src_so == NULL) {
  ------------------
  |  Branch (1691:9): [True: 0, False: 210k]
  ------------------
 1692|      0|        return sftk_CopyTokenObject(destObject, srcObject);
 1693|      0|    }
 1694|       |
 1695|   210k|    PZ_Lock(src_so->attributeLock);
  ------------------
  |  |  245|   210k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1696|  6.94M|    for (i = 0; i < src_so->hashSize; i++) {
  ------------------
  |  Branch (1696:17): [True: 6.73M, False: 210k]
  ------------------
 1697|  6.73M|        attribute = src_so->head[i];
 1698|  6.94M|        do {
 1699|  6.94M|            if (attribute) {
  ------------------
  |  Branch (1699:17): [True: 1.25M, False: 5.69M]
  ------------------
 1700|  1.25M|                if (!sftk_hasAttribute(destObject, attribute->handle)) {
  ------------------
  |  Branch (1700:21): [True: 1.25M, False: 2]
  ------------------
 1701|       |                    /* we need to copy the attribute since each attribute
 1702|       |                     * only has one set of link list pointers */
 1703|  1.25M|                    SFTKAttribute *newAttribute = sftk_NewAttribute(
 1704|  1.25M|                        destObject, sftk_attr_expand(&attribute->attrib));
  ------------------
  |  |  587|  1.25M|#define sftk_attr_expand(ap) (ap)->type, (ap)->pValue, (ap)->ulValueLen
  ------------------
 1705|  1.25M|                    if (newAttribute == NULL) {
  ------------------
  |  Branch (1705:25): [True: 0, False: 1.25M]
  ------------------
 1706|      0|                        PZ_Unlock(src_so->attributeLock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1707|      0|                        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1708|      0|                    }
 1709|  1.25M|                    sftk_AddAttribute(destObject, newAttribute);
 1710|  1.25M|                }
 1711|  1.25M|                attribute = attribute->next;
 1712|  1.25M|            }
 1713|  6.94M|        } while (attribute != NULL);
  ------------------
  |  Branch (1713:18): [True: 210k, False: 6.73M]
  ------------------
 1714|  6.73M|    }
 1715|   210k|    PZ_Unlock(src_so->attributeLock);
  ------------------
  |  |  246|   210k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1716|       |
 1717|   210k|    return CKR_OK;
  ------------------
  |  | 1388|   210k|#define CKR_OK 0x00000000UL
  ------------------
 1718|   210k|}
sftk_searchObjectList:
 1773|      2|{
 1774|      2|    unsigned int i;
 1775|      2|    SFTKObject *object;
 1776|      2|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|      2|#define CKR_OK 0x00000000UL
  ------------------
 1777|       |
 1778|      2|    PZ_Lock(lock);
  ------------------
  |  |  245|      2|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1779|     66|    for (i = 0; i < size; i++) {
  ------------------
  |  Branch (1779:17): [True: 64, False: 2]
  ------------------
 1780|     64|        for (object = head[i]; object != NULL; object = object->next) {
  ------------------
  |  Branch (1780:32): [True: 0, False: 64]
  ------------------
 1781|      0|            if (sftk_objectMatch(object, theTemplate, count)) {
  ------------------
  |  Branch (1781:17): [True: 0, False: 0]
  ------------------
 1782|       |                /* don't return objects that aren't yet visible */
 1783|      0|                if ((!isLoggedIn) && sftk_isTrue(object, CKA_PRIVATE))
  ------------------
  |  |  513|      0|#define CKA_PRIVATE 0x00000002UL
  ------------------
  |  Branch (1783:21): [True: 0, False: 0]
  |  Branch (1783:38): [True: 0, False: 0]
  ------------------
 1784|      0|                    continue;
 1785|      0|                sftk_addHandle(search, object->handle);
 1786|      0|            }
 1787|      0|        }
 1788|     64|    }
 1789|      2|    PZ_Unlock(lock);
  ------------------
  |  |  246|      2|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1790|      2|    return crv;
 1791|      2|}
sftk_FreeSearch:
 1821|  23.4k|{
 1822|  23.4k|    if (search->handles) {
  ------------------
  |  Branch (1822:9): [True: 23.4k, False: 0]
  ------------------
 1823|  23.4k|        PORT_Free(search->handles);
  ------------------
  |  |   60|  23.4k|#define PORT_Free PORT_Free_Util
  ------------------
 1824|  23.4k|    }
 1825|  23.4k|    PORT_Free(search);
  ------------------
  |  |   60|  23.4k|#define PORT_Free PORT_Free_Util
  ------------------
 1826|  23.4k|}
sftk_update_state:
 1836|  1.73M|{
 1837|  1.73M|    if (slot->isLoggedIn) {
  ------------------
  |  Branch (1837:9): [True: 0, False: 1.73M]
  ------------------
 1838|      0|        if (slot->ssoLoggedIn) {
  ------------------
  |  Branch (1838:13): [True: 0, False: 0]
  ------------------
 1839|      0|            session->info.state = CKS_RW_SO_FUNCTIONS;
  ------------------
  |  |  286|      0|#define CKS_RW_SO_FUNCTIONS 4
  ------------------
 1840|      0|        } else if (session->info.flags & CKF_RW_SESSION) {
  ------------------
  |  |  302|      0|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (1840:20): [True: 0, False: 0]
  ------------------
 1841|      0|            session->info.state = CKS_RW_USER_FUNCTIONS;
  ------------------
  |  |  285|      0|#define CKS_RW_USER_FUNCTIONS 3
  ------------------
 1842|      0|        } else {
 1843|      0|            session->info.state = CKS_RO_USER_FUNCTIONS;
  ------------------
  |  |  283|      0|#define CKS_RO_USER_FUNCTIONS 1
  ------------------
 1844|      0|        }
 1845|  1.73M|    } else {
 1846|  1.73M|        if (session->info.flags & CKF_RW_SESSION) {
  ------------------
  |  |  302|  1.73M|#define CKF_RW_SESSION 0x00000002UL     /* session is r/w */
  ------------------
  |  Branch (1846:13): [True: 0, False: 1.73M]
  ------------------
 1847|      0|            session->info.state = CKS_RW_PUBLIC_SESSION;
  ------------------
  |  |  284|      0|#define CKS_RW_PUBLIC_SESSION 2
  ------------------
 1848|  1.73M|        } else {
 1849|  1.73M|            session->info.state = CKS_RO_PUBLIC_SESSION;
  ------------------
  |  |  282|  1.73M|#define CKS_RO_PUBLIC_SESSION 0
  ------------------
 1850|  1.73M|        }
 1851|  1.73M|    }
 1852|  1.73M|}
sftk_FreeContext:
 1876|   916k|{
 1877|   916k|    if (context->cipherInfo) {
  ------------------
  |  Branch (1877:9): [True: 916k, False: 0]
  ------------------
 1878|   916k|        (*context->destroy)(context->cipherInfo, PR_TRUE);
  ------------------
  |  |  437|   916k|#define PR_TRUE 1
  ------------------
 1879|   916k|    }
 1880|   916k|    if (context->hashInfo) {
  ------------------
  |  Branch (1880:9): [True: 165k, False: 750k]
  ------------------
 1881|   165k|        (*context->hashdestroy)(context->hashInfo, PR_TRUE);
  ------------------
  |  |  437|   165k|#define PR_TRUE 1
  ------------------
 1882|   165k|    }
 1883|   916k|    if (context->key) {
  ------------------
  |  Branch (1883:9): [True: 650k, False: 265k]
  ------------------
 1884|   650k|        sftk_FreeObject(context->key);
 1885|   650k|        context->key = NULL;
 1886|   650k|    }
 1887|   916k|    PORT_Free(context);
  ------------------
  |  |   60|   916k|#define PORT_Free PORT_Free_Util
  ------------------
 1888|   916k|}
sftk_InitSession:
 1897|   869k|{
 1898|   869k|    session->next = session->prev = NULL;
 1899|   869k|    session->enc_context = NULL;
 1900|   869k|    session->hash_context = NULL;
 1901|   869k|    session->sign_context = NULL;
 1902|   869k|    session->search = NULL;
 1903|   869k|    session->objectIDCount = 1;
 1904|   869k|    session->objectLock = PZ_NewLock(nssILockObject);
  ------------------
  |  |  243|   869k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 1905|   869k|    if (session->objectLock == NULL) {
  ------------------
  |  Branch (1905:9): [True: 0, False: 869k]
  ------------------
 1906|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1907|      0|    }
 1908|   869k|    session->objects[0] = NULL;
 1909|       |
 1910|   869k|    session->slot = slot;
 1911|   869k|    session->notify = notify;
 1912|   869k|    session->appData = pApplication;
 1913|   869k|    session->info.flags = flags;
 1914|   869k|    session->info.slotID = slotID;
 1915|   869k|    session->info.ulDeviceError = 0;
 1916|   869k|    sftk_update_state(slot, session);
 1917|       |    /* no ops completed yet, so the last one couldn't be a FIPS op */
 1918|   869k|    session->lastOpWasFIPS = PR_FALSE;
  ------------------
  |  |  438|   869k|#define PR_FALSE 0
  ------------------
 1919|   869k|    return CKR_OK;
  ------------------
  |  | 1388|   869k|#define CKR_OK 0x00000000UL
  ------------------
 1920|   869k|}
sftk_NewSession:
 1928|   869k|{
 1929|   869k|    SFTKSession *session;
 1930|   869k|    SFTKSlot *slot = sftk_SlotFromID(slotID, PR_FALSE);
  ------------------
  |  |  438|   869k|#define PR_FALSE 0
  ------------------
 1931|   869k|    CK_RV crv;
 1932|       |
 1933|   869k|    if (slot == NULL)
  ------------------
  |  Branch (1933:9): [True: 0, False: 869k]
  ------------------
 1934|      0|        return NULL;
 1935|       |
 1936|   869k|    session = (SFTKSession *)PORT_Alloc(sizeof(SFTKSession));
  ------------------
  |  |   52|   869k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1937|   869k|    if (session == NULL)
  ------------------
  |  Branch (1937:9): [True: 0, False: 869k]
  ------------------
 1938|      0|        return NULL;
 1939|       |
 1940|   869k|    crv = sftk_InitSession(session, slot, slotID, notify, pApplication, flags);
 1941|   869k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   869k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1941:9): [True: 0, False: 869k]
  ------------------
 1942|      0|        PORT_Free(session);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1943|      0|        return NULL;
 1944|      0|    }
 1945|   869k|    return session;
 1946|   869k|}
sftk_ClearSession:
 1951|   869k|{
 1952|   869k|    SFTKObjectList *op, *next;
 1953|       |
 1954|       |    /* clean out the attributes */
 1955|       |    /* since no one is referencing us, it's safe to walk the chain
 1956|       |     * without a lock */
 1957|   869k|    for (op = session->objects[0]; op != NULL; op = next) {
  ------------------
  |  Branch (1957:36): [True: 0, False: 869k]
  ------------------
 1958|      0|        next = op->next;
 1959|       |        /* paranoia */
 1960|      0|        op->next = op->prev = NULL;
 1961|      0|        sftk_DeleteObject(session, op->parent);
 1962|      0|    }
 1963|   869k|    PZ_DestroyLock(session->objectLock);
  ------------------
  |  |  244|   869k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1964|   869k|    if (session->enc_context) {
  ------------------
  |  Branch (1964:9): [True: 377k, False: 492k]
  ------------------
 1965|   377k|        sftk_FreeContext(session->enc_context);
 1966|   377k|    }
 1967|   869k|    if (session->hash_context) {
  ------------------
  |  Branch (1967:9): [True: 73.3k, False: 796k]
  ------------------
 1968|  73.3k|        sftk_FreeContext(session->hash_context);
 1969|  73.3k|    }
 1970|   869k|    if (session->sign_context) {
  ------------------
  |  Branch (1970:9): [True: 0, False: 869k]
  ------------------
 1971|      0|        sftk_FreeContext(session->sign_context);
 1972|      0|    }
 1973|   869k|    if (session->search) {
  ------------------
  |  Branch (1973:9): [True: 0, False: 869k]
  ------------------
 1974|      0|        sftk_FreeSearch(session->search);
 1975|      0|    }
 1976|   869k|}
sftk_DestroySession:
 1981|   869k|{
 1982|   869k|    sftk_ClearSession(session);
 1983|   869k|    PORT_Free(session);
  ------------------
  |  |   60|   869k|#define PORT_Free PORT_Free_Util
  ------------------
 1984|   869k|}
sftk_SessionFromHandle:
 1992|  7.78M|{
 1993|  7.78M|    SFTKSlot *slot = sftk_SlotFromSessionHandle(handle);
 1994|  7.78M|    SFTKSession *session;
 1995|  7.78M|    PZLock *lock;
  ------------------
  |  |  185|  7.78M|#define PZLock PRLock
  ------------------
 1996|       |
 1997|  7.78M|    if (!slot)
  ------------------
  |  Branch (1997:9): [True: 0, False: 7.78M]
  ------------------
 1998|      0|        return NULL;
 1999|  7.78M|    lock = SFTK_SESSION_LOCK(slot, handle);
  ------------------
  |  |  583|  7.78M|    ((slot)->sessionLock[(handle) & (slot)->sessionLockMask])
  ------------------
 2000|       |
 2001|  7.78M|    PZ_Lock(lock);
  ------------------
  |  |  245|  7.78M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 2002|  7.78M|    sftkqueue_find(session, handle, slot->head, slot->sessHashSize);
  ------------------
  |  |  524|  13.3M|    for ((element) = (head)[sftk_hash(id, hash_size)]; (element) != NULL; \
  |  |  ------------------
  |  |  |  |  513|  7.78M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|  7.78M|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  |  Branch (524:56): [True: 13.3M, False: 0]
  |  |  ------------------
  |  |  525|  13.3M|         (element) = (element)->next) {                                   \
  |  |  526|  13.3M|        if ((element)->handle == (id)) {                                  \
  |  |  ------------------
  |  |  |  Branch (526:13): [True: 7.78M, False: 5.51M]
  |  |  ------------------
  |  |  527|  7.78M|            break;                                                        \
  |  |  528|  7.78M|        }                                                                 \
  |  |  529|  13.3M|    }
  ------------------
 2003|  7.78M|    PZ_Unlock(lock);
  ------------------
  |  |  246|  7.78M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 2004|       |
 2005|  7.78M|    return (session);
 2006|  7.78M|}
sftk_FreeSession:
 2015|  6.91M|{
 2016|  6.91M|    return;
 2017|  6.91M|}
sftk_narrowToSessionObject:
 2122|   106M|{
 2123|   106M|    return !sftk_isToken(obj->handle) ? (SFTKSessionObject *)obj : NULL;
  ------------------
  |  |  504|   106M|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|   106M|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|   106M|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  ------------------
  |  Branch (2123:12): [True: 106M, False: 0]
  ------------------
 2124|   106M|}
sftk_narrowToTokenObject:
 2128|  1.38M|{
 2129|  1.38M|    return sftk_isToken(obj->handle) ? (SFTKTokenObject *)obj : NULL;
  ------------------
  |  |  504|  1.38M|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|  1.38M|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|  1.38M|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  |  |  |  Branch (504:26): [True: 0, False: 1.38M]
  |  |  ------------------
  ------------------
 2130|  1.38M|}
sftk_AttributeToFlags:
 2207|   434k|{
 2208|   434k|    CK_FLAGS flags = 0;
 2209|       |
 2210|   434k|    switch (op) {
 2211|  23.0k|        case CKA_ENCRYPT:
  ------------------
  |  |  547|  23.0k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (2211:9): [True: 23.0k, False: 411k]
  ------------------
 2212|  23.0k|            flags = CKF_ENCRYPT;
  ------------------
  |  | 1353|  23.0k|#define CKF_ENCRYPT 0x00000100UL
  ------------------
 2213|  23.0k|            break;
 2214|  34.2k|        case CKA_DECRYPT:
  ------------------
  |  |  548|  34.2k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (2214:9): [True: 34.2k, False: 400k]
  ------------------
 2215|  34.2k|            flags = CKF_DECRYPT;
  ------------------
  |  | 1354|  34.2k|#define CKF_DECRYPT 0x00000200UL
  ------------------
 2216|  34.2k|            break;
 2217|  33.9k|        case CKA_WRAP:
  ------------------
  |  |  549|  33.9k|#define CKA_WRAP 0x00000106UL
  ------------------
  |  Branch (2217:9): [True: 33.9k, False: 400k]
  ------------------
 2218|  33.9k|            flags = CKF_WRAP;
  ------------------
  |  | 1362|  33.9k|#define CKF_WRAP 0x00020000UL
  ------------------
 2219|  33.9k|            break;
 2220|  11.9k|        case CKA_UNWRAP:
  ------------------
  |  |  550|  11.9k|#define CKA_UNWRAP 0x00000107UL
  ------------------
  |  Branch (2220:9): [True: 11.9k, False: 422k]
  ------------------
 2221|  11.9k|            flags = CKF_UNWRAP;
  ------------------
  |  | 1363|  11.9k|#define CKF_UNWRAP 0x00040000UL
  ------------------
 2222|  11.9k|            break;
 2223|      0|        case CKA_SIGN:
  ------------------
  |  |  551|      0|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (2223:9): [True: 0, False: 434k]
  ------------------
 2224|      0|            flags = CKF_SIGN;
  ------------------
  |  | 1356|      0|#define CKF_SIGN 0x00000800UL
  ------------------
 2225|      0|            break;
 2226|      0|        case CKA_SIGN_RECOVER:
  ------------------
  |  |  552|      0|#define CKA_SIGN_RECOVER 0x00000109UL
  ------------------
  |  Branch (2226:9): [True: 0, False: 434k]
  ------------------
 2227|      0|            flags = CKF_SIGN_RECOVER;
  ------------------
  |  | 1357|      0|#define CKF_SIGN_RECOVER 0x00001000UL
  ------------------
 2228|      0|            break;
 2229|      0|        case CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (2229:9): [True: 0, False: 434k]
  ------------------
 2230|      0|            flags = CKF_VERIFY;
  ------------------
  |  | 1358|      0|#define CKF_VERIFY 0x00002000
  ------------------
 2231|      0|            break;
 2232|      0|        case CKA_VERIFY_RECOVER:
  ------------------
  |  |  554|      0|#define CKA_VERIFY_RECOVER 0x0000010BUL
  ------------------
  |  Branch (2232:9): [True: 0, False: 434k]
  ------------------
 2233|      0|            flags = CKF_VERIFY_RECOVER;
  ------------------
  |  | 1359|      0|#define CKF_VERIFY_RECOVER 0x00004000UL
  ------------------
 2234|      0|            break;
 2235|      0|        case CKA_DERIVE:
  ------------------
  |  |  555|      0|#define CKA_DERIVE 0x0000010CUL
  ------------------
  |  Branch (2235:9): [True: 0, False: 434k]
  ------------------
 2236|      0|            flags = CKF_DERIVE;
  ------------------
  |  | 1364|      0|#define CKF_DERIVE 0x00080000UL
  ------------------
 2237|      0|            break;
 2238|       |        /* fake attribute to select digesting */
 2239|      0|        case CKA_DIGEST:
  ------------------
  |  |   68|      0|#define CKA_DIGEST 0x81000000L
  ------------------
  |  Branch (2239:9): [True: 0, False: 434k]
  ------------------
 2240|      0|            flags = CKF_DIGEST;
  ------------------
  |  | 1355|      0|#define CKF_DIGEST 0x00000400UL
  ------------------
 2241|      0|            break;
 2242|   161k|        case CKA_NSS_MESSAGE | CKA_ENCRYPT:
  ------------------
  |  |   69|   161k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_ENCRYPT:
  ------------------
  |  |  547|   161k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
  |  Branch (2242:9): [True: 161k, False: 273k]
  ------------------
 2243|   161k|            flags = CKF_MESSAGE_ENCRYPT;
  ------------------
  |  | 1339|   161k|#define CKF_MESSAGE_ENCRYPT 0x00000002UL
  ------------------
 2244|   161k|            break;
 2245|   169k|        case CKA_NSS_MESSAGE | CKA_DECRYPT:
  ------------------
  |  |   69|   169k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_DECRYPT:
  ------------------
  |  |  548|   169k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (2245:9): [True: 169k, False: 264k]
  ------------------
 2246|   169k|            flags = CKF_MESSAGE_DECRYPT;
  ------------------
  |  | 1340|   169k|#define CKF_MESSAGE_DECRYPT 0x00000004UL
  ------------------
 2247|   169k|            break;
 2248|      0|        case CKA_NSS_MESSAGE | CKA_SIGN:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_SIGN:
  ------------------
  |  |  551|      0|#define CKA_SIGN 0x00000108UL
  ------------------
  |  Branch (2248:9): [True: 0, False: 434k]
  ------------------
 2249|      0|            flags = CKF_MESSAGE_SIGN;
  ------------------
  |  | 1341|      0|#define CKF_MESSAGE_SIGN 0x00000008UL
  ------------------
 2250|      0|            break;
 2251|      0|        case CKA_NSS_MESSAGE | CKA_VERIFY:
  ------------------
  |  |   69|      0|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                      case CKA_NSS_MESSAGE | CKA_VERIFY:
  ------------------
  |  |  553|      0|#define CKA_VERIFY 0x0000010AUL
  ------------------
  |  Branch (2251:9): [True: 0, False: 434k]
  ------------------
 2252|      0|            flags = CKF_MESSAGE_VERIFY;
  ------------------
  |  | 1342|      0|#define CKF_MESSAGE_VERIFY 0x00000010UL
  ------------------
 2253|      0|            break;
 2254|      0|        default:
  ------------------
  |  Branch (2254:9): [True: 0, False: 434k]
  ------------------
 2255|      0|            break;
 2256|   434k|    }
 2257|   434k|    return flags;
 2258|   434k|}
sftk_GetHashTypeFromMechanism:
 2269|  1.06M|{
 2270|  1.06M|    switch (mech) {
 2271|      0|        case CKM_SHA_1:
  ------------------
  |  |  859|      0|#define CKM_SHA_1 0x00000220UL
  ------------------
  |  Branch (2271:9): [True: 0, False: 1.06M]
  ------------------
 2272|      0|        case CKG_MGF1_SHA1:
  ------------------
  |  | 1648|      0|#define CKG_MGF1_SHA1 0x00000001UL
  ------------------
  |  Branch (2272:9): [True: 0, False: 1.06M]
  ------------------
 2273|      0|            return HASH_AlgSHA1;
 2274|      0|        case CKM_SHA224:
  ------------------
  |  |  887|      0|#define CKM_SHA224 0x00000255UL
  ------------------
  |  Branch (2274:9): [True: 0, False: 1.06M]
  ------------------
 2275|      0|        case CKG_MGF1_SHA224:
  ------------------
  |  | 1654|      0|#define CKG_MGF1_SHA224 0x00000005UL
  ------------------
  |  Branch (2275:9): [True: 0, False: 1.06M]
  ------------------
 2276|      0|            return HASH_AlgSHA224;
 2277|   142k|        case CKM_SHA256:
  ------------------
  |  |  876|   142k|#define CKM_SHA256 0x00000250UL
  ------------------
  |  Branch (2277:9): [True: 142k, False: 924k]
  ------------------
 2278|   144k|        case CKG_MGF1_SHA256:
  ------------------
  |  | 1649|   144k|#define CKG_MGF1_SHA256 0x00000002UL
  ------------------
  |  Branch (2278:9): [True: 2.22k, False: 1.06M]
  ------------------
 2279|   144k|            return HASH_AlgSHA256;
 2280|   908k|        case CKM_SHA384:
  ------------------
  |  |  879|   908k|#define CKM_SHA384 0x00000260UL
  ------------------
  |  Branch (2280:9): [True: 908k, False: 159k]
  ------------------
 2281|   908k|        case CKG_MGF1_SHA384:
  ------------------
  |  | 1650|   908k|#define CKG_MGF1_SHA384 0x00000003UL
  ------------------
  |  Branch (2281:9): [True: 416, False: 1.06M]
  ------------------
 2282|   908k|            return HASH_AlgSHA384;
 2283|  7.07k|        case CKM_SHA512:
  ------------------
  |  |  882|  7.07k|#define CKM_SHA512 0x00000270UL
  ------------------
  |  Branch (2283:9): [True: 7.07k, False: 1.06M]
  ------------------
 2284|  14.1k|        case CKG_MGF1_SHA512:
  ------------------
  |  | 1651|  14.1k|#define CKG_MGF1_SHA512 0x00000004UL
  ------------------
  |  Branch (2284:9): [True: 7.07k, False: 1.06M]
  ------------------
 2285|  14.1k|            return HASH_AlgSHA512;
 2286|      0|        default:
  ------------------
  |  Branch (2286:9): [True: 0, False: 1.06M]
  ------------------
 2287|      0|            return HASH_AlgNULL;
 2288|  1.06M|    }
 2289|  1.06M|}
sftk_operationIsFIPS:
 2475|  1.93M|{
 2476|  1.93M|#ifndef NSS_HAS_FIPS_INDICATORS
 2477|  1.93M|    return PR_FALSE;
  ------------------
  |  |  438|  1.93M|#define PR_FALSE 0
  ------------------
 2478|       |#else
 2479|       |    int i;
 2480|       |    CK_FLAGS opFlags;
 2481|       |    CK_ULONG keyLength;
 2482|       |
 2483|       |    /* handle all the quick stuff first */
 2484|       |    if (!sftk_isFIPS(slot->slotID)) {
 2485|       |        return PR_FALSE;
 2486|       |    }
 2487|       |    if (source && !source->isFIPS) {
 2488|       |        return PR_FALSE;
 2489|       |    }
 2490|       |    if (mech == NULL) {
 2491|       |        return PR_FALSE;
 2492|       |    }
 2493|       |
 2494|       |    /* now get the calculated values */
 2495|       |    opFlags = sftk_AttributeToFlags(op);
 2496|       |    if (opFlags == 0) {
 2497|       |        return PR_FALSE;
 2498|       |    }
 2499|       |    keyLength = sftk_getKeyLength(source);
 2500|       |
 2501|       |    /* check against our algorithm array */
 2502|       |    for (i = 0; i < SFTK_NUMBER_FIPS_ALGORITHMS; i++) {
 2503|       |        SFTKFIPSAlgorithmList *mechs = &sftk_fips_mechs[i];
 2504|       |        /* if we match the number of records exactly, then we are an
 2505|       |         * approved algorithm in the approved mode with an approved key */
 2506|       |        if (((mech->mechanism == mechs->type) &&
 2507|       |             (opFlags == (mechs->info.flags & opFlags)) &&
 2508|       |             (keyLength <= mechs->info.ulMaxKeySize) &&
 2509|       |             (keyLength >= mechs->info.ulMinKeySize) &&
 2510|       |             ((keyLength - mechs->info.ulMinKeySize) % mechs->step) == 0) &&
 2511|       |            ((mechs->special == SFTKFIPSNone) ||
 2512|       |             sftk_handleSpecial(slot, mech, mechs, source))) {
 2513|       |            return PR_TRUE;
 2514|       |        }
 2515|       |    }
 2516|       |    return PR_FALSE;
 2517|       |#endif
 2518|  1.93M|}
pkcs11u.c:sftk_NewAttribute:
  114|  26.6M|{
  115|  26.6M|    SFTKAttribute *attribute;
  116|       |
  117|  26.6M|    SFTKSessionObject *so = sftk_narrowToSessionObject(object);
  118|  26.6M|    int index;
  119|       |
  120|  26.6M|    if (so == NULL) {
  ------------------
  |  Branch (120:9): [True: 0, False: 26.6M]
  ------------------
  121|       |        /* allocate new attribute in a buffer */
  122|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  123|      0|        return NULL;
  124|      0|    }
  125|       |    /*
  126|       |     * We attempt to keep down contention on Malloc and Arena locks by
  127|       |     * limiting the number of these calls on high traversed paths. This
  128|       |     * is done for attributes by 'allocating' them from a pool already
  129|       |     * allocated by the parent object.
  130|       |     */
  131|  26.6M|    PZ_Lock(so->attributeLock);
  ------------------
  |  |  245|  26.6M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  132|  26.6M|    index = so->nextAttr++;
  133|  26.6M|    PZ_Unlock(so->attributeLock);
  ------------------
  |  |  246|  26.6M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  134|  26.6M|    PORT_Assert(index < MAX_OBJS_ATTRS);
  ------------------
  |  |  120|  26.6M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  26.6M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 26.6M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  135|  26.6M|    if (index >= MAX_OBJS_ATTRS)
  ------------------
  |  |   37|  26.6M|#define MAX_OBJS_ATTRS 45 /* number of attributes to preallocate in \
  ------------------
  |  Branch (135:9): [True: 0, False: 26.6M]
  ------------------
  136|      0|        return NULL;
  137|       |
  138|  26.6M|    attribute = &so->attrList[index];
  139|  26.6M|    attribute->attrib.type = type;
  140|  26.6M|    attribute->freeAttr = PR_FALSE;
  ------------------
  |  |  438|  26.6M|#define PR_FALSE 0
  ------------------
  141|  26.6M|    attribute->freeData = PR_FALSE;
  ------------------
  |  |  438|  26.6M|#define PR_FALSE 0
  ------------------
  142|  26.6M|    if (value) {
  ------------------
  |  Branch (142:9): [True: 21.9M, False: 4.71M]
  ------------------
  143|  21.9M|        if (len <= ATTR_SPACE) {
  ------------------
  |  |   39|  21.9M|#define ATTR_SPACE 50     /* Maximum size of attribute data before extra \
  ------------------
  |  Branch (143:13): [True: 21.7M, False: 169k]
  ------------------
  144|  21.7M|            attribute->attrib.pValue = attribute->space;
  145|  21.7M|        } else {
  146|   169k|            attribute->attrib.pValue = PORT_Alloc(len);
  ------------------
  |  |   52|   169k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  147|   169k|            attribute->freeData = PR_TRUE;
  ------------------
  |  |  437|   169k|#define PR_TRUE 1
  ------------------
  148|   169k|        }
  149|  21.9M|        if (attribute->attrib.pValue == NULL) {
  ------------------
  |  Branch (149:13): [True: 0, False: 21.9M]
  ------------------
  150|      0|            return NULL;
  151|      0|        }
  152|  21.9M|        PORT_Memcpy(attribute->attrib.pValue, value, len);
  ------------------
  |  |  180|  21.9M|#define PORT_Memcpy memcpy
  ------------------
  153|  21.9M|        attribute->attrib.ulValueLen = len;
  154|  21.9M|    } else {
  155|  4.71M|        attribute->attrib.pValue = NULL;
  156|  4.71M|        attribute->attrib.ulValueLen = 0;
  157|  4.71M|    }
  158|  26.6M|    attribute->attrib.type = type;
  159|  26.6M|    attribute->handle = type;
  160|  26.6M|    attribute->next = attribute->prev = NULL;
  161|  26.6M|    return attribute;
  162|  26.6M|}
pkcs11u.c:sftk_AddAttribute:
  387|  26.6M|{
  388|  26.6M|    SFTKSessionObject *sessObject = sftk_narrowToSessionObject(object);
  389|       |
  390|  26.6M|    if (sessObject == NULL)
  ------------------
  |  Branch (390:9): [True: 0, False: 26.6M]
  ------------------
  391|      0|        return;
  392|  26.6M|    PZ_Lock(sessObject->attributeLock);
  ------------------
  |  |  245|  26.6M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  393|  26.6M|    sftkqueue_add(attribute, attribute->handle,
  ------------------
  |  |  515|  26.6M|    {                                               \
  |  |  516|  26.6M|        int tmp = sftk_hash(id, hash_size);         \
  |  |  ------------------
  |  |  |  |  513|  26.6M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  |  |  ------------------
  |  |  |  |  |  |  509|  26.6M|#define SHMULTIPLIER 1791398085
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  517|  26.6M|        (element)->next = (head)[tmp];              \
  |  |  518|  26.6M|        (element)->prev = NULL;                     \
  |  |  519|  26.6M|        if ((head)[tmp])                            \
  |  |  ------------------
  |  |  |  Branch (519:13): [True: 10.9M, False: 15.7M]
  |  |  ------------------
  |  |  520|  26.6M|            (head)[tmp]->prev = (element);          \
  |  |  521|  26.6M|        (head)[tmp] = (element);                    \
  |  |  522|  26.6M|    }
  ------------------
  394|  26.6M|                  sessObject->head, sessObject->hashSize);
  395|  26.6M|    PZ_Unlock(sessObject->attributeLock);
  ------------------
  |  |  246|  26.6M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  396|  26.6M|}
pkcs11u.c:sftk_tokenKeyLock:
  917|      2|{
  918|      2|    SKIP_AFTER_FORK(PZ_Lock(slot->objectLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
  919|      2|}
pkcs11u.c:sftk_tokenKeyUnlock:
  923|      2|{
  924|      2|    SKIP_AFTER_FORK(PZ_Unlock(slot->objectLock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
  925|      2|}
pkcs11u.c:sftk_InitFreeList:
 1031|      2|{
 1032|      2|    if (!list->lock) {
  ------------------
  |  Branch (1032:9): [True: 2, False: 0]
  ------------------
 1033|      2|        list->lock = PZ_NewLock(nssILockObject);
  ------------------
  |  |  243|      2|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 1034|      2|    }
 1035|      2|}
pkcs11u.c:sftk_CleanupFreeList:
 1046|      2|{
 1047|      2|    SFTKObject *object;
 1048|       |
 1049|      2|    if (!list->lock) {
  ------------------
  |  Branch (1049:9): [True: 0, False: 2]
  ------------------
 1050|      0|        return;
 1051|      0|    }
 1052|      2|    SKIP_AFTER_FORK(PZ_Lock(list->lock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 1053|      2|    for (object = list->head; object != NULL;
  ------------------
  |  Branch (1053:31): [True: 0, False: 2]
  ------------------
 1054|      2|         object = sftk_freeObjectData(object)) {
 1055|      0|        PZ_DestroyLock(object->refLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1056|      0|        if (isSessionList) {
  ------------------
  |  Branch (1056:13): [True: 0, False: 0]
  ------------------
 1057|      0|            PZ_DestroyLock(((SFTKSessionObject *)object)->attributeLock);
  ------------------
  |  |  244|      0|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1058|      0|        }
 1059|      0|    }
 1060|      2|    list->count = 0;
 1061|      2|    list->head = NULL;
 1062|      2|    SKIP_AFTER_FORK(PZ_Unlock(list->lock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 1063|      2|    SKIP_AFTER_FORK(PZ_DestroyLock(list->lock));
  ------------------
  |  |  256|      2|#define SKIP_AFTER_FORK(x) x
  ------------------
 1064|      2|    list->lock = NULL;
 1065|      2|}
pkcs11u.c:sftk_ObjectFromHandleOnSlot:
 1201|  4.07M|{
 1202|  4.07M|    SFTKObject *object;
 1203|  4.07M|    PRUint32 index = sftk_hash(handle, slot->sessObjHashSize);
  ------------------
  |  |  513|  4.07M|    ((PRUint32)((value)*SHMULTIPLIER) & (size - 1))
  |  |  ------------------
  |  |  |  |  509|  4.07M|#define SHMULTIPLIER 1791398085
  |  |  ------------------
  ------------------
 1204|       |
 1205|  4.07M|    if (sftk_isToken(handle)) {
  ------------------
  |  |  504|  4.07M|#define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  478|  4.07M|#define SFTK_TOKEN_MASK 0x80000000L
  |  |  ------------------
  |  |               #define sftk_isToken(id) (((id)&SFTK_TOKEN_MASK) == SFTK_TOKEN_MAGIC)
  |  |  ------------------
  |  |  |  |  479|  4.07M|#define SFTK_TOKEN_MAGIC 0x80000000L
  |  |  ------------------
  |  |  |  Branch (504:26): [True: 0, False: 4.07M]
  |  |  ------------------
  ------------------
 1206|      0|        return sftk_NewTokenObject(slot, NULL, handle);
 1207|      0|    }
 1208|       |
 1209|  4.07M|    PZ_Lock(slot->objectLock);
  ------------------
  |  |  245|  4.07M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 1210|  4.07M|    sftkqueue_find2(object, handle, index, slot->sessObjHashTable);
  ------------------
  |  |  555|  4.07M|    for ((element) = (head)[index];               \
  |  |  556|  4.19M|         (element) != NULL;                       \
  |  |  ------------------
  |  |  |  Branch (556:10): [True: 4.19M, False: 0]
  |  |  ------------------
  |  |  557|  4.19M|         (element) = (element)->next) {           \
  |  |  558|  4.19M|        if ((element)->handle == (id)) {          \
  |  |  ------------------
  |  |  |  Branch (558:13): [True: 4.07M, False: 117k]
  |  |  ------------------
  |  |  559|  4.07M|            break;                                \
  |  |  560|  4.07M|        }                                         \
  |  |  561|  4.19M|    }
  ------------------
 1211|  4.07M|    if (object) {
  ------------------
  |  Branch (1211:9): [True: 4.07M, False: 0]
  ------------------
 1212|  4.07M|        sftk_ReferenceObject(object);
 1213|  4.07M|    }
 1214|  4.07M|    PZ_Unlock(slot->objectLock);
  ------------------
  |  |  246|  4.07M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1215|       |
 1216|  4.07M|    return (object);
 1217|  4.07M|}
pkcs11u.c:sftk_DestroyObject:
 1160|  1.35M|{
 1161|  1.35M|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|  1.35M|#define CKR_OK 0x00000000UL
  ------------------
 1162|  1.35M|    SFTKSessionObject *so = sftk_narrowToSessionObject(object);
 1163|  1.35M|    SFTKTokenObject *to = sftk_narrowToTokenObject(object);
 1164|       |
 1165|  1.35M|    PORT_Assert(object->refCount == 0);
  ------------------
  |  |  120|  1.35M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.35M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.35M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1166|       |
 1167|       |    /* delete the database value */
 1168|  1.35M|    if (to) {
  ------------------
  |  Branch (1168:9): [True: 0, False: 1.35M]
  ------------------
 1169|      0|        if (to->dbKey.data) {
  ------------------
  |  Branch (1169:13): [True: 0, False: 0]
  ------------------
 1170|      0|            PORT_Free(to->dbKey.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1171|      0|            to->dbKey.data = NULL;
 1172|      0|        }
 1173|      0|    }
 1174|  1.35M|    if (so) {
  ------------------
  |  Branch (1174:9): [True: 1.35M, False: 0]
  ------------------
 1175|  1.35M|        sftk_DestroySessionObjectData(so);
 1176|  1.35M|    }
 1177|  1.35M|    if (object->objectInfo) {
  ------------------
  |  Branch (1177:9): [True: 97.7k, False: 1.25M]
  ------------------
 1178|  97.7k|        (*object->infoFree)(object->objectInfo);
 1179|  97.7k|        object->objectInfo = NULL;
 1180|  97.7k|        object->infoFree = NULL;
 1181|  97.7k|    }
 1182|  1.35M|    if (so) {
  ------------------
  |  Branch (1182:9): [True: 1.35M, False: 0]
  ------------------
 1183|  1.35M|        sftk_PutObjectToList(object, &sessionObjectList, PR_TRUE);
  ------------------
  |  |  437|  1.35M|#define PR_TRUE 1
  ------------------
 1184|  1.35M|    } else {
 1185|      0|        sftk_PutObjectToList(object, &tokenObjectList, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1186|      0|    }
 1187|  1.35M|    return crv;
 1188|  1.35M|}
pkcs11u.c:sftk_PutObjectToList:
  989|  1.35M|{
  990|       |
  991|       |    /* the code below is equivalent to :
  992|       |     *     optimizeSpace = isSessionObject ? object->optimizeSpace : PR_FALSE;
  993|       |     * just faster.
  994|       |     */
  995|  1.35M|    PRBool optimizeSpace = isSessionObject &&
  ------------------
  |  Branch (995:28): [True: 1.35M, False: 0]
  ------------------
  996|  1.35M|                           ((SFTKSessionObject *)object)->optimizeSpace;
  ------------------
  |  Branch (996:28): [True: 1.35M, False: 0]
  ------------------
  997|  1.35M|    if (object->refLock && !optimizeSpace) {
  ------------------
  |  Branch (997:9): [True: 1.35M, False: 0]
  |  Branch (997:28): [True: 0, False: 1.35M]
  ------------------
  998|      0|        PZ_Lock(list->lock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  999|      0|        if (list->count < MAX_OBJECT_LIST_SIZE) {
  ------------------
  |  |   71|      0|#define MAX_OBJECT_LIST_SIZE 800
  ------------------
  |  Branch (999:13): [True: 0, False: 0]
  ------------------
 1000|      0|            object->next = list->head;
 1001|      0|            list->head = object;
 1002|      0|            list->count++;
 1003|      0|            PZ_Unlock(list->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1004|      0|            return;
 1005|      0|        }
 1006|      0|        PZ_Unlock(list->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 1007|      0|    }
 1008|  1.35M|    if (isSessionObject) {
  ------------------
  |  Branch (1008:9): [True: 1.35M, False: 0]
  ------------------
 1009|  1.35M|        SFTKSessionObject *so = (SFTKSessionObject *)object;
 1010|  1.35M|        PZ_DestroyLock(so->attributeLock);
  ------------------
  |  |  244|  1.35M|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1011|  1.35M|        so->attributeLock = NULL;
 1012|  1.35M|    }
 1013|  1.35M|    if (object->refLock) {
  ------------------
  |  Branch (1013:9): [True: 1.35M, False: 0]
  ------------------
 1014|  1.35M|        PZ_DestroyLock(object->refLock);
  ------------------
  |  |  244|  1.35M|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 1015|  1.35M|        object->refLock = NULL;
 1016|  1.35M|    }
 1017|  1.35M|    PORT_Free(object);
  ------------------
  |  |   60|  1.35M|#define PORT_Free PORT_Free_Util
  ------------------
 1018|  1.35M|}
pkcs11u.c:sftk_DestroySessionObjectData:
 1136|  1.35M|{
 1137|  1.35M|    int i;
 1138|       |
 1139|  62.3M|    for (i = 0; i < MAX_OBJS_ATTRS; i++) {
  ------------------
  |  |   37|  62.3M|#define MAX_OBJS_ATTRS 45 /* number of attributes to preallocate in \
  ------------------
  |  Branch (1139:17): [True: 61.0M, False: 1.35M]
  ------------------
 1140|  61.0M|        unsigned char *value = so->attrList[i].attrib.pValue;
 1141|  61.0M|        if (value) {
  ------------------
  |  Branch (1141:13): [True: 21.9M, False: 39.0M]
  ------------------
 1142|  21.9M|            PORT_Memset(value, 0, so->attrList[i].attrib.ulValueLen);
  ------------------
  |  |  182|  21.9M|#define PORT_Memset memset
  ------------------
 1143|  21.9M|            if (so->attrList[i].freeData) {
  ------------------
  |  Branch (1143:17): [True: 169k, False: 21.8M]
  ------------------
 1144|   169k|                PORT_Free(value);
  ------------------
  |  |   60|   169k|#define PORT_Free PORT_Free_Util
  ------------------
 1145|   169k|            }
 1146|  21.9M|            so->attrList[i].attrib.pValue = NULL;
 1147|  21.9M|            so->attrList[i].freeData = PR_FALSE;
  ------------------
  |  |  438|  21.9M|#define PR_FALSE 0
  ------------------
 1148|  21.9M|        }
 1149|  61.0M|    }
 1150|       |    /*  PZ_DestroyLock(so->attributeLock);*/
 1151|  1.35M|    return CKR_OK;
  ------------------
  |  | 1388|  1.35M|#define CKR_OK 0x00000000UL
  ------------------
 1152|  1.35M|}

s_shutdown:
 2461|      1|{
 2462|       |#ifdef SQLITE_UNSAFE_THREADS
 2463|       |    if (sqlite_lock) {
 2464|       |        PR_DestroyLock(sqlite_lock);
 2465|       |        sqlite_lock = NULL;
 2466|       |    }
 2467|       |#endif
 2468|      1|    return CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 2469|      1|}

sftkdb_FindObjectsInit:
 1341|  23.4k|{
 1342|  23.4k|    unsigned char *data = NULL;
 1343|  23.4k|    CK_ATTRIBUTE *ntemplate = NULL;
 1344|  23.4k|    CK_RV crv;
 1345|  23.4k|    int dataSize;
 1346|  23.4k|    SDB *db;
 1347|       |
 1348|  23.4k|    if (handle == NULL) {
  ------------------
  |  Branch (1348:9): [True: 23.4k, False: 0]
  ------------------
 1349|  23.4k|        return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 1350|  23.4k|    }
 1351|      0|    db = SFTK_GET_SDB(handle);
  ------------------
  |  |   40|      0|    ((handle)->update ? (handle)->update : (handle)->db)
  |  |  ------------------
  |  |  |  Branch (40:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1352|       |
 1353|      0|    if (count != 0) {
  ------------------
  |  Branch (1353:9): [True: 0, False: 0]
  ------------------
 1354|      0|        ntemplate = sftkdb_fixupTemplateIn(template, count, &data, &dataSize);
 1355|      0|        if (ntemplate == NULL) {
  ------------------
  |  Branch (1355:13): [True: 0, False: 0]
  ------------------
 1356|      0|            return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
 1357|      0|        }
 1358|      0|    }
 1359|       |
 1360|      0|    crv = (*db->sdb_FindObjectsInit)(db, ntemplate,
 1361|      0|                                     count, find);
 1362|      0|    if (data) {
  ------------------
  |  Branch (1362:9): [True: 0, False: 0]
  ------------------
 1363|      0|        PORT_Free(ntemplate);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1364|      0|        PORT_ZFree(data, dataSize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 1365|      0|    }
 1366|      0|    return crv;
 1367|      0|}
sftkdb_FindObjects:
 1372|  23.4k|{
 1373|  23.4k|    CK_RV crv;
 1374|  23.4k|    SDB *db;
 1375|       |
 1376|  23.4k|    if (handle == NULL) {
  ------------------
  |  Branch (1376:9): [True: 23.4k, False: 0]
  ------------------
 1377|  23.4k|        *count = 0;
 1378|  23.4k|        return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 1379|  23.4k|    }
 1380|      0|    db = SFTK_GET_SDB(handle);
  ------------------
  |  |   40|      0|    ((handle)->update ? (handle)->update : (handle)->db)
  |  |  ------------------
  |  |  |  Branch (40:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1381|       |
 1382|      0|    crv = (*db->sdb_FindObjects)(db, find, ids,
 1383|      0|                                 arraySize, count);
 1384|      0|    if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (1384:9): [True: 0, False: 0]
  ------------------
 1385|      0|        unsigned int i;
 1386|      0|        for (i = 0; i < *count; i++) {
  ------------------
  |  Branch (1386:21): [True: 0, False: 0]
  ------------------
 1387|      0|            ids[i] |= (handle->type | SFTK_TOKEN_TYPE);
  ------------------
  |  |   33|      0|#define SFTK_TOKEN_TYPE 0x80000000
  ------------------
 1388|      0|        }
 1389|      0|    }
 1390|      0|    return crv;
 1391|  23.4k|}
sftkdb_FindObjectsFinal:
 1395|  23.4k|{
 1396|  23.4k|    SDB *db;
 1397|  23.4k|    if (handle == NULL) {
  ------------------
  |  Branch (1397:9): [True: 23.4k, False: 0]
  ------------------
 1398|  23.4k|        return CKR_OK;
  ------------------
  |  | 1388|  23.4k|#define CKR_OK 0x00000000UL
  ------------------
 1399|  23.4k|    }
 1400|      0|    db = SFTK_GET_SDB(handle);
  ------------------
  |  |   40|      0|    ((handle)->update ? (handle)->update : (handle)->db)
  |  |  ------------------
  |  |  |  Branch (40:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1401|      0|    return (*db->sdb_FindObjectsFinal)(db, find);
 1402|  23.4k|}
sftk_freeDB:
 2621|  23.4k|{
 2622|  23.4k|    PRInt32 ref;
 2623|       |
 2624|  23.4k|    if (!handle)
  ------------------
  |  Branch (2624:9): [True: 23.4k, False: 0]
  ------------------
 2625|  23.4k|        return;
 2626|      0|    ref = PR_ATOMIC_DECREMENT(&handle->ref);
  ------------------
  |  |  123|      0|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
 2627|      0|    if (ref == 0) {
  ------------------
  |  Branch (2627:9): [True: 0, False: 0]
  ------------------
 2628|      0|        sftkdb_CloseDB(handle);
 2629|      0|    }
 2630|      0|    return;
 2631|  23.4k|}
sftk_getCertDB:
 2639|  23.4k|{
 2640|  23.4k|    SFTKDBHandle *dbHandle;
 2641|       |
 2642|  23.4k|    PZ_Lock(slot->slotLock);
  ------------------
  |  |  245|  23.4k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 2643|  23.4k|    dbHandle = slot->certDB;
 2644|  23.4k|    if (dbHandle) {
  ------------------
  |  Branch (2644:9): [True: 0, False: 23.4k]
  ------------------
 2645|      0|        (void)PR_ATOMIC_INCREMENT(&dbHandle->ref);
  ------------------
  |  |  122|      0|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
 2646|      0|    }
 2647|  23.4k|    PZ_Unlock(slot->slotLock);
  ------------------
  |  |  246|  23.4k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 2648|  23.4k|    return dbHandle;
 2649|  23.4k|}
sftk_getKeyDB:
 2657|   869k|{
 2658|   869k|    SFTKDBHandle *dbHandle;
 2659|       |
 2660|   869k|    SKIP_AFTER_FORK(PZ_Lock(slot->slotLock));
  ------------------
  |  |  256|   869k|#define SKIP_AFTER_FORK(x) x
  ------------------
 2661|   869k|    dbHandle = slot->keyDB;
 2662|   869k|    if (dbHandle) {
  ------------------
  |  Branch (2662:9): [True: 0, False: 869k]
  ------------------
 2663|      0|        (void)PR_ATOMIC_INCREMENT(&dbHandle->ref);
  ------------------
  |  |  122|      0|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
 2664|      0|    }
 2665|   869k|    SKIP_AFTER_FORK(PZ_Unlock(slot->slotLock));
  ------------------
  |  |  256|   869k|#define SKIP_AFTER_FORK(x) x
  ------------------
 2666|   869k|    return dbHandle;
 2667|   869k|}
sftkdb_Shutdown:
 3041|      1|{
 3042|      1|    s_shutdown();
 3043|       |#ifndef NSS_DISABLE_DBM
 3044|       |    sftkdbCall_Shutdown();
 3045|       |#endif /* NSS_DISABLE_DBM */
 3046|      1|    return CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
 3047|      1|}

sftk_VerifyDH_Prime:
 6741|  27.7k|{
 6742|       |    /* use the length to decide which primes to check */
 6743|  27.7k|    switch (dhPrime->len) {
  ------------------
  |  Branch (6743:13): [True: 0, False: 27.7k]
  ------------------
 6744|      0|        case 1536 / PR_BITS_PER_BYTE:
  ------------------
  |  |  286|      0|#define PR_BITS_PER_BYTE    8
  ------------------
  |  Branch (6744:9): [True: 0, False: 27.7k]
  ------------------
 6745|       |            /* don't accept 1536 bit primes in FIPS mode */
 6746|      0|            if (isFIPS) {
  ------------------
  |  Branch (6746:17): [True: 0, False: 0]
  ------------------
 6747|      0|                break;
 6748|      0|            }
 6749|      0|            if (PORT_Memcmp(dhPrime->data, prime_ike_1536,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6749:17): [True: 0, False: 0]
  ------------------
 6750|      0|                            sizeof(prime_ike_1536)) == 0) {
 6751|      0|                if (g)
  ------------------
  |  Branch (6751:21): [True: 0, False: 0]
  ------------------
 6752|      0|                    *g = generator_2;
 6753|      0|                return &subprime_ike_1536;
 6754|      0|            }
 6755|      0|            break;
 6756|  20.6k|        case 2048 / PR_BITS_PER_BYTE:
  ------------------
  |  |  286|  20.6k|#define PR_BITS_PER_BYTE    8
  ------------------
  |  Branch (6756:9): [True: 20.6k, False: 7.12k]
  ------------------
 6757|  20.6k|            if (PORT_Memcmp(dhPrime->data, prime_tls_2048,
  ------------------
  |  |  179|  20.6k|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6757:17): [True: 20.6k, False: 0]
  ------------------
 6758|  20.6k|                            sizeof(prime_tls_2048)) == 0) {
 6759|  20.6k|                if (g)
  ------------------
  |  Branch (6759:21): [True: 0, False: 20.6k]
  ------------------
 6760|      0|                    *g = generator_2;
 6761|  20.6k|                return &subprime_tls_2048;
 6762|  20.6k|            }
 6763|      0|            if (PORT_Memcmp(dhPrime->data, prime_ike_2048,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6763:17): [True: 0, False: 0]
  ------------------
 6764|      0|                            sizeof(prime_ike_2048)) == 0) {
 6765|      0|                if (g)
  ------------------
  |  Branch (6765:21): [True: 0, False: 0]
  ------------------
 6766|      0|                    *g = generator_2;
 6767|      0|                return &subprime_ike_2048;
 6768|      0|            }
 6769|      0|            break;
 6770|  3.19k|        case 3072 / PR_BITS_PER_BYTE:
  ------------------
  |  |  286|  3.19k|#define PR_BITS_PER_BYTE    8
  ------------------
  |  Branch (6770:9): [True: 3.19k, False: 24.5k]
  ------------------
 6771|  3.19k|            if (PORT_Memcmp(dhPrime->data, prime_tls_3072,
  ------------------
  |  |  179|  3.19k|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6771:17): [True: 3.19k, False: 0]
  ------------------
 6772|  3.19k|                            sizeof(prime_tls_3072)) == 0) {
 6773|  3.19k|                if (g)
  ------------------
  |  Branch (6773:21): [True: 0, False: 3.19k]
  ------------------
 6774|      0|                    *g = generator_2;
 6775|  3.19k|                return &subprime_tls_3072;
 6776|  3.19k|            }
 6777|      0|            if (PORT_Memcmp(dhPrime->data, prime_ike_3072,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6777:17): [True: 0, False: 0]
  ------------------
 6778|      0|                            sizeof(prime_ike_3072)) == 0) {
 6779|      0|                if (g)
  ------------------
  |  Branch (6779:21): [True: 0, False: 0]
  ------------------
 6780|      0|                    *g = generator_2;
 6781|      0|                return &subprime_ike_3072;
 6782|      0|            }
 6783|      0|            break;
 6784|    332|        case 4096 / PR_BITS_PER_BYTE:
  ------------------
  |  |  286|    332|#define PR_BITS_PER_BYTE    8
  ------------------
  |  Branch (6784:9): [True: 332, False: 27.3k]
  ------------------
 6785|    332|            if (PORT_Memcmp(dhPrime->data, prime_tls_4096,
  ------------------
  |  |  179|    332|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6785:17): [True: 332, False: 0]
  ------------------
 6786|    332|                            sizeof(prime_tls_4096)) == 0) {
 6787|    332|                if (g)
  ------------------
  |  Branch (6787:21): [True: 0, False: 332]
  ------------------
 6788|      0|                    *g = generator_2;
 6789|    332|                return &subprime_tls_4096;
 6790|    332|            }
 6791|      0|            if (PORT_Memcmp(dhPrime->data, prime_ike_4096,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6791:17): [True: 0, False: 0]
  ------------------
 6792|      0|                            sizeof(prime_ike_4096)) == 0) {
 6793|      0|                if (g)
  ------------------
  |  Branch (6793:21): [True: 0, False: 0]
  ------------------
 6794|      0|                    *g = generator_2;
 6795|      0|                return &subprime_ike_4096;
 6796|      0|            }
 6797|      0|            break;
 6798|  2.31k|        case 6144 / PR_BITS_PER_BYTE:
  ------------------
  |  |  286|  2.31k|#define PR_BITS_PER_BYTE    8
  ------------------
  |  Branch (6798:9): [True: 2.31k, False: 25.4k]
  ------------------
 6799|  2.31k|            if (PORT_Memcmp(dhPrime->data, prime_tls_6144,
  ------------------
  |  |  179|  2.31k|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6799:17): [True: 2.31k, False: 0]
  ------------------
 6800|  2.31k|                            sizeof(prime_tls_6144)) == 0) {
 6801|  2.31k|                if (g)
  ------------------
  |  Branch (6801:21): [True: 0, False: 2.31k]
  ------------------
 6802|      0|                    *g = generator_2;
 6803|  2.31k|                return &subprime_tls_6144;
 6804|  2.31k|            }
 6805|      0|            if (PORT_Memcmp(dhPrime->data, prime_ike_6144,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6805:17): [True: 0, False: 0]
  ------------------
 6806|      0|                            sizeof(prime_ike_6144)) == 0) {
 6807|      0|                if (g)
  ------------------
  |  Branch (6807:21): [True: 0, False: 0]
  ------------------
 6808|      0|                    *g = generator_2;
 6809|      0|                return &subprime_ike_6144;
 6810|      0|            }
 6811|      0|            break;
 6812|  1.28k|        case 8192 / PR_BITS_PER_BYTE:
  ------------------
  |  |  286|  1.28k|#define PR_BITS_PER_BYTE    8
  ------------------
  |  Branch (6812:9): [True: 1.28k, False: 26.4k]
  ------------------
 6813|  1.28k|            if (PORT_Memcmp(dhPrime->data, prime_tls_8192,
  ------------------
  |  |  179|  1.28k|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6813:17): [True: 1.28k, False: 0]
  ------------------
 6814|  1.28k|                            sizeof(prime_tls_8192)) == 0) {
 6815|  1.28k|                if (g)
  ------------------
  |  Branch (6815:21): [True: 0, False: 1.28k]
  ------------------
 6816|      0|                    *g = generator_2;
 6817|  1.28k|                return &subprime_tls_8192;
 6818|  1.28k|            }
 6819|      0|            if (PORT_Memcmp(dhPrime->data, prime_ike_8192,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (6819:17): [True: 0, False: 0]
  ------------------
 6820|      0|                            sizeof(prime_ike_8192)) == 0) {
 6821|      0|                if (g)
  ------------------
  |  Branch (6821:21): [True: 0, False: 0]
  ------------------
 6822|      0|                    *g = generator_2;
 6823|      0|                return &subprime_ike_8192;
 6824|      0|            }
 6825|      0|            break;
 6826|  27.7k|    }
 6827|       |    /* no match found, return an error */
 6828|      0|    PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6829|      0|    return NULL;
 6830|  27.7k|}

sftk_HMACMechanismToHash:
   31|  60.4k|{
   32|  60.4k|    switch (mech) {
  ------------------
  |  Branch (32:13): [True: 0, False: 60.4k]
  ------------------
   33|      0|        case CKM_MD2_HMAC:
  ------------------
  |  |  850|      0|#define CKM_MD2_HMAC 0x00000201UL
  ------------------
  |  Branch (33:9): [True: 0, False: 60.4k]
  ------------------
   34|      0|            return HASH_AlgMD2;
   35|  4.87k|        case CKM_MD5_HMAC:
  ------------------
  |  |  856|  4.87k|#define CKM_MD5_HMAC 0x00000211UL
  ------------------
  |  Branch (35:9): [True: 4.87k, False: 55.6k]
  ------------------
   36|  4.87k|        case CKM_SSL3_MD5_MAC:
  ------------------
  |  |  975|  4.87k|#define CKM_SSL3_MD5_MAC 0x00000380UL
  ------------------
  |  Branch (36:9): [True: 0, False: 60.4k]
  ------------------
   37|  4.87k|            return HASH_AlgMD5;
   38|  51.7k|        case CKM_SHA_1_HMAC:
  ------------------
  |  |  862|  51.7k|#define CKM_SHA_1_HMAC 0x00000221UL
  ------------------
  |  Branch (38:9): [True: 51.7k, False: 8.72k]
  ------------------
   39|  51.7k|        case CKM_SSL3_SHA1_MAC:
  ------------------
  |  |  976|  51.7k|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
  |  Branch (39:9): [True: 0, False: 60.4k]
  ------------------
   40|  51.7k|            return HASH_AlgSHA1;
   41|      0|        case CKM_SHA224_HMAC:
  ------------------
  |  |  888|      0|#define CKM_SHA224_HMAC 0x00000256UL
  ------------------
  |  Branch (41:9): [True: 0, False: 60.4k]
  ------------------
   42|      0|            return HASH_AlgSHA224;
   43|  2.22k|        case CKM_SHA256_HMAC:
  ------------------
  |  |  877|  2.22k|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  |  Branch (43:9): [True: 2.22k, False: 58.2k]
  ------------------
   44|  2.22k|            return HASH_AlgSHA256;
   45|  1.62k|        case CKM_SHA384_HMAC:
  ------------------
  |  |  880|  1.62k|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  |  Branch (45:9): [True: 1.62k, False: 58.8k]
  ------------------
   46|  1.62k|            return HASH_AlgSHA384;
   47|      0|        case CKM_SHA512_HMAC:
  ------------------
  |  |  883|      0|#define CKM_SHA512_HMAC 0x00000271UL
  ------------------
  |  Branch (47:9): [True: 0, False: 60.4k]
  ------------------
   48|      0|            return HASH_AlgSHA512;
   49|      0|        case CKM_SHA3_224_HMAC:
  ------------------
  |  |  903|      0|#define CKM_SHA3_224_HMAC 0x000002B6UL
  ------------------
  |  Branch (49:9): [True: 0, False: 60.4k]
  ------------------
   50|      0|            return HASH_AlgSHA3_224;
   51|      0|        case CKM_SHA3_256_HMAC:
  ------------------
  |  |  899|      0|#define CKM_SHA3_256_HMAC 0x000002B1UL
  ------------------
  |  Branch (51:9): [True: 0, False: 60.4k]
  ------------------
   52|      0|            return HASH_AlgSHA3_256;
   53|      0|        case CKM_SHA3_384_HMAC:
  ------------------
  |  |  907|      0|#define CKM_SHA3_384_HMAC 0x000002C1UL
  ------------------
  |  Branch (53:9): [True: 0, False: 60.4k]
  ------------------
   54|      0|            return HASH_AlgSHA3_384;
   55|      0|        case CKM_SHA3_512_HMAC:
  ------------------
  |  |  911|      0|#define CKM_SHA3_512_HMAC 0x000002D1UL
  ------------------
  |  Branch (55:9): [True: 0, False: 60.4k]
  ------------------
   56|      0|            return HASH_AlgSHA3_512;
   57|  60.4k|    }
   58|      0|    return HASH_AlgNULL;
   59|  60.4k|}
sftk_MAC_Create:
  221|  60.4k|{
  222|  60.4k|    CK_RV ret;
  223|       |
  224|  60.4k|    if (ret_ctx == NULL || key == NULL) {
  ------------------
  |  Branch (224:9): [True: 0, False: 60.4k]
  |  Branch (224:28): [True: 0, False: 60.4k]
  ------------------
  225|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  226|      0|    }
  227|       |
  228|  60.4k|    *ret_ctx = PORT_New(sftk_MACCtx);
  ------------------
  |  |  151|  60.4k|#define PORT_New(type) (type *)PORT_Alloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   52|  60.4k|#define PORT_Alloc PORT_Alloc_Util
  |  |  ------------------
  ------------------
  229|  60.4k|    if (*ret_ctx == NULL) {
  ------------------
  |  Branch (229:9): [True: 0, False: 60.4k]
  ------------------
  230|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  231|      0|    }
  232|       |
  233|  60.4k|    ret = sftk_MAC_Init(*ret_ctx, mech, key);
  234|  60.4k|    if (ret != CKR_OK) {
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (234:9): [True: 0, False: 60.4k]
  ------------------
  235|      0|        sftk_MAC_DestroyContext(*ret_ctx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  236|      0|    }
  237|       |
  238|  60.4k|    return ret;
  239|  60.4k|}
sftk_MAC_Init:
  243|  60.4k|{
  244|  60.4k|    SFTKAttribute *keyval = NULL;
  245|  60.4k|    PRBool isFIPS = sftk_isFIPS(key->slot->slotID);
  ------------------
  |  |  506|  60.4k|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|  60.4k|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|  60.4k|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 60.4k]
  |  |  |  Branch (506:32): [True: 0, False: 60.4k]
  |  |  ------------------
  ------------------
  246|  60.4k|    CK_RV ret = CKR_OK;
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  247|       |
  248|       |    /* Find the actual value of the key. */
  249|  60.4k|    keyval = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|  60.4k|#define CKA_VALUE 0x00000011UL
  ------------------
  250|  60.4k|    if (keyval == NULL) {
  ------------------
  |  Branch (250:9): [True: 0, False: 60.4k]
  ------------------
  251|      0|        ret = CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
  252|      0|        goto done;
  253|      0|    }
  254|       |
  255|  60.4k|    ret = sftk_MAC_InitRaw(ctx, mech,
  256|  60.4k|                           (const unsigned char *)keyval->attrib.pValue,
  257|  60.4k|                           keyval->attrib.ulValueLen, isFIPS);
  258|       |
  259|  60.4k|done:
  260|  60.4k|    if (keyval) {
  ------------------
  |  Branch (260:9): [True: 60.4k, False: 0]
  ------------------
  261|  60.4k|        sftk_FreeAttribute(keyval);
  262|  60.4k|    }
  263|  60.4k|    return ret;
  264|  60.4k|}
sftk_MAC_InitRaw:
  268|  60.4k|{
  269|  60.4k|    const SECHashObject *hashObj = NULL;
  270|  60.4k|    CK_RV ret = CKR_OK;
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  271|       |
  272|  60.4k|    if (ctx == NULL) {
  ------------------
  |  Branch (272:9): [True: 0, False: 60.4k]
  ------------------
  273|      0|        return CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  274|      0|    }
  275|       |
  276|       |    /* Clear the context before use. */
  277|  60.4k|    PORT_Memset(ctx, 0, sizeof(*ctx));
  ------------------
  |  |  182|  60.4k|#define PORT_Memset memset
  ------------------
  278|       |
  279|       |    /* Save the mech. */
  280|  60.4k|    ctx->mech = mech;
  281|       |
  282|       |    /* Initialize the correct MAC context. */
  283|  60.4k|    switch (mech) {
  284|      0|        case CKM_MD2_HMAC:
  ------------------
  |  |  850|      0|#define CKM_MD2_HMAC 0x00000201UL
  ------------------
  |  Branch (284:9): [True: 0, False: 60.4k]
  ------------------
  285|  4.87k|        case CKM_MD5_HMAC:
  ------------------
  |  |  856|  4.87k|#define CKM_MD5_HMAC 0x00000211UL
  ------------------
  |  Branch (285:9): [True: 4.87k, False: 55.6k]
  ------------------
  286|  56.6k|        case CKM_SHA_1_HMAC:
  ------------------
  |  |  862|  56.6k|#define CKM_SHA_1_HMAC 0x00000221UL
  ------------------
  |  Branch (286:9): [True: 51.7k, False: 8.72k]
  ------------------
  287|  56.6k|        case CKM_SHA224_HMAC:
  ------------------
  |  |  888|  56.6k|#define CKM_SHA224_HMAC 0x00000256UL
  ------------------
  |  Branch (287:9): [True: 0, False: 60.4k]
  ------------------
  288|  58.8k|        case CKM_SHA256_HMAC:
  ------------------
  |  |  877|  58.8k|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  |  Branch (288:9): [True: 2.22k, False: 58.2k]
  ------------------
  289|  60.4k|        case CKM_SHA384_HMAC:
  ------------------
  |  |  880|  60.4k|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  |  Branch (289:9): [True: 1.62k, False: 58.8k]
  ------------------
  290|  60.4k|        case CKM_SHA512_HMAC:
  ------------------
  |  |  883|  60.4k|#define CKM_SHA512_HMAC 0x00000271UL
  ------------------
  |  Branch (290:9): [True: 0, False: 60.4k]
  ------------------
  291|  60.4k|        case CKM_SHA3_224_HMAC:
  ------------------
  |  |  903|  60.4k|#define CKM_SHA3_224_HMAC 0x000002B6UL
  ------------------
  |  Branch (291:9): [True: 0, False: 60.4k]
  ------------------
  292|  60.4k|        case CKM_SHA3_256_HMAC:
  ------------------
  |  |  899|  60.4k|#define CKM_SHA3_256_HMAC 0x000002B1UL
  ------------------
  |  Branch (292:9): [True: 0, False: 60.4k]
  ------------------
  293|  60.4k|        case CKM_SHA3_384_HMAC:
  ------------------
  |  |  907|  60.4k|#define CKM_SHA3_384_HMAC 0x000002C1UL
  ------------------
  |  Branch (293:9): [True: 0, False: 60.4k]
  ------------------
  294|  60.4k|        case CKM_SHA3_512_HMAC:
  ------------------
  |  |  911|  60.4k|#define CKM_SHA3_512_HMAC 0x000002D1UL
  ------------------
  |  Branch (294:9): [True: 0, False: 60.4k]
  ------------------
  295|  60.4k|            hashObj = HASH_GetRawHashObject(sftk_HMACMechanismToHash(mech));
  296|       |
  297|       |            /* Because we condition above only on hashes we know to be valid,
  298|       |             * hashObj should never be NULL. This assert is only useful when
  299|       |             * adding a new hash function (for which only partial support has
  300|       |             * been added); thus there is no need to turn it into an if and
  301|       |             * avoid the NULL dereference on the following line. */
  302|  60.4k|            PR_ASSERT(hashObj != NULL);
  ------------------
  |  |  208|  60.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 60.4k, False: 0]
  |  |  ------------------
  ------------------
  303|  60.4k|            ctx->mac_size = hashObj->length;
  304|       |
  305|  60.4k|            goto hmac;
  306|      0|        case CKM_AES_CMAC:
  ------------------
  |  | 1119|      0|#define CKM_AES_CMAC 0x0000108AUL
  ------------------
  |  Branch (306:9): [True: 0, False: 60.4k]
  ------------------
  307|      0|            ctx->mac.cmac = CMAC_Create(CMAC_AES, key, key_len);
  308|      0|            ctx->destroy_func = SFTKMAC_CMAC_Destroy;
  309|       |
  310|       |            /* Copy the behavior of sftk_doCMACInit here. */
  311|      0|            if (ctx->mac.cmac == NULL) {
  ------------------
  |  Branch (311:17): [True: 0, False: 0]
  ------------------
  312|      0|                if (PORT_GetError() == SEC_ERROR_INVALID_ARGS) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (312:21): [True: 0, False: 0]
  ------------------
  313|      0|                    ret = CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
  314|      0|                    goto done;
  315|      0|                }
  316|       |
  317|      0|                ret = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  318|      0|                goto done;
  319|      0|            }
  320|       |
  321|      0|            ctx->mac_size = AES_BLOCK_SIZE;
  ------------------
  |  |  130|      0|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  322|       |
  323|      0|            goto done;
  324|      0|        default:
  ------------------
  |  Branch (324:9): [True: 0, False: 60.4k]
  ------------------
  325|      0|            ret = CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
  326|      0|            goto done;
  327|  60.4k|    }
  328|       |
  329|  60.4k|hmac:
  330|  60.4k|    ctx->mac.hmac = HMAC_Create(hashObj, key, key_len, isFIPS);
  331|  60.4k|    ctx->destroy_func = SFTKMAC_HMAC_Destroy;
  332|       |
  333|       |    /* Copy the behavior of sftk_doHMACInit here. */
  334|  60.4k|    if (ctx->mac.hmac == NULL) {
  ------------------
  |  Branch (334:9): [True: 0, False: 60.4k]
  ------------------
  335|      0|        if (PORT_GetError() == SEC_ERROR_INVALID_ARGS) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (335:13): [True: 0, False: 0]
  ------------------
  336|      0|            ret = CKR_KEY_SIZE_RANGE;
  ------------------
  |  | 1432|      0|#define CKR_KEY_SIZE_RANGE 0x00000062UL
  ------------------
  337|      0|            goto done;
  338|      0|        }
  339|      0|        ret = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|      0|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  340|      0|        goto done;
  341|      0|    }
  342|       |
  343|       |    /* Semantics: HMAC and CMAC should behave the same. Begin HMAC now. */
  344|  60.4k|    HMAC_Begin(ctx->mac.hmac);
  345|       |
  346|  60.4k|done:
  347|       |    /* Handle a failure: ctx->mac.raw should be NULL, but make sure
  348|       |     * destroy_func isn't set. */
  349|  60.4k|    if (ret != CKR_OK) {
  ------------------
  |  | 1388|  60.4k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (349:9): [True: 0, False: 60.4k]
  ------------------
  350|      0|        ctx->destroy_func = NULL;
  351|      0|    }
  352|       |
  353|  60.4k|    return ret;
  354|  60.4k|}
sftk_MAC_Update:
  394|  1.63k|{
  395|  1.63k|    switch (ctx->mech) {
  396|      0|        case CKM_MD2_HMAC:
  ------------------
  |  |  850|      0|#define CKM_MD2_HMAC 0x00000201UL
  ------------------
  |  Branch (396:9): [True: 0, False: 1.63k]
  ------------------
  397|      0|        case CKM_MD5_HMAC:
  ------------------
  |  |  856|      0|#define CKM_MD5_HMAC 0x00000211UL
  ------------------
  |  Branch (397:9): [True: 0, False: 1.63k]
  ------------------
  398|      0|        case CKM_SHA_1_HMAC:
  ------------------
  |  |  862|      0|#define CKM_SHA_1_HMAC 0x00000221UL
  ------------------
  |  Branch (398:9): [True: 0, False: 1.63k]
  ------------------
  399|      0|        case CKM_SHA224_HMAC:
  ------------------
  |  |  888|      0|#define CKM_SHA224_HMAC 0x00000256UL
  ------------------
  |  Branch (399:9): [True: 0, False: 1.63k]
  ------------------
  400|    769|        case CKM_SHA256_HMAC:
  ------------------
  |  |  877|    769|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  |  Branch (400:9): [True: 769, False: 861]
  ------------------
  401|  1.63k|        case CKM_SHA384_HMAC:
  ------------------
  |  |  880|  1.63k|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  |  Branch (401:9): [True: 861, False: 769]
  ------------------
  402|  1.63k|        case CKM_SHA512_HMAC:
  ------------------
  |  |  883|  1.63k|#define CKM_SHA512_HMAC 0x00000271UL
  ------------------
  |  Branch (402:9): [True: 0, False: 1.63k]
  ------------------
  403|  1.63k|        case CKM_SHA3_224_HMAC:
  ------------------
  |  |  903|  1.63k|#define CKM_SHA3_224_HMAC 0x000002B6UL
  ------------------
  |  Branch (403:9): [True: 0, False: 1.63k]
  ------------------
  404|  1.63k|        case CKM_SHA3_256_HMAC:
  ------------------
  |  |  899|  1.63k|#define CKM_SHA3_256_HMAC 0x000002B1UL
  ------------------
  |  Branch (404:9): [True: 0, False: 1.63k]
  ------------------
  405|  1.63k|        case CKM_SHA3_384_HMAC:
  ------------------
  |  |  907|  1.63k|#define CKM_SHA3_384_HMAC 0x000002C1UL
  ------------------
  |  Branch (405:9): [True: 0, False: 1.63k]
  ------------------
  406|  1.63k|        case CKM_SHA3_512_HMAC:
  ------------------
  |  |  911|  1.63k|#define CKM_SHA3_512_HMAC 0x000002D1UL
  ------------------
  |  Branch (406:9): [True: 0, False: 1.63k]
  ------------------
  407|       |            /* HMAC doesn't indicate failure in the return code. */
  408|  1.63k|            HMAC_Update(ctx->mac.hmac, data, data_len);
  409|  1.63k|            break;
  410|      0|        case CKM_AES_CMAC:
  ------------------
  |  | 1119|      0|#define CKM_AES_CMAC 0x0000108AUL
  ------------------
  |  Branch (410:9): [True: 0, False: 1.63k]
  ------------------
  411|       |            /* CMAC indicates failure in the return code, however this is
  412|       |             * unlikely to occur. */
  413|      0|            if (CMAC_Update(ctx->mac.cmac, data, data_len) != SECSuccess) {
  ------------------
  |  Branch (413:17): [True: 0, False: 0]
  ------------------
  414|      0|                return CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
  415|      0|            }
  416|      0|            break;
  417|      0|        default:
  ------------------
  |  Branch (417:9): [True: 0, False: 1.63k]
  ------------------
  418|       |            /* This shouldn't happen -- asserting indicates partial support
  419|       |             * for a new MAC type. */
  420|      0|            PR_ASSERT(PR_FALSE);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  421|      0|            return CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
  422|  1.63k|    }
  423|  1.63k|    return CKR_OK;
  ------------------
  |  | 1388|  1.63k|#define CKR_OK 0x00000000UL
  ------------------
  424|  1.63k|}
sftk_MAC_End:
  428|  1.63k|{
  429|  1.63k|    unsigned int actual_result_len;
  430|       |
  431|  1.63k|    switch (ctx->mech) {
  432|      0|        case CKM_MD2_HMAC:
  ------------------
  |  |  850|      0|#define CKM_MD2_HMAC 0x00000201UL
  ------------------
  |  Branch (432:9): [True: 0, False: 1.63k]
  ------------------
  433|      0|        case CKM_MD5_HMAC:
  ------------------
  |  |  856|      0|#define CKM_MD5_HMAC 0x00000211UL
  ------------------
  |  Branch (433:9): [True: 0, False: 1.63k]
  ------------------
  434|      0|        case CKM_SHA_1_HMAC:
  ------------------
  |  |  862|      0|#define CKM_SHA_1_HMAC 0x00000221UL
  ------------------
  |  Branch (434:9): [True: 0, False: 1.63k]
  ------------------
  435|      0|        case CKM_SHA224_HMAC:
  ------------------
  |  |  888|      0|#define CKM_SHA224_HMAC 0x00000256UL
  ------------------
  |  Branch (435:9): [True: 0, False: 1.63k]
  ------------------
  436|    769|        case CKM_SHA256_HMAC:
  ------------------
  |  |  877|    769|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  |  Branch (436:9): [True: 769, False: 861]
  ------------------
  437|  1.63k|        case CKM_SHA384_HMAC:
  ------------------
  |  |  880|  1.63k|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  |  Branch (437:9): [True: 861, False: 769]
  ------------------
  438|  1.63k|        case CKM_SHA512_HMAC:
  ------------------
  |  |  883|  1.63k|#define CKM_SHA512_HMAC 0x00000271UL
  ------------------
  |  Branch (438:9): [True: 0, False: 1.63k]
  ------------------
  439|  1.63k|        case CKM_SHA3_224_HMAC:
  ------------------
  |  |  903|  1.63k|#define CKM_SHA3_224_HMAC 0x000002B6UL
  ------------------
  |  Branch (439:9): [True: 0, False: 1.63k]
  ------------------
  440|  1.63k|        case CKM_SHA3_256_HMAC:
  ------------------
  |  |  899|  1.63k|#define CKM_SHA3_256_HMAC 0x000002B1UL
  ------------------
  |  Branch (440:9): [True: 0, False: 1.63k]
  ------------------
  441|  1.63k|        case CKM_SHA3_384_HMAC:
  ------------------
  |  |  907|  1.63k|#define CKM_SHA3_384_HMAC 0x000002C1UL
  ------------------
  |  Branch (441:9): [True: 0, False: 1.63k]
  ------------------
  442|  1.63k|        case CKM_SHA3_512_HMAC:
  ------------------
  |  |  911|  1.63k|#define CKM_SHA3_512_HMAC 0x000002D1UL
  ------------------
  |  Branch (442:9): [True: 0, False: 1.63k]
  ------------------
  443|       |            /* HMAC doesn't indicate failure in the return code. Additionally,
  444|       |             * unlike CMAC, it doesn't support partial results. This means that we
  445|       |             * need to allocate a buffer if max_result_len < ctx->mac_size. */
  446|  1.63k|            if (max_result_len >= ctx->mac_size) {
  ------------------
  |  Branch (446:17): [True: 1.63k, False: 0]
  ------------------
  447|       |                /* Split this into two calls to avoid an unnecessary stack
  448|       |                 * allocation and memcpy when possible. */
  449|  1.63k|                HMAC_Finish(ctx->mac.hmac, result, &actual_result_len, max_result_len);
  450|  1.63k|            } else {
  451|      0|                uint8_t tmp_buffer[SFTK_MAX_MAC_LENGTH];
  452|       |
  453|       |                /* Assumption: buffer is large enough to hold this HMAC's
  454|       |                 * output. */
  455|      0|                PR_ASSERT(SFTK_MAX_MAC_LENGTH >= ctx->mac_size);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  456|       |
  457|      0|                HMAC_Finish(ctx->mac.hmac, tmp_buffer, &actual_result_len, SFTK_MAX_MAC_LENGTH);
  ------------------
  |  |  255|      0|#define SFTK_MAX_MAC_LENGTH 64
  ------------------
  458|       |
  459|      0|                if (actual_result_len > max_result_len) {
  ------------------
  |  Branch (459:21): [True: 0, False: 0]
  ------------------
  460|       |                    /* This should always be true since:
  461|       |                     *
  462|       |                     *   (SFTK_MAX_MAC_LENGTH >= ctx->mac_size =
  463|       |                     *       actual_result_len) > max_result_len,
  464|       |                     *
  465|       |                     * but guard this truncation just in case. */
  466|      0|                    actual_result_len = max_result_len;
  467|      0|                }
  468|       |
  469|      0|                PORT_Memcpy(result, tmp_buffer, actual_result_len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  470|      0|            }
  471|  1.63k|            break;
  472|      0|        case CKM_AES_CMAC:
  ------------------
  |  | 1119|      0|#define CKM_AES_CMAC 0x0000108AUL
  ------------------
  |  Branch (472:9): [True: 0, False: 1.63k]
  ------------------
  473|       |            /* CMAC indicates failure in the return code, however this is
  474|       |             * unlikely to occur. */
  475|      0|            if (CMAC_Finish(ctx->mac.cmac, result, &actual_result_len, max_result_len) != SECSuccess) {
  ------------------
  |  Branch (475:17): [True: 0, False: 0]
  ------------------
  476|      0|                return CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
  477|      0|            }
  478|      0|            break;
  479|      0|        default:
  ------------------
  |  Branch (479:9): [True: 0, False: 1.63k]
  ------------------
  480|       |            /* This shouldn't happen -- asserting indicates partial support
  481|       |             * for a new MAC type. */
  482|      0|            PR_ASSERT(PR_FALSE);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  ------------------
  ------------------
  483|      0|            return CKR_FUNCTION_FAILED;
  ------------------
  |  | 1397|      0|#define CKR_FUNCTION_FAILED 0x00000006UL
  ------------------
  484|  1.63k|    }
  485|       |
  486|  1.63k|    if (result_len) {
  ------------------
  |  Branch (486:9): [True: 1.63k, False: 0]
  ------------------
  487|       |        /* When result length is passed, inform the caller of its value. */
  488|  1.63k|        *result_len = actual_result_len;
  489|  1.63k|    } else if (max_result_len == ctx->mac_size) {
  ------------------
  |  Branch (489:16): [True: 0, False: 0]
  ------------------
  490|       |        /* Validate that the amount requested was what was actually given; the
  491|       |         * caller assumes that what they passed was the output size of the
  492|       |         * underlying MAC and that they got all the bytes the asked for. */
  493|      0|        PR_ASSERT(actual_result_len == max_result_len);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  494|      0|    }
  495|       |
  496|  1.63k|    return CKR_OK;
  ------------------
  |  | 1388|  1.63k|#define CKR_OK 0x00000000UL
  ------------------
  497|  1.63k|}
sftk_MAC_DestroyContext:
  501|  60.4k|{
  502|  60.4k|    if (ctx == NULL) {
  ------------------
  |  Branch (502:9): [True: 0, False: 60.4k]
  ------------------
  503|      0|        return;
  504|      0|    }
  505|       |
  506|  60.4k|    if (ctx->mac.raw != NULL && ctx->destroy_func != NULL) {
  ------------------
  |  Branch (506:9): [True: 60.4k, False: 0]
  |  Branch (506:33): [True: 60.4k, False: 0]
  ------------------
  507|  60.4k|        ctx->destroy_func(ctx->mac.raw, PR_TRUE);
  ------------------
  |  |  437|  60.4k|#define PR_TRUE 1
  ------------------
  508|  60.4k|    }
  509|       |
  510|       |    /* Clean up the struct so we don't double free accidentally. */
  511|  60.4k|    PORT_Memset(ctx, 0, sizeof(sftk_MACCtx));
  ------------------
  |  |  182|  60.4k|#define PORT_Memset memset
  ------------------
  512|       |
  513|  60.4k|    if (free_it == PR_TRUE) {
  ------------------
  |  |  437|  60.4k|#define PR_TRUE 1
  ------------------
  |  Branch (513:9): [True: 60.4k, False: 0]
  ------------------
  514|  60.4k|        PORT_Free(ctx);
  ------------------
  |  |   60|  60.4k|#define PORT_Free PORT_Free_Util
  ------------------
  515|  60.4k|    }
  516|  60.4k|}
sftkhmac.c:SFTKMAC_HMAC_Destroy:
   22|  60.4k|{
   23|  60.4k|    HMACContext *hctx = ctx;
   24|  60.4k|    HMAC_Destroy(hctx, freeit);
   25|  60.4k|}

sftk_ChaCha20Poly1305_DestroyContext:
   50|  4.75k|{
   51|  4.75k|    ChaCha20Poly1305Context *ctx = vctx;
   52|  4.75k|    ChaCha20Poly1305_DestroyContext(ctx, freeit);
   53|  4.75k|}
sftk_AES_DestroyContext:
   70|   326k|{
   71|   326k|    AESContext *actx = ctx;
   72|   326k|    AES_DestroyContext(actx, freeit);
   73|   326k|}
NSC_MessageEncryptInit:
  233|   161k|{
  234|   161k|    return sftk_MessageCryptInit(hSession, pMechanism, hKey,
  235|   161k|                                 SFTK_MESSAGE_ENCRYPT, CKA_ENCRYPT, PR_TRUE);
  ------------------
  |  |  547|   161k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
                                               SFTK_MESSAGE_ENCRYPT, CKA_ENCRYPT, PR_TRUE);
  ------------------
  |  |  437|   161k|#define PR_TRUE 1
  ------------------
  236|   161k|}
NSC_MessageDecryptInit:
  284|   169k|{
  285|   169k|    return sftk_MessageCryptInit(hSession, pMechanism, hKey,
  286|   169k|                                 SFTK_MESSAGE_DECRYPT, CKA_DECRYPT, PR_FALSE);
  ------------------
  |  |  548|   169k|#define CKA_DECRYPT 0x00000105UL
  ------------------
                                               SFTK_MESSAGE_DECRYPT, CKA_DECRYPT, PR_FALSE);
  ------------------
  |  |  438|   169k|#define PR_FALSE 0
  ------------------
  287|   169k|}
sftkmessage.c:sftk_MessageCryptInit:
   86|   331k|{
   87|   331k|    SFTKSession *session;
   88|   331k|    SFTKObject *key;
   89|   331k|    SFTKSessionContext *context;
   90|   331k|    SFTKAttribute *att;
   91|   331k|    CK_KEY_TYPE key_type;
   92|   331k|    CK_RV crv = CKR_OK;
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
   93|       |
   94|   331k|    if (!pMechanism) {
  ------------------
  |  Branch (94:9): [True: 0, False: 331k]
  ------------------
   95|      0|        return CKR_MECHANISM_PARAM_INVALID;
  ------------------
  |  | 1448|      0|#define CKR_MECHANISM_PARAM_INVALID 0x00000071UL
  ------------------
   96|      0|    }
   97|       |
   98|   331k|    crv = sftk_MechAllowsOperation(pMechanism->mechanism,
   99|   331k|                                   CKA_NSS_MESSAGE | operation);
  ------------------
  |  |   69|   331k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
  100|   331k|    if (crv != CKR_OK)
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (100:9): [True: 0, False: 331k]
  ------------------
  101|      0|        return crv;
  102|       |
  103|   331k|    session = sftk_SessionFromHandle(hSession);
  104|   331k|    if (session == NULL)
  ------------------
  |  Branch (104:9): [True: 0, False: 331k]
  ------------------
  105|      0|        return CKR_SESSION_HANDLE_INVALID;
  ------------------
  |  | 1465|      0|#define CKR_SESSION_HANDLE_INVALID 0x000000B3UL
  ------------------
  106|       |
  107|   331k|    crv = sftk_InitGeneric(session, pMechanism, &context, contextType, &key,
  108|   331k|                           hKey, &key_type, CKO_SECRET_KEY, operation);
  ------------------
  |  |  329|   331k|#define CKO_SECRET_KEY 0x00000004UL
  ------------------
  109|   331k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (109:9): [True: 0, False: 331k]
  ------------------
  110|      0|        sftk_FreeSession(session);
  111|      0|        return crv;
  112|      0|    }
  113|       |
  114|   331k|    att = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|   331k|#define CKA_VALUE 0x00000011UL
  ------------------
  115|   331k|    if (att == NULL) {
  ------------------
  |  Branch (115:9): [True: 0, False: 331k]
  ------------------
  116|      0|        sftk_FreeSession(session);
  117|      0|        sftk_FreeContext(context);
  118|      0|        return CKR_KEY_HANDLE_INVALID;
  ------------------
  |  | 1428|      0|#define CKR_KEY_HANDLE_INVALID 0x00000060UL
  ------------------
  119|      0|    }
  120|       |
  121|   331k|    context->doPad = PR_FALSE;
  ------------------
  |  |  438|   331k|#define PR_FALSE 0
  ------------------
  122|   331k|    context->multi = PR_TRUE; /* All message are 'multi' operations */
  ------------------
  |  |  437|   331k|#define PR_TRUE 1
  ------------------
  123|       |
  124|   331k|    switch (pMechanism->mechanism) {
  125|   326k|        case CKM_AES_GCM:
  ------------------
  |  | 1115|   326k|#define CKM_AES_GCM 0x00001087UL
  ------------------
  |  Branch (125:9): [True: 326k, False: 4.75k]
  ------------------
  126|   326k|            context->cipherInfo = AES_CreateContext(
  127|   326k|                (unsigned char *)att->attrib.pValue,
  128|   326k|                NULL, NSS_AES_GCM, encrypt, att->attrib.ulValueLen,
  ------------------
  |  |   39|   326k|#define NSS_AES_GCM 4
  ------------------
  129|   326k|                AES_BLOCK_SIZE);
  ------------------
  |  |  130|   326k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  130|   326k|            context->aeadUpdate = sftk_AES_AEAD;
  131|   326k|            context->destroy = sftk_AES_DestroyContext;
  132|   326k|            break;
  133|  4.75k|        case CKM_CHACHA20_POLY1305:
  ------------------
  |  | 1287|  4.75k|#define CKM_CHACHA20_POLY1305 0x00004021UL
  ------------------
  |  Branch (133:9): [True: 4.75k, False: 326k]
  ------------------
  134|  4.75k|            context->cipherInfo = ChaCha20Poly1305_CreateContext(
  135|  4.75k|                (unsigned char *)att->attrib.pValue, att->attrib.ulValueLen,
  136|  4.75k|                16);
  137|  4.75k|            context->aeadUpdate = (encrypt ? sftk_ChaCha20_Poly1305_Message_Encrypt : sftk_ChaCha20_Poly1305_Message_Decrypt);
  ------------------
  |  Branch (137:36): [True: 1.98k, False: 2.76k]
  ------------------
  138|  4.75k|            context->destroy = sftk_ChaCha20Poly1305_DestroyContext;
  139|  4.75k|            break;
  140|      0|        default:
  ------------------
  |  Branch (140:9): [True: 0, False: 331k]
  ------------------
  141|      0|            crv = CKR_MECHANISM_INVALID;
  ------------------
  |  | 1447|      0|#define CKR_MECHANISM_INVALID 0x00000070UL
  ------------------
  142|      0|            break;
  143|   331k|    }
  144|   331k|    if (context->cipherInfo == NULL) {
  ------------------
  |  Branch (144:9): [True: 0, False: 331k]
  ------------------
  145|      0|        crv = sftk_MapCryptError(PORT_GetError());
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  146|      0|        if (crv == CKR_OK) {
  ------------------
  |  | 1388|      0|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (146:13): [True: 0, False: 0]
  ------------------
  147|      0|            crv = CKR_GENERAL_ERROR;
  ------------------
  |  | 1396|      0|#define CKR_GENERAL_ERROR 0x00000005UL
  ------------------
  148|      0|        }
  149|      0|    }
  150|   331k|    if (crv != CKR_OK) {
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
  |  Branch (150:9): [True: 0, False: 331k]
  ------------------
  151|      0|        sftk_FreeContext(context);
  152|      0|        sftk_FreeSession(session);
  153|      0|        return crv;
  154|      0|    }
  155|   331k|    sftk_SetContextByType(session, contextType, context);
  156|   331k|    sftk_FreeSession(session);
  157|   331k|    return CKR_OK;
  ------------------
  |  | 1388|   331k|#define CKR_OK 0x00000000UL
  ------------------
  158|   331k|}

sftk_parseParameters:
  127|      1|{
  128|      1|    int next;
  129|      1|    char *tmp = NULL;
  130|      1|    const char *index;
  131|      1|    char *certPrefix = NULL, *keyPrefix = NULL;
  132|      1|    char *tokdes = NULL, *ptokdes = NULL, *pupdtokdes = NULL;
  133|      1|    char *slotdes = NULL, *pslotdes = NULL;
  134|      1|    char *fslotdes = NULL, *ftokdes = NULL;
  135|      1|    char *minPW = NULL;
  136|      1|    index = NSSUTIL_ArgStrip(param);
  137|       |
  138|      1|    PORT_Memset(parsed, 0, sizeof(sftk_parameters));
  ------------------
  |  |  182|      1|#define PORT_Memset memset
  ------------------
  139|       |
  140|     11|    while (*index) {
  ------------------
  |  Branch (140:12): [True: 10, False: 1]
  ------------------
  141|     10|        NSSUTIL_HANDLE_STRING_ARG(index, parsed->configdir, "configDir=", ;)
  ------------------
  |  |   21|     10|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|     10|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 9]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  142|      9|        NSSUTIL_HANDLE_STRING_ARG(index, parsed->updatedir, "updateDir=", ;)
  ------------------
  |  |   21|      9|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      9|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 8]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  143|      8|        NSSUTIL_HANDLE_STRING_ARG(index, parsed->updateID, "updateID=", ;)
  ------------------
  |  |   21|      8|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      8|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 7]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  144|      7|        NSSUTIL_HANDLE_STRING_ARG(index, parsed->secmodName, "secmod=", ;)
  ------------------
  |  |   21|      7|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      7|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 6]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  145|      6|        NSSUTIL_HANDLE_STRING_ARG(index, parsed->man, "manufacturerID=", ;)
  ------------------
  |  |   21|      6|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      6|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 6]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  146|      6|        NSSUTIL_HANDLE_STRING_ARG(index, parsed->libdes, "libraryDescription=", ;)
  ------------------
  |  |   21|      6|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      6|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 6]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  147|       |        /* constructed values, used so legacy interfaces still work */
  148|      6|        NSSUTIL_HANDLE_STRING_ARG(index, certPrefix, "certPrefix=", ;)
  ------------------
  |  |   21|      6|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      6|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 5]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  149|      5|        NSSUTIL_HANDLE_STRING_ARG(index, keyPrefix, "keyPrefix=", ;)
  ------------------
  |  |   21|      5|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      5|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 4]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  150|      4|        NSSUTIL_HANDLE_STRING_ARG(index, tokdes, "cryptoTokenDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  151|      4|        NSSUTIL_HANDLE_STRING_ARG(index, ptokdes, "dbTokenDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  152|      4|        NSSUTIL_HANDLE_STRING_ARG(index, slotdes, "cryptoSlotDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  153|      4|        NSSUTIL_HANDLE_STRING_ARG(index, pslotdes, "dbSlotDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  154|      4|        NSSUTIL_HANDLE_STRING_ARG(index, fslotdes, "FIPSSlotDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  155|      4|        NSSUTIL_HANDLE_STRING_ARG(index, ftokdes, "FIPSTokenDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 4]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  156|      4|        NSSUTIL_HANDLE_STRING_ARG(index, pupdtokdes, "updateTokenDescription=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 3]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  157|      3|        NSSUTIL_HANDLE_STRING_ARG(index, minPW, "minPWLen=", ;)
  ------------------
  |  |   21|      3|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      3|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 3]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  158|       |
  159|      3|        NSSUTIL_HANDLE_STRING_ARG(
  ------------------
  |  |   21|      3|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      3|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 2]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      2|        command;                                                  \
  |  |  ------------------
  |  |  |  Branch (27:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   28|      1|    } else
  ------------------
  160|      3|            index, tmp, "flags=",
  161|      3|            if (tmp) { sftk_parseFlags(param,parsed); PORT_Free(tmp); tmp = NULL; })
  162|      2|        NSSUTIL_HANDLE_STRING_ARG(
  ------------------
  |  |   21|      2|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      2|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |  ------------------
  |  |  |  Branch (27:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   28|      0|    } else
  ------------------
  163|      2|            index, tmp, "tokens=",
  164|      2|            if (tmp) { sftk_parseTokens(tmp,parsed); PORT_Free(tmp); tmp = NULL; })
  165|      2|        NSSUTIL_HANDLE_FINAL_ARG(index)
  ------------------
  |  |   31|      2|    {                                            \
  |  |   32|      2|        param = NSSUTIL_ArgSkipParameter(param); \
  |  |   33|      2|    }                                            \
  |  |   34|     10|    param = NSSUTIL_ArgStrip(param);
  ------------------
  166|     10|    }
  167|      1|    if (parsed->tokens == NULL) {
  ------------------
  |  Branch (167:9): [True: 1, False: 0]
  ------------------
  168|      1|        int count = isFIPS ? 1 : 2;
  ------------------
  |  Branch (168:21): [True: 0, False: 1]
  ------------------
  169|      1|        int i = count - 1;
  170|      1|        sftk_token_parameters *tokens = NULL;
  171|       |
  172|      1|        tokens = (sftk_token_parameters *)
  173|      1|            PORT_ZAlloc(count * sizeof(sftk_token_parameters));
  ------------------
  |  |   72|      1|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  174|      1|        if (tokens == NULL) {
  ------------------
  |  Branch (174:13): [True: 0, False: 1]
  ------------------
  175|      0|            goto loser;
  176|      0|        }
  177|      1|        parsed->tokens = tokens;
  178|      1|        parsed->token_count = count;
  179|      1|        tokens[i].slotID = isFIPS ? FIPS_SLOT_ID : PRIVATE_KEY_SLOT_ID;
  ------------------
  |  |  500|      0|#define FIPS_SLOT_ID 3
  ------------------
                      tokens[i].slotID = isFIPS ? FIPS_SLOT_ID : PRIVATE_KEY_SLOT_ID;
  ------------------
  |  |  499|      2|#define PRIVATE_KEY_SLOT_ID 2
  ------------------
  |  Branch (179:28): [True: 0, False: 1]
  ------------------
  180|      1|        tokens[i].certPrefix = certPrefix;
  181|      1|        tokens[i].keyPrefix = keyPrefix;
  182|      1|        tokens[i].minPW = minPW ? atoi(minPW) : 0;
  ------------------
  |  Branch (182:27): [True: 0, False: 1]
  ------------------
  183|      1|        tokens[i].readOnly = parsed->readOnly;
  184|      1|        tokens[i].noCertDB = parsed->noCertDB;
  185|      1|        tokens[i].noKeyDB = parsed->noCertDB;
  186|      1|        tokens[i].forceOpen = parsed->forceOpen;
  187|      1|        tokens[i].pwRequired = parsed->pwRequired;
  188|      1|        tokens[i].optimizeSpace = parsed->optimizeSpace;
  189|      1|        tokens[0].optimizeSpace = parsed->optimizeSpace;
  190|      1|        certPrefix = NULL;
  191|      1|        keyPrefix = NULL;
  192|      1|        if (isFIPS) {
  ------------------
  |  Branch (192:13): [True: 0, False: 1]
  ------------------
  193|      0|            tokens[i].tokdes = ftokdes;
  194|      0|            tokens[i].updtokdes = pupdtokdes;
  195|      0|            tokens[i].slotdes = fslotdes;
  196|      0|            fslotdes = NULL;
  197|      0|            ftokdes = NULL;
  198|      0|            pupdtokdes = NULL;
  199|      1|        } else {
  200|      1|            tokens[i].tokdes = ptokdes;
  201|      1|            tokens[i].updtokdes = pupdtokdes;
  202|      1|            tokens[i].slotdes = pslotdes;
  203|      1|            tokens[0].slotID = NETSCAPE_SLOT_ID;
  ------------------
  |  |  498|      1|#define NETSCAPE_SLOT_ID 1
  ------------------
  204|      1|            tokens[0].tokdes = tokdes;
  205|      1|            tokens[0].slotdes = slotdes;
  206|      1|            tokens[0].noCertDB = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  207|      1|            tokens[0].noKeyDB = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  208|      1|            pupdtokdes = NULL;
  209|      1|            ptokdes = NULL;
  210|      1|            pslotdes = NULL;
  211|      1|            tokdes = NULL;
  212|      1|            slotdes = NULL;
  213|      1|        }
  214|      1|    }
  215|       |
  216|      1|loser:
  217|      1|    FREE_CLEAR(certPrefix);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  218|      1|    FREE_CLEAR(keyPrefix);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  219|      1|    FREE_CLEAR(tokdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  220|      1|    FREE_CLEAR(ptokdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  221|      1|    FREE_CLEAR(pupdtokdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  222|      1|    FREE_CLEAR(slotdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  223|      1|    FREE_CLEAR(pslotdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  224|      1|    FREE_CLEAR(fslotdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  225|      1|    FREE_CLEAR(ftokdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  226|      1|    FREE_CLEAR(minPW);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  227|      1|    return CKR_OK;
  ------------------
  |  | 1388|      1|#define CKR_OK 0x00000000UL
  ------------------
  228|      1|}
sftk_freeParams:
  232|      1|{
  233|      1|    int i;
  234|       |
  235|      3|    for (i = 0; i < params->token_count; i++) {
  ------------------
  |  Branch (235:17): [True: 2, False: 1]
  ------------------
  236|      2|        FREE_CLEAR(params->tokens[i].configdir);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  237|      2|        FREE_CLEAR(params->tokens[i].certPrefix);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 1]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  238|      2|        FREE_CLEAR(params->tokens[i].keyPrefix);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 1]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  239|      2|        FREE_CLEAR(params->tokens[i].tokdes);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  240|      2|        FREE_CLEAR(params->tokens[i].slotdes);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  241|      2|        FREE_CLEAR(params->tokens[i].updatedir);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  242|      2|        FREE_CLEAR(params->tokens[i].updCertPrefix);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  243|      2|        FREE_CLEAR(params->tokens[i].updKeyPrefix);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  244|      2|        FREE_CLEAR(params->tokens[i].updateID);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  245|      2|        FREE_CLEAR(params->tokens[i].updtokdes);
  ------------------
  |  |   16|      2|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 1]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  246|      2|    }
  247|       |
  248|      1|    FREE_CLEAR(params->configdir);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  249|      1|    FREE_CLEAR(params->secmodName);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  250|      1|    FREE_CLEAR(params->man);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  251|      1|    FREE_CLEAR(params->libdes);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   17|      0|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      0|        p = NULL;     \
  |  |   19|      0|    }
  ------------------
  252|      1|    FREE_CLEAR(params->tokens);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  253|      1|    FREE_CLEAR(params->updatedir);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  254|      1|    FREE_CLEAR(params->updateID);
  ------------------
  |  |   16|      1|    if (p) {          \
  |  |  ------------------
  |  |  |  Branch (16:9): [True: 1, False: 0]
  |  |  ------------------
  |  |   17|      1|        PORT_Free(p); \
  |  |  ------------------
  |  |  |  |   60|      1|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   18|      1|        p = NULL;     \
  |  |   19|      1|    }
  ------------------
  255|      1|}
sftkpars.c:sftk_parseFlags:
   35|      1|{
   36|      1|    parsed->noModDB = NSSUTIL_ArgHasFlag("flags", "noModDB", tmp);
   37|      1|    parsed->readOnly = NSSUTIL_ArgHasFlag("flags", "readOnly", tmp);
   38|       |    /* keep legacy interface working */
   39|      1|    parsed->noCertDB = NSSUTIL_ArgHasFlag("flags", "noCertDB", tmp);
   40|      1|    parsed->forceOpen = NSSUTIL_ArgHasFlag("flags", "forceOpen", tmp);
   41|      1|    parsed->pwRequired = NSSUTIL_ArgHasFlag("flags", "passwordRequired", tmp);
   42|      1|    parsed->optimizeSpace = NSSUTIL_ArgHasFlag("flags", "optimizeSpace", tmp);
   43|      1|    return;
   44|      1|}

sftk_TLSPRFInit:
  158|   105k|{
  159|   105k|    SFTKAttribute *keyVal;
  160|   105k|    TLSPRFContext *prf_cx;
  161|   105k|    CK_RV crv = CKR_HOST_MEMORY;
  ------------------
  |  | 1390|   105k|#define CKR_HOST_MEMORY 0x00000002UL
  ------------------
  162|   105k|    PRUint32 keySize;
  163|   105k|    PRUint32 blockSize;
  164|       |
  165|   105k|    if (key_type != CKK_GENERIC_SECRET)
  ------------------
  |  |  383|   105k|#define CKK_GENERIC_SECRET 0x00000010UL
  ------------------
  |  Branch (165:9): [True: 0, False: 105k]
  ------------------
  166|      0|        return CKR_KEY_TYPE_INCONSISTENT; /* CKR_KEY_FUNCTION_NOT_PERMITTED */
  ------------------
  |  | 1433|      0|#define CKR_KEY_TYPE_INCONSISTENT 0x00000063UL
  ------------------
  167|       |
  168|   105k|    context->multi = PR_TRUE;
  ------------------
  |  |  437|   105k|#define PR_TRUE 1
  ------------------
  169|       |
  170|   105k|    keyVal = sftk_FindAttribute(key, CKA_VALUE);
  ------------------
  |  |  516|   105k|#define CKA_VALUE 0x00000011UL
  ------------------
  171|   105k|    keySize = (!keyVal) ? 0 : keyVal->attrib.ulValueLen;
  ------------------
  |  Branch (171:15): [True: 0, False: 105k]
  ------------------
  172|   105k|    blockSize = keySize + sizeof(TLSPRFContext);
  173|   105k|    prf_cx = (TLSPRFContext *)PORT_Alloc(blockSize);
  ------------------
  |  |   52|   105k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  174|   105k|    if (!prf_cx)
  ------------------
  |  Branch (174:9): [True: 0, False: 105k]
  ------------------
  175|      0|        goto done;
  176|   105k|    prf_cx->cxSize = blockSize;
  177|   105k|    prf_cx->cxKeyLen = keySize;
  178|   105k|    prf_cx->cxDataLen = 0;
  179|   105k|    prf_cx->cxBufSize = blockSize - offsetof(TLSPRFContext, cxBuf);
  180|   105k|    prf_cx->cxRv = SECSuccess;
  181|   105k|    prf_cx->cxIsFIPS = sftk_isFIPS(key->slot->slotID);
  ------------------
  |  |  506|   105k|    (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  500|   105k|#define FIPS_SLOT_ID 3
  |  |  ------------------
  |  |                   (((id) == FIPS_SLOT_ID) || ((id) >= SFTK_MIN_FIPS_USER_SLOT_ID))
  |  |  ------------------
  |  |  |  |  567|   105k|#define SFTK_MIN_FIPS_USER_SLOT_ID 101
  |  |  ------------------
  |  |  |  Branch (506:6): [True: 0, False: 105k]
  |  |  |  Branch (506:32): [True: 0, False: 105k]
  |  |  ------------------
  ------------------
  182|   105k|    prf_cx->cxBufPtr = prf_cx->cxBuf;
  183|   105k|    prf_cx->cxHashAlg = hash_alg;
  184|   105k|    prf_cx->cxOutLen = out_len;
  185|   105k|    if (keySize)
  ------------------
  |  Branch (185:9): [True: 105k, False: 0]
  ------------------
  186|   105k|        PORT_Memcpy(prf_cx->cxBufPtr, keyVal->attrib.pValue, keySize);
  ------------------
  |  |  180|   105k|#define PORT_Memcpy memcpy
  ------------------
  187|       |
  188|   105k|    context->hashInfo = (void *)prf_cx;
  189|   105k|    context->cipherInfo = (void *)prf_cx;
  190|   105k|    context->hashUpdate = sftk_TLSPRFHashUpdate;
  191|   105k|    context->end = sftk_TLSPRFEnd;
  192|   105k|    context->update = sftk_TLSPRFUpdate;
  193|   105k|    context->verify = sftk_TLSPRFVerify;
  194|   105k|    context->destroy = sftk_TLSPRFNull;
  195|   105k|    context->hashdestroy = sftk_TLSPRFHashDestroy;
  196|   105k|    crv = CKR_OK;
  ------------------
  |  | 1388|   105k|#define CKR_OK 0x00000000UL
  ------------------
  197|       |
  198|   105k|done:
  199|   105k|    if (keyVal)
  ------------------
  |  Branch (199:9): [True: 105k, False: 0]
  ------------------
  200|   105k|        sftk_FreeAttribute(keyVal);
  201|   105k|    return crv;
  202|   105k|}
tlsprf.c:sftk_TLSPRFHashUpdate:
   33|   210k|{
   34|   210k|    TLSPRFContext *cx = ctx;
   35|   210k|    PRUint32 bytesUsed = cx->cxKeyLen + cx->cxDataLen;
   36|       |
   37|   210k|    if (cx->cxRv != SECSuccess) /* function has previously failed. */
  ------------------
  |  Branch (37:9): [True: 0, False: 210k]
  ------------------
   38|      0|        return;
   39|   210k|    if (bytesUsed + data_len > cx->cxBufSize) {
  ------------------
  |  Branch (39:9): [True: 0, False: 210k]
  ------------------
   40|       |        /* We don't use realloc here because
   41|       |        ** (a) realloc doesn't zero out the old block, and
   42|       |        ** (b) if realloc fails, we lose the old block.
   43|       |        */
   44|      0|        PRUint32 newBufSize = bytesUsed + data_len + 512;
   45|      0|        unsigned char *newBuf = (unsigned char *)PORT_Alloc(newBufSize);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
   46|      0|        if (!newBuf) {
  ------------------
  |  Branch (46:13): [True: 0, False: 0]
  ------------------
   47|      0|            cx->cxRv = SECFailure;
   48|      0|            return;
   49|      0|        }
   50|      0|        PORT_Memcpy(newBuf, cx->cxBufPtr, bytesUsed);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
   51|      0|        if (cx->cxBufPtr != cx->cxBuf) {
  ------------------
  |  Branch (51:13): [True: 0, False: 0]
  ------------------
   52|      0|            PORT_ZFree(cx->cxBufPtr, bytesUsed);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
   53|      0|        }
   54|      0|        cx->cxBufPtr = newBuf;
   55|      0|        cx->cxBufSize = newBufSize;
   56|      0|    }
   57|   210k|    PORT_Memcpy(cx->cxBufPtr + bytesUsed, data, data_len);
  ------------------
  |  |  180|   210k|#define PORT_Memcpy memcpy
  ------------------
   58|   210k|    cx->cxDataLen += data_len;
   59|   210k|}
tlsprf.c:sftk_TLSPRFEnd:
   64|   105k|{
   65|   105k|    *pDigestLen = 0; /* tells Verify that no data has been input yet. */
   66|   105k|}
tlsprf.c:sftk_TLSPRFUpdate:
   76|   105k|{
   77|   105k|    TLSPRFContext *cx = ctx;
   78|   105k|    SECStatus rv;
   79|   105k|    SECItem sigItem;
   80|   105k|    SECItem seedItem;
   81|   105k|    SECItem secretItem;
   82|       |
   83|   105k|    if (cx->cxRv != SECSuccess)
  ------------------
  |  Branch (83:9): [True: 0, False: 105k]
  ------------------
   84|      0|        return cx->cxRv;
   85|       |
   86|   105k|    secretItem.data = cx->cxBufPtr;
   87|   105k|    secretItem.len = cx->cxKeyLen;
   88|       |
   89|   105k|    seedItem.data = cx->cxBufPtr + cx->cxKeyLen;
   90|   105k|    seedItem.len = cx->cxDataLen;
   91|       |
   92|   105k|    sigItem.data = sig;
   93|   105k|    if (cx->cxOutLen == 0) {
  ------------------
  |  Branch (93:9): [True: 0, False: 105k]
  ------------------
   94|      0|        sigItem.len = maxLen;
   95|   105k|    } else if (cx->cxOutLen <= maxLen) {
  ------------------
  |  Branch (95:16): [True: 105k, False: 0]
  ------------------
   96|   105k|        sigItem.len = cx->cxOutLen;
   97|   105k|    } else {
   98|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   99|      0|        return SECFailure;
  100|      0|    }
  101|       |
  102|   105k|    if (cx->cxHashAlg != HASH_AlgNULL) {
  ------------------
  |  Branch (102:9): [True: 93.0k, False: 12.0k]
  ------------------
  103|  93.0k|        rv = TLS_P_hash(cx->cxHashAlg, &secretItem, NULL, &seedItem, &sigItem,
  104|  93.0k|                        cx->cxIsFIPS);
  105|  93.0k|    } else {
  106|  12.0k|        rv = TLS_PRF(&secretItem, NULL, &seedItem, &sigItem, cx->cxIsFIPS);
  107|  12.0k|    }
  108|   105k|    if (rv == SECSuccess && sigLen != NULL)
  ------------------
  |  Branch (108:9): [True: 105k, False: 0]
  |  Branch (108:29): [True: 105k, False: 0]
  ------------------
  109|   105k|        *sigLen = sigItem.len;
  110|   105k|    return rv;
  111|   105k|}
tlsprf.c:sftk_TLSPRFNull:
   13|   105k|{
   14|   105k|    return;
   15|   105k|}
tlsprf.c:sftk_TLSPRFHashDestroy:
  143|   105k|{
  144|   105k|    TLSPRFContext *cx = ctx;
  145|   105k|    if (freeit) {
  ------------------
  |  Branch (145:9): [True: 105k, False: 0]
  ------------------
  146|   105k|        if (cx->cxBufPtr != cx->cxBuf)
  ------------------
  |  Branch (146:13): [True: 0, False: 105k]
  ------------------
  147|      0|            PORT_ZFree(cx->cxBufPtr, cx->cxBufSize);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  148|   105k|        PORT_ZFree(cx, cx->cxSize);
  ------------------
  |  |   75|   105k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  149|   105k|    }
  150|   105k|}

dtls_InitTimers:
  897|  9.71k|{
  898|  9.71k|    unsigned int i;
  899|  9.71k|    dtlsTimer **timers[PR_ARRAY_SIZE(ss->ssl3.hs.timers)] = {
  900|  9.71k|        &ss->ssl3.hs.rtTimer,
  901|  9.71k|        &ss->ssl3.hs.ackTimer,
  902|  9.71k|        &ss->ssl3.hs.hdTimer
  903|  9.71k|    };
  904|  9.71k|    static const char *timerLabels[] = {
  905|  9.71k|        "retransmit", "ack", "holddown"
  906|  9.71k|    };
  907|       |
  908|  9.71k|    PORT_Assert(PR_ARRAY_SIZE(timers) == PR_ARRAY_SIZE(timerLabels));
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  909|  38.8k|    for (i = 0; i < PR_ARRAY_SIZE(ss->ssl3.hs.timers); ++i) {
  ------------------
  |  |  167|  38.8k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (909:17): [True: 29.1k, False: 9.71k]
  ------------------
  910|  29.1k|        *timers[i] = &ss->ssl3.hs.timers[i];
  911|  29.1k|        ss->ssl3.hs.timers[i].label = timerLabels[i];
  912|  29.1k|    }
  913|  9.71k|}
dtls_InitRecvdRecords:
 1176|  19.4k|{
 1177|  19.4k|    PORT_Memset(records->data, 0, sizeof(records->data));
  ------------------
  |  |  182|  19.4k|#define PORT_Memset memset
  ------------------
 1178|  19.4k|    records->left = 0;
 1179|  19.4k|    records->right = DTLS_RECVD_RECORDS_WINDOW - 1;
  ------------------
  |  |  124|  19.4k|#define DTLS_RECVD_RECORDS_WINDOW 1024
  ------------------
 1180|  19.4k|}
dtls_ReceivedFirstMessageInFlight:
 1430|  55.4k|{
 1431|  55.4k|    if (!IS_DTLS(ss))
  ------------------
  |  |  892|  55.4k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (1431:9): [True: 55.4k, False: 0]
  ------------------
 1432|  55.4k|        return;
 1433|       |
 1434|       |    /* At this point we are advancing our state machine, so we can free our last
 1435|       |     * flight of messages. */
 1436|      0|    if (ss->ssl3.hs.ws != idle_handshake ||
  ------------------
  |  Branch (1436:9): [True: 0, False: 0]
  ------------------
 1437|      0|        ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1437:9): [True: 0, False: 0]
  ------------------
 1438|       |        /* We need to keep our last flight around in DTLS 1.2 and below,
 1439|       |         * so we can retransmit it in response to other people's
 1440|       |         * retransmits. */
 1441|      0|        dtls_FreeHandshakeMessages(&ss->ssl3.hs.lastMessageFlight);
 1442|       |
 1443|       |        /* Reset the timer to the initial value if the retry counter
 1444|       |         * is 0, per RFC 6347, Sec. 4.2.4.1 */
 1445|      0|        dtls_CancelTimer(ss, ss->ssl3.hs.rtTimer);
 1446|      0|        if (ss->ssl3.hs.rtRetries == 0) {
  ------------------
  |  Branch (1446:13): [True: 0, False: 0]
  ------------------
 1447|      0|            ss->ssl3.hs.rtTimer->timeout = DTLS_RETRANSMIT_INITIAL_MS;
  ------------------
  |  |  126|      0|#define DTLS_RETRANSMIT_INITIAL_MS 50
  ------------------
 1448|      0|        }
 1449|      0|    }
 1450|       |
 1451|       |    /* Empty the ACK queue (TLS 1.3 only). */
 1452|      0|    ssl_ClearPRCList(&ss->ssl3.hs.dtlsRcvdHandshake, NULL);
 1453|      0|}

ssl_SelfEncryptProtectInt:
   67|  3.82k|{
   68|  3.82k|    if (inLen > maxOutLen) {
  ------------------
  |  Branch (68:9): [True: 0, False: 3.82k]
  ------------------
   69|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   70|      0|        return SECFailure;
   71|      0|    }
   72|       |
   73|  3.82k|    PORT_Memcpy(out, in, inLen);
  ------------------
  |  |  180|  3.82k|#define PORT_Memcpy memcpy
  ------------------
   74|  3.82k|    *outLen = inLen;
   75|       |
   76|  3.82k|    return 0;
   77|  3.82k|}
ssl_SelfEncryptUnprotectInt:
   84|    386|{
   85|    386|    if (inLen > maxOutLen) {
  ------------------
  |  Branch (85:9): [True: 1, False: 385]
  ------------------
   86|      1|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
   87|      1|        return SECFailure;
   88|      1|    }
   89|       |
   90|    385|    PORT_Memcpy(out, in, inLen);
  ------------------
  |  |  180|    385|#define PORT_Memcpy memcpy
  ------------------
   91|    385|    *outLen = inLen;
   92|       |
   93|    385|    return 0;
   94|    386|}
ssl_SelfEncryptGetProtectedSize:
  271|  3.63k|{
  272|  3.63k|    return SELF_ENCRYPT_KEY_NAME_LEN +
  ------------------
  |  |  191|  3.63k|#define SELF_ENCRYPT_KEY_NAME_LEN 16
  ------------------
  273|  3.63k|           AES_BLOCK_SIZE +
  ------------------
  |  |  130|  3.63k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  274|  3.63k|           2 +
  275|  3.63k|           ((inLen / AES_BLOCK_SIZE) + 1) * AES_BLOCK_SIZE + /* Padded */
  ------------------
  |  |  130|  3.63k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
                         ((inLen / AES_BLOCK_SIZE) + 1) * AES_BLOCK_SIZE + /* Padded */
  ------------------
  |  |  130|  3.63k|#define AES_BLOCK_SIZE 16 /* bytes */
  ------------------
  276|  3.63k|           SHA256_LENGTH;
  ------------------
  |  |   41|  3.63k|#define SHA256_LENGTH 32
  ------------------
  277|  3.63k|}
ssl_SelfEncryptProtect:
  283|  3.82k|{
  284|  3.82k|    PRUint8 keyName[SELF_ENCRYPT_KEY_NAME_LEN];
  285|  3.82k|    PK11SymKey *encKey;
  286|  3.82k|    PK11SymKey *macKey;
  287|  3.82k|    SECStatus rv;
  288|       |
  289|       |    /* Get session ticket keys. */
  290|  3.82k|    rv = ssl_GetSelfEncryptKeys(ss, keyName, &encKey, &macKey);
  291|  3.82k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (291:9): [True: 0, False: 3.82k]
  ------------------
  292|      0|        SSL_DBG(("%d: SSL[%d]: Unable to get/generate self-encrypt keys.",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  293|      0|                 SSL_GETPID(), ss->fd));
  294|      0|        return SECFailure;
  295|      0|    }
  296|       |
  297|  3.82k|    return ssl_SelfEncryptProtectInt(encKey, macKey, keyName,
  298|  3.82k|                                     in, inLen, out, outLen, maxOutLen);
  299|  3.82k|}
ssl_SelfEncryptUnprotect:
  305|    386|{
  306|    386|    PRUint8 keyName[SELF_ENCRYPT_KEY_NAME_LEN];
  307|    386|    PK11SymKey *encKey;
  308|    386|    PK11SymKey *macKey;
  309|    386|    SECStatus rv;
  310|       |
  311|       |    /* Get session ticket keys. */
  312|    386|    rv = ssl_GetSelfEncryptKeys(ss, keyName, &encKey, &macKey);
  313|    386|    if (rv != SECSuccess) {
  ------------------
  |  Branch (313:9): [True: 0, False: 386]
  ------------------
  314|      0|        SSL_DBG(("%d: SSL[%d]: Unable to get/generate self-encrypt keys.",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  315|      0|                 SSL_GETPID(), ss->fd));
  316|      0|        return SECFailure;
  317|      0|    }
  318|       |
  319|    386|    return ssl_SelfEncryptUnprotectInt(encKey, macKey, keyName,
  320|    386|                                       in, inLen, out, outLen, maxOutLen);
  321|    386|}

ssl3_CheckCipherSuiteOrderConsistency:
  218|      1|{
  219|      1|    unsigned int i;
  220|       |
  221|      1|    PORT_Assert(SSL_NumImplementedCiphers == PR_ARRAY_SIZE(cipherSuites));
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  222|       |
  223|     72|    for (i = 0; i < PR_ARRAY_SIZE(cipherSuites); ++i) {
  ------------------
  |  |  167|     72|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (223:17): [True: 71, False: 1]
  ------------------
  224|     71|        PORT_Assert(SSL_ImplementedCiphers[i] == cipherSuites[i].cipher_suite);
  ------------------
  |  |  120|     71|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     71|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 71, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  225|     71|    }
  226|      1|}
ssl3_Alg2Mech:
  437|  4.99M|{
  438|  4.99M|    PORT_Assert(alg2Mech[calg].calg == calg);
  ------------------
  |  |  120|  4.99M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.99M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4.99M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  439|  4.99M|    return alg2Mech[calg].cmech;
  440|  4.99M|}
SSL_GetStatistics:
  545|  1.61k|{
  546|  1.61k|    return &ssl3stats;
  547|  1.61k|}
SSL_AtomicIncrementLong:
  561|  60.1k|{
  562|  60.1k|    if ((sizeof *x) == sizeof(PRInt32)) {
  ------------------
  |  Branch (562:9): [Folded - Ignored]
  ------------------
  563|      0|        PR_ATOMIC_INCREMENT((PRInt32 *)x);
  ------------------
  |  |  122|      0|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  564|  60.1k|    } else {
  565|  60.1k|        tooLong *tl = (tooLong *)x;
  566|  60.1k|        if (PR_ATOMIC_INCREMENT(&tl->low) == 0)
  ------------------
  |  |  122|  60.1k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  |  Branch (566:13): [True: 0, False: 60.1k]
  ------------------
  567|      0|            PR_ATOMIC_INCREMENT(&tl->high);
  ------------------
  |  |  122|      0|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
  568|  60.1k|    }
  569|  60.1k|}
ssl3_CipherSuiteAllowedForVersionRange:
  574|  1.57M|{
  575|  1.57M|    switch (cipherSuite) {
  576|  23.1k|        case TLS_DHE_RSA_WITH_AES_256_CBC_SHA256:
  ------------------
  |  |  128|  23.1k|#define TLS_DHE_RSA_WITH_AES_256_CBC_SHA256     0x006B
  ------------------
  |  Branch (576:9): [True: 23.1k, False: 1.54M]
  ------------------
  577|  44.3k|        case TLS_RSA_WITH_AES_256_CBC_SHA256:
  ------------------
  |  |  115|  44.3k|#define TLS_RSA_WITH_AES_256_CBC_SHA256         0x003D
  ------------------
  |  Branch (577:9): [True: 21.2k, False: 1.54M]
  ------------------
  578|  80.4k|        case TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256:
  ------------------
  |  |  190|  80.4k|#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 0xC023
  ------------------
  |  Branch (578:9): [True: 36.0k, False: 1.53M]
  ------------------
  579|   116k|        case TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384:
  ------------------
  |  |  191|   116k|#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 0xC024
  ------------------
  |  Branch (579:9): [True: 36.0k, False: 1.53M]
  ------------------
  580|   154k|        case TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256:
  ------------------
  |  |  192|   154k|#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256   0xC027
  ------------------
  |  Branch (580:9): [True: 37.8k, False: 1.53M]
  ------------------
  581|   192k|        case TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384:
  ------------------
  |  |  193|   192k|#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384   0xC028
  ------------------
  |  Branch (581:9): [True: 37.8k, False: 1.53M]
  ------------------
  582|   216k|        case TLS_DHE_RSA_WITH_AES_128_CBC_SHA256:
  ------------------
  |  |  126|   216k|#define TLS_DHE_RSA_WITH_AES_128_CBC_SHA256     0x0067
  ------------------
  |  Branch (582:9): [True: 24.1k, False: 1.54M]
  ------------------
  583|   239k|        case TLS_RSA_WITH_AES_128_CBC_SHA256:
  ------------------
  |  |  114|   239k|#define TLS_RSA_WITH_AES_128_CBC_SHA256         0x003C
  ------------------
  |  Branch (583:9): [True: 22.8k, False: 1.54M]
  ------------------
  584|   262k|        case TLS_RSA_WITH_AES_128_GCM_SHA256:
  ------------------
  |  |  139|   262k|#define TLS_RSA_WITH_AES_128_GCM_SHA256         0x009C
  ------------------
  |  Branch (584:9): [True: 23.1k, False: 1.54M]
  ------------------
  585|   285k|        case TLS_RSA_WITH_AES_256_GCM_SHA384:
  ------------------
  |  |  140|   285k|#define TLS_RSA_WITH_AES_256_GCM_SHA384         0x009D
  ------------------
  |  Branch (585:9): [True: 23.0k, False: 1.54M]
  ------------------
  586|   285k|        case TLS_DHE_DSS_WITH_AES_128_CBC_SHA256:
  ------------------
  |  |  117|   285k|#define TLS_DHE_DSS_WITH_AES_128_CBC_SHA256     0x0040
  ------------------
  |  Branch (586:9): [True: 0, False: 1.57M]
  ------------------
  587|   285k|        case TLS_DHE_DSS_WITH_AES_256_CBC_SHA256:
  ------------------
  |  |  127|   285k|#define TLS_DHE_DSS_WITH_AES_256_CBC_SHA256     0x006A
  ------------------
  |  Branch (587:9): [True: 0, False: 1.57M]
  ------------------
  588|   288k|        case TLS_RSA_WITH_NULL_SHA256:
  ------------------
  |  |  113|   288k|#define TLS_RSA_WITH_NULL_SHA256                0x003B
  ------------------
  |  Branch (588:9): [True: 2.70k, False: 1.56M]
  ------------------
  589|   288k|        case TLS_DHE_DSS_WITH_AES_128_GCM_SHA256:
  ------------------
  |  |  143|   288k|#define TLS_DHE_DSS_WITH_AES_128_GCM_SHA256     0x00A2
  ------------------
  |  Branch (589:9): [True: 0, False: 1.57M]
  ------------------
  590|   288k|        case TLS_DHE_DSS_WITH_AES_256_GCM_SHA384:
  ------------------
  |  |  144|   288k|#define TLS_DHE_DSS_WITH_AES_256_GCM_SHA384     0x00A3
  ------------------
  |  Branch (590:9): [True: 0, False: 1.57M]
  ------------------
  591|   333k|        case TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256:
  ------------------
  |  |  195|   333k|#define TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 0xC02B
  ------------------
  |  Branch (591:9): [True: 44.9k, False: 1.52M]
  ------------------
  592|   377k|        case TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384:
  ------------------
  |  |  196|   377k|#define TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 0xC02C
  ------------------
  |  Branch (592:9): [True: 44.7k, False: 1.52M]
  ------------------
  593|   429k|        case TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256:
  ------------------
  |  |  198|   429k|#define TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256   0xC02F
  ------------------
  |  Branch (593:9): [True: 51.4k, False: 1.51M]
  ------------------
  594|   471k|        case TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384:
  ------------------
  |  |  199|   471k|#define TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384   0xC030
  ------------------
  |  Branch (594:9): [True: 42.5k, False: 1.52M]
  ------------------
  595|   515k|        case TLS_DHE_RSA_WITH_AES_128_GCM_SHA256:
  ------------------
  |  |  141|   515k|#define TLS_DHE_RSA_WITH_AES_128_GCM_SHA256     0x009E
  ------------------
  |  Branch (595:9): [True: 43.2k, False: 1.52M]
  ------------------
  596|   553k|        case TLS_DHE_RSA_WITH_AES_256_GCM_SHA384:
  ------------------
  |  |  142|   553k|#define TLS_DHE_RSA_WITH_AES_256_GCM_SHA384     0x009F
  ------------------
  |  Branch (596:9): [True: 38.7k, False: 1.53M]
  ------------------
  597|   598k|        case TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256:
  ------------------
  |  |  204|   598k|#define TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 0xCCA9
  ------------------
  |  Branch (597:9): [True: 44.8k, False: 1.52M]
  ------------------
  598|   649k|        case TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256:
  ------------------
  |  |  203|   649k|#define TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256   0xCCA8
  ------------------
  |  Branch (598:9): [True: 50.8k, False: 1.52M]
  ------------------
  599|   688k|        case TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256:
  ------------------
  |  |  205|   688k|#define TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256     0xCCAA
  ------------------
  |  Branch (599:9): [True: 38.7k, False: 1.53M]
  ------------------
  600|   688k|            return vrange->max >= SSL_LIBRARY_VERSION_TLS_1_2 &&
  ------------------
  |  |   20|  1.37M|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (600:20): [True: 582k, False: 105k]
  ------------------
  601|   688k|                   vrange->min < SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|   582k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (601:20): [True: 582k, False: 160]
  ------------------
  602|       |
  603|       |        /* RFC 4492: ECC cipher suites need TLS extensions to negotiate curves and
  604|       |         * point formats.*/
  605|  3.27k|        case TLS_ECDH_ECDSA_WITH_NULL_SHA:
  ------------------
  |  |  160|  3.27k|#define TLS_ECDH_ECDSA_WITH_NULL_SHA            0xC001
  ------------------
  |  Branch (605:9): [True: 3.27k, False: 1.56M]
  ------------------
  606|  24.6k|        case TLS_ECDH_ECDSA_WITH_RC4_128_SHA:
  ------------------
  |  |  161|  24.6k|#define TLS_ECDH_ECDSA_WITH_RC4_128_SHA         0xC002
  ------------------
  |  Branch (606:9): [True: 21.4k, False: 1.54M]
  ------------------
  607|  46.1k|        case TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA:
  ------------------
  |  |  162|  46.1k|#define TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA    0xC003
  ------------------
  |  Branch (607:9): [True: 21.4k, False: 1.54M]
  ------------------
  608|  67.5k|        case TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA:
  ------------------
  |  |  163|  67.5k|#define TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA     0xC004
  ------------------
  |  Branch (608:9): [True: 21.4k, False: 1.54M]
  ------------------
  609|  89.0k|        case TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA:
  ------------------
  |  |  164|  89.0k|#define TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA     0xC005
  ------------------
  |  Branch (609:9): [True: 21.4k, False: 1.54M]
  ------------------
  610|  95.1k|        case TLS_ECDHE_ECDSA_WITH_NULL_SHA:
  ------------------
  |  |  166|  95.1k|#define TLS_ECDHE_ECDSA_WITH_NULL_SHA           0xC006
  ------------------
  |  Branch (610:9): [True: 6.09k, False: 1.56M]
  ------------------
  611|   130k|        case TLS_ECDHE_ECDSA_WITH_RC4_128_SHA:
  ------------------
  |  |  167|   130k|#define TLS_ECDHE_ECDSA_WITH_RC4_128_SHA        0xC007
  ------------------
  |  Branch (611:9): [True: 35.6k, False: 1.53M]
  ------------------
  612|   166k|        case TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA:
  ------------------
  |  |  168|   166k|#define TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA   0xC008
  ------------------
  |  Branch (612:9): [True: 35.7k, False: 1.53M]
  ------------------
  613|   202k|        case TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA:
  ------------------
  |  |  169|   202k|#define TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA    0xC009
  ------------------
  |  Branch (613:9): [True: 36.3k, False: 1.53M]
  ------------------
  614|   239k|        case TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA:
  ------------------
  |  |  170|   239k|#define TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA    0xC00A
  ------------------
  |  Branch (614:9): [True: 36.4k, False: 1.53M]
  ------------------
  615|   239k|        case TLS_ECDH_RSA_WITH_NULL_SHA:
  ------------------
  |  |  172|   239k|#define TLS_ECDH_RSA_WITH_NULL_SHA              0xC00B
  ------------------
  |  Branch (615:9): [True: 0, False: 1.57M]
  ------------------
  616|   239k|        case TLS_ECDH_RSA_WITH_RC4_128_SHA:
  ------------------
  |  |  173|   239k|#define TLS_ECDH_RSA_WITH_RC4_128_SHA           0xC00C
  ------------------
  |  Branch (616:9): [True: 0, False: 1.57M]
  ------------------
  617|   239k|        case TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA:
  ------------------
  |  |  174|   239k|#define TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA      0xC00D
  ------------------
  |  Branch (617:9): [True: 0, False: 1.57M]
  ------------------
  618|   239k|        case TLS_ECDH_RSA_WITH_AES_128_CBC_SHA:
  ------------------
  |  |  175|   239k|#define TLS_ECDH_RSA_WITH_AES_128_CBC_SHA       0xC00E
  ------------------
  |  Branch (618:9): [True: 0, False: 1.57M]
  ------------------
  619|   239k|        case TLS_ECDH_RSA_WITH_AES_256_CBC_SHA:
  ------------------
  |  |  176|   239k|#define TLS_ECDH_RSA_WITH_AES_256_CBC_SHA       0xC00F
  ------------------
  |  Branch (619:9): [True: 0, False: 1.57M]
  ------------------
  620|   243k|        case TLS_ECDHE_RSA_WITH_NULL_SHA:
  ------------------
  |  |  178|   243k|#define TLS_ECDHE_RSA_WITH_NULL_SHA             0xC010
  ------------------
  |  Branch (620:9): [True: 3.96k, False: 1.56M]
  ------------------
  621|   280k|        case TLS_ECDHE_RSA_WITH_RC4_128_SHA:
  ------------------
  |  |  179|   280k|#define TLS_ECDHE_RSA_WITH_RC4_128_SHA          0xC011
  ------------------
  |  Branch (621:9): [True: 37.2k, False: 1.53M]
  ------------------
  622|   317k|        case TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA:
  ------------------
  |  |  180|   317k|#define TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA     0xC012
  ------------------
  |  Branch (622:9): [True: 37.2k, False: 1.53M]
  ------------------
  623|   360k|        case TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA:
  ------------------
  |  |  181|   360k|#define TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA      0xC013
  ------------------
  |  Branch (623:9): [True: 42.2k, False: 1.52M]
  ------------------
  624|   397k|        case TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA:
  ------------------
  |  |  182|   397k|#define TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA      0xC014
  ------------------
  |  Branch (624:9): [True: 37.8k, False: 1.53M]
  ------------------
  625|   397k|            return vrange->max >= SSL_LIBRARY_VERSION_TLS_1_0 &&
  ------------------
  |  |   18|   795k|#define SSL_LIBRARY_VERSION_TLS_1_0             0x0301
  ------------------
  |  Branch (625:20): [True: 397k, False: 0]
  ------------------
  626|   397k|                   vrange->min < SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|   397k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (626:20): [True: 397k, False: 120]
  ------------------
  627|       |
  628|  60.3k|        case TLS_AES_128_GCM_SHA256:
  ------------------
  |  |  208|  60.3k|#define TLS_AES_128_GCM_SHA256                0x1301
  ------------------
  |  Branch (628:9): [True: 60.3k, False: 1.51M]
  ------------------
  629|   119k|        case TLS_AES_256_GCM_SHA384:
  ------------------
  |  |  209|   119k|#define TLS_AES_256_GCM_SHA384                0x1302
  ------------------
  |  Branch (629:9): [True: 59.5k, False: 1.51M]
  ------------------
  630|   180k|        case TLS_CHACHA20_POLY1305_SHA256:
  ------------------
  |  |  210|   180k|#define TLS_CHACHA20_POLY1305_SHA256          0x1303
  ------------------
  |  Branch (630:9): [True: 60.1k, False: 1.51M]
  ------------------
  631|   180k|            return vrange->max >= SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|   180k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  632|       |
  633|   304k|        default:
  ------------------
  |  Branch (633:9): [True: 304k, False: 1.26M]
  ------------------
  634|   304k|            return vrange->min < SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|   304k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  635|  1.57M|    }
  636|  1.57M|}
ssl_LookupCipherSuiteDef:
  642|  6.41M|{
  643|  6.41M|    int cipher_suite_def_len =
  644|  6.41M|        sizeof(cipher_suite_defs) / sizeof(cipher_suite_defs[0]);
  645|  6.41M|    int i;
  646|       |
  647|   257M|    for (i = 0; i < cipher_suite_def_len; i++) {
  ------------------
  |  Branch (647:17): [True: 257M, False: 0]
  ------------------
  648|   257M|        if (cipher_suite_defs[i].cipher_suite == suite)
  ------------------
  |  Branch (648:13): [True: 6.41M, False: 251M]
  ------------------
  649|  6.41M|            return &cipher_suite_defs[i];
  650|   257M|    }
  651|      0|    PORT_Assert(PR_FALSE); /* We should never get here. */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  652|      0|    PORT_SetError(SSL_ERROR_UNKNOWN_CIPHER_SUITE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  653|      0|    return NULL;
  654|  6.41M|}
ssl_LookupCipherSuiteCfg:
  675|  7.00k|{
  676|  7.00k|    return ssl_LookupCipherSuiteCfgMutable(suite,
  677|  7.00k|                                           CONST_CAST(ssl3CipherSuiteCfg, suites));
  ------------------
  |  |   96|  7.00k|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
  678|  7.00k|}
ssl3_config_match_init:
  940|  60.3k|{
  941|  60.3k|    ssl3CipherSuiteCfg *suite;
  942|  60.3k|    const ssl3CipherSuiteDef *cipher_def;
  943|  60.3k|    SSLCipherAlgorithm cipher_alg;
  944|  60.3k|    CK_MECHANISM_TYPE cipher_mech;
  945|  60.3k|    SSLAuthType authType;
  946|  60.3k|    SSLKEAType keaType;
  947|  60.3k|    unsigned int i;
  948|  60.3k|    unsigned int numPresent = 0;
  949|  60.3k|    unsigned int numEnabled = 0;
  950|       |
  951|  60.3k|    PORT_Assert(ss);
  ------------------
  |  |  120|  60.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  60.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 60.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  952|  60.3k|    if (!ss) {
  ------------------
  |  Branch (952:9): [True: 0, False: 60.3k]
  ------------------
  953|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  954|      0|        return 0;
  955|      0|    }
  956|  60.3k|    if (SSL_ALL_VERSIONS_DISABLED(&ss->vrange)) {
  ------------------
  |  | 1503|  60.3k|    ((vrange)->min == SSL_LIBRARY_VERSION_NONE)
  |  |  ------------------
  |  |  |  | 1481|  60.3k|#define SSL_LIBRARY_VERSION_NONE 0
  |  |  ------------------
  |  |  |  Branch (1503:5): [True: 0, False: 60.3k]
  |  |  ------------------
  ------------------
  957|      0|        return 0;
  958|      0|    }
  959|  60.3k|    if (ss->sec.isServer && ss->psk &&
  ------------------
  |  Branch (959:9): [True: 60.3k, False: 0]
  |  Branch (959:29): [True: 31.1k, False: 29.2k]
  ------------------
  960|  60.3k|        PR_CLIST_IS_EMPTY(&ss->serverCerts) &&
  ------------------
  |  |   94|  91.4k|    ((_l)->next == (_l))
  |  |  ------------------
  |  |  |  Branch (94:5): [True: 0, False: 31.1k]
  |  |  ------------------
  ------------------
  961|  60.3k|        (ss->opt.requestCertificate || ss->opt.requireCertificate)) {
  ------------------
  |  Branch (961:10): [True: 0, False: 0]
  |  Branch (961:40): [True: 0, False: 0]
  ------------------
  962|       |        /* PSK and certificate auth cannot be combined. */
  963|      0|        PORT_SetError(SSL_ERROR_NO_CERTIFICATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  964|      0|        return 0;
  965|      0|    }
  966|  60.3k|    if (ssl_CheckSignatureSchemes(ss) != SECSuccess) {
  ------------------
  |  Branch (966:9): [True: 0, False: 60.3k]
  ------------------
  967|      0|        return 0; /* Code already set. */
  968|      0|    }
  969|       |
  970|  60.3k|    ssl_FilterSupportedGroups(ss);
  971|  4.34M|    for (i = 0; i < ssl_V3_SUITES_IMPLEMENTED; i++) {
  ------------------
  |  |  245|  4.34M|#define ssl_V3_SUITES_IMPLEMENTED 71
  ------------------
  |  Branch (971:17): [True: 4.28M, False: 60.3k]
  ------------------
  972|  4.28M|        suite = &ss->cipherSuites[i];
  973|  4.28M|        if (suite->enabled) {
  ------------------
  |  Branch (973:13): [True: 4.28M, False: 0]
  ------------------
  974|  4.28M|            ++numEnabled;
  975|       |            /* We need the cipher defs to see if we have a token that can handle
  976|       |             * this cipher.  It isn't part of the static definition.
  977|       |             */
  978|  4.28M|            cipher_def = ssl_LookupCipherSuiteDef(suite->cipher_suite);
  979|  4.28M|            if (!cipher_def) {
  ------------------
  |  Branch (979:17): [True: 0, False: 4.28M]
  ------------------
  980|      0|                suite->isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  981|      0|                continue;
  982|      0|            }
  983|  4.28M|            cipher_alg = ssl_GetBulkCipherDef(cipher_def)->calg;
  984|  4.28M|            cipher_mech = ssl3_Alg2Mech(cipher_alg);
  985|       |
  986|       |            /* Mark the suites that are backed by real tokens, certs and keys */
  987|  4.28M|            suite->isPresent = PR_TRUE;
  ------------------
  |  |  437|  4.28M|#define PR_TRUE 1
  ------------------
  988|       |
  989|  4.28M|            authType = kea_defs[cipher_def->key_exchange_alg].authKeyType;
  990|  4.28M|            if (authType != ssl_auth_null && authType != ssl_auth_tls13_any) {
  ------------------
  |  Branch (990:17): [True: 4.28M, False: 0]
  |  Branch (990:46): [True: 4.10M, False: 181k]
  ------------------
  991|  4.10M|                if (ss->sec.isServer &&
  ------------------
  |  Branch (991:21): [True: 4.10M, False: 0]
  ------------------
  992|  4.10M|                    !(ssl_HasCert(ss, ss->vrange.max, authType) &&
  ------------------
  |  Branch (992:23): [True: 3.08M, False: 1.02M]
  ------------------
  993|  4.10M|                      ssl_HasSignatureScheme(ss, authType))) {
  ------------------
  |  Branch (993:23): [True: 3.08M, False: 0]
  ------------------
  994|  1.02M|                    suite->isPresent = PR_FALSE;
  ------------------
  |  |  438|  1.02M|#define PR_FALSE 0
  ------------------
  995|  3.08M|                } else if (!PK11_TokenExists(auth_alg_defs[authType])) {
  ------------------
  |  Branch (995:28): [True: 0, False: 3.08M]
  ------------------
  996|      0|                    suite->isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  997|      0|                }
  998|  4.10M|            }
  999|       |
 1000|  4.28M|            keaType = kea_defs[cipher_def->key_exchange_alg].exchKeyType;
 1001|  4.28M|            if (keaType != ssl_kea_null &&
  ------------------
  |  Branch (1001:17): [True: 4.28M, False: 0]
  ------------------
 1002|  4.28M|                keaType != ssl_kea_tls13_any &&
  ------------------
  |  Branch (1002:17): [True: 4.10M, False: 181k]
  ------------------
 1003|  4.28M|                !PK11_TokenExists(kea_alg_defs[keaType])) {
  ------------------
  |  Branch (1003:17): [True: 0, False: 4.10M]
  ------------------
 1004|      0|                suite->isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1005|      0|            }
 1006|       |
 1007|  4.28M|            if (cipher_alg != ssl_calg_null &&
  ------------------
  |  Branch (1007:17): [True: 3.86M, False: 422k]
  ------------------
 1008|  4.28M|                !PK11_TokenExists(cipher_mech)) {
  ------------------
  |  Branch (1008:17): [True: 0, False: 3.86M]
  ------------------
 1009|      0|                suite->isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1010|      0|            }
 1011|       |
 1012|  4.28M|            if (suite->isPresent) {
  ------------------
  |  Branch (1012:17): [True: 3.26M, False: 1.02M]
  ------------------
 1013|  3.26M|                ++numPresent;
 1014|  3.26M|            }
 1015|  4.28M|        }
 1016|  4.28M|    }
 1017|  60.3k|    PORT_AssertArg(numPresent > 0 || numEnabled == 0);
  ------------------
  |  |  124|  60.3k|#define PORT_AssertArg PR_ASSERT_ARG
  |  |  ------------------
  |  |  |  |  210|  60.3k|#define PR_ASSERT_ARG(_expr) PR_ASSERT(_expr)
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  60.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 60.3k, False: 0]
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1018|  60.3k|    if (numPresent == 0) {
  ------------------
  |  Branch (1018:9): [True: 0, False: 60.3k]
  ------------------
 1019|      0|        PORT_SetError(SSL_ERROR_NO_CIPHERS_SUPPORTED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1020|      0|    }
 1021|  60.3k|    return numPresent;
 1022|  60.3k|}
ssl3_config_match:
 1030|  2.11M|{
 1031|  2.11M|    const ssl3CipherSuiteDef *cipher_def;
 1032|  2.11M|    const ssl3KEADef *kea_def;
 1033|       |
 1034|  2.11M|    if (!suite) {
  ------------------
  |  Branch (1034:9): [True: 0, False: 2.11M]
  ------------------
 1035|      0|        PORT_Assert(suite);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1036|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1037|      0|    }
 1038|       |
 1039|  2.11M|    PORT_Assert(policy != SSL_NOT_ALLOWED);
  ------------------
  |  |  120|  2.11M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.11M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.11M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1040|  2.11M|    if (policy == SSL_NOT_ALLOWED)
  ------------------
  |  |  699|  2.11M|#define SSL_NOT_ALLOWED 0 /* or invalid or unimplemented */
  ------------------
  |  Branch (1040:9): [True: 0, False: 2.11M]
  ------------------
 1041|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1042|       |
 1043|  2.11M|    if (!suite->enabled || !suite->isPresent)
  ------------------
  |  Branch (1043:9): [True: 0, False: 2.11M]
  |  Branch (1043:28): [True: 392k, False: 1.72M]
  ------------------
 1044|   392k|        return PR_FALSE;
  ------------------
  |  |  438|   392k|#define PR_FALSE 0
  ------------------
 1045|       |
 1046|  1.72M|    if ((suite->policy == SSL_NOT_ALLOWED) ||
  ------------------
  |  |  699|  1.72M|#define SSL_NOT_ALLOWED 0 /* or invalid or unimplemented */
  ------------------
  |  Branch (1046:9): [True: 0, False: 1.72M]
  ------------------
 1047|  1.72M|        (suite->policy > policy))
  ------------------
  |  Branch (1047:9): [True: 0, False: 1.72M]
  ------------------
 1048|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1049|       |
 1050|  1.72M|    PORT_Assert(ss != NULL);
  ------------------
  |  |  120|  1.72M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.72M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.72M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1051|  1.72M|    cipher_def = ssl_LookupCipherSuiteDef(suite->cipher_suite);
 1052|  1.72M|    PORT_Assert(cipher_def != NULL);
  ------------------
  |  |  120|  1.72M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.72M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.72M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1053|  1.72M|    kea_def = &kea_defs[cipher_def->key_exchange_alg];
 1054|  1.72M|    PORT_Assert(kea_def != NULL);
  ------------------
  |  |  120|  1.72M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.72M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.72M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1055|  1.72M|    if (!ssl_KEAEnabled(ss, kea_def->exchKeyType)) {
  ------------------
  |  Branch (1055:9): [True: 124k, False: 1.60M]
  ------------------
 1056|   124k|        return PR_FALSE;
  ------------------
  |  |  438|   124k|#define PR_FALSE 0
  ------------------
 1057|   124k|    }
 1058|       |
 1059|  1.60M|    if (ss->sec.isServer && !ssl_HasCert(ss, vrange->max, kea_def->authKeyType)) {
  ------------------
  |  Branch (1059:9): [True: 1.60M, False: 0]
  |  Branch (1059:29): [True: 31.7k, False: 1.57M]
  ------------------
 1060|  31.7k|        return PR_FALSE;
  ------------------
  |  |  438|  31.7k|#define PR_FALSE 0
  ------------------
 1061|  31.7k|    }
 1062|       |
 1063|       |    /* If a PSK is selected, disable suites that use a different hash than
 1064|       |     * the PSK. We advertise non-PSK-compatible suites in the CH, as we could
 1065|       |     * fallback to certificate auth. The client handler will check hash
 1066|       |     * compatibility before committing to use the PSK. */
 1067|  1.57M|    if (ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (1067:9): [True: 0, False: 1.57M]
  ------------------
 1068|      0|        if (ss->xtnData.selectedPsk->hash != cipher_def->prf_hash) {
  ------------------
  |  Branch (1068:13): [True: 0, False: 0]
  ------------------
 1069|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1070|      0|        }
 1071|      0|    }
 1072|       |
 1073|  1.57M|    return ssl3_CipherSuiteAllowedForVersionRange(suite->cipher_suite, vrange);
 1074|  1.57M|}
Null_Cipher:
 1103|  1.05M|{
 1104|  1.05M|    if (inputLen > maxOutputLen) {
  ------------------
  |  Branch (1104:9): [True: 0, False: 1.05M]
  ------------------
 1105|      0|        *outputLen = 0; /* Match PK11_CipherOp in setting outputLen */
 1106|      0|        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1107|      0|        return SECFailure;
 1108|      0|    }
 1109|  1.05M|    *outputLen = inputLen;
 1110|  1.05M|    if (inputLen > 0 && input != output) {
  ------------------
  |  Branch (1110:9): [True: 1.04M, False: 7.79k]
  |  Branch (1110:25): [True: 1.04M, False: 0]
  ------------------
 1111|  1.04M|        PORT_Memcpy(output, input, inputLen);
  ------------------
  |  |  180|  1.04M|#define PORT_Memcpy memcpy
  ------------------
 1112|  1.04M|    }
 1113|  1.05M|    return SECSuccess;
 1114|  1.05M|}
ssl3_NegotiateVersion:
 1159|  58.2k|{
 1160|  58.2k|    SSL3ProtocolVersion negotiated;
 1161|       |
 1162|       |    /* Prevent negotiating to a lower version in response to a TLS 1.3 HRR. */
 1163|  58.2k|    if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (1163:9): [True: 3, False: 58.2k]
  ------------------
 1164|      3|        PORT_SetError(SSL_ERROR_UNSUPPORTED_VERSION);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
 1165|      3|        return SECFailure;
 1166|      3|    }
 1167|       |
 1168|  58.2k|    if (SSL_ALL_VERSIONS_DISABLED(&ss->vrange)) {
  ------------------
  |  | 1503|  58.2k|    ((vrange)->min == SSL_LIBRARY_VERSION_NONE)
  |  |  ------------------
  |  |  |  | 1481|  58.2k|#define SSL_LIBRARY_VERSION_NONE 0
  |  |  ------------------
  |  |  |  Branch (1503:5): [True: 0, False: 58.2k]
  |  |  ------------------
  ------------------
 1169|      0|        PORT_SetError(SSL_ERROR_SSL_DISABLED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1170|      0|        return SECFailure;
 1171|      0|    }
 1172|       |
 1173|  58.2k|    if (peerVersion < ss->vrange.min ||
  ------------------
  |  Branch (1173:9): [True: 15, False: 58.2k]
  ------------------
 1174|  58.2k|        (peerVersion > ss->vrange.max && !allowLargerPeerVersion)) {
  ------------------
  |  Branch (1174:10): [True: 6.40k, False: 51.8k]
  |  Branch (1174:42): [True: 0, False: 6.40k]
  ------------------
 1175|     15|        PORT_SetError(SSL_ERROR_UNSUPPORTED_VERSION);
  ------------------
  |  |   65|     15|#define PORT_SetError PORT_SetError_Util
  ------------------
 1176|     15|        return SECFailure;
 1177|     15|    }
 1178|       |
 1179|  58.2k|    negotiated = PR_MIN(peerVersion, ss->vrange.max);
  ------------------
  |  |  158|  58.2k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 41.6k, False: 16.6k]
  |  |  ------------------
  ------------------
 1180|  58.2k|    PORT_Assert(ssl3_VersionIsSupported(ss->protocolVariant, negotiated));
  ------------------
  |  |  120|  58.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  58.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 58.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1181|  58.2k|    if (ss->firstHsDone && ss->version != negotiated) {
  ------------------
  |  Branch (1181:9): [True: 51.3k, False: 6.94k]
  |  Branch (1181:28): [True: 1, False: 51.3k]
  ------------------
 1182|      1|        PORT_SetError(SSL_ERROR_UNSUPPORTED_VERSION);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1183|      1|        return SECFailure;
 1184|      1|    }
 1185|       |
 1186|  58.2k|    ss->version = negotiated;
 1187|  58.2k|    return SECSuccess;
 1188|  58.2k|}
ssl3_GetNewRandom:
 1226|  59.9k|{
 1227|  59.9k|    SECStatus rv;
 1228|       |
 1229|  59.9k|    rv = PK11_GenerateRandom(random, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|  59.9k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 1230|  59.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1230:9): [True: 0, False: 59.9k]
  ------------------
 1231|      0|        ssl_MapLowLevelError(SSL_ERROR_GENERATE_RANDOM_FAILURE);
 1232|      0|    }
 1233|  59.9k|    return rv;
 1234|  59.9k|}
ssl3_SignHashesWithPrivKey:
 1239|  47.3k|{
 1240|  47.3k|    SECStatus rv = SECFailure;
 1241|  47.3k|    PRBool doDerEncode = PR_FALSE;
  ------------------
  |  |  438|  47.3k|#define PR_FALSE 0
  ------------------
 1242|  47.3k|    PRBool useRsaPss = ssl_IsRsaPssSignatureScheme(scheme);
 1243|  47.3k|    SECItem hashItem;
 1244|       |
 1245|  47.3k|    buf->data = NULL;
 1246|       |
 1247|  47.3k|    switch (SECKEY_GetPrivateKeyType(key)) {
 1248|  35.5k|        case rsaKey:
  ------------------
  |  Branch (1248:9): [True: 35.5k, False: 11.7k]
  ------------------
 1249|  35.5k|            hashItem.data = hash->u.raw;
 1250|  35.5k|            hashItem.len = hash->len;
 1251|  35.5k|            break;
 1252|      0|        case dsaKey:
  ------------------
  |  Branch (1252:9): [True: 0, False: 47.3k]
  ------------------
 1253|      0|            doDerEncode = isTls;
 1254|       |            /* ssl_hash_none is used to specify the MD5/SHA1 concatenated hash.
 1255|       |             * In that case, we use just the SHA1 part. */
 1256|      0|            if (hash->hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1256:17): [True: 0, False: 0]
  ------------------
 1257|      0|                hashItem.data = hash->u.s.sha;
 1258|      0|                hashItem.len = sizeof(hash->u.s.sha);
 1259|      0|            } else {
 1260|      0|                hashItem.data = hash->u.raw;
 1261|      0|                hashItem.len = hash->len;
 1262|      0|            }
 1263|      0|            break;
 1264|  11.7k|        case ecKey:
  ------------------
  |  Branch (1264:9): [True: 11.7k, False: 35.5k]
  ------------------
 1265|  11.7k|            doDerEncode = PR_TRUE;
  ------------------
  |  |  437|  11.7k|#define PR_TRUE 1
  ------------------
 1266|       |            /* ssl_hash_none is used to specify the MD5/SHA1 concatenated hash.
 1267|       |             * In that case, we use just the SHA1 part. */
 1268|  11.7k|            if (hash->hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1268:17): [True: 859, False: 10.8k]
  ------------------
 1269|    859|                hashItem.data = hash->u.s.sha;
 1270|    859|                hashItem.len = sizeof(hash->u.s.sha);
 1271|  10.8k|            } else {
 1272|  10.8k|                hashItem.data = hash->u.raw;
 1273|  10.8k|                hashItem.len = hash->len;
 1274|  10.8k|            }
 1275|  11.7k|            break;
 1276|      0|        default:
  ------------------
  |  Branch (1276:9): [True: 0, False: 47.3k]
  ------------------
 1277|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1278|      0|            goto done;
 1279|  47.3k|    }
 1280|  47.3k|    PRINT_BUF(60, (NULL, "hash(es) to be signed", hashItem.data, hashItem.len));
  ------------------
  |  |   74|  47.3k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |   75|  47.3k|    ssl_PrintBuf b
  ------------------
 1281|       |
 1282|  47.3k|    if (useRsaPss || hash->hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1282:9): [True: 4.81k, False: 42.4k]
  |  Branch (1282:22): [True: 4.15k, False: 38.3k]
  ------------------
 1283|  8.96k|        CK_MECHANISM_TYPE mech = PK11_MapSignKeyType(key->keyType);
 1284|  8.96k|        int signatureLen = PK11_SignatureLen(key);
 1285|  8.96k|        PRInt32 optval;
 1286|       |
 1287|  8.96k|        SECItem *params = NULL;
 1288|  8.96k|        CK_RSA_PKCS_PSS_PARAMS pssParams;
 1289|  8.96k|        SECItem pssParamsItem = { siBuffer,
 1290|  8.96k|                                  (unsigned char *)&pssParams,
 1291|  8.96k|                                  sizeof(pssParams) };
 1292|       |
 1293|  8.96k|        if (signatureLen <= 0) {
  ------------------
  |  Branch (1293:13): [True: 0, False: 8.96k]
  ------------------
 1294|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1295|      0|            goto done;
 1296|      0|        }
 1297|       |        /* since we are calling PK11_SignWithMechanism directly, we need to check the
 1298|       |         * key policy ourselves (which is already checked in SGN_Digest */
 1299|  8.96k|        rv = NSS_OptionGet(NSS_KEY_SIZE_POLICY_FLAGS, &optval);
  ------------------
  |  |  317|  8.96k|#define NSS_KEY_SIZE_POLICY_FLAGS 0x00e
  ------------------
 1300|  8.96k|        if ((rv == SECSuccess) &&
  ------------------
  |  Branch (1300:13): [True: 8.96k, False: 0]
  ------------------
 1301|  8.96k|            ((optval & NSS_KEY_SIZE_POLICY_SIGN_FLAG) == NSS_KEY_SIZE_POLICY_SIGN_FLAG)) {
  ------------------
  |  |  323|  8.96k|#define NSS_KEY_SIZE_POLICY_SIGN_FLAG 4
  ------------------
                          ((optval & NSS_KEY_SIZE_POLICY_SIGN_FLAG) == NSS_KEY_SIZE_POLICY_SIGN_FLAG)) {
  ------------------
  |  |  323|  8.96k|#define NSS_KEY_SIZE_POLICY_SIGN_FLAG 4
  ------------------
  |  Branch (1301:13): [True: 8.96k, False: 0]
  ------------------
 1302|  8.96k|            rv = SECKEY_EnforceKeySize(key->keyType, SECKEY_PrivateKeyStrengthInBits(key),
 1303|  8.96k|                                       SEC_ERROR_SIGNATURE_ALGORITHM_DISABLED);
 1304|  8.96k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1304:17): [True: 0, False: 8.96k]
  ------------------
 1305|      0|                goto done; /* error code already set */
 1306|      0|            }
 1307|  8.96k|        }
 1308|       |
 1309|  8.96k|        buf->len = (unsigned)signatureLen;
 1310|  8.96k|        buf->data = (unsigned char *)PORT_Alloc(signatureLen);
  ------------------
  |  |   52|  8.96k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1311|  8.96k|        if (!buf->data)
  ------------------
  |  Branch (1311:13): [True: 0, False: 8.96k]
  ------------------
 1312|      0|            goto done; /* error code was set. */
 1313|       |
 1314|  8.96k|        if (useRsaPss) {
  ------------------
  |  Branch (1314:13): [True: 4.81k, False: 4.15k]
  ------------------
 1315|  4.81k|            pssParams.hashAlg = ssl3_GetHashMechanismByHashType(hash->hashAlg);
 1316|  4.81k|            pssParams.mgf = ssl3_GetMgfMechanismByHashType(hash->hashAlg);
 1317|  4.81k|            pssParams.sLen = hashItem.len;
 1318|  4.81k|            params = &pssParamsItem;
 1319|  4.81k|            mech = CKM_RSA_PKCS_PSS;
  ------------------
  |  |  741|  4.81k|#define CKM_RSA_PKCS_PSS 0x0000000DUL
  ------------------
 1320|  4.81k|        }
 1321|       |
 1322|  8.96k|        rv = PK11_SignWithMechanism(key, mech, params, buf, &hashItem);
 1323|  38.3k|    } else {
 1324|  38.3k|        SECOidTag hashOID = ssl3_HashTypeToOID(hash->hashAlg);
 1325|  38.3k|        rv = SGN_Digest(key, hashOID, buf, &hashItem);
 1326|  38.3k|    }
 1327|  47.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1327:9): [True: 0, False: 47.3k]
  ------------------
 1328|      0|        ssl_MapLowLevelError(SSL_ERROR_SIGN_HASHES_FAILURE);
 1329|  47.3k|    } else if (doDerEncode) {
  ------------------
  |  Branch (1329:16): [True: 11.7k, False: 35.5k]
  ------------------
 1330|  11.7k|        SECItem derSig = { siBuffer, NULL, 0 };
 1331|       |
 1332|       |        /* This also works for an ECDSA signature */
 1333|  11.7k|        rv = DSAU_EncodeDerSigWithLen(&derSig, buf, buf->len);
 1334|  11.7k|        if (rv == SECSuccess) {
  ------------------
  |  Branch (1334:13): [True: 11.7k, False: 0]
  ------------------
 1335|  11.7k|            PORT_Free(buf->data); /* discard unencoded signature. */
  ------------------
  |  |   60|  11.7k|#define PORT_Free PORT_Free_Util
  ------------------
 1336|  11.7k|            *buf = derSig;        /* give caller encoded signature. */
 1337|  11.7k|        } else if (derSig.data) {
  ------------------
  |  Branch (1337:20): [True: 0, False: 0]
  ------------------
 1338|      0|            PORT_Free(derSig.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1339|      0|        }
 1340|  11.7k|    }
 1341|       |
 1342|  47.3k|    PRINT_BUF(60, (NULL, "signed hashes", (unsigned char *)buf->data, buf->len));
  ------------------
  |  |   74|  47.3k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 47.3k]
  |  |  ------------------
  |  |   75|  47.3k|    ssl_PrintBuf b
  ------------------
 1343|  47.3k|done:
 1344|  47.3k|    if (rv != SECSuccess && buf->data) {
  ------------------
  |  Branch (1344:9): [True: 0, False: 47.3k]
  |  Branch (1344:29): [True: 0, False: 0]
  ------------------
 1345|      0|        PORT_Free(buf->data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1346|      0|        buf->data = NULL;
 1347|      0|    }
 1348|  47.3k|    return rv;
 1349|  47.3k|}
ssl3_SignHashes:
 1355|  47.3k|{
 1356|  47.3k|    SECStatus rv = SECFailure;
 1357|  47.3k|    PRBool isTLS = (PRBool)(ss->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  47.3k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
 1358|  47.3k|    SSLSignatureScheme scheme = ss->ssl3.hs.signatureScheme;
 1359|       |
 1360|  47.3k|    rv = ssl3_SignHashesWithPrivKey(hash, key, scheme, isTLS, buf);
 1361|  47.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1361:9): [True: 0, False: 47.3k]
  ------------------
 1362|      0|        return SECFailure;
 1363|      0|    }
 1364|       |
 1365|  47.3k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1365:9): [True: 47.3k, False: 0]
  ------------------
 1366|  47.3k|        ss->sec.signatureScheme = scheme;
 1367|  47.3k|        ss->sec.authType = ssl_SignatureSchemeToAuthType(scheme);
 1368|  47.3k|    }
 1369|       |
 1370|  47.3k|    return SECSuccess;
 1371|  47.3k|}
ssl_VerifySignedHashesWithPubKey:
 1378|  3.01k|{
 1379|  3.01k|    SECItem *signature = NULL;
 1380|  3.01k|    SECStatus rv = SECFailure;
 1381|  3.01k|    SECItem hashItem;
 1382|  3.01k|    SECOidTag encAlg;
 1383|  3.01k|    SECOidTag hashAlg;
 1384|  3.01k|    void *pwArg = ss->pkcs11PinArg;
 1385|  3.01k|    PRBool isRsaPssScheme = ssl_IsRsaPssSignatureScheme(scheme);
 1386|       |
 1387|  3.01k|    PRINT_BUF(60, (NULL, "check signed hashes", buf->data, buf->len));
  ------------------
  |  |   74|  3.01k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 3.01k]
  |  |  ------------------
  |  |   75|  3.01k|    ssl_PrintBuf b
  ------------------
 1388|       |
 1389|  3.01k|    hashAlg = ssl3_HashTypeToOID(hash->hashAlg);
 1390|  3.01k|    switch (SECKEY_GetPublicKeyType(key)) {
 1391|  3.01k|        case rsaKey:
  ------------------
  |  Branch (1391:9): [True: 3.01k, False: 0]
  ------------------
 1392|  3.01k|            encAlg = SEC_OID_PKCS1_RSA_ENCRYPTION;
 1393|  3.01k|            hashItem.data = hash->u.raw;
 1394|  3.01k|            hashItem.len = hash->len;
 1395|  3.01k|            if (scheme == ssl_sig_none) {
  ------------------
  |  Branch (1395:17): [True: 22, False: 2.99k]
  ------------------
 1396|     22|                scheme = ssl_sig_rsa_pkcs1_sha1md5;
 1397|     22|            }
 1398|  3.01k|            break;
 1399|      0|        case dsaKey:
  ------------------
  |  Branch (1399:9): [True: 0, False: 3.01k]
  ------------------
 1400|      0|            encAlg = SEC_OID_ANSIX9_DSA_SIGNATURE;
 1401|       |            /* ssl_hash_none is used to specify the MD5/SHA1 concatenated hash.
 1402|       |             * In that case, we use just the SHA1 part. */
 1403|      0|            if (hash->hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1403:17): [True: 0, False: 0]
  ------------------
 1404|      0|                hashItem.data = hash->u.s.sha;
 1405|      0|                hashItem.len = sizeof(hash->u.s.sha);
 1406|      0|            } else {
 1407|      0|                hashItem.data = hash->u.raw;
 1408|      0|                hashItem.len = hash->len;
 1409|      0|            }
 1410|       |            /* Allow DER encoded DSA signatures in SSL 3.0 */
 1411|      0|            if (ss->ssl3.prSpec->version > SSL_LIBRARY_VERSION_3_0 ||
  ------------------
  |  |   17|      0|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (1411:17): [True: 0, False: 0]
  ------------------
 1412|      0|                buf->len != SECKEY_SignatureLen(key)) {
  ------------------
  |  Branch (1412:17): [True: 0, False: 0]
  ------------------
 1413|      0|                signature = DSAU_DecodeDerSigToLen(buf, SECKEY_SignatureLen(key));
 1414|      0|                if (!signature) {
  ------------------
  |  Branch (1414:21): [True: 0, False: 0]
  ------------------
 1415|      0|                    PORT_SetError(SSL_ERROR_BAD_HANDSHAKE_HASH_VALUE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1416|      0|                    goto loser;
 1417|      0|                }
 1418|      0|                buf = signature;
 1419|      0|            }
 1420|      0|            if (scheme == ssl_sig_none) {
  ------------------
  |  Branch (1420:17): [True: 0, False: 0]
  ------------------
 1421|      0|                scheme = ssl_sig_dsa_sha1;
 1422|      0|            }
 1423|      0|            break;
 1424|       |
 1425|      0|        case ecKey:
  ------------------
  |  Branch (1425:9): [True: 0, False: 3.01k]
  ------------------
 1426|      0|            encAlg = SEC_OID_ANSIX962_EC_PUBLIC_KEY;
 1427|       |            /* ssl_hash_none is used to specify the MD5/SHA1 concatenated hash.
 1428|       |             * In that case, we use just the SHA1 part.
 1429|       |             * ECDSA signatures always encode the integers r and s using ASN.1
 1430|       |             * (unlike DSA where ASN.1 encoding is used with TLS but not with
 1431|       |             * SSL3). So we can use VFY_VerifyDigestDirect for ECDSA.
 1432|       |             */
 1433|      0|            if (hash->hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1433:17): [True: 0, False: 0]
  ------------------
 1434|      0|                hashAlg = SEC_OID_SHA1;
 1435|      0|                hashItem.data = hash->u.s.sha;
 1436|      0|                hashItem.len = sizeof(hash->u.s.sha);
 1437|      0|            } else {
 1438|      0|                hashItem.data = hash->u.raw;
 1439|      0|                hashItem.len = hash->len;
 1440|      0|            }
 1441|      0|            if (scheme == ssl_sig_none) {
  ------------------
  |  Branch (1441:17): [True: 0, False: 0]
  ------------------
 1442|      0|                scheme = ssl_sig_ecdsa_sha1;
 1443|      0|            }
 1444|      0|            break;
 1445|       |
 1446|      0|        default:
  ------------------
  |  Branch (1446:9): [True: 0, False: 3.01k]
  ------------------
 1447|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_KEYALG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1448|      0|            goto loser;
 1449|  3.01k|    }
 1450|       |
 1451|  3.01k|    PRINT_BUF(60, (NULL, "hash(es) to be verified",
  ------------------
  |  |   74|  3.01k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 3.01k]
  |  |  ------------------
  |  |   75|  3.01k|    ssl_PrintBuf b
  ------------------
 1452|  3.01k|                   hashItem.data, hashItem.len));
 1453|       |
 1454|  3.01k|    if (isRsaPssScheme ||
  ------------------
  |  Branch (1454:9): [True: 38, False: 2.98k]
  ------------------
 1455|  3.01k|        hashAlg == SEC_OID_UNKNOWN ||
  ------------------
  |  Branch (1455:9): [True: 22, False: 2.95k]
  ------------------
 1456|  3.01k|        SECKEY_GetPublicKeyType(key) == dsaKey) {
  ------------------
  |  Branch (1456:9): [True: 0, False: 2.95k]
  ------------------
 1457|       |        /* VFY_VerifyDigestDirect requires DSA signatures to be DER-encoded.
 1458|       |         * DSA signatures are DER-encoded in TLS but not in SSL3 and the code
 1459|       |         * above always removes the DER encoding of DSA signatures when
 1460|       |         * present. Thus DSA signatures are always verified with PK11_Verify.
 1461|       |         */
 1462|     60|        CK_MECHANISM_TYPE mech = PK11_MapSignKeyType(key->keyType);
 1463|       |
 1464|     60|        SECItem *params = NULL;
 1465|     60|        CK_RSA_PKCS_PSS_PARAMS pssParams;
 1466|     60|        SECItem pssParamsItem = { siBuffer,
 1467|     60|                                  (unsigned char *)&pssParams,
 1468|     60|                                  sizeof(pssParams) };
 1469|       |
 1470|     60|        if (isRsaPssScheme) {
  ------------------
  |  Branch (1470:13): [True: 38, False: 22]
  ------------------
 1471|     38|            pssParams.hashAlg = ssl3_GetHashMechanismByHashType(hash->hashAlg);
 1472|     38|            pssParams.mgf = ssl3_GetMgfMechanismByHashType(hash->hashAlg);
 1473|     38|            pssParams.sLen = hashItem.len;
 1474|     38|            params = &pssParamsItem;
 1475|     38|            mech = CKM_RSA_PKCS_PSS;
  ------------------
  |  |  741|     38|#define CKM_RSA_PKCS_PSS 0x0000000DUL
  ------------------
 1476|     38|        }
 1477|       |
 1478|     60|        rv = PK11_VerifyWithMechanism(key, mech, params, buf, &hashItem, pwArg);
 1479|  2.95k|    } else {
 1480|  2.95k|        rv = VFY_VerifyDigestDirect(&hashItem, key, buf, encAlg, hashAlg,
 1481|  2.95k|                                    pwArg);
 1482|  2.95k|    }
 1483|  3.01k|    if (signature) {
  ------------------
  |  Branch (1483:9): [True: 0, False: 3.01k]
  ------------------
 1484|      0|        SECITEM_FreeItem(signature, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(signature, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1485|      0|    }
 1486|  3.01k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1486:9): [True: 3.01k, False: 0]
  ------------------
 1487|  3.01k|        ssl_MapLowLevelError(SSL_ERROR_BAD_HANDSHAKE_HASH_VALUE);
 1488|  3.01k|    }
 1489|  3.01k|    if (!ss->sec.isServer) {
  ------------------
  |  Branch (1489:9): [True: 0, False: 3.01k]
  ------------------
 1490|      0|        ss->sec.signatureScheme = scheme;
 1491|      0|        ss->sec.authType = ssl_SignatureSchemeToAuthType(scheme);
 1492|      0|    }
 1493|       |
 1494|  3.01k|loser:
 1495|  3.01k|#ifdef UNSAFE_FUZZER_MODE
 1496|  3.01k|    rv = SECSuccess;
 1497|  3.01k|    PORT_SetError(0);
  ------------------
  |  |   65|  3.01k|#define PORT_SetError PORT_SetError_Util
  ------------------
 1498|  3.01k|#endif
 1499|  3.01k|    return rv;
 1500|  3.01k|}
ssl3_VerifySignedHashes:
 1506|  3.02k|{
 1507|  3.02k|    SECKEYPublicKey *pubKey =
 1508|  3.02k|        SECKEY_ExtractPublicKey(&ss->sec.peerCert->subjectPublicKeyInfo);
 1509|  3.02k|    if (pubKey == NULL) {
  ------------------
  |  Branch (1509:9): [True: 4, False: 3.01k]
  ------------------
 1510|      4|        ssl_MapLowLevelError(SSL_ERROR_EXTRACT_PUBLIC_KEY_FAILURE);
 1511|      4|        return SECFailure;
 1512|      4|    }
 1513|  3.01k|    SECStatus rv = ssl_VerifySignedHashesWithPubKey(ss, pubKey, scheme,
 1514|  3.01k|                                                    hash, buf);
 1515|  3.01k|    SECKEY_DestroyPublicKey(pubKey);
 1516|  3.01k|    return rv;
 1517|  3.02k|}
ssl3_ComputeCommonKeyHash:
 1529|  46.0k|{
 1530|  46.0k|    SECStatus rv;
 1531|  46.0k|    SECOidTag hashOID;
 1532|  46.0k|    PRUint32 policy;
 1533|       |
 1534|  46.0k|    if (hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1534:9): [True: 4.15k, False: 41.9k]
  ------------------
 1535|  4.15k|        if ((NSS_GetAlgorithmPolicy(SEC_OID_SHA1, &policy) == SECSuccess) &&
  ------------------
  |  Branch (1535:13): [True: 4.15k, False: 0]
  ------------------
 1536|  4.15k|            !(policy & NSS_USE_ALG_IN_SSL_KX)) {
  ------------------
  |  |  572|  4.15k|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
  |  Branch (1536:13): [True: 0, False: 4.15k]
  ------------------
 1537|      0|            ssl_MapLowLevelError(SSL_ERROR_UNSUPPORTED_HASH_ALGORITHM);
 1538|      0|            return SECFailure;
 1539|      0|        }
 1540|  4.15k|        rv = PK11_HashBuf(SEC_OID_MD5, hashes->u.s.md5, hashBuf, bufLen);
 1541|  4.15k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1541:13): [True: 0, False: 4.15k]
  ------------------
 1542|      0|            ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 1543|      0|            return rv;
 1544|      0|        }
 1545|  4.15k|        rv = PK11_HashBuf(SEC_OID_SHA1, hashes->u.s.sha, hashBuf, bufLen);
 1546|  4.15k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1546:13): [True: 0, False: 4.15k]
  ------------------
 1547|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 1548|      0|            return rv;
 1549|      0|        }
 1550|  4.15k|        hashes->len = MD5_LENGTH + SHA1_LENGTH;
  ------------------
  |  |   38|  4.15k|#define MD5_LENGTH 16
  ------------------
                      hashes->len = MD5_LENGTH + SHA1_LENGTH;
  ------------------
  |  |   39|  4.15k|#define SHA1_LENGTH 20
  ------------------
 1551|  41.9k|    } else {
 1552|  41.9k|        hashOID = ssl3_HashTypeToOID(hashAlg);
 1553|  41.9k|        if ((NSS_GetAlgorithmPolicy(hashOID, &policy) == SECSuccess) &&
  ------------------
  |  Branch (1553:13): [True: 41.9k, False: 0]
  ------------------
 1554|  41.9k|            !(policy & NSS_USE_ALG_IN_SSL_KX)) {
  ------------------
  |  |  572|  41.9k|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
  |  Branch (1554:13): [True: 0, False: 41.9k]
  ------------------
 1555|      0|            ssl_MapLowLevelError(SSL_ERROR_UNSUPPORTED_HASH_ALGORITHM);
 1556|      0|            return SECFailure;
 1557|      0|        }
 1558|  41.9k|        hashes->len = HASH_ResultLenByOidTag(hashOID);
 1559|  41.9k|        if (hashes->len == 0 || hashes->len > sizeof(hashes->u.raw)) {
  ------------------
  |  Branch (1559:13): [True: 0, False: 41.9k]
  |  Branch (1559:33): [True: 0, False: 41.9k]
  ------------------
 1560|      0|            ssl_MapLowLevelError(SSL_ERROR_UNSUPPORTED_HASH_ALGORITHM);
 1561|      0|            return SECFailure;
 1562|      0|        }
 1563|  41.9k|        rv = PK11_HashBuf(hashOID, hashes->u.raw, hashBuf, bufLen);
 1564|  41.9k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1564:13): [True: 0, False: 41.9k]
  ------------------
 1565|      0|            ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 1566|      0|            return rv;
 1567|      0|        }
 1568|  41.9k|    }
 1569|  46.0k|    hashes->hashAlg = hashAlg;
 1570|  46.0k|    return SECSuccess;
 1571|  46.0k|}
ssl3_SetupBothPendingCipherSpecs:
 1693|  58.7k|{
 1694|  58.7k|    ssl3CipherSuite suite = ss->ssl3.hs.cipher_suite;
 1695|  58.7k|    SSL3KeyExchangeAlgorithm kea;
 1696|  58.7k|    const ssl3CipherSuiteDef *suiteDef;
 1697|  58.7k|    SECStatus rv;
 1698|       |
 1699|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1700|  58.7k|    PORT_Assert(ss->version < SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  58.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 58.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1701|       |
 1702|  58.7k|    ssl_GetSpecWriteLock(ss); /*******************************/
  ------------------
  |  | 1435|  58.7k|    {                                            \
  |  | 1436|  58.7k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 30.1k, False: 28.5k]
  |  |  ------------------
  |  | 1437|  58.7k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  30.1k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  58.7k|    }
  ------------------
 1703|       |
 1704|       |    /* This hack provides maximal interoperability with SSL 3 servers. */
 1705|  58.7k|    if (ss->ssl3.cwSpec->macDef->mac == ssl_mac_null) {
  ------------------
  |  Branch (1705:9): [True: 6.71k, False: 52.0k]
  ------------------
 1706|       |        /* SSL records are not being MACed. */
 1707|  6.71k|        ss->ssl3.cwSpec->version = ss->version;
 1708|  6.71k|    }
 1709|       |
 1710|  58.7k|    SSL_TRC(3, ("%d: SSL3[%d]: Set XXX Pending Cipher Suite to 0x%04x",
  ------------------
  |  |   71|  58.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 58.7k]
  |  |  ------------------
  |  |   72|  58.7k|    ssl_Trace b
  ------------------
 1711|  58.7k|                SSL_GETPID(), ss->fd, suite));
 1712|       |
 1713|  58.7k|    suiteDef = ssl_LookupCipherSuiteDef(suite);
 1714|  58.7k|    if (suiteDef == NULL) {
  ------------------
  |  Branch (1714:9): [True: 0, False: 58.7k]
  ------------------
 1715|      0|        goto loser;
 1716|      0|    }
 1717|       |
 1718|  58.7k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  58.7k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 58.7k]
  |  |  ------------------
  ------------------
 1719|       |        /* Double-check that we did not pick an RC4 suite */
 1720|      0|        PORT_Assert(suiteDef->bulk_cipher_alg != cipher_rc4);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1721|      0|    }
 1722|       |
 1723|  58.7k|    ss->ssl3.hs.suite_def = suiteDef;
 1724|       |
 1725|  58.7k|    kea = suiteDef->key_exchange_alg;
 1726|  58.7k|    ss->ssl3.hs.kea_def = &kea_defs[kea];
 1727|  58.7k|    PORT_Assert(ss->ssl3.hs.kea_def->kea == kea);
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  58.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 58.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1728|       |
 1729|  58.7k|    rv = ssl3_SetupPendingCipherSpec(ss, ssl_secret_read, suiteDef,
 1730|  58.7k|                                     &ss->ssl3.prSpec);
 1731|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1731:9): [True: 0, False: 58.7k]
  ------------------
 1732|      0|        goto loser;
 1733|      0|    }
 1734|  58.7k|    rv = ssl3_SetupPendingCipherSpec(ss, ssl_secret_write, suiteDef,
 1735|  58.7k|                                     &ss->ssl3.pwSpec);
 1736|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1736:9): [True: 0, False: 58.7k]
  ------------------
 1737|      0|        goto loser;
 1738|      0|    }
 1739|       |
 1740|  58.7k|    if (ssl3_ExtensionNegotiated(ss, ssl_record_size_limit_xtn)) {
  ------------------
  |  Branch (1740:9): [True: 48, False: 58.6k]
  ------------------
 1741|     48|        ss->ssl3.prSpec->recordSizeLimit = PR_MIN(MAX_FRAGMENT_LENGTH,
  ------------------
  |  |  158|     48|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 48, False: 0]
  |  |  ------------------
  ------------------
 1742|     48|                                                  ss->opt.recordSizeLimit);
 1743|     48|        ss->ssl3.pwSpec->recordSizeLimit = PR_MIN(MAX_FRAGMENT_LENGTH,
  ------------------
  |  |  158|     48|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 48]
  |  |  ------------------
  ------------------
 1744|     48|                                                  ss->xtnData.recordSizeLimit);
 1745|     48|    }
 1746|       |
 1747|  58.7k|    ssl_ReleaseSpecWriteLock(ss); /*******************************/
  ------------------
  |  | 1440|  58.7k|    {                                              \
  |  | 1441|  58.7k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 30.1k, False: 28.5k]
  |  |  ------------------
  |  | 1442|  58.7k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  30.1k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  58.7k|    }
  ------------------
 1748|  58.7k|    return SECSuccess;
 1749|       |
 1750|      0|loser:
 1751|      0|    ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 1752|      0|    return SECFailure;
 1753|  58.7k|}
ssl3_InitPendingCipherSpecs:
 1898|  55.8k|{
 1899|  55.8k|    PK11SymKey *masterSecret;
 1900|  55.8k|    ssl3CipherSpec *pwSpec;
 1901|  55.8k|    ssl3CipherSpec *prSpec;
 1902|  55.8k|    SECStatus rv;
 1903|       |
 1904|  55.8k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  84.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27.2k, False: 28.6k]
  |  |  |  |  |  Branch (208:7): [True: 28.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1905|  55.8k|    PORT_Assert(secret);
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  55.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 55.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1906|       |
 1907|  55.8k|    ssl_GetSpecWriteLock(ss); /**************************************/
  ------------------
  |  | 1435|  55.8k|    {                                            \
  |  | 1436|  55.8k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 28.6k, False: 27.2k]
  |  |  ------------------
  |  | 1437|  55.8k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  28.6k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  55.8k|    }
  ------------------
 1908|       |
 1909|  55.8k|    PORT_Assert(ss->ssl3.pwSpec);
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  55.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 55.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1910|  55.8k|    PORT_Assert(ss->ssl3.cwSpec->epoch == ss->ssl3.crSpec->epoch);
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  55.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 55.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1911|  55.8k|    prSpec = ss->ssl3.prSpec;
 1912|  55.8k|    pwSpec = ss->ssl3.pwSpec;
 1913|       |
 1914|  55.8k|    if (ss->ssl3.cwSpec->epoch == PR_UINT16_MAX) {
  ------------------
  |  |  270|  55.8k|#define PR_UINT16_MAX 65535U
  ------------------
  |  Branch (1914:9): [True: 0, False: 55.8k]
  ------------------
 1915|       |        /* The problem here is that we have rehandshaked too many
 1916|       |         * times (you are not allowed to wrap the epoch). The
 1917|       |         * spec says you should be discarding the connection
 1918|       |         * and start over, so not much we can do here. */
 1919|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1920|      0|        goto loser;
 1921|      0|    }
 1922|       |
 1923|  55.8k|    if (derive) {
  ------------------
  |  Branch (1923:9): [True: 55.8k, False: 0]
  ------------------
 1924|  55.8k|        rv = ssl3_ComputeMasterSecret(ss, secret, &masterSecret);
 1925|  55.8k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1925:13): [True: 0, False: 55.8k]
  ------------------
 1926|      0|            goto loser;
 1927|      0|        }
 1928|  55.8k|    } else {
 1929|      0|        masterSecret = secret;
 1930|      0|    }
 1931|       |
 1932|  55.8k|    PORT_Assert(masterSecret);
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  55.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 55.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1933|  55.8k|    rv = ssl3_DeriveConnectionKeys(ss, masterSecret);
 1934|  55.8k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1934:9): [True: 0, False: 55.8k]
  ------------------
 1935|      0|        if (derive) {
  ------------------
  |  Branch (1935:13): [True: 0, False: 0]
  ------------------
 1936|       |            /* masterSecret was created here. */
 1937|      0|            PK11_FreeSymKey(masterSecret);
 1938|      0|        }
 1939|      0|        goto loser;
 1940|      0|    }
 1941|       |
 1942|       |    /* Both cipher specs maintain a reference to the master secret, since each
 1943|       |     * is managed and freed independently. */
 1944|  55.8k|    prSpec->masterSecret = masterSecret;
 1945|  55.8k|    pwSpec->masterSecret = PK11_ReferenceSymKey(masterSecret);
 1946|  55.8k|    rv = ssl3_InitPendingContexts(ss, ss->ssl3.prSpec);
 1947|  55.8k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1947:9): [True: 0, False: 55.8k]
  ------------------
 1948|      0|        goto loser;
 1949|      0|    }
 1950|       |
 1951|  55.8k|    rv = ssl3_InitPendingContexts(ss, ss->ssl3.pwSpec);
 1952|  55.8k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1952:9): [True: 0, False: 55.8k]
  ------------------
 1953|      0|        goto loser;
 1954|      0|    }
 1955|       |
 1956|  55.8k|    ssl_ReleaseSpecWriteLock(ss); /******************************/
  ------------------
  |  | 1440|  55.8k|    {                                              \
  |  | 1441|  55.8k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 28.6k, False: 27.2k]
  |  |  ------------------
  |  | 1442|  55.8k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  28.6k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  55.8k|    }
  ------------------
 1957|  55.8k|    return SECSuccess;
 1958|       |
 1959|      0|loser:
 1960|      0|    ssl_ReleaseSpecWriteLock(ss); /******************************/
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 1961|      0|    ssl_MapLowLevelError(SSL_ERROR_SESSION_KEY_GEN_FAILURE);
 1962|      0|    return SECFailure;
 1963|  55.8k|}
ssl_InsertRecordHeader:
 2338|   468k|{
 2339|   468k|    SECStatus rv;
 2340|       |
 2341|       |#ifndef UNSAFE_FUZZER_MODE
 2342|       |    if (cwSpec->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
 2343|       |        cwSpec->epoch > TrafficKeyClearText) {
 2344|       |        if (IS_DTLS(ss)) {
 2345|       |            return dtls13_InsertCipherTextHeader(ss, cwSpec, wrBuf,
 2346|       |                                                 needsLength);
 2347|       |        }
 2348|       |        contentType = ssl_ct_application_data;
 2349|       |    }
 2350|       |#endif
 2351|   468k|    rv = sslBuffer_AppendNumber(wrBuf, contentType, 1);
 2352|   468k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2352:9): [True: 0, False: 468k]
  ------------------
 2353|      0|        return SECFailure;
 2354|      0|    }
 2355|       |
 2356|   468k|    rv = sslBuffer_AppendNumber(wrBuf, cwSpec->recordVersion, 2);
 2357|   468k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2357:9): [True: 0, False: 468k]
  ------------------
 2358|      0|        return SECFailure;
 2359|      0|    }
 2360|   468k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   468k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 468k]
  |  |  ------------------
  ------------------
 2361|      0|        rv = sslBuffer_AppendNumber(wrBuf, cwSpec->epoch, 2);
 2362|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2362:13): [True: 0, False: 0]
  ------------------
 2363|      0|            return SECFailure;
 2364|      0|        }
 2365|      0|        rv = sslBuffer_AppendNumber(wrBuf, cwSpec->nextSeqNum, 6);
 2366|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2366:13): [True: 0, False: 0]
  ------------------
 2367|      0|            return SECFailure;
 2368|      0|        }
 2369|      0|    }
 2370|   468k|    *needsLength = PR_TRUE;
  ------------------
  |  |  437|   468k|#define PR_TRUE 1
  ------------------
 2371|   468k|    return SECSuccess;
 2372|   468k|}
ssl_ProtectRecord:
 2377|   468k|{
 2378|   468k|    PRBool needsLength;
 2379|   468k|    unsigned int lenOffset;
 2380|   468k|    SECStatus rv;
 2381|       |
 2382|   468k|    PORT_Assert(cwSpec->direction == ssl_secret_write);
  ------------------
  |  |  120|   468k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   468k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 468k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2383|   468k|    PORT_Assert(SSL_BUFFER_LEN(wrBuf) == 0);
  ------------------
  |  |  120|   468k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   468k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 468k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2384|   468k|    PORT_Assert(cwSpec->cipherDef->max_records <= RECORD_SEQ_MAX);
  ------------------
  |  |  120|   468k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   468k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 468k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2385|       |
 2386|   468k|    if (cwSpec->nextSeqNum >= cwSpec->cipherDef->max_records) {
  ------------------
  |  Branch (2386:9): [True: 0, False: 468k]
  ------------------
 2387|      0|        SSL_TRC(3, ("%d: SSL[-]: write sequence number at limit 0x%0llx",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 2388|      0|                    SSL_GETPID(), cwSpec->nextSeqNum));
 2389|      0|        PORT_SetError(SSL_ERROR_TOO_MANY_RECORDS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2390|      0|        return SECFailure;
 2391|      0|    }
 2392|       |
 2393|   468k|    rv = ssl_InsertRecordHeader(ss, cwSpec, ct, wrBuf, &needsLength);
 2394|   468k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2394:9): [True: 0, False: 468k]
  ------------------
 2395|      0|        return SECFailure;
 2396|      0|    }
 2397|   468k|    if (needsLength) {
  ------------------
  |  Branch (2397:9): [True: 468k, False: 0]
  ------------------
 2398|   468k|        rv = sslBuffer_Skip(wrBuf, 2, &lenOffset);
 2399|   468k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2399:13): [True: 0, False: 468k]
  ------------------
 2400|      0|            return SECFailure;
 2401|      0|        }
 2402|   468k|    }
 2403|       |
 2404|   468k|#ifdef UNSAFE_FUZZER_MODE
 2405|   468k|    {
 2406|   468k|        unsigned int len;
 2407|   468k|        rv = Null_Cipher(NULL, SSL_BUFFER_NEXT(wrBuf), &len,
  ------------------
  |  |   37|   468k|#define SSL_BUFFER_NEXT(b) ((b)->buf + (b)->len)
  ------------------
 2408|   468k|                         SSL_BUFFER_SPACE(wrBuf), pIn, contentLen);
  ------------------
  |  |   38|   468k|#define SSL_BUFFER_SPACE(b) ((b)->space - (b)->len)
  ------------------
 2409|   468k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2409:13): [True: 0, False: 468k]
  ------------------
 2410|      0|            return SECFailure; /* error was set */
 2411|      0|        }
 2412|   468k|        rv = sslBuffer_Skip(wrBuf, len, NULL);
 2413|   468k|        PORT_Assert(rv == SECSuccess); /* Can't fail. */
  ------------------
  |  |  120|   468k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   468k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 468k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2414|   468k|    }
 2415|       |#else
 2416|       |    if (cwSpec->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
 2417|       |        PRUint8 *cipherText = SSL_BUFFER_NEXT(wrBuf);
 2418|       |        unsigned int bufLen = SSL_BUFFER_LEN(wrBuf);
 2419|       |        rv = tls13_ProtectRecord(ss, cwSpec, ct, pIn, contentLen, wrBuf);
 2420|       |        if (rv != SECSuccess) {
 2421|       |            return SECFailure;
 2422|       |        }
 2423|       |        if (IS_DTLS(ss)) {
 2424|       |            bufLen = SSL_BUFFER_LEN(wrBuf) - bufLen;
 2425|       |            rv = dtls13_MaskSequenceNumber(ss, cwSpec,
 2426|       |                                           SSL_BUFFER_BASE(wrBuf),
 2427|       |                                           cipherText, bufLen);
 2428|       |        }
 2429|       |    } else {
 2430|       |        rv = ssl3_MACEncryptRecord(cwSpec, ss->sec.isServer, IS_DTLS(ss), ct,
 2431|       |                                   pIn, contentLen, wrBuf);
 2432|       |    }
 2433|       |#endif
 2434|   468k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2434:9): [True: 0, False: 468k]
  ------------------
 2435|      0|        return SECFailure; /* error was set */
 2436|      0|    }
 2437|       |
 2438|   468k|    if (needsLength) {
  ------------------
  |  Branch (2438:9): [True: 468k, False: 0]
  ------------------
 2439|       |        /* Insert the length. */
 2440|   468k|        rv = sslBuffer_InsertLength(wrBuf, lenOffset, 2);
 2441|   468k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2441:13): [True: 0, False: 468k]
  ------------------
 2442|      0|            PORT_Assert(0); /* Can't fail. */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2443|      0|            return SECFailure;
 2444|      0|        }
 2445|   468k|    }
 2446|       |
 2447|   468k|    ++cwSpec->nextSeqNum;
 2448|   468k|    return SECSuccess;
 2449|   468k|}
ssl_ProtectNextRecord:
 2455|   468k|{
 2456|   468k|    sslBuffer *wrBuf = &ss->sec.writeBuf;
 2457|   468k|    unsigned int contentLen;
 2458|   468k|    unsigned int spaceNeeded;
 2459|   468k|    SECStatus rv;
 2460|       |
 2461|   468k|    contentLen = PR_MIN(nIn, spec->recordSizeLimit);
  ------------------
  |  |  158|   468k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 465k, False: 2.91k]
  |  |  ------------------
  ------------------
 2462|   468k|    spaceNeeded = contentLen + SSL3_BUFFER_FUDGE;
  ------------------
  |  | 1373|   468k|#define SSL3_BUFFER_FUDGE 100
  ------------------
 2463|   468k|    if (spec->version >= SSL_LIBRARY_VERSION_TLS_1_1 &&
  ------------------
  |  |   19|   936k|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  ------------------
  |  Branch (2463:9): [True: 458k, False: 9.57k]
  ------------------
 2464|   468k|        spec->cipherDef->type == type_block) {
  ------------------
  |  Branch (2464:9): [True: 56.7k, False: 402k]
  ------------------
 2465|  56.7k|        spaceNeeded += spec->cipherDef->iv_size;
 2466|  56.7k|    }
 2467|   468k|    if (spaceNeeded > SSL_BUFFER_SPACE(wrBuf)) {
  ------------------
  |  |   38|   468k|#define SSL_BUFFER_SPACE(b) ((b)->space - (b)->len)
  ------------------
  |  Branch (2467:9): [True: 0, False: 468k]
  ------------------
 2468|      0|        rv = sslBuffer_Grow(wrBuf, spaceNeeded);
 2469|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2469:13): [True: 0, False: 0]
  ------------------
 2470|      0|            SSL_DBG(("%d: SSL3[%d]: failed to expand write buffer to %d",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 2471|      0|                     SSL_GETPID(), ss->fd, spaceNeeded));
 2472|      0|            return SECFailure;
 2473|      0|        }
 2474|      0|    }
 2475|       |
 2476|   468k|    rv = ssl_ProtectRecord(ss, spec, ct, pIn, contentLen, wrBuf);
 2477|   468k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2477:9): [True: 0, False: 468k]
  ------------------
 2478|      0|        return SECFailure;
 2479|      0|    }
 2480|   468k|    PRINT_BUF(50, (ss, "send (encrypted) record data:",
  ------------------
  |  |   74|   468k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 468k]
  |  |  ------------------
  |  |   75|   468k|    ssl_PrintBuf b
  ------------------
 2481|   468k|                   SSL_BUFFER_BASE(wrBuf), SSL_BUFFER_LEN(wrBuf)));
 2482|   468k|    *written = contentLen;
 2483|   468k|    return SECSuccess;
 2484|   468k|}
ssl3_SendRecord:
 2514|   466k|{
 2515|   466k|    sslBuffer *wrBuf = &ss->sec.writeBuf;
 2516|   466k|    ssl3CipherSpec *spec;
 2517|   466k|    SECStatus rv;
 2518|   466k|    PRInt32 totalSent = 0;
 2519|       |
 2520|   466k|    SSL_TRC(3, ("%d: SSL3[%d] SendRecord type: %s nIn=%d",
  ------------------
  |  |   71|   466k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 466k]
  |  |  ------------------
  |  |   72|   466k|    ssl_Trace b
  ------------------
 2521|   466k|                SSL_GETPID(), ss->fd, ssl3_DecodeContentType(ct),
 2522|   466k|                nIn));
 2523|   466k|    PRINT_BUF(50, (ss, "Send record (plain text)", pIn, nIn));
  ------------------
  |  |   74|   466k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 466k]
  |  |  ------------------
  |  |   75|   466k|    ssl_PrintBuf b
  ------------------
 2524|       |
 2525|   466k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|   466k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   702k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 231k, False: 235k]
  |  |  |  |  |  Branch (208:7): [True: 235k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2526|   466k|    PORT_Assert(SSL_BUFFER_LEN(wrBuf) == 0);
  ------------------
  |  |  120|   466k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   466k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 466k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2527|       |
 2528|   466k|    if (ss->ssl3.fatalAlertSent) {
  ------------------
  |  Branch (2528:9): [True: 1.19k, False: 465k]
  ------------------
 2529|  1.19k|        SSL_TRC(3, ("%d: SSL3[%d] Suppress write, fatal alert already sent",
  ------------------
  |  |   71|  1.19k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.19k]
  |  |  ------------------
  |  |   72|  1.19k|    ssl_Trace b
  ------------------
 2530|  1.19k|                    SSL_GETPID(), ss->fd));
 2531|  1.19k|        if (ct != ssl_ct_alert) {
  ------------------
  |  Branch (2531:13): [True: 8, False: 1.18k]
  ------------------
 2532|       |            /* If we are sending an alert, then we already have an
 2533|       |             * error, so don't overwrite. */
 2534|      8|            PORT_SetError(SSL_ERROR_HANDSHAKE_FAILED);
  ------------------
  |  |   65|      8|#define PORT_SetError PORT_SetError_Util
  ------------------
 2535|      8|        }
 2536|  1.19k|        return -1;
 2537|  1.19k|    }
 2538|       |
 2539|       |    /* check for Token Presence */
 2540|   465k|    if (!ssl3_ClientAuthTokenPresent(ss->sec.ci.sid)) {
  ------------------
  |  Branch (2540:9): [True: 0, False: 465k]
  ------------------
 2541|      0|        PORT_SetError(SSL_ERROR_TOKEN_INSERTION_REMOVAL);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2542|      0|        return -1;
 2543|      0|    }
 2544|       |
 2545|   465k|    if (ss->recordWriteCallback) {
  ------------------
  |  Branch (2545:9): [True: 0, False: 465k]
  ------------------
 2546|      0|        PRUint16 epoch;
 2547|      0|        ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|      0|    {                                           \
  |  | 1423|      0|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1424|      0|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|      0|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|      0|    }
  ------------------
 2548|      0|        epoch = ss->ssl3.cwSpec->epoch;
 2549|      0|        ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
 2550|      0|        rv = ss->recordWriteCallback(ss->fd, epoch, ct, pIn, nIn,
 2551|      0|                                     ss->recordWriteCallbackArg);
 2552|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2552:13): [True: 0, False: 0]
  ------------------
 2553|      0|            return -1;
 2554|      0|        }
 2555|      0|        return nIn;
 2556|      0|    }
 2557|       |
 2558|   465k|    if (cwSpec) {
  ------------------
  |  Branch (2558:9): [True: 0, False: 465k]
  ------------------
 2559|       |        /* cwSpec can only be set for retransmissions of the DTLS handshake. */
 2560|      0|        PORT_Assert(IS_DTLS(ss) &&
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2561|      0|                    (ct == ssl_ct_handshake ||
 2562|      0|                     ct == ssl_ct_change_cipher_spec));
 2563|      0|        spec = cwSpec;
 2564|   465k|    } else {
 2565|   465k|        spec = ss->ssl3.cwSpec;
 2566|   465k|    }
 2567|       |
 2568|   934k|    while (nIn > 0) {
  ------------------
  |  Branch (2568:12): [True: 468k, False: 465k]
  ------------------
 2569|   468k|        unsigned int written = 0;
 2570|   468k|        PRInt32 sent;
 2571|       |
 2572|   468k|        ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|   468k|    {                                           \
  |  | 1423|   468k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 236k, False: 231k]
  |  |  ------------------
  |  | 1424|   468k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|   236k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|   468k|    }
  ------------------
 2573|   468k|        rv = ssl_ProtectNextRecord(ss, spec, ct, pIn, nIn, &written);
 2574|   468k|        ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|   468k|    {                                             \
  |  | 1428|   468k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 236k, False: 231k]
  |  |  ------------------
  |  | 1429|   468k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|   236k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|   468k|    }
  ------------------
 2575|   468k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2575:13): [True: 0, False: 468k]
  ------------------
 2576|      0|            goto loser;
 2577|      0|        }
 2578|       |
 2579|   468k|        PORT_Assert(written > 0);
  ------------------
  |  |  120|   468k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   468k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 468k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2580|       |        /* DTLS should not fragment non-application data here. */
 2581|   468k|        if (IS_DTLS(ss) && ct != ssl_ct_application_data) {
  ------------------
  |  |  892|   936k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 468k]
  |  |  ------------------
  ------------------
  |  Branch (2581:28): [True: 0, False: 0]
  ------------------
 2582|      0|            PORT_Assert(written == nIn);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2583|      0|        }
 2584|       |
 2585|   468k|        pIn += written;
 2586|   468k|        nIn -= written;
 2587|   468k|        PORT_Assert(nIn >= 0);
  ------------------
  |  |  120|   468k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   468k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 468k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2588|       |
 2589|       |        /* If there's still some previously saved ciphertext,
 2590|       |         * or the caller doesn't want us to send the data yet,
 2591|       |         * then add all our new ciphertext to the amount previously saved.
 2592|       |         */
 2593|   468k|        if ((ss->pendingBuf.len > 0) ||
  ------------------
  |  Branch (2593:13): [True: 57.5k, False: 410k]
  ------------------
 2594|   468k|            (flags & ssl_SEND_FLAG_FORCE_INTO_BUFFER)) {
  ------------------
  |  |  223|   410k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
  |  Branch (2594:13): [True: 53.7k, False: 356k]
  ------------------
 2595|       |
 2596|   111k|            rv = ssl_SaveWriteData(ss, SSL_BUFFER_BASE(wrBuf),
  ------------------
  |  |   35|   111k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
 2597|   111k|                                   SSL_BUFFER_LEN(wrBuf));
  ------------------
  |  |   36|   111k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2598|   111k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2598:17): [True: 0, False: 111k]
  ------------------
 2599|       |                /* presumably a memory error, SEC_ERROR_NO_MEMORY */
 2600|      0|                goto loser;
 2601|      0|            }
 2602|       |
 2603|   111k|            if (!(flags & ssl_SEND_FLAG_FORCE_INTO_BUFFER)) {
  ------------------
  |  |  223|   111k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
  |  Branch (2603:17): [True: 53.7k, False: 57.5k]
  ------------------
 2604|  53.7k|                ss->handshakeBegun = 1;
 2605|  53.7k|                sent = ssl_SendSavedWriteData(ss);
 2606|  53.7k|                if (sent < 0 && PR_GetError() != PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (2606:21): [True: 0, False: 53.7k]
  |  Branch (2606:33): [True: 0, False: 0]
  ------------------
 2607|      0|                    ssl_MapLowLevelError(SSL_ERROR_SOCKET_WRITE_FAILURE);
 2608|      0|                    goto loser;
 2609|      0|                }
 2610|  53.7k|                if (ss->pendingBuf.len) {
  ------------------
  |  Branch (2610:21): [True: 0, False: 53.7k]
  ------------------
 2611|      0|                    flags |= ssl_SEND_FLAG_FORCE_INTO_BUFFER;
  ------------------
  |  |  223|      0|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
 2612|      0|                }
 2613|  53.7k|            }
 2614|   356k|        } else {
 2615|   356k|            PORT_Assert(SSL_BUFFER_LEN(wrBuf) > 0);
  ------------------
  |  |  120|   356k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   356k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 356k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2616|   356k|            ss->handshakeBegun = 1;
 2617|   356k|            sent = ssl_DefSend(ss, SSL_BUFFER_BASE(wrBuf),
  ------------------
  |  |   35|   356k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
 2618|   356k|                               SSL_BUFFER_LEN(wrBuf),
  ------------------
  |  |   36|   356k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2619|   356k|                               flags & ~ssl_SEND_FLAG_MASK);
  ------------------
  |  |  226|   356k|#define ssl_SEND_FLAG_MASK 0x7f000000
  ------------------
 2620|   356k|            if (sent < 0) {
  ------------------
  |  Branch (2620:17): [True: 0, False: 356k]
  ------------------
 2621|      0|                if (PORT_GetError() != PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
                              if (PORT_GetError() != PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (2621:21): [True: 0, False: 0]
  ------------------
 2622|      0|                    ssl_MapLowLevelError(SSL_ERROR_SOCKET_WRITE_FAILURE);
 2623|      0|                    goto loser;
 2624|      0|                }
 2625|       |                /* we got PR_WOULD_BLOCK_ERROR, which means none was sent. */
 2626|      0|                sent = 0;
 2627|      0|            }
 2628|   356k|            if (SSL_BUFFER_LEN(wrBuf) > (unsigned int)sent) {
  ------------------
  |  |   36|   356k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
  |  Branch (2628:17): [True: 0, False: 356k]
  ------------------
 2629|      0|                if (IS_DTLS(ss)) {
  ------------------
  |  |  892|      0|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2630|       |                    /* DTLS just says no in this case. No buffering */
 2631|      0|                    PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                                  PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
 2632|      0|                    goto loser;
 2633|      0|                }
 2634|       |                /* now take all the remaining unsent new ciphertext and
 2635|       |                 * append it to the buffer of previously unsent ciphertext.
 2636|       |                 */
 2637|      0|                rv = ssl_SaveWriteData(ss, SSL_BUFFER_BASE(wrBuf) + sent,
  ------------------
  |  |   35|      0|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
 2638|      0|                                       SSL_BUFFER_LEN(wrBuf) - sent);
  ------------------
  |  |   36|      0|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2639|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (2639:21): [True: 0, False: 0]
  ------------------
 2640|       |                    /* presumably a memory error, SEC_ERROR_NO_MEMORY */
 2641|      0|                    goto loser;
 2642|      0|                }
 2643|      0|            }
 2644|   356k|        }
 2645|   468k|        wrBuf->len = 0;
 2646|   468k|        totalSent += written;
 2647|   468k|    }
 2648|   465k|    return totalSent;
 2649|       |
 2650|      0|loser:
 2651|       |    /* Don't leave bits of buffer lying around. */
 2652|      0|    wrBuf->len = 0;
 2653|      0|    return -1;
 2654|   465k|}
ssl3_SendApplicationData:
 2664|   156k|{
 2665|   156k|    PRInt32 totalSent = 0;
 2666|   156k|    PRInt32 discarded = 0;
 2667|   156k|    PRBool splitNeeded = PR_FALSE;
  ------------------
  |  |  438|   156k|#define PR_FALSE 0
  ------------------
 2668|       |
 2669|   156k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|   156k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   236k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 76.8k, False: 79.9k]
  |  |  |  |  |  Branch (208:7): [True: 79.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2670|       |    /* These flags for internal use only */
 2671|   156k|    PORT_Assert(!(flags & ssl_SEND_FLAG_NO_RETRANSMIT));
  ------------------
  |  |  120|   156k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   156k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 156k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2672|   156k|    if (len < 0 || !in) {
  ------------------
  |  Branch (2672:9): [True: 0, False: 156k]
  |  Branch (2672:20): [True: 0, False: 156k]
  ------------------
 2673|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
 2674|      0|        return -1;
 2675|      0|    }
 2676|       |
 2677|   156k|    if (ss->pendingBuf.len > SSL3_PENDING_HIGH_WATER &&
  ------------------
  |  | 2656|   313k|#define SSL3_PENDING_HIGH_WATER 1024
  ------------------
  |  Branch (2677:9): [True: 0, False: 156k]
  ------------------
 2678|   156k|        !ssl_SocketIsBlocking(ss)) {
  ------------------
  |  Branch (2678:9): [True: 0, False: 0]
  ------------------
 2679|      0|        PORT_Assert(!ssl_SocketIsBlocking(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2680|      0|        PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
 2681|      0|        return -1;
 2682|      0|    }
 2683|       |
 2684|   156k|    if (ss->appDataBuffered && len) {
  ------------------
  |  Branch (2684:9): [True: 0, False: 156k]
  |  Branch (2684:32): [True: 0, False: 0]
  ------------------
 2685|      0|        PORT_Assert(in[0] == (unsigned char)(ss->appDataBuffered));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2686|      0|        if (in[0] != (unsigned char)(ss->appDataBuffered)) {
  ------------------
  |  Branch (2686:13): [True: 0, False: 0]
  ------------------
 2687|      0|            PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
 2688|      0|            return -1;
 2689|      0|        }
 2690|      0|        in++;
 2691|      0|        len--;
 2692|      0|        discarded = 1;
 2693|      0|    }
 2694|       |
 2695|       |    /* We will split the first byte of the record into its own record, as
 2696|       |     * explained in the documentation for SSL_CBC_RANDOM_IV in ssl.h.
 2697|       |     */
 2698|   156k|    if (len > 1 && ss->opt.cbcRandomIV &&
  ------------------
  |  Branch (2698:9): [True: 1.88k, False: 154k]
  |  Branch (2698:20): [True: 1.23k, False: 652]
  ------------------
 2699|   156k|        ss->version < SSL_LIBRARY_VERSION_TLS_1_1 &&
  ------------------
  |  |   19|   158k|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  ------------------
  |  Branch (2699:9): [True: 700, False: 537]
  ------------------
 2700|   156k|        ss->ssl3.cwSpec->cipherDef->type == type_block /* CBC */) {
  ------------------
  |  Branch (2700:9): [True: 633, False: 67]
  ------------------
 2701|    633|        splitNeeded = PR_TRUE;
  ------------------
  |  |  437|    633|#define PR_TRUE 1
  ------------------
 2702|    633|    }
 2703|       |
 2704|   314k|    while (len > totalSent) {
  ------------------
  |  Branch (2704:12): [True: 157k, False: 156k]
  ------------------
 2705|   157k|        PRInt32 sent, toSend;
 2706|       |
 2707|   157k|        if (totalSent > 0) {
  ------------------
  |  Branch (2707:13): [True: 633, False: 156k]
  ------------------
 2708|       |            /*
 2709|       |             * The thread yield is intended to give the reader thread a
 2710|       |             * chance to get some cycles while the writer thread is in
 2711|       |             * the middle of a large application data write.  (See
 2712|       |             * Bugzilla bug 127740, comment #1.)
 2713|       |             */
 2714|    633|            ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|    633|    {                                          \
  |  | 1472|    633|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 252, False: 381]
  |  |  ------------------
  |  | 1473|    633|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|    252|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|    633|    }
  ------------------
 2715|    633|            PR_Sleep(PR_INTERVAL_NO_WAIT); /* PR_Yield(); */
  ------------------
  |  |   53|    633|#define PR_INTERVAL_NO_WAIT 0UL
  ------------------
 2716|    633|            ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|    633|    {                                           \
  |  | 1467|    633|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 252, False: 381]
  |  |  ------------------
  |  | 1468|    633|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|    252|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|    633|    }
  ------------------
 2717|    633|        }
 2718|       |
 2719|   157k|        if (splitNeeded) {
  ------------------
  |  Branch (2719:13): [True: 633, False: 156k]
  ------------------
 2720|    633|            toSend = 1;
 2721|    633|            splitNeeded = PR_FALSE;
  ------------------
  |  |  438|    633|#define PR_FALSE 0
  ------------------
 2722|   156k|        } else {
 2723|   156k|            toSend = PR_MIN(len - totalSent, MAX_FRAGMENT_LENGTH);
  ------------------
  |  |  158|   156k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 156k, False: 0]
  |  |  ------------------
  ------------------
 2724|   156k|        }
 2725|       |
 2726|       |        /*
 2727|       |         * Note that the 0 epoch is OK because flags will never require
 2728|       |         * its use, as guaranteed by the PORT_Assert above.
 2729|       |         */
 2730|   157k|        sent = ssl3_SendRecord(ss, NULL, ssl_ct_application_data,
 2731|   157k|                               in + totalSent, toSend, flags);
 2732|   157k|        if (sent < 0) {
  ------------------
  |  Branch (2732:13): [True: 0, False: 157k]
  ------------------
 2733|      0|            if (totalSent > 0 && PR_GetError() == PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (2733:17): [True: 0, False: 0]
  |  Branch (2733:34): [True: 0, False: 0]
  ------------------
 2734|      0|                PORT_Assert(ss->lastWriteBlocked);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2735|      0|                break;
 2736|      0|            }
 2737|      0|            return -1; /* error code set by ssl3_SendRecord */
 2738|      0|        }
 2739|   157k|        totalSent += sent;
 2740|   157k|        if (ss->pendingBuf.len) {
  ------------------
  |  Branch (2740:13): [True: 0, False: 157k]
  ------------------
 2741|       |            /* must be a non-blocking socket */
 2742|      0|            PORT_Assert(!ssl_SocketIsBlocking(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2743|      0|            PORT_Assert(ss->lastWriteBlocked);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2744|      0|            break;
 2745|      0|        }
 2746|   157k|    }
 2747|   156k|    if (ss->pendingBuf.len) {
  ------------------
  |  Branch (2747:9): [True: 0, False: 156k]
  ------------------
 2748|       |        /* Must be non-blocking. */
 2749|      0|        PORT_Assert(!ssl_SocketIsBlocking(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2750|      0|        if (totalSent > 0) {
  ------------------
  |  Branch (2750:13): [True: 0, False: 0]
  ------------------
 2751|      0|            ss->appDataBuffered = 0x100 | in[totalSent - 1];
 2752|      0|        }
 2753|       |
 2754|      0|        totalSent = totalSent + discarded - 1;
 2755|      0|        if (totalSent <= 0) {
  ------------------
  |  Branch (2755:13): [True: 0, False: 0]
  ------------------
 2756|      0|            PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
 2757|      0|            totalSent = SECFailure;
 2758|      0|        }
 2759|      0|        return totalSent;
 2760|      0|    }
 2761|   156k|    ss->appDataBuffered = 0;
 2762|   156k|    return totalSent + discarded;
 2763|   156k|}
ssl3_FlushHandshake:
 2780|   583k|{
 2781|   583k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   583k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 583k]
  |  |  ------------------
  ------------------
 2782|      0|        return dtls_FlushHandshakeMessages(ss, flags);
 2783|      0|    }
 2784|   583k|    return ssl3_FlushHandshakeMessages(ss, flags);
 2785|   583k|}
ssl3_HandleNoCertificate:
 2843|    629|{
 2844|    629|    ssl3_CleanupPeerCerts(ss);
 2845|       |
 2846|       |    /* If the server has required client-auth blindly but doesn't
 2847|       |     * actually look at the certificate it won't know that no
 2848|       |     * certificate was presented so we shutdown the socket to ensure
 2849|       |     * an error.  We only do this if we haven't already completed the
 2850|       |     * first handshake because if we're redoing the handshake we
 2851|       |     * know the server is paying attention to the certificate.
 2852|       |     */
 2853|    629|    if ((ss->opt.requireCertificate == SSL_REQUIRE_ALWAYS) ||
  ------------------
  |  |  705|    629|#define SSL_REQUIRE_ALWAYS ((PRBool)1)
  ------------------
  |  Branch (2853:9): [True: 7, False: 622]
  ------------------
 2854|    629|        (!ss->firstHsDone &&
  ------------------
  |  Branch (2854:10): [True: 85, False: 537]
  ------------------
 2855|    622|         (ss->opt.requireCertificate == SSL_REQUIRE_FIRST_HANDSHAKE))) {
  ------------------
  |  |  706|     85|#define SSL_REQUIRE_FIRST_HANDSHAKE ((PRBool)2)
  ------------------
  |  Branch (2855:10): [True: 0, False: 85]
  ------------------
 2856|      7|        PRFileDesc *lower;
 2857|       |
 2858|      7|        ssl_UncacheSessionID(ss);
 2859|       |
 2860|      7|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      7|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (2860:13): [True: 2, False: 5]
  ------------------
 2861|      2|            SSL3_SendAlert(ss, alert_fatal, certificate_required);
 2862|      5|        } else {
 2863|      5|            SSL3_SendAlert(ss, alert_fatal, bad_certificate);
 2864|      5|        }
 2865|       |
 2866|      7|        lower = ss->fd->lower;
 2867|       |#ifdef _WIN32
 2868|       |        lower->methods->shutdown(lower, PR_SHUTDOWN_SEND);
 2869|       |#else
 2870|      7|        lower->methods->shutdown(lower, PR_SHUTDOWN_BOTH);
 2871|      7|#endif
 2872|      7|        PORT_SetError(SSL_ERROR_NO_CERTIFICATE);
  ------------------
  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  ------------------
 2873|      7|        return SECFailure;
 2874|      7|    }
 2875|    622|    return SECSuccess;
 2876|    629|}
SSL3_SendAlert:
 2907|  6.35k|{
 2908|  6.35k|    PRUint8 bytes[2];
 2909|  6.35k|    SECStatus rv;
 2910|  6.35k|    PRBool needHsLock = !ssl_HaveSSL3HandshakeLock(ss);
  ------------------
  |  | 1419|  6.35k|    (PZ_InMonitor((ss)->ssl3HandshakeLock))
  |  |  ------------------
  |  |  |  |  258|  6.35k|#define PZ_InMonitor(m) PR_InMonitor((m))
  |  |  |  |  ------------------
  |  |  |  |  |  |  281|  6.35k|#define PR_InMonitor(m)     (PR_GetMonitorEntryCount(m) > 0)
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2911|       |
 2912|       |    /* Check that if I need the HS lock I also need the Xmit lock */
 2913|  6.35k|    PORT_Assert(!needHsLock || !ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  6.35k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  10.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.85k, False: 4.50k]
  |  |  |  |  |  Branch (208:7): [True: 4.50k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2914|       |
 2915|  6.35k|    SSL_TRC(3, ("%d: SSL3[%d]: send alert record, level=%d desc=%d",
  ------------------
  |  |   71|  6.35k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 6.35k]
  |  |  ------------------
  |  |   72|  6.35k|    ssl_Trace b
  ------------------
 2916|  6.35k|                SSL_GETPID(), ss->fd, level, desc));
 2917|       |
 2918|  6.35k|    bytes[0] = level;
 2919|  6.35k|    bytes[1] = desc;
 2920|       |
 2921|  6.35k|    if (needHsLock) {
  ------------------
  |  Branch (2921:9): [True: 4.50k, False: 1.85k]
  ------------------
 2922|  4.50k|        ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  4.50k|    {                                                 \
  |  | 1408|  4.50k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 1.50k, False: 3.00k]
  |  |  ------------------
  |  | 1409|  1.50k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  1.50k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  1.50k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 1.50k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  1.50k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  1.50k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  1.50k|        }                                             \
  |  | 1412|  4.50k|    }
  ------------------
 2923|  4.50k|    }
 2924|  6.35k|    if (level == alert_fatal) {
  ------------------
  |  Branch (2924:9): [True: 3.73k, False: 2.62k]
  ------------------
 2925|  3.73k|        if (ss->sec.ci.sid) {
  ------------------
  |  Branch (2925:13): [True: 2.50k, False: 1.22k]
  ------------------
 2926|  2.50k|            ssl_UncacheSessionID(ss);
 2927|  2.50k|        }
 2928|  3.73k|    }
 2929|       |
 2930|  6.35k|    rv = tls13_SetAlertCipherSpec(ss);
 2931|  6.35k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2931:9): [True: 0, False: 6.35k]
  ------------------
 2932|      0|        if (needHsLock) {
  ------------------
  |  Branch (2932:13): [True: 0, False: 0]
  ------------------
 2933|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
 2934|      0|        }
 2935|      0|        return rv;
 2936|      0|    }
 2937|       |
 2938|  6.35k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  6.35k|    {                                           \
  |  | 1467|  6.35k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 3.35k, False: 3.00k]
  |  |  ------------------
  |  | 1468|  6.35k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  3.35k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  6.35k|    }
  ------------------
 2939|  6.35k|    rv = ssl3_FlushHandshake(ss, ssl_SEND_FLAG_FORCE_INTO_BUFFER);
  ------------------
  |  |  223|  6.35k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
 2940|  6.35k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (2940:9): [True: 6.35k, False: 2]
  ------------------
 2941|  6.35k|        PRInt32 sent;
 2942|  6.35k|        sent = ssl3_SendRecord(ss, NULL, ssl_ct_alert, bytes, 2,
 2943|  6.35k|                               (desc == no_certificate) ? ssl_SEND_FLAG_FORCE_INTO_BUFFER : 0);
  ------------------
  |  |  223|      0|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
  |  Branch (2943:32): [True: 0, False: 6.35k]
  ------------------
 2944|  6.35k|        rv = (sent >= 0) ? SECSuccess : (SECStatus)sent;
  ------------------
  |  Branch (2944:14): [True: 5.17k, False: 1.18k]
  ------------------
 2945|  6.35k|    }
 2946|  6.35k|    if (level == alert_fatal) {
  ------------------
  |  Branch (2946:9): [True: 3.73k, False: 2.62k]
  ------------------
 2947|  3.73k|        ss->ssl3.fatalAlertSent = PR_TRUE;
  ------------------
  |  |  437|  3.73k|#define PR_TRUE 1
  ------------------
 2948|  3.73k|    }
 2949|  6.35k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  6.35k|    {                                          \
  |  | 1472|  6.35k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 3.35k, False: 3.00k]
  |  |  ------------------
  |  | 1473|  6.35k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  3.35k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  6.35k|    }
  ------------------
 2950|  6.35k|    if (needHsLock) {
  ------------------
  |  Branch (2950:9): [True: 4.50k, False: 1.85k]
  ------------------
 2951|  4.50k|        ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  4.50k|    {                                                \
  |  | 1415|  4.50k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 1.50k, False: 3.00k]
  |  |  ------------------
  |  | 1416|  4.50k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  1.50k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  4.50k|    }
  ------------------
 2952|  4.50k|    }
 2953|  6.35k|    if (rv == SECSuccess && ss->alertSentCallback) {
  ------------------
  |  Branch (2953:9): [True: 5.17k, False: 1.18k]
  |  Branch (2953:29): [True: 0, False: 5.17k]
  ------------------
 2954|      0|        SSLAlert alert = { level, desc };
 2955|      0|        ss->alertSentCallback(ss->fd, ss->alertSentCallbackArg, &alert);
 2956|      0|    }
 2957|  6.35k|    return rv; /* error set by ssl3_FlushHandshake or ssl3_SendRecord */
 2958|  6.35k|}
ssl3_SendAlertForCertError:
 2986|    530|{
 2987|    530|    SSL3AlertDescription desc = bad_certificate;
 2988|    530|    PRBool isTLS = ss->version >= SSL_LIBRARY_VERSION_3_1_TLS;
  ------------------
  |  |   29|    530|#define SSL_LIBRARY_VERSION_3_1_TLS SSL_LIBRARY_VERSION_TLS_1_0
  |  |  ------------------
  |  |  |  |   18|    530|#define SSL_LIBRARY_VERSION_TLS_1_0             0x0301
  |  |  ------------------
  ------------------
 2989|       |
 2990|    530|    switch (errCode) {
 2991|     60|        case SEC_ERROR_LIBRARY_FAILURE:
  ------------------
  |  Branch (2991:9): [True: 60, False: 470]
  ------------------
 2992|     60|            desc = unsupported_certificate;
 2993|     60|            break;
 2994|      0|        case SEC_ERROR_EXPIRED_CERTIFICATE:
  ------------------
  |  Branch (2994:9): [True: 0, False: 530]
  ------------------
 2995|      0|            desc = certificate_expired;
 2996|      0|            break;
 2997|      0|        case SEC_ERROR_REVOKED_CERTIFICATE:
  ------------------
  |  Branch (2997:9): [True: 0, False: 530]
  ------------------
 2998|      0|            desc = certificate_revoked;
 2999|      0|            break;
 3000|      0|        case SEC_ERROR_INADEQUATE_KEY_USAGE:
  ------------------
  |  Branch (3000:9): [True: 0, False: 530]
  ------------------
 3001|      0|        case SEC_ERROR_INADEQUATE_CERT_TYPE:
  ------------------
  |  Branch (3001:9): [True: 0, False: 530]
  ------------------
 3002|      0|            desc = certificate_unknown;
 3003|      0|            break;
 3004|      0|        case SEC_ERROR_UNTRUSTED_CERT:
  ------------------
  |  Branch (3004:9): [True: 0, False: 530]
  ------------------
 3005|      0|            desc = isTLS ? access_denied : certificate_unknown;
  ------------------
  |  Branch (3005:20): [True: 0, False: 0]
  ------------------
 3006|      0|            break;
 3007|      0|        case SEC_ERROR_UNKNOWN_ISSUER:
  ------------------
  |  Branch (3007:9): [True: 0, False: 530]
  ------------------
 3008|      0|        case SEC_ERROR_UNTRUSTED_ISSUER:
  ------------------
  |  Branch (3008:9): [True: 0, False: 530]
  ------------------
 3009|      0|            desc = isTLS ? unknown_ca : certificate_unknown;
  ------------------
  |  Branch (3009:20): [True: 0, False: 0]
  ------------------
 3010|      0|            break;
 3011|      0|        case SEC_ERROR_EXPIRED_ISSUER_CERTIFICATE:
  ------------------
  |  Branch (3011:9): [True: 0, False: 530]
  ------------------
 3012|      0|            desc = isTLS ? unknown_ca : certificate_expired;
  ------------------
  |  Branch (3012:20): [True: 0, False: 0]
  ------------------
 3013|      0|            break;
 3014|       |
 3015|      0|        case SEC_ERROR_CERT_NOT_IN_NAME_SPACE:
  ------------------
  |  Branch (3015:9): [True: 0, False: 530]
  ------------------
 3016|      0|        case SEC_ERROR_PATH_LEN_CONSTRAINT_INVALID:
  ------------------
  |  Branch (3016:9): [True: 0, False: 530]
  ------------------
 3017|      0|        case SEC_ERROR_CA_CERT_INVALID:
  ------------------
  |  Branch (3017:9): [True: 0, False: 530]
  ------------------
 3018|      0|        case SEC_ERROR_BAD_SIGNATURE:
  ------------------
  |  Branch (3018:9): [True: 0, False: 530]
  ------------------
 3019|    470|        default:
  ------------------
  |  Branch (3019:9): [True: 470, False: 60]
  ------------------
 3020|    470|            desc = bad_certificate;
 3021|    470|            break;
 3022|    530|    }
 3023|    530|    SSL_DBG(("%d: SSL3[%d]: peer certificate is no good: error=%d",
  ------------------
  |  |   87|    530|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 530]
  |  |  ------------------
  |  |   88|    530|    ssl_Trace b
  ------------------
 3024|    530|             SSL_GETPID(), ss->fd, errCode));
 3025|       |
 3026|    530|    (void)SSL3_SendAlert(ss, alert_fatal, desc);
 3027|    530|}
ssl3_DecodeError:
 3034|    821|{
 3035|    821|    (void)SSL3_SendAlert(ss, alert_fatal,
 3036|    821|                         ss->version > SSL_LIBRARY_VERSION_3_0 ? decode_error
  ------------------
  |  |   17|    821|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (3036:26): [True: 669, False: 152]
  ------------------
 3037|    821|                                                               : illegal_parameter);
 3038|    821|    PORT_SetError(ss->sec.isServer ? SSL_ERROR_BAD_CLIENT
  ------------------
  |  |   65|    821|#define PORT_SetError PORT_SetError_Util
  ------------------
  |  Branch (3038:19): [True: 821, False: 0]
  ------------------
 3039|    821|                                   : SSL_ERROR_BAD_SERVER);
 3040|    821|    return SECFailure;
 3041|    821|}
ssl3_SendChangeCipherSpecsInt:
 3234|  52.9k|{
 3235|  52.9k|    PRUint8 change = change_cipher_spec_choice;
 3236|  52.9k|    SECStatus rv;
 3237|       |
 3238|  52.9k|    SSL_TRC(3, ("%d: SSL3[%d]: send change_cipher_spec record",
  ------------------
  |  |   71|  52.9k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 52.9k]
  |  |  ------------------
  |  |   72|  52.9k|    ssl_Trace b
  ------------------
 3239|  52.9k|                SSL_GETPID(), ss->fd));
 3240|       |
 3241|  52.9k|    rv = ssl3_FlushHandshake(ss, ssl_SEND_FLAG_FORCE_INTO_BUFFER);
  ------------------
  |  |  223|  52.9k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
 3242|  52.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3242:9): [True: 0, False: 52.9k]
  ------------------
 3243|      0|        return SECFailure; /* error code set by ssl3_FlushHandshake */
 3244|      0|    }
 3245|       |
 3246|  52.9k|    if (!IS_DTLS(ss)) {
  ------------------
  |  |  892|  52.9k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (3246:9): [True: 52.9k, False: 0]
  ------------------
 3247|  52.9k|        PRInt32 sent;
 3248|  52.9k|        sent = ssl3_SendRecord(ss, NULL, ssl_ct_change_cipher_spec,
 3249|  52.9k|                               &change, 1, ssl_SEND_FLAG_FORCE_INTO_BUFFER);
  ------------------
  |  |  223|  52.9k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
 3250|  52.9k|        if (sent < 0) {
  ------------------
  |  Branch (3250:13): [True: 0, False: 52.9k]
  ------------------
 3251|      0|            return SECFailure; /* error code set by ssl3_SendRecord */
 3252|      0|        }
 3253|  52.9k|    } else {
 3254|      0|        rv = dtls_QueueMessage(ss, ssl_ct_change_cipher_spec, &change, 1);
 3255|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3255:13): [True: 0, False: 0]
  ------------------
 3256|      0|            return SECFailure;
 3257|      0|        }
 3258|      0|    }
 3259|  52.9k|    return SECSuccess;
 3260|  52.9k|}
ssl3_InitHandshakeHashes:
 3861|  60.0k|{
 3862|  60.0k|    SSL_TRC(30, ("%d: SSL3[%d]: start handshake hashes", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|  60.0k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 60.0k]
  |  |  ------------------
  |  |   72|  60.0k|    ssl_Trace b
  ------------------
 3863|       |
 3864|  60.0k|    PORT_Assert(ss->ssl3.hs.hashType == handshake_hash_unknown);
  ------------------
  |  |  120|  60.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  60.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 60.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3865|  60.0k|    if (ss->version == SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  60.0k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (3865:9): [True: 52.1k, False: 7.87k]
  ------------------
 3866|  52.1k|        ss->ssl3.hs.hashType = handshake_hash_record;
 3867|  52.1k|    } else {
 3868|  7.87k|        PORT_Assert(!ss->ssl3.hs.md5 && !ss->ssl3.hs.sha);
  ------------------
  |  |  120|  7.87k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  15.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 7.87k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 7.87k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3869|       |        /*
 3870|       |         * note: We should probably lookup an SSL3 slot for these
 3871|       |         * handshake hashes in hopes that we wind up with the same slots
 3872|       |         * that the master secret will wind up in ...
 3873|       |         */
 3874|  7.87k|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  7.87k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (3874:13): [True: 1.24k, False: 6.63k]
  ------------------
 3875|       |            /* determine the hash from the prf */
 3876|  1.24k|            const SECOidData *hash_oid =
 3877|  1.24k|                SECOID_FindOIDByMechanism(ssl3_GetPrfHashMechanism(ss));
 3878|       |
 3879|       |            /* Get the PKCS #11 mechanism for the Hash from the cipher suite (prf_hash)
 3880|       |             * Convert that to the OidTag. We can then use that OidTag to create our
 3881|       |             * PK11Context */
 3882|  1.24k|            PORT_Assert(hash_oid != NULL);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3883|  1.24k|            if (hash_oid == NULL) {
  ------------------
  |  Branch (3883:17): [True: 0, False: 1.24k]
  ------------------
 3884|      0|                ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 3885|      0|                return SECFailure;
 3886|      0|            }
 3887|       |
 3888|  1.24k|            ss->ssl3.hs.sha = PK11_CreateDigestContext(hash_oid->offset);
 3889|  1.24k|            if (ss->ssl3.hs.sha == NULL) {
  ------------------
  |  Branch (3889:17): [True: 0, False: 1.24k]
  ------------------
 3890|      0|                ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 3891|      0|                return SECFailure;
 3892|      0|            }
 3893|  1.24k|            ss->ssl3.hs.hashType = handshake_hash_single;
 3894|  1.24k|            if (PK11_DigestBegin(ss->ssl3.hs.sha) != SECSuccess) {
  ------------------
  |  Branch (3894:17): [True: 0, False: 1.24k]
  ------------------
 3895|      0|                ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 3896|      0|                return SECFailure;
 3897|      0|            }
 3898|       |
 3899|       |            /* Transcript hash used on ECH client. */
 3900|  1.24k|            if (!ss->sec.isServer && ss->ssl3.hs.echHpkeCtx) {
  ------------------
  |  Branch (3900:17): [True: 0, False: 1.24k]
  |  Branch (3900:38): [True: 0, False: 0]
  ------------------
 3901|      0|                ss->ssl3.hs.shaEchInner = PK11_CreateDigestContext(hash_oid->offset);
 3902|      0|                if (ss->ssl3.hs.shaEchInner == NULL) {
  ------------------
  |  Branch (3902:21): [True: 0, False: 0]
  ------------------
 3903|      0|                    ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 3904|      0|                    return SECFailure;
 3905|      0|                }
 3906|      0|                if (PK11_DigestBegin(ss->ssl3.hs.shaEchInner) != SECSuccess) {
  ------------------
  |  Branch (3906:21): [True: 0, False: 0]
  ------------------
 3907|      0|                    ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 3908|      0|                    return SECFailure;
 3909|      0|                }
 3910|      0|            }
 3911|  6.63k|        } else {
 3912|       |            /* Both ss->ssl3.hs.md5 and ss->ssl3.hs.sha should be NULL or
 3913|       |             * created successfully. */
 3914|  6.63k|            ss->ssl3.hs.md5 = PK11_CreateDigestContext(SEC_OID_MD5);
 3915|  6.63k|            if (ss->ssl3.hs.md5 == NULL) {
  ------------------
  |  Branch (3915:17): [True: 0, False: 6.63k]
  ------------------
 3916|      0|                ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 3917|      0|                return SECFailure;
 3918|      0|            }
 3919|  6.63k|            ss->ssl3.hs.sha = PK11_CreateDigestContext(SEC_OID_SHA1);
 3920|  6.63k|            if (ss->ssl3.hs.sha == NULL) {
  ------------------
  |  Branch (3920:17): [True: 0, False: 6.63k]
  ------------------
 3921|      0|                PK11_DestroyContext(ss->ssl3.hs.md5, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3922|      0|                ss->ssl3.hs.md5 = NULL;
 3923|      0|                ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 3924|      0|                return SECFailure;
 3925|      0|            }
 3926|  6.63k|            ss->ssl3.hs.hashType = handshake_hash_combo;
 3927|       |
 3928|  6.63k|            if (PK11_DigestBegin(ss->ssl3.hs.md5) != SECSuccess) {
  ------------------
  |  Branch (3928:17): [True: 0, False: 6.63k]
  ------------------
 3929|      0|                ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 3930|      0|                return SECFailure;
 3931|      0|            }
 3932|  6.63k|            if (PK11_DigestBegin(ss->ssl3.hs.sha) != SECSuccess) {
  ------------------
  |  Branch (3932:17): [True: 0, False: 6.63k]
  ------------------
 3933|      0|                ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 3934|      0|                return SECFailure;
 3935|      0|            }
 3936|  6.63k|        }
 3937|  7.87k|    }
 3938|       |
 3939|  60.0k|    if (ss->ssl3.hs.hashType != handshake_hash_record &&
  ------------------
  |  Branch (3939:9): [True: 7.87k, False: 52.1k]
  ------------------
 3940|  60.0k|        ss->ssl3.hs.messages.len > 0) {
  ------------------
  |  Branch (3940:9): [True: 7.87k, False: 0]
  ------------------
 3941|       |        /* When doing ECH, ssl3_UpdateHandshakeHashes will store outer messages
 3942|       |         * into the both the outer and inner transcripts.
 3943|       |         * ssl3_UpdateDefaultHandshakeHashes uses the default context which is
 3944|       |         * the outer when doing client ECH. For ECH shared-mode or backend
 3945|       |         * servers only the hs.messages buffer is used. */
 3946|  7.87k|        if (ssl3_UpdateDefaultHandshakeHashes(ss, ss->ssl3.hs.messages.buf,
  ------------------
  |  Branch (3946:13): [True: 0, False: 7.87k]
  ------------------
 3947|  7.87k|                                              ss->ssl3.hs.messages.len) != SECSuccess) {
 3948|      0|            return SECFailure;
 3949|      0|        }
 3950|       |        /* When doing ECH, deriving the accept_confirmation value requires all
 3951|       |         * messages up to and including the ServerHello
 3952|       |         * (see draft-ietf-tls-esni-14, Section 7.2).
 3953|       |         *
 3954|       |         * Don't free the transcript buffer until confirmation calculation. */
 3955|  7.87k|        if (!ss->ssl3.hs.echHpkeCtx && !ss->opt.enableTls13BackendEch) {
  ------------------
  |  Branch (3955:13): [True: 7.87k, False: 0]
  |  Branch (3955:40): [True: 3.38k, False: 4.48k]
  ------------------
 3956|  3.38k|            sslBuffer_Clear(&ss->ssl3.hs.messages);
 3957|  3.38k|        }
 3958|  7.87k|    }
 3959|  60.0k|    if (ss->ssl3.hs.shaEchInner &&
  ------------------
  |  Branch (3959:9): [True: 0, False: 60.0k]
  ------------------
 3960|  60.0k|        ss->ssl3.hs.echInnerMessages.len > 0) {
  ------------------
  |  Branch (3960:9): [True: 0, False: 0]
  ------------------
 3961|      0|        if (PK11_DigestOp(ss->ssl3.hs.shaEchInner, ss->ssl3.hs.echInnerMessages.buf,
  ------------------
  |  Branch (3961:13): [True: 0, False: 0]
  ------------------
 3962|      0|                          ss->ssl3.hs.echInnerMessages.len) != SECSuccess) {
 3963|      0|            ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 3964|      0|            return SECFailure;
 3965|      0|        }
 3966|      0|        if (!ss->ssl3.hs.echHpkeCtx) {
  ------------------
  |  Branch (3966:13): [True: 0, False: 0]
  ------------------
 3967|      0|            sslBuffer_Clear(&ss->ssl3.hs.echInnerMessages);
 3968|      0|        }
 3969|      0|    }
 3970|       |
 3971|  60.0k|    return SECSuccess;
 3972|  60.0k|}
ssl3_RestartHandshakeHashes:
 3976|  61.2k|{
 3977|  61.2k|    SSL_TRC(30, ("%d: SSL3[%d]: reset handshake hashes",
  ------------------
  |  |   71|  61.2k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 61.2k]
  |  |  ------------------
  |  |   72|  61.2k|    ssl_Trace b
  ------------------
 3978|  61.2k|                 SSL_GETPID(), ss->fd));
 3979|  61.2k|    ss->ssl3.hs.hashType = handshake_hash_unknown;
 3980|  61.2k|    ss->ssl3.hs.messages.len = 0;
 3981|  61.2k|    ss->ssl3.hs.echInnerMessages.len = 0;
 3982|  61.2k|    if (ss->ssl3.hs.md5) {
  ------------------
  |  Branch (3982:9): [True: 5.90k, False: 55.3k]
  ------------------
 3983|  5.90k|        PK11_DestroyContext(ss->ssl3.hs.md5, PR_TRUE);
  ------------------
  |  |  437|  5.90k|#define PR_TRUE 1
  ------------------
 3984|  5.90k|        ss->ssl3.hs.md5 = NULL;
 3985|  5.90k|    }
 3986|  61.2k|    if (ss->ssl3.hs.sha) {
  ------------------
  |  Branch (3986:9): [True: 5.90k, False: 55.3k]
  ------------------
 3987|  5.90k|        PK11_DestroyContext(ss->ssl3.hs.sha, PR_TRUE);
  ------------------
  |  |  437|  5.90k|#define PR_TRUE 1
  ------------------
 3988|  5.90k|        ss->ssl3.hs.sha = NULL;
 3989|  5.90k|    }
 3990|  61.2k|    if (ss->ssl3.hs.shaEchInner) {
  ------------------
  |  Branch (3990:9): [True: 0, False: 61.2k]
  ------------------
 3991|      0|        PK11_DestroyContext(ss->ssl3.hs.shaEchInner, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3992|      0|        ss->ssl3.hs.shaEchInner = NULL;
 3993|      0|    }
 3994|  61.2k|    if (ss->ssl3.hs.shaPostHandshake) {
  ------------------
  |  Branch (3994:9): [True: 0, False: 61.2k]
  ------------------
 3995|      0|        PK11_DestroyContext(ss->ssl3.hs.shaPostHandshake, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3996|      0|        ss->ssl3.hs.shaPostHandshake = NULL;
 3997|      0|    }
 3998|  61.2k|}
ssl3_UpdateHandshakeHashesInt:
 4007|  1.60M|{
 4008|       |
 4009|  1.60M|    SECStatus rv = SECSuccess;
 4010|  1.60M|    PRBool explicit = (target != NULL);
 4011|  1.60M|    PRBool appendToEchInner = !ss->sec.isServer &&
  ------------------
  |  Branch (4011:31): [True: 0, False: 1.60M]
  ------------------
 4012|  1.60M|                              ss->ssl3.hs.echHpkeCtx &&
  ------------------
  |  Branch (4012:31): [True: 0, False: 0]
  ------------------
 4013|  1.60M|                              !explicit;
  ------------------
  |  Branch (4013:31): [True: 0, False: 0]
  ------------------
 4014|  1.60M|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.60M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.41M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 785k, False: 814k]
  |  |  |  |  |  Branch (208:7): [True: 814k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4015|  1.60M|    PORT_Assert(target != &ss->ssl3.hs.echInnerMessages ||
  ------------------
  |  |  120|  1.60M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.60M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.60M, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4016|  1.60M|                !ss->sec.isServer);
 4017|       |
 4018|  1.60M|    if (target == NULL) {
  ------------------
  |  Branch (4018:9): [True: 1.59M, False: 7.87k]
  ------------------
 4019|       |        /* Default context. */
 4020|  1.59M|        target = &ss->ssl3.hs.messages;
 4021|  1.59M|    }
 4022|       |    /* With TLS 1.3, and versions TLS.1.1 and older, we keep the hash(es)
 4023|       |     * always up to date. However, we must initially buffer the handshake
 4024|       |     * messages, until we know what to do.
 4025|       |     * If ss->ssl3.hs.hashType != handshake_hash_unknown,
 4026|       |     * it means we know what to do. We calculate (hash our input),
 4027|       |     * and we stop appending to the buffer.
 4028|       |     *
 4029|       |     * With TLS 1.2, we always append all handshake messages,
 4030|       |     * and never update the hash, because the hash function we must use for
 4031|       |     * certificate_verify might be different from the hash function we use
 4032|       |     * when signing other handshake hashes. */
 4033|  1.60M|    if (ss->ssl3.hs.hashType == handshake_hash_unknown ||
  ------------------
  |  Branch (4033:9): [True: 121k, False: 1.47M]
  ------------------
 4034|  1.60M|        ss->ssl3.hs.hashType == handshake_hash_record) {
  ------------------
  |  Branch (4034:9): [True: 1.30M, False: 179k]
  ------------------
 4035|  1.42M|        rv = sslBuffer_Append(target, b, l);
 4036|  1.42M|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4036:13): [True: 0, False: 1.42M]
  ------------------
 4037|      0|            return SECFailure;
 4038|      0|        }
 4039|  1.42M|        if (appendToEchInner) {
  ------------------
  |  Branch (4039:13): [True: 0, False: 1.42M]
  ------------------
 4040|      0|            return sslBuffer_Append(&ss->ssl3.hs.echInnerMessages, b, l);
 4041|      0|        }
 4042|  1.42M|        return SECSuccess;
 4043|  1.42M|    }
 4044|       |
 4045|   179k|    PRINT_BUF(90, (ss, "handshake hash input:", b, l));
  ------------------
  |  |   74|   179k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 179k]
  |  |  ------------------
  |  |   75|   179k|    ssl_PrintBuf b
  ------------------
 4046|       |
 4047|   179k|    if (ss->ssl3.hs.hashType == handshake_hash_single) {
  ------------------
  |  Branch (4047:9): [True: 26.3k, False: 152k]
  ------------------
 4048|  26.3k|        PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  26.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  26.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 26.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4049|  26.3k|        if (target == &ss->ssl3.hs.messages) {
  ------------------
  |  Branch (4049:13): [True: 26.3k, False: 0]
  ------------------
 4050|  26.3k|            rv = PK11_DigestOp(ss->ssl3.hs.sha, b, l);
 4051|  26.3k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (4051:17): [True: 0, False: 26.3k]
  ------------------
 4052|      0|                ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 4053|      0|                return rv;
 4054|      0|            }
 4055|  26.3k|        }
 4056|  26.3k|        if (ss->ssl3.hs.shaEchInner &&
  ------------------
  |  Branch (4056:13): [True: 0, False: 26.3k]
  ------------------
 4057|  26.3k|            (target == &ss->ssl3.hs.echInnerMessages || !explicit)) {
  ------------------
  |  Branch (4057:14): [True: 0, False: 0]
  |  Branch (4057:57): [True: 0, False: 0]
  ------------------
 4058|      0|            rv = PK11_DigestOp(ss->ssl3.hs.shaEchInner, b, l);
 4059|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (4059:17): [True: 0, False: 0]
  ------------------
 4060|      0|                ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 4061|      0|                return rv;
 4062|      0|            }
 4063|      0|        }
 4064|   152k|    } else if (ss->ssl3.hs.hashType == handshake_hash_combo) {
  ------------------
  |  Branch (4064:16): [True: 152k, False: 0]
  ------------------
 4065|   152k|        rv = PK11_DigestOp(ss->ssl3.hs.md5, b, l);
 4066|   152k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4066:13): [True: 0, False: 152k]
  ------------------
 4067|      0|            ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 4068|      0|            return rv;
 4069|      0|        }
 4070|   152k|        rv = PK11_DigestOp(ss->ssl3.hs.sha, b, l);
 4071|   152k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4071:13): [True: 0, False: 152k]
  ------------------
 4072|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4073|      0|            return rv;
 4074|      0|        }
 4075|   152k|    }
 4076|   179k|    return rv;
 4077|   179k|}
ssl3_UpdateHandshakeHashes:
 4106|  1.59M|{
 4107|  1.59M|    return ssl3_UpdateHandshakeHashesInt(ss, b, l, NULL);
 4108|  1.59M|}
ssl3_AppendHandshakeHeaderAndStashSeqNum:
 4135|   422k|{
 4136|   422k|    PORT_Assert(t != ssl_hs_client_hello);
  ------------------
  |  |  120|   422k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   422k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 422k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4137|   422k|    SECStatus rv;
 4138|       |
 4139|       |    /* If we already have a message in place, we need to enqueue it.
 4140|       |     * This empties the buffer. This is a convenient place to call
 4141|       |     * dtls_StageHandshakeMessage to mark the message boundary.
 4142|       |     */
 4143|   422k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   422k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 422k]
  |  |  ------------------
  ------------------
 4144|      0|        rv = dtls_StageHandshakeMessage(ss);
 4145|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4145:13): [True: 0, False: 0]
  ------------------
 4146|      0|            return rv;
 4147|      0|        }
 4148|      0|    }
 4149|       |
 4150|   422k|    SSL_TRC(30, ("%d: SSL3[%d]: append handshake header: type %s",
  ------------------
  |  |   71|   422k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 422k]
  |  |  ------------------
  |  |   72|   422k|    ssl_Trace b
  ------------------
 4151|   422k|                 SSL_GETPID(), ss->fd, ssl3_DecodeHandshakeType(t)));
 4152|       |
 4153|   422k|    rv = ssl3_AppendHandshakeNumber(ss, t, 1);
 4154|   422k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4154:9): [True: 0, False: 422k]
  ------------------
 4155|      0|        return rv; /* error code set by AppendHandshake, if applicable. */
 4156|      0|    }
 4157|   422k|    rv = ssl3_AppendHandshakeNumber(ss, length, 3);
 4158|   422k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4158:9): [True: 0, False: 422k]
  ------------------
 4159|      0|        return rv; /* error code set by AppendHandshake, if applicable. */
 4160|      0|    }
 4161|       |
 4162|   422k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   422k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 422k]
  |  |  ------------------
  ------------------
 4163|       |        /* RFC 9147. 5.2.  DTLS Handshake Message Format.
 4164|       |         * In DTLS 1.3, the message transcript is computed over the original TLS
 4165|       |         * 1.3-style Handshake messages without the message_seq,
 4166|       |         * fragment_offset, and fragment_length values.  Note that this is a
 4167|       |         * change from DTLS 1.2 where those values were included in the transcript. */
 4168|      0|        PRBool suppressHash = ss->version == SSL_LIBRARY_VERSION_TLS_1_3 ? PR_TRUE : PR_FALSE;
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
                      PRBool suppressHash = ss->version == SSL_LIBRARY_VERSION_TLS_1_3 ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                      PRBool suppressHash = ss->version == SSL_LIBRARY_VERSION_TLS_1_3 ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (4168:31): [True: 0, False: 0]
  ------------------
 4169|       |
 4170|       |        /* Note that we make an unfragmented message here. We fragment in the
 4171|       |         * transmission code, if necessary */
 4172|      0|        rv = ssl3_AppendHandshakeNumberSuppressHash(ss, ss->ssl3.hs.sendMessageSeq, 2, suppressHash);
 4173|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4173:13): [True: 0, False: 0]
  ------------------
 4174|      0|            return rv; /* error code set by AppendHandshake, if applicable. */
 4175|      0|        }
 4176|       |        /* In case if we provide a buffer for the sequence message,
 4177|       |        we write down sendMessageSeq to the buffer. */
 4178|      0|        if (sendMessageSeqOut != NULL) {
  ------------------
  |  Branch (4178:13): [True: 0, False: 0]
  ------------------
 4179|      0|            *sendMessageSeqOut = ss->ssl3.hs.sendMessageSeq;
 4180|      0|        }
 4181|      0|        ss->ssl3.hs.sendMessageSeq++;
 4182|       |
 4183|       |        /* 0 is the fragment offset, because it's not fragmented yet */
 4184|      0|        rv = ssl3_AppendHandshakeNumberSuppressHash(ss, 0, 3, suppressHash);
 4185|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4185:13): [True: 0, False: 0]
  ------------------
 4186|      0|            return rv; /* error code set by AppendHandshake, if applicable. */
 4187|      0|        }
 4188|       |
 4189|       |        /* Fragment length -- set to the packet length because not fragmented */
 4190|      0|        rv = ssl3_AppendHandshakeNumberSuppressHash(ss, length, 3, suppressHash);
 4191|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4191:13): [True: 0, False: 0]
  ------------------
 4192|      0|            return rv; /* error code set by AppendHandshake, if applicable. */
 4193|      0|        }
 4194|      0|    }
 4195|       |
 4196|   422k|    return rv; /* error code set by AppendHandshake, if applicable. */
 4197|   422k|}
ssl3_AppendHandshakeHeader:
 4204|   422k|{
 4205|   422k|    return ssl3_AppendHandshakeHeaderAndStashSeqNum(ss, t, length, NULL);
 4206|   422k|}
ssl3_ConsumeHandshake:
 4226|  61.4k|{
 4227|  61.4k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  61.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  92.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 29.8k, False: 31.5k]
  |  |  |  |  |  Branch (208:7): [True: 31.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4228|  61.4k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  61.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  92.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 29.8k, False: 31.5k]
  |  |  |  |  |  Branch (208:7): [True: 31.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4229|       |
 4230|  61.4k|    if ((PRUint32)bytes > *length) {
  ------------------
  |  Branch (4230:9): [True: 23, False: 61.3k]
  ------------------
 4231|     23|        return ssl3_DecodeError(ss);
 4232|     23|    }
 4233|  61.3k|    PORT_Memcpy(v, *b, bytes);
  ------------------
  |  |  180|  61.3k|#define PORT_Memcpy memcpy
  ------------------
 4234|  61.3k|    PRINT_BUF(60, (ss, "consume bytes:", *b, bytes));
  ------------------
  |  |   74|  61.3k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 61.3k]
  |  |  ------------------
  |  |   75|  61.3k|    ssl_PrintBuf b
  ------------------
 4235|  61.3k|    *b += bytes;
 4236|  61.3k|    *length -= bytes;
 4237|  61.3k|    return SECSuccess;
 4238|  61.4k|}
ssl3_ConsumeHandshakeNumber64:
 4250|   881k|{
 4251|   881k|    PRUint8 *buf = *b;
 4252|   881k|    PRUint32 i;
 4253|       |
 4254|   881k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   881k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.32M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 436k, False: 444k]
  |  |  |  |  |  Branch (208:7): [True: 444k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4255|   881k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   881k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.32M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 436k, False: 444k]
  |  |  |  |  |  Branch (208:7): [True: 444k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4256|       |
 4257|   881k|    *num = 0;
 4258|   881k|    if (bytes > sizeof(*num)) {
  ------------------
  |  Branch (4258:9): [True: 0, False: 881k]
  ------------------
 4259|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4260|      0|        return SECFailure;
 4261|      0|    }
 4262|       |
 4263|   881k|    if (bytes > *length) {
  ------------------
  |  Branch (4263:9): [True: 95, False: 881k]
  ------------------
 4264|     95|        return ssl3_DecodeError(ss);
 4265|     95|    }
 4266|   881k|    PRINT_BUF(60, (ss, "consume bytes:", *b, bytes));
  ------------------
  |  |   74|   881k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 881k]
  |  |  ------------------
  |  |   75|   881k|    ssl_PrintBuf b
  ------------------
 4267|       |
 4268|  2.37M|    for (i = 0; i < bytes; i++) {
  ------------------
  |  Branch (4268:17): [True: 1.48M, False: 881k]
  ------------------
 4269|  1.48M|        *num = (*num << 8) + buf[i];
 4270|  1.48M|    }
 4271|   881k|    *b += bytes;
 4272|   881k|    *length -= bytes;
 4273|   881k|    return SECSuccess;
 4274|   881k|}
ssl3_ConsumeHandshakeNumber:
 4279|   881k|{
 4280|   881k|    PRUint64 num64;
 4281|   881k|    SECStatus rv;
 4282|       |
 4283|   881k|    PORT_Assert(bytes <= sizeof(*num));
  ------------------
  |  |  120|   881k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   881k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 881k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4284|   881k|    if (bytes > sizeof(*num)) {
  ------------------
  |  Branch (4284:9): [True: 0, False: 881k]
  ------------------
 4285|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4286|      0|        return SECFailure;
 4287|      0|    }
 4288|   881k|    rv = ssl3_ConsumeHandshakeNumber64(ss, &num64, bytes, b, length);
 4289|   881k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4289:9): [True: 95, False: 881k]
  ------------------
 4290|     95|        return SECFailure;
 4291|     95|    }
 4292|   881k|    *num = num64 & 0xffffffff;
 4293|   881k|    return SECSuccess;
 4294|   881k|}
ssl3_ConsumeHandshakeVariable:
 4313|   382k|{
 4314|   382k|    PRUint32 count;
 4315|   382k|    SECStatus rv;
 4316|       |
 4317|   382k|    PORT_Assert(bytes <= 3);
  ------------------
  |  |  120|   382k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   382k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 382k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4318|   382k|    i->len = 0;
 4319|   382k|    i->data = NULL;
 4320|   382k|    i->type = siBuffer;
 4321|   382k|    rv = ssl3_ConsumeHandshakeNumber(ss, &count, bytes, b, length);
 4322|   382k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4322:9): [True: 31, False: 382k]
  ------------------
 4323|     31|        return SECFailure;
 4324|     31|    }
 4325|   382k|    if (count > 0) {
  ------------------
  |  Branch (4325:9): [True: 280k, False: 102k]
  ------------------
 4326|   280k|        if (count > *length) {
  ------------------
  |  Branch (4326:13): [True: 239, False: 279k]
  ------------------
 4327|    239|            return ssl3_DecodeError(ss);
 4328|    239|        }
 4329|   279k|        i->data = *b;
 4330|   279k|        i->len = count;
 4331|   279k|        *b += count;
 4332|   279k|        *length -= count;
 4333|   279k|    }
 4334|   382k|    return SECSuccess;
 4335|   382k|}
ssl3_HashTypeToOID:
 4343|  2.07M|{
 4344|  2.07M|    switch (hashType) {
 4345|   108k|        case ssl_hash_sha1:
  ------------------
  |  Branch (4345:9): [True: 108k, False: 1.96M]
  ------------------
 4346|   108k|            return SEC_OID_SHA1;
 4347|  1.81M|        case ssl_hash_sha256:
  ------------------
  |  Branch (4347:9): [True: 1.81M, False: 255k]
  ------------------
 4348|  1.81M|            return SEC_OID_SHA256;
 4349|  90.8k|        case ssl_hash_sha384:
  ------------------
  |  Branch (4349:9): [True: 90.8k, False: 1.97M]
  ------------------
 4350|  90.8k|            return SEC_OID_SHA384;
 4351|  56.7k|        case ssl_hash_sha512:
  ------------------
  |  Branch (4351:9): [True: 56.7k, False: 2.01M]
  ------------------
 4352|  56.7k|            return SEC_OID_SHA512;
 4353|     22|        default:
  ------------------
  |  Branch (4353:9): [True: 22, False: 2.07M]
  ------------------
 4354|     22|            break;
 4355|  2.07M|    }
 4356|     22|    return SEC_OID_UNKNOWN;
 4357|  2.07M|}
ssl3_AuthTypeToOID:
 4361|   751k|{
 4362|   751k|    switch (authType) {
 4363|  63.0k|        case ssl_auth_rsa_sign:
  ------------------
  |  Branch (4363:9): [True: 63.0k, False: 688k]
  ------------------
 4364|  63.0k|            return SEC_OID_PKCS1_RSA_ENCRYPTION;
 4365|      3|        case ssl_auth_rsa_pss:
  ------------------
  |  Branch (4365:9): [True: 3, False: 751k]
  ------------------
 4366|      3|            return SEC_OID_PKCS1_RSA_PSS_SIGNATURE;
 4367|   668k|        case ssl_auth_ecdsa:
  ------------------
  |  Branch (4367:9): [True: 668k, False: 83.3k]
  ------------------
 4368|   668k|            return SEC_OID_ANSIX962_EC_PUBLIC_KEY;
 4369|  20.2k|        case ssl_auth_dsa:
  ------------------
  |  Branch (4369:9): [True: 20.2k, False: 731k]
  ------------------
 4370|  20.2k|            return SEC_OID_ANSIX9_DSA_SIGNATURE;
 4371|      0|        default:
  ------------------
  |  Branch (4371:9): [True: 0, False: 751k]
  ------------------
 4372|      0|            break;
 4373|   751k|    }
 4374|       |    /* shouldn't ever get there */
 4375|      0|    PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4376|      0|    return SEC_OID_UNKNOWN;
 4377|   751k|}
ssl_SignatureSchemeToHashType:
 4381|  1.95M|{
 4382|  1.95M|    switch (scheme) {
  ------------------
  |  Branch (4382:13): [True: 0, False: 1.95M]
  ------------------
 4383|  41.8k|        case ssl_sig_rsa_pkcs1_sha1:
  ------------------
  |  Branch (4383:9): [True: 41.8k, False: 1.91M]
  ------------------
 4384|  47.0k|        case ssl_sig_dsa_sha1:
  ------------------
  |  Branch (4384:9): [True: 5.11k, False: 1.95M]
  ------------------
 4385|  72.0k|        case ssl_sig_ecdsa_sha1:
  ------------------
  |  Branch (4385:9): [True: 24.9k, False: 1.93M]
  ------------------
 4386|  72.0k|            return ssl_hash_sha1;
 4387|  17.8k|        case ssl_sig_rsa_pkcs1_sha256:
  ------------------
  |  Branch (4387:9): [True: 17.8k, False: 1.94M]
  ------------------
 4388|   608k|        case ssl_sig_ecdsa_secp256r1_sha256:
  ------------------
  |  Branch (4388:9): [True: 590k, False: 1.36M]
  ------------------
 4389|  1.76M|        case ssl_sig_rsa_pss_rsae_sha256:
  ------------------
  |  Branch (4389:9): [True: 1.15M, False: 803k]
  ------------------
 4390|  1.76M|        case ssl_sig_rsa_pss_pss_sha256:
  ------------------
  |  Branch (4390:9): [True: 117, False: 1.95M]
  ------------------
 4391|  1.76M|        case ssl_sig_dsa_sha256:
  ------------------
  |  Branch (4391:9): [True: 4.98k, False: 1.95M]
  ------------------
 4392|  1.76M|            return ssl_hash_sha256;
 4393|  8.06k|        case ssl_sig_rsa_pkcs1_sha384:
  ------------------
  |  Branch (4393:9): [True: 8.06k, False: 1.95M]
  ------------------
 4394|  26.9k|        case ssl_sig_ecdsa_secp384r1_sha384:
  ------------------
  |  Branch (4394:9): [True: 18.8k, False: 1.94M]
  ------------------
 4395|  49.1k|        case ssl_sig_rsa_pss_rsae_sha384:
  ------------------
  |  Branch (4395:9): [True: 22.1k, False: 1.93M]
  ------------------
 4396|  49.2k|        case ssl_sig_rsa_pss_pss_sha384:
  ------------------
  |  Branch (4396:9): [True: 183, False: 1.95M]
  ------------------
 4397|  54.9k|        case ssl_sig_dsa_sha384:
  ------------------
  |  Branch (4397:9): [True: 5.65k, False: 1.95M]
  ------------------
 4398|  54.9k|            return ssl_hash_sha384;
 4399|  7.69k|        case ssl_sig_rsa_pkcs1_sha512:
  ------------------
  |  Branch (4399:9): [True: 7.69k, False: 1.95M]
  ------------------
 4400|  29.7k|        case ssl_sig_ecdsa_secp521r1_sha512:
  ------------------
  |  Branch (4400:9): [True: 22.0k, False: 1.93M]
  ------------------
 4401|  58.0k|        case ssl_sig_rsa_pss_rsae_sha512:
  ------------------
  |  Branch (4401:9): [True: 28.3k, False: 1.93M]
  ------------------
 4402|  58.0k|        case ssl_sig_rsa_pss_pss_sha512:
  ------------------
  |  Branch (4402:9): [True: 26, False: 1.95M]
  ------------------
 4403|  63.0k|        case ssl_sig_dsa_sha512:
  ------------------
  |  Branch (4403:9): [True: 4.95k, False: 1.95M]
  ------------------
 4404|  63.0k|            return ssl_hash_sha512;
 4405|      0|        case ssl_sig_rsa_pkcs1_sha1md5:
  ------------------
  |  Branch (4405:9): [True: 0, False: 1.95M]
  ------------------
 4406|      0|            return ssl_hash_none; /* Special for TLS 1.0/1.1. */
 4407|      0|        case ssl_sig_none:
  ------------------
  |  Branch (4407:9): [True: 0, False: 1.95M]
  ------------------
 4408|      0|        case ssl_sig_ed25519:
  ------------------
  |  Branch (4408:9): [True: 0, False: 1.95M]
  ------------------
 4409|      0|        case ssl_sig_ed448:
  ------------------
  |  Branch (4409:9): [True: 0, False: 1.95M]
  ------------------
 4410|      0|            break;
 4411|  1.95M|    }
 4412|      0|    PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4413|      0|    return ssl_hash_none;
 4414|  1.95M|}
ssl_SignatureSchemeValid:
 4435|   100k|{
 4436|   100k|    if (!ssl_IsSupportedSignatureScheme(scheme)) {
  ------------------
  |  Branch (4436:9): [True: 21.9k, False: 78.9k]
  ------------------
 4437|  21.9k|        return PR_FALSE;
  ------------------
  |  |  438|  21.9k|#define PR_FALSE 0
  ------------------
 4438|  21.9k|    }
 4439|       |    /* if we are purposefully passed SEC_OID_UNKNOWN, it means
 4440|       |     * we not checking the scheme against a potential key, so skip
 4441|       |     * the call */
 4442|  78.9k|    if ((spkiOid != SEC_OID_UNKNOWN) &&
  ------------------
  |  Branch (4442:9): [True: 52.1k, False: 26.8k]
  ------------------
 4443|  78.9k|        !ssl_SignatureSchemeMatchesSpkiOid(scheme, spkiOid)) {
  ------------------
  |  Branch (4443:9): [True: 24.3k, False: 27.7k]
  ------------------
 4444|  24.3k|        return PR_FALSE;
  ------------------
  |  |  438|  24.3k|#define PR_FALSE 0
  ------------------
 4445|  24.3k|    }
 4446|  54.5k|    if (isTls13) {
  ------------------
  |  Branch (4446:9): [True: 5.70k, False: 48.8k]
  ------------------
 4447|  5.70k|        if (ssl_SignatureSchemeToHashType(scheme) == ssl_hash_sha1) {
  ------------------
  |  Branch (4447:13): [True: 307, False: 5.39k]
  ------------------
 4448|    307|            return PR_FALSE;
  ------------------
  |  |  438|    307|#define PR_FALSE 0
  ------------------
 4449|    307|        }
 4450|  5.39k|        if (ssl_IsRsaPkcs1SignatureScheme(scheme)) {
  ------------------
  |  Branch (4450:13): [True: 702, False: 4.69k]
  ------------------
 4451|    702|            return PR_FALSE;
  ------------------
  |  |  438|    702|#define PR_FALSE 0
  ------------------
 4452|    702|        }
 4453|  4.69k|        if (ssl_IsDsaSignatureScheme(scheme)) {
  ------------------
  |  Branch (4453:13): [True: 432, False: 4.26k]
  ------------------
 4454|    432|            return PR_FALSE;
  ------------------
  |  |  438|    432|#define PR_FALSE 0
  ------------------
 4455|    432|        }
 4456|       |        /* With TLS 1.3, EC keys should have been selected based on calling
 4457|       |         * ssl_SignatureSchemeFromSpki(), reject them otherwise. */
 4458|  4.26k|        return spkiOid != SEC_OID_ANSIX962_EC_PUBLIC_KEY;
 4459|  4.69k|    }
 4460|  48.8k|    return PR_TRUE;
  ------------------
  |  |  437|  48.8k|#define PR_TRUE 1
  ------------------
 4461|  54.5k|}
ssl_SignatureSchemeFromSpki:
 4552|  12.5k|{
 4553|  12.5k|    SECOidTag spkiOid = SECOID_GetAlgorithmTag(&spki->algorithm);
  ------------------
  |  |  119|  12.5k|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
 4554|       |
 4555|  12.5k|    if (spkiOid == SEC_OID_PKCS1_RSA_PSS_SIGNATURE) {
  ------------------
  |  Branch (4555:9): [True: 2, False: 12.5k]
  ------------------
 4556|      2|        return ssl_SignatureSchemeFromPssSpki(spki, scheme);
 4557|      2|    }
 4558|       |
 4559|       |    /* Only do this lookup for TLS 1.3, where the scheme can be determined from
 4560|       |     * the SPKI alone because the ECDSA key size determines the hash. Earlier
 4561|       |     * TLS versions allow the same EC key to be used with different hashes. */
 4562|  12.5k|    if (isTls13 && spkiOid == SEC_OID_ANSIX962_EC_PUBLIC_KEY) {
  ------------------
  |  Branch (4562:9): [True: 2.39k, False: 10.1k]
  |  Branch (4562:20): [True: 1.24k, False: 1.14k]
  ------------------
 4563|  1.24k|        return ssl_SignatureSchemeFromEcSpki(spki, scheme);
 4564|  1.24k|    }
 4565|       |
 4566|  11.3k|    *scheme = ssl_sig_none;
 4567|  11.3k|    return SECSuccess;
 4568|  12.5k|}
ssl_SignatureSchemeEnabled:
 4573|  4.25k|{
 4574|  4.25k|    unsigned int i;
 4575|  30.8k|    for (i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (4575:17): [True: 30.8k, False: 0]
  ------------------
 4576|  30.8k|        if (scheme == ss->ssl3.signatureSchemes[i]) {
  ------------------
  |  Branch (4576:13): [True: 4.25k, False: 26.5k]
  ------------------
 4577|  4.25k|            return PR_TRUE;
  ------------------
  |  |  437|  4.25k|#define PR_TRUE 1
  ------------------
 4578|  4.25k|        }
 4579|  30.8k|    }
 4580|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4581|  4.25k|}
ssl_CheckSignatureSchemeConsistency:
 4609|  3.01k|{
 4610|  3.01k|    SSLSignatureScheme spkiScheme;
 4611|  3.01k|    PRBool isTLS13 = ss->version == SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|  3.01k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
 4612|  3.01k|    SECOidTag spkiOid;
 4613|  3.01k|    SECStatus rv;
 4614|       |
 4615|  3.01k|    rv = ssl_SignatureSchemeFromSpki(spki, isTLS13, &spkiScheme);
 4616|  3.01k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4616:9): [True: 2, False: 3.01k]
  ------------------
 4617|      2|        return SECFailure;
 4618|      2|    }
 4619|  3.01k|    if (spkiScheme != ssl_sig_none) {
  ------------------
  |  Branch (4619:9): [True: 0, False: 3.01k]
  ------------------
 4620|       |        /* The SPKI in the certificate can only be used for a single scheme. */
 4621|      0|        if (spkiScheme != scheme ||
  ------------------
  |  Branch (4621:13): [True: 0, False: 0]
  ------------------
 4622|      0|            !ssl_SignatureSchemeEnabled(ss, scheme)) {
  ------------------
  |  Branch (4622:13): [True: 0, False: 0]
  ------------------
 4623|      0|            PORT_SetError(SSL_ERROR_INCORRECT_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4624|      0|            return SECFailure;
 4625|      0|        }
 4626|      0|        return SECSuccess;
 4627|      0|    }
 4628|       |
 4629|  3.01k|    spkiOid = SECOID_GetAlgorithmTag(&spki->algorithm);
  ------------------
  |  |  119|  3.01k|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
 4630|       |
 4631|       |    /* If we're a client, check that the signature algorithm matches the signing
 4632|       |     * key type of the cipher suite. */
 4633|  3.01k|    if (!isTLS13 && !ss->sec.isServer) {
  ------------------
  |  Branch (4633:9): [True: 3.01k, False: 0]
  |  Branch (4633:21): [True: 0, False: 3.01k]
  ------------------
 4634|      0|        if (!ssl_SignatureKeyMatchesSpkiOid(ss->ssl3.hs.kea_def, spkiOid)) {
  ------------------
  |  Branch (4634:13): [True: 0, False: 0]
  ------------------
 4635|      0|            PORT_SetError(SSL_ERROR_INCORRECT_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4636|      0|            return SECFailure;
 4637|      0|        }
 4638|      0|    }
 4639|       |
 4640|       |    /* Verify that the signature scheme matches the signing key. */
 4641|  3.01k|    if ((spkiOid == SEC_OID_UNKNOWN) ||
  ------------------
  |  Branch (4641:9): [True: 1, False: 3.01k]
  ------------------
 4642|  3.01k|        !ssl_SignatureSchemeValid(scheme, spkiOid, isTLS13)) {
  ------------------
  |  Branch (4642:9): [True: 7, False: 3.00k]
  ------------------
 4643|      8|        PORT_SetError(SSL_ERROR_INCORRECT_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      8|#define PORT_SetError PORT_SetError_Util
  ------------------
 4644|      8|        return SECFailure;
 4645|      8|    }
 4646|       |
 4647|  3.00k|    if (!ssl_SignatureSchemeEnabled(ss, scheme)) {
  ------------------
  |  Branch (4647:9): [True: 0, False: 3.00k]
  ------------------
 4648|      0|        PORT_SetError(SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4649|      0|        return SECFailure;
 4650|      0|    }
 4651|       |
 4652|  3.00k|    return SECSuccess;
 4653|  3.00k|}
ssl_IsSupportedSignatureScheme:
 4657|   103k|{
 4658|   103k|    switch (scheme) {
  ------------------
  |  Branch (4658:13): [True: 20.4k, False: 83.4k]
  ------------------
 4659|  7.63k|        case ssl_sig_rsa_pkcs1_sha1:
  ------------------
  |  Branch (4659:9): [True: 7.63k, False: 96.2k]
  ------------------
 4660|  15.7k|        case ssl_sig_rsa_pkcs1_sha256:
  ------------------
  |  Branch (4660:9): [True: 8.13k, False: 95.7k]
  ------------------
 4661|  16.9k|        case ssl_sig_rsa_pkcs1_sha384:
  ------------------
  |  Branch (4661:9): [True: 1.13k, False: 102k]
  ------------------
 4662|  18.1k|        case ssl_sig_rsa_pkcs1_sha512:
  ------------------
  |  Branch (4662:9): [True: 1.21k, False: 102k]
  ------------------
 4663|  25.4k|        case ssl_sig_rsa_pss_rsae_sha256:
  ------------------
  |  Branch (4663:9): [True: 7.37k, False: 96.4k]
  ------------------
 4664|  30.8k|        case ssl_sig_rsa_pss_rsae_sha384:
  ------------------
  |  Branch (4664:9): [True: 5.32k, False: 98.5k]
  ------------------
 4665|  39.2k|        case ssl_sig_rsa_pss_rsae_sha512:
  ------------------
  |  Branch (4665:9): [True: 8.41k, False: 95.4k]
  ------------------
 4666|  39.3k|        case ssl_sig_rsa_pss_pss_sha256:
  ------------------
  |  Branch (4666:9): [True: 84, False: 103k]
  ------------------
 4667|  39.4k|        case ssl_sig_rsa_pss_pss_sha384:
  ------------------
  |  Branch (4667:9): [True: 145, False: 103k]
  ------------------
 4668|  39.4k|        case ssl_sig_rsa_pss_pss_sha512:
  ------------------
  |  Branch (4668:9): [True: 19, False: 103k]
  ------------------
 4669|  51.6k|        case ssl_sig_ecdsa_secp256r1_sha256:
  ------------------
  |  Branch (4669:9): [True: 12.1k, False: 91.7k]
  ------------------
 4670|  60.2k|        case ssl_sig_ecdsa_secp384r1_sha384:
  ------------------
  |  Branch (4670:9): [True: 8.59k, False: 95.2k]
  ------------------
 4671|  70.4k|        case ssl_sig_ecdsa_secp521r1_sha512:
  ------------------
  |  Branch (4671:9): [True: 10.2k, False: 93.6k]
  ------------------
 4672|  70.5k|        case ssl_sig_dsa_sha1:
  ------------------
  |  Branch (4672:9): [True: 184, False: 103k]
  ------------------
 4673|  70.7k|        case ssl_sig_dsa_sha256:
  ------------------
  |  Branch (4673:9): [True: 108, False: 103k]
  ------------------
 4674|  71.2k|        case ssl_sig_dsa_sha384:
  ------------------
  |  Branch (4674:9): [True: 500, False: 103k]
  ------------------
 4675|  71.2k|        case ssl_sig_dsa_sha512:
  ------------------
  |  Branch (4675:9): [True: 95, False: 103k]
  ------------------
 4676|  81.9k|        case ssl_sig_ecdsa_sha1:
  ------------------
  |  Branch (4676:9): [True: 10.6k, False: 93.2k]
  ------------------
 4677|  81.9k|            return ssl_SchemePolicyOK(scheme, kSSLSigSchemePolicy);
 4678|      0|            break;
 4679|       |
 4680|      0|        case ssl_sig_rsa_pkcs1_sha1md5:
  ------------------
  |  Branch (4680:9): [True: 0, False: 103k]
  ------------------
 4681|    903|        case ssl_sig_none:
  ------------------
  |  Branch (4681:9): [True: 903, False: 102k]
  ------------------
 4682|    937|        case ssl_sig_ed25519:
  ------------------
  |  Branch (4682:9): [True: 34, False: 103k]
  ------------------
 4683|  1.46k|        case ssl_sig_ed448:
  ------------------
  |  Branch (4683:9): [True: 532, False: 103k]
  ------------------
 4684|  1.46k|            return PR_FALSE;
  ------------------
  |  |  438|  1.46k|#define PR_FALSE 0
  ------------------
 4685|   103k|    }
 4686|  20.4k|    return PR_FALSE;
  ------------------
  |  |  438|  20.4k|#define PR_FALSE 0
  ------------------
 4687|   103k|}
ssl_IsRsaPssSignatureScheme:
 4691|  3.74M|{
 4692|  3.74M|    switch (scheme) {
 4693|  2.28M|        case ssl_sig_rsa_pss_rsae_sha256:
  ------------------
  |  Branch (4693:9): [True: 2.28M, False: 1.45M]
  ------------------
 4694|  2.31M|        case ssl_sig_rsa_pss_rsae_sha384:
  ------------------
  |  Branch (4694:9): [True: 26.9k, False: 3.71M]
  ------------------
 4695|  2.34M|        case ssl_sig_rsa_pss_rsae_sha512:
  ------------------
  |  Branch (4695:9): [True: 32.8k, False: 3.70M]
  ------------------
 4696|  2.34M|        case ssl_sig_rsa_pss_pss_sha256:
  ------------------
  |  Branch (4696:9): [True: 84, False: 3.74M]
  ------------------
 4697|  2.34M|        case ssl_sig_rsa_pss_pss_sha384:
  ------------------
  |  Branch (4697:9): [True: 145, False: 3.74M]
  ------------------
 4698|  2.34M|        case ssl_sig_rsa_pss_pss_sha512:
  ------------------
  |  Branch (4698:9): [True: 19, False: 3.74M]
  ------------------
 4699|  2.34M|            return PR_TRUE;
  ------------------
  |  |  437|  2.34M|#define PR_TRUE 1
  ------------------
 4700|       |
 4701|  1.39M|        default:
  ------------------
  |  Branch (4701:9): [True: 1.39M, False: 2.34M]
  ------------------
 4702|  1.39M|            return PR_FALSE;
  ------------------
  |  |  438|  1.39M|#define PR_FALSE 0
  ------------------
 4703|  3.74M|    }
 4704|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4705|  3.74M|}
ssl_IsRsaPkcs1SignatureScheme:
 4724|   581k|{
 4725|   581k|    switch (scheme) {
 4726|  1.27k|        case ssl_sig_rsa_pkcs1_sha256:
  ------------------
  |  Branch (4726:9): [True: 1.27k, False: 580k]
  ------------------
 4727|  2.31k|        case ssl_sig_rsa_pkcs1_sha384:
  ------------------
  |  Branch (4727:9): [True: 1.03k, False: 580k]
  ------------------
 4728|  3.38k|        case ssl_sig_rsa_pkcs1_sha512:
  ------------------
  |  Branch (4728:9): [True: 1.06k, False: 580k]
  ------------------
 4729|  4.27k|        case ssl_sig_rsa_pkcs1_sha1:
  ------------------
  |  Branch (4729:9): [True: 894, False: 580k]
  ------------------
 4730|  4.27k|            return PR_TRUE;
  ------------------
  |  |  437|  4.27k|#define PR_TRUE 1
  ------------------
 4731|       |
 4732|   577k|        default:
  ------------------
  |  Branch (4732:9): [True: 577k, False: 4.27k]
  ------------------
 4733|   577k|            return PR_FALSE;
  ------------------
  |  |  438|   577k|#define PR_FALSE 0
  ------------------
 4734|   581k|    }
 4735|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4736|   581k|}
ssl_IsDsaSignatureScheme:
 4740|   638k|{
 4741|   638k|    switch (scheme) {
 4742|  6.21k|        case ssl_sig_dsa_sha256:
  ------------------
  |  Branch (4742:9): [True: 6.21k, False: 632k]
  ------------------
 4743|  12.7k|        case ssl_sig_dsa_sha384:
  ------------------
  |  Branch (4743:9): [True: 6.49k, False: 632k]
  ------------------
 4744|  18.9k|        case ssl_sig_dsa_sha512:
  ------------------
  |  Branch (4744:9): [True: 6.19k, False: 632k]
  ------------------
 4745|  25.0k|        case ssl_sig_dsa_sha1:
  ------------------
  |  Branch (4745:9): [True: 6.16k, False: 632k]
  ------------------
 4746|  25.0k|            return PR_TRUE;
  ------------------
  |  |  437|  25.0k|#define PR_TRUE 1
  ------------------
 4747|       |
 4748|   613k|        default:
  ------------------
  |  Branch (4748:9): [True: 613k, False: 25.0k]
  ------------------
 4749|   613k|            return PR_FALSE;
  ------------------
  |  |  438|   613k|#define PR_FALSE 0
  ------------------
 4750|   638k|    }
 4751|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4752|   638k|}
ssl_SignatureSchemeToAuthType:
 4756|  7.04M|{
 4757|  7.04M|    switch (scheme) {
 4758|  68.3k|        case ssl_sig_rsa_pkcs1_sha1:
  ------------------
  |  Branch (4758:9): [True: 68.3k, False: 6.97M]
  ------------------
 4759|  74.9k|        case ssl_sig_rsa_pkcs1_sha1md5:
  ------------------
  |  Branch (4759:9): [True: 6.59k, False: 7.03M]
  ------------------
 4760|  92.9k|        case ssl_sig_rsa_pkcs1_sha256:
  ------------------
  |  Branch (4760:9): [True: 18.0k, False: 7.02M]
  ------------------
 4761|   101k|        case ssl_sig_rsa_pkcs1_sha384:
  ------------------
  |  Branch (4761:9): [True: 8.19k, False: 7.03M]
  ------------------
 4762|   108k|        case ssl_sig_rsa_pkcs1_sha512:
  ------------------
  |  Branch (4762:9): [True: 7.56k, False: 7.03M]
  ------------------
 4763|       |        /* We report based on the key type for PSS signatures. */
 4764|  1.24M|        case ssl_sig_rsa_pss_rsae_sha256:
  ------------------
  |  Branch (4764:9): [True: 1.13M, False: 5.90M]
  ------------------
 4765|  1.25M|        case ssl_sig_rsa_pss_rsae_sha384:
  ------------------
  |  Branch (4765:9): [True: 5.41k, False: 7.03M]
  ------------------
 4766|  1.26M|        case ssl_sig_rsa_pss_rsae_sha512:
  ------------------
  |  Branch (4766:9): [True: 11.8k, False: 7.03M]
  ------------------
 4767|  1.26M|            return ssl_auth_rsa_sign;
 4768|      1|        case ssl_sig_rsa_pss_pss_sha256:
  ------------------
  |  Branch (4768:9): [True: 1, False: 7.04M]
  ------------------
 4769|      2|        case ssl_sig_rsa_pss_pss_sha384:
  ------------------
  |  Branch (4769:9): [True: 1, False: 7.04M]
  ------------------
 4770|      3|        case ssl_sig_rsa_pss_pss_sha512:
  ------------------
  |  Branch (4770:9): [True: 1, False: 7.04M]
  ------------------
 4771|      3|            return ssl_auth_rsa_pss;
 4772|  2.27M|        case ssl_sig_ecdsa_secp256r1_sha256:
  ------------------
  |  Branch (4772:9): [True: 2.27M, False: 4.76M]
  ------------------
 4773|  3.43M|        case ssl_sig_ecdsa_secp384r1_sha384:
  ------------------
  |  Branch (4773:9): [True: 1.15M, False: 5.88M]
  ------------------
 4774|  4.58M|        case ssl_sig_ecdsa_secp521r1_sha512:
  ------------------
  |  Branch (4774:9): [True: 1.15M, False: 5.88M]
  ------------------
 4775|  5.75M|        case ssl_sig_ecdsa_sha1:
  ------------------
  |  Branch (4775:9): [True: 1.16M, False: 5.87M]
  ------------------
 4776|  5.75M|            return ssl_auth_ecdsa;
 4777|  5.02k|        case ssl_sig_dsa_sha1:
  ------------------
  |  Branch (4777:9): [True: 5.02k, False: 7.03M]
  ------------------
 4778|  9.97k|        case ssl_sig_dsa_sha256:
  ------------------
  |  Branch (4778:9): [True: 4.95k, False: 7.03M]
  ------------------
 4779|  15.3k|        case ssl_sig_dsa_sha384:
  ------------------
  |  Branch (4779:9): [True: 5.34k, False: 7.03M]
  ------------------
 4780|  20.2k|        case ssl_sig_dsa_sha512:
  ------------------
  |  Branch (4780:9): [True: 4.93k, False: 7.03M]
  ------------------
 4781|  20.2k|            return ssl_auth_dsa;
 4782|       |
 4783|      0|        default:
  ------------------
  |  Branch (4783:9): [True: 0, False: 7.04M]
  ------------------
 4784|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4785|  7.04M|    }
 4786|      0|    return ssl_auth_null;
 4787|  7.04M|}
ssl_ConsumeSignatureScheme:
 4797|  3.02k|{
 4798|  3.02k|    PRUint32 tmp;
 4799|  3.02k|    SECStatus rv;
 4800|       |
 4801|  3.02k|    rv = ssl3_ConsumeHandshakeNumber(ss, &tmp, 2, b, length);
 4802|  3.02k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4802:9): [True: 1, False: 3.02k]
  ------------------
 4803|      1|        return SECFailure; /* Alert sent, Error code set already. */
 4804|      1|    }
 4805|  3.02k|    if (!ssl_IsSupportedSignatureScheme((SSLSignatureScheme)tmp)) {
  ------------------
  |  Branch (4805:9): [True: 1, False: 3.01k]
  ------------------
 4806|      1|        SSL3_SendAlert(ss, alert_fatal, illegal_parameter);
 4807|      1|        PORT_SetError(SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 4808|      1|        return SECFailure;
 4809|      1|    }
 4810|  3.01k|    *out = (SSLSignatureScheme)tmp;
 4811|  3.01k|    return SECSuccess;
 4812|  3.02k|}
ssl3_ComputeHandshakeHashes:
 4858|   111k|{
 4859|   111k|    SECStatus rv = SECSuccess;
 4860|   111k|    PRBool isTLS = (PRBool)(spec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|   111k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
 4861|   111k|    unsigned int outLength;
 4862|   111k|    PRUint8 md5_inner[MAX_MAC_LENGTH];
 4863|   111k|    PRUint8 sha_inner[MAX_MAC_LENGTH];
 4864|       |
 4865|   111k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   111k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   169k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 53.8k, False: 57.8k]
  |  |  |  |  |  Branch (208:7): [True: 57.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4866|   111k|    if (ss->ssl3.hs.hashType == handshake_hash_unknown) {
  ------------------
  |  Branch (4866:9): [True: 0, False: 111k]
  ------------------
 4867|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4868|      0|        return SECFailure;
 4869|      0|    }
 4870|       |
 4871|   111k|    hashes->hashAlg = ssl_hash_none;
 4872|       |
 4873|   111k|    if (ss->ssl3.hs.hashType == handshake_hash_single) {
  ------------------
  |  Branch (4873:9): [True: 0, False: 111k]
  ------------------
 4874|      0|        PK11Context *h;
 4875|      0|        unsigned int stateLen;
 4876|      0|        unsigned char stackBuf[1024];
 4877|      0|        unsigned char *stateBuf = NULL;
 4878|       |
 4879|      0|        h = ss->ssl3.hs.sha;
 4880|      0|        stateBuf = PK11_SaveContextAlloc(h, stackBuf,
 4881|      0|                                         sizeof(stackBuf), &stateLen);
 4882|      0|        if (stateBuf == NULL) {
  ------------------
  |  Branch (4882:13): [True: 0, False: 0]
  ------------------
 4883|      0|            ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 4884|      0|            rv = SECFailure;
 4885|      0|            goto tls12_loser;
 4886|      0|        }
 4887|      0|        rv |= PK11_DigestFinal(h, hashes->u.raw, &hashes->len,
 4888|      0|                               sizeof(hashes->u.raw));
 4889|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4889:13): [True: 0, False: 0]
  ------------------
 4890|      0|            ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 4891|      0|            rv = SECFailure;
 4892|      0|            goto tls12_loser;
 4893|      0|        }
 4894|       |
 4895|      0|        hashes->hashAlg = ssl3_GetSuitePrfHash(ss);
 4896|       |
 4897|      0|    tls12_loser:
 4898|      0|        if (stateBuf) {
  ------------------
  |  Branch (4898:13): [True: 0, False: 0]
  ------------------
 4899|      0|            if (PK11_RestoreContext(h, stateBuf, stateLen) != SECSuccess) {
  ------------------
  |  Branch (4899:17): [True: 0, False: 0]
  ------------------
 4900|      0|                ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 4901|      0|                rv = SECFailure;
 4902|      0|            }
 4903|      0|            if (stateBuf != stackBuf) {
  ------------------
  |  Branch (4903:17): [True: 0, False: 0]
  ------------------
 4904|      0|                PORT_ZFree(stateBuf, stateLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 4905|      0|            }
 4906|      0|        }
 4907|   111k|    } else if (ss->ssl3.hs.hashType == handshake_hash_record) {
  ------------------
  |  Branch (4907:16): [True: 98.9k, False: 12.7k]
  ------------------
 4908|  98.9k|        rv = ssl3_ComputeHandshakeHash(ss->ssl3.hs.messages.buf,
 4909|  98.9k|                                       ss->ssl3.hs.messages.len,
 4910|  98.9k|                                       ssl3_GetSuitePrfHash(ss),
 4911|  98.9k|                                       hashes);
 4912|  98.9k|    } else {
 4913|  12.7k|        PK11Context *md5;
 4914|  12.7k|        PK11Context *sha = NULL;
 4915|  12.7k|        unsigned char *md5StateBuf = NULL;
 4916|  12.7k|        unsigned char *shaStateBuf = NULL;
 4917|  12.7k|        unsigned int md5StateLen, shaStateLen;
 4918|  12.7k|        unsigned char md5StackBuf[256];
 4919|  12.7k|        unsigned char shaStackBuf[512];
 4920|  12.7k|        const int md5Pad = ssl_GetMacDefByAlg(ssl_mac_md5)->pad_size;
 4921|  12.7k|        const int shaPad = ssl_GetMacDefByAlg(ssl_mac_sha)->pad_size;
 4922|       |
 4923|  12.7k|        md5StateBuf = PK11_SaveContextAlloc(ss->ssl3.hs.md5, md5StackBuf,
 4924|  12.7k|                                            sizeof md5StackBuf, &md5StateLen);
 4925|  12.7k|        if (md5StateBuf == NULL) {
  ------------------
  |  Branch (4925:13): [True: 0, False: 12.7k]
  ------------------
 4926|      0|            ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 4927|      0|            rv = SECFailure;
 4928|      0|            goto loser;
 4929|      0|        }
 4930|  12.7k|        md5 = ss->ssl3.hs.md5;
 4931|       |
 4932|  12.7k|        shaStateBuf = PK11_SaveContextAlloc(ss->ssl3.hs.sha, shaStackBuf,
 4933|  12.7k|                                            sizeof shaStackBuf, &shaStateLen);
 4934|  12.7k|        if (shaStateBuf == NULL) {
  ------------------
  |  Branch (4934:13): [True: 0, False: 12.7k]
  ------------------
 4935|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4936|      0|            rv = SECFailure;
 4937|      0|            goto loser;
 4938|      0|        }
 4939|  12.7k|        sha = ss->ssl3.hs.sha;
 4940|       |
 4941|  12.7k|        if (!isTLS) {
  ------------------
  |  Branch (4941:13): [True: 0, False: 12.7k]
  ------------------
 4942|       |            /* compute hashes for SSL3. */
 4943|      0|            unsigned char s[4];
 4944|       |
 4945|      0|            if (!spec->masterSecret) {
  ------------------
  |  Branch (4945:17): [True: 0, False: 0]
  ------------------
 4946|      0|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_HANDSHAKE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4947|      0|                rv = SECFailure;
 4948|      0|                goto loser;
 4949|      0|            }
 4950|       |
 4951|      0|            s[0] = (unsigned char)(sender >> 24);
 4952|      0|            s[1] = (unsigned char)(sender >> 16);
 4953|      0|            s[2] = (unsigned char)(sender >> 8);
 4954|      0|            s[3] = (unsigned char)sender;
 4955|       |
 4956|      0|            if (sender != 0) {
  ------------------
  |  Branch (4956:17): [True: 0, False: 0]
  ------------------
 4957|      0|                rv |= PK11_DigestOp(md5, s, 4);
 4958|      0|                PRINT_BUF(95, (NULL, "MD5 inner: sender", s, 4));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4959|      0|            }
 4960|       |
 4961|      0|            PRINT_BUF(95, (NULL, "MD5 inner: MAC Pad 1", mac_pad_1, md5Pad));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4962|       |
 4963|      0|            rv |= PK11_DigestKey(md5, spec->masterSecret);
 4964|      0|            rv |= PK11_DigestOp(md5, mac_pad_1, md5Pad);
 4965|      0|            rv |= PK11_DigestFinal(md5, md5_inner, &outLength, MD5_LENGTH);
  ------------------
  |  |   38|      0|#define MD5_LENGTH 16
  ------------------
 4966|      0|            PORT_Assert(rv != SECSuccess || outLength == MD5_LENGTH);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4967|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (4967:17): [True: 0, False: 0]
  ------------------
 4968|      0|                ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 4969|      0|                rv = SECFailure;
 4970|      0|                goto loser;
 4971|      0|            }
 4972|       |
 4973|      0|            PRINT_BUF(95, (NULL, "MD5 inner: result", md5_inner, outLength));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4974|       |
 4975|      0|            if (sender != 0) {
  ------------------
  |  Branch (4975:17): [True: 0, False: 0]
  ------------------
 4976|      0|                rv |= PK11_DigestOp(sha, s, 4);
 4977|      0|                PRINT_BUF(95, (NULL, "SHA inner: sender", s, 4));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4978|      0|            }
 4979|       |
 4980|      0|            PRINT_BUF(95, (NULL, "SHA inner: MAC Pad 1", mac_pad_1, shaPad));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4981|       |
 4982|      0|            rv |= PK11_DigestKey(sha, spec->masterSecret);
 4983|      0|            rv |= PK11_DigestOp(sha, mac_pad_1, shaPad);
 4984|      0|            rv |= PK11_DigestFinal(sha, sha_inner, &outLength, SHA1_LENGTH);
  ------------------
  |  |   39|      0|#define SHA1_LENGTH 20
  ------------------
 4985|      0|            PORT_Assert(rv != SECSuccess || outLength == SHA1_LENGTH);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4986|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (4986:17): [True: 0, False: 0]
  ------------------
 4987|      0|                ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4988|      0|                rv = SECFailure;
 4989|      0|                goto loser;
 4990|      0|            }
 4991|       |
 4992|      0|            PRINT_BUF(95, (NULL, "SHA inner: result", sha_inner, outLength));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4993|       |
 4994|      0|            PRINT_BUF(95, (NULL, "MD5 outer: MAC Pad 2", mac_pad_2, md5Pad));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4995|      0|            PRINT_BUF(95, (NULL, "MD5 outer: MD5 inner", md5_inner, MD5_LENGTH));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4996|       |
 4997|      0|            rv |= PK11_DigestBegin(md5);
 4998|      0|            rv |= PK11_DigestKey(md5, spec->masterSecret);
 4999|      0|            rv |= PK11_DigestOp(md5, mac_pad_2, md5Pad);
 5000|      0|            rv |= PK11_DigestOp(md5, md5_inner, MD5_LENGTH);
  ------------------
  |  |   38|      0|#define MD5_LENGTH 16
  ------------------
 5001|      0|        }
 5002|  12.7k|        rv |= PK11_DigestFinal(md5, hashes->u.s.md5, &outLength, MD5_LENGTH);
  ------------------
  |  |   38|  12.7k|#define MD5_LENGTH 16
  ------------------
 5003|  12.7k|        PORT_Assert(rv != SECSuccess || outLength == MD5_LENGTH);
  ------------------
  |  |  120|  12.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  25.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 12.7k]
  |  |  |  |  |  Branch (208:7): [True: 12.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5004|  12.7k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5004:13): [True: 0, False: 12.7k]
  ------------------
 5005|      0|            ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 5006|      0|            rv = SECFailure;
 5007|      0|            goto loser;
 5008|      0|        }
 5009|       |
 5010|  12.7k|        PRINT_BUF(60, (NULL, "MD5 outer: result", hashes->u.s.md5, MD5_LENGTH));
  ------------------
  |  |   74|  12.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 12.7k]
  |  |  ------------------
  |  |   75|  12.7k|    ssl_PrintBuf b
  ------------------
 5011|       |
 5012|  12.7k|        if (!isTLS) {
  ------------------
  |  Branch (5012:13): [True: 0, False: 12.7k]
  ------------------
 5013|      0|            PRINT_BUF(95, (NULL, "SHA outer: MAC Pad 2", mac_pad_2, shaPad));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 5014|      0|            PRINT_BUF(95, (NULL, "SHA outer: SHA inner", sha_inner, SHA1_LENGTH));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 5015|       |
 5016|      0|            rv |= PK11_DigestBegin(sha);
 5017|      0|            rv |= PK11_DigestKey(sha, spec->masterSecret);
 5018|      0|            rv |= PK11_DigestOp(sha, mac_pad_2, shaPad);
 5019|      0|            rv |= PK11_DigestOp(sha, sha_inner, SHA1_LENGTH);
  ------------------
  |  |   39|      0|#define SHA1_LENGTH 20
  ------------------
 5020|      0|        }
 5021|  12.7k|        rv |= PK11_DigestFinal(sha, hashes->u.s.sha, &outLength, SHA1_LENGTH);
  ------------------
  |  |   39|  12.7k|#define SHA1_LENGTH 20
  ------------------
 5022|  12.7k|        PORT_Assert(rv != SECSuccess || outLength == SHA1_LENGTH);
  ------------------
  |  |  120|  12.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  25.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 12.7k]
  |  |  |  |  |  Branch (208:7): [True: 12.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5023|  12.7k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5023:13): [True: 0, False: 12.7k]
  ------------------
 5024|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 5025|      0|            rv = SECFailure;
 5026|      0|            goto loser;
 5027|      0|        }
 5028|       |
 5029|  12.7k|        PRINT_BUF(60, (NULL, "SHA outer: result", hashes->u.s.sha, SHA1_LENGTH));
  ------------------
  |  |   74|  12.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 12.7k]
  |  |  ------------------
  |  |   75|  12.7k|    ssl_PrintBuf b
  ------------------
 5030|       |
 5031|  12.7k|        hashes->len = MD5_LENGTH + SHA1_LENGTH;
  ------------------
  |  |   38|  12.7k|#define MD5_LENGTH 16
  ------------------
                      hashes->len = MD5_LENGTH + SHA1_LENGTH;
  ------------------
  |  |   39|  12.7k|#define SHA1_LENGTH 20
  ------------------
 5032|       |
 5033|  12.7k|    loser:
 5034|  12.7k|        if (md5StateBuf) {
  ------------------
  |  Branch (5034:13): [True: 12.7k, False: 0]
  ------------------
 5035|  12.7k|            if (PK11_RestoreContext(ss->ssl3.hs.md5, md5StateBuf, md5StateLen) !=
  ------------------
  |  Branch (5035:17): [True: 0, False: 12.7k]
  ------------------
 5036|  12.7k|                SECSuccess) {
 5037|      0|                ssl_MapLowLevelError(SSL_ERROR_MD5_DIGEST_FAILURE);
 5038|      0|                rv = SECFailure;
 5039|      0|            }
 5040|  12.7k|            if (md5StateBuf != md5StackBuf) {
  ------------------
  |  Branch (5040:17): [True: 0, False: 12.7k]
  ------------------
 5041|      0|                PORT_ZFree(md5StateBuf, md5StateLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 5042|      0|            }
 5043|  12.7k|        }
 5044|  12.7k|        if (shaStateBuf) {
  ------------------
  |  Branch (5044:13): [True: 12.7k, False: 0]
  ------------------
 5045|  12.7k|            if (PK11_RestoreContext(ss->ssl3.hs.sha, shaStateBuf, shaStateLen) !=
  ------------------
  |  Branch (5045:17): [True: 0, False: 12.7k]
  ------------------
 5046|  12.7k|                SECSuccess) {
 5047|      0|                ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 5048|      0|                rv = SECFailure;
 5049|      0|            }
 5050|  12.7k|            if (shaStateBuf != shaStackBuf) {
  ------------------
  |  Branch (5050:17): [True: 0, False: 12.7k]
  ------------------
 5051|      0|                PORT_ZFree(shaStateBuf, shaStateLen);
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 5052|      0|            }
 5053|  12.7k|        }
 5054|  12.7k|    }
 5055|   111k|    return rv;
 5056|   111k|}
ssl_FreeSymWrapKeysLock:
 5997|      1|{
 5998|      1|    if (symWrapKeysLock) {
  ------------------
  |  Branch (5998:9): [True: 1, False: 0]
  ------------------
 5999|      1|        PZ_DestroyLock(symWrapKeysLock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
 6000|      1|        symWrapKeysLock = NULL;
 6001|      1|        return SECSuccess;
 6002|      1|    }
 6003|      0|    PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6004|      0|    return SECFailure;
 6005|      1|}
SSL3_ShutdownServerCache:
 6009|      1|{
 6010|      1|    int i, j;
 6011|       |
 6012|      1|    if (!symWrapKeysLock)
  ------------------
  |  Branch (6012:9): [True: 0, False: 1]
  ------------------
 6013|      0|        return SECSuccess; /* lock was never initialized */
 6014|      1|    PZ_Lock(symWrapKeysLock);
  ------------------
  |  |  245|      1|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 6015|       |    /* get rid of all symWrapKeys */
 6016|     16|    for (i = 0; i < SSL_NUM_WRAP_MECHS; ++i) {
  ------------------
  |  |  115|     16|#define SSL_NUM_WRAP_MECHS 15
  ------------------
  |  Branch (6016:17): [True: 15, False: 1]
  ------------------
 6017|    105|        for (j = 0; j < SSL_NUM_WRAP_KEYS; ++j) {
  ------------------
  |  |  116|    105|#define SSL_NUM_WRAP_KEYS 6
  ------------------
  |  Branch (6017:21): [True: 90, False: 15]
  ------------------
 6018|     90|            PK11SymKey **pSymWrapKey;
 6019|     90|            pSymWrapKey = &symWrapKeys[i].symWrapKey[j];
 6020|     90|            if (*pSymWrapKey) {
  ------------------
  |  Branch (6020:17): [True: 2, False: 88]
  ------------------
 6021|      2|                PK11_FreeSymKey(*pSymWrapKey);
 6022|      2|                *pSymWrapKey = NULL;
 6023|      2|            }
 6024|     90|        }
 6025|     15|    }
 6026|       |
 6027|      1|    PZ_Unlock(symWrapKeysLock);
  ------------------
  |  |  246|      1|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 6028|      1|    ssl_FreeSessionCacheLocks();
 6029|      1|    return SECSuccess;
 6030|      1|}
ssl_InitSymWrapKeysLock:
 6034|      1|{
 6035|      1|    symWrapKeysLock = PZ_NewLock(nssILockOther);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 6036|      1|    return symWrapKeysLock ? SECSuccess : SECFailure;
  ------------------
  |  Branch (6036:12): [True: 1, False: 0]
  ------------------
 6037|      1|}
ssl3_GetWrappingKey:
 6053|  33.9k|{
 6054|  33.9k|    SSLAuthType authType;
 6055|  33.9k|    SECKEYPrivateKey *svrPrivKey;
 6056|  33.9k|    SECKEYPublicKey *svrPubKey = NULL;
 6057|  33.9k|    PK11SymKey *unwrappedWrappingKey = NULL;
 6058|  33.9k|    PK11SymKey **pSymWrapKey;
 6059|  33.9k|    CK_MECHANISM_TYPE asymWrapMechanism = CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|  33.9k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
 6060|  33.9k|    int length;
 6061|  33.9k|    unsigned int wrapMechIndex;
 6062|  33.9k|    unsigned int wrapKeyIndex;
 6063|  33.9k|    SECStatus rv;
 6064|  33.9k|    SECItem wrappedKey;
 6065|  33.9k|    SSLWrappedSymWrappingKey wswk;
 6066|  33.9k|    PK11SymKey *Ks = NULL;
 6067|  33.9k|    SECKEYPublicKey *pubWrapKey = NULL;
 6068|  33.9k|    SECKEYPrivateKey *privWrapKey = NULL;
 6069|  33.9k|    ECCWrappedKeyInfo *ecWrapped;
 6070|  33.9k|    const sslServerCert *serverCert = ss->sec.serverCert;
 6071|       |
 6072|  33.9k|    PORT_Assert(serverCert);
  ------------------
  |  |  120|  33.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  33.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 33.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6073|  33.9k|    PORT_Assert(serverCert->serverKeyPair);
  ------------------
  |  |  120|  33.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  33.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 33.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6074|  33.9k|    PORT_Assert(serverCert->serverKeyPair->privKey);
  ------------------
  |  |  120|  33.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  33.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 33.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6075|  33.9k|    PORT_Assert(serverCert->serverKeyPair->pubKey);
  ------------------
  |  |  120|  33.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  33.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 33.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6076|  33.9k|    if (!serverCert || !serverCert->serverKeyPair ||
  ------------------
  |  Branch (6076:9): [True: 0, False: 33.9k]
  |  Branch (6076:24): [True: 0, False: 33.9k]
  ------------------
 6077|  33.9k|        !serverCert->serverKeyPair->privKey ||
  ------------------
  |  Branch (6077:9): [True: 0, False: 33.9k]
  ------------------
 6078|  33.9k|        !serverCert->serverKeyPair->pubKey) {
  ------------------
  |  Branch (6078:9): [True: 0, False: 33.9k]
  ------------------
 6079|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6080|      0|        return NULL; /* hmm */
 6081|      0|    }
 6082|       |
 6083|  33.9k|    rv = ssl_FindIndexByWrapKey(serverCert, &wrapKeyIndex);
 6084|  33.9k|    if (rv != SECSuccess)
  ------------------
  |  Branch (6084:9): [True: 0, False: 33.9k]
  ------------------
 6085|      0|        return NULL; /* unusable wrapping key. */
 6086|       |
 6087|  33.9k|    rv = ssl_FindIndexByWrapMechanism(masterWrapMech, &wrapMechIndex);
 6088|  33.9k|    if (rv != SECSuccess)
  ------------------
  |  Branch (6088:9): [True: 0, False: 33.9k]
  ------------------
 6089|      0|        return NULL; /* invalid masterWrapMech. */
 6090|       |
 6091|  33.9k|    authType = ssl_wrap_key_auth_type[wrapKeyIndex];
 6092|  33.9k|    svrPrivKey = serverCert->serverKeyPair->privKey;
 6093|  33.9k|    pSymWrapKey = &symWrapKeys[wrapMechIndex].symWrapKey[wrapKeyIndex];
 6094|       |
 6095|  33.9k|    ssl_InitSessionCacheLocks(PR_TRUE);
  ------------------
  |  |  437|  33.9k|#define PR_TRUE 1
  ------------------
 6096|       |
 6097|  33.9k|    PZ_Lock(symWrapKeysLock);
  ------------------
  |  |  245|  33.9k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
 6098|       |
 6099|  33.9k|    unwrappedWrappingKey = *pSymWrapKey;
 6100|  33.9k|    if (unwrappedWrappingKey != NULL) {
  ------------------
  |  Branch (6100:9): [True: 33.9k, False: 2]
  ------------------
 6101|  33.9k|        if (PK11_VerifyKeyOK(unwrappedWrappingKey)) {
  ------------------
  |  Branch (6101:13): [True: 33.9k, False: 0]
  ------------------
 6102|  33.9k|            unwrappedWrappingKey = PK11_ReferenceSymKey(unwrappedWrappingKey);
 6103|  33.9k|            goto done;
 6104|  33.9k|        }
 6105|       |        /* slot series has changed, so this key is no good any more. */
 6106|      0|        PK11_FreeSymKey(unwrappedWrappingKey);
 6107|      0|        *pSymWrapKey = unwrappedWrappingKey = NULL;
 6108|      0|    }
 6109|       |
 6110|       |    /* Try to get wrapped SymWrapping key out of the (disk) cache. */
 6111|       |    /* Following call fills in wswk on success. */
 6112|      2|    rv = ssl_GetWrappingKey(wrapMechIndex, wrapKeyIndex, &wswk);
 6113|      2|    if (rv == SECSuccess) {
  ------------------
  |  Branch (6113:9): [True: 0, False: 2]
  ------------------
 6114|       |        /* found the wrapped sym wrapping key on disk. */
 6115|      0|        unwrappedWrappingKey =
 6116|      0|            ssl_UnwrapSymWrappingKey(&wswk, svrPrivKey, wrapKeyIndex,
 6117|      0|                                     masterWrapMech, pwArg);
 6118|      0|        if (unwrappedWrappingKey) {
  ------------------
  |  Branch (6118:13): [True: 0, False: 0]
  ------------------
 6119|      0|            goto install;
 6120|      0|        }
 6121|      0|    }
 6122|       |
 6123|      2|    if (!masterSecretSlot) /* caller doesn't want to create a new one. */
  ------------------
  |  Branch (6123:9): [True: 0, False: 2]
  ------------------
 6124|      0|        goto loser;
 6125|       |
 6126|      2|    length = PK11_GetBestKeyLength(masterSecretSlot, masterWrapMech);
 6127|       |    /* Zero length means fixed key length algorithm, or error.
 6128|       |     * It's ambiguous.
 6129|       |     */
 6130|      2|    unwrappedWrappingKey = PK11_KeyGen(masterSecretSlot, masterWrapMech, NULL,
 6131|      2|                                       length, pwArg);
 6132|      2|    if (!unwrappedWrappingKey) {
  ------------------
  |  Branch (6132:9): [True: 0, False: 2]
  ------------------
 6133|      0|        goto loser;
 6134|      0|    }
 6135|       |
 6136|       |    /* Prepare the buffer to receive the wrappedWrappingKey,
 6137|       |     * the symmetric wrapping key wrapped using the server's pub key.
 6138|       |     */
 6139|      2|    PORT_Memset(&wswk, 0, sizeof wswk); /* eliminate UMRs. */
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 6140|       |
 6141|      2|    svrPubKey = serverCert->serverKeyPair->pubKey;
 6142|      2|    wrappedKey.type = siBuffer;
 6143|      2|    wrappedKey.len = SECKEY_PublicKeyStrength(svrPubKey);
 6144|      2|    wrappedKey.data = wswk.wrappedSymmetricWrappingkey;
 6145|       |
 6146|      2|    PORT_Assert(wrappedKey.len <= sizeof wswk.wrappedSymmetricWrappingkey);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6147|      2|    if (wrappedKey.len > sizeof wswk.wrappedSymmetricWrappingkey)
  ------------------
  |  Branch (6147:9): [True: 0, False: 2]
  ------------------
 6148|      0|        goto loser;
 6149|       |
 6150|       |    /* wrap symmetric wrapping key in server's public key. */
 6151|      2|    switch (authType) {
 6152|      1|        case ssl_auth_rsa_decrypt:
  ------------------
  |  Branch (6152:9): [True: 1, False: 1]
  ------------------
 6153|      1|        case ssl_auth_rsa_sign: /* bad: see Bug 1248320 */
  ------------------
  |  Branch (6153:9): [True: 0, False: 2]
  ------------------
 6154|      1|        case ssl_auth_rsa_pss:
  ------------------
  |  Branch (6154:9): [True: 0, False: 2]
  ------------------
 6155|      1|            asymWrapMechanism = CKM_RSA_PKCS;
  ------------------
  |  |  720|      1|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
 6156|      1|            rv = PK11_PubWrapSymKey(asymWrapMechanism, svrPubKey,
 6157|      1|                                    unwrappedWrappingKey, &wrappedKey);
 6158|      1|            break;
 6159|       |
 6160|      1|        case ssl_auth_ecdsa:
  ------------------
  |  Branch (6160:9): [True: 1, False: 1]
  ------------------
 6161|      1|        case ssl_auth_ecdh_rsa:
  ------------------
  |  Branch (6161:9): [True: 0, False: 2]
  ------------------
 6162|      1|        case ssl_auth_ecdh_ecdsa:
  ------------------
  |  Branch (6162:9): [True: 0, False: 2]
  ------------------
 6163|       |            /*
 6164|       |             * We generate an ephemeral EC key pair. Perform an ECDH
 6165|       |             * computation involving this ephemeral EC public key and
 6166|       |             * the SSL server's (long-term) EC private key. The resulting
 6167|       |             * shared secret is treated in the same way as Fortezza's Ks,
 6168|       |             * i.e., it is used to wrap the wrapping key. To facilitate
 6169|       |             * unwrapping in ssl_UnwrapWrappingKey, we also store all
 6170|       |             * relevant info about the ephemeral EC public key in
 6171|       |             * wswk.wrappedSymmetricWrappingkey and lay it out as
 6172|       |             * described in the ECCWrappedKeyInfo structure.
 6173|       |             */
 6174|      1|            PORT_Assert(SECKEY_GetPublicKeyType(svrPubKey) == ecKey);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6175|      1|            if (SECKEY_GetPublicKeyType(svrPubKey) != ecKey) {
  ------------------
  |  Branch (6175:17): [True: 0, False: 1]
  ------------------
 6176|       |                /* something is wrong in sslsecur.c if this isn't an ecKey */
 6177|      0|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6178|      0|                rv = SECFailure;
 6179|      0|                goto ec_cleanup;
 6180|      0|            }
 6181|       |
 6182|      1|            privWrapKey = SECKEY_CreateECPrivateKey(
 6183|      1|                &svrPubKey->u.ec.DEREncodedParams, &pubWrapKey, NULL);
 6184|      1|            if ((privWrapKey == NULL) || (pubWrapKey == NULL)) {
  ------------------
  |  Branch (6184:17): [True: 0, False: 1]
  |  Branch (6184:42): [True: 0, False: 1]
  ------------------
 6185|      0|                rv = SECFailure;
 6186|      0|                goto ec_cleanup;
 6187|      0|            }
 6188|       |
 6189|       |            /* Set the key size in bits */
 6190|      1|            if (pubWrapKey->u.ec.size == 0) {
  ------------------
  |  Branch (6190:17): [True: 1, False: 0]
  ------------------
 6191|      1|                pubWrapKey->u.ec.size = SECKEY_PublicKeyStrengthInBits(svrPubKey);
 6192|      1|            }
 6193|       |
 6194|      1|            PORT_Assert(pubWrapKey->u.ec.DEREncodedParams.len +
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6195|      1|                            pubWrapKey->u.ec.publicValue.len <
 6196|      1|                        MAX_EC_WRAPPED_KEY_BUFLEN);
 6197|      1|            if (pubWrapKey->u.ec.DEREncodedParams.len +
  ------------------
  |  Branch (6197:17): [True: 0, False: 1]
  ------------------
 6198|      1|                    pubWrapKey->u.ec.publicValue.len >=
 6199|      1|                MAX_EC_WRAPPED_KEY_BUFLEN) {
  ------------------
  |  |  424|      1|#define MAX_EC_WRAPPED_KEY_BUFLEN 504
  ------------------
 6200|      0|                PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6201|      0|                rv = SECFailure;
 6202|      0|                goto ec_cleanup;
 6203|      0|            }
 6204|       |
 6205|       |            /* Derive Ks using ECDH */
 6206|      1|            Ks = PK11_PubDeriveWithKDF(svrPrivKey, pubWrapKey, PR_FALSE, NULL,
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 6207|      1|                                       NULL, CKM_ECDH1_DERIVE, masterWrapMech,
  ------------------
  |  | 1086|      1|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
 6208|      1|                                       CKA_DERIVE, 0, CKD_NULL, NULL, NULL);
  ------------------
  |  |  555|      1|#define CKA_DERIVE 0x0000010CUL
  ------------------
                                                     CKA_DERIVE, 0, CKD_NULL, NULL, NULL);
  ------------------
  |  | 1702|      1|#define CKD_NULL 0x00000001UL
  ------------------
 6209|      1|            if (Ks == NULL) {
  ------------------
  |  Branch (6209:17): [True: 0, False: 1]
  ------------------
 6210|      0|                rv = SECFailure;
 6211|      0|                goto ec_cleanup;
 6212|      0|            }
 6213|       |
 6214|      1|            ecWrapped = (ECCWrappedKeyInfo *)(wswk.wrappedSymmetricWrappingkey);
 6215|      1|            ecWrapped->size = pubWrapKey->u.ec.size;
 6216|      1|            ecWrapped->encodedParamLen = pubWrapKey->u.ec.DEREncodedParams.len;
 6217|      1|            PORT_Memcpy(ecWrapped->var, pubWrapKey->u.ec.DEREncodedParams.data,
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
 6218|      1|                        pubWrapKey->u.ec.DEREncodedParams.len);
 6219|       |
 6220|      1|            ecWrapped->pubValueLen = pubWrapKey->u.ec.publicValue.len;
 6221|      1|            PORT_Memcpy(ecWrapped->var + ecWrapped->encodedParamLen,
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
 6222|      1|                        pubWrapKey->u.ec.publicValue.data,
 6223|      1|                        pubWrapKey->u.ec.publicValue.len);
 6224|       |
 6225|      1|            wrappedKey.len = MAX_EC_WRAPPED_KEY_BUFLEN -
  ------------------
  |  |  424|      1|#define MAX_EC_WRAPPED_KEY_BUFLEN 504
  ------------------
 6226|      1|                             (ecWrapped->encodedParamLen + ecWrapped->pubValueLen);
 6227|      1|            wrappedKey.data = ecWrapped->var + ecWrapped->encodedParamLen +
 6228|      1|                              ecWrapped->pubValueLen;
 6229|       |
 6230|       |            /* wrap symmetricWrapping key with the local Ks */
 6231|      1|            rv = PK11_WrapSymKey(masterWrapMech, NULL, Ks,
 6232|      1|                                 unwrappedWrappingKey, &wrappedKey);
 6233|       |
 6234|      1|            if (rv != SECSuccess) {
  ------------------
  |  Branch (6234:17): [True: 0, False: 1]
  ------------------
 6235|      0|                goto ec_cleanup;
 6236|      0|            }
 6237|       |
 6238|       |            /* Write down the length of wrapped key in the buffer
 6239|       |             * wswk.wrappedSymmetricWrappingkey at the appropriate offset
 6240|       |             */
 6241|      1|            ecWrapped->wrappedKeyLen = wrappedKey.len;
 6242|       |
 6243|      1|        ec_cleanup:
 6244|      1|            if (privWrapKey)
  ------------------
  |  Branch (6244:17): [True: 1, False: 0]
  ------------------
 6245|      1|                SECKEY_DestroyPrivateKey(privWrapKey);
 6246|      1|            if (pubWrapKey)
  ------------------
  |  Branch (6246:17): [True: 1, False: 0]
  ------------------
 6247|      1|                SECKEY_DestroyPublicKey(pubWrapKey);
 6248|      1|            if (Ks)
  ------------------
  |  Branch (6248:17): [True: 1, False: 0]
  ------------------
 6249|      1|                PK11_FreeSymKey(Ks);
 6250|      1|            asymWrapMechanism = masterWrapMech;
 6251|      1|            break;
 6252|       |
 6253|      0|        default:
  ------------------
  |  Branch (6253:9): [True: 0, False: 2]
  ------------------
 6254|      0|            rv = SECFailure;
 6255|      0|            break;
 6256|      2|    }
 6257|       |
 6258|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6258:9): [True: 0, False: 2]
  ------------------
 6259|      0|        ssl_MapLowLevelError(SSL_ERROR_CLIENT_KEY_EXCHANGE_FAILURE);
 6260|      0|        goto loser;
 6261|      0|    }
 6262|       |
 6263|      2|    PORT_Assert(asymWrapMechanism != CKM_INVALID_MECHANISM);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6264|       |
 6265|      2|    wswk.symWrapMechanism = masterWrapMech;
 6266|      2|    wswk.asymWrapMechanism = asymWrapMechanism;
 6267|      2|    wswk.wrapMechIndex = wrapMechIndex;
 6268|      2|    wswk.wrapKeyIndex = wrapKeyIndex;
 6269|      2|    wswk.wrappedSymKeyLen = wrappedKey.len;
 6270|       |
 6271|       |    /* put it on disk. */
 6272|       |    /* If the wrapping key for this KEA type has already been set,
 6273|       |     * then abandon the value we just computed and
 6274|       |     * use the one we got from the disk.
 6275|       |     */
 6276|      2|    rv = ssl_SetWrappingKey(&wswk);
 6277|      2|    if (rv == SECSuccess) {
  ------------------
  |  Branch (6277:9): [True: 0, False: 2]
  ------------------
 6278|       |        /* somebody beat us to it.  The original contents of our wswk
 6279|       |         * has been replaced with the content on disk.  Now, discard
 6280|       |         * the key we just created and unwrap this new one.
 6281|       |         */
 6282|      0|        PK11_FreeSymKey(unwrappedWrappingKey);
 6283|       |
 6284|      0|        unwrappedWrappingKey =
 6285|      0|            ssl_UnwrapSymWrappingKey(&wswk, svrPrivKey, wrapKeyIndex,
 6286|      0|                                     masterWrapMech, pwArg);
 6287|      0|    }
 6288|       |
 6289|      2|install:
 6290|      2|    if (unwrappedWrappingKey) {
  ------------------
  |  Branch (6290:9): [True: 2, False: 0]
  ------------------
 6291|      2|        *pSymWrapKey = PK11_ReferenceSymKey(unwrappedWrappingKey);
 6292|      2|    }
 6293|       |
 6294|      2|loser:
 6295|  33.9k|done:
 6296|  33.9k|    PZ_Unlock(symWrapKeysLock);
  ------------------
  |  |  246|  33.9k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
 6297|  33.9k|    return unwrappedWrappingKey;
 6298|      2|}
ssl_AppendPaddedDHKeyShare:
 6414|  29.0k|{
 6415|  29.0k|    SECStatus rv;
 6416|  29.0k|    unsigned int pad = pubKey->u.dh.prime.len - pubKey->u.dh.publicValue.len;
 6417|       |
 6418|  29.0k|    if (appendLength) {
  ------------------
  |  Branch (6418:9): [True: 28.5k, False: 545]
  ------------------
 6419|  28.5k|        rv = sslBuffer_AppendNumber(buf, pubKey->u.dh.prime.len, 2);
 6420|  28.5k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (6420:13): [True: 0, False: 28.5k]
  ------------------
 6421|      0|            return rv;
 6422|      0|        }
 6423|  28.5k|    }
 6424|  29.3k|    while (pad) {
  ------------------
  |  Branch (6424:12): [True: 309, False: 29.0k]
  ------------------
 6425|    309|        rv = sslBuffer_AppendNumber(buf, 0, 1);
 6426|    309|        if (rv != SECSuccess) {
  ------------------
  |  Branch (6426:13): [True: 0, False: 309]
  ------------------
 6427|      0|            return rv;
 6428|      0|        }
 6429|    309|        --pad;
 6430|    309|    }
 6431|  29.0k|    rv = sslBuffer_Append(buf, pubKey->u.dh.publicValue.data,
 6432|  29.0k|                          pubKey->u.dh.publicValue.len);
 6433|  29.0k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6433:9): [True: 0, False: 29.0k]
  ------------------
 6434|      0|        return rv;
 6435|      0|    }
 6436|  29.0k|    return SECSuccess;
 6437|  29.0k|}
ssl_CanUseSignatureScheme:
 6611|  25.9k|{
 6612|  25.9k|    SSLHashType hashType;
 6613|  25.9k|    unsigned int i;
 6614|       |
 6615|       |    /* Skip RSA-PSS schemes when the certificate's private key slot does
 6616|       |     * not support this signature mechanism. */
 6617|  25.9k|    if (ssl_IsRsaPssSignatureScheme(scheme) && !slotDoesPss) {
  ------------------
  |  Branch (6617:9): [True: 15.7k, False: 10.1k]
  |  Branch (6617:48): [True: 0, False: 15.7k]
  ------------------
 6618|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6619|      0|    }
 6620|       |
 6621|  25.9k|    hashType = ssl_SignatureSchemeToHashType(scheme);
 6622|  25.9k|    if (requireSha1 && (hashType != ssl_hash_sha1)) {
  ------------------
  |  Branch (6622:9): [True: 0, False: 25.9k]
  |  Branch (6622:24): [True: 0, False: 0]
  ------------------
 6623|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6624|      0|    }
 6625|       |
 6626|  25.9k|    if (!ssl_SchemePolicyOK(scheme, kSSLSigSchemePolicy)) {
  ------------------
  |  Branch (6626:9): [True: 0, False: 25.9k]
  ------------------
 6627|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6628|      0|    }
 6629|       |
 6630|  80.7k|    for (i = 0; i < peerSchemeCount; i++) {
  ------------------
  |  Branch (6630:17): [True: 63.1k, False: 17.5k]
  ------------------
 6631|  63.1k|        if (peerSchemes[i] == scheme) {
  ------------------
  |  Branch (6631:13): [True: 8.37k, False: 54.7k]
  ------------------
 6632|  8.37k|            return PR_TRUE;
  ------------------
  |  |  437|  8.37k|#define PR_TRUE 1
  ------------------
 6633|  8.37k|        }
 6634|  63.1k|    }
 6635|  17.5k|    return PR_FALSE;
  ------------------
  |  |  438|  17.5k|#define PR_FALSE 0
  ------------------
 6636|  25.9k|}
ssl_PrivateKeySupportsRsaPss:
 6641|  9.54k|{
 6642|  9.54k|    PK11SlotInfo *slot = NULL;
 6643|  9.54k|    if (privKey) {
  ------------------
  |  Branch (6643:9): [True: 9.54k, False: 0]
  ------------------
 6644|  9.54k|        slot = PK11_GetSlotFromPrivateKey(privKey);
 6645|  9.54k|    } else {
 6646|      0|        CK_OBJECT_HANDLE certID = PK11_FindObjectForCert(cert, pwarg, &slot);
 6647|      0|        if (certID == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|      0|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (6647:13): [True: 0, False: 0]
  ------------------
 6648|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6649|      0|            return SECFailure;
 6650|      0|        }
 6651|      0|    }
 6652|  9.54k|    if (!slot) {
  ------------------
  |  Branch (6652:9): [True: 0, False: 9.54k]
  ------------------
 6653|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6654|      0|        return SECFailure;
 6655|      0|    }
 6656|  9.54k|    *supportsRsaPss = PK11_DoesMechanism(slot, auth_alg_defs[ssl_auth_rsa_pss]);
 6657|  9.54k|    PK11_FreeSlot(slot);
 6658|  9.54k|    return SECSuccess;
 6659|  9.54k|}
ssl_PickSignatureScheme:
 6670|  9.54k|{
 6671|  9.54k|    unsigned int i;
 6672|  9.54k|    PRBool doesRsaPss;
 6673|  9.54k|    PRBool isTLS13 = ss->version >= SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|  9.54k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
 6674|  9.54k|    SECStatus rv;
 6675|  9.54k|    SSLSignatureScheme scheme;
 6676|  9.54k|    SECOidTag spkiOid;
 6677|       |
 6678|       |    /* We can't require SHA-1 in TLS 1.3. */
 6679|  9.54k|    PORT_Assert(!(requireSha1 && isTLS13));
  ------------------
  |  |  120|  9.54k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.54k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 9.54k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6680|  9.54k|    if (!pubKey || !cert) {
  ------------------
  |  Branch (6680:9): [True: 0, False: 9.54k]
  |  Branch (6680:20): [True: 0, False: 9.54k]
  ------------------
 6681|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6682|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6683|      0|        return SECFailure;
 6684|      0|    }
 6685|  9.54k|    rv = ssl_PrivateKeySupportsRsaPss(privKey, cert, ss->pkcs11PinArg,
 6686|  9.54k|                                      &doesRsaPss);
 6687|  9.54k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6687:9): [True: 0, False: 9.54k]
  ------------------
 6688|      0|        return SECFailure;
 6689|      0|    }
 6690|       |
 6691|       |    /* If the certificate SPKI indicates a single scheme, don't search. */
 6692|  9.54k|    rv = ssl_SignatureSchemeFromSpki(&cert->subjectPublicKeyInfo,
 6693|  9.54k|                                     isTLS13, &scheme);
 6694|  9.54k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6694:9): [True: 0, False: 9.54k]
  ------------------
 6695|      0|        return SECFailure;
 6696|      0|    }
 6697|  9.54k|    if (scheme != ssl_sig_none) {
  ------------------
  |  Branch (6697:9): [True: 1.24k, False: 8.29k]
  ------------------
 6698|  1.24k|        if (!ssl_SignatureSchemeEnabled(ss, scheme) ||
  ------------------
  |  Branch (6698:13): [True: 0, False: 1.24k]
  ------------------
 6699|  1.24k|            !ssl_CanUseSignatureScheme(scheme, peerSchemes, peerSchemeCount,
  ------------------
  |  Branch (6699:13): [True: 1.14k, False: 104]
  ------------------
 6700|  1.24k|                                       requireSha1, doesRsaPss)) {
 6701|  1.14k|            PORT_SetError(SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|  1.14k|#define PORT_SetError PORT_SetError_Util
  ------------------
 6702|  1.14k|            return SECFailure;
 6703|  1.14k|        }
 6704|    104|        *schemePtr = scheme;
 6705|    104|        return SECSuccess;
 6706|  1.24k|    }
 6707|       |
 6708|  8.29k|    spkiOid = SECOID_GetAlgorithmTag(&cert->subjectPublicKeyInfo.algorithm);
  ------------------
  |  |  119|  8.29k|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
 6709|  8.29k|    if (spkiOid == SEC_OID_UNKNOWN) {
  ------------------
  |  Branch (6709:9): [True: 0, False: 8.29k]
  ------------------
 6710|      0|        return SECFailure;
 6711|      0|    }
 6712|       |
 6713|       |    /* Now we have to search based on the key type. Go through our preferred
 6714|       |     * schemes in order and find the first that can be used. */
 6715|  49.1k|    for (i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (6715:17): [True: 49.0k, False: 23]
  ------------------
 6716|  49.0k|        scheme = ss->ssl3.signatureSchemes[i];
 6717|       |
 6718|  49.0k|        if (ssl_SignatureSchemeValid(scheme, spkiOid, isTLS13) &&
  ------------------
  |  Branch (6718:13): [True: 24.7k, False: 24.3k]
  ------------------
 6719|  49.0k|            ssl_CanUseSignatureScheme(scheme, peerSchemes, peerSchemeCount,
  ------------------
  |  Branch (6719:13): [True: 8.27k, False: 16.4k]
  ------------------
 6720|  24.7k|                                      requireSha1, doesRsaPss)) {
 6721|  8.27k|            *schemePtr = scheme;
 6722|  8.27k|            return SECSuccess;
 6723|  8.27k|        }
 6724|  49.0k|    }
 6725|       |
 6726|     23|    PORT_SetError(SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|     23|#define PORT_SetError PORT_SetError_Util
  ------------------
 6727|     23|    return SECFailure;
 6728|  8.29k|}
ssl3_SetupCipherSuite:
 6920|  60.2k|{
 6921|  60.2k|    ss->ssl3.hs.suite_def = ssl_LookupCipherSuiteDef(ss->ssl3.hs.cipher_suite);
 6922|  60.2k|    if (!ss->ssl3.hs.suite_def) {
  ------------------
  |  Branch (6922:9): [True: 0, False: 60.2k]
  ------------------
 6923|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6924|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6925|      0|        return SECFailure;
 6926|      0|    }
 6927|       |
 6928|  60.2k|    ss->ssl3.hs.kea_def = &kea_defs[ss->ssl3.hs.suite_def->key_exchange_alg];
 6929|  60.2k|    ss->ssl3.hs.preliminaryInfo |= ssl_preinfo_cipher_suite;
  ------------------
  |  |  393|  60.2k|#define ssl_preinfo_cipher_suite (1U << 1)
  ------------------
 6930|       |
 6931|  60.2k|    if (!initHashes) {
  ------------------
  |  Branch (6931:9): [True: 1.53k, False: 58.7k]
  ------------------
 6932|  1.53k|        return SECSuccess;
 6933|  1.53k|    }
 6934|       |    /* Now we have a cipher suite, initialize the handshake hashes. */
 6935|  58.7k|    return ssl3_InitHandshakeHashes(ss);
 6936|  60.2k|}
ssl_ParseSignatureSchemes:
 7853|  8.73k|{
 7854|  8.73k|    SECStatus rv;
 7855|  8.73k|    SECItem buf;
 7856|  8.73k|    SSLSignatureScheme *schemes = NULL;
 7857|  8.73k|    unsigned int numSupported = 0;
 7858|  8.73k|    unsigned int numRemaining = 0;
 7859|  8.73k|    unsigned int max;
 7860|       |
 7861|  8.73k|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &buf, 2, b, len);
 7862|  8.73k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (7862:9): [True: 8, False: 8.72k]
  ------------------
 7863|      8|        return SECFailure;
 7864|      8|    }
 7865|       |    /* An odd-length value is invalid. */
 7866|  8.72k|    if ((buf.len & 1) != 0) {
  ------------------
  |  Branch (7866:9): [True: 1, False: 8.72k]
  ------------------
 7867|      1|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 7868|      1|        return SECFailure;
 7869|      1|    }
 7870|       |
 7871|       |    /* Let the caller decide whether to alert here. */
 7872|  8.72k|    if (buf.len == 0) {
  ------------------
  |  Branch (7872:9): [True: 2, False: 8.72k]
  ------------------
 7873|      2|        goto done;
 7874|      2|    }
 7875|       |
 7876|       |    /* Limit the number of schemes we read. */
 7877|  8.72k|    numRemaining = buf.len / 2;
 7878|  8.72k|    max = PR_MIN(numRemaining, MAX_SIGNATURE_SCHEMES);
  ------------------
  |  |  158|  8.72k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 8.66k, False: 63]
  |  |  ------------------
  ------------------
 7879|       |
 7880|  8.72k|    if (arena) {
  ------------------
  |  Branch (7880:9): [True: 0, False: 8.72k]
  ------------------
 7881|      0|        schemes = PORT_ArenaZNewArray(arena, SSLSignatureScheme, max);
  ------------------
  |  |  163|      0|    (type *)PORT_ArenaZAlloc(poolp, sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   59|      0|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  |  |  ------------------
  ------------------
 7882|  8.72k|    } else {
 7883|  8.72k|        schemes = PORT_ZNewArray(SSLSignatureScheme, max);
  ------------------
  |  |  159|  8.72k|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|  8.72k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 7884|  8.72k|    }
 7885|  8.72k|    if (!schemes) {
  ------------------
  |  Branch (7885:9): [True: 0, False: 8.72k]
  ------------------
 7886|      0|        ssl3_ExtSendAlert(ss, alert_fatal, internal_error);
 7887|      0|        return SECFailure;
 7888|      0|    }
 7889|       |
 7890|  57.4k|    for (; numRemaining && numSupported < MAX_SIGNATURE_SCHEMES; --numRemaining) {
  ------------------
  |  |  250|  48.7k|#define MAX_SIGNATURE_SCHEMES 18
  ------------------
  |  Branch (7890:12): [True: 48.7k, False: 8.72k]
  |  Branch (7890:28): [True: 48.7k, False: 0]
  ------------------
 7891|  48.7k|        PRUint32 tmp;
 7892|  48.7k|        rv = ssl3_ExtConsumeHandshakeNumber(ss, &tmp, 2, &buf.data, &buf.len);
 7893|  48.7k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (7893:13): [True: 0, False: 48.7k]
  ------------------
 7894|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7895|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 7896|      0|            return SECFailure;
 7897|      0|        }
 7898|  48.7k|        if (ssl_SignatureSchemeValid((SSLSignatureScheme)tmp, SEC_OID_UNKNOWN,
  ------------------
  |  Branch (7898:13): [True: 25.3k, False: 23.3k]
  ------------------
 7899|  48.7k|                                     (PRBool)ss->version >= SSL_LIBRARY_VERSION_TLS_1_3)) {
  ------------------
  |  |   21|  48.7k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
 7900|  25.3k|            ;
 7901|  25.3k|            schemes[numSupported++] = (SSLSignatureScheme)tmp;
 7902|  25.3k|        }
 7903|  48.7k|    }
 7904|       |
 7905|  8.72k|    if (!numSupported) {
  ------------------
  |  Branch (7905:9): [True: 73, False: 8.65k]
  ------------------
 7906|     73|        if (!arena) {
  ------------------
  |  Branch (7906:13): [True: 73, False: 0]
  ------------------
 7907|     73|            PORT_Free(schemes);
  ------------------
  |  |   60|     73|#define PORT_Free PORT_Free_Util
  ------------------
 7908|     73|        }
 7909|     73|        schemes = NULL;
 7910|     73|    }
 7911|       |
 7912|  8.72k|done:
 7913|  8.72k|    *schemesOut = schemes;
 7914|  8.72k|    *numSchemesOut = numSupported;
 7915|  8.72k|    return SECSuccess;
 7916|  8.72k|}
ssl3_NewSessionID:
 8482|  60.1k|{
 8483|  60.1k|    sslSessionID *sid;
 8484|       |
 8485|  60.1k|    sid = PORT_ZNew(sslSessionID);
  ------------------
  |  |  148|  60.1k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  60.1k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 8486|  60.1k|    if (sid == NULL)
  ------------------
  |  Branch (8486:9): [True: 0, False: 60.1k]
  ------------------
 8487|      0|        return sid;
 8488|       |
 8489|  60.1k|    if (is_server) {
  ------------------
  |  Branch (8489:9): [True: 60.1k, False: 0]
  ------------------
 8490|  60.1k|        const SECItem *srvName;
 8491|  60.1k|        SECStatus rv = SECSuccess;
 8492|       |
 8493|  60.1k|        ssl_GetSpecReadLock(ss); /********************************/
  ------------------
  |  | 1422|  60.1k|    {                                           \
  |  | 1423|  60.1k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 30.8k, False: 29.3k]
  |  |  ------------------
  |  | 1424|  60.1k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|  30.8k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|  60.1k|    }
  ------------------
 8494|  60.1k|        srvName = &ss->ssl3.hs.srvVirtName;
 8495|  60.1k|        if (srvName->len && srvName->data) {
  ------------------
  |  Branch (8495:13): [True: 0, False: 60.1k]
  |  Branch (8495:29): [True: 0, False: 0]
  ------------------
 8496|      0|            rv = SECITEM_CopyItem(NULL, &sid->u.ssl3.srvName, srvName);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 8497|      0|        }
 8498|  60.1k|        ssl_ReleaseSpecReadLock(ss); /************************************/
  ------------------
  |  | 1427|  60.1k|    {                                             \
  |  | 1428|  60.1k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 30.8k, False: 29.3k]
  |  |  ------------------
  |  | 1429|  60.1k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|  30.8k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|  60.1k|    }
  ------------------
 8499|  60.1k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (8499:13): [True: 0, False: 60.1k]
  ------------------
 8500|      0|            PORT_Free(sid);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 8501|      0|            return NULL;
 8502|      0|        }
 8503|  60.1k|    }
 8504|  60.1k|    sid->peerID = (ss->peerID == NULL) ? NULL : PORT_Strdup(ss->peerID);
  ------------------
  |  |   69|      0|#define PORT_Strdup PORT_Strdup_Util
  ------------------
  |  Branch (8504:19): [True: 60.1k, False: 0]
  ------------------
 8505|  60.1k|    sid->urlSvrName = (ss->url == NULL) ? NULL : PORT_Strdup(ss->url);
  ------------------
  |  |   69|  60.1k|#define PORT_Strdup PORT_Strdup_Util
  ------------------
  |  Branch (8505:23): [True: 0, False: 60.1k]
  ------------------
 8506|  60.1k|    sid->addr = ss->sec.ci.peer;
 8507|  60.1k|    sid->port = ss->sec.ci.port;
 8508|  60.1k|    sid->references = 1;
 8509|  60.1k|    sid->cached = never_cached;
 8510|  60.1k|    sid->version = ss->version;
 8511|  60.1k|    sid->sigScheme = ssl_sig_none;
 8512|       |
 8513|  60.1k|    sid->u.ssl3.keys.resumable = PR_TRUE;
  ------------------
  |  |  437|  60.1k|#define PR_TRUE 1
  ------------------
 8514|  60.1k|    sid->u.ssl3.policy = SSL_ALLOWED;
  ------------------
  |  |  700|  60.1k|#define SSL_ALLOWED 1
  ------------------
 8515|  60.1k|    sid->u.ssl3.keys.extendedMasterSecretUsed = PR_FALSE;
  ------------------
  |  |  438|  60.1k|#define PR_FALSE 0
  ------------------
 8516|       |
 8517|  60.1k|    if (is_server) {
  ------------------
  |  Branch (8517:9): [True: 60.1k, False: 0]
  ------------------
 8518|  60.1k|        SECStatus rv;
 8519|  60.1k|        int pid = SSL_GETPID();
  ------------------
  |  | 2059|  60.1k|#define SSL_GETPID getpid
  ------------------
 8520|       |
 8521|  60.1k|        sid->u.ssl3.sessionIDLength = SSL3_SESSIONID_BYTES;
  ------------------
  |  |  107|  60.1k|#define SSL3_SESSIONID_BYTES 32
  ------------------
 8522|  60.1k|        sid->u.ssl3.sessionID[0] = (pid >> 8) & 0xff;
 8523|  60.1k|        sid->u.ssl3.sessionID[1] = pid & 0xff;
 8524|  60.1k|        rv = PK11_GenerateRandom(sid->u.ssl3.sessionID + 2,
 8525|  60.1k|                                 SSL3_SESSIONID_BYTES - 2);
  ------------------
  |  |  107|  60.1k|#define SSL3_SESSIONID_BYTES 32
  ------------------
 8526|  60.1k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (8526:13): [True: 0, False: 60.1k]
  ------------------
 8527|      0|            ssl_FreeSID(sid);
 8528|      0|            ssl_MapLowLevelError(SSL_ERROR_GENERATE_RANDOM_FAILURE);
 8529|      0|            return NULL;
 8530|      0|        }
 8531|  60.1k|    }
 8532|  60.1k|    return sid;
 8533|  60.1k|}
ssl3_NegotiateCipherSuiteInner:
 8617|  60.3k|{
 8618|  60.3k|    unsigned int i;
 8619|  60.3k|    SSLVersionRange vrange = { version, version };
 8620|       |
 8621|       |    /* If we negotiated an External PSK and that PSK has a ciphersuite
 8622|       |     * configured, we need to constrain our choice. If the client does
 8623|       |     * not support it, negotiate a certificate auth suite and fall back.
 8624|       |     */
 8625|  60.3k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|   120k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (8625:9): [True: 1.54k, False: 58.8k]
  ------------------
 8626|  60.3k|        ss->xtnData.selectedPsk &&
  ------------------
  |  Branch (8626:9): [True: 0, False: 1.54k]
  ------------------
 8627|  60.3k|        ss->xtnData.selectedPsk->type == ssl_psk_external &&
  ------------------
  |  Branch (8627:9): [True: 0, False: 0]
  ------------------
 8628|  60.3k|        ss->xtnData.selectedPsk->zeroRttSuite != TLS_NULL_WITH_NULL_NULL) {
  ------------------
  |  |   76|      0|#define TLS_NULL_WITH_NULL_NULL                 0x0000
  ------------------
  |  Branch (8628:9): [True: 0, False: 0]
  ------------------
 8629|      0|        PRUint16 pskSuite = ss->xtnData.selectedPsk->zeroRttSuite;
 8630|      0|        ssl3CipherSuiteCfg *pskSuiteCfg = ssl_LookupCipherSuiteCfgMutable(pskSuite,
 8631|      0|                                                                          ss->cipherSuites);
 8632|      0|        if (ssl3_config_match(pskSuiteCfg, ss->ssl3.policy, &vrange, ss) &&
  ------------------
  |  Branch (8632:13): [True: 0, False: 0]
  ------------------
 8633|      0|            ssl3_PeerSupportsCipherSuite(suites, pskSuite)) {
  ------------------
  |  Branch (8633:13): [True: 0, False: 0]
  ------------------
 8634|      0|            *suitep = pskSuite;
 8635|      0|            return SECSuccess;
 8636|      0|        }
 8637|      0|    }
 8638|       |
 8639|  2.11M|    for (i = 0; i < ssl_V3_SUITES_IMPLEMENTED; i++) {
  ------------------
  |  |  245|  2.11M|#define ssl_V3_SUITES_IMPLEMENTED 71
  ------------------
  |  Branch (8639:17): [True: 2.11M, False: 89]
  ------------------
 8640|  2.11M|        ssl3CipherSuiteCfg *suite = &ss->cipherSuites[i];
 8641|  2.11M|        if (!ssl3_config_match(suite, ss->ssl3.policy, &vrange, ss)) {
  ------------------
  |  Branch (8641:13): [True: 831k, False: 1.28M]
  ------------------
 8642|   831k|            continue;
 8643|   831k|        }
 8644|  1.28M|        if (!ssl3_PeerSupportsCipherSuite(suites, suite->cipher_suite)) {
  ------------------
  |  Branch (8644:13): [True: 1.22M, False: 60.2k]
  ------------------
 8645|  1.22M|            continue;
 8646|  1.22M|        }
 8647|  60.2k|        *suitep = suite->cipher_suite;
 8648|  60.2k|        return SECSuccess;
 8649|  1.28M|    }
 8650|     89|    PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|     89|#define PORT_SetError PORT_SetError_Util
  ------------------
 8651|     89|    return SECFailure;
 8652|  60.3k|}
ssl3_NegotiateCipherSuite:
 8671|  60.3k|{
 8672|  60.3k|    PRUint16 selected;
 8673|  60.3k|    SECStatus rv;
 8674|       |
 8675|       |    /* Ensure that only valid cipher suites are enabled. */
 8676|  60.3k|    if (ssl3_config_match_init(ss) == 0) {
  ------------------
  |  Branch (8676:9): [True: 0, False: 60.3k]
  ------------------
 8677|       |        /* No configured cipher is both supported by PK11 and allowed.
 8678|       |         * This is a configuration error, so report handshake failure.*/
 8679|      0|        FATAL_ERROR(ss, PORT_GetError(), handshake_failure);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 8680|      0|        return SECFailure;
 8681|      0|    }
 8682|       |
 8683|  60.3k|    rv = ssl3_NegotiateCipherSuiteInner(ss, suites, ss->version, &selected);
 8684|  60.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8684:9): [True: 89, False: 60.2k]
  ------------------
 8685|     89|        return SECFailure;
 8686|     89|    }
 8687|       |
 8688|  60.2k|    ss->ssl3.hs.cipher_suite = selected;
 8689|  60.2k|    return ssl3_SetupCipherSuite(ss, initHashes);
 8690|  60.3k|}
ssl3_ServerCallSNICallback:
 8701|  60.2k|{
 8702|  60.2k|    int errCode = SSL_ERROR_RX_MALFORMED_CLIENT_HELLO;
 8703|  60.2k|    SSL3AlertDescription desc = illegal_parameter;
 8704|  60.2k|    int ret = 0;
 8705|       |
 8706|       |#ifdef SSL_SNI_ALLOW_NAME_CHANGE_2HS
 8707|       |#error("No longer allowed to set SSL_SNI_ALLOW_NAME_CHANGE_2HS")
 8708|       |#endif
 8709|  60.2k|    if (!ssl3_ExtensionNegotiated(ss, ssl_server_name_xtn)) {
  ------------------
  |  Branch (8709:9): [True: 60.2k, False: 0]
  ------------------
 8710|  60.2k|        if (ss->firstHsDone) {
  ------------------
  |  Branch (8710:13): [True: 52.0k, False: 8.19k]
  ------------------
 8711|       |            /* Check that we don't have the name is current spec
 8712|       |             * if this extension was not negotiated on the 2d hs. */
 8713|  52.0k|            PRBool passed = PR_TRUE;
  ------------------
  |  |  437|  52.0k|#define PR_TRUE 1
  ------------------
 8714|  52.0k|            ssl_GetSpecReadLock(ss); /*******************************/
  ------------------
  |  | 1422|  52.0k|    {                                           \
  |  | 1423|  52.0k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 26.7k, False: 25.3k]
  |  |  ------------------
  |  | 1424|  52.0k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|  26.7k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|  52.0k|    }
  ------------------
 8715|  52.0k|            if (ss->ssl3.hs.srvVirtName.data) {
  ------------------
  |  Branch (8715:17): [True: 0, False: 52.0k]
  ------------------
 8716|      0|                passed = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8717|      0|            }
 8718|  52.0k|            ssl_ReleaseSpecReadLock(ss); /***************************/
  ------------------
  |  | 1427|  52.0k|    {                                             \
  |  | 1428|  52.0k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 26.7k, False: 25.3k]
  |  |  ------------------
  |  | 1429|  52.0k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|  26.7k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|  52.0k|    }
  ------------------
 8719|  52.0k|            if (!passed) {
  ------------------
  |  Branch (8719:17): [True: 0, False: 52.0k]
  ------------------
 8720|      0|                errCode = SSL_ERROR_UNRECOGNIZED_NAME_ALERT;
 8721|      0|                desc = handshake_failure;
 8722|      0|                goto alert_loser;
 8723|      0|            }
 8724|  52.0k|        }
 8725|  60.2k|        return SECSuccess;
 8726|  60.2k|    }
 8727|       |
 8728|      0|    if (ss->sniSocketConfig)
  ------------------
  |  Branch (8728:9): [True: 0, False: 0]
  ------------------
 8729|      0|        do { /* not a loop */
 8730|      0|            PORT_Assert((ss->ssl3.hs.preliminaryInfo & ssl_preinfo_all) ==
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8731|      0|                        ssl_preinfo_all);
 8732|       |
 8733|      0|            ret = SSL_SNI_SEND_ALERT;
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
 8734|       |            /* If extension is negotiated, the len of names should > 0. */
 8735|      0|            if (ss->xtnData.sniNameArrSize) {
  ------------------
  |  Branch (8735:17): [True: 0, False: 0]
  ------------------
 8736|       |                /* Calling client callback to reconfigure the socket. */
 8737|      0|                ret = (SECStatus)(*ss->sniSocketConfig)(ss->fd,
 8738|      0|                                                        ss->xtnData.sniNameArr,
 8739|      0|                                                        ss->xtnData.sniNameArrSize,
 8740|      0|                                                        ss->sniSocketConfigArg);
 8741|      0|            }
 8742|      0|            if (ret <= SSL_SNI_SEND_ALERT) {
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
  |  Branch (8742:17): [True: 0, False: 0]
  ------------------
 8743|       |                /* Application does not know the name or was not able to
 8744|       |                 * properly reconfigure the socket. */
 8745|      0|                errCode = SSL_ERROR_UNRECOGNIZED_NAME_ALERT;
 8746|      0|                desc = unrecognized_name;
 8747|      0|                break;
 8748|      0|            } else if (ret == SSL_SNI_CURRENT_CONFIG_IS_USED) {
  ------------------
  |  |  962|      0|#define SSL_SNI_CURRENT_CONFIG_IS_USED -1
  ------------------
  |  Branch (8748:24): [True: 0, False: 0]
  ------------------
 8749|      0|                SECStatus rv = SECSuccess;
 8750|      0|                SECItem pwsNameBuf = { 0, NULL, 0 };
 8751|      0|                SECItem *pwsName = &pwsNameBuf;
 8752|      0|                SECItem *cwsName;
 8753|       |
 8754|      0|                ssl_GetSpecWriteLock(ss); /*******************************/
  ------------------
  |  | 1435|      0|    {                                            \
  |  | 1436|      0|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1437|      0|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|      0|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|      0|    }
  ------------------
 8755|      0|                cwsName = &ss->ssl3.hs.srvVirtName;
 8756|       |                /* not allow name change on the 2d HS */
 8757|      0|                if (ss->firstHsDone) {
  ------------------
  |  Branch (8757:21): [True: 0, False: 0]
  ------------------
 8758|      0|                    if (ssl3_ServerNameCompare(pwsName, cwsName)) {
  ------------------
  |  Branch (8758:25): [True: 0, False: 0]
  ------------------
 8759|      0|                        ssl_ReleaseSpecWriteLock(ss); /******************/
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 8760|      0|                        errCode = SSL_ERROR_UNRECOGNIZED_NAME_ALERT;
 8761|      0|                        desc = handshake_failure;
 8762|      0|                        ret = SSL_SNI_SEND_ALERT;
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
 8763|      0|                        break;
 8764|      0|                    }
 8765|      0|                }
 8766|      0|                if (pwsName->data) {
  ------------------
  |  Branch (8766:21): [True: 0, False: 0]
  ------------------
 8767|      0|                    SECITEM_FreeItem(pwsName, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                                  SECITEM_FreeItem(pwsName, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8768|      0|                }
 8769|      0|                if (cwsName->data) {
  ------------------
  |  Branch (8769:21): [True: 0, False: 0]
  ------------------
 8770|      0|                    rv = SECITEM_CopyItem(NULL, pwsName, cwsName);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 8771|      0|                }
 8772|      0|                ssl_ReleaseSpecWriteLock(ss); /**************************/
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 8773|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (8773:21): [True: 0, False: 0]
  ------------------
 8774|      0|                    errCode = SSL_ERROR_INTERNAL_ERROR_ALERT;
 8775|      0|                    desc = internal_error;
 8776|      0|                    ret = SSL_SNI_SEND_ALERT;
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
 8777|      0|                    break;
 8778|      0|                }
 8779|      0|            } else if ((unsigned int)ret < ss->xtnData.sniNameArrSize) {
  ------------------
  |  Branch (8779:24): [True: 0, False: 0]
  ------------------
 8780|       |                /* Application has configured new socket info. Lets check it
 8781|       |                 * and save the name. */
 8782|      0|                SECStatus rv;
 8783|      0|                SECItem *name = &ss->xtnData.sniNameArr[ret];
 8784|      0|                SECItem *pwsName;
 8785|       |
 8786|       |                /* get rid of the old name and save the newly picked. */
 8787|       |                /* This code is protected by ssl3HandshakeLock. */
 8788|      0|                ssl_GetSpecWriteLock(ss); /*******************************/
  ------------------
  |  | 1435|      0|    {                                            \
  |  | 1436|      0|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1437|      0|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|      0|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|      0|    }
  ------------------
 8789|       |                /* not allow name change on the 2d HS */
 8790|      0|                if (ss->firstHsDone) {
  ------------------
  |  Branch (8790:21): [True: 0, False: 0]
  ------------------
 8791|      0|                    SECItem *cwsName = &ss->ssl3.hs.srvVirtName;
 8792|      0|                    if (ssl3_ServerNameCompare(name, cwsName)) {
  ------------------
  |  Branch (8792:25): [True: 0, False: 0]
  ------------------
 8793|      0|                        ssl_ReleaseSpecWriteLock(ss); /******************/
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 8794|      0|                        errCode = SSL_ERROR_UNRECOGNIZED_NAME_ALERT;
 8795|      0|                        desc = handshake_failure;
 8796|      0|                        ret = SSL_SNI_SEND_ALERT;
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
 8797|      0|                        break;
 8798|      0|                    }
 8799|      0|                }
 8800|      0|                pwsName = &ss->ssl3.hs.srvVirtName;
 8801|      0|                if (pwsName->data) {
  ------------------
  |  Branch (8801:21): [True: 0, False: 0]
  ------------------
 8802|      0|                    SECITEM_FreeItem(pwsName, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                                  SECITEM_FreeItem(pwsName, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8803|      0|                }
 8804|      0|                rv = SECITEM_CopyItem(NULL, pwsName, name);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 8805|      0|                ssl_ReleaseSpecWriteLock(ss); /***************************/
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 8806|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (8806:21): [True: 0, False: 0]
  ------------------
 8807|      0|                    errCode = SSL_ERROR_INTERNAL_ERROR_ALERT;
 8808|      0|                    desc = internal_error;
 8809|      0|                    ret = SSL_SNI_SEND_ALERT;
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
 8810|      0|                    break;
 8811|      0|                }
 8812|       |                /* Need to tell the client that application has picked
 8813|       |                 * the name from the offered list and reconfigured the socket.
 8814|       |                 */
 8815|      0|                ssl3_RegisterExtensionSender(ss, &ss->xtnData, ssl_server_name_xtn,
 8816|      0|                                             ssl_SendEmptyExtension);
 8817|      0|            } else {
 8818|       |                /* Callback returned index outside of the boundary. */
 8819|      0|                PORT_Assert((unsigned int)ret < ss->xtnData.sniNameArrSize);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8820|      0|                errCode = SSL_ERROR_INTERNAL_ERROR_ALERT;
 8821|      0|                desc = internal_error;
 8822|      0|                ret = SSL_SNI_SEND_ALERT;
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
 8823|      0|                break;
 8824|      0|            }
 8825|      0|        } while (0);
  ------------------
  |  Branch (8825:18): [Folded - Ignored]
  ------------------
 8826|      0|    ssl3_FreeSniNameArray(&ss->xtnData);
 8827|      0|    if (ret <= SSL_SNI_SEND_ALERT) {
  ------------------
  |  |  963|      0|#define SSL_SNI_SEND_ALERT -2
  ------------------
  |  Branch (8827:9): [True: 0, False: 0]
  ------------------
 8828|       |        /* desc and errCode should be set. */
 8829|      0|        goto alert_loser;
 8830|      0|    }
 8831|       |
 8832|      0|    return SECSuccess;
 8833|       |
 8834|      0|alert_loser:
 8835|      0|    (void)SSL3_SendAlert(ss, alert_fatal, desc);
 8836|      0|    PORT_SetError(errCode);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 8837|      0|    return SECFailure;
 8838|      0|}
ssl3_SelectServerCert:
 8842|  58.7k|{
 8843|  58.7k|    const ssl3KEADef *kea_def = ss->ssl3.hs.kea_def;
 8844|  58.7k|    PRCList *cursor;
 8845|  58.7k|    SECStatus rv;
 8846|       |
 8847|       |    /* If the client didn't include the supported groups extension, assume just
 8848|       |     * P-256 support and disable all the other ECDHE groups.  This also affects
 8849|       |     * ECDHE group selection, but this function is called first. */
 8850|  58.7k|    if (!ssl3_ExtensionNegotiated(ss, ssl_supported_groups_xtn)) {
  ------------------
  |  Branch (8850:9): [True: 47.7k, False: 11.0k]
  ------------------
 8851|  47.7k|        unsigned int i;
 8852|  1.62M|        for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  1.62M|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (8852:21): [True: 1.57M, False: 47.7k]
  ------------------
 8853|  1.57M|            if (ss->namedGroupPreferences[i] &&
  ------------------
  |  Branch (8853:17): [True: 313k, False: 1.26M]
  ------------------
 8854|  1.57M|                ss->namedGroupPreferences[i]->keaType == ssl_kea_ecdh &&
  ------------------
  |  Branch (8854:17): [True: 58.1k, False: 255k]
  ------------------
 8855|  1.57M|                ss->namedGroupPreferences[i]->name != ssl_grp_ec_secp256r1) {
  ------------------
  |  Branch (8855:17): [True: 16.7k, False: 41.3k]
  ------------------
 8856|  16.7k|                ss->namedGroupPreferences[i] = NULL;
 8857|  16.7k|            }
 8858|  1.57M|        }
 8859|  47.7k|    }
 8860|       |
 8861|       |    /* This picks the first certificate that has:
 8862|       |     * a) the right authentication method, and
 8863|       |     * b) the right named curve (EC only)
 8864|       |     *
 8865|       |     * We might want to do some sort of ranking here later.  For now, it's all
 8866|       |     * based on what order they are configured in. */
 8867|  58.7k|    for (cursor = PR_NEXT_LINK(&ss->serverCerts);
  ------------------
  |  |   47|  58.7k|        ((_e)->next)
  ------------------
 8868|   105k|         cursor != &ss->serverCerts;
  ------------------
  |  Branch (8868:10): [True: 105k, False: 0]
  ------------------
 8869|   105k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|  47.0k|        ((_e)->next)
  ------------------
 8870|   105k|        sslServerCert *cert = (sslServerCert *)cursor;
 8871|   105k|        if (kea_def->authKeyType == ssl_auth_rsa_sign) {
  ------------------
  |  Branch (8871:13): [True: 68.9k, False: 36.8k]
  ------------------
 8872|       |            /* We consider PSS certificates here as well for TLS 1.2. */
 8873|  68.9k|            if (!SSL_CERT_IS(cert, ssl_auth_rsa_sign) &&
  ------------------
  |  |   53|   137k|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  ------------------
  |  Branch (8873:17): [True: 34.4k, False: 34.4k]
  ------------------
 8874|  68.9k|                (!SSL_CERT_IS(cert, ssl_auth_rsa_pss) ||
  ------------------
  |  |   53|  68.9k|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  ------------------
  |  Branch (8874:18): [True: 34.4k, False: 0]
  ------------------
 8875|  34.4k|                 ss->version < SSL_LIBRARY_VERSION_TLS_1_2)) {
  ------------------
  |  |   20|      0|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (8875:18): [True: 0, False: 0]
  ------------------
 8876|  34.4k|                continue;
 8877|  34.4k|            }
 8878|  68.9k|        } else {
 8879|  36.8k|            if (!SSL_CERT_IS(cert, kea_def->authKeyType)) {
  ------------------
  |  |   53|  36.8k|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  ------------------
  |  Branch (8879:17): [True: 12.5k, False: 24.2k]
  ------------------
 8880|  12.5k|                continue;
 8881|  12.5k|            }
 8882|  24.2k|            if (SSL_CERT_IS_EC(cert) &&
  ------------------
  |  |   56|  48.5k|    ((c)->authTypes & ((1 << ssl_auth_ecdsa) |    \
  |  |  ------------------
  |  |  |  Branch (56:5): [True: 11.7k, False: 12.5k]
  |  |  ------------------
  |  |   57|  48.5k|                       (1 << ssl_auth_ecdh_rsa) | \
  |  |   58|  48.5k|                       (1 << ssl_auth_ecdh_ecdsa)))
  ------------------
 8883|  24.2k|                !ssl_NamedGroupEnabled(ss, cert->namedCurve)) {
  ------------------
  |  Branch (8883:17): [True: 0, False: 11.7k]
  ------------------
 8884|      0|                continue;
 8885|      0|            }
 8886|  24.2k|        }
 8887|       |
 8888|       |        /* Found one. */
 8889|  58.7k|        ss->sec.serverCert = cert;
 8890|  58.7k|        ss->sec.authKeyBits = cert->serverKeyBits;
 8891|       |
 8892|       |        /* Don't pick a signature scheme if we aren't going to use it. */
 8893|  58.7k|        if (kea_def->signKeyType == nullKey) {
  ------------------
  |  Branch (8893:13): [True: 12.6k, False: 46.1k]
  ------------------
 8894|  12.6k|            ss->sec.authType = kea_def->authKeyType;
 8895|  12.6k|            return SECSuccess;
 8896|  12.6k|        }
 8897|       |
 8898|  46.1k|        rv = ssl3_PickServerSignatureScheme(ss);
 8899|  46.1k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (8899:13): [True: 20, False: 46.0k]
  ------------------
 8900|     20|            return SECFailure;
 8901|     20|        }
 8902|  46.0k|        ss->sec.authType =
 8903|  46.0k|            ssl_SignatureSchemeToAuthType(ss->ssl3.hs.signatureScheme);
 8904|  46.0k|        return SECSuccess;
 8905|  46.1k|    }
 8906|       |
 8907|      0|    PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 8908|      0|    return SECFailure;
 8909|  58.7k|}
ssl3_HandleClientHelloPreamble:
 8971|  61.2k|{
 8972|  61.2k|    SECStatus rv;
 8973|  61.2k|    PRUint32 tmp;
 8974|  61.2k|    rv = ssl3_ConsumeHandshakeNumber(ss, &tmp, 2, b, length);
 8975|  61.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8975:9): [True: 12, False: 61.2k]
  ------------------
 8976|     12|        return SECFailure; /* malformed, alert already sent */
 8977|     12|    }
 8978|       |
 8979|       |    /* Translate the version. */
 8980|  61.2k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  61.2k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 61.2k]
  |  |  ------------------
  ------------------
 8981|      0|        ss->clientHelloVersion = dtls_DTLSVersionToTLSVersion((SSL3ProtocolVersion)tmp);
 8982|  61.2k|    } else {
 8983|  61.2k|        ss->clientHelloVersion = (SSL3ProtocolVersion)tmp;
 8984|  61.2k|    }
 8985|       |
 8986|       |    /* Grab the client random data. */
 8987|  61.2k|    rv = ssl3_ConsumeHandshake(
 8988|  61.2k|        ss, ss->ssl3.hs.client_random, SSL3_RANDOM_LENGTH, b, length);
  ------------------
  |  |   24|  61.2k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 8989|  61.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8989:9): [True: 21, False: 61.1k]
  ------------------
 8990|     21|        return SECFailure; /* malformed */
 8991|     21|    }
 8992|       |
 8993|       |    /* Grab the client's SID, if present. */
 8994|  61.1k|    rv = ssl3_ConsumeHandshakeVariable(ss, sidBytes, 1, b, length);
 8995|       |    /* Check that the SID has the format: opaque legacy_session_id<0..32>, as
 8996|       |     * specified in RFC8446, Section 4.1.2. */
 8997|  61.1k|    if (rv != SECSuccess || sidBytes->len > SSL3_SESSIONID_BYTES) {
  ------------------
  |  |  107|  61.1k|#define SSL3_SESSIONID_BYTES 32
  ------------------
  |  Branch (8997:9): [True: 35, False: 61.1k]
  |  Branch (8997:29): [True: 15, False: 61.1k]
  ------------------
 8998|     50|        return SECFailure; /* malformed */
 8999|     50|    }
 9000|       |
 9001|       |    /* Grab the client's cookie, if present. It is checked after version negotiation. */
 9002|  61.1k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  61.1k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 61.1k]
  |  |  ------------------
  ------------------
 9003|      0|        rv = ssl3_ConsumeHandshakeVariable(ss, cookieBytes, 1, b, length);
 9004|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (9004:13): [True: 0, False: 0]
  ------------------
 9005|      0|            return SECFailure; /* malformed */
 9006|      0|        }
 9007|      0|    }
 9008|       |
 9009|       |    /* Grab the list of cipher suites. */
 9010|  61.1k|    rv = ssl3_ConsumeHandshakeVariable(ss, suites, 2, b, length);
 9011|  61.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9011:9): [True: 41, False: 61.1k]
  ------------------
 9012|     41|        return SECFailure; /* malformed */
 9013|     41|    }
 9014|       |
 9015|       |    /* Grab the list of compression methods. */
 9016|  61.1k|    rv = ssl3_ConsumeHandshakeVariable(ss, comps, 1, b, length);
 9017|  61.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9017:9): [True: 11, False: 61.0k]
  ------------------
 9018|     11|        return SECFailure; /* malformed */
 9019|     11|    }
 9020|  61.0k|    return SECSuccess;
 9021|  61.1k|}
ssl_ConstructServerHello:
10006|  60.1k|{
10007|  60.1k|    SECStatus rv;
10008|  60.1k|    SSL3ProtocolVersion version;
10009|  60.1k|    sslSessionID *sid = ss->sec.ci.sid;
10010|  60.1k|    const PRUint8 *random;
10011|       |
10012|  60.1k|    version = PR_MIN(ss->version, SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |  158|  60.1k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 6.63k, False: 53.5k]
  |  |  ------------------
  ------------------
10013|  60.1k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  60.1k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 60.1k]
  |  |  ------------------
  ------------------
10014|      0|        version = dtls_TLSVersionToDTLSVersion(version);
10015|      0|    }
10016|  60.1k|    rv = sslBuffer_AppendNumber(messageBuf, version, 2);
10017|  60.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10017:9): [True: 0, False: 60.1k]
  ------------------
10018|      0|        return SECFailure;
10019|      0|    }
10020|       |
10021|  60.1k|    if (helloRetry) {
  ------------------
  |  Branch (10021:9): [True: 181, False: 59.9k]
  ------------------
10022|    181|        random = ssl_hello_retry_random;
10023|  59.9k|    } else {
10024|  59.9k|        rv = ssl_GenerateServerRandom(ss);
10025|  59.9k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10025:13): [True: 0, False: 59.9k]
  ------------------
10026|      0|            return SECFailure;
10027|      0|        }
10028|  59.9k|        random = ss->ssl3.hs.server_random;
10029|  59.9k|    }
10030|  60.1k|    rv = sslBuffer_Append(messageBuf, random, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|  60.1k|#define SSL3_RANDOM_LENGTH 32
  ------------------
10031|  60.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10031:9): [True: 0, False: 60.1k]
  ------------------
10032|      0|        return SECFailure;
10033|      0|    }
10034|       |
10035|  60.1k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  60.1k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (10035:9): [True: 58.7k, False: 1.39k]
  ------------------
10036|  58.7k|        if (sid) {
  ------------------
  |  Branch (10036:13): [True: 58.7k, False: 0]
  ------------------
10037|  58.7k|            rv = sslBuffer_AppendVariable(messageBuf, sid->u.ssl3.sessionID,
10038|  58.7k|                                          sid->u.ssl3.sessionIDLength, 1);
10039|  58.7k|        } else {
10040|      0|            rv = sslBuffer_AppendNumber(messageBuf, 0, 1);
10041|      0|        }
10042|  58.7k|    } else {
10043|  1.39k|        rv = sslBuffer_AppendVariable(messageBuf, ss->ssl3.hs.fakeSid.data,
10044|  1.39k|                                      ss->ssl3.hs.fakeSid.len, 1);
10045|  1.39k|    }
10046|  60.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10046:9): [True: 0, False: 60.1k]
  ------------------
10047|      0|        return SECFailure;
10048|      0|    }
10049|       |
10050|  60.1k|    rv = sslBuffer_AppendNumber(messageBuf, ss->ssl3.hs.cipher_suite, 2);
10051|  60.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10051:9): [True: 0, False: 60.1k]
  ------------------
10052|      0|        return SECFailure;
10053|      0|    }
10054|  60.1k|    rv = sslBuffer_AppendNumber(messageBuf, ssl_compression_null, 1);
10055|  60.1k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10055:9): [True: 0, False: 60.1k]
  ------------------
10056|      0|        return SECFailure;
10057|      0|    }
10058|  60.1k|    if (SSL_BUFFER_LEN(extensionBuf)) {
  ------------------
  |  |   36|  60.1k|#define SSL_BUFFER_LEN(b) ((b)->len)
  |  |  ------------------
  |  |  |  Branch (36:27): [True: 13.6k, False: 46.5k]
  |  |  ------------------
  ------------------
10059|       |        /* Directly copy the extensions */
10060|  13.6k|        rv = sslBuffer_AppendBufferVariable(messageBuf, extensionBuf, 2);
10061|  13.6k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10061:13): [True: 0, False: 13.6k]
  ------------------
10062|      0|            return SECFailure;
10063|      0|        }
10064|  13.6k|    }
10065|       |
10066|  60.1k|    if (ss->xtnData.ech && ss->xtnData.ech->receivedInnerXtn) {
  ------------------
  |  Branch (10066:9): [True: 25, False: 60.1k]
  |  Branch (10066:28): [True: 16, False: 9]
  ------------------
10067|       |        /* Signal ECH acceptance if we handled handled both CHOuter/CHInner (i.e.
10068|       |         * in shared mode), or if we received a CHInner in split/backend mode. */
10069|     16|        if (ss->ssl3.hs.echAccepted || ss->opt.enableTls13BackendEch) {
  ------------------
  |  Branch (10069:13): [True: 0, False: 16]
  |  Branch (10069:40): [True: 16, False: 0]
  ------------------
10070|     16|            if (helloRetry) {
  ------------------
  |  Branch (10070:17): [True: 5, False: 11]
  ------------------
10071|      5|                return tls13_WriteServerEchHrrSignal(ss, SSL_BUFFER_BASE(messageBuf),
  ------------------
  |  |   35|      5|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
10072|      5|                                                     SSL_BUFFER_LEN(messageBuf));
  ------------------
  |  |   36|      5|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
10073|     11|            } else {
10074|     11|                return tls13_WriteServerEchSignal(ss, SSL_BUFFER_BASE(messageBuf),
  ------------------
  |  |   35|     11|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
10075|     11|                                                  SSL_BUFFER_LEN(messageBuf));
  ------------------
  |  |   36|     11|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
10076|     11|            }
10077|     16|        }
10078|     16|    }
10079|  60.1k|    return SECSuccess;
10080|  60.1k|}
ssl3_SendServerHello:
10090|  59.9k|{
10091|  59.9k|    SECStatus rv;
10092|  59.9k|    sslBuffer extensionBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  59.9k|    {                        \
  |  |   24|  59.9k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  59.9k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  59.9k|    }
  ------------------
10093|  59.9k|    sslBuffer messageBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  59.9k|    {                        \
  |  |   24|  59.9k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  59.9k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  59.9k|    }
  ------------------
10094|       |
10095|  59.9k|    SSL_TRC(3, ("%d: SSL3[%d]: send server_hello handshake", SSL_GETPID(),
  ------------------
  |  |   71|  59.9k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 59.9k]
  |  |  ------------------
  |  |   72|  59.9k|    ssl_Trace b
  ------------------
10096|  59.9k|                ss->fd));
10097|       |
10098|  59.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  59.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  90.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 29.1k, False: 30.7k]
  |  |  |  |  |  Branch (208:7): [True: 30.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10099|  59.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  59.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  90.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 29.1k, False: 30.7k]
  |  |  |  |  |  Branch (208:7): [True: 30.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10100|       |
10101|  59.9k|    PORT_Assert(MSB(ss->version) == MSB(SSL_LIBRARY_VERSION_3_0));
  ------------------
  |  |  120|  59.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  59.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 59.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10102|  59.9k|    if (MSB(ss->version) != MSB(SSL_LIBRARY_VERSION_3_0)) {
  ------------------
  |  |   94|  59.9k|#define MSB(x) ((unsigned char)(((unsigned)(x)) >> 8))
  ------------------
                  if (MSB(ss->version) != MSB(SSL_LIBRARY_VERSION_3_0)) {
  ------------------
  |  |   94|  59.9k|#define MSB(x) ((unsigned char)(((unsigned)(x)) >> 8))
  ------------------
  |  Branch (10102:9): [True: 0, False: 59.9k]
  ------------------
10103|      0|        PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10104|      0|        return SECFailure;
10105|      0|    }
10106|       |
10107|  59.9k|    rv = ssl_ConstructExtensions(ss, &extensionBuf, ssl_hs_server_hello);
10108|  59.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10108:9): [True: 0, False: 59.9k]
  ------------------
10109|      0|        goto loser;
10110|      0|    }
10111|       |
10112|  59.9k|    rv = ssl_ConstructServerHello(ss, PR_FALSE, &extensionBuf, &messageBuf);
  ------------------
  |  |  438|  59.9k|#define PR_FALSE 0
  ------------------
10113|  59.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10113:9): [True: 0, False: 59.9k]
  ------------------
10114|      0|        goto loser;
10115|      0|    }
10116|       |
10117|  59.9k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_server_hello,
10118|  59.9k|                                    SSL_BUFFER_LEN(&messageBuf));
  ------------------
  |  |   36|  59.9k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
10119|  59.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10119:9): [True: 0, False: 59.9k]
  ------------------
10120|      0|        goto loser; /* err set by AppendHandshake. */
10121|      0|    }
10122|       |
10123|  59.9k|    rv = ssl3_AppendHandshake(ss, SSL_BUFFER_BASE(&messageBuf),
  ------------------
  |  |   35|  59.9k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
10124|  59.9k|                              SSL_BUFFER_LEN(&messageBuf));
  ------------------
  |  |   36|  59.9k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
10125|  59.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10125:9): [True: 0, False: 59.9k]
  ------------------
10126|      0|        goto loser; /* err set by AppendHandshake. */
10127|      0|    }
10128|       |
10129|  59.9k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  59.9k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (10129:9): [True: 58.7k, False: 1.21k]
  ------------------
10130|  58.7k|        rv = ssl3_SetupBothPendingCipherSpecs(ss);
10131|  58.7k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10131:13): [True: 0, False: 58.7k]
  ------------------
10132|      0|            goto loser; /* err set */
10133|      0|        }
10134|  58.7k|    }
10135|       |
10136|  59.9k|    sslBuffer_Clear(&extensionBuf);
10137|  59.9k|    sslBuffer_Clear(&messageBuf);
10138|  59.9k|    return SECSuccess;
10139|       |
10140|      0|loser:
10141|      0|    sslBuffer_Clear(&extensionBuf);
10142|      0|    sslBuffer_Clear(&messageBuf);
10143|      0|    return SECFailure;
10144|  59.9k|}
ssl_CreateDHEKeyPair:
10150|  29.0k|{
10151|  29.0k|    SECKEYDHParams dhParam;
10152|  29.0k|    SECKEYPublicKey *pubKey = NULL;   /* Ephemeral DH key */
10153|  29.0k|    SECKEYPrivateKey *privKey = NULL; /* Ephemeral DH key */
10154|  29.0k|    sslEphemeralKeyPair *pair;
10155|       |
10156|  29.0k|    dhParam.prime.data = params->prime.data;
10157|  29.0k|    dhParam.prime.len = params->prime.len;
10158|  29.0k|    dhParam.base.data = params->base.data;
10159|  29.0k|    dhParam.base.len = params->base.len;
10160|       |
10161|  29.0k|    PRINT_BUF(60, (NULL, "Server DH p", dhParam.prime.data,
  ------------------
  |  |   74|  29.0k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   75|  29.0k|    ssl_PrintBuf b
  ------------------
10162|  29.0k|                   dhParam.prime.len));
10163|  29.0k|    PRINT_BUF(60, (NULL, "Server DH g", dhParam.base.data,
  ------------------
  |  |   74|  29.0k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 29.0k]
  |  |  ------------------
  |  |   75|  29.0k|    ssl_PrintBuf b
  ------------------
10164|  29.0k|                   dhParam.base.len));
10165|       |
10166|       |    /* Generate ephemeral DH keypair */
10167|  29.0k|    privKey = SECKEY_CreateDHPrivateKey(&dhParam, &pubKey, NULL);
10168|  29.0k|    if (!privKey || !pubKey) {
  ------------------
  |  Branch (10168:9): [True: 0, False: 29.0k]
  |  Branch (10168:21): [True: 0, False: 29.0k]
  ------------------
10169|      0|        ssl_MapLowLevelError(SEC_ERROR_KEYGEN_FAIL);
10170|      0|        return SECFailure;
10171|      0|    }
10172|       |
10173|  29.0k|    pair = ssl_NewEphemeralKeyPair(groupDef, privKey, pubKey);
10174|  29.0k|    if (!pair) {
  ------------------
  |  Branch (10174:9): [True: 0, False: 29.0k]
  ------------------
10175|      0|        SECKEY_DestroyPrivateKey(privKey);
10176|      0|        SECKEY_DestroyPublicKey(pubKey);
10177|       |
10178|      0|        return SECFailure;
10179|      0|    }
10180|       |
10181|  29.0k|    *keyPair = pair;
10182|  29.0k|    return SECSuccess;
10183|  29.0k|}
ssl3_EncodeSigAlgs:
10344|  5.26k|{
10345|  5.26k|    SSLSignatureScheme filtered[MAX_SIGNATURE_SCHEMES] = { 0 };
10346|  5.26k|    unsigned int filteredCount = 0;
10347|       |
10348|  5.26k|    SECStatus rv = ssl3_FilterSigAlgs(ss, minVersion, PR_FALSE, forCert,
  ------------------
  |  |  438|  5.26k|#define PR_FALSE 0
  ------------------
10349|  5.26k|                                      PR_ARRAY_SIZE(filtered),
  ------------------
  |  |  167|  5.26k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
10350|  5.26k|                                      filtered, &filteredCount);
10351|  5.26k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10351:9): [True: 0, False: 5.26k]
  ------------------
10352|      0|        return SECFailure;
10353|      0|    }
10354|  5.26k|    return ssl3_EncodeFilteredSigAlgs(ss, filtered, filteredCount, grease, buf);
10355|  5.26k|}
ssl3_EncodeFilteredSigAlgs:
10360|  5.26k|{
10361|  5.26k|    if (!numSchemes) {
  ------------------
  |  Branch (10361:9): [True: 0, False: 5.26k]
  ------------------
10362|      0|        PORT_SetError(SSL_ERROR_NO_SUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10363|      0|        return SECFailure;
10364|      0|    }
10365|       |
10366|  5.26k|    unsigned int lengthOffset;
10367|  5.26k|    SECStatus rv;
10368|       |
10369|  5.26k|    rv = sslBuffer_Skip(buf, 2, &lengthOffset);
10370|  5.26k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10370:9): [True: 0, False: 5.26k]
  ------------------
10371|      0|        return SECFailure;
10372|      0|    }
10373|       |
10374|  82.4k|    for (unsigned int i = 0; i < numSchemes; ++i) {
  ------------------
  |  Branch (10374:30): [True: 77.2k, False: 5.26k]
  ------------------
10375|  77.2k|        rv = sslBuffer_AppendNumber(buf, schemes[i], 2);
10376|  77.2k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10376:13): [True: 0, False: 77.2k]
  ------------------
10377|      0|            return SECFailure;
10378|      0|        }
10379|  77.2k|    }
10380|       |
10381|       |    /* GREASE SignatureAlgorithms:
10382|       |     * A client MAY select one or more GREASE signature algorithm values and
10383|       |     * advertise them in the "signature_algorithms" or
10384|       |     * "signature_algorithms_cert" extensions, if sent [RFC8701, Section 3.1].
10385|       |     *
10386|       |     * When sending a CertificateRequest in TLS 1.3, a server MAY behave as
10387|       |     * follows: [...] A server MAY select one or more GREASE signature
10388|       |     * algorithm values and advertise them in the "signature_algorithms" or
10389|       |     * "signature_algorithms_cert" extensions, if present
10390|       |     * [RFC8701, Section 4.1]. */
10391|  5.26k|    if (grease &&
  ------------------
  |  Branch (10391:9): [True: 200, False: 5.06k]
  ------------------
10392|  5.26k|        ((!ss->sec.isServer && ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3) ||
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (10392:11): [True: 0, False: 200]
  |  Branch (10392:32): [True: 0, False: 0]
  ------------------
10393|    200|         (ss->sec.isServer && ss->version >= SSL_LIBRARY_VERSION_TLS_1_3))) {
  ------------------
  |  |   21|    200|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (10393:11): [True: 200, False: 0]
  |  Branch (10393:31): [True: 200, False: 0]
  ------------------
10394|    200|        PRUint16 value;
10395|    200|        if (ss->sec.isServer) {
  ------------------
  |  Branch (10395:13): [True: 200, False: 0]
  ------------------
10396|    200|            rv = tls13_RandomGreaseValue(&value);
10397|    200|            if (rv != SECSuccess) {
  ------------------
  |  Branch (10397:17): [True: 0, False: 200]
  ------------------
10398|      0|                return SECFailure;
10399|      0|            }
10400|    200|        } else {
10401|      0|            value = ss->ssl3.hs.grease->idx[grease_sigalg];
10402|      0|        }
10403|    200|        rv = sslBuffer_AppendNumber(buf, value, 2);
10404|    200|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10404:13): [True: 0, False: 200]
  ------------------
10405|      0|            return SECFailure;
10406|      0|        }
10407|    200|    }
10408|       |
10409|  5.26k|    return sslBuffer_InsertLength(buf, lengthOffset, 2);
10410|  5.26k|}
ssl3_FilterSigAlgs:
10429|  5.26k|{
10430|  5.26k|    PORT_Assert(filteredSchemes);
  ------------------
  |  |  120|  5.26k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.26k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5.26k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10431|  5.26k|    PORT_Assert(numFilteredSchemes);
  ------------------
  |  |  120|  5.26k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.26k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5.26k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10432|  5.26k|    PORT_Assert(maxSchemes >= ss->ssl3.signatureSchemeCount);
  ------------------
  |  |  120|  5.26k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.26k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5.26k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10433|  5.26k|    if (maxSchemes < ss->ssl3.signatureSchemeCount) {
  ------------------
  |  Branch (10433:9): [True: 0, False: 5.26k]
  ------------------
10434|      0|        return SECFailure;
10435|      0|    }
10436|       |
10437|  5.26k|    *numFilteredSchemes = 0;
10438|  5.26k|    PRBool allowUnsortedPkcs1 = forCert && minVersion < SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|  5.26k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (10438:33): [True: 5.26k, False: 0]
  |  Branch (10438:44): [True: 4.81k, False: 447]
  ------------------
10439|  84.2k|    for (unsigned int i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (10439:30): [True: 78.9k, False: 5.26k]
  ------------------
10440|  78.9k|        if (disableRsae && ssl_IsRsaeSignatureScheme(ss->ssl3.signatureSchemes[i])) {
  ------------------
  |  Branch (10440:13): [True: 0, False: 78.9k]
  |  Branch (10440:28): [True: 0, False: 0]
  ------------------
10441|      0|            continue;
10442|      0|        }
10443|  78.9k|        if (ssl_SignatureSchemeAccepted(minVersion,
  ------------------
  |  Branch (10443:13): [True: 75.4k, False: 3.57k]
  ------------------
10444|  78.9k|                                        ss->ssl3.signatureSchemes[i],
10445|  78.9k|                                        allowUnsortedPkcs1)) {
10446|  75.4k|            filteredSchemes[(*numFilteredSchemes)++] = ss->ssl3.signatureSchemes[i];
10447|  75.4k|        }
10448|  78.9k|    }
10449|  5.26k|    if (forCert && !allowUnsortedPkcs1) {
  ------------------
  |  Branch (10449:9): [True: 5.26k, False: 0]
  |  Branch (10449:20): [True: 447, False: 4.81k]
  ------------------
10450|  7.15k|        for (unsigned int i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (10450:34): [True: 6.70k, False: 447]
  ------------------
10451|  6.70k|            if (disableRsae && ssl_IsRsaeSignatureScheme(ss->ssl3.signatureSchemes[i])) {
  ------------------
  |  Branch (10451:17): [True: 0, False: 6.70k]
  |  Branch (10451:32): [True: 0, False: 0]
  ------------------
10452|      0|                continue;
10453|      0|            }
10454|  6.70k|            if (!ssl_SignatureSchemeAccepted(minVersion,
  ------------------
  |  Branch (10454:17): [True: 3.57k, False: 3.12k]
  ------------------
10455|  6.70k|                                             ss->ssl3.signatureSchemes[i],
10456|  6.70k|                                             PR_FALSE) &&
  ------------------
  |  |  438|  6.70k|#define PR_FALSE 0
  ------------------
10457|  6.70k|                ssl_SignatureSchemeAccepted(minVersion,
  ------------------
  |  Branch (10457:17): [True: 1.78k, False: 1.78k]
  ------------------
10458|  3.57k|                                            ss->ssl3.signatureSchemes[i],
10459|  3.57k|                                            PR_TRUE)) {
  ------------------
  |  |  437|  3.57k|#define PR_TRUE 1
  ------------------
10460|  1.78k|                filteredSchemes[(*numFilteredSchemes)++] = ss->ssl3.signatureSchemes[i];
10461|  1.78k|            }
10462|  6.70k|        }
10463|    447|    }
10464|  5.26k|    return SECSuccess;
10465|  5.26k|}
ssl3_SendCertificateStatus:
11327|  58.7k|{
11328|  58.7k|    SECStatus rv;
11329|  58.7k|    int len = 0;
11330|  58.7k|    SECItemArray *statusToSend = NULL;
11331|  58.7k|    const sslServerCert *serverCert;
11332|       |
11333|  58.7k|    SSL_TRC(3, ("%d: SSL3[%d]: send certificate status handshake",
  ------------------
  |  |   71|  58.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 58.7k]
  |  |  ------------------
  |  |   72|  58.7k|    ssl_Trace b
  ------------------
11334|  58.7k|                SSL_GETPID(), ss->fd));
11335|       |
11336|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11337|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11338|  58.7k|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  58.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 58.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11339|       |
11340|  58.7k|    if (!ssl3_ExtensionNegotiated(ss, ssl_cert_status_xtn))
  ------------------
  |  Branch (11340:9): [True: 48.7k, False: 10.0k]
  ------------------
11341|  48.7k|        return SECSuccess;
11342|       |
11343|       |    /* Use certStatus based on the cert being used. */
11344|  10.0k|    serverCert = ss->sec.serverCert;
11345|  10.0k|    if (serverCert->certStatusArray && serverCert->certStatusArray->len) {
  ------------------
  |  Branch (11345:9): [True: 0, False: 10.0k]
  |  Branch (11345:40): [True: 0, False: 0]
  ------------------
11346|      0|        statusToSend = serverCert->certStatusArray;
11347|      0|    }
11348|  10.0k|    if (!statusToSend)
  ------------------
  |  Branch (11348:9): [True: 10.0k, False: 0]
  ------------------
11349|  10.0k|        return SECSuccess;
11350|       |
11351|       |    /* Use the array's first item only (single stapling) */
11352|      0|    len = 1 + statusToSend->items[0].len + 3;
11353|       |
11354|      0|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_certificate_status, len);
11355|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (11355:9): [True: 0, False: 0]
  ------------------
11356|      0|        return rv; /* err set by AppendHandshake. */
11357|      0|    }
11358|      0|    rv = ssl3_AppendHandshakeNumber(ss, 1 /*ocsp*/, 1);
11359|      0|    if (rv != SECSuccess)
  ------------------
  |  Branch (11359:9): [True: 0, False: 0]
  ------------------
11360|      0|        return rv; /* err set by AppendHandshake. */
11361|       |
11362|      0|    rv = ssl3_AppendHandshakeVariable(ss,
11363|      0|                                      statusToSend->items[0].data,
11364|      0|                                      statusToSend->items[0].len,
11365|      0|                                      3);
11366|      0|    if (rv != SECSuccess)
  ------------------
  |  Branch (11366:9): [True: 0, False: 0]
  ------------------
11367|      0|        return rv; /* err set by AppendHandshake. */
11368|       |
11369|      0|    return SECSuccess;
11370|      0|}
ssl3_CleanupPeerCerts:
11377|  7.80k|{
11378|  7.80k|    PLArenaPool *arena = ss->ssl3.peerCertArena;
11379|       |
11380|  7.80k|    if (arena)
  ------------------
  |  Branch (11380:9): [True: 4.10k, False: 3.70k]
  ------------------
11381|  4.10k|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|  4.10k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|  4.10k|#define PR_FALSE 0
  ------------------
11382|  7.80k|    ss->ssl3.peerCertArena = NULL;
11383|  7.80k|    ss->ssl3.peerCertChain = NULL;
11384|       |
11385|  7.80k|    if (ss->sec.peerCert != NULL) {
  ------------------
  |  Branch (11385:9): [True: 1.33k, False: 6.47k]
  ------------------
11386|  1.33k|        if (ss->sec.peerKey) {
  ------------------
  |  Branch (11386:13): [True: 0, False: 1.33k]
  ------------------
11387|      0|            SECKEY_DestroyPublicKey(ss->sec.peerKey);
11388|      0|            ss->sec.peerKey = NULL;
11389|      0|        }
11390|  1.33k|        CERT_DestroyCertificate(ss->sec.peerCert);
11391|  1.33k|        ss->sec.peerCert = NULL;
11392|  1.33k|    }
11393|  7.80k|}
ssl3_CompleteHandleCertificate:
11492|  4.39k|{
11493|  4.39k|    ssl3CertNode *c;
11494|  4.39k|    ssl3CertNode *lastCert = NULL;
11495|  4.39k|    PRUint32 remaining = 0;
11496|  4.39k|    PRUint32 size;
11497|  4.39k|    SECStatus rv;
11498|  4.39k|    PRBool isServer = ss->sec.isServer;
11499|  4.39k|    PRBool isTLS;
11500|  4.39k|    SSL3AlertDescription desc;
11501|  4.39k|    int errCode = SSL_ERROR_RX_MALFORMED_CERTIFICATE;
11502|  4.39k|    SECItem certItem;
11503|       |
11504|  4.39k|    ssl3_CleanupPeerCerts(ss);
11505|  4.39k|    isTLS = (PRBool)(ss->ssl3.prSpec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  4.39k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
11506|       |
11507|       |    /* It is reported that some TLS client sends a Certificate message
11508|       |    ** with a zero-length message body.  We'll treat that case like a
11509|       |    ** normal no_certificates message to maximize interoperability.
11510|       |    */
11511|  4.39k|    if (length) {
  ------------------
  |  Branch (11511:9): [True: 4.38k, False: 12]
  ------------------
11512|  4.38k|        rv = ssl3_ConsumeHandshakeNumber(ss, &remaining, 3, &b, &length);
11513|  4.38k|        if (rv != SECSuccess)
  ------------------
  |  Branch (11513:13): [True: 1, False: 4.38k]
  ------------------
11514|      1|            goto loser; /* fatal alert already sent by ConsumeHandshake. */
11515|  4.38k|        if (remaining > length)
  ------------------
  |  Branch (11515:13): [True: 41, False: 4.34k]
  ------------------
11516|     41|            goto decode_loser;
11517|  4.38k|    }
11518|       |
11519|  4.35k|    if (!remaining) {
  ------------------
  |  Branch (11519:9): [True: 258, False: 4.09k]
  ------------------
11520|    258|        if (!(isTLS && isServer)) {
  ------------------
  |  Branch (11520:15): [True: 258, False: 0]
  |  Branch (11520:24): [True: 258, False: 0]
  ------------------
11521|      0|            desc = bad_certificate;
11522|      0|            goto alert_loser;
11523|      0|        }
11524|       |        /* This is TLS's version of a no_certificate alert. */
11525|       |        /* I'm a server. I've requested a client cert. He hasn't got one. */
11526|    258|        rv = ssl3_HandleNoCertificate(ss);
11527|    258|        if (rv != SECSuccess) {
  ------------------
  |  Branch (11527:13): [True: 2, False: 256]
  ------------------
11528|      2|            errCode = PORT_GetError();
  ------------------
  |  |   62|      2|#define PORT_GetError PORT_GetError_Util
  ------------------
11529|      2|            goto loser;
11530|      2|        }
11531|       |
11532|    256|        if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|    256|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (11532:13): [True: 256, False: 0]
  ------------------
11533|    256|            ss->ssl3.hs.ws = wait_client_key;
11534|    256|        } else {
11535|      0|            TLS13_SET_HS_STATE(ss, wait_finished);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
11536|      0|        }
11537|    256|        return SECSuccess;
11538|    258|    }
11539|       |
11540|  4.09k|    ss->ssl3.peerCertArena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  4.09k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  ss->ssl3.peerCertArena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  4.09k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
11541|  4.09k|    if (ss->ssl3.peerCertArena == NULL) {
  ------------------
  |  Branch (11541:9): [True: 0, False: 4.09k]
  ------------------
11542|      0|        goto loser; /* don't send alerts on memory errors */
11543|      0|    }
11544|       |
11545|       |    /* First get the peer cert. */
11546|  4.09k|    if (remaining < 3)
  ------------------
  |  Branch (11546:9): [True: 1, False: 4.09k]
  ------------------
11547|      1|        goto decode_loser;
11548|       |
11549|  4.09k|    remaining -= 3;
11550|  4.09k|    rv = ssl3_ConsumeHandshakeNumber(ss, &size, 3, &b, &length);
11551|  4.09k|    if (rv != SECSuccess)
  ------------------
  |  Branch (11551:9): [True: 0, False: 4.09k]
  ------------------
11552|      0|        goto loser; /* fatal alert already sent by ConsumeHandshake. */
11553|  4.09k|    if (size == 0 || remaining < size)
  ------------------
  |  Branch (11553:9): [True: 2, False: 4.09k]
  |  Branch (11553:22): [True: 35, False: 4.06k]
  ------------------
11554|     37|        goto decode_loser;
11555|       |
11556|  4.06k|    certItem.data = b;
11557|  4.06k|    certItem.len = size;
11558|  4.06k|    b += size;
11559|  4.06k|    length -= size;
11560|  4.06k|    remaining -= size;
11561|       |
11562|  4.06k|    ss->sec.peerCert = CERT_NewTempCertificate(ss->dbHandle, &certItem, NULL,
11563|  4.06k|                                               PR_FALSE, PR_TRUE);
  ------------------
  |  |  438|  4.06k|#define PR_FALSE 0
  ------------------
                                                             PR_FALSE, PR_TRUE);
  ------------------
  |  |  437|  4.06k|#define PR_TRUE 1
  ------------------
11564|  4.06k|    if (ss->sec.peerCert == NULL) {
  ------------------
  |  Branch (11564:9): [True: 172, False: 3.88k]
  ------------------
11565|       |        /* We should report an alert if the cert was bad, but not if the
11566|       |         * problem was just some local problem, like memory error.
11567|       |         */
11568|    172|        goto ambiguous_err;
11569|    172|    }
11570|       |
11571|       |    /* Now get all of the CA certs. */
11572|  4.06k|    while (remaining > 0) {
  ------------------
  |  Branch (11572:12): [True: 237, False: 3.83k]
  ------------------
11573|    237|        if (remaining < 3)
  ------------------
  |  Branch (11573:13): [True: 1, False: 236]
  ------------------
11574|      1|            goto decode_loser;
11575|       |
11576|    236|        remaining -= 3;
11577|    236|        rv = ssl3_ConsumeHandshakeNumber(ss, &size, 3, &b, &length);
11578|    236|        if (rv != SECSuccess)
  ------------------
  |  Branch (11578:13): [True: 0, False: 236]
  ------------------
11579|      0|            goto loser; /* fatal alert already sent by ConsumeHandshake. */
11580|    236|        if (size == 0 || remaining < size)
  ------------------
  |  Branch (11580:13): [True: 1, False: 235]
  |  Branch (11580:26): [True: 55, False: 180]
  ------------------
11581|     56|            goto decode_loser;
11582|       |
11583|    180|        certItem.data = b;
11584|    180|        certItem.len = size;
11585|    180|        b += size;
11586|    180|        length -= size;
11587|    180|        remaining -= size;
11588|       |
11589|    180|        c = PORT_ArenaNew(ss->ssl3.peerCertArena, ssl3CertNode);
  ------------------
  |  |  153|    180|    (type *)PORT_ArenaAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   53|    180|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  |  |  ------------------
  ------------------
11590|    180|        if (c == NULL) {
  ------------------
  |  Branch (11590:13): [True: 0, False: 180]
  ------------------
11591|      0|            goto loser; /* don't send alerts on memory errors */
11592|      0|        }
11593|       |
11594|    180|        c->derCert = SECITEM_ArenaDupItem(ss->ssl3.peerCertArena,
  ------------------
  |  |  104|    180|#define SECITEM_ArenaDupItem SECITEM_ArenaDupItem_Util
  ------------------
11595|    180|                                          &certItem);
11596|    180|        if (c->derCert == NULL) {
  ------------------
  |  Branch (11596:13): [True: 0, False: 180]
  ------------------
11597|      0|            goto loser;
11598|      0|        }
11599|       |
11600|    180|        c->next = NULL;
11601|    180|        if (lastCert) {
  ------------------
  |  Branch (11601:13): [True: 127, False: 53]
  ------------------
11602|    127|            lastCert->next = c;
11603|    127|        } else {
11604|     53|            ss->ssl3.peerCertChain = c;
11605|     53|        }
11606|    180|        lastCert = c;
11607|    180|    }
11608|       |
11609|  3.83k|    SECKEY_UpdateCertPQG(ss->sec.peerCert);
11610|       |
11611|  3.83k|    if (!isServer &&
  ------------------
  |  Branch (11611:9): [True: 0, False: 3.83k]
  ------------------
11612|  3.83k|        ss->version < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|  3.83k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (11612:9): [True: 0, False: 0]
  ------------------
11613|  3.83k|        ssl3_ExtensionNegotiated(ss, ssl_cert_status_xtn)) {
  ------------------
  |  Branch (11613:9): [True: 0, False: 0]
  ------------------
11614|      0|        ss->ssl3.hs.ws = wait_certificate_status;
11615|      0|        rv = SECSuccess;
11616|  3.83k|    } else {
11617|  3.83k|        rv = ssl3_AuthCertificate(ss); /* sets ss->ssl3.hs.ws */
11618|  3.83k|    }
11619|       |
11620|  3.83k|    return rv;
11621|       |
11622|    172|ambiguous_err:
11623|    172|    errCode = PORT_GetError();
  ------------------
  |  |   62|    172|#define PORT_GetError PORT_GetError_Util
  ------------------
11624|    172|    switch (errCode) {
  ------------------
  |  Branch (11624:13): [True: 172, False: 0]
  ------------------
11625|      0|        case PR_OUT_OF_MEMORY_ERROR:
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  |  Branch (11625:9): [True: 0, False: 172]
  ------------------
11626|      0|        case SEC_ERROR_BAD_DATABASE:
  ------------------
  |  Branch (11626:9): [True: 0, False: 172]
  ------------------
11627|      0|        case SEC_ERROR_NO_MEMORY:
  ------------------
  |  Branch (11627:9): [True: 0, False: 172]
  ------------------
11628|      0|            if (isTLS) {
  ------------------
  |  Branch (11628:17): [True: 0, False: 0]
  ------------------
11629|      0|                desc = internal_error;
11630|      0|                goto alert_loser;
11631|      0|            }
11632|      0|            goto loser;
11633|    172|    }
11634|    172|    ssl3_SendAlertForCertError(ss, errCode);
11635|    172|    goto loser;
11636|       |
11637|    136|decode_loser:
11638|    136|    desc = isTLS ? decode_error : bad_certificate;
  ------------------
  |  Branch (11638:12): [True: 136, False: 0]
  ------------------
11639|       |
11640|    136|alert_loser:
11641|    136|    (void)SSL3_SendAlert(ss, alert_fatal, desc);
11642|       |
11643|    311|loser:
11644|    311|    (void)ssl_MapLowLevelError(errCode);
11645|    311|    return SECFailure;
11646|    136|}
ssl3_AuthCertificate:
11766|  3.83k|{
11767|  3.83k|    SECStatus rv;
11768|  3.83k|    PRBool isServer = ss->sec.isServer;
11769|  3.83k|    int errCode;
11770|       |
11771|  3.83k|    ss->ssl3.hs.authCertificatePending = PR_FALSE;
  ------------------
  |  |  438|  3.83k|#define PR_FALSE 0
  ------------------
11772|       |
11773|  3.83k|    PORT_Assert((ss->ssl3.hs.preliminaryInfo & ssl_preinfo_all) ==
  ------------------
  |  |  120|  3.83k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.83k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.83k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11774|  3.83k|                ssl_preinfo_all);
11775|       |
11776|  3.83k|    if (!ss->sec.isServer) {
  ------------------
  |  Branch (11776:9): [True: 0, False: 3.83k]
  ------------------
11777|       |        /* Set the |spki| used to verify the handshake. When verifying with a
11778|       |         * delegated credential (DC), this corresponds to the DC public key;
11779|       |         * otherwise it correspond to the public key of the peer's end-entity
11780|       |         * certificate. */
11781|      0|        rv = ssl3_HandleServerSpki(ss);
11782|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (11782:13): [True: 0, False: 0]
  ------------------
11783|       |            /* Alert sent and code set (if not SSL_ERROR_EXTRACT_PUBLIC_KEY_FAILURE).
11784|       |             * In either case, we're done here. */
11785|      0|            errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
11786|      0|            goto loser;
11787|      0|        }
11788|       |
11789|      0|        if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (11789:13): [True: 0, False: 0]
  ------------------
11790|      0|            ss->sec.authType = ss->ssl3.hs.kea_def->authKeyType;
11791|      0|            ss->sec.keaType = ss->ssl3.hs.kea_def->exchKeyType;
11792|      0|        }
11793|      0|    }
11794|       |
11795|       |    /*
11796|       |     * Ask caller-supplied callback function to validate cert chain.
11797|       |     */
11798|  3.83k|    rv = (SECStatus)(*ss->authCertificate)(ss->authCertificateArg, ss->fd,
11799|  3.83k|                                           PR_TRUE, isServer);
  ------------------
  |  |  437|  3.83k|#define PR_TRUE 1
  ------------------
11800|  3.83k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (11800:9): [True: 354, False: 3.47k]
  ------------------
11801|    354|        errCode = PORT_GetError();
  ------------------
  |  |   62|    354|#define PORT_GetError PORT_GetError_Util
  ------------------
11802|    354|        if (errCode == 0) {
  ------------------
  |  Branch (11802:13): [True: 0, False: 354]
  ------------------
11803|      0|            errCode = SSL_ERROR_BAD_CERTIFICATE;
11804|      0|        }
11805|    354|        if (rv != SECWouldBlock) {
  ------------------
  |  Branch (11805:13): [True: 354, False: 0]
  ------------------
11806|    354|            if (ss->handleBadCert) {
  ------------------
  |  Branch (11806:17): [True: 0, False: 354]
  ------------------
11807|      0|                rv = (*ss->handleBadCert)(ss->badCertArg, ss->fd);
11808|      0|            }
11809|    354|        }
11810|       |
11811|    354|        if (rv == SECWouldBlock) {
  ------------------
  |  Branch (11811:13): [True: 0, False: 354]
  ------------------
11812|      0|            if (ss->sec.isServer) {
  ------------------
  |  Branch (11812:17): [True: 0, False: 0]
  ------------------
11813|      0|                errCode = SSL_ERROR_FEATURE_NOT_SUPPORTED_FOR_SERVERS;
11814|      0|                goto loser;
11815|      0|            }
11816|       |
11817|      0|            ss->ssl3.hs.authCertificatePending = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
11818|      0|            rv = SECSuccess;
11819|      0|        }
11820|       |
11821|    354|        if (rv != SECSuccess) {
  ------------------
  |  Branch (11821:13): [True: 354, False: 0]
  ------------------
11822|    354|            ssl3_SendAlertForCertError(ss, errCode);
11823|    354|            goto loser;
11824|    354|        }
11825|    354|    }
11826|       |
11827|  3.47k|    if (ss->sec.ci.sid->peerCert) {
  ------------------
  |  Branch (11827:9): [True: 0, False: 3.47k]
  ------------------
11828|      0|        CERT_DestroyCertificate(ss->sec.ci.sid->peerCert);
11829|      0|    }
11830|  3.47k|    ss->sec.ci.sid->peerCert = CERT_DupCertificate(ss->sec.peerCert);
11831|       |
11832|  3.47k|    if (!ss->sec.isServer) {
  ------------------
  |  Branch (11832:9): [True: 0, False: 3.47k]
  ------------------
11833|      0|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (11833:13): [True: 0, False: 0]
  ------------------
11834|      0|            TLS13_SET_HS_STATE(ss, wait_cert_verify);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
11835|      0|        } else {
11836|       |            /* Ephemeral suites require ServerKeyExchange. */
11837|      0|            if (ss->ssl3.hs.kea_def->ephemeral) {
  ------------------
  |  Branch (11837:17): [True: 0, False: 0]
  ------------------
11838|       |                /* require server_key_exchange */
11839|      0|                ss->ssl3.hs.ws = wait_server_key;
11840|      0|            } else {
11841|       |                /* disallow server_key_exchange */
11842|      0|                ss->ssl3.hs.ws = wait_cert_request;
11843|       |                /* This is static RSA key exchange so set the key exchange
11844|       |                 * details to compensate for that. */
11845|      0|                ss->sec.keaKeyBits = ss->sec.authKeyBits;
11846|      0|                ss->sec.signatureScheme = ssl_sig_none;
11847|      0|                ss->sec.keaGroup = NULL;
11848|      0|            }
11849|      0|        }
11850|  3.47k|    } else {
11851|       |        /* Server */
11852|  3.47k|        if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  3.47k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (11852:13): [True: 3.47k, False: 0]
  ------------------
11853|  3.47k|            ss->ssl3.hs.ws = wait_client_key;
11854|  3.47k|        } else {
11855|      0|            TLS13_SET_HS_STATE(ss, wait_cert_verify);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
11856|      0|        }
11857|  3.47k|    }
11858|       |
11859|  3.47k|    PORT_Assert(rv == SECSuccess);
  ------------------
  |  |  120|  3.47k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.47k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.47k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11860|  3.47k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (11860:9): [True: 0, False: 3.47k]
  ------------------
11861|      0|        errCode = SEC_ERROR_LIBRARY_FAILURE;
11862|      0|        goto loser;
11863|      0|    }
11864|       |
11865|  3.47k|    return SECSuccess;
11866|       |
11867|    354|loser:
11868|    354|    (void)ssl_MapLowLevelError(errCode);
11869|    354|    return SECFailure;
11870|  3.47k|}
ssl3_RecordKeyLog:
12083|  58.6k|{
12084|  58.6k|#ifdef NSS_ALLOW_SSLKEYLOGFILE
12085|  58.6k|    SECStatus rv;
12086|  58.6k|    SECItem *keyData;
12087|       |    /* Longest label is "CLIENT_HANDSHAKE_TRAFFIC_SECRET", master secret is 48
12088|       |     * bytes which happens to be the largest in TLS 1.3 as well (SHA384).
12089|       |     * Maximum line length: "CLIENT_HANDSHAKE_TRAFFIC_SECRET" (31) + " " (1) +
12090|       |     * client_random (32*2) + " " (1) +
12091|       |     * traffic_secret (48*2) + "\n" (1) = 194. */
12092|  58.6k|    char buf[200];
12093|  58.6k|    unsigned int offset, len;
12094|       |
12095|  58.6k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  58.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.7k, False: 29.9k]
  |  |  |  |  |  Branch (208:7): [True: 29.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12096|       |
12097|  58.6k|    if (!ssl_keylog_iob)
  ------------------
  |  Branch (12097:9): [True: 58.6k, False: 0]
  ------------------
12098|  58.6k|        return;
12099|       |
12100|      0|    rv = PK11_ExtractKeyValue(secret);
12101|      0|    if (rv != SECSuccess)
  ------------------
  |  Branch (12101:9): [True: 0, False: 0]
  ------------------
12102|      0|        return;
12103|       |
12104|       |    /* keyData does not need to be freed. */
12105|      0|    keyData = PK11_GetKeyData(secret);
12106|      0|    if (!keyData || !keyData->data)
  ------------------
  |  Branch (12106:9): [True: 0, False: 0]
  |  Branch (12106:21): [True: 0, False: 0]
  ------------------
12107|      0|        return;
12108|       |
12109|      0|    len = strlen(label) + 1 +          /* label + space */
12110|      0|          SSL3_RANDOM_LENGTH * 2 + 1 + /* client random (hex) + space */
  ------------------
  |  |   24|      0|#define SSL3_RANDOM_LENGTH 32
  ------------------
12111|      0|          keyData->len * 2 + 1;        /* secret (hex) + newline */
12112|      0|    PORT_Assert(len <= sizeof(buf));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12113|      0|    if (len > sizeof(buf))
  ------------------
  |  Branch (12113:9): [True: 0, False: 0]
  ------------------
12114|      0|        return;
12115|       |
12116|       |    /* https://developer.mozilla.org/en/NSS_Key_Log_Format */
12117|       |
12118|       |    /* There could be multiple, concurrent writers to the
12119|       |     * keylog, so we have to do everything in a single call to
12120|       |     * fwrite. */
12121|       |
12122|      0|    strcpy(buf, label);
12123|      0|    offset = strlen(label);
12124|      0|    buf[offset++] += ' ';
12125|      0|    hexEncode(buf + offset, ss->ssl3.hs.client_random, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|      0|#define SSL3_RANDOM_LENGTH 32
  ------------------
12126|      0|    offset += SSL3_RANDOM_LENGTH * 2;
  ------------------
  |  |   24|      0|#define SSL3_RANDOM_LENGTH 32
  ------------------
12127|      0|    buf[offset++] = ' ';
12128|      0|    hexEncode(buf + offset, keyData->data, keyData->len);
12129|      0|    offset += keyData->len * 2;
12130|      0|    buf[offset++] = '\n';
12131|       |
12132|      0|    PORT_Assert(offset == len);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12133|       |
12134|      0|    PZ_Lock(ssl_keylog_lock);
  ------------------
  |  |  245|      0|#define PZ_Lock(k) PR_Lock((k))
  ------------------
12135|      0|    if (fwrite(buf, len, 1, ssl_keylog_iob) == 1)
  ------------------
  |  Branch (12135:9): [True: 0, False: 0]
  ------------------
12136|      0|        fflush(ssl_keylog_iob);
12137|      0|    PZ_Unlock(ssl_keylog_lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
12138|      0|#endif
12139|      0|}
ssl3_CacheWrappedSecret:
12219|  33.9k|{
12220|  33.9k|    PK11SymKey *wrappingKey = NULL;
12221|  33.9k|    PK11SlotInfo *symKeySlot;
12222|  33.9k|    void *pwArg = ss->pkcs11PinArg;
12223|  33.9k|    SECStatus rv = SECFailure;
12224|  33.9k|    PRBool isServer = ss->sec.isServer;
12225|  33.9k|    CK_MECHANISM_TYPE mechanism = CKM_INVALID_MECHANISM;
  ------------------
  |  |  155|  33.9k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
12226|       |
12227|  33.9k|    symKeySlot = PK11_GetSlotFromKey(secret);
12228|  33.9k|    if (!isServer) {
  ------------------
  |  Branch (12228:9): [True: 0, False: 33.9k]
  ------------------
12229|      0|        int wrapKeyIndex;
12230|      0|        int incarnation;
12231|       |
12232|       |        /* these next few functions are mere accessors and don't fail. */
12233|      0|        sid->u.ssl3.masterWrapIndex = wrapKeyIndex =
12234|      0|            PK11_GetCurrentWrapIndex(symKeySlot);
12235|      0|        PORT_Assert(wrapKeyIndex == 0); /* array has only one entry! */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12236|       |
12237|      0|        sid->u.ssl3.masterWrapSeries = incarnation =
12238|      0|            PK11_GetSlotSeries(symKeySlot);
12239|      0|        sid->u.ssl3.masterSlotID = PK11_GetSlotID(symKeySlot);
12240|      0|        sid->u.ssl3.masterModuleID = PK11_GetModuleID(symKeySlot);
12241|      0|        sid->u.ssl3.masterValid = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
12242|       |        /* Get the default wrapping key, for wrapping the master secret before
12243|       |         * placing it in the SID cache entry. */
12244|      0|        wrappingKey = PK11_GetWrapKey(symKeySlot, wrapKeyIndex,
12245|      0|                                      CKM_INVALID_MECHANISM, incarnation,
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
12246|      0|                                      pwArg);
12247|      0|        if (wrappingKey) {
  ------------------
  |  Branch (12247:13): [True: 0, False: 0]
  ------------------
12248|      0|            mechanism = PK11_GetMechanism(wrappingKey); /* can't fail. */
12249|      0|        } else {
12250|      0|            int keyLength;
12251|       |            /* if the wrappingKey doesn't exist, attempt to create it.
12252|       |             * Note: we intentionally ignore errors here.  If we cannot
12253|       |             * generate a wrapping key, it is not fatal to this SSL connection,
12254|       |             * but we will not be able to restart this session.
12255|       |             */
12256|      0|            mechanism = PK11_GetBestWrapMechanism(symKeySlot);
12257|      0|            keyLength = PK11_GetBestKeyLength(symKeySlot, mechanism);
12258|       |            /* Zero length means fixed key length algorithm, or error.
12259|       |             * It's ambiguous.
12260|       |             */
12261|      0|            wrappingKey = PK11_KeyGen(symKeySlot, mechanism, NULL,
12262|      0|                                      keyLength, pwArg);
12263|      0|            if (wrappingKey) {
  ------------------
  |  Branch (12263:17): [True: 0, False: 0]
  ------------------
12264|       |                /* The thread safety characteristics of PK11_[SG]etWrapKey is
12265|       |                 * abominable.  This protects against races in calling
12266|       |                 * PK11_SetWrapKey by dropping and re-acquiring the canonical
12267|       |                 * value once it is set.  The mutex in PK11_[SG]etWrapKey will
12268|       |                 * ensure that races produce the same value in the end. */
12269|      0|                PK11_SetWrapKey(symKeySlot, wrapKeyIndex, wrappingKey);
12270|      0|                PK11_FreeSymKey(wrappingKey);
12271|      0|                wrappingKey = PK11_GetWrapKey(symKeySlot, wrapKeyIndex,
12272|      0|                                              CKM_INVALID_MECHANISM, incarnation, pwArg);
  ------------------
  |  |  155|      0|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
12273|      0|                if (!wrappingKey) {
  ------------------
  |  Branch (12273:21): [True: 0, False: 0]
  ------------------
12274|      0|                    PK11_FreeSlot(symKeySlot);
12275|      0|                    return SECFailure;
12276|      0|                }
12277|      0|            }
12278|      0|        }
12279|  33.9k|    } else {
12280|       |        /* server socket using session cache. */
12281|  33.9k|        mechanism = PK11_GetBestWrapMechanism(symKeySlot);
12282|  33.9k|        if (mechanism != CKM_INVALID_MECHANISM) {
  ------------------
  |  |  155|  33.9k|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  |  Branch (12282:13): [True: 33.9k, False: 0]
  ------------------
12283|  33.9k|            wrappingKey =
12284|  33.9k|                ssl3_GetWrappingKey(ss, symKeySlot, mechanism, pwArg);
12285|  33.9k|            if (wrappingKey) {
  ------------------
  |  Branch (12285:17): [True: 33.9k, False: 0]
  ------------------
12286|  33.9k|                mechanism = PK11_GetMechanism(wrappingKey); /* can't fail. */
12287|  33.9k|            }
12288|  33.9k|        }
12289|  33.9k|    }
12290|       |
12291|  33.9k|    sid->u.ssl3.masterWrapMech = mechanism;
12292|  33.9k|    PK11_FreeSlot(symKeySlot);
12293|       |
12294|  33.9k|    if (wrappingKey) {
  ------------------
  |  Branch (12294:9): [True: 33.9k, False: 0]
  ------------------
12295|  33.9k|        SECItem wmsItem;
12296|       |
12297|  33.9k|        wmsItem.data = sid->u.ssl3.keys.wrapped_master_secret;
12298|  33.9k|        wmsItem.len = sizeof sid->u.ssl3.keys.wrapped_master_secret;
12299|  33.9k|        rv = PK11_WrapSymKey(mechanism, NULL, wrappingKey,
12300|  33.9k|                             secret, &wmsItem);
12301|       |        /* rv is examined below. */
12302|  33.9k|        sid->u.ssl3.keys.wrapped_master_secret_len = wmsItem.len;
12303|  33.9k|        PK11_FreeSymKey(wrappingKey);
12304|  33.9k|    }
12305|  33.9k|    return rv;
12306|  33.9k|}
ssl3_FillInCachedSID:
12476|  30.3k|{
12477|  30.3k|    PORT_Assert(secret);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12478|       |
12479|       |    /* fill in the sid */
12480|  30.3k|    sid->u.ssl3.cipherSuite = ss->ssl3.hs.cipher_suite;
12481|  30.3k|    sid->u.ssl3.policy = ss->ssl3.policy;
12482|  30.3k|    sid->version = ss->version;
12483|  30.3k|    sid->authType = ss->sec.authType;
12484|  30.3k|    sid->authKeyBits = ss->sec.authKeyBits;
12485|  30.3k|    sid->keaType = ss->sec.keaType;
12486|  30.3k|    sid->keaKeyBits = ss->sec.keaKeyBits;
12487|  30.3k|    if (ss->sec.keaGroup) {
  ------------------
  |  Branch (12487:9): [True: 24.9k, False: 5.37k]
  ------------------
12488|  24.9k|        sid->keaGroup = ss->sec.keaGroup->name;
12489|  24.9k|    } else {
12490|  5.37k|        sid->keaGroup = ssl_grp_none;
12491|  5.37k|    }
12492|  30.3k|    sid->sigScheme = ss->sec.signatureScheme;
12493|  30.3k|    sid->lastAccessTime = sid->creationTime = ssl_Time(ss);
12494|  30.3k|    sid->expirationTime = sid->creationTime + (ssl_ticket_lifetime * PR_USEC_PER_SEC);
  ------------------
  |  |   28|  30.3k|#define PR_USEC_PER_SEC     1000000L
  ------------------
12495|  30.3k|    if (sid->localCert) {
  ------------------
  |  Branch (12495:9): [True: 0, False: 30.3k]
  ------------------
12496|      0|        CERT_DestroyCertificate(sid->localCert);
12497|      0|    }
12498|  30.3k|    sid->localCert = CERT_DupCertificate(ss->sec.localCert);
12499|  30.3k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (12499:9): [True: 30.3k, False: 0]
  ------------------
12500|  30.3k|        sid->namedCurve = ss->sec.serverCert->namedCurve;
12501|  30.3k|    }
12502|       |
12503|  30.3k|    if (ss->xtnData.nextProtoState != SSL_NEXT_PROTO_NO_SUPPORT &&
  ------------------
  |  Branch (12503:9): [True: 0, False: 30.3k]
  ------------------
12504|  30.3k|        ss->xtnData.nextProto.data) {
  ------------------
  |  Branch (12504:9): [True: 0, False: 0]
  ------------------
12505|      0|        SECITEM_FreeItem(&sid->u.ssl3.alpnSelection, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sid->u.ssl3.alpnSelection, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
12506|      0|        if (SECITEM_CopyItem(
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (12506:13): [True: 0, False: 0]
  ------------------
12507|      0|                NULL, &sid->u.ssl3.alpnSelection, &ss->xtnData.nextProto) != SECSuccess) {
12508|      0|            return SECFailure; /* error already set. */
12509|      0|        }
12510|      0|    }
12511|       |
12512|       |    /* Copy the master secret (wrapped or unwrapped) into the sid */
12513|  30.3k|    return ssl3_CacheWrappedSecret(ss, ss->sec.ci.sid, secret);
12514|  30.3k|}
ssl_HashHandshakeMessageInt:
12577|   177k|{
12578|   177k|    PRUint8 hdr[4];
12579|   177k|    PRUint8 dtlsData[8];
12580|   177k|    SECStatus rv;
12581|       |
12582|   177k|    PRINT_BUF(50, (ss, "Hash handshake message:", b, length));
  ------------------
  |  |   74|   177k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 177k]
  |  |  ------------------
  |  |   75|   177k|    ssl_PrintBuf b
  ------------------
12583|       |
12584|   177k|    hdr[0] = (PRUint8)ct;
12585|   177k|    hdr[1] = (PRUint8)(length >> 16);
12586|   177k|    hdr[2] = (PRUint8)(length >> 8);
12587|   177k|    hdr[3] = (PRUint8)(length);
12588|       |
12589|   177k|    rv = updateHashes(ss, (unsigned char *)hdr, 4);
12590|   177k|    if (rv != SECSuccess)
  ------------------
  |  Branch (12590:9): [True: 0, False: 177k]
  ------------------
12591|      0|        return rv; /* err code already set. */
12592|       |
12593|       |    /* Extra data to simulate a complete DTLS handshake fragment */
12594|   177k|    if (IS_DTLS_1_OR_12(ss)) {
  ------------------
  |  |  893|   177k|#define IS_DTLS_1_OR_12(ss) (IS_DTLS(ss) && ss->version < SSL_LIBRARY_VERSION_TLS_1_3)
  |  |  ------------------
  |  |  |  |  892|   354k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (892:21): [True: 0, False: 177k]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |               #define IS_DTLS_1_OR_12(ss) (IS_DTLS(ss) && ss->version < SSL_LIBRARY_VERSION_TLS_1_3)
  |  |  ------------------
  |  |  |  |   21|   177k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  |  |  |  Branch (893:45): [True: 0, False: 0]
  |  |  ------------------
  ------------------
12595|       |        /* Sequence number */
12596|      0|        dtlsData[0] = MSB(dtlsSeq);
  ------------------
  |  |   94|      0|#define MSB(x) ((unsigned char)(((unsigned)(x)) >> 8))
  ------------------
12597|      0|        dtlsData[1] = LSB(dtlsSeq);
  ------------------
  |  |   93|      0|#define LSB(x) ((unsigned char)((x)&0xff))
  ------------------
12598|       |
12599|       |        /* Fragment offset */
12600|      0|        dtlsData[2] = 0;
12601|      0|        dtlsData[3] = 0;
12602|      0|        dtlsData[4] = 0;
12603|       |
12604|       |        /* Fragment length */
12605|      0|        dtlsData[5] = (PRUint8)(length >> 16);
12606|      0|        dtlsData[6] = (PRUint8)(length >> 8);
12607|      0|        dtlsData[7] = (PRUint8)(length);
12608|       |
12609|      0|        rv = updateHashes(ss, (unsigned char *)dtlsData, sizeof(dtlsData));
12610|      0|        if (rv != SECSuccess)
  ------------------
  |  Branch (12610:13): [True: 0, False: 0]
  ------------------
12611|      0|            return rv; /* err code already set. */
12612|      0|    }
12613|       |
12614|       |    /* The message body */
12615|   177k|    rv = updateHashes(ss, b, length);
12616|   177k|    if (rv != SECSuccess)
  ------------------
  |  Branch (12616:9): [True: 0, False: 177k]
  ------------------
12617|      0|        return rv; /* err code already set. */
12618|       |
12619|   177k|    return SECSuccess;
12620|   177k|}
ssl_HashHandshakeMessage:
12625|   177k|{
12626|   177k|    return ssl_HashHandshakeMessageInt(ss, ct, ss->ssl3.hs.recvMessageSeq,
12627|   177k|                                       b, length, ssl3_UpdateHandshakeHashes);
12628|   177k|}
ssl3_HandleHandshakeMessage:
12660|   320k|{
12661|   320k|    SECStatus rv = SECSuccess;
12662|   320k|    PRUint16 epoch;
12663|       |
12664|   320k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   320k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   480k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 159k, False: 160k]
  |  |  |  |  |  Branch (208:7): [True: 160k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12665|   320k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   320k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   480k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 159k, False: 160k]
  |  |  |  |  |  Branch (208:7): [True: 160k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12666|       |
12667|   320k|    SSL_TRC(30, ("%d: SSL3[%d]: handle handshake message: %s", SSL_GETPID(),
  ------------------
  |  |   71|   320k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 320k]
  |  |  ------------------
  |  |   72|   320k|    ssl_Trace b
  ------------------
12668|   320k|                 ss->fd, ssl3_DecodeHandshakeType(ss->ssl3.hs.msg_type)));
12669|       |
12670|       |    /* Start new handshake hashes when we start a new handshake. */
12671|   320k|    if (ss->ssl3.hs.msg_type == ssl_hs_client_hello) {
  ------------------
  |  Branch (12671:9): [True: 61.2k, False: 258k]
  ------------------
12672|  61.2k|        ssl3_RestartHandshakeHashes(ss);
12673|  61.2k|    }
12674|   320k|    switch (ss->ssl3.hs.msg_type) {
12675|     30|        case ssl_hs_hello_request:
  ------------------
  |  Branch (12675:9): [True: 30, False: 320k]
  ------------------
12676|     31|        case ssl_hs_hello_verify_request:
  ------------------
  |  Branch (12676:9): [True: 1, False: 320k]
  ------------------
12677|       |            /* We don't include hello_request and hello_verify_request messages
12678|       |             * in the handshake hashes */
12679|     31|            break;
12680|       |
12681|       |        /* Defer hashing of these messages until the message handlers. */
12682|  61.2k|        case ssl_hs_client_hello:
  ------------------
  |  Branch (12682:9): [True: 61.2k, False: 258k]
  ------------------
12683|  61.2k|        case ssl_hs_server_hello:
  ------------------
  |  Branch (12683:9): [True: 1, False: 320k]
  ------------------
12684|  64.3k|        case ssl_hs_certificate_verify:
  ------------------
  |  Branch (12684:9): [True: 3.06k, False: 317k]
  ------------------
12685|   117k|        case ssl_hs_finished:
  ------------------
  |  Branch (12685:9): [True: 53.0k, False: 267k]
  ------------------
12686|   117k|            break;
12687|       |
12688|   202k|        default:
  ------------------
  |  Branch (12688:9): [True: 202k, False: 117k]
  ------------------
12689|   202k|            if (!tls13_IsPostHandshake(ss)) {
  ------------------
  |  Branch (12689:17): [True: 60.7k, False: 141k]
  ------------------
12690|  60.7k|                rv = ssl_HashHandshakeMessage(ss, ss->ssl3.hs.msg_type, b, length);
12691|  60.7k|                if (rv != SECSuccess) {
  ------------------
  |  Branch (12691:21): [True: 0, False: 60.7k]
  ------------------
12692|      0|                    return SECFailure;
12693|      0|                }
12694|  60.7k|            }
12695|   320k|    }
12696|       |
12697|   320k|    PORT_SetError(0); /* each message starts with no error. */
  ------------------
  |  |   65|   320k|#define PORT_SetError PORT_SetError_Util
  ------------------
12698|       |
12699|   320k|    if (ss->ssl3.hs.ws == wait_certificate_status &&
  ------------------
  |  Branch (12699:9): [True: 0, False: 320k]
  ------------------
12700|   320k|        ss->ssl3.hs.msg_type != ssl_hs_certificate_status) {
  ------------------
  |  Branch (12700:9): [True: 0, False: 0]
  ------------------
12701|       |        /* If we negotiated the certificate_status extension then we deferred
12702|       |         * certificate validation until we get the CertificateStatus messsage.
12703|       |         * But the CertificateStatus message is optional. If the server did
12704|       |         * not send it then we need to validate the certificate now. If the
12705|       |         * server does send the CertificateStatus message then we will
12706|       |         * authenticate the certificate in ssl3_HandleCertificateStatus.
12707|       |         */
12708|      0|        rv = ssl3_AuthCertificate(ss); /* sets ss->ssl3.hs.ws */
12709|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (12709:13): [True: 0, False: 0]
  ------------------
12710|       |            /* This can't block. */
12711|      0|            PORT_Assert(PORT_GetError() != PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12712|      0|            return SECFailure;
12713|      0|        }
12714|      0|    }
12715|       |
12716|   320k|    epoch = ss->ssl3.crSpec->epoch;
12717|   320k|    switch (ss->ssl3.hs.msg_type) {
12718|  61.2k|        case ssl_hs_client_hello:
  ------------------
  |  Branch (12718:9): [True: 61.2k, False: 258k]
  ------------------
12719|  61.2k|            if (!ss->sec.isServer) {
  ------------------
  |  Branch (12719:17): [True: 0, False: 61.2k]
  ------------------
12720|      0|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12721|      0|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CLIENT_HELLO);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12722|      0|                return SECFailure;
12723|      0|            }
12724|  61.2k|            rv = ssl3_HandleClientHello(ss, b, length);
12725|  61.2k|            break;
12726|      1|        case ssl_hs_server_hello:
  ------------------
  |  Branch (12726:9): [True: 1, False: 320k]
  ------------------
12727|      1|            if (ss->sec.isServer) {
  ------------------
  |  Branch (12727:17): [True: 1, False: 0]
  ------------------
12728|      1|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12729|      1|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_SERVER_HELLO);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
12730|      1|                return SECFailure;
12731|      1|            }
12732|      0|            rv = ssl3_HandleServerHello(ss, b, length);
12733|      0|            break;
12734|   258k|        default:
  ------------------
  |  Branch (12734:9): [True: 258k, False: 61.2k]
  ------------------
12735|   258k|            if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|   258k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (12735:17): [True: 116k, False: 142k]
  ------------------
12736|   116k|                rv = ssl3_HandlePostHelloHandshakeMessage(ss, b, length);
12737|   142k|            } else {
12738|   142k|                rv = tls13_HandlePostHelloHandshakeMessage(ss, b, length);
12739|   142k|            }
12740|   258k|            break;
12741|   320k|    }
12742|   320k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|   640k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (12742:9): [True: 144k, False: 175k]
  ------------------
12743|   320k|        (epoch != ss->ssl3.crSpec->epoch) && !endOfRecord) {
  ------------------
  |  Branch (12743:9): [True: 143k, False: 804]
  |  Branch (12743:46): [True: 93, False: 143k]
  ------------------
12744|       |        /* If we changed read cipher states, there must not be any
12745|       |         * data in the input queue. */
12746|     93|        (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12747|     93|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_HANDSHAKE);
  ------------------
  |  |   65|     93|#define PORT_SetError PORT_SetError_Util
  ------------------
12748|     93|        return SECFailure;
12749|     93|    }
12750|       |    /* We consider the record to have been handled if SECSuccess or else WOULD_BLOCK is set
12751|       |     * Whoever set WOULD_BLOCK must handle any remaining actions required to finsih processing the record.
12752|       |     * e.g. by setting restartTarget.
12753|       |     */
12754|   320k|    if (IS_DTLS(ss) && (rv == SECSuccess || (rv == SECFailure && PR_GetError() == PR_WOULD_BLOCK_ERROR))) {
  ------------------
  |  |  892|   640k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 320k]
  |  |  ------------------
  ------------------
                  if (IS_DTLS(ss) && (rv == SECSuccess || (rv == SECFailure && PR_GetError() == PR_WOULD_BLOCK_ERROR))) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (12754:25): [True: 0, False: 0]
  |  Branch (12754:46): [True: 0, False: 0]
  |  Branch (12754:66): [True: 0, False: 0]
  ------------------
12755|       |        /* Increment the expected sequence number */
12756|      0|        ss->ssl3.hs.recvMessageSeq++;
12757|      0|    }
12758|       |
12759|       |    /* Taint the message so that it's easier to detect UAFs. */
12760|   320k|    PORT_Memset(b, 'N', length);
  ------------------
  |  |  182|   320k|#define PORT_Memset memset
  ------------------
12761|       |
12762|   320k|    return rv;
12763|   320k|}
ssl3_HandleNonApplicationData:
13425|   423k|{
13426|   423k|    SECStatus rv;
13427|       |
13428|       |    /* check for Token Presence */
13429|   423k|    if (!ssl3_ClientAuthTokenPresent(ss->sec.ci.sid)) {
  ------------------
  |  Branch (13429:9): [True: 0, False: 423k]
  ------------------
13430|      0|        PORT_SetError(SSL_ERROR_TOKEN_INSERTION_REMOVAL);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
13431|      0|        return SECFailure;
13432|      0|    }
13433|       |
13434|   423k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|   423k|    {                                                 \
  |  | 1408|   423k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 219k, False: 203k]
  |  |  ------------------
  |  | 1409|   219k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|   219k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   219k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 219k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|   219k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|   219k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|   219k|        }                                             \
  |  | 1412|   423k|    }
  ------------------
13435|       |
13436|       |    /* All the functions called in this switch MUST set error code if
13437|       |    ** they return SECFailure.
13438|       |    */
13439|   423k|    switch (rType) {
13440|  53.0k|        case ssl_ct_change_cipher_spec:
  ------------------
  |  Branch (13440:9): [True: 53.0k, False: 370k]
  ------------------
13441|  53.0k|            rv = ssl3_HandleChangeCipherSpecs(ss, databuf);
13442|  53.0k|            break;
13443|  10.8k|        case ssl_ct_alert:
  ------------------
  |  Branch (13443:9): [True: 10.8k, False: 412k]
  ------------------
13444|  10.8k|            rv = ssl3_HandleAlert(ss, databuf);
13445|  10.8k|            break;
13446|   359k|        case ssl_ct_handshake:
  ------------------
  |  Branch (13446:9): [True: 359k, False: 64.0k]
  ------------------
13447|   359k|            if (!IS_DTLS(ss)) {
  ------------------
  |  |  892|   359k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (13447:17): [True: 359k, False: 0]
  ------------------
13448|   359k|                rv = ssl3_HandleHandshake(ss, databuf);
13449|   359k|            } else {
13450|      0|                rv = dtls_HandleHandshake(ss, epoch, seqNum, databuf);
13451|      0|            }
13452|   359k|            break;
13453|      2|        case ssl_ct_ack:
  ------------------
  |  Branch (13453:9): [True: 2, False: 423k]
  ------------------
13454|      2|            if (IS_DTLS(ss) && tls13_MaybeTls13(ss)) {
  ------------------
  |  |  892|      4|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 2]
  |  |  ------------------
  ------------------
  |  Branch (13454:32): [True: 0, False: 0]
  ------------------
13455|      0|                rv = dtls13_HandleAck(ss, databuf);
13456|      0|                break;
13457|      0|            }
13458|       |        /* Fall through. */
13459|    144|        default:
  ------------------
  |  Branch (13459:9): [True: 142, False: 423k]
  ------------------
13460|       |            /* If a TLS implementation receives an unexpected record type,
13461|       |             * it MUST terminate the connection with an "unexpected_message"
13462|       |             * alert [RFC8446, Section 5].
13463|       |             *
13464|       |             * For TLS 1.3 the outer content type is checked before in
13465|       |             * tls13con.c/tls13_UnprotectRecord(),
13466|       |             * For DTLS 1.3 the outer content type is checked before in
13467|       |             * ssl3gthr.c/dtls_GatherData.
13468|       |             * The inner content types will be checked here.
13469|       |             *
13470|       |             * In DTLS generally invalid records SHOULD be silently discarded,
13471|       |             * no alert is sent [RFC6347, Section 4.1.2.7].
13472|       |             */
13473|    144|            if (!IS_DTLS(ss)) {
  ------------------
  |  |  892|    144|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (13473:17): [True: 144, False: 0]
  ------------------
13474|    144|                SSL3_SendAlert(ss, alert_fatal, unexpected_message);
13475|    144|            }
13476|    144|            PORT_SetError(SSL_ERROR_RX_UNKNOWN_RECORD_TYPE);
  ------------------
  |  |   65|    144|#define PORT_SetError PORT_SetError_Util
  ------------------
13477|    144|            SSL_DBG(("%d: SSL3[%d]: bogus content type=%d",
  ------------------
  |  |   87|    144|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 144]
  |  |  ------------------
  |  |   88|    144|    ssl_Trace b
  ------------------
13478|    144|                     SSL_GETPID(), ss->fd, rType));
13479|    144|            rv = SECFailure;
13480|    144|            break;
13481|   423k|    }
13482|       |
13483|   423k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|   423k|    {                                                \
  |  | 1415|   423k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 219k, False: 203k]
  |  |  ------------------
  |  | 1416|   423k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|   219k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|   423k|    }
  ------------------
13484|   423k|    return rv;
13485|   423k|}
ssl3_HandleRecord:
13544|   583k|{
13545|   583k|    SECStatus rv = SECFailure;
13546|   583k|    PRBool isTLS, isTLS13;
13547|   583k|    DTLSEpoch epoch;
13548|   583k|    ssl3CipherSpec *spec = NULL;
13549|   583k|    PRUint16 recordSizeLimit, cTextSizeLimit;
13550|   583k|    PRBool outOfOrderSpec = PR_FALSE;
  ------------------
  |  |  438|   583k|#define PR_FALSE 0
  ------------------
13551|   583k|    SSLContentType rType;
13552|   583k|    sslBuffer *plaintext = &ss->gs.buf;
13553|   583k|    SSL3AlertDescription alert = internal_error;
13554|   583k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   583k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   884k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 282k, False: 301k]
  |  |  |  |  |  Branch (208:7): [True: 301k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13555|       |
13556|       |    /* check for Token Presence */
13557|   583k|    if (!ssl3_ClientAuthTokenPresent(ss->sec.ci.sid)) {
  ------------------
  |  Branch (13557:9): [True: 0, False: 583k]
  ------------------
13558|      0|        PORT_SetError(SSL_ERROR_TOKEN_INSERTION_REMOVAL);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
13559|      0|        return SECFailure;
13560|      0|    }
13561|       |
13562|       |    /* Clear out the buffer in case this exits early.  Any data then won't be
13563|       |     * processed twice. */
13564|   583k|    plaintext->len = 0;
13565|       |
13566|       |    /* We're waiting for another ClientHello, which will appear unencrypted.
13567|       |     * Use the content type to tell whether this should be discarded. */
13568|   583k|    if (ss->ssl3.hs.zeroRttIgnore == ssl_0rtt_ignore_hrr &&
  ------------------
  |  Branch (13568:9): [True: 481, False: 582k]
  ------------------
13569|   583k|        cText->hdr[0] == ssl_ct_application_data) {
  ------------------
  |  Branch (13569:9): [True: 194, False: 287]
  ------------------
13570|    194|        PORT_Assert(ss->ssl3.hs.ws == wait_client_hello);
  ------------------
  |  |  120|    194|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    194|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 194, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13571|    194|        return SECSuccess;
13572|    194|    }
13573|       |
13574|   582k|    ssl_GetSpecReadLock(ss); /******************************************/
  ------------------
  |  | 1422|   582k|    {                                           \
  |  | 1423|   582k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 301k, False: 281k]
  |  |  ------------------
  |  | 1424|   582k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|   301k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|   582k|    }
  ------------------
13575|   582k|    spec = ssl3_GetCipherSpec(ss, cText);
13576|   582k|    if (!spec) {
  ------------------
  |  Branch (13576:9): [True: 0, False: 582k]
  ------------------
13577|      0|        PORT_Assert(IS_DTLS(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13578|      0|        ssl_ReleaseSpecReadLock(ss); /*****************************/
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
13579|      0|        return SECSuccess;
13580|      0|    }
13581|   582k|    if (spec != ss->ssl3.crSpec) {
  ------------------
  |  Branch (13581:9): [True: 0, False: 582k]
  ------------------
13582|      0|        PORT_Assert(IS_DTLS(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13583|      0|        SSL_TRC(3, ("%d: DTLS[%d]: Handling out-of-epoch record from epoch=%d",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
13584|      0|                    SSL_GETPID(), ss->fd, spec->epoch));
13585|      0|        outOfOrderSpec = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
13586|      0|    }
13587|   582k|    isTLS = (PRBool)(spec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|   582k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
13588|   582k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   582k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 582k]
  |  |  ------------------
  ------------------
13589|      0|        if (dtls13_MaskSequenceNumber(ss, spec, cText->hdr,
  ------------------
  |  Branch (13589:13): [True: 0, False: 0]
  ------------------
13590|      0|                                      SSL_BUFFER_BASE(cText->buf), SSL_BUFFER_LEN(cText->buf)) != SECSuccess) {
  ------------------
  |  |   35|      0|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
                                                    SSL_BUFFER_BASE(cText->buf), SSL_BUFFER_LEN(cText->buf)) != SECSuccess) {
  ------------------
  |  |   36|      0|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
13591|      0|            ssl_ReleaseSpecReadLock(ss); /*****************************/
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
13592|       |            /* code already set. */
13593|      0|            return SECFailure;
13594|      0|        }
13595|      0|        if (!dtls_IsRelevant(ss, spec, cText, &cText->seqNum)) {
  ------------------
  |  Branch (13595:13): [True: 0, False: 0]
  ------------------
13596|      0|            ssl_ReleaseSpecReadLock(ss); /*****************************/
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
13597|      0|            return SECSuccess;
13598|      0|        }
13599|   582k|    } else {
13600|   582k|        cText->seqNum = spec->nextSeqNum;
13601|   582k|    }
13602|   582k|    if (cText->seqNum >= spec->cipherDef->max_records) {
  ------------------
  |  Branch (13602:9): [True: 0, False: 582k]
  ------------------
13603|      0|        ssl_ReleaseSpecReadLock(ss); /*****************************/
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
13604|      0|        SSL_TRC(3, ("%d: SSL[%d]: read sequence number at limit 0x%0llx",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
13605|      0|                    SSL_GETPID(), ss->fd, cText->seqNum));
13606|      0|        PORT_SetError(SSL_ERROR_TOO_MANY_RECORDS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
13607|      0|        return SECFailure;
13608|      0|    }
13609|       |
13610|   582k|    isTLS13 = (PRBool)(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |   21|   582k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
13611|   582k|    recordSizeLimit = spec->recordSizeLimit;
13612|   582k|    cTextSizeLimit = recordSizeLimit;
13613|   582k|    cTextSizeLimit += (isTLS13) ? TLS_1_3_MAX_EXPANSION : TLS_1_2_MAX_EXPANSION;
  ------------------
  |  |   37|   318k|#define TLS_1_3_MAX_EXPANSION (255 + 1)
  ------------------
                  cTextSizeLimit += (isTLS13) ? TLS_1_3_MAX_EXPANSION : TLS_1_2_MAX_EXPANSION;
  ------------------
  |  |   36|   847k|#define TLS_1_2_MAX_EXPANSION 2048
  ------------------
  |  Branch (13613:23): [True: 318k, False: 264k]
  ------------------
13614|       |
13615|       |    /* Check if the specified recordSizeLimit and the RFC8446 specified max
13616|       |     * expansion are respected. recordSizeLimit is probably at the default for
13617|       |     * the first (hello) handshake message and then set to a smaller size by
13618|       |     * the Record Size Limit Extension.
13619|       |     * Stricter expansion size checks dependent on implemented cipher suites
13620|       |     * are performed in ssl3con.c/ssl3_UnprotectRecord() OR
13621|       |     * tls13con.c/tls13_UnprotextRecord().
13622|       |     * After Decryption the plaintext size is checked (l. 13424). This also
13623|       |     * applies to unencrypted records. */
13624|   582k|    if (cText->buf->len > cTextSizeLimit) {
  ------------------
  |  Branch (13624:9): [True: 0, False: 582k]
  ------------------
13625|      0|        ssl_ReleaseSpecReadLock(ss); /*****************************/
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
13626|       |        /* Drop DTLS Record Errors silently [RFC6347, Section 4.1.2.7] */
13627|      0|        if (IS_DTLS(ss)) {
  ------------------
  |  |  892|      0|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 0]
  |  |  ------------------
  ------------------
13628|      0|            return SECSuccess;
13629|      0|        }
13630|      0|        SSL3_SendAlert(ss, alert_fatal, record_overflow);
13631|      0|        PORT_SetError(SSL_ERROR_RX_RECORD_TOO_LONG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
13632|      0|        return SECFailure;
13633|      0|    }
13634|       |
13635|   582k|#ifdef DEBUG
13636|       |    /* In debug builds the gather buffers are freed after the handling of each
13637|       |     * record for advanced ASAN coverage. Allocate the buffer again to the
13638|       |     * maximum possibly needed size as on gather initialization in
13639|       |     * ssl3gthr.c/ssl3_InitGather(). */
13640|   582k|    PR_ASSERT(sslBuffer_Grow(plaintext, TLS_1_2_MAX_CTEXT_LENGTH) == SECSuccess);
  ------------------
  |  |  208|   582k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 582k, False: 0]
  |  |  ------------------
  ------------------
13641|   582k|#endif
13642|       |    /* This replaces a dynamic plaintext buffer size check, since the buffer is
13643|       |     * allocated to the maximum size in ssl3gthr.c/ssl3_InitGather(). The buffer
13644|       |     * was always grown to the maximum size at first record gathering before. */
13645|   582k|    PR_ASSERT(plaintext->space >= cTextSizeLimit);
  ------------------
  |  |  208|   582k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 582k, False: 0]
  |  |  ------------------
  ------------------
13646|       |
13647|       |    /* Most record types aside from protected TLS 1.3 records carry the content
13648|       |     * type in the first octet. TLS 1.3 will override this value later. */
13649|   582k|    rType = cText->hdr[0];
13650|       |    /* Encrypted application data records could arrive before the handshake
13651|       |     * completes in DTLS 1.3. These can look like valid TLS 1.2 application_data
13652|       |     * records in epoch 0, which is never valid. Pretend they didn't decrypt. */
13653|   582k|    if (spec->epoch == 0 && ((IS_DTLS(ss) &&
  ------------------
  |  |  892|  82.2k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 41.1k]
  |  |  ------------------
  ------------------
  |  Branch (13653:9): [True: 41.1k, False: 541k]
  ------------------
13654|  41.1k|                              dtls_IsDtls13Ciphertext(0, rType)) ||
  ------------------
  |  Branch (13654:31): [True: 0, False: 0]
  ------------------
13655|  41.1k|                             rType == ssl_ct_application_data)) {
  ------------------
  |  Branch (13655:30): [True: 14, False: 41.1k]
  ------------------
13656|     14|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_APPLICATION_DATA);
  ------------------
  |  |   65|     14|#define PORT_SetError PORT_SetError_Util
  ------------------
13657|     14|        alert = unexpected_message;
13658|     14|        rv = SECFailure;
13659|   582k|    } else {
13660|   582k|#ifdef UNSAFE_FUZZER_MODE
13661|   582k|        rv = Null_Cipher(NULL, plaintext->buf, &plaintext->len,
13662|   582k|                         plaintext->space, cText->buf->buf, cText->buf->len);
13663|       |#else
13664|       |        /* IMPORTANT:
13665|       |         * Unprotect functions MUST NOT send alerts
13666|       |         * because we still hold the spec read lock. Instead, if they
13667|       |         * return SECFailure, they set *alert to the alert to be sent.
13668|       |         * Additionaly, this is used to silently drop DTLS encryption/record
13669|       |         * errors/alerts using the error handling below as suggested in the
13670|       |         * DTLS specification [RFC6347, Section 4.1.2.7]. */
13671|       |        if (spec->cipherDef->cipher == cipher_null && cText->buf->len == 0) {
13672|       |            /* Handle a zero-length unprotected record
13673|       |             * In this case, we treat it as a no-op and let later functions decide
13674|       |             * whether to ignore or alert accordingly. */
13675|       |            PR_ASSERT(plaintext->len == 0);
13676|       |            rv = SECSuccess;
13677|       |        } else if (spec->version < SSL_LIBRARY_VERSION_TLS_1_3 || spec->epoch == 0) {
13678|       |            rv = ssl3_UnprotectRecord(ss, spec, cText, plaintext, &alert);
13679|       |        } else {
13680|       |            rv = tls13_UnprotectRecord(ss, spec, cText, plaintext, &rType,
13681|       |                                       &alert);
13682|       |        }
13683|       |#endif
13684|   582k|    }
13685|       |
13686|       |    /* Error/Alert handling for ssl3/tls13_UnprotectRecord */
13687|   582k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (13687:9): [True: 14, False: 582k]
  ------------------
13688|     14|        ssl_ReleaseSpecReadLock(ss); /***************************/
  ------------------
  |  | 1427|     14|    {                                             \
  |  | 1428|     14|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 11, False: 3]
  |  |  ------------------
  |  | 1429|     14|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|     11|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|     14|    }
  ------------------
13689|       |
13690|     14|        SSL_DBG(("%d: SSL3[%d]: decryption failed", SSL_GETPID(), ss->fd));
  ------------------
  |  |   87|     14|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 14]
  |  |  ------------------
  |  |   88|     14|    ssl_Trace b
  ------------------
13691|       |
13692|       |        /* Ensure that we don't process this data again. */
13693|     14|        plaintext->len = 0;
13694|       |
13695|       |        /* Ignore a CCS if compatibility mode is negotiated.  Note that this
13696|       |         * will fail if the server fails to negotiate compatibility mode in a
13697|       |         * 0-RTT session that is resumed from a session that did negotiate it.
13698|       |         * We don't care about that corner case right now. */
13699|     14|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|     28|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (13699:13): [True: 1, False: 13]
  ------------------
13700|     14|            cText->hdr[0] == ssl_ct_change_cipher_spec &&
  ------------------
  |  Branch (13700:13): [True: 0, False: 1]
  ------------------
13701|     14|            ss->ssl3.hs.ws != idle_handshake &&
  ------------------
  |  Branch (13701:13): [True: 0, False: 0]
  ------------------
13702|     14|            cText->buf->len == 1 &&
  ------------------
  |  Branch (13702:13): [True: 0, False: 0]
  ------------------
13703|     14|            cText->buf->buf[0] == change_cipher_spec_choice) {
  ------------------
  |  Branch (13703:13): [True: 0, False: 0]
  ------------------
13704|      0|            if (!ss->ssl3.hs.rejectCcs) {
  ------------------
  |  Branch (13704:17): [True: 0, False: 0]
  ------------------
13705|       |                /* Allow only the first CCS. */
13706|      0|                ss->ssl3.hs.rejectCcs = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
13707|      0|                return SECSuccess;
13708|      0|            } else {
13709|      0|                alert = unexpected_message;
13710|      0|                PORT_SetError(SSL_ERROR_RX_MALFORMED_CHANGE_CIPHER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
13711|      0|            }
13712|      0|        }
13713|       |
13714|       |        /* All errors/alerts that might occur during unprotection are related
13715|       |         * to invalid records (e.g. invalid formatting, length, MAC, ...).
13716|       |         * Following the DTLS specification such errors/alerts SHOULD be
13717|       |         * dropped silently [RFC9147, Section 4.5.2].
13718|       |         * This is done below. */
13719|       |
13720|     14|        if ((IS_DTLS(ss) && !dtls13_AeadLimitReached(spec)) ||
  ------------------
  |  |  892|     28|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 14]
  |  |  ------------------
  ------------------
  |  Branch (13720:29): [True: 0, False: 0]
  ------------------
13721|     14|            (!IS_DTLS(ss) && ss->sec.isServer &&
  ------------------
  |  |  892|     28|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (13721:14): [True: 14, False: 0]
  |  Branch (13721:30): [True: 14, False: 0]
  ------------------
13722|     14|             ss->ssl3.hs.zeroRttIgnore == ssl_0rtt_ignore_trial)) {
  ------------------
  |  Branch (13722:14): [True: 0, False: 14]
  ------------------
13723|       |            /* Silently drop the packet unless we set ss->ssl3.fatalAlertSent.
13724|       |             * (Manually or by using functions like
13725|       |             * SSL3_SendAlert(.., alert_fatal,..))
13726|       |             * This is not currently used in the unprotection functions since
13727|       |             * all TLS and DTLS errors are propagated to this handler. */
13728|      0|            if (ss->ssl3.fatalAlertSent) {
  ------------------
  |  Branch (13728:17): [True: 0, False: 0]
  ------------------
13729|      0|                return SECFailure;
13730|      0|            }
13731|      0|            return SECSuccess;
13732|      0|        }
13733|       |
13734|     14|        int errCode = PORT_GetError();
  ------------------
  |  |   62|     14|#define PORT_GetError PORT_GetError_Util
  ------------------
13735|     14|        SSL3_SendAlert(ss, alert_fatal, alert);
13736|       |        /* Reset the error code in case SSL3_SendAlert called
13737|       |         * PORT_SetError(). */
13738|     14|        PORT_SetError(errCode);
  ------------------
  |  |   65|     14|#define PORT_SetError PORT_SetError_Util
  ------------------
13739|     14|        return SECFailure;
13740|     14|    }
13741|       |
13742|       |    /* SECSuccess */
13743|   582k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   582k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 582k]
  |  |  ------------------
  ------------------
13744|      0|        dtls_RecordSetRecvd(&spec->recvdRecords, cText->seqNum);
13745|      0|        spec->nextSeqNum = PR_MAX(spec->nextSeqNum, cText->seqNum + 1);
  ------------------
  |  |  159|      0|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
13746|   582k|    } else {
13747|   582k|        ++spec->nextSeqNum;
13748|   582k|    }
13749|   582k|    epoch = spec->epoch;
13750|       |
13751|   582k|    ssl_ReleaseSpecReadLock(ss); /*****************************************/
  ------------------
  |  | 1427|   582k|    {                                             \
  |  | 1428|   582k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 301k, False: 281k]
  |  |  ------------------
  |  | 1429|   582k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|   301k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|   582k|    }
  ------------------
13752|       |
13753|       |    /*
13754|       |     * The decrypted data is now in plaintext.
13755|       |     */
13756|       |
13757|       |    /* IMPORTANT: We are in DTLS 1.3 mode and we have processed something
13758|       |     * from the wrong epoch. Divert to a divert processing function to make
13759|       |     * sure we don't accidentally use the data unsafely. */
13760|       |
13761|       |    /* We temporary allowed reading the records from the previous epoch n-1
13762|       |    until the moment we get a message from the new epoch n. */
13763|       |
13764|   582k|    if (outOfOrderSpec) {
  ------------------
  |  Branch (13764:9): [True: 0, False: 582k]
  ------------------
13765|      0|        PORT_Assert(IS_DTLS(ss) && ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13766|      0|        ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|      0|    {                                                 \
  |  | 1408|      0|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1409|      0|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|      0|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|      0|        }                                             \
  |  | 1412|      0|    }
  ------------------
13767|      0|        if (ss->ssl3.hs.allowPreviousEpoch && spec->epoch == ss->ssl3.crSpec->epoch - 1) {
  ------------------
  |  Branch (13767:13): [True: 0, False: 0]
  |  Branch (13767:47): [True: 0, False: 0]
  ------------------
13768|      0|            SSL_TRC(30, ("%d: DTLS13[%d]: Out of order message %d is accepted",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
13769|      0|                         SSL_GETPID(), ss->fd, spec->epoch));
13770|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
13771|      0|        } else {
13772|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
13773|      0|            return dtls13_HandleOutOfEpochRecord(ss, spec, rType, plaintext);
13774|      0|        }
13775|   582k|    } else {
13776|   582k|        ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|   582k|    {                                                 \
  |  | 1408|   582k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 301k, False: 281k]
  |  |  ------------------
  |  | 1409|   301k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|   301k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   301k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 301k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|   301k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|   301k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|   301k|        }                                             \
  |  | 1412|   582k|    }
  ------------------
13777|       |        /* Forbid (application) messages from the previous epoch.
13778|       |           From now, messages that arrive out of order will be discarded. */
13779|   582k|        ss->ssl3.hs.allowPreviousEpoch = PR_FALSE;
  ------------------
  |  |  438|   582k|#define PR_FALSE 0
  ------------------
13780|   582k|        ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|   582k|    {                                                \
  |  | 1415|   582k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 301k, False: 281k]
  |  |  ------------------
  |  | 1416|   582k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|   301k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|   582k|    }
  ------------------
13781|   582k|    }
13782|       |
13783|       |    /* Check the length of the plaintext. */
13784|   582k|    if (isTLS && plaintext->len > recordSizeLimit) {
  ------------------
  |  Branch (13784:9): [True: 582k, False: 0]
  |  Branch (13784:18): [True: 10, False: 582k]
  ------------------
13785|     10|        plaintext->len = 0;
13786|       |        /* Drop DTLS Record Errors silently [RFC6347, Section 4.1.2.7] */
13787|     10|        if (IS_DTLS(ss)) {
  ------------------
  |  |  892|     10|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 10]
  |  |  ------------------
  ------------------
13788|      0|            return SECSuccess;
13789|      0|        }
13790|     10|        SSL3_SendAlert(ss, alert_fatal, record_overflow);
13791|     10|        PORT_SetError(SSL_ERROR_RX_RECORD_TOO_LONG);
  ------------------
  |  |   65|     10|#define PORT_SetError PORT_SetError_Util
  ------------------
13792|     10|        return SECFailure;
13793|     10|    }
13794|       |
13795|       |    /* Application data records are processed by the caller of this
13796|       |    ** function, not by this function.
13797|       |    */
13798|   582k|    if (rType == ssl_ct_application_data) {
  ------------------
  |  Branch (13798:9): [True: 159k, False: 423k]
  ------------------
13799|   159k|        if (ss->firstHsDone)
  ------------------
  |  Branch (13799:13): [True: 159k, False: 7]
  ------------------
13800|   159k|            return SECSuccess;
13801|      7|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|     14|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (13801:13): [True: 4, False: 3]
  ------------------
13802|      7|            ss->sec.isServer &&
  ------------------
  |  Branch (13802:13): [True: 4, False: 0]
  ------------------
13803|      7|            ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted) {
  ------------------
  |  Branch (13803:13): [True: 0, False: 4]
  ------------------
13804|      0|            return tls13_HandleEarlyApplicationData(ss, plaintext);
13805|      0|        }
13806|      7|        plaintext->len = 0;
13807|      7|        (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
13808|      7|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_APPLICATION_DATA);
  ------------------
  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  ------------------
13809|      7|        return SECFailure;
13810|      7|    }
13811|       |
13812|   423k|    rv = ssl3_HandleNonApplicationData(ss, rType, epoch, cText->seqNum,
13813|   423k|                                       plaintext);
13814|       |
13815|   423k|#ifdef DEBUG
13816|       |    /* In Debug builds free and zero gather plaintext buffer after its content
13817|       |     * has been used/copied for advanced ASAN coverage/utilization.
13818|       |     * This frees buffer for non application data records, for application data
13819|       |     * records it is freed in sslsecur.c/DoRecv(). */
13820|   423k|    sslBuffer_Clear(&ss->gs.buf);
13821|   423k|#endif
13822|       |
13823|   423k|    return rv;
13824|   582k|}
ssl_InitSecState:
13832|  9.71k|{
13833|  9.71k|    sec->authType = ssl_auth_null;
13834|  9.71k|    sec->authKeyBits = 0;
13835|  9.71k|    sec->signatureScheme = ssl_sig_none;
13836|  9.71k|    sec->keaType = ssl_kea_null;
13837|  9.71k|    sec->keaKeyBits = 0;
13838|  9.71k|    sec->keaGroup = NULL;
13839|  9.71k|}
ssl3_InitState:
13843|  9.71k|{
13844|  9.71k|    SECStatus rv;
13845|       |
13846|  9.71k|    ss->ssl3.policy = SSL_ALLOWED;
  ------------------
  |  |  700|  9.71k|#define SSL_ALLOWED 1
  ------------------
13847|       |
13848|  9.71k|    ssl_InitSecState(&ss->sec);
13849|       |
13850|  9.71k|    ssl_GetSpecWriteLock(ss);
  ------------------
  |  | 1435|  9.71k|    {                                            \
  |  | 1436|  9.71k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1437|  9.71k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  9.71k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  9.71k|    }
  ------------------
13851|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.cipherSpecs);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13852|  9.71k|    rv = ssl_SetupNullCipherSpec(ss, ssl_secret_read);
13853|  9.71k|    rv |= ssl_SetupNullCipherSpec(ss, ssl_secret_write);
13854|  9.71k|    ss->ssl3.pwSpec = ss->ssl3.prSpec = NULL;
13855|  9.71k|    ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|  9.71k|    {                                              \
  |  | 1441|  9.71k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1442|  9.71k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  9.71k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  9.71k|    }
  ------------------
13856|  9.71k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (13856:9): [True: 0, False: 9.71k]
  ------------------
13857|       |        /* Rely on ssl_CreateNullCipherSpec() to set error code. */
13858|      0|        return SECFailure;
13859|      0|    }
13860|       |
13861|  9.71k|    ss->ssl3.hs.sendingSCSV = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
13862|  9.71k|    ss->ssl3.hs.preliminaryInfo = 0;
13863|  9.71k|    ss->ssl3.hs.ws = (ss->sec.isServer) ? wait_client_hello : idle_handshake;
  ------------------
  |  Branch (13863:22): [True: 0, False: 9.71k]
  ------------------
13864|       |
13865|  9.71k|    ssl3_ResetExtensionData(&ss->xtnData, ss);
13866|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.remoteExtensions);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13867|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.echOuterExtensions);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13868|  9.71k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  9.71k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 9.71k]
  |  |  ------------------
  ------------------
13869|      0|        ss->ssl3.hs.sendMessageSeq = 0;
13870|      0|        ss->ssl3.hs.recvMessageSeq = 0;
13871|      0|        ss->ssl3.hs.rtTimer->timeout = DTLS_RETRANSMIT_INITIAL_MS;
  ------------------
  |  |  126|      0|#define DTLS_RETRANSMIT_INITIAL_MS 50
  ------------------
13872|      0|        ss->ssl3.hs.rtRetries = 0;
13873|      0|        ss->ssl3.hs.recvdHighWater = -1;
13874|      0|        PR_INIT_CLIST(&ss->ssl3.hs.lastMessageFlight);
  ------------------
  |  |  100|      0|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      0|    (_l)->next = (_l); \
  |  |  102|      0|    (_l)->prev = (_l); \
  |  |  103|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13875|      0|        dtls_SetMTU(ss, 0); /* Set the MTU to the highest plateau */
13876|      0|    }
13877|       |
13878|  9.71k|    ss->ssl3.hs.currentSecret = NULL;
13879|  9.71k|    ss->ssl3.hs.resumptionMasterSecret = NULL;
13880|  9.71k|    ss->ssl3.hs.dheSecret = NULL;
13881|  9.71k|    ss->ssl3.hs.clientEarlyTrafficSecret = NULL;
13882|  9.71k|    ss->ssl3.hs.clientHsTrafficSecret = NULL;
13883|  9.71k|    ss->ssl3.hs.serverHsTrafficSecret = NULL;
13884|  9.71k|    ss->ssl3.hs.clientTrafficSecret = NULL;
13885|  9.71k|    ss->ssl3.hs.serverTrafficSecret = NULL;
13886|  9.71k|    ss->ssl3.hs.echHpkeCtx = NULL;
13887|  9.71k|    ss->ssl3.hs.greaseEchSize = 100;
13888|  9.71k|    ss->ssl3.hs.echAccepted = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
13889|  9.71k|    ss->ssl3.hs.echDecided = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
13890|       |
13891|  9.71k|    ss->ssl3.hs.clientAuthSignatureSchemes = NULL;
13892|  9.71k|    ss->ssl3.hs.clientAuthSignatureSchemesLen = 0;
13893|       |
13894|  9.71k|    PORT_Assert(!ss->ssl3.hs.messages.buf && !ss->ssl3.hs.messages.space);
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.71k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
13895|  9.71k|    ss->ssl3.hs.messages.buf = NULL;
13896|  9.71k|    ss->ssl3.hs.messages.space = 0;
13897|       |
13898|  9.71k|    ss->ssl3.hs.receivedNewSessionTicket = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
13899|  9.71k|    PORT_Memset(&ss->ssl3.hs.newSessionTicket, 0,
  ------------------
  |  |  182|  9.71k|#define PORT_Memset memset
  ------------------
13900|  9.71k|                sizeof(ss->ssl3.hs.newSessionTicket));
13901|       |
13902|  9.71k|    ss->ssl3.hs.zeroRttState = ssl_0rtt_none;
13903|  9.71k|    return SECSuccess;
13904|  9.71k|}
ssl3_CipherPrefSet:
13976|   690k|{
13977|   690k|    ssl3CipherSuiteCfg *suite;
13978|       |
13979|   690k|    suite = ssl_LookupCipherSuiteCfgMutable(which, ss->cipherSuites);
13980|   690k|    if (suite == NULL) {
  ------------------
  |  Branch (13980:9): [True: 0, False: 690k]
  ------------------
13981|      0|        return SECFailure; /* err code was set by ssl_LookupCipherSuiteCfg */
13982|      0|    }
13983|   690k|    suite->enabled = enabled;
13984|   690k|    return SECSuccess;
13985|   690k|}
ssl3_CipherPrefGet:
13989|  7.00k|{
13990|  7.00k|    const ssl3CipherSuiteCfg *suite;
13991|  7.00k|    PRBool pref;
13992|  7.00k|    SECStatus rv;
13993|       |
13994|  7.00k|    suite = ssl_LookupCipherSuiteCfg(which, ss->cipherSuites);
13995|  7.00k|    if (suite) {
  ------------------
  |  Branch (13995:9): [True: 7.00k, False: 0]
  ------------------
13996|  7.00k|        pref = suite->enabled;
13997|  7.00k|        rv = SECSuccess;
13998|  7.00k|    } else {
13999|      0|        pref = SSL_NOT_ALLOWED;
  ------------------
  |  |  699|      0|#define SSL_NOT_ALLOWED 0 /* or invalid or unimplemented */
  ------------------
14000|      0|        rv = SECFailure; /* err code was set by Lookup. */
14001|      0|    }
14002|  7.00k|    *enabled = pref;
14003|  7.00k|    return rv;
14004|  7.00k|}
ssl3_InitSocketPolicy:
14134|  9.71k|{
14135|  9.71k|    PORT_Memcpy(ss->cipherSuites, cipherSuites, sizeof(cipherSuites));
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
14136|  9.71k|    PORT_Memcpy(ss->ssl3.signatureSchemes, defaultSignatureSchemes,
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
14137|  9.71k|                sizeof(defaultSignatureSchemes));
14138|  9.71k|    ss->ssl3.signatureSchemeCount = PR_ARRAY_SIZE(defaultSignatureSchemes);
  ------------------
  |  |  167|  9.71k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
14139|  9.71k|}
ssl3_DestroySSL3Info:
14198|  9.71k|{
14199|       |
14200|  9.71k|    if (ss->ssl3.clientCertificate != NULL)
  ------------------
  |  Branch (14200:9): [True: 0, False: 9.71k]
  ------------------
14201|      0|        CERT_DestroyCertificate(ss->ssl3.clientCertificate);
14202|       |
14203|  9.71k|    if (ss->ssl3.clientPrivateKey != NULL)
  ------------------
  |  Branch (14203:9): [True: 0, False: 9.71k]
  ------------------
14204|      0|        SECKEY_DestroyPrivateKey(ss->ssl3.clientPrivateKey);
14205|       |
14206|  9.71k|    if (ss->ssl3.hs.clientAuthSignatureSchemes != NULL) {
  ------------------
  |  Branch (14206:9): [True: 0, False: 9.71k]
  ------------------
14207|      0|        PORT_Free(ss->ssl3.hs.clientAuthSignatureSchemes);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
14208|      0|        ss->ssl3.hs.clientAuthSignatureSchemes = NULL;
14209|      0|        ss->ssl3.hs.clientAuthSignatureSchemesLen = 0;
14210|      0|    }
14211|       |
14212|  9.71k|    if (ss->ssl3.peerCertArena != NULL)
  ------------------
  |  Branch (14212:9): [True: 2.77k, False: 6.94k]
  ------------------
14213|  2.77k|        ssl3_CleanupPeerCerts(ss);
14214|       |
14215|  9.71k|    if (ss->ssl3.clientCertChain != NULL) {
  ------------------
  |  Branch (14215:9): [True: 0, False: 9.71k]
  ------------------
14216|      0|        CERT_DestroyCertificateList(ss->ssl3.clientCertChain);
14217|      0|        ss->ssl3.clientCertChain = NULL;
14218|      0|    }
14219|  9.71k|    if (ss->ssl3.ca_list) {
  ------------------
  |  Branch (14219:9): [True: 0, False: 9.71k]
  ------------------
14220|      0|        CERT_FreeDistNames(ss->ssl3.ca_list);
14221|      0|    }
14222|       |
14223|       |    /* clean up handshake */
14224|  9.71k|    if (ss->ssl3.hs.md5) {
  ------------------
  |  Branch (14224:9): [True: 722, False: 8.99k]
  ------------------
14225|    722|        PK11_DestroyContext(ss->ssl3.hs.md5, PR_TRUE);
  ------------------
  |  |  437|    722|#define PR_TRUE 1
  ------------------
14226|    722|    }
14227|  9.71k|    if (ss->ssl3.hs.sha) {
  ------------------
  |  Branch (14227:9): [True: 1.96k, False: 7.75k]
  ------------------
14228|  1.96k|        PK11_DestroyContext(ss->ssl3.hs.sha, PR_TRUE);
  ------------------
  |  |  437|  1.96k|#define PR_TRUE 1
  ------------------
14229|  1.96k|    }
14230|  9.71k|    if (ss->ssl3.hs.shaEchInner) {
  ------------------
  |  Branch (14230:9): [True: 0, False: 9.71k]
  ------------------
14231|      0|        PK11_DestroyContext(ss->ssl3.hs.shaEchInner, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
14232|      0|    }
14233|  9.71k|    if (ss->ssl3.hs.shaPostHandshake) {
  ------------------
  |  Branch (14233:9): [True: 0, False: 9.71k]
  ------------------
14234|      0|        PK11_DestroyContext(ss->ssl3.hs.shaPostHandshake, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
14235|      0|    }
14236|  9.71k|    if (ss->ssl3.hs.messages.buf) {
  ------------------
  |  Branch (14236:9): [True: 7.27k, False: 2.44k]
  ------------------
14237|  7.27k|        sslBuffer_Clear(&ss->ssl3.hs.messages);
14238|  7.27k|    }
14239|  9.71k|    if (ss->ssl3.hs.echInnerMessages.buf) {
  ------------------
  |  Branch (14239:9): [True: 0, False: 9.71k]
  ------------------
14240|      0|        sslBuffer_Clear(&ss->ssl3.hs.echInnerMessages);
14241|      0|    }
14242|  9.71k|    if (ss->ssl3.hs.dtls13ClientMessageBuffer.buf) {
  ------------------
  |  Branch (14242:9): [True: 0, False: 9.71k]
  ------------------
14243|      0|        sslBuffer_Clear(&ss->ssl3.hs.dtls13ClientMessageBuffer);
14244|      0|    }
14245|       |
14246|       |    /* free the SSL3Buffer (msg_body) */
14247|  9.71k|    PORT_Free(ss->ssl3.hs.msg_body.buf);
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
14248|       |
14249|  9.71k|    SECITEM_FreeItem(&ss->ssl3.hs.newSessionTicket.ticket, PR_FALSE);
  ------------------
  |  |  108|  9.71k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&ss->ssl3.hs.newSessionTicket.ticket, PR_FALSE);
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
14250|  9.71k|    SECITEM_FreeItem(&ss->ssl3.hs.srvVirtName, PR_FALSE);
  ------------------
  |  |  108|  9.71k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&ss->ssl3.hs.srvVirtName, PR_FALSE);
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
14251|  9.71k|    SECITEM_FreeItem(&ss->ssl3.hs.fakeSid, PR_FALSE);
  ------------------
  |  |  108|  9.71k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&ss->ssl3.hs.fakeSid, PR_FALSE);
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
14252|       |
14253|       |    /* Destroy the DTLS data */
14254|  9.71k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  9.71k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 9.71k]
  |  |  ------------------
  ------------------
14255|      0|        dtls_FreeHandshakeMessages(&ss->ssl3.hs.lastMessageFlight);
14256|      0|        if (ss->ssl3.hs.recvdFragments.buf) {
  ------------------
  |  Branch (14256:13): [True: 0, False: 0]
  ------------------
14257|      0|            PORT_Free(ss->ssl3.hs.recvdFragments.buf);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
14258|      0|        }
14259|      0|    }
14260|       |
14261|       |    /* Destroy remote extensions */
14262|  9.71k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.remoteExtensions);
14263|  9.71k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.echOuterExtensions);
14264|  9.71k|    ssl3_DestroyExtensionData(&ss->xtnData);
14265|       |
14266|       |    /* Destroy cipher specs */
14267|  9.71k|    ssl_DestroyCipherSpecs(&ss->ssl3.hs.cipherSpecs);
14268|       |
14269|       |    /* Destroy TLS 1.3 keys */
14270|  9.71k|    if (ss->ssl3.hs.currentSecret)
  ------------------
  |  Branch (14270:9): [True: 796, False: 8.92k]
  ------------------
14271|    796|        PK11_FreeSymKey(ss->ssl3.hs.currentSecret);
14272|  9.71k|    if (ss->ssl3.hs.resumptionMasterSecret)
  ------------------
  |  Branch (14272:9): [True: 417, False: 9.30k]
  ------------------
14273|    417|        PK11_FreeSymKey(ss->ssl3.hs.resumptionMasterSecret);
14274|  9.71k|    if (ss->ssl3.hs.dheSecret)
  ------------------
  |  Branch (14274:9): [True: 0, False: 9.71k]
  ------------------
14275|      0|        PK11_FreeSymKey(ss->ssl3.hs.dheSecret);
14276|  9.71k|    if (ss->ssl3.hs.clientEarlyTrafficSecret)
  ------------------
  |  Branch (14276:9): [True: 0, False: 9.71k]
  ------------------
14277|      0|        PK11_FreeSymKey(ss->ssl3.hs.clientEarlyTrafficSecret);
14278|  9.71k|    if (ss->ssl3.hs.clientHsTrafficSecret)
  ------------------
  |  Branch (14278:9): [True: 796, False: 8.92k]
  ------------------
14279|    796|        PK11_FreeSymKey(ss->ssl3.hs.clientHsTrafficSecret);
14280|  9.71k|    if (ss->ssl3.hs.serverHsTrafficSecret)
  ------------------
  |  Branch (14280:9): [True: 796, False: 8.92k]
  ------------------
14281|    796|        PK11_FreeSymKey(ss->ssl3.hs.serverHsTrafficSecret);
14282|  9.71k|    if (ss->ssl3.hs.clientTrafficSecret)
  ------------------
  |  Branch (14282:9): [True: 1.21k, False: 8.50k]
  ------------------
14283|  1.21k|        PK11_FreeSymKey(ss->ssl3.hs.clientTrafficSecret);
14284|  9.71k|    if (ss->ssl3.hs.serverTrafficSecret)
  ------------------
  |  Branch (14284:9): [True: 1.21k, False: 8.50k]
  ------------------
14285|  1.21k|        PK11_FreeSymKey(ss->ssl3.hs.serverTrafficSecret);
14286|  9.71k|    if (ss->ssl3.hs.earlyExporterSecret)
  ------------------
  |  Branch (14286:9): [True: 0, False: 9.71k]
  ------------------
14287|      0|        PK11_FreeSymKey(ss->ssl3.hs.earlyExporterSecret);
14288|  9.71k|    if (ss->ssl3.hs.exporterSecret)
  ------------------
  |  Branch (14288:9): [True: 1.21k, False: 8.50k]
  ------------------
14289|  1.21k|        PK11_FreeSymKey(ss->ssl3.hs.exporterSecret);
14290|       |
14291|  9.71k|    ss->ssl3.hs.zeroRttState = ssl_0rtt_none;
14292|       |    /* Destroy TLS 1.3 buffered early data. */
14293|  9.71k|    tls13_DestroyEarlyData(&ss->ssl3.hs.bufferedEarlyData);
14294|       |
14295|       |    /* Destroy TLS 1.3 PSKs. */
14296|  9.71k|    tls13_DestroyPskList(&ss->ssl3.hs.psks);
14297|       |
14298|       |    /* TLS 1.3 ECH state. */
14299|  9.71k|    PK11_HPKE_DestroyContext(ss->ssl3.hs.echHpkeCtx, PR_TRUE);
  ------------------
  |  |  437|  9.71k|#define PR_TRUE 1
  ------------------
14300|  9.71k|    PORT_Free((void *)ss->ssl3.hs.echPublicName); /* CONST */
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
14301|  9.71k|    sslBuffer_Clear(&ss->ssl3.hs.greaseEchBuf);
14302|       |
14303|       |    /* TLS 1.3 GREASE (client) state. */
14304|  9.71k|    tls13_ClientGreaseDestroy(ss);
14305|       |
14306|       |    /* TLS ClientHello Extension Permutation state. */
14307|  9.71k|    tls_ClientHelloExtensionPermutationDestroy(ss);
14308|  9.71k|}
ssl3_ApplyNSSPolicy:
14404|      1|{
14405|      1|    unsigned i;
14406|      1|    SECStatus rv;
14407|      1|    PRUint32 policy = 0;
14408|       |
14409|      1|    rv = NSS_GetAlgorithmPolicy(SEC_OID_APPLY_SSL_POLICY, &policy);
14410|      1|    if (rv != SECSuccess || !(policy & NSS_USE_POLICY_IN_SSL)) {
  ------------------
  |  |  574|      1|#define NSS_USE_POLICY_IN_SSL 0x00000010           /* enable policy in SSL protocol */
  ------------------
  |  Branch (14410:9): [True: 0, False: 1]
  |  Branch (14410:29): [True: 1, False: 0]
  ------------------
14411|      1|        return SECSuccess; /* do nothing */
14412|      1|    }
14413|       |
14414|       |    /* disable every ciphersuite */
14415|      0|    for (i = 1; i < PR_ARRAY_SIZE(cipher_suite_defs); ++i) {
  ------------------
  |  |  167|      0|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (14415:17): [True: 0, False: 0]
  ------------------
14416|      0|        const ssl3CipherSuiteDef *suite = &cipher_suite_defs[i];
14417|      0|        SECOidTag policyOid;
14418|      0|        PRBool isDisabled = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
14419|       |
14420|       |        /* if we haven't explicitly disabled it below enable by policy */
14421|      0|        ssl_CipherPolicySet(suite->cipher_suite, SSL_ALLOWED);
  ------------------
  |  |  700|      0|#define SSL_ALLOWED 1
  ------------------
14422|       |
14423|       |        /* now check the various key exchange, ciphers and macs and
14424|       |         * if we ever disallow by policy, we are done, go to the next cipher
14425|       |         */
14426|      0|        policyOid = MAP_NULL(kea_defs[suite->key_exchange_alg].oid);
  ------------------
  |  |14400|      0|#define MAP_NULL(x) (((x) != 0) ? (x) : SEC_OID_NULL_CIPHER)
  |  |  ------------------
  |  |  |  Branch (14400:22): [True: 0, False: 0]
  |  |  ------------------
  ------------------
14427|      0|        if (ssl_HandlePolicy(suite->cipher_suite, policyOid,
  ------------------
  |  Branch (14427:13): [True: 0, False: 0]
  ------------------
14428|      0|                             NSS_USE_ALG_IN_SSL_KX, &isDisabled)) {
  ------------------
  |  |  572|      0|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
14429|      0|            continue;
14430|      0|        }
14431|       |
14432|      0|        policyOid = MAP_NULL(ssl_GetBulkCipherDef(suite)->oid);
  ------------------
  |  |14400|      0|#define MAP_NULL(x) (((x) != 0) ? (x) : SEC_OID_NULL_CIPHER)
  |  |  ------------------
  |  |  |  Branch (14400:22): [True: 0, False: 0]
  |  |  ------------------
  ------------------
14433|      0|        if (ssl_HandlePolicy(suite->cipher_suite, policyOid,
  ------------------
  |  Branch (14433:13): [True: 0, False: 0]
  ------------------
14434|      0|                             NSS_USE_ALG_IN_SSL, &isDisabled)) {
  ------------------
  |  |  573|      0|#define NSS_USE_ALG_IN_SSL 0x00000008              /* used in SSL record protocol */
  ------------------
14435|      0|            continue;
14436|      0|        }
14437|       |
14438|      0|        if (ssl_GetBulkCipherDef(suite)->type != type_aead) {
  ------------------
  |  Branch (14438:13): [True: 0, False: 0]
  ------------------
14439|      0|            policyOid = MAP_NULL(ssl_GetMacDefByAlg(suite->mac_alg)->oid);
  ------------------
  |  |14400|      0|#define MAP_NULL(x) (((x) != 0) ? (x) : SEC_OID_NULL_CIPHER)
  |  |  ------------------
  |  |  |  Branch (14400:22): [True: 0, False: 0]
  |  |  ------------------
  ------------------
14440|      0|            if (ssl_HandlePolicy(suite->cipher_suite, policyOid,
  ------------------
  |  Branch (14440:17): [True: 0, False: 0]
  ------------------
14441|      0|                                 NSS_USE_ALG_IN_SSL, &isDisabled)) {
  ------------------
  |  |  573|      0|#define NSS_USE_ALG_IN_SSL 0x00000008              /* used in SSL record protocol */
  ------------------
14442|      0|                continue;
14443|      0|            }
14444|      0|        }
14445|      0|    }
14446|       |
14447|      0|    rv = ssl3_ConstrainRangeByPolicy();
14448|       |
14449|      0|    return rv;
14450|      1|}
ssl3con.c:ssl_LookupCipherSuiteCfgMutable:
  661|   697k|{
  662|   697k|    int i;
  663|       |
  664|  24.9M|    for (i = 0; i < ssl_V3_SUITES_IMPLEMENTED; i++) {
  ------------------
  |  |  245|  24.9M|#define ssl_V3_SUITES_IMPLEMENTED 71
  ------------------
  |  Branch (664:17): [True: 24.9M, False: 0]
  ------------------
  665|  24.9M|        if (suites[i].cipher_suite == suite)
  ------------------
  |  Branch (665:13): [True: 697k, False: 24.2M]
  ------------------
  666|   697k|            return &suites[i];
  667|  24.9M|    }
  668|       |    /* return NULL and let the caller handle it.  */
  669|      0|    PORT_SetError(SSL_ERROR_UNKNOWN_CIPHER_SUITE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  670|      0|    return NULL;
  671|   697k|}
ssl3con.c:ssl_CheckSignatureSchemes:
  867|  60.3k|{
  868|  60.3k|    if (ss->vrange.max < SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  60.3k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (868:9): [True: 6.59k, False: 53.7k]
  ------------------
  869|  6.59k|        return SECSuccess;
  870|  6.59k|    }
  871|       |
  872|       |    /* If this is a server using TLS 1.3, we just need to have one signature
  873|       |     * scheme for which we have a usable certificate.
  874|       |     *
  875|       |     * Note: Certificates for earlier TLS versions are checked along with the
  876|       |     * cipher suite in ssl3_config_match_init. */
  877|  53.7k|    if (ss->sec.isServer && ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  53.7k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (877:9): [True: 53.7k, False: 0]
  |  Branch (877:29): [True: 43.5k, False: 10.2k]
  ------------------
  878|  43.5k|        PRBool foundCert = PR_FALSE;
  ------------------
  |  |  438|  43.5k|#define PR_FALSE 0
  ------------------
  879|  43.5k|        for (unsigned int i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (879:34): [True: 43.5k, False: 0]
  ------------------
  880|  43.5k|            SSLAuthType authType =
  881|  43.5k|                ssl_SignatureSchemeToAuthType(ss->ssl3.signatureSchemes[i]);
  882|  43.5k|            if (ssl_HasCert(ss, ss->vrange.max, authType)) {
  ------------------
  |  Branch (882:17): [True: 43.5k, False: 0]
  ------------------
  883|  43.5k|                foundCert = PR_TRUE;
  ------------------
  |  |  437|  43.5k|#define PR_TRUE 1
  ------------------
  884|  43.5k|                break;
  885|  43.5k|            }
  886|  43.5k|        }
  887|  43.5k|        if (!foundCert) {
  ------------------
  |  Branch (887:13): [True: 0, False: 43.5k]
  ------------------
  888|      0|            PORT_SetError(SSL_ERROR_NO_SUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  889|      0|            return SECFailure;
  890|      0|        }
  891|  43.5k|    }
  892|       |
  893|       |    /* Ensure that there is a signature scheme that can be accepted.*/
  894|  53.7k|    for (unsigned int i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (894:30): [True: 53.7k, False: 0]
  ------------------
  895|  53.7k|        if (ssl_SignatureSchemeAccepted(ss->vrange.min,
  ------------------
  |  Branch (895:13): [True: 53.7k, False: 0]
  ------------------
  896|  53.7k|                                        ss->ssl3.signatureSchemes[i],
  897|  53.7k|                                        PR_FALSE /* forCert */)) {
  ------------------
  |  |  438|  53.7k|#define PR_FALSE 0
  ------------------
  898|  53.7k|            return SECSuccess;
  899|  53.7k|        }
  900|  53.7k|    }
  901|      0|    PORT_SetError(SSL_ERROR_NO_SUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  902|      0|    return SECFailure;
  903|  53.7k|}
ssl3con.c:ssl_HasCert:
  761|  5.75M|{
  762|  5.75M|    PRCList *cursor;
  763|  5.75M|    if (authType == ssl_auth_null || authType == ssl_auth_psk || authType == ssl_auth_tls13_any) {
  ------------------
  |  Branch (763:9): [True: 0, False: 5.75M]
  |  Branch (763:38): [True: 0, False: 5.75M]
  |  Branch (763:66): [True: 180k, False: 5.57M]
  ------------------
  764|   180k|        return PR_TRUE;
  ------------------
  |  |  437|   180k|#define PR_TRUE 1
  ------------------
  765|   180k|    }
  766|  5.57M|    for (cursor = PR_NEXT_LINK(&ss->serverCerts);
  ------------------
  |  |   47|  5.57M|        ((_e)->next)
  ------------------
  767|  10.8M|         cursor != &ss->serverCerts;
  ------------------
  |  Branch (767:10): [True: 9.80M, False: 1.05M]
  ------------------
  768|  9.80M|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|  5.28M|        ((_e)->next)
  ------------------
  769|  9.80M|        sslServerCert *cert = (sslServerCert *)cursor;
  770|  9.80M|        if (!cert->serverKeyPair ||
  ------------------
  |  Branch (770:13): [True: 0, False: 9.80M]
  ------------------
  771|  9.80M|            !cert->serverKeyPair->privKey ||
  ------------------
  |  Branch (771:13): [True: 0, False: 9.80M]
  ------------------
  772|  9.80M|            !cert->serverCertChain ||
  ------------------
  |  Branch (772:13): [True: 0, False: 9.80M]
  ------------------
  773|  9.80M|            !SSL_CERT_IS(cert, authType)) {
  ------------------
  |  |   53|  9.80M|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  ------------------
  |  Branch (773:13): [True: 5.19M, False: 4.60M]
  ------------------
  774|  5.19M|            continue;
  775|  5.19M|        }
  776|       |        /* When called from ssl3_config_match_init(), all the EC curves will be
  777|       |         * enabled, so this will essentially do nothing (unless we implement
  778|       |         * curve configuration).  However, once we have seen the
  779|       |         * supported_groups extension and this is called from config_match(),
  780|       |         * this will filter out certificates with an unsupported curve.
  781|       |         *
  782|       |         * If we might negotiate TLS 1.3, skip this test as group configuration
  783|       |         * doesn't affect choices in TLS 1.3.
  784|       |         */
  785|  4.60M|        if (maxVersion < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|  9.21M|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (785:13): [True: 2.29M, False: 2.30M]
  ------------------
  786|  4.60M|            (authType == ssl_auth_ecdsa ||
  ------------------
  |  Branch (786:14): [True: 553k, False: 1.74M]
  ------------------
  787|  2.29M|             authType == ssl_auth_ecdh_ecdsa ||
  ------------------
  |  Branch (787:14): [True: 177k, False: 1.56M]
  ------------------
  788|  2.29M|             authType == ssl_auth_ecdh_rsa) &&
  ------------------
  |  Branch (788:14): [True: 0, False: 1.56M]
  ------------------
  789|  4.60M|            !ssl_NamedGroupEnabled(ss, cert->namedCurve)) {
  ------------------
  |  Branch (789:13): [True: 88.5k, False: 642k]
  ------------------
  790|  88.5k|            continue;
  791|  88.5k|        }
  792|  4.51M|        return PR_TRUE;
  ------------------
  |  |  437|  4.51M|#define PR_TRUE 1
  ------------------
  793|  4.60M|    }
  794|  1.05M|    if (authType == ssl_auth_rsa_sign) {
  ------------------
  |  Branch (794:9): [True: 0, False: 1.05M]
  ------------------
  795|      0|        return ssl_HasCert(ss, maxVersion, ssl_auth_rsa_pss);
  796|      0|    }
  797|  1.05M|    return PR_FALSE;
  ------------------
  |  |  438|  1.05M|#define PR_FALSE 0
  ------------------
  798|  1.05M|}
ssl3con.c:ssl_HasSignatureScheme:
  909|  3.08M|{
  910|  3.08M|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|  3.08M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.08M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.08M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  911|  3.08M|    PORT_Assert(ss->ssl3.hs.preliminaryInfo & ssl_preinfo_version);
  ------------------
  |  |  120|  3.08M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.08M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.08M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  912|  3.08M|    PORT_Assert(authType != ssl_auth_null);
  ------------------
  |  |  120|  3.08M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.08M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.08M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  913|  3.08M|    PORT_Assert(authType != ssl_auth_tls13_any);
  ------------------
  |  |  120|  3.08M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.08M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.08M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  914|  3.08M|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_2 ||
  ------------------
  |  |   20|  6.16M|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (914:9): [True: 327k, False: 2.75M]
  ------------------
  915|  3.08M|        authType == ssl_auth_rsa_decrypt ||
  ------------------
  |  Branch (915:9): [True: 859k, False: 1.89M]
  ------------------
  916|  3.08M|        authType == ssl_auth_ecdh_rsa ||
  ------------------
  |  Branch (916:9): [True: 0, False: 1.89M]
  ------------------
  917|  3.08M|        authType == ssl_auth_ecdh_ecdsa) {
  ------------------
  |  Branch (917:9): [True: 255k, False: 1.63M]
  ------------------
  918|  1.44M|        return PR_TRUE;
  ------------------
  |  |  437|  1.44M|#define PR_TRUE 1
  ------------------
  919|  1.44M|    }
  920|  6.15M|    for (unsigned int i = 0; i < ss->ssl3.signatureSchemeCount; ++i) {
  ------------------
  |  Branch (920:30): [True: 6.15M, False: 0]
  ------------------
  921|  6.15M|        SSLSignatureScheme scheme = ss->ssl3.signatureSchemes[i];
  922|  6.15M|        SSLAuthType schemeAuthType = ssl_SignatureSchemeToAuthType(scheme);
  923|  6.15M|        PRBool acceptable = authType == schemeAuthType ||
  ------------------
  |  Branch (923:29): [True: 1.63M, False: 4.51M]
  ------------------
  924|  6.15M|                            (schemeAuthType == ssl_auth_rsa_pss &&
  ------------------
  |  Branch (924:30): [True: 0, False: 4.51M]
  ------------------
  925|  4.51M|                             authType == ssl_auth_rsa_sign);
  ------------------
  |  Branch (925:30): [True: 0, False: 0]
  ------------------
  926|  6.15M|        if (acceptable && ssl_SignatureSchemeAccepted(ss->version, scheme, PR_FALSE /* forCert */)) {
  ------------------
  |  |  438|  1.63M|#define PR_FALSE 0
  ------------------
  |  Branch (926:13): [True: 1.63M, False: 4.51M]
  |  Branch (926:27): [True: 1.63M, False: 0]
  ------------------
  927|  1.63M|            return PR_TRUE;
  ------------------
  |  |  437|  1.63M|#define PR_TRUE 1
  ------------------
  928|  1.63M|        }
  929|  6.15M|    }
  930|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  931|  1.63M|}
ssl3con.c:ssl_KEAEnabled:
  695|  1.72M|{
  696|  1.72M|    switch (keaType) {
  697|   264k|        case ssl_kea_rsa:
  ------------------
  |  Branch (697:9): [True: 264k, False: 1.46M]
  ------------------
  698|   264k|            return PR_TRUE;
  ------------------
  |  |  437|   264k|#define PR_TRUE 1
  ------------------
  699|       |
  700|   310k|        case ssl_kea_dh:
  ------------------
  |  Branch (700:9): [True: 310k, False: 1.41M]
  ------------------
  701|   310k|        case ssl_kea_dh_psk: {
  ------------------
  |  Branch (701:9): [True: 0, False: 1.72M]
  ------------------
  702|   310k|            if (ss->sec.isServer && !ss->opt.enableServerDhe) {
  ------------------
  |  Branch (702:17): [True: 310k, False: 0]
  |  Branch (702:37): [True: 0, False: 310k]
  ------------------
  703|      0|                return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  704|      0|            }
  705|       |
  706|   310k|            if (ss->sec.isServer) {
  ------------------
  |  Branch (706:17): [True: 310k, False: 0]
  ------------------
  707|       |                /* If the server requires named FFDHE groups, then the client
  708|       |                 * must have included an FFDHE group. peerSupportsFfdheGroups
  709|       |                 * is set to true in ssl_HandleSupportedGroupsXtn(). */
  710|   310k|                if (ss->opt.requireDHENamedGroups &&
  ------------------
  |  Branch (710:21): [True: 0, False: 310k]
  ------------------
  711|   310k|                    !ss->xtnData.peerSupportsFfdheGroups) {
  ------------------
  |  Branch (711:21): [True: 0, False: 0]
  ------------------
  712|      0|                    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  713|      0|                }
  714|       |
  715|       |                /* We can use the weak DH group if all of these are true:
  716|       |                 * 1. We don't require named groups.
  717|       |                 * 2. The peer doesn't support named groups.
  718|       |                 * 3. This isn't TLS 1.3.
  719|       |                 * 4. The weak group is enabled. */
  720|   310k|                if (!ss->opt.requireDHENamedGroups &&
  ------------------
  |  Branch (720:21): [True: 310k, False: 0]
  ------------------
  721|   310k|                    !ss->xtnData.peerSupportsFfdheGroups &&
  ------------------
  |  Branch (721:21): [True: 303k, False: 6.75k]
  ------------------
  722|   310k|                    ss->version < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|   613k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (722:21): [True: 303k, False: 99]
  ------------------
  723|   310k|                    ss->ssl3.dheWeakGroupEnabled) {
  ------------------
  |  Branch (723:21): [True: 0, False: 303k]
  ------------------
  724|      0|                    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  725|      0|                }
  726|   310k|            } else {
  727|      0|                if (ss->vrange.min < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (727:21): [True: 0, False: 0]
  ------------------
  728|      0|                    !ss->opt.requireDHENamedGroups) {
  ------------------
  |  Branch (728:21): [True: 0, False: 0]
  ------------------
  729|       |                    /* The client enables DHE cipher suites even if no DHE groups
  730|       |                     * are enabled. Only if this isn't TLS 1.3 and named groups
  731|       |                     * are not required. */
  732|      0|                    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  733|      0|                }
  734|      0|            }
  735|   310k|            return ssl_NamedGroupTypeEnabled(ss, ssl_kea_dh);
  736|   310k|        }
  737|       |
  738|   971k|        case ssl_kea_ecdh:
  ------------------
  |  Branch (738:9): [True: 971k, False: 755k]
  ------------------
  739|   971k|        case ssl_kea_ecdh_psk:
  ------------------
  |  Branch (739:9): [True: 0, False: 1.72M]
  ------------------
  740|   971k|            return ssl_NamedGroupTypeEnabled(ss, ssl_kea_ecdh);
  741|       |
  742|      0|        case ssl_kea_ecdh_hybrid:
  ------------------
  |  Branch (742:9): [True: 0, False: 1.72M]
  ------------------
  743|      0|        case ssl_kea_ecdh_hybrid_psk:
  ------------------
  |  Branch (743:9): [True: 0, False: 1.72M]
  ------------------
  744|      0|            if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (744:17): [True: 0, False: 0]
  ------------------
  745|      0|                return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  746|      0|            }
  747|      0|            return ssl_NamedGroupTypeEnabled(ss, ssl_kea_ecdh_hybrid);
  748|       |
  749|   180k|        case ssl_kea_tls13_any:
  ------------------
  |  Branch (749:9): [True: 180k, False: 1.54M]
  ------------------
  750|   180k|            return PR_TRUE;
  ------------------
  |  |  437|   180k|#define PR_TRUE 1
  ------------------
  751|       |
  752|      0|        case ssl_kea_fortezza:
  ------------------
  |  Branch (752:9): [True: 0, False: 1.72M]
  ------------------
  753|      0|        default:
  ------------------
  |  Branch (753:9): [True: 0, False: 1.72M]
  ------------------
  754|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  755|  1.72M|    }
  756|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  757|  1.72M|}
ssl3con.c:ssl_NamedGroupTypeEnabled:
  682|  1.28M|{
  683|  1.28M|    unsigned int i;
  684|  7.89M|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  7.89M|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (684:17): [True: 7.77M, False: 124k]
  ------------------
  685|  7.77M|        if (ss->namedGroupPreferences[i] &&
  ------------------
  |  Branch (685:13): [True: 1.99M, False: 5.77M]
  ------------------
  686|  7.77M|            ss->namedGroupPreferences[i]->keaType == keaType) {
  ------------------
  |  Branch (686:13): [True: 1.15M, False: 839k]
  ------------------
  687|  1.15M|            return PR_TRUE;
  ------------------
  |  |  437|  1.15M|#define PR_TRUE 1
  ------------------
  688|  1.15M|        }
  689|  7.77M|    }
  690|   124k|    return PR_FALSE;
  ------------------
  |  |  438|   124k|#define PR_FALSE 0
  ------------------
  691|  1.28M|}
ssl3con.c:ssl3_SetupPendingCipherSpec:
 1655|   117k|{
 1656|   117k|    ssl3CipherSpec *spec;
 1657|   117k|    const ssl3CipherSpec *prev;
 1658|       |
 1659|   117k|    prev = (direction == ssl_secret_write) ? ss->ssl3.cwSpec : ss->ssl3.crSpec;
  ------------------
  |  Branch (1659:12): [True: 58.7k, False: 58.7k]
  ------------------
 1660|   117k|    if (prev->epoch == PR_UINT16_MAX) {
  ------------------
  |  |  270|   117k|#define PR_UINT16_MAX 65535U
  ------------------
  |  Branch (1660:9): [True: 0, False: 117k]
  ------------------
 1661|      0|        PORT_SetError(SSL_ERROR_RENEGOTIATION_NOT_ALLOWED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1662|      0|        return SECFailure;
 1663|      0|    }
 1664|       |
 1665|   117k|    spec = ssl_CreateCipherSpec(ss, direction);
 1666|   117k|    if (!spec) {
  ------------------
  |  Branch (1666:9): [True: 0, False: 117k]
  ------------------
 1667|      0|        return SECFailure;
 1668|      0|    }
 1669|       |
 1670|   117k|    spec->cipherDef = ssl_GetBulkCipherDef(suiteDef);
 1671|   117k|    spec->macDef = ssl_GetMacDef(ss, suiteDef);
 1672|       |
 1673|   117k|    spec->epoch = prev->epoch + 1;
 1674|   117k|    spec->nextSeqNum = 0;
 1675|   117k|    if (IS_DTLS(ss) && direction == ssl_secret_read) {
  ------------------
  |  |  892|   234k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 117k]
  |  |  ------------------
  ------------------
  |  Branch (1675:24): [True: 0, False: 0]
  ------------------
 1676|      0|        dtls_InitRecvdRecords(&spec->recvdRecords);
 1677|      0|    }
 1678|   117k|    ssl_SetSpecVersions(ss, spec);
 1679|       |
 1680|   117k|    ssl_SaveCipherSpec(ss, spec);
 1681|   117k|    *specp = spec;
 1682|   117k|    return SECSuccess;
 1683|   117k|}
ssl3con.c:ssl3_InitPendingContexts:
 1817|   111k|{
 1818|   111k|    CK_MECHANISM_TYPE encMechanism;
 1819|   111k|    CK_ATTRIBUTE_TYPE encMode;
 1820|   111k|    SECItem macParam;
 1821|   111k|    CK_ULONG macLength;
 1822|   111k|    SECItem iv;
 1823|   111k|    SSLCipherAlgorithm calg;
 1824|       |
 1825|   111k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   111k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   168k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 54.4k, False: 57.2k]
  |  |  |  |  |  Branch (208:7): [True: 57.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1826|   111k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSpecWriteLock(ss));
  ------------------
  |  |  120|   111k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   168k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 54.4k, False: 57.2k]
  |  |  |  |  |  Branch (208:7): [True: 57.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1827|       |
 1828|   111k|    calg = spec->cipherDef->calg;
 1829|   111k|    PORT_Assert(alg2Mech[calg].calg == calg);
  ------------------
  |  |  120|   111k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   111k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 111k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1830|       |
 1831|   111k|    if (spec->cipherDef->type != type_aead) {
  ------------------
  |  Branch (1831:9): [True: 58.8k, False: 52.8k]
  ------------------
 1832|  58.8k|        macLength = spec->macDef->mac_size;
 1833|       |
 1834|       |        /*
 1835|       |        ** Now setup the MAC contexts,
 1836|       |        **   crypto contexts are setup below.
 1837|       |        */
 1838|  58.8k|        macParam.data = (unsigned char *)&macLength;
 1839|  58.8k|        macParam.len = sizeof(macLength);
 1840|  58.8k|        macParam.type = siBuffer;
 1841|       |
 1842|  58.8k|        spec->keyMaterial.macContext = PK11_CreateContextBySymKey(
 1843|  58.8k|            spec->macDef->mmech, CKA_SIGN, spec->keyMaterial.macKey, &macParam);
  ------------------
  |  |  551|  58.8k|#define CKA_SIGN 0x00000108UL
  ------------------
 1844|  58.8k|        if (!spec->keyMaterial.macContext) {
  ------------------
  |  Branch (1844:13): [True: 0, False: 58.8k]
  ------------------
 1845|      0|            ssl_MapLowLevelError(SSL_ERROR_SYM_KEY_CONTEXT_FAILURE);
 1846|      0|            return SECFailure;
 1847|      0|        }
 1848|  58.8k|    }
 1849|       |
 1850|       |    /*
 1851|       |    ** Now setup the crypto contexts.
 1852|       |    */
 1853|   111k|    if (calg == ssl_calg_null) {
  ------------------
  |  Branch (1853:9): [True: 12.8k, False: 98.8k]
  ------------------
 1854|  12.8k|        spec->cipher = Null_Cipher;
 1855|  12.8k|        return SECSuccess;
 1856|  12.8k|    }
 1857|       |
 1858|  98.8k|    encMechanism = ssl3_Alg2Mech(calg);
 1859|  98.8k|    encMode = (spec->direction == ssl_secret_write) ? CKA_ENCRYPT : CKA_DECRYPT;
  ------------------
  |  |  547|  49.4k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
                  encMode = (spec->direction == ssl_secret_write) ? CKA_ENCRYPT : CKA_DECRYPT;
  ------------------
  |  |  548|   148k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (1859:15): [True: 49.4k, False: 49.4k]
  ------------------
 1860|  98.8k|    if (spec->cipherDef->type == type_aead) {
  ------------------
  |  Branch (1860:9): [True: 52.8k, False: 46.0k]
  ------------------
 1861|  52.8k|        encMode |= CKA_NSS_MESSAGE;
  ------------------
  |  |   69|  52.8k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
 1862|  52.8k|        iv.data = NULL;
 1863|  52.8k|        iv.len = 0;
 1864|  52.8k|    } else {
 1865|  46.0k|        spec->cipher = SSLCipher_PK11_CipherOp;
 1866|  46.0k|        iv.data = spec->keyMaterial.iv;
 1867|  46.0k|        iv.len = spec->cipherDef->iv_size;
 1868|  46.0k|    }
 1869|       |
 1870|       |    /*
 1871|       |     * build the context
 1872|       |     */
 1873|  98.8k|    spec->cipherContext = PK11_CreateContextBySymKey(encMechanism, encMode,
 1874|  98.8k|                                                     spec->keyMaterial.key,
 1875|  98.8k|                                                     &iv);
 1876|  98.8k|    if (!spec->cipherContext) {
  ------------------
  |  Branch (1876:9): [True: 0, False: 98.8k]
  ------------------
 1877|      0|        ssl_MapLowLevelError(SSL_ERROR_SYM_KEY_CONTEXT_FAILURE);
 1878|      0|        return SECFailure;
 1879|      0|    }
 1880|       |
 1881|  98.8k|    return SECSuccess;
 1882|  98.8k|}
ssl3con.c:ssl3_ClientAuthTokenPresent:
 2108|  1.47M|{
 2109|  1.47M|    PK11SlotInfo *slot = NULL;
 2110|  1.47M|    PRBool isPresent = PR_TRUE;
  ------------------
  |  |  437|  1.47M|#define PR_TRUE 1
  ------------------
 2111|       |
 2112|       |    /* we only care if we are doing client auth */
 2113|  1.47M|    if (!sid || !sid->u.ssl3.clAuthValid) {
  ------------------
  |  Branch (2113:9): [True: 55.1k, False: 1.41M]
  |  Branch (2113:17): [True: 1.41M, False: 0]
  ------------------
 2114|  1.47M|        return PR_TRUE;
  ------------------
  |  |  437|  1.47M|#define PR_TRUE 1
  ------------------
 2115|  1.47M|    }
 2116|       |
 2117|       |    /* get the slot */
 2118|      0|    slot = SECMOD_LookupSlot(sid->u.ssl3.clAuthModuleID,
 2119|      0|                             sid->u.ssl3.clAuthSlotID);
 2120|      0|    if (slot == NULL ||
  ------------------
  |  Branch (2120:9): [True: 0, False: 0]
  ------------------
 2121|      0|        !PK11_IsPresent(slot) ||
  ------------------
  |  Branch (2121:9): [True: 0, False: 0]
  ------------------
 2122|      0|        sid->u.ssl3.clAuthSeries != PK11_GetSlotSeries(slot) ||
  ------------------
  |  Branch (2122:9): [True: 0, False: 0]
  ------------------
 2123|      0|        sid->u.ssl3.clAuthSlotID != PK11_GetSlotID(slot) ||
  ------------------
  |  Branch (2123:9): [True: 0, False: 0]
  ------------------
 2124|      0|        sid->u.ssl3.clAuthModuleID != PK11_GetModuleID(slot) ||
  ------------------
  |  Branch (2124:9): [True: 0, False: 0]
  ------------------
 2125|      0|        (PK11_NeedLogin(slot) && !PK11_IsLoggedIn(slot, NULL))) {
  ------------------
  |  Branch (2125:10): [True: 0, False: 0]
  |  Branch (2125:34): [True: 0, False: 0]
  ------------------
 2126|      0|        isPresent = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2127|      0|    }
 2128|      0|    if (slot) {
  ------------------
  |  Branch (2128:9): [True: 0, False: 0]
  ------------------
 2129|      0|        PK11_FreeSlot(slot);
 2130|      0|    }
 2131|      0|    return isPresent;
 2132|  1.47M|}
ssl3con.c:ssl3_FlushHandshakeMessages:
 2794|   583k|{
 2795|   583k|    static const PRInt32 allowedFlags = ssl_SEND_FLAG_FORCE_INTO_BUFFER;
  ------------------
  |  |  223|   583k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
 2796|   583k|    PRInt32 count = -1;
 2797|   583k|    SECStatus rv;
 2798|       |
 2799|   583k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   583k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   872k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 294k, False: 288k]
  |  |  |  |  |  Branch (208:7): [True: 288k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2800|   583k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|   583k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   872k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 294k, False: 288k]
  |  |  |  |  |  Branch (208:7): [True: 288k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2801|       |
 2802|   583k|    if (!ss->sec.ci.sendBuf.buf || !ss->sec.ci.sendBuf.len)
  ------------------
  |  Branch (2802:9): [True: 1.13k, False: 582k]
  |  Branch (2802:36): [True: 332k, False: 250k]
  ------------------
 2803|   333k|        return SECSuccess;
 2804|       |
 2805|       |    /* only these flags are allowed */
 2806|   250k|    PORT_Assert(!(flags & ~allowedFlags));
  ------------------
  |  |  120|   250k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   250k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 250k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2807|   250k|    if ((flags & ~allowedFlags) != 0) {
  ------------------
  |  Branch (2807:9): [True: 0, False: 250k]
  ------------------
 2808|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2809|      0|        return SECFailure;
 2810|      0|    }
 2811|   250k|    count = ssl3_SendRecord(ss, NULL, ssl_ct_handshake,
 2812|   250k|                            ss->sec.ci.sendBuf.buf,
 2813|   250k|                            ss->sec.ci.sendBuf.len, flags);
 2814|   250k|    if (count < 0) {
  ------------------
  |  Branch (2814:9): [True: 8, False: 250k]
  ------------------
 2815|      8|        int err = PORT_GetError();
  ------------------
  |  |   62|      8|#define PORT_GetError PORT_GetError_Util
  ------------------
 2816|      8|        PORT_Assert(err != PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |  120|      8|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 8, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2817|      8|        if (err == PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|      8|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (2817:13): [True: 0, False: 8]
  ------------------
 2818|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2819|      0|        }
 2820|      8|        rv = SECFailure;
 2821|   250k|    } else if ((unsigned int)count < ss->sec.ci.sendBuf.len) {
  ------------------
  |  Branch (2821:16): [True: 0, False: 250k]
  ------------------
 2822|       |        /* short write should never happen */
 2823|      0|        PORT_Assert((unsigned int)count >= ss->sec.ci.sendBuf.len);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2824|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2825|      0|        rv = SECFailure;
 2826|   250k|    } else {
 2827|   250k|        rv = SECSuccess;
 2828|   250k|    }
 2829|       |
 2830|       |    /* Whether we succeeded or failed, toss the old handshake data. */
 2831|   250k|    ss->sec.ci.sendBuf.len = 0;
 2832|   250k|    return rv;
 2833|   250k|}
ssl3con.c:ssl3_GetMgfMechanismByHashType:
 3386|  4.85k|{
 3387|  4.85k|    switch (hash) {
 3388|  1.11k|        case ssl_hash_sha256:
  ------------------
  |  Branch (3388:9): [True: 1.11k, False: 3.74k]
  ------------------
 3389|  1.11k|            return CKG_MGF1_SHA256;
  ------------------
  |  | 1649|  1.11k|#define CKG_MGF1_SHA256 0x00000002UL
  ------------------
 3390|    208|        case ssl_hash_sha384:
  ------------------
  |  Branch (3390:9): [True: 208, False: 4.64k]
  ------------------
 3391|    208|            return CKG_MGF1_SHA384;
  ------------------
  |  | 1650|    208|#define CKG_MGF1_SHA384 0x00000003UL
  ------------------
 3392|  3.53k|        case ssl_hash_sha512:
  ------------------
  |  Branch (3392:9): [True: 3.53k, False: 1.31k]
  ------------------
 3393|  3.53k|            return CKG_MGF1_SHA512;
  ------------------
  |  | 1651|  3.53k|#define CKG_MGF1_SHA512 0x00000004UL
  ------------------
 3394|      0|        default:
  ------------------
  |  Branch (3394:9): [True: 0, False: 4.85k]
  ------------------
 3395|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3396|  4.85k|    }
 3397|      0|    return CKG_MGF1_SHA256;
  ------------------
  |  | 1649|      0|#define CKG_MGF1_SHA256 0x00000002UL
  ------------------
 3398|  4.85k|}
ssl3con.c:ssl3_GetHashMechanismByHashType:
 3403|   207k|{
 3404|   207k|    switch (hashType) {
 3405|  3.53k|        case ssl_hash_sha512:
  ------------------
  |  Branch (3405:9): [True: 3.53k, False: 204k]
  ------------------
 3406|  3.53k|            return CKM_SHA512;
  ------------------
  |  |  882|  3.53k|#define CKM_SHA512 0x00000270UL
  ------------------
 3407|  88.3k|        case ssl_hash_sha384:
  ------------------
  |  Branch (3407:9): [True: 88.3k, False: 119k]
  ------------------
 3408|  88.3k|            return CKM_SHA384;
  ------------------
  |  |  879|  88.3k|#define CKM_SHA384 0x00000260UL
  ------------------
 3409|  24.3k|        case ssl_hash_sha256:
  ------------------
  |  Branch (3409:9): [True: 24.3k, False: 183k]
  ------------------
 3410|   116k|        case ssl_hash_none:
  ------------------
  |  Branch (3410:9): [True: 91.7k, False: 116k]
  ------------------
 3411|       |            /* ssl_hash_none is for pre-1.2 suites, which use SHA-256. */
 3412|   116k|            return CKM_SHA256;
  ------------------
  |  |  876|   116k|#define CKM_SHA256 0x00000250UL
  ------------------
 3413|      0|        case ssl_hash_sha1:
  ------------------
  |  Branch (3413:9): [True: 0, False: 207k]
  ------------------
 3414|      0|            return CKM_SHA_1;
  ------------------
  |  |  859|      0|#define CKM_SHA_1 0x00000220UL
  ------------------
 3415|      0|        default:
  ------------------
  |  Branch (3415:9): [True: 0, False: 207k]
  ------------------
 3416|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3417|   207k|    }
 3418|      0|    return CKM_SHA256;
  ------------------
  |  |  876|      0|#define CKM_SHA256 0x00000250UL
  ------------------
 3419|   207k|}
ssl3con.c:ssl3_ComputeMasterSecret:
 3665|  67.8k|{
 3666|  67.8k|    PORT_Assert(pms != NULL);
  ------------------
  |  |  120|  67.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  67.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 67.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3667|  67.8k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  67.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   103k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 32.0k, False: 35.7k]
  |  |  |  |  |  Branch (208:7): [True: 35.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3668|       |
 3669|  67.8k|    if (ssl3_ExtensionNegotiated(ss, ssl_extended_master_secret_xtn)) {
  ------------------
  |  Branch (3669:9): [True: 6.58k, False: 61.2k]
  ------------------
 3670|  6.58k|        return tls_ComputeExtendedMasterSecretInt(ss, pms, msp);
 3671|  61.2k|    } else {
 3672|  61.2k|        return ssl3_ComputeMasterSecretInt(ss, pms, msp);
 3673|  61.2k|    }
 3674|  67.8k|}
ssl3con.c:tls_ComputeExtendedMasterSecretInt:
 3600|  6.58k|{
 3601|  6.58k|    ssl3CipherSpec *pwSpec = ss->ssl3.pwSpec;
 3602|  6.58k|    CK_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_PARAMS extended_master_params;
 3603|  6.58k|    SSL3Hashes hashes;
 3604|       |
 3605|       |    /*
 3606|       |     * Determine whether to use the DH/ECDH or RSA derivation modes.
 3607|       |     */
 3608|       |    /*
 3609|       |     * TODO(ekr@rtfm.com): Verify that the slot can handle this key expansion
 3610|       |     * mode. Bug 1198298 */
 3611|  6.58k|    PRBool isDH = (PRBool)((ss->ssl3.hs.kea_def->exchKeyType == ssl_kea_dh) ||
  ------------------
  |  Branch (3611:28): [True: 2.56k, False: 4.02k]
  ------------------
 3612|  6.58k|                           (ss->ssl3.hs.kea_def->exchKeyType == ssl_kea_ecdh) ||
  ------------------
  |  Branch (3612:28): [True: 2.58k, False: 1.44k]
  ------------------
 3613|  6.58k|                           (ss->ssl3.hs.kea_def->exchKeyType == ssl_kea_ecdh_hybrid));
  ------------------
  |  Branch (3613:28): [True: 0, False: 1.44k]
  ------------------
 3614|  6.58k|    CK_MECHANISM_TYPE master_derive;
 3615|  6.58k|    CK_MECHANISM_TYPE key_derive;
 3616|  6.58k|    SECItem params;
 3617|  6.58k|    const CK_FLAGS keyFlags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|  6.58k|#define CKF_SIGN 0x00000800UL
  ------------------
                  const CK_FLAGS keyFlags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|  6.58k|#define CKF_VERIFY 0x00002000
  ------------------
 3618|  6.58k|    CK_VERSION pms_version;
 3619|  6.58k|    CK_VERSION *pms_version_ptr = NULL;
 3620|  6.58k|    SECStatus rv;
 3621|       |
 3622|  6.58k|    rv = ssl3_ComputeHandshakeHashes(ss, pwSpec, &hashes, 0);
 3623|  6.58k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3623:9): [True: 0, False: 6.58k]
  ------------------
 3624|      0|        PORT_Assert(0); /* Should never fail */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3625|      0|        ssl_MapLowLevelError(SSL_ERROR_SESSION_KEY_GEN_FAILURE);
 3626|      0|        return SECFailure;
 3627|      0|    }
 3628|       |
 3629|  6.58k|    if (isDH) {
  ------------------
  |  Branch (3629:9): [True: 5.14k, False: 1.44k]
  ------------------
 3630|  5.14k|        master_derive = CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  240|  5.14k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE_DH (CKM_NSS + 26)
  |  |  ------------------
  |  |  |  |  162|  5.14k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  5.14k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  5.14k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3631|  5.14k|    } else {
 3632|  1.44k|        master_derive = CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE;
  ------------------
  |  |  239|  1.44k|#define CKM_NSS_TLS_EXTENDED_MASTER_KEY_DERIVE (CKM_NSS + 25)
  |  |  ------------------
  |  |  |  |  162|  1.44k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  1.44k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  1.44k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3633|  1.44k|        pms_version_ptr = &pms_version;
 3634|  1.44k|    }
 3635|       |
 3636|  6.58k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  6.58k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (3636:9): [True: 5.91k, False: 678]
  ------------------
 3637|       |        /* TLS 1.2+ */
 3638|  5.91k|        extended_master_params.prfHashMechanism = ssl3_GetPrfHashMechanism(ss);
 3639|  5.91k|        key_derive = CKM_TLS12_KEY_AND_MAC_DERIVE;
  ------------------
  |  | 1027|  5.91k|#define CKM_TLS12_KEY_AND_MAC_DERIVE 0x000003E1UL
  ------------------
 3640|  5.91k|    } else {
 3641|       |        /* TLS < 1.2 */
 3642|    678|        extended_master_params.prfHashMechanism = CKM_TLS_PRF;
  ------------------
  |  |  973|    678|#define CKM_TLS_PRF 0x00000378UL
  ------------------
 3643|    678|        key_derive = CKM_TLS_KEY_AND_MAC_DERIVE;
  ------------------
  |  |  969|    678|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
 3644|    678|    }
 3645|       |
 3646|  6.58k|    extended_master_params.pVersion = pms_version_ptr;
 3647|  6.58k|    extended_master_params.pSessionHash = hashes.u.raw;
 3648|  6.58k|    extended_master_params.ulSessionHashLen = hashes.len;
 3649|       |
 3650|  6.58k|    params.data = (unsigned char *)&extended_master_params;
 3651|  6.58k|    params.len = sizeof extended_master_params;
 3652|       |
 3653|  6.58k|    return ssl3_ComputeMasterSecretFinish(ss, master_derive, key_derive,
 3654|  6.58k|                                          pms_version_ptr, &params,
 3655|  6.58k|                                          keyFlags, pms, msp);
 3656|  6.58k|}
ssl3con.c:ssl3_ComputeMasterSecretFinish:
 3458|  67.8k|{
 3459|  67.8k|    PK11SymKey *ms = NULL;
 3460|       |
 3461|  67.8k|    ms = PK11_DeriveWithFlags(pms, master_derive,
 3462|  67.8k|                              params, key_derive,
 3463|  67.8k|                              CKA_DERIVE, 0, keyFlags);
  ------------------
  |  |  555|  67.8k|#define CKA_DERIVE 0x0000010CUL
  ------------------
 3464|  67.8k|    if (!ms) {
  ------------------
  |  Branch (3464:9): [True: 731, False: 67.0k]
  ------------------
 3465|    731|        ssl_MapLowLevelError(SSL_ERROR_SESSION_KEY_GEN_FAILURE);
 3466|    731|        return SECFailure;
 3467|    731|    }
 3468|       |
 3469|  67.0k|    if (pms_version && ss->opt.detectRollBack) {
  ------------------
  |  Branch (3469:9): [True: 23.2k, False: 43.8k]
  |  Branch (3469:24): [True: 23.2k, False: 0]
  ------------------
 3470|  23.2k|        SSL3ProtocolVersion client_version;
 3471|  23.2k|        client_version = pms_version->major << 8 | pms_version->minor;
 3472|       |
 3473|  23.2k|        if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  23.2k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 23.2k]
  |  |  ------------------
  ------------------
 3474|      0|            client_version = dtls_DTLSVersionToTLSVersion(client_version);
 3475|      0|        }
 3476|       |
 3477|  23.2k|        if (client_version != ss->clientHelloVersion) {
  ------------------
  |  Branch (3477:13): [True: 41, False: 23.1k]
  ------------------
 3478|       |            /* Destroy MS.  Version roll-back detected. */
 3479|     41|            PK11_FreeSymKey(ms);
 3480|     41|            ssl_MapLowLevelError(SSL_ERROR_SESSION_KEY_GEN_FAILURE);
 3481|     41|            return SECFailure;
 3482|     41|        }
 3483|  23.2k|    }
 3484|       |
 3485|  67.0k|    if (msp) {
  ------------------
  |  Branch (3485:9): [True: 55.8k, False: 11.2k]
  ------------------
 3486|  55.8k|        *msp = ms;
 3487|  55.8k|    } else {
 3488|  11.2k|        PK11_FreeSymKey(ms);
 3489|  11.2k|    }
 3490|       |
 3491|  67.0k|    return SECSuccess;
 3492|  67.0k|}
ssl3con.c:ssl3_ComputeMasterSecretInt:
 3502|  61.2k|{
 3503|  61.2k|    PRBool isTLS = (PRBool)(ss->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  61.2k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
 3504|  61.2k|    PRBool isTLS12 = (PRBool)(ss->version >= SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |   20|  61.2k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
 3505|       |    /*
 3506|       |     * Whenever isDH is true, we need to use CKM_TLS_MASTER_KEY_DERIVE_DH
 3507|       |     * which, unlike CKM_TLS_MASTER_KEY_DERIVE, converts arbitrary size
 3508|       |     * data into a 48-byte value, and does not expect to return the version.
 3509|       |     */
 3510|  61.2k|    PRBool isDH = (PRBool)((ss->ssl3.hs.kea_def->exchKeyType == ssl_kea_dh) ||
  ------------------
  |  Branch (3510:28): [True: 24.6k, False: 36.5k]
  ------------------
 3511|  61.2k|                           (ss->ssl3.hs.kea_def->exchKeyType == ssl_kea_ecdh) ||
  ------------------
  |  Branch (3511:28): [True: 14.0k, False: 22.5k]
  ------------------
 3512|  61.2k|                           (ss->ssl3.hs.kea_def->exchKeyType == ssl_kea_ecdh_hybrid));
  ------------------
  |  Branch (3512:28): [True: 0, False: 22.5k]
  ------------------
 3513|  61.2k|    CK_MECHANISM_TYPE master_derive;
 3514|  61.2k|    CK_MECHANISM_TYPE key_derive;
 3515|  61.2k|    SECItem params;
 3516|  61.2k|    CK_FLAGS keyFlags;
 3517|  61.2k|    CK_VERSION pms_version;
 3518|  61.2k|    CK_VERSION *pms_version_ptr = NULL;
 3519|       |    /* master_params may be used as a CK_SSL3_MASTER_KEY_DERIVE_PARAMS */
 3520|  61.2k|    CK_TLS12_MASTER_KEY_DERIVE_PARAMS master_params;
 3521|  61.2k|    unsigned int master_params_len;
 3522|       |
 3523|       |    /* if we are using TLS and we aren't using the extended master secret,
 3524|       |     * and SEC_OID_TLS_REQUIRE_EMS policy is true, fail. The caller will
 3525|       |     * send an alert (eventually). In the RSA Server case, the alert
 3526|       |     * won't happen until Finish time because the upper level code
 3527|       |     * can't tell a difference between this failure and an RSA decrypt
 3528|       |     * failure, so it will proceed with a faux key */
 3529|  61.2k|    if (isTLS) {
  ------------------
  |  Branch (3529:9): [True: 61.2k, False: 0]
  ------------------
 3530|  61.2k|        PRUint32 policy;
 3531|  61.2k|        SECStatus rv;
 3532|       |
 3533|       |        /* first fetch the policy for this algorithm */
 3534|  61.2k|        rv = NSS_GetAlgorithmPolicy(SEC_OID_TLS_REQUIRE_EMS, &policy);
 3535|       |        /* we only look at the policy if we can fetch it. */
 3536|  61.2k|        if ((rv == SECSuccess) && (policy & NSS_USE_ALG_IN_SSL_KX)) {
  ------------------
  |  |  572|  61.2k|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
  |  Branch (3536:13): [True: 61.2k, False: 0]
  |  Branch (3536:35): [True: 0, False: 61.2k]
  ------------------
 3537|       |            /* just set the error, we don't want to map any errors
 3538|       |             * set by NSS_GetAlgorithmPolicy here */
 3539|      0|            PORT_SetError(SSL_ERROR_MISSING_EXTENDED_MASTER_SECRET);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3540|      0|            return SECFailure;
 3541|      0|        }
 3542|  61.2k|    }
 3543|       |
 3544|  61.2k|    if (isTLS12) {
  ------------------
  |  Branch (3544:9): [True: 53.2k, False: 7.92k]
  ------------------
 3545|  53.2k|        if (isDH)
  ------------------
  |  Branch (3545:13): [True: 35.1k, False: 18.1k]
  ------------------
 3546|  35.1k|            master_derive = CKM_TLS12_MASTER_KEY_DERIVE_DH;
  ------------------
  |  | 1028|  35.1k|#define CKM_TLS12_MASTER_KEY_DERIVE_DH 0x000003E2UL
  ------------------
 3547|  18.1k|        else
 3548|  18.1k|            master_derive = CKM_TLS12_MASTER_KEY_DERIVE;
  ------------------
  |  | 1026|  18.1k|#define CKM_TLS12_MASTER_KEY_DERIVE 0x000003E0UL
  ------------------
 3549|  53.2k|        key_derive = CKM_TLS12_KEY_AND_MAC_DERIVE;
  ------------------
  |  | 1027|  53.2k|#define CKM_TLS12_KEY_AND_MAC_DERIVE 0x000003E1UL
  ------------------
 3550|  53.2k|        keyFlags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|  53.2k|#define CKF_SIGN 0x00000800UL
  ------------------
                      keyFlags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|  53.2k|#define CKF_VERIFY 0x00002000
  ------------------
 3551|  53.2k|    } else if (isTLS) {
  ------------------
  |  Branch (3551:16): [True: 7.92k, False: 0]
  ------------------
 3552|  7.92k|        if (isDH)
  ------------------
  |  Branch (3552:13): [True: 3.60k, False: 4.32k]
  ------------------
 3553|  3.60k|            master_derive = CKM_TLS_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  970|  3.60k|#define CKM_TLS_MASTER_KEY_DERIVE_DH 0x00000377UL
  ------------------
 3554|  4.32k|        else
 3555|  4.32k|            master_derive = CKM_TLS_MASTER_KEY_DERIVE;
  ------------------
  |  |  968|  4.32k|#define CKM_TLS_MASTER_KEY_DERIVE 0x00000375UL
  ------------------
 3556|  7.92k|        key_derive = CKM_TLS_KEY_AND_MAC_DERIVE;
  ------------------
  |  |  969|  7.92k|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
 3557|  7.92k|        keyFlags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1356|  7.92k|#define CKF_SIGN 0x00000800UL
  ------------------
                      keyFlags = CKF_SIGN | CKF_VERIFY;
  ------------------
  |  | 1358|  7.92k|#define CKF_VERIFY 0x00002000
  ------------------
 3558|  7.92k|    } else {
 3559|      0|        if (isDH)
  ------------------
  |  Branch (3559:13): [True: 0, False: 0]
  ------------------
 3560|      0|            master_derive = CKM_SSL3_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  966|      0|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
 3561|      0|        else
 3562|      0|            master_derive = CKM_SSL3_MASTER_KEY_DERIVE;
  ------------------
  |  |  960|      0|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
 3563|      0|        key_derive = CKM_SSL3_KEY_AND_MAC_DERIVE;
  ------------------
  |  |  961|      0|#define CKM_SSL3_KEY_AND_MAC_DERIVE 0x00000372UL
  ------------------
 3564|      0|        keyFlags = 0;
 3565|      0|    }
 3566|       |
 3567|  61.2k|    if (!isDH) {
  ------------------
  |  Branch (3567:9): [True: 22.5k, False: 38.7k]
  ------------------
 3568|  22.5k|        pms_version_ptr = &pms_version;
 3569|  22.5k|    }
 3570|       |
 3571|  61.2k|    master_params.pVersion = pms_version_ptr;
 3572|  61.2k|    master_params.RandomInfo.pClientRandom = ss->ssl3.hs.client_random;
 3573|  61.2k|    master_params.RandomInfo.ulClientRandomLen = SSL3_RANDOM_LENGTH;
  ------------------
  |  |   24|  61.2k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 3574|  61.2k|    master_params.RandomInfo.pServerRandom = ss->ssl3.hs.server_random;
 3575|  61.2k|    master_params.RandomInfo.ulServerRandomLen = SSL3_RANDOM_LENGTH;
  ------------------
  |  |   24|  61.2k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 3576|  61.2k|    if (isTLS12) {
  ------------------
  |  Branch (3576:9): [True: 53.2k, False: 7.92k]
  ------------------
 3577|  53.2k|        master_params.prfHashMechanism = ssl3_GetPrfHashMechanism(ss);
 3578|  53.2k|        master_params_len = sizeof(CK_TLS12_MASTER_KEY_DERIVE_PARAMS);
 3579|  53.2k|    } else {
 3580|       |        /* prfHashMechanism is not relevant with this PRF */
 3581|  7.92k|        master_params_len = sizeof(CK_SSL3_MASTER_KEY_DERIVE_PARAMS);
 3582|  7.92k|    }
 3583|       |
 3584|  61.2k|    params.data = (unsigned char *)&master_params;
 3585|  61.2k|    params.len = master_params_len;
 3586|       |
 3587|  61.2k|    return ssl3_ComputeMasterSecretFinish(ss, master_derive, key_derive,
 3588|  61.2k|                                          pms_version_ptr, &params,
 3589|  61.2k|                                          keyFlags, pms, msp);
 3590|  61.2k|}
ssl3con.c:ssl3_DeriveConnectionKeys:
 3693|  55.8k|{
 3694|  55.8k|    ssl3CipherSpec *pwSpec = ss->ssl3.pwSpec;
 3695|  55.8k|    ssl3CipherSpec *prSpec = ss->ssl3.prSpec;
 3696|  55.8k|    ssl3CipherSpec *clientSpec;
 3697|  55.8k|    ssl3CipherSpec *serverSpec;
 3698|  55.8k|    PRBool isTLS = (PRBool)(ss->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  55.8k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
 3699|  55.8k|    PRBool isTLS12 =
 3700|  55.8k|        (PRBool)(isTLS && ss->version >= SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |   20|  55.8k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (3700:18): [True: 55.8k, False: 0]
  |  Branch (3700:27): [True: 49.5k, False: 6.27k]
  ------------------
 3701|  55.8k|    const ssl3BulkCipherDef *cipher_def = pwSpec->cipherDef;
 3702|  55.8k|    PK11SlotInfo *slot = NULL;
 3703|  55.8k|    PK11SymKey *derivedKeyHandle = NULL;
 3704|  55.8k|    void *pwArg = ss->pkcs11PinArg;
 3705|  55.8k|    int keySize;
 3706|  55.8k|    CK_TLS12_KEY_MAT_PARAMS key_material_params; /* may be used as a
 3707|       |                                                  * CK_SSL3_KEY_MAT_PARAMS */
 3708|  55.8k|    unsigned int key_material_params_len;
 3709|  55.8k|    CK_SSL3_KEY_MAT_OUT returnedKeys;
 3710|  55.8k|    CK_MECHANISM_TYPE key_derive;
 3711|  55.8k|    CK_MECHANISM_TYPE bulk_mechanism;
 3712|  55.8k|    SSLCipherAlgorithm calg;
 3713|  55.8k|    SECItem params;
 3714|  55.8k|    PRBool skipKeysAndIVs = (PRBool)(cipher_def->calg == ssl_calg_null);
 3715|       |
 3716|  55.8k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  84.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27.2k, False: 28.6k]
  |  |  |  |  |  Branch (208:7): [True: 28.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3717|  55.8k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSpecWriteLock(ss));
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  84.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27.2k, False: 28.6k]
  |  |  |  |  |  Branch (208:7): [True: 28.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3718|  55.8k|    PORT_Assert(masterSecret);
  ------------------
  |  |  120|  55.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  55.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 55.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3719|       |
 3720|       |    /* These functions operate in terms of who is writing specs. */
 3721|  55.8k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (3721:9): [True: 55.8k, False: 0]
  ------------------
 3722|  55.8k|        clientSpec = prSpec;
 3723|  55.8k|        serverSpec = pwSpec;
 3724|  55.8k|    } else {
 3725|      0|        clientSpec = pwSpec;
 3726|      0|        serverSpec = prSpec;
 3727|      0|    }
 3728|       |
 3729|       |    /*
 3730|       |     * generate the key material
 3731|       |     */
 3732|  55.8k|    if (cipher_def->type == type_block &&
  ------------------
  |  Branch (3732:9): [True: 22.4k, False: 33.4k]
  ------------------
 3733|  55.8k|        ss->version >= SSL_LIBRARY_VERSION_TLS_1_1) {
  ------------------
  |  |   19|  22.4k|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  ------------------
  |  Branch (3733:9): [True: 20.8k, False: 1.62k]
  ------------------
 3734|       |        /* Block ciphers in >= TLS 1.1 use a per-record, explicit IV. */
 3735|  20.8k|        key_material_params.ulIVSizeInBits = 0;
 3736|  20.8k|        PORT_Memset(clientSpec->keyMaterial.iv, 0, cipher_def->iv_size);
  ------------------
  |  |  182|  20.8k|#define PORT_Memset memset
  ------------------
 3737|  20.8k|        PORT_Memset(serverSpec->keyMaterial.iv, 0, cipher_def->iv_size);
  ------------------
  |  |  182|  20.8k|#define PORT_Memset memset
  ------------------
 3738|  20.8k|    }
 3739|       |
 3740|  55.8k|    key_material_params.bIsExport = PR_FALSE;
  ------------------
  |  |  438|  55.8k|#define PR_FALSE 0
  ------------------
 3741|  55.8k|    key_material_params.RandomInfo.pClientRandom = ss->ssl3.hs.client_random;
 3742|  55.8k|    key_material_params.RandomInfo.ulClientRandomLen = SSL3_RANDOM_LENGTH;
  ------------------
  |  |   24|  55.8k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 3743|  55.8k|    key_material_params.RandomInfo.pServerRandom = ss->ssl3.hs.server_random;
 3744|  55.8k|    key_material_params.RandomInfo.ulServerRandomLen = SSL3_RANDOM_LENGTH;
  ------------------
  |  |   24|  55.8k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 3745|  55.8k|    key_material_params.pReturnedKeyMaterial = &returnedKeys;
 3746|       |
 3747|  55.8k|    if (skipKeysAndIVs) {
  ------------------
  |  Branch (3747:9): [True: 6.40k, False: 49.4k]
  ------------------
 3748|  6.40k|        keySize = 0;
 3749|  6.40k|        returnedKeys.pIVClient = NULL;
 3750|  6.40k|        returnedKeys.pIVServer = NULL;
 3751|  6.40k|        key_material_params.ulKeySizeInBits = 0;
 3752|  6.40k|        key_material_params.ulIVSizeInBits = 0;
 3753|  49.4k|    } else {
 3754|  49.4k|        keySize = cipher_def->key_size;
 3755|  49.4k|        returnedKeys.pIVClient = clientSpec->keyMaterial.iv;
 3756|  49.4k|        returnedKeys.pIVServer = serverSpec->keyMaterial.iv;
 3757|  49.4k|        key_material_params.ulKeySizeInBits = cipher_def->secret_key_size * BPB;
  ------------------
  |  |  122|  49.4k|#define BPB 8 /* Bits Per Byte */
  ------------------
 3758|  49.4k|        key_material_params.ulIVSizeInBits = cipher_def->iv_size * BPB;
  ------------------
  |  |  122|  49.4k|#define BPB 8 /* Bits Per Byte */
  ------------------
 3759|  49.4k|    }
 3760|  55.8k|    key_material_params.ulMacSizeInBits = pwSpec->macDef->mac_size * BPB;
  ------------------
  |  |  122|  55.8k|#define BPB 8 /* Bits Per Byte */
  ------------------
 3761|       |
 3762|  55.8k|    calg = cipher_def->calg;
 3763|  55.8k|    bulk_mechanism = ssl3_Alg2Mech(calg);
 3764|       |
 3765|  55.8k|    if (isTLS12) {
  ------------------
  |  Branch (3765:9): [True: 49.5k, False: 6.27k]
  ------------------
 3766|  49.5k|        key_derive = CKM_TLS12_KEY_AND_MAC_DERIVE;
  ------------------
  |  | 1027|  49.5k|#define CKM_TLS12_KEY_AND_MAC_DERIVE 0x000003E1UL
  ------------------
 3767|  49.5k|        key_material_params.prfHashMechanism = ssl3_GetPrfHashMechanism(ss);
 3768|  49.5k|        key_material_params_len = sizeof(CK_TLS12_KEY_MAT_PARAMS);
 3769|  49.5k|    } else if (isTLS) {
  ------------------
  |  Branch (3769:16): [True: 6.27k, False: 0]
  ------------------
 3770|  6.27k|        key_derive = CKM_TLS_KEY_AND_MAC_DERIVE;
  ------------------
  |  |  969|  6.27k|#define CKM_TLS_KEY_AND_MAC_DERIVE 0x00000376UL
  ------------------
 3771|  6.27k|        key_material_params_len = sizeof(CK_SSL3_KEY_MAT_PARAMS);
 3772|  6.27k|    } else {
 3773|      0|        key_derive = CKM_SSL3_KEY_AND_MAC_DERIVE;
  ------------------
  |  |  961|      0|#define CKM_SSL3_KEY_AND_MAC_DERIVE 0x00000372UL
  ------------------
 3774|      0|        key_material_params_len = sizeof(CK_SSL3_KEY_MAT_PARAMS);
 3775|      0|    }
 3776|       |
 3777|  55.8k|    params.data = (unsigned char *)&key_material_params;
 3778|  55.8k|    params.len = key_material_params_len;
 3779|       |
 3780|       |    /* CKM_SSL3_KEY_AND_MAC_DERIVE is defined to set ENCRYPT, DECRYPT, and
 3781|       |     * DERIVE by DEFAULT */
 3782|  55.8k|    derivedKeyHandle = PK11_Derive(masterSecret, key_derive, &params,
 3783|  55.8k|                                   bulk_mechanism, CKA_ENCRYPT, keySize);
  ------------------
  |  |  547|  55.8k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
 3784|  55.8k|    if (!derivedKeyHandle) {
  ------------------
  |  Branch (3784:9): [True: 0, False: 55.8k]
  ------------------
 3785|      0|        ssl_MapLowLevelError(SSL_ERROR_SESSION_KEY_GEN_FAILURE);
 3786|      0|        return SECFailure;
 3787|      0|    }
 3788|       |    /* we really should use the actual mac'ing mechanism here, but we
 3789|       |     * don't because these types are used to map keytype anyway and both
 3790|       |     * mac's map to the same keytype.
 3791|       |     */
 3792|  55.8k|    slot = PK11_GetSlotFromKey(derivedKeyHandle);
 3793|       |
 3794|  55.8k|    PK11_FreeSlot(slot); /* slot is held until the key is freed */
 3795|  55.8k|    clientSpec->keyMaterial.macKey =
 3796|  55.8k|        PK11_SymKeyFromHandle(slot, derivedKeyHandle, PK11_OriginDerive,
 3797|  55.8k|                              CKM_SSL3_SHA1_MAC, returnedKeys.hClientMacSecret,
  ------------------
  |  |  976|  55.8k|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
 3798|  55.8k|                              PR_TRUE, pwArg);
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 3799|  55.8k|    if (clientSpec->keyMaterial.macKey == NULL) {
  ------------------
  |  Branch (3799:9): [True: 0, False: 55.8k]
  ------------------
 3800|      0|        goto loser; /* loser sets err */
 3801|      0|    }
 3802|  55.8k|    serverSpec->keyMaterial.macKey =
 3803|  55.8k|        PK11_SymKeyFromHandle(slot, derivedKeyHandle, PK11_OriginDerive,
 3804|  55.8k|                              CKM_SSL3_SHA1_MAC, returnedKeys.hServerMacSecret,
  ------------------
  |  |  976|  55.8k|#define CKM_SSL3_SHA1_MAC 0x00000381UL
  ------------------
 3805|  55.8k|                              PR_TRUE, pwArg);
  ------------------
  |  |  437|  55.8k|#define PR_TRUE 1
  ------------------
 3806|  55.8k|    if (serverSpec->keyMaterial.macKey == NULL) {
  ------------------
  |  Branch (3806:9): [True: 0, False: 55.8k]
  ------------------
 3807|      0|        goto loser; /* loser sets err */
 3808|      0|    }
 3809|  55.8k|    if (!skipKeysAndIVs) {
  ------------------
  |  Branch (3809:9): [True: 49.4k, False: 6.40k]
  ------------------
 3810|  49.4k|        clientSpec->keyMaterial.key =
 3811|  49.4k|            PK11_SymKeyFromHandle(slot, derivedKeyHandle, PK11_OriginDerive,
 3812|  49.4k|                                  bulk_mechanism, returnedKeys.hClientKey,
 3813|  49.4k|                                  PR_TRUE, pwArg);
  ------------------
  |  |  437|  49.4k|#define PR_TRUE 1
  ------------------
 3814|  49.4k|        if (clientSpec->keyMaterial.key == NULL) {
  ------------------
  |  Branch (3814:13): [True: 0, False: 49.4k]
  ------------------
 3815|      0|            goto loser; /* loser sets err */
 3816|      0|        }
 3817|  49.4k|        serverSpec->keyMaterial.key =
 3818|  49.4k|            PK11_SymKeyFromHandle(slot, derivedKeyHandle, PK11_OriginDerive,
 3819|  49.4k|                                  bulk_mechanism, returnedKeys.hServerKey,
 3820|  49.4k|                                  PR_TRUE, pwArg);
  ------------------
  |  |  437|  49.4k|#define PR_TRUE 1
  ------------------
 3821|  49.4k|        if (serverSpec->keyMaterial.key == NULL) {
  ------------------
  |  Branch (3821:13): [True: 0, False: 49.4k]
  ------------------
 3822|      0|            goto loser; /* loser sets err */
 3823|      0|        }
 3824|  49.4k|    }
 3825|  55.8k|    PK11_FreeSymKey(derivedKeyHandle);
 3826|  55.8k|    return SECSuccess;
 3827|       |
 3828|      0|loser:
 3829|      0|    PK11_FreeSymKey(derivedKeyHandle);
 3830|      0|    ssl_MapLowLevelError(SSL_ERROR_SESSION_KEY_GEN_FAILURE);
 3831|      0|    return SECFailure;
 3832|  55.8k|}
ssl3con.c:ssl3_GetPrfHashMechanism:
 3424|   203k|{
 3425|   203k|    return ssl3_GetHashMechanismByHashType(ss->ssl3.hs.suite_def->prf_hash);
 3426|   203k|}
ssl3con.c:ssl3_UpdateDefaultHandshakeHashes:
 4082|  7.87k|{
 4083|  7.87k|    return ssl3_UpdateHandshakeHashesInt(ss, b, l,
 4084|  7.87k|                                         &ss->ssl3.hs.messages);
 4085|  7.87k|}
ssl3con.c:ssl_SignatureSchemeMatchesSpkiOid:
 4418|  52.1k|{
 4419|  52.1k|    SECOidTag authOid = ssl3_AuthTypeToOID(ssl_SignatureSchemeToAuthType(scheme));
 4420|       |
 4421|  52.1k|    if (spkiOid == authOid) {
  ------------------
  |  Branch (4421:9): [True: 27.7k, False: 24.3k]
  ------------------
 4422|  27.7k|        return PR_TRUE;
  ------------------
  |  |  437|  27.7k|#define PR_TRUE 1
  ------------------
 4423|  27.7k|    }
 4424|  24.3k|    if ((authOid == SEC_OID_PKCS1_RSA_ENCRYPTION) &&
  ------------------
  |  Branch (4424:9): [True: 31, False: 24.3k]
  ------------------
 4425|  24.3k|        (spkiOid == SEC_OID_X500_RSA_ENCRYPTION)) {
  ------------------
  |  Branch (4425:9): [True: 0, False: 31]
  ------------------
 4426|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 4427|      0|    }
 4428|  24.3k|    return PR_FALSE;
  ------------------
  |  |  438|  24.3k|#define PR_FALSE 0
  ------------------
 4429|  24.3k|}
ssl3con.c:ssl_SignatureSchemeFromPssSpki:
 4466|      2|{
 4467|      2|    SECKEYRSAPSSParams pssParam = { 0 };
 4468|      2|    PORTCheapArenaPool arena;
 4469|      2|    SECStatus rv;
 4470|       |
 4471|       |    /* The key doesn't have parameters, boo. */
 4472|      2|    if (!spki->algorithm.parameters.len) {
  ------------------
  |  Branch (4472:9): [True: 0, False: 2]
  ------------------
 4473|      0|        *scheme = ssl_sig_none;
 4474|      0|        return SECSuccess;
 4475|      0|    }
 4476|       |
 4477|      2|    PORT_InitCheapArena(&arena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|      2|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 4478|      2|    rv = SEC_QuickDERDecodeItem(&arena.arena, &pssParam,
  ------------------
  |  |  102|      2|#define SEC_QuickDERDecodeItem SEC_QuickDERDecodeItem_Util
  ------------------
 4479|      2|                                SEC_ASN1_GET(SECKEY_RSAPSSParamsTemplate),
  ------------------
  |  |  188|      2|#define SEC_ASN1_GET(x) x
  ------------------
 4480|      2|                                &spki->algorithm.parameters);
 4481|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4481:9): [True: 1, False: 1]
  ------------------
 4482|      1|        goto loser;
 4483|      1|    }
 4484|       |    /* Not having hashAlg means SHA-1 and we don't accept that. */
 4485|      1|    if (!pssParam.hashAlg) {
  ------------------
  |  Branch (4485:9): [True: 1, False: 0]
  ------------------
 4486|      1|        goto loser;
 4487|      1|    }
 4488|      0|    switch (SECOID_GetAlgorithmTag(pssParam.hashAlg)) {
  ------------------
  |  |  119|      0|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
 4489|      0|        case SEC_OID_SHA256:
  ------------------
  |  Branch (4489:9): [True: 0, False: 0]
  ------------------
 4490|      0|            *scheme = ssl_sig_rsa_pss_pss_sha256;
 4491|      0|            break;
 4492|      0|        case SEC_OID_SHA384:
  ------------------
  |  Branch (4492:9): [True: 0, False: 0]
  ------------------
 4493|      0|            *scheme = ssl_sig_rsa_pss_pss_sha384;
 4494|      0|            break;
 4495|      0|        case SEC_OID_SHA512:
  ------------------
  |  Branch (4495:9): [True: 0, False: 0]
  ------------------
 4496|      0|            *scheme = ssl_sig_rsa_pss_pss_sha512;
 4497|      0|            break;
 4498|      0|        default:
  ------------------
  |  Branch (4498:9): [True: 0, False: 0]
  ------------------
 4499|      0|            goto loser;
 4500|      0|    }
 4501|       |
 4502|      0|    PORT_DestroyCheapArena(&arena);
 4503|      0|    return SECSuccess;
 4504|       |
 4505|      2|loser:
 4506|      2|    PORT_DestroyCheapArena(&arena);
 4507|      2|    PORT_SetError(SSL_ERROR_BAD_CERTIFICATE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 4508|      2|    return SECFailure;
 4509|      0|}
ssl3con.c:ssl_SignatureSchemeFromEcSpki:
 4514|  1.24k|{
 4515|  1.24k|    const sslNamedGroupDef *group;
 4516|  1.24k|    SECKEYPublicKey *key;
 4517|       |
 4518|  1.24k|    key = SECKEY_ExtractPublicKey(spki);
 4519|  1.24k|    if (!key) {
  ------------------
  |  Branch (4519:9): [True: 0, False: 1.24k]
  ------------------
 4520|      0|        PORT_SetError(SSL_ERROR_BAD_CERTIFICATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4521|      0|        return SECFailure;
 4522|      0|    }
 4523|  1.24k|    group = ssl_ECPubKey2NamedGroup(key);
 4524|  1.24k|    SECKEY_DestroyPublicKey(key);
 4525|  1.24k|    if (!group) {
  ------------------
  |  Branch (4525:9): [True: 0, False: 1.24k]
  ------------------
 4526|      0|        PORT_SetError(SSL_ERROR_BAD_CERTIFICATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4527|      0|        return SECFailure;
 4528|      0|    }
 4529|  1.24k|    switch (group->name) {
 4530|  1.24k|        case ssl_grp_ec_secp256r1:
  ------------------
  |  Branch (4530:9): [True: 1.24k, False: 0]
  ------------------
 4531|  1.24k|            *scheme = ssl_sig_ecdsa_secp256r1_sha256;
 4532|  1.24k|            return SECSuccess;
 4533|      0|        case ssl_grp_ec_secp384r1:
  ------------------
  |  Branch (4533:9): [True: 0, False: 1.24k]
  ------------------
 4534|      0|            *scheme = ssl_sig_ecdsa_secp384r1_sha384;
 4535|      0|            return SECSuccess;
 4536|      0|        case ssl_grp_ec_secp521r1:
  ------------------
  |  Branch (4536:9): [True: 0, False: 1.24k]
  ------------------
 4537|      0|            *scheme = ssl_sig_ecdsa_secp521r1_sha512;
 4538|      0|            return SECSuccess;
 4539|      0|        default:
  ------------------
  |  Branch (4539:9): [True: 0, False: 1.24k]
  ------------------
 4540|      0|            break;
 4541|  1.24k|    }
 4542|      0|    PORT_SetError(SSL_ERROR_BAD_CERTIFICATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4543|      0|    return SECFailure;
 4544|  1.24k|}
ssl3con.c:ssl_SchemePolicyOK:
  805|  1.88M|{
  806|       |    /* Hash policy. */
  807|  1.88M|    PRUint32 policy;
  808|  1.88M|    SECOidTag hashOID = ssl3_HashTypeToOID(ssl_SignatureSchemeToHashType(scheme));
  809|  1.88M|    SECOidTag sigOID;
  810|       |
  811|       |    /* policy bits needed to enable a SignatureScheme */
  812|  1.88M|    SECStatus rv = NSS_GetAlgorithmPolicy(hashOID, &policy);
  813|  1.88M|    if (rv == SECSuccess &&
  ------------------
  |  Branch (813:9): [True: 1.88M, False: 0]
  ------------------
  814|  1.88M|        (policy & require) != require) {
  ------------------
  |  Branch (814:9): [True: 0, False: 1.88M]
  ------------------
  815|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  816|      0|    }
  817|       |
  818|       |    /* ssl_SignatureSchemeToAuthType reports rsa for rsa_pss_rsae, but we
  819|       |     * actually implement pss signatures when we sign, so just use RSA_PSS
  820|       |     * for all RSA PSS Siganture schemes */
  821|  1.88M|    if (ssl_IsRsaPssSignatureScheme(scheme)) {
  ------------------
  |  Branch (821:9): [True: 1.18M, False: 699k]
  ------------------
  822|  1.18M|        sigOID = SEC_OID_PKCS1_RSA_PSS_SIGNATURE;
  823|  1.18M|    } else {
  824|   699k|        sigOID = ssl3_AuthTypeToOID(ssl_SignatureSchemeToAuthType(scheme));
  825|   699k|    }
  826|       |    /* Signature Policy. */
  827|  1.88M|    rv = NSS_GetAlgorithmPolicy(sigOID, &policy);
  828|  1.88M|    if (rv == SECSuccess &&
  ------------------
  |  Branch (828:9): [True: 1.88M, False: 0]
  ------------------
  829|  1.88M|        (policy & require) != require) {
  ------------------
  |  Branch (829:9): [True: 0, False: 1.88M]
  ------------------
  830|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  831|      0|    }
  832|  1.88M|    return PR_TRUE;
  ------------------
  |  |  437|  1.88M|#define PR_TRUE 1
  ------------------
  833|  1.88M|}
ssl3con.c:ssl3_GetSuitePrfHash:
 3430|  98.9k|{
 3431|       |    /* ssl_hash_none is for pre-1.2 suites, which use SHA-256. */
 3432|  98.9k|    if (ss->ssl3.hs.suite_def->prf_hash == ssl_hash_none) {
  ------------------
  |  Branch (3432:9): [True: 42.2k, False: 56.7k]
  ------------------
 3433|  42.2k|        return ssl_hash_sha256;
 3434|  42.2k|    }
 3435|  56.7k|    return ss->ssl3.hs.suite_def->prf_hash;
 3436|  98.9k|}
ssl3con.c:ssl3_ComputeHandshakeHash:
 4821|   102k|{
 4822|   102k|    SECStatus rv = SECFailure;
 4823|   102k|    PK11Context *hashContext = PK11_CreateDigestContext(
 4824|   102k|        ssl3_HashTypeToOID(hashAlg));
 4825|       |
 4826|   102k|    if (!hashContext) {
  ------------------
  |  Branch (4826:9): [True: 0, False: 102k]
  ------------------
 4827|      0|        return rv;
 4828|      0|    }
 4829|   102k|    rv = PK11_DigestBegin(hashContext);
 4830|   102k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (4830:9): [True: 102k, False: 0]
  ------------------
 4831|   102k|        rv = PK11_DigestOp(hashContext, buf, len);
 4832|   102k|    }
 4833|   102k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (4833:9): [True: 102k, False: 0]
  ------------------
 4834|   102k|        rv = PK11_DigestFinal(hashContext, hashes->u.raw, &hashes->len,
 4835|   102k|                              sizeof(hashes->u.raw));
 4836|   102k|    }
 4837|   102k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (4837:9): [True: 102k, False: 0]
  ------------------
 4838|   102k|        hashes->hashAlg = hashAlg;
 4839|   102k|    }
 4840|   102k|    PK11_DestroyContext(hashContext, PR_TRUE);
  ------------------
  |  |  437|   102k|#define PR_TRUE 1
  ------------------
 4841|   102k|    return rv;
 4842|   102k|}
ssl3con.c:ssl_FindIndexByWrapKey:
 5876|  33.9k|{
 5877|  33.9k|    unsigned int i;
 5878|  54.3k|    for (i = 0; i < SSL_NUM_WRAP_KEYS; ++i) {
  ------------------
  |  |  116|  54.3k|#define SSL_NUM_WRAP_KEYS 6
  ------------------
  |  Branch (5878:17): [True: 54.3k, False: 0]
  ------------------
 5879|  54.3k|        if (SSL_CERT_IS(serverCert, ssl_wrap_key_auth_type[i])) {
  ------------------
  |  |   53|  54.3k|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  |  |  ------------------
  |  |  |  Branch (53:27): [True: 33.9k, False: 20.3k]
  |  |  ------------------
  ------------------
 5880|  33.9k|            *wrapKeyIndex = i;
 5881|  33.9k|            return SECSuccess;
 5882|  33.9k|        }
 5883|  54.3k|    }
 5884|       |    /* Can't assert here because we still get people using DSA certificates. */
 5885|      0|    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5886|      0|    return SECFailure;
 5887|  33.9k|}
ssl3con.c:ssl_FindIndexByWrapMechanism:
 5847|  33.9k|{
 5848|  33.9k|    unsigned int i;
 5849|  33.9k|    for (i = 0; i < SSL_NUM_WRAP_MECHS; ++i) {
  ------------------
  |  |  115|  33.9k|#define SSL_NUM_WRAP_MECHS 15
  ------------------
  |  Branch (5849:17): [True: 33.9k, False: 0]
  ------------------
 5850|  33.9k|        if (wrapMechanismList[i] == mech) {
  ------------------
  |  Branch (5850:13): [True: 33.9k, False: 0]
  ------------------
 5851|  33.9k|            *wrapMechIndex = i;
 5852|  33.9k|            return SECSuccess;
 5853|  33.9k|        }
 5854|  33.9k|    }
 5855|      0|    PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5856|      0|    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5857|      0|    return SECFailure;
 5858|  33.9k|}
ssl3con.c:ssl3_PeerSupportsCipherSuite:
 8604|  1.28M|{
 8605|  3.00M|    for (unsigned int i = 0; i + 1 < peerSuites->len; i += 2) {
  ------------------
  |  Branch (8605:30): [True: 1.77M, False: 1.22M]
  ------------------
 8606|  1.77M|        PRUint16 suite_i = (peerSuites->data[i] << 8) | peerSuites->data[i + 1];
 8607|  1.77M|        if (suite_i == suite) {
  ------------------
  |  Branch (8607:13): [True: 60.2k, False: 1.71M]
  ------------------
 8608|  60.2k|            return PR_TRUE;
  ------------------
  |  |  437|  60.2k|#define PR_TRUE 1
  ------------------
 8609|  60.2k|        }
 8610|  1.77M|    }
 8611|  1.22M|    return PR_FALSE;
  ------------------
  |  |  438|  1.22M|#define PR_FALSE 0
  ------------------
 8612|  1.28M|}
ssl3con.c:ssl3_PickServerSignatureScheme:
 6763|  46.1k|{
 6764|  46.1k|    const sslServerCert *cert = ss->sec.serverCert;
 6765|  46.1k|    PRBool isTLS12 = ss->version >= SSL_LIBRARY_VERSION_TLS_1_2;
  ------------------
  |  |   20|  46.1k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
 6766|       |
 6767|  46.1k|    if (!isTLS12 || !ssl3_ExtensionNegotiated(ss, ssl_signature_algorithms_xtn)) {
  ------------------
  |  Branch (6767:9): [True: 4.15k, False: 41.9k]
  |  Branch (6767:21): [True: 34.8k, False: 7.15k]
  ------------------
 6768|       |        /* If the client didn't provide any signature_algorithms extension then
 6769|       |         * we can assume that they support SHA-1: RFC5246, Section 7.4.1.4.1. */
 6770|  38.9k|        return ssl_PickFallbackSignatureScheme(ss, cert->serverKeyPair->pubKey);
 6771|  38.9k|    }
 6772|       |
 6773|       |    /* Sets error code, if needed. */
 6774|  7.15k|    return ssl_PickSignatureScheme(ss, cert->serverCert,
 6775|  7.15k|                                   cert->serverKeyPair->pubKey,
 6776|  7.15k|                                   cert->serverKeyPair->privKey,
 6777|  7.15k|                                   ss->xtnData.sigSchemes,
 6778|  7.15k|                                   ss->xtnData.numSigSchemes,
 6779|  7.15k|                                   PR_FALSE /* requireSha1 */,
  ------------------
  |  |  438|  7.15k|#define PR_FALSE 0
  ------------------
 6780|  7.15k|                                   &ss->ssl3.hs.signatureScheme);
 6781|  46.1k|}
ssl3con.c:ssl_PickFallbackSignatureScheme:
 6732|  38.9k|{
 6733|  38.9k|    PRBool isTLS12 = ss->version >= SSL_LIBRARY_VERSION_TLS_1_2;
  ------------------
  |  |   20|  38.9k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
 6734|       |
 6735|  38.9k|    switch (SECKEY_GetPublicKeyType(pubKey)) {
 6736|  29.5k|        case rsaKey:
  ------------------
  |  Branch (6736:9): [True: 29.5k, False: 9.39k]
  ------------------
 6737|  29.5k|            if (isTLS12) {
  ------------------
  |  Branch (6737:17): [True: 26.2k, False: 3.29k]
  ------------------
 6738|  26.2k|                ss->ssl3.hs.signatureScheme = ssl_sig_rsa_pkcs1_sha1;
 6739|  26.2k|            } else {
 6740|  3.29k|                ss->ssl3.hs.signatureScheme = ssl_sig_rsa_pkcs1_sha1md5;
 6741|  3.29k|            }
 6742|  29.5k|            break;
 6743|  9.39k|        case ecKey:
  ------------------
  |  Branch (6743:9): [True: 9.39k, False: 29.5k]
  ------------------
 6744|  9.39k|            ss->ssl3.hs.signatureScheme = ssl_sig_ecdsa_sha1;
 6745|  9.39k|            break;
 6746|      0|        case dsaKey:
  ------------------
  |  Branch (6746:9): [True: 0, False: 38.9k]
  ------------------
 6747|      0|            ss->ssl3.hs.signatureScheme = ssl_sig_dsa_sha1;
 6748|      0|            break;
 6749|      0|        default:
  ------------------
  |  Branch (6749:9): [True: 0, False: 38.9k]
  ------------------
 6750|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6751|      0|            PORT_SetError(SEC_ERROR_INVALID_KEY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6752|      0|            return SECFailure;
 6753|  38.9k|    }
 6754|  38.9k|    return SECSuccess;
 6755|  38.9k|}
ssl3con.c:ssl_SetSpecVersions:
 1138|   126k|{
 1139|   126k|    spec->version = ss->version;
 1140|   126k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|   126k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1140:9): [True: 1.88k, False: 124k]
  ------------------
 1141|  1.88k|        tls13_SetSpecRecordVersion(ss, spec);
 1142|   124k|    } else if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   124k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 124k]
  |  |  ------------------
  ------------------
 1143|      0|        spec->recordVersion = dtls_TLSVersionToDTLSVersion(ss->version);
 1144|   124k|    } else {
 1145|   124k|        spec->recordVersion = ss->version;
 1146|   124k|    }
 1147|   126k|}
ssl3con.c:ssl3_SendServerHelloSequence:
 8538|  58.7k|{
 8539|  58.7k|    const ssl3KEADef *kea_def;
 8540|  58.7k|    SECStatus rv;
 8541|       |
 8542|  58.7k|    SSL_TRC(3, ("%d: SSL3[%d]: begin send server_hello sequence",
  ------------------
  |  |   71|  58.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 58.7k]
  |  |  ------------------
  |  |   72|  58.7k|    ssl_Trace b
  ------------------
 8543|  58.7k|                SSL_GETPID(), ss->fd));
 8544|       |
 8545|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8546|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 8547|       |
 8548|  58.7k|    rv = ssl3_SendServerHello(ss);
 8549|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8549:9): [True: 0, False: 58.7k]
  ------------------
 8550|      0|        return rv; /* err code is set. */
 8551|      0|    }
 8552|  58.7k|    rv = ssl3_SendCertificate(ss);
 8553|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8553:9): [True: 0, False: 58.7k]
  ------------------
 8554|      0|        return rv; /* error code is set. */
 8555|      0|    }
 8556|  58.7k|    rv = ssl3_SendCertificateStatus(ss);
 8557|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8557:9): [True: 0, False: 58.7k]
  ------------------
 8558|      0|        return rv; /* error code is set. */
 8559|      0|    }
 8560|       |    /* We have to do this after the call to ssl3_SendServerHello,
 8561|       |     * because kea_def is set up by ssl3_SendServerHello().
 8562|       |     */
 8563|  58.7k|    kea_def = ss->ssl3.hs.kea_def;
 8564|       |
 8565|  58.7k|    if (kea_def->ephemeral) {
  ------------------
  |  Branch (8565:9): [True: 46.0k, False: 12.6k]
  ------------------
 8566|  46.0k|        rv = ssl3_SendServerKeyExchange(ss);
 8567|  46.0k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (8567:13): [True: 7, False: 46.0k]
  ------------------
 8568|      7|            return rv; /* err code was set. */
 8569|      7|        }
 8570|  46.0k|    }
 8571|       |
 8572|  58.7k|    if (ss->opt.requestCertificate) {
  ------------------
  |  Branch (8572:9): [True: 5.11k, False: 53.6k]
  ------------------
 8573|  5.11k|        rv = ssl3_SendCertificateRequest(ss);
 8574|  5.11k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (8574:13): [True: 0, False: 5.11k]
  ------------------
 8575|      0|            return rv; /* err code is set. */
 8576|      0|        }
 8577|  5.11k|    }
 8578|  58.7k|    rv = ssl3_SendServerHelloDone(ss);
 8579|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8579:9): [True: 6, False: 58.7k]
  ------------------
 8580|      6|        return rv; /* err code is set. */
 8581|      6|    }
 8582|       |
 8583|  58.7k|    ss->ssl3.hs.ws = (ss->opt.requestCertificate) ? wait_client_cert
  ------------------
  |  Branch (8583:22): [True: 5.11k, False: 53.6k]
  ------------------
 8584|  58.7k|                                                  : wait_client_key;
 8585|  58.7k|    return SECSuccess;
 8586|  58.7k|}
ssl3con.c:ssl3_SendCertificate:
11220|  58.7k|{
11221|  58.7k|    SECStatus rv;
11222|  58.7k|    CERTCertificateList *certChain;
11223|  58.7k|    int certChainLen = 0;
11224|  58.7k|    int i;
11225|       |#ifdef NISCC_TEST
11226|       |    SECItem fakeCert;
11227|       |    int ndex = -1;
11228|       |#endif
11229|  58.7k|    PRBool isTLS13 = ss->version >= SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|  58.7k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
11230|  58.7k|    SECItem context = { siBuffer, NULL, 0 };
11231|  58.7k|    unsigned int contextLen = 0;
11232|       |
11233|  58.7k|    SSL_TRC(3, ("%d: SSL3[%d]: send certificate handshake",
  ------------------
  |  |   71|  58.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 58.7k]
  |  |  ------------------
  |  |   72|  58.7k|    ssl_Trace b
  ------------------
11234|  58.7k|                SSL_GETPID(), ss->fd));
11235|       |
11236|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11237|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11238|  58.7k|    PR_ASSERT(!ss->ssl3.hs.clientCertificatePending);
  ------------------
  |  |  208|  58.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 58.7k, False: 0]
  |  |  ------------------
  ------------------
11239|       |
11240|  58.7k|    if (ss->sec.localCert)
  ------------------
  |  Branch (11240:9): [True: 52.0k, False: 6.71k]
  ------------------
11241|  52.0k|        CERT_DestroyCertificate(ss->sec.localCert);
11242|  58.7k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (11242:9): [True: 58.7k, False: 0]
  ------------------
11243|       |        /* A server certificate is selected in ssl3_HandleClientHello. */
11244|  58.7k|        PORT_Assert(ss->sec.serverCert);
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  58.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 58.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11245|       |
11246|  58.7k|        certChain = ss->sec.serverCert->serverCertChain;
11247|  58.7k|        ss->sec.localCert = CERT_DupCertificate(ss->sec.serverCert->serverCert);
11248|  58.7k|    } else {
11249|      0|        certChain = ss->ssl3.clientCertChain;
11250|      0|        ss->sec.localCert = CERT_DupCertificate(ss->ssl3.clientCertificate);
11251|      0|    }
11252|       |
11253|       |#ifdef NISCC_TEST
11254|       |    rv = get_fake_cert(&fakeCert, &ndex);
11255|       |#endif
11256|       |
11257|  58.7k|    if (isTLS13) {
  ------------------
  |  Branch (11257:9): [True: 0, False: 58.7k]
  ------------------
11258|      0|        contextLen = 1; /* Size of the context length */
11259|      0|        if (!ss->sec.isServer) {
  ------------------
  |  Branch (11259:13): [True: 0, False: 0]
  ------------------
11260|      0|            PORT_Assert(ss->ssl3.hs.clientCertRequested);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11261|      0|            context = ss->xtnData.certReqContext;
11262|      0|            contextLen += context.len;
11263|      0|        }
11264|      0|    }
11265|  58.7k|    if (certChain) {
  ------------------
  |  Branch (11265:9): [True: 58.7k, False: 0]
  ------------------
11266|   117k|        for (i = 0; i < certChain->len; i++) {
  ------------------
  |  Branch (11266:21): [True: 58.7k, False: 58.7k]
  ------------------
11267|       |#ifdef NISCC_TEST
11268|       |            if (fakeCert.len > 0 && i == ndex) {
11269|       |                certChainLen += fakeCert.len + 3;
11270|       |            } else {
11271|       |                certChainLen += certChain->certs[i].len + 3;
11272|       |            }
11273|       |#else
11274|  58.7k|            certChainLen += certChain->certs[i].len + 3;
11275|  58.7k|#endif
11276|  58.7k|        }
11277|  58.7k|    }
11278|       |
11279|  58.7k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_certificate,
11280|  58.7k|                                    contextLen + certChainLen + 3);
11281|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (11281:9): [True: 0, False: 58.7k]
  ------------------
11282|      0|        return rv; /* err set by AppendHandshake. */
11283|      0|    }
11284|       |
11285|  58.7k|    if (isTLS13) {
  ------------------
  |  Branch (11285:9): [True: 0, False: 58.7k]
  ------------------
11286|      0|        rv = ssl3_AppendHandshakeVariable(ss, context.data,
11287|      0|                                          context.len, 1);
11288|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (11288:13): [True: 0, False: 0]
  ------------------
11289|      0|            return rv; /* err set by AppendHandshake. */
11290|      0|        }
11291|      0|    }
11292|       |
11293|  58.7k|    rv = ssl3_AppendHandshakeNumber(ss, certChainLen, 3);
11294|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (11294:9): [True: 0, False: 58.7k]
  ------------------
11295|      0|        return rv; /* err set by AppendHandshake. */
11296|      0|    }
11297|  58.7k|    if (certChain) {
  ------------------
  |  Branch (11297:9): [True: 58.7k, False: 0]
  ------------------
11298|   117k|        for (i = 0; i < certChain->len; i++) {
  ------------------
  |  Branch (11298:21): [True: 58.7k, False: 58.7k]
  ------------------
11299|       |#ifdef NISCC_TEST
11300|       |            if (fakeCert.len > 0 && i == ndex) {
11301|       |                rv = ssl3_AppendHandshakeVariable(ss, fakeCert.data,
11302|       |                                                  fakeCert.len, 3);
11303|       |                SECITEM_FreeItem(&fakeCert, PR_FALSE);
11304|       |            } else {
11305|       |                rv = ssl3_AppendHandshakeVariable(ss, certChain->certs[i].data,
11306|       |                                                  certChain->certs[i].len, 3);
11307|       |            }
11308|       |#else
11309|  58.7k|            rv = ssl3_AppendHandshakeVariable(ss, certChain->certs[i].data,
11310|  58.7k|                                              certChain->certs[i].len, 3);
11311|  58.7k|#endif
11312|  58.7k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (11312:17): [True: 0, False: 58.7k]
  ------------------
11313|      0|                return rv; /* err set by AppendHandshake. */
11314|      0|            }
11315|  58.7k|        }
11316|  58.7k|    }
11317|       |
11318|  58.7k|    return SECSuccess;
11319|  58.7k|}
ssl3con.c:ssl3_SendServerKeyExchange:
10313|  46.0k|{
10314|  46.0k|    const ssl3KEADef *kea_def = ss->ssl3.hs.kea_def;
10315|       |
10316|  46.0k|    SSL_TRC(3, ("%d: SSL3[%d]: send server_key_exchange handshake",
  ------------------
  |  |   71|  46.0k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 46.0k]
  |  |  ------------------
  |  |   72|  46.0k|    ssl_Trace b
  ------------------
10317|  46.0k|                SSL_GETPID(), ss->fd));
10318|       |
10319|  46.0k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  46.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  68.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 23.3k, False: 22.7k]
  |  |  |  |  |  Branch (208:7): [True: 22.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10320|  46.0k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  46.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  68.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 23.3k, False: 22.7k]
  |  |  |  |  |  Branch (208:7): [True: 22.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10321|       |
10322|  46.0k|    switch (kea_def->exchKeyType) {
10323|  28.5k|        case ssl_kea_dh: {
  ------------------
  |  Branch (10323:9): [True: 28.5k, False: 17.5k]
  ------------------
10324|  28.5k|            return ssl3_SendDHServerKeyExchange(ss);
10325|      0|        }
10326|       |
10327|  17.5k|        case ssl_kea_ecdh: {
  ------------------
  |  Branch (10327:9): [True: 17.5k, False: 28.5k]
  ------------------
10328|  17.5k|            return ssl3_SendECDHServerKeyExchange(ss);
10329|      0|        }
10330|       |
10331|      0|        case ssl_kea_rsa:
  ------------------
  |  Branch (10331:9): [True: 0, False: 46.0k]
  ------------------
10332|      0|        case ssl_kea_null:
  ------------------
  |  Branch (10332:9): [True: 0, False: 46.0k]
  ------------------
10333|      0|        default:
  ------------------
  |  Branch (10333:9): [True: 0, False: 46.0k]
  ------------------
10334|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10335|      0|            break;
10336|  46.0k|    }
10337|       |
10338|      0|    return SECFailure;
10339|  46.0k|}
ssl3con.c:ssl3_SendDHServerKeyExchange:
10187|  28.5k|{
10188|  28.5k|    const ssl3KEADef *kea_def = ss->ssl3.hs.kea_def;
10189|  28.5k|    SECStatus rv = SECFailure;
10190|  28.5k|    int length;
10191|  28.5k|    SECItem signed_hash = { siBuffer, NULL, 0 };
10192|  28.5k|    SSL3Hashes hashes;
10193|  28.5k|    SSLHashType hashAlg;
10194|       |
10195|  28.5k|    const ssl3DHParams *params;
10196|  28.5k|    sslEphemeralKeyPair *keyPair;
10197|  28.5k|    SECKEYPublicKey *pubKey;
10198|  28.5k|    SECKEYPrivateKey *certPrivateKey;
10199|  28.5k|    const sslNamedGroupDef *groupDef;
10200|       |    /* Do this on the heap, this could be over 2k long. */
10201|  28.5k|    sslBuffer dhBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  28.5k|    {                        \
  |  |   24|  28.5k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  28.5k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  28.5k|    }
  ------------------
10202|       |
10203|  28.5k|    if (kea_def->kea != kea_dhe_dss && kea_def->kea != kea_dhe_rsa) {
  ------------------
  |  Branch (10203:9): [True: 28.5k, False: 0]
  |  Branch (10203:40): [True: 0, False: 28.5k]
  ------------------
10204|       |        /* TODO: Support DH_anon. It might be sufficient to drop the signature.
10205|       |                 See bug 1170510. */
10206|      0|        PORT_SetError(SSL_ERROR_SERVER_KEY_EXCHANGE_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10207|      0|        return SECFailure;
10208|      0|    }
10209|       |
10210|  28.5k|    rv = ssl_SelectDHEGroup(ss, &groupDef);
10211|  28.5k|    if (rv == SECFailure) {
  ------------------
  |  Branch (10211:9): [True: 0, False: 28.5k]
  ------------------
10212|      0|        PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10213|      0|        return SECFailure;
10214|      0|    }
10215|  28.5k|    ss->sec.keaGroup = groupDef;
10216|       |
10217|  28.5k|    params = ssl_GetDHEParams(groupDef);
10218|  28.5k|    rv = ssl_CreateDHEKeyPair(groupDef, params, &keyPair);
10219|  28.5k|    if (rv == SECFailure) {
  ------------------
  |  Branch (10219:9): [True: 0, False: 28.5k]
  ------------------
10220|      0|        ssl_MapLowLevelError(SEC_ERROR_KEYGEN_FAIL);
10221|      0|        return SECFailure;
10222|      0|    }
10223|  28.5k|    PR_APPEND_LINK(&keyPair->link, &ss->ephemeralKeyPairs);
  ------------------
  |  |   57|  28.5k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|  57.0k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|  28.5k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|  57.0k|    (_e)->next = (_l);   \
  |  |  |  |   27|  57.0k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|  57.0k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|  57.0k|    (_l)->prev = (_e);   \
  |  |  |  |   30|  57.0k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|  28.5k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10224|       |
10225|  28.5k|    if (ss->version == SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  28.5k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (10225:9): [True: 26.0k, False: 2.48k]
  ------------------
10226|  26.0k|        hashAlg = ssl_SignatureSchemeToHashType(ss->ssl3.hs.signatureScheme);
10227|  26.0k|    } else {
10228|       |        /* Use ssl_hash_none to represent the MD5+SHA1 combo. */
10229|  2.48k|        hashAlg = ssl_hash_none;
10230|  2.48k|    }
10231|       |
10232|  28.5k|    pubKey = keyPair->keys->pubKey;
10233|  28.5k|    PRINT_BUF(50, (ss, "DH public value:",
  ------------------
  |  |   74|  28.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 28.5k]
  |  |  ------------------
  |  |   75|  28.5k|    ssl_PrintBuf b
  ------------------
10234|  28.5k|                   pubKey->u.dh.publicValue.data,
10235|  28.5k|                   pubKey->u.dh.publicValue.len));
10236|  28.5k|    rv = ssl3_ComputeDHKeyHash(ss, hashAlg, &hashes,
10237|  28.5k|                               pubKey->u.dh.prime,
10238|  28.5k|                               pubKey->u.dh.base,
10239|  28.5k|                               pubKey->u.dh.publicValue,
10240|  28.5k|                               PR_TRUE /* padY */);
  ------------------
  |  |  437|  28.5k|#define PR_TRUE 1
  ------------------
10241|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10241:9): [True: 0, False: 28.5k]
  ------------------
10242|      0|        ssl_MapLowLevelError(SSL_ERROR_SERVER_KEY_EXCHANGE_FAILURE);
10243|      0|        goto loser;
10244|      0|    }
10245|       |
10246|  28.5k|    certPrivateKey = ss->sec.serverCert->serverKeyPair->privKey;
10247|  28.5k|    rv = ssl3_SignHashes(ss, &hashes, certPrivateKey, &signed_hash);
10248|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10248:9): [True: 0, False: 28.5k]
  ------------------
10249|      0|        goto loser; /* ssl3_SignHashes has set err. */
10250|      0|    }
10251|       |
10252|  28.5k|    length = 2 + pubKey->u.dh.prime.len +
10253|  28.5k|             2 + pubKey->u.dh.base.len +
10254|  28.5k|             2 + pubKey->u.dh.prime.len +
10255|  28.5k|             2 + signed_hash.len;
10256|       |
10257|  28.5k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  28.5k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (10257:9): [True: 26.0k, False: 2.48k]
  ------------------
10258|  26.0k|        length += 2;
10259|  26.0k|    }
10260|       |
10261|  28.5k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_server_key_exchange, length);
10262|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10262:9): [True: 0, False: 28.5k]
  ------------------
10263|      0|        goto loser; /* err set by AppendHandshake. */
10264|      0|    }
10265|       |
10266|  28.5k|    rv = ssl3_AppendHandshakeVariable(ss, pubKey->u.dh.prime.data,
10267|  28.5k|                                      pubKey->u.dh.prime.len, 2);
10268|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10268:9): [True: 0, False: 28.5k]
  ------------------
10269|      0|        goto loser; /* err set by AppendHandshake. */
10270|      0|    }
10271|       |
10272|  28.5k|    rv = ssl3_AppendHandshakeVariable(ss, pubKey->u.dh.base.data,
10273|  28.5k|                                      pubKey->u.dh.base.len, 2);
10274|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10274:9): [True: 0, False: 28.5k]
  ------------------
10275|      0|        goto loser; /* err set by AppendHandshake. */
10276|      0|    }
10277|       |
10278|  28.5k|    rv = ssl_AppendPaddedDHKeyShare(&dhBuf, pubKey, PR_TRUE);
  ------------------
  |  |  437|  28.5k|#define PR_TRUE 1
  ------------------
10279|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10279:9): [True: 0, False: 28.5k]
  ------------------
10280|      0|        goto loser; /* err set by AppendPaddedDHKeyShare. */
10281|      0|    }
10282|  28.5k|    rv = ssl3_AppendBufferToHandshake(ss, &dhBuf);
10283|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10283:9): [True: 0, False: 28.5k]
  ------------------
10284|      0|        goto loser; /* err set by AppendHandshake. */
10285|      0|    }
10286|       |
10287|  28.5k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  28.5k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (10287:9): [True: 26.0k, False: 2.48k]
  ------------------
10288|  26.0k|        rv = ssl3_AppendHandshakeNumber(ss, ss->ssl3.hs.signatureScheme, 2);
10289|  26.0k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10289:13): [True: 0, False: 26.0k]
  ------------------
10290|      0|            goto loser; /* err set by AppendHandshake. */
10291|      0|        }
10292|  26.0k|    }
10293|       |
10294|  28.5k|    rv = ssl3_AppendHandshakeVariable(ss, signed_hash.data,
10295|  28.5k|                                      signed_hash.len, 2);
10296|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10296:9): [True: 0, False: 28.5k]
  ------------------
10297|      0|        goto loser; /* err set by AppendHandshake. */
10298|      0|    }
10299|       |
10300|  28.5k|    sslBuffer_Clear(&dhBuf);
10301|  28.5k|    PORT_Free(signed_hash.data);
  ------------------
  |  |   60|  28.5k|#define PORT_Free PORT_Free_Util
  ------------------
10302|  28.5k|    return SECSuccess;
10303|       |
10304|      0|loser:
10305|      0|    if (signed_hash.data)
  ------------------
  |  Branch (10305:9): [True: 0, False: 0]
  ------------------
10306|      0|        PORT_Free(signed_hash.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
10307|      0|    sslBuffer_Clear(&dhBuf);
10308|      0|    return SECFailure;
10309|  28.5k|}
ssl3con.c:ssl3_ComputeDHKeyHash:
 1578|  28.5k|{
 1579|  28.5k|    sslBuffer buf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  28.5k|    {                        \
  |  |   24|  28.5k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  28.5k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  28.5k|    }
  ------------------
 1580|  28.5k|    SECStatus rv;
 1581|  28.5k|    unsigned int yLen;
 1582|  28.5k|    unsigned int i;
 1583|       |
 1584|  28.5k|    PORT_Assert(dh_p.data);
  ------------------
  |  |  120|  28.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  28.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 28.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1585|  28.5k|    PORT_Assert(dh_g.data);
  ------------------
  |  |  120|  28.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  28.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 28.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1586|  28.5k|    PORT_Assert(dh_Ys.data);
  ------------------
  |  |  120|  28.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  28.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 28.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1587|       |
 1588|  28.5k|    rv = sslBuffer_Append(&buf, ss->ssl3.hs.client_random, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|  28.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 1589|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1589:9): [True: 0, False: 28.5k]
  ------------------
 1590|      0|        goto loser;
 1591|      0|    }
 1592|  28.5k|    rv = sslBuffer_Append(&buf, ss->ssl3.hs.server_random, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|  28.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 1593|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1593:9): [True: 0, False: 28.5k]
  ------------------
 1594|      0|        goto loser;
 1595|      0|    }
 1596|       |    /* p */
 1597|  28.5k|    rv = sslBuffer_AppendVariable(&buf, dh_p.data, dh_p.len, 2);
 1598|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1598:9): [True: 0, False: 28.5k]
  ------------------
 1599|      0|        goto loser;
 1600|      0|    }
 1601|       |    /* g */
 1602|  28.5k|    rv = sslBuffer_AppendVariable(&buf, dh_g.data, dh_g.len, 2);
 1603|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1603:9): [True: 0, False: 28.5k]
  ------------------
 1604|      0|        goto loser;
 1605|      0|    }
 1606|       |    /* y - complicated by padding */
 1607|  28.5k|    yLen = padY ? dh_p.len : dh_Ys.len;
  ------------------
  |  Branch (1607:12): [True: 28.5k, False: 0]
  ------------------
 1608|  28.5k|    rv = sslBuffer_AppendNumber(&buf, yLen, 2);
 1609|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1609:9): [True: 0, False: 28.5k]
  ------------------
 1610|      0|        goto loser;
 1611|      0|    }
 1612|       |    /* If we're padding Y, dh_Ys can't be longer than dh_p. */
 1613|  28.5k|    PORT_Assert(!padY || dh_p.len >= dh_Ys.len);
  ------------------
  |  |  120|  28.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  57.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 28.5k]
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1614|  28.8k|    for (i = dh_Ys.len; i < yLen; ++i) {
  ------------------
  |  Branch (1614:25): [True: 309, False: 28.5k]
  ------------------
 1615|    309|        rv = sslBuffer_AppendNumber(&buf, 0, 1);
 1616|    309|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1616:13): [True: 0, False: 309]
  ------------------
 1617|      0|            goto loser;
 1618|      0|        }
 1619|    309|    }
 1620|  28.5k|    rv = sslBuffer_Append(&buf, dh_Ys.data, dh_Ys.len);
 1621|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1621:9): [True: 0, False: 28.5k]
  ------------------
 1622|      0|        goto loser;
 1623|      0|    }
 1624|       |
 1625|  28.5k|    rv = ssl3_ComputeCommonKeyHash(hashAlg, SSL_BUFFER_BASE(&buf),
  ------------------
  |  |   35|  28.5k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
 1626|  28.5k|                                   SSL_BUFFER_LEN(&buf), hashes);
  ------------------
  |  |   36|  28.5k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 1627|  28.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1627:9): [True: 0, False: 28.5k]
  ------------------
 1628|      0|        goto loser;
 1629|      0|    }
 1630|       |
 1631|  28.5k|    PRINT_BUF(95, (NULL, "DHkey hash: ", SSL_BUFFER_BASE(&buf),
  ------------------
  |  |   74|  28.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 28.5k]
  |  |  ------------------
  |  |   75|  28.5k|    ssl_PrintBuf b
  ------------------
 1632|  28.5k|                   SSL_BUFFER_LEN(&buf)));
 1633|  28.5k|    if (hashAlg == ssl_hash_none) {
  ------------------
  |  Branch (1633:9): [True: 2.48k, False: 26.0k]
  ------------------
 1634|  2.48k|        PRINT_BUF(95, (NULL, "DHkey hash: MD5 result",
  ------------------
  |  |   74|  2.48k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 2.48k]
  |  |  ------------------
  |  |   75|  2.48k|    ssl_PrintBuf b
  ------------------
 1635|  2.48k|                       hashes->u.s.md5, MD5_LENGTH));
 1636|  2.48k|        PRINT_BUF(95, (NULL, "DHkey hash: SHA1 result",
  ------------------
  |  |   74|  2.48k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 2.48k]
  |  |  ------------------
  |  |   75|  2.48k|    ssl_PrintBuf b
  ------------------
 1637|  2.48k|                       hashes->u.s.sha, SHA1_LENGTH));
 1638|  26.0k|    } else {
 1639|  26.0k|        PRINT_BUF(95, (NULL, "DHkey hash: result",
  ------------------
  |  |   74|  26.0k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 26.0k]
  |  |  ------------------
  |  |   75|  26.0k|    ssl_PrintBuf b
  ------------------
 1640|  26.0k|                       hashes->u.raw, hashes->len));
 1641|  26.0k|    }
 1642|       |
 1643|  28.5k|    sslBuffer_Clear(&buf);
 1644|  28.5k|    return SECSuccess;
 1645|       |
 1646|      0|loser:
 1647|      0|    sslBuffer_Clear(&buf);
 1648|      0|    return SECFailure;
 1649|  28.5k|}
ssl3con.c:ssl3_SendCertificateRequest:
10469|  5.11k|{
10470|  5.11k|    PRBool isTLS12;
10471|  5.11k|    const PRUint8 *certTypes;
10472|  5.11k|    SECStatus rv;
10473|  5.11k|    PRUint32 length;
10474|  5.11k|    const SECItem *names;
10475|  5.11k|    unsigned int calen;
10476|  5.11k|    unsigned int nnames;
10477|  5.11k|    const SECItem *name;
10478|  5.11k|    unsigned int i;
10479|  5.11k|    int certTypesLength;
10480|  5.11k|    PRUint8 sigAlgs[2 + MAX_SIGNATURE_SCHEMES * 2];
10481|  5.11k|    sslBuffer sigAlgsBuf = SSL_BUFFER(sigAlgs);
  ------------------
  |  |   34|  5.11k|#define SSL_BUFFER(b) SSL_BUFFER_FIXED(b, sizeof(b))
  |  |  ------------------
  |  |  |  |   27|  5.11k|    {                               \
  |  |  |  |   28|  5.11k|        b, 0, maxlen, PR_TRUE       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  437|  5.11k|#define PR_TRUE 1
  |  |  |  |  ------------------
  |  |  |  |   29|  5.11k|    }
  |  |  ------------------
  ------------------
10482|       |
10483|  5.11k|    SSL_TRC(3, ("%d: SSL3[%d]: send certificate_request handshake",
  ------------------
  |  |   71|  5.11k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 5.11k]
  |  |  ------------------
  |  |   72|  5.11k|    ssl_Trace b
  ------------------
10484|  5.11k|                SSL_GETPID(), ss->fd));
10485|       |
10486|  5.11k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  5.11k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.76k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2.46k, False: 2.65k]
  |  |  |  |  |  Branch (208:7): [True: 2.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10487|  5.11k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  5.11k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.76k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2.46k, False: 2.65k]
  |  |  |  |  |  Branch (208:7): [True: 2.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10488|       |
10489|  5.11k|    isTLS12 = (PRBool)(ss->version >= SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |   20|  5.11k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
10490|       |
10491|  5.11k|    rv = ssl_GetCertificateRequestCAs(ss, &calen, &names, &nnames);
10492|  5.11k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10492:9): [True: 0, False: 5.11k]
  ------------------
10493|      0|        return rv;
10494|      0|    }
10495|  5.11k|    certTypes = certificate_types;
10496|  5.11k|    certTypesLength = sizeof certificate_types;
10497|       |
10498|  5.11k|    length = 1 + certTypesLength + 2 + calen;
10499|  5.11k|    if (isTLS12) {
  ------------------
  |  Branch (10499:9): [True: 4.81k, False: 292]
  ------------------
10500|  4.81k|        rv = ssl3_EncodeSigAlgs(ss, ss->version, PR_TRUE /* forCert */,
  ------------------
  |  |  437|  4.81k|#define PR_TRUE 1
  ------------------
10501|  4.81k|                                PR_FALSE /* GREASE */, &sigAlgsBuf);
  ------------------
  |  |  438|  4.81k|#define PR_FALSE 0
  ------------------
10502|  4.81k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10502:13): [True: 0, False: 4.81k]
  ------------------
10503|      0|            return rv;
10504|      0|        }
10505|  4.81k|        length += SSL_BUFFER_LEN(&sigAlgsBuf);
  ------------------
  |  |   36|  4.81k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
10506|  4.81k|    }
10507|       |
10508|  5.11k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_certificate_request, length);
10509|  5.11k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10509:9): [True: 0, False: 5.11k]
  ------------------
10510|      0|        return rv; /* err set by AppendHandshake. */
10511|      0|    }
10512|  5.11k|    rv = ssl3_AppendHandshakeVariable(ss, certTypes, certTypesLength, 1);
10513|  5.11k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10513:9): [True: 0, False: 5.11k]
  ------------------
10514|      0|        return rv; /* err set by AppendHandshake. */
10515|      0|    }
10516|  5.11k|    if (isTLS12) {
  ------------------
  |  Branch (10516:9): [True: 4.81k, False: 292]
  ------------------
10517|  4.81k|        rv = ssl3_AppendHandshake(ss, SSL_BUFFER_BASE(&sigAlgsBuf),
  ------------------
  |  |   35|  4.81k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
10518|  4.81k|                                  SSL_BUFFER_LEN(&sigAlgsBuf));
  ------------------
  |  |   36|  4.81k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
10519|  4.81k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10519:13): [True: 0, False: 4.81k]
  ------------------
10520|      0|            return rv; /* err set by AppendHandshake. */
10521|      0|        }
10522|  4.81k|    }
10523|  5.11k|    rv = ssl3_AppendHandshakeNumber(ss, calen, 2);
10524|  5.11k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10524:9): [True: 0, False: 5.11k]
  ------------------
10525|      0|        return rv; /* err set by AppendHandshake. */
10526|      0|    }
10527|  5.11k|    for (i = 0, name = names; i < nnames; i++, name++) {
  ------------------
  |  Branch (10527:31): [True: 0, False: 5.11k]
  ------------------
10528|      0|        rv = ssl3_AppendHandshakeVariable(ss, name->data, name->len, 2);
10529|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10529:13): [True: 0, False: 0]
  ------------------
10530|      0|            return rv; /* err set by AppendHandshake. */
10531|      0|        }
10532|      0|    }
10533|       |
10534|  5.11k|    return SECSuccess;
10535|  5.11k|}
ssl3con.c:ssl3_SendServerHelloDone:
10539|  58.7k|{
10540|  58.7k|    SECStatus rv;
10541|       |
10542|  58.7k|    SSL_TRC(3, ("%d: SSL3[%d]: send server_hello_done handshake",
  ------------------
  |  |   71|  58.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 58.7k]
  |  |  ------------------
  |  |   72|  58.7k|    ssl_Trace b
  ------------------
10543|  58.7k|                SSL_GETPID(), ss->fd));
10544|       |
10545|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10546|  58.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  58.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  88.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 28.5k, False: 30.1k]
  |  |  |  |  |  Branch (208:7): [True: 30.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10547|       |
10548|  58.7k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_server_hello_done, 0);
10549|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10549:9): [True: 0, False: 58.7k]
  ------------------
10550|      0|        return rv; /* err set by AppendHandshake. */
10551|      0|    }
10552|  58.7k|    rv = ssl3_FlushHandshake(ss, 0);
10553|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10553:9): [True: 6, False: 58.7k]
  ------------------
10554|      6|        return rv; /* error code set by ssl3_FlushHandshake */
10555|      6|    }
10556|  58.7k|    return SECSuccess;
10557|  58.7k|}
ssl3con.c:ssl_GenerateServerRandom:
 8913|  59.9k|{
 8914|  59.9k|    SECStatus rv;
 8915|  59.9k|    PRUint8 *downgradeSentinel;
 8916|       |
 8917|  59.9k|    rv = ssl3_GetNewRandom(ss->ssl3.hs.server_random);
 8918|  59.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (8918:9): [True: 0, False: 59.9k]
  ------------------
 8919|      0|        return SECFailure;
 8920|      0|    }
 8921|       |
 8922|  59.9k|    if (ss->version == ss->vrange.max) {
  ------------------
  |  Branch (8922:9): [True: 17.8k, False: 42.0k]
  ------------------
 8923|  17.8k|        return SECSuccess;
 8924|  17.8k|    }
 8925|       |
 8926|       |    /*
 8927|       |     * [RFC 8446 Section 4.1.3].
 8928|       |     *
 8929|       |     * TLS 1.3 servers which negotiate TLS 1.2 or below in response to a
 8930|       |     * ClientHello MUST set the last 8 bytes of their Random value specially in
 8931|       |     * their ServerHello.
 8932|       |     *
 8933|       |     * If negotiating TLS 1.2, TLS 1.3 servers MUST set the last 8 bytes of
 8934|       |     * their Random value to the bytes:
 8935|       |     *
 8936|       |     *   44 4F 57 4E 47 52 44 01
 8937|       |     *
 8938|       |     * If negotiating TLS 1.1 or below, TLS 1.3 servers MUST, and TLS 1.2
 8939|       |     * servers SHOULD, set the last 8 bytes of their ServerHello.Random value to
 8940|       |     * the bytes:
 8941|       |     *
 8942|       |     *   44 4F 57 4E 47 52 44 00
 8943|       |     */
 8944|  42.0k|    downgradeSentinel =
 8945|  42.0k|        ss->ssl3.hs.server_random +
 8946|  42.0k|        SSL3_RANDOM_LENGTH - sizeof(tls12_downgrade_random);
  ------------------
  |  |   24|  42.0k|#define SSL3_RANDOM_LENGTH 32
  ------------------
 8947|  42.0k|    if (ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  42.0k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (8947:9): [True: 41.9k, False: 161]
  ------------------
 8948|  41.9k|        switch (ss->version) {
 8949|  41.8k|            case SSL_LIBRARY_VERSION_TLS_1_2:
  ------------------
  |  |   20|  41.8k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (8949:13): [True: 41.8k, False: 52]
  ------------------
 8950|       |                /* vrange.max > 1.2, since we didn't early exit above. */
 8951|  41.8k|                PORT_Memcpy(downgradeSentinel,
  ------------------
  |  |  180|  41.8k|#define PORT_Memcpy memcpy
  ------------------
 8952|  41.8k|                            tls12_downgrade_random, sizeof(tls12_downgrade_random));
 8953|  41.8k|                break;
 8954|     20|            case SSL_LIBRARY_VERSION_TLS_1_1:
  ------------------
  |  |   19|     20|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  ------------------
  |  Branch (8954:13): [True: 20, False: 41.8k]
  ------------------
 8955|     52|            case SSL_LIBRARY_VERSION_TLS_1_0:
  ------------------
  |  |   18|     52|#define SSL_LIBRARY_VERSION_TLS_1_0             0x0301
  ------------------
  |  Branch (8955:13): [True: 32, False: 41.8k]
  ------------------
 8956|     52|                PORT_Memcpy(downgradeSentinel,
  ------------------
  |  |  180|     52|#define PORT_Memcpy memcpy
  ------------------
 8957|     52|                            tls1_downgrade_random, sizeof(tls1_downgrade_random));
 8958|     52|                break;
 8959|      0|            default:
  ------------------
  |  Branch (8959:13): [True: 0, False: 41.9k]
  ------------------
 8960|       |                /* Do not change random. */
 8961|      0|                break;
 8962|  41.9k|        }
 8963|  41.9k|    }
 8964|       |
 8965|  42.0k|    return SECSuccess;
 8966|  42.0k|}
ssl3con.c:ssl_SignatureSchemeAccepted:
  841|  1.78M|{
  842|       |    /* Disable RSA-PSS schemes if there are no tokens to verify them. */
  843|  1.78M|    if (ssl_IsRsaPssSignatureScheme(scheme)) {
  ------------------
  |  Branch (843:9): [True: 1.14M, False: 637k]
  ------------------
  844|  1.14M|        if (!PK11_TokenExists(auth_alg_defs[ssl_auth_rsa_pss])) {
  ------------------
  |  Branch (844:13): [True: 0, False: 1.14M]
  ------------------
  845|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  846|      0|        }
  847|  1.14M|    } else if (!forCert && ssl_IsRsaPkcs1SignatureScheme(scheme)) {
  ------------------
  |  Branch (847:16): [True: 576k, False: 61.4k]
  |  Branch (847:28): [True: 3.57k, False: 572k]
  ------------------
  848|       |        /* Disable PKCS#1 signatures if we are limited to TLS 1.3.
  849|       |         * We still need to advertise PKCS#1 signatures in CH and CR
  850|       |         * for certificate signatures.
  851|       |         */
  852|  3.57k|        if (minVersion >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  3.57k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (852:13): [True: 3.57k, False: 0]
  ------------------
  853|  3.57k|            return PR_FALSE;
  ------------------
  |  |  438|  3.57k|#define PR_FALSE 0
  ------------------
  854|  3.57k|        }
  855|   633k|    } else if (ssl_IsDsaSignatureScheme(scheme)) {
  ------------------
  |  Branch (855:16): [True: 24.6k, False: 609k]
  ------------------
  856|       |        /* DSA: not in TLS 1.3, and check policy. */
  857|  24.6k|        if (minVersion >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  24.6k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (857:13): [True: 5.36k, False: 19.2k]
  ------------------
  858|  5.36k|            return PR_FALSE;
  ------------------
  |  |  438|  5.36k|#define PR_FALSE 0
  ------------------
  859|  5.36k|        }
  860|  24.6k|    }
  861|       |
  862|  1.77M|    return ssl_SchemePolicyOK(scheme, kSSLSigSchemePolicy);
  863|  1.78M|}
ssl3con.c:ssl3_FinishHandshake:
12521|  52.5k|{
12522|  52.5k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.5k, False: 26.9k]
  |  |  |  |  |  Branch (208:7): [True: 26.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12523|  52.5k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.5k, False: 26.9k]
  |  |  |  |  |  Branch (208:7): [True: 26.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12524|  52.5k|    PORT_Assert(ss->ssl3.hs.restartTarget == NULL);
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  52.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 52.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12525|  52.5k|    sslSessionID *sid = ss->sec.ci.sid;
12526|  52.5k|    SECStatus sidRv = SECFailure;
12527|       |
12528|       |    /* The first handshake is now completed. */
12529|  52.5k|    ss->handshake = NULL;
12530|       |
12531|  52.5k|    if (sid->cached == never_cached && !ss->opt.noCache) {
  ------------------
  |  Branch (12531:9): [True: 52.5k, False: 0]
  |  Branch (12531:40): [True: 30.3k, False: 22.2k]
  ------------------
12532|       |        /* If the wrap fails, don't cache the sid. The connection proceeds
12533|       |         * normally, so the rv is only used to determine whether we cache. */
12534|  30.3k|        sidRv = ssl3_FillInCachedSID(ss, sid, ss->ssl3.crSpec->masterSecret);
12535|  30.3k|    }
12536|       |
12537|       |    /* RFC 5077 Section 3.3: "The client MUST NOT treat the ticket as valid
12538|       |     * until it has verified the server's Finished message." When the server
12539|       |     * sends a NewSessionTicket in a resumption handshake, we must wait until
12540|       |     * the handshake is finished (we have verified the server's Finished
12541|       |     * AND the server's certificate) before we update the ticket in the sid.
12542|       |     *
12543|       |     * This must be done before we call ssl_CacheSessionID(ss)
12544|       |     * because CacheSID requires the session ticket to already be set, and also
12545|       |     * because of the lazy lock creation scheme used by CacheSID and
12546|       |     * ssl3_SetSIDSessionTicket. */
12547|  52.5k|    if (ss->ssl3.hs.receivedNewSessionTicket) {
  ------------------
  |  Branch (12547:9): [True: 0, False: 52.5k]
  ------------------
12548|      0|        PORT_Assert(!ss->sec.isServer);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12549|      0|        if (sidRv == SECSuccess) {
  ------------------
  |  Branch (12549:13): [True: 0, False: 0]
  ------------------
12550|       |            /* The sid takes over the ticket data */
12551|      0|            ssl3_SetSIDSessionTicket(ss->sec.ci.sid,
12552|      0|                                     &ss->ssl3.hs.newSessionTicket);
12553|      0|        } else {
12554|      0|            PORT_Assert(ss->ssl3.hs.newSessionTicket.ticket.data);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12555|      0|            SECITEM_FreeItem(&ss->ssl3.hs.newSessionTicket.ticket,
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
12556|      0|                             PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
12557|      0|        }
12558|      0|        PORT_Assert(!ss->ssl3.hs.newSessionTicket.ticket.data);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12559|      0|        ss->ssl3.hs.receivedNewSessionTicket = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
12560|      0|    }
12561|  52.5k|    if (sidRv == SECSuccess) {
  ------------------
  |  Branch (12561:9): [True: 30.3k, False: 22.2k]
  ------------------
12562|  30.3k|        PORT_Assert(ss->sec.ci.sid->cached == never_cached);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12563|  30.3k|        ssl_CacheSessionID(ss);
12564|  30.3k|    }
12565|       |
12566|  52.5k|    ss->ssl3.hs.canFalseStart = PR_FALSE; /* False Start phase is complete */
  ------------------
  |  |  438|  52.5k|#define PR_FALSE 0
  ------------------
12567|  52.5k|    ss->ssl3.hs.ws = idle_handshake;
12568|       |
12569|  52.5k|    return ssl_FinishHandshake(ss);
12570|  52.5k|}
ssl3con.c:ssl3_HandleClientHello:
 9096|  61.2k|{
 9097|  61.2k|    sslSessionID *sid = NULL;
 9098|  61.2k|    unsigned int i;
 9099|  61.2k|    SECStatus rv;
 9100|  61.2k|    PRUint32 extensionLength;
 9101|  61.2k|    int errCode = SSL_ERROR_RX_MALFORMED_CLIENT_HELLO;
 9102|  61.2k|    SSL3AlertDescription desc = illegal_parameter;
 9103|  61.2k|    SSL3AlertLevel level = alert_fatal;
 9104|  61.2k|    TLSExtension *versionExtension;
 9105|  61.2k|    SECItem sidBytes = { siBuffer, NULL, 0 };
 9106|  61.2k|    SECItem cookieBytes = { siBuffer, NULL, 0 };
 9107|  61.2k|    SECItem suites = { siBuffer, NULL, 0 };
 9108|  61.2k|    SECItem comps = { siBuffer, NULL, 0 };
 9109|  61.2k|    SECItem *echInner = NULL;
 9110|  61.2k|    PRBool isTLS13;
 9111|  61.2k|    const PRUint8 *savedMsg = b;
 9112|  61.2k|    const PRUint32 savedLen = length;
 9113|       |
 9114|  61.2k|    SSL_TRC(3, ("%d: SSL3[%d]: handle client_hello handshake",
  ------------------
  |  |   71|  61.2k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 61.2k]
  |  |  ------------------
  |  |   72|  61.2k|    ssl_Trace b
  ------------------
 9115|  61.2k|                SSL_GETPID(), ss->fd));
 9116|       |
 9117|  61.2k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  61.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  92.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 29.7k, False: 31.4k]
  |  |  |  |  |  Branch (208:7): [True: 31.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 9118|  61.2k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  61.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  92.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 29.7k, False: 31.4k]
  |  |  |  |  |  Branch (208:7): [True: 31.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 9119|  61.2k|    ss->ssl3.hs.preliminaryInfo = 0;
 9120|       |
 9121|  61.2k|    if (!ss->sec.isServer ||
  ------------------
  |  Branch (9121:9): [True: 0, False: 61.2k]
  ------------------
 9122|  61.2k|        (ss->ssl3.hs.ws != wait_client_hello &&
  ------------------
  |  Branch (9122:10): [True: 52.1k, False: 9.09k]
  ------------------
 9123|  61.2k|         ss->ssl3.hs.ws != idle_handshake)) {
  ------------------
  |  Branch (9123:10): [True: 38, False: 52.1k]
  ------------------
 9124|     38|        desc = unexpected_message;
 9125|     38|        errCode = SSL_ERROR_RX_UNEXPECTED_CLIENT_HELLO;
 9126|     38|        goto alert_loser;
 9127|     38|    }
 9128|  61.2k|    if (ss->ssl3.hs.ws == idle_handshake) {
  ------------------
  |  Branch (9128:9): [True: 52.1k, False: 9.09k]
  ------------------
 9129|       |        /* Refuse re-handshake when we have already negotiated TLS 1.3. */
 9130|  52.1k|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  52.1k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (9130:13): [True: 1, False: 52.1k]
  ------------------
 9131|      1|            desc = unexpected_message;
 9132|      1|            errCode = SSL_ERROR_RENEGOTIATION_NOT_ALLOWED;
 9133|      1|            goto alert_loser;
 9134|      1|        }
 9135|  52.1k|        if (ss->opt.enableRenegotiation == SSL_RENEGOTIATE_NEVER) {
  ------------------
  |  |  711|  52.1k|#define SSL_RENEGOTIATE_NEVER ((PRBool)0)
  ------------------
  |  Branch (9135:13): [True: 0, False: 52.1k]
  ------------------
 9136|      0|            desc = no_renegotiation;
 9137|      0|            level = alert_warning;
 9138|      0|            errCode = SSL_ERROR_RENEGOTIATION_NOT_ALLOWED;
 9139|      0|            goto alert_loser;
 9140|      0|        }
 9141|  52.1k|    }
 9142|       |
 9143|       |    /* We should always be in a fresh state. */
 9144|  61.2k|    SSL_ASSERT_HASHES_EMPTY(ss);
  ------------------
  |  |  815|  61.2k|    do {                                                             \
  |  |  816|  61.2k|        PORT_Assert(ss->ssl3.hs.hashType == handshake_hash_unknown); \
  |  |  ------------------
  |  |  |  |  120|  61.2k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  61.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 61.2k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  817|  61.2k|        PORT_Assert(ss->ssl3.hs.messages.len == 0);                  \
  |  |  ------------------
  |  |  |  |  120|  61.2k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  61.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 61.2k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  818|  61.2k|        PORT_Assert(ss->ssl3.hs.echInnerMessages.len == 0);          \
  |  |  ------------------
  |  |  |  |  120|  61.2k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  61.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 61.2k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  819|  61.2k|    } while (0)
  |  |  ------------------
  |  |  |  Branch (819:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9145|       |
 9146|       |    /* Get peer name of client */
 9147|  61.2k|    rv = ssl_GetPeerInfo(ss);
 9148|  61.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9148:9): [True: 0, False: 61.2k]
  ------------------
 9149|      0|        return rv; /* error code is set. */
 9150|      0|    }
 9151|       |
 9152|       |    /* We might be starting session renegotiation in which case we should
 9153|       |     * clear previous state.
 9154|       |     */
 9155|  61.2k|    ssl3_ResetExtensionData(&ss->xtnData, ss);
 9156|  61.2k|    ss->statelessResume = PR_FALSE;
  ------------------
  |  |  438|  61.2k|#define PR_FALSE 0
  ------------------
 9157|       |
 9158|  61.2k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  61.2k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 61.2k]
  |  |  ------------------
  ------------------
 9159|      0|        dtls_RehandshakeCleanup(ss);
 9160|      0|    }
 9161|       |
 9162|  61.2k|    rv = ssl3_HandleClientHelloPreamble(ss, &b, &length, &sidBytes,
 9163|  61.2k|                                        &cookieBytes, &suites, &comps);
 9164|  61.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9164:9): [True: 135, False: 61.0k]
  ------------------
 9165|    135|        goto loser; /* malformed */
 9166|    135|    }
 9167|       |
 9168|       |    /* Handle TLS hello extensions for SSL3 & TLS. We do not know if
 9169|       |     * we are restarting a previous session until extensions have been
 9170|       |     * parsed, since we might have received a SessionTicket extension.
 9171|       |     * Note: we allow extensions even when negotiating SSL3 for the sake
 9172|       |     * of interoperability (and backwards compatibility).
 9173|       |     */
 9174|  61.0k|    if (length) {
  ------------------
  |  Branch (9174:9): [True: 17.7k, False: 43.3k]
  ------------------
 9175|       |        /* Get length of hello extensions */
 9176|  17.7k|        rv = ssl3_ConsumeHandshakeNumber(ss, &extensionLength, 2, &b, &length);
 9177|  17.7k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (9177:13): [True: 2, False: 17.7k]
  ------------------
 9178|      2|            goto loser; /* alert already sent */
 9179|      2|        }
 9180|  17.7k|        if (extensionLength != length) {
  ------------------
  |  Branch (9180:13): [True: 41, False: 17.7k]
  ------------------
 9181|     41|            errCode = SSL_ERROR_RX_MALFORMED_CLIENT_HELLO;
 9182|     41|            desc = decode_error;
 9183|     41|            goto alert_loser;
 9184|     41|        }
 9185|       |
 9186|  17.7k|        rv = ssl3_ParseExtensions(ss, &b, &length);
 9187|  17.7k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (9187:13): [True: 22, False: 17.7k]
  ------------------
 9188|     22|            goto loser; /* malformed */
 9189|     22|        }
 9190|  17.7k|    }
 9191|       |
 9192|  61.0k|    versionExtension = ssl3_FindExtension(ss, ssl_tls13_supported_versions_xtn);
 9193|  61.0k|    if (versionExtension) {
  ------------------
  |  Branch (9193:9): [True: 2.73k, False: 58.2k]
  ------------------
 9194|  2.73k|        rv = tls13_NegotiateVersion(ss, versionExtension);
 9195|  2.73k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (9195:13): [True: 33, False: 2.70k]
  ------------------
 9196|     33|            errCode = PORT_GetError();
  ------------------
  |  |   62|     33|#define PORT_GetError PORT_GetError_Util
  ------------------
 9197|     33|            desc = (errCode == SSL_ERROR_UNSUPPORTED_VERSION) ? protocol_version : illegal_parameter;
  ------------------
  |  Branch (9197:20): [True: 26, False: 7]
  ------------------
 9198|     33|            goto alert_loser;
 9199|     33|        }
 9200|  58.2k|    } else {
 9201|       |        /* The PR_MIN here ensures that we never negotiate 1.3 if the
 9202|       |         * peer didn't offer "supported_versions". */
 9203|  58.2k|        rv = ssl3_NegotiateVersion(ss,
 9204|  58.2k|                                   PR_MIN(ss->clientHelloVersion,
  ------------------
  |  |  158|  58.2k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 50, False: 58.2k]
  |  |  ------------------
  ------------------
 9205|  58.2k|                                          SSL_LIBRARY_VERSION_TLS_1_2),
 9206|  58.2k|                                   PR_TRUE);
  ------------------
  |  |  437|  58.2k|#define PR_TRUE 1
  ------------------
 9207|       |        /* Send protocol version alert if the ClientHello.legacy_version is not
 9208|       |         * supported by the server.
 9209|       |         *
 9210|       |         * If the "supported_versions" extension is absent and the server only
 9211|       |         * supports versions greater than ClientHello.legacy_version, the
 9212|       |         * server MUST abort the handshake with a "protocol_version" alert
 9213|       |         * [RFC8446, Appendix D.2]. */
 9214|  58.2k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (9214:13): [True: 19, False: 58.2k]
  ------------------
 9215|     19|            desc = protocol_version;
 9216|     19|            errCode = SSL_ERROR_UNSUPPORTED_VERSION;
 9217|     19|            goto alert_loser;
 9218|     19|        }
 9219|  58.2k|    }
 9220|  60.9k|    ss->ssl3.hs.preliminaryInfo |= ssl_preinfo_version;
  ------------------
  |  |  392|  60.9k|#define ssl_preinfo_version (1U << 0)
  ------------------
 9221|       |
 9222|       |    /* Update the write spec to match the selected version. */
 9223|  60.9k|    if (!ss->firstHsDone) {
  ------------------
  |  Branch (9223:9): [True: 8.89k, False: 52.0k]
  ------------------
 9224|  8.89k|        ssl_GetSpecWriteLock(ss);
  ------------------
  |  | 1435|  8.89k|    {                                            \
  |  | 1436|  8.89k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 4.58k, False: 4.30k]
  |  |  ------------------
  |  | 1437|  8.89k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  4.58k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  8.89k|    }
  ------------------
 9225|  8.89k|        ssl_SetSpecVersions(ss, ss->ssl3.cwSpec);
 9226|  8.89k|        ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|  8.89k|    {                                              \
  |  | 1441|  8.89k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 4.58k, False: 4.30k]
  |  |  ------------------
  |  | 1442|  8.89k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  4.58k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  8.89k|    }
  ------------------
 9227|  8.89k|    }
 9228|       |
 9229|  60.9k|    isTLS13 = ss->version >= SSL_LIBRARY_VERSION_TLS_1_3;
  ------------------
  |  |   21|  60.9k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
 9230|  60.9k|    if (isTLS13) {
  ------------------
  |  Branch (9230:9): [True: 1.88k, False: 59.0k]
  ------------------
 9231|  1.88k|        if (ss->firstHsDone) {
  ------------------
  |  Branch (9231:13): [True: 1, False: 1.88k]
  ------------------
 9232|      1|            desc = unexpected_message;
 9233|      1|            errCode = SSL_ERROR_RENEGOTIATION_NOT_ALLOWED;
 9234|      1|            goto alert_loser;
 9235|      1|        }
 9236|       |
 9237|       |        /* If there is a cookie, then this is a second ClientHello (TLS 1.3). */
 9238|  1.88k|        if (ssl3_FindExtension(ss, ssl_tls13_cookie_xtn)) {
  ------------------
  |  Branch (9238:13): [True: 71, False: 1.81k]
  ------------------
 9239|     71|            ss->ssl3.hs.helloRetry = PR_TRUE;
  ------------------
  |  |  437|     71|#define PR_TRUE 1
  ------------------
 9240|     71|        }
 9241|       |
 9242|  1.88k|        rv = tls13_MaybeHandleEch(ss, savedMsg, savedLen, &sidBytes,
 9243|  1.88k|                                  &comps, &cookieBytes, &suites, &echInner);
 9244|  1.88k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (9244:13): [True: 32, False: 1.85k]
  ------------------
 9245|     32|            errCode = PORT_GetError();
  ------------------
  |  |   62|     32|#define PORT_GetError PORT_GetError_Util
  ------------------
 9246|     32|            goto loser; /* code set, alert sent. */
 9247|     32|        }
 9248|  1.88k|    }
 9249|       |
 9250|  60.9k|    rv = ssl3_ValidatePreambleWithVersion(ss, &sidBytes, &comps, &cookieBytes);
 9251|  60.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9251:9): [True: 21, False: 60.9k]
  ------------------
 9252|     21|        errCode = PORT_GetError();
  ------------------
  |  |   62|     21|#define PORT_GetError PORT_GetError_Util
  ------------------
 9253|     21|        goto loser; /* code set, alert sent. */
 9254|     21|    }
 9255|       |
 9256|       |    /* Now parse the rest of the extensions. */
 9257|  60.9k|    rv = ssl3_HandleParsedExtensions(ss, ssl_hs_client_hello);
 9258|  60.9k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.remoteExtensions);
 9259|  60.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9259:9): [True: 458, False: 60.4k]
  ------------------
 9260|    458|        if (PORT_GetError() == SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM) {
  ------------------
  |  |   62|    458|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (9260:13): [True: 75, False: 383]
  ------------------
 9261|     75|            errCode = SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM;
 9262|     75|        }
 9263|    458|        goto loser; /* malformed */
 9264|    458|    }
 9265|       |
 9266|       |    /* If the ClientHello version is less than our maximum version, check for a
 9267|       |     * TLS_FALLBACK_SCSV and reject the connection if found. */
 9268|  60.4k|    if (ss->vrange.max > ss->version) {
  ------------------
  |  Branch (9268:9): [True: 42.2k, False: 18.2k]
  ------------------
 9269|   133k|        for (i = 0; i + 1 < suites.len; i += 2) {
  ------------------
  |  Branch (9269:21): [True: 91.7k, False: 42.2k]
  ------------------
 9270|  91.7k|            PRUint16 suite_i = (suites.data[i] << 8) | suites.data[i + 1];
 9271|  91.7k|            if (suite_i != TLS_FALLBACK_SCSV)
  ------------------
  |  |  155|  91.7k|#define TLS_FALLBACK_SCSV                       0x5600
  ------------------
  |  Branch (9271:17): [True: 91.7k, False: 2]
  ------------------
 9272|  91.7k|                continue;
 9273|      2|            desc = inappropriate_fallback;
 9274|      2|            errCode = SSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT;
 9275|      2|            goto alert_loser;
 9276|  91.7k|        }
 9277|  42.2k|    }
 9278|       |
 9279|  60.4k|    if (!ssl3_ExtensionNegotiated(ss, ssl_renegotiation_info_xtn)) {
  ------------------
  |  Branch (9279:9): [True: 60.2k, False: 230]
  ------------------
 9280|       |        /* If we didn't receive an RI extension, look for the SCSV,
 9281|       |         * and if found, treat it just like an empty RI extension
 9282|       |         * by processing a local copy of an empty RI extension.
 9283|       |         */
 9284|   193k|        for (i = 0; i + 1 < suites.len; i += 2) {
  ------------------
  |  Branch (9284:21): [True: 135k, False: 58.1k]
  ------------------
 9285|   135k|            PRUint16 suite_i = (suites.data[i] << 8) | suites.data[i + 1];
 9286|   135k|            if (suite_i == TLS_EMPTY_RENEGOTIATION_INFO_SCSV) {
  ------------------
  |  |  150|   135k|#define TLS_EMPTY_RENEGOTIATION_INFO_SCSV       0x00FF
  ------------------
  |  Branch (9286:17): [True: 2.12k, False: 133k]
  ------------------
 9287|  2.12k|                PRUint8 *b2 = (PRUint8 *)emptyRIext;
 9288|  2.12k|                PRUint32 L2 = sizeof emptyRIext;
 9289|  2.12k|                (void)ssl3_HandleExtensions(ss, &b2, &L2, ssl_hs_client_hello);
 9290|  2.12k|                break;
 9291|  2.12k|            }
 9292|   135k|        }
 9293|  60.2k|    }
 9294|       |
 9295|       |    /* The check for renegotiation in TLS 1.3 is earlier. */
 9296|  60.4k|    if (!isTLS13) {
  ------------------
  |  Branch (9296:9): [True: 58.9k, False: 1.55k]
  ------------------
 9297|  58.9k|        if (ss->firstHsDone &&
  ------------------
  |  Branch (9297:13): [True: 52.0k, False: 6.85k]
  ------------------
 9298|  58.9k|            (ss->opt.enableRenegotiation == SSL_RENEGOTIATE_REQUIRES_XTN ||
  ------------------
  |  |  717|   104k|#define SSL_RENEGOTIATE_REQUIRES_XTN ((PRBool)2)
  ------------------
  |  Branch (9298:14): [True: 0, False: 52.0k]
  ------------------
 9299|  52.0k|             ss->opt.enableRenegotiation == SSL_RENEGOTIATE_TRANSITIONAL) &&
  ------------------
  |  |  722|  52.0k|#define SSL_RENEGOTIATE_TRANSITIONAL ((PRBool)3)
  ------------------
  |  Branch (9299:14): [True: 0, False: 52.0k]
  ------------------
 9300|  58.9k|            !ssl3_ExtensionNegotiated(ss, ssl_renegotiation_info_xtn)) {
  ------------------
  |  Branch (9300:13): [True: 0, False: 0]
  ------------------
 9301|      0|            desc = no_renegotiation;
 9302|      0|            level = alert_warning;
 9303|      0|            errCode = SSL_ERROR_RENEGOTIATION_NOT_ALLOWED;
 9304|      0|            goto alert_loser;
 9305|      0|        }
 9306|  58.9k|        if ((ss->opt.requireSafeNegotiation ||
  ------------------
  |  Branch (9306:14): [True: 776, False: 58.1k]
  ------------------
 9307|  58.9k|             (ss->firstHsDone && ss->peerRequestedProtection)) &&
  ------------------
  |  Branch (9307:15): [True: 52.0k, False: 6.08k]
  |  Branch (9307:34): [True: 3, False: 52.0k]
  ------------------
 9308|  58.9k|            !ssl3_ExtensionNegotiated(ss, ssl_renegotiation_info_xtn)) {
  ------------------
  |  Branch (9308:13): [True: 73, False: 706]
  ------------------
 9309|     73|            desc = handshake_failure;
 9310|     73|            errCode = SSL_ERROR_UNSAFE_NEGOTIATION;
 9311|     73|            goto alert_loser;
 9312|     73|        }
 9313|  58.9k|    }
 9314|       |
 9315|       |    /* We do stateful resumes only if we are in TLS < 1.3 and
 9316|       |     * either of the following conditions are satisfied:
 9317|       |     * (1) the client does not support the session ticket extension, or
 9318|       |     * (2) the client support the session ticket extension, but sent an
 9319|       |     * empty ticket.
 9320|       |     */
 9321|  60.3k|    if (!isTLS13 &&
  ------------------
  |  Branch (9321:9): [True: 58.8k, False: 1.55k]
  ------------------
 9322|  60.3k|        (!ssl3_ExtensionNegotiated(ss, ssl_session_ticket_xtn) ||
  ------------------
  |  Branch (9322:10): [True: 55.2k, False: 3.56k]
  ------------------
 9323|  58.8k|         ss->xtnData.emptySessionTicket)) {
  ------------------
  |  Branch (9323:10): [True: 3.45k, False: 108]
  ------------------
 9324|  58.7k|        if (sidBytes.len > 0 && !ss->opt.noCache) {
  ------------------
  |  Branch (9324:13): [True: 1.48k, False: 57.2k]
  |  Branch (9324:33): [True: 1.01k, False: 471]
  ------------------
 9325|  1.01k|            SSL_TRC(7, ("%d: SSL3[%d]: server, lookup client session-id for 0x%08x%08x%08x%08x",
  ------------------
  |  |   71|  1.01k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.01k]
  |  |  ------------------
  |  |   72|  1.01k|    ssl_Trace b
  ------------------
 9326|  1.01k|                        SSL_GETPID(), ss->fd, ss->sec.ci.peer.pr_s6_addr32[0],
 9327|  1.01k|                        ss->sec.ci.peer.pr_s6_addr32[1],
 9328|  1.01k|                        ss->sec.ci.peer.pr_s6_addr32[2],
 9329|  1.01k|                        ss->sec.ci.peer.pr_s6_addr32[3]));
 9330|  1.01k|            if (ssl_sid_lookup) {
  ------------------
  |  Branch (9330:17): [True: 1.01k, False: 0]
  ------------------
 9331|  1.01k|                sid = (*ssl_sid_lookup)(ssl_Time(ss), &ss->sec.ci.peer,
 9332|  1.01k|                                        sidBytes.data, sidBytes.len, ss->dbHandle);
 9333|  1.01k|            } else {
 9334|      0|                errCode = SSL_ERROR_SERVER_CACHE_NOT_CONFIGURED;
 9335|      0|                goto loser;
 9336|      0|            }
 9337|  1.01k|        }
 9338|  58.7k|    } else if (ss->statelessResume) {
  ------------------
  |  Branch (9338:16): [True: 171, False: 1.48k]
  ------------------
 9339|       |        /* Fill in the client's session ID if doing a stateless resume.
 9340|       |         * (When doing stateless resumes, server echos client's SessionID.)
 9341|       |         * This branch also handles TLS 1.3 resumption-PSK.
 9342|       |         */
 9343|    171|        sid = ss->sec.ci.sid;
 9344|    171|        PORT_Assert(sid != NULL); /* Should have already been filled in.*/
  ------------------
  |  |  120|    171|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    171|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 171, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 9345|       |
 9346|    171|        if (sidBytes.len > 0 && sidBytes.len <= SSL3_SESSIONID_BYTES) {
  ------------------
  |  |  107|     91|#define SSL3_SESSIONID_BYTES 32
  ------------------
  |  Branch (9346:13): [True: 91, False: 80]
  |  Branch (9346:33): [True: 91, False: 0]
  ------------------
 9347|     91|            sid->u.ssl3.sessionIDLength = sidBytes.len;
 9348|     91|            PORT_Memcpy(sid->u.ssl3.sessionID, sidBytes.data,
  ------------------
  |  |  180|     91|#define PORT_Memcpy memcpy
  ------------------
 9349|     91|                        sidBytes.len);
 9350|     91|            sid->u.ssl3.sessionIDLength = sidBytes.len;
 9351|     91|        } else {
 9352|     80|            sid->u.ssl3.sessionIDLength = 0;
 9353|     80|        }
 9354|    171|        ss->sec.ci.sid = NULL;
 9355|    171|    }
 9356|       |
 9357|       |    /* Free a potentially leftover session ID from a previous handshake. */
 9358|  60.3k|    if (ss->sec.ci.sid) {
  ------------------
  |  Branch (9358:9): [True: 51.9k, False: 8.40k]
  ------------------
 9359|  51.9k|        ssl_FreeSID(ss->sec.ci.sid);
 9360|  51.9k|        ss->sec.ci.sid = NULL;
 9361|  51.9k|    }
 9362|       |
 9363|  60.3k|    if (sid != NULL) {
  ------------------
  |  Branch (9363:9): [True: 171, False: 60.2k]
  ------------------
 9364|       |        /* We've found a session cache entry for this client.
 9365|       |         * Now, if we're going to require a client-auth cert,
 9366|       |         * and we don't already have this client's cert in the session cache,
 9367|       |         * and this is the first handshake on this connection (not a redo),
 9368|       |         * then drop this old cache entry and start a new session.
 9369|       |         */
 9370|    171|        if ((sid->peerCert == NULL) && ss->opt.requestCertificate &&
  ------------------
  |  Branch (9370:13): [True: 171, False: 0]
  |  Branch (9370:40): [True: 53, False: 118]
  ------------------
 9371|    171|            ((ss->opt.requireCertificate == SSL_REQUIRE_ALWAYS) ||
  ------------------
  |  |  705|     53|#define SSL_REQUIRE_ALWAYS ((PRBool)1)
  ------------------
  |  Branch (9371:14): [True: 18, False: 35]
  ------------------
 9372|     53|             (ss->opt.requireCertificate == SSL_REQUIRE_NO_ERROR) ||
  ------------------
  |  |  707|     35|#define SSL_REQUIRE_NO_ERROR ((PRBool)3)
  ------------------
  |  Branch (9372:14): [True: 0, False: 35]
  ------------------
 9373|     53|             ((ss->opt.requireCertificate == SSL_REQUIRE_FIRST_HANDSHAKE) &&
  ------------------
  |  |  706|     35|#define SSL_REQUIRE_FIRST_HANDSHAKE ((PRBool)2)
  ------------------
  |  Branch (9373:15): [True: 0, False: 35]
  ------------------
 9374|     35|              !ss->firstHsDone))) {
  ------------------
  |  Branch (9374:15): [True: 0, False: 0]
  ------------------
 9375|       |
 9376|     18|            SSL_AtomicIncrementLong(&ssl3stats.hch_sid_cache_not_ok);
 9377|     18|            ssl_FreeSID(sid);
 9378|     18|            sid = NULL;
 9379|     18|            ss->statelessResume = PR_FALSE;
  ------------------
  |  |  438|     18|#define PR_FALSE 0
  ------------------
 9380|     18|        }
 9381|    171|    }
 9382|       |
 9383|  60.3k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  60.3k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 60.3k]
  |  |  ------------------
  ------------------
 9384|      0|        ssl3_DisableNonDTLSSuites(ss);
 9385|      0|        dtls_ReceivedFirstMessageInFlight(ss);
 9386|      0|    }
 9387|       |
 9388|  60.3k|    if (isTLS13) {
  ------------------
  |  Branch (9388:9): [True: 1.55k, False: 58.8k]
  ------------------
 9389|  1.55k|        rv = tls13_HandleClientHelloPart2(ss, &suites, sid,
 9390|  1.55k|                                          ss->ssl3.hs.echAccepted ? echInner->data : savedMsg,
  ------------------
  |  Branch (9390:43): [True: 0, False: 1.55k]
  ------------------
 9391|  1.55k|                                          ss->ssl3.hs.echAccepted ? echInner->len : savedLen);
  ------------------
  |  Branch (9391:43): [True: 0, False: 1.55k]
  ------------------
 9392|  1.55k|        SECITEM_FreeItem(echInner, PR_TRUE);
  ------------------
  |  |  108|  1.55k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(echInner, PR_TRUE);
  ------------------
  |  |  437|  1.55k|#define PR_TRUE 1
  ------------------
 9393|  1.55k|        echInner = NULL;
 9394|  58.8k|    } else {
 9395|  58.8k|        rv = ssl3_HandleClientHelloPart2(ss, &suites, sid,
 9396|  58.8k|                                         savedMsg, savedLen);
 9397|  58.8k|    }
 9398|  60.3k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9398:9): [True: 269, False: 60.1k]
  ------------------
 9399|    269|        errCode = PORT_GetError();
  ------------------
  |  |   62|    269|#define PORT_GetError PORT_GetError_Util
  ------------------
 9400|    269|        goto loser;
 9401|    269|    }
 9402|  60.1k|    return SECSuccess;
 9403|       |
 9404|    208|alert_loser:
 9405|    208|    (void)SSL3_SendAlert(ss, level, desc);
 9406|       |/* FALLTHRU */
 9407|  1.14k|loser:
 9408|  1.14k|    SECITEM_FreeItem(echInner, PR_TRUE);
  ------------------
  |  |  108|  1.14k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(echInner, PR_TRUE);
  ------------------
  |  |  437|  1.14k|#define PR_TRUE 1
  ------------------
 9409|  1.14k|    PORT_SetError(errCode);
  ------------------
  |  |   65|  1.14k|#define PORT_SetError PORT_SetError_Util
  ------------------
 9410|  1.14k|    return SECFailure;
 9411|    208|}
ssl3con.c:ssl3_ValidatePreambleWithVersion:
 9026|  60.9k|{
 9027|  60.9k|    SECStatus rv;
 9028|  60.9k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  60.9k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (9028:9): [True: 1.85k, False: 59.0k]
  ------------------
 9029|  1.85k|        if (sidBytes->len > 0 && !IS_DTLS(ss)) {
  ------------------
  |  |  892|    459|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (9029:13): [True: 459, False: 1.39k]
  |  Branch (9029:34): [True: 459, False: 0]
  ------------------
 9030|    459|            SECITEM_FreeItem(&ss->ssl3.hs.fakeSid, PR_FALSE);
  ------------------
  |  |  108|    459|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(&ss->ssl3.hs.fakeSid, PR_FALSE);
  ------------------
  |  |  438|    459|#define PR_FALSE 0
  ------------------
 9031|    459|            rv = SECITEM_CopyItem(NULL, &ss->ssl3.hs.fakeSid, sidBytes);
  ------------------
  |  |  106|    459|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 9032|    459|            if (rv != SECSuccess) {
  ------------------
  |  Branch (9032:17): [True: 0, False: 459]
  ------------------
 9033|      0|                FATAL_ERROR(ss, PORT_GetError(), internal_error);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9034|      0|                return SECFailure;
 9035|      0|            }
 9036|    459|        }
 9037|       |
 9038|       |        /* TLS 1.3 requires that compression include only null. */
 9039|  1.85k|        if (comps->len != 1 || comps->data[0] != ssl_compression_null) {
  ------------------
  |  Branch (9039:13): [True: 1, False: 1.85k]
  |  Branch (9039:32): [True: 11, False: 1.84k]
  ------------------
 9040|     12|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |  175|     12|    do {                                     \
  |  |  176|     12|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|     12|    do {                                                                           \
  |  |  |  |  168|     12|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     12|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 12]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     12|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|     12|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|     12|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     12|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|     12|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|     12|        tls13_FatalError(ss, prError, desc); \
  |  |  178|     12|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9041|     12|            return SECFailure;
 9042|     12|        }
 9043|       |
 9044|       |        /* receivedCcs is only valid if we sent an HRR. */
 9045|  1.84k|        if (ss->ssl3.hs.receivedCcs && !ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (9045:13): [True: 2, False: 1.84k]
  |  Branch (9045:40): [True: 1, False: 1]
  ------------------
 9046|      1|            FATAL_ERROR(ss, SSL_ERROR_RX_UNEXPECTED_CHANGE_CIPHER, unexpected_message);
  ------------------
  |  |  175|      1|    do {                                     \
  |  |  176|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      1|    do {                                                                           \
  |  |  |  |  168|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      1|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9047|      1|            return SECFailure;
 9048|      1|        }
 9049|       |
 9050|       |        /* A DTLS 1.3-only client MUST set the legacy_cookie field to zero length.
 9051|       |         * If a DTLS 1.3 ClientHello is received with any other value in this field,
 9052|       |         * the server MUST abort the handshake with an "illegal_parameter" alert. */
 9053|  1.84k|        if (IS_DTLS(ss) && cookieBytes->len != 0) {
  ------------------
  |  |  892|  3.68k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 1.84k]
  |  |  ------------------
  ------------------
  |  Branch (9053:28): [True: 0, False: 0]
  ------------------
 9054|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9055|      0|            return SECFailure;
 9056|      0|        }
 9057|  59.0k|    } else {
 9058|       |        /* ECH not possible here. */
 9059|  59.0k|        ss->ssl3.hs.preliminaryInfo |= ssl_preinfo_ech;
  ------------------
  |  |  398|  59.0k|#define ssl_preinfo_ech (1U << 4)
  ------------------
 9060|       |
 9061|       |        /* HRR and ECH are TLS1.3-only. We ignore the Cookie extension here. */
 9062|  59.0k|        if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (9062:13): [True: 0, False: 59.0k]
  ------------------
 9063|      0|            FATAL_ERROR(ss, SSL_ERROR_UNSUPPORTED_VERSION, protocol_version);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9064|      0|            return SECFailure;
 9065|      0|        }
 9066|       |
 9067|       |        /* receivedCcs is only valid if we sent an HRR. */
 9068|  59.0k|        if (ss->ssl3.hs.receivedCcs) {
  ------------------
  |  Branch (9068:13): [True: 1, False: 59.0k]
  ------------------
 9069|      1|            FATAL_ERROR(ss, SSL_ERROR_RX_UNEXPECTED_CHANGE_CIPHER, unexpected_message);
  ------------------
  |  |  175|      1|    do {                                     \
  |  |  176|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      1|    do {                                                                           \
  |  |  |  |  168|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      1|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9070|      1|            return SECFailure;
 9071|      1|        }
 9072|       |
 9073|       |        /* TLS versions prior to 1.3 must include null somewhere. */
 9074|  59.0k|        if (comps->len < 1 ||
  ------------------
  |  Branch (9074:13): [True: 5, False: 59.0k]
  ------------------
 9075|  59.0k|            !memchr(comps->data, ssl_compression_null, comps->len)) {
  ------------------
  |  Branch (9075:13): [True: 2, False: 59.0k]
  ------------------
 9076|      7|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |  175|      7|    do {                                     \
  |  |  176|      7|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      7|    do {                                                                           \
  |  |  |  |  168|      7|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      7|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 7]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      7|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      7|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      7|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      7|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      7|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      7|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9077|      7|            return SECFailure;
 9078|      7|        }
 9079|       |
 9080|       |        /* We never send cookies in DTLS 1.2. */
 9081|  59.0k|        if (IS_DTLS(ss) && cookieBytes->len != 0) {
  ------------------
  |  |  892|   118k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 59.0k]
  |  |  ------------------
  ------------------
  |  Branch (9081:28): [True: 0, False: 0]
  ------------------
 9082|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 9083|      0|            return SECFailure;
 9084|      0|        }
 9085|  59.0k|    }
 9086|       |
 9087|  60.9k|    return SECSuccess;
 9088|  60.9k|}
ssl3con.c:ssl3_HandleClientHelloPart2:
 9492|  58.8k|{
 9493|  58.8k|    PRBool haveXmitBufLock = PR_FALSE;
  ------------------
  |  |  438|  58.8k|#define PR_FALSE 0
  ------------------
 9494|  58.8k|    int errCode = SSL_ERROR_RX_MALFORMED_CLIENT_HELLO;
 9495|  58.8k|    SSL3AlertDescription desc = illegal_parameter;
 9496|  58.8k|    SECStatus rv;
 9497|  58.8k|    unsigned int i;
 9498|  58.8k|    unsigned int j;
 9499|       |
 9500|  58.8k|    rv = ssl_HashHandshakeMessage(ss, ssl_hs_client_hello, msg, len);
 9501|  58.8k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9501:9): [True: 0, False: 58.8k]
  ------------------
 9502|      0|        errCode = SEC_ERROR_LIBRARY_FAILURE;
 9503|      0|        desc = internal_error;
 9504|      0|        goto alert_loser;
 9505|      0|    }
 9506|       |
 9507|       |    /* If we already have a session for this client, be sure to pick the same
 9508|       |    ** cipher suite we picked before.  This is not a loop, despite appearances.
 9509|       |    */
 9510|  58.8k|    if (sid)
  ------------------
  |  Branch (9510:9): [True: 102, False: 58.7k]
  ------------------
 9511|    102|        do {
 9512|    102|            ssl3CipherSuiteCfg *suite;
 9513|    102|            SSLVersionRange vrange = { ss->version, ss->version };
 9514|       |
 9515|    102|            suite = ss->cipherSuites;
 9516|       |            /* Find the entry for the cipher suite used in the cached session. */
 9517|  7.34k|            for (j = ssl_V3_SUITES_IMPLEMENTED; j > 0; --j, ++suite) {
  ------------------
  |  |  245|    102|#define ssl_V3_SUITES_IMPLEMENTED 71
  ------------------
  |  Branch (9517:49): [True: 7.24k, False: 102]
  ------------------
 9518|  7.24k|                if (suite->cipher_suite == sid->u.ssl3.cipherSuite)
  ------------------
  |  Branch (9518:21): [True: 0, False: 7.24k]
  ------------------
 9519|      0|                    break;
 9520|  7.24k|            }
 9521|       |
 9522|    102|            if (j == 0)
  ------------------
  |  Branch (9522:17): [True: 102, False: 0]
  ------------------
 9523|    102|                break;
 9524|       |
 9525|       |            /* Double check that the cached cipher suite is still enabled,
 9526|       |             * implemented, and allowed by policy.  Might have been disabled.
 9527|       |             */
 9528|      0|            if (ssl3_config_match_init(ss) == 0) {
  ------------------
  |  Branch (9528:17): [True: 0, False: 0]
  ------------------
 9529|      0|                desc = handshake_failure;
 9530|      0|                errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9531|      0|                goto alert_loser;
 9532|      0|            }
 9533|      0|            if (!ssl3_config_match(suite, ss->ssl3.policy, &vrange, ss))
  ------------------
  |  Branch (9533:17): [True: 0, False: 0]
  ------------------
 9534|      0|                break;
 9535|       |
 9536|       |            /* Double check that the cached cipher suite is in the client's
 9537|       |             * list.  If it isn't, fall through and start a new session. */
 9538|      0|            for (i = 0; i + 1 < suites->len; i += 2) {
  ------------------
  |  Branch (9538:25): [True: 0, False: 0]
  ------------------
 9539|      0|                PRUint16 suite_i = (suites->data[i] << 8) | suites->data[i + 1];
 9540|      0|                if (suite_i == suite->cipher_suite) {
  ------------------
  |  Branch (9540:21): [True: 0, False: 0]
  ------------------
 9541|      0|                    ss->ssl3.hs.cipher_suite = suite_i;
 9542|      0|                    rv = ssl3_SetupCipherSuite(ss, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 9543|      0|                    if (rv != SECSuccess) {
  ------------------
  |  Branch (9543:25): [True: 0, False: 0]
  ------------------
 9544|      0|                        desc = internal_error;
 9545|      0|                        errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9546|      0|                        goto alert_loser;
 9547|      0|                    }
 9548|       |
 9549|      0|                    goto cipher_found;
 9550|      0|                }
 9551|      0|            }
 9552|      0|        } while (0);
  ------------------
  |  Branch (9552:18): [Folded - Ignored]
  ------------------
 9553|       |    /* START A NEW SESSION */
 9554|       |
 9555|  58.8k|    rv = ssl3_NegotiateCipherSuite(ss, suites, PR_TRUE);
  ------------------
  |  |  437|  58.8k|#define PR_TRUE 1
  ------------------
 9556|  58.8k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9556:9): [True: 79, False: 58.7k]
  ------------------
 9557|     79|        desc = handshake_failure;
 9558|     79|        errCode = PORT_GetError();
  ------------------
  |  |   62|     79|#define PORT_GetError PORT_GetError_Util
  ------------------
 9559|     79|        goto alert_loser;
 9560|     79|    }
 9561|       |
 9562|  58.7k|cipher_found:
 9563|  58.7k|    suites->data = NULL;
 9564|       |
 9565|       |    /* If there are any failures while processing the old sid,
 9566|       |     * we don't consider them to be errors.  Instead, We just behave
 9567|       |     * as if the client had sent us no sid to begin with, and make a new one.
 9568|       |     * The exception here is attempts to resume extended_master_secret
 9569|       |     * sessions without the extension, which causes an alert.
 9570|       |     */
 9571|  58.7k|    if (sid != NULL)
  ------------------
  |  Branch (9571:9): [True: 98, False: 58.6k]
  ------------------
 9572|     98|        do {
 9573|     98|            PK11SymKey *masterSecret;
 9574|       |
 9575|     98|            if (sid->version != ss->version ||
  ------------------
  |  Branch (9575:17): [True: 98, False: 0]
  ------------------
 9576|     98|                sid->u.ssl3.cipherSuite != ss->ssl3.hs.cipher_suite) {
  ------------------
  |  Branch (9576:17): [True: 0, False: 0]
  ------------------
 9577|     98|                break; /* not an error */
 9578|     98|            }
 9579|       |
 9580|       |            /* server sids don't remember the server cert we previously sent,
 9581|       |            ** but they do remember the slot we originally used, so we
 9582|       |            ** can locate it again, provided that the current ssl socket
 9583|       |            ** has had its server certs configured the same as the previous one.
 9584|       |            */
 9585|      0|            ss->sec.serverCert = ssl_FindServerCert(ss, sid->authType, sid->namedCurve);
 9586|      0|            if (!ss->sec.serverCert || !ss->sec.serverCert->serverCert) {
  ------------------
  |  Branch (9586:17): [True: 0, False: 0]
  |  Branch (9586:40): [True: 0, False: 0]
  ------------------
 9587|       |                /* A compatible certificate must not have been configured.  It
 9588|       |                 * might not be the same certificate, but we only find that out
 9589|       |                 * when the ticket fails to decrypt. */
 9590|      0|                break;
 9591|      0|            }
 9592|       |
 9593|       |            /* [draft-ietf-tls-session-hash-06; Section 5.3]
 9594|       |             * o  If the original session did not use the "extended_master_secret"
 9595|       |             *    extension but the new ClientHello contains the extension, then the
 9596|       |             *    server MUST NOT perform the abbreviated handshake.  Instead, it
 9597|       |             *    SHOULD continue with a full handshake (as described in
 9598|       |             *    Section 5.2) to negotiate a new session.
 9599|       |             *
 9600|       |             * o  If the original session used the "extended_master_secret"
 9601|       |             *    extension but the new ClientHello does not contain the extension,
 9602|       |             *    the server MUST abort the abbreviated handshake.
 9603|       |             */
 9604|      0|            if (ssl3_ExtensionNegotiated(ss, ssl_extended_master_secret_xtn)) {
  ------------------
  |  Branch (9604:17): [True: 0, False: 0]
  ------------------
 9605|      0|                if (!sid->u.ssl3.keys.extendedMasterSecretUsed) {
  ------------------
  |  Branch (9605:21): [True: 0, False: 0]
  ------------------
 9606|      0|                    break; /* not an error */
 9607|      0|                }
 9608|      0|            } else {
 9609|      0|                if (sid->u.ssl3.keys.extendedMasterSecretUsed) {
  ------------------
  |  Branch (9609:21): [True: 0, False: 0]
  ------------------
 9610|       |                    /* Note: we do not destroy the session */
 9611|      0|                    desc = handshake_failure;
 9612|      0|                    errCode = SSL_ERROR_MISSING_EXTENDED_MASTER_SECRET;
 9613|      0|                    goto alert_loser;
 9614|      0|                }
 9615|      0|            }
 9616|       |
 9617|      0|            if (ss->sec.ci.sid) {
  ------------------
  |  Branch (9617:17): [True: 0, False: 0]
  ------------------
 9618|      0|                ssl_UncacheSessionID(ss);
 9619|      0|                PORT_Assert(ss->sec.ci.sid != sid); /* should be impossible, but ... */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 9620|      0|                if (ss->sec.ci.sid != sid) {
  ------------------
  |  Branch (9620:21): [True: 0, False: 0]
  ------------------
 9621|      0|                    ssl_FreeSID(ss->sec.ci.sid);
 9622|      0|                }
 9623|      0|                ss->sec.ci.sid = NULL;
 9624|      0|            }
 9625|       |
 9626|       |            /* we need to resurrect the master secret.... */
 9627|      0|            rv = ssl3_UnwrapMasterSecretServer(ss, sid, &masterSecret);
 9628|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (9628:17): [True: 0, False: 0]
  ------------------
 9629|      0|                break; /* not an error */
 9630|      0|            }
 9631|       |
 9632|      0|            ss->sec.ci.sid = sid;
 9633|      0|            if (sid->peerCert != NULL) {
  ------------------
  |  Branch (9633:17): [True: 0, False: 0]
  ------------------
 9634|      0|                ss->sec.peerCert = CERT_DupCertificate(sid->peerCert);
 9635|      0|            }
 9636|       |
 9637|       |            /*
 9638|       |             * Old SID passed all tests, so resume this old session.
 9639|       |             */
 9640|      0|            SSL_AtomicIncrementLong(&ssl3stats.hch_sid_cache_hits);
 9641|      0|            if (ss->statelessResume)
  ------------------
  |  Branch (9641:17): [True: 0, False: 0]
  ------------------
 9642|      0|                SSL_AtomicIncrementLong(&ssl3stats.hch_sid_stateless_resumes);
 9643|      0|            ss->ssl3.hs.isResuming = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 9644|       |
 9645|      0|            ss->sec.authType = sid->authType;
 9646|      0|            ss->sec.authKeyBits = sid->authKeyBits;
 9647|      0|            ss->sec.keaType = sid->keaType;
 9648|      0|            ss->sec.keaKeyBits = sid->keaKeyBits;
 9649|      0|            ss->sec.originalKeaGroup = ssl_LookupNamedGroup(sid->keaGroup);
 9650|      0|            ss->sec.signatureScheme = sid->sigScheme;
 9651|       |
 9652|      0|            ss->sec.localCert =
 9653|      0|                CERT_DupCertificate(ss->sec.serverCert->serverCert);
 9654|       |
 9655|       |            /* Copy cached name in to pending spec */
 9656|      0|            if (sid != NULL &&
  ------------------
  |  Branch (9656:17): [True: 0, False: 0]
  ------------------
 9657|      0|                sid->version > SSL_LIBRARY_VERSION_3_0 &&
  ------------------
  |  |   17|      0|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (9657:17): [True: 0, False: 0]
  ------------------
 9658|      0|                sid->u.ssl3.srvName.len && sid->u.ssl3.srvName.data) {
  ------------------
  |  Branch (9658:17): [True: 0, False: 0]
  |  Branch (9658:44): [True: 0, False: 0]
  ------------------
 9659|       |                /* Set server name from sid */
 9660|      0|                SECItem *sidName = &sid->u.ssl3.srvName;
 9661|      0|                SECItem *pwsName = &ss->ssl3.hs.srvVirtName;
 9662|      0|                if (pwsName->data) {
  ------------------
  |  Branch (9662:21): [True: 0, False: 0]
  ------------------
 9663|      0|                    SECITEM_FreeItem(pwsName, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                                  SECITEM_FreeItem(pwsName, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 9664|      0|                }
 9665|      0|                rv = SECITEM_CopyItem(NULL, pwsName, sidName);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 9666|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (9666:21): [True: 0, False: 0]
  ------------------
 9667|      0|                    errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9668|      0|                    desc = internal_error;
 9669|      0|                    goto alert_loser;
 9670|      0|                }
 9671|      0|            }
 9672|       |
 9673|       |            /* Clean up sni name array */
 9674|      0|            ssl3_FreeSniNameArray(&ss->xtnData);
 9675|       |
 9676|      0|            ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|      0|    {                                           \
  |  | 1467|      0|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1468|      0|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|      0|    }
  ------------------
 9677|      0|            haveXmitBufLock = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 9678|       |
 9679|      0|            rv = ssl3_SendServerHello(ss);
 9680|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (9680:17): [True: 0, False: 0]
  ------------------
 9681|      0|                errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9682|      0|                goto loser;
 9683|      0|            }
 9684|       |
 9685|       |            /* We are re-using the old MS, so no need to derive again. */
 9686|      0|            rv = ssl3_InitPendingCipherSpecs(ss, masterSecret, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 9687|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (9687:17): [True: 0, False: 0]
  ------------------
 9688|      0|                errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9689|      0|                goto loser;
 9690|      0|            }
 9691|       |
 9692|      0|            rv = ssl3_SendChangeCipherSpecs(ss);
 9693|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (9693:17): [True: 0, False: 0]
  ------------------
 9694|      0|                errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9695|      0|                goto loser;
 9696|      0|            }
 9697|      0|            rv = ssl3_SendFinished(ss, 0);
 9698|      0|            ss->ssl3.hs.ws = wait_change_cipher;
 9699|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (9699:17): [True: 0, False: 0]
  ------------------
 9700|      0|                errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9701|      0|                goto loser;
 9702|      0|            }
 9703|       |
 9704|      0|            if (haveXmitBufLock) {
  ------------------
  |  Branch (9704:17): [True: 0, False: 0]
  ------------------
 9705|      0|                ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
 9706|      0|            }
 9707|       |
 9708|      0|            return SECSuccess;
 9709|      0|        } while (0);
  ------------------
  |  Branch (9709:18): [Folded - Ignored]
  ------------------
 9710|       |
 9711|  58.7k|    if (sid) { /* we had a sid, but it's no longer valid, free it */
  ------------------
  |  Branch (9711:9): [True: 98, False: 58.6k]
  ------------------
 9712|     98|        ss->statelessResume = PR_FALSE;
  ------------------
  |  |  438|     98|#define PR_FALSE 0
  ------------------
 9713|     98|        SSL_AtomicIncrementLong(&ssl3stats.hch_sid_cache_not_ok);
 9714|     98|        ssl_UncacheSessionID(ss);
 9715|     98|        ssl_FreeSID(sid);
 9716|     98|        sid = NULL;
 9717|     98|    }
 9718|  58.7k|    SSL_AtomicIncrementLong(&ssl3stats.hch_sid_cache_misses);
 9719|       |
 9720|       |    /* We only send a session ticket extension if the client supports
 9721|       |     * the extension and we are unable to resume.
 9722|       |     *
 9723|       |     * TODO: send a session ticket if performing a stateful
 9724|       |     * resumption.  (As per RFC4507, a server may issue a session
 9725|       |     * ticket while doing a (stateless or stateful) session resume,
 9726|       |     * but OpenSSL-0.9.8g does not accept session tickets while
 9727|       |     * resuming.)
 9728|       |     */
 9729|  58.7k|    if (ssl3_ExtensionNegotiated(ss, ssl_session_ticket_xtn) &&
  ------------------
  |  Branch (9729:9): [True: 3.55k, False: 55.2k]
  ------------------
 9730|  58.7k|        ssl3_KEASupportsTickets(ss->ssl3.hs.kea_def)) {
  ------------------
  |  Branch (9730:9): [True: 3.55k, False: 0]
  ------------------
 9731|  3.55k|        ssl3_RegisterExtensionSender(ss, &ss->xtnData, ssl_session_ticket_xtn,
 9732|  3.55k|                                     ssl_SendEmptyExtension);
 9733|  3.55k|    }
 9734|       |
 9735|  58.7k|    rv = ssl3_ServerCallSNICallback(ss);
 9736|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9736:9): [True: 0, False: 58.7k]
  ------------------
 9737|       |        /* The alert has already been sent. */
 9738|      0|        errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9739|      0|        goto loser;
 9740|      0|    }
 9741|       |
 9742|  58.7k|    rv = ssl3_SelectServerCert(ss);
 9743|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9743:9): [True: 20, False: 58.7k]
  ------------------
 9744|     20|        errCode = PORT_GetError();
  ------------------
  |  |   62|     20|#define PORT_GetError PORT_GetError_Util
  ------------------
 9745|     20|        desc = handshake_failure;
 9746|     20|        goto alert_loser;
 9747|     20|    }
 9748|       |
 9749|  58.7k|    sid = ssl3_NewSessionID(ss, PR_TRUE);
  ------------------
  |  |  437|  58.7k|#define PR_TRUE 1
  ------------------
 9750|  58.7k|    if (sid == NULL) {
  ------------------
  |  Branch (9750:9): [True: 0, False: 58.7k]
  ------------------
 9751|      0|        errCode = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 9752|      0|        goto loser; /* memory error is set. */
 9753|      0|    }
 9754|  58.7k|    ss->sec.ci.sid = sid;
 9755|       |
 9756|  58.7k|    sid->u.ssl3.keys.extendedMasterSecretUsed =
 9757|  58.7k|        ssl3_ExtensionNegotiated(ss, ssl_extended_master_secret_xtn);
 9758|  58.7k|    ss->ssl3.hs.isResuming = PR_FALSE;
  ------------------
  |  |  438|  58.7k|#define PR_FALSE 0
  ------------------
 9759|       |
 9760|  58.7k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  58.7k|    {                                           \
  |  | 1467|  58.7k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 30.1k, False: 28.5k]
  |  |  ------------------
  |  | 1468|  58.7k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  30.1k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  58.7k|    }
  ------------------
 9761|  58.7k|    rv = ssl3_SendServerHelloSequence(ss);
 9762|  58.7k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  58.7k|    {                                          \
  |  | 1472|  58.7k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 30.1k, False: 28.5k]
  |  |  ------------------
  |  | 1473|  58.7k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  30.1k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  58.7k|    }
  ------------------
 9763|  58.7k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (9763:9): [True: 13, False: 58.7k]
  ------------------
 9764|     13|        errCode = PORT_GetError();
  ------------------
  |  |   62|     13|#define PORT_GetError PORT_GetError_Util
  ------------------
 9765|     13|        desc = handshake_failure;
 9766|     13|        goto alert_loser;
 9767|     13|    }
 9768|       |
 9769|  58.7k|    if (haveXmitBufLock) {
  ------------------
  |  Branch (9769:9): [True: 0, False: 58.7k]
  ------------------
 9770|      0|        ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
 9771|      0|    }
 9772|       |
 9773|  58.7k|    return SECSuccess;
 9774|       |
 9775|    112|alert_loser:
 9776|    112|    (void)SSL3_SendAlert(ss, alert_fatal, desc);
 9777|       |/* FALLTHRU */
 9778|    112|loser:
 9779|    112|    if (sid && sid != ss->sec.ci.sid) {
  ------------------
  |  Branch (9779:9): [True: 17, False: 95]
  |  Branch (9779:16): [True: 4, False: 13]
  ------------------
 9780|      4|        ssl_UncacheSessionID(ss);
 9781|      4|        ssl_FreeSID(sid);
 9782|      4|    }
 9783|       |
 9784|    112|    if (haveXmitBufLock) {
  ------------------
  |  Branch (9784:9): [True: 0, False: 112]
  ------------------
 9785|      0|        ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
 9786|      0|    }
 9787|       |
 9788|    112|    PORT_SetError(errCode);
  ------------------
  |  |   65|    112|#define PORT_SetError PORT_SetError_Util
  ------------------
 9789|    112|    return SECFailure;
 9790|    112|}
ssl3con.c:ssl3_SendChangeCipherSpecs:
 3264|  52.5k|{
 3265|  52.5k|    SECStatus rv;
 3266|       |
 3267|  52.5k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.5k, False: 26.9k]
  |  |  |  |  |  Branch (208:7): [True: 26.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3268|  52.5k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.5k, False: 26.9k]
  |  |  |  |  |  Branch (208:7): [True: 26.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3269|       |
 3270|  52.5k|    rv = ssl3_SendChangeCipherSpecsInt(ss);
 3271|  52.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3271:9): [True: 0, False: 52.5k]
  ------------------
 3272|      0|        return rv; /* Error code set. */
 3273|      0|    }
 3274|       |
 3275|       |    /* swap the pending and current write specs. */
 3276|  52.5k|    ssl_GetSpecWriteLock(ss); /**************************************/
  ------------------
  |  | 1435|  52.5k|    {                                            \
  |  | 1436|  52.5k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 26.9k, False: 25.5k]
  |  |  ------------------
  |  | 1437|  52.5k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  26.9k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  52.5k|    }
  ------------------
 3277|       |
 3278|  52.5k|    ssl_CipherSpecRelease(ss->ssl3.cwSpec);
 3279|  52.5k|    ss->ssl3.cwSpec = ss->ssl3.pwSpec;
 3280|  52.5k|    ss->ssl3.pwSpec = NULL;
 3281|       |
 3282|  52.5k|    SSL_TRC(3, ("%d: SSL3[%d] Set Current Write Cipher Suite to Pending",
  ------------------
  |  |   71|  52.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 52.5k]
  |  |  ------------------
  |  |   72|  52.5k|    ssl_Trace b
  ------------------
 3283|  52.5k|                SSL_GETPID(), ss->fd));
 3284|       |
 3285|       |    /* With DTLS, we need to set a holddown timer in case the final
 3286|       |     * message got lost */
 3287|  52.5k|    if (IS_DTLS(ss) && ss->ssl3.crSpec->epoch == ss->ssl3.cwSpec->epoch) {
  ------------------
  |  |  892|   105k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 52.5k]
  |  |  ------------------
  ------------------
  |  Branch (3287:24): [True: 0, False: 0]
  ------------------
 3288|      0|        rv = dtls_StartHolddownTimer(ss);
 3289|      0|    }
 3290|  52.5k|    ssl_ReleaseSpecWriteLock(ss); /**************************************/
  ------------------
  |  | 1440|  52.5k|    {                                              \
  |  | 1441|  52.5k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 26.9k, False: 25.5k]
  |  |  ------------------
  |  | 1442|  52.5k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  26.9k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  52.5k|    }
  ------------------
 3291|       |
 3292|  52.5k|    return rv;
 3293|  52.5k|}
ssl3con.c:ssl3_SendFinished:
12147|  52.5k|{
12148|  52.5k|    ssl3CipherSpec *cwSpec;
12149|  52.5k|    PRBool isTLS;
12150|  52.5k|    PRBool isServer = ss->sec.isServer;
12151|  52.5k|    SECStatus rv;
12152|  52.5k|    SSL3Sender sender = isServer ? sender_server : sender_client;
  ------------------
  |  Branch (12152:25): [True: 52.5k, False: 0]
  ------------------
12153|  52.5k|    SSL3Hashes hashes;
12154|  52.5k|    TLSFinished tlsFinished;
12155|       |
12156|  52.5k|    SSL_TRC(3, ("%d: SSL3[%d]: send finished handshake", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|  52.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 52.5k]
  |  |  ------------------
  |  |   72|  52.5k|    ssl_Trace b
  ------------------
12157|       |
12158|  52.5k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.5k, False: 26.9k]
  |  |  |  |  |  Branch (208:7): [True: 26.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12159|  52.5k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.5k, False: 26.9k]
  |  |  |  |  |  Branch (208:7): [True: 26.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12160|  52.5k|    PR_ASSERT(!ss->ssl3.hs.clientCertificatePending);
  ------------------
  |  |  208|  52.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 52.5k, False: 0]
  |  |  ------------------
  ------------------
12161|       |
12162|  52.5k|    ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|  52.5k|    {                                           \
  |  | 1423|  52.5k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 26.9k, False: 25.5k]
  |  |  ------------------
  |  | 1424|  52.5k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|  26.9k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|  52.5k|    }
  ------------------
12163|  52.5k|    cwSpec = ss->ssl3.cwSpec;
12164|  52.5k|    isTLS = (PRBool)(cwSpec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  52.5k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
12165|  52.5k|    rv = ssl3_ComputeHandshakeHashes(ss, cwSpec, &hashes, sender);
12166|  52.5k|    if (isTLS && rv == SECSuccess) {
  ------------------
  |  Branch (12166:9): [True: 52.5k, False: 0]
  |  Branch (12166:18): [True: 52.5k, False: 0]
  ------------------
12167|  52.5k|        rv = ssl3_ComputeTLSFinished(ss, cwSpec, isServer, &hashes, &tlsFinished);
12168|  52.5k|    }
12169|  52.5k|    ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|  52.5k|    {                                             \
  |  | 1428|  52.5k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 26.9k, False: 25.5k]
  |  |  ------------------
  |  | 1429|  52.5k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|  26.9k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|  52.5k|    }
  ------------------
12170|  52.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (12170:9): [True: 0, False: 52.5k]
  ------------------
12171|      0|        goto fail; /* err code was set by ssl3_ComputeHandshakeHashes */
12172|      0|    }
12173|       |
12174|  52.5k|    if (isTLS) {
  ------------------
  |  Branch (12174:9): [True: 52.5k, False: 0]
  ------------------
12175|  52.5k|        if (isServer)
  ------------------
  |  Branch (12175:13): [True: 52.5k, False: 0]
  ------------------
12176|  52.5k|            ss->ssl3.hs.finishedMsgs.tFinished[1] = tlsFinished;
12177|      0|        else
12178|      0|            ss->ssl3.hs.finishedMsgs.tFinished[0] = tlsFinished;
12179|  52.5k|        ss->ssl3.hs.finishedBytes = sizeof tlsFinished;
12180|  52.5k|        rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_finished, sizeof tlsFinished);
12181|  52.5k|        if (rv != SECSuccess)
  ------------------
  |  Branch (12181:13): [True: 0, False: 52.5k]
  ------------------
12182|      0|            goto fail; /* err set by AppendHandshake. */
12183|  52.5k|        rv = ssl3_AppendHandshake(ss, &tlsFinished, sizeof tlsFinished);
12184|  52.5k|        if (rv != SECSuccess)
  ------------------
  |  Branch (12184:13): [True: 0, False: 52.5k]
  ------------------
12185|      0|            goto fail; /* err set by AppendHandshake. */
12186|  52.5k|    } else {
12187|      0|        if (isServer)
  ------------------
  |  Branch (12187:13): [True: 0, False: 0]
  ------------------
12188|      0|            ss->ssl3.hs.finishedMsgs.sFinished[1] = hashes.u.s;
12189|      0|        else
12190|      0|            ss->ssl3.hs.finishedMsgs.sFinished[0] = hashes.u.s;
12191|      0|        PORT_Assert(hashes.len == sizeof hashes.u.s);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12192|      0|        ss->ssl3.hs.finishedBytes = sizeof hashes.u.s;
12193|      0|        rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_finished, sizeof hashes.u.s);
12194|      0|        if (rv != SECSuccess)
  ------------------
  |  Branch (12194:13): [True: 0, False: 0]
  ------------------
12195|      0|            goto fail; /* err set by AppendHandshake. */
12196|      0|        rv = ssl3_AppendHandshake(ss, &hashes.u.s, sizeof hashes.u.s);
12197|      0|        if (rv != SECSuccess)
  ------------------
  |  Branch (12197:13): [True: 0, False: 0]
  ------------------
12198|      0|            goto fail; /* err set by AppendHandshake. */
12199|      0|    }
12200|  52.5k|    rv = ssl3_FlushHandshake(ss, flags);
12201|  52.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (12201:9): [True: 0, False: 52.5k]
  ------------------
12202|      0|        goto fail; /* error code set by ssl3_FlushHandshake */
12203|      0|    }
12204|       |
12205|  52.5k|    ssl3_RecordKeyLog(ss, "CLIENT_RANDOM", ss->ssl3.cwSpec->masterSecret);
12206|       |
12207|  52.5k|    return SECSuccess;
12208|       |
12209|      0|fail:
12210|      0|    return rv;
12211|  52.5k|}
ssl3con.c:ssl3_ComputeTLSFinished:
11957|   105k|{
11958|   105k|    SECStatus rv;
11959|   105k|    CK_TLS_MAC_PARAMS tls_mac_params;
11960|   105k|    SECItem param = { siBuffer, NULL, 0 };
11961|   105k|    PK11Context *prf_context;
11962|   105k|    unsigned int retLen;
11963|       |
11964|   105k|    PORT_Assert(spec->masterSecret);
  ------------------
  |  |  120|   105k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   105k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 105k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11965|   105k|    if (!spec->masterSecret) {
  ------------------
  |  Branch (11965:9): [True: 0, False: 105k]
  ------------------
11966|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
11967|      0|        return SECFailure;
11968|      0|    }
11969|       |
11970|   105k|    if (spec->version < SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|   105k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (11970:9): [True: 12.0k, False: 93.0k]
  ------------------
11971|  12.0k|        tls_mac_params.prfHashMechanism = CKM_TLS_PRF;
  ------------------
  |  |  973|  12.0k|#define CKM_TLS_PRF 0x00000378UL
  ------------------
11972|  93.0k|    } else {
11973|  93.0k|        tls_mac_params.prfHashMechanism = ssl3_GetPrfHashMechanism(ss);
11974|  93.0k|    }
11975|   105k|    tls_mac_params.ulMacLength = 12;
11976|   105k|    tls_mac_params.ulServerOrClient = isServer ? 1 : 2;
  ------------------
  |  Branch (11976:39): [True: 52.5k, False: 52.5k]
  ------------------
11977|   105k|    param.data = (unsigned char *)&tls_mac_params;
11978|   105k|    param.len = sizeof(tls_mac_params);
11979|   105k|    prf_context = PK11_CreateContextBySymKey(CKM_TLS_MAC, CKA_SIGN,
  ------------------
  |  | 1032|   105k|#define CKM_TLS_MAC 0x000003E4UL
  ------------------
                  prf_context = PK11_CreateContextBySymKey(CKM_TLS_MAC, CKA_SIGN,
  ------------------
  |  |  551|   105k|#define CKA_SIGN 0x00000108UL
  ------------------
11980|   105k|                                             spec->masterSecret, &param);
11981|   105k|    if (!prf_context)
  ------------------
  |  Branch (11981:9): [True: 0, False: 105k]
  ------------------
11982|      0|        return SECFailure;
11983|       |
11984|   105k|    rv = PK11_DigestBegin(prf_context);
11985|   105k|    rv |= PK11_DigestOp(prf_context, hashes->u.raw, hashes->len);
11986|   105k|    rv |= PK11_DigestFinal(prf_context, tlsFinished->verify_data, &retLen,
11987|   105k|                           sizeof tlsFinished->verify_data);
11988|   105k|    PORT_Assert(rv != SECSuccess || retLen == sizeof tlsFinished->verify_data);
  ------------------
  |  |  120|   105k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   210k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 105k]
  |  |  |  |  |  Branch (208:7): [True: 105k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11989|       |
11990|   105k|    PK11_DestroyContext(prf_context, PR_TRUE);
  ------------------
  |  |  437|   105k|#define PR_TRUE 1
  ------------------
11991|       |
11992|   105k|    return rv;
11993|   105k|}
ssl3con.c:ssl3_KEASupportsTickets:
 8593|  6.93k|{
 8594|  6.93k|    if (kea_def->signKeyType == dsaKey) {
  ------------------
  |  Branch (8594:9): [True: 0, False: 6.93k]
  ------------------
 8595|       |        /* TODO: Fix session tickets for DSS. The server code rejects the
 8596|       |         * session ticket received from the client. Bug 1174677 */
 8597|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 8598|      0|    }
 8599|  6.93k|    return PR_TRUE;
  ------------------
  |  |  437|  6.93k|#define PR_TRUE 1
  ------------------
 8600|  6.93k|}
ssl3con.c:ssl3_HandlePostHelloHandshakeMessage:
12768|   116k|{
12769|   116k|    SECStatus rv;
12770|   116k|    PORT_Assert(ss->version < SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|   116k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   116k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 116k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12771|       |
12772|   116k|    switch (ss->ssl3.hs.msg_type) {
12773|     30|        case ssl_hs_hello_request:
  ------------------
  |  Branch (12773:9): [True: 30, False: 116k]
  ------------------
12774|     30|            if (length != 0) {
  ------------------
  |  Branch (12774:17): [True: 21, False: 9]
  ------------------
12775|     21|                (void)ssl3_DecodeError(ss);
12776|     21|                PORT_SetError(SSL_ERROR_RX_MALFORMED_HELLO_REQUEST);
  ------------------
  |  |   65|     21|#define PORT_SetError PORT_SetError_Util
  ------------------
12777|     21|                return SECFailure;
12778|     21|            }
12779|      9|            if (ss->sec.isServer) {
  ------------------
  |  Branch (12779:17): [True: 9, False: 0]
  ------------------
12780|      9|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12781|      9|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_HELLO_REQUEST);
  ------------------
  |  |   65|      9|#define PORT_SetError PORT_SetError_Util
  ------------------
12782|      9|                return SECFailure;
12783|      9|            }
12784|      0|            rv = ssl3_HandleHelloRequest(ss);
12785|      0|            break;
12786|       |
12787|      1|        case ssl_hs_hello_verify_request:
  ------------------
  |  Branch (12787:9): [True: 1, False: 116k]
  ------------------
12788|      1|            if (!IS_DTLS(ss) || ss->sec.isServer) {
  ------------------
  |  |  892|      2|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (12788:17): [True: 1, False: 0]
  |  Branch (12788:33): [True: 0, False: 0]
  ------------------
12789|      1|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12790|      1|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_HELLO_VERIFY_REQUEST);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
12791|      1|                return SECFailure;
12792|      1|            }
12793|      0|            rv = dtls_HandleHelloVerifyRequest(ss, b, length);
12794|      0|            break;
12795|  4.42k|        case ssl_hs_certificate:
  ------------------
  |  Branch (12795:9): [True: 4.42k, False: 111k]
  ------------------
12796|  4.42k|            rv = ssl3_HandleCertificate(ss, b, length);
12797|  4.42k|            break;
12798|      4|        case ssl_hs_certificate_status:
  ------------------
  |  Branch (12798:9): [True: 4, False: 116k]
  ------------------
12799|      4|            rv = ssl3_HandleCertificateStatus(ss, b, length);
12800|      4|            break;
12801|      5|        case ssl_hs_server_key_exchange:
  ------------------
  |  Branch (12801:9): [True: 5, False: 116k]
  ------------------
12802|      5|            if (ss->sec.isServer) {
  ------------------
  |  Branch (12802:17): [True: 5, False: 0]
  ------------------
12803|      5|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12804|      5|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_SERVER_KEY_EXCH);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
12805|      5|                return SECFailure;
12806|      5|            }
12807|      0|            rv = ssl3_HandleServerKeyExchange(ss, b, length);
12808|      0|            break;
12809|      4|        case ssl_hs_certificate_request:
  ------------------
  |  Branch (12809:9): [True: 4, False: 116k]
  ------------------
12810|      4|            if (ss->sec.isServer) {
  ------------------
  |  Branch (12810:17): [True: 4, False: 0]
  ------------------
12811|      4|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12812|      4|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CERT_REQUEST);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
12813|      4|                return SECFailure;
12814|      4|            }
12815|      0|            rv = ssl3_HandleCertificateRequest(ss, b, length);
12816|      0|            break;
12817|      5|        case ssl_hs_server_hello_done:
  ------------------
  |  Branch (12817:9): [True: 5, False: 116k]
  ------------------
12818|      5|            if (length != 0) {
  ------------------
  |  Branch (12818:17): [True: 4, False: 1]
  ------------------
12819|      4|                (void)ssl3_DecodeError(ss);
12820|      4|                PORT_SetError(SSL_ERROR_RX_MALFORMED_HELLO_DONE);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
12821|      4|                return SECFailure;
12822|      4|            }
12823|      1|            if (ss->sec.isServer) {
  ------------------
  |  Branch (12823:17): [True: 1, False: 0]
  ------------------
12824|      1|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12825|      1|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_HELLO_DONE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
12826|      1|                return SECFailure;
12827|      1|            }
12828|      0|            rv = ssl3_HandleServerHelloDone(ss);
12829|      0|            break;
12830|  3.06k|        case ssl_hs_certificate_verify:
  ------------------
  |  Branch (12830:9): [True: 3.06k, False: 113k]
  ------------------
12831|  3.06k|            if (!ss->sec.isServer) {
  ------------------
  |  Branch (12831:17): [True: 0, False: 3.06k]
  ------------------
12832|      0|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12833|      0|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CERT_VERIFY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12834|      0|                return SECFailure;
12835|      0|            }
12836|  3.06k|            rv = ssl3_HandleCertificateVerify(ss, b, length);
12837|  3.06k|            break;
12838|  56.1k|        case ssl_hs_client_key_exchange:
  ------------------
  |  Branch (12838:9): [True: 56.1k, False: 60.1k]
  ------------------
12839|  56.1k|            if (!ss->sec.isServer) {
  ------------------
  |  Branch (12839:17): [True: 0, False: 56.1k]
  ------------------
12840|      0|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12841|      0|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CLIENT_KEY_EXCH);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12842|      0|                return SECFailure;
12843|      0|            }
12844|  56.1k|            rv = ssl3_HandleClientKeyExchange(ss, b, length);
12845|  56.1k|            break;
12846|      4|        case ssl_hs_new_session_ticket:
  ------------------
  |  Branch (12846:9): [True: 4, False: 116k]
  ------------------
12847|      4|            if (ss->sec.isServer) {
  ------------------
  |  Branch (12847:17): [True: 4, False: 0]
  ------------------
12848|      4|                (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12849|      4|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_NEW_SESSION_TICKET);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
12850|      4|                return SECFailure;
12851|      4|            }
12852|      0|            rv = ssl3_HandleNewSessionTicket(ss, b, length);
12853|      0|            break;
12854|  52.6k|        case ssl_hs_finished:
  ------------------
  |  Branch (12854:9): [True: 52.6k, False: 63.7k]
  ------------------
12855|  52.6k|            rv = ssl3_HandleFinished(ss, b, length);
12856|  52.6k|            break;
12857|     24|        default:
  ------------------
  |  Branch (12857:9): [True: 24, False: 116k]
  ------------------
12858|     24|            (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12859|     24|            PORT_SetError(SSL_ERROR_RX_UNKNOWN_HANDSHAKE);
  ------------------
  |  |   65|     24|#define PORT_SetError PORT_SetError_Util
  ------------------
12860|     24|            rv = SECFailure;
12861|   116k|    }
12862|       |
12863|   116k|    return rv;
12864|   116k|}
ssl3con.c:ssl3_HandleCertificate:
11468|  4.42k|{
11469|  4.42k|    SSL_TRC(3, ("%d: SSL3[%d]: handle certificate handshake",
  ------------------
  |  |   71|  4.42k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 4.42k]
  |  |  ------------------
  |  |   72|  4.42k|    ssl_Trace b
  ------------------
11470|  4.42k|                SSL_GETPID(), ss->fd));
11471|  4.42k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  4.42k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.79k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2.05k, False: 2.36k]
  |  |  |  |  |  Branch (208:7): [True: 2.36k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11472|  4.42k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  4.42k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.79k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2.05k, False: 2.36k]
  |  |  |  |  |  Branch (208:7): [True: 2.36k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
11473|       |
11474|  4.42k|    if ((ss->sec.isServer && ss->ssl3.hs.ws != wait_client_cert) ||
  ------------------
  |  Branch (11474:10): [True: 4.42k, False: 0]
  |  Branch (11474:30): [True: 26, False: 4.39k]
  ------------------
11475|  4.42k|        (!ss->sec.isServer && ss->ssl3.hs.ws != wait_server_cert)) {
  ------------------
  |  Branch (11475:10): [True: 0, False: 4.39k]
  |  Branch (11475:31): [True: 0, False: 0]
  ------------------
11476|     26|        (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
11477|     26|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CERTIFICATE);
  ------------------
  |  |   65|     26|#define PORT_SetError PORT_SetError_Util
  ------------------
11478|     26|        return SECFailure;
11479|     26|    }
11480|       |
11481|  4.39k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (11481:9): [True: 4.39k, False: 0]
  ------------------
11482|  4.39k|        dtls_ReceivedFirstMessageInFlight(ss);
11483|  4.39k|    }
11484|       |
11485|  4.39k|    return ssl3_CompleteHandleCertificate(ss, b, length);
11486|  4.42k|}
ssl3con.c:ssl3_HandleCertificateStatus:
11401|      4|{
11402|      4|    SECStatus rv;
11403|       |
11404|      4|    if (ss->ssl3.hs.ws != wait_certificate_status) {
  ------------------
  |  Branch (11404:9): [True: 4, False: 0]
  ------------------
11405|      4|        (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
11406|      4|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CERT_STATUS);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
11407|      4|        return SECFailure;
11408|      4|    }
11409|       |
11410|      0|    rv = ssl_ReadCertificateStatus(ss, b, length);
11411|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (11411:9): [True: 0, False: 0]
  ------------------
11412|      0|        return SECFailure; /* code already set */
11413|      0|    }
11414|       |
11415|      0|    return ssl3_AuthCertificate(ss);
11416|      0|}
ssl3con.c:ssl3_GenerateRSAPMS:
10675|  11.9k|{
10676|  11.9k|    PK11SymKey *pms = NULL;
10677|  11.9k|    PK11SlotInfo *slot = serverKeySlot;
10678|  11.9k|    void *pwArg = ss->pkcs11PinArg;
10679|  11.9k|    SECItem param;
10680|  11.9k|    CK_VERSION version;
10681|  11.9k|    CK_MECHANISM_TYPE mechanism_array[3];
10682|       |
10683|  11.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  11.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  19.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.87k, False: 7.09k]
  |  |  |  |  |  Branch (208:7): [True: 7.09k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10684|       |
10685|  11.9k|    if (slot == NULL) {
  ------------------
  |  Branch (10685:9): [True: 0, False: 11.9k]
  ------------------
10686|      0|        SSLCipherAlgorithm calg;
10687|       |        /* The specReadLock would suffice here, but we cannot assert on
10688|       |        ** read locks.  Also, all the callers who call with a non-null
10689|       |        ** slot already hold the SpecWriteLock.
10690|       |        */
10691|      0|        PORT_Assert(ss->opt.noLocks || ssl_HaveSpecWriteLock(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10692|      0|        PORT_Assert(ss->ssl3.prSpec->epoch == ss->ssl3.pwSpec->epoch);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10693|       |
10694|      0|        calg = spec->cipherDef->calg;
10695|       |
10696|       |        /* First get an appropriate slot.  */
10697|      0|        mechanism_array[0] = CKM_SSL3_PRE_MASTER_KEY_GEN;
  ------------------
  |  |  959|      0|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
10698|      0|        mechanism_array[1] = CKM_RSA_PKCS;
  ------------------
  |  |  720|      0|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
10699|      0|        mechanism_array[2] = ssl3_Alg2Mech(calg);
10700|       |
10701|      0|        slot = PK11_GetBestSlotMultiple(mechanism_array, 3, pwArg);
10702|      0|        if (slot == NULL) {
  ------------------
  |  Branch (10702:13): [True: 0, False: 0]
  ------------------
10703|       |            /* can't find a slot with all three, find a slot with the minimum */
10704|      0|            slot = PK11_GetBestSlotMultiple(mechanism_array, 2, pwArg);
10705|      0|            if (slot == NULL) {
  ------------------
  |  Branch (10705:17): [True: 0, False: 0]
  ------------------
10706|      0|                PORT_SetError(SSL_ERROR_TOKEN_SLOT_NOT_FOUND);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10707|      0|                return pms; /* which is NULL */
10708|      0|            }
10709|      0|        }
10710|      0|    }
10711|       |
10712|       |    /* Generate the pre-master secret ...  */
10713|  11.9k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  11.9k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 11.9k]
  |  |  ------------------
  ------------------
10714|      0|        SSL3ProtocolVersion temp;
10715|       |
10716|      0|        temp = dtls_TLSVersionToDTLSVersion(ss->clientHelloVersion);
10717|      0|        version.major = MSB(temp);
  ------------------
  |  |   94|      0|#define MSB(x) ((unsigned char)(((unsigned)(x)) >> 8))
  ------------------
10718|      0|        version.minor = LSB(temp);
  ------------------
  |  |   93|      0|#define LSB(x) ((unsigned char)((x)&0xff))
  ------------------
10719|  11.9k|    } else {
10720|  11.9k|        version.major = MSB(ss->clientHelloVersion);
  ------------------
  |  |   94|  11.9k|#define MSB(x) ((unsigned char)(((unsigned)(x)) >> 8))
  ------------------
10721|  11.9k|        version.minor = LSB(ss->clientHelloVersion);
  ------------------
  |  |   93|  11.9k|#define LSB(x) ((unsigned char)((x)&0xff))
  ------------------
10722|  11.9k|    }
10723|       |
10724|  11.9k|    param.data = (unsigned char *)&version;
10725|  11.9k|    param.len = sizeof version;
10726|       |
10727|  11.9k|    pms = PK11_KeyGen(slot, CKM_SSL3_PRE_MASTER_KEY_GEN, &param, 0, pwArg);
  ------------------
  |  |  959|  11.9k|#define CKM_SSL3_PRE_MASTER_KEY_GEN 0x00000370UL
  ------------------
10728|  11.9k|    if (!serverKeySlot)
  ------------------
  |  Branch (10728:9): [True: 0, False: 11.9k]
  ------------------
10729|      0|        PK11_FreeSlot(slot);
10730|  11.9k|    if (pms == NULL) {
  ------------------
  |  Branch (10730:9): [True: 0, False: 11.9k]
  ------------------
10731|      0|        ssl_MapLowLevelError(SSL_ERROR_CLIENT_KEY_EXCHANGE_FAILURE);
10732|      0|    }
10733|  11.9k|    return pms;
10734|  11.9k|}
ssl3con.c:ssl3_HandleCertificateVerify:
10565|  3.06k|{
10566|  3.06k|    SECItem signed_hash = { siBuffer, NULL, 0 };
10567|  3.06k|    SECStatus rv;
10568|  3.06k|    int errCode = SSL_ERROR_RX_MALFORMED_CERT_VERIFY;
10569|  3.06k|    SSL3AlertDescription desc = handshake_failure;
10570|  3.06k|    PRBool isTLS;
10571|  3.06k|    SSLSignatureScheme sigScheme;
10572|  3.06k|    SSL3Hashes hashes;
10573|  3.06k|    const PRUint8 *savedMsg = b;
10574|  3.06k|    const PRUint32 savedLen = length;
10575|       |
10576|  3.06k|    SSL_TRC(3, ("%d: SSL3[%d]: handle certificate_verify handshake",
  ------------------
  |  |   71|  3.06k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 3.06k]
  |  |  ------------------
  |  |   72|  3.06k|    ssl_Trace b
  ------------------
10577|  3.06k|                SSL_GETPID(), ss->fd));
10578|  3.06k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  3.06k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.68k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.43k, False: 1.62k]
  |  |  |  |  |  Branch (208:7): [True: 1.62k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10579|  3.06k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  3.06k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.68k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.43k, False: 1.62k]
  |  |  |  |  |  Branch (208:7): [True: 1.62k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10580|       |
10581|  3.06k|    if (ss->ssl3.hs.ws != wait_cert_verify) {
  ------------------
  |  Branch (10581:9): [True: 6, False: 3.05k]
  ------------------
10582|      6|        desc = unexpected_message;
10583|      6|        errCode = SSL_ERROR_RX_UNEXPECTED_CERT_VERIFY;
10584|      6|        goto alert_loser;
10585|      6|    }
10586|       |
10587|       |    /* TLS 1.3 is handled by tls13_HandleCertificateVerify */
10588|  3.05k|    PORT_Assert(ss->ssl3.prSpec->version <= SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |  120|  3.05k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.05k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.05k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10589|       |
10590|  3.05k|    if (ss->ssl3.prSpec->version == SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  3.05k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (10590:9): [True: 3.02k, False: 33]
  ------------------
10591|  3.02k|        PORT_Assert(ss->ssl3.hs.hashType == handshake_hash_record);
  ------------------
  |  |  120|  3.02k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.02k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.02k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10592|  3.02k|        rv = ssl_ConsumeSignatureScheme(ss, &b, &length, &sigScheme);
10593|  3.02k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10593:13): [True: 2, False: 3.01k]
  ------------------
10594|      2|            if (PORT_GetError() == SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM) {
  ------------------
  |  |   62|      2|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (10594:17): [True: 1, False: 1]
  ------------------
10595|      1|                errCode = SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM;
10596|      1|            }
10597|      2|            goto loser; /* alert already sent */
10598|      2|        }
10599|  3.01k|        rv = ssl_CheckSignatureSchemeConsistency(
10600|  3.01k|            ss, sigScheme, &ss->sec.peerCert->subjectPublicKeyInfo);
10601|  3.01k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10601:13): [True: 10, False: 3.00k]
  ------------------
10602|     10|            errCode = PORT_GetError();
  ------------------
  |  |   62|     10|#define PORT_GetError PORT_GetError_Util
  ------------------
10603|     10|            desc = illegal_parameter;
10604|     10|            goto alert_loser;
10605|     10|        }
10606|       |
10607|  3.00k|        rv = ssl3_ComputeHandshakeHash(ss->ssl3.hs.messages.buf,
10608|  3.00k|                                       ss->ssl3.hs.messages.len,
10609|  3.00k|                                       ssl_SignatureSchemeToHashType(sigScheme),
10610|  3.00k|                                       &hashes);
10611|  3.00k|    } else {
10612|     33|        PORT_Assert(ss->ssl3.hs.hashType != handshake_hash_record);
  ------------------
  |  |  120|     33|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     33|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 33, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10613|     33|        sigScheme = ssl_sig_none;
10614|     33|        rv = ssl3_ComputeHandshakeHashes(ss, ss->ssl3.prSpec, &hashes, 0);
10615|     33|    }
10616|       |
10617|  3.04k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10617:9): [True: 0, False: 3.04k]
  ------------------
10618|      0|        errCode = SSL_ERROR_DIGEST_FAILURE;
10619|      0|        desc = decrypt_error;
10620|      0|        goto alert_loser;
10621|      0|    }
10622|       |
10623|  3.04k|    rv = ssl3_ConsumeHandshakeVariable(ss, &signed_hash, 2, &b, &length);
10624|  3.04k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10624:9): [True: 20, False: 3.02k]
  ------------------
10625|     20|        goto loser; /* malformed. */
10626|     20|    }
10627|       |
10628|  3.02k|    isTLS = (PRBool)(ss->ssl3.prSpec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  3.02k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
10629|       |
10630|       |    /* XXX verify that the key & kea match */
10631|  3.02k|    rv = ssl3_VerifySignedHashes(ss, sigScheme, &hashes, &signed_hash);
10632|  3.02k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10632:9): [True: 4, False: 3.01k]
  ------------------
10633|      4|        errCode = PORT_GetError();
  ------------------
  |  |   62|      4|#define PORT_GetError PORT_GetError_Util
  ------------------
10634|      4|        desc = isTLS ? decrypt_error : handshake_failure;
  ------------------
  |  Branch (10634:16): [True: 4, False: 0]
  ------------------
10635|      4|        goto alert_loser;
10636|      4|    }
10637|       |
10638|  3.01k|    signed_hash.data = NULL;
10639|       |
10640|  3.01k|    if (length != 0) {
  ------------------
  |  Branch (10640:9): [True: 28, False: 2.99k]
  ------------------
10641|     28|        desc = isTLS ? decode_error : illegal_parameter;
  ------------------
  |  Branch (10641:16): [True: 28, False: 0]
  ------------------
10642|     28|        goto alert_loser; /* malformed */
10643|     28|    }
10644|       |
10645|  2.99k|    rv = ssl_HashHandshakeMessage(ss, ssl_hs_certificate_verify,
10646|  2.99k|                                  savedMsg, savedLen);
10647|  2.99k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10647:9): [True: 0, False: 2.99k]
  ------------------
10648|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10649|      0|        return rv;
10650|      0|    }
10651|       |
10652|  2.99k|    ss->ssl3.hs.ws = wait_change_cipher;
10653|  2.99k|    return SECSuccess;
10654|       |
10655|     48|alert_loser:
10656|     48|    SSL3_SendAlert(ss, alert_fatal, desc);
10657|     70|loser:
10658|     70|    PORT_SetError(errCode);
  ------------------
  |  |   65|     70|#define PORT_SetError PORT_SetError_Util
  ------------------
10659|     70|    return SECFailure;
10660|     48|}
ssl3con.c:ssl3_HandleClientKeyExchange:
10941|  56.1k|{
10942|  56.1k|    sslKeyPair *serverKeyPair = NULL;
10943|  56.1k|    SECStatus rv;
10944|  56.1k|    const ssl3KEADef *kea_def;
10945|       |
10946|  56.1k|    SSL_TRC(3, ("%d: SSL3[%d]: handle client_key_exchange handshake",
  ------------------
  |  |   71|  56.1k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 56.1k]
  |  |  ------------------
  |  |   72|  56.1k|    ssl_Trace b
  ------------------
10947|  56.1k|                SSL_GETPID(), ss->fd));
10948|       |
10949|  56.1k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  56.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  85.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27.3k, False: 28.8k]
  |  |  |  |  |  Branch (208:7): [True: 28.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10950|  56.1k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  56.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  85.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27.3k, False: 28.8k]
  |  |  |  |  |  Branch (208:7): [True: 28.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10951|       |
10952|  56.1k|    if (ss->ssl3.hs.ws != wait_client_key) {
  ------------------
  |  Branch (10952:9): [True: 50, False: 56.1k]
  ------------------
10953|     50|        SSL3_SendAlert(ss, alert_fatal, unexpected_message);
10954|     50|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CLIENT_KEY_EXCH);
  ------------------
  |  |   65|     50|#define PORT_SetError PORT_SetError_Util
  ------------------
10955|     50|        return SECFailure;
10956|     50|    }
10957|       |
10958|  56.1k|    kea_def = ss->ssl3.hs.kea_def;
10959|       |
10960|  56.1k|    if (kea_def->ephemeral) {
  ------------------
  |  Branch (10960:9): [True: 44.1k, False: 11.9k]
  ------------------
10961|  44.1k|        sslEphemeralKeyPair *keyPair;
10962|       |        /* There should be exactly one pair. */
10963|  44.1k|        PORT_Assert(!PR_CLIST_IS_EMPTY(&ss->ephemeralKeyPairs));
  ------------------
  |  |  120|  44.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  44.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 44.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10964|  44.1k|        PORT_Assert(PR_PREV_LINK(&ss->ephemeralKeyPairs) ==
  ------------------
  |  |  120|  44.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  44.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 44.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10965|  44.1k|                    PR_NEXT_LINK(&ss->ephemeralKeyPairs));
10966|  44.1k|        keyPair = (sslEphemeralKeyPair *)PR_NEXT_LINK(&ss->ephemeralKeyPairs);
  ------------------
  |  |   47|  44.1k|        ((_e)->next)
  ------------------
10967|  44.1k|        serverKeyPair = keyPair->keys;
10968|  44.1k|        ss->sec.keaKeyBits =
10969|  44.1k|            SECKEY_PublicKeyStrengthInBits(serverKeyPair->pubKey);
10970|  44.1k|    } else {
10971|  11.9k|        serverKeyPair = ss->sec.serverCert->serverKeyPair;
10972|  11.9k|        ss->sec.keaKeyBits = ss->sec.serverCert->serverKeyBits;
10973|  11.9k|    }
10974|       |
10975|  56.1k|    if (!serverKeyPair) {
  ------------------
  |  Branch (10975:9): [True: 0, False: 56.1k]
  ------------------
10976|      0|        SSL3_SendAlert(ss, alert_fatal, handshake_failure);
10977|      0|        PORT_SetError(SSL_ERROR_NO_SERVER_KEY_FOR_ALG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10978|      0|        return SECFailure;
10979|      0|    }
10980|  56.1k|    PORT_Assert(serverKeyPair->pubKey);
  ------------------
  |  |  120|  56.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  56.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 56.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10981|  56.1k|    PORT_Assert(serverKeyPair->privKey);
  ------------------
  |  |  120|  56.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  56.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 56.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10982|       |
10983|  56.1k|    ss->sec.keaType = kea_def->exchKeyType;
10984|       |
10985|  56.1k|    switch (kea_def->exchKeyType) {
10986|  11.9k|        case ssl_kea_rsa:
  ------------------
  |  Branch (10986:9): [True: 11.9k, False: 44.1k]
  ------------------
10987|  11.9k|            rv = ssl3_HandleRSAClientKeyExchange(ss, b, length, serverKeyPair);
10988|  11.9k|            break;
10989|       |
10990|  27.2k|        case ssl_kea_dh:
  ------------------
  |  Branch (10990:9): [True: 27.2k, False: 28.8k]
  ------------------
10991|  27.2k|            rv = ssl3_HandleDHClientKeyExchange(ss, b, length, serverKeyPair);
10992|  27.2k|            break;
10993|       |
10994|  16.9k|        case ssl_kea_ecdh:
  ------------------
  |  Branch (10994:9): [True: 16.9k, False: 39.2k]
  ------------------
10995|  16.9k|            rv = ssl3_HandleECDHClientKeyExchange(ss, b, length, serverKeyPair);
10996|  16.9k|            break;
10997|       |
10998|      0|        default:
  ------------------
  |  Branch (10998:9): [True: 0, False: 56.1k]
  ------------------
10999|      0|            (void)ssl3_HandshakeFailure(ss);
11000|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_KEYALG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
11001|      0|            return SECFailure;
11002|  56.1k|    }
11003|  56.1k|    ssl_FreeEphemeralKeyPairs(ss);
11004|  56.1k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (11004:9): [True: 55.8k, False: 317]
  ------------------
11005|  55.8k|        ss->ssl3.hs.ws = ss->sec.peerCert ? wait_cert_verify : wait_change_cipher;
  ------------------
  |  Branch (11005:26): [True: 3.06k, False: 52.7k]
  ------------------
11006|  55.8k|    } else {
11007|       |        /* PORT_SetError has been called by all the Handle*ClientKeyExchange
11008|       |         * functions above.  However, not all error paths result in an alert, so
11009|       |         * this ensures that the server knows about the error.  Note that if an
11010|       |         * alert was already sent, SSL3_SendAlert() is a noop. */
11011|    317|        PRErrorCode errCode = PORT_GetError();
  ------------------
  |  |   62|    317|#define PORT_GetError PORT_GetError_Util
  ------------------
11012|    317|        (void)SSL3_SendAlert(ss, alert_fatal, handshake_failure);
11013|    317|        PORT_SetError(errCode);
  ------------------
  |  |   65|    317|#define PORT_SetError PORT_SetError_Util
  ------------------
11014|    317|    }
11015|  56.1k|    return rv;
11016|  56.1k|}
ssl3con.c:ssl3_HandleRSAClientKeyExchange:
10770|  11.9k|{
10771|  11.9k|    SECStatus rv;
10772|  11.9k|    SECItem enc_pms;
10773|  11.9k|    PK11SymKey *pms = NULL;
10774|  11.9k|    PK11SymKey *fauxPms = NULL;
10775|  11.9k|    PK11SlotInfo *slot = NULL;
10776|       |
10777|  11.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  11.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  19.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.88k, False: 7.09k]
  |  |  |  |  |  Branch (208:7): [True: 7.09k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10778|  11.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  11.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  19.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.88k, False: 7.09k]
  |  |  |  |  |  Branch (208:7): [True: 7.09k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10779|  11.9k|    PORT_Assert(ss->ssl3.prSpec->epoch == ss->ssl3.pwSpec->epoch);
  ------------------
  |  |  120|  11.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10780|       |
10781|  11.9k|    enc_pms.data = b;
10782|  11.9k|    enc_pms.len = length;
10783|       |
10784|  11.9k|    if (ss->ssl3.prSpec->version > SSL_LIBRARY_VERSION_3_0) { /* isTLS */
  ------------------
  |  |   17|  11.9k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (10784:9): [True: 11.9k, False: 0]
  ------------------
10785|  11.9k|        PRUint32 kLen;
10786|  11.9k|        rv = ssl3_ConsumeHandshakeNumber(ss, &kLen, 2, &enc_pms.data, &enc_pms.len);
10787|  11.9k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (10787:13): [True: 5, False: 11.9k]
  ------------------
10788|      5|            PORT_SetError(SSL_ERROR_CLIENT_KEY_EXCHANGE_FAILURE);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
10789|      5|            return SECFailure;
10790|      5|        }
10791|  11.9k|        if ((unsigned)kLen < enc_pms.len) {
  ------------------
  |  Branch (10791:13): [True: 6.29k, False: 5.68k]
  ------------------
10792|  6.29k|            enc_pms.len = kLen;
10793|  6.29k|        }
10794|  11.9k|    }
10795|       |
10796|       |    /*
10797|       |     * Get as close to algorithm 2 from RFC 5246; Section 7.4.7.1
10798|       |     * as we can within the constraints of the PKCS#11 interface.
10799|       |     *
10800|       |     * 1. Unconditionally generate a bogus PMS (what RFC 5246
10801|       |     *    calls R).
10802|       |     * 2. Attempt the RSA decryption to recover the PMS (what
10803|       |     *    RFC 5246 calls M).
10804|       |     * 3. Set PMS = (M == NULL) ? R : M
10805|       |     * 4. Use ssl3_ComputeMasterSecret(PMS) to attempt to derive
10806|       |     *    the MS from PMS. This includes performing the version
10807|       |     *    check and length check.
10808|       |     * 5. If either the initial RSA decryption failed or
10809|       |     *    ssl3_ComputeMasterSecret(PMS) failed, then discard
10810|       |     *    M and set PMS = R. Else, discard R and set PMS = M.
10811|       |     *
10812|       |     * We do two derivations here because we can't rely on having
10813|       |     * a function that only performs the PMS version and length
10814|       |     * check. The only redundant cost is that this runs the PRF,
10815|       |     * which isn't necessary here.
10816|       |     */
10817|       |
10818|       |    /* Generate the bogus PMS (R) */
10819|  11.9k|    slot = PK11_GetSlotFromPrivateKey(serverKeyPair->privKey);
10820|  11.9k|    if (!slot) {
  ------------------
  |  Branch (10820:9): [True: 0, False: 11.9k]
  ------------------
10821|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10822|      0|        return SECFailure;
10823|      0|    }
10824|       |
10825|  11.9k|    if (!PK11_DoesMechanism(slot, CKM_SSL3_MASTER_KEY_DERIVE)) {
  ------------------
  |  |  960|  11.9k|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
  |  Branch (10825:9): [True: 0, False: 11.9k]
  ------------------
10826|      0|        PK11_FreeSlot(slot);
10827|      0|        slot = PK11_GetBestSlot(CKM_SSL3_MASTER_KEY_DERIVE, NULL);
  ------------------
  |  |  960|      0|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
10828|      0|        if (!slot) {
  ------------------
  |  Branch (10828:13): [True: 0, False: 0]
  ------------------
10829|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
10830|      0|            return SECFailure;
10831|      0|        }
10832|      0|    }
10833|       |
10834|  11.9k|    ssl_GetSpecWriteLock(ss);
  ------------------
  |  | 1435|  11.9k|    {                                            \
  |  | 1436|  11.9k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 7.09k, False: 4.87k]
  |  |  ------------------
  |  | 1437|  11.9k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  7.09k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  11.9k|    }
  ------------------
10835|  11.9k|    fauxPms = ssl3_GenerateRSAPMS(ss, ss->ssl3.prSpec, slot);
10836|  11.9k|    ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|  11.9k|    {                                              \
  |  | 1441|  11.9k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 7.09k, False: 4.87k]
  |  |  ------------------
  |  | 1442|  11.9k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  7.09k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  11.9k|    }
  ------------------
10837|  11.9k|    PK11_FreeSlot(slot);
10838|       |
10839|  11.9k|    if (fauxPms == NULL) {
  ------------------
  |  Branch (10839:9): [True: 0, False: 11.9k]
  ------------------
10840|      0|        ssl_MapLowLevelError(SSL_ERROR_CLIENT_KEY_EXCHANGE_FAILURE);
10841|      0|        return SECFailure;
10842|      0|    }
10843|       |
10844|       |    /*
10845|       |     * unwrap pms out of the incoming buffer
10846|       |     * Note: CKM_SSL3_MASTER_KEY_DERIVE is NOT the mechanism used to do
10847|       |     *  the unwrap.  Rather, it is the mechanism with which the
10848|       |     *      unwrapped pms will be used.
10849|       |     */
10850|  11.9k|    pms = PK11_PubUnwrapSymKey(serverKeyPair->privKey, &enc_pms,
10851|  11.9k|                               CKM_SSL3_MASTER_KEY_DERIVE, CKA_DERIVE, 0);
  ------------------
  |  |  960|  11.9k|#define CKM_SSL3_MASTER_KEY_DERIVE 0x00000371UL
  ------------------
                                             CKM_SSL3_MASTER_KEY_DERIVE, CKA_DERIVE, 0);
  ------------------
  |  |  555|  11.9k|#define CKA_DERIVE 0x0000010CUL
  ------------------
10852|       |    /* Temporarily use the PMS if unwrapping the real PMS fails. */
10853|  11.9k|    ssl3_CSwapPK11SymKey(&pms, &fauxPms, pms == NULL);
10854|       |
10855|       |    /* Attempt to derive the MS from the PMS. This is the only way to
10856|       |     * check the version field in the RSA PMS. If this fails, we
10857|       |     * then use the faux PMS in place of the PMS. Note that this
10858|       |     * operation should never fail if we are using the faux PMS
10859|       |     * since it is correctly formatted. */
10860|  11.9k|    rv = ssl3_ComputeMasterSecret(ss, pms, NULL);
10861|       |
10862|       |    /* If we succeeded, then select the true PMS, else select the FPMS. */
10863|  11.9k|    ssl3_CSwapPK11SymKey(&pms, &fauxPms, (rv != SECSuccess) & (fauxPms != NULL));
10864|       |
10865|       |    /* This step will derive the MS from the PMS, among other things. */
10866|  11.9k|    rv = ssl3_InitPendingCipherSpecs(ss, pms, PR_TRUE);
  ------------------
  |  |  437|  11.9k|#define PR_TRUE 1
  ------------------
10867|       |
10868|       |    /* Clear both PMS. */
10869|  11.9k|    PK11_FreeSymKey(pms);
10870|  11.9k|    PK11_FreeSymKey(fauxPms);
10871|       |
10872|  11.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10872:9): [True: 0, False: 11.9k]
  ------------------
10873|      0|        (void)SSL3_SendAlert(ss, alert_fatal, handshake_failure);
10874|      0|        return SECFailure; /* error code set by ssl3_InitPendingCipherSpec */
10875|      0|    }
10876|       |
10877|  11.9k|    return SECSuccess;
10878|  11.9k|}
ssl3con.c:ssl3_CSwapPK11SymKey:
10738|  23.9k|{
10739|  23.9k|    uintptr_t mask = (uintptr_t)c;
10740|  23.9k|    unsigned int i;
10741|   167k|    for (i = 1; i < sizeof(uintptr_t) * 8; i <<= 1) {
  ------------------
  |  Branch (10741:17): [True: 143k, False: 23.9k]
  ------------------
10742|   143k|        mask |= mask << i;
10743|   143k|    }
10744|  23.9k|    uintptr_t x_ptr = (uintptr_t)*x;
10745|  23.9k|    uintptr_t y_ptr = (uintptr_t)*y;
10746|  23.9k|    uintptr_t tmp = (x_ptr ^ y_ptr) & mask;
10747|  23.9k|    x_ptr = x_ptr ^ tmp;
10748|  23.9k|    y_ptr = y_ptr ^ tmp;
10749|  23.9k|    *x = (PK11SymKey *)x_ptr;
10750|  23.9k|    *y = (PK11SymKey *)y_ptr;
10751|  23.9k|}
ssl3con.c:ssl3_HandleDHClientKeyExchange:
10885|  27.2k|{
10886|  27.2k|    PK11SymKey *pms;
10887|  27.2k|    SECStatus rv;
10888|  27.2k|    SECKEYPublicKey clntPubKey;
10889|  27.2k|    CK_MECHANISM_TYPE target;
10890|  27.2k|    PRBool isTLS;
10891|       |
10892|  27.2k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  27.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  41.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 13.4k, False: 13.8k]
  |  |  |  |  |  Branch (208:7): [True: 13.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10893|  27.2k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  27.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  41.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 13.4k, False: 13.8k]
  |  |  |  |  |  Branch (208:7): [True: 13.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
10894|       |
10895|  27.2k|    clntPubKey.keyType = dhKey;
10896|  27.2k|    clntPubKey.u.dh.prime.len = serverKeyPair->pubKey->u.dh.prime.len;
10897|  27.2k|    clntPubKey.u.dh.prime.data = serverKeyPair->pubKey->u.dh.prime.data;
10898|  27.2k|    clntPubKey.u.dh.base.len = serverKeyPair->pubKey->u.dh.base.len;
10899|  27.2k|    clntPubKey.u.dh.base.data = serverKeyPair->pubKey->u.dh.base.data;
10900|       |
10901|  27.2k|    rv = ssl3_ConsumeHandshakeVariable(ss, &clntPubKey.u.dh.publicValue,
10902|  27.2k|                                       2, &b, &length);
10903|  27.2k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (10903:9): [True: 38, False: 27.2k]
  ------------------
10904|     38|        return SECFailure;
10905|     38|    }
10906|       |
10907|  27.2k|    if (!ssl_IsValidDHEShare(&serverKeyPair->pubKey->u.dh.prime,
  ------------------
  |  Branch (10907:9): [True: 37, False: 27.1k]
  ------------------
10908|  27.2k|                             &clntPubKey.u.dh.publicValue)) {
10909|     37|        PORT_SetError(SSL_ERROR_RX_MALFORMED_DHE_KEY_SHARE);
  ------------------
  |  |   65|     37|#define PORT_SetError PORT_SetError_Util
  ------------------
10910|     37|        return SECFailure;
10911|     37|    }
10912|       |
10913|  27.1k|    isTLS = (PRBool)(ss->ssl3.prSpec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  27.1k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
10914|       |
10915|  27.1k|    if (isTLS)
  ------------------
  |  Branch (10915:9): [True: 27.1k, False: 0]
  ------------------
10916|  27.1k|        target = CKM_TLS_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  970|  27.1k|#define CKM_TLS_MASTER_KEY_DERIVE_DH 0x00000377UL
  ------------------
10917|      0|    else
10918|      0|        target = CKM_SSL3_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  966|      0|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
10919|       |
10920|       |    /* Determine the PMS */
10921|  27.1k|    pms = PK11_PubDerive(serverKeyPair->privKey, &clntPubKey, PR_FALSE, NULL, NULL,
  ------------------
  |  |  438|  27.1k|#define PR_FALSE 0
  ------------------
10922|  27.1k|                         CKM_DH_PKCS_DERIVE, target, CKA_DERIVE, 0, NULL);
  ------------------
  |  |  759|  27.1k|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
                                       CKM_DH_PKCS_DERIVE, target, CKA_DERIVE, 0, NULL);
  ------------------
  |  |  555|  27.1k|#define CKA_DERIVE 0x0000010CUL
  ------------------
10923|  27.1k|    if (pms == NULL) {
  ------------------
  |  Branch (10923:9): [True: 0, False: 27.1k]
  ------------------
10924|      0|        ssl_FreeEphemeralKeyPairs(ss);
10925|      0|        ssl_MapLowLevelError(SSL_ERROR_CLIENT_KEY_EXCHANGE_FAILURE);
10926|      0|        return SECFailure;
10927|      0|    }
10928|       |
10929|  27.1k|    rv = ssl3_InitPendingCipherSpecs(ss, pms, PR_TRUE);
  ------------------
  |  |  437|  27.1k|#define PR_TRUE 1
  ------------------
10930|  27.1k|    PK11_FreeSymKey(pms);
10931|  27.1k|    ssl_FreeEphemeralKeyPairs(ss);
10932|  27.1k|    return rv;
10933|  27.1k|}
ssl3con.c:ssl3_HandleFinished:
12314|  52.6k|{
12315|  52.6k|    SECStatus rv = SECSuccess;
12316|  52.6k|    PRBool isServer = ss->sec.isServer;
12317|  52.6k|    PRBool isTLS;
12318|  52.6k|    SSL3Hashes hashes;
12319|       |
12320|  52.6k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  52.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.6k, False: 27.0k]
  |  |  |  |  |  Branch (208:7): [True: 27.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12321|  52.6k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  52.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  79.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.6k, False: 27.0k]
  |  |  |  |  |  Branch (208:7): [True: 27.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12322|       |
12323|  52.6k|    SSL_TRC(3, ("%d: SSL3[%d]: handle finished handshake",
  ------------------
  |  |   71|  52.6k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 52.6k]
  |  |  ------------------
  |  |   72|  52.6k|    ssl_Trace b
  ------------------
12324|  52.6k|                SSL_GETPID(), ss->fd));
12325|       |
12326|  52.6k|    if (ss->ssl3.hs.ws != wait_finished) {
  ------------------
  |  Branch (12326:9): [True: 56, False: 52.5k]
  ------------------
12327|     56|        SSL3_SendAlert(ss, alert_fatal, unexpected_message);
12328|     56|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_FINISHED);
  ------------------
  |  |   65|     56|#define PORT_SetError PORT_SetError_Util
  ------------------
12329|     56|        return SECFailure;
12330|     56|    }
12331|       |
12332|  52.5k|    if (!ss->sec.isServer || !ss->opt.requestCertificate) {
  ------------------
  |  Branch (12332:9): [True: 0, False: 52.5k]
  |  Branch (12332:30): [True: 50.6k, False: 1.92k]
  ------------------
12333|  50.6k|        dtls_ReceivedFirstMessageInFlight(ss);
12334|  50.6k|    }
12335|       |
12336|  52.5k|    rv = ssl3_ComputeHandshakeHashes(ss, ss->ssl3.crSpec, &hashes,
12337|  52.5k|                                     isServer ? sender_client : sender_server);
  ------------------
  |  Branch (12337:38): [True: 52.5k, False: 0]
  ------------------
12338|  52.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (12338:9): [True: 0, False: 52.5k]
  ------------------
12339|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12340|      0|        return SECFailure;
12341|      0|    }
12342|       |
12343|  52.5k|    rv = ssl_HashHandshakeMessage(ss, ssl_hs_finished, b, length);
12344|  52.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (12344:9): [True: 0, False: 52.5k]
  ------------------
12345|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12346|      0|        return rv;
12347|      0|    }
12348|       |
12349|  52.5k|    isTLS = (PRBool)(ss->ssl3.crSpec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  52.5k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
12350|  52.5k|    if (isTLS) {
  ------------------
  |  Branch (12350:9): [True: 52.5k, False: 0]
  ------------------
12351|  52.5k|        TLSFinished tlsFinished;
12352|       |
12353|  52.5k|        if (length != sizeof(tlsFinished)) {
  ------------------
  |  Branch (12353:13): [True: 35.1k, False: 17.4k]
  ------------------
12354|       |#ifndef UNSAFE_FUZZER_MODE
12355|       |            (void)SSL3_SendAlert(ss, alert_fatal, decode_error);
12356|       |            PORT_SetError(SSL_ERROR_RX_MALFORMED_FINISHED);
12357|       |            return SECFailure;
12358|       |#endif
12359|  35.1k|        }
12360|  52.5k|        rv = ssl3_ComputeTLSFinished(ss, ss->ssl3.crSpec, !isServer,
12361|  52.5k|                                     &hashes, &tlsFinished);
12362|  52.5k|        if (!isServer)
  ------------------
  |  Branch (12362:13): [True: 0, False: 52.5k]
  ------------------
12363|      0|            ss->ssl3.hs.finishedMsgs.tFinished[1] = tlsFinished;
12364|  52.5k|        else
12365|  52.5k|            ss->ssl3.hs.finishedMsgs.tFinished[0] = tlsFinished;
12366|  52.5k|        ss->ssl3.hs.finishedBytes = sizeof(tlsFinished);
12367|  52.5k|        if (rv != SECSuccess ||
  ------------------
  |  Branch (12367:13): [True: 0, False: 52.5k]
  ------------------
12368|  52.5k|            0 != NSS_SecureMemcmp(&tlsFinished, b,
  ------------------
  |  Branch (12368:13): [True: 17.4k, False: 35.1k]
  ------------------
12369|  52.5k|                                  PR_MIN(length, ss->ssl3.hs.finishedBytes))) {
  ------------------
  |  |  158|  52.5k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 35.1k, False: 17.4k]
  |  |  ------------------
  ------------------
12370|       |#ifndef UNSAFE_FUZZER_MODE
12371|       |            (void)SSL3_SendAlert(ss, alert_fatal, decrypt_error);
12372|       |            PORT_SetError(SSL_ERROR_BAD_HANDSHAKE_HASH_VALUE);
12373|       |            return SECFailure;
12374|       |#endif
12375|  17.4k|        }
12376|  52.5k|    } else {
12377|      0|        if (length != sizeof(SSL3Finished)) {
  ------------------
  |  Branch (12377:13): [True: 0, False: 0]
  ------------------
12378|      0|            (void)ssl3_IllegalParameter(ss);
12379|      0|            PORT_SetError(SSL_ERROR_RX_MALFORMED_FINISHED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12380|      0|            return SECFailure;
12381|      0|        }
12382|       |
12383|      0|        if (!isServer)
  ------------------
  |  Branch (12383:13): [True: 0, False: 0]
  ------------------
12384|      0|            ss->ssl3.hs.finishedMsgs.sFinished[1] = hashes.u.s;
12385|      0|        else
12386|      0|            ss->ssl3.hs.finishedMsgs.sFinished[0] = hashes.u.s;
12387|      0|        PORT_Assert(hashes.len == sizeof hashes.u.s);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12388|      0|        ss->ssl3.hs.finishedBytes = sizeof hashes.u.s;
12389|      0|        if (0 != NSS_SecureMemcmp(&hashes.u.s, b, length)) {
  ------------------
  |  Branch (12389:13): [True: 0, False: 0]
  ------------------
12390|      0|            (void)ssl3_HandshakeFailure(ss);
12391|      0|            PORT_SetError(SSL_ERROR_BAD_HANDSHAKE_HASH_VALUE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12392|      0|            return SECFailure;
12393|      0|        }
12394|      0|    }
12395|       |
12396|  52.5k|    ssl_GetXmitBufLock(ss); /*************************************/
  ------------------
  |  | 1466|  52.5k|    {                                           \
  |  | 1467|  52.5k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 26.9k, False: 25.5k]
  |  |  ------------------
  |  | 1468|  52.5k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  26.9k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  52.5k|    }
  ------------------
12397|       |
12398|  52.5k|    if ((isServer && !ss->ssl3.hs.isResuming) ||
  ------------------
  |  Branch (12398:10): [True: 52.5k, False: 0]
  |  Branch (12398:22): [True: 52.5k, False: 0]
  ------------------
12399|  52.5k|        (!isServer && ss->ssl3.hs.isResuming)) {
  ------------------
  |  Branch (12399:10): [True: 0, False: 0]
  |  Branch (12399:23): [True: 0, False: 0]
  ------------------
12400|  52.5k|        PRInt32 flags = 0;
12401|       |
12402|       |        /* Send a NewSessionTicket message if the client sent us
12403|       |         * either an empty session ticket, or one that did not verify.
12404|       |         * (Note that if either of these conditions was met, then the
12405|       |         * server has sent a SessionTicket extension in the
12406|       |         * ServerHello message.)
12407|       |         */
12408|  52.5k|        if (isServer && !ss->ssl3.hs.isResuming &&
  ------------------
  |  Branch (12408:13): [True: 52.5k, False: 0]
  |  Branch (12408:25): [True: 52.5k, False: 0]
  ------------------
12409|  52.5k|            ssl3_ExtensionNegotiated(ss, ssl_session_ticket_xtn) &&
  ------------------
  |  Branch (12409:13): [True: 3.37k, False: 49.1k]
  ------------------
12410|  52.5k|            ssl3_KEASupportsTickets(ss->ssl3.hs.kea_def)) {
  ------------------
  |  Branch (12410:13): [True: 3.37k, False: 0]
  ------------------
12411|       |            /* RFC 5077 Section 3.3: "In the case of a full handshake, the
12412|       |             * server MUST verify the client's Finished message before sending
12413|       |             * the ticket." Presumably, this also means that the client's
12414|       |             * certificate, if any, must be verified beforehand too.
12415|       |             */
12416|  3.37k|            rv = ssl3_SendNewSessionTicket(ss);
12417|  3.37k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (12417:17): [True: 0, False: 3.37k]
  ------------------
12418|      0|                goto xmit_loser;
12419|      0|            }
12420|  3.37k|        }
12421|       |
12422|  52.5k|        rv = ssl3_SendChangeCipherSpecs(ss);
12423|  52.5k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (12423:13): [True: 0, False: 52.5k]
  ------------------
12424|      0|            goto xmit_loser; /* err is set. */
12425|      0|        }
12426|       |        /* If this thread is in SSL_SecureSend (trying to write some data)
12427|       |        ** then set the ssl_SEND_FLAG_FORCE_INTO_BUFFER flag, so that the
12428|       |        ** last two handshake messages (change cipher spec and finished)
12429|       |        ** will be sent in the same send/write call as the application data.
12430|       |        */
12431|  52.5k|        if (ss->writerThread == PR_GetCurrentThread()) {
  ------------------
  |  Branch (12431:13): [True: 0, False: 52.5k]
  ------------------
12432|      0|            flags = ssl_SEND_FLAG_FORCE_INTO_BUFFER;
  ------------------
  |  |  223|      0|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
12433|      0|        }
12434|       |
12435|  52.5k|        if (!isServer && !ss->firstHsDone) {
  ------------------
  |  Branch (12435:13): [True: 0, False: 52.5k]
  |  Branch (12435:26): [True: 0, False: 0]
  ------------------
12436|      0|            rv = ssl3_SendNextProto(ss);
12437|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (12437:17): [True: 0, False: 0]
  ------------------
12438|      0|                goto xmit_loser; /* err code was set. */
12439|      0|            }
12440|      0|        }
12441|       |
12442|  52.5k|        if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  52.5k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 52.5k]
  |  |  ------------------
  ------------------
12443|      0|            flags |= ssl_SEND_FLAG_NO_RETRANSMIT;
  ------------------
  |  |  225|      0|#define ssl_SEND_FLAG_NO_RETRANSMIT 0x08000000 /* DTLS only */
  ------------------
12444|      0|        }
12445|       |
12446|  52.5k|        rv = ssl3_SendFinished(ss, flags);
12447|  52.5k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (12447:13): [True: 0, False: 52.5k]
  ------------------
12448|      0|            goto xmit_loser; /* err is set. */
12449|      0|        }
12450|  52.5k|    }
12451|       |
12452|  52.5k|xmit_loser:
12453|  52.5k|    ssl_ReleaseXmitBufLock(ss); /*************************************/
  ------------------
  |  | 1471|  52.5k|    {                                          \
  |  | 1472|  52.5k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 26.9k, False: 25.5k]
  |  |  ------------------
  |  | 1473|  52.5k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  26.9k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  52.5k|    }
  ------------------
12454|  52.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (12454:9): [True: 0, False: 52.5k]
  ------------------
12455|      0|        return rv;
12456|      0|    }
12457|       |
12458|  52.5k|    if (ss->ssl3.hs.authCertificatePending) {
  ------------------
  |  Branch (12458:9): [True: 0, False: 52.5k]
  ------------------
12459|      0|        if (ss->ssl3.hs.restartTarget) {
  ------------------
  |  Branch (12459:13): [True: 0, False: 0]
  ------------------
12460|      0|            PR_NOT_REACHED("ssl3_HandleFinished: unexpected restartTarget");
  ------------------
  |  |  213|      0|    PR_Assert(_reasonStr,__FILE__,__LINE__)
  ------------------
12461|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
12462|      0|            return SECFailure;
12463|      0|        }
12464|       |
12465|      0|        ss->ssl3.hs.restartTarget = ssl3_FinishHandshake;
12466|      0|        PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
12467|      0|        return SECFailure;
12468|      0|    }
12469|       |
12470|  52.5k|    rv = ssl3_FinishHandshake(ss);
12471|  52.5k|    return rv;
12472|  52.5k|}
ssl3con.c:ssl3_IllegalParameter:
 2965|     13|{
 2966|     13|    (void)SSL3_SendAlert(ss, alert_fatal, illegal_parameter);
 2967|     13|    PORT_SetError(ss->sec.isServer ? SSL_ERROR_BAD_CLIENT
  ------------------
  |  |   65|     13|#define PORT_SetError PORT_SetError_Util
  ------------------
  |  Branch (2967:19): [True: 13, False: 0]
  ------------------
 2968|     13|                                   : SSL_ERROR_BAD_SERVER);
 2969|     13|    return SECFailure;
 2970|     13|}
ssl3con.c:ssl3_SendNewSessionTicket:
11055|  3.37k|{
11056|  3.37k|    SECItem ticket = { 0, NULL, 0 };
11057|  3.37k|    SECStatus rv;
11058|  3.37k|    NewSessionTicket nticket = { 0 };
11059|       |
11060|  3.37k|    rv = ssl3_EncodeSessionTicket(ss, &nticket, NULL, 0,
11061|  3.37k|                                  ss->ssl3.pwSpec->masterSecret, &ticket);
11062|  3.37k|    if (rv != SECSuccess)
  ------------------
  |  Branch (11062:9): [True: 0, False: 3.37k]
  ------------------
11063|      0|        goto loser;
11064|       |
11065|       |    /* Serialize the handshake message. Length =
11066|       |     * lifetime (4) + ticket length (2) + ticket. */
11067|  3.37k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_new_session_ticket,
11068|  3.37k|                                    4 + 2 + ticket.len);
11069|  3.37k|    if (rv != SECSuccess)
  ------------------
  |  Branch (11069:9): [True: 0, False: 3.37k]
  ------------------
11070|      0|        goto loser;
11071|       |
11072|       |    /* This is a fixed value. */
11073|  3.37k|    rv = ssl3_AppendHandshakeNumber(ss, ssl_ticket_lifetime, 4);
11074|  3.37k|    if (rv != SECSuccess)
  ------------------
  |  Branch (11074:9): [True: 0, False: 3.37k]
  ------------------
11075|      0|        goto loser;
11076|       |
11077|       |    /* Encode the ticket. */
11078|  3.37k|    rv = ssl3_AppendHandshakeVariable(ss, ticket.data, ticket.len, 2);
11079|  3.37k|    if (rv != SECSuccess)
  ------------------
  |  Branch (11079:9): [True: 0, False: 3.37k]
  ------------------
11080|      0|        goto loser;
11081|       |
11082|  3.37k|    rv = SECSuccess;
11083|       |
11084|  3.37k|loser:
11085|  3.37k|    if (ticket.data) {
  ------------------
  |  Branch (11085:9): [True: 3.37k, False: 0]
  ------------------
11086|  3.37k|        SECITEM_FreeItem(&ticket, PR_FALSE);
  ------------------
  |  |  108|  3.37k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&ticket, PR_FALSE);
  ------------------
  |  |  438|  3.37k|#define PR_FALSE 0
  ------------------
11087|  3.37k|    }
11088|  3.37k|    return rv;
11089|  3.37k|}
ssl3con.c:ssl3_HandleChangeCipherSpecs:
 3303|  53.0k|{
 3304|  53.0k|    SSL3WaitState ws = ss->ssl3.hs.ws;
 3305|  53.0k|    SSL3ChangeCipherSpecChoice change;
 3306|       |
 3307|  53.0k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  53.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  80.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.7k, False: 27.2k]
  |  |  |  |  |  Branch (208:7): [True: 27.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3308|  53.0k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  53.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  80.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.7k, False: 27.2k]
  |  |  |  |  |  Branch (208:7): [True: 27.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3309|       |
 3310|  53.0k|    SSL_TRC(3, ("%d: SSL3[%d]: handle change_cipher_spec record",
  ------------------
  |  |   71|  53.0k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 53.0k]
  |  |  ------------------
  |  |   72|  53.0k|    ssl_Trace b
  ------------------
 3311|  53.0k|                SSL_GETPID(), ss->fd));
 3312|       |
 3313|       |    /* For DTLS: Ignore this if we aren't expecting it.  Don't kill a connection
 3314|       |     *           as a result of receiving trash.
 3315|       |     * For TLS: Maybe ignore, but only after checking format. */
 3316|  53.0k|    if (ws != wait_change_cipher && IS_DTLS(ss)) {
  ------------------
  |  |  892|    222|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 222]
  |  |  ------------------
  ------------------
  |  Branch (3316:9): [True: 222, False: 52.7k]
  ------------------
 3317|       |        /* Ignore this because it's out of order. */
 3318|      0|        SSL_TRC(3, ("%d: SSL3[%d]: discard out of order "
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 3319|      0|                    "DTLS change_cipher_spec",
 3320|      0|                    SSL_GETPID(), ss->fd));
 3321|      0|        buf->len = 0;
 3322|      0|        return SECSuccess;
 3323|      0|    }
 3324|       |
 3325|       |    /* Handshake messages should not span ChangeCipherSpec. */
 3326|  53.0k|    if (ss->ssl3.hs.header_bytes) {
  ------------------
  |  Branch (3326:9): [True: 72, False: 52.9k]
  ------------------
 3327|     72|        (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
 3328|     72|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CHANGE_CIPHER);
  ------------------
  |  |   65|     72|#define PORT_SetError PORT_SetError_Util
  ------------------
 3329|     72|        return SECFailure;
 3330|     72|    }
 3331|  52.9k|    if (buf->len != 1) {
  ------------------
  |  Branch (3331:9): [True: 149, False: 52.7k]
  ------------------
 3332|    149|        (void)ssl3_DecodeError(ss);
 3333|    149|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CHANGE_CIPHER);
  ------------------
  |  |   65|    149|#define PORT_SetError PORT_SetError_Util
  ------------------
 3334|    149|        return SECFailure;
 3335|    149|    }
 3336|  52.7k|    change = (SSL3ChangeCipherSpecChoice)buf->buf[0];
 3337|  52.7k|    if (change != change_cipher_spec_choice) {
  ------------------
  |  Branch (3337:9): [True: 13, False: 52.7k]
  ------------------
 3338|       |        /* illegal_parameter is correct here for both SSL3 and TLS. */
 3339|     13|        (void)ssl3_IllegalParameter(ss);
 3340|     13|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CHANGE_CIPHER);
  ------------------
  |  |   65|     13|#define PORT_SetError PORT_SetError_Util
  ------------------
 3341|     13|        return SECFailure;
 3342|     13|    }
 3343|       |
 3344|  52.7k|    buf->len = 0;
 3345|  52.7k|    if (ws != wait_change_cipher) {
  ------------------
  |  Branch (3345:9): [True: 94, False: 52.6k]
  ------------------
 3346|       |        /* Ignore a CCS for TLS 1.3. This only happens if the server sends a
 3347|       |         * HelloRetryRequest.  In other cases, the CCS will fail decryption and
 3348|       |         * will be discarded by ssl3_HandleRecord(). */
 3349|     94|        if (ws == wait_server_hello &&
  ------------------
  |  Branch (3349:13): [True: 0, False: 94]
  ------------------
 3350|     94|            ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|     94|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (3350:13): [True: 0, False: 0]
  ------------------
 3351|     94|            ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (3351:13): [True: 0, False: 0]
  ------------------
 3352|      0|            PORT_Assert(!ss->sec.isServer);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3353|      0|            return SECSuccess;
 3354|      0|        }
 3355|       |        /* Note: For a server, we can't test ss->ssl3.hs.helloRetry or
 3356|       |         * ss->version because the server might be stateless (and so it won't
 3357|       |         * have set either value yet). Set a flag so that at least we will
 3358|       |         * guarantee that the server will treat any ClientHello properly. */
 3359|     94|        if (ws == wait_client_hello &&
  ------------------
  |  Branch (3359:13): [True: 13, False: 81]
  ------------------
 3360|     94|            ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|    107|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (3360:13): [True: 8, False: 5]
  ------------------
 3361|     94|            !ss->ssl3.hs.receivedCcs) {
  ------------------
  |  Branch (3361:13): [True: 7, False: 1]
  ------------------
 3362|      7|            PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|      7|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      7|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3363|      7|            ss->ssl3.hs.receivedCcs = PR_TRUE;
  ------------------
  |  |  437|      7|#define PR_TRUE 1
  ------------------
 3364|      7|            return SECSuccess;
 3365|      7|        }
 3366|     87|        (void)SSL3_SendAlert(ss, alert_fatal, unexpected_message);
 3367|     87|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_CHANGE_CIPHER);
  ------------------
  |  |   65|     87|#define PORT_SetError PORT_SetError_Util
  ------------------
 3368|     87|        return SECFailure;
 3369|     94|    }
 3370|       |
 3371|  52.6k|    SSL_TRC(3, ("%d: SSL3[%d] Set Current Read Cipher Suite to Pending",
  ------------------
  |  |   71|  52.6k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 52.6k]
  |  |  ------------------
  |  |   72|  52.6k|    ssl_Trace b
  ------------------
 3372|  52.6k|                SSL_GETPID(), ss->fd));
 3373|  52.6k|    ssl_GetSpecWriteLock(ss); /*************************************/
  ------------------
  |  | 1435|  52.6k|    {                                            \
  |  | 1436|  52.6k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 27.0k, False: 25.6k]
  |  |  ------------------
  |  | 1437|  52.6k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  27.0k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  52.6k|    }
  ------------------
 3374|  52.6k|    PORT_Assert(ss->ssl3.prSpec);
  ------------------
  |  |  120|  52.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  52.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 52.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3375|  52.6k|    ssl_CipherSpecRelease(ss->ssl3.crSpec);
 3376|  52.6k|    ss->ssl3.crSpec = ss->ssl3.prSpec;
 3377|  52.6k|    ss->ssl3.prSpec = NULL;
 3378|  52.6k|    ssl_ReleaseSpecWriteLock(ss); /*************************************/
  ------------------
  |  | 1440|  52.6k|    {                                              \
  |  | 1441|  52.6k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 27.0k, False: 25.6k]
  |  |  ------------------
  |  | 1442|  52.6k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  27.0k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  52.6k|    }
  ------------------
 3379|       |
 3380|  52.6k|    ss->ssl3.hs.ws = wait_finished;
 3381|  52.6k|    return SECSuccess;
 3382|  52.7k|}
ssl3con.c:ssl3_HandleAlert:
 3048|  10.8k|{
 3049|  10.8k|    SSL3AlertLevel level;
 3050|  10.8k|    SSL3AlertDescription desc;
 3051|  10.8k|    int error;
 3052|       |
 3053|  10.8k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  10.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  18.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 3.15k, False: 7.73k]
  |  |  |  |  |  Branch (208:7): [True: 7.73k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3054|  10.8k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  10.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  18.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 3.15k, False: 7.73k]
  |  |  |  |  |  Branch (208:7): [True: 7.73k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3055|       |
 3056|  10.8k|    SSL_TRC(3, ("%d: SSL3[%d]: handle alert record", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|  10.8k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 10.8k]
  |  |  ------------------
  |  |   72|  10.8k|    ssl_Trace b
  ------------------
 3057|       |
 3058|  10.8k|    if (buf->len != 2) {
  ------------------
  |  Branch (3058:9): [True: 74, False: 10.8k]
  ------------------
 3059|     74|        (void)ssl3_DecodeError(ss);
 3060|     74|        PORT_SetError(SSL_ERROR_RX_MALFORMED_ALERT);
  ------------------
  |  |   65|     74|#define PORT_SetError PORT_SetError_Util
  ------------------
 3061|     74|        return SECFailure;
 3062|     74|    }
 3063|  10.8k|    level = (SSL3AlertLevel)buf->buf[0];
 3064|  10.8k|    desc = (SSL3AlertDescription)buf->buf[1];
 3065|  10.8k|    buf->len = 0;
 3066|  10.8k|    SSL_TRC(5, ("%d: SSL3[%d] received alert, level = %d, description = %d",
  ------------------
  |  |   71|  10.8k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 10.8k]
  |  |  ------------------
  |  |   72|  10.8k|    ssl_Trace b
  ------------------
 3067|  10.8k|                SSL_GETPID(), ss->fd, level, desc));
 3068|       |
 3069|  10.8k|    if (ss->alertReceivedCallback) {
  ------------------
  |  Branch (3069:9): [True: 0, False: 10.8k]
  ------------------
 3070|      0|        SSLAlert alert = { level, desc };
 3071|      0|        ss->alertReceivedCallback(ss->fd, ss->alertReceivedCallbackArg, &alert);
 3072|      0|    }
 3073|       |
 3074|  10.8k|    switch (desc) {
 3075|      5|        case close_notify:
  ------------------
  |  Branch (3075:9): [True: 5, False: 10.8k]
  ------------------
 3076|      5|            ss->recvdCloseNotify = 1;
 3077|      5|            error = SSL_ERROR_CLOSE_NOTIFY_ALERT;
 3078|      5|            break;
 3079|    225|        case unexpected_message:
  ------------------
  |  Branch (3079:9): [True: 225, False: 10.5k]
  ------------------
 3080|    225|            error = SSL_ERROR_HANDSHAKE_UNEXPECTED_ALERT;
 3081|    225|            break;
 3082|    226|        case bad_record_mac:
  ------------------
  |  Branch (3082:9): [True: 226, False: 10.5k]
  ------------------
 3083|    226|            error = SSL_ERROR_BAD_MAC_ALERT;
 3084|    226|            break;
 3085|    284|        case decryption_failed_RESERVED:
  ------------------
  |  Branch (3085:9): [True: 284, False: 10.5k]
  ------------------
 3086|    284|            error = SSL_ERROR_DECRYPTION_FAILED_ALERT;
 3087|    284|            break;
 3088|    241|        case record_overflow:
  ------------------
  |  Branch (3088:9): [True: 241, False: 10.5k]
  ------------------
 3089|    241|            error = SSL_ERROR_RECORD_OVERFLOW_ALERT;
 3090|    241|            break;
 3091|    207|        case decompression_failure:
  ------------------
  |  Branch (3091:9): [True: 207, False: 10.6k]
  ------------------
 3092|    207|            error = SSL_ERROR_DECOMPRESSION_FAILURE_ALERT;
 3093|    207|            break;
 3094|    270|        case handshake_failure:
  ------------------
  |  Branch (3094:9): [True: 270, False: 10.5k]
  ------------------
 3095|    270|            error = SSL_ERROR_HANDSHAKE_FAILURE_ALERT;
 3096|    270|            break;
 3097|  1.16k|        case no_certificate:
  ------------------
  |  Branch (3097:9): [True: 1.16k, False: 9.64k]
  ------------------
 3098|  1.16k|            error = SSL_ERROR_NO_CERTIFICATE;
 3099|  1.16k|            break;
 3100|    198|        case certificate_required:
  ------------------
  |  Branch (3100:9): [True: 198, False: 10.6k]
  ------------------
 3101|    198|            error = SSL_ERROR_RX_CERTIFICATE_REQUIRED_ALERT;
 3102|    198|            break;
 3103|    195|        case bad_certificate:
  ------------------
  |  Branch (3103:9): [True: 195, False: 10.6k]
  ------------------
 3104|    195|            error = SSL_ERROR_BAD_CERT_ALERT;
 3105|    195|            break;
 3106|    206|        case unsupported_certificate:
  ------------------
  |  Branch (3106:9): [True: 206, False: 10.6k]
  ------------------
 3107|    206|            error = SSL_ERROR_UNSUPPORTED_CERT_ALERT;
 3108|    206|            break;
 3109|    353|        case certificate_revoked:
  ------------------
  |  Branch (3109:9): [True: 353, False: 10.4k]
  ------------------
 3110|    353|            error = SSL_ERROR_REVOKED_CERT_ALERT;
 3111|    353|            break;
 3112|    220|        case certificate_expired:
  ------------------
  |  Branch (3112:9): [True: 220, False: 10.5k]
  ------------------
 3113|    220|            error = SSL_ERROR_EXPIRED_CERT_ALERT;
 3114|    220|            break;
 3115|    198|        case certificate_unknown:
  ------------------
  |  Branch (3115:9): [True: 198, False: 10.6k]
  ------------------
 3116|    198|            error = SSL_ERROR_CERTIFICATE_UNKNOWN_ALERT;
 3117|    198|            break;
 3118|    278|        case illegal_parameter:
  ------------------
  |  Branch (3118:9): [True: 278, False: 10.5k]
  ------------------
 3119|    278|            error = SSL_ERROR_ILLEGAL_PARAMETER_ALERT;
 3120|    278|            break;
 3121|    215|        case inappropriate_fallback:
  ------------------
  |  Branch (3121:9): [True: 215, False: 10.6k]
  ------------------
 3122|    215|            error = SSL_ERROR_INAPPROPRIATE_FALLBACK_ALERT;
 3123|    215|            break;
 3124|       |
 3125|       |        /* All alerts below are TLS only. */
 3126|    213|        case unknown_ca:
  ------------------
  |  Branch (3126:9): [True: 213, False: 10.6k]
  ------------------
 3127|    213|            error = SSL_ERROR_UNKNOWN_CA_ALERT;
 3128|    213|            break;
 3129|    308|        case access_denied:
  ------------------
  |  Branch (3129:9): [True: 308, False: 10.5k]
  ------------------
 3130|    308|            error = SSL_ERROR_ACCESS_DENIED_ALERT;
 3131|    308|            break;
 3132|    198|        case decode_error:
  ------------------
  |  Branch (3132:9): [True: 198, False: 10.6k]
  ------------------
 3133|    198|            error = SSL_ERROR_DECODE_ERROR_ALERT;
 3134|    198|            break;
 3135|    205|        case decrypt_error:
  ------------------
  |  Branch (3135:9): [True: 205, False: 10.6k]
  ------------------
 3136|    205|            error = SSL_ERROR_DECRYPT_ERROR_ALERT;
 3137|    205|            break;
 3138|    231|        case export_restriction:
  ------------------
  |  Branch (3138:9): [True: 231, False: 10.5k]
  ------------------
 3139|    231|            error = SSL_ERROR_EXPORT_RESTRICTION_ALERT;
 3140|    231|            break;
 3141|    196|        case protocol_version:
  ------------------
  |  Branch (3141:9): [True: 196, False: 10.6k]
  ------------------
 3142|    196|            error = SSL_ERROR_PROTOCOL_VERSION_ALERT;
 3143|    196|            break;
 3144|    205|        case insufficient_security:
  ------------------
  |  Branch (3144:9): [True: 205, False: 10.6k]
  ------------------
 3145|    205|            error = SSL_ERROR_INSUFFICIENT_SECURITY_ALERT;
 3146|    205|            break;
 3147|    212|        case internal_error:
  ------------------
  |  Branch (3147:9): [True: 212, False: 10.6k]
  ------------------
 3148|    212|            error = SSL_ERROR_INTERNAL_ERROR_ALERT;
 3149|    212|            break;
 3150|    430|        case user_canceled:
  ------------------
  |  Branch (3150:9): [True: 430, False: 10.3k]
  ------------------
 3151|    430|            error = SSL_ERROR_USER_CANCELED_ALERT;
 3152|    430|            break;
 3153|    311|        case no_renegotiation:
  ------------------
  |  Branch (3153:9): [True: 311, False: 10.5k]
  ------------------
 3154|    311|            error = SSL_ERROR_NO_RENEGOTIATION_ALERT;
 3155|    311|            break;
 3156|       |
 3157|       |        /* Alerts for TLS client hello extensions */
 3158|    196|        case missing_extension:
  ------------------
  |  Branch (3158:9): [True: 196, False: 10.6k]
  ------------------
 3159|    196|            error = SSL_ERROR_MISSING_EXTENSION_ALERT;
 3160|    196|            break;
 3161|    360|        case unsupported_extension:
  ------------------
  |  Branch (3161:9): [True: 360, False: 10.4k]
  ------------------
 3162|    360|            error = SSL_ERROR_UNSUPPORTED_EXTENSION_ALERT;
 3163|    360|            break;
 3164|    377|        case certificate_unobtainable:
  ------------------
  |  Branch (3164:9): [True: 377, False: 10.4k]
  ------------------
 3165|    377|            error = SSL_ERROR_CERTIFICATE_UNOBTAINABLE_ALERT;
 3166|    377|            break;
 3167|    203|        case unrecognized_name:
  ------------------
  |  Branch (3167:9): [True: 203, False: 10.6k]
  ------------------
 3168|    203|            error = SSL_ERROR_UNRECOGNIZED_NAME_ALERT;
 3169|    203|            break;
 3170|    250|        case bad_certificate_status_response:
  ------------------
  |  Branch (3170:9): [True: 250, False: 10.5k]
  ------------------
 3171|    250|            error = SSL_ERROR_BAD_CERT_STATUS_RESPONSE_ALERT;
 3172|    250|            break;
 3173|    214|        case bad_certificate_hash_value:
  ------------------
  |  Branch (3173:9): [True: 214, False: 10.6k]
  ------------------
 3174|    214|            error = SSL_ERROR_BAD_CERT_HASH_VALUE_ALERT;
 3175|    214|            break;
 3176|    319|        case no_application_protocol:
  ------------------
  |  Branch (3176:9): [True: 319, False: 10.4k]
  ------------------
 3177|    319|            error = SSL_ERROR_NEXT_PROTOCOL_NO_PROTOCOL;
 3178|    319|            break;
 3179|    337|        case ech_required:
  ------------------
  |  Branch (3179:9): [True: 337, False: 10.4k]
  ------------------
 3180|    337|            error = SSL_ERROR_ECH_REQUIRED_ALERT;
 3181|    337|            break;
 3182|  1.56k|        default:
  ------------------
  |  Branch (3182:9): [True: 1.56k, False: 9.25k]
  ------------------
 3183|  1.56k|            error = SSL_ERROR_RX_UNKNOWN_ALERT;
 3184|  1.56k|            break;
 3185|  10.8k|    }
 3186|  10.8k|    if ((ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) &&
  ------------------
  |  |   21|  10.8k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (3186:9): [True: 200, False: 10.6k]
  ------------------
 3187|  10.8k|        (ss->ssl3.hs.ws != wait_server_hello)) {
  ------------------
  |  Branch (3187:9): [True: 200, False: 0]
  ------------------
 3188|       |        /* TLS 1.3 requires all but "end of data" alerts to be
 3189|       |         * treated as fatal. */
 3190|    200|        switch (desc) {
 3191|      1|            case close_notify:
  ------------------
  |  Branch (3191:13): [True: 1, False: 199]
  ------------------
 3192|    195|            case user_canceled:
  ------------------
  |  Branch (3192:13): [True: 194, False: 6]
  ------------------
 3193|    195|                break;
 3194|      5|            default:
  ------------------
  |  Branch (3194:13): [True: 5, False: 195]
  ------------------
 3195|      5|                level = alert_fatal;
 3196|    200|        }
 3197|    200|    }
 3198|  10.8k|    if (level == alert_fatal) {
  ------------------
  |  Branch (3198:9): [True: 16, False: 10.8k]
  ------------------
 3199|     16|        ssl_UncacheSessionID(ss);
 3200|     16|        if ((ss->ssl3.hs.ws == wait_server_hello) &&
  ------------------
  |  Branch (3200:13): [True: 0, False: 16]
  ------------------
 3201|     16|            (desc == handshake_failure)) {
  ------------------
  |  Branch (3201:13): [True: 0, False: 0]
  ------------------
 3202|       |            /* XXX This is a hack.  We're assuming that any handshake failure
 3203|       |             * XXX on the client hello is a failure to match ciphers.
 3204|       |             */
 3205|      0|            error = SSL_ERROR_NO_CYPHER_OVERLAP;
 3206|      0|        }
 3207|     16|        PORT_SetError(error);
  ------------------
  |  |   65|     16|#define PORT_SetError PORT_SetError_Util
  ------------------
 3208|     16|        return SECFailure;
 3209|     16|    }
 3210|  10.8k|    if ((desc == no_certificate) && (ss->ssl3.hs.ws == wait_client_cert)) {
  ------------------
  |  Branch (3210:9): [True: 1.16k, False: 9.63k]
  |  Branch (3210:37): [True: 362, False: 807]
  ------------------
 3211|       |        /* I'm a server. I've requested a client cert. He hasn't got one. */
 3212|    362|        SECStatus rv;
 3213|       |
 3214|    362|        PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|    362|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    362|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 362, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3215|    362|        ss->ssl3.hs.ws = wait_client_key;
 3216|    362|        rv = ssl3_HandleNoCertificate(ss);
 3217|    362|        return rv;
 3218|    362|    }
 3219|  10.4k|    return SECSuccess;
 3220|  10.8k|}
ssl3con.c:ssl3_HandleHandshake:
12872|   359k|{
12873|   359k|    sslBuffer buf = *origBuf; /* Work from a copy. */
12874|   359k|    SECStatus rv;
12875|       |
12876|   359k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   359k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   543k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 174k, False: 184k]
  |  |  |  |  |  Branch (208:7): [True: 184k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12877|   359k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   359k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   543k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 174k, False: 184k]
  |  |  |  |  |  Branch (208:7): [True: 184k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12878|       |
12879|  1.92M|    while (buf.len > 0) {
  ------------------
  |  Branch (12879:12): [True: 1.60M, False: 320k]
  ------------------
12880|  1.60M|        if (ss->ssl3.hs.header_bytes < 4) {
  ------------------
  |  Branch (12880:13): [True: 1.28M, False: 320k]
  ------------------
12881|  1.28M|            PRUint8 t;
12882|  1.28M|            t = *(buf.buf++);
12883|  1.28M|            buf.len--;
12884|  1.28M|            if (ss->ssl3.hs.header_bytes++ == 0)
  ------------------
  |  Branch (12884:17): [True: 320k, False: 961k]
  ------------------
12885|   320k|                ss->ssl3.hs.msg_type = (SSLHandshakeType)t;
12886|   961k|            else
12887|   961k|                ss->ssl3.hs.msg_len = (ss->ssl3.hs.msg_len << 8) + t;
12888|  1.28M|            if (ss->ssl3.hs.header_bytes < 4)
  ------------------
  |  Branch (12888:17): [True: 962k, False: 320k]
  ------------------
12889|   962k|                continue;
12890|       |
12891|   320k|#define MAX_HANDSHAKE_MSG_LEN 0x1ffff /* 128k - 1 */
12892|   320k|            if (ss->ssl3.hs.msg_len > MAX_HANDSHAKE_MSG_LEN) {
  ------------------
  |  |12891|   320k|#define MAX_HANDSHAKE_MSG_LEN 0x1ffff /* 128k - 1 */
  ------------------
  |  Branch (12892:17): [True: 124, False: 320k]
  ------------------
12893|    124|                (void)ssl3_DecodeError(ss);
12894|    124|                PORT_SetError(SSL_ERROR_RX_MALFORMED_HANDSHAKE);
  ------------------
  |  |   65|    124|#define PORT_SetError PORT_SetError_Util
  ------------------
12895|    124|                goto loser;
12896|    124|            }
12897|   320k|#undef MAX_HANDSHAKE_MSG_LEN
12898|       |
12899|       |            /* If msg_len is zero, be sure we fall through,
12900|       |            ** even if buf.len is zero.
12901|       |            */
12902|   320k|            if (ss->ssl3.hs.msg_len > 0)
  ------------------
  |  Branch (12902:17): [True: 284k, False: 35.6k]
  ------------------
12903|   284k|                continue;
12904|   320k|        }
12905|       |
12906|       |        /*
12907|       |         * Header has been gathered and there is at least one byte of new
12908|       |         * data available for this message. If it can be done right out
12909|       |         * of the original buffer, then use it from there.
12910|       |         */
12911|   355k|        if (ss->ssl3.hs.msg_body.len == 0 && buf.len >= ss->ssl3.hs.msg_len) {
  ------------------
  |  Branch (12911:13): [True: 320k, False: 35.3k]
  |  Branch (12911:46): [True: 310k, False: 10.2k]
  ------------------
12912|       |            /* handle it from input buffer */
12913|   310k|            rv = ssl3_HandleHandshakeMessage(ss, buf.buf, ss->ssl3.hs.msg_len,
12914|   310k|                                             buf.len == ss->ssl3.hs.msg_len);
12915|   310k|            buf.buf += ss->ssl3.hs.msg_len;
12916|   310k|            buf.len -= ss->ssl3.hs.msg_len;
12917|   310k|            ss->ssl3.hs.msg_len = 0;
12918|   310k|            ss->ssl3.hs.header_bytes = 0;
12919|   310k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (12919:17): [True: 1.84k, False: 308k]
  ------------------
12920|  1.84k|                goto loser;
12921|  1.84k|            }
12922|   310k|        } else {
12923|       |            /* must be copied to msg_body and dealt with from there */
12924|  45.6k|            unsigned int bytes;
12925|       |
12926|  45.6k|            PORT_Assert(ss->ssl3.hs.msg_body.len < ss->ssl3.hs.msg_len);
  ------------------
  |  |  120|  45.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  45.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 45.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12927|  45.6k|            bytes = PR_MIN(buf.len, ss->ssl3.hs.msg_len - ss->ssl3.hs.msg_body.len);
  ------------------
  |  |  158|  45.6k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 35.6k, False: 9.95k]
  |  |  ------------------
  ------------------
12928|       |
12929|       |            /* Grow the buffer if needed */
12930|  45.6k|            rv = sslBuffer_Grow(&ss->ssl3.hs.msg_body, ss->ssl3.hs.msg_len);
12931|  45.6k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (12931:17): [True: 0, False: 45.6k]
  ------------------
12932|       |                /* sslBuffer_Grow has set a memory error code. */
12933|      0|                goto loser;
12934|      0|            }
12935|       |
12936|  45.6k|            PORT_Memcpy(ss->ssl3.hs.msg_body.buf + ss->ssl3.hs.msg_body.len,
  ------------------
  |  |  180|  45.6k|#define PORT_Memcpy memcpy
  ------------------
12937|  45.6k|                        buf.buf, bytes);
12938|  45.6k|            ss->ssl3.hs.msg_body.len += bytes;
12939|  45.6k|            buf.buf += bytes;
12940|  45.6k|            buf.len -= bytes;
12941|       |
12942|  45.6k|            PORT_Assert(ss->ssl3.hs.msg_body.len <= ss->ssl3.hs.msg_len);
  ------------------
  |  |  120|  45.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  45.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 45.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12943|       |
12944|       |            /* if we have a whole message, do it */
12945|  45.6k|            if (ss->ssl3.hs.msg_body.len == ss->ssl3.hs.msg_len) {
  ------------------
  |  Branch (12945:17): [True: 9.95k, False: 35.6k]
  ------------------
12946|  9.95k|                rv = ssl3_HandleHandshakeMessage(
12947|  9.95k|                    ss, ss->ssl3.hs.msg_body.buf, ss->ssl3.hs.msg_len,
12948|  9.95k|                    buf.len == 0);
12949|  9.95k|                ss->ssl3.hs.msg_body.len = 0;
12950|  9.95k|                ss->ssl3.hs.msg_len = 0;
12951|  9.95k|                ss->ssl3.hs.header_bytes = 0;
12952|  9.95k|                if (rv != SECSuccess) {
  ------------------
  |  Branch (12952:21): [True: 766, False: 9.19k]
  ------------------
12953|    766|                    goto loser;
12954|    766|                }
12955|  35.6k|            } else {
12956|  35.6k|                PORT_Assert(buf.len == 0);
  ------------------
  |  |  120|  35.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  35.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 35.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12957|  35.6k|                break;
12958|  35.6k|            }
12959|  45.6k|        }
12960|   355k|    } /* end loop */
12961|       |
12962|   356k|    origBuf->len = 0; /* So ssl3_GatherAppDataRecord will keep looping. */
12963|   356k|    return SECSuccess;
12964|       |
12965|  2.73k|loser : {
12966|       |    /* Make sure to remove any data that was consumed. */
12967|  2.73k|    unsigned int consumed = origBuf->len - buf.len;
12968|  2.73k|    PORT_Assert(consumed == buf.buf - origBuf->buf);
  ------------------
  |  |  120|  2.73k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.73k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.73k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
12969|  2.73k|    if (consumed > 0) {
  ------------------
  |  Branch (12969:9): [True: 2.73k, False: 0]
  ------------------
12970|  2.73k|        memmove(origBuf->buf, origBuf->buf + consumed, buf.len);
12971|  2.73k|        origBuf->len = buf.len;
12972|  2.73k|    }
12973|  2.73k|}
12974|  2.73k|    return SECFailure;
12975|   359k|}
ssl3con.c:ssl3_GetCipherSpec:
13495|   582k|{
13496|   582k|    ssl3CipherSpec *crSpec = ss->ssl3.crSpec;
13497|   582k|    ssl3CipherSpec *newSpec = NULL;
13498|   582k|    DTLSEpoch epoch;
13499|       |
13500|   582k|    if (!IS_DTLS(ss)) {
  ------------------
  |  |  892|   582k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (13500:9): [True: 582k, False: 0]
  ------------------
13501|   582k|        return crSpec;
13502|   582k|    }
13503|      0|    epoch = dtls_ReadEpoch(crSpec->version, crSpec->epoch, cText->hdr);
13504|      0|    if (crSpec->epoch == epoch) {
  ------------------
  |  Branch (13504:9): [True: 0, False: 0]
  ------------------
13505|      0|        return crSpec;
13506|      0|    }
13507|      0|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (13507:9): [True: 0, False: 0]
  ------------------
13508|       |        /* Try to find the cipher spec. */
13509|      0|        newSpec = ssl_FindCipherSpecByEpoch(ss, ssl_secret_read,
13510|      0|                                            epoch);
13511|      0|        if (newSpec != NULL) {
  ------------------
  |  Branch (13511:13): [True: 0, False: 0]
  ------------------
13512|      0|            return newSpec;
13513|      0|        }
13514|      0|    }
13515|      0|    SSL_TRC(10, ("%d: DTLS[%d]: %s couldn't find cipherspec from epoch %d",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
13516|      0|                 SSL_GETPID(), ss->fd, SSL_ROLE(ss), epoch));
13517|      0|    return NULL;
13518|      0|}

ssl_NamedGroup2ECParams:
   37|  18.9k|{
   38|  18.9k|    SECOidData *oidData = NULL;
   39|       |
   40|  18.9k|    if (!params) {
  ------------------
  |  Branch (40:9): [True: 0, False: 18.9k]
  ------------------
   41|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   42|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   43|      0|        return SECFailure;
   44|      0|    }
   45|       |
   46|  18.9k|    if (!ecGroup || ecGroup->keaType != ssl_kea_ecdh ||
  ------------------
  |  Branch (46:9): [True: 0, False: 18.9k]
  |  Branch (46:21): [True: 0, False: 18.9k]
  ------------------
   47|  18.9k|        (oidData = SECOID_FindOIDByTag(ecGroup->oidTag)) == NULL) {
  ------------------
  |  |  116|  18.9k|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
  |  Branch (47:9): [True: 0, False: 18.9k]
  ------------------
   48|      0|        PORT_SetError(SEC_ERROR_UNSUPPORTED_ELLIPTIC_CURVE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   49|      0|        return SECFailure;
   50|      0|    }
   51|       |
   52|  18.9k|    if (SECITEM_AllocItem(arena, params, (2 + oidData->oid.len)) == NULL) {
  ------------------
  |  |  103|  18.9k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (52:9): [True: 0, False: 18.9k]
  ------------------
   53|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   54|      0|        return SECFailure;
   55|      0|    }
   56|       |
   57|       |    /*
   58|       |     * params->data needs to contain the ASN encoding of an object ID (OID)
   59|       |     * representing the named curve. The actual OID is in
   60|       |     * oidData->oid.data so we simply prepend 0x06 and OID length
   61|       |     */
   62|  18.9k|    params->data[0] = SEC_ASN1_OBJECT_ID;
  ------------------
  |  |   82|  18.9k|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
   63|  18.9k|    params->data[1] = oidData->oid.len;
   64|  18.9k|    memcpy(params->data + 2, oidData->oid.data, oidData->oid.len);
   65|       |
   66|  18.9k|    return SECSuccess;
   67|  18.9k|}
ssl_ECPubKey2NamedGroup:
   71|  17.9k|{
   72|  17.9k|    SECItem oid = { siBuffer, NULL, 0 };
   73|  17.9k|    SECOidData *oidData = NULL;
   74|  17.9k|    PRUint32 policyFlags = 0;
   75|  17.9k|    unsigned int i;
   76|  17.9k|    const SECKEYECParams *params;
   77|       |
   78|  17.9k|    if (pubKey->keyType != ecKey) {
  ------------------
  |  Branch (78:9): [True: 0, False: 17.9k]
  ------------------
   79|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   80|      0|        return NULL;
   81|      0|    }
   82|       |
   83|  17.9k|    params = &pubKey->u.ec.DEREncodedParams;
   84|       |
   85|       |    /*
   86|       |     * params->data needs to contain the ASN encoding of an object ID (OID)
   87|       |     * representing a named curve. Here, we strip away everything
   88|       |     * before the actual OID and use the OID to look up a named curve.
   89|       |     */
   90|  17.9k|    if (params->data[0] != SEC_ASN1_OBJECT_ID)
  ------------------
  |  |   82|  17.9k|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
  |  Branch (90:9): [True: 0, False: 17.9k]
  ------------------
   91|      0|        return NULL;
   92|  17.9k|    oid.len = params->len - 2;
   93|  17.9k|    oid.data = params->data + 2;
   94|  17.9k|    if ((oidData = SECOID_FindOID(&oid)) == NULL)
  ------------------
  |  |  115|  17.9k|#define SECOID_FindOID SECOID_FindOID_Util
  ------------------
  |  Branch (94:9): [True: 0, False: 17.9k]
  ------------------
   95|      0|        return NULL;
   96|  17.9k|    if ((NSS_GetAlgorithmPolicy(oidData->offset, &policyFlags) ==
  ------------------
  |  Branch (96:9): [True: 17.9k, False: 0]
  ------------------
   97|  17.9k|         SECSuccess) &&
   98|  17.9k|        !(policyFlags & NSS_USE_ALG_IN_SSL_KX)) {
  ------------------
  |  |  572|  17.9k|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
  |  Branch (98:9): [True: 0, False: 17.9k]
  ------------------
   99|      0|        return NULL;
  100|      0|    }
  101|  31.2k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  31.2k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (101:17): [True: 31.2k, False: 0]
  ------------------
  102|  31.2k|        if (ssl_named_groups[i].oidTag == oidData->offset) {
  ------------------
  |  Branch (102:13): [True: 17.9k, False: 13.3k]
  ------------------
  103|  17.9k|            return &ssl_named_groups[i];
  104|  17.9k|        }
  105|  31.2k|    }
  106|       |
  107|      0|    return NULL;
  108|  17.9k|}
ssl3_HandleECDHClientKeyExchange:
  260|  16.9k|{
  261|  16.9k|    PK11SymKey *pms;
  262|  16.9k|    SECStatus rv;
  263|  16.9k|    SECKEYPublicKey clntPubKey;
  264|  16.9k|    CK_MECHANISM_TYPE target;
  265|  16.9k|    PRBool isTLS, isTLS12;
  266|  16.9k|    int errCode = SSL_ERROR_RX_MALFORMED_CLIENT_KEY_EXCH;
  267|       |
  268|  16.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  16.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  24.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.06k, False: 7.84k]
  |  |  |  |  |  Branch (208:7): [True: 7.84k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  269|  16.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  16.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  24.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.06k, False: 7.84k]
  |  |  |  |  |  Branch (208:7): [True: 7.84k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  270|       |
  271|  16.9k|    clntPubKey.keyType = ecKey;
  272|  16.9k|    clntPubKey.u.ec.DEREncodedParams.len =
  273|  16.9k|        serverKeyPair->pubKey->u.ec.DEREncodedParams.len;
  274|  16.9k|    clntPubKey.u.ec.DEREncodedParams.data =
  275|  16.9k|        serverKeyPair->pubKey->u.ec.DEREncodedParams.data;
  276|  16.9k|    clntPubKey.u.ec.encoding = ECPoint_Undefined;
  277|       |
  278|  16.9k|    rv = ssl3_ConsumeHandshakeVariable(ss, &clntPubKey.u.ec.publicValue,
  279|  16.9k|                                       1, &b, &length);
  280|  16.9k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (280:9): [True: 7, False: 16.9k]
  ------------------
  281|      7|        PORT_SetError(errCode);
  ------------------
  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  ------------------
  282|      7|        return SECFailure;
  283|      7|    }
  284|       |
  285|       |    /* we have to catch the case when the client's public key has length 0. */
  286|  16.9k|    if (!clntPubKey.u.ec.publicValue.len) {
  ------------------
  |  Branch (286:9): [True: 3, False: 16.9k]
  ------------------
  287|      3|        (void)SSL3_SendAlert(ss, alert_fatal, illegal_parameter);
  288|      3|        PORT_SetError(errCode);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
  289|      3|        return SECFailure;
  290|      3|    }
  291|       |
  292|  16.9k|    isTLS = (PRBool)(ss->ssl3.prSpec->version > SSL_LIBRARY_VERSION_3_0);
  ------------------
  |  |   17|  16.9k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  293|  16.9k|    isTLS12 = (PRBool)(ss->ssl3.prSpec->version >= SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |   20|  16.9k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  294|       |
  295|  16.9k|    if (isTLS12) {
  ------------------
  |  Branch (295:9): [True: 15.2k, False: 1.60k]
  ------------------
  296|  15.2k|        target = CKM_TLS12_MASTER_KEY_DERIVE_DH;
  ------------------
  |  | 1028|  15.2k|#define CKM_TLS12_MASTER_KEY_DERIVE_DH 0x000003E2UL
  ------------------
  297|  15.2k|    } else if (isTLS) {
  ------------------
  |  Branch (297:16): [True: 1.60k, False: 0]
  ------------------
  298|  1.60k|        target = CKM_TLS_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  970|  1.60k|#define CKM_TLS_MASTER_KEY_DERIVE_DH 0x00000377UL
  ------------------
  299|  1.60k|    } else {
  300|      0|        target = CKM_SSL3_MASTER_KEY_DERIVE_DH;
  ------------------
  |  |  966|      0|#define CKM_SSL3_MASTER_KEY_DERIVE_DH 0x00000373UL
  ------------------
  301|      0|    }
  302|       |
  303|       |    /*  Determine the PMS */
  304|  16.9k|    pms = PK11_PubDeriveWithKDF(serverKeyPair->privKey, &clntPubKey,
  305|  16.9k|                                PR_FALSE, NULL, NULL,
  ------------------
  |  |  438|  16.9k|#define PR_FALSE 0
  ------------------
  306|  16.9k|                                CKM_ECDH1_DERIVE, target, CKA_DERIVE, 0,
  ------------------
  |  | 1086|  16.9k|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
                                              CKM_ECDH1_DERIVE, target, CKA_DERIVE, 0,
  ------------------
  |  |  555|  16.9k|#define CKA_DERIVE 0x0000010CUL
  ------------------
  307|  16.9k|                                CKD_NULL, NULL, NULL);
  ------------------
  |  | 1702|  16.9k|#define CKD_NULL 0x00000001UL
  ------------------
  308|       |
  309|  16.9k|    if (pms == NULL) {
  ------------------
  |  Branch (309:9): [True: 227, False: 16.6k]
  ------------------
  310|       |        /* last gasp.  */
  311|    227|        errCode = ssl_MapLowLevelError(SSL_ERROR_CLIENT_KEY_EXCHANGE_FAILURE);
  312|    227|        PORT_SetError(errCode);
  ------------------
  |  |   65|    227|#define PORT_SetError PORT_SetError_Util
  ------------------
  313|    227|        return SECFailure;
  314|    227|    }
  315|       |
  316|  16.6k|    rv = ssl3_InitPendingCipherSpecs(ss, pms, PR_TRUE);
  ------------------
  |  |  437|  16.6k|#define PR_TRUE 1
  ------------------
  317|  16.6k|    PK11_FreeSymKey(pms);
  318|  16.6k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (318:9): [True: 0, False: 16.6k]
  ------------------
  319|       |        /* error code set by ssl3_InitPendingCipherSpec */
  320|      0|        return SECFailure;
  321|      0|    }
  322|  16.6k|    ss->sec.keaGroup = ssl_ECPubKey2NamedGroup(&clntPubKey);
  323|  16.6k|    return SECSuccess;
  324|  16.6k|}
ssl_ImportECDHKeyShare:
  333|    696|{
  334|    696|    SECStatus rv;
  335|    696|    SECItem ecPoint = { siBuffer, NULL, 0 };
  336|       |
  337|    696|    if (!length) {
  ------------------
  |  Branch (337:9): [True: 1, False: 695]
  ------------------
  338|      1|        PORT_SetError(SSL_ERROR_RX_MALFORMED_ECDHE_KEY_SHARE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  339|      1|        return SECFailure;
  340|      1|    }
  341|       |
  342|       |    /* Fail if the ec point uses compressed representation */
  343|    695|    if (b[0] != EC_POINT_FORM_UNCOMPRESSED &&
  ------------------
  |  |   92|  1.39k|#define EC_POINT_FORM_UNCOMPRESSED 0x04
  ------------------
  |  Branch (343:9): [True: 690, False: 5]
  ------------------
  344|    695|        ecGroup->name != ssl_grp_ec_curve25519) {
  ------------------
  |  Branch (344:9): [True: 5, False: 685]
  ------------------
  345|      5|        PORT_SetError(SEC_ERROR_UNSUPPORTED_EC_POINT_FORM);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
  346|      5|        return SECFailure;
  347|      5|    }
  348|       |
  349|    690|    peerKey->keyType = ecKey;
  350|       |    /* Set up the encoded params */
  351|    690|    rv = ssl_NamedGroup2ECParams(peerKey->arena, ecGroup,
  352|    690|                                 &peerKey->u.ec.DEREncodedParams);
  353|    690|    if (rv != SECSuccess) {
  ------------------
  |  Branch (353:9): [True: 0, False: 690]
  ------------------
  354|      0|        ssl_MapLowLevelError(SSL_ERROR_RX_MALFORMED_ECDHE_KEY_SHARE);
  355|      0|        return SECFailure;
  356|      0|    }
  357|    690|    peerKey->u.ec.encoding = ECPoint_Undefined;
  358|       |
  359|       |    /* copy publicValue in peerKey */
  360|    690|    ecPoint.data = b;
  361|    690|    ecPoint.len = length;
  362|       |
  363|    690|    rv = SECITEM_CopyItem(peerKey->arena, &peerKey->u.ec.publicValue, &ecPoint);
  ------------------
  |  |  106|    690|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  364|    690|    if (rv != SECSuccess) {
  ------------------
  |  Branch (364:9): [True: 0, False: 690]
  ------------------
  365|      0|        return SECFailure;
  366|      0|    }
  367|       |
  368|    690|    return SECSuccess;
  369|    690|}
ssl_GetECGroupWithStrength:
  373|  17.5k|{
  374|  17.5k|    int i;
  375|       |
  376|  17.5k|    PORT_Assert(ss);
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  377|       |
  378|  30.7k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  30.7k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (378:17): [True: 30.7k, False: 7]
  ------------------
  379|  30.7k|        const sslNamedGroupDef *group = ss->namedGroupPreferences[i];
  380|  30.7k|        if (group && group->keaType == ssl_kea_ecdh &&
  ------------------
  |  Branch (380:13): [True: 17.5k, False: 13.1k]
  |  Branch (380:22): [True: 17.5k, False: 18]
  ------------------
  381|  30.7k|            group->bits >= requiredECCbits) {
  ------------------
  |  Branch (381:13): [True: 17.5k, False: 0]
  ------------------
  382|  17.5k|            return group;
  383|  17.5k|        }
  384|  30.7k|    }
  385|       |
  386|      7|    PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  ------------------
  387|      7|    return NULL;
  388|  17.5k|}
ssl_GetECGroupForServerSocket:
  394|  17.5k|{
  395|  17.5k|    const sslServerCert *cert = ss->sec.serverCert;
  396|  17.5k|    unsigned int certKeySize;
  397|  17.5k|    const ssl3BulkCipherDef *bulkCipher;
  398|  17.5k|    unsigned int requiredECCbits;
  399|       |
  400|  17.5k|    PORT_Assert(cert);
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  401|  17.5k|    if (!cert || !cert->serverKeyPair || !cert->serverKeyPair->pubKey) {
  ------------------
  |  Branch (401:9): [True: 0, False: 17.5k]
  |  Branch (401:18): [True: 0, False: 17.5k]
  |  Branch (401:42): [True: 0, False: 17.5k]
  ------------------
  402|      0|        PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  403|      0|        return NULL;
  404|      0|    }
  405|       |
  406|  17.5k|    if (SSL_CERT_IS(cert, ssl_auth_rsa_sign) ||
  ------------------
  |  |   53|  35.1k|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  |  |  ------------------
  |  |  |  Branch (53:27): [True: 5.94k, False: 11.6k]
  |  |  ------------------
  ------------------
  407|  17.5k|        SSL_CERT_IS(cert, ssl_auth_rsa_pss)) {
  ------------------
  |  |   53|  11.6k|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  |  |  ------------------
  |  |  |  Branch (53:27): [True: 0, False: 11.6k]
  |  |  ------------------
  ------------------
  408|  5.94k|        certKeySize = SECKEY_PublicKeyStrengthInBits(cert->serverKeyPair->pubKey);
  409|  5.94k|        certKeySize = SSL_RSASTRENGTH_TO_ECSTRENGTH(certKeySize);
  ------------------
  |  | 1597|  5.94k|    ((s <= 1024) ? 160                                              \
  |  |  ------------------
  |  |  |  Branch (1597:6): [True: 0, False: 5.94k]
  |  |  ------------------
  |  | 1598|  5.94k|                 : ((s <= 2048) ? 224                               \
  |  |  ------------------
  |  |  |  Branch (1598:21): [True: 5.94k, False: 0]
  |  |  ------------------
  |  | 1599|  5.94k|                                : ((s <= 3072) ? 256                \
  |  |  ------------------
  |  |  |  Branch (1599:36): [True: 0, False: 0]
  |  |  ------------------
  |  | 1600|      0|                                               : ((s <= 7168) ? 384 \
  |  |  ------------------
  |  |  |  Branch (1600:51): [True: 0, False: 0]
  |  |  ------------------
  |  | 1601|      0|                                                              : 521))))
  ------------------
  410|  11.6k|    } else if (SSL_CERT_IS_EC(cert)) {
  ------------------
  |  |   56|  11.6k|    ((c)->authTypes & ((1 << ssl_auth_ecdsa) |    \
  |  |  ------------------
  |  |  |  Branch (56:5): [True: 11.6k, False: 0]
  |  |  ------------------
  |  |   57|  11.6k|                       (1 << ssl_auth_ecdh_rsa) | \
  |  |   58|  11.6k|                       (1 << ssl_auth_ecdh_ecdsa)))
  ------------------
  411|       |        /* We won't select a certificate unless the named curve has been
  412|       |         * negotiated (or supported_curves was absent), double check that. */
  413|  11.6k|        PORT_Assert(cert->namedCurve->keaType == ssl_kea_ecdh);
  ------------------
  |  |  120|  11.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  414|  11.6k|        PORT_Assert(ssl_NamedGroupEnabled(ss, cert->namedCurve));
  ------------------
  |  |  120|  11.6k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.6k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  415|  11.6k|        if (!ssl_NamedGroupEnabled(ss, cert->namedCurve)) {
  ------------------
  |  Branch (415:13): [True: 0, False: 11.6k]
  ------------------
  416|      0|            return NULL;
  417|      0|        }
  418|  11.6k|        certKeySize = cert->namedCurve->bits;
  419|  11.6k|    } else {
  420|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  421|      0|        return NULL;
  422|      0|    }
  423|  17.5k|    bulkCipher = ssl_GetBulkCipherDef(ss->ssl3.hs.suite_def);
  424|  17.5k|    requiredECCbits = bulkCipher->key_size * BPB * 2;
  ------------------
  |  |  122|  17.5k|#define BPB 8 /* Bits Per Byte */
  ------------------
  425|  17.5k|    PORT_Assert(requiredECCbits ||
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  20.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 14.7k, False: 2.84k]
  |  |  |  |  |  Branch (208:7): [True: 2.84k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  426|  17.5k|                ss->ssl3.hs.suite_def->bulk_cipher_alg == cipher_null);
  427|  17.5k|    if (requiredECCbits > certKeySize) {
  ------------------
  |  Branch (427:9): [True: 14.3k, False: 3.17k]
  ------------------
  428|  14.3k|        requiredECCbits = certKeySize;
  429|  14.3k|    }
  430|       |
  431|  17.5k|    return ssl_GetECGroupWithStrength(ss, requiredECCbits);
  432|  17.5k|}
ssl_CreateECDHEphemeralKeyPair:
  473|  18.2k|{
  474|  18.2k|    SECKEYPrivateKey *privKey = NULL;
  475|  18.2k|    SECKEYPublicKey *pubKey = NULL;
  476|  18.2k|    SECKEYECParams ecParams = { siBuffer, NULL, 0 };
  477|  18.2k|    sslEphemeralKeyPair *pair;
  478|       |
  479|  18.2k|    if (ssl_NamedGroup2ECParams(NULL, ecGroup, &ecParams) != SECSuccess) {
  ------------------
  |  Branch (479:9): [True: 0, False: 18.2k]
  ------------------
  480|      0|        return SECFailure;
  481|      0|    }
  482|  18.2k|    privKey = ssl_CreateECDHEPrivateKey(&ecParams, &pubKey, ss->pkcs11PinArg);
  483|  18.2k|    SECITEM_FreeItem(&ecParams, PR_FALSE);
  ------------------
  |  |  108|  18.2k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&ecParams, PR_FALSE);
  ------------------
  |  |  438|  18.2k|#define PR_FALSE 0
  ------------------
  484|       |
  485|  18.2k|    if (!privKey || !pubKey ||
  ------------------
  |  Branch (485:9): [True: 22, False: 18.2k]
  |  Branch (485:21): [True: 0, False: 18.2k]
  ------------------
  486|  18.2k|        !(pair = ssl_NewEphemeralKeyPair(ecGroup, privKey, pubKey))) {
  ------------------
  |  Branch (486:9): [True: 0, False: 18.2k]
  ------------------
  487|     22|        if (privKey) {
  ------------------
  |  Branch (487:13): [True: 0, False: 22]
  ------------------
  488|      0|            SECKEY_DestroyPrivateKey(privKey);
  489|      0|        }
  490|     22|        if (pubKey) {
  ------------------
  |  Branch (490:13): [True: 0, False: 22]
  ------------------
  491|      0|            SECKEY_DestroyPublicKey(pubKey);
  492|      0|        }
  493|     22|        ssl_MapLowLevelError(SEC_ERROR_KEYGEN_FAIL);
  494|     22|        return SECFailure;
  495|     22|    }
  496|       |
  497|  18.2k|    *keyPair = pair;
  498|  18.2k|    SSL_TRC(50, ("%d: SSL[%d]: Create ECDH ephemeral key %d",
  ------------------
  |  |   71|  18.2k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |   72|  18.2k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  499|  18.2k|                 SSL_GETPID(), ss ? ss->fd : NULL, ecGroup->name));
  500|  18.2k|    PRINT_BUF(50, (ss, "Public Key", pubKey->u.ec.publicValue.data,
  ------------------
  |  |   74|  18.2k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 18.2k]
  |  |  ------------------
  |  |   75|  18.2k|    ssl_PrintBuf b
  ------------------
  501|  18.2k|                   pubKey->u.ec.publicValue.len));
  502|  18.2k|#ifdef TRACE
  503|  18.2k|    if (ssl_trace >= 50) {
  ------------------
  |  Branch (503:9): [True: 0, False: 18.2k]
  ------------------
  504|      0|        SECItem d = { siBuffer, NULL, 0 };
  505|      0|        SECStatus rv = PK11_ReadRawAttribute(PK11_TypePrivKey, privKey,
  506|      0|                                             CKA_VALUE, &d);
  ------------------
  |  |  516|      0|#define CKA_VALUE 0x00000011UL
  ------------------
  507|      0|        if (rv == SECSuccess) {
  ------------------
  |  Branch (507:13): [True: 0, False: 0]
  ------------------
  508|      0|            PRINT_BUF(50, (ss, "Private Key", d.data, d.len));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
  509|      0|            SECITEM_FreeItem(&d, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(&d, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  510|      0|        } else {
  511|      0|            SSL_TRC(50, ("Error extracting private key"));
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  512|      0|        }
  513|      0|    }
  514|  18.2k|#endif
  515|  18.2k|    return SECSuccess;
  516|  18.2k|}
ssl3_SendECDHServerKeyExchange:
  676|  17.5k|{
  677|  17.5k|    SECStatus rv = SECFailure;
  678|  17.5k|    int length;
  679|  17.5k|    PRBool isTLS12;
  680|  17.5k|    SECItem signed_hash = { siBuffer, NULL, 0 };
  681|  17.5k|    SSLHashType hashAlg;
  682|  17.5k|    SSL3Hashes hashes;
  683|       |
  684|  17.5k|    SECItem ec_params = { siBuffer, NULL, 0 };
  685|  17.5k|    unsigned char paramBuf[3];
  686|  17.5k|    const sslNamedGroupDef *ecGroup;
  687|  17.5k|    sslEphemeralKeyPair *keyPair;
  688|  17.5k|    SECKEYPublicKey *pubKey;
  689|       |
  690|       |    /* Generate ephemeral ECDH key pair and send the public key */
  691|  17.5k|    ecGroup = ssl_GetECGroupForServerSocket(ss);
  692|  17.5k|    if (!ecGroup) {
  ------------------
  |  Branch (692:9): [True: 7, False: 17.5k]
  ------------------
  693|      7|        goto loser;
  694|      7|    }
  695|       |
  696|  17.5k|    PORT_Assert(PR_CLIST_IS_EMPTY(&ss->ephemeralKeyPairs));
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  697|  17.5k|    if (ss->opt.reuseServerECDHEKey) {
  ------------------
  |  Branch (697:9): [True: 0, False: 17.5k]
  ------------------
  698|      0|        rv = ssl_CreateStaticECDHEKey(ss, ecGroup);
  699|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (699:13): [True: 0, False: 0]
  ------------------
  700|      0|            goto loser;
  701|      0|        }
  702|      0|        keyPair = (sslEphemeralKeyPair *)PR_NEXT_LINK(&ss->ephemeralKeyPairs);
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  703|  17.5k|    } else {
  704|  17.5k|        rv = ssl_CreateECDHEphemeralKeyPair(ss, ecGroup, &keyPair);
  705|  17.5k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (705:13): [True: 0, False: 17.5k]
  ------------------
  706|      0|            goto loser;
  707|      0|        }
  708|  17.5k|        PR_APPEND_LINK(&keyPair->link, &ss->ephemeralKeyPairs);
  ------------------
  |  |   57|  17.5k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|  35.1k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|  17.5k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|  35.1k|    (_e)->next = (_l);   \
  |  |  |  |   27|  35.1k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|  35.1k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|  35.1k|    (_l)->prev = (_e);   \
  |  |  |  |   30|  35.1k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|  17.5k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  709|  17.5k|    }
  710|       |
  711|  17.5k|    PORT_Assert(keyPair);
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  712|  17.5k|    if (!keyPair) {
  ------------------
  |  Branch (712:9): [True: 0, False: 17.5k]
  ------------------
  713|      0|        PORT_SetError(SSL_ERROR_SERVER_KEY_EXCHANGE_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  714|      0|        return SECFailure;
  715|      0|    }
  716|       |
  717|  17.5k|    ec_params.len = sizeof(paramBuf);
  718|  17.5k|    ec_params.data = paramBuf;
  719|  17.5k|    PORT_Assert(keyPair->group);
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  720|  17.5k|    PORT_Assert(keyPair->group->keaType == ssl_kea_ecdh);
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  721|  17.5k|    ec_params.data[0] = ec_type_named;
  722|  17.5k|    ec_params.data[1] = keyPair->group->name >> 8;
  723|  17.5k|    ec_params.data[2] = keyPair->group->name & 0xff;
  724|       |
  725|  17.5k|    pubKey = keyPair->keys->pubKey;
  726|  17.5k|    if (ss->version == SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  17.5k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (726:9): [True: 15.8k, False: 1.66k]
  ------------------
  727|  15.8k|        hashAlg = ssl_SignatureSchemeToHashType(ss->ssl3.hs.signatureScheme);
  728|  15.8k|    } else {
  729|       |        /* Use ssl_hash_none to represent the MD5+SHA1 combo. */
  730|  1.66k|        hashAlg = ssl_hash_none;
  731|  1.66k|    }
  732|  17.5k|    rv = ssl3_ComputeECDHKeyHash(hashAlg, ec_params,
  733|  17.5k|                                 pubKey->u.ec.publicValue,
  734|  17.5k|                                 ss->ssl3.hs.client_random,
  735|  17.5k|                                 ss->ssl3.hs.server_random,
  736|  17.5k|                                 &hashes);
  737|  17.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (737:9): [True: 0, False: 17.5k]
  ------------------
  738|      0|        ssl_MapLowLevelError(SSL_ERROR_SERVER_KEY_EXCHANGE_FAILURE);
  739|      0|        goto loser;
  740|      0|    }
  741|       |
  742|  17.5k|    isTLS12 = (PRBool)(ss->version >= SSL_LIBRARY_VERSION_TLS_1_2);
  ------------------
  |  |   20|  17.5k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  743|       |
  744|  17.5k|    rv = ssl3_SignHashes(ss, &hashes,
  745|  17.5k|                         ss->sec.serverCert->serverKeyPair->privKey, &signed_hash);
  746|  17.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (746:9): [True: 0, False: 17.5k]
  ------------------
  747|      0|        goto loser; /* ssl3_SignHashes has set err. */
  748|      0|    }
  749|       |
  750|  17.5k|    length = ec_params.len +
  751|  17.5k|             1 + pubKey->u.ec.publicValue.len +
  752|  17.5k|             (isTLS12 ? 2 : 0) + 2 + signed_hash.len;
  ------------------
  |  Branch (752:15): [True: 15.8k, False: 1.66k]
  ------------------
  753|       |
  754|  17.5k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_server_key_exchange, length);
  755|  17.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (755:9): [True: 0, False: 17.5k]
  ------------------
  756|      0|        goto loser; /* err set by AppendHandshake. */
  757|      0|    }
  758|       |
  759|  17.5k|    rv = ssl3_AppendHandshake(ss, ec_params.data, ec_params.len);
  760|  17.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (760:9): [True: 0, False: 17.5k]
  ------------------
  761|      0|        goto loser; /* err set by AppendHandshake. */
  762|      0|    }
  763|       |
  764|  17.5k|    rv = ssl3_AppendHandshakeVariable(ss, pubKey->u.ec.publicValue.data,
  765|  17.5k|                                      pubKey->u.ec.publicValue.len, 1);
  766|  17.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (766:9): [True: 0, False: 17.5k]
  ------------------
  767|      0|        goto loser; /* err set by AppendHandshake. */
  768|      0|    }
  769|       |
  770|  17.5k|    if (isTLS12) {
  ------------------
  |  Branch (770:9): [True: 15.8k, False: 1.66k]
  ------------------
  771|  15.8k|        rv = ssl3_AppendHandshakeNumber(ss, ss->ssl3.hs.signatureScheme, 2);
  772|  15.8k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (772:13): [True: 0, False: 15.8k]
  ------------------
  773|      0|            goto loser; /* err set by AppendHandshake. */
  774|      0|        }
  775|  15.8k|    }
  776|       |
  777|  17.5k|    rv = ssl3_AppendHandshakeVariable(ss, signed_hash.data,
  778|  17.5k|                                      signed_hash.len, 2);
  779|  17.5k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (779:9): [True: 0, False: 17.5k]
  ------------------
  780|      0|        goto loser; /* err set by AppendHandshake. */
  781|      0|    }
  782|       |
  783|  17.5k|    PORT_Free(signed_hash.data);
  ------------------
  |  |   60|  17.5k|#define PORT_Free PORT_Free_Util
  ------------------
  784|  17.5k|    return SECSuccess;
  785|       |
  786|      7|loser:
  787|      7|    if (signed_hash.data != NULL)
  ------------------
  |  Branch (787:9): [True: 0, False: 7]
  ------------------
  788|      0|        PORT_Free(signed_hash.data);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  789|      7|    return SECFailure;
  790|  17.5k|}
ssl_IsECCEnabled:
  872|  7.00k|{
  873|  7.00k|    PK11SlotInfo *slot;
  874|       |
  875|       |    /* make sure we can do ECC */
  876|  7.00k|    slot = PK11_GetBestSlot(CKM_ECDH1_DERIVE, ss->pkcs11PinArg);
  ------------------
  |  | 1086|  7.00k|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  877|  7.00k|    if (!slot) {
  ------------------
  |  Branch (877:9): [True: 0, False: 7.00k]
  ------------------
  878|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  879|      0|    }
  880|  7.00k|    PK11_FreeSlot(slot);
  881|       |
  882|       |    /* make sure an ECC cipher is enabled */
  883|  7.00k|    return ssl_IsSuiteEnabled(ss, ssl_all_ec_suites);
  884|  7.00k|}
ssl_SendSupportedGroupsXtn:
  896|  1.21k|{
  897|  1.21k|    unsigned int i;
  898|  1.21k|    PRBool ec;
  899|  1.21k|    PRBool ec_hybrid = PR_FALSE;
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
  900|  1.21k|    PRBool ff = PR_FALSE;
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
  901|  1.21k|    PRBool found = PR_FALSE;
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
  902|  1.21k|    SECStatus rv;
  903|  1.21k|    unsigned int lengthOffset;
  904|       |
  905|       |    /* We only send FF supported groups if we require DH named groups
  906|       |     * or if TLS 1.3 is a possibility. */
  907|  1.21k|    if (ss->vrange.max < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  1.21k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (907:9): [True: 0, False: 1.21k]
  ------------------
  908|      0|        ec = ssl_IsECCEnabled(ss);
  909|      0|        if (ss->opt.requireDHENamedGroups) {
  ------------------
  |  Branch (909:13): [True: 0, False: 0]
  ------------------
  910|      0|            ff = ssl_IsDHEEnabled(ss);
  911|      0|        }
  912|      0|        if (!ec && !ff) {
  ------------------
  |  Branch (912:13): [True: 0, False: 0]
  |  Branch (912:20): [True: 0, False: 0]
  ------------------
  913|      0|            return SECSuccess;
  914|      0|        }
  915|  1.21k|    } else {
  916|  1.21k|        ec = ec_hybrid = ff = PR_TRUE;
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
  917|  1.21k|    }
  918|       |
  919|       |    /* Mark the location of the length. */
  920|  1.21k|    rv = sslBuffer_Skip(buf, 2, &lengthOffset);
  921|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (921:9): [True: 0, False: 1.21k]
  ------------------
  922|      0|        return SECFailure;
  923|      0|    }
  924|       |
  925|  41.2k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  41.2k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (925:17): [True: 40.0k, False: 1.21k]
  ------------------
  926|  40.0k|        const sslNamedGroupDef *group = ss->namedGroupPreferences[i];
  927|  40.0k|        if (!group) {
  ------------------
  |  Branch (927:13): [True: 37.9k, False: 2.12k]
  ------------------
  928|  37.9k|            continue;
  929|  37.9k|        }
  930|  2.12k|        if (group->keaType == ssl_kea_ecdh && !ec) {
  ------------------
  |  Branch (930:13): [True: 830, False: 1.29k]
  |  Branch (930:47): [True: 0, False: 830]
  ------------------
  931|      0|            continue;
  932|      0|        }
  933|  2.12k|        if (group->keaType == ssl_kea_ecdh_hybrid && !ec_hybrid) {
  ------------------
  |  Branch (933:13): [True: 167, False: 1.96k]
  |  Branch (933:54): [True: 0, False: 167]
  ------------------
  934|      0|            continue;
  935|      0|        }
  936|  2.12k|        if (group->keaType == ssl_kea_dh && !ff) {
  ------------------
  |  Branch (936:13): [True: 1.13k, False: 997]
  |  Branch (936:45): [True: 0, False: 1.13k]
  ------------------
  937|      0|            continue;
  938|      0|        }
  939|       |
  940|  2.12k|        found = PR_TRUE;
  ------------------
  |  |  437|  2.12k|#define PR_TRUE 1
  ------------------
  941|  2.12k|        rv = sslBuffer_AppendNumber(buf, group->name, 2);
  942|  2.12k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (942:13): [True: 0, False: 2.12k]
  ------------------
  943|      0|            return SECFailure;
  944|      0|        }
  945|  2.12k|    }
  946|       |
  947|       |    /* GREASE SupportedGroups:
  948|       |     * A client MAY select one or more GREASE named group values and advertise
  949|       |     * them in the "supported_groups" extension, if sent [RFC8701, Section 3.1].
  950|       |     */
  951|  1.21k|    if (!ss->sec.isServer &&
  ------------------
  |  Branch (951:9): [True: 0, False: 1.21k]
  ------------------
  952|  1.21k|        ss->opt.enableGrease &&
  ------------------
  |  Branch (952:9): [True: 0, False: 0]
  ------------------
  953|  1.21k|        ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (953:9): [True: 0, False: 0]
  ------------------
  954|      0|        rv = sslBuffer_AppendNumber(buf, ss->ssl3.hs.grease->idx[grease_group], 2);
  955|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (955:13): [True: 0, False: 0]
  ------------------
  956|      0|            return SECFailure;
  957|      0|        }
  958|      0|        found = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  959|      0|    }
  960|       |
  961|  1.21k|    if (!found) {
  ------------------
  |  Branch (961:9): [True: 0, False: 1.21k]
  ------------------
  962|       |        /* We added nothing, don't send the extension. */
  963|      0|        return SECSuccess;
  964|      0|    }
  965|       |
  966|  1.21k|    rv = sslBuffer_InsertLength(buf, lengthOffset, 2);
  967|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (967:9): [True: 0, False: 1.21k]
  ------------------
  968|      0|        return SECFailure;
  969|      0|    }
  970|       |
  971|  1.21k|    *added = PR_TRUE;
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
  972|  1.21k|    return SECSuccess;
  973|  1.21k|}
ssl3_SendSupportedPointFormatsXtn:
  981|  7.00k|{
  982|  7.00k|    SECStatus rv;
  983|       |
  984|       |    /* No point in doing this unless we have a socket that supports ECC.
  985|       |     * Similarly, no point if we are going to do TLS 1.3 only or we have already
  986|       |     * picked TLS 1.3 (server) given that it doesn't use point formats. */
  987|  7.00k|    if (!ss || !ssl_IsECCEnabled(ss) ||
  ------------------
  |  Branch (987:9): [True: 0, False: 7.00k]
  |  Branch (987:16): [True: 0, False: 7.00k]
  ------------------
  988|  7.00k|        ss->vrange.min >= SSL_LIBRARY_VERSION_TLS_1_3 ||
  ------------------
  |  |   21|  14.0k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (988:9): [True: 0, False: 7.00k]
  ------------------
  989|  7.00k|        (ss->sec.isServer && ss->version >= SSL_LIBRARY_VERSION_TLS_1_3)) {
  ------------------
  |  |   21|  7.00k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (989:10): [True: 7.00k, False: 0]
  |  Branch (989:30): [True: 0, False: 7.00k]
  ------------------
  990|      0|        return SECSuccess;
  991|      0|    }
  992|  7.00k|    rv = sslBuffer_AppendNumber(buf, 1, 1); /* length */
  993|  7.00k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (993:9): [True: 0, False: 7.00k]
  ------------------
  994|      0|        return SECFailure;
  995|      0|    }
  996|  7.00k|    rv = sslBuffer_AppendNumber(buf, 0, 1); /* uncompressed type only */
  997|  7.00k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (997:9): [True: 0, False: 7.00k]
  ------------------
  998|      0|        return SECFailure;
  999|      0|    }
 1000|       |
 1001|  7.00k|    *added = PR_TRUE;
  ------------------
  |  |  437|  7.00k|#define PR_TRUE 1
  ------------------
 1002|  7.00k|    return SECSuccess;
 1003|  7.00k|}
ssl3ecc.c:ssl_CreateECDHEPrivateKey:
  443|  18.2k|{
  444|  18.2k|    SECKEYPrivateKey *privk = NULL;
  445|  18.2k|    CK_MECHANISM_TYPE type = CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN;
  ------------------
  |  |  274|  18.2k|#define CKM_NSS_ECDHE_NO_PAIRWISE_CHECK_KEY_PAIR_GEN (CKM_NSS + 47)
  |  |  ------------------
  |  |  |  |  162|  18.2k|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|  18.2k|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|  18.2k|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  446|       |
  447|  18.2k|    PK11SlotInfo *slot = PK11_GetInternalSlot();
  448|  18.2k|    if (!slot || !PK11_DoesMechanism(slot, type) || PK11_IsFIPS()) {
  ------------------
  |  Branch (448:9): [True: 0, False: 18.2k]
  |  Branch (448:18): [True: 0, False: 18.2k]
  |  Branch (448:53): [True: 0, False: 18.2k]
  ------------------
  449|      0|        if (slot) {
  ------------------
  |  Branch (449:13): [True: 0, False: 0]
  ------------------
  450|      0|            PK11_FreeSlot(slot);
  451|      0|        }
  452|      0|        return SECKEY_CreateECPrivateKey(param, pubk, cx);
  453|      0|    }
  454|       |
  455|  18.2k|    privk = PK11_GenerateKeyPairWithOpFlags(slot, type, param, pubk,
  456|  18.2k|                                            PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  |  195|  18.2k|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
                                                          PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  |  261|  18.2k|#define PK11_ATTR_INSENSITIVE 0x00000080L
  ------------------
                                                          PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  |  217|  18.2k|#define PK11_ATTR_PUBLIC 0x00000008L
  ------------------
  457|  18.2k|                                            CKF_DERIVE, CKF_DERIVE, cx);
  ------------------
  |  | 1364|  18.2k|#define CKF_DERIVE 0x00080000UL
  ------------------
                                                          CKF_DERIVE, CKF_DERIVE, cx);
  ------------------
  |  | 1364|  18.2k|#define CKF_DERIVE 0x00080000UL
  ------------------
  458|  18.2k|    if (!privk) {
  ------------------
  |  Branch (458:9): [True: 22, False: 18.2k]
  ------------------
  459|     22|        privk = PK11_GenerateKeyPairWithOpFlags(slot, type, param, pubk,
  460|     22|                                                PK11_ATTR_SESSION | PK11_ATTR_SENSITIVE | PK11_ATTR_PRIVATE,
  ------------------
  |  |  195|     22|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
                                                              PK11_ATTR_SESSION | PK11_ATTR_SENSITIVE | PK11_ATTR_PRIVATE,
  ------------------
  |  |  260|     22|#define PK11_ATTR_SENSITIVE 0x00000040L
  ------------------
                                                              PK11_ATTR_SESSION | PK11_ATTR_SENSITIVE | PK11_ATTR_PRIVATE,
  ------------------
  |  |  216|     22|#define PK11_ATTR_PRIVATE 0x00000004L
  ------------------
  461|     22|                                                CKF_DERIVE, CKF_DERIVE, cx);
  ------------------
  |  | 1364|     22|#define CKF_DERIVE 0x00080000UL
  ------------------
                                                              CKF_DERIVE, CKF_DERIVE, cx);
  ------------------
  |  | 1364|     22|#define CKF_DERIVE 0x00080000UL
  ------------------
  462|     22|    }
  463|       |
  464|  18.2k|    PK11_FreeSlot(slot);
  465|  18.2k|    return privk;
  466|  18.2k|}
ssl3ecc.c:ssl3_ComputeECDHKeyHash:
  116|  17.5k|{
  117|  17.5k|    PRUint8 *hashBuf;
  118|  17.5k|    PRUint8 *pBuf;
  119|  17.5k|    SECStatus rv = SECSuccess;
  120|  17.5k|    unsigned int bufLen;
  121|       |    /*
  122|       |     * We only support named curves (the appropriate checks are made before this
  123|       |     * method is called) so ec_params takes up only two bytes. ECPoint needs to
  124|       |     * fit in 256 bytes because the spec says the length must fit in one byte.
  125|       |     */
  126|  17.5k|    PRUint8 buf[2 * SSL3_RANDOM_LENGTH + 2 + 1 + 256];
  127|       |
  128|  17.5k|    bufLen = 2 * SSL3_RANDOM_LENGTH + ec_params.len + 1 + server_ecpoint.len;
  ------------------
  |  |   24|  17.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  129|  17.5k|    if (bufLen <= sizeof buf) {
  ------------------
  |  Branch (129:9): [True: 17.5k, False: 0]
  ------------------
  130|  17.5k|        hashBuf = buf;
  131|  17.5k|    } else {
  132|      0|        hashBuf = PORT_Alloc(bufLen);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  133|      0|        if (!hashBuf) {
  ------------------
  |  Branch (133:13): [True: 0, False: 0]
  ------------------
  134|      0|            return SECFailure;
  135|      0|        }
  136|      0|    }
  137|       |
  138|  17.5k|    memcpy(hashBuf, client_rand, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|  17.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  139|  17.5k|    pBuf = hashBuf + SSL3_RANDOM_LENGTH;
  ------------------
  |  |   24|  17.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  140|  17.5k|    memcpy(pBuf, server_rand, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|  17.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  141|  17.5k|    pBuf += SSL3_RANDOM_LENGTH;
  ------------------
  |  |   24|  17.5k|#define SSL3_RANDOM_LENGTH 32
  ------------------
  142|  17.5k|    memcpy(pBuf, ec_params.data, ec_params.len);
  143|  17.5k|    pBuf += ec_params.len;
  144|  17.5k|    pBuf[0] = (PRUint8)(server_ecpoint.len);
  145|  17.5k|    pBuf += 1;
  146|  17.5k|    memcpy(pBuf, server_ecpoint.data, server_ecpoint.len);
  147|  17.5k|    pBuf += server_ecpoint.len;
  148|  17.5k|    PORT_Assert((unsigned int)(pBuf - hashBuf) == bufLen);
  ------------------
  |  |  120|  17.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  17.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 17.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  149|       |
  150|  17.5k|    rv = ssl3_ComputeCommonKeyHash(hashAlg, hashBuf, bufLen, hashes);
  151|       |
  152|  17.5k|    PRINT_BUF(95, (NULL, "ECDHkey hash: ", hashBuf, bufLen));
  ------------------
  |  |   74|  17.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 17.5k]
  |  |  ------------------
  |  |   75|  17.5k|    ssl_PrintBuf b
  ------------------
  153|  17.5k|    PRINT_BUF(95, (NULL, "ECDHkey hash: MD5 result",
  ------------------
  |  |   74|  17.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 17.5k]
  |  |  ------------------
  |  |   75|  17.5k|    ssl_PrintBuf b
  ------------------
  154|  17.5k|                   hashes->u.s.md5, MD5_LENGTH));
  155|  17.5k|    PRINT_BUF(95, (NULL, "ECDHkey hash: SHA1 result",
  ------------------
  |  |   74|  17.5k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 17.5k]
  |  |  ------------------
  |  |   75|  17.5k|    ssl_PrintBuf b
  ------------------
  156|  17.5k|                   hashes->u.s.sha, SHA1_LENGTH));
  157|       |
  158|  17.5k|    if (hashBuf != buf)
  ------------------
  |  Branch (158:9): [True: 0, False: 17.5k]
  ------------------
  159|      0|        PORT_Free(hashBuf);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  160|  17.5k|    return rv;
  161|  17.5k|}
ssl3ecc.c:ssl_IsSuiteEnabled:
  855|  7.00k|{
  856|  7.00k|    const ssl3CipherSuite *suite;
  857|       |
  858|  7.00k|    for (suite = list; *suite; ++suite) {
  ------------------
  |  Branch (858:24): [True: 7.00k, False: 0]
  ------------------
  859|  7.00k|        PRBool enabled = PR_FALSE;
  ------------------
  |  |  438|  7.00k|#define PR_FALSE 0
  ------------------
  860|  7.00k|        SECStatus rv = ssl3_CipherPrefGet(ss, *suite, &enabled);
  861|       |
  862|  7.00k|        PORT_Assert(rv == SECSuccess); /* else is coding error */
  ------------------
  |  |  120|  7.00k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.00k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.00k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  863|  7.00k|        if (rv == SECSuccess && enabled)
  ------------------
  |  Branch (863:13): [True: 7.00k, False: 0]
  |  Branch (863:33): [True: 7.00k, False: 0]
  ------------------
  864|  7.00k|            return PR_TRUE;
  ------------------
  |  |  437|  7.00k|#define PR_TRUE 1
  ------------------
  865|  7.00k|    }
  866|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  867|  7.00k|}

ssl_FindCustomExtensionHooks:
  294|   192k|{
  295|   192k|    PRCList *cursor;
  296|       |
  297|   192k|    for (cursor = PR_NEXT_LINK(&ss->extensionHooks);
  ------------------
  |  |   47|   192k|        ((_e)->next)
  ------------------
  298|   192k|         cursor != &ss->extensionHooks;
  ------------------
  |  Branch (298:10): [True: 0, False: 192k]
  ------------------
  299|   192k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  300|      0|        sslCustomExtensionHooks *hook = (sslCustomExtensionHooks *)cursor;
  301|      0|        if (hook->type == extension) {
  ------------------
  |  Branch (301:13): [True: 0, False: 0]
  ------------------
  302|      0|            return hook;
  303|      0|        }
  304|      0|    }
  305|       |
  306|   192k|    return NULL;
  307|   192k|}
ssl3_ExtensionNegotiated:
  322|   973k|{
  323|   973k|    const TLSExtensionData *xtnData = &ss->xtnData;
  324|   973k|    return arrayContainsExtension(xtnData->negotiated,
  325|   973k|                                  xtnData->numNegotiated, ex_type);
  326|   973k|}
ssl3_ParseExtensions:
  356|  19.8k|{
  357|       |    /* Clean out the extensions list. */
  358|  19.8k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.remoteExtensions);
  359|       |
  360|   158k|    while (*length) {
  ------------------
  |  Branch (360:12): [True: 138k, False: 19.8k]
  ------------------
  361|   138k|        SECStatus rv;
  362|   138k|        PRUint32 extension_type;
  363|   138k|        SECItem extension_data = { siBuffer, NULL, 0 };
  364|   138k|        TLSExtension *extension;
  365|   138k|        PRCList *cursor;
  366|       |
  367|       |        /* Get the extension's type field */
  368|   138k|        rv = ssl3_ConsumeHandshakeNumber(ss, &extension_type, 2, b, length);
  369|   138k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (369:13): [True: 2, False: 138k]
  ------------------
  370|      2|            return SECFailure; /* alert already sent */
  371|      2|        }
  372|       |
  373|       |        /* Check whether an extension has been sent multiple times. */
  374|   138k|        for (cursor = PR_NEXT_LINK(&ss->ssl3.hs.remoteExtensions);
  ------------------
  |  |   47|   138k|        ((_e)->next)
  ------------------
  375|   639k|             cursor != &ss->ssl3.hs.remoteExtensions;
  ------------------
  |  Branch (375:14): [True: 500k, False: 138k]
  ------------------
  376|   500k|             cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|   500k|        ((_e)->next)
  ------------------
  377|   500k|            if (((TLSExtension *)cursor)->type == extension_type) {
  ------------------
  |  Branch (377:17): [True: 4, False: 500k]
  ------------------
  378|      4|                (void)SSL3_SendAlert(ss, alert_fatal, illegal_parameter);
  379|      4|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_EXTENSION);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
  380|      4|                return SECFailure;
  381|      4|            }
  382|   500k|        }
  383|       |
  384|       |        /* Get the data for this extension, so we can pass it or skip it. */
  385|   138k|        rv = ssl3_ConsumeHandshakeVariable(ss, &extension_data, 2, b, length);
  386|   138k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (386:13): [True: 16, False: 138k]
  ------------------
  387|     16|            return rv; /* alert already sent */
  388|     16|        }
  389|       |
  390|   138k|        SSL_TRC(10, ("%d: SSL3[%d]: parsed extension %d len=%u",
  ------------------
  |  |   71|   138k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 138k]
  |  |  ------------------
  |  |   72|   138k|    ssl_Trace b
  ------------------
  391|   138k|                     SSL_GETPID(), ss->fd, extension_type, extension_data.len));
  392|       |
  393|   138k|        extension = PORT_ZNew(TLSExtension);
  ------------------
  |  |  148|   138k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|   138k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  394|   138k|        if (!extension) {
  ------------------
  |  Branch (394:13): [True: 0, False: 138k]
  ------------------
  395|      0|            return SECFailure;
  396|      0|        }
  397|       |
  398|   138k|        extension->type = (PRUint16)extension_type;
  399|   138k|        extension->data = extension_data;
  400|   138k|        PR_APPEND_LINK(&extension->link, &ss->ssl3.hs.remoteExtensions);
  ------------------
  |  |   57|   138k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|   138k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|   138k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|   138k|    (_e)->next = (_l);   \
  |  |  |  |   27|   138k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|   138k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|   138k|    (_l)->prev = (_e);   \
  |  |  |  |   30|   138k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|   138k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  401|   138k|    }
  402|       |
  403|  19.8k|    return SECSuccess;
  404|  19.8k|}
ssl3_FindExtension:
  408|  64.8k|{
  409|  64.8k|    PRCList *cursor;
  410|       |
  411|  64.8k|    for (cursor = PR_NEXT_LINK(&ss->ssl3.hs.remoteExtensions);
  ------------------
  |  |   47|  64.8k|        ((_e)->next)
  ------------------
  412|   222k|         cursor != &ss->ssl3.hs.remoteExtensions;
  ------------------
  |  Branch (412:10): [True: 160k, False: 61.9k]
  ------------------
  413|   160k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|   157k|        ((_e)->next)
  ------------------
  414|   160k|        TLSExtension *extension = (TLSExtension *)cursor;
  415|       |
  416|   160k|        if (extension->type == extension_type) {
  ------------------
  |  Branch (416:13): [True: 2.94k, False: 157k]
  ------------------
  417|  2.94k|            return extension;
  418|  2.94k|        }
  419|   160k|    }
  420|       |
  421|  61.9k|    return NULL;
  422|  64.8k|}
ssl3_HandleParsedExtensions:
  475|  63.0k|{
  476|  63.0k|    const ssl3ExtensionHandler *handlers;
  477|       |    /* HelloRetryRequest doesn't set ss->version. It might be safe to
  478|       |     * do so, but we weren't entirely sure. TODO(ekr@rtfm.com). */
  479|  63.0k|    PRBool isTLS13 = (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) ||
  ------------------
  |  |   21|  63.0k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (479:22): [True: 2.61k, False: 60.4k]
  ------------------
  480|  63.0k|                     (message == ssl_hs_hello_retry_request);
  ------------------
  |  Branch (480:22): [True: 0, False: 60.4k]
  ------------------
  481|       |    /* The following messages can include extensions that were not included in
  482|       |     * the original ClientHello. */
  483|  63.0k|    PRBool allowNotOffered = (message == ssl_hs_client_hello) ||
  ------------------
  |  Branch (483:30): [True: 63.0k, False: 0]
  ------------------
  484|  63.0k|                             (message == ssl_hs_certificate_request) ||
  ------------------
  |  Branch (484:30): [True: 0, False: 0]
  ------------------
  485|  63.0k|                             (message == ssl_hs_new_session_ticket);
  ------------------
  |  Branch (485:30): [True: 0, False: 0]
  ------------------
  486|  63.0k|    PRCList *cursor;
  487|       |
  488|  63.0k|    switch (message) {
  489|  63.0k|        case ssl_hs_client_hello:
  ------------------
  |  Branch (489:9): [True: 63.0k, False: 0]
  ------------------
  490|  63.0k|            handlers = clientHelloHandlers;
  491|  63.0k|            break;
  492|      0|        case ssl_hs_new_session_ticket:
  ------------------
  |  Branch (492:9): [True: 0, False: 63.0k]
  ------------------
  493|      0|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  494|      0|            handlers = newSessionTicketHandlers;
  495|      0|            break;
  496|      0|        case ssl_hs_hello_retry_request:
  ------------------
  |  Branch (496:9): [True: 0, False: 63.0k]
  ------------------
  497|      0|            handlers = helloRetryRequestHandlers;
  498|      0|            break;
  499|      0|        case ssl_hs_encrypted_extensions:
  ------------------
  |  Branch (499:9): [True: 0, False: 63.0k]
  ------------------
  500|      0|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  501|       |        /* fall through */
  502|      0|        case ssl_hs_server_hello:
  ------------------
  |  Branch (502:9): [True: 0, False: 63.0k]
  ------------------
  503|      0|            if (ss->version > SSL_LIBRARY_VERSION_3_0) {
  ------------------
  |  |   17|      0|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (503:17): [True: 0, False: 0]
  ------------------
  504|      0|                handlers = serverHelloHandlersTLS;
  505|      0|            } else {
  506|      0|                handlers = serverHelloHandlersSSL3;
  507|      0|            }
  508|      0|            break;
  509|      0|        case ssl_hs_certificate:
  ------------------
  |  Branch (509:9): [True: 0, False: 63.0k]
  ------------------
  510|      0|            PORT_Assert(!ss->sec.isServer);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  511|      0|            handlers = serverCertificateHandlers;
  512|      0|            break;
  513|      0|        case ssl_hs_certificate_request:
  ------------------
  |  Branch (513:9): [True: 0, False: 63.0k]
  ------------------
  514|      0|            PORT_Assert(!ss->sec.isServer);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  515|      0|            handlers = certificateRequestHandlers;
  516|      0|            break;
  517|      0|        default:
  ------------------
  |  Branch (517:9): [True: 0, False: 63.0k]
  ------------------
  518|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  519|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  520|      0|            return SECFailure;
  521|  63.0k|    }
  522|       |
  523|  63.0k|    for (cursor = PR_NEXT_LINK(&ss->ssl3.hs.remoteExtensions);
  ------------------
  |  |   47|  63.0k|        ((_e)->next)
  ------------------
  524|   200k|         cursor != &ss->ssl3.hs.remoteExtensions;
  ------------------
  |  Branch (524:10): [True: 137k, False: 62.5k]
  ------------------
  525|   137k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|   137k|        ((_e)->next)
  ------------------
  526|   137k|        TLSExtension *extension = (TLSExtension *)cursor;
  527|   137k|        SECStatus rv;
  528|       |
  529|       |        /* Check whether the server sent an extension which was not advertised
  530|       |         * in the ClientHello.
  531|       |         *
  532|       |         * Note that a TLS 1.3 server should check if CertificateRequest
  533|       |         * extensions were sent.  But the extensions used for CertificateRequest
  534|       |         * do not have any response, so we rely on
  535|       |         * ssl3_ExtensionAdvertised to return false on the server.  That
  536|       |         * results in the server only rejecting any extension. */
  537|   137k|        if (!allowNotOffered && (extension->type != ssl_tls13_cookie_xtn)) {
  ------------------
  |  Branch (537:13): [True: 0, False: 137k]
  |  Branch (537:33): [True: 0, False: 0]
  ------------------
  538|      0|            if (!ssl3_ExtensionAdvertised(ss, extension->type)) {
  ------------------
  |  Branch (538:17): [True: 0, False: 0]
  ------------------
  539|      0|                SSL_TRC(10, ("Server sent xtn type=%d which is invalid for the CHO", extension->type));
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  540|      0|                (void)SSL3_SendAlert(ss, alert_fatal, unsupported_extension);
  541|      0|                PORT_SetError(SSL_ERROR_RX_UNEXPECTED_EXTENSION);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  542|      0|                return SECFailure;
  543|      0|            }
  544|       |            /* If we offered ECH, we also check whether the extension is compatible with
  545|       |             * the Client Hello Inner. We don't yet know whether the server accepted ECH,
  546|       |             * so we only store this for now. If we later accept, we check this boolean
  547|       |             * and reject with an unsupported_extension alert if it is set. */
  548|      0|            if (ss->ssl3.hs.echHpkeCtx && !ssl3_ExtensionAdvertisedClientHelloInner(ss, extension->type)) {
  ------------------
  |  Branch (548:17): [True: 0, False: 0]
  |  Branch (548:43): [True: 0, False: 0]
  ------------------
  549|      0|                SSL_TRC(10, ("Server sent xtn type=%d which is invalid for the CHI", extension->type));
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  550|      0|                ss->ssl3.hs.echInvalidExtension = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  551|      0|            }
  552|      0|        }
  553|       |
  554|       |        /* Check that this is a legal extension in TLS 1.3 */
  555|   137k|        if (isTLS13 &&
  ------------------
  |  Branch (555:13): [True: 15.7k, False: 122k]
  ------------------
  556|   137k|            !ssl_FindCustomExtensionHooks(ss, extension->type)) {
  ------------------
  |  Branch (556:13): [True: 15.7k, False: 0]
  ------------------
  557|  15.7k|            switch (tls13_ExtensionStatus(extension->type, message)) {
  ------------------
  |  Branch (557:21): [True: 0, False: 15.7k]
  ------------------
  558|  8.32k|                case tls13_extension_allowed:
  ------------------
  |  Branch (558:17): [True: 8.32k, False: 7.38k]
  ------------------
  559|  8.32k|                    break;
  560|  7.38k|                case tls13_extension_unknown:
  ------------------
  |  Branch (560:17): [True: 7.38k, False: 8.32k]
  ------------------
  561|  7.38k|                    if (allowNotOffered) {
  ------------------
  |  Branch (561:25): [True: 7.38k, False: 0]
  ------------------
  562|  7.38k|                        continue; /* Skip over unknown extensions. */
  563|  7.38k|                    }
  564|       |                    /* RFC8446 Section 4.2 - Implementations MUST NOT send extension responses if
  565|       |                     * the remote endpoint did not send the corresponding extension request ...
  566|       |                     * Upon receiving such an extension, an endpoint MUST abort the handshake with
  567|       |                     * an "unsupported_extension" alert. */
  568|      0|                    SSL_TRC(3, ("%d: TLS13: unknown extension %d in message %d",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  569|      0|                                SSL_GETPID(), extension, message));
  570|      0|                    tls13_FatalError(ss, SSL_ERROR_RX_UNEXPECTED_EXTENSION,
  571|      0|                                     unsupported_extension);
  572|      0|                    return SECFailure;
  573|      1|                case tls13_extension_disallowed:
  ------------------
  |  Branch (573:17): [True: 1, False: 15.7k]
  ------------------
  574|       |                    /* RFC8446 Section 4.2 - If an implementation receives an extension which it
  575|       |                     * recognizes and which is not specified for the message in which it appears,
  576|       |                     * it MUST abort the handshake with an "illegal_parameter" alert. */
  577|      1|                    SSL_TRC(3, ("%d: TLS13: disallowed extension %d in message %d",
  ------------------
  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   72|      1|    ssl_Trace b
  ------------------
  578|      1|                                SSL_GETPID(), extension, message));
  579|      1|                    tls13_FatalError(ss, SSL_ERROR_EXTENSION_DISALLOWED_FOR_VERSION,
  580|      1|                                     illegal_parameter);
  581|      1|                    return SECFailure;
  582|  15.7k|            }
  583|  15.7k|        }
  584|       |
  585|       |        /* Special check for this being the last extension if it's
  586|       |         * PreSharedKey */
  587|   130k|        if (ss->sec.isServer && isTLS13 &&
  ------------------
  |  Branch (587:13): [True: 130k, False: 0]
  |  Branch (587:33): [True: 8.32k, False: 122k]
  ------------------
  588|   130k|            (extension->type == ssl_tls13_pre_shared_key_xtn) &&
  ------------------
  |  Branch (588:13): [True: 221, False: 8.10k]
  ------------------
  589|   130k|            (PR_NEXT_LINK(cursor) != &ss->ssl3.hs.remoteExtensions)) {
  ------------------
  |  |   47|    221|        ((_e)->next)
  ------------------
  |  Branch (589:13): [True: 1, False: 220]
  ------------------
  590|      1|            tls13_FatalError(ss,
  591|      1|                             SSL_ERROR_RX_MALFORMED_CLIENT_HELLO,
  592|      1|                             illegal_parameter);
  593|      1|            return SECFailure;
  594|      1|        }
  595|       |
  596|   130k|        rv = ssl_CallExtensionHandler(ss, message, extension, handlers);
  597|   130k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (597:13): [True: 468, False: 130k]
  ------------------
  598|    468|            return SECFailure;
  599|    468|        }
  600|   130k|    }
  601|  62.5k|    return SECSuccess;
  602|  63.0k|}
ssl3_HandleExtensions:
  610|  2.12k|{
  611|  2.12k|    SECStatus rv;
  612|       |
  613|  2.12k|    rv = ssl3_ParseExtensions(ss, b, length);
  614|  2.12k|    if (rv != SECSuccess)
  ------------------
  |  Branch (614:9): [True: 0, False: 2.12k]
  ------------------
  615|      0|        return rv;
  616|       |
  617|  2.12k|    rv = ssl3_HandleParsedExtensions(ss, handshakeMessage);
  618|  2.12k|    if (rv != SECSuccess)
  ------------------
  |  Branch (618:9): [True: 12, False: 2.11k]
  ------------------
  619|     12|        return rv;
  620|       |
  621|  2.11k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.remoteExtensions);
  622|  2.11k|    return SECSuccess;
  623|  2.12k|}
ssl3_RegisterExtensionSender:
  632|  44.5k|{
  633|  44.5k|    int i;
  634|  44.5k|    sslExtensionBuilder *sender;
  635|  44.5k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  44.5k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (635:9): [True: 39.7k, False: 4.79k]
  ------------------
  636|  39.7k|        sender = &xtnData->serverHelloSenders[0];
  637|  39.7k|    } else {
  638|  4.79k|        if (tls13_ExtensionStatus(ex_type, ssl_hs_server_hello) ==
  ------------------
  |  Branch (638:13): [True: 2.45k, False: 2.33k]
  ------------------
  639|  4.79k|            tls13_extension_allowed) {
  640|  2.45k|            PORT_Assert(tls13_ExtensionStatus(ex_type,
  ------------------
  |  |  120|  2.45k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.45k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2.45k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  641|  2.45k|                                              ssl_hs_encrypted_extensions) ==
  642|  2.45k|                        tls13_extension_disallowed);
  643|  2.45k|            sender = &xtnData->serverHelloSenders[0];
  644|  2.45k|        } else if (tls13_ExtensionStatus(ex_type,
  ------------------
  |  Branch (644:20): [True: 2.22k, False: 105]
  ------------------
  645|  2.33k|                                         ssl_hs_encrypted_extensions) ==
  646|  2.33k|                   tls13_extension_allowed) {
  647|  2.22k|            sender = &xtnData->encryptedExtensionsSenders[0];
  648|  2.22k|        } else if (tls13_ExtensionStatus(ex_type, ssl_hs_certificate) ==
  ------------------
  |  Branch (648:20): [True: 105, False: 0]
  ------------------
  649|    105|                   tls13_extension_allowed) {
  650|    105|            sender = &xtnData->certificateSenders[0];
  651|    105|        } else {
  652|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  653|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  654|      0|            return SECFailure;
  655|      0|        }
  656|  4.79k|    }
  657|  87.0k|    for (i = 0; i < SSL_MAX_EXTENSIONS; ++i, ++sender) {
  ------------------
  |  |  576|  87.0k|#define SSL_MAX_EXTENSIONS 22
  ------------------
  |  Branch (657:17): [True: 87.0k, False: 0]
  ------------------
  658|  87.0k|        if (!sender->ex_sender) {
  ------------------
  |  Branch (658:13): [True: 44.5k, False: 42.4k]
  ------------------
  659|  44.5k|            sender->ex_type = ex_type;
  660|  44.5k|            sender->ex_sender = cb;
  661|  44.5k|            return SECSuccess;
  662|  44.5k|        }
  663|       |        /* detect duplicate senders */
  664|  42.4k|        PORT_Assert(sender->ex_type != ex_type);
  ------------------
  |  |  120|  42.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  42.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 42.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  665|  42.4k|        if (sender->ex_type == ex_type) {
  ------------------
  |  Branch (665:13): [True: 0, False: 42.4k]
  ------------------
  666|       |            /* duplicate */
  667|      0|            break;
  668|      0|        }
  669|  42.4k|    }
  670|      0|    PORT_Assert(i < SSL_MAX_EXTENSIONS); /* table needs to grow */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  671|      0|    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  672|      0|    return SECFailure;
  673|  44.5k|}
ssl_ConstructExtensions:
  760|  63.0k|{
  761|  63.0k|    const sslExtensionBuilder *sender;
  762|  63.0k|    SECStatus rv;
  763|       |
  764|  63.0k|    PORT_Assert(buf->len == 0);
  ------------------
  |  |  120|  63.0k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  63.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 63.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  765|       |
  766|       |    /* Clear out any extensions previously advertised */
  767|  63.0k|    ss->xtnData.numAdvertised = 0;
  768|  63.0k|    ss->xtnData.echNumAdvertised = 0;
  769|       |
  770|  63.0k|    switch (message) {
  771|      0|        case ssl_hs_client_hello:
  ------------------
  |  Branch (771:9): [True: 0, False: 63.0k]
  ------------------
  772|      0|            if (ss->vrange.max > SSL_LIBRARY_VERSION_3_0) {
  ------------------
  |  |   17|      0|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (772:17): [True: 0, False: 0]
  ------------------
  773|       |                /* Use TLS ClientHello Extension Permutation? */
  774|      0|                if (ss->opt.enableChXtnPermutation) {
  ------------------
  |  Branch (774:21): [True: 0, False: 0]
  ------------------
  775|      0|                    sender = ss->ssl3.hs.chExtensionPermutation;
  776|      0|                } else {
  777|      0|                    sender = clientHelloSendersTLS;
  778|      0|                }
  779|      0|            } else {
  780|      0|                sender = clientHelloSendersSSL3;
  781|      0|            }
  782|      0|            break;
  783|       |
  784|  59.9k|        case ssl_hs_server_hello:
  ------------------
  |  Branch (784:9): [True: 59.9k, False: 3.05k]
  ------------------
  785|  59.9k|            sender = ss->xtnData.serverHelloSenders;
  786|  59.9k|            break;
  787|       |
  788|    447|        case ssl_hs_certificate_request:
  ------------------
  |  Branch (788:9): [True: 447, False: 62.5k]
  ------------------
  789|    447|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|    447|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    447|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 447, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  790|    447|            sender = tls13_cert_req_senders;
  791|    447|            break;
  792|       |
  793|  1.21k|        case ssl_hs_certificate:
  ------------------
  |  Branch (793:9): [True: 1.21k, False: 61.7k]
  ------------------
  794|  1.21k|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  795|  1.21k|            sender = ss->xtnData.certificateSenders;
  796|  1.21k|            break;
  797|       |
  798|  1.21k|        case ssl_hs_encrypted_extensions:
  ------------------
  |  Branch (798:9): [True: 1.21k, False: 61.7k]
  ------------------
  799|  1.21k|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  800|  1.21k|            sender = ss->xtnData.encryptedExtensionsSenders;
  801|  1.21k|            break;
  802|       |
  803|    181|        case ssl_hs_hello_retry_request:
  ------------------
  |  Branch (803:9): [True: 181, False: 62.8k]
  ------------------
  804|    181|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  805|    181|            sender = tls13_hrr_senders;
  806|    181|            break;
  807|       |
  808|      0|        default:
  ------------------
  |  Branch (808:9): [True: 0, False: 63.0k]
  ------------------
  809|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  810|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  811|      0|            return SECFailure;
  812|  63.0k|    }
  813|       |
  814|   109k|    for (; sender->ex_sender != NULL; ++sender) {
  ------------------
  |  Branch (814:12): [True: 46.3k, False: 63.0k]
  ------------------
  815|  46.3k|        PRUint16 ex_type = sender->ex_type;
  816|  46.3k|        PRBool append = PR_FALSE;
  ------------------
  |  |  438|  46.3k|#define PR_FALSE 0
  ------------------
  817|  46.3k|        unsigned int start = buf->len;
  818|  46.3k|        unsigned int length;
  819|       |
  820|  46.3k|        if (ssl_FindCustomExtensionHooks(ss, sender->ex_type)) {
  ------------------
  |  Branch (820:13): [True: 0, False: 46.3k]
  ------------------
  821|      0|            continue;
  822|      0|        }
  823|       |
  824|       |        /* Save space for the extension type and length. Note that we don't grow
  825|       |         * the buffer now; rely on sslBuffer_Append* to do that. */
  826|  46.3k|        buf->len += 4;
  827|  46.3k|        rv = (*sender->ex_sender)(ss, &ss->xtnData, buf, &append);
  828|  46.3k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (828:13): [True: 0, False: 46.3k]
  ------------------
  829|      0|            goto loser;
  830|      0|        }
  831|       |
  832|       |        /* Save the length and go back to the start. */
  833|  46.3k|        length = buf->len - start - 4;
  834|  46.3k|        buf->len = start;
  835|  46.3k|        if (!append) {
  ------------------
  |  Branch (835:13): [True: 22.5k, False: 23.8k]
  ------------------
  836|  22.5k|            continue;
  837|  22.5k|        }
  838|       |
  839|       |        /* If TLS 1.3 GREASE is enabled, replace ssl_tls13_grease_xtn dummy
  840|       |         * GREASE extension types with randomly generated GREASE value. */
  841|  23.8k|        rv = tls13_MaybeGreaseExtensionType(ss, message, &ex_type);
  842|  23.8k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (842:13): [True: 0, False: 23.8k]
  ------------------
  843|      0|            goto loser; /* Code already set. */
  844|      0|        }
  845|       |
  846|  23.8k|        rv = sslBuffer_AppendNumber(buf, ex_type, 2);
  847|  23.8k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (847:13): [True: 0, False: 23.8k]
  ------------------
  848|      0|            goto loser; /* Code already set. */
  849|      0|        }
  850|  23.8k|        rv = sslBuffer_AppendNumber(buf, length, 2);
  851|  23.8k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (851:13): [True: 0, False: 23.8k]
  ------------------
  852|      0|            goto loser; /* Code already set. */
  853|      0|        }
  854|       |        /* Skip over the extension body. */
  855|  23.8k|        buf->len += length;
  856|       |
  857|  23.8k|        if (message == ssl_hs_client_hello ||
  ------------------
  |  Branch (857:13): [True: 0, False: 23.8k]
  ------------------
  858|  23.8k|            message == ssl_hs_certificate_request) {
  ------------------
  |  Branch (858:13): [True: 873, False: 22.9k]
  ------------------
  859|    873|            ss->xtnData.advertised[ss->xtnData.numAdvertised++] =
  860|    873|                ex_type;
  861|    873|        }
  862|  23.8k|    }
  863|       |
  864|  63.0k|    if (!PR_CLIST_IS_EMPTY(&ss->extensionHooks)) {
  ------------------
  |  |   94|  63.0k|    ((_l)->next == (_l))
  ------------------
  |  Branch (864:9): [True: 0, False: 63.0k]
  ------------------
  865|      0|        if (message == ssl_hs_client_hello && ss->opt.callExtensionWriterOnEchInner) {
  ------------------
  |  Branch (865:13): [True: 0, False: 0]
  |  Branch (865:47): [True: 0, False: 0]
  ------------------
  866|      0|            message = ssl_hs_ech_outer_client_hello;
  867|      0|        }
  868|      0|        rv = ssl_CallCustomExtensionSenders(ss, buf, message);
  869|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (869:13): [True: 0, False: 0]
  ------------------
  870|      0|            goto loser;
  871|      0|        }
  872|      0|    }
  873|       |
  874|  63.0k|    if (buf->len > 0xffff) {
  ------------------
  |  Branch (874:9): [True: 0, False: 63.0k]
  ------------------
  875|      0|        PORT_SetError(SSL_ERROR_TX_RECORD_TOO_LONG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  876|      0|        goto loser;
  877|      0|    }
  878|       |
  879|  63.0k|    return SECSuccess;
  880|       |
  881|      0|loser:
  882|      0|    sslBuffer_Clear(buf);
  883|      0|    return SECFailure;
  884|  63.0k|}
ssl_SendEmptyExtension:
  892|  9.63k|{
  893|  9.63k|    *append = PR_TRUE;
  ------------------
  |  |  437|  9.63k|#define PR_TRUE 1
  ------------------
  894|  9.63k|    return SECSuccess;
  895|  9.63k|}
ssl3_DestroyRemoteExtensions:
 1025|   121k|{
 1026|   121k|    PRCList *cur_p;
 1027|       |
 1028|   260k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|   260k|    ((_l)->next == (_l))
  ------------------
  |  Branch (1028:12): [True: 138k, False: 121k]
  ------------------
 1029|   138k|        cur_p = PR_LIST_TAIL(list);
  ------------------
  |  |   66|   138k|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
 1030|   138k|        PR_REMOVE_LINK(cur_p);
  ------------------
  |  |   72|   138k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|   138k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|   138k|    (_e)->prev->next = (_e)->next; \
  |  |   74|   138k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|   138k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|   138k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1031|   138k|        PORT_Free(cur_p);
  ------------------
  |  |   60|   138k|#define PORT_Free PORT_Free_Util
  ------------------
 1032|   138k|    }
 1033|   121k|}
ssl3_InitExtensionData:
 1038|  90.3k|{
 1039|  90.3k|    unsigned int advertisedMax;
 1040|  90.3k|    PRCList *cursor;
 1041|       |
 1042|       |    /* Set things up to the right starting state. */
 1043|  90.3k|    PORT_Memset(xtnData, 0, sizeof(*xtnData));
  ------------------
  |  |  182|  90.3k|#define PORT_Memset memset
  ------------------
 1044|  90.3k|    xtnData->peerSupportsFfdheGroups = PR_FALSE;
  ------------------
  |  |  438|  90.3k|#define PR_FALSE 0
  ------------------
 1045|  90.3k|    PR_INIT_CLIST(&xtnData->remoteKeyShares);
  ------------------
  |  |  100|  90.3k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  90.3k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  90.3k|    (_l)->next = (_l); \
  |  |  102|  90.3k|    (_l)->prev = (_l); \
  |  |  103|  90.3k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  90.3k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1046|       |
 1047|       |    /* Allocate enough to allow for native extensions, plus any custom ones. */
 1048|  90.3k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1048:9): [True: 61.2k, False: 29.1k]
  ------------------
 1049|  61.2k|        advertisedMax = PR_MAX(PR_ARRAY_SIZE(certificateRequestHandlers),
  ------------------
  |  |  159|  61.2k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1050|  61.2k|                               PR_ARRAY_SIZE(tls13_cert_req_senders));
 1051|  61.2k|    } else {
 1052|  29.1k|        advertisedMax = PR_MAX(PR_ARRAY_SIZE(clientHelloHandlers),
  ------------------
  |  |  159|  29.1k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1053|  29.1k|                               PR_ARRAY_SIZE(clientHelloSendersTLS));
 1054|  29.1k|        ++advertisedMax; /* For the RI SCSV, which we also track. */
 1055|  29.1k|    }
 1056|  90.3k|    for (cursor = PR_NEXT_LINK(&ss->extensionHooks);
  ------------------
  |  |   47|  90.3k|        ((_e)->next)
  ------------------
 1057|  90.3k|         cursor != &ss->extensionHooks;
  ------------------
  |  Branch (1057:10): [True: 0, False: 90.3k]
  ------------------
 1058|  90.3k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
 1059|      0|        ++advertisedMax;
 1060|      0|    }
 1061|  90.3k|    xtnData->advertised = PORT_ZNewArray(PRUint16, advertisedMax);
  ------------------
  |  |  159|  90.3k|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|  90.3k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1062|  90.3k|    xtnData->echAdvertised = PORT_ZNewArray(PRUint16, advertisedMax);
  ------------------
  |  |  159|  90.3k|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|  90.3k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1063|       |
 1064|  90.3k|    xtnData->peerDelegCred = NULL;
 1065|  90.3k|    xtnData->peerRequestedDelegCred = PR_FALSE;
  ------------------
  |  |  438|  90.3k|#define PR_FALSE 0
  ------------------
 1066|  90.3k|    xtnData->sendingDelegCredToPeer = PR_FALSE;
  ------------------
  |  |  438|  90.3k|#define PR_FALSE 0
  ------------------
 1067|  90.3k|    xtnData->selectedPsk = NULL;
 1068|  90.3k|}
ssl3_DestroyExtensionData:
 1072|  90.3k|{
 1073|  90.3k|    ssl3_FreeSniNameArray(xtnData);
 1074|  90.3k|    PORT_Free(xtnData->sigSchemes);
  ------------------
  |  |   60|  90.3k|#define PORT_Free PORT_Free_Util
  ------------------
 1075|  90.3k|    PORT_Free(xtnData->delegCredSigSchemes);
  ------------------
  |  |   60|  90.3k|#define PORT_Free PORT_Free_Util
  ------------------
 1076|  90.3k|    PORT_Free(xtnData->delegCredSigSchemesAdvertised);
  ------------------
  |  |   60|  90.3k|#define PORT_Free PORT_Free_Util
  ------------------
 1077|  90.3k|    SECITEM_FreeItem(&xtnData->nextProto, PR_FALSE);
  ------------------
  |  |  108|  90.3k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&xtnData->nextProto, PR_FALSE);
  ------------------
  |  |  438|  90.3k|#define PR_FALSE 0
  ------------------
 1078|  90.3k|    tls13_DestroyKeyShares(&xtnData->remoteKeyShares);
 1079|  90.3k|    SECITEM_FreeItem(&xtnData->certReqContext, PR_FALSE);
  ------------------
  |  |  108|  90.3k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&xtnData->certReqContext, PR_FALSE);
  ------------------
  |  |  438|  90.3k|#define PR_FALSE 0
  ------------------
 1080|  90.3k|    SECITEM_FreeItem(&xtnData->applicationToken, PR_FALSE);
  ------------------
  |  |  108|  90.3k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&xtnData->applicationToken, PR_FALSE);
  ------------------
  |  |  438|  90.3k|#define PR_FALSE 0
  ------------------
 1081|  90.3k|    if (xtnData->certReqAuthorities.arena) {
  ------------------
  |  Branch (1081:9): [True: 0, False: 90.3k]
  ------------------
 1082|      0|        PORT_FreeArena(xtnData->certReqAuthorities.arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(xtnData->certReqAuthorities.arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1083|      0|        xtnData->certReqAuthorities.arena = NULL;
 1084|      0|    }
 1085|  90.3k|    PORT_Free(xtnData->advertised);
  ------------------
  |  |   60|  90.3k|#define PORT_Free PORT_Free_Util
  ------------------
 1086|  90.3k|    PORT_Free(xtnData->echAdvertised);
  ------------------
  |  |   60|  90.3k|#define PORT_Free PORT_Free_Util
  ------------------
 1087|  90.3k|    tls13_DestroyDelegatedCredential(xtnData->peerDelegCred);
 1088|       |
 1089|  90.3k|    tls13_DestroyEchXtnState(xtnData->ech);
 1090|  90.3k|    xtnData->ech = NULL;
 1091|  90.3k|}
ssl3_ResetExtensionData:
 1097|  80.6k|{
 1098|  80.6k|    ssl3_DestroyExtensionData(xtnData);
 1099|  80.6k|    ssl3_InitExtensionData(xtnData, ss);
 1100|  80.6k|}
ssl3_ExtSendAlert:
 1106|    180|{
 1107|    180|    (void)SSL3_SendAlert((sslSocket *)ss, level, desc);
 1108|    180|}
ssl3_ExtDecodeError:
 1112|     70|{
 1113|     70|    (void)ssl3_DecodeError((sslSocket *)ss);
 1114|     70|}
ssl3_ExtConsumeHandshake:
 1119|    197|{
 1120|    197|    return ssl3_ConsumeHandshake((sslSocket *)ss, v, bytes, b, length);
 1121|    197|}
ssl3_ExtConsumeHandshakeNumber:
 1126|  54.0k|{
 1127|  54.0k|    return ssl3_ConsumeHandshakeNumber((sslSocket *)ss, num, bytes, b, length);
 1128|  54.0k|}
ssl3_ExtConsumeHandshakeVariable:
 1134|  10.4k|{
 1135|  10.4k|    return ssl3_ConsumeHandshakeVariable((sslSocket *)ss, i, bytes, b, length);
 1136|  10.4k|}
tls_ClientHelloExtensionPermutationDestroy:
 1185|  19.4k|{
 1186|  19.4k|    if (ss->ssl3.hs.chExtensionPermutation) {
  ------------------
  |  Branch (1186:9): [True: 0, False: 19.4k]
  ------------------
 1187|      0|        PORT_Free(ss->ssl3.hs.chExtensionPermutation);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1188|      0|        ss->ssl3.hs.chExtensionPermutation = NULL;
 1189|      0|    }
 1190|  19.4k|}
ssl3ext.c:arrayContainsExtension:
  311|   973k|{
  312|   973k|    unsigned int i;
  313|  2.02M|    for (i = 0; i < len; i++) {
  ------------------
  |  Branch (313:17): [True: 1.37M, False: 645k]
  ------------------
  314|  1.37M|        if (ex_type == array[i])
  ------------------
  |  Branch (314:13): [True: 327k, False: 1.04M]
  ------------------
  315|   327k|            return PR_TRUE;
  ------------------
  |  |  437|   327k|#define PR_TRUE 1
  ------------------
  316|  1.37M|    }
  317|   645k|    return PR_FALSE;
  ------------------
  |  |  438|   645k|#define PR_FALSE 0
  ------------------
  318|   973k|}
ssl3ext.c:ssl_CallExtensionHandler:
  428|   130k|{
  429|   130k|    SECStatus rv = SECSuccess;
  430|   130k|    SSLAlertDescription alert = handshake_failure;
  431|   130k|    sslCustomExtensionHooks *customHooks;
  432|       |
  433|   130k|    customHooks = ssl_FindCustomExtensionHooks(ss, extension->type);
  434|   130k|    if (customHooks) {
  ------------------
  |  Branch (434:9): [True: 0, False: 130k]
  ------------------
  435|      0|        if (customHooks->handler) {
  ------------------
  |  Branch (435:13): [True: 0, False: 0]
  ------------------
  436|      0|            rv = customHooks->handler(ss->fd, handshakeMessage,
  437|      0|                                      extension->data.data,
  438|      0|                                      extension->data.len,
  439|      0|                                      &alert, customHooks->handlerArg);
  440|      0|        }
  441|   130k|    } else {
  442|       |        /* Find extension_type in table of Hello Extension Handlers. */
  443|  1.59M|        for (; handler->ex_handler != NULL; ++handler) {
  ------------------
  |  Branch (443:16): [True: 1.55M, False: 45.4k]
  ------------------
  444|  1.55M|            if (handler->ex_type == extension->type) {
  ------------------
  |  Branch (444:17): [True: 85.0k, False: 1.46M]
  ------------------
  445|  85.0k|                SECItem tmp = extension->data;
  446|       |
  447|  85.0k|                rv = (*handler->ex_handler)(ss, &ss->xtnData, &tmp);
  448|  85.0k|                break;
  449|  85.0k|            }
  450|  1.55M|        }
  451|   130k|    }
  452|       |
  453|   130k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (453:9): [True: 468, False: 130k]
  ------------------
  454|    468|        if (!ss->ssl3.fatalAlertSent) {
  ------------------
  |  Branch (454:13): [True: 100, False: 368]
  ------------------
  455|       |            /* Send an alert if the handler didn't already. */
  456|    100|            (void)SSL3_SendAlert(ss, alert_fatal, alert);
  457|    100|        }
  458|    468|        return SECFailure;
  459|    468|    }
  460|       |
  461|   130k|    return SECSuccess;
  462|   130k|}

ssl3_HandleServerNameXtn:
   97|  11.3k|{
   98|  11.3k|    SECItem *names = NULL;
   99|  11.3k|    PRUint32 listLenBytes = 0;
  100|  11.3k|    SECStatus rv;
  101|       |
  102|  11.3k|    if (!ss->sec.isServer) {
  ------------------
  |  Branch (102:9): [True: 0, False: 11.3k]
  ------------------
  103|      0|        return SECSuccess; /* ignore extension */
  104|      0|    }
  105|       |
  106|       |    /* Server side - consume client data and register server sender. */
  107|       |    /* do not parse the data if don't have user extension handling function. */
  108|  11.3k|    if (!ss->sniSocketConfig) {
  ------------------
  |  Branch (108:9): [True: 11.3k, False: 0]
  ------------------
  109|  11.3k|        return SECSuccess;
  110|  11.3k|    }
  111|       |
  112|       |    /* length of server_name_list */
  113|      0|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &listLenBytes, 2, &data->data, &data->len);
  114|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (114:9): [True: 0, False: 0]
  ------------------
  115|      0|        goto loser; /* alert already sent */
  116|      0|    }
  117|      0|    if (listLenBytes == 0 || listLenBytes != data->len) {
  ------------------
  |  Branch (117:9): [True: 0, False: 0]
  |  Branch (117:30): [True: 0, False: 0]
  ------------------
  118|      0|        goto alert_loser;
  119|      0|    }
  120|       |
  121|       |    /* Read ServerNameList. */
  122|      0|    while (data->len > 0) {
  ------------------
  |  Branch (122:12): [True: 0, False: 0]
  ------------------
  123|      0|        SECItem tmp;
  124|      0|        PRUint32 type;
  125|       |
  126|       |        /* Read Name Type. */
  127|      0|        rv = ssl3_ExtConsumeHandshakeNumber(ss, &type, 1, &data->data, &data->len);
  128|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (128:13): [True: 0, False: 0]
  ------------------
  129|       |            /* alert sent in ConsumeHandshakeNumber */
  130|      0|            goto loser;
  131|      0|        }
  132|       |
  133|       |        /* Read ServerName (length and value). */
  134|      0|        rv = ssl3_ExtConsumeHandshakeVariable(ss, &tmp, 2, &data->data, &data->len);
  135|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (135:13): [True: 0, False: 0]
  ------------------
  136|      0|            goto loser;
  137|      0|        }
  138|       |
  139|       |        /* Record the value for host_name(0). */
  140|      0|        if (type == sni_nametype_hostname) {
  ------------------
  |  Branch (140:13): [True: 0, False: 0]
  ------------------
  141|       |            /* Fail if we encounter a second host_name entry. */
  142|      0|            if (names) {
  ------------------
  |  Branch (142:17): [True: 0, False: 0]
  ------------------
  143|      0|                goto alert_loser;
  144|      0|            }
  145|       |
  146|       |            /* Create an array for the only supported NameType. */
  147|      0|            names = PORT_ZNewArray(SECItem, 1);
  ------------------
  |  |  159|      0|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  148|      0|            if (!names) {
  ------------------
  |  Branch (148:17): [True: 0, False: 0]
  ------------------
  149|      0|                goto loser;
  150|      0|            }
  151|       |
  152|       |            /* Copy ServerName into the array. */
  153|      0|            if (SECITEM_CopyItem(NULL, &names[0], &tmp) != SECSuccess) {
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (153:17): [True: 0, False: 0]
  ------------------
  154|      0|                goto loser;
  155|      0|            }
  156|      0|        }
  157|       |
  158|       |        /* Even if we don't support NameTypes other than host_name at the
  159|       |         * moment, we continue parsing the whole list to check its validity.
  160|       |         * We do not check for duplicate entries with NameType != host_name(0).
  161|       |         */
  162|      0|    }
  163|      0|    if (names) {
  ------------------
  |  Branch (163:9): [True: 0, False: 0]
  ------------------
  164|       |        /* Free old and set the new data. */
  165|      0|        ssl3_FreeSniNameArray(xtnData);
  166|      0|        xtnData->sniNameArr = names;
  167|      0|        xtnData->sniNameArrSize = 1;
  168|      0|        xtnData->negotiated[xtnData->numNegotiated++] = ssl_server_name_xtn;
  169|      0|    }
  170|      0|    return SECSuccess;
  171|       |
  172|      0|alert_loser:
  173|      0|    ssl3_ExtDecodeError(ss);
  174|      0|loser:
  175|      0|    if (names) {
  ------------------
  |  Branch (175:9): [True: 0, False: 0]
  ------------------
  176|      0|        PORT_Free(names);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  177|      0|    }
  178|      0|    return SECFailure;
  179|      0|}
ssl3_FreeSniNameArray:
  184|   100k|{
  185|   100k|    PRUint32 i;
  186|       |
  187|   100k|    if (!xtnData->sniNameArr) {
  ------------------
  |  Branch (187:9): [True: 100k, False: 0]
  ------------------
  188|   100k|        return;
  189|   100k|    }
  190|       |
  191|      0|    for (i = 0; i < xtnData->sniNameArrSize; i++) {
  ------------------
  |  Branch (191:17): [True: 0, False: 0]
  ------------------
  192|      0|        SECITEM_FreeItem(&xtnData->sniNameArr[i], PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&xtnData->sniNameArr[i], PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  193|      0|    }
  194|       |
  195|      0|    PORT_Free(xtnData->sniNameArr);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  196|      0|    xtnData->sniNameArr = NULL;
  197|      0|    xtnData->sniNameArrSize = 0;
  198|      0|}
ssl3_ServerHandleAppProtoXtn:
  356|     66|{
  357|     66|    PRUint32 count;
  358|     66|    SECStatus rv;
  359|       |
  360|       |    /* We expressly don't want to allow ALPN on renegotiation,
  361|       |     * despite it being permitted by the spec. */
  362|     66|    if (ss->firstHsDone || data->len == 0) {
  ------------------
  |  Branch (362:9): [True: 3, False: 63]
  |  Branch (362:28): [True: 1, False: 62]
  ------------------
  363|       |        /* Clients MUST send a non-empty ALPN extension. */
  364|      4|        ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
  365|      4|        PORT_SetError(SSL_ERROR_NEXT_PROTOCOL_DATA_INVALID);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
  366|      4|        return SECFailure;
  367|      4|    }
  368|       |
  369|       |    /* ALPN has extra redundant length information so that
  370|       |     * the extension is the same in both ClientHello and ServerHello. */
  371|     62|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &count, 2, &data->data, &data->len);
  372|     62|    if (rv != SECSuccess || count != data->len) {
  ------------------
  |  Branch (372:9): [True: 1, False: 61]
  |  Branch (372:29): [True: 24, False: 37]
  ------------------
  373|     25|        ssl3_ExtDecodeError(ss);
  374|     25|        return SECFailure;
  375|     25|    }
  376|       |
  377|     37|    if (!ss->nextProtoCallback) {
  ------------------
  |  Branch (377:9): [True: 37, False: 0]
  ------------------
  378|       |        /* we're not configured for it */
  379|     37|        return SECSuccess;
  380|     37|    }
  381|       |
  382|      0|    rv = ssl3_SelectAppProtocol(ss, xtnData, ssl_app_layer_protocol_xtn, data);
  383|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (383:9): [True: 0, False: 0]
  ------------------
  384|      0|        return rv;
  385|      0|    }
  386|       |
  387|       |    /* prepare to send back a response, if we negotiated */
  388|      0|    if (xtnData->nextProtoState == SSL_NEXT_PROTO_NEGOTIATED) {
  ------------------
  |  Branch (388:9): [True: 0, False: 0]
  ------------------
  389|      0|        rv = ssl3_RegisterExtensionSender(ss, xtnData,
  390|      0|                                          ssl_app_layer_protocol_xtn,
  391|      0|                                          ssl3_ServerSendAppProtoXtn);
  392|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (392:13): [True: 0, False: 0]
  ------------------
  393|      0|            ssl3_ExtSendAlert(ss, alert_fatal, internal_error);
  394|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  395|      0|            return rv;
  396|      0|        }
  397|      0|    }
  398|      0|    return SECSuccess;
  399|      0|}
ssl3_ServerHandleStatusRequestXtn:
  525|  10.1k|{
  526|  10.1k|    sslExtensionBuilderFunc sender;
  527|       |
  528|  10.1k|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|  10.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  10.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 10.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  529|       |
  530|       |    /* remember that we got this extension. */
  531|  10.1k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_cert_status_xtn;
  532|       |
  533|  10.1k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  10.1k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (533:9): [True: 60, False: 10.0k]
  ------------------
  534|     60|        sender = tls13_ServerSendStatusRequestXtn;
  535|  10.0k|    } else {
  536|  10.0k|        sender = ssl3_ServerSendStatusRequestXtn;
  537|  10.0k|    }
  538|  10.1k|    return ssl3_RegisterExtensionSender(ss, xtnData, ssl_cert_status_xtn, sender);
  539|  10.1k|}
ssl3_ServerSendStatusRequestXtn:
  544|  10.0k|{
  545|  10.0k|    const sslServerCert *serverCert = ss->sec.serverCert;
  546|       |
  547|  10.0k|    if (!serverCert->certStatusArray ||
  ------------------
  |  Branch (547:9): [True: 10.0k, False: 0]
  ------------------
  548|  10.0k|        !serverCert->certStatusArray->len) {
  ------------------
  |  Branch (548:9): [True: 0, False: 0]
  ------------------
  549|  10.0k|        return SECSuccess;
  550|  10.0k|    }
  551|       |
  552|      0|    *added = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  553|      0|    return SECSuccess;
  554|  10.0k|}
ssl3_EncodeSessionTicket:
  622|  3.63k|{
  623|  3.63k|    SECStatus rv;
  624|  3.63k|    sslBuffer plaintext = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  3.63k|    {                        \
  |  |   24|  3.63k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  3.63k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  3.63k|    }
  ------------------
  625|  3.63k|    SECItem ticket_buf = { 0, NULL, 0 };
  626|  3.63k|    sslSessionID sid;
  627|  3.63k|    unsigned char wrapped_ms[SSL3_MASTER_SECRET_LENGTH];
  628|  3.63k|    SECItem ms_item = { 0, NULL, 0 };
  629|  3.63k|    PRTime now;
  630|  3.63k|    SECItem *srvName = NULL;
  631|  3.63k|    CK_MECHANISM_TYPE msWrapMech;
  632|  3.63k|    SECItem *alpnSelection = NULL;
  633|  3.63k|    PRUint32 ticketAgeBaseline;
  634|       |
  635|  3.63k|    SSL_TRC(3, ("%d: SSL3[%d]: send session_ticket handshake",
  ------------------
  |  |   71|  3.63k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 3.63k]
  |  |  ------------------
  |  |   72|  3.63k|    ssl_Trace b
  ------------------
  636|  3.63k|                SSL_GETPID(), ss->fd));
  637|       |
  638|  3.63k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.62k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.65k, False: 1.98k]
  |  |  |  |  |  Branch (208:7): [True: 1.98k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  639|  3.63k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.62k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.65k, False: 1.98k]
  |  |  |  |  |  Branch (208:7): [True: 1.98k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  640|       |
  641|       |    /* Extract the master secret wrapped. */
  642|       |
  643|  3.63k|    PORT_Memset(&sid, 0, sizeof(sslSessionID));
  ------------------
  |  |  182|  3.63k|#define PORT_Memset memset
  ------------------
  644|       |
  645|  3.63k|    PORT_Assert(secret);
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  646|  3.63k|    rv = ssl3_CacheWrappedSecret(ss, &sid, secret);
  647|  3.63k|    if (rv == SECSuccess) {
  ------------------
  |  Branch (647:9): [True: 3.63k, False: 0]
  ------------------
  648|  3.63k|        if (sid.u.ssl3.keys.wrapped_master_secret_len > sizeof(wrapped_ms))
  ------------------
  |  Branch (648:13): [True: 0, False: 3.63k]
  ------------------
  649|      0|            goto loser;
  650|  3.63k|        memcpy(wrapped_ms, sid.u.ssl3.keys.wrapped_master_secret,
  651|  3.63k|               sid.u.ssl3.keys.wrapped_master_secret_len);
  652|  3.63k|        ms_item.data = wrapped_ms;
  653|  3.63k|        ms_item.len = sid.u.ssl3.keys.wrapped_master_secret_len;
  654|  3.63k|        msWrapMech = sid.u.ssl3.masterWrapMech;
  655|  3.63k|    } else {
  656|       |        /* TODO: else send an empty ticket. */
  657|      0|        goto loser;
  658|      0|    }
  659|       |    /* Prep to send negotiated name */
  660|  3.63k|    srvName = &ss->sec.ci.sid->u.ssl3.srvName;
  661|       |
  662|       |    /* ticket version */
  663|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, TLS_EX_SESS_TICKET_VERSION,
  ------------------
  |  |  613|  3.63k|#define TLS_EX_SESS_TICKET_VERSION (0x010a)
  ------------------
  664|  3.63k|                                sizeof(PRUint16));
  665|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (665:9): [True: 0, False: 3.63k]
  ------------------
  666|      0|        goto loser;
  667|       |
  668|       |    /* ssl_version */
  669|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->version,
  670|  3.63k|                                sizeof(SSL3ProtocolVersion));
  671|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (671:9): [True: 0, False: 3.63k]
  ------------------
  672|      0|        goto loser;
  673|       |
  674|       |    /* ciphersuite */
  675|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->ssl3.hs.cipher_suite,
  676|  3.63k|                                sizeof(ssl3CipherSuite));
  677|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (677:9): [True: 0, False: 3.63k]
  ------------------
  678|      0|        goto loser;
  679|       |
  680|       |    /* cipher spec parameters */
  681|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->sec.authType, 1);
  682|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (682:9): [True: 0, False: 3.63k]
  ------------------
  683|      0|        goto loser;
  684|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->sec.authKeyBits, 4);
  685|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (685:9): [True: 0, False: 3.63k]
  ------------------
  686|      0|        goto loser;
  687|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->sec.keaType, 1);
  688|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (688:9): [True: 0, False: 3.63k]
  ------------------
  689|      0|        goto loser;
  690|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->sec.keaKeyBits, 4);
  691|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (691:9): [True: 0, False: 3.63k]
  ------------------
  692|      0|        goto loser;
  693|  3.63k|    if (ss->sec.keaGroup) {
  ------------------
  |  Branch (693:9): [True: 3.59k, False: 42]
  ------------------
  694|  3.59k|        rv = sslBuffer_AppendNumber(&plaintext, ss->sec.keaGroup->name, 4);
  695|  3.59k|        if (rv != SECSuccess)
  ------------------
  |  Branch (695:13): [True: 0, False: 3.59k]
  ------------------
  696|      0|            goto loser;
  697|  3.59k|    } else {
  698|       |        /* No kea group. Write 0 as invalid value. */
  699|     42|        rv = sslBuffer_AppendNumber(&plaintext, 0, 4);
  700|     42|        if (rv != SECSuccess)
  ------------------
  |  Branch (700:13): [True: 0, False: 42]
  ------------------
  701|      0|            goto loser;
  702|     42|    }
  703|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->sec.signatureScheme, 4);
  704|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (704:9): [True: 0, False: 3.63k]
  ------------------
  705|      0|        goto loser;
  706|       |
  707|       |    /* certificate type */
  708|  3.63k|    PORT_Assert(SSL_CERT_IS(ss->sec.serverCert, ss->sec.authType));
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  709|  3.63k|    if (SSL_CERT_IS_EC(ss->sec.serverCert)) {
  ------------------
  |  |   56|  3.63k|    ((c)->authTypes & ((1 << ssl_auth_ecdsa) |    \
  |  |  ------------------
  |  |  |  Branch (56:5): [True: 205, False: 3.43k]
  |  |  ------------------
  |  |   57|  3.63k|                       (1 << ssl_auth_ecdh_rsa) | \
  |  |   58|  3.63k|                       (1 << ssl_auth_ecdh_ecdsa)))
  ------------------
  710|    205|        const sslServerCert *cert = ss->sec.serverCert;
  711|    205|        PORT_Assert(cert->namedCurve);
  ------------------
  |  |  120|    205|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    205|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 205, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  712|       |        /* EC curves only use the second of the two bytes. */
  713|    205|        PORT_Assert(cert->namedCurve->name < 256);
  ------------------
  |  |  120|    205|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    205|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 205, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  714|    205|        rv = sslBuffer_AppendNumber(&plaintext, cert->namedCurve->name, 1);
  715|  3.43k|    } else {
  716|  3.43k|        rv = sslBuffer_AppendNumber(&plaintext, 0, 1);
  717|  3.43k|    }
  718|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (718:9): [True: 0, False: 3.63k]
  ------------------
  719|      0|        goto loser;
  720|       |
  721|       |    /* master_secret */
  722|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, msWrapMech, 4);
  723|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (723:9): [True: 0, False: 3.63k]
  ------------------
  724|      0|        goto loser;
  725|  3.63k|    rv = sslBuffer_AppendVariable(&plaintext, ms_item.data, ms_item.len, 2);
  726|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (726:9): [True: 0, False: 3.63k]
  ------------------
  727|      0|        goto loser;
  728|       |
  729|       |    /* client identity */
  730|  3.63k|    if (ss->opt.requestCertificate && ss->sec.ci.sid->peerCert) {
  ------------------
  |  Branch (730:9): [True: 194, False: 3.44k]
  |  Branch (730:39): [True: 14, False: 180]
  ------------------
  731|     14|        rv = sslBuffer_AppendNumber(&plaintext, CLIENT_AUTH_CERTIFICATE, 1);
  732|     14|        if (rv != SECSuccess)
  ------------------
  |  Branch (732:13): [True: 0, False: 14]
  ------------------
  733|      0|            goto loser;
  734|     14|        rv = sslBuffer_AppendVariable(&plaintext,
  735|     14|                                      ss->sec.ci.sid->peerCert->derCert.data,
  736|     14|                                      ss->sec.ci.sid->peerCert->derCert.len, 2);
  737|     14|        if (rv != SECSuccess)
  ------------------
  |  Branch (737:13): [True: 0, False: 14]
  ------------------
  738|      0|            goto loser;
  739|  3.62k|    } else {
  740|  3.62k|        rv = sslBuffer_AppendNumber(&plaintext, 0, 1);
  741|  3.62k|        if (rv != SECSuccess)
  ------------------
  |  Branch (741:13): [True: 0, False: 3.62k]
  ------------------
  742|      0|            goto loser;
  743|  3.62k|    }
  744|       |
  745|       |    /* timestamp */
  746|  3.63k|    now = ssl_Time(ss);
  747|  3.63k|    PORT_Assert(sizeof(now) == 8);
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  748|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, now, 8);
  749|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (749:9): [True: 0, False: 3.63k]
  ------------------
  750|      0|        goto loser;
  751|       |
  752|       |    /* HostName (length and value) */
  753|  3.63k|    rv = sslBuffer_AppendVariable(&plaintext, srvName->data, srvName->len, 2);
  754|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (754:9): [True: 0, False: 3.63k]
  ------------------
  755|      0|        goto loser;
  756|       |
  757|       |    /* extendedMasterSecretUsed */
  758|  3.63k|    rv = sslBuffer_AppendNumber(
  759|  3.63k|        &plaintext, ss->sec.ci.sid->u.ssl3.keys.extendedMasterSecretUsed, 1);
  760|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (760:9): [True: 0, False: 3.63k]
  ------------------
  761|      0|        goto loser;
  762|       |
  763|       |    /* Flags */
  764|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ticket->flags,
  765|  3.63k|                                sizeof(ticket->flags));
  766|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (766:9): [True: 0, False: 3.63k]
  ------------------
  767|      0|        goto loser;
  768|       |
  769|       |    /* ALPN value. */
  770|  3.63k|    PORT_Assert(ss->xtnData.nextProtoState == SSL_NEXT_PROTO_SELECTED ||
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 3.63k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 3.63k]
  |  |  |  |  |  Branch (208:7): [True: 3.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  771|  3.63k|                ss->xtnData.nextProtoState == SSL_NEXT_PROTO_NEGOTIATED ||
  772|  3.63k|                ss->xtnData.nextProto.len == 0);
  773|  3.63k|    alpnSelection = &ss->xtnData.nextProto;
  774|  3.63k|    PORT_Assert(alpnSelection->len < 256);
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  775|  3.63k|    rv = sslBuffer_AppendVariable(&plaintext, alpnSelection->data,
  776|  3.63k|                                  alpnSelection->len, 1);
  777|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (777:9): [True: 0, False: 3.63k]
  ------------------
  778|      0|        goto loser;
  779|       |
  780|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ss->opt.maxEarlyDataSize, 4);
  781|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (781:9): [True: 0, False: 3.63k]
  ------------------
  782|      0|        goto loser;
  783|       |
  784|       |    /*
  785|       |     * We store this in the ticket:
  786|       |     *    ticket_age_baseline = 1rtt - ticket_age_add
  787|       |     *
  788|       |     * When the client resumes, it will provide:
  789|       |     *    obfuscated_age = ticket_age_client + ticket_age_add
  790|       |     *
  791|       |     * We expect to receive the ticket at:
  792|       |     *    ticket_create + 1rtt + ticket_age_server
  793|       |     *
  794|       |     * We calculate the client's estimate of this as:
  795|       |     *    ticket_create + ticket_age_baseline + obfuscated_age
  796|       |     *    = ticket_create + 1rtt + ticket_age_client
  797|       |     *
  798|       |     * This is compared to the expected time, which should differ only as a
  799|       |     * result of clock errors or errors in the RTT estimate.
  800|       |     */
  801|  3.63k|    ticketAgeBaseline = ss->ssl3.hs.rttEstimate / PR_USEC_PER_MSEC;
  ------------------
  |  |   30|  3.63k|#define PR_USEC_PER_MSEC    1000L
  ------------------
  802|  3.63k|    ticketAgeBaseline -= ticket->ticket_age_add;
  803|  3.63k|    rv = sslBuffer_AppendNumber(&plaintext, ticketAgeBaseline, 4);
  804|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (804:9): [True: 0, False: 3.63k]
  ------------------
  805|      0|        goto loser;
  806|       |
  807|       |    /* Application token */
  808|  3.63k|    rv = sslBuffer_AppendVariable(&plaintext, appToken, appTokenLen, 2);
  809|  3.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (809:9): [True: 0, False: 3.63k]
  ------------------
  810|      0|        goto loser;
  811|       |
  812|       |    /* This really only happens if appTokenLen is too much, and that always
  813|       |     * comes from the using application. */
  814|  3.63k|    if (SSL_BUFFER_LEN(&plaintext) > 0xffff) {
  ------------------
  |  |   36|  3.63k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
  |  Branch (814:9): [True: 0, False: 3.63k]
  ------------------
  815|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  816|      0|        goto loser;
  817|      0|    }
  818|       |
  819|  3.63k|    ticket_buf.len = ssl_SelfEncryptGetProtectedSize(SSL_BUFFER_LEN(&plaintext));
  ------------------
  |  |   36|  3.63k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
  820|  3.63k|    PORT_Assert(ticket_buf.len > 0);
  ------------------
  |  |  120|  3.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  821|  3.63k|    if (SECITEM_AllocItem(NULL, &ticket_buf, ticket_buf.len) == NULL) {
  ------------------
  |  |  103|  3.63k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (821:9): [True: 0, False: 3.63k]
  ------------------
  822|      0|        goto loser;
  823|      0|    }
  824|       |
  825|       |    /* Finally, encrypt the ticket. */
  826|  3.63k|    rv = ssl_SelfEncryptProtect(ss, SSL_BUFFER_BASE(&plaintext),
  ------------------
  |  |   35|  3.63k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
  827|  3.63k|                                SSL_BUFFER_LEN(&plaintext),
  ------------------
  |  |   36|  3.63k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
  828|  3.63k|                                ticket_buf.data, &ticket_buf.len, ticket_buf.len);
  829|  3.63k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (829:9): [True: 0, False: 3.63k]
  ------------------
  830|      0|        goto loser;
  831|      0|    }
  832|       |
  833|       |    /* Give ownership of memory to caller. */
  834|  3.63k|    *ticket_data = ticket_buf;
  835|       |
  836|  3.63k|    sslBuffer_Clear(&plaintext);
  837|  3.63k|    return SECSuccess;
  838|       |
  839|      0|loser:
  840|      0|    sslBuffer_Clear(&plaintext);
  841|      0|    if (ticket_buf.data) {
  ------------------
  |  Branch (841:9): [True: 0, False: 0]
  ------------------
  842|      0|        SECITEM_FreeItem(&ticket_buf, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&ticket_buf, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  843|      0|    }
  844|       |
  845|      0|    return SECFailure;
  846|  3.63k|}
ssl3_ProcessSessionTicketCommon:
 1210|    316|{
 1211|    316|    SECItem decryptedTicket = { siBuffer, NULL, 0 };
 1212|    316|    SessionTicket parsedTicket;
 1213|    316|    sslSessionID *sid = NULL;
 1214|    316|    SECStatus rv;
 1215|       |
 1216|    316|    if (ss->sec.ci.sid != NULL) {
  ------------------
  |  Branch (1216:9): [True: 77, False: 239]
  ------------------
 1217|     77|        ssl_UncacheSessionID(ss);
 1218|     77|        ssl_FreeSID(ss->sec.ci.sid);
 1219|     77|        ss->sec.ci.sid = NULL;
 1220|     77|    }
 1221|       |
 1222|    316|    if (!SECITEM_AllocItem(NULL, &decryptedTicket, ticket->len)) {
  ------------------
  |  |  103|    316|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (1222:9): [True: 0, False: 316]
  ------------------
 1223|      0|        return SECFailure;
 1224|      0|    }
 1225|       |
 1226|       |    /* Decrypt the ticket. */
 1227|    316|    rv = ssl_SelfEncryptUnprotect(ss, ticket->data, ticket->len,
 1228|    316|                                  decryptedTicket.data,
 1229|    316|                                  &decryptedTicket.len,
 1230|    316|                                  decryptedTicket.len);
 1231|    316|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1231:9): [True: 0, False: 316]
  ------------------
 1232|       |        /* Ignore decryption failure if we are doing TLS 1.3; that
 1233|       |         * means the server rejects the client's resumption
 1234|       |         * attempt. In TLS 1.2, however, it's a hard failure, unless
 1235|       |         * it's just because we're not the recipient of the ticket. */
 1236|      0|        if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 ||
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1236:13): [True: 0, False: 0]
  ------------------
 1237|      0|            PORT_GetError() == SEC_ERROR_NOT_A_RECIPIENT) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (1237:13): [True: 0, False: 0]
  ------------------
 1238|      0|            SECITEM_ZfreeItem(&decryptedTicket, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(&decryptedTicket, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1239|      0|            return SECSuccess;
 1240|      0|        }
 1241|       |
 1242|      0|        SSL3_SendAlert(ss, alert_fatal, illegal_parameter);
 1243|      0|        goto loser;
 1244|      0|    }
 1245|       |
 1246|    316|    rv = ssl_ParseSessionTicket(ss, &decryptedTicket, &parsedTicket);
 1247|    316|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1247:9): [True: 65, False: 251]
  ------------------
 1248|     65|        SSL3Statistics *ssl3stats;
 1249|       |
 1250|     65|        SSL_DBG(("%d: SSL[%d]: Session ticket parsing failed.",
  ------------------
  |  |   87|     65|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 65]
  |  |  ------------------
  |  |   88|     65|    ssl_Trace b
  ------------------
 1251|     65|                 SSL_GETPID(), ss->fd));
 1252|     65|        ssl3stats = SSL_GetStatistics();
 1253|     65|        SSL_AtomicIncrementLong(&ssl3stats->hch_sid_ticket_parse_failures);
 1254|     65|        goto loser; /* code already set */
 1255|     65|    }
 1256|       |
 1257|       |    /* Use the ticket if it is valid and unexpired. */
 1258|    251|    PRTime end = parsedTicket.timestamp + (ssl_ticket_lifetime * PR_USEC_PER_SEC);
  ------------------
  |  |   28|    251|#define PR_USEC_PER_SEC     1000000L
  ------------------
 1259|    251|    if (end > ssl_Time(ss)) {
  ------------------
  |  Branch (1259:9): [True: 231, False: 20]
  ------------------
 1260|       |
 1261|    231|        rv = ssl_CreateSIDFromTicket(ss, ticket, &parsedTicket, &sid);
 1262|    231|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1262:13): [True: 3, False: 228]
  ------------------
 1263|      3|            goto loser; /* code already set */
 1264|      3|        }
 1265|    228|        if (appToken && parsedTicket.applicationToken.len) {
  ------------------
  |  Branch (1265:13): [True: 107, False: 121]
  |  Branch (1265:25): [True: 31, False: 76]
  ------------------
 1266|     31|            rv = SECITEM_CopyItem(NULL, appToken,
  ------------------
  |  |  106|     31|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1267|     31|                                  &parsedTicket.applicationToken);
 1268|     31|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1268:17): [True: 0, False: 31]
  ------------------
 1269|      0|                goto loser; /* code already set */
 1270|      0|            }
 1271|     31|        }
 1272|       |
 1273|    228|        ss->statelessResume = PR_TRUE;
  ------------------
  |  |  437|    228|#define PR_TRUE 1
  ------------------
 1274|    228|        ss->sec.ci.sid = sid;
 1275|       |
 1276|       |        /* We have the baseline value for the obfuscated ticket age here.  Save
 1277|       |         * that in xtnData temporarily.  This value is updated in
 1278|       |         * tls13_ServerHandlePreSharedKeyXtn with the final estimate. */
 1279|    228|        ss->xtnData.ticketAge = parsedTicket.ticketAgeBaseline;
 1280|    228|    }
 1281|       |
 1282|    248|    SECITEM_ZfreeItem(&decryptedTicket, PR_FALSE);
  ------------------
  |  |  110|    248|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                  SECITEM_ZfreeItem(&decryptedTicket, PR_FALSE);
  ------------------
  |  |  438|    248|#define PR_FALSE 0
  ------------------
 1283|    248|    PORT_Memset(&parsedTicket, 0, sizeof(parsedTicket));
  ------------------
  |  |  182|    248|#define PORT_Memset memset
  ------------------
 1284|    248|    return SECSuccess;
 1285|       |
 1286|     68|loser:
 1287|     68|    if (sid) {
  ------------------
  |  Branch (1287:9): [True: 0, False: 68]
  ------------------
 1288|      0|        ssl_FreeSID(sid);
 1289|      0|    }
 1290|     68|    SECITEM_ZfreeItem(&decryptedTicket, PR_FALSE);
  ------------------
  |  |  110|     68|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                  SECITEM_ZfreeItem(&decryptedTicket, PR_FALSE);
  ------------------
  |  |  438|     68|#define PR_FALSE 0
  ------------------
 1291|     68|    PORT_Memset(&parsedTicket, 0, sizeof(parsedTicket));
  ------------------
  |  |  182|     68|#define PORT_Memset memset
  ------------------
 1292|     68|    return SECFailure;
 1293|    251|}
ssl3_ServerHandleSessionTicketXtn:
 1298|  5.49k|{
 1299|  5.49k|    PORT_Assert(ss->version < SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  5.49k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  5.49k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5.49k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1300|       |
 1301|       |    /* Ignore the SessionTicket extension if processing is disabled. */
 1302|  5.49k|    if (!ss->opt.enableSessionTickets) {
  ------------------
  |  Branch (1302:9): [True: 1.90k, False: 3.58k]
  ------------------
 1303|  1.90k|        return SECSuccess;
 1304|  1.90k|    }
 1305|       |
 1306|       |    /* If we are doing TLS 1.3, then ignore this. */
 1307|  3.58k|    if (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  3.58k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1307:9): [True: 0, False: 3.58k]
  ------------------
 1308|      0|        return SECSuccess;
 1309|      0|    }
 1310|       |
 1311|       |    /* Keep track of negotiated extensions. */
 1312|  3.58k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_session_ticket_xtn;
 1313|       |
 1314|       |    /* Parse the received ticket sent in by the client.  We are
 1315|       |     * lenient about some parse errors, falling back to a fullshake
 1316|       |     * instead of terminating the current connection.
 1317|       |     */
 1318|  3.58k|    if (data->len == 0) {
  ------------------
  |  Branch (1318:9): [True: 3.46k, False: 121]
  ------------------
 1319|  3.46k|        xtnData->emptySessionTicket = PR_TRUE;
  ------------------
  |  |  437|  3.46k|#define PR_TRUE 1
  ------------------
 1320|  3.46k|        return SECSuccess;
 1321|  3.46k|    }
 1322|       |
 1323|    121|    return ssl3_ProcessSessionTicketCommon(CONST_CAST(sslSocket, ss), data,
  ------------------
  |  |   96|    121|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
 1324|    121|                                           NULL);
 1325|  3.58k|}
ssl3_SendRenegotiationInfoXtn:
 1337|  1.56k|{
 1338|  1.56k|    PRInt32 len = 0;
 1339|  1.56k|    SECStatus rv;
 1340|       |
 1341|       |    /* In RFC 5746, it is NOT RECOMMENDED to send both the SCSV and the empty
 1342|       |     * RI, so when we send SCSV in the initial handshake, we don't also send RI.
 1343|       |     */
 1344|  1.56k|    if (ss->ssl3.hs.sendingSCSV) {
  ------------------
  |  Branch (1344:9): [True: 0, False: 1.56k]
  ------------------
 1345|      0|        return 0;
 1346|      0|    }
 1347|  1.56k|    if (ss->firstHsDone) {
  ------------------
  |  Branch (1347:9): [True: 0, False: 1.56k]
  ------------------
 1348|      0|        len = ss->sec.isServer ? ss->ssl3.hs.finishedBytes * 2
  ------------------
  |  Branch (1348:15): [True: 0, False: 0]
  ------------------
 1349|      0|                               : ss->ssl3.hs.finishedBytes;
 1350|      0|    }
 1351|       |
 1352|       |    /* verify_Data from previous Finished message(s) */
 1353|  1.56k|    rv = sslBuffer_AppendVariable(buf,
 1354|  1.56k|                                  ss->ssl3.hs.finishedMsgs.data, len, 1);
 1355|  1.56k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1355:9): [True: 0, False: 1.56k]
  ------------------
 1356|      0|        return SECFailure;
 1357|      0|    }
 1358|       |
 1359|  1.56k|    *added = PR_TRUE;
  ------------------
  |  |  437|  1.56k|#define PR_TRUE 1
  ------------------
 1360|  1.56k|    return SECSuccess;
 1361|  1.56k|}
ssl3_HandleRenegotiationInfoXtn:
 1367|  1.60k|{
 1368|  1.60k|    SECStatus rv = SECSuccess;
 1369|  1.60k|    PRUint32 len = 0;
 1370|       |
 1371|  1.60k|    PORT_Assert(ss->version < SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  1.60k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.60k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.60k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1372|       |
 1373|  1.60k|    if (ss->firstHsDone) {
  ------------------
  |  Branch (1373:9): [True: 19, False: 1.58k]
  ------------------
 1374|     19|        len = ss->sec.isServer ? ss->ssl3.hs.finishedBytes
  ------------------
  |  Branch (1374:15): [True: 19, False: 0]
  ------------------
 1375|     19|                               : ss->ssl3.hs.finishedBytes * 2;
 1376|     19|    }
 1377|  1.60k|    if (data->len != 1 + len || data->data[0] != len) {
  ------------------
  |  Branch (1377:9): [True: 22, False: 1.58k]
  |  Branch (1377:33): [True: 2, False: 1.58k]
  ------------------
 1378|     24|        ssl3_ExtDecodeError(ss);
 1379|     24|        return SECFailure;
 1380|     24|    }
 1381|  1.58k|    if (len && NSS_SecureMemcmp(ss->ssl3.hs.finishedMsgs.data,
  ------------------
  |  Branch (1381:9): [True: 0, False: 1.58k]
  |  Branch (1381:16): [True: 0, False: 0]
  ------------------
 1382|      0|                                data->data + 1, len)) {
 1383|      0|        ssl3_ExtSendAlert(ss, alert_fatal, handshake_failure);
 1384|      0|        PORT_SetError(SSL_ERROR_BAD_HANDSHAKE_HASH_VALUE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1385|      0|        return SECFailure;
 1386|      0|    }
 1387|       |    /* remember that we got this extension and it was correct. */
 1388|  1.58k|    CONST_CAST(sslSocket, ss)
  ------------------
  |  |   96|  1.58k|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
 1389|  1.58k|        ->peerRequestedProtection = 1;
 1390|  1.58k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_renegotiation_info_xtn;
 1391|  1.58k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1391:9): [True: 1.58k, False: 0]
  ------------------
 1392|       |        /* prepare to send back the appropriate response */
 1393|  1.58k|        rv = ssl3_RegisterExtensionSender(ss, xtnData,
 1394|  1.58k|                                          ssl_renegotiation_info_xtn,
 1395|  1.58k|                                          ssl3_SendRenegotiationInfoXtn);
 1396|  1.58k|    }
 1397|  1.58k|    return rv;
 1398|  1.58k|}
ssl3_ServerHandleUseSRTPXtn:
 1533|     21|{
 1534|     21|    SECStatus rv;
 1535|     21|    SECItem ciphers = { siBuffer, NULL, 0 };
 1536|     21|    PRUint16 i;
 1537|     21|    unsigned int j;
 1538|     21|    PRUint16 cipher = 0;
 1539|     21|    PRBool found = PR_FALSE;
  ------------------
  |  |  438|     21|#define PR_FALSE 0
  ------------------
 1540|     21|    SECItem litem;
 1541|       |
 1542|     21|    if (!IS_DTLS(ss) || !ss->ssl3.dtlsSRTPCipherCount) {
  ------------------
  |  |  892|     42|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (1542:9): [True: 21, False: 0]
  |  Branch (1542:25): [True: 0, False: 0]
  ------------------
 1543|       |        /* Ignore the extension if we aren't doing DTLS or no DTLS-SRTP
 1544|       |         * preferences have been set. */
 1545|     21|        return SECSuccess;
 1546|     21|    }
 1547|       |
 1548|      0|    if (!data->data || data->len < 5) {
  ------------------
  |  Branch (1548:9): [True: 0, False: 0]
  |  Branch (1548:24): [True: 0, False: 0]
  ------------------
 1549|      0|        ssl3_ExtDecodeError(ss);
 1550|      0|        return SECFailure;
 1551|      0|    }
 1552|       |
 1553|       |    /* Get the cipher list */
 1554|      0|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &ciphers, 2,
 1555|      0|                                          &data->data, &data->len);
 1556|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1556:9): [True: 0, False: 0]
  ------------------
 1557|      0|        return SECFailure; /* alert already sent */
 1558|      0|    }
 1559|       |    /* Check that the list is even length */
 1560|      0|    if (ciphers.len % 2) {
  ------------------
  |  Branch (1560:9): [True: 0, False: 0]
  ------------------
 1561|      0|        ssl3_ExtDecodeError(ss);
 1562|      0|        return SECFailure;
 1563|      0|    }
 1564|       |
 1565|       |    /* Walk through the offered list and pick the most preferred of our
 1566|       |     * ciphers, if any */
 1567|      0|    for (i = 0; !found && i < ss->ssl3.dtlsSRTPCipherCount; i++) {
  ------------------
  |  Branch (1567:17): [True: 0, False: 0]
  |  Branch (1567:27): [True: 0, False: 0]
  ------------------
 1568|      0|        for (j = 0; j + 1 < ciphers.len; j += 2) {
  ------------------
  |  Branch (1568:21): [True: 0, False: 0]
  ------------------
 1569|      0|            cipher = (ciphers.data[j] << 8) | ciphers.data[j + 1];
 1570|      0|            if (cipher == ss->ssl3.dtlsSRTPCiphers[i]) {
  ------------------
  |  Branch (1570:17): [True: 0, False: 0]
  ------------------
 1571|      0|                found = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1572|      0|                break;
 1573|      0|            }
 1574|      0|        }
 1575|      0|    }
 1576|       |
 1577|       |    /* Get the srtp_mki value */
 1578|      0|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &litem, 1, &data->data, &data->len);
 1579|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1579:9): [True: 0, False: 0]
  ------------------
 1580|      0|        return SECFailure;
 1581|      0|    }
 1582|       |
 1583|      0|    if (data->len != 0) {
  ------------------
  |  Branch (1583:9): [True: 0, False: 0]
  ------------------
 1584|      0|        ssl3_ExtDecodeError(ss); /* trailing bytes */
 1585|      0|        return SECFailure;
 1586|      0|    }
 1587|       |
 1588|       |    /* Now figure out what to do */
 1589|      0|    if (!found) {
  ------------------
  |  Branch (1589:9): [True: 0, False: 0]
  ------------------
 1590|       |        /* No matching ciphers, pretend we don't support use_srtp */
 1591|      0|        return SECSuccess;
 1592|      0|    }
 1593|       |
 1594|       |    /* OK, we have a valid cipher and we've selected it */
 1595|      0|    xtnData->dtlsSRTPCipherSuite = cipher;
 1596|      0|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_use_srtp_xtn;
 1597|       |
 1598|      0|    return ssl3_RegisterExtensionSender(ss, xtnData,
 1599|      0|                                        ssl_use_srtp_xtn,
 1600|      0|                                        ssl3_ServerSendUseSRTPXtn);
 1601|      0|}
ssl3_HandleSigAlgsXtn:
 1609|  9.61k|{
 1610|  9.61k|    SECStatus rv;
 1611|       |
 1612|       |    /* Ignore this extension if we aren't doing TLS 1.2 or greater. */
 1613|  9.61k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|  9.61k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (1613:9): [True: 966, False: 8.64k]
  ------------------
 1614|    966|        return SECSuccess;
 1615|    966|    }
 1616|       |
 1617|  8.64k|    if (xtnData->sigSchemes) {
  ------------------
  |  Branch (1617:9): [True: 0, False: 8.64k]
  ------------------
 1618|      0|        PORT_Free(xtnData->sigSchemes);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1619|      0|        xtnData->sigSchemes = NULL;
 1620|      0|    }
 1621|  8.64k|    rv = ssl_ParseSignatureSchemes(ss, NULL,
 1622|  8.64k|                                   &xtnData->sigSchemes,
 1623|  8.64k|                                   &xtnData->numSigSchemes,
 1624|  8.64k|                                   &data->data, &data->len);
 1625|  8.64k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1625:9): [True: 7, False: 8.63k]
  ------------------
 1626|      7|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1627|      7|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  ------------------
 1628|      7|        return SECFailure;
 1629|      7|    }
 1630|  8.63k|    if (xtnData->numSigSchemes == 0) {
  ------------------
  |  Branch (1630:9): [True: 46, False: 8.59k]
  ------------------
 1631|     46|        ssl3_ExtSendAlert(ss, alert_fatal, handshake_failure);
 1632|     46|        PORT_SetError(SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|     46|#define PORT_SetError PORT_SetError_Util
  ------------------
 1633|     46|        return SECFailure;
 1634|     46|    }
 1635|       |    /* Check for trailing data. */
 1636|  8.59k|    if (data->len != 0) {
  ------------------
  |  Branch (1636:9): [True: 10, False: 8.58k]
  ------------------
 1637|     10|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1638|     10|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|     10|#define PORT_SetError PORT_SetError_Util
  ------------------
 1639|     10|        return SECFailure;
 1640|     10|    }
 1641|       |
 1642|       |    /* Keep track of negotiated extensions. */
 1643|  8.58k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_signature_algorithms_xtn;
 1644|  8.58k|    return SECSuccess;
 1645|  8.59k|}
ssl3_SendSigAlgsXtn:
 1652|    447|{
 1653|    447|    if (ss->vrange.max < SSL_LIBRARY_VERSION_TLS_1_2) {
  ------------------
  |  |   20|    447|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
  |  Branch (1653:9): [True: 0, False: 447]
  ------------------
 1654|      0|        return SECSuccess;
 1655|      0|    }
 1656|       |
 1657|    447|    PRUint16 minVersion;
 1658|    447|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1658:9): [True: 447, False: 0]
  ------------------
 1659|    447|        minVersion = ss->version; /* CertificateRequest */
 1660|    447|    } else {
 1661|      0|        minVersion = ss->vrange.min; /* ClientHello */
 1662|      0|    }
 1663|       |
 1664|    447|    SECStatus rv = ssl3_EncodeSigAlgs(ss, minVersion, PR_TRUE /* forCert */,
  ------------------
  |  |  437|    447|#define PR_TRUE 1
  ------------------
 1665|    447|                                      ss->opt.enableGrease, buf);
 1666|    447|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1666:9): [True: 0, False: 447]
  ------------------
 1667|      0|        return SECFailure;
 1668|      0|    }
 1669|       |
 1670|    447|    *added = PR_TRUE;
  ------------------
  |  |  437|    447|#define PR_TRUE 1
  ------------------
 1671|    447|    return SECSuccess;
 1672|    447|}
ssl3_HandleExtendedMasterSecretXtn:
 1692|  11.4k|{
 1693|  11.4k|    PORT_Assert(ss->version < SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  11.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1694|       |
 1695|  11.4k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_0) {
  ------------------
  |  |   18|  11.4k|#define SSL_LIBRARY_VERSION_TLS_1_0             0x0301
  ------------------
  |  Branch (1695:9): [True: 0, False: 11.4k]
  ------------------
 1696|      0|        return SECSuccess;
 1697|      0|    }
 1698|       |
 1699|  11.4k|    if (!ss->opt.enableExtendedMS) {
  ------------------
  |  Branch (1699:9): [True: 5.32k, False: 6.08k]
  ------------------
 1700|  5.32k|        return SECSuccess;
 1701|  5.32k|    }
 1702|       |
 1703|  6.08k|    if (data->len != 0) {
  ------------------
  |  Branch (1703:9): [True: 1, False: 6.08k]
  ------------------
 1704|      1|        SSL_TRC(30, ("%d: SSL3[%d]: Bogus extended master secret extension",
  ------------------
  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   72|      1|    ssl_Trace b
  ------------------
 1705|      1|                     SSL_GETPID(), ss->fd));
 1706|      1|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1707|      1|        return SECFailure;
 1708|      1|    }
 1709|       |
 1710|  6.08k|    SSL_DBG(("%d: SSL[%d]: Negotiated extended master secret extension.",
  ------------------
  |  |   87|  6.08k|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 6.08k]
  |  |  ------------------
  |  |   88|  6.08k|    ssl_Trace b
  ------------------
 1711|  6.08k|             SSL_GETPID(), ss->fd));
 1712|       |
 1713|       |    /* Keep track of negotiated extensions. */
 1714|  6.08k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_extended_master_secret_xtn;
 1715|       |
 1716|  6.08k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1716:9): [True: 6.08k, False: 0]
  ------------------
 1717|  6.08k|        return ssl3_RegisterExtensionSender(ss, xtnData,
 1718|  6.08k|                                            ssl_extended_master_secret_xtn,
 1719|  6.08k|                                            ssl_SendEmptyExtension);
 1720|  6.08k|    }
 1721|      0|    return SECSuccess;
 1722|  6.08k|}
ssl3_ServerSendSignedCertTimestampXtn:
 1768|  11.3k|{
 1769|  11.3k|    const SECItem *scts = &ss->sec.serverCert->signedCertTimestamps;
 1770|  11.3k|    SECStatus rv;
 1771|       |
 1772|  11.3k|    if (!scts->len) {
  ------------------
  |  Branch (1772:9): [True: 11.3k, False: 0]
  ------------------
 1773|       |        /* No timestamps to send */
 1774|  11.3k|        return SECSuccess;
 1775|  11.3k|    }
 1776|       |
 1777|      0|    rv = sslBuffer_Append(buf, scts->data, scts->len);
 1778|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1778:9): [True: 0, False: 0]
  ------------------
 1779|      0|        return SECFailure;
 1780|      0|    }
 1781|       |
 1782|      0|    *added = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1783|      0|    return SECSuccess;
 1784|      0|}
ssl3_ServerHandleSignedCertTimestampXtn:
 1790|  11.4k|{
 1791|  11.4k|    if (data->len != 0) {
  ------------------
  |  Branch (1791:9): [True: 1, False: 11.4k]
  ------------------
 1792|      1|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1793|      1|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1794|      1|        return SECFailure;
 1795|      1|    }
 1796|       |
 1797|  11.4k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_signed_cert_timestamp_xtn;
 1798|  11.4k|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|  11.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1799|  11.4k|    return ssl3_RegisterExtensionSender(ss, xtnData,
 1800|  11.4k|                                        ssl_signed_cert_timestamp_xtn,
 1801|  11.4k|                                        ssl3_ServerSendSignedCertTimestampXtn);
 1802|  11.4k|}
ssl3_HandleSupportedPointFormatsXtn:
 1811|  7.04k|{
 1812|  7.04k|    int i;
 1813|       |
 1814|  7.04k|    PORT_Assert(ss->version < SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  7.04k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  7.04k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7.04k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1815|       |
 1816|  7.04k|    if (data->len < 2 || data->len > 255 || !data->data ||
  ------------------
  |  Branch (1816:9): [True: 1, False: 7.04k]
  |  Branch (1816:26): [True: 2, False: 7.04k]
  |  Branch (1816:45): [True: 0, False: 7.04k]
  ------------------
 1817|  7.04k|        data->len != (unsigned int)data->data[0] + 1) {
  ------------------
  |  Branch (1817:9): [True: 9, False: 7.03k]
  ------------------
 1818|     12|        ssl3_ExtDecodeError(ss);
 1819|     12|        return SECFailure;
 1820|     12|    }
 1821|  7.43k|    for (i = data->len; --i > 0;) {
  ------------------
  |  Branch (1821:25): [True: 7.43k, False: 4]
  ------------------
 1822|  7.43k|        if (data->data[i] == 0) {
  ------------------
  |  Branch (1822:13): [True: 7.03k, False: 405]
  ------------------
 1823|       |            /* indicate that we should send a reply */
 1824|  7.03k|            return ssl3_RegisterExtensionSender(
 1825|  7.03k|                ss, xtnData, ssl_ec_point_formats_xtn,
 1826|  7.03k|                &ssl3_SendSupportedPointFormatsXtn);
 1827|  7.03k|        }
 1828|  7.43k|    }
 1829|       |
 1830|       |    /* Poor client doesn't support uncompressed points.
 1831|       |     *
 1832|       |     * If the client sends the extension and the extension does not contain the
 1833|       |     * uncompressed point format, and the client has used the Supported Groups
 1834|       |     * extension to indicate support for any of the curves defined in this
 1835|       |     * specification, then the server MUST abort the handshake and return an
 1836|       |     * illegal_parameter alert. [RFC8422, Section 5.1.2] */
 1837|      4|    ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
 1838|      4|    PORT_SetError(SSL_ERROR_RX_MALFORMED_HANDSHAKE);
  ------------------
  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  ------------------
 1839|       |
 1840|      4|    return SECFailure;
 1841|  7.03k|}
ssl_HandleSupportedGroupsXtn:
 1920|  12.7k|{
 1921|  12.7k|    SECStatus rv;
 1922|       |
 1923|  12.7k|    rv = ssl_UpdateSupportedGroups(CONST_CAST(sslSocket, ss), data);
  ------------------
  |  |   96|  12.7k|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
 1924|  12.7k|    if (rv != SECSuccess)
  ------------------
  |  Branch (1924:9): [True: 22, False: 12.7k]
  ------------------
 1925|     22|        return SECFailure;
 1926|       |
 1927|       |    /* TLS 1.3 permits the server to send this extension so make it so. */
 1928|  12.7k|    if (ss->sec.isServer && ss->version >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  12.7k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1928:9): [True: 12.7k, False: 0]
  |  Branch (1928:29): [True: 1.59k, False: 11.1k]
  ------------------
 1929|  1.59k|        rv = ssl3_RegisterExtensionSender(ss, xtnData, ssl_supported_groups_xtn,
 1930|  1.59k|                                          &ssl_SendSupportedGroupsXtn);
 1931|  1.59k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1931:13): [True: 0, False: 1.59k]
  ------------------
 1932|      0|            return SECFailure; /* error already set. */
 1933|      0|        }
 1934|  1.59k|    }
 1935|       |
 1936|       |    /* Remember that we negotiated this extension. */
 1937|  12.7k|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_supported_groups_xtn;
 1938|       |
 1939|  12.7k|    return SECSuccess;
 1940|  12.7k|}
ssl_HandleRecordSizeLimitXtn:
 1945|    684|{
 1946|    684|    SECStatus rv;
 1947|    684|    PRUint32 limit;
 1948|    684|    PRUint32 maxLimit = (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3)
  ------------------
  |  |   21|    684|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1948:25): [True: 626, False: 58]
  ------------------
 1949|    684|                            ? (MAX_FRAGMENT_LENGTH + 1)
  ------------------
  |  |   35|    626|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 1950|    684|                            : MAX_FRAGMENT_LENGTH;
  ------------------
  |  |   35|    742|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 1951|       |
 1952|    684|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &limit, 2, &data->data, &data->len);
 1953|    684|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1953:9): [True: 1, False: 683]
  ------------------
 1954|      1|        return SECFailure;
 1955|      1|    }
 1956|    683|    if (data->len != 0 || limit < 64) {
  ------------------
  |  Branch (1956:9): [True: 1, False: 682]
  |  Branch (1956:27): [True: 1, False: 681]
  ------------------
 1957|      2|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1958|      2|        PORT_SetError(SSL_ERROR_RX_MALFORMED_HANDSHAKE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1959|      2|        return SECFailure;
 1960|      2|    }
 1961|       |
 1962|    681|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1962:9): [True: 681, False: 0]
  ------------------
 1963|    681|        rv = ssl3_RegisterExtensionSender(ss, xtnData, ssl_record_size_limit_xtn,
 1964|    681|                                          &ssl_SendRecordSizeLimitXtn);
 1965|    681|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1965:13): [True: 0, False: 681]
  ------------------
 1966|      0|            return SECFailure; /* error already set. */
 1967|      0|        }
 1968|    681|    } else if (limit > maxLimit) {
  ------------------
  |  Branch (1968:16): [True: 0, False: 0]
  ------------------
 1969|       |        /* The client can sensibly check the maximum. */
 1970|      0|        ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
 1971|      0|        PORT_SetError(SSL_ERROR_RX_MALFORMED_HANDSHAKE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1972|      0|        return SECFailure;
 1973|      0|    }
 1974|       |
 1975|       |    /* We can't enforce the maximum on a server. But we do need to ensure
 1976|       |     * that we don't apply a limit that is too large. */
 1977|    681|    xtnData->recordSizeLimit = PR_MIN(maxLimit, limit);
  ------------------
  |  |  158|    681|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 29, False: 652]
  |  |  ------------------
  ------------------
 1978|    681|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_record_size_limit_xtn;
 1979|    681|    return SECSuccess;
 1980|    681|}
ssl_SendRecordSizeLimitXtn:
 1985|    586|{
 1986|    586|    PRUint32 maxLimit;
 1987|    586|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1987:9): [True: 586, False: 0]
  ------------------
 1988|    586|        maxLimit = (ss->version >= SSL_LIBRARY_VERSION_TLS_1_3)
  ------------------
  |  |   21|    586|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1988:20): [True: 538, False: 48]
  ------------------
 1989|    586|                       ? (MAX_FRAGMENT_LENGTH + 1)
  ------------------
  |  |   35|    538|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 1990|    586|                       : MAX_FRAGMENT_LENGTH;
  ------------------
  |  |   35|    634|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 1991|    586|    } else {
 1992|      0|        maxLimit = (ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3)
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1992:20): [True: 0, False: 0]
  ------------------
 1993|      0|                       ? (MAX_FRAGMENT_LENGTH + 1)
  ------------------
  |  |   35|      0|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 1994|      0|                       : MAX_FRAGMENT_LENGTH;
  ------------------
  |  |   35|      0|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 1995|      0|    }
 1996|    586|    PRUint32 limit = PR_MIN(ss->opt.recordSizeLimit, maxLimit);
  ------------------
  |  |  158|    586|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 586]
  |  |  ------------------
  ------------------
 1997|    586|    SECStatus rv = sslBuffer_AppendNumber(buf, limit, 2);
 1998|    586|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1998:9): [True: 0, False: 586]
  ------------------
 1999|      0|        return SECFailure;
 2000|      0|    }
 2001|       |
 2002|    586|    *added = PR_TRUE;
  ------------------
  |  |  437|    586|#define PR_TRUE 1
  ------------------
 2003|    586|    return SECSuccess;
 2004|    586|}
ssl3exthandle.c:ssl_ParseSessionTicket:
  871|    316|{
  872|    316|    PRUint32 temp;
  873|    316|    SECStatus rv;
  874|       |
  875|    316|    PRUint8 *buffer = decryptedTicket->data;
  876|    316|    unsigned int len = decryptedTicket->len;
  877|       |
  878|    316|    PORT_Memset(parsedTicket, 0, sizeof(*parsedTicket));
  ------------------
  |  |  182|    316|#define PORT_Memset memset
  ------------------
  879|    316|    parsedTicket->valid = PR_FALSE;
  ------------------
  |  |  438|    316|#define PR_FALSE 0
  ------------------
  880|       |
  881|       |    /* If the decrypted ticket is empty, then report success, but leave the
  882|       |     * ticket marked as invalid. */
  883|    316|    if (decryptedTicket->len == 0) {
  ------------------
  |  Branch (883:9): [True: 0, False: 316]
  ------------------
  884|      0|        return SECSuccess;
  885|      0|    }
  886|       |
  887|       |    /* Read ticket version. */
  888|    316|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 2, &buffer, &len);
  889|    316|    if (rv != SECSuccess) {
  ------------------
  |  Branch (889:9): [True: 3, False: 313]
  ------------------
  890|      3|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
  891|      3|        return SECFailure;
  892|      3|    }
  893|       |
  894|       |    /* All ticket versions start with 0x01, so check to see if this
  895|       |     * is a ticket or some other self-encrypted thing. */
  896|    313|    if ((temp >> 8) != 1) {
  ------------------
  |  Branch (896:9): [True: 17, False: 296]
  ------------------
  897|     17|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|     17|#define PORT_SetError PORT_SetError_Util
  ------------------
  898|     17|        return SECFailure;
  899|     17|    }
  900|       |    /* Skip the ticket if the version is wrong.  This won't result in a
  901|       |     * handshake failure, just a failure to resume. */
  902|    296|    if (temp != TLS_EX_SESS_TICKET_VERSION) {
  ------------------
  |  |  613|    296|#define TLS_EX_SESS_TICKET_VERSION (0x010a)
  ------------------
  |  Branch (902:9): [True: 120, False: 176]
  ------------------
  903|    120|        return SECSuccess;
  904|    120|    }
  905|       |
  906|       |    /* Read SSLVersion. */
  907|    176|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 2, &buffer, &len);
  908|    176|    if (rv != SECSuccess) {
  ------------------
  |  Branch (908:9): [True: 1, False: 175]
  ------------------
  909|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  910|      1|        return SECFailure;
  911|      1|    }
  912|    175|    parsedTicket->ssl_version = (SSL3ProtocolVersion)temp;
  913|    175|    if (!ssl3_VersionIsSupported(ss->protocolVariant,
  ------------------
  |  Branch (913:9): [True: 44, False: 131]
  ------------------
  914|    175|                                 parsedTicket->ssl_version)) {
  915|       |        /* This socket doesn't support the version from the ticket. */
  916|     44|        return SECSuccess;
  917|     44|    }
  918|       |
  919|       |    /* Read cipher_suite. */
  920|    131|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 2, &buffer, &len);
  921|    131|    if (rv != SECSuccess) {
  ------------------
  |  Branch (921:9): [True: 1, False: 130]
  ------------------
  922|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  923|      1|        return SECFailure;
  924|      1|    }
  925|    130|    parsedTicket->cipher_suite = (ssl3CipherSuite)temp;
  926|       |
  927|       |    /* Read cipher spec parameters. */
  928|    130|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 1, &buffer, &len);
  929|    130|    if (rv != SECSuccess) {
  ------------------
  |  Branch (929:9): [True: 1, False: 129]
  ------------------
  930|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  931|      1|        return SECFailure;
  932|      1|    }
  933|       |
  934|       |#ifndef UNSAFE_FUZZER_MODE
  935|       |    PORT_Assert(temp < ssl_auth_size);
  936|       |#else
  937|    129|    temp %= (8 * sizeof(SSLAuthType)) - 1;
  938|    129|#endif
  939|       |
  940|    129|    parsedTicket->authType = (SSLAuthType)temp;
  941|    129|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
  942|    129|    if (rv != SECSuccess) {
  ------------------
  |  Branch (942:9): [True: 1, False: 128]
  ------------------
  943|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  944|      1|        return SECFailure;
  945|      1|    }
  946|    128|    parsedTicket->authKeyBits = temp;
  947|    128|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 1, &buffer, &len);
  948|    128|    if (rv != SECSuccess) {
  ------------------
  |  Branch (948:9): [True: 1, False: 127]
  ------------------
  949|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  950|      1|        return SECFailure;
  951|      1|    }
  952|    127|    parsedTicket->keaType = (SSLKEAType)temp;
  953|    127|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
  954|    127|    if (rv != SECSuccess) {
  ------------------
  |  Branch (954:9): [True: 1, False: 126]
  ------------------
  955|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  956|      1|        return SECFailure;
  957|      1|    }
  958|    126|    parsedTicket->keaKeyBits = temp;
  959|    126|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
  960|    126|    if (rv != SECSuccess) {
  ------------------
  |  Branch (960:9): [True: 2, False: 124]
  ------------------
  961|      2|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  962|      2|        return SECFailure;
  963|      2|    }
  964|    124|    parsedTicket->originalKeaGroup = temp;
  965|    124|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
  966|    124|    if (rv != SECSuccess) {
  ------------------
  |  Branch (966:9): [True: 1, False: 123]
  ------------------
  967|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  968|      1|        return SECFailure;
  969|      1|    }
  970|    123|    parsedTicket->signatureScheme = (SSLSignatureScheme)temp;
  971|       |
  972|       |    /* Read the optional named curve. */
  973|    123|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 1, &buffer, &len);
  974|    123|    if (rv != SECSuccess) {
  ------------------
  |  Branch (974:9): [True: 1, False: 122]
  ------------------
  975|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  976|      1|        return SECFailure;
  977|      1|    }
  978|    122|    if (parsedTicket->authType == ssl_auth_ecdsa ||
  ------------------
  |  Branch (978:9): [True: 9, False: 113]
  ------------------
  979|    122|        parsedTicket->authType == ssl_auth_ecdh_rsa ||
  ------------------
  |  Branch (979:9): [True: 13, False: 100]
  ------------------
  980|    122|        parsedTicket->authType == ssl_auth_ecdh_ecdsa) {
  ------------------
  |  Branch (980:9): [True: 28, False: 72]
  ------------------
  981|     50|        const sslNamedGroupDef *group =
  982|     50|            ssl_LookupNamedGroup((SSLNamedGroup)temp);
  983|     50|        if (!group || group->keaType != ssl_kea_ecdh) {
  ------------------
  |  Branch (983:13): [True: 2, False: 48]
  |  Branch (983:23): [True: 0, False: 48]
  ------------------
  984|      2|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  985|      2|            return SECFailure;
  986|      2|        }
  987|     48|        parsedTicket->namedCurve = group;
  988|     48|    }
  989|       |
  990|       |    /* Read the master secret (and how it is wrapped). */
  991|    120|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
  992|    120|    if (rv != SECSuccess) {
  ------------------
  |  Branch (992:9): [True: 1, False: 119]
  ------------------
  993|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  994|      1|        return SECFailure;
  995|      1|    }
  996|    119|    parsedTicket->msWrapMech = (CK_MECHANISM_TYPE)temp;
  997|       |
  998|    119|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 2, &buffer, &len);
  999|    119|    if (rv != SECSuccess) {
  ------------------
  |  Branch (999:9): [True: 3, False: 116]
  ------------------
 1000|      3|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
 1001|      3|        return SECFailure;
 1002|      3|    }
 1003|    116|    if (temp == 0 || temp > sizeof(parsedTicket->master_secret)) {
  ------------------
  |  Branch (1003:9): [True: 1, False: 115]
  |  Branch (1003:22): [True: 12, False: 103]
  ------------------
 1004|     13|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|     13|#define PORT_SetError PORT_SetError_Util
  ------------------
 1005|     13|        return SECFailure;
 1006|     13|    }
 1007|    103|    parsedTicket->ms_length = (PRUint16)temp;
 1008|       |
 1009|       |    /* Read the master secret. */
 1010|    103|    rv = ssl3_ExtConsumeHandshake(ss, parsedTicket->master_secret,
 1011|    103|                                  parsedTicket->ms_length, &buffer, &len);
 1012|    103|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1012:9): [True: 1, False: 102]
  ------------------
 1013|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1014|      1|        return SECFailure;
 1015|      1|    }
 1016|       |    /* Read client identity */
 1017|    102|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 1, &buffer, &len);
 1018|    102|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1018:9): [True: 1, False: 101]
  ------------------
 1019|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1020|      1|        return SECFailure;
 1021|      1|    }
 1022|    101|    parsedTicket->client_auth_type = (ClientAuthenticationType)temp;
 1023|    101|    switch (parsedTicket->client_auth_type) {
 1024|     69|        case CLIENT_AUTH_ANONYMOUS:
  ------------------
  |  Branch (1024:9): [True: 69, False: 32]
  ------------------
 1025|     69|            break;
 1026|     31|        case CLIENT_AUTH_CERTIFICATE:
  ------------------
  |  Branch (1026:9): [True: 31, False: 70]
  ------------------
 1027|     31|            rv = ssl3_ExtConsumeHandshakeVariable(ss, &parsedTicket->peer_cert, 2,
 1028|     31|                                                  &buffer, &len);
 1029|     31|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1029:17): [True: 1, False: 30]
  ------------------
 1030|      1|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1031|      1|                return SECFailure;
 1032|      1|            }
 1033|     30|            break;
 1034|     30|        default:
  ------------------
  |  Branch (1034:9): [True: 1, False: 100]
  ------------------
 1035|      1|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1036|      1|            return SECFailure;
 1037|    101|    }
 1038|       |
 1039|       |    /* Read timestamp.  This is a 64-bit value and
 1040|       |     * ssl3_ExtConsumeHandshakeNumber only reads 32-bits at a time. */
 1041|     99|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
 1042|     99|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1042:9): [True: 1, False: 98]
  ------------------
 1043|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1044|      1|        return SECFailure;
 1045|      1|    }
 1046|       |
 1047|       |    /* Cast to avoid undefined behavior if the top bit is set. */
 1048|     98|    parsedTicket->timestamp = (PRTime)((PRUint64)temp << 32);
 1049|     98|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
 1050|     98|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1050:9): [True: 1, False: 97]
  ------------------
 1051|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1052|      1|        return SECFailure;
 1053|      1|    }
 1054|     97|    parsedTicket->timestamp |= (PRTime)temp;
 1055|       |
 1056|       |    /* Read server name */
 1057|     97|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &parsedTicket->srvName, 2,
 1058|     97|                                          &buffer, &len);
 1059|     97|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1059:9): [True: 2, False: 95]
  ------------------
 1060|      2|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1061|      2|        return SECFailure;
 1062|      2|    }
 1063|       |
 1064|       |    /* Read extendedMasterSecretUsed */
 1065|     95|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 1, &buffer, &len);
 1066|     95|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1066:9): [True: 1, False: 94]
  ------------------
 1067|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1068|      1|        return SECFailure;
 1069|      1|    }
 1070|       |#ifndef UNSAFE_FUZZER_MODE
 1071|       |    /* A well-behaving server should only write 0 or 1. */
 1072|       |    PORT_Assert(temp == PR_TRUE || temp == PR_FALSE);
 1073|       |#endif
 1074|     94|    parsedTicket->extendedMasterSecretUsed = temp ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|     80|#define PR_TRUE 1
  ------------------
                  parsedTicket->extendedMasterSecretUsed = temp ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|    108|#define PR_FALSE 0
  ------------------
  |  Branch (1074:46): [True: 80, False: 14]
  ------------------
 1075|       |
 1076|     94|    rv = ssl3_ExtConsumeHandshake(ss, &temp, 4, &buffer, &len);
 1077|     94|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1077:9): [True: 1, False: 93]
  ------------------
 1078|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1079|      1|        return SECFailure;
 1080|      1|    }
 1081|     93|    parsedTicket->flags = PR_ntohl(temp);
 1082|       |
 1083|     93|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &parsedTicket->alpnSelection, 1,
 1084|     93|                                          &buffer, &len);
 1085|     93|    PORT_Assert(parsedTicket->alpnSelection.len < 256);
  ------------------
  |  |  120|     93|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     93|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 93, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1086|     93|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1086:9): [True: 1, False: 92]
  ------------------
 1087|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1088|      1|        return SECFailure;
 1089|      1|    }
 1090|       |
 1091|     92|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
 1092|     92|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1092:9): [True: 2, False: 90]
  ------------------
 1093|      2|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1094|      2|        return SECFailure;
 1095|      2|    }
 1096|     90|    parsedTicket->maxEarlyData = temp;
 1097|       |
 1098|     90|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &temp, 4, &buffer, &len);
 1099|     90|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1099:9): [True: 1, False: 89]
  ------------------
 1100|      1|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1101|      1|        return SECFailure;
 1102|      1|    }
 1103|     89|    parsedTicket->ticketAgeBaseline = temp;
 1104|       |
 1105|     89|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &parsedTicket->applicationToken,
 1106|     89|                                          2, &buffer, &len);
 1107|     89|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1107:9): [True: 2, False: 87]
  ------------------
 1108|      2|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1109|      2|        return SECFailure;
 1110|      2|    }
 1111|       |
 1112|       |#ifndef UNSAFE_FUZZER_MODE
 1113|       |    /* Done parsing.  Check that all bytes have been consumed. */
 1114|       |    if (len != 0) {
 1115|       |        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
 1116|       |        return SECFailure;
 1117|       |    }
 1118|       |#endif
 1119|       |
 1120|     87|    parsedTicket->valid = PR_TRUE;
  ------------------
  |  |  437|     87|#define PR_TRUE 1
  ------------------
 1121|     87|    return SECSuccess;
 1122|     89|}
ssl3exthandle.c:ssl_CreateSIDFromTicket:
 1127|    231|{
 1128|    231|    sslSessionID *sid;
 1129|    231|    SECStatus rv;
 1130|       |
 1131|    231|    sid = ssl3_NewSessionID(ss, PR_TRUE);
  ------------------
  |  |  437|    231|#define PR_TRUE 1
  ------------------
 1132|    231|    if (sid == NULL) {
  ------------------
  |  Branch (1132:9): [True: 0, False: 231]
  ------------------
 1133|      0|        return SECFailure;
 1134|      0|    }
 1135|       |
 1136|       |    /* Copy over parameters. */
 1137|    231|    sid->version = parsedTicket->ssl_version;
 1138|    231|    sid->creationTime = parsedTicket->timestamp;
 1139|    231|    sid->u.ssl3.cipherSuite = parsedTicket->cipher_suite;
 1140|    231|    sid->authType = parsedTicket->authType;
 1141|    231|    sid->authKeyBits = parsedTicket->authKeyBits;
 1142|    231|    sid->keaType = parsedTicket->keaType;
 1143|    231|    sid->keaKeyBits = parsedTicket->keaKeyBits;
 1144|    231|    sid->keaGroup = parsedTicket->originalKeaGroup;
 1145|    231|    sid->namedCurve = parsedTicket->namedCurve;
 1146|    231|    sid->sigScheme = parsedTicket->signatureScheme;
 1147|       |
 1148|    231|    rv = SECITEM_CopyItem(NULL, &sid->u.ssl3.locked.sessionTicket.ticket,
  ------------------
  |  |  106|    231|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1149|    231|                          rawTicket);
 1150|    231|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1150:9): [True: 0, False: 231]
  ------------------
 1151|      0|        goto loser;
 1152|      0|    }
 1153|    231|    sid->u.ssl3.locked.sessionTicket.flags = parsedTicket->flags;
 1154|    231|    sid->u.ssl3.locked.sessionTicket.max_early_data_size =
 1155|    231|        parsedTicket->maxEarlyData;
 1156|       |
 1157|    231|    if (parsedTicket->ms_length >
  ------------------
  |  Branch (1157:9): [True: 0, False: 231]
  ------------------
 1158|    231|        sizeof(sid->u.ssl3.keys.wrapped_master_secret)) {
 1159|      0|        goto loser;
 1160|      0|    }
 1161|    231|    PORT_Memcpy(sid->u.ssl3.keys.wrapped_master_secret,
  ------------------
  |  |  180|    231|#define PORT_Memcpy memcpy
  ------------------
 1162|    231|                parsedTicket->master_secret, parsedTicket->ms_length);
 1163|    231|    sid->u.ssl3.keys.wrapped_master_secret_len = parsedTicket->ms_length;
 1164|    231|    sid->u.ssl3.masterWrapMech = parsedTicket->msWrapMech;
 1165|    231|    sid->u.ssl3.masterValid = PR_TRUE;
  ------------------
  |  |  437|    231|#define PR_TRUE 1
  ------------------
 1166|    231|    sid->u.ssl3.keys.resumable = PR_TRUE;
  ------------------
  |  |  437|    231|#define PR_TRUE 1
  ------------------
 1167|    231|    sid->u.ssl3.keys.extendedMasterSecretUsed = parsedTicket->extendedMasterSecretUsed;
 1168|       |
 1169|       |    /* Copy over client cert from session ticket if there is one. */
 1170|    231|    if (parsedTicket->peer_cert.data != NULL) {
  ------------------
  |  Branch (1170:9): [True: 3, False: 228]
  ------------------
 1171|      3|        PORT_Assert(!sid->peerCert);
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1172|      3|        sid->peerCert = CERT_NewTempCertificate(ss->dbHandle,
 1173|      3|                                                &parsedTicket->peer_cert,
 1174|      3|                                                NULL, PR_FALSE, PR_TRUE);
  ------------------
  |  |  438|      3|#define PR_FALSE 0
  ------------------
                                                              NULL, PR_FALSE, PR_TRUE);
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
 1175|      3|        if (!sid->peerCert) {
  ------------------
  |  Branch (1175:13): [True: 3, False: 0]
  ------------------
 1176|      3|            goto loser;
 1177|      3|        }
 1178|      3|    }
 1179|       |
 1180|       |    /* Transfer ownership of the remaining items. */
 1181|    228|    if (parsedTicket->srvName.data != NULL) {
  ------------------
  |  Branch (1181:9): [True: 36, False: 192]
  ------------------
 1182|     36|        SECITEM_FreeItem(&sid->u.ssl3.srvName, PR_FALSE);
  ------------------
  |  |  108|     36|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sid->u.ssl3.srvName, PR_FALSE);
  ------------------
  |  |  438|     36|#define PR_FALSE 0
  ------------------
 1183|     36|        rv = SECITEM_CopyItem(NULL, &sid->u.ssl3.srvName,
  ------------------
  |  |  106|     36|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1184|     36|                              &parsedTicket->srvName);
 1185|     36|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1185:13): [True: 0, False: 36]
  ------------------
 1186|      0|            goto loser;
 1187|      0|        }
 1188|     36|    }
 1189|    228|    if (parsedTicket->alpnSelection.data != NULL) {
  ------------------
  |  Branch (1189:9): [True: 55, False: 173]
  ------------------
 1190|     55|        SECITEM_FreeItem(&sid->u.ssl3.alpnSelection, PR_FALSE);
  ------------------
  |  |  108|     55|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sid->u.ssl3.alpnSelection, PR_FALSE);
  ------------------
  |  |  438|     55|#define PR_FALSE 0
  ------------------
 1191|     55|        rv = SECITEM_CopyItem(NULL, &sid->u.ssl3.alpnSelection,
  ------------------
  |  |  106|     55|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1192|     55|                              &parsedTicket->alpnSelection);
 1193|     55|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1193:13): [True: 0, False: 55]
  ------------------
 1194|      0|            goto loser;
 1195|      0|        }
 1196|     55|    }
 1197|       |
 1198|    228|    *out = sid;
 1199|    228|    return SECSuccess;
 1200|       |
 1201|      3|loser:
 1202|      3|    ssl_FreeSID(sid);
 1203|      3|    return SECFailure;
 1204|    228|}
ssl3exthandle.c:ssl_UpdateSupportedGroups:
 1845|  12.7k|{
 1846|  12.7k|    SECStatus rv;
 1847|  12.7k|    PRUint32 list_len;
 1848|  12.7k|    unsigned int i;
 1849|  12.7k|    const sslNamedGroupDef *enabled[SSL_NAMED_GROUP_COUNT] = { 0 };
 1850|  12.7k|    PORT_Assert(SSL_NAMED_GROUP_COUNT == PR_ARRAY_SIZE(enabled));
  ------------------
  |  |  120|  12.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  12.7k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1851|       |
 1852|  12.7k|    if (!data->data || data->len < 4) {
  ------------------
  |  Branch (1852:9): [True: 2, False: 12.7k]
  |  Branch (1852:24): [True: 2, False: 12.7k]
  ------------------
 1853|      4|        (void)ssl3_DecodeError(ss);
 1854|      4|        return SECFailure;
 1855|      4|    }
 1856|       |
 1857|       |    /* get the length of elliptic_curve_list */
 1858|  12.7k|    rv = ssl3_ConsumeHandshakeNumber(ss, &list_len, 2, &data->data, &data->len);
 1859|  12.7k|    if (rv != SECSuccess || data->len != list_len || (data->len % 2) != 0) {
  ------------------
  |  Branch (1859:9): [True: 0, False: 12.7k]
  |  Branch (1859:29): [True: 17, False: 12.7k]
  |  Branch (1859:54): [True: 1, False: 12.7k]
  ------------------
 1860|     18|        (void)ssl3_DecodeError(ss);
 1861|     18|        return SECFailure;
 1862|     18|    }
 1863|       |
 1864|       |    /* disable all groups and remember the enabled groups */
 1865|   432k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|   432k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (1865:17): [True: 419k, False: 12.7k]
  ------------------
 1866|   419k|        enabled[i] = ss->namedGroupPreferences[i];
 1867|   419k|        ss->namedGroupPreferences[i] = NULL;
 1868|   419k|    }
 1869|       |
 1870|       |    /* Read groups from data and enable if in |enabled| */
 1871|  61.7k|    while (data->len) {
  ------------------
  |  Branch (1871:12): [True: 48.9k, False: 12.7k]
  ------------------
 1872|  48.9k|        const sslNamedGroupDef *group;
 1873|  48.9k|        PRUint32 curve_name;
 1874|  48.9k|        rv = ssl3_ConsumeHandshakeNumber(ss, &curve_name, 2, &data->data,
 1875|  48.9k|                                         &data->len);
 1876|  48.9k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1876:13): [True: 0, False: 48.9k]
  ------------------
 1877|      0|            return SECFailure; /* fatal alert already sent */
 1878|      0|        }
 1879|  48.9k|        group = ssl_LookupNamedGroup(curve_name);
 1880|  48.9k|        if (group) {
  ------------------
  |  Branch (1880:13): [True: 30.9k, False: 17.9k]
  ------------------
 1881|   311k|            for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|   311k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (1881:25): [True: 304k, False: 6.87k]
  ------------------
 1882|   304k|                if (enabled[i] && group == enabled[i]) {
  ------------------
  |  Branch (1882:21): [True: 93.2k, False: 211k]
  |  Branch (1882:35): [True: 24.1k, False: 69.1k]
  ------------------
 1883|  24.1k|                    ss->namedGroupPreferences[i] = enabled[i];
 1884|  24.1k|                    break;
 1885|  24.1k|                }
 1886|   304k|            }
 1887|  30.9k|        }
 1888|       |
 1889|       |        /* "Codepoints in the NamedCurve registry with a high byte of 0x01 (that
 1890|       |         * is, between 256 and 511 inclusive) are set aside for FFDHE groups,"
 1891|       |         * -- https://tools.ietf.org/html/draft-ietf-tls-negotiated-ff-dhe-10
 1892|       |         */
 1893|  48.9k|        if ((curve_name & 0xff00) == 0x0100) {
  ------------------
  |  Branch (1893:13): [True: 4.93k, False: 44.0k]
  ------------------
 1894|  4.93k|            ss->xtnData.peerSupportsFfdheGroups = PR_TRUE;
  ------------------
  |  |  437|  4.93k|#define PR_TRUE 1
  ------------------
 1895|  4.93k|        }
 1896|  48.9k|    }
 1897|       |
 1898|       |    /* Note: if ss->opt.requireDHENamedGroups is set, we disable DHE cipher
 1899|       |     * suites, but we do that in ssl3_config_match(). */
 1900|  12.7k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|  25.4k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1900:9): [True: 11.1k, False: 1.59k]
  ------------------
 1901|  12.7k|        !ss->opt.requireDHENamedGroups && !ss->xtnData.peerSupportsFfdheGroups) {
  ------------------
  |  Branch (1901:9): [True: 11.1k, False: 0]
  |  Branch (1901:43): [True: 8.13k, False: 2.99k]
  ------------------
 1902|       |        /* If we don't require that DHE use named groups, and no FFDHE was
 1903|       |         * included, we pretend that they support all the FFDHE groups we do. */
 1904|   276k|        for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|   276k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (1904:21): [True: 268k, False: 8.13k]
  ------------------
 1905|   268k|            if (enabled[i] && enabled[i]->keaType == ssl_kea_dh) {
  ------------------
  |  Branch (1905:17): [True: 72.6k, False: 195k]
  |  Branch (1905:31): [True: 35.9k, False: 36.7k]
  ------------------
 1906|  35.9k|                ss->namedGroupPreferences[i] = enabled[i];
 1907|  35.9k|            }
 1908|   268k|        }
 1909|  8.13k|    }
 1910|       |
 1911|  12.7k|    return SECSuccess;
 1912|  12.7k|}

ssl3_InitGather:
   28|  19.4k|{
   29|  19.4k|    gs->state = GS_INIT;
  ------------------
  |  |  381|  19.4k|#define GS_INIT 0
  ------------------
   30|  19.4k|    gs->writeOffset = 0;
   31|  19.4k|    gs->readOffset = 0;
   32|  19.4k|    gs->dtlsPacketOffset = 0;
   33|  19.4k|    gs->dtlsPacket.len = 0;
   34|  19.4k|    gs->rejectV2Records = PR_FALSE;
  ------------------
  |  |  438|  19.4k|#define PR_FALSE 0
  ------------------
   35|       |    /* Allocate plaintext buffer to maximum possibly needed size. It needs to
   36|       |     * be larger than recordSizeLimit for TLS 1.0 and 1.1 compatability.
   37|       |     * The TLS 1.2 ciphertext is larger than the TLS 1.3 ciphertext. */
   38|  19.4k|    return sslBuffer_Grow(&gs->buf, TLS_1_2_MAX_CTEXT_LENGTH);
  ------------------
  |  |   39|  19.4k|#define TLS_1_2_MAX_CTEXT_LENGTH ((MAX_FRAGMENT_LENGTH) + (TLS_1_2_MAX_EXPANSION))
  |  |  ------------------
  |  |  |  |   35|  19.4k|#define MAX_FRAGMENT_LENGTH 16384
  |  |  ------------------
  |  |               #define TLS_1_2_MAX_CTEXT_LENGTH ((MAX_FRAGMENT_LENGTH) + (TLS_1_2_MAX_EXPANSION))
  |  |  ------------------
  |  |  |  |   36|  19.4k|#define TLS_1_2_MAX_EXPANSION 2048
  |  |  ------------------
  ------------------
   39|  19.4k|}
ssl3_DestroyGather:
   44|  9.71k|{
   45|  9.71k|    if (gs) { /* the PORT_*Free functions check for NULL pointers. */
  ------------------
  |  Branch (45:9): [True: 9.71k, False: 0]
  ------------------
   46|  9.71k|        PORT_ZFree(gs->buf.buf, gs->buf.space);
  ------------------
  |  |   75|  9.71k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
   47|  9.71k|        PORT_Free(gs->inbuf.buf);
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
   48|  9.71k|        PORT_Free(gs->dtlsPacket.buf);
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
   49|  9.71k|    }
   50|  9.71k|}
ssl3_GatherCompleteHandshake:
  449|   386k|{
  450|   386k|    int rv;
  451|   386k|    SSL3Ciphertext cText;
  452|   386k|    PRBool keepGoing = PR_TRUE;
  ------------------
  |  |  437|   386k|#define PR_TRUE 1
  ------------------
  453|       |
  454|   386k|    if (ss->ssl3.fatalAlertSent) {
  ------------------
  |  Branch (454:9): [True: 0, False: 386k]
  ------------------
  455|      0|        SSL_TRC(3, ("%d: SSL3[%d] Cannot gather data; fatal alert already sent",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  456|      0|                    SSL_GETPID(), ss->fd));
  457|      0|        PORT_SetError(SSL_ERROR_HANDSHAKE_FAILED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  458|      0|        return -1;
  459|      0|    }
  460|       |
  461|   386k|    SSL_TRC(30, ("%d: SSL3[%d]: ssl3_GatherCompleteHandshake",
  ------------------
  |  |   71|   386k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 386k]
  |  |  ------------------
  |  |   72|   386k|    ssl_Trace b
  ------------------
  462|   386k|                 SSL_GETPID(), ss->fd));
  463|       |
  464|       |    /* ssl3_HandleRecord may end up eventually calling ssl_FinishHandshake,
  465|       |     * which requires the 1stHandshakeLock, which must be acquired before the
  466|       |     * RecvBufLock.
  467|       |     */
  468|   386k|    PORT_Assert(ss->opt.noLocks || ssl_Have1stHandshakeLock(ss));
  ------------------
  |  |  120|   386k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   584k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 189k, False: 197k]
  |  |  |  |  |  Branch (208:7): [True: 197k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  469|   386k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   386k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   584k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 189k, False: 197k]
  |  |  |  |  |  Branch (208:7): [True: 197k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  470|       |
  471|   589k|    do {
  472|   589k|        PRBool processingEarlyData;
  473|       |
  474|   589k|        ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|   589k|    {                                                 \
  |  | 1408|   589k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 304k, False: 285k]
  |  |  ------------------
  |  | 1409|   304k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|   304k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   304k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 304k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|   304k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|   304k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|   304k|        }                                             \
  |  | 1412|   589k|    }
  ------------------
  475|       |
  476|   589k|        processingEarlyData = ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted;
  477|       |
  478|       |        /* Without this, we may end up wrongly reporting
  479|       |         * SSL_ERROR_RX_UNEXPECTED_* errors if we receive any records from the
  480|       |         * peer while we are waiting to be restarted.
  481|       |         */
  482|   589k|        if (ss->ssl3.hs.restartTarget) {
  ------------------
  |  Branch (482:13): [True: 0, False: 589k]
  ------------------
  483|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  484|      0|            PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  485|      0|            return -1;
  486|      0|        }
  487|       |
  488|       |        /* If we have a detached record layer, don't ever gather. */
  489|   589k|        if (ss->recordWriteCallback) {
  ------------------
  |  Branch (489:13): [True: 0, False: 589k]
  ------------------
  490|      0|            PRBool done = ss->firstHsDone;
  491|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  492|      0|            if (done) {
  ------------------
  |  Branch (492:17): [True: 0, False: 0]
  ------------------
  493|      0|                return 1;
  494|      0|            }
  495|      0|            PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  496|      0|            return -1;
  497|      0|        }
  498|       |
  499|   589k|        ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|   589k|    {                                                \
  |  | 1415|   589k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 304k, False: 285k]
  |  |  ------------------
  |  | 1416|   589k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|   304k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|   589k|    }
  ------------------
  500|       |
  501|       |        /* State for SSLv2 client hello support. */
  502|   589k|        ssl2Gather ssl2gs = { PR_FALSE, 0 };
  ------------------
  |  |  438|   589k|#define PR_FALSE 0
  ------------------
  503|   589k|        ssl2Gather *ssl2gs_ptr = NULL;
  504|       |
  505|       |        /* If we're a server and waiting for a client hello, accept v2. */
  506|   589k|        if (ss->sec.isServer && ss->opt.enableV2CompatibleHello &&
  ------------------
  |  Branch (506:13): [True: 589k, False: 0]
  |  Branch (506:33): [True: 0, False: 589k]
  ------------------
  507|   589k|            ss->ssl3.hs.ws == wait_client_hello) {
  ------------------
  |  Branch (507:13): [True: 0, False: 0]
  ------------------
  508|      0|            ssl2gs_ptr = &ssl2gs;
  509|      0|        }
  510|       |
  511|       |        /* bring in the next sslv3 record. */
  512|   589k|        if (ss->recvdCloseNotify) {
  ------------------
  |  Branch (512:13): [True: 2, False: 589k]
  ------------------
  513|       |            /* RFC 5246 Section 7.2.1:
  514|       |             *   Any data received after a closure alert is ignored.
  515|       |             */
  516|      2|            return 0;
  517|      2|        }
  518|       |
  519|   589k|        if (!IS_DTLS(ss)) {
  ------------------
  |  |  892|   589k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (519:13): [True: 589k, False: 0]
  ------------------
  520|       |            /* If we're a server waiting for a ClientHello then pass
  521|       |             * ssl2gs to support SSLv2 ClientHello messages. */
  522|   589k|            rv = ssl3_GatherData(ss, &ss->gs, flags, ssl2gs_ptr);
  523|   589k|        } else {
  524|      0|            rv = dtls_GatherData(ss, &ss->gs, flags);
  525|       |
  526|       |            /* If we got a would block error, that means that no data was
  527|       |             * available, so we check the timer to see if it's time to
  528|       |             * retransmit */
  529|      0|            if (rv == SECFailure &&
  ------------------
  |  Branch (529:17): [True: 0, False: 0]
  ------------------
  530|      0|                (PORT_GetError() == PR_WOULD_BLOCK_ERROR)) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
                              (PORT_GetError() == PR_WOULD_BLOCK_ERROR)) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (530:17): [True: 0, False: 0]
  ------------------
  531|      0|                dtls_CheckTimer(ss);
  532|       |                /* Restore the error in case something succeeded */
  533|      0|                PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                              PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  534|      0|            }
  535|      0|        }
  536|       |
  537|   589k|        if (rv <= 0) {
  ------------------
  |  Branch (537:13): [True: 6.38k, False: 583k]
  ------------------
  538|  6.38k|            return rv;
  539|  6.38k|        }
  540|       |
  541|   583k|        if (ssl2gs.isV2) {
  ------------------
  |  Branch (541:13): [True: 0, False: 583k]
  ------------------
  542|      0|            rv = ssl3_HandleV2ClientHello(ss, ss->gs.inbuf.buf,
  543|      0|                                          ss->gs.inbuf.len,
  544|      0|                                          ssl2gs.padding);
  545|      0|            if (rv < 0) {
  ------------------
  |  Branch (545:17): [True: 0, False: 0]
  ------------------
  546|      0|                return rv;
  547|      0|            }
  548|   583k|        } else {
  549|       |            /* decipher it, and handle it if it's a handshake.
  550|       |             * If it's application data, ss->gs.buf will not be empty upon return.
  551|       |             * If it's a change cipher spec, alert, or handshake message,
  552|       |             * ss->gs.buf.len will be 0 when ssl3_HandleRecord returns SECSuccess.
  553|       |             *
  554|       |             * cText only needs to be valid for this next function call, so
  555|       |             * it can borrow gs.hdr.
  556|       |             */
  557|   583k|            cText.hdr = ss->gs.hdr;
  558|   583k|            cText.hdrLen = ss->gs.hdrLen;
  559|   583k|            cText.buf = &ss->gs.inbuf;
  560|   583k|            rv = ssl3_HandleRecord(ss, &cText);
  561|   583k|        }
  562|       |
  563|   583k|#ifdef DEBUG
  564|       |        /* In Debug builds free gather ciphertext buffer after each decryption
  565|       |         * for advanced ASAN coverage/utilization. The buffer content has been
  566|       |         * used at this point, ssl3_HandleRecord() and thereby the decryption
  567|       |         * functions are only called from this point of the implementation. */
  568|   583k|        sslBuffer_Clear(&ss->gs.inbuf);
  569|   583k|#endif
  570|       |
  571|   583k|        if (rv < 0) {
  ------------------
  |  Branch (571:13): [True: 3.32k, False: 579k]
  ------------------
  572|  3.32k|            return ss->recvdCloseNotify ? 0 : rv;
  ------------------
  |  Branch (572:20): [True: 3, False: 3.32k]
  ------------------
  573|  3.32k|        }
  574|   579k|        if (ss->gs.buf.len > 0) {
  ------------------
  |  Branch (574:13): [True: 156k, False: 423k]
  ------------------
  575|       |            /* We have application data to return to the application. This
  576|       |             * prioritizes returning application data to the application over
  577|       |             * completing any renegotiation handshake we may be doing.
  578|       |             */
  579|   156k|            PORT_Assert(ss->firstHsDone);
  ------------------
  |  |  120|   156k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   156k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 156k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  580|   156k|            break;
  581|   156k|        }
  582|       |
  583|   423k|        PORT_Assert(keepGoing);
  ------------------
  |  |  120|   423k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   423k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 423k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  584|   423k|        ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|   423k|    {                                                 \
  |  | 1408|   423k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 219k, False: 203k]
  |  |  ------------------
  |  | 1409|   219k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|   219k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   219k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 219k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|   219k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|   219k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|   219k|        }                                             \
  |  | 1412|   423k|    }
  ------------------
  585|   423k|        if (ss->ssl3.hs.ws == idle_handshake) {
  ------------------
  |  Branch (585:13): [True: 220k, False: 202k]
  ------------------
  586|       |            /* We are done with the current handshake so stop trying to
  587|       |             * handshake. Note that it would be safe to test ss->firstHsDone
  588|       |             * instead of ss->ssl3.hs.ws. By testing ss->ssl3.hs.ws instead,
  589|       |             * we prioritize completing a renegotiation handshake over sending
  590|       |             * application data.
  591|       |             */
  592|   220k|            PORT_Assert(ss->firstHsDone);
  ------------------
  |  |  120|   220k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   220k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 220k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  593|   220k|            PORT_Assert(!ss->ssl3.hs.canFalseStart);
  ------------------
  |  |  120|   220k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   220k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 220k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  594|   220k|            keepGoing = PR_FALSE;
  ------------------
  |  |  438|   220k|#define PR_FALSE 0
  ------------------
  595|   220k|        } else if (ss->ssl3.hs.canFalseStart) {
  ------------------
  |  Branch (595:20): [True: 0, False: 202k]
  ------------------
  596|       |            /* Prioritize sending application data over trying to complete
  597|       |             * the handshake if we're false starting.
  598|       |             *
  599|       |             * If we were to do this check at the beginning of the loop instead
  600|       |             * of here, then this function would become be a no-op after
  601|       |             * receiving the ServerHelloDone in the false start case, and we
  602|       |             * would never complete the handshake.
  603|       |             */
  604|      0|            PORT_Assert(!ss->firstHsDone);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  605|       |
  606|      0|            if (ssl3_WaitingForServerSecondRound(ss)) {
  ------------------
  |  Branch (606:17): [True: 0, False: 0]
  ------------------
  607|      0|                keepGoing = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  608|      0|            } else {
  609|      0|                ss->ssl3.hs.canFalseStart = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  610|      0|            }
  611|   202k|        } else if (processingEarlyData &&
  ------------------
  |  Branch (611:20): [True: 0, False: 202k]
  ------------------
  612|   202k|                   ss->ssl3.hs.zeroRttState == ssl_0rtt_done &&
  ------------------
  |  Branch (612:20): [True: 0, False: 0]
  ------------------
  613|   202k|                   !PR_CLIST_IS_EMPTY(&ss->ssl3.hs.bufferedEarlyData)) {
  ------------------
  |  |   94|      0|    ((_l)->next == (_l))
  ------------------
  |  Branch (613:20): [True: 0, False: 0]
  ------------------
  614|       |            /* If we were processing early data and we are no longer, then force
  615|       |             * the handshake to block.  This ensures that early data is
  616|       |             * delivered to the application before the handshake completes. */
  617|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  618|      0|            PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  619|      0|            return -1;
  620|      0|        }
  621|   423k|        ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|   423k|    {                                                \
  |  | 1415|   423k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 219k, False: 203k]
  |  |  ------------------
  |  | 1416|   423k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|   219k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|   423k|    }
  ------------------
  622|   423k|    } while (keepGoing);
  ------------------
  |  Branch (622:14): [True: 202k, False: 220k]
  ------------------
  623|       |
  624|       |    /* Service the DTLS timer so that the post-handshake timers
  625|       |     * fire. */
  626|   376k|    if (IS_DTLS(ss) && (ss->ssl3.hs.ws == idle_handshake)) {
  ------------------
  |  |  892|   753k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 376k]
  |  |  ------------------
  ------------------
  |  Branch (626:24): [True: 0, False: 0]
  ------------------
  627|      0|        dtls_CheckTimer(ss);
  628|      0|    }
  629|   376k|    ss->gs.readOffset = 0;
  630|   376k|    ss->gs.writeOffset = ss->gs.buf.len;
  631|   376k|    return 1;
  632|   386k|}
ssl3_GatherAppDataRecord:
  646|   159k|{
  647|   159k|    int rv;
  648|       |
  649|       |    /* ssl3_GatherCompleteHandshake requires both of these locks. */
  650|   159k|    PORT_Assert(ss->opt.noLocks || ssl_Have1stHandshakeLock(ss));
  ------------------
  |  |  120|   159k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   240k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 77.9k, False: 81.1k]
  |  |  |  |  |  Branch (208:7): [True: 81.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  651|   159k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   159k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   240k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 77.9k, False: 81.1k]
  |  |  |  |  |  Branch (208:7): [True: 81.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  652|       |
  653|   376k|    do {
  654|   376k|        rv = ssl3_GatherCompleteHandshake(ss, flags);
  655|   376k|    } while (rv > 0 && ss->gs.buf.len == 0);
  ------------------
  |  Branch (655:14): [True: 374k, False: 2.62k]
  |  Branch (655:24): [True: 217k, False: 156k]
  ------------------
  656|       |
  657|   159k|    return rv;
  658|   159k|}
ssl3gthr.c:ssl3_GatherData:
   91|   589k|{
   92|   589k|    unsigned char *bp;
   93|   589k|    unsigned char *lbp;
   94|   589k|    int nb;
   95|   589k|    int err;
   96|   589k|    int rv = 1;
   97|   589k|    PRUint8 v2HdrLength = 0;
   98|       |
   99|   589k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   589k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   894k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 285k, False: 304k]
  |  |  |  |  |  Branch (208:7): [True: 304k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  100|   589k|    if (gs->state == GS_INIT) {
  ------------------
  |  |  381|   589k|#define GS_INIT 0
  ------------------
  |  Branch (100:9): [True: 589k, False: 0]
  ------------------
  101|   589k|        gs->state = GS_HEADER;
  ------------------
  |  |  382|   589k|#define GS_HEADER 1
  ------------------
  102|   589k|        gs->remainder = 5;
  103|   589k|        gs->offset = 0;
  104|   589k|        gs->writeOffset = 0;
  105|   589k|        gs->readOffset = 0;
  106|   589k|        gs->inbuf.len = 0;
  107|   589k|    }
  108|       |
  109|   589k|    lbp = gs->inbuf.buf;
  110|  1.16M|    for (;;) {
  111|  1.16M|        SSL_TRC(30, ("%d: SSL3[%d]: gather state %d (need %d more)",
  ------------------
  |  |   71|  1.16M|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.16M]
  |  |  ------------------
  |  |   72|  1.16M|    ssl_Trace b
  ------------------
  112|  1.16M|                     SSL_GETPID(), ss->fd, gs->state, gs->remainder));
  113|  1.16M|        bp = ((gs->state != GS_HEADER) ? lbp : gs->hdr) + gs->offset;
  ------------------
  |  |  382|  1.16M|#define GS_HEADER 1
  ------------------
  |  Branch (113:15): [True: 576k, False: 590k]
  ------------------
  114|  1.16M|        nb = ssl_DefRecv(ss, bp, gs->remainder, flags);
  115|       |
  116|  1.16M|        if (nb > 0) {
  ------------------
  |  Branch (116:13): [True: 1.16M, False: 6.10k]
  ------------------
  117|  1.16M|            PRINT_BUF(60, (ss, "raw gather data:", bp, nb));
  ------------------
  |  |   74|  1.16M|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.16M]
  |  |  ------------------
  |  |   75|  1.16M|    ssl_PrintBuf b
  ------------------
  118|  1.16M|        } else if (nb == 0) {
  ------------------
  |  Branch (118:20): [True: 6.10k, False: 0]
  ------------------
  119|       |            /* EOF */
  120|  6.10k|            SSL_TRC(30, ("%d: SSL3[%d]: EOF", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|  6.10k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 6.10k]
  |  |  ------------------
  |  |   72|  6.10k|    ssl_Trace b
  ------------------
  121|  6.10k|            rv = 0;
  122|  6.10k|            break;
  123|  6.10k|        } else /* if (nb < 0) */ {
  124|      0|            SSL_DBG(("%d: SSL3[%d]: recv error %d", SSL_GETPID(), ss->fd,
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  125|      0|                     PR_GetError()));
  126|      0|            rv = SECFailure;
  127|      0|            break;
  128|      0|        }
  129|       |
  130|  1.16M|        PORT_Assert((unsigned int)nb <= gs->remainder);
  ------------------
  |  |  120|  1.16M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.16M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.16M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  131|  1.16M|        if ((unsigned int)nb > gs->remainder) {
  ------------------
  |  Branch (131:13): [True: 0, False: 1.16M]
  ------------------
  132|       |            /* ssl_DefRecv is misbehaving!  this error is fatal to SSL. */
  133|      0|            gs->state = GS_INIT; /* so we don't crash next time */
  ------------------
  |  |  381|      0|#define GS_INIT 0
  ------------------
  134|      0|            rv = SECFailure;
  135|      0|            break;
  136|      0|        }
  137|       |
  138|  1.16M|        gs->offset += nb;
  139|  1.16M|        gs->remainder -= nb;
  140|  1.16M|        if (gs->state == GS_DATA)
  ------------------
  |  |  383|  1.16M|#define GS_DATA 2
  ------------------
  |  Branch (140:13): [True: 575k, False: 584k]
  ------------------
  141|   575k|            gs->inbuf.len += nb;
  142|       |
  143|       |        /* if there's more to go, read some more. */
  144|  1.16M|        if (gs->remainder > 0) {
  ------------------
  |  Branch (144:13): [True: 1.24k, False: 1.15M]
  ------------------
  145|  1.24k|            continue;
  146|  1.24k|        }
  147|       |
  148|       |        /* have received entire record header, or entire record. */
  149|  1.15M|        switch (gs->state) {
  ------------------
  |  Branch (149:17): [True: 0, False: 1.15M]
  ------------------
  150|   584k|            case GS_HEADER:
  ------------------
  |  |  382|   584k|#define GS_HEADER 1
  ------------------
  |  Branch (150:13): [True: 584k, False: 575k]
  ------------------
  151|       |                /* Check for SSLv2 handshakes. Always assume SSLv3 on clients,
  152|       |                 * support SSLv2 handshakes only when ssl2gs != NULL.
  153|       |                 * Always assume v3 after we received the first record. */
  154|   584k|                if (!ssl2gs ||
  ------------------
  |  Branch (154:21): [True: 584k, False: 0]
  ------------------
  155|   584k|                    ss->gs.rejectV2Records ||
  ------------------
  |  Branch (155:21): [True: 0, False: 0]
  ------------------
  156|   584k|                    ssl3_isLikelyV3Hello(gs->hdr)) {
  ------------------
  |  Branch (156:21): [True: 0, False: 0]
  ------------------
  157|       |                    /* Should have a non-SSLv2 record header in gs->hdr. Extract
  158|       |                     * the length of the following encrypted data, and then
  159|       |                     * read in the rest of the record into gs->inbuf. */
  160|   584k|                    gs->remainder = (gs->hdr[3] << 8) | gs->hdr[4];
  161|   584k|                    gs->hdrLen = SSL3_RECORD_HEADER_LENGTH;
  ------------------
  |  |   26|   584k|#define SSL3_RECORD_HEADER_LENGTH 5
  ------------------
  162|   584k|                } else {
  163|       |                    /* Probably an SSLv2 record header. No need to handle any
  164|       |                     * security escapes (gs->hdr[0] & 0x40) as we wouldn't get
  165|       |                     * here if one was set. See ssl3_isLikelyV3Hello(). */
  166|      0|                    gs->remainder = ((gs->hdr[0] & 0x7f) << 8) | gs->hdr[1];
  167|      0|                    ssl2gs->isV2 = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  168|      0|                    v2HdrLength = 2;
  169|       |
  170|       |                    /* Is it a 3-byte header with padding? */
  171|      0|                    if (!(gs->hdr[0] & 0x80)) {
  ------------------
  |  Branch (171:25): [True: 0, False: 0]
  ------------------
  172|      0|                        ssl2gs->padding = gs->hdr[2];
  173|      0|                        v2HdrLength++;
  174|      0|                    }
  175|      0|                }
  176|       |
  177|       |                /* If it is NOT an SSLv2 header */
  178|   584k|                if (!v2HdrLength) {
  ------------------
  |  Branch (178:21): [True: 584k, False: 0]
  ------------------
  179|       |                    /* Check if default RFC specified max ciphertext/record
  180|       |                     * limits are respected. Checks for used record size limit
  181|       |                     * extension boundaries are done in
  182|       |                     * ssl3con.c/ssl3_HandleRecord() for tls and dtls records.
  183|       |                     *
  184|       |                     * -> For TLS 1.2 records MUST NOT be longer than
  185|       |                     * 2^14 + 2048 bytes.
  186|       |                     * -> For TLS 1.3 records MUST NOT exceed 2^14 + 256 bytes.
  187|       |                     * -> For older versions this MAY be enforced, we do it.
  188|       |                     * [RFC8446 Section 5.2, RFC5246 Section 6.2.3]. */
  189|   584k|                    if (gs->remainder > TLS_1_2_MAX_CTEXT_LENGTH ||
  ------------------
  |  |   39|  1.16M|#define TLS_1_2_MAX_CTEXT_LENGTH ((MAX_FRAGMENT_LENGTH) + (TLS_1_2_MAX_EXPANSION))
  |  |  ------------------
  |  |  |  |   35|   584k|#define MAX_FRAGMENT_LENGTH 16384
  |  |  ------------------
  |  |               #define TLS_1_2_MAX_CTEXT_LENGTH ((MAX_FRAGMENT_LENGTH) + (TLS_1_2_MAX_EXPANSION))
  |  |  ------------------
  |  |  |  |   36|   584k|#define TLS_1_2_MAX_EXPANSION 2048
  |  |  ------------------
  ------------------
  |  Branch (189:25): [True: 278, False: 583k]
  ------------------
  190|   584k|                        (gs->remainder > TLS_1_3_MAX_CTEXT_LENGTH &&
  ------------------
  |  |   38|  1.16M|#define TLS_1_3_MAX_CTEXT_LENGTH ((MAX_FRAGMENT_LENGTH) + (TLS_1_3_MAX_EXPANSION))
  |  |  ------------------
  |  |  |  |   35|   583k|#define MAX_FRAGMENT_LENGTH 16384
  |  |  ------------------
  |  |               #define TLS_1_3_MAX_CTEXT_LENGTH ((MAX_FRAGMENT_LENGTH) + (TLS_1_3_MAX_EXPANSION))
  |  |  ------------------
  |  |  |  |   37|   583k|#define TLS_1_3_MAX_EXPANSION (255 + 1)
  |  |  ------------------
  ------------------
  |  Branch (190:26): [True: 34, False: 583k]
  ------------------
  191|   583k|                         ss->version >= SSL_LIBRARY_VERSION_TLS_1_3)) {
  ------------------
  |  |   21|     34|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (191:26): [True: 1, False: 33]
  ------------------
  192|    279|                        SSL3_SendAlert(ss, alert_fatal, record_overflow);
  193|    279|                        gs->state = GS_INIT;
  ------------------
  |  |  381|    279|#define GS_INIT 0
  ------------------
  194|    279|                        PORT_SetError(SSL_ERROR_RX_RECORD_TOO_LONG);
  ------------------
  |  |   65|    279|#define PORT_SetError PORT_SetError_Util
  ------------------
  195|    279|                        return SECFailure;
  196|    279|                    }
  197|   584k|                }
  198|       |
  199|   583k|                gs->state = GS_DATA;
  ------------------
  |  |  383|   583k|#define GS_DATA 2
  ------------------
  200|   583k|                gs->offset = 0;
  201|   583k|                gs->inbuf.len = 0;
  202|       |
  203|   583k|                if (gs->remainder > gs->inbuf.space) {
  ------------------
  |  Branch (203:21): [True: 575k, False: 7.99k]
  ------------------
  204|   575k|                    err = sslBuffer_Grow(&gs->inbuf, gs->remainder);
  205|   575k|                    if (err) { /* realloc has set error code to no mem. */
  ------------------
  |  Branch (205:25): [True: 0, False: 575k]
  ------------------
  206|      0|                        return err;
  207|      0|                    }
  208|   575k|                    lbp = gs->inbuf.buf;
  209|   575k|                }
  210|       |
  211|       |                /* When we encounter an SSLv2 hello we've read 2 or 3 bytes too
  212|       |                 * many into the gs->hdr[] buffer. Copy them over into inbuf so
  213|       |                 * that we can properly process the hello record later. */
  214|   583k|                if (v2HdrLength) {
  ------------------
  |  Branch (214:21): [True: 0, False: 583k]
  ------------------
  215|       |                    /* Reject v2 records that don't even carry enough data to
  216|       |                     * resemble a valid ClientHello header. */
  217|      0|                    if (gs->remainder < SSL_HL_CLIENT_HELLO_HBYTES) {
  ------------------
  |  |  231|      0|#define SSL_HL_CLIENT_HELLO_HBYTES              9
  ------------------
  |  Branch (217:25): [True: 0, False: 0]
  ------------------
  218|      0|                        SSL3_SendAlert(ss, alert_fatal, illegal_parameter);
  219|      0|                        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  220|      0|                        return SECFailure;
  221|      0|                    }
  222|       |
  223|      0|                    PORT_Assert(lbp);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  224|      0|                    gs->inbuf.len = 5 - v2HdrLength;
  225|      0|                    PORT_Memcpy(lbp, gs->hdr + v2HdrLength, gs->inbuf.len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  226|      0|                    gs->remainder -= gs->inbuf.len;
  227|      0|                    lbp += gs->inbuf.len;
  228|      0|                }
  229|       |
  230|   583k|                if (gs->remainder > 0) {
  ------------------
  |  Branch (230:21): [True: 575k, False: 7.99k]
  ------------------
  231|   575k|                    break; /* End this case.  Continue around the loop. */
  232|   575k|                }
  233|       |
  234|       |                /* FALL THROUGH if (gs->remainder == 0) as we just received
  235|       |                 * an empty record and there's really no point in calling
  236|       |                 * ssl_DefRecv() with buf=NULL and len=0. */
  237|       |
  238|   583k|            case GS_DATA:
  ------------------
  |  |  383|   583k|#define GS_DATA 2
  ------------------
  |  Branch (238:13): [True: 575k, False: 584k]
  ------------------
  239|       |                /*
  240|       |                ** SSL3 record has been completely received.
  241|       |                */
  242|   583k|                SSL_TRC(10, ("%d: SSL[%d]: got record of %d bytes",
  ------------------
  |  |   71|   583k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 583k]
  |  |  ------------------
  |  |   72|   583k|    ssl_Trace b
  ------------------
  243|   583k|                             SSL_GETPID(), ss->fd, gs->inbuf.len));
  244|       |
  245|       |                /* reject any v2 records from now on */
  246|   583k|                ss->gs.rejectV2Records = PR_TRUE;
  ------------------
  |  |  437|   583k|#define PR_TRUE 1
  ------------------
  247|       |
  248|   583k|                gs->state = GS_INIT;
  ------------------
  |  |  381|   583k|#define GS_INIT 0
  ------------------
  249|   583k|                return 1;
  250|  1.15M|        }
  251|  1.15M|    }
  252|       |
  253|  6.10k|    return rv;
  254|   589k|}

SSL_AuthCertificateHook:
  238|  9.71k|{
  239|  9.71k|    sslSocket *ss;
  240|       |
  241|  9.71k|    ss = ssl_FindSocket(s);
  242|  9.71k|    if (!ss) {
  ------------------
  |  Branch (242:9): [True: 0, False: 9.71k]
  ------------------
  243|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in AuthCertificateHook",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  244|      0|                 SSL_GETPID(), s));
  245|      0|        return SECFailure;
  246|      0|    }
  247|       |
  248|  9.71k|    ss->authCertificate = func;
  249|  9.71k|    ss->authCertificateArg = arg;
  250|       |
  251|  9.71k|    return SECSuccess;
  252|  9.71k|}

ssl_SetupCAList:
   51|  5.55k|{
   52|  5.55k|    if (PR_SUCCESS != PR_CallOnceWithArg(&ssl_server_ca_list.setup,
  ------------------
  |  Branch (52:9): [True: 0, False: 5.55k]
  ------------------
   53|  5.55k|                                         &ssl_SetupCAListOnce,
   54|  5.55k|                                         (void *)(ss->dbHandle))) {
   55|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   56|      0|        return SECFailure;
   57|      0|    }
   58|  5.55k|    return SECSuccess;
   59|  5.55k|}
ssl_GetCertificateRequestCAs:
   64|  5.55k|{
   65|  5.55k|    const SECItem *name;
   66|  5.55k|    const CERTDistNames *ca_list;
   67|  5.55k|    unsigned int i;
   68|       |
   69|  5.55k|    *calen = 0;
   70|  5.55k|    *names = NULL;
   71|  5.55k|    *nnames = 0;
   72|       |
   73|       |    /* ssl3.ca_list is initialized to NULL, and never changed. */
   74|  5.55k|    ca_list = ss->ssl3.ca_list;
   75|  5.55k|    if (!ca_list) {
  ------------------
  |  Branch (75:9): [True: 5.55k, False: 0]
  ------------------
   76|  5.55k|        if (ssl_SetupCAList(ss) != SECSuccess) {
  ------------------
  |  Branch (76:13): [True: 0, False: 5.55k]
  ------------------
   77|      0|            return SECFailure;
   78|      0|        }
   79|  5.55k|        ca_list = ssl_server_ca_list.names;
   80|  5.55k|    }
   81|       |
   82|  5.55k|    if (ca_list != NULL) {
  ------------------
  |  Branch (82:9): [True: 5.55k, False: 0]
  ------------------
   83|  5.55k|        *names = ca_list->names;
   84|  5.55k|        *nnames = ca_list->nnames;
   85|  5.55k|    }
   86|       |
   87|  5.55k|    for (i = 0, name = *names; i < *nnames; i++, name++) {
  ------------------
  |  Branch (87:32): [True: 0, False: 5.55k]
  ------------------
   88|      0|        *calen += 2 + name->len;
   89|      0|    }
   90|  5.55k|    return SECSuccess;
   91|  5.55k|}
ssl_NewServerCert:
   95|  19.4k|{
   96|  19.4k|    sslServerCert *sc = PORT_ZNew(sslServerCert);
  ------------------
  |  |  148|  19.4k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  19.4k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
   97|  19.4k|    if (!sc) {
  ------------------
  |  Branch (97:9): [True: 0, False: 19.4k]
  ------------------
   98|      0|        return NULL;
   99|      0|    }
  100|  19.4k|    sc->authTypes = 0;
  101|  19.4k|    sc->namedCurve = NULL;
  102|  19.4k|    sc->serverCert = NULL;
  103|  19.4k|    sc->serverCertChain = NULL;
  104|  19.4k|    sc->certStatusArray = NULL;
  105|  19.4k|    sc->signedCertTimestamps.len = 0;
  106|  19.4k|    sc->delegCred.len = 0;
  107|  19.4k|    sc->delegCredKeyPair = NULL;
  108|  19.4k|    return sc;
  109|  19.4k|}
ssl_CopyServerCert:
  113|  19.4k|{
  114|  19.4k|    sslServerCert *sc;
  115|       |
  116|  19.4k|    sc = ssl_NewServerCert();
  117|  19.4k|    if (!sc) {
  ------------------
  |  Branch (117:9): [True: 0, False: 19.4k]
  ------------------
  118|      0|        return NULL;
  119|      0|    }
  120|       |
  121|  19.4k|    sc->authTypes = oc->authTypes;
  122|  19.4k|    sc->namedCurve = oc->namedCurve;
  123|       |
  124|  19.4k|    if (oc->serverCert && oc->serverCertChain) {
  ------------------
  |  Branch (124:9): [True: 19.4k, False: 0]
  |  Branch (124:27): [True: 19.4k, False: 0]
  ------------------
  125|  19.4k|        sc->serverCert = CERT_DupCertificate(oc->serverCert);
  126|  19.4k|        if (!sc->serverCert)
  ------------------
  |  Branch (126:13): [True: 0, False: 19.4k]
  ------------------
  127|      0|            goto loser;
  128|  19.4k|        sc->serverCertChain = CERT_DupCertList(oc->serverCertChain);
  129|  19.4k|        if (!sc->serverCertChain)
  ------------------
  |  Branch (129:13): [True: 0, False: 19.4k]
  ------------------
  130|      0|            goto loser;
  131|  19.4k|    } else {
  132|      0|        sc->serverCert = NULL;
  133|      0|        sc->serverCertChain = NULL;
  134|      0|    }
  135|       |
  136|  19.4k|    if (oc->serverKeyPair) {
  ------------------
  |  Branch (136:9): [True: 19.4k, False: 0]
  ------------------
  137|  19.4k|        sc->serverKeyPair = ssl_GetKeyPairRef(oc->serverKeyPair);
  138|  19.4k|        if (!sc->serverKeyPair)
  ------------------
  |  Branch (138:13): [True: 0, False: 19.4k]
  ------------------
  139|      0|            goto loser;
  140|  19.4k|    } else {
  141|      0|        sc->serverKeyPair = NULL;
  142|      0|    }
  143|  19.4k|    sc->serverKeyBits = oc->serverKeyBits;
  144|       |
  145|  19.4k|    if (oc->certStatusArray) {
  ------------------
  |  Branch (145:9): [True: 0, False: 19.4k]
  ------------------
  146|      0|        sc->certStatusArray = SECITEM_DupArray(NULL, oc->certStatusArray);
  147|      0|        if (!sc->certStatusArray)
  ------------------
  |  Branch (147:13): [True: 0, False: 0]
  ------------------
  148|      0|            goto loser;
  149|  19.4k|    } else {
  150|  19.4k|        sc->certStatusArray = NULL;
  151|  19.4k|    }
  152|       |
  153|  19.4k|    if (SECITEM_CopyItem(NULL, &sc->signedCertTimestamps,
  ------------------
  |  |  106|  19.4k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (153:9): [True: 0, False: 19.4k]
  ------------------
  154|  19.4k|                         &oc->signedCertTimestamps) != SECSuccess) {
  155|      0|        goto loser;
  156|      0|    }
  157|       |
  158|  19.4k|    if (SECITEM_CopyItem(NULL, &sc->delegCred, &oc->delegCred) != SECSuccess) {
  ------------------
  |  |  106|  19.4k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (158:9): [True: 0, False: 19.4k]
  ------------------
  159|      0|        goto loser;
  160|      0|    }
  161|  19.4k|    if (oc->delegCredKeyPair) {
  ------------------
  |  Branch (161:9): [True: 0, False: 19.4k]
  ------------------
  162|      0|        sc->delegCredKeyPair = ssl_GetKeyPairRef(oc->delegCredKeyPair);
  163|      0|    }
  164|       |
  165|  19.4k|    return sc;
  166|      0|loser:
  167|      0|    ssl_FreeServerCert(sc);
  168|      0|    return NULL;
  169|  19.4k|}
ssl_FreeServerCert:
  173|  19.4k|{
  174|  19.4k|    if (!sc) {
  ------------------
  |  Branch (174:9): [True: 0, False: 19.4k]
  ------------------
  175|      0|        return;
  176|      0|    }
  177|       |
  178|  19.4k|    if (sc->serverCert) {
  ------------------
  |  Branch (178:9): [True: 19.4k, False: 0]
  ------------------
  179|  19.4k|        CERT_DestroyCertificate(sc->serverCert);
  180|  19.4k|    }
  181|  19.4k|    if (sc->serverCertChain) {
  ------------------
  |  Branch (181:9): [True: 19.4k, False: 0]
  ------------------
  182|  19.4k|        CERT_DestroyCertificateList(sc->serverCertChain);
  183|  19.4k|    }
  184|  19.4k|    if (sc->serverKeyPair) {
  ------------------
  |  Branch (184:9): [True: 19.4k, False: 0]
  ------------------
  185|  19.4k|        ssl_FreeKeyPair(sc->serverKeyPair);
  186|  19.4k|    }
  187|  19.4k|    if (sc->certStatusArray) {
  ------------------
  |  Branch (187:9): [True: 0, False: 19.4k]
  ------------------
  188|      0|        SECITEM_FreeArray(sc->certStatusArray, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  189|      0|    }
  190|  19.4k|    if (sc->signedCertTimestamps.len) {
  ------------------
  |  Branch (190:9): [True: 0, False: 19.4k]
  ------------------
  191|      0|        SECITEM_FreeItem(&sc->signedCertTimestamps, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sc->signedCertTimestamps, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  192|      0|    }
  193|  19.4k|    if (sc->delegCred.len) {
  ------------------
  |  Branch (193:9): [True: 0, False: 19.4k]
  ------------------
  194|      0|        SECITEM_FreeItem(&sc->delegCred, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sc->delegCred, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  195|      0|    }
  196|  19.4k|    if (sc->delegCredKeyPair) {
  ------------------
  |  Branch (196:9): [True: 0, False: 19.4k]
  ------------------
  197|      0|        ssl_FreeKeyPair(sc->delegCredKeyPair);
  198|      0|    }
  199|  19.4k|    PORT_ZFree(sc, sizeof(*sc));
  ------------------
  |  |   75|  19.4k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  200|  19.4k|}
ssl_FindServerCert:
  205|      6|{
  206|      6|    PRCList *cursor;
  207|       |
  208|       |    /* Bug 1749475: avoid UB while fuzzing session tickets */
  209|      6|    if ((unsigned)authType >= ssl_auth_size) {
  ------------------
  |  Branch (209:9): [True: 1, False: 5]
  ------------------
  210|      1|        return NULL;
  211|      1|    }
  212|       |
  213|      5|    for (cursor = PR_NEXT_LINK(&ss->serverCerts);
  ------------------
  |  |   47|      5|        ((_e)->next)
  ------------------
  214|     11|         cursor != &ss->serverCerts;
  ------------------
  |  Branch (214:10): [True: 9, False: 2]
  ------------------
  215|      9|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|      6|        ((_e)->next)
  ------------------
  216|      9|        sslServerCert *cert = (sslServerCert *)cursor;
  217|      9|        if (!SSL_CERT_IS(cert, authType)) {
  ------------------
  |  |   53|      9|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  ------------------
  |  Branch (217:13): [True: 5, False: 4]
  ------------------
  218|      5|            continue;
  219|      5|        }
  220|      4|        if (SSL_CERT_IS_EC(cert)) {
  ------------------
  |  |   56|      4|    ((c)->authTypes & ((1 << ssl_auth_ecdsa) |    \
  |  |  ------------------
  |  |  |  Branch (56:5): [True: 2, False: 2]
  |  |  ------------------
  |  |   57|      4|                       (1 << ssl_auth_ecdh_rsa) | \
  |  |   58|      4|                       (1 << ssl_auth_ecdh_ecdsa)))
  ------------------
  221|       |            /* Note: For deprecated APIs, we need to be able to find and
  222|       |               match a slot with any named curve. */
  223|      2|            if (namedCurve && cert->namedCurve != namedCurve) {
  ------------------
  |  Branch (223:17): [True: 2, False: 0]
  |  Branch (223:31): [True: 1, False: 1]
  ------------------
  224|      1|                continue;
  225|      1|            }
  226|      2|        }
  227|      3|        return cert;
  228|      4|    }
  229|      2|    return NULL;
  230|      5|}
SSL_ConfigServerCert:
  648|      2|{
  649|      2|    sslSocket *ss;
  650|      2|    sslKeyPair *keyPair;
  651|      2|    SECStatus rv;
  652|      2|    SSLExtraServerCertData dataCopy = {
  653|      2|        ssl_auth_null, NULL, NULL, NULL, NULL, NULL
  654|      2|    };
  655|      2|    sslAuthTypeMask authTypes;
  656|       |
  657|      2|    ss = ssl_FindSocket(fd);
  658|      2|    if (!ss) {
  ------------------
  |  Branch (658:9): [True: 0, False: 2]
  ------------------
  659|      0|        return SECFailure;
  660|      0|    }
  661|       |
  662|      2|    if (!cert || !key) {
  ------------------
  |  Branch (662:9): [True: 0, False: 2]
  |  Branch (662:18): [True: 0, False: 2]
  ------------------
  663|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  664|      0|        return SECFailure;
  665|      0|    }
  666|       |
  667|      2|    if (data) {
  ------------------
  |  Branch (667:9): [True: 0, False: 2]
  ------------------
  668|      0|        if (data_len > sizeof(dataCopy)) {
  ------------------
  |  Branch (668:13): [True: 0, False: 0]
  ------------------
  669|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  670|      0|            return SECFailure;
  671|      0|        }
  672|      0|        PORT_Memcpy(&dataCopy, data, data_len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  673|      0|    }
  674|       |
  675|      2|    authTypes = ssl_GetCertificateAuthTypes(cert, dataCopy.authType);
  676|      2|    if (!authTypes) {
  ------------------
  |  Branch (676:9): [True: 0, False: 2]
  ------------------
  677|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  678|      0|        return SECFailure;
  679|      0|    }
  680|       |
  681|      2|    keyPair = ssl_MakeKeyPairForCert(key, cert);
  682|      2|    if (!keyPair) {
  ------------------
  |  Branch (682:9): [True: 0, False: 2]
  ------------------
  683|      0|        return SECFailure;
  684|      0|    }
  685|       |
  686|      2|    rv = ssl_ConfigCert(ss, authTypes, cert, keyPair, &dataCopy);
  687|      2|    ssl_FreeKeyPair(keyPair);
  688|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (688:9): [True: 0, False: 2]
  ------------------
  689|      0|        return SECFailure;
  690|      0|    }
  691|      2|    return SECSuccess;
  692|      2|}
sslcert.c:ssl_SetupCAListOnce:
   38|      1|{
   39|      1|    CERTCertDBHandle *dbHandle = (CERTCertDBHandle *)arg;
   40|      1|    SECStatus rv = NSS_RegisterShutdown(ssl_ServerCAListShutdown, NULL);
   41|      1|    PORT_Assert(SECSuccess == rv);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   42|      1|    if (SECSuccess == rv) {
  ------------------
  |  Branch (42:9): [True: 1, False: 0]
  ------------------
   43|      1|        ssl_server_ca_list.names = CERT_GetSSLCACerts(dbHandle);
   44|      1|        return PR_SUCCESS;
   45|      1|    }
   46|      0|    return PR_FAILURE;
   47|      1|}
sslcert.c:ssl_ServerCAListShutdown:
   27|      1|{
   28|      1|    PORT_Assert(ssl_server_ca_list.names);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   29|      1|    if (ssl_server_ca_list.names) {
  ------------------
  |  Branch (29:9): [True: 1, False: 0]
  ------------------
   30|      1|        CERT_FreeDistNames(ssl_server_ca_list.names);
   31|      1|    }
   32|      1|    PORT_Memset(&ssl_server_ca_list, 0, sizeof(ssl_server_ca_list));
  ------------------
  |  |  182|      1|#define PORT_Memset memset
  ------------------
   33|      1|    return SECSuccess;
   34|      1|}
sslcert.c:ssl_GetCertificateAuthTypes:
  531|      2|{
  532|      2|    sslAuthTypeMask authTypes = 0;
  533|      2|    SECOidTag tag;
  534|       |
  535|      2|    tag = SECOID_GetAlgorithmTag(&cert->subjectPublicKeyInfo.algorithm);
  ------------------
  |  |  119|      2|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
  536|      2|    switch (tag) {
  537|      0|        case SEC_OID_X500_RSA_ENCRYPTION:
  ------------------
  |  Branch (537:9): [True: 0, False: 2]
  ------------------
  538|      1|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (538:9): [True: 1, False: 1]
  ------------------
  539|      1|            if (cert->keyUsage & KU_DIGITAL_SIGNATURE) {
  ------------------
  |  |  562|      1|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  ------------------
  |  Branch (539:17): [True: 1, False: 0]
  ------------------
  540|      1|                authTypes |= 1 << ssl_auth_rsa_sign;
  541|      1|            }
  542|       |
  543|      1|            if (cert->keyUsage & KU_KEY_ENCIPHERMENT) {
  ------------------
  |  |  564|      1|#define KU_KEY_ENCIPHERMENT (0x20)  /* bit 2 */
  ------------------
  |  Branch (543:17): [True: 1, False: 0]
  ------------------
  544|       |                /* If ku_sig=true we configure signature and encryption slots with the
  545|       |                 * same cert. This is bad form, but there are enough dual-usage RSA
  546|       |                 * certs that we can't really break by limiting this to one type. */
  547|      1|                authTypes |= 1 << ssl_auth_rsa_decrypt;
  548|      1|            }
  549|      1|            break;
  550|       |
  551|      0|        case SEC_OID_PKCS1_RSA_PSS_SIGNATURE:
  ------------------
  |  Branch (551:9): [True: 0, False: 2]
  ------------------
  552|      0|            if (cert->keyUsage & KU_DIGITAL_SIGNATURE) {
  ------------------
  |  |  562|      0|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  ------------------
  |  Branch (552:17): [True: 0, False: 0]
  ------------------
  553|      0|                authTypes |= 1 << ssl_auth_rsa_pss;
  554|      0|            }
  555|      0|            break;
  556|       |
  557|      0|        case SEC_OID_ANSIX9_DSA_SIGNATURE:
  ------------------
  |  Branch (557:9): [True: 0, False: 2]
  ------------------
  558|      0|            if (cert->keyUsage & KU_DIGITAL_SIGNATURE) {
  ------------------
  |  |  562|      0|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  ------------------
  |  Branch (558:17): [True: 0, False: 0]
  ------------------
  559|      0|                authTypes |= 1 << ssl_auth_dsa;
  560|      0|            }
  561|      0|            break;
  562|       |
  563|      1|        case SEC_OID_ANSIX962_EC_PUBLIC_KEY:
  ------------------
  |  Branch (563:9): [True: 1, False: 1]
  ------------------
  564|      1|            if (cert->keyUsage & KU_DIGITAL_SIGNATURE) {
  ------------------
  |  |  562|      1|#define KU_DIGITAL_SIGNATURE (0x80) /* bit 0 */
  ------------------
  |  Branch (564:17): [True: 1, False: 0]
  ------------------
  565|      1|                authTypes |= 1 << ssl_auth_ecdsa;
  566|      1|            }
  567|       |            /* Again, bad form to have dual usage and we don't prevent it. */
  568|      1|            if (cert->keyUsage & KU_KEY_ENCIPHERMENT) {
  ------------------
  |  |  564|      1|#define KU_KEY_ENCIPHERMENT (0x20)  /* bit 2 */
  ------------------
  |  Branch (568:17): [True: 1, False: 0]
  ------------------
  569|      1|                authTypes |= 1 << ssl_GetEcdhAuthType(cert);
  570|      1|            }
  571|      1|            break;
  572|       |
  573|      0|        default:
  ------------------
  |  Branch (573:9): [True: 0, False: 2]
  ------------------
  574|      0|            break;
  575|      2|    }
  576|       |
  577|       |    /* Check that we successfully picked an authType */
  578|      2|    if (targetAuthType != ssl_auth_null) {
  ------------------
  |  Branch (578:9): [True: 0, False: 2]
  ------------------
  579|      0|        authTypes &= 1 << targetAuthType;
  580|      0|    }
  581|      2|    return authTypes;
  582|      2|}
sslcert.c:ssl_GetEcdhAuthType:
  496|      1|{
  497|      1|    SECOidTag sigTag = SECOID_GetAlgorithmTag(&cert->signature);
  ------------------
  |  |  119|      1|#define SECOID_GetAlgorithmTag SECOID_GetAlgorithmTag_Util
  ------------------
  498|      1|    switch (sigTag) {
  499|      0|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (499:9): [True: 0, False: 1]
  ------------------
  500|      0|        case SEC_OID_PKCS1_RSA_PSS_SIGNATURE:
  ------------------
  |  Branch (500:9): [True: 0, False: 1]
  ------------------
  501|      0|        case SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (501:9): [True: 0, False: 1]
  ------------------
  502|      0|        case SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (502:9): [True: 0, False: 1]
  ------------------
  503|      0|        case SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (503:9): [True: 0, False: 1]
  ------------------
  504|      0|        case SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (504:9): [True: 0, False: 1]
  ------------------
  505|      0|        case SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (505:9): [True: 0, False: 1]
  ------------------
  506|      0|        case SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (506:9): [True: 0, False: 1]
  ------------------
  507|      0|        case SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (507:9): [True: 0, False: 1]
  ------------------
  508|      0|        case SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (508:9): [True: 0, False: 1]
  ------------------
  509|      0|            return ssl_auth_ecdh_rsa;
  510|      1|        case SEC_OID_ANSIX962_ECDSA_SHA1_SIGNATURE:
  ------------------
  |  Branch (510:9): [True: 1, False: 0]
  ------------------
  511|      1|        case SEC_OID_ANSIX962_ECDSA_SHA224_SIGNATURE:
  ------------------
  |  Branch (511:9): [True: 0, False: 1]
  ------------------
  512|      1|        case SEC_OID_ANSIX962_ECDSA_SHA256_SIGNATURE:
  ------------------
  |  Branch (512:9): [True: 0, False: 1]
  ------------------
  513|      1|        case SEC_OID_ANSIX962_ECDSA_SHA384_SIGNATURE:
  ------------------
  |  Branch (513:9): [True: 0, False: 1]
  ------------------
  514|      1|        case SEC_OID_ANSIX962_ECDSA_SHA512_SIGNATURE:
  ------------------
  |  Branch (514:9): [True: 0, False: 1]
  ------------------
  515|      1|        case SEC_OID_ANSIX962_ECDSA_SIGNATURE_RECOMMENDED_DIGEST:
  ------------------
  |  Branch (515:9): [True: 0, False: 1]
  ------------------
  516|      1|        case SEC_OID_ANSIX962_ECDSA_SIGNATURE_SPECIFIED_DIGEST:
  ------------------
  |  Branch (516:9): [True: 0, False: 1]
  ------------------
  517|      1|            return ssl_auth_ecdh_ecdsa;
  518|      0|        default:
  ------------------
  |  Branch (518:9): [True: 0, False: 1]
  ------------------
  519|      0|            return ssl_auth_null;
  520|      1|    }
  521|      1|}
sslcert.c:ssl_MakeKeyPairForCert:
  587|      2|{
  588|      2|    sslKeyPair *keyPair = NULL;
  589|      2|    SECKEYPublicKey *pubKey = NULL;
  590|      2|    SECKEYPrivateKey *privKeyCopy = NULL;
  591|      2|    PK11SlotInfo *bestSlot;
  592|       |
  593|      2|    pubKey = CERT_ExtractPublicKey(cert);
  594|      2|    if (!pubKey) {
  ------------------
  |  Branch (594:9): [True: 0, False: 2]
  ------------------
  595|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  596|      0|        return NULL;
  597|      0|    }
  598|       |
  599|      2|    if (SECKEY_GetPublicKeyType(pubKey) != SECKEY_GetPrivateKeyType(key)) {
  ------------------
  |  Branch (599:9): [True: 0, False: 2]
  ------------------
  600|      0|        SECKEY_DestroyPublicKey(pubKey);
  601|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  602|      0|        return NULL;
  603|      0|    }
  604|       |
  605|      2|    if (key->pkcs11Slot) {
  ------------------
  |  Branch (605:9): [True: 2, False: 0]
  ------------------
  606|      2|        bestSlot = PK11_ReferenceSlot(key->pkcs11Slot);
  607|      2|        if (bestSlot) {
  ------------------
  |  Branch (607:13): [True: 2, False: 0]
  ------------------
  608|      2|            privKeyCopy = PK11_CopyTokenPrivKeyToSessionPrivKey(bestSlot, key);
  609|      2|            PK11_FreeSlot(bestSlot);
  610|      2|        }
  611|      2|    }
  612|      2|    if (!privKeyCopy) {
  ------------------
  |  Branch (612:9): [True: 0, False: 2]
  ------------------
  613|      0|        CK_MECHANISM_TYPE keyMech = PK11_MapSignKeyType(key->keyType);
  614|       |        /* XXX Maybe should be bestSlotMultiple? */
  615|      0|        bestSlot = PK11_GetBestSlot(keyMech, NULL /* wincx */);
  616|      0|        if (bestSlot) {
  ------------------
  |  Branch (616:13): [True: 0, False: 0]
  ------------------
  617|      0|            privKeyCopy = PK11_CopyTokenPrivKeyToSessionPrivKey(bestSlot, key);
  618|      0|            PK11_FreeSlot(bestSlot);
  619|      0|        }
  620|      0|    }
  621|      2|    if (!privKeyCopy) {
  ------------------
  |  Branch (621:9): [True: 0, False: 2]
  ------------------
  622|      0|        privKeyCopy = SECKEY_CopyPrivateKey(key);
  623|      0|    }
  624|      2|    if (privKeyCopy) {
  ------------------
  |  Branch (624:9): [True: 2, False: 0]
  ------------------
  625|      2|        keyPair = ssl_NewKeyPair(privKeyCopy, pubKey);
  626|      2|    }
  627|      2|    if (!keyPair) {
  ------------------
  |  Branch (627:9): [True: 0, False: 2]
  ------------------
  628|      0|        if (privKeyCopy) {
  ------------------
  |  Branch (628:13): [True: 0, False: 0]
  ------------------
  629|      0|            SECKEY_DestroyPrivateKey(privKeyCopy);
  630|      0|        }
  631|      0|        SECKEY_DestroyPublicKey(pubKey);
  632|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  633|      0|    }
  634|      2|    return keyPair;
  635|      2|}
sslcert.c:ssl_ConfigCert:
  440|      2|{
  441|      2|    SECStatus rv;
  442|      2|    sslServerCert *sc = NULL;
  443|      2|    int error_code = SEC_ERROR_NO_MEMORY;
  444|       |
  445|      2|    PORT_Assert(cert);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  446|      2|    PORT_Assert(keyPair);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  447|      2|    PORT_Assert(data);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  448|      2|    PORT_Assert(authTypes);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  449|       |
  450|      2|    if (!cert || !keyPair || !data || !authTypes) {
  ------------------
  |  Branch (450:9): [True: 0, False: 2]
  |  Branch (450:18): [True: 0, False: 2]
  |  Branch (450:30): [True: 0, False: 2]
  |  Branch (450:39): [True: 0, False: 2]
  ------------------
  451|      0|        error_code = SEC_ERROR_INVALID_ARGS;
  452|      0|        goto loser;
  453|      0|    }
  454|       |
  455|      2|    sc = ssl_NewServerCert();
  456|      2|    if (!sc) {
  ------------------
  |  Branch (456:9): [True: 0, False: 2]
  ------------------
  457|      0|        goto loser;
  458|      0|    }
  459|       |
  460|      2|    sc->authTypes = authTypes;
  461|      2|    rv = ssl_PopulateServerCert(sc, cert, data->certChain);
  462|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (462:9): [True: 0, False: 2]
  ------------------
  463|      0|        goto loser;
  464|      0|    }
  465|      2|    rv = ssl_PopulateKeyPair(sc, keyPair);
  466|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (466:9): [True: 0, False: 2]
  ------------------
  467|      0|        error_code = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  468|      0|        goto loser;
  469|      0|    }
  470|      2|    rv = ssl_PopulateOCSPResponses(sc, data->stapledOCSPResponses);
  471|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (471:9): [True: 0, False: 2]
  ------------------
  472|      0|        goto loser;
  473|      0|    }
  474|      2|    rv = ssl_PopulateSignedCertTimestamps(sc, data->signedCertTimestamps);
  475|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (475:9): [True: 0, False: 2]
  ------------------
  476|      0|        goto loser;
  477|      0|    }
  478|      2|    rv = ssl_PopulateDelegatedCredential(sc, data->delegCred,
  479|      2|                                         data->delegCredPrivKey);
  480|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (480:9): [True: 0, False: 2]
  ------------------
  481|      0|        error_code = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  482|      0|        goto loser;
  483|      0|    }
  484|      2|    ssl_ClearMatchingCerts(ss, sc->authTypes, sc->namedCurve);
  485|      2|    PR_APPEND_LINK(&sc->link, &ss->serverCerts);
  ------------------
  |  |   57|      2|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|      2|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|      2|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|      2|    (_e)->next = (_l);   \
  |  |  |  |   27|      2|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|      2|    (_l)->prev->next = (_e); \
  |  |  |  |   29|      2|    (_l)->prev = (_e);   \
  |  |  |  |   30|      2|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|      2|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  486|      2|    return SECSuccess;
  487|       |
  488|      0|loser:
  489|      0|    ssl_FreeServerCert(sc);
  490|      0|    PORT_SetError(error_code);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  491|      0|    return SECFailure;
  492|      2|}
sslcert.c:ssl_PopulateDelegatedCredential:
  345|      2|{
  346|      2|    sslDelegatedCredential *dc = NULL;
  347|       |
  348|      2|    if (sc->delegCred.len) {
  ------------------
  |  Branch (348:9): [True: 0, False: 2]
  ------------------
  349|      0|        SECITEM_FreeItem(&sc->delegCred, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sc->delegCred, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  350|      0|    }
  351|       |
  352|      2|    if (sc->delegCredKeyPair) {
  ------------------
  |  Branch (352:9): [True: 0, False: 2]
  ------------------
  353|      0|        ssl_FreeKeyPair(sc->delegCredKeyPair);
  354|      0|        sc->delegCredKeyPair = NULL;
  355|      0|    }
  356|       |
  357|       |    /* Both the DC and its private are present. */
  358|      2|    if (delegCred && delegCredPrivKey) {
  ------------------
  |  Branch (358:9): [True: 0, False: 2]
  |  Branch (358:22): [True: 0, False: 0]
  ------------------
  359|      0|        SECStatus rv;
  360|      0|        SECKEYPublicKey *pub;
  361|      0|        SECKEYPrivateKey *priv;
  362|       |
  363|      0|        if (!delegCred->data || delegCred->len == 0) {
  ------------------
  |  Branch (363:13): [True: 0, False: 0]
  |  Branch (363:33): [True: 0, False: 0]
  ------------------
  364|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  365|      0|            goto loser;
  366|      0|        }
  367|       |
  368|       |        /* Parse the DC. */
  369|      0|        rv = tls13_ReadDelegatedCredential(delegCred->data, delegCred->len, &dc);
  370|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (370:13): [True: 0, False: 0]
  ------------------
  371|      0|            goto loser;
  372|      0|        }
  373|       |
  374|       |        /* Make a copy of the DC. */
  375|      0|        rv = SECITEM_CopyItem(NULL, &sc->delegCred, delegCred);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  376|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (376:13): [True: 0, False: 0]
  ------------------
  377|      0|            goto loser;
  378|      0|        }
  379|       |
  380|       |        /* Make a copy of the DC private key. */
  381|      0|        priv = SECKEY_CopyPrivateKey(delegCredPrivKey);
  382|      0|        if (!priv) {
  ------------------
  |  Branch (382:13): [True: 0, False: 0]
  ------------------
  383|      0|            goto loser;
  384|      0|        }
  385|       |
  386|       |        /* parse public key from the DC. */
  387|      0|        pub = SECKEY_ExtractPublicKey(dc->spki);
  388|      0|        if (!pub) {
  ------------------
  |  Branch (388:13): [True: 0, False: 0]
  ------------------
  389|      0|            goto loser;
  390|      0|        }
  391|       |
  392|      0|        sc->delegCredKeyPair = ssl_NewKeyPair(priv, pub);
  393|       |
  394|       |        /* Attempting to configure either the DC or DC private key, but not both. */
  395|      2|    } else if (delegCred || delegCredPrivKey) {
  ------------------
  |  Branch (395:16): [True: 0, False: 2]
  |  Branch (395:29): [True: 0, False: 2]
  ------------------
  396|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  397|      0|        goto loser;
  398|      0|    }
  399|       |
  400|      2|    tls13_DestroyDelegatedCredential(dc);
  401|      2|    return SECSuccess;
  402|       |
  403|      0|loser:
  404|      0|    tls13_DestroyDelegatedCredential(dc);
  405|      0|    return SECFailure;
  406|      2|}
sslcert.c:ssl_ClearMatchingCerts:
  414|      2|{
  415|      2|    PRCList *cursor = PR_NEXT_LINK(&ss->serverCerts);
  ------------------
  |  |   47|      2|        ((_e)->next)
  ------------------
  416|       |
  417|      3|    while (cursor != &ss->serverCerts) {
  ------------------
  |  Branch (417:12): [True: 1, False: 2]
  ------------------
  418|      1|        sslServerCert *sc = (sslServerCert *)cursor;
  419|      1|        cursor = PR_NEXT_LINK(cursor);
  ------------------
  |  |   47|      1|        ((_e)->next)
  ------------------
  420|      1|        if ((sc->authTypes & authTypes) == 0) {
  ------------------
  |  Branch (420:13): [True: 1, False: 0]
  ------------------
  421|      1|            continue;
  422|      1|        }
  423|       |        /* namedCurve will be NULL only for legacy functions. */
  424|      0|        if (namedCurve != NULL && sc->namedCurve != namedCurve) {
  ------------------
  |  Branch (424:13): [True: 0, False: 0]
  |  Branch (424:35): [True: 0, False: 0]
  ------------------
  425|      0|            continue;
  426|      0|        }
  427|       |
  428|      0|        sc->authTypes &= ~authTypes;
  429|      0|        if (sc->authTypes == 0) {
  ------------------
  |  Branch (429:13): [True: 0, False: 0]
  ------------------
  430|      0|            PR_REMOVE_LINK(&sc->link);
  ------------------
  |  |   72|      0|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      0|    (_e)->prev->next = (_e)->next; \
  |  |   74|      0|    (_e)->next->prev = (_e)->prev; \
  |  |   75|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  431|      0|            ssl_FreeServerCert(sc);
  432|      0|        }
  433|      0|    }
  434|      2|}
sslcert.c:ssl_PopulateServerCert:
  235|      2|{
  236|      2|    if (sc->serverCert) {
  ------------------
  |  Branch (236:9): [True: 0, False: 2]
  ------------------
  237|      0|        CERT_DestroyCertificate(sc->serverCert);
  238|      0|    }
  239|      2|    if (sc->serverCertChain) {
  ------------------
  |  Branch (239:9): [True: 0, False: 2]
  ------------------
  240|      0|        CERT_DestroyCertificateList(sc->serverCertChain);
  241|      0|    }
  242|       |
  243|      2|    if (!cert) {
  ------------------
  |  Branch (243:9): [True: 0, False: 2]
  ------------------
  244|      0|        sc->serverCert = NULL;
  245|      0|        sc->serverCertChain = NULL;
  246|      0|        return SECSuccess;
  247|      0|    }
  248|       |
  249|      2|    sc->serverCert = CERT_DupCertificate(cert);
  250|      2|    if (certChain) {
  ------------------
  |  Branch (250:9): [True: 0, False: 2]
  ------------------
  251|      0|        sc->serverCertChain = CERT_DupCertList(certChain);
  252|      2|    } else {
  253|      2|        sc->serverCertChain =
  254|      2|            CERT_CertChainFromCert(sc->serverCert, certUsageSSLServer,
  255|      2|                                   PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
  256|      2|    }
  257|      2|    return sc->serverCertChain ? SECSuccess : SECFailure;
  ------------------
  |  Branch (257:12): [True: 2, False: 0]
  ------------------
  258|      2|}
sslcert.c:ssl_PopulateKeyPair:
  262|      2|{
  263|      2|    if (sc->serverKeyPair) {
  ------------------
  |  Branch (263:9): [True: 0, False: 2]
  ------------------
  264|      0|        ssl_FreeKeyPair(sc->serverKeyPair);
  265|      0|        sc->serverKeyPair = NULL;
  266|      0|    }
  267|      2|    if (keyPair) {
  ------------------
  |  Branch (267:9): [True: 2, False: 0]
  ------------------
  268|      2|        KeyType keyType = SECKEY_GetPublicKeyType(keyPair->pubKey);
  269|      2|        PORT_Assert(keyType == SECKEY_GetPrivateKeyType(keyPair->privKey));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  270|       |
  271|      2|        if (keyType == ecKey) {
  ------------------
  |  Branch (271:13): [True: 1, False: 1]
  ------------------
  272|      1|            sc->namedCurve = ssl_ECPubKey2NamedGroup(keyPair->pubKey);
  273|      1|            if (!sc->namedCurve) {
  ------------------
  |  Branch (273:17): [True: 0, False: 1]
  ------------------
  274|       |                /* Unsupported curve. */
  275|      0|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  276|      0|                return SECFailure;
  277|      0|            }
  278|      1|        }
  279|       |
  280|       |        /* Get the size of the cert's public key, and remember it. */
  281|      2|        sc->serverKeyBits = SECKEY_PublicKeyStrengthInBits(keyPair->pubKey);
  282|      2|        if (sc->serverKeyBits == 0 ||
  ------------------
  |  Branch (282:13): [True: 0, False: 2]
  ------------------
  283|      2|            (keyType == rsaKey && sc->serverKeyBits > SSL_MAX_RSA_KEY_BITS)) {
  ------------------
  |  |  137|      1|#define SSL_MAX_RSA_KEY_BITS 8192
  ------------------
  |  Branch (283:14): [True: 1, False: 1]
  |  Branch (283:35): [True: 0, False: 1]
  ------------------
  284|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  285|      0|            return SECFailure;
  286|      0|        }
  287|       |
  288|      2|        SECKEY_CacheStaticFlags(keyPair->privKey);
  289|      2|        sc->serverKeyPair = ssl_GetKeyPairRef(keyPair);
  290|       |
  291|      2|        if (SSL_CERT_IS(sc, ssl_auth_rsa_decrypt)) {
  ------------------
  |  |   53|      2|#define SSL_CERT_IS(c, t) ((c)->authTypes & (1 << (t)))
  |  |  ------------------
  |  |  |  Branch (53:27): [True: 1, False: 1]
  |  |  ------------------
  ------------------
  292|       |            /* This will update the global session ticket key pair with this
  293|       |             * key, if a value hasn't been set already. */
  294|      1|            if (ssl_MaybeSetSelfEncryptKeyPair(keyPair) != SECSuccess) {
  ------------------
  |  Branch (294:17): [True: 0, False: 1]
  ------------------
  295|      0|                return SECFailure;
  296|      0|            }
  297|      1|        }
  298|      2|    } else {
  299|      0|        sc->serverKeyPair = NULL;
  300|      0|        sc->namedCurve = NULL;
  301|      0|    }
  302|      2|    return SECSuccess;
  303|      2|}
sslcert.c:ssl_PopulateOCSPResponses:
  308|      2|{
  309|      2|    if (sc->certStatusArray) {
  ------------------
  |  Branch (309:9): [True: 0, False: 2]
  ------------------
  310|      0|        SECITEM_FreeArray(sc->certStatusArray, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  311|      0|    }
  312|      2|    if (stapledOCSPResponses) {
  ------------------
  |  Branch (312:9): [True: 0, False: 2]
  ------------------
  313|      0|        sc->certStatusArray = SECITEM_DupArray(NULL, stapledOCSPResponses);
  314|      0|        return sc->certStatusArray ? SECSuccess : SECFailure;
  ------------------
  |  Branch (314:16): [True: 0, False: 0]
  ------------------
  315|      2|    } else {
  316|      2|        sc->certStatusArray = NULL;
  317|      2|    }
  318|      2|    return SECSuccess;
  319|      2|}
sslcert.c:ssl_PopulateSignedCertTimestamps:
  324|      2|{
  325|      2|    if (sc->signedCertTimestamps.len) {
  ------------------
  |  Branch (325:9): [True: 0, False: 2]
  ------------------
  326|      0|        SECITEM_FreeItem(&sc->signedCertTimestamps, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sc->signedCertTimestamps, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  327|      0|    }
  328|      2|    if (signedCertTimestamps && signedCertTimestamps->len) {
  ------------------
  |  Branch (328:9): [True: 0, False: 2]
  |  Branch (328:33): [True: 0, False: 0]
  ------------------
  329|      0|        return SECITEM_CopyItem(NULL, &sc->signedCertTimestamps,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  330|      0|                                signedCertTimestamps);
  331|      0|    }
  332|      2|    return SECSuccess;
  333|      2|}

ssl_GatherRecord1stHandshake:
   65|  9.71k|{
   66|  9.71k|    int rv;
   67|       |
   68|  9.71k|    PORT_Assert(ss->opt.noLocks || ssl_Have1stHandshakeLock(ss));
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.51k, False: 5.19k]
  |  |  |  |  |  Branch (208:7): [True: 5.19k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   69|       |
   70|  9.71k|    ssl_GetRecvBufLock(ss);
  ------------------
  |  | 1449|  9.71k|    {                                                    \
  |  | 1450|  9.71k|        if (!ss->opt.noLocks) {                          \
  |  |  ------------------
  |  |  |  Branch (1450:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1451|  5.19k|            PORT_Assert(!ssl_HaveSSL3HandshakeLock(ss)); \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.19k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1452|  5.19k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));       \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.19k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1453|  5.19k|            PZ_EnterMonitor((ss)->recvBufLock);          \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1454|  5.19k|        }                                                \
  |  | 1455|  9.71k|    }
  ------------------
   71|       |
   72|       |    /* Wait for handshake to complete, or application data to arrive.  */
   73|  9.71k|    rv = ssl3_GatherCompleteHandshake(ss, 0);
   74|  9.71k|    SSL_TRC(10, ("%d: SSL[%d]: handshake gathering, rv=%d",
  ------------------
  |  |   71|  9.71k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 9.71k]
  |  |  ------------------
  |  |   72|  9.71k|    ssl_Trace b
  ------------------
   75|  9.71k|                 SSL_GETPID(), ss->fd, rv));
   76|       |
   77|  9.71k|    ssl_ReleaseRecvBufLock(ss);
  ------------------
  |  | 1457|  9.71k|    {                                          \
  |  | 1458|  9.71k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1458:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1459|  9.71k|            PZ_ExitMonitor((ss)->recvBufLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1460|  9.71k|    }
  ------------------
   78|       |
   79|  9.71k|    if (rv <= 0) {
  ------------------
  |  Branch (79:9): [True: 7.09k, False: 2.62k]
  ------------------
   80|  7.09k|        if (rv == 0) {
  ------------------
  |  Branch (80:13): [True: 4.52k, False: 2.57k]
  ------------------
   81|       |            /* EOF. Loser  */
   82|  4.52k|            PORT_SetError(PR_END_OF_FILE_ERROR);
  ------------------
  |  |   65|  4.52k|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_END_OF_FILE_ERROR);
  ------------------
  |  |  202|  4.52k|#define PR_END_OF_FILE_ERROR                     (-5938L)
  ------------------
   83|  4.52k|        }
   84|  7.09k|        if (PORT_GetError() == PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   62|  7.09k|#define PORT_GetError PORT_GetError_Util
  ------------------
                      if (PORT_GetError() == PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|  7.09k|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (84:13): [True: 0, False: 7.09k]
  ------------------
   85|      0|            SSL_TRC(10, ("%d: SSL[%d]: handshake blocked (need %d)",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
   86|      0|                         SSL_GETPID(), ss->fd, ss->gs.remainder));
   87|      0|        }
   88|  7.09k|        return SECFailure; /* rv is < 0 here. */
   89|  7.09k|    }
   90|       |
   91|  2.62k|    ss->handshake = NULL;
   92|  2.62k|    return SECSuccess;
   93|  9.71k|}
ssl_BeginServerHandshake:
  201|  9.71k|{
  202|  9.71k|    SECStatus rv;
  203|       |
  204|  9.71k|    ss->sec.isServer = PR_TRUE;
  ------------------
  |  |  437|  9.71k|#define PR_TRUE 1
  ------------------
  205|  9.71k|    ss->ssl3.hs.ws = wait_client_hello;
  206|       |
  207|  9.71k|    rv = ssl_CheckConfigSanity(ss);
  208|  9.71k|    if (rv != SECSuccess)
  ------------------
  |  Branch (208:9): [True: 0, False: 9.71k]
  ------------------
  209|      0|        goto loser;
  210|       |
  211|  9.71k|    ss->handshake = ssl_GatherRecord1stHandshake;
  212|  9.71k|    return SECSuccess;
  213|       |
  214|      0|loser:
  215|      0|    return SECFailure;
  216|  9.71k|}
sslcon.c:ssl_CheckConfigSanity:
   99|  9.71k|{
  100|  9.71k|    if (SSL_ALL_VERSIONS_DISABLED(&ss->vrange)) {
  ------------------
  |  | 1503|  9.71k|    ((vrange)->min == SSL_LIBRARY_VERSION_NONE)
  |  |  ------------------
  |  |  |  | 1481|  9.71k|#define SSL_LIBRARY_VERSION_NONE 0
  |  |  ------------------
  |  |  |  Branch (1503:5): [True: 0, False: 9.71k]
  |  |  ------------------
  ------------------
  101|      0|        SSL_DBG(("%d: SSL[%d]: Can't handshake! all versions disabled.",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  102|      0|                 SSL_GETPID(), ss->fd));
  103|      0|        PORT_SetError(SSL_ERROR_SSL_DISABLED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  104|      0|        return SECFailure;
  105|      0|    }
  106|  9.71k|    return SECSuccess;
  107|  9.71k|}

ssl_DefRecv:
   65|  1.16M|{
   66|  1.16M|    PRFileDesc *lower = ss->fd->lower;
   67|  1.16M|    int rv;
   68|       |
   69|  1.16M|    PORT_Assert(buf && len > 0);
  ------------------
  |  |  120|  1.16M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.33M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.16M, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1.16M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   70|       |
   71|  1.16M|    rv = lower->methods->recv(lower, (void *)buf, len, flags, ss->rTimeout);
   72|  1.16M|    if (rv < 0) {
  ------------------
  |  Branch (72:9): [True: 0, False: 1.16M]
  ------------------
   73|      0|        DEFINE_ERROR
   74|      0|        MAP_ERROR(PR_SOCKET_SHUTDOWN_ERROR, PR_CONNECT_RESET_ERROR)
   75|  1.16M|    } else if (rv > len) {
  ------------------
  |  Branch (75:16): [True: 0, False: 1.16M]
  ------------------
   76|      0|        PORT_Assert(rv <= len);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   77|      0|        PORT_SetError(PR_BUFFER_OVERFLOW_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_BUFFER_OVERFLOW_ERROR);
  ------------------
  |  |  130|      0|#define PR_BUFFER_OVERFLOW_ERROR                 (-5962L)
  ------------------
   78|      0|        rv = SECFailure;
   79|      0|    }
   80|  1.16M|    return rv;
   81|  1.16M|}
ssl_DefSend:
   91|   410k|{
   92|   410k|    PRFileDesc *lower = ss->fd->lower;
   93|   410k|    int sent = 0;
   94|       |
   95|       |#if NSS_DISABLE_NAGLE_DELAYS
   96|       |    /* Although this is overkill, we disable Nagle delays completely for
   97|       |    ** SSL sockets.
   98|       |    */
   99|       |    if (ss->opt.useSecurity && !ss->delayDisabled) {
  100|       |        ssl_EnableNagleDelay(ss, PR_FALSE); /* ignore error */
  101|       |        ss->delayDisabled = 1;
  102|       |    }
  103|       |#endif
  104|   410k|    do {
  105|   410k|        int rv = lower->methods->send(lower, (const void *)(buf + sent),
  106|   410k|                                      len - sent, flags, ss->wTimeout);
  107|   410k|        if (rv < 0) {
  ------------------
  |  Branch (107:13): [True: 0, False: 410k]
  ------------------
  108|      0|            PRErrorCode err = PR_GetError();
  109|      0|            if (err == PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (109:17): [True: 0, False: 0]
  ------------------
  110|      0|                ss->lastWriteBlocked = 1;
  111|      0|                return sent ? sent : SECFailure;
  ------------------
  |  Branch (111:24): [True: 0, False: 0]
  ------------------
  112|      0|            }
  113|      0|            ss->lastWriteBlocked = 0;
  114|      0|            MAP_ERROR(PR_CONNECT_ABORTED_ERROR, PR_CONNECT_RESET_ERROR)
  115|       |            /* Loser */
  116|      0|            return rv;
  117|      0|        }
  118|   410k|        sent += rv;
  119|       |
  120|   410k|        if (IS_DTLS(ss) && (len > sent)) {
  ------------------
  |  |  892|   821k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 410k]
  |  |  ------------------
  ------------------
  |  Branch (120:28): [True: 0, False: 0]
  ------------------
  121|       |            /* We got a partial write so just return it */
  122|      0|            return sent;
  123|      0|        }
  124|   410k|    } while (len > sent);
  ------------------
  |  Branch (124:14): [True: 0, False: 410k]
  ------------------
  125|   410k|    ss->lastWriteBlocked = 0;
  126|   410k|    return sent;
  127|   410k|}
ssl_DefGetpeername:
  171|  9.71k|{
  172|  9.71k|    PRFileDesc *lower = ss->fd->lower;
  173|  9.71k|    int rv;
  174|       |
  175|  9.71k|    rv = lower->methods->getpeername(lower, name);
  176|  9.71k|    return rv;
  177|  9.71k|}
ssl_DefClose:
  191|  9.71k|{
  192|  9.71k|    PRFileDesc *fd;
  193|  9.71k|    PRFileDesc *popped;
  194|  9.71k|    int rv;
  195|       |
  196|  9.71k|    fd = ss->fd;
  197|       |
  198|       |    /* First, remove the SSL layer PRFileDesc from the socket's stack,
  199|       |    ** then invoke the SSL layer's PRFileDesc destructor.
  200|       |    ** This must happen before the next layer down is closed.
  201|       |    */
  202|  9.71k|    PORT_Assert(fd->higher == NULL);
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  203|  9.71k|    if (fd->higher) {
  ------------------
  |  Branch (203:9): [True: 0, False: 9.71k]
  ------------------
  204|      0|        PORT_SetError(PR_BAD_DESCRIPTOR_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_BAD_DESCRIPTOR_ERROR);
  ------------------
  |  |   19|      0|#define PR_BAD_DESCRIPTOR_ERROR                  (-5999L)
  ------------------
  205|      0|        return SECFailure;
  206|      0|    }
  207|  9.71k|    ss->fd = NULL;
  208|       |
  209|       |    /* PR_PopIOLayer will swap the contents of the top two PRFileDescs on
  210|       |    ** the stack, and then remove the second one.  This way, the address
  211|       |    ** of the PRFileDesc on the top of the stack doesn't change.
  212|       |    */
  213|  9.71k|    popped = PR_PopIOLayer(fd, PR_TOP_IO_LAYER);
  ------------------
  |  |  453|  9.71k|#define PR_TOP_IO_LAYER (PRDescIdentity)-2
  ------------------
  214|  9.71k|    popped->dtor(popped);
  215|       |
  216|       |    /* fd is now the PRFileDesc for the next layer down.
  217|       |    ** Now close the underlying socket.
  218|       |    */
  219|  9.71k|    rv = fd->methods->close(fd);
  220|       |
  221|  9.71k|    ssl_FreeSocket(ss);
  222|       |
  223|  9.71k|    SSL_TRC(5, ("%d: SSL[%d]: closing, rv=%d errno=%d",
  ------------------
  |  |   71|  9.71k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 9.71k]
  |  |  ------------------
  |  |   72|  9.71k|    ssl_Trace b
  ------------------
  224|  9.71k|                SSL_GETPID(), fd, rv, PORT_GetError()));
  225|  9.71k|    return rv;
  226|  9.71k|}

sslBuffer_Grow:
   32|  9.65M|{
   33|  9.65M|    PORT_Assert(b);
  ------------------
  |  |  120|  9.65M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.65M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.65M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   34|  9.65M|    if (b->fixed) {
  ------------------
  |  Branch (34:9): [True: 4.29M, False: 5.36M]
  ------------------
   35|  4.29M|        PORT_Assert(newLen <= b->space);
  ------------------
  |  |  120|  4.29M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.29M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4.29M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   36|  4.29M|        if (newLen > b->space) {
  ------------------
  |  Branch (36:13): [True: 0, False: 4.29M]
  ------------------
   37|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   38|      0|            return SECFailure;
   39|      0|        }
   40|  4.29M|        return SECSuccess;
   41|  4.29M|    }
   42|       |
   43|       |    /* If buf is non-NULL, space must be non-zero;
   44|       |     * if buf is NULL, space must be zero. */
   45|  5.36M|    PORT_Assert((b->buf && b->space) || (!b->buf && !b->space));
  ------------------
  |  |  120|  5.36M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  18.7M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.03M, False: 1.32M]
  |  |  |  |  |  Branch (208:7): [True: 4.03M, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1.32M, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1.32M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   46|  5.36M|    if (newLen > b->space) {
  ------------------
  |  Branch (46:9): [True: 1.33M, False: 4.02M]
  ------------------
   47|  1.33M|        newLen = PR_MAX(newLen, b->space + 2048);
  ------------------
  |  |  159|  1.33M|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 598k, False: 733k]
  |  |  ------------------
  ------------------
   48|  1.33M|        unsigned char *newBuf;
   49|  1.33M|        if (b->buf) {
  ------------------
  |  Branch (49:13): [True: 2.68k, False: 1.32M]
  ------------------
   50|  2.68k|            newBuf = (unsigned char *)PORT_Realloc(b->buf, newLen);
  ------------------
  |  |   64|  2.68k|#define PORT_Realloc PORT_Realloc_Util
  ------------------
   51|  1.32M|        } else {
   52|  1.32M|            newBuf = (unsigned char *)PORT_Alloc(newLen);
  ------------------
  |  |   52|  1.32M|#define PORT_Alloc PORT_Alloc_Util
  ------------------
   53|  1.32M|        }
   54|  1.33M|        if (!newBuf) {
  ------------------
  |  Branch (54:13): [True: 0, False: 1.33M]
  ------------------
   55|      0|            return SECFailure;
   56|      0|        }
   57|  1.33M|        b->buf = newBuf;
   58|  1.33M|        b->space = newLen;
   59|  1.33M|    }
   60|  5.36M|    return SECSuccess;
   61|  5.36M|}
sslBuffer_Append:
   81|  3.39M|{
   82|  3.39M|    SECStatus rv = sslBuffer_Grow(b, b->len + len);
   83|  3.39M|    if (rv != SECSuccess) {
  ------------------
  |  Branch (83:9): [True: 0, False: 3.39M]
  ------------------
   84|      0|        return SECFailure; /* Code already set. */
   85|      0|    }
   86|  3.39M|    if (len > 0) {
  ------------------
  |  Branch (86:9): [True: 3.36M, False: 30.5k]
  ------------------
   87|  3.36M|        PORT_Assert(data);
  ------------------
  |  |  120|  3.36M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.36M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.36M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   88|  3.36M|        PORT_Memcpy(SSL_BUFFER_NEXT(b), data, len);
  ------------------
  |  |  180|  3.36M|#define PORT_Memcpy memcpy
  ------------------
                      PORT_Memcpy(SSL_BUFFER_NEXT(b), data, len);
  ------------------
  |  |   37|  3.36M|#define SSL_BUFFER_NEXT(b) ((b)->buf + (b)->len)
  ------------------
   89|  3.36M|    }
   90|  3.39M|    b->len += len;
   91|  3.39M|    return SECSuccess;
   92|  3.39M|}
sslBuffer_AppendNumber:
   96|  3.07M|{
   97|  3.07M|    SECStatus rv = sslBuffer_Grow(b, b->len + size);
   98|  3.07M|    if (rv != SECSuccess) {
  ------------------
  |  Branch (98:9): [True: 0, False: 3.07M]
  ------------------
   99|      0|        return SECFailure;
  100|      0|    }
  101|  3.07M|    ssl_EncodeUintX(SSL_BUFFER_NEXT(b), v, size);
  ------------------
  |  |   37|  3.07M|#define SSL_BUFFER_NEXT(b) ((b)->buf + (b)->len)
  ------------------
  102|  3.07M|    b->len += size;
  103|  3.07M|    return SECSuccess;
  104|  3.07M|}
sslBuffer_AppendVariable:
  109|   993k|{
  110|   993k|    PORT_Assert(size <= 4 && size > 0);
  ------------------
  |  |  120|   993k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.98M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 993k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 993k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  111|   993k|    PORT_Assert(b);
  ------------------
  |  |  120|   993k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   993k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 993k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  112|   993k|    if (len >= (1ULL << (8 * size))) {
  ------------------
  |  Branch (112:9): [True: 0, False: 993k]
  ------------------
  113|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  114|      0|        return SECFailure;
  115|      0|    }
  116|       |
  117|   993k|    if (sslBuffer_Grow(b, b->len + len + size) != SECSuccess) {
  ------------------
  |  Branch (117:9): [True: 0, False: 993k]
  ------------------
  118|      0|        return SECFailure;
  119|      0|    }
  120|       |
  121|   993k|    ssl_EncodeUintX(SSL_BUFFER_NEXT(b), len, size);
  ------------------
  |  |   37|   993k|#define SSL_BUFFER_NEXT(b) ((b)->buf + (b)->len)
  ------------------
  122|   993k|    b->len += size;
  123|   993k|    if (len != 0) {
  ------------------
  |  Branch (123:9): [True: 144k, False: 849k]
  ------------------
  124|   144k|        PORT_Assert(data);
  ------------------
  |  |  120|   144k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   144k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 144k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  125|       |        /* We sometimes pass NULL, 0 and memcpy() doesn't want NULL. */
  126|   144k|        PORT_Memcpy(SSL_BUFFER_NEXT(b), data, len);
  ------------------
  |  |  180|   144k|#define PORT_Memcpy memcpy
  ------------------
                      PORT_Memcpy(SSL_BUFFER_NEXT(b), data, len);
  ------------------
  |  |   37|   144k|#define SSL_BUFFER_NEXT(b) ((b)->buf + (b)->len)
  ------------------
  127|   144k|    }
  128|   993k|    b->len += len;
  129|   993k|    return SECSuccess;
  130|   993k|}
sslBuffer_AppendBuffer:
  134|     32|{
  135|     32|    return sslBuffer_Append(b, append->buf, append->len);
  136|     32|}
sslBuffer_AppendBufferVariable:
  141|  14.8k|{
  142|  14.8k|    return sslBuffer_AppendVariable(b, append->buf, append->len, size);
  143|  14.8k|}
sslBuffer_Skip:
  147|   943k|{
  148|   943k|    if (sslBuffer_Grow(b, b->len + size) != SECSuccess) {
  ------------------
  |  Branch (148:9): [True: 0, False: 943k]
  ------------------
  149|      0|        return SECFailure;
  150|      0|    }
  151|       |
  152|   943k|    if (savedOffset) {
  ------------------
  |  Branch (152:9): [True: 474k, False: 468k]
  ------------------
  153|   474k|        *savedOffset = b->len;
  154|   474k|    }
  155|   943k|    b->len += size;
  156|   943k|    return SECSuccess;
  157|   943k|}
sslBuffer_InsertLength:
  170|   474k|{
  171|   474k|    unsigned int len;
  172|       |
  173|   474k|    PORT_Assert(b->len >= at + size);
  ------------------
  |  |  120|   474k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   474k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 474k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  174|   474k|    PORT_Assert(b->space >= at + size);
  ------------------
  |  |  120|   474k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   474k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 474k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  175|   474k|    len = b->len - (at + size);
  176|       |
  177|   474k|    PORT_Assert(size <= 4 && size > 0);
  ------------------
  |  |  120|   474k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   949k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 474k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 474k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  178|   474k|    if (len >= (1ULL << (8 * size))) {
  ------------------
  |  Branch (178:9): [True: 0, False: 474k]
  ------------------
  179|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  180|      0|        return SECFailure;
  181|      0|    }
  182|       |
  183|   474k|    ssl_EncodeUintX(SSL_BUFFER_BASE(b) + at, len, size);
  ------------------
  |  |   35|   474k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
  184|   474k|    return SECSuccess;
  185|   474k|}
sslBuffer_Clear:
  206|  1.37M|{
  207|  1.37M|    if (!b->fixed) {
  ------------------
  |  Branch (207:9): [True: 1.37M, False: 0]
  ------------------
  208|  1.37M|        if (b->buf) {
  ------------------
  |  Branch (208:13): [True: 1.30M, False: 70.1k]
  ------------------
  209|  1.30M|            PORT_Free(b->buf);
  ------------------
  |  |   60|  1.30M|#define PORT_Free PORT_Free_Util
  ------------------
  210|  1.30M|            b->buf = NULL;
  211|  1.30M|        }
  212|  1.37M|        b->space = 0;
  213|  1.37M|    }
  214|  1.37M|    b->len = 0;
  215|  1.37M|}
sslRead_Read:
  219|  1.76k|{
  220|  1.76k|    if (!reader || !out) {
  ------------------
  |  Branch (220:9): [True: 0, False: 1.76k]
  |  Branch (220:20): [True: 0, False: 1.76k]
  ------------------
  221|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  222|      0|        return SECFailure;
  223|      0|    }
  224|  1.76k|    if (reader->buf.len < reader->offset ||
  ------------------
  |  Branch (224:9): [True: 0, False: 1.76k]
  ------------------
  225|  1.76k|        count > SSL_READER_REMAINING(reader)) {
  ------------------
  |  |   91|  1.76k|    ((r)->buf.len - (r)->offset)
  ------------------
  |  Branch (225:9): [True: 46, False: 1.71k]
  ------------------
  226|     46|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|     46|#define PORT_SetError PORT_SetError_Util
  ------------------
  227|     46|        return SECFailure;
  228|     46|    }
  229|       |
  230|  1.71k|    out->buf = SSL_READER_CURRENT(reader);
  ------------------
  |  |   89|  1.71k|    ((r)->buf.buf + (r)->offset)
  ------------------
  231|  1.71k|    out->len = count;
  232|  1.71k|    reader->offset += count;
  233|       |
  234|  1.71k|    return SECSuccess;
  235|  1.76k|}
sslRead_ReadVariable:
  239|  2.85k|{
  240|  2.85k|    PRUint64 variableLen = 0;
  241|  2.85k|    SECStatus rv = sslRead_ReadNumber(reader, sizeLen, &variableLen);
  242|  2.85k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (242:9): [True: 9, False: 2.84k]
  ------------------
  243|      9|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|      9|#define PORT_SetError PORT_SetError_Util
  ------------------
  244|      9|        return SECFailure;
  245|      9|    }
  246|  2.84k|    if (!variableLen) {
  ------------------
  |  Branch (246:9): [True: 1.13k, False: 1.71k]
  ------------------
  247|       |        // It is ok to have an empty variable.
  248|  1.13k|        out->len = variableLen;
  249|  1.13k|        return SECSuccess;
  250|  1.13k|    }
  251|  1.71k|    return sslRead_Read(reader, variableLen, out);
  252|  2.84k|}
sslRead_ReadNumber:
  256|  6.03k|{
  257|  6.03k|    if (!reader || !num) {
  ------------------
  |  Branch (257:9): [True: 0, False: 6.03k]
  |  Branch (257:20): [True: 0, False: 6.03k]
  ------------------
  258|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  259|      0|        return SECFailure;
  260|      0|    }
  261|  6.03k|    if (reader->buf.len < reader->offset ||
  ------------------
  |  Branch (261:9): [True: 0, False: 6.03k]
  ------------------
  262|  6.03k|        bytes > SSL_READER_REMAINING(reader) ||
  ------------------
  |  |   91|  12.0k|    ((r)->buf.len - (r)->offset)
  ------------------
  |  Branch (262:9): [True: 22, False: 6.01k]
  ------------------
  263|  6.03k|        bytes > 8) {
  ------------------
  |  Branch (263:9): [True: 0, False: 6.01k]
  ------------------
  264|     22|        PORT_SetError(SEC_ERROR_BAD_DATA);
  ------------------
  |  |   65|     22|#define PORT_SetError PORT_SetError_Util
  ------------------
  265|     22|        return SECFailure;
  266|     22|    }
  267|  6.01k|    unsigned int i;
  268|  6.01k|    PRUint64 number = 0;
  269|  17.9k|    for (i = 0; i < bytes; i++) {
  ------------------
  |  Branch (269:17): [True: 11.8k, False: 6.01k]
  ------------------
  270|  11.8k|        number = (number << 8) + reader->buf.buf[i + reader->offset];
  271|  11.8k|    }
  272|       |
  273|  6.01k|    reader->offset = reader->offset + bytes;
  274|  6.01k|    *num = number;
  275|  6.01k|    return SECSuccess;
  276|  6.03k|}
ssl3_AppendHandshake:
  340|   357k|{
  341|   357k|    return ssl3_AppendHandshakeInternal(ss, void_src, bytes, PR_FALSE);
  ------------------
  |  |  438|   357k|#define PR_FALSE 0
  ------------------
  342|   357k|}
ssl3_AppendHandshakeNumberSuppressHash:
  346|  1.28M|{
  347|  1.28M|    if ((lenSize > 8) || ((lenSize < 8) && (num >= (1ULL << (8 * lenSize))))) {
  ------------------
  |  Branch (347:9): [True: 0, False: 1.28M]
  |  Branch (347:27): [True: 1.28M, False: 0]
  |  Branch (347:44): [True: 0, False: 1.28M]
  ------------------
  348|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  349|      0|        return SECFailure;
  350|      0|    }
  351|       |
  352|  1.28M|    PRUint8 b[sizeof(num)];
  353|  1.28M|    SSL_TRC(60, ("%d: number:", SSL_GETPID()));
  ------------------
  |  |   71|  1.28M|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.28M]
  |  |  ------------------
  |  |   72|  1.28M|    ssl_Trace b
  ------------------
  354|  1.28M|    ssl_EncodeUintX(b, num, lenSize);
  355|  1.28M|    return ssl3_AppendHandshakeInternal(ss, b, lenSize, suppressHash);
  356|  1.28M|}
ssl3_AppendHandshakeNumber:
  360|  1.28M|{
  361|  1.28M|    return ssl3_AppendHandshakeNumberSuppressHash(ss, num, lenSize, PR_FALSE);
  ------------------
  |  |  438|  1.28M|#define PR_FALSE 0
  ------------------
  362|  1.28M|}
ssl3_AppendHandshakeVariable:
  367|   191k|{
  368|   191k|    SECStatus rv;
  369|       |
  370|   191k|    PORT_Assert((bytes < (1 << 8) && lenSize == 1) ||
  ------------------
  |  |  120|   191k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.32M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 68.9k, False: 122k]
  |  |  |  |  |  Branch (208:7): [True: 23.3k, False: 45.5k]
  |  |  |  |  |  Branch (208:7): [True: 168k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 109k, False: 58.7k]
  |  |  |  |  |  Branch (208:7): [True: 58.7k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 58.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  371|   191k|                (bytes < (1L << 16) && lenSize == 2) ||
  372|   191k|                (bytes < (1L << 24) && lenSize == 3));
  373|       |
  374|   191k|    SSL_TRC(60, ("%d: append variable:", SSL_GETPID()));
  ------------------
  |  |   71|   191k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 191k]
  |  |  ------------------
  |  |   72|   191k|    ssl_Trace b
  ------------------
  375|   191k|    rv = ssl3_AppendHandshakeNumber(ss, bytes, lenSize);
  376|   191k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (376:9): [True: 0, False: 191k]
  ------------------
  377|      0|        return SECFailure; /* error code set by AppendHandshake. */
  378|      0|    }
  379|   191k|    SSL_TRC(60, ("data:"));
  ------------------
  |  |   71|   191k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 191k]
  |  |  ------------------
  |  |   72|   191k|    ssl_Trace b
  ------------------
  380|   191k|    return ssl3_AppendHandshake(ss, src, bytes);
  381|   191k|}
ssl3_AppendBufferToHandshake:
  385|  29.9k|{
  386|  29.9k|    return ssl3_AppendHandshake(ss, buf->buf, buf->len);
  387|  29.9k|}
ssl3_AppendBufferToHandshakeVariable:
  392|  1.66k|{
  393|  1.66k|    return ssl3_AppendHandshakeVariable(ss, buf->buf, buf->len, lenSize);
  394|  1.66k|}
sslencode.c:ssl_EncodeUintX:
   18|  5.82M|{
   19|  5.82M|    PRUint64 encoded;
   20|       |
   21|  5.82M|    PORT_Assert(bytes > 0 && bytes <= sizeof(encoded));
  ------------------
  |  |  120|  5.82M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  11.6M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 5.82M, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 5.82M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   22|       |
   23|  5.82M|    encoded = PR_htonll(value);
   24|  5.82M|    PORT_Memcpy(to, ((unsigned char *)(&encoded)) + (sizeof(encoded) - bytes),
  ------------------
  |  |  180|  5.82M|#define PORT_Memcpy memcpy
  ------------------
   25|  5.82M|                bytes);
   26|  5.82M|}
sslencode.c:ssl3_AppendHandshakeInternal:
  288|  1.63M|{
  289|  1.63M|    unsigned char *src = (unsigned char *)void_src;
  290|  1.63M|    int room = ss->sec.ci.sendBuf.space - ss->sec.ci.sendBuf.len;
  291|  1.63M|    SECStatus rv;
  292|       |
  293|  1.63M|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss)); /* protects sendBuf. */
  ------------------
  |  |  120|  1.63M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  2.46M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 815k, False: 823k]
  |  |  |  |  |  Branch (208:7): [True: 823k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  294|       |
  295|  1.63M|    if (!bytes)
  ------------------
  |  Branch (295:9): [True: 447, False: 1.63M]
  ------------------
  296|    447|        return SECSuccess;
  297|  1.63M|    if (ss->sec.ci.sendBuf.space < MAX_SEND_BUF_LENGTH && room < bytes) {
  ------------------
  |  |  283|  3.27M|#define MAX_SEND_BUF_LENGTH 32000 /* watch for 16-bit integer overflow */
  ------------------
  |  Branch (297:9): [True: 1.63M, False: 0]
  |  Branch (297:59): [True: 8.11k, False: 1.63M]
  ------------------
  298|  8.11k|        rv = sslBuffer_Grow(&ss->sec.ci.sendBuf, PR_MAX(MIN_SEND_BUF_LENGTH,
  ------------------
  |  |  159|  16.2k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 8.11k, False: 0]
  |  |  |  Branch (159:31): [True: 0, False: 8.11k]
  |  |  |  Branch (159:39): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  299|  8.11k|                                                        PR_MIN(MAX_SEND_BUF_LENGTH, ss->sec.ci.sendBuf.len + bytes)));
  300|  8.11k|        if (rv != SECSuccess)
  ------------------
  |  Branch (300:13): [True: 0, False: 8.11k]
  ------------------
  301|      0|            return SECFailure; /* sslBuffer_Grow sets a memory error code. */
  302|  8.11k|        room = ss->sec.ci.sendBuf.space - ss->sec.ci.sendBuf.len;
  303|  8.11k|    }
  304|       |
  305|  1.63M|    PRINT_BUF(60, (ss, "Append to Handshake", (unsigned char *)void_src, bytes));
  ------------------
  |  |   74|  1.63M|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.63M]
  |  |  ------------------
  |  |   75|  1.63M|    ssl_PrintBuf b
  ------------------
  306|       |    // TODO: Move firstHsDone and version check into callers as a suppression.
  307|  1.63M|    if (!suppressHash && (!ss->firstHsDone || ss->version < SSL_LIBRARY_VERSION_TLS_1_3)) {
  ------------------
  |  |   21|  1.48M|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (307:9): [True: 1.63M, False: 0]
  |  Branch (307:27): [True: 153k, False: 1.48M]
  |  Branch (307:47): [True: 1.08M, False: 400k]
  ------------------
  308|  1.23M|        rv = ssl3_UpdateHandshakeHashes(ss, src, bytes);
  309|  1.23M|        if (rv != SECSuccess)
  ------------------
  |  Branch (309:13): [True: 0, False: 1.23M]
  ------------------
  310|      0|            return SECFailure; /* error code set by ssl3_UpdateHandshakeHashes */
  311|  1.23M|    }
  312|       |
  313|  1.63M|    while (bytes > room) {
  ------------------
  |  Branch (313:12): [True: 0, False: 1.63M]
  ------------------
  314|      0|        if (room > 0)
  ------------------
  |  Branch (314:13): [True: 0, False: 0]
  ------------------
  315|      0|            PORT_Memcpy(ss->sec.ci.sendBuf.buf + ss->sec.ci.sendBuf.len, src,
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  316|      0|                        room);
  317|      0|        ss->sec.ci.sendBuf.len += room;
  318|      0|        rv = ssl3_FlushHandshake(ss, ssl_SEND_FLAG_FORCE_INTO_BUFFER);
  ------------------
  |  |  223|      0|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
  319|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (319:13): [True: 0, False: 0]
  ------------------
  320|      0|            return SECFailure; /* error code set by ssl3_FlushHandshake */
  321|      0|        }
  322|      0|        bytes -= room;
  323|      0|        src += room;
  324|      0|        room = ss->sec.ci.sendBuf.space;
  325|      0|        PORT_Assert(ss->sec.ci.sendBuf.len == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  326|      0|    }
  327|  1.63M|    PORT_Memcpy(ss->sec.ci.sendBuf.buf + ss->sec.ci.sendBuf.len, src, bytes);
  ------------------
  |  |  180|  1.63M|#define PORT_Memcpy memcpy
  ------------------
  328|  1.63M|    ss->sec.ci.sendBuf.len += bytes;
  329|  1.63M|    return SECSuccess;
  330|  1.63M|}

ssl_MapLowLevelError:
   21|  4.71k|{
   22|  4.71k|    int oldErr = PORT_GetError();
  ------------------
  |  |   62|  4.71k|#define PORT_GetError PORT_GetError_Util
  ------------------
   23|       |
   24|  4.71k|    switch (oldErr) {
   25|       |
   26|    121|        case 0:
  ------------------
  |  Branch (26:9): [True: 121, False: 4.59k]
  ------------------
   27|    121|        case PR_IO_ERROR:
  ------------------
  |  |   43|    121|#define PR_IO_ERROR                              (-5991L)
  ------------------
  |  Branch (27:9): [True: 0, False: 4.71k]
  ------------------
   28|    121|        case SEC_ERROR_IO:
  ------------------
  |  Branch (28:9): [True: 0, False: 4.71k]
  ------------------
   29|    121|        case SEC_ERROR_BAD_DATA:
  ------------------
  |  Branch (29:9): [True: 0, False: 4.71k]
  ------------------
   30|    181|        case SEC_ERROR_LIBRARY_FAILURE:
  ------------------
  |  Branch (30:9): [True: 60, False: 4.65k]
  ------------------
   31|    227|        case SEC_ERROR_EXTENSION_NOT_FOUND:
  ------------------
  |  Branch (31:9): [True: 46, False: 4.66k]
  ------------------
   32|    228|        case SSL_ERROR_BAD_CLIENT:
  ------------------
  |  Branch (32:9): [True: 1, False: 4.71k]
  ------------------
   33|    228|        case SSL_ERROR_BAD_SERVER:
  ------------------
  |  Branch (33:9): [True: 0, False: 4.71k]
  ------------------
   34|    228|        case SSL_ERROR_SESSION_NOT_FOUND:
  ------------------
  |  Branch (34:9): [True: 0, False: 4.71k]
  ------------------
   35|    228|            PORT_SetError(hiLevelError);
  ------------------
  |  |   65|    228|#define PORT_SetError PORT_SetError_Util
  ------------------
   36|    228|            return hiLevelError;
   37|       |
   38|  4.48k|        default: /* leave the majority of error codes alone. */
  ------------------
  |  Branch (38:9): [True: 4.48k, False: 228]
  ------------------
   39|  4.48k|            return oldErr;
   40|  4.71k|    }
   41|  4.71k|}

ssl_InitializePRErrorTable:
   32|      2|{
   33|      2|    return (PR_SUCCESS == PR_CallOnce(&once, ssl_InitializePRErrorTableOnce))
  ------------------
  |  Branch (33:12): [True: 2, False: 0]
  ------------------
   34|      2|               ? SECSuccess
   35|      2|               : SECFailure;
   36|      2|}
sslerrstrs.c:ssl_InitializePRErrorTableOnce:
   24|      1|{
   25|      1|    return PR_ErrorInstallTable(&ssl_et);
   26|      1|}

ssl_FilterSupportedGroups:
   77|  60.3k|{
   78|  60.3k|    unsigned int i;
   79|  60.3k|    PRStatus prv;
   80|  60.3k|    sslSocketAndGroupArg arg = { NULL, ss };
   81|       |
   82|  60.3k|    prv = PR_CallOnce(&cleanupECDHEKeysOnce, ssl_SetupCleanupECDHEKeysOnce);
   83|  60.3k|    PORT_Assert(prv == PR_SUCCESS);
  ------------------
  |  |  120|  60.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  60.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 60.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   84|  60.3k|    if (prv != PR_SUCCESS) {
  ------------------
  |  Branch (84:9): [True: 0, False: 60.3k]
  ------------------
   85|      0|        return;
   86|      0|    }
   87|       |
   88|  2.05M|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  2.05M|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (88:17): [True: 1.99M, False: 60.3k]
  ------------------
   89|  1.99M|        PRUint32 policy;
   90|  1.99M|        SECStatus srv;
   91|  1.99M|        unsigned int index;
   92|  1.99M|        const sslNamedGroupDef *group = ss->namedGroupPreferences[i];
   93|  1.99M|        if (!group) {
  ------------------
  |  Branch (93:13): [True: 1.49M, False: 501k]
  ------------------
   94|  1.49M|            continue;
   95|  1.49M|        }
   96|       |
   97|   501k|        srv = NSS_GetAlgorithmPolicy(group->oidTag, &policy);
   98|   501k|        if (srv == SECSuccess && !(policy & NSS_USE_ALG_IN_SSL_KX)) {
  ------------------
  |  |  572|   501k|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
  |  Branch (98:13): [True: 501k, False: 0]
  |  Branch (98:34): [True: 5.68k, False: 496k]
  ------------------
   99|  5.68k|            ss->namedGroupPreferences[i] = NULL;
  100|  5.68k|            continue;
  101|  5.68k|        }
  102|       |
  103|   496k|        if (group->assumeSupported) {
  ------------------
  |  Branch (103:13): [True: 372k, False: 123k]
  ------------------
  104|   372k|            continue;
  105|   372k|        }
  106|       |
  107|       |        /* For EC groups, we have to test that a key pair can be created. This
  108|       |         * is gross, and expensive, so only do it once. */
  109|   123k|        index = group - ssl_named_groups;
  110|   123k|        PORT_Assert(index < SSL_NAMED_GROUP_COUNT);
  ------------------
  |  |  120|   123k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   123k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 123k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  111|       |
  112|   123k|        arg.group = group;
  113|   123k|        prv = PR_CallOnceWithArg(&gECDHEKeyPairs[index].once,
  114|   123k|                                 ssl_CreateStaticECDHEKeyPair,
  115|   123k|                                 (void *)&arg);
  116|   123k|        PORT_Assert(prv == PR_SUCCESS);
  ------------------
  |  |  120|   123k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   123k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 123k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  117|   123k|        if (prv != PR_SUCCESS) {
  ------------------
  |  Branch (117:13): [True: 0, False: 123k]
  ------------------
  118|      0|            continue;
  119|      0|        }
  120|       |
  121|   123k|        if (!gECDHEKeyPairs[index].keyPair) {
  ------------------
  |  Branch (121:13): [True: 123k, False: 0]
  ------------------
  122|   123k|            ss->namedGroupPreferences[i] = NULL;
  123|   123k|        }
  124|   123k|    }
  125|  60.3k|}
sslgrp.c:ssl_SetupCleanupECDHEKeysOnce:
   43|      1|{
   44|      1|    SECStatus rv = NSS_RegisterShutdown(ssl_CleanupECDHEKeys, NULL);
   45|      1|    return (rv != SECSuccess) ? PR_FAILURE : PR_SUCCESS;
  ------------------
  |  Branch (45:12): [True: 0, False: 1]
  ------------------
   46|      1|}
sslgrp.c:ssl_CleanupECDHEKeys:
   27|      1|{
   28|      1|    unsigned int i;
   29|       |
   30|     34|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; i++) {
  ------------------
  |  |  133|     34|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (30:17): [True: 33, False: 1]
  ------------------
   31|     33|        if (gECDHEKeyPairs[i].keyPair) {
  ------------------
  |  Branch (31:13): [True: 0, False: 33]
  ------------------
   32|      0|            ssl_FreeEphemeralKeyPair(gECDHEKeyPairs[i].keyPair);
   33|      0|        }
   34|     33|    }
   35|      1|    memset(gECDHEKeyPairs, 0, sizeof(gECDHEKeyPairs));
   36|      1|    return SECSuccess;
   37|      1|}
sslgrp.c:ssl_CreateStaticECDHEKeyPair:
   55|     22|{
   56|     22|    const sslSocketAndGroupArg *typed_arg = (sslSocketAndGroupArg *)arg;
   57|     22|    const sslNamedGroupDef *group = typed_arg->group;
   58|     22|    const sslSocket *ss = typed_arg->ss;
   59|     22|    unsigned int i = group - ssl_named_groups;
   60|     22|    SECStatus rv;
   61|       |
   62|     22|    PORT_Assert(group->keaType == ssl_kea_ecdh);
  ------------------
  |  |  120|     22|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     22|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 22, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   63|     22|    PORT_Assert(i < SSL_NAMED_GROUP_COUNT);
  ------------------
  |  |  120|     22|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     22|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 22, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   64|     22|    rv = ssl_CreateECDHEphemeralKeyPair(ss, group,
   65|     22|                                        &gECDHEKeyPairs[i].keyPair);
   66|     22|    if (rv != SECSuccess) {
  ------------------
  |  Branch (66:9): [True: 22, False: 0]
  ------------------
   67|     22|        gECDHEKeyPairs[i].keyPair = NULL;
   68|     22|        SSL_TRC(5, ("%d: SSL[-]: disabling group %d",
  ------------------
  |  |   71|     22|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 22]
  |  |  ------------------
  |  |   72|     22|    ssl_Trace b
  ------------------
   69|     22|                    SSL_GETPID(), group->name));
   70|     22|    }
   71|       |
   72|     22|    return PR_SUCCESS;
   73|     22|}

ssl_InitCallOnce:
   29|      1|{
   30|      1|    int *error = (int *)arg;
   31|      1|    SECStatus rv;
   32|       |
   33|      1|    rv = ssl_InitializePRErrorTable();
   34|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (34:9): [True: 0, False: 1]
  ------------------
   35|      0|        *error = SEC_ERROR_NO_MEMORY;
   36|      0|        return PR_FAILURE;
   37|      0|    }
   38|      1|#ifdef DEBUG
   39|      1|    ssl3_CheckCipherSuiteOrderConsistency();
   40|      1|#endif
   41|       |
   42|      1|    rv = ssl3_ApplyNSSPolicy();
   43|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (43:9): [True: 0, False: 1]
  ------------------
   44|      0|        *error = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
   45|      0|        return PR_FAILURE;
   46|      0|    }
   47|       |
   48|      1|    rv = NSS_RegisterShutdown(ssl_InitShutdown, NULL);
   49|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (49:9): [True: 0, False: 1]
  ------------------
   50|      0|        *error = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
   51|      0|        return PR_FAILURE;
   52|      0|    }
   53|      1|    return PR_SUCCESS;
   54|      1|}
ssl_Init:
   58|  9.71k|{
   59|  9.71k|    int error;
   60|  9.71k|    PRStatus nrv = PR_CallOnceWithArg(&ssl_init, ssl_InitCallOnce, &error);
   61|  9.71k|    if (nrv != PR_SUCCESS) {
  ------------------
  |  Branch (61:9): [True: 0, False: 9.71k]
  ------------------
   62|      0|        PORT_SetError(error);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   63|      0|        return SECFailure;
   64|      0|    }
   65|  9.71k|    return SECSuccess;
   66|  9.71k|}
sslinit.c:ssl_InitShutdown:
   22|      1|{
   23|      1|    memset(&ssl_init, 0, sizeof(ssl_init));
   24|      1|    return SECSuccess;
   25|      1|}

sslMutex_Init:
  102|     11|{
  103|     11|    int err;
  104|     11|    PR_ASSERT(pMutex);
  ------------------
  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 11, False: 0]
  |  |  ------------------
  ------------------
  105|     11|    pMutex->isMultiProcess = (PRBool)(shared != 0);
  106|     11|    if (!shared) {
  ------------------
  |  Branch (106:9): [True: 11, False: 0]
  ------------------
  107|     11|        return single_process_sslMutex_Init(pMutex);
  108|     11|    }
  109|      0|    pMutex->u.pipeStr.mPipes[0] = -1;
  110|      0|    pMutex->u.pipeStr.mPipes[1] = -1;
  111|      0|    pMutex->u.pipeStr.mPipes[2] = -1;
  112|      0|    pMutex->u.pipeStr.nWaiters = 0;
  113|       |
  114|      0|    err = pipe(pMutex->u.pipeStr.mPipes);
  115|      0|    if (err) {
  ------------------
  |  Branch (115:9): [True: 0, False: 0]
  ------------------
  116|      0|        nss_MD_unix_map_default_error(errno);
  117|      0|        return err;
  118|      0|    }
  119|      0|#if NONBLOCKING_POSTS
  120|      0|    err = setNonBlocking(pMutex->u.pipeStr.mPipes[1], 1);
  121|      0|    if (err)
  ------------------
  |  Branch (121:9): [True: 0, False: 0]
  ------------------
  122|      0|        goto loser;
  123|      0|#endif
  124|       |
  125|      0|    pMutex->u.pipeStr.mPipes[2] = SSL_MUTEX_MAGIC;
  ------------------
  |  |   73|      0|#define SSL_MUTEX_MAGIC 0xfeedfd
  ------------------
  126|       |
  127|       |#if defined(LINUX) && defined(i386)
  128|       |    /* Pipe starts out empty */
  129|       |    return SECSuccess;
  130|       |#else
  131|       |    /* Pipe starts with one byte. */
  132|      0|    return sslMutex_Unlock(pMutex);
  133|      0|#endif
  134|       |
  135|      0|loser:
  136|      0|    nss_MD_unix_map_default_error(errno);
  137|      0|    close(pMutex->u.pipeStr.mPipes[0]);
  138|      0|    close(pMutex->u.pipeStr.mPipes[1]);
  139|      0|    return SECFailure;
  140|      0|}
sslMutex_Destroy:
  144|     11|{
  145|     11|    if (PR_FALSE == pMutex->isMultiProcess) {
  ------------------
  |  |  438|     11|#define PR_FALSE 0
  ------------------
  |  Branch (145:9): [True: 11, False: 0]
  ------------------
  146|     11|        return single_process_sslMutex_Destroy(pMutex);
  147|     11|    }
  148|      0|    if (pMutex->u.pipeStr.mPipes[2] != SSL_MUTEX_MAGIC) {
  ------------------
  |  |   73|      0|#define SSL_MUTEX_MAGIC 0xfeedfd
  ------------------
  |  Branch (148:9): [True: 0, False: 0]
  ------------------
  149|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  150|      0|        return SECFailure;
  151|      0|    }
  152|      0|    close(pMutex->u.pipeStr.mPipes[0]);
  153|      0|    close(pMutex->u.pipeStr.mPipes[1]);
  154|       |
  155|      0|    if (processLocal) {
  ------------------
  |  Branch (155:9): [True: 0, False: 0]
  ------------------
  156|      0|        return SECSuccess;
  157|      0|    }
  158|       |
  159|      0|    pMutex->u.pipeStr.mPipes[0] = -1;
  160|      0|    pMutex->u.pipeStr.mPipes[1] = -1;
  161|      0|    pMutex->u.pipeStr.mPipes[2] = -1;
  162|      0|    pMutex->u.pipeStr.nWaiters = 0;
  163|       |
  164|      0|    return SECSuccess;
  165|      0|}
sslMutex_Unlock:
  248|  33.5k|{
  249|  33.5k|    int cc;
  250|  33.5k|    char c = 1;
  251|       |
  252|  33.5k|    if (PR_FALSE == pMutex->isMultiProcess) {
  ------------------
  |  |  438|  33.5k|#define PR_FALSE 0
  ------------------
  |  Branch (252:9): [True: 33.5k, False: 0]
  ------------------
  253|  33.5k|        return single_process_sslMutex_Unlock(pMutex);
  254|  33.5k|    }
  255|       |
  256|      0|    if (pMutex->u.pipeStr.mPipes[2] != SSL_MUTEX_MAGIC) {
  ------------------
  |  |   73|      0|#define SSL_MUTEX_MAGIC 0xfeedfd
  ------------------
  |  Branch (256:9): [True: 0, False: 0]
  ------------------
  257|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  258|      0|        return SECFailure;
  259|      0|    }
  260|      0|    do {
  261|      0|        cc = write(pMutex->u.pipeStr.mPipes[1], &c, 1);
  262|      0|    } while (cc < 0 && (errno == EINTR || errno == EAGAIN));
  ------------------
  |  Branch (262:14): [True: 0, False: 0]
  |  Branch (262:25): [True: 0, False: 0]
  |  Branch (262:43): [True: 0, False: 0]
  ------------------
  263|      0|    if (cc != 1) {
  ------------------
  |  Branch (263:9): [True: 0, False: 0]
  ------------------
  264|      0|        if (cc < 0)
  ------------------
  |  Branch (264:13): [True: 0, False: 0]
  ------------------
  265|      0|            nss_MD_unix_map_default_error(errno);
  266|      0|        else
  267|      0|            PORT_SetError(PR_UNKNOWN_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_UNKNOWN_ERROR);
  ------------------
  |  |   34|      0|#define PR_UNKNOWN_ERROR                         (-5994L)
  ------------------
  268|      0|        return SECFailure;
  269|      0|    }
  270|       |
  271|      0|    return SECSuccess;
  272|      0|}
sslMutex_Lock:
  276|  33.5k|{
  277|  33.5k|    int cc;
  278|  33.5k|    char c;
  279|       |
  280|  33.5k|    if (PR_FALSE == pMutex->isMultiProcess) {
  ------------------
  |  |  438|  33.5k|#define PR_FALSE 0
  ------------------
  |  Branch (280:9): [True: 33.5k, False: 0]
  ------------------
  281|  33.5k|        return single_process_sslMutex_Lock(pMutex);
  282|  33.5k|    }
  283|       |
  284|      0|    if (pMutex->u.pipeStr.mPipes[2] != SSL_MUTEX_MAGIC) {
  ------------------
  |  |   73|      0|#define SSL_MUTEX_MAGIC 0xfeedfd
  ------------------
  |  Branch (284:9): [True: 0, False: 0]
  ------------------
  285|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  286|      0|        return SECFailure;
  287|      0|    }
  288|       |
  289|      0|    do {
  290|      0|        cc = read(pMutex->u.pipeStr.mPipes[0], &c, 1);
  291|      0|    } while (cc < 0 && errno == EINTR);
  ------------------
  |  Branch (291:14): [True: 0, False: 0]
  |  Branch (291:24): [True: 0, False: 0]
  ------------------
  292|      0|    if (cc != 1) {
  ------------------
  |  Branch (292:9): [True: 0, False: 0]
  ------------------
  293|      0|        if (cc < 0)
  ------------------
  |  Branch (293:13): [True: 0, False: 0]
  ------------------
  294|      0|            nss_MD_unix_map_default_error(errno);
  295|      0|        else
  296|      0|            PORT_SetError(PR_UNKNOWN_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_UNKNOWN_ERROR);
  ------------------
  |  |   34|      0|#define PR_UNKNOWN_ERROR                         (-5994L)
  ------------------
  297|      0|        return SECFailure;
  298|      0|    }
  299|       |
  300|      0|    return SECSuccess;
  301|      0|}
sslmutex.c:single_process_sslMutex_Init:
   14|     11|{
   15|     11|    PR_ASSERT(pMutex != 0 && pMutex->u.sslLock == 0);
  ------------------
  |  |  208|     22|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 11, False: 0]
  |  |  |  Branch (208:7): [True: 11, False: 0]
  |  |  ------------------
  ------------------
   16|       |
   17|     11|    pMutex->u.sslLock = PR_NewLock();
   18|     11|    if (!pMutex->u.sslLock) {
  ------------------
  |  Branch (18:9): [True: 0, False: 11]
  ------------------
   19|      0|        return SECFailure;
   20|      0|    }
   21|     11|    return SECSuccess;
   22|     11|}
sslmutex.c:single_process_sslMutex_Destroy:
   26|     11|{
   27|     11|    PR_ASSERT(pMutex != 0);
  ------------------
  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 11, False: 0]
  |  |  ------------------
  ------------------
   28|     11|    PR_ASSERT(pMutex->u.sslLock != 0);
  ------------------
  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 11, False: 0]
  |  |  ------------------
  ------------------
   29|     11|    if (!pMutex->u.sslLock) {
  ------------------
  |  Branch (29:9): [True: 0, False: 11]
  ------------------
   30|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
   31|      0|        return SECFailure;
   32|      0|    }
   33|     11|    PR_DestroyLock(pMutex->u.sslLock);
   34|     11|    return SECSuccess;
   35|     11|}
sslmutex.c:single_process_sslMutex_Unlock:
   39|  33.5k|{
   40|  33.5k|    PR_ASSERT(pMutex != 0);
  ------------------
  |  |  208|  33.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 33.5k, False: 0]
  |  |  ------------------
  ------------------
   41|  33.5k|    PR_ASSERT(pMutex->u.sslLock != 0);
  ------------------
  |  |  208|  33.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 33.5k, False: 0]
  |  |  ------------------
  ------------------
   42|  33.5k|    if (!pMutex->u.sslLock) {
  ------------------
  |  Branch (42:9): [True: 0, False: 33.5k]
  ------------------
   43|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
   44|      0|        return SECFailure;
   45|      0|    }
   46|  33.5k|    PR_Unlock(pMutex->u.sslLock);
   47|  33.5k|    return SECSuccess;
   48|  33.5k|}
sslmutex.c:single_process_sslMutex_Lock:
   52|  33.5k|{
   53|  33.5k|    PR_ASSERT(pMutex != 0);
  ------------------
  |  |  208|  33.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 33.5k, False: 0]
  |  |  ------------------
  ------------------
   54|  33.5k|    PR_ASSERT(pMutex->u.sslLock != 0);
  ------------------
  |  |  208|  33.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 33.5k, False: 0]
  |  |  ------------------
  ------------------
   55|  33.5k|    if (!pMutex->u.sslLock) {
  ------------------
  |  Branch (55:9): [True: 0, False: 33.5k]
  ------------------
   56|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
   57|      0|        return SECFailure;
   58|      0|    }
   59|  33.5k|    PR_Lock(pMutex->u.sslLock);
   60|  33.5k|    return SECSuccess;
   61|  33.5k|}

ssl_FreeSessionCacheLocks:
   90|      1|{
   91|      1|    PORT_Assert(PR_TRUE == LocksInitializedEarly);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   92|      1|    if (!LocksInitializedEarly) {
  ------------------
  |  Branch (92:9): [True: 0, False: 1]
  ------------------
   93|      0|        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   94|      0|        return SECFailure;
   95|      0|    }
   96|      1|    FreeSessionCacheLocks();
   97|      1|    LocksInitializedEarly = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
   98|      1|    return SECSuccess;
   99|      1|}
ssl_InitSessionCacheLocks:
  137|   103k|{
  138|   103k|    if (LocksInitializedEarly) {
  ------------------
  |  Branch (138:9): [True: 103k, False: 1]
  ------------------
  139|   103k|        return SECSuccess;
  140|   103k|    }
  141|       |
  142|      1|    if (lazyInit) {
  ------------------
  |  Branch (142:9): [True: 0, False: 1]
  ------------------
  143|      0|        return (PR_SUCCESS ==
  ------------------
  |  Branch (143:16): [True: 0, False: 0]
  ------------------
  144|      0|                PR_CallOnce(&lockOnce, initSessionCacheLocksLazily))
  145|      0|                   ? SECSuccess
  146|      0|                   : SECFailure;
  147|      0|    }
  148|       |
  149|      1|    if (SECSuccess == InitSessionCacheLocks()) {
  ------------------
  |  Branch (149:9): [True: 1, False: 0]
  ------------------
  150|      1|        LocksInitializedEarly = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  151|      1|        return SECSuccess;
  152|      1|    }
  153|       |
  154|      0|    return SECFailure;
  155|      1|}
ssl_DestroySID:
  169|  60.1k|{
  170|  60.1k|    SSL_TRC(8, ("SSL: destroy sid: sid=0x%x cached=%d", sid, sid->cached));
  ------------------
  |  |   71|  60.1k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 60.1k]
  |  |  ------------------
  |  |   72|  60.1k|    ssl_Trace b
  ------------------
  171|  60.1k|    PORT_Assert(sid->references == 0);
  ------------------
  |  |  120|  60.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  60.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 60.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  172|  60.1k|    PORT_Assert(sid->cached != in_client_cache);
  ------------------
  |  |  120|  60.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  60.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 60.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  173|       |
  174|  60.1k|    if (sid->u.ssl3.locked.sessionTicket.ticket.data) {
  ------------------
  |  Branch (174:9): [True: 231, False: 59.9k]
  ------------------
  175|    231|        SECITEM_FreeItem(&sid->u.ssl3.locked.sessionTicket.ticket,
  ------------------
  |  |  108|    231|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
  176|    231|                         PR_FALSE);
  ------------------
  |  |  438|    231|#define PR_FALSE 0
  ------------------
  177|    231|    }
  178|  60.1k|    if (sid->u.ssl3.srvName.data) {
  ------------------
  |  Branch (178:9): [True: 36, False: 60.1k]
  ------------------
  179|     36|        SECITEM_FreeItem(&sid->u.ssl3.srvName, PR_FALSE);
  ------------------
  |  |  108|     36|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sid->u.ssl3.srvName, PR_FALSE);
  ------------------
  |  |  438|     36|#define PR_FALSE 0
  ------------------
  180|     36|    }
  181|  60.1k|    if (sid->u.ssl3.signedCertTimestamps.data) {
  ------------------
  |  Branch (181:9): [True: 0, False: 60.1k]
  ------------------
  182|      0|        SECITEM_FreeItem(&sid->u.ssl3.signedCertTimestamps, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&sid->u.ssl3.signedCertTimestamps, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  183|      0|    }
  184|       |
  185|  60.1k|    if (sid->u.ssl3.lock) {
  ------------------
  |  Branch (185:9): [True: 0, False: 60.1k]
  ------------------
  186|      0|        PR_DestroyRWLock(sid->u.ssl3.lock);
  187|      0|    }
  188|       |
  189|  60.1k|    PORT_Free((void *)sid->peerID);
  ------------------
  |  |   60|  60.1k|#define PORT_Free PORT_Free_Util
  ------------------
  190|  60.1k|    PORT_Free((void *)sid->urlSvrName);
  ------------------
  |  |   60|  60.1k|#define PORT_Free PORT_Free_Util
  ------------------
  191|       |
  192|  60.1k|    if (sid->peerCert) {
  ------------------
  |  Branch (192:9): [True: 3.47k, False: 56.7k]
  ------------------
  193|  3.47k|        CERT_DestroyCertificate(sid->peerCert);
  194|  3.47k|    }
  195|  60.1k|    if (sid->peerCertStatus.items) {
  ------------------
  |  Branch (195:9): [True: 0, False: 60.1k]
  ------------------
  196|      0|        SECITEM_FreeArray(&sid->peerCertStatus, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  197|      0|    }
  198|       |
  199|  60.1k|    if (sid->localCert) {
  ------------------
  |  Branch (199:9): [True: 30.3k, False: 29.8k]
  ------------------
  200|  30.3k|        CERT_DestroyCertificate(sid->localCert);
  201|  30.3k|    }
  202|       |
  203|  60.1k|    SECITEM_FreeItem(&sid->u.ssl3.alpnSelection, PR_FALSE);
  ------------------
  |  |  108|  60.1k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&sid->u.ssl3.alpnSelection, PR_FALSE);
  ------------------
  |  |  438|  60.1k|#define PR_FALSE 0
  ------------------
  204|       |
  205|  60.1k|    if (freeIt) {
  ------------------
  |  Branch (205:9): [True: 60.1k, False: 0]
  ------------------
  206|  60.1k|        PORT_ZFree(sid, sizeof(sslSessionID));
  ------------------
  |  |   75|  60.1k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  207|  60.1k|    }
  208|  60.1k|}
ssl_FreeSID:
  234|  60.1k|{
  235|  60.1k|    if (sid) {
  ------------------
  |  Branch (235:9): [True: 60.1k, False: 0]
  ------------------
  236|  60.1k|        LOCK_CACHE;
  ------------------
  |  |   35|  60.1k|#define LOCK_CACHE lock_cache()
  ------------------
  237|  60.1k|        ssl_FreeLockedSID(sid);
  238|  60.1k|        UNLOCK_CACHE;
  ------------------
  |  |   36|  60.1k|#define UNLOCK_CACHE PZ_Unlock(cacheLock)
  |  |  ------------------
  |  |  |  |  246|  60.1k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  239|  60.1k|    }
  240|  60.1k|}
ssl_CacheSessionID:
 1123|  30.3k|{
 1124|  30.3k|    sslSecurityInfo *sec = &ss->sec;
 1125|  30.3k|    PORT_Assert(sec);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1126|  30.3k|    PORT_Assert(sec->ci.sid->cached == never_cached);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1127|       |
 1128|  30.3k|    if (sec->ci.sid && !sec->ci.sid->u.ssl3.keys.resumable) {
  ------------------
  |  Branch (1128:9): [True: 30.3k, False: 0]
  |  Branch (1128:24): [True: 0, False: 30.3k]
  ------------------
 1129|      0|        return;
 1130|      0|    }
 1131|       |
 1132|  30.3k|    if (!sec->isServer && ss->resumptionTokenCallback) {
  ------------------
  |  Branch (1132:9): [True: 0, False: 30.3k]
  |  Branch (1132:27): [True: 0, False: 0]
  ------------------
 1133|      0|        ssl_CacheExternalToken(ss);
 1134|      0|        return;
 1135|      0|    }
 1136|       |
 1137|  30.3k|    PORT_Assert(!ss->resumptionTokenCallback);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1138|  30.3k|    if (sec->isServer) {
  ------------------
  |  Branch (1138:9): [True: 30.3k, False: 0]
  ------------------
 1139|  30.3k|        ssl_ServerCacheSessionID(sec->ci.sid, ssl_Time(ss));
 1140|  30.3k|        return;
 1141|  30.3k|    }
 1142|       |
 1143|      0|    CacheSID(sec->ci.sid, ssl_Time(ss));
 1144|      0|}
ssl_UncacheSessionID:
 1148|  2.75k|{
 1149|  2.75k|    if (ss->opt.noCache) {
  ------------------
  |  Branch (1149:9): [True: 1.30k, False: 1.45k]
  ------------------
 1150|  1.30k|        return;
 1151|  1.30k|    }
 1152|       |
 1153|  1.45k|    sslSecurityInfo *sec = &ss->sec;
 1154|  1.45k|    PORT_Assert(sec);
  ------------------
  |  |  120|  1.45k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.45k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.45k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1155|       |
 1156|  1.45k|    if (sec->ci.sid) {
  ------------------
  |  Branch (1156:9): [True: 1.36k, False: 87]
  ------------------
 1157|  1.36k|        if (sec->isServer) {
  ------------------
  |  Branch (1157:13): [True: 1.36k, False: 0]
  ------------------
 1158|  1.36k|            ssl_ServerUncacheSessionID(sec->ci.sid);
 1159|  1.36k|        } else if (!ss->resumptionTokenCallback) {
  ------------------
  |  Branch (1159:20): [True: 0, False: 0]
  ------------------
 1160|      0|            LockAndUncacheSID(sec->ci.sid);
 1161|      0|        }
 1162|  1.36k|    }
 1163|  1.45k|}
SSL_ClearSessionCache:
 1168|  9.71k|{
 1169|  9.71k|    LOCK_CACHE;
  ------------------
  |  |   35|  9.71k|#define LOCK_CACHE lock_cache()
  ------------------
 1170|  9.71k|    while (cache != NULL)
  ------------------
  |  Branch (1170:12): [True: 0, False: 9.71k]
  ------------------
 1171|      0|        UncacheSID(cache);
 1172|  9.71k|    UNLOCK_CACHE;
  ------------------
  |  |   36|  9.71k|#define UNLOCK_CACHE PZ_Unlock(cacheLock)
  |  |  ------------------
  |  |  |  |  246|  9.71k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
 1173|  9.71k|}
sslnonce.c:FreeSessionCacheLocks:
   61|      1|{
   62|      1|    SECStatus rv1, rv2;
   63|      1|    rv1 = ssl_FreeSymWrapKeysLock();
   64|      1|    rv2 = ssl_FreeClientSessionCacheLock();
   65|      1|    if ((SECSuccess == rv1) && (SECSuccess == rv2)) {
  ------------------
  |  Branch (65:9): [True: 1, False: 0]
  |  Branch (65:32): [True: 1, False: 0]
  ------------------
   66|      1|        return SECSuccess;
   67|      1|    }
   68|      0|    return SECFailure;
   69|      1|}
sslnonce.c:ssl_FreeClientSessionCacheLock:
   47|      1|{
   48|      1|    if (cacheLock) {
  ------------------
  |  Branch (48:9): [True: 1, False: 0]
  ------------------
   49|      1|        PZ_DestroyLock(cacheLock);
  ------------------
  |  |  244|      1|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
   50|      1|        cacheLock = NULL;
   51|      1|        return SECSuccess;
   52|      1|    }
   53|      0|    PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   54|      0|    return SECFailure;
   55|      1|}
sslnonce.c:InitSessionCacheLocks:
   73|      1|{
   74|      1|    SECStatus rv1, rv2;
   75|      1|    PRErrorCode rc;
   76|      1|    rv1 = ssl_InitSymWrapKeysLock();
   77|      1|    rv2 = ssl_InitClientSessionCacheLock();
   78|      1|    if ((SECSuccess == rv1) && (SECSuccess == rv2)) {
  ------------------
  |  Branch (78:9): [True: 1, False: 0]
  |  Branch (78:32): [True: 1, False: 0]
  ------------------
   79|      1|        return SECSuccess;
   80|      1|    }
   81|      0|    rc = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
   82|      0|    FreeSessionCacheLocks();
   83|      0|    PORT_SetError(rc);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   84|      0|    return SECFailure;
   85|      1|}
sslnonce.c:ssl_InitClientSessionCacheLock:
   40|      1|{
   41|      1|    cacheLock = PZ_NewLock(nssILockCache);
  ------------------
  |  |  243|      1|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   42|      1|    return cacheLock ? SECSuccess : SECFailure;
  ------------------
  |  Branch (42:12): [True: 1, False: 0]
  ------------------
   43|      1|}
sslnonce.c:lock_cache:
  159|  69.8k|{
  160|  69.8k|    ssl_InitSessionCacheLocks(PR_TRUE);
  ------------------
  |  |  437|  69.8k|#define PR_TRUE 1
  ------------------
  161|  69.8k|    PZ_Lock(cacheLock);
  ------------------
  |  |  245|  69.8k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  162|  69.8k|}
sslnonce.c:ssl_FreeLockedSID:
  219|  60.1k|{
  220|  60.1k|    PORT_Assert(sid->references >= 1);
  ------------------
  |  |  120|  60.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  60.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 60.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  221|  60.1k|    if (--sid->references == 0) {
  ------------------
  |  Branch (221:9): [True: 60.1k, False: 0]
  ------------------
  222|  60.1k|        ssl_DestroySID(sid, PR_TRUE);
  ------------------
  |  |  437|  60.1k|#define PR_TRUE 1
  ------------------
  223|  60.1k|    }
  224|  60.1k|}

ssl_DestroyMaskingContextInner:
  439|   415k|{
  440|   415k|    if (!ctx) {
  ------------------
  |  Branch (440:9): [True: 415k, False: 0]
  ------------------
  441|   415k|        return SECSuccess;
  442|   415k|    }
  443|       |
  444|      0|    PK11_FreeSymKey(ctx->secret);
  445|      0|    PORT_ZFree(ctx, sizeof(*ctx));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  446|      0|    return SECSuccess;
  447|   415k|}

ssl_Do1stHandshake:
   34|  9.71k|{
   35|  9.71k|    SECStatus rv = SECSuccess;
   36|       |
   37|  29.1k|    while (ss->handshake && rv == SECSuccess) {
  ------------------
  |  Branch (37:12): [True: 26.5k, False: 2.62k]
  |  Branch (37:29): [True: 19.4k, False: 7.09k]
  ------------------
   38|  19.4k|        PORT_Assert(ss->opt.noLocks || ssl_Have1stHandshakeLock(ss));
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.03k, False: 10.3k]
  |  |  |  |  |  Branch (208:7): [True: 10.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   39|  19.4k|        PORT_Assert(ss->opt.noLocks || !ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.03k, False: 10.3k]
  |  |  |  |  |  Branch (208:7): [True: 10.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   40|  19.4k|        PORT_Assert(ss->opt.noLocks || !ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.03k, False: 10.3k]
  |  |  |  |  |  Branch (208:7): [True: 10.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   41|  19.4k|        PORT_Assert(ss->opt.noLocks || !ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  29.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 9.03k, False: 10.3k]
  |  |  |  |  |  Branch (208:7): [True: 10.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   42|       |
   43|  19.4k|        rv = (*ss->handshake)(ss);
   44|  19.4k|    };
   45|       |
   46|  9.71k|    PORT_Assert(ss->opt.noLocks || !ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.51k, False: 5.19k]
  |  |  |  |  |  Branch (208:7): [True: 5.19k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   47|  9.71k|    PORT_Assert(ss->opt.noLocks || !ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.51k, False: 5.19k]
  |  |  |  |  |  Branch (208:7): [True: 5.19k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   48|  9.71k|    PORT_Assert(ss->opt.noLocks || !ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.51k, False: 5.19k]
  |  |  |  |  |  Branch (208:7): [True: 5.19k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   49|       |
   50|  9.71k|    return rv;
   51|  9.71k|}
ssl_FinishHandshake:
   55|  52.9k|{
   56|  52.9k|    PORT_Assert(ss->opt.noLocks || ssl_Have1stHandshakeLock(ss));
  ------------------
  |  |  120|  52.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  80.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.8k, False: 27.1k]
  |  |  |  |  |  Branch (208:7): [True: 27.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   57|  52.9k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  52.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  80.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 25.8k, False: 27.1k]
  |  |  |  |  |  Branch (208:7): [True: 27.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   58|  52.9k|    PORT_Assert(ss->ssl3.hs.echAccepted ||
  ------------------
  |  |  120|  52.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   238k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 26.1k, False: 26.8k]
  |  |  |  |  |  Branch (208:7): [True: 7, False: 26.1k]
  |  |  |  |  |  Branch (208:7): [True: 7, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 52.9k]
  |  |  |  |  |  Branch (208:7): [True: 52.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   59|  52.9k|                (ss->opt.enableTls13BackendEch &&
   60|  52.9k|                 ss->xtnData.ech &&
   61|  52.9k|                 ss->xtnData.ech->receivedInnerXtn) ==
   62|  52.9k|                    ssl3_ExtensionNegotiated(ss, ssl_tls13_encrypted_client_hello_xtn));
   63|       |
   64|       |    /* If ECH was OFFERED to (echHpkeCtx is set on the client) DISABLED by the
   65|       |     * server through negotiation of a TLS version < 1.3, an 'ech_required'
   66|       |     * alert MUST be sent to inform the server about the intention / possible
   67|       |     * misconfiguration. */
   68|  52.9k|    if (!ss->sec.isServer && ss->ssl3.hs.echHpkeCtx && !ss->ssl3.hs.echAccepted) {
  ------------------
  |  Branch (68:9): [True: 0, False: 52.9k]
  |  Branch (68:30): [True: 0, False: 0]
  |  Branch (68:56): [True: 0, False: 0]
  ------------------
   69|      0|        SSL3_SendAlert(ss, alert_fatal, ech_required);
   70|       |        /* "If [one, none] of the retry_configs contains a supported version,
   71|       |         * the client can regard ECH as securely [replaced, disabled] by the
   72|       |         * server." */
   73|      0|        if (ss->xtnData.ech && ss->xtnData.ech->retryConfigs.len) {
  ------------------
  |  Branch (73:13): [True: 0, False: 0]
  |  Branch (73:32): [True: 0, False: 0]
  ------------------
   74|      0|            PORT_SetError(SSL_ERROR_ECH_RETRY_WITH_ECH);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   75|      0|            ss->xtnData.ech->retryConfigsValid = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
   76|      0|        } else {
   77|      0|            PORT_SetError(SSL_ERROR_ECH_RETRY_WITHOUT_ECH);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   78|      0|        }
   79|      0|        return SECFailure;
   80|      0|    }
   81|       |
   82|  52.9k|    SSL_TRC(3, ("%d: SSL[%d]: handshake is completed", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|  52.9k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 52.9k]
  |  |  ------------------
  |  |   72|  52.9k|    ssl_Trace b
  ------------------
   83|       |
   84|  52.9k|    ss->firstHsDone = PR_TRUE;
  ------------------
  |  |  437|  52.9k|#define PR_TRUE 1
  ------------------
   85|  52.9k|    ss->enoughFirstHsDone = PR_TRUE;
  ------------------
  |  |  437|  52.9k|#define PR_TRUE 1
  ------------------
   86|  52.9k|    ss->gs.writeOffset = 0;
   87|  52.9k|    ss->gs.readOffset = 0;
   88|       |
   89|  52.9k|    if (ss->handshakeCallback) {
  ------------------
  |  Branch (89:9): [True: 0, False: 52.9k]
  ------------------
   90|      0|        PORT_Assert((ss->ssl3.hs.preliminaryInfo & ssl_preinfo_all) ==
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   91|      0|                    ssl_preinfo_all);
   92|      0|        (ss->handshakeCallback)(ss->fd, ss->handshakeCallbackData);
   93|      0|    }
   94|       |
   95|  52.9k|    ssl_FreeEphemeralKeyPairs(ss);
   96|       |
   97|  52.9k|    return SECSuccess;
   98|  52.9k|}
SSL_ResetHandshake:
  149|  9.71k|{
  150|  9.71k|    sslSocket *ss;
  151|  9.71k|    SECStatus status;
  152|  9.71k|    PRNetAddr addr;
  153|       |
  154|  9.71k|    ss = ssl_FindSocket(s);
  155|  9.71k|    if (!ss) {
  ------------------
  |  Branch (155:9): [True: 0, False: 9.71k]
  ------------------
  156|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in ResetHandshake", SSL_GETPID(), s));
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  157|      0|        return SECFailure;
  158|      0|    }
  159|       |
  160|       |    /* Don't waste my time */
  161|  9.71k|    if (!ss->opt.useSecurity)
  ------------------
  |  Branch (161:9): [True: 0, False: 9.71k]
  ------------------
  162|      0|        return SECSuccess;
  163|       |
  164|  9.71k|    SSL_LOCK_READER(ss);
  ------------------
  |  | 1376|  9.71k|    if (ss->recvLock)       \
  |  |  ------------------
  |  |  |  Branch (1376:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1377|  9.71k|    PZ_Lock(ss->recvLock)
  |  |  ------------------
  |  |  |  |  245|  9.71k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  165|  9.71k|    SSL_LOCK_WRITER(ss);
  ------------------
  |  | 1382|  9.71k|    if (ss->sendLock)       \
  |  |  ------------------
  |  |  |  Branch (1382:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1383|  9.71k|    PZ_Lock(ss->sendLock)
  |  |  ------------------
  |  |  |  |  245|  9.71k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
  166|       |
  167|       |    /* Reset handshake state */
  168|  9.71k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  9.71k|    {                                                             \
  |  | 1391|  9.71k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1392|  5.19k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  10.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 5.19k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  5.19k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  5.19k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  5.19k|        }                                                         \
  |  | 1396|  9.71k|    }
  ------------------
  169|       |
  170|  9.71k|    ss->firstHsDone = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
  171|  9.71k|    ss->enoughFirstHsDone = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
  172|  9.71k|    if (asServer) {
  ------------------
  |  Branch (172:9): [True: 9.71k, False: 0]
  ------------------
  173|  9.71k|        ss->handshake = ssl_BeginServerHandshake;
  174|  9.71k|        ss->handshaking = sslHandshakingAsServer;
  175|  9.71k|    } else {
  176|      0|        ss->handshake = ssl_BeginClientHandshake;
  177|      0|        ss->handshaking = sslHandshakingAsClient;
  178|      0|    }
  179|       |
  180|  9.71k|    ssl_GetRecvBufLock(ss);
  ------------------
  |  | 1449|  9.71k|    {                                                    \
  |  | 1450|  9.71k|        if (!ss->opt.noLocks) {                          \
  |  |  ------------------
  |  |  |  Branch (1450:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1451|  5.19k|            PORT_Assert(!ssl_HaveSSL3HandshakeLock(ss)); \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.19k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1452|  5.19k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));       \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.19k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1453|  5.19k|            PZ_EnterMonitor((ss)->recvBufLock);          \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1454|  5.19k|        }                                                \
  |  | 1455|  9.71k|    }
  ------------------
  181|  9.71k|    status = ssl3_InitGather(&ss->gs);
  182|  9.71k|    ssl_ReleaseRecvBufLock(ss);
  ------------------
  |  | 1457|  9.71k|    {                                          \
  |  | 1458|  9.71k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1458:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1459|  9.71k|            PZ_ExitMonitor((ss)->recvBufLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1460|  9.71k|    }
  ------------------
  183|  9.71k|    if (status != SECSuccess)
  ------------------
  |  Branch (183:9): [True: 0, False: 9.71k]
  ------------------
  184|      0|        goto loser;
  185|       |
  186|  9.71k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  9.71k|    {                                                 \
  |  | 1408|  9.71k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1409|  5.19k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.19k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  5.19k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  5.19k|        }                                             \
  |  | 1412|  9.71k|    }
  ------------------
  187|  9.71k|    ss->ssl3.hs.canFalseStart = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
  188|  9.71k|    ss->ssl3.hs.restartTarget = NULL;
  189|       |
  190|       |    /*
  191|       |    ** Blow away old security state and get a fresh setup.
  192|       |    */
  193|  9.71k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  9.71k|    {                                           \
  |  | 1467|  9.71k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1468|  9.71k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  9.71k|    }
  ------------------
  194|  9.71k|    ssl_ResetSecurityInfo(&ss->sec, PR_TRUE);
  ------------------
  |  |  437|  9.71k|#define PR_TRUE 1
  ------------------
  195|  9.71k|    status = ssl_CreateSecurityInfo(ss);
  196|  9.71k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  9.71k|    {                                          \
  |  | 1472|  9.71k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1473|  9.71k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  9.71k|    }
  ------------------
  197|       |
  198|  9.71k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  9.71k|    {                                                \
  |  | 1415|  9.71k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1416|  9.71k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  9.71k|    }
  ------------------
  199|  9.71k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  9.71k|    {                                                 \
  |  | 1399|  9.71k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1400|  9.71k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  9.71k|    }
  ------------------
  200|       |
  201|  9.71k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.remoteExtensions);
  202|  9.71k|    ssl3_DestroyRemoteExtensions(&ss->ssl3.hs.echOuterExtensions);
  203|  9.71k|    ssl3_ResetExtensionData(&ss->xtnData, ss);
  204|  9.71k|    tls13_ResetHandshakePsks(ss, &ss->ssl3.hs.psks);
  205|       |
  206|  9.71k|    if (ss->ssl3.hs.echHpkeCtx) {
  ------------------
  |  Branch (206:9): [True: 0, False: 9.71k]
  ------------------
  207|      0|        PK11_HPKE_DestroyContext(ss->ssl3.hs.echHpkeCtx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  208|      0|        ss->ssl3.hs.echHpkeCtx = NULL;
  209|      0|        PORT_Assert(ss->ssl3.hs.echPublicName);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  210|      0|        PORT_Free((void *)ss->ssl3.hs.echPublicName); /* CONST */
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  211|      0|        ss->ssl3.hs.echPublicName = NULL;
  212|      0|    }
  213|       |    /* Make sure greaseEchBuf is freed in ECH setups without echHpkeCtx. */
  214|  9.71k|    if (ss->ssl3.hs.echHpkeCtx ||
  ------------------
  |  Branch (214:9): [True: 0, False: 9.71k]
  ------------------
  215|  9.71k|        ss->opt.enableTls13BackendEch ||
  ------------------
  |  Branch (215:9): [True: 4.69k, False: 5.02k]
  ------------------
  216|  9.71k|        ss->opt.enableTls13GreaseEch) {
  ------------------
  |  Branch (216:9): [True: 0, False: 5.02k]
  ------------------
  217|  4.69k|        sslBuffer_Clear(&ss->ssl3.hs.greaseEchBuf);
  218|  4.69k|    }
  219|       |
  220|  9.71k|    tls13_ClientGreaseDestroy(ss);
  221|       |
  222|  9.71k|    tls_ClientHelloExtensionPermutationDestroy(ss);
  223|       |
  224|  9.71k|    if (!ss->TCPconnected)
  ------------------
  |  Branch (224:9): [True: 0, False: 9.71k]
  ------------------
  225|      0|        ss->TCPconnected = (PR_SUCCESS == ssl_DefGetpeername(ss, &addr));
  226|       |
  227|  9.71k|loser:
  228|  9.71k|    SSL_UNLOCK_WRITER(ss);
  ------------------
  |  | 1385|  9.71k|    if (ss->sendLock)         \
  |  |  ------------------
  |  |  |  Branch (1385:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1386|  9.71k|    PZ_Unlock(ss->sendLock)
  |  |  ------------------
  |  |  |  |  246|  9.71k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  229|  9.71k|    SSL_UNLOCK_READER(ss);
  ------------------
  |  | 1379|  9.71k|    if (ss->recvLock)         \
  |  |  ------------------
  |  |  |  Branch (1379:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1380|  9.71k|    PZ_Unlock(ss->recvLock)
  |  |  ------------------
  |  |  |  |  246|  9.71k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  230|       |
  231|  9.71k|    return status;
  232|  9.71k|}
SSL_SetCanFalseStartCallback:
  324|  9.71k|{
  325|  9.71k|    sslSocket *ss;
  326|       |
  327|  9.71k|    ss = ssl_FindSocket(fd);
  328|  9.71k|    if (!ss) {
  ------------------
  |  Branch (328:9): [True: 0, False: 9.71k]
  ------------------
  329|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in SSL_SetCanFalseStartCallback",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  330|      0|                 SSL_GETPID(), fd));
  331|      0|        return SECFailure;
  332|      0|    }
  333|       |
  334|  9.71k|    if (!ss->opt.useSecurity) {
  ------------------
  |  Branch (334:9): [True: 0, False: 9.71k]
  ------------------
  335|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  336|      0|        return SECFailure;
  337|      0|    }
  338|       |
  339|  9.71k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  9.71k|    {                                                             \
  |  | 1391|  9.71k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1392|  9.71k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 9.71k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 9.71k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  9.71k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  9.71k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  9.71k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  9.71k|        }                                                         \
  |  | 1396|  9.71k|    }
  ------------------
  340|  9.71k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  9.71k|    {                                                 \
  |  | 1408|  9.71k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1409|  9.71k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  9.71k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  9.71k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  9.71k|        }                                             \
  |  | 1412|  9.71k|    }
  ------------------
  341|       |
  342|  9.71k|    ss->canFalseStartCallback = cb;
  343|  9.71k|    ss->canFalseStartCallbackData = arg;
  344|       |
  345|  9.71k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  9.71k|    {                                                \
  |  | 1415|  9.71k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1416|  9.71k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  9.71k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  9.71k|    }
  ------------------
  346|  9.71k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  9.71k|    {                                                 \
  |  | 1399|  9.71k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1400|  9.71k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  9.71k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  9.71k|    }
  ------------------
  347|       |
  348|  9.71k|    return SECSuccess;
  349|  9.71k|}
SSL_ForceHandshake:
  384|  9.71k|{
  385|  9.71k|    sslSocket *ss;
  386|  9.71k|    SECStatus rv = SECFailure;
  387|       |
  388|  9.71k|    ss = ssl_FindSocket(fd);
  389|  9.71k|    if (!ss) {
  ------------------
  |  Branch (389:9): [True: 0, False: 9.71k]
  ------------------
  390|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in ForceHandshake",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  391|      0|                 SSL_GETPID(), fd));
  392|      0|        return rv;
  393|      0|    }
  394|       |
  395|       |    /* Don't waste my time */
  396|  9.71k|    if (!ss->opt.useSecurity)
  ------------------
  |  Branch (396:9): [True: 0, False: 9.71k]
  ------------------
  397|      0|        return SECSuccess;
  398|       |
  399|  9.71k|    if (!ssl_SocketIsBlocking(ss)) {
  ------------------
  |  Branch (399:9): [True: 9.71k, False: 0]
  ------------------
  400|  9.71k|        ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  9.71k|    {                                           \
  |  | 1467|  9.71k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1468|  9.71k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  9.71k|    }
  ------------------
  401|  9.71k|        if (ss->pendingBuf.len != 0) {
  ------------------
  |  Branch (401:13): [True: 0, False: 9.71k]
  ------------------
  402|      0|            int sent = ssl_SendSavedWriteData(ss);
  403|      0|            if ((sent < 0) && (PORT_GetError() != PR_WOULD_BLOCK_ERROR)) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
                          if ((sent < 0) && (PORT_GetError() != PR_WOULD_BLOCK_ERROR)) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (403:17): [True: 0, False: 0]
  |  Branch (403:31): [True: 0, False: 0]
  ------------------
  404|      0|                ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
  405|      0|                return SECFailure;
  406|      0|            }
  407|      0|        }
  408|  9.71k|        ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  9.71k|    {                                          \
  |  | 1472|  9.71k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1473|  9.71k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  9.71k|    }
  ------------------
  409|  9.71k|    }
  410|       |
  411|  9.71k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  9.71k|    {                                                             \
  |  | 1391|  9.71k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1392|  5.19k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  5.19k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  10.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 5.19k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 5.19k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  5.19k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  5.19k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  5.19k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  5.19k|        }                                                         \
  |  | 1396|  9.71k|    }
  ------------------
  412|       |
  413|  9.71k|    if (ss->version >= SSL_LIBRARY_VERSION_3_0) {
  ------------------
  |  |   17|  9.71k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (413:9): [True: 0, False: 9.71k]
  ------------------
  414|      0|        int gatherResult;
  415|       |
  416|      0|        ssl_GetRecvBufLock(ss);
  ------------------
  |  | 1449|      0|    {                                                    \
  |  | 1450|      0|        if (!ss->opt.noLocks) {                          \
  |  |  ------------------
  |  |  |  Branch (1450:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1451|      0|            PORT_Assert(!ssl_HaveSSL3HandshakeLock(ss)); \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1452|      0|            PORT_Assert(!ssl_HaveXmitBufLock(ss));       \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1453|      0|            PZ_EnterMonitor((ss)->recvBufLock);          \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1454|      0|        }                                                \
  |  | 1455|      0|    }
  ------------------
  417|      0|        gatherResult = ssl3_GatherCompleteHandshake(ss, 0);
  418|      0|        ssl_ReleaseRecvBufLock(ss);
  ------------------
  |  | 1457|      0|    {                                          \
  |  | 1458|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1458:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1459|      0|            PZ_ExitMonitor((ss)->recvBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1460|      0|    }
  ------------------
  419|      0|        if (gatherResult > 0) {
  ------------------
  |  Branch (419:13): [True: 0, False: 0]
  ------------------
  420|      0|            rv = SECSuccess;
  421|      0|        } else {
  422|      0|            if (gatherResult == 0) {
  ------------------
  |  Branch (422:17): [True: 0, False: 0]
  ------------------
  423|      0|                PORT_SetError(PR_END_OF_FILE_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                              PORT_SetError(PR_END_OF_FILE_ERROR);
  ------------------
  |  |  202|      0|#define PR_END_OF_FILE_ERROR                     (-5938L)
  ------------------
  424|      0|            }
  425|       |            /* We can rely on ssl3_GatherCompleteHandshake to set
  426|       |             * PR_WOULD_BLOCK_ERROR as needed here. */
  427|      0|            rv = SECFailure;
  428|      0|        }
  429|  9.71k|    } else {
  430|  9.71k|        PORT_Assert(!ss->firstHsDone);
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  431|  9.71k|        rv = ssl_Do1stHandshake(ss);
  432|  9.71k|    }
  433|       |
  434|  9.71k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  9.71k|    {                                                 \
  |  | 1399|  9.71k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 5.19k, False: 4.51k]
  |  |  ------------------
  |  | 1400|  9.71k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  5.19k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  9.71k|    }
  ------------------
  435|       |
  436|  9.71k|    return rv;
  437|  9.71k|}
ssl_SaveWriteData:
  462|   111k|{
  463|   111k|    SECStatus rv;
  464|       |
  465|   111k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|   111k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   168k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 54.1k, False: 57.2k]
  |  |  |  |  |  Branch (208:7): [True: 57.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  466|   111k|    rv = sslBuffer_Append(&ss->pendingBuf, data, len);
  467|   111k|    SSL_TRC(5, ("%d: SSL[%d]: saving %u bytes of data (%u total saved so far)",
  ------------------
  |  |   71|   111k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 111k]
  |  |  ------------------
  |  |   72|   111k|    ssl_Trace b
  ------------------
  468|   111k|                SSL_GETPID(), ss->fd, len, ss->pendingBuf.len));
  469|   111k|    return rv;
  470|   111k|}
ssl_SendSavedWriteData:
  480|  53.7k|{
  481|  53.7k|    int rv = 0;
  482|       |
  483|  53.7k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  53.7k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  81.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 26.2k, False: 27.5k]
  |  |  |  |  |  Branch (208:7): [True: 27.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  484|  53.7k|    if (ss->pendingBuf.len != 0) {
  ------------------
  |  Branch (484:9): [True: 53.7k, False: 0]
  ------------------
  485|  53.7k|        SSL_TRC(5, ("%d: SSL[%d]: sending %d bytes of saved data",
  ------------------
  |  |   71|  53.7k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 53.7k]
  |  |  ------------------
  |  |   72|  53.7k|    ssl_Trace b
  ------------------
  486|  53.7k|                    SSL_GETPID(), ss->fd, ss->pendingBuf.len));
  487|  53.7k|        rv = ssl_DefSend(ss, ss->pendingBuf.buf, ss->pendingBuf.len, 0);
  488|  53.7k|        if (rv < 0) {
  ------------------
  |  Branch (488:13): [True: 0, False: 53.7k]
  ------------------
  489|      0|            return rv;
  490|      0|        }
  491|  53.7k|        if (rv > ss->pendingBuf.len) {
  ------------------
  |  Branch (491:13): [True: 0, False: 53.7k]
  ------------------
  492|      0|            PORT_Assert(0); /* This shouldn't happen */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  493|      0|            ss->pendingBuf.len = 0;
  494|  53.7k|        } else {
  495|  53.7k|            ss->pendingBuf.len -= rv;
  496|  53.7k|        }
  497|  53.7k|        if (ss->pendingBuf.len > 0 && rv > 0) {
  ------------------
  |  Branch (497:13): [True: 0, False: 53.7k]
  |  Branch (497:39): [True: 0, False: 0]
  ------------------
  498|       |            /* UGH !! This shifts the whole buffer down by copying it */
  499|      0|            PORT_Memmove(ss->pendingBuf.buf, ss->pendingBuf.buf + rv,
  ------------------
  |  |  181|      0|#define PORT_Memmove memmove
  ------------------
  500|      0|                         ss->pendingBuf.len);
  501|      0|        }
  502|  53.7k|    }
  503|  53.7k|    return rv;
  504|  53.7k|}
ssl_CreateSecurityInfo:
  619|  19.4k|{
  620|  19.4k|    SECStatus status;
  621|       |
  622|  19.4k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  19.4k|    {                                           \
  |  | 1467|  19.4k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 14.9k, False: 4.51k]
  |  |  ------------------
  |  | 1468|  19.4k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  14.9k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  19.4k|    }
  ------------------
  623|  19.4k|    status = sslBuffer_Grow(&ss->sec.writeBuf, 4096);
  624|  19.4k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  19.4k|    {                                          \
  |  | 1472|  19.4k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 14.9k, False: 4.51k]
  |  |  ------------------
  |  | 1473|  19.4k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  14.9k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  19.4k|    }
  ------------------
  625|       |
  626|  19.4k|    return status;
  627|  19.4k|}
ssl_CopySecurityInfo:
  631|  9.71k|{
  632|  9.71k|    ss->sec.isServer = os->sec.isServer;
  633|       |
  634|  9.71k|    ss->sec.peerCert = CERT_DupCertificate(os->sec.peerCert);
  635|  9.71k|    if (os->sec.peerCert && !ss->sec.peerCert)
  ------------------
  |  Branch (635:9): [True: 0, False: 9.71k]
  |  Branch (635:29): [True: 0, False: 0]
  ------------------
  636|      0|        goto loser;
  637|       |
  638|  9.71k|    return SECSuccess;
  639|       |
  640|      0|loser:
  641|      0|    return SECFailure;
  642|  9.71k|}
ssl_ResetSecurityInfo:
  649|  19.4k|{
  650|  19.4k|    if (sec->localCert) {
  ------------------
  |  Branch (650:9): [True: 7.93k, False: 11.5k]
  ------------------
  651|  7.93k|        CERT_DestroyCertificate(sec->localCert);
  652|  7.93k|        sec->localCert = NULL;
  653|  7.93k|    }
  654|  19.4k|    if (sec->peerCert) {
  ------------------
  |  Branch (654:9): [True: 2.55k, False: 16.8k]
  ------------------
  655|  2.55k|        CERT_DestroyCertificate(sec->peerCert);
  656|  2.55k|        sec->peerCert = NULL;
  657|  2.55k|    }
  658|  19.4k|    if (sec->peerKey) {
  ------------------
  |  Branch (658:9): [True: 0, False: 19.4k]
  ------------------
  659|      0|        SECKEY_DestroyPublicKey(sec->peerKey);
  660|      0|        sec->peerKey = NULL;
  661|      0|    }
  662|       |
  663|       |    /* cleanup the ci */
  664|  19.4k|    if (sec->ci.sid != NULL) {
  ------------------
  |  Branch (664:9): [True: 7.95k, False: 11.4k]
  ------------------
  665|  7.95k|        ssl_FreeSID(sec->ci.sid);
  666|  7.95k|    }
  667|  19.4k|    PORT_ZFree(sec->ci.sendBuf.buf, sec->ci.sendBuf.space);
  ------------------
  |  |   75|  19.4k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  668|  19.4k|    if (doMemset) {
  ------------------
  |  Branch (668:9): [True: 9.71k, False: 9.71k]
  ------------------
  669|  9.71k|        memset(&sec->ci, 0, sizeof sec->ci);
  670|  9.71k|    }
  671|  19.4k|}
ssl_DestroySecurityInfo:
  680|  9.71k|{
  681|  9.71k|    ssl_ResetSecurityInfo(sec, PR_FALSE);
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
  682|       |
  683|  9.71k|    PORT_ZFree(sec->writeBuf.buf, sec->writeBuf.space);
  ------------------
  |  |   75|  9.71k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  684|  9.71k|    sec->writeBuf.buf = 0;
  685|       |
  686|  9.71k|    memset(sec, 0, sizeof *sec);
  687|  9.71k|}
ssl_SecureClose:
  732|  9.71k|{
  733|  9.71k|    int rv;
  734|       |
  735|  9.71k|    if (!(ss->shutdownHow & ssl_SHUTDOWN_SEND) &&
  ------------------
  |  |  316|  9.71k|#define ssl_SHUTDOWN_SEND 2 /* PR_SHUTDOWN_SEND +1 */
  ------------------
  |  Branch (735:9): [True: 9.71k, False: 0]
  ------------------
  736|  9.71k|        ss->firstHsDone) {
  ------------------
  |  Branch (736:9): [True: 2.62k, False: 7.09k]
  ------------------
  737|       |
  738|       |        /* We don't want the final alert to be Nagle delayed. */
  739|  2.62k|        if (!ss->delayDisabled) {
  ------------------
  |  Branch (739:13): [True: 2.62k, False: 0]
  ------------------
  740|  2.62k|            ssl_EnableNagleDelay(ss, PR_FALSE);
  ------------------
  |  |  438|  2.62k|#define PR_FALSE 0
  ------------------
  741|  2.62k|            ss->delayDisabled = 1;
  742|  2.62k|        }
  743|       |
  744|  2.62k|        (void)SSL3_SendAlert(ss, alert_warning, close_notify);
  745|  2.62k|    }
  746|  9.71k|    rv = ssl_DefClose(ss);
  747|  9.71k|    return rv;
  748|  9.71k|}
ssl_SecureRecv:
  836|   159k|{
  837|   159k|    int rv = 0;
  838|       |
  839|   159k|    if (ss->shutdownHow & ssl_SHUTDOWN_RCV) {
  ------------------
  |  |  315|   159k|#define ssl_SHUTDOWN_RCV 1  /* PR_SHUTDOWN_RCV  +1 */
  ------------------
  |  Branch (839:9): [True: 0, False: 159k]
  ------------------
  840|      0|        PORT_SetError(PR_SOCKET_SHUTDOWN_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_SOCKET_SHUTDOWN_ERROR);
  ------------------
  |  |  229|      0|#define PR_SOCKET_SHUTDOWN_ERROR                 (-5929L)
  ------------------
  841|      0|        return PR_FAILURE;
  842|      0|    }
  843|   159k|    if (flags & ~PR_MSG_PEEK) {
  ------------------
  |  | 1441|   159k|#define PR_MSG_PEEK 0x2
  ------------------
  |  Branch (843:9): [True: 0, False: 159k]
  ------------------
  844|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  845|      0|        return PR_FAILURE;
  846|      0|    }
  847|       |
  848|   159k|    if (!ssl_SocketIsBlocking(ss) && !ss->opt.fdx) {
  ------------------
  |  Branch (848:9): [True: 159k, False: 0]
  |  Branch (848:38): [True: 159k, False: 0]
  ------------------
  849|   159k|        ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|   159k|    {                                           \
  |  | 1467|   159k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 81.3k, False: 78.1k]
  |  |  ------------------
  |  | 1468|   159k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  81.3k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|   159k|    }
  ------------------
  850|   159k|        if (ss->pendingBuf.len != 0) {
  ------------------
  |  Branch (850:13): [True: 0, False: 159k]
  ------------------
  851|      0|            rv = ssl_SendSavedWriteData(ss);
  852|      0|            if ((rv < 0) && (PORT_GetError() != PR_WOULD_BLOCK_ERROR)) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
                          if ((rv < 0) && (PORT_GetError() != PR_WOULD_BLOCK_ERROR)) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (852:17): [True: 0, False: 0]
  |  Branch (852:29): [True: 0, False: 0]
  ------------------
  853|      0|                ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
  854|      0|                return SECFailure;
  855|      0|            }
  856|      0|        }
  857|   159k|        ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|   159k|    {                                          \
  |  | 1472|   159k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 81.3k, False: 78.1k]
  |  |  ------------------
  |  | 1473|   159k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  81.3k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|   159k|    }
  ------------------
  858|   159k|    }
  859|       |
  860|   159k|    rv = 0;
  861|   159k|    if (!PR_CLIST_IS_EMPTY(&ss->ssl3.hs.bufferedEarlyData)) {
  ------------------
  |  |   94|   159k|    ((_l)->next == (_l))
  ------------------
  |  Branch (861:9): [True: 0, False: 159k]
  ------------------
  862|      0|        PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  863|      0|        return tls13_Read0RttData(ss, buf, len);
  864|      0|    }
  865|       |
  866|       |    /* If any of these is non-zero, the initial handshake is not done. */
  867|   159k|    if (!ss->firstHsDone) {
  ------------------
  |  Branch (867:9): [True: 0, False: 159k]
  ------------------
  868|      0|        ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|      0|    {                                                             \
  |  | 1391|      0|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1392|      0|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|      0|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|      0|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|      0|        }                                                         \
  |  | 1396|      0|    }
  ------------------
  869|      0|        if (ss->handshake) {
  ------------------
  |  Branch (869:13): [True: 0, False: 0]
  ------------------
  870|      0|            rv = ssl_Do1stHandshake(ss);
  871|      0|        }
  872|      0|        ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|      0|    {                                                 \
  |  | 1399|      0|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1400|      0|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|      0|    }
  ------------------
  873|   159k|    } else {
  874|   159k|        if (tls13_CheckKeyUpdate(ss, ssl_secret_read) != SECSuccess) {
  ------------------
  |  Branch (874:13): [True: 0, False: 159k]
  ------------------
  875|      0|            rv = PR_FAILURE;
  876|      0|        }
  877|   159k|    }
  878|   159k|    if (rv < 0) {
  ------------------
  |  Branch (878:9): [True: 0, False: 159k]
  ------------------
  879|      0|        if (PORT_GetError() == PR_WOULD_BLOCK_ERROR &&
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
                      if (PORT_GetError() == PR_WOULD_BLOCK_ERROR &&
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (879:13): [True: 0, False: 0]
  ------------------
  880|      0|            !PR_CLIST_IS_EMPTY(&ss->ssl3.hs.bufferedEarlyData)) {
  ------------------
  |  |   94|      0|    ((_l)->next == (_l))
  ------------------
  |  Branch (880:13): [True: 0, False: 0]
  ------------------
  881|      0|            PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  882|      0|            return tls13_Read0RttData(ss, buf, len);
  883|      0|        }
  884|      0|        return rv;
  885|      0|    }
  886|       |
  887|   159k|    if (len == 0)
  ------------------
  |  Branch (887:9): [True: 0, False: 159k]
  ------------------
  888|      0|        return 0;
  889|       |
  890|   159k|    rv = DoRecv(ss, (unsigned char *)buf, len, flags);
  891|   159k|    SSL_TRC(2, ("%d: SSL[%d]: recving %d bytes securely (errno=%d)",
  ------------------
  |  |   71|   159k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 159k]
  |  |  ------------------
  |  |   72|   159k|    ssl_Trace b
  ------------------
  892|   159k|                SSL_GETPID(), ss->fd, rv, PORT_GetError()));
  893|   159k|    return rv;
  894|   159k|}
ssl_SecureRead:
  898|   159k|{
  899|   159k|    return ssl_SecureRecv(ss, buf, len, 0);
  900|   159k|}
ssl_SecureSend:
  905|   156k|{
  906|   156k|    int rv = 0;
  907|   156k|    PRBool zeroRtt = PR_FALSE;
  ------------------
  |  |  438|   156k|#define PR_FALSE 0
  ------------------
  908|       |
  909|   156k|    SSL_TRC(2, ("%d: SSL[%d]: SecureSend: sending %d bytes",
  ------------------
  |  |   71|   156k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 156k]
  |  |  ------------------
  |  |   72|   156k|    ssl_Trace b
  ------------------
  910|   156k|                SSL_GETPID(), ss->fd, len));
  911|       |
  912|   156k|    if (ss->shutdownHow & ssl_SHUTDOWN_SEND) {
  ------------------
  |  |  316|   156k|#define ssl_SHUTDOWN_SEND 2 /* PR_SHUTDOWN_SEND +1 */
  ------------------
  |  Branch (912:9): [True: 0, False: 156k]
  ------------------
  913|      0|        PORT_SetError(PR_SOCKET_SHUTDOWN_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_SOCKET_SHUTDOWN_ERROR);
  ------------------
  |  |  229|      0|#define PR_SOCKET_SHUTDOWN_ERROR                 (-5929L)
  ------------------
  914|      0|        rv = PR_FAILURE;
  915|      0|        goto done;
  916|      0|    }
  917|   156k|    if (flags) {
  ------------------
  |  Branch (917:9): [True: 0, False: 156k]
  ------------------
  918|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
  919|      0|        rv = PR_FAILURE;
  920|      0|        goto done;
  921|      0|    }
  922|       |
  923|   156k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|   156k|    {                                           \
  |  | 1467|   156k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 79.9k, False: 76.8k]
  |  |  ------------------
  |  | 1468|   156k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  79.9k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|   156k|    }
  ------------------
  924|   156k|    if (ss->pendingBuf.len != 0) {
  ------------------
  |  Branch (924:9): [True: 0, False: 156k]
  ------------------
  925|      0|        PORT_Assert(ss->pendingBuf.len > 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  926|      0|        rv = ssl_SendSavedWriteData(ss);
  927|      0|        if (rv >= 0 && ss->pendingBuf.len != 0) {
  ------------------
  |  Branch (927:13): [True: 0, False: 0]
  |  Branch (927:24): [True: 0, False: 0]
  ------------------
  928|      0|            PORT_Assert(ss->pendingBuf.len > 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  929|      0|            PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  930|      0|            rv = SECFailure;
  931|      0|        }
  932|      0|    }
  933|   156k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|   156k|    {                                          \
  |  | 1472|   156k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 79.9k, False: 76.8k]
  |  |  ------------------
  |  | 1473|   156k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  79.9k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|   156k|    }
  ------------------
  934|   156k|    if (rv < 0) {
  ------------------
  |  Branch (934:9): [True: 0, False: 156k]
  ------------------
  935|      0|        goto done;
  936|      0|    }
  937|       |
  938|   156k|    if (len > 0)
  ------------------
  |  Branch (938:9): [True: 156k, False: 0]
  ------------------
  939|   156k|        ss->writerThread = PR_GetCurrentThread();
  940|       |
  941|       |    /* Check to see if we can write even though we're not finished.
  942|       |     *
  943|       |     * Case 1: False start
  944|       |     * Case 2: TLS 1.3 0-RTT
  945|       |     */
  946|   156k|    if (!ss->firstHsDone) {
  ------------------
  |  Branch (946:9): [True: 0, False: 156k]
  ------------------
  947|      0|        PRBool allowEarlySend = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  948|      0|        PRBool firstClientWrite = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  949|       |
  950|      0|        ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|      0|    {                                                             \
  |  | 1391|      0|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1392|      0|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|      0|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|      0|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|      0|        }                                                         \
  |  | 1396|      0|    }
  ------------------
  951|       |        /* The client can sometimes send before the handshake is fully
  952|       |         * complete. In TLS 1.2: false start; in TLS 1.3: 0-RTT. */
  953|      0|        if (!ss->sec.isServer &&
  ------------------
  |  Branch (953:13): [True: 0, False: 0]
  ------------------
  954|      0|            (ss->opt.enableFalseStart || ss->opt.enable0RttData)) {
  ------------------
  |  Branch (954:14): [True: 0, False: 0]
  |  Branch (954:42): [True: 0, False: 0]
  ------------------
  955|      0|            ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|      0|    {                                                 \
  |  | 1408|      0|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1409|      0|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|      0|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|      0|        }                                             \
  |  | 1412|      0|    }
  ------------------
  956|      0|            zeroRtt = ss->ssl3.hs.zeroRttState == ssl_0rtt_sent ||
  ------------------
  |  Branch (956:23): [True: 0, False: 0]
  ------------------
  957|      0|                      ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted;
  ------------------
  |  Branch (957:23): [True: 0, False: 0]
  ------------------
  958|      0|            allowEarlySend = ss->ssl3.hs.canFalseStart || zeroRtt;
  ------------------
  |  Branch (958:30): [True: 0, False: 0]
  |  Branch (958:59): [True: 0, False: 0]
  ------------------
  959|      0|            firstClientWrite = ss->ssl3.hs.ws == idle_handshake;
  960|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  961|      0|        }
  962|       |        /* Allow the server to send 0.5 RTT data in TLS 1.3. Requesting a
  963|       |         * certificate implies that the server might condition its sending on
  964|       |         * client authentication, so force servers that do that to wait.
  965|       |         *
  966|       |         * What might not be obvious here is that this allows 0.5 RTT when doing
  967|       |         * PSK-based resumption.  As a result, 0.5 RTT is always enabled when
  968|       |         * early data is accepted.
  969|       |         *
  970|       |         * This check might be more conservative than absolutely necessary.
  971|       |         * It's possible that allowing 0.5 RTT data when the server requests,
  972|       |         * but does not require client authentication is safe because we can
  973|       |         * expect the server to check for a client certificate properly. */
  974|      0|        if (ss->sec.isServer &&
  ------------------
  |  Branch (974:13): [True: 0, False: 0]
  ------------------
  975|      0|            ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (975:13): [True: 0, False: 0]
  ------------------
  976|      0|            !tls13_ShouldRequestClientAuth(ss)) {
  ------------------
  |  Branch (976:13): [True: 0, False: 0]
  ------------------
  977|      0|            ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|      0|    {                                                 \
  |  | 1408|      0|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1409|      0|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|      0|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|      0|        }                                             \
  |  | 1412|      0|    }
  ------------------
  978|      0|            allowEarlySend = TLS13_IN_HS_STATE(ss, wait_finished);
  ------------------
  |  |   44|      0|    tls13_InHsState(ss, __VA_ARGS__, wait_invalid)
  ------------------
  979|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  980|      0|        }
  981|      0|        if (!allowEarlySend && ss->handshake) {
  ------------------
  |  Branch (981:13): [True: 0, False: 0]
  |  Branch (981:32): [True: 0, False: 0]
  ------------------
  982|      0|            rv = ssl_Do1stHandshake(ss);
  983|      0|        }
  984|      0|        if (firstClientWrite) {
  ------------------
  |  Branch (984:13): [True: 0, False: 0]
  ------------------
  985|       |            /* Wait until after sending ClientHello and double-check 0-RTT. */
  986|      0|            ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|      0|    {                                                 \
  |  | 1408|      0|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1409|      0|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|      0|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|      0|        }                                             \
  |  | 1412|      0|    }
  ------------------
  987|      0|            zeroRtt = ss->ssl3.hs.zeroRttState == ssl_0rtt_sent ||
  ------------------
  |  Branch (987:23): [True: 0, False: 0]
  ------------------
  988|      0|                      ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted;
  ------------------
  |  Branch (988:23): [True: 0, False: 0]
  ------------------
  989|      0|            ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  990|      0|        }
  991|      0|        ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|      0|    {                                                 \
  |  | 1399|      0|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1400|      0|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|      0|    }
  ------------------
  992|      0|    }
  993|       |
  994|   156k|    if (rv < 0) {
  ------------------
  |  Branch (994:9): [True: 0, False: 156k]
  ------------------
  995|      0|        ss->writerThread = NULL;
  996|      0|        goto done;
  997|      0|    }
  998|       |
  999|   156k|    if (ss->firstHsDone) {
  ------------------
  |  Branch (999:9): [True: 156k, False: 0]
  ------------------
 1000|   156k|        if (tls13_CheckKeyUpdate(ss, ssl_secret_write) != SECSuccess) {
  ------------------
  |  Branch (1000:13): [True: 0, False: 156k]
  ------------------
 1001|      0|            rv = PR_FAILURE;
 1002|      0|            goto done;
 1003|      0|        }
 1004|   156k|    }
 1005|       |
 1006|   156k|    if (zeroRtt) {
  ------------------
  |  Branch (1006:9): [True: 0, False: 156k]
  ------------------
 1007|       |        /* There's a limit to the number of early data octets we can send.
 1008|       |         *
 1009|       |         * Note that taking this lock doesn't prevent the cipher specs from
 1010|       |         * being changed out between here and when records are ultimately
 1011|       |         * encrypted.  The only effect of that is to occasionally do an
 1012|       |         * unnecessary short write when data is identified as 0-RTT here but
 1013|       |         * 1-RTT later.
 1014|       |         */
 1015|      0|        ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|      0|    {                                           \
  |  | 1423|      0|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1424|      0|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|      0|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|      0|    }
  ------------------
 1016|      0|        len = tls13_LimitEarlyData(ss, ssl_ct_application_data, len);
 1017|      0|        ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|      0|    {                                             \
  |  | 1428|      0|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1429|      0|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|      0|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|      0|    }
  ------------------
 1018|      0|    }
 1019|       |
 1020|       |    /* Check for zero length writes after we do housekeeping so we make forward
 1021|       |     * progress.
 1022|       |     */
 1023|   156k|    if (len == 0) {
  ------------------
  |  Branch (1023:9): [True: 0, False: 156k]
  ------------------
 1024|      0|        rv = 0;
 1025|      0|        goto done;
 1026|      0|    }
 1027|   156k|    PORT_Assert(buf != NULL);
  ------------------
  |  |  120|   156k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   156k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 156k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1028|   156k|    if (!buf) {
  ------------------
  |  Branch (1028:9): [True: 0, False: 156k]
  ------------------
 1029|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
 1030|      0|        rv = PR_FAILURE;
 1031|      0|        goto done;
 1032|      0|    }
 1033|       |
 1034|   156k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|   156k|    {                                           \
  |  | 1467|   156k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 79.9k, False: 76.8k]
  |  |  ------------------
  |  | 1468|   156k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  79.9k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|   156k|    }
  ------------------
 1035|   156k|    rv = ssl3_SendApplicationData(ss, buf, len, flags);
 1036|   156k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|   156k|    {                                          \
  |  | 1472|   156k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 79.9k, False: 76.8k]
  |  |  ------------------
  |  | 1473|   156k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  79.9k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|   156k|    }
  ------------------
 1037|   156k|    ss->writerThread = NULL;
 1038|   156k|done:
 1039|   156k|    if (rv < 0) {
  ------------------
  |  Branch (1039:9): [True: 0, False: 156k]
  ------------------
 1040|      0|        SSL_TRC(2, ("%d: SSL[%d]: SecureSend: returning %d count, error %d",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 1041|      0|                    SSL_GETPID(), ss->fd, rv, PORT_GetError()));
 1042|   156k|    } else {
 1043|   156k|        SSL_TRC(2, ("%d: SSL[%d]: SecureSend: returning %d count",
  ------------------
  |  |   71|   156k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 156k]
  |  |  ------------------
  |  |   72|   156k|    ssl_Trace b
  ------------------
 1044|   156k|                    SSL_GETPID(), ss->fd, rv));
 1045|   156k|    }
 1046|   156k|    return rv;
 1047|   156k|}
ssl_SecureWrite:
 1051|   156k|{
 1052|   156k|    return ssl_SecureSend(ss, buf, len, 0);
 1053|   156k|}
SSL_SetURL:
 1145|  9.71k|{
 1146|  9.71k|    sslSocket *ss = ssl_FindSocket(fd);
 1147|  9.71k|    SECStatus rv = SECSuccess;
 1148|       |
 1149|  9.71k|    if (!ss) {
  ------------------
  |  Branch (1149:9): [True: 0, False: 9.71k]
  ------------------
 1150|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in SSLSetURL",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 1151|      0|                 SSL_GETPID(), fd));
 1152|      0|        return SECFailure;
 1153|      0|    }
 1154|  9.71k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  9.71k|    {                                                             \
  |  | 1391|  9.71k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1392|  9.71k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 9.71k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 9.71k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  9.71k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  9.71k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  9.71k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  9.71k|        }                                                         \
  |  | 1396|  9.71k|    }
  ------------------
 1155|  9.71k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  9.71k|    {                                                 \
  |  | 1408|  9.71k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1409|  9.71k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  9.71k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  9.71k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  9.71k|        }                                             \
  |  | 1412|  9.71k|    }
  ------------------
 1156|       |
 1157|  9.71k|    if (ss->url) {
  ------------------
  |  Branch (1157:9): [True: 0, False: 9.71k]
  ------------------
 1158|      0|        PORT_Free((void *)ss->url); /* CONST */
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1159|      0|    }
 1160|       |
 1161|  9.71k|    ss->url = (const char *)PORT_Strdup(url);
  ------------------
  |  |   69|  9.71k|#define PORT_Strdup PORT_Strdup_Util
  ------------------
 1162|  9.71k|    if (ss->url == NULL) {
  ------------------
  |  Branch (1162:9): [True: 0, False: 9.71k]
  ------------------
 1163|      0|        rv = SECFailure;
 1164|      0|    }
 1165|       |
 1166|  9.71k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  9.71k|    {                                                \
  |  | 1415|  9.71k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1416|  9.71k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  9.71k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  9.71k|    }
  ------------------
 1167|  9.71k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  9.71k|    {                                                 \
  |  | 1399|  9.71k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1400|  9.71k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  9.71k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  9.71k|    }
  ------------------
 1168|       |
 1169|  9.71k|    return rv;
 1170|  9.71k|}
sslsecur.c:tls13_CheckKeyUpdate:
  781|   316k|{
  782|   316k|    PRBool keyUpdate;
  783|   316k|    ssl3CipherSpec *spec;
  784|   316k|    sslSequenceNumber seqNum;
  785|   316k|    sslSequenceNumber margin;
  786|   316k|    tls13KeyUpdateRequest keyUpdateRequest;
  787|   316k|    SECStatus rv = SECSuccess;
  788|       |
  789|   316k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|   316k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (789:9): [True: 8.39k, False: 307k]
  ------------------
  790|  8.39k|        return SECSuccess;
  791|  8.39k|    }
  792|       |
  793|       |    /* If both sides update at the same number, then this will cause two updates
  794|       |     * to happen at once. The problem is that the KeyUpdate itself consumes a
  795|       |     * sequence number, and that will trigger the reading side to request an
  796|       |     * update.
  797|       |     *
  798|       |     * If we have the writing side update first, the writer will be the one that
  799|       |     * drives the update.  An update by the writer doesn't need a response, so
  800|       |     * it is more efficient overall.  The margins here are pretty arbitrary, but
  801|       |     * having the write margin larger reduces the number of times that a
  802|       |     * KeyUpdate is sent by a reader. */
  803|   307k|    ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|   307k|    {                                           \
  |  | 1423|   307k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 157k, False: 150k]
  |  |  ------------------
  |  | 1424|   307k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|   157k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|   307k|    }
  ------------------
  804|   307k|    if (dir == ssl_secret_read) {
  ------------------
  |  Branch (804:9): [True: 154k, False: 153k]
  ------------------
  805|   154k|        spec = ss->ssl3.crSpec;
  806|   154k|        margin = spec->cipherDef->max_records / 8;
  807|   154k|    } else {
  808|   153k|        spec = ss->ssl3.cwSpec;
  809|   153k|        margin = spec->cipherDef->max_records / 4;
  810|   153k|    }
  811|   307k|    seqNum = spec->nextSeqNum;
  812|   307k|    keyUpdate = seqNum > spec->cipherDef->max_records - margin;
  813|   307k|    ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|   307k|    {                                             \
  |  | 1428|   307k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 157k, False: 150k]
  |  |  ------------------
  |  | 1429|   307k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|   157k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|   307k|    }
  ------------------
  814|   307k|    if (!keyUpdate) {
  ------------------
  |  Branch (814:9): [True: 307k, False: 0]
  ------------------
  815|   307k|        return SECSuccess;
  816|   307k|    }
  817|       |
  818|      0|    SSL_TRC(5, ("%d: SSL[%d]: automatic key update at %llx for %s cipher spec",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  819|      0|                SSL_GETPID(), ss->fd, seqNum,
  820|      0|                (dir == ssl_secret_read) ? "read" : "write"));
  821|      0|    keyUpdateRequest = (dir == ssl_secret_read) ? update_requested : update_not_requested;
  ------------------
  |  Branch (821:24): [True: 0, False: 0]
  ------------------
  822|      0|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|      0|    {                                                 \
  |  | 1408|      0|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1409|      0|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|      0|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|      0|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|      0|        }                                             \
  |  | 1412|      0|    }
  ------------------
  823|      0|    if (ss->ssl3.clientCertRequested) {
  ------------------
  |  Branch (823:9): [True: 0, False: 0]
  ------------------
  824|      0|        ss->ssl3.hs.keyUpdateDeferred = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  825|      0|        ss->ssl3.hs.deferredKeyUpdateRequest = keyUpdateRequest;
  826|      0|    } else {
  827|      0|        rv = tls13_SendKeyUpdate(ss, keyUpdateRequest,
  828|      0|                                 dir == ssl_secret_write /* buffer */);
  829|      0|    }
  830|      0|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
  831|      0|    return rv;
  832|   307k|}
sslsecur.c:DoRecv:
  523|   159k|{
  524|   159k|    int rv;
  525|   159k|    int amount;
  526|   159k|    int available;
  527|       |
  528|       |    /* ssl3_GatherAppDataRecord may call ssl_FinishHandshake, which needs the
  529|       |     * 1stHandshakeLock. */
  530|   159k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|   159k|    {                                                             \
  |  | 1391|   159k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 81.3k, False: 78.1k]
  |  |  ------------------
  |  | 1392|  81.3k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  81.3k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   162k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 81.3k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 81.3k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  81.3k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  81.3k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  81.3k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  81.3k|        }                                                         \
  |  | 1396|   159k|    }
  ------------------
  531|   159k|    ssl_GetRecvBufLock(ss);
  ------------------
  |  | 1449|   159k|    {                                                    \
  |  | 1450|   159k|        if (!ss->opt.noLocks) {                          \
  |  |  ------------------
  |  |  |  Branch (1450:13): [True: 81.3k, False: 78.1k]
  |  |  ------------------
  |  | 1451|  81.3k|            PORT_Assert(!ssl_HaveSSL3HandshakeLock(ss)); \
  |  |  ------------------
  |  |  |  |  120|  81.3k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  81.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 81.3k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1452|  81.3k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));       \
  |  |  ------------------
  |  |  |  |  120|  81.3k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  81.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 81.3k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1453|  81.3k|            PZ_EnterMonitor((ss)->recvBufLock);          \
  |  |  ------------------
  |  |  |  |  256|  81.3k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1454|  81.3k|        }                                                \
  |  | 1455|   159k|    }
  ------------------
  532|       |
  533|   159k|    available = ss->gs.writeOffset - ss->gs.readOffset;
  534|   159k|    if (available == 0) {
  ------------------
  |  Branch (534:9): [True: 159k, False: 312]
  ------------------
  535|       |        /* Wait for application data to arrive.  */
  536|   159k|        rv = ssl3_GatherAppDataRecord(ss, 0);
  537|   159k|        if (rv <= 0) {
  ------------------
  |  Branch (537:13): [True: 2.62k, False: 156k]
  ------------------
  538|  2.62k|            if (rv == 0) {
  ------------------
  |  Branch (538:17): [True: 1.59k, False: 1.02k]
  ------------------
  539|       |                /* EOF */
  540|  1.59k|                SSL_TRC(10, ("%d: SSL[%d]: ssl_recv EOF",
  ------------------
  |  |   71|  1.59k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.59k]
  |  |  ------------------
  |  |   72|  1.59k|    ssl_Trace b
  ------------------
  541|  1.59k|                             SSL_GETPID(), ss->fd));
  542|  1.59k|                goto done;
  543|  1.59k|            }
  544|  1.02k|            if (PR_GetError() != PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|  1.02k|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (544:17): [True: 1.02k, False: 0]
  ------------------
  545|       |                /* Some random error */
  546|  1.02k|                goto done;
  547|  1.02k|            }
  548|       |
  549|       |            /*
  550|       |            ** Gather record is blocked waiting for more record data to
  551|       |            ** arrive. Try to process what we have already received
  552|       |            */
  553|   156k|        } else {
  554|       |            /* Gather record has finished getting a complete record */
  555|   156k|        }
  556|       |
  557|       |        /* See if any clear data is now available */
  558|   156k|        available = ss->gs.writeOffset - ss->gs.readOffset;
  559|   156k|        if (available == 0) {
  ------------------
  |  Branch (559:13): [True: 0, False: 156k]
  ------------------
  560|       |            /*
  561|       |            ** No partial data is available. Force error code to
  562|       |            ** EWOULDBLOCK so that caller will try again later. Note
  563|       |            ** that the error code is probably EWOULDBLOCK already,
  564|       |            ** but if it isn't (for example, if we received a zero
  565|       |            ** length record) then this will force it to be correct.
  566|       |            */
  567|      0|            PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                          PORT_SetError(PR_WOULD_BLOCK_ERROR);
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  568|      0|            rv = SECFailure;
  569|      0|            goto done;
  570|      0|        }
  571|   156k|        SSL_TRC(30, ("%d: SSL[%d]: partial data ready, available=%d",
  ------------------
  |  |   71|   156k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 156k]
  |  |  ------------------
  |  |   72|   156k|    ssl_Trace b
  ------------------
  572|   156k|                     SSL_GETPID(), ss->fd, available));
  573|   156k|    }
  574|       |
  575|   156k|    if (IS_DTLS(ss) && (len < available)) {
  ------------------
  |  |  892|   313k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 156k]
  |  |  ------------------
  ------------------
  |  Branch (575:24): [True: 0, False: 0]
  ------------------
  576|       |        /* DTLS does not allow you to do partial reads */
  577|      0|        SSL_TRC(30, ("%d: SSL[%d]: DTLS short read. len=%d available=%d",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  578|      0|                     SSL_GETPID(), ss->fd, len, available));
  579|      0|        ss->gs.readOffset += available;
  580|      0|        PORT_SetError(SSL_ERROR_RX_SHORT_DTLS_READ);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  581|      0|        rv = SECFailure;
  582|      0|        goto done;
  583|      0|    }
  584|       |
  585|       |    /* Dole out clear data to reader */
  586|   156k|    amount = PR_MIN(len, available);
  ------------------
  |  |  158|   156k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 312, False: 156k]
  |  |  ------------------
  ------------------
  587|   156k|    PORT_Memcpy(out, ss->gs.buf.buf + ss->gs.readOffset, amount);
  ------------------
  |  |  180|   156k|#define PORT_Memcpy memcpy
  ------------------
  588|   156k|    if (!(flags & PR_MSG_PEEK)) {
  ------------------
  |  | 1441|   156k|#define PR_MSG_PEEK 0x2
  ------------------
  |  Branch (588:9): [True: 156k, False: 0]
  ------------------
  589|   156k|        ss->gs.readOffset += amount;
  590|   156k|    }
  591|   156k|    PORT_Assert(ss->gs.readOffset <= ss->gs.writeOffset);
  ------------------
  |  |  120|   156k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   156k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 156k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  592|   156k|    rv = amount;
  593|       |
  594|   156k|#ifdef DEBUG
  595|       |    /* In Debug builds free and zero gather plaintext buffer after its content
  596|       |     * has been used/copied for advanced ASAN coverage/utilization.
  597|       |     * This frees the buffer after reception of application data,
  598|       |     * non-application data is freed at the end of
  599|       |     * ssl3con.c/ssl3_HandleRecord(). */
  600|   156k|    if (ss->gs.writeOffset == ss->gs.readOffset) {
  ------------------
  |  Branch (600:9): [True: 156k, False: 312]
  ------------------
  601|   156k|        sslBuffer_Clear(&ss->gs.buf);
  602|   156k|    }
  603|   156k|#endif
  604|       |
  605|   156k|    SSL_TRC(30, ("%d: SSL[%d]: amount=%d available=%d",
  ------------------
  |  |   71|   156k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 156k]
  |  |  ------------------
  |  |   72|   156k|    ssl_Trace b
  ------------------
  606|   156k|                 SSL_GETPID(), ss->fd, amount, available));
  607|   156k|    PRINT_BUF(4, (ss, "DoRecv receiving plaintext:", out, amount));
  ------------------
  |  |   74|   156k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 156k]
  |  |  ------------------
  |  |   75|   156k|    ssl_PrintBuf b
  ------------------
  608|       |
  609|   159k|done:
  610|   159k|    ssl_ReleaseRecvBufLock(ss);
  ------------------
  |  | 1457|   159k|    {                                          \
  |  | 1458|   159k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1458:13): [True: 81.3k, False: 78.1k]
  |  |  ------------------
  |  | 1459|   159k|            PZ_ExitMonitor((ss)->recvBufLock); \
  |  |  ------------------
  |  |  |  |  257|  81.3k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1460|   159k|    }
  ------------------
  611|   159k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|   159k|    {                                                 \
  |  | 1399|   159k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 81.3k, False: 78.1k]
  |  |  ------------------
  |  | 1400|   159k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  81.3k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|   159k|    }
  ------------------
  612|   159k|    return rv;
  613|   156k|}

ssl_ServerCacheSessionID:
  758|  30.3k|{
  759|  30.3k|    PORT_Assert(sid);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  760|       |
  761|  30.3k|    sidCacheEntry sce;
  762|  30.3k|    PRUint32 now = 0;
  763|  30.3k|    cacheDesc *cache = &globalCache;
  764|       |
  765|  30.3k|    if (sid->u.ssl3.sessionIDLength == 0) {
  ------------------
  |  Branch (765:9): [True: 0, False: 30.3k]
  ------------------
  766|      0|        return;
  767|      0|    }
  768|       |
  769|  30.3k|    if (sid->cached == never_cached || sid->cached == invalid_cache) {
  ------------------
  |  Branch (769:9): [True: 30.3k, False: 0]
  |  Branch (769:40): [True: 0, False: 0]
  ------------------
  770|  30.3k|        PRUint32 set;
  771|  30.3k|        SECItem *name;
  772|       |
  773|  30.3k|        PORT_Assert(sid->creationTime != 0);
  ------------------
  |  |  120|  30.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  30.3k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 30.3k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  774|  30.3k|        if (!sid->creationTime)
  ------------------
  |  Branch (774:13): [True: 0, False: 30.3k]
  ------------------
  775|      0|            sid->lastAccessTime = sid->creationTime = creationTime;
  776|       |        /* override caller's expiration time, which uses client timeout
  777|       |         * duration, not server timeout duration.
  778|       |         */
  779|  30.3k|        sid->expirationTime =
  780|  30.3k|            sid->creationTime + cache->ssl3Timeout * PR_USEC_PER_SEC;
  ------------------
  |  |   28|  30.3k|#define PR_USEC_PER_SEC     1000000L
  ------------------
  781|  30.3k|        SSL_TRC(8, ("%d: SSL: CacheMT: cached=%d addr=0x%08x%08x%08x%08x time=%x "
  ------------------
  |  |   71|  30.3k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 30.3k]
  |  |  ------------------
  |  |   72|  30.3k|    ssl_Trace b
  ------------------
  782|  30.3k|                    "cipherSuite=%d",
  783|  30.3k|                    myPid, sid->cached,
  784|  30.3k|                    sid->addr.pr_s6_addr32[0], sid->addr.pr_s6_addr32[1],
  785|  30.3k|                    sid->addr.pr_s6_addr32[2], sid->addr.pr_s6_addr32[3],
  786|  30.3k|                    sid->creationTime / PR_USEC_PER_SEC,
  787|  30.3k|                    sid->u.ssl3.cipherSuite));
  788|  30.3k|        PRINT_BUF(8, (0, "sessionID:", sid->u.ssl3.sessionID,
  ------------------
  |  |   74|  30.3k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 30.3k]
  |  |  ------------------
  |  |   75|  30.3k|    ssl_PrintBuf b
  ------------------
  789|  30.3k|                      sid->u.ssl3.sessionIDLength));
  790|       |
  791|  30.3k|        ConvertFromSID(&sce, sid);
  792|       |
  793|  30.3k|        name = &sid->u.ssl3.srvName;
  794|  30.3k|        if (name->len && name->data) {
  ------------------
  |  Branch (794:13): [True: 0, False: 30.3k]
  |  Branch (794:26): [True: 0, False: 0]
  ------------------
  795|      0|            now = CacheSrvName(cache, name, &sce);
  796|      0|        }
  797|  30.3k|        if (sid->peerCert != NULL) {
  ------------------
  |  Branch (797:13): [True: 797, False: 29.5k]
  ------------------
  798|    797|            now = CacheCert(cache, sid->peerCert, &sce);
  799|    797|        }
  800|       |
  801|  30.3k|        set = SIDindex(cache, &sce.addr, sce.sessionID, sce.sessionIDLength);
  802|  30.3k|        now = LockSet(cache, set, now);
  803|  30.3k|        if (now) {
  ------------------
  |  Branch (803:13): [True: 30.3k, False: 0]
  ------------------
  804|  30.3k|            PRUint32 next = cache->sidCacheSets[set].next;
  805|  30.3k|            PRUint32 ndx = set * SID_CACHE_ENTRIES_PER_SET + next;
  ------------------
  |  |  231|  30.3k|#define SID_CACHE_ENTRIES_PER_SET 128
  ------------------
  806|       |
  807|       |            /* Write out new cache entry */
  808|  30.3k|            cache->sidCacheData[ndx] = sce;
  809|       |
  810|  30.3k|            cache->sidCacheSets[set].next =
  811|  30.3k|                (next + 1) % SID_CACHE_ENTRIES_PER_SET;
  ------------------
  |  |  231|  30.3k|#define SID_CACHE_ENTRIES_PER_SET 128
  ------------------
  812|       |
  813|  30.3k|            UnlockSet(cache, set);
  814|  30.3k|            sid->cached = in_server_cache;
  815|  30.3k|        }
  816|  30.3k|    }
  817|  30.3k|}
ssl_ServerUncacheSessionID:
  825|  1.36k|{
  826|  1.36k|    cacheDesc *cache = &globalCache;
  827|  1.36k|    PRUint8 *sessionID;
  828|  1.36k|    unsigned int sessionIDLength;
  829|  1.36k|    PRErrorCode err;
  830|  1.36k|    PRUint32 set;
  831|  1.36k|    PRUint32 now;
  832|  1.36k|    sidCacheEntry *psce;
  833|       |
  834|  1.36k|    if (sid == NULL)
  ------------------
  |  Branch (834:9): [True: 0, False: 1.36k]
  ------------------
  835|      0|        return;
  836|       |
  837|       |    /* Uncaching a SID should never change the error code.
  838|       |    ** So save it here and restore it before exiting.
  839|       |    */
  840|  1.36k|    err = PR_GetError();
  841|       |
  842|  1.36k|    sessionID = sid->u.ssl3.sessionID;
  843|  1.36k|    sessionIDLength = sid->u.ssl3.sessionIDLength;
  844|  1.36k|    SSL_TRC(8, ("%d: SSL3: UncacheMT: valid=%d addr=0x%08x%08x%08x%08x time=%x "
  ------------------
  |  |   71|  1.36k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   72|  1.36k|    ssl_Trace b
  ------------------
  845|  1.36k|                "cipherSuite=%d",
  846|  1.36k|                myPid, sid->cached,
  847|  1.36k|                sid->addr.pr_s6_addr32[0], sid->addr.pr_s6_addr32[1],
  848|  1.36k|                sid->addr.pr_s6_addr32[2], sid->addr.pr_s6_addr32[3],
  849|  1.36k|                sid->creationTime / PR_USEC_PER_SEC,
  850|  1.36k|                sid->u.ssl3.cipherSuite));
  851|  1.36k|    PRINT_BUF(8, (0, "sessionID:", sessionID, sessionIDLength));
  ------------------
  |  |   74|  1.36k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   75|  1.36k|    ssl_PrintBuf b
  ------------------
  852|  1.36k|    set = SIDindex(cache, &sid->addr, sessionID, sessionIDLength);
  853|  1.36k|    now = LockSet(cache, set, 0);
  854|  1.36k|    if (now) {
  ------------------
  |  Branch (854:9): [True: 1.36k, False: 0]
  ------------------
  855|  1.36k|        psce = FindSID(cache, set, now, &sid->addr, sessionID, sessionIDLength);
  856|  1.36k|        if (psce) {
  ------------------
  |  Branch (856:13): [True: 986, False: 381]
  ------------------
  857|    986|            psce->valid = 0;
  858|    986|        }
  859|  1.36k|        UnlockSet(cache, set);
  860|  1.36k|    }
  861|  1.36k|    sid->cached = invalid_cache;
  862|  1.36k|    PORT_SetError(err);
  ------------------
  |  |   65|  1.36k|#define PORT_SetError PORT_SetError_Util
  ------------------
  863|  1.36k|}
SSL_ConfigServerSessionIDCacheInstance:
 1186|      1|{
 1187|      1|    return ssl_ConfigServerSessionIDCacheInstanceWithOpt(cache,
 1188|      1|                                                         ssl3_timeout,
 1189|      1|                                                         directory,
 1190|      1|                                                         shared,
 1191|      1|                                                         maxCacheEntries,
 1192|      1|                                                         -1, -1);
 1193|      1|}
SSL_ConfigServerSessionIDCache:
 1200|      1|{
 1201|      1|    ssl_InitSessionCacheLocks(PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1202|      1|    return SSL_ConfigServerSessionIDCacheInstance(&globalCache,
 1203|      1|                                                  maxCacheEntries, ssl2_timeout, ssl3_timeout, directory, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1204|      1|}
SSL_ShutdownServerSessionIDCacheInstance:
 1208|      1|{
 1209|      1|    CloseCache(cache);
 1210|      1|    return SECSuccess;
 1211|      1|}
SSL_ShutdownServerSessionIDCache:
 1215|      1|{
 1216|      1|#if defined(XP_UNIX)
 1217|       |    /* Stop the thread that polls cache for expired locks on Unix */
 1218|      1|    StopLockPoller(&globalCache);
 1219|      1|#endif
 1220|      1|    SSL3_ShutdownServerCache();
 1221|      1|    return SSL_ShutdownServerSessionIDCacheInstance(&globalCache);
 1222|      1|}
ssl_ResetSelfEncryptKeys:
 1645|      1|{
 1646|      1|    if (ssl_self_encrypt_keys.encKey) {
  ------------------
  |  Branch (1646:9): [True: 1, False: 0]
  ------------------
 1647|      1|        PORT_Assert(ssl_self_encrypt_keys.macKey);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1648|      1|        PK11_FreeSymKey(ssl_self_encrypt_keys.encKey);
 1649|      1|        PK11_FreeSymKey(ssl_self_encrypt_keys.macKey);
 1650|      1|    }
 1651|      1|    PORT_Memset(&ssl_self_encrypt_keys, 0,
  ------------------
  |  |  182|      1|#define PORT_Memset memset
  ------------------
 1652|      1|                sizeof(ssl_self_encrypt_keys));
 1653|      1|}
ssl_MaybeSetSelfEncryptKeyPair:
 1746|      1|{
 1747|      1|    PRBool configured;
 1748|       |
 1749|      1|    if (PR_SUCCESS != PR_CallOnce(&ssl_self_encrypt_key_pair.setup,
  ------------------
  |  Branch (1749:9): [True: 0, False: 1]
  ------------------
 1750|      1|                                  &ssl_SelfEncryptSetup)) {
 1751|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1752|      0|        return SECFailure;
 1753|      0|    }
 1754|       |
 1755|      1|    PR_RWLock_Rlock(ssl_self_encrypt_key_pair.lock);
 1756|      1|    configured = ssl_self_encrypt_key_pair.configured;
 1757|      1|    PR_RWLock_Unlock(ssl_self_encrypt_key_pair.lock);
 1758|      1|    if (configured) {
  ------------------
  |  Branch (1758:9): [True: 0, False: 1]
  ------------------
 1759|      0|        return SECSuccess;
 1760|      0|    }
 1761|      1|    return ssl_SetSelfEncryptKeyPair(keyPair->pubKey,
 1762|      1|                                     keyPair->privKey, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1763|      1|}
ssl_GetSelfEncryptKeys:
 1833|  4.20k|{
 1834|  4.20k|    if (PR_SUCCESS != PR_CallOnceWithArg(&ssl_self_encrypt_keys.setup,
  ------------------
  |  Branch (1834:9): [True: 0, False: 4.20k]
  ------------------
 1835|  4.20k|                                         &ssl_GenerateSelfEncryptKeysOnce,
 1836|  4.20k|                                         ss->pkcs11PinArg)) {
 1837|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1838|      0|        return SECFailure;
 1839|      0|    }
 1840|       |
 1841|  4.20k|    if (!ssl_self_encrypt_keys.encKey || !ssl_self_encrypt_keys.macKey) {
  ------------------
  |  Branch (1841:9): [True: 0, False: 4.20k]
  |  Branch (1841:42): [True: 0, False: 4.20k]
  ------------------
 1842|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1843|      0|        return SECFailure;
 1844|      0|    }
 1845|       |
 1846|  4.20k|    PORT_Memcpy(keyName, ssl_self_encrypt_keys.keyName,
  ------------------
  |  |  180|  4.20k|#define PORT_Memcpy memcpy
  ------------------
 1847|  4.20k|                sizeof(ssl_self_encrypt_keys.keyName));
 1848|  4.20k|    *encKey = ssl_self_encrypt_keys.encKey;
 1849|  4.20k|    *macKey = ssl_self_encrypt_keys.macKey;
 1850|  4.20k|    return SECSuccess;
 1851|  4.20k|}
ssl_GetWrappingKey:
 1896|      2|{
 1897|      2|    PORT_Assert(wrapMechIndex < SSL_NUM_WRAP_MECHS);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1898|      2|    PORT_Assert(wrapKeyIndex < SSL_NUM_WRAP_KEYS);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1899|      2|    if (wrapMechIndex >= SSL_NUM_WRAP_MECHS ||
  ------------------
  |  |  115|      4|#define SSL_NUM_WRAP_MECHS 15
  ------------------
  |  Branch (1899:9): [True: 0, False: 2]
  ------------------
 1900|      2|        wrapKeyIndex >= SSL_NUM_WRAP_KEYS) {
  ------------------
  |  |  116|      2|#define SSL_NUM_WRAP_KEYS 6
  ------------------
  |  Branch (1900:9): [True: 0, False: 2]
  ------------------
 1901|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1902|      0|        return SECFailure;
 1903|      0|    }
 1904|       |
 1905|      2|    return getSvrWrappingKey(wrapMechIndex, wrapKeyIndex, wswk,
 1906|      2|                             &globalCache, 0);
 1907|      2|}
ssl_SetWrappingKey:
 2122|      2|{
 2123|      2|    cacheDesc *cache = &globalCache;
 2124|      2|    PRBool rv = SECFailure;
 2125|      2|    PRUint32 ndx;
 2126|      2|    PRUint32 now;
 2127|      2|    SSLWrappedSymWrappingKey myWswk;
 2128|       |
 2129|      2|    if (!cache->cacheMem) { /* cache is uninitialized */
  ------------------
  |  Branch (2129:9): [True: 0, False: 2]
  ------------------
 2130|      0|        PORT_SetError(SSL_ERROR_SERVER_CACHE_NOT_CONFIGURED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2131|      0|        return SECFailure;
 2132|      0|    }
 2133|       |
 2134|      2|    PORT_Assert(wswk->wrapMechIndex < SSL_NUM_WRAP_MECHS);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2135|      2|    PORT_Assert(wswk->wrapKeyIndex < SSL_NUM_WRAP_KEYS);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2136|      2|    if (wswk->wrapMechIndex >= SSL_NUM_WRAP_MECHS ||
  ------------------
  |  |  115|      4|#define SSL_NUM_WRAP_MECHS 15
  ------------------
  |  Branch (2136:9): [True: 0, False: 2]
  ------------------
 2137|      2|        wswk->wrapKeyIndex >= SSL_NUM_WRAP_KEYS) {
  ------------------
  |  |  116|      2|#define SSL_NUM_WRAP_KEYS 6
  ------------------
  |  Branch (2137:9): [True: 0, False: 2]
  ------------------
 2138|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2139|      0|        return SECFailure;
 2140|      0|    }
 2141|       |
 2142|      2|    ndx = (wswk->wrapKeyIndex * SSL_NUM_WRAP_MECHS) + wswk->wrapMechIndex;
  ------------------
  |  |  115|      2|#define SSL_NUM_WRAP_MECHS 15
  ------------------
 2143|      2|    PORT_Memset(&myWswk, 0, sizeof myWswk); /* eliminate UMRs. */
  ------------------
  |  |  182|      2|#define PORT_Memset memset
  ------------------
 2144|       |
 2145|      2|    now = LockSidCacheLock(cache->keyCacheLock, 0);
 2146|      2|    if (!now) {
  ------------------
  |  Branch (2146:9): [True: 0, False: 2]
  ------------------
 2147|      0|        return SECFailure;
 2148|      0|    }
 2149|      2|    rv = getSvrWrappingKey(wswk->wrapMechIndex, wswk->wrapKeyIndex,
 2150|      2|                           &myWswk, cache, now);
 2151|      2|    if (rv == SECSuccess) {
  ------------------
  |  Branch (2151:9): [True: 0, False: 2]
  ------------------
 2152|       |        /* we found it on disk, copy it out to the caller. */
 2153|      0|        PORT_Memcpy(wswk, &myWswk, sizeof *wswk);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 2154|      2|    } else {
 2155|       |        /* Wasn't on disk, and we're still holding the lock, so write it. */
 2156|      2|        cache->keyCacheData[ndx] = *wswk;
 2157|      2|    }
 2158|      2|    UnlockSidCacheLock(cache->keyCacheLock);
 2159|      2|    return rv;
 2160|      2|}
sslsnce.c:ConvertFromSID:
  446|  30.3k|{
  447|  30.3k|    to->valid = 1;
  448|  30.3k|    to->version = from->version;
  449|  30.3k|    to->addr = from->addr;
  450|  30.3k|    to->creationTime = from->creationTime;
  451|  30.3k|    to->lastAccessTime = from->lastAccessTime;
  452|  30.3k|    to->expirationTime = from->expirationTime;
  453|  30.3k|    to->authType = from->authType;
  454|  30.3k|    to->authKeyBits = from->authKeyBits;
  455|  30.3k|    to->keaType = from->keaType;
  456|  30.3k|    to->keaKeyBits = from->keaKeyBits;
  457|  30.3k|    to->keaGroup = from->keaGroup;
  458|  30.3k|    to->signatureScheme = from->sigScheme;
  459|       |
  460|  30.3k|    to->u.ssl3.cipherSuite = from->u.ssl3.cipherSuite;
  461|  30.3k|    to->u.ssl3.keys = from->u.ssl3.keys;
  462|  30.3k|    to->u.ssl3.masterWrapMech = from->u.ssl3.masterWrapMech;
  463|  30.3k|    to->sessionIDLength = from->u.ssl3.sessionIDLength;
  464|  30.3k|    to->u.ssl3.certIndex = -1;
  465|  30.3k|    to->u.ssl3.srvNameIndex = -1;
  466|  30.3k|    PORT_Memcpy(to->sessionID, from->u.ssl3.sessionID,
  ------------------
  |  |  180|  30.3k|#define PORT_Memcpy memcpy
  ------------------
  467|  30.3k|                to->sessionIDLength);
  468|  30.3k|    to->u.ssl3.namedCurve = 0U;
  469|  30.3k|    if (from->authType == ssl_auth_ecdsa ||
  ------------------
  |  Branch (469:9): [True: 6.56k, False: 23.7k]
  ------------------
  470|  30.3k|        from->authType == ssl_auth_ecdh_rsa ||
  ------------------
  |  Branch (470:9): [True: 0, False: 23.7k]
  ------------------
  471|  30.3k|        from->authType == ssl_auth_ecdh_ecdsa) {
  ------------------
  |  Branch (471:9): [True: 1, False: 23.7k]
  ------------------
  472|  6.57k|        PORT_Assert(from->namedCurve);
  ------------------
  |  |  120|  6.57k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.57k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 6.57k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  473|  6.57k|        to->u.ssl3.namedCurve = (PRUint16)from->namedCurve->name;
  474|  6.57k|    }
  475|       |
  476|  30.3k|    SSL_TRC(8, ("%d: SSL3: ConvertSID: time=%d addr=0x%08x%08x%08x%08x "
  ------------------
  |  |   71|  30.3k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 30.3k]
  |  |  ------------------
  |  |   72|  30.3k|    ssl_Trace b
  ------------------
  477|  30.3k|                "cipherSuite=%d",
  478|  30.3k|                myPid, to->creationTime / PR_USEC_PER_SEC,
  479|  30.3k|                to->addr.pr_s6_addr32[0], to->addr.pr_s6_addr32[1],
  480|  30.3k|                to->addr.pr_s6_addr32[2], to->addr.pr_s6_addr32[3],
  481|  30.3k|                to->u.ssl3.cipherSuite));
  482|  30.3k|}
sslsnce.c:CacheCert:
  348|    797|{
  349|    797|    PRUint32 now;
  350|    797|    certCacheEntry cce;
  351|       |
  352|    797|    if ((cert->derCert.len > SSL_MAX_CACHED_CERT_LEN) ||
  ------------------
  |  |  119|    797|#define SSL_MAX_CACHED_CERT_LEN 4060
  ------------------
  |  Branch (352:9): [True: 0, False: 797]
  ------------------
  353|    797|        (cert->derCert.len <= 0) ||
  ------------------
  |  Branch (353:9): [True: 0, False: 797]
  ------------------
  354|    797|        (cert->derCert.data == NULL)) {
  ------------------
  |  Branch (354:9): [True: 0, False: 797]
  ------------------
  355|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  356|      0|        return 0;
  357|      0|    }
  358|       |
  359|    797|    cce.sessionIDLength = sce->sessionIDLength;
  360|    797|    PORT_Memcpy(cce.sessionID, sce->sessionID, cce.sessionIDLength);
  ------------------
  |  |  180|    797|#define PORT_Memcpy memcpy
  ------------------
  361|       |
  362|    797|    cce.certLength = cert->derCert.len;
  363|    797|    PORT_Memcpy(cce.cert, cert->derCert.data, cce.certLength);
  ------------------
  |  |  180|    797|#define PORT_Memcpy memcpy
  ------------------
  364|       |
  365|       |    /* get lock on cert cache */
  366|    797|    now = LockSidCacheLock(cache->certCacheLock, 0);
  367|    797|    if (now) {
  ------------------
  |  Branch (367:9): [True: 797, False: 0]
  ------------------
  368|       |
  369|       |        /* Find where to place the next cert cache entry. */
  370|    797|        cacheDesc *sharedCache = cache->sharedCache;
  371|    797|        PRUint32 ndx = sharedCache->nextCertCacheEntry;
  372|       |
  373|       |        /* write the entry */
  374|    797|        cache->certCacheData[ndx] = cce;
  375|       |
  376|       |        /* remember where we put it. */
  377|    797|        sce->u.ssl3.certIndex = ndx;
  378|       |
  379|       |        /* update the "next" cache entry index */
  380|    797|        sharedCache->nextCertCacheEntry =
  381|    797|            (ndx + 1) % cache->numCertCacheEntries;
  382|       |
  383|    797|        UnlockSidCacheLock(cache->certCacheLock);
  384|    797|    }
  385|    797|    return now;
  386|    797|}
sslsnce.c:SIDindex:
  580|  32.7k|{
  581|  32.7k|    PRUint32 rv;
  582|  32.7k|    PRUint32 x[8];
  583|       |
  584|  32.7k|    memset(x, 0, sizeof x);
  585|  32.7k|    if (nl > sizeof x)
  ------------------
  |  Branch (585:9): [True: 0, False: 32.7k]
  ------------------
  586|      0|        nl = sizeof x;
  587|  32.7k|    memcpy(x, s, nl);
  588|       |
  589|  32.7k|    rv = (addr->pr_s6_addr32[0] ^ addr->pr_s6_addr32[1] ^
  ------------------
  |  |  140|  32.7k|#define pr_s6_addr32    _S6_un._S6_u32
  ------------------
                  rv = (addr->pr_s6_addr32[0] ^ addr->pr_s6_addr32[1] ^
  ------------------
  |  |  140|  32.7k|#define pr_s6_addr32    _S6_un._S6_u32
  ------------------
  590|  32.7k|          addr->pr_s6_addr32[2] ^ addr->pr_s6_addr32[3] ^
  ------------------
  |  |  140|  32.7k|#define pr_s6_addr32    _S6_un._S6_u32
  ------------------
                        addr->pr_s6_addr32[2] ^ addr->pr_s6_addr32[3] ^
  ------------------
  |  |  140|  32.7k|#define pr_s6_addr32    _S6_un._S6_u32
  ------------------
  591|  32.7k|          x[0] ^ x[1] ^ x[2] ^ x[3] ^ x[4] ^ x[5] ^ x[6] ^ x[7]) %
  592|  32.7k|         cache->numSIDCacheSets;
  593|  32.7k|    return rv;
  594|  32.7k|}
sslsnce.c:LockSet:
  326|  32.7k|{
  327|  32.7k|    PRUint32 lockNum = set % cache->numSIDCacheLocks;
  328|  32.7k|    sidCacheLock *lock = cache->sidCacheLocks + lockNum;
  329|       |
  330|  32.7k|    return LockSidCacheLock(lock, now);
  331|  32.7k|}
sslsnce.c:UnlockSet:
  335|  32.7k|{
  336|  32.7k|    PRUint32 lockNum = set % cache->numSIDCacheLocks;
  337|  32.7k|    sidCacheLock *lock = cache->sidCacheLocks + lockNum;
  338|       |
  339|  32.7k|    return UnlockSidCacheLock(lock);
  340|  32.7k|}
sslsnce.c:FindSID:
  605|  2.37k|{
  606|  2.37k|    PRUint32 ndx = cache->sidCacheSets[setNum].next;
  607|  2.37k|    int i;
  608|       |
  609|  2.37k|    sidCacheEntry *set = cache->sidCacheData +
  610|  2.37k|                         (setNum * SID_CACHE_ENTRIES_PER_SET);
  ------------------
  |  |  231|  2.37k|#define SID_CACHE_ENTRIES_PER_SET 128
  ------------------
  611|       |
  612|   196k|    for (i = SID_CACHE_ENTRIES_PER_SET; i > 0; --i) {
  ------------------
  |  |  231|  2.37k|#define SID_CACHE_ENTRIES_PER_SET 128
  ------------------
  |  Branch (612:41): [True: 194k, False: 1.39k]
  ------------------
  613|   194k|        sidCacheEntry *sce;
  614|       |
  615|   194k|        ndx = (ndx - 1) % SID_CACHE_ENTRIES_PER_SET;
  ------------------
  |  |  231|   194k|#define SID_CACHE_ENTRIES_PER_SET 128
  ------------------
  616|   194k|        sce = set + ndx;
  617|       |
  618|   194k|        if (!sce->valid)
  ------------------
  |  Branch (618:13): [True: 52.9k, False: 141k]
  ------------------
  619|  52.9k|            continue;
  620|       |
  621|   141k|        if (now > sce->expirationTime) {
  ------------------
  |  Branch (621:13): [True: 0, False: 141k]
  ------------------
  622|       |            /* SessionID has timed out. Invalidate the entry. */
  623|      0|            SSL_TRC(7, ("%d: timed out sid entry addr=%08x%08x%08x%08x now=%x "
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  624|      0|                        "time+=%x",
  625|      0|                        myPid, sce->addr.pr_s6_addr32[0],
  626|      0|                        sce->addr.pr_s6_addr32[1], sce->addr.pr_s6_addr32[2],
  627|      0|                        sce->addr.pr_s6_addr32[3], now,
  628|      0|                        sce->expirationTime));
  629|      0|            sce->valid = 0;
  630|      0|            continue;
  631|      0|        }
  632|       |
  633|       |        /*
  634|       |        ** Next, examine specific session-id/addr data to see if the cache
  635|       |        ** entry matches our addr+session-id value
  636|       |        */
  637|   141k|        if (sessionIDLength == sce->sessionIDLength &&
  ------------------
  |  Branch (637:13): [True: 28.2k, False: 113k]
  ------------------
  638|   141k|            !memcmp(&sce->addr, addr, sizeof(PRIPv6Addr)) &&
  ------------------
  |  Branch (638:13): [True: 28.2k, False: 0]
  ------------------
  639|   141k|            !memcmp(sce->sessionID, sessionID, sessionIDLength)) {
  ------------------
  |  Branch (639:13): [True: 986, False: 27.2k]
  ------------------
  640|       |            /* Found it */
  641|    986|            return sce;
  642|    986|        }
  643|   141k|    }
  644|       |
  645|  1.39k|    PORT_SetError(SSL_ERROR_SESSION_NOT_FOUND);
  ------------------
  |  |   65|  1.39k|#define PORT_SetError PORT_SetError_Util
  ------------------
  646|  1.39k|    return NULL;
  647|  2.37k|}
sslsnce.c:ssl_ConfigServerSessionIDCacheInstanceWithOpt:
 1158|      1|{
 1159|      1|    SECStatus rv;
 1160|       |
 1161|      1|    rv = ssl_InitSessionCache();
 1162|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1162:9): [True: 0, False: 1]
  ------------------
 1163|      0|        return rv;
 1164|      0|    }
 1165|       |
 1166|      1|    myPid = SSL_GETPID();
  ------------------
  |  | 2059|      1|#define SSL_GETPID getpid
  ------------------
 1167|      1|    if (!directory) {
  ------------------
  |  Branch (1167:9): [True: 0, False: 1]
  ------------------
 1168|      0|        directory = DEFAULT_CACHE_DIRECTORY;
  ------------------
  |  |  273|      0|#define DEFAULT_CACHE_DIRECTORY "/tmp"
  ------------------
 1169|      0|    }
 1170|      1|    rv = InitCache(cache, maxCacheEntries, maxCertCacheEntries,
 1171|      1|                   maxSrvNameCacheEntries, ssl3_timeout, directory, shared);
 1172|      1|    if (rv) {
  ------------------
  |  Branch (1172:9): [True: 0, False: 1]
  ------------------
 1173|      0|        return SECFailure;
 1174|      0|    }
 1175|       |
 1176|      1|    ssl_sid_lookup = ServerSessionIDLookup;
 1177|      1|    return SECSuccess;
 1178|      1|}
sslsnce.c:InitCache:
  901|      1|{
  902|      1|    ptrdiff_t ptr;
  903|      1|    sidCacheLock *pLock;
  904|      1|    char *cacheMem;
  905|      1|    PRFileMap *cacheMemMap;
  906|      1|    char *cfn = NULL; /* cache file name */
  907|      1|    int locks_initialized = 0;
  908|      1|    int locks_to_initialize = 0;
  909|      1|    PRUint32 init_time;
  910|       |
  911|      1|    if ((!cache) || (maxCacheEntries < 0) || (!directory)) {
  ------------------
  |  Branch (911:9): [True: 0, False: 1]
  |  Branch (911:21): [True: 0, False: 1]
  |  Branch (911:46): [True: 0, False: 1]
  ------------------
  912|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  913|      0|        return SECFailure;
  914|      0|    }
  915|       |
  916|      1|    if (cache->cacheMem) {
  ------------------
  |  Branch (916:9): [True: 0, False: 1]
  ------------------
  917|       |        /* Already done */
  918|      0|        return SECSuccess;
  919|      0|    }
  920|       |
  921|       |    /* make sure loser can clean up properly */
  922|      1|    cache->shared = shared;
  923|      1|    cache->cacheMem = cacheMem = NULL;
  924|      1|    cache->cacheMemMap = cacheMemMap = NULL;
  925|      1|    cache->sharedCache = (cacheDesc *)0;
  926|       |
  927|      1|    cache->numSIDCacheLocksInitialized = 0;
  928|      1|    cache->nextCertCacheEntry = 0;
  929|      1|    cache->stopPolling = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  930|      1|    cache->everInherited = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  931|      1|    cache->poller = NULL;
  932|      1|    cache->mutexTimeout = 0;
  933|       |
  934|      1|    cache->numSIDCacheEntries = maxCacheEntries ? maxCacheEntries
  ------------------
  |  Branch (934:33): [True: 1, False: 0]
  ------------------
  935|      1|                                                : DEF_SID_CACHE_ENTRIES;
  ------------------
  |  |  225|      1|#define DEF_SID_CACHE_ENTRIES 10000
  ------------------
  936|      1|    cache->numSIDCacheSets =
  937|      1|        SID_HOWMANY(cache->numSIDCacheEntries, SID_CACHE_ENTRIES_PER_SET);
  ------------------
  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  ------------------
  938|       |
  939|      1|    cache->numSIDCacheEntries =
  940|      1|        cache->numSIDCacheSets * SID_CACHE_ENTRIES_PER_SET;
  ------------------
  |  |  231|      1|#define SID_CACHE_ENTRIES_PER_SET 128
  ------------------
  941|       |
  942|      1|    cache->numSIDCacheLocks =
  943|      1|        PR_MIN(cache->numSIDCacheSets, ssl_max_sid_cache_locks);
  ------------------
  |  |  158|      1|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 1]
  |  |  ------------------
  ------------------
  944|       |
  945|      1|    cache->numSIDCacheSetsPerLock =
  946|      1|        SID_HOWMANY(cache->numSIDCacheSets, cache->numSIDCacheLocks);
  ------------------
  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  ------------------
  947|       |
  948|      1|    cache->numCertCacheEntries = (maxCertCacheEntries > 0) ? maxCertCacheEntries
  ------------------
  |  Branch (948:34): [True: 0, False: 1]
  ------------------
  949|      1|                                                           : 0;
  950|      1|    cache->numSrvNameCacheEntries = (maxSrvNameCacheEntries >= 0) ? maxSrvNameCacheEntries
  ------------------
  |  Branch (950:37): [True: 0, False: 1]
  ------------------
  951|      1|                                                                  : DEF_NAME_CACHE_ENTRIES;
  ------------------
  |  |  229|      2|#define DEF_NAME_CACHE_ENTRIES 1000
  ------------------
  952|       |
  953|       |    /* compute size of shared memory, and offsets of all pointers */
  954|      1|    ptr = 0;
  955|      1|    cache->cacheMem = (char *)ptr;
  956|      1|    ptr += SID_ROUNDUP(sizeof(cacheDesc), SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
  957|       |
  958|      1|    cache->sidCacheLocks = (sidCacheLock *)ptr;
  959|      1|    cache->keyCacheLock = cache->sidCacheLocks + cache->numSIDCacheLocks;
  960|      1|    cache->certCacheLock = cache->keyCacheLock + 1;
  961|      1|    cache->srvNameCacheLock = cache->certCacheLock + 1;
  962|      1|    ptr = (ptrdiff_t)(cache->srvNameCacheLock + 1);
  963|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
  964|       |
  965|      1|    cache->sidCacheSets = (sidCacheSet *)ptr;
  966|      1|    ptr = (ptrdiff_t)(cache->sidCacheSets + cache->numSIDCacheSets);
  967|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
  968|       |
  969|      1|    cache->sidCacheData = (sidCacheEntry *)ptr;
  970|      1|    ptr = (ptrdiff_t)(cache->sidCacheData + cache->numSIDCacheEntries);
  971|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
  972|       |
  973|      1|    cache->certCacheData = (certCacheEntry *)ptr;
  974|      1|    cache->sidCacheSize =
  975|      1|        (char *)cache->certCacheData - (char *)cache->sidCacheData;
  976|       |
  977|      1|    if (cache->numCertCacheEntries < MIN_CERT_CACHE_ENTRIES) {
  ------------------
  |  |  227|      1|#define MIN_CERT_CACHE_ENTRIES 125 /* the effective size in old releases. */
  ------------------
  |  Branch (977:9): [True: 1, False: 0]
  ------------------
  978|       |        /* This is really a poor way to computer this! */
  979|      1|        cache->numCertCacheEntries = cache->sidCacheSize / sizeof(certCacheEntry);
  980|      1|        if (cache->numCertCacheEntries < MIN_CERT_CACHE_ENTRIES)
  ------------------
  |  |  227|      1|#define MIN_CERT_CACHE_ENTRIES 125 /* the effective size in old releases. */
  ------------------
  |  Branch (980:13): [True: 1, False: 0]
  ------------------
  981|      1|            cache->numCertCacheEntries = MIN_CERT_CACHE_ENTRIES;
  ------------------
  |  |  227|      1|#define MIN_CERT_CACHE_ENTRIES 125 /* the effective size in old releases. */
  ------------------
  982|      1|    }
  983|      1|    ptr = (ptrdiff_t)(cache->certCacheData + cache->numCertCacheEntries);
  984|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
  985|       |
  986|      1|    cache->keyCacheData = (SSLWrappedSymWrappingKey *)ptr;
  987|      1|    cache->certCacheSize =
  988|      1|        (char *)cache->keyCacheData - (char *)cache->certCacheData;
  989|       |
  990|      1|    cache->numKeyCacheEntries = SSL_NUM_WRAP_KEYS * SSL_NUM_WRAP_MECHS;
  ------------------
  |  |  116|      1|#define SSL_NUM_WRAP_KEYS 6
  ------------------
                  cache->numKeyCacheEntries = SSL_NUM_WRAP_KEYS * SSL_NUM_WRAP_MECHS;
  ------------------
  |  |  115|      1|#define SSL_NUM_WRAP_MECHS 15
  ------------------
  991|      1|    ptr = (ptrdiff_t)(cache->keyCacheData + cache->numKeyCacheEntries);
  992|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
  993|       |
  994|      1|    cache->keyCacheSize = (char *)ptr - (char *)cache->keyCacheData;
  995|       |
  996|      1|    cache->ticketKeyNameSuffix = (PRUint8 *)ptr;
  997|      1|    ptr = (ptrdiff_t)(cache->ticketKeyNameSuffix +
  998|      1|                      SELF_ENCRYPT_KEY_VAR_NAME_LEN);
  ------------------
  |  |  194|      1|#define SELF_ENCRYPT_KEY_VAR_NAME_LEN 12
  ------------------
  999|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
 1000|       |
 1001|      1|    cache->ticketEncKey = (encKeyCacheEntry *)ptr;
 1002|      1|    ptr = (ptrdiff_t)(cache->ticketEncKey + 1);
 1003|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
 1004|       |
 1005|      1|    cache->ticketMacKey = (encKeyCacheEntry *)ptr;
 1006|      1|    ptr = (ptrdiff_t)(cache->ticketMacKey + 1);
 1007|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
 1008|       |
 1009|      1|    cache->ticketKeysValid = (PRUint32 *)ptr;
 1010|      1|    ptr = (ptrdiff_t)(cache->ticketKeysValid + 1);
 1011|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
 1012|       |
 1013|      1|    cache->srvNameCacheData = (srvNameCacheEntry *)ptr;
 1014|      1|    cache->srvNameCacheSize =
 1015|      1|        cache->numSrvNameCacheEntries * sizeof(srvNameCacheEntry);
 1016|      1|    ptr = (ptrdiff_t)(cache->srvNameCacheData + cache->numSrvNameCacheEntries);
 1017|      1|    ptr = SID_ROUNDUP(ptr, SID_ALIGNMENT);
  ------------------
  |  |  245|      1|#define SID_ROUNDUP(val, size) ((size)*SID_HOWMANY((val), (size)))
  |  |  ------------------
  |  |  |  |  244|      1|#define SID_HOWMANY(val, size) (((val) + ((size)-1)) / (size))
  |  |  ------------------
  ------------------
 1018|       |
 1019|      1|    cache->cacheMemSize = ptr;
 1020|       |
 1021|      1|    if (ssl3_timeout) {
  ------------------
  |  Branch (1021:9): [True: 0, False: 1]
  ------------------
 1022|      0|        if (ssl3_timeout > MAX_SSL3_TIMEOUT) {
  ------------------
  |  |  235|      0|#define MAX_SSL3_TIMEOUT 86400L /* 24 hours */
  ------------------
  |  Branch (1022:13): [True: 0, False: 0]
  ------------------
 1023|      0|            ssl3_timeout = MAX_SSL3_TIMEOUT;
  ------------------
  |  |  235|      0|#define MAX_SSL3_TIMEOUT 86400L /* 24 hours */
  ------------------
 1024|      0|        }
 1025|      0|        if (ssl3_timeout < MIN_SSL3_TIMEOUT) {
  ------------------
  |  |  236|      0|#define MIN_SSL3_TIMEOUT 5      /* seconds  */
  ------------------
  |  Branch (1025:13): [True: 0, False: 0]
  ------------------
 1026|      0|            ssl3_timeout = MIN_SSL3_TIMEOUT;
  ------------------
  |  |  236|      0|#define MIN_SSL3_TIMEOUT 5      /* seconds  */
  ------------------
 1027|      0|        }
 1028|      0|        cache->ssl3Timeout = ssl3_timeout;
 1029|      1|    } else {
 1030|      1|        cache->ssl3Timeout = DEF_SSL3_TIMEOUT;
  ------------------
  |  |  234|      1|#define DEF_SSL3_TIMEOUT 86400L /* 24 hours */
  ------------------
 1031|      1|    }
 1032|       |
 1033|      1|    if (shared) {
  ------------------
  |  Branch (1033:9): [True: 0, False: 1]
  ------------------
 1034|       |/* Create file names */
 1035|      0|#if defined(XP_UNIX)
 1036|       |        /* there's some confusion here about whether PR_OpenAnonFileMap wants
 1037|       |        ** a directory name or a file name for its first argument.
 1038|       |        cfn = PR_smprintf("%s/.sslsvrcache.%d", directory, myPid);
 1039|       |        */
 1040|      0|        cfn = PR_smprintf("%s", directory);
 1041|       |#elif defined(XP_WIN32)
 1042|       |        cfn = PR_smprintf("%s/svrcache_%d_%x.ssl", directory, myPid,
 1043|       |                          GetCurrentThreadId());
 1044|       |#else
 1045|       |#error "Don't know how to create file name for this platform!"
 1046|       |#endif
 1047|      0|        if (!cfn) {
  ------------------
  |  Branch (1047:13): [True: 0, False: 0]
  ------------------
 1048|      0|            goto loser;
 1049|      0|        }
 1050|       |
 1051|       |        /* Create cache */
 1052|      0|        cacheMemMap = PR_OpenAnonFileMap(cfn, cache->cacheMemSize,
 1053|      0|                                         PR_PROT_READWRITE);
 1054|       |
 1055|      0|        PR_smprintf_free(cfn);
 1056|      0|        if (!cacheMemMap) {
  ------------------
  |  Branch (1056:13): [True: 0, False: 0]
  ------------------
 1057|      0|            goto loser;
 1058|      0|        }
 1059|       |
 1060|      0|        cacheMem = PR_MemMap(cacheMemMap, 0, cache->cacheMemSize);
 1061|      1|    } else {
 1062|      1|        cacheMem = PORT_Alloc(cache->cacheMemSize);
  ------------------
  |  |   52|      1|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1063|      1|    }
 1064|       |
 1065|      1|    if (!cacheMem) {
  ------------------
  |  Branch (1065:9): [True: 0, False: 1]
  ------------------
 1066|      0|        goto loser;
 1067|      0|    }
 1068|       |
 1069|       |    /* Initialize shared memory. This may not be necessary on all platforms */
 1070|      1|    memset(cacheMem, 0, cache->cacheMemSize);
 1071|       |
 1072|       |    /* Copy cache descriptor header into shared memory */
 1073|      1|    memcpy(cacheMem, cache, sizeof *cache);
 1074|       |
 1075|       |    /* save private copies of these values */
 1076|      1|    cache->cacheMemMap = cacheMemMap;
 1077|      1|    cache->cacheMem = cacheMem;
 1078|      1|    cache->sharedCache = (cacheDesc *)cacheMem;
 1079|       |
 1080|       |    /* Fix pointers in our private copy of cache descriptor to point to
 1081|       |    ** spaces in shared memory
 1082|       |    */
 1083|      1|    cache->sidCacheLocks = (sidCacheLock *)(cache->cacheMem + (ptrdiff_t)cache->sidCacheLocks);
 1084|      1|    cache->keyCacheLock = (sidCacheLock *)(cache->cacheMem + (ptrdiff_t)cache->keyCacheLock);
 1085|      1|    cache->certCacheLock = (sidCacheLock *)(cache->cacheMem + (ptrdiff_t)cache->certCacheLock);
 1086|      1|    cache->srvNameCacheLock = (sidCacheLock *)(cache->cacheMem + (ptrdiff_t)cache->srvNameCacheLock);
 1087|      1|    cache->sidCacheSets = (sidCacheSet *)(cache->cacheMem + (ptrdiff_t)cache->sidCacheSets);
 1088|      1|    cache->sidCacheData = (sidCacheEntry *)(cache->cacheMem + (ptrdiff_t)cache->sidCacheData);
 1089|      1|    cache->certCacheData = (certCacheEntry *)(cache->cacheMem + (ptrdiff_t)cache->certCacheData);
 1090|      1|    cache->keyCacheData = (SSLWrappedSymWrappingKey *)(cache->cacheMem + (ptrdiff_t)cache->keyCacheData);
 1091|      1|    cache->ticketKeyNameSuffix = (PRUint8 *)(cache->cacheMem + (ptrdiff_t)cache->ticketKeyNameSuffix);
 1092|      1|    cache->ticketEncKey = (encKeyCacheEntry *)(cache->cacheMem + (ptrdiff_t)cache->ticketEncKey);
 1093|      1|    cache->ticketMacKey = (encKeyCacheEntry *)(cache->cacheMem + (ptrdiff_t)cache->ticketMacKey);
 1094|      1|    cache->ticketKeysValid = (PRUint32 *)(cache->cacheMem + (ptrdiff_t)cache->ticketKeysValid);
 1095|      1|    cache->srvNameCacheData = (srvNameCacheEntry *)(cache->cacheMem + (ptrdiff_t)cache->srvNameCacheData);
 1096|       |
 1097|       |    /* initialize the locks */
 1098|      1|    init_time = ssl_CacheNow();
 1099|      1|    pLock = cache->sidCacheLocks;
 1100|      1|    for (locks_to_initialize = cache->numSIDCacheLocks + 3;
 1101|     12|         locks_initialized < locks_to_initialize;
  ------------------
  |  Branch (1101:10): [True: 11, False: 1]
  ------------------
 1102|     11|         ++locks_initialized, ++pLock) {
 1103|       |
 1104|     11|        SECStatus err = sslMutex_Init(&pLock->mutex, shared);
 1105|     11|        if (err) {
  ------------------
  |  Branch (1105:13): [True: 0, False: 11]
  ------------------
 1106|      0|            cache->numSIDCacheLocksInitialized = locks_initialized;
 1107|      0|            goto loser;
 1108|      0|        }
 1109|     11|        pLock->timeStamp = init_time;
 1110|     11|        pLock->pid = 0;
 1111|     11|    }
 1112|      1|    cache->numSIDCacheLocksInitialized = locks_initialized;
 1113|       |
 1114|      1|    return SECSuccess;
 1115|       |
 1116|      0|loser:
 1117|      0|    CloseCache(cache);
 1118|      0|    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1119|      0|    return SECFailure;
 1120|      1|}
sslsnce.c:ssl_CacheNow:
  294|  32.7k|{
  295|  32.7k|    return PR_Now() / PR_USEC_PER_SEC;
  ------------------
  |  |   28|  32.7k|#define PR_USEC_PER_SEC     1000000L
  ------------------
  296|  32.7k|}
sslsnce.c:CloseCache:
  867|      1|{
  868|      1|    int locks_initialized = cache->numSIDCacheLocksInitialized;
  869|       |
  870|      1|    if (cache->cacheMem) {
  ------------------
  |  Branch (870:9): [True: 1, False: 0]
  ------------------
  871|      1|        if (cache->sharedCache) {
  ------------------
  |  Branch (871:13): [True: 1, False: 0]
  ------------------
  872|      1|            sidCacheLock *pLock = cache->sidCacheLocks;
  873|     12|            for (; locks_initialized > 0; --locks_initialized, ++pLock) {
  ------------------
  |  Branch (873:20): [True: 11, False: 1]
  ------------------
  874|       |                /* If everInherited is true, this shared cache was (and may
  875|       |                ** still be) in use by multiple processes.  We do not wish to
  876|       |                ** destroy the mutexes while they are still in use, but we do
  877|       |                ** want to free mutex resources associated with this process.
  878|       |                */
  879|     11|                sslMutex_Destroy(&pLock->mutex,
  880|     11|                                 cache->sharedCache->everInherited);
  881|     11|            }
  882|      1|        }
  883|      1|        if (cache->shared) {
  ------------------
  |  Branch (883:13): [True: 0, False: 1]
  ------------------
  884|      0|            PR_MemUnmap(cache->cacheMem, cache->cacheMemSize);
  885|      1|        } else {
  886|      1|            PORT_Free(cache->cacheMem);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  887|      1|        }
  888|      1|        cache->cacheMem = NULL;
  889|      1|    }
  890|      1|    if (cache->cacheMemMap) {
  ------------------
  |  Branch (890:9): [True: 0, False: 1]
  ------------------
  891|      0|        PR_CloseFileMap(cache->cacheMemMap);
  892|      0|        cache->cacheMemMap = NULL;
  893|      0|    }
  894|      1|    memset(cache, 0, sizeof *cache);
  895|      1|}
sslsnce.c:ssl_InitSessionCache:
  285|      1|{
  286|       |    /* currently only one function, which is itself idempotent */
  287|      1|    return ssl_InitializePRErrorTable();
  288|      1|}
sslsnce.c:ServerSessionIDLookup:
  663|  1.01k|{
  664|  1.01k|    sslSessionID *sid = 0;
  665|  1.01k|    sidCacheEntry *psce;
  666|  1.01k|    certCacheEntry *pcce = 0;
  667|  1.01k|    srvNameCacheEntry *psnce = 0;
  668|  1.01k|    cacheDesc *cache = &globalCache;
  669|  1.01k|    PRUint32 now;
  670|  1.01k|    PRUint32 set;
  671|  1.01k|    PRInt32 cndx;
  672|  1.01k|    sidCacheEntry sce;
  673|  1.01k|    certCacheEntry cce;
  674|  1.01k|    srvNameCacheEntry snce;
  675|       |
  676|  1.01k|    set = SIDindex(cache, addr, sessionID, sessionIDLength);
  677|  1.01k|    now = LockSet(cache, set, 0);
  678|  1.01k|    if (!now)
  ------------------
  |  Branch (678:9): [True: 0, False: 1.01k]
  ------------------
  679|      0|        return NULL;
  680|       |
  681|  1.01k|    psce = FindSID(cache, set, now, addr, sessionID, sessionIDLength);
  682|  1.01k|    if (psce) {
  ------------------
  |  Branch (682:9): [True: 0, False: 1.01k]
  ------------------
  683|      0|        if ((cndx = psce->u.ssl3.certIndex) != -1) {
  ------------------
  |  Branch (683:13): [True: 0, False: 0]
  ------------------
  684|      0|            PRUint32 gotLock = LockSidCacheLock(cache->certCacheLock, now);
  685|      0|            if (gotLock) {
  ------------------
  |  Branch (685:17): [True: 0, False: 0]
  ------------------
  686|      0|                pcce = &cache->certCacheData[cndx];
  687|       |
  688|       |                /* See if the cert's session ID matches the sce cache. */
  689|      0|                if ((pcce->sessionIDLength == psce->sessionIDLength) &&
  ------------------
  |  Branch (689:21): [True: 0, False: 0]
  ------------------
  690|      0|                    !PORT_Memcmp(pcce->sessionID, psce->sessionID,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (690:21): [True: 0, False: 0]
  ------------------
  691|      0|                                 pcce->sessionIDLength)) {
  692|      0|                    cce = *pcce;
  693|      0|                } else {
  694|       |                    /* The cert doesen't match the SID cache entry,
  695|       |                    ** so invalidate the SID cache entry.
  696|       |                    */
  697|      0|                    psce->valid = 0;
  698|      0|                    psce = 0;
  699|      0|                    pcce = 0;
  700|      0|                }
  701|      0|                UnlockSidCacheLock(cache->certCacheLock);
  702|      0|            } else {
  703|       |                /* what the ??.  Didn't get the cert cache lock.
  704|       |                ** Don't invalidate the SID cache entry, but don't find it.
  705|       |                */
  706|      0|                PORT_AssertNotReached("Didn't get cert Cache Lock!");
  ------------------
  |  |  127|      0|#define PORT_AssertNotReached(reasonStr) PR_NOT_REACHED(reasonStr)
  |  |  ------------------
  |  |  |  |  213|      0|    PR_Assert(_reasonStr,__FILE__,__LINE__)
  |  |  ------------------
  ------------------
  707|      0|                psce = 0;
  708|      0|                pcce = 0;
  709|      0|            }
  710|      0|        }
  711|      0|        if (psce && ((cndx = psce->u.ssl3.srvNameIndex) != -1)) {
  ------------------
  |  Branch (711:13): [True: 0, False: 0]
  |  Branch (711:21): [True: 0, False: 0]
  ------------------
  712|      0|            PRUint32 gotLock = LockSidCacheLock(cache->srvNameCacheLock,
  713|      0|                                                now);
  714|      0|            if (gotLock) {
  ------------------
  |  Branch (714:17): [True: 0, False: 0]
  ------------------
  715|      0|                psnce = &cache->srvNameCacheData[cndx];
  716|       |
  717|      0|                if (!PORT_Memcmp(psnce->nameHash, psce->u.ssl3.srvNameHash,
  ------------------
  |  |  179|      0|#define PORT_Memcmp memcmp
  ------------------
  |  Branch (717:21): [True: 0, False: 0]
  ------------------
  718|      0|                                 SHA256_LENGTH)) {
  ------------------
  |  |   41|      0|#define SHA256_LENGTH 32
  ------------------
  719|      0|                    snce = *psnce;
  720|      0|                } else {
  721|       |                    /* The name doesen't match the SID cache entry,
  722|       |                    ** so invalidate the SID cache entry.
  723|       |                    */
  724|      0|                    psce->valid = 0;
  725|      0|                    psce = 0;
  726|      0|                    psnce = 0;
  727|      0|                }
  728|      0|                UnlockSidCacheLock(cache->srvNameCacheLock);
  729|      0|            } else {
  730|       |                /* what the ??.  Didn't get the cert cache lock.
  731|       |                ** Don't invalidate the SID cache entry, but don't find it.
  732|       |                */
  733|      0|                PORT_AssertNotReached("Didn't get name Cache Lock!");
  ------------------
  |  |  127|      0|#define PORT_AssertNotReached(reasonStr) PR_NOT_REACHED(reasonStr)
  |  |  ------------------
  |  |  |  |  213|      0|    PR_Assert(_reasonStr,__FILE__,__LINE__)
  |  |  ------------------
  ------------------
  734|      0|                psce = 0;
  735|      0|                psnce = 0;
  736|      0|            }
  737|      0|        }
  738|      0|        if (psce) {
  ------------------
  |  Branch (738:13): [True: 0, False: 0]
  ------------------
  739|      0|            psce->lastAccessTime = sslNow;
  740|      0|            sce = *psce; /* grab a copy while holding the lock */
  741|      0|        }
  742|      0|    }
  743|  1.01k|    UnlockSet(cache, set);
  744|  1.01k|    if (psce) {
  ------------------
  |  Branch (744:9): [True: 0, False: 1.01k]
  ------------------
  745|       |        /* sce conains a copy of the cache entry.
  746|       |        ** Convert shared memory format to local format
  747|       |        */
  748|      0|        sid = ConvertToSID(&sce, pcce ? &cce : 0, psnce ? &snce : 0, dbHandle);
  ------------------
  |  Branch (748:34): [True: 0, False: 0]
  |  Branch (748:51): [True: 0, False: 0]
  ------------------
  749|      0|    }
  750|  1.01k|    return sid;
  751|  1.01k|}
sslsnce.c:StopLockPoller:
 1588|      1|{
 1589|      1|    if (!cache->poller) {
  ------------------
  |  Branch (1589:9): [True: 1, False: 0]
  ------------------
 1590|      1|        return SECSuccess;
 1591|      1|    }
 1592|      0|    cache->sharedCache->stopPolling = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1593|      0|    if (PR_Interrupt(cache->poller) != PR_SUCCESS) {
  ------------------
  |  Branch (1593:9): [True: 0, False: 0]
  ------------------
 1594|      0|        return SECFailure;
 1595|      0|    }
 1596|      0|    if (PR_JoinThread(cache->poller) != PR_SUCCESS) {
  ------------------
  |  Branch (1596:9): [True: 0, False: 0]
  ------------------
 1597|      0|        return SECFailure;
 1598|      0|    }
 1599|      0|    cache->poller = NULL;
 1600|      0|    return SECSuccess;
 1601|      0|}
sslsnce.c:ssl_SelfEncryptSetup:
 1669|      1|{
 1670|      1|    SECStatus rv = NSS_RegisterShutdown(ssl_SelfEncryptShutdown, NULL);
 1671|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1671:9): [True: 0, False: 1]
  ------------------
 1672|      0|        return PR_FAILURE;
 1673|      0|    }
 1674|      1|    ssl_self_encrypt_key_pair.lock = PR_NewRWLock(PR_RWLOCK_RANK_NONE, NULL);
  ------------------
  |  |   29|      1|#define PR_RWLOCK_RANK_NONE 0
  ------------------
 1675|      1|    if (!ssl_self_encrypt_key_pair.lock) {
  ------------------
  |  Branch (1675:9): [True: 0, False: 1]
  ------------------
 1676|      0|        return PR_FAILURE;
 1677|      0|    }
 1678|      1|    return PR_SUCCESS;
 1679|      1|}
sslsnce.c:ssl_SelfEncryptShutdown:
 1657|      1|{
 1658|      1|    ssl_CleanupSelfEncryptKeyPair();
 1659|      1|    PR_DestroyRWLock(ssl_self_encrypt_key_pair.lock);
 1660|      1|    PORT_Memset(&ssl_self_encrypt_key_pair, 0,
  ------------------
  |  |  182|      1|#define PORT_Memset memset
  ------------------
 1661|      1|                sizeof(ssl_self_encrypt_key_pair));
 1662|       |
 1663|      1|    ssl_ResetSelfEncryptKeys();
 1664|      1|    return SECSuccess;
 1665|      1|}
sslsnce.c:ssl_CleanupSelfEncryptKeyPair:
 1635|      1|{
 1636|      1|    if (ssl_self_encrypt_key_pair.pubKey) {
  ------------------
  |  Branch (1636:9): [True: 1, False: 0]
  ------------------
 1637|      1|        PORT_Assert(ssl_self_encrypt_key_pair.privKey);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1638|      1|        SECKEY_DestroyPublicKey(ssl_self_encrypt_key_pair.pubKey);
 1639|      1|        SECKEY_DestroyPrivateKey(ssl_self_encrypt_key_pair.privKey);
 1640|      1|    }
 1641|      1|}
sslsnce.c:ssl_SetSelfEncryptKeyPair:
 1688|      1|{
 1689|      1|    SECKEYPublicKey *pubKeyCopy, *oldPubKey;
 1690|      1|    SECKEYPrivateKey *privKeyCopy, *oldPrivKey;
 1691|       |
 1692|      1|    PORT_Assert(ssl_self_encrypt_key_pair.lock);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1693|      1|    pubKeyCopy = SECKEY_CopyPublicKey(pubKey);
 1694|      1|    privKeyCopy = SECKEY_CopyPrivateKey(privKey);
 1695|       |
 1696|      1|    if (!pubKeyCopy || !privKeyCopy) {
  ------------------
  |  Branch (1696:9): [True: 0, False: 1]
  |  Branch (1696:24): [True: 0, False: 1]
  ------------------
 1697|      0|        SECKEY_DestroyPublicKey(pubKeyCopy);
 1698|      0|        SECKEY_DestroyPrivateKey(privKeyCopy);
 1699|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1700|      0|        return SECFailure;
 1701|      0|    }
 1702|       |
 1703|      1|    PR_RWLock_Wlock(ssl_self_encrypt_key_pair.lock);
 1704|      1|    oldPubKey = ssl_self_encrypt_key_pair.pubKey;
 1705|      1|    oldPrivKey = ssl_self_encrypt_key_pair.privKey;
 1706|      1|    ssl_self_encrypt_key_pair.pubKey = pubKeyCopy;
 1707|      1|    ssl_self_encrypt_key_pair.privKey = privKeyCopy;
 1708|      1|    ssl_self_encrypt_key_pair.configured = explicitConfig;
 1709|      1|    PR_RWLock_Unlock(ssl_self_encrypt_key_pair.lock);
 1710|       |
 1711|      1|    if (oldPubKey) {
  ------------------
  |  Branch (1711:9): [True: 0, False: 1]
  ------------------
 1712|      0|        PORT_Assert(oldPrivKey);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1713|      0|        SECKEY_DestroyPublicKey(oldPubKey);
 1714|      0|        SECKEY_DestroyPrivateKey(oldPrivKey);
 1715|      0|    }
 1716|       |
 1717|      1|    return SECSuccess;
 1718|      1|}
sslsnce.c:ssl_GenerateSelfEncryptKeysOnce:
 1811|      1|{
 1812|      1|    SECStatus rv;
 1813|       |
 1814|       |    /* Get a copy of the session keys from shared memory. */
 1815|      1|    PORT_Memcpy(ssl_self_encrypt_keys.keyName,
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
 1816|      1|                SELF_ENCRYPT_KEY_NAME_PREFIX,
  ------------------
  |  |  192|      1|#define SELF_ENCRYPT_KEY_NAME_PREFIX "NSS!"
  ------------------
 1817|      1|                sizeof(SELF_ENCRYPT_KEY_NAME_PREFIX));
  ------------------
  |  |  192|      1|#define SELF_ENCRYPT_KEY_NAME_PREFIX "NSS!"
  ------------------
 1818|       |    /* This function calls ssl_GetSelfEncryptKeyPair(), which initializes the
 1819|       |     * key pair stuff.  That allows this to use the same shutdown function. */
 1820|      1|    rv = ssl_GenerateSelfEncryptKeys(arg, ssl_self_encrypt_keys.keyName,
 1821|      1|                                     &ssl_self_encrypt_keys.encKey,
 1822|      1|                                     &ssl_self_encrypt_keys.macKey);
 1823|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1823:9): [True: 0, False: 1]
  ------------------
 1824|      0|        return PR_FAILURE;
 1825|      0|    }
 1826|       |
 1827|      1|    return PR_SUCCESS;
 1828|      1|}
sslsnce.c:ssl_GenerateSelfEncryptKeys:
 2071|      1|{
 2072|      1|    SECKEYPrivateKey *svrPrivKey = NULL;
 2073|      1|    SECKEYPublicKey *svrPubKey = NULL;
 2074|      1|    PRUint32 now;
 2075|      1|    cacheDesc *cache = &globalCache;
 2076|       |
 2077|      1|    SECStatus rv = ssl_GetSelfEncryptKeyPair(&svrPubKey, &svrPrivKey);
 2078|      1|    if (rv != SECSuccess || !cache->cacheMem) {
  ------------------
  |  Branch (2078:9): [True: 0, False: 1]
  |  Branch (2078:29): [True: 0, False: 1]
  ------------------
 2079|       |        /* No key pair for wrapping, or the cache is uninitialized. Generate
 2080|       |         * keys and return them without caching. */
 2081|      0|        rv = GenerateSelfEncryptKeys(pwArg, keyName, encKey, macKey);
 2082|      1|    } else {
 2083|      1|        now = LockSidCacheLock(cache->keyCacheLock, 0);
 2084|      1|        if (!now) {
  ------------------
  |  Branch (2084:13): [True: 0, False: 1]
  ------------------
 2085|      0|            goto loser;
 2086|      0|        }
 2087|       |
 2088|      1|        if (*(cache->ticketKeysValid)) {
  ------------------
  |  Branch (2088:13): [True: 0, False: 1]
  ------------------
 2089|      0|            rv = UnwrapCachedSelfEncryptKeys(svrPrivKey, keyName, encKey, macKey);
 2090|      1|        } else {
 2091|       |            /* Keys do not exist, create them. */
 2092|      1|            rv = GenerateAndWrapSelfEncryptKeys(svrPubKey, pwArg, keyName,
 2093|      1|                                                encKey, macKey);
 2094|      1|            if (rv == SECSuccess) {
  ------------------
  |  Branch (2094:17): [True: 1, False: 0]
  ------------------
 2095|      1|                *(cache->ticketKeysValid) = 1;
 2096|      1|            }
 2097|      1|        }
 2098|      1|        UnlockSidCacheLock(cache->keyCacheLock);
 2099|      1|    }
 2100|      1|    SECKEY_DestroyPublicKey(svrPubKey);
 2101|      1|    SECKEY_DestroyPrivateKey(svrPrivKey);
 2102|      1|    return rv;
 2103|       |
 2104|      0|loser:
 2105|      0|    UnlockSidCacheLock(cache->keyCacheLock);
 2106|      0|    SECKEY_DestroyPublicKey(svrPubKey);
 2107|      0|    SECKEY_DestroyPrivateKey(svrPrivKey);
 2108|      0|    return SECFailure;
 2109|      1|}
sslsnce.c:ssl_GetSelfEncryptKeyPair:
 1768|      1|{
 1769|      1|    if (PR_SUCCESS != PR_CallOnce(&ssl_self_encrypt_key_pair.setup,
  ------------------
  |  Branch (1769:9): [True: 0, False: 1]
  ------------------
 1770|      1|                                  &ssl_SelfEncryptSetup)) {
 1771|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1772|      0|        return SECFailure;
 1773|      0|    }
 1774|       |
 1775|      1|    SECKEYPublicKey *pubKeyCopy = NULL;
 1776|      1|    SECKEYPrivateKey *privKeyCopy = NULL;
 1777|      1|    PRBool noKey = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 1778|       |
 1779|      1|    PR_RWLock_Rlock(ssl_self_encrypt_key_pair.lock);
 1780|      1|    if (ssl_self_encrypt_key_pair.pubKey && ssl_self_encrypt_key_pair.privKey) {
  ------------------
  |  Branch (1780:9): [True: 1, False: 0]
  |  Branch (1780:45): [True: 1, False: 0]
  ------------------
 1781|      1|        pubKeyCopy = SECKEY_CopyPublicKey(ssl_self_encrypt_key_pair.pubKey);
 1782|      1|        privKeyCopy = SECKEY_CopyPrivateKey(ssl_self_encrypt_key_pair.privKey);
 1783|      1|    } else {
 1784|      0|        noKey = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1785|      0|    }
 1786|      1|    PR_RWLock_Unlock(ssl_self_encrypt_key_pair.lock);
 1787|       |
 1788|      1|    if (noKey) {
  ------------------
  |  Branch (1788:9): [True: 0, False: 1]
  ------------------
 1789|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1790|      0|        return SECFailure;
 1791|      0|    }
 1792|       |
 1793|      1|    if (!pubKeyCopy || !privKeyCopy) {
  ------------------
  |  Branch (1793:9): [True: 0, False: 1]
  |  Branch (1793:24): [True: 0, False: 1]
  ------------------
 1794|      0|        SECKEY_DestroyPublicKey(pubKeyCopy);
 1795|      0|        SECKEY_DestroyPrivateKey(privKeyCopy);
 1796|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1797|      0|        return SECFailure;
 1798|      0|    }
 1799|       |
 1800|      1|    *pubKey = pubKeyCopy;
 1801|      1|    *privKey = privKeyCopy;
 1802|      1|    return SECSuccess;
 1803|      1|}
sslsnce.c:GenerateSelfEncryptKeys:
 1935|      1|{
 1936|      1|    PK11SlotInfo *slot;
 1937|      1|    CK_MECHANISM_TYPE mechanismArray[2];
 1938|      1|    PK11SymKey *aesKeyTmp = NULL;
 1939|      1|    PK11SymKey *macKeyTmp = NULL;
 1940|      1|    cacheDesc *cache = &globalCache;
 1941|      1|    PRUint8 ticketKeyNameSuffixLocal[SELF_ENCRYPT_KEY_VAR_NAME_LEN];
 1942|      1|    PRUint8 *ticketKeyNameSuffix;
 1943|       |
 1944|      1|    if (!cache->cacheMem) {
  ------------------
  |  Branch (1944:9): [True: 0, False: 1]
  ------------------
 1945|       |        /* cache is not initalized. Use stack buffer */
 1946|      0|        ticketKeyNameSuffix = ticketKeyNameSuffixLocal;
 1947|      1|    } else {
 1948|      1|        ticketKeyNameSuffix = cache->ticketKeyNameSuffix;
 1949|      1|    }
 1950|       |
 1951|      1|    if (PK11_GenerateRandom(ticketKeyNameSuffix,
  ------------------
  |  Branch (1951:9): [True: 0, False: 1]
  ------------------
 1952|      1|                            SELF_ENCRYPT_KEY_VAR_NAME_LEN) !=
  ------------------
  |  |  194|      1|#define SELF_ENCRYPT_KEY_VAR_NAME_LEN 12
  ------------------
 1953|      1|        SECSuccess) {
 1954|      0|        SSL_DBG(("%d: SSL[%s]: Unable to generate random key name bytes.",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 1955|      0|                 SSL_GETPID(), "unknown"));
 1956|      0|        return SECFailure;
 1957|      0|    }
 1958|       |
 1959|      1|    mechanismArray[0] = CKM_AES_CBC;
  ------------------
  |  | 1108|      1|#define CKM_AES_CBC 0x00001082UL
  ------------------
 1960|      1|    mechanismArray[1] = CKM_SHA256_HMAC;
  ------------------
  |  |  877|      1|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
 1961|       |
 1962|      1|    slot = PK11_GetBestSlotMultiple(mechanismArray, 2, pwArg);
 1963|      1|    if (slot) {
  ------------------
  |  Branch (1963:9): [True: 1, False: 0]
  ------------------
 1964|      1|        aesKeyTmp = PK11_KeyGen(slot, mechanismArray[0], NULL,
 1965|      1|                                AES_256_KEY_LENGTH, pwArg);
  ------------------
  |  |  136|      1|#define AES_256_KEY_LENGTH 32 /* bytes */
  ------------------
 1966|      1|        macKeyTmp = PK11_KeyGen(slot, mechanismArray[1], NULL,
 1967|      1|                                SHA256_LENGTH, pwArg);
  ------------------
  |  |   41|      1|#define SHA256_LENGTH 32
  ------------------
 1968|      1|        PK11_FreeSlot(slot);
 1969|      1|    }
 1970|       |
 1971|      1|    if (aesKeyTmp == NULL || macKeyTmp == NULL) {
  ------------------
  |  Branch (1971:9): [True: 0, False: 1]
  |  Branch (1971:30): [True: 0, False: 1]
  ------------------
 1972|      0|        SSL_DBG(("%d: SSL[%s]: Unable to generate session ticket keys.",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 1973|      0|                 SSL_GETPID(), "unknown"));
 1974|      0|        goto loser;
 1975|      0|    }
 1976|      1|    PORT_Memcpy(keyName, ticketKeyNameSuffix, SELF_ENCRYPT_KEY_VAR_NAME_LEN);
  ------------------
  |  |  180|      1|#define PORT_Memcpy memcpy
  ------------------
                  PORT_Memcpy(keyName, ticketKeyNameSuffix, SELF_ENCRYPT_KEY_VAR_NAME_LEN);
  ------------------
  |  |  194|      1|#define SELF_ENCRYPT_KEY_VAR_NAME_LEN 12
  ------------------
 1977|      1|    *aesKey = aesKeyTmp;
 1978|      1|    *macKey = macKeyTmp;
 1979|      1|    return SECSuccess;
 1980|       |
 1981|      0|loser:
 1982|      0|    if (aesKeyTmp)
  ------------------
  |  Branch (1982:9): [True: 0, False: 0]
  ------------------
 1983|      0|        PK11_FreeSymKey(aesKeyTmp);
 1984|      0|    if (macKeyTmp)
  ------------------
  |  Branch (1984:9): [True: 0, False: 0]
  ------------------
 1985|      0|        PK11_FreeSymKey(macKeyTmp);
 1986|      0|    return SECFailure;
 1987|      1|}
sslsnce.c:GenerateAndWrapSelfEncryptKeys:
 1993|      1|{
 1994|      1|    PK11SymKey *aesKeyTmp = NULL;
 1995|      1|    PK11SymKey *macKeyTmp = NULL;
 1996|      1|    cacheDesc *cache = &globalCache;
 1997|      1|    SECStatus rv;
 1998|       |
 1999|      1|    rv = GenerateSelfEncryptKeys(pwArg, keyName, &aesKeyTmp, &macKeyTmp);
 2000|      1|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2000:9): [True: 0, False: 1]
  ------------------
 2001|      0|        return SECFailure;
 2002|      0|    }
 2003|       |
 2004|      1|    if (cache->cacheMem) {
  ------------------
  |  Branch (2004:9): [True: 1, False: 0]
  ------------------
 2005|       |        /* Export the keys to the shared cache in wrapped form. */
 2006|      1|        rv = WrapSelfEncryptKey(svrPubKey, aesKeyTmp, "enc key", cache->ticketEncKey);
 2007|      1|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2007:13): [True: 0, False: 1]
  ------------------
 2008|      0|            goto loser;
 2009|      0|        }
 2010|      1|        rv = WrapSelfEncryptKey(svrPubKey, macKeyTmp, "mac key", cache->ticketMacKey);
 2011|      1|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2011:13): [True: 0, False: 1]
  ------------------
 2012|      0|            goto loser;
 2013|      0|        }
 2014|      1|    }
 2015|      1|    *aesKey = aesKeyTmp;
 2016|      1|    *macKey = macKeyTmp;
 2017|      1|    return SECSuccess;
 2018|       |
 2019|      0|loser:
 2020|      0|    PK11_FreeSymKey(aesKeyTmp);
 2021|      0|    PK11_FreeSymKey(macKeyTmp);
 2022|      0|    return SECFailure;
 2023|      1|}
sslsnce.c:WrapSelfEncryptKey:
 1913|      2|{
 1914|      2|    SECItem wrappedKey = { siBuffer, NULL, 0 };
 1915|       |
 1916|      2|    wrappedKey.len = SECKEY_PublicKeyStrength(svrPubKey);
 1917|      2|    PORT_Assert(wrappedKey.len <= sizeof(cacheEntry->bytes));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1918|      2|    if (wrappedKey.len > sizeof(cacheEntry->bytes))
  ------------------
  |  Branch (1918:9): [True: 0, False: 2]
  ------------------
 1919|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1920|      2|    wrappedKey.data = cacheEntry->bytes;
 1921|       |
 1922|      2|    if (PK11_PubWrapSymKey(CKM_RSA_PKCS, svrPubKey, symKey, &wrappedKey) !=
  ------------------
  |  |  720|      2|#define CKM_RSA_PKCS 0x00000001UL
  ------------------
  |  Branch (1922:9): [True: 0, False: 2]
  ------------------
 1923|      2|        SECSuccess) {
 1924|      0|        SSL_DBG(("%d: SSL[%s]: Unable to wrap self encrypt key %s.",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 1925|      0|                 SSL_GETPID(), "unknown", keyName));
 1926|      0|        return SECFailure;
 1927|      0|    }
 1928|      2|    cacheEntry->length = wrappedKey.len;
 1929|      2|    return SECSuccess;
 1930|      2|}
sslsnce.c:getSvrWrappingKey:
 1862|      4|{
 1863|      4|    PRUint32 now = 0;
 1864|      4|    PRBool rv = SECFailure;
 1865|       |
 1866|      4|    if (!cache->cacheMem) { /* cache is uninitialized */
  ------------------
  |  Branch (1866:9): [True: 0, False: 4]
  ------------------
 1867|      0|        PORT_SetError(SSL_ERROR_SERVER_CACHE_NOT_CONFIGURED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1868|      0|        return SECFailure;
 1869|      0|    }
 1870|       |
 1871|      4|    PRUint32 ndx = (wrapKeyIndex * SSL_NUM_WRAP_MECHS) + symWrapMechIndex;
  ------------------
  |  |  115|      4|#define SSL_NUM_WRAP_MECHS 15
  ------------------
 1872|      4|    SSLWrappedSymWrappingKey *pwswk = cache->keyCacheData + ndx;
 1873|       |
 1874|      4|    if (!lockTime) {
  ------------------
  |  Branch (1874:9): [True: 2, False: 2]
  ------------------
 1875|      2|        now = LockSidCacheLock(cache->keyCacheLock, 0);
 1876|      2|        if (!now) {
  ------------------
  |  Branch (1876:13): [True: 0, False: 2]
  ------------------
 1877|      0|            return SECFailure;
 1878|      0|        }
 1879|      2|    }
 1880|      4|    if (pwswk->wrapKeyIndex == wrapKeyIndex &&
  ------------------
  |  Branch (1880:9): [True: 2, False: 2]
  ------------------
 1881|      4|        pwswk->wrapMechIndex == symWrapMechIndex &&
  ------------------
  |  Branch (1881:9): [True: 2, False: 0]
  ------------------
 1882|      4|        pwswk->wrappedSymKeyLen != 0) {
  ------------------
  |  Branch (1882:9): [True: 0, False: 2]
  ------------------
 1883|      0|        *wswk = *pwswk;
 1884|      0|        rv = SECSuccess;
 1885|      0|    }
 1886|      4|    if (now) {
  ------------------
  |  Branch (1886:9): [True: 2, False: 2]
  ------------------
 1887|      2|        UnlockSidCacheLock(cache->keyCacheLock);
 1888|      2|    }
 1889|      4|    return rv;
 1890|      4|}
sslsnce.c:LockSidCacheLock:
  300|  33.5k|{
  301|  33.5k|    SECStatus rv = sslMutex_Lock(&lock->mutex);
  302|  33.5k|    if (rv != SECSuccess)
  ------------------
  |  Branch (302:9): [True: 0, False: 33.5k]
  ------------------
  303|      0|        return 0;
  304|  33.5k|    if (!now) {
  ------------------
  |  Branch (304:9): [True: 32.7k, False: 797]
  ------------------
  305|  32.7k|        now = ssl_CacheNow();
  306|  32.7k|    }
  307|       |
  308|  33.5k|    lock->timeStamp = now;
  309|  33.5k|    lock->pid = myPid;
  310|  33.5k|    return now;
  311|  33.5k|}
sslsnce.c:UnlockSidCacheLock:
  315|  33.5k|{
  316|  33.5k|    SECStatus rv;
  317|       |
  318|  33.5k|    lock->pid = 0;
  319|  33.5k|    rv = sslMutex_Unlock(&lock->mutex);
  320|  33.5k|    return rv;
  321|  33.5k|}

ssl_FindSocket:
  250|   946k|{
  251|   946k|    PRFileDesc *layer;
  252|   946k|    sslSocket *ss;
  253|       |
  254|   946k|    PORT_Assert(fd != NULL);
  ------------------
  |  |  120|   946k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   946k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 946k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  255|   946k|    PORT_Assert(ssl_layer_id != 0);
  ------------------
  |  |  120|   946k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   946k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 946k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  256|       |
  257|   946k|    layer = PR_GetIdentitiesLayer(fd, ssl_layer_id);
  258|   946k|    if (layer == NULL) {
  ------------------
  |  Branch (258:9): [True: 0, False: 946k]
  ------------------
  259|      0|        PORT_SetError(PR_BAD_DESCRIPTOR_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_BAD_DESCRIPTOR_ERROR);
  ------------------
  |  |   19|      0|#define PR_BAD_DESCRIPTOR_ERROR                  (-5999L)
  ------------------
  260|      0|        return NULL;
  261|      0|    }
  262|       |
  263|   946k|    ss = (sslSocket *)layer->secret;
  264|       |    /* Set ss->fd lazily. We can't rely on the value of ss->fd set by
  265|       |     * ssl_PushIOLayer because another PR_PushIOLayer call will switch the
  266|       |     * contents of the PRFileDesc pointed by ss->fd and the new layer.
  267|       |     * See bug 807250.
  268|       |     */
  269|   946k|    ss->fd = layer;
  270|   946k|    return ss;
  271|   946k|}
ssl_FreeSocket:
  514|  9.71k|{
  515|       |    /* Get every lock you can imagine!
  516|       |    ** Caller already holds these:
  517|       |    **  SSL_LOCK_READER(ss);
  518|       |    **  SSL_LOCK_WRITER(ss);
  519|       |    */
  520|  9.71k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  9.71k|    {                                                             \
  |  | 1391|  9.71k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1392|  5.20k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  5.20k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  10.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 5.20k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 5.20k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  5.20k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  5.20k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  5.20k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  5.20k|        }                                                         \
  |  | 1396|  9.71k|    }
  ------------------
  521|  9.71k|    ssl_GetRecvBufLock(ss);
  ------------------
  |  | 1449|  9.71k|    {                                                    \
  |  | 1450|  9.71k|        if (!ss->opt.noLocks) {                          \
  |  |  ------------------
  |  |  |  Branch (1450:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1451|  5.20k|            PORT_Assert(!ssl_HaveSSL3HandshakeLock(ss)); \
  |  |  ------------------
  |  |  |  |  120|  5.20k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.20k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.20k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1452|  5.20k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));       \
  |  |  ------------------
  |  |  |  |  120|  5.20k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.20k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.20k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1453|  5.20k|            PZ_EnterMonitor((ss)->recvBufLock);          \
  |  |  ------------------
  |  |  |  |  256|  5.20k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1454|  5.20k|        }                                                \
  |  | 1455|  9.71k|    }
  ------------------
  522|  9.71k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  9.71k|    {                                                 \
  |  | 1408|  9.71k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1409|  5.20k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  5.20k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  5.20k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 5.20k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  5.20k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  5.20k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  5.20k|        }                                             \
  |  | 1412|  9.71k|    }
  ------------------
  523|  9.71k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  9.71k|    {                                           \
  |  | 1467|  9.71k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1468|  9.71k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  5.20k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  9.71k|    }
  ------------------
  524|  9.71k|    ssl_GetSpecWriteLock(ss);
  ------------------
  |  | 1435|  9.71k|    {                                            \
  |  | 1436|  9.71k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1437|  9.71k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|  5.20k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|  9.71k|    }
  ------------------
  525|       |
  526|  9.71k|    ssl_DestroySocketContents(ss);
  527|       |
  528|       |    /* Release all the locks acquired above.  */
  529|  9.71k|    SSL_UNLOCK_READER(ss);
  ------------------
  |  | 1379|  9.71k|    if (ss->recvLock)         \
  |  |  ------------------
  |  |  |  Branch (1379:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1380|  9.71k|    PZ_Unlock(ss->recvLock)
  |  |  ------------------
  |  |  |  |  246|  9.71k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  530|  9.71k|    SSL_UNLOCK_WRITER(ss);
  ------------------
  |  | 1385|  9.71k|    if (ss->sendLock)         \
  |  |  ------------------
  |  |  |  Branch (1385:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1386|  9.71k|    PZ_Unlock(ss->sendLock)
  |  |  ------------------
  |  |  |  |  246|  9.71k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
  531|  9.71k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  9.71k|    {                                                 \
  |  | 1399|  9.71k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1400|  9.71k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  5.20k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  9.71k|    }
  ------------------
  532|  9.71k|    ssl_ReleaseRecvBufLock(ss);
  ------------------
  |  | 1457|  9.71k|    {                                          \
  |  | 1458|  9.71k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1458:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1459|  9.71k|            PZ_ExitMonitor((ss)->recvBufLock); \
  |  |  ------------------
  |  |  |  |  257|  5.20k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1460|  9.71k|    }
  ------------------
  533|  9.71k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  9.71k|    {                                                \
  |  | 1415|  9.71k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1416|  9.71k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  5.20k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  9.71k|    }
  ------------------
  534|  9.71k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  9.71k|    {                                          \
  |  | 1472|  9.71k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1473|  9.71k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  5.20k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  9.71k|    }
  ------------------
  535|  9.71k|    ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|  9.71k|    {                                              \
  |  | 1441|  9.71k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 5.20k, False: 4.51k]
  |  |  ------------------
  |  | 1442|  9.71k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|  5.20k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|  9.71k|    }
  ------------------
  536|       |
  537|  9.71k|    ssl_DestroyLocks(ss);
  538|       |
  539|  9.71k|#ifdef DEBUG
  540|  9.71k|    PORT_Memset(ss, 0x1f, sizeof *ss);
  ------------------
  |  |  182|  9.71k|#define PORT_Memset memset
  ------------------
  541|  9.71k|#endif
  542|  9.71k|    PORT_Free(ss);
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
  543|  9.71k|    return;
  544|  9.71k|}
ssl_EnableNagleDelay:
  549|  2.62k|{
  550|  2.62k|    PRFileDesc *osfd = ss->fd->lower;
  551|  2.62k|    SECStatus rv = SECFailure;
  552|  2.62k|    PRSocketOptionData opt;
  553|       |
  554|  2.62k|    opt.option = PR_SockOpt_NoDelay;
  555|  2.62k|    opt.value.no_delay = (PRBool)!enabled;
  556|       |
  557|  2.62k|    if (osfd->methods->setsocketoption) {
  ------------------
  |  Branch (557:9): [True: 2.62k, False: 0]
  ------------------
  558|  2.62k|        rv = (SECStatus)osfd->methods->setsocketoption(osfd, &opt);
  559|  2.62k|    } else {
  560|      0|        PR_SetError(PR_NOT_IMPLEMENTED_ERROR, 0);
  ------------------
  |  |   40|      0|#define PR_NOT_IMPLEMENTED_ERROR                 (-5992L)
  ------------------
  561|      0|    }
  562|       |
  563|  2.62k|    return rv;
  564|  2.62k|}
SSL_OptionSet:
  669|   155k|{
  670|   155k|    sslSocket *ss = ssl_FindSocket(fd);
  671|   155k|    SECStatus rv = SECSuccess;
  672|   155k|    PRBool holdingLocks;
  673|       |
  674|   155k|    if (!ss) {
  ------------------
  |  Branch (674:9): [True: 0, False: 155k]
  ------------------
  675|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in Enable", SSL_GETPID(), fd));
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
  676|      0|        return SECFailure;
  677|      0|    }
  678|       |
  679|   155k|    holdingLocks = (!ss->opt.noLocks);
  680|   155k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|   155k|    {                                                             \
  |  | 1391|   155k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 141k, False: 13.5k]
  |  |  ------------------
  |  | 1392|   141k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|   141k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   283k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 141k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 141k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|   141k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|   141k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|   141k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|   141k|        }                                                         \
  |  | 1396|   155k|    }
  ------------------
  681|   155k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|   155k|    {                                                 \
  |  | 1408|   155k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 141k, False: 13.5k]
  |  |  ------------------
  |  | 1409|   141k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|   141k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|   141k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 141k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|   141k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|   141k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|   141k|        }                                             \
  |  | 1412|   155k|    }
  ------------------
  682|       |
  683|   155k|    switch (which) {
  684|      0|        case SSL_SOCKS:
  ------------------
  |  |   70|      0|#define SSL_SOCKS 2               /* (off by default) */
  ------------------
  |  Branch (684:9): [True: 0, False: 155k]
  ------------------
  685|      0|            ss->opt.useSocks = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  686|      0|            rv = PrepareSocket(ss);
  687|      0|            if (val) {
  ------------------
  |  Branch (687:17): [True: 0, False: 0]
  ------------------
  688|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  689|      0|                rv = SECFailure;
  690|      0|            }
  691|      0|            break;
  692|       |
  693|      0|        case SSL_SECURITY:
  ------------------
  |  |   69|      0|#define SSL_SECURITY 1            /* (on by default) */
  ------------------
  |  Branch (693:9): [True: 0, False: 155k]
  ------------------
  694|      0|            ss->opt.useSecurity = val;
  695|      0|            rv = PrepareSocket(ss);
  696|      0|            break;
  697|       |
  698|  9.71k|        case SSL_REQUEST_CERTIFICATE:
  ------------------
  |  |   71|  9.71k|#define SSL_REQUEST_CERTIFICATE 3 /* (off by default) */
  ------------------
  |  Branch (698:9): [True: 9.71k, False: 145k]
  ------------------
  699|  9.71k|            ss->opt.requestCertificate = val;
  700|  9.71k|            break;
  701|       |
  702|  9.71k|        case SSL_REQUIRE_CERTIFICATE:
  ------------------
  |  |   87|  9.71k|#define SSL_REQUIRE_CERTIFICATE 10 /* (SSL_REQUIRE_FIRST_HANDSHAKE */
  ------------------
  |  Branch (702:9): [True: 9.71k, False: 145k]
  ------------------
  703|  9.71k|            ss->opt.requireCertificate = val;
  704|  9.71k|            break;
  705|       |
  706|      0|        case SSL_HANDSHAKE_AS_CLIENT:
  ------------------
  |  |   72|      0|#define SSL_HANDSHAKE_AS_CLIENT 5 /* force accept to hs as client */
  ------------------
  |  Branch (706:9): [True: 0, False: 155k]
  ------------------
  707|      0|            if (ss->opt.handshakeAsServer && val) {
  ------------------
  |  Branch (707:17): [True: 0, False: 0]
  |  Branch (707:46): [True: 0, False: 0]
  ------------------
  708|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  709|      0|                rv = SECFailure;
  710|      0|                break;
  711|      0|            }
  712|      0|            ss->opt.handshakeAsClient = val;
  713|      0|            break;
  714|       |
  715|      0|        case SSL_HANDSHAKE_AS_SERVER:
  ------------------
  |  |   74|      0|#define SSL_HANDSHAKE_AS_SERVER 6 /* force connect to hs as server */
  ------------------
  |  Branch (715:9): [True: 0, False: 155k]
  ------------------
  716|      0|            if (ss->opt.handshakeAsClient && val) {
  ------------------
  |  Branch (716:17): [True: 0, False: 0]
  |  Branch (716:46): [True: 0, False: 0]
  ------------------
  717|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  718|      0|                rv = SECFailure;
  719|      0|                break;
  720|      0|            }
  721|      0|            ss->opt.handshakeAsServer = val;
  722|      0|            break;
  723|       |
  724|      0|        case SSL_ENABLE_TLS:
  ------------------
  |  |  102|      0|#define SSL_ENABLE_TLS 13 /* enable TLS (on by default) */
  ------------------
  |  Branch (724:9): [True: 0, False: 155k]
  ------------------
  725|      0|            if (IS_DTLS(ss)) {
  ------------------
  |  |  892|      0|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  726|      0|                if (val) {
  ------------------
  |  Branch (726:21): [True: 0, False: 0]
  ------------------
  727|      0|                    PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  728|      0|                    rv = SECFailure; /* not allowed */
  729|      0|                }
  730|      0|                break;
  731|      0|            }
  732|      0|            ssl_EnableTLS(&ss->vrange, val);
  733|      0|            break;
  734|       |
  735|      0|        case SSL_ENABLE_SSL3:
  ------------------
  |  |   83|      0|#define SSL_ENABLE_SSL3 8 /* enable ssl v3 (on by default) */
  ------------------
  |  Branch (735:9): [True: 0, False: 155k]
  ------------------
  736|      0|            if (IS_DTLS(ss)) {
  ------------------
  |  |  892|      0|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  737|      0|                if (val) {
  ------------------
  |  Branch (737:21): [True: 0, False: 0]
  ------------------
  738|      0|                    PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  739|      0|                    rv = SECFailure; /* not allowed */
  740|      0|                }
  741|      0|                break;
  742|      0|            }
  743|      0|            ssl_EnableSSL3(&ss->vrange, val);
  744|      0|            break;
  745|       |
  746|      0|        case SSL_ENABLE_SSL2:
  ------------------
  |  |   78|      0|#define SSL_ENABLE_SSL2 7 /* enable ssl v2 (off by default) */
  ------------------
  |  Branch (746:9): [True: 0, False: 155k]
  ------------------
  747|      0|        case SSL_V2_COMPATIBLE_HELLO:
  ------------------
  |  |   96|      0|#define SSL_V2_COMPATIBLE_HELLO 12 /* send v3 client hello in v2 fmt */
  ------------------
  |  Branch (747:9): [True: 0, False: 155k]
  ------------------
  748|       |            /* We no longer support SSL v2.
  749|       |             * However, if an old application requests to disable SSL v2,
  750|       |             * we shouldn't fail.
  751|       |             */
  752|      0|            if (val) {
  ------------------
  |  Branch (752:17): [True: 0, False: 0]
  ------------------
  753|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  754|      0|                rv = SECFailure;
  755|      0|            }
  756|      0|            break;
  757|       |
  758|  9.71k|        case SSL_NO_CACHE:
  ------------------
  |  |   85|  9.71k|#define SSL_NO_CACHE 9             /* don't use the session cache */
  ------------------
  |  Branch (758:9): [True: 9.71k, False: 145k]
  ------------------
  759|  9.71k|            ss->opt.noCache = val;
  760|  9.71k|            break;
  761|       |
  762|      0|        case SSL_ENABLE_FDX:
  ------------------
  |  |   89|      0|#define SSL_ENABLE_FDX 11          /* permit simultaneous read/write */
  ------------------
  |  Branch (762:9): [True: 0, False: 155k]
  ------------------
  763|      0|            if (val && ss->opt.noLocks) {
  ------------------
  |  Branch (763:17): [True: 0, False: 0]
  |  Branch (763:24): [True: 0, False: 0]
  ------------------
  764|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  765|      0|                rv = SECFailure;
  766|      0|            }
  767|      0|            ss->opt.fdx = val;
  768|      0|            break;
  769|       |
  770|      0|        case SSL_ROLLBACK_DETECTION:
  ------------------
  |  |  104|      0|#define SSL_ROLLBACK_DETECTION 14       /* for compatibility, default: on */
  ------------------
  |  Branch (770:9): [True: 0, False: 155k]
  ------------------
  771|      0|            ss->opt.detectRollBack = val;
  772|      0|            break;
  773|       |
  774|      0|        case SSL_NO_STEP_DOWN:
  ------------------
  |  |  105|      0|#define SSL_NO_STEP_DOWN 15             /* (unsupported, deprecated, off) */
  ------------------
  |  Branch (774:9): [True: 0, False: 155k]
  ------------------
  775|      0|            break;
  776|       |
  777|      0|        case SSL_BYPASS_PKCS11:
  ------------------
  |  |  106|      0|#define SSL_BYPASS_PKCS11 16            /* (unsupported, deprecated, off) */
  ------------------
  |  Branch (777:9): [True: 0, False: 155k]
  ------------------
  778|      0|            break;
  779|       |
  780|  9.71k|        case SSL_NO_LOCKS:
  ------------------
  |  |  107|  9.71k|#define SSL_NO_LOCKS 17                 /* Don't use locks for protection */
  ------------------
  |  Branch (780:9): [True: 9.71k, False: 145k]
  ------------------
  781|  9.71k|            if (val && ss->opt.fdx) {
  ------------------
  |  Branch (781:17): [True: 4.51k, False: 5.19k]
  |  Branch (781:24): [True: 0, False: 4.51k]
  ------------------
  782|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  783|      0|                rv = SECFailure;
  784|      0|            }
  785|  9.71k|            if (val && ssl_force_locks)
  ------------------
  |  Branch (785:17): [True: 4.51k, False: 5.19k]
  |  Branch (785:24): [True: 0, False: 4.51k]
  ------------------
  786|      0|                val = PR_FALSE; /* silent override */
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  787|  9.71k|            ss->opt.noLocks = val;
  788|  9.71k|            if (!val && !holdingLocks) {
  ------------------
  |  Branch (788:17): [True: 5.19k, False: 4.51k]
  |  Branch (788:25): [True: 0, False: 5.19k]
  ------------------
  789|      0|                rv = ssl_MakeLocks(ss);
  790|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (790:21): [True: 0, False: 0]
  ------------------
  791|      0|                    ss->opt.noLocks = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  792|      0|                }
  793|      0|            }
  794|  9.71k|            break;
  795|       |
  796|  9.71k|        case SSL_ENABLE_SESSION_TICKETS:
  ------------------
  |  |  108|  9.71k|#define SSL_ENABLE_SESSION_TICKETS 18   /* Enable TLS SessionTicket       */
  ------------------
  |  Branch (796:9): [True: 9.71k, False: 145k]
  ------------------
  797|  9.71k|            ss->opt.enableSessionTickets = val;
  798|  9.71k|            break;
  799|       |
  800|  9.71k|        case SSL_ENABLE_DEFLATE:
  ------------------
  |  |  110|  9.71k|#define SSL_ENABLE_DEFLATE 19           /* (unsupported, deprecated, off) */
  ------------------
  |  Branch (800:9): [True: 9.71k, False: 145k]
  ------------------
  801|  9.71k|            ss->opt.enableDeflate = val;
  802|  9.71k|            break;
  803|       |
  804|  9.71k|        case SSL_ENABLE_RENEGOTIATION:
  ------------------
  |  |  111|  9.71k|#define SSL_ENABLE_RENEGOTIATION 20     /* Values below (default: never)  */
  ------------------
  |  Branch (804:9): [True: 9.71k, False: 145k]
  ------------------
  805|  9.71k|            if (IS_DTLS(ss) && val != SSL_RENEGOTIATE_NEVER) {
  ------------------
  |  |  892|  19.4k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 9.71k]
  |  |  ------------------
  ------------------
                          if (IS_DTLS(ss) && val != SSL_RENEGOTIATE_NEVER) {
  ------------------
  |  |  711|      0|#define SSL_RENEGOTIATE_NEVER ((PRBool)0)
  ------------------
  |  Branch (805:32): [True: 0, False: 0]
  ------------------
  806|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  807|      0|                rv = SECFailure;
  808|      0|                break;
  809|      0|            }
  810|  9.71k|            ss->opt.enableRenegotiation = val;
  811|  9.71k|            break;
  812|       |
  813|  9.71k|        case SSL_REQUIRE_SAFE_NEGOTIATION:
  ------------------
  |  |  112|  9.71k|#define SSL_REQUIRE_SAFE_NEGOTIATION 21 /* Peer must send Signaling       */
  ------------------
  |  Branch (813:9): [True: 9.71k, False: 145k]
  ------------------
  814|  9.71k|            ss->opt.requireSafeNegotiation = val;
  815|  9.71k|            break;
  816|       |
  817|      0|        case SSL_ENABLE_FALSE_START:
  ------------------
  |  |  117|      0|#define SSL_ENABLE_FALSE_START 22       /* Enable SSL false start (off by */
  ------------------
  |  Branch (817:9): [True: 0, False: 155k]
  ------------------
  818|      0|            ss->opt.enableFalseStart = val;
  819|      0|            break;
  820|       |
  821|  9.71k|        case SSL_CBC_RANDOM_IV:
  ------------------
  |  |  158|  9.71k|#define SSL_CBC_RANDOM_IV 23
  ------------------
  |  Branch (821:9): [True: 9.71k, False: 145k]
  ------------------
  822|  9.71k|            ss->opt.cbcRandomIV = val;
  823|  9.71k|            break;
  824|       |
  825|      0|        case SSL_ENABLE_OCSP_STAPLING:
  ------------------
  |  |  159|      0|#define SSL_ENABLE_OCSP_STAPLING 24 /* Request OCSP stapling (client) */
  ------------------
  |  Branch (825:9): [True: 0, False: 155k]
  ------------------
  826|      0|            ss->opt.enableOCSPStapling = val;
  827|      0|            break;
  828|       |
  829|  9.71k|        case SSL_ENABLE_DELEGATED_CREDENTIALS:
  ------------------
  |  |  328|  9.71k|#define SSL_ENABLE_DELEGATED_CREDENTIALS 40
  ------------------
  |  Branch (829:9): [True: 9.71k, False: 145k]
  ------------------
  830|  9.71k|            ss->opt.enableDelegatedCredentials = val;
  831|  9.71k|            break;
  832|       |
  833|      0|        case SSL_ENABLE_NPN:
  ------------------
  |  |  163|      0|#define SSL_ENABLE_NPN 25
  ------------------
  |  Branch (833:9): [True: 0, False: 155k]
  ------------------
  834|      0|            break;
  835|       |
  836|  9.71k|        case SSL_ENABLE_ALPN:
  ------------------
  |  |  174|  9.71k|#define SSL_ENABLE_ALPN 26
  ------------------
  |  Branch (836:9): [True: 9.71k, False: 145k]
  ------------------
  837|  9.71k|            ss->opt.enableALPN = val;
  838|  9.71k|            break;
  839|       |
  840|      0|        case SSL_REUSE_SERVER_ECDHE_KEY:
  ------------------
  |  |  181|      0|#define SSL_REUSE_SERVER_ECDHE_KEY 27
  ------------------
  |  Branch (840:9): [True: 0, False: 155k]
  ------------------
  841|      0|            ss->opt.reuseServerECDHEKey = val;
  842|      0|            break;
  843|       |
  844|  9.71k|        case SSL_ENABLE_FALLBACK_SCSV:
  ------------------
  |  |  183|  9.71k|#define SSL_ENABLE_FALLBACK_SCSV 28 /* Send fallback SCSV in \
  ------------------
  |  Branch (844:9): [True: 9.71k, False: 145k]
  ------------------
  845|  9.71k|            ss->opt.enableFallbackSCSV = val;
  846|  9.71k|            break;
  847|       |
  848|      0|        case SSL_ENABLE_SERVER_DHE:
  ------------------
  |  |  188|      0|#define SSL_ENABLE_SERVER_DHE 29
  ------------------
  |  Branch (848:9): [True: 0, False: 155k]
  ------------------
  849|      0|            ss->opt.enableServerDhe = val;
  850|      0|            break;
  851|       |
  852|  9.71k|        case SSL_ENABLE_EXTENDED_MASTER_SECRET:
  ------------------
  |  |  195|  9.71k|#define SSL_ENABLE_EXTENDED_MASTER_SECRET 30
  ------------------
  |  Branch (852:9): [True: 9.71k, False: 145k]
  ------------------
  853|  9.71k|            ss->opt.enableExtendedMS = val;
  854|  9.71k|            break;
  855|       |
  856|      0|        case SSL_ENABLE_SIGNED_CERT_TIMESTAMPS:
  ------------------
  |  |  198|      0|#define SSL_ENABLE_SIGNED_CERT_TIMESTAMPS 31
  ------------------
  |  Branch (856:9): [True: 0, False: 155k]
  ------------------
  857|      0|            ss->opt.enableSignedCertTimestamps = val;
  858|      0|            break;
  859|       |
  860|      0|        case SSL_REQUIRE_DH_NAMED_GROUPS:
  ------------------
  |  |  214|      0|#define SSL_REQUIRE_DH_NAMED_GROUPS 32
  ------------------
  |  Branch (860:9): [True: 0, False: 155k]
  ------------------
  861|      0|            ss->opt.requireDHENamedGroups = val;
  862|      0|            break;
  863|       |
  864|  9.71k|        case SSL_ENABLE_0RTT_DATA:
  ------------------
  |  |  244|  9.71k|#define SSL_ENABLE_0RTT_DATA 33
  ------------------
  |  Branch (864:9): [True: 9.71k, False: 145k]
  ------------------
  865|  9.71k|            ss->opt.enable0RttData = val;
  866|  9.71k|            break;
  867|       |
  868|      0|        case SSL_RECORD_SIZE_LIMIT:
  ------------------
  |  |  266|      0|#define SSL_RECORD_SIZE_LIMIT 34
  ------------------
  |  Branch (868:9): [True: 0, False: 155k]
  ------------------
  869|      0|            if (val < 64 || val > (MAX_FRAGMENT_LENGTH + 1)) {
  ------------------
  |  |   35|      0|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
  |  Branch (869:17): [True: 0, False: 0]
  |  Branch (869:29): [True: 0, False: 0]
  ------------------
  870|      0|                PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  871|      0|                rv = SECFailure;
  872|      0|            } else {
  873|      0|                ss->opt.recordSizeLimit = val;
  874|      0|            }
  875|      0|            break;
  876|       |
  877|      0|        case SSL_ENABLE_TLS13_COMPAT_MODE:
  ------------------
  |  |  272|      0|#define SSL_ENABLE_TLS13_COMPAT_MODE 35
  ------------------
  |  Branch (877:9): [True: 0, False: 155k]
  ------------------
  878|      0|            ss->opt.enableTls13CompatMode = val;
  879|      0|            break;
  880|       |
  881|  9.71k|        case SSL_ENABLE_DTLS_SHORT_HEADER:
  ------------------
  |  |  283|  9.71k|#define SSL_ENABLE_DTLS_SHORT_HEADER 36
  ------------------
  |  Branch (881:9): [True: 9.71k, False: 145k]
  ------------------
  882|  9.71k|            ss->opt.enableDtlsShortHeader = val;
  883|  9.71k|            break;
  884|       |
  885|      0|        case SSL_ENABLE_HELLO_DOWNGRADE_CHECK:
  ------------------
  |  |  292|      0|#define SSL_ENABLE_HELLO_DOWNGRADE_CHECK 37
  ------------------
  |  Branch (885:9): [True: 0, False: 155k]
  ------------------
  886|      0|            ss->opt.enableHelloDowngradeCheck = val;
  887|      0|            break;
  888|       |
  889|      0|        case SSL_ENABLE_V2_COMPATIBLE_HELLO:
  ------------------
  |  |  300|      0|#define SSL_ENABLE_V2_COMPATIBLE_HELLO 38
  ------------------
  |  Branch (889:9): [True: 0, False: 155k]
  ------------------
  890|      0|            ss->opt.enableV2CompatibleHello = val;
  891|      0|            break;
  892|       |
  893|      0|        case SSL_ENABLE_POST_HANDSHAKE_AUTH:
  ------------------
  |  |  311|      0|#define SSL_ENABLE_POST_HANDSHAKE_AUTH 39
  ------------------
  |  Branch (893:9): [True: 0, False: 155k]
  ------------------
  894|      0|            ss->opt.enablePostHandshakeAuth = val;
  895|      0|            break;
  896|       |
  897|      0|        case SSL_SUPPRESS_END_OF_EARLY_DATA:
  ------------------
  |  |  347|      0|#define SSL_SUPPRESS_END_OF_EARLY_DATA 41
  ------------------
  |  Branch (897:9): [True: 0, False: 155k]
  ------------------
  898|      0|            ss->opt.suppressEndOfEarlyData = val;
  899|      0|            break;
  900|       |
  901|  9.71k|        case SSL_ENABLE_GREASE:
  ------------------
  |  |  374|  9.71k|#define SSL_ENABLE_GREASE 42
  ------------------
  |  Branch (901:9): [True: 9.71k, False: 145k]
  ------------------
  902|  9.71k|            ss->opt.enableGrease = val;
  903|  9.71k|            break;
  904|       |
  905|      0|        case SSL_ENABLE_CH_EXTENSION_PERMUTATION:
  ------------------
  |  |  381|      0|#define SSL_ENABLE_CH_EXTENSION_PERMUTATION 43
  ------------------
  |  Branch (905:9): [True: 0, False: 155k]
  ------------------
  906|      0|            ss->opt.enableChXtnPermutation = val;
  907|      0|            break;
  908|       |
  909|      0|        default:
  ------------------
  |  Branch (909:9): [True: 0, False: 155k]
  ------------------
  910|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  911|      0|            rv = SECFailure;
  912|   155k|    }
  913|       |
  914|       |    /* We can't use the macros for releasing the locks here,
  915|       |     * because ss->opt.noLocks might have changed just above.
  916|       |     * We must release these locks (monitors) here, if we aquired them above,
  917|       |     * regardless of the current value of ss->opt.noLocks.
  918|       |     */
  919|   155k|    if (holdingLocks) {
  ------------------
  |  Branch (919:9): [True: 141k, False: 13.5k]
  ------------------
  920|   141k|        PZ_ExitMonitor((ss)->ssl3HandshakeLock);
  ------------------
  |  |  257|   141k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  ------------------
  921|   141k|        PZ_ExitMonitor((ss)->firstHandshakeLock);
  ------------------
  |  |  257|   141k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  ------------------
  922|   141k|    }
  923|       |
  924|   155k|    return rv;
  925|   155k|}
SSL_CipherPrefSet:
 1565|   690k|{
 1566|   690k|    sslSocket *ss = ssl_FindSocket(fd);
 1567|   690k|    PRInt32 locks;
 1568|   690k|    SECStatus rv;
 1569|       |
 1570|   690k|    if (!ss) {
  ------------------
  |  Branch (1570:9): [True: 0, False: 690k]
  ------------------
 1571|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in CipherPrefSet", SSL_GETPID(), fd));
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 1572|      0|        return SECFailure;
 1573|      0|    }
 1574|   690k|    rv = NSS_OptionGet(NSS_DEFAULT_LOCKS, &locks);
  ------------------
  |  |  302|   690k|#define NSS_DEFAULT_LOCKS 0x00d /* lock default values */
  ------------------
 1575|   690k|    if ((rv == SECSuccess) && (locks & NSS_DEFAULT_SSL_LOCK)) {
  ------------------
  |  |  303|   690k|#define NSS_DEFAULT_SSL_LOCK 1  /* lock the ssl default values */
  ------------------
  |  Branch (1575:9): [True: 690k, False: 0]
  |  Branch (1575:31): [True: 0, False: 690k]
  ------------------
 1576|      0|        return SECSuccess;
 1577|      0|    }
 1578|   690k|    if (ssl_IsRemovedCipherSuite(which))
  ------------------
  |  Branch (1578:9): [True: 0, False: 690k]
  ------------------
 1579|      0|        return SECSuccess;
 1580|   690k|    return ssl3_CipherPrefSet(ss, (ssl3CipherSuite)which, enabled);
 1581|   690k|}
ssl_GetDHEParams:
 1991|  29.0k|{
 1992|  29.0k|    switch (groupDef->name) {
 1993|  21.7k|        case ssl_grp_ffdhe_2048:
  ------------------
  |  Branch (1993:9): [True: 21.7k, False: 7.30k]
  ------------------
 1994|  21.7k|            return &ff_dhe_2048_params;
 1995|  3.24k|        case ssl_grp_ffdhe_3072:
  ------------------
  |  Branch (1995:9): [True: 3.24k, False: 25.8k]
  ------------------
 1996|  3.24k|            return &ff_dhe_3072_params;
 1997|    369|        case ssl_grp_ffdhe_4096:
  ------------------
  |  Branch (1997:9): [True: 369, False: 28.7k]
  ------------------
 1998|    369|            return &ff_dhe_4096_params;
 1999|  2.35k|        case ssl_grp_ffdhe_6144:
  ------------------
  |  Branch (1999:9): [True: 2.35k, False: 26.7k]
  ------------------
 2000|  2.35k|            return &ff_dhe_6144_params;
 2001|  1.33k|        case ssl_grp_ffdhe_8192:
  ------------------
  |  Branch (2001:9): [True: 1.33k, False: 27.7k]
  ------------------
 2002|  1.33k|            return &ff_dhe_8192_params;
 2003|      0|        case ssl_grp_ffdhe_custom:
  ------------------
  |  Branch (2003:9): [True: 0, False: 29.0k]
  ------------------
 2004|      0|            PORT_Assert(gWeakDHParams);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2005|      0|            return gWeakDHParams;
 2006|      0|        default:
  ------------------
  |  Branch (2006:9): [True: 0, False: 29.0k]
  ------------------
 2007|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2008|  29.0k|    }
 2009|      0|    return NULL;
 2010|  29.0k|}
ssl_IsValidDHEShare:
 2015|  27.7k|{
 2016|  27.7k|    unsigned int size_p = SECKEY_BigIntegerBitLength(dh_p);
 2017|  27.7k|    unsigned int size_y = SECKEY_BigIntegerBitLength(dh_Ys);
 2018|  27.7k|    unsigned int commonPart;
 2019|  27.7k|    int cmp;
 2020|       |
 2021|  27.7k|    if (dh_p->len == 0 || dh_Ys->len == 0) {
  ------------------
  |  Branch (2021:9): [True: 0, False: 27.7k]
  |  Branch (2021:27): [True: 3, False: 27.7k]
  ------------------
 2022|      3|        return PR_FALSE;
  ------------------
  |  |  438|      3|#define PR_FALSE 0
  ------------------
 2023|      3|    }
 2024|       |    /* Check that the prime is at least odd. */
 2025|  27.7k|    if ((dh_p->data[dh_p->len - 1] & 0x01) == 0) {
  ------------------
  |  Branch (2025:9): [True: 0, False: 27.7k]
  ------------------
 2026|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2027|      0|    }
 2028|       |    /* dh_Ys can't be 1, or bigger than dh_p. */
 2029|  27.7k|    if (size_y <= 1 || size_y > size_p) {
  ------------------
  |  Branch (2029:9): [True: 6, False: 27.7k]
  |  Branch (2029:24): [True: 5, False: 27.7k]
  ------------------
 2030|     11|        return PR_FALSE;
  ------------------
  |  |  438|     11|#define PR_FALSE 0
  ------------------
 2031|     11|    }
 2032|       |    /* If dh_Ys is shorter, then it's definitely smaller than p-1. */
 2033|  27.7k|    if (size_y < size_p) {
  ------------------
  |  Branch (2033:9): [True: 27.5k, False: 194]
  ------------------
 2034|  27.5k|        return PR_TRUE;
  ------------------
  |  |  437|  27.5k|#define PR_TRUE 1
  ------------------
 2035|  27.5k|    }
 2036|       |
 2037|       |    /* Compare the common part of each, minus the final octet. */
 2038|    194|    commonPart = (size_p + 7) / 8;
 2039|    194|    PORT_Assert(commonPart <= dh_Ys->len);
  ------------------
  |  |  120|    194|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    194|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 194, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2040|    194|    PORT_Assert(commonPart <= dh_p->len);
  ------------------
  |  |  120|    194|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    194|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 194, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2041|    194|    cmp = PORT_Memcmp(dh_Ys->data + dh_Ys->len - commonPart,
  ------------------
  |  |  179|    194|#define PORT_Memcmp memcmp
  ------------------
 2042|    194|                      dh_p->data + dh_p->len - commonPart, commonPart - 1);
 2043|    194|    if (cmp < 0) {
  ------------------
  |  Branch (2043:9): [True: 168, False: 26]
  ------------------
 2044|    168|        return PR_TRUE;
  ------------------
  |  |  437|    168|#define PR_TRUE 1
  ------------------
 2045|    168|    }
 2046|     26|    if (cmp > 0) {
  ------------------
  |  Branch (2046:9): [True: 26, False: 0]
  ------------------
 2047|     26|        return PR_FALSE;
  ------------------
  |  |  438|     26|#define PR_FALSE 0
  ------------------
 2048|     26|    }
 2049|       |
 2050|       |    /* The last octet of the prime is the only thing that is different and that
 2051|       |     * has to be two greater than the share, otherwise we have Ys == p - 1,
 2052|       |     * and that means small subgroups. */
 2053|      0|    if (dh_Ys->data[dh_Ys->len - 1] >= (dh_p->data[dh_p->len - 1] - 1)) {
  ------------------
  |  Branch (2053:9): [True: 0, False: 0]
  ------------------
 2054|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2055|      0|    }
 2056|       |
 2057|      0|    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2058|      0|}
ssl_SelectDHEGroup:
 2105|  28.5k|{
 2106|  28.5k|    unsigned int i;
 2107|  28.5k|    static const sslNamedGroupDef weak_group_def = {
 2108|  28.5k|        ssl_grp_ffdhe_custom, WEAK_DHE_SIZE, ssl_kea_dh,
  ------------------
  |  | 1889|  28.5k|#define WEAK_DHE_SIZE 1024
  ------------------
 2109|  28.5k|        SEC_OID_TLS_DHE_CUSTOM, PR_TRUE
  ------------------
  |  |  437|  28.5k|#define PR_TRUE 1
  ------------------
 2110|  28.5k|    };
 2111|  28.5k|    PRInt32 minDH;
 2112|  28.5k|    SECStatus rv;
 2113|       |
 2114|       |    // make sure we select a group consistent with our
 2115|       |    // current policy policy
 2116|  28.5k|    rv = NSS_OptionGet(NSS_DH_MIN_KEY_SIZE, &minDH);
  ------------------
  |  |  287|  28.5k|#define NSS_DH_MIN_KEY_SIZE 0x002
  ------------------
 2117|  28.5k|    if (rv != SECSuccess || minDH <= 0) {
  ------------------
  |  Branch (2117:9): [True: 0, False: 28.5k]
  |  Branch (2117:29): [True: 0, False: 28.5k]
  ------------------
 2118|      0|        minDH = DH_MIN_P_BITS;
  ------------------
  |  |  154|      0|#define DH_MIN_P_BITS 128
  ------------------
 2119|      0|    }
 2120|       |
 2121|       |    /* Only select weak groups in TLS 1.2 and earlier, but not if the client has
 2122|       |     * indicated that it supports an FFDHE named group. */
 2123|  28.5k|    if (ss->ssl3.dheWeakGroupEnabled &&
  ------------------
  |  Branch (2123:9): [True: 0, False: 28.5k]
  ------------------
 2124|  28.5k|        ss->version < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|  28.5k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (2124:9): [True: 0, False: 0]
  ------------------
 2125|  28.5k|        !ss->xtnData.peerSupportsFfdheGroups &&
  ------------------
  |  Branch (2125:9): [True: 0, False: 0]
  ------------------
 2126|  28.5k|        weak_group_def.bits >= minDH) {
  ------------------
  |  Branch (2126:9): [True: 0, False: 0]
  ------------------
 2127|      0|        *groupDef = &weak_group_def;
 2128|      0|        return SECSuccess;
 2129|      0|    }
 2130|  28.5k|    if (ss->ssl3.dhePreferredGroup &&
  ------------------
  |  Branch (2130:9): [True: 0, False: 28.5k]
  ------------------
 2131|  28.5k|        ssl_NamedGroupEnabled(ss, ss->ssl3.dhePreferredGroup) &&
  ------------------
  |  Branch (2131:9): [True: 0, False: 0]
  ------------------
 2132|  28.5k|        ss->ssl3.dhePreferredGroup->bits >= minDH) {
  ------------------
  |  Branch (2132:9): [True: 0, False: 0]
  ------------------
 2133|      0|        *groupDef = ss->ssl3.dhePreferredGroup;
 2134|      0|        return SECSuccess;
 2135|      0|    }
 2136|   215k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|   215k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (2136:17): [True: 215k, False: 0]
  ------------------
 2137|   215k|        if (ss->namedGroupPreferences[i] &&
  ------------------
  |  Branch (2137:13): [True: 71.2k, False: 144k]
  ------------------
 2138|   215k|            ss->namedGroupPreferences[i]->keaType == ssl_kea_dh &&
  ------------------
  |  Branch (2138:13): [True: 28.5k, False: 42.6k]
  ------------------
 2139|   215k|            ss->namedGroupPreferences[i]->bits >= minDH) {
  ------------------
  |  Branch (2139:13): [True: 28.5k, False: 0]
  ------------------
 2140|  28.5k|            *groupDef = ss->namedGroupPreferences[i];
 2141|  28.5k|            return SECSuccess;
 2142|  28.5k|        }
 2143|   215k|    }
 2144|       |
 2145|      0|    *groupDef = NULL;
 2146|      0|    PORT_SetError(SSL_ERROR_NO_CYPHER_OVERLAP);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2147|      0|    return SECFailure;
 2148|  28.5k|}
SSL_ImportFD:
 2196|  9.71k|{
 2197|  9.71k|    return ssl_ImportFD(model, fd, ssl_variant_stream);
 2198|  9.71k|}
ssl3_GetEffectiveVersionPolicy:
 2585|   111k|{
 2586|   111k|    SECStatus rv;
 2587|   111k|    PRUint32 policyFlag;
 2588|   111k|    PRInt32 minPolicy, maxPolicy;
 2589|       |
 2590|   111k|    if (variant == ssl_variant_stream) {
  ------------------
  |  Branch (2590:9): [True: 91.5k, False: 19.4k]
  ------------------
 2591|  91.5k|        effectivePolicy->min = SSL_LIBRARY_VERSION_MIN_SUPPORTED_STREAM;
  ------------------
  |  | 1489|  91.5k|#define SSL_LIBRARY_VERSION_MIN_SUPPORTED_STREAM SSL_LIBRARY_VERSION_3_0
  |  |  ------------------
  |  |  |  |   17|  91.5k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  |  |  ------------------
  ------------------
 2592|  91.5k|        effectivePolicy->max = SSL_LIBRARY_VERSION_MAX_SUPPORTED;
  ------------------
  |  | 1497|  91.5k|#define SSL_LIBRARY_VERSION_MAX_SUPPORTED SSL_LIBRARY_VERSION_TLS_1_3
  |  |  ------------------
  |  |  |  |   21|  91.5k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  ------------------
 2593|  91.5k|    } else {
 2594|  19.4k|        effectivePolicy->min = SSL_LIBRARY_VERSION_MIN_SUPPORTED_DATAGRAM;
  ------------------
  |  | 1488|  19.4k|#define SSL_LIBRARY_VERSION_MIN_SUPPORTED_DATAGRAM SSL_LIBRARY_VERSION_TLS_1_1
  |  |  ------------------
  |  |  |  |   19|  19.4k|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  |  |  ------------------
  ------------------
 2595|  19.4k|        effectivePolicy->max = SSL_LIBRARY_VERSION_MAX_SUPPORTED;
  ------------------
  |  | 1497|  19.4k|#define SSL_LIBRARY_VERSION_MAX_SUPPORTED SSL_LIBRARY_VERSION_TLS_1_3
  |  |  ------------------
  |  |  |  |   21|  19.4k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  ------------------
 2596|  19.4k|    }
 2597|       |
 2598|   111k|    rv = NSS_GetAlgorithmPolicy(SEC_OID_APPLY_SSL_POLICY, &policyFlag);
 2599|   111k|    if ((rv != SECSuccess) || !(policyFlag & NSS_USE_POLICY_IN_SSL)) {
  ------------------
  |  |  574|   111k|#define NSS_USE_POLICY_IN_SSL 0x00000010           /* enable policy in SSL protocol */
  ------------------
  |  Branch (2599:9): [True: 0, False: 111k]
  |  Branch (2599:31): [True: 111k, False: 0]
  ------------------
 2600|       |        /* Policy is not active, report library extents. */
 2601|   111k|        return SECSuccess;
 2602|   111k|    }
 2603|       |
 2604|      0|    rv = NSS_OptionGet(VERSIONS_POLICY_MIN(variant), &minPolicy);
  ------------------
  |  |  119|      0|    (variant == ssl_variant_stream ? NSS_TLS_VERSION_MIN_POLICY : NSS_DTLS_VERSION_MIN_POLICY)
  |  |  ------------------
  |  |  |  |  289|      0|#define NSS_TLS_VERSION_MIN_POLICY 0x008
  |  |  ------------------
  |  |                   (variant == ssl_variant_stream ? NSS_TLS_VERSION_MIN_POLICY : NSS_DTLS_VERSION_MIN_POLICY)
  |  |  ------------------
  |  |  |  |  291|      0|#define NSS_DTLS_VERSION_MIN_POLICY 0x00a
  |  |  ------------------
  |  |  |  Branch (119:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2605|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2605:9): [True: 0, False: 0]
  ------------------
 2606|      0|        return SECFailure;
 2607|      0|    }
 2608|      0|    rv = NSS_OptionGet(VERSIONS_POLICY_MAX(variant), &maxPolicy);
  ------------------
  |  |  121|      0|    (variant == ssl_variant_stream ? NSS_TLS_VERSION_MAX_POLICY : NSS_DTLS_VERSION_MAX_POLICY)
  |  |  ------------------
  |  |  |  |  290|      0|#define NSS_TLS_VERSION_MAX_POLICY 0x009
  |  |  ------------------
  |  |                   (variant == ssl_variant_stream ? NSS_TLS_VERSION_MAX_POLICY : NSS_DTLS_VERSION_MAX_POLICY)
  |  |  ------------------
  |  |  |  |  292|      0|#define NSS_DTLS_VERSION_MAX_POLICY 0x00b
  |  |  ------------------
  |  |  |  Branch (121:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2609|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2609:9): [True: 0, False: 0]
  ------------------
 2610|      0|        return SECFailure;
 2611|      0|    }
 2612|       |
 2613|      0|    if (minPolicy > effectivePolicy->max ||
  ------------------
  |  Branch (2613:9): [True: 0, False: 0]
  ------------------
 2614|      0|        maxPolicy < effectivePolicy->min ||
  ------------------
  |  Branch (2614:9): [True: 0, False: 0]
  ------------------
 2615|      0|        minPolicy > maxPolicy) {
  ------------------
  |  Branch (2615:9): [True: 0, False: 0]
  ------------------
 2616|      0|        return SECFailure;
 2617|      0|    }
 2618|      0|    effectivePolicy->min = PR_MAX(effectivePolicy->min, minPolicy);
  ------------------
  |  |  159|      0|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2619|      0|    effectivePolicy->max = PR_MIN(effectivePolicy->max, maxPolicy);
  ------------------
  |  |  158|      0|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2620|      0|    return SECSuccess;
 2621|      0|}
ssl3_VersionIsSupportedByCode:
 2700|   105k|{
 2701|   105k|    switch (protocolVariant) {
  ------------------
  |  Branch (2701:13): [True: 0, False: 105k]
  ------------------
 2702|  85.7k|        case ssl_variant_stream:
  ------------------
  |  Branch (2702:9): [True: 85.7k, False: 19.4k]
  ------------------
 2703|  85.7k|            return (version >= SSL_LIBRARY_VERSION_MIN_SUPPORTED_STREAM &&
  ------------------
  |  | 1489|  85.7k|#define SSL_LIBRARY_VERSION_MIN_SUPPORTED_STREAM SSL_LIBRARY_VERSION_3_0
  |  |  ------------------
  |  |  |  |   17|   171k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  |  |  ------------------
  ------------------
  |  Branch (2703:21): [True: 85.7k, False: 0]
  ------------------
 2704|  85.7k|                    version <= SSL_LIBRARY_VERSION_MAX_SUPPORTED);
  ------------------
  |  | 1497|  85.7k|#define SSL_LIBRARY_VERSION_MAX_SUPPORTED SSL_LIBRARY_VERSION_TLS_1_3
  |  |  ------------------
  |  |  |  |   21|  85.7k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  ------------------
  |  Branch (2704:21): [True: 85.7k, False: 0]
  ------------------
 2705|  19.4k|        case ssl_variant_datagram:
  ------------------
  |  Branch (2705:9): [True: 19.4k, False: 85.7k]
  ------------------
 2706|  19.4k|            return (version >= SSL_LIBRARY_VERSION_MIN_SUPPORTED_DATAGRAM &&
  ------------------
  |  | 1488|  19.4k|#define SSL_LIBRARY_VERSION_MIN_SUPPORTED_DATAGRAM SSL_LIBRARY_VERSION_TLS_1_1
  |  |  ------------------
  |  |  |  |   19|  38.8k|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  |  |  ------------------
  ------------------
  |  Branch (2706:21): [True: 19.4k, False: 0]
  ------------------
 2707|  19.4k|                    version <= SSL_LIBRARY_VERSION_MAX_SUPPORTED);
  ------------------
  |  | 1497|  19.4k|#define SSL_LIBRARY_VERSION_MAX_SUPPORTED SSL_LIBRARY_VERSION_TLS_1_3
  |  |  ------------------
  |  |  |  |   21|  19.4k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  ------------------
  |  Branch (2707:21): [True: 19.4k, False: 0]
  ------------------
 2708|   105k|    }
 2709|       |
 2710|       |    /* Can't get here */
 2711|      0|    PORT_Assert(PR_FALSE);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2712|      0|    return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2713|   105k|}
ssl3_VersionIsSupported:
 2718|  58.4k|{
 2719|  58.4k|    if (!ssl_VersionIsSupportedByPolicy(protocolVariant, version)) {
  ------------------
  |  Branch (2719:9): [True: 44, False: 58.4k]
  ------------------
 2720|     44|        return PR_FALSE;
  ------------------
  |  |  438|     44|#define PR_FALSE 0
  ------------------
 2721|     44|    }
 2722|  58.4k|    return ssl3_VersionIsSupportedByCode(protocolVariant, version);
 2723|  58.4k|}
SSL_VersionRangeGetSupported:
 2747|  19.4k|{
 2748|  19.4k|    SECStatus rv;
 2749|       |
 2750|  19.4k|    if (!vrange) {
  ------------------
  |  Branch (2750:9): [True: 0, False: 19.4k]
  ------------------
 2751|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2752|      0|        return SECFailure;
 2753|      0|    }
 2754|       |
 2755|  19.4k|    switch (protocolVariant) {
 2756|  9.71k|        case ssl_variant_stream:
  ------------------
  |  Branch (2756:9): [True: 9.71k, False: 9.71k]
  ------------------
 2757|  9.71k|            vrange->min = SSL_LIBRARY_VERSION_MIN_SUPPORTED_STREAM;
  ------------------
  |  | 1489|  9.71k|#define SSL_LIBRARY_VERSION_MIN_SUPPORTED_STREAM SSL_LIBRARY_VERSION_3_0
  |  |  ------------------
  |  |  |  |   17|  9.71k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  |  |  ------------------
  ------------------
 2758|  9.71k|            vrange->max = SSL_LIBRARY_VERSION_MAX_SUPPORTED;
  ------------------
  |  | 1497|  9.71k|#define SSL_LIBRARY_VERSION_MAX_SUPPORTED SSL_LIBRARY_VERSION_TLS_1_3
  |  |  ------------------
  |  |  |  |   21|  9.71k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  ------------------
 2759|       |            /* We don't allow SSLv3 and TLSv1.3 together.
 2760|       |             * However, don't check yet, apply the policy first.
 2761|       |             * Because if the effective supported range doesn't use TLS 1.3,
 2762|       |             * then we don't need to increase the minimum. */
 2763|  9.71k|            break;
 2764|  9.71k|        case ssl_variant_datagram:
  ------------------
  |  Branch (2764:9): [True: 9.71k, False: 9.71k]
  ------------------
 2765|  9.71k|            vrange->min = SSL_LIBRARY_VERSION_MIN_SUPPORTED_DATAGRAM;
  ------------------
  |  | 1488|  9.71k|#define SSL_LIBRARY_VERSION_MIN_SUPPORTED_DATAGRAM SSL_LIBRARY_VERSION_TLS_1_1
  |  |  ------------------
  |  |  |  |   19|  9.71k|#define SSL_LIBRARY_VERSION_TLS_1_1             0x0302
  |  |  ------------------
  ------------------
 2766|  9.71k|            vrange->max = SSL_LIBRARY_VERSION_MAX_SUPPORTED;
  ------------------
  |  | 1497|  9.71k|#define SSL_LIBRARY_VERSION_MAX_SUPPORTED SSL_LIBRARY_VERSION_TLS_1_3
  |  |  ------------------
  |  |  |  |   21|  9.71k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  |  |  ------------------
  ------------------
 2767|  9.71k|            break;
 2768|      0|        default:
  ------------------
  |  Branch (2768:9): [True: 0, False: 19.4k]
  ------------------
 2769|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2770|      0|            return SECFailure;
 2771|  19.4k|    }
 2772|       |
 2773|  19.4k|    rv = ssl3_CreateOverlapWithPolicy(protocolVariant, vrange, vrange);
 2774|  19.4k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2774:9): [True: 0, False: 19.4k]
  ------------------
 2775|       |        /* Library default and policy don't overlap. */
 2776|      0|        return rv;
 2777|      0|    }
 2778|       |
 2779|       |    /* We don't allow SSLv3 and TLSv1.3 together */
 2780|  19.4k|    if (vrange->max >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  19.4k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (2780:9): [True: 19.4k, False: 0]
  ------------------
 2781|  19.4k|        vrange->min = PR_MAX(vrange->min, SSL_LIBRARY_VERSION_TLS_1_0);
  ------------------
  |  |  159|  19.4k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 9.71k, False: 9.71k]
  |  |  ------------------
  ------------------
 2782|  19.4k|    }
 2783|       |
 2784|  19.4k|    return SECSuccess;
 2785|  19.4k|}
SSL_VersionRangeSetDefault:
 2843|  19.4k|{
 2844|  19.4k|    SSLVersionRange constrainedRange;
 2845|  19.4k|    SECStatus rv;
 2846|       |
 2847|  19.4k|    if (!vrange) {
  ------------------
  |  Branch (2847:9): [True: 0, False: 19.4k]
  ------------------
 2848|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2849|      0|        return SECFailure;
 2850|      0|    }
 2851|       |
 2852|  19.4k|    constrainedRange = *vrange;
 2853|  19.4k|    rv = ssl3_CheckRangeValidAndConstrainByPolicy(protocolVariant,
 2854|  19.4k|                                                  &constrainedRange);
 2855|  19.4k|    if (rv != SECSuccess)
  ------------------
  |  Branch (2855:9): [True: 0, False: 19.4k]
  ------------------
 2856|      0|        return rv;
 2857|       |
 2858|  19.4k|    *VERSIONS_DEFAULTS(protocolVariant) = constrainedRange;
  ------------------
  |  |  117|  19.4k|    (variant == ssl_variant_stream ? &versions_defaults_stream : &versions_defaults_datagram)
  |  |  ------------------
  |  |  |  Branch (117:6): [True: 9.71k, False: 9.71k]
  |  |  ------------------
  ------------------
 2859|  19.4k|    return SECSuccess;
 2860|  19.4k|}
SSL_VersionRangeSet:
 2891|  3.96k|{
 2892|  3.96k|    SSLVersionRange constrainedRange;
 2893|  3.96k|    sslSocket *ss;
 2894|  3.96k|    SECStatus rv;
 2895|       |
 2896|  3.96k|    if (!vrange) {
  ------------------
  |  Branch (2896:9): [True: 0, False: 3.96k]
  ------------------
 2897|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2898|      0|        return SECFailure;
 2899|      0|    }
 2900|       |
 2901|  3.96k|    ss = ssl_FindSocket(fd);
 2902|  3.96k|    if (!ss) {
  ------------------
  |  Branch (2902:9): [True: 0, False: 3.96k]
  ------------------
 2903|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in SSL_VersionRangeSet",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 2904|      0|                 SSL_GETPID(), fd));
 2905|      0|        return SECFailure;
 2906|      0|    }
 2907|       |
 2908|  3.96k|    constrainedRange = *vrange;
 2909|  3.96k|    rv = ssl3_CheckRangeValidAndConstrainByPolicy(ss->protocolVariant,
 2910|  3.96k|                                                  &constrainedRange);
 2911|  3.96k|    if (rv != SECSuccess)
  ------------------
  |  Branch (2911:9): [True: 0, False: 3.96k]
  ------------------
 2912|      0|        return rv;
 2913|       |
 2914|  3.96k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  3.96k|    {                                                             \
  |  | 1391|  3.96k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 3.96k, False: 0]
  |  |  ------------------
  |  | 1392|  3.96k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  3.96k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  7.93k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 3.96k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 3.96k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  3.96k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  3.96k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  3.96k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  3.96k|        }                                                         \
  |  | 1396|  3.96k|    }
  ------------------
 2915|  3.96k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  3.96k|    {                                                 \
  |  | 1408|  3.96k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 3.96k, False: 0]
  |  |  ------------------
  |  | 1409|  3.96k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  3.96k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  3.96k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 3.96k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  3.96k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  3.96k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  3.96k|        }                                             \
  |  | 1412|  3.96k|    }
  ------------------
 2916|       |
 2917|  3.96k|    if (ss->ssl3.downgradeCheckVersion &&
  ------------------
  |  Branch (2917:9): [True: 0, False: 3.96k]
  ------------------
 2918|  3.96k|        ss->vrange.max > ss->ssl3.downgradeCheckVersion) {
  ------------------
  |  Branch (2918:9): [True: 0, False: 0]
  ------------------
 2919|      0|        PORT_SetError(SSL_ERROR_INVALID_VERSION_RANGE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2920|      0|        ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
 2921|      0|        ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|      0|    {                                                 \
  |  | 1399|      0|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1400|      0|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|      0|    }
  ------------------
 2922|      0|        return SECFailure;
 2923|      0|    }
 2924|       |
 2925|  3.96k|    ss->vrange = constrainedRange;
 2926|       |
 2927|  3.96k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  3.96k|    {                                                \
  |  | 1415|  3.96k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 3.96k, False: 0]
  |  |  ------------------
  |  | 1416|  3.96k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  3.96k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  3.96k|    }
  ------------------
 2928|  3.96k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  3.96k|    {                                                 \
  |  | 1399|  3.96k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 3.96k, False: 0]
  |  |  ------------------
  |  | 1400|  3.96k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  3.96k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  3.96k|    }
  ------------------
 2929|       |
 2930|  3.96k|    return SECSuccess;
 2931|  3.96k|}
ssl_GetPeerInfo:
 3281|  61.2k|{
 3282|  61.2k|    PRFileDesc *osfd;
 3283|  61.2k|    int rv;
 3284|  61.2k|    PRNetAddr sin;
 3285|       |
 3286|  61.2k|    osfd = ss->fd->lower;
 3287|       |
 3288|  61.2k|    PORT_Memset(&sin, 0, sizeof(sin));
  ------------------
  |  |  182|  61.2k|#define PORT_Memset memset
  ------------------
 3289|  61.2k|    rv = osfd->methods->getpeername(osfd, &sin);
 3290|  61.2k|    if (rv < 0) {
  ------------------
  |  Branch (3290:9): [True: 0, False: 61.2k]
  ------------------
 3291|      0|        return SECFailure;
 3292|      0|    }
 3293|  61.2k|    ss->TCPconnected = 1;
 3294|  61.2k|    if (sin.inet.family == PR_AF_INET) {
  ------------------
  |  |   96|  61.2k|#define PR_AF_INET AF_INET
  ------------------
  |  Branch (3294:9): [True: 61.2k, False: 0]
  ------------------
 3295|  61.2k|        PR_ConvertIPv4AddrToIPv6(sin.inet.ip, &ss->sec.ci.peer);
 3296|  61.2k|        ss->sec.ci.port = sin.inet.port;
 3297|  61.2k|    } else if (sin.ipv6.family == PR_AF_INET6) {
  ------------------
  |  |   27|      0|#define PR_AF_INET6 10  /* same as AF_INET6 */
  ------------------
  |  Branch (3297:16): [True: 0, False: 0]
  ------------------
 3298|      0|        ss->sec.ci.peer = sin.ipv6.ip;
 3299|      0|        ss->sec.ci.port = sin.ipv6.port;
 3300|      0|    } else {
 3301|      0|        PORT_SetError(PR_ADDRESS_NOT_SUPPORTED_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_ADDRESS_NOT_SUPPORTED_ERROR);
  ------------------
  |  |   61|      0|#define PR_ADDRESS_NOT_SUPPORTED_ERROR           (-5985L)
  ------------------
 3302|      0|        return SECFailure;
 3303|      0|    }
 3304|  61.2k|    return SECSuccess;
 3305|  61.2k|}
ssl_FdIsBlocking:
 3485|   169k|{
 3486|   169k|    PRSocketOptionData opt;
 3487|   169k|    PRStatus status;
 3488|       |
 3489|   169k|    opt.option = PR_SockOpt_Nonblocking;
 3490|   169k|    opt.value.non_blocking = PR_FALSE;
  ------------------
  |  |  438|   169k|#define PR_FALSE 0
  ------------------
 3491|   169k|    status = PR_GetSocketOption(fd, &opt);
 3492|   169k|    if (status != PR_SUCCESS)
  ------------------
  |  Branch (3492:9): [True: 0, False: 169k]
  ------------------
 3493|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3494|   169k|    return (PRBool)!opt.value.non_blocking;
 3495|   169k|}
ssl_SocketIsBlocking:
 3499|   169k|{
 3500|   169k|    return ssl_FdIsBlocking(ss->fd);
 3501|   169k|}
ssl_LookupNamedGroup:
 4001|  53.3k|{
 4002|  53.3k|    unsigned int i;
 4003|       |
 4004|   784k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|   784k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (4004:17): [True: 764k, False: 19.2k]
  ------------------
 4005|   764k|        if (ssl_named_groups[i].name == group) {
  ------------------
  |  Branch (4005:13): [True: 34.0k, False: 730k]
  ------------------
 4006|  34.0k|            return &ssl_named_groups[i];
 4007|  34.0k|        }
 4008|   764k|    }
 4009|  19.2k|    return NULL;
 4010|  53.3k|}
ssl_NamedGroupEnabled:
 4014|   765k|{
 4015|   765k|    unsigned int i;
 4016|       |
 4017|   765k|    if (!groupDef) {
  ------------------
  |  Branch (4017:9): [True: 0, False: 765k]
  ------------------
 4018|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4019|      0|    }
 4020|       |
 4021|  4.36M|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|  4.36M|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (4021:17): [True: 4.27M, False: 88.5k]
  ------------------
 4022|  4.27M|        if (ss->namedGroupPreferences[i] &&
  ------------------
  |  Branch (4022:13): [True: 1.11M, False: 3.15M]
  ------------------
 4023|  4.27M|            ss->namedGroupPreferences[i] == groupDef) {
  ------------------
  |  Branch (4023:13): [True: 677k, False: 440k]
  ------------------
 4024|   677k|            return PR_TRUE;
  ------------------
  |  |  437|   677k|#define PR_TRUE 1
  ------------------
 4025|   677k|        }
 4026|  4.27M|    }
 4027|  88.5k|    return PR_FALSE;
  ------------------
  |  |  438|  88.5k|#define PR_FALSE 0
  ------------------
 4028|   765k|}
ssl_NewKeyPair:
 4036|  47.3k|{
 4037|  47.3k|    sslKeyPair *pair;
 4038|       |
 4039|  47.3k|    if (!privKey || !pubKey) {
  ------------------
  |  Branch (4039:9): [True: 0, False: 47.3k]
  |  Branch (4039:21): [True: 0, False: 47.3k]
  ------------------
 4040|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
 4041|      0|        return NULL;
 4042|      0|    }
 4043|  47.3k|    pair = PORT_ZNew(sslKeyPair);
  ------------------
  |  |  148|  47.3k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  47.3k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 4044|  47.3k|    if (!pair)
  ------------------
  |  Branch (4044:9): [True: 0, False: 47.3k]
  ------------------
 4045|      0|        return NULL; /* error code is set. */
 4046|  47.3k|    pair->privKey = privKey;
 4047|  47.3k|    pair->pubKey = pubKey;
 4048|  47.3k|    pair->refCount = 1;
 4049|  47.3k|    return pair; /* success */
 4050|  47.3k|}
ssl_GetKeyPairRef:
 4054|  19.4k|{
 4055|  19.4k|    PR_ATOMIC_INCREMENT(&keyPair->refCount);
  ------------------
  |  |  122|  19.4k|#define PR_ATOMIC_INCREMENT(val) __sync_add_and_fetch(val, 1)
  ------------------
 4056|  19.4k|    return keyPair;
 4057|  19.4k|}
ssl_FreeKeyPair:
 4061|   114k|{
 4062|   114k|    if (!keyPair) {
  ------------------
  |  Branch (4062:9): [True: 47.3k, False: 66.7k]
  ------------------
 4063|  47.3k|        return;
 4064|  47.3k|    }
 4065|       |
 4066|  66.7k|    PRInt32 newCount = PR_ATOMIC_DECREMENT(&keyPair->refCount);
  ------------------
  |  |  123|  66.7k|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
 4067|  66.7k|    if (!newCount) {
  ------------------
  |  Branch (4067:9): [True: 47.3k, False: 19.4k]
  ------------------
 4068|  47.3k|        SECKEY_DestroyPrivateKey(keyPair->privKey);
 4069|  47.3k|        SECKEY_DestroyPublicKey(keyPair->pubKey);
 4070|  47.3k|        PORT_Free(keyPair);
  ------------------
  |  |   60|  47.3k|#define PORT_Free PORT_Free_Util
  ------------------
 4071|  47.3k|    }
 4072|  66.7k|}
ssl_NewEphemeralKeyPair:
 4078|  47.3k|{
 4079|  47.3k|    sslKeyPair *keys;
 4080|  47.3k|    sslEphemeralKeyPair *pair;
 4081|       |
 4082|  47.3k|    if (!group) {
  ------------------
  |  Branch (4082:9): [True: 0, False: 47.3k]
  ------------------
 4083|      0|        PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_INVALID_ARGUMENT_ERROR);
  ------------------
  |  |   55|      0|#define PR_INVALID_ARGUMENT_ERROR                (-5987L)
  ------------------
 4084|      0|        return NULL;
 4085|      0|    }
 4086|       |
 4087|  47.3k|    keys = ssl_NewKeyPair(privKey, pubKey);
 4088|  47.3k|    if (!keys) {
  ------------------
  |  Branch (4088:9): [True: 0, False: 47.3k]
  ------------------
 4089|      0|        return NULL;
 4090|      0|    }
 4091|       |
 4092|  47.3k|    pair = PORT_ZNew(sslEphemeralKeyPair);
  ------------------
  |  |  148|  47.3k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  47.3k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 4093|  47.3k|    if (!pair) {
  ------------------
  |  Branch (4093:9): [True: 0, False: 47.3k]
  ------------------
 4094|      0|        ssl_FreeKeyPair(keys);
 4095|      0|        return NULL; /* error already set */
 4096|      0|    }
 4097|       |
 4098|  47.3k|    PR_INIT_CLIST(&pair->link);
  ------------------
  |  |  100|  94.6k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  47.3k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  94.6k|    (_l)->next = (_l); \
  |  |  102|  94.6k|    (_l)->prev = (_l); \
  |  |  103|  94.6k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  47.3k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4099|  47.3k|    pair->group = group;
 4100|  47.3k|    pair->keys = keys;
 4101|  47.3k|    pair->kemKeys = NULL;
 4102|  47.3k|    pair->kemCt = NULL;
 4103|       |
 4104|  47.3k|    return pair;
 4105|  47.3k|}
ssl_FreeEphemeralKeyPair:
 4136|  47.3k|{
 4137|  47.3k|    if (!keyPair) {
  ------------------
  |  Branch (4137:9): [True: 0, False: 47.3k]
  ------------------
 4138|      0|        return;
 4139|      0|    }
 4140|       |
 4141|  47.3k|    ssl_FreeKeyPair(keyPair->keys);
 4142|  47.3k|    ssl_FreeKeyPair(keyPair->kemKeys);
 4143|  47.3k|    SECITEM_FreeItem(keyPair->kemCt, PR_TRUE);
  ------------------
  |  |  108|  47.3k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(keyPair->kemCt, PR_TRUE);
  ------------------
  |  |  437|  47.3k|#define PR_TRUE 1
  ------------------
 4144|  47.3k|    PR_REMOVE_LINK(&keyPair->link);
  ------------------
  |  |   72|  47.3k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|  47.3k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|  47.3k|    (_e)->prev->next = (_e)->next; \
  |  |   74|  47.3k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|  47.3k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  47.3k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4145|  47.3k|    PORT_Free(keyPair);
  ------------------
  |  |   60|  47.3k|#define PORT_Free PORT_Free_Util
  ------------------
 4146|  47.3k|}
ssl_LookupEphemeralKeyPair:
 4156|  1.27k|{
 4157|  1.27k|    PRCList *cursor;
 4158|  1.27k|    for (cursor = PR_NEXT_LINK(&ss->ephemeralKeyPairs);
  ------------------
  |  |   47|  1.27k|        ((_e)->next)
  ------------------
 4159|  1.27k|         cursor != &ss->ephemeralKeyPairs;
  ------------------
  |  Branch (4159:10): [True: 0, False: 1.27k]
  ------------------
 4160|  1.27k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
 4161|      0|        sslEphemeralKeyPair *keyPair = (sslEphemeralKeyPair *)cursor;
 4162|      0|        if (keyPair->group == groupDef) {
  ------------------
  |  Branch (4162:13): [True: 0, False: 0]
  ------------------
 4163|      0|            return keyPair;
 4164|      0|        }
 4165|      0|    }
 4166|  1.27k|    return NULL;
 4167|  1.27k|}
ssl_FreeEphemeralKeyPairs:
 4171|   146k|{
 4172|   193k|    while (!PR_CLIST_IS_EMPTY(&ss->ephemeralKeyPairs)) {
  ------------------
  |  |   94|   193k|    ((_l)->next == (_l))
  ------------------
  |  Branch (4172:12): [True: 47.3k, False: 146k]
  ------------------
 4173|  47.3k|        PRCList *cursor = PR_LIST_TAIL(&ss->ephemeralKeyPairs);
  ------------------
  |  |   66|  47.3k|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
 4174|  47.3k|        ssl_FreeEphemeralKeyPair((sslEphemeralKeyPair *)cursor);
 4175|  47.3k|    }
 4176|   146k|}
ssl_Time:
 4180|  67.2k|{
 4181|  67.2k|    if (!ss->now) {
  ------------------
  |  Branch (4181:9): [True: 0, False: 67.2k]
  ------------------
 4182|      0|        return PR_Now();
 4183|      0|    }
 4184|  67.2k|    return ss->now(ss->nowArg);
 4185|  67.2k|}
SSL_GetExperimentalAPI:
 4390|  58.1k|{
 4391|  58.1k|    unsigned int i;
 4392|  1.76M|    for (i = 0; i < PR_ARRAY_SIZE(ssl_experimental_functions); ++i) {
  ------------------
  |  |  167|  1.76M|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (4392:17): [True: 1.76M, False: 0]
  ------------------
 4393|  1.76M|        if (strcmp(name, ssl_experimental_functions[i].name) == 0) {
  ------------------
  |  Branch (4393:13): [True: 58.1k, False: 1.70M]
  ------------------
 4394|  58.1k|            return ssl_experimental_functions[i].function;
 4395|  58.1k|        }
 4396|  1.76M|    }
 4397|      0|    PORT_SetError(SSL_ERROR_UNSUPPORTED_EXPERIMENTAL_API);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4398|      0|    return NULL;
 4399|  58.1k|}
ssl_ClearPRCList:
 4403|  29.1k|{
 4404|  29.1k|    PRCList *cursor;
 4405|       |
 4406|  29.1k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|  29.1k|    ((_l)->next == (_l))
  ------------------
  |  Branch (4406:12): [True: 0, False: 29.1k]
  ------------------
 4407|      0|        cursor = PR_LIST_TAIL(list);
  ------------------
  |  |   66|      0|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
 4408|       |
 4409|      0|        PR_REMOVE_LINK(cursor);
  ------------------
  |  |   72|      0|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      0|    (_e)->prev->next = (_e)->next; \
  |  |   74|      0|    (_e)->next->prev = (_e)->prev; \
  |  |   75|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4410|      0|        if (f) {
  ------------------
  |  Branch (4410:13): [True: 0, False: 0]
  ------------------
 4411|      0|            f(cursor);
 4412|      0|        }
 4413|      0|        PORT_Free(cursor);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 4414|      0|    }
 4415|  29.1k|}
SSLExp_EnableTls13BackendEch:
 4448|  9.71k|{
 4449|  9.71k|    sslSocket *ss = ssl_FindSocket(fd);
 4450|  9.71k|    if (!ss) {
  ------------------
  |  Branch (4450:9): [True: 0, False: 9.71k]
  ------------------
 4451|      0|        return SECFailure;
 4452|      0|    }
 4453|  9.71k|    ss->opt.enableTls13BackendEch = enabled;
 4454|  9.71k|    return SECSuccess;
 4455|  9.71k|}
SSLExp_SetTimeFunc:
 4481|  9.71k|{
 4482|  9.71k|    sslSocket *ss = ssl_FindSocket(fd);
 4483|       |
 4484|  9.71k|    if (!ss) {
  ------------------
  |  Branch (4484:9): [True: 0, False: 9.71k]
  ------------------
 4485|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in SSL_SetTimeFunc",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 4486|      0|                 SSL_GETPID(), fd));
 4487|      0|        return SECFailure;
 4488|      0|    }
 4489|  9.71k|    ss->now = f;
 4490|  9.71k|    ss->nowArg = arg;
 4491|  9.71k|    return SECSuccess;
 4492|  9.71k|}
sslsock.c:ssl_DestroySocketContents:
  465|  9.71k|{
  466|  9.71k|    PRCList *cursor;
  467|       |
  468|       |    /* Free up socket */
  469|  9.71k|    ssl_DestroySecurityInfo(&ss->sec);
  470|       |
  471|  9.71k|    ssl3_DestroySSL3Info(ss);
  472|       |
  473|  9.71k|    PORT_Free(ss->saveBuf.buf);
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
  474|  9.71k|    PORT_Free(ss->pendingBuf.buf);
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
  475|  9.71k|    ssl3_DestroyGather(&ss->gs);
  476|       |
  477|  9.71k|    if (ss->peerID != NULL)
  ------------------
  |  Branch (477:9): [True: 0, False: 9.71k]
  ------------------
  478|      0|        PORT_Free(ss->peerID);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  479|  9.71k|    if (ss->url != NULL)
  ------------------
  |  Branch (479:9): [True: 9.71k, False: 1]
  ------------------
  480|  9.71k|        PORT_Free((void *)ss->url); /* CONST */
  ------------------
  |  |   60|  9.71k|#define PORT_Free PORT_Free_Util
  ------------------
  481|       |
  482|       |    /* Clean up server certificates and sundries. */
  483|  29.1k|    while (!PR_CLIST_IS_EMPTY(&ss->serverCerts)) {
  ------------------
  |  |   94|  29.1k|    ((_l)->next == (_l))
  ------------------
  |  Branch (483:12): [True: 19.4k, False: 9.71k]
  ------------------
  484|  19.4k|        cursor = PR_LIST_TAIL(&ss->serverCerts);
  ------------------
  |  |   66|  19.4k|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
  485|  19.4k|        PR_REMOVE_LINK(cursor);
  ------------------
  |  |   72|  19.4k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|  19.4k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|  19.4k|    (_e)->prev->next = (_e)->next; \
  |  |   74|  19.4k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|  19.4k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  19.4k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  486|  19.4k|        ssl_FreeServerCert((sslServerCert *)cursor);
  487|  19.4k|    }
  488|       |
  489|       |    /* Remove extension handlers. */
  490|  9.71k|    ssl_ClearPRCList(&ss->extensionHooks, NULL);
  491|       |
  492|  9.71k|    ssl_FreeEphemeralKeyPairs(ss);
  493|  9.71k|    SECITEM_FreeItem(&ss->opt.nextProtoNego, PR_FALSE);
  ------------------
  |  |  108|  9.71k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&ss->opt.nextProtoNego, PR_FALSE);
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
  494|  9.71k|    ssl3_FreeSniNameArray(&ss->xtnData);
  495|       |
  496|  9.71k|    ssl_ClearPRCList(&ss->ssl3.hs.dtlsSentHandshake, NULL);
  497|  9.71k|    ssl_ClearPRCList(&ss->ssl3.hs.dtlsRcvdHandshake, NULL);
  498|  9.71k|    tls13_DestroyPskList(&ss->ssl3.hs.psks);
  499|       |
  500|  9.71k|    tls13_ReleaseAntiReplayContext(ss->antiReplay);
  501|       |
  502|  9.71k|    tls13_DestroyPsk(ss->psk);
  503|       |
  504|  9.71k|    tls13_DestroyEchConfigs(&ss->echConfigs);
  505|  9.71k|    SECKEY_DestroyPrivateKey(ss->echPrivKey);
  506|  9.71k|    SECKEY_DestroyPublicKey(ss->echPubKey);
  507|  9.71k|}
sslsock.c:ssl_DestroyLocks:
  429|  9.71k|{
  430|       |    /* Destroy locks. */
  431|  9.71k|    if (ss->firstHandshakeLock) {
  ------------------
  |  Branch (431:9): [True: 9.71k, False: 0]
  ------------------
  432|  9.71k|        PZ_DestroyMonitor(ss->firstHandshakeLock);
  ------------------
  |  |  255|  9.71k|#define PZ_DestroyMonitor(m) PR_DestroyMonitor((m))
  ------------------
  433|  9.71k|        ss->firstHandshakeLock = NULL;
  434|  9.71k|    }
  435|  9.71k|    if (ss->ssl3HandshakeLock) {
  ------------------
  |  Branch (435:9): [True: 9.71k, False: 0]
  ------------------
  436|  9.71k|        PZ_DestroyMonitor(ss->ssl3HandshakeLock);
  ------------------
  |  |  255|  9.71k|#define PZ_DestroyMonitor(m) PR_DestroyMonitor((m))
  ------------------
  437|  9.71k|        ss->ssl3HandshakeLock = NULL;
  438|  9.71k|    }
  439|  9.71k|    if (ss->specLock) {
  ------------------
  |  Branch (439:9): [True: 9.71k, False: 0]
  ------------------
  440|  9.71k|        NSSRWLock_Destroy(ss->specLock);
  ------------------
  |  |   45|  9.71k|#define NSSRWLock_Destroy NSSRWLock_Destroy_Util
  ------------------
  441|  9.71k|        ss->specLock = NULL;
  442|  9.71k|    }
  443|       |
  444|  9.71k|    if (ss->recvLock) {
  ------------------
  |  Branch (444:9): [True: 9.71k, False: 0]
  ------------------
  445|  9.71k|        PZ_DestroyLock(ss->recvLock);
  ------------------
  |  |  244|  9.71k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  446|  9.71k|        ss->recvLock = NULL;
  447|  9.71k|    }
  448|  9.71k|    if (ss->sendLock) {
  ------------------
  |  Branch (448:9): [True: 9.71k, False: 0]
  ------------------
  449|  9.71k|        PZ_DestroyLock(ss->sendLock);
  ------------------
  |  |  244|  9.71k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  450|  9.71k|        ss->sendLock = NULL;
  451|  9.71k|    }
  452|  9.71k|    if (ss->xmitBufLock) {
  ------------------
  |  Branch (452:9): [True: 9.71k, False: 0]
  ------------------
  453|  9.71k|        PZ_DestroyMonitor(ss->xmitBufLock);
  ------------------
  |  |  255|  9.71k|#define PZ_DestroyMonitor(m) PR_DestroyMonitor((m))
  ------------------
  454|  9.71k|        ss->xmitBufLock = NULL;
  455|  9.71k|    }
  456|  9.71k|    if (ss->recvBufLock) {
  ------------------
  |  Branch (456:9): [True: 9.71k, False: 0]
  ------------------
  457|  9.71k|        PZ_DestroyMonitor(ss->recvBufLock);
  ------------------
  |  |  255|  9.71k|#define PZ_DestroyMonitor(m) PR_DestroyMonitor((m))
  ------------------
  458|  9.71k|        ss->recvBufLock = NULL;
  459|  9.71k|    }
  460|  9.71k|}
sslsock.c:ssl_ChooseOps:
  568|  9.71k|{
  569|  9.71k|    ss->ops = ss->opt.useSecurity ? &ssl_secure_ops : &ssl_default_ops;
  ------------------
  |  Branch (569:15): [True: 9.71k, False: 0]
  ------------------
  570|  9.71k|}
sslsock.c:ssl_IsRemovedCipherSuite:
 1440|   690k|{
 1441|   690k|    switch (suite) {
 1442|      0|        case SSL_FORTEZZA_DMS_WITH_NULL_SHA:
  ------------------
  |  |  275|      0|#define SSL_FORTEZZA_DMS_WITH_NULL_SHA          0x001c
  ------------------
  |  Branch (1442:9): [True: 0, False: 690k]
  ------------------
 1443|      0|        case SSL_FORTEZZA_DMS_WITH_FORTEZZA_CBC_SHA:
  ------------------
  |  |  276|      0|#define SSL_FORTEZZA_DMS_WITH_FORTEZZA_CBC_SHA  0x001d
  ------------------
  |  Branch (1443:9): [True: 0, False: 690k]
  ------------------
 1444|      0|        case SSL_FORTEZZA_DMS_WITH_RC4_128_SHA:
  ------------------
  |  |  277|      0|#define SSL_FORTEZZA_DMS_WITH_RC4_128_SHA       0x001e
  ------------------
  |  Branch (1444:9): [True: 0, False: 690k]
  ------------------
 1445|      0|            return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1446|   690k|        default:
  ------------------
  |  Branch (1446:9): [True: 690k, False: 0]
  ------------------
 1447|   690k|            return PR_FALSE;
  ------------------
  |  |  438|   690k|#define PR_FALSE 0
  ------------------
 1448|   690k|    }
 1449|   690k|}
sslsock.c:ssl_ImportFD:
 2153|  9.71k|{
 2154|  9.71k|    sslSocket *ns = NULL;
 2155|  9.71k|    PRStatus rv;
 2156|  9.71k|    PRNetAddr addr;
 2157|  9.71k|    SECStatus status = ssl_Init();
 2158|       |
 2159|  9.71k|    if (status != SECSuccess) {
  ------------------
  |  Branch (2159:9): [True: 0, False: 9.71k]
  ------------------
 2160|      0|        return NULL;
 2161|      0|    }
 2162|       |
 2163|  9.71k|    if (model == NULL) {
  ------------------
  |  Branch (2163:9): [True: 1, False: 9.71k]
  ------------------
 2164|       |        /* Just create a default socket if we're given NULL for the model */
 2165|      1|        ns = ssl_NewSocket((PRBool)(!ssl_defaults.noLocks), variant);
 2166|  9.71k|    } else {
 2167|  9.71k|        sslSocket *ss = ssl_FindSocket(model);
 2168|  9.71k|        if (ss == NULL || ss->protocolVariant != variant) {
  ------------------
  |  Branch (2168:13): [True: 0, False: 9.71k]
  |  Branch (2168:27): [True: 0, False: 9.71k]
  ------------------
 2169|      0|            SSL_DBG(("%d: SSL[%d]: bad model socket in ssl_ImportFD",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 2170|      0|                     SSL_GETPID(), model));
 2171|      0|            return NULL;
 2172|      0|        }
 2173|  9.71k|        ns = ssl_DupSocket(ss);
 2174|  9.71k|    }
 2175|  9.71k|    if (ns == NULL)
  ------------------
  |  Branch (2175:9): [True: 0, False: 9.71k]
  ------------------
 2176|      0|        return NULL;
 2177|       |
 2178|  9.71k|    rv = ssl_PushIOLayer(ns, fd, PR_TOP_IO_LAYER);
  ------------------
  |  |  453|  9.71k|#define PR_TOP_IO_LAYER (PRDescIdentity)-2
  ------------------
 2179|  9.71k|    if (rv != PR_SUCCESS) {
  ------------------
  |  Branch (2179:9): [True: 0, False: 9.71k]
  ------------------
 2180|      0|        ssl_FreeSocket(ns);
 2181|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2182|      0|        return NULL;
 2183|      0|    }
 2184|  9.71k|#if defined(DEBUG) || defined(FORCE_PR_ASSERT)
 2185|  9.71k|    {
 2186|  9.71k|        sslSocket *ss = ssl_FindSocket(fd);
 2187|  9.71k|        PORT_Assert(ss == ns);
  ------------------
  |  |  120|  9.71k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.71k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.71k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2188|  9.71k|    }
 2189|  9.71k|#endif
 2190|  9.71k|    ns->TCPconnected = (PR_SUCCESS == ssl_DefGetpeername(ns, &addr));
 2191|  9.71k|    return fd;
 2192|  9.71k|}
sslsock.c:ssl_NewSocket:
 4192|  9.71k|{
 4193|  9.71k|    SECStatus rv;
 4194|  9.71k|    sslSocket *ss;
 4195|  9.71k|    int i;
 4196|  9.71k|    ssl_SetDefaultsFromEnvironment();
 4197|       |
 4198|  9.71k|    if (ssl_force_locks)
  ------------------
  |  Branch (4198:9): [True: 0, False: 9.71k]
  ------------------
 4199|      0|        makeLocks = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 4200|       |
 4201|       |    /* Make a new socket and get it ready */
 4202|  9.71k|    ss = PORT_ZNew(sslSocket);
  ------------------
  |  |  148|  9.71k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  9.71k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 4203|  9.71k|    if (!ss) {
  ------------------
  |  Branch (4203:9): [True: 0, False: 9.71k]
  ------------------
 4204|      0|        return NULL;
 4205|      0|    }
 4206|  9.71k|    ss->opt = ssl_defaults;
 4207|  9.71k|    if (protocolVariant == ssl_variant_datagram) {
  ------------------
  |  Branch (4207:9): [True: 0, False: 9.71k]
  ------------------
 4208|      0|        ss->opt.enableRenegotiation = SSL_RENEGOTIATE_NEVER;
  ------------------
  |  |  711|      0|#define SSL_RENEGOTIATE_NEVER ((PRBool)0)
  ------------------
 4209|      0|    }
 4210|  9.71k|    ss->opt.useSocks = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
 4211|  9.71k|    ss->opt.noLocks = !makeLocks;
 4212|  9.71k|    ss->vrange = *VERSIONS_DEFAULTS(protocolVariant);
  ------------------
  |  |  117|  9.71k|    (variant == ssl_variant_stream ? &versions_defaults_stream : &versions_defaults_datagram)
  |  |  ------------------
  |  |  |  Branch (117:6): [True: 9.71k, False: 0]
  |  |  ------------------
  ------------------
 4213|  9.71k|    ss->protocolVariant = protocolVariant;
 4214|       |    /* Ignore overlap failures, because returning NULL would trigger assertion
 4215|       |     * failures elsewhere. We don't want this scenario to be fatal, it's just
 4216|       |     * a state where no SSL connectivity is possible. */
 4217|  9.71k|    ssl3_CreateOverlapWithPolicy(ss->protocolVariant, &ss->vrange, &ss->vrange);
 4218|  9.71k|    ss->peerID = NULL;
 4219|  9.71k|    ss->rTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|  9.71k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 4220|  9.71k|    ss->wTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|  9.71k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 4221|  9.71k|    ss->cTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|  9.71k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 4222|  9.71k|    ss->url = NULL;
 4223|       |
 4224|  9.71k|    PR_INIT_CLIST(&ss->serverCerts);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4225|  9.71k|    PR_INIT_CLIST(&ss->ephemeralKeyPairs);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4226|  9.71k|    PR_INIT_CLIST(&ss->extensionHooks);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4227|  9.71k|    PR_INIT_CLIST(&ss->echConfigs);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4228|       |
 4229|  9.71k|    ss->dbHandle = CERT_GetDefaultCertDB();
 4230|       |
 4231|       |    /* Provide default implementation of hooks */
 4232|  9.71k|    ss->authCertificate = SSL_AuthCertificate;
 4233|  9.71k|    ss->authCertificateArg = (void *)ss->dbHandle;
 4234|  9.71k|    ss->sniSocketConfig = NULL;
 4235|  9.71k|    ss->sniSocketConfigArg = NULL;
 4236|  9.71k|    ss->getClientAuthData = NULL;
 4237|  9.71k|    ss->alertReceivedCallback = NULL;
 4238|  9.71k|    ss->alertReceivedCallbackArg = NULL;
 4239|  9.71k|    ss->alertSentCallback = NULL;
 4240|  9.71k|    ss->alertSentCallbackArg = NULL;
 4241|  9.71k|    ss->handleBadCert = NULL;
 4242|  9.71k|    ss->badCertArg = NULL;
 4243|  9.71k|    ss->pkcs11PinArg = NULL;
 4244|       |
 4245|  9.71k|    ssl_ChooseOps(ss);
 4246|  9.71k|    ssl3_InitSocketPolicy(ss);
 4247|   330k|    for (i = 0; i < SSL_NAMED_GROUP_COUNT; ++i) {
  ------------------
  |  |  133|   330k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (4247:17): [True: 320k, False: 9.71k]
  ------------------
 4248|   320k|        ss->namedGroupPreferences[i] = &ssl_named_groups[i];
 4249|   320k|    }
 4250|  9.71k|    ss->additionalShares = 0;
 4251|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.remoteExtensions);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4252|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.lastMessageFlight);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4253|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.cipherSpecs);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4254|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.bufferedEarlyData);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4255|  9.71k|    ssl3_InitExtensionData(&ss->xtnData, ss);
 4256|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.dtlsSentHandshake);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4257|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.dtlsRcvdHandshake);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4258|  9.71k|    PR_INIT_CLIST(&ss->ssl3.hs.psks);
  ------------------
  |  |  100|  9.71k|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|  9.71k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|  9.71k|    (_l)->next = (_l); \
  |  |  102|  9.71k|    (_l)->prev = (_l); \
  |  |  103|  9.71k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.71k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4259|  9.71k|    dtls_InitTimers(ss);
 4260|       |
 4261|  9.71k|    ss->echPrivKey = NULL;
 4262|  9.71k|    ss->echPubKey = NULL;
 4263|  9.71k|    ss->antiReplay = NULL;
 4264|  9.71k|    ss->psk = NULL;
 4265|       |
 4266|  9.71k|    if (makeLocks) {
  ------------------
  |  Branch (4266:9): [True: 9.71k, False: 0]
  ------------------
 4267|  9.71k|        rv = ssl_MakeLocks(ss);
 4268|  9.71k|        if (rv != SECSuccess)
  ------------------
  |  Branch (4268:13): [True: 0, False: 9.71k]
  ------------------
 4269|      0|            goto loser;
 4270|  9.71k|    }
 4271|  9.71k|    rv = ssl_CreateSecurityInfo(ss);
 4272|  9.71k|    if (rv != SECSuccess)
  ------------------
  |  Branch (4272:9): [True: 0, False: 9.71k]
  ------------------
 4273|      0|        goto loser;
 4274|  9.71k|    rv = ssl3_InitGather(&ss->gs);
 4275|  9.71k|    if (rv != SECSuccess)
  ------------------
  |  Branch (4275:9): [True: 0, False: 9.71k]
  ------------------
 4276|      0|        goto loser;
 4277|  9.71k|    rv = ssl3_InitState(ss);
 4278|  9.71k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4278:9): [True: 0, False: 9.71k]
  ------------------
 4279|      0|        goto loser;
 4280|      0|    }
 4281|  9.71k|    return ss;
 4282|       |
 4283|      0|loser:
 4284|      0|    ssl_DestroySocketContents(ss);
 4285|      0|    ssl_DestroyLocks(ss);
 4286|      0|    PORT_Free(ss);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 4287|      0|    return NULL;
 4288|  9.71k|}
sslsock.c:ssl_DupSocket:
  275|  9.71k|{
  276|  9.71k|    sslSocket *ss;
  277|  9.71k|    SECStatus rv;
  278|       |
  279|  9.71k|    ss = ssl_NewSocket((PRBool)(!os->opt.noLocks), os->protocolVariant);
  280|  9.71k|    if (!ss) {
  ------------------
  |  Branch (280:9): [True: 0, False: 9.71k]
  ------------------
  281|      0|        return NULL;
  282|      0|    }
  283|       |
  284|  9.71k|    ss->opt = os->opt;
  285|  9.71k|    ss->opt.useSocks = PR_FALSE;
  ------------------
  |  |  438|  9.71k|#define PR_FALSE 0
  ------------------
  286|  9.71k|    rv = SECITEM_CopyItem(NULL, &ss->opt.nextProtoNego, &os->opt.nextProtoNego);
  ------------------
  |  |  106|  9.71k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  287|  9.71k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (287:9): [True: 0, False: 9.71k]
  ------------------
  288|      0|        goto loser;
  289|      0|    }
  290|  9.71k|    ss->vrange = os->vrange;
  291|  9.71k|    ss->now = os->now;
  292|  9.71k|    ss->nowArg = os->nowArg;
  293|       |
  294|  9.71k|    ss->peerID = !os->peerID ? NULL : PORT_Strdup(os->peerID);
  ------------------
  |  |   69|      0|#define PORT_Strdup PORT_Strdup_Util
  ------------------
  |  Branch (294:18): [True: 9.71k, False: 0]
  ------------------
  295|  9.71k|    ss->url = !os->url ? NULL : PORT_Strdup(os->url);
  ------------------
  |  |   69|      0|#define PORT_Strdup PORT_Strdup_Util
  ------------------
  |  Branch (295:15): [True: 9.71k, False: 0]
  ------------------
  296|       |
  297|  9.71k|    ss->ops = os->ops;
  298|  9.71k|    ss->rTimeout = os->rTimeout;
  299|  9.71k|    ss->wTimeout = os->wTimeout;
  300|  9.71k|    ss->cTimeout = os->cTimeout;
  301|  9.71k|    ss->dbHandle = os->dbHandle;
  302|       |
  303|       |    /* copy ssl2&3 policy & prefs, even if it's not selected (yet) */
  304|  9.71k|    PORT_Memcpy(ss->cipherSuites, os->cipherSuites, sizeof os->cipherSuites);
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
  305|  9.71k|    PORT_Memcpy(ss->ssl3.dtlsSRTPCiphers, os->ssl3.dtlsSRTPCiphers,
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
  306|  9.71k|                sizeof(PRUint16) * os->ssl3.dtlsSRTPCipherCount);
  307|  9.71k|    ss->ssl3.dtlsSRTPCipherCount = os->ssl3.dtlsSRTPCipherCount;
  308|  9.71k|    PORT_Memcpy(ss->ssl3.signatureSchemes, os->ssl3.signatureSchemes,
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
  309|  9.71k|                sizeof(ss->ssl3.signatureSchemes[0]) *
  310|  9.71k|                    os->ssl3.signatureSchemeCount);
  311|  9.71k|    ss->ssl3.signatureSchemeCount = os->ssl3.signatureSchemeCount;
  312|  9.71k|    ss->ssl3.downgradeCheckVersion = os->ssl3.downgradeCheckVersion;
  313|       |
  314|  9.71k|    ss->ssl3.dheWeakGroupEnabled = os->ssl3.dheWeakGroupEnabled;
  315|       |
  316|  9.71k|    PORT_Memcpy(ss->ssl3.supportedCertCompressionAlgorithms,
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
  317|  9.71k|                os->ssl3.supportedCertCompressionAlgorithms,
  318|  9.71k|                sizeof(ss->ssl3.supportedCertCompressionAlgorithms[0]) *
  319|  9.71k|                    os->ssl3.supportedCertCompressionAlgorithmsCount);
  320|  9.71k|    ss->ssl3.supportedCertCompressionAlgorithmsCount =
  321|  9.71k|        os->ssl3.supportedCertCompressionAlgorithmsCount;
  322|       |
  323|  9.71k|    if (ss->opt.useSecurity) {
  ------------------
  |  Branch (323:9): [True: 9.71k, False: 0]
  ------------------
  324|  9.71k|        PRCList *cursor;
  325|       |
  326|  9.71k|        for (cursor = PR_NEXT_LINK(&os->serverCerts);
  ------------------
  |  |   47|  9.71k|        ((_e)->next)
  ------------------
  327|  29.1k|             cursor != &os->serverCerts;
  ------------------
  |  Branch (327:14): [True: 19.4k, False: 9.71k]
  ------------------
  328|  19.4k|             cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|  19.4k|        ((_e)->next)
  ------------------
  329|  19.4k|            sslServerCert *sc = ssl_CopyServerCert((sslServerCert *)cursor);
  330|  19.4k|            if (!sc)
  ------------------
  |  Branch (330:17): [True: 0, False: 19.4k]
  ------------------
  331|      0|                goto loser;
  332|  19.4k|            PR_APPEND_LINK(&sc->link, &ss->serverCerts);
  ------------------
  |  |   57|  19.4k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|  38.8k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|  19.4k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|  38.8k|    (_e)->next = (_l);   \
  |  |  |  |   27|  38.8k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|  38.8k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|  38.8k|    (_l)->prev = (_e);   \
  |  |  |  |   30|  38.8k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|  19.4k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  333|  19.4k|        }
  334|       |
  335|  9.71k|        for (cursor = PR_NEXT_LINK(&os->ephemeralKeyPairs);
  ------------------
  |  |   47|  9.71k|        ((_e)->next)
  ------------------
  336|  9.71k|             cursor != &os->ephemeralKeyPairs;
  ------------------
  |  Branch (336:14): [True: 0, False: 9.71k]
  ------------------
  337|  9.71k|             cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  338|      0|            sslEphemeralKeyPair *okp = (sslEphemeralKeyPair *)cursor;
  339|      0|            sslEphemeralKeyPair *skp = ssl_CopyEphemeralKeyPair(okp);
  340|      0|            if (!skp)
  ------------------
  |  Branch (340:17): [True: 0, False: 0]
  ------------------
  341|      0|                goto loser;
  342|      0|            PR_APPEND_LINK(&skp->link, &ss->ephemeralKeyPairs);
  ------------------
  |  |   57|      0|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|      0|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|      0|    (_e)->next = (_l);   \
  |  |  |  |   27|      0|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|      0|    (_l)->prev->next = (_e); \
  |  |  |  |   29|      0|    (_l)->prev = (_e);   \
  |  |  |  |   30|      0|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  343|      0|        }
  344|       |
  345|  9.71k|        for (cursor = PR_NEXT_LINK(&os->extensionHooks);
  ------------------
  |  |   47|  9.71k|        ((_e)->next)
  ------------------
  346|  9.71k|             cursor != &os->extensionHooks;
  ------------------
  |  Branch (346:14): [True: 0, False: 9.71k]
  ------------------
  347|  9.71k|             cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  348|      0|            sslCustomExtensionHooks *oh = (sslCustomExtensionHooks *)cursor;
  349|      0|            sslCustomExtensionHooks *sh = PORT_ZNew(sslCustomExtensionHooks);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  350|      0|            if (!sh) {
  ------------------
  |  Branch (350:17): [True: 0, False: 0]
  ------------------
  351|      0|                goto loser;
  352|      0|            }
  353|      0|            *sh = *oh;
  354|      0|            PR_APPEND_LINK(&sh->link, &ss->extensionHooks);
  ------------------
  |  |   57|      0|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|      0|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|      0|    (_e)->next = (_l);   \
  |  |  |  |   27|      0|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|      0|    (_l)->prev->next = (_e); \
  |  |  |  |   29|      0|    (_l)->prev = (_e);   \
  |  |  |  |   30|      0|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  355|      0|        }
  356|       |
  357|       |        /*
  358|       |         * XXX the preceding CERT_ and SECKEY_ functions can fail and return NULL.
  359|       |         * XXX We should detect this, and not just march on with NULL pointers.
  360|       |         */
  361|  9.71k|        ss->authCertificate = os->authCertificate;
  362|  9.71k|        ss->authCertificateArg = os->authCertificateArg;
  363|  9.71k|        ss->getClientAuthData = os->getClientAuthData;
  364|  9.71k|        ss->getClientAuthDataArg = os->getClientAuthDataArg;
  365|  9.71k|        ss->sniSocketConfig = os->sniSocketConfig;
  366|  9.71k|        ss->sniSocketConfigArg = os->sniSocketConfigArg;
  367|  9.71k|        ss->alertReceivedCallback = os->alertReceivedCallback;
  368|  9.71k|        ss->alertReceivedCallbackArg = os->alertReceivedCallbackArg;
  369|  9.71k|        ss->alertSentCallback = os->alertSentCallback;
  370|  9.71k|        ss->alertSentCallbackArg = os->alertSentCallbackArg;
  371|  9.71k|        ss->handleBadCert = os->handleBadCert;
  372|  9.71k|        ss->badCertArg = os->badCertArg;
  373|  9.71k|        ss->handshakeCallback = os->handshakeCallback;
  374|  9.71k|        ss->handshakeCallbackData = os->handshakeCallbackData;
  375|  9.71k|        ss->canFalseStartCallback = os->canFalseStartCallback;
  376|  9.71k|        ss->canFalseStartCallbackData = os->canFalseStartCallbackData;
  377|  9.71k|        ss->pkcs11PinArg = os->pkcs11PinArg;
  378|  9.71k|        ss->nextProtoCallback = os->nextProtoCallback;
  379|  9.71k|        ss->nextProtoArg = os->nextProtoArg;
  380|  9.71k|        PORT_Memcpy((void *)ss->namedGroupPreferences,
  ------------------
  |  |  180|  9.71k|#define PORT_Memcpy memcpy
  ------------------
  381|  9.71k|                    os->namedGroupPreferences,
  382|  9.71k|                    sizeof(ss->namedGroupPreferences));
  383|  9.71k|        ss->additionalShares = os->additionalShares;
  384|  9.71k|        ss->resumptionTokenCallback = os->resumptionTokenCallback;
  385|  9.71k|        ss->resumptionTokenContext = os->resumptionTokenContext;
  386|       |
  387|  9.71k|        rv = tls13_CopyEchConfigs(&os->echConfigs, &ss->echConfigs);
  388|  9.71k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (388:13): [True: 0, False: 9.71k]
  ------------------
  389|      0|            goto loser;
  390|      0|        }
  391|  9.71k|        if (os->echPrivKey && os->echPubKey) {
  ------------------
  |  Branch (391:13): [True: 0, False: 9.71k]
  |  Branch (391:31): [True: 0, False: 0]
  ------------------
  392|      0|            ss->echPrivKey = SECKEY_CopyPrivateKey(os->echPrivKey);
  393|      0|            ss->echPubKey = SECKEY_CopyPublicKey(os->echPubKey);
  394|      0|            if (!ss->echPrivKey || !ss->echPubKey) {
  ------------------
  |  Branch (394:17): [True: 0, False: 0]
  |  Branch (394:36): [True: 0, False: 0]
  ------------------
  395|      0|                goto loser;
  396|      0|            }
  397|      0|        }
  398|       |
  399|  9.71k|        if (os->antiReplay) {
  ------------------
  |  Branch (399:13): [True: 0, False: 9.71k]
  ------------------
  400|      0|            ss->antiReplay = tls13_RefAntiReplayContext(os->antiReplay);
  401|      0|            PORT_Assert(ss->antiReplay); /* Can't fail. */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  402|      0|            if (!ss->antiReplay) {
  ------------------
  |  Branch (402:17): [True: 0, False: 0]
  ------------------
  403|      0|                goto loser;
  404|      0|            }
  405|      0|        }
  406|  9.71k|        if (os->psk) {
  ------------------
  |  Branch (406:13): [True: 0, False: 9.71k]
  ------------------
  407|      0|            ss->psk = tls13_CopyPsk(os->psk);
  408|      0|            if (!ss->psk) {
  ------------------
  |  Branch (408:17): [True: 0, False: 0]
  ------------------
  409|      0|                goto loser;
  410|      0|            }
  411|      0|        }
  412|       |
  413|       |        /* Create security data */
  414|  9.71k|        rv = ssl_CopySecurityInfo(ss, os);
  415|  9.71k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (415:13): [True: 0, False: 9.71k]
  ------------------
  416|      0|            goto loser;
  417|      0|        }
  418|  9.71k|    }
  419|       |
  420|  9.71k|    return ss;
  421|       |
  422|      0|loser:
  423|      0|    ssl_FreeSocket(ss);
  424|      0|    return NULL;
  425|  9.71k|}
sslsock.c:ssl_PushIOLayer:
 3829|  9.71k|{
 3830|  9.71k|    PRFileDesc *layer = NULL;
 3831|  9.71k|    PRStatus status;
 3832|       |
 3833|  9.71k|    status = PR_CallOnce(&initIoLayerOnce, &ssl_InitIOLayer);
 3834|  9.71k|    if (status != PR_SUCCESS) {
  ------------------
  |  Branch (3834:9): [True: 0, False: 9.71k]
  ------------------
 3835|      0|        goto loser;
 3836|      0|    }
 3837|  9.71k|    if (ns == NULL) {
  ------------------
  |  Branch (3837:9): [True: 0, False: 9.71k]
  ------------------
 3838|      0|        goto loser;
 3839|      0|    }
 3840|  9.71k|    layer = PR_CreateIOLayerStub(ssl_layer_id, &combined_methods);
 3841|  9.71k|    if (layer == NULL)
  ------------------
  |  Branch (3841:9): [True: 0, False: 9.71k]
  ------------------
 3842|      0|        goto loser;
 3843|  9.71k|    layer->secret = (PRFilePrivate *)ns;
 3844|       |
 3845|       |    /* Here, "stack" points to the PRFileDesc on the top of the stack.
 3846|       |    ** "layer" points to a new FD that is to be inserted into the stack.
 3847|       |    ** If layer is being pushed onto the top of the stack, then
 3848|       |    ** PR_PushIOLayer switches the contents of stack and layer, and then
 3849|       |    ** puts stack on top of layer, so that after it is done, the top of
 3850|       |    ** stack is the same "stack" as it was before, and layer is now the
 3851|       |    ** FD for the former top of stack.
 3852|       |    ** After this call, stack always points to the top PRFD on the stack.
 3853|       |    ** If this function fails, the contents of stack and layer are as
 3854|       |    ** they were before the call.
 3855|       |    */
 3856|  9.71k|    status = PR_PushIOLayer(stack, id, layer);
 3857|  9.71k|    if (status != PR_SUCCESS)
  ------------------
  |  Branch (3857:9): [True: 0, False: 9.71k]
  ------------------
 3858|      0|        goto loser;
 3859|       |
 3860|  9.71k|    ns->fd = (id == PR_TOP_IO_LAYER) ? stack : layer;
  ------------------
  |  |  453|  9.71k|#define PR_TOP_IO_LAYER (PRDescIdentity)-2
  ------------------
  |  Branch (3860:14): [True: 9.71k, False: 0]
  ------------------
 3861|  9.71k|    return PR_SUCCESS;
 3862|       |
 3863|      0|loser:
 3864|      0|    if (layer) {
  ------------------
  |  Branch (3864:9): [True: 0, False: 0]
  ------------------
 3865|      0|        layer->dtor(layer); /* free layer */
 3866|      0|    }
 3867|      0|    return PR_FAILURE;
 3868|  9.71k|}
sslsock.c:ssl_InitIOLayer:
 3821|      1|{
 3822|      1|    ssl_layer_id = PR_GetUniqueIdentity("SSL");
 3823|      1|    ssl_SetupIOMethods();
 3824|      1|    return PR_SUCCESS;
 3825|      1|}
sslsock.c:ssl_SetupIOMethods:
 3779|      1|{
 3780|      1|    PRIOMethods *new_methods = &combined_methods;
 3781|      1|    const PRIOMethods *nspr_methods = PR_GetDefaultIOMethods();
 3782|      1|    const PRIOMethods *my_methods = &ssl_methods;
 3783|       |
 3784|      1|    *new_methods = *nspr_methods;
 3785|       |
 3786|      1|    new_methods->file_type = my_methods->file_type;
 3787|      1|    new_methods->close = my_methods->close;
 3788|      1|    new_methods->read = my_methods->read;
 3789|      1|    new_methods->write = my_methods->write;
 3790|      1|    new_methods->available = my_methods->available;
 3791|      1|    new_methods->available64 = my_methods->available64;
 3792|      1|    new_methods->fsync = my_methods->fsync;
 3793|      1|    new_methods->seek = my_methods->seek;
 3794|      1|    new_methods->seek64 = my_methods->seek64;
 3795|      1|    new_methods->fileInfo = my_methods->fileInfo;
 3796|      1|    new_methods->fileInfo64 = my_methods->fileInfo64;
 3797|      1|    new_methods->writev = my_methods->writev;
 3798|      1|    new_methods->connect = my_methods->connect;
 3799|      1|    new_methods->accept = my_methods->accept;
 3800|      1|    new_methods->bind = my_methods->bind;
 3801|      1|    new_methods->listen = my_methods->listen;
 3802|      1|    new_methods->shutdown = my_methods->shutdown;
 3803|      1|    new_methods->recv = my_methods->recv;
 3804|      1|    new_methods->send = my_methods->send;
 3805|      1|    new_methods->recvfrom = my_methods->recvfrom;
 3806|      1|    new_methods->sendto = my_methods->sendto;
 3807|      1|    new_methods->poll = my_methods->poll;
 3808|      1|    new_methods->acceptread = my_methods->acceptread;
 3809|      1|    new_methods->transmitfile = my_methods->transmitfile;
 3810|      1|    new_methods->getsockname = my_methods->getsockname;
 3811|      1|    new_methods->getpeername = my_methods->getpeername;
 3812|       |    /*  new_methods->getsocketoption   = my_methods->getsocketoption;       */
 3813|       |    /*  new_methods->setsocketoption   = my_methods->setsocketoption;       */
 3814|      1|    new_methods->sendfile = my_methods->sendfile;
 3815|      1|}
sslsock.c:ssl_Close:
 3157|  9.71k|{
 3158|  9.71k|    sslSocket *ss;
 3159|  9.71k|    PRStatus rv;
 3160|       |
 3161|  9.71k|    ss = ssl_GetPrivate(fd);
 3162|  9.71k|    if (!ss) {
  ------------------
  |  Branch (3162:9): [True: 0, False: 9.71k]
  ------------------
 3163|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in close", SSL_GETPID(), fd));
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 3164|      0|        return PR_FAILURE;
 3165|      0|    }
 3166|       |
 3167|       |    /* There must not be any I/O going on */
 3168|  9.71k|    SSL_LOCK_READER(ss);
  ------------------
  |  | 1376|  9.71k|    if (ss->recvLock)       \
  |  |  ------------------
  |  |  |  Branch (1376:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1377|  9.71k|    PZ_Lock(ss->recvLock)
  |  |  ------------------
  |  |  |  |  245|  9.71k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
 3169|  9.71k|    SSL_LOCK_WRITER(ss);
  ------------------
  |  | 1382|  9.71k|    if (ss->sendLock)       \
  |  |  ------------------
  |  |  |  Branch (1382:9): [True: 9.71k, False: 0]
  |  |  ------------------
  |  | 1383|  9.71k|    PZ_Lock(ss->sendLock)
  |  |  ------------------
  |  |  |  |  245|  9.71k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
 3170|       |
 3171|       |    /* By the time this function returns,
 3172|       |    ** ss is an invalid pointer, and the locks to which it points have
 3173|       |    ** been unlocked and freed.  So, this is the ONE PLACE in all of SSL
 3174|       |    ** where the LOCK calls and the corresponding UNLOCK calls are not in
 3175|       |    ** the same function scope.  The unlock calls are in ssl_FreeSocket().
 3176|       |    */
 3177|  9.71k|    rv = (PRStatus)(*ss->ops->close)(ss);
 3178|       |
 3179|  9.71k|    return rv;
 3180|  9.71k|}
sslsock.c:ssl_GetPrivate:
  220|   325k|{
  221|   325k|    sslSocket *ss;
  222|       |
  223|   325k|    PORT_Assert(fd != NULL);
  ------------------
  |  |  120|   325k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   325k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 325k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  224|   325k|    PORT_Assert(fd->methods->file_type == PR_DESC_LAYERED);
  ------------------
  |  |  120|   325k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   325k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 325k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  225|   325k|    PORT_Assert(fd->identity == ssl_layer_id);
  ------------------
  |  |  120|   325k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   325k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 325k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  226|       |
  227|   325k|    if (fd->methods->file_type != PR_DESC_LAYERED ||
  ------------------
  |  Branch (227:9): [True: 0, False: 325k]
  ------------------
  228|   325k|        fd->identity != ssl_layer_id) {
  ------------------
  |  Branch (228:9): [True: 0, False: 325k]
  ------------------
  229|      0|        PORT_SetError(PR_BAD_DESCRIPTOR_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
                      PORT_SetError(PR_BAD_DESCRIPTOR_ERROR);
  ------------------
  |  |   19|      0|#define PR_BAD_DESCRIPTOR_ERROR                  (-5999L)
  ------------------
  230|      0|        return NULL;
  231|      0|    }
  232|       |
  233|   325k|    ss = (sslSocket *)fd->secret;
  234|       |    /* Set ss->fd lazily. We can't rely on the value of ss->fd set by
  235|       |     * ssl_PushIOLayer because another PR_PushIOLayer call will switch the
  236|       |     * contents of the PRFileDesc pointed by ss->fd and the new layer.
  237|       |     * See bug 807250.
  238|       |     */
  239|   325k|    ss->fd = fd;
  240|   325k|    return ss;
  241|   325k|}
sslsock.c:ssl_Read:
 3226|   159k|{
 3227|   159k|    sslSocket *ss;
 3228|   159k|    int rv;
 3229|       |
 3230|   159k|    ss = ssl_GetPrivate(fd);
 3231|   159k|    if (!ss) {
  ------------------
  |  Branch (3231:9): [True: 0, False: 159k]
  ------------------
 3232|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in read", SSL_GETPID(), fd));
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 3233|      0|        return SECFailure;
 3234|      0|    }
 3235|   159k|    SSL_LOCK_READER(ss);
  ------------------
  |  | 1376|   159k|    if (ss->recvLock)       \
  |  |  ------------------
  |  |  |  Branch (1376:9): [True: 159k, False: 0]
  |  |  ------------------
  |  | 1377|   159k|    PZ_Lock(ss->recvLock)
  |  |  ------------------
  |  |  |  |  245|   159k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
 3236|   159k|    ss->rTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|   159k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 3237|   159k|    if (!ss->opt.fdx)
  ------------------
  |  Branch (3237:9): [True: 159k, False: 0]
  ------------------
 3238|   159k|        ss->wTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|   159k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 3239|   159k|    rv = (*ss->ops->read)(ss, (unsigned char *)buf, len);
 3240|   159k|    SSL_UNLOCK_READER(ss);
  ------------------
  |  | 1379|   159k|    if (ss->recvLock)         \
  |  |  ------------------
  |  |  |  Branch (1379:9): [True: 159k, False: 0]
  |  |  ------------------
  |  | 1380|   159k|    PZ_Unlock(ss->recvLock)
  |  |  ------------------
  |  |  |  |  246|   159k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
 3241|   159k|    return rv;
 3242|   159k|}
sslsock.c:ssl_Write:
 3246|   156k|{
 3247|   156k|    sslSocket *ss;
 3248|   156k|    int rv;
 3249|       |
 3250|   156k|    ss = ssl_GetPrivate(fd);
 3251|   156k|    if (!ss) {
  ------------------
  |  Branch (3251:9): [True: 0, False: 156k]
  ------------------
 3252|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in write", SSL_GETPID(), fd));
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
 3253|      0|        return SECFailure;
 3254|      0|    }
 3255|   156k|    SSL_LOCK_WRITER(ss);
  ------------------
  |  | 1382|   156k|    if (ss->sendLock)       \
  |  |  ------------------
  |  |  |  Branch (1382:9): [True: 156k, False: 0]
  |  |  ------------------
  |  | 1383|   156k|    PZ_Lock(ss->sendLock)
  |  |  ------------------
  |  |  |  |  245|   156k|#define PZ_Lock(k) PR_Lock((k))
  |  |  ------------------
  ------------------
 3256|   156k|    ss->wTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|   156k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 3257|   156k|    if (!ss->opt.fdx)
  ------------------
  |  Branch (3257:9): [True: 156k, False: 0]
  ------------------
 3258|   156k|        ss->rTimeout = PR_INTERVAL_NO_TIMEOUT;
  ------------------
  |  |   54|   156k|#define PR_INTERVAL_NO_TIMEOUT 0xffffffffUL
  ------------------
 3259|   156k|    rv = (*ss->ops->write)(ss, (const unsigned char *)buf, len);
 3260|   156k|    SSL_UNLOCK_WRITER(ss);
  ------------------
  |  | 1385|   156k|    if (ss->sendLock)         \
  |  |  ------------------
  |  |  |  Branch (1385:9): [True: 156k, False: 0]
  |  |  ------------------
  |  | 1386|   156k|    PZ_Unlock(ss->sendLock)
  |  |  ------------------
  |  |  |  |  246|   156k|#define PZ_Unlock(k) PR_Unlock((k))
  |  |  ------------------
  ------------------
 3261|   156k|    return rv;
 3262|   156k|}
sslsock.c:ssl3_CreateOverlapWithPolicy:
 2633|  52.5k|{
 2634|  52.5k|    SECStatus rv;
 2635|  52.5k|    SSLVersionRange effectivePolicyBoundary;
 2636|  52.5k|    SSLVersionRange vrange;
 2637|       |
 2638|  52.5k|    PORT_Assert(input != NULL);
  ------------------
  |  |  120|  52.5k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  52.5k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 52.5k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2639|       |
 2640|  52.5k|    rv = ssl3_GetEffectiveVersionPolicy(protocolVariant,
 2641|  52.5k|                                        &effectivePolicyBoundary);
 2642|  52.5k|    if (rv == SECFailure) {
  ------------------
  |  Branch (2642:9): [True: 0, False: 52.5k]
  ------------------
 2643|       |        /* SECFailure means internal failure or invalid configuration. */
 2644|      0|        overlap->min = overlap->max = SSL_LIBRARY_VERSION_NONE;
  ------------------
  |  | 1481|      0|#define SSL_LIBRARY_VERSION_NONE 0
  ------------------
 2645|      0|        return SECFailure;
 2646|      0|    }
 2647|       |
 2648|  52.5k|    vrange.min = PR_MAX(input->min, effectivePolicyBoundary.min);
  ------------------
  |  |  159|  52.5k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 23.4k, False: 29.1k]
  |  |  ------------------
  ------------------
 2649|  52.5k|    vrange.max = PR_MIN(input->max, effectivePolicyBoundary.max);
  ------------------
  |  |  158|  52.5k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 2.10k, False: 50.4k]
  |  |  ------------------
  ------------------
 2650|       |
 2651|  52.5k|    if (vrange.max < vrange.min) {
  ------------------
  |  Branch (2651:9): [True: 0, False: 52.5k]
  ------------------
 2652|       |        /* there was no overlap, turn off range altogether */
 2653|      0|        overlap->min = overlap->max = SSL_LIBRARY_VERSION_NONE;
  ------------------
  |  | 1481|      0|#define SSL_LIBRARY_VERSION_NONE 0
  ------------------
 2654|      0|        return SECFailure;
 2655|      0|    }
 2656|       |
 2657|  52.5k|    *overlap = vrange;
 2658|  52.5k|    return SECSuccess;
 2659|  52.5k|}
sslsock.c:ssl_VersionIsSupportedByPolicy:
 2664|  58.4k|{
 2665|  58.4k|    SECStatus rv;
 2666|  58.4k|    SSLVersionRange effectivePolicyBoundary;
 2667|       |
 2668|  58.4k|    rv = ssl3_GetEffectiveVersionPolicy(protocolVariant,
 2669|  58.4k|                                        &effectivePolicyBoundary);
 2670|  58.4k|    if (rv == SECFailure) {
  ------------------
  |  Branch (2670:9): [True: 0, False: 58.4k]
  ------------------
 2671|       |        /* SECFailure means internal failure or invalid configuration. */
 2672|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2673|      0|    }
 2674|  58.4k|    return version >= effectivePolicyBoundary.min &&
  ------------------
  |  Branch (2674:12): [True: 58.4k, False: 10]
  ------------------
 2675|  58.4k|           version <= effectivePolicyBoundary.max;
  ------------------
  |  Branch (2675:12): [True: 58.4k, False: 34]
  ------------------
 2676|  58.4k|}
sslsock.c:ssl3_CheckRangeValidAndConstrainByPolicy:
 2812|  23.4k|{
 2813|  23.4k|    SECStatus rv;
 2814|       |
 2815|  23.4k|    if (vrange->min > vrange->max ||
  ------------------
  |  Branch (2815:9): [True: 0, False: 23.4k]
  ------------------
 2816|  23.4k|        !ssl3_VersionIsSupportedByCode(protocolVariant, vrange->min) ||
  ------------------
  |  Branch (2816:9): [True: 0, False: 23.4k]
  ------------------
 2817|  23.4k|        !ssl3_VersionIsSupportedByCode(protocolVariant, vrange->max) ||
  ------------------
  |  Branch (2817:9): [True: 0, False: 23.4k]
  ------------------
 2818|  23.4k|        ssl3_HasConflictingSSLVersions(vrange)) {
  ------------------
  |  Branch (2818:9): [True: 0, False: 23.4k]
  ------------------
 2819|      0|        PORT_SetError(SSL_ERROR_INVALID_VERSION_RANGE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2820|      0|        return SECFailure;
 2821|      0|    }
 2822|       |
 2823|       |    /* Try to adjust the received range using our policy.
 2824|       |     * If there's overlap, we'll use the (possibly reduced) range.
 2825|       |     * If there isn't overlap, it's failure. */
 2826|       |
 2827|  23.4k|    rv = ssl3_CreateOverlapWithPolicy(protocolVariant, vrange, vrange);
 2828|  23.4k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2828:9): [True: 0, False: 23.4k]
  ------------------
 2829|      0|        return rv;
 2830|      0|    }
 2831|       |
 2832|       |    /* We don't allow SSLv3 and TLSv1.3 together */
 2833|  23.4k|    if (vrange->max >= SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  23.4k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (2833:9): [True: 21.3k, False: 2.10k]
  ------------------
 2834|  21.3k|        vrange->min = PR_MAX(vrange->min, SSL_LIBRARY_VERSION_TLS_1_0);
  ------------------
  |  |  159|  21.3k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 11.2k, False: 10.1k]
  |  |  ------------------
  ------------------
 2835|  21.3k|    }
 2836|       |
 2837|  23.4k|    return SECSuccess;
 2838|  23.4k|}
sslsock.c:ssl3_HasConflictingSSLVersions:
 2804|  23.4k|{
 2805|  23.4k|    return (vrange->min <= SSL_LIBRARY_VERSION_3_0 &&
  ------------------
  |  |   17|  46.8k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (2805:13): [True: 0, False: 23.4k]
  ------------------
 2806|  23.4k|            vrange->max >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (2806:13): [True: 0, False: 0]
  ------------------
 2807|  23.4k|}
sslsock.c:ssl_MakeLocks:
 3873|  9.71k|{
 3874|  9.71k|    ss->firstHandshakeLock = PZ_NewMonitor(nssILockSSL);
  ------------------
  |  |  254|  9.71k|#define PZ_NewMonitor(t) PR_NewMonitor()
  ------------------
 3875|  9.71k|    if (!ss->firstHandshakeLock)
  ------------------
  |  Branch (3875:9): [True: 0, False: 9.71k]
  ------------------
 3876|      0|        goto loser;
 3877|  9.71k|    ss->ssl3HandshakeLock = PZ_NewMonitor(nssILockSSL);
  ------------------
  |  |  254|  9.71k|#define PZ_NewMonitor(t) PR_NewMonitor()
  ------------------
 3878|  9.71k|    if (!ss->ssl3HandshakeLock)
  ------------------
  |  Branch (3878:9): [True: 0, False: 9.71k]
  ------------------
 3879|      0|        goto loser;
 3880|  9.71k|    ss->specLock = NSSRWLock_New(SSL_LOCK_RANK_SPEC, NULL);
  ------------------
  |  |   49|  9.71k|#define NSSRWLock_New NSSRWLock_New_Util
  ------------------
                  ss->specLock = NSSRWLock_New(SSL_LOCK_RANK_SPEC, NULL);
  ------------------
  |  |  306|  9.71k|#define SSL_LOCK_RANK_SPEC 255
  ------------------
 3881|  9.71k|    if (!ss->specLock)
  ------------------
  |  Branch (3881:9): [True: 0, False: 9.71k]
  ------------------
 3882|      0|        goto loser;
 3883|  9.71k|    ss->recvBufLock = PZ_NewMonitor(nssILockSSL);
  ------------------
  |  |  254|  9.71k|#define PZ_NewMonitor(t) PR_NewMonitor()
  ------------------
 3884|  9.71k|    if (!ss->recvBufLock)
  ------------------
  |  Branch (3884:9): [True: 0, False: 9.71k]
  ------------------
 3885|      0|        goto loser;
 3886|  9.71k|    ss->xmitBufLock = PZ_NewMonitor(nssILockSSL);
  ------------------
  |  |  254|  9.71k|#define PZ_NewMonitor(t) PR_NewMonitor()
  ------------------
 3887|  9.71k|    if (!ss->xmitBufLock)
  ------------------
  |  Branch (3887:9): [True: 0, False: 9.71k]
  ------------------
 3888|      0|        goto loser;
 3889|  9.71k|    ss->writerThread = NULL;
 3890|  9.71k|    if (ssl_lock_readers) {
  ------------------
  |  Branch (3890:9): [True: 9.71k, False: 0]
  ------------------
 3891|  9.71k|        ss->recvLock = PZ_NewLock(nssILockSSL);
  ------------------
  |  |  243|  9.71k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 3892|  9.71k|        if (!ss->recvLock)
  ------------------
  |  Branch (3892:13): [True: 0, False: 9.71k]
  ------------------
 3893|      0|            goto loser;
 3894|  9.71k|        ss->sendLock = PZ_NewLock(nssILockSSL);
  ------------------
  |  |  243|  9.71k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
 3895|  9.71k|        if (!ss->sendLock)
  ------------------
  |  Branch (3895:13): [True: 0, False: 9.71k]
  ------------------
 3896|      0|            goto loser;
 3897|  9.71k|    }
 3898|  9.71k|    return SECSuccess;
 3899|      0|loser:
 3900|      0|    ssl_DestroyLocks(ss);
 3901|      0|    return SECFailure;
 3902|  9.71k|}
sslsock.c:ssl_SetDefaultsFromEnvironment:
 3995|  9.71k|{
 3996|  9.71k|    PR_CallOnce(&ssl_setDefaultsFromEnvironment, ssl_SetDefaultsFromEnvironmentCallOnce);
 3997|  9.71k|}
sslsock.c:ssl_SetDefaultsFromEnvironmentCallOnce:
 3912|      1|{
 3913|      1|#if defined(NSS_HAVE_GETENV)
 3914|      1|    char *ev;
 3915|      1|#ifdef DEBUG
 3916|      1|    ssl_trace_iob = NULL;
 3917|      1|    ev = PR_GetEnvSecure("SSLDEBUGFILE");
 3918|      1|    if (ev && ev[0]) {
  ------------------
  |  Branch (3918:9): [True: 0, False: 1]
  |  Branch (3918:15): [True: 0, False: 0]
  ------------------
 3919|      0|        ssl_trace_iob = fopen(ev, "w");
 3920|      0|    }
 3921|      1|    if (!ssl_trace_iob) {
  ------------------
  |  Branch (3921:9): [True: 1, False: 0]
  ------------------
 3922|      1|        ssl_trace_iob = stderr;
 3923|      1|    }
 3924|      1|#ifdef TRACE
 3925|      1|    ev = PR_GetEnvSecure("SSLTRACE");
 3926|      1|    if (ev && ev[0]) {
  ------------------
  |  Branch (3926:9): [True: 0, False: 1]
  |  Branch (3926:15): [True: 0, False: 0]
  ------------------
 3927|      0|        ssl_trace = atoi(ev);
 3928|      0|        SSL_TRACE(("SSL: tracing set to %d", ssl_trace));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3929|      0|    }
 3930|      1|#endif /* TRACE */
 3931|      1|    ev = PR_GetEnvSecure("SSLDEBUG");
 3932|      1|    if (ev && ev[0]) {
  ------------------
  |  Branch (3932:9): [True: 0, False: 1]
  |  Branch (3932:15): [True: 0, False: 0]
  ------------------
 3933|      0|        ssl_debug = atoi(ev);
 3934|      0|        SSL_TRACE(("SSL: debugging set to %d", ssl_debug));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3935|      0|    }
 3936|      1|#endif /* DEBUG */
 3937|      1|#ifdef NSS_ALLOW_SSLKEYLOGFILE
 3938|      1|    ssl_keylog_iob = NULL;
 3939|      1|    ev = PR_GetEnvSecure("SSLKEYLOGFILE");
 3940|      1|    if (ev && ev[0]) {
  ------------------
  |  Branch (3940:9): [True: 0, False: 1]
  |  Branch (3940:15): [True: 0, False: 0]
  ------------------
 3941|      0|        ssl_keylog_iob = fopen(ev, "a");
 3942|      0|        if (!ssl_keylog_iob) {
  ------------------
  |  Branch (3942:13): [True: 0, False: 0]
  ------------------
 3943|      0|            SSL_TRACE(("SSL: failed to open key log file"));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3944|      0|        } else {
 3945|      0|            if (ftell(ssl_keylog_iob) == 0) {
  ------------------
  |  Branch (3945:17): [True: 0, False: 0]
  ------------------
 3946|      0|                fputs("# SSL/TLS secrets log file, generated by NSS\n",
 3947|      0|                      ssl_keylog_iob);
 3948|      0|            }
 3949|      0|            SSL_TRACE(("SSL: logging SSL/TLS secrets to %s", ev));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3950|      0|            ssl_keylog_lock = PR_NewLock();
 3951|      0|            if (!ssl_keylog_lock) {
  ------------------
  |  Branch (3951:17): [True: 0, False: 0]
  ------------------
 3952|      0|                SSL_TRACE(("SSL: failed to create key log lock"));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3953|      0|                fclose(ssl_keylog_iob);
 3954|      0|                ssl_keylog_iob = NULL;
 3955|      0|            }
 3956|      0|        }
 3957|      0|    }
 3958|      1|#endif
 3959|      1|    ev = PR_GetEnvSecure("SSLFORCELOCKS");
 3960|      1|    if (ev && ev[0] == '1') {
  ------------------
  |  Branch (3960:9): [True: 0, False: 1]
  |  Branch (3960:15): [True: 0, False: 0]
  ------------------
 3961|      0|        ssl_force_locks = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3962|      0|        ssl_defaults.noLocks = 0;
 3963|      0|        SSL_TRACE(("SSL: force_locks set to %d", ssl_force_locks));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3964|      0|    }
 3965|      1|    ev = PR_GetEnvSecure("NSS_SSL_ENABLE_RENEGOTIATION");
 3966|      1|    if (ev) {
  ------------------
  |  Branch (3966:9): [True: 0, False: 1]
  ------------------
 3967|      0|        if (ev[0] == '1' || LOWER(ev[0]) == 'u')
  ------------------
  |  | 3908|      0|#define LOWER(x) (x | 0x20) /* cheap ToLower function ignores LOCALE */
  ------------------
  |  Branch (3967:13): [True: 0, False: 0]
  |  Branch (3967:29): [True: 0, False: 0]
  ------------------
 3968|      0|            ssl_defaults.enableRenegotiation = SSL_RENEGOTIATE_UNRESTRICTED;
  ------------------
  |  |  714|      0|#define SSL_RENEGOTIATE_UNRESTRICTED ((PRBool)1)
  ------------------
 3969|      0|        else if (ev[0] == '0' || LOWER(ev[0]) == 'n')
  ------------------
  |  | 3908|      0|#define LOWER(x) (x | 0x20) /* cheap ToLower function ignores LOCALE */
  ------------------
  |  Branch (3969:18): [True: 0, False: 0]
  |  Branch (3969:34): [True: 0, False: 0]
  ------------------
 3970|      0|            ssl_defaults.enableRenegotiation = SSL_RENEGOTIATE_NEVER;
  ------------------
  |  |  711|      0|#define SSL_RENEGOTIATE_NEVER ((PRBool)0)
  ------------------
 3971|      0|        else if (ev[0] == '2' || LOWER(ev[0]) == 'r')
  ------------------
  |  | 3908|      0|#define LOWER(x) (x | 0x20) /* cheap ToLower function ignores LOCALE */
  ------------------
  |  Branch (3971:18): [True: 0, False: 0]
  |  Branch (3971:34): [True: 0, False: 0]
  ------------------
 3972|      0|            ssl_defaults.enableRenegotiation = SSL_RENEGOTIATE_REQUIRES_XTN;
  ------------------
  |  |  717|      0|#define SSL_RENEGOTIATE_REQUIRES_XTN ((PRBool)2)
  ------------------
 3973|      0|        else if (ev[0] == '3' || LOWER(ev[0]) == 't')
  ------------------
  |  | 3908|      0|#define LOWER(x) (x | 0x20) /* cheap ToLower function ignores LOCALE */
  ------------------
  |  Branch (3973:18): [True: 0, False: 0]
  |  Branch (3973:34): [True: 0, False: 0]
  ------------------
 3974|      0|            ssl_defaults.enableRenegotiation = SSL_RENEGOTIATE_TRANSITIONAL;
  ------------------
  |  |  722|      0|#define SSL_RENEGOTIATE_TRANSITIONAL ((PRBool)3)
  ------------------
 3975|      0|        SSL_TRACE(("SSL: enableRenegotiation set to %d",
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3976|      0|                   ssl_defaults.enableRenegotiation));
 3977|      0|    }
 3978|      1|    ev = PR_GetEnvSecure("NSS_SSL_REQUIRE_SAFE_NEGOTIATION");
 3979|      1|    if (ev && ev[0] == '1') {
  ------------------
  |  Branch (3979:9): [True: 0, False: 1]
  |  Branch (3979:15): [True: 0, False: 0]
  ------------------
 3980|      0|        ssl_defaults.requireSafeNegotiation = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3981|      0|        SSL_TRACE(("SSL: requireSafeNegotiation set to %d",
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3982|      0|                   PR_TRUE));
 3983|      0|    }
 3984|      1|    ev = PR_GetEnvSecure("NSS_SSL_CBC_RANDOM_IV");
 3985|      1|    if (ev && ev[0] == '0') {
  ------------------
  |  Branch (3985:9): [True: 0, False: 1]
  |  Branch (3985:15): [True: 0, False: 0]
  ------------------
 3986|      0|        ssl_defaults.cbcRandomIV = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3987|      0|        SSL_TRACE(("SSL: cbcRandomIV set to 0"));
  ------------------
  |  | 1900|      0|#define SSL_TRACE(msg) ssl_Trace msg
  ------------------
 3988|      0|    }
 3989|      1|#endif /* NSS_HAVE_GETENV */
 3990|      1|    return PR_SUCCESS;
 3991|      1|}

ssl_GetBulkCipherDef:
   68|  4.70M|{
   69|  4.70M|    SSL3BulkCipher bulkCipher = suiteDef->bulk_cipher_alg;
   70|  4.70M|    PORT_Assert(bulkCipher < PR_ARRAY_SIZE(ssl_bulk_cipher_defs));
  ------------------
  |  |  120|  4.70M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.70M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4.70M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   71|  4.70M|    PORT_Assert(ssl_bulk_cipher_defs[bulkCipher].cipher == bulkCipher);
  ------------------
  |  |  120|  4.70M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.70M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4.70M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   72|  4.70M|    return &ssl_bulk_cipher_defs[bulkCipher];
   73|  4.70M|}
ssl_GetMacDefByAlg:
   91|   142k|{
   92|       |    /* Cast here for clang: https://bugs.llvm.org/show_bug.cgi?id=16154 */
   93|   142k|    PORT_Assert((size_t)mac < PR_ARRAY_SIZE(ssl_mac_defs));
  ------------------
  |  |  120|   142k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   142k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 142k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   94|   142k|    PORT_Assert(ssl_mac_defs[mac].mac == mac);
  ------------------
  |  |  120|   142k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   142k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 142k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   95|   142k|    return &ssl_mac_defs[mac];
   96|   142k|}
ssl_GetMacDef:
  100|   117k|{
  101|   117k|    SSL3MACAlgorithm mac = suiteDef->mac_alg;
  102|   117k|    if (ss->version > SSL_LIBRARY_VERSION_3_0) {
  ------------------
  |  |   17|   117k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (102:9): [True: 117k, False: 0]
  ------------------
  103|   117k|        switch (mac) {
  104|  5.12k|            case ssl_mac_md5:
  ------------------
  |  Branch (104:13): [True: 5.12k, False: 112k]
  ------------------
  105|  5.12k|                mac = ssl_hmac_md5;
  106|  5.12k|                break;
  107|  55.0k|            case ssl_mac_sha:
  ------------------
  |  Branch (107:13): [True: 55.0k, False: 62.4k]
  ------------------
  108|  55.0k|                mac = ssl_hmac_sha;
  109|  55.0k|                break;
  110|  57.3k|            default:
  ------------------
  |  Branch (110:13): [True: 57.3k, False: 60.1k]
  ------------------
  111|  57.3k|                break;
  112|   117k|        }
  113|   117k|    }
  114|   117k|    return ssl_GetMacDefByAlg(mac);
  115|   117k|}
ssl_CreateCipherSpec:
  139|   415k|{
  140|   415k|    ssl3CipherSpec *spec = PORT_ZNew(ssl3CipherSpec);
  ------------------
  |  |  148|   415k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|   415k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  141|   415k|    if (!spec) {
  ------------------
  |  Branch (141:9): [True: 0, False: 415k]
  ------------------
  142|      0|        return NULL;
  143|      0|    }
  144|   415k|    spec->refCt = 1;
  145|   415k|    spec->version = ss->version;
  146|   415k|    spec->direction = direction;
  147|   415k|    spec->recordSizeLimit = MAX_FRAGMENT_LENGTH;
  ------------------
  |  |   35|   415k|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
  148|   415k|    SSL_TRC(10, ("%d: SSL[%d]: new %s spec %d ct=%d",
  ------------------
  |  |   71|   415k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 415k]
  |  |  ------------------
  |  |   72|   415k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  149|   415k|                 SSL_GETPID(), ss->fd, SPEC_DIR(spec), spec,
  150|   415k|                 spec->refCt));
  151|   415k|    return spec;
  152|   415k|}
ssl_SaveCipherSpec:
  156|   415k|{
  157|   415k|    PR_APPEND_LINK(&spec->link, &ss->ssl3.hs.cipherSpecs);
  ------------------
  |  |   57|   415k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|   415k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|   415k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|   415k|    (_e)->next = (_l);   \
  |  |  |  |   27|   415k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|   415k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|   415k|    (_l)->prev = (_e);   \
  |  |  |  |   30|   415k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|   415k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  158|   415k|}
ssl_SetupNullCipherSpec:
  164|  19.4k|{
  165|  19.4k|    ssl3CipherSpec *spec;
  166|       |
  167|  19.4k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSpecWriteLock(ss));
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  38.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 19.4k]
  |  |  |  |  |  Branch (208:7): [True: 19.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  168|       |
  169|  19.4k|    spec = ssl_CreateCipherSpec(ss, dir);
  170|  19.4k|    if (!spec) {
  ------------------
  |  Branch (170:9): [True: 0, False: 19.4k]
  ------------------
  171|      0|        return SECFailure;
  172|      0|    }
  173|       |
  174|       |    /* Set default versions.  This value will be used to generate and send
  175|       |     * alerts if a version is not negotiated.  These values are overridden when
  176|       |     * sending a ClientHello and when a version is negotiated. */
  177|  19.4k|    spec->version = SSL_LIBRARY_VERSION_TLS_1_0;
  ------------------
  |  |   18|  19.4k|#define SSL_LIBRARY_VERSION_TLS_1_0             0x0301
  ------------------
  178|  19.4k|    spec->recordVersion = IS_DTLS(ss)
  ------------------
  |  |  892|  19.4k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 19.4k]
  |  |  ------------------
  ------------------
  179|  19.4k|                              ? SSL_LIBRARY_VERSION_DTLS_1_0_WIRE
  ------------------
  |  |   32|      0|#define SSL_LIBRARY_VERSION_DTLS_1_0_WIRE       ((~0x0100) & 0xffff)
  ------------------
  180|  19.4k|                              : SSL_LIBRARY_VERSION_TLS_1_0;
  ------------------
  |  |   18|  38.8k|#define SSL_LIBRARY_VERSION_TLS_1_0             0x0301
  ------------------
  181|  19.4k|    spec->cipherDef = &ssl_bulk_cipher_defs[cipher_null];
  182|  19.4k|    PORT_Assert(spec->cipherDef->cipher == cipher_null);
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 19.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  183|  19.4k|    spec->macDef = &ssl_mac_defs[ssl_mac_null];
  184|  19.4k|    PORT_Assert(spec->macDef->mac == ssl_mac_null);
  ------------------
  |  |  120|  19.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  19.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 19.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  185|  19.4k|    spec->cipher = Null_Cipher;
  186|       |
  187|  19.4k|    spec->phase = "cleartext";
  188|  19.4k|    dtls_InitRecvdRecords(&spec->recvdRecords);
  189|       |
  190|  19.4k|    ssl_SaveCipherSpec(ss, spec);
  191|  19.4k|    if (dir == ssl_secret_read) {
  ------------------
  |  Branch (191:9): [True: 9.71k, False: 9.71k]
  ------------------
  192|  9.71k|        ss->ssl3.crSpec = spec;
  193|  9.71k|    } else {
  194|  9.71k|        ss->ssl3.cwSpec = spec;
  195|  9.71k|    }
  196|  19.4k|    return SECSuccess;
  197|  19.4k|}
ssl_DestroyKeyMaterial:
  209|   415k|{
  210|   415k|    PK11_FreeSymKey(keyMaterial->key);
  211|   415k|    PK11_FreeSymKey(keyMaterial->macKey);
  212|   415k|    if (keyMaterial->macContext != NULL) {
  ------------------
  |  Branch (212:9): [True: 58.8k, False: 356k]
  ------------------
  213|  58.8k|        PK11_DestroyContext(keyMaterial->macContext, PR_TRUE);
  ------------------
  |  |  437|  58.8k|#define PR_TRUE 1
  ------------------
  214|  58.8k|    }
  215|   415k|}
ssl_CipherSpecRelease:
  240|   383k|{
  241|   383k|    if (!spec) {
  ------------------
  |  Branch (241:9): [True: 0, False: 383k]
  ------------------
  242|      0|        return;
  243|      0|    }
  244|       |
  245|   383k|    PORT_Assert(spec->refCt > 0);
  ------------------
  |  |  120|   383k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   383k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 383k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  246|   383k|    --spec->refCt;
  247|   383k|    SSL_TRC(10, ("%d: SSL[-]: decrement refct for %s spec %d. epoch=%d new ct = %d",
  ------------------
  |  |   71|   383k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 383k]
  |  |  ------------------
  |  |   72|   383k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  248|   383k|                 SSL_GETPID(), SPEC_DIR(spec), spec, spec->epoch, spec->refCt));
  249|   383k|    if (!spec->refCt) {
  ------------------
  |  Branch (249:9): [True: 383k, False: 0]
  ------------------
  250|   383k|        ssl_FreeCipherSpec(spec);
  251|   383k|    }
  252|   383k|}
ssl_DestroyCipherSpecs:
  256|  9.71k|{
  257|  41.3k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|  41.3k|    ((_l)->next == (_l))
  ------------------
  |  Branch (257:12): [True: 31.6k, False: 9.71k]
  ------------------
  258|  31.6k|        ssl3CipherSpec *spec = (ssl3CipherSpec *)PR_LIST_TAIL(list);
  ------------------
  |  |   66|  31.6k|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
  259|  31.6k|        ssl_FreeCipherSpec(spec);
  260|  31.6k|    }
  261|  9.71k|}
sslspec.c:ssl_FreeCipherSpec:
  219|   415k|{
  220|   415k|    SSL_TRC(10, ("%d: SSL[-]: Freeing %s spec %d. epoch=%d",
  ------------------
  |  |   71|   415k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 415k]
  |  |  ------------------
  |  |   72|   415k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  221|   415k|                 SSL_GETPID(), SPEC_DIR(spec), spec, spec->epoch));
  222|       |
  223|   415k|    PR_REMOVE_LINK(&spec->link);
  ------------------
  |  |   72|   415k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|   415k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|   415k|    (_e)->prev->next = (_e)->next; \
  |  |   74|   415k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|   415k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|   415k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  224|       |
  225|       |    /*  PORT_Assert( ss->opt.noLocks || ssl_HaveSpecWriteLock(ss)); Don't have ss! */
  226|   415k|    if (spec->cipherContext) {
  ------------------
  |  Branch (226:9): [True: 377k, False: 38.0k]
  ------------------
  227|   377k|        PK11_DestroyContext(spec->cipherContext, PR_TRUE);
  ------------------
  |  |  437|   377k|#define PR_TRUE 1
  ------------------
  228|   377k|    }
  229|   415k|    PK11_FreeSymKey(spec->masterSecret);
  230|   415k|    ssl_DestroyKeyMaterial(&spec->keyMaterial);
  231|   415k|    ssl_DestroyMaskingContextInner(spec->maskContext);
  232|       |
  233|   415k|    PORT_ZFree(spec, sizeof(*spec));
  ------------------
  |  |   75|   415k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  234|   415k|}

tls13_FatalError:
  138|    362|{
  139|    362|    PORT_Assert(desc != internal_error); /* These should never happen */
  ------------------
  |  |  120|    362|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    362|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 362, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  140|    362|    (void)SSL3_SendAlert(ss, alert_fatal, desc);
  141|    362|    PORT_SetError(prError);
  ------------------
  |  |   65|    362|#define PORT_SetError PORT_SetError_Util
  ------------------
  142|    362|}
tls13_SetHsState:
  188|  1.63k|{
  189|  1.63k|#ifdef TRACE
  190|  1.63k|    const char *new_state_name =
  191|  1.63k|        tls13_HandshakeState(ws);
  192|       |
  193|  1.63k|    SSL_TRC(3, ("%d: TLS13[%d]: %s state change from %s->%s in %s (%s:%d)",
  ------------------
  |  |   71|  1.63k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |   72|  1.63k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  194|  1.63k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss),
  195|  1.63k|                tls13_HandshakeState(TLS13_BASE_WAIT_STATE(ss->ssl3.hs.ws)),
  196|  1.63k|                new_state_name,
  197|  1.63k|                func, file, line));
  198|  1.63k|#endif
  199|       |
  200|  1.63k|    ss->ssl3.hs.ws = TLS13_WAIT_STATE(ws);
  ------------------
  |  |  180|  1.63k|#define TLS13_WAIT_STATE(ws) (((ws == idle_handshake) || (ws == wait_server_hello)) ? ws : ws | TLS13_WAIT_STATE_MASK)
  |  |  ------------------
  |  |  |  |  176|  2.85k|#define TLS13_WAIT_STATE_MASK 0x80
  |  |  ------------------
  |  |  |  Branch (180:32): [True: 417, False: 1.22k]
  |  |  |  Branch (180:58): [True: 0, False: 1.22k]
  |  |  ------------------
  ------------------
  201|  1.63k|}
tls13_IsPostHandshake:
  253|   477k|{
  254|   477k|    return ss->version >= SSL_LIBRARY_VERSION_TLS_1_3 && ss->firstHsDone;
  ------------------
  |  |   21|   955k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (254:12): [True: 417k, False: 60.6k]
  |  Branch (254:58): [True: 416k, False: 511]
  ------------------
  255|   477k|}
tls13_GetHash:
  271|  1.40M|{
  272|       |    /* suite_def may not be set yet when doing EPSK 0-Rtt. */
  273|  1.40M|    if (!ss->ssl3.hs.suite_def) {
  ------------------
  |  Branch (273:9): [True: 0, False: 1.40M]
  ------------------
  274|      0|        if (ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (274:13): [True: 0, False: 0]
  ------------------
  275|      0|            return ss->xtnData.selectedPsk->hash;
  276|      0|        }
  277|       |        /* This should never happen. */
  278|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  279|      0|        return ssl_hash_none;
  280|      0|    }
  281|       |
  282|       |    /* All TLS 1.3 cipher suites must have an explict PRF hash. */
  283|  1.40M|    PORT_Assert(ss->ssl3.hs.suite_def->prf_hash != ssl_hash_none);
  ------------------
  |  |  120|  1.40M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.40M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.40M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  284|  1.40M|    return ss->ssl3.hs.suite_def->prf_hash;
  285|  1.40M|}
tls13_GetHashSizeForHash:
  317|   301k|{
  318|   301k|    switch (hash) {
  319|  18.4k|        case ssl_hash_sha256:
  ------------------
  |  Branch (319:9): [True: 18.4k, False: 283k]
  ------------------
  320|  18.4k|            return 32;
  321|   283k|        case ssl_hash_sha384:
  ------------------
  |  Branch (321:9): [True: 283k, False: 18.4k]
  ------------------
  322|   283k|            return 48;
  323|      0|        default:
  ------------------
  |  Branch (323:9): [True: 0, False: 301k]
  ------------------
  324|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  325|   301k|    }
  326|      0|    return 32;
  327|   301k|}
tls13_GetHashSize:
  331|   285k|{
  332|   285k|    return tls13_GetHashSizeForHash(tls13_GetHash(ss));
  333|   285k|}
tls13_ComputeHash:
  359|  2.44k|{
  360|  2.44k|    SECStatus rv;
  361|       |
  362|  2.44k|    rv = PK11_HashBuf(ssl3_HashTypeToOID(hash), hashes->u.raw, buf, len);
  363|  2.44k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (363:9): [True: 0, False: 2.44k]
  ------------------
  364|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  365|      0|        return SECFailure;
  366|      0|    }
  367|  2.44k|    hashes->len = tls13_GetHashSizeForHash(hash);
  368|       |
  369|  2.44k|    return SECSuccess;
  370|  2.44k|}
tls13_CreateKeyShare:
  454|  1.24k|{
  455|  1.24k|    SECStatus rv;
  456|  1.24k|    const ssl3DHParams *params;
  457|  1.24k|    sslEphemeralKeyPair *keyPair = NULL;
  458|       |
  459|  1.24k|    PORT_Assert(groupDef);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  460|  1.24k|    switch (groupDef->keaType) {
  461|    102|        case ssl_kea_ecdh_hybrid:
  ------------------
  |  Branch (461:9): [True: 102, False: 1.14k]
  ------------------
  462|    102|            if (groupDef->name != ssl_grp_kem_xyber768d00 && groupDef->name != ssl_grp_kem_mlkem768x25519) {
  ------------------
  |  Branch (462:17): [True: 102, False: 0]
  |  Branch (462:62): [True: 0, False: 102]
  ------------------
  463|      0|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  464|      0|                return SECFailure;
  465|      0|            }
  466|    102|            const sslNamedGroupDef *x25519 = ssl_LookupNamedGroup(ssl_grp_ec_curve25519);
  467|    102|            sslEphemeralKeyPair *x25519Pair = ssl_LookupEphemeralKeyPair(ss, x25519);
  468|    102|            if (x25519Pair) {
  ------------------
  |  Branch (468:17): [True: 0, False: 102]
  ------------------
  469|      0|                keyPair = ssl_CopyEphemeralKeyPair(x25519Pair);
  470|      0|            }
  471|    102|            if (!keyPair) {
  ------------------
  |  Branch (471:17): [True: 102, False: 0]
  ------------------
  472|    102|                rv = ssl_CreateECDHEphemeralKeyPair(ss, x25519, &keyPair);
  473|    102|                if (rv != SECSuccess) {
  ------------------
  |  Branch (473:21): [True: 0, False: 102]
  ------------------
  474|      0|                    return SECFailure;
  475|      0|                }
  476|    102|            }
  477|    102|            keyPair->group = groupDef;
  478|    102|            break;
  479|    595|        case ssl_kea_ecdh:
  ------------------
  |  Branch (479:9): [True: 595, False: 650]
  ------------------
  480|    595|            if (groupDef->name == ssl_grp_ec_curve25519) {
  ------------------
  |  Branch (480:17): [True: 588, False: 7]
  ------------------
  481|    588|                sslEphemeralKeyPair *hybridPair = ssl_LookupEphemeralKeyPair(ss, ssl_LookupNamedGroup(ssl_grp_kem_mlkem768x25519));
  482|    588|                if (!hybridPair) {
  ------------------
  |  Branch (482:21): [True: 588, False: 0]
  ------------------
  483|    588|                    hybridPair = ssl_LookupEphemeralKeyPair(ss, ssl_LookupNamedGroup(ssl_grp_kem_xyber768d00));
  484|    588|                }
  485|    588|                if (hybridPair) {
  ------------------
  |  Branch (485:21): [True: 0, False: 588]
  ------------------
  486|       |                    // We could use ssl_CopyEphemeralKeyPair here, but we would need to free
  487|       |                    // the KEM components. We should pull this out into a utility function when
  488|       |                    // we refactor to support multiple hybrid mechanisms.
  489|      0|                    keyPair = PORT_ZNew(sslEphemeralKeyPair);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  490|      0|                    if (!keyPair) {
  ------------------
  |  Branch (490:25): [True: 0, False: 0]
  ------------------
  491|      0|                        return SECFailure;
  492|      0|                    }
  493|      0|                    PR_INIT_CLIST(&keyPair->link);
  ------------------
  |  |  100|      0|    PR_BEGIN_MACRO     \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  101|      0|    (_l)->next = (_l); \
  |  |  102|      0|    (_l)->prev = (_l); \
  |  |  103|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  494|      0|                    keyPair->group = groupDef;
  495|      0|                    keyPair->keys = ssl_GetKeyPairRef(hybridPair->keys);
  496|      0|                }
  497|    588|            }
  498|    595|            if (!keyPair) {
  ------------------
  |  Branch (498:17): [True: 595, False: 0]
  ------------------
  499|    595|                rv = ssl_CreateECDHEphemeralKeyPair(ss, groupDef, &keyPair);
  500|    595|                if (rv != SECSuccess) {
  ------------------
  |  Branch (500:21): [True: 0, False: 595]
  ------------------
  501|      0|                    return SECFailure;
  502|      0|                }
  503|    595|            }
  504|    595|            break;
  505|    595|        case ssl_kea_dh:
  ------------------
  |  Branch (505:9): [True: 548, False: 697]
  ------------------
  506|    548|            params = ssl_GetDHEParams(groupDef);
  507|    548|            PORT_Assert(params->name != ssl_grp_ffdhe_custom);
  ------------------
  |  |  120|    548|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    548|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 548, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  508|    548|            rv = ssl_CreateDHEKeyPair(groupDef, params, &keyPair);
  509|    548|            if (rv != SECSuccess) {
  ------------------
  |  Branch (509:17): [True: 0, False: 548]
  ------------------
  510|      0|                return SECFailure;
  511|      0|            }
  512|    548|            break;
  513|    548|        default:
  ------------------
  |  Branch (513:9): [True: 0, False: 1.24k]
  ------------------
  514|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  515|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  516|      0|            return SECFailure;
  517|  1.24k|    }
  518|       |
  519|       |    // If we're creating an ECDH + KEM hybrid share and we're the client, then
  520|       |    // we still need to generate the KEM key pair. Otherwise we're done.
  521|  1.24k|    if (groupDef->keaType == ssl_kea_ecdh_hybrid && !ss->sec.isServer) {
  ------------------
  |  Branch (521:9): [True: 102, False: 1.14k]
  |  Branch (521:53): [True: 0, False: 102]
  ------------------
  522|      0|        rv = tls13_CreateKEMKeyPair(ss, groupDef, &keyPair->kemKeys);
  523|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (523:13): [True: 0, False: 0]
  ------------------
  524|      0|            ssl_FreeEphemeralKeyPair(keyPair);
  525|      0|            return SECFailure;
  526|      0|        }
  527|      0|    }
  528|       |
  529|  1.24k|    *outKeyPair = keyPair;
  530|  1.24k|    return SECSuccess;
  531|  1.24k|}
tls13_AddKeyShare:
  535|  1.24k|{
  536|  1.24k|    sslEphemeralKeyPair *keyPair = NULL;
  537|  1.24k|    SECStatus rv;
  538|       |
  539|  1.24k|    rv = tls13_CreateKeyShare(ss, groupDef, &keyPair);
  540|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (540:9): [True: 0, False: 1.24k]
  ------------------
  541|      0|        return SECFailure;
  542|      0|    }
  543|  1.24k|    PR_APPEND_LINK(&keyPair->link, &ss->ephemeralKeyPairs);
  ------------------
  |  |   57|  1.24k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|  2.49k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|  1.24k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|  2.49k|    (_e)->next = (_l);   \
  |  |  |  |   27|  2.49k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|  2.49k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|  2.49k|    (_l)->prev = (_e);   \
  |  |  |  |   30|  2.49k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|  1.24k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  544|  1.24k|    return SECSuccess;
  545|  1.24k|}
tls13_HandleKeyShare:
  850|  1.24k|{
  851|  1.24k|    PORTCheapArenaPool arena;
  852|  1.24k|    SECKEYPublicKey *peerKey;
  853|  1.24k|    CK_MECHANISM_TYPE mechanism;
  854|  1.24k|    PK11SymKey *key;
  855|  1.24k|    unsigned char *ec_data;
  856|  1.24k|    SECStatus rv;
  857|  1.24k|    int keySize = 0;
  858|       |
  859|  1.24k|    PORT_InitCheapArena(&arena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  1.24k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  860|  1.24k|    peerKey = PORT_ArenaZNew(&arena.arena, SECKEYPublicKey);
  ------------------
  |  |  155|  1.24k|    (type *)PORT_ArenaZAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   59|  1.24k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  |  |  ------------------
  ------------------
  861|  1.24k|    if (peerKey == NULL) {
  ------------------
  |  Branch (861:9): [True: 0, False: 1.24k]
  ------------------
  862|      0|        goto loser;
  863|      0|    }
  864|  1.24k|    peerKey->arena = &arena.arena;
  865|  1.24k|    peerKey->pkcs11Slot = NULL;
  866|  1.24k|    peerKey->pkcs11ID = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  1.24k|#define CK_INVALID_HANDLE 0
  ------------------
  867|       |
  868|  1.24k|    switch (entry->group->keaType) {
  869|    102|        case ssl_kea_ecdh_hybrid:
  ------------------
  |  Branch (869:9): [True: 102, False: 1.14k]
  ------------------
  870|    102|            switch (entry->group->name) {
  871|      0|                case ssl_grp_kem_xyber768d00:
  ------------------
  |  Branch (871:17): [True: 0, False: 102]
  ------------------
  872|       |                    // x25519 share is at the beginning
  873|      0|                    ec_data = entry->key_exchange.len < X25519_PUBLIC_KEY_BYTES
  ------------------
  |  |    8|      0|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
  |  Branch (873:31): [True: 0, False: 0]
  ------------------
  874|      0|                                  ? NULL
  875|      0|                                  : entry->key_exchange.data;
  876|      0|                    break;
  877|    102|                case ssl_grp_kem_mlkem768x25519:
  ------------------
  |  Branch (877:17): [True: 102, False: 0]
  ------------------
  878|       |                    // x25519 share is at the end
  879|    102|                    ec_data = entry->key_exchange.len < X25519_PUBLIC_KEY_BYTES
  ------------------
  |  |    8|    102|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
  |  Branch (879:31): [True: 1, False: 101]
  ------------------
  880|    102|                                  ? NULL
  881|    102|                                  : entry->key_exchange.data + entry->key_exchange.len - X25519_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|    203|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
  882|    102|                    break;
  883|      0|                default:
  ------------------
  |  Branch (883:17): [True: 0, False: 102]
  ------------------
  884|      0|                    ec_data = NULL;
  885|      0|                    break;
  886|    102|            }
  887|    102|            if (!ec_data) {
  ------------------
  |  Branch (887:17): [True: 1, False: 101]
  ------------------
  888|      1|                PORT_SetError(SSL_ERROR_RX_MALFORMED_HYBRID_KEY_SHARE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  889|      1|                goto loser;
  890|      1|            }
  891|    101|            rv = ssl_ImportECDHKeyShare(peerKey,
  892|    101|                                        ec_data,
  893|    101|                                        X25519_PUBLIC_KEY_BYTES,
  ------------------
  |  |    8|    101|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
  894|    101|                                        ssl_LookupNamedGroup(ssl_grp_ec_curve25519));
  895|    101|            mechanism = CKM_ECDH1_DERIVE;
  ------------------
  |  | 1086|    101|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  896|    101|            break;
  897|    595|        case ssl_kea_ecdh:
  ------------------
  |  Branch (897:9): [True: 595, False: 650]
  ------------------
  898|    595|            rv = ssl_ImportECDHKeyShare(peerKey,
  899|    595|                                        entry->key_exchange.data,
  900|    595|                                        entry->key_exchange.len,
  901|    595|                                        entry->group);
  902|    595|            mechanism = CKM_ECDH1_DERIVE;
  ------------------
  |  | 1086|    595|#define CKM_ECDH1_DERIVE 0x00001050UL
  ------------------
  903|    595|            break;
  904|    548|        case ssl_kea_dh:
  ------------------
  |  Branch (904:9): [True: 548, False: 697]
  ------------------
  905|    548|            rv = tls13_ImportDHEKeyShare(peerKey,
  906|    548|                                         entry->key_exchange.data,
  907|    548|                                         entry->key_exchange.len,
  908|    548|                                         keyPair->pubKey);
  909|    548|            mechanism = CKM_DH_PKCS_DERIVE;
  ------------------
  |  |  759|    548|#define CKM_DH_PKCS_DERIVE 0x00000021UL
  ------------------
  910|    548|            keySize = peerKey->u.dh.publicValue.len;
  911|    548|            break;
  912|      0|        default:
  ------------------
  |  Branch (912:9): [True: 0, False: 1.24k]
  ------------------
  913|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  914|      0|            goto loser;
  915|  1.24k|    }
  916|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (916:9): [True: 9, False: 1.23k]
  ------------------
  917|      9|        goto loser;
  918|      9|    }
  919|       |
  920|  1.23k|    key = PK11_PubDeriveWithKDF(
  921|  1.23k|        keyPair->privKey, peerKey, PR_FALSE, NULL, NULL, mechanism,
  ------------------
  |  |  438|  1.23k|#define PR_FALSE 0
  ------------------
  922|  1.23k|        CKM_HKDF_DERIVE, CKA_DERIVE, keySize, CKD_NULL, NULL, NULL);
  ------------------
  |  | 1296|  1.23k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
                      CKM_HKDF_DERIVE, CKA_DERIVE, keySize, CKD_NULL, NULL, NULL);
  ------------------
  |  |  555|  1.23k|#define CKA_DERIVE 0x0000010CUL
  ------------------
                      CKM_HKDF_DERIVE, CKA_DERIVE, keySize, CKD_NULL, NULL, NULL);
  ------------------
  |  | 1702|  1.23k|#define CKD_NULL 0x00000001UL
  ------------------
  923|  1.23k|    if (!key) {
  ------------------
  |  Branch (923:9): [True: 4, False: 1.23k]
  ------------------
  924|      4|        ssl_MapLowLevelError(SSL_ERROR_KEY_EXCHANGE_FAILURE);
  925|      4|        goto loser;
  926|      4|    }
  927|       |
  928|  1.23k|    *out = key;
  929|  1.23k|    PORT_DestroyCheapArena(&arena);
  930|  1.23k|    return SECSuccess;
  931|       |
  932|     14|loser:
  933|     14|    PORT_DestroyCheapArena(&arena);
  934|     14|    return SECFailure;
  935|  1.23k|}
tls13_UpdateTrafficKeys:
  954|   274k|{
  955|   274k|    PK11SymKey **secret;
  956|   274k|    PK11SymKey *updatedSecret;
  957|   274k|    PRUint16 epoch;
  958|   274k|    SECStatus rv;
  959|       |
  960|   274k|    secret = tls13_TrafficSecretRef(ss, direction);
  961|   274k|    rv = tls13_HkdfExpandLabel(*secret, tls13_GetHash(ss),
  962|   274k|                               NULL, 0,
  963|   274k|                               kHkdfLabelTrafficUpdate,
  964|   274k|                               strlen(kHkdfLabelTrafficUpdate),
  965|   274k|                               tls13_GetHmacMechanism(ss),
  966|   274k|                               tls13_GetHashSize(ss),
  967|   274k|                               ss->protocolVariant,
  968|   274k|                               &updatedSecret);
  969|   274k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (969:9): [True: 0, False: 274k]
  ------------------
  970|      0|        return SECFailure;
  971|      0|    }
  972|       |
  973|   274k|    PK11_FreeSymKey(*secret);
  974|   274k|    *secret = updatedSecret;
  975|       |
  976|   274k|    ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|   274k|    {                                           \
  |  | 1423|   274k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 133k, False: 140k]
  |  |  ------------------
  |  | 1424|   274k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|   133k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|   274k|    }
  ------------------
  977|   274k|    if (direction == ssl_secret_read) {
  ------------------
  |  Branch (977:9): [True: 141k, False: 132k]
  ------------------
  978|   141k|        epoch = ss->ssl3.crSpec->epoch;
  979|   141k|    } else {
  980|   132k|        epoch = ss->ssl3.cwSpec->epoch;
  981|   132k|    }
  982|   274k|    ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|   274k|    {                                             \
  |  | 1428|   274k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 133k, False: 140k]
  |  |  ------------------
  |  | 1429|   274k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|   133k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|   274k|    }
  ------------------
  983|       |
  984|   274k|    if (epoch == PR_UINT16_MAX) {
  ------------------
  |  |  270|   274k|#define PR_UINT16_MAX 65535U
  ------------------
  |  Branch (984:9): [True: 0, False: 274k]
  ------------------
  985|       |        /* Good chance that this is an overflow from too many updates. */
  986|      0|        FATAL_ERROR(ss, SSL_ERROR_TOO_MANY_KEY_UPDATES, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  987|      0|        return SECFailure;
  988|      0|    }
  989|   274k|    ++epoch;
  990|       |
  991|   274k|    if (ss->secretCallback) {
  ------------------
  |  Branch (991:9): [True: 0, False: 274k]
  ------------------
  992|      0|        ss->secretCallback(ss->fd, epoch, direction, updatedSecret,
  993|      0|                           ss->secretCallbackArg);
  994|      0|    }
  995|   274k|    rv = tls13_SetCipherSpec(ss, epoch, direction, PR_FALSE);
  ------------------
  |  |  438|   274k|#define PR_FALSE 0
  ------------------
  996|   274k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (996:9): [True: 0, False: 274k]
  ------------------
  997|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  998|      0|        return SECFailure;
  999|      0|    }
 1000|   274k|    return SECSuccess;
 1001|   274k|}
tls13_SendKeyUpdate:
 1005|   132k|{
 1006|   132k|    SECStatus rv;
 1007|       |
 1008|   132k|    SSL_TRC(3, ("%d: TLS13[%d]: %s send key update, response %s",
  ------------------
  |  |   71|   132k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 132k]
  |  |  ------------------
  |  |   72|   132k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1009|   132k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss),
 1010|   132k|                (request == update_requested) ? "requested"
 1011|   132k|                                              : "not requested"));
 1012|       |
 1013|   132k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   132k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   197k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 67.9k, False: 64.6k]
  |  |  |  |  |  Branch (208:7): [True: 64.6k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1014|   132k|    PORT_Assert(!ss->sec.isServer || !ss->ssl3.clientCertRequested);
  ------------------
  |  |  120|   132k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   265k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 132k]
  |  |  |  |  |  Branch (208:7): [True: 132k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1015|       |
 1016|   132k|    if (!tls13_IsPostHandshake(ss)) {
  ------------------
  |  Branch (1016:9): [True: 0, False: 132k]
  ------------------
 1017|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1018|      0|        return SECFailure;
 1019|      0|    }
 1020|       |
 1021|   132k|    rv = TLS13_CHECK_HS_STATE(ss, SEC_ERROR_LIBRARY_FAILURE,
  ------------------
  |  |  182|   132k|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|   132k|                       __VA_ARGS__,                                 \
  |  |  184|   132k|                       wait_invalid)
  ------------------
 1022|   132k|                              idle_handshake);
 1023|   132k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1023:9): [True: 0, False: 132k]
  ------------------
 1024|      0|        return SECFailure;
 1025|      0|    }
 1026|       |
 1027|   132k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   132k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 132k]
  |  |  ------------------
  ------------------
 1028|      0|        rv = dtls13_MaybeSendKeyUpdate(ss, request, buffer);
 1029|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1029:13): [True: 0, False: 0]
  ------------------
 1030|       |            /* Error code set already. */
 1031|      0|            return SECFailure;
 1032|      0|        }
 1033|      0|        return rv;
 1034|      0|    }
 1035|       |
 1036|   132k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|   132k|    {                                           \
  |  | 1467|   132k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 64.6k, False: 67.9k]
  |  |  ------------------
  |  | 1468|   132k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|  64.6k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|   132k|    }
  ------------------
 1037|   132k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_key_update, 1);
 1038|   132k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1038:9): [True: 0, False: 132k]
  ------------------
 1039|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1040|      0|        goto loser;
 1041|      0|    }
 1042|   132k|    rv = ssl3_AppendHandshakeNumber(ss, request, 1);
 1043|   132k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1043:9): [True: 0, False: 132k]
  ------------------
 1044|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1045|      0|        goto loser;
 1046|      0|    }
 1047|       |
 1048|       |    /* If we have been asked to buffer, then do so.  This allows us to coalesce
 1049|       |     * a KeyUpdate with a pending write. */
 1050|   132k|    rv = ssl3_FlushHandshake(ss, buffer ? ssl_SEND_FLAG_FORCE_INTO_BUFFER : 0);
  ------------------
  |  |  223|      0|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
  |  Branch (1050:34): [True: 0, False: 132k]
  ------------------
 1051|   132k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1051:9): [True: 0, False: 132k]
  ------------------
 1052|      0|        goto loser; /* error code set by ssl3_FlushHandshake */
 1053|      0|    }
 1054|   132k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|   132k|    {                                          \
  |  | 1472|   132k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 64.6k, False: 67.9k]
  |  |  ------------------
  |  | 1473|   132k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|  64.6k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|   132k|    }
  ------------------
 1055|       |
 1056|   132k|    rv = tls13_UpdateTrafficKeys(ss, ssl_secret_write);
 1057|   132k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1057:9): [True: 0, False: 132k]
  ------------------
 1058|      0|        goto loser; /* error code set by tls13_UpdateTrafficKeys */
 1059|      0|    }
 1060|       |
 1061|   132k|    return SECSuccess;
 1062|       |
 1063|      0|loser:
 1064|      0|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
 1065|      0|    return SECFailure;
 1066|   132k|}
SSLExp_SetCertificateCompressionAlgorithm:
 1107|  4.93k|{
 1108|  4.93k|    sslSocket *ss = ssl_FindSocket(fd);
 1109|  4.93k|    if (!ss) {
  ------------------
  |  Branch (1109:9): [True: 0, False: 4.93k]
  ------------------
 1110|      0|        return SECFailure; /* Code already set. */
 1111|      0|    }
 1112|       |
 1113|  4.93k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  4.93k|    {                                                 \
  |  | 1408|  4.93k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 4.93k, False: 0]
  |  |  ------------------
  |  | 1409|  4.93k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  4.93k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  4.93k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 4.93k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  4.93k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  4.93k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  4.93k|        }                                             \
  |  | 1412|  4.93k|    }
  ------------------
 1114|  4.93k|    if (ss->ssl3.supportedCertCompressionAlgorithmsCount == MAX_SUPPORTED_CERTIFICATE_COMPRESSION_ALGS) {
  ------------------
  |  |  252|  4.93k|#define MAX_SUPPORTED_CERTIFICATE_COMPRESSION_ALGS 32
  ------------------
  |  Branch (1114:9): [True: 0, False: 4.93k]
  ------------------
 1115|      0|        goto loser;
 1116|      0|    }
 1117|       |
 1118|       |    /* Reserved ID */
 1119|  4.93k|    if (alg.id == 0) {
  ------------------
  |  Branch (1119:9): [True: 0, False: 4.93k]
  ------------------
 1120|      0|        goto loser;
 1121|      0|    }
 1122|       |
 1123|  4.93k|    if (alg.encode == NULL && alg.decode == NULL) {
  ------------------
  |  Branch (1123:9): [True: 0, False: 4.93k]
  |  Branch (1123:31): [True: 0, False: 0]
  ------------------
 1124|      0|        goto loser;
 1125|      0|    }
 1126|       |
 1127|       |    /* Checking that we have not yet registed an algorithm with the same ID. */
 1128|  4.93k|    for (int i = 0; i < ss->ssl3.supportedCertCompressionAlgorithmsCount; i++) {
  ------------------
  |  Branch (1128:21): [True: 0, False: 4.93k]
  ------------------
 1129|      0|        if (ss->ssl3.supportedCertCompressionAlgorithms[i].id == alg.id) {
  ------------------
  |  Branch (1129:13): [True: 0, False: 0]
  ------------------
 1130|      0|            goto loser;
 1131|      0|        }
 1132|      0|    }
 1133|       |
 1134|  4.93k|    PORT_Memcpy(&ss->ssl3.supportedCertCompressionAlgorithms
  ------------------
  |  |  180|  4.93k|#define PORT_Memcpy memcpy
  ------------------
 1135|  4.93k|                     [ss->ssl3.supportedCertCompressionAlgorithmsCount],
 1136|  4.93k|                &alg, sizeof(alg));
 1137|  4.93k|    ss->ssl3.supportedCertCompressionAlgorithmsCount += 1;
 1138|  4.93k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  4.93k|    {                                                \
  |  | 1415|  4.93k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 4.93k, False: 0]
  |  |  ------------------
  |  | 1416|  4.93k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  4.93k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  4.93k|    }
  ------------------
 1139|  4.93k|    return SECSuccess;
 1140|       |
 1141|      0|loser:
 1142|      0|    PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1143|      0|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|      0|    {                                                \
  |  | 1415|      0|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1416|      0|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|      0|    }
  ------------------
 1144|      0|    return SECFailure;
 1145|  4.93k|}
tls13_HandlePostHelloHandshakeMessage:
 1293|   142k|{
 1294|   142k|    if (ss->sec.isServer && ss->ssl3.hs.zeroRttIgnore != ssl_0rtt_ignore_none) {
  ------------------
  |  Branch (1294:9): [True: 142k, False: 0]
  |  Branch (1294:29): [True: 20, False: 142k]
  ------------------
 1295|     20|        SSL_TRC(3, ("%d: TLS13[%d]: successfully decrypted handshake after "
  ------------------
  |  |   71|     20|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 20]
  |  |  ------------------
  |  |   72|     20|    ssl_Trace b
  ------------------
 1296|     20|                    "failed 0-RTT",
 1297|     20|                    SSL_GETPID(), ss->fd));
 1298|     20|        ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_none;
 1299|     20|    }
 1300|       |
 1301|       |    /* TODO(ekr@rtfm.com): Would it be better to check all the states here? */
 1302|   142k|    switch (ss->ssl3.hs.msg_type) {
 1303|     53|        case ssl_hs_certificate:
  ------------------
  |  Branch (1303:9): [True: 53, False: 142k]
  ------------------
 1304|     53|            return tls13_HandleCertificate(ss, b, length, PR_FALSE);
  ------------------
  |  |  438|     53|#define PR_FALSE 0
  ------------------
 1305|     17|        case ssl_hs_compressed_certificate:
  ------------------
  |  Branch (1305:9): [True: 17, False: 142k]
  ------------------
 1306|     17|            return tls13_HandleCertificateDecode(ss, b, length);
 1307|      3|        case ssl_hs_certificate_request:
  ------------------
  |  Branch (1307:9): [True: 3, False: 142k]
  ------------------
 1308|      3|            return tls13_HandleCertificateRequest(ss, b, length);
 1309|       |
 1310|      2|        case ssl_hs_certificate_verify:
  ------------------
  |  Branch (1310:9): [True: 2, False: 142k]
  ------------------
 1311|      2|            return tls13_HandleCertificateVerify(ss, b, length);
 1312|       |
 1313|      3|        case ssl_hs_encrypted_extensions:
  ------------------
  |  Branch (1313:9): [True: 3, False: 142k]
  ------------------
 1314|      3|            return tls13_HandleEncryptedExtensions(ss, b, length);
 1315|       |
 1316|      2|        case ssl_hs_new_session_ticket:
  ------------------
  |  Branch (1316:9): [True: 2, False: 142k]
  ------------------
 1317|      2|            return tls13_HandleNewSessionTicket(ss, b, length);
 1318|       |
 1319|    430|        case ssl_hs_finished:
  ------------------
  |  Branch (1319:9): [True: 430, False: 142k]
  ------------------
 1320|    430|            if (ss->sec.isServer) {
  ------------------
  |  Branch (1320:17): [True: 430, False: 0]
  ------------------
 1321|    430|                return tls13_ServerHandleFinished(ss, b, length);
 1322|    430|            } else {
 1323|      0|                return tls13_ClientHandleFinished(ss, b, length);
 1324|      0|            }
 1325|       |
 1326|      3|        case ssl_hs_end_of_early_data:
  ------------------
  |  Branch (1326:9): [True: 3, False: 142k]
  ------------------
 1327|      3|            return tls13_HandleEndOfEarlyData(ss, b, length);
 1328|       |
 1329|   141k|        case ssl_hs_key_update:
  ------------------
  |  Branch (1329:9): [True: 141k, False: 526]
  ------------------
 1330|   141k|            return tls13_HandleKeyUpdate(ss, b, length);
 1331|       |
 1332|     13|        default:
  ------------------
  |  Branch (1332:9): [True: 13, False: 142k]
  ------------------
 1333|     13|            FATAL_ERROR(ss, SSL_ERROR_RX_UNKNOWN_HANDSHAKE, unexpected_message);
  ------------------
  |  |   22|     13|    do {                                     \
  |  |   23|     13|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     13|    do {                                                                           \
  |  |  |  |   15|     13|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     13|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 13]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     13|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     13|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     13|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     13|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     13|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     13|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     13|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1334|     13|            return SECFailure;
 1335|   142k|    }
 1336|       |
 1337|      0|    PORT_Assert(0); /* Unreached */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1338|      0|    return SECFailure;
 1339|   142k|}
tls13_SelectServerCert:
 2008|  1.25k|{
 2009|  1.25k|    PRCList *cursor;
 2010|  1.25k|    SECStatus rv;
 2011|       |
 2012|  1.25k|    if (!ssl3_ExtensionNegotiated(ss, ssl_signature_algorithms_xtn)) {
  ------------------
  |  Branch (2012:9): [True: 2, False: 1.24k]
  ------------------
 2013|      2|        FATAL_ERROR(ss, SSL_ERROR_MISSING_SIGNATURE_ALGORITHMS_EXTENSION,
  ------------------
  |  |   22|      2|    do {                                     \
  |  |   23|      2|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      2|    do {                                                                           \
  |  |  |  |   15|      2|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      2|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 2]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      2|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      2|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      2|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      2|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      2|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      2|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2014|      2|                    missing_extension);
 2015|      2|        return SECFailure;
 2016|      2|    }
 2017|       |
 2018|       |    /* This picks the first certificate that has:
 2019|       |     * a) the right authentication method, and
 2020|       |     * b) the right named curve (EC only)
 2021|       |     *
 2022|       |     * We might want to do some sort of ranking here later.  For now, it's all
 2023|       |     * based on what order they are configured in. */
 2024|  1.24k|    for (cursor = PR_NEXT_LINK(&ss->serverCerts);
  ------------------
  |  |   47|  1.24k|        ((_e)->next)
  ------------------
 2025|  2.39k|         cursor != &ss->serverCerts;
  ------------------
  |  Branch (2025:10): [True: 2.39k, False: 3]
  ------------------
 2026|  2.39k|         cursor = PR_NEXT_LINK(cursor)) {
  ------------------
  |  |   47|  1.14k|        ((_e)->next)
  ------------------
 2027|  2.39k|        sslServerCert *cert = (sslServerCert *)cursor;
 2028|       |
 2029|  2.39k|        if (SSL_CERT_IS_ONLY(cert, ssl_auth_rsa_decrypt)) {
  ------------------
  |  |   54|  2.39k|#define SSL_CERT_IS_ONLY(c, t) ((c)->authTypes == (1 << (t)))
  |  |  ------------------
  |  |  |  Branch (54:32): [True: 0, False: 2.39k]
  |  |  ------------------
  ------------------
 2030|      0|            continue;
 2031|      0|        }
 2032|       |
 2033|  2.39k|        rv = ssl_PickSignatureScheme(ss,
 2034|  2.39k|                                     cert->serverCert,
 2035|  2.39k|                                     cert->serverKeyPair->pubKey,
 2036|  2.39k|                                     cert->serverKeyPair->privKey,
 2037|  2.39k|                                     ss->xtnData.sigSchemes,
 2038|  2.39k|                                     ss->xtnData.numSigSchemes,
 2039|  2.39k|                                     PR_FALSE,
  ------------------
  |  |  438|  2.39k|#define PR_FALSE 0
  ------------------
 2040|  2.39k|                                     &ss->ssl3.hs.signatureScheme);
 2041|  2.39k|        if (rv == SECSuccess) {
  ------------------
  |  Branch (2041:13): [True: 1.24k, False: 1.14k]
  ------------------
 2042|       |            /* Found one. */
 2043|  1.24k|            ss->sec.serverCert = cert;
 2044|       |
 2045|       |            /* If we can use a delegated credential (DC) for authentication in
 2046|       |             * the current handshake, then commit to using it now. We'll send a
 2047|       |             * DC as an extension and use the DC private key to sign the
 2048|       |             * handshake.
 2049|       |             *
 2050|       |             * This sets the signature scheme to be the signature scheme
 2051|       |             * indicated by the DC.
 2052|       |             */
 2053|  1.24k|            rv = tls13_MaybeSetDelegatedCredential(ss);
 2054|  1.24k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2054:17): [True: 0, False: 1.24k]
  ------------------
 2055|      0|                return SECFailure; /* Failure indicates an internal error. */
 2056|      0|            }
 2057|       |
 2058|  1.24k|            ss->sec.authType = ss->ssl3.hs.kea_def_mutable.authKeyType =
 2059|  1.24k|                ssl_SignatureSchemeToAuthType(ss->ssl3.hs.signatureScheme);
 2060|  1.24k|            ss->sec.authKeyBits = cert->serverKeyBits;
 2061|  1.24k|            return SECSuccess;
 2062|  1.24k|        }
 2063|  2.39k|    }
 2064|       |
 2065|      3|    FATAL_ERROR(ss, SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM,
  ------------------
  |  |   22|      3|    do {                                     \
  |  |   23|      3|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      3|    do {                                                                           \
  |  |  |  |   15|      3|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      3|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      3|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      3|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      3|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      3|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      3|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2066|      3|                handshake_failure);
 2067|      3|    return SECFailure;
 2068|  1.24k|}
tls13_HandleClientHelloPart2:
 2184|  1.55k|{
 2185|  1.55k|    SECStatus rv;
 2186|  1.55k|    SSL3Statistics *ssl3stats = SSL_GetStatistics();
 2187|  1.55k|    const sslNamedGroupDef *requestedGroup = NULL;
 2188|  1.55k|    TLS13KeyShareEntry *clientShare = NULL;
 2189|  1.55k|    ssl3CipherSuite previousCipherSuite = 0;
 2190|  1.55k|    const sslNamedGroupDef *previousGroup = NULL;
 2191|  1.55k|    PRBool hrr = PR_FALSE;
  ------------------
  |  |  438|  1.55k|#define PR_FALSE 0
  ------------------
 2192|  1.55k|    PRBool previousOfferedEch;
 2193|       |
 2194|       |    /* If the legacy_version field is set to 0x300 or smaller,
 2195|       |     * reject the connection with protocol_version alert. */
 2196|  1.55k|    if (ss->clientHelloVersion <= SSL_LIBRARY_VERSION_3_0) {
  ------------------
  |  |   17|  1.55k|#define SSL_LIBRARY_VERSION_3_0                 0x0300
  ------------------
  |  Branch (2196:9): [True: 11, False: 1.54k]
  ------------------
 2197|     11|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, protocol_version);
  ------------------
  |  |   22|     11|    do {                                     \
  |  |   23|     11|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     11|    do {                                                                           \
  |  |  |  |   15|     11|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     11|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 11]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     11|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     11|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     11|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     11|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     11|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     11|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     11|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2198|     11|        goto loser;
 2199|     11|    }
 2200|       |
 2201|  1.54k|    ss->ssl3.hs.endOfFlight = PR_TRUE;
  ------------------
  |  |  437|  1.54k|#define PR_TRUE 1
  ------------------
 2202|       |
 2203|  1.54k|    if (ssl3_ExtensionNegotiated(ss, ssl_tls13_early_data_xtn)) {
  ------------------
  |  Branch (2203:9): [True: 92, False: 1.44k]
  ------------------
 2204|     92|        ss->ssl3.hs.zeroRttState = ssl_0rtt_sent;
 2205|     92|    }
 2206|       |
 2207|       |    /* Negotiate cipher suite. */
 2208|  1.54k|    rv = ssl3_NegotiateCipherSuite(ss, suites, PR_FALSE);
  ------------------
  |  |  438|  1.54k|#define PR_FALSE 0
  ------------------
 2209|  1.54k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2209:9): [True: 10, False: 1.53k]
  ------------------
 2210|     10|        FATAL_ERROR(ss, PORT_GetError(), handshake_failure);
  ------------------
  |  |   22|     10|    do {                                     \
  |  |   23|     10|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     10|    do {                                                                           \
  |  |  |  |   15|     10|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     10|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 10]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     10|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     10|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     10|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     10|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     10|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     10|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     10|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2211|     10|        goto loser;
 2212|     10|    }
 2213|       |
 2214|       |    /* If we are going around again, then we should make sure that the cipher
 2215|       |     * suite selection doesn't change. That's a sign of client shennanigans. */
 2216|  1.53k|    if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (2216:9): [True: 65, False: 1.46k]
  ------------------
 2217|       |
 2218|       |        /* Update sequence numbers before checking the cookie so that any alerts
 2219|       |         * we generate are sent with the right sequence numbers. */
 2220|     65|        if (IS_DTLS(ss)) {
  ------------------
  |  |  892|     65|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 65]
  |  |  ------------------
  ------------------
 2221|       |            /* Count the first ClientHello and the HelloRetryRequest. */
 2222|      0|            ss->ssl3.hs.sendMessageSeq = 1;
 2223|      0|            ss->ssl3.hs.recvMessageSeq = 1;
 2224|      0|            ssl_GetSpecWriteLock(ss);
  ------------------
  |  | 1435|      0|    {                                            \
  |  | 1436|      0|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1437|      0|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|      0|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|      0|    }
  ------------------
 2225|       |            /* Increase the write sequence number.  The read sequence number
 2226|       |             * will be reset after this to early data or handshake. */
 2227|      0|            ss->ssl3.cwSpec->nextSeqNum = 1;
 2228|      0|            ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|      0|    {                                              \
  |  | 1441|      0|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1442|      0|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|      0|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|      0|    }
  ------------------
 2229|      0|        }
 2230|       |
 2231|     65|        if (!ssl3_ExtensionNegotiated(ss, ssl_tls13_cookie_xtn) ||
  ------------------
  |  Branch (2231:13): [True: 41, False: 24]
  ------------------
 2232|     65|            !ss->xtnData.cookie.len) {
  ------------------
  |  Branch (2232:13): [True: 0, False: 24]
  ------------------
 2233|     41|            FATAL_ERROR(ss, SSL_ERROR_MISSING_COOKIE_EXTENSION,
  ------------------
  |  |   22|     41|    do {                                     \
  |  |   23|     41|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     41|    do {                                                                           \
  |  |  |  |   15|     41|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     41|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 41]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     41|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     41|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     41|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     41|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     41|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     41|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     41|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2234|     41|                        missing_extension);
 2235|     41|            goto loser;
 2236|     41|        }
 2237|     24|        PRINT_BUF(50, (ss, "Client sent cookie",
  ------------------
  |  |   74|     24|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 24]
  |  |  ------------------
  |  |   75|     24|    ssl_PrintBuf b
  ------------------
 2238|     24|                       ss->xtnData.cookie.data, ss->xtnData.cookie.len));
 2239|       |
 2240|     24|        rv = tls13_HandleHrrCookie(ss, ss->xtnData.cookie.data,
 2241|     24|                                   ss->xtnData.cookie.len,
 2242|     24|                                   &previousCipherSuite,
 2243|     24|                                   &previousGroup,
 2244|     24|                                   &previousOfferedEch, NULL, PR_TRUE);
  ------------------
  |  |  437|     24|#define PR_TRUE 1
  ------------------
 2245|       |
 2246|     24|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2246:13): [True: 24, False: 0]
  ------------------
 2247|     24|            FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|     24|    do {                                     \
  |  |   23|     24|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     24|    do {                                                                           \
  |  |  |  |   15|     24|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     24|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 24]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     24|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     24|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     24|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     24|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     24|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     24|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     24|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2248|     24|            goto loser;
 2249|     24|        }
 2250|     24|    }
 2251|       |
 2252|       |    /* Now merge the ClientHello into the hash state. */
 2253|  1.46k|    rv = ssl_HashHandshakeMessage(ss, ssl_hs_client_hello, msg, len);
 2254|  1.46k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2254:9): [True: 0, False: 1.46k]
  ------------------
 2255|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2256|      0|        goto loser;
 2257|      0|    }
 2258|       |
 2259|       |    /* Now create a synthetic kea_def that we can tweak. */
 2260|  1.46k|    ss->ssl3.hs.kea_def_mutable = *ss->ssl3.hs.kea_def;
 2261|  1.46k|    ss->ssl3.hs.kea_def = &ss->ssl3.hs.kea_def_mutable;
 2262|       |
 2263|       |    /* Note: We call this quite a bit earlier than with TLS 1.2 and
 2264|       |     * before. */
 2265|  1.46k|    rv = ssl3_ServerCallSNICallback(ss);
 2266|  1.46k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2266:9): [True: 0, False: 1.46k]
  ------------------
 2267|      0|        goto loser; /* An alert has already been sent. */
 2268|      0|    }
 2269|       |
 2270|       |    /* Check if we could in principle resume. */
 2271|  1.46k|    if (ss->statelessResume) {
  ------------------
  |  Branch (2271:9): [True: 47, False: 1.41k]
  ------------------
 2272|     47|        PORT_Assert(sid);
  ------------------
  |  |  120|     47|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     47|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 47, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2273|     47|        if (!sid) {
  ------------------
  |  Branch (2273:13): [True: 0, False: 47]
  ------------------
 2274|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2275|      0|            return SECFailure;
 2276|      0|        }
 2277|     47|        if (!tls13_CanResume(ss, sid)) {
  ------------------
  |  Branch (2277:13): [True: 44, False: 3]
  ------------------
 2278|     44|            ss->statelessResume = PR_FALSE;
  ------------------
  |  |  438|     44|#define PR_FALSE 0
  ------------------
 2279|     44|        }
 2280|     47|    }
 2281|       |
 2282|       |    /* Select key exchange. */
 2283|  1.46k|    rv = tls13_NegotiateKeyExchange(ss, &requestedGroup, &clientShare);
 2284|  1.46k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2284:9): [True: 34, False: 1.43k]
  ------------------
 2285|     34|        goto loser;
 2286|     34|    }
 2287|       |    /* We should get either one of these, but not both. */
 2288|  1.43k|    PORT_Assert((requestedGroup && !clientShare) ||
  ------------------
  |  |  120|  1.43k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  6.79k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 181, False: 1.25k]
  |  |  |  |  |  Branch (208:7): [True: 181, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1.25k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1.25k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2289|  1.43k|                (!requestedGroup && clientShare));
 2290|       |
 2291|       |    /* After HelloRetryRequest, check consistency of cipher and group. */
 2292|  1.43k|    if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (2292:9): [True: 0, False: 1.43k]
  ------------------
 2293|      0|        PORT_Assert(previousCipherSuite);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2294|      0|        if (ss->ssl3.hs.cipher_suite != previousCipherSuite) {
  ------------------
  |  Branch (2294:13): [True: 0, False: 0]
  ------------------
 2295|      0|            FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2296|      0|                        illegal_parameter);
 2297|      0|            goto loser;
 2298|      0|        }
 2299|      0|        if (!clientShare) {
  ------------------
  |  Branch (2299:13): [True: 0, False: 0]
  ------------------
 2300|      0|            FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2301|      0|                        illegal_parameter);
 2302|      0|            goto loser;
 2303|      0|        }
 2304|       |
 2305|       |        /* CH1/CH2 must either both include ECH, or both exclude it. */
 2306|      0|        if (previousOfferedEch != (ss->xtnData.ech != NULL)) {
  ------------------
  |  Branch (2306:13): [True: 0, False: 0]
  ------------------
 2307|      0|            FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  ------------------
  |  |  |  Branch (24:39): [True: 0, False: 0]
  |  |  ------------------
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2308|      0|                        previousOfferedEch ? missing_extension : illegal_parameter);
 2309|      0|            goto loser;
 2310|      0|        }
 2311|       |
 2312|       |        /* If we requested a new key share, check that the client provided just
 2313|       |         * one of the right type. */
 2314|      0|        if (previousGroup) {
  ------------------
  |  Branch (2314:13): [True: 0, False: 0]
  ------------------
 2315|      0|            if (PR_PREV_LINK(&ss->xtnData.remoteKeyShares) !=
  ------------------
  |  |   52|      0|        ((_e)->prev)
  ------------------
  |  Branch (2315:17): [True: 0, False: 0]
  ------------------
 2316|      0|                PR_NEXT_LINK(&ss->xtnData.remoteKeyShares)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
 2317|      0|                FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2318|      0|                            illegal_parameter);
 2319|      0|                goto loser;
 2320|      0|            }
 2321|      0|            if (clientShare->group != previousGroup) {
  ------------------
  |  Branch (2321:17): [True: 0, False: 0]
  ------------------
 2322|      0|                FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2323|      0|                            illegal_parameter);
 2324|      0|                goto loser;
 2325|      0|            }
 2326|      0|        }
 2327|      0|    }
 2328|       |
 2329|  1.43k|    rv = tls13_MaybeSendHelloRetry(ss, requestedGroup, &hrr);
 2330|  1.43k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2330:9): [True: 0, False: 1.43k]
  ------------------
 2331|      0|        goto loser;
 2332|      0|    }
 2333|  1.43k|    if (hrr) {
  ------------------
  |  Branch (2333:9): [True: 181, False: 1.25k]
  ------------------
 2334|    181|        if (sid) { /* Free the sid. */
  ------------------
  |  Branch (2334:13): [True: 22, False: 159]
  ------------------
 2335|     22|            ssl_UncacheSessionID(ss);
 2336|     22|            ssl_FreeSID(sid);
 2337|     22|        }
 2338|    181|        PORT_Assert(ss->ssl3.hs.helloRetry);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2339|    181|        return SECSuccess;
 2340|    181|    }
 2341|       |
 2342|       |    /* Select the authentication (this is also handshake shape). */
 2343|  1.25k|    rv = tls13_NegotiateAuthentication(ss);
 2344|  1.25k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2344:9): [True: 5, False: 1.24k]
  ------------------
 2345|      5|        goto loser;
 2346|      5|    }
 2347|       |
 2348|  1.24k|    if (ss->sec.authType == ssl_auth_psk) {
  ------------------
  |  Branch (2348:9): [True: 0, False: 1.24k]
  ------------------
 2349|      0|        if (ss->statelessResume) {
  ------------------
  |  Branch (2349:13): [True: 0, False: 0]
  ------------------
 2350|       |            /* We are now committed to trying to resume. */
 2351|      0|            PORT_Assert(sid);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2352|       |            /* Check that the negotiated SNI and the cached SNI match. */
 2353|      0|            if (SECITEM_CompareItem(&sid->u.ssl3.srvName,
  ------------------
  |  |  105|      0|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (2353:17): [True: 0, False: 0]
  ------------------
 2354|      0|                                    &ss->ssl3.hs.srvVirtName) != SECEqual) {
 2355|      0|                FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2356|      0|                            handshake_failure);
 2357|      0|                goto loser;
 2358|      0|            }
 2359|       |
 2360|      0|            ss->sec.serverCert = ssl_FindServerCert(ss, sid->authType,
 2361|      0|                                                    sid->namedCurve);
 2362|      0|            PORT_Assert(ss->sec.serverCert);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2363|       |
 2364|      0|            rv = tls13_RecoverWrappedSharedSecret(ss, sid);
 2365|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2365:17): [True: 0, False: 0]
  ------------------
 2366|      0|                SSL_AtomicIncrementLong(&ssl3stats->hch_sid_cache_not_ok);
 2367|      0|                FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2368|      0|                goto loser;
 2369|      0|            }
 2370|      0|            tls13_RestoreCipherInfo(ss, sid);
 2371|       |
 2372|      0|            PORT_Assert(!ss->sec.localCert);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2373|      0|            ss->sec.localCert = CERT_DupCertificate(ss->sec.serverCert->serverCert);
 2374|      0|            if (sid->peerCert != NULL) {
  ------------------
  |  Branch (2374:17): [True: 0, False: 0]
  ------------------
 2375|      0|                ss->sec.peerCert = CERT_DupCertificate(sid->peerCert);
 2376|      0|            }
 2377|      0|        } else if (sid) {
  ------------------
  |  Branch (2377:20): [True: 0, False: 0]
  ------------------
 2378|       |            /* We should never have a SID in the non-resumption case. */
 2379|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2380|      0|            ssl_UncacheSessionID(ss);
 2381|      0|            ssl_FreeSID(sid);
 2382|      0|            sid = NULL;
 2383|      0|        }
 2384|      0|        ssl3_RegisterExtensionSender(
 2385|      0|            ss, &ss->xtnData,
 2386|      0|            ssl_tls13_pre_shared_key_xtn, tls13_ServerSendPreSharedKeyXtn);
 2387|      0|        tls13_NegotiateZeroRtt(ss, sid);
 2388|       |
 2389|      0|        rv = tls13_ComputeEarlySecretsWithPsk(ss);
 2390|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2390:13): [True: 0, False: 0]
  ------------------
 2391|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2392|      0|            return SECFailure;
 2393|      0|        }
 2394|  1.24k|    } else {
 2395|  1.24k|        if (sid) { /* we had a sid, but it's no longer valid, free it */
  ------------------
  |  Branch (2395:13): [True: 0, False: 1.24k]
  ------------------
 2396|      0|            SSL_AtomicIncrementLong(&ssl3stats->hch_sid_cache_not_ok);
 2397|      0|            ssl_UncacheSessionID(ss);
 2398|      0|            ssl_FreeSID(sid);
 2399|      0|            sid = NULL;
 2400|      0|        }
 2401|  1.24k|        tls13_NegotiateZeroRtt(ss, NULL);
 2402|  1.24k|    }
 2403|       |
 2404|  1.24k|    if (ss->statelessResume) {
  ------------------
  |  Branch (2404:9): [True: 0, False: 1.24k]
  ------------------
 2405|      0|        PORT_Assert(ss->xtnData.selectedPsk);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2406|      0|        PORT_Assert(ss->ssl3.hs.kea_def_mutable.authKeyType == ssl_auth_psk);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2407|      0|    }
 2408|       |
 2409|       |    /* Now that we have the binder key, check the binder. */
 2410|  1.24k|    if (ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (2410:9): [True: 0, False: 1.24k]
  ------------------
 2411|      0|        SSL3Hashes hashes;
 2412|      0|        PORT_Assert(ss->ssl3.hs.messages.len > ss->xtnData.pskBindersLen);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2413|      0|        rv = tls13_ComputePskBinderHash(
 2414|      0|            ss,
 2415|      0|            ss->ssl3.hs.messages.buf,
 2416|      0|            ss->ssl3.hs.messages.len - ss->xtnData.pskBindersLen,
 2417|      0|            &hashes, tls13_GetHash(ss));
 2418|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2418:13): [True: 0, False: 0]
  ------------------
 2419|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2420|      0|            goto loser;
 2421|      0|        }
 2422|       |
 2423|      0|        PORT_Assert(ss->xtnData.selectedPsk->hash == tls13_GetHash(ss));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2424|      0|        PORT_Assert(ss->ssl3.hs.suite_def);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2425|      0|        rv = tls13_VerifyFinished(ss, ssl_hs_client_hello,
 2426|      0|                                  ss->xtnData.selectedPsk->binderKey,
 2427|      0|                                  ss->xtnData.pskBinder.data,
 2428|      0|                                  ss->xtnData.pskBinder.len,
 2429|      0|                                  &hashes);
 2430|      0|    }
 2431|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2431:9): [True: 0, False: 1.24k]
  ------------------
 2432|      0|        goto loser;
 2433|      0|    }
 2434|       |
 2435|       |    /* This needs to go after we verify the psk binder. */
 2436|  1.24k|    rv = ssl3_InitHandshakeHashes(ss);
 2437|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2437:9): [True: 0, False: 1.24k]
  ------------------
 2438|      0|        goto loser;
 2439|      0|    }
 2440|       |
 2441|       |    /* If this is TLS 1.3 we are expecting a ClientKeyShare
 2442|       |     * extension. Missing/absent extension cause failure
 2443|       |     * below. */
 2444|  1.24k|    rv = tls13_HandleClientKeyShare(ss, clientShare);
 2445|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2445:9): [True: 32, False: 1.21k]
  ------------------
 2446|     32|        goto loser; /* An alert was sent already. */
 2447|     32|    }
 2448|       |
 2449|       |    /* From this point we are either committed to resumption, or not. */
 2450|  1.21k|    if (ss->statelessResume) {
  ------------------
  |  Branch (2450:9): [True: 0, False: 1.21k]
  ------------------
 2451|      0|        SSL_AtomicIncrementLong(&ssl3stats->hch_sid_cache_hits);
 2452|      0|        SSL_AtomicIncrementLong(&ssl3stats->hch_sid_stateless_resumes);
 2453|  1.21k|    } else {
 2454|  1.21k|        if (sid) {
  ------------------
  |  Branch (2454:13): [True: 0, False: 1.21k]
  ------------------
 2455|       |            /* We had a sid, but it's no longer valid, free it. */
 2456|      0|            SSL_AtomicIncrementLong(&ssl3stats->hch_sid_cache_not_ok);
 2457|      0|            ssl_UncacheSessionID(ss);
 2458|      0|            ssl_FreeSID(sid);
 2459|  1.21k|        } else if (!ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (2459:20): [True: 1.21k, False: 0]
  ------------------
 2460|  1.21k|            SSL_AtomicIncrementLong(&ssl3stats->hch_sid_cache_misses);
 2461|  1.21k|        }
 2462|       |
 2463|  1.21k|        sid = ssl3_NewSessionID(ss, PR_TRUE);
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
 2464|  1.21k|        if (!sid) {
  ------------------
  |  Branch (2464:13): [True: 0, False: 1.21k]
  ------------------
 2465|      0|            FATAL_ERROR(ss, PORT_GetError(), internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2466|      0|            return SECFailure;
 2467|      0|        }
 2468|  1.21k|    }
 2469|       |    /* Take ownership of the session. */
 2470|  1.21k|    ss->sec.ci.sid = sid;
 2471|  1.21k|    sid = NULL;
 2472|       |
 2473|  1.21k|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted) {
  ------------------
  |  Branch (2473:9): [True: 0, False: 1.21k]
  ------------------
 2474|      0|        rv = tls13_DeriveEarlySecrets(ss);
 2475|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2475:13): [True: 0, False: 0]
  ------------------
 2476|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2477|      0|            return SECFailure;
 2478|      0|        }
 2479|      0|    }
 2480|       |
 2481|  1.21k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|  1.21k|    {                                           \
  |  | 1467|  1.21k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 588, False: 625]
  |  |  ------------------
  |  | 1468|  1.21k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|    588|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|  1.21k|    }
  ------------------
 2482|  1.21k|    rv = tls13_SendServerHelloSequence(ss);
 2483|  1.21k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|  1.21k|    {                                          \
  |  | 1472|  1.21k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 588, False: 625]
  |  |  ------------------
  |  | 1473|  1.21k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|    588|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|  1.21k|    }
  ------------------
 2484|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2484:9): [True: 0, False: 1.21k]
  ------------------
 2485|      0|        FATAL_ERROR(ss, PORT_GetError(), handshake_failure);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2486|      0|        return SECFailure;
 2487|      0|    }
 2488|       |
 2489|       |    /* We're done with PSKs */
 2490|  1.21k|    tls13_DestroyPskList(&ss->ssl3.hs.psks);
 2491|  1.21k|    ss->xtnData.selectedPsk = NULL;
 2492|       |
 2493|  1.21k|    return SECSuccess;
 2494|       |
 2495|    157|loser:
 2496|    157|    if (sid) {
  ------------------
  |  Branch (2496:9): [True: 29, False: 128]
  ------------------
 2497|     29|        ssl_UncacheSessionID(ss);
 2498|     29|        ssl_FreeSID(sid);
 2499|     29|    }
 2500|    157|    return SECFailure;
 2501|  1.21k|}
tls13_ConstructHelloRetryRequest:
 2535|    181|{
 2536|    181|    SECStatus rv;
 2537|    181|    sslBuffer extensionsBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|    181|    {                        \
  |  |   24|    181|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|    181|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|    181|    }
  ------------------
 2538|    181|    PORT_Assert(buffer->len == 0);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2539|       |
 2540|       |    /* Note: cookie is pointing to a stack variable, so is only valid
 2541|       |     * now. */
 2542|    181|    ss->xtnData.selectedGroup = selectedGroup;
 2543|    181|    ss->xtnData.cookie.data = cookie;
 2544|    181|    ss->xtnData.cookie.len = cookieLen;
 2545|       |
 2546|       |    /* Set restored ss->ssl3.hs.greaseEchBuf value for ECH HRR extension
 2547|       |     * reconstruction. */
 2548|    181|    if (cookieGreaseEchSignal) {
  ------------------
  |  Branch (2548:9): [True: 0, False: 181]
  ------------------
 2549|      0|        PORT_Assert(!ss->ssl3.hs.greaseEchBuf.len);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2550|      0|        rv = sslBuffer_Append(&ss->ssl3.hs.greaseEchBuf,
 2551|      0|                              cookieGreaseEchSignal,
 2552|      0|                              TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|      0|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2553|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2553:13): [True: 0, False: 0]
  ------------------
 2554|      0|            goto loser;
 2555|      0|        }
 2556|      0|    }
 2557|    181|    rv = ssl_ConstructExtensions(ss, &extensionsBuf,
 2558|    181|                                 ssl_hs_hello_retry_request);
 2559|       |    /* Reset ss->ssl3.hs.greaseEchBuf if it was changed. */
 2560|    181|    if (cookieGreaseEchSignal) {
  ------------------
  |  Branch (2560:9): [True: 0, False: 181]
  ------------------
 2561|      0|        sslBuffer_Clear(&ss->ssl3.hs.greaseEchBuf);
 2562|      0|    }
 2563|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2563:9): [True: 0, False: 181]
  ------------------
 2564|      0|        goto loser;
 2565|      0|    }
 2566|       |    /* These extensions can't be empty. */
 2567|    181|    PORT_Assert(SSL_BUFFER_LEN(&extensionsBuf) > 0);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2568|       |
 2569|       |    /* Clean up cookie so we're not pointing at random memory. */
 2570|    181|    ss->xtnData.cookie.data = NULL;
 2571|    181|    ss->xtnData.cookie.len = 0;
 2572|       |
 2573|    181|    rv = ssl_ConstructServerHello(ss, PR_TRUE, &extensionsBuf, buffer);
  ------------------
  |  |  437|    181|#define PR_TRUE 1
  ------------------
 2574|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2574:9): [True: 0, False: 181]
  ------------------
 2575|      0|        goto loser;
 2576|      0|    }
 2577|    181|    sslBuffer_Clear(&extensionsBuf);
 2578|    181|    return SECSuccess;
 2579|       |
 2580|      0|loser:
 2581|      0|    sslBuffer_Clear(&extensionsBuf);
 2582|      0|    sslBuffer_Clear(buffer);
 2583|      0|    return SECFailure;
 2584|    181|}
tls13_ShouldRequestClientAuth:
 3244|  3.27k|{
 3245|       |    /* Even if we are configured to request a certificate, we can't
 3246|       |     * if this handshake used a PSK, even when we are resuming. */
 3247|  3.27k|    return ss->opt.requestCertificate &&
  ------------------
  |  Branch (3247:12): [True: 907, False: 2.36k]
  ------------------
 3248|  3.27k|           ss->ssl3.hs.kea_def->authKeyType != ssl_auth_psk;
  ------------------
  |  Branch (3248:12): [True: 907, False: 0]
  ------------------
 3249|  3.27k|}
tls13_AddContextToHashes:
 4298|  1.21k|{
 4299|  1.21k|    SECStatus rv = SECSuccess;
 4300|  1.21k|    PK11Context *ctx;
 4301|  1.21k|    const unsigned char context_padding[] = {
 4302|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4303|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4304|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4305|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4306|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4307|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4308|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20,
 4309|  1.21k|        0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20, 0x20
 4310|  1.21k|    };
 4311|       |
 4312|  1.21k|    const char *client_cert_verify_string = "TLS 1.3, client CertificateVerify";
 4313|  1.21k|    const char *server_cert_verify_string = "TLS 1.3, server CertificateVerify";
 4314|  1.21k|    const char *context_string = (sending ^ ss->sec.isServer) ? client_cert_verify_string
  ------------------
  |  Branch (4314:34): [True: 0, False: 1.21k]
  ------------------
 4315|  1.21k|                                                              : server_cert_verify_string;
 4316|  1.21k|    unsigned int hashlength;
 4317|       |
 4318|       |    /* Double check that we are doing the same hash.*/
 4319|  1.21k|    PORT_Assert(hashes->len == tls13_GetHashSize(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4320|       |
 4321|  1.21k|    ctx = PK11_CreateDigestContext(ssl3_HashTypeToOID(algorithm));
 4322|  1.21k|    if (!ctx) {
  ------------------
  |  Branch (4322:9): [True: 0, False: 1.21k]
  ------------------
 4323|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4324|      0|        goto loser;
 4325|      0|    }
 4326|       |
 4327|  1.21k|    PORT_Assert(SECFailure);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4328|  1.21k|    PORT_Assert(!SECSuccess);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4329|       |
 4330|  1.21k|    PRINT_BUF(50, (ss, "TLS 1.3 hash without context", hashes->u.raw, hashes->len));
  ------------------
  |  |   74|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   75|  1.21k|    ssl_PrintBuf b
  ------------------
 4331|  1.21k|    PRINT_BUF(50, (ss, "Context string", context_string, strlen(context_string)));
  ------------------
  |  |   74|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   75|  1.21k|    ssl_PrintBuf b
  ------------------
 4332|  1.21k|    rv |= PK11_DigestBegin(ctx);
 4333|  1.21k|    rv |= PK11_DigestOp(ctx, context_padding, sizeof(context_padding));
 4334|  1.21k|    rv |= PK11_DigestOp(ctx, (unsigned char *)context_string,
 4335|  1.21k|                        strlen(context_string) + 1); /* +1 includes the terminating 0 */
 4336|  1.21k|    rv |= PK11_DigestOp(ctx, hashes->u.raw, hashes->len);
 4337|       |    /* Update the hash in-place */
 4338|  1.21k|    rv |= PK11_DigestFinal(ctx, tbsHash->u.raw, &hashlength, sizeof(tbsHash->u.raw));
 4339|  1.21k|    PK11_DestroyContext(ctx, PR_TRUE);
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
 4340|  1.21k|    PRINT_BUF(50, (ss, "TLS 1.3 hash with context", tbsHash->u.raw, hashlength));
  ------------------
  |  |   74|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   75|  1.21k|    ssl_PrintBuf b
  ------------------
 4341|       |
 4342|  1.21k|    tbsHash->len = hashlength;
 4343|  1.21k|    tbsHash->hashAlg = algorithm;
 4344|       |
 4345|  1.21k|    if (rv) {
  ------------------
  |  Branch (4345:9): [True: 0, False: 1.21k]
  ------------------
 4346|      0|        ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4347|      0|        goto loser;
 4348|      0|    }
 4349|  1.21k|    return SECSuccess;
 4350|       |
 4351|      0|loser:
 4352|      0|    return SECFailure;
 4353|  1.21k|}
tls13_DeriveSecret:
 4367|  8.90k|{
 4368|  8.90k|    SECStatus rv;
 4369|       |
 4370|  8.90k|    rv = tls13_HkdfExpandLabel(key, hash, hashes->u.raw, hashes->len,
 4371|  8.90k|                               label, labelLen, CKM_HKDF_DERIVE,
  ------------------
  |  | 1296|  8.90k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
 4372|  8.90k|                               tls13_GetHashSizeForHash(hash),
 4373|  8.90k|                               ss->protocolVariant, dest);
 4374|  8.90k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4374:9): [True: 0, False: 8.90k]
  ------------------
 4375|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4376|      0|        return SECFailure;
 4377|      0|    }
 4378|  8.90k|    return SECSuccess;
 4379|  8.90k|}
tls13_DeriveSecretNullHash:
 4388|  2.42k|{
 4389|  2.42k|    SSL3Hashes hashes;
 4390|  2.42k|    SECStatus rv;
 4391|  2.42k|    PRUint8 buf[] = { 0 };
 4392|       |
 4393|  2.42k|    rv = tls13_ComputeHash(ss, &hashes, buf, 0, hash);
 4394|  2.42k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4394:9): [True: 0, False: 2.42k]
  ------------------
 4395|      0|        return SECFailure;
 4396|      0|    }
 4397|       |
 4398|  2.42k|    return tls13_DeriveSecret(ss, key, label, labelLen, &hashes, dest, hash);
 4399|  2.42k|}
tls13_SetSpecRecordVersion:
 4565|   280k|{
 4566|       |    /* Set the record version to pretend to be (D)TLS 1.2. */
 4567|   280k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   280k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 280k]
  |  |  ------------------
  ------------------
 4568|      0|        spec->recordVersion = SSL_LIBRARY_VERSION_DTLS_1_2_WIRE;
  ------------------
  |  |   33|      0|#define SSL_LIBRARY_VERSION_DTLS_1_2_WIRE       ((~0x0102) & 0xffff)
  ------------------
 4569|   280k|    } else {
 4570|   280k|        spec->recordVersion = SSL_LIBRARY_VERSION_TLS_1_2;
  ------------------
  |  |   20|   280k|#define SSL_LIBRARY_VERSION_TLS_1_2             0x0303
  ------------------
 4571|   280k|    }
 4572|   280k|    SSL_TRC(10, ("%d: TLS13[%d]: set spec=%d record version to 0x%04x",
  ------------------
  |  |   71|   280k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 280k]
  |  |  ------------------
  |  |   72|   280k|    ssl_Trace b
  ------------------
 4573|   280k|                 SSL_GETPID(), ss->fd, spec, spec->recordVersion));
 4574|   280k|}
tls13_SetAlertCipherSpec:
 4662|  6.35k|{
 4663|  6.35k|    SECStatus rv;
 4664|       |
 4665|  6.35k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (4665:9): [True: 6.35k, False: 0]
  ------------------
 4666|  6.35k|        return SECSuccess;
 4667|  6.35k|    }
 4668|      0|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (4668:9): [True: 0, False: 0]
  ------------------
 4669|      0|        return SECSuccess;
 4670|      0|    }
 4671|      0|    if (TLS13_IN_HS_STATE(ss, wait_server_hello)) {
  ------------------
  |  |   44|      0|    tls13_InHsState(ss, __VA_ARGS__, wait_invalid)
  |  |  ------------------
  |  |  |  Branch (44:5): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4672|      0|        return SECSuccess;
 4673|      0|    }
 4674|      0|    if ((ss->ssl3.cwSpec->epoch != TrafficKeyClearText) &&
  ------------------
  |  Branch (4674:9): [True: 0, False: 0]
  ------------------
 4675|      0|        (ss->ssl3.cwSpec->epoch != TrafficKeyEarlyApplicationData)) {
  ------------------
  |  Branch (4675:9): [True: 0, False: 0]
  ------------------
 4676|      0|        return SECSuccess;
 4677|      0|    }
 4678|       |
 4679|      0|    rv = tls13_SetCipherSpec(ss, TrafficKeyHandshake,
 4680|      0|                             ssl_secret_write, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4681|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4681:9): [True: 0, False: 0]
  ------------------
 4682|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4683|      0|        return SECFailure;
 4684|      0|    }
 4685|      0|    return SECSuccess;
 4686|      0|}
tls13_ComputeHandshakeHashes:
 4757|  9.50k|{
 4758|  9.50k|    SECStatus rv;
 4759|  9.50k|    PK11Context *ctx = NULL;
 4760|  9.50k|    PRBool useEchInner;
 4761|  9.50k|    sslBuffer *transcript;
 4762|       |
 4763|  9.50k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  9.50k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.0k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4.91k, False: 4.59k]
  |  |  |  |  |  Branch (208:7): [True: 4.59k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4764|  9.50k|    if (ss->ssl3.hs.hashType == handshake_hash_unknown) {
  ------------------
  |  Branch (4764:9): [True: 181, False: 9.32k]
  ------------------
 4765|       |        /* Backup: if we haven't done any hashing, then hash now.
 4766|       |         * This happens when we are doing 0-RTT on the client. */
 4767|    181|        ctx = PK11_CreateDigestContext(ssl3_HashTypeToOID(tls13_GetHash(ss)));
 4768|    181|        if (!ctx) {
  ------------------
  |  Branch (4768:13): [True: 0, False: 181]
  ------------------
 4769|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4770|      0|            return SECFailure;
 4771|      0|        }
 4772|       |
 4773|    181|        if (PK11_DigestBegin(ctx) != SECSuccess) {
  ------------------
  |  Branch (4773:13): [True: 0, False: 181]
  ------------------
 4774|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4775|      0|            goto loser;
 4776|      0|        }
 4777|       |
 4778|       |        /* One might expect this to use ss->ssl3.hs.echAccepted,
 4779|       |         * but with 0-RTT we don't know that yet. */
 4780|    181|        useEchInner = ss->sec.isServer ? PR_FALSE : !!ss->ssl3.hs.echHpkeCtx;
  ------------------
  |  |  438|    181|#define PR_FALSE 0
  ------------------
  |  Branch (4780:23): [True: 181, False: 0]
  ------------------
 4781|    181|        transcript = useEchInner ? &ss->ssl3.hs.echInnerMessages : &ss->ssl3.hs.messages;
  ------------------
  |  Branch (4781:22): [True: 0, False: 181]
  ------------------
 4782|       |
 4783|    181|        PRINT_BUF(10, (ss, "Handshake hash computed over saved messages",
  ------------------
  |  |   74|    181|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 181]
  |  |  ------------------
  |  |   75|    181|    ssl_PrintBuf b
  ------------------
 4784|    181|                       transcript->buf,
 4785|    181|                       transcript->len));
 4786|       |
 4787|    181|        if (PK11_DigestOp(ctx,
  ------------------
  |  Branch (4787:13): [True: 0, False: 181]
  ------------------
 4788|    181|                          transcript->buf,
 4789|    181|                          transcript->len) != SECSuccess) {
 4790|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4791|      0|            goto loser;
 4792|      0|        }
 4793|  9.32k|    } else {
 4794|  9.32k|        if (ss->firstHsDone) {
  ------------------
  |  Branch (4794:13): [True: 0, False: 9.32k]
  ------------------
 4795|      0|            ctx = PK11_CloneContext(ss->ssl3.hs.shaPostHandshake);
 4796|  9.32k|        } else {
 4797|  9.32k|            ctx = PK11_CloneContext(ss->ssl3.hs.sha);
 4798|  9.32k|        }
 4799|  9.32k|        if (!ctx) {
  ------------------
  |  Branch (4799:13): [True: 0, False: 9.32k]
  ------------------
 4800|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 4801|      0|            return SECFailure;
 4802|      0|        }
 4803|  9.32k|    }
 4804|       |
 4805|  9.50k|    rv = PK11_DigestFinal(ctx, hashes->u.raw,
 4806|  9.50k|                          &hashes->len,
 4807|  9.50k|                          sizeof(hashes->u.raw));
 4808|  9.50k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4808:9): [True: 0, False: 9.50k]
  ------------------
 4809|      0|        ssl_MapLowLevelError(SSL_ERROR_DIGEST_FAILURE);
 4810|      0|        goto loser;
 4811|      0|    }
 4812|       |
 4813|  9.50k|    PRINT_BUF(10, (ss, "Handshake hash", hashes->u.raw, hashes->len));
  ------------------
  |  |   74|  9.50k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 9.50k]
  |  |  ------------------
  |  |   75|  9.50k|    ssl_PrintBuf b
  ------------------
 4814|  9.50k|    PORT_Assert(hashes->len == tls13_GetHashSize(ss));
  ------------------
  |  |  120|  9.50k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.50k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.50k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4815|  9.50k|    PK11_DestroyContext(ctx, PR_TRUE);
  ------------------
  |  |  437|  9.50k|#define PR_TRUE 1
  ------------------
 4816|       |
 4817|  9.50k|    return SECSuccess;
 4818|       |
 4819|      0|loser:
 4820|      0|    PK11_DestroyContext(ctx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 4821|      0|    return SECFailure;
 4822|  9.50k|}
tls13_DestroyKeyShareEntry:
 4845|  1.65k|{
 4846|  1.65k|    if (!offer) {
  ------------------
  |  Branch (4846:9): [True: 38, False: 1.61k]
  ------------------
 4847|     38|        return;
 4848|     38|    }
 4849|  1.61k|    SECITEM_ZfreeItem(&offer->key_exchange, PR_FALSE);
  ------------------
  |  |  110|  1.61k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                  SECITEM_ZfreeItem(&offer->key_exchange, PR_FALSE);
  ------------------
  |  |  438|  1.61k|#define PR_FALSE 0
  ------------------
 4850|  1.61k|    PORT_ZFree(offer, sizeof(*offer));
  ------------------
  |  |   75|  1.61k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 4851|  1.61k|}
tls13_DestroyKeyShares:
 4855|  90.4k|{
 4856|  90.4k|    PRCList *cur_p;
 4857|       |
 4858|       |    /* The list must be initialized. */
 4859|  90.4k|    PORT_Assert(PR_LIST_HEAD(list));
  ------------------
  |  |  120|  90.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  90.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 90.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4860|       |
 4861|  92.0k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|  92.0k|    ((_l)->next == (_l))
  ------------------
  |  Branch (4861:12): [True: 1.61k, False: 90.4k]
  ------------------
 4862|  1.61k|        cur_p = PR_LIST_TAIL(list);
  ------------------
  |  |   66|  1.61k|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
 4863|  1.61k|        PR_REMOVE_LINK(cur_p);
  ------------------
  |  |   72|  1.61k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|  1.61k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|  1.61k|    (_e)->prev->next = (_e)->next; \
  |  |   74|  1.61k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|  1.61k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  1.61k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4864|  1.61k|        tls13_DestroyKeyShareEntry((TLS13KeyShareEntry *)cur_p);
 4865|  1.61k|    }
 4866|  90.4k|}
tls13_DestroyEarlyData:
 4870|  9.71k|{
 4871|  9.71k|    PRCList *cur_p;
 4872|       |
 4873|  9.71k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|  9.71k|    ((_l)->next == (_l))
  ------------------
  |  Branch (4873:12): [True: 0, False: 9.71k]
  ------------------
 4874|      0|        TLS13EarlyData *msg;
 4875|       |
 4876|      0|        cur_p = PR_LIST_TAIL(list);
  ------------------
  |  |   66|      0|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
 4877|      0|        msg = (TLS13EarlyData *)cur_p;
 4878|       |
 4879|      0|        PR_REMOVE_LINK(cur_p);
  ------------------
  |  |   72|      0|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      0|    (_e)->prev->next = (_e)->next; \
  |  |   74|      0|    (_e)->next->prev = (_e)->prev; \
  |  |   75|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4880|      0|        SECITEM_ZfreeItem(&msg->data, PR_FALSE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                      SECITEM_ZfreeItem(&msg->data, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4881|      0|        PORT_ZFree(msg, sizeof(*msg));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
 4882|      0|    }
 4883|  9.71k|}
tls13_ExtensionStatus:
 6432|  25.3k|{
 6433|  25.3k|    unsigned int i;
 6434|       |
 6435|  25.3k|    PORT_Assert((message == ssl_hs_client_hello) ||
  ------------------
  |  |  120|  25.3k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   172k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 15.7k, False: 9.68k]
  |  |  |  |  |  Branch (208:7): [True: 4.79k, False: 4.89k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 4.89k]
  |  |  |  |  |  Branch (208:7): [True: 4.79k, False: 105]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 105]
  |  |  |  |  |  Branch (208:7): [True: 105, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6436|  25.3k|                (message == ssl_hs_server_hello) ||
 6437|  25.3k|                (message == ssl_hs_hello_retry_request) ||
 6438|  25.3k|                (message == ssl_hs_encrypted_extensions) ||
 6439|  25.3k|                (message == ssl_hs_new_session_ticket) ||
 6440|  25.3k|                (message == ssl_hs_certificate) ||
 6441|  25.3k|                (message == ssl_hs_certificate_request));
 6442|       |
 6443|   339k|    for (i = 0; i < PR_ARRAY_SIZE(KnownExtensions); i++) {
  ------------------
  |  |  167|   339k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (6443:17): [True: 331k, False: 7.38k]
  ------------------
 6444|       |        /* Hacky check for message numbers > 30. */
 6445|   331k|        PORT_Assert(!(KnownExtensions[i].messages & (1U << 31)));
  ------------------
  |  |  120|   331k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   331k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 331k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6446|   331k|        if (KnownExtensions[i].ex_value == extension) {
  ------------------
  |  Branch (6446:13): [True: 18.0k, False: 313k]
  ------------------
 6447|  18.0k|            break;
 6448|  18.0k|        }
 6449|   331k|    }
 6450|  25.3k|    if (i >= PR_ARRAY_SIZE(KnownExtensions)) {
  ------------------
  |  |  167|  25.3k|#define PR_ARRAY_SIZE(a) (sizeof(a)/sizeof((a)[0]))
  ------------------
  |  Branch (6450:9): [True: 7.38k, False: 18.0k]
  ------------------
 6451|  7.38k|        return tls13_extension_unknown;
 6452|  7.38k|    }
 6453|       |
 6454|       |    /* Return "disallowed" if the message mask bit isn't set. */
 6455|  18.0k|    if (!(_M(message) & KnownExtensions[i].messages)) {
  ------------------
  |  | 6391|  18.0k|#define _M(a) (1 << PR_MIN(a, 31))
  |  |  ------------------
  |  |  |  |  158|  18.0k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (158:26): [True: 18.0k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (6455:9): [True: 4.89k, False: 13.1k]
  ------------------
 6456|  4.89k|        return tls13_extension_disallowed;
 6457|  4.89k|    }
 6458|       |
 6459|  13.1k|    return tls13_extension_allowed;
 6460|  18.0k|}
tls13_EncodeVersion:
 7090|  4.92k|{
 7091|  4.92k|    if (variant == ssl_variant_datagram) {
  ------------------
  |  Branch (7091:9): [True: 0, False: 4.92k]
  ------------------
 7092|      0|        return dtls_TLSVersionToDTLSVersion(version);
 7093|      0|    }
 7094|       |    /* Stream-variant encodings do not change. */
 7095|  4.92k|    return (PRUint16)version;
 7096|  4.92k|}
tls13_NegotiateVersion:
 7149|  2.73k|{
 7150|  2.73k|    PRUint16 version;
 7151|       |    /* Make a copy so we're nondestructive. */
 7152|  2.73k|    SECItem data = supportedVersions->data;
 7153|  2.73k|    SECItem versions;
 7154|  2.73k|    SECStatus rv;
 7155|       |
 7156|  2.73k|    rv = ssl3_ConsumeHandshakeVariable(ss, &versions, 1,
 7157|  2.73k|                                       &data.data, &data.len);
 7158|  2.73k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (7158:9): [True: 1, False: 2.73k]
  ------------------
 7159|      1|        return SECFailure;
 7160|      1|    }
 7161|  2.73k|    if (data.len || !versions.len || (versions.len & 1)) {
  ------------------
  |  Branch (7161:9): [True: 4, False: 2.73k]
  |  Branch (7161:21): [True: 1, False: 2.73k]
  |  Branch (7161:38): [True: 1, False: 2.72k]
  ------------------
 7162|      6|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      6|    do {                                     \
  |  |   23|      6|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      6|    do {                                                                           \
  |  |  |  |   15|      6|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      6|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 6]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      6|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      6|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      6|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      6|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      6|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      6|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      6|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 7163|      6|        return SECFailure;
 7164|      6|    }
 7165|  3.55k|    for (version = ss->vrange.max; version >= ss->vrange.min; --version) {
  ------------------
  |  Branch (7165:36): [True: 3.53k, False: 23]
  ------------------
 7166|  3.53k|        if (version < SSL_LIBRARY_VERSION_TLS_1_3 &&
  ------------------
  |  |   21|  7.07k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (7166:13): [True: 1.07k, False: 2.45k]
  ------------------
 7167|  3.53k|            (ss->ssl3.hs.helloRetry || ss->ssl3.hs.echAccepted)) {
  ------------------
  |  Branch (7167:14): [True: 3, False: 1.07k]
  |  Branch (7167:40): [True: 0, False: 1.07k]
  ------------------
 7168|       |            /* Prevent negotiating to a lower version after 1.3 HRR or ECH
 7169|       |             * When accepting ECH, a different alert is generated.
 7170|       |             */
 7171|      3|            SSL3AlertDescription alert = ss->ssl3.hs.echAccepted ? illegal_parameter : protocol_version;
  ------------------
  |  Branch (7171:42): [True: 0, False: 3]
  ------------------
 7172|      3|            PORT_SetError(SSL_ERROR_UNSUPPORTED_VERSION);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
 7173|      3|            FATAL_ERROR(ss, SSL_ERROR_UNSUPPORTED_VERSION, alert);
  ------------------
  |  |   22|      3|    do {                                     \
  |  |   23|      3|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      3|    do {                                                                           \
  |  |  |  |   15|      3|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      3|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      3|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      3|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      3|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      3|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      3|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 7174|      3|            return SECFailure;
 7175|      3|        }
 7176|       |
 7177|  3.53k|        PRUint16 wire = tls13_EncodeVersion(version, ss->protocolVariant);
 7178|  3.53k|        unsigned long offset;
 7179|       |
 7180|  11.6k|        for (offset = 0; offset < versions.len; offset += 2) {
  ------------------
  |  Branch (7180:26): [True: 10.8k, False: 829]
  ------------------
 7181|  10.8k|            PRUint16 supported =
 7182|  10.8k|                (versions.data[offset] << 8) | versions.data[offset + 1];
 7183|  10.8k|            if (supported == wire) {
  ------------------
  |  Branch (7183:17): [True: 2.70k, False: 8.09k]
  ------------------
 7184|  2.70k|                ss->version = version;
 7185|  2.70k|                return SECSuccess;
 7186|  2.70k|            }
 7187|  10.8k|        }
 7188|  3.53k|    }
 7189|       |
 7190|     23|    FATAL_ERROR(ss, SSL_ERROR_UNSUPPORTED_VERSION, protocol_version);
  ------------------
  |  |   22|     23|    do {                                     \
  |  |   23|     23|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     23|    do {                                                                           \
  |  |  |  |   15|     23|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     23|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 23]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     23|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     23|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     23|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     23|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     23|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     23|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     23|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 7191|     23|    return SECFailure;
 7192|  2.72k|}
tls13_ClientGreaseDestroy:
 7258|  19.4k|{
 7259|  19.4k|    if (ss->ssl3.hs.grease) {
  ------------------
  |  Branch (7259:9): [True: 0, False: 19.4k]
  ------------------
 7260|      0|        PORT_Free(ss->ssl3.hs.grease);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 7261|      0|        ss->ssl3.hs.grease = NULL;
 7262|      0|    }
 7263|  19.4k|}
tls13_RandomGreaseValue:
 7269|    554|{
 7270|    554|    PRUint8 random;
 7271|       |
 7272|    554|    if (PK11_GenerateRandom(&random, sizeof(random)) != SECSuccess) {
  ------------------
  |  Branch (7272:9): [True: 0, False: 554]
  ------------------
 7273|      0|        return SECFailure;
 7274|      0|    }
 7275|       |
 7276|    554|    random = ((random & 0xf0) | 0x0a);
 7277|    554|    *out = ((random << 8) | random);
 7278|       |
 7279|    554|    return SECSuccess;
 7280|    554|}
tls13_MaybeGreaseExtensionType:
 7287|  23.8k|{
 7288|  23.8k|    if (*exType != ssl_tls13_grease_xtn) {
  ------------------
  |  Branch (7288:9): [True: 23.6k, False: 200]
  ------------------
 7289|  23.6k|        return SECSuccess;
 7290|  23.6k|    }
 7291|       |
 7292|    200|    PR_ASSERT(ss->opt.enableGrease);
  ------------------
  |  |  208|    200|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 200, False: 0]
  |  |  ------------------
  ------------------
 7293|    200|    PR_ASSERT(message == ssl_hs_client_hello ||
  ------------------
  |  |  208|    400|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 0, False: 200]
  |  |  |  Branch (208:7): [True: 200, False: 0]
  |  |  ------------------
  ------------------
 7294|    200|              message == ssl_hs_certificate_request);
 7295|       |
 7296|       |    /* GREASE ClientHello:
 7297|       |     * A client MAY select one or more GREASE extension values and
 7298|       |     * advertise them as extensions with varying length and contents
 7299|       |     * [RFC8701, Section 3.1]. */
 7300|    200|    if (message == ssl_hs_client_hello) {
  ------------------
  |  Branch (7300:9): [True: 0, False: 200]
  ------------------
 7301|      0|        PR_ASSERT(ss->vrange.max >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 7302|       |        /* Check if the first GREASE extension was already added. */
 7303|      0|        if (!ssl3_ExtensionAdvertised(ss, ss->ssl3.hs.grease->idx[grease_extension1])) {
  ------------------
  |  Branch (7303:13): [True: 0, False: 0]
  ------------------
 7304|      0|            *exType = ss->ssl3.hs.grease->idx[grease_extension1];
 7305|      0|        } else {
 7306|      0|            *exType = ss->ssl3.hs.grease->idx[grease_extension2];
 7307|      0|        }
 7308|      0|    }
 7309|       |    /* GREASE CertificateRequest:
 7310|       |     * When sending a CertificateRequest in TLS 1.3, a server MAY behave as
 7311|       |     * follows: A server MAY select one or more GREASE extension values and
 7312|       |     * advertise them as extensions with varying length and contents
 7313|       |     * [RFC8701, Section 4.1]. */
 7314|    200|    else if (message == ssl_hs_certificate_request) {
  ------------------
  |  Branch (7314:14): [True: 200, False: 0]
  ------------------
 7315|    200|        PR_ASSERT(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  208|    200|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 200, False: 0]
  |  |  ------------------
  ------------------
 7316|       |        /* Get random grease extension type. */
 7317|    200|        SECStatus rv = tls13_RandomGreaseValue(exType);
 7318|    200|        if (rv != SECSuccess) {
  ------------------
  |  Branch (7318:13): [True: 0, False: 200]
  ------------------
 7319|      0|            return SECFailure;
 7320|      0|        }
 7321|    200|    }
 7322|       |
 7323|    200|    return SECSuccess;
 7324|    200|}
tls13con.c:tls13_HandshakeState:
  150|  1.63k|{
  151|  1.63k|    switch (st) {
  152|    417|        STATE_CASE(idle_handshake);
  ------------------
  |  |  146|    417|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 417, False: 1.22k]
  |  |  ------------------
  |  |  147|    417|        return #a
  ------------------
  153|      0|        STATE_CASE(wait_client_hello);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  154|      0|        STATE_CASE(wait_end_of_early_data);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  155|    447|        STATE_CASE(wait_client_cert);
  ------------------
  |  |  146|    447|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 447, False: 1.19k]
  |  |  ------------------
  |  |  147|    447|        return #a
  ------------------
  156|      0|        STATE_CASE(wait_client_key);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  157|      0|        STATE_CASE(wait_cert_verify);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  158|      0|        STATE_CASE(wait_change_cipher);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  159|    773|        STATE_CASE(wait_finished);
  ------------------
  |  |  146|    773|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 773, False: 864]
  |  |  ------------------
  |  |  147|    773|        return #a
  ------------------
  160|      0|        STATE_CASE(wait_server_hello);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  161|      0|        STATE_CASE(wait_certificate_status);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  162|      0|        STATE_CASE(wait_server_cert);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  163|      0|        STATE_CASE(wait_server_key);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  164|      0|        STATE_CASE(wait_cert_request);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  165|      0|        STATE_CASE(wait_hello_done);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  166|      0|        STATE_CASE(wait_new_session_ticket);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  167|      0|        STATE_CASE(wait_encrypted_extensions);
  ------------------
  |  |  146|      0|    case a:           \
  |  |  ------------------
  |  |  |  Branch (146:5): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |  147|      0|        return #a
  ------------------
  168|      0|        default:
  ------------------
  |  Branch (168:9): [True: 0, False: 1.63k]
  ------------------
  169|      0|            break;
  170|  1.63k|    }
  171|      0|    PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  172|      0|    return "unknown";
  173|  1.63k|}
tls13con.c:tls13_InHsStateV:
  205|   275k|{
  206|   275k|    SSL3WaitState ws;
  207|       |
  208|   275k|    while ((ws = va_arg(ap, SSL3WaitState)) != wait_invalid) {
  ------------------
  |  Branch (208:12): [True: 275k, False: 33]
  ------------------
  209|   275k|        if (TLS13_WAIT_STATE(ws) == ss->ssl3.hs.ws) {
  ------------------
  |  |  180|   275k|#define TLS13_WAIT_STATE(ws) (((ws == idle_handshake) || (ws == wait_server_hello)) ? ws : ws | TLS13_WAIT_STATE_MASK)
  |  |  ------------------
  |  |  |  |  176|   275k|#define TLS13_WAIT_STATE_MASK 0x80
  |  |  ------------------
  |  |  |  Branch (180:32): [True: 274k, False: 507]
  |  |  |  Branch (180:58): [True: 0, False: 507]
  |  |  ------------------
  ------------------
  |  Branch (209:13): [True: 275k, False: 33]
  ------------------
  210|   275k|            return PR_TRUE;
  ------------------
  |  |  437|   275k|#define PR_TRUE 1
  ------------------
  211|   275k|        }
  212|   275k|    }
  213|     33|    return PR_FALSE;
  ------------------
  |  |  438|     33|#define PR_FALSE 0
  ------------------
  214|   275k|}
tls13con.c:tls13_ImportDHEKeyShare:
  673|    548|{
  674|    548|    SECStatus rv;
  675|    548|    SECItem publicValue = { siBuffer, NULL, 0 };
  676|       |
  677|    548|    publicValue.data = b;
  678|    548|    publicValue.len = length;
  679|    548|    if (!ssl_IsValidDHEShare(&pubKey->u.dh.prime, &publicValue)) {
  ------------------
  |  Branch (679:9): [True: 3, False: 545]
  ------------------
  680|      3|        PORT_SetError(SSL_ERROR_RX_MALFORMED_DHE_KEY_SHARE);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
  681|      3|        return SECFailure;
  682|      3|    }
  683|       |
  684|    545|    peerKey->keyType = dhKey;
  685|    545|    rv = SECITEM_CopyItem(peerKey->arena, &peerKey->u.dh.prime,
  ------------------
  |  |  106|    545|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  686|    545|                          &pubKey->u.dh.prime);
  687|    545|    if (rv != SECSuccess)
  ------------------
  |  Branch (687:9): [True: 0, False: 545]
  ------------------
  688|      0|        return SECFailure;
  689|    545|    rv = SECITEM_CopyItem(peerKey->arena, &peerKey->u.dh.base,
  ------------------
  |  |  106|    545|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  690|    545|                          &pubKey->u.dh.base);
  691|    545|    if (rv != SECSuccess)
  ------------------
  |  Branch (691:9): [True: 0, False: 545]
  ------------------
  692|      0|        return SECFailure;
  693|    545|    rv = SECITEM_CopyItem(peerKey->arena, &peerKey->u.dh.publicValue,
  ------------------
  |  |  106|    545|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  694|    545|                          &publicValue);
  695|    545|    if (rv != SECSuccess)
  ------------------
  |  Branch (695:9): [True: 0, False: 545]
  ------------------
  696|      0|        return SECFailure;
  697|       |
  698|    545|    return SECSuccess;
  699|    545|}
tls13con.c:tls13_TrafficSecretRef:
  945|   274k|{
  946|   274k|    if (tls13_UseServerSecret(ss, direction)) {
  ------------------
  |  Branch (946:9): [True: 132k, False: 141k]
  ------------------
  947|   132k|        return &ss->ssl3.hs.serverTrafficSecret;
  948|   132k|    }
  949|   141k|    return &ss->ssl3.hs.clientTrafficSecret;
  950|   274k|}
tls13con.c:tls13_UseServerSecret:
  939|   553k|{
  940|   553k|    return ss->sec.isServer == (direction == ssl_secret_write);
  941|   553k|}
tls13con.c:tls13_GetHmacMechanism:
  351|   274k|{
  352|   274k|    return tls13_GetHmacMechanismFromHash(tls13_GetHash(ss));
  353|   274k|}
tls13con.c:tls13_GetHmacMechanismFromHash:
  337|   277k|{
  338|   277k|    switch (hashType) {
  339|  6.47k|        case ssl_hash_sha256:
  ------------------
  |  Branch (339:9): [True: 6.47k, False: 271k]
  ------------------
  340|  6.47k|            return CKM_SHA256_HMAC;
  ------------------
  |  |  877|  6.47k|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  341|   271k|        case ssl_hash_sha384:
  ------------------
  |  Branch (341:9): [True: 271k, False: 6.47k]
  ------------------
  342|   271k|            return CKM_SHA384_HMAC;
  ------------------
  |  |  880|   271k|#define CKM_SHA384_HMAC 0x00000261UL
  ------------------
  343|      0|        default:
  ------------------
  |  Branch (343:9): [True: 0, False: 277k]
  ------------------
  344|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  345|   277k|    }
  346|      0|    return CKM_SHA256_HMAC;
  ------------------
  |  |  877|      0|#define CKM_SHA256_HMAC 0x00000251UL
  ------------------
  347|   277k|}
tls13con.c:tls13_CheckHsState:
  233|   275k|{
  234|   275k|    va_list ap;
  235|   275k|    va_start(ap, line);
  236|   275k|    if (tls13_InHsStateV(ss, ap)) {
  ------------------
  |  Branch (236:9): [True: 275k, False: 33]
  ------------------
  237|   275k|        va_end(ap);
  238|   275k|        return SECSuccess;
  239|   275k|    }
  240|     33|    va_end(ap);
  241|       |
  242|     33|    SSL_TRC(3, ("%d: TLS13[%d]: error %s state is (%s) at %s (%s:%d)",
  ------------------
  |  |   71|     33|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 33]
  |  |  ------------------
  |  |   72|     33|    ssl_Trace b
  ------------------
  243|     33|                SSL_GETPID(), ss->fd,
  244|     33|                error_name,
  245|     33|                tls13_HandshakeState(TLS13_BASE_WAIT_STATE(ss->ssl3.hs.ws)),
  246|     33|                func, file, line));
  247|     33|    tls13_FatalError(ss, err, unexpected_message);
  248|     33|    return SECFailure;
  249|   275k|}
tls13con.c:tls13_HandleKeyUpdate:
 1160|   141k|{
 1161|   141k|    SECStatus rv;
 1162|   141k|    PRUint32 update;
 1163|       |
 1164|   141k|    SSL_TRC(3, ("%d: TLS13[%d]: %s handle key update",
  ------------------
  |  |   71|   141k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 141k]
  |  |  ------------------
  |  |   72|   141k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1165|   141k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1166|       |
 1167|   141k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|   141k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   210k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 73.0k, False: 68.8k]
  |  |  |  |  |  Branch (208:7): [True: 68.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1168|   141k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   141k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   210k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 73.0k, False: 68.8k]
  |  |  |  |  |  Branch (208:7): [True: 68.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1169|       |
 1170|   141k|    if (!tls13_IsPostHandshake(ss)) {
  ------------------
  |  Branch (1170:9): [True: 3, False: 141k]
  ------------------
 1171|      3|        FATAL_ERROR(ss, SSL_ERROR_RX_UNEXPECTED_KEY_UPDATE, unexpected_message);
  ------------------
  |  |   22|      3|    do {                                     \
  |  |   23|      3|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      3|    do {                                                                           \
  |  |  |  |   15|      3|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      3|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      3|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      3|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      3|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      3|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      3|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1172|      3|        return SECFailure;
 1173|      3|    }
 1174|       |
 1175|   141k|    rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_KEY_UPDATE,
  ------------------
  |  |  182|   141k|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|   141k|                       __VA_ARGS__,                                 \
  |  |  184|   141k|                       wait_invalid)
  ------------------
 1176|   141k|                              idle_handshake);
 1177|   141k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1177:9): [True: 0, False: 141k]
  ------------------
 1178|       |        /* We should never be idle_handshake prior to firstHsDone. */
 1179|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1180|      0|        return SECFailure;
 1181|      0|    }
 1182|       |
 1183|   141k|    rv = ssl3_ConsumeHandshakeNumber(ss, &update, 1, &b, &length);
 1184|   141k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1184:9): [True: 1, False: 141k]
  ------------------
 1185|      1|        return SECFailure; /* Error code set already. */
 1186|      1|    }
 1187|   141k|    if (length != 0) {
  ------------------
  |  Branch (1187:9): [True: 2, False: 141k]
  ------------------
 1188|      2|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_KEY_UPDATE, decode_error);
  ------------------
  |  |   22|      2|    do {                                     \
  |  |   23|      2|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      2|    do {                                                                           \
  |  |  |  |   15|      2|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      2|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 2]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      2|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      2|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      2|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      2|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      2|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      2|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1189|      2|        return SECFailure;
 1190|      2|    }
 1191|   141k|    if (!(update == update_requested ||
  ------------------
  |  Branch (1191:11): [True: 141k, False: 230]
  ------------------
 1192|   141k|          update == update_not_requested)) {
  ------------------
  |  Branch (1192:11): [True: 225, False: 5]
  ------------------
 1193|      5|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_KEY_UPDATE, decode_error);
  ------------------
  |  |   22|      5|    do {                                     \
  |  |   23|      5|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      5|    do {                                                                           \
  |  |  |  |   15|      5|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      5|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 5]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      5|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      5|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      5|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      5|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      5|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      5|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1194|      5|        return SECFailure;
 1195|      5|    }
 1196|       |
 1197|   141k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   141k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 141k]
  |  |  ------------------
  ------------------
 1198|      0|        return dtls13_HandleKeyUpdate(ss, b, length, update);
 1199|      0|    }
 1200|       |
 1201|   141k|    rv = tls13_UpdateTrafficKeys(ss, ssl_secret_read);
 1202|   141k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1202:9): [True: 0, False: 141k]
  ------------------
 1203|      0|        return SECFailure; /* Error code set by tls13_UpdateTrafficKeys. */
 1204|      0|    }
 1205|       |
 1206|   141k|    if (update == update_requested) {
  ------------------
  |  Branch (1206:9): [True: 141k, False: 225]
  ------------------
 1207|   141k|        PRBool sendUpdate;
 1208|   141k|        if (ss->ssl3.clientCertRequested) {
  ------------------
  |  Branch (1208:13): [True: 0, False: 141k]
  ------------------
 1209|       |            /* Post-handshake auth is in progress; defer sending a key update. */
 1210|      0|            ss->ssl3.hs.keyUpdateDeferred = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1211|      0|            ss->ssl3.hs.deferredKeyUpdateRequest = update_not_requested;
 1212|      0|            sendUpdate = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1213|   141k|        } else if (ss->ssl3.peerRequestedKeyUpdate) {
  ------------------
  |  Branch (1213:20): [True: 141k, False: 320]
  ------------------
 1214|       |            /* Only send an update if we have sent with the current spec.  This
 1215|       |             * prevents us from being forced to crank forward pointlessly. */
 1216|   141k|            ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|   141k|    {                                           \
  |  | 1423|   141k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 68.6k, False: 72.7k]
  |  |  ------------------
  |  | 1424|   141k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|  68.6k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|   141k|    }
  ------------------
 1217|   141k|            sendUpdate = ss->ssl3.cwSpec->nextSeqNum > 0;
 1218|   141k|            ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|   141k|    {                                             \
  |  | 1428|   141k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 68.6k, False: 72.7k]
  |  |  ------------------
  |  | 1429|   141k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|  68.6k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|   141k|    }
  ------------------
 1219|   141k|        } else {
 1220|    320|            sendUpdate = PR_TRUE;
  ------------------
  |  |  437|    320|#define PR_TRUE 1
  ------------------
 1221|    320|        }
 1222|   141k|        if (sendUpdate) {
  ------------------
  |  Branch (1222:13): [True: 132k, False: 9.13k]
  ------------------
 1223|       |            /* Respond immediately (don't buffer). */
 1224|   132k|            rv = tls13_SendKeyUpdate(ss, update_not_requested, PR_FALSE);
  ------------------
  |  |  438|   132k|#define PR_FALSE 0
  ------------------
 1225|   132k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (1225:17): [True: 0, False: 132k]
  ------------------
 1226|      0|                return SECFailure; /* Error already set. */
 1227|      0|            }
 1228|   132k|        }
 1229|   141k|        ss->ssl3.peerRequestedKeyUpdate = PR_TRUE;
  ------------------
  |  |  437|   141k|#define PR_TRUE 1
  ------------------
 1230|   141k|    }
 1231|       |
 1232|   141k|    return SECSuccess;
 1233|   141k|}
tls13con.c:tls13_CanResume:
 1741|     47|{
 1742|     47|    const sslServerCert *sc;
 1743|       |
 1744|     47|    if (!sid) {
  ------------------
  |  Branch (1744:9): [True: 0, False: 47]
  ------------------
 1745|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1746|      0|    }
 1747|       |
 1748|     47|    if (sid->version != ss->version) {
  ------------------
  |  Branch (1748:9): [True: 20, False: 27]
  ------------------
 1749|     20|        return PR_FALSE;
  ------------------
  |  |  438|     20|#define PR_FALSE 0
  ------------------
 1750|     20|    }
 1751|       |
 1752|     27|#ifdef UNSAFE_FUZZER_MODE
 1753|       |    /* When fuzzing, sid could contain garbage that will crash tls13_GetHashForCipherSuite.
 1754|       |     * Do a direct comparison of cipher suites.  This makes us refuse to resume when the
 1755|       |     * protocol allows it, but resumption is discretionary anyway. */
 1756|     27|    if (sid->u.ssl3.cipherSuite != ss->ssl3.hs.cipher_suite) {
  ------------------
  |  Branch (1756:9): [True: 21, False: 6]
  ------------------
 1757|       |#else
 1758|       |    if (tls13_GetHashForCipherSuite(sid->u.ssl3.cipherSuite) != tls13_GetHashForCipherSuite(ss->ssl3.hs.cipher_suite)) {
 1759|       |#endif
 1760|     21|        return PR_FALSE;
  ------------------
  |  |  438|     21|#define PR_FALSE 0
  ------------------
 1761|     21|    }
 1762|       |
 1763|       |    /* Server sids don't remember the server cert we previously sent, but they
 1764|       |     * do remember the type of certificate we originally used, so we can locate
 1765|       |     * it again, provided that the current ssl socket has had its server certs
 1766|       |     * configured the same as the previous one. */
 1767|      6|    sc = ssl_FindServerCert(ss, sid->authType, sid->namedCurve);
 1768|      6|    if (!sc || !sc->serverCert) {
  ------------------
  |  Branch (1768:9): [True: 3, False: 3]
  |  Branch (1768:16): [True: 0, False: 3]
  ------------------
 1769|      3|        return PR_FALSE;
  ------------------
  |  |  438|      3|#define PR_FALSE 0
  ------------------
 1770|      3|    }
 1771|       |
 1772|      3|    return PR_TRUE;
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
 1773|      6|}
tls13con.c:tls13_NegotiateKeyExchange:
 1911|  1.46k|{
 1912|  1.46k|    unsigned int index;
 1913|  1.46k|    TLS13KeyShareEntry *entry = NULL;
 1914|  1.46k|    const sslNamedGroupDef *preferredGroup = NULL;
 1915|       |
 1916|       |    /* We insist on DHE. */
 1917|  1.46k|    if (ssl3_ExtensionNegotiated(ss, ssl_tls13_pre_shared_key_xtn)) {
  ------------------
  |  Branch (1917:9): [True: 56, False: 1.40k]
  ------------------
 1918|     56|        if (!ssl3_ExtensionNegotiated(ss, ssl_tls13_psk_key_exchange_modes_xtn)) {
  ------------------
  |  Branch (1918:13): [True: 23, False: 33]
  ------------------
 1919|     23|            FATAL_ERROR(ss, SSL_ERROR_MISSING_PSK_KEY_EXCHANGE_MODES,
  ------------------
  |  |   22|     23|    do {                                     \
  |  |   23|     23|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     23|    do {                                                                           \
  |  |  |  |   15|     23|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     23|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 23]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     23|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     23|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     23|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     23|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     23|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     23|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     23|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1920|     23|                        missing_extension);
 1921|     23|            return SECFailure;
 1922|     23|        }
 1923|       |        /* Since the server insists on DHE to provide forward secracy, for
 1924|       |         * every other PskKem value but DHE stateless resumption is disabled,
 1925|       |         * this includes other specified and GREASE values. */
 1926|     33|        if (!memchr(ss->xtnData.psk_ke_modes.data, tls13_psk_dh_ke,
  ------------------
  |  Branch (1926:13): [True: 31, False: 2]
  ------------------
 1927|     33|                    ss->xtnData.psk_ke_modes.len)) {
 1928|     31|            SSL_TRC(3, ("%d: TLS13[%d]: client offered PSK without DH",
  ------------------
  |  |   71|     31|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 31]
  |  |  ------------------
  |  |   72|     31|    ssl_Trace b
  ------------------
 1929|     31|                        SSL_GETPID(), ss->fd));
 1930|     31|            ss->statelessResume = PR_FALSE;
  ------------------
  |  |  438|     31|#define PR_FALSE 0
  ------------------
 1931|     31|        }
 1932|     33|    }
 1933|       |
 1934|       |    /* Now figure out which key share we like the best out of the
 1935|       |     * mutually supported groups, regardless of what the client offered
 1936|       |     * for key shares.
 1937|       |     */
 1938|  1.44k|    if (!ssl3_ExtensionNegotiated(ss, ssl_supported_groups_xtn)) {
  ------------------
  |  Branch (1938:9): [True: 6, False: 1.43k]
  ------------------
 1939|      6|        FATAL_ERROR(ss, SSL_ERROR_MISSING_SUPPORTED_GROUPS_EXTENSION,
  ------------------
  |  |   22|      6|    do {                                     \
  |  |   23|      6|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      6|    do {                                                                           \
  |  |  |  |   15|      6|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      6|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 6]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      6|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      6|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      6|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      6|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      6|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      6|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      6|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1940|      6|                    missing_extension);
 1941|      6|        return SECFailure;
 1942|      6|    }
 1943|       |
 1944|  1.43k|    SSL_TRC(3, ("%d: TLS13[%d]: selected KE = %s", SSL_GETPID(),
  ------------------
  |  |   71|  1.43k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.43k]
  |  |  ------------------
  |  |   72|  1.43k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1945|  1.43k|                ss->fd, ss->statelessResume || ss->xtnData.selectedPsk ? "PSK + (EC)DHE" : "(EC)DHE"));
 1946|       |
 1947|       |    /* Find the preferred group and an according client key share available. */
 1948|  6.81k|    for (index = 0; index < SSL_NAMED_GROUP_COUNT; ++index) {
  ------------------
  |  |  133|  6.81k|#define SSL_NAMED_GROUP_COUNT 33
  ------------------
  |  Branch (1948:21): [True: 6.81k, False: 5]
  ------------------
 1949|       |        /* Continue to the next group if this one is not enabled. */
 1950|  6.81k|        if (!ss->namedGroupPreferences[index]) {
  ------------------
  |  Branch (1950:13): [True: 5.35k, False: 1.45k]
  ------------------
 1951|       |            /* There's a gap in the preferred groups list. Assume this is a group
 1952|       |             * that's not supported by the client but preferred by the server. */
 1953|  5.35k|            if (preferredGroup) {
  ------------------
  |  Branch (1953:17): [True: 157, False: 5.19k]
  ------------------
 1954|    157|                entry = NULL;
 1955|    157|                break;
 1956|    157|            }
 1957|  5.19k|            continue;
 1958|  5.35k|        }
 1959|       |
 1960|       |        /* Check if the client sent a key share for this group. */
 1961|  1.45k|        entry = tls13_FindKeyShareEntry(ss, ss->namedGroupPreferences[index]);
 1962|       |
 1963|  1.45k|        if (preferredGroup) {
  ------------------
  |  Branch (1963:13): [True: 25, False: 1.43k]
  ------------------
 1964|       |            /* We already found our preferred group but the group didn't have a share. */
 1965|     25|            if (entry) {
  ------------------
  |  Branch (1965:17): [True: 8, False: 17]
  ------------------
 1966|       |                /* The client sent a key share with group ss->namedGroupPreferences[index] */
 1967|      8|                if (tls13_isGroupAcceptable(ss->namedGroupPreferences[index],
  ------------------
  |  Branch (1967:21): [True: 1, False: 7]
  ------------------
 1968|      8|                                            preferredGroup)) {
 1969|       |                    /* This is not the preferred group, but it's acceptable */
 1970|      1|                    preferredGroup = ss->namedGroupPreferences[index];
 1971|      7|                } else {
 1972|       |                    /* The proposed group is not acceptable. */
 1973|      7|                    entry = NULL;
 1974|      7|                }
 1975|      8|            }
 1976|     25|            break;
 1977|  1.43k|        } else {
 1978|       |            /* The first enabled group is the preferred group. */
 1979|  1.43k|            preferredGroup = ss->namedGroupPreferences[index];
 1980|  1.43k|            if (entry) {
  ------------------
  |  Branch (1980:17): [True: 1.24k, False: 182]
  ------------------
 1981|  1.24k|                break;
 1982|  1.24k|            }
 1983|  1.43k|        }
 1984|  1.45k|    }
 1985|       |
 1986|  1.43k|    if (!preferredGroup) {
  ------------------
  |  Branch (1986:9): [True: 5, False: 1.43k]
  ------------------
 1987|      5|        FATAL_ERROR(ss, SSL_ERROR_NO_CYPHER_OVERLAP, handshake_failure);
  ------------------
  |  |   22|      5|    do {                                     \
  |  |   23|      5|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      5|    do {                                                                           \
  |  |  |  |   15|      5|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      5|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 5]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      5|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      5|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      5|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      5|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      5|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      5|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1988|      5|        return SECFailure;
 1989|      5|    }
 1990|  1.43k|    SSL_TRC(3, ("%d: TLS13[%d]: group = %d", SSL_GETPID(), ss->fd,
  ------------------
  |  |   71|  1.43k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.43k]
  |  |  ------------------
  |  |   72|  1.43k|    ssl_Trace b
  ------------------
 1991|  1.43k|                preferredGroup->name));
 1992|       |
 1993|       |    /* Either provide a share, or provide a group that should be requested in a
 1994|       |     * HelloRetryRequest, but not both. */
 1995|  1.43k|    if (entry) {
  ------------------
  |  Branch (1995:9): [True: 1.25k, False: 181]
  ------------------
 1996|  1.25k|        PORT_Assert(preferredGroup == entry->group);
  ------------------
  |  |  120|  1.25k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.25k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.25k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1997|  1.25k|        *clientShare = entry;
 1998|  1.25k|        *requestedGroup = NULL;
 1999|  1.25k|    } else {
 2000|    181|        *clientShare = NULL;
 2001|    181|        *requestedGroup = preferredGroup;
 2002|    181|    }
 2003|  1.43k|    return SECSuccess;
 2004|  1.43k|}
tls13con.c:tls13_FindKeyShareEntry:
 1895|  1.45k|{
 1896|  1.45k|    PRCList *cur_p = PR_NEXT_LINK(&ss->xtnData.remoteKeyShares);
  ------------------
  |  |   47|  1.45k|        ((_e)->next)
  ------------------
 1897|  1.60k|    while (cur_p != &ss->xtnData.remoteKeyShares) {
  ------------------
  |  Branch (1897:12): [True: 1.40k, False: 199]
  ------------------
 1898|  1.40k|        TLS13KeyShareEntry *offer = (TLS13KeyShareEntry *)cur_p;
 1899|  1.40k|        if (offer->group == group) {
  ------------------
  |  Branch (1899:13): [True: 1.25k, False: 151]
  ------------------
 1900|  1.25k|            return offer;
 1901|  1.25k|        }
 1902|    151|        cur_p = PR_NEXT_LINK(cur_p);
  ------------------
  |  |   47|    151|        ((_e)->next)
  ------------------
 1903|    151|    }
 1904|    199|    return NULL;
 1905|  1.45k|}
tls13con.c:tls13_isGroupAcceptable:
 1876|      8|{
 1877|       |    /* We accept epsilon (e) bits around the offered group size. */
 1878|      8|    const unsigned int e = 2;
 1879|       |
 1880|      8|    PORT_Assert(offered);
  ------------------
  |  |  120|      8|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 8, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1881|      8|    PORT_Assert(preferredGroup);
  ------------------
  |  |  120|      8|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 8, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1882|       |
 1883|      8|    if (offered->bits >= preferredGroup->bits - e &&
  ------------------
  |  Branch (1883:9): [True: 8, False: 0]
  ------------------
 1884|      8|        offered->bits <= preferredGroup->bits + e) {
  ------------------
  |  Branch (1884:9): [True: 1, False: 7]
  ------------------
 1885|      1|        return PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
 1886|      1|    }
 1887|       |
 1888|      7|    return PR_FALSE;
  ------------------
  |  |  438|      7|#define PR_FALSE 0
  ------------------
 1889|      8|}
tls13con.c:tls13_MaybeSendHelloRetry:
 2074|  1.43k|{
 2075|  1.43k|    SSLHelloRetryRequestAction action = ssl_hello_retry_accept;
 2076|  1.43k|    PRUint8 token[256] = { 0 };
 2077|  1.43k|    unsigned int tokenLen = 0;
 2078|  1.43k|    SECStatus rv;
 2079|       |
 2080|  1.43k|    if (ss->hrrCallback) {
  ------------------
  |  Branch (2080:9): [True: 0, False: 1.43k]
  ------------------
 2081|      0|        action = ss->hrrCallback(!ss->ssl3.hs.helloRetry,
 2082|      0|                                 ss->xtnData.applicationToken.data,
 2083|      0|                                 ss->xtnData.applicationToken.len,
 2084|      0|                                 token, &tokenLen, sizeof(token),
 2085|      0|                                 ss->hrrCallbackArg);
 2086|      0|    }
 2087|       |
 2088|       |    /* These use SSL3_SendAlert directly to avoid an assertion in
 2089|       |     * tls13_FatalError(), which is ordinarily OK. */
 2090|  1.43k|    if (action == ssl_hello_retry_request && ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (2090:9): [True: 0, False: 1.43k]
  |  Branch (2090:46): [True: 0, False: 0]
  ------------------
 2091|      0|        (void)SSL3_SendAlert(ss, alert_fatal, internal_error);
 2092|      0|        PORT_SetError(SSL_ERROR_APP_CALLBACK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2093|      0|        return SECFailure;
 2094|      0|    }
 2095|       |
 2096|  1.43k|    if (action != ssl_hello_retry_request && tokenLen) {
  ------------------
  |  Branch (2096:9): [True: 1.43k, False: 0]
  |  Branch (2096:46): [True: 0, False: 1.43k]
  ------------------
 2097|      0|        (void)SSL3_SendAlert(ss, alert_fatal, internal_error);
 2098|      0|        PORT_SetError(SSL_ERROR_APP_CALLBACK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2099|      0|        return SECFailure;
 2100|      0|    }
 2101|       |
 2102|  1.43k|    if (tokenLen > sizeof(token)) {
  ------------------
  |  Branch (2102:9): [True: 0, False: 1.43k]
  ------------------
 2103|      0|        (void)SSL3_SendAlert(ss, alert_fatal, internal_error);
 2104|      0|        PORT_SetError(SSL_ERROR_APP_CALLBACK_ERROR);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2105|      0|        return SECFailure;
 2106|      0|    }
 2107|       |
 2108|  1.43k|    if (action == ssl_hello_retry_fail) {
  ------------------
  |  Branch (2108:9): [True: 0, False: 1.43k]
  ------------------
 2109|      0|        FATAL_ERROR(ss, SSL_ERROR_APPLICATION_ABORT, handshake_failure);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2110|      0|        return SECFailure;
 2111|      0|    }
 2112|       |
 2113|  1.43k|    if (action == ssl_hello_retry_reject_0rtt) {
  ------------------
  |  Branch (2113:9): [True: 0, False: 1.43k]
  ------------------
 2114|      0|        ss->ssl3.hs.zeroRttState = ssl_0rtt_ignored;
 2115|      0|        ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_trial;
 2116|      0|    }
 2117|       |
 2118|  1.43k|    if (!requestedGroup && action != ssl_hello_retry_request) {
  ------------------
  |  Branch (2118:9): [True: 1.25k, False: 181]
  |  Branch (2118:28): [True: 1.25k, False: 0]
  ------------------
 2119|  1.25k|        return SECSuccess;
 2120|  1.25k|    }
 2121|       |
 2122|    181|    rv = tls13_SendHelloRetryRequest(ss, requestedGroup, token, tokenLen);
 2123|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2123:9): [True: 0, False: 181]
  ------------------
 2124|      0|        return SECFailure; /* Code already set. */
 2125|      0|    }
 2126|       |
 2127|       |    /* We may have received ECH, but have to start over with CH2. */
 2128|    181|    ss->ssl3.hs.echAccepted = PR_FALSE;
  ------------------
  |  |  438|    181|#define PR_FALSE 0
  ------------------
 2129|    181|    PK11_HPKE_DestroyContext(ss->ssl3.hs.echHpkeCtx, PR_TRUE);
  ------------------
  |  |  437|    181|#define PR_TRUE 1
  ------------------
 2130|    181|    ss->ssl3.hs.echHpkeCtx = NULL;
 2131|       |
 2132|    181|    *hrrSent = PR_TRUE;
  ------------------
  |  |  437|    181|#define PR_TRUE 1
  ------------------
 2133|    181|    return SECSuccess;
 2134|    181|}
tls13con.c:tls13_SendHelloRetryRequest:
 2590|    181|{
 2591|    181|    SECStatus rv;
 2592|    181|    unsigned int cookieLen;
 2593|    181|    PRUint8 cookie[1024];
 2594|    181|    sslBuffer messageBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|    181|    {                        \
  |  |   24|    181|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|    181|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|    181|    }
  ------------------
 2595|       |
 2596|    181|    SSL_TRC(3, ("%d: TLS13[%d]: send hello retry request handshake",
  ------------------
  |  |   71|    181|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 181]
  |  |  ------------------
  |  |   72|    181|    ssl_Trace b
  ------------------
 2597|    181|                SSL_GETPID(), ss->fd));
 2598|       |
 2599|    181|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    275|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 87, False: 94]
  |  |  |  |  |  Branch (208:7): [True: 94, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2600|       |
 2601|       |    /* If an ECH backend or shared-mode server accepted ECH when offered,
 2602|       |     * the HRR extension's payload must be set to 8 zero bytes, these are
 2603|       |     * overwritten with the accept_confirmation value after the handshake
 2604|       |     * transcript calculation.
 2605|       |     * If a client-facing or shared-mode server did not accept ECH when offered
 2606|       |     * OR if ECH GREASE is enabled on the server and a ECH extension was
 2607|       |     * received, a 8 byte random value is set as the extension's payload
 2608|       |     * [draft-ietf-tls-esni-14, Section 7].
 2609|       |     *
 2610|       |     * The (temporary) payload is written to the extension in tls13exthandle.c/
 2611|       |     * tls13_ServerSendHrrEchXtn(). */
 2612|    181|    if (ss->xtnData.ech) {
  ------------------
  |  Branch (2612:9): [True: 13, False: 168]
  ------------------
 2613|     13|        PRUint8 echGreaseRaw[TLS13_ECH_SIGNAL_LEN] = { 0 };
 2614|     13|        if (!(ss->ssl3.hs.echAccepted ||
  ------------------
  |  Branch (2614:15): [True: 0, False: 13]
  ------------------
 2615|     13|              (ss->opt.enableTls13BackendEch &&
  ------------------
  |  Branch (2615:16): [True: 8, False: 5]
  ------------------
 2616|     13|               ss->xtnData.ech &&
  ------------------
  |  Branch (2616:16): [True: 8, False: 0]
  ------------------
 2617|     13|               ss->xtnData.ech->receivedInnerXtn))) {
  ------------------
  |  Branch (2617:16): [True: 5, False: 3]
  ------------------
 2618|      8|            rv = PK11_GenerateRandom(echGreaseRaw, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|      8|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2619|      8|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2619:17): [True: 0, False: 8]
  ------------------
 2620|      0|                return SECFailure;
 2621|      0|            }
 2622|      8|            SSL_TRC(100, ("Generated random value for ECH HRR GREASE."));
  ------------------
  |  |   71|      8|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 8]
  |  |  ------------------
  |  |   72|      8|    ssl_Trace b
  ------------------
 2623|      8|        }
 2624|     13|        sslBuffer echGreaseBuffer = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|     13|    {                        \
  |  |   24|     13|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|     13|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|     13|    }
  ------------------
 2625|     13|        rv = sslBuffer_Append(&echGreaseBuffer, echGreaseRaw, sizeof(echGreaseRaw));
 2626|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2626:13): [True: 0, False: 13]
  ------------------
 2627|      0|            return SECFailure;
 2628|      0|        }
 2629|       |        /* HRR GREASE/accept_confirmation zero bytes placeholder buffer. */
 2630|     13|        ss->ssl3.hs.greaseEchBuf = echGreaseBuffer;
 2631|     13|    }
 2632|       |
 2633|       |    /* Compute the cookie we are going to need. */
 2634|    181|    rv = tls13_MakeHrrCookie(ss, requestedGroup,
 2635|    181|                             appToken, appTokenLen,
 2636|    181|                             cookie, &cookieLen, sizeof(cookie));
 2637|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2637:9): [True: 0, False: 181]
  ------------------
 2638|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2639|      0|        return SECFailure;
 2640|      0|    }
 2641|       |
 2642|       |    /* Now build the body of the message. */
 2643|    181|    rv = tls13_ConstructHelloRetryRequest(ss, ss->ssl3.hs.cipher_suite,
 2644|    181|                                          requestedGroup,
 2645|    181|                                          cookie, cookieLen,
 2646|    181|                                          NULL, &messageBuf);
 2647|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2647:9): [True: 0, False: 181]
  ------------------
 2648|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2649|      0|        return SECFailure;
 2650|      0|    }
 2651|       |
 2652|       |    /* And send it. */
 2653|    181|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|    181|    {                                           \
  |  | 1467|    181|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 94, False: 87]
  |  |  ------------------
  |  | 1468|    181|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|     94|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|    181|    }
  ------------------
 2654|    181|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_server_hello,
 2655|    181|                                    SSL_BUFFER_LEN(&messageBuf));
  ------------------
  |  |   36|    181|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2656|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2656:9): [True: 0, False: 181]
  ------------------
 2657|      0|        goto loser;
 2658|      0|    }
 2659|    181|    rv = ssl3_AppendBufferToHandshake(ss, &messageBuf);
 2660|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2660:9): [True: 0, False: 181]
  ------------------
 2661|      0|        goto loser;
 2662|      0|    }
 2663|    181|    sslBuffer_Clear(&messageBuf); /* Done with messageBuf */
 2664|       |
 2665|    181|    if (ss->ssl3.hs.fakeSid.len) {
  ------------------
  |  Branch (2665:9): [True: 13, False: 168]
  ------------------
 2666|     13|        PRInt32 sent;
 2667|       |
 2668|     13|        PORT_Assert(!IS_DTLS(ss));
  ------------------
  |  |  120|     13|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     13|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 13, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2669|     13|        rv = ssl3_SendChangeCipherSpecsInt(ss);
 2670|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2670:13): [True: 0, False: 13]
  ------------------
 2671|      0|            goto loser;
 2672|      0|        }
 2673|       |        /* ssl3_SendChangeCipherSpecsInt() only flushes to the output buffer, so we
 2674|       |         * have to force a send. */
 2675|     13|        sent = ssl_SendSavedWriteData(ss);
 2676|     13|        if (sent < 0 && PORT_GetError() != PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
                      if (sent < 0 && PORT_GetError() != PR_WOULD_BLOCK_ERROR) {
  ------------------
  |  |   22|      0|#define PR_WOULD_BLOCK_ERROR                     (-5998L)
  ------------------
  |  Branch (2676:13): [True: 0, False: 13]
  |  Branch (2676:25): [True: 0, False: 0]
  ------------------
 2677|      0|            PORT_SetError(SSL_ERROR_SOCKET_WRITE_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2678|      0|            goto loser;
 2679|      0|        }
 2680|    168|    } else {
 2681|    168|        rv = ssl3_FlushHandshake(ss, 0);
 2682|    168|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2682:13): [True: 0, False: 168]
  ------------------
 2683|      0|            goto loser; /* error code set by ssl3_FlushHandshake */
 2684|      0|        }
 2685|    168|    }
 2686|       |
 2687|       |    /* We depend on this being exactly one record and one message. */
 2688|    181|    PORT_Assert(!IS_DTLS(ss) || (ss->ssl3.hs.sendMessageSeq == 1 &&
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2689|    181|                                 ss->ssl3.cwSpec->nextSeqNum == 1));
 2690|    181|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|    181|    {                                          \
  |  | 1472|    181|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 94, False: 87]
  |  |  ------------------
  |  | 1473|    181|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|     94|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|    181|    }
  ------------------
 2691|       |
 2692|    181|    ss->ssl3.hs.helloRetry = PR_TRUE;
  ------------------
  |  |  437|    181|#define PR_TRUE 1
  ------------------
 2693|       |
 2694|       |    /* We received early data but have to ignore it because we sent a retry. */
 2695|    181|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_sent) {
  ------------------
  |  Branch (2695:9): [True: 50, False: 131]
  ------------------
 2696|     50|        ss->ssl3.hs.zeroRttState = ssl_0rtt_ignored;
 2697|     50|        ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_hrr;
 2698|     50|    }
 2699|       |
 2700|    181|    return SECSuccess;
 2701|       |
 2702|      0|loser:
 2703|      0|    sslBuffer_Clear(&messageBuf);
 2704|      0|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
 2705|      0|    return SECFailure;
 2706|    181|}
tls13con.c:tls13_NegotiateAuthentication:
 2138|  1.25k|{
 2139|  1.25k|    if (ss->statelessResume) {
  ------------------
  |  Branch (2139:9): [True: 0, False: 1.25k]
  ------------------
 2140|      0|        SSL_TRC(3, ("%d: TLS13[%d]: selected resumption PSK authentication",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 2141|      0|                    SSL_GETPID(), ss->fd));
 2142|      0|        ss->ssl3.hs.signatureScheme = ssl_sig_none;
 2143|      0|        ss->ssl3.hs.kea_def_mutable.authKeyType = ssl_auth_psk;
 2144|       |        /* Overwritten by tls13_RestoreCipherInfo. */
 2145|      0|        ss->sec.authType = ssl_auth_psk;
 2146|      0|        return SECSuccess;
 2147|  1.25k|    } else if (ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (2147:16): [True: 0, False: 1.25k]
  ------------------
 2148|       |        /* If the EPSK doesn't specify a suite, use what was negotiated.
 2149|       |         * Else, only use the EPSK if we negotiated that suite. */
 2150|      0|        if (ss->xtnData.selectedPsk->zeroRttSuite == TLS_NULL_WITH_NULL_NULL ||
  ------------------
  |  |   76|      0|#define TLS_NULL_WITH_NULL_NULL                 0x0000
  ------------------
  |  Branch (2150:13): [True: 0, False: 0]
  ------------------
 2151|      0|            ss->ssl3.hs.cipher_suite == ss->xtnData.selectedPsk->zeroRttSuite) {
  ------------------
  |  Branch (2151:13): [True: 0, False: 0]
  ------------------
 2152|      0|            SSL_TRC(3, ("%d: TLS13[%d]: selected external PSK authentication",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 2153|      0|                        SSL_GETPID(), ss->fd));
 2154|      0|            ss->ssl3.hs.signatureScheme = ssl_sig_none;
 2155|      0|            ss->ssl3.hs.kea_def_mutable.authKeyType = ssl_auth_psk;
 2156|      0|            ss->sec.authType = ssl_auth_psk;
 2157|      0|            return SECSuccess;
 2158|      0|        }
 2159|      0|    }
 2160|       |
 2161|       |    /* If there were PSKs, they are no longer needed. */
 2162|  1.25k|    if (ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (2162:9): [True: 0, False: 1.25k]
  ------------------
 2163|      0|        tls13_DestroyPskList(&ss->ssl3.hs.psks);
 2164|      0|        ss->xtnData.selectedPsk = NULL;
 2165|      0|    }
 2166|       |
 2167|  1.25k|    SSL_TRC(3, ("%d: TLS13[%d]: selected certificate authentication",
  ------------------
  |  |   71|  1.25k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.25k]
  |  |  ------------------
  |  |   72|  1.25k|    ssl_Trace b
  ------------------
 2168|  1.25k|                SSL_GETPID(), ss->fd));
 2169|  1.25k|    SECStatus rv = tls13_SelectServerCert(ss);
 2170|  1.25k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2170:9): [True: 5, False: 1.24k]
  ------------------
 2171|      5|        return SECFailure;
 2172|      5|    }
 2173|  1.24k|    return SECSuccess;
 2174|  1.25k|}
tls13con.c:tls13_NegotiateZeroRtt:
 1832|  1.24k|{
 1833|  1.24k|    SSL_TRC(3, ("%d: TLS13[%d]: negotiate 0-RTT %p",
  ------------------
  |  |   71|  1.24k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.24k]
  |  |  ------------------
  |  |   72|  1.24k|    ssl_Trace b
  ------------------
 1834|  1.24k|                SSL_GETPID(), ss->fd, sid));
 1835|       |
 1836|       |    /* tls13_ServerHandleEarlyDataXtn sets this to ssl_0rtt_sent, so this will
 1837|       |     * be ssl_0rtt_none unless early_data is present. */
 1838|  1.24k|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_none) {
  ------------------
  |  Branch (1838:9): [True: 1.20k, False: 41]
  ------------------
 1839|  1.20k|        return;
 1840|  1.20k|    }
 1841|       |
 1842|     41|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_ignored) {
  ------------------
  |  Branch (1842:9): [True: 0, False: 41]
  ------------------
 1843|       |        /* HelloRetryRequest causes 0-RTT to be ignored. On the second
 1844|       |         * ClientHello, reset the ignore state so that decryption failure is
 1845|       |         * handled normally. */
 1846|      0|        if (ss->ssl3.hs.zeroRttIgnore == ssl_0rtt_ignore_hrr) {
  ------------------
  |  Branch (1846:13): [True: 0, False: 0]
  ------------------
 1847|      0|            PORT_Assert(ss->ssl3.hs.helloRetry);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1848|      0|            ss->ssl3.hs.zeroRttState = ssl_0rtt_none;
 1849|      0|            ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_none;
 1850|      0|        } else {
 1851|      0|            SSL_TRC(3, ("%d: TLS13[%d]: application ignored 0-RTT",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 1852|      0|                        SSL_GETPID(), ss->fd));
 1853|      0|        }
 1854|      0|        return;
 1855|      0|    }
 1856|       |
 1857|     41|    if (!tls13_CanNegotiateZeroRtt(ss, sid)) {
  ------------------
  |  Branch (1857:9): [True: 41, False: 0]
  ------------------
 1858|     41|        SSL_TRC(3, ("%d: TLS13[%d]: ignore 0-RTT", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|     41|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 41]
  |  |  ------------------
  |  |   72|     41|    ssl_Trace b
  ------------------
 1859|     41|        ss->ssl3.hs.zeroRttState = ssl_0rtt_ignored;
 1860|     41|        ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_trial;
 1861|     41|        return;
 1862|     41|    }
 1863|       |
 1864|      0|    SSL_TRC(3, ("%d: TLS13[%d]: enable 0-RTT", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 1865|      0|    PORT_Assert(ss->xtnData.selectedPsk);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1866|      0|    ss->ssl3.hs.zeroRttState = ssl_0rtt_accepted;
 1867|      0|    ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_none;
 1868|      0|    ss->ssl3.hs.zeroRttSuite = ss->ssl3.hs.cipher_suite;
 1869|      0|    ss->ssl3.hs.preliminaryInfo |= ssl_preinfo_0rtt_cipher_suite;
  ------------------
  |  |  394|      0|#define ssl_preinfo_0rtt_cipher_suite (1U << 2)
  ------------------
 1870|      0|}
tls13con.c:tls13_CanNegotiateZeroRtt:
 1777|     41|{
 1778|     41|    PORT_Assert(ss->ssl3.hs.zeroRttState == ssl_0rtt_sent);
  ------------------
  |  |  120|     41|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     41|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 41, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1779|     41|    sslPsk *psk = ss->xtnData.selectedPsk;
 1780|       |
 1781|     41|    if (!ss->opt.enable0RttData) {
  ------------------
  |  Branch (1781:9): [True: 18, False: 23]
  ------------------
 1782|     18|        return PR_FALSE;
  ------------------
  |  |  438|     18|#define PR_FALSE 0
  ------------------
 1783|     18|    }
 1784|     23|    if (!psk) {
  ------------------
  |  Branch (1784:9): [True: 23, False: 0]
  ------------------
 1785|     23|        return PR_FALSE;
  ------------------
  |  |  438|     23|#define PR_FALSE 0
  ------------------
 1786|     23|    }
 1787|      0|    if (psk->zeroRttSuite == TLS_NULL_WITH_NULL_NULL) {
  ------------------
  |  |   76|      0|#define TLS_NULL_WITH_NULL_NULL                 0x0000
  ------------------
  |  Branch (1787:9): [True: 0, False: 0]
  ------------------
 1788|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1789|      0|    }
 1790|      0|    if (!psk->maxEarlyData) {
  ------------------
  |  Branch (1790:9): [True: 0, False: 0]
  ------------------
 1791|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1792|      0|    }
 1793|      0|    if (ss->ssl3.hs.cipher_suite != psk->zeroRttSuite) {
  ------------------
  |  Branch (1793:9): [True: 0, False: 0]
  ------------------
 1794|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1795|      0|    }
 1796|      0|    if (psk->type == ssl_psk_resume) {
  ------------------
  |  Branch (1796:9): [True: 0, False: 0]
  ------------------
 1797|      0|        if (!sid) {
  ------------------
  |  Branch (1797:13): [True: 0, False: 0]
  ------------------
 1798|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1799|      0|        }
 1800|      0|        PORT_Assert(sid->u.ssl3.locked.sessionTicket.flags & ticket_allow_early_data);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1801|      0|        PORT_Assert(ss->statelessResume);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1802|      0|        if (!ss->statelessResume) {
  ------------------
  |  Branch (1802:13): [True: 0, False: 0]
  ------------------
 1803|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1804|      0|        }
 1805|      0|        if (SECITEM_CompareItem(&ss->xtnData.nextProto,
  ------------------
  |  |  105|      0|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (1805:13): [True: 0, False: 0]
  ------------------
 1806|      0|                                &sid->u.ssl3.alpnSelection) != 0) {
 1807|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1808|      0|        }
 1809|      0|    } else if (psk->type != ssl_psk_external) {
  ------------------
  |  Branch (1809:16): [True: 0, False: 0]
  ------------------
 1810|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1811|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1812|      0|    }
 1813|       |
 1814|      0|    if (tls13_IsReplay(ss, sid)) {
  ------------------
  |  Branch (1814:9): [True: 0, False: 0]
  ------------------
 1815|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1816|      0|    }
 1817|       |
 1818|      0|    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1819|      0|}
tls13con.c:tls13_DeriveSecretWrap:
 4408|  6.48k|{
 4409|  6.48k|    SECStatus rv;
 4410|  6.48k|    SSL3Hashes hashes;
 4411|  6.48k|    char buf[100];
 4412|  6.48k|    const char *label;
 4413|       |
 4414|  6.48k|    if (prefix) {
  ------------------
  |  Branch (4414:9): [True: 4.85k, False: 1.63k]
  ------------------
 4415|  4.85k|        if ((strlen(prefix) + strlen(suffix) + 2) > sizeof(buf)) {
  ------------------
  |  Branch (4415:13): [True: 0, False: 4.85k]
  ------------------
 4416|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4417|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4418|      0|            return SECFailure;
 4419|      0|        }
 4420|  4.85k|        (void)PR_snprintf(buf, sizeof(buf), "%s %s",
 4421|  4.85k|                          prefix, suffix);
 4422|  4.85k|        label = buf;
 4423|  4.85k|    } else {
 4424|  1.63k|        label = suffix;
 4425|  1.63k|    }
 4426|       |
 4427|  6.48k|    SSL_TRC(3, ("%d: TLS13[%d]: deriving secret '%s'",
  ------------------
  |  |   71|  6.48k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 6.48k]
  |  |  ------------------
  |  |   72|  6.48k|    ssl_Trace b
  ------------------
 4428|  6.48k|                SSL_GETPID(), ss->fd, label));
 4429|  6.48k|    rv = tls13_ComputeHandshakeHashes(ss, &hashes);
 4430|  6.48k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4430:9): [True: 0, False: 6.48k]
  ------------------
 4431|      0|        PORT_Assert(0); /* Should never fail */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4432|      0|        ssl_MapLowLevelError(SEC_ERROR_LIBRARY_FAILURE);
 4433|      0|        return SECFailure;
 4434|      0|    }
 4435|       |
 4436|  6.48k|    rv = tls13_DeriveSecret(ss, key, label, strlen(label),
 4437|  6.48k|                            &hashes, dest, tls13_GetHash(ss));
 4438|  6.48k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4438:9): [True: 0, False: 6.48k]
  ------------------
 4439|      0|        return SECFailure;
 4440|      0|    }
 4441|       |
 4442|  6.48k|    if (keylogLabel) {
  ------------------
  |  Branch (4442:9): [True: 6.06k, False: 417]
  ------------------
 4443|  6.06k|        ssl3_RecordKeyLog(ss, keylogLabel, *dest);
 4444|  6.06k|    }
 4445|  6.48k|    return SECSuccess;
 4446|  6.48k|}
tls13con.c:tls13_HandleClientKeyShare:
 2715|  1.24k|{
 2716|  1.24k|    SECStatus rv;
 2717|  1.24k|    sslEphemeralKeyPair *keyPair; /* ours */
 2718|  1.24k|    SECItem *ciphertext = NULL;
 2719|  1.24k|    PK11SymKey *dheSecret = NULL;
 2720|  1.24k|    PK11SymKey *kemSecret = NULL;
 2721|       |
 2722|  1.24k|    SSL_TRC(3, ("%d: TLS13[%d]: handle client_key_share handshake",
  ------------------
  |  |   71|  1.24k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.24k]
  |  |  ------------------
  |  |   72|  1.24k|    ssl_Trace b
  ------------------
 2723|  1.24k|                SSL_GETPID(), ss->fd));
 2724|       |
 2725|  1.24k|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.85k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 634, False: 611]
  |  |  |  |  |  Branch (208:7): [True: 611, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2726|  1.24k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.85k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 634, False: 611]
  |  |  |  |  |  Branch (208:7): [True: 611, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2727|  1.24k|    PORT_Assert(peerShare);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2728|       |
 2729|  1.24k|    tls13_SetKeyExchangeType(ss, peerShare->group);
 2730|       |
 2731|       |    /* Generate our key */
 2732|  1.24k|    rv = tls13_AddKeyShare(ss, peerShare->group);
 2733|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2733:9): [True: 0, False: 1.24k]
  ------------------
 2734|      0|        return rv;
 2735|      0|    }
 2736|       |
 2737|       |    /* We should have exactly one key share. */
 2738|  1.24k|    PORT_Assert(!PR_CLIST_IS_EMPTY(&ss->ephemeralKeyPairs));
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2739|  1.24k|    PORT_Assert(PR_PREV_LINK(&ss->ephemeralKeyPairs) ==
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2740|  1.24k|                PR_NEXT_LINK(&ss->ephemeralKeyPairs));
 2741|       |
 2742|  1.24k|    keyPair = ((sslEphemeralKeyPair *)PR_NEXT_LINK(&ss->ephemeralKeyPairs));
  ------------------
  |  |   47|  1.24k|        ((_e)->next)
  ------------------
 2743|  1.24k|    ss->sec.keaKeyBits = SECKEY_PublicKeyStrengthInBits(keyPair->keys->pubKey);
 2744|       |
 2745|       |    /* Register the sender */
 2746|  1.24k|    rv = ssl3_RegisterExtensionSender(ss, &ss->xtnData, ssl_tls13_key_share_xtn,
 2747|  1.24k|                                      tls13_ServerSendKeyShareXtn);
 2748|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2748:9): [True: 0, False: 1.24k]
  ------------------
 2749|      0|        return SECFailure; /* Error code set already. */
 2750|      0|    }
 2751|       |
 2752|  1.24k|    rv = tls13_HandleKeyShare(ss, peerShare, keyPair->keys,
 2753|  1.24k|                              tls13_GetHash(ss),
 2754|  1.24k|                              &dheSecret);
 2755|  1.24k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2755:9): [True: 14, False: 1.23k]
  ------------------
 2756|     14|        goto loser; /* Error code already set. */
 2757|     14|    }
 2758|       |
 2759|  1.23k|    if (peerShare->group->keaType == ssl_kea_ecdh_hybrid) {
  ------------------
  |  Branch (2759:9): [True: 101, False: 1.13k]
  ------------------
 2760|    101|        rv = tls13_HandleKEMKey(ss, peerShare, &kemSecret, &ciphertext);
 2761|    101|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2761:13): [True: 18, False: 83]
  ------------------
 2762|     18|            goto loser; /* Error set by tls13_HandleKEMKey */
 2763|     18|        }
 2764|     83|        switch (peerShare->group->name) {
 2765|      0|            case ssl_grp_kem_xyber768d00:
  ------------------
  |  Branch (2765:13): [True: 0, False: 83]
  ------------------
 2766|      0|                ss->ssl3.hs.dheSecret = PK11_ConcatSymKeys(dheSecret, kemSecret, CKM_HKDF_DERIVE, CKA_DERIVE);
  ------------------
  |  | 1296|      0|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
                              ss->ssl3.hs.dheSecret = PK11_ConcatSymKeys(dheSecret, kemSecret, CKM_HKDF_DERIVE, CKA_DERIVE);
  ------------------
  |  |  555|      0|#define CKA_DERIVE 0x0000010CUL
  ------------------
 2767|      0|                break;
 2768|     83|            case ssl_grp_kem_mlkem768x25519:
  ------------------
  |  Branch (2768:13): [True: 83, False: 0]
  ------------------
 2769|     83|                ss->ssl3.hs.dheSecret = PK11_ConcatSymKeys(kemSecret, dheSecret, CKM_HKDF_DERIVE, CKA_DERIVE);
  ------------------
  |  | 1296|     83|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
                              ss->ssl3.hs.dheSecret = PK11_ConcatSymKeys(kemSecret, dheSecret, CKM_HKDF_DERIVE, CKA_DERIVE);
  ------------------
  |  |  555|     83|#define CKA_DERIVE 0x0000010CUL
  ------------------
 2770|     83|                break;
 2771|      0|            default:
  ------------------
  |  Branch (2771:13): [True: 0, False: 83]
  ------------------
 2772|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2773|      0|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2774|      0|                ss->ssl3.hs.dheSecret = NULL;
 2775|      0|                break;
 2776|     83|        }
 2777|     83|        if (!ss->ssl3.hs.dheSecret) {
  ------------------
  |  Branch (2777:13): [True: 0, False: 83]
  ------------------
 2778|      0|            goto loser; /* Error set by PK11_ConcatSymKeys */
 2779|      0|        }
 2780|     83|        keyPair->kemCt = ciphertext;
 2781|     83|        PK11_FreeSymKey(dheSecret);
 2782|     83|        PK11_FreeSymKey(kemSecret);
 2783|  1.13k|    } else {
 2784|  1.13k|        ss->ssl3.hs.dheSecret = dheSecret;
 2785|  1.13k|    }
 2786|       |
 2787|  1.21k|    return SECSuccess;
 2788|       |
 2789|     32|loser:
 2790|     32|    SECITEM_FreeItem(ciphertext, PR_TRUE);
  ------------------
  |  |  108|     32|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(ciphertext, PR_TRUE);
  ------------------
  |  |  437|     32|#define PR_TRUE 1
  ------------------
 2791|     32|    PK11_FreeSymKey(dheSecret);
 2792|     32|    PK11_FreeSymKey(kemSecret);
 2793|     32|    FATAL_ERROR(ss, PORT_GetError(), illegal_parameter);
  ------------------
  |  |   22|     32|    do {                                     \
  |  |   23|     32|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     32|    do {                                                                           \
  |  |  |  |   15|     32|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     32|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 32]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     32|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     32|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     32|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     32|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     32|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     32|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     32|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2794|     32|    return SECFailure;
 2795|  1.23k|}
tls13con.c:tls13_SetKeyExchangeType:
 3548|  1.24k|{
 3549|  1.24k|    ss->sec.keaGroup = group;
 3550|  1.24k|    switch (group->keaType) {
 3551|       |        /* Note: These overwrite on resumption.... so if you start with ECDH
 3552|       |         * and resume with DH, we report DH. That's fine, since no answer
 3553|       |         * is really right. */
 3554|    595|        case ssl_kea_ecdh:
  ------------------
  |  Branch (3554:9): [True: 595, False: 650]
  ------------------
 3555|    595|            ss->ssl3.hs.kea_def_mutable.exchKeyType =
 3556|    595|                ss->statelessResume ? ssl_kea_ecdh_psk : ssl_kea_ecdh;
  ------------------
  |  Branch (3556:17): [True: 0, False: 595]
  ------------------
 3557|    595|            ss->sec.keaType = ssl_kea_ecdh;
 3558|    595|            break;
 3559|    102|        case ssl_kea_ecdh_hybrid:
  ------------------
  |  Branch (3559:9): [True: 102, False: 1.14k]
  ------------------
 3560|    102|            ss->ssl3.hs.kea_def_mutable.exchKeyType =
 3561|    102|                ss->statelessResume ? ssl_kea_ecdh_hybrid_psk : ssl_kea_ecdh_hybrid;
  ------------------
  |  Branch (3561:17): [True: 0, False: 102]
  ------------------
 3562|    102|            ss->sec.keaType = ssl_kea_ecdh_hybrid;
 3563|    102|            break;
 3564|    548|        case ssl_kea_dh:
  ------------------
  |  Branch (3564:9): [True: 548, False: 697]
  ------------------
 3565|    548|            ss->ssl3.hs.kea_def_mutable.exchKeyType =
 3566|    548|                ss->statelessResume ? ssl_kea_dh_psk : ssl_kea_dh;
  ------------------
  |  Branch (3566:17): [True: 0, False: 548]
  ------------------
 3567|    548|            ss->sec.keaType = ssl_kea_dh;
 3568|    548|            break;
 3569|      0|        default:
  ------------------
  |  Branch (3569:9): [True: 0, False: 1.24k]
  ------------------
 3570|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3571|  1.24k|    }
 3572|  1.24k|}
tls13con.c:tls13_HandleKEMKey:
  796|    101|{
  797|    101|    PORTCheapArenaPool arena;
  798|    101|    SECKEYPublicKey *peerKey;
  799|    101|    CK_OBJECT_HANDLE handle;
  800|    101|    SECStatus rv;
  801|       |
  802|    101|    PORT_InitCheapArena(&arena, DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|    101|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
  803|    101|    peerKey = PORT_ArenaZNew(&arena.arena, SECKEYPublicKey);
  ------------------
  |  |  155|    101|    (type *)PORT_ArenaZAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   59|    101|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  |  |  ------------------
  ------------------
  804|    101|    if (peerKey == NULL) {
  ------------------
  |  Branch (804:9): [True: 0, False: 101]
  ------------------
  805|      0|        goto loser;
  806|      0|    }
  807|    101|    peerKey->arena = &arena.arena;
  808|    101|    peerKey->pkcs11Slot = NULL;
  809|    101|    peerKey->pkcs11ID = CK_INVALID_HANDLE;
  ------------------
  |  |   78|    101|#define CK_INVALID_HANDLE 0
  ------------------
  810|       |
  811|    101|    rv = tls13_ImportKEMKeyShare(peerKey, entry);
  812|    101|    if (rv != SECSuccess) {
  ------------------
  |  Branch (812:9): [True: 2, False: 99]
  ------------------
  813|      2|        goto loser;
  814|      2|    }
  815|       |
  816|     99|    PK11SlotInfo *slot = PK11_GetBestSlot(CKM_NSS_KYBER, ss->pkcs11PinArg);
  ------------------
  |  |  268|     99|#define CKM_NSS_KYBER (CKM_NSS + 46)
  |  |  ------------------
  |  |  |  |  162|     99|#define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  | 1309|     99|#define CKM_VENDOR_DEFINED 0x80000000UL
  |  |  |  |  ------------------
  |  |  |  |               #define CKM_NSS (CKM_VENDOR_DEFINED | NSSCK_VENDOR_NSS)
  |  |  |  |  ------------------
  |  |  |  |  |  |   27|     99|#define NSSCK_VENDOR_NSS 0x4E534350 /* NSCP */
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  817|     99|    if (!slot) {
  ------------------
  |  Branch (817:9): [True: 0, False: 99]
  ------------------
  818|      0|        goto loser;
  819|      0|    }
  820|       |
  821|     99|    handle = PK11_ImportPublicKey(slot, peerKey, PR_FALSE);
  ------------------
  |  |  438|     99|#define PR_FALSE 0
  ------------------
  822|     99|    PK11_FreeSlot(slot); /* peerKey holds a slot reference on success. */
  823|     99|    if (handle == CK_INVALID_HANDLE) {
  ------------------
  |  |   78|     99|#define CK_INVALID_HANDLE 0
  ------------------
  |  Branch (823:9): [True: 0, False: 99]
  ------------------
  824|      0|        goto loser;
  825|      0|    }
  826|       |
  827|     99|    rv = PK11_Encapsulate(peerKey,
  828|     99|                          CKM_HKDF_DERIVE, PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  | 1296|     99|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
                                        CKM_HKDF_DERIVE, PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  |  195|     99|#define PK11_ATTR_SESSION 0x00000002L
  ------------------
                                        CKM_HKDF_DERIVE, PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  |  261|     99|#define PK11_ATTR_INSENSITIVE 0x00000080L
  ------------------
                                        CKM_HKDF_DERIVE, PK11_ATTR_SESSION | PK11_ATTR_INSENSITIVE | PK11_ATTR_PUBLIC,
  ------------------
  |  |  217|     99|#define PK11_ATTR_PUBLIC 0x00000008L
  ------------------
  829|     99|                          CKF_DERIVE, key, ciphertext);
  ------------------
  |  | 1364|     99|#define CKF_DERIVE 0x00080000UL
  ------------------
  830|       |
  831|       |    /* Destroy the imported public key */
  832|     99|    PORT_Assert(peerKey->pkcs11Slot);
  ------------------
  |  |  120|     99|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     99|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 99, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  833|     99|    PK11_DestroyObject(peerKey->pkcs11Slot, peerKey->pkcs11ID);
  834|     99|    PK11_FreeSlot(peerKey->pkcs11Slot);
  835|       |
  836|     99|    PORT_DestroyCheapArena(&arena);
  837|     99|    return rv;
  838|       |
  839|      2|loser:
  840|      2|    PORT_DestroyCheapArena(&arena);
  841|      2|    return SECFailure;
  842|     99|}
tls13con.c:tls13_ImportKEMKeyShare:
  703|    101|{
  704|    101|    SECItem pk = { siBuffer, NULL, 0 };
  705|    101|    SECStatus rv;
  706|    101|    size_t expected_len;
  707|       |
  708|    101|    switch (entry->group->name) {
  709|      0|        case ssl_grp_kem_xyber768d00:
  ------------------
  |  Branch (709:9): [True: 0, False: 101]
  ------------------
  710|      0|            expected_len = X25519_PUBLIC_KEY_BYTES + KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|      0|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
                          expected_len = X25519_PUBLIC_KEY_BYTES + KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|      0|#define KYBER768_PUBLIC_KEY_BYTES 1184U
  ------------------
  711|      0|            break;
  712|    101|        case ssl_grp_kem_mlkem768x25519:
  ------------------
  |  Branch (712:9): [True: 101, False: 0]
  ------------------
  713|    101|            expected_len = X25519_PUBLIC_KEY_BYTES + KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|    101|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
                          expected_len = X25519_PUBLIC_KEY_BYTES + KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|    101|#define KYBER768_PUBLIC_KEY_BYTES 1184U
  ------------------
  714|    101|            break;
  715|      0|        default:
  ------------------
  |  Branch (715:9): [True: 0, False: 101]
  ------------------
  716|      0|            PORT_SetError(SEC_ERROR_UNSUPPORTED_KEYALG);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  717|      0|            return SECFailure;
  718|    101|    }
  719|       |
  720|    101|    if (entry->key_exchange.len != expected_len) {
  ------------------
  |  Branch (720:9): [True: 2, False: 99]
  ------------------
  721|      2|        PORT_SetError(SSL_ERROR_RX_MALFORMED_HYBRID_KEY_SHARE);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  722|      2|        return SECFailure;
  723|      2|    }
  724|       |
  725|     99|    switch (entry->group->name) {
  726|      0|        case ssl_grp_kem_xyber768d00:
  ------------------
  |  Branch (726:9): [True: 0, False: 99]
  ------------------
  727|      0|            peerKey->keyType = kyberKey;
  728|      0|            peerKey->u.kyber.params = params_kyber768_round3;
  729|       |            // key_exchange.data is `x25519 || kyber768`
  730|      0|            pk.data = entry->key_exchange.data + X25519_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|      0|#define X25519_PUBLIC_KEY_BYTES 32U
  ------------------
  731|      0|            pk.len = KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|      0|#define KYBER768_PUBLIC_KEY_BYTES 1184U
  ------------------
  732|      0|            break;
  733|     99|        case ssl_grp_kem_mlkem768x25519:
  ------------------
  |  Branch (733:9): [True: 99, False: 0]
  ------------------
  734|     99|            peerKey->keyType = kyberKey;
  735|     99|            peerKey->u.kyber.params = params_ml_kem768;
  736|       |            // key_exchange.data is `mlkem768 || x25519`
  737|     99|            pk.data = entry->key_exchange.data;
  738|     99|            pk.len = KYBER768_PUBLIC_KEY_BYTES;
  ------------------
  |  |    8|     99|#define KYBER768_PUBLIC_KEY_BYTES 1184U
  ------------------
  739|     99|            break;
  740|      0|        default:
  ------------------
  |  Branch (740:9): [True: 0, False: 99]
  ------------------
  741|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  742|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  743|      0|            return SECFailure;
  744|     99|    }
  745|       |
  746|     99|    rv = SECITEM_CopyItem(peerKey->arena, &peerKey->u.kyber.publicValue, &pk);
  ------------------
  |  |  106|     99|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  747|     99|    if (rv != SECSuccess) {
  ------------------
  |  Branch (747:9): [True: 0, False: 99]
  ------------------
  748|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  749|      0|        return SECFailure;
  750|      0|    }
  751|       |
  752|     99|    return SECSuccess;
  753|     99|}
tls13con.c:tls13_SendCertificateRequest:
 2817|    447|{
 2818|    447|    SECStatus rv;
 2819|    447|    sslBuffer extensionBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|    447|    {                        \
  |  |   24|    447|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|    447|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|    447|    }
  ------------------
 2820|    447|    unsigned int offset = 0;
 2821|       |
 2822|    447|    SSL_TRC(3, ("%d: TLS13[%d]: begin send certificate_request",
  ------------------
  |  |   71|    447|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 447]
  |  |  ------------------
  |  |   72|    447|    ssl_Trace b
  ------------------
 2823|    447|                SSL_GETPID(), ss->fd));
 2824|       |
 2825|    447|    if (ss->firstHsDone) {
  ------------------
  |  Branch (2825:9): [True: 0, False: 447]
  ------------------
 2826|      0|        PORT_Assert(ss->ssl3.hs.shaPostHandshake == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2827|      0|        ss->ssl3.hs.shaPostHandshake = PK11_CloneContext(ss->ssl3.hs.sha);
 2828|      0|        if (ss->ssl3.hs.shaPostHandshake == NULL) {
  ------------------
  |  Branch (2828:13): [True: 0, False: 0]
  ------------------
 2829|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 2830|      0|            return SECFailure;
 2831|      0|        }
 2832|      0|    }
 2833|       |
 2834|    447|    rv = ssl_ConstructExtensions(ss, &extensionBuf, ssl_hs_certificate_request);
 2835|    447|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2835:9): [True: 0, False: 447]
  ------------------
 2836|      0|        return SECFailure; /* Code already set. */
 2837|      0|    }
 2838|       |    /* We should always have at least one of these. */
 2839|    447|    PORT_Assert(SSL_BUFFER_LEN(&extensionBuf) > 0);
  ------------------
  |  |  120|    447|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    447|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 447, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2840|       |
 2841|       |    /* Create a new request context for post-handshake authentication */
 2842|    447|    if (ss->firstHsDone) {
  ------------------
  |  Branch (2842:9): [True: 0, False: 447]
  ------------------
 2843|      0|        PRUint8 context[16];
 2844|      0|        SECItem contextItem = { siBuffer, context, sizeof(context) };
 2845|       |
 2846|      0|        rv = PK11_GenerateRandom(context, sizeof(context));
 2847|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2847:13): [True: 0, False: 0]
  ------------------
 2848|      0|            goto loser;
 2849|      0|        }
 2850|       |
 2851|      0|        SECITEM_FreeItem(&ss->xtnData.certReqContext, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&ss->xtnData.certReqContext, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2852|      0|        rv = SECITEM_CopyItem(NULL, &ss->xtnData.certReqContext, &contextItem);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 2853|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2853:13): [True: 0, False: 0]
  ------------------
 2854|      0|            FATAL_ERROR(ss, SEC_ERROR_NO_MEMORY, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2855|      0|            goto loser;
 2856|      0|        }
 2857|       |
 2858|      0|        offset = SSL_BUFFER_LEN(&ss->sec.ci.sendBuf);
  ------------------
  |  |   36|      0|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2859|      0|    }
 2860|       |
 2861|    447|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_certificate_request,
 2862|    447|                                    1 + /* request context length */
 2863|    447|                                        ss->xtnData.certReqContext.len +
 2864|    447|                                        2 + /* extension length */
 2865|    447|                                        SSL_BUFFER_LEN(&extensionBuf));
  ------------------
  |  |   36|    447|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2866|    447|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2866:9): [True: 0, False: 447]
  ------------------
 2867|      0|        goto loser; /* err set by AppendHandshake. */
 2868|      0|    }
 2869|       |
 2870|       |    /* Context. */
 2871|    447|    rv = ssl3_AppendHandshakeVariable(ss, ss->xtnData.certReqContext.data,
 2872|    447|                                      ss->xtnData.certReqContext.len, 1);
 2873|    447|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2873:9): [True: 0, False: 447]
  ------------------
 2874|      0|        goto loser; /* err set by AppendHandshake. */
 2875|      0|    }
 2876|       |    /* Extensions. */
 2877|    447|    rv = ssl3_AppendBufferToHandshakeVariable(ss, &extensionBuf, 2);
 2878|    447|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2878:9): [True: 0, False: 447]
  ------------------
 2879|      0|        goto loser; /* err set by AppendHandshake. */
 2880|      0|    }
 2881|       |
 2882|    447|    if (ss->firstHsDone) {
  ------------------
  |  Branch (2882:9): [True: 0, False: 447]
  ------------------
 2883|      0|        rv = ssl3_UpdatePostHandshakeHashes(ss,
 2884|      0|                                            SSL_BUFFER_BASE(&ss->sec.ci.sendBuf) + offset,
  ------------------
  |  |   35|      0|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
 2885|      0|                                            SSL_BUFFER_LEN(&ss->sec.ci.sendBuf) - offset);
  ------------------
  |  |   36|      0|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 2886|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2886:13): [True: 0, False: 0]
  ------------------
 2887|      0|            goto loser;
 2888|      0|        }
 2889|      0|    }
 2890|       |
 2891|    447|    sslBuffer_Clear(&extensionBuf);
 2892|    447|    return SECSuccess;
 2893|       |
 2894|      0|loser:
 2895|      0|    sslBuffer_Clear(&extensionBuf);
 2896|      0|    return SECFailure;
 2897|    447|}
tls13con.c:tls13_HandleCertificateRequest:
 3108|      3|{
 3109|      3|    SECStatus rv;
 3110|      3|    SECItem context = { siBuffer, NULL, 0 };
 3111|      3|    SECItem extensionsData = { siBuffer, NULL, 0 };
 3112|       |
 3113|      3|    SSL_TRC(3, ("%d: TLS13[%d]: handle certificate_request sequence",
  ------------------
  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  ------------------
  |  |   72|      3|    ssl_Trace b
  ------------------
 3114|      3|                SSL_GETPID(), ss->fd));
 3115|       |
 3116|      3|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 2]
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3117|      3|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 2]
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3118|       |
 3119|       |    /* Client */
 3120|      3|    if (ss->opt.enablePostHandshakeAuth) {
  ------------------
  |  Branch (3120:9): [True: 0, False: 3]
  ------------------
 3121|      0|        rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_CERT_REQUEST,
  ------------------
  |  |  182|      0|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      0|                       __VA_ARGS__,                                 \
  |  |  184|      0|                       wait_invalid)
  ------------------
 3122|      0|                                  wait_cert_request, idle_handshake);
 3123|      3|    } else {
 3124|      3|        rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_CERT_REQUEST,
  ------------------
  |  |  182|      3|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      3|                       __VA_ARGS__,                                 \
  |  |  184|      3|                       wait_invalid)
  ------------------
 3125|      3|                                  wait_cert_request);
 3126|      3|    }
 3127|      3|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3127:9): [True: 3, False: 0]
  ------------------
 3128|      3|        return SECFailure;
 3129|      3|    }
 3130|       |
 3131|       |    /*  MUST NOT combine external PSKs with certificate authentication. */
 3132|      0|    if (ss->sec.authType == ssl_auth_psk) {
  ------------------
  |  Branch (3132:9): [True: 0, False: 0]
  ------------------
 3133|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_UNEXPECTED_CERT_REQUEST, unexpected_message);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3134|      0|        return SECFailure;
 3135|      0|    }
 3136|       |
 3137|      0|    if (tls13_IsPostHandshake(ss)) {
  ------------------
  |  Branch (3137:9): [True: 0, False: 0]
  ------------------
 3138|      0|        PORT_Assert(ss->ssl3.hs.shaPostHandshake == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3139|      0|        ss->ssl3.hs.shaPostHandshake = PK11_CloneContext(ss->ssl3.hs.sha);
 3140|      0|        if (ss->ssl3.hs.shaPostHandshake == NULL) {
  ------------------
  |  Branch (3140:13): [True: 0, False: 0]
  ------------------
 3141|      0|            ssl_MapLowLevelError(SSL_ERROR_SHA_DIGEST_FAILURE);
 3142|      0|            return SECFailure;
 3143|      0|        }
 3144|      0|        rv = ssl_HashPostHandshakeMessage(ss, ssl_hs_certificate_request, b, length);
 3145|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3145:13): [True: 0, False: 0]
  ------------------
 3146|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3147|      0|            return SECFailure;
 3148|      0|        }
 3149|       |
 3150|       |        /* clean up anything left from previous handshake. */
 3151|      0|        if (ss->ssl3.clientCertChain != NULL) {
  ------------------
  |  Branch (3151:13): [True: 0, False: 0]
  ------------------
 3152|      0|            CERT_DestroyCertificateList(ss->ssl3.clientCertChain);
 3153|      0|            ss->ssl3.clientCertChain = NULL;
 3154|      0|        }
 3155|      0|        if (ss->ssl3.clientCertificate != NULL) {
  ------------------
  |  Branch (3155:13): [True: 0, False: 0]
  ------------------
 3156|      0|            CERT_DestroyCertificate(ss->ssl3.clientCertificate);
 3157|      0|            ss->ssl3.clientCertificate = NULL;
 3158|      0|        }
 3159|      0|        if (ss->ssl3.clientPrivateKey != NULL) {
  ------------------
  |  Branch (3159:13): [True: 0, False: 0]
  ------------------
 3160|      0|            SECKEY_DestroyPrivateKey(ss->ssl3.clientPrivateKey);
 3161|      0|            ss->ssl3.clientPrivateKey = NULL;
 3162|      0|        }
 3163|      0|        if (ss->ssl3.hs.clientAuthSignatureSchemes != NULL) {
  ------------------
  |  Branch (3163:13): [True: 0, False: 0]
  ------------------
 3164|      0|            PORT_Free(ss->ssl3.hs.clientAuthSignatureSchemes);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 3165|      0|            ss->ssl3.hs.clientAuthSignatureSchemes = NULL;
 3166|      0|            ss->ssl3.hs.clientAuthSignatureSchemesLen = 0;
 3167|      0|        }
 3168|      0|        SECITEM_FreeItem(&ss->xtnData.certReqContext, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&ss->xtnData.certReqContext, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3169|      0|        ss->xtnData.certReqContext.data = NULL;
 3170|      0|    } else {
 3171|      0|        PORT_Assert(ss->ssl3.clientCertChain == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3172|      0|        PORT_Assert(ss->ssl3.clientCertificate == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3173|      0|        PORT_Assert(ss->ssl3.clientPrivateKey == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3174|      0|        PORT_Assert(ss->ssl3.hs.clientAuthSignatureSchemes == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3175|      0|        PORT_Assert(ss->ssl3.hs.clientAuthSignatureSchemesLen == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3176|      0|        PORT_Assert(!ss->ssl3.hs.clientCertRequested);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3177|      0|        PORT_Assert(ss->xtnData.certReqContext.data == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3178|      0|    }
 3179|       |
 3180|      0|    rv = ssl3_ConsumeHandshakeVariable(ss, &context, 1, &b, &length);
 3181|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3181:9): [True: 0, False: 0]
  ------------------
 3182|      0|        return SECFailure;
 3183|      0|    }
 3184|       |
 3185|       |    /* Unless it is a post-handshake client auth, the certificate
 3186|       |     * request context must be empty. */
 3187|      0|    if (!tls13_IsPostHandshake(ss) && context.len > 0) {
  ------------------
  |  Branch (3187:9): [True: 0, False: 0]
  |  Branch (3187:39): [True: 0, False: 0]
  ------------------
 3188|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERT_REQUEST, illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3189|      0|        return SECFailure;
 3190|      0|    }
 3191|       |
 3192|      0|    rv = ssl3_ConsumeHandshakeVariable(ss, &extensionsData, 2, &b, &length);
 3193|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3193:9): [True: 0, False: 0]
  ------------------
 3194|      0|        return SECFailure;
 3195|      0|    }
 3196|       |
 3197|      0|    if (length) {
  ------------------
  |  Branch (3197:9): [True: 0, False: 0]
  ------------------
 3198|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERT_REQUEST, decode_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3199|      0|        return SECFailure;
 3200|      0|    }
 3201|       |
 3202|       |    /* Process all the extensions. */
 3203|      0|    rv = ssl3_HandleExtensions(ss, &extensionsData.data, &extensionsData.len,
 3204|      0|                               ssl_hs_certificate_request);
 3205|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3205:9): [True: 0, False: 0]
  ------------------
 3206|      0|        return SECFailure;
 3207|      0|    }
 3208|       |
 3209|      0|    if (!ss->xtnData.numSigSchemes) {
  ------------------
  |  Branch (3209:9): [True: 0, False: 0]
  ------------------
 3210|      0|        FATAL_ERROR(ss, SSL_ERROR_MISSING_SIGNATURE_ALGORITHMS_EXTENSION,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3211|      0|                    missing_extension);
 3212|      0|        return SECFailure;
 3213|      0|    }
 3214|       |
 3215|      0|    rv = SECITEM_CopyItem(NULL, &ss->xtnData.certReqContext, &context);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 3216|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3216:9): [True: 0, False: 0]
  ------------------
 3217|      0|        return SECFailure;
 3218|      0|    }
 3219|       |
 3220|      0|    ss->ssl3.hs.clientCertRequested = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3221|       |
 3222|      0|    if (ss->firstHsDone) {
  ------------------
  |  Branch (3222:9): [True: 0, False: 0]
  ------------------
 3223|       |
 3224|       |        /* Request a client certificate. */
 3225|      0|        rv = ssl3_BeginHandleCertificateRequest(
 3226|      0|            ss, ss->xtnData.sigSchemes, ss->xtnData.numSigSchemes,
 3227|      0|            &ss->xtnData.certReqAuthorities);
 3228|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3228:13): [True: 0, False: 0]
  ------------------
 3229|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3230|      0|            return rv;
 3231|      0|        }
 3232|      0|        rv = tls13_SendPostHandshakeCertificate(ss);
 3233|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3233:13): [True: 0, False: 0]
  ------------------
 3234|      0|            return rv; /* error code is set. */
 3235|      0|        }
 3236|      0|    } else {
 3237|      0|        TLS13_SET_HS_STATE(ss, wait_server_cert);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 3238|      0|    }
 3239|      0|    return SECSuccess;
 3240|      0|}
tls13con.c:tls13_SendCertificate:
 3799|  1.21k|{
 3800|  1.21k|    SECStatus rv;
 3801|  1.21k|    CERTCertificateList *certChain;
 3802|  1.21k|    int certChainLen = 0;
 3803|  1.21k|    int i;
 3804|  1.21k|    SECItem context = { siBuffer, NULL, 0 };
 3805|  1.21k|    sslBuffer extensionBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  1.21k|    {                        \
  |  |   24|  1.21k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  1.21k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  1.21k|    }
  ------------------
 3806|  1.21k|    sslBuffer bufferCertificate = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  1.21k|    {                        \
  |  |   24|  1.21k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  1.21k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  1.21k|    }
  ------------------
 3807|       |
 3808|  1.21k|    SSL_TRC(3, ("%d: TLS1.3[%d]: send certificate handshake",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  ------------------
 3809|  1.21k|                SSL_GETPID(), ss->fd));
 3810|       |
 3811|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3812|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3813|       |
 3814|  1.21k|    if (ss->sec.isServer) {
  ------------------
  |  Branch (3814:9): [True: 1.21k, False: 0]
  ------------------
 3815|  1.21k|        PORT_Assert(!ss->sec.localCert);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3816|       |        /* A server certificate is selected in tls13_SelectServerCert(). */
 3817|  1.21k|        PORT_Assert(ss->sec.serverCert);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3818|       |
 3819|  1.21k|        certChain = ss->sec.serverCert->serverCertChain;
 3820|  1.21k|        ss->sec.localCert = CERT_DupCertificate(ss->sec.serverCert->serverCert);
 3821|  1.21k|    } else {
 3822|      0|        if (ss->sec.localCert)
  ------------------
  |  Branch (3822:13): [True: 0, False: 0]
  ------------------
 3823|      0|            CERT_DestroyCertificate(ss->sec.localCert);
 3824|       |
 3825|      0|        certChain = ss->ssl3.clientCertChain;
 3826|      0|        ss->sec.localCert = CERT_DupCertificate(ss->ssl3.clientCertificate);
 3827|      0|    }
 3828|       |
 3829|  1.21k|    if (!ss->sec.isServer) {
  ------------------
  |  Branch (3829:9): [True: 0, False: 1.21k]
  ------------------
 3830|      0|        PORT_Assert(ss->ssl3.hs.clientCertRequested);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3831|      0|        context = ss->xtnData.certReqContext;
 3832|      0|    }
 3833|       |
 3834|  1.21k|    if (certChain) {
  ------------------
  |  Branch (3834:9): [True: 1.21k, False: 0]
  ------------------
 3835|  2.42k|        for (i = 0; i < certChain->len; i++) {
  ------------------
  |  Branch (3835:21): [True: 1.21k, False: 1.21k]
  ------------------
 3836|       |            /* Each cert is 3 octet length, cert, and extensions */
 3837|  1.21k|            certChainLen += 3 + certChain->certs[i].len + 2;
 3838|  1.21k|        }
 3839|       |
 3840|       |        /* Build the extensions. This only applies to the leaf cert, because we
 3841|       |         * don't yet send extensions for non-leaf certs. */
 3842|  1.21k|        rv = ssl_ConstructExtensions(ss, &extensionBuf, ssl_hs_certificate);
 3843|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3843:13): [True: 0, False: 1.21k]
  ------------------
 3844|      0|            return SECFailure; /* code already set */
 3845|      0|        }
 3846|       |        /* extensionBuf.len is only added once, for the leaf cert. */
 3847|  1.21k|        certChainLen += SSL_BUFFER_LEN(&extensionBuf);
  ------------------
  |  |   36|  1.21k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 3848|  1.21k|    }
 3849|       |
 3850|  1.21k|    rv = sslBuffer_AppendVariable(&bufferCertificate, context.data, context.len, 1);
 3851|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3851:9): [True: 0, False: 1.21k]
  ------------------
 3852|      0|        goto loser; /* Code already set. */
 3853|      0|    }
 3854|       |
 3855|  1.21k|    rv = sslBuffer_AppendNumber(&bufferCertificate, certChainLen, 3);
 3856|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3856:9): [True: 0, False: 1.21k]
  ------------------
 3857|      0|        goto loser; /* Code already set. */
 3858|      0|    }
 3859|       |
 3860|  1.21k|    if (certChain) {
  ------------------
  |  Branch (3860:9): [True: 1.21k, False: 0]
  ------------------
 3861|  2.42k|        for (i = 0; i < certChain->len; i++) {
  ------------------
  |  Branch (3861:21): [True: 1.21k, False: 1.21k]
  ------------------
 3862|  1.21k|            rv = sslBuffer_AppendVariable(&bufferCertificate, certChain->certs[i].data,
 3863|  1.21k|                                          certChain->certs[i].len, 3);
 3864|  1.21k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (3864:17): [True: 0, False: 1.21k]
  ------------------
 3865|      0|                goto loser; /* Code already set. */
 3866|      0|            }
 3867|       |
 3868|  1.21k|            if (i) {
  ------------------
  |  Branch (3868:17): [True: 0, False: 1.21k]
  ------------------
 3869|       |                /* Not end-entity. */
 3870|      0|                rv = sslBuffer_AppendNumber(&bufferCertificate, 0, 2);
 3871|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (3871:21): [True: 0, False: 0]
  ------------------
 3872|      0|                    goto loser; /* Code already set. */
 3873|      0|                }
 3874|      0|                continue;
 3875|      0|            }
 3876|       |
 3877|  1.21k|            rv = sslBuffer_AppendBufferVariable(&bufferCertificate, &extensionBuf, 2);
 3878|  1.21k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (3878:17): [True: 0, False: 1.21k]
  ------------------
 3879|      0|                goto loser; /* Code already set. */
 3880|      0|            }
 3881|  1.21k|        }
 3882|  1.21k|    }
 3883|       |
 3884|       |    /* If no compression mechanism was established or
 3885|       |     * the compression mechanism supports only decoding,
 3886|       |     * we continue as before. */
 3887|  1.21k|    if (ss->xtnData.compressionAlg == 0 || !tls13_FindCompressionAlgAndCheckIfSupportsEncoding(ss)) {
  ------------------
  |  Branch (3887:9): [True: 1.21k, False: 0]
  |  Branch (3887:44): [True: 0, False: 0]
  ------------------
 3888|  1.21k|        rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_certificate,
 3889|  1.21k|                                        1 + context.len + 3 + certChainLen);
 3890|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3890:13): [True: 0, False: 1.21k]
  ------------------
 3891|      0|            goto loser; /* err set by AppendHandshake. */
 3892|      0|        }
 3893|  1.21k|        rv = ssl3_AppendBufferToHandshake(ss, &bufferCertificate);
 3894|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3894:13): [True: 0, False: 1.21k]
  ------------------
 3895|      0|            goto loser; /* err set by AppendHandshake. */
 3896|      0|        }
 3897|  1.21k|    } else {
 3898|      0|        rv = tls13_SendCompressedCertificate(ss, &bufferCertificate);
 3899|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3899:13): [True: 0, False: 0]
  ------------------
 3900|      0|            goto loser; /* err set by tls13_SendCompressedCertificate. */
 3901|      0|        }
 3902|      0|    }
 3903|       |
 3904|  1.21k|    sslBuffer_Clear(&bufferCertificate);
 3905|  1.21k|    sslBuffer_Clear(&extensionBuf);
 3906|  1.21k|    return SECSuccess;
 3907|       |
 3908|      0|loser:
 3909|      0|    sslBuffer_Clear(&bufferCertificate);
 3910|      0|    sslBuffer_Clear(&extensionBuf);
 3911|      0|    return SECFailure;
 3912|  1.21k|}
tls13con.c:tls13_SendCertificateVerify:
 5152|  1.21k|{
 5153|  1.21k|    SECStatus rv = SECFailure;
 5154|  1.21k|    SECItem buf = { siBuffer, NULL, 0 };
 5155|  1.21k|    unsigned int len;
 5156|  1.21k|    SSLHashType hashAlg;
 5157|  1.21k|    SSL3Hashes hash;
 5158|  1.21k|    SSL3Hashes tbsHash; /* The hash "to be signed". */
 5159|       |
 5160|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5161|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5162|       |
 5163|  1.21k|    SSL_TRC(3, ("%d: TLS13[%d]: send certificate_verify handshake",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  ------------------
 5164|  1.21k|                SSL_GETPID(), ss->fd));
 5165|       |
 5166|  1.21k|    PORT_Assert(ss->ssl3.hs.hashType == handshake_hash_single);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5167|  1.21k|    rv = tls13_ComputeHandshakeHashes(ss, &hash);
 5168|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5168:9): [True: 0, False: 1.21k]
  ------------------
 5169|      0|        return SECFailure;
 5170|      0|    }
 5171|       |
 5172|       |    /* We should have picked a signature scheme when we received a
 5173|       |     * CertificateRequest, or when we picked a server certificate. */
 5174|  1.21k|    PORT_Assert(ss->ssl3.hs.signatureScheme != ssl_sig_none);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5175|  1.21k|    if (ss->ssl3.hs.signatureScheme == ssl_sig_none) {
  ------------------
  |  Branch (5175:9): [True: 0, False: 1.21k]
  ------------------
 5176|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5177|      0|        return SECFailure;
 5178|      0|    }
 5179|  1.21k|    hashAlg = ssl_SignatureSchemeToHashType(ss->ssl3.hs.signatureScheme);
 5180|  1.21k|    rv = tls13_AddContextToHashes(ss, &hash, hashAlg,
 5181|  1.21k|                                  PR_TRUE, &tbsHash);
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
 5182|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5182:9): [True: 0, False: 1.21k]
  ------------------
 5183|      0|        return SECFailure;
 5184|      0|    }
 5185|       |
 5186|  1.21k|    rv = ssl3_SignHashes(ss, &tbsHash, privKey, &buf);
 5187|  1.21k|    if (rv == SECSuccess && !ss->sec.isServer) {
  ------------------
  |  Branch (5187:9): [True: 1.21k, False: 0]
  |  Branch (5187:29): [True: 0, False: 1.21k]
  ------------------
 5188|       |        /* Remember the info about the slot that did the signing.
 5189|       |         * Later, when doing an SSL restart handshake, verify this.
 5190|       |         * These calls are mere accessors, and can't fail.
 5191|       |         */
 5192|      0|        PK11SlotInfo *slot;
 5193|      0|        sslSessionID *sid = ss->sec.ci.sid;
 5194|       |
 5195|      0|        slot = PK11_GetSlotFromPrivateKey(privKey);
 5196|      0|        sid->u.ssl3.clAuthSeries = PK11_GetSlotSeries(slot);
 5197|      0|        sid->u.ssl3.clAuthSlotID = PK11_GetSlotID(slot);
 5198|      0|        sid->u.ssl3.clAuthModuleID = PK11_GetModuleID(slot);
 5199|      0|        sid->u.ssl3.clAuthValid = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5200|      0|        PK11_FreeSlot(slot);
 5201|      0|    }
 5202|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5202:9): [True: 0, False: 1.21k]
  ------------------
 5203|      0|        goto done; /* err code was set by ssl3_SignHashes */
 5204|      0|    }
 5205|       |
 5206|  1.21k|    len = buf.len + 2 + 2;
 5207|       |
 5208|  1.21k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_certificate_verify, len);
 5209|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5209:9): [True: 0, False: 1.21k]
  ------------------
 5210|      0|        goto done; /* error code set by AppendHandshake */
 5211|      0|    }
 5212|       |
 5213|  1.21k|    rv = ssl3_AppendHandshakeNumber(ss, ss->ssl3.hs.signatureScheme, 2);
 5214|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5214:9): [True: 0, False: 1.21k]
  ------------------
 5215|      0|        goto done; /* err set by AppendHandshakeNumber */
 5216|      0|    }
 5217|       |
 5218|  1.21k|    rv = ssl3_AppendHandshakeVariable(ss, buf.data, buf.len, 2);
 5219|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5219:9): [True: 0, False: 1.21k]
  ------------------
 5220|      0|        goto done; /* error code set by AppendHandshake */
 5221|      0|    }
 5222|       |
 5223|  1.21k|done:
 5224|       |    /* For parity with the allocation functions, which don't use
 5225|       |     * SECITEM_AllocItem(). */
 5226|  1.21k|    if (buf.data)
  ------------------
  |  Branch (5226:9): [True: 1.21k, False: 0]
  ------------------
 5227|  1.21k|        PORT_Free(buf.data);
  ------------------
  |  |   60|  1.21k|#define PORT_Free PORT_Free_Util
  ------------------
 5228|  1.21k|    return rv;
 5229|  1.21k|}
tls13con.c:tls13_SendFinished:
 5596|  1.21k|{
 5597|  1.21k|    SECStatus rv;
 5598|  1.21k|    PRUint8 finishedBuf[TLS13_MAX_FINISHED_SIZE];
 5599|  1.21k|    unsigned int finishedLen;
 5600|  1.21k|    SSL3Hashes hashes;
 5601|       |
 5602|  1.21k|    SSL_TRC(3, ("%d: TLS13[%d]: send finished handshake", SSL_GETPID(), ss->fd));
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  ------------------
 5603|       |
 5604|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5605|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5606|       |
 5607|  1.21k|    rv = tls13_ComputeHandshakeHashes(ss, &hashes);
 5608|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5608:9): [True: 0, False: 1.21k]
  ------------------
 5609|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5610|      0|        return SECFailure;
 5611|      0|    }
 5612|       |
 5613|  1.21k|    ssl_GetSpecReadLock(ss);
  ------------------
  |  | 1422|  1.21k|    {                                           \
  |  | 1423|  1.21k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1423:13): [True: 588, False: 625]
  |  |  ------------------
  |  | 1424|  1.21k|            NSSRWLock_LockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   47|    588|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  |  |  ------------------
  |  | 1425|  1.21k|    }
  ------------------
 5614|  1.21k|    rv = tls13_ComputeFinished(ss, baseKey, tls13_GetHash(ss), &hashes, PR_TRUE,
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
 5615|  1.21k|                               finishedBuf, &finishedLen, sizeof(finishedBuf));
 5616|  1.21k|    ssl_ReleaseSpecReadLock(ss);
  ------------------
  |  | 1427|  1.21k|    {                                             \
  |  | 1428|  1.21k|        if (!ss->opt.noLocks)                     \
  |  |  ------------------
  |  |  |  Branch (1428:13): [True: 588, False: 625]
  |  |  ------------------
  |  | 1429|  1.21k|            NSSRWLock_UnlockRead((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   50|    588|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  |  |  ------------------
  |  | 1430|  1.21k|    }
  ------------------
 5617|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5617:9): [True: 0, False: 1.21k]
  ------------------
 5618|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5619|      0|        return SECFailure;
 5620|      0|    }
 5621|       |
 5622|  1.21k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_finished, finishedLen);
 5623|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5623:9): [True: 0, False: 1.21k]
  ------------------
 5624|      0|        return SECFailure; /* Error code already set. */
 5625|      0|    }
 5626|       |
 5627|  1.21k|    rv = ssl3_AppendHandshake(ss, finishedBuf, finishedLen);
 5628|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5628:9): [True: 0, False: 1.21k]
  ------------------
 5629|      0|        return SECFailure; /* Error code already set. */
 5630|      0|    }
 5631|       |
 5632|       |    /* TODO(ekr@rtfm.com): Record key log */
 5633|  1.21k|    return SECSuccess;
 5634|  1.21k|}
tls13con.c:tls13_SendServerHelloSequence:
 3321|  1.21k|{
 3322|  1.21k|    SECStatus rv;
 3323|  1.21k|    PRErrorCode err = 0;
 3324|       |
 3325|  1.21k|    SSL_TRC(3, ("%d: TLS13[%d]: begin send server_hello sequence",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  ------------------
 3326|  1.21k|                SSL_GETPID(), ss->fd));
 3327|       |
 3328|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3329|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3330|       |
 3331|  1.21k|    rv = ssl3_RegisterExtensionSender(ss, &ss->xtnData,
 3332|  1.21k|                                      ssl_tls13_supported_versions_xtn,
 3333|  1.21k|                                      tls13_ServerSendSupportedVersionsXtn);
 3334|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3334:9): [True: 0, False: 1.21k]
  ------------------
 3335|      0|        return SECFailure;
 3336|      0|    }
 3337|       |
 3338|  1.21k|    rv = tls13_ComputeHandshakeSecret(ss);
 3339|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3339:9): [True: 0, False: 1.21k]
  ------------------
 3340|      0|        return SECFailure; /* error code is set. */
 3341|      0|    }
 3342|       |
 3343|  1.21k|    rv = ssl3_SendServerHello(ss);
 3344|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3344:9): [True: 0, False: 1.21k]
  ------------------
 3345|      0|        return rv; /* err code is set. */
 3346|      0|    }
 3347|       |
 3348|  1.21k|    if (ss->ssl3.hs.fakeSid.len) {
  ------------------
  |  Branch (3348:9): [True: 413, False: 800]
  ------------------
 3349|    413|        PORT_Assert(!IS_DTLS(ss));
  ------------------
  |  |  120|    413|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    413|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 413, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3350|    413|        SECITEM_FreeItem(&ss->ssl3.hs.fakeSid, PR_FALSE);
  ------------------
  |  |  108|    413|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&ss->ssl3.hs.fakeSid, PR_FALSE);
  ------------------
  |  |  438|    413|#define PR_FALSE 0
  ------------------
 3351|    413|        if (!ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (3351:13): [True: 413, False: 0]
  ------------------
 3352|    413|            rv = ssl3_SendChangeCipherSpecsInt(ss);
 3353|    413|            if (rv != SECSuccess) {
  ------------------
  |  Branch (3353:17): [True: 0, False: 413]
  ------------------
 3354|      0|                return rv;
 3355|      0|            }
 3356|    413|        }
 3357|    413|    }
 3358|       |
 3359|  1.21k|    rv = tls13_SendEncryptedServerSequence(ss);
 3360|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3360:9): [True: 0, False: 1.21k]
  ------------------
 3361|      0|        err = PORT_GetError();
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
 3362|      0|    }
 3363|       |    /* Even if we get an error, since the ServerHello was successfully
 3364|       |     * serialized, we should give it a chance to reach the network.  This gives
 3365|       |     * the client a chance to perform the key exchange and decrypt the alert
 3366|       |     * we're about to send. */
 3367|  1.21k|    rv |= ssl3_FlushHandshake(ss, 0);
 3368|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3368:9): [True: 0, False: 1.21k]
  ------------------
 3369|      0|        if (err) {
  ------------------
  |  Branch (3369:13): [True: 0, False: 0]
  ------------------
 3370|      0|            PORT_SetError(err);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3371|      0|        }
 3372|      0|        return SECFailure;
 3373|      0|    }
 3374|       |
 3375|       |    /* Compute the rest of the secrets except for the resumption
 3376|       |     * and exporter secret. */
 3377|  1.21k|    rv = tls13_ComputeApplicationSecrets(ss);
 3378|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3378:9): [True: 0, False: 1.21k]
  ------------------
 3379|      0|        LOG_ERROR(ss, PORT_GetError());
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3380|      0|        return SECFailure;
 3381|      0|    }
 3382|       |
 3383|  1.21k|    rv = tls13_SetCipherSpec(ss, TrafficKeyApplicationData,
 3384|  1.21k|                             ssl_secret_write, PR_FALSE);
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
 3385|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3385:9): [True: 0, False: 1.21k]
  ------------------
 3386|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3387|      0|        return SECFailure;
 3388|      0|    }
 3389|       |
 3390|  1.21k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|  1.21k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 1.21k]
  |  |  ------------------
  ------------------
 3391|       |        /* We need this for reading ACKs. */
 3392|      0|        ssl_CipherSpecAddRef(ss->ssl3.crSpec);
 3393|      0|    }
 3394|  1.21k|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted) {
  ------------------
  |  Branch (3394:9): [True: 0, False: 1.21k]
  ------------------
 3395|      0|        rv = tls13_SetCipherSpec(ss, TrafficKeyEarlyApplicationData,
 3396|      0|                                 ssl_secret_read, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 3397|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3397:13): [True: 0, False: 0]
  ------------------
 3398|      0|            LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3399|      0|            return SECFailure;
 3400|      0|        }
 3401|      0|        TLS13_SET_HS_STATE(ss, wait_end_of_early_data);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 3402|  1.21k|    } else {
 3403|  1.21k|        PORT_Assert(ss->ssl3.hs.zeroRttState == ssl_0rtt_none ||
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.25k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1.17k, False: 40]
  |  |  |  |  |  Branch (208:7): [True: 40, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3404|  1.21k|                    ss->ssl3.hs.zeroRttState == ssl_0rtt_ignored);
 3405|       |
 3406|  1.21k|        rv = tls13_SetCipherSpec(ss,
 3407|  1.21k|                                 TrafficKeyHandshake,
 3408|  1.21k|                                 ssl_secret_read, PR_FALSE);
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
 3409|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3409:13): [True: 0, False: 1.21k]
  ------------------
 3410|      0|            LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3411|      0|            return SECFailure;
 3412|      0|        }
 3413|  1.21k|        if (tls13_ShouldRequestClientAuth(ss)) {
  ------------------
  |  Branch (3413:13): [True: 447, False: 766]
  ------------------
 3414|    447|            TLS13_SET_HS_STATE(ss, wait_client_cert);
  ------------------
  |  |   37|    447|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 3415|    766|        } else {
 3416|    766|            TLS13_SET_HS_STATE(ss, wait_finished);
  ------------------
  |  |   37|    766|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 3417|    766|        }
 3418|  1.21k|    }
 3419|       |
 3420|       |    /* Here we set a baseline value for our RTT estimation.
 3421|       |     * This value is updated when we get a response from the client. */
 3422|  1.21k|    ss->ssl3.hs.rttEstimate = ssl_Time(ss);
 3423|  1.21k|    return SECSuccess;
 3424|  1.21k|}
tls13con.c:tls13_SendEncryptedServerSequence:
 3253|  1.21k|{
 3254|  1.21k|    SECStatus rv;
 3255|       |
 3256|  1.21k|    rv = tls13_ComputeHandshakeSecrets(ss);
 3257|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3257:9): [True: 0, False: 1.21k]
  ------------------
 3258|      0|        return SECFailure; /* error code is set. */
 3259|      0|    }
 3260|       |
 3261|  1.21k|    rv = tls13_SetCipherSpec(ss, TrafficKeyHandshake,
 3262|  1.21k|                             ssl_secret_write, PR_FALSE);
  ------------------
  |  |  438|  1.21k|#define PR_FALSE 0
  ------------------
 3263|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3263:9): [True: 0, False: 1.21k]
  ------------------
 3264|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3265|      0|        return SECFailure;
 3266|      0|    }
 3267|       |
 3268|  1.21k|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted) {
  ------------------
  |  Branch (3268:9): [True: 0, False: 1.21k]
  ------------------
 3269|      0|        rv = ssl3_RegisterExtensionSender(ss, &ss->xtnData,
 3270|      0|                                          ssl_tls13_early_data_xtn,
 3271|      0|                                          ssl_SendEmptyExtension);
 3272|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3272:13): [True: 0, False: 0]
  ------------------
 3273|      0|            return SECFailure; /* Error code set already. */
 3274|      0|        }
 3275|      0|    }
 3276|       |
 3277|  1.21k|    rv = tls13_SendEncryptedExtensions(ss);
 3278|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3278:9): [True: 0, False: 1.21k]
  ------------------
 3279|      0|        return SECFailure; /* error code is set. */
 3280|      0|    }
 3281|       |
 3282|  1.21k|    if (tls13_ShouldRequestClientAuth(ss)) {
  ------------------
  |  Branch (3282:9): [True: 447, False: 766]
  ------------------
 3283|    447|        rv = tls13_SendCertificateRequest(ss);
 3284|    447|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3284:13): [True: 0, False: 447]
  ------------------
 3285|      0|            return SECFailure; /* error code is set. */
 3286|      0|        }
 3287|    447|    }
 3288|  1.21k|    if (ss->ssl3.hs.signatureScheme != ssl_sig_none) {
  ------------------
  |  Branch (3288:9): [True: 1.21k, False: 0]
  ------------------
 3289|  1.21k|        SECKEYPrivateKey *svrPrivKey;
 3290|       |
 3291|  1.21k|        rv = tls13_SendCertificate(ss);
 3292|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3292:13): [True: 0, False: 1.21k]
  ------------------
 3293|      0|            return SECFailure; /* error code is set. */
 3294|      0|        }
 3295|       |
 3296|  1.21k|        if (tls13_IsSigningWithDelegatedCredential(ss)) {
  ------------------
  |  Branch (3296:13): [True: 0, False: 1.21k]
  ------------------
 3297|      0|            SSL_TRC(3, ("%d: TLS13[%d]: Signing with delegated credential",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 3298|      0|                        SSL_GETPID(), ss->fd));
 3299|      0|            svrPrivKey = ss->sec.serverCert->delegCredKeyPair->privKey;
 3300|  1.21k|        } else {
 3301|  1.21k|            svrPrivKey = ss->sec.serverCert->serverKeyPair->privKey;
 3302|  1.21k|        }
 3303|       |
 3304|  1.21k|        rv = tls13_SendCertificateVerify(ss, svrPrivKey);
 3305|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3305:13): [True: 0, False: 1.21k]
  ------------------
 3306|      0|            return SECFailure; /* err code is set. */
 3307|      0|        }
 3308|  1.21k|    }
 3309|       |
 3310|  1.21k|    rv = tls13_SendFinished(ss, ss->ssl3.hs.serverHsTrafficSecret);
 3311|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3311:9): [True: 0, False: 1.21k]
  ------------------
 3312|      0|        return SECFailure; /* error code is set. */
 3313|      0|    }
 3314|       |
 3315|  1.21k|    return SECSuccess;
 3316|  1.21k|}
tls13con.c:tls13_SendEncryptedExtensions:
 5116|  1.21k|{
 5117|  1.21k|    sslBuffer extensions = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|  1.21k|    {                        \
  |  |   24|  1.21k|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|  1.21k|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|  1.21k|    }
  ------------------
 5118|  1.21k|    SECStatus rv;
 5119|       |
 5120|  1.21k|    SSL_TRC(3, ("%d: TLS13[%d]: send encrypted extensions handshake",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  ------------------
 5121|  1.21k|                SSL_GETPID(), ss->fd));
 5122|       |
 5123|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5124|  1.21k|    PORT_Assert(ss->opt.noLocks || ssl_HaveXmitBufLock(ss));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.80k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 625, False: 588]
  |  |  |  |  |  Branch (208:7): [True: 588, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5125|       |
 5126|  1.21k|    rv = ssl_ConstructExtensions(ss, &extensions, ssl_hs_encrypted_extensions);
 5127|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5127:9): [True: 0, False: 1.21k]
  ------------------
 5128|      0|        return SECFailure;
 5129|      0|    }
 5130|       |
 5131|  1.21k|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_encrypted_extensions,
 5132|  1.21k|                                    SSL_BUFFER_LEN(&extensions) + 2);
  ------------------
  |  |   36|  1.21k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
 5133|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5133:9): [True: 0, False: 1.21k]
  ------------------
 5134|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5135|      0|        goto loser;
 5136|      0|    }
 5137|  1.21k|    rv = ssl3_AppendBufferToHandshakeVariable(ss, &extensions, 2);
 5138|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5138:9): [True: 0, False: 1.21k]
  ------------------
 5139|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5140|      0|        goto loser;
 5141|      0|    }
 5142|  1.21k|    sslBuffer_Clear(&extensions);
 5143|  1.21k|    return SECSuccess;
 5144|       |
 5145|      0|loser:
 5146|      0|    sslBuffer_Clear(&extensions);
 5147|      0|    return SECFailure;
 5148|  1.21k|}
tls13con.c:tls13_ComputeApplicationSecrets:
 1661|  1.21k|{
 1662|  1.21k|    SECStatus rv;
 1663|       |
 1664|  1.21k|    rv = tls13_DeriveSecretWrap(ss, ss->ssl3.hs.currentSecret,
 1665|  1.21k|                                kHkdfLabelClient,
 1666|  1.21k|                                kHkdfLabelApplicationTrafficSecret,
 1667|  1.21k|                                keylogLabelClientTrafficSecret,
 1668|  1.21k|                                &ss->ssl3.hs.clientTrafficSecret);
 1669|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1669:9): [True: 0, False: 1.21k]
  ------------------
 1670|      0|        return SECFailure;
 1671|      0|    }
 1672|  1.21k|    rv = tls13_DeriveSecretWrap(ss, ss->ssl3.hs.currentSecret,
 1673|  1.21k|                                kHkdfLabelServer,
 1674|  1.21k|                                kHkdfLabelApplicationTrafficSecret,
 1675|  1.21k|                                keylogLabelServerTrafficSecret,
 1676|  1.21k|                                &ss->ssl3.hs.serverTrafficSecret);
 1677|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1677:9): [True: 0, False: 1.21k]
  ------------------
 1678|      0|        return SECFailure;
 1679|      0|    }
 1680|       |
 1681|  1.21k|    if (ss->secretCallback) {
  ------------------
  |  Branch (1681:9): [True: 0, False: 1.21k]
  ------------------
 1682|      0|        SSLSecretDirection dir =
 1683|      0|            ss->sec.isServer ? ssl_secret_read : ssl_secret_write;
  ------------------
  |  Branch (1683:13): [True: 0, False: 0]
  ------------------
 1684|      0|        ss->secretCallback(ss->fd, (PRUint16)TrafficKeyApplicationData,
 1685|      0|                           dir, ss->ssl3.hs.clientTrafficSecret,
 1686|      0|                           ss->secretCallbackArg);
 1687|      0|        dir = ss->sec.isServer ? ssl_secret_write : ssl_secret_read;
  ------------------
  |  Branch (1687:15): [True: 0, False: 0]
  ------------------
 1688|      0|        ss->secretCallback(ss->fd, (PRUint16)TrafficKeyApplicationData,
 1689|      0|                           dir, ss->ssl3.hs.serverTrafficSecret,
 1690|      0|                           ss->secretCallbackArg);
 1691|      0|    }
 1692|       |
 1693|  1.21k|    rv = tls13_DeriveSecretWrap(ss, ss->ssl3.hs.currentSecret,
 1694|  1.21k|                                NULL, kHkdfLabelExporterMasterSecret,
 1695|  1.21k|                                keylogLabelExporterSecret,
 1696|  1.21k|                                &ss->ssl3.hs.exporterSecret);
 1697|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1697:9): [True: 0, False: 1.21k]
  ------------------
 1698|      0|        return SECFailure;
 1699|      0|    }
 1700|       |
 1701|  1.21k|    return SECSuccess;
 1702|  1.21k|}
tls13con.c:tls13_ComputeHandshakeSecret:
 1543|  1.21k|{
 1544|  1.21k|    SECStatus rv;
 1545|  1.21k|    PK11SymKey *derivedSecret = NULL;
 1546|  1.21k|    PK11SymKey *newSecret = NULL;
 1547|  1.21k|    SSL_TRC(5, ("%d: TLS13[%d]: compute handshake secret (%s)",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1548|  1.21k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1549|       |
 1550|       |    /* If no PSK, generate the default early secret. */
 1551|  1.21k|    if (!ss->ssl3.hs.currentSecret) {
  ------------------
  |  Branch (1551:9): [True: 1.21k, False: 0]
  ------------------
 1552|  1.21k|        PORT_Assert(!ss->xtnData.selectedPsk);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1553|  1.21k|        rv = tls13_HkdfExtract(NULL, NULL,
 1554|  1.21k|                               tls13_GetHash(ss), &ss->ssl3.hs.currentSecret);
 1555|  1.21k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1555:13): [True: 0, False: 1.21k]
  ------------------
 1556|      0|            return SECFailure;
 1557|      0|        }
 1558|  1.21k|    }
 1559|  1.21k|    PORT_Assert(ss->ssl3.hs.currentSecret);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1560|  1.21k|    PORT_Assert(ss->ssl3.hs.dheSecret);
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1561|       |
 1562|       |    /* Derive-Secret(., "derived", "") */
 1563|  1.21k|    rv = tls13_DeriveSecretNullHash(ss, ss->ssl3.hs.currentSecret,
 1564|  1.21k|                                    kHkdfLabelDerivedSecret,
 1565|  1.21k|                                    strlen(kHkdfLabelDerivedSecret),
 1566|  1.21k|                                    &derivedSecret, tls13_GetHash(ss));
 1567|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1567:9): [True: 0, False: 1.21k]
  ------------------
 1568|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1569|      0|        return rv;
 1570|      0|    }
 1571|       |
 1572|       |    /* HKDF-Extract(ECDHE, .) = Handshake Secret */
 1573|  1.21k|    rv = tls13_HkdfExtract(derivedSecret, ss->ssl3.hs.dheSecret,
 1574|  1.21k|                           tls13_GetHash(ss), &newSecret);
 1575|  1.21k|    PK11_FreeSymKey(derivedSecret);
 1576|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1576:9): [True: 0, False: 1.21k]
  ------------------
 1577|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1578|      0|        return rv;
 1579|      0|    }
 1580|       |
 1581|  1.21k|    PK11_FreeSymKey(ss->ssl3.hs.currentSecret);
 1582|  1.21k|    ss->ssl3.hs.currentSecret = newSecret;
 1583|  1.21k|    return SECSuccess;
 1584|  1.21k|}
tls13con.c:tls13_ComputeHandshakeSecrets:
 1588|  1.21k|{
 1589|  1.21k|    SECStatus rv;
 1590|  1.21k|    PK11SymKey *derivedSecret = NULL;
 1591|  1.21k|    PK11SymKey *newSecret = NULL;
 1592|       |
 1593|  1.21k|    PK11_FreeSymKey(ss->ssl3.hs.dheSecret);
 1594|  1.21k|    ss->ssl3.hs.dheSecret = NULL;
 1595|       |
 1596|  1.21k|    SSL_TRC(5, ("%d: TLS13[%d]: compute handshake secrets (%s)",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1597|  1.21k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1598|       |
 1599|       |    /* Now compute |*HsTrafficSecret| */
 1600|  1.21k|    rv = tls13_DeriveSecretWrap(ss, ss->ssl3.hs.currentSecret,
 1601|  1.21k|                                kHkdfLabelClient,
 1602|  1.21k|                                kHkdfLabelHandshakeTrafficSecret,
 1603|  1.21k|                                keylogLabelClientHsTrafficSecret,
 1604|  1.21k|                                &ss->ssl3.hs.clientHsTrafficSecret);
 1605|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1605:9): [True: 0, False: 1.21k]
  ------------------
 1606|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1607|      0|        return rv;
 1608|      0|    }
 1609|  1.21k|    rv = tls13_DeriveSecretWrap(ss, ss->ssl3.hs.currentSecret,
 1610|  1.21k|                                kHkdfLabelServer,
 1611|  1.21k|                                kHkdfLabelHandshakeTrafficSecret,
 1612|  1.21k|                                keylogLabelServerHsTrafficSecret,
 1613|  1.21k|                                &ss->ssl3.hs.serverHsTrafficSecret);
 1614|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1614:9): [True: 0, False: 1.21k]
  ------------------
 1615|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1616|      0|        return rv;
 1617|      0|    }
 1618|       |
 1619|  1.21k|    if (ss->secretCallback) {
  ------------------
  |  Branch (1619:9): [True: 0, False: 1.21k]
  ------------------
 1620|      0|        SSLSecretDirection dir =
 1621|      0|            ss->sec.isServer ? ssl_secret_read : ssl_secret_write;
  ------------------
  |  Branch (1621:13): [True: 0, False: 0]
  ------------------
 1622|      0|        ss->secretCallback(ss->fd, (PRUint16)TrafficKeyHandshake, dir,
 1623|      0|                           ss->ssl3.hs.clientHsTrafficSecret,
 1624|      0|                           ss->secretCallbackArg);
 1625|      0|        dir = ss->sec.isServer ? ssl_secret_write : ssl_secret_read;
  ------------------
  |  Branch (1625:15): [True: 0, False: 0]
  ------------------
 1626|      0|        ss->secretCallback(ss->fd, (PRUint16)TrafficKeyHandshake, dir,
 1627|      0|                           ss->ssl3.hs.serverHsTrafficSecret,
 1628|      0|                           ss->secretCallbackArg);
 1629|      0|    }
 1630|       |
 1631|  1.21k|    SSL_TRC(5, ("%d: TLS13[%d]: compute master secret (%s)",
  ------------------
  |  |   71|  1.21k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.21k]
  |  |  ------------------
  |  |   72|  1.21k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1632|  1.21k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1633|       |
 1634|       |    /* Crank HKDF forward to make master secret, which we
 1635|       |     * stuff in current secret. */
 1636|  1.21k|    rv = tls13_DeriveSecretNullHash(ss, ss->ssl3.hs.currentSecret,
 1637|  1.21k|                                    kHkdfLabelDerivedSecret,
 1638|  1.21k|                                    strlen(kHkdfLabelDerivedSecret),
 1639|  1.21k|                                    &derivedSecret, tls13_GetHash(ss));
 1640|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1640:9): [True: 0, False: 1.21k]
  ------------------
 1641|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1642|      0|        return rv;
 1643|      0|    }
 1644|  1.21k|    rv = tls13_HkdfExtract(derivedSecret,
 1645|  1.21k|                           NULL,
 1646|  1.21k|                           tls13_GetHash(ss),
 1647|  1.21k|                           &newSecret);
 1648|  1.21k|    PK11_FreeSymKey(derivedSecret);
 1649|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1649:9): [True: 0, False: 1.21k]
  ------------------
 1650|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 1651|      0|        return SECFailure;
 1652|      0|    }
 1653|  1.21k|    PK11_FreeSymKey(ss->ssl3.hs.currentSecret);
 1654|  1.21k|    ss->ssl3.hs.currentSecret = newSecret;
 1655|       |
 1656|  1.21k|    return SECSuccess;
 1657|  1.21k|}
tls13con.c:tls13_HandleCertificateDecode:
 3985|     17|{
 3986|     17|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|     17|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     26|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 8, False: 9]
  |  |  |  |  |  Branch (208:7): [True: 9, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3987|     17|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|     17|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     26|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 8, False: 9]
  |  |  |  |  |  Branch (208:7): [True: 9, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3988|       |
 3989|     17|    SECStatus rv = SECFailure;
 3990|       |
 3991|     17|    if (!ss->xtnData.certificateCompressionAdvertised) {
  ------------------
  |  Branch (3991:9): [True: 4, False: 13]
  ------------------
 3992|      4|        FATAL_ERROR(ss, SEC_ERROR_UNEXPECTED_COMPRESSED_CERTIFICATE, decode_error);
  ------------------
  |  |   22|      4|    do {                                     \
  |  |   23|      4|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      4|    do {                                                                           \
  |  |  |  |   15|      4|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      4|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 4]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      4|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      4|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      4|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      4|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      4|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      4|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      4|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 3993|      4|        return SECFailure;
 3994|      4|    }
 3995|       |
 3996|     13|    rv = tls13_EnsureCerticateExpected(ss);
 3997|     13|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3997:9): [True: 1, False: 12]
  ------------------
 3998|      1|        return SECFailure; /* Code already set. */
 3999|      1|    }
 4000|       |
 4001|     12|    if (ss->firstHsDone) {
  ------------------
  |  Branch (4001:9): [True: 0, False: 12]
  ------------------
 4002|      0|        rv = ssl_HashPostHandshakeMessage(ss, ssl_hs_compressed_certificate, b, length);
 4003|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4003:13): [True: 0, False: 0]
  ------------------
 4004|      0|            return rv;
 4005|      0|        }
 4006|      0|    }
 4007|       |
 4008|     12|    SSL_TRC(30, ("%d: TLS1.3[%d]: %s handles certificate compression handshake",
  ------------------
  |  |   71|     12|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 12]
  |  |  ------------------
  |  |   72|     12|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4009|     12|                 SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 4010|       |
 4011|     12|    PRINT_BUF(50, (NULL, "The certificate before decoding:", b, length));
  ------------------
  |  |   74|     12|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 12]
  |  |  ------------------
  |  |   75|     12|    ssl_PrintBuf b
  ------------------
 4012|       |    /* Reading CertificateCompressionAlgorithm. */
 4013|     12|    PRUint32 compressionAlg = 0;
 4014|     12|    rv = ssl3_ConsumeHandshakeNumber(ss, &compressionAlg, 2, &b, &length);
 4015|     12|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4015:9): [True: 1, False: 11]
  ------------------
 4016|      1|        return SECFailure; /* Alert already sent. */
 4017|      1|    }
 4018|       |
 4019|     11|    PRBool compressionAlgorithmIsSupported = PR_FALSE;
  ------------------
  |  |  438|     11|#define PR_FALSE 0
  ------------------
 4020|     11|    SECStatus (*certificateDecodingFunc)(const SECItem *,
 4021|     11|                                         unsigned char *output, size_t outputLen, size_t *usedLen) = NULL;
 4022|     22|    for (int i = 0; i < ss->ssl3.supportedCertCompressionAlgorithmsCount; i++) {
  ------------------
  |  Branch (4022:21): [True: 11, False: 11]
  ------------------
 4023|     11|        if (ss->ssl3.supportedCertCompressionAlgorithms[i].id == compressionAlg) {
  ------------------
  |  Branch (4023:13): [True: 0, False: 11]
  ------------------
 4024|      0|            compressionAlgorithmIsSupported = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 4025|      0|            certificateDecodingFunc = ss->ssl3.supportedCertCompressionAlgorithms[i].decode;
 4026|      0|        }
 4027|     11|    }
 4028|       |
 4029|       |    /* Peer selected a compression algorithm we do not support (and did not advertise). */
 4030|     11|    if (!compressionAlgorithmIsSupported) {
  ------------------
  |  Branch (4030:9): [True: 11, False: 0]
  ------------------
 4031|     11|        PORT_SetError(SEC_ERROR_CERTIFICATE_COMPRESSION_ALGORITHM_NOT_SUPPORTED);
  ------------------
  |  |   65|     11|#define PORT_SetError PORT_SetError_Util
  ------------------
 4032|     11|        FATAL_ERROR(ss, PORT_GetError(), illegal_parameter);
  ------------------
  |  |   22|     11|    do {                                     \
  |  |   23|     11|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     11|    do {                                                                           \
  |  |  |  |   15|     11|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     11|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 11]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     11|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     11|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     11|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     11|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     11|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     11|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     11|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4033|     11|        return SECFailure;
 4034|     11|    }
 4035|       |
 4036|       |    /* The algorithm does not support decoding. */
 4037|      0|    if (certificateDecodingFunc == NULL) {
  ------------------
  |  Branch (4037:9): [True: 0, False: 0]
  ------------------
 4038|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4039|      0|        FATAL_ERROR(ss, PORT_GetError(), illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4040|      0|        return SECFailure;
 4041|      0|    }
 4042|       |
 4043|      0|    SSL_TRC(30, ("%d: TLS13[%d]: %s is decoding the certificate using the %s compression algorithm",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4044|      0|                 SSL_GETPID(), ss->fd, SSL_ROLE(ss),
 4045|      0|                 ssl3_mapCertificateCompressionAlgorithmToName(ss, compressionAlg)));
 4046|      0|    PRUint32 decodedCertLen = 0;
 4047|      0|    rv = ssl3_ConsumeHandshakeNumber(ss, &decodedCertLen, 3, &b, &length);
 4048|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4048:9): [True: 0, False: 0]
  ------------------
 4049|      0|        return SECFailure; /* alert has been sent */
 4050|      0|    }
 4051|       |
 4052|       |    /*  If the received CompressedCertificate message cannot be decompressed,
 4053|       |     *  he connection MUST be terminated with the "bad_certificate" alert.
 4054|       |     */
 4055|      0|    if (decodedCertLen == 0) {
  ------------------
  |  Branch (4055:9): [True: 0, False: 0]
  ------------------
 4056|      0|        SSL_TRC(50, ("%d: TLS13[%d]: %s decoded certificate length is incorrect",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4057|      0|                     SSL_GETPID(), ss->fd, SSL_ROLE(ss),
 4058|      0|                     ssl3_mapCertificateCompressionAlgorithmToName(ss, compressionAlg)));
 4059|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, bad_certificate);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4060|      0|        return SECFailure;
 4061|      0|    }
 4062|       |
 4063|       |    /* opaque compressed_certificate_message<1..2^24-1>; */
 4064|      0|    PRUint32 compressedCertLen = 0;
 4065|      0|    rv = ssl3_ConsumeHandshakeNumber(ss, &compressedCertLen, 3, &b, &length);
 4066|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4066:9): [True: 0, False: 0]
  ------------------
 4067|      0|        return SECFailure; /* alert has been sent */
 4068|      0|    }
 4069|       |
 4070|      0|    if (compressedCertLen == 0 || compressedCertLen != length) {
  ------------------
  |  Branch (4070:9): [True: 0, False: 0]
  |  Branch (4070:35): [True: 0, False: 0]
  ------------------
 4071|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, bad_certificate);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4072|      0|        return SECFailure;
 4073|      0|    }
 4074|       |
 4075|       |    /* Decoding received certificate. */
 4076|      0|    PRUint8 *decodedCert = PORT_ZAlloc(decodedCertLen);
  ------------------
  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
 4077|      0|    if (!decodedCert) {
  ------------------
  |  Branch (4077:9): [True: 0, False: 0]
  ------------------
 4078|      0|        return SECFailure;
 4079|      0|    }
 4080|       |
 4081|      0|    size_t actualCertLen = 0;
 4082|       |
 4083|      0|    SECItem encodedCertAsSecItem = { siBuffer, b, compressedCertLen };
 4084|      0|    rv = certificateDecodingFunc(&encodedCertAsSecItem,
 4085|      0|                                 decodedCert, decodedCertLen, &actualCertLen);
 4086|       |
 4087|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4087:9): [True: 0, False: 0]
  ------------------
 4088|      0|        SSL_TRC(50, ("%d: TLS13[%d]: %s decoding of the certificate has failed",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4089|      0|                     SSL_GETPID(), ss->fd, SSL_ROLE(ss),
 4090|      0|                     ssl3_mapCertificateCompressionAlgorithmToName(ss, compressionAlg)));
 4091|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, bad_certificate);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4092|      0|        goto loser;
 4093|      0|    }
 4094|      0|    PRINT_BUF(60, (ss, "consume bytes:", b, compressedCertLen));
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4095|      0|    *b += compressedCertLen;
 4096|      0|    length -= compressedCertLen;
 4097|       |
 4098|       |    /*  If, after decompression, the specified length does not match the actual length,
 4099|       |     *  the party receiving the invalid message MUST abort the connection
 4100|       |     *  with the "bad_certificate" alert.
 4101|       |     */
 4102|      0|    if (actualCertLen != decodedCertLen) {
  ------------------
  |  Branch (4102:9): [True: 0, False: 0]
  ------------------
 4103|      0|        SSL_TRC(50, ("%d: TLS13[%d]: %s certificate length does not correspond to extension length",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4104|      0|                     SSL_GETPID(), ss->fd, SSL_ROLE(ss),
 4105|      0|                     ssl3_mapCertificateCompressionAlgorithmToName(ss, compressionAlg)));
 4106|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, bad_certificate);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4107|      0|        goto loser;
 4108|      0|    }
 4109|       |
 4110|      0|    PRINT_BUF(50, (NULL, "Decoded certificate",
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 4111|      0|                   decodedCert, decodedCertLen));
 4112|       |
 4113|       |    /* compressed_certificate_message:  The result of applying the indicated
 4114|       |     * compression algorithm to the encoded Certificate message that
 4115|       |     *  would have been sent if certificate compression was not in use.
 4116|       |     *
 4117|       |     * After decompression, the Certificate message MUST be processed as if
 4118|       |     * it were encoded without being compressed.  This way, the parsing and
 4119|       |     * the verification have the same security properties as they would have
 4120|       |     * in TLS normally.
 4121|       |     */
 4122|      0|    rv = tls13_HandleCertificate(ss, decodedCert, decodedCertLen, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 4123|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4123:9): [True: 0, False: 0]
  ------------------
 4124|      0|        goto loser;
 4125|      0|    }
 4126|       |    /* We allow only one compressed certificate to be handled after each
 4127|       |       certificate compression advertisement.
 4128|       |       See test CertificateCompression_TwoEncodedCertificateRequests. */
 4129|      0|    ss->xtnData.certificateCompressionAdvertised = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4130|      0|    PORT_Free(decodedCert);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 4131|      0|    return SECSuccess;
 4132|       |
 4133|      0|loser:
 4134|      0|    PORT_Free(decodedCert);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 4135|      0|    return SECFailure;
 4136|      0|}
tls13con.c:tls13_EnsureCerticateExpected:
 3949|     66|{
 3950|     66|    SECStatus rv = SECFailure;
 3951|     66|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|     66|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     98|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 34, False: 32]
  |  |  |  |  |  Branch (208:7): [True: 32, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3952|     66|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|     66|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     98|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 34, False: 32]
  |  |  |  |  |  Branch (208:7): [True: 32, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 3953|       |
 3954|     66|    if (ss->sec.isServer) {
  ------------------
  |  Branch (3954:9): [True: 66, False: 0]
  ------------------
 3955|       |        /* Receiving this message might be the first sign we have that
 3956|       |         * early data is over, so pretend we received EOED. */
 3957|     66|        rv = tls13_MaybeHandleSuppressedEndOfEarlyData(ss);
 3958|     66|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3958:13): [True: 0, False: 66]
  ------------------
 3959|      0|            return SECFailure; /* Code already set. */
 3960|      0|        }
 3961|       |
 3962|     66|        if (ss->ssl3.clientCertRequested) {
  ------------------
  |  Branch (3962:13): [True: 0, False: 66]
  ------------------
 3963|      0|            rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_CERTIFICATE,
  ------------------
  |  |  182|      0|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      0|                       __VA_ARGS__,                                 \
  |  |  184|      0|                       wait_invalid)
  ------------------
 3964|      0|                                      idle_handshake);
 3965|     66|        } else {
 3966|     66|            rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_CERTIFICATE,
  ------------------
  |  |  182|     66|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|     66|                       __VA_ARGS__,                                 \
  |  |  184|     66|                       wait_invalid)
  ------------------
 3967|     66|                                      wait_client_cert);
 3968|     66|        }
 3969|     66|    } else {
 3970|      0|        rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_CERTIFICATE,
  ------------------
  |  |  182|      0|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      0|                       __VA_ARGS__,                                 \
  |  |  184|      0|                       wait_invalid)
  ------------------
 3971|      0|                                  wait_cert_request, wait_server_cert);
 3972|      0|    }
 3973|     66|    return rv;
 3974|     66|}
tls13con.c:tls13_MaybeHandleSuppressedEndOfEarlyData:
 7044|    486|{
 7045|    486|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|    486|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    486|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 486, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7046|    486|    if (!ss->opt.suppressEndOfEarlyData ||
  ------------------
  |  Branch (7046:9): [True: 486, False: 0]
  ------------------
 7047|    486|        ss->ssl3.hs.zeroRttState != ssl_0rtt_accepted) {
  ------------------
  |  Branch (7047:9): [True: 0, False: 0]
  ------------------
 7048|    486|        return SECSuccess;
 7049|    486|    }
 7050|       |
 7051|      0|    return tls13_HandleEndOfEarlyData(ss, NULL, 0);
 7052|    486|}
tls13con.c:tls13_HandleCertificate:
 4144|     53|{
 4145|     53|    SECStatus rv;
 4146|     53|    SECItem context = { siBuffer, NULL, 0 };
 4147|     53|    SECItem certList;
 4148|     53|    PRBool first = PR_TRUE;
  ------------------
  |  |  437|     53|#define PR_TRUE 1
  ------------------
 4149|     53|    ssl3CertNode *lastCert = NULL;
 4150|       |
 4151|     53|    SSL_TRC(3, ("%d: TLS13[%d]: handle certificate handshake",
  ------------------
  |  |   71|     53|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 53]
  |  |  ------------------
  |  |   72|     53|    ssl_Trace b
  ------------------
 4152|     53|                SSL_GETPID(), ss->fd));
 4153|     53|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|     53|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     79|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27, False: 26]
  |  |  |  |  |  Branch (208:7): [True: 26, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4154|     53|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|     53|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     79|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27, False: 26]
  |  |  |  |  |  Branch (208:7): [True: 26, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4155|       |
 4156|     53|    rv = tls13_EnsureCerticateExpected(ss);
 4157|     53|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4157:9): [True: 7, False: 46]
  ------------------
 4158|      7|        return SECFailure; /* Code already set. */
 4159|      7|    }
 4160|       |
 4161|       |    /* We can ignore any other cleartext from the client. */
 4162|     46|    if (ss->sec.isServer && IS_DTLS(ss)) {
  ------------------
  |  |  892|     46|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 46]
  |  |  ------------------
  ------------------
  |  Branch (4162:9): [True: 46, False: 0]
  ------------------
 4163|      0|        ssl_CipherSpecReleaseByEpoch(ss, ssl_secret_read, TrafficKeyClearText);
 4164|      0|        dtls_ReceivedFirstMessageInFlight(ss);
 4165|      0|    }
 4166|       |
 4167|       |    /* AlreadyHashed is true only when Certificate Compression is used. */
 4168|     46|    if (ss->firstHsDone && !alreadyHashed) {
  ------------------
  |  Branch (4168:9): [True: 0, False: 46]
  |  Branch (4168:28): [True: 0, False: 0]
  ------------------
 4169|      0|        rv = ssl_HashPostHandshakeMessage(ss, ssl_hs_certificate, b, length);
 4170|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4170:13): [True: 0, False: 0]
  ------------------
 4171|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 4172|      0|            return SECFailure;
 4173|      0|        }
 4174|      0|    }
 4175|       |
 4176|     46|    if (!ss->firstHsDone && ss->sec.isServer) {
  ------------------
  |  Branch (4176:9): [True: 46, False: 0]
  |  Branch (4176:29): [True: 46, False: 0]
  ------------------
 4177|       |        /* Our first shot an getting an RTT estimate.  If the client took extra
 4178|       |         * time to fetch a certificate, this will be bad, but we can't do much
 4179|       |         * about that. */
 4180|     46|        ss->ssl3.hs.rttEstimate = ssl_Time(ss) - ss->ssl3.hs.rttEstimate;
 4181|     46|    }
 4182|       |
 4183|       |    /* Process the context string */
 4184|     46|    rv = ssl3_ConsumeHandshakeVariable(ss, &context, 1, &b, &length);
 4185|     46|    if (rv != SECSuccess)
  ------------------
  |  Branch (4185:9): [True: 1, False: 45]
  ------------------
 4186|      1|        return SECFailure;
 4187|       |
 4188|     45|    if (ss->ssl3.clientCertRequested) {
  ------------------
  |  Branch (4188:9): [True: 0, False: 45]
  ------------------
 4189|      0|        PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4190|      0|        if (SECITEM_CompareItem(&context, &ss->xtnData.certReqContext) != 0) {
  ------------------
  |  |  105|      0|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (4190:13): [True: 0, False: 0]
  ------------------
 4191|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4192|      0|            return SECFailure;
 4193|      0|        }
 4194|      0|    }
 4195|     45|    rv = ssl3_ConsumeHandshakeVariable(ss, &certList, 3, &b, &length);
 4196|     45|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4196:9): [True: 15, False: 30]
  ------------------
 4197|     15|        return SECFailure;
 4198|     15|    }
 4199|     30|    if (length) {
  ------------------
  |  Branch (4199:9): [True: 14, False: 16]
  ------------------
 4200|     14|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, illegal_parameter);
  ------------------
  |  |   22|     14|    do {                                     \
  |  |   23|     14|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     14|    do {                                                                           \
  |  |  |  |   15|     14|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     14|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 14]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     14|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     14|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     14|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     14|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     14|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     14|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     14|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4201|     14|        return SECFailure;
 4202|     14|    }
 4203|       |
 4204|     16|    if (!certList.len) {
  ------------------
  |  Branch (4204:9): [True: 9, False: 7]
  ------------------
 4205|      9|        if (!ss->sec.isServer) {
  ------------------
  |  Branch (4205:13): [True: 0, False: 9]
  ------------------
 4206|       |            /* Servers always need to send some cert. */
 4207|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERTIFICATE, bad_certificate);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4208|      0|            return SECFailure;
 4209|      9|        } else {
 4210|       |            /* This is TLS's version of a no_certificate alert. */
 4211|       |            /* I'm a server. I've requested a client cert. He hasn't got one. */
 4212|      9|            rv = ssl3_HandleNoCertificate(ss);
 4213|      9|            if (rv != SECSuccess) {
  ------------------
  |  Branch (4213:17): [True: 2, False: 7]
  ------------------
 4214|      2|                return SECFailure;
 4215|      2|            }
 4216|       |
 4217|      7|            TLS13_SET_HS_STATE(ss, wait_finished);
  ------------------
  |  |   37|      7|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 4218|      7|            return SECSuccess;
 4219|      9|        }
 4220|      9|    }
 4221|       |
 4222|       |    /* Now clean up. */
 4223|      7|    ssl3_CleanupPeerCerts(ss);
 4224|      7|    ss->ssl3.peerCertArena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|      7|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  ss->ssl3.peerCertArena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|      7|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
 4225|      7|    if (ss->ssl3.peerCertArena == NULL) {
  ------------------
  |  Branch (4225:9): [True: 0, False: 7]
  ------------------
 4226|      0|        FATAL_ERROR(ss, SEC_ERROR_NO_MEMORY, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4227|      0|        return SECFailure;
 4228|      0|    }
 4229|       |
 4230|      7|    while (certList.len) {
  ------------------
  |  Branch (4230:12): [True: 7, False: 0]
  ------------------
 4231|      7|        SECItem derCert; // will hold a weak reference into certList
 4232|      7|        rv = tls13_HandleCertificateEntry(ss, &certList, first,
 4233|      7|                                          &derCert);
 4234|      7|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4234:13): [True: 3, False: 4]
  ------------------
 4235|      3|            ss->xtnData.signedCertTimestamps.len = 0;
 4236|      3|            return SECFailure;
 4237|      3|        }
 4238|       |
 4239|      4|        if (first) {
  ------------------
  |  Branch (4239:13): [True: 4, False: 0]
  ------------------
 4240|      4|            ss->sec.peerCert = CERT_NewTempCertificate(ss->dbHandle, &derCert,
 4241|      4|                                                       NULL, PR_FALSE, PR_TRUE);
  ------------------
  |  |  438|      4|#define PR_FALSE 0
  ------------------
                                                                     NULL, PR_FALSE, PR_TRUE);
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
 4242|      4|            if (!ss->sec.peerCert) {
  ------------------
  |  Branch (4242:17): [True: 4, False: 0]
  ------------------
 4243|      4|                PRErrorCode errCode = PORT_GetError();
  ------------------
  |  |   62|      4|#define PORT_GetError PORT_GetError_Util
  ------------------
 4244|      4|                switch (errCode) {
 4245|      0|                    case PR_OUT_OF_MEMORY_ERROR:
  ------------------
  |  |   16|      0|#define PR_OUT_OF_MEMORY_ERROR                   (-6000L)
  ------------------
  |  Branch (4245:21): [True: 0, False: 4]
  ------------------
 4246|      0|                    case SEC_ERROR_BAD_DATABASE:
  ------------------
  |  Branch (4246:21): [True: 0, False: 4]
  ------------------
 4247|      0|                    case SEC_ERROR_NO_MEMORY:
  ------------------
  |  Branch (4247:21): [True: 0, False: 4]
  ------------------
 4248|      0|                        FATAL_ERROR(ss, errCode, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4249|      0|                        return SECFailure;
 4250|      4|                    default:
  ------------------
  |  Branch (4250:21): [True: 4, False: 0]
  ------------------
 4251|      4|                        ssl3_SendAlertForCertError(ss, errCode);
 4252|      4|                        return SECFailure;
 4253|      4|                }
 4254|      4|            }
 4255|       |
 4256|      0|            if (ss->xtnData.signedCertTimestamps.len) {
  ------------------
  |  Branch (4256:17): [True: 0, False: 0]
  ------------------
 4257|      0|                sslSessionID *sid = ss->sec.ci.sid;
 4258|      0|                rv = SECITEM_CopyItem(NULL, &sid->u.ssl3.signedCertTimestamps,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 4259|      0|                                      &ss->xtnData.signedCertTimestamps);
 4260|      0|                ss->xtnData.signedCertTimestamps.len = 0;
 4261|      0|                if (rv != SECSuccess) {
  ------------------
  |  Branch (4261:21): [True: 0, False: 0]
  ------------------
 4262|      0|                    FATAL_ERROR(ss, SEC_ERROR_NO_MEMORY, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4263|      0|                    return SECFailure;
 4264|      0|                }
 4265|      0|            }
 4266|      0|        } else {
 4267|      0|            ssl3CertNode *c = PORT_ArenaNew(ss->ssl3.peerCertArena,
  ------------------
  |  |  153|      0|    (type *)PORT_ArenaAlloc(poolp, sizeof(type))
  |  |  ------------------
  |  |  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  |  |  ------------------
  ------------------
 4268|      0|                                            ssl3CertNode);
 4269|      0|            if (!c) {
  ------------------
  |  Branch (4269:17): [True: 0, False: 0]
  ------------------
 4270|      0|                FATAL_ERROR(ss, SEC_ERROR_NO_MEMORY, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4271|      0|                return SECFailure;
 4272|      0|            }
 4273|      0|            c->derCert = SECITEM_ArenaDupItem(ss->ssl3.peerCertArena,
  ------------------
  |  |  104|      0|#define SECITEM_ArenaDupItem SECITEM_ArenaDupItem_Util
  ------------------
 4274|      0|                                              &derCert);
 4275|      0|            c->next = NULL;
 4276|       |
 4277|      0|            if (lastCert) {
  ------------------
  |  Branch (4277:17): [True: 0, False: 0]
  ------------------
 4278|      0|                lastCert->next = c;
 4279|      0|            } else {
 4280|      0|                ss->ssl3.peerCertChain = c;
 4281|      0|            }
 4282|      0|            lastCert = c;
 4283|      0|        }
 4284|       |
 4285|      0|        first = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 4286|      0|    }
 4287|      0|    SECKEY_UpdateCertPQG(ss->sec.peerCert);
 4288|       |
 4289|      0|    return ssl3_AuthCertificate(ss); /* sets ss->ssl3.hs.ws */
 4290|      7|}
tls13con.c:tls13_HandleCertificateEntry:
 3917|      7|{
 3918|      7|    SECStatus rv;
 3919|      7|    SECItem extensionsData;
 3920|       |
 3921|      7|    rv = ssl3_ConsumeHandshakeVariable(ss, certData,
 3922|      7|                                       3, &data->data, &data->len);
 3923|      7|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3923:9): [True: 2, False: 5]
  ------------------
 3924|      2|        return SECFailure;
 3925|      2|    }
 3926|       |
 3927|      5|    rv = ssl3_ConsumeHandshakeVariable(ss, &extensionsData,
 3928|      5|                                       2, &data->data, &data->len);
 3929|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (3929:9): [True: 1, False: 4]
  ------------------
 3930|      1|        return SECFailure;
 3931|      1|    }
 3932|       |
 3933|       |    /* Parse all the extensions. */
 3934|      4|    if (first && !ss->sec.isServer) {
  ------------------
  |  Branch (3934:9): [True: 4, False: 0]
  |  Branch (3934:18): [True: 0, False: 4]
  ------------------
 3935|      0|        rv = ssl3_HandleExtensions(ss, &extensionsData.data,
 3936|      0|                                   &extensionsData.len,
 3937|      0|                                   ssl_hs_certificate);
 3938|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (3938:13): [True: 0, False: 0]
  ------------------
 3939|      0|            return SECFailure;
 3940|      0|        }
 3941|       |        /* TODO(ekr@rtfm.com): Copy out SCTs. Bug 1315727. */
 3942|      0|    }
 3943|       |
 3944|      4|    return SECSuccess;
 3945|      4|}
tls13con.c:tls13_SetCipherSpec:
 4696|   278k|{
 4697|   278k|    TrafficKeyType type;
 4698|   278k|    SECStatus rv;
 4699|   278k|    ssl3CipherSpec *spec = NULL;
 4700|   278k|    ssl3CipherSpec **specp;
 4701|       |
 4702|       |    /* Flush out old handshake data. */
 4703|   278k|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|   278k|    {                                           \
  |  | 1467|   278k|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 135k, False: 143k]
  |  |  ------------------
  |  | 1468|   278k|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|   135k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|   278k|    }
  ------------------
 4704|   278k|    rv = ssl3_FlushHandshake(ss, ssl_SEND_FLAG_FORCE_INTO_BUFFER);
  ------------------
  |  |  223|   278k|#define ssl_SEND_FLAG_FORCE_INTO_BUFFER 0x40000000
  ------------------
 4705|   278k|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|   278k|    {                                          \
  |  | 1472|   278k|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 135k, False: 143k]
  |  |  ------------------
  |  | 1473|   278k|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|   135k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|   278k|    }
  ------------------
 4706|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4706:9): [True: 0, False: 278k]
  ------------------
 4707|      0|        return SECFailure;
 4708|      0|    }
 4709|       |
 4710|       |    /* Create the new spec. */
 4711|   278k|    spec = ssl_CreateCipherSpec(ss, direction);
 4712|   278k|    if (!spec) {
  ------------------
  |  Branch (4712:9): [True: 0, False: 278k]
  ------------------
 4713|      0|        return SECFailure;
 4714|      0|    }
 4715|   278k|    spec->epoch = epoch;
 4716|   278k|    spec->nextSeqNum = 0;
 4717|   278k|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|   278k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 278k]
  |  |  ------------------
  ------------------
 4718|      0|        dtls_InitRecvdRecords(&spec->recvdRecords);
 4719|      0|    }
 4720|       |
 4721|       |    /* This depends on spec having a valid direction and epoch. */
 4722|   278k|    rv = tls13_SetupPendingCipherSpec(ss, spec);
 4723|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4723:9): [True: 0, False: 278k]
  ------------------
 4724|      0|        goto loser;
 4725|      0|    }
 4726|       |
 4727|   278k|    type = (TrafficKeyType)PR_MIN(TrafficKeyApplicationData, epoch);
  ------------------
  |  |  158|   278k|#define PR_MIN(x,y)     ((x)<(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (158:26): [True: 274k, False: 4.05k]
  |  |  ------------------
  ------------------
 4728|   278k|    rv = tls13_DeriveTrafficKeys(ss, spec, type, deleteSecret);
 4729|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4729:9): [True: 0, False: 278k]
  ------------------
 4730|      0|        goto loser;
 4731|      0|    }
 4732|       |
 4733|   278k|    rv = tls13_InitPendingContext(ss, spec);
 4734|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4734:9): [True: 0, False: 278k]
  ------------------
 4735|      0|        goto loser;
 4736|      0|    }
 4737|       |
 4738|       |    /* Now that we've set almost everything up, finally cut over. */
 4739|   278k|    specp = (direction == ssl_secret_read) ? &ss->ssl3.crSpec : &ss->ssl3.cwSpec;
  ------------------
  |  Branch (4739:13): [True: 143k, False: 135k]
  ------------------
 4740|   278k|    ssl_GetSpecWriteLock(ss);
  ------------------
  |  | 1435|   278k|    {                                            \
  |  | 1436|   278k|        if (!ss->opt.noLocks)                    \
  |  |  ------------------
  |  |  |  Branch (1436:13): [True: 135k, False: 143k]
  |  |  ------------------
  |  | 1437|   278k|            NSSRWLock_LockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   48|   135k|#define NSSRWLock_LockWrite NSSRWLock_LockWrite_Util
  |  |  ------------------
  |  | 1438|   278k|    }
  ------------------
 4741|   278k|    ssl_CipherSpecRelease(*specp); /* May delete old cipher. */
 4742|   278k|    *specp = spec;                 /* Overwrite. */
 4743|   278k|    ssl_ReleaseSpecWriteLock(ss);
  ------------------
  |  | 1440|   278k|    {                                              \
  |  | 1441|   278k|        if (!ss->opt.noLocks)                      \
  |  |  ------------------
  |  |  |  Branch (1441:13): [True: 135k, False: 143k]
  |  |  ------------------
  |  | 1442|   278k|            NSSRWLock_UnlockWrite((ss)->specLock); \
  |  |  ------------------
  |  |  |  |   51|   135k|#define NSSRWLock_UnlockWrite NSSRWLock_UnlockWrite_Util
  |  |  ------------------
  |  | 1443|   278k|    }
  ------------------
 4744|       |
 4745|   278k|    SSL_TRC(3, ("%d: TLS13[%d]: %s installed key for epoch=%d (%s) dir=%s",
  ------------------
  |  |   71|   278k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 278k]
  |  |  ------------------
  |  |   72|   278k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4746|   278k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss), spec->epoch,
 4747|   278k|                spec->phase, SPEC_DIR(spec)));
 4748|   278k|    return SECSuccess;
 4749|       |
 4750|      0|loser:
 4751|      0|    ssl_CipherSpecRelease(spec);
 4752|      0|    return SECFailure;
 4753|   278k|}
tls13con.c:tls13_SetupPendingCipherSpec:
 4578|   278k|{
 4579|   278k|    ssl3CipherSuite suite = ss->ssl3.hs.cipher_suite;
 4580|       |
 4581|   278k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   278k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   414k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 143k, False: 135k]
  |  |  |  |  |  Branch (208:7): [True: 135k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4582|   278k|    PORT_Assert(spec->epoch);
  ------------------
  |  |  120|   278k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   278k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 278k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4583|       |
 4584|       |    /* Version isn't set when we send 0-RTT data. */
 4585|   278k|    spec->version = PR_MAX(SSL_LIBRARY_VERSION_TLS_1_3, ss->version);
  ------------------
  |  |  159|   278k|#define PR_MAX(x,y)     ((x)>(y)?(x):(y))
  |  |  ------------------
  |  |  |  Branch (159:26): [True: 0, False: 278k]
  |  |  ------------------
  ------------------
 4586|       |
 4587|   278k|    ssl_SaveCipherSpec(ss, spec);
 4588|       |    /* We want to keep read cipher specs around longer because
 4589|       |     * there are cases where we might get either epoch N or
 4590|       |     * epoch N+1. */
 4591|   278k|    if (IS_DTLS(ss) && spec->direction == ssl_secret_read) {
  ------------------
  |  |  892|   557k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 278k]
  |  |  ------------------
  ------------------
  |  Branch (4591:24): [True: 0, False: 0]
  ------------------
 4592|      0|        ssl_CipherSpecAddRef(spec);
 4593|      0|    }
 4594|       |
 4595|   278k|    SSL_TRC(3, ("%d: TLS13[%d]: Set Pending Cipher Suite to 0x%04x",
  ------------------
  |  |   71|   278k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 278k]
  |  |  ------------------
  |  |   72|   278k|    ssl_Trace b
  ------------------
 4596|   278k|                SSL_GETPID(), ss->fd, suite));
 4597|       |
 4598|   278k|    spec->cipherDef = ssl_GetBulkCipherDef(ssl_LookupCipherSuiteDef(suite));
 4599|       |
 4600|   278k|    if (spec->epoch == TrafficKeyEarlyApplicationData) {
  ------------------
  |  Branch (4600:9): [True: 0, False: 278k]
  ------------------
 4601|      0|        if (ss->xtnData.selectedPsk &&
  ------------------
  |  Branch (4601:13): [True: 0, False: 0]
  ------------------
 4602|      0|            ss->xtnData.selectedPsk->zeroRttSuite != TLS_NULL_WITH_NULL_NULL) {
  ------------------
  |  |   76|      0|#define TLS_NULL_WITH_NULL_NULL                 0x0000
  ------------------
  |  Branch (4602:13): [True: 0, False: 0]
  ------------------
 4603|      0|            spec->earlyDataRemaining = ss->xtnData.selectedPsk->maxEarlyData;
 4604|      0|        }
 4605|      0|    }
 4606|       |
 4607|   278k|    tls13_SetSpecRecordVersion(ss, spec);
 4608|       |
 4609|       |    /* The record size limit is reduced by one so that the remainder of the
 4610|       |     * record handling code can use the same checks for all versions. */
 4611|   278k|    if (ssl3_ExtensionNegotiated(ss, ssl_record_size_limit_xtn)) {
  ------------------
  |  Branch (4611:9): [True: 272k, False: 6.00k]
  ------------------
 4612|   272k|        spec->recordSizeLimit = ((spec->direction == ssl_secret_read)
  ------------------
  |  Branch (4612:34): [True: 139k, False: 132k]
  ------------------
 4613|   272k|                                     ? ss->opt.recordSizeLimit
 4614|   272k|                                     : ss->xtnData.recordSizeLimit) -
 4615|   272k|                                1;
 4616|   272k|    } else {
 4617|  6.00k|        spec->recordSizeLimit = MAX_FRAGMENT_LENGTH;
  ------------------
  |  |   35|  6.00k|#define MAX_FRAGMENT_LENGTH 16384
  ------------------
 4618|  6.00k|    }
 4619|   278k|    return SECSuccess;
 4620|   278k|}
tls13con.c:tls13_DeriveTrafficKeys:
 4472|   278k|{
 4473|   278k|    size_t keySize = spec->cipherDef->key_size;
 4474|   278k|    size_t ivSize = spec->cipherDef->iv_size +
 4475|   278k|                    spec->cipherDef->explicit_nonce_size; /* This isn't always going to
 4476|       |                                                           * work, but it does for
 4477|       |                                                           * AES-GCM */
 4478|   278k|    CK_MECHANISM_TYPE bulkAlgorithm = ssl3_Alg2Mech(spec->cipherDef->calg);
 4479|   278k|    PK11SymKey **prkp = NULL;
 4480|   278k|    PK11SymKey *prk = NULL;
 4481|   278k|    PRBool clientSecret;
 4482|   278k|    SECStatus rv;
 4483|       |    /* These labels are just used for debugging. */
 4484|   278k|    static const char kHkdfPhaseEarlyApplicationDataKeys[] = "early application data";
 4485|   278k|    static const char kHkdfPhaseHandshakeKeys[] = "handshake data";
 4486|   278k|    static const char kHkdfPhaseApplicationDataKeys[] = "application data";
 4487|       |
 4488|   278k|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|   278k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   414k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 143k, False: 135k]
  |  |  |  |  |  Branch (208:7): [True: 135k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4489|       |
 4490|   278k|    clientSecret = !tls13_UseServerSecret(ss, spec->direction);
 4491|   278k|    switch (type) {
 4492|      0|        case TrafficKeyEarlyApplicationData:
  ------------------
  |  Branch (4492:9): [True: 0, False: 278k]
  ------------------
 4493|      0|            PORT_Assert(clientSecret);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4494|      0|            prkp = &ss->ssl3.hs.clientEarlyTrafficSecret;
 4495|      0|            spec->phase = kHkdfPhaseEarlyApplicationDataKeys;
 4496|      0|            break;
 4497|  2.42k|        case TrafficKeyHandshake:
  ------------------
  |  Branch (4497:9): [True: 2.42k, False: 276k]
  ------------------
 4498|  2.42k|            prkp = clientSecret ? &ss->ssl3.hs.clientHsTrafficSecret
  ------------------
  |  Branch (4498:20): [True: 1.21k, False: 1.21k]
  ------------------
 4499|  2.42k|                                : &ss->ssl3.hs.serverHsTrafficSecret;
 4500|  2.42k|            spec->phase = kHkdfPhaseHandshakeKeys;
 4501|  2.42k|            break;
 4502|   276k|        case TrafficKeyApplicationData:
  ------------------
  |  Branch (4502:9): [True: 276k, False: 2.42k]
  ------------------
 4503|   276k|            prkp = clientSecret ? &ss->ssl3.hs.clientTrafficSecret
  ------------------
  |  Branch (4503:20): [True: 142k, False: 133k]
  ------------------
 4504|   276k|                                : &ss->ssl3.hs.serverTrafficSecret;
 4505|   276k|            spec->phase = kHkdfPhaseApplicationDataKeys;
 4506|   276k|            break;
 4507|      0|        default:
  ------------------
  |  Branch (4507:9): [True: 0, False: 278k]
  ------------------
 4508|      0|            LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4509|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4510|      0|            return SECFailure;
 4511|   278k|    }
 4512|   278k|    PORT_Assert(prkp != NULL);
  ------------------
  |  |  120|   278k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   278k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 278k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4513|   278k|    prk = *prkp;
 4514|       |
 4515|   278k|    SSL_TRC(3, ("%d: TLS13[%d]: deriving %s traffic keys epoch=%d (%s)",
  ------------------
  |  |   71|   278k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 278k]
  |  |  ------------------
  |  |   72|   278k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 4516|   278k|                SSL_GETPID(), ss->fd, SPEC_DIR(spec),
 4517|   278k|                spec->epoch, spec->phase));
 4518|       |
 4519|   278k|    rv = tls13_HkdfExpandLabel(prk, tls13_GetHash(ss),
 4520|   278k|                               NULL, 0,
 4521|   278k|                               kHkdfPurposeKey, strlen(kHkdfPurposeKey),
 4522|   278k|                               bulkAlgorithm, keySize,
 4523|   278k|                               ss->protocolVariant,
 4524|   278k|                               &spec->keyMaterial.key);
 4525|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4525:9): [True: 0, False: 278k]
  ------------------
 4526|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4527|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4528|      0|        goto loser;
 4529|      0|    }
 4530|       |
 4531|   278k|    if (IS_DTLS(ss) && spec->epoch > 0) {
  ------------------
  |  |  892|   557k|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 278k]
  |  |  ------------------
  ------------------
  |  Branch (4531:24): [True: 0, False: 0]
  ------------------
 4532|      0|        rv = ssl_CreateMaskingContextInner(spec->version, ss->ssl3.hs.cipher_suite,
 4533|      0|                                           ss->protocolVariant, prk, kHkdfPurposeSn,
 4534|      0|                                           strlen(kHkdfPurposeSn), &spec->maskContext);
 4535|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (4535:13): [True: 0, False: 0]
  ------------------
 4536|      0|            LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4537|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4538|      0|            goto loser;
 4539|      0|        }
 4540|      0|    }
 4541|       |
 4542|   278k|    rv = tls13_HkdfExpandLabelRaw(prk, tls13_GetHash(ss),
 4543|   278k|                                  NULL, 0,
 4544|   278k|                                  kHkdfPurposeIv, strlen(kHkdfPurposeIv),
 4545|   278k|                                  ss->protocolVariant,
 4546|   278k|                                  spec->keyMaterial.iv, ivSize);
 4547|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (4547:9): [True: 0, False: 278k]
  ------------------
 4548|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 4549|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 4550|      0|        goto loser;
 4551|      0|    }
 4552|       |
 4553|   278k|    if (deleteSecret) {
  ------------------
  |  Branch (4553:9): [True: 0, False: 278k]
  ------------------
 4554|      0|        PK11_FreeSymKey(prk);
 4555|      0|        *prkp = NULL;
 4556|      0|    }
 4557|   278k|    return SECSuccess;
 4558|       |
 4559|      0|loser:
 4560|      0|    return SECFailure;
 4561|   278k|}
tls13con.c:tls13_InitPendingContext:
 4628|   278k|{
 4629|   278k|    CK_MECHANISM_TYPE encMechanism;
 4630|   278k|    CK_ATTRIBUTE_TYPE encMode;
 4631|   278k|    SECItem iv;
 4632|   278k|    SSLCipherAlgorithm calg;
 4633|       |
 4634|   278k|    calg = spec->cipherDef->calg;
 4635|       |
 4636|   278k|    encMechanism = ssl3_Alg2Mech(calg);
 4637|   278k|    encMode = CKA_NSS_MESSAGE | ((spec->direction == ssl_secret_write) ? CKA_ENCRYPT : CKA_DECRYPT);
  ------------------
  |  |   69|   278k|#define CKA_NSS_MESSAGE 0x82000000L
  ------------------
                  encMode = CKA_NSS_MESSAGE | ((spec->direction == ssl_secret_write) ? CKA_ENCRYPT : CKA_DECRYPT);
  ------------------
  |  |  547|   135k|#define CKA_ENCRYPT 0x00000104UL
  ------------------
                  encMode = CKA_NSS_MESSAGE | ((spec->direction == ssl_secret_write) ? CKA_ENCRYPT : CKA_DECRYPT);
  ------------------
  |  |  548|   143k|#define CKA_DECRYPT 0x00000105UL
  ------------------
  |  Branch (4637:34): [True: 135k, False: 143k]
  ------------------
 4638|   278k|    iv.data = NULL;
 4639|   278k|    iv.len = 0;
 4640|       |
 4641|       |    /*
 4642|       |     * build the context
 4643|       |     */
 4644|   278k|    spec->cipherContext = PK11_CreateContextBySymKey(encMechanism, encMode,
 4645|   278k|                                                     spec->keyMaterial.key,
 4646|   278k|                                                     &iv);
 4647|   278k|    if (!spec->cipherContext) {
  ------------------
  |  Branch (4647:9): [True: 0, False: 278k]
  ------------------
 4648|      0|        ssl_MapLowLevelError(SSL_ERROR_SYM_KEY_CONTEXT_FAILURE);
 4649|      0|        return SECFailure;
 4650|      0|    }
 4651|   278k|    return SECSuccess;
 4652|   278k|}
tls13con.c:tls13_HandleEncryptedExtensions:
 5019|      3|{
 5020|      3|    SECStatus rv;
 5021|      3|    PRUint32 innerLength;
 5022|      3|    SECItem oldAlpn = { siBuffer, NULL, 0 };
 5023|       |
 5024|      3|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2, False: 1]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5025|      3|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2, False: 1]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5026|       |
 5027|      3|    SSL_TRC(3, ("%d: TLS13[%d]: handle encrypted extensions",
  ------------------
  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  ------------------
  |  |   72|      3|    ssl_Trace b
  ------------------
 5028|      3|                SSL_GETPID(), ss->fd));
 5029|       |
 5030|      3|    rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_ENCRYPTED_EXTENSIONS,
  ------------------
  |  |  182|      3|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      3|                       __VA_ARGS__,                                 \
  |  |  184|      3|                       wait_invalid)
  ------------------
 5031|      3|                              wait_encrypted_extensions);
 5032|      3|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5032:9): [True: 3, False: 0]
  ------------------
 5033|      3|        return SECFailure;
 5034|      3|    }
 5035|       |
 5036|      0|    rv = ssl3_ConsumeHandshakeNumber(ss, &innerLength, 2, &b, &length);
 5037|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5037:9): [True: 0, False: 0]
  ------------------
 5038|      0|        return SECFailure; /* Alert already sent. */
 5039|      0|    }
 5040|      0|    if (innerLength != length) {
  ------------------
  |  Branch (5040:9): [True: 0, False: 0]
  ------------------
 5041|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_ENCRYPTED_EXTENSIONS,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5042|      0|                    illegal_parameter);
 5043|      0|        return SECFailure;
 5044|      0|    }
 5045|       |
 5046|       |    /* If we are doing 0-RTT, then we already have an ALPN value. Stash
 5047|       |     * it for comparison. */
 5048|      0|    if (ss->ssl3.hs.zeroRttState == ssl_0rtt_sent &&
  ------------------
  |  Branch (5048:9): [True: 0, False: 0]
  ------------------
 5049|      0|        ss->xtnData.nextProtoState == SSL_NEXT_PROTO_EARLY_VALUE) {
  ------------------
  |  Branch (5049:9): [True: 0, False: 0]
  ------------------
 5050|      0|        oldAlpn = ss->xtnData.nextProto;
 5051|      0|        ss->xtnData.nextProto.data = NULL;
 5052|      0|        ss->xtnData.nextProtoState = SSL_NEXT_PROTO_NO_SUPPORT;
 5053|      0|    }
 5054|       |
 5055|      0|    rv = ssl3_ParseExtensions(ss, &b, &length);
 5056|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5056:9): [True: 0, False: 0]
  ------------------
 5057|      0|        return SECFailure; /* Error code set below */
 5058|      0|    }
 5059|       |
 5060|       |    /* Handle the rest of the extensions. */
 5061|      0|    rv = ssl3_HandleParsedExtensions(ss, ssl_hs_encrypted_extensions);
 5062|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5062:9): [True: 0, False: 0]
  ------------------
 5063|      0|        return SECFailure; /* Error code set below */
 5064|      0|    }
 5065|       |
 5066|       |    /* We can only get here if we offered 0-RTT. */
 5067|      0|    if (ssl3_ExtensionNegotiated(ss, ssl_tls13_early_data_xtn)) {
  ------------------
  |  Branch (5067:9): [True: 0, False: 0]
  ------------------
 5068|      0|        PORT_Assert(ss->ssl3.hs.zeroRttState == ssl_0rtt_sent);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5069|      0|        if (!ss->xtnData.selectedPsk) {
  ------------------
  |  Branch (5069:13): [True: 0, False: 0]
  ------------------
 5070|       |            /* Illegal to accept 0-RTT without also accepting PSK. */
 5071|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_ENCRYPTED_EXTENSIONS,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5072|      0|                        illegal_parameter);
 5073|      0|        }
 5074|      0|        ss->ssl3.hs.zeroRttState = ssl_0rtt_accepted;
 5075|       |
 5076|       |        /* Check that the server negotiated the same ALPN (if any). */
 5077|      0|        if (SECITEM_CompareItem(&oldAlpn, &ss->xtnData.nextProto)) {
  ------------------
  |  |  105|      0|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (5077:13): [True: 0, False: 0]
  ------------------
 5078|      0|            SECITEM_FreeItem(&oldAlpn, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(&oldAlpn, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5079|      0|            FATAL_ERROR(ss, SSL_ERROR_NEXT_PROTOCOL_DATA_INVALID,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5080|      0|                        illegal_parameter);
 5081|      0|            return SECFailure;
 5082|      0|        }
 5083|       |        /* Check that the server negotiated the same cipher suite. */
 5084|      0|        if (ss->ssl3.hs.cipher_suite != ss->ssl3.hs.zeroRttSuite) {
  ------------------
  |  Branch (5084:13): [True: 0, False: 0]
  ------------------
 5085|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_ENCRYPTED_EXTENSIONS,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5086|      0|                        illegal_parameter);
 5087|      0|            return SECFailure;
 5088|      0|        }
 5089|      0|    } else if (ss->ssl3.hs.zeroRttState == ssl_0rtt_sent) {
  ------------------
  |  Branch (5089:16): [True: 0, False: 0]
  ------------------
 5090|       |        /* Though we sent 0-RTT, the early_data extension wasn't present so the
 5091|       |         * state is unmodified; the server must have rejected 0-RTT. */
 5092|      0|        ss->ssl3.hs.zeroRttState = ssl_0rtt_ignored;
 5093|      0|        ss->ssl3.hs.zeroRttIgnore = ssl_0rtt_ignore_trial;
 5094|      0|    } else {
 5095|      0|        PORT_Assert(ss->ssl3.hs.zeroRttState == ssl_0rtt_none ||
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5096|      0|                    (ss->ssl3.hs.helloRetry &&
 5097|      0|                     ss->ssl3.hs.zeroRttState == ssl_0rtt_ignored));
 5098|      0|    }
 5099|       |
 5100|      0|    SECITEM_FreeItem(&oldAlpn, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&oldAlpn, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5101|      0|    if (ss->ssl3.hs.kea_def->authKeyType == ssl_auth_psk) {
  ------------------
  |  Branch (5101:9): [True: 0, False: 0]
  ------------------
 5102|      0|        TLS13_SET_HS_STATE(ss, wait_finished);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 5103|      0|    } else {
 5104|      0|        TLS13_SET_HS_STATE(ss, wait_cert_request);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 5105|      0|    }
 5106|       |
 5107|       |    /* Client is done with any PSKs */
 5108|      0|    tls13_DestroyPskList(&ss->ssl3.hs.psks);
 5109|      0|    ss->xtnData.selectedPsk = NULL;
 5110|       |
 5111|      0|    return SECSuccess;
 5112|      0|}
tls13con.c:tls13_HandleCertificateVerify:
 5237|      2|{
 5238|      2|    sslDelegatedCredential *dc = ss->xtnData.peerDelegCred;
 5239|      2|    CERTSubjectPublicKeyInfo *spki;
 5240|      2|    SECKEYPublicKey *pubKey = NULL;
 5241|      2|    SECItem signed_hash = { siBuffer, NULL, 0 };
 5242|      2|    SECStatus rv;
 5243|      2|    SSLSignatureScheme sigScheme;
 5244|      2|    SSLHashType hashAlg;
 5245|      2|    SSL3Hashes tbsHash;
 5246|      2|    SSL3Hashes hashes;
 5247|       |
 5248|      2|    SSL_TRC(3, ("%d: TLS13[%d]: handle certificate_verify handshake",
  ------------------
  |  |   71|      2|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   72|      2|    ssl_Trace b
  ------------------
 5249|      2|                SSL_GETPID(), ss->fd));
 5250|      2|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 1]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5251|      2|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 1]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5252|       |
 5253|      2|    rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_CERT_VERIFY,
  ------------------
  |  |  182|      2|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      2|                       __VA_ARGS__,                                 \
  |  |  184|      2|                       wait_invalid)
  ------------------
 5254|      2|                              wait_cert_verify);
 5255|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5255:9): [True: 2, False: 0]
  ------------------
 5256|      2|        return SECFailure;
 5257|      2|    }
 5258|       |
 5259|      0|    rv = tls13_ComputeHandshakeHashes(ss, &hashes);
 5260|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5260:9): [True: 0, False: 0]
  ------------------
 5261|      0|        return SECFailure;
 5262|      0|    }
 5263|       |
 5264|      0|    if (ss->firstHsDone) {
  ------------------
  |  Branch (5264:9): [True: 0, False: 0]
  ------------------
 5265|      0|        rv = ssl_HashPostHandshakeMessage(ss, ssl_hs_certificate_verify, b, length);
 5266|      0|    } else {
 5267|      0|        rv = ssl_HashHandshakeMessage(ss, ssl_hs_certificate_verify, b, length);
 5268|      0|    }
 5269|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5269:9): [True: 0, False: 0]
  ------------------
 5270|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5271|      0|        return SECFailure;
 5272|      0|    }
 5273|       |
 5274|      0|    rv = ssl_ConsumeSignatureScheme(ss, &b, &length, &sigScheme);
 5275|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5275:9): [True: 0, False: 0]
  ------------------
 5276|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERT_VERIFY, illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5277|      0|        return SECFailure;
 5278|      0|    }
 5279|       |
 5280|       |    /* Set the |spki| used to verify the handshake. When verifying with a
 5281|       |     * delegated credential (DC), this corresponds to the DC public key;
 5282|       |     * otherwise it correspond to the public key of the peer's end-entity
 5283|       |     * certificate.
 5284|       |     */
 5285|      0|    if (tls13_IsVerifyingWithDelegatedCredential(ss)) {
  ------------------
  |  Branch (5285:9): [True: 0, False: 0]
  ------------------
 5286|       |        /* DelegatedCredential.cred.expected_cert_verify_algorithm is expected
 5287|       |         * to match CertificateVerify.scheme.
 5288|       |         * DelegatedCredential.cred.expected_cert_verify_algorithm must also be
 5289|       |         * the same as was reported in ssl3_AuthCertificate.
 5290|       |         */
 5291|      0|        if (sigScheme != dc->expectedCertVerifyAlg || sigScheme != ss->sec.signatureScheme) {
  ------------------
  |  Branch (5291:13): [True: 0, False: 0]
  |  Branch (5291:55): [True: 0, False: 0]
  ------------------
 5292|      0|            FATAL_ERROR(ss, SSL_ERROR_DC_CERT_VERIFY_ALG_MISMATCH, illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5293|      0|            return SECFailure;
 5294|      0|        }
 5295|       |
 5296|       |        /* Verify the DC has three steps: (1) use the peer's end-entity
 5297|       |         * certificate to verify DelegatedCredential.signature, (2) check that
 5298|       |         * the certificate has the correct key usage, and (3) check that the DC
 5299|       |         * hasn't expired.
 5300|       |         */
 5301|      0|        rv = tls13_VerifyDelegatedCredential(ss, dc);
 5302|      0|        if (rv != SECSuccess) { /* Calls FATAL_ERROR() */
  ------------------
  |  Branch (5302:13): [True: 0, False: 0]
  ------------------
 5303|      0|            return SECFailure;
 5304|      0|        }
 5305|       |
 5306|      0|        SSL_TRC(3, ("%d: TLS13[%d]: Verifying with delegated credential",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 5307|      0|                    SSL_GETPID(), ss->fd));
 5308|      0|        spki = dc->spki;
 5309|      0|    } else {
 5310|      0|        spki = &ss->sec.peerCert->subjectPublicKeyInfo;
 5311|      0|    }
 5312|       |
 5313|      0|    rv = ssl_CheckSignatureSchemeConsistency(ss, sigScheme, spki);
 5314|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5314:9): [True: 0, False: 0]
  ------------------
 5315|       |        /* Error set already */
 5316|      0|        FATAL_ERROR(ss, PORT_GetError(), illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5317|      0|        return SECFailure;
 5318|      0|    }
 5319|      0|    hashAlg = ssl_SignatureSchemeToHashType(sigScheme);
 5320|       |
 5321|      0|    rv = tls13_AddContextToHashes(ss, &hashes, hashAlg, PR_FALSE, &tbsHash);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5322|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5322:9): [True: 0, False: 0]
  ------------------
 5323|      0|        FATAL_ERROR(ss, SSL_ERROR_DIGEST_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5324|      0|        return SECFailure;
 5325|      0|    }
 5326|       |
 5327|      0|    rv = ssl3_ConsumeHandshakeVariable(ss, &signed_hash, 2, &b, &length);
 5328|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5328:9): [True: 0, False: 0]
  ------------------
 5329|      0|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CERT_VERIFY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5330|      0|        return SECFailure;
 5331|      0|    }
 5332|       |
 5333|      0|    if (length != 0) {
  ------------------
  |  Branch (5333:9): [True: 0, False: 0]
  ------------------
 5334|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CERT_VERIFY, decode_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5335|      0|        return SECFailure;
 5336|      0|    }
 5337|       |
 5338|      0|    pubKey = SECKEY_ExtractPublicKey(spki);
 5339|      0|    if (pubKey == NULL) {
  ------------------
  |  Branch (5339:9): [True: 0, False: 0]
  ------------------
 5340|      0|        ssl_MapLowLevelError(SSL_ERROR_EXTRACT_PUBLIC_KEY_FAILURE);
 5341|      0|        return SECFailure;
 5342|      0|    }
 5343|       |
 5344|      0|    rv = ssl_VerifySignedHashesWithPubKey(ss, pubKey, sigScheme,
 5345|      0|                                          &tbsHash, &signed_hash);
 5346|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5346:9): [True: 0, False: 0]
  ------------------
 5347|      0|        FATAL_ERROR(ss, PORT_GetError(), decrypt_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5348|      0|        goto loser;
 5349|      0|    }
 5350|       |
 5351|       |    /* Set the auth type and verify it is what we captured in ssl3_AuthCertificate */
 5352|      0|    if (!ss->sec.isServer) {
  ------------------
  |  Branch (5352:9): [True: 0, False: 0]
  ------------------
 5353|      0|        ss->sec.authType = ssl_SignatureSchemeToAuthType(sigScheme);
 5354|       |
 5355|      0|        uint32_t prelimAuthKeyBits = ss->sec.authKeyBits;
 5356|      0|        rv = ssl_SetAuthKeyBits(ss, pubKey);
 5357|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5357:13): [True: 0, False: 0]
  ------------------
 5358|      0|            goto loser; /* Alert sent and code set. */
 5359|      0|        }
 5360|       |
 5361|      0|        if (prelimAuthKeyBits != ss->sec.authKeyBits) {
  ------------------
  |  Branch (5361:13): [True: 0, False: 0]
  ------------------
 5362|      0|            FATAL_ERROR(ss, SSL_ERROR_DC_CERT_VERIFY_ALG_MISMATCH, illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5363|      0|            goto loser;
 5364|      0|        }
 5365|      0|    }
 5366|       |
 5367|       |    /* Request a client certificate now if one was requested. */
 5368|      0|    if (ss->ssl3.hs.clientCertRequested) {
  ------------------
  |  Branch (5368:9): [True: 0, False: 0]
  ------------------
 5369|      0|        PORT_Assert(!ss->sec.isServer);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5370|      0|        rv = ssl3_BeginHandleCertificateRequest(
 5371|      0|            ss, ss->xtnData.sigSchemes, ss->xtnData.numSigSchemes,
 5372|      0|            &ss->xtnData.certReqAuthorities);
 5373|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5373:13): [True: 0, False: 0]
  ------------------
 5374|      0|            FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5375|      0|            goto loser;
 5376|      0|        }
 5377|      0|    }
 5378|       |
 5379|      0|    SECKEY_DestroyPublicKey(pubKey);
 5380|      0|    TLS13_SET_HS_STATE(ss, wait_finished);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 5381|      0|    return SECSuccess;
 5382|       |
 5383|      0|loser:
 5384|      0|    SECKEY_DestroyPublicKey(pubKey);
 5385|      0|    return SECFailure;
 5386|      0|}
tls13con.c:tls13_ComputeFinished:
 5531|  1.63k|{
 5532|  1.63k|    SECStatus rv;
 5533|  1.63k|    PK11Context *hmacCtx = NULL;
 5534|  1.63k|    CK_MECHANISM_TYPE macAlg = tls13_GetHmacMechanismFromHash(hashType);
 5535|  1.63k|    SECItem param = { siBuffer, NULL, 0 };
 5536|  1.63k|    unsigned int outputLenUint;
 5537|  1.63k|    const char *label = kHkdfLabelFinishedSecret;
 5538|  1.63k|    PK11SymKey *secret = NULL;
 5539|       |
 5540|  1.63k|    PORT_Assert(baseKey);
  ------------------
  |  |  120|  1.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5541|  1.63k|    SSL_TRC(3, ("%d: TLS13[%d]: %s calculate finished",
  ------------------
  |  |   71|  1.63k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |   72|  1.63k|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 5542|  1.63k|                SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 5543|  1.63k|    PRINT_BUF(50, (ss, "Handshake hash", hashes->u.raw, hashes->len));
  ------------------
  |  |   74|  1.63k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |   75|  1.63k|    ssl_PrintBuf b
  ------------------
 5544|       |
 5545|       |    /* Now derive the appropriate finished secret from the base secret. */
 5546|  1.63k|    rv = tls13_HkdfExpandLabel(baseKey, hashType,
 5547|  1.63k|                               NULL, 0, label, strlen(label),
 5548|  1.63k|                               tls13_GetHmacMechanismFromHash(hashType),
 5549|  1.63k|                               tls13_GetHashSizeForHash(hashType),
 5550|  1.63k|                               ss->protocolVariant, &secret);
 5551|  1.63k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5551:9): [True: 0, False: 1.63k]
  ------------------
 5552|      0|        goto abort;
 5553|      0|    }
 5554|       |
 5555|  1.63k|    PORT_Assert(hashes->len == tls13_GetHashSizeForHash(hashType));
  ------------------
  |  |  120|  1.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5556|  1.63k|    hmacCtx = PK11_CreateContextBySymKey(macAlg, CKA_SIGN,
  ------------------
  |  |  551|  1.63k|#define CKA_SIGN 0x00000108UL
  ------------------
 5557|  1.63k|                                         secret, &param);
 5558|  1.63k|    if (!hmacCtx) {
  ------------------
  |  Branch (5558:9): [True: 0, False: 1.63k]
  ------------------
 5559|      0|        goto abort;
 5560|      0|    }
 5561|       |
 5562|  1.63k|    rv = PK11_DigestBegin(hmacCtx);
 5563|  1.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (5563:9): [True: 0, False: 1.63k]
  ------------------
 5564|      0|        goto abort;
 5565|       |
 5566|  1.63k|    rv = PK11_DigestOp(hmacCtx, hashes->u.raw, hashes->len);
 5567|  1.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (5567:9): [True: 0, False: 1.63k]
  ------------------
 5568|      0|        goto abort;
 5569|       |
 5570|  1.63k|    PORT_Assert(maxOutputLen >= tls13_GetHashSizeForHash(hashType));
  ------------------
  |  |  120|  1.63k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.63k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.63k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5571|  1.63k|    rv = PK11_DigestFinal(hmacCtx, output, &outputLenUint, maxOutputLen);
 5572|  1.63k|    if (rv != SECSuccess)
  ------------------
  |  Branch (5572:9): [True: 0, False: 1.63k]
  ------------------
 5573|      0|        goto abort;
 5574|  1.63k|    *outputLen = outputLenUint;
 5575|       |
 5576|  1.63k|    PK11_FreeSymKey(secret);
 5577|  1.63k|    PK11_DestroyContext(hmacCtx, PR_TRUE);
  ------------------
  |  |  437|  1.63k|#define PR_TRUE 1
  ------------------
 5578|  1.63k|    PRINT_BUF(50, (ss, "finished value", output, outputLenUint));
  ------------------
  |  |   74|  1.63k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 1.63k]
  |  |  ------------------
  |  |   75|  1.63k|    ssl_PrintBuf b
  ------------------
 5579|  1.63k|    return SECSuccess;
 5580|       |
 5581|      0|abort:
 5582|      0|    if (secret) {
  ------------------
  |  Branch (5582:9): [True: 0, False: 0]
  ------------------
 5583|      0|        PK11_FreeSymKey(secret);
 5584|      0|    }
 5585|       |
 5586|      0|    if (hmacCtx) {
  ------------------
  |  Branch (5586:9): [True: 0, False: 0]
  ------------------
 5587|      0|        PK11_DestroyContext(hmacCtx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5588|      0|    }
 5589|       |
 5590|      0|    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5591|      0|    return SECFailure;
 5592|  1.63k|}
tls13con.c:tls13_VerifyFinished:
 5641|    417|{
 5642|    417|    SECStatus rv;
 5643|    417|    PRUint8 finishedBuf[TLS13_MAX_FINISHED_SIZE];
 5644|    417|    unsigned int finishedLen;
 5645|       |
 5646|    417|    if (!hashes) {
  ------------------
  |  Branch (5646:9): [True: 0, False: 417]
  ------------------
 5647|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5648|      0|        return SECFailure;
 5649|      0|    }
 5650|       |
 5651|    417|    rv = tls13_ComputeFinished(ss, secret, tls13_GetHash(ss), hashes, PR_FALSE,
  ------------------
  |  |  438|    417|#define PR_FALSE 0
  ------------------
 5652|    417|                               finishedBuf, &finishedLen, sizeof(finishedBuf));
 5653|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5653:9): [True: 0, False: 417]
  ------------------
 5654|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5655|      0|        return SECFailure;
 5656|      0|    }
 5657|       |
 5658|    417|    if (length != finishedLen) {
  ------------------
  |  Branch (5658:9): [True: 417, False: 0]
  ------------------
 5659|       |#ifndef UNSAFE_FUZZER_MODE
 5660|       |        FATAL_ERROR(ss, message == ssl_hs_finished ? SSL_ERROR_RX_MALFORMED_FINISHED : SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
 5661|       |        return SECFailure;
 5662|       |#endif
 5663|    417|    }
 5664|       |
 5665|    417|    if (NSS_SecureMemcmp(b, finishedBuf, finishedLen) != 0) {
  ------------------
  |  Branch (5665:9): [True: 417, False: 0]
  ------------------
 5666|       |#ifndef UNSAFE_FUZZER_MODE
 5667|       |        FATAL_ERROR(ss, SSL_ERROR_BAD_HANDSHAKE_HASH_VALUE,
 5668|       |                    decrypt_error);
 5669|       |        return SECFailure;
 5670|       |#endif
 5671|    417|    }
 5672|       |
 5673|    417|    return SECSuccess;
 5674|    417|}
tls13con.c:tls13_CommonHandleFinished:
 5679|    430|{
 5680|    430|    SECStatus rv;
 5681|    430|    SSL3Hashes hashes;
 5682|       |
 5683|    430|    rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_FINISHED,
  ------------------
  |  |  182|    430|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|    430|                       __VA_ARGS__,                                 \
  |  |  184|    430|                       wait_invalid)
  ------------------
 5684|    430|                              wait_finished);
 5685|    430|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5685:9): [True: 13, False: 417]
  ------------------
 5686|     13|        return SECFailure;
 5687|     13|    }
 5688|    417|    ss->ssl3.hs.endOfFlight = PR_TRUE;
  ------------------
  |  |  437|    417|#define PR_TRUE 1
  ------------------
 5689|       |
 5690|    417|    rv = tls13_ComputeHandshakeHashes(ss, &hashes);
 5691|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5691:9): [True: 0, False: 417]
  ------------------
 5692|      0|        LOG_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   14|      0|    do {                                                                           \
  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  ------------------
  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  ------------------
  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  ------------------
  |  |   18|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5693|      0|        return SECFailure;
 5694|      0|    }
 5695|       |
 5696|    417|    if (ss->firstHsDone) {
  ------------------
  |  Branch (5696:9): [True: 0, False: 417]
  ------------------
 5697|      0|        rv = ssl_HashPostHandshakeMessage(ss, ssl_hs_finished, b, length);
 5698|    417|    } else {
 5699|    417|        rv = ssl_HashHandshakeMessage(ss, ssl_hs_finished, b, length);
 5700|    417|    }
 5701|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5701:9): [True: 0, False: 417]
  ------------------
 5702|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 5703|      0|        return SECFailure;
 5704|      0|    }
 5705|       |
 5706|    417|    return tls13_VerifyFinished(ss, ssl_hs_finished,
 5707|    417|                                key, b, length, &hashes);
 5708|    417|}
tls13con.c:tls13_ComputeFinalSecrets:
 1706|    417|{
 1707|    417|    SECStatus rv;
 1708|       |
 1709|    417|    PORT_Assert(!ss->ssl3.crSpec->masterSecret);
  ------------------
  |  |  120|    417|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    417|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 417, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1710|    417|    PORT_Assert(!ss->ssl3.cwSpec->masterSecret);
  ------------------
  |  |  120|    417|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    417|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 417, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1711|    417|    PORT_Assert(ss->ssl3.hs.currentSecret);
  ------------------
  |  |  120|    417|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    417|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 417, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1712|    417|    rv = tls13_DeriveSecretWrap(ss, ss->ssl3.hs.currentSecret,
 1713|    417|                                NULL, kHkdfLabelResumptionMasterSecret,
 1714|    417|                                NULL,
 1715|    417|                                &ss->ssl3.hs.resumptionMasterSecret);
 1716|    417|    PK11_FreeSymKey(ss->ssl3.hs.currentSecret);
 1717|    417|    ss->ssl3.hs.currentSecret = NULL;
 1718|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1718:9): [True: 0, False: 417]
  ------------------
 1719|      0|        return SECFailure;
 1720|      0|    }
 1721|       |
 1722|    417|    return SECSuccess;
 1723|    417|}
tls13con.c:tls13_FinishHandshake:
 5839|    417|{
 5840|    417|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|    417|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    608|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 226, False: 191]
  |  |  |  |  |  Branch (208:7): [True: 191, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5841|    417|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|    417|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    608|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 226, False: 191]
  |  |  |  |  |  Branch (208:7): [True: 191, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5842|    417|    PORT_Assert(ss->ssl3.hs.restartTarget == NULL);
  ------------------
  |  |  120|    417|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    417|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 417, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5843|       |
 5844|       |    /* The first handshake is now completed. */
 5845|    417|    ss->handshake = NULL;
 5846|       |
 5847|       |    /* Don't need this. */
 5848|    417|    PK11_FreeSymKey(ss->ssl3.hs.clientHsTrafficSecret);
 5849|    417|    ss->ssl3.hs.clientHsTrafficSecret = NULL;
 5850|    417|    PK11_FreeSymKey(ss->ssl3.hs.serverHsTrafficSecret);
 5851|    417|    ss->ssl3.hs.serverHsTrafficSecret = NULL;
 5852|       |
 5853|    417|    TLS13_SET_HS_STATE(ss, idle_handshake);
  ------------------
  |  |   37|    417|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 5854|       |
 5855|    417|    return ssl_FinishHandshake(ss);
 5856|    417|}
tls13con.c:tls13_ServerHandleFinished:
 5732|    430|{
 5733|    430|    SECStatus rv;
 5734|       |
 5735|    430|    PORT_Assert(ss->opt.noLocks || ssl_HaveRecvBufLock(ss));
  ------------------
  |  |  120|    430|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    628|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 232, False: 198]
  |  |  |  |  |  Branch (208:7): [True: 198, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5736|    430|    PORT_Assert(ss->opt.noLocks || ssl_HaveSSL3HandshakeLock(ss));
  ------------------
  |  |  120|    430|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    628|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 232, False: 198]
  |  |  |  |  |  Branch (208:7): [True: 198, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5737|       |
 5738|    430|    SSL_TRC(3, ("%d: TLS13[%d]: server handle finished handshake",
  ------------------
  |  |   71|    430|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 430]
  |  |  ------------------
  |  |   72|    430|    ssl_Trace b
  ------------------
 5739|    430|                SSL_GETPID(), ss->fd));
 5740|       |
 5741|    430|    if (!tls13_ShouldRequestClientAuth(ss)) {
  ------------------
  |  Branch (5741:9): [True: 420, False: 10]
  ------------------
 5742|       |        /* Receiving this message might be the first sign we have that
 5743|       |         * early data is over, so pretend we received EOED. */
 5744|    420|        rv = tls13_MaybeHandleSuppressedEndOfEarlyData(ss);
 5745|    420|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5745:13): [True: 0, False: 420]
  ------------------
 5746|      0|            return SECFailure; /* Code already set. */
 5747|      0|        }
 5748|       |
 5749|    420|        if (!tls13_IsPostHandshake(ss)) {
  ------------------
  |  Branch (5749:13): [True: 415, False: 5]
  ------------------
 5750|       |            /* Finalize the RTT estimate. */
 5751|    415|            ss->ssl3.hs.rttEstimate = ssl_Time(ss) - ss->ssl3.hs.rttEstimate;
 5752|    415|        }
 5753|    420|    }
 5754|       |
 5755|    430|    rv = tls13_CommonHandleFinished(ss,
 5756|    430|                                    ss->firstHsDone ? ss->ssl3.hs.clientTrafficSecret : ss->ssl3.hs.clientHsTrafficSecret,
  ------------------
  |  Branch (5756:37): [True: 6, False: 424]
  ------------------
 5757|    430|                                    b, length);
 5758|    430|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5758:9): [True: 13, False: 417]
  ------------------
 5759|     13|        return SECFailure;
 5760|     13|    }
 5761|       |
 5762|    417|    if (ss->firstHsDone) {
  ------------------
  |  Branch (5762:9): [True: 0, False: 417]
  ------------------
 5763|      0|        TLS13_SET_HS_STATE(ss, idle_handshake);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 5764|       |
 5765|      0|        PORT_Assert(ss->ssl3.hs.shaPostHandshake != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 5766|      0|        PK11_DestroyContext(ss->ssl3.hs.shaPostHandshake, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 5767|      0|        ss->ssl3.hs.shaPostHandshake = NULL;
 5768|       |
 5769|      0|        ss->ssl3.clientCertRequested = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5770|       |
 5771|      0|        if (ss->ssl3.hs.keyUpdateDeferred) {
  ------------------
  |  Branch (5771:13): [True: 0, False: 0]
  ------------------
 5772|      0|            rv = tls13_SendKeyUpdate(ss, ss->ssl3.hs.deferredKeyUpdateRequest,
 5773|      0|                                     PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5774|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (5774:17): [True: 0, False: 0]
  ------------------
 5775|      0|                return SECFailure; /* error is set. */
 5776|      0|            }
 5777|      0|            ss->ssl3.hs.keyUpdateDeferred = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 5778|      0|        }
 5779|       |
 5780|      0|        return SECSuccess;
 5781|      0|    }
 5782|       |
 5783|    417|    if (!tls13_ShouldRequestClientAuth(ss) &&
  ------------------
  |  Branch (5783:9): [True: 414, False: 3]
  ------------------
 5784|    417|        (ss->ssl3.hs.zeroRttState != ssl_0rtt_done)) {
  ------------------
  |  Branch (5784:9): [True: 414, False: 0]
  ------------------
 5785|    414|        dtls_ReceivedFirstMessageInFlight(ss);
 5786|    414|    }
 5787|       |
 5788|    417|    rv = tls13_SetCipherSpec(ss, TrafficKeyApplicationData,
 5789|    417|                             ssl_secret_read, PR_FALSE);
  ------------------
  |  |  438|    417|#define PR_FALSE 0
  ------------------
 5790|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5790:9): [True: 0, False: 417]
  ------------------
 5791|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 5792|      0|        return SECFailure;
 5793|      0|    }
 5794|       |
 5795|    417|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|    417|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 417]
  |  |  ------------------
  ------------------
 5796|      0|        ssl_CipherSpecReleaseByEpoch(ss, ssl_secret_read, TrafficKeyClearText);
 5797|       |        /* We need to keep the handshake cipher spec so we can
 5798|       |         * read re-transmitted client Finished. */
 5799|      0|        rv = dtls_StartTimer(ss, ss->ssl3.hs.hdTimer,
 5800|      0|                             DTLS_RETRANSMIT_FINISHED_MS,
  ------------------
  |  |  130|      0|#define DTLS_RETRANSMIT_FINISHED_MS 30000
  ------------------
 5801|      0|                             dtls13_HolddownTimerCb);
 5802|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5802:13): [True: 0, False: 0]
  ------------------
 5803|      0|            return SECFailure;
 5804|      0|        }
 5805|      0|    }
 5806|       |
 5807|    417|    rv = tls13_ComputeFinalSecrets(ss);
 5808|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5808:9): [True: 0, False: 417]
  ------------------
 5809|      0|        return SECFailure;
 5810|      0|    }
 5811|       |
 5812|    417|    rv = tls13_FinishHandshake(ss);
 5813|    417|    if (rv != SECSuccess) {
  ------------------
  |  Branch (5813:9): [True: 0, False: 417]
  ------------------
 5814|      0|        return SECFailure;
 5815|      0|    }
 5816|       |
 5817|    417|    ssl_GetXmitBufLock(ss);
  ------------------
  |  | 1466|    417|    {                                           \
  |  | 1467|    417|        if (!ss->opt.noLocks)                   \
  |  |  ------------------
  |  |  |  Branch (1467:13): [True: 191, False: 226]
  |  |  ------------------
  |  | 1468|    417|            PZ_EnterMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  256|    191|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1469|    417|    }
  ------------------
 5818|       |    /* If resumption, authType is the original value and not ssl_auth_psk. */
 5819|    417|    if (ss->opt.enableSessionTickets && ss->sec.authType != ssl_auth_psk) {
  ------------------
  |  Branch (5819:9): [True: 261, False: 156]
  |  Branch (5819:41): [True: 261, False: 0]
  ------------------
 5820|    261|        rv = tls13_SendNewSessionTicket(ss, NULL, 0);
 5821|    261|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5821:13): [True: 0, False: 261]
  ------------------
 5822|      0|            goto loser;
 5823|      0|        }
 5824|    261|        rv = ssl3_FlushHandshake(ss, 0);
 5825|    261|        if (rv != SECSuccess) {
  ------------------
  |  Branch (5825:13): [True: 0, False: 261]
  ------------------
 5826|      0|            goto loser;
 5827|      0|        }
 5828|    261|    }
 5829|    417|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|    417|    {                                          \
  |  | 1472|    417|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 191, False: 226]
  |  |  ------------------
  |  | 1473|    417|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|    191|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|    417|    }
  ------------------
 5830|    417|    return SECSuccess;
 5831|       |
 5832|      0|loser:
 5833|      0|    ssl_ReleaseXmitBufLock(ss);
  ------------------
  |  | 1471|      0|    {                                          \
  |  | 1472|      0|        if (!ss->opt.noLocks)                  \
  |  |  ------------------
  |  |  |  Branch (1472:13): [True: 0, False: 0]
  |  |  ------------------
  |  | 1473|      0|            PZ_ExitMonitor((ss)->xmitBufLock); \
  |  |  ------------------
  |  |  |  |  257|      0|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1474|      0|    }
  ------------------
 5834|      0|    return SECFailure;
 5835|    417|}
tls13con.c:tls13_SendNewSessionTicket:
 6061|    261|{
 6062|    261|    PRUint16 message_length;
 6063|    261|    PK11SymKey *secret;
 6064|    261|    SECItem ticket_data = { 0, NULL, 0 };
 6065|    261|    SECStatus rv;
 6066|    261|    NewSessionTicket ticket = { 0 };
 6067|    261|    PRUint32 max_early_data_size_len = 0;
 6068|    261|    PRUint32 greaseLen = 0;
 6069|    261|    PRUint8 ticketNonce[sizeof(ss->ssl3.hs.ticketNonce)];
 6070|    261|    sslBuffer ticketNonceBuf = SSL_BUFFER(ticketNonce);
  ------------------
  |  |   34|    261|#define SSL_BUFFER(b) SSL_BUFFER_FIXED(b, sizeof(b))
  |  |  ------------------
  |  |  |  |   27|    261|    {                               \
  |  |  |  |   28|    261|        b, 0, maxlen, PR_TRUE       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  437|    261|#define PR_TRUE 1
  |  |  |  |  ------------------
  |  |  |  |   29|    261|    }
  |  |  ------------------
  ------------------
 6071|       |
 6072|    261|    SSL_TRC(3, ("%d: TLS13[%d]: send new session ticket message %d",
  ------------------
  |  |   71|    261|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 261]
  |  |  ------------------
  |  |   72|    261|    ssl_Trace b
  ------------------
 6073|    261|                SSL_GETPID(), ss->fd, ss->ssl3.hs.ticketNonce));
 6074|       |
 6075|    261|    ticket.flags = 0;
 6076|    261|    if (ss->opt.enable0RttData) {
  ------------------
  |  Branch (6076:9): [True: 157, False: 104]
  ------------------
 6077|    157|        ticket.flags |= ticket_allow_early_data;
 6078|    157|        max_early_data_size_len = 8; /* type + len + value. */
 6079|    157|    }
 6080|    261|    ticket.ticket_lifetime_hint = ssl_ticket_lifetime;
 6081|       |
 6082|    261|    if (ss->opt.enableGrease) {
  ------------------
  |  Branch (6082:9): [True: 154, False: 107]
  ------------------
 6083|    154|        greaseLen = 4; /* type + len + 0 (empty) */
 6084|    154|    }
 6085|       |
 6086|       |    /* The ticket age obfuscator. */
 6087|    261|    rv = PK11_GenerateRandom((PRUint8 *)&ticket.ticket_age_add,
 6088|    261|                             sizeof(ticket.ticket_age_add));
 6089|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6089:9): [True: 0, False: 261]
  ------------------
 6090|      0|        goto loser;
 6091|       |
 6092|    261|    rv = sslBuffer_AppendNumber(&ticketNonceBuf, ss->ssl3.hs.ticketNonce,
 6093|    261|                                sizeof(ticketNonce));
 6094|    261|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6094:9): [True: 0, False: 261]
  ------------------
 6095|      0|        goto loser;
 6096|      0|    }
 6097|    261|    ++ss->ssl3.hs.ticketNonce;
 6098|    261|    rv = tls13_HkdfExpandLabel(ss->ssl3.hs.resumptionMasterSecret,
 6099|    261|                               tls13_GetHash(ss),
 6100|    261|                               ticketNonce, sizeof(ticketNonce),
 6101|    261|                               kHkdfLabelResumption,
 6102|    261|                               strlen(kHkdfLabelResumption),
 6103|    261|                               CKM_HKDF_DERIVE,
  ------------------
  |  | 1296|    261|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
 6104|    261|                               tls13_GetHashSize(ss),
 6105|    261|                               ss->protocolVariant, &secret);
 6106|    261|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6106:9): [True: 0, False: 261]
  ------------------
 6107|      0|        goto loser;
 6108|      0|    }
 6109|       |
 6110|    261|    rv = ssl3_EncodeSessionTicket(ss, &ticket, appToken, appTokenLen,
 6111|    261|                                  secret, &ticket_data);
 6112|    261|    PK11_FreeSymKey(secret);
 6113|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6113:9): [True: 0, False: 261]
  ------------------
 6114|      0|        goto loser;
 6115|       |
 6116|    261|    message_length =
 6117|    261|        4 +                       /* lifetime */
 6118|    261|        4 +                       /* ticket_age_add */
 6119|    261|        1 + sizeof(ticketNonce) + /* ticket_nonce */
 6120|    261|        2 +                       /* extensions lentgh */
 6121|    261|        max_early_data_size_len + /* max_early_data_size extension length */
 6122|    261|        greaseLen +               /* GREASE extension length */
 6123|    261|        2 +                       /* ticket length */
 6124|    261|        ticket_data.len;
 6125|       |
 6126|    261|    rv = ssl3_AppendHandshakeHeader(ss, ssl_hs_new_session_ticket,
 6127|    261|                                    message_length);
 6128|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6128:9): [True: 0, False: 261]
  ------------------
 6129|      0|        goto loser;
 6130|       |
 6131|       |    /* This is a fixed value. */
 6132|    261|    rv = ssl3_AppendHandshakeNumber(ss, ssl_ticket_lifetime, 4);
 6133|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6133:9): [True: 0, False: 261]
  ------------------
 6134|      0|        goto loser;
 6135|       |
 6136|    261|    rv = ssl3_AppendHandshakeNumber(ss, ticket.ticket_age_add, 4);
 6137|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6137:9): [True: 0, False: 261]
  ------------------
 6138|      0|        goto loser;
 6139|       |
 6140|       |    /* The ticket nonce. */
 6141|    261|    rv = ssl3_AppendHandshakeVariable(ss, ticketNonce, sizeof(ticketNonce), 1);
 6142|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6142:9): [True: 0, False: 261]
  ------------------
 6143|      0|        goto loser;
 6144|       |
 6145|       |    /* Encode the ticket. */
 6146|    261|    rv = ssl3_AppendHandshakeVariable(
 6147|    261|        ss, ticket_data.data, ticket_data.len, 2);
 6148|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6148:9): [True: 0, False: 261]
  ------------------
 6149|      0|        goto loser;
 6150|       |
 6151|       |    /* Extensions */
 6152|    261|    rv = ssl3_AppendHandshakeNumber(ss, max_early_data_size_len + greaseLen, 2);
 6153|    261|    if (rv != SECSuccess)
  ------------------
  |  Branch (6153:9): [True: 0, False: 261]
  ------------------
 6154|      0|        goto loser;
 6155|       |
 6156|       |    /* GREASE NewSessionTicket:
 6157|       |     * When sending a NewSessionTicket message in TLS 1.3, a server MAY select
 6158|       |     * one or more GREASE extension values and advertise them as extensions
 6159|       |     * with varying length and contents [RFC8701, SEction 4.1]. */
 6160|    261|    if (ss->opt.enableGrease) {
  ------------------
  |  Branch (6160:9): [True: 154, False: 107]
  ------------------
 6161|    154|        PR_ASSERT(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  208|    154|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 154, False: 0]
  |  |  ------------------
  ------------------
 6162|       |
 6163|    154|        PRUint16 grease;
 6164|    154|        rv = tls13_RandomGreaseValue(&grease);
 6165|    154|        if (rv != SECSuccess)
  ------------------
  |  Branch (6165:13): [True: 0, False: 154]
  ------------------
 6166|      0|            goto loser;
 6167|       |        /* Extension type */
 6168|    154|        rv = ssl3_AppendHandshakeNumber(ss, grease, 2);
 6169|    154|        if (rv != SECSuccess)
  ------------------
  |  Branch (6169:13): [True: 0, False: 154]
  ------------------
 6170|      0|            goto loser;
 6171|       |        /* Extension length */
 6172|    154|        rv = ssl3_AppendHandshakeNumber(ss, 0, 2);
 6173|    154|        if (rv != SECSuccess)
  ------------------
  |  Branch (6173:13): [True: 0, False: 154]
  ------------------
 6174|      0|            goto loser;
 6175|    154|    }
 6176|       |
 6177|       |    /* Max early data size extension. */
 6178|    261|    if (max_early_data_size_len) {
  ------------------
  |  Branch (6178:9): [True: 157, False: 104]
  ------------------
 6179|    157|        rv = ssl3_AppendHandshakeNumber(
 6180|    157|            ss, ssl_tls13_early_data_xtn, 2);
 6181|    157|        if (rv != SECSuccess)
  ------------------
  |  Branch (6181:13): [True: 0, False: 157]
  ------------------
 6182|      0|            goto loser;
 6183|       |
 6184|       |        /* Length */
 6185|    157|        rv = ssl3_AppendHandshakeNumber(ss, 4, 2);
 6186|    157|        if (rv != SECSuccess)
  ------------------
  |  Branch (6186:13): [True: 0, False: 157]
  ------------------
 6187|      0|            goto loser;
 6188|       |
 6189|    157|        rv = ssl3_AppendHandshakeNumber(ss, ss->opt.maxEarlyDataSize, 4);
 6190|    157|        if (rv != SECSuccess)
  ------------------
  |  Branch (6190:13): [True: 0, False: 157]
  ------------------
 6191|      0|            goto loser;
 6192|    157|    }
 6193|       |
 6194|    261|    SECITEM_FreeItem(&ticket_data, PR_FALSE);
  ------------------
  |  |  108|    261|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&ticket_data, PR_FALSE);
  ------------------
  |  |  438|    261|#define PR_FALSE 0
  ------------------
 6195|    261|    return SECSuccess;
 6196|       |
 6197|      0|loser:
 6198|      0|    if (ticket_data.data) {
  ------------------
  |  Branch (6198:9): [True: 0, False: 0]
  ------------------
 6199|      0|        SECITEM_FreeItem(&ticket_data, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(&ticket_data, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6200|      0|    }
 6201|      0|    return SECFailure;
 6202|    261|}
tls13con.c:tls13_HandleNewSessionTicket:
 6249|      2|{
 6250|      2|    SECStatus rv;
 6251|      2|    PRUint32 utmp;
 6252|      2|    NewSessionTicket ticket = { 0 };
 6253|      2|    SECItem data;
 6254|      2|    SECItem ticket_nonce;
 6255|      2|    SECItem ticket_data;
 6256|       |
 6257|      2|    SSL_TRC(3, ("%d: TLS13[%d]: handle new session ticket message",
  ------------------
  |  |   71|      2|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 2]
  |  |  ------------------
  |  |   72|      2|    ssl_Trace b
  ------------------
 6258|      2|                SSL_GETPID(), ss->fd));
 6259|       |
 6260|      2|    rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_NEW_SESSION_TICKET,
  ------------------
  |  |  182|      2|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      2|                       __VA_ARGS__,                                 \
  |  |  184|      2|                       wait_invalid)
  ------------------
 6261|      2|                              idle_handshake);
 6262|      2|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6262:9): [True: 1, False: 1]
  ------------------
 6263|      1|        return SECFailure;
 6264|      1|    }
 6265|      1|    if (!tls13_IsPostHandshake(ss) || ss->sec.isServer) {
  ------------------
  |  Branch (6265:9): [True: 0, False: 1]
  |  Branch (6265:39): [True: 1, False: 0]
  ------------------
 6266|      1|        FATAL_ERROR(ss, SSL_ERROR_RX_UNEXPECTED_NEW_SESSION_TICKET,
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6267|      1|                    unexpected_message);
 6268|      1|        return SECFailure;
 6269|      1|    }
 6270|       |
 6271|      0|    ticket.received_timestamp = ssl_Time(ss);
 6272|      0|    rv = ssl3_ConsumeHandshakeNumber(ss, &ticket.ticket_lifetime_hint, 4, &b,
 6273|      0|                                     &length);
 6274|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6274:9): [True: 0, False: 0]
  ------------------
 6275|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_NEW_SESSION_TICKET,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6276|      0|                    decode_error);
 6277|      0|        return SECFailure;
 6278|      0|    }
 6279|      0|    ticket.ticket.type = siBuffer;
 6280|       |
 6281|      0|    rv = ssl3_ConsumeHandshake(ss, &utmp, sizeof(utmp),
 6282|      0|                               &b, &length);
 6283|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6283:9): [True: 0, False: 0]
  ------------------
 6284|      0|        PORT_SetError(SSL_ERROR_RX_MALFORMED_NEW_SESSION_TICKET);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 6285|      0|        return SECFailure;
 6286|      0|    }
 6287|      0|    ticket.ticket_age_add = PR_ntohl(utmp);
 6288|       |
 6289|       |    /* The nonce. */
 6290|      0|    rv = ssl3_ConsumeHandshakeVariable(ss, &ticket_nonce, 1, &b, &length);
 6291|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6291:9): [True: 0, False: 0]
  ------------------
 6292|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_NEW_SESSION_TICKET,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6293|      0|                    decode_error);
 6294|      0|        return SECFailure;
 6295|      0|    }
 6296|       |
 6297|       |    /* Get the ticket value. */
 6298|      0|    rv = ssl3_ConsumeHandshakeVariable(ss, &ticket_data, 2, &b, &length);
 6299|      0|    if (rv != SECSuccess || !ticket_data.len) {
  ------------------
  |  Branch (6299:9): [True: 0, False: 0]
  |  Branch (6299:29): [True: 0, False: 0]
  ------------------
 6300|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_NEW_SESSION_TICKET,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6301|      0|                    decode_error);
 6302|      0|        return SECFailure;
 6303|      0|    }
 6304|       |
 6305|       |    /* Parse extensions. */
 6306|      0|    rv = ssl3_ConsumeHandshakeVariable(ss, &data, 2, &b, &length);
 6307|      0|    if (rv != SECSuccess || length) {
  ------------------
  |  Branch (6307:9): [True: 0, False: 0]
  |  Branch (6307:29): [True: 0, False: 0]
  ------------------
 6308|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_NEW_SESSION_TICKET,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6309|      0|                    decode_error);
 6310|      0|        return SECFailure;
 6311|      0|    }
 6312|       |
 6313|      0|    rv = ssl3_HandleExtensions(ss, &data.data,
 6314|      0|                               &data.len, ssl_hs_new_session_ticket);
 6315|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (6315:9): [True: 0, False: 0]
  ------------------
 6316|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_NEW_SESSION_TICKET,
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6317|      0|                    decode_error);
 6318|      0|        return SECFailure;
 6319|      0|    }
 6320|      0|    if (ss->xtnData.max_early_data_size) {
  ------------------
  |  Branch (6320:9): [True: 0, False: 0]
  ------------------
 6321|      0|        ticket.flags |= ticket_allow_early_data;
 6322|      0|        ticket.max_early_data_size = ss->xtnData.max_early_data_size;
 6323|      0|    }
 6324|       |
 6325|      0|    if (!ss->opt.noCache) {
  ------------------
  |  Branch (6325:9): [True: 0, False: 0]
  ------------------
 6326|      0|        PK11SymKey *secret;
 6327|       |
 6328|      0|        PORT_Assert(ss->sec.ci.sid);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6329|      0|        rv = SECITEM_CopyItem(NULL, &ticket.ticket, &ticket_data);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 6330|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (6330:13): [True: 0, False: 0]
  ------------------
 6331|      0|            FATAL_ERROR(ss, SEC_ERROR_NO_MEMORY, internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 6332|      0|            return SECFailure;
 6333|      0|        }
 6334|      0|        PRINT_BUF(50, (ss, "Caching session ticket",
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 6335|      0|                       ticket.ticket.data,
 6336|      0|                       ticket.ticket.len));
 6337|       |
 6338|       |        /* Replace a previous session ticket when
 6339|       |         * we receive a second NewSessionTicket message. */
 6340|      0|        if (ss->sec.ci.sid->cached == in_client_cache ||
  ------------------
  |  Branch (6340:13): [True: 0, False: 0]
  ------------------
 6341|      0|            ss->sec.ci.sid->cached == in_external_cache) {
  ------------------
  |  Branch (6341:13): [True: 0, False: 0]
  ------------------
 6342|       |            /* Create a new session ID. */
 6343|      0|            sslSessionID *sid = ssl3_NewSessionID(ss, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 6344|      0|            if (!sid) {
  ------------------
  |  Branch (6344:17): [True: 0, False: 0]
  ------------------
 6345|      0|                return SECFailure;
 6346|      0|            }
 6347|       |
 6348|       |            /* Copy over the peerCert. */
 6349|      0|            PORT_Assert(ss->sec.ci.sid->peerCert);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6350|      0|            sid->peerCert = CERT_DupCertificate(ss->sec.ci.sid->peerCert);
 6351|      0|            if (!sid->peerCert) {
  ------------------
  |  Branch (6351:17): [True: 0, False: 0]
  ------------------
 6352|      0|                ssl_FreeSID(sid);
 6353|      0|                return SECFailure;
 6354|      0|            }
 6355|       |
 6356|       |            /* Destroy the old SID. */
 6357|      0|            ssl_UncacheSessionID(ss);
 6358|      0|            ssl_FreeSID(ss->sec.ci.sid);
 6359|      0|            ss->sec.ci.sid = sid;
 6360|      0|        }
 6361|       |
 6362|      0|        ssl3_SetSIDSessionTicket(ss->sec.ci.sid, &ticket);
 6363|      0|        PORT_Assert(!ticket.ticket.data);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 6364|       |
 6365|      0|        rv = tls13_HkdfExpandLabel(ss->ssl3.hs.resumptionMasterSecret,
 6366|      0|                                   tls13_GetHash(ss),
 6367|      0|                                   ticket_nonce.data, ticket_nonce.len,
 6368|      0|                                   kHkdfLabelResumption,
 6369|      0|                                   strlen(kHkdfLabelResumption),
 6370|      0|                                   CKM_HKDF_DERIVE,
  ------------------
  |  | 1296|      0|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
 6371|      0|                                   tls13_GetHashSize(ss),
 6372|      0|                                   ss->protocolVariant, &secret);
 6373|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (6373:13): [True: 0, False: 0]
  ------------------
 6374|      0|            return SECFailure;
 6375|      0|        }
 6376|       |
 6377|      0|        rv = ssl3_FillInCachedSID(ss, ss->sec.ci.sid, secret);
 6378|      0|        PK11_FreeSymKey(secret);
 6379|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (6379:13): [True: 0, False: 0]
  ------------------
 6380|      0|            return SECFailure;
 6381|      0|        }
 6382|       |
 6383|       |        /* Cache the session. */
 6384|      0|        ssl_CacheSessionID(ss);
 6385|      0|    }
 6386|       |
 6387|      0|    return SECSuccess;
 6388|      0|}
tls13con.c:tls13_HandleEndOfEarlyData:
 7000|      3|{
 7001|      3|    SECStatus rv;
 7002|       |
 7003|      3|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7004|       |
 7005|      3|    rv = TLS13_CHECK_HS_STATE(ss, SSL_ERROR_RX_UNEXPECTED_END_OF_EARLY_DATA,
  ------------------
  |  |  182|      3|    tls13_CheckHsState(ss, err, #err, __func__, __FILE__, __LINE__, \
  |  |  183|      3|                       __VA_ARGS__,                                 \
  |  |  184|      3|                       wait_invalid)
  ------------------
 7006|      3|                              wait_end_of_early_data);
 7007|      3|    if (rv != SECSuccess) {
  ------------------
  |  Branch (7007:9): [True: 3, False: 0]
  ------------------
 7008|      3|        return SECFailure;
 7009|      3|    }
 7010|       |
 7011|       |    /* We shouldn't be getting any more early data, and if we do,
 7012|       |     * it is because of reordering and we drop it. */
 7013|      0|    if (IS_DTLS(ss)) {
  ------------------
  |  |  892|      0|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 7014|      0|        ssl_CipherSpecReleaseByEpoch(ss, ssl_secret_read,
 7015|      0|                                     TrafficKeyEarlyApplicationData);
 7016|      0|        dtls_ReceivedFirstMessageInFlight(ss);
 7017|      0|    }
 7018|       |
 7019|      0|    PORT_Assert(ss->ssl3.hs.zeroRttState == ssl_0rtt_accepted);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 7020|       |
 7021|      0|    if (length) {
  ------------------
  |  Branch (7021:9): [True: 0, False: 0]
  ------------------
 7022|      0|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_END_OF_EARLY_DATA, decode_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 7023|      0|        return SECFailure;
 7024|      0|    }
 7025|       |
 7026|      0|    rv = tls13_SetCipherSpec(ss, TrafficKeyHandshake,
 7027|      0|                             ssl_secret_read, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 7028|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (7028:9): [True: 0, False: 0]
  ------------------
 7029|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 7030|      0|        return SECFailure;
 7031|      0|    }
 7032|       |
 7033|      0|    ss->ssl3.hs.zeroRttState = ssl_0rtt_done;
 7034|      0|    if (tls13_ShouldRequestClientAuth(ss)) {
  ------------------
  |  Branch (7034:9): [True: 0, False: 0]
  ------------------
 7035|      0|        TLS13_SET_HS_STATE(ss, wait_client_cert);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 7036|      0|    } else {
 7037|      0|        TLS13_SET_HS_STATE(ss, wait_finished);
  ------------------
  |  |   37|      0|    tls13_SetHsState(ss, ws, __func__, __FILE__, __LINE__)
  ------------------
 7038|      0|    }
 7039|      0|    return SECSuccess;
 7040|      0|}

tls13_Debug_CheckXtnBegins:
   36|     10|{
   37|     10|#ifdef DEBUG
   38|     10|    SECStatus rv;
   39|     10|    sslReader ext_reader = SSL_READER(start, 2);
  ------------------
  |  |   85|     10|    {                    \
  |  |   86|     10|        { b, l }, 0      \
  |  |   87|     10|    }
  ------------------
   40|     10|    PRUint64 extension_number;
   41|     10|    rv = sslRead_ReadNumber(&ext_reader, 2, &extension_number);
   42|     10|    return ((rv == SECSuccess) && (extension_number == xtnType));
  ------------------
  |  Branch (42:13): [True: 10, False: 0]
  |  Branch (42:35): [True: 10, False: 0]
  ------------------
   43|       |#else
   44|       |    return PR_TRUE;
   45|       |#endif
   46|     10|}
tls13_DestroyEchConfigs:
   64|  9.71k|{
   65|  9.71k|    PRCList *cur_p;
   66|  9.71k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|  9.71k|    ((_l)->next == (_l))
  ------------------
  |  Branch (66:12): [True: 0, False: 9.71k]
  ------------------
   67|      0|        cur_p = PR_LIST_TAIL(list);
  ------------------
  |  |   66|      0|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
   68|      0|        PR_REMOVE_LINK(cur_p);
  ------------------
  |  |   72|      0|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|      0|    (_e)->prev->next = (_e)->next; \
  |  |   74|      0|    (_e)->next->prev = (_e)->prev; \
  |  |   75|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   69|      0|        tls13_DestroyEchConfig((sslEchConfig *)cur_p);
   70|      0|    }
   71|  9.71k|}
tls13_DestroyEchXtnState:
   75|  90.3k|{
   76|  90.3k|    if (!state) {
  ------------------
  |  Branch (76:9): [True: 90.2k, False: 89]
  ------------------
   77|  90.2k|        return;
   78|  90.2k|    }
   79|     89|    SECITEM_FreeItem(&state->innerCh, PR_FALSE);
  ------------------
  |  |  108|     89|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&state->innerCh, PR_FALSE);
  ------------------
  |  |  438|     89|#define PR_FALSE 0
  ------------------
   80|     89|    SECITEM_FreeItem(&state->senderPubKey, PR_FALSE);
  ------------------
  |  |  108|     89|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&state->senderPubKey, PR_FALSE);
  ------------------
  |  |  438|     89|#define PR_FALSE 0
  ------------------
   81|     89|    SECITEM_FreeItem(&state->retryConfigs, PR_FALSE);
  ------------------
  |  |  108|     89|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&state->retryConfigs, PR_FALSE);
  ------------------
  |  |  438|     89|#define PR_FALSE 0
  ------------------
   82|     89|    PORT_ZFree(state, sizeof(*state));
  ------------------
  |  |   75|     89|#define PORT_ZFree PORT_ZFree_Util
  ------------------
   83|     89|}
tls13_CopyEchConfigs:
   87|  9.71k|{
   88|  9.71k|    SECStatus rv;
   89|  9.71k|    sslEchConfig *config;
   90|  9.71k|    sslEchConfig *newConfig = NULL;
   91|       |
   92|  9.71k|    for (PRCList *cur_p = PR_LIST_HEAD(oConfigs);
  ------------------
  |  |   65|  9.71k|#define PR_LIST_HEAD(_l) (_l)->next
  ------------------
   93|  9.71k|         cur_p != oConfigs;
  ------------------
  |  Branch (93:10): [True: 0, False: 9.71k]
  ------------------
   94|  9.71k|         cur_p = PR_NEXT_LINK(cur_p)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
   95|      0|        config = (sslEchConfig *)PR_LIST_TAIL(oConfigs);
  ------------------
  |  |   66|      0|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
   96|      0|        newConfig = PORT_ZNew(sslEchConfig);
  ------------------
  |  |  148|      0|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
   97|      0|        if (!newConfig) {
  ------------------
  |  Branch (97:13): [True: 0, False: 0]
  ------------------
   98|      0|            goto loser;
   99|      0|        }
  100|       |
  101|      0|        rv = SECITEM_CopyItem(NULL, &newConfig->raw, &config->raw);
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  102|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (102:13): [True: 0, False: 0]
  ------------------
  103|      0|            goto loser;
  104|      0|        }
  105|      0|        newConfig->contents.publicName = PORT_Strdup(config->contents.publicName);
  ------------------
  |  |   69|      0|#define PORT_Strdup PORT_Strdup_Util
  ------------------
  106|      0|        if (!newConfig->contents.publicName) {
  ------------------
  |  Branch (106:13): [True: 0, False: 0]
  ------------------
  107|      0|            goto loser;
  108|      0|        }
  109|      0|        rv = SECITEM_CopyItem(NULL, &newConfig->contents.publicKey,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  110|      0|                              &config->contents.publicKey);
  111|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (111:13): [True: 0, False: 0]
  ------------------
  112|      0|            goto loser;
  113|      0|        }
  114|      0|        rv = SECITEM_CopyItem(NULL, &newConfig->contents.suites,
  ------------------
  |  |  106|      0|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  115|      0|                              &config->contents.suites);
  116|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (116:13): [True: 0, False: 0]
  ------------------
  117|      0|            goto loser;
  118|      0|        }
  119|      0|        newConfig->contents.configId = config->contents.configId;
  120|      0|        newConfig->contents.kemId = config->contents.kemId;
  121|      0|        newConfig->contents.kdfId = config->contents.kdfId;
  122|      0|        newConfig->contents.aeadId = config->contents.aeadId;
  123|      0|        newConfig->contents.maxNameLen = config->contents.maxNameLen;
  124|      0|        newConfig->version = config->version;
  125|      0|        PR_APPEND_LINK(&newConfig->link, configs);
  ------------------
  |  |   57|      0|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|      0|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|      0|    (_e)->next = (_l);   \
  |  |  |  |   27|      0|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|      0|    (_l)->prev->next = (_e); \
  |  |  |  |   29|      0|    (_l)->prev = (_e);   \
  |  |  |  |   30|      0|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  126|      0|    }
  127|  9.71k|    return SECSuccess;
  128|       |
  129|      0|loser:
  130|      0|    tls13_DestroyEchConfig(newConfig);
  131|      0|    tls13_DestroyEchConfigs(configs);
  132|      0|    return SECFailure;
  133|  9.71k|}
tls13_GetMatchingEchConfigs:
  896|     11|{
  897|     11|    SSL_TRC(50, ("%d: TLS13[%d]: GetMatchingEchConfig %d",
  ------------------
  |  |   71|     11|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 11]
  |  |  ------------------
  |  |   72|     11|    ssl_Trace b
  ------------------
  898|     11|                 SSL_GETPID(), ss->fd, configId));
  899|       |
  900|       |    /* If |cur|, resume the search at that node, else the list head. */
  901|     11|    for (PRCList *cur_p = cur ? ((PRCList *)cur)->next : PR_LIST_HEAD(&ss->echConfigs);
  ------------------
  |  |   65|     11|#define PR_LIST_HEAD(_l) (_l)->next
  ------------------
  |  Branch (901:27): [True: 0, False: 11]
  ------------------
  902|     11|         cur_p != &ss->echConfigs;
  ------------------
  |  Branch (902:10): [True: 0, False: 11]
  ------------------
  903|     11|         cur_p = PR_NEXT_LINK(cur_p)) {
  ------------------
  |  |   47|      0|        ((_e)->next)
  ------------------
  904|      0|        sslEchConfig *echConfig = (sslEchConfig *)cur_p;
  905|      0|        if (echConfig->contents.configId == configId &&
  ------------------
  |  Branch (905:13): [True: 0, False: 0]
  ------------------
  906|      0|            echConfig->contents.aeadId == aead &&
  ------------------
  |  Branch (906:13): [True: 0, False: 0]
  ------------------
  907|      0|            echConfig->contents.kdfId == kdf) {
  ------------------
  |  Branch (907:13): [True: 0, False: 0]
  ------------------
  908|      0|            *next = echConfig;
  909|      0|            return SECSuccess;
  910|      0|        }
  911|      0|    }
  912|       |
  913|     11|    *next = NULL;
  914|     11|    return SECSuccess;
  915|     11|}
tls13_ComputeEchSignal:
 2030|     16|{
 2031|     16|    SECStatus rv;
 2032|     16|    sslBuffer confMsgs = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|     16|    {                        \
  |  |   24|     16|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|     16|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|     16|    }
  ------------------
 2033|     16|    SSL3Hashes hashes;
 2034|     16|    PK11SymKey *echSecret = NULL;
 2035|       |
 2036|     16|    const char *hkdfInfo = isHrr ? kHkdfInfoEchHrrConfirm : kHkdfInfoEchConfirm;
  ------------------
  |  Branch (2036:28): [True: 5, False: 11]
  ------------------
 2037|     16|    const size_t hkdfInfoLen = strlen(hkdfInfo);
 2038|       |
 2039|     16|    PRINT_BUF(100, (ss, "ECH Server Hello", sh, shLen));
  ------------------
  |  |   74|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   75|     16|    ssl_PrintBuf b
  ------------------
 2040|       |
 2041|     16|    if (isHrr) {
  ------------------
  |  Branch (2041:9): [True: 5, False: 11]
  ------------------
 2042|      5|        rv = tls13_ComputeEchHelloRetryTranscript(ss, sh, shLen, &confMsgs);
 2043|     11|    } else {
 2044|     11|        rv = tls13_ComputeEchServerHelloTranscript(ss, sh, shLen, &confMsgs);
 2045|     11|    }
 2046|     16|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2046:9): [True: 0, False: 16]
  ------------------
 2047|      0|        goto loser;
 2048|      0|    }
 2049|     16|    PRINT_BUF(100, (ss, "ECH Transcript", confMsgs.buf, confMsgs.len));
  ------------------
  |  |   74|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   75|     16|    ssl_PrintBuf b
  ------------------
 2050|     16|    rv = tls13_ComputeHash(ss, &hashes, confMsgs.buf, confMsgs.len,
 2051|     16|                           tls13_GetHash(ss));
 2052|     16|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2052:9): [True: 0, False: 16]
  ------------------
 2053|      0|        goto loser;
 2054|      0|    }
 2055|     16|    PRINT_BUF(100, (ss, "ECH Transcript Hash", &hashes.u, hashes.len));
  ------------------
  |  |   74|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   75|     16|    ssl_PrintBuf b
  ------------------
 2056|     16|    rv = tls13_DeriveEchSecret(ss, &echSecret);
 2057|     16|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2057:9): [True: 0, False: 16]
  ------------------
 2058|      0|        return SECFailure;
 2059|      0|    }
 2060|     16|    rv = tls13_HkdfExpandLabelRaw(echSecret, tls13_GetHash(ss), hashes.u.raw,
 2061|     16|                                  hashes.len, hkdfInfo, hkdfInfoLen, ss->protocolVariant,
 2062|     16|                                  out, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|     16|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2063|     16|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2063:9): [True: 0, False: 16]
  ------------------
 2064|      0|        return SECFailure;
 2065|      0|    }
 2066|     16|    SSL_TRC(50, ("%d: TLS13[%d]: %s computed ECH signal", SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
  ------------------
  |  |   71|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   72|     16|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2067|     16|    PRINT_BUF(50, (ss, "Computed ECH Signal", out, TLS13_ECH_SIGNAL_LEN));
  ------------------
  |  |   74|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   75|     16|    ssl_PrintBuf b
  ------------------
 2068|     16|    PK11_FreeSymKey(echSecret);
 2069|     16|    sslBuffer_Clear(&confMsgs);
 2070|     16|    return SECSuccess;
 2071|       |
 2072|      0|loser:
 2073|      0|    PK11_FreeSymKey(echSecret);
 2074|      0|    sslBuffer_Clear(&confMsgs);
 2075|      0|    return SECFailure;
 2076|     16|}
tls13_DeriveEchSecret:
 2082|     16|{
 2083|     16|    SECStatus rv;
 2084|     16|    PK11SlotInfo *slot = NULL;
 2085|     16|    PK11SymKey *crKey = NULL;
 2086|     16|    SECItem rawKey;
 2087|     16|    const unsigned char *client_random = ss->sec.isServer ? ss->ssl3.hs.client_random : ss->ssl3.hs.client_inner_random;
  ------------------
  |  Branch (2087:42): [True: 16, False: 0]
  ------------------
 2088|     16|    PRINT_BUF(50, (ss, "Client Random for ECH", client_random, SSL3_RANDOM_LENGTH));
  ------------------
  |  |   74|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   75|     16|    ssl_PrintBuf b
  ------------------
 2089|       |    /* We need a SECItem */
 2090|     16|    rv = SECITEM_MakeItem(NULL, &rawKey, client_random, SSL3_RANDOM_LENGTH);
  ------------------
  |  |   24|     16|#define SSL3_RANDOM_LENGTH 32
  ------------------
 2091|     16|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2091:9): [True: 0, False: 16]
  ------------------
 2092|      0|        goto cleanup;
 2093|      0|    }
 2094|       |    /* We need a slot*/
 2095|     16|    slot = PK11_GetBestSlot(CKM_HKDF_DERIVE, NULL);
  ------------------
  |  | 1296|     16|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
 2096|     16|    if (!slot) {
  ------------------
  |  Branch (2096:9): [True: 0, False: 16]
  ------------------
 2097|      0|        rv = SECFailure;
 2098|      0|        goto cleanup;
 2099|      0|    }
 2100|       |    /* We import the key */
 2101|     16|    crKey = PK11_ImportDataKey(slot, CKM_HKDF_DERIVE, PK11_OriginUnwrap,
  ------------------
  |  | 1296|     16|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
 2102|     16|                               CKA_DERIVE, &rawKey, NULL);
  ------------------
  |  |  555|     16|#define CKA_DERIVE 0x0000010CUL
  ------------------
 2103|     16|    if (crKey == NULL) {
  ------------------
  |  Branch (2103:9): [True: 0, False: 16]
  ------------------
 2104|      0|        rv = SECFailure;
 2105|      0|        goto cleanup;
 2106|      0|    }
 2107|       |    /* NULL will be expanded to 0s of hash length */
 2108|     16|    rv = tls13_HkdfExtract(NULL, crKey, tls13_GetHash(ss), output);
 2109|     16|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2109:9): [True: 0, False: 16]
  ------------------
 2110|      0|        goto cleanup;
 2111|      0|    }
 2112|     16|    SSL_TRC(50, ("%d: TLS13[%d]: ECH Confirmation Key Derived.",
  ------------------
  |  |   71|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   72|     16|    ssl_Trace b
  ------------------
 2113|     16|                 SSL_GETPID(), ss->fd));
 2114|     16|    PRINT_KEY(50, (NULL, "ECH Confirmation Key", *output));
  ------------------
  |  |   77|     16|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (77:9): [True: 0, False: 16]
  |  |  ------------------
  |  |   78|     16|    ssl_PrintKey b
  ------------------
 2115|     16|cleanup:
 2116|     16|    SECITEM_ZfreeItem(&rawKey, PR_FALSE);
  ------------------
  |  |  110|     16|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                  SECITEM_ZfreeItem(&rawKey, PR_FALSE);
  ------------------
  |  |  438|     16|#define PR_FALSE 0
  ------------------
 2117|     16|    if (slot) {
  ------------------
  |  Branch (2117:9): [True: 16, False: 0]
  ------------------
 2118|     16|        PK11_FreeSlot(slot);
 2119|     16|    }
 2120|     16|    if (crKey) {
  ------------------
  |  Branch (2120:9): [True: 16, False: 0]
  ------------------
 2121|     16|        PK11_FreeSymKey(crKey);
 2122|     16|    }
 2123|     16|    if (rv != SECSuccess && *output) {
  ------------------
  |  Branch (2123:9): [True: 0, False: 16]
  |  Branch (2123:29): [True: 0, False: 0]
  ------------------
 2124|      0|        PK11_FreeSymKey(*output);
 2125|      0|        *output = NULL;
 2126|      0|    }
 2127|     16|    return rv;
 2128|     16|}
tls13_MaybeHandleEch:
 2295|  1.88k|{
 2296|  1.88k|    SECStatus rv;
 2297|  1.88k|    SECItem *tmpEchInner = NULL;
 2298|  1.88k|    PRUint8 *b;
 2299|  1.88k|    PRUint32 length;
 2300|  1.88k|    TLSExtension *echExtension;
 2301|  1.88k|    TLSExtension *versionExtension;
 2302|  1.88k|    PORT_Assert(!ss->ssl3.hs.echAccepted);
  ------------------
  |  |  120|  1.88k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.88k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.88k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2303|  1.88k|    SECItem tmpSid = { siBuffer, NULL, 0 };
 2304|  1.88k|    SECItem tmpCookie = { siBuffer, NULL, 0 };
 2305|  1.88k|    SECItem tmpSuites = { siBuffer, NULL, 0 };
 2306|  1.88k|    SECItem tmpComps = { siBuffer, NULL, 0 };
 2307|       |
 2308|  1.88k|    echExtension = ssl3_FindExtension(ss, ssl_tls13_encrypted_client_hello_xtn);
 2309|  1.88k|    if (echExtension) {
  ------------------
  |  Branch (2309:9): [True: 94, False: 1.79k]
  ------------------
 2310|     94|        rv = tls13_ServerHandleOuterEchXtn(ss, &ss->xtnData, &echExtension->data);
 2311|     94|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2311:13): [True: 16, False: 78]
  ------------------
 2312|     16|            goto loser; /* code set, alert sent. */
 2313|     16|        }
 2314|     78|        rv = tls13_MaybeAcceptEch(ss, sidBytes, msg, msgLen, &tmpEchInner);
 2315|     78|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2315:13): [True: 16, False: 62]
  ------------------
 2316|     16|            goto loser; /* code set, alert sent. */
 2317|     16|        }
 2318|     78|    }
 2319|  1.85k|    ss->ssl3.hs.preliminaryInfo |= ssl_preinfo_ech;
  ------------------
  |  |  398|  1.85k|#define ssl_preinfo_ech (1U << 4)
  ------------------
 2320|       |
 2321|  1.85k|    if (ss->ssl3.hs.echAccepted) {
  ------------------
  |  Branch (2321:9): [True: 0, False: 1.85k]
  ------------------
 2322|      0|        PORT_Assert(tmpEchInner);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2323|      0|        PORT_Assert(!PR_CLIST_IS_EMPTY(&ss->ssl3.hs.remoteExtensions));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2324|       |
 2325|       |        /* Start over on ECHInner */
 2326|      0|        b = tmpEchInner->data;
 2327|      0|        length = tmpEchInner->len;
 2328|      0|        rv = ssl3_HandleClientHelloPreamble(ss, &b, &length, &tmpSid,
 2329|      0|                                            &tmpCookie, &tmpSuites, &tmpComps);
 2330|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2330:13): [True: 0, False: 0]
  ------------------
 2331|      0|            goto loser; /* code set, alert sent. */
 2332|      0|        }
 2333|       |
 2334|      0|        versionExtension = ssl3_FindExtension(ss, ssl_tls13_supported_versions_xtn);
 2335|      0|        if (!versionExtension) {
  ------------------
  |  Branch (2335:13): [True: 0, False: 0]
  ------------------
 2336|      0|            FATAL_ERROR(ss, SSL_ERROR_UNSUPPORTED_VERSION, illegal_parameter);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2337|      0|            goto loser;
 2338|      0|        }
 2339|      0|        rv = tls13_NegotiateVersion(ss, versionExtension);
 2340|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2340:13): [True: 0, False: 0]
  ------------------
 2341|       |            /* code and alert set by tls13_NegotiateVersion */
 2342|      0|            goto loser;
 2343|      0|        }
 2344|       |
 2345|      0|        *comps = tmpComps;
 2346|      0|        *cookieBytes = tmpCookie;
 2347|      0|        *sidBytes = tmpSid;
 2348|      0|        *suites = tmpSuites;
 2349|      0|        *echInner = tmpEchInner;
 2350|      0|    }
 2351|  1.85k|    return SECSuccess;
 2352|       |
 2353|     32|loser:
 2354|     32|    SECITEM_FreeItem(tmpEchInner, PR_TRUE);
  ------------------
  |  |  108|     32|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(tmpEchInner, PR_TRUE);
  ------------------
  |  |  437|     32|#define PR_TRUE 1
  ------------------
 2355|     32|    PORT_Assert(PORT_GetError() != 0);
  ------------------
  |  |  120|     32|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     32|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 32, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2356|     32|    return SECFailure;
 2357|  1.85k|}
tls13_MaybeAcceptEch:
 2652|     78|{
 2653|     78|    SECStatus rv;
 2654|     78|    SECItem outer = { siBuffer, CONST_CAST(PRUint8, chOuter), chOuterLen };
  ------------------
  |  |   96|     78|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
 2655|     78|    SECItem *decryptedChInner = NULL;
 2656|     78|    SECItem outerAAD = { siBuffer, NULL, 0 };
 2657|     78|    SECItem cookieData = { siBuffer, NULL, 0 };
 2658|     78|    sslEchCookieData echData;
 2659|     78|    sslEchConfig *candidate = NULL; /* non-owning */
 2660|     78|    TLSExtension *hrrXtn;
 2661|     78|    PRBool previouslyOfferedEch;
 2662|       |
 2663|     78|    if (!ss->xtnData.ech || ss->xtnData.ech->receivedInnerXtn || IS_DTLS(ss)) {
  ------------------
  |  |  892|     61|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  |  |  ------------------
  |  |  |  Branch (892:21): [True: 0, False: 61]
  |  |  ------------------
  ------------------
  |  Branch (2663:9): [True: 0, False: 78]
  |  Branch (2663:29): [True: 17, False: 61]
  ------------------
 2664|     17|        ss->ssl3.hs.echDecided = PR_TRUE;
  ------------------
  |  |  437|     17|#define PR_TRUE 1
  ------------------
 2665|     17|        return SECSuccess;
 2666|     17|    }
 2667|       |
 2668|     61|    PORT_Assert(ss->xtnData.ech->innerCh.data);
  ------------------
  |  |  120|     61|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     61|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 61, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2669|       |
 2670|     61|    if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (2670:9): [True: 50, False: 11]
  ------------------
 2671|     50|        ss->ssl3.hs.echDecided = PR_TRUE;
  ------------------
  |  |  437|     50|#define PR_TRUE 1
  ------------------
 2672|     50|        PORT_Assert(!ss->ssl3.hs.echHpkeCtx);
  ------------------
  |  |  120|     50|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     50|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 50, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2673|     50|        hrrXtn = ssl3_FindExtension(ss, ssl_tls13_cookie_xtn);
 2674|     50|        if (!hrrXtn) {
  ------------------
  |  Branch (2674:13): [True: 3, False: 47]
  ------------------
 2675|       |            /* If the client doesn't echo cookie, we can't decrypt. */
 2676|      3|            return SECSuccess;
 2677|      3|        }
 2678|       |
 2679|     47|        PORT_Assert(!ss->ssl3.hs.echHpkeCtx);
  ------------------
  |  |  120|     47|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     47|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 47, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2680|       |
 2681|     47|        PRUint8 *tmp = hrrXtn->data.data;
 2682|     47|        PRUint32 len = hrrXtn->data.len;
 2683|     47|        rv = ssl3_ExtConsumeHandshakeVariable(ss, &cookieData, 2,
 2684|     47|                                              &tmp, &len);
 2685|     47|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2685:13): [True: 1, False: 46]
  ------------------
 2686|      1|            return SECFailure;
 2687|      1|        }
 2688|       |
 2689|       |        /* Extract ECH info without restoring hash state. If there's
 2690|       |         * something wrong with the cookie, continue without ECH
 2691|       |         * and let HRR code handle the problem. */
 2692|     46|        rv = tls13_HandleHrrCookie(ss, cookieData.data, cookieData.len,
 2693|     46|                                   NULL, NULL, &previouslyOfferedEch, &echData, PR_FALSE);
  ------------------
  |  |  438|     46|#define PR_FALSE 0
  ------------------
 2694|     46|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2694:13): [True: 26, False: 20]
  ------------------
 2695|     26|            return SECSuccess;
 2696|     26|        }
 2697|       |
 2698|     20|        ss->ssl3.hs.echHpkeCtx = echData.hpkeCtx;
 2699|       |
 2700|     20|        const PRUint8 greaseConstant[TLS13_ECH_SIGNAL_LEN] = { 0 };
 2701|     20|        ss->ssl3.hs.echAccepted = previouslyOfferedEch &&
  ------------------
  |  Branch (2701:35): [True: 0, False: 20]
  ------------------
 2702|     20|                                  !NSS_SecureMemcmp(greaseConstant, echData.signal, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|      0|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
  |  Branch (2702:35): [True: 0, False: 0]
  ------------------
 2703|       |
 2704|     20|        if (echData.configId != ss->xtnData.ech->configId ||
  ------------------
  |  Branch (2704:13): [True: 1, False: 19]
  ------------------
 2705|     20|            echData.kdfId != ss->xtnData.ech->kdfId ||
  ------------------
  |  Branch (2705:13): [True: 11, False: 8]
  ------------------
 2706|     20|            echData.aeadId != ss->xtnData.ech->aeadId) {
  ------------------
  |  Branch (2706:13): [True: 3, False: 5]
  ------------------
 2707|     15|            FATAL_ERROR(ss, SSL_ERROR_BAD_2ND_CLIENT_HELLO,
  ------------------
  |  |  175|     15|    do {                                     \
  |  |  176|     15|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|     15|    do {                                                                           \
  |  |  |  |  168|     15|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     15|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 15]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     15|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|     15|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|     15|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     15|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|     15|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|     15|        tls13_FatalError(ss, prError, desc); \
  |  |  178|     15|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2708|     15|                        illegal_parameter);
 2709|     15|            return SECFailure;
 2710|     15|        }
 2711|       |
 2712|      5|        if (!ss->ssl3.hs.echHpkeCtx) {
  ------------------
  |  Branch (2712:13): [True: 5, False: 0]
  ------------------
 2713|      5|            return SECSuccess;
 2714|      5|        }
 2715|      5|    }
 2716|       |
 2717|     11|    if (ss->ssl3.hs.echDecided && !ss->ssl3.hs.echAccepted) {
  ------------------
  |  Branch (2717:9): [True: 0, False: 11]
  |  Branch (2717:35): [True: 0, False: 0]
  ------------------
 2718|       |        /* We don't change our mind */
 2719|      0|        return SECSuccess;
 2720|      0|    }
 2721|       |    /* Regardless of where we return, the outcome is decided */
 2722|     11|    ss->ssl3.hs.echDecided = PR_TRUE;
  ------------------
  |  |  437|     11|#define PR_TRUE 1
  ------------------
 2723|       |
 2724|       |    /* Cookie data was good, proceed with ECH. */
 2725|     11|    rv = tls13_GetMatchingEchConfigs(ss, ss->xtnData.ech->kdfId, ss->xtnData.ech->aeadId,
 2726|     11|                                     ss->xtnData.ech->configId, candidate, &candidate);
 2727|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2727:9): [True: 0, False: 11]
  ------------------
 2728|      0|        FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2729|      0|        return SECFailure;
 2730|      0|    }
 2731|       |
 2732|     11|    if (candidate) {
  ------------------
  |  Branch (2732:9): [True: 0, False: 11]
  ------------------
 2733|      0|        rv = tls13_ServerMakeChOuterAAD(ss, chOuter, chOuterLen, &outerAAD);
 2734|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2734:13): [True: 0, False: 0]
  ------------------
 2735|      0|            return SECFailure;
 2736|      0|        }
 2737|      0|    }
 2738|       |
 2739|     11|    while (candidate) {
  ------------------
  |  Branch (2739:12): [True: 0, False: 11]
  ------------------
 2740|      0|        rv = tls13_OpenClientHelloInner(ss, &outer, &outerAAD, candidate, &decryptedChInner);
 2741|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2741:13): [True: 0, False: 0]
  ------------------
 2742|       |            /* Get the next matching config */
 2743|      0|            rv = tls13_GetMatchingEchConfigs(ss, ss->xtnData.ech->kdfId, ss->xtnData.ech->aeadId,
 2744|      0|                                             ss->xtnData.ech->configId, candidate, &candidate);
 2745|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (2745:17): [True: 0, False: 0]
  ------------------
 2746|      0|                FATAL_ERROR(ss, SEC_ERROR_LIBRARY_FAILURE, internal_error);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2747|      0|                SECITEM_FreeItem(&outerAAD, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                              SECITEM_FreeItem(&outerAAD, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 2748|      0|                return SECFailure;
 2749|      0|            }
 2750|      0|            continue;
 2751|      0|        }
 2752|      0|        break;
 2753|      0|    }
 2754|     11|    SECITEM_FreeItem(&outerAAD, PR_FALSE);
  ------------------
  |  |  108|     11|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&outerAAD, PR_FALSE);
  ------------------
  |  |  438|     11|#define PR_FALSE 0
  ------------------
 2755|       |
 2756|     11|    if (rv != SECSuccess || !decryptedChInner) {
  ------------------
  |  Branch (2756:9): [True: 0, False: 11]
  |  Branch (2756:29): [True: 11, False: 0]
  ------------------
 2757|     11|        if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (2757:13): [True: 0, False: 11]
  ------------------
 2758|      0|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_ECH_EXTENSION, decrypt_error);
  ------------------
  |  |  175|      0|    do {                                     \
  |  |  176|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |  167|      0|    do {                                                                           \
  |  |  |  |  168|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |  169|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |  170|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |  171|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (171:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  177|      0|        tls13_FatalError(ss, prError, desc); \
  |  |  178|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (178:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
 2759|      0|            return SECFailure;
 2760|     11|        } else {
 2761|       |            /* Send retry_configs (if we have any) when we fail to decrypt or
 2762|       |             * found no candidates. This does *not* count as negotiating ECH. */
 2763|     11|            return ssl3_RegisterExtensionSender(ss, &ss->xtnData,
 2764|     11|                                                ssl_tls13_encrypted_client_hello_xtn,
 2765|     11|                                                tls13_ServerSendEchXtn);
 2766|     11|        }
 2767|     11|    }
 2768|       |
 2769|      0|    SSL_TRC(20, ("%d: TLS13[%d]: Successfully opened ECH inner CH",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 2770|      0|                 SSL_GETPID(), ss->fd));
 2771|      0|    PRINT_BUF(50, (ss, "Compressed CHInner", decryptedChInner->data,
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 2772|      0|                   decryptedChInner->len));
 2773|       |
 2774|      0|    ss->ssl3.hs.echAccepted = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2775|       |
 2776|       |    /* Stash the CHOuter extensions. They're not yet handled (only parsed). If
 2777|       |     * the CHInner contains outer_extensions_xtn, we'll need to reference them. */
 2778|      0|    ssl3_MoveRemoteExtensions(&ss->ssl3.hs.echOuterExtensions, &ss->ssl3.hs.remoteExtensions);
 2779|       |
 2780|      0|    rv = tls13_UnencodeChInner(ss, sidBytes, &decryptedChInner);
 2781|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2781:9): [True: 0, False: 0]
  ------------------
 2782|      0|        SECITEM_FreeItem(decryptedChInner, PR_TRUE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                      SECITEM_FreeItem(decryptedChInner, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2783|      0|        return SECFailure; /* code set */
 2784|      0|    }
 2785|      0|    PRINT_BUF(50, (ss, "Uncompressed CHInner", decryptedChInner->data,
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
 2786|      0|                   decryptedChInner->len));
 2787|      0|    *chInner = decryptedChInner;
 2788|      0|    return SECSuccess;
 2789|      0|}
tls13_WriteServerEchSignal:
 2793|     11|{
 2794|     11|    SECStatus rv;
 2795|     11|    PRUint8 signal[TLS13_ECH_SIGNAL_LEN];
 2796|     11|    PRUint8 *msg_random = &sh[sizeof(SSL3ProtocolVersion)];
 2797|       |
 2798|     11|    PORT_Assert(shLen > sizeof(SSL3ProtocolVersion) + SSL3_RANDOM_LENGTH);
  ------------------
  |  |  120|     11|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2799|     11|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|     11|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2800|       |
 2801|     11|    rv = tls13_ComputeEchSignal(ss, PR_FALSE, sh, shLen, signal);
  ------------------
  |  |  438|     11|#define PR_FALSE 0
  ------------------
 2802|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2802:9): [True: 0, False: 11]
  ------------------
 2803|      0|        return SECFailure;
 2804|      0|    }
 2805|     11|    PRUint8 *dest = &msg_random[SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN];
  ------------------
  |  |   24|     11|#define SSL3_RANDOM_LENGTH 32
  ------------------
                  PRUint8 *dest = &msg_random[SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN];
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2806|     11|    PORT_Memcpy(dest, signal, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  180|     11|#define PORT_Memcpy memcpy
  ------------------
                  PORT_Memcpy(dest, signal, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2807|       |
 2808|       |    /* Keep the socket copy consistent. */
 2809|     11|    PORT_Assert(0 == memcmp(msg_random, &ss->ssl3.hs.server_random, SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN));
  ------------------
  |  |  120|     11|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 11, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2810|     11|    dest = &ss->ssl3.hs.server_random[SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN];
  ------------------
  |  |   24|     11|#define SSL3_RANDOM_LENGTH 32
  ------------------
                  dest = &ss->ssl3.hs.server_random[SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN];
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2811|     11|    PORT_Memcpy(dest, signal, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  180|     11|#define PORT_Memcpy memcpy
  ------------------
                  PORT_Memcpy(dest, signal, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2812|       |
 2813|     11|    return SECSuccess;
 2814|     11|}
tls13_WriteServerEchHrrSignal:
 2818|      5|{
 2819|      5|    SECStatus rv;
 2820|      5|    PR_ASSERT(shLen >= 4 + TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  ------------------
  ------------------
 2821|       |    /* We put the HRR ECH extension last. */
 2822|      5|    PRUint8 *placeholder_location = sh + shLen - TLS13_ECH_SIGNAL_LEN;
  ------------------
  |  |   25|      5|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2823|       |    /* Defensive check that we are overwriting the contents of the right extension */
 2824|      5|    PR_ASSERT(tls13_Debug_CheckXtnBegins(placeholder_location - 4, ssl_tls13_encrypted_client_hello_xtn));
  ------------------
  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  ------------------
  ------------------
 2825|       |    /* Calculate signal and overwrite */
 2826|      5|    rv = tls13_ComputeEchSignal(ss, PR_TRUE, sh, shLen, placeholder_location);
  ------------------
  |  |  437|      5|#define PR_TRUE 1
  ------------------
 2827|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2827:9): [True: 0, False: 5]
  ------------------
 2828|      0|        return SECFailure;
 2829|      0|    }
 2830|       |    /* Free HRR GREASE/accept_confirmation value, it MUST be restored from
 2831|       |     * cookie when handling CH2 after HRR. */
 2832|      5|    sslBuffer_Clear(&ss->ssl3.hs.greaseEchBuf);
 2833|      5|    return SECSuccess;
 2834|      5|}
tls13ech.c:tls13_ComputeEchHelloRetryTranscript:
 1865|      5|{
 1866|      5|    SECStatus rv;
 1867|      5|    PRUint8 zeroedEchSignal[TLS13_ECH_SIGNAL_LEN] = { 0 };
 1868|      5|    sslBuffer *previousTranscript;
 1869|       |
 1870|      5|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1870:9): [True: 5, False: 0]
  ------------------
 1871|      5|        previousTranscript = &(ss->ssl3.hs.messages);
 1872|      5|    } else {
 1873|      0|        previousTranscript = &(ss->ssl3.hs.echInnerMessages);
 1874|      0|    }
 1875|       |    /*
 1876|       |     *  This segment calculates the hash of the Client Hello
 1877|       |     *  TODO(djackson@mozilla.com) - Replace with existing function?
 1878|       |     *  e.g. tls13_ReinjectHandshakeTranscript
 1879|       |     *  TODO(djackson@mozilla.com) - Replace with streaming version
 1880|       |     */
 1881|      5|    if (!ss->ssl3.hs.helloRetry || !ss->sec.isServer) {
  ------------------
  |  Branch (1881:9): [True: 5, False: 0]
  |  Branch (1881:36): [True: 0, False: 0]
  ------------------
 1882|       |        /*
 1883|       |         * This function can be called in three situations:
 1884|       |         *    - By the server, prior to sending the HRR, when ECH was accepted
 1885|       |         *    - By the client, after receiving the HRR, but before it knows whether ECH was accepted
 1886|       |         *    - By the server, after accepting ECH and receiving CH2 when it needs to reconstruct the HRR
 1887|       |         * In the first two situations, we need to include the message hash of inner ClientHello1 but don't
 1888|       |         * want to alter the buffer containing the current transcript.
 1889|       |         * In the last, the buffer already contains the message hash of inner ClientHello1.
 1890|       |         */
 1891|      5|        SSL3Hashes hashes;
 1892|      5|        rv = tls13_ComputeHash(ss, &hashes, previousTranscript->buf, previousTranscript->len, tls13_GetHash(ss));
 1893|      5|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1893:13): [True: 0, False: 5]
  ------------------
 1894|      0|            goto loser;
 1895|      0|        }
 1896|      5|        rv = sslBuffer_AppendNumber(out, ssl_hs_message_hash, 1);
 1897|      5|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1897:13): [True: 0, False: 5]
  ------------------
 1898|      0|            goto loser;
 1899|      0|        }
 1900|      5|        rv = sslBuffer_AppendNumber(out, hashes.len, 3);
 1901|      5|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1901:13): [True: 0, False: 5]
  ------------------
 1902|      0|            goto loser;
 1903|      0|        }
 1904|      5|        rv = sslBuffer_Append(out, hashes.u.raw, hashes.len);
 1905|      5|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1905:13): [True: 0, False: 5]
  ------------------
 1906|      0|            goto loser;
 1907|      0|        }
 1908|      5|    } else {
 1909|      0|        rv = sslBuffer_AppendBuffer(out, previousTranscript);
 1910|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1910:13): [True: 0, False: 0]
  ------------------
 1911|      0|            goto loser;
 1912|      0|        }
 1913|      0|    }
 1914|       |    /* Ensure the first ClientHello has been hashed. */
 1915|      5|    PR_ASSERT(out->len == tls13_GetHashSize(ss) + 4);
  ------------------
  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  ------------------
  ------------------
 1916|      5|    PRINT_BUF(100, (ss, "ECH Client Hello Message Hash", out->buf, out->len));
  ------------------
  |  |   74|      5|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 5]
  |  |  ------------------
  |  |   75|      5|    ssl_PrintBuf b
  ------------------
 1917|       |    /* Message Header */
 1918|      5|    rv = sslBuffer_AppendNumber(out, ssl_hs_server_hello, 1);
 1919|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1919:9): [True: 0, False: 5]
  ------------------
 1920|      0|        goto loser;
 1921|      0|    }
 1922|       |    /* Message Size */
 1923|      5|    rv = sslBuffer_AppendNumber(out, shLen, 3);
 1924|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1924:9): [True: 0, False: 5]
  ------------------
 1925|      0|        goto loser;
 1926|      0|    }
 1927|       |    /* Calculate where the HRR ECH Xtn Signal begins */
 1928|      5|    unsigned int absEchOffset;
 1929|      5|    if (ss->sec.isServer) {
  ------------------
  |  Branch (1929:9): [True: 5, False: 0]
  ------------------
 1930|       |        /* We know the ECH HRR Xtn is last */
 1931|      5|        PORT_Assert(shLen >= TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  120|      5|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1932|      5|        absEchOffset = shLen - TLS13_ECH_SIGNAL_LEN;
  ------------------
  |  |   25|      5|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 1933|      5|    } else {
 1934|       |        /* We parsed the offset earlier */
 1935|       |        /* The result of pointer comparision is unspecified
 1936|       |         * (and pointer arithemtic is undefined) if the pointers
 1937|       |         * do not point to the same array or struct. That means these
 1938|       |         * asserts cannot be relied on for correctness in compiled code,
 1939|       |         * but may help the reader understand the requirements.
 1940|       |         */
 1941|      0|        PORT_Assert(ss->xtnData.ech->hrrConfirmation > sh);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1942|      0|        PORT_Assert(ss->xtnData.ech->hrrConfirmation < sh + shLen);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1943|      0|        absEchOffset = ss->xtnData.ech->hrrConfirmation - sh;
 1944|      0|    }
 1945|      5|    PR_ASSERT(tls13_Debug_CheckXtnBegins(sh + absEchOffset - 4, ssl_tls13_encrypted_client_hello_xtn));
  ------------------
  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  ------------------
  ------------------
 1946|       |    /* The HRR up to the ECH Xtn signal */
 1947|      5|    rv = sslBuffer_Append(out, sh, absEchOffset);
 1948|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1948:9): [True: 0, False: 5]
  ------------------
 1949|      0|        goto loser;
 1950|      0|    }
 1951|      5|    rv = sslBuffer_Append(out, zeroedEchSignal, sizeof(zeroedEchSignal));
 1952|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1952:9): [True: 0, False: 5]
  ------------------
 1953|      0|        goto loser;
 1954|      0|    }
 1955|      5|    PR_ASSERT(absEchOffset + TLS13_ECH_SIGNAL_LEN <= shLen);
  ------------------
  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  ------------------
  ------------------
 1956|       |    /* The remainder of the HRR */
 1957|      5|    rv = sslBuffer_Append(out, sh + absEchOffset + TLS13_ECH_SIGNAL_LEN, shLen - absEchOffset - TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|      5|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
                  rv = sslBuffer_Append(out, sh + absEchOffset + TLS13_ECH_SIGNAL_LEN, shLen - absEchOffset - TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|      5|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 1958|      5|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1958:9): [True: 0, False: 5]
  ------------------
 1959|      0|        goto loser;
 1960|      0|    }
 1961|      5|    PR_ASSERT(out->len == tls13_GetHashSize(ss) + 4 + shLen + 4);
  ------------------
  |  |  208|      5|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 5, False: 0]
  |  |  ------------------
  ------------------
 1962|      5|    return SECSuccess;
 1963|      0|loser:
 1964|      0|    sslBuffer_Clear(out);
 1965|      0|    return SECFailure;
 1966|      5|}
tls13ech.c:tls13_ComputeEchServerHelloTranscript:
 1970|     11|{
 1971|     11|    SECStatus rv;
 1972|     11|    sslBuffer *chSource = ss->sec.isServer ? &ss->ssl3.hs.messages : &ss->ssl3.hs.echInnerMessages;
  ------------------
  |  Branch (1972:27): [True: 11, False: 0]
  ------------------
 1973|     11|    unsigned int offset = sizeof(SSL3ProtocolVersion) +
 1974|     11|                          SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN;
  ------------------
  |  |   24|     11|#define SSL3_RANDOM_LENGTH 32
  ------------------
                                        SSL3_RANDOM_LENGTH - TLS13_ECH_SIGNAL_LEN;
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 1975|     11|    PORT_Assert(sh && shLen > offset);
  ------------------
  |  |  120|     11|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     22|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 11, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 11, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1976|     11|    PORT_Assert(TLS13_ECH_SIGNAL_LEN <= SSL3_RANDOM_LENGTH);
  ------------------
  |  |  120|     11|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     11|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1977|       |
 1978|       |    /* TODO(djackson@mozilla.com) - Replace with streaming version */
 1979|       |
 1980|     11|    rv = sslBuffer_AppendBuffer(out, chSource);
 1981|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1981:9): [True: 0, False: 11]
  ------------------
 1982|      0|        goto loser;
 1983|      0|    }
 1984|       |
 1985|       |    /* Re-create the message header. */
 1986|     11|    rv = sslBuffer_AppendNumber(out, ssl_hs_server_hello, 1);
 1987|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1987:9): [True: 0, False: 11]
  ------------------
 1988|      0|        goto loser;
 1989|      0|    }
 1990|       |
 1991|     11|    rv = sslBuffer_AppendNumber(out, shLen, 3);
 1992|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1992:9): [True: 0, False: 11]
  ------------------
 1993|      0|        goto loser;
 1994|      0|    }
 1995|       |
 1996|       |    /* Copy the version and 24B of server_random. */
 1997|     11|    rv = sslBuffer_Append(out, sh, offset);
 1998|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1998:9): [True: 0, False: 11]
  ------------------
 1999|      0|        goto loser;
 2000|      0|    }
 2001|       |
 2002|       |    /* Zero the signal placeholder. */
 2003|     11|    rv = sslBuffer_AppendNumber(out, 0, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2004|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2004:9): [True: 0, False: 11]
  ------------------
 2005|      0|        goto loser;
 2006|      0|    }
 2007|     11|    offset += TLS13_ECH_SIGNAL_LEN;
  ------------------
  |  |   25|     11|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
 2008|       |
 2009|       |    /* Use the remainder of SH. */
 2010|     11|    rv = sslBuffer_Append(out, &sh[offset], shLen - offset);
 2011|     11|    if (rv != SECSuccess) {
  ------------------
  |  Branch (2011:9): [True: 0, False: 11]
  ------------------
 2012|      0|        goto loser;
 2013|      0|    }
 2014|     11|    sslBuffer_Clear(&ss->ssl3.hs.messages);
 2015|     11|    sslBuffer_Clear(&ss->ssl3.hs.echInnerMessages);
 2016|     11|    return SECSuccess;
 2017|      0|loser:
 2018|      0|    sslBuffer_Clear(&ss->ssl3.hs.messages);
 2019|      0|    sslBuffer_Clear(&ss->ssl3.hs.echInnerMessages);
 2020|      0|    sslBuffer_Clear(out);
 2021|      0|    return SECFailure;
 2022|     11|}

tls13_ServerSendStatusRequestXtn:
   25|     19|{
   26|     19|    const sslServerCert *serverCert = ss->sec.serverCert;
   27|     19|    const SECItem *item;
   28|     19|    SECStatus rv;
   29|       |
   30|     19|    if (!serverCert->certStatusArray ||
  ------------------
  |  Branch (30:9): [True: 19, False: 0]
  ------------------
   31|     19|        !serverCert->certStatusArray->len) {
  ------------------
  |  Branch (31:9): [True: 0, False: 0]
  ------------------
   32|     19|        return SECSuccess;
   33|     19|    }
   34|       |
   35|      0|    item = &serverCert->certStatusArray->items[0];
   36|       |
   37|       |    /* Only send the first entry. */
   38|       |    /* status_type == ocsp */
   39|      0|    rv = sslBuffer_AppendNumber(buf, 1 /*ocsp*/, 1);
   40|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (40:9): [True: 0, False: 0]
  ------------------
   41|      0|        return SECFailure;
   42|      0|    }
   43|       |    /* opaque OCSPResponse<1..2^24-1> */
   44|      0|    rv = sslBuffer_AppendVariable(buf, item->data, item->len, 3);
   45|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (45:9): [True: 0, False: 0]
  ------------------
   46|      0|        return SECFailure;
   47|      0|    }
   48|       |
   49|      0|    *added = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
   50|      0|    return SECSuccess;
   51|      0|}
tls13_SizeOfKeyShareEntry:
   64|  1.21k|{
   65|       |    /* Size = NamedGroup(2) + length(2) + opaque<?> share */
   66|  1.21k|    PRUint32 size = 2 + 2;
   67|       |
   68|  1.21k|    const SECKEYPublicKey *pubKey = keyPair->keys->pubKey;
   69|  1.21k|    switch (pubKey->keyType) {
   70|    668|        case ecKey:
  ------------------
  |  Branch (70:9): [True: 668, False: 545]
  ------------------
   71|    668|            size += pubKey->u.ec.publicValue.len;
   72|    668|            break;
   73|    545|        case dhKey:
  ------------------
  |  Branch (73:9): [True: 545, False: 668]
  ------------------
   74|    545|            size += pubKey->u.dh.prime.len;
   75|    545|            break;
   76|      0|        default:
  ------------------
  |  Branch (76:9): [True: 0, False: 1.21k]
  ------------------
   77|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   78|      0|            return 0;
   79|  1.21k|    }
   80|       |
   81|  1.21k|    if (keyPair->kemKeys) {
  ------------------
  |  Branch (81:9): [True: 0, False: 1.21k]
  ------------------
   82|      0|        PORT_Assert(!keyPair->kemCt);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   83|      0|        PORT_Assert(keyPair->group->name == ssl_grp_kem_xyber768d00 || keyPair->group->name == ssl_grp_kem_mlkem768x25519);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   84|      0|        pubKey = keyPair->kemKeys->pubKey;
   85|      0|        size += pubKey->u.kyber.publicValue.len;
   86|      0|    }
   87|  1.21k|    if (keyPair->kemCt) {
  ------------------
  |  Branch (87:9): [True: 83, False: 1.13k]
  ------------------
   88|     83|        PORT_Assert(!keyPair->kemKeys);
  ------------------
  |  |  120|     83|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     83|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 83, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   89|     83|        PORT_Assert(keyPair->group->name == ssl_grp_kem_xyber768d00 || keyPair->group->name == ssl_grp_kem_mlkem768x25519);
  ------------------
  |  |  120|     83|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    166|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 83]
  |  |  |  |  |  Branch (208:7): [True: 83, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   90|     83|        size += keyPair->kemCt->len;
   91|     83|    }
   92|       |
   93|  1.21k|    return size;
   94|  1.21k|}
tls13_EncodeKeyShareEntry:
  175|  1.21k|{
  176|  1.21k|    SECStatus rv;
  177|  1.21k|    unsigned int size = tls13_SizeOfKeyShareEntry(keyPair);
  178|       |
  179|  1.21k|    rv = sslBuffer_AppendNumber(buf, keyPair->group->name, 2);
  180|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (180:9): [True: 0, False: 1.21k]
  ------------------
  181|      0|        return rv;
  182|      0|    }
  183|       |
  184|  1.21k|    rv = sslBuffer_AppendNumber(buf, size - 4, 2);
  185|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (185:9): [True: 0, False: 1.21k]
  ------------------
  186|      0|        return rv;
  187|      0|    }
  188|       |
  189|  1.21k|    switch (keyPair->group->name) {
  190|     83|        case ssl_grp_kem_mlkem768x25519:
  ------------------
  |  Branch (190:9): [True: 83, False: 1.13k]
  ------------------
  191|     83|            rv = tls13_WriteMLKEM768X25519KeyExchangeInfo(buf, keyPair);
  192|     83|            break;
  193|      0|        case ssl_grp_kem_xyber768d00:
  ------------------
  |  Branch (193:9): [True: 0, False: 1.21k]
  ------------------
  194|      0|            rv = tls13_WriteXyber768D00KeyExchangeInfo(buf, keyPair);
  195|      0|            break;
  196|  1.13k|        default:
  ------------------
  |  Branch (196:9): [True: 1.13k, False: 83]
  ------------------
  197|  1.13k|            rv = tls13_WriteKeyExchangeInfo(buf, keyPair);
  198|  1.13k|            break;
  199|  1.21k|    }
  200|  1.21k|    return rv;
  201|  1.21k|}
tls13_DecodeKeyShareEntry:
  269|  2.85k|{
  270|  2.85k|    SECStatus rv;
  271|  2.85k|    PRUint64 group;
  272|  2.85k|    const sslNamedGroupDef *groupDef;
  273|  2.85k|    TLS13KeyShareEntry *ks = NULL;
  274|  2.85k|    sslReadBuffer share;
  275|       |
  276|  2.85k|    rv = sslRead_ReadNumber(rdr, 2, &group);
  277|  2.85k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (277:9): [True: 4, False: 2.85k]
  ------------------
  278|      4|        goto loser;
  279|      4|    }
  280|  2.85k|    groupDef = ssl_LookupNamedGroup(group);
  281|  2.85k|    rv = sslRead_ReadVariable(rdr, 2, &share);
  282|  2.85k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (282:9): [True: 34, False: 2.82k]
  ------------------
  283|     34|        goto loser;
  284|     34|    }
  285|       |
  286|       |    /* This has to happen here because we want to consume
  287|       |     * the entire entry even if the group is unknown
  288|       |     * or disabled. */
  289|       |    /* If the group is disabled, continue. */
  290|  2.82k|    if (!groupDef) {
  ------------------
  |  Branch (290:9): [True: 1.20k, False: 1.61k]
  ------------------
  291|  1.20k|        return SECSuccess;
  292|  1.20k|    }
  293|       |
  294|  1.61k|    ks = PORT_ZNew(TLS13KeyShareEntry);
  ------------------
  |  |  148|  1.61k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  1.61k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  295|  1.61k|    if (!ks) {
  ------------------
  |  Branch (295:9): [True: 0, False: 1.61k]
  ------------------
  296|      0|        goto loser;
  297|      0|    }
  298|  1.61k|    ks->group = groupDef;
  299|       |
  300|  1.61k|    rv = SECITEM_MakeItem(NULL, &ks->key_exchange,
  301|  1.61k|                          share.buf, share.len);
  302|  1.61k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (302:9): [True: 0, False: 1.61k]
  ------------------
  303|      0|        goto loser;
  304|      0|    }
  305|       |
  306|  1.61k|    *ksp = ks;
  307|  1.61k|    return SECSuccess;
  308|       |
  309|     38|loser:
  310|     38|    tls13_DestroyKeyShareEntry(ks);
  311|       |
  312|     38|    return SECFailure;
  313|  1.61k|}
tls13_ServerHandleKeyShareXtn:
  408|  1.44k|{
  409|  1.44k|    SECStatus rv;
  410|  1.44k|    PRUint32 length;
  411|       |
  412|  1.44k|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|  1.44k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.44k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.44k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  413|  1.44k|    PORT_Assert(PR_CLIST_IS_EMPTY(&xtnData->remoteKeyShares));
  ------------------
  |  |  120|  1.44k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.44k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.44k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  414|       |
  415|  1.44k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  1.44k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (415:9): [True: 77, False: 1.36k]
  ------------------
  416|     77|        return SECSuccess;
  417|     77|    }
  418|       |
  419|  1.36k|    SSL_TRC(3, ("%d: SSL3[%d]: handle key_share extension",
  ------------------
  |  |   71|  1.36k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.36k]
  |  |  ------------------
  |  |   72|  1.36k|    ssl_Trace b
  ------------------
  420|  1.36k|                SSL_GETPID(), ss->fd));
  421|       |
  422|       |    /* Redundant length because of TLS encoding (this vector consumes
  423|       |     * the entire extension.) */
  424|  1.36k|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &length, 2, &data->data,
  425|  1.36k|                                        &data->len);
  426|  1.36k|    if (rv != SECSuccess)
  ------------------
  |  Branch (426:9): [True: 1, False: 1.36k]
  ------------------
  427|      1|        goto loser;
  428|  1.36k|    if (length != data->len) {
  ------------------
  |  Branch (428:9): [True: 18, False: 1.34k]
  ------------------
  429|       |        /* Check for consistency */
  430|     18|        PORT_SetError(SSL_ERROR_RX_MALFORMED_KEY_SHARE);
  ------------------
  |  |   65|     18|#define PORT_SetError PORT_SetError_Util
  ------------------
  431|     18|        goto loser;
  432|     18|    }
  433|       |
  434|  1.34k|    sslReader rdr = SSL_READER(data->data, data->len);
  ------------------
  |  |   85|  1.34k|    {                    \
  |  |   86|  1.34k|        { b, l }, 0      \
  |  |   87|  1.34k|    }
  ------------------
  435|  4.16k|    while (SSL_READER_REMAINING(&rdr)) {
  ------------------
  |  |   91|  4.16k|    ((r)->buf.len - (r)->offset)
  |  |  ------------------
  |  |  |  Branch (91:5): [True: 2.85k, False: 1.30k]
  |  |  ------------------
  ------------------
  436|  2.85k|        TLS13KeyShareEntry *ks = NULL;
  437|  2.85k|        rv = tls13_DecodeKeyShareEntry(&rdr, &ks);
  438|  2.85k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (438:13): [True: 38, False: 2.82k]
  ------------------
  439|     38|            PORT_SetError(SSL_ERROR_RX_MALFORMED_KEY_SHARE);
  ------------------
  |  |   65|     38|#define PORT_SetError PORT_SetError_Util
  ------------------
  440|     38|            goto loser;
  441|     38|        }
  442|  2.82k|        if (ks) {
  ------------------
  |  Branch (442:13): [True: 1.61k, False: 1.20k]
  ------------------
  443|       |            /* |ks| == NULL if this is an unknown group. */
  444|  1.61k|            PR_APPEND_LINK(&ks->link, &xtnData->remoteKeyShares);
  ------------------
  |  |   57|  1.61k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|  1.61k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|  1.61k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|  1.61k|    (_e)->next = (_l);   \
  |  |  |  |   27|  1.61k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|  1.61k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|  1.61k|    (_l)->prev = (_e);   \
  |  |  |  |   30|  1.61k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|  1.61k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  445|  1.61k|        }
  446|  2.82k|    }
  447|       |
  448|       |    /* Keep track of negotiated extensions. */
  449|  1.30k|    xtnData->negotiated[xtnData->numNegotiated++] =
  450|  1.30k|        ssl_tls13_key_share_xtn;
  451|       |
  452|  1.30k|    return SECSuccess;
  453|       |
  454|     57|loser:
  455|     57|    tls13_DestroyKeyShares(&xtnData->remoteKeyShares);
  456|     57|    return SECFailure;
  457|  1.34k|}
tls13_ServerSendKeyShareXtn:
  462|  1.21k|{
  463|  1.21k|    SECStatus rv;
  464|  1.21k|    sslEphemeralKeyPair *keyPair;
  465|       |
  466|       |    /* There should be exactly one key share. */
  467|  1.21k|    PORT_Assert(!PR_CLIST_IS_EMPTY(&ss->ephemeralKeyPairs));
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  468|  1.21k|    PORT_Assert(PR_PREV_LINK(&ss->ephemeralKeyPairs) ==
  ------------------
  |  |  120|  1.21k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.21k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.21k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  469|  1.21k|                PR_NEXT_LINK(&ss->ephemeralKeyPairs));
  470|       |
  471|  1.21k|    keyPair = (sslEphemeralKeyPair *)PR_NEXT_LINK(&ss->ephemeralKeyPairs);
  ------------------
  |  |   47|  1.21k|        ((_e)->next)
  ------------------
  472|       |
  473|  1.21k|    rv = tls13_EncodeKeyShareEntry(buf, keyPair);
  474|  1.21k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (474:9): [True: 0, False: 1.21k]
  ------------------
  475|      0|        return SECFailure;
  476|      0|    }
  477|       |
  478|  1.21k|    *added = PR_TRUE;
  ------------------
  |  |  437|  1.21k|#define PR_TRUE 1
  ------------------
  479|  1.21k|    return SECSuccess;
  480|  1.21k|}
tls13_ServerHandlePreSharedKeyXtn:
  613|    253|{
  614|    253|    SECItem inner;
  615|    253|    SECStatus rv;
  616|    253|    unsigned int numIdentities = 0;
  617|    253|    unsigned int numBinders = 0;
  618|    253|    SECItem *appToken;
  619|       |
  620|    253|    SSL_TRC(3, ("%d: SSL3[%d]: handle pre_shared_key extension",
  ------------------
  |  |   71|    253|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 253]
  |  |  ------------------
  |  |   72|    253|    ssl_Trace b
  ------------------
  621|    253|                SSL_GETPID(), ss->fd));
  622|       |
  623|       |    /* If we are doing < TLS 1.3, then ignore this. */
  624|    253|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|    253|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (624:9): [True: 33, False: 220]
  ------------------
  625|     33|        return SECSuccess;
  626|     33|    }
  627|       |
  628|       |    /* The application token is set via the cookie extension if this is the
  629|       |     * second ClientHello.  Don't set it twice.  The cookie extension handler
  630|       |     * sets |helloRetry| and that will have been called already because this
  631|       |     * extension always comes last. */
  632|    220|    if (!ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (632:9): [True: 206, False: 14]
  ------------------
  633|    206|        appToken = &xtnData->applicationToken;
  634|    206|    } else {
  635|     14|        appToken = NULL;
  636|     14|    }
  637|       |
  638|       |    /* Parse the identities list. */
  639|    220|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &inner, 2,
  640|    220|                                          &data->data, &data->len);
  641|    220|    if (rv != SECSuccess) {
  ------------------
  |  Branch (641:9): [True: 15, False: 205]
  ------------------
  642|     15|        return SECFailure;
  643|     15|    }
  644|       |
  645|    363|    while (inner.len) {
  ------------------
  |  Branch (645:12): [True: 252, False: 111]
  ------------------
  646|    252|        SECItem label;
  647|    252|        PRUint32 obfuscatedAge;
  648|       |
  649|    252|        rv = ssl3_ExtConsumeHandshakeVariable(ss, &label, 2,
  650|    252|                                              &inner.data, &inner.len);
  651|    252|        if (rv != SECSuccess)
  ------------------
  |  Branch (651:13): [True: 24, False: 228]
  ------------------
  652|     24|            return rv;
  653|    228|        if (!label.len) {
  ------------------
  |  Branch (653:13): [True: 5, False: 223]
  ------------------
  654|      5|            goto alert_loser;
  655|      5|        }
  656|       |
  657|    223|        rv = ssl3_ExtConsumeHandshakeNumber(ss, &obfuscatedAge, 4,
  658|    223|                                            &inner.data, &inner.len);
  659|    223|        if (rv != SECSuccess)
  ------------------
  |  Branch (659:13): [True: 5, False: 218]
  ------------------
  660|      5|            return rv;
  661|       |
  662|    218|        if (!numIdentities) {
  ------------------
  |  Branch (662:13): [True: 195, False: 23]
  ------------------
  663|       |            /* Check any configured external PSK for a matching label.
  664|       |             * If none exists, try to parse it as a ticket. */
  665|    195|            PORT_Assert(!xtnData->selectedPsk);
  ------------------
  |  |  120|    195|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    195|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 195, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  666|    195|            for (PRCList *cur_p = PR_LIST_HEAD(&ss->ssl3.hs.psks);
  ------------------
  |  |   65|    195|#define PR_LIST_HEAD(_l) (_l)->next
  ------------------
  667|    287|                 cur_p != &ss->ssl3.hs.psks;
  ------------------
  |  Branch (667:18): [True: 92, False: 195]
  ------------------
  668|    195|                 cur_p = PR_NEXT_LINK(cur_p)) {
  ------------------
  |  |   47|     92|        ((_e)->next)
  ------------------
  669|     92|                sslPsk *psk = (sslPsk *)cur_p;
  670|     92|                if (psk->type != ssl_psk_external ||
  ------------------
  |  Branch (670:21): [True: 0, False: 92]
  ------------------
  671|     92|                    SECITEM_CompareItem(&psk->label, &label) != SECEqual) {
  ------------------
  |  |  105|     92|#define SECITEM_CompareItem SECITEM_CompareItem_Util
  ------------------
  |  Branch (671:21): [True: 92, False: 0]
  ------------------
  672|     92|                    continue;
  673|     92|                }
  674|      0|                PRINT_BUF(50, (ss, "Using External PSK with label",
  ------------------
  |  |   74|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   75|      0|    ssl_PrintBuf b
  ------------------
  675|      0|                               psk->label.data, psk->label.len));
  676|      0|                xtnData->selectedPsk = psk;
  677|      0|            }
  678|       |
  679|    195|            if (!xtnData->selectedPsk) {
  ------------------
  |  Branch (679:17): [True: 195, False: 0]
  ------------------
  680|    195|                PRINT_BUF(50, (ss, "Handling PreSharedKey value",
  ------------------
  |  |   74|    195|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 195]
  |  |  ------------------
  |  |   75|    195|    ssl_PrintBuf b
  ------------------
  681|    195|                               label.data, label.len));
  682|    195|                rv = ssl3_ProcessSessionTicketCommon(
  683|    195|                    CONST_CAST(sslSocket, ss), &label, appToken);
  ------------------
  |  |   96|    195|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
  684|       |                /* This only happens if we have an internal error, not
  685|       |                 * a malformed ticket. Bogus tickets just don't resume
  686|       |                 * and return SECSuccess. */
  687|    195|                if (rv != SECSuccess) {
  ------------------
  |  Branch (687:21): [True: 60, False: 135]
  ------------------
  688|     60|                    return SECFailure;
  689|     60|                }
  690|       |
  691|    135|                if (ss->sec.ci.sid) {
  ------------------
  |  Branch (691:21): [True: 115, False: 20]
  ------------------
  692|       |                    /* xtnData->ticketAge contains the baseline we use for
  693|       |                     * calculating the ticket age (i.e., our RTT estimate less the
  694|       |                     * value of ticket_age_add).
  695|       |                     *
  696|       |                     * Add that to the obfuscated ticket age to recover the client's
  697|       |                     * view of the ticket age plus the estimated RTT.
  698|       |                     *
  699|       |                     * See ssl3_EncodeSessionTicket() for details. */
  700|    115|                    xtnData->ticketAge += obfuscatedAge;
  701|       |
  702|       |                    /* We are not committed to resumption until after unwrapping the
  703|       |                     * RMS in tls13_HandleClientHelloPart2. The RPSK will be stored
  704|       |                     * in ss->xtnData.selectedPsk at that point, so continue. */
  705|    115|                }
  706|    135|            }
  707|    195|        }
  708|       |
  709|    158|        ++numIdentities;
  710|    158|    }
  711|       |
  712|    111|    xtnData->pskBindersLen = data->len;
  713|       |
  714|       |    /* Parse the binders list. */
  715|    111|    rv = ssl3_ExtConsumeHandshakeVariable(ss,
  716|    111|                                          &inner, 2, &data->data, &data->len);
  717|    111|    if (rv != SECSuccess)
  ------------------
  |  Branch (717:9): [True: 16, False: 95]
  ------------------
  718|     16|        return SECFailure;
  719|     95|    if (data->len) {
  ------------------
  |  Branch (719:9): [True: 15, False: 80]
  ------------------
  720|     15|        goto alert_loser;
  721|     15|    }
  722|       |
  723|    186|    while (inner.len) {
  ------------------
  |  Branch (723:12): [True: 116, False: 70]
  ------------------
  724|    116|        SECItem binder;
  725|    116|        rv = ssl3_ExtConsumeHandshakeVariable(ss, &binder, 1,
  726|    116|                                              &inner.data, &inner.len);
  727|    116|        if (rv != SECSuccess)
  ------------------
  |  Branch (727:13): [True: 6, False: 110]
  ------------------
  728|      6|            return rv;
  729|    110|        if (binder.len < 32) {
  ------------------
  |  Branch (729:13): [True: 4, False: 106]
  ------------------
  730|      4|            goto alert_loser;
  731|      4|        }
  732|       |
  733|    106|        if (!numBinders) {
  ------------------
  |  Branch (733:13): [True: 77, False: 29]
  ------------------
  734|     77|            xtnData->pskBinder = binder;
  735|     77|        }
  736|    106|        ++numBinders;
  737|    106|    }
  738|       |
  739|     70|    if (numBinders != numIdentities)
  ------------------
  |  Branch (739:9): [True: 2, False: 68]
  ------------------
  740|      2|        goto alert_loser;
  741|       |
  742|     68|    if (ss->statelessResume) {
  ------------------
  |  Branch (742:9): [True: 63, False: 5]
  ------------------
  743|     63|        PORT_Assert(!ss->xtnData.selectedPsk);
  ------------------
  |  |  120|     63|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     63|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 63, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  744|     63|    } else if (!xtnData->selectedPsk) {
  ------------------
  |  Branch (744:16): [True: 5, False: 0]
  ------------------
  745|       |        /* No matching EPSK. */
  746|      5|        return SECSuccess;
  747|      5|    }
  748|       |
  749|     63|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_tls13_pre_shared_key_xtn;
  750|     63|    return SECSuccess;
  751|       |
  752|     26|alert_loser:
  753|     26|    ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
  754|     26|    PORT_SetError(SSL_ERROR_MALFORMED_PRE_SHARED_KEY);
  ------------------
  |  |   65|     26|#define PORT_SetError PORT_SetError_Util
  ------------------
  755|     26|    return SECFailure;
  756|     68|}
tls13_ServerHandleEarlyDataXtn:
  843|    120|{
  844|    120|    SSL_TRC(3, ("%d: TLS13[%d]: handle early_data extension",
  ------------------
  |  |   71|    120|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 120]
  |  |  ------------------
  |  |   72|    120|    ssl_Trace b
  ------------------
  845|    120|                SSL_GETPID(), ss->fd));
  846|       |
  847|       |    /* If we are doing < TLS 1.3, then ignore this. */
  848|    120|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|    120|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (848:9): [True: 22, False: 98]
  ------------------
  849|     22|        return SECSuccess;
  850|     22|    }
  851|       |
  852|     98|    if (ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (852:9): [True: 5, False: 93]
  ------------------
  853|      5|        ssl3_ExtSendAlert(ss, alert_fatal, unsupported_extension);
  854|      5|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_EXTENSION);
  ------------------
  |  |   65|      5|#define PORT_SetError PORT_SetError_Util
  ------------------
  855|      5|        return SECFailure;
  856|      5|    }
  857|       |
  858|     93|    if (data->len) {
  ------------------
  |  Branch (858:9): [True: 1, False: 92]
  ------------------
  859|      1|        PORT_SetError(SSL_ERROR_MALFORMED_EARLY_DATA);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  860|      1|        return SECFailure;
  861|      1|    }
  862|       |
  863|     92|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_tls13_early_data_xtn;
  864|       |
  865|     92|    return SECSuccess;
  866|     93|}
tls13_ServerSendSupportedVersionsXtn:
 1002|  1.39k|{
 1003|  1.39k|    SECStatus rv;
 1004|       |
 1005|  1.39k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  1.39k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1005:9): [True: 0, False: 1.39k]
  ------------------
 1006|      0|        return SECSuccess;
 1007|      0|    }
 1008|       |
 1009|  1.39k|    SSL_TRC(3, ("%d: TLS13[%d]: server send supported_versions extension",
  ------------------
  |  |   71|  1.39k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1.39k]
  |  |  ------------------
  |  |   72|  1.39k|    ssl_Trace b
  ------------------
 1010|  1.39k|                SSL_GETPID(), ss->fd));
 1011|       |
 1012|  1.39k|    PRUint16 ver = tls13_EncodeVersion(SSL_LIBRARY_VERSION_TLS_1_3,
  ------------------
  |  |   21|  1.39k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
 1013|  1.39k|                                       ss->protocolVariant);
 1014|  1.39k|    rv = sslBuffer_AppendNumber(buf, ver, 2);
 1015|  1.39k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1015:9): [True: 0, False: 1.39k]
  ------------------
 1016|      0|        return SECFailure;
 1017|      0|    }
 1018|       |
 1019|  1.39k|    *added = PR_TRUE;
  ------------------
  |  |  437|  1.39k|#define PR_TRUE 1
  ------------------
 1020|  1.39k|    return SECSuccess;
 1021|  1.39k|}
tls13_ServerHandleCookieXtn:
 1081|     55|{
 1082|     55|    SECStatus rv;
 1083|       |
 1084|     55|    SSL_TRC(3, ("%d: TLS13[%d]: handle cookie extension",
  ------------------
  |  |   71|     55|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 55]
  |  |  ------------------
  |  |   72|     55|    ssl_Trace b
  ------------------
 1085|     55|                SSL_GETPID(), ss->fd));
 1086|       |
 1087|     55|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &xtnData->cookie, 2,
 1088|     55|                                          &data->data, &data->len);
 1089|     55|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1089:9): [True: 3, False: 52]
  ------------------
 1090|      3|        return SECFailure;
 1091|      3|    }
 1092|       |
 1093|     52|    if (xtnData->cookie.len == 0) {
  ------------------
  |  Branch (1093:9): [True: 2, False: 50]
  ------------------
 1094|      2|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1095|      2|        return SECFailure;
 1096|      2|    }
 1097|       |
 1098|     50|    if (data->len) {
  ------------------
  |  Branch (1098:9): [True: 10, False: 40]
  ------------------
 1099|     10|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|     10|#define PORT_SetError PORT_SetError_Util
  ------------------
 1100|     10|        return SECFailure;
 1101|     10|    }
 1102|       |
 1103|       |    /* Keep track of negotiated extensions. */
 1104|     40|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_tls13_cookie_xtn;
 1105|       |
 1106|     40|    return SECSuccess;
 1107|     50|}
tls13_ServerHandlePostHandshakeAuthXtn:
 1128|    201|{
 1129|    201|    SSL_TRC(3, ("%d: TLS13[%d]: handle post_handshake_auth extension",
  ------------------
  |  |   71|    201|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 201]
  |  |  ------------------
  |  |   72|    201|    ssl_Trace b
  ------------------
 1130|    201|                SSL_GETPID(), ss->fd));
 1131|       |
 1132|    201|    if (data->len) {
  ------------------
  |  Branch (1132:9): [True: 1, False: 200]
  ------------------
 1133|      1|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1134|      1|        return SECFailure;
 1135|      1|    }
 1136|       |
 1137|       |    /* Only one post-handshake message is supported: a single
 1138|       |     * NST immediately following the client Finished. */
 1139|    200|    if (!IS_DTLS(ss)) {
  ------------------
  |  |  892|    200|#define IS_DTLS(ss) (ss->protocolVariant == ssl_variant_datagram)
  ------------------
  |  Branch (1139:9): [True: 200, False: 0]
  ------------------
 1140|       |        /* Keep track of negotiated extensions. */
 1141|    200|        xtnData->negotiated[xtnData->numNegotiated++] = ssl_tls13_post_handshake_auth_xtn;
 1142|    200|    }
 1143|       |
 1144|    200|    return SECSuccess;
 1145|    201|}
tls13_ServerHandlePskModesXtn:
 1188|  1.23k|{
 1189|  1.23k|    SECStatus rv;
 1190|       |
 1191|       |    /* If we are doing < TLS 1.3, then ignore this. */
 1192|  1.23k|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|  1.23k|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1192:9): [True: 800, False: 439]
  ------------------
 1193|    800|        return SECSuccess;
 1194|    800|    }
 1195|       |
 1196|    439|    SSL_TRC(3, ("%d: TLS13[%d]: handle PSK key exchange modes extension",
  ------------------
  |  |   71|    439|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 439]
  |  |  ------------------
  |  |   72|    439|    ssl_Trace b
  ------------------
 1197|    439|                SSL_GETPID(), ss->fd));
 1198|       |
 1199|       |    /* IMPORTANT: We aren't copying these values, just setting pointers.
 1200|       |     * They will only be valid as long as the ClientHello is in memory. */
 1201|    439|    rv = ssl3_ExtConsumeHandshakeVariable(ss,
 1202|    439|                                          &xtnData->psk_ke_modes, 1,
 1203|    439|                                          &data->data, &data->len);
 1204|    439|    if (rv != SECSuccess)
  ------------------
  |  Branch (1204:9): [True: 1, False: 438]
  ------------------
 1205|      1|        return rv;
 1206|    438|    if (!xtnData->psk_ke_modes.len || data->len) {
  ------------------
  |  Branch (1206:9): [True: 1, False: 437]
  |  Branch (1206:39): [True: 2, False: 435]
  ------------------
 1207|      3|        PORT_SetError(SSL_ERROR_MALFORMED_PSK_KEY_EXCHANGE_MODES);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
 1208|      3|        return SECFailure;
 1209|      3|    }
 1210|       |
 1211|       |    /* Keep track of negotiated extensions. */
 1212|    435|    xtnData->negotiated[xtnData->numNegotiated++] =
 1213|    435|        ssl_tls13_psk_key_exchange_modes_xtn;
 1214|       |
 1215|    435|    return SECSuccess;
 1216|    438|}
tls13_SendCertAuthoritiesXtn:
 1221|    447|{
 1222|    447|    unsigned int calen;
 1223|    447|    const SECItem *name;
 1224|    447|    unsigned int nnames;
 1225|    447|    SECStatus rv;
 1226|       |
 1227|    447|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|    447|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    447|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 447, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1228|       |
 1229|    447|    rv = ssl_GetCertificateRequestCAs(ss, &calen, &name, &nnames);
 1230|    447|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1230:9): [True: 0, False: 447]
  ------------------
 1231|      0|        return SECFailure;
 1232|      0|    }
 1233|       |
 1234|    447|    if (!calen) {
  ------------------
  |  Branch (1234:9): [True: 447, False: 0]
  ------------------
 1235|    447|        return SECSuccess;
 1236|    447|    }
 1237|       |
 1238|      0|    rv = sslBuffer_AppendNumber(buf, calen, 2);
 1239|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1239:9): [True: 0, False: 0]
  ------------------
 1240|      0|        return SECFailure;
 1241|      0|    }
 1242|       |
 1243|      0|    while (nnames) {
  ------------------
  |  Branch (1243:12): [True: 0, False: 0]
  ------------------
 1244|      0|        rv = sslBuffer_AppendVariable(buf, name->data, name->len, 2);
 1245|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1245:13): [True: 0, False: 0]
  ------------------
 1246|      0|            return SECFailure;
 1247|      0|        }
 1248|      0|        ++name;
 1249|      0|        --nnames;
 1250|      0|    }
 1251|       |
 1252|      0|    *added = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1253|      0|    return SECSuccess;
 1254|      0|}
tls13_ServerHandleCertAuthoritiesXtn:
 1298|     92|{
 1299|     92|    SSL_TRC(3, ("%d: TLS13[%d]: ignore certificate_authorities extension",
  ------------------
  |  |   71|     92|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 92]
  |  |  ------------------
  |  |   72|     92|    ssl_Trace b
  ------------------
 1300|     92|                SSL_GETPID(), ss->fd));
 1301|       |    /* NSS ignores certificate_authorities in the ClientHello */
 1302|     92|    return SECSuccess;
 1303|     92|}
tls13_ServerSendHrrKeyShareXtn:
 1308|    181|{
 1309|    181|    SECStatus rv;
 1310|       |
 1311|    181|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1312|       |
 1313|    181|    if (!xtnData->selectedGroup) {
  ------------------
  |  Branch (1313:9): [True: 0, False: 181]
  ------------------
 1314|      0|        return SECSuccess;
 1315|      0|    }
 1316|       |
 1317|    181|    rv = sslBuffer_AppendNumber(buf, xtnData->selectedGroup->name, 2);
 1318|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1318:9): [True: 0, False: 181]
  ------------------
 1319|      0|        return SECFailure;
 1320|      0|    }
 1321|       |
 1322|    181|    *added = PR_TRUE;
  ------------------
  |  |  437|    181|#define PR_TRUE 1
  ------------------
 1323|    181|    return SECSuccess;
 1324|    181|}
tls13_ServerSendHrrCookieXtn:
 1329|    181|{
 1330|    181|    SECStatus rv;
 1331|       |
 1332|    181|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1333|    181|    PORT_Assert(xtnData->cookie.len > 0);
  ------------------
  |  |  120|    181|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    181|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 181, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1334|       |
 1335|    181|    rv = sslBuffer_AppendVariable(buf,
 1336|    181|                                  xtnData->cookie.data, xtnData->cookie.len, 2);
 1337|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1337:9): [True: 0, False: 181]
  ------------------
 1338|      0|        return SECFailure;
 1339|      0|    }
 1340|       |
 1341|    181|    *added = PR_TRUE;
  ------------------
  |  |  437|    181|#define PR_TRUE 1
  ------------------
 1342|    181|    return SECSuccess;
 1343|    181|}
tls13_ServerHandleDelegatedCredentialsXtn:
 1593|     92|{
 1594|     92|    if (xtnData->delegCredSigSchemes) {
  ------------------
  |  Branch (1594:9): [True: 0, False: 92]
  ------------------
 1595|      0|        PORT_Free(xtnData->delegCredSigSchemes);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1596|      0|        xtnData->delegCredSigSchemes = NULL;
 1597|      0|        xtnData->numDelegCredSigSchemes = 0;
 1598|      0|    }
 1599|     92|    SECStatus rv = ssl_ParseSignatureSchemes(ss, NULL,
 1600|     92|                                             &xtnData->delegCredSigSchemes,
 1601|     92|                                             &xtnData->numDelegCredSigSchemes,
 1602|     92|                                             &data->data, &data->len);
 1603|     92|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1603:9): [True: 2, False: 90]
  ------------------
 1604|      2|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1605|      2|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
 1606|      2|        return SECFailure;
 1607|      2|    }
 1608|     90|    if (xtnData->numDelegCredSigSchemes == 0) {
  ------------------
  |  Branch (1608:9): [True: 29, False: 61]
  ------------------
 1609|     29|        ssl3_ExtSendAlert(ss, alert_fatal, handshake_failure);
 1610|     29|        PORT_SetError(SSL_ERROR_UNSUPPORTED_SIGNATURE_ALGORITHM);
  ------------------
  |  |   65|     29|#define PORT_SetError PORT_SetError_Util
  ------------------
 1611|     29|        return SECFailure;
 1612|     29|    }
 1613|       |    /* Check for trailing data. */
 1614|     61|    if (data->len != 0) {
  ------------------
  |  Branch (1614:9): [True: 26, False: 35]
  ------------------
 1615|     26|        ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1616|     26|        PORT_SetError(SSL_ERROR_RX_MALFORMED_CLIENT_HELLO);
  ------------------
  |  |   65|     26|#define PORT_SetError PORT_SetError_Util
  ------------------
 1617|     26|        return SECFailure;
 1618|     26|    }
 1619|       |
 1620|       |    /* Keep track of negotiated extensions. */
 1621|     35|    xtnData->peerRequestedDelegCred = PR_TRUE;
  ------------------
  |  |  437|     35|#define PR_TRUE 1
  ------------------
 1622|     35|    xtnData->negotiated[xtnData->numNegotiated++] =
 1623|     35|        ssl_delegated_credentials_xtn;
 1624|       |
 1625|     35|    return ssl3_RegisterExtensionSender(
 1626|     35|        ss, xtnData, ssl_delegated_credentials_xtn,
 1627|     35|        tls13_ServerSendDelegatedCredentialsXtn);
 1628|     61|}
tls13_ServerSendEchXtn:
 1635|      1|{
 1636|      1|    SECStatus rv;
 1637|      1|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1638|      1|    if (PR_CLIST_IS_EMPTY(&ss->echConfigs)) {
  ------------------
  |  |   94|      1|    ((_l)->next == (_l))
  |  |  ------------------
  |  |  |  Branch (94:5): [True: 1, False: 0]
  |  |  ------------------
  ------------------
 1639|      1|        return SECSuccess;
 1640|      1|    }
 1641|       |
 1642|      0|    const sslEchConfig *cfg = (sslEchConfig *)PR_LIST_HEAD(&ss->echConfigs);
  ------------------
  |  |   65|      0|#define PR_LIST_HEAD(_l) (_l)->next
  ------------------
 1643|      0|    rv = sslBuffer_AppendVariable(buf, cfg->raw.data, cfg->raw.len, 2);
 1644|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1644:9): [True: 0, False: 0]
  ------------------
 1645|      0|        return SECFailure;
 1646|      0|    }
 1647|       |
 1648|      0|    *added = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1649|      0|    return SECSuccess;
 1650|      0|}
tls13_ServerSendHrrEchXtn:
 1665|    181|{
 1666|    181|    SECStatus rv;
 1667|       |    /* Do not send HRR ECH extension if TLS < 1.3 was negotiated OR no ECH
 1668|       |     * extension was received OR the server is NOT in any ECH server mode AND
 1669|       |     * ECH GREASE is NOT enabled. */
 1670|    181|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3 ||
  ------------------
  |  |   21|    362|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1670:9): [True: 0, False: 181]
  ------------------
 1671|    181|        !xtnData->ech ||
  ------------------
  |  Branch (1671:9): [True: 168, False: 13]
  ------------------
 1672|    181|        (!ss->echPubKey && !ss->opt.enableTls13BackendEch && !ss->opt.enableTls13GreaseEch)) {
  ------------------
  |  Branch (1672:10): [True: 13, False: 0]
  |  Branch (1672:28): [True: 5, False: 8]
  |  Branch (1672:62): [True: 5, False: 0]
  ------------------
 1673|    173|        SSL_TRC(100, ("%d: TLS13[%d]: server not sending HRR ECH Xtn",
  ------------------
  |  |   71|    173|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 173]
  |  |  ------------------
  |  |   72|    173|    ssl_Trace b
  ------------------
 1674|    173|                      SSL_GETPID(), ss->fd));
 1675|    173|        return SECSuccess;
 1676|    173|    }
 1677|      8|    SSL_TRC(100, ("%d: TLS13[%d]: server sending HRR ECH Xtn",
  ------------------
  |  |   71|      8|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 8]
  |  |  ------------------
  |  |   72|      8|    ssl_Trace b
  ------------------
 1678|      8|                  SSL_GETPID(), ss->fd));
 1679|      8|    PR_ASSERT(SSL_BUFFER_LEN(&ss->ssl3.hs.greaseEchBuf) == TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 8, False: 0]
  |  |  ------------------
  ------------------
 1680|      8|    PRINT_BUF(100, (ss, "grease_ech_confirmation", ss->ssl3.hs.greaseEchBuf.buf, TLS13_ECH_SIGNAL_LEN));
  ------------------
  |  |   74|      8|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 8]
  |  |  ------------------
  |  |   75|      8|    ssl_PrintBuf b
  ------------------
 1681|      8|    rv = sslBuffer_AppendBuffer(buf, &ss->ssl3.hs.greaseEchBuf);
 1682|      8|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1682:9): [True: 0, False: 8]
  ------------------
 1683|      0|        return SECFailure;
 1684|      0|    }
 1685|      8|    *added = PR_TRUE;
  ------------------
  |  |  437|      8|#define PR_TRUE 1
  ------------------
 1686|      8|    return SECSuccess;
 1687|      8|}
tls13_ServerHandleInnerEchXtn:
 1692|     18|{
 1693|     18|    PRUint64 xtn_type;
 1694|     18|    sslReader xtnReader = SSL_READER(data->data, data->len);
  ------------------
  |  |   85|     18|    {                    \
  |  |   86|     18|        { b, l }, 0      \
  |  |   87|     18|    }
  ------------------
 1695|       |
 1696|     18|    PR_ASSERT(ss->ssl3.hs.echAccepted || ss->opt.enableTls13BackendEch);
  ------------------
  |  |  208|     36|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 0, False: 18]
  |  |  |  Branch (208:7): [True: 18, False: 0]
  |  |  ------------------
  ------------------
 1697|     18|    PR_ASSERT(!xtnData->ech->receivedInnerXtn);
  ------------------
  |  |  208|     18|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 18, False: 0]
  |  |  ------------------
  ------------------
 1698|       |
 1699|     18|    SECStatus rv = sslRead_ReadNumber(&xtnReader, 1, &xtn_type);
 1700|     18|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1700:9): [True: 0, False: 18]
  ------------------
 1701|      0|        goto alert_loser;
 1702|      0|    }
 1703|     18|    if (xtn_type != ech_xtn_type_inner) {
  ------------------
  |  Branch (1703:9): [True: 0, False: 18]
  ------------------
 1704|      0|        goto alert_loser;
 1705|      0|    }
 1706|     18|    if (SSL_READER_REMAINING(&xtnReader)) {
  ------------------
  |  |   91|     18|    ((r)->buf.len - (r)->offset)
  |  |  ------------------
  |  |  |  Branch (91:5): [True: 1, False: 17]
  |  |  ------------------
  ------------------
 1707|       |        /* Inner ECH Extension must contain only type enum */
 1708|      1|        goto alert_loser;
 1709|      1|    }
 1710|       |
 1711|     17|    xtnData->ech->receivedInnerXtn = PR_TRUE;
  ------------------
  |  |  437|     17|#define PR_TRUE 1
  ------------------
 1712|     17|    xtnData->negotiated[xtnData->numNegotiated++] = ssl_tls13_encrypted_client_hello_xtn;
 1713|     17|    return SECSuccess;
 1714|       |
 1715|      1|alert_loser:
 1716|      1|    ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1717|      1|    PORT_SetError(SSL_ERROR_RX_MALFORMED_ECH_EXTENSION);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
                  PORT_SetError(SSL_ERROR_RX_MALFORMED_ECH_EXTENSION);
  ------------------
  |  |  294|      1|#define SSL_ERROR_RX_MALFORMED_ECH_EXTENSION SSL_ERROR_RX_MALFORMED_ESNI_EXTENSION
  ------------------
 1718|      1|    return SECFailure;
 1719|     18|}
tls13_ServerHandleOuterEchXtn:
 1724|     94|{
 1725|     94|    SECStatus rv;
 1726|     94|    HpkeKdfId kdf;
 1727|     94|    HpkeAeadId aead;
 1728|     94|    PRUint32 tmp;
 1729|     94|    PRUint8 configId;
 1730|     94|    SECItem senderPubKey;
 1731|     94|    SECItem encryptedCh;
 1732|       |
 1733|     94|    PRUint32 xtn_type;
 1734|     94|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &xtn_type, 1, &data->data, &data->len);
 1735|     94|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1735:9): [True: 1, False: 93]
  ------------------
 1736|      1|        goto alert_loser;
 1737|      1|    }
 1738|     93|    if (xtn_type != ech_xtn_type_outer && xtn_type != ech_xtn_type_inner) {
  ------------------
  |  Branch (1738:9): [True: 22, False: 71]
  |  Branch (1738:43): [True: 3, False: 19]
  ------------------
 1739|      3|        SSL_TRC(3, ("%d: TLS13[%d]: unexpected ECH extension type in client hello outer, alert",
  ------------------
  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  ------------------
  |  |   72|      3|    ssl_Trace b
  ------------------
 1740|      3|                    SSL_GETPID(), ss->fd));
 1741|      3|        goto alert_loser;
 1742|      3|    }
 1743|       |    /* If we are operating in shared mode, we can accept an inner xtn in the ClientHelloOuter */
 1744|     90|    if (xtn_type == ech_xtn_type_inner) {
  ------------------
  |  Branch (1744:9): [True: 19, False: 71]
  ------------------
 1745|     19|        if (!ss->opt.enableTls13BackendEch) {
  ------------------
  |  Branch (1745:13): [True: 1, False: 18]
  ------------------
 1746|      1|            ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
 1747|      1|            PORT_SetError(SSL_ERROR_RX_UNEXPECTED_EXTENSION);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
 1748|      1|            return SECFailure;
 1749|      1|        }
 1750|     18|        PORT_Assert(!xtnData->ech);
  ------------------
  |  |  120|     18|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     18|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 18, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1751|     18|        xtnData->ech = PORT_ZNew(sslEchXtnState);
  ------------------
  |  |  148|     18|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|     18|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1752|     18|        if (!xtnData->ech) {
  ------------------
  |  Branch (1752:13): [True: 0, False: 18]
  ------------------
 1753|      0|            return SECFailure;
 1754|      0|        }
 1755|       |        /* We have to rewind the buffer advanced by ssl3_ExtConsumeHandshakeNumber */
 1756|     18|        data->data--;
 1757|     18|        data->len++;
 1758|     18|        return tls13_ServerHandleInnerEchXtn(ss, xtnData, data);
 1759|     18|    }
 1760|     71|    if (ss->ssl3.hs.echAccepted) {
  ------------------
  |  Branch (1760:9): [True: 0, False: 71]
  ------------------
 1761|      0|        ssl3_ExtSendAlert(ss, alert_fatal, illegal_parameter);
 1762|      0|        PORT_SetError(SSL_ERROR_RX_UNEXPECTED_EXTENSION);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1763|      0|        return SECFailure;
 1764|      0|    }
 1765|       |
 1766|     71|    SSL_TRC(3, ("%d: TLS13[%d]: handle outer ECH extension",
  ------------------
  |  |   71|     71|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 71]
  |  |  ------------------
  |  |   72|     71|    ssl_Trace b
  ------------------
 1767|     71|                SSL_GETPID(), ss->fd));
 1768|       |
 1769|     71|    PORT_Assert(!xtnData->ech);
  ------------------
  |  |  120|     71|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     71|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 71, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1770|     71|    xtnData->ech = PORT_ZNew(sslEchXtnState);
  ------------------
  |  |  148|     71|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|     71|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
 1771|     71|    if (!xtnData->ech) {
  ------------------
  |  Branch (1771:9): [True: 0, False: 71]
  ------------------
 1772|      0|        return SECFailure;
 1773|      0|    }
 1774|       |
 1775|       |    /* Parse the KDF and AEAD. */
 1776|     71|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &tmp, 2,
 1777|     71|                                        &data->data, &data->len);
 1778|     71|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1778:9): [True: 1, False: 70]
  ------------------
 1779|      1|        goto alert_loser;
 1780|      1|    }
 1781|     70|    kdf = (HpkeKdfId)tmp;
 1782|     70|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &tmp, 2,
 1783|     70|                                        &data->data, &data->len);
 1784|     70|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1784:9): [True: 1, False: 69]
  ------------------
 1785|      1|        goto alert_loser;
 1786|      1|    }
 1787|     69|    aead = (HpkeAeadId)tmp;
 1788|       |
 1789|       |    /* config_id */
 1790|     69|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &tmp, 1,
 1791|     69|                                        &data->data, &data->len);
 1792|     69|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1792:9): [True: 1, False: 68]
  ------------------
 1793|      1|        goto alert_loser;
 1794|      1|    }
 1795|     68|    configId = tmp;
 1796|       |
 1797|       |    /* enc */
 1798|     68|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &senderPubKey, 2,
 1799|     68|                                          &data->data, &data->len);
 1800|     68|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1800:9): [True: 1, False: 67]
  ------------------
 1801|      1|        goto alert_loser;
 1802|      1|    }
 1803|       |
 1804|       |    /* payload, which must be final and non-empty. */
 1805|     67|    xtnData->ech->payloadStart = data->data + 2; /* Move past length */
 1806|     67|    rv = ssl3_ExtConsumeHandshakeVariable(ss, &encryptedCh, 2,
 1807|     67|                                          &data->data, &data->len);
 1808|     67|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1808:9): [True: 1, False: 66]
  ------------------
 1809|      1|        goto alert_loser;
 1810|      1|    }
 1811|     66|    if (data->len || !encryptedCh.len) {
  ------------------
  |  Branch (1811:9): [True: 3, False: 63]
  |  Branch (1811:22): [True: 1, False: 62]
  ------------------
 1812|      4|        goto alert_loser;
 1813|      4|    }
 1814|       |
 1815|     62|    if (!ss->ssl3.hs.helloRetry) {
  ------------------
  |  Branch (1815:9): [True: 12, False: 50]
  ------------------
 1816|       |        /* In the real ECH HRR case, config_id and enc should be empty. This
 1817|       |         * is checked after acceptance, because it might be GREASE ECH. */
 1818|     12|        if (!senderPubKey.len) {
  ------------------
  |  Branch (1818:13): [True: 1, False: 11]
  ------------------
 1819|      1|            goto alert_loser;
 1820|      1|        }
 1821|       |
 1822|     11|        rv = SECITEM_CopyItem(NULL, &xtnData->ech->senderPubKey, &senderPubKey);
  ------------------
  |  |  106|     11|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1823|     11|        if (rv == SECFailure) {
  ------------------
  |  Branch (1823:13): [True: 0, False: 11]
  ------------------
 1824|      0|            return SECFailure;
 1825|      0|        }
 1826|     11|    }
 1827|       |
 1828|     61|    rv = SECITEM_CopyItem(NULL, &xtnData->ech->innerCh, &encryptedCh);
  ------------------
  |  |  106|     61|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
 1829|     61|    PRINT_BUF(100, (ss, "CT for ECH Decryption", encryptedCh.data, encryptedCh.len));
  ------------------
  |  |   74|     61|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 61]
  |  |  ------------------
  |  |   75|     61|    ssl_PrintBuf b
  ------------------
 1830|     61|    if (rv == SECFailure) {
  ------------------
  |  Branch (1830:9): [True: 0, False: 61]
  ------------------
 1831|      0|        return SECFailure;
 1832|      0|    }
 1833|     61|    xtnData->ech->configId = configId;
 1834|     61|    xtnData->ech->kdfId = kdf;
 1835|     61|    xtnData->ech->aeadId = aead;
 1836|       |
 1837|       |    /* Not negotiated until tls13_MaybeAcceptEch. */
 1838|     61|    return SECSuccess;
 1839|       |
 1840|     14|alert_loser:
 1841|     14|    ssl3_ExtSendAlert(ss, alert_fatal, decode_error);
 1842|     14|    PORT_SetError(SSL_ERROR_RX_MALFORMED_ECH_EXTENSION);
  ------------------
  |  |   65|     14|#define PORT_SetError PORT_SetError_Util
  ------------------
                  PORT_SetError(SSL_ERROR_RX_MALFORMED_ECH_EXTENSION);
  ------------------
  |  |  294|     14|#define SSL_ERROR_RX_MALFORMED_ECH_EXTENSION SSL_ERROR_RX_MALFORMED_ESNI_EXTENSION
  ------------------
 1843|     14|    return SECFailure;
 1844|     61|}
tls13_SendEmptyGreaseXtn:
 1850|    447|{
 1851|    447|    if (!ss->opt.enableGrease ||
  ------------------
  |  Branch (1851:9): [True: 247, False: 200]
  ------------------
 1852|    447|        (!ss->sec.isServer && ss->vrange.max < SSL_LIBRARY_VERSION_TLS_1_3) ||
  ------------------
  |  |   21|      0|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1852:10): [True: 0, False: 200]
  |  Branch (1852:31): [True: 0, False: 0]
  ------------------
 1853|    447|        (ss->sec.isServer && ss->version < SSL_LIBRARY_VERSION_TLS_1_3)) {
  ------------------
  |  |   21|    200|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1853:10): [True: 200, False: 0]
  |  Branch (1853:30): [True: 0, False: 200]
  ------------------
 1854|    247|        return SECSuccess;
 1855|    247|    }
 1856|       |
 1857|    200|    *added = PR_TRUE;
  ------------------
  |  |  437|    200|#define PR_TRUE 1
  ------------------
 1858|    200|    return SECSuccess;
 1859|    447|}
ssl3_SendCertificateCompressionXtn:
 1885|    447|{
 1886|       |    /* enum {
 1887|       |     *  zlib(1),
 1888|       |     *  brotli(2),
 1889|       |     *  zstd(3),
 1890|       |     *  (65535)
 1891|       |     * } CertificateCompressionAlgorithm;
 1892|       |     *
 1893|       |     * struct {
 1894|       |     *      CertificateCompressionAlgorithm algorithms<2..2^8-2>;
 1895|       |     *  } CertificateCompressionAlgorithms;
 1896|       |     */
 1897|       |
 1898|    447|    SECStatus rv = SECFailure;
 1899|    447|    if (ss->ssl3.cwSpec->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|    447|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1899:9): [True: 0, False: 447]
  ------------------
 1900|      0|        SSL_TRC(50, ("%d: TLS13[%d]: certificate_compression_algorithm extension requires TLS1.3 and above",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
 1901|      0|                     SSL_GETPID(), ss->fd));
 1902|      0|        return SECSuccess;
 1903|      0|    }
 1904|       |
 1905|    447|    size_t certificateCompressionAlgorithmsLen = ss->ssl3.supportedCertCompressionAlgorithmsCount;
 1906|    447|    if (certificateCompressionAlgorithmsLen == 0) {
  ------------------
  |  Branch (1906:9): [True: 221, False: 226]
  ------------------
 1907|    221|        SSL_TRC(30, ("%d: TLS13[%d]: %s does not support any certificate compression algorithm",
  ------------------
  |  |   71|    221|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 221]
  |  |  ------------------
  |  |   72|    221|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1908|    221|                     SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1909|    221|        return SECSuccess;
 1910|    221|    }
 1911|       |
 1912|    226|    SSL_TRC(30, ("%d: TLS13[%d]: %s sends certificate_compression_algorithm extension",
  ------------------
  |  |   71|    226|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 226]
  |  |  ------------------
  |  |   72|    226|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1913|    226|                 SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1914|    226|    PORT_Assert(certificateCompressionAlgorithmsLen < (0x1u << 8) - 1);
  ------------------
  |  |  120|    226|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    226|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 226, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1915|       |
 1916|    226|    rv = sslBuffer_AppendNumber(buf, certificateCompressionAlgorithmsLen << 1, 1);
 1917|    226|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1917:9): [True: 0, False: 226]
  ------------------
 1918|      0|        return SECFailure;
 1919|      0|    }
 1920|       |
 1921|    452|    for (size_t i = 0; i < certificateCompressionAlgorithmsLen; i++) {
  ------------------
  |  Branch (1921:24): [True: 226, False: 226]
  ------------------
 1922|    226|        rv = sslBuffer_AppendNumber(buf, ss->ssl3.supportedCertCompressionAlgorithms[i].id, 2);
 1923|    226|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1923:13): [True: 0, False: 226]
  ------------------
 1924|      0|            return SECFailure;
 1925|      0|        }
 1926|    226|    }
 1927|       |
 1928|    226|    xtnData->certificateCompressionAdvertised = PR_TRUE;
  ------------------
  |  |  437|    226|#define PR_TRUE 1
  ------------------
 1929|    226|    *added = PR_TRUE;
  ------------------
  |  |  437|    226|#define PR_TRUE 1
  ------------------
 1930|    226|    return SECSuccess;
 1931|    226|}
ssl3_HandleCertificateCompressionXtn:
 1948|     61|{
 1949|       |    /* This extension is only supported with TLS 1.3 [RFC8446] and newer;
 1950|       |     * if TLS 1.2 [RFC5246] or earlier is negotiated, the peers MUST ignore this extension.
 1951|       |     */
 1952|     61|    if (ss->version < SSL_LIBRARY_VERSION_TLS_1_3) {
  ------------------
  |  |   21|     61|#define SSL_LIBRARY_VERSION_TLS_1_3             0x0304
  ------------------
  |  Branch (1952:9): [True: 14, False: 47]
  ------------------
 1953|     14|        SSL_TRC(50, ("%d: TLS13[%d]: ignore certificate_compression extension",
  ------------------
  |  |   71|     14|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 14]
  |  |  ------------------
  |  |   72|     14|    ssl_Trace b
  ------------------
 1954|     14|                     SSL_GETPID(), ss->fd));
 1955|     14|        return SECSuccess;
 1956|     14|    }
 1957|       |
 1958|     47|    SECStatus rv = SECFailure;
 1959|     47|    PRUint32 lengthSupportedAlgorithms = 0;
 1960|     47|    PRUint32 certComprAlgId = 0;
 1961|       |
 1962|     47|    SSL_TRC(30, ("%d: TLS13[%d]: %s handles certificate_compression_algorithm extension",
  ------------------
  |  |   71|     47|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 47]
  |  |  ------------------
  |  |   72|     47|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 1963|     47|                 SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 1964|       |
 1965|     47|    rv = ssl3_ExtConsumeHandshakeNumber(ss, &lengthSupportedAlgorithms, 1, &data->data, &data->len);
 1966|     47|    if (rv != SECSuccess) {
  ------------------
  |  Branch (1966:9): [True: 3, False: 44]
  ------------------
 1967|      3|        goto alert_loser;
 1968|      3|    }
 1969|       |
 1970|       |    /* Each of the algorithm is 2 bytes. */
 1971|     44|    if (lengthSupportedAlgorithms % 2 != 0) {
  ------------------
  |  Branch (1971:9): [True: 1, False: 43]
  ------------------
 1972|      1|        goto alert_loser;
 1973|      1|    }
 1974|       |
 1975|     43|    if (data->len != lengthSupportedAlgorithms) {
  ------------------
  |  Branch (1975:9): [True: 5, False: 38]
  ------------------
 1976|      5|        goto alert_loser;
 1977|      5|    }
 1978|       |
 1979|     38|    SECStatus algFound = SECFailure;
 1980|       |
 1981|       |    /* We use the first common algorithm we found. */
 1982|    364|    for (int i = 0; i < lengthSupportedAlgorithms / 2; i++) {
  ------------------
  |  Branch (1982:21): [True: 326, False: 38]
  ------------------
 1983|    326|        rv = ssl3_ExtConsumeHandshakeNumber(ss, &certComprAlgId, 2, &data->data, &data->len);
 1984|    326|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1984:13): [True: 0, False: 326]
  ------------------
 1985|      0|            goto alert_loser;
 1986|      0|        }
 1987|       |
 1988|    326|        SSLCertificateCompressionAlgorithmID alg = (SSLCertificateCompressionAlgorithmID)certComprAlgId;
 1989|    326|        if (alg == 0) {
  ------------------
  |  Branch (1989:13): [True: 111, False: 215]
  ------------------
 1990|    111|            SSL_TRC(50, ("%d: TLS13[%d]: certificate compression ignores reserved algorithm %02x",
  ------------------
  |  |   71|    111|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 111]
  |  |  ------------------
  |  |   72|    111|    ssl_Trace b
  ------------------
 1991|    111|                         SSL_GETPID(), ss->fd, alg));
 1992|    111|            continue;
 1993|    111|        }
 1994|       |
 1995|    329|        for (int j = 0; j < ss->ssl3.supportedCertCompressionAlgorithmsCount; j++) {
  ------------------
  |  Branch (1995:25): [True: 114, False: 215]
  ------------------
 1996|    114|            if (ss->ssl3.supportedCertCompressionAlgorithms[j].id == alg) {
  ------------------
  |  Branch (1996:17): [True: 0, False: 114]
  ------------------
 1997|      0|                xtnData->compressionAlg = alg;
 1998|      0|                xtnData->negotiated[xtnData->numNegotiated++] = ssl_certificate_compression_xtn;
 1999|      0|                algFound = SECSuccess;
 2000|      0|                break;
 2001|      0|            }
 2002|    114|        }
 2003|       |
 2004|    215|        if (algFound == SECSuccess) {
  ------------------
  |  Branch (2004:13): [True: 0, False: 215]
  ------------------
 2005|      0|            break;
 2006|      0|        }
 2007|    215|    }
 2008|       |
 2009|     38|    if (algFound == SECSuccess) {
  ------------------
  |  Branch (2009:9): [True: 0, False: 38]
  ------------------
 2010|      0|        SSL_TRC(30, ("%d: TLS13[%d]: %s established certificate compression algorithm %s",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2011|      0|                     SSL_GETPID(), ss->fd, SSL_ROLE(ss),
 2012|      0|                     ssl3_mapCertificateCompressionAlgorithmToName(ss, xtnData->compressionAlg)));
 2013|     38|    } else {
 2014|     38|        SSL_TRC(30, ("%d: TLS13[%d]: no common certificate compression algorithms found on the %s side",
  ------------------
  |  |   71|     38|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 38]
  |  |  ------------------
  |  |   72|     38|    ssl_Trace b
  |  |  ------------------
  |  |  |  Branch (72:15): [True: 0, False: 0]
  |  |  ------------------
  ------------------
 2015|     38|                     SSL_GETPID(), ss->fd, SSL_ROLE(ss)));
 2016|     38|    }
 2017|       |
 2018|     38|    return SECSuccess;
 2019|       |
 2020|      9|alert_loser:
 2021|      9|    ssl3_ExtDecodeError(ss);
 2022|      9|    return SECFailure;
 2023|     38|}
tls13exthandle.c:tls13_WriteMLKEM768X25519KeyExchangeInfo:
  125|     83|{
  126|     83|    PORT_Assert(keyPair->group->name == ssl_grp_kem_mlkem768x25519);
  ------------------
  |  |  120|     83|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     83|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 83, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  127|     83|    PORT_Assert(keyPair->keys->pubKey->keyType == ecKey);
  ------------------
  |  |  120|     83|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     83|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 83, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  128|       |
  129|       |    // Encode the ML-KEM-768 key or ciphertext first, then the X25519 share.
  130|     83|    SECStatus rv;
  131|     83|    if (keyPair->kemKeys) {
  ------------------
  |  Branch (131:9): [True: 0, False: 83]
  ------------------
  132|      0|        PORT_Assert(!keyPair->kemCt);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  133|      0|        rv = sslBuffer_Append(buf, keyPair->kemKeys->pubKey->u.kyber.publicValue.data, keyPair->kemKeys->pubKey->u.kyber.publicValue.len);
  134|     83|    } else if (keyPair->kemCt) {
  ------------------
  |  Branch (134:16): [True: 83, False: 0]
  ------------------
  135|     83|        rv = sslBuffer_Append(buf, keyPair->kemCt->data, keyPair->kemCt->len);
  136|     83|    } else {
  137|      0|        PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  138|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  139|      0|        rv = SECFailure;
  140|      0|    }
  141|     83|    if (rv != SECSuccess) {
  ------------------
  |  Branch (141:9): [True: 0, False: 83]
  ------------------
  142|      0|        return rv;
  143|      0|    }
  144|       |
  145|     83|    rv = sslBuffer_Append(buf, keyPair->keys->pubKey->u.ec.publicValue.data,
  146|     83|                          keyPair->keys->pubKey->u.ec.publicValue.len);
  147|     83|    return rv;
  148|     83|}
tls13exthandle.c:tls13_WriteKeyExchangeInfo:
  152|  1.13k|{
  153|  1.13k|    SECStatus rv;
  154|  1.13k|    const SECKEYPublicKey *pubKey = keyPair->keys->pubKey;
  155|  1.13k|    switch (pubKey->keyType) {
  156|    585|        case ecKey:
  ------------------
  |  Branch (156:9): [True: 585, False: 545]
  ------------------
  157|    585|            rv = sslBuffer_Append(buf, pubKey->u.ec.publicValue.data,
  158|    585|                                  pubKey->u.ec.publicValue.len);
  159|    585|            break;
  160|    545|        case dhKey:
  ------------------
  |  Branch (160:9): [True: 545, False: 585]
  ------------------
  161|    545|            rv = ssl_AppendPaddedDHKeyShare(buf, pubKey, PR_FALSE);
  ------------------
  |  |  438|    545|#define PR_FALSE 0
  ------------------
  162|    545|            break;
  163|      0|        default:
  ------------------
  |  Branch (163:9): [True: 0, False: 1.13k]
  ------------------
  164|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  165|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  166|      0|            rv = SECFailure;
  167|      0|            break;
  168|  1.13k|    }
  169|       |
  170|  1.13k|    return rv;
  171|  1.13k|}
tls13exthandle.c:tls13_ServerSendDelegatedCredentialsXtn:
 1573|     10|{
 1574|     10|    if (tls13_IsSigningWithDelegatedCredential(ss)) {
  ------------------
  |  Branch (1574:9): [True: 0, False: 10]
  ------------------
 1575|      0|        const SECItem *dc = &ss->sec.serverCert->delegCred;
 1576|      0|        SECStatus rv;
 1577|      0|        rv = sslBuffer_Append(buf, dc->data, dc->len);
 1578|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (1578:13): [True: 0, False: 0]
  ------------------
 1579|      0|            return SECFailure;
 1580|      0|        }
 1581|      0|        *added = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1582|      0|    }
 1583|     10|    return SECSuccess;
 1584|     10|}

tls13_MakeHrrCookie:
   42|    181|{
   43|    181|    SECStatus rv;
   44|    181|    SSL3Hashes hashes;
   45|    181|    PRUint8 cookie[1024];
   46|    181|    sslBuffer cookieBuf = SSL_BUFFER(cookie);
  ------------------
  |  |   34|    181|#define SSL_BUFFER(b) SSL_BUFFER_FIXED(b, sizeof(b))
  |  |  ------------------
  |  |  |  |   27|    181|    {                               \
  |  |  |  |   28|    181|        b, 0, maxlen, PR_TRUE       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  437|    181|#define PR_TRUE 1
  |  |  |  |  ------------------
  |  |  |  |   29|    181|    }
  |  |  ------------------
  ------------------
   47|    181|    static const PRUint8 indicator = 0xff;
   48|    181|    SECItem *echHpkeCtx = NULL;
   49|       |
   50|       |    /* Encode header. */
   51|    181|    rv = sslBuffer_Append(&cookieBuf, &indicator, 1);
   52|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (52:9): [True: 0, False: 181]
  ------------------
   53|      0|        return SECFailure;
   54|      0|    }
   55|    181|    rv = sslBuffer_AppendNumber(&cookieBuf, ss->ssl3.hs.cipher_suite, 2);
   56|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (56:9): [True: 0, False: 181]
  ------------------
   57|      0|        return SECFailure;
   58|      0|    }
   59|    181|    rv = sslBuffer_AppendNumber(&cookieBuf,
   60|    181|                                selectedGroup ? selectedGroup->name : 0, 2);
  ------------------
  |  Branch (60:33): [True: 181, False: 0]
  ------------------
   61|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (61:9): [True: 0, False: 181]
  ------------------
   62|      0|        return SECFailure;
   63|      0|    }
   64|       |
   65|    181|    if (ss->xtnData.ech) {
  ------------------
  |  Branch (65:9): [True: 13, False: 168]
  ------------------
   66|       |        /* Record that we received ECH. See sslEchCookieData */
   67|     13|        rv = sslBuffer_AppendNumber(&cookieBuf, PR_TRUE, 1);
  ------------------
  |  |  437|     13|#define PR_TRUE 1
  ------------------
   68|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (68:13): [True: 0, False: 13]
  ------------------
   69|      0|            return SECFailure;
   70|      0|        }
   71|       |
   72|     13|        rv = sslBuffer_AppendNumber(&cookieBuf, ss->xtnData.ech->configId,
   73|     13|                                    1);
   74|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (74:13): [True: 0, False: 13]
  ------------------
   75|      0|            return SECFailure;
   76|      0|        }
   77|       |
   78|     13|        rv = sslBuffer_AppendNumber(&cookieBuf, ss->xtnData.ech->kdfId, 2);
   79|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (79:13): [True: 0, False: 13]
  ------------------
   80|      0|            return SECFailure;
   81|      0|        }
   82|     13|        rv = sslBuffer_AppendNumber(&cookieBuf, ss->xtnData.ech->aeadId, 2);
   83|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (83:13): [True: 0, False: 13]
  ------------------
   84|      0|            return SECFailure;
   85|      0|        }
   86|       |        /* We need to send a ECH HRR Extension containing a signal for the client,
   87|       |         * we must store the signal in the cookie so we can reconstruct the transcript
   88|       |         * later. To avoid leaking whether ECH was accepted in the length of the cookie
   89|       |         * we include the empty signal in the cookie regardless.
   90|       |         */
   91|     13|        PR_ASSERT(SSL_BUFFER_LEN(&ss->ssl3.hs.greaseEchBuf) == TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  208|     13|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 13, False: 0]
  |  |  ------------------
  ------------------
   92|     13|        rv = sslBuffer_AppendBuffer(&cookieBuf, &ss->ssl3.hs.greaseEchBuf);
   93|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (93:13): [True: 0, False: 13]
  ------------------
   94|      0|            return SECFailure;
   95|      0|        }
   96|       |
   97|       |        /* There might be no HPKE Context, e.g. when we lack a matching ECHConfig. */
   98|     13|        if (ss->ssl3.hs.echHpkeCtx) {
  ------------------
  |  Branch (98:13): [True: 0, False: 13]
  ------------------
   99|      0|            rv = PK11_HPKE_ExportContext(ss->ssl3.hs.echHpkeCtx, NULL, &echHpkeCtx);
  100|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (100:17): [True: 0, False: 0]
  ------------------
  101|      0|                return SECFailure;
  102|      0|            }
  103|      0|            rv = sslBuffer_AppendVariable(&cookieBuf, echHpkeCtx->data, echHpkeCtx->len, 2);
  104|      0|            SECITEM_ZfreeItem(echHpkeCtx, PR_TRUE);
  ------------------
  |  |  110|      0|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                          SECITEM_ZfreeItem(echHpkeCtx, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  105|     13|        } else {
  106|       |            /* Zero length HPKE context. */
  107|     13|            rv = sslBuffer_AppendNumber(&cookieBuf, 0, 2);
  108|     13|        }
  109|     13|        if (rv != SECSuccess) {
  ------------------
  |  Branch (109:13): [True: 0, False: 13]
  ------------------
  110|      0|            return SECFailure;
  111|      0|        }
  112|    168|    } else {
  113|    168|        rv = sslBuffer_AppendNumber(&cookieBuf, PR_FALSE, 1);
  ------------------
  |  |  438|    168|#define PR_FALSE 0
  ------------------
  114|    168|        if (rv != SECSuccess) {
  ------------------
  |  Branch (114:13): [True: 0, False: 168]
  ------------------
  115|      0|            return SECFailure;
  116|      0|        }
  117|    168|    }
  118|       |
  119|       |    /* Application token. */
  120|    181|    rv = sslBuffer_AppendVariable(&cookieBuf, appToken, appTokenLen, 2);
  121|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (121:9): [True: 0, False: 181]
  ------------------
  122|      0|        return SECFailure;
  123|      0|    }
  124|       |
  125|       |    /* Compute and encode hashes. */
  126|    181|    rv = tls13_ComputeHandshakeHashes(ss, &hashes);
  127|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (127:9): [True: 0, False: 181]
  ------------------
  128|      0|        return SECFailure;
  129|      0|    }
  130|    181|    rv = sslBuffer_Append(&cookieBuf, hashes.u.raw, hashes.len);
  131|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (131:9): [True: 0, False: 181]
  ------------------
  132|      0|        return SECFailure;
  133|      0|    }
  134|       |
  135|       |    /* Encrypt right into the buffer. */
  136|    181|    rv = ssl_SelfEncryptProtect(ss, cookieBuf.buf, cookieBuf.len,
  137|    181|                                buf, len, maxlen);
  138|    181|    if (rv != SECSuccess) {
  ------------------
  |  Branch (138:9): [True: 0, False: 181]
  ------------------
  139|      0|        return SECFailure;
  140|      0|    }
  141|       |
  142|    181|    return SECSuccess;
  143|    181|}
tls13_HandleHrrCookie:
  159|     70|{
  160|     70|    SECStatus rv;
  161|     70|    unsigned char plaintext[1024];
  162|     70|    unsigned int plaintextLen = 0;
  163|     70|    sslBuffer messageBuf = SSL_BUFFER_EMPTY;
  ------------------
  |  |   23|     70|    {                        \
  |  |   24|     70|        NULL, 0, 0, PR_FALSE \
  |  |  ------------------
  |  |  |  |  438|     70|#define PR_FALSE 0
  |  |  ------------------
  |  |   25|     70|    }
  ------------------
  164|     70|    sslReadBuffer echHpkeBuf = { 0 };
  165|     70|    PRBool receivedEch;
  166|     70|    PRUint64 sentinel;
  167|     70|    PRUint64 cipherSuite;
  168|     70|    sslEchCookieData parsedEchData = { 0 };
  169|     70|    sslReadBuffer greaseReadBuf = { 0 };
  170|     70|    PRUint64 group;
  171|     70|    PRUint64 tmp64;
  172|     70|    const sslNamedGroupDef *selectedGroup;
  173|     70|    PRUint64 appTokenLen;
  174|       |
  175|     70|    rv = ssl_SelfEncryptUnprotect(ss, cookie, cookieLen,
  176|     70|                                  plaintext, &plaintextLen, sizeof(plaintext));
  177|     70|    if (rv != SECSuccess) {
  ------------------
  |  Branch (177:9): [True: 1, False: 69]
  ------------------
  178|      1|        SSL_TRC(100, ("Error decrypting cookie."));
  ------------------
  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  ------------------
  |  |   72|      1|    ssl_Trace b
  ------------------
  179|      1|        return SECFailure;
  180|      1|    }
  181|       |
  182|     69|    sslReader reader = SSL_READER(plaintext, plaintextLen);
  ------------------
  |  |   85|     69|    {                    \
  |  |   86|     69|        { b, l }, 0      \
  |  |   87|     69|    }
  ------------------
  183|       |
  184|       |    /* Should start with the sentinel value. */
  185|     69|    rv = sslRead_ReadNumber(&reader, 1, &sentinel);
  186|     69|    if ((rv != SECSuccess) || (sentinel != TLS13_COOKIE_SENTINEL)) {
  ------------------
  |  |   22|     67|#define TLS13_COOKIE_SENTINEL 0xff
  ------------------
  |  Branch (186:9): [True: 2, False: 67]
  |  Branch (186:31): [True: 12, False: 55]
  ------------------
  187|     14|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|     14|    do {                                     \
  |  |   23|     14|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     14|    do {                                                                           \
  |  |  |  |   15|     14|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     14|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 14]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     14|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     14|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     14|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     14|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     14|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     14|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     14|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  188|     14|        return SECFailure;
  189|     14|    }
  190|       |    /* The cipher suite should be the same or there are some shenanigans. */
  191|     55|    rv = sslRead_ReadNumber(&reader, 2, &cipherSuite);
  192|     55|    if (rv != SECSuccess) {
  ------------------
  |  Branch (192:9): [True: 1, False: 54]
  ------------------
  193|      1|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  194|      1|        return SECFailure;
  195|      1|    }
  196|       |
  197|       |    /* The named group, if any. */
  198|     54|    rv = sslRead_ReadNumber(&reader, 2, &group);
  199|     54|    if (rv != SECSuccess) {
  ------------------
  |  Branch (199:9): [True: 1, False: 53]
  ------------------
  200|      1|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  201|      1|        return SECFailure;
  202|      1|    }
  203|     53|    selectedGroup = ssl_LookupNamedGroup(group);
  204|       |
  205|       |    /* Was ECH received. */
  206|     53|    rv = sslRead_ReadNumber(&reader, 1, &tmp64);
  207|     53|    if (rv != SECSuccess) {
  ------------------
  |  Branch (207:9): [True: 1, False: 52]
  ------------------
  208|      1|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  209|      1|        return SECFailure;
  210|      1|    }
  211|     52|    receivedEch = tmp64 == PR_TRUE;
  ------------------
  |  |  437|     52|#define PR_TRUE 1
  ------------------
  212|     52|    *previousOfferedEch = receivedEch;
  213|     52|    if (receivedEch) {
  ------------------
  |  Branch (213:9): [True: 8, False: 44]
  ------------------
  214|       |        /* ECH config ID */
  215|      8|        rv = sslRead_ReadNumber(&reader, 1, &tmp64);
  216|      8|        if (rv != SECSuccess) {
  ------------------
  |  Branch (216:13): [True: 1, False: 7]
  ------------------
  217|      1|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  218|      1|            return SECFailure;
  219|      1|        }
  220|      7|        parsedEchData.configId = (PRUint8)tmp64;
  221|       |
  222|       |        /* ECH Ciphersuite */
  223|      7|        rv = sslRead_ReadNumber(&reader, 2, &tmp64);
  224|      7|        if (rv != SECSuccess) {
  ------------------
  |  Branch (224:13): [True: 1, False: 6]
  ------------------
  225|      1|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  226|      1|            return SECFailure;
  227|      1|        }
  228|      6|        parsedEchData.kdfId = (HpkeKdfId)tmp64;
  229|       |
  230|      6|        rv = sslRead_ReadNumber(&reader, 2, &tmp64);
  231|      6|        if (rv != SECSuccess) {
  ------------------
  |  Branch (231:13): [True: 1, False: 5]
  ------------------
  232|      1|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  233|      1|            return SECFailure;
  234|      1|        }
  235|      5|        parsedEchData.aeadId = (HpkeAeadId)tmp64;
  236|       |
  237|       |        /* ECH accept_confirmation signal. */
  238|      5|        rv = sslRead_Read(&reader, TLS13_ECH_SIGNAL_LEN, &greaseReadBuf);
  ------------------
  |  |   25|      5|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
  239|      5|        if (rv != SECSuccess) {
  ------------------
  |  Branch (239:13): [True: 3, False: 2]
  ------------------
  240|      3|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      3|    do {                                     \
  |  |   23|      3|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      3|    do {                                                                           \
  |  |  |  |   15|      3|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      3|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 3]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      3|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      3|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      3|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      3|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      3|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      3|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  241|      3|            return SECFailure;
  242|      3|        }
  243|      2|        PORT_Memcpy(parsedEchData.signal, greaseReadBuf.buf, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |  180|      2|#define PORT_Memcpy memcpy
  ------------------
                      PORT_Memcpy(parsedEchData.signal, greaseReadBuf.buf, TLS13_ECH_SIGNAL_LEN);
  ------------------
  |  |   25|      2|#define TLS13_ECH_SIGNAL_LEN 8
  ------------------
  244|       |
  245|       |        /* ECH HPKE context may be empty. */
  246|      2|        rv = sslRead_ReadVariable(&reader, 2, &echHpkeBuf);
  247|      2|        if (rv != SECSuccess) {
  ------------------
  |  Branch (247:13): [True: 1, False: 1]
  ------------------
  248|      1|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  249|      1|            return SECFailure;
  250|      1|        }
  251|      1|        if (echData && echHpkeBuf.len) {
  ------------------
  |  Branch (251:13): [True: 0, False: 1]
  |  Branch (251:24): [True: 0, False: 0]
  ------------------
  252|      0|            const SECItem hpkeItem = { siBuffer, CONST_CAST(unsigned char, echHpkeBuf.buf),
  ------------------
  |  |   96|      0|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
  253|      0|                                       echHpkeBuf.len };
  254|      0|            parsedEchData.hpkeCtx = PK11_HPKE_ImportContext(&hpkeItem, NULL);
  255|      0|            if (!parsedEchData.hpkeCtx) {
  ------------------
  |  Branch (255:17): [True: 0, False: 0]
  ------------------
  256|      0|                FATAL_ERROR(ss, PORT_GetError(), illegal_parameter);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  257|      0|                return SECFailure;
  258|      0|            }
  259|      0|        }
  260|      1|    }
  261|       |
  262|       |    /* Application token. */
  263|     45|    rv = sslRead_ReadNumber(&reader, 2, &appTokenLen);
  264|     45|    if (rv != SECSuccess) {
  ------------------
  |  Branch (264:9): [True: 1, False: 44]
  ------------------
  265|      1|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      1|    do {                                     \
  |  |   23|      1|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      1|    do {                                                                           \
  |  |  |  |   15|      1|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      1|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 1]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      1|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      1|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      1|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      1|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      1|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      1|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  266|      1|        return SECFailure;
  267|      1|    }
  268|     44|    sslReadBuffer appTokenReader = { 0 };
  269|     44|    rv = sslRead_Read(&reader, appTokenLen, &appTokenReader);
  270|     44|    if (rv != SECSuccess) {
  ------------------
  |  Branch (270:9): [True: 17, False: 27]
  ------------------
  271|     17|        FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|     17|    do {                                     \
  |  |   23|     17|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|     17|    do {                                                                           \
  |  |  |  |   15|     17|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|     17|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 17]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|     17|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|     17|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|     17|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|     17|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|     17|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|     17|        tls13_FatalError(ss, prError, desc); \
  |  |   25|     17|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  272|     17|        return SECFailure;
  273|     17|    }
  274|     27|    PORT_Assert(appTokenReader.len == appTokenLen);
  ------------------
  |  |  120|     27|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     27|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 27, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  275|       |
  276|     27|    if (recoverState) {
  ------------------
  |  Branch (276:9): [True: 7, False: 20]
  ------------------
  277|      7|        PORT_Assert(ss->xtnData.applicationToken.len == 0);
  ------------------
  |  |  120|      7|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      7|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 7, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  278|      7|        if (SECITEM_AllocItem(NULL, &ss->xtnData.applicationToken,
  ------------------
  |  |  103|      7|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  |  Branch (278:13): [True: 0, False: 7]
  ------------------
  279|      7|                              appTokenLen) == NULL) {
  280|      0|            FATAL_ERROR(ss, PORT_GetError(), internal_error);
  ------------------
  |  |   22|      0|    do {                                     \
  |  |   23|      0|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      0|    do {                                                                           \
  |  |  |  |   15|      0|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      0|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      0|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      0|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      0|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      0|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  281|      0|            return SECFailure;
  282|      0|        }
  283|      7|        PORT_Memcpy(ss->xtnData.applicationToken.data, appTokenReader.buf, appTokenLen);
  ------------------
  |  |  180|      7|#define PORT_Memcpy memcpy
  ------------------
  284|      7|        ss->xtnData.applicationToken.len = appTokenLen;
  285|       |
  286|       |        /* The remainder is the hash. */
  287|      7|        unsigned int hashLen = SSL_READER_REMAINING(&reader);
  ------------------
  |  |   91|      7|    ((r)->buf.len - (r)->offset)
  ------------------
  288|      7|        if (hashLen != tls13_GetHashSize(ss)) {
  ------------------
  |  Branch (288:13): [True: 7, False: 0]
  ------------------
  289|      7|            FATAL_ERROR(ss, SSL_ERROR_RX_MALFORMED_CLIENT_HELLO, illegal_parameter);
  ------------------
  |  |   22|      7|    do {                                     \
  |  |   23|      7|        LOG_ERROR(ss, prError);              \
  |  |  ------------------
  |  |  |  |   14|      7|    do {                                                                           \
  |  |  |  |   15|      7|        SSL_TRC(3, ("%d: TLS13[%d]: fatal error %d in %s (%s:%d)",                 \
  |  |  |  |  ------------------
  |  |  |  |  |  |   71|      7|    if (ssl_trace >= (a)) \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (71:9): [True: 0, False: 7]
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |   72|      7|    ssl_Trace b
  |  |  |  |  ------------------
  |  |  |  |   16|      7|                    SSL_GETPID(), ss->fd, prError, __func__, __FILE__, __LINE__)); \
  |  |  |  |   17|      7|        PORT_SetError(prError);                                                    \
  |  |  |  |  ------------------
  |  |  |  |  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  |  |  |  |  ------------------
  |  |  |  |   18|      7|    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (18:14): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   24|      7|        tls13_FatalError(ss, prError, desc); \
  |  |   25|      7|    } while (0)
  |  |  ------------------
  |  |  |  Branch (25:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  290|      7|            return SECFailure;
  291|      7|        }
  292|       |
  293|       |        /* Now reinject the message. */
  294|      0|        SSL_ASSERT_HASHES_EMPTY(ss);
  ------------------
  |  |  815|      0|    do {                                                             \
  |  |  816|      0|        PORT_Assert(ss->ssl3.hs.hashType == handshake_hash_unknown); \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  817|      0|        PORT_Assert(ss->ssl3.hs.messages.len == 0);                  \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  818|      0|        PORT_Assert(ss->ssl3.hs.echInnerMessages.len == 0);          \
  |  |  ------------------
  |  |  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  819|      0|    } while (0)
  |  |  ------------------
  |  |  |  Branch (819:14): [Folded - Ignored]
  |  |  ------------------
  ------------------
  295|      0|        rv = ssl_HashHandshakeMessageInt(ss, ssl_hs_message_hash, 0,
  296|      0|                                         SSL_READER_CURRENT(&reader), hashLen,
  ------------------
  |  |   89|      0|    ((r)->buf.buf + (r)->offset)
  ------------------
  297|      0|                                         ssl3_UpdateHandshakeHashes);
  298|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (298:13): [True: 0, False: 0]
  ------------------
  299|      0|            return SECFailure;
  300|      0|        }
  301|       |
  302|       |        /* And finally reinject the HRR. */
  303|      0|        rv = tls13_ConstructHelloRetryRequest(ss, cipherSuite,
  304|      0|                                              selectedGroup,
  305|      0|                                              cookie, cookieLen,
  306|      0|                                              parsedEchData.signal,
  307|      0|                                              &messageBuf);
  308|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (308:13): [True: 0, False: 0]
  ------------------
  309|      0|            return SECFailure;
  310|      0|        }
  311|       |
  312|      0|        rv = ssl_HashHandshakeMessageInt(ss, ssl_hs_server_hello, 0,
  313|      0|                                         SSL_BUFFER_BASE(&messageBuf),
  ------------------
  |  |   35|      0|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
  314|      0|                                         SSL_BUFFER_LEN(&messageBuf),
  ------------------
  |  |   36|      0|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
  315|      0|                                         ssl3_UpdateHandshakeHashes);
  316|      0|        sslBuffer_Clear(&messageBuf);
  317|      0|        if (rv != SECSuccess) {
  ------------------
  |  Branch (317:13): [True: 0, False: 0]
  ------------------
  318|      0|            return SECFailure;
  319|      0|        }
  320|      0|    }
  321|       |
  322|     20|    if (previousCipherSuite) {
  ------------------
  |  Branch (322:9): [True: 0, False: 20]
  ------------------
  323|      0|        *previousCipherSuite = cipherSuite;
  324|      0|    }
  325|     20|    if (previousGroup) {
  ------------------
  |  Branch (325:9): [True: 0, False: 20]
  ------------------
  326|      0|        *previousGroup = selectedGroup;
  327|      0|    }
  328|     20|    if (echData) {
  ------------------
  |  Branch (328:9): [True: 20, False: 0]
  ------------------
  329|     20|        PORT_Memcpy(echData, &parsedEchData, sizeof(parsedEchData));
  ------------------
  |  |  180|     20|#define PORT_Memcpy memcpy
  ------------------
  330|     20|    }
  331|     20|    return SECSuccess;
  332|     27|}

tls13_HkdfExtract:
   36|  3.65k|{
   37|  3.65k|    CK_HKDF_PARAMS params;
   38|  3.65k|    SECItem paramsi;
   39|  3.65k|    PK11SymKey *prk;
   40|  3.65k|    static const PRUint8 zeroKeyBuf[HASH_LENGTH_MAX];
   41|  3.65k|    SECItem zeroKeyItem = { siBuffer, CONST_CAST(PRUint8, zeroKeyBuf), kTlsHkdfInfo[baseHash].hashSize };
  ------------------
  |  |   96|  3.65k|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
   42|  3.65k|    PK11SlotInfo *slot = NULL;
   43|  3.65k|    PK11SymKey *newIkm2 = NULL;
   44|  3.65k|    PK11SymKey *newIkm1 = NULL;
   45|  3.65k|    SECStatus rv;
   46|       |
   47|  3.65k|    params.bExtract = CK_TRUE;
  ------------------
  |  |   22|  3.65k|#define CK_TRUE 1
  ------------------
   48|  3.65k|    params.bExpand = CK_FALSE;
  ------------------
  |  |   23|  3.65k|#define CK_FALSE 0
  ------------------
   49|  3.65k|    params.prfHashMechanism = kTlsHkdfInfo[baseHash].pkcs11Mech;
   50|  3.65k|    params.pInfo = NULL;
   51|  3.65k|    params.ulInfoLen = 0UL;
   52|  3.65k|    params.pSalt = NULL;
   53|  3.65k|    params.ulSaltLen = 0UL;
   54|  3.65k|    params.hSaltKey = CK_INVALID_HANDLE;
  ------------------
  |  |   78|  3.65k|#define CK_INVALID_HANDLE 0
  ------------------
   55|       |
   56|  3.65k|    if (!ikm1) {
  ------------------
  |  Branch (56:9): [True: 1.22k, False: 2.42k]
  ------------------
   57|       |        /* PKCS #11 v3.0 has and explict NULL value, which equates to
   58|       |         * a sequence of zeros equal in length to the HMAC. */
   59|  1.22k|        params.ulSaltType = CKF_HKDF_SALT_NULL;
  ------------------
  |  | 2252|  1.22k|#define CKF_HKDF_SALT_NULL 0x00000001UL
  ------------------
   60|  2.42k|    } else {
   61|       |        /* PKCS #11 v3.0 can take the salt as a key handle */
   62|  2.42k|        params.hSaltKey = PK11_GetSymKeyHandle(ikm1);
   63|  2.42k|        params.ulSaltType = CKF_HKDF_SALT_KEY;
  ------------------
  |  | 2254|  2.42k|#define CKF_HKDF_SALT_KEY 0x00000004UL
  ------------------
   64|       |
   65|       |        /* if we have both keys, make sure they are in the same slot */
   66|  2.42k|        if (ikm2) {
  ------------------
  |  Branch (66:13): [True: 1.21k, False: 1.21k]
  ------------------
   67|  1.21k|            rv = PK11_SymKeysToSameSlot(CKM_HKDF_DERIVE,
  ------------------
  |  | 1296|  1.21k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
   68|  1.21k|                                        CKA_DERIVE, CKA_DERIVE,
  ------------------
  |  |  555|  1.21k|#define CKA_DERIVE 0x0000010CUL
  ------------------
                                                      CKA_DERIVE, CKA_DERIVE,
  ------------------
  |  |  555|  1.21k|#define CKA_DERIVE 0x0000010CUL
  ------------------
   69|  1.21k|                                        ikm2, ikm1, &newIkm2, &newIkm1);
   70|  1.21k|            if (rv != SECSuccess) {
  ------------------
  |  Branch (70:17): [True: 0, False: 1.21k]
  ------------------
   71|      0|                SECItem *salt;
   72|       |                /* couldn't move the keys, try extracting the salt */
   73|      0|                rv = PK11_ExtractKeyValue(ikm1);
   74|      0|                if (rv != SECSuccess)
  ------------------
  |  Branch (74:21): [True: 0, False: 0]
  ------------------
   75|      0|                    return rv;
   76|      0|                salt = PK11_GetKeyData(ikm1);
   77|      0|                if (!salt)
  ------------------
  |  Branch (77:21): [True: 0, False: 0]
  ------------------
   78|      0|                    return SECFailure;
   79|      0|                PORT_Assert(salt->len > 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   80|       |                /* Set up for Salt as Data instead of Salt as key */
   81|      0|                params.pSalt = salt->data;
   82|      0|                params.ulSaltLen = salt->len;
   83|      0|                params.ulSaltType = CKF_HKDF_SALT_DATA;
  ------------------
  |  | 2253|      0|#define CKF_HKDF_SALT_DATA 0x00000002UL
  ------------------
   84|      0|            }
   85|       |            /* use the new keys */
   86|  1.21k|            if (newIkm1) {
  ------------------
  |  Branch (86:17): [True: 1.21k, False: 0]
  ------------------
   87|       |                /* we've moved the key, get the handle for the new key */
   88|  1.21k|                params.hSaltKey = PK11_GetSymKeyHandle(newIkm1);
   89|       |                /* we don't use ikm1 after this, so don't bother setting it */
   90|  1.21k|            }
   91|  1.21k|            if (newIkm2) {
  ------------------
  |  Branch (91:17): [True: 0, False: 1.21k]
  ------------------
   92|       |                /* new ikm2 key, use the new key */
   93|      0|                ikm2 = newIkm2;
   94|      0|            }
   95|  1.21k|        }
   96|  2.42k|    }
   97|  3.65k|    paramsi.data = (unsigned char *)&params;
   98|  3.65k|    paramsi.len = sizeof(params);
   99|       |
  100|  3.65k|    PORT_Assert(kTlsHkdfInfo[baseHash].pkcs11Mech);
  ------------------
  |  |  120|  3.65k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.65k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  101|  3.65k|    PORT_Assert(kTlsHkdfInfo[baseHash].hashSize);
  ------------------
  |  |  120|  3.65k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.65k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  102|  3.65k|    PORT_Assert(kTlsHkdfInfo[baseHash].hash == baseHash);
  ------------------
  |  |  120|  3.65k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.65k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  103|       |
  104|       |    /* A zero ikm2 is a key of hash-length 0s. */
  105|  3.65k|    if (!ikm2) {
  ------------------
  |  Branch (105:9): [True: 2.42k, False: 1.22k]
  ------------------
  106|       |        /* if we have ikm1, put the zero key in the same slot */
  107|  2.42k|        slot = ikm1 ? PK11_GetSlotFromKey(ikm1) : PK11_GetBestSlot(CKM_HKDF_DERIVE, NULL);
  ------------------
  |  | 1296|  1.21k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  |  Branch (107:16): [True: 1.21k, False: 1.21k]
  ------------------
  108|  2.42k|        if (!slot) {
  ------------------
  |  Branch (108:13): [True: 0, False: 2.42k]
  ------------------
  109|      0|            return SECFailure;
  110|      0|        }
  111|       |
  112|  2.42k|        newIkm2 = PK11_ImportDataKey(slot, CKM_HKDF_DERIVE, PK11_OriginUnwrap,
  ------------------
  |  | 1296|  2.42k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  113|  2.42k|                                     CKA_DERIVE, &zeroKeyItem, NULL);
  ------------------
  |  |  555|  2.42k|#define CKA_DERIVE 0x0000010CUL
  ------------------
  114|  2.42k|        if (!newIkm2) {
  ------------------
  |  Branch (114:13): [True: 0, False: 2.42k]
  ------------------
  115|      0|            return SECFailure;
  116|      0|        }
  117|  2.42k|        ikm2 = newIkm2;
  118|  2.42k|    }
  119|  3.65k|    PORT_Assert(ikm2);
  ------------------
  |  |  120|  3.65k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  3.65k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3.65k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  120|       |
  121|  3.65k|    PRINT_BUF(50, (NULL, "HKDF Extract: IKM1/Salt", params.pSalt, params.ulSaltLen));
  ------------------
  |  |   74|  3.65k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 3.65k]
  |  |  ------------------
  |  |   75|  3.65k|    ssl_PrintBuf b
  ------------------
  122|  3.65k|    PRINT_KEY(50, (NULL, "HKDF Extract: IKM2", ikm2));
  ------------------
  |  |   77|  3.65k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (77:9): [True: 0, False: 3.65k]
  |  |  ------------------
  |  |   78|  3.65k|    ssl_PrintKey b
  ------------------
  123|       |
  124|  3.65k|    prk = PK11_Derive(ikm2, CKM_HKDF_DERIVE, &paramsi, CKM_HKDF_DERIVE,
  ------------------
  |  | 1296|  3.65k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
                  prk = PK11_Derive(ikm2, CKM_HKDF_DERIVE, &paramsi, CKM_HKDF_DERIVE,
  ------------------
  |  | 1296|  3.65k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  125|  3.65k|                      CKA_DERIVE, 0);
  ------------------
  |  |  555|  3.65k|#define CKA_DERIVE 0x0000010CUL
  ------------------
  126|  3.65k|    PK11_FreeSymKey(newIkm2);
  127|  3.65k|    PK11_FreeSymKey(newIkm1);
  128|  3.65k|    if (slot)
  ------------------
  |  Branch (128:9): [True: 2.42k, False: 1.22k]
  ------------------
  129|  2.42k|        PK11_FreeSlot(slot);
  130|  3.65k|    if (!prk) {
  ------------------
  |  Branch (130:9): [True: 0, False: 3.65k]
  ------------------
  131|      0|        return SECFailure;
  132|      0|    }
  133|       |
  134|  3.65k|    PRINT_KEY(50, (NULL, "HKDF Extract", prk));
  ------------------
  |  |   77|  3.65k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (77:9): [True: 0, False: 3.65k]
  |  |  ------------------
  |  |   78|  3.65k|    ssl_PrintKey b
  ------------------
  135|  3.65k|    *prkp = prk;
  136|       |
  137|  3.65k|    return SECSuccess;
  138|  3.65k|}
tls13_HkdfExpandLabelGeneral:
  147|   842k|{
  148|   842k|    CK_HKDF_PARAMS params;
  149|   842k|    SECItem paramsi = { siBuffer, NULL, 0 };
  150|       |    /* Size of info array needs to be big enough to hold the maximum Prefix,
  151|       |     * Label, plus HandshakeHash. If it's ever to small, the code will abort.
  152|       |     */
  153|   842k|    PRUint8 info[256];
  154|   842k|    sslBuffer infoBuf = SSL_BUFFER(info);
  ------------------
  |  |   34|   842k|#define SSL_BUFFER(b) SSL_BUFFER_FIXED(b, sizeof(b))
  |  |  ------------------
  |  |  |  |   27|   842k|    {                               \
  |  |  |  |   28|   842k|        b, 0, maxlen, PR_TRUE       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  437|   842k|#define PR_TRUE 1
  |  |  |  |  ------------------
  |  |  |  |   29|   842k|    }
  |  |  ------------------
  ------------------
  155|   842k|    PK11SymKey *derived;
  156|   842k|    SECStatus rv;
  157|   842k|    const char *kLabelPrefixTls = "tls13 ";
  158|   842k|    const char *kLabelPrefixDtls = "dtls13";
  159|   842k|    const unsigned int kLabelPrefixLen =
  160|   842k|        (variant == ssl_variant_stream) ? strlen(kLabelPrefixTls) : strlen(kLabelPrefixDtls);
  ------------------
  |  Branch (160:9): [True: 842k, False: 0]
  ------------------
  161|   842k|    const char *kLabelPrefix =
  162|   842k|        (variant == ssl_variant_stream) ? kLabelPrefixTls : kLabelPrefixDtls;
  ------------------
  |  Branch (162:9): [True: 842k, False: 0]
  ------------------
  163|       |
  164|   842k|    PORT_Assert(prk);
  ------------------
  |  |  120|   842k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   842k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 842k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  165|   842k|    PORT_Assert(keyp);
  ------------------
  |  |  120|   842k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   842k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 842k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  166|   842k|    if ((handshakeHashLen > 255) ||
  ------------------
  |  Branch (166:9): [True: 0, False: 842k]
  ------------------
  167|   842k|        (handshakeHash == NULL && handshakeHashLen > 0) ||
  ------------------
  |  Branch (167:10): [True: 833k, False: 9.18k]
  |  Branch (167:35): [True: 0, False: 833k]
  ------------------
  168|   842k|        (labelLen + kLabelPrefixLen > 255)) {
  ------------------
  |  Branch (168:9): [True: 0, False: 842k]
  ------------------
  169|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  170|      0|        return SECFailure;
  171|      0|    }
  172|       |
  173|       |    /*
  174|       |     *  [draft-ietf-tls-tls13-11] Section 7.1:
  175|       |     *
  176|       |     *  HKDF-Expand-Label(Secret, Label, HashValue, Length) =
  177|       |     *       HKDF-Expand(Secret, HkdfLabel, Length)
  178|       |     *
  179|       |     *  Where HkdfLabel is specified as:
  180|       |     *
  181|       |     *  struct HkdfLabel {
  182|       |     *    uint16 length;
  183|       |     *    opaque label<9..255>;
  184|       |     *    opaque hash_value<0..255>;
  185|       |     *  };
  186|       |     *
  187|       |     *  Where:
  188|       |     *  - HkdfLabel.length is Length
  189|       |     *  - HkdfLabel.hash_value is HashValue.
  190|       |     *  - HkdfLabel.label is "TLS 1.3, " + Label
  191|       |     *
  192|       |     */
  193|   842k|    rv = sslBuffer_AppendNumber(&infoBuf, keySize, 2);
  194|   842k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (194:9): [True: 0, False: 842k]
  ------------------
  195|      0|        return SECFailure;
  196|      0|    }
  197|   842k|    rv = sslBuffer_AppendNumber(&infoBuf, labelLen + kLabelPrefixLen, 1);
  198|   842k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (198:9): [True: 0, False: 842k]
  ------------------
  199|      0|        return SECFailure;
  200|      0|    }
  201|   842k|    rv = sslBuffer_Append(&infoBuf, kLabelPrefix, kLabelPrefixLen);
  202|   842k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (202:9): [True: 0, False: 842k]
  ------------------
  203|      0|        return SECFailure;
  204|      0|    }
  205|   842k|    rv = sslBuffer_Append(&infoBuf, label, labelLen);
  206|   842k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (206:9): [True: 0, False: 842k]
  ------------------
  207|      0|        return SECFailure;
  208|      0|    }
  209|   842k|    rv = sslBuffer_AppendVariable(&infoBuf, handshakeHash, handshakeHashLen, 1);
  210|   842k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (210:9): [True: 0, False: 842k]
  ------------------
  211|      0|        return SECFailure;
  212|      0|    }
  213|       |
  214|   842k|    params.bExtract = CK_FALSE;
  ------------------
  |  |   23|   842k|#define CK_FALSE 0
  ------------------
  215|   842k|    params.bExpand = CK_TRUE;
  ------------------
  |  |   22|   842k|#define CK_TRUE 1
  ------------------
  216|   842k|    params.prfHashMechanism = kTlsHkdfInfo[baseHash].pkcs11Mech;
  217|   842k|    params.pInfo = SSL_BUFFER_BASE(&infoBuf);
  ------------------
  |  |   35|   842k|#define SSL_BUFFER_BASE(b) ((b)->buf)
  ------------------
  218|   842k|    params.ulInfoLen = SSL_BUFFER_LEN(&infoBuf);
  ------------------
  |  |   36|   842k|#define SSL_BUFFER_LEN(b) ((b)->len)
  ------------------
  219|   842k|    paramsi.data = (unsigned char *)&params;
  220|   842k|    paramsi.len = sizeof(params);
  221|   842k|    derived = PK11_DeriveWithFlags(prk, deriveMech,
  222|   842k|                                   &paramsi, algorithm,
  223|   842k|                                   CKA_DERIVE, keySize,
  ------------------
  |  |  555|   842k|#define CKA_DERIVE 0x0000010CUL
  ------------------
  224|   842k|                                   CKF_SIGN | CKF_VERIFY);
  ------------------
  |  | 1356|   842k|#define CKF_SIGN 0x00000800UL
  ------------------
                                                 CKF_SIGN | CKF_VERIFY);
  ------------------
  |  | 1358|   842k|#define CKF_VERIFY 0x00002000
  ------------------
  225|   842k|    if (!derived) {
  ------------------
  |  Branch (225:9): [True: 0, False: 842k]
  ------------------
  226|      0|        return SECFailure;
  227|      0|    }
  228|       |
  229|   842k|    *keyp = derived;
  230|       |
  231|   842k|#ifdef TRACE
  232|   842k|    if (ssl_trace >= 50) {
  ------------------
  |  Branch (232:9): [True: 0, False: 842k]
  ------------------
  233|       |        /* Make sure the label is null terminated. */
  234|      0|        char labelStr[100];
  235|      0|        PORT_Memcpy(labelStr, label, labelLen);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  236|      0|        labelStr[labelLen] = 0;
  237|      0|        SSL_TRC(50, ("HKDF Expand: label='tls13 %s',requested length=%d",
  ------------------
  |  |   71|      0|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (71:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   72|      0|    ssl_Trace b
  ------------------
  238|      0|                     labelStr, keySize));
  239|      0|    }
  240|   842k|    PRINT_KEY(50, (NULL, "PRK", prk));
  ------------------
  |  |   77|   842k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (77:9): [True: 0, False: 842k]
  |  |  ------------------
  |  |   78|   842k|    ssl_PrintKey b
  ------------------
  241|   842k|    PRINT_BUF(50, (NULL, "Hash", handshakeHash, handshakeHashLen));
  ------------------
  |  |   74|   842k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 842k]
  |  |  ------------------
  |  |   75|   842k|    ssl_PrintBuf b
  ------------------
  242|   842k|    PRINT_BUF(50, (NULL, "Info", SSL_BUFFER_BASE(&infoBuf),
  ------------------
  |  |   74|   842k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (74:9): [True: 0, False: 842k]
  |  |  ------------------
  |  |   75|   842k|    ssl_PrintBuf b
  ------------------
  243|   842k|                   SSL_BUFFER_LEN(&infoBuf)));
  244|   842k|    PRINT_KEY(50, (NULL, "Derived key", derived));
  ------------------
  |  |   77|   842k|    if (ssl_trace >= (a)) \
  |  |  ------------------
  |  |  |  Branch (77:9): [True: 0, False: 842k]
  |  |  ------------------
  |  |   78|   842k|    ssl_PrintKey b
  ------------------
  245|   842k|#endif
  246|       |
  247|   842k|    return SECSuccess;
  248|   842k|}
tls13_HkdfExpandLabel:
  256|   563k|{
  257|   563k|    return tls13_HkdfExpandLabelGeneral(CKM_HKDF_DERIVE, prk, baseHash,
  ------------------
  |  | 1296|   563k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  258|   563k|                                        handshakeHash, handshakeHashLen,
  259|   563k|                                        label, labelLen, algorithm, keySize,
  260|   563k|                                        variant, keyp);
  261|   563k|}
tls13_HkdfExpandLabelRaw:
  269|   278k|{
  270|   278k|    PK11SymKey *derived = NULL;
  271|   278k|    SECItem *rawkey;
  272|   278k|    SECStatus rv;
  273|       |
  274|       |    /* the result is not really a key, it's a data object */
  275|   278k|    rv = tls13_HkdfExpandLabelGeneral(CKM_HKDF_DATA, prk, baseHash,
  ------------------
  |  | 1297|   278k|#define CKM_HKDF_DATA 0x0000402bUL
  ------------------
  276|   278k|                                      handshakeHash, handshakeHashLen,
  277|   278k|                                      label, labelLen, CKM_HKDF_DERIVE, outputLen,
  ------------------
  |  | 1296|   278k|#define CKM_HKDF_DERIVE 0x0000402aUL
  ------------------
  278|   278k|                                      variant, &derived);
  279|   278k|    if (rv != SECSuccess || !derived) {
  ------------------
  |  Branch (279:9): [True: 0, False: 278k]
  |  Branch (279:29): [True: 0, False: 278k]
  ------------------
  280|      0|        goto abort;
  281|      0|    }
  282|       |
  283|   278k|    rv = PK11_ExtractKeyValue(derived);
  284|   278k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (284:9): [True: 0, False: 278k]
  ------------------
  285|      0|        goto abort;
  286|      0|    }
  287|       |
  288|   278k|    rawkey = PK11_GetKeyData(derived);
  289|   278k|    if (!rawkey) {
  ------------------
  |  Branch (289:9): [True: 0, False: 278k]
  ------------------
  290|      0|        goto abort;
  291|      0|    }
  292|       |
  293|   278k|    PORT_Assert(rawkey->len == outputLen);
  ------------------
  |  |  120|   278k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   278k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 278k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  294|   278k|    memcpy(output, rawkey->data, outputLen);
  295|   278k|    PK11_FreeSymKey(derived);
  296|       |
  297|   278k|    return SECSuccess;
  298|       |
  299|      0|abort:
  300|      0|    if (derived) {
  ------------------
  |  Branch (300:9): [True: 0, False: 0]
  ------------------
  301|      0|        PK11_FreeSymKey(derived);
  302|      0|    }
  303|      0|    PORT_SetError(SSL_ERROR_SYM_KEY_CONTEXT_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  304|      0|    return SECFailure;
  305|   278k|}

SSLExp_AddExternalPsk0Rtt:
   21|  4.72k|{
   22|       |
   23|  4.72k|    sslSocket *ss = ssl_FindSocket(fd);
   24|  4.72k|    if (!ss) {
  ------------------
  |  Branch (24:9): [True: 0, False: 4.72k]
  ------------------
   25|      0|        SSL_DBG(("%d: SSL[%d]: bad socket in SSLExp_SetExternalPsk",
  ------------------
  |  |   87|      0|    if (ssl_debug) \
  |  |  ------------------
  |  |  |  Branch (87:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   88|      0|    ssl_Trace b
  ------------------
   26|      0|                 SSL_GETPID(), fd));
   27|      0|        return SECFailure;
   28|      0|    }
   29|       |
   30|  4.72k|    if (!key || !identity || !identityLen || identityLen > 0xFFFF ||
  ------------------
  |  Branch (30:9): [True: 0, False: 4.72k]
  |  Branch (30:17): [True: 0, False: 4.72k]
  |  Branch (30:30): [True: 0, False: 4.72k]
  |  Branch (30:46): [True: 0, False: 4.72k]
  ------------------
   31|  4.72k|        (hash != ssl_hash_sha256 && hash != ssl_hash_sha384)) {
  ------------------
  |  Branch (31:10): [True: 2.27k, False: 2.44k]
  |  Branch (31:37): [True: 0, False: 2.27k]
  ------------------
   32|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   33|      0|        return SECFailure;
   34|      0|    }
   35|       |
   36|  4.72k|    SECItem label = { siBuffer, CONST_CAST(unsigned char, identity), identityLen };
  ------------------
  |  |   96|  4.72k|#define CONST_CAST(T, X) ((T *)(X))
  ------------------
   37|  4.72k|    sslPsk *psk = tls13_MakePsk(PK11_ReferenceSymKey(key), ssl_psk_external,
   38|  4.72k|                                hash, &label);
   39|  4.72k|    if (!psk) {
  ------------------
  |  Branch (39:9): [True: 0, False: 4.72k]
  ------------------
   40|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   41|      0|        return SECFailure;
   42|      0|    }
   43|  4.72k|    psk->zeroRttSuite = zeroRttSuite;
   44|  4.72k|    psk->maxEarlyData = maxEarlyData;
   45|  4.72k|    SECStatus rv = SECFailure;
   46|       |
   47|  4.72k|    ssl_Get1stHandshakeLock(ss);
  ------------------
  |  | 1390|  4.72k|    {                                                             \
  |  | 1391|  4.72k|        if (!ss->opt.noLocks) {                                   \
  |  |  ------------------
  |  |  |  Branch (1391:13): [True: 4.72k, False: 0]
  |  |  ------------------
  |  | 1392|  4.72k|            PORT_Assert(PZ_InMonitor((ss)->firstHandshakeLock) || \
  |  |  ------------------
  |  |  |  |  120|  4.72k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  9.44k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:7): [True: 0, False: 4.72k]
  |  |  |  |  |  |  |  Branch (208:7): [True: 4.72k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1393|  4.72k|                        !ssl_HaveRecvBufLock(ss));                \
  |  | 1394|  4.72k|            PZ_EnterMonitor((ss)->firstHandshakeLock);            \
  |  |  ------------------
  |  |  |  |  256|  4.72k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1395|  4.72k|        }                                                         \
  |  | 1396|  4.72k|    }
  ------------------
   48|  4.72k|    ssl_GetSSL3HandshakeLock(ss);
  ------------------
  |  | 1407|  4.72k|    {                                                 \
  |  | 1408|  4.72k|        if (!ss->opt.noLocks) {                       \
  |  |  ------------------
  |  |  |  Branch (1408:13): [True: 4.72k, False: 0]
  |  |  ------------------
  |  | 1409|  4.72k|            PORT_Assert(!ssl_HaveXmitBufLock(ss));    \
  |  |  ------------------
  |  |  |  |  120|  4.72k|#define PORT_Assert PR_ASSERT
  |  |  |  |  ------------------
  |  |  |  |  |  |  208|  4.72k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (208:6): [True: 4.72k, False: 0]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  | 1410|  4.72k|            PZ_EnterMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  256|  4.72k|#define PZ_EnterMonitor(m) PR_EnterMonitor((m))
  |  |  ------------------
  |  | 1411|  4.72k|        }                                             \
  |  | 1412|  4.72k|    }
  ------------------
   49|       |
   50|  4.72k|    if (ss->psk) {
  ------------------
  |  Branch (50:9): [True: 0, False: 4.72k]
  ------------------
   51|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   52|      0|        tls13_DestroyPsk(psk);
   53|  4.72k|    } else {
   54|  4.72k|        ss->psk = psk;
   55|  4.72k|        rv = SECSuccess;
   56|  4.72k|        tls13_ResetHandshakePsks(ss, &ss->ssl3.hs.psks);
   57|  4.72k|    }
   58|       |
   59|  4.72k|    ssl_ReleaseSSL3HandshakeLock(ss);
  ------------------
  |  | 1414|  4.72k|    {                                                \
  |  | 1415|  4.72k|        if (!ss->opt.noLocks)                        \
  |  |  ------------------
  |  |  |  Branch (1415:13): [True: 4.72k, False: 0]
  |  |  ------------------
  |  | 1416|  4.72k|            PZ_ExitMonitor((ss)->ssl3HandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  4.72k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1417|  4.72k|    }
  ------------------
   60|  4.72k|    ssl_Release1stHandshakeLock(ss);
  ------------------
  |  | 1398|  4.72k|    {                                                 \
  |  | 1399|  4.72k|        if (!ss->opt.noLocks)                         \
  |  |  ------------------
  |  |  |  Branch (1399:13): [True: 4.72k, False: 0]
  |  |  ------------------
  |  | 1400|  4.72k|            PZ_ExitMonitor((ss)->firstHandshakeLock); \
  |  |  ------------------
  |  |  |  |  257|  4.72k|#define PZ_ExitMonitor(m) PR_ExitMonitor((m))
  |  |  ------------------
  |  | 1401|  4.72k|    }
  ------------------
   61|       |
   62|  4.72k|    return rv;
   63|  4.72k|}
SSLExp_AddExternalPsk:
   68|  4.72k|{
   69|  4.72k|    return SSLExp_AddExternalPsk0Rtt(fd, key, identity, identityLen,
   70|  4.72k|                                     hash, TLS_NULL_WITH_NULL_NULL, 0);
  ------------------
  |  |   76|  4.72k|#define TLS_NULL_WITH_NULL_NULL                 0x0000
  ------------------
   71|  4.72k|}
tls13_DestroyPsk:
  143|  19.1k|{
  144|  19.1k|    if (!psk) {
  ------------------
  |  Branch (144:9): [True: 4.99k, False: 14.1k]
  ------------------
  145|  4.99k|        return;
  146|  4.99k|    }
  147|  14.1k|    if (psk->key) {
  ------------------
  |  Branch (147:9): [True: 14.1k, False: 0]
  ------------------
  148|  14.1k|        PK11_FreeSymKey(psk->key);
  149|  14.1k|        psk->key = NULL;
  150|  14.1k|    }
  151|  14.1k|    if (psk->binderKey) {
  ------------------
  |  Branch (151:9): [True: 0, False: 14.1k]
  ------------------
  152|      0|        PK11_FreeSymKey(psk->binderKey);
  153|      0|        psk->binderKey = NULL;
  154|      0|    }
  155|  14.1k|    SECITEM_ZfreeItem(&psk->label, PR_FALSE);
  ------------------
  |  |  110|  14.1k|#define SECITEM_ZfreeItem SECITEM_ZfreeItem_Util
  ------------------
                  SECITEM_ZfreeItem(&psk->label, PR_FALSE);
  ------------------
  |  |  438|  14.1k|#define PR_FALSE 0
  ------------------
  156|  14.1k|    PORT_ZFree(psk, sizeof(*psk));
  ------------------
  |  |   75|  14.1k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  157|  14.1k|}
tls13_DestroyPskList:
  161|  35.0k|{
  162|  35.0k|    PRCList *cur_p;
  163|  44.5k|    while (!PR_CLIST_IS_EMPTY(list)) {
  ------------------
  |  |   94|  44.5k|    ((_l)->next == (_l))
  ------------------
  |  Branch (163:12): [True: 9.44k, False: 35.0k]
  ------------------
  164|  9.44k|        cur_p = PR_LIST_TAIL(list);
  ------------------
  |  |   66|  9.44k|#define PR_LIST_TAIL(_l) (_l)->prev
  ------------------
  165|  9.44k|        PR_REMOVE_LINK(cur_p);
  ------------------
  |  |   72|  9.44k|    PR_BEGIN_MACRO             \
  |  |  ------------------
  |  |  |  |  123|  9.44k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |   73|  9.44k|    (_e)->prev->next = (_e)->next; \
  |  |   74|  9.44k|    (_e)->next->prev = (_e)->prev; \
  |  |   75|  9.44k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.44k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  166|  9.44k|        tls13_DestroyPsk((sslPsk *)cur_p);
  167|  9.44k|    }
  168|  35.0k|}
tls13_MakePsk:
  172|  14.1k|{
  173|  14.1k|    sslPsk *psk = PORT_ZNew(sslPsk);
  ------------------
  |  |  148|  14.1k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|  14.1k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  174|  14.1k|    if (!psk) {
  ------------------
  |  Branch (174:9): [True: 0, False: 14.1k]
  ------------------
  175|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  176|      0|        return NULL;
  177|      0|    }
  178|  14.1k|    psk->type = pskType;
  179|  14.1k|    psk->hash = hashType;
  180|  14.1k|    psk->key = key;
  181|       |
  182|       |    /* Label is NULL in the resumption case. */
  183|  14.1k|    if (label) {
  ------------------
  |  Branch (183:9): [True: 14.1k, False: 0]
  ------------------
  184|  14.1k|        PORT_Assert(psk->type != ssl_psk_resume);
  ------------------
  |  |  120|  14.1k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.1k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 14.1k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  185|  14.1k|        SECStatus rv = SECITEM_CopyItem(NULL, &psk->label, label);
  ------------------
  |  |  106|  14.1k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  186|  14.1k|        if (rv != SECSuccess) {
  ------------------
  |  Branch (186:13): [True: 0, False: 14.1k]
  ------------------
  187|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  188|      0|            tls13_DestroyPsk(psk);
  189|      0|            return NULL;
  190|      0|        }
  191|  14.1k|    }
  192|       |
  193|  14.1k|    return psk;
  194|  14.1k|}
tls13_ResetHandshakePsks:
  200|  14.4k|{
  201|  14.4k|    tls13_DestroyPskList(list);
  202|  14.4k|    PORT_Assert(!ss->xtnData.selectedPsk);
  ------------------
  |  |  120|  14.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  14.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 14.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  203|  14.4k|    ss->xtnData.selectedPsk = NULL;
  204|  14.4k|    if (ss->psk) {
  ------------------
  |  Branch (204:9): [True: 9.44k, False: 4.99k]
  ------------------
  205|  9.44k|        PORT_Assert(ss->psk->type == ssl_psk_external);
  ------------------
  |  |  120|  9.44k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.44k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.44k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  206|  9.44k|        PORT_Assert(ss->psk->key);
  ------------------
  |  |  120|  9.44k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.44k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.44k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  207|  9.44k|        PORT_Assert(!ss->psk->binderKey);
  ------------------
  |  |  120|  9.44k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  9.44k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9.44k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  208|       |
  209|  9.44k|        sslPsk *epsk = tls13_MakePsk(PK11_ReferenceSymKey(ss->psk->key),
  210|  9.44k|                                     ss->psk->type, ss->psk->hash, &ss->psk->label);
  211|  9.44k|        if (!epsk) {
  ------------------
  |  Branch (211:13): [True: 0, False: 9.44k]
  ------------------
  212|      0|            return SECFailure;
  213|      0|        }
  214|  9.44k|        epsk->zeroRttSuite = ss->psk->zeroRttSuite;
  215|  9.44k|        epsk->maxEarlyData = ss->psk->maxEarlyData;
  216|  9.44k|        PR_APPEND_LINK(&epsk->link, list);
  ------------------
  |  |   57|  9.44k|#define PR_APPEND_LINK(_e,_l) PR_INSERT_BEFORE(_e,_l)
  |  |  ------------------
  |  |  |  |   25|  9.44k|    PR_BEGIN_MACRO       \
  |  |  |  |  ------------------
  |  |  |  |  |  |  123|  9.44k|#define PR_BEGIN_MACRO  do {
  |  |  |  |  ------------------
  |  |  |  |   26|  9.44k|    (_e)->next = (_l);   \
  |  |  |  |   27|  9.44k|    (_e)->prev = (_l)->prev; \
  |  |  |  |   28|  9.44k|    (_l)->prev->next = (_e); \
  |  |  |  |   29|  9.44k|    (_l)->prev = (_e);   \
  |  |  |  |   30|  9.44k|    PR_END_MACRO
  |  |  |  |  ------------------
  |  |  |  |  |  |  124|  9.44k|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  217|  9.44k|    }
  218|  14.4k|    return SECSuccess;
  219|  14.4k|}

tls13_ReleaseAntiReplayContext:
   40|  9.71k|{
   41|  9.71k|    if (!ctx) {
  ------------------
  |  Branch (41:9): [True: 9.71k, False: 0]
  ------------------
   42|  9.71k|        return;
   43|  9.71k|    }
   44|      0|    if (PR_ATOMIC_DECREMENT(&ctx->refCount) >= 1) {
  ------------------
  |  |  123|      0|#define PR_ATOMIC_DECREMENT(val) __sync_sub_and_fetch(val, 1)
  ------------------
  |  Branch (44:9): [True: 0, False: 0]
  ------------------
   45|      0|        return;
   46|      0|    }
   47|       |
   48|      0|    if (ctx->lock) {
  ------------------
  |  Branch (48:9): [True: 0, False: 0]
  ------------------
   49|      0|        PZ_DestroyMonitor(ctx->lock);
  ------------------
  |  |  255|      0|#define PZ_DestroyMonitor(m) PR_DestroyMonitor((m))
  ------------------
   50|      0|        ctx->lock = NULL;
   51|      0|    }
   52|      0|    PK11_FreeSymKey(ctx->key);
   53|      0|    ctx->key = NULL;
   54|      0|    sslBloom_Destroy(&ctx->filters[0]);
   55|      0|    sslBloom_Destroy(&ctx->filters[1]);
   56|      0|    PORT_Free(ctx);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
   57|      0|}

tls13_DestroyDelegatedCredential:
  108|  90.3k|{
  109|  90.3k|    if (!dc) {
  ------------------
  |  Branch (109:9): [True: 90.3k, False: 0]
  ------------------
  110|  90.3k|        return;
  111|  90.3k|    }
  112|       |
  113|      0|    SECKEY_DestroySubjectPublicKeyInfo(dc->spki);
  114|      0|    SECITEM_FreeItem(&dc->derSpki, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&dc->derSpki, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  115|      0|    SECITEM_FreeItem(&dc->signature, PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(&dc->signature, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  116|      0|    PORT_ZFree(dc, sizeof(sslDelegatedCredential));
  ------------------
  |  |   75|      0|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  117|      0|}
tls13_IsSigningWithDelegatedCredential:
  165|  1.22k|{
  166|  1.22k|    if (!ss->sec.isServer ||
  ------------------
  |  Branch (166:9): [True: 0, False: 1.22k]
  ------------------
  167|  1.22k|        !ss->xtnData.sendingDelegCredToPeer ||
  ------------------
  |  Branch (167:9): [True: 1.22k, False: 0]
  ------------------
  168|  1.22k|        !ss->xtnData.peerRequestedDelegCred) {
  ------------------
  |  Branch (168:9): [True: 0, False: 0]
  ------------------
  169|  1.22k|        return PR_FALSE;
  ------------------
  |  |  438|  1.22k|#define PR_FALSE 0
  ------------------
  170|  1.22k|    }
  171|       |
  172|      0|    return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  173|  1.22k|}
tls13_MaybeSetDelegatedCredential:
  187|  1.24k|{
  188|  1.24k|    SECStatus rv;
  189|  1.24k|    PRBool doesRsaPss;
  190|  1.24k|    SECKEYPrivateKey *priv;
  191|  1.24k|    SSLSignatureScheme scheme;
  192|       |
  193|       |    /* Assert that the host is the server (we do not currently support
  194|       |     * client-delegated credentials), the certificate has been
  195|       |     * chosen, TLS 1.3 or higher has been negotiated, and that the set of
  196|       |     * signature schemes supported by the client is known.
  197|       |     */
  198|  1.24k|    PORT_Assert(ss->sec.isServer);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  199|  1.24k|    PORT_Assert(ss->sec.serverCert);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  200|  1.24k|    PORT_Assert(ss->version >= SSL_LIBRARY_VERSION_TLS_1_3);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  201|  1.24k|    PORT_Assert(ss->xtnData.peerRequestedDelegCred == !!ss->xtnData.delegCredSigSchemes);
  ------------------
  |  |  120|  1.24k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  202|       |
  203|       |    /* Check that the peer has indicated support and that a DC has been
  204|       |     * configured for the selected certificate.
  205|       |     */
  206|  1.24k|    if (!ss->xtnData.peerRequestedDelegCred ||
  ------------------
  |  Branch (206:9): [True: 1.24k, False: 2]
  ------------------
  207|  1.24k|        !ss->xtnData.delegCredSigSchemes ||
  ------------------
  |  Branch (207:9): [True: 0, False: 2]
  ------------------
  208|  1.24k|        !ss->sec.serverCert->delegCred.len ||
  ------------------
  |  Branch (208:9): [True: 2, False: 0]
  ------------------
  209|  1.24k|        !ss->sec.serverCert->delegCredKeyPair) {
  ------------------
  |  Branch (209:9): [True: 0, False: 0]
  ------------------
  210|  1.24k|        return SECSuccess;
  211|  1.24k|    }
  212|       |
  213|       |    /* Check that the host and peer both support the signing algorithm used with
  214|       |     * the DC.
  215|       |     */
  216|      0|    rv = tls13_GetExpectedCertVerifyAlg(ss->sec.serverCert->delegCred,
  217|      0|                                        &scheme);
  218|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (218:9): [True: 0, False: 0]
  ------------------
  219|      0|        return SECFailure;
  220|      0|    }
  221|       |
  222|      0|    priv = ss->sec.serverCert->delegCredKeyPair->privKey;
  223|      0|    rv = ssl_PrivateKeySupportsRsaPss(priv, NULL, NULL, &doesRsaPss);
  224|      0|    if (rv != SECSuccess) {
  ------------------
  |  Branch (224:9): [True: 0, False: 0]
  ------------------
  225|      0|        return SECFailure;
  226|      0|    }
  227|       |
  228|      0|    if (!ssl_SignatureSchemeEnabled(ss, scheme) ||
  ------------------
  |  Branch (228:9): [True: 0, False: 0]
  ------------------
  229|      0|        !ssl_CanUseSignatureScheme(scheme,
  ------------------
  |  Branch (229:9): [True: 0, False: 0]
  ------------------
  230|      0|                                   ss->xtnData.delegCredSigSchemes,
  231|      0|                                   ss->xtnData.numDelegCredSigSchemes,
  232|      0|                                   PR_FALSE /* requireSha1 */,
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  233|      0|                                   doesRsaPss)) {
  234|      0|        return SECSuccess;
  235|      0|    }
  236|       |
  237|       |    /* Commit to sending a DC and set the handshake signature scheme to the
  238|       |     * indicated algorithm.
  239|       |     */
  240|      0|    ss->xtnData.sendingDelegCredToPeer = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  241|      0|    ss->ssl3.hs.signatureScheme = scheme;
  242|      0|    return SECSuccess;
  243|      0|}

DER_Encode_Util:
  434|  27.4k|{
  435|  27.4k|    unsigned int contents_len, header_len;
  436|       |
  437|  27.4k|    src = (void **)((char *)src + dtemplate->offset);
  438|       |
  439|       |    /*
  440|       |     * First figure out how long the encoding will be. Do this by
  441|       |     * traversing the template from top to bottom and accumulating
  442|       |     * the length of each leaf item.
  443|       |     */
  444|  27.4k|    contents_len = contents_length(dtemplate, src);
  445|  27.4k|    header_len = header_length(dtemplate, contents_len);
  446|       |
  447|  27.4k|    dest->len = contents_len + header_len;
  448|       |
  449|       |    /* Allocate storage to hold the encoding */
  450|  27.4k|    dest->data = (unsigned char *)PORT_ArenaAlloc(arena, dest->len);
  ------------------
  |  |   53|  27.4k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  451|  27.4k|    if (dest->data == NULL) {
  ------------------
  |  Branch (451:9): [True: 0, False: 27.4k]
  ------------------
  452|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  453|      0|        return SECFailure;
  454|      0|    }
  455|       |
  456|       |    /* Now encode into the buffer */
  457|  27.4k|    (void)der_encode(dest->data, dtemplate, src);
  458|       |
  459|  27.4k|    return SECSuccess;
  460|  27.4k|}
derenc.c:contents_length:
  155|   439k|{
  156|   439k|    PRUint32 len;
  157|   439k|    unsigned long encode_kind, under_kind;
  158|   439k|    PRBool universal;
  159|       |
  160|   439k|    PORT_Assert(src != NULL);
  ------------------
  |  |  120|   439k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   439k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 439k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  161|       |
  162|   439k|    encode_kind = dtemplate->kind;
  163|       |
  164|   439k|    universal = ((encode_kind & DER_CLASS_MASK) == DER_UNIVERSAL)
  ------------------
  |  |   98|   439k|#define DER_CLASS_MASK 0xc0
  ------------------
                  universal = ((encode_kind & DER_CLASS_MASK) == DER_UNIVERSAL)
  ------------------
  |  |   99|   439k|#define DER_UNIVERSAL 0x00
  ------------------
  |  Branch (164:17): [True: 439k, False: 0]
  ------------------
  165|   439k|                    ? PR_TRUE
  ------------------
  |  |  437|   439k|#define PR_TRUE 1
  ------------------
  166|   439k|                    : PR_FALSE;
  ------------------
  |  |  438|   439k|#define PR_FALSE 0
  ------------------
  167|   439k|    encode_kind &= ~DER_OPTIONAL;
  ------------------
  |  |  109|   439k|#define DER_OPTIONAL 0x00100
  ------------------
  168|       |
  169|   439k|    if (encode_kind & DER_POINTER) {
  ------------------
  |  |  113|   439k|#define DER_POINTER 0x01000
  ------------------
  |  Branch (169:9): [True: 0, False: 439k]
  ------------------
  170|      0|        src = *(void **)src;
  171|      0|        if (src == NULL) {
  ------------------
  |  Branch (171:13): [True: 0, False: 0]
  ------------------
  172|      0|            return 0;
  173|      0|        }
  174|      0|        if (dtemplate->sub != NULL) {
  ------------------
  |  Branch (174:13): [True: 0, False: 0]
  ------------------
  175|      0|            dtemplate = dtemplate->sub;
  176|      0|            under_kind = dtemplate->kind;
  177|      0|            src = (void *)((char *)src + dtemplate->offset);
  178|      0|        } else if (universal) {
  ------------------
  |  Branch (178:20): [True: 0, False: 0]
  ------------------
  179|      0|            under_kind = encode_kind & ~DER_POINTER;
  ------------------
  |  |  113|      0|#define DER_POINTER 0x01000
  ------------------
  180|      0|        } else {
  181|      0|            under_kind = dtemplate->arg;
  182|      0|        }
  183|   439k|    } else if (encode_kind & DER_INLINE) {
  ------------------
  |  |  112|   439k|#define DER_INLINE 0x00800
  ------------------
  |  Branch (183:16): [True: 82.4k, False: 357k]
  ------------------
  184|  82.4k|        PORT_Assert(dtemplate->sub != NULL);
  ------------------
  |  |  120|  82.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  82.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 82.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  185|  82.4k|        dtemplate = dtemplate->sub;
  186|  82.4k|        under_kind = dtemplate->kind;
  187|  82.4k|        src = (void *)((char *)src + dtemplate->offset);
  188|   357k|    } else if (universal) {
  ------------------
  |  Branch (188:16): [True: 357k, False: 0]
  ------------------
  189|   357k|        under_kind = encode_kind;
  190|   357k|    } else {
  191|      0|        under_kind = dtemplate->arg;
  192|      0|    }
  193|       |
  194|       |    /* Having any of these bits is not expected here...  */
  195|   439k|    PORT_Assert((under_kind & (DER_EXPLICIT | DER_INLINE | DER_OPTIONAL | DER_POINTER | DER_SKIP)) == 0);
  ------------------
  |  |  120|   439k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   439k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 439k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  196|       |
  197|       |    /* This is only used in decoding; it plays no part in encoding.  */
  198|   439k|    if (under_kind & DER_DERPTR)
  ------------------
  |  |  115|   439k|#define DER_DERPTR 0x04000
  ------------------
  |  Branch (198:9): [True: 0, False: 439k]
  ------------------
  199|      0|        return 0;
  200|       |
  201|   439k|    if (under_kind & DER_INDEFINITE) {
  ------------------
  |  |  114|   439k|#define DER_INDEFINITE 0x02000
  ------------------
  |  Branch (201:9): [True: 0, False: 439k]
  ------------------
  202|      0|        PRUint32 sub_len;
  203|      0|        void **indp = *(void ***)src;
  204|       |
  205|      0|        if (indp == NULL)
  ------------------
  |  Branch (205:13): [True: 0, False: 0]
  ------------------
  206|      0|            return 0;
  207|       |
  208|      0|        len = 0;
  209|      0|        under_kind &= ~DER_INDEFINITE;
  ------------------
  |  |  114|      0|#define DER_INDEFINITE 0x02000
  ------------------
  210|       |
  211|      0|        if (under_kind == DER_SET || under_kind == DER_SEQUENCE) {
  ------------------
  |  |   81|      0|#define DER_SET 0x11
  ------------------
                      if (under_kind == DER_SET || under_kind == DER_SEQUENCE) {
  ------------------
  |  |   80|      0|#define DER_SEQUENCE 0x10
  ------------------
  |  Branch (211:13): [True: 0, False: 0]
  |  Branch (211:38): [True: 0, False: 0]
  ------------------
  212|      0|            DERTemplate *tmpt = dtemplate->sub;
  213|      0|            PORT_Assert(tmpt != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  214|       |
  215|      0|            for (; *indp != NULL; indp++) {
  ------------------
  |  Branch (215:20): [True: 0, False: 0]
  ------------------
  216|      0|                void *sub_src = (void *)((char *)(*indp) + tmpt->offset);
  217|      0|                sub_len = contents_length(tmpt, sub_src);
  218|      0|                len += sub_len + header_length(tmpt, sub_len);
  219|      0|            }
  220|      0|        } else {
  221|       |            /*
  222|       |             * XXX Lisa is not sure this code (for handling, for example,
  223|       |             * DER_INDEFINITE | DER_OCTET_STRING) is right.
  224|       |             */
  225|      0|            for (; *indp != NULL; indp++) {
  ------------------
  |  Branch (225:20): [True: 0, False: 0]
  ------------------
  226|      0|                SECItem *item = (SECItem *)(*indp);
  227|      0|                sub_len = item->len;
  228|      0|                if (under_kind == DER_BIT_STRING) {
  ------------------
  |  |   76|      0|#define DER_BIT_STRING 0x03
  ------------------
  |  Branch (228:21): [True: 0, False: 0]
  ------------------
  229|      0|                    sub_len = (sub_len + 7) >> 3;
  230|       |                    /* bit string contents involve an extra octet */
  231|      0|                    if (sub_len)
  ------------------
  |  Branch (231:25): [True: 0, False: 0]
  ------------------
  232|      0|                        sub_len++;
  233|      0|                }
  234|      0|                if (under_kind != DER_ANY)
  ------------------
  |  |  111|      0|#define DER_ANY 0x00400
  ------------------
  |  Branch (234:21): [True: 0, False: 0]
  ------------------
  235|      0|                    len += 1 + DER_LengthLength(sub_len);
  236|      0|            }
  237|      0|        }
  238|       |
  239|      0|        return len;
  240|      0|    }
  241|       |
  242|   439k|    switch (under_kind) {
  243|   137k|        case DER_SEQUENCE:
  ------------------
  |  |   80|   137k|#define DER_SEQUENCE 0x10
  ------------------
  |  Branch (243:9): [True: 137k, False: 302k]
  ------------------
  244|   137k|        case DER_SET: {
  ------------------
  |  |   81|   137k|#define DER_SET 0x11
  ------------------
  |  Branch (244:9): [True: 0, False: 439k]
  ------------------
  245|   137k|            DERTemplate *tmpt;
  246|   137k|            void *sub_src;
  247|   137k|            PRUint32 sub_len;
  248|       |
  249|   137k|            len = 0;
  250|   412k|            for (tmpt = dtemplate + 1; tmpt->kind; tmpt++) {
  ------------------
  |  Branch (250:40): [True: 274k, False: 137k]
  ------------------
  251|   274k|                sub_src = (void *)((char *)src + tmpt->offset);
  252|   274k|                sub_len = contents_length(tmpt, sub_src);
  253|   274k|                len += sub_len + header_length(tmpt, sub_len);
  254|   274k|            }
  255|   137k|        } break;
  256|       |
  257|      0|        case DER_BIT_STRING:
  ------------------
  |  |   76|      0|#define DER_BIT_STRING 0x03
  ------------------
  |  Branch (257:9): [True: 0, False: 439k]
  ------------------
  258|      0|            len = (((SECItem *)src)->len + 7) >> 3;
  259|       |            /* bit string contents involve an extra octet */
  260|      0|            if (len)
  ------------------
  |  Branch (260:17): [True: 0, False: 0]
  ------------------
  261|      0|                len++;
  262|      0|            break;
  263|       |
  264|   302k|        default:
  ------------------
  |  Branch (264:9): [True: 302k, False: 137k]
  ------------------
  265|   302k|            len = ((SECItem *)src)->len;
  266|   302k|            break;
  267|   439k|    }
  268|       |
  269|   439k|    return len;
  270|   439k|}
derenc.c:header_length:
   72|   439k|{
   73|   439k|    PRUint32 len;
   74|   439k|    unsigned long encode_kind, under_kind;
   75|   439k|    PRBool explicit, optional, universal;
   76|       |
   77|   439k|    encode_kind = dtemplate->kind;
   78|       |
   79|   439k|    explicit = (encode_kind & DER_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  110|   439k|#define DER_EXPLICIT 0x00200
  ------------------
                  explicit = (encode_kind & DER_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  explicit = (encode_kind & DER_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   879k|#define PR_FALSE 0
  ------------------
  |  Branch (79:16): [True: 0, False: 439k]
  ------------------
   80|   439k|    optional = (encode_kind & DER_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  109|   439k|#define DER_OPTIONAL 0x00100
  ------------------
                  optional = (encode_kind & DER_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|   109k|#define PR_TRUE 1
  ------------------
                  optional = (encode_kind & DER_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   769k|#define PR_FALSE 0
  ------------------
  |  Branch (80:16): [True: 109k, False: 329k]
  ------------------
   81|   439k|    universal = ((encode_kind & DER_CLASS_MASK) == DER_UNIVERSAL)
  ------------------
  |  |   98|   439k|#define DER_CLASS_MASK 0xc0
  ------------------
                  universal = ((encode_kind & DER_CLASS_MASK) == DER_UNIVERSAL)
  ------------------
  |  |   99|   439k|#define DER_UNIVERSAL 0x00
  ------------------
  |  Branch (81:17): [True: 439k, False: 0]
  ------------------
   82|   439k|                    ? PR_TRUE
  ------------------
  |  |  437|   439k|#define PR_TRUE 1
  ------------------
   83|   439k|                    : PR_FALSE;
  ------------------
  |  |  438|   439k|#define PR_FALSE 0
  ------------------
   84|       |
   85|   439k|    PORT_Assert(!(explicit && universal)); /* bad templates */
  ------------------
  |  |  120|   439k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   439k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 439k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   86|       |
   87|   439k|    if (encode_kind & DER_POINTER) {
  ------------------
  |  |  113|   439k|#define DER_POINTER 0x01000
  ------------------
  |  Branch (87:9): [True: 0, False: 439k]
  ------------------
   88|      0|        if (dtemplate->sub != NULL) {
  ------------------
  |  Branch (88:13): [True: 0, False: 0]
  ------------------
   89|      0|            under_kind = dtemplate->sub->kind;
   90|      0|            if (universal) {
  ------------------
  |  Branch (90:17): [True: 0, False: 0]
  ------------------
   91|      0|                encode_kind = under_kind;
   92|      0|            }
   93|      0|        } else if (universal) {
  ------------------
  |  Branch (93:20): [True: 0, False: 0]
  ------------------
   94|      0|            under_kind = encode_kind & ~DER_POINTER;
  ------------------
  |  |  113|      0|#define DER_POINTER 0x01000
  ------------------
   95|      0|        } else {
   96|      0|            under_kind = dtemplate->arg;
   97|      0|        }
   98|   439k|    } else if (encode_kind & DER_INLINE) {
  ------------------
  |  |  112|   439k|#define DER_INLINE 0x00800
  ------------------
  |  Branch (98:16): [True: 82.4k, False: 357k]
  ------------------
   99|  82.4k|        PORT_Assert(dtemplate->sub != NULL);
  ------------------
  |  |  120|  82.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  82.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 82.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  100|  82.4k|        under_kind = dtemplate->sub->kind;
  101|  82.4k|        if (universal) {
  ------------------
  |  Branch (101:13): [True: 82.4k, False: 0]
  ------------------
  102|  82.4k|            encode_kind = under_kind;
  103|  82.4k|        }
  104|   357k|    } else if (universal) {
  ------------------
  |  Branch (104:16): [True: 357k, False: 0]
  ------------------
  105|   357k|        under_kind = encode_kind;
  106|   357k|    } else {
  107|      0|        under_kind = dtemplate->arg;
  108|      0|    }
  109|       |
  110|       |    /* This is only used in decoding; it plays no part in encoding.  */
  111|   439k|    if (under_kind & DER_DERPTR)
  ------------------
  |  |  115|   439k|#define DER_DERPTR 0x04000
  ------------------
  |  Branch (111:9): [True: 0, False: 439k]
  ------------------
  112|      0|        return 0;
  113|       |
  114|       |    /* No header at all for an "empty" optional.  */
  115|   439k|    if ((contents_len == 0) && optional)
  ------------------
  |  Branch (115:9): [True: 0, False: 439k]
  |  Branch (115:32): [True: 0, False: 0]
  ------------------
  116|      0|        return 0;
  117|       |
  118|       |    /* And no header for a full DER_ANY.  */
  119|   439k|    if (encode_kind & DER_ANY)
  ------------------
  |  |  111|   439k|#define DER_ANY 0x00400
  ------------------
  |  Branch (119:9): [True: 109k, False: 329k]
  ------------------
  120|   109k|        return 0;
  121|       |
  122|       |    /*
  123|       |     * The common case: one octet for identifier and as many octets
  124|       |     * as necessary to hold the content length.
  125|       |     */
  126|   329k|    len = 1 + DER_LengthLength(contents_len);
  127|       |
  128|       |    /* Account for the explicit wrapper, if necessary.  */
  129|   329k|    if (explicit) {
  ------------------
  |  Branch (129:9): [True: 0, False: 329k]
  ------------------
  130|       |#if 0 /*                                                         \
  131|       |       * Well, I was trying to do something useful, but these    \
  132|       |       * assertions are too restrictive on valid templates.      \
  133|       |       * I wanted to make sure that the top-level "kind" of      \
  134|       |       * a template does not also specify DER_EXPLICIT, which    \
  135|       |       * should only modify a component field.  Maybe later      \
  136|       |       * I can figure out a better way to detect such a problem, \
  137|       |       * but for now I must remove these checks altogether.      \
  138|       |       */
  139|       |	/*
  140|       |	 * This modifier applies only to components of a set or sequence;
  141|       |	 * it should never be used on a set/sequence itself -- confirm.
  142|       |	 */
  143|       |	PORT_Assert (under_kind != DER_SEQUENCE);
  144|       |	PORT_Assert (under_kind != DER_SET);
  145|       |#endif
  146|       |
  147|      0|        len += 1 + DER_LengthLength(len + contents_len);
  148|      0|    }
  149|       |
  150|   329k|    return len;
  151|   439k|}
derenc.c:der_encode:
  274|   137k|{
  275|   137k|    int header_len;
  276|   137k|    PRUint32 contents_len;
  277|   137k|    unsigned long encode_kind, under_kind;
  278|   137k|    PRBool explicit, universal;
  279|       |
  280|       |    /*
  281|       |     * First figure out how long the encoding will be.  Do this by
  282|       |     * traversing the template from top to bottom and accumulating
  283|       |     * the length of each leaf item.
  284|       |     */
  285|   137k|    contents_len = contents_length(dtemplate, src);
  286|   137k|    header_len = header_length(dtemplate, contents_len);
  287|       |
  288|       |    /*
  289|       |     * Enough smarts was involved already, so that if both the
  290|       |     * header and the contents have a length of zero, then we
  291|       |     * are not doing any encoding for this element.
  292|       |     */
  293|   137k|    if (header_len == 0 && contents_len == 0)
  ------------------
  |  Branch (293:9): [True: 27.4k, False: 109k]
  |  Branch (293:28): [True: 0, False: 27.4k]
  ------------------
  294|      0|        return buf;
  295|       |
  296|   137k|    encode_kind = dtemplate->kind;
  297|       |
  298|   137k|    explicit = (encode_kind & DER_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  110|   137k|#define DER_EXPLICIT 0x00200
  ------------------
                  explicit = (encode_kind & DER_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  explicit = (encode_kind & DER_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   274k|#define PR_FALSE 0
  ------------------
  |  Branch (298:16): [True: 0, False: 137k]
  ------------------
  299|   137k|    encode_kind &= ~DER_OPTIONAL;
  ------------------
  |  |  109|   137k|#define DER_OPTIONAL 0x00100
  ------------------
  300|   137k|    universal = ((encode_kind & DER_CLASS_MASK) == DER_UNIVERSAL)
  ------------------
  |  |   98|   137k|#define DER_CLASS_MASK 0xc0
  ------------------
                  universal = ((encode_kind & DER_CLASS_MASK) == DER_UNIVERSAL)
  ------------------
  |  |   99|   137k|#define DER_UNIVERSAL 0x00
  ------------------
  |  Branch (300:17): [True: 137k, False: 0]
  ------------------
  301|   137k|                    ? PR_TRUE
  ------------------
  |  |  437|   137k|#define PR_TRUE 1
  ------------------
  302|   137k|                    : PR_FALSE;
  ------------------
  |  |  438|   137k|#define PR_FALSE 0
  ------------------
  303|       |
  304|   137k|    if (encode_kind & DER_POINTER) {
  ------------------
  |  |  113|   137k|#define DER_POINTER 0x01000
  ------------------
  |  Branch (304:9): [True: 0, False: 137k]
  ------------------
  305|      0|        if (contents_len) {
  ------------------
  |  Branch (305:13): [True: 0, False: 0]
  ------------------
  306|      0|            src = *(void **)src;
  307|      0|            PORT_Assert(src != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  308|      0|        }
  309|      0|        if (dtemplate->sub != NULL) {
  ------------------
  |  Branch (309:13): [True: 0, False: 0]
  ------------------
  310|      0|            dtemplate = dtemplate->sub;
  311|      0|            under_kind = dtemplate->kind;
  312|      0|            if (universal) {
  ------------------
  |  Branch (312:17): [True: 0, False: 0]
  ------------------
  313|      0|                encode_kind = under_kind;
  314|      0|            }
  315|      0|            src = (void *)((char *)src + dtemplate->offset);
  316|      0|        } else if (universal) {
  ------------------
  |  Branch (316:20): [True: 0, False: 0]
  ------------------
  317|      0|            under_kind = encode_kind & ~DER_POINTER;
  ------------------
  |  |  113|      0|#define DER_POINTER 0x01000
  ------------------
  318|      0|        } else {
  319|      0|            under_kind = dtemplate->arg;
  320|      0|        }
  321|   137k|    } else if (encode_kind & DER_INLINE) {
  ------------------
  |  |  112|   137k|#define DER_INLINE 0x00800
  ------------------
  |  Branch (321:16): [True: 27.4k, False: 109k]
  ------------------
  322|  27.4k|        dtemplate = dtemplate->sub;
  323|  27.4k|        under_kind = dtemplate->kind;
  324|  27.4k|        if (universal) {
  ------------------
  |  Branch (324:13): [True: 27.4k, False: 0]
  ------------------
  325|  27.4k|            encode_kind = under_kind;
  326|  27.4k|        }
  327|  27.4k|        src = (void *)((char *)src + dtemplate->offset);
  328|   109k|    } else if (universal) {
  ------------------
  |  Branch (328:16): [True: 109k, False: 0]
  ------------------
  329|   109k|        under_kind = encode_kind;
  330|   109k|    } else {
  331|      0|        under_kind = dtemplate->arg;
  332|      0|    }
  333|       |
  334|   137k|    if (explicit) {
  ------------------
  |  Branch (334:9): [True: 0, False: 137k]
  ------------------
  335|      0|        buf = DER_StoreHeader(buf, encode_kind,
  336|      0|                              (1 + DER_LengthLength(contents_len) + contents_len));
  337|      0|        encode_kind = under_kind;
  338|      0|    }
  339|       |
  340|   137k|    if ((encode_kind & DER_ANY) == 0) { /* DER_ANY already contains header */
  ------------------
  |  |  111|   137k|#define DER_ANY 0x00400
  ------------------
  |  Branch (340:9): [True: 109k, False: 27.4k]
  ------------------
  341|   109k|        buf = DER_StoreHeader(buf, encode_kind, contents_len);
  342|   109k|    }
  343|       |
  344|       |    /* If no real contents to encode, then we are done.  */
  345|   137k|    if (contents_len == 0)
  ------------------
  |  Branch (345:9): [True: 0, False: 137k]
  ------------------
  346|      0|        return buf;
  347|       |
  348|   137k|    if (under_kind & DER_INDEFINITE) {
  ------------------
  |  |  114|   137k|#define DER_INDEFINITE 0x02000
  ------------------
  |  Branch (348:9): [True: 0, False: 137k]
  ------------------
  349|      0|        void **indp;
  350|       |
  351|      0|        indp = *(void ***)src;
  352|      0|        PORT_Assert(indp != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  353|       |
  354|      0|        under_kind &= ~DER_INDEFINITE;
  ------------------
  |  |  114|      0|#define DER_INDEFINITE 0x02000
  ------------------
  355|      0|        if (under_kind == DER_SET || under_kind == DER_SEQUENCE) {
  ------------------
  |  |   81|      0|#define DER_SET 0x11
  ------------------
                      if (under_kind == DER_SET || under_kind == DER_SEQUENCE) {
  ------------------
  |  |   80|      0|#define DER_SEQUENCE 0x10
  ------------------
  |  Branch (355:13): [True: 0, False: 0]
  |  Branch (355:38): [True: 0, False: 0]
  ------------------
  356|      0|            DERTemplate *tmpt = dtemplate->sub;
  357|      0|            PORT_Assert(tmpt != NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  358|      0|            for (; *indp != NULL; indp++) {
  ------------------
  |  Branch (358:20): [True: 0, False: 0]
  ------------------
  359|      0|                void *sub_src = (void *)((char *)(*indp) + tmpt->offset);
  360|      0|                buf = der_encode(buf, tmpt, sub_src);
  361|      0|            }
  362|      0|        } else {
  363|      0|            for (; *indp != NULL; indp++) {
  ------------------
  |  Branch (363:20): [True: 0, False: 0]
  ------------------
  364|      0|                SECItem *item;
  365|      0|                int sub_len;
  366|       |
  367|      0|                item = (SECItem *)(*indp);
  368|      0|                sub_len = item->len;
  369|      0|                if (under_kind == DER_BIT_STRING) {
  ------------------
  |  |   76|      0|#define DER_BIT_STRING 0x03
  ------------------
  |  Branch (369:21): [True: 0, False: 0]
  ------------------
  370|      0|                    if (sub_len) {
  ------------------
  |  Branch (370:25): [True: 0, False: 0]
  ------------------
  371|      0|                        int rem;
  372|       |
  373|      0|                        sub_len = (sub_len + 7) >> 3;
  374|      0|                        buf = DER_StoreHeader(buf, under_kind, sub_len + 1);
  375|      0|                        rem = (sub_len << 3) - item->len;
  376|      0|                        *buf++ = rem; /* remaining bits */
  377|      0|                    } else {
  378|      0|                        buf = DER_StoreHeader(buf, under_kind, 0);
  379|      0|                    }
  380|      0|                } else if (under_kind != DER_ANY) {
  ------------------
  |  |  111|      0|#define DER_ANY 0x00400
  ------------------
  |  Branch (380:28): [True: 0, False: 0]
  ------------------
  381|      0|                    buf = DER_StoreHeader(buf, under_kind, sub_len);
  382|      0|                }
  383|      0|                PORT_Memcpy(buf, item->data, sub_len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  384|      0|                buf += sub_len;
  385|      0|            }
  386|      0|        }
  387|      0|        return buf;
  388|      0|    }
  389|       |
  390|   137k|    switch (under_kind) {
  391|  54.9k|        case DER_SEQUENCE:
  ------------------
  |  |   80|  54.9k|#define DER_SEQUENCE 0x10
  ------------------
  |  Branch (391:9): [True: 54.9k, False: 82.4k]
  ------------------
  392|  54.9k|        case DER_SET: {
  ------------------
  |  |   81|  54.9k|#define DER_SET 0x11
  ------------------
  |  Branch (392:9): [True: 0, False: 137k]
  ------------------
  393|  54.9k|            DERTemplate *tmpt;
  394|  54.9k|            void *sub_src;
  395|       |
  396|   164k|            for (tmpt = dtemplate + 1; tmpt->kind; tmpt++) {
  ------------------
  |  Branch (396:40): [True: 109k, False: 54.9k]
  ------------------
  397|   109k|                sub_src = (void *)((char *)src + tmpt->offset);
  398|   109k|                buf = der_encode(buf, tmpt, sub_src);
  399|   109k|            }
  400|  54.9k|        } break;
  401|       |
  402|      0|        case DER_BIT_STRING: {
  ------------------
  |  |   76|      0|#define DER_BIT_STRING 0x03
  ------------------
  |  Branch (402:9): [True: 0, False: 137k]
  ------------------
  403|      0|            SECItem *item;
  404|      0|            int rem;
  405|       |
  406|       |            /*
  407|       |             * The contents length includes our extra octet; subtract
  408|       |             * it off so we just have the real string length there.
  409|       |             */
  410|      0|            contents_len--;
  411|      0|            item = (SECItem *)src;
  412|      0|            PORT_Assert(contents_len == ((item->len + 7) >> 3));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  413|      0|            rem = (contents_len << 3) - item->len;
  414|      0|            *buf++ = rem; /* remaining bits */
  415|      0|            PORT_Memcpy(buf, item->data, contents_len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
  416|      0|            buf += contents_len;
  417|      0|        } break;
  418|       |
  419|  82.4k|        default: {
  ------------------
  |  Branch (419:9): [True: 82.4k, False: 54.9k]
  ------------------
  420|  82.4k|            SECItem *item;
  421|       |
  422|  82.4k|            item = (SECItem *)src;
  423|  82.4k|            PORT_Assert(contents_len == item->len);
  ------------------
  |  |  120|  82.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  82.4k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 82.4k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  424|  82.4k|            PORT_Memcpy(buf, item->data, contents_len);
  ------------------
  |  |  180|  82.4k|#define PORT_Memcpy memcpy
  ------------------
  425|  82.4k|            buf += contents_len;
  426|  82.4k|        } break;
  427|   137k|    }
  428|       |
  429|   137k|    return buf;
  430|   137k|}

DER_LengthLength:
   11|   329k|{
   12|   329k|    if (len > 127) {
  ------------------
  |  Branch (12:9): [True: 0, False: 329k]
  ------------------
   13|      0|        if (len > 255) {
  ------------------
  |  Branch (13:13): [True: 0, False: 0]
  ------------------
   14|      0|            if (len > 65535L) {
  ------------------
  |  Branch (14:17): [True: 0, False: 0]
  ------------------
   15|      0|                if (len > 16777215L) {
  ------------------
  |  Branch (15:21): [True: 0, False: 0]
  ------------------
   16|      0|                    return 5;
   17|      0|                } else {
   18|      0|                    return 4;
   19|      0|                }
   20|      0|            } else {
   21|      0|                return 3;
   22|      0|            }
   23|      0|        } else {
   24|      0|            return 2;
   25|      0|        }
   26|   329k|    } else {
   27|   329k|        return 1;
   28|   329k|    }
   29|   329k|}
DER_StoreHeader:
   33|   109k|{
   34|   109k|    unsigned char b[4];
   35|       |
   36|   109k|    b[0] = (unsigned char)(len >> 24);
   37|   109k|    b[1] = (unsigned char)(len >> 16);
   38|   109k|    b[2] = (unsigned char)(len >> 8);
   39|   109k|    b[3] = (unsigned char)len;
   40|   109k|    if ((code & DER_TAGNUM_MASK) == DER_SET || (code & DER_TAGNUM_MASK) == DER_SEQUENCE)
  ------------------
  |  |   73|   109k|#define DER_TAGNUM_MASK 0x1f
  ------------------
                  if ((code & DER_TAGNUM_MASK) == DER_SET || (code & DER_TAGNUM_MASK) == DER_SEQUENCE)
  ------------------
  |  |   81|   219k|#define DER_SET 0x11
  ------------------
                  if ((code & DER_TAGNUM_MASK) == DER_SET || (code & DER_TAGNUM_MASK) == DER_SEQUENCE)
  ------------------
  |  |   73|   109k|#define DER_TAGNUM_MASK 0x1f
  ------------------
                  if ((code & DER_TAGNUM_MASK) == DER_SET || (code & DER_TAGNUM_MASK) == DER_SEQUENCE)
  ------------------
  |  |   80|   109k|#define DER_SEQUENCE 0x10
  ------------------
  |  Branch (40:9): [True: 0, False: 109k]
  |  Branch (40:48): [True: 54.9k, False: 54.9k]
  ------------------
   41|  54.9k|        code |= DER_CONSTRUCTED;
  ------------------
  |  |   96|  54.9k|#define DER_CONSTRUCTED 0x20
  ------------------
   42|   109k|    *buf++ = code;
   43|   109k|    if (len > 127) {
  ------------------
  |  Branch (43:9): [True: 0, False: 109k]
  ------------------
   44|      0|        if (len > 255) {
  ------------------
  |  Branch (44:13): [True: 0, False: 0]
  ------------------
   45|      0|            if (len > 65535) {
  ------------------
  |  Branch (45:17): [True: 0, False: 0]
  ------------------
   46|      0|                if (len > 16777215) {
  ------------------
  |  Branch (46:21): [True: 0, False: 0]
  ------------------
   47|      0|                    *buf++ = 0x84;
   48|      0|                    *buf++ = b[0];
   49|      0|                    *buf++ = b[1];
   50|      0|                    *buf++ = b[2];
   51|      0|                    *buf++ = b[3];
   52|      0|                } else {
   53|      0|                    *buf++ = 0x83;
   54|      0|                    *buf++ = b[1];
   55|      0|                    *buf++ = b[2];
   56|      0|                    *buf++ = b[3];
   57|      0|                }
   58|      0|            } else {
   59|      0|                *buf++ = 0x82;
   60|      0|                *buf++ = b[2];
   61|      0|                *buf++ = b[3];
   62|      0|            }
   63|      0|        } else {
   64|      0|            *buf++ = 0x81;
   65|      0|            *buf++ = b[3];
   66|      0|        }
   67|   109k|    } else {
   68|   109k|        *buf++ = b[3];
   69|   109k|    }
   70|   109k|    return buf;
   71|   109k|}
DER_SetUInteger:
  130|  18.2k|{
  131|  18.2k|    unsigned char bb[5];
  132|  18.2k|    int len;
  133|       |
  134|  18.2k|    bb[0] = 0;
  135|  18.2k|    bb[1] = (unsigned char)(ui >> 24);
  136|  18.2k|    bb[2] = (unsigned char)(ui >> 16);
  137|  18.2k|    bb[3] = (unsigned char)(ui >> 8);
  138|  18.2k|    bb[4] = (unsigned char)(ui);
  139|       |
  140|       |    /*
  141|       |    ** Small integers are encoded in a single byte. Larger integers
  142|       |    ** require progressively more space.
  143|       |    */
  144|  18.2k|    if (ui > 0x7f) {
  ------------------
  |  Branch (144:9): [True: 0, False: 18.2k]
  ------------------
  145|      0|        if (ui > 0x7fff) {
  ------------------
  |  Branch (145:13): [True: 0, False: 0]
  ------------------
  146|      0|            if (ui > 0x7fffffL) {
  ------------------
  |  Branch (146:17): [True: 0, False: 0]
  ------------------
  147|      0|                if (ui >= 0x80000000L) {
  ------------------
  |  Branch (147:21): [True: 0, False: 0]
  ------------------
  148|      0|                    len = 5;
  149|      0|                } else {
  150|      0|                    len = 4;
  151|      0|                }
  152|      0|            } else {
  153|      0|                len = 3;
  154|      0|            }
  155|      0|        } else {
  156|      0|            len = 2;
  157|      0|        }
  158|  18.2k|    } else {
  159|  18.2k|        len = 1;
  160|  18.2k|    }
  161|       |
  162|  18.2k|    it->data = (unsigned char *)PORT_ArenaAlloc(arena, len);
  ------------------
  |  |   53|  18.2k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  163|  18.2k|    if (it->data == NULL) {
  ------------------
  |  Branch (163:9): [True: 0, False: 18.2k]
  ------------------
  164|      0|        return SECFailure;
  165|      0|    }
  166|       |
  167|  18.2k|    it->len = len;
  168|  18.2k|    PORT_Memcpy(it->data, bb + (sizeof(bb) - len), len);
  ------------------
  |  |  180|  18.2k|#define PORT_Memcpy memcpy
  ------------------
  169|       |
  170|  18.2k|    return SECSuccess;
  171|  18.2k|}
DER_GetInteger_Util:
  179|     97|{
  180|     97|    unsigned long ival;
  181|     97|    PRBool negative;
  182|     97|    unsigned int len = it->len;
  183|     97|    unsigned char *cp = it->data;
  184|     97|    size_t lsize = sizeof(ival);
  185|       |
  186|     97|    PORT_Assert(len);
  ------------------
  |  |  120|     97|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     97|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 97, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  187|     97|    if (!len) {
  ------------------
  |  Branch (187:9): [True: 0, False: 97]
  ------------------
  188|      0|        PORT_SetError(SEC_ERROR_INPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  189|      0|        return 0;
  190|      0|    }
  191|       |
  192|     97|    negative = (PRBool)(*cp & 0x80);
  193|     97|    ival = negative ? ~0 : 0;
  ------------------
  |  Branch (193:12): [True: 49, False: 48]
  ------------------
  194|       |
  195|       |    /* Ignore leading zeros/ones. */
  196|    354|    while (len && *cp == (unsigned char)ival) {
  ------------------
  |  Branch (196:12): [True: 335, False: 19]
  |  Branch (196:19): [True: 257, False: 78]
  ------------------
  197|    257|        len--;
  198|    257|        cp++;
  199|    257|    }
  200|       |
  201|       |    /* Check for overflow/underflow. */
  202|     97|    if (len > lsize || (len == lsize && (*cp & 0x80) != negative)) {
  ------------------
  |  Branch (202:9): [True: 1, False: 96]
  |  Branch (202:25): [True: 9, False: 87]
  |  Branch (202:41): [True: 1, False: 8]
  ------------------
  203|      2|        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  204|      2|        return negative ? LONG_MIN : LONG_MAX;
  ------------------
  |  Branch (204:16): [True: 1, False: 1]
  ------------------
  205|      2|    }
  206|       |
  207|    330|    while (len--) {
  ------------------
  |  Branch (207:12): [True: 235, False: 95]
  ------------------
  208|    235|        ival <<= 8;
  209|    235|        ival |= *cp++;
  210|    235|    }
  211|       |
  212|     95|    return ival;
  213|     97|}

DER_UTCTimeToTime_Util:
  106|    568|{
  107|       |    /* Minimum valid UTCTime is yymmddhhmmZ       which is 11 bytes.
  108|       |    ** Maximum valid UTCTime is yymmddhhmmss+0000 which is 17 bytes.
  109|       |    ** 20 should be large enough for all valid encoded times.
  110|       |    */
  111|    568|    unsigned int i;
  112|    568|    char localBuf[20];
  113|    568|    const char *end = NULL;
  114|    568|    SECStatus rv;
  115|       |
  116|    568|    if (!time || !time->data || time->len < 11 || time->len > 17) {
  ------------------
  |  Branch (116:9): [True: 0, False: 568]
  |  Branch (116:18): [True: 0, False: 568]
  |  Branch (116:33): [True: 1, False: 567]
  |  Branch (116:51): [True: 0, False: 567]
  ------------------
  117|      1|        PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  118|      1|        return SECFailure;
  119|      1|    }
  120|       |
  121|  7.87k|    for (i = 0; i < time->len; i++) {
  ------------------
  |  Branch (121:17): [True: 7.31k, False: 560]
  ------------------
  122|  7.31k|        if (time->data[i] == '\0') {
  ------------------
  |  Branch (122:13): [True: 7, False: 7.31k]
  ------------------
  123|      7|            PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|      7|#define PORT_SetError PORT_SetError_Util
  ------------------
  124|      7|            return SECFailure;
  125|      7|        }
  126|  7.31k|        localBuf[i] = time->data[i];
  127|  7.31k|    }
  128|    560|    localBuf[i] = '\0';
  129|       |
  130|    560|    rv = der_TimeStringToTime(dst, localBuf, UTC_STRING, &end);
  ------------------
  |  |   88|    560|#define UTC_STRING 0 /* TimeString is a UTCTime         */
  ------------------
  131|    560|    if (rv == SECSuccess && *end != '\0') {
  ------------------
  |  Branch (131:9): [True: 473, False: 87]
  |  Branch (131:29): [True: 2, False: 471]
  ------------------
  132|      2|        PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|      2|#define PORT_SetError PORT_SetError_Util
  ------------------
  133|      2|        return SECFailure;
  134|      2|    }
  135|    558|    return rv;
  136|    560|}
DER_GeneralizedTimeToTime_Util:
  199|     36|{
  200|       |    /* Minimum valid GeneralizedTime is ccyymmddhhmmZ       which is 13 bytes.
  201|       |    ** Maximum valid GeneralizedTime is ccyymmddhhmmss+0000 which is 19 bytes.
  202|       |    ** 20 should be large enough for all valid encoded times.
  203|       |    */
  204|     36|    unsigned int i;
  205|     36|    char localBuf[20];
  206|     36|    const char *end = NULL;
  207|     36|    SECStatus rv;
  208|       |
  209|     36|    if (!time || !time->data || time->len < 13 || time->len > 19) {
  ------------------
  |  Branch (209:9): [True: 0, False: 36]
  |  Branch (209:18): [True: 0, False: 36]
  |  Branch (209:33): [True: 1, False: 35]
  |  Branch (209:51): [True: 0, False: 35]
  ------------------
  210|      1|        PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  211|      1|        return SECFailure;
  212|      1|    }
  213|       |
  214|    434|    for (i = 0; i < time->len; i++) {
  ------------------
  |  Branch (214:17): [True: 405, False: 29]
  ------------------
  215|    405|        if (time->data[i] == '\0') {
  ------------------
  |  Branch (215:13): [True: 6, False: 399]
  ------------------
  216|      6|            PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|      6|#define PORT_SetError PORT_SetError_Util
  ------------------
  217|      6|            return SECFailure;
  218|      6|        }
  219|    399|        localBuf[i] = time->data[i];
  220|    399|    }
  221|     29|    localBuf[i] = '\0';
  222|       |
  223|     29|    rv = der_TimeStringToTime(dst, localBuf, GEN_STRING, &end);
  ------------------
  |  |   87|     29|#define GEN_STRING 2 /* TimeString is a GeneralizedTime */
  ------------------
  224|     29|    if (rv == SECSuccess && *end != '\0') {
  ------------------
  |  Branch (224:9): [True: 13, False: 16]
  |  Branch (224:29): [True: 0, False: 13]
  ------------------
  225|      0|        PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  226|      0|        return SECFailure;
  227|      0|    }
  228|     29|    return rv;
  229|     29|}
dertime.c:der_TimeStringToTime:
  234|    589|{
  235|    589|    PRExplodedTime genTime;
  236|    589|    long hourOff = 0, minOff = 0;
  237|    589|    PRUint16 century;
  238|    589|    char signum;
  239|       |
  240|    589|    if (string == NULL || dst == NULL) {
  ------------------
  |  Branch (240:9): [True: 0, False: 589]
  |  Branch (240:27): [True: 0, False: 589]
  ------------------
  241|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  242|      0|        return SECFailure;
  243|      0|    }
  244|       |
  245|       |    /* Verify time is formatted properly and capture information */
  246|    589|    memset(&genTime, 0, sizeof genTime);
  247|       |
  248|    589|    if (generalized == UTC_STRING) {
  ------------------
  |  |   88|    589|#define UTC_STRING 0 /* TimeString is a UTCTime         */
  ------------------
  |  Branch (248:9): [True: 560, False: 29]
  ------------------
  249|    560|        CAPTURE(genTime.tm_year, string, loser);
  ------------------
  |  |   16|    560|    {                                                 \
  |  |   17|    560|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|  1.12k|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 556, False: 4]
  |  |  |  |  |  Branch (14:41): [True: 555, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    555|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 551, False: 4]
  |  |  |  |  |  Branch (14:41): [True: 549, False: 2]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|    560|            goto label;                               \
  |  |   19|    560|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|    549|        p += 2;                                       \
  |  |   21|    549|    }
  ------------------
  250|    549|        century = (genTime.tm_year < 50) ? 20 : 19;
  ------------------
  |  Branch (250:19): [True: 434, False: 115]
  ------------------
  251|    549|    } else {
  252|     29|        CAPTURE(century, string, loser);
  ------------------
  |  |   16|     29|    {                                                 \
  |  |   17|     29|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|     58|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 27, False: 2]
  |  |  |  |  |  Branch (14:41): [True: 26, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|     26|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 25, False: 1]
  |  |  |  |  |  Branch (14:41): [True: 23, False: 2]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|     29|            goto label;                               \
  |  |   19|     29|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|     23|        p += 2;                                       \
  |  |   21|     23|    }
  ------------------
  253|     23|        CAPTURE(genTime.tm_year, string, loser);
  ------------------
  |  |   16|     23|    {                                                 \
  |  |   17|     23|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|     46|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 20, False: 3]
  |  |  |  |  |  Branch (14:41): [True: 19, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|     19|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 18, False: 1]
  |  |  |  |  |  Branch (14:41): [True: 17, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|     23|            goto label;                               \
  |  |   19|     23|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|     17|        p += 2;                                       \
  |  |   21|     17|    }
  ------------------
  254|     17|    }
  255|    566|    genTime.tm_year += century * 100;
  256|       |
  257|    566|    CAPTURE(genTime.tm_month, string, loser);
  ------------------
  |  |   16|    566|    {                                                 \
  |  |   17|    566|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|  1.13k|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 559, False: 7]
  |  |  |  |  |  Branch (14:41): [True: 557, False: 2]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    557|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 555, False: 2]
  |  |  |  |  |  Branch (14:41): [True: 554, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|    566|            goto label;                               \
  |  |   19|    566|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|    554|        p += 2;                                       \
  |  |   21|    554|    }
  ------------------
  258|    554|    if ((genTime.tm_month == 0) || (genTime.tm_month > 12))
  ------------------
  |  Branch (258:9): [True: 1, False: 553]
  |  Branch (258:36): [True: 5, False: 548]
  ------------------
  259|      6|        goto loser;
  260|       |
  261|       |    /* NSPR month base is 0 */
  262|    548|    --genTime.tm_month;
  263|       |
  264|    548|    CAPTURE(genTime.tm_mday, string, loser);
  ------------------
  |  |   16|    548|    {                                                 \
  |  |   17|    548|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|  1.09k|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 543, False: 5]
  |  |  |  |  |  Branch (14:41): [True: 542, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    542|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 538, False: 4]
  |  |  |  |  |  Branch (14:41): [True: 537, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|    548|            goto label;                               \
  |  |   19|    548|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|    537|        p += 2;                                       \
  |  |   21|    537|    }
  ------------------
  265|    537|    if ((genTime.tm_mday == 0) || (genTime.tm_mday > 31))
  ------------------
  |  Branch (265:9): [True: 1, False: 536]
  |  Branch (265:35): [True: 4, False: 532]
  ------------------
  266|      5|        goto loser;
  267|       |
  268|  1.05k|    CAPTURE(genTime.tm_hour, string, loser);
  ------------------
  |  |   16|    532|    {                                                 \
  |  |   17|    532|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|  1.06k|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 524, False: 8]
  |  |  |  |  |  Branch (14:41): [True: 522, False: 2]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    522|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 520, False: 2]
  |  |  |  |  |  Branch (14:41): [True: 519, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|    532|            goto label;                               \
  |  |   19|    532|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|    519|        p += 2;                                       \
  |  |   21|    519|    }
  ------------------
  269|  1.05k|    if (genTime.tm_hour > 23)
  ------------------
  |  Branch (269:9): [True: 1, False: 518]
  ------------------
  270|      1|        goto loser;
  271|       |
  272|  1.02k|    CAPTURE(genTime.tm_min, string, loser);
  ------------------
  |  |   16|    518|    {                                                 \
  |  |   17|    518|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|  1.03k|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 516, False: 2]
  |  |  |  |  |  Branch (14:41): [True: 515, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    515|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 511, False: 4]
  |  |  |  |  |  Branch (14:41): [True: 510, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|    518|            goto label;                               \
  |  |   19|    518|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|    510|        p += 2;                                       \
  |  |   21|    510|    }
  ------------------
  273|  1.02k|    if (genTime.tm_min > 59)
  ------------------
  |  Branch (273:9): [True: 2, False: 508]
  ------------------
  274|      2|        goto loser;
  275|       |
  276|    508|    if (ISDIGIT(string[0])) {
  ------------------
  |  |   14|    508|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  ------------------
  |  |  |  Branch (14:23): [True: 498, False: 10]
  |  |  |  Branch (14:41): [True: 481, False: 17]
  |  |  ------------------
  ------------------
  277|    481|        CAPTURE(genTime.tm_sec, string, loser);
  ------------------
  |  |   16|    481|    {                                                 \
  |  |   17|    481|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    962|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 481, False: 0]
  |  |  |  |  |  Branch (14:41): [True: 481, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|    481|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 480, False: 1]
  |  |  |  |  |  Branch (14:41): [True: 479, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|    481|            goto label;                               \
  |  |   19|    481|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|    479|        p += 2;                                       \
  |  |   21|    479|    }
  ------------------
  278|    479|        if (genTime.tm_sec > 59)
  ------------------
  |  Branch (278:13): [True: 2, False: 477]
  ------------------
  279|      2|            goto loser;
  280|    479|    }
  281|    504|    signum = *string++;
  282|    504|    if (signum == '+' || signum == '-') {
  ------------------
  |  Branch (282:9): [True: 5, False: 499]
  |  Branch (282:26): [True: 2, False: 497]
  ------------------
  283|      7|        CAPTURE(hourOff, string, loser);
  ------------------
  |  |   16|      7|    {                                                 \
  |  |   17|      7|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|     14|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 5, False: 2]
  |  |  |  |  |  Branch (14:41): [True: 4, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|      4|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 3, False: 1]
  |  |  |  |  |  Branch (14:41): [True: 2, False: 1]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|      7|            goto label;                               \
  |  |   19|      7|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|      2|        p += 2;                                       \
  |  |   21|      2|    }
  ------------------
  284|      2|        if (hourOff > 23)
  ------------------
  |  Branch (284:13): [True: 1, False: 1]
  ------------------
  285|      1|            goto loser;
  286|      1|        CAPTURE(minOff, string, loser);
  ------------------
  |  |   16|      1|    {                                                 \
  |  |   17|      1|        if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|      2|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 0, False: 1]
  |  |  |  |  |  Branch (14:41): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |                       if (!ISDIGIT((p)[0]) || !ISDIGIT((p)[1]))     \
  |  |  ------------------
  |  |  |  |   14|      0|#define ISDIGIT(dig) (((dig) >= '0') && ((dig) <= '9'))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (14:23): [True: 0, False: 0]
  |  |  |  |  |  Branch (14:41): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  |  |   18|      1|            goto label;                               \
  |  |   19|      1|        (var) = ((p)[0] - '0') * 10 + ((p)[1] - '0'); \
  |  |   20|      0|        p += 2;                                       \
  |  |   21|      0|    }
  ------------------
  287|      1|        if (minOff > 59)
  ------------------
  |  Branch (287:13): [True: 0, False: 0]
  ------------------
  288|      0|            goto loser;
  289|      0|        if (signum == '-') {
  ------------------
  |  Branch (289:13): [True: 0, False: 0]
  ------------------
  290|      0|            hourOff = -hourOff;
  291|      0|            minOff = -minOff;
  292|      0|        }
  293|    497|    } else if (signum != 'Z') {
  ------------------
  |  Branch (293:16): [True: 11, False: 486]
  ------------------
  294|     11|        goto loser;
  295|     11|    }
  296|       |
  297|    486|    if (endptr)
  ------------------
  |  Branch (297:9): [True: 486, False: 0]
  ------------------
  298|    486|        *endptr = string;
  299|       |
  300|       |    /* Convert the GMT offset to seconds and save it in genTime
  301|       |     * for the implode time call.
  302|       |     */
  303|    486|    genTime.tm_params.tp_gmt_offset = (PRInt32)((hourOff * 60L + minOff) * 60L);
  304|    486|    *dst = PR_ImplodeTime(&genTime);
  305|    486|    return SECSuccess;
  306|       |
  307|    103|loser:
  308|    103|    PORT_SetError(SEC_ERROR_INVALID_TIME);
  ------------------
  |  |   65|    103|#define PORT_SetError PORT_SetError_Util
  ------------------
  309|    103|    return SECFailure;
  310|    504|}

NSS_InitializePRErrorTable:
   37|      1|{
   38|      1|    return (PR_SUCCESS == PR_CallOnce(&once, nss_InitializePRErrorTableOnce))
  ------------------
  |  Branch (38:12): [True: 1, False: 0]
  ------------------
   39|      1|               ? SECSuccess
   40|      1|               : SECFailure;
   41|      1|}
errstrs.c:nss_InitializePRErrorTableOnce:
   29|      1|{
   30|      1|    return PR_ErrorInstallTable(&sec_et);
   31|      1|}

HASH_GetHashTypeByOidTag_Util:
   12|   153k|{
   13|   153k|    HASH_HashType ht = HASH_AlgNULL;
   14|       |
   15|   153k|    switch (hashOid) {
   16|      0|        case SEC_OID_MD2:
  ------------------
  |  Branch (16:9): [True: 0, False: 153k]
  ------------------
   17|      0|            ht = HASH_AlgMD2;
   18|      0|            break;
   19|  4.15k|        case SEC_OID_MD5:
  ------------------
  |  Branch (19:9): [True: 4.15k, False: 149k]
  ------------------
   20|  4.15k|            ht = HASH_AlgMD5;
   21|  4.15k|            break;
   22|   131k|        case SEC_OID_SHA1:
  ------------------
  |  Branch (22:9): [True: 131k, False: 22.0k]
  ------------------
   23|   131k|            ht = HASH_AlgSHA1;
   24|   131k|            break;
   25|      0|        case SEC_OID_SHA224:
  ------------------
  |  Branch (25:9): [True: 0, False: 153k]
  ------------------
   26|      0|            ht = HASH_AlgSHA224;
   27|      0|            break;
   28|  5.09k|        case SEC_OID_SHA256:
  ------------------
  |  Branch (28:9): [True: 5.09k, False: 148k]
  ------------------
   29|  5.09k|            ht = HASH_AlgSHA256;
   30|  5.09k|            break;
   31|  2.71k|        case SEC_OID_SHA384:
  ------------------
  |  Branch (31:9): [True: 2.71k, False: 150k]
  ------------------
   32|  2.71k|            ht = HASH_AlgSHA384;
   33|  2.71k|            break;
   34|  10.0k|        case SEC_OID_SHA512:
  ------------------
  |  Branch (34:9): [True: 10.0k, False: 143k]
  ------------------
   35|  10.0k|            ht = HASH_AlgSHA512;
   36|  10.0k|            break;
   37|      0|        case SEC_OID_SHA3_224:
  ------------------
  |  Branch (37:9): [True: 0, False: 153k]
  ------------------
   38|      0|            ht = HASH_AlgSHA3_224;
   39|      0|            break;
   40|      0|        case SEC_OID_SHA3_256:
  ------------------
  |  Branch (40:9): [True: 0, False: 153k]
  ------------------
   41|      0|            ht = HASH_AlgSHA3_256;
   42|      0|            break;
   43|      0|        case SEC_OID_SHA3_384:
  ------------------
  |  Branch (43:9): [True: 0, False: 153k]
  ------------------
   44|      0|            ht = HASH_AlgSHA3_384;
   45|      0|            break;
   46|      0|        case SEC_OID_SHA3_512:
  ------------------
  |  Branch (46:9): [True: 0, False: 153k]
  ------------------
   47|      0|            ht = HASH_AlgSHA3_512;
   48|      0|            break;
   49|      0|        default:
  ------------------
  |  Branch (49:9): [True: 0, False: 153k]
  ------------------
   50|      0|            PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   51|      0|            break;
   52|   153k|    }
   53|   153k|    return ht;
   54|   153k|}

NSSRWLock_New_Util:
   74|  9.72k|{
   75|  9.72k|    NSSRWLock *rwlock;
   76|       |
   77|  9.72k|    rwlock = PR_NEWZAP(NSSRWLock);
  ------------------
  |  |   99|  9.72k|#define PR_NEWZAP(_struct) ((_struct*)PR_Calloc(1, sizeof(_struct)))
  ------------------
   78|  9.72k|    if (rwlock == NULL)
  ------------------
  |  Branch (78:9): [True: 0, False: 9.72k]
  ------------------
   79|      0|        return NULL;
   80|       |
   81|  9.72k|    rwlock->rw_lock = PZ_NewLock(nssILockRWLock);
  ------------------
  |  |  243|  9.72k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
   82|  9.72k|    if (rwlock->rw_lock == NULL) {
  ------------------
  |  Branch (82:9): [True: 0, False: 9.72k]
  ------------------
   83|      0|        goto loser;
   84|      0|    }
   85|  9.72k|    rwlock->rw_reader_waitq = PZ_NewCondVar(rwlock->rw_lock);
  ------------------
  |  |  248|  9.72k|#define PZ_NewCondVar(l) PR_NewCondVar((l))
  ------------------
   86|  9.72k|    if (rwlock->rw_reader_waitq == NULL) {
  ------------------
  |  Branch (86:9): [True: 0, False: 9.72k]
  ------------------
   87|      0|        goto loser;
   88|      0|    }
   89|  9.72k|    rwlock->rw_writer_waitq = PZ_NewCondVar(rwlock->rw_lock);
  ------------------
  |  |  248|  9.72k|#define PZ_NewCondVar(l) PR_NewCondVar((l))
  ------------------
   90|  9.72k|    if (rwlock->rw_writer_waitq == NULL) {
  ------------------
  |  Branch (90:9): [True: 0, False: 9.72k]
  ------------------
   91|      0|        goto loser;
   92|      0|    }
   93|  9.72k|    if (lock_name != NULL) {
  ------------------
  |  Branch (93:9): [True: 3, False: 9.71k]
  ------------------
   94|      3|        rwlock->rw_name = (char *)PR_Malloc((PRUint32)strlen(lock_name) + 1);
   95|      3|        if (rwlock->rw_name == NULL) {
  ------------------
  |  Branch (95:13): [True: 0, False: 3]
  ------------------
   96|      0|            goto loser;
   97|      0|        }
   98|      3|        strcpy(rwlock->rw_name, lock_name);
   99|  9.71k|    } else {
  100|  9.71k|        rwlock->rw_name = NULL;
  101|  9.71k|    }
  102|  9.72k|    rwlock->rw_rank = lock_rank;
  103|  9.72k|    rwlock->rw_waiting_readers = 0;
  104|  9.72k|    rwlock->rw_waiting_writers = 0;
  105|  9.72k|    rwlock->rw_reader_locks = 0;
  106|  9.72k|    rwlock->rw_writer_locks = 0;
  107|       |
  108|  9.72k|    return rwlock;
  109|       |
  110|      0|loser:
  111|      0|    NSSRWLock_Destroy(rwlock);
  ------------------
  |  |   45|      0|#define NSSRWLock_Destroy NSSRWLock_Destroy_Util
  ------------------
  112|      0|    return (NULL);
  113|  9.72k|}
NSSRWLock_Destroy_Util:
  120|  9.72k|{
  121|  9.72k|    PR_ASSERT(rwlock != NULL);
  ------------------
  |  |  208|  9.72k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.72k, False: 0]
  |  |  ------------------
  ------------------
  122|  9.72k|    PR_ASSERT(rwlock->rw_waiting_readers == 0);
  ------------------
  |  |  208|  9.72k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.72k, False: 0]
  |  |  ------------------
  ------------------
  123|  9.72k|    PR_ASSERT(rwlock->rw_writer_locks == 0);
  ------------------
  |  |  208|  9.72k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.72k, False: 0]
  |  |  ------------------
  ------------------
  124|  9.72k|    PR_ASSERT(rwlock->rw_reader_locks == 0);
  ------------------
  |  |  208|  9.72k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 9.72k, False: 0]
  |  |  ------------------
  ------------------
  125|       |
  126|       |    /* XXX Shouldn't we lock the PZLock before destroying this?? */
  127|       |
  128|  9.72k|    if (rwlock->rw_name)
  ------------------
  |  Branch (128:9): [True: 3, False: 9.71k]
  ------------------
  129|      3|        PR_Free(rwlock->rw_name);
  130|  9.72k|    if (rwlock->rw_reader_waitq)
  ------------------
  |  Branch (130:9): [True: 9.72k, False: 0]
  ------------------
  131|  9.72k|        PZ_DestroyCondVar(rwlock->rw_reader_waitq);
  ------------------
  |  |  249|  9.72k|#define PZ_DestroyCondVar(v) PR_DestroyCondVar((v))
  ------------------
  132|  9.72k|    if (rwlock->rw_writer_waitq)
  ------------------
  |  Branch (132:9): [True: 9.72k, False: 0]
  ------------------
  133|  9.72k|        PZ_DestroyCondVar(rwlock->rw_writer_waitq);
  ------------------
  |  |  249|  9.72k|#define PZ_DestroyCondVar(v) PR_DestroyCondVar((v))
  ------------------
  134|  9.72k|    if (rwlock->rw_lock)
  ------------------
  |  Branch (134:9): [True: 9.72k, False: 0]
  ------------------
  135|  9.72k|        PZ_DestroyLock(rwlock->rw_lock);
  ------------------
  |  |  244|  9.72k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  136|  9.72k|    PR_DELETE(rwlock);
  ------------------
  |  |  110|  9.72k|#define PR_DELETE(_ptr) { PR_Free(_ptr); (_ptr) = NULL; }
  ------------------
  137|  9.72k|}
NSSRWLock_LockRead_Util:
  144|  1.00M|{
  145|  1.00M|    PRThread *me = PR_GetCurrentThread();
  146|       |
  147|  1.00M|    PZ_Lock(rwlock->rw_lock);
  ------------------
  |  |  245|  1.00M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  148|       |#ifdef NSS_RWLOCK_RANK_ORDER_DEBUG
  149|       |
  150|       |    /*
  151|       |     * assert that rank ordering is not violated; the rank of 'rwlock' should
  152|       |     * be equal to or greater than the highest rank of all the locks held by
  153|       |     * the thread.
  154|       |     */
  155|       |    PR_ASSERT((rwlock->rw_rank == NSS_RWLOCK_RANK_NONE) ||
  156|       |              (rwlock->rw_rank >= nssRWLock_GetThreadRank(me)));
  157|       |#endif
  158|       |    /*
  159|       |     * wait if write-locked or if a writer is waiting; preference for writers
  160|       |     */
  161|  1.00M|    UNTIL((rwlock->rw_owner == me) ||    /* I own it, or        */
  ------------------
  |  |   60|  4.02M|#define UNTIL(x) while (!(x))
  |  |  ------------------
  |  |  |  Branch (60:27): [True: 1.00M, False: 0]
  |  |  |  Branch (60:27): [True: 1.00M, False: 0]
  |  |  |  Branch (60:27): [True: 0, False: 1.00M]
  |  |  ------------------
  ------------------
  162|  1.00M|          ((rwlock->rw_owner == NULL) && /* no-one owns it, and */
  163|  1.00M|           (rwlock->rw_waiting_writers == 0)))
  164|      0|    { /* no-one is waiting to own */
  165|       |
  166|      0|        rwlock->rw_waiting_readers++;
  167|      0|        PZ_WaitCondVar(rwlock->rw_reader_waitq, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |  250|      0|#define PZ_WaitCondVar(v, t) PR_WaitCondVar((v), (t))
  ------------------
  168|      0|        rwlock->rw_waiting_readers--;
  169|      0|    }
  170|  1.00M|    rwlock->rw_reader_locks++; /* Increment read-lock count */
  171|       |
  172|  1.00M|    PZ_Unlock(rwlock->rw_lock);
  ------------------
  |  |  246|  1.00M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  173|       |
  174|       |#ifdef NSS_RWLOCK_RANK_ORDER_DEBUG
  175|       |    nssRWLock_SetThreadRank(me, rwlock); /* update thread's lock rank */
  176|       |#endif
  177|  1.00M|}
NSSRWLock_UnlockRead_Util:
  183|  1.00M|{
  184|  1.00M|    PZ_Lock(rwlock->rw_lock);
  ------------------
  |  |  245|  1.00M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  185|       |
  186|  1.00M|    PR_ASSERT(rwlock->rw_reader_locks > 0); /* lock must be read locked */
  ------------------
  |  |  208|  1.00M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1.00M, False: 0]
  |  |  ------------------
  ------------------
  187|       |
  188|  1.00M|    if ((rwlock->rw_reader_locks > 0) &&    /* caller isn't screwey */
  ------------------
  |  Branch (188:9): [True: 1.00M, False: 0]
  ------------------
  189|  1.00M|        (--rwlock->rw_reader_locks == 0) && /* not read locked any more */
  ------------------
  |  Branch (189:9): [True: 1.00M, False: 0]
  ------------------
  190|  1.00M|        (rwlock->rw_owner == NULL) &&       /* not write locked */
  ------------------
  |  Branch (190:9): [True: 1.00M, False: 0]
  ------------------
  191|  1.00M|        (rwlock->rw_waiting_writers > 0)) { /* someone's waiting. */
  ------------------
  |  Branch (191:9): [True: 0, False: 1.00M]
  ------------------
  192|       |
  193|      0|        PZ_NotifyCondVar(rwlock->rw_writer_waitq); /* wake him up. */
  ------------------
  |  |  251|      0|#define PZ_NotifyCondVar(v) PR_NotifyCondVar((v))
  ------------------
  194|      0|    }
  195|       |
  196|  1.00M|    PZ_Unlock(rwlock->rw_lock);
  ------------------
  |  |  246|  1.00M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  197|       |
  198|       |#ifdef NSS_RWLOCK_RANK_ORDER_DEBUG
  199|       |    /*
  200|       |     * update thread's lock rank
  201|       |     */
  202|       |    nssRWLock_UnsetThreadRank(me, rwlock);
  203|       |#endif
  204|  1.00M|    return;
  205|  1.00M|}
NSSRWLock_LockWrite_Util:
  212|   274k|{
  213|   274k|    PRThread *me = PR_GetCurrentThread();
  214|       |
  215|   274k|    PZ_Lock(rwlock->rw_lock);
  ------------------
  |  |  245|   274k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  216|       |#ifdef NSS_RWLOCK_RANK_ORDER_DEBUG
  217|       |    /*
  218|       |     * assert that rank ordering is not violated; the rank of 'rwlock' should
  219|       |     * be equal to or greater than the highest rank of all the locks held by
  220|       |     * the thread.
  221|       |     */
  222|       |    PR_ASSERT((rwlock->rw_rank == NSS_RWLOCK_RANK_NONE) ||
  223|       |              (rwlock->rw_rank >= nssRWLock_GetThreadRank(me)));
  224|       |#endif
  225|       |    /*
  226|       |     * wait if read locked or write locked.
  227|       |     */
  228|   274k|    PR_ASSERT(rwlock->rw_reader_locks >= 0);
  ------------------
  |  |  208|   274k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 274k, False: 0]
  |  |  ------------------
  ------------------
  229|   274k|    PR_ASSERT(me != NULL);
  ------------------
  |  |  208|   274k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 274k, False: 0]
  |  |  ------------------
  ------------------
  230|       |
  231|   274k|    UNTIL((rwlock->rw_owner == me) ||    /* I own write lock, or */
  ------------------
  |  |   60|  1.09M|#define UNTIL(x) while (!(x))
  |  |  ------------------
  |  |  |  Branch (60:27): [True: 274k, False: 0]
  |  |  |  Branch (60:27): [True: 274k, False: 0]
  |  |  |  Branch (60:27): [True: 2, False: 274k]
  |  |  ------------------
  ------------------
  232|   274k|          ((rwlock->rw_owner == NULL) && /* no writer   and */
  233|   274k|           (rwlock->rw_reader_locks == 0)))
  234|      0|    { /* no readers, either. */
  235|       |
  236|      0|        rwlock->rw_waiting_writers++;
  237|      0|        PZ_WaitCondVar(rwlock->rw_writer_waitq, PR_INTERVAL_NO_TIMEOUT);
  ------------------
  |  |  250|      0|#define PZ_WaitCondVar(v, t) PR_WaitCondVar((v), (t))
  ------------------
  238|      0|        rwlock->rw_waiting_writers--;
  239|      0|        PR_ASSERT(rwlock->rw_reader_locks >= 0);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  240|      0|    }
  241|       |
  242|   274k|    PR_ASSERT(rwlock->rw_reader_locks == 0);
  ------------------
  |  |  208|   274k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 274k, False: 0]
  |  |  ------------------
  ------------------
  243|       |    /*
  244|       |     * apply write lock
  245|       |     */
  246|   274k|    rwlock->rw_owner = me;
  247|   274k|    rwlock->rw_writer_locks++; /* Increment write-lock count */
  248|       |
  249|   274k|    PZ_Unlock(rwlock->rw_lock);
  ------------------
  |  |  246|   274k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  250|       |
  251|       |#ifdef NSS_RWLOCK_RANK_ORDER_DEBUG
  252|       |    /*
  253|       |     * update thread's lock rank
  254|       |     */
  255|       |    nssRWLock_SetThreadRank(me, rwlock);
  256|       |#endif
  257|   274k|}
NSSRWLock_UnlockWrite_Util:
  263|   274k|{
  264|   274k|    PRThread *me = PR_GetCurrentThread();
  265|       |
  266|   274k|    PZ_Lock(rwlock->rw_lock);
  ------------------
  |  |  245|   274k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  267|   274k|    PR_ASSERT(rwlock->rw_owner == me);      /* lock must be write-locked by me.  */
  ------------------
  |  |  208|   274k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 274k, False: 0]
  |  |  ------------------
  ------------------
  268|   274k|    PR_ASSERT(rwlock->rw_writer_locks > 0); /* lock must be write locked */
  ------------------
  |  |  208|   274k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 274k, False: 0]
  |  |  ------------------
  ------------------
  269|       |
  270|   274k|    if (rwlock->rw_owner == me &&         /* I own it, and            */
  ------------------
  |  Branch (270:9): [True: 274k, False: 0]
  ------------------
  271|   274k|        rwlock->rw_writer_locks > 0 &&    /* I own it, and            */
  ------------------
  |  Branch (271:9): [True: 274k, False: 0]
  ------------------
  272|   274k|        --rwlock->rw_writer_locks == 0) { /* I'm all done with it     */
  ------------------
  |  Branch (272:9): [True: 274k, False: 2]
  ------------------
  273|       |
  274|   274k|        rwlock->rw_owner = NULL; /* I don't own it any more. */
  275|       |
  276|       |        /* Give preference to waiting writers. */
  277|   274k|        if (rwlock->rw_waiting_writers > 0) {
  ------------------
  |  Branch (277:13): [True: 0, False: 274k]
  ------------------
  278|      0|            if (rwlock->rw_reader_locks == 0)
  ------------------
  |  Branch (278:17): [True: 0, False: 0]
  ------------------
  279|      0|                PZ_NotifyCondVar(rwlock->rw_writer_waitq);
  ------------------
  |  |  251|      0|#define PZ_NotifyCondVar(v) PR_NotifyCondVar((v))
  ------------------
  280|   274k|        } else if (rwlock->rw_waiting_readers > 0) {
  ------------------
  |  Branch (280:20): [True: 0, False: 274k]
  ------------------
  281|      0|            PZ_NotifyAllCondVar(rwlock->rw_reader_waitq);
  ------------------
  |  |  252|      0|#define PZ_NotifyAllCondVar(v) PR_NotifyAllCondVar((v))
  ------------------
  282|      0|        }
  283|   274k|    }
  284|   274k|    PZ_Unlock(rwlock->rw_lock);
  ------------------
  |  |  246|   274k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  285|       |
  286|       |#ifdef NSS_RWLOCK_RANK_ORDER_DEBUG
  287|       |    /*
  288|       |     * update thread's lock rank
  289|       |     */
  290|       |    nssRWLock_UnsetThreadRank(me, rwlock);
  291|       |#endif
  292|   274k|    return;
  293|   274k|}
NSSRWLock_HaveWriteLock_Util:
  298|   105k|{
  299|   105k|    PRBool ownWriteLock;
  300|   105k|    PRThread *me = PR_GetCurrentThread();
  301|       |
  302|       |/* This lock call isn't really necessary.
  303|       | ** If this thread is the owner, that fact cannot change during this call,
  304|       | ** because this thread is in this call.
  305|       | ** If this thread is NOT the owner, the owner could change, but it
  306|       | ** could not become this thread.
  307|       | */
  308|       |#if UNNECESSARY
  309|       |    PZ_Lock(rwlock->rw_lock);
  310|       |#endif
  311|   105k|    ownWriteLock = (PRBool)(me == rwlock->rw_owner);
  312|       |#if UNNECESSARY
  313|       |    PZ_Unlock(rwlock->rw_lock);
  314|       |#endif
  315|   105k|    return ownWriteLock;
  316|   105k|}

_SGN_VerifyPKCS1DigestInfo:
   95|      4|{
   96|      4|    SECOidData *hashOid;
   97|      4|    pkcs1Prefix prefix;
   98|      4|    SECStatus rv;
   99|       |
  100|      4|    if (!digest || !digest->data ||
  ------------------
  |  Branch (100:9): [True: 0, False: 4]
  |  Branch (100:20): [True: 0, False: 4]
  ------------------
  101|      4|        !dataRecoveredFromSignature || !dataRecoveredFromSignature->data) {
  ------------------
  |  Branch (101:9): [True: 0, False: 4]
  |  Branch (101:40): [True: 0, False: 4]
  ------------------
  102|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  103|      0|        return SECFailure;
  104|      0|    }
  105|       |
  106|      4|    hashOid = SECOID_FindOIDByTag(digestAlg);
  ------------------
  |  |  116|      4|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
  107|      4|    if (hashOid == NULL) {
  ------------------
  |  Branch (107:9): [True: 0, False: 4]
  ------------------
  108|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  109|      0|        return SECFailure;
  110|      0|    }
  111|       |
  112|      4|    prefix.data = NULL;
  113|       |
  114|      4|    rv = encodePrefix(hashOid, digest->len, &prefix, PR_TRUE);
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
  115|       |
  116|      4|    if (rv == SECSuccess) {
  ------------------
  |  Branch (116:9): [True: 4, False: 0]
  ------------------
  117|       |        /* We don't attempt to avoid timing attacks on these comparisons because
  118|       |         * signature verification is a public key operation, not a private key
  119|       |         * operation.
  120|       |         */
  121|       |
  122|      4|        if (dataRecoveredFromSignature->len != prefix.len + digest->len) {
  ------------------
  |  Branch (122:13): [True: 3, False: 1]
  ------------------
  123|      3|            PRBool lengthMismatch = PR_TRUE;
  ------------------
  |  |  437|      3|#define PR_TRUE 1
  ------------------
  124|       |#ifdef NSS_PKCS1_AllowMissingParameters
  125|       |            if (unsafeAllowMissingParameters) {
  126|       |                if (prefix.data) {
  127|       |                    PORT_Free(prefix.data);
  128|       |                    prefix.data = NULL;
  129|       |                }
  130|       |                rv = encodePrefix(hashOid, digest->len, &prefix, PR_FALSE);
  131|       |                if (rv != SECSuccess ||
  132|       |                    dataRecoveredFromSignature->len == prefix.len + digest->len) {
  133|       |                    lengthMismatch = PR_FALSE;
  134|       |                }
  135|       |            }
  136|       |#endif
  137|      3|            if (lengthMismatch) {
  ------------------
  |  Branch (137:17): [True: 3, False: 0]
  ------------------
  138|      3|                PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
  139|      3|                rv = SECFailure;
  140|      3|            }
  141|      3|        }
  142|      4|    }
  143|       |
  144|      4|    if (rv == SECSuccess) {
  ------------------
  |  Branch (144:9): [True: 1, False: 3]
  ------------------
  145|      1|        if (memcmp(dataRecoveredFromSignature->data, prefix.data, prefix.len) ||
  ------------------
  |  Branch (145:13): [True: 0, False: 1]
  ------------------
  146|      1|            memcmp(dataRecoveredFromSignature->data + prefix.len, digest->data,
  ------------------
  |  Branch (146:13): [True: 1, False: 0]
  ------------------
  147|      1|                   digest->len)) {
  148|      1|            PORT_SetError(SEC_ERROR_BAD_SIGNATURE);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  149|      1|            rv = SECFailure;
  150|      1|        }
  151|      1|    }
  152|       |
  153|      4|    if (prefix.data) {
  ------------------
  |  Branch (153:9): [True: 4, False: 0]
  ------------------
  154|      4|        PORT_Free(prefix.data);
  ------------------
  |  |   60|      4|#define PORT_Free PORT_Free_Util
  ------------------
  155|      4|    }
  156|       |
  157|      4|    return rv;
  158|      4|}
pkcs1sig.c:encodePrefix:
   26|      4|{
   27|       |    /* with params coding is:
   28|       |     *  Sequence (2 bytes) {
   29|       |     *      Sequence (2 bytes) {
   30|       |     *               Oid (2 bytes)  {
   31|       |     *                   Oid value (derOid->oid.len)
   32|       |     *               }
   33|       |     *               NULL (2 bytes)
   34|       |     *      }
   35|       |     *      OCTECT (2 bytes);
   36|       |     *
   37|       |     * without params coding is:
   38|       |     *  Sequence (2 bytes) {
   39|       |     *      Sequence (2 bytes) {
   40|       |     *               Oid (2 bytes)  {
   41|       |     *                   Oid value (derOid->oid.len)
   42|       |     *               }
   43|       |     *      }
   44|       |     *      OCTECT (2 bytes);
   45|       |     */
   46|       |
   47|      4|    unsigned int innerSeqLen = 2 + hashOid->oid.len;
   48|      4|    unsigned int outerSeqLen = 2 + innerSeqLen + 2 + digestLen;
   49|      4|    unsigned int extra = 0;
   50|       |
   51|      4|    if (withParams) {
  ------------------
  |  Branch (51:9): [True: 4, False: 0]
  ------------------
   52|      4|        innerSeqLen += 2;
   53|      4|        outerSeqLen += 2;
   54|      4|        extra = 2;
   55|      4|    }
   56|       |
   57|      4|    if (innerSeqLen >= 128 ||
  ------------------
  |  Branch (57:9): [True: 0, False: 4]
  ------------------
   58|      4|        outerSeqLen >= 128 ||
  ------------------
  |  Branch (58:9): [True: 0, False: 4]
  ------------------
   59|      4|        (outerSeqLen + 2 - digestLen) >
  ------------------
  |  Branch (59:9): [True: 0, False: 4]
  ------------------
   60|      4|            (MAX_PREFIX_LEN_EXCLUDING_OID + hashOid->oid.len)) {
  ------------------
  |  |   21|      4|#define MAX_PREFIX_LEN_EXCLUDING_OID 10
  ------------------
   61|       |        /* this is actually a library failure, It shouldn't happen */
   62|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   63|      0|        return SECFailure;
   64|      0|    }
   65|       |
   66|      4|    prefix->len = 6 + hashOid->oid.len + extra + 2;
   67|      4|    prefix->data = PORT_Alloc(prefix->len);
  ------------------
  |  |   52|      4|#define PORT_Alloc PORT_Alloc_Util
  ------------------
   68|      4|    if (!prefix->data) {
  ------------------
  |  Branch (68:9): [True: 0, False: 4]
  ------------------
   69|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   70|      0|        return SECFailure;
   71|      0|    }
   72|       |
   73|      4|    prefix->data[0] = SEC_ASN1_SEQUENCE | SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |   92|      4|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
                  prefix->data[0] = SEC_ASN1_SEQUENCE | SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|      4|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
   74|      4|    prefix->data[1] = outerSeqLen;
   75|      4|    prefix->data[2] = SEC_ASN1_SEQUENCE | SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |   92|      4|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
                  prefix->data[2] = SEC_ASN1_SEQUENCE | SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|      4|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
   76|      4|    prefix->data[3] = innerSeqLen;
   77|      4|    prefix->data[4] = SEC_ASN1_OBJECT_ID;
  ------------------
  |  |   82|      4|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
   78|      4|    prefix->data[5] = hashOid->oid.len;
   79|      4|    PORT_Memcpy(&prefix->data[6], hashOid->oid.data, hashOid->oid.len);
  ------------------
  |  |  180|      4|#define PORT_Memcpy memcpy
  ------------------
   80|      4|    if (withParams) {
  ------------------
  |  Branch (80:9): [True: 4, False: 0]
  ------------------
   81|      4|        prefix->data[6 + hashOid->oid.len] = SEC_ASN1_NULL;
  ------------------
  |  |   81|      4|#define SEC_ASN1_NULL 0x05
  ------------------
   82|      4|        prefix->data[6 + hashOid->oid.len + 1] = 0;
   83|      4|    }
   84|      4|    prefix->data[6 + hashOid->oid.len + extra] = SEC_ASN1_OCTET_STRING;
  ------------------
  |  |   80|      4|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
   85|      4|    prefix->data[6 + hashOid->oid.len + extra + 1] = digestLen;
   86|       |
   87|      4|    return SECSuccess;
   88|      4|}

SEC_QuickDERDecodeItem_Util:
  818|   118k|{
  819|   118k|    SECStatus rv = SECSuccess;
  820|   118k|    SECItem newsrc;
  821|       |
  822|   118k|    if (!arena || !templateEntry || !src) {
  ------------------
  |  Branch (822:9): [True: 0, False: 118k]
  |  Branch (822:19): [True: 0, False: 118k]
  |  Branch (822:37): [True: 0, False: 118k]
  ------------------
  823|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  824|      0|        rv = SECFailure;
  825|      0|    }
  826|       |
  827|   118k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (827:9): [True: 118k, False: 0]
  ------------------
  828|   118k|        newsrc = *src;
  829|   118k|        rv = DecodeItem(dest, templateEntry, &newsrc, arena, PR_TRUE);
  ------------------
  |  |  437|   118k|#define PR_TRUE 1
  ------------------
  830|   118k|        if (SECSuccess == rv && newsrc.len) {
  ------------------
  |  Branch (830:13): [True: 112k, False: 5.23k]
  |  Branch (830:33): [True: 90, False: 112k]
  ------------------
  831|     90|            rv = SECFailure;
  832|     90|            PORT_SetError(SEC_ERROR_EXTRA_INPUT);
  ------------------
  |  |   65|     90|#define PORT_SetError PORT_SetError_Util
  ------------------
  833|     90|        }
  834|   118k|    }
  835|       |
  836|   118k|    return rv;
  837|   118k|}
quickder.c:DecodeItem:
  592|   557k|{
  593|   557k|    SECStatus rv = SECSuccess;
  594|   557k|    SECItem temp;
  595|   557k|    SECItem mark = { siBuffer, NULL, 0 };
  596|   557k|    PRBool pop = PR_FALSE;
  ------------------
  |  |  438|   557k|#define PR_FALSE 0
  ------------------
  597|   557k|    PRBool decode = PR_TRUE;
  ------------------
  |  |  437|   557k|#define PR_TRUE 1
  ------------------
  598|   557k|    PRBool save = PR_FALSE;
  ------------------
  |  |  438|   557k|#define PR_FALSE 0
  ------------------
  599|   557k|    unsigned long kind;
  600|   557k|    PRBool match = PR_TRUE;
  ------------------
  |  |  437|   557k|#define PR_TRUE 1
  ------------------
  601|       |
  602|   557k|    PR_ASSERT(src && dest && templateEntry && arena);
  ------------------
  |  |  208|  3.34M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 557k, False: 0]
  |  |  |  Branch (208:7): [True: 557k, False: 0]
  |  |  |  Branch (208:7): [True: 557k, False: 0]
  |  |  |  Branch (208:7): [True: 557k, False: 0]
  |  |  ------------------
  ------------------
  603|       |#if 0
  604|       |    if (!src || !dest || !templateEntry || !arena)
  605|       |    {
  606|       |        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  607|       |        rv = SECFailure;
  608|       |    }
  609|       |#endif
  610|       |
  611|   557k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (611:9): [True: 557k, False: 0]
  ------------------
  612|       |        /* do the template validation */
  613|   557k|        kind = templateEntry->kind;
  614|   557k|        if (!kind) {
  ------------------
  |  Branch (614:13): [True: 0, False: 557k]
  ------------------
  615|      0|            PORT_SetError(SEC_ERROR_BAD_TEMPLATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  616|      0|            rv = SECFailure;
  617|      0|        }
  618|   557k|    }
  619|       |
  620|   557k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (620:9): [True: 557k, False: 0]
  ------------------
  621|   557k|#ifdef DEBUG
  622|   557k|        if (kind & SEC_ASN1_DEBUG_BREAK) {
  ------------------
  |  |  160|   557k|#define SEC_ASN1_DEBUG_BREAK 0X400000 /* put this in your template and the \
  ------------------
  |  Branch (622:13): [True: 0, False: 557k]
  ------------------
  623|       |            /* when debugging the decoder or a template that fails to
  624|       |            decode, put SEC_ASN1_DEBUG in the component that gives you
  625|       |            trouble. The decoder will then get to this block and assert.
  626|       |            If you want to debug the rest of the code, you can set a
  627|       |            breakpoint and set dontassert to PR_TRUE, which will let
  628|       |            you skip over the assert and continue the debugging session
  629|       |            past it. */
  630|      0|            PRBool dontassert = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  631|      0|            PR_ASSERT(dontassert); /* set bkpoint here & set dontassert*/
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  632|      0|        }
  633|   557k|#endif
  634|       |
  635|   557k|        if ((kind & SEC_ASN1_SKIP) ||
  ------------------
  |  |  140|   557k|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (635:13): [True: 35.1k, False: 521k]
  ------------------
  636|   557k|            (kind & SEC_ASN1_SAVE)) {
  ------------------
  |  |  144|   521k|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  ------------------
  |  Branch (636:13): [True: 15.9k, False: 506k]
  ------------------
  637|       |            /* if skipping or saving this component, don't decode it */
  638|  51.0k|            decode = PR_FALSE;
  ------------------
  |  |  438|  51.0k|#define PR_FALSE 0
  ------------------
  639|  51.0k|        }
  640|       |
  641|   557k|        if (kind & (SEC_ASN1_SAVE | SEC_ASN1_OPTIONAL)) {
  ------------------
  |  |  144|   557k|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  ------------------
                      if (kind & (SEC_ASN1_SAVE | SEC_ASN1_OPTIONAL)) {
  ------------------
  |  |  131|   557k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  |  Branch (641:13): [True: 95.5k, False: 461k]
  ------------------
  642|       |            /* if saving this component, or if it is optional, we may not want to
  643|       |               move past it, so save the position in case we have to rewind */
  644|  95.5k|            mark = *src;
  645|  95.5k|            if (kind & SEC_ASN1_SAVE) {
  ------------------
  |  |  144|  95.5k|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  ------------------
  |  Branch (645:17): [True: 15.9k, False: 79.6k]
  ------------------
  646|  15.9k|                save = PR_TRUE;
  ------------------
  |  |  437|  15.9k|#define PR_TRUE 1
  ------------------
  647|  15.9k|                if (0 == (kind & SEC_ASN1_SKIP)) {
  ------------------
  |  |  140|  15.9k|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (647:21): [True: 15.9k, False: 0]
  ------------------
  648|       |                    /* we will for sure have to rewind when saving this
  649|       |                       component and not skipping it. This is true for all
  650|       |                       legacy uses of SEC_ASN1_SAVE where the following entry
  651|       |                       in the template would causes the same component to be
  652|       |                       processed again */
  653|  15.9k|                    pop = PR_TRUE;
  ------------------
  |  |  437|  15.9k|#define PR_TRUE 1
  ------------------
  654|  15.9k|                }
  655|  15.9k|            }
  656|  95.5k|        }
  657|       |
  658|   557k|        rv = GetItem(src, &temp, PR_TRUE);
  ------------------
  |  |  437|   557k|#define PR_TRUE 1
  ------------------
  659|   557k|    }
  660|       |
  661|   557k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (661:9): [True: 556k, False: 479]
  ------------------
  662|       |        /* now check if the component matches what we expect in the template */
  663|       |
  664|   556k|        if (PR_TRUE == checkTag)
  ------------------
  |  |  437|   556k|#define PR_TRUE 1
  ------------------
  |  Branch (664:13): [True: 556k, False: 252]
  ------------------
  665|       |
  666|   556k|        {
  667|   556k|            rv = MatchComponentType(templateEntry, &temp, &match, dest);
  668|   556k|        }
  669|       |
  670|   556k|        if ((SECSuccess == rv) && (PR_TRUE != match)) {
  ------------------
  |  |  437|   556k|#define PR_TRUE 1
  ------------------
  |  Branch (670:13): [True: 556k, False: 0]
  |  Branch (670:35): [True: 29.4k, False: 527k]
  ------------------
  671|  29.4k|            if (kind & SEC_ASN1_OPTIONAL) {
  ------------------
  |  |  131|  29.4k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  |  Branch (671:17): [True: 24.7k, False: 4.66k]
  ------------------
  672|       |
  673|       |                /* the optional component is missing. This is not fatal. */
  674|       |                /* Rewind, don't decode, and don't save */
  675|  24.7k|                pop = PR_TRUE;
  ------------------
  |  |  437|  24.7k|#define PR_TRUE 1
  ------------------
  676|  24.7k|                decode = PR_FALSE;
  ------------------
  |  |  438|  24.7k|#define PR_FALSE 0
  ------------------
  677|  24.7k|                save = PR_FALSE;
  ------------------
  |  |  438|  24.7k|#define PR_FALSE 0
  ------------------
  678|  24.7k|            } else {
  679|       |                /* a required component is missing. abort */
  680|  4.66k|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|  4.66k|#define PORT_SetError PORT_SetError_Util
  ------------------
  681|  4.66k|                rv = SECFailure;
  682|  4.66k|            }
  683|  29.4k|        }
  684|   556k|    }
  685|       |
  686|   557k|    if ((SECSuccess == rv) && (PR_TRUE == decode)) {
  ------------------
  |  |  437|   551k|#define PR_TRUE 1
  ------------------
  |  Branch (686:9): [True: 551k, False: 5.14k]
  |  Branch (686:31): [True: 476k, False: 75.7k]
  ------------------
  687|       |        /* the order of processing here is is the tricky part */
  688|       |        /* we start with our special cases */
  689|       |        /* first, check the component class */
  690|   476k|        if (kind & SEC_ASN1_INLINE) {
  ------------------
  |  |  134|   476k|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (690:13): [True: 59.4k, False: 416k]
  ------------------
  691|       |            /* decode inline template */
  692|  59.4k|            rv = DecodeInline(dest, templateEntry, &temp, arena, PR_TRUE);
  ------------------
  |  |  437|  59.4k|#define PR_TRUE 1
  ------------------
  693|  59.4k|        }
  694|       |
  695|   416k|        else if (kind & SEC_ASN1_EXPLICIT) {
  ------------------
  |  |  132|   416k|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
  |  Branch (695:18): [True: 27.1k, False: 389k]
  ------------------
  696|  27.1k|            rv = DecodeExplicit(dest, templateEntry, &temp, arena);
  697|   389k|        } else if ((SEC_ASN1_UNIVERSAL != (kind & SEC_ASN1_CLASS_MASK)) &&
  ------------------
  |  |  120|   389k|#define SEC_ASN1_UNIVERSAL 0x00
  ------------------
                      } else if ((SEC_ASN1_UNIVERSAL != (kind & SEC_ASN1_CLASS_MASK)) &&
  ------------------
  |  |  119|   389k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
  |  Branch (697:20): [True: 252, False: 389k]
  ------------------
  698|       |
  699|   389k|                   (!(kind & SEC_ASN1_EXPLICIT))) {
  ------------------
  |  |  132|    252|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
  |  Branch (699:20): [True: 252, False: 0]
  ------------------
  700|       |
  701|       |            /* decode implicitly tagged components */
  702|    252|            rv = DecodeImplicit(dest, templateEntry, &temp, arena);
  703|   389k|        } else if (kind & SEC_ASN1_POINTER) {
  ------------------
  |  |  135|   389k|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (703:20): [True: 0, False: 389k]
  ------------------
  704|      0|            rv = DecodePointer(dest, templateEntry, &temp, arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  705|   389k|        } else if (kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|   389k|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (705:20): [True: 7.93k, False: 381k]
  ------------------
  706|  7.93k|            rv = DecodeChoice(dest, templateEntry, &temp, arena);
  707|   381k|        } else if (kind & SEC_ASN1_ANY) {
  ------------------
  |  |  133|   381k|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (707:20): [True: 77.0k, False: 304k]
  ------------------
  708|       |            /* catch-all ANY type, don't decode */
  709|  77.0k|            save = PR_TRUE;
  ------------------
  |  |  437|  77.0k|#define PR_TRUE 1
  ------------------
  710|  77.0k|            if (kind & SEC_ASN1_INNER) {
  ------------------
  |  |  141|  77.0k|#define SEC_ASN1_INNER 0x10000        /* with ANY means capture the      \
  ------------------
  |  Branch (710:17): [True: 0, False: 77.0k]
  ------------------
  711|       |                /* skip the tag and length */
  712|      0|                SECItem newtemp = temp;
  713|      0|                rv = GetItem(&newtemp, &temp, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  714|      0|            }
  715|   304k|        } else if (kind & SEC_ASN1_GROUP) {
  ------------------
  |  |  136|   304k|#define SEC_ASN1_GROUP 0x02000        /* with SET or SEQUENCE means \
  ------------------
  |  Branch (715:20): [True: 22.2k, False: 282k]
  ------------------
  716|  22.2k|            if ((SEC_ASN1_SEQUENCE == (kind & SEC_ASN1_TAGNUM_MASK)) ||
  ------------------
  |  |   92|  22.2k|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
                          if ((SEC_ASN1_SEQUENCE == (kind & SEC_ASN1_TAGNUM_MASK)) ||
  ------------------
  |  |   76|  22.2k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (716:17): [True: 11.9k, False: 10.2k]
  ------------------
  717|  22.2k|                (SEC_ASN1_SET == (kind & SEC_ASN1_TAGNUM_MASK))) {
  ------------------
  |  |   93|  10.2k|#define SEC_ASN1_SET 0x11
  ------------------
                              (SEC_ASN1_SET == (kind & SEC_ASN1_TAGNUM_MASK))) {
  ------------------
  |  |   76|  10.2k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (717:17): [True: 10.2k, False: 0]
  ------------------
  718|  22.2k|                rv = DecodeGroup(dest, templateEntry, &temp, arena);
  719|  22.2k|            } else {
  720|       |                /* a group can only be a SET OF or SEQUENCE OF */
  721|      0|                PORT_SetError(SEC_ERROR_BAD_TEMPLATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  722|      0|                rv = SECFailure;
  723|      0|            }
  724|   282k|        } else if (SEC_ASN1_SEQUENCE == (kind & SEC_ASN1_TAGNUM_MASK)) {
  ------------------
  |  |   92|   282k|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
                      } else if (SEC_ASN1_SEQUENCE == (kind & SEC_ASN1_TAGNUM_MASK)) {
  ------------------
  |  |   76|   282k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (724:20): [True: 110k, False: 171k]
  ------------------
  725|       |            /* plain SEQUENCE */
  726|   110k|            rv = DecodeSequence(dest, templateEntry, &temp, arena);
  727|   171k|        } else {
  728|       |            /* handle all other types as "save" */
  729|       |            /* we should only get here for primitive universal types */
  730|   171k|            SECItem newtemp = temp;
  731|   171k|            rv = GetItem(&newtemp, &temp, PR_FALSE);
  ------------------
  |  |  438|   171k|#define PR_FALSE 0
  ------------------
  732|   171k|            save = PR_TRUE;
  ------------------
  |  |  437|   171k|#define PR_TRUE 1
  ------------------
  733|   171k|            if ((SECSuccess == rv) &&
  ------------------
  |  Branch (733:17): [True: 171k, False: 0]
  ------------------
  734|   171k|                SEC_ASN1_UNIVERSAL == (kind & SEC_ASN1_CLASS_MASK)) {
  ------------------
  |  |  120|   171k|#define SEC_ASN1_UNIVERSAL 0x00
  ------------------
                              SEC_ASN1_UNIVERSAL == (kind & SEC_ASN1_CLASS_MASK)) {
  ------------------
  |  |  119|   171k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
  |  Branch (734:17): [True: 171k, False: 0]
  ------------------
  735|   171k|                unsigned long tagnum = kind & SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   76|   171k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  736|   171k|                if (temp.len == 0 && (tagnum == SEC_ASN1_BOOLEAN ||
  ------------------
  |  |   77|    234|#define SEC_ASN1_BOOLEAN 0x01
  ------------------
  |  Branch (736:21): [True: 117, False: 171k]
  |  Branch (736:39): [True: 19, False: 98]
  ------------------
  737|    117|                                      tagnum == SEC_ASN1_INTEGER ||
  ------------------
  |  |   78|    215|#define SEC_ASN1_INTEGER 0x02
  ------------------
  |  Branch (737:39): [True: 6, False: 92]
  ------------------
  738|    117|                                      tagnum == SEC_ASN1_BIT_STRING ||
  ------------------
  |  |   79|    209|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (738:39): [True: 12, False: 80]
  ------------------
  739|    117|                                      tagnum == SEC_ASN1_OBJECT_ID ||
  ------------------
  |  |   82|    197|#define SEC_ASN1_OBJECT_ID 0x06
  ------------------
  |  Branch (739:39): [True: 8, False: 72]
  ------------------
  740|    117|                                      tagnum == SEC_ASN1_ENUMERATED ||
  ------------------
  |  |   86|    189|#define SEC_ASN1_ENUMERATED 0x0a
  ------------------
  |  Branch (740:39): [True: 0, False: 72]
  ------------------
  741|    117|                                      tagnum == SEC_ASN1_UTC_TIME ||
  ------------------
  |  |   99|    189|#define SEC_ASN1_UTC_TIME 0x17
  ------------------
  |  Branch (741:39): [True: 2, False: 70]
  ------------------
  742|    117|                                      tagnum == SEC_ASN1_GENERALIZED_TIME)) {
  ------------------
  |  |  100|     70|#define SEC_ASN1_GENERALIZED_TIME 0x18
  ------------------
  |  Branch (742:39): [True: 1, False: 69]
  ------------------
  743|       |                    /* these types MUST have at least one content octet */
  744|     48|                    PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|     48|#define PORT_SetError PORT_SetError_Util
  ------------------
  745|     48|                    rv = SECFailure;
  746|     48|                } else
  747|   171k|                    switch (tagnum) {
  748|       |                        /* special cases of primitive types */
  749|  14.0k|                        case SEC_ASN1_INTEGER: {
  ------------------
  |  |   78|  14.0k|#define SEC_ASN1_INTEGER 0x02
  ------------------
  |  Branch (749:25): [True: 14.0k, False: 157k]
  ------------------
  750|  14.0k|                            SECItem* destItem = (SECItem*)((char*)dest +
  751|  14.0k|                                                           templateEntry->offset);
  752|  14.0k|                            if (destItem && (siUnsignedInteger == destItem->type)) {
  ------------------
  |  Branch (752:33): [True: 14.0k, False: 0]
  |  Branch (752:45): [True: 6.04k, False: 7.98k]
  ------------------
  753|       |                                /* A leading 0 is only allowed when a value
  754|       |                                 * would otherwise be interpreted as negative. */
  755|  6.04k|                                if (temp.len > 1 && temp.data[0] == 0) {
  ------------------
  |  Branch (755:37): [True: 6.04k, False: 1]
  |  Branch (755:53): [True: 4.12k, False: 1.92k]
  ------------------
  756|  4.12k|                                    temp.data++;
  757|  4.12k|                                    temp.len--;
  758|  4.12k|                                    if (!(temp.data[0] & 0x80)) {
  ------------------
  |  Branch (758:41): [True: 1, False: 4.12k]
  ------------------
  759|      1|                                        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      1|#define PORT_SetError PORT_SetError_Util
  ------------------
  760|      1|                                        rv = SECFailure;
  761|      1|                                    }
  762|  4.12k|                                }
  763|  6.04k|                            }
  764|  14.0k|                            break;
  765|      0|                        }
  766|       |
  767|  27.5k|                        case SEC_ASN1_BIT_STRING: {
  ------------------
  |  |   79|  27.5k|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (767:25): [True: 27.5k, False: 144k]
  ------------------
  768|       |                            /* Can't be 8 or more spare bits, or any spare bits
  769|       |                             * if there are no octets. */
  770|  27.5k|                            if (temp.data[0] >= 8 || (temp.data[0] > 0 && temp.len == 1)) {
  ------------------
  |  Branch (770:33): [True: 15, False: 27.5k]
  |  Branch (770:55): [True: 717, False: 26.8k]
  |  Branch (770:75): [True: 6, False: 711]
  ------------------
  771|     21|                                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|     21|#define PORT_SetError PORT_SetError_Util
  ------------------
  772|     21|                                rv = SECFailure;
  773|     21|                                break;
  774|     21|                            }
  775|       |                            /* change the length in the SECItem to be the number
  776|       |                               of bits */
  777|  27.5k|                            temp.len = (temp.len - 1) * 8 - (temp.data[0] & 0x7);
  778|  27.5k|                            temp.data++;
  779|  27.5k|                            break;
  780|  27.5k|                        }
  781|       |
  782|   129k|                        default: {
  ------------------
  |  Branch (782:25): [True: 129k, False: 41.6k]
  ------------------
  783|   129k|                            break;
  784|  27.5k|                        }
  785|   171k|                    }
  786|   171k|            }
  787|   171k|        }
  788|   476k|    }
  789|       |
  790|   557k|    if ((SECSuccess == rv) && (PR_TRUE == save)) {
  ------------------
  |  |  437|   550k|#define PR_TRUE 1
  ------------------
  |  Branch (790:9): [True: 550k, False: 6.28k]
  |  Branch (790:31): [True: 264k, False: 286k]
  ------------------
  791|   264k|        SECItem* destItem = (SECItem*)((char*)dest + templateEntry->offset);
  792|   264k|        if (destItem) {
  ------------------
  |  Branch (792:13): [True: 264k, False: 0]
  ------------------
  793|       |            /* we leave the type alone in the destination SECItem.
  794|       |               If part of the destination was allocated by the decoder, in
  795|       |               cases of POINTER, SET OF and SEQUENCE OF, then type is set to
  796|       |               siBuffer due to the use of PORT_ArenaZAlloc*/
  797|   264k|            destItem->data = temp.len ? temp.data : NULL;
  ------------------
  |  Branch (797:30): [True: 264k, False: 77]
  ------------------
  798|   264k|            destItem->len = temp.len;
  799|   264k|        } else {
  800|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  801|      0|            rv = SECFailure;
  802|      0|        }
  803|   264k|    }
  804|       |
  805|   557k|    if (PR_TRUE == pop) {
  ------------------
  |  |  437|   557k|#define PR_TRUE 1
  ------------------
  |  Branch (805:9): [True: 40.6k, False: 516k]
  ------------------
  806|       |        /* we don't want to move ahead, so restore the position */
  807|  40.6k|        *src = mark;
  808|  40.6k|    }
  809|   557k|    return rv;
  810|   557k|}
quickder.c:GetItem:
  115|   917k|{
  116|   917k|    if ((!src) || (!dest) || (!src->data && src->len)) {
  ------------------
  |  Branch (116:9): [True: 0, False: 917k]
  |  Branch (116:19): [True: 0, False: 917k]
  |  Branch (116:31): [True: 10, False: 917k]
  |  Branch (116:45): [True: 0, False: 10]
  ------------------
  117|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  118|      0|        return SECFailure;
  119|      0|    }
  120|       |
  121|   917k|    if (!src->len) {
  ------------------
  |  Branch (121:9): [True: 9.06k, False: 908k]
  ------------------
  122|       |        /* reaching the end of the buffer is not an error */
  123|  9.06k|        dest->data = NULL;
  124|  9.06k|        dest->len = 0;
  125|  9.06k|        return SECSuccess;
  126|  9.06k|    }
  127|       |
  128|   908k|    dest->data = definite_length_decoder(src->data, src->len, &dest->len,
  129|   908k|                                         includeTag);
  130|   908k|    if (dest->data == NULL) {
  ------------------
  |  Branch (130:9): [True: 526, False: 907k]
  ------------------
  131|    526|        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|    526|#define PORT_SetError PORT_SetError_Util
  ------------------
  132|    526|        return SECFailure;
  133|    526|    }
  134|   907k|    src->len -= (int)(dest->data - src->data) + dest->len;
  135|   907k|    src->data = dest->data + dest->len;
  136|   907k|    return SECSuccess;
  137|   908k|}
quickder.c:definite_length_decoder:
   22|   908k|{
   23|   908k|    unsigned char tag;
   24|   908k|    unsigned int used_length = 0;
   25|   908k|    unsigned int data_length = 0;
   26|   908k|    unsigned char length_field_len = 0;
   27|   908k|    unsigned char byte;
   28|   908k|    unsigned int i;
   29|       |
   30|   908k|    if (used_length >= buf_length) {
  ------------------
  |  Branch (30:9): [True: 0, False: 908k]
  ------------------
   31|       |        /* Tag field was not found! */
   32|      0|        return NULL;
   33|      0|    }
   34|   908k|    tag = buf[used_length++];
   35|       |
   36|   908k|    if (tag == 0) {
  ------------------
  |  Branch (36:9): [True: 51, False: 908k]
  ------------------
   37|       |        /* End-of-contents octects should not be present in DER because
   38|       |           DER doesn't use the indefinite length form. */
   39|     51|        return NULL;
   40|     51|    }
   41|       |
   42|   908k|    if ((tag & 0x1F) == 0x1F) {
  ------------------
  |  Branch (42:9): [True: 45, False: 908k]
  ------------------
   43|       |        /* High tag number (a tag number > 30) is not supported */
   44|     45|        return NULL;
   45|     45|    }
   46|       |
   47|   908k|    if (used_length >= buf_length) {
  ------------------
  |  Branch (47:9): [True: 24, False: 908k]
  ------------------
   48|       |        /* Length field was not found! */
   49|     24|        return NULL;
   50|     24|    }
   51|   908k|    byte = buf[used_length++];
   52|       |
   53|   908k|    if (!(byte & 0x80)) {
  ------------------
  |  Branch (53:9): [True: 712k, False: 196k]
  ------------------
   54|       |        /* Short form: The high bit is not set. */
   55|   712k|        data_length = byte; /* clarity; we're returning a 32-bit int. */
   56|   712k|    } else {
   57|       |        /* Long form. Extract the field length */
   58|   196k|        length_field_len = byte & 0x7F;
   59|   196k|        if (length_field_len == 0) {
  ------------------
  |  Branch (59:13): [True: 23, False: 196k]
  ------------------
   60|       |            /* DER doesn't use the indefinite length form. */
   61|     23|            return NULL;
   62|     23|        }
   63|       |
   64|   196k|        if (length_field_len > sizeof(data_length)) {
  ------------------
  |  Branch (64:13): [True: 57, False: 196k]
  ------------------
   65|       |            /* We don't support an extended length field  longer than
   66|       |               4 bytes (2^32) */
   67|     57|            return NULL;
   68|     57|        }
   69|       |
   70|   196k|        if (length_field_len > (buf_length - used_length)) {
  ------------------
  |  Branch (70:13): [True: 7, False: 196k]
  ------------------
   71|       |            /* Extended length field was not found */
   72|      7|            return NULL;
   73|      7|        }
   74|       |
   75|       |        /* Iterate across the extended length field */
   76|   514k|        for (i = 0; i < length_field_len; i++) {
  ------------------
  |  Branch (76:21): [True: 318k, False: 196k]
  ------------------
   77|   318k|            byte = buf[used_length++];
   78|   318k|            data_length = (data_length << 8) | byte;
   79|       |
   80|   318k|            if (i == 0) {
  ------------------
  |  Branch (80:17): [True: 196k, False: 122k]
  ------------------
   81|   196k|                PRBool too_long = PR_FALSE;
  ------------------
  |  |  438|   196k|#define PR_FALSE 0
  ------------------
   82|   196k|                if (length_field_len == 1) {
  ------------------
  |  Branch (82:21): [True: 73.8k, False: 122k]
  ------------------
   83|  73.8k|                    too_long = ((byte & 0x80) == 0); /* Short form suffices */
   84|   122k|                } else {
   85|   122k|                    too_long = (byte == 0); /* This zero byte can be omitted */
   86|   122k|                }
   87|   196k|                if (too_long) {
  ------------------
  |  Branch (87:21): [True: 19, False: 196k]
  ------------------
   88|       |                    /* The length is longer than needed. */
   89|     19|                    return NULL;
   90|     19|                }
   91|   196k|            }
   92|   318k|        }
   93|   196k|    }
   94|       |
   95|   908k|    if ((tag & SEC_ASN1_TAGNUM_MASK) == SEC_ASN1_NULL && data_length != 0) {
  ------------------
  |  |   76|   908k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
                  if ((tag & SEC_ASN1_TAGNUM_MASK) == SEC_ASN1_NULL && data_length != 0) {
  ------------------
  |  |   81|  1.81M|#define SEC_ASN1_NULL 0x05
  ------------------
  |  Branch (95:9): [True: 26.2k, False: 881k]
  |  Branch (95:58): [True: 29, False: 26.2k]
  ------------------
   96|       |        /* The DER encoding of NULL has no contents octets */
   97|     29|        return NULL;
   98|     29|    }
   99|       |
  100|   908k|    if (data_length > (buf_length - used_length)) {
  ------------------
  |  Branch (100:9): [True: 271, False: 907k]
  ------------------
  101|       |        /* The decoded length exceeds the available buffer */
  102|    271|        return NULL;
  103|    271|    }
  104|       |
  105|   907k|    if (includeTag) {
  ------------------
  |  Branch (105:9): [True: 576k, False: 331k]
  ------------------
  106|   576k|        data_length += used_length;
  107|   576k|    }
  108|       |
  109|   907k|    *out_data_length = data_length;
  110|   907k|    return ((unsigned char*)buf + (includeTag ? 0 : used_length));
  ------------------
  |  Branch (110:36): [True: 576k, False: 331k]
  ------------------
  111|   908k|}
quickder.c:MatchComponentType:
  144|   564k|{
  145|   564k|    unsigned long kind = 0;
  146|   564k|    unsigned char tag = 0;
  147|       |
  148|   564k|    if ((!item) || (!item->data && item->len) || (!templateEntry) || (!match)) {
  ------------------
  |  Branch (148:9): [True: 0, False: 564k]
  |  Branch (148:21): [True: 8.81k, False: 555k]
  |  Branch (148:36): [True: 0, False: 8.81k]
  |  Branch (148:50): [True: 0, False: 564k]
  |  Branch (148:70): [True: 0, False: 564k]
  ------------------
  149|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  150|      0|        return SECFailure;
  151|      0|    }
  152|       |
  153|   564k|    if (!item->len) {
  ------------------
  |  Branch (153:9): [True: 8.81k, False: 555k]
  ------------------
  154|  8.81k|        *match = PR_FALSE;
  ------------------
  |  |  438|  8.81k|#define PR_FALSE 0
  ------------------
  155|  8.81k|        return SECSuccess;
  156|  8.81k|    }
  157|       |
  158|   555k|    kind = templateEntry->kind;
  159|   555k|    tag = *(unsigned char*)item->data;
  160|       |
  161|   555k|    if (((kind & SEC_ASN1_INLINE) ||
  ------------------
  |  |  134|   555k|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (161:10): [True: 59.4k, False: 496k]
  ------------------
  162|   555k|         (kind & SEC_ASN1_POINTER)) &&
  ------------------
  |  |  135|   496k|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (162:10): [True: 0, False: 496k]
  ------------------
  163|   555k|        (0 == (kind & SEC_ASN1_TAG_MASK))) {
  ------------------
  |  |   65|  59.4k|#define SEC_ASN1_TAG_MASK 0xff
  ------------------
  |  Branch (163:9): [True: 59.4k, False: 0]
  ------------------
  164|       |        /* These cases are special because the template's "kind" does not
  165|       |           give us the information for the ASN.1 tag of the next item. It can
  166|       |           only be figured out from the subtemplate. */
  167|  59.4k|        if (!(kind & SEC_ASN1_OPTIONAL)) {
  ------------------
  |  |  131|  59.4k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  |  Branch (167:13): [True: 59.4k, False: 0]
  ------------------
  168|       |            /* This is a required component. If there is a type mismatch,
  169|       |               the decoding of the subtemplate will fail, so assume this
  170|       |               is a match at the parent level and let it fail later. This
  171|       |               avoids a redundant check in matching cases */
  172|  59.4k|            *match = PR_TRUE;
  ------------------
  |  |  437|  59.4k|#define PR_TRUE 1
  ------------------
  173|  59.4k|            return SECSuccess;
  174|  59.4k|        } else {
  175|       |            /* optional component. This is the hard case. Now we need to
  176|       |               look at the subtemplate to get the expected kind */
  177|      0|            const SEC_ASN1Template* subTemplate =
  178|      0|                SEC_ASN1GetSubtemplate(templateEntry, dest, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  179|      0|            if (!subTemplate) {
  ------------------
  |  Branch (179:17): [True: 0, False: 0]
  ------------------
  180|      0|                PORT_SetError(SEC_ERROR_BAD_TEMPLATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  181|      0|                return SECFailure;
  182|      0|            }
  183|      0|            if ((subTemplate->kind & SEC_ASN1_INLINE) ||
  ------------------
  |  |  134|      0|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (183:17): [True: 0, False: 0]
  ------------------
  184|      0|                (subTemplate->kind & SEC_ASN1_POINTER)) {
  ------------------
  |  |  135|      0|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (184:17): [True: 0, False: 0]
  ------------------
  185|       |                /* disallow nesting SEC_ASN1_POINTER and SEC_ASN1_INLINE,
  186|       |                   otherwise you may get a false positive due to the recursion
  187|       |                   optimization above that always matches the type if the
  188|       |                   component is required . Nesting these should never be
  189|       |                   required, so that no one should miss this ability */
  190|      0|                PORT_SetError(SEC_ERROR_BAD_TEMPLATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  191|      0|                return SECFailure;
  192|      0|            }
  193|      0|            return MatchComponentType(subTemplate, item, match,
  194|      0|                                      (void*)((char*)dest + templateEntry->offset));
  195|      0|        }
  196|  59.4k|    }
  197|       |
  198|   496k|    if (kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|   496k|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (198:9): [True: 7.93k, False: 488k]
  ------------------
  199|       |        /* we need to check the component's tag against each choice's tag */
  200|       |        /* XXX it would be nice to save the index of the choice here so that
  201|       |           DecodeChoice wouldn't have to do this again. However, due to the
  202|       |           recursivity of MatchComponentType, we don't know if we are in a
  203|       |           required or optional component, so we can't write anywhere in
  204|       |           the destination within this function */
  205|  7.93k|        unsigned choiceIndex = 1;
  206|  7.93k|        const SEC_ASN1Template* choiceEntry;
  207|  8.03k|        while ((choiceEntry = &templateEntry[choiceIndex++]) && (choiceEntry->kind)) {
  ------------------
  |  Branch (207:16): [True: 8.03k, False: 0]
  |  Branch (207:65): [True: 8.03k, False: 4]
  ------------------
  208|  8.03k|            if ((SECSuccess == MatchComponentType(choiceEntry, item, match,
  ------------------
  |  Branch (208:17): [True: 8.03k, False: 0]
  ------------------
  209|  8.03k|                                                  (void*)((char*)dest + choiceEntry->offset))) &&
  210|  8.03k|                (PR_TRUE == *match)) {
  ------------------
  |  |  437|  8.03k|#define PR_TRUE 1
  ------------------
  |  Branch (210:17): [True: 7.93k, False: 102]
  ------------------
  211|  7.93k|                return SECSuccess;
  212|  7.93k|            }
  213|  8.03k|        }
  214|       |        /* no match, caller must decide if this is BAD DER, or not. */
  215|      4|        *match = PR_FALSE;
  ------------------
  |  |  438|      4|#define PR_FALSE 0
  ------------------
  216|      4|        return SECSuccess;
  217|  7.93k|    }
  218|       |
  219|   488k|    if (kind & SEC_ASN1_ANY) {
  ------------------
  |  |  133|   488k|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (219:9): [True: 77.0k, False: 411k]
  ------------------
  220|       |        /* SEC_ASN1_ANY always matches */
  221|  77.0k|        *match = PR_TRUE;
  ------------------
  |  |  437|  77.0k|#define PR_TRUE 1
  ------------------
  222|  77.0k|        return SECSuccess;
  223|  77.0k|    }
  224|       |
  225|   411k|    if ((0 == ((unsigned char)kind & SEC_ASN1_TAGNUM_MASK)) &&
  ------------------
  |  |   76|   411k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (225:9): [True: 74.8k, False: 336k]
  ------------------
  226|   411k|        (!(kind & SEC_ASN1_EXPLICIT)) &&
  ------------------
  |  |  132|  74.8k|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
  |  Branch (226:9): [True: 51.2k, False: 23.6k]
  ------------------
  227|   411k|        (((kind & SEC_ASN1_SAVE) ||
  ------------------
  |  |  144|  51.2k|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  ------------------
  |  Branch (227:11): [True: 15.9k, False: 35.2k]
  ------------------
  228|  51.2k|          (kind & SEC_ASN1_SKIP)) &&
  ------------------
  |  |  140|  35.2k|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (228:11): [True: 35.1k, False: 183]
  ------------------
  229|  51.2k|         (!(kind & SEC_ASN1_OPTIONAL)))) {
  ------------------
  |  |  131|  51.0k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  |  Branch (229:10): [True: 51.0k, False: 0]
  ------------------
  230|       |        /* when saving or skipping a required component,  a type is not
  231|       |           required in the template. This is for legacy support of
  232|       |           SEC_ASN1_SAVE and SEC_ASN1_SKIP only. XXX I would like to
  233|       |           deprecate these usages and always require a type, as this
  234|       |           disables type checking, and effectively forbids us from
  235|       |           transparently ignoring optional components we aren't aware of */
  236|  51.0k|        *match = PR_TRUE;
  ------------------
  |  |  437|  51.0k|#define PR_TRUE 1
  ------------------
  237|  51.0k|        return SECSuccess;
  238|  51.0k|    }
  239|       |
  240|       |    /* first, do a class check */
  241|   360k|    if ((tag & SEC_ASN1_CLASS_MASK) !=
  ------------------
  |  |  119|   360k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
  |  Branch (241:9): [True: 3.24k, False: 356k]
  ------------------
  242|   360k|        (((unsigned char)kind) & SEC_ASN1_CLASS_MASK)) {
  ------------------
  |  |  119|   360k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
  243|       |        /* this is only to help debugging of the decoder in case of problems */
  244|       |        /* unsigned char tagclass = tag & SEC_ASN1_CLASS_MASK; */
  245|       |        /* unsigned char expectedclass = (unsigned char)kind & SEC_ASN1_CLASS_MASK; */
  246|  3.24k|        *match = PR_FALSE;
  ------------------
  |  |  438|  3.24k|#define PR_FALSE 0
  ------------------
  247|  3.24k|        return SECSuccess;
  248|  3.24k|    }
  249|       |
  250|       |    /* now do a tag check */
  251|   356k|    if (((unsigned char)kind & SEC_ASN1_TAGNUM_MASK) !=
  ------------------
  |  |   76|   356k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (251:9): [True: 17.4k, False: 339k]
  ------------------
  252|   356k|        (tag & SEC_ASN1_TAGNUM_MASK)) {
  ------------------
  |  |   76|   356k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  253|  17.4k|        *match = PR_FALSE;
  ------------------
  |  |  438|  17.4k|#define PR_FALSE 0
  ------------------
  254|  17.4k|        return SECSuccess;
  255|  17.4k|    }
  256|       |
  257|       |    /* now, do a method check. This depends on the class */
  258|   339k|    switch (tag & SEC_ASN1_CLASS_MASK) {
  ------------------
  |  |  119|   339k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
  259|   311k|        case SEC_ASN1_UNIVERSAL:
  ------------------
  |  |  120|   311k|#define SEC_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (259:9): [True: 311k, False: 27.4k]
  ------------------
  260|       |            /* For types of the SEC_ASN1_UNIVERSAL class, we know which must be
  261|       |               primitive or constructed based on the tag */
  262|   311k|            switch (tag & SEC_ASN1_TAGNUM_MASK) {
  ------------------
  |  |   76|   311k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  263|   122k|                case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|   122k|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (263:17): [True: 122k, False: 189k]
  ------------------
  264|   132k|                case SEC_ASN1_SET:
  ------------------
  |  |   93|   132k|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (264:17): [True: 10.2k, False: 301k]
  ------------------
  265|   132k|                case SEC_ASN1_EMBEDDED_PDV:
  ------------------
  |  |   87|   132k|#define SEC_ASN1_EMBEDDED_PDV 0x0b
  ------------------
  |  Branch (265:17): [True: 0, False: 311k]
  ------------------
  266|       |                    /* this component must be a constructed type */
  267|       |                    /* XXX add any new universal constructed type here */
  268|   132k|                    if (tag & SEC_ASN1_CONSTRUCTED) {
  ------------------
  |  |  117|   132k|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  |  Branch (268:25): [True: 132k, False: 13]
  ------------------
  269|   132k|                        *match = PR_TRUE;
  ------------------
  |  |  437|   132k|#define PR_TRUE 1
  ------------------
  270|   132k|                        return SECSuccess;
  271|   132k|                    }
  272|     13|                    break;
  273|       |
  274|   179k|                default:
  ------------------
  |  Branch (274:17): [True: 179k, False: 132k]
  ------------------
  275|       |                    /* this component must be a primitive type */
  276|   179k|                    if (!(tag & SEC_ASN1_CONSTRUCTED)) {
  ------------------
  |  |  117|   179k|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  |  Branch (276:25): [True: 179k, False: 7]
  ------------------
  277|   179k|                        *match = PR_TRUE;
  ------------------
  |  |  437|   179k|#define PR_TRUE 1
  ------------------
  278|   179k|                        return SECSuccess;
  279|   179k|                    }
  280|      7|                    break;
  281|   311k|            }
  282|     20|            break;
  283|       |
  284|  27.4k|        default:
  ------------------
  |  Branch (284:9): [True: 27.4k, False: 311k]
  ------------------
  285|       |            /* for all other classes, we check the method based on the template */
  286|  27.4k|            if ((unsigned char)(kind & SEC_ASN1_METHOD_MASK) ==
  ------------------
  |  |  115|  27.4k|#define SEC_ASN1_METHOD_MASK 0x20
  ------------------
  |  Branch (286:17): [True: 27.4k, False: 12]
  ------------------
  287|  27.4k|                (tag & SEC_ASN1_METHOD_MASK)) {
  ------------------
  |  |  115|  27.4k|#define SEC_ASN1_METHOD_MASK 0x20
  ------------------
  288|  27.4k|                *match = PR_TRUE;
  ------------------
  |  |  437|  27.4k|#define PR_TRUE 1
  ------------------
  289|  27.4k|                return SECSuccess;
  290|  27.4k|            }
  291|       |            /* method does not match between template and component */
  292|     12|            break;
  293|   339k|    }
  294|       |
  295|     32|    *match = PR_FALSE;
  ------------------
  |  |  438|     32|#define PR_FALSE 0
  ------------------
  296|     32|    return SECSuccess;
  297|   339k|}
quickder.c:DecodeInline:
  402|  86.8k|{
  403|  86.8k|    const SEC_ASN1Template* inlineTemplate =
  404|  86.8k|        SEC_ASN1GetSubtemplate(templateEntry, dest, PR_FALSE);
  ------------------
  |  |  438|  86.8k|#define PR_FALSE 0
  ------------------
  405|  86.8k|    return DecodeItem((void*)((char*)dest + templateEntry->offset),
  406|  86.8k|                      inlineTemplate, src, arena, checkTag);
  407|  86.8k|}
quickder.c:DecodeExplicit:
  568|  27.1k|{
  569|  27.1k|    SECStatus rv = SECSuccess;
  570|  27.1k|    SECItem subItem;
  571|  27.1k|    SECItem constructed = *src;
  572|       |
  573|  27.1k|    rv = GetItem(&constructed, &subItem, PR_FALSE);
  ------------------
  |  |  438|  27.1k|#define PR_FALSE 0
  ------------------
  574|       |
  575|  27.1k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (575:9): [True: 27.1k, False: 0]
  ------------------
  576|  27.1k|        if (templateEntry->kind & SEC_ASN1_POINTER) {
  ------------------
  |  |  135|  27.1k|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (576:13): [True: 0, False: 27.1k]
  ------------------
  577|      0|            rv = DecodePointer(dest, templateEntry, &subItem, arena, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  578|  27.1k|        } else {
  579|  27.1k|            rv = DecodeInline(dest, templateEntry, &subItem, arena, PR_TRUE);
  ------------------
  |  |  437|  27.1k|#define PR_TRUE 1
  ------------------
  580|  27.1k|        }
  581|  27.1k|    }
  582|       |
  583|  27.1k|    return rv;
  584|  27.1k|}
quickder.c:DecodeImplicit:
  434|    252|{
  435|    252|    if (templateEntry->kind & SEC_ASN1_POINTER) {
  ------------------
  |  |  135|    252|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (435:9): [True: 0, False: 252]
  ------------------
  436|      0|        return DecodePointer((void*)((char*)dest),
  437|      0|                             templateEntry, src, arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  438|    252|    } else {
  439|    252|        return DecodeInline((void*)((char*)dest),
  440|    252|                            templateEntry, src, arena, PR_FALSE);
  ------------------
  |  |  438|    252|#define PR_FALSE 0
  ------------------
  441|    252|    }
  442|    252|}
quickder.c:DecodeChoice:
  448|  7.93k|{
  449|  7.93k|    SECStatus rv = SECSuccess;
  450|  7.93k|    SECItem choice;
  451|  7.93k|    const SEC_ASN1Template* choiceTemplate = &(templateEntry[1]);
  452|  7.93k|    const SEC_ASN1Template* choiceEntry = NULL;
  453|  7.93k|    unsigned long choiceindex = 0;
  454|       |
  455|       |    /* XXX for a choice component, we should validate the template to make
  456|       |       sure the tags are distinct, in debug builds. This hasn't been
  457|       |       implemented yet */
  458|       |    /* rv = CheckChoiceTemplate(sequenceTemplate); */
  459|       |
  460|       |    /* process it */
  461|  8.02k|    do {
  462|  8.02k|        choice = *src;
  463|  8.02k|        choiceEntry = &choiceTemplate[choiceindex++];
  464|  8.02k|        if (choiceEntry->kind) {
  ------------------
  |  Branch (464:13): [True: 8.02k, False: 3]
  ------------------
  465|  8.02k|            rv = DecodeItem(dest, choiceEntry, &choice, arena, PR_TRUE);
  ------------------
  |  |  437|  8.02k|#define PR_TRUE 1
  ------------------
  466|  8.02k|        }
  467|  8.02k|    } while ((SECFailure == rv) && (choiceEntry->kind));
  ------------------
  |  Branch (467:14): [True: 102, False: 7.92k]
  |  Branch (467:36): [True: 99, False: 3]
  ------------------
  468|       |
  469|  7.93k|    if (SECFailure == rv) {
  ------------------
  |  Branch (469:9): [True: 3, False: 7.92k]
  ------------------
  470|       |        /* the component didn't match any of the choices */
  471|      3|        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      3|#define PORT_SetError PORT_SetError_Util
  ------------------
  472|  7.92k|    } else {
  473|       |        /* set the type in the union here */
  474|  7.92k|        int* which = (int*)((char*)dest + templateEntry->offset);
  475|  7.92k|        *which = (int)choiceEntry->size;
  476|  7.92k|    }
  477|       |
  478|       |    /* we should have consumed all the bytes by now */
  479|       |    /* fail if we have not */
  480|  7.93k|    if (SECSuccess == rv && choice.len) {
  ------------------
  |  Branch (480:9): [True: 7.92k, False: 3]
  |  Branch (480:29): [True: 0, False: 7.92k]
  ------------------
  481|       |        /* there is extra data that isn't listed in the template */
  482|      0|        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  483|      0|        rv = SECFailure;
  484|      0|    }
  485|  7.93k|    return rv;
  486|  7.93k|}
quickder.c:DecodeGroup:
  492|  22.2k|{
  493|  22.2k|    SECStatus rv = SECSuccess;
  494|  22.2k|    SECItem source;
  495|  22.2k|    SECItem group;
  496|  22.2k|    PRUint32 totalEntries = 0;
  497|  22.2k|    PRUint32 entryIndex = 0;
  498|  22.2k|    void** entries = NULL;
  499|       |
  500|  22.2k|    const SEC_ASN1Template* subTemplate =
  501|  22.2k|        SEC_ASN1GetSubtemplate(templateEntry, dest, PR_FALSE);
  ------------------
  |  |  438|  22.2k|#define PR_FALSE 0
  ------------------
  502|       |
  503|  22.2k|    source = *src;
  504|       |
  505|       |    /* get the group */
  506|  22.2k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (506:9): [True: 22.2k, False: 0]
  ------------------
  507|  22.2k|        rv = GetItem(&source, &group, PR_FALSE);
  ------------------
  |  |  438|  22.2k|#define PR_FALSE 0
  ------------------
  508|  22.2k|    }
  509|       |
  510|       |    /* XXX we should check the subtemplate in debug builds */
  511|  22.2k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (511:9): [True: 22.2k, False: 0]
  ------------------
  512|       |        /* first, count the number of entries. Benchmarking showed that this
  513|       |           counting pass is more efficient than trying to allocate entries as
  514|       |           we read the DER, even if allocating many entries at a time
  515|       |        */
  516|  22.2k|        SECItem counter = group;
  517|  29.0k|        do {
  518|  29.0k|            SECItem anitem;
  519|  29.0k|            rv = GetItem(&counter, &anitem, PR_TRUE);
  ------------------
  |  |  437|  29.0k|#define PR_TRUE 1
  ------------------
  520|  29.0k|            if (SECSuccess == rv && (anitem.len)) {
  ------------------
  |  Branch (520:17): [True: 29.0k, False: 47]
  |  Branch (520:37): [True: 28.7k, False: 251]
  ------------------
  521|  28.7k|                totalEntries++;
  522|  28.7k|            }
  523|  29.0k|        } while ((SECSuccess == rv) && (counter.len));
  ------------------
  |  Branch (523:18): [True: 29.0k, False: 47]
  |  Branch (523:40): [True: 6.89k, False: 22.1k]
  ------------------
  524|       |
  525|  22.2k|        if (SECSuccess == rv) {
  ------------------
  |  Branch (525:13): [True: 22.1k, False: 47]
  ------------------
  526|       |            /* allocate room for pointer array and entries */
  527|       |            /* we want to allocate the array even if there is 0 entry */
  528|  22.1k|            entries = (void**)PORT_ArenaZAlloc(arena, sizeof(void*) * (totalEntries + 1) + /* the extra one is for NULL termination */
  ------------------
  |  |   59|  22.1k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  529|  22.1k|                                                          subTemplate->size * totalEntries);
  530|       |
  531|  22.1k|            if (entries) {
  ------------------
  |  Branch (531:17): [True: 22.1k, False: 0]
  ------------------
  532|  22.1k|                entries[totalEntries] = NULL; /* terminate the array */
  533|  22.1k|            } else {
  534|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  535|      0|                rv = SECFailure;
  536|      0|            }
  537|  22.1k|            if (SECSuccess == rv) {
  ------------------
  |  Branch (537:17): [True: 22.1k, False: 0]
  ------------------
  538|  22.1k|                void* entriesData = (unsigned char*)entries + (unsigned long)(sizeof(void*) * (totalEntries + 1));
  539|       |                /* and fix the pointers in the array */
  540|  22.1k|                PRUint32 entriesIndex = 0;
  541|  50.9k|                for (entriesIndex = 0; entriesIndex < totalEntries; entriesIndex++) {
  ------------------
  |  Branch (541:40): [True: 28.7k, False: 22.1k]
  ------------------
  542|  28.7k|                    entries[entriesIndex] =
  543|  28.7k|                        (char*)entriesData + (subTemplate->size * entriesIndex);
  544|  28.7k|                }
  545|  22.1k|            }
  546|  22.1k|        }
  547|  22.2k|    }
  548|       |
  549|  22.2k|    if (SECSuccess == rv && totalEntries)
  ------------------
  |  Branch (549:9): [True: 22.1k, False: 47]
  |  Branch (549:29): [True: 21.9k, False: 251]
  ------------------
  550|  28.4k|        do {
  551|  28.4k|            if (!(entryIndex < totalEntries)) {
  ------------------
  |  Branch (551:17): [True: 0, False: 28.4k]
  ------------------
  552|      0|                rv = SECFailure;
  553|      0|                break;
  554|      0|            }
  555|  28.4k|            rv = DecodeItem(entries[entryIndex++], subTemplate, &group, arena, PR_TRUE);
  ------------------
  |  |  437|  28.4k|#define PR_TRUE 1
  ------------------
  556|  28.4k|        } while ((SECSuccess == rv) && (group.len));
  ------------------
  |  Branch (556:18): [True: 28.3k, False: 64]
  |  Branch (556:40): [True: 6.55k, False: 21.8k]
  ------------------
  557|       |    /* we should be at the end of the set by now */
  558|       |    /* save the entries where requested */
  559|      0|    memcpy(((char*)dest + templateEntry->offset), &entries, sizeof(void**));
  560|       |
  561|  22.2k|    return rv;
  562|  22.2k|}
quickder.c:DecodeSequence:
  353|   110k|{
  354|   110k|    SECStatus rv = SECSuccess;
  355|   110k|    SECItem source;
  356|   110k|    SECItem sequence;
  357|   110k|    const SEC_ASN1Template* sequenceTemplate = &(templateEntry[1]);
  358|   110k|    const SEC_ASN1Template* sequenceEntry = NULL;
  359|   110k|    unsigned long seqindex = 0;
  360|       |
  361|   110k|#ifdef DEBUG
  362|       |    /* for a sequence, we need to validate the template. */
  363|   110k|    rv = CheckSequenceTemplate(sequenceTemplate);
  364|   110k|#endif
  365|       |
  366|   110k|    source = *src;
  367|       |
  368|       |    /* get the sequence */
  369|   110k|    if (SECSuccess == rv) {
  ------------------
  |  Branch (369:9): [True: 110k, False: 0]
  ------------------
  370|   110k|        rv = GetItem(&source, &sequence, PR_FALSE);
  ------------------
  |  |  438|   110k|#define PR_FALSE 0
  ------------------
  371|   110k|    }
  372|       |
  373|       |    /* process it */
  374|   110k|    if (SECSuccess == rv)
  ------------------
  |  Branch (374:9): [True: 110k, False: 0]
  ------------------
  375|   425k|        do {
  376|   425k|            sequenceEntry = &sequenceTemplate[seqindex++];
  377|   425k|            if ((sequenceEntry && sequenceEntry->kind) &&
  ------------------
  |  Branch (377:18): [True: 425k, False: 0]
  |  Branch (377:35): [True: 335k, False: 90.2k]
  ------------------
  378|   425k|                (sequenceEntry->kind != SEC_ASN1_SKIP_REST)) {
  ------------------
  |  |  151|   335k|#define SEC_ASN1_SKIP_REST 0x80000    /* skip all following fields; \
  ------------------
  |  Branch (378:17): [True: 315k, False: 19.6k]
  ------------------
  379|   315k|                rv = DecodeItem(dest, sequenceEntry, &sequence, arena, PR_TRUE);
  ------------------
  |  |  437|   315k|#define PR_TRUE 1
  ------------------
  380|   315k|            }
  381|   425k|        } while ((SECSuccess == rv) &&
  ------------------
  |  Branch (381:18): [True: 424k, False: 566]
  ------------------
  382|   425k|                 (sequenceEntry->kind &&
  ------------------
  |  Branch (382:19): [True: 334k, False: 90.2k]
  ------------------
  383|   424k|                  sequenceEntry->kind != SEC_ASN1_SKIP_REST));
  ------------------
  |  |  151|   334k|#define SEC_ASN1_SKIP_REST 0x80000    /* skip all following fields; \
  ------------------
  |  Branch (383:19): [True: 314k, False: 19.6k]
  ------------------
  384|       |    /* we should have consumed all the bytes in the sequence by now
  385|       |       unless the caller doesn't care about the rest of the sequence */
  386|   110k|    if (SECSuccess == rv && sequence.len &&
  ------------------
  |  Branch (386:9): [True: 109k, False: 566]
  |  Branch (386:29): [True: 19.7k, False: 90.1k]
  ------------------
  387|   110k|        sequenceEntry && sequenceEntry->kind != SEC_ASN1_SKIP_REST) {
  ------------------
  |  |  151|  19.7k|#define SEC_ASN1_SKIP_REST 0x80000    /* skip all following fields; \
  ------------------
  |  Branch (387:9): [True: 19.7k, False: 0]
  |  Branch (387:26): [True: 70, False: 19.6k]
  ------------------
  388|       |        /* it isn't 100% clear whether this is a bad DER or a bad template.
  389|       |           The problem is that logically, they don't match - there is extra
  390|       |           data in the DER that the template doesn't know about */
  391|     70|        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|     70|#define PORT_SetError PORT_SetError_Util
  ------------------
  392|     70|        rv = SECFailure;
  393|     70|    }
  394|       |
  395|   110k|    return rv;
  396|   110k|}
quickder.c:CheckSequenceTemplate:
  303|   110k|{
  304|   110k|    SECStatus rv = SECSuccess;
  305|   110k|    const SEC_ASN1Template* sequenceEntry = NULL;
  306|   110k|    unsigned long seqIndex = 0;
  307|   110k|    unsigned long lastEntryIndex = 0;
  308|   110k|    unsigned long ambiguityIndex = 0;
  309|   110k|    PRBool foundAmbiguity = PR_FALSE;
  ------------------
  |  |  438|   110k|#define PR_FALSE 0
  ------------------
  310|       |
  311|   446k|    do {
  312|   446k|        sequenceEntry = &sequenceTemplate[seqIndex++];
  313|   446k|        if (sequenceEntry->kind) {
  ------------------
  |  Branch (313:13): [True: 336k, False: 110k]
  ------------------
  314|       |            /* ensure that we don't have an optional component of SEC_ASN1_ANY
  315|       |               in the middle of the sequence, since we could not handle it */
  316|       |            /* XXX this function needs to dig into the subtemplates to find
  317|       |               the next tag */
  318|   336k|            if ((PR_FALSE == foundAmbiguity) &&
  ------------------
  |  |  438|   336k|#define PR_FALSE 0
  ------------------
  |  Branch (318:17): [True: 336k, False: 0]
  ------------------
  319|   336k|                (sequenceEntry->kind & SEC_ASN1_OPTIONAL) &&
  ------------------
  |  |  131|   336k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  |  Branch (319:17): [True: 80.0k, False: 256k]
  ------------------
  320|   336k|                (sequenceEntry->kind & SEC_ASN1_ANY)) {
  ------------------
  |  |  133|  80.0k|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (320:17): [True: 31.5k, False: 48.4k]
  ------------------
  321|  31.5k|                foundAmbiguity = PR_TRUE;
  ------------------
  |  |  437|  31.5k|#define PR_TRUE 1
  ------------------
  322|  31.5k|                ambiguityIndex = seqIndex - 1;
  323|  31.5k|            }
  324|   336k|        }
  325|   446k|    } while (sequenceEntry->kind);
  ------------------
  |  Branch (325:14): [True: 336k, False: 110k]
  ------------------
  326|       |
  327|   110k|    lastEntryIndex = seqIndex - 2;
  328|       |
  329|   110k|    if (PR_FALSE != foundAmbiguity) {
  ------------------
  |  |  438|   110k|#define PR_FALSE 0
  ------------------
  |  Branch (329:9): [True: 31.5k, False: 78.8k]
  ------------------
  330|  31.5k|        if (ambiguityIndex < lastEntryIndex) {
  ------------------
  |  Branch (330:13): [True: 0, False: 31.5k]
  ------------------
  331|       |            /* ambiguity can only be tolerated on the last entry */
  332|      0|            PORT_SetError(SEC_ERROR_BAD_TEMPLATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  333|      0|            rv = SECFailure;
  334|      0|        }
  335|  31.5k|    }
  336|       |
  337|       |    /* XXX also enforce ASN.1 requirement that tags be
  338|       |       distinct for consecutive optional components */
  339|       |
  340|   110k|    return rv;
  341|   110k|}

SECOID_GetAlgorithmTag_Util:
   14|  28.1k|{
   15|  28.1k|    if (id == NULL || id->algorithm.data == NULL)
  ------------------
  |  Branch (15:9): [True: 0, False: 28.1k]
  |  Branch (15:23): [True: 0, False: 28.1k]
  ------------------
   16|      0|        return SEC_OID_UNKNOWN;
   17|       |
   18|  28.1k|    return SECOID_FindOIDTag(&(id->algorithm));
  ------------------
  |  |  117|  28.1k|#define SECOID_FindOIDTag SECOID_FindOIDTag_Util
  ------------------
   19|  28.1k|}
SECOID_SetAlgorithmID_Util:
   44|  27.4k|{
   45|  27.4k|    SECOidData *oiddata;
   46|  27.4k|    PRBool add_null_param;
   47|       |
   48|  27.4k|    oiddata = SECOID_FindOIDByTag(which);
  ------------------
  |  |  116|  27.4k|#define SECOID_FindOIDByTag SECOID_FindOIDByTag_Util
  ------------------
   49|  27.4k|    if (!oiddata) {
  ------------------
  |  Branch (49:9): [True: 0, False: 27.4k]
  ------------------
   50|      0|        PORT_SetError(SEC_ERROR_INVALID_ALGORITHM);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   51|      0|        return SECFailure;
   52|      0|    }
   53|       |
   54|  27.4k|    if (SECITEM_CopyItem(arena, &id->algorithm, &oiddata->oid))
  ------------------
  |  |  106|  27.4k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (54:9): [True: 0, False: 27.4k]
  ------------------
   55|      0|        return SECFailure;
   56|       |
   57|  27.4k|    if ((secoid_IsRSAPKCS1(which)) ||
  ------------------
  |  Branch (57:9): [True: 0, False: 27.4k]
  ------------------
   58|  27.4k|        (HASH_GetHashTypeByOidTag(which) != HASH_AlgNULL)) {
  ------------------
  |  |  125|  27.4k|#define HASH_GetHashTypeByOidTag HASH_GetHashTypeByOidTag_Util
  ------------------
  |  Branch (58:9): [True: 27.4k, False: 0]
  ------------------
   59|  27.4k|        add_null_param = PR_TRUE;
  ------------------
  |  |  437|  27.4k|#define PR_TRUE 1
  ------------------
   60|  27.4k|    } else {
   61|      0|        add_null_param = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   62|      0|    }
   63|       |
   64|  27.4k|    if (params) {
  ------------------
  |  Branch (64:9): [True: 27.4k, False: 0]
  ------------------
   65|       |        /*
   66|       |         * I am specifically *not* enforcing the following assertion
   67|       |         * (by following it up with an error and a return of failure)
   68|       |         * because I do not want to introduce any change in the current
   69|       |         * behavior.  But I do want for us to notice if the following is
   70|       |         * ever true, because I do not think it should be so and probably
   71|       |         * signifies an error/bug somewhere.
   72|       |         */
   73|  27.4k|        PORT_Assert(!add_null_param || (params->len == 2 && params->data[0] == SEC_ASN1_NULL && params->data[1] == 0));
  ------------------
  |  |  120|  27.4k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   164k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 27.4k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 27.4k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 27.4k, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 27.4k]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   74|  27.4k|        if (SECITEM_CopyItem(arena, &id->parameters, params)) {
  ------------------
  |  |  106|  27.4k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
  |  Branch (74:13): [True: 0, False: 27.4k]
  ------------------
   75|      0|            return SECFailure;
   76|      0|        }
   77|  27.4k|    } else {
   78|       |        /*
   79|       |         * Again, this is not considered an error.  But if we assume
   80|       |         * that nobody tries to set the parameters field themselves
   81|       |         * (but always uses this routine to do that), then we should
   82|       |         * not hit the following assertion.  Unless they forgot to zero
   83|       |         * the structure, which could also be a bad (and wrong) thing.
   84|       |         */
   85|      0|        PORT_Assert(id->parameters.data == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   86|       |
   87|      0|        if (add_null_param) {
  ------------------
  |  Branch (87:13): [True: 0, False: 0]
  ------------------
   88|      0|            (void)SECITEM_AllocItem(arena, &id->parameters, 2);
  ------------------
  |  |  103|      0|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
   89|      0|            if (id->parameters.data == NULL) {
  ------------------
  |  Branch (89:17): [True: 0, False: 0]
  ------------------
   90|      0|                return SECFailure;
   91|      0|            }
   92|      0|            id->parameters.data[0] = SEC_ASN1_NULL;
  ------------------
  |  |   81|      0|#define SEC_ASN1_NULL 0x05
  ------------------
   93|      0|            id->parameters.data[1] = 0;
   94|      0|        }
   95|      0|    }
   96|       |
   97|  27.4k|    return SECSuccess;
   98|  27.4k|}
secalgid.c:secoid_IsRSAPKCS1:
   23|  27.4k|{
   24|  27.4k|    switch (which) {
   25|      0|        case SEC_OID_PKCS1_RSA_ENCRYPTION:
  ------------------
  |  Branch (25:9): [True: 0, False: 27.4k]
  ------------------
   26|      0|        case SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (26:9): [True: 0, False: 27.4k]
  ------------------
   27|      0|        case SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (27:9): [True: 0, False: 27.4k]
  ------------------
   28|      0|        case SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (28:9): [True: 0, False: 27.4k]
  ------------------
   29|      0|        case SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (29:9): [True: 0, False: 27.4k]
  ------------------
   30|      0|        case SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (30:9): [True: 0, False: 27.4k]
  ------------------
   31|      0|        case SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (31:9): [True: 0, False: 27.4k]
  ------------------
   32|      0|        case SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (32:9): [True: 0, False: 27.4k]
  ------------------
   33|      0|        case SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION:
  ------------------
  |  Branch (33:9): [True: 0, False: 27.4k]
  ------------------
   34|      0|            return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
   35|  27.4k|        default:
  ------------------
  |  Branch (35:9): [True: 27.4k, False: 0]
  ------------------
   36|  27.4k|            break;
   37|  27.4k|    }
   38|  27.4k|    return PR_FALSE;
  ------------------
  |  |  438|  27.4k|#define PR_FALSE 0
  ------------------
   39|  27.4k|}

SEC_ASN1DecoderUpdate_Util:
 2771|      2|{
 2772|      2|    sec_asn1d_state *state = NULL;
 2773|      2|    unsigned long consumed;
 2774|      2|    SEC_ASN1EncodingPart what;
 2775|       |
 2776|      2|    if (cx->status == needBytes)
  ------------------
  |  Branch (2776:9): [True: 2, False: 0]
  ------------------
 2777|      2|        cx->status = keepGoing;
 2778|       |
 2779|     93|    while (cx->status == keepGoing) {
  ------------------
  |  Branch (2779:12): [True: 93, False: 0]
  ------------------
 2780|     93|        state = cx->current;
 2781|     93|        what = SEC_ASN1_Contents;
 2782|     93|        consumed = 0;
 2783|       |#ifdef DEBUG_ASN1D_STATES
 2784|       |        printf("\nPLACE = %s, next byte = 0x%02x, %p[%lu]\n",
 2785|       |               (state->place >= 0 && state->place <= notInUse) ? place_names[state->place] : "(undefined)",
 2786|       |               len ? (unsigned int)((unsigned char *)buf)[consumed] : 0,
 2787|       |               buf, consumed);
 2788|       |        dump_states(cx);
 2789|       |#endif /* DEBUG_ASN1D_STATES */
 2790|     93|        switch (state->place) {
 2791|     12|            case beforeIdentifier:
  ------------------
  |  Branch (2791:13): [True: 12, False: 81]
  ------------------
 2792|     12|                consumed = sec_asn1d_parse_identifier(state, buf, len);
 2793|     12|                what = SEC_ASN1_Identifier;
 2794|     12|                break;
 2795|      0|            case duringIdentifier:
  ------------------
  |  Branch (2795:13): [True: 0, False: 93]
  ------------------
 2796|      0|                consumed = sec_asn1d_parse_more_identifier(state, buf, len);
 2797|      0|                what = SEC_ASN1_Identifier;
 2798|      0|                break;
 2799|     12|            case afterIdentifier:
  ------------------
  |  Branch (2799:13): [True: 12, False: 81]
  ------------------
 2800|     12|                sec_asn1d_confirm_identifier(state);
 2801|     12|                break;
 2802|     12|            case beforeLength:
  ------------------
  |  Branch (2802:13): [True: 12, False: 81]
  ------------------
 2803|     12|                consumed = sec_asn1d_parse_length(state, buf, len);
 2804|     12|                what = SEC_ASN1_Length;
 2805|     12|                break;
 2806|      3|            case duringLength:
  ------------------
  |  Branch (2806:13): [True: 3, False: 90]
  ------------------
 2807|      3|                consumed = sec_asn1d_parse_more_length(state, buf, len);
 2808|      3|                what = SEC_ASN1_Length;
 2809|      3|                break;
 2810|     12|            case afterLength:
  ------------------
  |  Branch (2810:13): [True: 12, False: 81]
  ------------------
 2811|     12|                sec_asn1d_prepare_for_contents(state);
 2812|     12|                break;
 2813|      0|            case beforeBitString:
  ------------------
  |  Branch (2813:13): [True: 0, False: 93]
  ------------------
 2814|      0|                consumed = sec_asn1d_parse_bit_string(state, buf, len);
 2815|      0|                break;
 2816|      0|            case duringBitString:
  ------------------
  |  Branch (2816:13): [True: 0, False: 93]
  ------------------
 2817|      0|                consumed = sec_asn1d_parse_more_bit_string(state, buf, len);
 2818|      0|                break;
 2819|      0|            case duringConstructedString:
  ------------------
  |  Branch (2819:13): [True: 0, False: 93]
  ------------------
 2820|      0|                sec_asn1d_next_substring(state);
 2821|      0|                break;
 2822|      0|            case duringGroup:
  ------------------
  |  Branch (2822:13): [True: 0, False: 93]
  ------------------
 2823|      0|                sec_asn1d_next_in_group(state);
 2824|      0|                break;
 2825|      7|            case duringLeaf:
  ------------------
  |  Branch (2825:13): [True: 7, False: 86]
  ------------------
 2826|      7|                consumed = sec_asn1d_parse_leaf(state, buf, len);
 2827|      7|                break;
 2828|      0|            case duringSaveEncoding:
  ------------------
  |  Branch (2828:13): [True: 0, False: 93]
  ------------------
 2829|      0|                sec_asn1d_reuse_encoding(state);
 2830|      0|                if (cx->status == decodeError) {
  ------------------
  |  Branch (2830:21): [True: 0, False: 0]
  ------------------
 2831|       |                    /* recursive call has already popped all states from stack.
 2832|       |                    ** Bail out quickly.
 2833|       |                    */
 2834|      0|                    return SECFailure;
 2835|      0|                }
 2836|      0|                if (cx->status == needBytes) {
  ------------------
  |  Branch (2836:21): [True: 0, False: 0]
  ------------------
 2837|       |                    /* recursive call wanted more data. Fatal. Clean up below. */
 2838|      0|                    PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2839|      0|                    cx->status = decodeError;
 2840|      0|                }
 2841|      0|                break;
 2842|     10|            case duringSequence:
  ------------------
  |  Branch (2842:13): [True: 10, False: 83]
  ------------------
 2843|     10|                sec_asn1d_next_in_sequence(state);
 2844|     10|                break;
 2845|      0|            case afterConstructedString:
  ------------------
  |  Branch (2845:13): [True: 0, False: 93]
  ------------------
 2846|      0|                sec_asn1d_concat_substrings(state);
 2847|      0|                break;
 2848|      0|            case afterExplicit:
  ------------------
  |  Branch (2848:13): [True: 0, False: 93]
  ------------------
 2849|      0|            case afterImplicit:
  ------------------
  |  Branch (2849:13): [True: 0, False: 93]
  ------------------
 2850|      2|            case afterInline:
  ------------------
  |  Branch (2850:13): [True: 2, False: 91]
  ------------------
 2851|      2|            case afterPointer:
  ------------------
  |  Branch (2851:13): [True: 0, False: 93]
  ------------------
 2852|      2|                sec_asn1d_absorb_child(state);
 2853|      2|                break;
 2854|      0|            case afterGroup:
  ------------------
  |  Branch (2854:13): [True: 0, False: 93]
  ------------------
 2855|      0|                sec_asn1d_concat_group(state);
 2856|      0|                break;
 2857|      0|            case afterSaveEncoding:
  ------------------
  |  Branch (2857:13): [True: 0, False: 93]
  ------------------
 2858|       |                /* SEC_ASN1DecoderUpdate has called itself recursively to
 2859|       |                ** decode SAVEd encoded data, and now is done decoding that.
 2860|       |                ** Return to the calling copy of SEC_ASN1DecoderUpdate.
 2861|       |                */
 2862|      0|                return SECSuccess;
 2863|      9|            case beforeEndOfContents:
  ------------------
  |  Branch (2863:13): [True: 9, False: 84]
  ------------------
 2864|      9|                sec_asn1d_prepare_for_end_of_contents(state);
 2865|      9|                break;
 2866|      0|            case duringEndOfContents:
  ------------------
  |  Branch (2866:13): [True: 0, False: 93]
  ------------------
 2867|      0|                consumed = sec_asn1d_parse_end_of_contents(state, buf, len);
 2868|      0|                what = SEC_ASN1_EndOfContents;
 2869|      0|                break;
 2870|     14|            case afterEndOfContents:
  ------------------
  |  Branch (2870:13): [True: 14, False: 79]
  ------------------
 2871|     14|                sec_asn1d_pop_state(state);
 2872|     14|                break;
 2873|      0|            case beforeChoice:
  ------------------
  |  Branch (2873:13): [True: 0, False: 93]
  ------------------
 2874|      0|                state = sec_asn1d_before_choice(state);
 2875|      0|                break;
 2876|      0|            case duringChoice:
  ------------------
  |  Branch (2876:13): [True: 0, False: 93]
  ------------------
 2877|      0|                state = sec_asn1d_during_choice(state);
 2878|      0|                break;
 2879|      0|            case afterChoice:
  ------------------
  |  Branch (2879:13): [True: 0, False: 93]
  ------------------
 2880|      0|                sec_asn1d_after_choice(state);
 2881|      0|                break;
 2882|      0|            case notInUse:
  ------------------
  |  Branch (2882:13): [True: 0, False: 93]
  ------------------
 2883|      0|            default:
  ------------------
  |  Branch (2883:13): [True: 0, False: 93]
  ------------------
 2884|       |                /* This is not an error, but rather a plain old BUG! */
 2885|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2886|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2887|      0|                cx->status = decodeError;
 2888|      0|                break;
 2889|     93|        }
 2890|       |
 2891|     93|        if (cx->status == decodeError)
  ------------------
  |  Branch (2891:13): [True: 0, False: 93]
  ------------------
 2892|      0|            break;
 2893|       |
 2894|       |        /* We should not consume more than we have.  */
 2895|     93|        PORT_Assert(consumed <= len);
  ------------------
  |  |  120|     93|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     93|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 93, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2896|     93|        if (consumed > len) {
  ------------------
  |  Branch (2896:13): [True: 0, False: 93]
  ------------------
 2897|      0|            PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2898|      0|            cx->status = decodeError;
 2899|      0|            break;
 2900|      0|        }
 2901|       |
 2902|       |        /* It might have changed, so we have to update our local copy.  */
 2903|     93|        state = cx->current;
 2904|       |
 2905|       |        /* If it is NULL, we have popped all the way to the top.  */
 2906|     93|        if (state == NULL) {
  ------------------
  |  Branch (2906:13): [True: 2, False: 91]
  ------------------
 2907|      2|            PORT_Assert(consumed == 0);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2908|       |#if 0 /* XXX I want this here, but it seems that we have situations (like \
 2909|       |       * downloading a pkcs7 cert chain from some issuers) that give us a \
 2910|       |       * length which is greater than the entire encoding.  So, we cannot \
 2911|       |       * have this be an error.                                           \
 2912|       |       */
 2913|       |        if (len > 0) {
 2914|       |        PORT_SetError (SEC_ERROR_BAD_DER);
 2915|       |        cx->status = decodeError;
 2916|       |        } else
 2917|       |#endif
 2918|      2|            cx->status = allDone;
 2919|      2|            break;
 2920|     91|        } else if (state->theTemplate->kind == SEC_ASN1_SKIP_REST) {
  ------------------
  |  |  151|     91|#define SEC_ASN1_SKIP_REST 0x80000    /* skip all following fields; \
  ------------------
  |  Branch (2920:20): [True: 0, False: 91]
  ------------------
 2921|      0|            cx->status = allDone;
 2922|      0|            break;
 2923|      0|        }
 2924|       |
 2925|     91|        if (consumed == 0)
  ------------------
  |  Branch (2925:13): [True: 57, False: 34]
  ------------------
 2926|     57|            continue;
 2927|       |
 2928|       |        /*
 2929|       |         * The following check is specifically looking for an ANY
 2930|       |         * that is *not* also an INNER, because we need to save aside
 2931|       |         * all bytes in that case -- the contents parts will get
 2932|       |         * handled like all other contents, and the end-of-contents
 2933|       |         * bytes are added by the concat code, but the outer header
 2934|       |         * bytes need to get saved too, so we do them explicitly here.
 2935|       |         */
 2936|     34|        if (state->underlying_kind == SEC_ASN1_ANY && !cx->filter_only && (what == SEC_ASN1_Identifier || what == SEC_ASN1_Length)) {
  ------------------
  |  |  133|     68|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (2936:13): [True: 5, False: 29]
  |  Branch (2936:55): [True: 5, False: 0]
  |  Branch (2936:76): [True: 2, False: 3]
  |  Branch (2936:107): [True: 2, False: 1]
  ------------------
 2937|      4|            sec_asn1d_record_any_header(state, buf, consumed);
 2938|      4|        }
 2939|       |
 2940|       |        /*
 2941|       |         * We had some number of good, accepted bytes.  If the caller
 2942|       |         * has registered to see them, pass them along.
 2943|       |         */
 2944|     34|        if (state->top->filter_proc != NULL) {
  ------------------
  |  Branch (2944:13): [True: 0, False: 34]
  ------------------
 2945|      0|            int depth;
 2946|       |
 2947|      0|            depth = state->depth;
 2948|      0|            if (what == SEC_ASN1_EndOfContents && !state->indefinite) {
  ------------------
  |  Branch (2948:17): [True: 0, False: 0]
  |  Branch (2948:51): [True: 0, False: 0]
  ------------------
 2949|      0|                PORT_Assert(state->parent != NULL && state->parent->indefinite);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2950|      0|                depth--;
 2951|      0|                PORT_Assert(depth == state->parent->depth);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2952|      0|            }
 2953|      0|            (*state->top->filter_proc)(state->top->filter_arg,
 2954|      0|                                       buf, consumed, depth, what);
 2955|      0|        }
 2956|       |
 2957|     34|        state->consumed += consumed;
 2958|     34|        buf += consumed;
 2959|     34|        len -= consumed;
 2960|     34|    }
 2961|       |
 2962|      2|    if (cx->status == decodeError) {
  ------------------
  |  Branch (2962:9): [True: 0, False: 2]
  ------------------
 2963|      0|        while (state != NULL) {
  ------------------
  |  Branch (2963:16): [True: 0, False: 0]
  ------------------
 2964|      0|            sec_asn1d_free_child(state, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 2965|      0|            state = state->parent;
 2966|      0|        }
 2967|       |#ifdef SEC_ASN1D_FREE_ON_ERROR /*                                           \
 2968|       |                                * XXX This does not work because we can     \
 2969|       |                                * end up leaving behind dangling pointers   \
 2970|       |                                * to stuff that was allocated.  In order    \
 2971|       |                                * to make this really work (which would     \
 2972|       |                                * be a good thing, I think), we need to     \
 2973|       |                                * keep track of every place/pointer that    \
 2974|       |                                * was allocated and make sure to NULL it    \
 2975|       |                                * out before we then free back to the mark. \
 2976|       |                                */
 2977|       |        if (cx->their_pool != NULL) {
 2978|       |            PORT_Assert(cx->their_mark != NULL);
 2979|       |            PORT_ArenaRelease(cx->their_pool, cx->their_mark);
 2980|       |            cx->their_mark = NULL;
 2981|       |        }
 2982|       |#endif
 2983|      0|        return SECFailure;
 2984|      0|    }
 2985|       |
 2986|       |#if 0 /* XXX This is what I want, but cannot have because it seems we    \
 2987|       |       * have situations (like when downloading a pkcs7 cert chain from  \
 2988|       |       * some issuers) that give us a total length which is greater than \
 2989|       |       * the entire encoding.  So, we have to allow allDone to have a    \
 2990|       |       * remaining length greater than zero.  I wanted to catch internal \
 2991|       |       * bugs with this, noticing when we do not have the right length.  \
 2992|       |       * Oh well.                                                        \
 2993|       |       */
 2994|       |    PORT_Assert (len == 0
 2995|       |         && (cx->status == needBytes || cx->status == allDone));
 2996|       |#else
 2997|      2|    PORT_Assert((len == 0 && cx->status == needBytes) || cx->status == allDone);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 2]
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2998|      2|#endif
 2999|      2|    return SECSuccess;
 3000|      2|}
SEC_ASN1DecoderFinish_Util:
 3004|      2|{
 3005|      2|    SECStatus rv;
 3006|       |
 3007|      2|    if (!cx || cx->status == needBytes) {
  ------------------
  |  Branch (3007:9): [True: 0, False: 2]
  |  Branch (3007:16): [True: 0, False: 2]
  ------------------
 3008|      0|        if (0 == PORT_GetError()) {
  ------------------
  |  |   62|      0|#define PORT_GetError PORT_GetError_Util
  ------------------
  |  Branch (3008:13): [True: 0, False: 0]
  ------------------
 3009|       |            /* don't clobber a real reason for the failure like bad password
 3010|       |             * or invalid algorithm */
 3011|      0|            PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 3012|      0|        }
 3013|      0|        rv = SECFailure;
 3014|      2|    } else {
 3015|      2|        rv = SECSuccess;
 3016|      2|    }
 3017|       |
 3018|       |    /*
 3019|       |     * XXX anything else that needs to be finished?
 3020|       |     */
 3021|       |
 3022|      2|    if (cx) {
  ------------------
  |  Branch (3022:9): [True: 2, False: 0]
  ------------------
 3023|      2|        PORT_FreeArena(cx->our_pool, PR_TRUE);
  ------------------
  |  |   61|      2|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(cx->our_pool, PR_TRUE);
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 3024|      2|    }
 3025|       |
 3026|      2|    return rv;
 3027|      2|}
SEC_ASN1DecoderStart_Util:
 3032|      2|{
 3033|      2|    PLArenaPool *our_pool;
 3034|      2|    SEC_ASN1DecoderContext *cx;
 3035|       |
 3036|      2|    our_pool = PORT_NewArena(SEC_ASN1_DEFAULT_ARENA_SIZE);
  ------------------
  |  |   63|      2|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  our_pool = PORT_NewArena(SEC_ASN1_DEFAULT_ARENA_SIZE);
  ------------------
  |  |   60|      2|#define SEC_ASN1_DEFAULT_ARENA_SIZE (2048)
  ------------------
 3037|      2|    if (our_pool == NULL)
  ------------------
  |  Branch (3037:9): [True: 0, False: 2]
  ------------------
 3038|      0|        return NULL;
 3039|       |
 3040|      2|    cx = (SEC_ASN1DecoderContext *)PORT_ArenaZAlloc(our_pool, sizeof(*cx));
  ------------------
  |  |   59|      2|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 3041|      2|    if (cx == NULL) {
  ------------------
  |  Branch (3041:9): [True: 0, False: 2]
  ------------------
 3042|      0|        PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3043|      0|        return NULL;
 3044|      0|    }
 3045|       |
 3046|      2|    cx->our_pool = our_pool;
 3047|      2|    if (their_pool != NULL) {
  ------------------
  |  Branch (3047:9): [True: 2, False: 0]
  ------------------
 3048|      2|        cx->their_pool = their_pool;
 3049|       |#ifdef SEC_ASN1D_FREE_ON_ERROR
 3050|       |        cx->their_mark = PORT_ArenaMark(their_pool);
 3051|       |#endif
 3052|      2|    }
 3053|       |
 3054|      2|    cx->status = needBytes;
 3055|       |
 3056|      2|    if (sec_asn1d_push_state(cx, theTemplate, dest, PR_FALSE) == NULL || sec_asn1d_init_state_based_on_template(cx->current) == NULL) {
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  |  Branch (3056:9): [True: 0, False: 2]
  |  Branch (3056:74): [True: 0, False: 2]
  ------------------
 3057|       |        /*
 3058|       |         * Trouble initializing (probably due to failed allocations)
 3059|       |         * requires that we just give up.
 3060|       |         */
 3061|      0|        PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 3062|      0|        return NULL;
 3063|      0|    }
 3064|       |
 3065|      2|    return cx;
 3066|      2|}
SEC_ASN1DecoderSetMaximumElementSize:
 3110|      2|{
 3111|      2|    cx->max_element_size = max_size;
 3112|      2|}
SEC_ASN1Decode_Util:
 3126|      2|{
 3127|      2|    SEC_ASN1DecoderContext *dcx;
 3128|      2|    SECStatus urv, frv;
 3129|       |
 3130|      2|    dcx = SEC_ASN1DecoderStart(poolp, dest, theTemplate);
  ------------------
  |  |   85|      2|#define SEC_ASN1DecoderStart SEC_ASN1DecoderStart_Util
  ------------------
 3131|      2|    if (dcx == NULL)
  ------------------
  |  Branch (3131:9): [True: 0, False: 2]
  ------------------
 3132|      0|        return SECFailure;
 3133|       |
 3134|       |    /* In one-shot mode, there's no possibility of streaming data beyond the
 3135|       |     * length of len */
 3136|      2|    SEC_ASN1DecoderSetMaximumElementSize(dcx, len);
 3137|       |
 3138|      2|    urv = SEC_ASN1DecoderUpdate(dcx, buf, len);
  ------------------
  |  |   86|      2|#define SEC_ASN1DecoderUpdate SEC_ASN1DecoderUpdate_Util
  ------------------
 3139|      2|    frv = SEC_ASN1DecoderFinish(dcx);
  ------------------
  |  |   82|      2|#define SEC_ASN1DecoderFinish SEC_ASN1DecoderFinish_Util
  ------------------
 3140|       |
 3141|      2|    if (urv != SECSuccess)
  ------------------
  |  Branch (3141:9): [True: 0, False: 2]
  ------------------
 3142|      0|        return urv;
 3143|       |
 3144|      2|    return frv;
 3145|      2|}
SEC_ASN1DecodeItem_Util:
 3151|      2|{
 3152|      2|    return SEC_ASN1Decode(poolp, dest, theTemplate,
  ------------------
  |  |   76|      2|#define SEC_ASN1Decode SEC_ASN1Decode_Util
  ------------------
 3153|      2|                          (const char *)src->data, src->len);
 3154|      2|}
secasn1d.c:sec_asn1d_parse_identifier:
  740|     12|{
  741|     12|    unsigned char byte;
  742|     12|    unsigned char tag_number;
  743|       |
  744|     12|    PORT_Assert(state->place == beforeIdentifier);
  ------------------
  |  |  120|     12|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     12|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 12, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  745|       |
  746|     12|    if (len == 0) {
  ------------------
  |  Branch (746:9): [True: 0, False: 12]
  ------------------
  747|      0|        state->top->status = needBytes;
  748|      0|        return 0;
  749|      0|    }
  750|       |
  751|     12|    byte = (unsigned char)*buf;
  752|       |#ifdef DEBUG_ASN1D_STATES
  753|       |    {
  754|       |        int bufsize = 256;
  755|       |        char kindBuf[bufsize];
  756|       |        formatKind(byte, kindBuf, bufsize);
  757|       |        printf("Found tag %02x %s\n", byte, kindBuf);
  758|       |    }
  759|       |#endif
  760|     12|    tag_number = byte & SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   76|     12|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  761|       |
  762|     12|    if (IS_HIGH_TAG_NUMBER(tag_number)) {
  ------------------
  |  |  260|     12|#define IS_HIGH_TAG_NUMBER(n) ((n) == SEC_ASN1_HIGH_TAG_NUMBER)
  |  |  ------------------
  |  |  |  |  107|     12|#define SEC_ASN1_HIGH_TAG_NUMBER 0x1f
  |  |  ------------------
  |  |  |  Branch (260:31): [True: 0, False: 12]
  |  |  ------------------
  ------------------
  763|      0|        state->place = duringIdentifier;
  764|      0|        state->found_tag_number = 0;
  765|       |        /*
  766|       |         * Actually, we have no idea how many bytes are pending, but we
  767|       |         * do know that it is at least 1.  That is all we know; we have
  768|       |         * to look at each byte to know if there is another, etc.
  769|       |         */
  770|      0|        state->pending = 1;
  771|     12|    } else {
  772|     12|        if (byte == 0 && sec_asn1d_parent_allows_EOC(state)) {
  ------------------
  |  Branch (772:13): [True: 0, False: 12]
  |  Branch (772:26): [True: 0, False: 0]
  ------------------
  773|       |            /*
  774|       |             * Our parent has indefinite-length encoding, and the
  775|       |             * entire tag found is 0, so it seems that we have hit the
  776|       |             * end-of-contents octets.  To handle this, we just change
  777|       |             * our state to that which expects to get the bytes of the
  778|       |             * end-of-contents octets and let that code re-read this byte
  779|       |             * so that our categorization of field types is correct.
  780|       |             * After that, our parent will then deal with everything else.
  781|       |             */
  782|      0|            state->place = duringEndOfContents;
  783|      0|            state->pending = 2;
  784|      0|            state->found_tag_number = 0;
  785|      0|            state->found_tag_modifiers = 0;
  786|       |            /*
  787|       |             * We might be an optional field that is, as we now find out,
  788|       |             * missing.  Give our parent a clue that this happened.
  789|       |             */
  790|      0|            if (state->optional)
  ------------------
  |  Branch (790:17): [True: 0, False: 0]
  ------------------
  791|      0|                state->missing = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  792|      0|            return 0;
  793|      0|        }
  794|     12|        state->place = afterIdentifier;
  795|     12|        state->found_tag_number = tag_number;
  796|     12|    }
  797|     12|    state->found_tag_modifiers = byte & ~SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   76|     12|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  798|       |
  799|     12|    return 1;
  800|     12|}
secasn1d.c:sec_asn1d_get_enclosing_construct:
  701|     22|{
  702|     26|    for (state = state->parent; state; state = state->parent) {
  ------------------
  |  Branch (702:33): [True: 24, False: 2]
  ------------------
  703|     24|        sec_asn1d_parse_place place = state->place;
  704|     24|        if (place != afterImplicit &&
  ------------------
  |  Branch (704:13): [True: 24, False: 0]
  ------------------
  705|     24|            place != afterPointer &&
  ------------------
  |  Branch (705:13): [True: 24, False: 0]
  ------------------
  706|     24|            place != afterInline &&
  ------------------
  |  Branch (706:13): [True: 20, False: 4]
  ------------------
  707|     24|            place != afterSaveEncoding &&
  ------------------
  |  Branch (707:13): [True: 20, False: 0]
  ------------------
  708|     24|            place != duringSaveEncoding &&
  ------------------
  |  Branch (708:13): [True: 20, False: 0]
  ------------------
  709|     24|            place != duringChoice) {
  ------------------
  |  Branch (709:13): [True: 20, False: 0]
  ------------------
  710|       |
  711|       |            /* we've walked up the stack to a state that represents
  712|       |            ** the enclosing construct.
  713|       |            */
  714|     20|            break;
  715|     20|        }
  716|     24|    }
  717|     22|    return state;
  718|     22|}
secasn1d.c:sec_asn1d_confirm_identifier:
  848|     12|{
  849|     12|    PRBool match;
  850|       |
  851|     12|    PORT_Assert(state->place == afterIdentifier);
  ------------------
  |  |  120|     12|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     12|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 12, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  852|       |
  853|     12|    match = (PRBool)(((state->found_tag_modifiers & state->check_tag_mask) == state->expect_tag_modifiers) && ((state->found_tag_number & state->check_tag_mask) == state->expect_tag_number));
  ------------------
  |  Branch (853:22): [True: 12, False: 0]
  |  Branch (853:111): [True: 12, False: 0]
  ------------------
  854|     12|    if (match) {
  ------------------
  |  Branch (854:9): [True: 12, False: 0]
  ------------------
  855|     12|        state->place = beforeLength;
  856|     12|    } else {
  857|      0|        if (state->optional) {
  ------------------
  |  Branch (857:13): [True: 0, False: 0]
  ------------------
  858|      0|            state->missing = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  859|      0|            state->place = afterEndOfContents;
  860|      0|        } else {
  861|      0|            PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  862|      0|            state->top->status = decodeError;
  863|      0|        }
  864|      0|    }
  865|     12|}
secasn1d.c:sec_asn1d_parse_length:
  870|     12|{
  871|     12|    unsigned char byte;
  872|       |
  873|     12|    PORT_Assert(state->place == beforeLength);
  ------------------
  |  |  120|     12|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     12|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 12, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  874|       |
  875|     12|    if (len == 0) {
  ------------------
  |  Branch (875:9): [True: 0, False: 12]
  ------------------
  876|      0|        state->top->status = needBytes;
  877|      0|        return 0;
  878|      0|    }
  879|       |
  880|       |    /*
  881|       |     * The default/likely outcome.  It may get adjusted below.
  882|       |     */
  883|     12|    state->place = afterLength;
  884|       |
  885|     12|    byte = (unsigned char)*buf;
  886|       |
  887|     12|    if (LENGTH_IS_SHORT_FORM(byte)) {
  ------------------
  |  |  265|     12|#define LENGTH_IS_SHORT_FORM(b) (((b)&0x80) == 0)
  |  |  ------------------
  |  |  |  Branch (265:33): [True: 9, False: 3]
  |  |  ------------------
  ------------------
  888|      9|        state->contents_length = byte;
  889|      9|    } else {
  890|      3|        state->contents_length = 0;
  891|      3|        state->pending = LONG_FORM_LENGTH(byte);
  ------------------
  |  |  266|      3|#define LONG_FORM_LENGTH(b) ((b)&0x7f)
  ------------------
  892|      3|        if (state->pending == 0) {
  ------------------
  |  Branch (892:13): [True: 0, False: 3]
  ------------------
  893|      0|            state->indefinite = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  894|      3|        } else {
  895|      3|            state->place = duringLength;
  896|      3|        }
  897|      3|    }
  898|       |
  899|       |    /* If we're parsing an ANY, SKIP, or SAVE template, and
  900|       |    ** the object being saved is definite length encoded and constructed,
  901|       |    ** there's no point in decoding that construct's members.
  902|       |    ** So, just forget it's constructed and treat it as primitive.
  903|       |    ** (SAVE appears as an ANY at this point)
  904|       |    */
  905|     12|    if (!state->indefinite &&
  ------------------
  |  Branch (905:9): [True: 12, False: 0]
  ------------------
  906|     12|        (state->underlying_kind & (SEC_ASN1_ANY | SEC_ASN1_SKIP))) {
  ------------------
  |  |  133|     12|#define SEC_ASN1_ANY 0x00400
  ------------------
                      (state->underlying_kind & (SEC_ASN1_ANY | SEC_ASN1_SKIP))) {
  ------------------
  |  |  140|     12|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (906:9): [True: 2, False: 10]
  ------------------
  907|      2|        state->found_tag_modifiers &= ~SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|      2|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  908|      2|    }
  909|       |
  910|     12|    return 1;
  911|     12|}
secasn1d.c:sec_asn1d_parse_more_length:
  916|      3|{
  917|      3|    int count;
  918|       |
  919|      3|    PORT_Assert(state->pending > 0);
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  920|      3|    PORT_Assert(state->place == duringLength);
  ------------------
  |  |  120|      3|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      3|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 3, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  921|       |
  922|      3|    if (len == 0) {
  ------------------
  |  Branch (922:9): [True: 0, False: 3]
  ------------------
  923|      0|        state->top->status = needBytes;
  924|      0|        return 0;
  925|      0|    }
  926|       |
  927|      3|    count = 0;
  928|       |
  929|      8|    while (len && state->pending) {
  ------------------
  |  Branch (929:12): [True: 8, False: 0]
  |  Branch (929:19): [True: 5, False: 3]
  ------------------
  930|      5|        if (HIGH_BITS(state->contents_length, 9) != 0) {
  ------------------
  |  |  268|      5|#define HIGH_BITS(field, cnt) ((field) >> ((sizeof(field) * 8) - (cnt)))
  ------------------
  |  Branch (930:13): [True: 0, False: 5]
  ------------------
  931|       |            /*
  932|       |             * The given full content length overflows our container;
  933|       |             * just give up.
  934|       |             */
  935|      0|            PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  936|      0|            state->top->status = decodeError;
  937|      0|            return 0;
  938|      0|        }
  939|       |
  940|      5|        state->contents_length <<= 8;
  941|      5|        state->contents_length |= (unsigned char)buf[count++];
  942|       |
  943|      5|        len--;
  944|      5|        state->pending--;
  945|      5|    }
  946|       |
  947|      3|    if (state->pending == 0)
  ------------------
  |  Branch (947:9): [True: 3, False: 0]
  ------------------
  948|      3|        state->place = afterLength;
  949|       |
  950|      3|    return count;
  951|      3|}
secasn1d.c:sec_asn1d_prepare_for_contents:
  983|     12|{
  984|     12|    SECItem *item;
  985|     12|    PLArenaPool *poolp;
  986|     12|    unsigned long alloc_len;
  987|     12|    sec_asn1d_state *parent;
  988|       |
  989|       |#ifdef DEBUG_ASN1D_STATES
  990|       |    {
  991|       |        printf("Found Length %lu %s\n", state->contents_length,
  992|       |               state->indefinite ? "indefinite" : "");
  993|       |    }
  994|       |#endif
  995|       |
  996|       |    /**
  997|       |     * The maximum length for a child element should be constrained to the
  998|       |     * length remaining in the first definite length element in the ancestor
  999|       |     * stack. If there is no definite length element in the ancestor stack,
 1000|       |     * there's nothing to constrain the length of the child, so there's no
 1001|       |     * further processing necessary.
 1002|       |     *
 1003|       |     * It's necessary to walk the ancestor stack, because it's possible to have
 1004|       |     * definite length children that are part of an indefinite length element,
 1005|       |     * which is itself part of an indefinite length element, and which is
 1006|       |     * ultimately part of a definite length element. A simple example of this
 1007|       |     * would be the handling of constructed OCTET STRINGs in BER encoding.
 1008|       |     *
 1009|       |     * This algorithm finds the first definite length element in the ancestor
 1010|       |     * stack, if any, and if so, ensures that the length of the child element
 1011|       |     * is consistent with the number of bytes remaining in the constraining
 1012|       |     * ancestor element (that is, after accounting for any other sibling
 1013|       |     * elements that may have been read).
 1014|       |     *
 1015|       |     * It's slightly complicated by the need to account both for integer
 1016|       |     * underflow and overflow, as well as ensure that for indefinite length
 1017|       |     * encodings, there's also enough space for the End-of-Contents (EOC)
 1018|       |     * octets (Tag = 0x00, Length = 0x00, or two bytes).
 1019|       |     */
 1020|       |
 1021|       |    /* Determine the maximum length available for this element by finding the
 1022|       |     * first definite length ancestor, if any. */
 1023|     12|    parent = sec_asn1d_get_enclosing_construct(state);
 1024|     12|    while (parent && parent->indefinite) {
  ------------------
  |  Branch (1024:12): [True: 10, False: 2]
  |  Branch (1024:22): [True: 0, False: 10]
  ------------------
 1025|      0|        parent = sec_asn1d_get_enclosing_construct(parent);
 1026|      0|    }
 1027|       |    /* If parent is null, state is either the outermost state / at the top of
 1028|       |     * the stack, or the outermost state uses indefinite length encoding. In
 1029|       |     * these cases, there's nothing external to constrain this element, so
 1030|       |     * there's nothing to check. */
 1031|     12|    if (parent) {
  ------------------
  |  Branch (1031:9): [True: 10, False: 2]
  ------------------
 1032|     10|        unsigned long remaining = parent->pending;
 1033|     10|        parent = state;
 1034|     10|        do {
 1035|     10|            if (!sec_asn1d_check_and_subtract_length(
  ------------------
  |  Branch (1035:17): [True: 0, False: 10]
  ------------------
 1036|     10|                    &remaining, parent->consumed, state->top) ||
 1037|       |                /* If parent->indefinite is true, parent->contents_length is
 1038|       |                 * zero and this is a no-op. */
 1039|     10|                !sec_asn1d_check_and_subtract_length(
  ------------------
  |  Branch (1039:17): [True: 0, False: 10]
  ------------------
 1040|     10|                    &remaining, parent->contents_length, state->top) ||
 1041|       |                /* If parent->indefinite is true, then ensure there is enough
 1042|       |                 * space for an EOC tag of 2 bytes. */
 1043|     10|                (parent->indefinite && !sec_asn1d_check_and_subtract_length(&remaining, 2, state->top))) {
  ------------------
  |  Branch (1043:18): [True: 0, False: 10]
  |  Branch (1043:40): [True: 0, False: 0]
  ------------------
 1044|       |                /* This element is larger than its enclosing element, which is
 1045|       |                 * invalid. */
 1046|      0|                return;
 1047|      0|            }
 1048|     10|        } while ((parent = sec_asn1d_get_enclosing_construct(parent)) &&
  ------------------
  |  Branch (1048:18): [True: 10, False: 0]
  ------------------
 1049|     10|                 parent->indefinite);
  ------------------
  |  Branch (1049:18): [True: 0, False: 10]
  ------------------
 1050|     10|    }
 1051|       |
 1052|       |    /*
 1053|       |     * XXX I cannot decide if this allocation should exclude the case
 1054|       |     *     where state->endofcontents is true -- figure it out!
 1055|       |     */
 1056|     12|    if (state->allocate) {
  ------------------
  |  Branch (1056:9): [True: 0, False: 12]
  ------------------
 1057|      0|        void *dest;
 1058|       |
 1059|      0|        PORT_Assert(state->dest == NULL);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1060|       |        /*
 1061|       |         * We are handling a POINTER or a member of a GROUP, and need to
 1062|       |         * allocate for the data structure.
 1063|       |         */
 1064|      0|        dest = sec_asn1d_zalloc(state->top->their_pool,
 1065|      0|                                state->theTemplate->size);
 1066|      0|        if (dest == NULL) {
  ------------------
  |  Branch (1066:13): [True: 0, False: 0]
  ------------------
 1067|      0|            state->top->status = decodeError;
 1068|      0|            return;
 1069|      0|        }
 1070|      0|        state->dest = (char *)dest + state->theTemplate->offset;
 1071|       |
 1072|       |        /*
 1073|       |         * For a member of a GROUP, our parent will later put the
 1074|       |         * pointer wherever it belongs.  But for a POINTER, we need
 1075|       |         * to record the destination now, in case notify or filter
 1076|       |         * procs need access to it -- they cannot find it otherwise,
 1077|       |         * until it is too late (for one-pass processing).
 1078|       |         */
 1079|      0|        if (state->parent->place == afterPointer) {
  ------------------
  |  Branch (1079:13): [True: 0, False: 0]
  ------------------
 1080|      0|            void **placep;
 1081|       |
 1082|      0|            placep = state->parent->dest;
 1083|      0|            *placep = dest;
 1084|      0|        }
 1085|      0|    }
 1086|       |
 1087|       |    /*
 1088|       |     * Remember, length may be indefinite here!  In that case,
 1089|       |     * both contents_length and pending will be zero.
 1090|       |     */
 1091|     12|    state->pending = state->contents_length;
 1092|       |
 1093|       |    /*
 1094|       |     * An EXPLICIT is nothing but an outer header, which we have
 1095|       |     * already parsed and accepted.  Now we need to do the inner
 1096|       |     * header and its contents.
 1097|       |     */
 1098|     12|    if (state->explicit) {
  ------------------
  |  Branch (1098:9): [True: 0, False: 12]
  ------------------
 1099|      0|        state->place = afterExplicit;
 1100|      0|        state = sec_asn1d_push_state(state->top,
 1101|      0|                                     SEC_ASN1GetSubtemplate(state->theTemplate,
 1102|      0|                                                            state->dest,
 1103|      0|                                                            PR_FALSE),
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1104|      0|                                     state->dest, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1105|      0|        if (state != NULL) {
  ------------------
  |  Branch (1105:13): [True: 0, False: 0]
  ------------------
 1106|      0|            (void)sec_asn1d_init_state_based_on_template(state);
 1107|      0|        }
 1108|      0|        return;
 1109|      0|    }
 1110|       |
 1111|       |    /*
 1112|       |     * For GROUP (SET OF, SEQUENCE OF), even if we know the length here
 1113|       |     * we cannot tell how many items we will end up with ... so push a
 1114|       |     * state that can keep track of "children" (the individual members
 1115|       |     * of the group; we will allocate as we go and put them all together
 1116|       |     * at the end.
 1117|       |     */
 1118|     12|    if (state->underlying_kind & SEC_ASN1_GROUP) {
  ------------------
  |  |  136|     12|#define SEC_ASN1_GROUP 0x02000        /* with SET or SEQUENCE means \
  ------------------
  |  Branch (1118:9): [True: 0, False: 12]
  ------------------
 1119|       |        /* XXX If this assertion holds (should be able to confirm it via
 1120|       |         * inspection, too) then move this code into the switch statement
 1121|       |         * below under cases SET_OF and SEQUENCE_OF; it will be cleaner.
 1122|       |         */
 1123|      0|        PORT_Assert(state->underlying_kind == SEC_ASN1_SET_OF || state->underlying_kind == SEC_ASN1_SEQUENCE_OF || state->underlying_kind == (SEC_ASN1_SET_OF | SEC_ASN1_DYNAMIC) || state->underlying_kind == (SEC_ASN1_SEQUENCE_OF | SEC_ASN1_DYNAMIC));
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1124|      0|        if (state->contents_length != 0 || state->indefinite) {
  ------------------
  |  Branch (1124:13): [True: 0, False: 0]
  |  Branch (1124:44): [True: 0, False: 0]
  ------------------
 1125|      0|            const SEC_ASN1Template *subt;
 1126|       |
 1127|      0|            state->place = duringGroup;
 1128|      0|            subt = SEC_ASN1GetSubtemplate(state->theTemplate, state->dest,
 1129|      0|                                          PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1130|      0|            state = sec_asn1d_push_state(state->top, subt, NULL, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1131|      0|            if (state != NULL) {
  ------------------
  |  Branch (1131:17): [True: 0, False: 0]
  ------------------
 1132|      0|                if (!state->top->filter_only)
  ------------------
  |  Branch (1132:21): [True: 0, False: 0]
  ------------------
 1133|      0|                    state->allocate = PR_TRUE; /* XXX propogate this? */
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1134|       |                /*
 1135|       |                 * Do the "before" field notification for next in group.
 1136|       |                 */
 1137|      0|                sec_asn1d_notify_before(state->top, state->dest, state->depth);
 1138|      0|                (void)sec_asn1d_init_state_based_on_template(state);
 1139|      0|            }
 1140|      0|        } else {
 1141|       |            /*
 1142|       |             * A group of zero; we are done.
 1143|       |             * Set state to afterGroup and let that code plant the NULL.
 1144|       |             */
 1145|      0|            state->place = afterGroup;
 1146|      0|        }
 1147|      0|        return;
 1148|      0|    }
 1149|       |
 1150|     12|    switch (state->underlying_kind) {
 1151|      4|        case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|      4|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (1151:9): [True: 4, False: 8]
  ------------------
 1152|       |            /*
 1153|       |             * We need to push a child to handle the individual fields.
 1154|       |             */
 1155|      4|            state->place = duringSequence;
 1156|      4|            state = sec_asn1d_push_state(state->top, state->theTemplate + 1,
 1157|      4|                                         state->dest, PR_TRUE);
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
 1158|      4|            if (state != NULL) {
  ------------------
  |  Branch (1158:17): [True: 4, False: 0]
  ------------------
 1159|       |                /*
 1160|       |                 * Do the "before" field notification.
 1161|       |                 */
 1162|      4|                sec_asn1d_notify_before(state->top, state->dest, state->depth);
 1163|      4|                (void)sec_asn1d_init_state_based_on_template(state);
 1164|      4|            }
 1165|      4|            break;
 1166|       |
 1167|      0|        case SEC_ASN1_SET: /* XXX SET is not really implemented */
  ------------------
  |  |   93|      0|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (1167:9): [True: 0, False: 12]
  ------------------
 1168|       |            /*
 1169|       |             * XXX A plain SET requires special handling; scanning of a
 1170|       |             * template to see where a field should go (because by definition,
 1171|       |             * they are not in any particular order, and you have to look at
 1172|       |             * each tag to disambiguate what the field is).  We may never
 1173|       |             * implement this because in practice, it seems to be unused.
 1174|       |             */
 1175|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1176|      0|            PORT_SetError(SEC_ERROR_BAD_DER); /* XXX */
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1177|      0|            state->top->status = decodeError;
 1178|      0|            break;
 1179|       |
 1180|      0|        case SEC_ASN1_NULL:
  ------------------
  |  |   81|      0|#define SEC_ASN1_NULL 0x05
  ------------------
  |  Branch (1180:9): [True: 0, False: 12]
  ------------------
 1181|       |            /*
 1182|       |             * The NULL type, by definition, is "nothing", content length of zero.
 1183|       |             * An indefinite-length encoding is not alloweed.
 1184|       |             */
 1185|      0|            if (state->contents_length || state->indefinite) {
  ------------------
  |  Branch (1185:17): [True: 0, False: 0]
  |  Branch (1185:43): [True: 0, False: 0]
  ------------------
 1186|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1187|      0|                state->top->status = decodeError;
 1188|      0|                break;
 1189|      0|            }
 1190|      0|            if (state->dest != NULL) {
  ------------------
  |  Branch (1190:17): [True: 0, False: 0]
  ------------------
 1191|      0|                item = (SECItem *)(state->dest);
 1192|      0|                item->data = NULL;
 1193|      0|                item->len = 0;
 1194|      0|            }
 1195|      0|            state->place = afterEndOfContents;
 1196|      0|            break;
 1197|       |
 1198|      0|        case SEC_ASN1_BMP_STRING:
  ------------------
  |  |  106|      0|#define SEC_ASN1_BMP_STRING 0x1e
  ------------------
  |  Branch (1198:9): [True: 0, False: 12]
  ------------------
 1199|       |            /* Error if length is not divisable by 2 */
 1200|      0|            if (state->contents_length % 2) {
  ------------------
  |  Branch (1200:17): [True: 0, False: 0]
  ------------------
 1201|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1202|      0|                state->top->status = decodeError;
 1203|      0|                break;
 1204|      0|            }
 1205|       |            /* otherwise, handle as other string types */
 1206|      0|            goto regular_string_type;
 1207|       |
 1208|      0|        case SEC_ASN1_UNIVERSAL_STRING:
  ------------------
  |  |  104|      0|#define SEC_ASN1_UNIVERSAL_STRING 0x1c
  ------------------
  |  Branch (1208:9): [True: 0, False: 12]
  ------------------
 1209|       |            /* Error if length is not divisable by 4 */
 1210|      0|            if (state->contents_length % 4) {
  ------------------
  |  Branch (1210:17): [True: 0, False: 0]
  ------------------
 1211|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1212|      0|                state->top->status = decodeError;
 1213|      0|                break;
 1214|      0|            }
 1215|       |            /* otherwise, handle as other string types */
 1216|      0|            goto regular_string_type;
 1217|       |
 1218|      0|        case SEC_ASN1_SKIP:
  ------------------
  |  |  140|      0|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (1218:9): [True: 0, False: 12]
  ------------------
 1219|      2|        case SEC_ASN1_ANY:
  ------------------
  |  |  133|      2|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (1219:9): [True: 2, False: 10]
  ------------------
 1220|      2|        case SEC_ASN1_ANY_CONTENTS:
  ------------------
  |  |  168|      2|#define SEC_ASN1_ANY_CONTENTS (SEC_ASN1_ANY | SEC_ASN1_INNER)
  |  |  ------------------
  |  |  |  |  133|      2|#define SEC_ASN1_ANY 0x00400
  |  |  ------------------
  |  |               #define SEC_ASN1_ANY_CONTENTS (SEC_ASN1_ANY | SEC_ASN1_INNER)
  |  |  ------------------
  |  |  |  |  141|      2|#define SEC_ASN1_INNER 0x10000        /* with ANY means capture the      \
  |  |  ------------------
  ------------------
  |  Branch (1220:9): [True: 0, False: 12]
  ------------------
 1221|       |        /*
 1222|       |         * These are not (necessarily) strings, but they need nearly
 1223|       |         * identical handling (especially when we need to deal with
 1224|       |         * constructed sub-pieces), so we pretend they are.
 1225|       |         */
 1226|       |        /* fallthru */
 1227|      2|        regular_string_type:
 1228|      2|        case SEC_ASN1_BIT_STRING:
  ------------------
  |  |   79|      2|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (1228:9): [True: 0, False: 12]
  ------------------
 1229|      2|        case SEC_ASN1_IA5_STRING:
  ------------------
  |  |   98|      2|#define SEC_ASN1_IA5_STRING 0x16
  ------------------
  |  Branch (1229:9): [True: 0, False: 12]
  ------------------
 1230|      4|        case SEC_ASN1_OCTET_STRING:
  ------------------
  |  |   80|      4|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
  |  Branch (1230:9): [True: 2, False: 10]
  ------------------
 1231|      4|        case SEC_ASN1_PRINTABLE_STRING:
  ------------------
  |  |   95|      4|#define SEC_ASN1_PRINTABLE_STRING 0x13
  ------------------
  |  Branch (1231:9): [True: 0, False: 12]
  ------------------
 1232|      4|        case SEC_ASN1_T61_STRING:
  ------------------
  |  |   96|      4|#define SEC_ASN1_T61_STRING 0x14
  ------------------
  |  Branch (1232:9): [True: 0, False: 12]
  ------------------
 1233|      4|        case SEC_ASN1_UTC_TIME:
  ------------------
  |  |   99|      4|#define SEC_ASN1_UTC_TIME 0x17
  ------------------
  |  Branch (1233:9): [True: 0, False: 12]
  ------------------
 1234|      4|        case SEC_ASN1_UTF8_STRING:
  ------------------
  |  |   88|      4|#define SEC_ASN1_UTF8_STRING 0x0c
  ------------------
  |  Branch (1234:9): [True: 0, False: 12]
  ------------------
 1235|      4|        case SEC_ASN1_VISIBLE_STRING:
  ------------------
  |  |  102|      4|#define SEC_ASN1_VISIBLE_STRING 0x1a
  ------------------
  |  Branch (1235:9): [True: 0, False: 12]
  ------------------
 1236|       |            /*
 1237|       |             * We are allocating for a primitive or a constructed string.
 1238|       |             * If it is a constructed string, it may also be indefinite-length.
 1239|       |             * If it is primitive, the length can (legally) be zero.
 1240|       |             * Our first order of business is to allocate the memory for
 1241|       |             * the string, if we can (if we know the length).
 1242|       |             */
 1243|      4|            item = (SECItem *)(state->dest);
 1244|       |
 1245|       |            /*
 1246|       |             * If the item is a definite-length constructed string, then
 1247|       |             * the contents_length is actually larger than what we need
 1248|       |             * (because it also counts each intermediate header which we
 1249|       |             * will be throwing away as we go), but it is a perfectly good
 1250|       |             * upper bound that we just allocate anyway, and then concat
 1251|       |             * as we go; we end up wasting a few extra bytes but save a
 1252|       |             * whole other copy.
 1253|       |             */
 1254|      4|            alloc_len = state->contents_length;
 1255|      4|            poolp = NULL; /* quiet compiler warnings about unused... */
 1256|       |
 1257|      4|            if (item == NULL || state->top->filter_only) {
  ------------------
  |  Branch (1257:17): [True: 0, False: 4]
  |  Branch (1257:33): [True: 0, False: 4]
  ------------------
 1258|      0|                if (item != NULL) {
  ------------------
  |  Branch (1258:21): [True: 0, False: 0]
  ------------------
 1259|      0|                    item->data = NULL;
 1260|      0|                    item->len = 0;
 1261|      0|                }
 1262|      0|                alloc_len = 0;
 1263|      4|            } else if (state->substring) {
  ------------------
  |  Branch (1263:24): [True: 0, False: 4]
  ------------------
 1264|       |                /*
 1265|       |                 * If we are a substring of a constructed string, then we may
 1266|       |                 * not have to allocate anything (because our parent, the
 1267|       |                 * actual constructed string, did it for us).  If we are a
 1268|       |                 * substring and we *do* have to allocate, that means our
 1269|       |                 * parent is an indefinite-length, so we allocate from our pool;
 1270|       |                 * later our parent will copy our string into the aggregated
 1271|       |                 * whole and free our pool allocation.
 1272|       |                 */
 1273|      0|                if (item->data == NULL) {
  ------------------
  |  Branch (1273:21): [True: 0, False: 0]
  ------------------
 1274|      0|                    PORT_Assert(item->len == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1275|      0|                    poolp = state->top->our_pool;
 1276|      0|                } else {
 1277|      0|                    alloc_len = 0;
 1278|      0|                }
 1279|      4|            } else {
 1280|      4|                item->len = 0;
 1281|      4|                item->data = NULL;
 1282|      4|                poolp = state->top->their_pool;
 1283|      4|            }
 1284|       |
 1285|      4|            if (alloc_len || ((!state->indefinite) && (state->subitems_head != NULL))) {
  ------------------
  |  Branch (1285:17): [True: 3, False: 1]
  |  Branch (1285:31): [True: 1, False: 0]
  |  Branch (1285:55): [True: 1, False: 0]
  ------------------
 1286|      4|                struct subitem *subitem;
 1287|      4|                int len;
 1288|       |
 1289|      4|                PORT_Assert(item);
  ------------------
  |  |  120|      4|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1290|      4|                if (!item) {
  ------------------
  |  Branch (1290:21): [True: 0, False: 4]
  ------------------
 1291|      0|                    PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1292|      0|                    state->top->status = decodeError;
 1293|      0|                    return;
 1294|      0|                }
 1295|      4|                PORT_Assert(item->len == 0 && item->data == NULL);
  ------------------
  |  |  120|      4|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 4, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 4, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1296|       |                /*
 1297|       |                 * Check for and handle an ANY which has stashed aside the
 1298|       |                 * header (identifier and length) bytes for us to include
 1299|       |                 * in the saved contents.
 1300|       |                 */
 1301|      4|                if (state->subitems_head != NULL) {
  ------------------
  |  Branch (1301:21): [True: 2, False: 2]
  ------------------
 1302|      2|                    PORT_Assert(state->underlying_kind == SEC_ASN1_ANY);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1303|      2|                    for (subitem = state->subitems_head;
 1304|      6|                         subitem != NULL; subitem = subitem->next)
  ------------------
  |  Branch (1304:26): [True: 4, False: 2]
  ------------------
 1305|      4|                        alloc_len += subitem->len;
 1306|      2|                }
 1307|       |
 1308|      4|                if (state->top->max_element_size > 0 &&
  ------------------
  |  Branch (1308:21): [True: 4, False: 0]
  ------------------
 1309|      4|                    alloc_len > state->top->max_element_size) {
  ------------------
  |  Branch (1309:21): [True: 0, False: 4]
  ------------------
 1310|      0|                    PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1311|      0|                    state->top->status = decodeError;
 1312|      0|                    return;
 1313|      0|                }
 1314|       |
 1315|      4|                item->data = (unsigned char *)sec_asn1d_zalloc(poolp, alloc_len);
 1316|      4|                if (item->data == NULL) {
  ------------------
  |  Branch (1316:21): [True: 0, False: 4]
  ------------------
 1317|      0|                    state->top->status = decodeError;
 1318|      0|                    break;
 1319|      0|                }
 1320|       |
 1321|      4|                len = 0;
 1322|      4|                for (subitem = state->subitems_head;
 1323|      8|                     subitem != NULL; subitem = subitem->next) {
  ------------------
  |  Branch (1323:22): [True: 4, False: 4]
  ------------------
 1324|      4|                    PORT_Memcpy(item->data + len, subitem->data, subitem->len);
  ------------------
  |  |  180|      4|#define PORT_Memcpy memcpy
  ------------------
 1325|      4|                    len += subitem->len;
 1326|      4|                }
 1327|      4|                item->len = len;
 1328|       |
 1329|       |                /*
 1330|       |                 * Because we use arenas and have a mark set, we later free
 1331|       |                 * everything we have allocated, so this does *not* present
 1332|       |                 * a memory leak (it is just temporarily left dangling).
 1333|       |                 */
 1334|      4|                state->subitems_head = state->subitems_tail = NULL;
 1335|      4|            }
 1336|       |
 1337|      4|            if (state->contents_length == 0 && (!state->indefinite)) {
  ------------------
  |  Branch (1337:17): [True: 1, False: 3]
  |  Branch (1337:48): [True: 1, False: 0]
  ------------------
 1338|       |                /*
 1339|       |                 * A zero-length simple or constructed string; we are done.
 1340|       |                 */
 1341|      1|                state->place = afterEndOfContents;
 1342|      3|            } else if (state->found_tag_modifiers & SEC_ASN1_CONSTRUCTED) {
  ------------------
  |  |  117|      3|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  |  Branch (1342:24): [True: 0, False: 3]
  ------------------
 1343|      0|                const SEC_ASN1Template *sub;
 1344|       |
 1345|      0|                switch (state->underlying_kind) {
 1346|      0|                    case SEC_ASN1_ANY:
  ------------------
  |  |  133|      0|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (1346:21): [True: 0, False: 0]
  ------------------
 1347|      0|                    case SEC_ASN1_ANY_CONTENTS:
  ------------------
  |  |  168|      0|#define SEC_ASN1_ANY_CONTENTS (SEC_ASN1_ANY | SEC_ASN1_INNER)
  |  |  ------------------
  |  |  |  |  133|      0|#define SEC_ASN1_ANY 0x00400
  |  |  ------------------
  |  |               #define SEC_ASN1_ANY_CONTENTS (SEC_ASN1_ANY | SEC_ASN1_INNER)
  |  |  ------------------
  |  |  |  |  141|      0|#define SEC_ASN1_INNER 0x10000        /* with ANY means capture the      \
  |  |  ------------------
  ------------------
  |  Branch (1347:21): [True: 0, False: 0]
  ------------------
 1348|      0|                        sub = SEC_AnyTemplate;
  ------------------
  |  |  148|      0|#define SEC_AnyTemplate SEC_AnyTemplate_Util
  ------------------
 1349|      0|                        break;
 1350|      0|                    case SEC_ASN1_BIT_STRING:
  ------------------
  |  |   79|      0|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (1350:21): [True: 0, False: 0]
  ------------------
 1351|      0|                        sub = SEC_BitStringTemplate;
  ------------------
  |  |  149|      0|#define SEC_BitStringTemplate SEC_BitStringTemplate_Util
  ------------------
 1352|      0|                        break;
 1353|      0|                    case SEC_ASN1_BMP_STRING:
  ------------------
  |  |  106|      0|#define SEC_ASN1_BMP_STRING 0x1e
  ------------------
  |  Branch (1353:21): [True: 0, False: 0]
  ------------------
 1354|      0|                        sub = SEC_BMPStringTemplate;
  ------------------
  |  |  150|      0|#define SEC_BMPStringTemplate SEC_BMPStringTemplate_Util
  ------------------
 1355|      0|                        break;
 1356|      0|                    case SEC_ASN1_GENERALIZED_TIME:
  ------------------
  |  |  100|      0|#define SEC_ASN1_GENERALIZED_TIME 0x18
  ------------------
  |  Branch (1356:21): [True: 0, False: 0]
  ------------------
 1357|      0|                        sub = SEC_GeneralizedTimeTemplate;
  ------------------
  |  |  152|      0|#define SEC_GeneralizedTimeTemplate SEC_GeneralizedTimeTemplate_Util
  ------------------
 1358|      0|                        break;
 1359|      0|                    case SEC_ASN1_IA5_STRING:
  ------------------
  |  |   98|      0|#define SEC_ASN1_IA5_STRING 0x16
  ------------------
  |  Branch (1359:21): [True: 0, False: 0]
  ------------------
 1360|      0|                        sub = SEC_IA5StringTemplate;
  ------------------
  |  |  153|      0|#define SEC_IA5StringTemplate SEC_IA5StringTemplate_Util
  ------------------
 1361|      0|                        break;
 1362|      0|                    case SEC_ASN1_OCTET_STRING:
  ------------------
  |  |   80|      0|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
  |  Branch (1362:21): [True: 0, False: 0]
  ------------------
 1363|      0|                        sub = SEC_OctetStringTemplate;
  ------------------
  |  |  157|      0|#define SEC_OctetStringTemplate SEC_OctetStringTemplate_Util
  ------------------
 1364|      0|                        break;
 1365|      0|                    case SEC_ASN1_PRINTABLE_STRING:
  ------------------
  |  |   95|      0|#define SEC_ASN1_PRINTABLE_STRING 0x13
  ------------------
  |  Branch (1365:21): [True: 0, False: 0]
  ------------------
 1366|      0|                        sub = SEC_PrintableStringTemplate;
 1367|      0|                        break;
 1368|      0|                    case SEC_ASN1_T61_STRING:
  ------------------
  |  |   96|      0|#define SEC_ASN1_T61_STRING 0x14
  ------------------
  |  Branch (1368:21): [True: 0, False: 0]
  ------------------
 1369|      0|                        sub = SEC_T61StringTemplate;
 1370|      0|                        break;
 1371|      0|                    case SEC_ASN1_UNIVERSAL_STRING:
  ------------------
  |  |  104|      0|#define SEC_ASN1_UNIVERSAL_STRING 0x1c
  ------------------
  |  Branch (1371:21): [True: 0, False: 0]
  ------------------
 1372|      0|                        sub = SEC_UniversalStringTemplate;
 1373|      0|                        break;
 1374|      0|                    case SEC_ASN1_UTC_TIME:
  ------------------
  |  |   99|      0|#define SEC_ASN1_UTC_TIME 0x17
  ------------------
  |  Branch (1374:21): [True: 0, False: 0]
  ------------------
 1375|      0|                        sub = SEC_UTCTimeTemplate;
  ------------------
  |  |  161|      0|#define SEC_UTCTimeTemplate SEC_UTCTimeTemplate_Util
  ------------------
 1376|      0|                        break;
 1377|      0|                    case SEC_ASN1_UTF8_STRING:
  ------------------
  |  |   88|      0|#define SEC_ASN1_UTF8_STRING 0x0c
  ------------------
  |  Branch (1377:21): [True: 0, False: 0]
  ------------------
 1378|      0|                        sub = SEC_UTF8StringTemplate;
  ------------------
  |  |  162|      0|#define SEC_UTF8StringTemplate SEC_UTF8StringTemplate_Util
  ------------------
 1379|      0|                        break;
 1380|      0|                    case SEC_ASN1_VISIBLE_STRING:
  ------------------
  |  |  102|      0|#define SEC_ASN1_VISIBLE_STRING 0x1a
  ------------------
  |  Branch (1380:21): [True: 0, False: 0]
  ------------------
 1381|      0|                        sub = SEC_VisibleStringTemplate;
 1382|      0|                        break;
 1383|      0|                    case SEC_ASN1_SKIP:
  ------------------
  |  |  140|      0|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (1383:21): [True: 0, False: 0]
  ------------------
 1384|      0|                        sub = SEC_SkipTemplate;
 1385|      0|                        break;
 1386|      0|                    default:            /* redundant given outer switch cases, but */
  ------------------
  |  Branch (1386:21): [True: 0, False: 0]
  ------------------
 1387|      0|                        PORT_Assert(0); /* the compiler does not seem to know that, */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1388|      0|                        sub = NULL;     /* so just do enough to quiet it. */
 1389|      0|                        break;
 1390|      0|                }
 1391|       |
 1392|      0|                state->place = duringConstructedString;
 1393|      0|                state = sec_asn1d_push_state(state->top, sub, item, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1394|      0|                if (state != NULL) {
  ------------------
  |  Branch (1394:21): [True: 0, False: 0]
  ------------------
 1395|      0|                    state->substring = PR_TRUE; /* XXX propogate? */
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1396|      0|                    (void)sec_asn1d_init_state_based_on_template(state);
 1397|      0|                }
 1398|      3|            } else if (state->indefinite) {
  ------------------
  |  Branch (1398:24): [True: 0, False: 3]
  ------------------
 1399|       |                /*
 1400|       |                 * An indefinite-length string *must* be constructed!
 1401|       |                 */
 1402|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1403|      0|                state->top->status = decodeError;
 1404|      3|            } else {
 1405|       |                /*
 1406|       |                 * A non-zero-length simple string.
 1407|       |                 */
 1408|      3|                if (state->underlying_kind == SEC_ASN1_BIT_STRING)
  ------------------
  |  |   79|      3|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (1408:21): [True: 0, False: 3]
  ------------------
 1409|      0|                    state->place = beforeBitString;
 1410|      3|                else
 1411|      3|                    state->place = duringLeaf;
 1412|      3|            }
 1413|      4|            break;
 1414|       |
 1415|      4|        default:
  ------------------
  |  Branch (1415:9): [True: 4, False: 8]
  ------------------
 1416|       |            /*
 1417|       |             * We are allocating for a simple leaf item.
 1418|       |             */
 1419|      4|            if (state->contents_length) {
  ------------------
  |  Branch (1419:17): [True: 4, False: 0]
  ------------------
 1420|      4|                if (state->dest != NULL) {
  ------------------
  |  Branch (1420:21): [True: 4, False: 0]
  ------------------
 1421|      4|                    item = (SECItem *)(state->dest);
 1422|      4|                    item->len = 0;
 1423|      4|                    if (state->top->max_element_size > 0 &&
  ------------------
  |  Branch (1423:25): [True: 4, False: 0]
  ------------------
 1424|      4|                        state->contents_length > state->top->max_element_size) {
  ------------------
  |  Branch (1424:25): [True: 0, False: 4]
  ------------------
 1425|      0|                        PORT_SetError(SEC_ERROR_OUTPUT_LEN);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1426|      0|                        state->top->status = decodeError;
 1427|      0|                        return;
 1428|      0|                    }
 1429|       |
 1430|      4|                    if (state->top->filter_only) {
  ------------------
  |  Branch (1430:25): [True: 0, False: 4]
  ------------------
 1431|      0|                        item->data = NULL;
 1432|      4|                    } else {
 1433|      4|                        item->data = (unsigned char *)
 1434|      4|                            sec_asn1d_zalloc(state->top->their_pool,
 1435|      4|                                             state->contents_length);
 1436|      4|                        if (item->data == NULL) {
  ------------------
  |  Branch (1436:29): [True: 0, False: 4]
  ------------------
 1437|      0|                            state->top->status = decodeError;
 1438|      0|                            return;
 1439|      0|                        }
 1440|      4|                    }
 1441|      4|                }
 1442|      4|                state->place = duringLeaf;
 1443|      4|            } else {
 1444|       |                /*
 1445|       |                 * An indefinite-length or zero-length item is not allowed.
 1446|       |                 * (All legal cases of such were handled above.)
 1447|       |                 */
 1448|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1449|      0|                state->top->status = decodeError;
 1450|      0|            }
 1451|     12|    }
 1452|     12|}
secasn1d.c:sec_asn1d_check_and_subtract_length:
  964|     20|{
  965|     20|    PORT_Assert(remaining);
  ------------------
  |  |  120|     20|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     20|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 20, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  966|     20|    PORT_Assert(cx);
  ------------------
  |  |  120|     20|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     20|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 20, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  967|     20|    if (!remaining || !cx) {
  ------------------
  |  Branch (967:9): [True: 0, False: 20]
  |  Branch (967:23): [True: 0, False: 20]
  ------------------
  968|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  969|      0|        cx->status = decodeError;
  970|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  971|      0|    }
  972|     20|    if (*remaining < consumed) {
  ------------------
  |  Branch (972:9): [True: 0, False: 20]
  ------------------
  973|      0|        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  974|      0|        cx->status = decodeError;
  975|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  976|      0|    }
  977|     20|    *remaining -= consumed;
  978|     20|    return PR_TRUE;
  ------------------
  |  |  437|     20|#define PR_TRUE 1
  ------------------
  979|     20|}
secasn1d.c:sec_asn1d_zalloc:
  343|     20|{
  344|     20|    void *thing;
  345|       |
  346|     20|    thing = sec_asn1d_alloc(poolp, len);
  347|     20|    if (thing != NULL)
  ------------------
  |  Branch (347:9): [True: 20, False: 0]
  ------------------
  348|     20|        PORT_Memset(thing, 0, len);
  ------------------
  |  |  182|     20|#define PORT_Memset memset
  ------------------
  349|     20|    return thing;
  350|     20|}
secasn1d.c:sec_asn1d_alloc:
  320|     24|{
  321|     24|    void *thing;
  322|       |
  323|     24|    if (poolp != NULL) {
  ------------------
  |  Branch (323:9): [True: 24, False: 0]
  ------------------
  324|       |        /*
  325|       |         * Allocate from the pool.
  326|       |         */
  327|     24|        thing = PORT_ArenaAlloc(poolp, len);
  ------------------
  |  |   53|     24|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  328|     24|    } else {
  329|       |        /*
  330|       |         * Allocate generically.
  331|       |         */
  332|      0|        thing = PORT_Alloc(len);
  ------------------
  |  |   52|      0|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  333|      0|    }
  334|       |
  335|     24|    return thing;
  336|     24|}
secasn1d.c:sec_asn1d_notify_before:
  425|     10|{
  426|     10|    if (cx->notify_proc == NULL)
  ------------------
  |  Branch (426:9): [True: 10, False: 0]
  ------------------
  427|     10|        return;
  428|       |
  429|      0|    cx->during_notify = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  430|      0|    (*cx->notify_proc)(cx->notify_arg, PR_TRUE, dest, depth);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  431|      0|    cx->during_notify = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  432|      0|}
secasn1d.c:sec_asn1d_add_to_subitems:
 1723|      4|{
 1724|      4|    struct subitem *thing;
 1725|       |
 1726|      4|    thing = (struct subitem *)sec_asn1d_zalloc(state->top->our_pool,
 1727|      4|                                               sizeof(struct subitem));
 1728|      4|    if (thing == NULL) {
  ------------------
  |  Branch (1728:9): [True: 0, False: 4]
  ------------------
 1729|      0|        state->top->status = decodeError;
 1730|      0|        return NULL;
 1731|      0|    }
 1732|       |
 1733|      4|    if (copy_data) {
  ------------------
  |  Branch (1733:9): [True: 4, False: 0]
  ------------------
 1734|      4|        void *copy;
 1735|      4|        copy = sec_asn1d_alloc(state->top->our_pool, len);
 1736|      4|        if (copy == NULL) {
  ------------------
  |  Branch (1736:13): [True: 0, False: 4]
  ------------------
 1737|      0|            state->top->status = decodeError;
 1738|      0|            if (!state->top->our_pool)
  ------------------
  |  Branch (1738:17): [True: 0, False: 0]
  ------------------
 1739|      0|                PORT_Free(thing);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1740|      0|            return NULL;
 1741|      0|        }
 1742|      4|        PORT_Memcpy(copy, data, len);
  ------------------
  |  |  180|      4|#define PORT_Memcpy memcpy
  ------------------
 1743|      4|        thing->data = copy;
 1744|      4|    } else {
 1745|      0|        thing->data = data;
 1746|      0|    }
 1747|      4|    thing->len = len;
 1748|      4|    thing->next = NULL;
 1749|       |
 1750|      4|    if (state->subitems_head == NULL) {
  ------------------
  |  Branch (1750:9): [True: 2, False: 2]
  ------------------
 1751|      2|        PORT_Assert(state->subitems_tail == NULL);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1752|      2|        state->subitems_head = state->subitems_tail = thing;
 1753|      2|    } else {
 1754|      2|        state->subitems_tail->next = thing;
 1755|      2|        state->subitems_tail = thing;
 1756|      2|    }
 1757|       |
 1758|      4|    return thing;
 1759|      4|}
secasn1d.c:sec_asn1d_scrub_state:
  411|     14|{
  412|       |    /*
  413|       |     * Some default "scrubbing".
  414|       |     * XXX right set of initializations?
  415|       |     */
  416|     14|    state->place = beforeIdentifier;
  417|     14|    state->endofcontents = PR_FALSE;
  ------------------
  |  |  438|     14|#define PR_FALSE 0
  ------------------
  418|     14|    state->indefinite = PR_FALSE;
  ------------------
  |  |  438|     14|#define PR_FALSE 0
  ------------------
  419|     14|    state->missing = PR_FALSE;
  ------------------
  |  |  438|     14|#define PR_FALSE 0
  ------------------
  420|     14|    PORT_Assert(state->consumed == 0);
  ------------------
  |  |  120|     14|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     14|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 14, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  421|     14|}
secasn1d.c:sec_asn1d_notify_after:
  436|     10|{
  437|     10|    if (cx->notify_proc == NULL)
  ------------------
  |  Branch (437:9): [True: 10, False: 0]
  ------------------
  438|     10|        return;
  439|       |
  440|      0|    cx->during_notify = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  441|      0|    (*cx->notify_proc)(cx->notify_arg, PR_FALSE, dest, depth);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  442|      0|    cx->during_notify = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  443|      0|}
secasn1d.c:sec_asn1d_parse_leaf:
 1585|      7|{
 1586|      7|    SECItem *item;
 1587|      7|    unsigned long bufLen;
 1588|       |
 1589|      7|    if (len == 0) {
  ------------------
  |  Branch (1589:9): [True: 0, False: 7]
  ------------------
 1590|      0|        state->top->status = needBytes;
 1591|      0|        return 0;
 1592|      0|    }
 1593|       |
 1594|      7|    if (state->pending < len)
  ------------------
  |  Branch (1594:9): [True: 5, False: 2]
  ------------------
 1595|      5|        len = state->pending;
 1596|       |
 1597|      7|    bufLen = len;
 1598|       |
 1599|      7|    item = (SECItem *)(state->dest);
 1600|      7|    if (item != NULL && item->data != NULL) {
  ------------------
  |  Branch (1600:9): [True: 7, False: 0]
  |  Branch (1600:25): [True: 7, False: 0]
  ------------------
 1601|      7|        unsigned long offset;
 1602|       |        /* Strip leading zeroes when target is unsigned integer */
 1603|      7|        if (state->underlying_kind == SEC_ASN1_INTEGER && /* INTEGER   */
  ------------------
  |  |   78|     14|#define SEC_ASN1_INTEGER 0x02
  ------------------
  |  Branch (1603:13): [True: 2, False: 5]
  ------------------
 1604|      7|            item->len == 0 &&                             /* MSB       */
  ------------------
  |  Branch (1604:13): [True: 2, False: 0]
  ------------------
 1605|      7|            item->type == siUnsignedInteger)              /* unsigned  */
  ------------------
  |  Branch (1605:13): [True: 0, False: 2]
  ------------------
 1606|      0|        {
 1607|      0|            while (len > 1 && buf[0] == 0) { /* leading 0 */
  ------------------
  |  Branch (1607:20): [True: 0, False: 0]
  |  Branch (1607:31): [True: 0, False: 0]
  ------------------
 1608|      0|                buf++;
 1609|      0|                len--;
 1610|      0|            }
 1611|      0|        }
 1612|      7|        offset = item->len;
 1613|      7|        if (state->underlying_kind == SEC_ASN1_BIT_STRING) {
  ------------------
  |  |   79|      7|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (1613:13): [True: 0, False: 7]
  ------------------
 1614|       |            // The previous bit string must have no unused bits.
 1615|      0|            if (item->len & 0x7) {
  ------------------
  |  Branch (1615:17): [True: 0, False: 0]
  ------------------
 1616|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1617|      0|                state->top->status = decodeError;
 1618|      0|                return 0;
 1619|      0|            }
 1620|       |            // If this is a bit string, the length is bits, not bytes.
 1621|      0|            offset = item->len >> 3;
 1622|      0|        }
 1623|      7|        if (state->underlying_kind == SEC_ASN1_BIT_STRING) {
  ------------------
  |  |   79|      7|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (1623:13): [True: 0, False: 7]
  ------------------
 1624|      0|            unsigned long len_in_bits;
 1625|       |            // Protect against overflow during the bytes-to-bits conversion.
 1626|      0|            if (len >= (ULONG_MAX >> 3) + 1) {
  ------------------
  |  Branch (1626:17): [True: 0, False: 0]
  ------------------
 1627|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1628|      0|                state->top->status = decodeError;
 1629|      0|                return 0;
 1630|      0|            }
 1631|      0|            len_in_bits = (len << 3) - state->bit_string_unused_bits;
 1632|       |            // Protect against overflow when computing the total length in bits.
 1633|      0|            if (UINT_MAX - item->len < len_in_bits) {
  ------------------
  |  Branch (1633:17): [True: 0, False: 0]
  ------------------
 1634|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1635|      0|                state->top->status = decodeError;
 1636|      0|                return 0;
 1637|      0|            }
 1638|      0|            item->len += len_in_bits;
 1639|      7|        } else {
 1640|      7|            if (UINT_MAX - item->len < len) {
  ------------------
  |  Branch (1640:17): [True: 0, False: 7]
  ------------------
 1641|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 1642|      0|                state->top->status = decodeError;
 1643|      0|                return 0;
 1644|      0|            }
 1645|      7|            item->len += len;
 1646|      7|        }
 1647|      7|        PORT_Memcpy(item->data + offset, buf, len);
  ------------------
  |  |  180|      7|#define PORT_Memcpy memcpy
  ------------------
 1648|      7|    }
 1649|      7|    state->pending -= bufLen;
 1650|      7|    if (state->pending == 0)
  ------------------
  |  Branch (1650:9): [True: 7, False: 0]
  ------------------
 1651|      7|        state->place = beforeEndOfContents;
 1652|       |
 1653|      7|    return bufLen;
 1654|      7|}
secasn1d.c:sec_asn1d_next_in_sequence:
 2069|     10|{
 2070|     10|    sec_asn1d_state *child;
 2071|     10|    unsigned long child_consumed;
 2072|     10|    PRBool child_missing;
 2073|       |
 2074|     10|    PORT_Assert(state->place == duringSequence);
  ------------------
  |  |  120|     10|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     10|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 10, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2075|     10|    PORT_Assert(state->child != NULL);
  ------------------
  |  |  120|     10|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     10|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 10, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2076|       |
 2077|     10|    child = state->child;
 2078|       |
 2079|       |    /*
 2080|       |     * Do the "after" field notification.
 2081|       |     */
 2082|     10|    sec_asn1d_notify_after(state->top, child->dest, child->depth);
 2083|       |
 2084|     10|    child_missing = (PRBool)child->missing;
 2085|     10|    child_consumed = child->consumed;
 2086|     10|    child->consumed = 0;
 2087|       |
 2088|       |    /*
 2089|       |     * Take care of accounting.
 2090|       |     */
 2091|     10|    if (child_missing) {
  ------------------
  |  Branch (2091:9): [True: 0, False: 10]
  ------------------
 2092|      0|        PORT_Assert(child->optional);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2093|     10|    } else {
 2094|     10|        state->consumed += child_consumed;
 2095|       |        /*
 2096|       |         * Free any grandchild.
 2097|       |         */
 2098|     10|        sec_asn1d_free_child(child, PR_FALSE);
  ------------------
  |  |  438|     10|#define PR_FALSE 0
  ------------------
 2099|     10|        if (state->pending) {
  ------------------
  |  Branch (2099:13): [True: 10, False: 0]
  ------------------
 2100|     10|            PORT_Assert(!state->indefinite);
  ------------------
  |  |  120|     10|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     10|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 10, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2101|     10|            if (child_consumed > state->pending) {
  ------------------
  |  Branch (2101:17): [True: 0, False: 10]
  ------------------
 2102|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2103|      0|                state->top->status = decodeError;
 2104|      0|                return;
 2105|      0|            }
 2106|     10|            state->pending -= child_consumed;
 2107|     10|            if (state->pending == 0) {
  ------------------
  |  Branch (2107:17): [True: 4, False: 6]
  ------------------
 2108|      4|                child->theTemplate++;
 2109|      6|                while (child->theTemplate->kind != 0) {
  ------------------
  |  Branch (2109:24): [True: 2, False: 4]
  ------------------
 2110|      2|                    if ((child->theTemplate->kind & SEC_ASN1_OPTIONAL) == 0) {
  ------------------
  |  |  131|      2|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  |  Branch (2110:25): [True: 0, False: 2]
  ------------------
 2111|      0|                        PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2112|      0|                        state->top->status = decodeError;
 2113|      0|                        return;
 2114|      0|                    }
 2115|      2|                    child->theTemplate++;
 2116|      2|                }
 2117|      4|                child->place = notInUse;
 2118|      4|                state->place = afterEndOfContents;
 2119|      4|                return;
 2120|      4|            }
 2121|     10|        }
 2122|     10|    }
 2123|       |
 2124|       |    /*
 2125|       |     * Move forward.
 2126|       |     */
 2127|      6|    child->theTemplate++;
 2128|      6|    if (child->theTemplate->kind == 0) {
  ------------------
  |  Branch (2128:9): [True: 0, False: 6]
  ------------------
 2129|       |        /*
 2130|       |         * We are done with this sequence.
 2131|       |         */
 2132|      0|        child->place = notInUse;
 2133|      0|        if (state->pending) {
  ------------------
  |  Branch (2133:13): [True: 0, False: 0]
  ------------------
 2134|      0|            PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2135|      0|            state->top->status = decodeError;
 2136|      0|        } else if (child_missing) {
  ------------------
  |  Branch (2136:20): [True: 0, False: 0]
  ------------------
 2137|       |            /*
 2138|       |             * We got to the end, but have a child that started parsing
 2139|       |             * and ended up "missing".  The only legitimate reason for
 2140|       |             * this is that we had one or more optional fields at the
 2141|       |             * end of our sequence, and we were encoded indefinite-length,
 2142|       |             * so when we went looking for those optional fields we
 2143|       |             * found our end-of-contents octets instead.
 2144|       |             * (Yes, this is ugly; dunno a better way to handle it.)
 2145|       |             * So, first confirm the situation, and then mark that we
 2146|       |             * are done.
 2147|       |             */
 2148|      0|            if (state->indefinite && child->endofcontents) {
  ------------------
  |  Branch (2148:17): [True: 0, False: 0]
  |  Branch (2148:38): [True: 0, False: 0]
  ------------------
 2149|      0|                PORT_Assert(child_consumed == 2);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2150|      0|                if (child_consumed != 2) {
  ------------------
  |  Branch (2150:21): [True: 0, False: 0]
  ------------------
 2151|      0|                    PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2152|      0|                    state->top->status = decodeError;
 2153|      0|                } else {
 2154|      0|                    state->consumed += child_consumed;
 2155|      0|                    state->place = afterEndOfContents;
 2156|      0|                }
 2157|      0|            } else {
 2158|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2159|      0|                state->top->status = decodeError;
 2160|      0|            }
 2161|      0|        } else {
 2162|       |            /*
 2163|       |             * We have to finish out, maybe reading end-of-contents octets;
 2164|       |             * let the normal logic do the right thing.
 2165|       |             */
 2166|      0|            state->place = beforeEndOfContents;
 2167|      0|        }
 2168|      6|    } else {
 2169|      6|        unsigned char child_found_tag_modifiers = 0;
 2170|      6|        unsigned long child_found_tag_number = 0;
 2171|       |
 2172|       |        /*
 2173|       |         * Reset state and push.
 2174|       |         */
 2175|      6|        if (state->dest != NULL)
  ------------------
  |  Branch (2175:13): [True: 6, False: 0]
  ------------------
 2176|      6|            child->dest = (char *)state->dest + child->theTemplate->offset;
 2177|       |
 2178|       |        /*
 2179|       |         * Do the "before" field notification.
 2180|       |         */
 2181|      6|        sec_asn1d_notify_before(state->top, child->dest, child->depth);
 2182|       |
 2183|      6|        if (child_missing) { /* if previous child was missing, copy the tag data we already have */
  ------------------
  |  Branch (2183:13): [True: 0, False: 6]
  ------------------
 2184|      0|            child_found_tag_modifiers = child->found_tag_modifiers;
 2185|      0|            child_found_tag_number = child->found_tag_number;
 2186|      0|        }
 2187|      6|        state->top->current = child;
 2188|      6|        child = sec_asn1d_init_state_based_on_template(child);
 2189|      6|        if (child_missing && child) {
  ------------------
  |  Branch (2189:13): [True: 0, False: 6]
  |  Branch (2189:30): [True: 0, False: 0]
  ------------------
 2190|      0|            child->place = afterIdentifier;
 2191|      0|            child->found_tag_modifiers = child_found_tag_modifiers;
 2192|      0|            child->found_tag_number = child_found_tag_number;
 2193|      0|            child->consumed = child_consumed;
 2194|      0|            if (child->underlying_kind == SEC_ASN1_ANY && !child->top->filter_only) {
  ------------------
  |  |  133|      0|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (2194:17): [True: 0, False: 0]
  |  Branch (2194:59): [True: 0, False: 0]
  ------------------
 2195|       |                /*
 2196|       |                 * If the new field is an ANY, and we are storing, then
 2197|       |                 * we need to save the tag out.  We would have done this
 2198|       |                 * already in the normal case, but since we were looking
 2199|       |                 * for an optional field, and we did not find it, we only
 2200|       |                 * now realize we need to save the tag.
 2201|       |                 */
 2202|      0|                unsigned char identifier;
 2203|       |
 2204|       |                /*
 2205|       |                 * Check that we did not end up with a high tag; for that
 2206|       |                 * we need to re-encode the tag into multiple bytes in order
 2207|       |                 * to store it back to look like what we parsed originally.
 2208|       |                 * In practice this does not happen, but for completeness
 2209|       |                 * sake it should probably be made to work at some point.
 2210|       |                 */
 2211|      0|                if (child_found_tag_modifiers >= SEC_ASN1_HIGH_TAG_NUMBER) {
  ------------------
  |  |  107|      0|#define SEC_ASN1_HIGH_TAG_NUMBER 0x1f
  ------------------
  |  Branch (2211:21): [True: 0, False: 0]
  ------------------
 2212|      0|                    PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2213|      0|                    state->top->status = decodeError;
 2214|      0|                } else {
 2215|      0|                    identifier = (unsigned char)(child_found_tag_modifiers | child_found_tag_number);
 2216|      0|                    sec_asn1d_record_any_header(child, (char *)&identifier, 1);
 2217|      0|                }
 2218|      0|            }
 2219|      0|        }
 2220|      6|    }
 2221|      6|}
secasn1d.c:sec_asn1d_absorb_child:
 2364|      2|{
 2365|       |    /*
 2366|       |     * There is absolutely supposed to be a child there.
 2367|       |     */
 2368|      2|    PORT_Assert(state->child != NULL);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2369|       |
 2370|       |    /*
 2371|       |     * Inherit the missing status of our child, and do the ugly
 2372|       |     * backing-up if necessary.
 2373|       |     */
 2374|      2|    state->missing = state->child->missing;
 2375|      2|    if (state->missing) {
  ------------------
  |  Branch (2375:9): [True: 0, False: 2]
  ------------------
 2376|      0|        state->found_tag_number = state->child->found_tag_number;
 2377|      0|        state->found_tag_modifiers = state->child->found_tag_modifiers;
 2378|      0|        state->endofcontents = state->child->endofcontents;
 2379|      0|    }
 2380|       |
 2381|       |    /*
 2382|       |     * Add in number of bytes consumed by child.
 2383|       |     * (Only EXPLICIT should have already consumed bytes itself.)
 2384|       |     */
 2385|      2|    PORT_Assert(state->place == afterExplicit || state->consumed == 0);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 2]
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2386|      2|    state->consumed += state->child->consumed;
 2387|       |
 2388|       |    /*
 2389|       |     * Subtract from bytes pending; this only applies to a definite-length
 2390|       |     * EXPLICIT field.
 2391|       |     */
 2392|      2|    if (state->pending) {
  ------------------
  |  Branch (2392:9): [True: 0, False: 2]
  ------------------
 2393|      0|        PORT_Assert(!state->indefinite);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2394|      0|        PORT_Assert(state->place == afterExplicit);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2395|       |
 2396|       |        /*
 2397|       |         * If we had a definite-length explicit, then what the child
 2398|       |         * consumed should be what was left pending.
 2399|       |         */
 2400|      0|        if (state->pending != state->child->consumed) {
  ------------------
  |  Branch (2400:13): [True: 0, False: 0]
  ------------------
 2401|      0|            if (state->pending < state->child->consumed) {
  ------------------
  |  Branch (2401:17): [True: 0, False: 0]
  ------------------
 2402|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2403|      0|                state->top->status = decodeError;
 2404|      0|                return;
 2405|      0|            }
 2406|       |            /*
 2407|       |             * Okay, this is a hack.  It *should* be an error whether
 2408|       |             * pending is too big or too small, but it turns out that
 2409|       |             * we had a bug in our *old* DER encoder that ended up
 2410|       |             * counting an explicit header twice in the case where
 2411|       |             * the underlying type was an ANY.  So, because we cannot
 2412|       |             * prevent receiving these (our own certificate server can
 2413|       |             * send them to us), we need to be lenient and accept them.
 2414|       |             * To do so, we need to pretend as if we read all of the
 2415|       |             * bytes that the header said we would find, even though
 2416|       |             * we actually came up short.
 2417|       |             */
 2418|      0|            state->consumed += (state->pending - state->child->consumed);
 2419|      0|        }
 2420|      0|        state->pending = 0;
 2421|      0|    }
 2422|       |
 2423|       |    /*
 2424|       |     * Indicate that we are done with child.
 2425|       |     */
 2426|      2|    state->child->consumed = 0;
 2427|       |
 2428|       |    /*
 2429|       |     * And move on to final state.
 2430|       |     * (Technically everybody could move to afterEndOfContents except
 2431|       |     * for an indefinite-length EXPLICIT; for simplicity though we assert
 2432|       |     * that but let the end-of-contents code do the real determination.)
 2433|       |     */
 2434|      2|    PORT_Assert(state->place == afterExplicit || (!state->indefinite));
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 2]
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2435|      2|    state->place = beforeEndOfContents;
 2436|      2|}
secasn1d.c:sec_asn1d_prepare_for_end_of_contents:
 2440|      9|{
 2441|      9|    PORT_Assert(state->place == beforeEndOfContents);
  ------------------
  |  |  120|      9|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      9|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 9, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2442|       |
 2443|      9|    if (state->indefinite) {
  ------------------
  |  Branch (2443:9): [True: 0, False: 9]
  ------------------
 2444|      0|        state->place = duringEndOfContents;
 2445|      0|        state->pending = 2;
 2446|      9|    } else {
 2447|      9|        state->place = afterEndOfContents;
 2448|      9|    }
 2449|      9|}
secasn1d.c:sec_asn1d_pop_state:
 2502|     14|{
 2503|       |#if 0  /* XXX I think this should always be handled explicitly by parent? */
 2504|       |    /*
 2505|       |     * Account for our child.
 2506|       |     */
 2507|       |    if (state->child != NULL) {
 2508|       |    state->consumed += state->child->consumed;
 2509|       |    if (state->pending) {
 2510|       |        PORT_Assert (!state->indefinite);
 2511|       |        if (state->child->consumed > state->pending) {
 2512|       |        PORT_SetError (SEC_ERROR_BAD_DER);
 2513|       |        state->top->status = decodeError;
 2514|       |        } else {
 2515|       |        state->pending -= state->child->consumed;
 2516|       |        }
 2517|       |    }
 2518|       |    state->child->consumed = 0;
 2519|       |    }
 2520|       |#endif /* XXX */
 2521|       |
 2522|       |    /*
 2523|       |     * Free our child.
 2524|       |     */
 2525|     14|    sec_asn1d_free_child(state, PR_FALSE);
  ------------------
  |  |  438|     14|#define PR_FALSE 0
  ------------------
 2526|       |
 2527|       |    /*
 2528|       |     * Just make my parent be the current state.  It will then clean
 2529|       |     * up after me and free me (or reuse me).
 2530|       |     */
 2531|     14|    state->top->current = state->parent;
 2532|     14|}
secasn1d.c:sec_asn1d_record_any_header:
 1765|      4|{
 1766|      4|    SECItem *item;
 1767|       |
 1768|      4|    item = (SECItem *)(state->dest);
 1769|      4|    if (item != NULL && item->data != NULL) {
  ------------------
  |  Branch (1769:9): [True: 4, False: 0]
  |  Branch (1769:25): [True: 0, False: 4]
  ------------------
 1770|      0|        PORT_Assert(state->substring);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1771|      0|        PORT_Memcpy(item->data + item->len, buf, len);
  ------------------
  |  |  180|      0|#define PORT_Memcpy memcpy
  ------------------
 1772|      0|        item->len += len;
 1773|      4|    } else {
 1774|      4|        sec_asn1d_add_to_subitems(state, buf, len, PR_TRUE);
  ------------------
  |  |  437|      4|#define PR_TRUE 1
  ------------------
 1775|      4|    }
 1776|      4|}
secasn1d.c:sec_asn1d_free_child:
 1456|     24|{
 1457|     24|    if (state->child != NULL) {
  ------------------
  |  Branch (1457:9): [True: 6, False: 18]
  ------------------
 1458|      6|        PORT_Assert(error || state->child->consumed == 0);
  ------------------
  |  |  120|      6|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     12|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 6]
  |  |  |  |  |  Branch (208:7): [True: 6, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1459|      6|        PORT_Assert(state->our_mark != NULL);
  ------------------
  |  |  120|      6|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      6|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 6, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1460|      6|        PORT_ArenaZRelease(state->top->our_pool, state->our_mark);
 1461|      6|        if (error && state->top->their_pool == NULL) {
  ------------------
  |  Branch (1461:13): [True: 0, False: 6]
  |  Branch (1461:22): [True: 0, False: 0]
  ------------------
 1462|       |            /*
 1463|       |             * XXX We need to free anything allocated.
 1464|       |             * At this point, we failed in the middle of decoding. But we
 1465|       |             * can't free the data we previously allocated with PR_Malloc
 1466|       |             * unless we keep track of every pointer. So instead we have a
 1467|       |             * memory leak when decoding fails half-way, unless an arena is
 1468|       |             * used. See bug 95311 .
 1469|       |             */
 1470|      0|        }
 1471|      6|        state->child = NULL;
 1472|      6|        state->our_mark = NULL;
 1473|     18|    } else {
 1474|       |        /*
 1475|       |         * It is important that we do not leave a mark unreleased/unmarked.
 1476|       |         * But I do not think we should ever have one set in this case, only
 1477|       |         * if we had a child (handled above).  So check for that.  If this
 1478|       |         * assertion should ever get hit, then we probably need to add code
 1479|       |         * here to release back to our_mark (and then set our_mark to NULL).
 1480|       |         */
 1481|     18|        PORT_Assert(state->our_mark == NULL);
  ------------------
  |  |  120|     18|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     18|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 18, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1482|     18|    }
 1483|     24|    state->place = beforeEndOfContents;
 1484|     24|}
secasn1d.c:sec_asn1d_push_state:
  356|      8|{
  357|      8|    sec_asn1d_state *state, *new_state;
  358|       |
  359|      8|    state = cx->current;
  360|       |
  361|      8|    PORT_Assert(state == NULL || state->child == NULL);
  ------------------
  |  |  120|      8|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     14|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2, False: 6]
  |  |  |  |  |  Branch (208:7): [True: 6, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  362|       |
  363|      8|    if (state != NULL) {
  ------------------
  |  Branch (363:9): [True: 6, False: 2]
  ------------------
  364|      6|        PORT_Assert(state->our_mark == NULL);
  ------------------
  |  |  120|      6|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      6|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 6, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  365|      6|        state->our_mark = PORT_ArenaMark(cx->our_pool);
  ------------------
  |  |   55|      6|#define PORT_ArenaMark PORT_ArenaMark_Util
  ------------------
  366|      6|    }
  367|       |
  368|      8|    if (theTemplate == NULL) {
  ------------------
  |  Branch (368:9): [True: 0, False: 8]
  ------------------
  369|      0|        PORT_SetError(SEC_ERROR_BAD_TEMPLATE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  370|      0|        goto loser;
  371|      0|    }
  372|       |
  373|      8|    new_state = (sec_asn1d_state *)sec_asn1d_zalloc(cx->our_pool,
  374|      8|                                                    sizeof(*new_state));
  375|      8|    if (new_state == NULL) {
  ------------------
  |  Branch (375:9): [True: 0, False: 8]
  ------------------
  376|      0|        goto loser;
  377|      0|    }
  378|       |
  379|      8|    new_state->top = cx;
  380|      8|    new_state->parent = state;
  381|      8|    new_state->theTemplate = theTemplate;
  382|      8|    new_state->place = notInUse;
  383|      8|    if (dest != NULL)
  ------------------
  |  Branch (383:9): [True: 8, False: 0]
  ------------------
  384|      8|        new_state->dest = (char *)dest + theTemplate->offset;
  385|       |
  386|      8|    if (state != NULL) {
  ------------------
  |  Branch (386:9): [True: 6, False: 2]
  ------------------
  387|      6|        new_state->depth = state->depth;
  388|      6|        if (new_depth) {
  ------------------
  |  Branch (388:13): [True: 4, False: 2]
  ------------------
  389|      4|            if (++new_state->depth > SEC_ASN1D_MAX_DEPTH) {
  ------------------
  |  |  171|      4|#define SEC_ASN1D_MAX_DEPTH 32
  ------------------
  |  Branch (389:17): [True: 0, False: 4]
  ------------------
  390|      0|                PORT_SetError(SEC_ERROR_BAD_DER);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  391|      0|                goto loser;
  392|      0|            }
  393|      4|        }
  394|      6|        state->child = new_state;
  395|      6|    }
  396|       |
  397|      8|    cx->current = new_state;
  398|      8|    return new_state;
  399|       |
  400|      0|loser:
  401|      0|    cx->status = decodeError;
  402|      0|    if (state != NULL) {
  ------------------
  |  Branch (402:9): [True: 0, False: 0]
  ------------------
  403|      0|        PORT_ArenaRelease(cx->our_pool, state->our_mark);
  ------------------
  |  |   56|      0|#define PORT_ArenaRelease PORT_ArenaRelease_Util
  ------------------
  404|      0|        state->our_mark = NULL;
  405|      0|    }
  406|      0|    return NULL;
  407|      8|}
secasn1d.c:sec_asn1d_init_state_based_on_template:
  447|     14|{
  448|     14|    PRBool explicit, optional, universal;
  449|     14|    unsigned char expect_tag_modifiers;
  450|     14|    unsigned long encode_kind, under_kind;
  451|     14|    unsigned long check_tag_mask, expect_tag_number;
  452|       |
  453|       |    /* XXX Check that both of these tests are really needed/appropriate. */
  454|     14|    if (state == NULL || state->top->status == decodeError)
  ------------------
  |  Branch (454:9): [True: 0, False: 14]
  |  Branch (454:26): [True: 0, False: 14]
  ------------------
  455|      0|        return state;
  456|       |
  457|     14|    encode_kind = state->theTemplate->kind;
  458|       |
  459|     14|    if (encode_kind & SEC_ASN1_SAVE) {
  ------------------
  |  |  144|     14|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  ------------------
  |  Branch (459:9): [True: 0, False: 14]
  ------------------
  460|       |        /*
  461|       |         * This is a "magic" field that saves away all bytes, allowing
  462|       |         * the immediately following field to still be decoded from this
  463|       |         * same spot -- sort of a fork.
  464|       |         */
  465|       |        /* check that there are no extraneous bits */
  466|      0|        PORT_Assert(encode_kind == SEC_ASN1_SAVE);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  467|      0|        if (state->top->filter_only) {
  ------------------
  |  Branch (467:13): [True: 0, False: 0]
  ------------------
  468|       |            /*
  469|       |             * If we are not storing, then we do not do the SAVE field
  470|       |             * at all.  Just move ahead to the "real" field instead,
  471|       |             * doing the appropriate notify calls before and after.
  472|       |             */
  473|      0|            sec_asn1d_notify_after(state->top, state->dest, state->depth);
  474|       |            /*
  475|       |             * Since we are not storing, allow for our current dest value
  476|       |             * to be NULL.  (This might not actually occur, but right now I
  477|       |             * cannot convince myself one way or the other.)  If it is NULL,
  478|       |             * assume that our parent dest can help us out.
  479|       |             */
  480|      0|            if (state->dest == NULL)
  ------------------
  |  Branch (480:17): [True: 0, False: 0]
  ------------------
  481|      0|                state->dest = state->parent->dest;
  482|      0|            else
  483|      0|                state->dest = (char *)state->dest - state->theTemplate->offset;
  484|      0|            state->theTemplate++;
  485|      0|            if (state->dest != NULL)
  ------------------
  |  Branch (485:17): [True: 0, False: 0]
  ------------------
  486|      0|                state->dest = (char *)state->dest + state->theTemplate->offset;
  487|      0|            sec_asn1d_notify_before(state->top, state->dest, state->depth);
  488|      0|            encode_kind = state->theTemplate->kind;
  489|      0|            PORT_Assert((encode_kind & SEC_ASN1_SAVE) == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  490|      0|        } else {
  491|      0|            sec_asn1d_scrub_state(state);
  492|      0|            state->place = duringSaveEncoding;
  493|      0|            state = sec_asn1d_push_state(state->top, SEC_AnyTemplate,
  ------------------
  |  |  148|      0|#define SEC_AnyTemplate SEC_AnyTemplate_Util
  ------------------
  494|      0|                                         state->dest, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  495|      0|            if (state != NULL)
  ------------------
  |  Branch (495:17): [True: 0, False: 0]
  ------------------
  496|      0|                state = sec_asn1d_init_state_based_on_template(state);
  497|      0|            return state;
  498|      0|        }
  499|      0|    }
  500|       |
  501|     14|    universal = ((encode_kind & SEC_ASN1_CLASS_MASK) == SEC_ASN1_UNIVERSAL)
  ------------------
  |  |  119|     14|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
                  universal = ((encode_kind & SEC_ASN1_CLASS_MASK) == SEC_ASN1_UNIVERSAL)
  ------------------
  |  |  120|     14|#define SEC_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (501:17): [True: 14, False: 0]
  ------------------
  502|     14|                    ? PR_TRUE
  ------------------
  |  |  437|     14|#define PR_TRUE 1
  ------------------
  503|     14|                    : PR_FALSE;
  ------------------
  |  |  438|     14|#define PR_FALSE 0
  ------------------
  504|       |
  505|     14|    explicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  132|     14|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
                  explicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  explicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|     28|#define PR_FALSE 0
  ------------------
  |  Branch (505:16): [True: 0, False: 14]
  ------------------
  506|     14|    encode_kind &= ~SEC_ASN1_EXPLICIT;
  ------------------
  |  |  132|     14|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
  507|       |
  508|     14|    optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  131|     14|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
                  optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
                  optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|     26|#define PR_FALSE 0
  ------------------
  |  Branch (508:16): [True: 2, False: 12]
  ------------------
  509|     14|    encode_kind &= ~SEC_ASN1_OPTIONAL;
  ------------------
  |  |  131|     14|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  510|       |
  511|     14|    PORT_Assert(!(explicit && universal)); /* bad templates */
  ------------------
  |  |  120|     14|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     14|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 14]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  512|       |
  513|     14|    encode_kind &= ~SEC_ASN1_DYNAMIC;
  ------------------
  |  |  138|     14|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  ------------------
  514|     14|    encode_kind &= ~SEC_ASN1_MAY_STREAM;
  ------------------
  |  |  146|     14|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
  515|       |
  516|     14|    if (encode_kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|     14|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (516:9): [True: 0, False: 14]
  ------------------
  517|       |#if 0 /* XXX remove? */
  518|       |      sec_asn1d_state *child = sec_asn1d_push_state(state->top, state->theTemplate, state->dest, PR_FALSE);
  519|       |      if ((sec_asn1d_state *)NULL == child) {
  520|       |        return (sec_asn1d_state *)NULL;
  521|       |      }
  522|       |
  523|       |      child->allocate = state->allocate;
  524|       |      child->place = beforeChoice;
  525|       |      return child;
  526|       |#else
  527|      0|        state->place = beforeChoice;
  528|      0|        return state;
  529|      0|#endif
  530|      0|    }
  531|       |
  532|     14|    if ((encode_kind & (SEC_ASN1_POINTER | SEC_ASN1_INLINE)) || (!universal && !explicit)) {
  ------------------
  |  |  135|     14|#define SEC_ASN1_POINTER 0x01000
  ------------------
                  if ((encode_kind & (SEC_ASN1_POINTER | SEC_ASN1_INLINE)) || (!universal && !explicit)) {
  ------------------
  |  |  134|     14|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (532:9): [True: 2, False: 12]
  |  Branch (532:66): [True: 0, False: 12]
  |  Branch (532:80): [True: 0, False: 0]
  ------------------
  533|      2|        const SEC_ASN1Template *subt;
  534|      2|        void *dest;
  535|      2|        PRBool child_allocate;
  536|       |
  537|      2|        PORT_Assert((encode_kind & (SEC_ASN1_ANY | SEC_ASN1_SKIP)) == 0);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  538|       |
  539|      2|        sec_asn1d_scrub_state(state);
  540|      2|        child_allocate = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  541|       |
  542|      2|        if (encode_kind & SEC_ASN1_POINTER) {
  ------------------
  |  |  135|      2|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (542:13): [True: 0, False: 2]
  ------------------
  543|       |            /*
  544|       |             * A POINTER means we need to allocate the destination for
  545|       |             * this field.  But, since it may also be an optional field,
  546|       |             * we defer the allocation until later; we just record that
  547|       |             * it needs to be done.
  548|       |             *
  549|       |             * There are two possible scenarios here -- one is just a
  550|       |             * plain POINTER (kind of like INLINE, except with allocation)
  551|       |             * and the other is an implicitly-tagged POINTER.  We don't
  552|       |             * need to do anything special here for the two cases, but
  553|       |             * since the template definition can be tricky, we do check
  554|       |             * that there are no extraneous bits set in encode_kind.
  555|       |             *
  556|       |             * XXX The same conditions which assert should set an error.
  557|       |             */
  558|      0|            if (universal) {
  ------------------
  |  Branch (558:17): [True: 0, False: 0]
  ------------------
  559|       |                /*
  560|       |                 * "universal" means this entry is a standalone POINTER;
  561|       |                 * there should be no other bits set in encode_kind.
  562|       |                 */
  563|      0|                PORT_Assert(encode_kind == SEC_ASN1_POINTER);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  564|      0|            } else {
  565|       |                /*
  566|       |                 * If we get here we have an implicitly-tagged field
  567|       |                 * that needs to be put into a POINTER.  The subtemplate
  568|       |                 * will determine how to decode the field, but encode_kind
  569|       |                 * describes the (implicit) tag we are looking for.
  570|       |                 * The non-tag bits of encode_kind will be ignored by
  571|       |                 * the code below; none of them should be set, however,
  572|       |                 * except for the POINTER bit itself -- so check that.
  573|       |                 */
  574|      0|                PORT_Assert((encode_kind & ~SEC_ASN1_TAG_MASK) == SEC_ASN1_POINTER);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  575|      0|            }
  576|      0|            if (!state->top->filter_only)
  ------------------
  |  Branch (576:17): [True: 0, False: 0]
  ------------------
  577|      0|                child_allocate = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  578|      0|            dest = NULL;
  579|      0|            state->place = afterPointer;
  580|      2|        } else {
  581|      2|            dest = state->dest;
  582|      2|            if (encode_kind & SEC_ASN1_INLINE) {
  ------------------
  |  |  134|      2|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (582:17): [True: 2, False: 0]
  ------------------
  583|       |                /* check that there are no extraneous bits */
  584|      2|                PORT_Assert(encode_kind == SEC_ASN1_INLINE && !optional);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      4|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  585|      2|                state->place = afterInline;
  586|      2|            } else {
  587|      0|                state->place = afterImplicit;
  588|      0|            }
  589|      2|        }
  590|       |
  591|      2|        state->optional = optional;
  592|      2|        subt = SEC_ASN1GetSubtemplate(state->theTemplate, state->dest, PR_FALSE);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  593|      2|        state = sec_asn1d_push_state(state->top, subt, dest, PR_FALSE);
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  594|      2|        if (state == NULL)
  ------------------
  |  Branch (594:13): [True: 0, False: 2]
  ------------------
  595|      0|            return NULL;
  596|       |
  597|      2|        state->allocate = child_allocate;
  598|       |
  599|      2|        if (universal) {
  ------------------
  |  Branch (599:13): [True: 2, False: 0]
  ------------------
  600|      2|            state = sec_asn1d_init_state_based_on_template(state);
  601|      2|            if (state != NULL) {
  ------------------
  |  Branch (601:17): [True: 2, False: 0]
  ------------------
  602|       |                /*
  603|       |                 * If this field is optional, we need to record that on
  604|       |                 * the pushed child so it won't fail if the field isn't
  605|       |                 * found.  I can't think of a way that this new state
  606|       |                 * could already have optional set (which we would wipe
  607|       |                 * out below if our local optional is not set) -- but
  608|       |                 * just to be sure, assert that it isn't set.
  609|       |                 */
  610|      2|                PORT_Assert(!state->optional);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  611|      2|                state->optional = optional;
  612|      2|            }
  613|      2|            return state;
  614|      2|        }
  615|       |
  616|      0|        under_kind = state->theTemplate->kind;
  617|      0|        under_kind &= ~SEC_ASN1_MAY_STREAM;
  ------------------
  |  |  146|      0|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
  618|     12|    } else if (explicit) {
  ------------------
  |  Branch (618:16): [True: 0, False: 12]
  ------------------
  619|       |        /*
  620|       |         * For explicit, we only need to match the encoding tag next,
  621|       |         * then we will push another state to handle the entire inner
  622|       |         * part.  In this case, there is no underlying kind which plays
  623|       |         * any part in the determination of the outer, explicit tag.
  624|       |         * So we just set under_kind to 0, which is not a valid tag,
  625|       |         * and the rest of the tag matching stuff should be okay.
  626|       |         */
  627|      0|        under_kind = 0;
  628|     12|    } else {
  629|       |        /*
  630|       |         * Nothing special; the underlying kind and the given encoding
  631|       |         * information are the same.
  632|       |         */
  633|     12|        under_kind = encode_kind;
  634|     12|    }
  635|       |
  636|       |    /* XXX is this the right set of bits to test here? */
  637|     12|    PORT_Assert((under_kind & (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_MAY_STREAM | SEC_ASN1_INLINE | SEC_ASN1_POINTER)) == 0);
  ------------------
  |  |  120|     12|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     12|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 12, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  638|       |
  639|     12|    if (encode_kind & (SEC_ASN1_ANY | SEC_ASN1_SKIP)) {
  ------------------
  |  |  133|     12|#define SEC_ASN1_ANY 0x00400
  ------------------
                  if (encode_kind & (SEC_ASN1_ANY | SEC_ASN1_SKIP)) {
  ------------------
  |  |  140|     12|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (639:9): [True: 2, False: 10]
  ------------------
  640|      2|        PORT_Assert(encode_kind == under_kind);
  ------------------
  |  |  120|      2|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      2|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 2, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  641|      2|        if (encode_kind & SEC_ASN1_SKIP) {
  ------------------
  |  |  140|      2|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  ------------------
  |  Branch (641:13): [True: 0, False: 2]
  ------------------
  642|      0|            PORT_Assert(!optional);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  643|      0|            PORT_Assert(encode_kind == SEC_ASN1_SKIP);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  644|      0|            state->dest = NULL;
  645|      0|        }
  646|      2|        check_tag_mask = 0;
  647|      2|        expect_tag_modifiers = 0;
  648|      2|        expect_tag_number = 0;
  649|     10|    } else {
  650|     10|        check_tag_mask = SEC_ASN1_TAG_MASK;
  ------------------
  |  |   65|     10|#define SEC_ASN1_TAG_MASK 0xff
  ------------------
  651|     10|        expect_tag_modifiers = (unsigned char)encode_kind & SEC_ASN1_TAG_MASK & ~SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   65|     10|#define SEC_ASN1_TAG_MASK 0xff
  ------------------
                      expect_tag_modifiers = (unsigned char)encode_kind & SEC_ASN1_TAG_MASK & ~SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   76|     10|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  652|       |        /*
  653|       |         * XXX This assumes only single-octet identifiers.  To handle
  654|       |         * the HIGH TAG form we would need to do some more work, especially
  655|       |         * in how to specify them in the template, because right now we
  656|       |         * do not provide a way to specify more *tag* bits in encode_kind.
  657|       |         */
  658|     10|        expect_tag_number = encode_kind & SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   76|     10|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  659|       |
  660|     10|        switch (under_kind & SEC_ASN1_TAGNUM_MASK) {
  ------------------
  |  |   76|     10|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (660:17): [True: 4, False: 6]
  ------------------
  661|      0|            case SEC_ASN1_SET:
  ------------------
  |  |   93|      0|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (661:13): [True: 0, False: 10]
  ------------------
  662|       |                /*
  663|       |                 * XXX A plain old SET (as opposed to a SET OF) is not implemented.
  664|       |                 * If it ever is, remove this assert...
  665|       |                 */
  666|      0|                PORT_Assert((under_kind & SEC_ASN1_GROUP) != 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  667|       |            /* fallthru */
  668|      4|            case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|      4|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (668:13): [True: 4, False: 6]
  ------------------
  669|      4|                expect_tag_modifiers |= SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|      4|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  670|      4|                break;
  671|      0|            case SEC_ASN1_BIT_STRING:
  ------------------
  |  |   79|      0|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (671:13): [True: 0, False: 10]
  ------------------
  672|      0|            case SEC_ASN1_BMP_STRING:
  ------------------
  |  |  106|      0|#define SEC_ASN1_BMP_STRING 0x1e
  ------------------
  |  Branch (672:13): [True: 0, False: 10]
  ------------------
  673|      0|            case SEC_ASN1_GENERALIZED_TIME:
  ------------------
  |  |  100|      0|#define SEC_ASN1_GENERALIZED_TIME 0x18
  ------------------
  |  Branch (673:13): [True: 0, False: 10]
  ------------------
  674|      0|            case SEC_ASN1_IA5_STRING:
  ------------------
  |  |   98|      0|#define SEC_ASN1_IA5_STRING 0x16
  ------------------
  |  Branch (674:13): [True: 0, False: 10]
  ------------------
  675|      2|            case SEC_ASN1_OCTET_STRING:
  ------------------
  |  |   80|      2|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
  |  Branch (675:13): [True: 2, False: 8]
  ------------------
  676|      2|            case SEC_ASN1_PRINTABLE_STRING:
  ------------------
  |  |   95|      2|#define SEC_ASN1_PRINTABLE_STRING 0x13
  ------------------
  |  Branch (676:13): [True: 0, False: 10]
  ------------------
  677|      2|            case SEC_ASN1_T61_STRING:
  ------------------
  |  |   96|      2|#define SEC_ASN1_T61_STRING 0x14
  ------------------
  |  Branch (677:13): [True: 0, False: 10]
  ------------------
  678|      2|            case SEC_ASN1_UNIVERSAL_STRING:
  ------------------
  |  |  104|      2|#define SEC_ASN1_UNIVERSAL_STRING 0x1c
  ------------------
  |  Branch (678:13): [True: 0, False: 10]
  ------------------
  679|      2|            case SEC_ASN1_UTC_TIME:
  ------------------
  |  |   99|      2|#define SEC_ASN1_UTC_TIME 0x17
  ------------------
  |  Branch (679:13): [True: 0, False: 10]
  ------------------
  680|      2|            case SEC_ASN1_UTF8_STRING:
  ------------------
  |  |   88|      2|#define SEC_ASN1_UTF8_STRING 0x0c
  ------------------
  |  Branch (680:13): [True: 0, False: 10]
  ------------------
  681|      2|            case SEC_ASN1_VISIBLE_STRING:
  ------------------
  |  |  102|      2|#define SEC_ASN1_VISIBLE_STRING 0x1a
  ------------------
  |  Branch (681:13): [True: 0, False: 10]
  ------------------
  682|      2|                check_tag_mask &= ~SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|      2|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  683|      2|                break;
  684|     10|        }
  685|     10|    }
  686|       |
  687|     12|    state->check_tag_mask = check_tag_mask;
  688|     12|    state->expect_tag_modifiers = expect_tag_modifiers;
  689|     12|    state->expect_tag_number = expect_tag_number;
  690|     12|    state->underlying_kind = under_kind;
  691|     12|    state->explicit = explicit;
  692|     12|    state->optional = optional;
  693|       |
  694|     12|    sec_asn1d_scrub_state(state);
  695|       |
  696|     12|    return state;
  697|     12|}

SEC_ASN1EncodeLength:
  397|   147k|{
  398|   147k|    int lenlen;
  399|       |
  400|   147k|    lenlen = SEC_ASN1LengthLength(value);
  ------------------
  |  |  101|   147k|#define SEC_ASN1LengthLength SEC_ASN1LengthLength_Util
  ------------------
  401|   147k|    if (lenlen == 1) {
  ------------------
  |  Branch (401:9): [True: 147k, False: 178]
  ------------------
  402|   147k|        buf[0] = value;
  403|   147k|    } else {
  404|    178|        int i;
  405|       |
  406|    178|        i = lenlen - 1;
  407|    178|        buf[0] = 0x80 | i;
  408|    356|        while (i) {
  ------------------
  |  Branch (408:16): [True: 178, False: 178]
  ------------------
  409|    178|            buf[i--] = value;
  410|    178|            value >>= 8;
  411|    178|        }
  412|    178|        PORT_Assert(value == 0);
  ------------------
  |  |  120|    178|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    178|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 178, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  413|    178|    }
  414|   147k|    return lenlen;
  415|   147k|}
SEC_ASN1EncoderUpdate_Util:
 1201|   100k|{
 1202|   100k|    sec_asn1e_state *state;
 1203|       |
 1204|   100k|    if (cx->status == needBytes) {
  ------------------
  |  Branch (1204:9): [True: 0, False: 100k]
  ------------------
 1205|      0|        cx->status = keepGoing;
 1206|      0|    }
 1207|       |
 1208|   410k|    while (cx->status == keepGoing) {
  ------------------
  |  Branch (1208:12): [True: 410k, False: 0]
  ------------------
 1209|   410k|        state = cx->current;
 1210|   410k|        switch (state->place) {
 1211|   147k|            case beforeHeader:
  ------------------
  |  Branch (1211:13): [True: 147k, False: 263k]
  ------------------
 1212|   147k|                sec_asn1e_write_header(state);
 1213|   147k|                break;
 1214|  68.9k|            case duringContents:
  ------------------
  |  Branch (1214:13): [True: 68.9k, False: 341k]
  ------------------
 1215|  68.9k|                if (cx->from_buf)
  ------------------
  |  Branch (1215:21): [True: 0, False: 68.9k]
  ------------------
 1216|      0|                    sec_asn1e_write_contents_from_buf(state, buf, len);
 1217|  68.9k|                else
 1218|  68.9k|                    sec_asn1e_write_contents(state);
 1219|  68.9k|                break;
 1220|      0|            case duringGroup:
  ------------------
  |  Branch (1220:13): [True: 0, False: 410k]
  ------------------
 1221|      0|                sec_asn1e_next_in_group(state);
 1222|      0|                break;
 1223|  46.8k|            case duringSequence:
  ------------------
  |  Branch (1223:13): [True: 46.8k, False: 363k]
  ------------------
 1224|  46.8k|                sec_asn1e_next_in_sequence(state);
 1225|  46.8k|                break;
 1226|   147k|            case afterContents:
  ------------------
  |  Branch (1226:13): [True: 147k, False: 263k]
  ------------------
 1227|   147k|                sec_asn1e_after_contents(state);
 1228|   147k|                break;
 1229|      0|            case afterImplicit:
  ------------------
  |  Branch (1229:13): [True: 0, False: 410k]
  ------------------
 1230|      0|            case afterInline:
  ------------------
  |  Branch (1230:13): [True: 0, False: 410k]
  ------------------
 1231|      0|            case afterPointer:
  ------------------
  |  Branch (1231:13): [True: 0, False: 410k]
  ------------------
 1232|      0|            case afterChoice:
  ------------------
  |  Branch (1232:13): [True: 0, False: 410k]
  ------------------
 1233|       |                /*
 1234|       |                 * These states are more documentation than anything.
 1235|       |                 * They just need to force a pop.
 1236|       |                 */
 1237|      0|                PORT_Assert(!state->indefinite);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1238|      0|                state->place = afterContents;
 1239|      0|                break;
 1240|      0|            case notInUse:
  ------------------
  |  Branch (1240:13): [True: 0, False: 410k]
  ------------------
 1241|      0|            default:
  ------------------
  |  Branch (1241:13): [True: 0, False: 410k]
  ------------------
 1242|       |                /* This is not an error, but rather a plain old BUG! */
 1243|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1244|      0|                cx->status = encodeError;
 1245|      0|                break;
 1246|   410k|        }
 1247|       |
 1248|   410k|        if (cx->status == encodeError)
  ------------------
  |  Branch (1248:13): [True: 0, False: 410k]
  ------------------
 1249|      0|            break;
 1250|       |
 1251|       |        /* It might have changed, so we have to update our local copy.  */
 1252|   410k|        state = cx->current;
 1253|       |
 1254|       |        /* If it is NULL, we have popped all the way to the top.  */
 1255|   410k|        if (state == NULL) {
  ------------------
  |  Branch (1255:13): [True: 100k, False: 310k]
  ------------------
 1256|   100k|            cx->status = allDone;
 1257|   100k|            break;
 1258|   100k|        }
 1259|   410k|    }
 1260|       |
 1261|   100k|    if (cx->status == encodeError) {
  ------------------
  |  Branch (1261:9): [True: 0, False: 100k]
  ------------------
 1262|      0|        return SECFailure;
 1263|      0|    }
 1264|       |
 1265|   100k|    return SECSuccess;
 1266|   100k|}
SEC_ASN1EncoderFinish_Util:
 1270|   100k|{
 1271|       |    /*
 1272|       |     * XXX anything else that needs to be finished?
 1273|       |     */
 1274|       |
 1275|   100k|    PORT_FreeArena(cx->our_pool, PR_FALSE);
  ------------------
  |  |   61|   100k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                  PORT_FreeArena(cx->our_pool, PR_FALSE);
  ------------------
  |  |  438|   100k|#define PR_FALSE 0
  ------------------
 1276|   100k|}
SEC_ASN1EncoderStart_Util:
 1281|   100k|{
 1282|   100k|    PLArenaPool *our_pool;
 1283|   100k|    SEC_ASN1EncoderContext *cx;
 1284|       |
 1285|   100k|    our_pool = PORT_NewArena(SEC_ASN1_DEFAULT_ARENA_SIZE);
  ------------------
  |  |   63|   100k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  our_pool = PORT_NewArena(SEC_ASN1_DEFAULT_ARENA_SIZE);
  ------------------
  |  |   60|   100k|#define SEC_ASN1_DEFAULT_ARENA_SIZE (2048)
  ------------------
 1286|   100k|    if (our_pool == NULL)
  ------------------
  |  Branch (1286:9): [True: 0, False: 100k]
  ------------------
 1287|      0|        return NULL;
 1288|       |
 1289|   100k|    cx = (SEC_ASN1EncoderContext *)PORT_ArenaZAlloc(our_pool, sizeof(*cx));
  ------------------
  |  |   59|   100k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
 1290|   100k|    if (cx == NULL) {
  ------------------
  |  Branch (1290:9): [True: 0, False: 100k]
  ------------------
 1291|      0|        PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1292|      0|        return NULL;
 1293|      0|    }
 1294|       |
 1295|   100k|    cx->our_pool = our_pool;
 1296|   100k|    cx->output_proc = output_proc;
 1297|   100k|    cx->output_arg = output_arg;
 1298|       |
 1299|   100k|    cx->status = keepGoing;
 1300|       |
 1301|   100k|    if (sec_asn1e_push_state(cx, theTemplate, src, PR_FALSE) == NULL ||
  ------------------
  |  |  438|   100k|#define PR_FALSE 0
  ------------------
  |  Branch (1301:9): [True: 0, False: 100k]
  ------------------
 1302|   100k|        sec_asn1e_init_state_based_on_template(cx->current) == NULL) {
  ------------------
  |  Branch (1302:9): [True: 0, False: 100k]
  ------------------
 1303|       |        /*
 1304|       |         * Trouble initializing (probably due to failed allocations)
 1305|       |         * requires that we just give up.
 1306|       |         */
 1307|      0|        PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(our_pool, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
 1308|      0|        return NULL;
 1309|      0|    }
 1310|       |
 1311|   100k|    return cx;
 1312|   100k|}
SEC_ASN1Encode_Util:
 1389|   100k|{
 1390|   100k|    SEC_ASN1EncoderContext *ecx;
 1391|   100k|    SECStatus rv;
 1392|       |
 1393|   100k|    ecx = SEC_ASN1EncoderStart(src, theTemplate, output_proc, output_arg);
  ------------------
  |  |   98|   100k|#define SEC_ASN1EncoderStart SEC_ASN1EncoderStart_Util
  ------------------
 1394|   100k|    if (ecx == NULL)
  ------------------
  |  Branch (1394:9): [True: 0, False: 100k]
  ------------------
 1395|      0|        return SECFailure;
 1396|       |
 1397|   100k|    rv = SEC_ASN1EncoderUpdate(ecx, NULL, 0);
  ------------------
  |  |   99|   100k|#define SEC_ASN1EncoderUpdate SEC_ASN1EncoderUpdate_Util
  ------------------
 1398|       |
 1399|   100k|    SEC_ASN1EncoderFinish(ecx);
  ------------------
  |  |   94|   100k|#define SEC_ASN1EncoderFinish SEC_ASN1EncoderFinish_Util
  ------------------
 1400|   100k|    return rv;
 1401|   100k|}
SEC_ASN1EncodeItem_Util:
 1487|  50.2k|{
 1488|  50.2k|    unsigned long encoding_length;
 1489|  50.2k|    SECStatus rv;
 1490|       |
 1491|  50.2k|    PORT_Assert(dest == NULL || dest->data == NULL);
  ------------------
  |  |  120|  50.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  61.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 38.5k, False: 11.7k]
  |  |  |  |  |  Branch (208:7): [True: 11.7k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1492|       |
 1493|  50.2k|    encoding_length = 0;
 1494|  50.2k|    rv = SEC_ASN1Encode(src, theTemplate,
  ------------------
  |  |   87|  50.2k|#define SEC_ASN1Encode SEC_ASN1Encode_Util
  ------------------
 1495|  50.2k|                        sec_asn1e_encode_item_count, &encoding_length);
 1496|  50.2k|    if (rv != SECSuccess)
  ------------------
  |  Branch (1496:9): [True: 0, False: 50.2k]
  ------------------
 1497|      0|        return NULL;
 1498|       |
 1499|  50.2k|    dest = sec_asn1e_allocate_item(poolp, dest, encoding_length);
 1500|  50.2k|    if (dest == NULL)
  ------------------
  |  Branch (1500:9): [True: 0, False: 50.2k]
  ------------------
 1501|      0|        return NULL;
 1502|       |
 1503|       |    /* XXX necessary?  This really just checks for a bug in the allocate fn */
 1504|  50.2k|    PORT_Assert(dest->data != NULL);
  ------------------
  |  |  120|  50.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  50.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 50.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1505|  50.2k|    if (dest->data == NULL)
  ------------------
  |  Branch (1505:9): [True: 0, False: 50.2k]
  ------------------
 1506|      0|        return NULL;
 1507|       |
 1508|  50.2k|    dest->len = 0;
 1509|  50.2k|    (void)SEC_ASN1Encode(src, theTemplate, sec_asn1e_encode_item_store, dest);
  ------------------
  |  |   87|  50.2k|#define SEC_ASN1Encode SEC_ASN1Encode_Util
  ------------------
 1510|       |
 1511|  50.2k|    PORT_Assert(encoding_length == dest->len);
  ------------------
  |  |  120|  50.2k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  50.2k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 50.2k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1512|  50.2k|    return dest;
 1513|  50.2k|}
secasn1e.c:sec_asn1e_write_header:
  734|   147k|{
  735|   147k|    unsigned long contents_length;
  736|   147k|    unsigned char tag_number, tag_modifiers;
  737|   147k|    sec_asn1e_hdr_encoding hdrException = hdr_normal;
  738|   147k|    PRBool indefinite = PR_FALSE;
  ------------------
  |  |  438|   147k|#define PR_FALSE 0
  ------------------
  739|       |
  740|   147k|    PORT_Assert(state->place == beforeHeader);
  ------------------
  |  |  120|   147k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   147k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 147k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  741|       |
  742|   147k|    tag_number = state->tag_number;
  743|   147k|    tag_modifiers = state->tag_modifiers;
  744|       |
  745|   147k|    if (state->underlying_kind == SEC_ASN1_ANY) {
  ------------------
  |  |  133|   147k|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (745:9): [True: 0, False: 147k]
  ------------------
  746|      0|        state->place = duringContents;
  747|      0|        return;
  748|      0|    }
  749|       |
  750|   147k|    if (state->underlying_kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|   147k|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (750:9): [True: 0, False: 147k]
  ------------------
  751|      0|        int indx = sec_asn1e_which_choice(state->src, state->theTemplate);
  752|      0|        if (0 == indx) {
  ------------------
  |  Branch (752:13): [True: 0, False: 0]
  ------------------
  753|       |            /* XXX set an error? "choice not found" */
  754|      0|            state->top->status = encodeError;
  755|      0|            return;
  756|      0|        }
  757|      0|        state->place = afterChoice;
  758|      0|        state = sec_asn1e_push_state(state->top, &state->theTemplate[indx],
  759|      0|                                     (char *)state->src - state->theTemplate->offset,
  760|      0|                                     PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  761|      0|        if (state) {
  ------------------
  |  Branch (761:13): [True: 0, False: 0]
  ------------------
  762|       |            /*
  763|       |             * Do the "before" field notification.
  764|       |             */
  765|      0|            sec_asn1e_notify_before(state->top, state->src, state->depth);
  766|      0|            (void)sec_asn1e_init_state_based_on_template(state);
  767|      0|        }
  768|      0|        return;
  769|      0|    }
  770|       |
  771|       |    /* The !isString test below is apparently intended to ensure that all
  772|       |    ** constructed types receive indefinite length encoding.
  773|       |    */
  774|   147k|    indefinite = (PRBool)(state->top->streaming && state->may_stream &&
  ------------------
  |  Branch (774:27): [True: 0, False: 147k]
  |  Branch (774:52): [True: 0, False: 0]
  ------------------
  775|   147k|                          (state->top->from_buf || !state->is_string));
  ------------------
  |  Branch (775:28): [True: 0, False: 0]
  |  Branch (775:52): [True: 0, False: 0]
  ------------------
  776|       |
  777|       |    /*
  778|       |     * If we are doing a definite-length encoding, first we have to
  779|       |     * walk the data structure to calculate the entire contents length.
  780|       |     * If we are doing an indefinite-length encoding, we still need to
  781|       |     * know if the contents is:
  782|       |     *    optional and to be omitted, or
  783|       |     *    an ANY (header is pre-encoded), or
  784|       |     *    a SAVE or some other kind of template used only by the decoder.
  785|       |     * So, we call this function either way.
  786|       |     */
  787|   147k|    contents_length = sec_asn1e_contents_length(state->theTemplate,
  788|   147k|                                                state->src,
  789|   147k|                                                state->disallowStreaming,
  790|   147k|                                                indefinite,
  791|   147k|                                                &hdrException);
  792|       |    /*
  793|       |     * We might be told explicitly not to put out a header.
  794|       |     * But it can also be the case, via a pushed subtemplate, that
  795|       |     * sec_asn1e_contents_length could not know that this field is
  796|       |     * really optional.  So check for that explicitly, too.
  797|       |     */
  798|   147k|    if (hdrException != hdr_normal ||
  ------------------
  |  Branch (798:9): [True: 0, False: 147k]
  ------------------
  799|   147k|        (contents_length == 0 && state->optional)) {
  ------------------
  |  Branch (799:10): [True: 54.9k, False: 92.4k]
  |  Branch (799:34): [True: 0, False: 54.9k]
  ------------------
  800|      0|        state->place = afterContents;
  801|      0|        if (state->top->streaming &&
  ------------------
  |  Branch (801:13): [True: 0, False: 0]
  ------------------
  802|      0|            state->may_stream &&
  ------------------
  |  Branch (802:13): [True: 0, False: 0]
  ------------------
  803|      0|            state->top->from_buf) {
  ------------------
  |  Branch (803:13): [True: 0, False: 0]
  ------------------
  804|       |            /* we did not find an optional indefinite string, so we
  805|       |             * don't encode it.  However, if TakeFromBuf is on, we stop
  806|       |             * here anyway to give our caller a chance to intercept at the
  807|       |             * same point where we would stop if the field were present.
  808|       |             */
  809|      0|            state->top->status = needBytes;
  810|      0|        }
  811|      0|        return;
  812|      0|    }
  813|       |
  814|   147k|    if (indefinite) {
  ------------------
  |  Branch (814:9): [True: 0, False: 147k]
  ------------------
  815|       |        /*
  816|       |         * We need to put out an indefinite-length encoding.
  817|       |         * The only universal types that can be constructed are SETs,
  818|       |         * SEQUENCEs, and strings; so check that it is one of those,
  819|       |         * or that it is not universal (e.g. context-specific).
  820|       |         */
  821|      0|        state->indefinite = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  822|      0|        PORT_Assert((tag_number == SEC_ASN1_SET) || (tag_number == SEC_ASN1_SEQUENCE) || ((tag_modifiers & SEC_ASN1_CLASS_MASK) != 0) || state->is_string);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  823|      0|        tag_modifiers |= SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|      0|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  824|      0|        contents_length = 0;
  825|      0|    }
  826|       |
  827|   147k|    sec_asn1e_write_identifier_bytes(state,
  828|   147k|                                     (unsigned char)(tag_number | tag_modifiers));
  829|   147k|    sec_asn1e_write_length_bytes(state, contents_length, state->indefinite);
  830|       |
  831|   147k|    if (contents_length == 0 && !state->indefinite) {
  ------------------
  |  Branch (831:9): [True: 54.9k, False: 92.4k]
  |  Branch (831:33): [True: 54.9k, False: 0]
  ------------------
  832|       |        /*
  833|       |         * If no real contents to encode, then we are done with this field.
  834|       |         */
  835|  54.9k|        state->place = afterContents;
  836|  54.9k|        return;
  837|  54.9k|    }
  838|       |
  839|       |    /*
  840|       |     * An EXPLICIT is nothing but an outer header, which we have already
  841|       |     * written.  Now we need to do the inner header and contents.
  842|       |     */
  843|  92.4k|    if (state->isExplicit) {
  ------------------
  |  Branch (843:9): [True: 0, False: 92.4k]
  ------------------
  844|      0|        const SEC_ASN1Template *subt =
  845|      0|            SEC_ASN1GetSubtemplate(state->theTemplate, state->src, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  846|      0|        state->place = afterContents;
  847|      0|        state = sec_asn1e_push_state(state->top, subt, state->src, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  848|      0|        if (state != NULL) {
  ------------------
  |  Branch (848:13): [True: 0, False: 0]
  ------------------
  849|      0|            (void)sec_asn1e_init_state_based_on_template(state);
  850|      0|        }
  851|      0|        return;
  852|      0|    }
  853|       |
  854|  92.4k|    switch (state->underlying_kind) {
  855|      0|        case SEC_ASN1_SET_OF:
  ------------------
  |  |  167|      0|#define SEC_ASN1_SET_OF (SEC_ASN1_GROUP | SEC_ASN1_SET)
  |  |  ------------------
  |  |  |  |  136|      0|#define SEC_ASN1_GROUP 0x02000        /* with SET or SEQUENCE means \
  |  |  ------------------
  |  |               #define SEC_ASN1_SET_OF (SEC_ASN1_GROUP | SEC_ASN1_SET)
  |  |  ------------------
  |  |  |  |   93|      0|#define SEC_ASN1_SET 0x11
  |  |  ------------------
  ------------------
  |  Branch (855:9): [True: 0, False: 92.4k]
  ------------------
  856|      0|        case SEC_ASN1_SEQUENCE_OF:
  ------------------
  |  |  166|      0|#define SEC_ASN1_SEQUENCE_OF (SEC_ASN1_GROUP | SEC_ASN1_SEQUENCE)
  |  |  ------------------
  |  |  |  |  136|      0|#define SEC_ASN1_GROUP 0x02000        /* with SET or SEQUENCE means \
  |  |  ------------------
  |  |               #define SEC_ASN1_SEQUENCE_OF (SEC_ASN1_GROUP | SEC_ASN1_SEQUENCE)
  |  |  ------------------
  |  |  |  |   92|      0|#define SEC_ASN1_SEQUENCE 0x10
  |  |  ------------------
  ------------------
  |  Branch (856:9): [True: 0, False: 92.4k]
  ------------------
  857|       |            /*
  858|       |             * We need to push a child to handle each member.
  859|       |             */
  860|      0|            {
  861|      0|                void **group;
  862|      0|                const SEC_ASN1Template *subt;
  863|       |
  864|      0|                group = *(void ***)state->src;
  865|      0|                if (group == NULL || *group == NULL) {
  ------------------
  |  Branch (865:21): [True: 0, False: 0]
  |  Branch (865:38): [True: 0, False: 0]
  ------------------
  866|       |                    /*
  867|       |                     * Group is empty; we are done.
  868|       |                     */
  869|      0|                    state->place = afterContents;
  870|      0|                    return;
  871|      0|                }
  872|      0|                state->place = duringGroup;
  873|      0|                subt = SEC_ASN1GetSubtemplate(state->theTemplate, state->src,
  874|      0|                                              PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  875|      0|                state = sec_asn1e_push_state(state->top, subt, *group, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  876|      0|                if (state != NULL) {
  ------------------
  |  Branch (876:21): [True: 0, False: 0]
  ------------------
  877|      0|                    (void)sec_asn1e_init_state_based_on_template(state);
  878|      0|                }
  879|      0|            }
  880|      0|            break;
  881|       |
  882|  23.4k|        case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|  23.4k|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (882:9): [True: 23.4k, False: 68.9k]
  ------------------
  883|  23.4k|        case SEC_ASN1_SET:
  ------------------
  |  |   93|  23.4k|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (883:9): [True: 0, False: 92.4k]
  ------------------
  884|       |            /*
  885|       |             * We need to push a child to handle the individual fields.
  886|       |             */
  887|  23.4k|            state->place = duringSequence;
  888|  23.4k|            state = sec_asn1e_push_state(state->top, state->theTemplate + 1,
  889|  23.4k|                                         state->src, PR_TRUE);
  ------------------
  |  |  437|  23.4k|#define PR_TRUE 1
  ------------------
  890|  23.4k|            if (state != NULL) {
  ------------------
  |  Branch (890:17): [True: 23.4k, False: 0]
  ------------------
  891|       |                /*
  892|       |                 * Do the "before" field notification.
  893|       |                 */
  894|  23.4k|                sec_asn1e_notify_before(state->top, state->src, state->depth);
  895|  23.4k|                (void)sec_asn1e_init_state_based_on_template(state);
  896|  23.4k|            }
  897|  23.4k|            break;
  898|       |
  899|  68.9k|        default:
  ------------------
  |  Branch (899:9): [True: 68.9k, False: 23.4k]
  ------------------
  900|       |            /*
  901|       |             * I think we do not need to do anything else.
  902|       |             * XXX Correct?
  903|       |             */
  904|  68.9k|            state->place = duringContents;
  905|  68.9k|            break;
  906|  92.4k|    }
  907|  92.4k|}
secasn1e.c:sec_asn1e_notify_before:
  141|  46.8k|{
  142|  46.8k|    if (cx->notify_proc == NULL)
  ------------------
  |  Branch (142:9): [True: 46.8k, False: 0]
  ------------------
  143|  46.8k|        return;
  144|       |
  145|      0|    cx->during_notify = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  146|      0|    (*cx->notify_proc)(cx->notify_arg, PR_TRUE, src, depth);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  147|      0|    cx->during_notify = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  148|      0|}
secasn1e.c:sec_asn1e_contents_length:
  471|   194k|{
  472|   194k|    unsigned long encode_kind, underlying_kind;
  473|   194k|    PRBool isExplicit, optional, universal, may_stream;
  474|   194k|    unsigned long len;
  475|       |
  476|       |    /*
  477|       |     * This function currently calculates the length in all cases
  478|       |     * except the following: when writing out the contents of a
  479|       |     * template that belongs to a state where it was a sub-template
  480|       |     * with the SEC_ASN1_MAY_STREAM bit set and it's parent had the
  481|       |     * optional bit set.  The information that the parent is optional
  482|       |     * and that we should return the length of 0 when that length is
  483|       |     * present since that means the optional field is no longer present.
  484|       |     * So we add the disallowStreaming flag which is passed in when
  485|       |     * writing the contents, but for all recursive calls to
  486|       |     * sec_asn1e_contents_length, we pass PR_FALSE, because this
  487|       |     * function correctly calculates the length for children templates
  488|       |     * from that point on.  Confused yet?  At least you didn't have
  489|       |     * to figure it out.  ;)  -javi
  490|       |     */
  491|   194k|    encode_kind = theTemplate->kind;
  492|       |
  493|   194k|    universal = ((encode_kind & SEC_ASN1_CLASS_MASK) == SEC_ASN1_UNIVERSAL)
  ------------------
  |  |  119|   194k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
                  universal = ((encode_kind & SEC_ASN1_CLASS_MASK) == SEC_ASN1_UNIVERSAL)
  ------------------
  |  |  120|   194k|#define SEC_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (493:17): [True: 194k, False: 0]
  ------------------
  494|   194k|                    ? PR_TRUE
  ------------------
  |  |  437|   194k|#define PR_TRUE 1
  ------------------
  495|   194k|                    : PR_FALSE;
  ------------------
  |  |  438|   194k|#define PR_FALSE 0
  ------------------
  496|       |
  497|   194k|    isExplicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  132|   194k|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
                  isExplicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  isExplicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   388k|#define PR_FALSE 0
  ------------------
  |  Branch (497:18): [True: 0, False: 194k]
  ------------------
  498|   194k|    encode_kind &= ~SEC_ASN1_EXPLICIT;
  ------------------
  |  |  132|   194k|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
  499|       |
  500|   194k|    optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  131|   194k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
                  optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   388k|#define PR_FALSE 0
  ------------------
  |  Branch (500:16): [True: 0, False: 194k]
  ------------------
  501|   194k|    encode_kind &= ~SEC_ASN1_OPTIONAL;
  ------------------
  |  |  131|   194k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  502|       |
  503|   194k|    PORT_Assert(!(isExplicit && universal)); /* bad templates */
  ------------------
  |  |  120|   194k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   194k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 194k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  504|       |
  505|   194k|    may_stream = (encode_kind & SEC_ASN1_MAY_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  146|   194k|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
                  may_stream = (encode_kind & SEC_ASN1_MAY_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|  22.1k|#define PR_TRUE 1
  ------------------
                  may_stream = (encode_kind & SEC_ASN1_MAY_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   366k|#define PR_FALSE 0
  ------------------
  |  Branch (505:18): [True: 22.1k, False: 172k]
  ------------------
  506|   194k|    encode_kind &= ~SEC_ASN1_MAY_STREAM;
  ------------------
  |  |  146|   194k|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
  507|       |
  508|       |    /* Just clear this to get it out of the way; we do not need it here */
  509|   194k|    encode_kind &= ~SEC_ASN1_DYNAMIC;
  ------------------
  |  |  138|   194k|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  ------------------
  510|       |
  511|   194k|    if (encode_kind & SEC_ASN1_NO_STREAM) {
  ------------------
  |  |  154|   194k|#define SEC_ASN1_NO_STREAM 0X200000   /* This entry will not stream          \
  ------------------
  |  Branch (511:9): [True: 0, False: 194k]
  ------------------
  512|      0|        disallowStreaming = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  513|      0|    }
  514|   194k|    encode_kind &= ~SEC_ASN1_NO_STREAM;
  ------------------
  |  |  154|   194k|#define SEC_ASN1_NO_STREAM 0X200000   /* This entry will not stream          \
  ------------------
  515|       |
  516|   194k|    if (encode_kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|   194k|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (516:9): [True: 0, False: 194k]
  ------------------
  517|      0|        void *src2;
  518|      0|        int indx = sec_asn1e_which_choice(src, theTemplate);
  519|      0|        if (0 == indx) {
  ------------------
  |  Branch (519:13): [True: 0, False: 0]
  ------------------
  520|       |            /* XXX set an error? "choice not found" */
  521|       |            /* state->top->status = encodeError; */
  522|      0|            return 0;
  523|      0|        }
  524|       |
  525|      0|        src2 = (void *)((char *)src - theTemplate->offset + theTemplate[indx].offset);
  526|       |
  527|      0|        return sec_asn1e_contents_length(&theTemplate[indx], src2,
  528|      0|                                         disallowStreaming, insideIndefinite,
  529|      0|                                         pHdrException);
  530|      0|    }
  531|       |
  532|   194k|    if ((encode_kind & (SEC_ASN1_POINTER | SEC_ASN1_INLINE)) || !universal) {
  ------------------
  |  |  135|   194k|#define SEC_ASN1_POINTER 0x01000
  ------------------
                  if ((encode_kind & (SEC_ASN1_POINTER | SEC_ASN1_INLINE)) || !universal) {
  ------------------
  |  |  134|   194k|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (532:9): [True: 0, False: 194k]
  |  Branch (532:65): [True: 0, False: 194k]
  ------------------
  533|       |        /* XXX any bits we want to disallow (PORT_Assert against) here? */
  534|      0|        theTemplate = SEC_ASN1GetSubtemplate(theTemplate, src, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  535|      0|        if (encode_kind & SEC_ASN1_POINTER) {
  ------------------
  |  |  135|      0|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (535:13): [True: 0, False: 0]
  ------------------
  536|      0|            src = *(void **)src;
  537|      0|            if (src == NULL) {
  ------------------
  |  Branch (537:17): [True: 0, False: 0]
  ------------------
  538|      0|                *pHdrException = optional ? hdr_optional : hdr_normal;
  ------------------
  |  Branch (538:34): [True: 0, False: 0]
  ------------------
  539|      0|                return 0;
  540|      0|            }
  541|      0|        } else if (encode_kind & SEC_ASN1_INLINE) {
  ------------------
  |  |  134|      0|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (541:20): [True: 0, False: 0]
  ------------------
  542|       |            /* check that there are no extraneous bits */
  543|      0|            if (optional) {
  ------------------
  |  Branch (543:17): [True: 0, False: 0]
  ------------------
  544|      0|                if (PR_FALSE != SEC_ASN1IsTemplateSimple(theTemplate)) {
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (544:21): [True: 0, False: 0]
  ------------------
  545|       |                    /* we now know that the target is a SECItem*, so we can check
  546|       |                       if the source contains one */
  547|      0|                    SECItem *target = (SECItem *)src;
  548|      0|                    if (!target || !target->data || !target->len) {
  ------------------
  |  Branch (548:25): [True: 0, False: 0]
  |  Branch (548:36): [True: 0, False: 0]
  |  Branch (548:53): [True: 0, False: 0]
  ------------------
  549|       |                        /* no valid data to encode subtemplate */
  550|      0|                        *pHdrException = hdr_optional;
  551|      0|                        return 0;
  552|      0|                    }
  553|      0|                } else {
  554|      0|                    PORT_Assert(0); /* complex templates not handled as inline
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  555|       |                                       optional */
  556|      0|                }
  557|      0|            }
  558|      0|        }
  559|       |
  560|      0|        src = (char *)src + theTemplate->offset;
  561|       |
  562|       |        /* recurse to find the length of the subtemplate */
  563|      0|        len = sec_asn1e_contents_length(theTemplate, src, disallowStreaming,
  564|      0|                                        insideIndefinite, pHdrException);
  565|      0|        if (len == 0 && optional) {
  ------------------
  |  Branch (565:13): [True: 0, False: 0]
  |  Branch (565:25): [True: 0, False: 0]
  ------------------
  566|      0|            *pHdrException = hdr_optional;
  567|      0|        } else if (isExplicit) {
  ------------------
  |  Branch (567:20): [True: 0, False: 0]
  ------------------
  568|      0|            if (*pHdrException == hdr_any) {
  ------------------
  |  Branch (568:17): [True: 0, False: 0]
  ------------------
  569|       |                /* *we* do not want to add in a header,
  570|       |                ** but our caller still does.
  571|       |                */
  572|      0|                *pHdrException = hdr_normal;
  573|      0|            } else if (*pHdrException == hdr_normal) {
  ------------------
  |  Branch (573:24): [True: 0, False: 0]
  ------------------
  574|       |                /* if the inner content exists, our length is
  575|       |                 * len(identifier) + len(length) + len(innercontent)
  576|       |                 * XXX we currently assume len(identifier) == 1;
  577|       |                 * to support a high-tag-number this would need to be smarter.
  578|       |                 */
  579|      0|                len += 1 + SEC_ASN1LengthLength(len);
  ------------------
  |  |  101|      0|#define SEC_ASN1LengthLength SEC_ASN1LengthLength_Util
  ------------------
  580|      0|            }
  581|      0|        }
  582|      0|        return len;
  583|      0|    }
  584|   194k|    underlying_kind = encode_kind;
  585|       |
  586|       |    /* This is only used in decoding; it plays no part in encoding.  */
  587|   194k|    if (underlying_kind & SEC_ASN1_SAVE) {
  ------------------
  |  |  144|   194k|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  ------------------
  |  Branch (587:9): [True: 0, False: 194k]
  ------------------
  588|       |        /* check that there are no extraneous bits */
  589|      0|        PORT_Assert(underlying_kind == SEC_ASN1_SAVE);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  590|      0|        *pHdrException = hdr_decoder;
  591|      0|        return 0;
  592|      0|    }
  593|       |
  594|   194k|#define UNEXPECTED_FLAGS                                                          \
  595|   194k|    (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_INLINE | SEC_ASN1_POINTER | \
  596|   194k|     SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_SAVE | SEC_ASN1_SKIP)
  597|       |
  598|       |    /* Having any of these bits is not expected here...  */
  599|   194k|    PORT_Assert((underlying_kind & UNEXPECTED_FLAGS) == 0);
  ------------------
  |  |  120|   194k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   194k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 194k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  600|   194k|    underlying_kind &= ~UNEXPECTED_FLAGS;
  ------------------
  |  |  595|   194k|    (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_INLINE | SEC_ASN1_POINTER | \
  |  |  ------------------
  |  |  |  |  132|   194k|#define SEC_ASN1_EXPLICIT 0x00200
  |  |  ------------------
  |  |                   (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_INLINE | SEC_ASN1_POINTER | \
  |  |  ------------------
  |  |  |  |  131|   194k|#define SEC_ASN1_OPTIONAL 0x00100
  |  |  ------------------
  |  |                   (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_INLINE | SEC_ASN1_POINTER | \
  |  |  ------------------
  |  |  |  |  134|   194k|#define SEC_ASN1_INLINE 0x00800
  |  |  ------------------
  |  |                   (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_INLINE | SEC_ASN1_POINTER | \
  |  |  ------------------
  |  |  |  |  135|   194k|#define SEC_ASN1_POINTER 0x01000
  |  |  ------------------
  |  |  596|   194k|     SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_SAVE | SEC_ASN1_SKIP)
  |  |  ------------------
  |  |  |  |  138|   194k|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  |  |  ------------------
  |  |                    SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_SAVE | SEC_ASN1_SKIP)
  |  |  ------------------
  |  |  |  |  146|   194k|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  |  |  ------------------
  |  |                    SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_SAVE | SEC_ASN1_SKIP)
  |  |  ------------------
  |  |  |  |  144|   194k|#define SEC_ASN1_SAVE 0x20000         /* stash away the encoded bytes first; \
  |  |  ------------------
  |  |                    SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_SAVE | SEC_ASN1_SKIP)
  |  |  ------------------
  |  |  |  |  140|   194k|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  |  |  ------------------
  ------------------
  601|   194k|#undef UNEXPECTED_FLAGS
  602|       |
  603|   194k|    if (underlying_kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|   194k|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (603:9): [True: 0, False: 194k]
  ------------------
  604|      0|        void *src2;
  605|      0|        int indx = sec_asn1e_which_choice(src, theTemplate);
  606|      0|        if (0 == indx) {
  ------------------
  |  Branch (606:13): [True: 0, False: 0]
  ------------------
  607|       |            /* XXX set an error? "choice not found" */
  608|       |            /* state->top->status = encodeError; */
  609|      0|            return 0;
  610|      0|        }
  611|       |
  612|      0|        src2 = (void *)((char *)src - theTemplate->offset + theTemplate[indx].offset);
  613|      0|        len = sec_asn1e_contents_length(&theTemplate[indx], src2,
  614|      0|                                        disallowStreaming, insideIndefinite,
  615|      0|                                        pHdrException);
  616|   194k|    } else {
  617|   194k|        switch (underlying_kind) {
  618|      0|            case SEC_ASN1_SEQUENCE_OF:
  ------------------
  |  |  166|      0|#define SEC_ASN1_SEQUENCE_OF (SEC_ASN1_GROUP | SEC_ASN1_SEQUENCE)
  |  |  ------------------
  |  |  |  |  136|      0|#define SEC_ASN1_GROUP 0x02000        /* with SET or SEQUENCE means \
  |  |  ------------------
  |  |               #define SEC_ASN1_SEQUENCE_OF (SEC_ASN1_GROUP | SEC_ASN1_SEQUENCE)
  |  |  ------------------
  |  |  |  |   92|      0|#define SEC_ASN1_SEQUENCE 0x10
  |  |  ------------------
  ------------------
  |  Branch (618:13): [True: 0, False: 194k]
  ------------------
  619|      0|            case SEC_ASN1_SET_OF: {
  ------------------
  |  |  167|      0|#define SEC_ASN1_SET_OF (SEC_ASN1_GROUP | SEC_ASN1_SET)
  |  |  ------------------
  |  |  |  |  136|      0|#define SEC_ASN1_GROUP 0x02000        /* with SET or SEQUENCE means \
  |  |  ------------------
  |  |               #define SEC_ASN1_SET_OF (SEC_ASN1_GROUP | SEC_ASN1_SET)
  |  |  ------------------
  |  |  |  |   93|      0|#define SEC_ASN1_SET 0x11
  |  |  ------------------
  ------------------
  |  Branch (619:13): [True: 0, False: 194k]
  ------------------
  620|      0|                const SEC_ASN1Template *tmpt;
  621|      0|                void *sub_src;
  622|      0|                unsigned long sub_len;
  623|      0|                void **group;
  624|       |
  625|      0|                len = 0;
  626|       |
  627|      0|                group = *(void ***)src;
  628|      0|                if (group == NULL)
  ------------------
  |  Branch (628:21): [True: 0, False: 0]
  ------------------
  629|      0|                    break;
  630|       |
  631|      0|                tmpt = SEC_ASN1GetSubtemplate(theTemplate, src, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  632|       |
  633|      0|                for (; *group != NULL; group++) {
  ------------------
  |  Branch (633:24): [True: 0, False: 0]
  ------------------
  634|      0|                    sub_src = (char *)(*group) + tmpt->offset;
  635|      0|                    sub_len = sec_asn1e_contents_length(tmpt, sub_src,
  636|      0|                                                        disallowStreaming,
  637|      0|                                                        insideIndefinite,
  638|      0|                                                        pHdrException);
  639|      0|                    len += sub_len;
  640|       |                    /*
  641|       |                     * XXX The 1 below is the presumed length of the identifier;
  642|       |                     * to support a high-tag-number this would need to be smarter.
  643|       |                     */
  644|      0|                    if (*pHdrException == hdr_normal)
  ------------------
  |  Branch (644:25): [True: 0, False: 0]
  ------------------
  645|      0|                        len += 1 + SEC_ASN1LengthLength(sub_len);
  ------------------
  |  |  101|      0|#define SEC_ASN1LengthLength SEC_ASN1LengthLength_Util
  ------------------
  646|      0|                }
  647|      0|            } break;
  648|       |
  649|  23.4k|            case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|  23.4k|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (649:13): [True: 23.4k, False: 170k]
  ------------------
  650|  23.4k|            case SEC_ASN1_SET: {
  ------------------
  |  |   93|  23.4k|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (650:13): [True: 0, False: 194k]
  ------------------
  651|  23.4k|                const SEC_ASN1Template *tmpt;
  652|  23.4k|                void *sub_src;
  653|  23.4k|                unsigned long sub_len;
  654|       |
  655|  23.4k|                len = 0;
  656|  70.3k|                for (tmpt = theTemplate + 1; tmpt->kind; tmpt++) {
  ------------------
  |  Branch (656:46): [True: 46.8k, False: 23.4k]
  ------------------
  657|  46.8k|                    sub_src = (char *)src + tmpt->offset;
  658|  46.8k|                    sub_len = sec_asn1e_contents_length(tmpt, sub_src,
  659|  46.8k|                                                        disallowStreaming,
  660|  46.8k|                                                        insideIndefinite,
  661|  46.8k|                                                        pHdrException);
  662|  46.8k|                    len += sub_len;
  663|       |                    /*
  664|       |                     * XXX The 1 below is the presumed length of the identifier;
  665|       |                     * to support a high-tag-number this would need to be smarter.
  666|       |                     */
  667|  46.8k|                    if (*pHdrException == hdr_normal)
  ------------------
  |  Branch (667:25): [True: 46.8k, False: 0]
  ------------------
  668|  46.8k|                        len += 1 + SEC_ASN1LengthLength(sub_len);
  ------------------
  |  |  101|  46.8k|#define SEC_ASN1LengthLength SEC_ASN1LengthLength_Util
  ------------------
  669|  46.8k|                }
  670|  23.4k|            } break;
  671|       |
  672|      0|            case SEC_ASN1_BIT_STRING:
  ------------------
  |  |   79|      0|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (672:13): [True: 0, False: 194k]
  ------------------
  673|       |                /* convert bit length to byte */
  674|      0|                len = (((SECItem *)src)->len + 7) >> 3;
  675|       |                /* bit string contents involve an extra octet */
  676|      0|                if (len)
  ------------------
  |  Branch (676:21): [True: 0, False: 0]
  ------------------
  677|      0|                    len++;
  678|      0|                break;
  679|       |
  680|  93.7k|            case SEC_ASN1_INTEGER:
  ------------------
  |  |   78|  93.7k|#define SEC_ASN1_INTEGER 0x02
  ------------------
  |  Branch (680:13): [True: 93.7k, False: 100k]
  ------------------
  681|       |                /* ASN.1 INTEGERs are signed.
  682|       |                 * If the source is an unsigned integer, the encoder will need
  683|       |                 * to handle the conversion here.
  684|       |                 */
  685|  93.7k|                {
  686|  93.7k|                    unsigned char *buf = ((SECItem *)src)->data;
  687|  93.7k|                    SECItemType integerType = ((SECItem *)src)->type;
  688|  93.7k|                    len = ((SECItem *)src)->len;
  689|  93.7k|                    while (len > 0) {
  ------------------
  |  Branch (689:28): [True: 93.7k, False: 0]
  ------------------
  690|  93.7k|                        if (*buf != 0) {
  ------------------
  |  Branch (690:29): [True: 47.0k, False: 46.7k]
  ------------------
  691|  47.0k|                            if (*buf & 0x80 && integerType == siUnsignedInteger) {
  ------------------
  |  Branch (691:33): [True: 0, False: 47.0k]
  |  Branch (691:48): [True: 0, False: 0]
  ------------------
  692|      0|                                len++; /* leading zero needed to make number signed */
  693|      0|                            }
  694|  47.0k|                            break; /* reached beginning of number */
  695|  47.0k|                        }
  696|  46.7k|                        if (len == 1) {
  ------------------
  |  Branch (696:29): [True: 0, False: 46.7k]
  ------------------
  697|      0|                            break; /* the number 0 */
  698|      0|                        }
  699|  46.7k|                        if (buf[1] & 0x80) {
  ------------------
  |  Branch (699:29): [True: 46.7k, False: 0]
  ------------------
  700|  46.7k|                            break; /* leading zero already present */
  701|  46.7k|                        }
  702|       |                        /* extraneous leading zero, keep going */
  703|      0|                        buf++;
  704|      0|                        len--;
  705|      0|                    }
  706|  93.7k|                }
  707|  93.7k|                break;
  708|       |
  709|  77.0k|            default:
  ------------------
  |  Branch (709:13): [True: 77.0k, False: 117k]
  ------------------
  710|  77.0k|                len = ((SECItem *)src)->len;
  711|  77.0k|                break;
  712|   194k|        } /* end switch */
  713|       |
  714|   194k|#ifndef WHAT_PROBLEM_DOES_THIS_SOLVE
  715|       |        /* if we're streaming, we may have a secitem w/len 0 as placeholder */
  716|   194k|        if (!len && insideIndefinite && may_stream && !disallowStreaming) {
  ------------------
  |  Branch (716:13): [True: 54.9k, False: 139k]
  |  Branch (716:21): [True: 0, False: 54.9k]
  |  Branch (716:41): [True: 0, False: 0]
  |  Branch (716:55): [True: 0, False: 0]
  ------------------
  717|      0|            len = 1;
  718|      0|        }
  719|   194k|#endif
  720|   194k|    } /* end else */
  721|       |
  722|   194k|    if (len == 0 && optional)
  ------------------
  |  Branch (722:9): [True: 54.9k, False: 139k]
  |  Branch (722:21): [True: 0, False: 54.9k]
  ------------------
  723|      0|        *pHdrException = hdr_optional;
  724|   194k|    else if (underlying_kind == SEC_ASN1_ANY)
  ------------------
  |  |  133|   194k|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (724:14): [True: 0, False: 194k]
  ------------------
  725|      0|        *pHdrException = hdr_any;
  726|   194k|    else
  727|   194k|        *pHdrException = hdr_normal;
  728|       |
  729|   194k|    return len;
  730|   194k|}
secasn1e.c:sec_asn1e_write_identifier_bytes:
  388|   147k|{
  389|   147k|    char byte;
  390|       |
  391|   147k|    byte = (char)value;
  392|   147k|    sec_asn1e_write_part(state, &byte, 1, SEC_ASN1_Identifier);
  393|   147k|}
secasn1e.c:sec_asn1e_write_part:
  374|   387k|{
  375|   387k|    SEC_ASN1EncoderContext *cx;
  376|       |
  377|   387k|    cx = state->top;
  378|   387k|    (*cx->output_proc)(cx->output_arg, buf, len, state->depth, part);
  379|   387k|}
secasn1e.c:sec_asn1e_write_length_bytes:
  420|   147k|{
  421|   147k|    int lenlen;
  422|   147k|    unsigned char buf[sizeof(unsigned long) + 1];
  423|       |
  424|   147k|    if (indefinite) {
  ------------------
  |  Branch (424:9): [True: 0, False: 147k]
  ------------------
  425|      0|        PORT_Assert(value == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  426|      0|        buf[0] = 0x80;
  427|      0|        lenlen = 1;
  428|   147k|    } else {
  429|   147k|        lenlen = SEC_ASN1EncodeLength(buf, value);
  430|   147k|    }
  431|       |
  432|   147k|    sec_asn1e_write_part(state, (char *)buf, lenlen, SEC_ASN1_Length);
  433|   147k|}
secasn1e.c:sec_asn1e_write_contents_bytes:
  438|  92.3k|{
  439|  92.3k|    sec_asn1e_write_part(state, buf, len, SEC_ASN1_Contents);
  440|  92.3k|}
secasn1e.c:sec_asn1e_write_contents:
  981|  68.9k|{
  982|  68.9k|    unsigned long len = 0;
  983|       |
  984|  68.9k|    PORT_Assert(state->place == duringContents);
  ------------------
  |  |  120|  68.9k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  68.9k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 68.9k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  985|       |
  986|  68.9k|    switch (state->underlying_kind) {
  987|      0|        case SEC_ASN1_SET:
  ------------------
  |  |   93|      0|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (987:9): [True: 0, False: 68.9k]
  ------------------
  988|      0|        case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|      0|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (988:9): [True: 0, False: 68.9k]
  ------------------
  989|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  990|      0|            break;
  991|       |
  992|      0|        case SEC_ASN1_BIT_STRING: {
  ------------------
  |  |   79|      0|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (992:9): [True: 0, False: 68.9k]
  ------------------
  993|      0|            SECItem *item;
  994|      0|            char rem;
  995|       |
  996|      0|            item = (SECItem *)state->src;
  997|      0|            len = (item->len + 7) >> 3;
  998|      0|            rem = (unsigned char)((len << 3) - item->len); /* remaining bits */
  999|      0|            sec_asn1e_write_contents_bytes(state, &rem, 1);
 1000|      0|            sec_asn1e_write_contents_bytes(state, (char *)item->data, len);
 1001|      0|        } break;
 1002|       |
 1003|      0|        case SEC_ASN1_BMP_STRING:
  ------------------
  |  |  106|      0|#define SEC_ASN1_BMP_STRING 0x1e
  ------------------
  |  Branch (1003:9): [True: 0, False: 68.9k]
  ------------------
 1004|       |            /* The number of bytes must be divisable by 2 */
 1005|      0|            if ((((SECItem *)state->src)->len) % 2) {
  ------------------
  |  Branch (1005:17): [True: 0, False: 0]
  ------------------
 1006|      0|                SEC_ASN1EncoderContext *cx;
 1007|       |
 1008|      0|                cx = state->top;
 1009|      0|                cx->status = encodeError;
 1010|      0|                break;
 1011|      0|            }
 1012|       |            /* otherwise, fall through to write the content */
 1013|      0|            goto process_string;
 1014|       |
 1015|      0|        case SEC_ASN1_UNIVERSAL_STRING:
  ------------------
  |  |  104|      0|#define SEC_ASN1_UNIVERSAL_STRING 0x1c
  ------------------
  |  Branch (1015:9): [True: 0, False: 68.9k]
  ------------------
 1016|       |            /* The number of bytes must be divisable by 4 */
 1017|      0|            if ((((SECItem *)state->src)->len) % 4) {
  ------------------
  |  Branch (1017:17): [True: 0, False: 0]
  ------------------
 1018|      0|                SEC_ASN1EncoderContext *cx;
 1019|       |
 1020|      0|                cx = state->top;
 1021|      0|                cx->status = encodeError;
 1022|      0|                break;
 1023|      0|            }
 1024|       |            /* otherwise, fall through to write the content */
 1025|      0|            goto process_string;
 1026|       |
 1027|  46.8k|        case SEC_ASN1_INTEGER:
  ------------------
  |  |   78|  46.8k|#define SEC_ASN1_INTEGER 0x02
  ------------------
  |  Branch (1027:9): [True: 46.8k, False: 22.1k]
  ------------------
 1028|       |            /* ASN.1 INTEGERs are signed.  If the source is an unsigned
 1029|       |             * integer, the encoder will need to handle the conversion here.
 1030|       |             */
 1031|  46.8k|            {
 1032|  46.8k|                unsigned int blen;
 1033|  46.8k|                unsigned char *buf;
 1034|  46.8k|                SECItemType integerType;
 1035|  46.8k|                blen = ((SECItem *)state->src)->len;
 1036|  46.8k|                buf = ((SECItem *)state->src)->data;
 1037|  46.8k|                integerType = ((SECItem *)state->src)->type;
 1038|  70.2k|                while (blen > 0) {
  ------------------
  |  Branch (1038:24): [True: 70.2k, False: 0]
  ------------------
 1039|  70.2k|                    if (*buf & 0x80 && integerType == siUnsignedInteger) {
  ------------------
  |  Branch (1039:25): [True: 23.3k, False: 46.8k]
  |  Branch (1039:40): [True: 23.3k, False: 0]
  ------------------
 1040|  23.3k|                        char zero = 0; /* write a leading 0 */
 1041|  23.3k|                        sec_asn1e_write_contents_bytes(state, &zero, 1);
 1042|       |                        /* and then the remaining buffer */
 1043|  23.3k|                        sec_asn1e_write_contents_bytes(state,
 1044|  23.3k|                                                       (char *)buf, blen);
 1045|  23.3k|                        break;
 1046|  23.3k|                    }
 1047|       |                    /* Check three possibilities:
 1048|       |                     * 1.  No leading zeros, msb of MSB is not 1;
 1049|       |                     * 2.  The number is zero itself;
 1050|       |                     * 3.  Encoding a signed integer with a leading zero,
 1051|       |                     *     keep the zero so that the number is positive.
 1052|       |                     */
 1053|  46.8k|                    if (*buf != 0 ||
  ------------------
  |  Branch (1053:25): [True: 23.5k, False: 23.3k]
  ------------------
 1054|  46.8k|                        blen == 1 ||
  ------------------
  |  Branch (1054:25): [True: 0, False: 23.3k]
  ------------------
 1055|  46.8k|                        (buf[1] & 0x80 && integerType != siUnsignedInteger)) {
  ------------------
  |  Branch (1055:26): [True: 23.3k, False: 0]
  |  Branch (1055:43): [True: 0, False: 23.3k]
  ------------------
 1056|  23.5k|                        sec_asn1e_write_contents_bytes(state,
 1057|  23.5k|                                                       (char *)buf, blen);
 1058|  23.5k|                        break;
 1059|  23.5k|                    }
 1060|       |                    /* byte is 0, continue */
 1061|  23.3k|                    buf++;
 1062|  23.3k|                    blen--;
 1063|  23.3k|                }
 1064|  46.8k|            }
 1065|       |            /* done with this content */
 1066|  46.8k|            break;
 1067|       |
 1068|      0|        process_string:
 1069|  22.1k|        default: {
  ------------------
  |  Branch (1069:9): [True: 22.1k, False: 46.8k]
  ------------------
 1070|  22.1k|            SECItem *item;
 1071|       |
 1072|  22.1k|            item = (SECItem *)state->src;
 1073|  22.1k|            sec_asn1e_write_contents_bytes(state, (char *)item->data,
 1074|  22.1k|                                           item->len);
 1075|  22.1k|        } break;
 1076|  68.9k|    }
 1077|  68.9k|    state->place = afterContents;
 1078|  68.9k|}
secasn1e.c:sec_asn1e_scrub_state:
  130|   147k|{
  131|       |    /*
  132|       |     * Some default "scrubbing".
  133|       |     * XXX right set of initializations?
  134|       |     */
  135|   147k|    state->place = beforeHeader;
  136|   147k|    state->indefinite = PR_FALSE;
  ------------------
  |  |  438|   147k|#define PR_FALSE 0
  ------------------
  137|   147k|}
secasn1e.c:sec_asn1e_next_in_sequence:
 1131|  46.8k|{
 1132|  46.8k|    sec_asn1e_state *child;
 1133|       |
 1134|  46.8k|    PORT_Assert(state->place == duringSequence);
  ------------------
  |  |  120|  46.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  46.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 46.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1135|  46.8k|    PORT_Assert(state->child != NULL);
  ------------------
  |  |  120|  46.8k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  46.8k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 46.8k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1136|       |
 1137|  46.8k|    child = state->child;
 1138|       |
 1139|       |    /*
 1140|       |     * Do the "after" field notification.
 1141|       |     */
 1142|  46.8k|    sec_asn1e_notify_after(state->top, child->src, child->depth);
 1143|       |
 1144|       |    /*
 1145|       |     * Move forward.
 1146|       |     */
 1147|  46.8k|    child->theTemplate++;
 1148|  46.8k|    if (child->theTemplate->kind == 0) {
  ------------------
  |  Branch (1148:9): [True: 23.4k, False: 23.4k]
  ------------------
 1149|       |        /*
 1150|       |         * We are done with this sequence.
 1151|       |         */
 1152|  23.4k|        child->place = notInUse;
 1153|  23.4k|        state->place = afterContents;
 1154|  23.4k|        return;
 1155|  23.4k|    }
 1156|       |
 1157|       |    /*
 1158|       |     * Reset state and push.
 1159|       |     */
 1160|       |
 1161|  23.4k|    child->src = (char *)state->src + child->theTemplate->offset;
 1162|       |
 1163|       |    /*
 1164|       |     * Do the "before" field notification.
 1165|       |     */
 1166|  23.4k|    sec_asn1e_notify_before(state->top, child->src, child->depth);
 1167|       |
 1168|  23.4k|    state->top->current = child;
 1169|  23.4k|    (void)sec_asn1e_init_state_based_on_template(child);
 1170|  23.4k|}
secasn1e.c:sec_asn1e_notify_after:
  152|  46.8k|{
  153|  46.8k|    if (cx->notify_proc == NULL)
  ------------------
  |  Branch (153:9): [True: 46.8k, False: 0]
  ------------------
  154|  46.8k|        return;
  155|       |
  156|      0|    cx->during_notify = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  157|      0|    (*cx->notify_proc)(cx->notify_arg, PR_FALSE, src, depth);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  158|      0|    cx->during_notify = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  159|      0|}
secasn1e.c:sec_asn1e_after_contents:
 1174|   147k|{
 1175|   147k|    PORT_Assert(state->place == afterContents);
  ------------------
  |  |  120|   147k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   147k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 147k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1176|       |
 1177|   147k|    if (state->indefinite)
  ------------------
  |  Branch (1177:9): [True: 0, False: 147k]
  ------------------
 1178|      0|        sec_asn1e_write_end_of_contents_bytes(state);
 1179|       |
 1180|       |    /*
 1181|       |     * Just make my parent be the current state.  It will then clean
 1182|       |     * up after me and free me (or reuse me).
 1183|       |     */
 1184|   147k|    state->top->current = state->parent;
 1185|   147k|}
secasn1e.c:sec_asn1e_push_state:
   94|   123k|{
   95|   123k|    sec_asn1e_state *state, *new_state;
   96|       |
   97|   123k|    if (theTemplate == NULL) {
  ------------------
  |  Branch (97:9): [True: 0, False: 123k]
  ------------------
   98|      0|        cx->status = encodeError;
   99|      0|        return NULL;
  100|      0|    }
  101|       |
  102|   123k|    state = cx->current;
  103|   123k|    new_state = (sec_asn1e_state *)PORT_ArenaZAlloc(cx->our_pool,
  ------------------
  |  |   59|   123k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
  104|   123k|                                                    sizeof(*new_state));
  105|   123k|    if (new_state == NULL) {
  ------------------
  |  Branch (105:9): [True: 0, False: 123k]
  ------------------
  106|      0|        cx->status = encodeError;
  107|      0|        return NULL;
  108|      0|    }
  109|       |
  110|   123k|    new_state->top = cx;
  111|   123k|    new_state->parent = state;
  112|   123k|    new_state->theTemplate = theTemplate;
  113|   123k|    new_state->place = notInUse;
  114|   123k|    if (src != NULL)
  ------------------
  |  Branch (114:9): [True: 123k, False: 0]
  ------------------
  115|   123k|        new_state->src = (char *)src + theTemplate->offset;
  116|       |
  117|   123k|    if (state != NULL) {
  ------------------
  |  Branch (117:9): [True: 23.4k, False: 100k]
  ------------------
  118|  23.4k|        new_state->depth = state->depth;
  119|  23.4k|        if (new_depth)
  ------------------
  |  Branch (119:13): [True: 23.4k, False: 0]
  ------------------
  120|  23.4k|            new_state->depth++;
  121|  23.4k|        state->child = new_state;
  122|  23.4k|    }
  123|       |
  124|   123k|    cx->current = new_state;
  125|   123k|    return new_state;
  126|   123k|}
secasn1e.c:sec_asn1e_init_state_based_on_template:
  163|   147k|{
  164|   147k|    PRBool isExplicit, is_string, may_stream, optional, universal;
  165|   147k|    PRBool disallowStreaming;
  166|   147k|    unsigned char tag_modifiers;
  167|   147k|    unsigned long encode_kind, under_kind;
  168|   147k|    unsigned long tag_number;
  169|   147k|    PRBool isInline = PR_FALSE;
  ------------------
  |  |  438|   147k|#define PR_FALSE 0
  ------------------
  170|       |
  171|   147k|    encode_kind = state->theTemplate->kind;
  172|       |
  173|   147k|    universal = ((encode_kind & SEC_ASN1_CLASS_MASK) == SEC_ASN1_UNIVERSAL)
  ------------------
  |  |  119|   147k|#define SEC_ASN1_CLASS_MASK 0xc0
  ------------------
                  universal = ((encode_kind & SEC_ASN1_CLASS_MASK) == SEC_ASN1_UNIVERSAL)
  ------------------
  |  |  120|   147k|#define SEC_ASN1_UNIVERSAL 0x00
  ------------------
  |  Branch (173:17): [True: 147k, False: 0]
  ------------------
  174|   147k|                    ? PR_TRUE
  ------------------
  |  |  437|   147k|#define PR_TRUE 1
  ------------------
  175|   147k|                    : PR_FALSE;
  ------------------
  |  |  438|   147k|#define PR_FALSE 0
  ------------------
  176|       |
  177|   147k|    isExplicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  132|   147k|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
                  isExplicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  isExplicit = (encode_kind & SEC_ASN1_EXPLICIT) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   294k|#define PR_FALSE 0
  ------------------
  |  Branch (177:18): [True: 0, False: 147k]
  ------------------
  178|   147k|    encode_kind &= ~SEC_ASN1_EXPLICIT;
  ------------------
  |  |  132|   147k|#define SEC_ASN1_EXPLICIT 0x00200
  ------------------
  179|       |
  180|   147k|    optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  131|   147k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
                  optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  optional = (encode_kind & SEC_ASN1_OPTIONAL) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   294k|#define PR_FALSE 0
  ------------------
  |  Branch (180:16): [True: 0, False: 147k]
  ------------------
  181|   147k|    encode_kind &= ~SEC_ASN1_OPTIONAL;
  ------------------
  |  |  131|   147k|#define SEC_ASN1_OPTIONAL 0x00100
  ------------------
  182|       |
  183|   147k|    PORT_Assert(!(isExplicit && universal)); /* bad templates */
  ------------------
  |  |  120|   147k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   147k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 0, False: 147k]
  |  |  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  184|       |
  185|   147k|    may_stream = (encode_kind & SEC_ASN1_MAY_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  146|   147k|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
                  may_stream = (encode_kind & SEC_ASN1_MAY_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|  22.1k|#define PR_TRUE 1
  ------------------
                  may_stream = (encode_kind & SEC_ASN1_MAY_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   272k|#define PR_FALSE 0
  ------------------
  |  Branch (185:18): [True: 22.1k, False: 125k]
  ------------------
  186|   147k|    encode_kind &= ~SEC_ASN1_MAY_STREAM;
  ------------------
  |  |  146|   147k|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
  187|       |
  188|   147k|    disallowStreaming = (encode_kind & SEC_ASN1_NO_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  154|   147k|#define SEC_ASN1_NO_STREAM 0X200000   /* This entry will not stream          \
  ------------------
                  disallowStreaming = (encode_kind & SEC_ASN1_NO_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                  disallowStreaming = (encode_kind & SEC_ASN1_NO_STREAM) ? PR_TRUE : PR_FALSE;
  ------------------
  |  |  438|   294k|#define PR_FALSE 0
  ------------------
  |  Branch (188:25): [True: 0, False: 147k]
  ------------------
  189|   147k|    encode_kind &= ~SEC_ASN1_NO_STREAM;
  ------------------
  |  |  154|   147k|#define SEC_ASN1_NO_STREAM 0X200000   /* This entry will not stream          \
  ------------------
  190|       |
  191|       |    /* Just clear this to get it out of the way; we do not need it here */
  192|   147k|    encode_kind &= ~SEC_ASN1_DYNAMIC;
  ------------------
  |  |  138|   147k|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  ------------------
  193|       |
  194|   147k|    if (encode_kind & SEC_ASN1_CHOICE) {
  ------------------
  |  |  153|   147k|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  |  Branch (194:9): [True: 0, False: 147k]
  ------------------
  195|      0|        under_kind = SEC_ASN1_CHOICE;
  ------------------
  |  |  153|      0|#define SEC_ASN1_CHOICE 0x100000      /* pick one from a template */
  ------------------
  196|   147k|    } else if ((encode_kind & (SEC_ASN1_POINTER | SEC_ASN1_INLINE)) ||
  ------------------
  |  |  135|   147k|#define SEC_ASN1_POINTER 0x01000
  ------------------
                  } else if ((encode_kind & (SEC_ASN1_POINTER | SEC_ASN1_INLINE)) ||
  ------------------
  |  |  134|   147k|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (196:16): [True: 0, False: 147k]
  ------------------
  197|   147k|               (!universal && !isExplicit)) {
  ------------------
  |  Branch (197:17): [True: 0, False: 147k]
  |  Branch (197:31): [True: 0, False: 0]
  ------------------
  198|      0|        const SEC_ASN1Template *subt;
  199|      0|        void *src = NULL;
  200|       |
  201|      0|        PORT_Assert((encode_kind & (SEC_ASN1_ANY | SEC_ASN1_SKIP)) == 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  202|       |
  203|      0|        sec_asn1e_scrub_state(state);
  204|       |
  205|      0|        if (encode_kind & SEC_ASN1_POINTER) {
  ------------------
  |  |  135|      0|#define SEC_ASN1_POINTER 0x01000
  ------------------
  |  Branch (205:13): [True: 0, False: 0]
  ------------------
  206|      0|            src = *(void **)state->src;
  207|      0|            state->place = afterPointer;
  208|       |
  209|      0|            if (src == NULL) {
  ------------------
  |  Branch (209:17): [True: 0, False: 0]
  ------------------
  210|       |                /*
  211|       |                 * If this is optional, but NULL, then the field does
  212|       |                 * not need to be encoded.  In this case we are done;
  213|       |                 * we do not want to push a subtemplate.
  214|       |                 */
  215|      0|                if (optional)
  ------------------
  |  Branch (215:21): [True: 0, False: 0]
  ------------------
  216|      0|                    return state;
  217|       |
  218|       |                /*
  219|       |                 * XXX this is an error; need to figure out
  220|       |                 * how to handle this
  221|       |                 */
  222|      0|            }
  223|      0|        } else {
  224|      0|            src = state->src;
  225|      0|            if (encode_kind & SEC_ASN1_INLINE) {
  ------------------
  |  |  134|      0|#define SEC_ASN1_INLINE 0x00800
  ------------------
  |  Branch (225:17): [True: 0, False: 0]
  ------------------
  226|       |                /* check that there are no extraneous bits */
  227|       |                /* PORT_Assert (encode_kind == SEC_ASN1_INLINE && !optional); */
  228|      0|                state->place = afterInline;
  229|      0|                isInline = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  230|      0|            } else {
  231|       |                /*
  232|       |                 * Save the tag modifiers and tag number here before moving
  233|       |                 * on to the next state in case this is a member of a
  234|       |                 * SEQUENCE OF
  235|       |                 */
  236|      0|                state->tag_modifiers = (unsigned char)(encode_kind & (SEC_ASN1_TAG_MASK & ~SEC_ASN1_TAGNUM_MASK));
  ------------------
  |  |   65|      0|#define SEC_ASN1_TAG_MASK 0xff
  ------------------
                              state->tag_modifiers = (unsigned char)(encode_kind & (SEC_ASN1_TAG_MASK & ~SEC_ASN1_TAGNUM_MASK));
  ------------------
  |  |   76|      0|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  237|      0|                state->tag_number = (unsigned char)(encode_kind & SEC_ASN1_TAGNUM_MASK);
  ------------------
  |  |   76|      0|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  238|       |
  239|      0|                state->place = afterImplicit;
  240|      0|                state->optional = optional;
  241|      0|            }
  242|      0|        }
  243|       |
  244|      0|        subt = SEC_ASN1GetSubtemplate(state->theTemplate, state->src, PR_TRUE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  245|      0|        if (isInline && optional) {
  ------------------
  |  Branch (245:13): [True: 0, False: 0]
  |  Branch (245:25): [True: 0, False: 0]
  ------------------
  246|       |            /* we only handle a very limited set of optional inline cases at
  247|       |               this time */
  248|      0|            if (PR_FALSE != SEC_ASN1IsTemplateSimple(subt)) {
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (248:17): [True: 0, False: 0]
  ------------------
  249|       |                /* we now know that the target is a SECItem*, so we can check
  250|       |                   if the source contains one */
  251|      0|                SECItem *target = (SECItem *)state->src;
  252|      0|                if (!target || !target->data || !target->len) {
  ------------------
  |  Branch (252:21): [True: 0, False: 0]
  |  Branch (252:32): [True: 0, False: 0]
  |  Branch (252:49): [True: 0, False: 0]
  ------------------
  253|       |                    /* no valid data to encode subtemplate */
  254|      0|                    return state;
  255|      0|                }
  256|      0|            } else {
  257|      0|                PORT_Assert(0); /* complex templates are not handled as
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  258|       |                                   inline optional */
  259|      0|            }
  260|      0|        }
  261|      0|        state = sec_asn1e_push_state(state->top, subt, src, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  262|      0|        if (state == NULL)
  ------------------
  |  Branch (262:13): [True: 0, False: 0]
  ------------------
  263|      0|            return state;
  264|       |
  265|      0|        if (universal) {
  ------------------
  |  Branch (265:13): [True: 0, False: 0]
  ------------------
  266|       |            /*
  267|       |             * This is a POINTER or INLINE; just init based on that
  268|       |             * and we are done.
  269|       |             */
  270|      0|            return sec_asn1e_init_state_based_on_template(state);
  271|      0|        }
  272|       |
  273|       |        /*
  274|       |         * This is an implicit, non-universal (meaning, application-private
  275|       |         * or context-specific) field.  This results in a "magic" tag but
  276|       |         * encoding based on the underlying type.  We pushed a new state
  277|       |         * that is based on the subtemplate (the underlying type), but
  278|       |         * now we will sort of alias it to give it some of our properties
  279|       |         * (tag, optional status, etc.).
  280|       |         *
  281|       |         * NB: ALL the following flags in the subtemplate are disallowed
  282|       |         *     and/or ignored: EXPLICIT, OPTIONAL, INNER, INLINE, POINTER.
  283|       |         */
  284|       |
  285|      0|        under_kind = state->theTemplate->kind;
  286|      0|        if ((under_kind & SEC_ASN1_MAY_STREAM) && !disallowStreaming) {
  ------------------
  |  |  146|      0|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
  |  Branch (286:13): [True: 0, False: 0]
  |  Branch (286:51): [True: 0, False: 0]
  ------------------
  287|      0|            may_stream = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  288|      0|        }
  289|      0|        under_kind &= ~(SEC_ASN1_MAY_STREAM | SEC_ASN1_DYNAMIC);
  ------------------
  |  |  146|      0|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  ------------------
                      under_kind &= ~(SEC_ASN1_MAY_STREAM | SEC_ASN1_DYNAMIC);
  ------------------
  |  |  138|      0|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  ------------------
  290|   147k|    } else {
  291|   147k|        under_kind = encode_kind;
  292|   147k|    }
  293|       |
  294|       |/*
  295|       | * Sanity check that there are no unwanted bits marked in under_kind.
  296|       | * These bits were either removed above (after we recorded them) or
  297|       | * they simply should not be found (signalling a bad/broken template).
  298|       | * XXX is this the right set of bits to test here? (i.e. need to add
  299|       | * or remove any?)
  300|       | */
  301|   147k|#define UNEXPECTED_FLAGS                                                      \
  302|   147k|    (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_SKIP | SEC_ASN1_INNER | \
  303|   147k|     SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_INLINE | SEC_ASN1_POINTER)
  304|       |
  305|   147k|    PORT_Assert((under_kind & UNEXPECTED_FLAGS) == 0);
  ------------------
  |  |  120|   147k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   147k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 147k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  306|   147k|    under_kind &= ~UNEXPECTED_FLAGS;
  ------------------
  |  |  302|   147k|    (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_SKIP | SEC_ASN1_INNER | \
  |  |  ------------------
  |  |  |  |  132|   147k|#define SEC_ASN1_EXPLICIT 0x00200
  |  |  ------------------
  |  |                   (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_SKIP | SEC_ASN1_INNER | \
  |  |  ------------------
  |  |  |  |  131|   147k|#define SEC_ASN1_OPTIONAL 0x00100
  |  |  ------------------
  |  |                   (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_SKIP | SEC_ASN1_INNER | \
  |  |  ------------------
  |  |  |  |  140|   147k|#define SEC_ASN1_SKIP 0x08000         /* skip a field; only for decoding */
  |  |  ------------------
  |  |                   (SEC_ASN1_EXPLICIT | SEC_ASN1_OPTIONAL | SEC_ASN1_SKIP | SEC_ASN1_INNER | \
  |  |  ------------------
  |  |  |  |  141|   147k|#define SEC_ASN1_INNER 0x10000        /* with ANY means capture the      \
  |  |  ------------------
  |  |  303|   147k|     SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_INLINE | SEC_ASN1_POINTER)
  |  |  ------------------
  |  |  |  |  138|   147k|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  |  |  ------------------
  |  |                    SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_INLINE | SEC_ASN1_POINTER)
  |  |  ------------------
  |  |  |  |  146|   147k|#define SEC_ASN1_MAY_STREAM 0x40000   /* field or one of its sub-fields may \
  |  |  ------------------
  |  |                    SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_INLINE | SEC_ASN1_POINTER)
  |  |  ------------------
  |  |  |  |  134|   147k|#define SEC_ASN1_INLINE 0x00800
  |  |  ------------------
  |  |                    SEC_ASN1_DYNAMIC | SEC_ASN1_MAY_STREAM | SEC_ASN1_INLINE | SEC_ASN1_POINTER)
  |  |  ------------------
  |  |  |  |  135|   147k|#define SEC_ASN1_POINTER 0x01000
  |  |  ------------------
  ------------------
  307|   147k|#undef UNEXPECTED_FLAGS
  308|       |
  309|   147k|    if (encode_kind & SEC_ASN1_ANY) {
  ------------------
  |  |  133|   147k|#define SEC_ASN1_ANY 0x00400
  ------------------
  |  Branch (309:9): [True: 0, False: 147k]
  ------------------
  310|      0|        PORT_Assert(encode_kind == under_kind);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  311|      0|        tag_modifiers = 0;
  312|      0|        tag_number = 0;
  313|      0|        is_string = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  314|   147k|    } else {
  315|   147k|        tag_modifiers = (unsigned char)(encode_kind & (SEC_ASN1_TAG_MASK & ~SEC_ASN1_TAGNUM_MASK));
  ------------------
  |  |   65|   147k|#define SEC_ASN1_TAG_MASK 0xff
  ------------------
                      tag_modifiers = (unsigned char)(encode_kind & (SEC_ASN1_TAG_MASK & ~SEC_ASN1_TAGNUM_MASK));
  ------------------
  |  |   76|   147k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  316|       |        /*
  317|       |         * XXX This assumes only single-octet identifiers.  To handle
  318|       |         * the HIGH TAG form we would need to do some more work, especially
  319|       |         * in how to specify them in the template, because right now we
  320|       |         * do not provide a way to specify more *tag* bits in encode_kind.
  321|       |         */
  322|   147k|        tag_number = encode_kind & SEC_ASN1_TAGNUM_MASK;
  ------------------
  |  |   76|   147k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  323|       |
  324|   147k|        is_string = PR_FALSE;
  ------------------
  |  |  438|   147k|#define PR_FALSE 0
  ------------------
  325|   147k|        switch (under_kind & SEC_ASN1_TAGNUM_MASK) {
  ------------------
  |  |   76|   147k|#define SEC_ASN1_TAGNUM_MASK 0x1f
  ------------------
  |  Branch (325:17): [True: 101k, False: 45.5k]
  ------------------
  326|      0|            case SEC_ASN1_SET:
  ------------------
  |  |   93|      0|#define SEC_ASN1_SET 0x11
  ------------------
  |  Branch (326:13): [True: 0, False: 147k]
  ------------------
  327|       |                /*
  328|       |                 * XXX A plain old SET (as opposed to a SET OF) is not implemented.
  329|       |                 * If it ever is, remove this assert...
  330|       |                 */
  331|      0|                PORT_Assert((under_kind & SEC_ASN1_GROUP) != 0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  332|       |            /* fallthru */
  333|  23.4k|            case SEC_ASN1_SEQUENCE:
  ------------------
  |  |   92|  23.4k|#define SEC_ASN1_SEQUENCE 0x10
  ------------------
  |  Branch (333:13): [True: 23.4k, False: 123k]
  ------------------
  334|  23.4k|                tag_modifiers |= SEC_ASN1_CONSTRUCTED;
  ------------------
  |  |  117|  23.4k|#define SEC_ASN1_CONSTRUCTED 0x20
  ------------------
  335|  23.4k|                break;
  336|      0|            case SEC_ASN1_BIT_STRING:
  ------------------
  |  |   79|      0|#define SEC_ASN1_BIT_STRING 0x03
  ------------------
  |  Branch (336:13): [True: 0, False: 147k]
  ------------------
  337|      0|            case SEC_ASN1_BMP_STRING:
  ------------------
  |  |  106|      0|#define SEC_ASN1_BMP_STRING 0x1e
  ------------------
  |  Branch (337:13): [True: 0, False: 147k]
  ------------------
  338|      0|            case SEC_ASN1_GENERALIZED_TIME:
  ------------------
  |  |  100|      0|#define SEC_ASN1_GENERALIZED_TIME 0x18
  ------------------
  |  Branch (338:13): [True: 0, False: 147k]
  ------------------
  339|      0|            case SEC_ASN1_IA5_STRING:
  ------------------
  |  |   98|      0|#define SEC_ASN1_IA5_STRING 0x16
  ------------------
  |  Branch (339:13): [True: 0, False: 147k]
  ------------------
  340|  22.1k|            case SEC_ASN1_OCTET_STRING:
  ------------------
  |  |   80|  22.1k|#define SEC_ASN1_OCTET_STRING 0x04
  ------------------
  |  Branch (340:13): [True: 22.1k, False: 125k]
  ------------------
  341|  22.1k|            case SEC_ASN1_PRINTABLE_STRING:
  ------------------
  |  |   95|  22.1k|#define SEC_ASN1_PRINTABLE_STRING 0x13
  ------------------
  |  Branch (341:13): [True: 0, False: 147k]
  ------------------
  342|  22.1k|            case SEC_ASN1_T61_STRING:
  ------------------
  |  |   96|  22.1k|#define SEC_ASN1_T61_STRING 0x14
  ------------------
  |  Branch (342:13): [True: 0, False: 147k]
  ------------------
  343|  22.1k|            case SEC_ASN1_UNIVERSAL_STRING:
  ------------------
  |  |  104|  22.1k|#define SEC_ASN1_UNIVERSAL_STRING 0x1c
  ------------------
  |  Branch (343:13): [True: 0, False: 147k]
  ------------------
  344|  22.1k|            case SEC_ASN1_UTC_TIME:
  ------------------
  |  |   99|  22.1k|#define SEC_ASN1_UTC_TIME 0x17
  ------------------
  |  Branch (344:13): [True: 0, False: 147k]
  ------------------
  345|  22.1k|            case SEC_ASN1_UTF8_STRING:
  ------------------
  |  |   88|  22.1k|#define SEC_ASN1_UTF8_STRING 0x0c
  ------------------
  |  Branch (345:13): [True: 0, False: 147k]
  ------------------
  346|  22.1k|            case SEC_ASN1_VISIBLE_STRING:
  ------------------
  |  |  102|  22.1k|#define SEC_ASN1_VISIBLE_STRING 0x1a
  ------------------
  |  Branch (346:13): [True: 0, False: 147k]
  ------------------
  347|       |                /*
  348|       |                 * We do not yet know if we will be constructing the string,
  349|       |                 * so we have to wait to do this final tag modification.
  350|       |                 */
  351|  22.1k|                is_string = PR_TRUE;
  ------------------
  |  |  437|  22.1k|#define PR_TRUE 1
  ------------------
  352|  22.1k|                break;
  353|   147k|        }
  354|   147k|    }
  355|       |
  356|   147k|    state->tag_modifiers = tag_modifiers;
  357|   147k|    state->tag_number = (unsigned char)tag_number;
  358|   147k|    state->underlying_kind = under_kind;
  359|   147k|    state->isExplicit = isExplicit;
  360|   147k|    state->may_stream = may_stream;
  361|   147k|    state->is_string = is_string;
  362|   147k|    state->optional = optional;
  363|   147k|    state->disallowStreaming = disallowStreaming;
  364|       |
  365|   147k|    sec_asn1e_scrub_state(state);
  366|       |
  367|   147k|    return state;
  368|   147k|}
secasn1e.c:sec_asn1e_encode_item_count:
 1410|   193k|{
 1411|   193k|    unsigned long *count;
 1412|       |
 1413|   193k|    count = (unsigned long *)arg;
 1414|   193k|    PORT_Assert(count != NULL);
  ------------------
  |  |  120|   193k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   193k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 193k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1415|       |
 1416|   193k|    *count += len;
 1417|   193k|}
secasn1e.c:sec_asn1e_allocate_item:
 1444|  50.2k|{
 1445|  50.2k|    if (poolp != NULL) {
  ------------------
  |  Branch (1445:9): [True: 0, False: 50.2k]
  ------------------
 1446|      0|        void *release;
 1447|       |
 1448|      0|        release = PORT_ArenaMark(poolp);
  ------------------
  |  |   55|      0|#define PORT_ArenaMark PORT_ArenaMark_Util
  ------------------
 1449|      0|        if (dest == NULL)
  ------------------
  |  Branch (1449:13): [True: 0, False: 0]
  ------------------
 1450|      0|            dest = (SECItem *)PORT_ArenaAlloc(poolp, sizeof(SECItem));
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1451|      0|        if (dest != NULL) {
  ------------------
  |  Branch (1451:13): [True: 0, False: 0]
  ------------------
 1452|      0|            dest->data = (unsigned char *)PORT_ArenaAlloc(poolp, len);
  ------------------
  |  |   53|      0|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
 1453|      0|            if (dest->data == NULL) {
  ------------------
  |  Branch (1453:17): [True: 0, False: 0]
  ------------------
 1454|      0|                dest = NULL;
 1455|      0|            }
 1456|      0|        }
 1457|      0|        if (dest == NULL) {
  ------------------
  |  Branch (1457:13): [True: 0, False: 0]
  ------------------
 1458|       |            /* one or both allocations failed; release everything */
 1459|      0|            PORT_ArenaRelease(poolp, release);
  ------------------
  |  |   56|      0|#define PORT_ArenaRelease PORT_ArenaRelease_Util
  ------------------
 1460|      0|        } else {
 1461|       |            /* everything okay; unmark the arena */
 1462|      0|            PORT_ArenaUnmark(poolp, release);
  ------------------
  |  |   58|      0|#define PORT_ArenaUnmark PORT_ArenaUnmark_Util
  ------------------
 1463|      0|        }
 1464|  50.2k|    } else {
 1465|  50.2k|        SECItem *indest;
 1466|       |
 1467|  50.2k|        indest = dest;
 1468|  50.2k|        if (dest == NULL)
  ------------------
  |  Branch (1468:13): [True: 38.5k, False: 11.7k]
  ------------------
 1469|  38.5k|            dest = (SECItem *)PORT_Alloc(sizeof(SECItem));
  ------------------
  |  |   52|  38.5k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1470|  50.2k|        if (dest != NULL) {
  ------------------
  |  Branch (1470:13): [True: 50.2k, False: 0]
  ------------------
 1471|  50.2k|            dest->type = siBuffer;
 1472|  50.2k|            dest->data = (unsigned char *)PORT_Alloc(len);
  ------------------
  |  |   52|  50.2k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
 1473|  50.2k|            if (dest->data == NULL) {
  ------------------
  |  Branch (1473:17): [True: 0, False: 50.2k]
  ------------------
 1474|      0|                if (indest == NULL)
  ------------------
  |  Branch (1474:21): [True: 0, False: 0]
  ------------------
 1475|      0|                    PORT_Free(dest);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 1476|      0|                dest = NULL;
 1477|      0|            }
 1478|  50.2k|        }
 1479|  50.2k|    }
 1480|       |
 1481|  50.2k|    return dest;
 1482|  50.2k|}
secasn1e.c:sec_asn1e_encode_item_store:
 1423|   193k|{
 1424|   193k|    SECItem *dest;
 1425|       |
 1426|   193k|    dest = (SECItem *)arg;
 1427|   193k|    PORT_Assert(dest != NULL);
  ------------------
  |  |  120|   193k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   193k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 193k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 1428|       |
 1429|   193k|    if (len > 0) {
  ------------------
  |  Branch (1429:9): [True: 193k, False: 0]
  ------------------
 1430|   193k|        PORT_Memcpy(dest->data + dest->len, buf, len);
  ------------------
  |  |  180|   193k|#define PORT_Memcpy memcpy
  ------------------
 1431|   193k|        dest->len += len;
 1432|   193k|    }
 1433|   193k|}

SEC_ASN1LengthLength_Util:
   21|   194k|{
   22|   194k|    int lenlen = 1;
   23|       |
   24|   194k|    if (len > 0x7f) {
  ------------------
  |  Branch (24:9): [True: 178, False: 194k]
  ------------------
   25|    178|        do {
   26|    178|            lenlen++;
   27|    178|            len >>= 8;
   28|    178|        } while (len);
  ------------------
  |  Branch (28:18): [True: 0, False: 178]
  ------------------
   29|    178|    }
   30|       |
   31|   194k|    return lenlen;
   32|   194k|}
SEC_ASN1GetSubtemplate:
   53|   109k|{
   54|   109k|    const SEC_ASN1Template *subt = NULL;
   55|       |
   56|   109k|    PORT_Assert(theTemplate->sub != NULL);
  ------------------
  |  |  120|   109k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   109k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 109k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   57|   109k|    if (theTemplate->sub != NULL) {
  ------------------
  |  Branch (57:9): [True: 109k, False: 0]
  ------------------
   58|   109k|        if (theTemplate->kind & SEC_ASN1_DYNAMIC) {
  ------------------
  |  |  138|   109k|#define SEC_ASN1_DYNAMIC 0x04000      /* subtemplate is found by calling \
  ------------------
  |  Branch (58:13): [True: 0, False: 109k]
  ------------------
   59|      0|            SEC_ASN1TemplateChooserPtr chooserp;
   60|       |
   61|      0|            chooserp = *(SEC_ASN1TemplateChooserPtr *)theTemplate->sub;
   62|      0|            if (chooserp) {
  ------------------
  |  Branch (62:17): [True: 0, False: 0]
  ------------------
   63|      0|                if (thing != NULL)
  ------------------
  |  Branch (63:21): [True: 0, False: 0]
  ------------------
   64|      0|                    thing = (char *)thing - theTemplate->offset;
   65|      0|                subt = (*chooserp)(thing, encoding);
   66|      0|            }
   67|   109k|        } else {
   68|   109k|            subt = (SEC_ASN1Template *)theTemplate->sub;
   69|   109k|        }
   70|   109k|    }
   71|   109k|    return subt;
   72|   109k|}

SGN_CreateDigestInfo_Util:
   36|  27.4k|{
   37|  27.4k|    SGNDigestInfo *di;
   38|  27.4k|    SECStatus rv;
   39|  27.4k|    PLArenaPool *arena;
   40|  27.4k|    SECItem *null_param;
   41|  27.4k|    SECItem dummy_value;
   42|       |
   43|       |    /* make sure we are encoding an actual hash function */
   44|  27.4k|    if (HASH_GetHashTypeByOidTag(algorithm) == HASH_AlgNULL) {
  ------------------
  |  |  125|  27.4k|#define HASH_GetHashTypeByOidTag HASH_GetHashTypeByOidTag_Util
  ------------------
  |  Branch (44:9): [True: 0, False: 27.4k]
  ------------------
   45|      0|        return NULL;
   46|      0|    }
   47|  27.4k|    arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   63|  27.4k|#define PORT_NewArena PORT_NewArena_Util
  ------------------
                  arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE);
  ------------------
  |  |   60|  27.4k|#define DER_DEFAULT_CHUNKSIZE (2048)
  ------------------
   48|  27.4k|    if (arena == NULL) {
  ------------------
  |  Branch (48:9): [True: 0, False: 27.4k]
  ------------------
   49|      0|        return NULL;
   50|      0|    }
   51|       |
   52|  27.4k|    di = (SGNDigestInfo *)PORT_ArenaZAlloc(arena, sizeof(SGNDigestInfo));
  ------------------
  |  |   59|  27.4k|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
   53|  27.4k|    if (di == NULL) {
  ------------------
  |  Branch (53:9): [True: 0, False: 27.4k]
  ------------------
   54|      0|        PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |   61|      0|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(arena, PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   55|      0|        return NULL;
   56|      0|    }
   57|       |
   58|  27.4k|    di->arena = arena;
   59|       |
   60|       |    /*
   61|       |     * PKCS #1 specifies that the AlgorithmID must have a NULL parameter
   62|       |     * (as opposed to no parameter at all).
   63|       |     */
   64|  27.4k|    dummy_value.data = NULL;
   65|  27.4k|    dummy_value.len = 0;
   66|  27.4k|    null_param = SEC_ASN1EncodeItem(NULL, NULL, &dummy_value, SEC_NullTemplate);
  ------------------
  |  |   89|  27.4k|#define SEC_ASN1EncodeItem SEC_ASN1EncodeItem_Util
  ------------------
                  null_param = SEC_ASN1EncodeItem(NULL, NULL, &dummy_value, SEC_NullTemplate);
  ------------------
  |  |  155|  27.4k|#define SEC_NullTemplate SEC_NullTemplate_Util
  ------------------
   67|  27.4k|    if (null_param == NULL) {
  ------------------
  |  Branch (67:9): [True: 0, False: 27.4k]
  ------------------
   68|      0|        goto loser;
   69|      0|    }
   70|       |
   71|  27.4k|    rv = SECOID_SetAlgorithmID(arena, &di->digestAlgorithm, algorithm,
  ------------------
  |  |  120|  27.4k|#define SECOID_SetAlgorithmID SECOID_SetAlgorithmID_Util
  ------------------
   72|  27.4k|                               null_param);
   73|       |
   74|  27.4k|    SECITEM_FreeItem(null_param, PR_TRUE);
  ------------------
  |  |  108|  27.4k|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                  SECITEM_FreeItem(null_param, PR_TRUE);
  ------------------
  |  |  437|  27.4k|#define PR_TRUE 1
  ------------------
   75|       |
   76|  27.4k|    if (rv != SECSuccess) {
  ------------------
  |  Branch (76:9): [True: 0, False: 27.4k]
  ------------------
   77|      0|        goto loser;
   78|      0|    }
   79|       |
   80|  27.4k|    di->digest.data = (unsigned char *)PORT_ArenaAlloc(arena, len);
  ------------------
  |  |   53|  27.4k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
   81|  27.4k|    if (di->digest.data == NULL) {
  ------------------
  |  Branch (81:9): [True: 0, False: 27.4k]
  ------------------
   82|      0|        goto loser;
   83|      0|    }
   84|       |
   85|  27.4k|    di->digest.len = len;
   86|  27.4k|    PORT_Memcpy(di->digest.data, sig, len);
  ------------------
  |  |  180|  27.4k|#define PORT_Memcpy memcpy
  ------------------
   87|  27.4k|    return di;
   88|       |
   89|      0|loser:
   90|      0|    SGN_DestroyDigestInfo(di);
  ------------------
  |  |  124|      0|#define SGN_DestroyDigestInfo SGN_DestroyDigestInfo_Util
  ------------------
   91|      0|    return NULL;
   92|  27.4k|}
SGN_DestroyDigestInfo_Util:
  128|  38.3k|{
  129|  38.3k|    if (di && di->arena) {
  ------------------
  |  Branch (129:9): [True: 27.4k, False: 10.8k]
  |  Branch (129:15): [True: 27.4k, False: 0]
  ------------------
  130|  27.4k|        PORT_FreeArena(di->arena, PR_TRUE);
  ------------------
  |  |   61|  27.4k|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                      PORT_FreeArena(di->arena, PR_TRUE);
  ------------------
  |  |  437|  27.4k|#define PR_TRUE 1
  ------------------
  131|  27.4k|    }
  132|       |
  133|  38.3k|    return;
  134|  38.3k|}

SECITEM_AllocItem_Util:
   16|   880k|{
   17|   880k|    SECItem *result = NULL;
   18|   880k|    void *mark = NULL;
   19|       |
   20|   880k|    if (arena != NULL) {
  ------------------
  |  Branch (20:9): [True: 429k, False: 450k]
  ------------------
   21|   429k|        mark = PORT_ArenaMark(arena);
  ------------------
  |  |   55|   429k|#define PORT_ArenaMark PORT_ArenaMark_Util
  ------------------
   22|   429k|    }
   23|       |
   24|   880k|    if (item == NULL) {
  ------------------
  |  Branch (24:9): [True: 248k, False: 632k]
  ------------------
   25|   248k|        if (arena != NULL) {
  ------------------
  |  Branch (25:13): [True: 345, False: 247k]
  ------------------
   26|    345|            result = PORT_ArenaZAlloc(arena, sizeof(SECItem));
  ------------------
  |  |   59|    345|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  ------------------
   27|   247k|        } else {
   28|   247k|            result = PORT_ZAlloc(sizeof(SECItem));
  ------------------
  |  |   72|   247k|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
   29|   247k|        }
   30|   248k|        if (result == NULL) {
  ------------------
  |  Branch (30:13): [True: 0, False: 248k]
  ------------------
   31|      0|            goto loser;
   32|      0|        }
   33|   632k|    } else {
   34|   632k|        PORT_Assert(item->data == NULL);
  ------------------
  |  |  120|   632k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   632k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 632k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
   35|   632k|        result = item;
   36|   632k|    }
   37|       |
   38|   880k|    result->len = len;
   39|   880k|    if (len) {
  ------------------
  |  Branch (39:9): [True: 880k, False: 44]
  ------------------
   40|   880k|        if (arena != NULL) {
  ------------------
  |  Branch (40:13): [True: 429k, False: 450k]
  ------------------
   41|   429k|            result->data = PORT_ArenaAlloc(arena, len);
  ------------------
  |  |   53|   429k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
   42|   450k|        } else {
   43|   450k|            result->data = PORT_Alloc(len);
  ------------------
  |  |   52|   450k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
   44|   450k|        }
   45|   880k|        if (result->data == NULL) {
  ------------------
  |  Branch (45:13): [True: 0, False: 880k]
  ------------------
   46|      0|            goto loser;
   47|      0|        }
   48|   880k|    } else {
   49|     44|        result->data = NULL;
   50|     44|    }
   51|       |
   52|   880k|    if (mark) {
  ------------------
  |  Branch (52:9): [True: 429k, False: 450k]
  ------------------
   53|   429k|        PORT_ArenaUnmark(arena, mark);
  ------------------
  |  |   58|   429k|#define PORT_ArenaUnmark PORT_ArenaUnmark_Util
  ------------------
   54|   429k|    }
   55|   880k|    return (result);
   56|       |
   57|      0|loser:
   58|      0|    if (arena != NULL) {
  ------------------
  |  Branch (58:9): [True: 0, False: 0]
  ------------------
   59|      0|        if (mark) {
  ------------------
  |  Branch (59:13): [True: 0, False: 0]
  ------------------
   60|      0|            PORT_ArenaRelease(arena, mark);
  ------------------
  |  |   56|      0|#define PORT_ArenaRelease PORT_ArenaRelease_Util
  ------------------
   61|      0|        }
   62|      0|        if (item != NULL) {
  ------------------
  |  Branch (62:13): [True: 0, False: 0]
  ------------------
   63|      0|            item->data = NULL;
   64|      0|            item->len = 0;
   65|      0|        }
   66|      0|    } else {
   67|      0|        if (result != NULL) {
  ------------------
  |  Branch (67:13): [True: 0, False: 0]
  ------------------
   68|      0|            SECITEM_FreeItem(result, (item == NULL) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  108|      0|#define SECITEM_FreeItem SECITEM_FreeItem_Util
  ------------------
                          SECITEM_FreeItem(result, (item == NULL) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
                          SECITEM_FreeItem(result, (item == NULL) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (68:38): [True: 0, False: 0]
  ------------------
   69|      0|        }
   70|       |        /*
   71|       |         * If item is not NULL, the above has set item->data and
   72|       |         * item->len to 0.
   73|       |         */
   74|      0|    }
   75|      0|    return (NULL);
   76|   880k|}
SECITEM_MakeItem:
   81|  1.63k|{
   82|  1.63k|    SECItem it = { siBuffer, (unsigned char *)data, len };
   83|       |
   84|  1.63k|    return SECITEM_CopyItem(arena, dest, &it);
  ------------------
  |  |  106|  1.63k|#define SECITEM_CopyItem SECITEM_CopyItem_Util
  ------------------
   85|  1.63k|}
SECITEM_CompareItem_Util:
  189|  99.9k|{
  190|  99.9k|    unsigned m;
  191|  99.9k|    int rv;
  192|       |
  193|  99.9k|    if (a == b)
  ------------------
  |  Branch (193:9): [True: 0, False: 99.9k]
  ------------------
  194|      0|        return SECEqual;
  195|  99.9k|    if (!a || !a->len || !a->data)
  ------------------
  |  Branch (195:9): [True: 0, False: 99.9k]
  |  Branch (195:15): [True: 0, False: 99.9k]
  |  Branch (195:26): [True: 0, False: 99.9k]
  ------------------
  196|      0|        return (!b || !b->len || !b->data) ? SECEqual : SECLessThan;
  ------------------
  |  Branch (196:17): [True: 0, False: 0]
  |  Branch (196:23): [True: 0, False: 0]
  |  Branch (196:34): [True: 0, False: 0]
  ------------------
  197|  99.9k|    if (!b || !b->len || !b->data)
  ------------------
  |  Branch (197:9): [True: 0, False: 99.9k]
  |  Branch (197:15): [True: 0, False: 99.9k]
  |  Branch (197:26): [True: 0, False: 99.9k]
  ------------------
  198|      0|        return SECGreaterThan;
  199|       |
  200|  99.9k|    m = ((a->len < b->len) ? a->len : b->len);
  ------------------
  |  Branch (200:10): [True: 432, False: 99.5k]
  ------------------
  201|       |
  202|  99.9k|    rv = PORT_Memcmp(a->data, b->data, m);
  ------------------
  |  |  179|  99.9k|#define PORT_Memcmp memcmp
  ------------------
  203|  99.9k|    if (rv) {
  ------------------
  |  Branch (203:9): [True: 56.3k, False: 43.6k]
  ------------------
  204|  56.3k|        return rv < 0 ? SECLessThan : SECGreaterThan;
  ------------------
  |  Branch (204:16): [True: 15.7k, False: 40.5k]
  ------------------
  205|  56.3k|    }
  206|  43.6k|    if (a->len < b->len) {
  ------------------
  |  Branch (206:9): [True: 17, False: 43.6k]
  ------------------
  207|     17|        return SECLessThan;
  208|     17|    }
  209|  43.6k|    if (a->len == b->len) {
  ------------------
  |  Branch (209:9): [True: 43.5k, False: 15]
  ------------------
  210|  43.5k|        return SECEqual;
  211|  43.5k|    }
  212|     15|    return SECGreaterThan;
  213|  43.6k|}
SECITEM_ItemsAreEqual_Util:
  217|   197k|{
  218|   197k|    if (a->len != b->len)
  ------------------
  |  Branch (218:9): [True: 92, False: 197k]
  ------------------
  219|     92|        return PR_FALSE;
  ------------------
  |  |  438|     92|#define PR_FALSE 0
  ------------------
  220|   197k|    if (!a->len)
  ------------------
  |  Branch (220:9): [True: 40, False: 197k]
  ------------------
  221|     40|        return PR_TRUE;
  ------------------
  |  |  437|     40|#define PR_TRUE 1
  ------------------
  222|   197k|    if (!a->data || !b->data) {
  ------------------
  |  Branch (222:9): [True: 0, False: 197k]
  |  Branch (222:21): [True: 0, False: 197k]
  ------------------
  223|       |        /* avoid null pointer crash. */
  224|      0|        return (PRBool)(a->data == b->data);
  225|      0|    }
  226|   197k|    return (PRBool)!PORT_Memcmp(a->data, b->data, a->len);
  ------------------
  |  |  179|   197k|#define PORT_Memcmp memcmp
  ------------------
  227|   197k|}
SECITEM_DupItem_Util:
  231|   242k|{
  232|   242k|    return SECITEM_ArenaDupItem(NULL, from);
  ------------------
  |  |  104|   242k|#define SECITEM_ArenaDupItem SECITEM_ArenaDupItem_Util
  ------------------
  233|   242k|}
SECITEM_ArenaDupItem_Util:
  237|   243k|{
  238|   243k|    SECItem *to;
  239|       |
  240|   243k|    if (from == NULL) {
  ------------------
  |  Branch (240:9): [True: 0, False: 243k]
  ------------------
  241|      0|        return NULL;
  242|      0|    }
  243|       |
  244|   243k|    to = SECITEM_AllocItem(arena, NULL, from->len);
  ------------------
  |  |  103|   243k|#define SECITEM_AllocItem SECITEM_AllocItem_Util
  ------------------
  245|   243k|    if (to == NULL) {
  ------------------
  |  Branch (245:9): [True: 0, False: 243k]
  ------------------
  246|      0|        return NULL;
  247|      0|    }
  248|       |
  249|   243k|    to->type = from->type;
  250|   243k|    if (to->len) {
  ------------------
  |  Branch (250:9): [True: 242k, False: 39]
  ------------------
  251|   242k|        PORT_Memcpy(to->data, from->data, to->len);
  ------------------
  |  |  180|   242k|#define PORT_Memcpy memcpy
  ------------------
  252|   242k|    }
  253|       |
  254|   243k|    return to;
  255|   243k|}
SECITEM_CopyItem_Util:
  259|   385k|{
  260|   385k|    to->type = from->type;
  261|   385k|    if (from->data && from->len) {
  ------------------
  |  Branch (261:9): [True: 318k, False: 66.8k]
  |  Branch (261:23): [True: 318k, False: 197]
  ------------------
  262|   318k|        if (arena) {
  ------------------
  |  Branch (262:13): [True: 275k, False: 42.9k]
  ------------------
  263|   275k|            to->data = (unsigned char *)PORT_ArenaAlloc(arena, from->len);
  ------------------
  |  |   53|   275k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  264|   275k|        } else {
  265|  42.9k|            to->data = (unsigned char *)PORT_Alloc(from->len);
  ------------------
  |  |   52|  42.9k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  266|  42.9k|        }
  267|       |
  268|   318k|        if (!to->data) {
  ------------------
  |  Branch (268:13): [True: 0, False: 318k]
  ------------------
  269|      0|            return SECFailure;
  270|      0|        }
  271|   318k|        PORT_Memcpy(to->data, from->data, from->len);
  ------------------
  |  |  180|   318k|#define PORT_Memcpy memcpy
  ------------------
  272|   318k|        to->len = from->len;
  273|   318k|    } else {
  274|       |        /*
  275|       |         * If from->data is NULL but from->len is nonzero, this function
  276|       |         * will succeed.  Is this right?
  277|       |         */
  278|  67.0k|        to->data = 0;
  279|  67.0k|        to->len = 0;
  280|  67.0k|    }
  281|   385k|    return SECSuccess;
  282|   385k|}
SECITEM_FreeItem_Util:
  286|   790k|{
  287|   790k|    if (zap) {
  ------------------
  |  Branch (287:9): [True: 740k, False: 50.0k]
  ------------------
  288|   740k|        PORT_Free(zap->data);
  ------------------
  |  |   60|   740k|#define PORT_Free PORT_Free_Util
  ------------------
  289|   740k|        zap->data = 0;
  290|   740k|        zap->len = 0;
  291|   740k|        if (freeit) {
  ------------------
  |  Branch (291:13): [True: 339k, False: 400k]
  ------------------
  292|   339k|            PORT_Free(zap);
  ------------------
  |  |   60|   339k|#define PORT_Free PORT_Free_Util
  ------------------
  293|   339k|        }
  294|   740k|    }
  295|   790k|}
SECITEM_ZfreeItem_Util:
  299|   292k|{
  300|   292k|    if (zap) {
  ------------------
  |  Branch (300:9): [True: 292k, False: 0]
  ------------------
  301|   292k|        PORT_ZFree(zap->data, zap->len);
  ------------------
  |  |   75|   292k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  302|   292k|        zap->data = 0;
  303|   292k|        zap->len = 0;
  304|   292k|        if (freeit) {
  ------------------
  |  Branch (304:13): [True: 39.9k, False: 252k]
  ------------------
  305|  39.9k|            PORT_ZFree(zap, sizeof(SECItem));
  ------------------
  |  |   75|  39.9k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  306|  39.9k|        }
  307|   292k|    }
  308|   292k|}
SECITEM_Hash:
  319|   202k|{
  320|   202k|    const SECItem *item = (const SECItem *)key;
  321|   202k|    PLHashNumber rv = 0;
  322|       |
  323|   202k|    PRUint8 *data = (PRUint8 *)item->data;
  324|   202k|    PRUint32 i;
  325|   202k|    PRUint8 *rvc = (PRUint8 *)&rv;
  326|       |
  327|  1.75M|    for (i = 0; i < item->len; i++) {
  ------------------
  |  Branch (327:17): [True: 1.55M, False: 202k]
  ------------------
  328|  1.55M|        rvc[i % sizeof(rv)] ^= *data;
  329|  1.55M|        data++;
  330|  1.55M|    }
  331|       |
  332|   202k|    return rv;
  333|   202k|}
SECITEM_HashCompare:
  343|   193k|{
  344|   193k|    const SECItem *i1 = (const SECItem *)k1;
  345|   193k|    const SECItem *i2 = (const SECItem *)k2;
  346|       |
  347|   193k|    return SECITEM_ItemsAreEqual(i1, i2);
  ------------------
  |  |  109|   193k|#define SECITEM_ItemsAreEqual SECITEM_ItemsAreEqual_Util
  ------------------
  348|   193k|}

SECOID_Init:
 2167|      2|{
 2168|      2|    PLHashEntry *entry;
 2169|      2|    const SECOidData *oid;
 2170|      2|    SECOidTag i;
 2171|      2|    char *envVal;
 2172|       |
 2173|      2|#define NSS_VERSION_VARIABLE __nss_util_version
 2174|      2|#include "verref.h"
  ------------------
  |  |    1|       |/* This Source Code Form is subject to the terms of the Mozilla Public
  |  |    2|       | * License, v. 2.0. If a copy of the MPL was not distributed with this
  |  |    3|       | * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
  |  |    4|       |
  |  |    5|       |/* This header is used inline in a function to ensure that a version string
  |  |    6|       | * symbol is linked in and not optimized out. A volatile reference is added to
  |  |    7|       | * the variable identified by NSS_VERSION_VARIABLE.
  |  |    8|       | *
  |  |    9|       | * Use this as follows:
  |  |   10|       | *
  |  |   11|       | * #define NSS_VERSION_VARIABLE __nss_ssl_version
  |  |   12|       | * #include "verref.h"
  |  |   13|       | */
  |  |   14|       |
  |  |   15|       |/* Suppress unused variable warnings. */
  |  |   16|       |#ifdef _MSC_VER
  |  |   17|       |#pragma warning(push)
  |  |   18|       |#pragma warning(disable : 4101)
  |  |   19|       |#endif
  |  |   20|       |/* This works for both gcc and clang */
  |  |   21|      2|#if defined(__GNUC__) && !defined(NSS_NO_GCC48)
  |  |   22|      2|#pragma GCC diagnostic push
  |  |   23|      2|#pragma GCC diagnostic ignored "-Wunused-variable"
  |  |   24|      2|#endif
  |  |   25|       |
  |  |   26|       |#ifndef NSS_VERSION_VARIABLE
  |  |   27|       |#error NSS_VERSION_VARIABLE must be set before including "verref.h"
  |  |   28|       |#endif
  |  |   29|      2|{
  |  |   30|      2|    extern const char NSS_VERSION_VARIABLE[];
  |  |   31|      2|#if defined(__GNUC__) || defined(__clang__)
  |  |   32|      2|    __attribute__((unused))
  |  |   33|      2|#endif
  |  |   34|      2|    volatile const char _nss_version_c = NSS_VERSION_VARIABLE[0];
  |  |  ------------------
  |  |  |  | 2173|      2|#define NSS_VERSION_VARIABLE __nss_util_version
  |  |  ------------------
  |  |   35|      2|}
  |  |   36|      2|#undef NSS_VERSION_VARIABLE
  |  |   37|       |
  |  |   38|       |#ifdef _MSC_VER
  |  |   39|       |#pragma warning(pop)
  |  |   40|       |#endif
  |  |   41|      2|#if defined(__GNUC__) && !defined(NSS_NO_GCC48)
  |  |   42|      2|#pragma GCC diagnostic pop
  |  |   43|      2|#endif
  ------------------
 2175|       |
 2176|      2|    if (oidhash) {
  ------------------
  |  Branch (2176:9): [True: 1, False: 1]
  ------------------
 2177|      1|        return SECSuccess; /* already initialized */
 2178|      1|    }
 2179|       |
 2180|       |    /* xyber768d00 must be enabled explicitly */
 2181|      1|    xOids[SEC_OID_XYBER768D00].notPolicyFlags = NSS_USE_ALG_IN_SSL_KX;
  ------------------
  |  |  572|      1|#define NSS_USE_ALG_IN_SSL_KX 0x00000004           /* used in SSL key exchange */
  ------------------
 2182|       |
 2183|      1|    if (!PR_GetEnvSecure("NSS_ALLOW_WEAK_SIGNATURE_ALG")) {
  ------------------
  |  Branch (2183:9): [True: 1, False: 0]
  ------------------
 2184|       |        /* initialize any policy flags that are disabled by default */
 2185|      1|        xOids[SEC_OID_MD2].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
  ------------------
  |  |  576|      1|#define NSS_USE_ALG_IN_PKCS12_DECRYPT 0x00000040   /* used to decrypt pkcs12 */
  ------------------
 2186|      1|        xOids[SEC_OID_MD4].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
  ------------------
  |  |  576|      1|#define NSS_USE_ALG_IN_PKCS12_DECRYPT 0x00000040   /* used to decrypt pkcs12 */
  ------------------
 2187|      1|        xOids[SEC_OID_MD5].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
  ------------------
  |  |  576|      1|#define NSS_USE_ALG_IN_PKCS12_DECRYPT 0x00000040   /* used to decrypt pkcs12 */
  ------------------
 2188|      1|        xOids[SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
 2189|      1|        xOids[SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
 2190|      1|        xOids[SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
 2191|      1|        xOids[SEC_OID_PKCS5_PBE_WITH_MD2_AND_DES_CBC].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
  ------------------
  |  |  576|      1|#define NSS_USE_ALG_IN_PKCS12_DECRYPT 0x00000040   /* used to decrypt pkcs12 */
  ------------------
 2192|      1|        xOids[SEC_OID_PKCS5_PBE_WITH_MD5_AND_DES_CBC].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
  ------------------
  |  |  576|      1|#define NSS_USE_ALG_IN_PKCS12_DECRYPT 0x00000040   /* used to decrypt pkcs12 */
  ------------------
 2193|      1|    }
 2194|       |
 2195|       |    /* turn off NSS_USE_POLICY_IN_SSL by default */
 2196|      1|    xOids[SEC_OID_APPLY_SSL_POLICY].notPolicyFlags = NSS_USE_POLICY_IN_SSL;
  ------------------
  |  |  574|      1|#define NSS_USE_POLICY_IN_SSL 0x00000010           /* enable policy in SSL protocol */
  ------------------
 2197|       |    /* turn off TLS REQUIRE EMS by default */
 2198|      1|    xOids[SEC_OID_TLS_REQUIRE_EMS].notPolicyFlags = ~0;
 2199|       |
 2200|      1|    envVal = PR_GetEnvSecure("NSS_HASH_ALG_SUPPORT");
 2201|      1|    if (envVal)
  ------------------
  |  Branch (2201:9): [True: 0, False: 1]
  ------------------
 2202|      0|        handleHashAlgSupport(envVal);
 2203|       |
 2204|      1|    if (secoid_InitDynOidData() != SECSuccess) {
  ------------------
  |  Branch (2204:9): [True: 0, False: 1]
  ------------------
 2205|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2206|      0|        PORT_Assert(0); /* this function should never fail */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2207|      0|        return SECFailure;
 2208|      0|    }
 2209|       |
 2210|      1|    oidhash = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
 2211|      1|                              PL_CompareValues, NULL, NULL);
 2212|      1|    oidmechhash = PL_NewHashTable(0, secoid_HashNumber, PL_CompareValues,
 2213|      1|                                  PL_CompareValues, NULL, NULL);
 2214|       |
 2215|      1|    if (!oidhash || !oidmechhash) {
  ------------------
  |  Branch (2215:9): [True: 0, False: 1]
  |  Branch (2215:21): [True: 0, False: 1]
  ------------------
 2216|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2217|      0|        PORT_Assert(0); /*This function should never fail. */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2218|      0|        return (SECFailure);
 2219|      0|    }
 2220|       |
 2221|    392|    for (i = 0; i < SEC_OID_TOTAL; i++) {
  ------------------
  |  Branch (2221:17): [True: 391, False: 1]
  ------------------
 2222|    391|        oid = &oids[i];
 2223|    391|        PORT_Assert(oid->offset == i);
  ------------------
  |  |  120|    391|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    391|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 391, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2224|    391|        entry = PL_HashTableAdd(oidhash, &oid->oid, (void *)oid);
 2225|       |
 2226|    391|        if (entry == NULL) {
  ------------------
  |  Branch (2226:13): [True: 0, False: 391]
  ------------------
 2227|      0|            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2228|      0|            PORT_Assert(0); /*This function should never fail. */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2229|      0|            return (SECFailure);
 2230|      0|        }
 2231|       |
 2232|    391|        if (oid->mechanism != CKM_INVALID_MECHANISM) {
  ------------------
  |  |  155|    391|#define CKM_INVALID_MECHANISM 0xffffffffUL
  ------------------
  |  Branch (2232:13): [True: 108, False: 283]
  ------------------
 2233|    108|            entry = PL_HashTableAdd(oidmechhash,
 2234|    108|                                    (void *)(uintptr_t)oid->mechanism, (void *)oid);
 2235|    108|            if (entry == NULL) {
  ------------------
  |  Branch (2235:17): [True: 0, False: 108]
  ------------------
 2236|      0|                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2237|      0|                PORT_Assert(0); /* This function should never fail. */
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2238|      0|                return (SECFailure);
 2239|      0|            }
 2240|    108|        }
 2241|    391|    }
 2242|       |
 2243|      1|    PORT_Assert(i == SEC_OID_TOTAL);
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      1|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2244|       |    /* finally, clear S/MIME from the policy oids. If no one turns on any
 2245|       |     * S/MIME policies after this, then S/MIME will enable the traditional
 2246|       |     * algs when it initializes */
 2247|      1|    (void)NSS_SetAlgorithmPolicyAll(0, NSS_USE_ALG_IN_SMIME);
  ------------------
  |  |  597|      1|#define NSS_USE_ALG_IN_SMIME (NSS_USE_ALG_IN_SMIME_LEGACY | \
  |  |  ------------------
  |  |  |  |  578|      1|#define NSS_USE_ALG_IN_SMIME_LEGACY 0x00000100     /* used to decrypt smime */
  |  |  ------------------
  |  |  598|      1|                              NSS_USE_ALG_IN_SMIME_ENCRYPT)
  |  |  ------------------
  |  |  |  |  579|      1|#define NSS_USE_ALG_IN_SMIME_ENCRYPT 0x00000200    /* used to decrypt smime */
  |  |  ------------------
  ------------------
 2248|       |
 2249|      1|    return (SECSuccess);
 2250|      1|}
SECOID_FindOIDByMechanism:
 2254|  1.24k|{
 2255|  1.24k|    SECOidData *ret;
 2256|       |
 2257|  1.24k|    PR_ASSERT(oidmechhash != NULL);
  ------------------
  |  |  208|  1.24k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 1.24k, False: 0]
  |  |  ------------------
  ------------------
 2258|  1.24k|    if (oidmechhash == NULL && SECOID_Init() != SECSuccess) {
  ------------------
  |  Branch (2258:9): [True: 0, False: 1.24k]
  |  Branch (2258:32): [True: 0, False: 0]
  ------------------
 2259|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2260|      0|        return NULL;
 2261|      0|    }
 2262|       |
 2263|  1.24k|    ret = PL_HashTableLookupConst(oidmechhash, (void *)(uintptr_t)mechanism);
 2264|  1.24k|    if (ret == NULL) {
  ------------------
  |  Branch (2264:9): [True: 0, False: 1.24k]
  ------------------
 2265|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2266|      0|    }
 2267|       |
 2268|  1.24k|    return (ret);
 2269|  1.24k|}
SECOID_FindOID_Util:
 2273|   202k|{
 2274|   202k|    SECOidData *ret;
 2275|       |
 2276|   202k|    PR_ASSERT(oidhash != NULL);
  ------------------
  |  |  208|   202k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:6): [True: 202k, False: 0]
  |  |  ------------------
  ------------------
 2277|   202k|    if (oidhash == NULL && SECOID_Init() != SECSuccess) {
  ------------------
  |  Branch (2277:9): [True: 0, False: 202k]
  |  Branch (2277:28): [True: 0, False: 0]
  ------------------
 2278|      0|        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2279|      0|        return NULL;
 2280|      0|    }
 2281|       |
 2282|   202k|    if ((oid == NULL) || (oid->data == NULL)) {
  ------------------
  |  Branch (2282:9): [True: 0, False: 202k]
  |  Branch (2282:26): [True: 0, False: 202k]
  ------------------
 2283|      0|        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2284|      0|        return NULL;
 2285|      0|    }
 2286|       |
 2287|   202k|    ret = PL_HashTableLookupConst(oidhash, oid);
 2288|   202k|    if (ret == NULL) {
  ------------------
  |  Branch (2288:9): [True: 8.98k, False: 193k]
  ------------------
 2289|  8.98k|        ret = secoid_FindDynamic(oid);
 2290|  8.98k|        if (ret == NULL) {
  ------------------
  |  Branch (2290:13): [True: 8.98k, False: 0]
  ------------------
 2291|  8.98k|            PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
  ------------------
  |  |   65|  8.98k|#define PORT_SetError PORT_SetError_Util
  ------------------
 2292|  8.98k|        }
 2293|  8.98k|    }
 2294|   202k|    return (ret);
 2295|   202k|}
SECOID_FindOIDTag_Util:
 2299|   160k|{
 2300|   160k|    SECOidData *oiddata;
 2301|       |
 2302|   160k|    oiddata = SECOID_FindOID(oid);
  ------------------
  |  |  115|   160k|#define SECOID_FindOID SECOID_FindOID_Util
  ------------------
 2303|   160k|    if (oiddata == NULL) {
  ------------------
  |  Branch (2303:9): [True: 241, False: 160k]
  ------------------
 2304|    241|        return SEC_OID_UNKNOWN;
 2305|    241|    }
 2306|       |
 2307|   160k|    return oiddata->offset;
 2308|   160k|}
SECOID_FindOIDByTag_Util:
 2313|   303k|{
 2314|   303k|    if (tagnum >= SEC_OID_TOTAL) {
  ------------------
  |  Branch (2314:9): [True: 0, False: 303k]
  ------------------
 2315|      0|        return (SECOidData *)secoid_FindDynamicByTag(tagnum);
 2316|      0|    }
 2317|       |
 2318|   303k|    PORT_Assert((unsigned int)tagnum < SEC_OID_TOTAL);
  ------------------
  |  |  120|   303k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   303k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 303k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2319|   303k|    return (SECOidData *)(&oids[tagnum]);
 2320|   303k|}
SECOID_KnownCertExtenOID:
 2324|     39|{
 2325|     39|    SECOidData *oidData;
 2326|       |
 2327|     39|    oidData = SECOID_FindOID(extenOid);
  ------------------
  |  |  115|     39|#define SECOID_FindOID SECOID_FindOID_Util
  ------------------
 2328|     39|    if (oidData == (SECOidData *)NULL)
  ------------------
  |  Branch (2328:9): [True: 6, False: 33]
  ------------------
 2329|      6|        return (PR_FALSE);
  ------------------
  |  |  438|      6|#define PR_FALSE 0
  ------------------
 2330|     33|    return ((oidData->supportedExtension == SUPPORTED_CERT_EXTENSION) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  437|     33|#define PR_TRUE 1
  ------------------
                  return ((oidData->supportedExtension == SUPPORTED_CERT_EXTENSION) ? PR_TRUE : PR_FALSE);
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  |  Branch (2330:13): [True: 33, False: 0]
  ------------------
 2331|     39|}
SECOID_GetTotalTags:
 2347|      1|{
 2348|      1|    SECOidTag total;
 2349|       |
 2350|       |    /* get the lock to make sure we don't catch and inconsistant value
 2351|       |     * for dynOidEntriesUsed. */
 2352|      1|    NSSRWLock_LockRead(dynOidLock);
  ------------------
  |  |   47|      1|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  ------------------
 2353|      1|    total = SEC_OID_TOTAL + dynOidEntriesUsed;
 2354|      1|    NSSRWLock_UnlockRead(dynOidLock);
  ------------------
  |  |   50|      1|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  ------------------
 2355|      1|    return total;
 2356|      1|}
NSS_GetAlgorithmPolicy:
 2383|  4.58M|{
 2384|  4.58M|    privXOid *pxo = secoid_FindXOidByTag(tag);
 2385|  4.58M|    if (!pxo)
  ------------------
  |  Branch (2385:9): [True: 0, False: 4.58M]
  ------------------
 2386|      0|        return SECFailure;
 2387|  4.58M|    if (!pValue) {
  ------------------
  |  Branch (2387:9): [True: 0, False: 4.58M]
  ------------------
 2388|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2389|      0|        return SECFailure;
 2390|      0|    }
 2391|  4.58M|    *pValue = ~(pxo->notPolicyFlags);
 2392|  4.58M|    return SECSuccess;
 2393|  4.58M|}
NSS_SetAlgorithmPolicy:
 2403|    391|{
 2404|    391|    privXOid *pxo = secoid_FindXOidByTag(tag);
 2405|    391|    PRUint32 policyFlags;
 2406|    391|    if (!pxo)
  ------------------
  |  Branch (2406:9): [True: 0, False: 391]
  ------------------
 2407|      0|        return SECFailure;
 2408|       |
 2409|    391|    if (nss_policy_locked) {
  ------------------
  |  Branch (2409:9): [True: 0, False: 391]
  ------------------
 2410|      0|        PORT_SetError(SEC_ERROR_POLICY_LOCKED);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
 2411|      0|        return SECFailure;
 2412|      0|    }
 2413|       |    /* The stored policy flags are the ones complement of the flags as
 2414|       |     * seen by the user.  This is not atomic, but these changes should
 2415|       |     * be done rarely, e.g. at initialization time.
 2416|       |     */
 2417|    391|    policyFlags = ~(pxo->notPolicyFlags);
 2418|    391|    policyFlags = (policyFlags & ~clearBits) | setBits;
 2419|    391|    pxo->notPolicyFlags = ~policyFlags;
 2420|    391|    return SECSuccess;
 2421|    391|}
NSS_SetAlgorithmPolicyAll:
 2426|      1|{
 2427|      1|    SECOidTag tag;
 2428|       |    /* call this once,not once per loop */
 2429|      1|    SECOidTag lastTag = SECOID_GetTotalTags();
 2430|       |
 2431|    392|    for (tag = SEC_OID_UNKNOWN; tag < lastTag; tag++) {
  ------------------
  |  Branch (2431:33): [True: 391, False: 1]
  ------------------
 2432|    391|        SECStatus rv = NSS_SetAlgorithmPolicy(tag, setBits, clearBits);
 2433|       |        /* there are only 2 reasons SetAlgorithmPolicy can fail:
 2434|       |         *  1) we passed an invalid tag, or 2) policy is locked.
 2435|       |         *  The first case should not happen because we are only looping
 2436|       |         *  through known good tags. In the second case, we will always fail,
 2437|       |         *  so there is no point continuing our loop */
 2438|    391|        if (rv != SECSuccess) {
  ------------------
  |  Branch (2438:13): [True: 0, False: 391]
  ------------------
 2439|      0|            return rv;
 2440|      0|        }
 2441|    391|    }
 2442|      1|    return SECSuccess;
 2443|      1|}
SECOID_Shutdown:
 2521|      2|{
 2522|      2|    if (oidhash) {
  ------------------
  |  Branch (2522:9): [True: 1, False: 1]
  ------------------
 2523|      1|        PL_HashTableDestroy(oidhash);
 2524|      1|        oidhash = NULL;
 2525|      1|    }
 2526|      2|    if (oidmechhash) {
  ------------------
  |  Branch (2526:9): [True: 1, False: 1]
  ------------------
 2527|      1|        PL_HashTableDestroy(oidmechhash);
 2528|      1|        oidmechhash = NULL;
 2529|      1|    }
 2530|       |    /* Have to handle the case where the lock was created, but
 2531|       |    ** the pool wasn't.
 2532|       |    ** I'm not going to attempt to create the lock, just to protect
 2533|       |    ** the destruction of data that probably isn't initialized anyway.
 2534|       |    */
 2535|      2|    if (dynOidLock) {
  ------------------
  |  Branch (2535:9): [True: 1, False: 1]
  ------------------
 2536|      1|        SKIP_AFTER_FORK(NSSRWLock_LockWrite(dynOidLock));
  ------------------
  |  | 2513|      1|    if (!parentForkedAfterC_Initialize) \
  |  |  ------------------
  |  |  |  Branch (2513:9): [True: 1, False: 0]
  |  |  ------------------
  |  | 2514|      1|    x
  ------------------
 2537|      1|        if (dynOidHash) {
  ------------------
  |  Branch (2537:13): [True: 0, False: 1]
  ------------------
 2538|      0|            PL_HashTableDestroy(dynOidHash);
 2539|      0|            dynOidHash = NULL;
 2540|      0|        }
 2541|      1|        if (dynOidPool) {
  ------------------
  |  Branch (2541:13): [True: 1, False: 0]
  ------------------
 2542|      1|            PORT_FreeArena(dynOidPool, PR_FALSE);
  ------------------
  |  |   61|      1|#define PORT_FreeArena PORT_FreeArena_Util
  ------------------
                          PORT_FreeArena(dynOidPool, PR_FALSE);
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
 2543|      1|            dynOidPool = NULL;
 2544|      1|        }
 2545|      1|        if (dynOidTable) {
  ------------------
  |  Branch (2545:13): [True: 0, False: 1]
  ------------------
 2546|      0|            PORT_Free(dynOidTable);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
 2547|      0|            dynOidTable = NULL;
 2548|      0|        }
 2549|      1|        dynOidEntriesAllocated = 0;
 2550|      1|        dynOidEntriesUsed = 0;
 2551|       |
 2552|      1|        SKIP_AFTER_FORK(NSSRWLock_UnlockWrite(dynOidLock));
  ------------------
  |  | 2513|      1|    if (!parentForkedAfterC_Initialize) \
  |  |  ------------------
  |  |  |  Branch (2513:9): [True: 1, False: 0]
  |  |  ------------------
  |  | 2514|      1|    x
  ------------------
 2553|      1|        SKIP_AFTER_FORK(NSSRWLock_Destroy(dynOidLock));
  ------------------
  |  | 2513|      1|    if (!parentForkedAfterC_Initialize) \
  |  |  ------------------
  |  |  |  Branch (2513:9): [True: 1, False: 0]
  |  |  ------------------
  |  | 2514|      1|    x
  ------------------
 2554|      1|        dynOidLock = NULL;
 2555|      1|    } else {
 2556|       |        /* Since dynOidLock doesn't exist, then all the data it protects
 2557|       |        ** should be uninitialized.  We'll check that (in DEBUG builds),
 2558|       |        ** and then make sure it is so, in case NSS is reinitialized.
 2559|       |        */
 2560|      1|        PORT_Assert(!dynOidHash && !dynOidPool && !dynOidTable &&
  ------------------
  |  |  120|      1|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      8|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 1, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2561|      1|                    !dynOidEntriesAllocated && !dynOidEntriesUsed);
 2562|      1|        dynOidHash = NULL;
 2563|      1|        dynOidPool = NULL;
 2564|      1|        dynOidTable = NULL;
 2565|      1|        dynOidEntriesAllocated = 0;
 2566|      1|        dynOidEntriesUsed = 0;
 2567|      1|    }
 2568|       |    /* we are trashing the old policy state now, also reenable changing
 2569|       |     * the policy as well */
 2570|      2|    nss_policy_locked = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 2571|      2|    memset(xOids, 0, sizeof xOids);
 2572|      2|    return SECSuccess;
 2573|      2|}
UTIL_SetForkState:
 2577|      2|{
 2578|      2|    parentForkedAfterC_Initialize = forked;
 2579|      2|}
secoid.c:secoid_InitDynOidData:
 1949|      1|{
 1950|      1|    SECStatus rv = SECSuccess;
 1951|       |
 1952|      1|    dynOidLock = NSSRWLock_New(1, "dynamic OID data");
  ------------------
  |  |   49|      1|#define NSSRWLock_New NSSRWLock_New_Util
  ------------------
 1953|      1|    if (!dynOidLock) {
  ------------------
  |  Branch (1953:9): [True: 0, False: 1]
  ------------------
 1954|      0|        return SECFailure; /* Error code should already be set. */
 1955|      0|    }
 1956|      1|    dynOidPool = PORT_NewArena(2048);
  ------------------
  |  |   63|      1|#define PORT_NewArena PORT_NewArena_Util
  ------------------
 1957|      1|    if (!dynOidPool) {
  ------------------
  |  Branch (1957:9): [True: 0, False: 1]
  ------------------
 1958|      0|        rv = SECFailure /* Error code should already be set. */;
 1959|      0|    }
 1960|      1|    return rv;
 1961|      1|}
secoid.c:secoid_HashNumber:
 2128|  1.35k|{
 2129|  1.35k|    return (PLHashNumber)((char *)key - (char *)NULL);
 2130|  1.35k|}
secoid.c:secoid_FindDynamic:
 1988|  8.98k|{
 1989|  8.98k|    SECOidData *ret = NULL;
 1990|       |
 1991|  8.98k|    NSSRWLock_LockRead(dynOidLock);
  ------------------
  |  |   47|  8.98k|#define NSSRWLock_LockRead NSSRWLock_LockRead_Util
  ------------------
 1992|  8.98k|    if (dynOidHash) {
  ------------------
  |  Branch (1992:9): [True: 0, False: 8.98k]
  ------------------
 1993|      0|        ret = (SECOidData *)PL_HashTableLookup(dynOidHash, key);
 1994|      0|    }
 1995|  8.98k|    NSSRWLock_UnlockRead(dynOidLock);
  ------------------
  |  |   50|  8.98k|#define NSSRWLock_UnlockRead NSSRWLock_UnlockRead_Util
  ------------------
 1996|  8.98k|    if (ret == NULL) {
  ------------------
  |  Branch (1996:9): [True: 8.98k, False: 0]
  ------------------
 1997|  8.98k|        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
  ------------------
  |  |   65|  8.98k|#define PORT_SetError PORT_SetError_Util
  ------------------
 1998|  8.98k|    }
 1999|  8.98k|    return ret;
 2000|  8.98k|}
secoid.c:secoid_FindXOidByTag:
 2366|  4.58M|{
 2367|  4.58M|    if (tagnum >= SEC_OID_TOTAL) {
  ------------------
  |  Branch (2367:9): [True: 0, False: 4.58M]
  ------------------
 2368|      0|        dynXOid *dxo = secoid_FindDynamicByTag(tagnum);
 2369|      0|        return (dxo ? &dxo->priv : NULL);
  ------------------
  |  Branch (2369:17): [True: 0, False: 0]
  ------------------
 2370|      0|    }
 2371|       |
 2372|  4.58M|    PORT_Assert((unsigned int)tagnum < SEC_OID_TOTAL);
  ------------------
  |  |  120|  4.58M|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|  4.58M|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 4.58M, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
 2373|  4.58M|    return &xOids[tagnum];
 2374|  4.58M|}

PORT_Alloc_Util:
   82|  7.66M|{
   83|  7.66M|    void *rv = NULL;
   84|       |
   85|  7.66M|    if (bytes <= MAX_SIZE) {
  ------------------
  |  |   78|  7.66M|#define MAX_SIZE (PR_UINT32_MAX >> 1)
  |  |  ------------------
  |  |  |  |  302|  7.66M|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  |  |  ------------------
  |  |  |  |  |  |  282|  7.66M|#define PR_UINT32(x) x ## U
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (85:9): [True: 7.66M, False: 0]
  ------------------
   86|       |        /* Always allocate a non-zero amount of bytes */
   87|  7.66M|        rv = PR_Malloc(bytes ? bytes : 1);
  ------------------
  |  Branch (87:24): [True: 7.66M, False: 86]
  ------------------
   88|  7.66M|    }
   89|  7.66M|    if (!rv) {
  ------------------
  |  Branch (89:9): [True: 0, False: 7.66M]
  ------------------
   90|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
   91|      0|    }
   92|  7.66M|    return rv;
   93|  7.66M|}
PORT_Realloc_Util:
   97|  2.69k|{
   98|  2.69k|    void *rv = NULL;
   99|       |
  100|  2.69k|    if (bytes <= MAX_SIZE) {
  ------------------
  |  |   78|  2.69k|#define MAX_SIZE (PR_UINT32_MAX >> 1)
  |  |  ------------------
  |  |  |  |  302|  2.69k|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  |  |  ------------------
  |  |  |  |  |  |  282|  2.69k|#define PR_UINT32(x) x ## U
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (100:9): [True: 2.69k, False: 0]
  ------------------
  101|  2.69k|        rv = PR_Realloc(oldptr, bytes);
  102|  2.69k|    }
  103|  2.69k|    if (!rv) {
  ------------------
  |  Branch (103:9): [True: 0, False: 2.69k]
  ------------------
  104|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  105|      0|    }
  106|  2.69k|    return rv;
  107|  2.69k|}
PORT_ZAlloc_Util:
  111|  5.29M|{
  112|  5.29M|    void *rv = NULL;
  113|       |
  114|  5.29M|    if (bytes <= MAX_SIZE) {
  ------------------
  |  |   78|  5.29M|#define MAX_SIZE (PR_UINT32_MAX >> 1)
  |  |  ------------------
  |  |  |  |  302|  5.29M|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  |  |  ------------------
  |  |  |  |  |  |  282|  5.29M|#define PR_UINT32(x) x ## U
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (114:9): [True: 5.29M, False: 0]
  ------------------
  115|       |        /* Always allocate a non-zero amount of bytes */
  116|  5.29M|        rv = PR_Calloc(1, bytes ? bytes : 1);
  ------------------
  |  Branch (116:27): [True: 5.29M, False: 0]
  ------------------
  117|  5.29M|    }
  118|  5.29M|    if (!rv) {
  ------------------
  |  Branch (118:9): [True: 0, False: 5.29M]
  ------------------
  119|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  120|      0|    }
  121|  5.29M|    return rv;
  122|  5.29M|}
PORT_ZAllocAligned_Util:
  127|   669k|{
  128|   669k|    size_t x = alignment - 1;
  129|       |
  130|       |    /* This only works if alignment is a power of 2. */
  131|   669k|    if ((alignment == 0) || (alignment & (alignment - 1))) {
  ------------------
  |  Branch (131:9): [True: 0, False: 669k]
  |  Branch (131:29): [True: 0, False: 669k]
  ------------------
  132|      0|        PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  133|      0|        return NULL;
  134|      0|    }
  135|       |
  136|   669k|    if (!mem) {
  ------------------
  |  Branch (136:9): [True: 0, False: 669k]
  ------------------
  137|      0|        return NULL;
  138|      0|    }
  139|       |
  140|       |    /* Always allocate a non-zero amount of bytes */
  141|   669k|    *mem = PORT_ZAlloc((bytes ? bytes : 1) + x);
  ------------------
  |  |   72|   669k|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  |  Branch (141:25): [True: 669k, False: 0]
  ------------------
  142|   669k|    if (!*mem) {
  ------------------
  |  Branch (142:9): [True: 0, False: 669k]
  ------------------
  143|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  144|      0|        return NULL;
  145|      0|    }
  146|       |
  147|   669k|    return (void *)(((uintptr_t)*mem + x) & ~(uintptr_t)x);
  148|   669k|}
PORT_ZAllocAlignedOffset_Util:
  152|   669k|{
  153|   669k|    PORT_Assert(offset < size);
  ------------------
  |  |  120|   669k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   669k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 669k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  154|   669k|    if (offset > size) {
  ------------------
  |  Branch (154:9): [True: 0, False: 669k]
  ------------------
  155|      0|        return NULL;
  156|      0|    }
  157|       |
  158|   669k|    void *mem = NULL;
  159|   669k|    void *v = PORT_ZAllocAligned(size, alignment, &mem);
  ------------------
  |  |   73|   669k|#define PORT_ZAllocAligned PORT_ZAllocAligned_Util
  ------------------
  160|   669k|    if (!v) {
  ------------------
  |  Branch (160:9): [True: 0, False: 669k]
  ------------------
  161|      0|        return NULL;
  162|      0|    }
  163|       |
  164|   669k|    PORT_Assert(mem);
  ------------------
  |  |  120|   669k|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|   669k|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 669k, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  165|   669k|    *((void **)((uintptr_t)v + offset)) = mem;
  166|   669k|    return v;
  167|   669k|}
PORT_Free_Util:
  171|  13.0M|{
  172|  13.0M|    if (ptr) {
  ------------------
  |  Branch (172:9): [True: 11.3M, False: 1.66M]
  ------------------
  173|  11.3M|        PR_Free(ptr);
  174|  11.3M|    }
  175|  13.0M|}
PORT_ZFree_Util:
  179|  1.64M|{
  180|  1.64M|    if (ptr) {
  ------------------
  |  Branch (180:9): [True: 1.62M, False: 21.1k]
  ------------------
  181|  1.62M|        memset(ptr, 0, len);
  182|  1.62M|        PR_Free(ptr);
  183|  1.62M|    }
  184|  1.64M|}
PORT_Strdup_Util:
  188|  69.9k|{
  189|  69.9k|    size_t len = PORT_Strlen(str) + 1;
  ------------------
  |  |  190|  69.9k|#define PORT_Strlen(s) strlen(s)
  ------------------
  190|  69.9k|    char *newstr;
  191|       |
  192|  69.9k|    newstr = (char *)PORT_Alloc(len);
  ------------------
  |  |   52|  69.9k|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  193|  69.9k|    if (newstr) {
  ------------------
  |  Branch (193:9): [True: 69.9k, False: 0]
  ------------------
  194|  69.9k|        PORT_Memcpy(newstr, str, len);
  ------------------
  |  |  180|  69.9k|#define PORT_Memcpy memcpy
  ------------------
  195|  69.9k|    }
  196|  69.9k|    return newstr;
  197|  69.9k|}
PORT_SetError_Util:
  201|   821k|{
  202|   821k|    PR_SetError(value, 0);
  203|   821k|    return;
  204|   821k|}
PORT_GetError_Util:
  208|  62.0k|{
  209|  62.0k|    return (PR_GetError());
  210|  62.0k|}
PORT_SafeZero:
  214|   855k|{
  215|       |    /* there are cases where the compiler optimizes away our attempt to clear
  216|       |     * out our stack variables. There are multiple solutions for this problem,
  217|       |     * but they aren't universally accepted on all platforms. This attempts
  218|       |     * to select the best solution available given our os, compilier, and
  219|       |     * libc */
  220|       |#ifdef __STDC_LIB_EXT1__
  221|       |    /* if the os implements C11 annex K, use memset_s */
  222|       |    memset_s(p, n, 0, n);
  223|       |#else
  224|       |    /* _DEFAULT_SORUCE  == BSD source in GCC based environments
  225|       |     * if other environmens support explicit_bzero, their defines
  226|       |     * should be added here */
  227|   855k|#if (defined(_DEFAULT_SOURCE) || defined(_BSD_SOURCE)) && (__GLIBC__ > 2 || (__GLIBC__ == 2 && __GLIBC_MINOR__ >= 25))
  228|   855k|    explicit_bzero(p, n);
  229|       |#else
  230|       |#ifdef XP_WIN
  231|       |    /* windows has a secure zero funtion */
  232|       |    SecureZeroMemory(p, n);
  233|       |#else
  234|       |    /* if the os doesn't support one of the above, but does support
  235|       |     * memset_explicit, you can add the definition for memset with the
  236|       |     * appropriate define check here */
  237|       |    /* define an explicitly implementated Safe zero if the OS
  238|       |     * doesn't provide one */
  239|       |    if (p != NULL) {
  240|       |        volatile unsigned char *__vl = (unsigned char *)p;
  241|       |        size_t __nl = n;
  242|       |        while (__nl--)
  243|       |            *__vl++ = 0;
  244|       |    }
  245|       |#endif /* no windows SecureZeroMemory */
  246|       |#endif /* no explicit_bzero */
  247|   855k|#endif /* no memset_s */
  248|   855k|}
PORT_NewArena_Util:
  300|   496k|{
  301|   496k|    PORTArenaPool *pool;
  302|       |
  303|   496k|    if (chunksize > MAX_SIZE) {
  ------------------
  |  |   78|   496k|#define MAX_SIZE (PR_UINT32_MAX >> 1)
  |  |  ------------------
  |  |  |  |  302|   496k|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  |  |  ------------------
  |  |  |  |  |  |  282|   496k|#define PR_UINT32(x) x ## U
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (303:9): [True: 0, False: 496k]
  ------------------
  304|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  305|      0|        return NULL;
  306|      0|    }
  307|   496k|    pool = PORT_ZNew(PORTArenaPool);
  ------------------
  |  |  148|   496k|#define PORT_ZNew(type) (type *)PORT_ZAlloc(sizeof(type))
  |  |  ------------------
  |  |  |  |   72|   496k|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  308|   496k|    if (!pool) {
  ------------------
  |  Branch (308:9): [True: 0, False: 496k]
  ------------------
  309|      0|        return NULL;
  310|      0|    }
  311|   496k|    pool->magic = ARENAPOOL_MAGIC;
  ------------------
  |  |   51|   496k|#define ARENAPOOL_MAGIC 0xB8AC9BDF
  ------------------
  312|   496k|    pool->lock = PZ_NewLock(nssILockArena);
  ------------------
  |  |  243|   496k|#define PZ_NewLock(t) PR_NewLock()
  ------------------
  313|   496k|    if (!pool->lock) {
  ------------------
  |  Branch (313:9): [True: 0, False: 496k]
  ------------------
  314|      0|        PORT_Free(pool);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  315|      0|        return NULL;
  316|      0|    }
  317|   496k|    PL_InitArenaPool(&pool->arena, "security", chunksize, sizeof(double));
  318|   496k|    return (&pool->arena);
  319|   496k|}
PORT_InitCheapArena:
  323|  60.6k|{
  324|  60.6k|    pool->magic = CHEAP_ARENAPOOL_MAGIC;
  ------------------
  |  |   53|  60.6k|#define CHEAP_ARENAPOOL_MAGIC 0x3F16BB09
  ------------------
  325|  60.6k|    PL_InitArenaPool(&pool->arena, "security", chunksize, sizeof(double));
  326|  60.6k|}
PORT_ArenaAlloc_Util:
  330|  1.74M|{
  331|  1.74M|    void *p = NULL;
  332|       |
  333|  1.74M|    PORTArenaPool *pool = (PORTArenaPool *)arena;
  334|       |
  335|  1.74M|    if (size <= 0) {
  ------------------
  |  Branch (335:9): [True: 4, False: 1.74M]
  ------------------
  336|      4|        size = 1;
  337|      4|    }
  338|       |
  339|  1.74M|    if (size > MAX_SIZE) {
  ------------------
  |  |   78|  1.74M|#define MAX_SIZE (PR_UINT32_MAX >> 1)
  |  |  ------------------
  |  |  |  |  302|  1.74M|#define PR_UINT32_MAX PR_UINT32(4294967295)
  |  |  |  |  ------------------
  |  |  |  |  |  |  282|  1.74M|#define PR_UINT32(x) x ## U
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  |  Branch (339:9): [True: 0, False: 1.74M]
  ------------------
  340|       |        /* you lose. */
  341|      0|    } else
  342|       |        /* Is it one of ours?  Assume so and check the magic */
  343|  1.74M|        if (ARENAPOOL_MAGIC == pool->magic) {
  ------------------
  |  |   51|  1.74M|#define ARENAPOOL_MAGIC 0xB8AC9BDF
  ------------------
  |  Branch (343:13): [True: 1.73M, False: 9.36k]
  ------------------
  344|  1.73M|            PZ_Lock(pool->lock);
  ------------------
  |  |  245|  1.73M|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  345|  1.73M|#ifdef THREADMARK
  346|       |            /* Most likely one of ours.  Is there a thread id? */
  347|  1.73M|            if (pool->marking_thread &&
  ------------------
  |  Branch (347:17): [True: 648k, False: 1.09M]
  ------------------
  348|  1.73M|                pool->marking_thread != PR_GetCurrentThread()) {
  ------------------
  |  Branch (348:17): [True: 0, False: 648k]
  ------------------
  349|       |                /* Another thread holds a mark in this arena */
  350|      0|                PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  351|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  352|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  353|      0|                return NULL;
  354|      0|            } /* tid != null */
  355|  1.73M|#endif        /* THREADMARK */
  356|  1.73M|            PL_ARENA_ALLOCATE(p, arena, size);
  ------------------
  |  |  150|  3.47M|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|  1.73M|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  151|  3.47M|        PLArena *_a = (pool)->current; \
  |  |  152|  3.47M|        PRUint32 _nb = PL_ARENA_ALIGN(pool, (PRUint32)nb); \
  |  |  ------------------
  |  |  |  |  146|  1.73M|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  |  |  ------------------
  |  |  153|  3.47M|        PRUword _p = _a->avail; \
  |  |  154|  3.47M|        if (_nb < (PRUint32)nb) { \
  |  |  ------------------
  |  |  |  Branch (154:13): [True: 0, False: 1.73M]
  |  |  ------------------
  |  |  155|      0|            _p = 0; \
  |  |  156|  1.73M|        } else if (_nb > (_a->limit - _a->avail)) { \
  |  |  ------------------
  |  |  |  Branch (156:20): [True: 450k, False: 1.28M]
  |  |  ------------------
  |  |  157|   450k|            _p = (PRUword)PL_ArenaAllocate(pool, _nb); \
  |  |  158|  1.28M|        } else { \
  |  |  159|  1.28M|            _a->avail += _nb; \
  |  |  160|  1.28M|        } \
  |  |  161|  3.47M|        p = (void *)_p; \
  |  |  162|  3.47M|        if (p) { \
  |  |  ------------------
  |  |  |  Branch (162:13): [True: 1.73M, False: 0]
  |  |  ------------------
  |  |  163|  1.73M|            PL_MAKE_MEM_UNDEFINED(p, (PRUint32)nb); \
  |  |  164|  1.73M|            PL_ArenaCountAllocation(pool, (PRUint32)nb); \
  |  |  165|  1.73M|        } \
  |  |  166|  3.47M|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  1.73M|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  357|  1.73M|            PZ_Unlock(pool->lock);
  ------------------
  |  |  246|  1.73M|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  358|  1.73M|        } else {
  359|  9.36k|            PL_ARENA_ALLOCATE(p, arena, size);
  ------------------
  |  |  150|  9.36k|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|  9.36k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  151|  9.36k|        PLArena *_a = (pool)->current; \
  |  |  152|  9.36k|        PRUint32 _nb = PL_ARENA_ALIGN(pool, (PRUint32)nb); \
  |  |  ------------------
  |  |  |  |  146|  9.36k|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  |  |  ------------------
  |  |  153|  9.36k|        PRUword _p = _a->avail; \
  |  |  154|  9.36k|        if (_nb < (PRUint32)nb) { \
  |  |  ------------------
  |  |  |  Branch (154:13): [True: 0, False: 9.36k]
  |  |  ------------------
  |  |  155|      0|            _p = 0; \
  |  |  156|  9.36k|        } else if (_nb > (_a->limit - _a->avail)) { \
  |  |  ------------------
  |  |  |  Branch (156:20): [True: 5.79k, False: 3.56k]
  |  |  ------------------
  |  |  157|  5.79k|            _p = (PRUword)PL_ArenaAllocate(pool, _nb); \
  |  |  158|  5.79k|        } else { \
  |  |  159|  3.56k|            _a->avail += _nb; \
  |  |  160|  3.56k|        } \
  |  |  161|  9.36k|        p = (void *)_p; \
  |  |  162|  9.36k|        if (p) { \
  |  |  ------------------
  |  |  |  Branch (162:13): [True: 9.36k, False: 0]
  |  |  ------------------
  |  |  163|  9.36k|            PL_MAKE_MEM_UNDEFINED(p, (PRUint32)nb); \
  |  |  164|  9.36k|            PL_ArenaCountAllocation(pool, (PRUint32)nb); \
  |  |  165|  9.36k|        } \
  |  |  166|  9.36k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|  9.36k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  360|  9.36k|        }
  361|       |
  362|  1.74M|    if (!p) {
  ------------------
  |  Branch (362:9): [True: 0, False: 1.74M]
  ------------------
  363|      0|        PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  364|      0|    }
  365|       |
  366|  1.74M|    return (p);
  367|  1.74M|}
PORT_ArenaZAlloc_Util:
  371|   499k|{
  372|   499k|    void *p;
  373|       |
  374|   499k|    if (size <= 0)
  ------------------
  |  Branch (374:9): [True: 39, False: 499k]
  ------------------
  375|     39|        size = 1;
  376|       |
  377|   499k|    p = PORT_ArenaAlloc(arena, size);
  ------------------
  |  |   53|   499k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  378|       |
  379|   499k|    if (p) {
  ------------------
  |  Branch (379:9): [True: 499k, False: 0]
  ------------------
  380|   499k|        PORT_Memset(p, 0, size);
  ------------------
  |  |  182|   499k|#define PORT_Memset memset
  ------------------
  381|   499k|    }
  382|       |
  383|   499k|    return (p);
  384|   499k|}
PORT_FreeArena_Util:
  401|   496k|{
  402|   496k|    PORTArenaPool *pool = (PORTArenaPool *)arena;
  403|   496k|    PRLock *lock = (PRLock *)0;
  404|   496k|    size_t len = sizeof *arena;
  405|       |
  406|   496k|    if (!pool)
  ------------------
  |  Branch (406:9): [True: 0, False: 496k]
  ------------------
  407|      0|        return;
  408|   496k|    if (ARENAPOOL_MAGIC == pool->magic) {
  ------------------
  |  |   51|   496k|#define ARENAPOOL_MAGIC 0xB8AC9BDF
  ------------------
  |  Branch (408:9): [True: 496k, False: 0]
  ------------------
  409|   496k|        len = sizeof *pool;
  410|   496k|        lock = pool->lock;
  411|   496k|        PZ_Lock(lock);
  ------------------
  |  |  245|   496k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  412|   496k|    }
  413|   496k|    if (zero) {
  ------------------
  |  Branch (413:9): [True: 238k, False: 257k]
  ------------------
  414|   238k|        PL_ClearArenaPool(arena, 0);
  415|   238k|    }
  416|   496k|    (void)PR_CallOnce(&setupUseFreeListOnce, &SetupUseFreeList);
  417|   496k|    if (useFreeList) {
  ------------------
  |  Branch (417:9): [True: 496k, False: 0]
  ------------------
  418|   496k|        PL_FreeArenaPool(arena);
  419|   496k|    } else {
  420|      0|        PL_FinishArenaPool(arena);
  421|      0|    }
  422|   496k|    PORT_ZFree(arena, len);
  ------------------
  |  |   75|   496k|#define PORT_ZFree PORT_ZFree_Util
  ------------------
  423|   496k|    if (lock) {
  ------------------
  |  Branch (423:9): [True: 496k, False: 0]
  ------------------
  424|   496k|        PZ_Unlock(lock);
  ------------------
  |  |  246|   496k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  425|   496k|        PZ_DestroyLock(lock);
  ------------------
  |  |  244|   496k|#define PZ_DestroyLock(k) PR_DestroyLock((k))
  ------------------
  426|   496k|    }
  427|   496k|}
PORT_DestroyCheapArena:
  431|  60.6k|{
  432|  60.6k|    (void)PR_CallOnce(&setupUseFreeListOnce, &SetupUseFreeList);
  433|  60.6k|    if (useFreeList) {
  ------------------
  |  Branch (433:9): [True: 60.6k, False: 0]
  ------------------
  434|  60.6k|        PL_FreeArenaPool(&pool->arena);
  435|  60.6k|    } else {
  436|      0|        PL_FinishArenaPool(&pool->arena);
  437|      0|    }
  438|  60.6k|}
PORT_ArenaMark_Util:
  465|   477k|{
  466|   477k|    void *result;
  467|       |
  468|   477k|    PORTArenaPool *pool = (PORTArenaPool *)arena;
  469|   477k|    if (ARENAPOOL_MAGIC == pool->magic) {
  ------------------
  |  |   51|   477k|#define ARENAPOOL_MAGIC 0xB8AC9BDF
  ------------------
  |  Branch (469:9): [True: 476k, False: 834]
  ------------------
  470|   476k|        PZ_Lock(pool->lock);
  ------------------
  |  |  245|   476k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  471|   476k|#ifdef THREADMARK
  472|   476k|        {
  473|   476k|            threadmark_mark *tm, **pw;
  474|   476k|            PRThread *currentThread = PR_GetCurrentThread();
  475|       |
  476|   476k|            if (!pool->marking_thread) {
  ------------------
  |  Branch (476:17): [True: 476k, False: 25]
  ------------------
  477|       |                /* First mark */
  478|   476k|                pool->marking_thread = currentThread;
  479|   476k|            } else if (currentThread != pool->marking_thread) {
  ------------------
  |  Branch (479:24): [True: 0, False: 25]
  ------------------
  480|      0|                PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  481|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  482|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  483|      0|                return NULL;
  484|      0|            }
  485|       |
  486|   476k|            result = PL_ARENA_MARK(arena);
  ------------------
  |  |  187|   476k|#define PL_ARENA_MARK(pool) ((void *) (pool)->current->avail)
  ------------------
  487|   476k|            PL_ARENA_ALLOCATE(tm, arena, sizeof(threadmark_mark));
  ------------------
  |  |  150|   476k|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|   476k|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  151|   476k|        PLArena *_a = (pool)->current; \
  |  |  152|   476k|        PRUint32 _nb = PL_ARENA_ALIGN(pool, (PRUint32)nb); \
  |  |  ------------------
  |  |  |  |  146|   476k|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  |  |  ------------------
  |  |  153|   476k|        PRUword _p = _a->avail; \
  |  |  154|   476k|        if (_nb < (PRUint32)nb) { \
  |  |  ------------------
  |  |  |  Branch (154:13): [True: 0, False: 476k]
  |  |  ------------------
  |  |  155|      0|            _p = 0; \
  |  |  156|   476k|        } else if (_nb > (_a->limit - _a->avail)) { \
  |  |  ------------------
  |  |  |  Branch (156:20): [True: 29.0k, False: 447k]
  |  |  ------------------
  |  |  157|  29.0k|            _p = (PRUword)PL_ArenaAllocate(pool, _nb); \
  |  |  158|   447k|        } else { \
  |  |  159|   447k|            _a->avail += _nb; \
  |  |  160|   447k|        } \
  |  |  161|   476k|        p = (void *)_p; \
  |  |  162|   476k|        if (p) { \
  |  |  ------------------
  |  |  |  Branch (162:13): [True: 476k, False: 0]
  |  |  ------------------
  |  |  163|   476k|            PL_MAKE_MEM_UNDEFINED(p, (PRUint32)nb); \
  |  |  164|   476k|            PL_ArenaCountAllocation(pool, (PRUint32)nb); \
  |  |  165|   476k|        } \
  |  |  166|   476k|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|   476k|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  488|   476k|            if (!tm) {
  ------------------
  |  Branch (488:17): [True: 0, False: 476k]
  ------------------
  489|      0|                PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  490|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  491|      0|                return NULL;
  492|      0|            }
  493|       |
  494|   476k|            tm->mark = result;
  495|   476k|            tm->next = (threadmark_mark *)NULL;
  496|       |
  497|   476k|            pw = &pool->first_mark;
  498|   476k|            while (*pw) {
  ------------------
  |  Branch (498:20): [True: 27, False: 476k]
  ------------------
  499|     27|                pw = &(*pw)->next;
  500|     27|            }
  501|       |
  502|   476k|            *pw = tm;
  503|   476k|        }
  504|       |#else  /* THREADMARK */
  505|       |        result = PL_ARENA_MARK(arena);
  506|       |#endif /* THREADMARK */
  507|   476k|        PZ_Unlock(pool->lock);
  ------------------
  |  |  246|   476k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  508|   476k|    } else {
  509|       |        /* a "pure" NSPR arena */
  510|    834|        result = PL_ARENA_MARK(arena);
  ------------------
  |  |  187|    834|#define PL_ARENA_MARK(pool) ((void *) (pool)->current->avail)
  ------------------
  511|    834|    }
  512|   477k|    return result;
  513|   477k|}
PORT_ArenaRelease_Util:
  617|    128|{
  618|    128|    port_ArenaRelease(arena, mark, PR_FALSE);
  ------------------
  |  |  438|    128|#define PR_FALSE 0
  ------------------
  619|    128|}
PORT_ArenaZRelease:
  626|      6|{
  627|      6|    port_ArenaRelease(arena, mark, PR_TRUE);
  ------------------
  |  |  437|      6|#define PR_TRUE 1
  ------------------
  628|      6|}
PORT_ArenaUnmark_Util:
  632|   477k|{
  633|   477k|#ifdef THREADMARK
  634|   477k|    PORTArenaPool *pool = (PORTArenaPool *)arena;
  635|   477k|    if (ARENAPOOL_MAGIC == pool->magic) {
  ------------------
  |  |   51|   477k|#define ARENAPOOL_MAGIC 0xB8AC9BDF
  ------------------
  |  Branch (635:9): [True: 476k, False: 834]
  ------------------
  636|   476k|        threadmark_mark **pw;
  637|       |
  638|   476k|        PZ_Lock(pool->lock);
  ------------------
  |  |  245|   476k|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  639|       |
  640|   476k|        if (PR_GetCurrentThread() != pool->marking_thread) {
  ------------------
  |  Branch (640:13): [True: 0, False: 476k]
  ------------------
  641|      0|            PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  642|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  643|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  644|      0|            return /* no error indication available */;
  645|      0|        }
  646|       |
  647|   476k|        pw = &pool->first_mark;
  648|   476k|        while (((threadmark_mark *)NULL != *pw) && (mark != (*pw)->mark)) {
  ------------------
  |  Branch (648:16): [True: 476k, False: 0]
  |  Branch (648:52): [True: 21, False: 476k]
  ------------------
  649|     21|            pw = &(*pw)->next;
  650|     21|        }
  651|       |
  652|   476k|        if ((threadmark_mark *)NULL == *pw) {
  ------------------
  |  Branch (652:13): [True: 0, False: 476k]
  ------------------
  653|       |            /* bad mark */
  654|      0|            PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  655|      0|            PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  656|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  657|      0|            return /* no error indication available */;
  658|      0|        }
  659|       |
  660|   476k|        *pw = (threadmark_mark *)NULL;
  661|       |
  662|   476k|        if (!pool->first_mark) {
  ------------------
  |  Branch (662:13): [True: 476k, False: 21]
  ------------------
  663|   476k|            pool->marking_thread = (PRThread *)NULL;
  664|   476k|        }
  665|       |
  666|   476k|        PZ_Unlock(pool->lock);
  ------------------
  |  |  246|   476k|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  667|   476k|    }
  668|   477k|#endif /* THREADMARK */
  669|   477k|}
PORT_ArenaStrdup_Util:
  673|  7.75k|{
  674|  7.75k|    int len = PORT_Strlen(str) + 1;
  ------------------
  |  |  190|  7.75k|#define PORT_Strlen(s) strlen(s)
  ------------------
  675|  7.75k|    char *newstr;
  676|       |
  677|  7.75k|    newstr = (char *)PORT_ArenaAlloc(arena, len);
  ------------------
  |  |   53|  7.75k|#define PORT_ArenaAlloc PORT_ArenaAlloc_Util
  ------------------
  678|  7.75k|    if (newstr) {
  ------------------
  |  Branch (678:9): [True: 7.75k, False: 0]
  ------------------
  679|  7.75k|        PORT_Memcpy(newstr, str, len);
  ------------------
  |  |  180|  7.75k|#define PORT_Memcpy memcpy
  ------------------
  680|  7.75k|    }
  681|  7.75k|    return newstr;
  682|  7.75k|}
PORT_UCS4_UTF8Conversion:
  717|     88|{
  718|     88|    if (!ucs4Utf8ConvertFunc) {
  ------------------
  |  Branch (718:9): [True: 88, False: 0]
  ------------------
  719|     88|        return sec_port_ucs4_utf8_conversion_function(toUnicode,
  720|     88|                                                      inBuf, inBufLen, outBuf, maxOutBufLen, outBufLen);
  721|     88|    }
  722|       |
  723|      0|    return (*ucs4Utf8ConvertFunc)(toUnicode, inBuf, inBufLen, outBuf,
  724|      0|                                  maxOutBufLen, outBufLen);
  725|     88|}
PORT_UCS2_UTF8Conversion_Util:
  731|    273|{
  732|    273|    if (!ucs2Utf8ConvertFunc) {
  ------------------
  |  Branch (732:9): [True: 273, False: 0]
  ------------------
  733|    273|        return sec_port_ucs2_utf8_conversion_function(toUnicode,
  734|    273|                                                      inBuf, inBufLen, outBuf, maxOutBufLen, outBufLen);
  735|    273|    }
  736|       |
  737|      0|    return (*ucs2Utf8ConvertFunc)(toUnicode, inBuf, inBufLen, outBuf,
  738|      0|                                  maxOutBufLen, outBufLen);
  739|    273|}
PORT_ISO88591_UTF8Conversion:
  745|    149|{
  746|    149|    return sec_port_iso88591_utf8_conversion_function(inBuf, inBufLen,
  747|    149|                                                      outBuf, maxOutBufLen, outBufLen);
  748|    149|}
NSS_SecureMemcmp:
  811|   228k|{
  812|   228k|    const unsigned char *a = (const unsigned char *)ia;
  813|   228k|    const unsigned char *b = (const unsigned char *)ib;
  814|   228k|    int r = 0;
  815|       |
  816|  6.07M|    for (size_t i = 0; i < n; ++i) {
  ------------------
  |  Branch (816:24): [True: 5.84M, False: 228k]
  ------------------
  817|  5.84M|        r |= a[i] ^ b[i];
  818|  5.84M|    }
  819|       |
  820|       |    /* 0 <= r < 256, so -r has bit 8 set when r != 0 */
  821|   228k|    return 1 & (-r >> 8);
  822|   228k|}
NSS_SecureMemcmpZero:
  830|  14.6k|{
  831|  14.6k|    const unsigned char *a = (const unsigned char *)mem;
  832|  14.6k|    int r = 0;
  833|       |
  834|   482k|    for (size_t i = 0; i < n; ++i) {
  ------------------
  |  Branch (834:24): [True: 467k, False: 14.6k]
  ------------------
  835|   467k|        r |= a[i];
  836|   467k|    }
  837|       |
  838|       |    /* 0 <= r < 256, so -r has bit 8 set when r != 0 */
  839|  14.6k|    return 1 & (-r >> 8);
  840|  14.6k|}
NSS_GetSystemFIPSEnabled:
  925|      2|{
  926|       |/* if FIPS is disabled in NSS, always return FALSE, even if the environment
  927|       | * variable is set, or the system is in FIPS mode */
  928|       |#ifndef NSS_FIPS_DISABLED
  929|       |    const char *env;
  930|       |
  931|       |    /* The environment variable is active for all platforms */
  932|       |    env = PR_GetEnvSecure("NSS_FIPS");
  933|       |    /* we generally accept y, Y, 1, FIPS, TRUE, and ON as turning on FIPS
  934|       |     * mode. Anything else is considered 'off' */
  935|       |    if (env && (*env == 'y' || *env == '1' || *env == 'Y' ||
  936|       |                (PORT_Strcasecmp(env, "fips") == 0) ||
  937|       |                (PORT_Strcasecmp(env, "true") == 0) ||
  938|       |                (PORT_Strcasecmp(env, "on") == 0))) {
  939|       |        return PR_TRUE;
  940|       |    }
  941|       |
  942|       |/* currently only Linux has a system FIPS indicator. Add others here
  943|       | * as they become available/known */
  944|       |#ifdef LINUX
  945|       |    {
  946|       |        FILE *f;
  947|       |        char d;
  948|       |        size_t size;
  949|       |        f = fopen("/proc/sys/crypto/fips_enabled", "r");
  950|       |        if (!f)
  951|       |            return PR_FALSE;
  952|       |
  953|       |        size = fread(&d, 1, 1, f);
  954|       |        fclose(f);
  955|       |        if (size != 1)
  956|       |            return PR_FALSE;
  957|       |        if (d == '1')
  958|       |            return PR_TRUE;
  959|       |    }
  960|       |#endif /* LINUX */
  961|       |#endif /* NSS_FIPS_DISABLED == 0 */
  962|      2|    return PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  963|      2|}
secport.c:SetupUseFreeList:
  391|      1|{
  392|      1|    useFreeList = (PR_GetEnvSecure("NSS_DISABLE_ARENA_FREE_LIST") == NULL);
  393|      1|    return PR_SUCCESS;
  394|      1|}
secport.c:port_ArenaRelease:
  561|    134|{
  562|    134|    PORTArenaPool *pool = (PORTArenaPool *)arena;
  563|    134|    if (ARENAPOOL_MAGIC == pool->magic) {
  ------------------
  |  |   51|    134|#define ARENAPOOL_MAGIC 0xB8AC9BDF
  ------------------
  |  Branch (563:9): [True: 134, False: 0]
  ------------------
  564|    134|        PZ_Lock(pool->lock);
  ------------------
  |  |  245|    134|#define PZ_Lock(k) PR_Lock((k))
  ------------------
  565|    134|#ifdef THREADMARK
  566|    134|        {
  567|    134|            threadmark_mark **pw;
  568|       |
  569|    134|            if (PR_GetCurrentThread() != pool->marking_thread) {
  ------------------
  |  Branch (569:17): [True: 0, False: 134]
  ------------------
  570|      0|                PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  571|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  572|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  573|      0|                return /* no error indication available */;
  574|      0|            }
  575|       |
  576|    134|            pw = &pool->first_mark;
  577|    140|            while (*pw && (mark != (*pw)->mark)) {
  ------------------
  |  Branch (577:20): [True: 140, False: 0]
  |  Branch (577:27): [True: 6, False: 134]
  ------------------
  578|      6|                pw = &(*pw)->next;
  579|      6|            }
  580|       |
  581|    134|            if (!*pw) {
  ------------------
  |  Branch (581:17): [True: 0, False: 134]
  ------------------
  582|       |                /* bad mark */
  583|      0|                PZ_Unlock(pool->lock);
  ------------------
  |  |  246|      0|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  584|      0|                PORT_SetError(SEC_ERROR_NO_MEMORY);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  585|      0|                PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  586|      0|                return /* no error indication available */;
  587|      0|            }
  588|       |
  589|    134|            *pw = (threadmark_mark *)NULL;
  590|       |
  591|    134|            if (zero) {
  ------------------
  |  Branch (591:17): [True: 6, False: 128]
  ------------------
  592|      6|                port_ArenaZeroAfterMark(arena, mark);
  593|      6|            }
  594|    134|            PL_ARENA_RELEASE(arena, mark);
  ------------------
  |  |  210|    134|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|    134|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  211|    134|        char *_m = (char *)(mark); \
  |  |  212|    134|        PLArena *_a = (pool)->current; \
  |  |  213|    134|        if (PR_UPTRDIFF(_m, _a->base) <= PR_UPTRDIFF(_a->avail, _a->base)) { \
  |  |  ------------------
  |  |  |  |  188|    134|#define PR_UPTRDIFF(p,q) ((PRUword)(p) - (PRUword)(q))
  |  |  ------------------
  |  |                       if (PR_UPTRDIFF(_m, _a->base) <= PR_UPTRDIFF(_a->avail, _a->base)) { \
  |  |  ------------------
  |  |  |  |  188|    134|#define PR_UPTRDIFF(p,q) ((PRUword)(p) - (PRUword)(q))
  |  |  ------------------
  |  |  |  Branch (213:13): [True: 61, False: 73]
  |  |  ------------------
  |  |  214|     61|            _a->avail = (PRUword)PL_ARENA_ALIGN(pool, _m); \
  |  |  ------------------
  |  |  |  |  146|     61|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  |  |  ------------------
  |  |  215|     61|            PL_CLEAR_UNUSED(_a); \
  |  |  ------------------
  |  |  |  |  198|     61|#define PL_CLEAR_UNUSED(a) PL_CLEAR_UNUSED_PATTERN((a), PL_FREE_PATTERN)
  |  |  |  |  ------------------
  |  |  |  |  |  |  191|     61|    PR_BEGIN_MACRO \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  123|     61|#define PR_BEGIN_MACRO  do {
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  192|     61|        PR_ASSERT((a)->avail <= (a)->limit); \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  208|     61|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  Branch (208:6): [True: 61, False: 0]
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  193|     61|        PL_MAKE_MEM_UNDEFINED((void*)(a)->avail, (a)->limit - (a)->avail); \
  |  |  |  |  |  |  194|     61|        memset((void*)(a)->avail, (pattern), (a)->limit - (a)->avail); \
  |  |  |  |  |  |  195|     61|    PR_END_MACRO
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  124|     61|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  216|     61|            PL_MAKE_MEM_NOACCESS((void*)_a->avail, _a->limit - _a->avail); \
  |  |  217|     61|            PL_ArenaCountRetract(pool, _m); \
  |  |  218|     73|        } else { \
  |  |  219|     73|            PL_ArenaRelease(pool, _m); \
  |  |  220|     73|        } \
  |  |  221|    134|        PL_ArenaCountRelease(pool, _m); \
  |  |  222|    134|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|    134|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  595|       |
  596|    134|            if (!pool->first_mark) {
  ------------------
  |  Branch (596:17): [True: 130, False: 4]
  ------------------
  597|    130|                pool->marking_thread = (PRThread *)NULL;
  598|    130|            }
  599|    134|        }
  600|       |#else  /* THREADMARK */
  601|       |        if (zero) {
  602|       |            port_ArenaZeroAfterMark(arena, mark);
  603|       |        }
  604|       |        PL_ARENA_RELEASE(arena, mark);
  605|       |#endif /* THREADMARK */
  606|    134|        PZ_Unlock(pool->lock);
  ------------------
  |  |  246|    134|#define PZ_Unlock(k) PR_Unlock((k))
  ------------------
  607|    134|    } else {
  608|      0|        if (zero) {
  ------------------
  |  Branch (608:13): [True: 0, False: 0]
  ------------------
  609|      0|            port_ArenaZeroAfterMark(arena, mark);
  610|      0|        }
  611|      0|        PL_ARENA_RELEASE(arena, mark);
  ------------------
  |  |  210|      0|    PR_BEGIN_MACRO \
  |  |  ------------------
  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  ------------------
  |  |  211|      0|        char *_m = (char *)(mark); \
  |  |  212|      0|        PLArena *_a = (pool)->current; \
  |  |  213|      0|        if (PR_UPTRDIFF(_m, _a->base) <= PR_UPTRDIFF(_a->avail, _a->base)) { \
  |  |  ------------------
  |  |  |  |  188|      0|#define PR_UPTRDIFF(p,q) ((PRUword)(p) - (PRUword)(q))
  |  |  ------------------
  |  |                       if (PR_UPTRDIFF(_m, _a->base) <= PR_UPTRDIFF(_a->avail, _a->base)) { \
  |  |  ------------------
  |  |  |  |  188|      0|#define PR_UPTRDIFF(p,q) ((PRUword)(p) - (PRUword)(q))
  |  |  ------------------
  |  |  |  Branch (213:13): [True: 0, False: 0]
  |  |  ------------------
  |  |  214|      0|            _a->avail = (PRUword)PL_ARENA_ALIGN(pool, _m); \
  |  |  ------------------
  |  |  |  |  146|      0|#define PL_ARENA_ALIGN(pool, n) (((PRUword)(n) + (pool)->mask) & ~(pool)->mask)
  |  |  ------------------
  |  |  215|      0|            PL_CLEAR_UNUSED(_a); \
  |  |  ------------------
  |  |  |  |  198|      0|#define PL_CLEAR_UNUSED(a) PL_CLEAR_UNUSED_PATTERN((a), PL_FREE_PATTERN)
  |  |  |  |  ------------------
  |  |  |  |  |  |  191|      0|    PR_BEGIN_MACRO \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  123|      0|#define PR_BEGIN_MACRO  do {
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  192|      0|        PR_ASSERT((a)->avail <= (a)->limit); \
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  Branch (208:6): [True: 0, False: 0]
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  193|      0|        PL_MAKE_MEM_UNDEFINED((void*)(a)->avail, (a)->limit - (a)->avail); \
  |  |  |  |  |  |  194|      0|        memset((void*)(a)->avail, (pattern), (a)->limit - (a)->avail); \
  |  |  |  |  |  |  195|      0|    PR_END_MACRO
  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  |  |  |  |  ------------------
  |  |  |  |  |  |  ------------------
  |  |  |  |  ------------------
  |  |  ------------------
  |  |  216|      0|            PL_MAKE_MEM_NOACCESS((void*)_a->avail, _a->limit - _a->avail); \
  |  |  217|      0|            PL_ArenaCountRetract(pool, _m); \
  |  |  218|      0|        } else { \
  |  |  219|      0|            PL_ArenaRelease(pool, _m); \
  |  |  220|      0|        } \
  |  |  221|      0|        PL_ArenaCountRelease(pool, _m); \
  |  |  222|      0|    PR_END_MACRO
  |  |  ------------------
  |  |  |  |  124|      0|#define PR_END_MACRO    } while (0)
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (124:34): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  612|      0|    }
  613|    134|}
secport.c:port_ArenaZeroAfterMark:
  528|      6|{
  529|      6|    PLArena *a = arena->current;
  530|      6|    if (a->base <= (PRUword)mark && (PRUword)mark <= a->avail) {
  ------------------
  |  Branch (530:9): [True: 6, False: 0]
  |  Branch (530:37): [True: 6, False: 0]
  ------------------
  531|       |/* fast path: mark falls in the current arena */
  532|      6|#ifdef PL_MAKE_MEM_UNDEFINED
  533|      6|        PL_MAKE_MEM_UNDEFINED(mark, a->avail - (PRUword)mark);
  534|      6|#endif
  535|      6|        memset(mark, 0, a->avail - (PRUword)mark);
  536|      6|    } else {
  537|       |        /* slow path: need to find the arena that mark falls in */
  538|      0|        for (a = arena->first.next; a; a = a->next) {
  ------------------
  |  Branch (538:37): [True: 0, False: 0]
  ------------------
  539|      0|            PR_ASSERT(a->base <= a->avail && a->avail <= a->limit);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  540|      0|            if (a->base <= (PRUword)mark && (PRUword)mark <= a->avail) {
  ------------------
  |  Branch (540:17): [True: 0, False: 0]
  |  Branch (540:45): [True: 0, False: 0]
  ------------------
  541|      0|#ifdef PL_MAKE_MEM_UNDEFINED
  542|      0|                PL_MAKE_MEM_UNDEFINED(mark, a->avail - (PRUword)mark);
  543|      0|#endif
  544|      0|                memset(mark, 0, a->avail - (PRUword)mark);
  545|      0|                a = a->next;
  546|      0|                break;
  547|      0|            }
  548|      0|        }
  549|      0|        for (; a; a = a->next) {
  ------------------
  |  Branch (549:16): [True: 0, False: 0]
  ------------------
  550|      0|            PR_ASSERT(a->base <= a->avail && a->avail <= a->limit);
  ------------------
  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  ------------------
  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  |  Branch (208:7): [True: 0, False: 0]
  |  |  ------------------
  ------------------
  551|      0|#ifdef PL_MAKE_MEM_UNDEFINED
  552|      0|            PL_MAKE_MEM_UNDEFINED((void *)a->base, a->avail - a->base);
  553|      0|#endif
  554|      0|            memset((void *)a->base, 0, a->avail - a->base);
  555|      0|        }
  556|      0|    }
  557|      6|}

DER_DecodeTimeChoice_Util:
  135|    604|{
  136|    604|    switch (input->type) {
  137|     36|        case siGeneralizedTime:
  ------------------
  |  Branch (137:9): [True: 36, False: 568]
  ------------------
  138|     36|            return DER_GeneralizedTimeToTime(output, input);
  ------------------
  |  |   26|     36|#define DER_GeneralizedTimeToTime DER_GeneralizedTimeToTime_Util
  ------------------
  139|       |
  140|    568|        case siUTCTime:
  ------------------
  |  Branch (140:9): [True: 568, False: 36]
  ------------------
  141|    568|            return DER_UTCTimeToTime(output, input);
  ------------------
  |  |   35|    568|#define DER_UTCTimeToTime DER_UTCTimeToTime_Util
  ------------------
  142|       |
  143|      0|        default:
  ------------------
  |  Branch (143:9): [True: 0, False: 604]
  ------------------
  144|      0|            PORT_SetError(SEC_ERROR_INVALID_ARGS);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  145|      0|            PORT_Assert(0);
  ------------------
  |  |  120|      0|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|      0|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [Folded - Ignored]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  146|      0|            return SECFailure;
  147|    604|    }
  148|    604|}

sec_port_ucs4_utf8_conversion_function:
  132|     88|{
  133|     88|    PORT_Assert((unsigned int *)NULL != outBufLen);
  ------------------
  |  |  120|     88|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     88|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 88, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  134|       |
  135|     88|    if (toUnicode) {
  ------------------
  |  Branch (135:9): [True: 0, False: 88]
  ------------------
  136|      0|        unsigned int i, len = 0;
  137|       |
  138|      0|        for (i = 0; i < inBufLen;) {
  ------------------
  |  Branch (138:21): [True: 0, False: 0]
  ------------------
  139|      0|            if ((inBuf[i] & 0x80) == 0x00)
  ------------------
  |  Branch (139:17): [True: 0, False: 0]
  ------------------
  140|      0|                i += 1;
  141|      0|            else if ((inBuf[i] & 0xE0) == 0xC0)
  ------------------
  |  Branch (141:22): [True: 0, False: 0]
  ------------------
  142|      0|                i += 2;
  143|      0|            else if ((inBuf[i] & 0xF0) == 0xE0)
  ------------------
  |  Branch (143:22): [True: 0, False: 0]
  ------------------
  144|      0|                i += 3;
  145|      0|            else if ((inBuf[i] & 0xF8) == 0xF0)
  ------------------
  |  Branch (145:22): [True: 0, False: 0]
  ------------------
  146|      0|                i += 4;
  147|      0|            else
  148|      0|                return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  149|       |
  150|      0|            len += 4;
  151|      0|        }
  152|       |
  153|      0|        if (len > maxOutBufLen) {
  ------------------
  |  Branch (153:13): [True: 0, False: 0]
  ------------------
  154|      0|            *outBufLen = len;
  155|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  156|      0|        }
  157|       |
  158|      0|        len = 0;
  159|       |
  160|      0|        for (i = 0; i < inBufLen;) {
  ------------------
  |  Branch (160:21): [True: 0, False: 0]
  ------------------
  161|      0|            PRUint32 ucs4 = sec_port_read_utf8(&i, inBuf, inBufLen);
  162|       |
  163|      0|            if (ucs4 == BAD_UTF8)
  ------------------
  |  |   63|      0|#define BAD_UTF8 ((PRUint32)-1)
  ------------------
  |  Branch (163:17): [True: 0, False: 0]
  ------------------
  164|      0|                return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  165|       |
  166|      0|            outBuf[len + L_0] = 0x00;
  ------------------
  |  |   56|      0|#define L_0 0
  ------------------
  167|      0|            outBuf[len + L_1] = (unsigned char)(ucs4 >> 16);
  ------------------
  |  |   57|      0|#define L_1 1
  ------------------
  168|      0|            outBuf[len + L_2] = (unsigned char)(ucs4 >> 8);
  ------------------
  |  |   58|      0|#define L_2 2
  ------------------
  169|      0|            outBuf[len + L_3] = (unsigned char)ucs4;
  ------------------
  |  |   59|      0|#define L_3 3
  ------------------
  170|       |
  171|      0|            len += 4;
  172|      0|        }
  173|       |
  174|      0|        *outBufLen = len;
  175|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  176|     88|    } else {
  177|     88|        unsigned int i, len = 0;
  178|     88|        PORT_Assert((inBufLen % 4) == 0);
  ------------------
  |  |  120|     88|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     88|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 88, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  179|     88|        if ((inBufLen % 4) != 0) {
  ------------------
  |  Branch (179:13): [True: 0, False: 88]
  ------------------
  180|      0|            *outBufLen = 0;
  181|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  182|      0|        }
  183|       |
  184|    232|        for (i = 0; i < inBufLen; i += 4) {
  ------------------
  |  Branch (184:21): [True: 183, False: 49]
  ------------------
  185|    183|            if ((inBuf[i + L_0] > 0x00) || (inBuf[i + L_1] > 0x10)) {
  ------------------
  |  |   56|    183|#define L_0 0
  ------------------
                          if ((inBuf[i + L_0] > 0x00) || (inBuf[i + L_1] > 0x10)) {
  ------------------
  |  |   57|    160|#define L_1 1
  ------------------
  |  Branch (185:17): [True: 23, False: 160]
  |  Branch (185:44): [True: 16, False: 144]
  ------------------
  186|     39|                *outBufLen = 0;
  187|     39|                return PR_FALSE;
  ------------------
  |  |  438|     39|#define PR_FALSE 0
  ------------------
  188|    144|            } else if (inBuf[i + L_1] >= 0x01)
  ------------------
  |  |   57|    144|#define L_1 1
  ------------------
  |  Branch (188:24): [True: 48, False: 96]
  ------------------
  189|     48|                len += 4;
  190|     96|            else if (inBuf[i + L_2] >= 0x08)
  ------------------
  |  |   58|     96|#define L_2 2
  ------------------
  |  Branch (190:22): [True: 44, False: 52]
  ------------------
  191|     44|                len += 3;
  192|     52|            else if ((inBuf[i + L_2] > 0x00) || (inBuf[i + L_3] >= 0x80))
  ------------------
  |  |   58|     52|#define L_2 2
  ------------------
                          else if ((inBuf[i + L_2] > 0x00) || (inBuf[i + L_3] >= 0x80))
  ------------------
  |  |   59|     36|#define L_3 3
  ------------------
  |  Branch (192:22): [True: 16, False: 36]
  |  Branch (192:49): [True: 11, False: 25]
  ------------------
  193|     27|                len += 2;
  194|     25|            else
  195|     25|                len += 1;
  196|    183|        }
  197|       |
  198|     49|        if (len > maxOutBufLen) {
  ------------------
  |  Branch (198:13): [True: 0, False: 49]
  ------------------
  199|      0|            *outBufLen = len;
  200|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  201|      0|        }
  202|       |
  203|     49|        len = 0;
  204|       |
  205|    169|        for (i = 0; i < inBufLen; i += 4) {
  ------------------
  |  Branch (205:21): [True: 120, False: 49]
  ------------------
  206|    120|            if (inBuf[i + L_1] >= 0x01) {
  ------------------
  |  |   57|    120|#define L_1 1
  ------------------
  |  Branch (206:17): [True: 32, False: 88]
  ------------------
  207|       |                /* 0001 0000-001F FFFF -> 11110xxx 10xxxxxx 10xxxxxx 10xxxxxx */
  208|       |                /* 00000000 000abcde fghijklm nopqrstu ->
  209|       |                   11110abc 10defghi 10jklmno 10pqrstu */
  210|       |
  211|     32|                outBuf[len + 0] = 0xF0 | ((inBuf[i + L_1] & 0x1C) >> 2);
  ------------------
  |  |   57|     32|#define L_1 1
  ------------------
  212|     32|                outBuf[len + 1] = 0x80 | ((inBuf[i + L_1] & 0x03) << 4) | ((inBuf[i + L_2] & 0xF0) >> 4);
  ------------------
  |  |   57|     32|#define L_1 1
  ------------------
                              outBuf[len + 1] = 0x80 | ((inBuf[i + L_1] & 0x03) << 4) | ((inBuf[i + L_2] & 0xF0) >> 4);
  ------------------
  |  |   58|     32|#define L_2 2
  ------------------
  213|     32|                outBuf[len + 2] = 0x80 | ((inBuf[i + L_2] & 0x0F) << 2) | ((inBuf[i + L_3] & 0xC0) >> 6);
  ------------------
  |  |   58|     32|#define L_2 2
  ------------------
                              outBuf[len + 2] = 0x80 | ((inBuf[i + L_2] & 0x0F) << 2) | ((inBuf[i + L_3] & 0xC0) >> 6);
  ------------------
  |  |   59|     32|#define L_3 3
  ------------------
  214|     32|                outBuf[len + 3] = 0x80 | ((inBuf[i + L_3] & 0x3F) >> 0);
  ------------------
  |  |   59|     32|#define L_3 3
  ------------------
  215|       |
  216|     32|                len += 4;
  217|     88|            } else if (inBuf[i + L_2] >= 0x08) {
  ------------------
  |  |   58|     88|#define L_2 2
  ------------------
  |  Branch (217:24): [True: 40, False: 48]
  ------------------
  218|       |                /* 0000 0800-0000 FFFF -> 1110xxxx 10xxxxxx 10xxxxxx */
  219|       |                /* 00000000 00000000 abcdefgh ijklmnop ->
  220|       |                   1110abcd 10efghij 10klmnop */
  221|       |
  222|     40|                outBuf[len + 0] = 0xE0 | ((inBuf[i + L_2] & 0xF0) >> 4);
  ------------------
  |  |   58|     40|#define L_2 2
  ------------------
  223|     40|                outBuf[len + 1] = 0x80 | ((inBuf[i + L_2] & 0x0F) << 2) | ((inBuf[i + L_3] & 0xC0) >> 6);
  ------------------
  |  |   58|     40|#define L_2 2
  ------------------
                              outBuf[len + 1] = 0x80 | ((inBuf[i + L_2] & 0x0F) << 2) | ((inBuf[i + L_3] & 0xC0) >> 6);
  ------------------
  |  |   59|     40|#define L_3 3
  ------------------
  224|     40|                outBuf[len + 2] = 0x80 | ((inBuf[i + L_3] & 0x3F) >> 0);
  ------------------
  |  |   59|     40|#define L_3 3
  ------------------
  225|       |
  226|     40|                len += 3;
  227|     48|            } else if ((inBuf[i + L_2] > 0x00) || (inBuf[i + L_3] >= 0x80)) {
  ------------------
  |  |   58|     48|#define L_2 2
  ------------------
                          } else if ((inBuf[i + L_2] > 0x00) || (inBuf[i + L_3] >= 0x80)) {
  ------------------
  |  |   59|     33|#define L_3 3
  ------------------
  |  Branch (227:24): [True: 15, False: 33]
  |  Branch (227:51): [True: 11, False: 22]
  ------------------
  228|       |                /* 0000 0080-0000 07FF -> 110xxxxx 10xxxxxx */
  229|       |                /* 00000000 00000000 00000abc defghijk ->
  230|       |                   110abcde 10fghijk */
  231|       |
  232|     26|                outBuf[len + 0] = 0xC0 | ((inBuf[i + L_2] & 0x07) << 2) | ((inBuf[i + L_3] & 0xC0) >> 6);
  ------------------
  |  |   58|     26|#define L_2 2
  ------------------
                              outBuf[len + 0] = 0xC0 | ((inBuf[i + L_2] & 0x07) << 2) | ((inBuf[i + L_3] & 0xC0) >> 6);
  ------------------
  |  |   59|     26|#define L_3 3
  ------------------
  233|     26|                outBuf[len + 1] = 0x80 | ((inBuf[i + L_3] & 0x3F) >> 0);
  ------------------
  |  |   59|     26|#define L_3 3
  ------------------
  234|       |
  235|     26|                len += 2;
  236|     26|            } else {
  237|       |                /* 0000 0000-0000 007F -> 0xxxxxx */
  238|       |                /* 00000000 00000000 00000000 0abcdefg ->
  239|       |                   0abcdefg */
  240|       |
  241|     22|                outBuf[len + 0] = (inBuf[i + L_3] & 0x7F);
  ------------------
  |  |   59|     22|#define L_3 3
  ------------------
  242|       |
  243|     22|                len += 1;
  244|     22|            }
  245|    120|        }
  246|       |
  247|     49|        *outBufLen = len;
  248|     49|        return PR_TRUE;
  ------------------
  |  |  437|     49|#define PR_TRUE 1
  ------------------
  249|     49|    }
  250|     88|}
sec_port_ucs2_utf8_conversion_function:
  260|    273|{
  261|    273|    PORT_Assert((unsigned int *)NULL != outBufLen);
  ------------------
  |  |  120|    273|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    273|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 273, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  262|       |
  263|    273|    if (toUnicode) {
  ------------------
  |  Branch (263:9): [True: 0, False: 273]
  ------------------
  264|      0|        unsigned int i, len = 0;
  265|       |
  266|      0|        for (i = 0; i < inBufLen;) {
  ------------------
  |  Branch (266:21): [True: 0, False: 0]
  ------------------
  267|      0|            if ((inBuf[i] & 0x80) == 0x00) {
  ------------------
  |  Branch (267:17): [True: 0, False: 0]
  ------------------
  268|      0|                i += 1;
  269|      0|                len += 2;
  270|      0|            } else if ((inBuf[i] & 0xE0) == 0xC0) {
  ------------------
  |  Branch (270:24): [True: 0, False: 0]
  ------------------
  271|      0|                i += 2;
  272|      0|                len += 2;
  273|      0|            } else if ((inBuf[i] & 0xF0) == 0xE0) {
  ------------------
  |  Branch (273:24): [True: 0, False: 0]
  ------------------
  274|      0|                i += 3;
  275|      0|                len += 2;
  276|      0|            } else if ((inBuf[i] & 0xF8) == 0xF0) {
  ------------------
  |  Branch (276:24): [True: 0, False: 0]
  ------------------
  277|      0|                i += 4;
  278|      0|                len += 4;
  279|      0|            } else
  280|      0|                return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  281|      0|        }
  282|       |
  283|      0|        if (len > maxOutBufLen) {
  ------------------
  |  Branch (283:13): [True: 0, False: 0]
  ------------------
  284|      0|            *outBufLen = len;
  285|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  286|      0|        }
  287|       |
  288|      0|        len = 0;
  289|       |
  290|      0|        for (i = 0; i < inBufLen;) {
  ------------------
  |  Branch (290:21): [True: 0, False: 0]
  ------------------
  291|      0|            PRUint32 ucs4 = sec_port_read_utf8(&i, inBuf, inBufLen);
  292|       |
  293|      0|            if (ucs4 == BAD_UTF8)
  ------------------
  |  |   63|      0|#define BAD_UTF8 ((PRUint32)-1)
  ------------------
  |  Branch (293:17): [True: 0, False: 0]
  ------------------
  294|      0|                return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  295|       |
  296|      0|            if (ucs4 < 0x10000) {
  ------------------
  |  Branch (296:17): [True: 0, False: 0]
  ------------------
  297|      0|                outBuf[len + H_0] = (unsigned char)(ucs4 >> 8);
  ------------------
  |  |   60|      0|#define H_0 0
  ------------------
  298|      0|                outBuf[len + H_1] = (unsigned char)ucs4;
  ------------------
  |  |   61|      0|#define H_1 1
  ------------------
  299|      0|                len += 2;
  300|      0|            } else {
  301|      0|                ucs4 -= 0x10000;
  302|      0|                outBuf[len + 0 + H_0] = (unsigned char)(0xD8 | ((ucs4 >> 18) & 0x3));
  ------------------
  |  |   60|      0|#define H_0 0
  ------------------
  303|      0|                outBuf[len + 0 + H_1] = (unsigned char)(ucs4 >> 10);
  ------------------
  |  |   61|      0|#define H_1 1
  ------------------
  304|      0|                outBuf[len + 2 + H_0] = (unsigned char)(0xDC | ((ucs4 >> 8) & 0x3));
  ------------------
  |  |   60|      0|#define H_0 0
  ------------------
  305|      0|                outBuf[len + 2 + H_1] = (unsigned char)ucs4;
  ------------------
  |  |   61|      0|#define H_1 1
  ------------------
  306|      0|                len += 4;
  307|      0|            }
  308|      0|        }
  309|       |
  310|      0|        *outBufLen = len;
  311|      0|        return PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  312|    273|    } else {
  313|    273|        unsigned int i, len = 0;
  314|    273|        PORT_Assert((inBufLen % 2) == 0);
  ------------------
  |  |  120|    273|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    273|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 273, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  315|    273|        if ((inBufLen % 2) != 0) {
  ------------------
  |  Branch (315:13): [True: 0, False: 273]
  ------------------
  316|      0|            *outBufLen = 0;
  317|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  318|      0|        }
  319|       |
  320|  1.63k|        for (i = 0; i < inBufLen; i += 2) {
  ------------------
  |  Branch (320:21): [True: 1.38k, False: 242]
  ------------------
  321|  1.38k|            if ((inBuf[i + H_0] == 0x00) && ((inBuf[i + H_1] & 0x80) == 0x00))
  ------------------
  |  |   60|  1.38k|#define H_0 0
  ------------------
                          if ((inBuf[i + H_0] == 0x00) && ((inBuf[i + H_1] & 0x80) == 0x00))
  ------------------
  |  |   61|    422|#define H_1 1
  ------------------
  |  Branch (321:17): [True: 422, False: 966]
  |  Branch (321:45): [True: 305, False: 117]
  ------------------
  322|    305|                len += 1;
  323|  1.08k|            else if (inBuf[i + H_0] < 0x08)
  ------------------
  |  |   60|  1.08k|#define H_0 0
  ------------------
  |  Branch (323:22): [True: 191, False: 892]
  ------------------
  324|    191|                len += 2;
  325|    892|            else if (((inBuf[i + H_0] & 0xFC) == 0xD8)) {
  ------------------
  |  |   60|    892|#define H_0 0
  ------------------
  |  Branch (325:22): [True: 26, False: 866]
  ------------------
  326|     26|                if (((inBufLen - i) > 2) && ((inBuf[i + 2 + H_0] & 0xFC) == 0xDC)) {
  ------------------
  |  |   60|     20|#define H_0 0
  ------------------
  |  Branch (326:21): [True: 20, False: 6]
  |  Branch (326:45): [True: 9, False: 11]
  ------------------
  327|      9|                    i += 2;
  328|      9|                    len += 4;
  329|     17|                } else {
  330|     17|                    return PR_FALSE;
  ------------------
  |  |  438|     17|#define PR_FALSE 0
  ------------------
  331|     17|                }
  332|    866|            } else if ((inBuf[i + H_0] & 0xFC) == 0xDC) {
  ------------------
  |  |   60|    866|#define H_0 0
  ------------------
  |  Branch (332:24): [True: 14, False: 852]
  ------------------
  333|     14|                return PR_FALSE;
  ------------------
  |  |  438|     14|#define PR_FALSE 0
  ------------------
  334|    852|            } else {
  335|    852|                len += 3;
  336|    852|            }
  337|  1.38k|        }
  338|       |
  339|    242|        if (len > maxOutBufLen) {
  ------------------
  |  Branch (339:13): [True: 0, False: 242]
  ------------------
  340|      0|            *outBufLen = len;
  341|      0|            return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  342|      0|        }
  343|       |
  344|    242|        len = 0;
  345|       |
  346|  1.45k|        for (i = 0; i < inBufLen; i += 2) {
  ------------------
  |  Branch (346:21): [True: 1.21k, False: 242]
  ------------------
  347|  1.21k|            if ((inBuf[i + H_0] == 0x00) && ((inBuf[i + H_1] & 0x80) == 0x00)) {
  ------------------
  |  |   60|  1.21k|#define H_0 0
  ------------------
                          if ((inBuf[i + H_0] == 0x00) && ((inBuf[i + H_1] & 0x80) == 0x00)) {
  ------------------
  |  |   61|    401|#define H_1 1
  ------------------
  |  Branch (347:17): [True: 401, False: 811]
  |  Branch (347:45): [True: 294, False: 107]
  ------------------
  348|       |                /* 0000-007F -> 0xxxxxx */
  349|       |                /* 00000000 0abcdefg -> 0abcdefg */
  350|       |
  351|    294|                outBuf[len] = inBuf[i + H_1] & 0x7F;
  ------------------
  |  |   61|    294|#define H_1 1
  ------------------
  352|       |
  353|    294|                len += 1;
  354|    918|            } else if (inBuf[i + H_0] < 0x08) {
  ------------------
  |  |   60|    918|#define H_0 0
  ------------------
  |  Branch (354:24): [True: 171, False: 747]
  ------------------
  355|       |                /* 0080-07FF -> 110xxxxx 10xxxxxx */
  356|       |                /* 00000abc defghijk -> 110abcde 10fghijk */
  357|       |
  358|    171|                outBuf[len + 0] = 0xC0 | ((inBuf[i + H_0] & 0x07) << 2) | ((inBuf[i + H_1] & 0xC0) >> 6);
  ------------------
  |  |   60|    171|#define H_0 0
  ------------------
                              outBuf[len + 0] = 0xC0 | ((inBuf[i + H_0] & 0x07) << 2) | ((inBuf[i + H_1] & 0xC0) >> 6);
  ------------------
  |  |   61|    171|#define H_1 1
  ------------------
  359|    171|                outBuf[len + 1] = 0x80 | ((inBuf[i + H_1] & 0x3F) >> 0);
  ------------------
  |  |   61|    171|#define H_1 1
  ------------------
  360|       |
  361|    171|                len += 2;
  362|    747|            } else if ((inBuf[i + H_0] & 0xFC) == 0xD8) {
  ------------------
  |  |   60|    747|#define H_0 0
  ------------------
  |  Branch (362:24): [True: 8, False: 739]
  ------------------
  363|      8|                int abcde, BCDE;
  364|       |
  365|      8|                PORT_Assert(((inBufLen - i) > 2) && ((inBuf[i + 2 + H_0] & 0xFC) == 0xDC));
  ------------------
  |  |  120|      8|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     16|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:7): [True: 8, False: 0]
  |  |  |  |  |  Branch (208:7): [True: 8, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  366|       |
  367|       |                /* D800-DBFF DC00-DFFF -> 11110xxx 10xxxxxx 10xxxxxx 10xxxxxx */
  368|       |                /* 110110BC DEfghijk 110111lm nopqrstu ->
  369|       |                   { Let abcde = BCDE + 1 }
  370|       |                   11110abc 10defghi 10jklmno 10pqrstu */
  371|       |
  372|      8|                BCDE = ((inBuf[i + H_0] & 0x03) << 2) | ((inBuf[i + H_1] & 0xC0) >> 6);
  ------------------
  |  |   60|      8|#define H_0 0
  ------------------
                              BCDE = ((inBuf[i + H_0] & 0x03) << 2) | ((inBuf[i + H_1] & 0xC0) >> 6);
  ------------------
  |  |   61|      8|#define H_1 1
  ------------------
  373|      8|                abcde = BCDE + 1;
  374|       |
  375|      8|                outBuf[len + 0] = 0xF0 | ((abcde & 0x1C) >> 2);
  376|      8|                outBuf[len + 1] = 0x80 | ((abcde & 0x03) << 4) | ((inBuf[i + 0 + H_1] & 0x3C) >> 2);
  ------------------
  |  |   61|      8|#define H_1 1
  ------------------
  377|      8|                outBuf[len + 2] = 0x80 | ((inBuf[i + 0 + H_1] & 0x03) << 4) | ((inBuf[i + 2 + H_0] & 0x03) << 2) | ((inBuf[i + 2 + H_1] & 0xC0) >> 6);
  ------------------
  |  |   61|      8|#define H_1 1
  ------------------
                              outBuf[len + 2] = 0x80 | ((inBuf[i + 0 + H_1] & 0x03) << 4) | ((inBuf[i + 2 + H_0] & 0x03) << 2) | ((inBuf[i + 2 + H_1] & 0xC0) >> 6);
  ------------------
  |  |   60|      8|#define H_0 0
  ------------------
                              outBuf[len + 2] = 0x80 | ((inBuf[i + 0 + H_1] & 0x03) << 4) | ((inBuf[i + 2 + H_0] & 0x03) << 2) | ((inBuf[i + 2 + H_1] & 0xC0) >> 6);
  ------------------
  |  |   61|      8|#define H_1 1
  ------------------
  378|      8|                outBuf[len + 3] = 0x80 | ((inBuf[i + 2 + H_1] & 0x3F) >> 0);
  ------------------
  |  |   61|      8|#define H_1 1
  ------------------
  379|       |
  380|      8|                i += 2;
  381|      8|                len += 4;
  382|    739|            } else {
  383|       |                /* 0800-FFFF -> 1110xxxx 10xxxxxx 10xxxxxx */
  384|       |                /* abcdefgh ijklmnop -> 1110abcd 10efghij 10klmnop */
  385|       |
  386|    739|                outBuf[len + 0] = 0xE0 | ((inBuf[i + H_0] & 0xF0) >> 4);
  ------------------
  |  |   60|    739|#define H_0 0
  ------------------
  387|    739|                outBuf[len + 1] = 0x80 | ((inBuf[i + H_0] & 0x0F) << 2) | ((inBuf[i + H_1] & 0xC0) >> 6);
  ------------------
  |  |   60|    739|#define H_0 0
  ------------------
                              outBuf[len + 1] = 0x80 | ((inBuf[i + H_0] & 0x0F) << 2) | ((inBuf[i + H_1] & 0xC0) >> 6);
  ------------------
  |  |   61|    739|#define H_1 1
  ------------------
  388|    739|                outBuf[len + 2] = 0x80 | ((inBuf[i + H_1] & 0x3F) >> 0);
  ------------------
  |  |   61|    739|#define H_1 1
  ------------------
  389|       |
  390|    739|                len += 3;
  391|    739|            }
  392|  1.21k|        }
  393|       |
  394|    242|        *outBufLen = len;
  395|    242|        return PR_TRUE;
  ------------------
  |  |  437|    242|#define PR_TRUE 1
  ------------------
  396|    242|    }
  397|    273|}
sec_port_iso88591_utf8_conversion_function:
  406|    149|{
  407|    149|    unsigned int i, len = 0;
  408|       |
  409|    149|    PORT_Assert((unsigned int *)NULL != outBufLen);
  ------------------
  |  |  120|    149|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|    149|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 149, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  410|       |
  411|  1.66k|    for (i = 0; i < inBufLen; i++) {
  ------------------
  |  Branch (411:17): [True: 1.51k, False: 149]
  ------------------
  412|  1.51k|        if ((inBuf[i] & 0x80) == 0x00)
  ------------------
  |  Branch (412:13): [True: 1.21k, False: 297]
  ------------------
  413|  1.21k|            len += 1;
  414|    297|        else
  415|    297|            len += 2;
  416|  1.51k|    }
  417|       |
  418|    149|    if (len > maxOutBufLen) {
  ------------------
  |  Branch (418:9): [True: 0, False: 149]
  ------------------
  419|      0|        *outBufLen = len;
  420|      0|        return PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  421|      0|    }
  422|       |
  423|    149|    len = 0;
  424|       |
  425|  1.66k|    for (i = 0; i < inBufLen; i++) {
  ------------------
  |  Branch (425:17): [True: 1.51k, False: 149]
  ------------------
  426|  1.51k|        if ((inBuf[i] & 0x80) == 0x00) {
  ------------------
  |  Branch (426:13): [True: 1.21k, False: 297]
  ------------------
  427|       |            /* 00-7F -> 0xxxxxxx */
  428|       |            /* 0abcdefg -> 0abcdefg */
  429|       |
  430|  1.21k|            outBuf[len] = inBuf[i];
  431|  1.21k|            len += 1;
  432|  1.21k|        } else {
  433|       |            /* 80-FF <- 110xxxxx 10xxxxxx */
  434|       |            /* 00000000 abcdefgh -> 110000ab 10cdefgh */
  435|       |
  436|    297|            outBuf[len + 0] = 0xC0 | ((inBuf[i] & 0xC0) >> 6);
  437|    297|            outBuf[len + 1] = 0x80 | ((inBuf[i] & 0x3F) >> 0);
  438|       |
  439|    297|            len += 2;
  440|    297|        }
  441|  1.51k|    }
  442|       |
  443|    149|    *outBufLen = len;
  444|    149|    return PR_TRUE;
  ------------------
  |  |  437|    149|#define PR_TRUE 1
  ------------------
  445|    149|}

NSSUTIL_DoModuleDBFunction:
  899|      2|{
  900|      2|    char *secmod = NULL;
  901|      2|    char *appName = NULL;
  902|      2|    char *filename = NULL;
  903|      2|    NSSDBType dbType = NSS_DB_TYPE_NONE;
  904|      2|    PRBool rw;
  905|      2|    static char *success = "Success";
  906|      2|    char **rvstr = NULL;
  907|       |
  908|      2|    secmod = _NSSUTIL_GetSecmodName(parameters, &dbType, &appName,
  909|      2|                                    &filename, &rw);
  910|      2|    if ((dbType == NSS_DB_TYPE_LEGACY) ||
  ------------------
  |  Branch (910:9): [True: 0, False: 2]
  ------------------
  911|      2|        (dbType == NSS_DB_TYPE_MULTIACCESS)) {
  ------------------
  |  Branch (911:9): [True: 0, False: 2]
  ------------------
  912|       |        /* we can't handle the old database, only softoken can */
  913|      0|        PORT_SetError(SEC_ERROR_LEGACY_DATABASE);
  ------------------
  |  |   65|      0|#define PORT_SetError PORT_SetError_Util
  ------------------
  914|      0|        rvstr = NULL;
  915|      0|        goto done;
  916|      0|    }
  917|       |
  918|      2|    switch (function) {
  ------------------
  |  Branch (918:13): [True: 0, False: 2]
  ------------------
  919|      1|        case SECMOD_MODULE_DB_FUNCTION_FIND:
  ------------------
  |  |  557|      1|#define SECMOD_MODULE_DB_FUNCTION_FIND 0
  ------------------
  |  Branch (919:9): [True: 1, False: 1]
  ------------------
  920|      1|            rvstr = nssutil_ReadSecmodDB(appName, filename,
  921|      1|                                         secmod, (char *)parameters, rw);
  922|      1|            break;
  923|      0|        case SECMOD_MODULE_DB_FUNCTION_ADD:
  ------------------
  |  |  558|      0|#define SECMOD_MODULE_DB_FUNCTION_ADD 1
  ------------------
  |  Branch (923:9): [True: 0, False: 2]
  ------------------
  924|      0|            rvstr = (nssutil_AddSecmodDBEntry(appName, filename,
  ------------------
  |  Branch (924:21): [True: 0, False: 0]
  ------------------
  925|      0|                                              secmod, (char *)args, rw) == SECSuccess)
  926|      0|                        ? &success
  927|      0|                        : NULL;
  928|      0|            break;
  929|      0|        case SECMOD_MODULE_DB_FUNCTION_DEL:
  ------------------
  |  |  559|      0|#define SECMOD_MODULE_DB_FUNCTION_DEL 2
  ------------------
  |  Branch (929:9): [True: 0, False: 2]
  ------------------
  930|      0|            rvstr = (nssutil_DeleteSecmodDBEntry(appName, filename,
  ------------------
  |  Branch (930:21): [True: 0, False: 0]
  ------------------
  931|      0|                                                 secmod, (char *)args, rw) == SECSuccess)
  932|      0|                        ? &success
  933|      0|                        : NULL;
  934|      0|            break;
  935|      1|        case SECMOD_MODULE_DB_FUNCTION_RELEASE:
  ------------------
  |  |  560|      1|#define SECMOD_MODULE_DB_FUNCTION_RELEASE 3
  ------------------
  |  Branch (935:9): [True: 1, False: 1]
  ------------------
  936|      1|            rvstr = (nssutil_ReleaseSecmodDBData(appName, filename,
  ------------------
  |  Branch (936:21): [True: 1, False: 0]
  ------------------
  937|      1|                                                 secmod, (char **)args, rw) == SECSuccess)
  938|      1|                        ? &success
  939|      1|                        : NULL;
  940|      1|            break;
  941|      2|    }
  942|      2|done:
  943|      2|    if (secmod)
  ------------------
  |  Branch (943:9): [True: 0, False: 2]
  ------------------
  944|      0|        PR_smprintf_free(secmod);
  945|      2|    if (appName)
  ------------------
  |  Branch (945:9): [True: 0, False: 2]
  ------------------
  946|      0|        PORT_Free(appName);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  947|      2|    if (filename)
  ------------------
  |  Branch (947:9): [True: 0, False: 2]
  ------------------
  948|      0|        PORT_Free(filename);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  949|      2|    return rvstr;
  950|      2|}
utilmod.c:nssutil_ReadSecmodDB:
  375|      1|{
  376|      1|    FILE *fd = NULL;
  377|      1|    char **moduleList = NULL;
  378|      1|    int moduleCount = 1;
  379|      1|    int useCount = SECMOD_STEP;
  ------------------
  |  |  294|      1|#define SECMOD_STEP 10
  ------------------
  380|      1|    char line[MAX_LINE_LENGTH];
  381|      1|    PRBool internal = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  382|      1|    PRBool skipParams = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  383|      1|    char *moduleString = NULL;
  384|      1|    char *paramsValue = NULL;
  385|      1|    PRBool failed = PR_TRUE;
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  386|       |
  387|      1|    moduleList = (char **)PORT_ZAlloc(useCount * sizeof(char *));
  ------------------
  |  |   72|      1|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  388|      1|    if (moduleList == NULL)
  ------------------
  |  Branch (388:9): [True: 0, False: 1]
  ------------------
  389|      0|        return NULL;
  390|       |
  391|      1|    if (dbname == NULL) {
  ------------------
  |  Branch (391:9): [True: 1, False: 0]
  ------------------
  392|      1|        goto return_default;
  393|      1|    }
  394|       |
  395|       |    /* do we really want to use streams here */
  396|      0|    fd = os_fopen(dbname, "r");
  ------------------
  |  |  215|      0|#define os_fopen fopen
  ------------------
  397|      0|    if (fd == NULL)
  ------------------
  |  Branch (397:9): [True: 0, False: 0]
  ------------------
  398|      0|        goto done;
  399|       |
  400|       |    /*
  401|       |     * the following loop takes line separated config lines and collapses
  402|       |     * the lines to a single string, escaping and quoting as necessary.
  403|       |     */
  404|       |    /* loop state variables */
  405|      0|    moduleString = NULL;   /* current concatenated string */
  406|      0|    internal = PR_FALSE;   /* is this an internal module */
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  407|      0|    skipParams = PR_FALSE; /* did we find an override parameter block*/
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  408|      0|    paramsValue = NULL;    /* the current parameter block value */
  409|      0|    do {
  410|      0|        int len;
  411|       |
  412|      0|        if (fgets(line, sizeof(line), fd) == NULL) {
  ------------------
  |  Branch (412:13): [True: 0, False: 0]
  ------------------
  413|      0|            goto endloop;
  414|      0|        }
  415|       |
  416|       |        /* remove the ending newline */
  417|      0|        len = PORT_Strlen(line);
  ------------------
  |  |  190|      0|#define PORT_Strlen(s) strlen(s)
  ------------------
  418|      0|        if (len >= 2 && line[len - 2] == '\r' && line[len - 1] == '\n') {
  ------------------
  |  Branch (418:13): [True: 0, False: 0]
  |  Branch (418:25): [True: 0, False: 0]
  |  Branch (418:50): [True: 0, False: 0]
  ------------------
  419|      0|            len = len - 2;
  420|      0|            line[len] = 0;
  421|      0|        } else if (len && (line[len - 1] == '\n' || line[len - 1] == '\r')) {
  ------------------
  |  Branch (421:20): [True: 0, False: 0]
  |  Branch (421:28): [True: 0, False: 0]
  |  Branch (421:53): [True: 0, False: 0]
  ------------------
  422|      0|            len--;
  423|      0|            line[len] = 0;
  424|      0|        }
  425|      0|        if (*line == '#') {
  ------------------
  |  Branch (425:13): [True: 0, False: 0]
  ------------------
  426|      0|            continue;
  427|      0|        }
  428|      0|        if (*line != 0) {
  ------------------
  |  Branch (428:13): [True: 0, False: 0]
  ------------------
  429|       |            /*
  430|       |             * The PKCS #11 group standard assumes blocks of strings
  431|       |             * separated by new lines, clumped by new lines. Internally
  432|       |             * we take strings separated by spaces, so we may need to escape
  433|       |             * certain spaces.
  434|       |             */
  435|      0|            char *value = PORT_Strchr(line, '=');
  ------------------
  |  |  186|      0|#define PORT_Strchr strchr
  ------------------
  436|       |
  437|       |            /* there is no value, write out the stanza as is */
  438|      0|            if (value == NULL || value[1] == 0) {
  ------------------
  |  Branch (438:17): [True: 0, False: 0]
  |  Branch (438:34): [True: 0, False: 0]
  ------------------
  439|      0|                if (moduleString) {
  ------------------
  |  Branch (439:21): [True: 0, False: 0]
  ------------------
  440|      0|                    moduleString = nssutil_DupnCat(moduleString, " ", 1);
  441|      0|                    if (moduleString == NULL)
  ------------------
  |  Branch (441:25): [True: 0, False: 0]
  ------------------
  442|      0|                        goto loser;
  443|      0|                }
  444|      0|                moduleString = nssutil_DupCat(moduleString, line);
  445|      0|                if (moduleString == NULL)
  ------------------
  |  Branch (445:21): [True: 0, False: 0]
  ------------------
  446|      0|                    goto loser;
  447|       |                /* value is already quoted, just write it out */
  448|      0|            } else if (value[1] == '"') {
  ------------------
  |  Branch (448:24): [True: 0, False: 0]
  ------------------
  449|      0|                if (moduleString) {
  ------------------
  |  Branch (449:21): [True: 0, False: 0]
  ------------------
  450|      0|                    moduleString = nssutil_DupnCat(moduleString, " ", 1);
  451|      0|                    if (moduleString == NULL)
  ------------------
  |  Branch (451:25): [True: 0, False: 0]
  ------------------
  452|      0|                        goto loser;
  453|      0|                }
  454|      0|                moduleString = nssutil_DupCat(moduleString, line);
  455|      0|                if (moduleString == NULL)
  ------------------
  |  Branch (455:21): [True: 0, False: 0]
  ------------------
  456|      0|                    goto loser;
  457|       |                /* we have an override parameter section, remember that
  458|       |                 * we found this (see following comment about why this
  459|       |                 * is necessary). */
  460|      0|                if (PORT_Strncasecmp(line, "parameters", 10) == 0) {
  ------------------
  |  |  191|      0|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
  |  Branch (460:21): [True: 0, False: 0]
  ------------------
  461|      0|                    skipParams = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  462|      0|                }
  463|       |                /*
  464|       |                 * The internal token always overrides it's parameter block
  465|       |                 * from the passed in parameters, so wait until then end
  466|       |                 * before we include the parameter block in case we need to
  467|       |                 * override it. NOTE: if the parameter block is quoted with ("),
  468|       |                 * this override does not happen. This allows you to override
  469|       |                 * the application's parameter configuration.
  470|       |                 *
  471|       |                 * parameter block state is controlled by the following variables:
  472|       |                 *  skipParams - Bool : set to true of we have an override param
  473|       |                 *    block (all other blocks, either implicit or explicit are
  474|       |                 *    ignored).
  475|       |                 *  paramsValue - char * : pointer to the current param block. In
  476|       |                 *    the absence of overrides, paramsValue is set to the first
  477|       |                 *    parameter block we find. All subsequent blocks are ignored.
  478|       |                 *    When we find an internal token, the application passed
  479|       |                 *    parameters take precident.
  480|       |                 */
  481|      0|            } else if (PORT_Strncasecmp(line, "parameters", 10) == 0) {
  ------------------
  |  |  191|      0|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
  |  Branch (481:24): [True: 0, False: 0]
  ------------------
  482|       |                /* already have parameters */
  483|      0|                if (paramsValue) {
  ------------------
  |  Branch (483:21): [True: 0, False: 0]
  ------------------
  484|      0|                    continue;
  485|      0|                }
  486|      0|                paramsValue = NSSUTIL_Quote(&value[1], '"');
  487|      0|                if (paramsValue == NULL)
  ------------------
  |  Branch (487:21): [True: 0, False: 0]
  ------------------
  488|      0|                    goto loser;
  489|      0|                continue;
  490|      0|            } else {
  491|       |                /* may need to quote */
  492|      0|                char *newLine;
  493|      0|                if (moduleString) {
  ------------------
  |  Branch (493:21): [True: 0, False: 0]
  ------------------
  494|      0|                    moduleString = nssutil_DupnCat(moduleString, " ", 1);
  495|      0|                    if (moduleString == NULL)
  ------------------
  |  Branch (495:25): [True: 0, False: 0]
  ------------------
  496|      0|                        goto loser;
  497|      0|                }
  498|      0|                moduleString = nssutil_DupnCat(moduleString, line, value - line + 1);
  499|      0|                if (moduleString == NULL)
  ------------------
  |  Branch (499:21): [True: 0, False: 0]
  ------------------
  500|      0|                    goto loser;
  501|      0|                newLine = NSSUTIL_Quote(&value[1], '"');
  502|      0|                if (newLine == NULL)
  ------------------
  |  Branch (502:21): [True: 0, False: 0]
  ------------------
  503|      0|                    goto loser;
  504|      0|                moduleString = nssutil_DupCat(moduleString, newLine);
  505|      0|                PORT_Free(newLine);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  506|      0|                if (moduleString == NULL)
  ------------------
  |  Branch (506:21): [True: 0, False: 0]
  ------------------
  507|      0|                    goto loser;
  508|      0|            }
  509|       |
  510|       |            /* check to see if it's internal? */
  511|      0|            if (PORT_Strncasecmp(line, "NSS=", 4) == 0) {
  ------------------
  |  |  191|      0|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
  |  Branch (511:17): [True: 0, False: 0]
  ------------------
  512|       |                /* This should be case insensitive! reviewers make
  513|       |                 * me fix it if it's not */
  514|      0|                if (PORT_Strstr(line, "internal")) {
  ------------------
  |  |  196|      0|#define PORT_Strstr strstr
  ------------------
  |  Branch (514:21): [True: 0, False: 0]
  ------------------
  515|      0|                    internal = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  516|       |                    /* override the parameters */
  517|      0|                    if (paramsValue) {
  ------------------
  |  Branch (517:25): [True: 0, False: 0]
  ------------------
  518|      0|                        PORT_Free(paramsValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  519|      0|                    }
  520|      0|                    paramsValue = NSSUTIL_Quote(params, '"');
  521|      0|                }
  522|      0|            }
  523|      0|            continue;
  524|      0|        }
  525|      0|        if ((moduleString == NULL) || (*moduleString == 0)) {
  ------------------
  |  Branch (525:13): [True: 0, False: 0]
  |  Branch (525:39): [True: 0, False: 0]
  ------------------
  526|      0|            continue;
  527|      0|        }
  528|       |
  529|      0|    endloop:
  530|       |        /*
  531|       |         * if we are here, we have found a complete stanza. Now write out
  532|       |         * any param section we may have found.
  533|       |         */
  534|      0|        if (paramsValue) {
  ------------------
  |  Branch (534:13): [True: 0, False: 0]
  ------------------
  535|       |            /* we had an override */
  536|      0|            if (!skipParams) {
  ------------------
  |  Branch (536:17): [True: 0, False: 0]
  ------------------
  537|      0|                moduleString = nssutil_DupnCat(moduleString, " parameters=", 12);
  538|      0|                if (moduleString == NULL)
  ------------------
  |  Branch (538:21): [True: 0, False: 0]
  ------------------
  539|      0|                    goto loser;
  540|      0|                moduleString = nssutil_DupCat(moduleString, paramsValue);
  541|      0|                if (moduleString == NULL)
  ------------------
  |  Branch (541:21): [True: 0, False: 0]
  ------------------
  542|      0|                    goto loser;
  543|      0|            }
  544|      0|            PORT_Free(paramsValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  545|      0|            paramsValue = NULL;
  546|      0|        }
  547|       |
  548|      0|        if ((moduleCount + 1) >= useCount) {
  ------------------
  |  Branch (548:13): [True: 0, False: 0]
  ------------------
  549|      0|            SECStatus rv;
  550|      0|            rv = nssutil_growList(&moduleList, &useCount, moduleCount + 1);
  551|      0|            if (rv != SECSuccess) {
  ------------------
  |  Branch (551:17): [True: 0, False: 0]
  ------------------
  552|      0|                goto loser;
  553|      0|            }
  554|      0|        }
  555|       |
  556|      0|        if (internal) {
  ------------------
  |  Branch (556:13): [True: 0, False: 0]
  ------------------
  557|      0|            moduleList[0] = moduleString;
  558|      0|        } else {
  559|      0|            moduleList[moduleCount] = moduleString;
  560|      0|            moduleCount++;
  561|      0|        }
  562|      0|        moduleString = NULL;
  563|      0|        internal = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  564|      0|        skipParams = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  565|      0|    } while (!feof(fd));
  ------------------
  |  Branch (565:14): [True: 0, False: 0]
  ------------------
  566|       |
  567|      0|    if (moduleString) {
  ------------------
  |  Branch (567:9): [True: 0, False: 0]
  ------------------
  568|      0|        PORT_Free(moduleString);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  569|      0|        moduleString = NULL;
  570|      0|    }
  571|      0|done:
  572|       |#ifndef NSS_DISABLE_DBM
  573|       |    /* if we couldn't open a pkcs11 database, look for the old one */
  574|       |    if (fd == NULL) {
  575|       |        char *olddbname = _NSSUTIL_GetOldSecmodName(dbname, filename);
  576|       |        PRStatus status;
  577|       |
  578|       |        /* couldn't get the old name */
  579|       |        if (!olddbname) {
  580|       |            goto bail;
  581|       |        }
  582|       |
  583|       |        /* old one exists */
  584|       |        status = _NSSUTIL_Access(olddbname, PR_ACCESS_EXISTS);
  585|       |        if (status == PR_SUCCESS) {
  586|       |            PR_smprintf_free(olddbname);
  587|       |            PORT_ZFree(moduleList, useCount * sizeof(char *));
  588|       |            PORT_SetError(SEC_ERROR_LEGACY_DATABASE);
  589|       |            return NULL;
  590|       |        }
  591|       |
  592|       |    bail:
  593|       |        if (olddbname) {
  594|       |            PR_smprintf_free(olddbname);
  595|       |        }
  596|       |    }
  597|       |#endif // NSS_DISABLE_DBM
  598|       |
  599|      1|return_default:
  600|       |
  601|      1|    if (!moduleList[0]) {
  ------------------
  |  Branch (601:9): [True: 1, False: 0]
  ------------------
  602|      1|        char *newParams;
  603|      1|        moduleString = PORT_Strdup(NSSUTIL_DEFAULT_INTERNAL_INIT1);
  ------------------
  |  |   69|      1|#define PORT_Strdup PORT_Strdup_Util
  ------------------
                      moduleString = PORT_Strdup(NSSUTIL_DEFAULT_INTERNAL_INIT1);
  ------------------
  |  |   40|      1|    "library= name=\"NSS Internal PKCS #11 Module\" parameters="
  ------------------
  604|      1|        newParams = NSSUTIL_Quote(params, '"');
  605|      1|        if (newParams == NULL)
  ------------------
  |  Branch (605:13): [True: 0, False: 1]
  ------------------
  606|      0|            goto loser;
  607|      1|        moduleString = nssutil_DupCat(moduleString, newParams);
  608|      1|        PORT_Free(newParams);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  609|      1|        if (moduleString == NULL)
  ------------------
  |  Branch (609:13): [True: 0, False: 1]
  ------------------
  610|      0|            goto loser;
  611|      1|        moduleString = nssutil_DupCat(moduleString,
  612|      1|                                      NSSUTIL_DEFAULT_INTERNAL_INIT2);
  ------------------
  |  |   42|      1|    " NSS=\"Flags=internal,critical trustOrder=75 cipherOrder=100 slotParams=(1={"
  ------------------
  613|      1|        if (moduleString == NULL)
  ------------------
  |  Branch (613:13): [True: 0, False: 1]
  ------------------
  614|      0|            goto loser;
  615|      1|        moduleString = nssutil_DupCat(moduleString,
  616|      1|                                      NSSUTIL_DEFAULT_SFTKN_FLAGS);
  ------------------
  |  |   46|      1|    "slotFlags=[ECC,RSA,DSA,DH,RC2,RC4,DES,RANDOM,SHA1,MD5,MD2,SSL,TLS,AES,Camellia,SEED,SHA256,SHA512]"
  ------------------
  617|      1|        if (moduleString == NULL)
  ------------------
  |  Branch (617:13): [True: 0, False: 1]
  ------------------
  618|      0|            goto loser;
  619|      1|        moduleString = nssutil_DupCat(moduleString,
  620|      1|                                      NSSUTIL_DEFAULT_INTERNAL_INIT3);
  ------------------
  |  |   44|      1|    " askpw=any timeout=30})\""
  ------------------
  621|      1|        if (moduleString == NULL)
  ------------------
  |  Branch (621:13): [True: 0, False: 1]
  ------------------
  622|      0|            goto loser;
  623|      1|        moduleList[0] = moduleString;
  624|      1|        moduleString = NULL;
  625|      1|    }
  626|      1|    failed = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  627|       |
  628|      1|loser:
  629|       |    /*
  630|       |     * cleanup
  631|       |     */
  632|       |    /* deal with trust cert db here */
  633|      1|    if (moduleString) {
  ------------------
  |  Branch (633:9): [True: 0, False: 1]
  ------------------
  634|      0|        PORT_Free(moduleString);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  635|      0|        moduleString = NULL;
  636|      0|    }
  637|      1|    if (paramsValue) {
  ------------------
  |  Branch (637:9): [True: 0, False: 1]
  ------------------
  638|      0|        PORT_Free(paramsValue);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  639|      0|        paramsValue = NULL;
  640|      0|    }
  641|      1|    if (failed || (moduleList[0] == NULL)) {
  ------------------
  |  Branch (641:9): [True: 0, False: 1]
  |  Branch (641:19): [True: 0, False: 1]
  ------------------
  642|       |        /* This is wrong! FIXME */
  643|      0|        nssutil_releaseSpecList(moduleList);
  644|      0|        moduleList = NULL;
  645|      0|        failed = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  646|      0|    }
  647|      1|    if (fd != NULL) {
  ------------------
  |  Branch (647:9): [True: 0, False: 1]
  ------------------
  648|      0|        fclose(fd);
  649|      1|    } else if (!failed && rw) {
  ------------------
  |  Branch (649:16): [True: 1, False: 0]
  |  Branch (649:27): [True: 0, False: 1]
  ------------------
  650|       |        /* update our internal module */
  651|      0|        nssutil_AddSecmodDBEntry(appName, filename, dbname, moduleList[0], rw);
  652|      0|    }
  653|      1|    return moduleList;
  654|      1|}
utilmod.c:nssutil_DupnCat:
  255|      4|{
  256|      4|    int baseStringLen = baseString ? PORT_Strlen(baseString) : 0;
  ------------------
  |  |  190|      4|#define PORT_Strlen(s) strlen(s)
  ------------------
  |  Branch (256:25): [True: 4, False: 0]
  ------------------
  257|      4|    int len = baseStringLen + 1;
  258|      4|    char *newString;
  259|       |
  260|      4|    len += str_len;
  261|      4|    newString = (char *)PORT_Realloc(baseString, len);
  ------------------
  |  |   64|      4|#define PORT_Realloc PORT_Realloc_Util
  ------------------
  262|      4|    if (newString == NULL) {
  ------------------
  |  Branch (262:9): [True: 0, False: 4]
  ------------------
  263|      0|        PORT_Free(baseString);
  ------------------
  |  |   60|      0|#define PORT_Free PORT_Free_Util
  ------------------
  264|      0|        return NULL;
  265|      0|    }
  266|      4|    PORT_Memcpy(&newString[baseStringLen], str, str_len);
  ------------------
  |  |  180|      4|#define PORT_Memcpy memcpy
  ------------------
  267|      4|    newString[len - 1] = 0;
  268|      4|    return newString;
  269|      4|}
utilmod.c:nssutil_DupCat:
  275|      4|{
  276|      4|    return nssutil_DupnCat(baseString, str, PORT_Strlen(str));
  ------------------
  |  |  190|      4|#define PORT_Strlen(s) strlen(s)
  ------------------
  277|      4|}
utilmod.c:nssutil_releaseSpecList:
  283|      1|{
  284|      1|    if (moduleSpecList) {
  ------------------
  |  Branch (284:9): [True: 1, False: 0]
  ------------------
  285|      1|        char **index;
  286|      2|        for (index = moduleSpecList; *index; index++) {
  ------------------
  |  Branch (286:38): [True: 1, False: 1]
  ------------------
  287|      1|            PORT_Free(*index);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  288|      1|        }
  289|      1|        PORT_Free(moduleSpecList);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  290|      1|    }
  291|      1|    return SECSuccess;
  292|      1|}
utilmod.c:nssutil_ReleaseSecmodDBData:
  660|      1|{
  661|      1|    if (moduleSpecList) {
  ------------------
  |  Branch (661:9): [True: 1, False: 0]
  ------------------
  662|      1|        nssutil_releaseSpecList(moduleSpecList);
  663|      1|    }
  664|      1|    return SECSuccess;
  665|      1|}

NSSUTIL_ArgGetPair:
   20|     90|{
   21|     90|    switch (c) {
   22|     75|        case '\'':
  ------------------
  |  Branch (22:9): [True: 75, False: 15]
  ------------------
   23|     75|            return c;
   24|      6|        case '\"':
  ------------------
  |  Branch (24:9): [True: 6, False: 84]
  ------------------
   25|      6|            return c;
   26|      0|        case '<':
  ------------------
  |  Branch (26:9): [True: 0, False: 90]
  ------------------
   27|      0|            return '>';
   28|      2|        case '{':
  ------------------
  |  Branch (28:9): [True: 2, False: 88]
  ------------------
   29|      2|            return '}';
   30|      5|        case '[':
  ------------------
  |  Branch (30:9): [True: 5, False: 85]
  ------------------
   31|      5|            return ']';
   32|      2|        case '(':
  ------------------
  |  Branch (32:9): [True: 2, False: 88]
  ------------------
   33|      2|            return ')';
   34|      0|        default:
  ------------------
  |  Branch (34:9): [True: 0, False: 90]
  ------------------
   35|      0|            break;
   36|     90|    }
   37|      0|    return ' ';
   38|     90|}
NSSUTIL_ArgIsBlank:
   42|  3.36k|{
   43|  3.36k|    return isspace((unsigned char)c);
   44|  3.36k|}
NSSUTIL_ArgIsEscape:
   48|  6.98k|{
   49|  6.98k|    return c == '\\';
   50|  6.98k|}
NSSUTIL_ArgIsQuote:
   54|    219|{
   55|    219|    switch (c) {
   56|     86|        case '\'':
  ------------------
  |  Branch (56:9): [True: 86, False: 133]
  ------------------
   57|     98|        case '\"':
  ------------------
  |  Branch (57:9): [True: 12, False: 207]
  ------------------
   58|     98|        case '<':
  ------------------
  |  Branch (58:9): [True: 0, False: 219]
  ------------------
   59|    101|        case '{': /* } end curly to keep vi bracket matching working */
  ------------------
  |  Branch (59:9): [True: 3, False: 216]
  ------------------
   60|    104|        case '(': /* ) */
  ------------------
  |  Branch (60:9): [True: 3, False: 216]
  ------------------
   61|    110|        case '[': /* ] */
  ------------------
  |  Branch (61:9): [True: 6, False: 213]
  ------------------
   62|    110|            return PR_TRUE;
  ------------------
  |  |  437|    110|#define PR_TRUE 1
  ------------------
   63|    109|        default:
  ------------------
  |  Branch (63:9): [True: 109, False: 110]
  ------------------
   64|    109|            break;
   65|    219|    }
   66|    109|    return PR_FALSE;
  ------------------
  |  |  438|    109|#define PR_FALSE 0
  ------------------
   67|    219|}
NSSUTIL_ArgStrip:
   71|    121|{
   72|    205|    while (*c && NSSUTIL_ArgIsBlank(*c))
  ------------------
  |  Branch (72:12): [True: 191, False: 14]
  |  Branch (72:18): [True: 84, False: 107]
  ------------------
   73|     84|        c++;
   74|    121|    return c;
   75|    121|}
NSSUTIL_ArgFindEnd:
   83|    155|{
   84|    155|    char endChar = ' ';
   85|    155|    PRBool lastEscape = PR_FALSE;
  ------------------
  |  |  438|    155|#define PR_FALSE 0
  ------------------
   86|       |
   87|    155|    if (NSSUTIL_ArgIsQuote(*string)) {
  ------------------
  |  Branch (87:9): [True: 90, False: 65]
  ------------------
   88|     90|        endChar = NSSUTIL_ArgGetPair(*string);
   89|     90|        string++;
   90|     90|    }
   91|       |
   92|  4.10k|    for (; *string; string++) {
  ------------------
  |  Branch (92:12): [True: 4.08k, False: 22]
  ------------------
   93|  4.08k|        if (lastEscape) {
  ------------------
  |  Branch (93:13): [True: 0, False: 4.08k]
  ------------------
   94|      0|            lastEscape = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
   95|      0|            continue;
   96|      0|        }
   97|  4.08k|        if (NSSUTIL_ArgIsEscape(*string) && !lastEscape) {
  ------------------
  |  Branch (97:13): [True: 0, False: 4.08k]
  |  Branch (97:45): [True: 0, False: 0]
  ------------------
   98|      0|            lastEscape = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
   99|      0|            continue;
  100|      0|        }
  101|  4.08k|        if ((endChar == ' ') && NSSUTIL_ArgIsBlank(*string))
  ------------------
  |  Branch (101:13): [True: 2.37k, False: 1.70k]
  |  Branch (101:33): [True: 43, False: 2.33k]
  ------------------
  102|     43|            break;
  103|  4.04k|        if (*string == endChar) {
  ------------------
  |  Branch (103:13): [True: 90, False: 3.95k]
  ------------------
  104|     90|            break;
  105|     90|        }
  106|  4.04k|    }
  107|       |
  108|    155|    return string;
  109|    155|}
NSSUTIL_ArgFetchValue:
  117|     65|{
  118|     65|    const char *end = NSSUTIL_ArgFindEnd(string);
  119|     65|    char *retString, *copyString;
  120|     65|    PRBool lastEscape = PR_FALSE;
  ------------------
  |  |  438|     65|#define PR_FALSE 0
  ------------------
  121|     65|    int len;
  122|       |
  123|     65|    len = end - string;
  124|     65|    if (len == 0) {
  ------------------
  |  Branch (124:9): [True: 1, False: 64]
  ------------------
  125|      1|        *pcount = 0;
  126|      1|        return NULL;
  127|      1|    }
  128|       |
  129|     64|    copyString = retString = (char *)PORT_Alloc(len + 1);
  ------------------
  |  |   52|     64|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  130|       |
  131|     64|    if (*end)
  ------------------
  |  Branch (131:9): [True: 48, False: 16]
  ------------------
  132|     48|        len++;
  133|     64|    *pcount = len;
  134|     64|    if (retString == NULL)
  ------------------
  |  Branch (134:9): [True: 0, False: 64]
  ------------------
  135|      0|        return NULL;
  136|       |
  137|     64|    if (NSSUTIL_ArgIsQuote(*string))
  ------------------
  |  Branch (137:9): [True: 20, False: 44]
  ------------------
  138|     20|        string++;
  139|  2.96k|    for (; string < end; string++) {
  ------------------
  |  Branch (139:12): [True: 2.90k, False: 64]
  ------------------
  140|  2.90k|        if (NSSUTIL_ArgIsEscape(*string) && !lastEscape) {
  ------------------
  |  Branch (140:13): [True: 0, False: 2.90k]
  |  Branch (140:45): [True: 0, False: 0]
  ------------------
  141|      0|            lastEscape = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  142|      0|            continue;
  143|      0|        }
  144|  2.90k|        lastEscape = PR_FALSE;
  ------------------
  |  |  438|  2.90k|#define PR_FALSE 0
  ------------------
  145|  2.90k|        *copyString++ = *string;
  146|  2.90k|    }
  147|     64|    *copyString = 0;
  148|     64|    return retString;
  149|     64|}
NSSUTIL_ArgSkipParameter:
  156|     90|{
  157|     90|    const char *end;
  158|       |    /* look for the end of the <name>= */
  159|    885|    for (; *string; string++) {
  ------------------
  |  Branch (159:12): [True: 885, False: 0]
  ------------------
  160|    885|        if (*string == '=') {
  ------------------
  |  Branch (160:13): [True: 90, False: 795]
  ------------------
  161|     90|            string++;
  162|     90|            break;
  163|     90|        }
  164|    795|        if (NSSUTIL_ArgIsBlank(*string))
  ------------------
  |  Branch (164:13): [True: 0, False: 795]
  ------------------
  165|      0|            return (string);
  166|    795|    }
  167|       |
  168|     90|    end = NSSUTIL_ArgFindEnd(string);
  169|     90|    if (*end)
  ------------------
  |  Branch (169:9): [True: 84, False: 6]
  ------------------
  170|     84|        end++;
  171|     90|    return end;
  172|     90|}
NSSUTIL_ArgGetParamValue:
  179|     52|{
  180|     52|    char searchValue[256];
  181|     52|    size_t paramLen = strlen(paramName);
  182|     52|    char *returnValue = NULL;
  183|     52|    int next;
  184|       |
  185|     52|    if ((parameters == NULL) || (*parameters == 0))
  ------------------
  |  Branch (185:9): [True: 0, False: 52]
  |  Branch (185:33): [True: 0, False: 52]
  ------------------
  186|      0|        return NULL;
  187|       |
  188|     52|    PORT_Assert(paramLen + 2 < sizeof(searchValue));
  ------------------
  |  |  120|     52|#define PORT_Assert PR_ASSERT
  |  |  ------------------
  |  |  |  |  208|     52|    ((_expr)?((void)0):PR_Assert(# _expr,__FILE__,__LINE__))
  |  |  |  |  ------------------
  |  |  |  |  |  Branch (208:6): [True: 52, False: 0]
  |  |  |  |  ------------------
  |  |  ------------------
  ------------------
  189|       |
  190|     52|    PORT_Strcpy(searchValue, paramName);
  ------------------
  |  |  189|     52|#define PORT_Strcpy strcpy
  ------------------
  191|     52|    PORT_Strcat(searchValue, "=");
  ------------------
  |  |  185|     52|#define PORT_Strcat strcat
  ------------------
  192|    123|    while (*parameters) {
  ------------------
  |  Branch (192:12): [True: 116, False: 7]
  ------------------
  193|    116|        if (PORT_Strncasecmp(parameters, searchValue, paramLen + 1) == 0) {
  ------------------
  |  |  191|    116|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
  |  Branch (193:13): [True: 45, False: 71]
  ------------------
  194|     45|            parameters += paramLen + 1;
  195|     45|            returnValue = NSSUTIL_ArgFetchValue(parameters, &next);
  196|     45|            break;
  197|     71|        } else {
  198|     71|            parameters = NSSUTIL_ArgSkipParameter(parameters);
  199|     71|        }
  200|     71|        parameters = NSSUTIL_ArgStrip(parameters);
  201|     71|    }
  202|     52|    return returnValue;
  203|     52|}
NSSUTIL_ArgNextFlag:
  210|    137|{
  211|  1.32k|    for (; *flags; flags++) {
  ------------------
  |  Branch (211:12): [True: 1.30k, False: 23]
  ------------------
  212|  1.30k|        if (*flags == ',') {
  ------------------
  |  Branch (212:13): [True: 114, False: 1.18k]
  ------------------
  213|    114|            flags++;
  214|    114|            break;
  215|    114|        }
  216|  1.30k|    }
  217|    137|    return flags;
  218|    137|}
NSSUTIL_ArgHasFlag:
  225|     41|{
  226|     41|    char *flags;
  227|     41|    const char *index;
  228|     41|    int len = strlen(flag);
  229|     41|    PRBool found = PR_FALSE;
  ------------------
  |  |  438|     41|#define PR_FALSE 0
  ------------------
  230|       |
  231|     41|    flags = NSSUTIL_ArgGetParamValue(label, parameters);
  232|     41|    if (flags == NULL)
  ------------------
  |  Branch (232:9): [True: 2, False: 39]
  ------------------
  233|      2|        return PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
  234|       |
  235|    158|    for (index = flags; *index; index = NSSUTIL_ArgNextFlag(index)) {
  ------------------
  |  Branch (235:25): [True: 136, False: 22]
  ------------------
  236|    136|        if (PORT_Strncasecmp(index, flag, len) == 0) {
  ------------------
  |  |  191|    136|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
  |  Branch (236:13): [True: 17, False: 119]
  ------------------
  237|     17|            found = PR_TRUE;
  ------------------
  |  |  437|     17|#define PR_TRUE 1
  ------------------
  238|     17|            break;
  239|     17|        }
  240|    136|    }
  241|     39|    PORT_Free(flags);
  ------------------
  |  |   60|     39|#define PORT_Free PORT_Free_Util
  ------------------
  242|     39|    return found;
  243|     41|}
NSSUTIL_ArgDecodeNumber:
  250|      4|{
  251|      4|    int radix = 10;
  252|      4|    unsigned long value = 0;
  253|      4|    long retValue = 0;
  254|      4|    int sign = 1;
  255|      4|    int digit;
  256|       |
  257|      4|    if (num == NULL)
  ------------------
  |  Branch (257:9): [True: 0, False: 4]
  ------------------
  258|      0|        return retValue;
  259|       |
  260|      4|    num = NSSUTIL_ArgStrip(num);
  261|       |
  262|      4|    if (*num == '-') {
  ------------------
  |  Branch (262:9): [True: 0, False: 4]
  ------------------
  263|      0|        sign = -1;
  264|      0|        num++;
  265|      0|    }
  266|       |
  267|      4|    if (*num == '0') {
  ------------------
  |  Branch (267:9): [True: 0, False: 4]
  ------------------
  268|      0|        radix = 8;
  269|      0|        num++;
  270|      0|        if ((*num == 'x') || (*num == 'X')) {
  ------------------
  |  Branch (270:13): [True: 0, False: 0]
  |  Branch (270:30): [True: 0, False: 0]
  ------------------
  271|      0|            radix = 16;
  272|      0|            num++;
  273|      0|        }
  274|      0|    }
  275|       |
  276|     12|    for (; *num; num++) {
  ------------------
  |  Branch (276:12): [True: 8, False: 4]
  ------------------
  277|      8|        if (isdigit((unsigned char)*num)) {
  278|      8|            digit = *num - '0';
  279|      8|        } else if ((*num >= 'a') && (*num <= 'f')) {
  ------------------
  |  Branch (279:20): [True: 0, False: 0]
  |  Branch (279:37): [True: 0, False: 0]
  ------------------
  280|      0|            digit = *num - 'a' + 10;
  281|      0|        } else if ((*num >= 'A') && (*num <= 'F')) {
  ------------------
  |  Branch (281:20): [True: 0, False: 0]
  |  Branch (281:37): [True: 0, False: 0]
  ------------------
  282|      0|            digit = *num - 'A' + 10;
  283|      0|        } else {
  284|      0|            break;
  285|      0|        }
  286|      8|        if (digit >= radix)
  ------------------
  |  Branch (286:13): [True: 0, False: 8]
  ------------------
  287|      0|            break;
  288|      8|        value = value * radix + digit;
  289|      8|    }
  290|       |
  291|      4|    retValue = ((int)value) * sign;
  292|      4|    return retValue;
  293|      4|}
NSSUTIL_ArgGetLabel:
  301|      1|{
  302|      1|    char *name = NULL;
  303|      1|    const char *string;
  304|      1|    int len;
  305|       |
  306|       |    /* look for the end of the <label>= */
  307|      2|    for (string = inString; *string; string++) {
  ------------------
  |  Branch (307:29): [True: 2, False: 0]
  ------------------
  308|      2|        if (*string == '=') {
  ------------------
  |  Branch (308:13): [True: 1, False: 1]
  ------------------
  309|      1|            break;
  310|      1|        }
  311|      1|        if (NSSUTIL_ArgIsBlank(*string))
  ------------------
  |  Branch (311:13): [True: 0, False: 1]
  ------------------
  312|      0|            break;
  313|      1|    }
  314|       |
  315|      1|    len = string - inString;
  316|       |
  317|      1|    *next = len;
  318|      1|    if (*string == '=')
  ------------------
  |  Branch (318:9): [True: 1, False: 0]
  ------------------
  319|      1|        (*next) += 1;
  320|      1|    if (len > 0) {
  ------------------
  |  Branch (320:9): [True: 1, False: 0]
  ------------------
  321|      1|        name = PORT_Alloc(len + 1);
  ------------------
  |  |   52|      1|#define PORT_Alloc PORT_Alloc_Util
  ------------------
  322|      1|        PORT_Strncpy(name, inString, len);
  ------------------
  |  |  194|      1|#define PORT_Strncpy strncpy
  ------------------
  323|      1|        name[len] = 0;
  324|      1|    }
  325|      1|    return name;
  326|      1|}
NSSUTIL_ArgReadLong:
  334|      5|{
  335|      5|    char *value;
  336|      5|    long retValue;
  337|      5|    if (isdefault)
  ------------------
  |  Branch (337:9): [True: 0, False: 5]
  ------------------
  338|      0|        *isdefault = PR_FALSE;
  ------------------
  |  |  438|      0|#define PR_FALSE 0
  ------------------
  339|       |
  340|      5|    value = NSSUTIL_ArgGetParamValue(label, params);
  341|      5|    if (value == NULL) {
  ------------------
  |  Branch (341:9): [True: 2, False: 3]
  ------------------
  342|      2|        if (isdefault)
  ------------------
  |  Branch (342:13): [True: 0, False: 2]
  ------------------
  343|      0|            *isdefault = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  344|      2|        return defValue;
  345|      2|    }
  346|      3|    retValue = NSSUTIL_ArgDecodeNumber(value);
  347|      3|    if (value)
  ------------------
  |  Branch (347:9): [True: 3, False: 0]
  ------------------
  348|      3|        PORT_Free(value);
  ------------------
  |  |   60|      3|#define PORT_Free PORT_Free_Util
  ------------------
  349|       |
  350|      3|    return retValue;
  351|      5|}
NSSUTIL_Quote:
  421|      1|{
  422|      1|    return nssutil_escapeQuotes(string, quote, PR_TRUE);
  ------------------
  |  |  437|      1|#define PR_TRUE 1
  ------------------
  423|      1|}
NSSUTIL_DoubleEscape:
  445|      9|{
  446|      9|    char *round1 = NULL;
  447|      9|    char *retValue = NULL;
  448|      9|    if (string == NULL) {
  ------------------
  |  Branch (448:9): [True: 0, False: 9]
  ------------------
  449|      0|        goto done;
  450|      0|    }
  451|      9|    round1 = nssutil_escapeQuotes(string, quote1, PR_FALSE);
  ------------------
  |  |  438|      9|#define PR_FALSE 0
  ------------------
  452|      9|    if (round1) {
  ------------------
  |  Branch (452:9): [True: 9, False: 0]
  ------------------
  453|      9|        retValue = nssutil_escapeQuotes(round1, quote2, PR_FALSE);
  ------------------
  |  |  438|      9|#define PR_FALSE 0
  ------------------
  454|      9|        PORT_Free(round1);
  ------------------
  |  |   60|      9|#define PORT_Free PORT_Free_Util
  ------------------
  455|      9|    }
  456|       |
  457|      9|done:
  458|      9|    if (retValue == NULL) {
  ------------------
  |  Branch (458:9): [True: 0, False: 9]
  ------------------
  459|      0|        retValue = PORT_Strdup("");
  ------------------
  |  |   69|      0|#define PORT_Strdup PORT_Strdup_Util
  ------------------
  460|      0|    }
  461|      9|    return retValue;
  462|      9|}
NSSUTIL_ArgParseSlotFlags:
  621|      1|{
  622|      1|    char *flags;
  623|      1|    const char *index;
  624|      1|    unsigned long retValue = 0;
  625|      1|    int i;
  626|      1|    PRBool all = PR_FALSE;
  ------------------
  |  |  438|      1|#define PR_FALSE 0
  ------------------
  627|       |
  628|      1|    flags = NSSUTIL_ArgGetParamValue(label, params);
  629|      1|    if (flags == NULL)
  ------------------
  |  Branch (629:9): [True: 0, False: 1]
  ------------------
  630|      0|        return 0;
  631|       |
  632|      1|    if (PORT_Strcasecmp(flags, "all") == 0)
  ------------------
  |  |  184|      1|#define PORT_Strcasecmp PL_strcasecmp
  ------------------
  |  Branch (632:9): [True: 0, False: 1]
  ------------------
  633|      0|        all = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
  634|       |
  635|     19|    for (index = flags; *index; index = NSSUTIL_ArgNextFlag(index)) {
  ------------------
  |  Branch (635:25): [True: 18, False: 1]
  ------------------
  636|    414|        for (i = 0; i < nssutil_argSlotFlagTableSize; i++) {
  ------------------
  |  Branch (636:21): [True: 396, False: 18]
  ------------------
  637|    396|            if (all ||
  ------------------
  |  Branch (637:17): [True: 0, False: 396]
  ------------------
  638|    396|                (PORT_Strncasecmp(index, nssutil_argSlotFlagTable[i].name,
  ------------------
  |  |  191|    396|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
  |  Branch (638:17): [True: 18, False: 378]
  ------------------
  639|    396|                                  nssutil_argSlotFlagTable[i].len) == 0)) {
  640|     18|                retValue |= nssutil_argSlotFlagTable[i].value;
  641|     18|            }
  642|    396|        }
  643|     18|    }
  644|      1|    PORT_Free(flags);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  645|      1|    return retValue;
  646|      1|}
NSSUTIL_ArgParseSlotInfo:
  681|      2|{
  682|      2|    const char *slotIndex;
  683|      2|    struct NSSUTILPreSlotInfoStr *slotInfo = NULL;
  684|      2|    int i = 0, count = 0, next;
  685|       |
  686|      2|    *retCount = 0;
  687|      2|    if ((slotParams == NULL) || (*slotParams == 0))
  ------------------
  |  Branch (687:9): [True: 1, False: 1]
  |  Branch (687:33): [True: 0, False: 1]
  ------------------
  688|      1|        return NULL;
  689|       |
  690|       |    /* first count the number of slots */
  691|      2|    for (slotIndex = NSSUTIL_ArgStrip(slotParams); *slotIndex;
  ------------------
  |  Branch (691:52): [True: 1, False: 1]
  ------------------
  692|      1|         slotIndex = NSSUTIL_ArgStrip(NSSUTIL_ArgSkipParameter(slotIndex))) {
  693|      1|        count++;
  694|      1|    }
  695|       |
  696|       |    /* get the data structures */
  697|      1|    if (arena) {
  ------------------
  |  Branch (697:9): [True: 1, False: 0]
  ------------------
  698|      1|        slotInfo = PORT_ArenaZNewArray(arena,
  ------------------
  |  |  163|      1|    (type *)PORT_ArenaZAlloc(poolp, sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   59|      1|#define PORT_ArenaZAlloc PORT_ArenaZAlloc_Util
  |  |  ------------------
  ------------------
  699|      1|                                       struct NSSUTILPreSlotInfoStr, count);
  700|      1|    } else {
  701|      0|        slotInfo = PORT_ZNewArray(struct NSSUTILPreSlotInfoStr, count);
  ------------------
  |  |  159|      0|    (type *)PORT_ZAlloc(sizeof(type) * (num))
  |  |  ------------------
  |  |  |  |   72|      0|#define PORT_ZAlloc PORT_ZAlloc_Util
  |  |  ------------------
  ------------------
  702|      0|    }
  703|      1|    if (slotInfo == NULL)
  ------------------
  |  Branch (703:9): [True: 0, False: 1]
  ------------------
  704|      0|        return NULL;
  705|       |
  706|      1|    for (slotIndex = NSSUTIL_ArgStrip(slotParams), i = 0;
  707|      2|         *slotIndex && i < count;) {
  ------------------
  |  Branch (707:10): [True: 1, False: 1]
  |  Branch (707:24): [True: 1, False: 0]
  ------------------
  708|      1|        char *name;
  709|      1|        name = NSSUTIL_ArgGetLabel(slotIndex, &next);
  710|      1|        slotIndex += next;
  711|       |
  712|      1|        if (!NSSUTIL_ArgIsBlank(*slotIndex)) {
  ------------------
  |  Branch (712:13): [True: 1, False: 0]
  ------------------
  713|      1|            char *args = NSSUTIL_ArgFetchValue(slotIndex, &next);
  714|      1|            slotIndex += next;
  715|      1|            if (args) {
  ------------------
  |  Branch (715:17): [True: 1, False: 0]
  ------------------
  716|      1|                nssutil_argDecodeSingleSlotInfo(name, args, &slotInfo[i]);
  717|      1|                i++;
  718|      1|                PORT_Free(args);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  719|      1|            }
  720|      1|        }
  721|      1|        if (name)
  ------------------
  |  Branch (721:13): [True: 1, False: 0]
  ------------------
  722|      1|            PORT_Free(name);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  723|      1|        slotIndex = NSSUTIL_ArgStrip(slotIndex);
  724|      1|    }
  725|      1|    *retCount = i;
  726|      1|    return slotInfo;
  727|      1|}
NSSUTIL_ArgParseModuleSpecEx:
  836|      2|{
  837|      2|    int next;
  838|      2|    modulespec = NSSUTIL_ArgStrip(modulespec);
  839|       |
  840|      2|    *lib = *mod = *parameters = *nss = *config = 0;
  841|       |
  842|      9|    while (*modulespec) {
  ------------------
  |  Branch (842:12): [True: 7, False: 2]
  ------------------
  843|      7|        NSSUTIL_HANDLE_STRING_ARG(modulespec, *lib, "library=", ;)
  ------------------
  |  |   21|      7|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      7|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 1, False: 6]
  |  |  ------------------
  |  |   22|      1|        param += sizeof(value) - 1;                               \
  |  |   23|      1|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 1]
  |  |  ------------------
  |  |   24|      1|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      1|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      1|        param += next;                                            \
  |  |   27|      1|        command;                                                  \
  |  |   28|      1|    } else
  ------------------
  844|      6|        NSSUTIL_HANDLE_STRING_ARG(modulespec, *mod, "name=", ;)
  ------------------
  |  |   21|      6|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      6|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 2, False: 4]
  |  |  ------------------
  |  |   22|      2|        param += sizeof(value) - 1;                               \
  |  |   23|      2|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 2]
  |  |  ------------------
  |  |   24|      2|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      2|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      2|        param += next;                                            \
  |  |   27|      2|        command;                                                  \
  |  |   28|      2|    } else
  ------------------
  845|      4|        NSSUTIL_HANDLE_STRING_ARG(modulespec, *parameters, "parameters=", ;)
  ------------------
  |  |   21|      4|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      4|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 2, False: 2]
  |  |  ------------------
  |  |   22|      2|        param += sizeof(value) - 1;                               \
  |  |   23|      2|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 2]
  |  |  ------------------
  |  |   24|      2|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      2|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      2|        param += next;                                            \
  |  |   27|      2|        command;                                                  \
  |  |   28|      2|    } else
  ------------------
  846|      2|        NSSUTIL_HANDLE_STRING_ARG(modulespec, *nss, "nss=", ;)
  ------------------
  |  |   21|      2|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      2|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 2, False: 0]
  |  |  ------------------
  |  |   22|      2|        param += sizeof(value) - 1;                               \
  |  |   23|      2|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 2]
  |  |  ------------------
  |  |   24|      2|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      2|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      2|        param += next;                                            \
  |  |   27|      2|        command;                                                  \
  |  |   28|      2|    } else
  ------------------
  847|      0|        NSSUTIL_HANDLE_STRING_ARG(modulespec, *config, "config=", ;)
  ------------------
  |  |   21|      0|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|      0|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 0, False: 0]
  |  |  ------------------
  |  |   22|      0|        param += sizeof(value) - 1;                               \
  |  |   23|      0|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 0]
  |  |  ------------------
  |  |   24|      0|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      0|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      0|        param += next;                                            \
  |  |   27|      0|        command;                                                  \
  |  |   28|      0|    } else
  ------------------
  848|      0|        NSSUTIL_HANDLE_FINAL_ARG(modulespec)
  ------------------
  |  |   31|      0|    {                                            \
  |  |   32|      0|        param = NSSUTIL_ArgSkipParameter(param); \
  |  |   33|      0|    }                                            \
  |  |   34|      7|    param = NSSUTIL_ArgStrip(param);
  ------------------
  849|      7|    }
  850|      2|    return SECSuccess;
  851|      2|}
NSSUTIL_ArgParseCipherFlags:
 1008|      2|{
 1009|      2|    newCiphers[0] = newCiphers[1] = 0;
 1010|      2|    if ((cipherList == NULL) || (*cipherList == 0))
  ------------------
  |  Branch (1010:9): [True: 2, False: 0]
  |  Branch (1010:33): [True: 0, False: 0]
  ------------------
 1011|      2|        return;
 1012|       |
 1013|      0|    for (; *cipherList; cipherList = NSSUTIL_ArgNextFlag(cipherList)) {
  ------------------
  |  Branch (1013:12): [True: 0, False: 0]
  ------------------
 1014|      0|        if (PORT_Strncasecmp(cipherList, NSSUTIL_ARG_FORTEZZA_FLAG,
  ------------------
  |  |  191|      0|#define PORT_Strncasecmp PL_strncasecmp
  ------------------
                      if (PORT_Strncasecmp(cipherList, NSSUTIL_ARG_FORTEZZA_FLAG,
  ------------------
  |  | 1002|      0|#define NSSUTIL_ARG_FORTEZZA_FLAG "FORTEZZA"
  ------------------
  |  Branch (1014:13): [True: 0, False: 0]
  ------------------
 1015|      0|                             sizeof(NSSUTIL_ARG_FORTEZZA_FLAG) - 1) == 0) {
  ------------------
  |  | 1002|      0|#define NSSUTIL_ARG_FORTEZZA_FLAG "FORTEZZA"
  ------------------
 1016|      0|            newCiphers[0] |= SECMOD_FORTEZZA_FLAG;
  ------------------
  |  |   18|      0|#define SECMOD_FORTEZZA_FLAG 0x00000040L
  ------------------
 1017|      0|        }
 1018|       |
 1019|       |        /* add additional flags here as necessary */
 1020|       |        /* direct bit mapping escape */
 1021|      0|        if (*cipherList == 0) {
  ------------------
  |  Branch (1021:13): [True: 0, False: 0]
  ------------------
 1022|      0|            if (cipherList[1] == 'l') {
  ------------------
  |  Branch (1022:17): [True: 0, False: 0]
  ------------------
 1023|      0|                newCiphers[1] |= atoi(&cipherList[2]);
 1024|      0|            } else {
 1025|      0|                newCiphers[0] |= atoi(&cipherList[2]);
 1026|      0|            }
 1027|      0|        }
 1028|      0|    }
 1029|      0|}
_NSSUTIL_EvaluateConfigDir:
 1196|      2|{
 1197|      2|    NSSDBType dbType;
 1198|      2|    PRBool checkEnvDefaultDB = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1199|      2|    *appName = NULL;
 1200|       |    /* force the default */
 1201|      2|    dbType = NSS_DB_TYPE_SQL;
 1202|      2|    if (configdir == NULL) {
  ------------------
  |  Branch (1202:9): [True: 0, False: 2]
  ------------------
 1203|      0|        checkEnvDefaultDB = PR_TRUE;
  ------------------
  |  |  437|      0|#define PR_TRUE 1
  ------------------
 1204|      2|    } else if (PORT_Strncmp(configdir, MULTIACCESS, sizeof(MULTIACCESS) - 1) == 0) {
  ------------------
  |  |  193|      2|#define PORT_Strncmp strncmp
  ------------------
                  } else if (PORT_Strncmp(configdir, MULTIACCESS, sizeof(MULTIACCESS) - 1) == 0) {
  ------------------
  |  | 1191|      2|#define MULTIACCESS "multiaccess:"
  ------------------
                  } else if (PORT_Strncmp(configdir, MULTIACCESS, sizeof(MULTIACCESS) - 1) == 0) {
  ------------------
  |  | 1191|      2|#define MULTIACCESS "multiaccess:"
  ------------------
  |  Branch (1204:16): [True: 0, False: 2]
  ------------------
 1205|      0|        char *cdir;
 1206|      0|        dbType = NSS_DB_TYPE_MULTIACCESS;
 1207|       |
 1208|      0|        *appName = PORT_Strdup(configdir + sizeof(MULTIACCESS) - 1);
  ------------------
  |  |   69|      0|#define PORT_Strdup PORT_Strdup_Util
  ------------------
                      *appName = PORT_Strdup(configdir + sizeof(MULTIACCESS) - 1);
  ------------------
  |  | 1191|      0|#define MULTIACCESS "multiaccess:"
  ------------------
 1209|      0|        if (*appName == NULL) {
  ------------------
  |  Branch (1209:13): [True: 0, False: 0]
  ------------------
 1210|      0|            return configdir;
 1211|      0|        }
 1212|      0|        cdir = *appName;
 1213|      0|        while (*cdir && *cdir != ':') {
  ------------------
  |  Branch (1213:16): [True: 0, False: 0]
  |  Branch (1213:25): [True: 0, False: 0]
  ------------------
 1214|      0|            cdir++;
 1215|      0|        }
 1216|      0|        if (*cdir == ':') {
  ------------------
  |  Branch (1216:13): [True: 0, False: 0]
  ------------------
 1217|      0|            *cdir = 0;
 1218|      0|            cdir++;
 1219|      0|        }
 1220|      0|        configdir = cdir;
 1221|      2|    } else if (PORT_Strncmp(configdir, SQLDB, sizeof(SQLDB) - 1) == 0) {
  ------------------
  |  |  193|      2|#define PORT_Strncmp strncmp
  ------------------
                  } else if (PORT_Strncmp(configdir, SQLDB, sizeof(SQLDB) - 1) == 0) {
  ------------------
  |  | 1188|      2|#define SQLDB "sql:"
  ------------------
                  } else if (PORT_Strncmp(configdir, SQLDB, sizeof(SQLDB) - 1) == 0) {
  ------------------
  |  | 1188|      2|#define SQLDB "sql:"
  ------------------
  |  Branch (1221:16): [True: 0, False: 2]
  ------------------
 1222|      0|        dbType = NSS_DB_TYPE_SQL;
 1223|      0|        configdir = configdir + sizeof(SQLDB) - 1;
  ------------------
  |  | 1188|      0|#define SQLDB "sql:"
  ------------------
 1224|      2|    } else if (PORT_Strncmp(configdir, EXTERNDB, sizeof(EXTERNDB) - 1) == 0) {
  ------------------
  |  |  193|      2|#define PORT_Strncmp strncmp
  ------------------
                  } else if (PORT_Strncmp(configdir, EXTERNDB, sizeof(EXTERNDB) - 1) == 0) {
  ------------------
  |  | 1189|      2|#define EXTERNDB "extern:"
  ------------------
                  } else if (PORT_Strncmp(configdir, EXTERNDB, sizeof(EXTERNDB) - 1) == 0) {
  ------------------
  |  | 1189|      2|#define EXTERNDB "extern:"
  ------------------
  |  Branch (1224:16): [True: 0, False: 2]
  ------------------
 1225|      0|        dbType = NSS_DB_TYPE_EXTERN;
 1226|      0|        configdir = configdir + sizeof(EXTERNDB) - 1;
  ------------------
  |  | 1189|      0|#define EXTERNDB "extern:"
  ------------------
 1227|      2|    } else if (PORT_Strncmp(configdir, LEGACY, sizeof(LEGACY) - 1) == 0) {
  ------------------
  |  |  193|      2|#define PORT_Strncmp strncmp
  ------------------
                  } else if (PORT_Strncmp(configdir, LEGACY, sizeof(LEGACY) - 1) == 0) {
  ------------------
  |  | 1190|      2|#define LEGACY "dbm:"
  ------------------
                  } else if (PORT_Strncmp(configdir, LEGACY, sizeof(LEGACY) - 1) == 0) {
  ------------------
  |  | 1190|      2|#define LEGACY "dbm:"
  ------------------
  |  Branch (1227:16): [True: 0, False: 2]
  ------------------
 1228|      0|        dbType = NSS_DB_TYPE_LEGACY;
 1229|      0|        configdir = configdir + sizeof(LEGACY) - 1;
  ------------------
  |  | 1190|      0|#define LEGACY "dbm:"
  ------------------
 1230|      2|    } else {
 1231|      2|        checkEnvDefaultDB = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1232|      2|    }
 1233|       |
 1234|       |    /* look up the default from the environment */
 1235|      2|    if (checkEnvDefaultDB) {
  ------------------
  |  Branch (1235:9): [True: 2, False: 0]
  ------------------
 1236|      2|        char *defaultType = PR_GetEnvSecure("NSS_DEFAULT_DB_TYPE");
 1237|      2|        if (defaultType != NULL) {
  ------------------
  |  Branch (1237:13): [True: 0, False: 2]
  ------------------
 1238|      0|            if (PORT_Strncmp(defaultType, SQLDB, sizeof(SQLDB) - 2) == 0) {
  ------------------
  |  |  193|      0|#define PORT_Strncmp strncmp
  ------------------
                          if (PORT_Strncmp(defaultType, SQLDB, sizeof(SQLDB) - 2) == 0) {
  ------------------
  |  | 1188|      0|#define SQLDB "sql:"
  ------------------
                          if (PORT_Strncmp(defaultType, SQLDB, sizeof(SQLDB) - 2) == 0) {
  ------------------
  |  | 1188|      0|#define SQLDB "sql:"
  ------------------
  |  Branch (1238:17): [True: 0, False: 0]
  ------------------
 1239|      0|                dbType = NSS_DB_TYPE_SQL;
 1240|      0|            } else if (PORT_Strncmp(defaultType, EXTERNDB, sizeof(EXTERNDB) - 2) == 0) {
  ------------------
  |  |  193|      0|#define PORT_Strncmp strncmp
  ------------------
                          } else if (PORT_Strncmp(defaultType, EXTERNDB, sizeof(EXTERNDB) - 2) == 0) {
  ------------------
  |  | 1189|      0|#define EXTERNDB "extern:"
  ------------------
                          } else if (PORT_Strncmp(defaultType, EXTERNDB, sizeof(EXTERNDB) - 2) == 0) {
  ------------------
  |  | 1189|      0|#define EXTERNDB "extern:"
  ------------------
  |  Branch (1240:24): [True: 0, False: 0]
  ------------------
 1241|      0|                dbType = NSS_DB_TYPE_EXTERN;
 1242|      0|            } else if (PORT_Strncmp(defaultType, LEGACY, sizeof(LEGACY) - 2) == 0) {
  ------------------
  |  |  193|      0|#define PORT_Strncmp strncmp
  ------------------
                          } else if (PORT_Strncmp(defaultType, LEGACY, sizeof(LEGACY) - 2) == 0) {
  ------------------
  |  | 1190|      0|#define LEGACY "dbm:"
  ------------------
                          } else if (PORT_Strncmp(defaultType, LEGACY, sizeof(LEGACY) - 2) == 0) {
  ------------------
  |  | 1190|      0|#define LEGACY "dbm:"
  ------------------
  |  Branch (1242:24): [True: 0, False: 0]
  ------------------
 1243|      0|                dbType = NSS_DB_TYPE_LEGACY;
 1244|      0|            }
 1245|      0|        }
 1246|      2|    }
 1247|       |    /* if the caller has already set a type, don't change it */
 1248|      2|    if (*pdbType == NSS_DB_TYPE_NONE) {
  ------------------
  |  Branch (1248:9): [True: 2, False: 0]
  ------------------
 1249|      2|        *pdbType = dbType;
 1250|      2|    }
 1251|      2|    return configdir;
 1252|      2|}
_NSSUTIL_GetSecmodName:
 1257|      2|{
 1258|      2|    int next;
 1259|      2|    char *configdir = NULL;
 1260|      2|    char *secmodName = NULL;
 1261|      2|    char *value = NULL;
 1262|      2|    const char *save_params = param;
 1263|      2|    const char *lconfigdir;
 1264|      2|    PRBool noModDB = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1265|      2|    param = NSSUTIL_ArgStrip(param);
 1266|       |
 1267|     22|    while (*param) {
  ------------------
  |  Branch (1267:12): [True: 20, False: 2]
  ------------------
 1268|     20|        NSSUTIL_HANDLE_STRING_ARG(param, configdir, "configDir=", ;)
  ------------------
  |  |   21|     20|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|     20|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 2, False: 18]
  |  |  ------------------
  |  |   22|      2|        param += sizeof(value) - 1;                               \
  |  |   23|      2|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 2]
  |  |  ------------------
  |  |   24|      2|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      2|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      2|        param += next;                                            \
  |  |   27|      2|        command;                                                  \
  |  |   28|      2|    } else
  ------------------
 1269|     18|        NSSUTIL_HANDLE_STRING_ARG(param, secmodName, "secmod=", ;)
  ------------------
  |  |   21|     18|    if (PORT_Strncasecmp(param, value, sizeof(value) - 1) == 0) { \
  |  |  ------------------
  |  |  |  |  191|     18|#define PORT_Strncasecmp PL_strncasecmp
  |  |  ------------------
  |  |  |  Branch (21:9): [True: 2, False: 16]
  |  |  ------------------
  |  |   22|      2|        param += sizeof(value) - 1;                               \
  |  |   23|      2|        if (target)                                               \
  |  |  ------------------
  |  |  |  Branch (23:13): [True: 0, False: 2]
  |  |  ------------------
  |  |   24|      2|            PORT_Free(target);                                    \
  |  |  ------------------
  |  |  |  |   60|      0|#define PORT_Free PORT_Free_Util
  |  |  ------------------
  |  |   25|      2|        target = NSSUTIL_ArgFetchValue(param, &next);             \
  |  |   26|      2|        param += next;                                            \
  |  |   27|      2|        command;                                                  \
  |  |   28|      2|    } else
  ------------------
 1270|     16|        NSSUTIL_HANDLE_FINAL_ARG(param)
  ------------------
  |  |   31|     16|    {                                            \
  |  |   32|     16|        param = NSSUTIL_ArgSkipParameter(param); \
  |  |   33|     16|    }                                            \
  |  |   34|     20|    param = NSSUTIL_ArgStrip(param);
  ------------------
 1271|     20|    }
 1272|       |
 1273|      2|    *rw = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1274|      2|    if (NSSUTIL_ArgHasFlag("flags", "readOnly", save_params)) {
  ------------------
  |  Branch (1274:9): [True: 2, False: 0]
  ------------------
 1275|      2|        *rw = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1276|      2|    }
 1277|       |
 1278|      2|    if (!secmodName || *secmodName == '\0') {
  ------------------
  |  Branch (1278:9): [True: 0, False: 2]
  |  Branch (1278:24): [True: 2, False: 0]
  ------------------
 1279|      2|        if (secmodName)
  ------------------
  |  Branch (1279:13): [True: 2, False: 0]
  ------------------
 1280|      2|            PORT_Free(secmodName);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 1281|      2|        secmodName = PORT_Strdup(SECMOD_DB);
  ------------------
  |  |   69|      2|#define PORT_Strdup PORT_Strdup_Util
  ------------------
                      secmodName = PORT_Strdup(SECMOD_DB);
  ------------------
  |  | 1192|      2|#define SECMOD_DB "secmod.db"
  ------------------
 1282|      2|    }
 1283|       |
 1284|      2|    *filename = secmodName;
 1285|      2|    lconfigdir = _NSSUTIL_EvaluateConfigDir(configdir, dbType, appName);
 1286|       |
 1287|      2|    if (NSSUTIL_ArgHasFlag("flags", "noModDB", save_params)) {
  ------------------
  |  Branch (1287:9): [True: 2, False: 0]
  ------------------
 1288|       |        /* there isn't a module db, don't load the legacy support */
 1289|      2|        noModDB = PR_TRUE;
  ------------------
  |  |  437|      2|#define PR_TRUE 1
  ------------------
 1290|      2|        *dbType = NSS_DB_TYPE_SQL;
 1291|      2|        PORT_Free(*filename);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 1292|      2|        *filename = NULL;
 1293|      2|        *rw = PR_FALSE;
  ------------------
  |  |  438|      2|#define PR_FALSE 0
  ------------------
 1294|      2|    }
 1295|       |
 1296|       |    /* only use the renamed secmod for legacy databases */
 1297|      2|    if ((*dbType != NSS_DB_TYPE_LEGACY) &&
  ------------------
  |  Branch (1297:9): [True: 2, False: 0]
  ------------------
 1298|      2|        (*dbType != NSS_DB_TYPE_MULTIACCESS) &&
  ------------------
  |  Branch (1298:9): [True: 2, False: 0]
  ------------------
 1299|      2|        !NSSUTIL_ArgHasFlag("flags", "forceSecmodChoice", save_params)) {
  ------------------
  |  Branch (1299:9): [True: 2, False: 0]
  ------------------
 1300|      2|        secmodName = "pkcs11.txt";
 1301|      2|    }
 1302|       |
 1303|      2|    if (noModDB) {
  ------------------
  |  Branch (1303:9): [True: 2, False: 0]
  ------------------
 1304|      2|        value = NULL;
 1305|      2|    } else if (lconfigdir && lconfigdir[0] != '\0') {
  ------------------
  |  Branch (1305:16): [True: 0, False: 0]
  |  Branch (1305:30): [True: 0, False: 0]
  ------------------
 1306|      0|        value = PR_smprintf("%s" NSSUTIL_PATH_SEPARATOR "%s",
 1307|      0|                            lconfigdir, secmodName);
 1308|      0|    } else {
 1309|      0|        value = PR_smprintf("%s", secmodName);
 1310|      0|    }
 1311|      2|    if (configdir)
  ------------------
  |  Branch (1311:9): [True: 2, False: 0]
  ------------------
 1312|      2|        PORT_Free(configdir);
  ------------------
  |  |   60|      2|#define PORT_Free PORT_Free_Util
  ------------------
 1313|      2|    return value;
 1314|      2|}
utilpars.c:nssutil_escapeQuotesSize:
  359|     19|{
  360|     19|    int escapes = 0, size = 0;
  361|     19|    const char *src;
  362|       |
  363|     19|    size = addquotes ? 2 : 0;
  ------------------
  |  Branch (363:12): [True: 1, False: 18]
  ------------------
  364|    215|    for (src = string; *src; src++) {
  ------------------
  |  Branch (364:24): [True: 196, False: 19]
  ------------------
  365|    196|        if ((*src == quote) || (*src == '\\'))
  ------------------
  |  Branch (365:13): [True: 0, False: 196]
  |  Branch (365:32): [True: 0, False: 196]
  ------------------
  366|      0|            escapes++;
  367|    196|        size++;
  368|    196|    }
  369|     19|    return size + escapes + 1;
  370|     19|}
utilpars.c:nssutil_escapeQuotes:
  374|     19|{
  375|     19|    char *newString = 0;
  376|     19|    int size = 0;
  377|     19|    const char *src;
  378|     19|    char *dest;
  379|       |
  380|     19|    size = nssutil_escapeQuotesSize(string, quote, addquotes);
  381|       |
  382|     19|    dest = newString = PORT_ZAlloc(size);
  ------------------
  |  |   72|     19|#define PORT_ZAlloc PORT_ZAlloc_Util
  ------------------
  383|     19|    if (newString == NULL) {
  ------------------
  |  Branch (383:9): [True: 0, False: 19]
  ------------------
  384|      0|        return NULL;
  385|      0|    }
  386|       |
  387|     19|    if (addquotes)
  ------------------
  |  Branch (387:9): [True: 1, False: 18]
  ------------------
  388|      1|        *dest++ = quote;
  389|    215|    for (src = string; *src; src++, dest++) {
  ------------------
  |  Branch (389:24): [True: 196, False: 19]
  ------------------
  390|    196|        if ((*src == '\\') || (*src == quote)) {
  ------------------
  |  Branch (390:13): [True: 0, False: 196]
  |  Branch (390:31): [True: 0, False: 196]
  ------------------
  391|      0|            *dest++ = '\\';
  392|      0|        }
  393|    196|        *dest = *src;
  394|    196|    }
  395|     19|    if (addquotes)
  ------------------
  |  Branch (395:9): [True: 1, False: 18]
  ------------------
  396|      1|        *dest = quote;
  397|       |
  398|     19|    return newString;
  399|     19|}
utilpars.c:nssutil_argDecodeSingleSlotInfo:
  652|      1|{
  653|      1|    char *askpw;
  654|       |
  655|      1|    slotInfo->slotID = NSSUTIL_ArgDecodeNumber(name);
  656|      1|    slotInfo->defaultFlags = NSSUTIL_ArgParseSlotFlags("slotFlags", params);
  657|      1|    slotInfo->timeout = NSSUTIL_ArgReadLong("timeout", params, 0, NULL);
  658|       |
  659|      1|    askpw = NSSUTIL_ArgGetParamValue("askpw", params);
  660|      1|    slotInfo->askpw = 0;
  661|       |
  662|      1|    if (askpw) {
  ------------------
  |  Branch (662:9): [True: 1, False: 0]
  ------------------
  663|      1|        if (PORT_Strcasecmp(askpw, "every") == 0) {
  ------------------
  |  |  184|      1|#define PORT_Strcasecmp PL_strcasecmp
  ------------------
  |  Branch (663:13): [True: 0, False: 1]
  ------------------
  664|      0|            slotInfo->askpw = -1;
  665|      1|        } else if (PORT_Strcasecmp(askpw, "timeout") == 0) {
  ------------------
  |  |  184|      1|#define PORT_Strcasecmp PL_strcasecmp
  ------------------
  |  Branch (665:20): [True: 0, False: 1]
  ------------------
  666|      0|            slotInfo->askpw = 1;
  667|      0|        }
  668|      1|        PORT_Free(askpw);
  ------------------
  |  |   60|      1|#define PORT_Free PORT_Free_Util
  ------------------
  669|      1|        slotInfo->defaultFlags |= PK11_OWN_PW_DEFAULTS;
  ------------------
  |  |   36|      1|#define PK11_OWN_PW_DEFAULTS 0x20000000L
  ------------------
  670|      1|    }
  671|      1|    slotInfo->hasRootCerts = NSSUTIL_ArgHasFlag("rootFlags", "hasRootCerts",
  672|      1|                                                params);
  673|      1|    slotInfo->hasRootTrust = NSSUTIL_ArgHasFlag("rootFlags", "hasRootTrust",
  674|      1|                                                params);
  675|      1|}

